°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

Ðû²¼Ê±¼ä 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ£¬£¬£¬£¬°¢¸ùÍ¢»ú³¡Çå¾²¾¯Ô±£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°Ö°Ô±µÄСÎÒ˽¼Ò¼°²ÆÎñÊý¾Ýй¶¡£¡£¾ÝÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳÎó²î»ñÈ¡ÁËPSAµÄÈËΪ¼Í¼£¬£¬£¬£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𣬣¬£¬£¬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£Ö»¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´ÓÍâÑóÕվɰ¢¸ùÍ¢¾³ÄÚÌᳫ£¬£¬£¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬£¬£¬£¬µ«PSAÒÑ·â±Õ²¿·ÖЧÀͲ¢Æô¶¯ÄÚ²¿ÍøÂçÇå¾²Ðû´«ÒÔÓ¦¶Ô¡£¡£±ðµÄ£¬£¬£¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬£¬£¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£7Ô£¬£¬£¬£¬°¢¸ùÍ¢µçÐÅÒ²±¨¸æÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£¡£4Ô£¬£¬£¬£¬ºÚ¿ÍÉù³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAPÇå¾²Îó²îÒý·¢DoS¹¥»÷Σº¦£¬£¬£¬£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ£¬£¬£¬£¬ÍøÂçÉÏ¿ËÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒ飨LDAP£©µÄÇå¾²Îó²îʹÓóÌÐò£¬£¬£¬£¬ÃûΪLDAPNightmare£¬£¬£¬£¬¸Ã³ÌÐò¿ÉÄÜÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¸ÃÎó²îΪԽ½ç¶ÁÈ¡Îó²î£¬£¬£¬£¬±àºÅΪCVE - 2024 - 49113£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£¡£Í¬Ê±£¬£¬£¬£¬Î¢Èí»¹ÐÞ¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑÏÖØÎó²îCVE - 2024 - 49112£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£LDAPNightmareÎó²îʹÓóÌÐòͨ¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢ËÍÈ«ÐĽṹµÄDCE/RPCÇëÇ󣬣¬£¬£¬µ¼ÖÂÍâµØÇå¾²»ú¹¹×ÓϵͳЧÀÍ£¨LSASS£©Í߽⣬£¬£¬£¬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üÊ±Ç¿ÖÆÐ§ÀÍÖØÊÓÆô¡£¡£±ðµÄ£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÏàͬµÄÎó²îʹÓÃÁ´£¬£¬£¬£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¬Ã¦ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬²¢ÊµÑé¼ì²â²½·¥ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRVÅÌÎÊ£¬£¬£¬£¬ÒÔ±ÜÃâ±»¹¥»÷ÕßʹÓᣡ£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ£¬£¬£¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬£¬£¬£¬µ¼ÖÂITЧÀÍÖÐÖ¹¡£¡£10ÔÂ10ÈÕ£¬£¬£¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¡£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ£¬£¬£¬£¬Ô±¹¤¡¢ÉÌҵͬ°é¼°ÉÙÁ¿¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý±»ÇÔÈ¡¡£¡£¾­ÓÉÊӲ죬£¬£¬£¬¿¨Î÷Å·Ðû²¼ÁËÏêϸµÄÊý¾Ýй¶ϸ½Ú£¬£¬£¬£¬°üÀ¨6456ÃûÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡¢1931ÃûÉÌҵͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍЧÀÍÐÅÏ¢¡£¡£Ö»¹Ü²¿·ÖÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎÊÂÎñÏà¹ØµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬µ«¿¨Î÷Å·ÌåÏÖ£¬£¬£¬£¬ÆäÔ±¹¤¡¢ÏàÖúͬ°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¡£¿£¿£¿¨Î÷Å·Ç¿µ÷£¬£¬£¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬£¬£¬£¬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£¡£ÔÚÓëÖ´·¨»ú¹¹¡¢×´Ê¦ºÍÇ徲ר¼ÒЭÉ̺󣬣¬£¬£¬¿¨Î÷Å·¾öÒé²»ÓëÍøÂç·¸·¨·Ö×Ó¾ÙÐÐ̸ÅС£¡£ÏÖÔÚ£¬£¬£¬£¬´ó´ó¶¼ÊÜÓ°ÏìµÄЧÀÍÒѻָ´Õý³££¬£¬£¬£¬µ«ÈÔÓв¿·ÖЧÀÍÉÐδ»Ö¸´¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬£¬£¬£¬µ«ÔÚͳһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçʹÓÃÁãÈÕÎó²îÌᳫȫÇò¹¥»÷


1ÔÂ7ÈÕ£¬£¬£¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÖØ´ó£¬£¬£¬£¬ËüʹÓÃÁãÈÕÎó²î¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓ×°±¸µÄÇå¾²Îó²î¡£¡£¾ÝChainxin X LabÑо¿Ö°Ô±¼à²â£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂ×îÏÈʹÓÃÒÔǰδ֪µÄÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856Îó²î¡£¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸£¬£¬£¬£¬ÌìÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬£¬£¬£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬£¬£¬£¬Õë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£ËüʹÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈËÎó²îÈö²¥µ½»¥ÁªÍøÌ»Â¶µÄ×°±¸£¬£¬£¬£¬Ä¿µÄ°üÀ¨»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬£¬£¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬£¬£¬£¬PZTÏà»ú£¬£¬£¬£¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬£¬£¬£¬Lilin DVR£¬£¬£¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓ×°±¸µÈ¡£¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿£¿£¿é£¬£¬£¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬£¬£¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÏÂÁî½á¹¹¡£¡£X Lab±¨¸æ³Æ£¬£¬£¬£¬ÆäDDoS¹¥»÷Ò»Á¬Ê±¼ä¶Ìµ«Ç¿¶È¸ß£¬£¬£¬£¬Á÷Á¿Áè¼Ý100 Gbps¡£¡£Óû§Ó¦×°ÖÃ×îÐÂ×°±¸¸üУ¬£¬£¬£¬½ûÓÃÔ¶³Ì»á¼û£¬£¬£¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ±ÕÊ»§Æ¾Ö¤ÒÔ±£»£»£»£»£»¤×°±¸¡£¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFIÎó²î£¬£¬£¬£¬»òÖÂ×°±¸±»½ûÓÃ


1ÔÂ7ÈÕ£¬£¬£¬£¬ÃÀ¹úÉúÎïÊÖÒÕ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢Ã÷±£´æBIOS/UEFIÎó²î£¬£¬£¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃ×°±¸£¬£¬£¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¹Ì¼þÇå¾²¹«Ë¾EclypsiumÔÚÆÊÎöÖз¢Ã÷£¬£¬£¬£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾£¬£¬£¬£¬ÇÒδͨ¹ýÇå¾²ÆôÏÂÊÖÒÕ¾ÙÐб£»£»£»£»£»¤£¬£¬£¬£¬±£´æ¶à¸öÎó²î£¬£¬£¬£¬°üÀ¨BIOSд±£»£»£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£ÕâЩÎó²îÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯×°±¸µÄ´úÂ룬£¬£¬£¬ÉõÖÁ¸Ä¶¯²âÊÔЧ¹û¡£¡£EclypsiumÇ¿µ÷£¬£¬£¬£¬ÕâЩÎÊÌâ²»µ«ÏÞÓÚiSeq 100£¬£¬£¬£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤Òµ×°±¸Ò²¿ÉÄܱ£´æÀàËÆÎÊÌâ¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡£¬£¬£¬£¬µ«¹«Ë¾ÌåÏÖÆðÔ´ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»¾ßÓиßΣº¦¡£¡£È»¶ø£¬£¬£¬£¬EclypsiumÖÒÑԳƣ¬£¬£¬£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÈÝÒ×½ûÓøÃ×°±¸£¬£¬£¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬£¬£¬£¬ÓÉÓÚÆÆËð¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£±ðµÄ£¬£¬£¬£¬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢Ã÷DNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬£¬£¬£¬ÓÉÓÚËüÃǹØÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖ÷Òª¡£¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖÒÑÔ£ºOracle WebLogicÓëMitel MiCollabϵͳ±£´æÑÏÖØÎó²î


1ÔÂ7ÈÕ£¬£¬£¬£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³öÖÒÑÔ£¬£¬£¬£¬ÒªÇóÔöǿϵͳ·À»¤£¬£¬£¬£¬ÒÔÌá·ÀOracle WebLogic ServerºÍMitel MiCollabϵͳÖб£´æµÄÑÏÖØÎó²î¡£¡£ÆäÖУ¬£¬£¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢Ã÷±£´æÒªº¦Â·¾¶±éÀúÎó²î£¨CVE-2024-41713£©£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢»á¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬£¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£Í¬Ê±£¬£¬£¬£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀúÎó²î£¨CVE-2024-55550£©ÔÊÐí¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¬£¬£¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£±ðµÄ£¬£¬£¬£¬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰ»ñµÃÐÞ²¹£¬£¬£¬£¬µ«Î´ÐÞ²¹µÄЧÀÍÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖΣº¦¡£¡£CISA½«ÕâÈý¸öÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖУ¬£¬£¬£¬²¢±ê¼ÇΪ±»Æð¾¢Ê¹Ó㬣¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö»ú¹¹ÔÚ»®×¼Ê±¼äÄÚ±£»£»£»£»£»¤ÆäÍøÂç¡£¡£ËäÈ»¸ÃÄ¿Â¼ÖØµã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹£¬£¬£¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÇå¾²Îó²î£¬£¬£¬£¬ÒÔ×èÖ¹ÕýÔÚ¾ÙÐеĹ¥»÷¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/