Spotify²¥·ÅÁбíÓë²¥¿Í³É·Ç·¨·Ö×ÓÍÆ¹ãµÁ°æÈí¼þÐÂÇþµÀ

Ðû²¼Ê±¼ä 2024-11-21

1. Spotify²¥·ÅÁбíÓë²¥¿Í³É·Ç·¨·Ö×ÓÍÆ¹ãµÁ°æÈí¼þÐÂÇþµÀ


11ÔÂ19ÈÕ£¬Spotifyƽ̨ÉϵIJ¥·ÅÁбíºÍ²¥¿Í±»·Ç·¨·Ö×ÓÀÄÓã¬ÓÃÓÚÍÆ¹ãµÁ°æÈí¼þ¡¢ÓÎÏ·×÷±×Âë¡¢À¬»øÁ´½ÓºÍ¡°µÁ°æÈí¼þ¡±ÍøÕ¾¡£Í¨¹ýÔÚ²¥·ÅÁбíÃû³ÆºÍ²¥¿ÍÃèÊöÖÐǶÈëÄ¿±êÒªº¦×ÖºÍÁ´½Ó£¬ÕâЩÍþвÐÐΪÕßÄܹ»´ÓÌáÉýÆä¿ÉÒÉÔÚÏß×ʲúµÄSEOÖÐÊÜÒæ£¬ÒòΪSpotifyµÄÍøÂç²¥·ÅÆ÷½á¹û»á·ºÆðÔÚGoogleµÈËÑË÷ÒýÇæÖС£ÀýÈ磬ÓÐÍøÂçÄþ¾²×¨¼Ò·¢ÏÖÁ˱êÌâΪ¡°Sony Vegas Pro 13 Crack...¡±µÄSpotify²¥·ÅÁбí£¬¸ÃÁÐ±í½«Á÷Á¿Òýµ¼ÖÁ²¥·ÅÁбí±êÌâºÍÃèÊöÖÐÁгöµÄ¡°Ãâ·Ñ¡±Èí¼þÍøÕ¾¡£´ËÍ⣬²¥¿ÍÒ²±»ÓÃÓÚÐû´«À¬»øÁ´½Ó¡¢¿´ËÆÆ­¾ÖµÄµç±¨ÆµµÀµÈ¡£ÕâЩÁ´½Óͨ³£»áÒýµ¼Óû§ÖÁ³äÂú¹ã¸æ¡¢À¬»øÄÚÈÝ¡¢Ðé¼Ù¡°ÊӲ족ºÍ¼ÓÃÜÔùÆ·µÄ·þÎñÆ÷£¬Óû§±ØÐëä¯ÀÀÕâЩÐÅÏ¢²ÅÆø×îÖÕÏÂÔØÆÆ½âµÄÈí¼þ²úÎ¶øÕâ»á´øÀ´·çÏÕ¡£SpotifyÒÑɾ³ýÏà¹Ø²¥·ÅÁбíºÍ²¥¿Í£¬²¢ÌåÏÖÆäÆ½Ì¨¹æÔò½ûÖ¹Ðû²¼¡¢·ÖÏí»òÌṩÓйØÊµÊ©¶ñÒâÈí¼þ»òÏà¹Ø¶ñÒâÐÐΪµÄ˵Ã÷¡£Í¬Ê±£¬µÚÈý·½Ó¦Ó÷¨Ê½ºÍ·þÎñÒ²±»ÍþвÐÐΪÕßÀûÓÃÀ´½«À¬»øÄÚÈÝÒýÈëÆ½Ì¨¡£


https://www.bleepingcomputer.com/news/security/spotify-abused-to-promote-pirated-software-and-game-cheats/


2. Great Plains Regional Medical CenterÔâÀÕË÷Èí¼þ¹¥»÷£¬133,000ÈËÊý¾Ýй¶


11ÔÂ19ÈÕ£¬Great Plains Regional Medical Center£¨Î»ÓÚ¶í¿ËÀ­ºÉÂíÖÝ£©ÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ133,149È˵ĸöÈËÊý¾ÝÔ⵽й¶¡£ÔÚ2024Äê9ÔÂ5ÈÕÖÁ8ÈÕÆÚ¼ä£¬Ò»ÃûÍþвÐÐΪÕß·ÃÎʲ¢¼ÓÃÜÁ˸ÃÒ½ÁÆÖÐÐÄϵͳÉϵÄÎļþ£¬²¢¿ÉÄܸ´ÖÆÁËÆäÖÐһЩÎļþ¡£¸ÃÒ½ÁÆÖÐÐÄÔÚÍøÂçÄþ¾²¹«Ë¾µÄЭÖúÏÂÕ¹¿ªÁËÊӲ죬²¢Ñ¸ËÙ»Ö¸´ÁËϵͳ£¬µ«ÓÐÏÞÊýÁ¿µÄ»¼ÕßÐÅÏ¢ÎÞ·¨»Ö¸´¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄܰüÂÞÐÕÃû¡¢ÈË¿Úͳ¼ÆÐÅÏ¢¡¢½¡¿µ±£ÏÕÐÅÏ¢¡¢ÁÙ´²ÖÎÁÆÐÅÏ¢¡¢¼ÝʻִÕÕºÅÂëÒÔ¼°Éç»áÄþ¾²ºÅÂëµÈÃô¸ÐÊý¾Ý¡£¸ÃÒ½ÁÆÖÐÐÄÕýÔÚ֪ͨÊÜÓ°ÏìµÄ»¼Õߣ¬²¢ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓÃ¼à¿Ø¡£È»¶ø£¬¸ÃÒ½ÁÆÖÐÐIJ¢Î´Í¸Â¶Óйع¥»÷ÆäϵͳµÄÀÕË÷Èí¼þ¼Ò×åµÄÐÅÏ¢£¬Ä¿Ç°Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´ÎÄþ¾²Â©¶´ÂôÁ¦¡£


https://securityaffairs.com/171156/data-breach/great-plains-regional-medical-center-data-breach.html


3. EquinoxÊý¾Ýй¶Ê¼þ£ºLockBitÀÕË÷Èí¼þÍÅ»ïÒÉΪĻºóºÚÊÖ


11ÔÂ20ÈÕ£¬Å¦Ô¼ÖÝÎÀÉúÓ빫ÖÚ·þÎñ×éÖ¯Equinox֪ͨÁè¼Ý21,000Ãû¿Í»§ºÍÔ±¹¤£¬ËûÃÇÔÚ½üÆß¸öÔÂǰµÄÒ»´ÎÊý¾ÝÄþ¾²Ê¼þÖУ¬¸öÈ˽¡¿µ¡¢²ÆÕþµÈÐÅÏ¢±»µÁ¡£¾ÝÍÆ²â£¬Õâ´ÎʼþÓɱ¾Ó¦Òѱ»¹Ø±ÕµÄLockBitÀÕË÷Èí¼þÍÅ»ïËùΪ¡£EquinoxΪŦԼÖÝÊ׸®µØÓòÌṩÐÄÀí½¡¿µ¡¢½äñ«·þÎñ¡¢¼ÒÍ¥±©Á¦Ö§³ÖµÈ¶àÏî·þÎñ¡£4ÔÂ29ÈÕ£¬¸Ã×éÖ¯ÍøÂç·ÃÎÊÖжÏ£¬Ëæºó·¢ÏÖÍøÂçÖеÄijЩÎļþ¿ÉÄܱ»Î´¾­ÊÚȨ·ÃÎÊ»òÏÂÔØ¡£9ÔÂ16ÈÕ£¬EquinoxÈ·ÈÏijЩÈ˵ĸöÈ˺ÍÊܱ£»¤µÄ½¡¿µÐÅÏ¢¿ÉÄÜÒò´ËʼþÊÜÓ°Ïì¡£ÖµµÃ×¢ÒâµÄÊÇ£¬LockBit 3.0ÀÕË÷Èí¼þ×éÖ¯ÔøÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöEquinox£¬Éù³ÆÇÔÈ¡ÁË49GBÊý¾Ý£¬²¢×îÖÕй¶ÁË31.8GBÎļþ¡£¾¡¹ÜLockBitÔÚ2Ô·ÝÊܵ½¸ßµ÷ÆÆ»µ£¬µ«×èÖ¹ÀÕË÷Èí¼þ»öº¦ÈÔÈ»·Ç³£À§ÄÑ£¬LockBit 3.0ÈÔÊǽñÄê×î»îÔ¾µÄ¼ÓÃܺÍÀÕË÷ÍÅ»ïÖ®Ò»¡£


https://www.theregister.com/2024/11/20/equinox_patients_employees_data/


4. Oracle PLM¿ò¼Ü¸ßΣ©¶´Ôâ¹ã·ºÀûÓã¬Óû§Ð辡¿ì´ò²¹¶¡


11ÔÂ20ÈÕ£¬Oracle½üÆÚÐû²¼¾¯¸æ£¬Ö¸³öÆäÃô½Ý²úÎïÉúÃüÖÜÆÚ¹ÜÀí£¨PLM£©¿ò¼ÜÖдæÔÚÒ»¸öÒѱ»¹ã·ºÀûÓõĸßÑÏÖØÐÔÄþ¾²Â©¶´£¬±àºÅΪCVE-2024-21287£¬CVSSÆÀ·ÖΪ7.5¡£¸Ã©¶´ÎÞÐèÉí·ÝÑéÖ¤¼´¿É±»Ô¶³ÌÀûÓ㬿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶£¬°üÂÞÎļþÄÚÈÝ¡£OracleÔÚͨ¸æÖÐÇ¿µ÷£¬ÎÞÐèÓû§ÃûºÍÃÜÂ룬¹¥»÷Õß¼´¿Éͨ¹ýÍøÂçÔ¶³Ì¹¥»÷£¬ÀÖ³ÉÀûÓøÃ©¶´ºóÄܹ»ÏÂÔØPLMÓ¦Ó÷¨Ê½È¨ÏÞÏ¿ɷÃÎʵÄÎļþ¡£CrowdStrikeµÄÄþ¾²Ñо¿ÈËÔ±Joel SnapeºÍLutz WolfÒò·¢ÏÖ²¢³ÂËß´Ë©¶´¶øÊܵ½ÔÞÓþ¡£È»¶ø£¬Ä¿Ç°Éв»Çå³þË­ÔÚÀûÓôË©¶´¡¢¶ñÒâ»î¶¯µÄÄ¿±êÊÇË­ÒÔ¼°¹¥»÷·¶Î§Óжà¹ã¡£OracleÄþ¾²±£Õϸ±×ܲÃEric Maurice½¨ÒéÓû§¾¡¿ìÓ¦ÓÃ×îв¹¶¡ÒÔ»ñµÃ×î¼Ñ±£»¤¡£


https://thehackernews.com/2024/11/oracle-warns-of-agile-plm-vulnerability.html


5. WordPress²å¼þReally Simple SecurityÏÖÑÏÖØÂ©¶´£¬Ó°Ï쳬400Íò¸öÍøÕ¾


11ÔÂ18ÈÕ£¬WordPress²å¼þReally Simple Security´æÔÚÑÏÖØÂ©¶´£¬Ó°ÏìÁËÁè¼Ý400Íò¸öÍøÕ¾£¬Ê¹¹¥»÷ÕßÄܹ»»ñµÃÍêÈ«µÄ¹ÜÀíÔ±·ÃÎÊȨÏÞ¡£¸Ã©¶´±àºÅΪCVE-2024-10924£¬CVSSÆÀ·ÖΪ9.8£¬ÊÇWordfenceÑо¿ÈËÔ±Istv¨¢n M¨¢rtonÔÚ2024Äê11ÔÂ6ÈÕ·¢Ïֵġ£Really Simple Security£¨ÒÔǰ³ÆÎªReally Simple SSL£©ÊÇÒ»¿îÁ÷ÐеÄWordPress¹¤¾ß£¬ÓÃÓÚÔöÇ¿ÍøÕ¾Äþ¾²ÐÔ¡£È»¶ø£¬¸Ã²å¼þÔÚË«ÒòËØÉí·ÝÑéÖ¤¹¦Ð§ÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¬µ±ÆôÓøù¦Ð§Ê±£¬¹¥»÷Õß¿ÉÒÔÔ¶³Ì·ÃÎÊÍøÕ¾ÉϵÄÈκÎÕÊ»§£¬°üÂÞ¹ÜÀíÔ±ÕÊ»§¡£Â©¶´ÊÇÓÉÓÚÔÚË«ÒòËØREST API²Ù×÷ÖжÔÓû§¼ì²é´íÎó´¦Öò»Í×Ôì³ÉµÄ¡£Ñо¿ÈËÔ±¾¯¸æ³Æ£¬¸Ã©¶´¿É±àд½Å±¾£¬ÔÊÐí¹¥»÷ÕßÔÚ´ó¹æÄ£×Ô¶¯¹¥»÷ÖÐ×Ô¶¯ÀûÓᣴ˩¶´½öÓ°ÏìÔÚ²å¼þÉèÖÃÖÐÆôÓÃÁË¡°Ë«ÒòËØÉí·ÝÑéÖ¤¡±µÄWordPressÍøÕ¾£¬Ó°Ï췶Χ°üÂÞ¡°Ãâ·Ñ°æ¡±¡¢¡°×¨Òµ°æ¡±ºÍ¡°×¨Òµ¶àÕ¾µã°æ¡±µÄ²å¼þ°æ±¾9.0.0ÖÁ9.1.1.1¡£¸Ã©¶´ÒÑÔÚ9.1.2°æÖÐÐÞ¸´£¬Äþ¾²¸üÐÂÒÑÐû²¼£¬µ«¹ÜÀíÔ±Ó¦ÑéÖ¤ËûÃÇÊÇ·ñʹÓõÄÊÇ×îа汾¡£


https://securityaffairs.com/171100/hacking/really-simple-security-plugin-flaw-affects-4m-sites.html


6. ·¨¹úÒ½ÔºÊý¾Ýй¶£º75Íò»¼Õ߼ǼÔâÆØ¹â


11ÔÂ20ÈÕ£¬Ò»ÆðÉæ¼°·¨¹úÒ½ÔºµÄÊý¾Ýй¶Ê¼þÒý·¢Á˹㷺¹Ø×¢¡£Ò»Ãû×Ô³ÆÎª¡°nears¡±µÄÍþвÐÐΪÕßÉù³Æ¹¥»÷Á˶à¼Ò·¨¹úÒ½ÁÆ»ú¹¹£¬ÄÜ·ÃÎÊÁè¼Ý150ÍòÈ˵IJ¡Àú¡£¾ßÌå¶øÑÔ£¬ºÚ¿Íͨ¹ýÈí¼þÒ½ÁƼ¯ÍÅÈëÇÖÁËÌṩµç×Ó²¡Àú½â¾ö·½°¸µÄMediBoard£¬µ¼ÖÂÒ»¼Òδ¾ßÃûµÄ·¨¹úÒ½Ôº75ÍòÓàÃû»¼ÕßµÄÒ½ÁƼǼ±»Ð¹Â¶¡£ÕâЩ¼Ç¼°üÂÞ»¼ÕßµÄÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢ÐԱ𡢼Òͥסַ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Ò½ÉúÐÅÏ¢¡¢´¦·½¼°½¡¿µ¿¨ÀúÊ·µÈÃô¸ÐÊý¾Ý¡£Softway Medical GroupÈ·ÈϺڿÍÈëÇÖÁËMediBoardÕÊ»§£¬µ«Ç¿µ÷Êý¾Ýй¶²¢·ÇÈí¼þ©¶´»òÅäÖôíÎóËùÖ£¬¶øÊÇҽԺʹÓÃÁ˱»µÁµÄƾ¾Ý¡£ºÚ¿ÍÉõÖÁ¿ªÊ¼³öÊÛËûÃÇÉù³ÆµÄMediBoardƽ̨·ÃÎÊȨÏÞ£¬Éæ¼°¶à¼Ò·¨¹úÒ½Ôº£¬ÔÊÐíÂò·½¼ì²ìÒ½ÔºµÄÃô¸ÐÒ½ÁƱ£½¡ºÍÕ˵¥ÐÅÏ¢¡¢»¼Õ߼Ǽ£¬²¢¾ß±¸²¿ÊðºÍÐÞ¸ÄÔ¤Ô¼»òÒ½ÁƼǼµÄÄÜÁ¦¡£¾¡¹ÜÊý¾ÝÉÐδ±»¹ûÈ»³öÊÛ£¬µ«´æÔÚÃâ·Ñй¶µ½ÍøÉϵķçÏÕ£¬Ôö¼ÓÁËÊÜÓ°ÏìÈËÔ±ÔâÊÜÍøÂçµöÓã¡¢Õ©Æ­ºÍÉç»á¹¤³Ì¹¥»÷µÄ¿ÉÄÜÐÔ¡£


https://www.bleepingcomputer.com/news/security/cyberattack-at-french-hospital-exposes-health-data-of-750-000-patients/