×êÑÐÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄ°²È«·ì϶

°ä²¼¹¦·ò 2023-11-24
1¡¢×êÑÐÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄ°²È«·ì϶


¾ÝýÌå11ÔÂ22ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖÁ˶à¸ö·ì϶£¬¿ÉÓÃÀ´ÈƹýDell Inspiron 15¡¢Lenovo ThinkPad T14ºÍMicrosoft Surface Pro X±Ê¼Ç±¾µçÄÔÉϵÄWindows HelloÉí·ÝÑéÖ¤¡£ËùÓвâÊÔµÄÖ¸ÎÆ´«¸ÐÆ÷¶¼ÊÇMatch-on-Chip (MoC)´«¸ÐÆ÷£¬¹ÌÈ»MoC´«¸ÐÆ÷Äܹ»×èÖ¹½«´æ´¢µÄÖ¸ÎÆÊý¾Ý³Á·Åµ½Ö÷»ú½øÐÐÆ¥Å䣬µ«ËüÃÇ×ÔÉí²¢²»ÄÜ×èÖ¹¶ñÒâ´«¸ÐÆ÷·ÂÕպϷ¨´«¸ÐÆ÷ÓëÖ÷»ú½øÐÐͨѶ¡£Õâ¿ÉÄÜ»áÃýÎóµØÏÔʾÓû§Éí·ÝÑéÖ¤³É¹¦£¬»ò³Á·Å֮ǰµÄÖ÷»úºÍ´«¸ÐÆ÷Ö®¼äµÄÁ÷Á¿¡£Îª´Ë£¬Î¢Èí¿ª·¢Á˰²È«É豸ÏνӺÍ̸£¨SDCP£©£¬µ«×êÑÐÈËÔ±»¹ÊÇÀûÓÃMiTM¹¥»÷³É¹¦ÈƹýÁËWindows HelloÉí·ÝÑéÖ¤¡£


https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html


2¡¢º«¹úIT¹«Ë¾TmaxSoftÅäÖÃÃýÎ󳬹ý5000Íò±Ê¼Í¼й¶


¾Ý11ÔÂ22ÈÕ±¨Â·£¬º«¹úIT¹«Ë¾TmaxSoftÔ¼2TBµÄÊý¾ÝÒѹ«¿ª³¬¹ýÁ½Äê¡£×êÑÐÈËÔ±ÔçÔÚ½ñÄê1Ô¾ͷ¢ÏÖÁËÒ»¸ö¶³öµÄKibana½ÚÔìÃæ°å£¬²¢Ö¸³öÕâ×éÊý¾ÝÓÚ2021Äê6Ô³õ´Î±»·¢ÏÖ¡£Êý¾Ý¿â×ܹ²Óг¬¹ý5600Íò±Ê¼Í¼£¬Ô̺¬Ô±¹¤ÐÕÃûºÍµç»°¡¢¹ÍÓ¶ºÏͬºÅ¡¢·¢Ë͵ĸ½¼þºÍ¶þ½øÔìÎļþµÄÔªÊý¾ÝµÈ¡£²»ÐÒµÄÊÇ£¬¸Ã¹«Ë¾ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´£¬²¢ÇÒÔ̺¬´óÁ¿Êý¾ÝµÄ½ÚÔìÃæ°åÒÀÈ»´¦ÓÚ¹«¿ª×´Ì¬¡£


https://securityaffairs.com/154567/data-breach/tmaxsoft-leaks-2tb-of-data.html


3¡¢Î¢ÈíÅû¶Diamond SleetÀûÓÃCyberLinkµÄ¹©¸øÁ´¹¥»÷


΢ÈíÔÚ11ÔÂ22ÈÕÅû¶Á˳¯ÏʺڿÍÍÅ»ïDiamond Sleet(ZINC)ÌáÒéµÄ¹©¸øÁ´¹¥»÷¡£×êÑÐÈËÔ±ÔÚ10ÔÂ20Èչ۲쵽ÁËÕâ´Î¿ÉÒɻ£¬Ëü¶ÔÖйų́Íå¶àýÌåÈí¼þ¹«Ë¾CyberLink¿ª·¢µÄÀûÓ÷¨Ê½½øÐÐľÂí»¯¡£¶ñÒâÎļþʹÓÃCyberLinkÐû¸æµÄÓÐЧ֤Êé½øÐÐÊðÃû£¬ÍйÜÔڸù«Ë¾Õ¼ÓеĺϷ¨µÄ¸üлù´¡ÉèÊ©ÉÏ¡£Æù½ñΪֹ£¬¸Ã¶ñÒâ»î¶¯ÒÑÓ°Ïì¶à¸ö¹ú¶È/µØÓòµÄ100¶ą̀É豸£¬Ô̺¬ÈÕ±¾¡¢Öйų́Íå¡¢¼ÓÄôóºÍÃÀ¹ú¡£


https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/


4¡¢Blenderй©³ÖÐøµÄDDoS¹¥»÷µ¼ÖÂÆä·þÎñÆ÷å´»úÊýÈÕ


ýÌå11ÔÂ22Èճƣ¬Blenderй©×î½üµÄÍøÕ¾·þÎñÖжÏÊdzÖÐøµÄDDoS¹¥»÷µ¼ÖµÄ¡£¸ÃÏîÄ¿ÍŶӰµÊ¾£¬×Ô11ÔÂ18ÈÕÒÔÀ´£¬blender.org·þÎñÆ÷¾ÍÔâµ½DDoS¹¥»÷£¬Æä·þÎñÆ÷ÒòÒªÇó¹ýÔØ¶øå´»ú¡£¼´±ãÔÚ¹¥»÷ÕßÔÝÍ£¹¥»÷µÄʱ³½£¬BlenderµÄ»ù´¡ÉèÊ©ÒÀÈ»Òò´óÁ¿´ý´¦ÖõĺϷ¨ÒªÇó¶ø¹ýÔØ¡£×îÖÕ£¬ÔÚ¾­ÀúÁË4ÌìµÄ³ÖÐøÖжϺ󣬸ÃÍŶӽ«ÆäÖ÷ÍøÕ¾×ªÒÆµ½ÁËCloudFlareÉÏ£¬ÕâÏ÷¼õ¹¥»÷µÄÓ°Ïì¡£Blender·ÖÏíµÄͳ¼ÆÊý¾ÝÏÔʾ£¬¹¥»÷ÈÔÔÚ³ÖÐø£¬Õë¶Ô¸ÃÏîÄ¿·þÎñÆ÷µÄÐéαҪÇ󳬹ý2.4ÒڴΡ£


https://www.bleepingcomputer.com/news/security/open-source-blender-project-battling-ddos-attacks-since-saturday/


5¡¢Akamai°ä²¼Ð½©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö»ã±¨


11ÔÂ21ÈÕ£¬Akamai°ä²¼»ùÓÚMiraiµÄн©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö»ã±¨¡£InfectedSlursÒ»ÏòÔÚÀûÓÃÁ½¸öRCE·ì϶À´Ï°È¾Â·ÓÉÆ÷ºÍ¼Ïñ»ú(NVR)É豸£¬×êÑÐÈËÔ±ÓÚ½ñÄê10Ô·¢ÏÖÁ˸ý©Ê¬ÍøÂ磬²¢ÒÔΪËüÖÁÉÙ´Ó2022ÄêÆð¾ÍÒ»Ïò»îÔ¾¡£ËüÊÇJenX MiraiµÄ±äÌ壬ÓÉÓÚÔÚC2ÓòºÍÓ²±àÂë×Ö·û´®ÖÐʹÓù¥»÷ÐÔ˵»°¶øµÃÃû¡£ÆäC2»ù´¡ÉèÊ©Ïà¶Ô¼¯ÖУ¬ËƺõÒ²Ö§³ÖhailBotµÄÔËÐС£¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°Ï칩¸øÉ̵ÄÃû³Æ£¬µ«¹©¸øÉ̳Ðŵ½«ÓÚ12Ô°䲼°²È«¸üС£


https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days


6¡¢Kaspersky°ä²¼2024ÄêÏû·ÑÕßÍøÂçÍþвµÄÔ¤²â»ã±¨


11ÔÂ23ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚ2024ÄêÏû·ÑÕßÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨¡£×êÑÐÈËÔ±¶Ô2024Äê×ö³öÁËÕ°Íû£¬Ô̺¬¸ü¶à´È±¯ÓйصÄÚ¿Æ­¼´½«À´ÁÙ¡¢ÍøÉÏÉ̵꽫Óë´È±¯»ú¹¹µÄºÏ×÷¡¢»¥ÁªÍø»®·Ö¸üϸ¡¢VPN·þÎñ³ÊÉÏÉýÇ÷Ïò¡¢°²È«ÐÔ¸ßÓÚÓû§Êæ·þ¶È½«´ßÉúÐµİ²È«ÎÊÌâ¡¢ÍøÂç¹¥»÷Õß½«Õë¶ÔP2E¡¢¿ª·¢Í¨ÓõÄDeepfake²é³­¹¤¾ß¡¢ÓïÒôDeepfakeÊÂÎñÔö¶àÒÔ¼°ÒÔµçÓ°Ê×ӳΪµö¶üµÄȦÌ×Ôö¶àµÈ¡£


https://securelist.com/kaspersky-security-bulletin-consumer-threats-2024/111135/