³¬26.9Íò¸öÍøÕ¾Ò»¸öÔÂÄÚѬȾJavaScript¶ñÒâ´úÂë
Ðû²¼Ê±¼ä 2025-06-161. ³¬26.9Íò¸öÍøÕ¾Ò»¸öÔÂÄÚѬȾJavaScript¶ñÒâ´úÂë
6ÔÂ13ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±½üÆÚÅû¶ÁËÒ»Ïî´ó¹æÄ£¹¥»÷»î¶¯£¬£¬£¬¹¥»÷ÕßÔÚÕýµ±ÍøÕ¾ÉÏ×¢ÈëʹÓà JSFuck ÊÖÒÕ»ìÏýµÄ¶ñÒâ JavaScript ´úÂë¡£¡£¡£ÓÉÓÚÉæ¼°²»ÑÅÓÃÓ£¬£¬¸ÃÊÖÒÕ±»ÍøÂçÇå¾²¹«Ë¾ÃüÃûΪ¡°JSFireTruck¡±¡£¡£¡£×¢Èë´úÂë»á¼ì²éÍøÕ¾Òý¼öȪԴ£¬£¬£¬ÈôÒý¼öȪԴΪGoogle¡¢BingµÈËÑË÷ÒýÇæ£¬£¬£¬Êܺ¦Õß½«±»Öض¨Ïòµ½Èö²¥¶ñÒâÈí¼þ¡¢Îó²îʹÓóÌÐò¡¢¾ÙÐÐÁ÷Á¿±äÏÖºÍÈö²¥¶ñÒâ¹ã¸æµÄ¶ñÒâÍøÖ·¡£¡£¡£ÔÚ2025Äê3ÔÂ26ÈÕÖÁ4ÔÂ25ÈÕʱ´ú£¬£¬£¬ÓÐ269,552¸öÍøÒ³±»·¢Ã÷ѬȾÁËʹÓøÃÊÖÒÕµÄJavaScript´úÂ룬£¬£¬4ÔÂ12ÈÕÊ״ηºÆð·åÖµ£¬£¬£¬µ¥ÈÕ·¢Ã÷³¬5Íò¸öÊÜÑ¬È¾ÍøÒ³¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬Gen Digital½Ò¿ªÁËÃûΪHelloTDSµÄÖØ´óÁ÷Á¿·Ö·¢Ð§À͵ÄÃæÉ´£¬£¬£¬¸ÃЧÀÍͨ¹ý×¢ÈëÍøÕ¾µÄÔ¶³ÌÍйÜJavaScript´úÂ룬£¬£¬ÓÐÌõ¼þµØ½«»á¼ûÕßÖØ¶¨Ïòµ½ÐéαÑéÖ¤ÂëÒ³Ãæ¡¢ÊÖÒÕÖ§³ÖÕ©ÆÒ³ÃæµÈ¡£¡£¡£ÆäÖ÷ҪĿµÄÊǶÔÊܺ¦Õß×°±¸ÊÕÂÞÖ¸ÎÆÌØÕ÷ºó£¬£¬£¬È·¶¨Í¶·ÅÄÚÈÝÐÔ×Ó£¬£¬£¬ÈôÓû§·ÇºÏÊÊÄ¿µÄ£¬£¬£¬»á±»Öض¨Ïòµ½Á¼ÐÔÍøÒ³¡£¡£¡£¹¥»÷»î¶¯Èë¿ÚµãÊÇÊÜѬȾ»ò±»¿ØÖƵÄÁ÷ýÌåÍøÕ¾¡¢Îļþ¹²ÏíЧÀͼ°¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£Êܺ¦Õßɸѡ»ùÓÚµØÀíλÖá¢IPµØµãºÍä¯ÀÀÆ÷Ö¸ÎÆÌØÕ÷£¬£¬£¬Í¨¹ýVPN»òÎÞÍ·ä¯ÀÀÆ÷µÄÅþÁ¬»á±»¼ì²â²¢¾Ü¾ø¡£¡£¡£²¿·Ö¹¥»÷Á´»áÌṩʹÓÃClickFixÕ½ÂÔÓÕÆÓû§ÔËÐжñÒâ´úÂëµÄÐéαÑéÖ¤ÂëÒ³Ãæ£¬£¬£¬Ê¹»úеѬȾ¡°·åÖµÖ®¹â¡±¶ñÒâÈí¼þ£¬£¬£¬¸ÃÈí¼þ»á¼ÓÔØÐÅÏ¢ÇÔÈ¡³ÌÐòÈçLumma¡£¡£¡£
https://thehackernews.com/2025/06/over-269000-websites-infected-with.html
2. ³¬4.6ÍòGrafanaʵÀýδÐÞ²¹Îó²îCVE-2025-4123
6ÔÂ15ÈÕ£¬£¬£¬Áè¼Ý46,000¸öÃæÏò»¥ÁªÍøµÄGrafanaʵÀýÒòδÐÞ²¹¿Í»§¶Ë¿ª·ÅÖØ¶¨ÏòÎó²î£¨CVE-2025-4123£©¶øÌ»Â¶ÓÚΣº¦Ö®ÖУ¬£¬£¬¸ÃÎó²î¿ÉÖ¶ñÒâ²å¼þÖ´ÐÐÓëÕÊ»§½ÓÊÜ¡£¡£¡£¸ÃÎó²îÔÚGrafana Labs 5ÔÂ21ÈÕÐû²¼µÄÇå¾²¸üÐÂÖлñµÃ½â¾ö¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ý¹ØÁªÊý¾ÝÓëÆ½Ì¨ÔÚÉú̬ϵͳÖеÄÂþÑÜ£¬£¬£¬ÆÀ¹À³ö¹²ÓÐ128,864¸öʵÀý̻¶ÔÚÍøÉÏ£¬£¬£¬ÆäÖÐ46,506¸öÈÔÔÚÔËÐб£´æÎó²îµÄ°æ±¾£¬£¬£¬Õ¼±ÈÔ¼36%¡£¡£¡£OX SecurityÉîÈëÆÊÎö·¢Ã÷£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÁ¬Ïµ¿Í»§¶Ë·¾¶±éÀúºÍ¿ª·ÅÖØ¶¨Ïò»úÖÆ£¬£¬£¬ÓÕʹÊܺ¦Õßµã»÷¶ñÒâURL£¬£¬£¬´Ó¶ø´ÓÍþвÐÐΪÕß¿ØÖƵÄÍøÕ¾¼ÓÔØ¶ñÒâGrafana²å¼þ£¬£¬£¬ÕâЩ¶ñÒâÁ´½Ó¿ÉÔÚÓû§ä¯ÀÀÆ÷ÖÐÖ´ÐÐí§ÒâJavaScript¡£¡£¡£¸ÃÎó²îÎÞÐèÌáÉýȨÏÞ£¬£¬£¬×ÝÈ»ÆôÓÃÄäÃû»á¼ûÒ²¿Éʩչ×÷Ó㬣¬£¬ÔÊÐí¹¥»÷ÕßÐ®ÖÆÓû§»á»°¡¢¸ü¸ÄÕÊ»§Æ¾Ö¤£¬£¬£¬²¢ÔÚ×°ÖÃGrafana Image Renderer²å¼þµÄÇéÐÎÏÂÖ´ÐÐЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©À´¶ÁÈ¡ÄÚ²¿×ÊÔ´¡£¡£¡£Ö»¹ÜGrafanaÖеÄĬÈÏÄÚÈÝÇå¾²Õ½ÂÔ£¨CSP£©ÌṩÁËÒ»¶¨±£»£»£»£»£»£»¤£¬£¬£¬µ«ÎÞ·¨×èÖ¹´ËÀ๥»÷¡£¡£¡£OX SecurityµÄÎó²îÅú×¢£¬£¬£¬CVE-2025-4123¿ÉÔÚ¿Í»§¶Ë±»Ê¹Ó㬣¬£¬²¢Í¨¹ýGrafanaÔÉúµÄJavaScript·ÓÉÂß¼ÈÆ¹ýÏÖ´úä¯ÀÀÆ÷¹æ·¶»¯»úÖÆ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-46-000-grafana-instances-exposed-to-account-takeover-bug/
3. ¼ÓÄôóµÚ¶þ´óº½¿Õ¹«Ë¾Î÷½Ýº½¿ÕÔâÓöÍøÂç¹¥»÷
6ÔÂ15ÈÕ£¬£¬£¬Î÷½Ýº½¿Õ×÷Ϊ¼ÓÄôóµÚ¶þ´óº½¿Õ¹«Ë¾£¬£¬£¬ÕýÔÚÊÓ²ìÒ»ÆðÓ°ÏìÆä²¿·ÖÄÚ²¿ÏµÍ³ºÍÒÆ¶¯Ó¦ÓóÌÐòµÄÍøÂçÇå¾²ÊÂÎñ¡£¡£¡£¸ÃÊÂÎñµ¼Ö¶àÃûÓû§ÎÞ·¨»á¼ûÏà¹ØÏµÍ³£¬£¬£¬µ«¹«Ë¾Ç¿µ÷ÔËÓªÇ徲δÊÜÓ°Ïì¡£¡£¡£Î÷½Ýº½¿ÕÔÚÊÂÎñ±¬·¢ºóѸËÙÆô¶¯ÁËרÃŵÄÄÚ²¿ÍŶӣ¬£¬£¬²¢ÓëÖ´·¨²¿·ÖºÍ¼ÓÄôó½»Í¨²¿Ï¸ÃÜÏàÖú£¬£¬£¬ÒÔÊÓ²ìÊÂÎñÔµ¹ÊÔÓɲ¢Ö»¹ÜïÔÌÆäÓ°Ïì¡£¡£¡£¹«Ë¾ÕýÖÂÁ¦ÓÚ±£»£»£»£»£»£»¤ÂÿͺÍÔ±¹¤µÄÃô¸ÐÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬²¢¶ÔЧÀÍÖÐÖ¹ÌåÏÖǸÒâ¡£¡£¡£ÏÖÔÚ£¬£¬£¬¹ØÓڴ˴ι¥»÷µÄÏêϸϸ½ÚÉв»ÇåÎú£¬£¬£¬µ«Î÷½Ýº½¿ÕÔÊÐíÔÚ»ñµÃ¸ü¶àÐÅÏ¢ºóʵʱ·ÖÏí¡£¡£¡£¹«Ë¾½¨ÒéÂÿͺÍÔ±¹¤ÔÚ¹²ÏíСÎÒ˽¼ÒÐÅϢʱ¼á³ÖÉóÉ÷¡£¡£¡£×èÖ¹2025Äê6ÔÂ14ÈÕ£¬£¬£¬Î÷½Ýº½¿Õº½°àÔËÓªÇ徲δÊÜÓ°Ï죬£¬£¬¹«Ë¾ÕýÔÚÆÀ¹ÀÊÂÎñÓ°Ï첢ѸËÙ½â¾öÎÊÌâ¡£¡£¡£
https://securityaffairs.com/179027/uncategorized/canadas-airline-westjet-is-containing-a-cyberattack.html
4. SimpleHelpÎó²îÔâʹÓ㬣¬£¬¹¥»÷¹«ÓÃÊÂÒµ¼Æ·ÑÈí¼þ¿Í»§
6ÔÂ13ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²»ú¹¹CISA·¢³öÖÒÑÔ£¬£¬£¬ÀÕË÷Èí¼þÔËÓªÉÌÕýʹÓÃSimpleHelpÎó²î¶Ô¹«ÓÃÊÂÒµ¼Æ·ÑÈí¼þÌṩÉ̵Ŀͻ§Ìᳫ¹¥»÷¡£¡£¡£±»Ê¹ÓõÄÎó²î±àºÅΪCVE-2024-57727£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷Õß¼ìË÷Ãô¸ÐÐÅÏ¢£¬£¬£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿¡£¡£¡£´ËÎó²îÓëÁíÍâÁ½¸öÔÊÐí¹¥»÷ÕßÉÏ´«í§ÒâÎļþ²¢ÌáÉýȨÏÞΪÖÎÀíÔ±µÄÎó²îCVE-2024-57728ºÍCVE-2024-57726ÓÚ1Ô·Ýһͬ»ñµÃÐÞ²¹¡£¡£¡£CISAÔÚ·¢Ã÷ÍþвÐÐΪÕßʹÓÃCVE-2024-57727¹¥»÷ÔËÐÐSimpleHelpÔ¶³Ì¼à¿ØºÍÖÎÀíÈí¼þµÄ×°±¸ºó£¬£¬£¬ÓÚ2Ô·ݽ«¸ÃÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îÁбíÖС£¡£¡£5ÔÂÏÂÑ®£¬£¬£¬SophosÖÒÑÔ³ÆDragonForceÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜʹÓÃSimpleHelpʵÀýÎó²îΣ¼°ÍйÜЧÀÍÌṩÉ̼°Æä¿Í»§µÄÇå¾²¡£¡£¡£CISA½¨ÒéÈí¼þ¹©Ó¦ÉÌ¡¢ÏÂÓοͻ§ºÍ×îÖÕÓû§Á¬Ã¦½ÓÄɲ½·¥ÐÞ²¹ÆäSimpleHelp°²ÅŲ¢Ñ°ÕÒÍ×ÐÖ¸±ê¡£¡£¡£
https://www.securityweek.com/simplehelp-vulnerability-exploited-against-utility-billing-software-users/
5. º«¹úƱÎñƽ̨Yes24ÔâÀÕË÷¹¥»÷£¬£¬£¬ÓéÀÖ¹¤ÒµÏÝÈëÔÓÂÒ
6ÔÂ12ÈÕ£¬£¬£¬º«¹úÖ÷ҪƱÎñƽ̨¼°ÔÚÏßͼÊéÁãÊÛÉÌYes24ÓÚ6ÔÂ9ÈÕÆÆÏþÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ¼Ö¸ùúÓéÀÖ¹¤ÒµÏÝÈëÔÓÂÒ¡£¡£¡£´Ë´Î¹¥»÷ÖÂʹYes24ÍøÕ¾¼°Ð§ÀÍÒ»Á¬ËÄÌì̱»¾£¬£¬£¬ÔÚÏßÑݳª»áÔ¤¶©¡¢µç×ÓÊé»á¼ûºÍÉçÇøÂÛ̳¹¦Ð§¾ùÎÞ·¨Õý³£Ê¹Ó㬣¬£¬¹«Ë¾ËäÉùÃ÷Ä¿µÄÔÚ6ÔÂ15ÈÕǰÖÜÈ«»Ö¸´ÔËÓª£¬£¬£¬µ«Ó°ÏìÒÑÊ®·ÖÏÔÖø¡£¡£¡£º«¹úÒþ˽î¿Ïµ»ú¹¹¡°Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»£»£»¤Î¯Ô±»á¡±ÒÑÆô¶¯ÊӲ죬£¬£¬ÏÓÒÉ´Ë´ÎÊÂÎñ¿ÉÄܵ¼Ö¿ͻ§Êý¾Ýй¶£¬£¬£¬Õþ¸®½«Éó²éYes24ÊÇ·ñÍÆÐÐÁ˺«¹úÊý¾ÝÒþ˽¹æÔò¶¨µÄÖ´·¨ÒåÎñ¡£¡£¡£ÍâµØÃ½Ì屨µÀ£¬£¬£¬´Ë´ÎЧÀÍÖÐÖ¹Òý·¢ÁËÁ¬Ëø·´Ó¦£¬£¬£¬°üÀ¨ÆÓ±¦½£¡¢ENHYPEN¡¢ATEEZ¼°Ëµ³ª¸èÊÖB.IÔÚÄڵĶàλº«Á÷Ã÷ÐÇÔ¤ÊÛ¼°·ÛË¿»î¶¯±»ÆÈÍÆ³Ù»ò×÷·Ï£¬£¬£¬²¿·ÖÒôÀÖ¾çÖÆ×÷·½Ò²ÒªÇó¹ÛÖÚ³öʾֽÖÊÃÅÆ±»òÓʼþÈ·ÈϺ¯È볡£¬£¬£¬µ¼Ö²¿·Ö¹ÛÖÚÒòÎÞ·¨Ìṩ¿ÉÑé֤ƱÎñÐÅÏ¢¶øÔâ¾ÜÈ볡¡£¡£¡£Yes24ÖÜÈýÉùÃ÷ÒÑÖØÐÂÕÆ¿ØÖÎÀíÔ±ÕË»§£¬£¬£¬ÕýÆð¾¢»Ö¸´ÆäËûЧÀÍ£¬£¬£¬µ«¹¥»÷ÕßÉí·ÝÏÖÔÚÉÐδÃ÷È·¡£¡£¡£¹«Ë¾ÌåÏÖÉÐδȷÈÏСÎÒ˽¼ÒÐÅÏ¢Íâй£¬£¬£¬µ«ÒÑÏòº«¹úÊý¾ÝÒþ˽»ú¹¹±¨¸æÉæ¼°¿Í»§Êý¾ÝδÊÚȨ»á¼ûµÄ¿ÉÒɻ£¬£¬£¬²¢ÔÊÐíÈôºóÐøÊÓ²ì֤ʵСÎÒ˽¼ÒÐÅϢй¶£¬£¬£¬½«Á¬Ã¦Í¨ÖªÓû§¡£¡£¡£
https://therecord.media/yes24-south-korea-ransomware-attack
6. ºÚ¿Í³ÆÕ®Îñ´ßÊÕ¹«Ë¾CCCÔâÈëÇÖ£¬£¬£¬900¶àÍòÃÀ¹úÈËÐÅϢй¶
6ÔÂ13ÈÕ£¬£¬£¬ÍþвÐÐΪÕßÉù³ÆÒÑÈëÇÖ¸¥¼ªÄáÑÇÖÝÕ®Îñ´ßÊÕ¹«Ë¾ÐÅÓÿØÖƹ«Ë¾£¨CCC£©£¬£¬£¬²¢µ¼ÖÂÊý°ÙÍòÃÀ¹úÈËСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£ÕâЩºÚ¿ÍÔÚÒ»¸öÊý¾Ýй¶ÂÛ̳ÉÏÐû²¼ÁËÏà¹ØÐÅÏ¢£¬£¬£¬Éù³ÆÇÔÈ¡ÁË910ÍòÃÀ¹úÈ˵ÄÃô¸ÐÊý¾Ý¡£¡£¡£CCCÊÇÒ»¼ÒרעÓÚÒ½ÁƱ£½¡ºÍµçÐÅÐÐÒµµÄÕ®Îñ´ßÊÕ¹«Ë¾£¬£¬£¬ÏÖÔÚÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£Ñо¿ÍŶÓÊÓ²ìÁ˹¥»÷Õ߸½¼ÓÔÚÌû×ÓÖеÄÊý¾ÝÑù±¾£¬£¬£¬·¢Ã÷й¶µÄÐÅÏ¢¿ÉÄܰüÀ¨È«Ãû¡¢µç»°ºÅÂë¡¢ÐÔ±ð¡¢ÄêËê¡¢·¿²úÐÅÏ¢¡¢µäÖÊ´û¿îÊý¾ÝºÍ´û¿îÀàÐ͵ȡ£¡£¡£¹¥»÷Õßͨ³£¶ÔÓµÓдó×ÚÏêϸÐÅÏ¢µÄÊý¾Ý¿â¸ÐÐËȤ£¬£¬£¬ÓÉÓÚÕâЩÊý¾Ý¿ÉÓÃÓÚ×Ô¶¯»¯´¹ÂÚÓʼþÕ©Æ¡¢½ðÈÚթƺÍÉí·Ý͵ÇÔ¡£¡£¡£Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢ºÍ²ÆÎñÐÅÏ¢µÄй¶Ϊ¶¨Öƹ¥»÷ÌṩÁ˸»×ãʱ»ú£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÐÅÏ¢Õë¶Ô±£´æ²ÆÎñÎÊÌâµÄÓû§¾ÙÐÐÚ²ÆÐÔ²ÆÎñÔ®Öú»òÆäËûЧÀ͵ÄÕ©Æ¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬Õâ²¢·ÇCCCÊ×´ÎÔâÓöÊý¾Ýй¶ÊÂÎñ¡£¡£¡£2023Ä꣬£¬£¬¸Ã¹«Ë¾¾ÍÔøÅû¶һÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬µ¼ÖÂÁè¼Ý30ÍòÃÀ¹úסÃñµÄÊý¾Ýй¶£¬£¬£¬Æäʱй¶µÄÐÅÏ¢°üÀ¨ÐÕÃûºÍÉç»áÇå¾²ºÅÂëµÈ¡£¡£¡£
https://cybernews.com/news/credit-control-corporation-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ