Spotify²¥·ÅÁбíÓë²¥¿Í³É²»·¨·Ö×ÓÍƹãµÁ°æÈí¼þÐÂÇþµÀ

Ðû²¼Ê±¼ä 2024-11-21

1. Spotify²¥·ÅÁбíÓë²¥¿Í³É²»·¨·Ö×ÓÍƹãµÁ°æÈí¼þÐÂÇþµÀ


11ÔÂ19ÈÕ£¬Spotifyƽ̨ÉϵIJ¥·ÅÁбíºÍ²¥¿Í±»²»·¨·Ö×ÓÀÄÓã¬ÓÃÓÚÍƹãµÁ°æÈí¼þ¡¢ÓÎÏ·×÷±×Âë¡¢À¬»øÁ´½ÓºÍ¡°µÁ°æÈí¼þ¡±ÍøÕ¾¡£Í¨¹ýÔÚ²¥·ÅÁбíÃû³ÆºÍ²¥¿ÍÐÎòÖÐǶÈëÄ¿µÄÒªº¦×ÖºÍÁ´½Ó£¬ÕâЩÍþвÐÐΪÕßÄܹ»´ÓÌáÉýÆä¿ÉÒÉÔÚÏß×ʲúµÄSEOÖÐÊÜÒ棬ÓÉÓÚSpotifyµÄÍøÂç²¥·ÅÆ÷Ч¹û»á·ºÆðÔÚGoogleµÈËÑË÷ÒýÇæÖС£ÀýÈ磬ÓÐÍøÂçÇ徲ר¼Ò·¢Ã÷ÁËÎÊÌâΪ¡°Sony Vegas Pro 13 Crack...¡±µÄSpotify²¥·ÅÁбí£¬¸ÃÁÐ±í½«Á÷Á¿Ö¸µ¼ÖÁ²¥·ÅÁбíÎÊÌâºÍÐÎòÖÐÁгöµÄ¡°Ãâ·Ñ¡±Èí¼þÍøÕ¾¡£±ðµÄ£¬²¥¿ÍÒ²±»ÓÃÓÚÐû´«À¬»øÁ´½Ó¡¢¿´ËÆȦÌ׵ĵ籨ƵµÀµÈ¡£ÕâЩÁ´½Óͨ³ £»áÖ¸µ¼Óû§ÖÁ³äÂú¹ã¸æ¡¢À¬»øÄÚÈÝ¡¢Ðéα¡°ÊӲ족ºÍ¼ÓÃÜÔùÆ·µÄ·þÎñÆ÷£¬Óû§±ØÐèä¯ÀÀÕâЩÐÅÏ¢²Å»ª×îÖÕÏÂÔØÆƽâµÄÈí¼þ²úÆ·£¬¶øÕâ»á´øÀ´Î£º¦¡£SpotifyÒÑɾ³ýÏà¹Ø²¥·ÅÁбíºÍ²¥¿Í£¬²¢ÌåÏÖÆäƽ̨¹æÔòեȡÐû²¼¡¢·ÖÏí»òÌṩÓйØʵÑé¶ñÒâÈí¼þ»òÏà¹Ø¶ñÒâÐÐΪµÄ˵Ã÷¡£Í¬Ê±£¬µÚÈý·½Ó¦ÓóÌÐòºÍ·þÎñÒ²±»ÍþвÐÐΪÕßʹÓÃÀ´½«À¬»øÄÚÈÝÒýÈëƽ̨¡£


https://www.bleepingcomputer.com/news/security/spotify-abused-to-promote-pirated-software-and-game-cheats/


2. Great Plains Regional Medical CenterÔâÀÕË÷Èí¼þ¹¥»÷£¬133,000ÈËÊý¾Ýй¶


11ÔÂ19ÈÕ£¬Great Plains Regional Medical Center£¨Î»ÓÚ¶í¿ËÀ­ºÉÂíÖÝ£©ÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ133,149È˵ÄСÎÒ˽¼ÒÊý¾ÝÔ⵽й¶¡£ÔÚ2024Äê9ÔÂ5ÈÕÖÁ8ÈÕʱ´ú£¬Ò»ÃûÍþвÐÐΪÕß»á¼û²¢¼ÓÃÜÁ˸ÃÒ½ÁÆÖÐÐÄϵͳÉϵÄÎļþ£¬²¢¿ÉÄܸ´ÖÆÁËÆäÖÐһЩÎļþ¡£¸ÃÒ½ÁÆÖÐÐÄÔÚÍøÂçÇå¾²¹«Ë¾µÄЭÖúÏÂÕö¿ªÁËÊӲ죬²¢Ñ¸ËÙ»Ö¸´ÁËϵͳ£¬µ«ÓÐÏÞÊýÄ¿µÄ»¼ÕßÐÅÏ¢ÎÞ·¨»Ö¸´¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜ°üÀ¨ÐÕÃû¡¢Éú³Ýͳ¼ÆÐÅÏ¢¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢ÁÙ´²ÖÎÁÆÐÅÏ¢¡¢¼ÝʻִÕÕºÅÂëÒÔ¼°Éç»áÇå¾²ºÅÂëµÈÃô¸ÐÊý¾Ý¡£¸ÃÒ½ÁÆÖÐÐÄÕýÔÚ֪ͨÊÜÓ°ÏìµÄ»¼Õߣ¬²¢ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓüà¿Ø¡£È»¶ø£¬¸ÃÒ½ÁÆÖÐÐIJ¢Î´Í¸Â¶Óйع¥»÷ÆäϵͳµÄÀÕË÷Èí¼þ¼Ò×åµÄÐÅÏ¢£¬ÏÖÔÚҲûÓÐÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´ÎÇå¾²Îó²îÈÏÕæ¡£


https://securityaffairs.com/171156/data-breach/great-plains-regional-medical-center-data-breach.html


3. EquinoxÊý¾Ýй¶ÊÂÎñ£ºLockBitÀÕË÷Èí¼þÍÅ»ïÒÉΪĻºóºÚÊÖ


11ÔÂ20ÈÕ£¬Å¦Ô¼ÖÝÎÀÉúÓ빫ÖÚ·þÎñ×éÖ¯Equinox֪ͨÁè¼Ý21,000Ãû¿Í»§ºÍÔ±¹¤£¬ËûÃÇÔÚ½üÆ߸öÔÂÇ°µÄÒ»´ÎÊý¾ÝÇå¾²ÊÂÎñÖУ¬Ð¡ÎÒ˽¼Ò¿µ½¡¡¢²ÆÎñµÈÐÅÏ¢±»µÁ¡£¾ÝÍƲ⣬Õâ´ÎÊÂÎñÓɱ¾Ó¦Òѱ»¹Ø±ÕµÄLockBitÀÕË÷Èí¼þÍÅ»ïËùΪ¡£EquinoxΪŦԼÖÝÊ׸®µØÇøÌṩÐÄÀí¿µ½¡¡¢½äñ«·þÎñ¡¢¼ÒÍ¥±©Á¦Ö§³ÖµÈ¶àÏî·þÎñ¡£4ÔÂ29ÈÕ£¬¸Ã×éÖ¯ÍøÂç»á¼ûÖÐÖ¹£¬Ëæºó·¢Ã÷ÍøÂçÖеÄijЩÎļþ¿ÉÄܱ»Î´¾­ÊÚȨ»á¼û»òÏÂÔØ¡£9ÔÂ16ÈÕ£¬EquinoxÈ·ÈÏijЩÈ˵ÄСÎÒ˽¼ÒºÍÊܱ £»¤µÄ¿µ½¡ÐÅÏ¢¿ÉÄÜÒò´ËÊÂÎñÊÜÓ°Ïì¡£ÖµµÃ×¢ÖصÄÊÇ£¬LockBit 3.0ÀÕË÷Èí¼þ×éÖ¯ÔøÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÁгöEquinox£¬Éù³ÆÇÔÈ¡ÁË49GBÊý¾Ý£¬²¢×îÖÕй¶ÁË31.8GBÎļþ¡£Ö»¹ÜLockBitÔÚ2Ô·ÝÊܵ½¸ßµ÷ÆÆË𣬵«×èÖ¹ÀÕË÷Èí¼þ»öÑêÈÔÈ»ºÜÊÇÄÑÌ⣬LockBit 3.0ÈÔÊǽñÄê×î»îÔ¾µÄ¼ÓÃܺÍÀÕË÷ÍÅ»ïÖ®Ò»¡£


https://www.theregister.com/2024/11/20/equinox_patients_employees_data/


4. Oracle PLM¿ò¼Ü¸ßΣÎó²îÔâÆÕ±éʹÓã¬Óû§Ð辡¿ì´ò²¹¶¡


11ÔÂ20ÈÕ£¬Oracle½üÆÚÐû²¼ÖÒÑÔ£¬Ö¸³öÆäѸËÙ²úÆ·ÉúÃüÖÜÆÚÖÎÀí£¨PLM£©¿ò¼ÜÖб£´æÒ»¸öÒѱ»ÆÕ±éʹÓõĸßÑÏÖØÐÔÇå¾²Îó²î£¬±àºÅΪCVE-2024-21287£¬CVSSÆÀ·ÖΪ7.5¡£¸ÃÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿É±»Ô¶³ÌʹÓ㬿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶£¬°üÀ¨ÎļþÄÚÈÝ¡£OracleÔÚͨ¸æÖÐÇ¿µ÷£¬ÎÞÐèÓû§ÃûºÍÃÜÂ룬¹¥»÷Õß¼´¿Éͨ¹ýÍøÂçÔ¶³Ì¹¥»÷£¬ÀÖ³ÉʹÓøÃÎó²îºóÄܹ»ÏÂÔØPLMÓ¦ÓóÌÐòȨÏÞÏ¿ɻá¼ûµÄÎļþ¡£CrowdStrikeµÄÇå¾²Ñо¿Ö°Ô±Joel SnapeºÍLutz WolfÒò·¢Ã÷²¢±¨¸æ´ËÎó²î¶øÊܵ½ÔÞÓþ¡£È»¶ø£¬ÏÖÔÚÉв»ÇåÎúË­ÔÚʹÓôËÎó²î¡¢¶ñÒâÔ˶¯µÄÄ¿µÄÊÇË­ÒÔ¼°¹¥»÷¹æÄ£Óжà¹ã¡£OracleÇå¾²°ü¹Ü¸±×ܲÃEric Maurice½¨ÒéÓû§¾¡¿ìÓ¦ÓÃ×îв¹¶¡ÒÔ»ñµÃ×î¼Ñ± £»¤¡£


https://thehackernews.com/2024/11/oracle-warns-of-agile-plm-vulnerability.html


5. WordPress²å¼þReally Simple SecurityÏÖÑÏÖØÎó²î£¬Ó°Ï쳬400Íò¸öÍøÕ¾


11ÔÂ18ÈÕ£¬WordPress²å¼þReally Simple Security±£´æÑÏÖØÎó²î£¬Ó°ÏìÁËÁè¼Ý400Íò¸öÍøÕ¾£¬Ê¹¹¥»÷ÕßÄܹ»»ñµÃÍêÈ«µÄÖÎÀíÔ±»á¼ûȨÏÞ¡£¸ÃÎó²î±àºÅΪCVE-2024-10924£¬CVSSÆÀ·ÖΪ9.8£¬ÊÇWordfenceÑо¿Ö°Ô±Istv¨¢n M¨¢rtonÔÚ2024Äê11ÔÂ6ÈÕ·¢Ã÷µÄ¡£Really Simple Security£¨ÒÔÇ°³ÆΪReally Simple SSL£©ÊÇÒ»¿îÊ¢ÐеÄWordPress¹¤¾ß£¬ÓÃÓÚÔöÇ¿ÍøÕ¾Çå¾²ÐÔ¡£È»¶ø£¬¸Ã²å¼þÔÚË«ÒòËØÉí·ÝÑéÖ¤¹¦Ð§Öб£´æÉí·ÝÑéÖ¤ÈƹýÎó²î£¬µ±ÆôÓøù¦Ð§Ê±£¬¹¥»÷Õß¿ÉÒÔÔ¶³Ì»á¼ûÍøÕ¾ÉϵÄÈκÎÕÊ»§£¬°üÀ¨ÖÎÀíÔ±ÕÊ»§¡£Îó²îÊÇÓÉÓÚÔÚË«ÒòËØREST API²Ù×÷ÖжÔÓû§¼ì²é¹ýʧ´¦Öóͷ£²»µ±Ôì³ÉµÄ¡£Ñо¿Ö°Ô±ÖÒÑԳƣ¬¸ÃÎó²î¿É±àд¾ç±¾£¬ÔÊÐí¹¥»÷ÕßÔÚ´ó¹æÄ£×Ô¶¯¹¥»÷ÖÐ×Ô¶¯Ê¹ÓᣴËÎó²î½öÓ°ÏìÔÚ²å¼þÉèÖÃÖÐÆôÓÃÁË¡°Ë«ÒòËØÉí·ÝÑéÖ¤¡±µÄWordPressÍøÕ¾£¬Ó°Ïì¹æÄ£°üÀ¨¡°Ãâ·Ñ°æ¡±¡¢¡°×¨Òµ°æ¡±ºÍ¡°×¨Òµ¶àÕ¾µã°æ¡±µÄ²å¼þ°æ±¾9.0.0ÖÁ9.1.1.1¡£¸ÃÎó²îÒÑÔÚ9.1.2°æÖÐÐÞ¸´£¬Çå¾²¸üÐÂÒÑÐû²¼£¬µ«ÖÎÀíÔ±Ó¦ÑéÖ¤ËûÃÇÊÇ·ñʹÓõÄÊÇ×îа汾¡£


https://securityaffairs.com/171100/hacking/really-simple-security-plugin-flaw-affects-4m-sites.html


6. ·¨¹úÒ½ÔºÊý¾Ýй¶£º75Íò»¼Õ߼ͼÔâÆعâ


11ÔÂ20ÈÕ£¬Ò»ÆðÉæ¼°·¨¹úÒ½ÔºµÄÊý¾Ýй¶ÊÂÎñÒý·¢ÁËÆÕ±é¹Ø×¢¡£Ò»Ãû×Ô³ÆΪ¡°nears¡±µÄÍþвÐÐΪÕßÉù³Æ¹¥»÷Á˶à¼Ò·¨¹úÒ½ÁÆ»ú¹¹£¬ÄÜ»á¼ûÁè¼Ý150ÍòÈ˵IJ¡Àú¡£Ïêϸ¶øÑÔ£¬ºÚ¿Íͨ¹ýÈí¼þÒ½ÁƼ¯ÍÅÈëÇÖÁËÌṩµç×Ó²¡Àú½â¾ö¼Æ»®µÄMediBoard£¬µ¼ÖÂÒ»¼Òδǩ×ֵķ¨¹úÒ½Ôº75ÍòÓàÃû»¼ÕßµÄÒ½ÁƼͼ±»Ð¹Â¶¡£ÕâЩ¼Í¼°üÀ¨»¼ÕßµÄÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢ÐԱ𡢼Òͥסַ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Ò½ÉúÐÅÏ¢¡¢´¦·½¼°¿µ½¡¿¨ÀúÊ·µÈÃô¸ÐÊý¾Ý¡£Softway Medical GroupÈ·ÈϺڿÍÈëÇÖÁËMediBoardÕÊ»§£¬µ«Ç¿µ÷Êý¾Ýй¶²¢·ÇÈí¼þÎó²î»òÉèÖùýʧËùÖ£¬¶øÊÇҽԺʹÓÃÁ˱»µÁµÄƾ֤¡£ºÚ¿ÍÉõÖÁ×îÏȳöÊÛËûÃÇÉù³ÆµÄMediBoardƽ̨»á¼ûȨÏÞ£¬Éæ¼°¶à¼Ò·¨¹úÒ½Ôº£¬ÔÊÐíÂò·½Éó²éÒ½ÔºµÄÃô¸ÐÒ½ÁƱ£½¡ºÍÕ˵¥ÐÅÏ¢¡¢»¼Õ߼ͼ£¬²¢¾ß±¸°²ÅźÍÐÞ¸ÄÔ¤Ô¼»òÒ½ÁƼͼµÄÄÜÁ¦¡£Ö»¹ÜÊý¾ÝÉÐδ±»¹ûÕæ³öÊÛ£¬µ«±£´æÃâ·Ñ鶵½ÍøÉϵÄΣº¦£¬ÔöÌíÁËÊÜÓ°ÏìÖ°Ô±ÔâÊÜÍøÂç´¹ÂÚ¡¢Õ©Æ­ºÍÉç»á¹¤³Ì¹¥»÷µÄ¿ÉÄÜÐÔ¡£


https://www.bleepingcomputer.com/news/security/cyberattack-at-french-hospital-exposes-health-data-of-750-000-patients/