×êÑÐÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄ°²È«·ì϶

°ä²¼¹¦·ò 2023-11-24
1¡¢×êÑÐÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄ°²È«·ì϶


¾ÝýÌå11ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁ˶à¸ö·ì϶£¬£¬£¬£¬ £¬¿ÉÓÃÀ´ÈƹýDell Inspiron 15¡¢Lenovo ThinkPad T14ºÍMicrosoft Surface Pro X±Ê¼Ç±¾µçÄÔÉϵÄWindows HelloÉí·ÝÑéÖ¤ ¡£¡£¡£¡£¡£ËùÓвâÊÔµÄÖ¸ÎÆ´«¸ÐÆ÷¶¼ÊÇMatch-on-Chip (MoC)´«¸ÐÆ÷£¬£¬£¬£¬ £¬¹ÌÈ»MoC´«¸ÐÆ÷Äܹ»×èÖ¹½«´æ´¢µÄÖ¸ÎÆÊý¾Ý³Á·Åµ½Ö÷»ú½øÐÐÆ¥Å䣬£¬£¬£¬ £¬µ«ËüÃÇ×ÔÉí²¢²»ÄÜ×èÖ¹¶ñÒâ´«¸ÐÆ÷·ÂÕպϷ¨´«¸ÐÆ÷ÓëÖ÷»ú½øÐÐͨѶ ¡£¡£¡£¡£¡£Õâ¿ÉÄÜ»áÃýÎóµØÏÔʾÓû§Éí·ÝÑéÖ¤³É¹¦£¬£¬£¬£¬ £¬»ò³Á·Å֮ǰµÄÖ÷»úºÍ´«¸ÐÆ÷Ö®¼äµÄÁ÷Á¿ ¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬ £¬Î¢Èí¿ª·¢Á˰²È«É豸ÏνӺÍ̸£¨SDCP£©£¬£¬£¬£¬ £¬µ«×êÑÐÈËÔ±»¹ÊÇÀûÓÃMiTM¹¥»÷³É¹¦ÈƹýÁËWindows HelloÉí·ÝÑéÖ¤ ¡£¡£¡£¡£¡£


https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html


2¡¢º«¹úIT¹«Ë¾TmaxSoftÅäÖÃÃýÎ󳬹ý5000Íò±Ê¼Í¼й¶


¾Ý11ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬ £¬º«¹úIT¹«Ë¾TmaxSoftÔ¼2TBµÄÊý¾ÝÒѹ«¿ª³¬¹ýÁ½Äê ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔçÔÚ½ñÄê1Ô¾ͷ¢ÏÖÁËÒ»¸ö¶³öµÄKibana½ÚÔìÃæ°å£¬£¬£¬£¬ £¬²¢Ö¸³öÕâ×éÊý¾ÝÓÚ2021Äê6Ô³õ´Î±»·¢ÏÖ ¡£¡£¡£¡£¡£Êý¾Ý¿â×ܹ²Óг¬¹ý5600Íò±Ê¼Í¼£¬£¬£¬£¬ £¬Ô̺¬Ô±¹¤ÐÕÃûºÍµç»°¡¢¹ÍÓ¶ºÏͬºÅ¡¢·¢Ë͵ĸ½¼þºÍ¶þ½øÔìÎļþµÄÔªÊý¾ÝµÈ ¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬ £¬¸Ã¹«Ë¾ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´£¬£¬£¬£¬ £¬²¢ÇÒÔ̺¬´óÁ¿Êý¾ÝµÄ½ÚÔìÃæ°åÒÀÈ»´¦ÓÚ¹«¿ª×´Ì¬ ¡£¡£¡£¡£¡£


https://securityaffairs.com/154567/data-breach/tmaxsoft-leaks-2tb-of-data.html


3¡¢Î¢ÈíÅû¶Diamond SleetÀûÓÃCyberLinkµÄ¹©¸øÁ´¹¥»÷


΢ÈíÔÚ11ÔÂ22ÈÕÅû¶Á˳¯ÏʺڿÍÍÅ»ïDiamond Sleet(ZINC)ÌáÒéµÄ¹©¸øÁ´¹¥»÷ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ10ÔÂ20Èչ۲쵽ÁËÕâ´Î¿ÉÒɻ£¬£¬£¬£¬ £¬Ëü¶ÔÖйų́Íå¶àýÌåÈí¼þ¹«Ë¾CyberLink¿ª·¢µÄÀûÓ÷¨Ê½½øÐÐľÂí»¯ ¡£¡£¡£¡£¡£¶ñÒâÎļþʹÓÃCyberLinkÐû¸æµÄÓÐЧ֤Êé½øÐÐÊðÃû£¬£¬£¬£¬ £¬ÍйÜÔڸù«Ë¾Õ¼ÓеĺϷ¨µÄ¸üлù´¡ÉèÊ©ÉÏ ¡£¡£¡£¡£¡£Æù½ñΪֹ£¬£¬£¬£¬ £¬¸Ã¶ñÒâ»î¶¯ÒÑÓ°Ïì¶à¸ö¹ú¶È/µØÓòµÄ100¶ą̀É豸£¬£¬£¬£¬ £¬Ô̺¬ÈÕ±¾¡¢Öйų́Íå¡¢¼ÓÄôóºÍÃÀ¹ú ¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/


4¡¢Blenderй©³ÖÐøµÄDDoS¹¥»÷µ¼ÖÂÆä·þÎñÆ÷å´»úÊýÈÕ


ýÌå11ÔÂ22Èճƣ¬£¬£¬£¬ £¬Blenderй©×î½üµÄÍøÕ¾·þÎñÖжÏÊdzÖÐøµÄDDoS¹¥»÷µ¼Ö嵀 ¡£¡£¡£¡£¡£¸ÃÏîÄ¿ÍŶӰµÊ¾£¬£¬£¬£¬ £¬×Ô11ÔÂ18ÈÕÒÔÀ´£¬£¬£¬£¬ £¬blender.org·þÎñÆ÷¾ÍÔâµ½DDoS¹¥»÷£¬£¬£¬£¬ £¬Æä·þÎñÆ÷ÒòÒªÇó¹ýÔØ¶øå´»ú ¡£¡£¡£¡£¡£¼´±ãÔÚ¹¥»÷ÕßÔÝÍ£¹¥»÷µÄʱ³½£¬£¬£¬£¬ £¬BlenderµÄ»ù´¡ÉèÊ©ÒÀÈ»Òò´óÁ¿´ý´¦ÖõĺϷ¨ÒªÇó¶ø¹ýÔØ ¡£¡£¡£¡£¡£×îÖÕ£¬£¬£¬£¬ £¬ÔÚ¾­ÀúÁË4ÌìµÄ³ÖÐøÖжϺ󣬣¬£¬£¬ £¬¸ÃÍŶӽ«ÆäÖ÷ÍøÕ¾×ªÒÆµ½ÁËCloudFlareÉÏ£¬£¬£¬£¬ £¬ÕâÏ÷¼õ¹¥»÷µÄÓ°Ïì ¡£¡£¡£¡£¡£Blender·ÖÏíµÄͳ¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬ £¬¹¥»÷ÈÔÔÚ³ÖÐø£¬£¬£¬£¬ £¬Õë¶Ô¸ÃÏîÄ¿·þÎñÆ÷µÄÐéαҪÇ󳬹ý2.4ÒÚ´Î ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/open-source-blender-project-battling-ddos-attacks-since-saturday/


5¡¢Akamai°ä²¼Ð½©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö»ã±¨


11ÔÂ21ÈÕ£¬£¬£¬£¬ £¬Akamai°ä²¼»ùÓÚMiraiµÄн©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£InfectedSlursÒ»ÏòÔÚÀûÓÃÁ½¸öRCE·ì϶À´Ï°È¾Â·ÓÉÆ÷ºÍ¼Ïñ»ú(NVR)É豸£¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÓÚ½ñÄê10Ô·¢ÏÖÁ˸ý©Ê¬ÍøÂ磬£¬£¬£¬ £¬²¢ÒÔΪËüÖÁÉÙ´Ó2022ÄêÆð¾ÍÒ»Ïò»îÔ¾ ¡£¡£¡£¡£¡£ËüÊÇJenX MiraiµÄ±äÌ壬£¬£¬£¬ £¬ÓÉÓÚÔÚC2ÓòºÍÓ²±àÂë×Ö·û´®ÖÐʹÓù¥»÷ÐÔ˵»°¶øµÃÃû ¡£¡£¡£¡£¡£ÆäC2»ù´¡ÉèÊ©Ïà¶Ô¼¯ÖУ¬£¬£¬£¬ £¬ËƺõÒ²Ö§³ÖhailBotµÄÔËÐÐ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°Ï칩¸øÉ̵ÄÃû³Æ£¬£¬£¬£¬ £¬µ«¹©¸øÉ̳Ðŵ½«ÓÚ12Ô°䲼°²È«¸üР¡£¡£¡£¡£¡£


https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days


6¡¢Kaspersky°ä²¼2024ÄêÏû·ÑÕßÍøÂçÍþвµÄÔ¤²â»ã±¨


11ÔÂ23ÈÕ£¬£¬£¬£¬ £¬Kaspersky°ä²¼Á˹ØÓÚ2024ÄêÏû·ÑÕßÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±¶Ô2024Äê×ö³öÁËÕ°Íû£¬£¬£¬£¬ £¬Ô̺¬¸ü¶à´È±¯ÓйصÄÚ¿Æ­¼´½«À´ÁÙ¡¢ÍøÉÏÉ̵꽫Óë´È±¯»ú¹¹µÄºÏ×÷¡¢»¥ÁªÍø»®·Ö¸üϸ¡¢VPN·þÎñ³ÊÉÏÉýÇ÷Ïò¡¢°²È«ÐÔ¸ßÓÚÓû§Êæ·þ¶È½«´ßÉúÐµİ²È«ÎÊÌâ¡¢ÍøÂç¹¥»÷Õß½«Õë¶ÔP2E¡¢¿ª·¢Í¨ÓõÄDeepfake²é³­¹¤¾ß¡¢ÓïÒôDeepfakeÊÂÎñÔö¶àÒÔ¼°ÒÔµçÓ°Ê×ӳΪµö¶üµÄȦÌ×Ôö¶àµÈ ¡£¡£¡£¡£¡£


https://securelist.com/kaspersky-security-bulletin-consumer-threats-2024/111135/