Python JSON Logger¿â·ìÏ¶ÆØ¹â£º4300Íò×°ÖÃÃæ¶ÔRCE·çÏÕ

°ä²¼¹¦·ò 2025-03-13

1. Python JSON Logger¿â·ìÏ¶ÆØ¹â£º4300Íò×°ÖÃÃæ¶ÔRCE·çÏÕ


3ÔÂ10ÈÕ £¬½üÈÕ £¬Python JSON Logger ¿âÖÐÅû¶ÁËÒ»¸öÑϳÁ·ì϶£¨GHSA-wmxh-pxcx-9w24£© £¬CVSS v3 ÑϳÁÐԵȼ¶Îª8.8/10 £¬¿ÉÄܵ¼ÖÂÔ¼4300Íò¸ö×°ÖÃÃæ¶ÔÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷·çÏÕ ¡£¸Ã·ì϶ԴÓÚδע²áµÄÒÀÀµÏî¡°msgspec-python313-pre¡± £¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÖ´ÐÐÊÜÓ°Ïì°æ±¾£¨3.2.0ºÍ3.2.1£©µÄÈÕ־ʵÓ÷¨Ê½µÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂë ¡£¸Ã·ì϶ÊÇÒÀÀµ»ìºÏ¹¥»÷µÄµäÐÍÀý×Ó £¬ÀûÓÃÈí¼þ¹©¸øÁ´Öеķì϶ ¡£Ö»¹ÜûÓÐÖ¤¾ÝÅú×¢ÔÚ·ì϶´°¿ÚÆÚ¼ä²úÉúÁ˶ñÒâÀûÓà £¬µ«¸Ã¿âµÄ¿í·ºÑ¡È¡·Å´óÁËDZÔÚÓ°Ïì ¡£³É¹¦ÀûÓø÷ì϶½«Ê¹¹¥»÷Õß»ñµÃ¶ÔϵͳµÄÆëÈ«½ÚÔìȨ ¡ £»º½â´ëÊ©Ô̺¬°ä²¼v3.3.0°æ±¾ £¬ÆëÈ«½â³ýÁËmsgspec-python313-preÒÀÀµÐÔ £¬²¢Ó밲ȫ×êÑÐԱЭµ÷×ªÒÆÓÐÕùÒéµÄÈí¼þ°üÃû³ÆµÄËùÓÐȨ ¡£°²È«ÍŶӽ¨Òéµ±¼´Éý¼¶µ½v3.3.0 £¬ÎÞ·¨µ±¼´¸üеÄ×éÖ¯Ó¦ÉóºËÆäPython»·¾³ ¡£´Ë·ì϶͹ÏÔÁËPythonÉú̬ϵͳÔÚÆ½ºâ¿ÉÓÃÐԺͰ²È«ÐÔ·½ÃæÃæ¶ÔµÄ³ÖÐøÌôÕ½ £¬²¢´ÙÊ¹ÖØÒª¿ªÔ´ÉçÇø³ÁÐÂÉóÊÓÒÀÀµÖÎÀíʵ¼Ê ¡£


https://cybersecuritynews.com/popular-python-library-vulnerability/


2. ³¬¹ý300¸ö¹Ø¼ü»ù´¡ÉèÊ©×éÖ¯Êܵ½MedusaÀÕË÷Èí¼þ¹¥»÷


3ÔÂ12ÈÕ £¬CISA¡¢FBIºÍ¶àÖÝÐÅÏ¢¹²ÏíÓë·ÖÎöÖÐÐÄ(MS-ISAC)½áºÏ°ä²¼²¼¸æ³Æ £¬½ØÖÁ2025Äê2Ô £¬MedusaÀÕË÷Èí¼þÐж¯ÒÑÓ°ÏìÃÀ¹ú300¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©ÁìÓòµÄ×éÖ¯ £¬Éæ¼°Ò½ÁÆ¡¢½ÌÓý¡¢Ë¾·¨¡¢±£ÏÕ¡¢¼¼ÊõºÍÔì×÷ÒµµÈ¶à¸öÐÐÒµ ¡£Îª·ÀÓùMedusaÀÕË÷Èí¼þ¹¥»÷ £¬½¨Òé×éÖ¯²ÉÈ¡»º½â´ëÊ© £¬Ô̺¬½¨²¹°²È«·ì϶¡¢·Ö¶ÎÍøÂç¡¢¹ýÂËÍøÂçÁ÷Á¿µÈ ¡£MedusaÀÕË÷Èí¼þÍÅ»ï×Ô2021Äê1Ô³öÏÖ £¬2023ÄêÆðÍ·»îÔ¾ £¬ÒÑÔÚÈ«ÇòÔì³É400¶àÃûÊܺ¦Õß £¬²¢Í¨¹ýйÃÜÍøÕ¾ºÍºÚ°Â·ÕË÷ÃÅ»§ÍøÕ¾ÏòÊܺ¦ÕßʩѹҪÇóÖ§¸¶Êê½ð ¡£¸ÃÍÅ»ïѡȡÀÕË÷Èí¼þ¼´·þÎñ(RaaS)ÔËÓªºÍͬÃËģʽ £¬ÕÐļ³õʼ½Ó¼û¾­¼ÍÈËÒÔ»ñµÃ¶ÔDZÔÚÊܺ¦Õߵijõʼ½Ó¼ûȨ ¡£´Ë±í £¬¶à¸ö¶ñÒâÈí¼þ¼Ò×åºÍÍøÂç·¸×ï×´¶¯¶¼×Ô³ÆÊÇMedusa £¬µ¼Ö¹ØÓÚMedusaÀÕË÷Èí¼þµÄ±¨Â·³öÏÖ»ìºÏ ¡£ÉϸöÔ £¬CISAºÍFBI»¹°ä²¼Á˹ØÓÚGhostÀÕË÷Èí¼þ¹¥»÷µÄ½áºÏ¾¯±¨ £¬³Æ¶à¸öÐÐÒµÁìÓòµÄÊܺ¦Õß¶¼Êܵ½Á˹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-300-critical-infrastructure-orgs/


3. ³¯ÏÊAPT37×éÖ¯ÍÆ³öÐÂÐÍAndroid¼äµýÈí¼þKoSpy


3ÔÂ12ÈÕ £¬Ò»ÖÖÃûΪ¡°KoSpy¡±µÄÐÂÐÍAndroid¼äµýÈí¼þÓ볯ÏÊÍþв×éÖ¯APT37£¨±ðÃû¡°ScarCruft¡±£©ÓйØ £¬¸Ã×é֯ͨ¹ýÖÁÉÙÎå¸ö¶ñÒâÀûÓ÷¨Ê½ÉøÈëµ½Google PlayºÍµÚÈý·½ÀûÓÃÉ̵êAPKPure ¡£ÕâЩÀûÓ÷¨Ê½¼Ù×°³ÉÎļþÖÎÀíÆ÷¡¢°²È«¹¤¾ßºÍÈí¼þ¸üз¨Ê½ £¬Õë¶Ôº«ÓïºÍÓ¢ÓïÓû§ ¡£Ò»µ©¼¤»î £¬KoSpy»á´ÓFirebase FirestoreÊý¾Ý¿âÖмìË÷¼ÓÃÜÅäÖÃÎļþ £¬Ïνӵ½ºÅÁîºÍ½ÚÔì·þÎñÆ÷ £¬²¢ÔËÐи÷ÀàÊý¾ÝÍøÂçÖ°ÄÜ £¬ÈçÀ¹½Ø¶ÌÐźÍͨ»°¼Í¼¡¢ÊµÊ±×·×ÙGPSµØÎ»¡¢ÇÔÈ¡Îļþ¡¢Â¼ÔìÒôƵºÍÊÓÆµµÈ ¡£Ö»¹ÜÕâЩÀûÓ÷¨Ê½ÒÑ´ÓGoogle PlayºÍAPKPureÖÐÒÆ³ý £¬µ«Óû§ÈÔÐèÊÖ¶¯Ð¶Ôز¢Ê¹Óð²È«¹¤¾ßɨÃèÉ豸 ¡£Google Play Protect¿ÉÄÜ×èÖ¹ÒÑÖªµÄ¶ñÒâÀûÓ÷¨Ê½ £¬Ô®ÊÖ·À±¸KoSpy ¡£¹È¸èÒÑÈ·ÈÏËùÓÐKoSpyÀûÓÃÒÑ´ÓGoogle PlayÖÐɾ³ý £¬ÏàÓ¦µÄFirebaseÏîĿҲÒѱ»³·Ï ¡£Ê¹ÓÃÇøÓò˵»°Åú×¢ÕâÊÇÓÐÕë¶ÔÐԵĶñÒâÈí¼þ £¬Google Play Protect»á×Ô¶¯± £»¤AndroidÓû§ÃâÊÜÒÑÖª°æ±¾µÄ¶ñÒâÈí¼þÇÖº¦ ¡£


https://www.bleepingcomputer.com/news/security/new-north-korean-android-spyware-slips-onto-google-play/


4. MozillaÖҸ棺FirefoxÓû§Ðè¸üÐÂä¯ÀÀÆ÷ÒÔÔ¤·À°²È«·çÏÕ


3ÔÂ12ÈÕ £¬Mozilla½üÆÚÖÒ¸æFirefoxÓû§ £¬Îñ±Ø½«Æää¯ÀÀÆ÷¸üе½×îа汾 £¬ÒÔÔ¤·ÀÒò¹«Ë¾µÄÒ»¸ö¸ùÖ¤Êé¼´½«µ½ÆÚ¶ø¿ÉÄܵ¼ÖµÄÖжϺͰ²È«·çÏÕ ¡£¸Ã¸ùÖ¤ÊéÓÃÓÚÇ©ÊðÔ̺¬Firefox×ÔÉí¼°MozillaÏîÄ¿¸½¼Ó×é¼þÔÚÄÚµÄÄÚÈÝ £¬½«ÓÚ2025Äê3ÔÂ14ÈÕµ½ÆÚ ¡£ÎªÈ·±£Õý³£Ê¹Óø½¼Ó×é¼þ²¢Ô¤·À°²È«·çÏÕ £¬Óû§Ð轫ä¯ÀÀÆ÷¸üÐÂÖÁFirefox 128£¨2024Äê7Ô°䲼£©»ò¸ü¸ß°æ±¾ £¬ÒÔ¼°¡°À©´óÖ§³Ö°æ±¾¡±£¨ESR£©Óû§µÄESR 115.13»ò¸ü¸ß°æ±¾ ¡£ÕâЩ·çÏÕÔ̺¬¶ñÒâ²å¼þ¿ÉÄÜÈÆ¹ý°²È«± £»¤Ð¹Â¶Óû§Êý¾Ý¡¢²»ÊÜÐÅÀµµÄÖ¤Êé¿ÉÄÜÔÊÐíÓû§½Ó¼ûڲƭ»ò²»°²È«µÄÍøÕ¾ £¬ÒÔ¼°ÃÜÂëй¶¾¯±¨¿ÉÄÜÖÕ³¡¹¤×÷µÈ ¡£Óû§¿Éͨ¹ýä¯ÀÀÆ÷²Ëµ¥²é³­²¢È·Èϰ汾 £¬´Ë²Ù×÷Ò²»á×Ô¶¯´¥·¢¸üв鳭 ¡£¸ÃÎÊÌâÓ°ÏìËùÓÐÆ½Ì¨ÉϵÄFirefox £¬µ«iOSÖ®±í ¡£Mozilla½¨ÒéÓû§¸üе½×îа汾ÒÔÈ·±£ä¯ÀÀÆ÷°²È«¸ßЧ £¬²¢ÎªÓöµ½ÎÊÌâµÄÓû§ÉèÖÃÁËÖ§³ÖÏß³Ì ¡£Í¬Ê± £¬»ùÓÚFirefoxµÄä¯ÀÀÆ÷ÈçTor¡¢LibreWolfºÍWaterfoxµÄÓû§Ò²Ó¦È·±£ÔËÐеÄÊÇ»ùÓÚFirefox 128¼°¸ü¸ß°æ±¾µÄ°æ±¾ ¡£


https://www.bleepingcomputer.com/news/software/mozilla-warns-users-to-update-firefox-before-certificate-expires/


5. ÈÕ±¾Ôâ¡°MirrorFace¡±APT¹¥»÷ £¬ÀûÓÃWindows SandboxÌӱܼì²â


3ÔÂ12ÈÕ £¬ÈÕ±¾¹ú¶È¾¯Ô±ÌüºÍ¹ú¶ÈÍøÂ簲ȫÊÂÎñ³ï±¸ºÍÕ½ÊõÖÐÐİ䲼ÁËÒ»·Ý°²È«²¼¸æ £¬ÖÒ¸æÈÕ±¾×éÖ¯Ãæ¶ÔÀ´×Ô¡°MirrorFace¡¹ØâÒ»APT10×Ó×éÖ¯µÄ¸ß¼¶³ÖÐøÐÔÍþв¹¥»÷ ¡£¸Ã×éÖ¯ÀûÓÃWindows SandboxºÍVisual Studio CodeÖ´ÐжñÒâ»î¶¯ £¬²¢Ê¹ÓÃÁËÃûΪ¡°LilimRAT¡±µÄ¶¨Ôì¶ñÒâÈí¼þ £¬×¨ÃÅÉè¼ÆÔÚWindows SandboxÖÐÔËÐÐ £¬ÒÔÌÓ±ÜÖ÷»úϵͳÉϰ²È«¹¤¾ßµÄ¼ì²â ¡£¹¥»÷Õßͨ¹ýÆôÓÃWindows Sandbox¡¢´´½¨×Ô½ç˵ÅäÖÃÎļþºÍÔÚ¸ôÀë»·¾³ÖÐÖ´ÐжñÒâÈí¼þµÈ¸´ÔӵĶà½×¶Î¹¥»÷Á÷³Ì £¬ÔÚÊÜϰȾϵͳÉÏά³ÖÓÆ¾ÃÐÔ²¢×î´óÏ޶ȵØÏ÷¼õ»î¶¯ºÛ¼£ ¡£ÓÉÓÚWindows SandboxĬÈϽûÓÃÇÒWindows DefenderÔÚÆäÖÐҲĬÈϽûÓà £¬Îª¹¥»÷ÕßÌṩÁËÒ»¸ö²»°²È«µÄ²Ù×÷»·¾³ ¡£°²È«×¨¼Ò½¨Òéά³ÖWindows Sandbox½ûÓÃ״̬ £¬¼à¿ØÓйعý³Ì £¬ÏÞ¶ÈÖÎÀíȨÏÞ £¬²¢Ö´ÐÐAppLockerÕ½Êõ £¬ÒÔÔ¤·Àδ¾­ÊÚȨִÐÐWindows Sandbox ¡£


https://cybersecuritynews.com/mirrorface-apt-hackers-exploited-windows-sandbox-visual-studio-code/


6. FacebookÖҸ棺FreeType×ÖÌå¿â¸ßΣ·ì϶Ð费ΣÉý¼¶


3ÔÂ12ÈÕ £¬Facebook½üÈÕ·¢³öÖÒ¸æ £¬Ö¸³öÔÚFreeType 2.13¼°ÒÔÉϰ汾ÖдæÔÚÒ»¸ö¸ßΣ·ì϶£¨CVE-2025-27363£© £¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ £¬ÇÒÒÑÓл㱨³Æ¸Ã·ì϶ÔÚ±»»ý¼«ÀûÓýøÐй¥»÷ ¡£FreeTypeÊÇÒ»¸ö¿í·ºÊ¹ÓõĿªÔ´×ÖÌåäÖȾ¿â £¬×°ÖÃÔÚÔ̺¬Linux¡¢AndroidµÈ¶à¸öϵͳºÍ·þÎñÖÐ ¡£¸Ã·ì϶ÔÚ³¢ÊÔ½âÎöTrueType GXºÍ¿É±ä×ÖÌåÎļþÓйصÄ×ÖÌå×Ó×ÖÐνṹʱ²úÉúÔ½½çдÈë £¬´æÔÚÓÚFreeType 2.13.0¼°ÒÔϰ汾ÖÐ £¬µ«ÒÑÔÚ2.13.0°æ±¾µÄ¸üÐÂÖеÃÒÔ½¨¸´ ¡£Ö»¹Ü×îеÄÒ×Êܹ¥»÷°æ±¾ÒÑÓÐÁ½Ä꺹Çà £¬µ«¾ÉµÄ¿â°æ±¾ÔÚÈí¼þÏîÄ¿ÖпÉÄܳ־ôæÔÚ £¬Òò¶øÈí¼þ¿ª·¢ÈËÔ±ºÍÏîÄ¿ÖÎÀíÔ±Ð辡¿ìÉý¼¶µ½×îа汾FreeType 2.13.3 £¬ÒÔÔ¤·ÀDZÔڵݲȫ·çÏÕ ¡£Facebook°µÊ¾ £¬ËûÃÇ·¢ÏÖ´Ë·ì϶ºó½øÐÐÁ˻㱨 £¬Ö¼ÔÚ¼ÓǿÿÓ×ÎÒµÄÔÚÏß°²È« £¬²¢ÖÂÁ¦ÓÚ± £»¤Óû§µÄ¸öÈËͨѶ ¡£Ë¼¿¼µ½FreeTypeµÄ¿í·ºÀûÓà £¬¾¡¿ì½â¾ö¸Ã·ì϶¶ÔÓÚ±£ÏÕÍøÂ簲ȫÖÁ¹Ø³ÁÒª ¡£


https://www.bleepingcomputer.com/news/security/facebook-discloses-freetype-2-flaw-exploited-in-attacks/