E-ZPass´¹ÂÚ¶ÌÐŹ¥»÷±¬·¢ £¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþµÀÇÔÈ¡

Ðû²¼Ê±¼ä 2025-04-07

1. E-ZPass´¹ÂÚ¶ÌÐŹ¥»÷±¬·¢ £¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþµÀÇÔÈ¡


4ÔÂ6ÈÕ £¬½üÆÚ £¬Õë¶Ô½»Í¨ÊÕ·Ñ·þÎñÓû§µÄÍøÂç´¹ÂÚ¹¥»÷·ºÆð±¬·¢Ê½ÔöÌí £¬²»·¨·Ö×Óð³äE-ZPass¡¢FasTrakµÈÊÕ·Ñ»ú¹¹ £¬Í¨¹ýiMessage¼°SMSÇþµÀ´ó¹æÄ£·¢ËÍڲƭ¶ÌÐÅ¡£¹¥»÷ÕßʹÓÃ×Ô¶¯»¯¹¤¾ßÈÆ¹ý·´À¬»øÓʼþϵͳ £¬ÍŽáËæ»ú»¯·¢¼þµØÖ·ÊµÑé¸ßƵ´Î¹¥»÷ £¬µ¥ÈÕ·¢ËÍÁ¿¿É´ï7Ìõ £¬ÏÔÖøÔöÇ¿ÁËÕ©Æ­µÄÉøÍ¸ÄÜÁ¦¡£´ËÀà¶ÌÐÅͨ³£½ÓÄɽôÆÈÐÔ»°Êõ £¬Èç"48СʱÄÚδ½ÉͨÐзѽ«ÔÝÍ£¼ÝÊ»×ʸñ"µÈÍþвÐÔÄÚÈÝ £¬ÓÕµ¼Óû§µã»÷ǶÈëµÄ¶ñÒâÁ´½Ó¡£Îª¹æ±ÜApple iMessageµÄÇå¾²»úÖÆ £¬Õ©Æ­·Ö×ÓÒªÇóÓû§ÏȻظ´¶ÌÐÅÒÔ¼¤»î¿Éµã»÷Á´½Ó £¬½ø¶øÌø×ªÖÁÈ«ÐÄ·ÂÖÆµÄ´¹ÂÚÍøÕ¾¡£¾­ÊÖÒÕÑéÖ¤ £¬ÕâЩ´¹ÂÚÒ³Ãæ½ÓÄÉÏìӦʽÉè¼Æ £¬½öÄÜÔÚÒÆ¶¯¶ËÍêÕûÏÔʾ £¬Í¨¹ýÊÓ¾õαװÇÔÈ¡Óû§ÐÕÃû¡¢ÐÅÓÿ¨ºÅµÈÃô¸ÐÐÅÏ¢¡£ÖµµÃ×¢ÖØµÄÊÇ £¬ÐÂÐËÍøÂç·¸·¨¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÈçLucidºÍDarcula±»Ö¸¼ÓÈë´ËÀ๥»÷ £¬ÆäʹÓüÓÃܵÄRCSºÍiMessageЭÒéÍ»ÆÆ¹Å°å¹ýÂËϵͳ £¬ÏÔÖø½µµÍ×÷°¸±¾Ç®¡£Áª°îÊÓ²ì¾Ö£¨FBI£©ÔçÔÚ2024Äê4ÔÂÒÑÐû²¼Ïà¹ØÔ¤¾¯ £¬µ«¹¥»÷ÕßÒ»Á¬µü´úÊÖ·¨ £¬µ¼ÖÂÓû§ÊÜÆ­Î£º¦Ò»Á¬ÅÊÉý¡£


https://www.bleepingcomputer.com/news/security/toll-payment-text-scam-returns-in-massive-phishing-wave/


2. disgrasya¶ñÒâ°üÀÄÓÃPyPI·Ö·¢ÇþµÀÍþвWooCommerceÐÅÓÿ¨Çå¾²


4ÔÂ6ÈÕ £¬¿ËÈÕ £¬Çå¾²Ñо¿Ö°Ô±½ÒÆÆÁËÒ»¸öÃûΪ"disgrasya"µÄ¶ñÒâPython°ü £¬¸Ã°üͨ¹ýPyPIƽ̨±»ÏÂÔØÁè¼Ý3.4Íò´Î £¬ÆäרÃÅÓÃÓÚÑéÖ¤±»µÁÐÅÓÿ¨µÄ²»·¨Ô˶¯¡£¸Ã¶ñÒâÈí¼þÕë¶ÔʹÓÃCyberSourceÖ§¸¶Íø¹ØµÄWooCommerceµçÉÌÆ½Ì¨ £¬Í¨¹ýÄ£ÄâÍêÕû¹ºÎïÁ÷³ÌʵÑéÐÅÓÿ¨Ú²Æ­ÑéÖ¤¡£ÊÖÒÕÆÊÎöÏÔʾ £¬¹¥»÷ÕßʹÓøðüÖ´Ðи߶È×Ô¶¯»¯µÄ¹¥»÷Á´£ºÊ×ÏÈץȡĿµÄÊÐËÁÉÌÆ·ID²¢ÌìÉúÐéÄ⹺Îï³µ £¬ËæºóÇÔÈ¡½áÕËÒ³ÃæµÄCSRFÁîÅÆºÍÖ§¸¶Íø¹ØÉÏÏÂÎIJÎÊý¡£Òªº¦°ì·¨ÖÐ £¬±»µÁÐÅÓÿ¨Êý¾Ý²¢·ÇÖ±½ÓÌá½»¸øÖ§¸¶Íø¹Ø £¬¶øÊÇ·¢ËÍÖÁ¹¥»÷Õß¿ØÖƵĶñÒâ·þÎñÆ÷£¨railgunmisaka.com£© £¬¸Ã·þÎñÆ÷αװ³ÉÕýµ±Ö§¸¶½Ó¿Ú·µ»ØÐéαÊÚȨЧ¹û £¬×îÖÕͨ¹ýÌá½»´ø±ê¼ÇµÄ¶©µ¥Íê³ÉÑéÖ¤¡£ÕâÖÖ¹¥»÷ÊÖ·¨¾ßÓм«Ç¿µÄÒþ²ØÐÔ¡£Ò»·½Ãæ £¬Õû¸öÁ÷³ÌÄ£ÄâÕæÊÊÓû§ÐÐΪ £¬ÍêÉÆÈÚÈëÕý³£ÉúÒâÁ÷Á¿£»ÁíÒ»·½Ãæ £¬¹¥»÷Õß½ÓÄÉ"ÖÐÐÄÈËÑéÖ¤"ģʽ £¬¼È¹æ±ÜÁËÖ±½Ó´¥ÅöÖ§¸¶ÏµÍ³µÄ¼ì²âΣº¦ £¬ÓÖÄÜÅúÁ¿´¦Öóͷ£°µÍø»ñÈ¡µÄÐÅÓÿ¨Êý¾Ý¡£SocketÇå¾²ÍŶÓÖ¸³ö £¬¸Ã¶ñÒâ°üÉõÖÁÔÚÆä¹Ù·½ÐÎòÖйûÕæÈÏ¿ÉÓÃÓÚ²»·¨ÓÃ; £¬Í¹ÏԺڿͶԿªÔ´Æ½Ì¨ÀÄÓÃˮƽ֮Éî¡£


https://www.bleepingcomputer.com/news/security/carding-tool-abusing-woocommerce-api-downloaded-34k-times-on-pypi/


3. Verizon iOSÓ¦ÓÃÎó²î̻¶ͨ»°¼Í¼ԪÊý¾Ý £¬ÒÑÐÞ¸´Î´ÏÖÀÄÓÃ


4ÔÂ5ÈÕ £¬Verizon Wireless½üÆÚÐÞ¸´µÄiOS°æCall FilterÓ¦ÓÃÎó²î £¬Ì»Â¶³öDZÔڵĴó¹æÄ£Í¨»°¼Í¼й¶Σº¦¡£Çå¾²Ñо¿Ô±Evan ConnellyÓÚ2025Äê2Ô·¢Ã÷ £¬¸ÃÓ¦ÓõÄ/clr/callLogRetrieval½Ó¿Ú±£´æÉí·ÝÑé֤ȱÏÝ£ºÖ»¹Ü½ÓÄÉJWTÁîÅÆÈÏÖ¤ £¬µ«·þÎñÆ÷δУÑéÇëÇóÖеĵ绰ºÅÂëÓëÓû§IDµÄÆ¥ÅäÐÔ¡£ÕâʹµÃ¹¥»÷Õß¿Éͨ¹ýαÔìÇëÇó £¬í§Òâ¼ìË÷Ä¿µÄÓû§µÄͨ»°¼Í¼ £¬ÊÜÓ°Ïì¹æÄ£º­¸ÇĬÈÏÆôÓø÷þÎñµÄ´ó¶¼iOSÓû§¡£¸ÃÎó²îµÄDZÔÚΣº¦Ô¶³¬Í¨Ë×Êý¾Ýй¶¡£×¨¼ÒÖÒÑÔ £¬Í¨»°¼Í¼µÄʱ¼ä´ÁÐÅÏ¢¿É±»ÓÃÓÚʵʱ¼à¿ØÌض¨¹¤¾ß £¬Èç¼ÇÕß¡¢Ö´·¨Ö°Ô±»ò¼Ò±©Êܺ¦Õß £¬ÆäÒ»Ñùƽ³£ÁªÏµÄ£Ê½¼°Ðж¯¹ì¼£½«Íêȫ̻¶¡£Í¨Ì«¹ýÎöÖØ¸´Í¨»°ºÅÂë £¬ÉõÖÁ¿ÉÄÜʶ±ðÔÝʱͨѶÏß·»ò˽ÃܹØÏµÍøÂç £¬×é³ÉÑÏÖØµÄÒþ˽Íþв¡£ÊÖÒÕËÝÔ´ÏÔʾ £¬Îó²îÓëCequint¹«Ë¾µÄÊÖÒռܹ¹±£´æ¹ØÁª¡£Verizon½«¸ÃÓ¦ÓõÄAPI°²ÅÅÔÚͨ¹ýGoDaddy×¢²áµÄÓòÃûÏ £¬¶øCequint×÷ΪÀ´µçÏÔʾÊÖÒÕÌṩÉÌ £¬ÆäÒѹرյĹٷ½ÍøÕ¾Òý·¢¶ÔÊý¾Ý¹ÜÀíÄÜÁ¦µÄÖÊÒÉ¡£Ö»¹ÜVerizonÉù³ÆÎ´·¢Ã÷ÀÄÓúۼ£ÇÒÎó²î½öÓ°ÏìiOS×°±¸ £¬µ«´ËÀàÃô¸ÐÊý¾ÝµÄ¼¯Öд洢ÈÔÇÃÏìÇå¾²¾¯ÖÓ¡£


https://securityaffairs.com/176217/hacking/verizon-s-ios-call-filter-app-flaw.html


4. Î÷ÑÅͼ¸ÛÔâRhysidaÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂ9ÍòÓû§ÐÅϢй¶


4ÔÂ4ÈÕ £¬ÃÀ¹úÎ÷ÑÅͼ¸Û½üÆÚÅû¶ £¬ÆäÔÚ2024Äê8ÔÂÔâÓöRhysidaÀÕË÷Èí¼þ×éÖ¯µÄÍøÂç¹¥»÷ £¬µ¼ÖÂÔ¼9ÍòÃûÔ±¹¤¡¢³Ð°üÉ̼°Óû§µÄÃô¸ÐÐÅϢй¶¡£×÷Ϊî¿ÏµÎ÷ÑÅͼº£¸Û¼°¹ú¼Ê»ú³¡µÄÁª°î»ú¹¹ £¬´Ë´Î¹¥»÷Ôì³ÉITϵͳÖÐÖ¹ £¬Ó°Ïì»ú³¡º½°àÔËÓª¡¢ÂÿͷþÎñϵͳ¼°¹Ù·½ÍøÕ¾¹¦Ð§¡£¿Ú°¶Õþ¸®ÔÚ¹¥»÷±¬·¢ÈýÖܺóÈ·ÈÏ £¬Rhysida×é֯ϵ¸ÃÊÂÎñµÄÄ»ºóºÚÊÖ¡£Ö»¹Ü¹¥»÷ÕßÍþв½«ÔÚ°µÍø¹ûÕæÇÔÈ¡Êý¾Ý £¬Î÷ÑÅͼ¸ÛÃ÷È·¾Ü¾øÖ§¸¶Êê½ðÒªÇó¡£Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ루²¿·Öº¬ºóËÄ룩¡¢¼ÝʻִÕÕ¼°Ò½ÁÆÐÅÏ¢µÈ £¬ÊÜÓ°ÏìÈËȺÖÐÔ¼7.1ÍòÀ´×Ô»ªÊ¢¶ÙÖÝ¡£Î÷ÑÅͼ¸ÛÒÑÏòÊÜÓ°ÏìÕß¼ÄËÍ9Íò·âÊéÃæÍ¨Öª £¬Ç¿µ÷Òªº¦ÔËӪϵͳδÊܲ¨¼°¡£¿Ú°¶ÌØÊâÖ¸³ö £¬»ú³¡¼°º£ÔËÂÿÍÊý¾ÝÊÜÓ°ÏìÓÐÏÞ £¬Ö§¸¶ÏµÍ³¼á³ÖÇå¾² £¬Ö÷ÒªºÏ×÷»ï°é£¨°üÀ¨º½¿Õ¹«Ë¾¡¢ÓÊÂÖÆóÒµ¼°Áª°î»ú¹¹£©µÄרÓÐÍøÂçҲδ±»ÉøÍ¸¡£


https://www.bleepingcomputer.com/news/security/port-of-seattle-says-ransomware-breach-impacts-90-000-people/


5. °Ä´óÀûÑÇÑøÀϽðÐÐÒµÔâÓö´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷


4ÔÂ4ÈÕ £¬°Ä´óÀûÑÇÑøÀϽðÐÐÒµÉÏÖÜÔâÓö´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷ £¬¶à¼Ò´óÐÍ»ù½ð»áÔ±ÕË»§Çå¾²ÊÜÍþв¡£¾Ý°Ä´óÀûÑÇÑøÀϽð»ù½ðЭ»á£¨ASFA£©Åû¶ £¬Ö»¹Ü´ó¶¼¹¥»÷±»ÀֳɷÀÓù £¬ÈÔÓв¿·Ö»áÔ±ÕË»§±»ÈëÇÖ £¬ÐÐÒµËðʧÇéÐÎÕýÒ»Á¬ÆÀ¹ÀÖС£×÷Ϊ¸Ã¹ú×î´óÑøÀϽð»ù½ðÖ®Ò» £¬AustralianSuperÈ·ÈϹ¥»÷ÕßʹÓñ»µÁƾ֤ÇÖÈëÖÁÉÙ600¸öÕË»§ £¬ÆóÒµÒѽôÆÈËø¶¨¿ÉÒÉÕË»§²¢Í¨ÖªÊÜÓ°Ïì»áÔ±¡£REST»ù½ð͸¶ £¬Ô¼8000Ãû»áÔ±µÄÐÕÃû¡¢ÓÊÏä¼°»áÔ±±àºÅµÈÃô¸ÐÐÅÏ¢ÔÚ¹¥»÷Öб»»á¼û £¬µ«ËùÐÒ䱬·¢×ʽð͵ȡ¡£HostplusÔòÌåÏÖÆä»áԱδÔâÊܲÆÎñËðʧ £¬ÏÖÔÚÕýÔÚÆÀ¹ÀÕË»§Ó°Ïì¹æÄ£¡£Í¶×ÊÆ½Ì¨Insignia FinancialµÄExpand Wrap PlatformÒ²Ôâ¹¥»÷ £¬Ô¼100¸ö¿Í»§ÕË»§±»ÉøÍ¸ £¬µ«ÉÐδ·¢Ã÷×ʽðËðʧ֤¾Ý¡£¸Ã¹«Ë¾ºôÓõÓû§×èÖ¹¿çÆ½Ì¨ÖØ¸´Ê¹ÓÃÃÜÂë £¬²¢°´ÆÚ¸üÐÂ×°±¸Çå¾²¡£ÖµµÃ×¢ÖØµÄÊÇ £¬HESTAºÍMercer SuperÁ½¼Ò´óÐÍ»ù½ðδÊܲ¨¼° £¬Æä¹ÜÀíµÄ200ÓàÍò»áÔ±ÕË»§¼á³ÖÇå¾²¡£ASFAÒÑÆô¶¯½ðÈÚ·¸·¨±£»¤½¨Òé £¬½¨Éè¿çÐÐÒµ-Õþ¸®Ð­×÷ÈÈÏß £¬²¢Ðû²¼·ÀÓù¹¤¾ß°üÇ¿»¯Ç徲Эµ÷¡£


https://www.bleepingcomputer.com/news/security/australian-pension-funds-hit-by-wave-of-credential-stuffing-attacks/


6. EuropcarÔâGitLabÈëÇÖµ¼Ö¶à´ï20Íò¿Í»§Êý¾Ýй¶


4ÔÂ4ÈÕ £¬¿ç¹úÆû³µ×âÁÞ¾ÞÍ·Europcar Mobility Group½üÆÚÔâÓöÖØ´óÍøÂçÇå¾²ÊÂÎñ £¬ÆäGitLab´úÂë¿ÍÕ»ÔâºÚ¿ÍÈëÇÖ £¬µ¼ÖÂAndroid/iOSÓ¦ÓÃÔ´´úÂë¼°²¿·Ö¿Í»§Êý¾Ýй¶¡£¹¥»÷ÕßÐû³ÆÕÆÎÕ37GBÃô¸ÐÊý¾Ý £¬°üÀ¨ÔÆ»ù´¡ÉèÊ©ÏêÇé¼°SQL±¸·ÝÎļþ £¬²¢Íþв¹ûÕæÐÅϢʵÑéÀÕË÷¡£¾­ÆðÔ´È·ÈÏ £¬Ð¹Â¶Êý¾ÝÉæ¼°GoldcarºÍUbeeqoÆ·ÅÆ5ÍòÖÁ20Íò¿Í»§µÄÐÕÃûÓëÓÊÏ䵨ַ £¬µ«Î´Éæ¼°ÒøÐÐÐÅÏ¢¡¢ÃÜÂëµÈ½¹µãÃô¸Ð×ֶΡ£¸Ã¹«Ë¾ÒÑÆô¶¯Ó¦¼±ÏìÓ¦ £¬ÏòÊÜÓ°Ïì¿Í»§·¢ËÍ֪ͨ²¢±¨±¸Êý¾Ý±£»¤»ú¹¹¡£ÖµµÃ×¢ÖØµÄÊÇ £¬´Ë´ÎÊÂÎñ䲨¼°ËùÓдúÂë¿ÍÕ» £¬ÈÔÓв¿·ÖÔ´´úÂë¼á³ÖÍêÕû¡£ÏÖÔÚ»¹²»ÇåÎúÍþвÐÐΪÕßÊÇÔõÑù»ñµÃ Europcar ´úÂë´æ´¢¿âµÄ»á¼ûȨÏÞµÄ £¬µ«×î½ü±¬·¢µÄÐí¶àÎ¥¹æÐÐΪ¶¼ÊÇÓÉÐÅÏ¢ÇÔÈ¡ÕßÇÔÈ¡µÄƾ֤ÒýÆðµÄ¡£


https://www.bleepingcomputer.com/news/security/europcar-gitlab-breach-exposes-data-of-up-to-200-000-customers/