½¡Éí¾ÞÍ·Basic-FitÔâÈëÇÖ£¬£¬£¬£¬£¬£¬°ÙÍò¿Í»§Êý¾Ýй¶

Ðû²¼Ê±¼ä 2026-04-14

1. ½¡Éí¾ÞÍ·Basic-FitÔâÈëÇÖ£¬£¬£¬£¬£¬£¬°ÙÍò¿Í»§Êý¾Ýй¶


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ºÉÀ¼½¡ÉíÁ¬Ëø¾ÞÍ·Basic-Fit¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬ÆäϵͳÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼100Íò¿Í»§µÄÐÅÏ¢±»ÇÔÈ¡¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ·¢Ã÷Òì³£ºóѸËÙÐû²¼ÉùÃ÷£¬£¬£¬£¬£¬£¬³ÆÆäϵͳ¼à¿Ø³ÌÐò¼ì²âµ½ÁËδ¾­ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬²¢ÔÚ¼¸·ÖÖÓÄÚÓèÒÔ×èÖ¹¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ËæºóµÄÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈÔÀֳɻñÈ¡Á˲¿·Ö»áÔ±µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÏÖʵµØµã¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐÐÕË»§ÏêÇéÒÔ¼°ÆäËû»áÔ±Ïà¹ØÊý¾Ý¡£¡£¡£¡£ÖµµÃÇìÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬ÌØÐíı»®µêµÄ¿Í»§Êý¾ÝÒò´æ´¢ÔÚ×ÔÁ¦µÄϵͳÖУ¬£¬£¬£¬£¬£¬Î´ÊÜ´Ë´ÎÊÂÎñÓ°Ïì¡£¡£¡£¡£Æ¾Ö¤¹Ù·½Åû¶£¬£¬£¬£¬£¬£¬ºÉÀ¼¾³ÄÚÊÜÓ°ÏìµÄÈËÊýԼΪ20Íò£¬£¬£¬£¬£¬£¬¶øÕûÌåÊÜÓ°Ïì¿Í»§×ÜÊý¿¿½ü100Íò£¬£¬£¬£¬£¬£¬±é²¼ºÉÀ¼¡¢±ÈÀûʱ¡¢Â¬É­±¤¡¢·¨¹ú¡¢Î÷°àÑÀºÍµÂ¹úµÈ¶à¸öÅ·ÖÞ¹ú¼Ò¡£¡£¡£¡£Basic-FitÏÖÔÚÔÚÅ·ÖÞÓµÓÐÔ¼500Íò»áÔ±£¬£¬£¬£¬£¬£¬´Ë´Îй¶ÊÂÎñ²¨¼°ÃæÏ൱ÆÕ±é¡£¡£¡£¡£²»¹ý£¬£¬£¬£¬£¬£¬¹«Ë¾Ç¿µ÷£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñ²¢Î´µ¼ÖÂÈκÎÉí·Ý֤ʵÎļþ»òÕË»§ÃÜÂë±»»á¼û£¬£¬£¬£¬£¬£¬Ò»¶¨Ë®Æ½ÉϽµµÍÁËÉí·Ý±»µÁÓõÄΣº¦¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/european-gym-giant-basic-fit-data-breach-affects-1-million-members/


2. µÚÈý·½Îó²îÖÂRockstar Games 7860ÍòÌõÊý¾Ýй¶


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬×ÅÃûÓÎÏ·¿ª·¢ÉÌRockstar Games½üÆÚÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬ÆäÔ¼7860ÍòÌõ¼Í¼±»ShinyHuntersÀÕË÷ÍÅ»ïÔÚ°µÍø¹ûÕæ¡£¡£¡£¡£´Ë´ÎÊÂÎñµÄÔ´Í·²¢·ÇRockstar×ÔÉíϵͳµÄÖ±½ÓÈëÇÖ£¬£¬£¬£¬£¬£¬¶øÊÇÔ´ÓÚÆäµÚÈý·½Ð§ÀÍÉÌAnodotµÄÇå¾²Îó²î¡£¡£¡£¡£AnodotÊÇÒ»¼ÒÊý¾ÝÒì³£¼ì²â¹«Ë¾£¬£¬£¬£¬£¬£¬¿ÉÓë¶àÖÖSaaSÔÆÆ½Ì¨¼¯³É¡£¡£¡£¡£ÔÚ´ËǰÕë¶ÔAnodotµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÇÔÈ¡ÁËÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÕâЩÁîÅÆ»á¼ûÁË´æ´¢ÔÚ¹ØÁªSnowflakeʵÀýÖеĿͻ§Êý¾Ý¡£¡£¡£¡£ShinyHunters×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÒÑʹÓñ»µÁÓõÄÁîÅÆ´ÓÊýÊ®¼Ò¹«Ë¾ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£Õë¶ÔRockstar Games£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐû²¼µÄ¾Ý³ÆÊÇÆäSnowflakeÇéÐÎÖеÄÖ¸±êÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Áè¼Ý7860ÍòÌõ¼Í¼¡£¡£¡£¡£¾ÝÍþвÐÐΪÕß͸¶£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÖ÷ÒªÊÇÓÃÓÚ¼à¿ØRockstarÔÚÏßЧÀͺÍÖ§³Ö¹¤µ¥µÄÄÚ²¿·ÖÎöÊý¾Ý£¬£¬£¬£¬£¬£¬Ïêϸ°üÀ¨¡¶ÏÀµÁÁÔ³µÊÖOnline¡·ºÍ¡¶»ÄÔ­´óïÚ¿ÍOnline¡·µÄÓÎÏ·ÄÚÊÕÈëÓ빺ÖÃÖ¸±ê¡¢Íæ¼ÒÐÐΪ׷×Ù¡¢ÓÎÏ·¾­¼ÃÊý¾Ý£¬£¬£¬£¬£¬£¬ÒÔ¼°¸Ã¹«Ë¾Zendesk¿Í·þϵͳµÄ¿Í»§Ö§³ÖÆÊÎöÊý¾Ý¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ò»·ÝÎļþÁбíÖл¹Ìáµ½ÁËڲƭ¼ì²âϵͳºÍ·´×÷±×Ä£×Ó²âÊÔµÄÏà¹ØÐÅÏ¢¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/


3. Booking.comÖÒÑÔ¿Í»§£ºÔ¤¶©ÐÅÏ¢¿ÉÄÜÔâºÚ¿Í»á¼û


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬×ÅÃûÔÚÏßÂÃÐÐÔ¤¶©Æ½Ì¨Booking.com¿ËÈÕÏò¿Í»§·¢³öÖÒÑÔ£¬£¬£¬£¬£¬£¬³ÆÎ´¾­ÊÚȨµÄµÚÈý·½¿ÉÄÜÒÑ»ñÈ¡²¿·ÖÓû§µÄÂÃÐÐÔ¤¶©Ïà¹ØÐÅÏ¢¡£¡£¡£¡£Booking.comÊÇÈ«ÇòÁìÏȵÄÔÚÏßÂÃÐÐÉçºÍÊý×ÖÂÃÓι«Ë¾Ö®Ò»£¬£¬£¬£¬£¬£¬×¨ÃÅ´ÓÊÂÂùݡ¢¶È¼Ù×âÁ޺͹«Ô¢µÈסËÞÔ¤¶©Ð§ÀÍ¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾·¢Ë͸øÊÜÓ°ÏìÓû§µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬±»»á¼ûµÄÐÅÏ¢¿ÉÄܰüÀ¨Ô¤¶©ÏêÇé¡¢¿Í»§ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÁªÏµµç»°£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëסËÞ·½¹²ÏíµÄÈÎºÎÆäËûÐÅÏ¢¡£¡£¡£¡£Booking.comÔÚ֪ͨÖÐÌåÏÖ£º¡°ÎÒÃǽüÆÚ×¢ÖØµ½Ò»Ð©Ô¤¶©±£´æ¿ÉÒɻ£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦½ÓÄɲ½·¥¿ØÖÆÊÂ̬¡£¡£¡£¡£¡±×÷ΪӦ¶Ô²½·¥£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÖØÖÃÁËÊÜÓ°ÏìÔ¤¶©µÄÃÜÂë¡£¡£¡£¡£Booking.comδ͸¶´Ë´ÎÊÂÎñµÄÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬£¬Ò²Î´ËµÃ÷¹¥»÷ÕßÊÇ·ñÖ±½ÓÈëÇÖÁËÆäÄÚ²¿ÏµÍ³¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬¹«Ë¾Ã»ÓйûÕæÊÜÓ°ÏìÓû§µÄÏêϸÊýÄ¿£¬£¬£¬£¬£¬£¬µ«ÌåÏÖÒÑÀֳɿØÖÆÊÂ̬²¢Í¨ÖªÁËËùÓÐÊÜÓ°ÏìµÄ¿Í»§¡£¡£¡£¡£ÖµµÃÇìÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬Booking.comÇ¿µ÷ûÓÐÖ§¸¶Êý¾ÝÔÚ´Ë´ÎÊÂÎñÖб»Ð¹Â¶¡£¡£¡£¡£¸Ã¹«Ë¾Í¬Ê±ÌáÐѿͻ§Ð¡ÐÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬Ã÷È·Ö¸³öBooking.com¾ø²»»áͨ¹ýµç×ÓÓʼþ¡¢µç»°¡¢WhatsApp»ò¶ÌÐŵȷ½·¨Ë÷ÒªÒøÐп¨ÐÅÏ¢»òÒªÇó¾ÙÐÐÈκÎÒ쳣תÕË¡£¡£¡£¡£


https://securityaffairs.com/190757/data-breach/hackers-access-booking-com-user-data-company-secures-systems.html


4. ÃÀÓ¡ÄáÁªºÏÐж¯£¬£¬£¬£¬£¬£¬µ·»Ù¡°W3LL¡±È«Çò´¹ÂÚÆ½Ì¨


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾ÖÑÇÌØÀ¼´ó·Ö¾ÖÓëÓ¡ÄáÕþ¸®¿ËÈÕÁªºÏµ·»ÙÁËÃûΪ¡°W3LL¡±µÄÈ«Çò´¹ÂÚÆ½Ì¨£¬£¬£¬£¬£¬£¬²é·âÁËÏà¹Ø»ù´¡ÉèÊ©²¢¾Ð²¶ÁËÉæÏÓ¿ª·¢Õß¡£¡£¡£¡£ÕâÊÇÃÀ¹úºÍÓ¡ÄáÊ×´ÎÕë¶Ô´¹ÂÚ¹¤¾ß°ü¿ª·¢Õß¿ªÕ¹µÄЭµ÷Ö´·¨Ðж¯¡£¡£¡£¡£W3LLÊÐËÁÊÇÒ»¸öÌṩ´¹ÂÚ¹¤¾ß°üµÄÔÚÏßÊг¡£¡£¡£¡£¬£¬£¬£¬£¬£¬Ê¹ÍøÂç·¸·¨·Ö×ÓÄܹ»ÇÔÈ¡Êýǧ¸öƾ֤²¢ÊÔͼʵÑéÁè¼Ý2000ÍòÃÀÔªµÄÕ©Æ­»î¶¯¡£¡£¡£¡£±»²é·âµÄÓòÃûw3ll.storeÒ³ÃæÉÏÏÔʾ£¬£¬£¬£¬£¬£¬¸ÃÓòÃûÒÑÆ¾Ö¤ÃÀ¹ú×ôÖÎÑÇÖݱ±ÇøµØÒªÁìÔºµÄ¿ÛѺÁî±»Áª°îÊÓ²ì¾Ö¿ÛѺ¡£¡£¡£¡£W3LL´¹ÂÚ¹¤¾ß°üÊÛ¼Û500ÃÀÔª£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËü½¨Éè±ÆÕæµÄÆóÒµµÇ¼ÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Óû§Æ¾Ö¤¡£¡£¡£¡£¸Ã¹¤¾ß°ü»¹ÔÊÐí¹¥»÷Õß²¶»ñÉí·ÝÑéÖ¤»á»°ÁîÅÆ£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý¶àÒòËØÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬»ñµÃ¶Ô±»µÁÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ãƽ̨»¹ÌṩÁËÒ»¸öÃûΪW3LLSTOREµÄÊг¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÓÃÓÚÉúÒâ±»µÁƾ֤ºÍδ¾­ÊÚȨµÄÍøÂç»á¼ûȨÏÞ¡£¡£¡£¡£¾ÝÕþ¸®³Æ£¬£¬£¬£¬£¬£¬¸ÃÊг¡ÔÚ2019ÄêÖÁ2023Äê¼ä´Ù³ÉÁËÁè¼Ý2.5Íò¸ö±»µÁÕË»§µÄÏúÊÛ¡£¡£¡£¡£2023ÄêÖÁ2024Äê¼ä£¬£¬£¬£¬£¬£¬¸Ã´¹ÂÚ¹¤¾ß°ü±»ÓÃÓÚ¹¥»÷È«ÇòÁè¼Ý1.7ÍòÃûÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ÊÓ²ìÖ°Ô±·¢Ã÷¿ª·¢ÕßÍøÂ粢תÊÛÁ˱»µÁÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-takedown-of-w3ll-phishing-service-leads-to-developer-arrest/


5. Adobe½ôÆÈÐÞ¸´ÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬¶ñÒâPDF¿ÉÇÔÈ¡Îļþ


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Adobe¿ËÈÕÐû²¼ÁËAcrobat ReaderµÄ½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Ò»¸ö±àºÅΪCVE-2026-34621µÄÎó²î¡£¡£¡£¡£¸ÃÎó²îÖÁÉÙ´ÓÈ¥Äê12ÔÂÆðÒѱ»ÓÃÓÚÁãÈÕ¹¥»÷£¬£¬£¬£¬£¬£¬ÔÊÐí¶ñÒâPDFÎļþÈÆ¹ýɳÏäÏÞÖÆ²¢Å²ÓÃÌØÈ¨JavaScript API£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¹¥»÷Öз¢Ã÷µÄʹÓ÷½·¨Äܹ»¶ÁÈ¡ºÍÇÔÈ¡í§ÒâÎļþ£¬£¬£¬£¬£¬£¬ÇÒ³ýÁË·­¿ª¶ñÒâPDFÎļþÖ®Í⣬£¬£¬£¬£¬£¬ÎÞÐèÈκÎÓû§½»»¥¡£¡£¡£¡£Ïêϸ¶øÑÔ£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÓÃÁËutil.readFileIntoStream()µÈAPI¶ÁÈ¡í§ÒâÍâµØÎļþ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃRSS.addFeed()ÇÔÈ¡Êý¾Ý¼°»ñÈ¡¹¥»÷Õß¿ØÖÆµÄÆäËû´úÂë¡£¡£¡£¡£AdobeÔÚÖÜÄ©Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬½«Îó²î±àºÅ¶¨ÎªCVE-2026-34621¡£¡£¡£¡£¸ÃÎó²î×î³õ±»ÆÀΪÑÏÖØ¼¶±ð£¨9.6£©£¬£¬£¬£¬£¬£¬¹¥»÷;¾¶ÎªÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ«AdobeËæºó½«¹¥»÷;¾¶¸ÄΪÍâµØ¹¥»÷£¬£¬£¬£¬£¬£¬ÑÏÖØË®Æ½½µÖÁ8.6¡£¡£¡£¡£Í¨¸æÖÐδÁгöÈκνâ¾öÒªÁì»ò»º½â²½·¥£¬£¬£¬£¬£¬£¬Òò´ËÓ¦ÓÃÇå¾²¸üÐÂÊÇÎ¨Ò»ÍÆ¼öµÄ·À»¤ÊֶΡ£¡£¡£¡£Óû§Ó¦Ê¼ÖÕ¶ÔÀ´×Ôδ¾­ÇëÇóȪԴµÄPDFÎļþ¼á³ÖСÐÄ£¬£¬£¬£¬£¬£¬²¢ÔÚÏÓÒÉʱÔÚɳºÐÇéÐÎÖз­¿ª¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/adobe-rolls-out-emergency-fix-for-acrobat-reader-zero-day-flaw/


6. ³¯ÏÊAPT37ʹÓÃFacebookÉç½»¹¤³ÌÈö²¥RokRATľÂí


4ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖÃûScarCruft£©½üÆÚ±»Ö¸¿ØÌᳫÁËÒ»³¡ÐµĶà½×¶ÎÉç»á¹¤³Ì¹¥»÷»î¶¯¡£¡£¡£¡£¹¥»÷Õßͨ¹ýFacebook¿¿½üÄ¿µÄÓû§²¢Ìí¼ÓΪֿÓÑ£¬£¬£¬£¬£¬£¬½«½¨ÉèÐÅÈεÄÀú³Ìת»¯ÎªÈö²¥ÃûΪRokRATµÄÔ¶³Ì»á¼ûľÂíµÄÇþµÀ¡£¡£¡£¡£¾ÝGeniansÇå¾²ÖÐÐĵÄÊÖÒÕÆÊÎö£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÁ½¸öλÖû®·ÖÉèÖÃΪ³¯ÏÊÆ½ÈÀÇå¾²³ÇµÄFacebookÕË»§À´Ê¶±ðºÍɸѡĿµÄ¡£¡£¡£¡£ÔÚͨ¹ýÖ¿ÓÑÇëÇó½¨ÉèÐÅÈκ󣬣¬£¬£¬£¬£¬¹¥»÷Õß½«¶Ô»°×ªÒƵ½Messenger£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÌØ¶¨»°ÌâÒýÓÕÄ¿µÄ£¬£¬£¬£¬£¬£¬ÕâÊǹ¥»÷³õÆÚÉç½»¹¤³Ì½×¶ÎµÄÒ»²¿·Ö¡£¡£¡£¡£´Ë´Î¹¥»÷µÄ½¹µãÔÚÓÚʹÓÃÁË¡°Ô¤ÉèÇé¾³¡±Õ½ÂÔ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÓÕÆ­Óû§×°ÖÃרÓõÄPDFÉó²éÆ÷£¬£¬£¬£¬£¬£¬²¢Éù³Æ¸ÃÈí¼þÊÇ·­¿ª¼ÓÃܾüÊÂÎļþµÄÐëÒª¹¤¾ß¡£¡£¡£¡£Ñ¬È¾Á´ÖÐʹÓõÄPDFÉó²éÆ÷ÊǸ͝¹ýµÄWondershare PDFelement°æ±¾£¬£¬£¬£¬£¬£¬¸ÃÈí¼þÆô¶¯ºó»á´¥·¢Ç¶ÈëʽshellcodeÖ´ÐУ¬£¬£¬£¬£¬£¬Ê¹¹¥»÷Õß»ñµÃ³õʼפ×ãµã¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯»¹Ê¹ÓÃÕýµ±µ«Òѱ»ÈëÇֵĻù´¡ÉèÊ©¾ÙÐÐÖ¸»Ó¿ØÖÆ£¬£¬£¬£¬£¬£¬½«ÓëÒ»¼ÒÈÕ±¾·¿µØ²úÐÅϢЧÀ͹«Ë¾Ê×¶û·Ö²¿¹ØÁªµÄÍøÕ¾ÎäÆ÷»¯£¬£¬£¬£¬£¬£¬ÓÃÓÚÐû²¼¶ñÒâÖ¸ÁîºÍÓÐÓÃÔØºÉ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓÐÓÃÔØºÉαװ³É¿´ËÆÎÞº¦µÄJPGͼƬÀ´Èö²¥RokRAT¶ñÒâÈí¼þ¡£¡£¡£¡£


https://thehackernews.com/2026/04/north-koreas-apt37-uses-facebook-social.html