CorsairÈ·ÈÏÊÇK100¼üÅ̹̼þÖеÄBugµ¼ÖÂ×Ô¶¯´ò×Ö
°ä²¼¹¦·ò 2022-12-23
¾ÝýÌå12ÔÂ21ÈÕ±¨Â·£¬CorsairÒÑÈ·ÈÏÆäK100¼üÅ̹̼þÖеÄÒ»¸öBug£¬µ¼ÖÂÏÈǰÊäÈëµÄÎı¾ÔÚ¼¸Ììºó×Ô¶¯ÊäÈëµ½ÀûÓ÷¨Ê½ÖУ¬¶ø²»ÊǶñÒâÈí¼þµÄÔÒò¡£Õâ¸öÎÊÌâÓÚ2022Äê8Ô³õ´ÎÔÚCorsairÂÛ̳ÉÏÅû¶£¬Óû§²»°²ÊÇijÖÖ´ó¾ÖµÄ¼üÅ̼ͼ·¨Ê½»ò¶ñÒâÈí¼þµ¼Öµġ£¾ÝϤ£¬¸ÃÎÊÌâÔ´ÓÚºê¼Í¼ְÄÜÖеķì϶£¬µ¼ÖÂËüÃýÎ󵨴ò¿ª²¢ÆðÍ·¼Í¼»÷¼üºÍÊó±êÒÆ¶¯¡£ÕâЩºê·¨Ê½Ëæºó±»´¥·¢£¬µ¼ÖÂÔÙ´ÎÊäÈë±£ÁôµÄÎı¾¡£
https://www.bleepingcomputer.com/news/security/corsair-keyboard-bug-makes-it-type-on-its-own-no-malware-involved/
2¡¢Comcast XfinityÓû§µÄÕÊ»§Ôâµ½2FAÈÆ¹ý¹¥»÷
ýÌå12ÔÂ22Èճƣ¬Comcast XfinityµÄÓû§Ð¹Â©ËûÃǵÄÕÊ»§Ôâµ½ÁËË«³É·ÖÉí·ÝÑéÖ¤ÈÆ¹ý¹¥»÷¡£´Ó12ÔÂ19ÈÕÆðÍ·£¬ºÜ¶àXfinityÓʼþÓû§ÊÕµ½ËûÃǵÄÕÊ»§ÐÅÏ¢ÒѸü¸ÄµÄ֪ͨ¡£µ«ÊÇ£¬µ±³¢ÊÔ½Ó¼ûÕâЩÕÊ»§Ê±£¬ÓÉÓÚÃÜÂëÒѱ»¸ü¸ÄÎÞ·¨µÇ¼¡£ÔÚ³ÁлñµÃ¶ÔÕÊ»§µÄ½Ó¼ûȨÏÞºó£¬Óû§·¢ÏÔìäÔâµ½Á˹¥»÷£¬Ò»´ÎÐÔ@yopmail.comÓòÃûÉϵĸ¨Öúµç×ÓÓʼþ±»Ôö³¤µ½ËûÃǵÄ×ʲÂÖС£×êÑÐÈËÔ±³Æ£¬ºÚ¿Í¿ÉÄÜÊÇͨ¹ýƾ֤Ìî³ä¹¥»÷À´»ñµÃµÇ¼ƾ֤£¬Ò»µ©½øÈëÕË»§²¢±»ÌáÐÑÊäÈë2FA´úÂ룬ËûÃǾÍʹÓðµÀïÁ÷´«µÄXfinityÍøÕ¾µÄOTPÅÔ·£¬À´Î±Ôì³É¹¦µÄ2FAÑéÖ¤ÒªÇó¡£
https://www.bleepingcomputer.com/news/security/comcast-xfinity-accounts-hacked-in-widespread-2fa-bypass-attacks/
3¡¢Ð¬ÀàÁãÊÛÉÌEcco·þÎñÆ÷ÅäÖÃÃýÎóй¶³¬¹ý60GBÊý¾Ý
CyberNewsÔÚ12ÔÂ21ÈÕ±¨Â·³Æ£¬Ð¬ÀàÔì×÷É̺ÍÁãÊÛÉÌEcco³¬¹ý60GBÊý¾ÝÒѾй¶¡£ÆäÖÐÔ̺¬Êý°ÙÍòµÄÎļþ£¬Éæ¼°ÏúÊÛ¡¢ÓªÏú¡¢ÈÕÖ¾¼Í¼ºÍϵͳÐÅÏ¢£¬ÈκÎÓÐȨ½Ó¼ûµÄÈ˶¼Äܹ»²é¿´¡¢±à×ë¡¢¸´ÔìºÍÇÔÈ¡»òɾ³ýÊý¾Ý¡£Ö»¹Ü¶³öµÄ·þÎñÆ÷Êܵ½HTTPÉí·ÝÑéÖ¤µÄ±£»¤£¬µ«ÆäÅäÖÃÃýÎó²¢ÔÊÐíËùÓÐAPIÒªÇóͨ¹ý¡£º¹ÇàÊý¾ÝÅú×¢£¬×Ô2021Äê6ÔÂ4ÈÕÆð£¬¸ÃÊý¾Ý¿âÄܹ»±»½Ó¼ûÖÁÉÙ506Ì졣Ŀǰ£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£
https://cybernews.com/security/ecco-leaks-sensitive-data-for-months/
4¡¢Ä¾ÂíGodFatherÕë¶Ô400¶à¼ÒÒøÐкͼÓÃÜÇ®±ÒÂòÂôËù
12ÔÂ21ÈÕ£¬Group IBÅû¶ÁËAndroidÒøÐÐľÂíGodFatherµÄ¹¥»÷»î¶¯¡£Æù½ñΪֹ£¬ËüÒѹ¥»÷È«Çò16¸ö¹ú¶È/µØÓòµÄ400¶à¸öÖ¸±ê£¬Éæ¼°ÒøÐÐÀûÓ÷¨Ê½¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÂòÂôËù¡£GodFatherÓÚ2021Äê6Ô³õ´Î±»¼ì²âµ½£¬·ÖÎöÅú×¢ËüÊÇAnubisµÄ¼ÌÈÎÕß¡£Æä»î¶¯ÔÚ2022Äê6Ô·ÝÖÕ³¡£¬ÓÖÔÚÄê9ÔÂÔٴγöÏÖ£¬´Ë¿ÌWebSocketÖ°ÄÜÂÔÓб䶯¡£´Ë±í£¬Ëüͨ¹ý½âÃÜʹÓÃBlowfishÃÜÂë±àÂëµÄTelegram channelÃèÊöÀ´¼ìË÷ÆäC2·þÎñÆ÷µØÖ·¡£
https://blog.group-ib.com/godfather-trojan
5¡¢¼ÓÄôó¶ù¿ÆÒ½ÔºSickKidsÔâµ½¹¥»÷µ¼Ö¶à¸öϵͳ崻ú
¾Ý12ÔÂ21ÈÕ±¨Â·£¬Î»ÓÚ¼ÓÄôó¶àÂ×¶àµÄ¶ù¿ÆÒ½ÔºSickKidsÔâµ½¹¥»÷£¬¶à¸öϵͳ崻ú¡£SickKidsÓÚ2022Äê12ÔÂ20ÈÕ´«µÝÁ˸ÃÊÂÎñ£¬²¢Ð¹Â©´ÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ18ÈÕÐÇÆÚÈÕÍíÉÏ9µã30·Ö¸ôʼ£¬Æäϵͳ³öÏÖ¹ÊÕÏ¡£Ò½Ôº°µÊ¾Ó×ÎÒÐÅÏ¢²¢Î´Êܵ½Ó°Ï죬µ«ÆäÍøÕ¾ËÆºõÈÔ´¦ÓÚÀëÏß״̬¡£Ä¿Ç°£¬¸ÃÊÂÎñµÄÐÔÖʺÍÁìÓòÈÔÔÚµ÷²éÖУ¬SickKidsûÓÐй©¹ØÓÚÊÂÎñÔÒòµÄÐÅÏ¢¡£
https://www.infosecurity-magazine.com/news/cyber-incident-failure-children/
6¡¢Î¢Èí°ä²¼¹ØÓÚ½©Ê¬ÍøÂçZerobotÐÂÖ°ÄܵķÖÎö»ã±¨
΢ÈíÔÚ12ÔÂ21ÈÕ°ä²¼Á˹ØÓÚ×îа汾µÄ¶ñÒâÈí¼þZerobot 1.1µÄ·ÖÎö»ã±¨¡£ZerobotÖÁÉÙ´Ó11ÔÂÆðÍ·¾ÍÔÚ»ý¼«¿ª·¢£¬Ôö³¤ÁËÐÂÄ£¿éºÍÖ°ÄÜ£¬ÒÔÀ©´ó¹¥»÷ý½é²¢Ê¹Æä¸üÈÝÒ×ϰȾÐÂÉ豸¡£×Ô12Ô³õÒÔÀ´£¬ËüµÄ¿ª·¢ÈËÔ±ÒѾɾ³ýÁËÕë¶ÔphpMyAdmin·þÎñÆ÷¡¢Dasan GPON·ÓÉÆ÷ºÍD-Link DSL-2750BÎÞÏß·ÓÉÆ÷µÄÄ£¿é¡£²¢Ôö³¤ÁËеķì϶£¬Ê¹Æä¿ÉÄÜÕë¶Ô7ÖÖÐÂÐÍÉ豸ºÍÈí¼þ£¬Ô̺¬Apache£¨CVE-2021-42013£©ºÍApache Spark·þÎñÆ÷£¨CVE-2022-33891£©¡£´Ë±í£¬Ð±äÌåÓµÓÐ7ÖÖеÄDDoSÖ°ÄÜ£¬Ô̺¬TCP_XMAS¹¥»÷¡£
https://www.microsoft.com/en-us/security/blog/2022/12/21/microsoft-research-uncovers-new-zerobot-capabilities/


¾©¹«Íø°²±¸11010802024551ºÅ