DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾­ÏúÉÌ

Ðû²¼Ê±¼ä 2025-12-04

1. DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾­ÏúÉÌ


12ÔÂ2ÈÕ£¬ £¬£¬ÃÀ¹ú×î´óCricket WirelessÊÚȨ¾­ÏúÉÌMobilelink USAÔâÓë¶íÂÞ˹¹ØÁªµÄÀÕË÷Èí¼þ×éÖ¯DragonForce¹¥»÷£¬ £¬£¬¸Ã×éÖ¯Ðû³ÆÇÔÈ¡³¬5TBÊý¾Ý²¢ÉèÖõ¹¼ÆÊ±Íþв¡£¡£¡£¡£¡£¡£DragonForceÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû²¼Mobilelink±ê¼Ç¼°¶à¼ÒÊܺ¦Õß±êʶ£¬ £¬£¬ÒªÇóÆäÔÚÔ¼6Ìì16СʱÄÚÖª×ãÀÕË÷ÒªÇó£¬ £¬£¬²»È»½«¹ûÕæ±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£Mobilelink×÷Ϊ¿ìËÙÀ©ÕŵĵçÐÅÔËÓªÉÌ£¬ £¬£¬ÔÚÃÀ¹ú21¸öÖÝÔËÓª550¼ÒÁãÊ۵꣬ £¬£¬ÓµÓÐ650ÓàÃûÔ±¹¤£¬ £¬£¬×¨ÃÅÌṩÎÞºÏÔ¼5G LTEЧÀÍ¡¢Ô¤¸¶·ÑÌײͼ°ÊÖ»úÅä¼þ¡£¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶¿ÉÄܲ¨¼°Cricketĸ¹«Ë¾AT&TµÄ1300Íò¿Í»§ÈºÌ壬 £¬£¬µ¼ÖÂÊý°ÙÍòÃô¸ÐСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©¼°²ÆÎñÊý¾Ýй¶£¬ £¬£¬Ê¹ÊÜÓ°ÏìÓû§ÃæÁÙÉí·Ý͵ÇÔ¡¢ÍøÂç´¹ÂÚ¹¥»÷µÈΣº¦¡£¡£¡£¡£¡£¡£DragonForceÊÇ2025Äê×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò»£¬ £¬£¬¾ÝCybernews°µÍø¼à¿Ø¹¤¾ßÏÔʾ£¬ £¬£¬¸Ã×éÖ¯2025ÄêÒѹ¥»÷185¸ö×éÖ¯£¬ £¬£¬ÆäÖÐ130´Î±¬·¢ÔÚ½üÁù¸öÔ¡£¡£¡£¡£¡£¡£


https://cybernews.com/news/cricket-wireless-mobilelink-usa-ransomware-attack-dragonforce/


2. MarquisÈí¼þÊý¾Ýй¶ÊÂÎñ²¨¼°40Íò½ðÈÚ¿Í»§


12ÔÂ3ÈÕ£¬ £¬£¬½üÆÚ£¬ £¬£¬Îª700Óà¼ÒÒøÐС¢ÐÅÓÃÉç¼°µäÖÊ´û¿î»ú¹¹ÌṩÊý¾ÝÆÊÎö¡¢CRM¹¤¾ßµÈЧÀ͵ĽðÈÚÈí¼þ¹©Ó¦ÉÌMarquis Software SolutionsÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬µ¼ÖÂÃÀ¹ú74¼Ò½ðÈÚ»ú¹¹µÄ40ÓàÍò¿Í»§Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¹¥»÷ͨ¹ý±£´æÎó²îµÄSonicWall·À»ðǽÈëÇÖϵͳ£¬ £¬£¬ºÚ¿ÍÇÔÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢Éç»á°ü¹ÜºÅÂë¡¢ÄÉ˰ÈËʶÓÖÃûÂë¡¢ÎÞÇå¾²ÂëµÄ½ðÈÚÕË»§ÐÅÏ¢¼°³öÉúÈÕÆÚµÈÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£ÊÂÎñÓ°Ïì¹æÄ£ÁýÕÖÃåÒò¡¢°®ºÉ»ª¡¢µÂ¿ËÈøË¹µÈ¶àÖÝ£¬ £¬£¬Éæ¼°±±¼ÓÖݵÚÒ»ÐÅÓÃÉç¡¢±´¶ûΤɪÉçÇøÐÅÓÃÉç¡¢Gateway First BankµÈ74¼Ò»ú¹¹¡£¡£¡£¡£¡£¡£MarquisÔÚ֪ͨÖÐÇ¿µ÷£¬ £¬£¬ÏÖÔÚÎÞÖ¤¾ÝÏÔʾÊý¾Ý±»ÀÄÓûò¹ûÕæÐû²¼£¬ £¬£¬µ«ÒÑ´ú±í¿Í»§Ïò¸÷ÖÝÌá½»Ïêϸй¶±¨¸æ£¬ £¬£¬²¿·ÖÖÝÎļþϸ·ÖÁËÊÜÓ°Ïì¿Í»§ÊýÄ¿¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ £¬£¬Community 1stÐÅÓÃÉçÒÑɾ³ýµÄÎļþÏÔʾ£¬ £¬£¬MarquisÔøÖ§¸¶Êê½ðÒÔ×èÖ¹Êý¾Ýй¶£¬ £¬£¬¶øCoVantage Credit UnionµÄÎļþÔòÅû¶ÁËMarquisÔöÇ¿Çå¾²µÄÏêϸ²½·¥£º¸üзÀ»ðǽ²¹¶¡¡¢ÂÖ»»ÍâµØÕË»§ÃÜÂ롢ɾ³ýÈßÓàÕË»§¡¢ÆôÓöàÒòËØÈÏÖ¤¡¢ÑÓÉìÈÕÖ¾Áô´æÊ±¼ä¡¢ÊµÑéÕË»§Ëø¶¨Õ½ÂÔ¡¢ÏÞÖÆÅþÁ¬ÈªÔ´¹ú±ð¼°×Ô¶¯·â±Õ½©Ê¬ÍøÂçIP¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/marquis-data-breach-impacts-over-74-us-banks-credit-unions/


3. WordPress²å¼þ¸ßΣÎó²îÒý·¢´ó¹æÄ£¹¥»÷


12ÔÂ3ÈÕ£¬ £¬£¬¿ËÈÕ£¬ £¬£¬WordPressƽ̨Á½¿îÈÈÃŲå¼þ½ÓÁ¬Ì»Â¶ÑÏÖØÇå¾²Îó²î£¬ £¬£¬Òý·¢È«Çò³¬4.8Íò´Î¹¥»÷ʵÑé¡£¡£¡£¡£¡£¡£King Addons for Elementor²å¼þµÄCVE-2025-8489Îó²îÔÊÐí¹¥»÷ÕßÖ±½Ó»ñÈ¡ÍøÕ¾ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÚ2025Äê10ÔÂ31ÈÕ¹ûÕæºó£¬ £¬£¬WordfenceÇ徲ɨÃèÆ÷ÒÑ×èµ²48400Óà´Î¹¥»÷£¬ £¬£¬ÆäÖÐ11ÔÂ9ÈÕÖÁ10ÈÕµÖ´ïá¯Á룬 £¬£¬Á½¸ö»îÔ¾IPµØµã»®·ÖÌᳫ28900´ÎºÍ16900´ÎʵÑé¡£¡£¡£¡£¡£¡£Ô¼10000¸öʹÓøòå¼þµÄÍøÕ¾ÃæÁÙΣº¦£¬ £¬£¬½¨ÒéÁ¬Ã¦Éý¼¶ÖÁ51.1.35°æ±¾ÐÞ¸´¡£¡£¡£¡£¡£¡£Í¬ÆÚ£¬ £¬£¬Advanced Custom Fields: Extended²å¼þµÄCVE-2025-13486Îó²îÒàÒý·¢¹Ø×¢¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚ0.9.0.5ÖÁ0.9.1.1°æ±¾ÖУ¬ £¬£¬Óɲ¨À¼CERTÈÏÕæÈËMarcin Dudek·¢Ã÷²¢±¨¸æ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÔÚδÈÏÖ¤ÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂ룬 £¬£¬¿ÉÄÜÓÃÓÚ×¢ÈëºóÃÅ»ò½¨Éè¶ñÒâÖÎÀíÔ±ÕË»§¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÚ11ÔÂ18ÈÕÅû¶ºó£¬ £¬£¬¹©Ó¦ÉÌÔ½ÈÕ¼´Ðû²¼0.9.2°æ±¾ÐÞ¸´£¬ £¬£¬µ«¼øÓÚÊÖÒÕϸ½ÚÒѹûÕæ£¬ £¬£¬×¨¼ÒÖÒÑÔ¿ÉÄÜÒý·¢ÐÂÒ»ÂÖ¶ñÒâ¹¥»÷¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/critical-flaw-in-wordpress-add-on-for-elementor-exploited-in-attacks/


4. ·¨¹úÀÖ»ªÃ·À¼Åû¶Êý¾Ýй¶ÊÂÎñ


12ÔÂ3ÈÕ£¬ £¬£¬·¨¹ú¼Ò¾Ó½¨²ÄÓëÔ°ÒÕÁãÊÛ¾ÞÍ·ÀÖ»ªÃ·À¼£¨Leroy Merlin£©¿ËÈÕ֪ͨ¿Í»§£¬ £¬£¬Æä²¿·ÖСÎÒ˽¼ÒÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖÐÔâÍⲿй¶¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓªÒµÁýÕÖÅ·ÖÞ¶à¹ú¼°ÄÏ·Ç¡¢°ÍÎ÷£¬ £¬£¬ÓµÓÐ16.5ÍòÃûÔ±¹¤£¬ £¬£¬ÄêÊÕÈë´ï99ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ½öÓ°Ïì·¨¹ú¿Í»§£¬ £¬£¬Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢ÓÊÕþµØµã¡¢³öÉúÈÕÆÚ¼°»áÔ±ÍýÏëÏà¹ØÐÅÏ¢£¬ £¬£¬µ«²»Éæ¼°ÒøÐÐÕË»§ÃÜÂë»òÍøÉÏÕË»§Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ÀÖ»ªÃ·À¼ÔÚ֪ͨÖÐÇ¿µ÷£¬ £¬£¬ÊÂÎñ±¬·¢ºóÒÑÁ¬Ã¦½ÓÄɲ½·¥×èֹδ¾­ÊÚȨ»á¼û²¢¿ØÖÆÊÂ̬Éú³¤¡£¡£¡£¡£¡£¡£Ö»¹ÜÄ¿½ñÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢±»¶ñÒâʹÓûòÓÃÓÚÀÕË÷£¬ £¬£¬¹«Ë¾ÈÔÌáÐѿͻ§Ð¡ÐÄÍøÂç´¹ÂÚ¹¥»÷£¬ £¬£¬²¢ÌṩÁËʶ±ð·ÂÃ°Æ·ÅÆ´¹ÂÚÐÅÏ¢µÄÒªÁì¡£¡£¡£¡£¡£¡£Èô¿Í»§·¢Ã÷ÕË»§Òì³£»£»£»£»î¶¯»ò»áÔ±ÕÛ¿Û¶Ò»»ÎÊÌ⣬ £¬£¬¿ÉÖ±½ÓÏò¹«Ë¾±¨¸æ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬ÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/french-diy-retail-giant-leroy-merlin-discloses-a-data-breach/


5. Freedom MobileÅû¶Êý¾Ýй¶ÊÂÎñ


12ÔÂ3ÈÕ£¬ £¬£¬¼ÓÄôóµÚËÄ´óÎÞÏßÔËÓªÉÌFreedom Mobile¿ËÈÕÅûÂ¶ÖØ´óÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÉGlobaliveÓÚ2008Ä꽨É裬 £¬£¬Ô­ÃûΪWind Mobile£¬ £¬£¬2023Äê±»¿ý±±¿ËµçÐÅ×Ó¹«Ë¾Vid¨¦otronÊÕ¹ººó£¬ £¬£¬ÐγÉÓµÓг¬350ÍòÒÆ¶¯Óû§¡¢½ü7500ÃûÔ±¹¤¼°ÁýÕÖ99%¼ÓÄôóÈ˵ÄЧÀÍÍøÂç¡£¡£¡£¡£¡£¡£±¾´ÎÊÂÎñ±¬·¢ÓÚ2025Äê10ÔÂ23ÈÕ£¬ £¬£¬¹¥»÷Õß̫ͨ¹ý°üÉ̱»µÁÕË»§ÈëÇÖ¿Í»§ÕË»§ÖÎÀíÆ½Ì¨£¬ £¬£¬ÇÔÈ¡Á˲¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬ £¬£¬Ïêϸ°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢ÊÖ»úºÅÂë¼°Freedom MobileÕË»§ºÅÂë¡£¡£¡£¡£¡£¡£¹«Ë¾ÉùÏÔ×Åʾ£¬ £¬£¬ÊÂÎñ±¬·¢ºó£¬ £¬£¬FreedomѸËÙ½ÓÄÉÐж¯£¬ £¬£¬ÆÁÕÏ¿ÉÒÉÕË»§¼°¶ÔÓ¦IPµØµã£¬ £¬£¬²¢ÔöÇ¿Çå¾²²½·¥¡£¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚÎÞÖ¤¾ÝÅúעй¶Êý¾ÝÒѱ»ÀÄÓ㬠£¬£¬µ«ÔËÓªÉÌÈÔ½¨ÒéÊÜÓ°Ïì¿Í»§Ð¡ÐÄ´¹ÂÚ¹¥»÷£¬ £¬£¬×èÖ¹µã»÷¿ÉÒÉÁ´½Ó»òÏÂÔØ¸½¼þ£¬ £¬£¬²¢°´ÆÚ¼ì²éÕË»§Òì³£»£»£»£»î¶¯¡£¡£¡£¡£¡£¡£Freedom Mobile½²»°ÈËÇ¿µ÷£¬ £¬£¬´Ë´ÎÊÂÎñ䲨¼°ÍøÂçºÍÔËӪϵͳ£¬ £¬£¬²»ÊôÓÚÀÕË÷Èí¼þ¹¥»÷ÀàÐÍ£¬ £¬£¬µ«Î´Í¸Â¶ÏêϸÊÜÓ°Ïì¿Í»§ÊýÄ¿¡£¡£¡£¡£¡£¡£×÷Ϊ¼ÓÄôóÖ÷ÒªµçÐÅЧÀÍÉÌ£¬ £¬£¬FreedomµÄÊý¾Ýй¶¿ÉÄÜÒý·¢¿Í»§ÐÅÈÎΣ»£»£»£»ú¼°î¿ÏµÉó²é¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/freedom-mobile-discloses-data-breach-exposing-customer-data/


6. ·ï»Ë³Ç´óѧÓöClop¹¥»÷ÖÂʦÉúÊý¾Ýй¶


12ÔÂ3ÈÕ£¬ £¬£¬ÃÀ¹ú·ï»Ë³Ç´óѧ£¨UoPX£©8Ô³ÉΪClopÀÕË÷Èí¼þÍÅ»ïʹÓÃOracle E-Business Suite£¨EBS£©ÁãÈÕÎó²î£¨CVE-2025-61882£©¹¥»÷µÄÄ¿µÄ£¬ £¬£¬µ¼Ö´ó×ÚÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£ÕâËù½¨ÉèÓÚ1976ÄêµÄ˽Á¢ÓªÀûÐÔ´óѧӵÓнü3000Ãû½ÌÖ°Ô±¹¤ºÍ³¬10ÍòÔÚУѧÉú£¬ £¬£¬Æäĸ¹«Ë¾Phoenix Education PartnersÒÑÏòÃÀ¹ú֤ȯÉúÒâίԱ»áÌá½»8-K±í¸ñÅû¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýOracle EBS²ÆÎñÓ¦ÓóÌÐòµÄÎó²îÇÔÈ¡ÁËÏÖÈμ°Ç°ÈÎѧÉú¡¢½ÌÖ°¹¤¡¢¹©Ó¦É̵ÄÐÕÃû¡¢ÁªÏµ·½·¨¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂë¡¢ÒøÐÐÕË»§¼°Â·ÓɺÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÔÚClop½«ÆäÁÐÈëÊý¾ÝÐ¹Â¶ÍøÕ¾ºó£¬ £¬£¬UoPXÓÚ11ÔÂ21ÈÕ·¢Ã÷ÊÂÎñ£¬ £¬£¬²¢ÌåÏÖ½«Éó²éÊÜÓ°ÏìÊý¾Ý£¬ £¬£¬Í¨¹ýÃÀ¹úÓÊÕþÏòÊÜÓ°ÏìСÎÒ˽¼Ò¼ÄËÍ֪ͨ£¬ £¬£¬Í¬Ê±Ïòî¿Ïµ»ú¹¹±¨¸æ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬Ñ§Ð£Î´Í¸Â¶ÏêϸÊÜÓ°ÏìÈËÊý¼°Ä»ºóºÚÊÖ£¬ £¬£¬µ«¹ûÕæÐÅÏ¢Ö¸ÏòClopÍŻ¡£¡£¡£¡£¡£·ï»Ë³Ç´óѧǿµ÷ÒѽÓÄɲ½·¥×èֹΣº¦£¬ £¬£¬µ«Î´²¨¼°½¹µãÍøÂçÔËÓª¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/university-of-phoenix-discloses-data-breach-after-oracle-hack/