iHeartMediaÆìϵç̨ÓöÍøÂçÈëÇÖ£¬Ãô¸ÐÊý¾Ý±íй
°ä²¼¹¦·ò 2025-05-081. iHeartMediaÆìϵç̨ÓöÍøÂçÈëÇÖ£¬Ãô¸ÐÊý¾Ý±íй
5ÔÂ6ÈÕ£¬ÃÀ¹ú×î´óÒôƵ´«Ã½¼¯ÍÅiHeartMediaÅû¶£¬ÆäÆì϶à¼Ò¹ã²¥µç̨ÓÚÈ¥Äê12ÔÂÔâ·êÍøÂçÈëÇÖ£¬Ôì³ÉÔ±¹¤Ãô¸ÐÊý¾Ý±íй¡£ÕâЩÊý¾Ýº¸ÇÔ±¹¤Éç»á°²È«ºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢¡¢Ë°ºÅ¡¢¼ÝÕÕ/»¤ÕÕºÅÂë¡¢½¡È«±£ÏÕ×ÊÁϼ°Ö§¸¶¿¨ºÅµÈ¡£Ö»¹ÜiHeartMediaÒÑÏòÃåÒòÖÝ¡¢ÂíÈøÖîÈûÖÝÓë¼ÓÀû¸£ÄáÑÇÖÝÌá½»Êý¾Ýй¶»ã±¨£¬µ«»Ø¾øÐ¹Â©ÊÜÓ°ÏìÈËÊý¼°Ôâ¹¥»÷µç̨ÊýÁ¿¡£iHeartMedia½²»°È˰µÊ¾£¬ÔÚ·¢ÏÖÉÙÊý´¦Ëùµç̨²¿ÃÅϵͳ´æÔÚÒì³£»î¶¯ºó£¬¹«Ë¾µ±¼´²ÉÈ¡´ëÊ©×è¶ÏÈëÇÖ£¬Æô¶¯ÊÂÎñÏìÓ¦Á÷³Ì£¬²¢ÀñƸµÚÈý·½ÍøÂ簲ȫ¹«Ë¾ÐÖúµ÷²é£¬Í¬Ê±ÒÑÏò·¨Âɲ¿ÃÅ´«µÝ¡£Ð¹Â¶Í¨ÖªÎļþÏÔʾ£¬¹¥»÷ÕßÔÚ12ÔÂ24ÈÕÖÁ27ÈÕÆÚ¼äÇÖÈ빫˾ϵͳ£¬½Ó¼û²¢ÇÔÈ¡ÁË´æ´¢ÓÚ´¦Ëùµç̨µÄÃô¸ÐÎļþ¡£¾¹ý³ÖÐøÖÁ½ñÄê4ÔÂ11Èյĵ÷²é£¬±íйÊý¾ÝµÃµ½È·ÈÏ¡£Îª±£»¤ÊÜÓ°ÏìÔ±¹¤È¨Àû£¬iHeartMedia½«ÎªÆäÌṩһÄêÆÚÉí·Ý±£»¤·þÎñ£¬²¢¿ªÃ÷רÉèµç»°ÈÈÏß¹©Ô±¹¤Õ÷ѯ¡£²»Í⣬ÔÚÌá½»¸øÃåÒòÖݵĻ㱨ÖУ¬iHeartMedia¿ÌÒâÒþÈ¥ÁËÊܺ¦Õß×ÜÊýͳ¼ÆÏĿǰ£¬ÉÐÎÞºÚ¿Í×éÖ¯Ðû³Æ¶Ô´ËÊÂÎñÕÆ¹Ü¡£
https://therecord.media/iheart-radio-stations-breached-december
2. LockBitÀÕË÷Èí¼þÍÅ»ïÔâºÚ¿Í¹¥»÷£¬Êܺ¦Õß½»Éæ¼ÍÂ¼ÆØ¹â
5ÔÂ7ÈÕ£¬LockBitÀÕË÷Èí¼þÍÅ»ïÔâ·êÊý¾Ýй¶ÊÂÎñ£¬Æä°µÍø´ÓÊôÃæ°å±»·ÛË飬²¢±»´úÌæÎªÖ¸ÏòMySQLÊý¾Ý¿âת´¢µÄÁ´½ÓÐÂÎÅ¡£Ä¿Ç°£¬¸ÃÍÅ»ïËùÓÐÖÎÀíÃæ°å¾ùÏÔʾ¡°²»Òª·¸×·¸×ïÊÇ»µÊ£¬À´×Ô²¼À¸ñµÄxoxo¡±×ÖÑù£¬²¢¸½ÓÐÏÂÔØ¡°paneldb_dump.zip¡±µÄÁ´½Ó¡£¸Ãµµ°¸Ô̺¬´ÓÍøÕ¾´ÓÊôÃæ°åMySQLÊý¾Ý¿âת´¢µÄSQLÎļþ£¬¾ÝBleepingComputer·ÖÎö£¬Êý¾Ý¿âº¬20¸ö±í£¬²¿ÃűíÐÅÏ¢ÆÄ¾ß¼ÛÖµ¡£Èç¡°btc_addresses¡±±íº¬59975¸öΨһ±ÈÌØ±ÒµØÖ·£»¡°builds¡±±íÔ̺¬¹ØÁª·½Îª¹¥»÷´´½¨µÄ¹¹½¨¼°²¿ÃÅÖ¸±ê¹«Ë¾Ãû³Æ£»¡°builds_configurations¡±±íº¬¸÷¹¹½¨Ê¹ÓõÄÅäÖ㻡°Ì¸Ì족±í¼Í¼ÁËÀÕË÷Èí¼þ²Ù×÷ÓëÊܺ¦Õß¼ä4442Ìõ½»ÉæÐÂÎÅ£»¡°Óû§¡±±íÁгöÁË75λÓÐȨ½Ó¼ûͬÃËÃæ°åµÄÖÎÀíÔ±ºÍͬÃË»áÔ±£¬ÇÒÃÜÂëÒÔÃ÷ÎÄ´ó¾Ö´æ´¢£¬Ê¾ÀýÔ̺¬¡°Weekendlover69¡±µÈ¡£LockBitÔËÓªÉÌ¡°LockBitSupp¡±Ö¤ÊµÁËÕâ´ÎйÃÜÊÂÎñ£¬µ«³ÆÎÞ˽Կй¶»òÊý¾ÝÃÔʧ¡£Æ¾¾ÝMySQLת´¢ÌìÉú¹¦·òºÍ½»ÉæÌ¸Ìì±í×îºóÈÕÆÚ¼Í¼£¬Êý¾Ý¿âËÆÔÚ2025Äê4ÔÂ29ÈÕ±»×ª´¢¡£Ä¿Ç°¹¥»÷ÕßÉí·Ý¼°¹¥»÷·½Ê½Éв»Ã÷È·£¬µ«±»·ÛËéÐÅÏ¢ÓëEverestÀÕË÷Èí¼þ°µÍøÍøÕ¾±»¹¥»÷ʱËùÓÃÐÅÏ¢Ïà·û£¬»ò´æÔÚÁªÏµ¡£´Ë±í£¬phpMyAdmin SQLת´¢ÏÔʾ¸Ã·þÎñÆ÷ÔËÐдæÔÚÑϳÁ·ì϶CVE-2024-4577µÄPHP 8.1.2°æ±¾£¬¸Ã·ì϶¿ÉÓÃÓÚÔ¶³Ì´úÂëÖ´ÐС£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-hacked-victim-negotiations-exposed/
3. PowerSchoolÔâÊý¾Ýй¶ºóºÚ¿Í½è¾ÉÊý¾ÝÀÕË÷Ñ§Çø
5ÔÂ7ÈÕ£¬PowerSchoolÖÒ¸æ³Æ£¬È¥Äê12Ô·¢ÆðÍøÂç¹¥»÷µÄºÚ¿ÍÕý¶ÔѧÌýøÐе¥¶ÀÀÕË÷£¬Ò԰䲼֮ǰ±»µÁѧÉúºÍÀÏʦÊý¾ÝΪÍþв¡£PowerSchoolÈ·ÈÏÍþвÐÐΪÕßÒÑÁªÏµ¶à¸öÑ§Çø¿Í»§£¬ÀûÓÃÈ¥Äê12ÔÂÊÂÎñÊý¾Ý½øÐÐÀÕË÷£¬ÒòÊý¾ÝÑù±¾Óë±»µÁÊý¾ÝÏà·û£¬Åжϲ¢·ÇÐÂÊÂÎñ¡£½ñÄê1Ô£¬PowerSchoolÅû¶ÆäPowerSource¿Í»§Ö§³ÖÃÅ»§ÍøÕ¾Òòƾ֤й¶ÔâÈëÇÖ£¬¹¥»÷ÕßÀûÓÃȨÏÞÏÂÔØÑ§ÇøÊý¾Ý¿â£¬Ô̺¬Ñ§ÉúºÍÀÏʦ¶à·½ÃæÃô¸ÐÐÅÏ¢¡£¸Ã·ì϶×î³õÓÚÈ¥Äê12ÔÂ28ÈÕ±»·¢ÏÖ£¬µ«ÔçÔÚ2024Äê8ÔºÍ9Ô¾ÍÒÑÔâÈëÇÖ¡£ºÚ¿ÍÔøÐû³ÆÇÔÈ¡¶à¹ú´óÁ¿Ñ§ÇøÑ§ÉúºÍÀÏʦÊý¾Ý£¬PowerSchoolÆäʱȷÈÏÖ§¸¶Êê½ðÒÔ×èÖ¹Êý¾Ýй¶£¬µ«ÍþвÕßδ¶ÒÏÖ³Ðŵ¡£¸Ã¹«Ë¾ÒÑÏòÃÀ¡¢¼Ó·¨Âɲ¿ÃŻ㱨£¬ÕýÓë¿Í»§Ç×êǺÏ×÷Ìṩ֧³Ö£¬¶Ô´ËÉî¸ÐÒź¶¡£PowerSchool¶ÔÎ¥¹æÐÐΪÔì³ÉµÄ³ÖÐøÍþв°µÊ¾Ç¸Ò⣬³Æ½«³ÖÐøÓë¿Í»§ºÍ·¨Âɲ¿ÃźÏ×÷Ó¦¶ÔÀÕË÷ÐÐΪ¡£Í¬Ê±£¬½¨ÒéѧÉúºÍ½ÌÈËÔ±¹¤ÀûÓÃÁ½ÄêÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ·À±¸Ú²ÆºÍÉí·Ý͵ÇÔ¡£´Ë±í£¬PowerSchool·´Ë¼ÁËÖ§¸¶Êê½ðµÄÑ¡Ôñ£¬°µÊ¾ËäÊǼè¾Þ¾ö¶¨£¬µ«Îª±£»¤¿Í»§ÀûÒæ£¬ÔÚÈ¥Äê12ÔÂÊÂÎñ²úÉú¼¸Ììºó±ã¾ö¶¨Ö§¸¶Êê½ðÒÔÔ¤·ÀÊý¾Ý¹«¿ª£¬²»ÍâÈÔ´æÔÚ·¸·¨·Ö×Ó²»Ô¸É¾³ýÇÔÈ¡Êý¾ÝµÄ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/powerschool-hacker-now-extorting-individual-school-districts/
4. ºÚ¿ÍÀûÓÃOttoKit WordPress²å¼þ·ì϶Ôö³¤ÖÎÀíÔ¹ØÊ»§
5ÔÂ7ÈÕ£¬ºÚ¿ÍÕýÀûÓÃOttoKit WordPress²å¼þÖеÄÑϳÁȨÏÞÌáÉý·ì϶CVE-2025-27007ÔÚÖ¸±êÍøÕ¾ÉÏ´´½¨¶ñÒâÖÎÀíÔ¹ØÊ»§¡£OttoKit£¨ÔøÓÃÃûSureTriggers£©ÊÇÒ»¿îÊÜÓ½ÓµÄ×Ô¶¯»¯ºÍ¼¯³É²å¼þ£¬Óû§Á¿³¬10Íò£¬ÓÃÓÚÏνÓÍøÕ¾ÓëµÚÈý·½·þÎñ²¢×Ô¶¯»¯¹¤×÷Á÷³Ì¡£2025Äê4ÔÂ11ÈÕ£¬PatchstackÊÕµ½×êÑÐÔ±µ¤·ð¡¤½Ü¿ËÑ·Ìá½»µÄ·ì϶»ã±¨£¬Ö¸³ö¹¥»÷Õß¿ÉÀûÓá°create_wp_connection¡±º¯ÊýÖеÄÂß¼ÃýÎó£¬Í¨¹ý²å¼þAPIÈÆ¹ýÉí·ÝÑéÖ¤£¬»ñÈ¡ÖÎÀíÔ±½Ó¼ûȨÏÞ¡£¹©¸øÉÌÔÚÊÕµ½Í¨ÖªºóµÄµÚ¶þÌì»ñϤ´ËÇé¿ö£¬²¢ÓÚ4ÔÂ21ÈÕ°ä²¼²¹¶¡£¨OttiKit 1.0.83°æ±¾£©£¬Ôö³¤Á˶ÔÒªÇóÖнӼûÃÜÔ¿µÄÑéÖ¤²é³¡£½ØÖÁ4ÔÂ24ÈÕ£¬ÎÞÊýÓû§ÒѸüÐÂÖÁ½¨²¹°æ±¾¡£È»¶ø£¬PatchstackÓÚ5ÔÂ5ÈÕ°ä²¼µÄ»ã±¨ÏÔʾ£¬·ì϶ÀûÓûÔÚ¹«¿ªÅû¶ºóÔ¼90·ÖÖÓ¼´ÒÑÆðÍ·¡£¹¥»÷Õßͨ¹ý¶Ô×¼REST API¶Ëµã£¬·¢ËÍ·ÂÕպϷ¨¼¯³É³¢ÊÔµÄÒªÇ󣬲¢³¢ÊԲ²â»ò±©Á¦ÆÆ½âÖÎÀíÔ±Óû§Ãû¡¢ÃÜÂë¼°Ðéα½Ó¼ûÃÜÔ¿ºÍµç×ÓÓʼþµØÖ·À´ÀûÓ÷ì϶¡£Ò»µ©¹¥»÷³É¹¦£¬¹¥»÷Õ߻ᷢ³öºóÐøAPIŲÓã¬ÔÚ´æÔÚ·ì϶µÄ×°ÖÃÖд´½¨ÐµÄÖÎÀíÔ¹ØÊ»§¡£Patchstack½¨ÒéʹÓÃOttoKit²å¼þµÄÓû§¾¡¿ì¸üÐÂÍøÕ¾£¬²¢²é³ÈÕÖ¾ºÍÍøÕ¾ÉèÖÃÖÐÊÇ·ñ´æÔÚ¹¥»÷ºÍй¶ָ±ê¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-ottokit-wordpress-plugin-flaw-to-add-admin-accounts/
5. Masimo CorporationÔâÍøÂç¹¥»÷Ó°Ïì³ö²úÔËÓª
5ÔÂ7ÈÕ£¬Ò½ÁÆÆ÷е¹«Ë¾Masimo Corporation·¢³öÖҸ棬³ÆÆäÕýÔâ·êÍøÂç¹¥»÷£¬¸Ã¹¥»÷ÒѶԳö²úÔËÓªÔì³ÉÓ°Ïì²¢µ¼Ö¿ͻ§¶©µ¥ÍƹãÑÓ³¤¡£Masimo Corporation×ܲ¿Î»ÓÚ¼ÓÖÝ£¬ÊÇÒ»¼Ò³ÛÃûµÄÒ½ÁƼ¼ÊõºÍÏû·Ñµç×Ó²úÆ·Ôì×÷ÉÌ£¬ÒÔÎÞ´´»¼Õß¼à²â²úÆ·ÎÅÃû£¬ÈçÂö²«ÑªÑõÒÇ¡¢ÄÔÖ°Äܼà²âÒǵȡ£¸Ã¹«Ë¾ÓÚ2025Äê4ÔÂ27ÈÕÔâ·êÕâ´ÎÍøÂç¹¥»÷£¬²¢ÓÚ×òÍíÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»µÄ8-K±í¸ñÎļþÖÐÅû¶Á˸ÃÊÂÎñ¡£Ö»¹ÜMasimoδй©¹¥»÷ÀàÐ͵ľßÌåϸ½Ú£¬µ«È·ÈÏÍþвÐÐΪÕßÇÖÈëÁËÆäÄÚ²¿ÍøÂ磬ÆÈʹ¹«Ë¾¸ôÀëÊÜÓ°ÏìµÄϵͳ¡£Õâ´ÎÍøÂ簲ȫÊÂÎñ¶Ô¹«Ë¾µÄ³ö²úºÍÒµÎñÔËÓª²úÉúÁËÏÔÖøÓ°Ï죬²¿ÃÅÔì×÷ÉèÊ©µÄÔËӪˮƽµÍÓÚÕý³££¬¿Í»§¶©µ¥µÄ´¦Öá¢ÍƹãºÍ·¢ËÍÄÜÁ¦Ò²Êܵ½ÁÙʱӰÏì¡£¹«Ë¾ÕýÖÂÁ¦¸´ÔÊÜÓ°ÏìÍøÂ粿ÃŵÄÔÚÏßÔËÐУ¬ÒÔ¸´ÔÕý³£ÒµÎñÔËÓª²¢¼õÇáÊÂÎñÓ°Ïì¡£MasimoÒÔΪÕâ´ÎÍøÂç¹¥»÷½öÏÞÓÚÄÚ²¿ÏµÍ³£¬²»»á²¨¼°Æä»ùÓÚÔÆµÄ»ù´¡ÉèÊ©¡£Ä¿Ç°£¬¹«Ë¾ÔÚÓë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷£¬²¢ÒÑ֪ͨ·¨Âɲ¿ÃÅ£¬¶ÔÊÂÎñµÄ¾ßÌåÐÔÖÊ¡¢ÁìÓòºÍÏÖʵӰÏìµÄµ÷²éÈÔÔÚ½øÐÐÖУ¬Òò¶øÉв»Ã÷ÏÔÊÇ·ñÓ°ÏìÁ˿ͻ§Êý¾Ý£¬ÒÔ¼°ÊÇ·ñ»á¶Ô±¾¼¾¶È²ÆÕþÊý¾Ý²úÉúÈκÎÓ°Ïì¡£½ØÖÁĿǰ£¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/medical-device-maker-masimo-warns-of-cyberattack-manufacturing-delays/
6. ¶à¹ú½áºÏÐж¯½ø¹¥Áù¸öDDoS¹ÍӶƽ̨£¬ËÄÃûÏÓÒÉÈ˱»¾Ð
5ÔÂ7ÈÕ£¬²¨À¼µ±¾Ö½üÆÚ¿ÛÁôÁËËÄÃûÓëÁù¸öDDoS¹ÍӶƽ̨ÓйصÄÏÓÒÉÈË£¬ÕâЩƽ̨×Ô2022ÄêÆðÒѶÔÈ«ÇòѧÌᢵ±¾Ö·þÎñ¡¢ÆóÒµºÍÓÎϷƽ̨·¢ÆðÁËÊýǧ´Î¹¥»÷¡£ÕâЩƽ̨ÔÚ°µÍøºÍºÚ¿ÍÂÛ̳Éϱ»¼Ù×°³ÉºÏ·¨²âÊÔ¹¤¾ß£¬ÊµÔòÓÃÓÚ·¢ÆðDDoS¹¥»÷£¬Í¨¹ýÏòÔÚÏß·þÎñ¡¢·þÎñÆ÷ºÍÍøÕ¾×¢Èë´óÁ¿Á÷Á¿£¬µ¼ÖÂÆäÎÞ·¨Õý³£Ê¹Óá£Å·ÖÞÐ̾¯×éÖ¯°ä·¢£¬²¨À¼µ±¾ÖÔÚÐͬ·¨ÂÉÐж¯ÖУ¬ÓëµÂ¹ú¡¢ºÉÀ¼ºÍÃÀ¹úºÏ×÷£¬³É¹¦¹Ø¹ØÁËÁù¸öDDoS·þÎñƽ̨£¬Ô̺¬Cfxapi¡¢Cfxsecurity¡¢neostress¡¢jetstress¡¢quickdownºÍzapcut¡£¾ÝÐÅ£¬ÕâËÄÃûÏÓÒÉÈËÊÇÕâЩƽ̨µÄÄ»ºóÔËÓªÕߣ¬ËûÃÇÌṩµÄDDoS¹ÍÓ¶·þÎñÔÊÐí¸¶·Ñ¿Í»§ÒÔµÍÖÁ10Å·ÔªµÄ¼ÛÖµ·¢Æð¹¥»÷£¬Ê¹Ö¸±êÍøÕ¾ÏÂÏß¡£ÕâЩ·þÎñͨ³£ÌṩÒ×ÓÚʹÓõĽçÃæ£¬¿Í»§Ö»ÐèÖ§¸¶Óöȡ¢ÊäÈëÖ¸±êIPµØÖ·²¢Ñ¡Ôñ¹¥»÷ÀàÐͺͳÖÐø¹¦·ò£¬ÎÞÐèÈκμ¼Êõ¼¼Êõ¡£ºÉÀ¼¾¯·½Í¨¹ý¹²Ïí´ÓÕâЩƽ̨»ñÈ¡µÄÊý¾Ý£¬ÐÖú²¨À¼¿ÛÁôÁËÓйØÖÎÀíÔ±¡£×÷Ϊ½áºÏÐж¯µÄÒ»²¿ÃÅ£¬ÃÀ¹ú²é·âÁË9¸öÓòÃû£¬µÂ¹úÔòÐÖúµ÷²é²¢·ÖÏíµý±¨¡£ºÉÀ¼µ÷²éÈËÔ±»¹´´½¨ÁËÐéαÊèµ¼ÍøÕ¾£¬ÖÒ¸æÇ±ÔÚÓû§´ËÀà»î¶¯µÄ·¸·¨ÐÔ£¬²¢Ç¿µ÷¼à¿ØºÍ¸æ×´·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/police-takes-down-six-ddos-for-hire-services-arrests-admins/


¾©¹«Íø°²±¸11010802024551ºÅ