VMware vCenter Server¼°Cloud FoundationÆØ¹Ø¼ü°²È«·ì϶
°ä²¼¹¦·ò 2024-09-199ÔÂ18ÈÕ£¬£¬£¬£¬£¬VMware¹«Ë¾½üÆÚ¸æ·¢ÁËÁ½¸öÕë¶ÔÆävCenter ServerºÍCloud Foundation²úÆ·µÄ³Á´ó°²È«·ì϶£¬£¬£¬£¬£¬CVE-2024-38812ºÍCVE-2024-38813£¬£¬£¬£¬£¬±ðÀëÉæ¼°¶ÑÒç³öºÍȨÏÞÌáÉýÎÊÌ⣬£¬£¬£¬£¬¶ÔvCenter Server 7.0ºÍ8.0¼°Cloud Foundation 4.xºÍ5.x°æ±¾×é³ÉÍþв¡£¡£¡£¡£¡£¡£¡£¡£CVE-2024-38812ÓÈΪÑϳÁ£¬£¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.8£¬£¬£¬£¬£¬ÔÊÐíÕ¼ÓÐÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õßͨ¹ý·¢ËͶ¨ÔìÊý¾Ý°üÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¶øCVE-2024-38813ÔòÄÜÈù¥»÷Õß½«È¨ÏÞÌáÉýÖÁroot¼¶±ð£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£¡£VMwareÒÑѸËÙÏìÓ¦£¬£¬£¬£¬£¬°ä²¼Á˽¨²¹·¨Ê½£¬£¬£¬£¬£¬²¢Ç¿ÁÒ¶½´ÙÓû§Á¢¼´Éý¼¶ÖÁ×îа汾£¨vCenter Server 8.0 U3b»ò7.0 U3s£¬£¬£¬£¬£¬Cloud FoundationÔòÀûÓÃKB88287ÖеÄÒì²½²¹¶¡£¡£¡£¡£¡£¡£¡£¡£©¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰδ·¢ÏÖÕâЩ·ì϶µÄÒ°±íÀûÓð¸Àý£¬£¬£¬£¬£¬µ«¼øÓÚvCenter ServerÔÚÐé¹¹»¯»·¾³ÖÎÀíÖеÄÖ÷Ìâְ룬£¬£¬£¬£¬ÆäDZÔÚ·çÏÕ²»ÈݺöÊÓ¡£¡£¡£¡£¡£¡£¡£¡£
https://cybersecuritynews.com/vmware-vcenter-server-remote-code/#google_vignette
2. CISA ÖÒ¸æ Adobe Flash Player ·ì϶Õý±»»ý¼«ÀûÓÃ
9ÔÂ17ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÆÚ½«ËĸöÑϳÁµÄAdobe Flash Player·ì϶ÁÐÈëÆäÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖУ¬£¬£¬£¬£¬ÕâЩ·ì϶µÄÆØ¹âÔÙ´Î͹ÏÔÁ˼´±ãÔÚFlash PlayerÒѰ䷢ÓÚ2020ÄêÖÕֹʹÓú󣬣¬£¬£¬£¬ÒÅÁôÈí¼þ·ì϶µÄ³ÖÐø°²È«Íþв¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶£¬£¬£¬£¬£¬Ô̺¬¿É×·ÒäÖÁ2013ÄêµÄCVE-2013-0643ºÍCVE-2013-0648´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬ÒÔ¼°2014ÄêµÄCVE-2014-0497ÕûÊýÏÂÒçºÍCVE-2014-0502Ë«³Á¿ªÊÍ·ì϶£¬£¬£¬£¬£¬¶¼ÔøÊÇÁãÈÕ¹¥»÷µÄÖ¸±ê£¬£¬£¬£¬£¬¶ÔFirefoxÓû§µÈ×é³ÉÍþв¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜFlash PlayerÔøÊÇÍøÂ绥¶¯ÄÚÈݵĻùʯ£¬£¬£¬£¬£¬µ«Ëæ×ʦ·òµÄÍÆÒÆ£¬£¬£¬£¬£¬ËüÒѳÉÎªÖØÒªµÄ°²È«Òþ»¼£¬£¬£¬£¬£¬ÆµÈÔÊܵ½¹¥»÷ÕßÀûÓᣡ£¡£¡£¡£¡£¡£¡£CISAÒò¶ø´¹Î£ºôÓõËùÓÐÁª¹ú»ú¹¹ÔÚ2024Äê10ÔÂ8ÈÕǰ³¹µ×ÒÆ³ýFlash Player£¬£¬£¬£¬£¬ÒÔ½µµÍDZÔڵݲȫ·çÏÕ£¬£¬£¬£¬£¬±£»£»£»£»£»£»£»¤Ãô¸ÐµÐÔÖÊý¾ÝºÍ¹Ø¼ü»ù´¡ÉèÊ©ÃâÊÜÇÖº¦¡£¡£¡£¡£¡£¡£¡£¡£Adobe×Ô2020ÄêÆðÒÑÖÕ³¡Flash PlayerµÄ¿ª·¢£¬£¬£¬£¬£¬Ö÷Á÷ä¯ÀÀÆ÷Ò²²»ÔÙ¼æÈÝ£¬£¬£¬£¬£¬¹ÌÈ» Flash ÒѾÔÚ»¥ÁªÍøµÄ·¢Õ¹ÖвûÑï¹ý³ÁÒª×÷Ó㬣¬£¬£¬£¬µ«Æä°²È«·çÏÕÒÑʹÆä¹ýÆÚ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/cisa-warns-of-actively-exploited-adobe-flash-player-vulnerabilities/
3. UNC2970×éÖ¯ÀûÓÃľÂí»¯PDFÔĶÁÆ÷¹¥»÷¹Ø¼ü»ù´¡ÉèÊ©
9ÔÂ17ÈÕ£¬£¬£¬£¬£¬Mandiant½ÒʾÁËÓ볯ÏʹØÁªµÄUNC2970×éÖ¯ÌáÒéµÄ¸´ÔÓÍøÂç¼äµý»î¶¯£¬£¬£¬£¬£¬¸Ã×éÖ¯ÀûÓø߶ȶ¨ÔìµÄÍøÂç´¹µö¼¿Á©£¬£¬£¬£¬£¬Õë¶ÔÄÜÔ´ºÍº½¿Õº½ÌìµÈ¹Ø¼üÐÐÒµµÄ¸ß¼¶Ô±¹¤¡£¡£¡£¡£¡£¡£¡£¡£UNC2970ͨ¹ý¼Ù×°³É³ÛÃûÆóÒµµÄ¹¤×÷»úÓöµö¶ü£¬£¬£¬£¬£¬ÏòÖ¸±ê·¢ËÍÔ̺¬Ä¾Âí»¯SumatraPDFÔĶÁÆ÷µÄZIPÎļþ£¬£¬£¬£¬£¬¸ÃÔĶÁÆ÷ÄÚǶMISTPENºóÃÅ£¬£¬£¬£¬£¬Ò»µ©Êܺ¦ÕßʹÓÃÆä´ò¿ª¼Ù×°³ÉְλÃèÊöµÄPDFÎļþ£¬£¬£¬£¬£¬¼´´¥·¢Ï°È¾Á´¡£¡£¡£¡£¡£¡£¡£¡£MISTPEN×÷ΪһÖÖÒþÃØ¹¤¾ß£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ¶ñÒâ²Ù×÷£¬£¬£¬£¬£¬ÀûÓúϷ¨·þÎñÈÚÈëÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬ÒÔʵÏֳ־ýÚÔìºÍÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£UNC2970ͨ¹ýÅú¸Ä¿ªÔ´Èí¼þ´úÂëºÍ¾«ÐÄÉè¼ÆµÄְλÃèÊö£¬£¬£¬£¬£¬Ìá¸ßÁ˹¥»÷µÄÒñ±ÎÐԺͳɹ¦ÂÊ£¬£¬£¬£¬£¬¶Ô¶à¸ö¹ú¶ÈµÄ»ù´¡ÉèÊ©°²È«×é³É³Á´óÍþв¡£¡£¡£¡£¡£¡£¡£¡£¼øÓÚÆäÕë¶Ô¹Ø¼üÁìÓòµÄ»î¶¯£¬£¬£¬£¬£¬ÓйØ×éÖ¯Ð费Σ¼ÓÇ¿·ÀÓù´ëÊ©£¬£¬£¬£¬£¬ÒÔÕмܴËÀà¸ß¼¶ÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/unc2970s-backdoor-deployed-via-trojanized-pdf-reader-targets-critical-infrastructure/
4. ¶íÂÞ˹°²È«¹«Ë¾Dr.WebÔâºÚ¿Í¹¥»÷
9ÔÂ18ÈÕ£¬£¬£¬£¬£¬¶íÂÞ˹³ÛÃûµÄ·´¶ñÒâÈí¼þ¹«Ë¾Doctor Web£¨Dr.Web£©¹«¿ª°ä·¢£¬£¬£¬£¬£¬ÆäIT»ù´¡ÉèÊ©Ôâ·êÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬²¢Òò¶ø·¢ÏÖÁ˰²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Ãæ¶ÔÕâÒ»´¹Î£Çé¿ö£¬£¬£¬£¬£¬Dr.WebѸËÙ²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬¶Â½ØÁËËùÓзþÎñÆ÷ÓëÄÚ²¿ÍøÂçµÄÏνӣ¬£¬£¬£¬£¬ÒÔÔ¤·À¹¥»÷½øÒ»²½À©É¢¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ʼÓÚ9ÔÂ14ÈÕ£¬£¬£¬£¬£¬Dr.WebËæ¼´·¢Õ¹ÁËÏ꾡µÄµ÷²é²¢çÇÃÜ¼à¿ØÊÂ̬·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£ÔÚµ÷²éÆÚ¼ä£¬£¬£¬£¬£¬ÎªÁ˱£ÏÕ¿Í»§°²È«£¬£¬£¬£¬£¬Dr.Web²»µÃ²»ÔÚÖÜÒ»ÔÝÍ£Á˲¡¶¾Êý¾Ý¿âµÄ¸üзþÎñ¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¹«Ë¾Ç¿µ÷£¬£¬£¬£¬£¬¶Ô»ù´¡ÉèÊ©µÄ·ÛËḛ́ͼÒѱ»ÊµÊ±¶ôÔ죬£¬£¬£¬£¬ËùÓÐÊÜDr.Web±£»£»£»£»£»£»£»¤µÄÓû§ÏµÍ³¾ùδÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÖÜÈý£¬£¬£¬£¬£¬Dr.Web°ä·¢ÒѸ´Ô²¡¶¾Êý¾Ý¿âµÄ¸üзþÎñ£¬£¬£¬£¬£¬²¢È·ÈÏÕâ´Î°²È«ÊÂÎñ²¢Î´¸øÆä¿Í»§´øÀ´ÈκθºÃæÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Îª³¹µ×½â³ý°²È«Íþв£¬£¬£¬£¬£¬Dr.Web²ÉÈ¡ÁËÔ̺¬Ê¹ÓúÏÓÃÓÚLinuxµÄDr.Web FixIt!ÔÚÄÚµÄһϵÁÐÓ¦¼±´ëÊ©£¬£¬£¬£¬£¬²¢³É¹¦¸ôÀëÁËDZÔÚ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÍøÂçµÄÊý¾ÝΪ°²È«×¨¼ÒÌṩÁ˹ؼüÐÅÏ¢£¬£¬£¬£¬£¬Ô®ÊÖËûÃÇÈ·±£ÏµÍ³°²È«ÎÞÓÝ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/russian-security-firm-drweb-disconnects-all-servers-after-breach/
5. FleetPanda·þÎñÆ÷ÅäÖÃÃýÎó¶³ö°ÙÍò·ÝÃô¸ÐÎļþ
9ÔÂ18ÈÕ£¬£¬£¬£¬£¬Ê¯ÓÍÓëȼÁÏÐÐҵȷµ±ÏÈÈí¼þ¹©¸øÉÌFleetPandaÒò·þÎñÆ÷ÅäÖÃÃýÎó¶øÔâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬½ü°ÙÍò·ÝÃô¸ÐÎļþ±»·¸·¨Â¶³ö¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎļþº¸ÇÁË´Ó2019ÄêÖÁ2024Äê8Ôµķ¢Æ±¡¢ÔËÊä¼Í¼¡¢¼ÝÕÕÐÅÏ¢¼°²¼¾°µ÷²éµÈ£¬£¬£¬£¬£¬Éæ¼°¼ÓÖÝ¡¢¶íÀÕ¸Ô¡¢µÂ¿ËÈøË¹µÈ¶à¸öÖÝ£¬£¬£¬£¬£¬×ÜÁ¿¸ß´ï193GB¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂ簲ȫר¼ÒJeremiah Fowler·¢ÏÖÁËÕâһδÊܱ£»£»£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬ÆäÄÚÈÝÏ꾡µØÕ¹Ê¾ÁËÐÐÒµÄÚµÄȼÁÏÔËÊäÓëÒµÎñÍùÀ´£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬ÁËÉç»á°²È«ºÅÂëµÈ¸ß¶ÈÃô¸ÐµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶²»½öÍþвµ½Ó×ÎÒÒþÖÔ°²È«£¬£¬£¬£¬£¬»¹¿ÉÄÜÒý·¢Éí·Ý͵ÇԺ;¼ÃËðʧ£¬£¬£¬£¬£¬Í¬Ê±£¬£¬£¬£¬£¬·¸×ï·Ö×Ó¿ÉÄÜÀûÓ÷¢Æ±ÐÅÏ¢Ö´ÐÐÚ²ÆÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£¶ÔʯÓͺÍȼÁÏÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬¹©¸øÁ´µÄ²»±äÐÔºÍÐÅÏ¢°²È«ÒàÊܵ½³å»÷£¬£¬£¬£¬£¬¿ÉÄÜÒý·¢Êг¡µßô¤ºÍ¼ÛÖµÉÏÕÇ¡£¡£¡£¡£¡£¡£¡£¡£Fowler½¨ÒéÆóÒµÓ¦½«Ãô¸ÐÊý¾ÝÓëÈÕ³£ÒµÎñÎļþ·ÖÀë´æ´¢£¬£¬£¬£¬£¬Ç¿»¯½Ó¼û½ÚÔ죬£¬£¬£¬£¬¶¨ÆÚ¸üÐÂϵͳ²¢¼ÓǿԱ¹¤Åàѵ£¬£¬£¬£¬£¬ÒÔ¹¹½¨Ô½·¢²»±äµÄÍøÂ簲ȫ·ÀÏß¡£¡£¡£¡£¡£¡£¡£¡£
https://hackread.com/server-misconfiguration-fuel-software-exposed-pii-data/
6. Delta Primeƽ̨Ôâ·êÍøÂç¹¥»÷£¬£¬£¬£¬£¬¼ÓÃÜÇ®±ÒʧÇÔ½üÁù°ÙÍòÃÀÔª
9ÔÂ18ÈÕ£¬£¬£¬£¬£¬Delta Primeƽ̨½üÆÚÔâ·êÑϳÁÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¼ÛÖµ¸ß´ïÔ¼600ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁ£¬£¬£¬£¬£¬Ô¶³¬×î³õ»ã±¨µÄ450ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¡£¡£¡£Çø¿éÁ´°²È«¹«Ë¾CyversÓÚ9ÔÂ16ÈÕÂÊÏȸ淢´ËÊ£¬£¬£¬£¬£¬Ö¸³öºÚ¿ÍÒÑÆðÍ·½«µÁÈ¡µÄUSDCת»»ÎªETH£¬£¬£¬£¬£¬²¢ÖÒ¸æÔÚ¼ì²â³õÆÚ£¬£¬£¬£¬£¬ºÚ¿ÍÇ®°üÈÔ³ÖÐø´Óƽ̨³é×Ê£¬£¬£¬£¬£¬Íþв½øÒ»²½Ëðʧ¡£¡£¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬Fuzzland´ú±íÈ·ÈÏÁËËðʧ×ܶîÒÑÅÊÉýÖÁ½ü600ÍòÃÀÔª£¬£¬£¬£¬£¬²¢½Òʾ´æÔÚ¸ü¶à¶ñÒâÂòÂô»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÈëÇÖ±»¹éÒòÓÚDelta Primeƽ̨Ǯ°üÖÎÀíÔ±ÃÜԿʧÇÔ£¬£¬£¬£¬£¬ºÚ¿ÍµÃÊÖºó½ÚÔìÁËÍйܴúÀíºÏÔ¼µÄÇ®°ü£¬£¬£¬£¬£¬½ø¶øÅú¸ÄºÏÔ¼ÉèÖ㬣¬£¬£¬£¬½«Æä³Á¶¨ÏòÖÁ¶ñÒâºÏÔ¼£¬£¬£¬£¬£¬´Ó¶øÔÚArbitrumÍøÂçÉÏ´ó¾ÙÇÔÈ¡×ʽ𣬣¬£¬£¬£¬×ÜËðʧ¹ÀËã´ïµ½590ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÒýÆðÁËÍøÂ簲ȫÁìÓòµÄ¸ß¶È¹Ø×¢£¬£¬£¬£¬£¬×¨¼ÒÖÒ¸æºÚ¿Í½«À´¿ÉÄܶÔ×¼¸ü´ó¹æÄ£µÄÖ¸±ê£¬£¬£¬£¬£¬³ö¸ñÊÇÃÀ¹ú¼ÓÃÜÇ®±ÒETF»ù½ð£¬£¬£¬£¬£¬ÆäÖØ´óµÄ±ÈÌØ±Ò´¢Ðî¶ÔºÚ¿Í¼«¾ßÒýÓÕÁ¦£¬£¬£¬£¬£¬Ô̺¬³¯ÏÊLazarus¼¯ÍŵÈDZÔÚÍþв¡£¡£¡£¡£¡£¡£¡£¡£¾ÝDune·ÖÎöƽ̨Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬±ÈÌØ±ÒÖ§³ÖµÄETF×Ü×ʲúÒѸߴï534ÒÚÃÀÔª£¬£¬£¬£¬£¬½øÒ»²½Í¹ÏÔÁË´ËÀà×ʲúµÄ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/cyberattack-on-delta-prime-losses-soar-to-6m/


¾©¹«Íø°²±¸11010802024551ºÅ