BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ £¬£¬ £¬£¬£¬ £¬£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀

°ä²¼¹¦·ò 2024-12-20

1. BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ £¬£¬ £¬£¬£¬ £¬£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬BadBox Android ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÀ©ÕÅ £¬£¬ £¬£¬£¬ £¬£¬Ï°È¾É豸ÊýÁ¿Òѳ¬¹ý192,000̨ £¬£¬ £¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬³ÛÃûÆ·ÅÆµÄÖÇÄܵçÊÓºÍÖÇÄÜÊÖ»ú £¬£¬ £¬£¬£¬ £¬£¬ÈçYandexºÍº£ÐÅ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×î³õͨ¹ý¹©¸øÁ´¹¥»÷ϰȾ²»³ÛÃûÔì×÷É̵ÄÉ豸 £¬£¬ £¬£¬£¬ £¬£¬ÏÖÒÑÀ©´óµ½ÔÚÏßÏúÊÛµÄÎÞÃû²úÆ·¼°ÆäËû³ÛÃûÆ·ÅÆ¡£¡£¡£¡£¡£¡£ÆäÖ¸±êÖØÒªÊÇ»ñÈ¡¾­¼ÃÀûÒæ £¬£¬ £¬£¬£¬ £¬£¬Í¨¹ý½«É豸Ôì³Éסլ´úÀí»òÓÃÓÚ¸æ°×ڲƭʵÏÖ¡£¡£¡£¡£¡£¡£Ö»¹ÜµÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©Ôø°ä·¢µ·»ÙBadBoxµÄÐж¯ £¬£¬ £¬£¬£¬ £¬£¬¶Â½ØÁË30,000̨É豸µÄͨѶ £¬£¬ £¬£¬£¬ £¬£¬µ«BadBoxÈÔÔÚ³ÖÐø·¢Õ¹¡£¡£¡£¡£¡£¡£BitSight×êÑÐÈËÔ±·¢ÏÖ £¬£¬ £¬£¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þÒÑ×°ÖÃÔÚ192,000̨É豸ÉÏ £¬£¬ £¬£¬£¬ £¬£¬ÇÒÊýÁ¿ÈÔÔÚÎȲ½Ôö³¤¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÉè±¸ÖØÒªÎ»ÓÚ¶íÂÞ˹¡¢Öйú¡¢Ó¡¶È¡¢°×¶íÂÞ˹¡¢°ÍÎ÷ºÍÎÚ¿ËÀ¼¡£¡£¡£¡£¡£¡£Ïû·ÑÕßÓ¦ÀûÓÃ×îеĹ̼þ°²È«¸üС¢½«ÖÇÄÜÉ豸Óë¹Ø¼üϵͳ¸ôÀë²¢ÔÚ²»Ê¹ÓÃʱ¶Ï¿ªÍøÂçÏÎ½Ó £¬£¬ £¬£¬£¬ £¬£¬ÒÔ·À±¸BadBoxϰȾ¡£¡£¡£¡£¡£¡£ÈôÉ豸ÎÞ¿ÉÓøüР£¬£¬ £¬£¬£¬ £¬£¬½¨Òé¶Ï¿ªÍøÂç»ò¹Ø¹ØÉ豸¡£¡£¡£¡£¡£¡£Ï°È¾¼£ÏóÔ̺¬¹ýÈÈ¡¢»úÄܽµÂä¡¢´¦ÖÃÆ÷ʹÓÃÂʸߺÍÍøÂçÁ÷Á¿Òì³£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/badbox-malware-botnet-infects-192-000-android-devices-despite-disruption/


2. ΢Èí365 OfficeÀûÓÃÏÖ¡°²úÆ·ÒÑÍ£Óá±ÃýÎó £¬£¬ £¬£¬£¬ £¬£¬Ô´ÓÚÐí¿ÉÖ¤µ÷»»ÎÊÌâ


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬Î¢ÈíÔÚµ÷²éÒ»¸öµ¼ÖÂMicrosoft 365 OfficeÀûÓÃÓû§´¥·¢¡°²úÆ·ÒÑÍ£Óá±ÃýÎóµÄÎÊÌâ¡£¡£¡£¡£¡£¡£¾ÝRedditºÍ΢ÈíÉçÇøÍøÕ¾ÉϵĻ㱨 £¬£¬ £¬£¬£¬ £¬£¬Óû§ÔÚOfficeÀûÓÃÖÐËæ»úÊÕµ½´ËÃýÎó £¬£¬ £¬£¬£¬ £¬£¬Ôì³É»ìÂÒºÍÖжϡ£¡£¡£¡£¡£¡£ÎÊÌâÔ´ÓÚÖÎÀíÔ±ÌáÒéµÄÐí¿ÉÖ¤µ÷»» £¬£¬ £¬£¬£¬ £¬£¬ÈçÒÆ¶¯Óû§µ½·ÖÆçµÄÐí¿É×é»ò¸ü¸ÄÓû§¶©ÔÄ¡£¡£¡£¡£¡£¡£µ±ÖÎÀíԱɾ³ý²¢³ÁÐÂÔö³¤Óû§µ½Ðí¿ÉÖ¤×é¡¢µ÷ÕûÐí¿ÉÖ¤»ò·þÎñ´òËãÉèÖà £¬£¬ £¬£¬£¬ £¬£¬»òÇл»¡°×îа汾µÄ×ÀÃæÀûÓ÷¨Ê½¡±·þÎñ´òËãʱ £¬£¬ £¬£¬£¬ £¬£¬Ò²»á´¥·¢´ËÎÊÌâ¡£¡£¡£¡£¡£¡£Óû§Äܹ»Í¨¹ýµ¥»÷ÃýÎóºá·ùÉϵġ°³Áм¤»î¡±°´Å¥»òÍ˳ö²¢³ÁÐÂÆô¶¯Microsoft 365ÀûÓÃÀ´½â¾ö´ËÎÊÌâ¡£¡£¡£¡£¡£¡£ÈôÊÇÎÊÌâÒÀÈ»´æÔÚ £¬£¬ £¬£¬£¬ £¬£¬½¨ÒéÁªÏµÖÎÀíÔ±²é³­¶©ÔÄÊÇ·ñÒѹýÆÚ¡£¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÓÐδ½â¾öÖ§³Ö°¸ÀýµÄÓû§ÌṩʹÓÃOfficeÐí¿ÉÕï¶Ï¹¤¾ßÍøÂçµÄÕï¶ÏÊý¾Ý £¬£¬ £¬£¬£¬ £¬£¬²¢ÌáÐÑÊÜÓ°ÏìµÄÓû§Ìṩ´æ´¢ÔÚ%temp%/diagnosticsĿ¼ÖеÄÈÕÖ¾¡£¡£¡£¡£¡£¡£¹ÌȻ΢ÈíÉÐδ°ä²¼½¨¸´¹¦·ò±í £¬£¬ £¬£¬£¬ £¬£¬µ«Æä¹¤³ÌÍŶÓÔÚ»ý¼«µ÷²é´ËÎÊÌâ £¬£¬ £¬£¬£¬ £¬£¬²¢¼¤ÀøÊÜÓ°ÏìµÄÓû§ºÍÖÎÀíÔ±¹Ø×¢ÆäÖ§³ÖÇþ·ÒÔ»ñÈ¡¸üС£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-users-hit-by-random-product-deactivation-errors/


3. ÑÇÂíÑ·ÀûÓÃÉ̵꾪ÏÖBMI CalculationVsn¶ñÒâ¼äµýÈí¼þ


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬ÔÚÑÇÂíÑ·ÀûÓÃÉ̵êÖÐ £¬£¬ £¬£¬£¬ £¬£¬Ò»¿îÃûΪ¡°BMI CalculationVsn¡±µÄAndroidÀûÓ÷¨Ê½±»·¢ÏÖÏÖʵÉÏÊÇÒ»¿î¶ñÒâ¼äµýÈí¼þ £¬£¬ £¬£¬£¬ £¬£¬Ëü¼Ù×°³É½¡È«¹¤¾ßÇÔÈ¡Óû§É豸Êý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÓÉÂõ¿Ë·Æ³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ £¬£¬ £¬£¬£¬ £¬£¬²¢Òѱ»´ÓÉ̵êÖÐÒÆ³ý £¬£¬ £¬£¬£¬ £¬£¬µ«ÒÑ×°ÖõÄÓû§ÐèÊÖ¶¯É¾³ý²¢Ö´ÐÐÆëȫɨÃèÒԶϸù²ÐÁôºÛ¼£¡£¡£¡£¡£¡£¡£¸Ã¼äµýÈí¼þÓÉ¡°PT Visionet Data Internasional¡±°ä²¼ £¬£¬ £¬£¬£¬ £¬£¬×î³õÐû´«ÎªÉí¶ÎÖÊÁ¿Ö¸Êý£¨BMI£©ÍÆËãÆ÷ £¬£¬ £¬£¬£¬ £¬£¬µ«ºó¶ÜÖ´ÐжñÒâ²Ù×÷ £¬£¬ £¬£¬£¬ £¬£¬Ô̺¬Æô¶¯ÆÁϼÔì·þÎñ¡¢É¨ÃèÒÑ×°ÖõÄÀûÓ÷¨Ê½ÒÔ¼°À¹½Ø²¢ÍøÂç¶ÌÐÅ £¬£¬ £¬£¬£¬ £¬£¬Ô̺¬Ò»´ÎÐÔÃÜÂëºÍÑéÖ¤Âë¡£¡£¡£¡£¡£¡£¼øÓÚ´ËÀàΣÏÕÀûÓÃÈÔÄÜÌӱܺϷ¨ÀûÓÃÉ̵êµÄ´úÂëÉó²é £¬£¬ £¬£¬£¬ £¬£¬AndroidÓû§Ó¦Ö»×°ÖÃÀ´×Ô³ÛÃû¿¯ÐÐÉ̵ÄÀûÓà £¬£¬ £¬£¬£¬ £¬£¬²¢×Ðϸ²é³­ËùÒªÇóµÄȨÏÞ £¬£¬ £¬£¬£¬ £¬£¬ÔÚ×°Öúó³·ÏúÓзçÏÕµÄȨÏÞ¡£¡£¡£¡£¡£¡£Í¬Ê± £¬£¬ £¬£¬£¬ £¬£¬Î¬³ÖGoogle Play Protect»îԾ״̬¶ÔÓÚ¼ì²â²¢×èÖ¹ÒÑÖª¶ñÒâÈí¼þÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/android-spyware-found-on-amazon-appstore-disguised-as-health-app/


4. Mirai¶ñÒâÈí¼þÀûÓÃĬÈÏÆ¾Ö¤Ï°È¾Session Smart·ÓÉÆ÷


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬Õ°²©ÍøÂçÏò¿Í»§·¢³öÖÒ¸æ £¬£¬ £¬£¬£¬ £¬£¬Ö¸³öMirai¶ñÒâÈí¼þÔÚÀûÓÃĬÈÏÆ¾Ö¤¹¥»÷²¢Ï°È¾Session Smart·ÓÉÆ÷ £¬£¬ £¬£¬£¬ £¬£¬½ø¶øÌáÒéÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áɨÃèÓµÓÐĬÈϵǼʹ´¦µÄÉ豸 £¬£¬ £¬£¬£¬ £¬£¬²¢ÔÚ»ñµÃ½Ó¼ûȨÏÞºóÔ¶³ÌÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£Õ°²©ÍøÂ罨Òé¿Í»§Á¢¼´¸ü¸ÄËùÓÐSession Smart·ÓÉÆ÷ÉϵÄĬÈÏÍ´´¦ £¬£¬ £¬£¬£¬ £¬£¬²¢Ê¹ÓùÖÒìÇÒÇ¿µÄÃÜÂë £¬£¬ £¬£¬£¬ £¬£¬Í¬Ê±Î¬³Ö¹Ì¼þ¸üР£¬£¬ £¬£¬£¬ £¬£¬²é³­½Ó¼ûÈÕÖ¾ÖеÄÒì³£ £¬£¬ £¬£¬£¬ £¬£¬²¢²¿ÊðÈëÇÖ¼ì²âϵͳºÍ·À»ðǽÀ´¼ÓÇ¿°²È«ÐÔ¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬ £¬£¬£¬ £¬£¬Õ°²©ÍøÂ绹ÌáÐÑÖÎÀíÔ±°ÑÎÈDZÔÚµÄÈëÇÖÖ¸±ê £¬£¬ £¬£¬£¬ £¬£¬ÈçɨÃè³£¼û¶Ë¿Ú¡¢SSH·þÎñµÇ¼³¢ÊÔʧ°Ü¡¢³öÕ¾Á÷Á¿¼¤ÔöµÈ¡£¡£¡£¡£¡£¡£ÒѾ­Ï°È¾µÄ·ÓÉÆ÷±ØÐë³ÁÐÂÓ³Ïñ»¯ÄÜÁ¦³ÁÐÂÉÏÏß¡£¡£¡£¡£¡£¡£´Ëǰ £¬£¬ £¬£¬£¬ £¬£¬Õ°²©ÍøÂçÒ²ÔøÂÅ´ÎÖÒ¸æÆä²úÆ·ÖдæÔÚµÄÔ¶³Ì´úÂëÖ´Ðзì϶ºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬£¬ £¬£¬£¬ £¬£¬²¢°ä²¼ÁËÏàÓ¦µÄ²¹¶¡¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/juniper-warns-of-mirai-botnet-targeting-session-smart-routers/


5. BeyondTrustÔâÍøÂç¹¥»÷ £¬£¬ £¬£¬£¬ £¬£¬·¢ÏÖ°²È«·ì϶²¢´¹Î£Ó¦¶Ô


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬BeyondTrustÊÇÒ»¼ÒÌá¹©ÌØÈ¨½Ó¼ûÖÎÀíºÍ°²È«Ô¶³Ì½Ó¼û½â¾ö¹æ»®µÄÍøÂ簲ȫ¹«Ë¾ £¬£¬ £¬£¬£¬ £¬£¬ÔÚ12Ô³õÔâ·êÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÈëÇÖÁËÆä²¿ÃÅÔ¶³ÌÖ§³ÖSaaSÊ·ý £¬£¬ £¬£¬£¬ £¬£¬»ñµÃÁËÔ¶³ÌÖ§³ÖSaaS APIÃÜÔ¿µÄ½Ó¼ûȨÏÞ £¬£¬ £¬£¬£¬ £¬£¬Äܹ»³ÁÖñ¾µØÀûÓ÷¨Ê½ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£¡£BeyondTrustÁ¢¼´³·ÏúÁËAPIÃÜÔ¿ £¬£¬ £¬£¬£¬ £¬£¬Í¨ÖªÁËÊÜÓ°ÏìµÄ¿Í»§ £¬£¬ £¬£¬£¬ £¬£¬²¢ÔÝÍ£ÁËÕâЩÊ·ý¡£¡£¡£¡£¡£¡£ÔÚµ÷²é¹ý³ÌÖÐ £¬£¬ £¬£¬£¬ £¬£¬·¢ÏÖÁËÁ½¸ö·ì϶ £¬£¬ £¬£¬£¬ £¬£¬ÆäÖÐÒ»¸öΪÑϳÁµÄºÅÁî×¢Èë·ì϶CVE-2024-12356 £¬£¬ £¬£¬£¬ £¬£¬ÁíÒ»¸öΪÖеÈÑϳÁÐÔ·ì϶CVE-2024-12686¡£¡£¡£¡£¡£¡£BeyondTrustÒÑ×Ô¶¯ÔÚËùÓÐÔÆÊ·ýÉÏÀûÓÃÁËÕë¶ÔÕâÁ½¸öȱµãµÄ²¹¶¡ £¬£¬ £¬£¬£¬ £¬£¬µ«ÔËÐÐ×ÔÍйÜÊ·ýµÄÓû§±ØÒªÊÖ¶¯ÀûÓð²È«¸üС£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇ·ñÀûÓÃÕâЩ·ì϶À´¹¥»÷ÏÂÓοͻ§ £¬£¬ £¬£¬£¬ £¬£¬µ«CISA°µÊ¾CVE-2024-12356Òѱ»ÀûÓÃÓÚ¹¥»÷¡£¡£¡£¡£¡£¡£BeyondTrust°µÊ¾ £¬£¬ £¬£¬£¬ £¬£¬ËûÃÇÔÚ³ÖÐøÓë¶ÀÁ¢µÄµÚÈý·½ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½øÐг¹µ×µ÷²é £¬£¬ £¬£¬£¬ £¬£¬²¢×¨Ò»ÓÚÈ·±£ËùÓпͻ§Ê·ý¶¼µÃµ½È«Ãæ¸üкͰ²È«±£ÏÕ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/


6. FortiWLMÆØÑϳÁ·ì϶£º¿ÉÔ¶³ÌÊÕÊÜÉ豸


12ÔÂ19ÈÕ £¬£¬ £¬£¬£¬ £¬£¬FortinetÎÞÏßÖÎÀíÆ÷£¨FortiWLM£©ÖдæÔÚÒ»¸ö±àºÅΪCVE-2023-34990µÄÑϳÁ·ì϶ £¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìWebÒªÇóÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë»òºÅÁî £¬£¬ £¬£¬£¬ £¬£¬´Ó¶øÊÕÊÜÉ豸¡£¡£¡£¡£¡£¡£´Ë·ì϶ÊÇÒ»¸öÏà¶Ôõè¾¶±éÀú·ì϶ £¬£¬ £¬£¬£¬ £¬£¬ÆÀ·ÖΪ9.8 £¬£¬ £¬£¬£¬ £¬£¬ÓÉHorizon3×êÑÐÔ±Zach HanleyÔÚ2023Äê5Ô·¢ÏÖ¡£¡£¡£¡£¡£¡£È»¶ø £¬£¬ £¬£¬£¬ £¬£¬ÔÚ³¤´ïÊ®¸öԵŦ·òÀï £¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶δµÃµ½½¨¸´ £¬£¬ £¬£¬£¬ £¬£¬ÆÈʹHanleyÔÚ2024Äê3Ô¹«¿ªÅû¶ÁË·ì϶ÐÅÏ¢ºÍÖ¤Ã÷´úÂ루POC£©¡£¡£¡£¡£¡£¡£ÀûÓô˷ì϶ £¬£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»¶ÁÈ¡Ãô¸ÐÈÕÖ¾Îļþ £¬£¬ £¬£¬£¬ £¬£¬Ô̺¬ÖÎÀíÔ±»á»°ID £¬£¬ £¬£¬£¬ £¬£¬½ø¶ø½Ù³ÖÖÎÀíÔ±»á»°²¢»ñÈ¡ÌØÈ¨½Ó¼û¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËFortiWLM°æ±¾8.6.0ÖÁ8.6.5ºÍ8.5.0ÖÁ8.5.4¡£¡£¡£¡£¡£¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑ·¢³öÖÒ¸æ £¬£¬ £¬£¬£¬ £¬£¬µ«ÓÉÓÚ²»×ãCVE IDºÍ°²È«²¼¸æ £¬£¬ £¬£¬£¬ £¬£¬Óû§²¢Î´Òâʶµ½·çÏÕ¡£¡£¡£¡£¡£¡£Ö±µ½2024Äê12ÔÂ18ÈÕ £¬£¬ £¬£¬£¬ £¬£¬Fortinet²Å°ä²¼°²È«²¼¸æ³Æ £¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶ÒÑÔÚ2023Äê9Ôµװ䲼µÄFortiWLM°æ±¾8.6.6ºÍ8.5.5Öеõ½½¨¸´¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£Ë¼¿¼µ½FortiWLM±»¿í·ºÀûÓÃÓÚµ±¾Ö»ú¹¹¡¢Ò½ÁƱ£½¡×éÖ¯¡¢½ÌÓý»ú¹¹ºÍ´óÐÍÆóÒµµÈ¹Ø¼ü»·¾³ÖÐ £¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶µÄ´æÔÚ¿ÉÄܵ¼ÖÂÕû¸öÍøÂçÖжϺÍÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£Òò¶ø £¬£¬ £¬£¬£¬ £¬£¬Ç¿ÁÒ½¨ÒéFortiWLMÖÎÀíԱʵʱÀûÓÃËùÓпÉÓøüС£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortiwlm-bug-giving-hackers-admin-privileges/