΢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î

Ðû²¼Ê±¼ä 2024-01-10

1¡¢Î¢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î


¾ÝýÌå1ÔÂ9ÈÕ±¨µÀ£¬£¬£¬ £¬£¬ £¬Î¢ÈíÐû²¼ÁË2024Äê1Ô·ݵÄÖܶþ²¹¶¡£¬£¬£¬ £¬£¬ £¬×ܼÆÐÞ¸´ÁË49¸öÎó²î¡£¡£¡£¡£±¾ÔÂÐÞ¸´µÄ½ÏÁ¿ÓÐȤµÄÎó²îÊÇOfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-20677£©£¬£¬£¬ £¬£¬ £¬¿É±»ÓÃÀ´Í¨¹ýʹÓÃǶÈëʽFBX 3DÄ£×ÓÎļþ½¨Éè¶ñÒâÖÆ×÷µÄOfficeÎĵµ£¬£¬£¬ £¬£¬ £¬À´Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ÁíÒ»¸öÊÇWindows KerberosÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-20674£©£¬£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýMITM¹¥»÷»òÆäËûÍâµØÍøÂçÓÕÆ­ÊÖÒÕÀ´Ê¹ÓôËÎó²î£¬£¬£¬ £¬£¬ £¬Ïò¿Í»§¶Ë·¢ËͶñÒâKerberosÐÂÎÅ£¬£¬£¬ £¬£¬ £¬½«×Ô¼ºÎ±×°³ÉKerberosÉí·ÝÑé֤ЧÀÍÆ÷¡£¡£¡£¡£


2¡¢LockBitÍþвҪ¹ûÕæCapital HealthÔ¼7TBµÄÊý¾Ý


¾Ý1ÔÂ9ÈÕ±¨µÀ£¬£¬£¬ £¬£¬ £¬LockBitÉù³ÆÒÑÈëÇÖCapital Health£¬£¬£¬ £¬£¬ £¬²¢ÍþвҪй¶±»µÁÊý¾ÝºÍ̸ÅÐ̸Ìì¼Í¼¡£¡£¡£¡£2023Äê11Ô£¬£¬£¬ £¬£¬ £¬Capital HealthÔÚÔâµ½¹¥»÷ºóϵͳ·ºÆðÖÐÖ¹£¬£¬£¬ £¬£¬ £¬²¢ÌåÏÖ¸ÃÊÂÎñ½«Ó°ÏìÆäÔËÓªÖÁÉÙÒ»ÖÜ¡£¡£¡£¡£LockBitÔÚ8ÈÕ½«¸ÃÒ½ÁÆ»ú¹¹ÁÐÈëÆäÍøÕ¾£¬£¬£¬ £¬£¬ £¬Éù³ÆÇÔÈ¡ÁË7 TBµÄÒ½ÁÆÊý¾Ý¡£¡£¡£¡£»£»£»£»¹Íþв³ÆÈôÊǸûú¹¹Î´ÄÜÖª×ãËûÃǵÄÒªÇ󣬣¬£¬ £¬£¬ £¬ËûÃǾͻáÔÚ1ÔÂ9ÈÕй¶ÕâЩÊý¾Ý¡£¡£¡£¡£


3¡¢¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½Ransomexx¹¥»÷Áè¼Ý2GBÊý¾Ýй¶


1ÔÂ8ÈÕ±¨µÀ³Æ£¬£¬£¬ £¬£¬ £¬·ÇÖÞ×î´óµÄº½¿Õ¹«Ë¾Ö®Ò»¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½ÁËRansomexxÀÕË÷ÍÅ»ïµÄ¹¥»÷¡£¡£¡£¡£¹¥»÷ÕßÔÚ°µÍøÐû²¼Á˾ݳÆÊǴӸú½¿Õ¹«Ë¾ÇÔÈ¡µÄÁè¼Ý2 GBÊý¾Ý£¬£¬£¬ £¬£¬ £¬Êý¾ÝÊ÷ÏÔʾ£¬£¬£¬ £¬£¬ £¬°üÀ¨Ê¹ʱ¨¸æ¡¢»¤ÕÕ¸´Ó¡¼þºÍÖÖÖÖ¿ÕÄѱ¨¸æ¡£¡£¡£¡£¹¥»÷ÕßÔÚÐû²¼Ìû×Óʱ£¬£¬£¬ £¬£¬ £¬Ê×ÏÈÉÏ´«ÁËÒ»ÕžݳÆÊÇ¿ÏÄáÑǺ½¿Õ¹«Ë¾Ò»¼Ü·É»úÒýÇæÊÜËðµÄͼƬ£¬£¬£¬ £¬£¬ £¬Êý¾ÝÑù±¾Öл¹°üÀ¨Ò»Ð©ÎÞ¹éÊôϵͳµÄÖÖÖÖÃÜÂë¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬ £¬¿ÏÄáÑǺ½¿Õ¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£


4¡¢Fortinet·¢Ã÷ͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ»î¶¯


FortinetÔÚ1ÔÂ8ÈÕÅû¶ÁËͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈ»áÈëÇÖYouTubeµÄÕÊ»§£¬£¬£¬ £¬£¬ £¬²¢ÉÏ´«Î±×°³É¹²ÏíÆÆ½âÈí¼þµÄÊÓÆµ¡£¡£¡£¡£È«ÐÄÖÆ×÷µÄ×°ÖÃZIPÎļþÊÇ·Ö·¢payloadµÄÓÕ¶ü£¬£¬£¬ £¬£¬ £¬ËüʹÓÃÁËÓû§×°ÖÃÓ¦ÓõÄÒâͼ£¬£¬£¬ £¬£¬ £¬´ÙʹÓû§¾ø²»ÓÌÔ¥ËùÔÚ»÷×°ÖÃÎļþ¡£¡£¡£¡£Õû¸ö»î¶¯ÖеÄURLÀ´×Ô¿ªÔ´ÍøÕ¾£¬£¬£¬ £¬£¬ £¬Ä¿µÄÊÇÏ÷ÈõÓû§µÄÇå¾²Òâʶ¡£¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö˽ÓÐ.NET¼ÓÔØ³ÌÐò£¬£¬£¬ £¬£¬ £¬Ëü¾ßÓÐÇéÐμì²é¡¢ÖÖÖÖAnti-VMºÍ·´µ÷ÊÔ¹¦Ð§¡£¡£¡£¡£


5¡¢É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿Ãô¸ÐÊý¾Ýй¶¿ÉÓÃÓÚÄÚÍø¹¥»÷


ýÌå1ÔÂ8Èճƣ¬£¬£¬ £¬£¬ £¬É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿(MIM)µÄÇéÐÎÎļþ(env.)й¶³¤´ï15¸öÔ¡£¡£¡£¡£Ì»Â¶µÄenv.Éæ¼°Á˶àÖÖÀàÐ͵ÄÊý¾Ý¿âƾ֤¡¢Óʼþƾ֤ºÍÊý¾Ý¼ÓÃÜÃÜÔ¿£¬£¬£¬ £¬£¬ £¬ÀýÈçSMTPƾ֤¡¢Laravel APP_Key¡¢MySQLºÍRedisÊý¾Ý¿âµÄƾ֤µÈ¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢¿É±»¹¥»÷ÕßÓÃÓÚÔڸò¿ÏµÍ³ÄÚ¾ÙÐкáÏòÒÆ¶¯£¬£¬£¬ £¬£¬ £¬²¢µ¼ÖÂÕÊ»§½ÓÊܺÍÀÕË÷¹¥»÷µÈÖÖÖÖ¹¥»÷¡£¡£¡£¡£¸ÃÎļþÔÚ2022Äê3ÔÂÊ״α»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬£¬£¬ £¬£¬ £¬ÏÖÔÚÒѱ»±£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£


6¡¢Ñо¿Ö°Ô±Ðû²¼2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ


1ÔÂ3ÈÕ£¬£¬£¬ £¬£¬ £¬CisoµÄÑо¿Ö°Ô±Jerry GamblinÐû²¼ÁË2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬ £¬×èÖ¹2023Äê¹²Ðû²¼ÁË28902¸öCVE£¬£¬£¬ £¬£¬ £¬±È2022ÄêµÄ25081¸öCVEÔöÌíÁË15%ÒÔÉÏ¡£¡£¡£¡£Æ½¾ùÌìÌìÐû²¼79.18¸ö¡£¡£¡£¡£10ÔÂÊÇÐû²¼CVE×î¶àµÄÔ·Ý£¬£¬£¬ £¬£¬ £¬¹²2690¸ö£¬£¬£¬ £¬£¬ £¬Õ¼ÕûÄêµÄ9.3%¡£¡£¡£¡£´ÓÑÏÖØË®Æ½À´¿´£¬£¬£¬ £¬£¬ £¬2023ÄêCVEµÄƽ¾ùCVSSÆÀ·ÖΪ7.12£¬£¬£¬ £¬£¬ £¬ÆäÖÐ36¸öÎó²îµÄÆÀ·ÖΪ10.0¡£¡£¡£¡£×î³£·ÖÅɵij£¼ûÎó²îö¾Ù(CWE)±êʶ·ûÀàÐÍÊÇCWE-79£¬£¬£¬ £¬£¬ £¬¼´ÍøÒ³ÌìÉúʱ´úÊäÈëµÄÖкͲ»µ±£¬£¬£¬ £¬£¬ £¬Ò²³ÆÎªXSS£¬£¬£¬ £¬£¬ £¬È¥ÄêÓÐ4100¶à¸öCVE±»·ÖÀàΪXSSÎó²î¡£¡£¡£¡£