DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾ÏúÉÌ
°ä²¼¹¦·ò 2025-12-041. DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾ÏúÉÌ
12ÔÂ2ÈÕ£¬ÃÀ¹ú×î´óCricket WirelessÊÚȨ¾ÏúÉÌMobilelink USAÔâÓë¶íÂÞ˹¹ØÁªµÄÀÕË÷Èí¼þ×éÖ¯DragonForce¹¥»÷£¬¸Ã×éÖ¯Ðû³ÆÇÔÈ¡³¬5TBÊý¾Ý²¢ÉèÖõ¹¼ÆÊ±Íþв¡£DragonForceÔÚ°µÍøÐ¹Â¶ÍøÕ¾°ä²¼Mobilelink±êÖ¾¼°¶à¼ÒÊܺ¦Õß±êʶ£¬ÒªÇóÆäÔÚÔ¼6Ìì16Ó×ʱÄÚÂú×ãÀÕË÷ÒªÇ󣬲»È»½«¹«¿ª±»µÁÊý¾Ý¡£Mobilelink×÷Ϊ¼±¾çÀ©ÕŵĵçÐÅÔËÓªÉÌ£¬ÔÚÃÀ¹ú21¸öÖÝÔËÓª550¼ÒÁãÊ۵꣬ռÓÐ650ÓàÃûÔ±¹¤£¬×¨ÃÅÌṩÎÞºÏÔ¼5G LTE·þÎñ¡¢Ô¤¸¶·ÑÌײͼ°ÊÖ»úÅä¼þ¡£Õâ´ÎÊý¾Ýй¶¿ÉÄܲ¨¼°Cricketĸ¹«Ë¾AT&TµÄ1300Íò¿Í»§ÈºÌ壬µ¼ÖÂÊý°ÙÍòÃô¸ÐÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¼°²ÆÕþÊý¾Ýй¶£¬Ê¹ÊÜÓ°ÏìÓû§Ãæ¶ÔÉí·Ý͵ÇÔ¡¢ÍøÂç´¹µö¹¥»÷µÈ·çÏÕ¡£DragonForceÊÇ2025Äê×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò»£¬¾ÝCybernews°µÍø¼à¿Ø¹¤¾ßÏÔʾ£¬¸Ã×éÖ¯2025ÄêÒѹ¥»÷185¸ö×éÖ¯£¬ÆäÖÐ130´Î²úÉúÔÚ½üÁù¸öÔ¡£
https://cybernews.com/news/cricket-wireless-mobilelink-usa-ransomware-attack-dragonforce/
2. MarquisÈí¼þÊý¾Ýй¶ÊÂÎñ²¨¼°40Íò½ðÈÚ¿Í»§
12ÔÂ3ÈÕ£¬½üÆÚ£¬Îª700Óà¼ÒÒøÐÓ×¢ÐÅÓþÉç¼°µÖѺ´û¿î»ú¹¹ÌṩÊý¾Ý·ÖÎö¡¢CRM¹¤¾ßµÈ·þÎñµÄ½ðÈÚÈí¼þ¹©¸øÉÌMarquis Software SolutionsÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÃÀ¹ú74¼Ò½ðÈÚ»ú¹¹µÄ40ÓàÍò¿Í»§Êý¾Ýй¶¡£¹¥»÷ͨ¹ý´æÔÚ·ì϶µÄSonicWall·À»ðǽÈëÇÖϵͳ£¬ºÚ¿ÍÇÔÈ¡ÁËÔ̺¬¿Í»§ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á±£ÏÕºÅÂë¡¢ÄÉ˰È˼ø±ðºÅÂë¡¢ÎÞ°²È«ÂëµÄ½ðÈÚÕË»§ÐÅÏ¢¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÎļþ¡£ÊÂÎñÓ°ÏìÁìÓò¸²¸ÇÃåÒò¡¢°®ºÉ»ª¡¢µÂ¿ËÈøË¹µÈ¶àÖÝ£¬Éæ¼°±±¼ÓÖݵÚÒ»ÐÅÓþÉç¡¢±´¶ûΤɪÉçÇøÐÅÓþÉç¡¢Gateway First BankµÈ74¼Ò»ú¹¹¡£MarquisÔÚ֪ͨÖÐÇ¿µ÷£¬Ä¿Ç°ÎÞÖ¤¾ÝÏÔʾÊý¾Ý±»ÀÄÓûò¹«¿ª°ä²¼£¬µ«ÒÑ´ú±í¿Í»§Ïò¸÷ÖÝÌá½»¾ßÌåй¶»ã±¨£¬²¿ÃÅÖÝÎļþϸ·ÖÁËÊÜÓ°Ïì¿Í»§ÊýÁ¿¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Community 1stÐÅÓþÉçÒÑɾ³ýµÄÎļþÏÔʾ£¬MarquisÔøÖ§¸¶Êê½ðÒÔ×èÖ¹Êý¾Ýй¶£¬¶øCoVantage Credit UnionµÄÎļþÔòÅû¶ÁËMarquis¼ÓÇ¿°²È«µÄ¾ßÌå´ëÊ©£º¸üзÀ»ðǽ²¹¶¡¡¢ÂÖ»»±¾µØÕË»§ÃÜÂ롢ɾ³ýÈßÓàÕË»§¡¢ÆôÓöà³É·ÖÈÏÖ¤¡¢µ¢¸éÈÕÖ¾Áô´æ¹¦·ò¡¢Ö´ÐÐÕË»§Ëø¶¨Õ½Êõ¡¢ÏÞ¶ÈÏÎ½ÓÆðÔ´¹ú±ð¼°×Ô¶¯¹Ø±Õ½©Ê¬ÍøÂçIP¡£
https://www.bleepingcomputer.com/news/security/marquis-data-breach-impacts-over-74-us-banks-credit-unions/
3. WordPress²å¼þ¸ßΣ·ì϶Òý·¢´ó¹æÄ£¹¥»÷
12ÔÂ3ÈÕ£¬½üÈÕ£¬WordPressƽ̨Á½¿îÈȵã²å¼þ½ÓÁ¬Â¶³öÑϳÁ°²È«·ì϶£¬Òý·¢È«Çò³¬4.8Íò´Î¹¥»÷³¢ÊÔ¡£King Addons for Elementor²å¼þµÄCVE-2025-8489·ì϶ÔÊÐí¹¥»÷ÕßÖ±½Ó»ñÈ¡ÍøÕ¾ÖÎÀíԱȨÏÞ¡£¸Ã·ì϶ÓÚ2025Äê10ÔÂ31ÈÕ¹«¿ªºó£¬Wordfence°²È«É¨ÃèÆ÷ÒÑÀ¹½Ø48400Óà´Î¹¥»÷£¬ÆäÖÐ11ÔÂ9ÈÕÖÁ10ÈÕ´ïµ½¶¥·å£¬Á½¸ö»îÔ¾IPµØÖ·±ðÀëÌáÒé28900´ÎºÍ16900´Î³¢ÊÔ¡£Ô¼10000¸öʹÓøòå¼þµÄÍøÕ¾Ãæ¶Ô·çÏÕ£¬½¨Òéµ±¼´Éý¼¶ÖÁ51.1.35°æ±¾½¨¸´¡£Í¬ÆÚ£¬Advanced Custom Fields: Extended²å¼þµÄCVE-2025-13486·ì϶ÒàÒý·¢¹Ø×¢¡£¸Ã·ì϶´æÔÚÓÚ0.9.0.5ÖÁ0.9.1.1°æ±¾ÖУ¬Óɲ¨À¼CERTÕÆ¹ÜÈËMarcin Dudek·¢ÏÖ²¢»ã±¨¡£¹¥»÷Õß¿ÉÔÚδÈÏÖ¤Çé¿öÏÂÔ¶³ÌÖ´ÐÐËÁÒâ´úÂ룬¿ÉÄÜÓÃÓÚ×¢ÈëºóÃÅ»ò´´½¨¶ñÒâÖÎÀíÔ¹ØË»§¡£¸Ã·ì϶ÓÚ11ÔÂ18ÈÕÅû¶ºó£¬¹©¸øÉÌ´ÎÈÕ¼´°ä²¼0.9.2°æ±¾½¨¸´£¬µ«¼øÓÚ¼¼Êõϸ½ÚÒѹ«¿ª£¬×¨¼ÒÖÒ¸æ¿ÉÄÜÒý·¢ÐÂÒ»ÂÖ¶ñÒâ¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/critical-flaw-in-wordpress-add-on-for-elementor-exploited-in-attacks/
4. ·¨¹úÀÖ»ªÃ·À¼Åû¶Êý¾Ýй¶ÊÂÎñ
12ÔÂ3ÈÕ£¬·¨¹ú¶È¾Ó½¨²ÄÓëÔ°ÒÕÁãÊÛ¾ÞÍ·ÀÖ»ªÃ·À¼£¨Leroy Merlin£©½üÈÕ֪ͨ¿Í»§£¬Æä²¿ÃÅÓ×ÎÒÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖÐÔâ±í²¿Ð¹Â¶¡£¸Ã¹«Ë¾ÒµÎñ¸²¸ÇÅ·ÖÞ¶à¹ú¼°ÄÏ·Ç¡¢°ÍÎ÷£¬Õ¼ÓÐ16.5ÍòÃûÔ±¹¤£¬ÄêÊÕÈë´ï99ÒÚÃÀÔª¡£Õâ´ÎÊÂÎñ½öÓ°Ïì·¨¹ú¿Í»§£¬Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢ÓÊÕþµØÖ·¡¢µ®ÉúÈÕÆÚ¼°»áÔ±´òËãÓйØÐÅÏ¢£¬µ«²»Éæ¼°ÒøÐÐÕË»§ÃÜÂë»òÍøÉÏÕË»§Ãô¸ÐÊý¾Ý¡£ÀÖ»ªÃ·À¼ÔÚ֪ͨÖÐÇ¿µ÷£¬ÊÂÎñ²úÉúºóÒѵ±¼´²ÉÈ¡´ëÊ©×èֹδ¾ÊÚȨ½Ó¼û²¢½ÚÔìÊÂ̬·¢Õ¹¡£Ö»¹Üµ±Ç°ÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢±»¶ñÒâʹÓûòÓÃÓÚÀÕË÷£¬¹«Ë¾ÈÔÌáÐѿͻ§¾¯ÌèÍøÂç´¹µö¹¥»÷£¬²¢ÌṩÁ˼ø±ð·ÂÃ°Æ·ÅÆ´¹µöÐÅÏ¢µÄ²½Öè¡£Èô¿Í»§·¢ÏÖÕË»§Òì³£»î¶¯»ò»áÔ¹ØÛ¿Û¶Ò»»ÎÊÌ⣬¿ÉÖ±½ÓÏò¹«Ë¾»ã±¨¡£Ä¿Ç°£¬ÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/french-diy-retail-giant-leroy-merlin-discloses-a-data-breach/
5. Freedom MobileÅû¶Êý¾Ýй¶ÊÂÎñ
12ÔÂ3ÈÕ£¬¼ÓÄôóµÚËÄ´óÎÞÏßÔËÓªÉÌFreedom Mobile½üÈÕÅû¶³Á´óÊý¾Ýй¶ÊÂÎñ¡£¸Ã¹«Ë¾ÓÉGlobaliveÓÚ2008ÄêµÞÔ죬ÔÃûΪWind Mobile£¬2023Äê±»¿ý±±¿ËµçÐÅ×Ó¹«Ë¾Vid¨¦otronÊÕ¹ººó£¬ÐγÉÕ¼Óг¬350ÍòÒÆ¶¯Óû§¡¢½ü7500ÃûÔ±¹¤¼°¸²¸Ç99%¼ÓÄôóÈ˵ķþÎñÍøÂç¡£±¾´ÎÊÂÎñ²úÉúÓÚ2025Äê10ÔÂ23ÈÕ£¬¹¥»÷Õßͨ¹ý¶È°üÉ̱»µÁÕË»§ÈëÇÖ¿Í»§ÕË»§ÖÎÀíÆ½Ì¨£¬ÇÔÈ¡Á˲¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢£¬¾ßÌåÔ̺¬ÐÕÃû¡¢¼Òͥסַ¡¢µ®ÉúÈÕÆÚ¡¢ÊÖ»úºÅÂë¼°Freedom MobileÕË»§ºÅÂë¡£¹«Ë¾ÉùÏÔÖøÊ¾£¬ÊÂÎñ²úÉúºó£¬FreedomѸ¿ì²ÉÈ¡Ðж¯£¬ÆÁ±Î¿ÉÒÉÕË»§¼°¶ÔÓ¦IPµØÖ·£¬²¢¼ÓÇ¿°²È«´ëÊ©¡£Ö»¹ÜĿǰÎÞÖ¤¾ÝÅúעй¶Êý¾ÝÒѱ»ÀÄÓ㬵«ÔËÓªÉÌÈÔ½¨ÒéÊÜÓ°Ïì¿Í»§¾¯Ìè´¹µö¹¥»÷£¬Ô¤·Àµã»÷¿ÉÒÉÁ´½Ó»òÏÂÔØ¸½¼þ£¬²¢¶¨ÆÚ²é³ÕË»§Òì³£»î¶¯¡£Freedom Mobile½²»°ÈËÇ¿µ÷£¬Õâ´ÎÊÂÎñ䲨¼°ÍøÂçºÍÔËӪϵͳ£¬²»ÊôÓÚÀÕË÷Èí¼þ¹¥»÷ÀàÐÍ£¬µ«Î´Ð¹Â©¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿¡£×÷Ϊ¼ÓÄôóÖØÒªµçÕÛ·þÎñÉÌ£¬FreedomµÄÊý¾Ýй¶¿ÉÄÜÒý·¢¿Í»§ÐÅÀµÎ£»ú¼°¼à¹ÜÉó²é¡£
https://www.bleepingcomputer.com/news/security/freedom-mobile-discloses-data-breach-exposing-customer-data/
6. ·ï»Ë³Ç´óѧÓöClop¹¥»÷ÖÂʦÉúÊý¾Ýй¶
12ÔÂ3ÈÕ£¬ÃÀ¹ú·ï»Ë³Ç´óѧ£¨UoPX£©8Ô³ÉΪClopÀÕË÷Èí¼þÍÅ»ïÀûÓÃOracle E-Business Suite£¨EBS£©ÁãÈÕ·ì϶£¨CVE-2025-61882£©¹¥»÷µÄÖ¸±ê£¬µ¼Ö´óÁ¿Ãô¸ÐÊý¾Ýй¶¡£ÕâËù³ÉÁ¢ÓÚ1976ÄêµÄ˽Á¢Í¶»úÐÔ´óѧռÓнü3000Ãû½ÌÈËÔ±¹¤ºÍ³¬10ÍòÔÚУѧÉú£¬Æäĸ¹«Ë¾Phoenix Education PartnersÒÑÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»8-K±í¸ñÅû¶ÊÂÎñ¡£¹¥»÷Õßͨ¹ýOracle EBS²ÆÕþÀûÓ÷¨Ê½µÄ·ì϶ÇÔÈ¡ÁËÏÖÈμ°Ç°ÈÎѧÉú¡¢½ÌÖ°¹¤¡¢¹©¸øÉ̵ÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£ÏÕºÅÂë¡¢ÒøÐÐÕË»§¼°Â·ÓɺÅÂëµÈÃô¸ÐÐÅÏ¢¡£ÔÚClop½«ÆäÁÐÈëÊý¾ÝÐ¹Â¶ÍøÕ¾ºó£¬UoPXÓÚ11ÔÂ21ÈÕ·¢ÏÖÊÂÎñ£¬²¢°µÊ¾½«Éó²éÊÜÓ°ÏìÊý¾Ý£¬Í¨¹ýÃÀ¹úÓÊÕþÏòÊÜÓ°ÏìÓ×ÎÒ¼ÄËÍ֪ͨ£¬Í¬Ê±Ïò¼à¹Ü»ú¹¹»ã±¨¡£Ä¿Ç°£¬Ñ§ÌÃδй©¾ßÌåÊÜÓ°ÏìÈËÊý¼°Ä»ºóºÚÊÖ£¬µ«¹«¿ªÐÅÏ¢Ö¸ÏòClopÍŻ·ï»Ë³Ç´óѧǿµ÷ÒѲÉÈ¡´ëÊ©¶ôÔì·çÏÕ£¬µ«Î´²¨¼°Ö÷ÌâÍøÂçÔËÓª¡£
https://www.bleepingcomputer.com/news/security/university-of-phoenix-discloses-data-breach-after-oracle-hack/


¾©¹«Íø°²±¸11010802024551ºÅ