CorsairÈ·ÈÏÊÇK100¼üÅ̹̼þÖеÄBugµ¼ÖÂ×Ô¶¯´ò×Ö

°ä²¼¹¦·ò 2022-12-23
1¡¢CorsairÈ·ÈÏÊÇK100¼üÅ̹̼þÖеÄBugµ¼ÖÂ×Ô¶¯´ò×Ö

     

 ¾ÝýÌå12ÔÂ21ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬CorsairÒÑÈ·ÈÏÆäK100¼üÅ̹̼þÖеÄÒ»¸öBug£¬ £¬£¬£¬£¬£¬µ¼ÖÂÏÈǰÊäÈëµÄÎı¾ÔÚ¼¸Ììºó×Ô¶¯ÊäÈëµ½ÀûÓ÷¨Ê½ÖУ¬ £¬£¬£¬£¬£¬¶ø²»ÊǶñÒâÈí¼þµÄÔ­Òò¡£¡£¡£¡£¡£ ¡£¡£¡£Õâ¸öÎÊÌâÓÚ2022Äê8Ô³õ´ÎÔÚCorsairÂÛ̳ÉÏÅû¶£¬ £¬£¬£¬£¬£¬Óû§²»°²ÊÇijÖÖ´ó¾ÖµÄ¼üÅ̼ͼ·¨Ê½»ò¶ñÒâÈí¼þµ¼Öµġ£¡£¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬£¬¸ÃÎÊÌâÔ´ÓÚºê¼Í¼ְÄÜÖеķì϶£¬ £¬£¬£¬£¬£¬µ¼ÖÂËüÃýÎ󵨴ò¿ª²¢ÆðÍ·¼Í¼»÷¼üºÍÊó±êÒÆ¶¯¡£¡£¡£¡£¡£ ¡£¡£¡£ÕâЩºê·¨Ê½Ëæºó±»´¥·¢£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔÙ´ÎÊäÈë±£ÁôµÄÎı¾¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/corsair-keyboard-bug-makes-it-type-on-its-own-no-malware-involved/


2¡¢Comcast XfinityÓû§µÄÕÊ»§Ôâµ½2FAÈÆ¹ý¹¥»÷

      

ýÌå12ÔÂ22Èճƣ¬ £¬£¬£¬£¬£¬Comcast XfinityµÄÓû§Ð¹Â©ËûÃǵÄÕÊ»§Ôâµ½ÁËË«³É·ÖÉí·ÝÑéÖ¤ÈÆ¹ý¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£´Ó12ÔÂ19ÈÕÆðÍ·£¬ £¬£¬£¬£¬£¬ºÜ¶àXfinityÓʼþÓû§ÊÕµ½ËûÃǵÄÕÊ»§ÐÅÏ¢ÒѸü¸ÄµÄ֪ͨ¡£¡£¡£¡£¡£ ¡£¡£¡£µ«ÊÇ£¬ £¬£¬£¬£¬£¬µ±³¢ÊÔ½Ó¼ûÕâЩÕÊ»§Ê±£¬ £¬£¬£¬£¬£¬ÓÉÓÚÃÜÂëÒѱ»¸ü¸ÄÎÞ·¨µÇ¼¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ³ÁлñµÃ¶ÔÕÊ»§µÄ½Ó¼ûȨÏÞºó£¬ £¬£¬£¬£¬£¬Óû§·¢ÏÔìäÔâµ½Á˹¥»÷£¬ £¬£¬£¬£¬£¬Ò»´ÎÐÔ@yopmail.comÓòÃûÉϵĸ¨Öúµç×ÓÓʼþ±»Ôö³¤µ½ËûÃǵÄ×ÊÁÏÖÓ×£¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÊÇͨ¹ýƾ֤Ìî³ä¹¥»÷À´»ñµÃµÇ¼ƾ֤£¬ £¬£¬£¬£¬£¬Ò»µ©½øÈëÕË»§²¢±»ÌáÐÑÊäÈë2FA´úÂ룬 £¬£¬£¬£¬£¬ËûÃǾÍʹÓðµÀïÁ÷´«µÄXfinityÍøÕ¾µÄOTPÅÔ·£¬ £¬£¬£¬£¬£¬À´Î±Ôì³É¹¦µÄ2FAÑéÖ¤ÒªÇ󡣡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/comcast-xfinity-accounts-hacked-in-widespread-2fa-bypass-attacks/


3¡¢Ð¬ÀàÁãÊÛÉÌEcco·þÎñÆ÷ÅäÖÃÃýÎóй¶³¬¹ý60GBÊý¾Ý

      

CyberNewsÔÚ12ÔÂ21ÈÕ±¨Â·³Æ£¬ £¬£¬£¬£¬£¬Ð¬ÀàÔì×÷É̺ÍÁãÊÛÉÌEcco³¬¹ý60GBÊý¾ÝÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£ ¡£¡£¡£ÆäÖÐÔ̺¬Êý°ÙÍòµÄÎļþ£¬ £¬£¬£¬£¬£¬Éæ¼°ÏúÊÛ¡¢ÓªÏú¡¢ÈÕÖ¾¼Í¼ºÍϵͳÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÈκÎÓÐȨ½Ó¼ûµÄÈ˶¼Äܹ»²é¿´¡¢±à×ë¡¢¸´ÔìºÍÇÔÈ¡»òɾ³ýÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£Ö»¹Ü¶³öµÄ·þÎñÆ÷Êܵ½HTTPÉí·ÝÑéÖ¤µÄ±£»£» £»£»£»£»£» £»¤£¬ £¬£¬£¬£¬£¬µ«ÆäÅäÖÃÃýÎó²¢ÔÊÐíËùÓÐAPIÒªÇóͨ¹ý¡£¡£¡£¡£¡£ ¡£¡£¡£º¹ÇàÊý¾ÝÅú×¢£¬ £¬£¬£¬£¬£¬×Ô2021Äê6ÔÂ4ÈÕÆð£¬ £¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÄܹ»±»½Ó¼ûÖÁÉÙ506Ìì¡£¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£¡£ ¡£¡£¡£


https://cybernews.com/security/ecco-leaks-sensitive-data-for-months/


4¡¢Ä¾ÂíGodFatherÕë¶Ô400¶à¼ÒÒøÐкͼÓÃÜÇ®±ÒÂòÂôËù

      

12ÔÂ21ÈÕ£¬ £¬£¬£¬£¬£¬Group IBÅû¶ÁËAndroidÒøÐÐľÂíGodFatherµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¡£Æù½ñΪֹ£¬ £¬£¬£¬£¬£¬ËüÒѹ¥»÷È«Çò16¸ö¹ú¶È/µØÓòµÄ400¶à¸öÖ¸±ê£¬ £¬£¬£¬£¬£¬Éæ¼°ÒøÐÐÀûÓ÷¨Ê½¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÂòÂôËù¡£¡£¡£¡£¡£ ¡£¡£¡£GodFatherÓÚ2021Äê6Ô³õ´Î±»¼ì²âµ½£¬ £¬£¬£¬£¬£¬·ÖÎöÅú×¢ËüÊÇAnubisµÄ¼ÌÈÎÕß¡£¡£¡£¡£¡£ ¡£¡£¡£Æä»î¶¯ÔÚ2022Äê6Ô·ÝÖÕ³¡£¬ £¬£¬£¬£¬£¬ÓÖÔÚÄê9ÔÂÔٴγöÏÖ£¬ £¬£¬£¬£¬£¬´Ë¿ÌWebSocketÖ°ÄÜÂÔÓб䶯¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬Ëüͨ¹ý½âÃÜʹÓÃBlowfishÃÜÂë±àÂëµÄTelegram channelÃèÊöÀ´¼ìË÷ÆäC2·þÎñÆ÷µØÖ·¡£¡£¡£¡£¡£ ¡£¡£¡£


https://blog.group-ib.com/godfather-trojan


5¡¢¼ÓÄôó¶ù¿ÆÒ½ÔºSickKidsÔâµ½¹¥»÷µ¼Ö¶à¸öϵͳ崻ú

      

¾Ý12ÔÂ21ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬Î»ÓÚ¼ÓÄôó¶àÂ×¶àµÄ¶ù¿ÆÒ½ÔºSickKidsÔâµ½¹¥»÷£¬ £¬£¬£¬£¬£¬¶à¸öϵͳ崻ú¡£¡£¡£¡£¡£ ¡£¡£¡£SickKidsÓÚ2022Äê12ÔÂ20ÈÕ´«µÝÁ˸ÃÊÂÎñ£¬ £¬£¬£¬£¬£¬²¢Ð¹Â©´ÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ18ÈÕÐÇÆÚÈÕÍíÉÏ9µã30·Ö¸ôʼ£¬ £¬£¬£¬£¬£¬Æäϵͳ³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£ ¡£¡£¡£Ò½Ôº°µÊ¾Ó×ÎÒÐÅÏ¢²¢Î´Êܵ½Ó°Ï죬 £¬£¬£¬£¬£¬µ«ÆäÍøÕ¾ËÆºõÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñµÄÐÔÖʺÍÁìÓòÈÔÔÚµ÷²éÖУ¬ £¬£¬£¬£¬£¬SickKidsûÓÐй©¹ØÓÚÊÂÎñÔ­ÒòµÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.infosecurity-magazine.com/news/cyber-incident-failure-children/


6¡¢Î¢Èí°ä²¼¹ØÓÚ½©Ê¬ÍøÂçZerobotÐÂÖ°ÄܵķÖÎö»ã±¨

      

΢ÈíÔÚ12ÔÂ21ÈÕ°ä²¼Á˹ØÓÚ×îа汾µÄ¶ñÒâÈí¼þZerobot 1.1µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£¡£ZerobotÖÁÉÙ´Ó11ÔÂÆðÍ·¾ÍÔÚ»ý¼«¿ª·¢£¬ £¬£¬£¬£¬£¬Ôö³¤ÁËÐÂÄ £¿£¿£¿£¿£¿£¿£¿éºÍÖ°ÄÜ£¬ £¬£¬£¬£¬£¬ÒÔÀ©´ó¹¥»÷ý½é²¢Ê¹Æä¸üÈÝÒ×ϰȾÐÂÉ豸¡£¡£¡£¡£¡£ ¡£¡£¡£×Ô12Ô³õÒÔÀ´£¬ £¬£¬£¬£¬£¬ËüµÄ¿ª·¢ÈËÔ±ÒѾ­É¾³ýÁËÕë¶ÔphpMyAdmin·þÎñÆ÷¡¢Dasan GPON·ÓÉÆ÷ºÍD-Link DSL-2750BÎÞÏß·ÓÉÆ÷µÄÄ £¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£ ¡£¡£¡£²¢Ôö³¤ÁËеķì϶£¬ £¬£¬£¬£¬£¬Ê¹Æä¿ÉÄÜÕë¶Ô7ÖÖÐÂÐÍÉ豸ºÍÈí¼þ£¬ £¬£¬£¬£¬£¬Ô̺¬Apache£¨CVE-2021-42013£©ºÍApache Spark·þÎñÆ÷£¨CVE-2022-33891£©¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬Ð±äÌåÓµÓÐ7ÖÖеÄDDoSÖ°ÄÜ£¬ £¬£¬£¬£¬£¬Ô̺¬TCP_XMAS¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2022/12/21/microsoft-research-uncovers-new-zerobot-capabilities/