°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

Ðû²¼Ê±¼ä 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Çå¾²¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ £¬£¬£¬°¢¸ùÍ¢»ú³¡Çå¾²¾¯Ô±£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷ £¬£¬£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°Ö°Ô±µÄСÎÒ˽¼Ò¼°²ÆÎñÊý¾Ýй¶¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ £¬£¬£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳÎó²î»ñÈ¡ÁËPSAµÄÈËΪ¼Í¼ £¬£¬£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𠣬£¬£¬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£¡£¡£Ö»¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´ÓÍâÑóÕվɰ¢¸ùÍ¢¾³ÄÚÌᳫ £¬£¬£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï £¬£¬£¬µ«PSAÒÑ·â±Õ²¿·ÖЧÀͲ¢Æô¶¯ÄÚ²¿ÍøÂçÇå¾²Ðû´«ÒÔÓ¦¶Ô¡£¡£¡£±ðµÄ £¬£¬£¬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ £¬£¬£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£¡£¡£7Ô £¬£¬£¬°¢¸ùÍ¢µçÐÅÒ²±¨¸æÁËÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£¡£¡£4Ô £¬£¬£¬ºÚ¿ÍÉù³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAPÇå¾²Îó²îÒý·¢DoS¹¥»÷Σº¦ £¬£¬£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ £¬£¬£¬ÍøÂçÉÏ¿ËÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒ飨LDAP£©µÄÇå¾²Îó²îʹÓóÌÐò £¬£¬£¬ÃûΪLDAPNightmare £¬£¬£¬¸Ã³ÌÐò¿ÉÄÜÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷¡£¡£¡£¸ÃÎó²îΪԽ½ç¶ÁÈ¡Îó²î £¬£¬£¬±àºÅΪCVE - 2024 - 49113 £¬£¬£¬CVSSÆÀ·ÖΪ7.5 £¬£¬£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£¡£¡£Í¬Ê± £¬£¬£¬Î¢Èí»¹ÐÞ¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑÏÖØÎó²îCVE - 2024 - 49112 £¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8¡£¡£¡£LDAPNightmareÎó²îʹÓóÌÐòͨ¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢ËÍÈ«ÐĽṹµÄDCE/RPCÇëÇó £¬£¬£¬µ¼ÖÂÍâµØÇå¾²»ú¹¹×ÓϵͳЧÀÍ£¨LSASS£©Í߽⠣¬£¬£¬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üÊ±Ç¿ÖÆÐ§ÀÍÖØÊÓÆô¡£¡£¡£±ðµÄ £¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÏàͬµÄÎó²îʹÓÃÁ´ £¬£¬£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ £¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¬Ã¦ÐÞ¸´¸ÃÎó²î £¬£¬£¬²¢ÊµÑé¼ì²â²½·¥ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRVÅÌÎÊ £¬£¬£¬ÒÔ±ÜÃâ±»¹¥»÷ÕßʹÓᣡ£¡£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ £¬£¬£¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖØµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¹¥»÷Õßͨ¹ýÍøÂç´¹ÂÚÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ £¬£¬£¬µ¼ÖÂITЧÀÍÖÐÖ¹¡£¡£¡£10ÔÂ10ÈÕ £¬£¬£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ £¬£¬£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¿£¿£¿£¿£¿¨Î÷Å·Ëæºó֤ʵ £¬£¬£¬Ô±¹¤¡¢ÉÌҵͬ°é¼°ÉÙÁ¿¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý±»ÇÔÈ¡¡£¡£¡£¾­ÓÉÊÓ²ì £¬£¬£¬¿¨Î÷Å·Ðû²¼ÁËÏêϸµÄÊý¾Ýй¶ϸ½Ú £¬£¬£¬°üÀ¨6456ÃûÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡¢1931ÃûÉÌҵͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍЧÀÍÐÅÏ¢¡£¡£¡£Ö»¹Ü²¿·ÖÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎÊÂÎñÏà¹ØµÄ´¹ÂÚÓʼþ £¬£¬£¬µ«¿¨Î÷Å·ÌåÏÖ £¬£¬£¬ÆäÔ±¹¤¡¢ÏàÖúͬ°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¡£¡£¿£¿£¿£¿£¿¨Î÷Å·Ç¿µ÷ £¬£¬£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ïì £¬£¬£¬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£¡£¡£ÔÚÓëÖ´·¨»ú¹¹¡¢×´Ê¦ºÍÇ徲ר¼ÒЭÉÌºó £¬£¬£¬¿¨Î÷Å·¾öÒé²»ÓëÍøÂç·¸·¨·Ö×Ó¾ÙÐÐ̸ÅС£¡£¡£ÏÖÔÚ £¬£¬£¬´ó´ó¶¼ÊÜÓ°ÏìµÄЧÀÍÒѻָ´Õý³£ £¬£¬£¬µ«ÈÔÓв¿·ÖЧÀÍÉÐδ»Ö¸´¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ £¬£¬£¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ïì £¬£¬£¬µ«ÔÚͳһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£¡£¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçʹÓÃÁãÈÕÎó²îÌᳫȫÇò¹¥»÷


1ÔÂ7ÈÕ £¬£¬£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÖØ´ó £¬£¬£¬ËüʹÓÃÁãÈÕÎó²î¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓ×°±¸µÄÇå¾²Îó²î¡£¡£¡£¾ÝChainxin X LabÑо¿Ö°Ô±¼à²â £¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂ×îÏÈʹÓÃÒÔǰδ֪µÄÎó²î £¬£¬£¬ÆäÖаüÀ¨Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856Îó²î¡£¡£¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸ £¬£¬£¬ÌìÌìÓÐ15,000¸ö»îÔ¾½Úµã £¬£¬£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ £¬£¬£¬Õë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷ÒÔIJÀû¡£¡£¡£ËüʹÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈËÎó²îÈö²¥µ½»¥ÁªÍøÌ»Â¶µÄ×°±¸ £¬£¬£¬Ä¿µÄ°üÀ¨»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷ £¬£¬£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷ £¬£¬£¬PZTÏà»ú £¬£¬£¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú £¬£¬£¬Lilin DVR £¬£¬£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓ×°±¸µÈ¡£¡£¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿£¿£¿£¿£¿é £¬£¬£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü £¬£¬£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÏÂÁî½á¹¹¡£¡£¡£X Lab±¨¸æ³Æ £¬£¬£¬ÆäDDoS¹¥»÷Ò»Á¬Ê±¼ä¶Ìµ«Ç¿¶È¸ß £¬£¬£¬Á÷Á¿Áè¼Ý100 Gbps¡£¡£¡£Óû§Ó¦×°ÖÃ×îÐÂ×°±¸¸üР£¬£¬£¬½ûÓÃÔ¶³Ì»á¼û £¬£¬£¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ±ÕÊ»§Æ¾Ö¤ÒÔ±£»£»£»¤×°±¸¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFIÎó²î £¬£¬£¬»òÖÂ×°±¸±»½ûÓÃ


1ÔÂ7ÈÕ £¬£¬£¬ÃÀ¹úÉúÎïÊÖÒÕ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢Ã÷±£´æBIOS/UEFIÎó²î £¬£¬£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃ×°±¸ £¬£¬£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¡£¡£¹Ì¼þÇå¾²¹«Ë¾EclypsiumÔÚÆÊÎöÖз¢Ã÷ £¬£¬£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾ £¬£¬£¬ÇÒδͨ¹ýÇå¾²ÆôÏÂÊÖÒÕ¾ÙÐб£»£»£»¤ £¬£¬£¬±£´æ¶à¸öÎó²î £¬£¬£¬°üÀ¨BIOSд±£»£»£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£¡£¡£ÕâЩÎó²îÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯×°±¸µÄ´úÂë £¬£¬£¬ÉõÖÁ¸Ä¶¯²âÊÔЧ¹û¡£¡£¡£EclypsiumÇ¿µ÷ £¬£¬£¬ÕâЩÎÊÌâ²»µ«ÏÞÓÚiSeq 100 £¬£¬£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤Òµ×°±¸Ò²¿ÉÄܱ£´æÀàËÆÎÊÌâ¡£¡£¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡ £¬£¬£¬µ«¹«Ë¾ÌåÏÖÆðÔ´ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»¾ßÓиßΣº¦¡£¡£¡£È»¶ø £¬£¬£¬EclypsiumÖÒÑÔ³Æ £¬£¬£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÈÝÒ×½ûÓøÃ×°±¸ £¬£¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦ £¬£¬£¬ÓÉÓÚÆÆËð¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£±ðµÄ £¬£¬£¬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢Ã÷DNA²âÐòϵͳºÜÓÐÎüÒýÁ¦ £¬£¬£¬ÓÉÓÚËüÃǹØÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖ÷Òª¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖÒÑÔ£ºOracle WebLogicÓëMitel MiCollabϵͳ±£´æÑÏÖØÎó²î


1ÔÂ7ÈÕ £¬£¬£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³öÖÒÑÔ £¬£¬£¬ÒªÇóÔöǿϵͳ·À»¤ £¬£¬£¬ÒÔÌá·ÀOracle WebLogic ServerºÍMitel MiCollabϵͳÖб£´æµÄÑÏÖØÎó²î¡£¡£¡£ÆäÖÐ £¬£¬£¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢Ã÷±£´æÒªº¦Â·¾¶±éÀúÎó²î£¨CVE-2024-41713£© £¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢»á¼ûÓû§ºÍÍøÂçÐÅÏ¢ £¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£Í¬Ê± £¬£¬£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀúÎó²î£¨CVE-2024-55550£©ÔÊÐí¾ßÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ £¬£¬£¬µ«Ó°ÏìÓÐÏÞ¡£¡£¡£±ðµÄ £¬£¬£¬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰ»ñµÃÐÞ²¹ £¬£¬£¬µ«Î´ÐÞ²¹µÄЧÀÍÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖΣº¦¡£¡£¡£CISA½«ÕâÈý¸öÎó²îÌí¼Óµ½ÆäÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖÐ £¬£¬£¬²¢±ê¼ÇΪ±»Æð¾¢Ê¹Óà £¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö»ú¹¹ÔÚ»®×¼Ê±¼äÄÚ±£»£»£»¤ÆäÍøÂç¡£¡£¡£ËäÈ»¸ÃÄ¿Â¼ÖØµã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹ £¬£¬£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÇå¾²Îó²î £¬£¬£¬ÒÔ×èÖ¹ÕýÔÚ¾ÙÐеĹ¥»÷¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/