΢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î
Ðû²¼Ê±¼ä 2024-01-101¡¢Î¢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î
¾ÝýÌå1ÔÂ9ÈÕ±¨µÀ£¬Î¢ÈíÐû²¼ÁË2024Äê1Ô·ݵÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË49¸öÎó²î¡£±¾ÔÂÐÞ¸´µÄ½ÏÁ¿ÓÐȤµÄÎó²îÊÇOfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-20677£©£¬¿É±»ÓÃÀ´Í¨¹ýʹÓÃǶÈëʽFBX 3DÄ£×ÓÎļþ½¨Éè¶ñÒâÖÆ×÷µÄOfficeÎĵµ£¬À´Ô¶³ÌÖ´ÐдúÂë¡£ÁíÒ»¸öÊÇWindows KerberosÖеÄÉí·ÝÑéÖ¤ÈƹýÎó²î£¨CVE-2024-20674£©£¬¹¥»÷Õß¿ÉÒÔͨ¹ýMITM¹¥»÷»òÆäËûÍâµØÍøÂçÓÕÆÊÖÒÕÀ´Ê¹ÓôËÎó²î£¬Ïò¿Í»§¶Ë·¢ËͶñÒâKerberosÐÂÎÅ£¬½«×Ô¼ºÎ±×°³ÉKerberosÉí·ÝÑéÖ¤·þÎñÆ÷¡£
2¡¢LockBitÍþвҪ¹ûÕæCapital HealthÔ¼7TBµÄÊý¾Ý
¾Ý1ÔÂ9ÈÕ±¨µÀ£¬LockBitÉù³ÆÒÑÈëÇÖCapital Health£¬²¢ÍþвҪ鶱»µÁÊý¾ÝºÍ̸ÅÐ̸Ìì¼Í¼¡£2023Äê11Ô£¬Capital HealthÔÚÔâµ½¹¥»÷ºóϵͳ·ºÆðÖÐÖ¹£¬²¢ÌåÏÖ¸ÃÊÂÎñ½«Ó°ÏìÆäÔËÓªÖÁÉÙÒ»ÖÜ¡£LockBitÔÚ8ÈÕ½«¸ÃÒ½ÁÆ»ú¹¹ÁÐÈëÆäÍøÕ¾£¬Éù³ÆÇÔÈ¡ÁË7 TBµÄÒ½ÁÆÊý¾Ý¡£»¹Íþв³ÆÈôÊǸûú¹¹Î´ÄÜÖª×ãËûÃǵÄÒªÇó£¬ËûÃǾͻáÔÚ1ÔÂ9ÈÕй¶ÕâЩÊý¾Ý¡£
3¡¢¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½Ransomexx¹¥»÷Áè¼Ý2GBÊý¾Ýй¶
1ÔÂ8ÈÕ±¨µÀ³Æ£¬·ÇÖÞ×î´óµÄº½¿Õ¹«Ë¾Ö®Ò»¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½ÁËRansomexxÀÕË÷ÍÅ»ïµÄ¹¥»÷¡£¹¥»÷ÕßÔÚ°µÍøÐû²¼Á˾ݳÆÊǴӸú½¿Õ¹«Ë¾ÇÔÈ¡µÄÁè¼Ý2 GBÊý¾Ý£¬Êý¾ÝÊ÷ÏÔʾ£¬°üÀ¨Ê¹ʱ¨¸æ¡¢»¤ÕÕ¸´Ó¡¼þºÍÖÖÖÖ¿ÕÄѱ¨¸æ¡£¹¥»÷ÕßÔÚÐû²¼Ìû×Óʱ£¬Ê×ÏÈÉÏ´«ÁËÒ»ÕžݳÆÊÇ¿ÏÄáÑǺ½¿Õ¹«Ë¾Ò»¼Ü·É»úÒýÇæÊÜËðµÄͼƬ£¬Êý¾ÝÑù±¾Öл¹°üÀ¨Ò»Ð©ÎÞ¹éÊôϵͳµÄÖÖÖÖÃÜÂë¡£ÏÖÔÚ£¬¿ÏÄáÑǺ½¿Õ¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£
4¡¢Fortinet·¢Ã÷ͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄÔ˶¯
FortinetÔÚ1ÔÂ8ÈÕÅû¶ÁËͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ¹¥»÷Ô˶¯¡£¹¥»÷ÕßÊ×ÏÈ»áÈëÇÖYouTubeµÄÕÊ»§£¬²¢ÉÏ´«Î±×°³É¹²ÏíÆƽâÈí¼þµÄÊÓƵ¡£È«ÐÄÖÆ×÷µÄ×°ÖÃZIPÎļþÊÇ·Ö·¢payloadµÄÓÕ¶ü£¬ËüʹÓÃÁËÓû§×°ÖÃÓ¦ÓõÄÒâͼ£¬´ÙʹÓû§¾ø²»ÓÌÔ¥ËùÔÚ»÷×°ÖÃÎļþ¡£Õû¸öÔ˶¯ÖеÄURLÀ´×Ô¿ªÔ´ÍøÕ¾£¬Ä¿µÄÊÇÏ÷ÈõÓû§µÄÇå¾²Òâʶ¡£¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö˽ÓÐ.NET¼ÓÔسÌÐò£¬Ëü¾ßÓÐÇéÐμì²é¡¢ÖÖÖÖAnti-VMºÍ·´µ÷ÊÔ¹¦Ð§¡£
5¡¢É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿Ãô¸ÐÊý¾Ýй¶¿ÉÓÃÓÚÄÚÍø¹¥»÷
ýÌå1ÔÂ8Èճƣ¬É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿(MIM)µÄÇéÐÎÎļþ(env.)й¶³¤´ï15¸öÔ¡£Ì»Â¶µÄenv.Éæ¼°Á˶àÖÖÀàÐ͵ÄÊý¾Ý¿âƾ֤¡¢Óʼþƾ֤ºÍÊý¾Ý¼ÓÃÜÃÜÔ¿£¬ÀýÈçSMTPƾ֤¡¢Laravel APP_Key¡¢MySQLºÍRedisÊý¾Ý¿âµÄƾ֤µÈ¡£Ð¹Â¶µÄÐÅÏ¢¿É±»¹¥»÷ÕßÓÃÓÚÔڸò¿ÏµÍ³ÄÚ¾ÙÐкáÏòÒƶ¯£¬²¢µ¼ÖÂÕÊ»§½ÓÊܺÍÀÕË÷¹¥»÷µÈÖÖÖÖ¹¥»÷¡£¸ÃÎļþÔÚ2022Äê3ÔÂÊ״α»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬ÏÖÔÚÒѱ»±£»¤ÆðÀ´¡£
6¡¢Ñо¿Ö°Ô±Ðû²¼2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ
1ÔÂ3ÈÕ£¬CisoµÄÑо¿Ö°Ô±Jerry GamblinÐû²¼ÁË2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ¡£±¨¸æÖ¸³ö£¬×èÖ¹2023Äê¹²Ðû²¼ÁË28902¸öCVE£¬±È2022ÄêµÄ25081¸öCVEÔöÌíÁË15%ÒÔÉÏ¡£Æ½¾ùÌìÌìÐû²¼79.18¸ö¡£10ÔÂÊÇÐû²¼CVE×î¶àµÄÔ·ݣ¬¹²2690¸ö£¬Õ¼ÕûÄêµÄ9.3%¡£´ÓÑÏÖØˮƽÀ´¿´£¬2023ÄêCVEµÄƽ¾ùCVSSÆÀ·ÖΪ7.12£¬ÆäÖÐ36¸öÎó²îµÄÆÀ·ÖΪ10.0¡£×î³£·ÖÅɵij£¼ûÎó²îö¾Ù(CWE)±êʶ·ûÀàÐÍÊÇCWE-79£¬¼´ÍøÒ³ÌìÉúʱ´úÊäÈëµÄÖкͲ»µ±£¬Ò²³ÆΪXSS£¬È¥ÄêÓÐ4100¶à¸öCVE±»·ÖÀàΪXSSÎó²î¡£