Ruby-SAML¿âÆØ·ì϶CVE-2024-45409£¬£¬£¬£¬£¬£¬Î£¼°Éí·ÝÑéÖ¤°²È«
°ä²¼¹¦·ò 2024-09-139ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Ruby-SAML¿â×÷ΪִÐÐSAML£¨°²È«¶ÏÑÔÏóÕ÷˵»°£©ÊÚȨµÄ³ÁÒª¹¤¾ß£¬£¬£¬£¬£¬£¬½üÆÚ±»ÆØ³öÑϳÁ°²È«·ì϶CVE-2024-45409£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï10£¬£¬£¬£¬£¬£¬Åú×¢Æä¼«¸ßµÄ·çÏÕÐÔ¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚRuby-SAMLµÄ¶à¸ö°æ±¾ÖУ¬£¬£¬£¬£¬£¬ÖØÒªÒòXPathÑ¡ÔñÆ÷ÃýÎóµ¼Ö£¬£¬£¬£¬£¬£¬Ê¹µÃSAMLÏìÓ¦µÄÊðÃûÑé֤ʧЧ¡£¡£¡£¡£¡£¡£¡£¡£SAML×÷Ϊµ¥µãµÇ¼£¨SSO£©µÄÖ÷ÌâºÍ̸£¬£¬£¬£¬£¬£¬ÆäÊðÃûÆëÈ«ÐÔµÄȱʧֱ½ÓÍþвµ½ÏµÍ³µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬½öͨ¹ýαÔì»ò´Û¸ÄÔ̺¬ËÁÒâÊý¾ÝµÄSAMLÏìÓ¦£¬£¬£¬£¬£¬£¬¼´¿ÉÇáËÉÈÆ¹ýÉí·ÝÑéÖ¤»úÔ죬£¬£¬£¬£¬£¬¼ÙðÈκÎÓû§Éí·ÝµÇ¼ϵͳ£¬£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡¶ÔÃô¸ÐÊý¾ÝºÍ¹Ø¼üϵͳµÄδÊÚȨ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»·ì϶µÄ¿í·ºÓ°Ïì²»ÈݺöÊÓ£¬£¬£¬£¬£¬£¬ÓÉÓÚ¶à¶à×éÖ¯ÒÀÀµSAMLÉí·ÝÑéÖ¤À´±£ÏÕÀûÓýӼû°²È«£¬£¬£¬£¬£¬£¬Ò»µ©Ôâµ½ÀûÓ㬣¬£¬£¬£¬£¬½«¿ÉÄܵ¼ÖÂÓû§Êý¾Ýй¶ºÍÆóÒµ×ʲúÊÜË𡣡£¡£¡£¡£¡£¡£¡£ÌáÐÑËùÓÐRuby-SAMLÓû§Á¢¼´²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬¸üÐÂÖÁ×îа²È«°æ±¾£¬£¬£¬£¬£¬£¬ÒÔ·À±¸Ç±Ôڵݲȫ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/cve-2024-45409-cvss-10-critical-ruby-saml-flaw-leaves-user-accounts-exposed/
2. ²é¶û˹¡¤´ï¶ûÎÄѧÌÃÔâÀÕË÷Èí¼þ¹¥»÷´¹Î£Í£¿£¿£¿£¿£¿Î
9ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬Ó¢¹úÂ×¶ØÄϲ¿µÄ²é¶û˹¡¤´ï¶ûÎÄѧÌÃÒòÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬°ä·¢±¾ÖÜǰÈýÌ콫¹Ø¹ØÐ£Ô°½øÐÐÍøÂ簲ȫËãÕʹ¤×÷£¬£¬£¬£¬£¬£¬´Ë¾ÙÓ°ÏìÁËÔ¼1300ÃûѧÉúµÄÕý³£½ø½¨¡£¡£¡£¡£¡£¡£¡£¡£×Ô9ÔÂ5ÈÕÆð£¬£¬£¬£¬£¬£¬Ñ§Éú±»ÆÈÀëУ£¬£¬£¬£¬£¬£¬Ð£³¤Aston SmithËæºóÏò¼Ò³¤´«µÝ£¬£¬£¬£¬£¬£¬Õâ´ÎITÎÊÌâʵΪÑϳÁµÄÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂËùÓÐÔ±¹¤É豸±»ÒƳýÒÔ½øÐа²È«´¦Öᣡ£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬Ñ§Ìþö¶¨±ÉÈËÖÜÒ»¡¢¶þ¡¢ÈýÔÝÍ£ÊڿΣ¬£¬£¬£¬£¬£¬ÒÔ±ãÀÏʦ³Áй滮¿Î³Ì£¬£¬£¬£¬£¬£¬ÖÎÀí²ãÔòÖÂÁ¦ÓÚ¹¹½¨ÐÂϵͳÒÔ¸´ÔѧÌÃÔËÓª¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬Ñ§ÉúµÄ΢ÈíOffice 365ÕË»§±»ÁÙʱ½ûÓ㬣¬£¬£¬£¬£¬ÒÔ·À½øÒ»²½·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Ð£³¤Ç¿µ÷£¬£¬£¬£¬£¬£¬ÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬¼Ò³¤ÓëѧÉúӦͨ¹ý¹Ù·½½ø½¨Æ½Ì¨Satchel One»ñÈ¡×îÐÂ֪ͨ£¬£¬£¬£¬£¬£¬ÇÐÎðÇáÐÅÀµºÎδ¾ºËʵµÄÓʼþ»òÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£¼øÓÚÊý¾Ýй¶µÄ¿ÉÄÜÐÔ£¬£¬£¬£¬£¬£¬Ñ§ÌöÔÓëÍøÂ簲ȫר¼ÒçÇÃܺÏ×÷£¬£¬£¬£¬£¬£¬µ«¾ßÌåËðʧϸ½ÚÉдýµ÷²éʵÏÖºó°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£Ð£³¤»¹Ö¸³ö£¬£¬£¬£¬£¬£¬Ö»¹ÜѧÌÃÒѲÉÈ¡ÏȽøµÄ°²È«´ëÊ©£¬£¬£¬£¬£¬£¬´ËÀàÍøÂç¹¥»÷ÈÔÈÕÒæ·è¿ñ£¬£¬£¬£¬£¬£¬Óë½üÆÚÓ¢¹ú¶àÆð³ÛÃû»ú¹¹ÔâÏ®ÊÂÎñÀàËÆ£¬£¬£¬£¬£¬£¬Í¹ÏÔÁËÍøÂ簲ȫÌôÕ½µÄÑϸñÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/ransomware-attack-forces-london-high-school-to-close
3. °ÙÍò°²×¿µçÊÓºÐÔâVo1dºóÃŶñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬È«Çò¶à¹úÂÙÏÝ
9ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ÍþвÕßÀûÓÃÐÂÐÍVo1dºóÃŶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬³É¹¦Ï°È¾ÁËÈ«Çò³¬¹ý130Íǫ̀ÔËÐÐAndroidϵͳµÄµçÊÓÁ÷ýÌåºÐ£¬£¬£¬£¬£¬£¬ÖØÒª¼¯ÖÐÓÚ°ÍÎ÷¡¢Ä¦Âå¸çµÈ¶à¹ú£¬£¬£¬£¬£¬£¬¸³Óè¹¥»÷Õß¶ÔÕâЩÉ豸µÄÆëÈ«½ÚÔìȨ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¿î¶ñÒâÈí¼þÔ´×ÔAndroid¿ªÔ´ÏîÄ¿£¨AOSP£©£¬£¬£¬£¬£¬£¬ÓÉGoogleÖ÷µ¼£¬£¬£¬£¬£¬£¬¿í·ºÓÃÓÚ¶àÖÖÉ豸¡£¡£¡£¡£¡£¡£¡£¡£Dr.WebµÄ×êÑнÒʾ£¬£¬£¬£¬£¬£¬Vo1d¶ñÒâÈí¼þͨ¹ý´Û¸ÄAndroidµÄÆô¶¯¾ç±¾£¨Èçinstall-recovery.sh¡¢daemonsuµÈ£©£¬£¬£¬£¬£¬£¬Êµ´Ë¿ÌÉ豸ÉϵÄÓÆ¾Ã´æÔÚÓë×Ô¶¯Æô¶¯¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖØÒªÖ°ÄÜÓÉvo1dºÍwdÁ½¸ö×é¼þÐͬʵÏÖ£¬£¬£¬£¬£¬£¬vo1dÕÆ¹ÜwdµÄÆô¶¯Óë½ÚÔ죬£¬£¬£¬£¬£¬²¢ÄÜÖ´ÐÐÀ´×ÔC&C·þÎñÆ÷µÄºÅÁ£»£»£»£»£»£»wdÔòÕÆ¹Ü×°ÖÃÊØ»¤¹ý³Ì£¬£¬£¬£¬£¬£¬¼à¶½Ä¿Â¼²¢×°ÖÃAPKÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Ï°È¾õè¾¶ËäÉв»Ã÷È·£¬£¬£¬£¬£¬£¬µ«´§Ä¦¿ÉÄÜÉæ¼°²Ù×÷ϵͳ·ì϶µÄÀûÓûò·Ç¹Ù·½¹Ì¼þÖеÄrootȨÏÞ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÎªÔ¤·À½øÒ»²½Ï°È¾£¬£¬£¬£¬£¬£¬AndroidÓû§Ó¦¶¨ÆÚ²é³²¢×°Öù̼þ¸üУ¬£¬£¬£¬£¬£¬Í¬Ê±Ô¤·ÀʹÓÃÀ´×Էǹٷ½Çþ·µÄAPKÀûÓᣡ£¡£¡£¡£¡£¡£¡£¼øÓÚÊÜϰȾÉ豸ÏÖʵÔËÐеÄÊÇAOSP¶ø·ÇAndroid TV£¬£¬£¬£¬£¬£¬ÕâÒ»·¢ÏÖÇ¿µ÷Á˼´±ãÊÇ»ùÓÚ¿ªÔ´ÏîÖ÷ÕÅÉ豸ҲÐèά³Ö¾¯Ì裬£¬£¬£¬£¬£¬ÒÔ·ÀÔâ·êÀàËÆ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-vo1d-malware-infects-13-million-android-streaming-boxes/
4. Hadooken¶ñÒâÈí¼þ¶Ô×¼Oracle WebLogic·þÎñÆ÷
9ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬AquaµÄ×êÑÐÍŶÓ×î½ü½ÒʾÁËÕë¶ÔOracle WebLogic·þÎñÆ÷µÄϵÁй¥»÷£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ÀûÓÃÈõÃÜÂë×÷ÎªÍ»ÆÆ¿Ú£¬£¬£¬£¬£¬£¬²¿ÊðÁËÒ»ÖÖÐÂÐ˵ÄLinux¶ñÒâÈí¼þHadooken¡£¡£¡£¡£¡£¡£¡£¡£AquaÔÚ¼à¿ØÖв¶»ñµ½ÊýÊ®Æð´ËÀàÈëÇÖ£¬£¬£¬£¬£¬£¬Åú×¢¹¥»÷»î¶¯»îÔ¾ÇÒÆµÈÔ¡£¡£¡£¡£¡£¡£¡£¡£Hadooken ºÜ¿ÉÄÜÒÔ¡¶½ÖÍ·°ÔÍõ¡·µç×ÓÓÎϷϵÁÐÖеÄÒ»´Î¹¥»÷¶¨Ãû£¬£¬£¬£¬£¬£¬¼¯³ÉÁ˼ÓÃÜ¿ó¹¤ÓëDZÔÚµÄTsunami DDoS½©Ê¬ÍøÂçÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Hadookenͨ¹ý´´½¨cronjobʵÏÖÓÆ¾Ã»¯£¬£¬£¬£¬£¬£¬²¢Ô̺¬ÇÔÈ¡Óû§Æ¾Ö¤µÄ¾ç±¾£¬£¬£¬£¬£¬£¬±ãÓÚ¹¥»÷ÕߺáÏòÀ©´óÖÁÆäËû·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Aqua×·×Ùµ½HadookenÏÂÔØÔ´×ÔÁ½¸öIPµØÖ·Ö®Ò»ÓëÓ¢¹úijÍйܹ«Ë¾Óйأ¬£¬£¬£¬£¬£¬µ«ÎÞÖ±½ÓÖ¤¾ÝÅú×¢¸Ã¹«Ë¾Éæ¶ñ¡£¡£¡£¡£¡£¡£¡£¡£½øÒ»²½·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬HadookenÓëRHOMBUSºÍNoEscapeÀÕË÷Èí¼þ´æÔÚ¼¼Êõ¹ØÁª£¬£¬£¬£¬£¬£¬°µÊ¾¹¥»÷Õß¿ÉÄÜͬʱ¶Ô×¼Windows¶ËµãÖ´ÐÐÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬²¢ÀûÓÃLinux·þÎñÆ÷²¿ÊðºóÃźͼÓÃܿ󹤣¬£¬£¬£¬£¬£¬Õë¶Ô´óÐÍÆóÒµÖ´Ðи´ºÏÐÍÍþв¡£¡£¡£¡£¡£¡£¡£¡£
https://www.theregister.com/2024/09/13/hadooken_attacks_oracle_weblogic/
5. ºÚ¿ÍÀûÓÃAzure SharePoint·ì϶µ¼ÖÂFortinet 440GBÊý¾Ýй¶
9ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿Í¡°Fortibitch¡±ÔÚµØÏÂÂÛ̳Breach ForumÉÏÐû³Æ´ÓÍøÂ簲ȫ¾ÞÍ·FortinetµÄAzure SharePointÊ·ýÖÐÇÔÈ¡ÁË440GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬¸Ã·ì϶±»¶¨ÃûΪ¡°Fortileak¡±¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÔð¹ÖFortinetµÄAzure SharePoint¶³ö²¢±»ÈëÇÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬£¬²¢·ÖÏíÁ˽Ӽûƾ֤ÒÔ±ãÏÂÔØÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹Ìáµ½FortinetµÄCEOл¿Ï»Ø¾øÁËÊê½ðÒªÇ󣬣¬£¬£¬£¬£¬²¢ÀäЦÆä̬¶È¡£¡£¡£¡£¡£¡£¡£¡£Fortinet¹Ù·½»ØÓ¦³Æ£¬£¬£¬£¬£¬£¬Ò»ÃûδÊÚȨ¸ö±ð½Ó¼ûÁË´æ´¢ÔÚµÚÈý·½Ôƶ˹²ÏíÎļþÇý¶¯Æ÷ÉϵÄÓÐÏÞÎļþ£¬£¬£¬£¬£¬£¬ÕâЩÎļþÉæ¼°¡°Ò»Óײ¿ÃÅ¡±¿Í»§Êý¾Ý£¬£¬£¬£¬£¬£¬µ«¹«Ë¾ÔËÓª¡¢²úÆ·ºÍ·þÎñδÊÜÓ°Ï죬£¬£¬£¬£¬£¬ÇÒÒÑÓë¿Í»§¹µÍ¨¡£¡£¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬FortinetÒ²Ôâ·ê¹ý°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬Ô̺¬±»ÀûÓÃÁãÈÕ·ì϶ºÍFortiOS²Ù×÷ϵͳ·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬Õâ´ÎÊý¾Ýй¶µÄÑϳÁˮƽ¼°Êê½ð½»Éæ½øÕ¹Éв»Ë¬ÀÊ£¬£¬£¬£¬£¬£¬¿Í»§ºÍÍøÂ簲ȫÁìÓòÕýÇ×êǹØ×¢ÊÂ̬·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£
https://hackread.com/fortinet-confirms-data-breach-hacker-data-leak/
6. DockerSpy£º×Ô¶¯É¨ÃèDocker Hub¾µÏñ£¬£¬£¬£¬£¬£¬ÊØ»¤Ãô¸ÐÊý¾Ý°²È«
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬DockerSpy ÊÇÒ»¿îרΪ½â¾ö Docker ¾µÏñÖÐÃô¸ÐÊý¾Ýй¶ÎÊÌâ¶øÉè¼ÆµÄ¹¤¾ß£¬£¬£¬£¬£¬£¬ËüÄÜ×Ô¶¯É¨Ãè Docker Hub ÉϵÄͼÏñ£¬£¬£¬£¬£¬£¬¼±¾ç¼ìË÷³öÔ̺¬Éí·ÝÑéÖ¤»úÃÜ¡¢Ë½Ô¿µÈÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£´´½¨Õß Alisson Moretto °µÊ¾£¬£¬£¬£¬£¬£¬Ëæ×Å Docker ¾µÏñµÄ¿í·ºÊ¹Ó㬣¬£¬£¬£¬£¬ÓÈÆäÊǹ«¹²¾µÏñ¿âÖÐDZÔڵݲȫÒþ»¼ÈÕÒæÍ¹ÏÔ£¬£¬£¬£¬£¬£¬DockerSpy µÄµ®ÉúÖ¼ÔÚÌṩһ²ã¶î±íµÄ°²È«·®À飬£¬£¬£¬£¬£¬Ô®ÊÖ¿ª·¢Õßʵʱ·¢ÏÖ²¢¶Ï¸ù¾µÏñÖеÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬¼ÓÇ¿°²È«ÐԺͺϹæÐÔ¡£¡£¡£¡£¡£¡£¡£¡£DockerSpy µÄ¹ÖÒìÓÅÊÆÔÚÓÚÆäÓë Docker Hub µÄÎ޷켯³É£¬£¬£¬£¬£¬£¬ÊµÏÖÁË×Ô¶¯»¯ÌáÈ¡ºÍ·ÖÎö¾µÏñµÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬ÎÞÐèÊÖ¶¯¹ýÎÊ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÏȽøµÄɨÃèÒýÇæ¿ÉÄܼø±ð¶àÖÖ´ó¾ÖµÄ»úÃÜÐÅÏ¢£¬£¬£¬£¬£¬£¬ÎÞÂÛÊÇÓ²±àÂëµÄƾ֤»¹Êǰµ²ØÔÚ´úÂë¼°»·¾³±äÁ¿Öеĸ´ÔÓģʽ£¬£¬£¬£¬£¬£¬¶¼ÄÜÓÐЧ׽Äò¢¾ßÌå·ÖÎöDZÔÚ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬DockerSpy ÒÑÔÚ GitHub ÉÏÊ¢¿ªÏÂÔØ£¬£¬£¬£¬£¬£¬¹©¿ª·¢ÕßÃâ·ÑʹÓᣡ£¡£¡£¡£¡£¡£¡£
https://www.helpnetsecurity.com/2024/09/11/dockerspy-extract-sensitive-information-docker-hub-images/?web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ