°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

°ä²¼¹¦·ò 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬°¢¸ùÍ¢»ú³¡°²È«¾¯Ô±£¨PSA£©½üÆÚÔâ·êÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°ÈËÔ±µÄÓ×ÎÒ¼°²ÆÕþÊý¾Ýй¶¡£¡£¡£¡£¡£¾Ý±¾µØÃ½Ì屨·£¬£¬ £¬£¬£¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¶ÈÒøÐÐϵͳ·ì϶»ñÈ¡ÁËPSAµÄ¹¤×ʼͼ£¬£¬ £¬£¬£¬£¬²¢´ÓÔ±¹¤¹¤×ÊÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𣬣¬ £¬£¬£¬£¬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£¡£¡£¡£Ö»¹ÜÉÐδȷ¶¨Õâ´Î¹¥»÷ÊÇ´Ó¹ú±í»¹Êǰ¢¸ùÍ¢¾³ÄÚÌáÒ飬£¬ £¬£¬£¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬£¬ £¬£¬£¬£¬µ«PSAÒѹرղ¿ÃÅ·þÎñ²¢Æô¶¯ÄÚ²¿ÍøÂ簲ȫÐû´«ÒÔÓ¦¶Ô¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹Ôâ·êÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ£¬£¬ £¬£¬£¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£¡£¡£¡£7Ô£¬£¬ £¬£¬£¬£¬°¢¸ùÍ¢µçÐÅÒ²»ã±¨ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬¶à´ï18000¸ö¹¤×÷Õ¾±»¼ÓÃÜ¡£¡£¡£¡£¡£4Ô£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÐû³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAP°²È«·ì϶Òý·¢DoS¹¥»÷·çÏÕ£¬£¬ £¬£¬£¬£¬Î¢ÈíÒѽ¨¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ£¬£¬ £¬£¬£¬£¬ÍøÂçÉϽüÈÕ°ä²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸£¨LDAP£©µÄ°²È«·ì϶ÀûÓ÷¨Ê½£¬£¬ £¬£¬£¬£¬ÃûΪLDAPNightmare£¬£¬ £¬£¬£¬£¬¸Ã·¨Ê½¿ÉÄÜÒý·¢»Ø¾ø·þÎñ£¨DoS£©¹¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶ΪԽ½ç¶ÁÈ¡·ì϶£¬£¬ £¬£¬£¬£¬±àºÅΪCVE - 2024 - 49113£¬£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5£¬£¬ £¬£¬£¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖн¨¸´¡£¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬£¬Î¢Èí»¹½¨¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑϳÁ·ì϶CVE - 2024 - 49112£¬£¬ £¬£¬£¬£¬¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£¡£¡£¡£LDAPNightmare·ì϶ÀûÓ÷¨Ê½Í¨¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢Ë;«ÐÄ»ú¹ØµÄDCE/RPCÒªÇ󣬣¬ £¬£¬£¬£¬µ¼Ö±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ£¨LSASS£©±ÀÀ££¬£¬ £¬£¬£¬£¬²¢ÔÚ·¢ËÍ´øÓÓ×°lm_referral¡±·ÇÁãÖµµÄÌØÔìCLDAPת½éÏìÓ¦Êý¾Ý°üʱǿÔì·þÎñÆ÷³ÁÆô¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»ÀûÓÃÒ»ÑùµÄ·ì϶ÀûÓÃÁ´£¬£¬ £¬£¬£¬£¬Í¨¹ýÅú¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬£¬ £¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¢¼´½¨¸´¸Ã·ì϶£¬£¬ £¬£¬£¬£¬²¢Ö´Ðмì²â´ëÊ©ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRV²éÎÊ£¬£¬ £¬£¬£¬£¬ÒÔÔ¤·À±»¹¥»÷ÕßÀûÓᣡ£¡£¡£¡£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâ·êÁËÒ»´ÎÑϳÁµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹µö¼¿Á©ÓÚ10ÔÂ5Èճɹ¦ÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬£¬ £¬£¬£¬£¬µ¼ÖÂIT·þÎñÖжÏ¡£¡£¡£¡£¡£10ÔÂ10ÈÕ£¬£¬ £¬£¬£¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬ £¬£¬£¬£¬²¢Íþвй¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡ £¿ £¿£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ£¬£¬ £¬£¬£¬£¬Ô±¹¤¡¢Ã³Ò×ͬ°é¼°ÉÙÁ¿¿Í»§µÄÓ×ÎÒÊý¾Ý±»ÇÔÈ¡¡£¡£¡£¡£¡£¾­¹ýµ÷²é£¬£¬ £¬£¬£¬£¬¿¨Î÷Å·°ä²¼Á˾ßÌåµÄÊý¾Ýй¶ϸ½Ú£¬£¬ £¬£¬£¬£¬Ô̺¬6456ÃûÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡¢1931ÃûóÒ×ͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍ·þÎñÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹Ü²¿ÃÅÔ±¹¤ÊÕµ½ÁËÓëÕâ´ÎÊÂÎñÓйصĴ¹µöÓʼþ£¬£¬ £¬£¬£¬£¬µ«¿¨Î÷Å·°µÊ¾£¬£¬ £¬£¬£¬£¬ÆäÔ±¹¤¡¢ºÏ×÷ͬ°é»ò¿Í»§ÉÐδÔâ·ê½øÒ»²½µÄÇÖº¦¡£¡£¡£¡£¡ £¿ £¿£¿£¿£¿¨Î÷Å·Ç¿µ÷£¬£¬ £¬£¬£¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬£¬ £¬£¬£¬£¬Òò¶øÐÅÓþ¿¨ÐÅϢδ±»Ð¹Â¶¡£¡£¡£¡£¡£ÔÚÓë·¨ÂÉ»ú¹¹¡¢ÂÉʦºÍ°²È«×¨¼ÒЭÉ̺󣬣¬ £¬£¬£¬£¬¿¨Î÷Å·¾ö¶¨²»ÓëÍøÂç·¸×ï·Ö×Ó½øÐн»Éæ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬£¬´óÎÞÊýÊÜÓ°ÏìµÄ·þÎñÒѸ´Ô­Õý³££¬£¬ £¬£¬£¬£¬µ«ÈÔÓв¿ÃÅ·þÎñÉÐδ¸´Ô­¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬ £¬£¬£¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬£¬ £¬£¬£¬£¬µ«ÔÚͳһ¹¦·ò¶ÎÒ²Ôâ·êÁËÆäËû¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçÀûÓÃÁãÈÕ·ì϶ÌáÒéÈ«Çò¹¥»÷


1ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÔÚ±äµÃÈÕÒæ¸´ÔÓ£¬£¬ £¬£¬£¬£¬ËüÀûÓÃÁãÈÕ·ì϶¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓÉ豸µÄ°²È«·ì϶¡£¡£¡£¡£¡£¾ÝChainxin X Lab×êÑÐÈËÔ±¼à²â£¬£¬ £¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂÆðÍ·ÀûÓÃÒÔǰδ֪µÄ·ì϶£¬£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856·ì϶¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÃû³ÆÓµÓпÖͬµÄ°µÖ¸£¬£¬ £¬£¬£¬£¬Ã¿ÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬£¬ £¬£¬£¬£¬ÖØÒªÎ»ÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬£¬ £¬£¬£¬£¬Õë¶ÔÖ¸¶¨Ö¸±ê½øÐÐÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£¡£¡£¡£ËüÀûÓó¬¹ý20¸ö¹«¹²ºÍ¸öÈË·ì϶´«²¼µ½»¥ÁªÍøÂ¶³öµÄÉ豸£¬£¬ £¬£¬£¬£¬Ö¸±êÔ̺¬»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬£¬ £¬£¬£¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬£¬ £¬£¬£¬£¬PZTÏà»ú£¬£¬ £¬£¬£¬£¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú£¬£¬ £¬£¬£¬£¬Lilin DVR£¬£¬ £¬£¬£¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓÉ豸µÈ¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÓµÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ £¿ £¿£¿£¿£¿é£¬£¬ £¬£¬£¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬£¬ £¬£¬£¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄºÅÁî½á¹¹¡£¡£¡£¡£¡£X Lab»ã±¨³Æ£¬£¬ £¬£¬£¬£¬ÆäDDoS¹¥»÷³ÖÐø¹¦·ò¶Ìµ«Ç¿¶È¸ß£¬£¬ £¬£¬£¬£¬Á÷Á¿³¬¹ý100 Gbps¡£¡£¡£¡£¡£Óû§Ó¦×°ÖÃ×îÐÂÉ豸¸üУ¬£¬ £¬£¬£¬£¬½ûÓÃÔ¶³Ì½Ó¼û£¬£¬ £¬£¬£¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ¹ØÊ»§Í´´¦ÒÔ±£»£»£»£»£»£»£»£»¤É豸¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFI·ì϶£¬£¬ £¬£¬£¬£¬»òÖÂÉ豸±»½ûÓÃ


1ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬ÃÀ¹úÉúÎï¼¼Êõ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢ÏÖ´æÔÚBIOS/UEFI·ì϶£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃÉ豸£¬£¬ £¬£¬£¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¡£¡£¡£¹Ì¼þ°²È«¹«Ë¾EclypsiumÔÚ·ÖÎöÖз¢ÏÖ£¬£¬ £¬£¬£¬£¬iSeq 100ÔËÐеÄÊǹýÆÚµÄBIOS¹Ì¼þ°æ±¾£¬£¬ £¬£¬£¬£¬ÇÒδͨ¹ý°²È«Æô¶¯¼¼Êõ½øÐб£»£»£»£»£»£»£»£»¤£¬£¬ £¬£¬£¬£¬´æÔÚ¶à¸ö·ì϶£¬£¬ £¬£¬£¬£¬Ô̺¬BIOSд±£»£»£»£»£»£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£¡£¡£¡£ÕâЩ·ì϶ÔÊÐí¹¥»÷ÕßÅú¸ÄÆô¶¯É豸µÄ´úÂ룬£¬ £¬£¬£¬£¬ÉõÖÁ´Û¸Ä²âÊÔÁ˾Ö¡£¡£¡£¡£¡£EclypsiumÇ¿µ÷£¬£¬ £¬£¬£¬£¬ÕâЩÎÊÌâ²»½öÏÞÓÚiSeq 100£¬£¬ £¬£¬£¬£¬Ê¹ÓÃÒ»ÑùÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤ÒµÉ豸Ҳ¿ÉÄÜ´æÔÚÀàËÆÎÊÌâ¡£¡£¡£¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§°ä²¼Á˲¹¶¡£¡£¡£¡£¡£¬£¬ £¬£¬£¬£¬µ«¹«Ë¾°µÊ¾³õ²½ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»ÓµÓи߷çÏÕ¡£¡£¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬EclypsiumÖÒ¸æ³Æ£¬£¬ £¬£¬£¬£¬¿ÉÄܸ²¸ÇiSeq 100¹Ì¼þµÄÍþвÐÐΪÕßÄܹ»µÈÏнûÓøÃÉ豸£¬£¬ £¬£¬£¬£¬Õâ¶ÔÓÚÀÕË÷Èí¼þ²Î¼ÓÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬£¬ £¬£¬£¬£¬ÓÉÓÚ·ÛËé¸ß¼ÛֵϵͳÄܹ»ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬¹ú¶ÈÐÐΪÕßÒ²¿ÉÄÜ·¢ÏÖDNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬£¬ £¬£¬£¬£¬ÓÉÓÚËüÃǶÔÓÚ¼²²¡¼ì²â¡¢ÒßÃç³ö²úµÈÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖҸ棺Oracle WebLogicÓëMitel MiCollabϵͳ´æÔÚÑϳÁ·ì϶


1ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬CISAÒÑÏòÃÀ¹úÁª¹ú»ú¹¹·¢³öÖҸ棬£¬ £¬£¬£¬£¬ÒªÇó¼Óǿϵͳ·À»¤£¬£¬ £¬£¬£¬£¬ÒÔ·À±¸Oracle WebLogic ServerºÍMitel MiCollabϵͳÖдæÔÚµÄÑϳÁ·ì϶¡£¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢ÏÖ´æÔڹؼüõè¾¶±éÀú·ì϶£¨CVE-2024-41713£©£¬£¬ £¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢½Ó¼ûÓû§ºÍÍøÂçÐÅÏ¢£¬£¬ £¬£¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓᣡ£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬£¬ÁíÒ»¸öMitel MiCollabõè¾¶±éÀú·ì϶£¨CVE-2024-55550£©ÔÊÐíÓµÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄËÁÒâÎļþ£¬£¬ £¬£¬£¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬Oracle WebLogic ServerµÄÒ»¸öÑϳÁ·ì϶£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰµÃµ½½¨²¹£¬£¬ £¬£¬£¬£¬µ«Î´½¨²¹µÄ·þÎñÆ÷ÈÔÃæ¶ÔÔ¶³ÌÈëÇÖ·çÏÕ¡£¡£¡£¡£¡£CISA½«ÕâÈý¸ö·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖУ¬£¬ £¬£¬£¬£¬²¢ÏóÕ÷Ϊ±»»ý¼«ÀûÓ㬣¬ £¬£¬£¬£¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ»ú¹¹Ôڹ水¹¦·òÄÚ±£»£»£»£»£»£»£»£»¤ÆäÍøÂç¡£¡£¡£¡£¡£¹ÌÈ»¸ÃĿ¼³Áµã¹Ø×¢ÃÀ¹úÁª¹ú»ú¹¹£¬£¬ £¬£¬£¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩ°²È«·ì϶£¬£¬ £¬£¬£¬£¬ÒÔ×èÖ¹ÔÚ½øÐеĹ¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/