MicroliseÔâÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬Ö¼àÓü³µºÍ¿ìµÝ³µÁ¾×·×Ùϵͳ̱»¾

°ä²¼¹¦·ò 2024-11-08

1. MicroliseÔâÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬Ö¼àÓü³µºÍ¿ìµÝ³µÁ¾×·×Ùϵͳ̱»¾


11ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬MicroliseÊÇÒ»¼ÒΪ³µ¶ÓÔËÓªÉÌÌṩ³µÁ¾×·×Ù½â¾ö¹æ»®µÄ¹«Ë¾£¬£¬£¬£¬ £¬£¬£¬£¬½üÆÚÔâ·êÁËÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬µ¼ÖÂÆä¼àÓü³µºÍ¿ìµÝ³µÁ¾µÄ×·×ÙϵͳºÍ¾¯±¨ÏµÍ³±»½ûÓᣡ£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÔÚ10ÔÂ31ÈÕ֪ͨÂ×¶ØÖ¤È¯ÂòÂôËùÆäÍøÂçÉϲúÉúÁË¡°Î´¾­ÊÚȨµÄ»î¶¯¡±£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÀñƸÁË±í²¿ÍøÂ簲ȫר¼Ò½øÐе÷²éºÍ¸´Ô­¹¤×÷¡£¡£¡£¡£¡£¡£ ¡£¡£½ØÖÁ11ÔÂ6ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Microlise°µÊ¾ÒÑÔÚ½ÚÔìºÍ¶Ï¸ùÍøÂçÍþв·½Ãæ»ñµÃÄÚÈÝÐÔ½øÕ¹£¬£¬£¬£¬ £¬£¬£¬£¬²¢¸´Ô­ÁËËùÓзþÎñ£¬£¬£¬£¬ £¬£¬£¬£¬Ô¤¼ÆÏÂÖÜÄ©½«È«ÃæÍ¶ÈëÔËÓª¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷δÇÖº¦¿Í»§ÏµÍ³Êý¾Ý£¬£¬£¬£¬ £¬£¬£¬£¬µ«²¿ÃÅÔ±¹¤Êý¾ÝÊܵ½Ó°Ï죬£¬£¬£¬ £¬£¬£¬£¬ÊÜÓ°ÏìÓ×ÎÒ½«Æ¾¾Ý¹«Ë¾¼à¹ÜʹÃüµÃµ½Í¨Öª£¬£¬£¬£¬ £¬£¬£¬£¬²¢·î¸æÓйز¿ÃÅ¡£¡£¡£¡£¡£¡£ ¡£¡£ÊÜÓ°ÏìµÄ¿Í»§Ô̺¬Ó¢¹úµ±¾Ö³Ð°üÉÌSercoºÍ¿ìµÝ¹«Ë¾DHL£¬£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐSercoÔÚÏ®»÷Ó°Ïì·¢ÏÖǰµÄ¼¸ÌìÄÚ£¬£¬£¬£¬ £¬£¬£¬£¬²¿ÃÅÇô·¸»¤ËÍ·þÎñ²»×ãµØÎ»¸ú×ٺͰ²È«±£ÏÕ£¬£¬£¬£¬ £¬£¬£¬£¬¶øDHLµÄ²¿Ãųµ¶ÓÒ²²»×ã×·×ÙÖ°ÄÜ¡£¡£¡£¡£¡£¡£ ¡£¡£MicroliseÎ´Ð¹Â©ÍøÂç¹¥»÷ÀàÐͼ°ÊÜÓ°Ïì¿Í»§µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.securityweek.com/cyberattack-on-microlise-disables-tracking-in-prison-vans-courier-vehicles/


2. CISAÖҸ棺Palo Alto Networks Expedition´æÔÚÉí·ÝÑéÖ¤·ì϶Ôâ¹¥»÷


11ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬CISA½üÈÕ·¢³öÖҸ棬£¬£¬£¬ £¬£¬£¬£¬Ö¸³ö¹¥»÷ÕßÔÚÀûÓÃPalo Alto Networks ExpeditionÖеÄÑϳÁÉí·ÝÑéÖ¤·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£ExpeditionÊÇÒ»ÖÖǨá㹤¾ß£¬£¬£¬£¬ £¬£¬£¬£¬ÓÃÓÚ½«·À»ðǽÅäÖôÓCheckpoint¡¢CiscoµÈ¹©¸øÉÌת»»ÎªPAN-OS¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶£¨CVE-2024-5910£©ÒÑÔÚ7Ôµõ½½¨¸´£¬£¬£¬£¬ £¬£¬£¬£¬µ«ÍþвÕßÈÔÄÜÔ¶³ÌÀûÓÃËü³ÁÖö³öÔÚ»¥ÁªÍøÉϵÄExpedition·þÎñÆ÷ÉϵÄÀûÓ÷¨Ê½ÖÎÀíԱʹ´¦¡£¡£¡£¡£¡£¡£ ¡£¡£CISAÖ¸³ö£¬£¬£¬£¬ £¬£¬£¬£¬´Ë·ì϶ÔÊÐí¹¥»÷ÕßÊÕÊÜExpeditionÖÎÀíÔ¹ØÊ»§£¬£¬£¬£¬ £¬£¬£¬£¬²¢¿ÉÄܽӼû»úÃÜÅäÖá¢Í´´¦¼°ÆäËûÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÍøÂ簲ȫ»ú¹¹Î´Ìṩ¸ü¶à¹¥»÷ϸ½Ú£¬£¬£¬£¬ £¬£¬£¬£¬µ«Horizon3.ai·ì϶×êÑÐÔ±Zach Hanley°ä²¼ÁËÒ»¸ö¸ÅÏëÑéÖ¤·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬¿É½áºÏÁíÒ»¸öÒѽ¨²¹µÄºÅÁî×¢Èë·ì϶£¨CVE-2024-9464£©£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉÏʵÏÖδ¾­Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£ ¡£¡£Palo Alto Networks½¨ÒéÖÎÀíÔ±ÏÞ¶ÈExpeditionµÄÍøÂç½Ó¼û£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÔÚÉý¼¶µ½¹Ì¶¨°æ±¾ºóÂÖ»»ËùÓÐЧ»§Ãû¡¢ÃÜÂëºÍAPIÃÜÔ¿¡£¡£¡£¡£¡£¡£ ¡£¡£CISAÒѽ«¸Ã·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖУ¬£¬£¬£¬ £¬£¬£¬£¬ÒªÇóÃÀ¹úÁª¹ú»ú¹¹ÔÚÈýÖÜÄÚ£¨¼´11ÔÂ28ÈÕǰ£©±£» £»£»£»£»£»£»£»¤ÆäÍøÂçÉϵÄÒ×Êܹ¥»÷·þÎñÆ÷¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-palo-alto-networks-bug-exploited-in-attacks/


3. Androxgh0stÓëMozi½©Ê¬ÍøÂ缯³É£¬£¬£¬£¬ £¬£¬£¬£¬ÍþвȫÇòWebºÍIoTÉ豸°²È«


11ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬CloudSEK»ã±¨Ö¸³ö£¬£¬£¬£¬ £¬£¬£¬£¬Androxgh0st½©Ê¬ÍøÂçÒÑÓëMozi½©Ê¬ÍøÂ缯³É£¬£¬£¬£¬ £¬£¬£¬£¬ÀûÓÃWebÀûÓ÷¨Ê½ºÍIoTÉ豸ÖеĶàÖÖ·ì϶½øÐй¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£×Ô2024Äê1ÔÂÆð£¬£¬£¬£¬ £¬£¬£¬£¬Androxgh0stÕë¶ÔÍøÂç·þÎñÆ÷½øÐÐˢкó³ÁгöÏÖ£¬£¬£¬£¬ £¬£¬£¬£¬²¢¹²ÏíÁËMozi½©Ê¬ÍøÂçµÄ×é¼þ£¬£¬£¬£¬ £¬£¬£¬£¬´Ó¶ø¿ÉÄÜϰȾ¸ü¶àIoTÉ豸¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬ £¬£¬£¬£¬Androxgh0stµÄ¹¥»÷²½ÖèÒÑÀ©´ó£¬£¬£¬£¬ £¬£¬£¬£¬¶Ô×¼ÁËÔ̺¬Cisco ASA¡¢Atlassian JIRA¡¢PHP¿ò¼Ü¡¢Metabase¡¢Apache Web·þÎñÆ÷ºÍ¶àÖÖÎïÁªÍøÉ豸ÔÚÄڵĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£Í¨¹ýÕûºÏMoziµÄÖ°ÄÜ£¬£¬£¬£¬ £¬£¬£¬£¬Androxgh0st¿ÉÄÜÀûÓÃÅäÖÃÃýÎóµÄ·ÓÉÆ÷ºÍÉ豸£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚÈ«ÇòÁìÓòÄÚϰȾÉ豸¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã½©Ê¬ÍøÂ绹Õë¶Ô¶à¸ö¹ú¶ÈºÍµØÓòµÄÉ豸½øÐй¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬µÂ¹úλ¾ÓÊÜϰȾÉ豸ÊýÁ¿°ñÊס£¡£¡£¡£¡£¡£ ¡£¡£×éÖ¯Ó¦Á¢¼´½¨²¹Óйطì϶£¬£¬£¬£¬ £¬£¬£¬£¬¼à¿ØÍøÂçÁ÷Á¿£¬£¬£¬£¬ £¬£¬£¬£¬²¢·ÖÎöÈÕÖ¾ÒÔ²éÕÒÈëÇÖ¼£Ï󣬣¬£¬£¬ £¬£¬£¬£¬ÒÔ±£» £»£»£»£»£»£»£»¤ÏµÍ³ÃâÊÜÕâÖÖ²»ÐÝÑݱäµÄÍþв¡£¡£¡£¡£¡£¡£ ¡£¡£


https://hackread.com/androxgh0st-botnet-integrate-mozi-iot-vulnerabilities/


4. ³¯ÏʺڿÍÀûÓá°°µ²Ø·çÏÕ¡±¶ñÒâÈí¼þ¹¥»÷¼ÓÃÜÇ®±ÒÆóÒµ


11ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬³¯Ïʵ±¾ÖÖ§³ÖµÄAPT×éÖ¯BlueNoroffÔÚÀûÓÃÒ»ÖÖÃûΪ¡°°µ²Ø·çÏÕ¡±µÄÐÂÐͶñÒâÈí¼þ¹¥»÷¼ÓÃÜÇ®±ÒÆóÒµ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹¥»÷ͨ¹ý¾«ÐÄÔì×÷µÄÍøÂç´¹µöµç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÕʹÊܺ¦Õßµã»÷¶ñÒâÁ´½Ó£¬£¬£¬£¬ £¬£¬£¬£¬ÏÂÔØ¼Ù×°³ÉPDFÔĶÁÆ÷µÄ¶ñÒâMacÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©Ö´ÐУ¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÀûÓ÷¨Ê½»á°ÂÃØÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÔìÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬×°ÖúóÃŲ¢ÍøÂçϵͳÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬ÓëÔ¶³Ì·þÎñÆ÷ͨѶ£¬£¬£¬£¬ £¬£¬£¬£¬½Ó¹Ü²¢Ö´ÐкÅÁî¡£¡£¡£¡£¡£¡£ ¡£¡£ÎªÁËÈ·Î¬ÓÆ¾ÃÐÔ£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»¹Åú¸ÄÁËZshÅäÖÃÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬Ê¹ºóÃÅÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯Ö´ÐС£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±ÒÔΪ£¬£¬£¬£¬ £¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯ÓëBlueNoroffÓйØÁª£¬£¬£¬£¬ £¬£¬£¬£¬ÒòÆä¼¼ÊõÓëBlueNoroff´ÓǰµÄ¹¥»÷»î¶¯ÀàËÆ£¬£¬£¬£¬ £¬£¬£¬£¬ÇÒʹÓÃÁËÓëÆäÓйصĶñÒâÈí¼þµÄÓû§´úÀí×Ö·û´®£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÀûÓÿª·¢ÕßÕÊ»§ÈÃApple¹«Ö¤¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬£¬£¬´Ó¶øÈƹý°²È«´ëÊ©¡£¡£¡£¡£¡£¡£ ¡£¡£¼øÓÚBlueNoroffÂÅ´ÎÒÔ¼ÓÃÜÇ®±ÒÂòÂôËù¡¢·çÏÕͶ×ʹ«Ë¾ºÍÒøÐÐΪָ±ê£¬£¬£¬£¬ £¬£¬£¬£¬ÐÐҵӦά³Ö¾¯Ìè¡£¡£¡£¡£¡£¡£ ¡£¡£Óû§Ó¦×Ðϸ²é³­µç×ÓÓʼþµØÖ·£¬£¬£¬£¬ £¬£¬£¬£¬Ô¤·Àµã»÷δ֪µç×ÓÓʼþÖеÄÁ´½Ó£¬£¬£¬£¬ £¬£¬£¬£¬ÓÈÆäÊÇÒªÇóÏÂÔØÀûÓ÷¨Ê½/PDFµÄÁ´½Ó£¬£¬£¬£¬ £¬£¬£¬£¬ÒÔÈ·±£×ÔÉí°²È«¡£¡£¡£¡£¡£¡£ ¡£¡£


https://hackread.com/north-korean-hackers-crypto-fake-news-hidden-risk-malware/


5. °×ñºÚ¿ÍSean Kahler¸æ·¢²¢Öú½¨EAÕË»§ÏµÍ³ÑϳÁ·ì϶


11ÔÂ6ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÎÏ·¿ª·¢Õß¼æÄæÏò¹¤³ÌʦSean Kahler·¢ÏÖ²¢ÀûÓÃÁËÒ»¸öÓ°Ïìµç×ÓÒս磨EA£©ÕË»§ÏµÍ³µÄÑϳÁ·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬·¸·¨»ñÈ¡Á˳¬¹ý7ÒÚEAÓû§ÕË»§ÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬Ô̺¬ÓÎϷͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£Ëûͨ¹ýÔÚÓÎÏ·¿ÉÖ´ÐÐÎļþÖÐÕÒµ½Ó²±àÂëÆ¾Ö¤£¬£¬£¬£¬ £¬£¬£¬£¬»ñµÃÁËEA¿ª·¢ÈËÔ±²âÊÔ»·¾³ÖеÄÌØÈ¨½Ó¼ûÁîÅÆ£¬£¬£¬£¬ £¬£¬£¬£¬½ø¶ø·¢ÏÖÁËÒ»¸ö¶³öµÄÄÚ²¿·þÎñAPI£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃAPIÔÊÐíÅú¸ÄÍæ¼Ò×ÊÁÏ¡£¡£¡£¡£¡£¡£ ¡£¡£KahlerÀûÓô˷ì϶½«EAÕË»§×´Ì¬¸ü¸ÄΪ¡°ÒѲ»ÈÝ¡±£¬£¬£¬£¬ £¬£¬£¬£¬×èÖ¹Óû§µÇ¼ÓÎÏ·£¬£¬£¬£¬ £¬£¬£¬£¬²¢Äܽ«Steam»òXboxÕË»§Á´½Óµ½ÆäËûÓû§µÄEAÕË»§£¬£¬£¬£¬ £¬£¬£¬£¬ÎÞÐèÑéÖ¤»òÃÜÂë¼´¿ÉµÇ¼ÆäËûÕË»§¡£¡£¡£¡£¡£¡£ ¡£¡£ËûÒâʶµ½ÕâÒ»·ì϶µÄÑϳÁÐԺ󣬣¬£¬£¬ £¬£¬£¬£¬ÓÚ2024Äê6ÔÂ16ÈÕÏòEAÕÆ¹ÜÈεØÅû¶ÁË·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬EAÈ·ÈÏÁË·ì϶²¢°ä²¼ÁËÎå¸ö²¹¶¡½øÐн¨¸´¡£¡£¡£¡£¡£¡£ ¡£¡£È»¶ø£¬£¬£¬£¬ £¬£¬£¬£¬KahlerÖ¸³öEA»¨Á˽ϳ¤¹¦·ò²Å½¨¸´·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬ÇÒÉÐδÆô¶¯·ì϶Éͽð´òË㣬£¬£¬£¬ £¬£¬£¬£¬²»×ã»ã±¨·ì϶µÄ¶¯Á¦¡£¡£¡£¡£¡£¡£ ¡£¡£


https://cybernews.com/security/whitehat-gains-access-to-over-700-million-ea-accounts/


6. GodFather¶ñÒâÈí¼þÈ«ÇòÀ©ÕÅ£ºÕë¶Ô500¶à¸ö½ðÈÚÀûÓÃ


11ÔÂ7ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Cyble ×êÑÐÓëµý±¨³¢ÊÔÊÒ (CRIL) »ã±¨Ö¸³ö£¬£¬£¬£¬ £¬£¬£¬£¬GodFather ¶ñÒâÈí¼þµÄÁìÓòÒÑÀ©´óÖÁÈ«Çò 500 ¶à¸öÒøÐкͼÓÃÜÇ®±ÒÀûÓ÷¨Ê½£¬£¬£¬£¬ £¬£¬£¬£¬Ñ¡È¡¸´ÔÓ¼¼ÊõÈç±¾»ú´úÂëʵÏÖºÍ×îµÍȨÏÞ£¬£¬£¬£¬ £¬£¬£¬£¬Ê¹Æä±ÈÒÔǰԽ·¢ÄÑÒÔ×½ÃþºÍΣÏÕ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÀûÓô¹µöÍøÕ¾·Ö·¢¼Ù×°³ÉºÏ·¨ÀûÓ÷¨Ê½µÄ¶ñÒâ APK Îļþ£¬£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡ÒøÐÐÆ¾Ö¤¡£¡£¡£¡£¡£¡£ ¡£¡£Ëü»¹ÄÜÀûÓà Android É豸µÄ Accessibility ·þÎñÖ´Ðи÷Àà¶ñÒâÖ°ÄÜ£¬£¬£¬£¬ £¬£¬£¬£¬Èç×Ô×ÅÊÖÊÆ¡¢ÓëºÅÁîºÍ½ÚÔì·þÎñÆ÷³ÉÁ¢ÏνÓÒÔ¼°¼üÅ̼ͼ¡£¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©¼ì²âµ½Ö¸±êÀûÓ÷¨Ê½£¬£¬£¬£¬ £¬£¬£¬£¬GodFather ¾Í»á¹Ø¹ØºÏ·¨ÀûÓ÷¨Ê½²¢¼ÓÔØÐéαµÇÂ¼Ò³ÃæÒÔÇÔȡʹ´¦¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬ÆäµØÀí¸²¸ÇÁìÓòÒ²ÔÚÀ©´ó£¬£¬£¬£¬ £¬£¬£¬£¬ÏÖÒÑÕë¶ÔÈÕ±¾¡¢ÐÂ¼ÓÆÂ¡¢°¢Èû°Ý½®ºÍÏ£À°µÄÓû§¡£¡£¡£¡£¡£¡£ ¡£¡£CRIL ×Ü½á³Æ£¬£¬£¬£¬ £¬£¬£¬£¬Æ¾½èÆäеÄ×Ô¶¯»¯²Ù×÷ºÍÔÚ¸ü¶à¹ú¶È/µØÓòÕë¶ÔÀûÓ÷¨Ê½µÄ¸ü¿í·ºÖ¸±ê£¬£¬£¬£¬ £¬£¬£¬£¬GodFather ¶ñÒâÈí¼þ¶ÔÈ«ÇòÓû§×é³ÉÁËÔ½À´Ô½´óµÄ·çÏÕ£¬£¬£¬£¬ £¬£¬£¬£¬Òò¶øÎ¬³Ö¾¯Ìè²¢ÔÚÒÆ¶¯É豸ÉϲÉȡ׳´óµÄ°²È«´ëÊ©ÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/godfather-malware-now-targets-500-banking-and-crypto-apps