ÍøÂç·¸×ïÕßÀûÓÃWMI×é¼þBMOF´«²¼XMRigÍÚ¿ó¶ñÒâÈí¼þ

°ä²¼¹¦·ò 2024-09-12
1. ÍøÂç·¸×ïÕßÀûÓÃWMI×é¼þBMOF´«²¼XMRigÍÚ¿ó¶ñÒâÈí¼þ


9ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬AhnLab °²È«µý±¨ÖÐÐÄ£¨ASEC£©½üÆÚ½ÒʾÁËÒ»ÖÖÁîÈ˾¯ÌèµÄÍøÂç·¸×ïÐÂÇ÷Ïò£¬ £¬£¬£¬£¬£¬£¬¼´·¸×ï·Ö×ÓÆæÃîÀûÓöþ½øÔìÖÎÀí¶ÔÏóÎļþ£¨BMOF£©£¬ £¬£¬£¬£¬£¬£¬ÕâÊÇÔÚWindowsÖÎÀí¹æ·¶£¨WMI£©ÖÐÖÁ¹Ø³ÁÒªµÄ×é¼þ£¬ £¬£¬£¬£¬£¬£¬×÷Ϊ´«²¼XMRig¼ÓÃÜÇ®±ÒÍÚ¿ó¶ñÒâÈí¼þµÄÔØÌå¡£¡£¡£¡£ ¡£BMOFÕý±¾ÓÃÓÚÖ´Ðо籾µÄÖ°Äܱ»¶ñÒâÀûÓ㬠£¬£¬£¬£¬£¬£¬Í¨¹ý´´½¨¡°ÓÀÔ¶ÊÂÎñ¶©ÔÄ¡±»úÔ죬 £¬£¬£¬£¬£¬£¬ÊµÏÖ¶ñÒâÈí¼þµÄÓÆ¾Ã»¯´æÔÚÓë×ÔÎÒ¸´Ô­ÄÜÁ¦£¬ £¬£¬£¬£¬£¬£¬¼«´ó¼ÓÇ¿Á˹¥»÷Õß¶ÔÊܺ¦ÏµÍ³µÄ½ÚÔìÁ¦¡£¡£¡£¡£ ¡£´Ë¹¥»÷ÊÖ·¨³£ÓëBondNet¶ñÒâÈí¼þЭͬ£¬ £¬£¬£¬£¬£¬£¬ºóÕßר¹¥SQL·þÎñÆ÷£¬ £¬£¬£¬£¬£¬£¬Í¨¹ý·ì϶ÀûÓûò±©Á¦ÆÆ½â»ñÈ¡³õʼ½Ó¼ûȨ£¬ £¬£¬£¬£¬£¬£¬ËæºóÀûÓÃBMOFÏÂÔØ²¢Ö´Ðиü¶à¶ñÒâ×é¼þ£¬ £¬£¬£¬£¬£¬£¬×îÖÕ²¿ÊðXMRigÍÚ¿óÈí¼þ¡£¡£¡£¡£ ¡£XMRig×÷ΪһÖÖ¼ÓÃܽٳֶñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬ÇÄÎÞÉùÏ¢µØÕ¼ÓÃÊܺ¦Õßϵͳ×ÊÔ´ÍÚ¾òÃÅÂÞ±Ò£¬ £¬£¬£¬£¬£¬£¬¶Ôϵͳ»úÄÜÓëÄܺÄÔì³ÉÏÔÖø¸ºÃæÓ°Ï죬 £¬£¬£¬£¬£¬£¬Îª¹¥»÷Õßıȡ·¸·¨ÀûÒæ¡£¡£¡£¡£ ¡£


https://securityonline.info/cybercriminals-exploit-legitimate-windows-tool-for-cryptojacking/


2. Ð嵀 PIXHELL Éùѧ¹¥»÷й¶ÁËÒº¾§ÆÁÄ»ÔëÒôµÄ°ÂÃØ


9ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÐÂÐÍÉùѧ¹¥»÷¡°PIXHELL¡¹Ø¹Ê¾ÁË´Ó¸ôÀëϵͳÖÐÒþÃØÐ¹Â¶ÐÅÏ¢µÄ׳´óÄÜÁ¦£¬ £¬£¬£¬£¬£¬£¬Ëüͨ¹ýÏνӵÄLCDÏÔʾÆ÷·¢³öÈ˶úÄÑÒÔ¾õ²ìµÄÉù²¨£¨0-22 kHz£©£¬ £¬£¬£¬£¬£¬£¬ÀûÓÃÏñËØÄ£Ê½µ÷Ôì´«µÝ±àÂëÐźÅ£¬ £¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÄܱ»×ó½üµÄÖÇÄÜÉ豸²¶»ñ¡£¡£¡£¡£ ¡£Ö»¹ÜÊý¾Ý´«ÊäËٶȽÏÂý£¨½ö20 bps£©£¬ £¬£¬£¬£¬£¬£¬µ«Ëü×ãÒÔ½øÐÐʵʱ¼üÅ̼ͼ»òÇÔÈ¡Ó×Îı¾Îļþ¡£¡£¡£¡£ ¡£PIXHELLÓÉÒÔÉ«ÁÐÄڸǷò±¾¡¤¹ÅÀï°²´óѧµÄMordechai Guri²©Ê¿¿ª·¢£¬ £¬£¬£¬£¬£¬£¬ÀûÓÃÁËLCDÆÁÄ»µÄÌìÈ»Éù·¢Éä¸öÐÔ£¬ £¬£¬£¬£¬£¬£¬½áºÏÌØÔì¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬Í¨¹ý·ÖÆçµÄµ÷Ôì¼¼Êõ£¨ÈçOOK¡¢FSK¡¢ASK£©½«Êý¾Ý±àÂëΪÉùÒôÐźÅ¡£¡£¡£¡£ ¡£ÓÉÓÚÕâЩÉùÒôºÍÏñËØ±ä¶¯¶ÔÈËÀàÓû§¶øÑÔÏÕЩ²»Ë½¼û£¬ £¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷¼«ÆäÒñ±Î¡£¡£¡£¡£ ¡£Ãæ¶ÔPIXHELL¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¿É²ÉÈ¡µÄ·ÀÓù´ëÊ©Ô̺¬£ºÔÚÃô¸ÐÇøÓò½ûÓÃЯ´øÂó¿Ë·çµÄÉ豸£¬ £¬£¬£¬£¬£¬£¬Ôö³¤²¼¾°ÔëÉùÒÔ×ÌÈÅÐźÅ£¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃÉãÏñÍ·¼à¿ØÆÁÄ»»º³åÇøÒÔ¼ì²âÒì³£ÏñËØÄ£Ê½¡£¡£¡£¡£ ¡£ÕâЩ´ëÊ©¹²Í¬×é³ÉÁËÒ»¸ö¶àµµ´ÎµÄ°²È«·À»¤Íø£¬ £¬£¬£¬£¬£¬£¬Ö¼ÔÚÓÐЧÕмܴËÀàÐÂÐÍÉùѧ²àÐÅ·¹¥»÷¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/new-pixhell-acoustic-attack-leaks-secrets-from-lcd-screen-noise/


3. Kemper Sports ManagementÊý¾Ýй¶£¬ £¬£¬£¬£¬£¬£¬Ó°Ïì6.2ÍòÈË


9ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬¸ß¶û·òÇò³¡ÖÎÀí¼°¾Æµê·þÎñÌṩÉÌKemper Sports Management°ä·¢ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬£¬£¬²¨¼°6.2ÍòÃûÓ×ÎÒ£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÉæ¼°ÆäÏÖÈμ°Ç°ÈÎÔ±¹¤µÄÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃûºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£ ¡£¹«Ë¾ÓÚ2024Äê4ÔÂ1ÈÕ¾õ²ìÍøÂçÒì³££¬ £¬£¬£¬£¬£¬£¬¾­µ÷²éÈ·ÈÏ£¬ £¬£¬£¬£¬£¬£¬²»Ã÷ÍþвÕßÒÑ·¸·¨ÇÖÈëϵͳ²¢»ñÈ¡ÁËÕâЩÐÅÏ¢¡£¡£¡£¡£ ¡£Õâ´Îй¶ÊÂÎñÓ°ÏìÁìÓò¿í·º£¬ £¬£¬£¬£¬£¬£¬²¨¼°KemperSportsÔÚÃÀ¹ú30¸öÖݵij¬¹ý7,500ÃûÔ±¹¤£¬ £¬£¬£¬£¬£¬£¬¸²¸ÇÆä140¶à¸ö·ÖÖ§»ú¹¹¡£¡£¡£¡£ ¡£Ö»¹ÜĿǰÉÐÎÞÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»¶ñÒâÀûÓÃÓÚÉí·Ý͵ÇÔ»òڲƭ»î¶¯£¬ £¬£¬£¬£¬£¬£¬KemperSportsÒÑѸËÙ²ÉÈ¡Ðж¯£¬ £¬£¬£¬£¬£¬£¬ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩһÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý¸´Ô­·þÎñ×÷ΪÅâ³¥¡£¡£¡£¡£ ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ £¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ²¢Î´Ã÷È·Ö¸ÏòÈκÎÒÑÖªµÄÀÕË÷Èí¼þ×éÖ¯£¬ £¬£¬£¬£¬£¬£¬ÇÒ¹«Ë¾Ç¿µ÷£¬ £¬£¬£¬£¬£¬£¬¼´±ãÉæ¼°Êê½ðÖ§¸¶£¬ £¬£¬£¬£¬£¬£¬ÆäÒ²²»»á³ÉΪйÃÜÐÅÏ¢µÄ¹«¿ª¶ÔÏ󡣡£¡£¡£ ¡£´ËÐÂÎÅѸËÙÒýÆð˾·¨½çµÄ¹Ø×¢£¬ £¬£¬£¬£¬£¬£¬¶à¼ÒÂÉʦÊÂÎñËùÒѰ䲼ÉêÃ÷£¬ £¬£¬£¬£¬£¬£¬Òâͼ´ú±íÊܺ¦ÕßÏòKemperSportsÌáÒ鼯ÌåËßËÏ¡£¡£¡£¡£ ¡£


https://www.securityweek.com/data-breach-at-golf-course-management-firm-kempersports-impacts-62000/


4. ÍøÂç´¹µöÐÂÇ÷Ïò£ºÓòÃûÇÀ×¢ÓëÆ·ÅÆ¼ÙÒâËÁŰ


9ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬Zscaler ThreatLabz×îл㱨½ÒʾÁËÍøÂç´¹µö»î¶¯ÕýÒÔǰËùδÓеÄËÙ¶ÈÔö³¤£¬ £¬£¬£¬£¬£¬£¬³ö¸ñÊÇͨ¹ýÓòÃûÇÀ×¢ºÍÆ·ÅÆ¼ÙÒ⼿Á©¡£¡£¡£¡£ ¡£ÔÚ2024Äê2ÔÂÖÁ7ÔÂÆÚ¼ä£¬ £¬£¬£¬£¬£¬£¬×êÑÐÍŶӷÖÎöÁ˳¬¹ý3Íò¸öÓëÈ«Çò³ÛÃûÆ·ÅÆÀàËÆµÄÓòÃû£¬ £¬£¬£¬£¬£¬£¬·¢ÏÔìäÖÐÈý·Ö֮һΪ¶ñÒâÓòÃû£¬ £¬£¬£¬£¬£¬£¬ÓÈÒԹȸ衢΢ÈíºÍÑÇÂíÑ·µÈ¿Æ¼¼¾ÞͷΪ¼ÙÒâ³ÁÔÖÇø£¬ £¬£¬£¬£¬£¬£¬Õ¼±È½üËÄ·ÖÖ®Èý¡£¡£¡£¡£ ¡£ÕâЩ¹¥»÷ÕßÀûÓÃÆ·ÅƳÛÃû¶ÈºÍÓû§ÐÅÀµ£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýÇá΢ƴдÃýÎóµÄÓòÃûÓÕÆ­Óû§½øÈë¶ñÒâÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬ÀûÓñ»µÁƾ֤ѸËÙ±äÏÖ¡£¡£¡£¡£ ¡£»£»£»£»£»¥ÁªÍø·þÎñÐÐÒµ³ÉÎªÍøÂç´¹µöµÄÖØÒªÖ¸±ê£¬ £¬£¬£¬£¬£¬£¬Õ¼±È½üÈý³É£¬ £¬£¬£¬£¬£¬£¬×¨Òµ·þÎñÓëÔÚÏß¹ºÎïÍøÕ¾½ôËæÆäºó£¬ £¬£¬£¬£¬£¬£¬ÒòÆä´¦ÖôóÁ¿Ãô¸ÐºÍ²ÆÕþÊý¾Ý¶ø±¸ÊÜÇàíù¡£¡£¡£¡£ ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ £¬£¬£¬£¬£¬£¬½ü°ë´¹µöÓòÃûѡȡÃâ·ÑµÄLet's Encrypt TLSÖ¤Êé¼Ù×°ºÏ·¨£¬ £¬£¬£¬£¬£¬£¬ÀûÓá°¹ÒËø¡±·ûºÅÎóµ¼Óû§£¬ £¬£¬£¬£¬£¬£¬ÌÓ±Üä¯ÀÀÆ÷°²È«ÖҸ档¡£¡£¡£ ¡£¼øÓÚÓòÃûÇÀ×¢ºÍÆ·ÅÆ¼ÙÒâ»î¶¯³ÖÐø·è¿ñ£¬ £¬£¬£¬£¬£¬£¬ÌáÉýÓû§·À±¸ÒâʶºÍ¼ÓÇ¿ÆóÒµÍøÂ簲ȫ´ëÊ©Èç¼¢ËÆ¿Ê¡£¡£¡£¡£ ¡£


https://securityonline.info/cybercriminals-increasingly-target-google-microsoft-and-amazon-in-sophisticated-phishing-schemes/


5. LearnPressÆØ·ì϶CVE-2024-8522£¬ £¬£¬£¬£¬£¬£¬Íþв³¬9Íò¸öÍøÕ¾°²È«


9ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬LearnPressÊÇÒ»¿î¹ãÊÜ»¶Ó­µÄWordPressÔÚÏ߿γÌÖÎÀí¹¤¾ß²å¼þ£¬ £¬£¬£¬£¬£¬£¬½üÆÚ±»·¢ÏÖ´æÔÚÒ»¸ö¸ßΣSQL×¢Èë·ì϶£¬ £¬£¬£¬£¬£¬£¬±àºÅΪCVE-2024-8522£¬ £¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï10£¬ £¬£¬£¬£¬£¬£¬Åú×¢¸Ã·ì϶ӵÓм«¸ßµÄÑϳÁÐÔ¡£¡£¡£¡£ ¡£´Ë·ì϶DZ²ØÓÚLearnPressµÄREST API¶ËµãÖУ¬ £¬£¬£¬£¬£¬£¬¾ßÌ幨Áªµ½¡°c_only_fields¡±²ÎÊýµÄ´¦Öò»µ±£¬ £¬£¬£¬£¬£¬£¬Òò²»×ã×ã¹»µÄתÒå´ëÊ©ºÍSQL²éÎʳﱸ£¬ £¬£¬£¬£¬£¬£¬Ê¹µÃδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜ×¢Èë¶ñÒâSQL´úÂ룬 £¬£¬£¬£¬£¬£¬½ø¶ø¿ÉÄܽӼû²¢ÇÔÈ¡´æ´¢ÔÚWordPressÊý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÈçÓû§Æ¾Ö¤¡¢Ó×ÎÒÊý¾Ý¼°¿Î³Ì×ÊÁÏ¡£¡£¡£¡£ ¡£¼øÓÚLearnPressÕ¼Óг¬¹ý90,000¸ö»îÔ¾×°ÖÃÁ¿£¬ £¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁìÓò¿í·ºÇÒÉîÔ¶£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÄÜÀûÓô˷ì϶Åú¸Ä»òɾ³ýÊý¾Ý¿âÄÚÈÝ£¬ £¬£¬£¬£¬£¬£¬ÆëÈ«½ÚÔìÊÜÓ°ÏìµÄÍøÕ¾¡£¡£¡£¡£ ¡£¼øÓڸ÷ì϶µÄ¼òÒ×ÀûÓÃÐԺ͸߷çÏÕÐÔ£¬ £¬£¬£¬£¬£¬£¬ËùÓÐʹÓÃLearnPressµÄWordPressÍøÕ¾¾ùÃæ¶ÔÖ±½Ó·çÏÕ¡£¡£¡£¡£ ¡£LearnPress¿ª·¢ÍŶÓÒÑѸËÙÏìÓ¦£¬ £¬£¬£¬£¬£¬£¬°ä²¼ÁË4.2.7.1°æ±¾ÒÔ½¨¸´´Ë·ì϶¡£¡£¡£¡£ ¡£Òò¶ø£¬ £¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéËùÓÐЧ»§Á¢¼´¸üÐÂÖÁ×îа汾£¬ £¬£¬£¬£¬£¬£¬ÒÔÓÐЧ·À±¸Ç±ÔڵݲȫÍþв¡£¡£¡£¡£ ¡£


https://securityonline.info/cve-2024-8522-cvss-10-learnpress-sqli-flaw-leaves-90k-wordpress-sites-at-risk/


6. ÍøÂçÚ¿Æ­ÐÂÖ¸±ê£ºÌØÀÊÆÕÊý×ÖÂòÂô¿¨Ôâ´¹µöÍøÕ¾Î§¹¥


9ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓô¹µöÍøÕ¾¡¢ÐéαÓòÃû¼°Éç»á¹¤³Ì¼¿Á©£¬ £¬£¬£¬£¬£¬£¬Õë¶ÔÌØÀÊÆÕµÄÊý×ÖÂòÂô¿¨ÌáÒé¹¥»÷£¬ £¬£¬£¬£¬£¬£¬Ì°Í¼ÇÔÈ¡ÆäÃô¸ÐÊý¾Ý¡£¡£¡£¡£ ¡£ÌØÀÊÆÕµÄÐÂÊý×ÖÂòÂô¿¨ÒòÆäÌṩµÄ¶À¼ÒÊý×Ö×ʲúºÍÕæÊµÂÄÀú¶ø±¸ÊܹØ×¢£¬ £¬£¬£¬£¬£¬£¬È´Ò²Òò¶ø³ÉΪ·¸·¨·Ö×ÓµÄÖ¸±ê¡£¡£¡£¡£ ¡£¾ÝVeritiÍøÂ簲ȫ¹«Ë¾»ã±¨£¬ £¬£¬£¬£¬£¬£¬Ú¿Æ­Õßͨ¹ý¹¹½¨Óë¹Ù·½ÍøÖ·¸ß¶ÈÀàËÆµÄÐéαURL£¬ £¬£¬£¬£¬£¬£¬ÈçʹÓá°.xyz¡±ºó׺»òÓÐÒâÆ´Ð´ÃýÎó£¨Èç¡°trunpcards¡±£©£¬ £¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§½Ó¼û²¢Ð¹Â¶ÐÅÏ¢»ò×°ÖöñÒâÈí¼þ¡£¡£¡£¡£ ¡£ËûÃÇÀûÓõç×ÓÓʼþÍøÂç´¹µö£¬ £¬£¬£¬£¬£¬£¬·¢ËÍ¿´ËÆÀ´×ԺϷ¨Çþ·µÄÏÞʱÓÅ»ÝÓʼþ£¬ £¬£¬£¬£¬£¬£¬ÄÚº¬¶ñÒâÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬ÓÕÆ­Óû§µã»÷¡£¡£¡£¡£ ¡£ÌØÀʱ鼰ÆäÖ§³ÖÕß²¢·Ç³õ´Î³ÉÎªÍøÂç·¸×ïµÄÖ¸±ê£¬ £¬£¬£¬£¬£¬£¬´ÓÇ°Ò²Ôø²úÉú¹ýÀàËÆÚ¿Æ­ÊÂÎñ£¬ £¬£¬£¬£¬£¬£¬Èçͨ¹ýÐéÎ±ÍøÕ¾ÇÔÈ¡¾è¿î¡¢ÀûÓÃÐéαÓö´ÌÊÂÎñÆ­È¡¼ÓÃÜÇ®±ÒµÈ¡£¡£¡£¡£ ¡£Ãæ¶ÔÕâЩ·çÏÕ£¬ £¬£¬£¬£¬£¬£¬Êý×ÖÕ䲨¿¨°®ºÃÕßÐèά³Ö¸ß¶È¾¯Ì裬 £¬£¬£¬£¬£¬£¬²ÉÈ¡·À±¸´ëÊ©£¬ £¬£¬£¬£¬£¬£¬ÈçʹÓÃѧÎÊÅжÏÐÅÏ¢ÕæÎ±¡¢²é³­URLµÄHTTPS±êʶ¼°Æ´Ð´ÕýÈ·ÐÔ¡¢Ô¤·Àµã»÷δ¾­ÑéÖ¤µÄÓʼþÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬²¢×Ô¶¯½Ó¼û¹Ù·½ÍøÕ¾¡£¡£¡£¡£ ¡£


https://hackread.com/fake-domains-trump-supporters-trading-card-scam/