ÂíÊõÆ÷²Ä¾ÞÍ·ÔâPlayÀÕË÷Èí¼þË«ÖØÀÕË÷

Ðû²¼Ê±¼ä 2025-11-05

1. ÂíÊõÆ÷²Ä¾ÞÍ·ÔâPlayÀÕË÷Èí¼þË«ÖØÀÕË÷


11ÔÂ3ÈÕ £¬ÃÀ¹ú¼ÓÖÝÂíÊõÔ˶¯Æ÷²Ä¾ÞÍ·Professional's Choice Sports Medicine Products¿ËÈÕ³ÉΪPlayÀÕË÷Èí¼þ×îÐÂÄ¿µÄ ¡£¸Ã×éÖ¯ÔÚ°µÍøÐû²¼11ÔÂ4ÈÕÌû×Ó £¬Éù³ÆÇÔÈ¡Õâ¼Ò1976Ä꽨Éè¡¢ÄêÊÕÈë6500ÍòÃÀÔªÆóÒµµÄ¡°Ë½ÈËÉñÃØÊý¾Ý¡¢¿Í»§Îļþ¡¢Ô¤Ëã¡¢ÈËΪµ¥¡¢Ë°Îñ¼°²ÆÎñÐÅÏ¢¡± £¬²¢Íþв24СʱÄÚ¹ûÕæÐ¹Â¶ ¡£PlayÍÅ»ï½ÓÄÉË«ÖØÀÕË÷ģʽ£ºÏÈÒªÇóÖ§¸¶Êê½ð»»È¡¼ÓÃÜÊý¾Ý½âÃÜÃÜÔ¿ £¬ÔÙË÷ÒªµÚ¶þ±ÊÊê½ð²»È»³öÊÛ»ò¹ûÕæ±»µÁÊý¾Ý ¡£¸ÃÍÅ»ïÓë¶íÂÞ˹¹ØÁª £¬Á½Äê¼äÒѹ¥»÷964¸öÄ¿µÄ £¬º­¸ÇÒªº¦»ù´¡ÉèÊ©¼°ÆóÒµ ¡£ÊÖÒÕ²ãÃæ £¬Play±»ÊÓΪÊ×Åú½ÓÄÉ¡°¼äЪÐÔ¼ÓÃÜ¡±µÄÀÕË÷Èí¼þ×éÖ¯ ¡£¸ÃÕ½ÂÔ½ö¼ÓÃÜϵͳÀο¿²¿·Ö £¬´ó·ùËõ¶Ì¼ÓÃÜʱ¼ä £¬¼ÓËÙÊý¾ÝÇÔÈ¡ ¡£ÀàËÆÊÖ·¨Ò²±»ALPHV/BlackCat¡¢DarkBitµÈ×ÅÃûÍÅ»ïЧ·Â ¡£


https://cybernews.com/security/ransomware-proffesional-choice-sports-medicine-products/


2. ³¬40ÍòWordPressÍøÕ¾ÃæÁÙPost SMTP²å¼þÎó²îÍþв


11ÔÂ4ÈÕ £¬½üÆÚ £¬ÍþвÐÐΪÕßÕýʹÓÃWordPress²å¼þPost SMTPÖеÄÑÏÖØÎó²î¶Ô³¬40ÍòÍøÕ¾Ìᳫ¹¥»÷ £¬¸ÃÎó²î¿Éµ¼ÖÂÖÎÀíÔ±ÕË»§±»ÍêÈ«½ÓÊÜ ¡£Post SMTPÊÇÌæ»»Ä¬ÈÏwp_mail()º¯ÊýµÄÖ÷Á÷Óʼþ·¢Ëͽâ¾ö¼Æ»® £¬Æä3.6.0¼°¸üÔç°æ±¾±£´æ±àºÅΪCVE-2025-11833µÄ¸ßΣÎó²î£¨CVSSÆÀ·Ö9.8£© £¬Ô´ÓÚ²å¼þµÄPostmanEmailLogsÁ÷³ÌÖÐ_constructº¯Êýȱ·¦ÊÚȨ¼ì²é £¬ÔÊÐíδÈÏÖ¤¹¥»÷ÕßÖ±½Ó¶ÁÈ¡í§ÒâÒѼͼµÄµç×ÓÓʼþÄÚÈÝ £¬°üÀ¨º¬ÃÜÂëÖØÖÃÁ´½ÓµÄÃô¸ÐÐÅÏ¢ ¡£¹¥»÷Õß¿ÉʹÓôËÀàÁ´½ÓÈÆ¹ýÕýµ±ÕË»§ÑéÖ¤ £¬Ö±½ÓÖØÖÃÖÎÀíÔ±ÃÜÂë²¢¿ØÖÆÕû¸öÍøÕ¾ ¡£WordfenceÇå¾²ÍŶÓÓÚ10ÔÂ11ÈÕÊ×´ÎÊÕµ½Ñо¿Ô±"netranger"µÄÎó²î±¨¸æ £¬15ÈÕÍê³ÉÊÖÒÕÑéÖ¤ºóÏò²å¼þ¿ª·¢ÕßSaad IqbalÅû¶ £¬10ÔÂ29ÈÕÐû²¼²¹¶¡°æ±¾3.6.1 ¡£È»¶ø £¬Æ¾Ö¤WordPress.orgÊý¾Ý £¬½öÔ¼50%Óû§Íê³ÉÉý¼¶ £¬ÈÔÓÐÔ¼21ÍòÍøÕ¾´¦ÓÚΣº¦×´Ì¬ ¡£×Ô11ÔÂ1ÈÕÆð £¬ºÚ¿ÍÒÑ×îÏÈ´ó¹æÄ£Ê¹ÓøÃÎó²î £¬WordfenceÒÑÔÚÆä¿Í»§ÈºÖÐ×èµ²³¬4500´Î¹¥»÷ʵÑé ¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-post-smtp-to-hijack-admin-accounts/


3. Apache»ù½ð»á·ñ¶¨OpenOfficeÔâÀÕË÷¹¥»÷Ö¸¿Ø


11ÔÂ4ÈÕ £¬ApacheÈí¼þ»ù½ð»á¿ËÈÕ¹ûÕæ·ñ¶¨Æä¿ªÔ´ÏîÄ¿OpenOfficeÔâÊÜAkiraÀÕË÷Èí¼þ¹¥»÷µÄ˵·¨ ¡£´Ëǰ £¬AkiraÍÅ»ïÉù³ÆÓÚ10ÔÂ30ÈÕÈëÇÖ¸ÃÏîÄ¿²¢ÇÔÈ¡23GBÊý¾Ý £¬°üÀ¨Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡¢²ÆÎñ¼Í¼¼°ÄÚ²¿ÎļþµÈ ¡£OpenOffice×÷ΪÃâ·Ñ¿ªÔ´°ì¹«Ì×¼þ £¬¼æÈÝÖ÷Á÷ÎĵµÃûÌà £¬Ö§³Ö¶à²Ù×÷ϵͳÔËÐÐ £¬ÓÉÈ«Çò×ÔÔ¸ÕßТ˳ÕßÅäºÏά»¤ ¡£Õë¶ÔÖ¸¿Ø £¬»ù½ð»áÇ¿µ÷OpenOfficeÏîÄ¿²»±£´æÍþвÐÐΪÕßÐÎòµÄÃô¸ÐÊý¾ÝÀàÐÍ ¡£ÓÉÓÚÏîÄ¿½ÓÄɷǹÍÓ¶ÖÆ¿ª·¢Ä£Ê½ £¬Ð¢Ë³Õß¾ùΪ×ÔÔ¸Õß £¬Òò´Ë²»´æ´¢Ô±¹¤µØµã¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Éç±£ºÅÂëµÈ¹Å°åÆóÒµ¼¶Êý¾Ý ¡£ÏîÄ¿¿ª·¢È«³Ìͨ¹ý¹ûÕæÓʼþÁбí¾ÙÐÐ £¬ËùÓÐÎó²î±¨¸æ¡¢¹¦Ð§ÇëÇó¼°ÊÖÒÕÎÊÌâ¾ù͸Ã÷¿É¼û £¬²»±£´æ"ÄÚ²¿ÉñÃØÎļþ" ¡ £»ù½ð»áÖ¸³ö £¬AkiraËù³ÆµÄ"23GB¹«Ë¾Îļþ"ÓëÏîÄ¿ÏÖʵÊý¾Ý½á¹¹²»·û £¬ÇÒÖÁ½ñδÌṩÈκÎÊý¾ÝÑù±¾ÑéÖ¤ÆäÖ÷ÕÅ ¡ £»ù½ð»áÌåÏÖ £¬ÏÖÔÚδÊÕµ½ÈκÎÀÕË÷ÒªÇó £¬Ò²Î´·¢Ã÷ϵͳ±»ÈëÇÖµÄÖ¤¾Ý ¡£ÊÓ²ìÏÔʾ £¬»ù½ð»á¼°OpenOfficeÏîÄ¿µÄ»ù´¡ÉèʩδÊÜÓ°Ïì £¬ÏîÄ¿¿ª·¢Á÷³ÌµÄ¹ûÕæÐÔ×Ô¼º¼´×é³ÉÇå¾²ÆÁÕÏ ¡£


https://www.bleepingcomputer.com/news/security/apache-openoffice-disputes-data-breach-claims-by-ransomware-gang/


4. Google PlayÉϵĶñÒâAndroidÓ¦ÓÃÏÂÔØÁ¿´ï4200Íò´Î


11ÔÂ4ÈÕ £¬ÔÆÇå¾²¹«Ë¾ZscalerÐû²¼µÄÄê¶È±¨¸æÏÔʾ £¬2024Äê6ÔÂÖÁ2025Äê5ÔÂʱ´ú £¬Google PlayÊÐËÁÖÐ239¿î¶ñÒâAndroidÓ¦ÓÃÀÛ¼ÆÏÂÔØÁ¿³¬4200Íò´Î £¬½ÏÉÏÄêͬÆÚÔöÌíÏÔÖø ¡£Í¬ÆÚÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷ͬ±ÈÔöÌí67% £¬Ìع¤Èí¼þÓëÒøÐÐľÂí³ÉΪÖ÷ÒªÍþв £¬ÆäÖÐ¹ã¸æÈí¼þÕ¼±È¸ß´ï69% £¬ÏÕЩÊÇÈ¥ÄêÁ½±¶ £¬JokerÐÅÏ¢ÇÔÈ¡³ÌÐòÊг¡·Ý¶î´Ó38%½µÖÁ23% ¡£±¨¸æÖ¸³ö £¬¹¥»÷ÊÖ¶ÎÕý´Ó¹Å°åÐÅÓÿ¨Ú²Æ­×ªÏòÍøÂç´¹ÂÚ¡¢¶ÌÐÅ´¹ÂÚ¡¢SIM¿¨½»Á÷ºÍÖ§¸¶Õ©Æ­µÈÉç»á¹¤³Ì¹¥»÷ £¬ÕâµÃÒæÓÚоƬÇå¾²±ê×¼ÌáÉý¼°Òƶ¯Ö§¸¶ÆÕ¼° ¡£Ìع¤Èí¼þ¼Ò×åÈçSpyNote¡¢SpyLoanµÈͬ±È¼¤Ôö220% £¬±»ÓÃÓÚ¼àÊÓ¡¢ÀÕË÷ºÍÉí·Ý͵ÇÔ ¡£´ÓµØÇøÂþÑÜ¿´ £¬Ó¡¶È¡¢ÃÀ¹úºÍ¼ÓÄôóÔâÊÜ55%µÄ¹¥»÷ £¬Òâ´óÀûºÍÒÔÉ«ÁеĹ¥»÷Á¿¸üͬ±È±©Ôö800%-4000% ¡£Öصã¶ñÒâÈí¼þ·½Ãæ £¬AnatsaÒøÐÐľÂíͨ¹ýαװЧ¹ûÂʹ¤¾ßÓ¦ÓÃDZÈëGoogle Play £¬×îбäÖÖ¿ÉÇÔÈ¡831¼Ò½ðÈÚ»ú¹¹¼°¼ÓÃÜÇ®±Òƽ̨Êý¾Ý £»Android VoidºóÃÅÔòѬȾ160Íǫ̀ÔËÐйýʱAOSPϵͳµÄ×°±¸ £¬Ö÷ÒªÂþÑÜÔÚÓ¡¶ÈºÍ°ÍÎ÷ £»Xnotice RATÔòÕë¶ÔÖж«¼°ÒÁÀÊʯÓÍÐÐÒµÇóÖ°Õß £¬Í¨¹ýÐéαÕÐÆ¸Ó¦ÓÃÈö²¥ £¬Í¨¹ýÁýÕֲ㡢MFA´úÂëÇÔÈ¡ÒøÐÐÆ¾Ö¤ ¡£


https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/


5. ÈðµäMilj?dataÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË150ÍòÈË


11ÔÂ4ÈÕ £¬ÈðµäÒþ˽± £»¤¾Ö£¨IMY£©Õý¶ÔITϵͳ¹©Ó¦ÉÌMilj?dataÔâÊܵÄÍøÂç¹¥»÷Õö¿ªÉî¶ÈÊÓ²ì £¬¸ÃÊÂÎñµ¼ÖÂÔ¼150Íò¹«ÃñСÎÒ˽¼ÒÊý¾Ýй¶ £¬Éæ¼°ÐÕÃû¡¢µØµã¡¢µç»°¡¢Éí·ÝÖ¤¼þ¼°³öÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢ ¡£Milj?data×÷ΪÈðµäÔ¼80%ÊÐÕþÕþ¸®µÄITϵͳ·þÎñÉÌ £¬ÓÚ8ÔÂ25ÈÕÅû¶¹¥»÷ϸ½Ú£º¹¥»÷ÕßÇÔÈ¡Êý¾ÝºóÀÕË÷1.5¸ö±ÈÌØ±Ò £¬²»È»½«¹ûÕæÊý¾Ý ¡£´Ë´ÎÊÂÎñÔì³É¹þÀ¼¡¢¸çÌØÀ¼µÈ¶àµØÇøÔËÓªÖÐÖ¹ £¬Ó°Ï칫Ãñ·þÎñ ¡£IMYÈÏÕæÈËÖ¸³ö £¬Êý¾Ýй¶Òý·¢¶ÔϵͳÇ徲Ʒ¼¶¼°´æ´¢ÐÅÏ¢ÀàÐ͵ÄÑÏÖØÖÊÒÉ ¡£ÊÓ²ìÖØµã¾Û½¹ÓÚʶ±ðϵͳÇå¾²Îó²î¼°Êý¾Ý´¦Öóͷ£Êµ¼ùÖеÄȱ·¦ £¬ÒÔÌá·ÀδÀ´ÀàËÆÊÂÎñ ¡£°µÍø¼à¿ØÏÔʾ £¬Íþв×éÖ¯DatacarryÓÚ9ÔÂ13ÈÕÔÚÆäÃÅ»§ÍøÕ¾Ðû²¼224MBµÄ±»µÁÊý¾Ý´æµµ £¬²¢ÁгöÁíÍâ12ÃûÊܺ¦Õß ¡£Ö»¹ÜMilj?dataÅû¶ʱÎÞÀÕË÷×éÖ¯ÈÏÁì £¬µ«Êý¾ÝÒѱ»Have I Been PwnedÊÕ¼ £¬¸Ãƽ̨±¨¸æÏÔÊ¾Ð¹Â¶Éæ¼°87ÍòÈË £¬Ô¼ÎªIMYͳ¼ÆÊý×ÖµÄÒ»°ë £¬Êý¾ÝÁ¿²î±ðÒý·¢½øÒ»²½ºË²éÐèÇó ¡£


https://www.bleepingcomputer.com/news/security/data-breach-at-major-swedish-software-supplier-impacts-15-million/


6. ÈÕ¾­ÐÂÎÅSlackƽ̨ÔâÈëÇÖÖÂ1.7ÍòÌõÐÅϢй¶


11ÔÂ4ÈÕ £¬ÈÕ±¾³öÊé¾ÞÍ·ÈÕ¾­ÐÂÎÅ¿ËÈÕÅû¶ £¬ÆäSlack¼´Ê±Í¨Ñ¶Æ½Ì¨ÒòÔ±¹¤µçÄÔѬȾ¶ñÒâÈí¼þµ¼ÖÂÉí·ÝÑé֤ƾ֤±»µÁ £¬¹¥»÷Õß½è´Ë»á¼ûÔ±¹¤ÕË»§ £¬Ôì³ÉÁè¼Ý17,000ÃûÔ±¹¤¼°ÉÌҵͬ°éµÄÐÕÃû¡¢µç×ÓÓʼþµØµã¼°Ì¸Ìì¼Í¼й¶ ¡£×÷ΪȫÇò×î´óýÌ弯ÍÅÖ®Ò» £¬ÈÕ¾­ÆìÏÂÓµÓС¶½ðÈÚʱ±¨¡·¡¶ÈÕ¾­ÐÂÎÅ¡·µÈ370ÍòÊý×Ö¶©ÔÄÓû§¼°40Óà¼ÒÁ¥Êô¹«Ë¾ £¬ÓªÒµÁýÕÖ³öÊé¡¢¹ã²¥¡¢Êý¾Ý¿â·þÎñµÈÁìÓò £¬²¢ÔÚÈ«ÇòÉèÓÐ37¸öÍâÑó±à¼­²¿¼°1500ÓàÃû¼ÇÕß ¡£ÊÂÎñ±¬·¢ÓÚ½ñÄê9Ô £¬ÈÕ¾­·¢Ã÷Çå¾²Îó²îºóÁ¬Ã¦½ÓÄÉÇ¿ÖÆÃÜÂë¸ü¸ÄµÈ²½·¥ ¡£Ö»¹Üй¶ÐÅÏ¢²»ÊôÓÚÈÕ±¾¡¶Ð¡ÎÒ˽¼ÒÐÅÏ¢± £»¤·¨¡·Ç¿ÖƱ¨¸æ¹æÄ£ £¬µ«ÈÕ¾­×Ô¶¯ÏòСÎÒ˽¼ÒÐÅÏ¢± £»¤Î¯Ô±»á±¨¸æ £¬Ç¿µ÷ÊÂÎñ¡°Ö÷ÒªÐÔ¡±¼°Í¸Ã÷¶ÈÔ­Ôò ¡£¹«Ë¾ÌØÊâÉùÃ÷ £¬ÓëÉñÃØÐÂÎÅȪԴ¼°±¨µÀÔ˶¯Ïà¹ØµÄÐÅϢδ±»Ð¹Â¶ £¬ÐÂÎÅÊÕÂÞÊý¾Ý¼á³ÖÇå¾² ¡£


https://www.bleepingcomputer.com/news/security/media-giant-nikkei-reports-data-breach-impacting-17-000-people/