BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀

°ä²¼¹¦·ò 2024-12-20

1. BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀


12ÔÂ19ÈÕ£¬BadBox Android ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÀ©ÕÅ£¬Ï°È¾É豸ÊýÁ¿Òѳ¬¹ý192,000̨£¬ÆäÖÐÔ̺¬³ÛÃûÆ·ÅÆµÄÖÇÄܵçÊÓºÍÖÇÄÜÊÖ»ú£¬ÈçYandexºÍº£ÐÅ¡£¸Ã¶ñÒâÈí¼þ×î³õͨ¹ý¹©¸øÁ´¹¥»÷ϰȾ²»³ÛÃûÔì×÷É̵ÄÉ豸£¬ÏÖÒÑÀ©´óµ½ÔÚÏßÏúÊÛµÄÎÞÃû²úÆ·¼°ÆäËû³ÛÃûÆ·ÅÆ¡£ÆäÖ¸±êÖØÒªÊÇ»ñÈ¡¾­¼ÃÀûÒæ£¬Í¨¹ý½«É豸Ôì³Éסլ´úÀí»òÓÃÓÚ¸æ°×ڲƭʵÏÖ¡£Ö»¹ÜµÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©Ôø°ä·¢µ·»ÙBadBoxµÄÐж¯£¬¶Â½ØÁË30,000̨É豸µÄͨѶ£¬µ«BadBoxÈÔÔÚ³ÖÐø·¢Õ¹¡£BitSight×êÑÐÈËÔ±·¢ÏÖ£¬¸Ã¶ñÒâÈí¼þÒÑ×°ÖÃÔÚ192,000̨É豸ÉÏ£¬ÇÒÊýÁ¿ÈÔÔÚÎȲ½Ôö³¤¡£ÊÜÓ°ÏìµÄÉè±¸ÖØÒªÎ»ÓÚ¶íÂÞ˹¡¢Öйú¡¢Ó¡¶È¡¢°×¶íÂÞ˹¡¢°ÍÎ÷ºÍÎÚ¿ËÀ¼¡£Ïû·ÑÕßÓ¦ÀûÓÃ×îеĹ̼þ°²È«¸üС¢½«ÖÇÄÜÉ豸Óë¹Ø¼üϵͳ¸ôÀë²¢ÔÚ²»Ê¹ÓÃʱ¶Ï¿ªÍøÂçÏνÓ£¬ÒÔ·À±¸BadBoxϰȾ¡£ÈôÉ豸ÎÞ¿ÉÓøüУ¬½¨Òé¶Ï¿ªÍøÂç»ò¹Ø¹ØÉ豸¡£Ï°È¾¼£ÏóÔ̺¬¹ýÈÈ¡¢»úÄܽµÂä¡¢´¦ÖÃÆ÷ʹÓÃÂʸߺÍÍøÂçÁ÷Á¿Òì³£¡£


https://www.bleepingcomputer.com/news/security/badbox-malware-botnet-infects-192-000-android-devices-despite-disruption/


2. ΢Èí365 OfficeÀûÓÃÏÖ¡°²úÆ·ÒÑÍ£Óá±ÃýÎó£¬Ô´ÓÚÐí¿ÉÖ¤µ÷»»ÎÊÌâ


12ÔÂ19ÈÕ£¬Î¢ÈíÔÚµ÷²éÒ»¸öµ¼ÖÂMicrosoft 365 OfficeÀûÓÃÓû§´¥·¢¡°²úÆ·ÒÑÍ£Óá±ÃýÎóµÄÎÊÌâ¡£¾ÝRedditºÍ΢ÈíÉçÇøÍøÕ¾ÉϵĻ㱨£¬Óû§ÔÚOfficeÀûÓÃÖÐËæ»úÊÕµ½´ËÃýÎó£¬Ôì³É»ìÂÒºÍÖжÏ¡£ÎÊÌâÔ´ÓÚÖÎÀíÔ±ÌáÒéµÄÐí¿ÉÖ¤µ÷»»£¬ÈçÒÆ¶¯Óû§µ½·ÖÆçµÄÐí¿É×é»ò¸ü¸ÄÓû§¶©ÔÄ¡£µ±ÖÎÀíԱɾ³ý²¢³ÁÐÂÔö³¤Óû§µ½Ðí¿ÉÖ¤×é¡¢µ÷ÕûÐí¿ÉÖ¤»ò·þÎñ´òËãÉèÖ㬻òÇл»¡°×îа汾µÄ×ÀÃæÀûÓ÷¨Ê½¡±·þÎñ´òËãʱ£¬Ò²»á´¥·¢´ËÎÊÌâ¡£Óû§Äܹ»Í¨¹ýµ¥»÷ÃýÎóºá·ùÉϵġ°³Áм¤»î¡±°´Å¥»òÍ˳ö²¢³ÁÐÂÆô¶¯Microsoft 365ÀûÓÃÀ´½â¾ö´ËÎÊÌâ¡£ÈôÊÇÎÊÌâÒÀÈ»´æÔÚ£¬½¨ÒéÁªÏµÖÎÀíÔ±²é³­¶©ÔÄÊÇ·ñÒѹýÆÚ¡£Î¢Èí½¨ÒéÓÐδ½â¾öÖ§³Ö°¸ÀýµÄÓû§ÌṩʹÓÃOfficeÐí¿ÉÕï¶Ï¹¤¾ßÍøÂçµÄÕï¶ÏÊý¾Ý£¬²¢ÌáÐÑÊÜÓ°ÏìµÄÓû§Ìṩ´æ´¢ÔÚ%temp%/diagnosticsĿ¼ÖеÄÈÕÖ¾¡£¹ÌȻ΢ÈíÉÐδ°ä²¼½¨¸´¹¦·ò±í£¬µ«Æä¹¤³ÌÍŶÓÔÚ»ý¼«µ÷²é´ËÎÊÌ⣬²¢¼¤ÀøÊÜÓ°ÏìµÄÓû§ºÍÖÎÀíÔ±¹Ø×¢ÆäÖ§³ÖÇþ·ÒÔ»ñÈ¡¸üС£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-users-hit-by-random-product-deactivation-errors/


3. ÑÇÂíÑ·ÀûÓÃÉ̵꾪ÏÖBMI CalculationVsn¶ñÒâ¼äµýÈí¼þ


12ÔÂ19ÈÕ£¬ÔÚÑÇÂíÑ·ÀûÓÃÉ̵êÖУ¬Ò»¿îÃûΪ¡°BMI CalculationVsn¡±µÄAndroidÀûÓ÷¨Ê½±»·¢ÏÖÏÖʵÉÏÊÇÒ»¿î¶ñÒâ¼äµýÈí¼þ£¬Ëü¼Ù×°³É½¡È«¹¤¾ßÇÔÈ¡Óû§É豸Êý¾Ý¡£¸ÃÀûÓÃÓÉÂõ¿Ë·Æ³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ£¬²¢Òѱ»´ÓÉ̵êÖÐÒÆ³ý£¬µ«ÒÑ×°ÖõÄÓû§ÐèÊÖ¶¯É¾³ý²¢Ö´ÐÐÆëȫɨÃèÒԶϸù²ÐÁôºÛ¼£¡£¸Ã¼äµýÈí¼þÓÉ¡°PT Visionet Data Internasional¡±°ä²¼£¬×î³õÐû´«ÎªÉí¶ÎÖÊÁ¿Ö¸Êý£¨BMI£©ÍÆËãÆ÷£¬µ«ºó¶ÜÖ´ÐжñÒâ²Ù×÷£¬Ô̺¬Æô¶¯ÆÁϼÔì·þÎñ¡¢É¨ÃèÒÑ×°ÖõÄÀûÓ÷¨Ê½ÒÔ¼°À¹½Ø²¢ÍøÂç¶ÌÐÅ£¬Ô̺¬Ò»´ÎÐÔÃÜÂëºÍÑéÖ¤Âë¡£¼øÓÚ´ËÀàΣÏÕÀûÓÃÈÔÄÜÌӱܺϷ¨ÀûÓÃÉ̵êµÄ´úÂëÉó²é£¬AndroidÓû§Ó¦Ö»×°ÖÃÀ´×Ô³ÛÃû¿¯ÐÐÉ̵ÄÀûÓ㬲¢×Ðϸ²é³­ËùÒªÇóµÄȨÏÞ£¬ÔÚ×°Öúó³·ÏúÓзçÏÕµÄȨÏÞ¡£Í¬Ê±£¬Î¬³ÖGoogle Play Protect»îԾ״̬¶ÔÓÚ¼ì²â²¢×èÖ¹ÒÑÖª¶ñÒâÈí¼þÖÁ¹Ø³ÁÒª¡£


https://www.bleepingcomputer.com/news/security/android-spyware-found-on-amazon-appstore-disguised-as-health-app/


4. Mirai¶ñÒâÈí¼þÀûÓÃĬÈÏÆ¾Ö¤Ï°È¾Session Smart·ÓÉÆ÷


12ÔÂ19ÈÕ£¬Õ°²©ÍøÂçÏò¿Í»§·¢³öÖҸ棬ָ³öMirai¶ñÒâÈí¼þÔÚÀûÓÃĬÈÏÆ¾Ö¤¹¥»÷²¢Ï°È¾Session Smart·ÓÉÆ÷£¬½ø¶øÌáÒéÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¸Ã¶ñÒâÈí¼þ»áɨÃèÓµÓÐĬÈϵǼʹ´¦µÄÉ豸£¬²¢ÔÚ»ñµÃ½Ó¼ûȨÏÞºóÔ¶³ÌÖ´ÐкÅÁî¡£Õ°²©ÍøÂ罨Òé¿Í»§µ±¼´¸ü¸ÄËùÓÐSession Smart·ÓÉÆ÷ÉϵÄĬÈÏÍ´´¦£¬²¢Ê¹ÓùÖÒìÇÒÇ¿µÄÃÜÂ룬ͬʱά³Ö¹Ì¼þ¸üУ¬²é³­½Ó¼ûÈÕÖ¾ÖеÄÒì³££¬²¢²¿ÊðÈëÇÖ¼ì²âϵͳºÍ·À»ðǽÀ´¼ÓÇ¿°²È«ÐÔ¡£´Ë±í£¬Õ°²©ÍøÂ绹ÌáÐÑÖÎÀíÔ±°ÑÎÈDZÔÚµÄÈëÇÖÖ¸±ê£¬ÈçɨÃè³£¼û¶Ë¿Ú¡¢SSH·þÎñµÇ¼³¢ÊÔʧ°Ü¡¢³öÕ¾Á÷Á¿¼¤ÔöµÈ¡£ÒѾ­Ï°È¾µÄ·ÓÉÆ÷±ØÐë³ÁÐÂÓ³Ïñ»¯ÄÜÁ¦³ÁÐÂÉÏÏß¡£´Ëǰ£¬Õ°²©ÍøÂçÒ²ÔøÂÅ´ÎÖÒ¸æÆä²úÆ·ÖдæÔÚµÄÔ¶³Ì´úÂëÖ´Ðзì϶ºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬²¢°ä²¼ÁËÏàÓ¦µÄ²¹¶¡¡£


https://www.bleepingcomputer.com/news/security/juniper-warns-of-mirai-botnet-targeting-session-smart-routers/


5. BeyondTrustÔâÍøÂç¹¥»÷£¬·¢ÏÖ°²È«·ì϶²¢´¹Î£Ó¦¶Ô


12ÔÂ19ÈÕ£¬BeyondTrustÊÇÒ»¼ÒÌá¹©ÌØÈ¨½Ó¼ûÖÎÀíºÍ°²È«Ô¶³Ì½Ó¼û½â¾ö¹æ»®µÄÍøÂ簲ȫ¹«Ë¾£¬ÔÚ12Ô³õÔâ·êÁËÍøÂç¹¥»÷¡£ÍþвÐÐΪÕßÈëÇÖÁËÆä²¿ÃÅÔ¶³ÌÖ§³ÖSaaSÊ·ý£¬»ñµÃÁËÔ¶³ÌÖ§³ÖSaaS APIÃÜÔ¿µÄ½Ó¼ûȨÏÞ£¬Äܹ»³ÁÖñ¾µØÀûÓ÷¨Ê½ÕÊ»§µÄÃÜÂë¡£BeyondTrustµ±¼´³·ÏúÁËAPIÃÜÔ¿£¬Í¨ÖªÁËÊÜÓ°ÏìµÄ¿Í»§£¬²¢ÔÝÍ£ÁËÕâЩÊ·ý¡£ÔÚµ÷²é¹ý³ÌÖУ¬·¢ÏÖÁËÁ½¸ö·ì϶£¬ÆäÖÐÒ»¸öΪÑϳÁµÄºÅÁî×¢Èë·ì϶CVE-2024-12356£¬ÁíÒ»¸öΪÖеÈÑϳÁÐÔ·ì϶CVE-2024-12686¡£BeyondTrustÒÑ×Ô¶¯ÔÚËùÓÐÔÆÊ·ýÉÏÀûÓÃÁËÕë¶ÔÕâÁ½¸öȱµãµÄ²¹¶¡£¬µ«ÔËÐÐ×ÔÍйÜÊ·ýµÄÓû§±ØÒªÊÖ¶¯ÀûÓð²È«¸üС£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇ·ñÀûÓÃÕâЩ·ì϶À´¹¥»÷ÏÂÓοͻ§£¬µ«CISA°µÊ¾CVE-2024-12356Òѱ»ÀûÓÃÓÚ¹¥»÷¡£BeyondTrust°µÊ¾£¬ËûÃÇÔÚ³ÖÐøÓë¶ÀÁ¢µÄµÚÈý·½ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½øÐг¹µ×µ÷²é£¬²¢×¨Ò»ÓÚÈ·±£ËùÓпͻ§Ê·ý¶¼µÃµ½È«Ãæ¸üкͰ²È«±£ÏÕ¡£


https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/


6. FortiWLMÆØÑϳÁ·ì϶£º¿ÉÔ¶³ÌÊÕÊÜÉ豸


12ÔÂ19ÈÕ£¬FortinetÎÞÏßÖÎÀíÆ÷£¨FortiWLM£©ÖдæÔÚÒ»¸ö±àºÅΪCVE-2023-34990µÄÑϳÁ·ì϶£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìWebÒªÇóÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë»òºÅÁ´Ó¶øÊÕÊÜÉ豸¡£´Ë·ì϶ÊÇÒ»¸öÏà¶Ôõè¾¶±éÀú·ì϶£¬ÆÀ·ÖΪ9.8£¬ÓÉHorizon3×êÑÐÔ±Zach HanleyÔÚ2023Äê5Ô·¢ÏÖ¡£È»¶ø£¬ÔÚ³¤´ïÊ®¸öԵŦ·òÀ¸Ã·ì϶δµÃµ½½¨¸´£¬ÆÈʹHanleyÔÚ2024Äê3Ô¹«¿ªÅû¶ÁË·ì϶ÐÅÏ¢ºÍÖ¤Ã÷´úÂ루POC£©¡£ÀûÓô˷ì϶£¬¹¥»÷ÕßÄܹ»¶ÁÈ¡Ãô¸ÐÈÕÖ¾Îļþ£¬Ô̺¬ÖÎÀíÔ±»á»°ID£¬½ø¶ø½Ù³ÖÖÎÀíÔ±»á»°²¢»ñÈ¡ÌØÈ¨½Ó¼û¡£¸Ã·ì϶ӰÏìÁËFortiWLM°æ±¾8.6.0ÖÁ8.6.5ºÍ8.5.0ÖÁ8.5.4¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑ·¢³öÖҸ棬µ«ÓÉÓÚ²»×ãCVE IDºÍ°²È«²¼¸æ£¬Óû§²¢Î´Òâʶµ½·çÏÕ¡£Ö±µ½2024Äê12ÔÂ18ÈÕ£¬Fortinet²Å°ä²¼°²È«²¼¸æ³Æ£¬¸Ã·ì϶ÒÑÔÚ2023Äê9Ôµװ䲼µÄFortiWLM°æ±¾8.6.6ºÍ8.5.5Öеõ½½¨¸´¡£Ë¼¿¼µ½FortiWLM±»¿í·ºÀûÓÃÓÚµ±¾Ö»ú¹¹¡¢Ò½ÁƱ£½¡×éÖ¯¡¢½ÌÓý»ú¹¹ºÍ´óÐÍÆóÒµµÈ¹Ø¼ü»·¾³ÖУ¬¸Ã·ì϶µÄ´æÔÚ¿ÉÄܵ¼ÖÂÕû¸öÍøÂçÖжϺÍÃô¸ÐÊý¾Ýй¶¡£Òò¶ø£¬Ç¿ÁÒ½¨ÒéFortiWLMÖÎÀíԱʵʱÀûÓÃËùÓпÉÓøüС£


https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortiwlm-bug-giving-hackers-admin-privileges/