ÊýÊ®¿î¼ÙÇ®°ü²å¼þÓ¿ÈëFirefoxÊÐËÁ£¬ÍµÈ¡¼ÓÃÜÇ®±Ò

Ðû²¼Ê±¼ä 2025-07-04

1. ÊýÊ®¿î¼ÙÇ®°ü²å¼þÓ¿ÈëFirefoxÊÐËÁ£¬ÍµÈ¡¼ÓÃÜÇ®±Ò


7ÔÂ2ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾Koi Security×îÐÂÅû¶£¬Firefox¹Ù·½¸½¼Ó×é¼þÊÐËÁÕýÔâÊÜ´ó¹æÄ£¶ñÒâÀ©Õ¹³ÌÐò¹¥»÷£¬Áè¼Ý40¿îαװ³ÉÖ÷Á÷¼ÓÃÜÇ®±ÒÇ®°üµÄ²å¼þÒ»Á¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý¡£ÕâЩ·ÂðӦÓÃÁýÕÖCoinbase¡¢MetaMask¡¢Trust WalletµÈ°Ë´ó×ÅÃûÆ·ÅÆ£¬Í¨¹ýÖ²Èë¶ñÒâ´úÂëʵʱ²¶»ñÇ®°üƾ֤¼°Öú¼Ç´Ê£¬¹¥»÷Õß½è´Ë¿ÉÍêÈ«¿ØÖÆÊܺ¦ÕßÊý×Ö×ʲú¡£Ñо¿Õ¹ÏÖ£¬¸ÃºÚ¿Í×éÖ¯½ÓÄÉË«ÖØÓÕÆ­Õ½ÂÔ£ºÒ»·½Ã棬ֱ½Ó¿Ë¡¿ªÔ´Ç®°ü´úÂë²¢×¢Èë¶ñÒâÂß¼­£¬Í¨¹ý"ÊäÈë/µã»÷"ÊÂÎñ¼àÌýÆ÷ɸѡ³¤¶ÈÁè¼Ý30×Ö·ûµÄÃÜÔ¿ÐÅÏ¢£»ÁíÒ»·½Ã棬αÔìÊý°ÙÌõÐéαÎåÐÇºÃÆÀ»ìÏýÊÓÌý£¬ÉõÖÁ»ìÈë´ó×ÚÒ»ÐDzîÆÀÖÆÔì"¿ÉÐŶÈ"¡£ÊÖÒÕÆÊÎöÏÔʾ£¬¶ñÒâ´úÂëͨ¹ýÒþ²Ø¹ýʧ¶Ô»°¿òʵÏÖÍêÈ«¾²Ä¬ÔËÐУ¬Êܺ¦Õß×ʲú±»µÁºóÍùÍùÎóÒÔΪÕý³£ÉúÒ⣬µ¼ÖÂËðʧÄÑÒÔ×·ËÝ¡£Koi Security×·×Ù·¢Ã÷£¬¸Ã¹¥»÷Ðж¯ÖÁÉÙÒ»Á¬ÖÁ4Ô£¬Ã¿ÖܾùÓÐÐÂÐͶñÒâ²å¼þÉÏÏß¡£×îа¸ÀýÏÔʾ£¬ÉÏÖÜÈÔÓзÂðǮ°üͨ¹ýMozillaÉóºËÁ÷³Ì¡£Ö»¹ÜMozillaÉù³ÆÒѰ²ÅÅ×Ô¶¯»¯Î£º¦ÆÀ¹Àϵͳ£¬µ«×èÖ¹±¨µÀÐû²¼£¬´ó¶¼ÉæÊ²å¼þÈÔ¿ÉÕý³£ÏÂÔØ¡£


https://www.bleepingcomputer.com/news/security/dozens-of-fake-wallet-add-ons-flood-firefox-store-to-drain-crypto/


2. ˼¿ÆÖÒÑÔ¹¥»÷Õß¿ÉÆ¾¾²Ì¬ÃÜÂëÔ¶³Ì½ÓÊÜIPµç»°ÏµÍ³


7ÔÂ2ÈÕ£¬ÍøÂçÇå¾²ÁìÓòÔÙÏ쾯±¨£¬Ë¼¿ÆÏµÍ³¹«Ë¾Ðû²¼ÔÚÆä½¹µãͨѶ²úÆ·ÖнôÆÈÒÆ³ýÒ»¸ö¸ßΣºóÃÅÕË»§¡£¸ÃÎó²î£¨CVE-2025-20309£©Ó°ÏìCisco Unified Communications Manager£¨Ô­CallManager£©¼°SME Engineering Special°æ±¾15.0.1.13010-1ÖÁ15.0.1.13017-1£¬ÔÊÐí¹¥»÷Õßͨ¹ýÎÞ·¨Ð޸ĵľ²Ì¬rootƾ֤Զ³Ì»ñȡװ±¸×î¸ßȨÏÞ¡£×÷ΪȫÇòÆóÒµIPµç»°ÏµÍ³µÄÖÐÊàÆ½Ì¨£¬Unified CMÖÎÀí×ÅÊý°ÙÍǫ̀װ±¸µÄºô½Ð·ÓÉ¡¢ÉèÖÃÕ½ÂÔ¼°ÓïÒô·þÎñ¡£´Ë´ÎÅû¶µÄÎó²îÔ´ÓÚ¿ª·¢²âÊÔ½×¶ÎÒÅÁôµÄÓ²±àÂëÕË»§£¬¸ÃÕË»§Î´ÔÚÉú²ú°æ±¾ÖнûÓã¬ÇÒĬÈÏÆ¾Ö¤Ö±½Ó̻¶ÓÚ¹«Íø¡£Ë¼¿ÆÇ徲ͨ¸æÖ¤Êµ£¬¹¥»÷ÕßÎÞÐèÈκÎÉí·ÝÑéÖ¤¼´¿Éͨ¹ý¸ÃºóÃÅÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁÍêÕû¿ØÖÆÊÜÓ°Ïì×°±¸¡£Ö»¹ÜÉÐδ·¢Ã÷Ò°Íâ¹¥»÷Ñù±¾£¬µ«ÈÕÖ¾ÆÊÎöÏÔʾ£¬/var/log/active/syslog/secure·¾¶ÒѼͼÏà¹ØÈëÇÖºÛ¼££¬ÖÎÀíÔ±¿Éͨ¹ýfile get activelog syslog/secureÏÂÁî¼ì²âÒì³£µÇ¼¡£ÓëÒÔÍùÎó²î²î±ð£¬´Ë´ÎÊÂÎñÎÞÔÝʱ»º½â²½·¥£¬Ë¼¿Æ½öÌṩÁ½ÖÖÐÞ¸´Â·¾¶£ºÉý¼¶ÖÁ2025Äê7ÔÂÐû²¼µÄ15SU3°æ±¾£¬»ò½ôÆÈ×°ÖÃCSCwp27755²¹¶¡¡£¸ÃÎó²î±»ÆÀ¶¨Îª×î¸ßÑÏÖØÆ·¼¶£¨CVSS 10.0£©£¬¹¥»÷Õ߿ɽè´ËºáÏòÉøÍ¸ÄÚÍø£¬ÇÔȡͨ»°¼Í¼¡¢¸Ä¶¯ÓïÒôÓʼþ£¬ÉõÖÁ½«ÆóÒµµç»°ÏµÍ³×ª»¯Îª½©Ê¬ÍøÂç½Úµã¡£


https://www.bleepingcomputer.com/news/security/cisco-removes-unified-cm-callManager-backdoor-root-account/


3. Forminator²å¼þ¸ßΣÎó²îÍþв60ÍòWordPressÍøÕ¾


7ÔÂ2ÈÕ£¬È«Çò³¬60ÍòWordPressÍøÕ¾ÕýÃæÁÙÑÏËàÇå¾²Íþв£¬ÆäʹÓõÄForminator±íµ¥²å¼þ±»ÆØ±£´æ¸ßΣí§ÒâÎļþɾ³ýÎó²î£¨CVE-2025-6463£¬CVSS 8.8£©¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÎÞÐèÈÏÖ¤¼´¿Éɾ³ý·þÎñÆ÷Òªº¦Îļþ£¬°üÀ¨½¹µãÉèÖÃÎļþwp-config.php£¬×îÖÕµ¼ÖÂÍøÕ¾Íêȫʧ¿Ø¡£Çå¾²ÍŶÓÇ¿ÁÒ½¨ÒéÁ¬Ã¦Éý¼¶ÖÁ1.44.3°æ±¾ÒÔÐÞ¸´´ËΣº¦¡£Îó²î½¹µãÔ´ÓÚ²å¼þµÄentry_delete_upload_files()º¯Êý±£´æÂ·¾¶Ñé֤ȱÏÝ¡£µ±ÖÎÀíÔ±ÕûÀí¶ñÒâ±íµ¥Ìύʱ£¬¹¥»÷Õ߿ɽṹ°üÀ¨Â·¾¶±éÀú×Ö·û´®£¨Èç../../../wp-config.php£©µÄ±íµ¥×ֶΣ¬´¥·¢·þÎñÆ÷ɾ³ýí§ÒâÎļþ¡£Ò»µ©wp-config.php±»É¾£¬WordPress½«×Ô¶¯ÖØÖÃΪװÖÃģʽ£¬¹¥»÷Õß½è´Ë¿É¸Ä¶¯Êý¾Ý¿âƾ֤²¢Ö²ÈëºóÃÅ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÊÖÒÕÆÊÎöÏÔʾ£¬¸ÃÎó²îʹÓÃÌõ¼þ¼«Îª¿íËÉ£º½öÐèÄ¿µÄÍøÕ¾ÆôÓÃForminator²å¼þÇÒ±£´æ¿É±»É¾³ýµÄ±íµ¥¼Í¼¡£¹¥»÷Õ߼ȿÉÊÖ¶¯Ìá½»¶ñÒâ±íµ¥£¬Òà¿ÉʹÓÃ×Ô¶¯»¯¹¤¾ßÅúÁ¿É¨ÃèųÈõÕ¾µã¡£


https://cybersecuritynews.com/forminator-wordpress-plugin-vulnerability/


4. ¸¥¼ªÄáÑǸñÂåË¹ÌØÏØÔâÀÕË÷Èí¼þ¹¥»÷£¬Õþ¸®¹ÍÔ±Êý¾Ýй¶


7ÔÂ4ÈÕ£¬½ñÄê4Ô£¬ÃÀ¹ú¸¥¼ªÄáÑÇÖݸñÂåË¹ÌØÏØ±¬·¢Ò»ÆðÕë¶ÔµØ·½Õþ¸®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬µ¼ÖÂ3527ÃûÏÖÈμ°Ç°ÈÎÕþ¸®¹ÍÔ±µÄÃô¸ÐÐÅÏ¢±»µÁ£¬Òý·¢Éç»á¶ÔÍøÂçÇå¾²ÍþвµÄÆÕ±é¹Ø×¢¡£´Ë´ÎÊÂÎñÖУ¬ºÚ¿ÍÀÖ³ÉÈëÇÖ¸ÃÏØÐÅϢϵͳ£¬ÇÔÈ¡Á˰üÀ¨Éç»áÇå¾²ºÅÂë¡¢¼ÝÕÕÐÅÏ¢¡¢ÒøÐÐÕË»§ÏêÇé¡¢¿µ½¡°ü¹ÜºÅÂë¼°Ò½ÁƼͼµÈ¸ß¶ÈÃô¸ÐÊý¾Ý£¬¶ÔСÎÒ˽¼ÒÒþ˽ºÍ¹¤ÒµÇå¾²×é³ÉÑÏÖØÍþв¡£¸ñÂåË¹ÌØÏØÎ»ÓÚ¸¥¼ªÄáÑÇÖݶ«²¿£¬¾àÊ׸®ÀïÊ¿ÂúԼһСʱ³µ³Ì£¬Éú³ÝÔ¼4Íò¡£ÊÂÎñ±¬·¢ºó£¬¸ÃÏØÐÐÕþÖ÷×ù¿¨ÂÞ¶û¡¤Ë¹µÙ¶ûÓÚ±¾ÖÜÕýʽÏòÊÜÓ°Ïì¹ÍÔ±·¢³ö֪ͨ£¬È·ÈÏÊý¾Ýй¶ÊÂʵ£¬²¢ÌåÏÖÒÑÔ¼ÇëÍøÂçÇ徲ר¼ÒЭÖúϵͳ»Ö¸´£¬Í¬Ê±ÏòÁª°îÊÓ²ì¾Ö£¨FBI£©ÍøÂç·¸·¨²¿·Ö¼°¸¥¼ªÄáÑÇÖݾ¯Ô±¾ÖÍøÂçÈÚºÏÖÐÐı¨°¸¡£ÖµµÃ×¢ÖØµÄÊÇ£¬Ö»¹Ü¸ÃÏØÔøÓÚ4ÔÂ22ÈÕÖÁ23ÈÕʱ´úÐû²¼ÍøÂçÖÐÖ¹ÖÒÑÔ£¬µ«ÒÔºóδһÁ¬¸üÐÂÊÂÎñÏ£Íû£¬½öÇ¿µ÷¡°ÕýÔÚÒ»Á¬¼à¿ØÓ°Ï족¡£ÊÓ²ìÏÔʾ£¬´Ë´Î¹¥»÷ÓëÃûΪBlackSuitµÄÀÕË÷Èí¼þÍÅ»ïÓйØ¡£¸Ã×éÖ¯ÓÚ5ÔÂ15ÈÕÔÚ°µÍøÐû²¼Ìû×Ó£¬Ðû³Æ¶Ô¸ñÂåË¹ÌØÏØÊÂÎñÈÏÕæ£¬²¢Ö¸¿ØÏØ·½¾Ü¾ø¾ÍÊê½ðÕö¿ªÌ¸ÅС£


https://therecord.media/virginia-county-says-ransomware-attack-exposed-ssns


5. °ÍÎ÷CIEE Oneƽ̨Êý¾Ýй¶ÊÂÎñ£ºÃô¸ÐÐÅÏ¢ÔâÇÔ²¢ÔÚ°µÍø³öÊÛ


7ÔÂ3ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾ResecurityÅû¶°ÍÎ÷Ö÷ҪʵϰÓëѧͽÏîÄ¿·þÎñƽ̨CIEE One±¬·¢ÖØ´óÊý¾Ýй¶ÊÂÎñ£¬µ¼Ö´ó×ÚÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢£¨PII£©¼°Îļþ±»ÇÔ²¢ÔÚ°µÍø³öÊÛ¡£´Ë´ÎÊÂÎñÖУ¬ÍþвÐÐΪÕßͨ¹ý̻¶µÄ¹È¸èÔÆ´æ´¢Í°ÈëÇÖϵͳ£¬ÍµÈ¡Á˰üÀ¨Éí·Ý¼Í¼¡¢ÁªÏµ·½·¨¡¢Ò½ÁƱ¨¸æ¼°ÎĵµÉ¨Ãè¼þµÈ¸ß¼ÛÖµÊý¾Ý£¬ËæºóÓɵØÏÂÊý¾Ý¾­¼ÍÉÌ"888"ÔÚ°µÍøÆ½Ì¨¾ÙÐÐÉúÒâ¡£CIEE OneÓɰÍÎ÷CIEEÉÌѧԺÕûºÏÖÐÐÄÔËÓª£¬Îª°üÀ¨BradescoÒøÐС¢Caixa¾­¼ÃÒøÐС¢ClaroµçÐŵÈÔÚÄڵĶ¥¼¶½ðÈÚ»ú¹¹¼°ÄÜÔ´¡¢¿Æ¼¼ÁìÓòÆóÒµÌṩÕÐÆ¸·þÎñ£¬ÅþÁ¬ÊýÍòÃûרҵÈËÊ¿Óë°ÍÎ÷±¾ÍÁ¼°¿ç¹ú¹«Ë¾¡£ÓÉÓÚÆäÆ½Ì¨»ã¾ÛÁËÓÃÓÚÅä¾°ÊÓ²ìºÍÕÐÆ¸Á÷³ÌµÄº£Á¿Ãô¸ÐÊý¾Ý£¬³ÉÎªÍøÂç·¸·¨·Ö×ÓµÄÖØµãÄ¿µÄ¡£±»µÁÐÅÏ¢¼«Ò×±»ÓÃÓÚÉí·Ý͵ÇÔ¡¢½ðÈÚڲƭµÈ²»·¨Ô˶¯£¬¶ÔÆóÒµºÍÇóÖ°Õß×é³ÉË«ÖØÎ£º¦¡£¾ÝResecurityÆÊÎö£¬´Ë´ÎÈëÇÖÔ´ÓÚÔÆ´æ´¢·þÎñÉèÖò»µ±£¬Ì»Â¶µÄ¹È¸èÔÆ´æ´¢Í°Òòȱ·¦»ù±¾Çå¾²·À»¤³ÉΪ¹¥»÷Èë¿Ú¡£


https://securityaffairs.com/179609/data-breach/cybercriminals-target-brazil-248725-exposed-in-ciee-one-data-breach.html


6. Hunters InternationalÀÕË÷Èí¼þÐû²¼Í£Ô˲¢ÌṩÃ⺬»ìÃܹ¤¾ß


7ÔÂ3ÈÕ£¬È«Çò×ÅÃûÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯Hunters InternationalÓÚ¿ËÈÕÐû²¼Õýʽ×èÖ¹ÔËÓª£¬²¢ÓÐÊýµØÏòËùÓÐÊܺ¦ÆóÒµÌṩÃ⺬»ìÃܹ¤¾ß£¬³ÉΪÊ׸ö×Ô¶¯·ÅÆúÊê½ðÒªÇóµÄÍøÂç·¸·¨ÕûÌå¡£¸Ã×éÖ¯ÔÚ°µÍøÐû²¼µÄÉùÃ÷ÖгÆ£¬´Ë¾ÙÖ¼ÔÚ"±í´ïÉÆÒâ²¢×ÊÖúÊÜÓ°Ï칫˾»Ö¸´Êý¾Ý"£¬Í¬Ê±Ç¿µ÷¹Ø±Õ¾öÒé¾­ÓÉ"ÎÈÖØË¼Á¿"£¬µ«Î´Ã÷È·Ìá¼°ÏêϸԵ¹ÊÔ­ÓÉ¡£Hunters International×Ô2023ÄêβáÈÆð£¬Òò´úÂëÌØÕ÷ÓëÒÑÇýÖðµÄHiveÀÕË÷Èí¼þ¸ß¶ÈÏàËÆ£¬±»Çå¾²»ú¹¹ÊÓΪÆäDZÔڸİæ¡£¸Ã×éÖ¯½ÓÄÉ¶àÆ½Ì¨¹¥»÷Õ½ÂÔ£¬Æä¶ñÒâÈí¼þÖ§³ÖWindows¡¢Linux¡¢FreeBSDµÈϵͳ¼°x64¡¢ARMµÈ¼Ü¹¹£¬¾ß±¸¿çƽ̨ѬȾÄÜÁ¦¡£ÒÑÍùÁ½Äê¼ä£¬¸ÃÍÅ»ï¶ÔÈ«Çò½ü300¼ÒÆóÒµÌᳫ¹¥»÷£¬Êê½ðÒªÇó´ÓÊýÊ®ÍòÖÁÊý°ÙÍòÃÀÔª²»µÈ¡£´Ë´ÎÍ£Ô˲¢·ÇͻȻ¡£2024Äê11Ô£¬¸Ã×éÖ¯ÔøÔ¤¸æ½«Òò"Ö´·¨Éó²éÔöÇ¿ºÍÓ¯ÀûÄÜÁ¦Ï½µ"¹Ø±Õ¡£Í¬ÆÚ£¬ÍþвÇ鱨¹«Ë¾Group-IBÅû¶ÆäÕýÍýÏëתÐÍ£¬ÍýÏëͨ¹ý¸üÃûΪ"World Leaks"µÄÐÂÆ·ÅÆ×¨×¢Êý¾Ý͵ÇÔ£¬Ê¹ÓÃÉý¼¶°æÐ¹Â¶¹¤¾ß¿ªÕ¹´¿ÀÕË÷Ðж¯£¬²»ÔÙ¼ÓÃÜÎļþ¶øÊÇÖ±½ÓÍþÐ²ÆØ¹âÊý¾Ý¡£ÕâÒ»¶¯ÏòÅú×¢£¬Ö»¹ÜHunters InternationalÖ÷Ìå×èÖ¹ÔËÓª£¬µ«ÆäÊÖÒÕ×ʲú¿ÉÄÜÒÔÐÂÐÎ̬¼ÌÐø»îÔ¾¡£


https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-shuts-down-after-world-leaks-rebrand/