E-ZPass´¹µö¶ÌÐŹ¥»÷·¢×÷£¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþ·ÇÔÈ¡
°ä²¼¹¦·ò 2025-04-071. E-ZPass´¹µö¶ÌÐŹ¥»÷·¢×÷£¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþ·ÇÔÈ¡
4ÔÂ6ÈÕ£¬½üÆÚ£¬Õë¶Ô½»Í¨ÊÕ·Ñ·þÎñÓû§µÄÍøÂç´¹µö¹¥»÷³öÏÖ·¢×÷ʽÔö³¤£¬·¸·¨·Ö×Ó¼ÙÒâE-ZPass¡¢FasTrakµÈÊÕ·Ñ»ú¹¹£¬Í¨¹ýiMessage¼°SMSÇþ·´ó¹æÄ£·¢ËÍڲƶÌÐÅ¡£¹¥»÷ÕßÀûÓÃ×Ô¶¯»¯¹¤¾ßÈÆ¹ý·´À¬»øÓʼþϵͳ£¬½áºÏËæ»ú»¯·¢¼þµØÖ·Ö´ÐÐ¸ßÆµ´Î¹¥»÷£¬µ¥ÈÕ·¢ËÍÁ¿¿É´ï7Ìõ£¬ÏÔÖø¼ÓÇ¿ÁËڿƵÄÉøÈëÄÜÁ¦¡£´ËÀà¶ÌÐÅͨ³£Ñ¡È¡½ôÆÈÐÔ»°Êõ£¬Èç"48Ó×ʱÄÚδ½Éͨ³©·Ñ½«ÔÝÍ£¼ÝÊ»×ʸñ"µÈÍþвÐÔÄÚÈÝ£¬ÓÕµ¼Óû§µã»÷ǶÈëµÄ¶ñÒâÁ´½Ó¡£Îª¶ã±ÜApple iMessageµÄ°²È«»úÔ죬ڿƷÖ×ÓÒªÇóÓû§ÏȻظ´¶ÌÐÅÒÔ¼¤»î¿Éµã»÷Á´½Ó£¬½ø¶øÌø×ªÖÁ¾«ÐÄ·ÂÔìµÄ´¹µöÍøÕ¾¡£¾¼¼ÊõÑéÖ¤£¬ÕâЩ´¹µöÒ³ÃæÑ¡È¡ÏìӦʽÉè¼Æ£¬½öÄÜÔÚÒÆ¶¯¶ËÆëÈ«ÏÔʾ£¬Í¨¹ýÊÓ¾õ¼Ù×°ÇÔÈ¡Óû§ÐÕÃû¡¢ÐÅÓþ¿¨ºÅµÈÃô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÐÂÐËÍøÂç·¸×ï¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÈçLucidºÍDarcula±»Ö¸²Î¼Ó´ËÀ๥»÷£¬ÆäÀûÓüÓÃܵÄRCSºÍiMessageºÍÌ¸Í»ÆÆ´«Í³¹ýÂËϵͳ£¬ÏÔÖø½µµÍ×÷°¸³É±¾¡£Áª¹úµ÷²é¾Ö£¨FBI£©ÔçÔÚ2024Äê4ÔÂÒѰ䲼ÓйØÔ¤¾¯£¬µ«¹¥»÷Õß³ÖÐøµü´úÊÖ·¨£¬µ¼ÖÂÓû§ÊÜÆ·çÏÕ³ÖÐøÅÊÉý¡£
https://www.bleepingcomputer.com/news/security/toll-payment-text-scam-returns-in-massive-phishing-wave/
2. disgrasya¶ñÒâ°üÀÄÓÃPyPI·Ö·¢Çþ·ÍþвWooCommerceÐÅÓþ¿¨°²È«
4ÔÂ6ÈÕ£¬½üÈÕ£¬°²È«×êÑÐÈËÔ±¸æ·¢ÁËÒ»¸öÃûΪ"disgrasya"µÄ¶ñÒâPython°ü£¬¸Ã°üͨ¹ýPyPIƽ̨±»ÏÂÔØ³¬¹ý3.4Íò´Î£¬ÆäרÃÅÓÃÓÚÑéÖ¤±»µÁÐÅÓþ¿¨µÄ·¸·¨»î¶¯¡£¸Ã¶ñÒâÈí¼þÕë¶ÔʹÓÃCyberSourceÖ§¸¶Íø¹ØµÄWooCommerceµçÉÌÆ½Ì¨£¬Í¨¹ý·ÂÕÕÆëÈ«¹ºÎïÁ÷³ÌÖ´ÐÐÐÅÓþ¿¨Ú²ÆÑéÖ¤¡£¼¼Êõ·ÖÎöÏÔʾ£¬¹¥»÷ÕßÀûÓøðüÖ´Ðи߶È×Ô¶¯»¯µÄ¹¥»÷Á´£ºÊ×ÏÈץȡָ±êÉ̵êÉÌÆ·ID²¢ÌìÉúÐé¹¹¹ºÎï³µ£¬ËæºóÇÔÈ¡½áÕËÒ³ÃæµÄCSRFÁîÅÆºÍÖ§¸¶Íø¹Ø¸ßµÍÎIJÎÊý¡£¹Ø¼ü²½ÖèÖУ¬±»µÁÐÅÓþ¿¨Êý¾Ý²¢·ÇÖ±½ÓÌá½»¸øÖ§¸¶Íø¹Ø£¬¶øÊÇ·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄ¶ñÒâ·þÎñÆ÷£¨railgunmisaka.com£©£¬¸Ã·þÎñÆ÷¼Ù×°³ÉºÏ·¨Ö§¸¶½Ó¿Ú·µ»ØÐéαÊÚȨÁ˾֣¬×îÖÕͨ¹ýÌá½»´øÏóÕ÷µÄ¶©µ¥ÊµÏÖÑéÖ¤¡£ÕâÖÖ¹¥»÷ÊÖ·¨ÓµÓм«Ç¿µÄÒñ±ÎÐÔ¡£Ò»·½Ã棬Õû¸öÁ÷³Ì·ÂÕÕÕæÊµÓû§ÐÐΪ£¬ÃÀÂúÈÚÈëÕý³£ÂòÂôÁ÷Á¿£»ÁíÒ»·½Ã棬¹¥»÷Õßѡȡ"ÖÐÑëÈËÑéÖ¤"ģʽ£¬¼È¶ã±ÜÁËÖ±½Ó´¥ÅöÖ§¸¶ÏµÍ³µÄ¼ì²â·çÏÕ£¬ÓÖÄÜÅúÁ¿´¦ÖðµÍø»ñÈ¡µÄÐÅÓþ¿¨Êý¾Ý¡£Socket°²È«ÍŶÓÖ¸³ö£¬¸Ã¶ñÒâ°üÉõÖÁÔÚÆä¹Ù·½ÃèÊöÖй«¿ªÈÏ¿ÉÓÃÓÚ·¸·¨Óô¦£¬Í¹ÏԺڿͶԿªÔ´Æ½Ì¨ÀÄÓÃˮƽ֮Éî¡£
https://www.bleepingcomputer.com/news/security/carding-tool-abusing-woocommerce-api-downloaded-34k-times-on-pypi/
3. Verizon iOSÀûÓ÷ì϶¶³öͨ»°¼Í¼ԪÊý¾Ý£¬Òѽ¨¸´Î´ÏÖÀÄÓÃ
4ÔÂ5ÈÕ£¬Verizon Wireless½üÆÚ½¨¸´µÄiOS°æCall FilterÀûÓ÷ì϶£¬Â¶³ö³öDZÔڵĴó¹æÄ£Í¨»°¼Í¼й¶·çÏÕ¡£°²È«×êÑÐÔ±Evan ConnellyÓÚ2025Äê2Ô·¢ÏÖ£¬¸ÃÀûÓõÄ/clr/callLogRetrieval½Ó¿Ú´æÔÚÉí·ÝÑé֤ȱµã£ºÖ»¹ÜѡȡJWTÁîÅÆÈÏÖ¤£¬µ«·þÎñÆ÷δУÑéÒªÇóÖеĵ绰ºÅÂëÓëÓû§IDµÄÆ¥ÅäÐÔ¡£ÕâʹµÃ¹¥»÷Õß¿Éͨ¹ýαÔìÒªÇó£¬ËÁÒâ¼ìË÷Ö¸±êÓû§µÄͨ»°¼Í¼£¬ÊÜÓ°ÏìÁìÓòº¸ÇĬÈÏÆôÓø÷þÎñµÄÎÞÊýiOSÓû§¡£¸Ã·ì϶µÄDZÔÚ·çÏÕÔ¶³¬Í¨³£Êý¾Ýй¶¡£×¨¼ÒÖҸ棬ͨ»°¼Í¼µÄ¹¦·ò´ÁÐÅÏ¢¿É±»ÓÃÓÚʵʱ¼à¿ØÌض¨¶ÔÏó£¬Èç¼ÇÕß¡¢·¨ÂÉÈËÔ±»ò¼Ò±©Êܺ¦Õߣ¬ÆäÈÕ³£ÁªÏµÄ£Ê½¼°Ðж¯¹ì¼£½«Æëȫ¶³ö¡£Í¨¹ý¶ÈÎö³Á¸´Í¨»°ºÅÂ룬ÉõÖÁ¿ÉÄܼø±ðһʱͨѶÏß·»ò˽ÃܹØÏµÍøÂ磬×é³ÉÑϳÁµÄÒþÖÔÍþв¡£¼¼ÊõËÝÔ´ÏÔʾ£¬·ì϶ÓëCequint¹«Ë¾µÄ¼¼Êõ¼Ü¹¹´æÔÚ¹ØÁª¡£Verizon½«¸ÃÀûÓõÄAPI²¿ÊðÔÚͨ¹ýGoDaddy×¢²áµÄÓòÃûÏ£¬¶øCequint×÷ΪÀ´µçÏÔʾ¼¼ÊõÌṩÉÌ£¬ÆäÒѹعصĹٷ½ÍøÕ¾Òý·¢¶ÔÊý¾ÝÖÎÀíÄÜÁ¦µÄÖÊÒÉ¡£Ö»¹ÜVerizonÐû³ÆÎ´·¢ÏÖÀÄÓúۼ£ÇÒ·ì϶½öÓ°ÏìiOSÉ豸£¬µ«´ËÀàÃô¸ÐÊý¾ÝµÄ¼¯Öд洢ÈÔÇÃÏ찲ȫ¾¯ÖÓ¡£
https://securityaffairs.com/176217/hacking/verizon-s-ios-call-filter-app-flaw.html
4. Î÷ÑÅͼ¸ÛÔâRhysidaÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ9ÍòÓû§ÐÅϢй¶
4ÔÂ4ÈÕ£¬ÃÀ¹úÎ÷ÑÅͼ¸Û½üÆÚÅû¶£¬ÆäÔÚ2024Äê8ÔÂÔâ·êRhysidaÀÕË÷Èí¼þ×éÖ¯µÄÍøÂç¹¥»÷£¬µ¼ÖÂÔ¼9ÍòÃûÔ±¹¤¡¢³Ð°üÉ̼°Óû§µÄÃô¸ÐÐÅϢй¶¡£×÷Ϊ¼à¹ÜÎ÷ÑÅͼº£¸Û¼°¹ú¼Ê»ú³¡µÄÁª¹ú»ú¹¹£¬Õâ´Î¹¥»÷Ôì³ÉITϵͳÖжϣ¬Ó°Ïì»ú³¡º½°àÔËÓª¡¢³Ë¿Í·þÎñϵͳ¼°¹Ù·½ÍøÕ¾Ö°ÄÜ¡£¸Û¿Úµ±¾ÖÔÚ¹¥»÷²úÉúÈýÖܺóÈ·ÈÏ£¬Rhysida×é֯ϵ¸ÃÊÂÎñµÄÄ»ºóºÚÊÖ¡£Ö»¹Ü¹¥»÷ÕßÍþв½«ÔÚ°µÍø¹«¿ªÇÔÈ¡Êý¾Ý£¬Î÷ÑÅͼ¸ÛÃ÷È·»Ø¾øÖ§¸¶Êê½ðÒªÇó¡£Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂ루²¿Ãź¬ºóËÄ룩¡¢¼ÝÊ»ÅÆÕÕ¼°Ò½ÁÆÐÅÏ¢µÈ£¬ÊÜÓ°ÏìÈËȺÖÐÔ¼7.1ÍòÀ´×Ô»ªÊ¢¶ÙÖÝ¡£Î÷ÑÅͼ¸ÛÒÑÏòÊÜÓ°ÏìÕß¼ÄËÍ9Íò·âÊéÃæÍ¨Öª£¬Ç¿µ÷¹Ø¼üÔËӪϵͳδÊܲ¨¼°¡£¸Û¿Ú³ö¸ñÖ¸³ö£¬»ú³¡¼°º£Ô˳˿ÍÊý¾ÝÊÜÓ°ÏìÓÐÏÞ£¬Ö§¸¶ÏµÍ³Î¬³Ö°²È«£¬ÖØÒªºÏ×÷ͬ°é£¨Ô̺¬º½¿Õ¹«Ë¾¡¢ÓÊÂÔìóÒµ¼°Áª¹ú»ú¹¹£©µÄרÓÐÍøÂçҲδ±»ÉøÈë¡£
https://www.bleepingcomputer.com/news/security/port-of-seattle-says-ransomware-breach-impacts-90-000-people/
5. °Ä´óÀûÑÇÑøÀϽðÐÐÒµÔâ·ê´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷
4ÔÂ4ÈÕ£¬°Ä´óÀûÑÇÑøÀϽðÐÐÒµÉÏÖÜÔâÓö´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷£¬¶à¼Ò´óÐÍ»ù½ð»áÔ¹ØË»§°²È«ÊÜÍþв¡£¾Ý°Ä´óÀûÑÇÑøÀϽð»ù½ðлᣨASFA£©Åû¶£¬Ö»¹ÜÎÞÊý¹¥»÷±»³É¹¦·ÀÓù£¬ÈÔÓв¿ÃÅ»áÔ¹ØË»§±»ÈëÇÖ£¬ÐÐÒµËðʧÇé¿öÕý³ÖÐøÆÀ¹ÀÖС£×÷Ϊ¸Ã¹ú×î´óÑøÀϽð»ù½ðÖ®Ò»£¬AustralianSuperÈ·ÈϹ¥»÷ÕßÀûÓñ»µÁƾ֤ÇÖÈëÖÁÉÙ600¸öÕË»§£¬ÆóÒµÒÑ´¹Î£Ëø¶¨¿ÉÒÉÕË»§²¢Í¨ÖªÊÜÓ°Ïì»áÔ±¡£REST»ù½ðй©£¬Ô¼8000Ãû»áÔ±µÄÐÕÃû¡¢ÓÊÏä¼°»áÔ±±àºÅµÈÃô¸ÐÐÅÏ¢ÔÚ¹¥»÷Öб»½Ó¼û£¬µ«ËùÐÒδ²úÉú×ʽðµÁÈ¡¡£HostplusÔò°µÊ¾Æä»áԱδÔâ·ê²ÆÕþËðʧ£¬Ä¿Ç°ÔÚÆÀ¹ÀÕË»§Ó°ÏìÁìÓò¡£Í¶×ÊÆ½Ì¨Insignia FinancialµÄExpand Wrap PlatformÒ²Ôâ¹¥»÷£¬Ô¼100¸ö¿Í»§ÕË»§±»ÉøÈ룬µ«ÉÐδ·¢ÏÖ×ʽðËðʧ֤¾Ý¡£¸Ã¹«Ë¾ºôÓõÓû§Ô¤·À¿çƽ̨³Á¸´Ê¹ÓÃÃÜÂ룬²¢¶¨ÆÚ¸üÐÂÉ豸°²È«¡£ÖµÍ×ÌùÐĵÄÊÇ£¬HESTAºÍMercer SuperÁ½¼Ò´óÐÍ»ù½ðδÊܲ¨¼°£¬ÆäÖÎÀíµÄ200ÓàÍò»áÔ¹ØË»§Î¬³Ö°²È«¡£ASFAÒÑÆô¶¯½ðÈÚ·¸×ï±£»¤½¨Ò飬³ÉÁ¢¿çÐÐÒµ-µ±¾ÖºÏ×÷ÈÈÏߣ¬²¢°ä²¼·ÀÓù¹¤¾ß°üÇ¿»¯°²È«Ðµ÷¡£
https://www.bleepingcomputer.com/news/security/australian-pension-funds-hit-by-wave-of-credential-stuffing-attacks/
6. EuropcarÔâGitLabÈëÇÖµ¼Ö¶à´ï20Íò¿Í»§Êý¾Ýй¶
4ÔÂ4ÈÕ£¬¿ç¹úÆû³µ×âÁÞ¾ÞÍ·Europcar Mobility Group½üÆÚÔâ·ê³Á´óÍøÂ簲ȫÊÂÎñ£¬ÆäGitLab´úÂë²Ö¿âÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂAndroid/iOSÀûÓÃÔ´´úÂë¼°²¿Ãſͻ§Êý¾Ýй¶¡£¹¥»÷ÕßÐû³Æ°ÑÎÕ37GBÃô¸ÐÊý¾Ý£¬Ô̺¬ÔÆ»ù´¡ÉèÊ©ÏêÇé¼°SQL±¸·ÝÎļþ£¬²¢Íþв¹«¿ªÐÅÏ¢Ö´ÐÐÀÕË÷¡£¾³õ²½È·ÈÏ£¬Ð¹Â¶Êý¾ÝÉæ¼°GoldcarºÍUbeeqoÆ·ÅÆ5ÍòÖÁ20Íò¿Í»§µÄÐÕÃûÓëÓÊÏ䵨ַ£¬µ«Î´Éæ¼°ÒøÐÐÐÅÏ¢¡¢ÃÜÂëµÈÖ÷ÌâÃô¸Ð×ֶΡ£¸Ã¹«Ë¾ÒÑÆô¶¯Ó¦¼±ÏìÓ¦£¬ÏòÊÜÓ°Ïì¿Í»§·¢ËÍ֪ͨ²¢±¨±¸Êý¾Ý±£»¤»ú¹¹¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´ÎÊÂÎñ䲨¼°È«Êý´úÂë²Ö¿â£¬ÈÔÓв¿ÃÅÔ´´úÂëά³ÖÆëÈ«¡£Ä¿Ç°»¹²»Ã÷ÏÔÍþвÐÐΪÕßÊÇÈôºÎ»ñµÃ Europcar ´úÂë´æ´¢¿âµÄ½Ó¼ûȨÏ޵쬵«×î½ü²úÉúµÄºÜ¶àÎ¥¹æÐÐΪ¶¼ÊÇÓÉÐÅÏ¢ÇÔÈ¡ÕßÇÔÈ¡µÄƾ֤ÒýÆðµÄ¡£
https://www.bleepingcomputer.com/news/security/europcar-gitlab-breach-exposes-data-of-up-to-200-000-customers/


¾©¹«Íø°²±¸11010802024551ºÅ