Willow PaysÊý¾Ý¿âÔâй¶£¬£¬£¬£¬£¬ £¬ £¬£¬24ÍòÓû§Ãô¸ÐÐÅÏ¢ÆØ¹â

°ä²¼¹¦·ò 2025-01-22

1. Willow PaysÊý¾Ý¿âÔâй¶£¬£¬£¬£¬£¬ £¬ £¬£¬24ÍòÓû§Ãô¸ÐÐÅÏ¢ÆØ¹â


1ÔÂ20ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬°²È«×êÑÐÔ±Jeremiah Fowler×î½ü·¢ÏÖÒ»¸öδÊÜÃÜÂë±£»£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬ £¬£¬¸ÃÊý¾Ý¿âÔ̺¬ÃÀ¹ú½ðÈڿƼ¼Õ˵¥Ö§¸¶Æ½Ì¨Willow PaysµÄ240,000¶àÌõÃô¸Ð¼Í¼£¬£¬£¬£¬£¬ £¬ £¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¶î¶ÈºÍÄÚ²¿Õ˵¥¾ßÌåÐÅÏ¢µÈ¡£¡£¡£¡£ ¡£¡£Willow PaysÔÊÐíÓû§ÔÚÖÜΧÄÚÖ§¸¶Õ˵¥ºÍÆäËûÓöȣ¬£¬£¬£¬£¬ £¬ £¬£¬µ«¸ÃÊý¾Ý¿âÈ´²»×ãÃÜÂë±£»£»£»£»£»£»¤»ò¼ÓÃÜ£¬£¬£¬£¬£¬ £¬ £¬£¬Ê¹µÃÕâЩÐÅÏ¢ÈÝÒ×±»Ð¹Â¶¡£¡£¡£¡£ ¡£¡£¹ÌÈ»Éв»Ã÷ÏÔÏÖʵÊý¾Ýй¶µÄˮƽ£¬£¬£¬£¬£¬ £¬ £¬£¬µ«FowlerÒÔΪÕâЩÐÅÏ¢¿ÉÄܻᱻ·¸×ï·Ö×ÓÓÃÓÚÍøÂç´¹µö¹¥»÷»òδ¾­ÊÚȨ½Ó¼ûÆäËûÕË»§¡£¡£¡£¡£ ¡£¡£FowlerÏòWillow Pays·¢³öÁËÒ»·ÝÕÆ¹ÜÈεÄÅû¶֪ͨ£¬£¬£¬£¬£¬ £¬ £¬£¬ºóÕßÁ¢¼´²»ÈÝÁ˹«¼Ò¶Ô¸ÃÊý¾Ý¿âµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£ÕâÒ»ÊÂÎñ͹ÏÔÁ˽ðÈÚ»ú¹¹Ãæ¶ÔµÄÍøÂç¹¥»÷ÍþвÈÕÒæÔö³¤£¬£¬£¬£¬£¬ £¬ £¬£¬°²È«×¨¼ÒÇ¿µ÷½ðÈÚÈí¼þÌṩÉ̱ØÒªÖ´ÐÐÓÐЧµÄÍøÂ簲ȫ´ëÊ©£¬£¬£¬£¬£¬ £¬ £¬£¬Ô̺¬¼ÓÃÜÃô¸ÐÊý¾Ý¡¢¶¨ÆÚ½øÐа²È«Éó¼ÆÒÔ¼°Ñ¡È¡¶à³É·ÖÉí·ÝÑéÖ¤µÈ£¬£¬£¬£¬£¬ £¬ £¬£¬ÒÔÔ¤·ÀÔÚÏß½ðÈÚڲƭ¡£¡£¡£¡£ ¡£¡£


https://hackread.com/fintech-bill-pay-willow-pays-exposes-240000-records/


2. ¶àÖÖËí·ºÍ̸°²È«·ìÏ¶ÆØ¹â£¬£¬£¬£¬£¬ £¬ £¬£¬420Íǫ̀Ö÷»úÃæ¶Ô¹¥»÷·çÏÕ


1ÔÂ20ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬ÐÂ×êÑÐÏÔʾ£¬£¬£¬£¬£¬ £¬ £¬£¬¶àÖÖËí·ºÍ̸´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬¿ÉÄÜʹ¹¥»÷ÕßÖ´ÐжàÖÖ¹¥»÷¡£¡£¡£¡£ ¡£¡£Top10VPNÓë³ãë´óѧ½ÌÊÚÂíµÙ¡¤·¶»ô·òºÏ×÷µÄ×êÑÐÖ¸³ö£¬£¬£¬£¬£¬ £¬ £¬£¬ÈôÍøÂçÖ÷»ú½ÓÊÜËí·Êý¾Ý°ü¶ø²»ÑéÖ¤·¢ËÍÕßÉí·Ý£¬£¬£¬£¬£¬ £¬ £¬£¬Ôò¿ÉÄܱ»½Ù³ÖÖ´ÐÐÄäÃû¹¥»÷²¢»ñµÃÍøÂç½Ó¼ûȨÏÞ¡£¡£¡£¡£ ¡£¡£×êÑз¢ÏÖ£¬£¬£¬£¬£¬ £¬ £¬£¬¶à´ï420Íǫ̀Ö÷»úÒ×Êܹ¥»÷£¬£¬£¬£¬£¬ £¬ £¬£¬Ô̺¬VPN¡¢ISP¼Òͥ·ÓÉÆ÷¡¢Ö÷Ì⻥ÁªÍøÂ·ÓÉÆ÷¡¢Òƶ¯ÍøÂçÍø¹ØºÍCDN½Úµã£¬£¬£¬£¬£¬ £¬ £¬£¬ÊÜÓ°Ïì×îÑϳÁµÄ¹ú¶ÈÔ̺¬Öйú¡¢·¨¹ú¡¢ÈÕ±¾¡¢ÃÀ¹úºÍ°ÍÎ÷¡£¡£¡£¡£ ¡£¡£ÕâЩ·ì϶ÔÊÐí¹¥»÷ÕßÀÄÓÃÒ×Êܹ¥»÷µÄϵͳ×÷Ϊµ¥Ïò´úÀí£¬£¬£¬£¬£¬ £¬ £¬£¬²¢·¢ÆðDoS¹¥»÷¡£¡£¡£¡£ ¡£¡£CERTЭµ÷ÖÐÐÄÖ¸³ö£¬£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß»¹¿ÉαÔìÔ´IPv4/6µØÖ·£¬£¬£¬£¬£¬ £¬ £¬£¬½Ó¼û˽ÓÐÍøÂç»ò·¢ÆðDDoS¹¥»÷¡£¡£¡£¡£ ¡£¡£·ì϶±¾Ô­ÔÚÓÚËí·ºÍ̸ÈçIP6IP6¡¢GRE6µÈ²»×ã×ã¹»µÄ°²È«ºÍ̸£¬£¬£¬£¬£¬ £¬ £¬£¬ÈçIPsec£¬£¬£¬£¬£¬ £¬ £¬£¬²»ºÏÁ÷Á¿½øÐÐÉí·ÝÑéÖ¤ºÍ¼ÓÃÜ¡£¡£¡£¡£ ¡£¡£ÕâЩºÍ̸Òѱ»·ÖÅäÁËÏàÓ¦µÄCVE±àºÅ¡£¡£¡£¡£ ¡£¡£×÷Ϊ·ÀÓù´ëÊ©£¬£¬£¬£¬£¬ £¬ £¬£¬½¨ÒéʹÓÃIPSec»òWireGuardÌṩÉí·ÝÑéÖ¤ºÍ¼ÓÃÜ£¬£¬£¬£¬£¬ £¬ £¬£¬²¢½ö½ÓÊÜÀ´×Ô¿ÉÐÅÔ´µÄËí·Êý¾Ý°ü¡£¡£¡£¡£ ¡£¡£Í¬Ê±£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÚÍøÂç²ãÃæÖ´ÐÐÁ÷Á¿¹ýÂË¡¢Éî¶È°ü²é³­£¬£¬£¬£¬£¬ £¬ £¬£¬²¢×èÖ¹ËùÓÐδ¼ÓÃܵÄËí·Êý¾Ý°ü¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2025/01/unsecured-tunneling-protocols-expose-42.html


3. з¢ÏÖÎïÁªÍø½©Ê¬ÍøÂçÈ«Çò²ß¶¯DDoS¹¥»÷


1ÔÂ20ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬×Ô2024Äêµ×ÒÔÀ´£¬£¬£¬£¬£¬ £¬ £¬£¬Ò»¸öз¢ÏÖµÄÎïÁªÍø(IoT)½©Ê¬ÍøÂçÔÚÈ«ÇòÁìÓòÄڲ߶¯´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷£¬£¬£¬£¬£¬ £¬ £¬£¬ÖØÒªÀûÓ÷ÓÉÆ÷¡¢IPÉãÏñÓŵÈÎïÁªÍøÉ豸Öеķì϶¡£¡£¡£¡£ ¡£¡£¸Ã½©Ê¬ÍøÂç½áºÏÁËMiraiºÍBashlite¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬ £¬£¬Í¨¹ýÔ¶³Ì´úÂëÖ´Ðзì϶»ò±©Á¦ÆÆ½âÈõÃÜÂëϰȾÉ豸£¬£¬£¬£¬£¬ £¬ £¬£¬Ï°È¾¹ý³ÌÔ̺¬ÉøÈë¡¢¸ºÔØ´«µÝºÍÏνӵ½ºÅÁîÓë½ÚÔì(C&C)·þÎñÆ÷½Ó¹Ü¹¥»÷ºÅÁî¡£¡£¡£¡£ ¡£¡£¸Ã½©Ê¬ÍøÂçѡȡ¶àÖÖDDoS¹¥»÷ý½é£¬£¬£¬£¬£¬ £¬ £¬£¬ÈçSYNºéË®¡¢UDPºéË®¡¢GREºÍ̸·ì϶ºÍTCPÎÕÊÖºéË®µÈ£¬£¬£¬£¬£¬ £¬ £¬£¬¶ÔÈ«Çò½ðÈÚ¡¢½»Í¨ºÍµçÐŵÈÐÐÒµ×é³É³Á´óÍþв£¬£¬£¬£¬£¬ £¬ £¬£¬±±ÃÀºÍÅ·ÖÞÓÈÆäÊÇÃÀ¹úºÍÈÕ±¾Êܵ½ÑϳÁÓ°Ïì¡£¡£¡£¡£ ¡£¡£ÊÜϰȾµÄÉ豸´ó²¿ÃÅÊÇÎÞÏß·ÓÉÆ÷ºÍIPÉãÏñÍ·£¬£¬£¬£¬£¬ £¬ £¬£¬TP-LinkºÍZyxelµÈÆ·ÅÆÒòÆä¿í·ºÊ¹ÓúÍÒÑÖª·ì϶¶øÆµÈÔÊܵ½¹¥»÷¡£¡£¡£¡£ ¡£¡£ÎªÁËÔ¤·À±»·¢ÏÖ£¬£¬£¬£¬£¬ £¬ £¬£¬¸Ã¶ñÒâÈí¼þ»á½ûÓÃÊÜϰȾÉ豸ÉϵĿ´ÃŹ·¼ÆÊ±Æ÷ºÍ°Ñ³Öiptables¹æ¶¨¡£¡£¡£¡£ ¡£¡£×¨¼Ò½¨Òé²ÉÈ¡¸ü¸ÄĬÈÏÃÜÂë¡¢¶¨ÆÚ¸üй̼þ¡¢¸ôÀëÎïÁªÍøÉ豸¡¢Ñ¡È¡ÈëÇÖ¼ì²âϵͳºÍÓë·þÎñÌṩÉ̺Ï×÷¹ýÂ˶ñÒâÁ÷Á¿µÈ´ëÊ©À´½µµÍϰȾ·çÏÕ¡£¡£¡£¡£ ¡£¡£


https://cybersecuritynews.com/new-iot-botnet-launching-large-scale-ddos-attacks/#google_vignette


4. ANWSDÍøÂ簲ȫÊÂÎñ²¼¸æ¼°Ó×ÎÒÐÅÏ¢±£»£»£»£»£»£»¤´ëÊ©


1ÔÂ21ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬°¬µÏÉ­Î÷±±Ñ§Çø£¨ANWSD£©½üÆÚÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬ £¬ £¬£¬ÆäÖÐһ̨´æ´¢2008ÄêÖÁ2022ÄêÔ±¹¤¼Í¼µÄ¾É¹¤×Êϵͳ·þÎñÆ÷±»ÈëÇÖ¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÕâЩÐÅÏ¢²¢·ÇÒÔÒ×ÓÚ½Ó¼ûµÄÌåʽ´æ´¢£¬£¬£¬£¬£¬ £¬ £¬£¬µ«Ô̺¬Éç»á°²È«ºÅÂëºÍÖ±½Ó´æ¿îÒøÐеÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ £¬ £¬£¬Òò¶øANWSDÈç¹ûËùÓÐÎļþ¿ÉÄÜÒѶ³ö¡£¡£¡£¡£ ¡£¡£ÎªÓ¦¶Ô´ËÊÂÎñ£¬£¬£¬£¬£¬ £¬ £¬£¬ANWSD°ä²¼ÁËÇ峺²¼¸æ£¬£¬£¬£¬£¬ £¬ £¬£¬²¢ÌṩÁ˶àÏÒéÒÔ±£»£»£»£»£»£»¤ÊÜÓ°ÏìÓ×ÎÒµÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬ £¬£¬Ô̺¬²ÎÓëÐÅÓþ¼à¿Ø·þÎñ¡¢Ë÷È¡Ãâ·ÑÐÅÓþ»ã±¨¡¢¼à¿Ø²ÆÕþÕË»§¡¢ÆôÓÃڲƭ¾¯±¨ÒÔ¼°¸ü¸ÄÃÜÂëµÈ¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬ £¬£¬ANWSD»¹ÌṩÁËÁª¹úÒµÎñίԱ»áÍøÕ¾www.IdentityTheft.gov×÷Ϊ»ñÈ¡¸ü¶à±£»£»£»£»£»£»¤Ó×ÎÒÐÅÏ¢µÄ×ÊÔ´¡£¡£¡£¡£ ¡£¡£ANWSD¶ÔÕâ´ÎÊÂÎñ¿ÉÄÜ´øÀ´µÄ²»±ã»òÓÇÓô°µÊ¾Ç¸Ò⣬£¬£¬£¬£¬ £¬ £¬£¬²¢¼¤ÀøÓÐÒÉÄÑ»ò±ØÒªÔ®ÊÖµÄÓ×ÎÒÁªÏµ²ÆÕþºÍÔËÓª×ܼàElizabeth Jennings¡£¡£¡£¡£ ¡£¡£ANWSDÔÚ»ý¼«Ó¦¶Ô´ËÇé¿ö£¬£¬£¬£¬£¬ £¬ £¬£¬²¢ÖÂÁ¦È·±£ÀàËÆÊÂÎñ²»ÔÙ²úÉú¡£¡£¡£¡£ ¡£¡£


https://databreaches.net/2025/01/21/cybersecurity-incident-impacting-addison-northwest-school-district-anwsd/


5. ConduentÔâÍøÂç¹¥»÷ÖÂÒµÎñÖжϣ¬£¬£¬£¬£¬ £¬ £¬£¬Ó°Ïì¶àÖݵ±¾Ö·þÎñ


1ÔÂ22ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬µ±¾ÐļÊõ³Ð°üÉÌConduent½üÆÚÔâ·êÁËÒ»´ÎÓÉÍøÂç¹¥»÷Òý·¢µÄÍ£µçÊÂÎñ£¬£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷·ÛËéÁËÆä²Ù×÷ϵͳ¡£¡£¡£¡£ ¡£¡£¾ÝConduent½²»°ÈËй©£¬£¬£¬£¬£¬ £¬ £¬£¬Õâ´ÎÈëÇÖÒÑѸËٵõ½½ÚÔ죬£¬£¬£¬£¬ £¬ £¬£¬²¢¾­µÚÈý·½°²È«×¨¼ÒÈ·ÈÏ£¬£¬£¬£¬£¬ £¬ £¬£¬¼¼Êõ»·¾³Ä¿Ç°ÎÞÒÑÖª¶ñÒâ»î¶¯¡£¡£¡£¡£ ¡£¡£È»¶ø£¬£¬£¬£¬£¬ £¬ £¬£¬ÑϸñµÄ¸´Ô­¹ý³Ìµ¼Ö¹«Ë¾¶àÏîÒµÎñÖжÏÊýÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬Ó°ÏìÁËÔ̺¬Ò½ÁƲ¹Öú¡¢¶ùͯ·öÑø¡¢Ê³Æ·ÔöÔ®µÈ´òËãÔÚÄÚÈ·µ±¾Ö·þÎñ¡£¡£¡£¡£ ¡£¡£Íþ˹¿µÐÇÖÝÊÇÊÜÓ°ÏìµÄÖÝÖ®Ò»£¬£¬£¬£¬£¬ £¬ £¬£¬¾ÓÃñ±§Ô¹Òòϵͳ¹ÊÕÏÎÞ·¨Ö§¸¶Óöȡ£¡£¡£¡£ ¡£¡£ÏµÍ³ÓÚÖÜÈÕ¸´Ô­£¬£¬£¬£¬£¬ £¬ £¬£¬ConduentÌṩÁ˶î±í¹¤×÷ÈËԱЭÖú´¦ÖÃÑÓ³¤¸¶¿î¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÓÐËĸöÖÝÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬ £¬£¬µ«Conduentδй©ÆäËûÊÜÓ°ÏìÖݵÄÐÅÏ¢¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬ £¬£¬ConduentÓë°¢À­Ë¹¼ÓÖÝÇ©ÊðÁË9200ÍòÃÀÔªµÄºÏͬ£¬£¬£¬£¬£¬ £¬ £¬£¬ÓÃÓÚÒ½ÁƲ¹ÖúÖÎÀíÐÅϢϵͳµÄÏÖ´ú»¯Ë¢Ð¡¢ÔËÓªºÍÖÎÀí¡£¡£¡£¡£ ¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬ £¬ £¬£¬ConduentÔÚ2020ÄêÔøÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾Ã¿Äê´¦ÖÃÔ¼1000ÒÚÃÀԪȷµ±¾Ö¿î×Ó£¬£¬£¬£¬£¬ £¬ £¬£¬ÉÏÒ»²Æ¼¾ÓªÊÕ³¬¹ý8ÒÚÃÀÔª¡£¡£¡£¡£ ¡£¡£


https://therecord.media/government-contractor-conduent-outage-compromise


6. Google¸æ°×ÔâºÚ¿ÍÀÄÓô«²¼¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬ £¬£¬HomebrewÓû§Ð辯Ìè


1ÔÂ21ÈÕ£¬£¬£¬£¬£¬ £¬ £¬£¬ºÚ¿ÍÀûÓÃGoogle¸æ°×´«²¼¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬ £¬£¬Í¨¹ýÐéαµÄHomebrewÍøÕ¾Ï°È¾MacºÍLinuxÉ豸£¬£¬£¬£¬£¬ £¬ £¬£¬²¢ÇÔÈ¡Óû§µÄƾ֤¡¢ä¯ÀÀÆ÷Êý¾ÝºÍ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£ ¡£¡£Õâ´Î¶ñÒâ¸æ°×»î¶¯ÖÐʹÓõĶñÒâÈí¼þÊÇAmosStealer£¨±ðÃû¡°Atomic¡±£©£¬£¬£¬£¬£¬ £¬ £¬£¬ÕâÊÇÒ»ÖÖרΪmacOSϵͳÉè¼ÆµÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬ £¬ £¬£¬Ã¿ÔÂÒÔ1000ÃÀÔªµÄ¼ÛÖµÏúÊÛ¸øÍøÂç·¸×ï·Ö×Ó¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÀûÓÃURL¼¼Êõ£¬£¬£¬£¬£¬ £¬ £¬£¬ÔÚGoogle¸æ°×ÖÐÏÔʾÕýÈ·µÄHomebrew URL£¬£¬£¬£¬£¬ £¬ £¬£¬ÓÕÆ­Óû§µã»÷³Á¶¨Ïòµ½ÐéαµÄHomebrewÍøÕ¾£¬£¬£¬£¬£¬ £¬ £¬£¬µ±Óû§ÔËÐÐÐéÎ±ÍøÕ¾ÏÔʾµÄºÅÁîʱ£¬£¬£¬£¬£¬ £¬ £¬£¬É豸¾Í»áÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£HomebrewÏîÄ¿ÕÆ¹ÜÈËÆ·ÆÀ¹È¸è²»×ãÉó²é£¬£¬£¬£¬£¬ £¬ £¬£¬Ç¿µ÷´ËÇé¿öÒѳ¬³öÆä½ÚÔìÁìÓò¡£¡£¡£¡£ ¡£¡£¹ÌÈ»¶ñÒâ¸æ°×Òѱ»É¾³ý£¬£¬£¬£¬£¬ £¬ £¬£¬µ«¸Ã»î¶¯¿ÉÄÜ»áͨ¹ýÆäËû³Á¶¨ÏòÓò³ÖÐø½øÐУ¬£¬£¬£¬£¬ £¬ £¬£¬Òò¶øHomebrewÓû§±ØÒª¾¯Ìè¡£¡£¡£¡£ ¡£¡£ÎªÁ˽µµÍϰȾ·çÏÕ£¬£¬£¬£¬£¬ £¬ £¬£¬Óû§Ó¦È·±£µã»÷GoogleÁ´½Óºó´ïµ½µÄÊÇÏîÄ¿»ò¹«Ë¾µÄºÏ·¨ÍøÕ¾£¬£¬£¬£¬£¬ £¬ £¬£¬²¢½«³£ÓÃÍøÕ¾Ôö³¤µ½ÊéÇ©ÖÐÒÔ»ñÈ¡Èí¼þ¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/fake-homebrew-google-ads-target-mac-users-with-malware/