ÍøÂç·¸×ïÕßÀûÓÃWMI×é¼þBMOF´«²¼XMRigÍÚ¿ó¶ñÒâÈí¼þ
°ä²¼¹¦·ò 2024-09-129ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬AhnLab °²È«µý±¨ÖÐÐÄ£¨ASEC£©½üÆÚ½ÒʾÁËÒ»ÖÖÁîÈ˾¯ÌèµÄÍøÂç·¸×ïÐÂÇ÷Ïò£¬£¬£¬£¬£¬£¬£¬¼´·¸×ï·Ö×ÓÆæÃîÀûÓöþ½øÔìÖÎÀí¶ÔÏóÎļþ£¨BMOF£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÔÚWindowsÖÎÀí¹æ·¶£¨WMI£©ÖÐÖÁ¹Ø³ÁÒªµÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬×÷Ϊ´«²¼XMRig¼ÓÃÜÇ®±ÒÍÚ¿ó¶ñÒâÈí¼þµÄÔØÌå¡£¡£¡£¡£¡£BMOFÕý±¾ÓÃÓÚÖ´Ðо籾µÄÖ°Äܱ»¶ñÒâÀûÓ㬣¬£¬£¬£¬£¬£¬Í¨¹ý´´½¨¡°ÓÀÔ¶ÊÂÎñ¶©ÔÄ¡±»úÔ죬£¬£¬£¬£¬£¬£¬ÊµÏÖ¶ñÒâÈí¼þµÄÓÆ¾Ã»¯´æÔÚÓë×ÔÎÒ¸´ÔÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬¼«´ó¼ÓÇ¿Á˹¥»÷Õß¶ÔÊܺ¦ÏµÍ³µÄ½ÚÔìÁ¦¡£¡£¡£¡£¡£´Ë¹¥»÷ÊÖ·¨³£ÓëBondNet¶ñÒâÈí¼þÐͬ£¬£¬£¬£¬£¬£¬£¬ºóÕßר¹¥SQL·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬Í¨¹ý·ì϶ÀûÓûò±©Á¦ÆÆ½â»ñÈ¡³õʼ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬£¬ËæºóÀûÓÃBMOFÏÂÔØ²¢Ö´Ðиü¶à¶ñÒâ×é¼þ£¬£¬£¬£¬£¬£¬£¬×îÖÕ²¿ÊðXMRigÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£XMRig×÷ΪһÖÖ¼ÓÃܽٳֶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÇÄÎÞÉùÏ¢µØÕ¼ÓÃÊܺ¦Õßϵͳ×ÊÔ´ÍÚ¾òÃÅÂÞ±Ò£¬£¬£¬£¬£¬£¬£¬¶Ôϵͳ»úÄÜÓëÄܺÄÔì³ÉÏÔÖø¸ºÃæÓ°Ï죬£¬£¬£¬£¬£¬£¬Îª¹¥»÷Õßıȡ·¸·¨ÀûÒæ¡£¡£¡£¡£¡£
https://securityonline.info/cybercriminals-exploit-legitimate-windows-tool-for-cryptojacking/
2. Ð嵀 PIXHELL Éùѧ¹¥»÷й¶ÁËÒº¾§ÆÁÄ»ÔëÒôµÄ°ÂÃØ
9ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬ÐÂÐÍÉùѧ¹¥»÷¡°PIXHELL¡¹Ø¹Ê¾ÁË´Ó¸ôÀëϵͳÖÐÒþÃØÐ¹Â¶ÐÅÏ¢µÄ׳´óÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬Ëüͨ¹ýÏνӵÄLCDÏÔʾÆ÷·¢³öÈ˶úÄÑÒÔ¾õ²ìµÄÉù²¨£¨0-22 kHz£©£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÏñËØÄ£Ê½µ÷Ôì´«µÝ±àÂëÐźţ¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÄܱ»×ó½üµÄÖÇÄÜÉ豸²¶»ñ¡£¡£¡£¡£¡£Ö»¹ÜÊý¾Ý´«ÊäËٶȽÏÂý£¨½ö20 bps£©£¬£¬£¬£¬£¬£¬£¬µ«Ëü×ãÒÔ½øÐÐʵʱ¼üÅ̼ͼ»òÇÔÈ¡Ó×Îı¾Îļþ¡£¡£¡£¡£¡£PIXHELLÓÉÒÔÉ«ÁÐÄڸǷò±¾¡¤¹ÅÀï°²´óѧµÄMordechai Guri²©Ê¿¿ª·¢£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁËLCDÆÁÄ»µÄÌìÈ»Éù·¢Éä¸öÐÔ£¬£¬£¬£¬£¬£¬£¬½áºÏÌØÔì¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý·ÖÆçµÄµ÷Ôì¼¼Êõ£¨ÈçOOK¡¢FSK¡¢ASK£©½«Êý¾Ý±àÂëΪÉùÒôÐźš£¡£¡£¡£¡£ÓÉÓÚÕâЩÉùÒôºÍÏñËØ±ä¶¯¶ÔÈËÀàÓû§¶øÑÔÏÕЩ²»Ë½¼û£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷¼«ÆäÒñ±Î¡£¡£¡£¡£¡£Ãæ¶ÔPIXHELL¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿É²ÉÈ¡µÄ·ÀÓù´ëÊ©Ô̺¬£ºÔÚÃô¸ÐÇøÓò½ûÓÃЯ´øÂó¿Ë·çµÄÉ豸£¬£¬£¬£¬£¬£¬£¬Ôö³¤²¼¾°ÔëÉùÒÔ×ÌÈÅÐźţ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃÉãÏñÍ·¼à¿ØÆÁÄ»»º³åÇøÒÔ¼ì²âÒì³£ÏñËØÄ£Ê½¡£¡£¡£¡£¡£ÕâЩ´ëÊ©¹²Í¬×é³ÉÁËÒ»¸ö¶àµµ´ÎµÄ°²È«·À»¤Íø£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÓÐЧÕмܴËÀàÐÂÐÍÉùѧ²àÐÅ·¹¥»÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-pixhell-acoustic-attack-leaks-secrets-from-lcd-screen-noise/
3. Kemper Sports ManagementÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ó°Ïì6.2ÍòÈË
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬¸ß¶û·òÇò³¡ÖÎÀí¼°¾Æµê·þÎñÌṩÉÌKemper Sports Management°ä·¢ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¨¼°6.2ÍòÃûÓ×ÎÒ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÉæ¼°ÆäÏÖÈμ°Ç°ÈÎÔ±¹¤µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃûºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2024Äê4ÔÂ1ÈÕ¾õ²ìÍøÂçÒì³££¬£¬£¬£¬£¬£¬£¬¾µ÷²éÈ·ÈÏ£¬£¬£¬£¬£¬£¬£¬²»Ã÷ÍþвÕßÒÑ·¸·¨ÇÖÈëϵͳ²¢»ñÈ¡ÁËÕâЩÐÅÏ¢¡£¡£¡£¡£¡£Õâ´Îй¶ÊÂÎñÓ°ÏìÁìÓò¿í·º£¬£¬£¬£¬£¬£¬£¬²¨¼°KemperSportsÔÚÃÀ¹ú30¸öÖݵij¬¹ý7,500ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬¸²¸ÇÆä140¶à¸ö·ÖÖ§»ú¹¹¡£¡£¡£¡£¡£Ö»¹ÜĿǰÉÐÎÞÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»¶ñÒâÀûÓÃÓÚÉí·Ý͵ÇÔ»òڲƻ£¬£¬£¬£¬£¬£¬£¬KemperSportsÒÑѸËÙ²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬£¬ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩһÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý¸´Ô·þÎñ×÷ΪÅâ³¥¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ²¢Î´Ã÷È·Ö¸ÏòÈκÎÒÑÖªµÄÀÕË÷Èí¼þ×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÇÒ¹«Ë¾Ç¿µ÷£¬£¬£¬£¬£¬£¬£¬¼´±ãÉæ¼°Êê½ðÖ§¸¶£¬£¬£¬£¬£¬£¬£¬ÆäÒ²²»»á³ÉΪйÃÜÐÅÏ¢µÄ¹«¿ª¶ÔÏ󡣡£¡£¡£¡£´ËÐÂÎÅѸËÙÒýÆð˾·¨½çµÄ¹Ø×¢£¬£¬£¬£¬£¬£¬£¬¶à¼ÒÂÉʦÊÂÎñËùÒѰ䲼ÉêÃ÷£¬£¬£¬£¬£¬£¬£¬Òâͼ´ú±íÊܺ¦ÕßÏòKemperSportsÌáÒ鼯ÌåËßËÏ¡£¡£¡£¡£¡£
https://www.securityweek.com/data-breach-at-golf-course-management-firm-kempersports-impacts-62000/
4. ÍøÂç´¹µöÐÂÇ÷Ïò£ºÓòÃûÇÀ×¢ÓëÆ·ÅÆ¼ÙÒâËÁŰ
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Zscaler ThreatLabz×îл㱨½ÒʾÁËÍøÂç´¹µö»î¶¯ÕýÒÔǰËùδÓеÄËÙ¶ÈÔö³¤£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇͨ¹ýÓòÃûÇÀ×¢ºÍÆ·ÅÆ¼ÙÒ⼿Á©¡£¡£¡£¡£¡£ÔÚ2024Äê2ÔÂÖÁ7ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷÖÎöÁ˳¬¹ý3Íò¸öÓëÈ«Çò³ÛÃûÆ·ÅÆÀàËÆµÄÓòÃû£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäÖÐÈý·Ö֮һΪ¶ñÒâÓòÃû£¬£¬£¬£¬£¬£¬£¬ÓÈÒԹȸ衢΢ÈíºÍÑÇÂíÑ·µÈ¿Æ¼¼¾ÞͷΪ¼ÙÒâ³ÁÔÖÇø£¬£¬£¬£¬£¬£¬£¬Õ¼±È½üËÄ·ÖÖ®Èý¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÕßÀûÓÃÆ·ÅƳÛÃû¶ÈºÍÓû§ÐÅÀµ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÇá΢ƴдÃýÎóµÄÓòÃûÓÕÆÓû§½øÈë¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÀûÓñ»µÁƾ֤ѸËÙ±äÏÖ¡£¡£¡£¡£¡£»£»£»£»£»¥ÁªÍø·þÎñÐÐÒµ³ÉÎªÍøÂç´¹µöµÄÖØÒªÖ¸±ê£¬£¬£¬£¬£¬£¬£¬Õ¼±È½üÈý³É£¬£¬£¬£¬£¬£¬£¬×¨Òµ·þÎñÓëÔÚÏß¹ºÎïÍøÕ¾½ôËæÆäºó£¬£¬£¬£¬£¬£¬£¬ÒòÆä´¦ÖôóÁ¿Ãô¸ÐºÍ²ÆÕþÊý¾Ý¶ø±¸ÊÜÇàíù¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬½ü°ë´¹µöÓòÃûѡȡÃâ·ÑµÄLet's Encrypt TLSÖ¤Êé¼Ù×°ºÏ·¨£¬£¬£¬£¬£¬£¬£¬ÀûÓá°¹ÒËø¡±·ûºÅÎóµ¼Óû§£¬£¬£¬£¬£¬£¬£¬ÌÓ±Üä¯ÀÀÆ÷°²È«ÖҸ档¡£¡£¡£¡£¼øÓÚÓòÃûÇÀ×¢ºÍÆ·ÅÆ¼ÙÒâ»î¶¯³ÖÐø·è¿ñ£¬£¬£¬£¬£¬£¬£¬ÌáÉýÓû§·À±¸ÒâʶºÍ¼ÓÇ¿ÆóÒµÍøÂ簲ȫ´ëÊ©Èç¼¢ËÆ¿Ê¡£¡£¡£¡£¡£
https://securityonline.info/cybercriminals-increasingly-target-google-microsoft-and-amazon-in-sophisticated-phishing-schemes/
5. LearnPressÆØ·ì϶CVE-2024-8522£¬£¬£¬£¬£¬£¬£¬Íþв³¬9Íò¸öÍøÕ¾°²È«
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬LearnPressÊÇÒ»¿î¹ãÊÜ»¶ÓµÄWordPressÔÚÏ߿γÌÖÎÀí¹¤¾ß²å¼þ£¬£¬£¬£¬£¬£¬£¬½üÆÚ±»·¢ÏÖ´æÔÚÒ»¸ö¸ßΣSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬±àºÅΪCVE-2024-8522£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï10£¬£¬£¬£¬£¬£¬£¬Åú×¢¸Ã·ì϶ӵÓм«¸ßµÄÑϳÁÐÔ¡£¡£¡£¡£¡£´Ë·ì϶DZ²ØÓÚLearnPressµÄREST API¶ËµãÖУ¬£¬£¬£¬£¬£¬£¬¾ßÌ幨Áªµ½¡°c_only_fields¡±²ÎÊýµÄ´¦Öò»µ±£¬£¬£¬£¬£¬£¬£¬Òò²»×ã×ã¹»µÄתÒå´ëÊ©ºÍSQL²éÎʳﱸ£¬£¬£¬£¬£¬£¬£¬Ê¹µÃδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜ×¢Èë¶ñÒâSQL´úÂ룬£¬£¬£¬£¬£¬£¬½ø¶ø¿ÉÄܽӼû²¢ÇÔÈ¡´æ´¢ÔÚWordPressÊý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÓû§Æ¾Ö¤¡¢Ó×ÎÒÊý¾Ý¼°¿Î³Ì×ÊÁÏ¡£¡£¡£¡£¡£¼øÓÚLearnPressÕ¼Óг¬¹ý90,000¸ö»îÔ¾×°ÖÃÁ¿£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁìÓò¿í·ºÇÒÉîÔ¶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÄÜÀûÓô˷ì϶Åú¸Ä»òɾ³ýÊý¾Ý¿âÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬ÆëÈ«½ÚÔìÊÜÓ°ÏìµÄÍøÕ¾¡£¡£¡£¡£¡£¼øÓڸ÷ì϶µÄ¼òÒ×ÀûÓÃÐԺ͸߷çÏÕÐÔ£¬£¬£¬£¬£¬£¬£¬ËùÓÐʹÓÃLearnPressµÄWordPressÍøÕ¾¾ùÃæ¶ÔÖ±½Ó·çÏÕ¡£¡£¡£¡£¡£LearnPress¿ª·¢ÍŶÓÒÑѸËÙÏìÓ¦£¬£¬£¬£¬£¬£¬£¬°ä²¼ÁË4.2.7.1°æ±¾ÒÔ½¨¸´´Ë·ì϶¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéËùÓÐЧ»§Á¢¼´¸üÐÂÖÁ×îа汾£¬£¬£¬£¬£¬£¬£¬ÒÔÓÐЧ·À±¸Ç±ÔڵݲȫÍþв¡£¡£¡£¡£¡£
https://securityonline.info/cve-2024-8522-cvss-10-learnpress-sqli-flaw-leaves-90k-wordpress-sites-at-risk/
6. ÍøÂçÚ¿ÆÐÂÖ¸±ê£ºÌØÀÊÆÕÊý×ÖÂòÂô¿¨Ôâ´¹µöÍøÕ¾Î§¹¥
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓô¹µöÍøÕ¾¡¢ÐéαÓòÃû¼°Éç»á¹¤³Ì¼¿Á©£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÌØÀÊÆÕµÄÊý×ÖÂòÂô¿¨ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ì°Í¼ÇÔÈ¡ÆäÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ÌØÀÊÆÕµÄÐÂÊý×ÖÂòÂô¿¨ÒòÆäÌṩµÄ¶À¼ÒÊý×Ö×ʲúºÍÕæÊµÂÄÀú¶ø±¸ÊܹØ×¢£¬£¬£¬£¬£¬£¬£¬È´Ò²Òò¶ø³ÉΪ·¸·¨·Ö×ÓµÄÖ¸±ê¡£¡£¡£¡£¡£¾ÝVeritiÍøÂ簲ȫ¹«Ë¾»ã±¨£¬£¬£¬£¬£¬£¬£¬Ú¿ÆÕßͨ¹ý¹¹½¨Óë¹Ù·½ÍøÖ·¸ß¶ÈÀàËÆµÄÐéαURL£¬£¬£¬£¬£¬£¬£¬ÈçʹÓá°.xyz¡±ºó׺»òÓÐÒâÆ´Ð´ÃýÎó£¨Èç¡°trunpcards¡±£©£¬£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§½Ó¼û²¢Ð¹Â¶ÐÅÏ¢»ò×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£ËûÃÇÀûÓõç×ÓÓʼþÍøÂç´¹µö£¬£¬£¬£¬£¬£¬£¬·¢ËÍ¿´ËÆÀ´×ԺϷ¨Çþ·µÄÏÞʱÓÅ»ÝÓʼþ£¬£¬£¬£¬£¬£¬£¬ÄÚº¬¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬£¬ÓÕÆÓû§µã»÷¡£¡£¡£¡£¡£ÌØÀʱ鼰ÆäÖ§³ÖÕß²¢·Ç³õ´Î³ÉÎªÍøÂç·¸×ïµÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬´ÓÇ°Ò²Ôø²úÉú¹ýÀàËÆÚ¿ÆÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Èçͨ¹ýÐéÎ±ÍøÕ¾ÇÔÈ¡¾è¿î¡¢ÀûÓÃÐéαÓö´ÌÊÂÎñÆÈ¡¼ÓÃÜÇ®±ÒµÈ¡£¡£¡£¡£¡£Ãæ¶ÔÕâЩ·çÏÕ£¬£¬£¬£¬£¬£¬£¬Êý×ÖÕ䲨¿¨°®ºÃÕßÐèά³Ö¸ß¶È¾¯Ì裬£¬£¬£¬£¬£¬£¬²ÉÈ¡·À±¸´ëÊ©£¬£¬£¬£¬£¬£¬£¬ÈçʹÓÃѧÎÊÅжÏÐÅÏ¢ÕæÎ±¡¢²é³URLµÄHTTPS±êʶ¼°Æ´Ð´ÕýÈ·ÐÔ¡¢Ô¤·Àµã»÷δ¾ÑéÖ¤µÄÓʼþÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²¢×Ô¶¯½Ó¼û¹Ù·½ÍøÕ¾¡£¡£¡£¡£¡£
https://hackread.com/fake-domains-trump-supporters-trading-card-scam/


¾©¹«Íø°²±¸11010802024551ºÅ