WindowsÀÛ»ý¸üе¼Ö²¿ÃÅWin11µÄWi-FiÏνÓÖжÏ
°ä²¼¹¦·ò 2023-12-20¾ÝýÌå12ÔÂ18ÈÕ±¨Â·£¬12ÔÂWindowsÀÛ»ý¸üÐÂKB5033375»áµ¼Ö²¿ÃÅWin 11É豸ÉϵÄWi-FiÏνӳöÏÖÎÊÌ⡣ƾ¾ÝÓû§µÄ»ã±¨£¬´ËÎÊÌâÓ°ÏìÆôÓÃfast-transition/fast-roamingÀ´ÍƽøÎÞÏß½ÓÈëµãÖ®¼äÎÞ·ìÉè±¸ÒÆ¶¯µÄÆóÒµÎÞÏßÍøÂç¡£×°ÖÃÁËKB5033375»òKB50532288µÄ¼ÒÍ¥Óû§ÉÐδ»ã±¨Óöµ½Wi-FiÏνÓÎÊÌâ¡£×÷Ϊһʱ½â¾ö¹æ»®£¬½¨ÒéÊÜ´ËÎÊÌâÓ°ÏìµÄÓû§Ð¶ÔØËùÓÐÓÐÎÊÌâµÄWin 11¸üС£µ¼Ö´ËÎÊÌâµÄÔÒòÈÔÔÚµ÷²éÖС£
https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/
2¡¢VF CorporationÔâµ½ÀÕË÷¹¥»÷£¬ÒµÎñÔËÓªÊܵ½Ó°Ïì
¾Ý12ÔÂ18ÈÕ±¨Â·£¬ÃÀ¹ú·þ×°ºÍЬÀ๫˾VF Corp.Ôâµ½ÍøÂç¹¥»÷£¬ÒµÎñÔËÓªÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾Õ¼ÓÐSupreme¡¢VansºÍThe North FaceµÈ13¸ö³ÛÃûÆ·ÅÆ£¬ÄêÊÕÈë¸ß´ï116ÒÚÃÀÔª¡£VFй©¹¥»÷²úÉúÓÚ12ÔÂ13ÈÕ£¬¸Ã¹«Ë¾¹Ø¹ØÁ˲¿ÃÅϵͳ×÷ΪӦ¶Ô´ëÊ©¡£È»¶ø£¬¹¥»÷Õß»¹ÊǼÓÃÜÁ˹«Ë¾µÄ²¿ÃÅÍÆËã»ú²¢ÇÔÈ¡ÁËÓ×ÎÒÊý¾Ý¡£¹ÌÈ»¸ÃÊÂÎñÓµÓÐÀÕË÷¹¥»÷µÄËùÓÐÌØµã£¬µ«½ØÖÁĿǰÉÐÎÞÀÕË÷ÍŻﰵʾ¶Ô´ËÊÂÕÆ¹Ü¡£½ØÖÁ18ÈÕ£¬¸Ã¹«Ë¾¹É¼Û×ÅÂä½ü9%¡£
https://www.securityweek.com/vf-corp-disrupted-by-cyberattack-online-operations-impacted/
3¡¢ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr.Cooperй©1470ÍòÈ˵ÄÊý¾Ýй¶
ýÌå12ÔÂ18Èճƣ¬ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr.Cooper½ü1470ÍòÈ˵ÄÐÅϢй¶¡£11Ô³õ£¬¸Ã¹«Ë¾°ä·¢ÔÚ10ÔÂ30ÈÕÔâµ½ÈëÇÖ£¬²¢ÓÚ´ÎÈÕ·¢ÏÖÁËÕâÒ»Çé¿ö¡£Ö®ºó£¬¸Ã¹«Ë¾¹Ø¹ØÁËÔ̺¬ÓÃÓÚÖ§¸¶´û¿îºÍµÖѺ´û¿îµÄÔÚÏßÖ§¸¼ûÅ»§ÔÚÄÚµÄËùÓÐϵͳ£¬À´Ó¦¶Ô¹¥»÷¡£¾µ÷²é£¬Õâ´ÎÊÂÎñÓ°ÏìÁË14690284ÈË£¬Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á°²È«ºÅÂë(SSN)¡¢µ®ÉúÈÕÆÚºÍÒøÐÐÕʺŵȡ£Mr.Cooper½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩ24¸öÔµÄÉí·Ý±£»¤·þÎñ¡£
https://therecord.media/mr-cooper-cyberattack-data-breach-notifications
4¡¢Òâ´óÀûWestpole±»LockbitÈëÇÖ±¾µØ¶àÏîÊÐÕþ·þÎñÖжÏ
12ÔÂ19ÈÕ±¨Â·³Æ£¬Òâ´óÀûÔÆ·þÎñÌṩÉÌWestpoleÔâµ½ÁËLockbitµÄÀÕË÷¹¥»÷¡£¹¥»÷²úÉúÓÚ12ÔÂ8ÈÕ£¬Ó°ÏìÁËWestpoleµÄ¿Í»§¹«Ë¾PA Digitale£¬ËüΪ1300¸ö¹«¹²ÖÎÀí»ú¹¹Ìṩ·þÎñ¡£¾ÝϤ£¬¹¥»÷ÕßʹÓÃÁËLockbit 3.0£¬µ¼Öºܶ๫¹²ÖÎÀí²¿ÃźÍÊÐÕþ»ú¹¹µÄ·þÎñÖжϣ¬²¿ÃųÇÊб»ÆÈ¸´ÔÈËΪÀ´Ìṩ·þÎñ¡£±¾µØÃ½Ì屨·£¬¹¥»÷¿ÉÄÜ»áÓ°ÏìһЩµ±¾Ö»ú¹¹Ô±¹¤12Ô·ݹ¤×ʵķ¢·Å¡£¹¥»÷Ôì³ÉµÄËðʧˮƽÄÑÒÔÆÀ¹À£¬La Repubblicaй©£¬Westpole½ö¸´ÔÁË50%µÄϵͳ£¬Òâ´óÀû°²È«»ú¹¹ACNÖ¸³ö¸´Ô¹ý³Ì»ºÂýÇÒÓµÓÐÌôÕ½ÐÔ¡£
https://securityaffairs.com/156090/cyber-crime/westpole-ransomware-attack.html
5¡¢Xfinity³ÆÆäCitrix·þÎñÆ÷±»ºÚÒÑÒªÇóÓû§³ÁÖÃÃÜÂë
ýÌå12ÔÂ18ÈÕ±¨Â·£¬ComcastÓÐÏßͨѶ¹«Ë¾£¨ÒÔXfinityÃûÒå·¢Õ¹ÒµÎñ£©Ð¹Â©£¬ÆäCitrix·þÎñÆ÷±»ºÚ£¬²¿Ãſͻ§µÄÐÅϢй¶¡£10ÔÂ25ÈÕ£¬¼´Citrix½¨¸´Citrix Bleed·ì϶£¨CVE-2023-4966£©Á½Öܺó£¬Õâ¼ÒµçÐŹ«Ë¾·¢ÏÖ10ÔÂ16ÈÕÖÁ19ÈյĶñÒâ»î¶¯¡£XfinityÓÚ11ÔÂ16ÈÕ·¢ÏÖ£¬¹¥»÷Õß»¹´ÓÆäϵͳÖÐÇÔÈ¡ÁË35879455È˵ÄÊý¾Ý£¬²¢ÓÚ12ÔÂ6ÈÕÈ·¶¨£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§ÃûºÍ¹þÏ£ÃÜÂë¡£Xfinity°µÊ¾£¬ÒÑÒªÇóÓû§³ÁÖÃÃÜÂëÀ´±£»¤ËûÃǵÄÕÊ»§¡£
https://www.bleepingcomputer.com/news/security/xfinity-discloses-data-breach-after-recent-citrix-server-hack/
6¡¢Qualys°ä²¼¹ØÓÚ2023ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨
12ÔÂ19ÈÕ£¬Qualys°ä²¼¹ØÓÚ2023ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨¡£2023Äê¹²Åû¶ÁË26447¸ö·ì϶£¬±È2022Äê¶àÁË1500¶à¸öCVE¡£³¬¹ý7000¸ö·ì϶ӵÓÐPoC£¬µ«ÊÇÀûÓôúÂëµÄÖÊÁ¿Í¨³£½ÏµÍ¡£206¸ö·ì϶ӵÓпÉÓõıøÆ÷»¯ÀûÓôúÂ룬115¸ö·ì϶ʱʱ±»¹¥»÷ÕßÀûÓ᣽ñÄê·ì϶ÀûÓõľùÔȹ¦·òΪ44Ì죬µ«25%µÄ¸ß·çÏÕ·ì϶ÔÚ°ä²¼µ±Ìì¾Í±»ÀûÓá£×î³£±»ÀûÓõķì϶Ô̺¬CVE-2023-0669ºÍCVE-2023-20887µÈ£¬×î»îÔ¾µÄ¹¥»÷ÕßΪCL0P¡£·ì϶ÀûÓÃÖÐʹÓõÄÖØÒªMITRE ATT&CKÕ½ÊõºÍ¼¼ÊõÔ̺¬ÀûÓÃÔ¶³Ì·þÎñ¡¢ÃæÏò¹«¼ÒµÄÀûÓúÍȨÏÞÌáÉý¡£
https://blog.qualys.com/vulnerabilities-threat-research/2023/12/19/2023-threat-landscape-year-in-review-part-one


¾©¹«Íø°²±¸11010802024551ºÅ