°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ
°ä²¼¹¦·ò 2025-01-081. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ
1ÔÂ7ÈÕ£¬°¢¸ùÍ¢»ú³¡°²È«¾¯Ô±£¨PSA£©½üÆÚÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°ÈËÔ±µÄÓ×ÎÒ¼°²ÆÕþÊý¾Ýй¶¡£¾Ý±¾µØÃ½Ì屨·£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¶ÈÒøÐÐϵͳ·ì϶»ñÈ¡ÁËPSAµÄ¹¤×ʼͼ£¬²¢´ÓÔ±¹¤¹¤×ÊÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽð£¬ÕâЩڲÆÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£Ö»¹ÜÉÐδȷ¶¨Õâ´Î¹¥»÷ÊÇ´Ó¹ú±í»¹Êǰ¢¸ùÍ¢¾³ÄÚÌáÒ飬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬µ«PSAÒѹرղ¿ÃÅ·þÎñ²¢Æô¶¯ÄÚ²¿ÍøÂ簲ȫÐû´«ÒÔÓ¦¶Ô¡£´Ë±í£¬°¢¸ùÍ¢ÔÚ12Ô»¹Ôâ·êÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£7Ô£¬°¢¸ùÍ¢µçÐÅÒ²»ã±¨ÁËÀÕË÷Èí¼þ¹¥»÷£¬¶à´ï18000¸ö¹¤×÷Õ¾±»¼ÓÃÜ¡£4Ô£¬ºÚ¿ÍÐû³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ¡£
https://therecord.media/hackers-target-airport-security-payroll
2. LDAP°²È«·ì϶Òý·¢DoS¹¥»÷·çÏÕ£¬Î¢ÈíÒѽ¨¸´²¢¾¯Ê¾
1ÔÂ3ÈÕ£¬ÍøÂçÉϽüÈÕ°ä²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸£¨LDAP£©µÄ°²È«·ì϶ÀûÓ÷¨Ê½£¬ÃûΪLDAPNightmare£¬¸Ã·¨Ê½¿ÉÄÜÒý·¢»Ø¾ø·þÎñ£¨DoS£©¹¥»÷¡£¸Ã·ì϶ΪԽ½ç¶ÁÈ¡·ì϶£¬±àºÅΪCVE - 2024 - 49113£¬CVSSÆÀ·ÖΪ7.5£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖн¨¸´¡£Í¬Ê±£¬Î¢Èí»¹½¨¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑϳÁ·ì϶CVE - 2024 - 49112£¬¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·Ö¸ß´ï9.8¡£LDAPNightmare·ì϶ÀûÓ÷¨Ê½Í¨¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢Ë;«ÐÄ»ú¹ØµÄDCE/RPCÒªÇ󣬵¼Ö±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ£¨LSASS£©±ÀÀ££¬²¢ÔÚ·¢ËÍ´øÓÓ×°lm_referral¡±·ÇÁãÖµµÄÌØÔìCLDAPת½éÏìÓ¦Êý¾Ý°üʱǿÔì·þÎñÆ÷³ÁÆô¡£´Ë±í£¬¹¥»÷Õß»¹Äܹ»ÀûÓÃÒ»ÑùµÄ·ì϶ÀûÓÃÁ´£¬Í¨¹ýÅú¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯µ±¼´½¨¸´¸Ã·ì϶£¬²¢Ö´Ðмì²â´ëÊ©ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRV²éÎÊ£¬ÒÔÔ¤·À±»¹¥»÷ÕßÀûÓá£
https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html
3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬8500ÈËÊý¾ÝÔâй¶
1ÔÂ7ÈÕ£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâ·êÁËÒ»´ÎÑϳÁµÄÀÕË÷Èí¼þ¹¥»÷¡£¹¥»÷Õßͨ¹ýÍøÂç´¹µö¼¿Á©ÓÚ10ÔÂ5Èճɹ¦ÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬µ¼ÖÂIT·þÎñÖжϡ£10ÔÂ10ÈÕ£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢Íþвй¼ûô¸ÐÐÅÏ¢¡£¿¨Î÷Å·Ëæºó֤ʵ£¬Ô±¹¤¡¢Ã³Ò×ͬ°é¼°ÉÙÁ¿¿Í»§µÄÓ×ÎÒÊý¾Ý±»ÇÔÈ¡¡£¾¹ýµ÷²é£¬¿¨Î÷Å·°ä²¼Á˾ßÌåµÄÊý¾Ýй¶ϸ½Ú£¬Ô̺¬6456ÃûÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡¢1931ÃûóÒ×ͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍ·þÎñÐÅÏ¢¡£Ö»¹Ü²¿ÃÅÔ±¹¤ÊÕµ½ÁËÓëÕâ´ÎÊÂÎñÓйصĴ¹µöÓʼþ£¬µ«¿¨Î÷Å·°µÊ¾£¬ÆäÔ±¹¤¡¢ºÏ×÷ͬ°é»ò¿Í»§ÉÐδÔâ·ê½øÒ»²½µÄÇÖº¦¡£¿¨Î÷Å·Ç¿µ÷£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬Òò¶øÐÅÓþ¿¨ÐÅϢδ±»Ð¹Â¶¡£ÔÚÓë·¨ÂÉ»ú¹¹¡¢ÂÉʦºÍ°²È«×¨¼ÒÐÉ̺󣬿¨Î÷Å·¾ö¶¨²»ÓëÍøÂç·¸×ï·Ö×Ó½øÐн»É档Ŀǰ£¬´óÎÞÊýÊÜÓ°ÏìµÄ·þÎñÒѸ´ÔÕý³££¬µ«ÈÔÓв¿ÃÅ·þÎñÉÐδ¸´Ô¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬µ«ÔÚͳһ¹¦·ò¶ÎÒ²Ôâ·êÁËÆäËû¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/
4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçÀûÓÃÁãÈÕ·ì϶ÌáÒéÈ«Çò¹¥»÷
1ÔÂ7ÈÕ£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÔÚ±äµÃÈÕÒæ¸´ÔÓ£¬ËüÀûÓÃÁãÈÕ·ì϶¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓÉ豸µÄ°²È«·ì϶¡£¾ÝChainxin X Lab×êÑÐÈËÔ±¼à²â£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂÆðÍ·ÀûÓÃÒÔǰδ֪µÄ·ì϶£¬ÆäÖÐÔ̺¬Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856·ì϶¡£¸Ã½©Ê¬ÍøÂçÃû³ÆÓµÓпÖͬµÄ°µÖ¸£¬Ã¿ÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬ÖØÒªÎ»ÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬Õë¶ÔÖ¸¶¨Ö¸±ê½øÐÐÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷ÒÔIJÀû¡£ËüÀûÓó¬¹ý20¸ö¹«¹²ºÍ¸öÈË·ì϶´«²¼µ½»¥ÁªÍøÂ¶³öµÄÉ豸£¬Ö¸±êÔ̺¬»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬PZTÏà»ú£¬¿ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬Lilin DVR£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓÉ豸µÈ¡£¸Ã½©Ê¬ÍøÂçÓµÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿é£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬²¢ÊµÏÖ»ùÓÚMiraiµÄºÅÁî½á¹¹¡£X Lab»ã±¨³Æ£¬ÆäDDoS¹¥»÷³ÖÐø¹¦·ò¶Ìµ«Ç¿¶È¸ß£¬Á÷Á¿³¬¹ý100 Gbps¡£Óû§Ó¦×°ÖÃ×îÐÂÉ豸¸üУ¬½ûÓÃÔ¶³Ì½Ó¼û£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ¹ØÊ»§Í´´¦ÒÔ±£»¤É豸¡£
https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/
5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFI·ì϶£¬»òÖÂÉ豸±»½ûÓÃ
1ÔÂ7ÈÕ£¬ÃÀ¹úÉúÎï¼¼Êõ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢ÏÖ´æÔÚBIOS/UEFI·ì϶£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃÉ豸£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¹Ì¼þ°²È«¹«Ë¾EclypsiumÔÚ·ÖÎöÖз¢ÏÖ£¬iSeq 100ÔËÐеÄÊǹýÆÚµÄBIOS¹Ì¼þ°æ±¾£¬ÇÒδͨ¹ý°²È«Æô¶¯¼¼Êõ½øÐб£»¤£¬´æÔÚ¶à¸ö·ì϶£¬Ô̺¬BIOSд±£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£ÕâЩ·ì϶ÔÊÐí¹¥»÷ÕßÅú¸ÄÆô¶¯É豸µÄ´úÂ룬ÉõÖÁ´Û¸Ä²âÊÔÁ˾֡£EclypsiumÇ¿µ÷£¬ÕâЩÎÊÌâ²»½öÏÞÓÚiSeq 100£¬Ê¹ÓÃÒ»ÑùÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤ÒµÉ豸Ҳ¿ÉÄÜ´æÔÚÀàËÆÎÊÌâ¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§°ä²¼Á˲¹¶¡£¬µ«¹«Ë¾°µÊ¾³õ²½ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»ÓµÓи߷çÏÕ¡£È»¶ø£¬EclypsiumÖÒ¸æ³Æ£¬¿ÉÄܸ²¸ÇiSeq 100¹Ì¼þµÄÍþвÐÐΪÕßÄܹ»µÈÏнûÓøÃÉ豸£¬Õâ¶ÔÓÚÀÕË÷Èí¼þ²Î¼ÓÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬ÓÉÓÚ·ÛËé¸ß¼ÛֵϵͳÄܹ»ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£´Ë±í£¬¹ú¶ÈÐÐΪÕßÒ²¿ÉÄÜ·¢ÏÖDNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬ÓÉÓÚËüÃǶÔÓÚ¼²²¡¼ì²â¡¢ÒßÃç³ö²úµÈÖÁ¹Ø³ÁÒª¡£
https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/
6. CISAÖҸ棺Oracle WebLogicÓëMitel MiCollabϵͳ´æÔÚÑϳÁ·ì϶
1ÔÂ7ÈÕ£¬CISAÒÑÏòÃÀ¹úÁª¹ú»ú¹¹·¢³öÖҸ棬ҪÇó¼Óǿϵͳ·À»¤£¬ÒÔ·À±¸Oracle WebLogic ServerºÍMitel MiCollabϵͳÖдæÔÚµÄÑϳÁ·ì϶¡£ÆäÖУ¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢ÏÖ´æÔڹؼüõè¾¶±éÀú·ì϶£¨CVE-2024-41713£©£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾ÊÚȨµÄÖÎÀí²Ù×÷²¢½Ó¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£Í¬Ê±£¬ÁíÒ»¸öMitel MiCollabõè¾¶±éÀú·ì϶£¨CVE-2024-55550£©ÔÊÐíÓµÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¬µ«Ó°ÏìÓÐÏÞ¡£´Ë±í£¬Oracle WebLogic ServerµÄÒ»¸öÑϳÁ·ì϶£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰµÃµ½½¨²¹£¬µ«Î´½¨²¹µÄ·þÎñÆ÷ÈÔÃæ¶ÔÔ¶³ÌÈëÇÖ·çÏÕ¡£CISA½«ÕâÈý¸ö·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖУ¬²¢ÏóÕ÷Ϊ±»»ý¼«ÀûÓã¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ»ú¹¹Ôڹ水¹¦·òÄÚ±£»¤ÆäÍøÂç¡£¹ÌÈ»¸ÃĿ¼³Áµã¹Ø×¢ÃÀ¹úÁª¹ú»ú¹¹£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩ°²È«·ì϶£¬ÒÔ×èÖ¹ÔÚ½øÐеĹ¥»÷¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ