·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÔ¼215Íò¿Í»§

Ðû²¼Ê±¼ä 2023-05-15

1¡¢·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÔ¼215Íò¿Í»§


¾ÝýÌå5ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬·áÌïÆû³µÅû¶ÁËÆäÔÆÇéÐδÓ2013Äê11ÔÂ6ÈÕµ½2023Äê4ÔÂ17ÈÕµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Ì»Â¶ÁËÔ¼2150000Ãû¿Í»§µÄÆû³µÎ»ÖÃÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¸ÃÊÂÎñÊÇÓÉÓÚÊý¾Ý¿âÉèÖùýʧµ¼ÖÂÈκÎÈËÎÞÐèÃÜÂë¼´¿É»á¼ûÆäÄÚÈÝ¡£¡£¡£¡£¡£ ¡£Ð¹Â¶ÁË2012Äê1ÔÂ2ÈÕÖÁ2023Äê4ÔÂ17ÈÕʱ´úʹÓøù«Ë¾T-Connect G-Link¡¢G-Link Lite»òG-BOOKЧÀ͵Ŀͻ§ÐÅÏ¢£¬£¬£¬£¬£¬£¬Éæ¼°³µÁ¾Ê¶ÓÖÃû¡¢³µÁ¾Î»ÖüͼºÍÐгµ¼Í¼ÒÇÊÓÆµµÈ¡£¡£¡£¡£¡£ ¡£


https://www.infosecurity-magazine.com/news/toyota-admits-decade-long-data-leak/


2¡¢DiscordµÚÈý·½Ö§³ÖÊðÀíÔâµ½¹¥»÷µ¼Ö²¿·ÖÐÅϢй¶


ýÌå5ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬DiscordÕýÔÚ֪ͨÊÜÓ°ÏìÓû§¹ØÓÚµÚÈý·½Ö§³ÖÊðÀíµÄÕÊ»§Ôâµ½ÈëÇÖµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£ ¡£Discord͸¶£¬£¬£¬£¬£¬£¬ÓÉÓÚÊÂÎñµÄÐÔ×Ó£¬£¬£¬£¬£¬£¬Óû§ÓʼþµØµã¡¢¿Í»§Ð§ÀÍÐÂÎŵÄÄÚÈÝÒÔ¼°ÓëDiscordÖ®¼ä·¢Ë͵ÄÈκθ½¼þ¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£ ¡£ÎªÓ¦¶ÔÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Á¬Ã¦½ûÓÃÁ˱»ÈëÇÖµÄÕË»§£¬£¬£¬£¬£¬£¬²¢¶ÔÊÜÓ°ÏìµÄÅÌËã»ú¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨ËüÊÇ·ñѬȾÁ˶ñÒâÈí¼þ¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Discord½²»°ÈËûÓлظ´ÖÃÆÀÇëÇ󡣡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-support-agent-got-hacked/


3¡¢Bl00dyÍÅ»ïʹÓÃPaperCut RCEÎó²î¹¥»÷ÃÀ¹ú½ÌÓýÐÐÒµ


¾Ý5ÔÂ11ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBl00dy½üÆÚʹÓÃPaperCut RCE£¨CVE-2023-27350£©¹¥»÷ÃÀ¹úµÄ½ÌÓýÐÐÒµ¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÓÚ4ÔÂÖÐÑ®¾Í×îÏÈʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬ÏÖÔÚ¹¥»÷ÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ʼÓÚ5Ô³õ¡£¡£¡£¡£¡£ ¡£½üÆÚÊӲ쵽µÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²îÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢ÒÔÖÎÀíÔ±Éí·Ý»á¼ûЧÀÍÆ÷¡£¡£¡£¡£¡£ ¡£Ê¹ÓôËȨÏÞÌìÉú¸ßȨÏÞµÄcmd.exeºÍpowershell.exeÀú³Ì£¬£¬£¬£¬£¬£¬»ñµÃ×°±¸µÄÔ¶³Ì»á¼û²¢ºáÏòÈö²¥£¬£¬£¬£¬£¬£¬×îÖջᵼÖÂÊý¾Ýй¶ºÍϵͳ¼ÓÃÜ¡£¡£¡£¡£¡£ ¡£


https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a


4¡¢·¨¹úÂÃÓι«Ë¾La Malle Postaleй¶9ÍòÓû§Ð¡ÎÒ˽¼ÒÐÅÏ¢


5ÔÂ13ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷·¨¹úÂÃÓι«Ë¾La Malle Postaleй¶ÁËÆä¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£ ¡£1ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Cybernews·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄÊý¾Ý´æ´¢£¬£¬£¬£¬£¬£¬´æ´¢ÁËÁè¼Ý4GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨½ü90000¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþºÍµç»°ºÅÂ룬£¬£¬£¬£¬£¬13000¶àÌõ¹«Ë¾Óë¿Í»§Ö®¼äSMSÐÂÎÅ£¬£¬£¬£¬£¬£¬70000¸ö¿Í»§Æ¾Ö¤ÒÔ¼°¹«Ë¾µÄÇý¶¯³ÌÐòºÍÖÎÀíԱƾ֤µÈ¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÊý¾ÝÊý¾Ý¿âÓÚ4ÔÂβ±»±£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£ ¡£


https://securityaffairs.com/146191/data-breach/personal-info-of-90k-hikers-leaked-by-french-tourism-company-la-malle-postale.html


5¡¢Deep InstinctÅû¶LinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú


5ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Deep InstinctÅû¶ÁËLinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú¡£¡£¡£¡£¡£ ¡£BPFDoorÊÇÒ»ÖÖÒþ²ØµÄºóÃÅ£¬£¬£¬£¬£¬£¬´Ó2017Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬µ«Ö±µ½Ò»Äêǰ²ÅÊ״α»·¢Ã÷¡£¡£¡£¡£¡£ ¡£¸ÃбäÌå¾ßÓÐÐí¶àÌØµã£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹Óþ²Ì¬¿â¼ÓÃÜ£¬£¬£¬£¬£¬£¬Ê¹Ó÷´ÏòshellͨѶ£¬£¬£¬£¬£¬£¬ÒÔ¼°ËùÓÐÏÂÁî¾ùÓÉC2ЧÀÍÆ÷·¢ËÍ¡£¡£¡£¡£¡£ ¡£Ê×´ÎÖ´ÐÐʱ£¬£¬£¬£¬£¬£¬BPFDoorÔÚ/var/run/initd.lockÖн¨Éè²¢Ëø¶¨Ò»¸öÔËÐÐʱÎļþ£¬£¬£¬£¬£¬£¬È»ºó½«×Ô¼ºforkΪһ¸ö×ÓÀú³ÌÔËÐС£¡£¡£¡£¡£ ¡£BPFDoorÈÔδ±»Çå¾²Èí¼þ¼ì²âµ½£¬£¬£¬£¬£¬£¬Òò´ËÖÎÀíÔ±Ö»ÄÜÒÀÀµÇ¿Ê¢µÄÍøÂçÁ÷Á¿ºÍÈÕÖ¾¼à¿Ø¡£¡£¡£¡£¡£ ¡£


https://www.deepinstinct.com/blog/bpfdoor-malware-evolves-stealthy-sniffing-backdoor-ups-its-game


6¡¢WordPress²å¼þÖÐÎó²îCVE-2023-32243Ó°ÏìÉϰÙÍòÍøÕ¾


ýÌå5ÔÂ11ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬WordPress²å¼þEssential Addons for ElementorÖÐÎó²î¿É±»Ô¶³Ì¹¥»÷ÓÃÀ´»ñµÃÍøÕ¾µÄÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£ ¡£ÕâÊÇÒ»¸ö°üÀ¨90¸öÀ©Õ¹µÄ¿â£¬£¬£¬£¬£¬£¬±»Áè¼Ý100Íò¸öWordPressÍøÕ¾Ê¹Óᣡ£¡£¡£¡£ ¡£¸ÃÎó²î¸ú×ÙΪCVE-2023-32243£¬£¬£¬£¬£¬£¬ÊDzå¼þÃÜÂëÖØÖù¦Ð§µÄδ¾­Éí·ÝÑéÖ¤µÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬Ó°Ïì°æ±¾5.4.0ÖÁ5.7.1¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬Ö»ÐèÖªµÀÓû§Ãû£¬£¬£¬£¬£¬£¬¾Í¿ÉÒÔÖØÖÃÈκÎÓû§µÄÃÜÂ룬£¬£¬£¬£¬£¬´Ó¶øÖØÖÃÖÎÀíÔ±ÃÜÂë²¢µÇ¼ÕÊ»§¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÐÞ¸´³ÌÐòÒѾ­Ðû²¼£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐÓû§¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£ ¡£


https://securityaffairs.com/146119/hacking/essential-addons-for-elementor-flaw.html