https://cybersecuritynews.com/powerschool-massive-data-breach/
3.1.2.ÍâÂôƽ̨GrubHubÅûÂ¶ÖØ´óÊý¾Ýй¶Ê¼þ
¾ÝCybersecuritynewsÏûÏ¢£¬ÖªÃûÍâÂôƽ̨ GrubHub ÅûÂ¶ÖØ´óÊý¾Ýй¶Ê¼þ£¬Éæ¼°¿Í»§¡¢É̼ҺÍ˾»úÐÅÏ¢¡£´Ë´Îй¶Ê¼þÊÇÓɵÚÈý·½³Ð°üÉÌÕË»§±»¹¥ÆÆÒýÆðµÄ¡£±»ÆØ¹âÊý¾Ý°üÀ¨ÐÕÃû¡¢ÓÊÏä¡¢µç»°ºÅÂë¡¢²¿·ÖУ԰ÓòÍÕߵIJ¿·ÖÖ§¸¶¿¨ÐÅÏ¢ÒÔ¼°Ä³Ð©¾ÉϵͳµÄ¹þÏ£ÃÜÂ룬Ãô¸ÐÊý¾Ýδ±»·ÃÎÊ¡£
À´Ô´£º
https://cybersecuritynews.com/grubhub-data-breach/
3.1.3.Belsen ¼¯ÍÅй¶³¬ 1.5 Íò·Ý FortiGate ·À»ðǽÅäÖÃÐÅÏ¢
¾ÝHackreadÏûÏ¢£¬ÃûΪBelsen_GroupµÄÍþв×é֯й¶Á˳¬1.5Íò·Ý FortiGate ·À»ðǽÅäÖá£Ð¹Â¶ÐÅÏ¢°üÀ¨Óû§Ãû¡¢ÃÜÂë¡¢Êý×ÖÖ¤Êé¼°·À»ðǽ¹æÔòµÈ¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢ÈÆ¹ý·À»¤´ëÊ©²¢·ÃÎÊÃô¸Ðϵͳ£¬Òò´Ë´Ë´Îй¶Ê¼þ½«¶ÔʹÓÃÕâЩÉ豸µÄ×éÖ¯¹¹³ÉÍþв£¬ÃÀ¹ú¡¢Ó¢¹ú¡¢²¨À¼ºÍ±ÈÀûʱÊÇÊܺ¦ÕßÊýÁ¿×î¶àµÄ¹ú¼Ò£¬·¨¹ú¡¢Î÷°àÑÀ¡¢ÂíÀ´Î÷ÑÇ¡¢ºÉÀ¼¡¢Ì©¹úºÍÉ³ÌØ°¢À²®Æä´Î¡£
À´Ô´£º
https://hackread.com/belsen-group-leaks-fortigate-firewall-configurations/
4.1.¹úÄÚÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.1.1.º£ÄÏ·¢²¼É̳¬Ïû·ÑÁìÓò¸öÈËÐÅÏ¢±£»¤ºÏ¹æÖ¸Òý£¬Éæ¼°ÃŵêAPP¡¢Ð¡³ÌÐòÔËÐй淶
¡¶º£ÄÏÊ¡É̳¡³¬ÊÐÏû·ÑÁìÓò¸öÈËÐÅÏ¢±£»¤ºÏ¹æÖ¸Òý¡·ÓÚ2025Äê1ÔÂ9ÈÕ·¢²¼£¬Ö¼ÔÚÔöÇ¿É̳¡³¬ÊжÔÏû·ÑÕßÒþ˽ÐÅÏ¢µÄ±£»¤¡£¡¶Ö¸Òý¡·ÒªÇóÉ̳¡³¬ÊоӪÕßÔÚʹÓÃAPPºÍС³ÌÐòʱ£¬±ØÐëÃ÷È·ÌáʾÏû·ÑÕßÒþ˽Õþ²ß²¢È¡µÃÃ÷ȷͬÒ⣬ȷ±£¸öÈËÐÅÏ¢µÄÊÕ¼¯ºÍʹÓ÷ûºÏÊÚȨ·¶Î§¡£´ËÍ⣬¾ÓªÕß²»µÃËæÒâ¹²ÏíÏû·ÑÕߵĸöÈËÐÅÏ¢»ò·¢Ë͸öÐÔ»¯ÉÌÒµÐÅÏ¢£¬Ðè±£ÕÏÏû·ÑÕßÔÚÐÅÏ¢±£»¤ÖеÄ×ÔÖ÷Ȩ¡£
À´Ô´£º
http://www.hkwb.net/news/content/2025-01/10/content_4312159.htm
4.1.2.¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐļà²â·¢ÏÖ16¿îÎ¥¹æÒƶ¯Ó¦ÓÃ
¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶AppÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢ÐÐΪÈ϶¨·½·¨¡·µÈ·¨ÂÉ·¨¹æ¼°Ïà¹Ø¹ú¼Ò±ê×¼ÒªÇ󣬽üÆÚͨ¹ý»¥ÁªÍø¼à²â·¢ÏÖ16¿îÒÆ¶¯App´æÔÚÒþ˽²»ºÏ¹æÐÐΪ¡£
¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÌáÐѹã´óÊÖ»úÓû§½÷É÷ÏÂÔØÊ¹ÓÃÒÔÉÏÎ¥¹æÒƶ¯App£¬×¢ÒâÈÏÕæÔĶÁÆäÓû§ÐÒéºÍÒþ˽Õþ²ß˵Ã÷£¬²»ËæÒ⿪·ÅºÍͬÒâ²»±ØÒªµÄÒþ˽ȨÏÞ£¬²»ËæÒâÊäÈë¸öÈËÒþ˽ÐÅÏ¢£¬¶¨ÆÚά»¤ºÍÇåÀíÏà¹ØÊý¾Ý£¬±ÜÃâ¸öÈËÒþ˽ÐÅÏ¢±»Ð¹Â¶¡£
https://mp.weixin.qq.com/s/7V6FHFZ8s53AtYePIlSiaw
4.2.¹úÍâÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.2.1.ÐÂÐÍAndroid¶ñÒâÈí¼þÄ£·ÂÁÄÌìÓ¦ÓÃÇÔÈ¡Ãô¸ÐÊý¾Ý
¾ÝCyber Security NewsÏûÏ¢£¬Cyfirma µÄÍøÂç»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±×î½ü·¢ÏÖÁËÒ»¸öÕë¶ÔÄÏÑÇÓû§£¬ÓÈÆäÊÇÓ¡¶È¿ËʲÃ×¶ûµØÇøÓû§µÄ¸´ÔÓ Android ¶ñÒâÈí¼þ»î¶¯£¬Í¨¹ýαװ³ÉÒ»¿îÃûΪ¡°Tanzeem¡± µÄÁÄÌìÓ¦ÓóÌÐòÒÔÇÔȡĿ±êÉ豸ÖеÄÃô¸ÐÊý¾Ý¡£¸Ã¶ñÒâÈí¼þÀûÓÃÁËÁ÷ÐеĿͻ§²ÎÓëÆ½Ì¨ OneSignal£¬Í¨¹ýÍÆËÍÍøÂçµöÓãÁ´½Ó½øÐд«²¥¡£¼¼Êõ·ÖÎöÏÔʾ£¬Î±×°³É¡°Tanzeem¡±µÄ¶ñÒâÈí¼þÔÚ°²×°ºó¾ÍÍ£Ö¹ÔËÐУ¬µ«±³ºóÒѾÇëÇóÁ˶àÏîÃô¸ÐȨÏÞ£¬°üÀ¨·ÃÎÊͨ»°¼Ç¼¡¢ÁªÏµÈË¡¢¶ÌÐÅ¡¢Îļþ´æ´¢ºÍ¾«È·Î»ÖÃÊý¾Ý¡£Ëü»¹ÊÔͼÌáÈ¡ÓÃÓڵǼ¸÷ÖÖ»¥ÁªÍøÆ½Ì¨µÄµç×ÓÓʼþºÍÓû§ÃûȨÏÞ¡£
À´Ô´£º
https://thehackernews.com/2025/01/donot-team-linked-to-new-tanzeem.html
4.2.2.Óû§¼¯ÌåÆðËßSiri¡°ÍµÌý¡±£¬Æ»¹û»¨9500ÍòÃÀÔªºÍ½â
2025Äê1ÔÂ3ÈÕÏûÏ¢£¬¿Æ¼¼¾ÞÍ·Æ»¹û¹«Ë¾Í¬ÒâÖ§¸¶9500ÍòÃÀÔªÏÖ½ð£¬ÒԺͽâÒ»ÏîÄâÒéµÄ¼¯ÌåËßËÏ£¬¸ÃËßËÏÉù³ÆÆäSiriÓïÒôÖúÊÖÇÖ·¸ÁËÓû§µÄÒþ˽¡£´Ë´ÎËßËÏµÄÆðÒòÔ´ÓÚÓÐÃÀ¹úÓû§·´Ó³£¬SiriÔÚδ±»Ã÷È·»½ÐÑʱ£¬Ëƺõ»á×Ô¶¯¼¤»î²¢¼Ç¼ÖܱßÉùÒôÐÅÏ¢¡£ÀýÈ磬һЩÓû§ÔÚ¼ÒÖÐ˽Ͻ»Ì¸Ê±£¬SiriָʾµÆÍ»È»ÁÁÆð£¬ËûÃǵ£ÐÄ×Ô¼ºµÄ˽È˶Ի°±»ÊÕ¼¯ÉÏ´«¡£Ëæ×ÅÀàËÆ·´À¡Ô½À´Ô½¶à£¬Ïû·ÑÕßÈ¨Òæ±£»¤×éÖ¯´ú±í¹ã´óÓû§ÏòÆ»¹û¹«Ë¾ÌáÆð¼¯ÌåËßËÏ£¬Ö¸¿ØÆ»¹ûÇÖ·¸Óû§Òþ˽£¬Í¨¹ýSiriÊÕ¼¯Óû§ÈÕ³£¶Ô»°£¬ÓÃÓÚ¸ÄÉÆ·þÎñ»òÆäËûδ¹«¿ªÓÃ;£¬ÇÒδ³ä·ÖÕ÷µÃÓû§Í¬Òâ¡£Õâ·ÝºÍ½âÐÒ麸ÇÁË2014Äê9ÔÂ17ÈÕÖÁ2024Äê12ÔÂ31ÈÕÆÚ¼äʹÓÃSiriµÄÃÀ¹úÓû§£¬Éæ¼°ÊýǧÍòÈË¡£Ã¿Î»²ÎÓëËßËϵÄÓû§×î¶à¿ÉΪ5̨SiriÉ豸ÉêÇëÅâ³¥£¬Ã¿Ì¨É豸×î¸ß¿É»ñµÃ20ÃÀÔª¡£´ËÍ⣬ƻ¹û¹«Ë¾ÐèÔÚÁù¸öÔÂÄÚÓÀ¾Ãɾ³ý2019Äê10ÔÂǰÊÕ¼¯µÄSiri¸öÈËÒôƵ¼Ç¼¡£
À´Ô´£º
https://h5.stcn.com/pages/detail/detail?id=1478210&jump_type=reported_info
4.2.3.°²×¿ÍƳö"Éí·ÝÑéÖ¤"й¦ÄÜ£¬ÔöÇ¿É豸·ÀµÁ±£»¤
½üÈÕ£¬¹È¸èÐû²¼ÔÚ°²×¿ÏµÍ³ÖÐÍÆ³öÒ»ÏîеÄ"Éí·ÝÑéÖ¤"»Æ½ð³Ç¹ÙÍø¹¦ÄÜ£¬µ±Óû§À뿪ÊÜÐÅÈεÄλÖÃʱ£¬¸Ã¹¦Äܽ«ÒªÇóʹÓÃÉúÎïʶ±ðÈÏÖ¤À´·ÃÎÊÃô¸ÐµÄÉ豸ÉèÖá£Õâһй¦ÄÜÊǰ²×¿·ÀµÁ±£»¤Ì×¼þµÄÒ»²¿·Ö¡£"Éí·ÝÑéÖ¤"¹¦ÄÜÖ¼ÔÚͨ¹ýÒªÇóÓû§ÔÚÀ뿪ÊÜÐÅÈÎλÖÃʱʹÓÃÉúÎïʶ±ðÈÏÖ¤£¬À´ÔöÇ¿°²×¿ÏµÍ³¶Ô¹Ø¼üÕË»§ºÍÉ豸ÉèÖõı£»¤¡£ÐèÒªÉúÎïʶ±ðÈÏÖ¤µÄÃô¸Ð²Ù×÷°üÀ¨:Ö´Ðлָ´³ö³§ÉèÖᢸü¸ÄÆÁÄ»Ëø¶¨¡¢×¢²áÐÂÖ¸ÎÆ¡¢¹Ø±Õ"²éÕÒÎÒµÄÉ豸"¹¦ÄÜ¡¢Ìí¼Ó¹È¸èÕË»§¡¢·ÃÎÊ¿ª·¢ÕßÑ¡ÏîÒÔ¼°´ò¿ª¹È¸èÃÜÂë¹ÜÀíÆ÷µÈ¡£¸Ã¹¦ÄÜ»¹Îª¹È¸èÕË»§ÆôÓÃÁË"ÔöÇ¿±£»¤"£¬²¢ÔÚ·ûºÏÌõ¼þµÄÉ豸ÉÏΪÈýÐÇÕË»§ÌṩÁ˶îÍâµÄ»Æ½ð³Ç¹ÙÍø±£»¤¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/new-android-identity-check-locks-settings-outside-trusted-locations/
4.2.4.ÈýÐÇÐÞ¸´ÊÖ»úÉϵÄÁãµã»÷©¶´£¬¿Éµ¼ÖÂϵͳ½ø³Ì±ÀÀ£
½üÈÕ£¬ÈýÐÇ·¢²¼»Æ½ð³Ç¹ÙÍø¸üУ¬ÐÞ¸´ÁËÆäÆì½¢ÊÖ»ú Galaxy S23 ºÍS24 ÖеÄÒ»¸öÑÏÖØµÄÁãµã»÷»Æ½ð³Ç¹ÙÍøÂ©¶´£¨CVE-2024-49415£©£¬Éæ¼° Monkey¡¯s Audio (APE)½âÂëÆ÷£¬Ó°Ïì Android 12 ¡¢13 ºÍ14 °æ±¾£¬ÔÊÐí¹¥»÷ÕßÔÚ²»ÐèÒªÓû§²Ù×÷µÄÇé¿öϹ¥»÷É豸¡£¹È¸è½¨ÒéÓû§ÔÚ²¹¶¡·¢²¼Ö®Ç°²ÉÈ¡ÒÔÏ´ëÊ©£ºÈç²»±ØÒª£¬½ûÓà RCS ÏûÏ¢£»±ÜÃâͨ¹ýÏûÏ¢Ó¦ÓûòÎļþä¯ÀÀÆ÷´ò¿ª»ò²¥·Å²»¿ÉÐŵÄÒôƵÎļþ£»¾¡¿ìÓ¦ÓÃÈýÐÇÌṩµÄ»Æ½ð³Ç¹ÙÍø¸üС£
À´Ô´£º
https://cybersecuritynews.com/samsung-0-click-vulnerability-fixed/
4.2.5.ÐÂÐͰ²×¿¶ñÒâÈí¼þFireScamÀ´Ï®£¬ÊµÊ±ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢
ÐÂÐͰ²×¿¶ñÒâÈí¼þFireScamÕýÔÚͨ¹ýÄ£·Â¶íÂÞË¹ÒÆ¶¯Ó¦ÓÃÊг¡ RuStore µÄµöÓãÍøÕ¾£¬ÒÔTelegramÓ¦Óõĸ߼¶°æ±¾½øÐд«²¥¡£¸ù¾ÝÍþв¹ÜÀí¹«Ë¾CyfirmaµÄÑо¿£¬Î±×°³É RuStore µÄ¶ñÒâ GitHub Ò³ÃæÊ×ÏÈÌṩһ¸öÃûΪ GetAppsRu.apkµÄͶ·ÅÄ£¿é¡£¸ÃÄ£¿éʹÓÃDexGuard½øÐлìÏýÒÔ±ÜÃâ¼ì²â£¬²¢»ñȡȨÏÞÒÔʶ±ðÒѰ²×°µÄÓ¦ÓóÌÐò¡¢·ÃÎÊÉ豸´æ´¢²¢°²×°ÆäËû°ü¡£Ëæºó£¬ËüÌáÈ¡²¢°²×°Ö÷ÒªµÄ¶ñÒâÈí¼þÔØºÉ¡°Telegram Premium.apk¡±£¬¸ÃÓ¦ÓÃÇëÇó¼à¿ØÍ¨Öª¡¢¼ôÌù°åÊý¾Ý¡¢¶ÌÐź͵绰·þÎñµÈȨÏÞ¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/new-firescam-android-data-theft-malware-poses-as-telegram-premium-app/