°¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ

°ä²¼¹¦·ò 2025-01-08

1. °¢¸ù͢ƵÔâÍøÂç¹¥»÷£º»ú³¡°²È«¾¯Ô±Êý¾Ýй¶³É×îÐÂÊÂÎñ


1ÔÂ7ÈÕ £¬°¢¸ùÍ¢»ú³¡°²È«¾¯Ô±£¨PSA£©½üÆÚÔâ·êÍøÂç¹¥»÷ £¬µ¼ÖÂÆä¹ÙÔ±ºÍÎÄÖ°ÈËÔ±µÄÓ×ÎÒ¼°²ÆÕþÊý¾Ýй¶¡£¾Ý±¾µØÃ½Ì屨· £¬Ò»ÃûÉí·Ý²»Ã÷µÄºÚ¿Íͨ¹ý¹ú¶ÈÒøÐÐϵͳ·ì϶»ñÈ¡ÁËPSAµÄ¹¤×ʼͼ £¬²¢´ÓÔ±¹¤¹¤×ÊÖп۳ýÁË2000ÖÁ5000±ÈË÷£¨Ô¼ºÏ100ÖÁ245ÃÀÔª£©²»µÈµÄ×ʽ𠣬ÕâЩڲƭÐÔ¿Û¿î±»ÁÐÔÚÈç¡°DD mayor¡±ºÍ¡°DD seguros¡±µÈÐéα±êǩϡ£Ö»¹ÜÉÐδȷ¶¨Õâ´Î¹¥»÷ÊÇ´Ó¹ú±í»¹Êǰ¢¸ùÍ¢¾³ÄÚÌáÒé £¬ÇÒ¿ÉÄÜÉæ¼°ÄÚ²¿Í¬»ï £¬µ«PSAÒѹرղ¿ÃÅ·þÎñ²¢Æô¶¯ÄÚ²¿ÍøÂ簲ȫÐû´«ÒÔÓ¦¶Ô¡£´Ë±í £¬°¢¸ùÍ¢ÔÚ12Ô»¹Ôâ·êÁËÁ½Æðµç×ÓÕþÎñƽ̨ÔâºÚ¿ÍÈëÇÖµÄÊÂÎñ £¬µ¼ÖÂÊý°ÙÍò¹«ÃñÐÅϢй¶¡£7Ô £¬°¢¸ùÍ¢µçÐÅÒ²»ã±¨ÁËÀÕË÷Èí¼þ¹¥»÷ £¬¶à´ï18000¸ö¹¤×÷Õ¾±»¼ÓÃÜ¡£4Ô £¬ºÚ¿ÍÐû³Æ»ñÈ¡Á˰¢¸ùÍ¢ÖÐÑëÒøÐÐÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ¡£


https://therecord.media/hackers-target-airport-security-payroll


2. LDAP°²È«·ì϶Òý·¢DoS¹¥»÷·çÏÕ £¬Î¢ÈíÒѽ¨¸´²¢¾¯Ê¾


1ÔÂ3ÈÕ £¬ÍøÂçÉϽüÈÕ°ä²¼ÁËÒ»¸öÕë¶ÔWindowsÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸£¨LDAP£©µÄ°²È«·ì϶ÀûÓ÷¨Ê½ £¬ÃûΪLDAPNightmare £¬¸Ã·¨Ê½¿ÉÄÜÒý·¢»Ø¾ø·þÎñ£¨DoS£©¹¥»÷¡£¸Ã·ì϶ΪԽ½ç¶ÁÈ¡·ì϶ £¬±àºÅΪCVE - 2024 - 49113 £¬CVSSÆÀ·ÖΪ7.5 £¬Òѱ»Î¢ÈíÔÚ2024Äê12ÔµIJ¹¶¡ÈÕ¸üÐÂÖн¨¸´¡£Í¬Ê± £¬Î¢Èí»¹½¨¸´ÁËͳһ×é¼þÖеÄÁíÒ»¸öÑϳÁ·ì϶CVE - 2024 - 49112 £¬¸Ã·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬CVSSÆÀ·Ö¸ß´ï9.8¡£LDAPNightmare·ì϶ÀûÓ÷¨Ê½Í¨¹ýÏòδ´ò²¹¶¡µÄWindows Server·¢Ë;«ÐÄ»ú¹ØµÄDCE/RPCÒªÇó £¬µ¼Ö±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ£¨LSASS£©±ÀÀ£ £¬²¢ÔÚ·¢ËÍ´øÓÓ×°lm_referral¡±·ÇÁãÖµµÄÌØÔìCLDAPת½éÏìÓ¦Êý¾Ý°üʱǿÔì·þÎñÆ÷³ÁÆô¡£´Ë±í £¬¹¥»÷Õß»¹Äܹ»ÀûÓÃÒ»ÑùµÄ·ì϶ÀûÓÃÁ´ £¬Í¨¹ýÅú¸ÄCLDAPÊý¾Ý°üÄÚÈÝ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Î¢Èí½¨ÒéÆóÒµ/×éÖ¯Á¢¼´½¨¸´¸Ã·ì϶ £¬²¢Ö´Ðмì²â´ëÊ©ÒÔ¼à¿Ø¿ÉÒɵÄCLDAPת½éÏìÓ¦¡¢DsrGetDcNameEx2ŲÓÃÒÔ¼°DNS SRV²éÎÊ £¬ÒÔÔ¤·À±»¹¥»÷ÕßÀûÓá£


https://thehackernews.com/2025/01/ldapnightmare-poc-exploit-crashes-lsass.html


3. ¿¨Î÷Å·ÔâÀÕË÷Èí¼þ¹¥»÷ £¬8500ÈËÊý¾ÝÔâй¶


1ÔÂ7ÈÕ £¬ÈÕ±¾µç×Ó²úÆ·¾ÞÍ·¿¨Î÷Å·ÔÚ2024Äê10ÔÂÔâ·êÁËÒ»´ÎÑϳÁµÄÀÕË÷Èí¼þ¹¥»÷¡£¹¥»÷Õßͨ¹ýÍøÂç´¹µö¼¿Á©ÓÚ10ÔÂ5Èճɹ¦ÈëÇÖ¿¨Î÷Å·µÄÍøÂçϵͳ £¬µ¼ÖÂIT·þÎñÖжÏ¡£10ÔÂ10ÈÕ £¬UndergroundÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬²¢Íþвй¼ûô¸ÐÐÅÏ¢¡£¿¨Î÷Å·Ëæºó֤ʵ £¬Ô±¹¤¡¢Ã³Ò×ͬ°é¼°ÉÙÁ¿¿Í»§µÄÓ×ÎÒÊý¾Ý±»ÇÔÈ¡¡£¾­¹ýµ÷²é £¬¿¨Î÷Å·°ä²¼Á˾ßÌåµÄÊý¾Ýй¶ϸ½Ú £¬Ô̺¬6456ÃûÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡¢1931ÃûóÒ×ͬ°éµÄ×ÊÁÏÒÔ¼°91Ãû¿Í»§µÄËÍ»õºÍ·þÎñÐÅÏ¢¡£Ö»¹Ü²¿ÃÅÔ±¹¤ÊÕµ½ÁËÓëÕâ´ÎÊÂÎñÓйصĴ¹µöÓʼþ £¬µ«¿¨Î÷Å·°µÊ¾ £¬ÆäÔ±¹¤¡¢ºÏ×÷ͬ°é»ò¿Í»§ÉÐδÔâ·ê½øÒ»²½µÄÇÖº¦¡£¿¨Î÷Å·Ç¿µ÷ £¬¿Í»§µÄÊý¾Ý¿âδÊÜÓ°Ïì £¬Òò¶øÐÅÓþ¿¨ÐÅϢδ±»Ð¹Â¶¡£ÔÚÓë·¨ÂÉ»ú¹¹¡¢ÂÉʦºÍ°²È«×¨¼ÒЭÉ̺ó £¬¿¨Î÷Å·¾ö¶¨²»ÓëÍøÂç·¸×ï·Ö×Ó½øÐн»É档Ŀǰ £¬´óÎÞÊýÊÜÓ°ÏìµÄ·þÎñÒѸ´Ô­Õý³£ £¬µ«ÈÔÓв¿ÃÅ·þÎñÉÐδ¸´Ô­¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Ö»¹Ü¿¨Î÷Å·µÄCASIO IDºÍClassPad.netƽ̨δÊÜÀÕË÷Èí¼þÖ±½ÓÓ°Ïì £¬µ«ÔÚͳһ¹¦·ò¶ÎÒ²Ôâ·êÁËÆäËû¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/


4. »ùÓÚMiraiµÄ½©Ê¬ÍøÂçÀûÓÃÁãÈÕ·ì϶ÌáÒéÈ«Çò¹¥»÷


1ÔÂ7ÈÕ £¬Ò»¸ö»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÔÚ±äµÃÈÕÒæ¸´ÔÓ £¬ËüÀûÓÃÁãÈÕ·ì϶¹¥»÷¹¤ÒµÂ·ÓÉÆ÷ºÍÖÇÄܼҾÓÉ豸µÄ°²È«·ì϶¡£¾ÝChainxin X Lab×êÑÐÈËÔ±¼à²â £¬¸Ã½©Ê¬ÍøÂç×Ô2024Äê11ÔÂÆðÍ·ÀûÓÃÒÔǰδ֪µÄ·ì϶ £¬ÆäÖÐÔ̺¬Four-Faith¹¤ÒµÂ·ÓÉÆ÷µÄCVE-2024-12856·ì϶¡£¸Ã½©Ê¬ÍøÂçÃû³ÆÓµÓпÖͬµÄ°µÖ¸ £¬Ã¿ÌìÓÐ15,000¸ö»îÔ¾½Úµã £¬ÖØÒªÎ»ÓÚÖйú¡¢ÃÀ¹ú¡¢¶íÂÞ˹µÈµØ £¬Õë¶ÔÖ¸¶¨Ö¸±ê½øÐÐÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷ÒÔIJÀû¡£ËüÀûÓó¬¹ý20¸ö¹«¹²ºÍ¸öÈË·ì϶´«²¼µ½»¥ÁªÍøÂ¶³öµÄÉ豸 £¬Ö¸±êÔ̺¬»ªË¶¡¢»ªÎªÂ·ÓÉÆ÷ £¬Neterbit¡¢LB-Link¡¢Four-Faith·ÓÉÆ÷ £¬PZTÏà»ú £¬¿­ÎÀÊý×ÖÊÓÆµÂ¼Ïñ»ú £¬Lilin DVR £¬Í¨ÓÃDVRÒÔ¼°VimarÖÇÄܼҾÓÉ豸µÈ¡£¸Ã½©Ê¬ÍøÂçÓµÓÐÕë¶ÔÈõTelnetÃÜÂëµÄ±©Á¦ÆÆ½âÄ£¿é £¬Ê¹ÓÃ×Ô½ç˵UPX´ò°ü £¬²¢ÊµÏÖ»ùÓÚMiraiµÄºÅÁî½á¹¹¡£X Lab»ã±¨³Æ £¬ÆäDDoS¹¥»÷³ÖÐø¹¦·ò¶Ìµ«Ç¿¶È¸ß £¬Á÷Á¿³¬¹ý100 Gbps¡£Óû§Ó¦×°ÖÃ×îÐÂÉ豸¸üР£¬½ûÓÃÔ¶³Ì½Ó¼û £¬²¢¸ü¸ÄĬÈÏÖÎÀíÔ¹ØÊ»§Í´´¦ÒÔ± £»¤É豸¡£


https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/


5. Illumina iSeq 100 DNA²âÐòÒÇ´æBIOS/UEFI·ì϶ £¬»òÖÂÉ豸±»½ûÓÃ


1ÔÂ7ÈÕ £¬ÃÀ¹úÉúÎï¼¼Êõ¹«Ë¾IlluminaµÄiSeq 100 DNA²âÐòÒDZ»·¢ÏÖ´æÔÚBIOS/UEFI·ì϶ £¬Õâ¿ÉÄÜ»áÈù¥»÷Õß½ûÓøÃÉ豸 £¬½ø¶øÓ°Ïì¼²²¡¼ì²âºÍÒßÃ翪·¢¡£¹Ì¼þ°²È«¹«Ë¾EclypsiumÔÚ·ÖÎöÖз¢ÏÖ £¬iSeq 100ÔËÐеÄÊǹýÆÚµÄBIOS¹Ì¼þ°æ±¾ £¬ÇÒδͨ¹ý°²È«Æô¶¯¼¼Êõ½øÐб £»¤ £¬´æÔÚ¶à¸ö·ì϶ £¬Ô̺¬BIOSд± £»¤È±Ê§¡¢Ò×ÊÜLogoFAIL¡¢Spectre 2ºÍ΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)¹¥»÷µÈ¡£ÕâЩ·ì϶ÔÊÐí¹¥»÷ÕßÅú¸ÄÆô¶¯É豸µÄ´úÂë £¬ÉõÖÁ´Û¸Ä²âÊÔÁ˾Ö¡£EclypsiumÇ¿µ÷ £¬ÕâЩÎÊÌâ²»½öÏÞÓÚiSeq 100 £¬Ê¹ÓÃÒ»ÑùÖ÷°åµÄÆäËûÒ½ÁÆ»ò¹¤ÒµÉ豸Ҳ¿ÉÄÜ´æÔÚÀàËÆÎÊÌâ¡£IlluminaÒÑÏòÊÜÓ°ÏìµÄ¿Í»§°ä²¼Á˲¹¶¡ £¬µ«¹«Ë¾°µÊ¾³õ²½ÆÀ¹ÀÒÔΪÕâЩÎÊÌâ²¢²»ÓµÓи߷çÏÕ¡£È»¶ø £¬EclypsiumÖÒ¸æ³Æ £¬¿ÉÄܸ²¸ÇiSeq 100¹Ì¼þµÄÍþвÐÐΪÕßÄܹ»µÈÏнûÓøÃÉ豸 £¬Õâ¶ÔÓÚÀÕË÷Èí¼þ²Î¼ÓÕßÀ´ËµºÜÓÐÎüÒýÁ¦ £¬ÓÉÓÚ·ÛËé¸ß¼ÛֵϵͳÄܹ»ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£´Ë±í £¬¹ú¶ÈÐÐΪÕßÒ²¿ÉÄÜ·¢ÏÖDNA²âÐòϵͳºÜÓÐÎüÒýÁ¦ £¬ÓÉÓÚËüÃǶÔÓÚ¼²²¡¼ì²â¡¢ÒßÃç³ö²úµÈÖÁ¹Ø³ÁÒª¡£


https://www.bleepingcomputer.com/news/security/bios-flaws-expose-iseq-dna-sequencers-to-bootkit-attacks/


6. CISAÖҸ棺Oracle WebLogicÓëMitel MiCollabϵͳ´æÔÚÑϳÁ·ì϶


1ÔÂ7ÈÕ £¬CISAÒÑÏòÃÀ¹úÁª¹ú»ú¹¹·¢³öÖÒ¸æ £¬ÒªÇó¼Óǿϵͳ·À»¤ £¬ÒÔ·À±¸Oracle WebLogic ServerºÍMitel MiCollabϵͳÖдæÔÚµÄÑϳÁ·ì϶¡£ÆäÖÐ £¬MitelµÄMiCollabͳһͨѶƽ̨±»·¢ÏÖ´æÔڹؼüõè¾¶±éÀú·ì϶£¨CVE-2024-41713£© £¬ÔÊÐí¹¥»÷ÕßÖ´ÐÐδ¾­ÊÚȨµÄÖÎÀí²Ù×÷²¢½Ó¼ûÓû§ºÍÍøÂçÐÅÏ¢ £¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£Í¬Ê± £¬ÁíÒ»¸öMitel MiCollabõè¾¶±éÀú·ì϶£¨CVE-2024-55550£©ÔÊÐíÓµÓÐÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¶ÁÈ¡Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄËÁÒâÎļþ £¬µ«Ó°ÏìÓÐÏÞ¡£´Ë±í £¬Oracle WebLogic ServerµÄÒ»¸öÑϳÁ·ì϶£¨CVE-2020-2883£©Ò²ÓÚËÄÄêǰµÃµ½½¨²¹ £¬µ«Î´½¨²¹µÄ·þÎñÆ÷ÈÔÃæ¶ÔÔ¶³ÌÈëÇÖ·çÏÕ¡£CISA½«ÕâÈý¸ö·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖÐ £¬²¢ÏóÕ÷Ϊ±»»ý¼«ÀûÓà £¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ»ú¹¹Ôڹ水¹¦·òÄÚ± £»¤ÆäÍøÂç¡£¹ÌÈ»¸ÃĿ¼³Áµã¹Ø×¢ÃÀ¹úÁª¹ú»ú¹¹ £¬µ«½¨ÒéËùÓÐ×éÖ¯ÓÅÏÈ»º½âÕâЩ°²È«·ì϶ £¬ÒÔ×èÖ¹ÔÚ½øÐеĹ¥»÷¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/