GFI KerioControl·À»ðǽÔâÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶Íþв

°ä²¼¹¦·ò 2025-02-11

1. GFI KerioControl·À»ðǽÔâÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶Íþв


2ÔÂ10ÈÕ£¬³¬¹ýÒ»ÍòÁ½Ç§¸ö GFI KerioControl ·À»ðǽÊ·ý±»·¢ÏÖ´æÔÚ±àºÅΪ CVE-2024-52875 µÄÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶¡£KerioControl ÊÇÒ»¿îרΪÖÐÓ×ÐÍÆóÒµÉè¼ÆµÄÍøÂ簲ȫÌ×¼þ£¬Ö°ÄÜÔ̺¬ VPN¡¢´ø¿íÖÎÀí¡¢»ã±¨¼à¿Ø¡¢Á÷Á¿¹ýÂË¡¢AV ±£»¤ºÍÈëÇÖ·ÀÓù¡£´Ë·ì϶Óɰ²È«×êÑÐÔ± Egidio Romano£¨EgiX£©ÓÚ 2024 Äê 12 ÔÂÖÐÑ®·¢ÏÖ£¬²¢Õ¹Ê¾ÁË¿ÉÄܵÄÒ»¼ü RCE ¹¥»÷¡£Ö»¹Ü GFI Software ÒÑÔÚ 12 Ô 19 ÈÕ°ä²¼ÁËÕë¶Ô¸ÃÎÊÌâµÄ°²È«¸üУ¨9.4.5 Patch 1 °æ±¾£©£¬µ«Æ¾¾Ý Censys Êý¾Ý£¬ÈýÖܺóÈÔÓдóÁ¿Ê·ý佨¸´¡£Greynoise ÒѼì²âµ½ÀûÓø÷ì϶µÄ×Ô¶¯¹¥»÷³¢ÊÔ£¬Ö¼ÔÚÇÔÈ¡ÖÎÀíÔ± CSRF ÁîÅÆ¡£Shadowserver Foundation »ã±¨³Æ£¬Ä¿Ç°ÈÔÓÐ 12,229 ¸ö KerioControl ·À»ðÇ½Ãæ¶Ô´Ë·ì϶Íþв£¬ÊÜÓ°ÏìµØÓòÔ̺¬ÒÁÀÊ¡¢ÃÀ¹ú¡¢Òâ´óÀû¡¢µÂ¹úµÈ¡£ÓÉÓÚ´æÔÚ¹«¿ªµÄ·ì϶֤Ã÷£¨PoC£©£¬ÀûÓÃÃż÷¼«µÍ£¬ÉõÖÁ²»´¿ÊìµÄºÚ¿ÍÒ²¿ÉÄܲμӶñÒâ»î¶¯¡£·ì϶ԭÒòÔÚÓÚÓû§ÊäÈëδµÃµ½Êʵ±ËãÕÊ£¬¿ÉÄܱ»ÀûÓÃÖ´ÐÐ HTTP ÏìÓ¦²ð·Ö¹¥»÷£¬½ø¶ø¿ÉÄܵ¼Ö·´ÉäÐÍ¿çÕ¾µã¾ç±¾£¨XSS£©ºÍÆäËû¹¥»÷¡£Òò¶ø£¬Ç¿ÁÒ½¨ÒéÉÐδÀûÓøüеÄÓû§×°Öà 2025 Äê 1 Ô 31 ÈÕ°ä²¼µÄ KerioControl °æ±¾ 9.4.5 Patch 2£¬ÒÔ¼ÓÇ¿°²È«ÐÔ¡£


https://www.bleepingcomputer.com/news/security/over-12-000-keriocontrol-firewalls-exposed-to-exploited-rce-flaw/


2. HandalaºÚ¿Í×é֝ɿÏÓ¶ÔÒÔÉ«Áо¯·½·¢Æð´ó¹æÄ£ÍøÂç¹¥»÷


2ÔÂ10ÈÕ£¬³ôÃûÔ¶ÑïµÄHandalaºÚ¿Í×éÖ¯£¬ÉæÏÓÓëÒÁÀʵý±¨»ú¹¹ÓйØÁª£¬½üÆÚ°ä·¢¶ÔÒÔÉ«Áо¯Ô±¶ÓÁз¢ÆðÁËÍøÂç¹¥»÷£¬Ðû³Æ³É¹¦ÇÔÈ¡ÁË2.1TBµÄÃô¸ÐÊý¾Ý£¬Ô̺¬ÈËʼͼ¡¢±øÆ÷Çåµ¥¡¢Ò½ÁƺÍÉúÀíµµ°¸µÈ£¬²¢¹«¿ª´«²¼ÁËÆäÖÐ35Íò·ÝÎļþ¡£Ö»¹ÜÒÔÉ«Áо¯·½·ñ¶¨ÏµÍ³Ö±½ÓÔâÈëÇÖ£¬µ«Õâ´ÎÊý¾Ýй¶ÊÂÎñÁìÓò¿í·º£¬Éæ¼°´óÁ¿Ãô¸ÐÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·¡¢³Öǹ֤¡¢¾¯¹ÙÕÕÆ¬ºÍÓ×ÎÒÁªÏµ·½Ê½µÈ¡£Í¬Ê±£¬Handala»¹Ö¸¿ØÆä»ñÈ¡Á˾¯Ô±µÄÉúÀíÆÀ¹ÀµÈ¸öÈËÊý¾Ý£¬²¢ÇÖÈëÁËÒÔÉ«Áйú¶È°²È«ÊýµÄ·þÎñÆ÷¡£Õâ´ÎÊÂÎñÊÇHandalaÕë¶ÔÒÔÉ«ÁÐʵÌåÖ´ÐзÛËéÐÔÍøÂçÐж¯µÄµäÐͰ¸Àý£¬³ö¸ñÊÇÔÚÒÔÉ«ÁÐÓë¹þÂí˹ì¶ÜÉý¼¶ºó£¬ÒÔÉ«ÁÐÒѳÉΪÒÁÀÊÍøÂçÐж¯µÄÖØÒªÖ¸±ê¡£HandalaµÄ»î¶¯ÆµÈÔ£¬²»½öÉæÏӲμÓÕë¶ÔÒÔÉ«ÁÐ×éÖ¯ÍøÂ簲ȫÈËÔ±µÄÍøÂç´¹µö»î¶¯£¬»¹Õë¶ÔÒÔÉ«ÁеÄSoreqºË×êÑÐÖÐÐÄ·¢ÆðÀÕË÷Èí¼þ¹¥»÷£¬×î½üÓÖÈëÇÖÁËÒÔÉ«Áеç×Ó¹«Ë¾ÔËÓªµÄ´¹Î£¾¯±¨ÏµÍ³£¬Òý·¢´óÁìÓò·¢¼±¡£¸Ã×éÖ¯ÔÚÌû×ÓÖг°·íÒÔÉ«ÁУ¬Ç¿µ÷Æä³É¹¦Í»ÆÆ·ÀÓù²¢¸æ·¢°ÂÃØ£¬³ÁÉêÆä¡°²»»á½¡Íü£¬²»»áÔ­Á¡±µÄ±êÓï¡£


https://hackread.com/handala-hackers-israeli-police-breach-data-leak/


3. ¾¯·½¿ÛÁô 4 Ãû Phobos ÀÕË÷Èí¼þÏÓÒÉÈË£¬²é·â 8Base ÍøÕ¾


2ÔÂ10ÈÕ£¬È«Çò·¨ÂÉÐж¯¡°Phobos Aetor¡¹Øë¶ÔPhobosÀÕË÷Èí¼þÍŻ﷢չ£¬ÒÑÔÚÌ©¹úÆÕ¼ªµº¿ÛÁôËÄÃûÅ·ÖÞºÚ¿ÍÏÓÒÉÈË£¬²¢²é·â8Base°µÍøÍøÕ¾¡£ÕâЩÏÓÒÉÈ˱»Ö¸¿Ø¶ÔÈ«Çò³¬¹ý1000ÃûÊܺ¦Õß½øÐÐÁËÍøÂç¹¥»÷£¬ÀÕË÷Á˼ÛÖµ1600ÍòÃÀÔªµÄ±ÈÌØ±Ò¡£Õâ´ÎÐж¯Éæ¼°¶à¸ö¹ú¶ÈºÍµØÓòµÄ¾¯·½Ð­Í¬Í»Ï®£¬½É»ñÁ˵ç×ÓÉ豸ºÍ¼ÓÃÜÇ®±ÒÇ®°ü¡£8BaseÀÕË÷Èí¼þÍÅ»ï×Ô2022Äê3Ô³ÉÁ¢ÒÔÀ´£¬Ò»ÏòÏà¶ÔƧ¾²£¬Ö±µ½2023Äê6ÔÂÆðͷй¶Êܺ¦ÕßÊý¾Ý¡£¸ÃÍÅ»ï»áÈëÇÔìóÒµÍøÂ磬ÇÔÈ¡Êý¾Ý²¢Ê¹ÓÃPhobosÀÕË÷Èí¼þ¼ÓÃÜÆ÷¼ÓÃÜÉ豸£¬ÒªÇóÖ§¸¶¸ß¶îÊê½ðÒÔ»»È¡½âÃÜÃÜÔ¿ºÍ²»°ä²¼Êý¾ÝµÄ³Ðŵ¡£³ÛÃûÊܺ¦ÕßÔ̺¬ÈÕ±¾µç²úÖêʽ»áÉçºÍ½áºÏ¹ú¿ª·¢´òËãÊð¡£Õâ´ÎÐж¯Åú×¢£¬È«Çò·¨Âɲ¿ÃÅÔÚ¼ÓÇ¿ºÏ×÷½ø¹¥ÀÕË÷Èí¼þ·¸×ï¡£


https://www.bleepingcomputer.com/news/legal/police-arrests-4-phobos-ransomware-suspects-seizes-8base-sites/


4. Lee Enterprises±¨Òµ¼¯ÍÅÔâÍøÂç¹¥»÷ÖÂÔËÓªÖжÏ


2ÔÂ10ÈÕ£¬ÃÀ¹ú±¨Òµ¼¯ÍÅLee EnterprisesÔÚ2025Äê2ÔÂ3ÈÕÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬µ¼ÖÂÆäÒµÎñÔËÓªÖжÏ¡£Õâ´Î¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø¹ØÁ˺ܶàÍøÂ磬ÇÖÈÅÁËÊýÊ®ÖÖ±¨Ö½µÄÓ¡Ë¢ºÍ¿¯ÐУ¬²¢ÇÒʹµÃ¼ÇÕߺͱà×ëÎÞ·¨½Ó¼ûËûÃǵÄÎļþ¡£¸Ã¹«Ë¾ÔÚÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»µÄÎļþÖÐÈ·ÈÏÁËÕâ´Î¹¥»÷£¬²¢°µÊ¾ÔÚµ÷²éÄÄЩÐÅÏ¢¿ÉÄÜÊܵ½Ó°Ïì¡£¶à¼ÒLee Enterprises³ö°æÎïÔÚÍøÕ¾¶¥²¿ÏÔÊ¾ÊØ»¤ºá·ù£¬Ïò¶ÁÕß·Ǹ²¢°µÊ¾ÔÚÖÂÁ¦½â¾öÎÊÌâ¡£Lee EnterprisesÔÚ26¸öÖݳö°æ77·ÝÈÕ±¨ºÍ350·ÝÖÜ¿¯¼°×¨Òµ¿¯ÎռÓг¬¹ý120ÍòµÄÈÕ¿¯ÐÐÁ¿ºÍ³¬¹ý4400ÍòµÄÊý×Ö°æ¶ÀÁ¢·Ã¿Í¡£ÎåÄêǰ£¬¸Ã¼¯ÍÅÒ²ÔøÔâ·êÍøÂç¹¥»÷£¬ÆäʱÒÁÀʺڿÍÈëÇÖÁËÆäÍøÂç×÷Ϊ´«²¼ÐéαÐÅÏ¢»î¶¯µÄÒ»²¿ÃÅ¡£


https://www.bleepingcomputer.com/news/security/cyberattack-disrupts-lee-newspapers-operations-across-the-us/


5. Facebook³ÉÍøÂç´¹µöÐÂÖ¸±ê£¬Êý°Ù¼ÒÆóÒµÓʼþµØÖ·Ôâ½Ù³Ö


2ÔÂ10ÈÕ£¬Check Point ResearchµÄ×îÐÂ×êÑÐÏÔʾ£¬È«Çòµ±ÏȵÄÉ罻ýÌåÆ½Ì¨Facebook³ÉΪÁËÐÂÒ»ÂÖÍøÂç´¹µö»î¶¯µÄÖ¸±ê£¬¸Ã»î¶¯Ö¼ÔÚÇÔÈ¡Êý°Ù¼ÒÆóÒµµÄ12,000¶à¸öµç×ÓÓʼþµØÖ·¡£Õâ´Î¹¥»÷»î¶¯Ê¼ÓÚ2024Äê12ÔÂ20ÈÕ×óÓÒ£¬ÖØÒªÕë¶ÔÅ·ÃË¡¢ÃÀ¹úºÍ°Ä´óÀûÑǵĹ«Ë¾£¬µ«Ò²Ó°Ïìµ½ÁËÈ«ÇòÆäËûµØÓò¡£Ú¿Æ­ÕßÀûÓÃSalesforceµÄ×Ô¶¯Óʼþ·þÎñ·¢ËͺýŪÐÔµç×ÓÓʼþ£¬ÓʼþÖдøÓмÙðµÄFacebook»Õ±ê£¬²¢Ö¸¿ØÊÕ¼þÈ˼Ӻ¦°æÈ¨¡£³ý·ÇÊÕ¼þÈËÔڶ̹¦·òÄÚÌá³öÒìÒ飬²»È»½«Ãæ¶ÔÕË»§Ï޶ȵÄÍþв¡£ÓʼþÖÐÔ̺¬ÐéαµÄFacebookÖ§³ÖÒ³ÃæÁ´½Ó£¬ÓÕÆ­Êܺ¦ÕßÊäÈëµÇ¼ʹ´¦£¬´Ó¶øÌáÈ¡Ãô¸ÐÐÅÏ¢¡£ÕâÖÖºýŪÐÐΪÍþв×ÅÈ«ÇòÒÀÀµFacebookµÄÆóÒµ£¬¿ÉÄܵ¼ÖÂÆäÖÎÀíÔ¹ØË»§±»½ÚÔì¡¢ÄÚÈݱ»¸ü¸Ä¡¢ÐÂÎű»°Ñ³Ö¡¢Ìû×Ó±»É¾³ýºÍ°²È«ÉèÖñ»Åú¸Ä£¬½ø¶øÔì³É¿Í»§ÐÅÀµ¶È½µÂä¡¢¿Í»§Á÷ʧºÍDZÔÚµÄ˾·¨ËßËϵȺó¹û¡£¶ÔÓÚÒ½ÁƱ£½¡ºÍ½ðÈÚµÈÊܼà¹ÜÐÐÒµµÄÆóÒ·´Ëµ£¬»¹¿ÉÄܵ¼Ö²»ºÏ¹æ¡¢·£¿îºÍ˾·¨ÌôÕ½¡£Òò¶ø£¬×éÖ¯Ó¦Ö´ÐÐÃ÷È·µÄÊÂÎñÏìÓ¦´òË㣬ÒÔ½µµÍÊܵ½¹¥»÷µÄ·çÏÕ¡£


https://hackread.com/scammers-use-fake-facebook-copyright-notices-to-hijack-accounts/


6. ÁôÏëÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬12Íò»¼ÕßÐÅÏ¢Ôâй¶


2ÔÂ10ÈÕ£¬×ôÖÎÑÇÖݰ಼ÀïÆæµÄÒ»¼ÒÓ×ÐÍ´åÂäÒ½ÔºÁôÏëÒ½ÔººÍׯ԰ÔÚ2024Äê11ÔÂÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäϵͳ̱»¾£¬²»µÃ²»Ñ¡È¡Ö½ÖÊÁ÷³Ì¼Í¼»¼ÕßÐÅÏ¢¡£Ö»¹ÜÔËӪδÖжÏ£¬µ«ÆÚ´ý¹¦·òµ¢¸é¡£¹¥»÷Õ߾ݳƴÓҽԺϵͳÖÐÇÔÈ¡ÁË1.15TBµÄÊý¾Ý£¬²¢ÔÚTorйÃÜÍøÕ¾ÉϹ«¿ª£¬ÆäÖÐÔ̺¬120,085È˵ÄÓ×ÎÒÐÅÏ¢ºÍ½¡È«ÐÅÏ¢£¬ÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢²¡Ê·¡¢Ò½ÖÎÐÅÏ¢ºÍ½¡È«±£ÏÕÐÅÏ¢¡£EmbargoÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£ÁôÏëÒ½ÔºÒÑÏòÊÜÓ°ÏìÓ×ÎÒ·¢ËÍÊéÃæÍ¨Öª£¬²¢Ìṩ12¸öÔµÄÃâ·ÑÉí·Ý±£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£Ö»¹ÜĿǰûÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÐÅÏ¢±»ÀÄÓ㬵«ÓÉÓÚÊý¾Ý¿É¹«¿ªÏÂÔØ£¬ÊÜÓ°ÏìÈËȺ¿ÉÄÜÃæ¶ÔÍøÂç´¹µöºÍÆäËûÀàÐ͹¥»÷µÄ·çÏÕ¡£


https://www.securityweek.com/information-of-120000-stolen-in-ransomware-attack-on-georgia-hospital/