Central TicketsÈ·ÈÏÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íй¶100ÍòÓû§Êý¾Ý

°ä²¼¹¦·ò 2024-10-16
1. Central TicketsÈ·ÈÏÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íй¶100ÍòÓû§Êý¾Ý


10ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Â׶صÄÕÛ¿Û¾çԺƱÎñƽ̨Central Tickets½üÆÚÔâ·êÁËÒ»´Î³Á´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÓ×ÎÒÐÅÏ¢±»µÁ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£Ö»¹Üй¶²úÉúÔÚ7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬µ«¹«Ë¾Ö±µ½9Ô²ÅÒâʶµ½´ËÊ£¬£¬£¬£¬£¬£¬£¬£¬ÆäʱÂ׶ؾ¯Ô±ÌüÔÚ°µÍøÉÏ·¢ÏÖÁ˹ØÓÚ±»µÁÊý¾ÝµÄ»áÉÌ¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í±ðºÅ0xy0um0m£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ2ÈÕ½Ó¼ûÁËCentral TicketsµÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÊÔͼÒÔ3000ÃÀÔªµÄ¼ÛÖµÏúÊÛÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Central TicketsÈ·ÈÏÈëÇÖÓ°ÏìÁËÓÃÓÚ²âÊÔµÄһʱÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âËäÓëÖ÷ϵͳ¸ôÀ룬£¬£¬£¬£¬£¬£¬£¬µ«Ô̺¬Óû§Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ëæºóƾ¾ÝGDPR»®¶¨ÏòÐÅϢרԱ°ì¹«Êһ㱨£¬£¬£¬£¬£¬£¬£¬£¬²¢Á¢¼´Ëø¶¨ÁËÊÜϰȾµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Ç¿ÔìÓû§³ÁÖÃÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬²¢·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓû§ÊýÁ¿Î´Åû¶£¬£¬£¬£¬£¬£¬£¬£¬µ«¹«Ë¾ÖÒ¸æÓû§¿ÉÄÜÒ×ÊÜÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢¶½´ÙËûÃÇά³Ö¾¯Ìè¡£¡£¡£¡£¡£¡£¡£Hackread.com×·×ÙÁ˺ڿͻ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ö¸³öºÚ¿ÍÔÚBreach ForumsÉÏй¶ÁË100Íò¿Í»§µÄÊý¾ÝºÍÄÚ²¿ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×¨¼ÒÆ·ÆÀCentral TicketsÔÚ·¢ÏÖÈëÇÖÊÂÎñ·½Ãæ´æÔÚÑÓ³¤£¬£¬£¬£¬£¬£¬£¬£¬¶½´ÙÆóҵȷ±£Óдëʩʵʱ¼ì²âºÍÓ¦¶ÔÍøÂçÊÂÎñ¡£¡£¡£¡£¡£¡£¡£


https://hackread.com/central-tickets-data-breach-hacker-leaks-user-data/


2. ÀûÓúϷ¨ÊðÃûÖ¤ÊéµÄHijack Loader¼°XWorm¶ñÒâÈí¼þ»î¶¯ÆØ¹â


10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½ÒʾÁËеĶñÒâÈí¼þ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÀûÓúϷ¨´úÂëÊðÃûÖ¤ÊéÊðÃûµÄHijack Loader¹¤¼þ¡£¡£¡£¡£¡£¡£¡£·¨¹úÍøÂ簲ȫ¹«Ë¾HarfangLabÓÚ±¾Ô³õ¼à²âµ½ÕâÒ»Ö¼ÔÚ²¿ÊðÐÅÏ¢ÇÔÈ¡·¨Ê½LummaµÄ¹¥»÷Á´¡£¡£¡£¡£¡£¡£¡£Hijack Loader£¨ÓÖ³ÆDOILoader¡¢IDAT LoaderºÍSHADOWLADDER£©×Ô2023Äê9Ô³õ´ÎÆØ¹â£¬£¬£¬£¬£¬£¬£¬£¬Í¨³£Í¨¹ýÓÕÆ­Óû§ÏÂÔØ´øÓÐÏÝÚåµÄ¶þ½øÔìÎļþÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£½üÆÚ±äÖÖ½«Óû§µ¼ÏòÐéαCAPTCHAÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇó¸´ÔìºÍÔËÐÐPowerShellºÅÁîÒÔ¿ªÊͶñÒâ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£HarfangLab¹Û²ìµ½Èý¸ö·ÖÆç°æ±¾µÄPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°mshta.exe¡¢Invoke-ExpressionºÍmsiexec.exeÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£ZIP´æµµÔ̺¬Ò×ÊÜDLL²à¼ÓÔØÓ°ÏìµÄ¿ÉÖ´ÐÐÎļþºÍ¶ñÒâDLL£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½âÃܲ¢Ö´ÐмÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£ÎªÌӱܼì²â£¬£¬£¬£¬£¬£¬£¬£¬´«ËÍ»úÔìÒÑ´ÓDLL²à¼ÓÔØ×ª±äΪʹÓöà¸öÊðÃû¶þ½øÔìÎļþ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö¤ÊéÏÖÒѱ»³·Ïú¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬´úÂëÊðÃû×ÔÉí²»ÄÜ×÷Ϊ¿ÉÐŶȻù×¼¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬SonicWall Capture LabsÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬CoreWarrior¶ñÒâÈí¼þϰȾWindows»úеµÄÍøÂç¹¥»÷ÊýÁ¿¼¤Ôö£¬£¬£¬£¬£¬£¬£¬£¬¶øÍøÂç´¹µö»î¶¯Ò²Í¨¹ýWindows¾ç±¾Îļþ´«²¼XWorm¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖ°ÄÜ¿í·º¡£¡£¡£¡£¡£¡£¡£

https://thehackernews.com/2024/10/researchers-uncover-hijack-loader.html


3. ¿¨¶û¼ÓÀ﹫¹²Í¼Êé¹ÝÔâÍøÂç¹¥»÷±»ÆÈÏÞ¶È·þÎñ


10ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¿¨¶û¼ÓÀ﹫¹²Í¼Êé¹Ý½üÆÚÒòÔâ·êÍøÂç¹¥»÷¶ø±»ÆÈÏÞ¶È·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˸ÃÊÐ130Íò¾ÓÃñ¡£¡£¡£¡£¡£¡£¡£¸ÃͼÊé¹ÝϵͳռÓÐ22¸ö·ÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÓÚÖÜÎå³õ´Î¹«¿ªÖÒ¸æ³ÆÔâ·êÁË¡°ÍøÂ簲ȫ·ì϶¡±£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö²¿ÃÅϵͳÊܵ½Íþв¡£¡£¡£¡£¡£¡£¡£Í¼Êé¹ÝËæ¼´¹Ø¹ØËùÓзþÎñÆ÷ºÍÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚÖÜÎåÌáǰ¹Ø¹Ý¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÖÜÈý¸÷µØÖ·¸´Ô­ÁËÕý³£¿£¿£¿£¿ £¿£¿£¿£Ê¢¿ª¹¦·ò£¬£¬£¬£¬£¬£¬£¬£¬µ«·þÎñÒѽøÐе÷Õû£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§½öÄÜʹÓ÷Ǽ¼Êõ¼¿Á©µÄͼÊé¹Ý¿Õ¼äºÍ·þÎñ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Í¼Êé¹ÝÕý¾­ÀúÑϳÁµÄ·þÎñÖжϣ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Í¼ÊéËÍ»¹·þÎñ¡¢¼¼ÊõºÍÊý×Ö·þÎñ£¨ÈçÍÆËã»ú½Ó¼û¡¢´òÓ¡¡¢WiFiµÈ£©ÒÔ¼°Êý×ÖͼÊé¹ÝºÍµç×Ó×ÊÔ´¹¤¾ß¾ù²»³ÉÓᣡ£¡£¡£¡£¡£¡£Í¼Êé¹Ýδй©¸´Ô­Õý³£·þÎñµÄ¹¦·ò£¬£¬£¬£¬£¬£¬£¬£¬µ«°µÊ¾µ«Ô¸¾¡¿ì¸´Ô­¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬¼¸ÏîÏÈǰÆÌÅŵĻÈÔ½«³ÖÐø½øÐС£¡£¡£¡£¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬Í¼Êé¹ÝÒòÌṩ³ÁÒª·þÎñ¶ø³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬£¬¼ÓÄôó¶à¸öÖØÒª³ÇÊеÄͼÊé¹ÝϵͳҲÔâ·êÁËÀàËÆ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÊܵ½ÑϳÁÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

https://therecord.media/calgary-public-library-limits-services


4. ¹«¹²Æû³µ¼¯ÍÅÔâ8BaseÀÕË÷Èí¼þ×éÖ¯¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÇÔÈ¡´óÁ¿»úÃÜÐÅÏ¢


10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¹«¹²Æû³µ¼¯ÍŽüÆÚ°ä·¢ÉêÃ÷»ØÓ¦ÁËÒ»Â·ÍøÂç¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪ8BaseµÄÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÒÑ´Ó¸ÃÆû³µÔì×÷É̵ÄϵͳÖÐÇÔÈ¡ÁËÔ̺¬·¢Æ±¡¢ÊÕÌõ¡¢¹ÜÕÊÎļþ¡¢Ó×ÎÒÊý¾Ý¡¢Ö¤Êé¡¢¹ÍÓ¶ºÏͬ¡¢ÈËʵµ°¸µÈÔÚÄڵġ°´óÁ¿»úÃÜÐÅÏ¢¡±¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬¹«¹²Æû³µ½²»°È˰µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¹«¹²Æû³µ¼¯ÍŵÄIT»ù´¡ÉèÊ©²¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬²¢½«³ÖÐøÇ×êǹØ×¢ÊÂ̬·¢Õ¹¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÉÐδй©ÓйØÕâ´ÎÍøÂç¹¥»÷µÄÈÎºÎÆäËûÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü8BaseÀÕË÷Èí¼þ×éÖ¯ÔÚÍøÕ¾Éϰ䲼Á˹«¹²Æû³µµÄÊê½ðÆÚÏÞÒѵ½£¬£¬£¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍËÆºõ²¢Î´¹«¿ªÈκα»µÁÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£8Base×Ô2023ËêÊ×¾ÍÒÑ´æÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Æù½ñΪֹÒѰ䲼ÁË400¶àÃûÊܺ¦ÕßµÄÃû×Ö¡£¡£¡£¡£¡£¡£¡£ÍøÂç·¸×ï·Ö×ÓÒ»µ©»ñµÃÖ¸±ê×é֯ϵͳµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÇÔÈ¡Ãô¸ÐÊý¾Ý²¢ÏòÊܺ¦ÕßʩѹÒÔÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/volkswagen-says-it-infrastructure-not-affected-after-ransomware-gang-claims-data-theft/


5. Google PlayÉϳ¬¹ý200¸ö¶ñÒâÀûÓÃÏÂÔØÁ¿½ü800Íò


10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ZscalerµÄÍþвµý±¨×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2023Äê6ÔÂÖÁ2024Äê4ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬£¬Android¹Ù·½É̵êGoogle Play·Ö·¢Á˳¬¹ý200¸ö¶ñÒâÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÀÛ¼ÆÏÂÔØÁ¿¿¿½ü800Íò´Î¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þÔ̺¬ÐÅÏ¢ÇÔÈ¡ÕßJoker¡¢¸æ°×Èí¼þ¡¢FacebookÕÊ»§Æ¾Ö¤ÇÔÈ¡·¨Ê½Facestealer¡¢ÐÅÏ¢ÇÔÈ¡ºÍ¶ÌÐÅÀ¹½Ø·¨Ê½CoperµÈ¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹È¸èÕ¼Óмì²â¶ñÒâÀûÓ÷¨Ê½µÄ°²È«»úÔ죬£¬£¬£¬£¬£¬£¬£¬µ«ÍþвÐÐΪÕßÈÔʹÓÃһЩ¼¼ÇÉÈÆ¹ýÑéÖ¤¹ý³Ì¡£¡£¡£¡£¡£¡£¡£ZscalerµÄ»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬½üÒ»°ë¶ñÒâÀûÓ÷¨Ê½ÊÇÔÚGoogle PlayµÄ¹¤¾ß¡¢¸öÐÔ»¯¡¢ÉãÓ°¡¢³ö²úÁ¦ºÍÉúÑÄ·½Ê½Àà±ðϰ䲼µÄ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬È¥ÄêGoogle PlayÉÏÒ²³öÏÖÁËÆäËû¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçNecro¡¢GoldosonºÍSpyLoanµÈ£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄÏÂÔØÁ¿±ðÀë´ïµ½1100Íò´Î¡¢1Òڴκͳ¬¹ý1200Íò´Î¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¶ÈÊÇÓ¡¶ÈºÍÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬½ÌÓýÐÐÒµ³ÉÎªÖØÒª¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£¡£¡£ÎªÁËÏ÷¼õ±»Google Play¶ñÒâÈí¼þϰȾµÄ»úÓö£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÔĶÁÆÀÂÛ¡¢²é³­ÀûÓ÷¨Ê½°ä²¼ÕßÒÔ¼°×°ÖÃʱҪÇóµÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-200-malicious-apps-on-google-play-downloaded-millions-of-times/


6. WordPress Jetpack ²å¼þÑϳÁ·ì϶ӰÏì2700Íò¸öÍøÕ¾


10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬WordPress Jetpack²å¼þ½üÈÕ°ä²¼ÁËÒ»Ïî¹Ø¼ü¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸ö×Ô2016ÄêÒÔÀ´Ò»Ïò´æÔÚµÄÑϳÁ·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ²å¼þµÄÁªÏµ±íµ¥Ö°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÔÊÐíÈκεÇÂ¼ÍøÕ¾µÄÓû§²é¿´Í³Ò»ÍøÕ¾ÉÏÆäËûÈËÌá½»µÄ±íµ¥¡£¡£¡£¡£¡£¡£¡£JetpackÊÇÒ»¿îÊ¢ÐеÄWordPress²å¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉWordPress.com±³ºóµÄ¹«Ë¾Automattic¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬ÌṩÁËһϵÁÐÖ°ÄÜÀ´¼ÓÇ¿ÍøÕ¾µÄÖ°ÄÜ¡¢°²È«ÐԺͻúÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Òѱ»2700Íò¸öWordPressÍøÕ¾Ê¹Óᣡ£¡£¡£¡£¡£¡£¹ÌÈ»ÊØ»¤ÈËÔ±²¢Î´·¢Ïָ÷ì϶Òѱ»Ò°±í¹¥»÷ÀûÓõÄÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬µ«ÈÔ¶½´ÙÓû§¾¡¿ì¸üÐÂÖÁ×îа汾13.9.1£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÍøÕ¾µÄ°²È«¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÍøÕ¾ÒѾ­»ò¼´½«×Ô¶¯¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£JetpackÍŶӶÔÕâ´Î¸øÓû§´øÀ´µÄ²»±ã°µÊ¾Ç¸Ò⣬£¬£¬£¬£¬£¬£¬£¬²¢³Ðŵ½«³ÖÐø¶¨ÆÚÉóºË´úÂë¿â£¬£¬£¬£¬£¬£¬£¬£¬È·±£Óû§ÍøÕ¾µÄ°²È«¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/169848/uncategorized/wordpress-jetpack-plugin-critical-flaw.html