΢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î

Ðû²¼Ê±¼ä 2024-01-10

1¡¢Î¢ÈíÐû²¼1Ô·ÝÇå¾²¸üÐÂ×ܼÆÐÞ¸´49¸öÎó²î


¾ÝýÌå1ÔÂ9ÈÕ±¨µÀ£¬ £¬£¬£¬£¬Î¢ÈíÐû²¼ÁË2024Äê1Ô·ݵÄÖܶþ²¹¶¡£¬ £¬£¬£¬£¬×ܼÆÐÞ¸´ÁË49¸öÎó²î¡£¡£¡£±¾ÔÂÐÞ¸´µÄ½ÏÁ¿ÓÐȤµÄÎó²îÊÇOfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-20677£©£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´Í¨¹ýʹÓÃǶÈëʽFBX 3DÄ£×ÓÎļþ½¨Éè¶ñÒâÖÆ×÷µÄOfficeÎĵµ£¬ £¬£¬£¬£¬À´Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£ÁíÒ»¸öÊÇWindows KerberosÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-20674£©£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýMITM¹¥»÷»òÆäËûÍâµØÍøÂçÓÕÆ­ÊÖÒÕÀ´Ê¹ÓôËÎó²î£¬ £¬£¬£¬£¬Ïò¿Í»§¶Ë·¢ËͶñÒâKerberosÐÂÎÅ£¬ £¬£¬£¬£¬½«×Ô¼ºÎ±×°³ÉKerberosÉí·ÝÑé֤ЧÀÍÆ÷¡£¡£¡£


2¡¢LockBitÍþвҪ¹ûÕæCapital HealthÔ¼7TBµÄÊý¾Ý


¾Ý1ÔÂ9ÈÕ±¨µÀ£¬ £¬£¬£¬£¬LockBitÉù³ÆÒÑÈëÇÖCapital Health£¬ £¬£¬£¬£¬²¢ÍþвҪй¶±»µÁÊý¾ÝºÍ̸ÅÐ̸Ìì¼Í¼¡£¡£¡£2023Äê11Ô£¬ £¬£¬£¬£¬Capital HealthÔÚÔâµ½¹¥»÷ºóϵͳ·ºÆðÖÐÖ¹£¬ £¬£¬£¬£¬²¢ÌåÏÖ¸ÃÊÂÎñ½«Ó°ÏìÆäÔËÓªÖÁÉÙÒ»ÖÜ¡£¡£¡£LockBitÔÚ8ÈÕ½«¸ÃÒ½ÁÆ»ú¹¹ÁÐÈëÆäÍøÕ¾£¬ £¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË7 TBµÄÒ½ÁÆÊý¾Ý¡£¡£¡£»£»£»£»£»¹Íþв³ÆÈôÊǸûú¹¹Î´ÄÜÖª×ãËûÃǵÄÒªÇó£¬ £¬£¬£¬£¬ËûÃǾͻáÔÚ1ÔÂ9ÈÕй¶ÕâЩÊý¾Ý¡£¡£¡£


3¡¢¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½Ransomexx¹¥»÷Áè¼Ý2GBÊý¾Ýй¶


1ÔÂ8ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬·ÇÖÞ×î´óµÄº½¿Õ¹«Ë¾Ö®Ò»¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½ÁËRansomexxÀÕË÷ÍÅ»ïµÄ¹¥»÷¡£¡£¡£¹¥»÷ÕßÔÚ°µÍøÐû²¼Á˾ݳÆÊǴӸú½¿Õ¹«Ë¾ÇÔÈ¡µÄÁè¼Ý2 GBÊý¾Ý£¬ £¬£¬£¬£¬Êý¾ÝÊ÷ÏÔʾ£¬ £¬£¬£¬£¬°üÀ¨Ê¹ʱ¨¸æ¡¢»¤ÕÕ¸´Ó¡¼þºÍÖÖÖÖ¿ÕÄѱ¨¸æ¡£¡£¡£¹¥»÷ÕßÔÚÐû²¼Ìû×Óʱ£¬ £¬£¬£¬£¬Ê×ÏÈÉÏ´«ÁËÒ»ÕžݳÆÊÇ¿ÏÄáÑǺ½¿Õ¹«Ë¾Ò»¼Ü·É»úÒýÇæÊÜËðµÄͼƬ£¬ £¬£¬£¬£¬Êý¾ÝÑù±¾Öл¹°üÀ¨Ò»Ð©ÎÞ¹éÊôϵͳµÄÖÖÖÖÃÜÂë¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬¿ÏÄáÑǺ½¿Õ¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£


4¡¢Fortinet·¢Ã÷ͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ»î¶¯


FortinetÔÚ1ÔÂ8ÈÕÅû¶ÁËͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ¹¥»÷»î¶¯¡£¡£¡£¹¥»÷ÕßÊ×ÏÈ»áÈëÇÖYouTubeµÄÕÊ»§£¬ £¬£¬£¬£¬²¢ÉÏ´«Î±×°³É¹²ÏíÆÆ½âÈí¼þµÄÊÓÆµ¡£¡£¡£È«ÐÄÖÆ×÷µÄ×°ÖÃZIPÎļþÊÇ·Ö·¢payloadµÄÓÕ¶ü£¬ £¬£¬£¬£¬ËüʹÓÃÁËÓû§×°ÖÃÓ¦ÓõÄÒâͼ£¬ £¬£¬£¬£¬´ÙʹÓû§¾ø²»ÓÌÔ¥ËùÔÚ»÷×°ÖÃÎļþ¡£¡£¡£Õû¸ö»î¶¯ÖеÄURLÀ´×Ô¿ªÔ´ÍøÕ¾£¬ £¬£¬£¬£¬Ä¿µÄÊÇÏ÷ÈõÓû§µÄÇå¾²Òâʶ¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö˽ÓÐ.NET¼ÓÔØ³ÌÐò£¬ £¬£¬£¬£¬Ëü¾ßÓÐÇéÐμì²é¡¢ÖÖÖÖAnti-VMºÍ·´µ÷ÊÔ¹¦Ð§¡£¡£¡£


5¡¢É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿Ãô¸ÐÊý¾Ýй¶¿ÉÓÃÓÚÄÚÍø¹¥»÷


ýÌå1ÔÂ8Èճƣ¬ £¬£¬£¬£¬É³Ìع¤ÒµºÍ¿ó²ú×ÊÔ´²¿(MIM)µÄÇéÐÎÎļþ(env.)й¶³¤´ï15¸öÔ¡£¡£¡£Ì»Â¶µÄenv.Éæ¼°Á˶àÖÖÀàÐ͵ÄÊý¾Ý¿âƾ֤¡¢Óʼþƾ֤ºÍÊý¾Ý¼ÓÃÜÃÜÔ¿£¬ £¬£¬£¬£¬ÀýÈçSMTPƾ֤¡¢Laravel APP_Key¡¢MySQLºÍRedisÊý¾Ý¿âµÄƾ֤µÈ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢¿É±»¹¥»÷ÕßÓÃÓÚÔڸò¿ÏµÍ³ÄÚ¾ÙÐкáÏòÒÆ¶¯£¬ £¬£¬£¬£¬²¢µ¼ÖÂÕÊ»§½ÓÊܺÍÀÕË÷¹¥»÷µÈÖÖÖÖ¹¥»÷¡£¡£¡£¸ÃÎļþÔÚ2022Äê3ÔÂÊ״α»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬ £¬£¬£¬£¬ÏÖÔÚÒѱ»±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£


6¡¢Ñо¿Ö°Ô±Ðû²¼2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ


1ÔÂ3ÈÕ£¬ £¬£¬£¬£¬CisoµÄÑо¿Ö°Ô±Jerry GamblinÐû²¼ÁË2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬×èÖ¹2023Äê¹²Ðû²¼ÁË28902¸öCVE£¬ £¬£¬£¬£¬±È2022ÄêµÄ25081¸öCVEÔöÌíÁË15%ÒÔÉÏ¡£¡£¡£Æ½¾ùÌìÌìÐû²¼79.18¸ö¡£¡£¡£10ÔÂÊÇÐû²¼CVE×î¶àµÄÔ·Ý£¬ £¬£¬£¬£¬¹²2690¸ö£¬ £¬£¬£¬£¬Õ¼ÕûÄêµÄ9.3%¡£¡£¡£´ÓÑÏÖØË®Æ½À´¿´£¬ £¬£¬£¬£¬2023ÄêCVEµÄƽ¾ùCVSSÆÀ·ÖΪ7.12£¬ £¬£¬£¬£¬ÆäÖÐ36¸öÎó²îµÄÆÀ·ÖΪ10.0¡£¡£¡£×î³£·ÖÅɵij£¼ûÎó²îö¾Ù(CWE)±êʶ·ûÀàÐÍÊÇCWE-79£¬ £¬£¬£¬£¬¼´ÍøÒ³ÌìÉúʱ´úÊäÈëµÄÖкͲ»µ±£¬ £¬£¬£¬£¬Ò²³ÆÎªXSS£¬ £¬£¬£¬£¬È¥ÄêÓÐ4100¶à¸öCVE±»·ÖÀàΪXSSÎó²î¡£¡£¡£