°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

Ðû²¼Ê±¼ä 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ£¬ £¬ £¬£¬°¢¸ùÍ¢»ú³¡Çå¾²¾¯Ô±£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷£¬ £¬ £¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°Ö°Ô±µÄСÎÒ˽¼Ò¼°²ÆÎñÊý¾Ýй¶¡£¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ£¬ £¬ £¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳÎó²î»ñÈ¡ÁËPSAµÄÈËΪ¼Í¼£¬ £¬ £¬£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𣬠£¬ £¬£¬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£¡£¡£¡£Ö»¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´ÓÍâÑóÕվɰ¢¸ùÍ¢¾³ÄÚÌᳫ£¬ £¬ £¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬ £¬ £¬£¬µ«PSAÒÑ·â±Õ²¿·ÖЧÀͲ¢Æô¶¯ÄÚ²¿ÍøÂçÇå¾²Ðû´«ÒÔÓ¦¶Ô¡£¡£¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬ £¬ £¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£¡£¡£¡£7Ô£¬ £¬ £¬£¬°¢¸ùÍ¢µçÐÅÒ²±¨¸æÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£¡£¡£¡£¡£4Ô£¬ £¬ £¬£¬ºÚ¿ÍÉù³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAPÇå¾²Îó²îÒý·¢DoS¹¥»÷Σº¦£¬ £¬ £¬£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ£¬ £¬ £¬£¬ÍøÂçÉÏ¿ËÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒ飨LDAP£©µÄÇå¾²Îó²îʹÓóÌÐò£¬ £¬ £¬£¬ÃûΪLDAPNightmare£¬ £¬ £¬£¬¸Ã³ÌÐò¿ÉÄÜÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²îΪԽ½ç¶ÁÈ¡Îó²î£¬ £¬ £¬£¬±àºÅΪCVE - 2024 - 49113£¬ £¬ £¬£¬CVSSÆÀ·ÖΪ7.5£¬ £¬ £¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£¡£Í¬Ê±£¬ £¬ £¬£¬Î¢Èí»¹ÐÞ¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑÏÖØÎó²îCVE - 2024 - 49112£¬ £¬ £¬£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ £¬ £¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£LDAPNightmareÎó²îʹÓóÌÐòͨ¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢ËÍÈ«ÐĽṹµÄDCE/RPCÇëÇó£¬ £¬ £¬£¬µ¼ÖÂÍâµØÇå¾²»ú¹¹×ÓϵͳЧÀÍ£¨LSASS£©Í߽⣬ £¬ £¬£¬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üÊ±Ç¿ÖÆÐ§ÀÍÖØÊÓÆô¡£¡£¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÏàͬµÄÎó²îʹÓÃÁ´£¬ £¬ £¬£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬ £¬ £¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬ £¬ £¬£¬²¢ÊµÑé¼ì²â²½·¥ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRVÅÌÎÊ£¬ £¬ £¬£¬ÒÔ±ÜÃâ±»¹¥»÷ÕßʹÓᣡ£¡£¡£¡£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ£¬ £¬ £¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬ £¬ £¬£¬µ¼ÖÂITЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£10ÔÂ10ÈÕ£¬ £¬ £¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬ £¬ £¬£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ£¬ £¬ £¬£¬Ô±¹¤¡¢ÉÌҵͬ°é¼°ÉÙÁ¿¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý±»ÇÔÈ¡¡£¡£¡£¡£¡£¾­ÓÉÊӲ죬 £¬ £¬£¬¿¨Î÷Å·Ðû²¼ÁËÏêϸµÄÊý¾Ýй¶ϸ½Ú£¬ £¬ £¬£¬°üÀ¨6456ÃûÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡¢1931ÃûÉÌҵͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍЧÀÍÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹Ü²¿·ÖÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎÊÂÎñÏà¹ØµÄ´¹ÂÚÓʼþ£¬ £¬ £¬£¬µ«¿¨Î÷Å·ÌåÏÖ£¬ £¬ £¬£¬ÆäÔ±¹¤¡¢ÏàÖúͬ°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿¨Î÷Å·Ç¿µ÷£¬ £¬ £¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬 £¬ £¬£¬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£¡£¡£¡£¡£ÔÚÓëÖ´·¨»ú¹¹¡¢×´Ê¦ºÍÇ徲ר¼ÒЭÉÌºó£¬ £¬ £¬£¬¿¨Î÷Å·¾öÒé²»ÓëÍøÂç·¸·¨·Ö×Ó¾ÙÐÐ̸ÅС£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬ £¬£¬´ó´ó¶¼ÊÜÓ°ÏìµÄЧÀÍÒѻָ´Õý³££¬ £¬ £¬£¬µ«ÈÔÓв¿·ÖЧÀÍÉÐδ»Ö¸´¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ £¬ £¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬 £¬ £¬£¬µ«ÔÚͳһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçʹÓÃÁãÈÕÎó²îÌᳫȫÇò¹¥»÷


1ÔÂ7ÈÕ£¬ £¬ £¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÖØ´ó£¬ £¬ £¬£¬ËüʹÓÃÁãÈÕÎó²î¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓ×°±¸µÄÇå¾²Îó²î¡£¡£¡£¡£¡£¾ÝChainxin X LabÑо¿Ö°Ô±¼à²â£¬ £¬ £¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂ×îÏÈʹÓÃÒÔǰδ֪µÄÎó²î£¬ £¬ £¬£¬ÆäÖаüÀ¨Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856Îó²î¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸£¬ £¬ £¬£¬ÌìÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬ £¬ £¬£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬ £¬ £¬£¬Õë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£¡£¡£¡£ËüʹÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈËÎó²îÈö²¥µ½»¥ÁªÍøÌ»Â¶µÄ×°±¸£¬ £¬ £¬£¬Ä¿µÄ°üÀ¨»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬ £¬ £¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬ £¬ £¬£¬PZTÏà»ú£¬ £¬ £¬£¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬ £¬ £¬£¬Lilin DVR£¬ £¬ £¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓ×°±¸µÈ¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿£¿£¿£¿£¿£¿é£¬ £¬ £¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬ £¬ £¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÏÂÁî½á¹¹¡£¡£¡£¡£¡£X Lab±¨¸æ³Æ£¬ £¬ £¬£¬ÆäDDoS¹¥»÷Ò»Á¬Ê±¼ä¶Ìµ«Ç¿¶È¸ß£¬ £¬ £¬£¬Á÷Á¿Áè¼Ý100 Gbps¡£¡£¡£¡£¡£Óû§Ó¦×°ÖÃ×îÐÂ×°±¸¸üУ¬ £¬ £¬£¬½ûÓÃÔ¶³Ì»á¼û£¬ £¬ £¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ±ÕÊ»§Æ¾Ö¤ÒÔ±£»£»£»£»£»£»£»¤×°±¸¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFIÎó²î£¬ £¬ £¬£¬»òÖÂ×°±¸±»½ûÓÃ


1ÔÂ7ÈÕ£¬ £¬ £¬£¬ÃÀ¹úÉúÎïÊÖÒÕ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢Ã÷±£´æBIOS/UEFIÎó²î£¬ £¬ £¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃ×°±¸£¬ £¬ £¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¡£¡£¡£¹Ì¼þÇå¾²¹«Ë¾EclypsiumÔÚÆÊÎöÖз¢Ã÷£¬ £¬ £¬£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾£¬ £¬ £¬£¬ÇÒδͨ¹ýÇå¾²ÆôÏÂÊÖÒÕ¾ÙÐб£»£»£»£»£»£»£»¤£¬ £¬ £¬£¬±£´æ¶à¸öÎó²î£¬ £¬ £¬£¬°üÀ¨BIOSд±£»£»£»£»£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£¡£¡£¡£ÕâЩÎó²îÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯×°±¸µÄ´úÂ룬 £¬ £¬£¬ÉõÖÁ¸Ä¶¯²âÊÔЧ¹û¡£¡£¡£¡£¡£EclypsiumÇ¿µ÷£¬ £¬ £¬£¬ÕâЩÎÊÌâ²»µ«ÏÞÓÚiSeq 100£¬ £¬ £¬£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤Òµ×°±¸Ò²¿ÉÄܱ£´æÀàËÆÎÊÌâ¡£¡£¡£¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡£¡£¡£¡£¡£¬ £¬ £¬£¬µ«¹«Ë¾ÌåÏÖÆðÔ´ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»¾ßÓиßΣº¦¡£¡£¡£¡£¡£È»¶ø£¬ £¬ £¬£¬EclypsiumÖÒÑԳƣ¬ £¬ £¬£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÈÝÒ×½ûÓøÃ×°±¸£¬ £¬ £¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬ £¬ £¬£¬ÓÉÓÚÆÆËð¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢Ã÷DNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬ £¬ £¬£¬ÓÉÓÚËüÃǹØÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖ÷Òª¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖÒÑÔ£ºOracle WebLogicÓëMitel MiCollabϵͳ±£´æÑÏÖØÎó²î


1ÔÂ7ÈÕ£¬ £¬ £¬£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³öÖÒÑÔ£¬ £¬ £¬£¬ÒªÇóÔöǿϵͳ·À»¤£¬ £¬ £¬£¬ÒÔÌá·ÀOracle WebLogic ServerºÍMitel MiCollabϵͳÖб£´æµÄÑÏÖØÎó²î¡£¡£¡£¡£¡£ÆäÖУ¬ £¬ £¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢Ã÷±£´æÒªº¦Â·¾¶±éÀúÎó²î£¨CVE-2024-41713£©£¬ £¬ £¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢»á¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬ £¬ £¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£¡£Í¬Ê±£¬ £¬ £¬£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀúÎó²î£¨CVE-2024-55550£©ÔÊÐí¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬ £¬ £¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰ»ñµÃÐÞ²¹£¬ £¬ £¬£¬µ«Î´ÐÞ²¹µÄЧÀÍÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖΣº¦¡£¡£¡£¡£¡£CISA½«ÕâÈý¸öÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖУ¬ £¬ £¬£¬²¢±ê¼ÇΪ±»Æð¾¢Ê¹Ó㬠£¬ £¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö»ú¹¹ÔÚ»®×¼Ê±¼äÄÚ±£»£»£»£»£»£»£»¤ÆäÍøÂç¡£¡£¡£¡£¡£ËäÈ»¸ÃÄ¿Â¼ÖØµã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹£¬ £¬ £¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÇå¾²Îó²î£¬ £¬ £¬£¬ÒÔ×èÖ¹ÕýÔÚ¾ÙÐеĹ¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/