Windows Bug½«´òÓ¡»ú³Á¶¨ÃûΪHP LaserJet M101-M106
°ä²¼¹¦·ò 2023-12-071¡¢Windows Bug½«´òÓ¡»ú³Á¶¨ÃûΪHP LaserJet M101-M106
¾ÝýÌå12ÔÂ5ÈÕ±¨Â·£¬Windows³öÏÖBug½«ËùÓдòÓ¡»ú³Á¶¨ÃûΪHP LaserJet M101-M106£¬²¢×Ô¶¯×°ÖÃHP SmartÀûÓá£×ÔÉÏÖÜÒÔÀ´£¬Óû§Ò»ÏòÔڻ㱨´ËÎÊÌâ¡£×î³õһЩÓû§ÒÔΪËûÃǵÄϵͳÔâµ½Á˹¥»÷£¬µ«MicrosoftÏÖÒÑÈ·ÈÏÕâÊÇÒ»¸öÓ°Ïì¿Í»§¶Ë£¨Windows 10 1809¼°¸ü¸ß°æ±¾£©ºÍ·þÎñÆ÷£¨Windows Server 2012¼°¸ü¸ß°æ±¾£©µÄÎÊÌâ¡£ËùÓдòÓ¡»ú£¬ÎÞÂÛÆäÔʼÔì×÷ÉÌÈôºÎ£¬¶¼½«±»³ÁÐÂÏóÕ÷ΪHP´òÓ¡»ú£¬´òÓ¡»úͼ±êÒ²¿ÉÄÜ»á¸ü¸Ä¡£µ±Óû§³¢ÊÔ´ò¿ª´òÓ¡»úʱ£¬»¹¿ÉÄÜ¿´µ½ÃýÎóÐÂÎÅ¡°´ËÒ³ÃæÃ»ÓпÉÓõŤ×÷¡±¡£Ô¤¼Æ´òÓ¡¹ý³Ì²»»áÊܵ½Ó°Ï죬ÎÊÌâÈÔÔÚµ÷²éÖС£
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-bug-renames-printers-to-hp-laserjet-m101-m106/
2¡¢ForescoutÅû¶ӰÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸ö·ì϶
ForescoutÔÚ12ÔÂ5ÈÕÅû¶ÁËÓ°ÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸ö·ì϶£¬Í³³ÆÎª¡°Sierra:21¡±¡£ÕâЩ·ì϶´æÔÚÓÚSierra AirLink·äÎÑ·ÓÉÆ÷£¬ÒÔ¼°TinyXMLºÍOpenNDS×é¼þÖС£×êÑÐÈËÔ±³Æ£¬¹¥»÷ÕßÄܹ»ÀûÓÃÆäÖÐһЩ·ì϶ÆëÈ«½ÚÔì¹Ø¼ü»ù´¡ÉèÊ©ÖеÄOT/IoT·ÓÉÆ÷£¬´Ó¶øµ¼ÖÂÍøÂçÖжϡ¢¼äµý»î¶¯»òºáÏò×ªÒÆºÍ¶ñÒâÈí¼þ×°Öá£ShodanɨÃè·¢ÏÖÁ˹ؼü»ù´¡ÉèÊ©Öг¬¹ý86000¸öÒ×±»¹¥»÷µÄAirLink·ÓÉÆ÷£¬ÆäÖдóÎÞÊýλÓÚÃÀ¹ú£¨Ô¼80%£©£¬Æä´ÎÊǼÓÄô󡢰ĴóÀûÑÇ¡¢·¨¹úºÍÌ©¹ú¡£
https://www.forescout.com/blog/sierra21-supply-chain-vulnerabilities-iot-ot-routers/
3¡¢°²È«»ú¹¹³ÆColdFusion·ì϶±»ÀûÓù¥»÷ÃÀ¹úÈ·µ±¾Ö»ú¹¹
ÃÀ¹úCISAÓÚ12ÔÂ5Èճƣ¬¹¥»÷ÕßÀûÓÃAdobe ColdFusion·ì϶£¨CVE-2023-26360£©À´»ñÈ¡¶Ôµ±¾Ö»ú¹¹·þÎñÆ÷µÄ³õʼ½Ó¼ûȨÏÞ¡£ÕâÊÇÒ»¸ö²»ÕýÈ·µÄ½Ó¼û½ÚÔì·ì϶£¬ÒÑÓÚ½ñÄê3Ô·ݱ»½¨¸´¡£CISA¹«¿ªÁËÀûÓø÷ì϶µÄÁ½´Î¹¥»÷»î¶¯£¬µÚһ·ÊÂÎñ²úÉúÔÚ6ÔÂ26ÈÕ£¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2016.0.0.3µÄ·þÎñÆ÷£»µÚ¶þÆðÊÂÎñ²úÉúÔÚ6ÔÂ2ÈÕ£¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2021.0.0.2µÄ·þÎñÆ÷¡£×êÑÐÈËÔ±ÒÔΪÕâÊÇ¿úËŻµÄÒ»²¿ÃÅ£¬Éв»Ã÷ÏÔÁ½´ÎÈëÇÖÊÇ·ñÊÇͳһ¹¥»÷ÕßËùΪ¡£
https://securityaffairs.com/155289/security/us-govt-adobe-coldfusion-flaw.html
4¡¢IT·þÎñºÍÕ÷ѯ¹«Ë¾HTCÔâµ½ALPHV¹¥»÷²¿ÃÅÊý¾Ýй¶
¾Ý12ÔÂ5ÈÕ±¨Â·£¬IT·þÎñºÍóÒ×Õ÷ѯ¹«Ë¾HTC Global ServicesÔâµ½ÁËALPHVµÄ¹¥»÷¡£ALPHVÒѽ«HTCÁÐÔÚÆäÍøÕ¾ÉÏ£¬²¢¸½ÉÏÁ˱»µÁÊý¾ÝµÄ½ØÍ¼£¬Ô̺¬»¤ÕÕ¡¢ÁªÏµÈËÃûµ¥¡¢µç×ÓÓʼþºÍ»úÃÜÎļþµÈ¡£¹ÌÈ»ÓйØHTC¹¥»÷µÄÐÅÏ¢ºÜÉÙ£¬µ«×êÑÐÈËÔ±ÒÔΪ¹¥»÷Ô´ÓÚCitrix Bleed·ì϶¡£¾ÝϤ£¬HTCµÄÒµÎñ²¿ÃÅÖ®Ò»CareTechÔËÓª×Å´æÔÚ·ì϶µÄCitrix NetscalerÉ豸£¬±»ÓÃÀ´¶Ô¹«Ë¾ÍøÂç½øÐгõʼ½Ó¼û¡£
https://www.bleepingcomputer.com/news/security/htc-global-services-confirms-cyberattack-after-data-leaked-online/
5¡¢Google PlayÉÏÊ®Êý¸ö¶ñÒâ´û¿îÀûÓÃÏÂÔØ³¬¹ý1200Íò´Î
12ÔÂ5ÈÕ£¬ESET°ä²¼»ã±¨£¬ÃèÊöÁËAndroid¶ñÒâ´û¿îÀûÓõÄÔö³¤¼°ÆäÓÃÀ´ÈƹýGoogle PlayµÄ¼¼Êõ¡£×Ô½ñÄêËêÊ×ÒÔÀ´£¬ESETÒÑ·¢ÏÖ18¸ö¶ñÒâ´û¿îÀûÓ÷¨Ê½£¨Í³³ÆÎªSpyLoan£©£¬ÔÚGoogle PlayµÄÏÂÔØÁ¿³¬¹ý1200Íò´Î¡£µ«ÓÉÓÚËüÃÇ»¹¿É´ÓµÚÈý·½É̵êºÍ¿ÉÒÉÍøÕ¾¸ßµÍÔØ£¬Òò¶øÏÖʵÏÂÔØÁ¿Òª¶àµÃ¶à¡£SpyLoan»á´ÓÉ豸ÖÐÇÔÈ¡Ó×ÎÒÐÅÏ¢£¬¼ÙÒâºÏ·¨µÄ´û¿î½ðÈÚ·þÎñ£¬ÓÕÆÓû§½ÓÊܸßÏ¢¸¶¿î£¬¶øºóɧÈŲ¢ÀÕË÷Ö¸±ê¸¶¿î¡£
https://www.welivesecurity.com/en/eset-research/beware-predatory-fintech-loan-sharks-use-android-apps-reach-new-depths/
6¡¢Kaspersky°ä²¼¹ØÓÚÕë¶ÔmacOSµÄÐÂľÂíµÄ·ÖÎö»ã±¨
12ÔÂ5ÈÕ£¬Kaspersky³ÆÆä·¢ÏÖÁËÕë¶ÔmacOSµÄÐÂÐͶñÒâ¼ÓÔØ·¨Ê½£¬¿ÉÄÜÓëÃûΪRustBucketµÄ»î¶¯Óйء£ÔçÆÚµÄRustBucket°æ±¾¼Ù×°³ÉPDFÔĶÁÆ÷£¬¶øÕâÖÖбäÌåÊÇÔÚÒ»¸öZIPÎĵµÖз¢Ïֵģ¬ÔªÊý¾ÝÏÔʾÀûÓô´½¨ÓÚ½ñÄê10ÔÂ21ÈÕ¡£¶ñÒâÀûÓñ»·¢ÏÖʱӵÓÐÓÐЧÊðÃû£¬µ«Ö¤ÊéÒѱ»³·Ïú¡£¿ÉÖ´ÐÐÎļþÓÃSwift¿ª·¢£¬ÃûΪ"EdoneViewer"£¬Ô̺¬IntelºÍApple SiliconоƬµÄ°æ±¾¡£²»ÐÒµÄÊÇ£¬×êÑÐÈËԱûÓÐÊÕµ½À´×Ô·þÎñÆ÷µÄÈκκÅÁÒò¶øÎÞ·¨´§¶ÈºóÐø¹¥»÷µÄÄÚÈÝ¡£
https://securelist.com/bluenoroff-new-macos-malware/111290/


¾©¹«Íø°²±¸11010802024551ºÅ