³¬26.9Íò¸öÍøÕ¾Ò»¸öÔÂÄÚѬȾJavaScript¶ñÒâ´úÂë
Ðû²¼Ê±¼ä 2025-06-161. ³¬26.9Íò¸öÍøÕ¾Ò»¸öÔÂÄÚѬȾJavaScript¶ñÒâ´úÂë
6ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±½üÆÚÅû¶ÁËÒ»Ïî´ó¹æÄ£¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÕýµ±ÍøÕ¾ÉÏ×¢ÈëʹÓà JSFuck ÊÖÒÕ»ìÏýµÄ¶ñÒâ JavaScript ´úÂë¡£¡£¡£¡£¡£¡£ÓÉÓÚÉæ¼°²»ÑÅÓÃÓ£¬£¬£¬£¬£¬¸ÃÊÖÒÕ±»ÍøÂçÇå¾²¹«Ë¾ÃüÃûΪ¡°JSFireTruck¡±¡£¡£¡£¡£¡£¡£×¢Èë´úÂë»á¼ì²éÍøÕ¾Òý¼öȪԴ£¬£¬£¬£¬£¬£¬ÈôÒý¼öȪԴΪGoogle¡¢BingµÈËÑË÷ÒýÇæ£¬£¬£¬£¬£¬£¬Êܺ¦Õß½«±»Öض¨Ïòµ½Èö²¥¶ñÒâÈí¼þ¡¢Îó²îʹÓóÌÐò¡¢¾ÙÐÐÁ÷Á¿±äÏÖºÍÈö²¥¶ñÒâ¹ã¸æµÄ¶ñÒâÍøÖ·¡£¡£¡£¡£¡£¡£ÔÚ2025Äê3ÔÂ26ÈÕÖÁ4ÔÂ25ÈÕʱ´ú£¬£¬£¬£¬£¬£¬ÓÐ269,552¸öÍøÒ³±»·¢Ã÷ѬȾÁËʹÓøÃÊÖÒÕµÄJavaScript´úÂ룬£¬£¬£¬£¬£¬4ÔÂ12ÈÕÊ״ηºÆð·åÖµ£¬£¬£¬£¬£¬£¬µ¥ÈÕ·¢Ã÷³¬5Íò¸öÊÜÑ¬È¾ÍøÒ³¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬£¬Gen Digital½Ò¿ªÁËÃûΪHelloTDSµÄÖØ´óÁ÷Á¿·Ö·¢Ð§À͵ÄÃæÉ´£¬£¬£¬£¬£¬£¬¸ÃЧÀÍͨ¹ý×¢ÈëÍøÕ¾µÄÔ¶³ÌÍйÜJavaScript´úÂ룬£¬£¬£¬£¬£¬ÓÐÌõ¼þµØ½«»á¼ûÕßÖØ¶¨Ïòµ½ÐéαÑéÖ¤ÂëÒ³Ãæ¡¢ÊÖÒÕÖ§³ÖÕ©ÆÒ³ÃæµÈ¡£¡£¡£¡£¡£¡£ÆäÖ÷ҪĿµÄÊǶÔÊܺ¦Õß×°±¸ÊÕÂÞÖ¸ÎÆÌØÕ÷ºó£¬£¬£¬£¬£¬£¬È·¶¨Í¶·ÅÄÚÈÝÐÔ×Ó£¬£¬£¬£¬£¬£¬ÈôÓû§·ÇºÏÊÊÄ¿µÄ£¬£¬£¬£¬£¬£¬»á±»Öض¨Ïòµ½Á¼ÐÔÍøÒ³¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯Èë¿ÚµãÊÇÊÜѬȾ»ò±»¿ØÖƵÄÁ÷ýÌåÍøÕ¾¡¢Îļþ¹²ÏíЧÀͼ°¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£¡£¡£¡£Êܺ¦Õßɸѡ»ùÓÚµØÀíλÖá¢IPµØµãºÍä¯ÀÀÆ÷Ö¸ÎÆÌØÕ÷£¬£¬£¬£¬£¬£¬Í¨¹ýVPN»òÎÞÍ·ä¯ÀÀÆ÷µÄÅþÁ¬»á±»¼ì²â²¢¾Ü¾ø¡£¡£¡£¡£¡£¡£²¿·Ö¹¥»÷Á´»áÌṩʹÓÃClickFixÕ½ÂÔÓÕÆÓû§ÔËÐжñÒâ´úÂëµÄÐéαÑéÖ¤ÂëÒ³Ãæ£¬£¬£¬£¬£¬£¬Ê¹»úеѬȾ¡°·åÖµÖ®¹â¡±¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬¸ÃÈí¼þ»á¼ÓÔØÐÅÏ¢ÇÔÈ¡³ÌÐòÈçLumma¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/06/over-269000-websites-infected-with.html
2. ³¬4.6ÍòGrafanaʵÀýδÐÞ²¹Îó²îCVE-2025-4123
6ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬Áè¼Ý46,000¸öÃæÏò»¥ÁªÍøµÄGrafanaʵÀýÒòδÐÞ²¹¿Í»§¶Ë¿ª·ÅÖØ¶¨ÏòÎó²î£¨CVE-2025-4123£©¶øÌ»Â¶ÓÚΣº¦Ö®ÖУ¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÖ¶ñÒâ²å¼þÖ´ÐÐÓëÕÊ»§½ÓÊÜ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÚGrafana Labs 5ÔÂ21ÈÕÐû²¼µÄÇå¾²¸üÐÂÖлñµÃ½â¾ö¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ý¹ØÁªÊý¾ÝÓëÆ½Ì¨ÔÚÉú̬ϵͳÖеÄÂþÑÜ£¬£¬£¬£¬£¬£¬ÆÀ¹À³ö¹²ÓÐ128,864¸öʵÀý̻¶ÔÚÍøÉÏ£¬£¬£¬£¬£¬£¬ÆäÖÐ46,506¸öÈÔÔÚÔËÐб£´æÎó²îµÄ°æ±¾£¬£¬£¬£¬£¬£¬Õ¼±ÈÔ¼36%¡£¡£¡£¡£¡£¡£OX SecurityÉîÈëÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÁ¬Ïµ¿Í»§¶Ë·¾¶±éÀúºÍ¿ª·ÅÖØ¶¨Ïò»úÖÆ£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õßµã»÷¶ñÒâURL£¬£¬£¬£¬£¬£¬´Ó¶ø´ÓÍþвÐÐΪÕß¿ØÖƵÄÍøÕ¾¼ÓÔØ¶ñÒâGrafana²å¼þ£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÁ´½Ó¿ÉÔÚÓû§ä¯ÀÀÆ÷ÖÐÖ´ÐÐí§ÒâJavaScript¡£¡£¡£¡£¡£¡£¸ÃÎó²îÎÞÐèÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬×ÝÈ»ÆôÓÃÄäÃû»á¼ûÒ²¿Éʩչ×÷Ó㬣¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÐ®ÖÆÓû§»á»°¡¢¸ü¸ÄÕÊ»§Æ¾Ö¤£¬£¬£¬£¬£¬£¬²¢ÔÚ×°ÖÃGrafana Image Renderer²å¼þµÄÇéÐÎÏÂÖ´ÐÐЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©À´¶ÁÈ¡ÄÚ²¿×ÊÔ´¡£¡£¡£¡£¡£¡£Ö»¹ÜGrafanaÖеÄĬÈÏÄÚÈÝÇå¾²Õ½ÂÔ£¨CSP£©ÌṩÁËÒ»¶¨±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨×èÖ¹´ËÀ๥»÷¡£¡£¡£¡£¡£¡£OX SecurityµÄÎó²îÅú×¢£¬£¬£¬£¬£¬£¬CVE-2025-4123¿ÉÔÚ¿Í»§¶Ë±»Ê¹Ó㬣¬£¬£¬£¬£¬²¢Í¨¹ýGrafanaÔÉúµÄJavaScript·ÓÉÂß¼ÈÆ¹ýÏÖ´úä¯ÀÀÆ÷¹æ·¶»¯»úÖÆ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-46-000-grafana-instances-exposed-to-account-takeover-bug/
3. ¼ÓÄôóµÚ¶þ´óº½¿Õ¹«Ë¾Î÷½Ýº½¿ÕÔâÓöÍøÂç¹¥»÷
6ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬Î÷½Ýº½¿Õ×÷Ϊ¼ÓÄôóµÚ¶þ´óº½¿Õ¹«Ë¾£¬£¬£¬£¬£¬£¬ÕýÔÚÊÓ²ìÒ»ÆðÓ°ÏìÆä²¿·ÖÄÚ²¿ÏµÍ³ºÍÒÆ¶¯Ó¦ÓóÌÐòµÄÍøÂçÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñµ¼Ö¶àÃûÓû§ÎÞ·¨»á¼ûÏà¹ØÏµÍ³£¬£¬£¬£¬£¬£¬µ«¹«Ë¾Ç¿µ÷ÔËÓªÇ徲δÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£Î÷½Ýº½¿ÕÔÚÊÂÎñ±¬·¢ºóѸËÙÆô¶¯ÁËרÃŵÄÄÚ²¿ÍŶӣ¬£¬£¬£¬£¬£¬²¢ÓëÖ´·¨²¿·ÖºÍ¼ÓÄôó½»Í¨²¿Ï¸ÃÜÏàÖú£¬£¬£¬£¬£¬£¬ÒÔÊÓ²ìÊÂÎñÔµ¹ÊÔÓɲ¢Ö»¹ÜïÔÌÆäÓ°Ïì¡£¡£¡£¡£¡£¡£¹«Ë¾ÕýÖÂÁ¦ÓÚ±£»£»£»£»£»£»£»¤ÂÿͺÍÔ±¹¤µÄÃô¸ÐÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢¶ÔЧÀÍÖÐÖ¹ÌåÏÖǸÒâ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¹ØÓڴ˴ι¥»÷µÄÏêϸϸ½ÚÉв»ÇåÎú£¬£¬£¬£¬£¬£¬µ«Î÷½Ýº½¿ÕÔÊÐíÔÚ»ñµÃ¸ü¶àÐÅÏ¢ºóʵʱ·ÖÏí¡£¡£¡£¡£¡£¡£¹«Ë¾½¨ÒéÂÿͺÍÔ±¹¤ÔÚ¹²ÏíСÎÒ˽¼ÒÐÅϢʱ¼á³ÖÉóÉ÷¡£¡£¡£¡£¡£¡£×èÖ¹2025Äê6ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Î÷½Ýº½¿Õº½°àÔËÓªÇ徲δÊÜÓ°Ï죬£¬£¬£¬£¬£¬¹«Ë¾ÕýÔÚÆÀ¹ÀÊÂÎñÓ°Ï첢ѸËÙ½â¾öÎÊÌâ¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/179027/uncategorized/canadas-airline-westjet-is-containing-a-cyberattack.html
4. SimpleHelpÎó²îÔâʹÓ㬣¬£¬£¬£¬£¬¹¥»÷¹«ÓÃÊÂÒµ¼Æ·ÑÈí¼þ¿Í»§
6ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²»ú¹¹CISA·¢³öÖÒÑÔ£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÔËÓªÉÌÕýʹÓÃSimpleHelpÎó²î¶Ô¹«ÓÃÊÂÒµ¼Æ·ÑÈí¼þÌṩÉ̵Ŀͻ§Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£±»Ê¹ÓõÄÎó²î±àºÅΪCVE-2024-57727£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷Õß¼ìË÷Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿¡£¡£¡£¡£¡£¡£´ËÎó²îÓëÁíÍâÁ½¸öÔÊÐí¹¥»÷ÕßÉÏ´«í§ÒâÎļþ²¢ÌáÉýȨÏÞΪÖÎÀíÔ±µÄÎó²îCVE-2024-57728ºÍCVE-2024-57726ÓÚ1Ô·Ýһͬ»ñµÃÐÞ²¹¡£¡£¡£¡£¡£¡£CISAÔÚ·¢Ã÷ÍþвÐÐΪÕßʹÓÃCVE-2024-57727¹¥»÷ÔËÐÐSimpleHelpÔ¶³Ì¼à¿ØºÍÖÎÀíÈí¼þµÄ×°±¸ºó£¬£¬£¬£¬£¬£¬ÓÚ2Ô·ݽ«¸ÃÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îÁбíÖС£¡£¡£¡£¡£¡£5ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬SophosÖÒÑÔ³ÆDragonForceÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜʹÓÃSimpleHelpʵÀýÎó²îΣ¼°ÍйÜЧÀÍÌṩÉ̼°Æä¿Í»§µÄÇå¾²¡£¡£¡£¡£¡£¡£CISA½¨ÒéÈí¼þ¹©Ó¦ÉÌ¡¢ÏÂÓοͻ§ºÍ×îÖÕÓû§Á¬Ã¦½ÓÄɲ½·¥ÐÞ²¹ÆäSimpleHelp°²ÅŲ¢Ñ°ÕÒÍ×ÐÖ¸±ê¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/simplehelp-vulnerability-exploited-against-utility-billing-software-users/
5. º«¹úƱÎñƽ̨Yes24ÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬ÓéÀÖ¹¤ÒµÏÝÈëÔÓÂÒ
6ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬º«¹úÖ÷ҪƱÎñƽ̨¼°ÔÚÏßͼÊéÁãÊÛÉÌYes24ÓÚ6ÔÂ9ÈÕÆÆÏþÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼Ö¸ùúÓéÀÖ¹¤ÒµÏÝÈëÔÓÂÒ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖÂʹYes24ÍøÕ¾¼°Ð§ÀÍÒ»Á¬ËÄÌì̱»¾£¬£¬£¬£¬£¬£¬ÔÚÏßÑݳª»áÔ¤¶©¡¢µç×ÓÊé»á¼ûºÍÉçÇøÂÛ̳¹¦Ð§¾ùÎÞ·¨Õý³£Ê¹Ó㬣¬£¬£¬£¬£¬¹«Ë¾ËäÉùÃ÷Ä¿µÄÔÚ6ÔÂ15ÈÕǰÖÜÈ«»Ö¸´ÔËÓª£¬£¬£¬£¬£¬£¬µ«Ó°ÏìÒÑÊ®·ÖÏÔÖø¡£¡£¡£¡£¡£¡£º«¹úÒþ˽î¿Ïµ»ú¹¹¡°Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»£»£»£»¤Î¯Ô±»á¡±ÒÑÆô¶¯ÊӲ죬£¬£¬£¬£¬£¬ÏÓÒÉ´Ë´ÎÊÂÎñ¿ÉÄܵ¼Ö¿ͻ§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬Õþ¸®½«Éó²éYes24ÊÇ·ñÍÆÐÐÁ˺«¹úÊý¾ÝÒþ˽¹æÔò¶¨µÄÖ´·¨ÒåÎñ¡£¡£¡£¡£¡£¡£ÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬£¬£¬´Ë´ÎЧÀÍÖÐÖ¹Òý·¢ÁËÁ¬Ëø·´Ó¦£¬£¬£¬£¬£¬£¬°üÀ¨ÆÓ±¦½£¡¢ENHYPEN¡¢ATEEZ¼°Ëµ³ª¸èÊÖB.IÔÚÄڵĶàλº«Á÷Ã÷ÐÇÔ¤ÊÛ¼°·ÛË¿»î¶¯±»ÆÈÍÆ³Ù»ò×÷·Ï£¬£¬£¬£¬£¬£¬²¿·ÖÒôÀÖ¾çÖÆ×÷·½Ò²ÒªÇó¹ÛÖÚ³öʾֽÖÊÃÅÆ±»òÓʼþÈ·ÈϺ¯È볡£¬£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¹ÛÖÚÒòÎÞ·¨Ìṩ¿ÉÑé֤ƱÎñÐÅÏ¢¶øÔâ¾ÜÈ볡¡£¡£¡£¡£¡£¡£Yes24ÖÜÈýÉùÃ÷ÒÑÖØÐÂÕÆ¿ØÖÎÀíÔ±ÕË»§£¬£¬£¬£¬£¬£¬ÕýÆð¾¢»Ö¸´ÆäËûЧÀÍ£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÉí·ÝÏÖÔÚÉÐδÃ÷È·¡£¡£¡£¡£¡£¡£¹«Ë¾ÌåÏÖÉÐδȷÈÏСÎÒ˽¼ÒÐÅÏ¢Íâй£¬£¬£¬£¬£¬£¬µ«ÒÑÏòº«¹úÊý¾ÝÒþ˽»ú¹¹±¨¸æÉæ¼°¿Í»§Êý¾ÝδÊÚȨ»á¼ûµÄ¿ÉÒɻ£¬£¬£¬£¬£¬£¬²¢ÔÊÐíÈôºóÐøÊÓ²ì֤ʵСÎÒ˽¼ÒÐÅϢй¶£¬£¬£¬£¬£¬£¬½«Á¬Ã¦Í¨ÖªÓû§¡£¡£¡£¡£¡£¡£
https://therecord.media/yes24-south-korea-ransomware-attack
6. ºÚ¿Í³ÆÕ®Îñ´ßÊÕ¹«Ë¾CCCÔâÈëÇÖ£¬£¬£¬£¬£¬£¬900¶àÍòÃÀ¹úÈËÐÅϢй¶
6ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÉù³ÆÒÑÈëÇÖ¸¥¼ªÄáÑÇÖÝÕ®Îñ´ßÊÕ¹«Ë¾ÐÅÓÿØÖƹ«Ë¾£¨CCC£©£¬£¬£¬£¬£¬£¬²¢µ¼ÖÂÊý°ÙÍòÃÀ¹úÈËСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£ÕâЩºÚ¿ÍÔÚÒ»¸öÊý¾Ýй¶ÂÛ̳ÉÏÐû²¼ÁËÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË910ÍòÃÀ¹úÈ˵ÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£CCCÊÇÒ»¼ÒרעÓÚÒ½ÁƱ£½¡ºÍµçÐÅÐÐÒµµÄÕ®Îñ´ßÊÕ¹«Ë¾£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£¡£Ñо¿ÍŶÓÊÓ²ìÁ˹¥»÷Õ߸½¼ÓÔÚÌû×ÓÖеÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬·¢Ã÷й¶µÄÐÅÏ¢¿ÉÄܰüÀ¨È«Ãû¡¢µç»°ºÅÂë¡¢ÐÔ±ð¡¢ÄêËê¡¢·¿²úÐÅÏ¢¡¢µäÖÊ´û¿îÊý¾ÝºÍ´û¿îÀàÐ͵ȡ£¡£¡£¡£¡£¡£¹¥»÷Õßͨ³£¶ÔÓµÓдó×ÚÏêϸÐÅÏ¢µÄÊý¾Ý¿â¸ÐÐËȤ£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÊý¾Ý¿ÉÓÃÓÚ×Ô¶¯»¯´¹ÂÚÓʼþÕ©Æ¡¢½ðÈÚթƺÍÉí·Ý͵ÇÔ¡£¡£¡£¡£¡£¡£Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢ºÍ²ÆÎñÐÅÏ¢µÄй¶Ϊ¶¨Öƹ¥»÷ÌṩÁ˸»×ãʱ»ú£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÐÅÏ¢Õë¶Ô±£´æ²ÆÎñÎÊÌâµÄÓû§¾ÙÐÐÚ²ÆÐÔ²ÆÎñÔ®Öú»òÆäËûЧÀ͵ÄÕ©Æ¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬Õâ²¢·ÇCCCÊ×´ÎÔâÓöÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£2023Ä꣬£¬£¬£¬£¬£¬¸Ã¹«Ë¾¾ÍÔøÅû¶һÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬µ¼ÖÂÁè¼Ý30ÍòÃÀ¹úסÃñµÄÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Æäʱй¶µÄÐÅÏ¢°üÀ¨ÐÕÃûºÍÉç»áÇå¾²ºÅÂëµÈ¡£¡£¡£¡£¡£¡£
https://cybernews.com/news/credit-control-corporation-data-breach/