Wordfence·¢ÏÖÕë¶Ô160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷
°ä²¼¹¦·ò 2021-12-14
12ÔÂ10ÈÕ£¬ÈðµäÆû³µÔì×÷ÉÌÎÖ¶ûÎÖ³ÆÆä·þÎñÆ÷Ôâµ½ÀÕË÷¹¥»÷£¬²¿ÃÅÑз¢Êý¾ÝÒѾй¶¡£ÎÖ¶ûÎÖ°µÊ¾£¬Ä¿Ç°ÔÚ¶Ô´ËÊ·¢Õ¹µ÷²é£¬¿Í»§µÄÓ×ÎÒÊý¾Ý²¢²»»áÊܵ½Ó°Ï죬µ«¹«Ë¾µÄÔËÓª¿ÉÄÜÊܵ½Ó°Ïì¡£¹ÌÈ»¸Ã¹«Ë¾ÉÐδй©ÓйØÕâ´ÎÊÂÎñµÄÆäËüϸ½Ú£¬µ«ÀÕË÷ÔËÓªÍÅ»ïSnatchÒÑÓÚ11ÔÂ30ÈÕ½«¸Ã¹«Ë¾Ôö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾µÄĿ¼ÖУ¬²¢¹«¿ªÁ˱»µÁÎļþµÄ½ØÍ¼ºÍ35.9 MBµÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/volvo-cars-discloses-security-breach-leading-to-randd-data-theft/
Wordfence·¢ÏÖÕë¶Ô160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷

WordfenceÔÚ12ÔÂ9ÈÕ¹«¿ªÁ˽üÆÚÕë¶Ô³¬¹ý160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷»î¶¯¡£ÕâЩ¹¥»÷ÖØÒªÕë¶Ô4¸ö²å¼þ£¨PublishPress CapabilitiesºÍKiwi Social PluginµÈ£©ºÍ15¸öEpsilon¿ò¼ÜÖ÷Ì⣨ShapelyºÍNatureMag LiteµÈ£©¡£Í¨¹ýÆôÓÃusers_can_registerÑ¡Ï²¢½«default_roleÑ¡ÏîÉèÖÃΪÖÎÀíÔ±£¬¹¥»÷Õß¾ÍÄܹ»×¢²áΪÖÎÀíÔ±²¢ÊÕÊܸÃÍøÕ¾¡£×êÑÐÈËÔ±½¨ÒéÓû§µ±¼´¸üÐÂÊÜÓ°Ïì²å¼þ£¬ÆäÖÐNatureMag LiteûÓпÉÓò¹¶¡£¬±ØÒªµ±¼´Ð¶ÔØ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125469/hacking/wordpress-sites-under-attack.html
Frontier Softwareй¶Լ8Íò¸ö°Ä´óÀûÑǹ«ÃñµÄÐÅÏ¢

ÄϰĴóÀûÑÇÖݵ±¾ÖÔÚ12ÔÂ10ÈÕ°ä²¼²¼¸æ£¬³ÆÆäÔ¼8Íò¸öÔ±¹¤µÄÐÅÏ¢ÒѾй¶¡£Õâ´Îй¶ÊÂÎñµÄÔÒòÊÇн×ÊÈí¼þ¹«Ë¾Frontier SoftwareÓÚ11ÔÂ13ÈÕÔâµ½ÀÕË÷¹¥»÷£¬¸Ã»î¶¯¿ÉÄÜÓëContiÓйء£11ÔÂ16ÈÕ£¬ContiÔøÔÚÆäÍøÕ¾ÁгöÁËFrontier Software£¬µ«ÊǴ˿̸ÃÁбíÒѱ»É¾³ý£¬Õâ¿ÉÄÜÒâζ׎»ÉæÒѾʵÏÖ¡£¸ÃÖÝΨһûÓÐÊܵ½Ó°ÏìµÄ¹«¹²×éÖ¯ÊǽÌÓý²¿£¬ÓÉÓÚËü²»Ê¹ÓÃFrontierµÄ²úÆ·¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/data-breach-impacts-80-000-south-australian-govt-employees/
Cofense·¢ÏÖÕë¶ÔµÂ¹ú½ðÈÚÐÐÒµµÄÐÂÒ»ÂÖ´¹µö»î¶¯

12ÔÂ9ÈÕ£¬Cofense·¢´Ë¿Ì´Óǰ¼¸ÖÜÖУ¬ÀûÓöþάÂëÕë¶ÔµÂ¹ú½ðÈÚÐÐÒµµÄÐÂÒ»ÂÖ´¹µö»î¶¯¡£Õâ´Î»î¶¯Ê¹ÓõÄÓʼþÖв¢Ã»ÓÐÃ÷ÎÄURL£¬¶øÊÇͨ¹ýQRÂ뽫Óû§³Á¶¨Ïòµ½´¹µöÍøÕ¾£¬ÒÔÈÆ¹ý°²È«Èí¼þµÄ¼ì²â¡£ÓÉÓÚQRÂëµÄÖ¸±êÊÇÒÆ¶¯Óû§£¬ÕâЩÓû§ºÜÉÙÊܵ½°²È«¹¤¾ßµÄ±£»¤£¬ÕâÌá¸ßÁ˹¥»÷µÄÓÐЧÐÔ¡£¹¥»÷³É¹¦ºó£¬±ã»áÇÔȡָ±êµÄÒøÐеØÖ·¡¢´úÂë¡¢Óû§ÃûºÍPINµÈÐÅÏ¢£¬ÖØÒªÕë¶ÔµÄÁ½¸ö½ðÈÚ»ú¹¹ÊÇSparkasseºÍVolksbanken Raiffeisenbanken¡£
ÔÎÄÁ´½Ó£º
https://cofense.com/blog/german-users-targeted-in-digital-bank-heist-phishing-campaigns/
×êÑÐÍŶӷ¢ÏÖÀûÓÃLog4Shell·ì϶·Ö·¢¶à¸ö¶ñÒâÈí¼þµÄ»î¶¯

12ÔÂ12ÈÕ£¬×êÑÐÍŶӷ¢ÏÖÀûÓÃApache Log4jÖеķì϶Log4Shell·Ö·¢¶àÖÖ¶ñÒâÈí¼þµÄ»î¶¯¡£Log4ShellÓÚÉÏÖÜÎ幫¿ª£¬ApacheÔÚ²»¾ÃÖ®ºó°ä²¼ÁËLog4j 2.15.0À´½¨¸´¸Ã·ì϶¡£¸Ã·ì϶ÒѾ°ä²¼£¬¾ÍÓкö๥»÷ÕßÀûÓÃÆä×°Öø÷Àà¿ó¹¤Èí¼þ£¬ÀýÈçºóÃÅKinsingºÍ½©Ê¬ÍøÂçcryptomining±³ºóµÄ¹¥»÷Õß¡£»¹Óй¥»÷ÕßÀûÓø÷ì϶ÔÚÖ¸±êÉ豸ÉÏ×°ÖöñÒâÈí¼þMiraiºÍMuhstik¡£³ýÁË×°ÖöñÒâÈí¼þÖ®±í£¬×êÑÐÈËÔ±»¹·¢ÏÖÁËÕë¶Ô¸Ã·ì϶µÄ´ó¹æÄ£É¨Ãè»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-start-pushing-malware-in-worldwide-log4shell-attacks/
Î÷²¿Êý¾Ý°ä²¼¸üн¨¸´SanDisk SecureAccessÖзì϶

Western DigitalÔÚÉÏÖÜÈý°ä²¼°²È«¸üУ¬½¨¸´SanDisk SecureAccessÖеķì϶CVE-2021-36750¡£SanDisk SecureAccess£¨´Ë¿Ì¸ÄÃûΪSanDisk PrivateAccess£©ÓÃÀ´ÔÚSanDisk USBÉÁ´æÇý¶¯Æ÷ÉÏ´æ´¢ºÍ±£»¤³ÁÒªÎļþ£¬ÆäʹÓÃÁ˵¥Ïò¼ÓÃÜhashºÍ¿ÉÔ¤²âsalt£¬ÕâʹÆäÈÝÒ×Ôâµ½×ֵ乥»÷£»»¹Ê¹ÓÃÁËÍÆËãÁ¿²»¼°µÄhash£¬Ê¹Óû§ÃÜÂëÒ×±»±©Á¦ÆÆ½â¡£¹«Ë¾³ÆÕâЩÎÊÌâÒѾͨ¹ýʹÓÃPBKDF2-SHA256ºÍËæ»úsalt½¨¸´£¬½¨ÒéÓû§µ±¼´¸üС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125530/security/western-digital-sandisk-secureaccess-flaws.html


¾©¹«Íø°²±¸11010802024551ºÅ