DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾­ÏúÉÌ

Ðû²¼Ê±¼ä 2025-12-04

1. DragonForce¹¥»÷ÃÀ¹ú×î´óCricket¾­ÏúÉÌ


12ÔÂ2ÈÕ £¬ÃÀ¹ú×î´óCricket WirelessÊÚȨ¾­ÏúÉÌMobilelink USAÔâÓë¶íÂÞ˹¹ØÁªµÄÀÕË÷Èí¼þ×éÖ¯DragonForce¹¥»÷ £¬¸Ã×éÖ¯Ðû³ÆÇÔÈ¡³¬5TBÊý¾Ý²¢ÉèÖõ¹¼ÆÊ±Íþв ¡£DragonForceÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû²¼Mobilelink±ê¼Ç¼°¶à¼ÒÊܺ¦Õß±êʶ £¬ÒªÇóÆäÔÚÔ¼6Ìì16СʱÄÚÖª×ãÀÕË÷ÒªÇó £¬²»È»½«¹ûÕæ±»µÁÊý¾Ý ¡£Mobilelink×÷Ϊ¿ìËÙÀ©ÕŵĵçÐÅÔËÓªÉÌ £¬ÔÚÃÀ¹ú21¸öÖÝÔËÓª550¼ÒÁãÊÛµê £¬ÓµÓÐ650ÓàÃûÔ±¹¤ £¬×¨ÃÅÌṩÎÞºÏÔ¼5G LTE·þÎñ¡¢Ô¤¸¶·ÑÌײͼ°ÊÖ»úÅä¼þ ¡£´Ë´ÎÊý¾Ýй¶¿ÉÄܲ¨¼°Cricketĸ¹«Ë¾AT&TµÄ1300Íò¿Í»§ÈºÌå £¬µ¼ÖÂÊý°ÙÍòÃô¸ÐСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©¼°²ÆÎñÊý¾Ýй¶ £¬Ê¹ÊÜÓ°ÏìÓû§ÃæÁÙÉí·Ý͵ÇÔ¡¢ÍøÂç´¹ÂÚ¹¥»÷µÈΣº¦ ¡£DragonForceÊÇ2025Äê×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò» £¬¾ÝCybernews°µÍø¼à¿Ø¹¤¾ßÏÔʾ £¬¸Ã×éÖ¯2025ÄêÒѹ¥»÷185¸ö×éÖ¯ £¬ÆäÖÐ130´Î±¬·¢ÔÚ½üÁù¸öÔ ¡£


https://cybernews.com/news/cricket-wireless-mobilelink-usa-ransomware-attack-dragonforce/


2. MarquisÈí¼þÊý¾Ýй¶ÊÂÎñ²¨¼°40Íò½ðÈÚ¿Í»§


12ÔÂ3ÈÕ £¬½üÆÚ £¬Îª700Óà¼ÒÒøÐС¢ÐÅÓÃÉç¼°µäÖÊ´û¿î»ú¹¹ÌṩÊý¾ÝÆÊÎö¡¢CRM¹¤¾ßµÈ·þÎñµÄ½ðÈÚÈí¼þ¹©Ó¦ÉÌMarquis Software SolutionsÔâÓöÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÃÀ¹ú74¼Ò½ðÈÚ»ú¹¹µÄ40ÓàÍò¿Í»§Êý¾Ýй¶ ¡£¹¥»÷ͨ¹ý±£´æÎó²îµÄSonicWall·À»ðǽÈëÇÖϵͳ £¬ºÚ¿ÍÇÔÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢Éç»á°ü¹ÜºÅÂë¡¢ÄÉ˰ÈËʶÓÖÃûÂë¡¢ÎÞÇå¾²ÂëµÄ½ðÈÚÕË»§ÐÅÏ¢¼°³öÉúÈÕÆÚµÈÃô¸ÐÎļþ ¡£ÊÂÎñÓ°Ïì¹æÄ£ÁýÕÖÃåÒò¡¢°®ºÉ»ª¡¢µÂ¿ËÈøË¹µÈ¶àÖÝ £¬Éæ¼°±±¼ÓÖݵÚÒ»ÐÅÓÃÉç¡¢±´¶ûΤɪÉçÇøÐÅÓÃÉç¡¢Gateway First BankµÈ74¼Ò»ú¹¹ ¡£MarquisÔÚ֪ͨÖÐÇ¿µ÷ £¬ÏÖÔÚÎÞÖ¤¾ÝÏÔʾÊý¾Ý±»ÀÄÓûò¹ûÕæÐû²¼ £¬µ«ÒÑ´ú±í¿Í»§Ïò¸÷ÖÝÌá½»Ïêϸй¶±¨¸æ £¬²¿·ÖÖÝÎļþϸ·ÖÁËÊÜÓ°Ïì¿Í»§ÊýÄ¿ ¡£ÖµµÃ×¢ÖØµÄÊÇ £¬Community 1stÐÅÓÃÉçÒÑɾ³ýµÄÎļþÏÔʾ £¬MarquisÔøÖ§¸¶Êê½ðÒÔ×èÖ¹Êý¾Ýй¶ £¬¶øCoVantage Credit UnionµÄÎļþÔòÅû¶ÁËMarquisÔöÇ¿Çå¾²µÄÏêϸ²½·¥£º¸üзÀ»ðǽ²¹¶¡¡¢ÂÖ»»ÍâµØÕË»§ÃÜÂ롢ɾ³ýÈßÓàÕË»§¡¢ÆôÓöàÒòËØÈÏÖ¤¡¢ÑÓÉìÈÕÖ¾Áô´æÊ±¼ä¡¢ÊµÑéÕË»§Ëø¶¨Õ½ÂÔ¡¢ÏÞÖÆÅþÁ¬ÈªÔ´¹ú±ð¼°×Ô¶¯·â±Õ½©Ê¬ÍøÂçIP ¡£


https://www.bleepingcomputer.com/news/security/marquis-data-breach-impacts-over-74-us-banks-credit-unions/


3. WordPress²å¼þ¸ßΣÎó²îÒý·¢´ó¹æÄ£¹¥»÷


12ÔÂ3ÈÕ £¬¿ËÈÕ £¬WordPressƽ̨Á½¿îÈÈÃŲå¼þ½ÓÁ¬Ì»Â¶ÑÏÖØÇå¾²Îó²î £¬Òý·¢È«Çò³¬4.8Íò´Î¹¥»÷ʵÑé ¡£King Addons for Elementor²å¼þµÄCVE-2025-8489Îó²îÔÊÐí¹¥»÷ÕßÖ±½Ó»ñÈ¡ÍøÕ¾ÖÎÀíԱȨÏÞ ¡£¸ÃÎó²îÓÚ2025Äê10ÔÂ31ÈÕ¹ûÕæºó £¬WordfenceÇ徲ɨÃèÆ÷ÒÑ×èµ²48400Óà´Î¹¥»÷ £¬ÆäÖÐ11ÔÂ9ÈÕÖÁ10ÈÕµÖ´ïá¯Áë £¬Á½¸ö»îÔ¾IPµØµã»®·ÖÌᳫ28900´ÎºÍ16900´ÎʵÑé ¡£Ô¼10000¸öʹÓøòå¼þµÄÍøÕ¾ÃæÁÙΣº¦ £¬½¨ÒéÁ¬Ã¦Éý¼¶ÖÁ51.1.35°æ±¾ÐÞ¸´ ¡£Í¬ÆÚ £¬Advanced Custom Fields: Extended²å¼þµÄCVE-2025-13486Îó²îÒàÒý·¢¹Ø×¢ ¡£¸ÃÎó²î±£´æÓÚ0.9.0.5ÖÁ0.9.1.1°æ±¾ÖÐ £¬Óɲ¨À¼CERTÈÏÕæÈËMarcin Dudek·¢Ã÷²¢±¨¸æ ¡£¹¥»÷Õß¿ÉÔÚδÈÏÖ¤ÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂë £¬¿ÉÄÜÓÃÓÚ×¢ÈëºóÃÅ»ò½¨Éè¶ñÒâÖÎÀíÔ±ÕË»§ ¡£¸ÃÎó²îÓÚ11ÔÂ18ÈÕÅû¶ºó £¬¹©Ó¦ÉÌÔ½ÈÕ¼´Ðû²¼0.9.2°æ±¾ÐÞ¸´ £¬µ«¼øÓÚÊÖÒÕϸ½ÚÒѹûÕæ £¬×¨¼ÒÖÒÑÔ¿ÉÄÜÒý·¢ÐÂÒ»ÂÖ¶ñÒâ¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/critical-flaw-in-wordpress-add-on-for-elementor-exploited-in-attacks/


4. ·¨¹úÀÖ»ªÃ·À¼Åû¶Êý¾Ýй¶ÊÂÎñ


12ÔÂ3ÈÕ £¬·¨¹ú¼Ò¾Ó½¨²ÄÓëÔ°ÒÕÁãÊÛ¾ÞÍ·ÀÖ»ªÃ·À¼£¨Leroy Merlin£©¿ËÈÕ֪ͨ¿Í»§ £¬Æä²¿·ÖСÎÒ˽¼ÒÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖÐÔâÍⲿй¶ ¡£¸Ã¹«Ë¾ÓªÒµÁýÕÖÅ·ÖÞ¶à¹ú¼°ÄÏ·Ç¡¢°ÍÎ÷ £¬ÓµÓÐ16.5ÍòÃûÔ±¹¤ £¬ÄêÊÕÈë´ï99ÒÚÃÀÔª ¡£´Ë´ÎÊÂÎñ½öÓ°Ïì·¨¹ú¿Í»§ £¬Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢ÓÊÕþµØµã¡¢³öÉúÈÕÆÚ¼°»áÔ±ÍýÏëÏà¹ØÐÅÏ¢ £¬µ«²»Éæ¼°ÒøÐÐÕË»§ÃÜÂë»òÍøÉÏÕË»§Ãô¸ÐÊý¾Ý ¡£ÀÖ»ªÃ·À¼ÔÚ֪ͨÖÐÇ¿µ÷ £¬ÊÂÎñ±¬·¢ºóÒÑÁ¬Ã¦½ÓÄɲ½·¥×èֹδ¾­ÊÚȨ»á¼û²¢¿ØÖÆÊÂ̬Éú³¤ ¡£Ö»¹ÜÄ¿½ñÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢±»¶ñÒâʹÓûòÓÃÓÚÀÕË÷ £¬¹«Ë¾ÈÔÌáÐѿͻ§Ð¡ÐÄÍøÂç´¹ÂÚ¹¥»÷ £¬²¢ÌṩÁËʶ±ð·ÂÃ°Æ·ÅÆ´¹ÂÚÐÅÏ¢µÄÒªÁì ¡£Èô¿Í»§·¢Ã÷ÕË»§Òì³£Ô˶¯»ò»áÔ±ÕÛ¿Û¶Ò»»ÎÊÌâ £¬¿ÉÖ±½ÓÏò¹«Ë¾±¨¸æ ¡£ÏÖÔÚ £¬ÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ ¡£


https://www.bleepingcomputer.com/news/security/french-diy-retail-giant-leroy-merlin-discloses-a-data-breach/


5. Freedom MobileÅû¶Êý¾Ýй¶ÊÂÎñ


12ÔÂ3ÈÕ £¬¼ÓÄôóµÚËÄ´óÎÞÏßÔËÓªÉÌFreedom Mobile¿ËÈÕÅûÂ¶ÖØ´óÊý¾Ýй¶ÊÂÎñ ¡£¸Ã¹«Ë¾ÓÉGlobaliveÓÚ2008Ä꽨Éè £¬Ô­ÃûΪWind Mobile £¬2023Äê±»¿ý±±¿ËµçÐÅ×Ó¹«Ë¾Vid¨¦otronÊÕ¹ººó £¬ÐγÉÓµÓг¬350ÍòÒÆ¶¯Óû§¡¢½ü7500ÃûÔ±¹¤¼°ÁýÕÖ99%¼ÓÄôóÈ˵ķþÎñÍøÂç ¡£±¾´ÎÊÂÎñ±¬·¢ÓÚ2025Äê10ÔÂ23ÈÕ £¬¹¥»÷Õß̫ͨ¹ý°üÉ̱»µÁÕË»§ÈëÇÖ¿Í»§ÕË»§ÖÎÀíÆ½Ì¨ £¬ÇÔÈ¡Á˲¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ £¬Ïêϸ°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢ÊÖ»úºÅÂë¼°Freedom MobileÕË»§ºÅÂë ¡£¹«Ë¾ÉùÏÔ×Åʾ £¬ÊÂÎñ±¬·¢ºó £¬FreedomѸËÙ½ÓÄÉÐж¯ £¬ÆÁÕÏ¿ÉÒÉÕË»§¼°¶ÔÓ¦IPµØµã £¬²¢ÔöÇ¿Çå¾²²½·¥ ¡£Ö»¹ÜÏÖÔÚÎÞÖ¤¾ÝÅúעй¶Êý¾ÝÒѱ»ÀÄÓà £¬µ«ÔËÓªÉÌÈÔ½¨ÒéÊÜÓ°Ïì¿Í»§Ð¡ÐÄ´¹ÂÚ¹¥»÷ £¬×èÖ¹µã»÷¿ÉÒÉÁ´½Ó»òÏÂÔØ¸½¼þ £¬²¢°´ÆÚ¼ì²éÕË»§Òì³£Ô˶¯ ¡£Freedom Mobile½²»°ÈËÇ¿µ÷ £¬´Ë´ÎÊÂÎñ䲨¼°ÍøÂçºÍÔËӪϵͳ £¬²»ÊôÓÚÀÕË÷Èí¼þ¹¥»÷ÀàÐÍ £¬µ«Î´Í¸Â¶ÏêϸÊÜÓ°Ïì¿Í»§ÊýÄ¿ ¡£×÷Ϊ¼ÓÄôóÖ÷ÒªµçÐÅ·þÎñÉÌ £¬FreedomµÄÊý¾Ýй¶¿ÉÄÜÒý·¢¿Í»§ÐÅÍÐΣ»ú¼°î¿ÏµÉó²é ¡£


https://www.bleepingcomputer.com/news/security/freedom-mobile-discloses-data-breach-exposing-customer-data/


6. ·ï»Ë³Ç´óѧÓöClop¹¥»÷ÖÂʦÉúÊý¾Ýй¶


12ÔÂ3ÈÕ £¬ÃÀ¹ú·ï»Ë³Ç´óѧ£¨UoPX£©8Ô³ÉΪClopÀÕË÷Èí¼þÍÅ»ïʹÓÃOracle E-Business Suite£¨EBS£©ÁãÈÕÎó²î£¨CVE-2025-61882£©¹¥»÷µÄÄ¿µÄ £¬µ¼Ö´ó×ÚÃô¸ÐÊý¾Ýй¶ ¡£ÕâËù½¨ÉèÓÚ1976ÄêµÄ˽Á¢ÓªÀûÐÔ´óѧӵÓнü3000Ãû½ÌÖ°Ô±¹¤ºÍ³¬10ÍòÔÚУѧÉú £¬Æäĸ¹«Ë¾Phoenix Education PartnersÒÑÏòÃÀ¹ú֤ȯÉúÒâίԱ»áÌá½»8-K±í¸ñÅû¶ÊÂÎñ ¡£¹¥»÷Õßͨ¹ýOracle EBS²ÆÎñÓ¦ÓóÌÐòµÄÎó²îÇÔÈ¡ÁËÏÖÈμ°Ç°ÈÎѧÉú¡¢½ÌÖ°¹¤¡¢¹©Ó¦É̵ÄÐÕÃû¡¢ÁªÏµ·½·¨¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂë¡¢ÒøÐÐÕË»§¼°Â·ÓɺÅÂëµÈÃô¸ÐÐÅÏ¢ ¡£ÔÚClop½«ÆäÁÐÈëÊý¾ÝÐ¹Â¶ÍøÕ¾ºó £¬UoPXÓÚ11ÔÂ21ÈÕ·¢Ã÷ÊÂÎñ £¬²¢ÌåÏÖ½«Éó²éÊÜÓ°ÏìÊý¾Ý £¬Í¨¹ýÃÀ¹úÓÊÕþÏòÊÜÓ°ÏìСÎÒ˽¼Ò¼ÄËÍ֪ͨ £¬Í¬Ê±Ïòî¿Ïµ»ú¹¹±¨¸æ ¡£ÏÖÔÚ £¬Ñ§Ð£Î´Í¸Â¶ÏêϸÊÜÓ°ÏìÈËÊý¼°Ä»ºóºÚÊÖ £¬µ«¹ûÕæÐÅÏ¢Ö¸ÏòClopÍÅ»ï ¡£·ï»Ë³Ç´óѧǿµ÷ÒѽÓÄɲ½·¥×èֹΣº¦ £¬µ«Î´²¨¼°½¹µãÍøÂçÔËÓª ¡£


https://www.bleepingcomputer.com/news/security/university-of-phoenix-discloses-data-breach-after-oracle-hack/