°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Äþ¾²¾¯²ìÊý¾Ýй¶³É×îÐÂʼþ
Ðû²¼Ê±¼ä 2025-01-081. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡Äþ¾²¾¯²ìÊý¾Ýй¶³É×îÐÂʼþ
1ÔÂ7ÈÕ£¬°¢¸ùÍ¢»ú³¡Äþ¾²¾¯²ì£¨PSA£©½üÆÚÔâÊÜÍøÂç¹¥»÷£¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°ÈËÔ±µÄ¸öÈ˼°²ÆÕþÊý¾Ýй¶¡£¾Ýµ±µØýÌ屨µÀ£¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¼ÒÒøÐÐϵͳ©¶´»ñÈ¡ÁËPSAµÄÈËΪ¼Ç¼£¬²¢´ÓÔ±¹¤ÈËΪÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽð£¬ÕâЩÆÛÕ©ÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐé¼Ù±êÇ©Ï¡£¾¡¹ÜÉÐδȷ¶¨´Ë´Î¹¥»÷ÊÇ´Ó¹úÍ⻹ÊÇ°¢¸ùÍ¢¾³ÄÚÌᳫ£¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï£¬µ«PSAÒÑ·âËø²¿ÃÅ·þÎñ²¢Æô¶¯ÄÚ²¿ÍøÂçÄþ¾²Ðû´«ÒÔÓ¦¶Ô¡£´ËÍ⣬°¢¸ùÍ¢ÔÚ12Ô»¹ÔâÓöÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄʼþ£¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£7Ô£¬°¢¸ùÍ¢µçÐÅÒ²³ÂËßÁËÀÕË÷Èí¼þ¹¥»÷£¬¶à´ï18000¸öÊÂÇéÕ¾±»¼ÓÃÜ¡£4Ô£¬ºÚ¿ÍÉù³Æ»ñÈ¡ÁË°¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ·ÃÎÊȨÏÞ¡£
https://therecord.media/hackers-target-airport-security-payroll
2. LDAPÄþ¾²Â©¶´Òý·¢DoS¹¥»÷·çÏÕ£¬Î¢ÈíÒÑÐÞ¸´²¢¾¯Ê¾
1ÔÂ3ÈÕ£¬ÍøÂçÉϽüÈÕÐû²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼·ÃÎÊÐÒ飨LDAP£©µÄÄþ¾²Â©¶´ÀûÓ÷¨Ê½£¬ÃûΪLDAPNightmare£¬¸Ã·¨Ê½¿ÉÄÜÒý·¢¾Ü¾ø·þÎñ£¨DoS£©¹¥»÷¡£¸Ã©¶´ÎªÔ½½ç¶Áȡ©¶´£¬±àºÅΪCVE - 2024 - 49113£¬CVSSÆÀ·ÖΪ7.5£¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖÐÐÞ¸´¡£Í¬Ê±£¬Î¢Èí»¹ÐÞ¸´ÁËͬһ×é¼þÖеÄÁíÒ»¸öÑÏÖØ©¶´CVE - 2024 - 49112£¬¸Ã©¶´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·Ö¸ß´ï9.8¡£LDAPNightmare©¶´ÀûÓ÷¨Ê½Í¨¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢Ë;«ÐĽṹµÄDCE/RPCÇëÇ󣬵¼Öµ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñ£¨LSASS£©Í߽⣬²¢ÔÚ·¢ËÍ´øÓС°lm_referral¡±·ÇÁãÖµµÄÌØÖÆCLDAPת½éÏìÓ¦Êý¾Ý°üʱǿÖÆ·þÎñÆ÷ÖØÆô¡£´ËÍ⣬¹¥»÷Õß»¹¿ÉÒÔÀûÓÃÏàͬµÄ©¶´ÀûÓÃÁ´£¬Í¨¹ýÐÞ¸ÄCLDAPÊý¾Ý°üÄÚÈÝ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¢¼´ÐÞ¸´¸Ã©¶´£¬²¢ÊµÊ©¼ì²â´ëÊ©ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2µ÷ÓÃÒÔ¼°DNS SRV²éѯ£¬ÒÔ·ÀÖ¹±»¹¥»÷ÕßÀûÓá£
https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html
3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷£¬8500ÈËÊý¾ÝÔâй¶
1ÔÂ7ÈÕ£¬ÈÕ±¾µç×Ó²úÎï¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâÓöÁËÒ»´ÎÑÏÖصÄÀÕË÷Èí¼þ¹¥»÷¡£¹¥»÷Õßͨ¹ýÍøÂçµöÓãÊÖ¶ÎÓÚ10ÔÂ5ÈÕÀÖ³ÉÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ£¬µ¼ÖÂIT·þÎñÖжϡ£10ÔÂ10ÈÕ£¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢Íþвй¶Ãô¸ÐÐÅÏ¢¡£¿¨Î÷Å·Ëæºó֤ʵ£¬Ô±¹¤¡¢ÉÌÒµ»ï°é¼°ÉÙÁ¿¿Í»§µÄ¸öÈËÊý¾Ý±»ÇÔÈ¡¡£¾¹ýÊӲ죬¿¨Î÷Å·Ðû²¼Á˾ßÌåµÄÊý¾Ýй¶ϸ½Ú£¬°üÂÞ6456ÃûÔ±¹¤µÄ¸öÈËÐÅÏ¢¡¢1931ÃûÉÌÒµ»ï°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍ·þÎñÐÅÏ¢¡£¾¡¹Ü²¿ÃÅÔ±¹¤ÊÕµ½ÁËÓë´Ë´ÎʼþÏà¹ØµÄµöÓãÓʼþ£¬µ«¿¨Î÷Å·ÌåÏÖ£¬ÆäÔ±¹¤¡¢ºÏ×÷»ï°é»ò¿Í»§ÉÐδÔâÊܽøÒ»²½µÄË𺦡£¿¨Î÷Å·Ç¿µ÷£¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ï죬Òò´ËÐÅÓÿ¨ÐÅϢδ±»Ð¹Â¶¡£ÔÚÓëÖ´·¨»ú¹¹¡¢ÂÉʦºÍÄþ¾²×¨¼ÒÐÉ̺󣬿¨Î÷Å·¾ö¶¨²»ÓëÍøÂç·¸×ï·Ö×Ó½øÐÐ̸ÅС£Ä¿Ç°£¬´ó¶àÊýÊÜÓ°ÏìµÄ·þÎñÒѻָ´Õý³££¬µ«ÈÔÓв¿ÃÅ·þÎñÉÐδ»Ö¸´¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¾¡¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ï죬µ«ÔÚͬһʱ¼ä¶ÎÒ²ÔâÓöÁËÆäËû¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/
4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçÀûÓÃÁãÈÕ©¶´ÌᳫȫÇò¹¥»÷
1ÔÂ7ÈÕ£¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÕýÔÚ±äµÃÈÕÒæÅÓ´ó£¬ËüÀûÓÃÁãÈÕ©¶´¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓÉ豸µÄÄþ¾²Â©¶´¡£¾ÝChainxin X LabÑо¿ÈËÔ±¼à²â£¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11Ô¿ªÊ¼ÀûÓÃÒÔǰδ֪µÄ©¶´£¬ÆäÖаüÂÞFour-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856©¶´¡£¸Ã½©Ê¬ÍøÂçÃû³Æ¾ßÓпÖͬµÄ°µÖ¸£¬Ã¿ÌìÓÐ15,000¸ö»îÔ¾½Úµã£¬Ö÷ҪλÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ£¬Õë¶ÔÖ¸¶¨Ä¿±ê½øÐÐÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷ÒÔIJÀû¡£ËüÀûÓÃÁè¼Ý20¸ö¹«¹²ºÍ˽ÈË©¶´Á÷´«µ½»¥ÁªÍø̻¶µÄÉ豸£¬Ä¿±ê°üÂÞ»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷£¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷£¬PZTÏà»ú£¬¿ÎÀÊý×ÖÊÓƵ¼Ïñ»ú£¬Lilin DVR£¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓÉ豸µÈ¡£¸Ã½©Ê¬ÍøÂç¾ßÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆƽâÄ£¿é£¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü£¬²¢ÊµÏÖ»ùÓÚMiraiµÄÃüÁî½á¹¹¡£X Lab³ÂË߳ƣ¬ÆäDDoS¹¥»÷Á¬Ðøʱ¼ä¶Ìµ«Ç¿¶È¸ß£¬Á÷Á¿Áè¼Ý100 Gbps¡£Óû§Ó¦°²×°×îÐÂÉ豸¸üУ¬½ûÓÃÔ¶³Ì·ÃÎÊ£¬²¢¸ü¸ÄĬÈϹÜÀíÔ±ÕÊ»§Æ¾¾ÝÒÔ±£»¤É豸¡£
https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/
5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFI©¶´£¬»òÖÂÉ豸±»½ûÓÃ
1ÔÂ7ÈÕ£¬ÃÀ¹úÉúÎï¼¼Êõ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢ÏÖ´æÔÚBIOS/UEFI©¶´£¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃÉ豸£¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¹Ì¼þÄþ¾²¹«Ë¾EclypsiumÔÚ·ÖÎöÖз¢ÏÖ£¬iSeq 100ÔËÐеÄÊǹýʱµÄBIOS¹Ì¼þ°æ±¾£¬ÇÒδͨ¹ýÄþ¾²Æô¶¯¼¼Êõ½øÐб£»¤£¬´æÔÚ¶à¸ö©¶´£¬°üÂÞBIOSд±£»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£ÕâЩ©¶´ÔÊÐí¹¥»÷ÕßÐÞ¸ÄÆô¶¯É豸µÄ´úÂ룬ÉõÖÁ¸Ä¶¯²âÊÔ½á¹û¡£EclypsiumÇ¿µ÷£¬ÕâЩÎÊÌâ²»½öÏÞÓÚiSeq 100£¬Ê¹ÓÃÏàͬÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤ÒµÉ豸Ҳ¿ÉÄÜ´æÔÚÀàËÆÎÊÌâ¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§Ðû²¼Á˲¹¶¡£¬µ«¹«Ë¾ÌåÏÖ¿ª¶ËÆÀ¹ÀÈÏΪÕâЩÎÊÌâ²¢²»¾ßÓи߷çÏÕ¡£È»¶ø£¬Eclypsium¾¯¸æ³Æ£¬Äܹ»ÁýÕÖiSeq 100¹Ì¼þµÄÍþвÐÐΪÕß¿ÉÒÔÇáÒ×½ûÓøÃÉ豸£¬Õâ¶ÔÓÚÀÕË÷Èí¼þ¼ÓÈëÕßÀ´ËµºÜÓÐÎüÒýÁ¦£¬ÒòΪÆÆ»µ¸ß¼Ûֵϵͳ¿ÉÒÔÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£´ËÍ⣬¹ú¼ÒÐÐΪÕßÒ²¿ÉÄÜ·¢ÏÖDNA²âÐòϵͳºÜÓÐÎüÒýÁ¦£¬ÒòΪËüÃǶÔÓÚ¼²²¡¼ì²â¡¢ÒßÃçÉú²úµÈÖÁ¹ØÖØÒª¡£
https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/
6. CISA¾¯¸æ£ºOracle WebLogicÓëMitel MiCollabϵͳ´æÔÚÑÏÖØ©¶´
1ÔÂ7ÈÕ£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³ö¾¯¸æ£¬ÒªÇó¼Óǿϵͳ·À»¤£¬ÒÔ·À·¶Oracle WebLogic ServerºÍMitel MiCollabϵͳÖдæÔÚµÄÑÏÖØ©¶´¡£ÆäÖУ¬MitelµÄMiCollabͳһͨÐÅƽ̨±»·¢ÏÖ´æÔÚÒªº¦Â·¾¶±éÀú©¶´£¨CVE-2024-41713£©£¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾ÊÚȨµÄ¹ÜÀí²Ù×÷²¢·ÃÎÊÓû§ºÍÍøÂçÐÅÏ¢£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£Í¬Ê±£¬ÁíÒ»¸öMitel MiCollab·¾¶±éÀú©¶´£¨CVE-2024-55550£©ÔÊÐí¾ßÓйÜÀíԱȨÏ޵Ĺ¥»÷Õ߶ÁÈ¡Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄÈÎÒâÎļþ£¬µ«Ó°ÏìÓÐÏÞ¡£´ËÍ⣬Oracle WebLogic ServerµÄÒ»¸öÑÏÖØ©¶´£¨CVE-2020-2883£©Ò²ÓÚËÄÄêÇ°µÃµ½ÐÞ²¹£¬µ«Î´ÐÞ²¹µÄ·þÎñÆ÷ÈÔÃæÁÙÔ¶³ÌÈëÇÖ·çÏÕ¡£CISA½«ÕâÈý¸ö©¶´Ìí¼Óµ½ÆäÒÑÖª±»ÀûÓ鶴Ŀ¼ÖУ¬²¢±ê־Ϊ±»»ý¼«ÀûÓã¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿ÃÅ»ú¹¹Ôڹ涨ʱ¼äÄÚ±£»¤ÆäÍøÂç¡£ËäÈ»¸ÃĿ¼Öصã¹Ø×¢ÃÀ¹úÁª°î»ú¹¹£¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩÄþ¾²Â©¶´£¬ÒÔ×èÖ¹ÕýÔÚ½øÐеĹ¥»÷¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/