Wordfence·¢ÏÖÕë¶Ô160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷

Ðû²¼Ê±¼ä 2021-12-14
ÎÖ¶ûÎÖ¹«Ë¾Ôâµ½SnatchµÄÀÕË÷¹¥»÷µ¼ÖÂÑз¢Êý¾Ýй¶


ÎÖ¶ûÎÖ¹«Ë¾Ôâµ½SnatchµÄÀÕË÷¹¥»÷µ¼ÖÂÑз¢Êý¾Ýй¶.png


12ÔÂ10ÈÕ  £¬ÈðµäÆû³µÖÆÔìÉÌÎÖ¶ûÎÖ³ÆÆä·þÎñÆ÷Ôâµ½ÀÕË÷¹¥»÷  £¬²¿ÃÅÑз¢Êý¾ÝÒѾ­Ð¹Â¶¡£ÎÖ¶ûÎÖÌåÏÖ  £¬Ä¿Ç°ÕýÔÚ¶Ô´ËÊÂÕ¹¿ªÊÓ²ì  £¬¿Í»§µÄ¸öÈËÊý¾Ý²¢²»»áÊܵ½Ó°Ïì  £¬µ«¹«Ë¾µÄÔËÓª¿ÉÄÜÊܵ½Ó°Ïì¡£ËäÈ»¸Ã¹«Ë¾ÉÐδ͸¶Óйش˴ÎʼþµÄÆäËüϸ½Ú  £¬µ«ÀÕË÷ÔËÓªÍÅ»ïSnatchÒÑÓÚ11ÔÂ30ÈÕ½«¸Ã¹«Ë¾Ìí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾µÄĿ¼ÖÐ  £¬²¢¹ûÈ»Á˱»µÁÎļþµÄ½ØÍ¼ºÍ35.9 MBµÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/volvo-cars-discloses-security-breach-leading-to-randd-data-theft/


Wordfence·¢ÏÖÕë¶Ô160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷


Wordfence·¢ÏÖÕë¶Ô160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷.png


WordfenceÔÚ12ÔÂ9ÈÕ¹ûÈ»Á˽üÆÚÕë¶ÔÁè¼Ý160Íò¸öWordPressÍøÕ¾µÄ´ó¹æÄ£¹¥»÷»î¶¯¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô4¸ö²å¼þ£¨PublishPress CapabilitiesºÍKiwi Social PluginµÈ£©ºÍ15¸öEpsilon¿ò¼ÜÖ÷Ì⣨ShapelyºÍNatureMag LiteµÈ£©¡£Í¨¹ýÆôÓÃusers_can_registerÑ¡Ïî  £¬²¢½«default_roleÑ¡ÏîÉèÖÃΪ¹ÜÀíÔ±  £¬¹¥»÷Õ߾ͿÉÒÔ×¢²áΪ¹ÜÀíÔ±²¢½Ó¹Ü¸ÃÍøÕ¾¡£Ñо¿ÈËÔ±½¨ÒéÓû§Á¢¼´¸üÐÂÊÜÓ°Ïì²å¼þ  £¬ÆäÖÐNatureMag LiteûÓпÉÓò¹¶¡  £¬ÐèÒªÁ¢¼´Ð¶ÔØ¡£

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125469/hacking/wordpress-sites-under-attack.html


Frontier Softwareй¶Լ8Íò¸ö°Ä´óÀûÑǹ«ÃñµÄÐÅÏ¢


Frontier Softwareй¶Լ8Íò¸ö°Ä´óÀûÑǹ«ÃñµÄÐÅÏ¢.png


ÄϰĴóÀûÑÇÖÝÕþ¸®ÔÚ12ÔÂ10ÈÕÐû²¼Í¨¸æ  £¬³ÆÆäÔ¼8Íò¸öÔ±¹¤µÄÐÅÏ¢ÒѾ­Ð¹Â¶¡£´Ë´Îй¶Ê¼þµÄÔ­ÒòÊÇн×ÊÈí¼þ¹«Ë¾Frontier SoftwareÓÚ11ÔÂ13ÈÕÔâµ½ÀÕË÷¹¥»÷  £¬¸Ã»î¶¯¿ÉÄÜÓëContiÓйØ¡£11ÔÂ16ÈÕ  £¬ContiÔøÔÚÆäÍøÕ¾ÁгöÁËFrontier Software  £¬µ«ÊÇÏÖÔÚ¸ÃÁбíÒѱ»É¾³ý  £¬Õâ¿ÉÄÜÒâζ×Å̸ÅÐÒѾ­½áÊø¡£¸ÃÖÝΨһûÓÐÊܵ½Ó°ÏìµÄ¹«¹²×éÖ¯ÊǽÌÓý²¿  £¬ÒòΪËü²»Ê¹ÓÃFrontierµÄ²úÎï¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-impacts-80-000-south-australian-govt-employees/


Cofense·¢ÏÖÕë¶ÔµÂ¹ú½ðÈÚÐÐÒµµÄÐÂÒ»ÂÖµöÓã»î¶¯


Cofense·¢ÏÖÕë¶ÔµÂ¹ú½ðÈÚÐÐÒµµÄÐÂÒ»ÂÖµöÓã»î¶¯.png


12ÔÂ9ÈÕ  £¬Cofense·¢ÏÖÔÚ¹ýÈ¥¼¸ÖÜÖÐ  £¬ÀûÓöþάÂëÕë¶ÔµÂ¹ú½ðÈÚÐÐÒµµÄÐÂÒ»ÂÖµöÓã»î¶¯¡£´Ë´Î»î¶¯Ê¹ÓõÄÓʼþÖв¢Ã»ÓÐÃ÷ÎÄURL  £¬¶øÊÇͨ¹ýQRÂ뽫Óû§Öض¨Ïòµ½µöÓãÍøÕ¾  £¬ÒÔÈÆ¹ýÄþ¾²Èí¼þµÄ¼ì²â¡£ÒòΪQRÂëµÄÄ¿±êÊÇÒÆ¶¯Óû§  £¬ÕâЩÓû§ºÜÉÙÊܵ½Äþ¾²¹¤¾ßµÄ±£»¤  £¬ÕâÌá¸ßÁ˹¥»÷µÄÓÐЧÐÔ¡£¹¥»÷Àֳɺó  £¬±ã»áÇÔȡĿ±êµÄÒøÐеØÖ·¡¢´úÂë¡¢Óû§ÃûºÍPINµÈÐÅÏ¢  £¬Ö÷ÒªÕë¶ÔµÄÁ½¸ö½ðÈÚ»ú¹¹ÊÇSparkasseºÍVolksbanken Raiffeisenbanken¡£


Ô­ÎÄÁ´½Ó£º

https://cofense.com/blog/german-users-targeted-in-digital-bank-heist-phishing-campaigns/


Ñо¿ÍŶӷ¢ÏÖÀûÓÃLog4Shell©¶´·Ö·¢¶à¸ö¶ñÒâÈí¼þµÄ»î¶¯


Ñо¿ÍŶӷ¢ÏÖÀûÓÃLog4Shell©¶´·Ö·¢¶à¸ö¶ñÒâÈí¼þµÄ»î¶¯.png


12ÔÂ12ÈÕ  £¬Ñо¿ÍŶӷ¢ÏÖÀûÓÃApache Log4jÖеÄ©¶´Log4Shell·Ö·¢¶àÖÖ¶ñÒâÈí¼þµÄ»î¶¯¡£Log4ShellÓÚÉÏÖÜÎå¹ûÈ»  £¬ApacheÔÚ²»¾ÃÖ®ºóÐû²¼ÁËLog4j 2.15.0À´ÐÞ¸´¸Ã©¶´¡£¸Ã©¶´Ò»¾­Ðû²¼  £¬¾ÍÓкܶ๥»÷ÕßÀûÓÃÆä°²×°ÖÖÖÖ¿ó¹¤Èí¼þ  £¬ÀýÈçºóÃÅKinsingºÍ½©Ê¬ÍøÂçcryptomining±³ºóµÄ¹¥»÷Õß¡£»¹Óй¥»÷ÕßÀûÓøÃ©¶´ÔÚÄ¿±êÉ豸Éϰ²×°¶ñÒâÈí¼þMiraiºÍMuhstik¡£³ýÁ˰²×°¶ñÒâÈí¼þÖ®Íâ  £¬Ñо¿ÈËÔ±»¹·¢ÏÖÁËÕë¶Ô¸Ã©¶´µÄ´ó¹æÄ£É¨Ãè»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-start-pushing-malware-in-worldwide-log4shell-attacks/


Î÷²¿Êý¾ÝÐû²¼¸üÐÂÐÞ¸´SanDisk SecureAccessÖЩ¶´


Î÷²¿Êý¾ÝÐû²¼¸üÐÂÐÞ¸´SanDisk SecureAccessÖЩ¶´.png


Western DigitalÔÚÉÏÖÜÈýÐû²¼Äþ¾²¸üР £¬ÐÞ¸´SanDisk SecureAccessÖеÄ©¶´CVE-2021-36750¡£SanDisk SecureAccess£¨ÏÖÔÚ¸üÃûΪSanDisk PrivateAccess£©ÓÃÀ´ÔÚSanDisk USBÉÁ´æÇý¶¯Æ÷ÉÏ´æ´¢ºÍ±£»¤ÖØÒªÎļþ  £¬ÆäʹÓÃÁ˵¥Ïò¼ÓÃÜhashºÍ¿ÉÔ¤²âsalt  £¬ÕâʹÆäÈÝÒ×Ôâµ½×ֵ乥»÷£»»¹Ê¹ÓÃÁ˼ÆËãÁ¿²»×ãµÄhash  £¬Ê¹Óû§ÃÜÂëÒ×±»±©Á¦ÆÆ½â¡£¹«Ë¾³ÆÕâЩÎÊÌâÒѾ­Í¨¹ýʹÓÃPBKDF2-SHA256ºÍËæ»úsaltÐÞ¸´  £¬½¨ÒéÓû§Á¢¼´¸üС£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125530/security/western-digital-sandisk-secureaccess-flaws.html