΢Èí°ä²¼1Ô·ݰ²È«¸üÐÂ×ܼƽ¨¸´49¸ö·ì϶
°ä²¼¹¦·ò 2024-01-101¡¢Î¢Èí°ä²¼1Ô·ݰ²È«¸üÐÂ×ܼƽ¨¸´49¸ö·ì϶
¾ÝýÌå1ÔÂ9ÈÕ±¨Â·£¬Î¢Èí°ä²¼ÁË2024Äê1Ô·ݵÄÖܶþ²¹¶¡£¬×ܼƽ¨¸´ÁË49¸ö·ì϶¡£±¾Ô½¨¸´µÄ±ÈÁ¦ÓÐȤµÄ·ì϶ÊÇOfficeÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-20677£©£¬¿É±»ÓÃÀ´Í¨¹ýʹÓÃǶÈëʽFBX 3DÄ£ÐÍÎļþ´´½¨¶ñÒâÔì×÷µÄOfficeÎĵµ£¬À´Ô¶³ÌÖ´ÐдúÂë¡£ÁíÒ»¸öÊÇWindows KerberosÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2024-20674£©£¬¹¥»÷ÕßÄܹ»Í¨¹ýMITM¹¥»÷»òÆäËû±¾µØÍøÂçºýŪ¼¼ÊõÀ´ÀûÓô˷ì϶£¬Ïò¿Í»§¶Ë·¢ËͶñÒâKerberosÐÂÎÅ£¬½«×Ô¼º¼Ù×°³ÉKerberosÉí·ÝÑéÖ¤·þÎñÆ÷¡£
2¡¢LockBitÍþвҪ¹«¿ªCapital HealthÔ¼7TBµÄÊý¾Ý
¾Ý1ÔÂ9ÈÕ±¨Â·£¬LockBitÐû³ÆÒÑÈëÇÖCapital Health£¬²¢ÍþвҪй¶±»µÁÊý¾ÝºÍ½»ÉæÌ¸Ìì¼Í¼¡£2023Äê11Ô£¬Capital HealthÔÚÔâµ½¹¥»÷ºóϵͳ³öÏÖÖжϣ¬²¢°µÊ¾¸ÃÊÂÎñ½«Ó°ÏìÆäÔËÓªÖÁÉÙÒ»ÖÜ¡£LockBitÔÚ8ÈÕ½«¸ÃÒ½ÁÆ»ú¹¹ÁÐÈëÆäÍøÕ¾£¬Ðû³ÆÇÔÈ¡ÁË7 TBµÄÒ½ÁÆÊý¾Ý¡£»¹Íþв³ÆÈôÊǸûú¹¹Î´ÄÜÂú×ãËûÃǵÄÒªÇó£¬ËûÃǾͻáÔÚ1ÔÂ9ÈÕй¶ÕâЩÊý¾Ý¡£
3¡¢¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½Ransomexx¹¥»÷³¬¹ý2GBÊý¾Ýй¶
1ÔÂ8ÈÕ±¨Â·³Æ£¬·ÇÖÞ×î´óµÄº½¿Õ¹«Ë¾Ö®Ò»¿ÏÄáÑǺ½¿Õ¹«Ë¾Ôâµ½ÁËRansomexxÀÕË÷ÍÅ»ïµÄ¹¥»÷¡£¹¥»÷ÕßÔÚ°µÍø°ä²¼Á˾ݳÆÊǴӸú½¿Õ¹«Ë¾ÇÔÈ¡µÄ³¬¹ý2 GBÊý¾Ý£¬Êý¾ÝÊ÷ÏÔʾ£¬Ô̺¬±äÂһ㱨¡¢»¤ÕÕ¸´Ó¡¼þºÍ¸÷Àà¿ÕÄѻ㱨¡£¹¥»÷ÕßÔÚ°ä²¼Ìû×Óʱ£¬Ê×ÏÈÉÏ´«ÁËÒ»ÕžݳÆÊÇ¿ÏÄáÑǺ½¿Õ¹«Ë¾Ò»¼Ü·É»úÒýÇæÊÜËðµÄͼƬ£¬Êý¾ÝÑù±¾Öл¹Ô̺¬Ò»Ð©ÎÞ¹éÊôϵͳµÄ¸÷ÀàÃÜÂ롣Ŀǰ£¬¿ÏÄáÑǺ½¿Õ¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£
4¡¢Fortinet·¢ÏÖͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ»î¶¯
FortinetÔÚ1ÔÂ8ÈÕÅû¶ÁËͨ¹ýYouTube·Ö·¢Lumma±äÌåµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈ»áÈëÇÖYouTubeµÄÕÊ»§£¬²¢ÉÏ´«¼Ù×°³É¹²ÏíÆÆ½âÈí¼þµÄÊÓÆµ¡£¾«ÐÄÔì×÷µÄ×°ÖÃZIPÎļþÊÇ·Ö·¢payloadµÄµö¶ü£¬ËüÀûÓÃÁËÓû§×°ÖÃÀûÓõÄÒâͼ£¬´ÙʹÓû§¾ø²»ÓÌÔ¥µØÖ·»÷×°ÖÃÎļþ¡£Õû¸ö»î¶¯ÖеÄURLÀ´×Ô¿ªÔ´ÍøÕ¾£¬Ö÷ÕÅÊǼõÈõÓû§µÄ°²È«Òâʶ¡£¹¥»÷Õß»¹ÀûÓÃÁËÒ»¸ö˽ÓÐ.NET¼ÓÔØ·¨Ê½£¬ËüÓµÓл·¾³²é³¡¢¸÷ÀàAnti-VMºÍ·´µ÷ÊÔÖ°ÄÜ¡£
5¡¢É³¼éϸҵºÍ¿ó²ú×ÊÔ´²¿Ãô¸ÐÊý¾Ýй¶¿ÉÓÃÓÚÄÚÍø¹¥»÷
ýÌå1ÔÂ8Èճƣ¬É³¼éϸҵºÍ¿ó²ú×ÊÔ´²¿(MIM)µÄ»·¾³Îļþ(env.)й¶³¤´ï15¸öÔ¡£Â¶³öµÄenv.Éæ¼°Á˶àÖÖÀàÐ͵ÄÊý¾Ý¿âÍ´´¦¡¢ÓʼþÍ´´¦ºÍÊý¾Ý¼ÓÃÜÃÜÔ¿£¬ÀýÈçSMTPÍ´´¦¡¢Laravel APP_Key¡¢MySQLºÍRedisÊý¾Ý¿âµÄÍ´´¦µÈ¡£Ð¹Â¶µÄÐÅÏ¢¿É±»¹¥»÷ÕßÓÃÓÚÔڸò¿ÏµÍ³ÄÚ½øÐкáÏòÒÆ¶¯£¬²¢µ¼ÖÂÕÊ»§ÊÕÊܺÍÀÕË÷¹¥»÷µÈ¸÷À๥»÷¡£¸ÃÎļþÔÚ2022Äê3Ô³õ´Î±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬Ä¿Ç°Òѱ»±£»¤ÆðÀ´¡£
6¡¢×êÑÐÈËÔ±°ä²¼2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ»ã±¨
1ÔÂ3ÈÕ£¬CisoµÄ×êÑÐÈËÔ±Jerry Gamblin°ä²¼ÁË2023ÄêCVEÊý¾ÝµÄ»ØÊ׺Íͳ¼Æ»ã±¨¡£»ã±¨Ö¸³ö£¬½ØÖÁ2023Äê¹²°ä²¼ÁË28902¸öCVE£¬±È2022ÄêµÄ25081¸öCVEÔö³¤ÁË15%ÒÔÉÏ¡£¾ùÔÈÿÌì°ä²¼79.18¸ö¡£10ÔÂÊǰ䲼CVE×î¶àµÄÔ·ݣ¬¹²2690¸ö£¬Õ¼ÕûÄêµÄ9.3%¡£´ÓÑϳÁˮƽÀ´¿´£¬2023ÄêCVEµÄ¾ùÔÈCVSSÆÀ·ÖΪ7.12£¬ÆäÖÐ36¸ö·ì϶µÄÆÀ·ÖΪ10.0¡£×î³£·ÖÅäµÄ³£¼û·ìϼû¶¾Ù(CWE)±êʶ·ûÀàÐÍÊÇCWE-79£¬¼´ÍøÒ³ÌìÉúÆÚ¼äÊäÈëµÄÖкͲ»µ±£¬Ò²³ÆÎªXSS£¬È¥ÄêÓÐ4100¶à¸öCVE±»·ÖÀàΪXSS·ì϶¡£


¾©¹«Íø°²±¸11010802024551ºÅ