°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ
Ðû²¼Ê±¼ä 2025-01-081. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ
1ÔÂ7ÈÕ£¬£¬£¬°¢¸ùÍ¢»ú³¡Çå¾²¾¯Ô±£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷£¬£¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°Ö°Ô±µÄСÎÒ˽¼Ò¼°²ÆÎñÊý¾Ýй¶¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ£¬£¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳÎó²î»ñÈ¡ÁËPSAµÄÈËΪ¼Í¼£¬£¬£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𣬣¬£¬ÕâЩڲÆÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£¡£¡£Ö»¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´ÓÍâÑóÕվɰ¢¸ùÍ¢¾³ÄÚÌᳫ£¬£¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬£¬£¬µ«PSAÒÑ·â±Õ²¿·ÖЧÀͲ¢Æô¶¯ÄÚ²¿ÍøÂçÇå¾²Ðû´«ÒÔÓ¦¶Ô¡£¡£¡£¡£±ðµÄ£¬£¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬£¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£¡£¡£7Ô£¬£¬£¬°¢¸ùÍ¢µçÐÅÒ²±¨¸æÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£¡£¡£¡£4Ô£¬£¬£¬ºÚ¿ÍÉù³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£¡£¡£
https://therecord.media/hackers-target-airport-security-payroll
2. LDAPÇå¾²Îó²îÒý·¢DoS¹¥»÷Σº¦£¬£¬£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾
1ÔÂ3ÈÕ£¬£¬£¬ÍøÂçÉÏ¿ËÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼»á¼ûÐÒ飨LDAP£©µÄÇå¾²Îó²îʹÓóÌÐò£¬£¬£¬ÃûΪLDAPNightmare£¬£¬£¬¸Ã³ÌÐò¿ÉÄÜÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¡£¡£¸ÃÎó²îΪԽ½ç¶ÁÈ¡Îó²î£¬£¬£¬±àºÅΪCVE - 2024 - 49113£¬£¬£¬CVSSÆÀ·ÖΪ7.5£¬£¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£Í¬Ê±£¬£¬£¬Î¢Èí»¹ÐÞ¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑÏÖØÎó²îCVE - 2024 - 49112£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£LDAPNightmareÎó²îʹÓóÌÐòͨ¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢ËÍÈ«ÐĽṹµÄDCE/RPCÇëÇ󣬣¬£¬µ¼ÖÂÍâµØÇå¾²»ú¹¹×ÓϵͳЧÀÍ£¨LSASS£©Í߽⣬£¬£¬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üÊ±Ç¿ÖÆÐ§ÀÍÖØÊÓÆô¡£¡£¡£¡£±ðµÄ£¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÏàͬµÄÎó²îʹÓÃÁ´£¬£¬£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬£¬£¬²¢ÊµÑé¼ì²â²½·¥ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRVÅÌÎÊ£¬£¬£¬ÒÔ±ÜÃâ±»¹¥»÷ÕßʹÓᣡ£¡£¡£
https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html
3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬8500ÈËÊý¾ÝÔâй¶
1ÔÂ7ÈÕ£¬£¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬£¬£¬µ¼ÖÂITЧÀÍÖÐÖ¹¡£¡£¡£¡£10ÔÂ10ÈÕ£¬£¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¿£¿£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ£¬£¬£¬Ô±¹¤¡¢ÉÌҵͬ°é¼°ÉÙÁ¿¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý±»ÇÔÈ¡¡£¡£¡£¡£¾ÓÉÊӲ죬£¬£¬¿¨Î÷Å·Ðû²¼ÁËÏêϸµÄÊý¾Ýй¶ϸ½Ú£¬£¬£¬°üÀ¨6456ÃûÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡¢1931ÃûÉÌҵͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍЧÀÍÐÅÏ¢¡£¡£¡£¡£Ö»¹Ü²¿·ÖÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎÊÂÎñÏà¹ØµÄ´¹ÂÚÓʼþ£¬£¬£¬µ«¿¨Î÷Å·ÌåÏÖ£¬£¬£¬ÆäÔ±¹¤¡¢ÏàÖúͬ°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¡£¡£¡£¿£¿£¿£¿£¿¨Î÷Å·Ç¿µ÷£¬£¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬£¬£¬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£¡£¡£¡£ÔÚÓëÖ´·¨»ú¹¹¡¢×´Ê¦ºÍÇ徲ר¼ÒÐÉ̺󣬣¬£¬¿¨Î÷Å·¾öÒé²»ÓëÍøÂç·¸·¨·Ö×Ó¾ÙÐÐ̸ÅС£¡£¡£¡£ÏÖÔÚ£¬£¬£¬´ó´ó¶¼ÊÜÓ°ÏìµÄЧÀÍÒѻָ´Õý³££¬£¬£¬µ«ÈÔÓв¿·ÖЧÀÍÉÐδ»Ö¸´¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬£¬£¬µ«ÔÚͳһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/
4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçʹÓÃÁãÈÕÎó²îÌᳫȫÇò¹¥»÷
1ÔÂ7ÈÕ£¬£¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÖØ´ó£¬£¬£¬ËüʹÓÃÁãÈÕÎó²î¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓ×°±¸µÄÇå¾²Îó²î¡£¡£¡£¡£¾ÝChainxin X LabÑо¿Ö°Ô±¼à²â£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂ×îÏÈʹÓÃÒÔǰδ֪µÄÎó²î£¬£¬£¬ÆäÖаüÀ¨Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856Îó²î¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸£¬£¬£¬ÌìÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬£¬£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬£¬£¬Õë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£¡£¡£ËüʹÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈËÎó²îÈö²¥µ½»¥ÁªÍøÌ»Â¶µÄ×°±¸£¬£¬£¬Ä¿µÄ°üÀ¨»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬£¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬£¬£¬PZTÏà»ú£¬£¬£¬¿ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬£¬£¬Lilin DVR£¬£¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓ×°±¸µÈ¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿£¿£¿£¿£¿é£¬£¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬£¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÏÂÁî½á¹¹¡£¡£¡£¡£X Lab±¨¸æ³Æ£¬£¬£¬ÆäDDoS¹¥»÷Ò»Á¬Ê±¼ä¶Ìµ«Ç¿¶È¸ß£¬£¬£¬Á÷Á¿Áè¼Ý100 Gbps¡£¡£¡£¡£Óû§Ó¦×°ÖÃ×îÐÂ×°±¸¸üУ¬£¬£¬½ûÓÃÔ¶³Ì»á¼û£¬£¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ±ÕÊ»§Æ¾Ö¤ÒÔ±£»£»£»£»£»¤×°±¸¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/
5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFIÎó²î£¬£¬£¬»òÖÂ×°±¸±»½ûÓÃ
1ÔÂ7ÈÕ£¬£¬£¬ÃÀ¹úÉúÎïÊÖÒÕ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢Ã÷±£´æBIOS/UEFIÎó²î£¬£¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃ×°±¸£¬£¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¡£¡£¹Ì¼þÇå¾²¹«Ë¾EclypsiumÔÚÆÊÎöÖз¢Ã÷£¬£¬£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾£¬£¬£¬ÇÒδͨ¹ýÇå¾²ÆôÏÂÊÖÒÕ¾ÙÐб£»£»£»£»£»¤£¬£¬£¬±£´æ¶à¸öÎó²î£¬£¬£¬°üÀ¨BIOSд±£»£»£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£¡£¡£ÕâЩÎó²îÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯×°±¸µÄ´úÂ룬£¬£¬ÉõÖÁ¸Ä¶¯²âÊÔЧ¹û¡£¡£¡£¡£EclypsiumÇ¿µ÷£¬£¬£¬ÕâЩÎÊÌâ²»µ«ÏÞÓÚiSeq 100£¬£¬£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤Òµ×°±¸Ò²¿ÉÄܱ£´æÀàËÆÎÊÌâ¡£¡£¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡£¡£¡£¡£¬£¬£¬µ«¹«Ë¾ÌåÏÖÆðÔ´ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»¾ßÓиßΣº¦¡£¡£¡£¡£È»¶ø£¬£¬£¬EclypsiumÖÒÑԳƣ¬£¬£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÈÝÒ×½ûÓøÃ×°±¸£¬£¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬£¬£¬ÓÉÓÚÆÆËð¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£±ðµÄ£¬£¬£¬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢Ã÷DNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬£¬£¬ÓÉÓÚËüÃǹØÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖ÷Òª¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/
6. CISAÖÒÑÔ£ºOracle WebLogicÓëMitel MiCollabϵͳ±£´æÑÏÖØÎó²î
1ÔÂ7ÈÕ£¬£¬£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³öÖÒÑÔ£¬£¬£¬ÒªÇóÔöǿϵͳ·À»¤£¬£¬£¬ÒÔÌá·ÀOracle WebLogic ServerºÍMitel MiCollabϵͳÖб£´æµÄÑÏÖØÎó²î¡£¡£¡£¡£ÆäÖУ¬£¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢Ã÷±£´æÒªº¦Â·¾¶±éÀúÎó²î£¨CVE-2024-41713£©£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾ÊÚȨµÄÖÎÀí²Ù×÷²¢»á¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£Í¬Ê±£¬£¬£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀúÎó²î£¨CVE-2024-55550£©ÔÊÐí¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£¡£¡£±ðµÄ£¬£¬£¬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰ»ñµÃÐÞ²¹£¬£¬£¬µ«Î´ÐÞ²¹µÄЧÀÍÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖΣº¦¡£¡£¡£¡£CISA½«ÕâÈý¸öÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖУ¬£¬£¬²¢±ê¼ÇΪ±»Æð¾¢Ê¹Ó㬣¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö»ú¹¹ÔÚ»®×¼Ê±¼äÄÚ±£»£»£»£»£»¤ÆäÍøÂç¡£¡£¡£¡£ËäÈ»¸ÃÄ¿Â¼ÖØµã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹£¬£¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÇå¾²Îó²î£¬£¬£¬ÒÔ×èÖ¹ÕýÔÚ¾ÙÐеĹ¥»÷¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ