E-ZPass´¹µö¶ÌÐŹ¥»÷·¢×÷ £¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþ·ÇÔÈ¡

°ä²¼¹¦·ò 2025-04-07

1. E-ZPass´¹µö¶ÌÐŹ¥»÷·¢×÷ £¬Óû§Ãô¸ÐÐÅÏ¢Ôâ¼ÓÃÜÇþ·ÇÔÈ¡


4ÔÂ6ÈÕ £¬½üÆÚ £¬Õë¶Ô½»Í¨ÊÕ·Ñ·þÎñÓû§µÄÍøÂç´¹µö¹¥»÷³öÏÖ·¢×÷ʽÔö³¤ £¬·¸·¨·Ö×Ó¼ÙÒâE-ZPass¡¢FasTrakµÈÊÕ·Ñ»ú¹¹ £¬Í¨¹ýiMessage¼°SMSÇþ·´ó¹æÄ£·¢ËÍڲƭ¶ÌÐÅ¡£¹¥»÷ÕßÀûÓÃ×Ô¶¯»¯¹¤¾ßÈÆ¹ý·´À¬»øÓʼþϵͳ £¬½áºÏËæ»ú»¯·¢¼þµØÖ·Ö´ÐÐ¸ßÆµ´Î¹¥»÷ £¬µ¥ÈÕ·¢ËÍÁ¿¿É´ï7Ìõ £¬ÏÔÖø¼ÓÇ¿ÁËÚ¿Æ­µÄÉøÈëÄÜÁ¦¡£´ËÀà¶ÌÐÅͨ³£Ñ¡È¡½ôÆÈÐÔ»°Êõ £¬Èç"48Ó×ʱÄÚδ½Éͨ³©·Ñ½«ÔÝÍ£¼ÝÊ»×ʸñ"µÈÍþвÐÔÄÚÈÝ £¬ÓÕµ¼Óû§µã»÷ǶÈëµÄ¶ñÒâÁ´½Ó¡£Îª¶ã±ÜApple iMessageµÄ°²È«»úÔì £¬Ú¿Æ­·Ö×ÓÒªÇóÓû§ÏȻظ´¶ÌÐÅÒÔ¼¤»î¿Éµã»÷Á´½Ó £¬½ø¶øÌø×ªÖÁ¾«ÐÄ·ÂÔìµÄ´¹µöÍøÕ¾¡£¾­¼¼ÊõÑéÖ¤ £¬ÕâЩ´¹µöÒ³ÃæÑ¡È¡ÏìӦʽÉè¼Æ £¬½öÄÜÔÚÒÆ¶¯¶ËÆëÈ«ÏÔʾ £¬Í¨¹ýÊÓ¾õ¼Ù×°ÇÔÈ¡Óû§ÐÕÃû¡¢ÐÅÓþ¿¨ºÅµÈÃô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ £¬ÐÂÐËÍøÂç·¸×ï¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÈçLucidºÍDarcula±»Ö¸²Î¼Ó´ËÀ๥»÷ £¬ÆäÀûÓüÓÃܵÄRCSºÍiMessageºÍÌ¸Í»ÆÆ´«Í³¹ýÂËϵͳ £¬ÏÔÖø½µµÍ×÷°¸³É±¾¡£Áª¹úµ÷²é¾Ö£¨FBI£©ÔçÔÚ2024Äê4ÔÂÒѰ䲼ÓйØÔ¤¾¯ £¬µ«¹¥»÷Õß³ÖÐøµü´úÊÖ·¨ £¬µ¼ÖÂÓû§ÊÜÆ­·çÏÕ³ÖÐøÅÊÉý¡£


https://www.bleepingcomputer.com/news/security/toll-payment-text-scam-returns-in-massive-phishing-wave/


2. disgrasya¶ñÒâ°üÀÄÓÃPyPI·Ö·¢Çþ·ÍþвWooCommerceÐÅÓþ¿¨°²È«


4ÔÂ6ÈÕ £¬½üÈÕ £¬°²È«×êÑÐÈËÔ±¸æ·¢ÁËÒ»¸öÃûΪ"disgrasya"µÄ¶ñÒâPython°ü £¬¸Ã°üͨ¹ýPyPIƽ̨±»ÏÂÔØ³¬¹ý3.4Íò´Î £¬ÆäרÃÅÓÃÓÚÑéÖ¤±»µÁÐÅÓþ¿¨µÄ·¸·¨»î¶¯¡£¸Ã¶ñÒâÈí¼þÕë¶ÔʹÓÃCyberSourceÖ§¸¶Íø¹ØµÄWooCommerceµçÉÌÆ½Ì¨ £¬Í¨¹ý·ÂÕÕÆëÈ«¹ºÎïÁ÷³ÌÖ´ÐÐÐÅÓþ¿¨Ú²Æ­ÑéÖ¤¡£¼¼Êõ·ÖÎöÏÔʾ £¬¹¥»÷ÕßÀûÓøðüÖ´Ðи߶È×Ô¶¯»¯µÄ¹¥»÷Á´£ºÊ×ÏÈץȡָ±êÉ̵êÉÌÆ·ID²¢ÌìÉúÐé¹¹¹ºÎï³µ £¬ËæºóÇÔÈ¡½áÕËÒ³ÃæµÄCSRFÁîÅÆºÍÖ§¸¶Íø¹Ø¸ßµÍÎIJÎÊý¡£¹Ø¼ü²½ÖèÖÐ £¬±»µÁÐÅÓþ¿¨Êý¾Ý²¢·ÇÖ±½ÓÌá½»¸øÖ§¸¶Íø¹Ø £¬¶øÊÇ·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄ¶ñÒâ·þÎñÆ÷£¨railgunmisaka.com£© £¬¸Ã·þÎñÆ÷¼Ù×°³ÉºÏ·¨Ö§¸¶½Ó¿Ú·µ»ØÐéαÊÚȨÁ˾Ö £¬×îÖÕͨ¹ýÌá½»´øÏóÕ÷µÄ¶©µ¥ÊµÏÖÑéÖ¤¡£ÕâÖÖ¹¥»÷ÊÖ·¨ÓµÓм«Ç¿µÄÒñ±ÎÐÔ¡£Ò»·½Ãæ £¬Õû¸öÁ÷³Ì·ÂÕÕÕæÊµÓû§ÐÐΪ £¬ÃÀÂúÈÚÈëÕý³£ÂòÂôÁ÷Á¿ £»ÁíÒ»·½Ãæ £¬¹¥»÷Õßѡȡ"ÖÐÑëÈËÑéÖ¤"ģʽ £¬¼È¶ã±ÜÁËÖ±½Ó´¥ÅöÖ§¸¶ÏµÍ³µÄ¼ì²â·çÏÕ £¬ÓÖÄÜÅúÁ¿´¦ÖðµÍø»ñÈ¡µÄÐÅÓþ¿¨Êý¾Ý¡£Socket°²È«ÍŶÓÖ¸³ö £¬¸Ã¶ñÒâ°üÉõÖÁÔÚÆä¹Ù·½ÃèÊöÖй«¿ªÈÏ¿ÉÓÃÓÚ·¸·¨Óô¦ £¬Í¹ÏԺڿͶԿªÔ´Æ½Ì¨ÀÄÓÃˮƽ֮Éî¡£


https://www.bleepingcomputer.com/news/security/carding-tool-abusing-woocommerce-api-downloaded-34k-times-on-pypi/


3. Verizon iOSÀûÓ÷ì϶¶³öͨ»°¼Í¼ԪÊý¾Ý £¬Òѽ¨¸´Î´ÏÖÀÄÓÃ


4ÔÂ5ÈÕ £¬Verizon Wireless½üÆÚ½¨¸´µÄiOS°æCall FilterÀûÓ÷ì϶ £¬Â¶³ö³öDZÔڵĴó¹æÄ£Í¨»°¼Í¼й¶·çÏÕ¡£°²È«×êÑÐÔ±Evan ConnellyÓÚ2025Äê2Ô·¢ÏÖ £¬¸ÃÀûÓõÄ/clr/callLogRetrieval½Ó¿Ú´æÔÚÉí·ÝÑé֤ȱµã£ºÖ»¹ÜѡȡJWTÁîÅÆÈÏÖ¤ £¬µ«·þÎñÆ÷δУÑéÒªÇóÖеĵ绰ºÅÂëÓëÓû§IDµÄÆ¥ÅäÐÔ¡£ÕâʹµÃ¹¥»÷Õß¿Éͨ¹ýαÔìÒªÇó £¬ËÁÒâ¼ìË÷Ö¸±êÓû§µÄͨ»°¼Í¼ £¬ÊÜÓ°ÏìÁìÓòº­¸ÇĬÈÏÆôÓø÷þÎñµÄÎÞÊýiOSÓû§¡£¸Ã·ì϶µÄDZÔÚ·çÏÕÔ¶³¬Í¨³£Êý¾Ýй¶¡£×¨¼ÒÖÒ¸æ £¬Í¨»°¼Í¼µÄ¹¦·ò´ÁÐÅÏ¢¿É±»ÓÃÓÚʵʱ¼à¿ØÌض¨¶ÔÏó £¬Èç¼ÇÕß¡¢·¨ÂÉÈËÔ±»ò¼Ò±©Êܺ¦Õß £¬ÆäÈÕ³£ÁªÏµÄ£Ê½¼°Ðж¯¹ì¼£½«Æëȫ¶³ö¡£Í¨¹ý¶ÈÎö³Á¸´Í¨»°ºÅÂë £¬ÉõÖÁ¿ÉÄܼø±ðһʱͨѶÏß·»ò˽ÃܹØÏµÍøÂç £¬×é³ÉÑϳÁµÄÒþÖÔÍþв¡£¼¼ÊõËÝÔ´ÏÔʾ £¬·ì϶ÓëCequint¹«Ë¾µÄ¼¼Êõ¼Ü¹¹´æÔÚ¹ØÁª¡£Verizon½«¸ÃÀûÓõÄAPI²¿ÊðÔÚͨ¹ýGoDaddy×¢²áµÄÓòÃûÏ £¬¶øCequint×÷ΪÀ´µçÏÔʾ¼¼ÊõÌṩÉÌ £¬ÆäÒѹعصĹٷ½ÍøÕ¾Òý·¢¶ÔÊý¾ÝÖÎÀíÄÜÁ¦µÄÖÊÒÉ¡£Ö»¹ÜVerizonÐû³ÆÎ´·¢ÏÖÀÄÓúۼ£ÇÒ·ì϶½öÓ°ÏìiOSÉ豸 £¬µ«´ËÀàÃô¸ÐÊý¾ÝµÄ¼¯Öд洢ÈÔÇÃÏ찲ȫ¾¯ÖÓ¡£


https://securityaffairs.com/176217/hacking/verizon-s-ios-call-filter-app-flaw.html


4. Î÷ÑÅͼ¸ÛÔâRhysidaÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂ9ÍòÓû§ÐÅϢй¶


4ÔÂ4ÈÕ £¬ÃÀ¹úÎ÷ÑÅͼ¸Û½üÆÚÅû¶ £¬ÆäÔÚ2024Äê8ÔÂÔâ·êRhysidaÀÕË÷Èí¼þ×éÖ¯µÄÍøÂç¹¥»÷ £¬µ¼ÖÂÔ¼9ÍòÃûÔ±¹¤¡¢³Ð°üÉ̼°Óû§µÄÃô¸ÐÐÅϢй¶¡£×÷Ϊ¼à¹ÜÎ÷ÑÅͼº£¸Û¼°¹ú¼Ê»ú³¡µÄÁª¹ú»ú¹¹ £¬Õâ´Î¹¥»÷Ôì³ÉITϵͳÖжÏ £¬Ó°Ïì»ú³¡º½°àÔËÓª¡¢³Ë¿Í·þÎñϵͳ¼°¹Ù·½ÍøÕ¾Ö°ÄÜ¡£¸Û¿Úµ±¾ÖÔÚ¹¥»÷²úÉúÈýÖܺóÈ·ÈÏ £¬Rhysida×é֯ϵ¸ÃÊÂÎñµÄÄ»ºóºÚÊÖ¡£Ö»¹Ü¹¥»÷ÕßÍþв½«ÔÚ°µÍø¹«¿ªÇÔÈ¡Êý¾Ý £¬Î÷ÑÅͼ¸ÛÃ÷È·»Ø¾øÖ§¸¶Êê½ðÒªÇó¡£Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂ루²¿Ãź¬ºóËÄ룩¡¢¼ÝÊ»ÅÆÕÕ¼°Ò½ÁÆÐÅÏ¢µÈ £¬ÊÜÓ°ÏìÈËȺÖÐÔ¼7.1ÍòÀ´×Ô»ªÊ¢¶ÙÖÝ¡£Î÷ÑÅͼ¸ÛÒÑÏòÊÜÓ°ÏìÕß¼ÄËÍ9Íò·âÊéÃæÍ¨Öª £¬Ç¿µ÷¹Ø¼üÔËӪϵͳδÊܲ¨¼°¡£¸Û¿Ú³ö¸ñÖ¸³ö £¬»ú³¡¼°º£Ô˳˿ÍÊý¾ÝÊÜÓ°ÏìÓÐÏÞ £¬Ö§¸¶ÏµÍ³Î¬³Ö°²È« £¬ÖØÒªºÏ×÷ͬ°é£¨Ô̺¬º½¿Õ¹«Ë¾¡¢ÓÊÂÔìóÒµ¼°Áª¹ú»ú¹¹£©µÄרÓÐÍøÂçҲδ±»ÉøÈë¡£


https://www.bleepingcomputer.com/news/security/port-of-seattle-says-ransomware-breach-impacts-90-000-people/


5. °Ä´óÀûÑÇÑøÀϽðÐÐÒµÔâ·ê´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷


4ÔÂ4ÈÕ £¬°Ä´óÀûÑÇÑøÀϽðÐÐÒµÉÏÖÜÔâÓö´ó¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷ £¬¶à¼Ò´óÐÍ»ù½ð»áÔ¹ØË»§°²È«ÊÜÍþв¡£¾Ý°Ä´óÀûÑÇÑøÀϽð»ù½ðЭ»á£¨ASFA£©Åû¶ £¬Ö»¹ÜÎÞÊý¹¥»÷±»³É¹¦·ÀÓù £¬ÈÔÓв¿ÃÅ»áÔ¹ØË»§±»ÈëÇÖ £¬ÐÐÒµËðʧÇé¿öÕý³ÖÐøÆÀ¹ÀÖС£×÷Ϊ¸Ã¹ú×î´óÑøÀϽð»ù½ðÖ®Ò» £¬AustralianSuperÈ·ÈϹ¥»÷ÕßÀûÓñ»µÁƾ֤ÇÖÈëÖÁÉÙ600¸öÕË»§ £¬ÆóÒµÒÑ´¹Î£Ëø¶¨¿ÉÒÉÕË»§²¢Í¨ÖªÊÜÓ°Ïì»áÔ±¡£REST»ù½ðй© £¬Ô¼8000Ãû»áÔ±µÄÐÕÃû¡¢ÓÊÏä¼°»áÔ±±àºÅµÈÃô¸ÐÐÅÏ¢ÔÚ¹¥»÷Öб»½Ó¼û £¬µ«ËùÐÒδ²úÉú×ʽðµÁÈ¡¡£HostplusÔò°µÊ¾Æä»áԱδÔâ·ê²ÆÕþËðʧ £¬Ä¿Ç°ÔÚÆÀ¹ÀÕË»§Ó°ÏìÁìÓò¡£Í¶×ÊÆ½Ì¨Insignia FinancialµÄExpand Wrap PlatformÒ²Ôâ¹¥»÷ £¬Ô¼100¸ö¿Í»§ÕË»§±»ÉøÈë £¬µ«ÉÐδ·¢ÏÖ×ʽðËðʧ֤¾Ý¡£¸Ã¹«Ë¾ºôÓõÓû§Ô¤·À¿çƽ̨³Á¸´Ê¹ÓÃÃÜÂë £¬²¢¶¨ÆÚ¸üÐÂÉ豸°²È«¡£ÖµÍ×ÌùÐĵÄÊÇ £¬HESTAºÍMercer SuperÁ½¼Ò´óÐÍ»ù½ðδÊܲ¨¼° £¬ÆäÖÎÀíµÄ200ÓàÍò»áÔ¹ØË»§Î¬³Ö°²È«¡£ASFAÒÑÆô¶¯½ðÈÚ·¸×ï± £»¤½¨Òé £¬³ÉÁ¢¿çÐÐÒµ-µ±¾ÖºÏ×÷ÈÈÏß £¬²¢°ä²¼·ÀÓù¹¤¾ß°üÇ¿»¯°²È«Ð­µ÷¡£


https://www.bleepingcomputer.com/news/security/australian-pension-funds-hit-by-wave-of-credential-stuffing-attacks/


6. EuropcarÔâGitLabÈëÇÖµ¼Ö¶à´ï20Íò¿Í»§Êý¾Ýй¶


4ÔÂ4ÈÕ £¬¿ç¹úÆû³µ×âÁÞ¾ÞÍ·Europcar Mobility Group½üÆÚÔâ·ê³Á´óÍøÂ簲ȫÊÂÎñ £¬ÆäGitLab´úÂë²Ö¿âÔâºÚ¿ÍÈëÇÖ £¬µ¼ÖÂAndroid/iOSÀûÓÃÔ´´úÂë¼°²¿Ãſͻ§Êý¾Ýй¶¡£¹¥»÷ÕßÐû³Æ°ÑÎÕ37GBÃô¸ÐÊý¾Ý £¬Ô̺¬ÔÆ»ù´¡ÉèÊ©ÏêÇé¼°SQL±¸·ÝÎļþ £¬²¢Íþв¹«¿ªÐÅÏ¢Ö´ÐÐÀÕË÷¡£¾­³õ²½È·ÈÏ £¬Ð¹Â¶Êý¾ÝÉæ¼°GoldcarºÍUbeeqoÆ·ÅÆ5ÍòÖÁ20Íò¿Í»§µÄÐÕÃûÓëÓÊÏ䵨ַ £¬µ«Î´Éæ¼°ÒøÐÐÐÅÏ¢¡¢ÃÜÂëµÈÖ÷ÌâÃô¸Ð×ֶΡ£¸Ã¹«Ë¾ÒÑÆô¶¯Ó¦¼±ÏìÓ¦ £¬ÏòÊÜÓ°Ïì¿Í»§·¢ËÍ֪ͨ²¢±¨±¸Êý¾Ý± £»¤»ú¹¹¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Õâ´ÎÊÂÎñ䲨¼°È«Êý´úÂë²Ö¿â £¬ÈÔÓв¿ÃÅÔ´´úÂëά³ÖÆëÈ«¡£Ä¿Ç°»¹²»Ã÷ÏÔÍþвÐÐΪÕßÊÇÈôºÎ»ñµÃ Europcar ´úÂë´æ´¢¿âµÄ½Ó¼ûȨÏÞµÄ £¬µ«×î½ü²úÉúµÄºÜ¶àÎ¥¹æÐÐΪ¶¼ÊÇÓÉÐÅÏ¢ÇÔÈ¡ÕßÇÔÈ¡µÄƾ֤ÒýÆðµÄ¡£


https://www.bleepingcomputer.com/news/security/europcar-gitlab-breach-exposes-data-of-up-to-200-000-customers/