°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

Ðû²¼Ê±¼ä 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ£¬£¬£¬£¬£¬°¢¸ùÍ¢»ú³¡Çå¾²¾¯Ô±£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°Ö°Ô±µÄСÎÒ˽¼Ò¼°²ÆÎñÊý¾Ýй¶¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳÎó²î»ñÈ¡ÁËPSAµÄÈËΪ¼Í¼£¬£¬£¬£¬£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𣬣¬£¬£¬£¬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£¡£¡£Ö»¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´ÓÍâÑóÕվɰ¢¸ùÍ¢¾³ÄÚÌᳫ£¬£¬£¬£¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬£¬£¬£¬£¬µ«PSAÒÑ·â±Õ²¿·ÖЧÀͲ¢Æô¶¯ÄÚ²¿ÍøÂçÇå¾²Ðû´«ÒÔÓ¦¶Ô¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬£¬£¬£¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£¡£¡£7Ô£¬£¬£¬£¬£¬°¢¸ùÍ¢µçÐÅÒ²±¨¸æÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£¡£¡£¡£4Ô£¬£¬£¬£¬£¬ºÚ¿ÍÉù³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£¡£¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAPÇå¾²Îó²îÒý·¢DoS¹¥»÷Σº¦£¬£¬£¬£¬£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ£¬£¬£¬£¬£¬ÍøÂçÉÏ¿ËÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒ飨LDAP£©µÄÇå¾²Îó²îʹÓóÌÐò£¬£¬£¬£¬£¬ÃûΪLDAPNightmare£¬£¬£¬£¬£¬¸Ã³ÌÐò¿ÉÄÜÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¡£¡£¸ÃÎó²îΪԽ½ç¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬±àºÅΪCVE - 2024 - 49113£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬Î¢Èí»¹ÐÞ¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑÏÖØÎó²îCVE - 2024 - 49112£¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£LDAPNightmareÎó²îʹÓóÌÐòͨ¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢ËÍÈ«ÐĽṹµÄDCE/RPCÇëÇ󣬣¬£¬£¬£¬µ¼ÖÂÍâµØÇå¾²»ú¹¹×ÓϵͳЧÀÍ£¨LSASS£©Í߽⣬£¬£¬£¬£¬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üÊ±Ç¿ÖÆÐ§ÀÍÖØÊÓÆô¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÏàͬµÄÎó²îʹÓÃÁ´£¬£¬£¬£¬£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬²¢ÊµÑé¼ì²â²½·¥ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRVÅÌÎÊ£¬£¬£¬£¬£¬ÒÔ±ÜÃâ±»¹¥»÷ÕßʹÓᣡ£¡£¡£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬£¬£¬£¬£¬µ¼ÖÂITЧÀÍÖÐÖ¹¡£¡£¡£¡£10ÔÂ10ÈÕ£¬£¬£¬£¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¿£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ£¬£¬£¬£¬£¬Ô±¹¤¡¢ÉÌҵͬ°é¼°ÉÙÁ¿¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý±»ÇÔÈ¡¡£¡£¡£¡£¾­ÓÉÊӲ죬£¬£¬£¬£¬¿¨Î÷Å·Ðû²¼ÁËÏêϸµÄÊý¾Ýй¶ϸ½Ú£¬£¬£¬£¬£¬°üÀ¨6456ÃûÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡¢1931ÃûÉÌҵͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍЧÀÍÐÅÏ¢¡£¡£¡£¡£Ö»¹Ü²¿·ÖÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎÊÂÎñÏà¹ØµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬µ«¿¨Î÷Å·ÌåÏÖ£¬£¬£¬£¬£¬ÆäÔ±¹¤¡¢ÏàÖúͬ°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¡£¡£¡£¿£¿£¿£¿¨Î÷Å·Ç¿µ÷£¬£¬£¬£¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬£¬£¬£¬£¬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£¡£¡£¡£ÔÚÓëÖ´·¨»ú¹¹¡¢×´Ê¦ºÍÇ徲ר¼ÒЭÉ̺󣬣¬£¬£¬£¬¿¨Î÷Å·¾öÒé²»ÓëÍøÂç·¸·¨·Ö×Ó¾ÙÐÐ̸ÅС£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬´ó´ó¶¼ÊÜÓ°ÏìµÄЧÀÍÒѻָ´Õý³££¬£¬£¬£¬£¬µ«ÈÔÓв¿·ÖЧÀÍÉÐδ»Ö¸´¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬£¬£¬£¬£¬µ«ÔÚͳһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçʹÓÃÁãÈÕÎó²îÌᳫȫÇò¹¥»÷


1ÔÂ7ÈÕ£¬£¬£¬£¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÖØ´ó£¬£¬£¬£¬£¬ËüʹÓÃÁãÈÕÎó²î¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓ×°±¸µÄÇå¾²Îó²î¡£¡£¡£¡£¾ÝChainxin X LabÑо¿Ö°Ô±¼à²â£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂ×îÏÈʹÓÃÒÔǰδ֪µÄÎó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856Îó²î¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸£¬£¬£¬£¬£¬ÌìÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬£¬£¬£¬£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬£¬£¬£¬£¬Õë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£¡£¡£ËüʹÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈËÎó²îÈö²¥µ½»¥ÁªÍøÌ»Â¶µÄ×°±¸£¬£¬£¬£¬£¬Ä¿µÄ°üÀ¨»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬£¬£¬£¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬£¬£¬£¬£¬PZTÏà»ú£¬£¬£¬£¬£¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬£¬£¬£¬£¬Lilin DVR£¬£¬£¬£¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓ×°±¸µÈ¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬£¬£¬£¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÏÂÁî½á¹¹¡£¡£¡£¡£X Lab±¨¸æ³Æ£¬£¬£¬£¬£¬ÆäDDoS¹¥»÷Ò»Á¬Ê±¼ä¶Ìµ«Ç¿¶È¸ß£¬£¬£¬£¬£¬Á÷Á¿Áè¼Ý100 Gbps¡£¡£¡£¡£Óû§Ó¦×°ÖÃ×îÐÂ×°±¸¸üУ¬£¬£¬£¬£¬½ûÓÃÔ¶³Ì»á¼û£¬£¬£¬£¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ±ÕÊ»§Æ¾Ö¤ÒÔ± £»£» £»£»£»£»£»¤×°±¸¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFIÎó²î£¬£¬£¬£¬£¬»òÖÂ×°±¸±»½ûÓÃ


1ÔÂ7ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÉúÎïÊÖÒÕ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢Ã÷±£´æBIOS/UEFIÎó²î£¬£¬£¬£¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃ×°±¸£¬£¬£¬£¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¡£¡£¹Ì¼þÇå¾²¹«Ë¾EclypsiumÔÚÆÊÎöÖз¢Ã÷£¬£¬£¬£¬£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾£¬£¬£¬£¬£¬ÇÒδͨ¹ýÇå¾²ÆôÏÂÊÖÒÕ¾ÙÐб £»£» £»£»£»£»£»¤£¬£¬£¬£¬£¬±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨BIOSд± £»£» £»£»£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£¡£¡£ÕâЩÎó²îÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯×°±¸µÄ´úÂ룬£¬£¬£¬£¬ÉõÖÁ¸Ä¶¯²âÊÔЧ¹û¡£¡£¡£¡£EclypsiumÇ¿µ÷£¬£¬£¬£¬£¬ÕâЩÎÊÌâ²»µ«ÏÞÓÚiSeq 100£¬£¬£¬£¬£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤Òµ×°±¸Ò²¿ÉÄܱ£´æÀàËÆÎÊÌâ¡£¡£¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡£¬£¬£¬£¬£¬µ«¹«Ë¾ÌåÏÖÆðÔ´ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»¾ßÓиßΣº¦¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬EclypsiumÖÒÑԳƣ¬£¬£¬£¬£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÈÝÒ×½ûÓøÃ×°±¸£¬£¬£¬£¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬£¬£¬£¬£¬ÓÉÓÚÆÆËð¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢Ã÷DNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬£¬£¬£¬£¬ÓÉÓÚËüÃǹØÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖ÷Òª¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖÒÑÔ£ºOracle WebLogicÓëMitel MiCollabϵͳ±£´æÑÏÖØÎó²î


1ÔÂ7ÈÕ£¬£¬£¬£¬£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³öÖÒÑÔ£¬£¬£¬£¬£¬ÒªÇóÔöǿϵͳ·À»¤£¬£¬£¬£¬£¬ÒÔÌá·ÀOracle WebLogic ServerºÍMitel MiCollabϵͳÖб£´æµÄÑÏÖØÎó²î¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢Ã÷±£´æÒªº¦Â·¾¶±éÀúÎó²î£¨CVE-2024-41713£©£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢»á¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬£¬£¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀúÎó²î£¨CVE-2024-55550£©ÔÊÐí¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰ»ñµÃÐÞ²¹£¬£¬£¬£¬£¬µ«Î´ÐÞ²¹µÄЧÀÍÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖΣº¦¡£¡£¡£¡£CISA½«ÕâÈý¸öÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖУ¬£¬£¬£¬£¬²¢±ê¼ÇΪ±»Æð¾¢Ê¹Ó㬣¬£¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö»ú¹¹ÔÚ»®×¼Ê±¼äÄÚ± £»£» £»£»£»£»£»¤ÆäÍøÂç¡£¡£¡£¡£ËäÈ»¸ÃÄ¿Â¼ÖØµã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹£¬£¬£¬£¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÇå¾²Îó²î£¬£¬£¬£¬£¬ÒÔ×èÖ¹ÕýÔÚ¾ÙÐеĹ¥»÷¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/