BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ£¬£¬£¬£¬£¬£¬£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀
°ä²¼¹¦·ò 2024-12-201. BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ£¬£¬£¬£¬£¬£¬£¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬BadBox Android ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÀ©ÕÅ£¬£¬£¬£¬£¬£¬£¬Ï°È¾É豸ÊýÁ¿Òѳ¬¹ý192,000̨£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³ÛÃûÆ·ÅÆµÄÖÇÄܵçÊÓºÍÖÇÄÜÊÖ»ú£¬£¬£¬£¬£¬£¬£¬ÈçYandexºÍº£ÐÅ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×î³õͨ¹ý¹©¸øÁ´¹¥»÷ϰȾ²»³ÛÃûÔì×÷É̵ÄÉ豸£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑÀ©´óµ½ÔÚÏßÏúÊÛµÄÎÞÃû²úÆ·¼°ÆäËû³ÛÃûÆ·ÅÆ¡£¡£¡£¡£¡£¡£ÆäÖ¸±êÖØÒªÊÇ»ñÈ¡¾¼ÃÀûÒæ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý½«É豸Ôì³Éסլ´úÀí»òÓÃÓÚ¸æ°×Ú²ÆÊµÏÖ¡£¡£¡£¡£¡£¡£Ö»¹ÜµÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©Ôø°ä·¢µ·»ÙBadBoxµÄÐж¯£¬£¬£¬£¬£¬£¬£¬¶Â½ØÁË30,000̨É豸µÄͨѶ£¬£¬£¬£¬£¬£¬£¬µ«BadBoxÈÔÔÚ³ÖÐø·¢Õ¹¡£¡£¡£¡£¡£¡£BitSight×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÑ×°ÖÃÔÚ192,000̨É豸ÉÏ£¬£¬£¬£¬£¬£¬£¬ÇÒÊýÁ¿ÈÔÔÚÎȲ½Ôö³¤¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÉè±¸ÖØÒªÎ»ÓÚ¶íÂÞ˹¡¢Öйú¡¢Ó¡¶È¡¢°×¶íÂÞ˹¡¢°ÍÎ÷ºÍÎÚ¿ËÀ¼¡£¡£¡£¡£¡£¡£Ïû·ÑÕßÓ¦ÀûÓÃ×îеĹ̼þ°²È«¸üС¢½«ÖÇÄÜÉ豸Óë¹Ø¼üϵͳ¸ôÀë²¢ÔÚ²»Ê¹ÓÃʱ¶Ï¿ªÍøÂçÏνӣ¬£¬£¬£¬£¬£¬£¬ÒÔ·À±¸BadBoxϰȾ¡£¡£¡£¡£¡£¡£ÈôÉ豸ÎÞ¿ÉÓøüУ¬£¬£¬£¬£¬£¬£¬½¨Òé¶Ï¿ªÍøÂç»ò¹Ø¹ØÉ豸¡£¡£¡£¡£¡£¡£Ï°È¾¼£ÏóÔ̺¬¹ýÈÈ¡¢»úÄܽµÂä¡¢´¦ÖÃÆ÷ʹÓÃÂʸߺÍÍøÂçÁ÷Á¿Òì³£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/badbox-malware-botnet-infects-192-000-android-devices-despite-disruption/
2. ΢Èí365 OfficeÀûÓÃÏÖ¡°²úÆ·ÒÑÍ£Óá±ÃýÎ󣬣¬£¬£¬£¬£¬£¬Ô´ÓÚÐí¿ÉÖ¤µ÷»»ÎÊÌâ
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚµ÷²éÒ»¸öµ¼ÖÂMicrosoft 365 OfficeÀûÓÃÓû§´¥·¢¡°²úÆ·ÒÑÍ£Óá±ÃýÎóµÄÎÊÌâ¡£¡£¡£¡£¡£¡£¾ÝRedditºÍ΢ÈíÉçÇøÍøÕ¾ÉϵĻ㱨£¬£¬£¬£¬£¬£¬£¬Óû§ÔÚOfficeÀûÓÃÖÐËæ»úÊÕµ½´ËÃýÎ󣬣¬£¬£¬£¬£¬£¬Ôì³É»ìÂÒºÍÖжϡ£¡£¡£¡£¡£¡£ÎÊÌâÔ´ÓÚÖÎÀíÔ±ÌáÒéµÄÐí¿ÉÖ¤µ÷»»£¬£¬£¬£¬£¬£¬£¬ÈçÒÆ¶¯Óû§µ½·ÖÆçµÄÐí¿É×é»ò¸ü¸ÄÓû§¶©ÔÄ¡£¡£¡£¡£¡£¡£µ±ÖÎÀíԱɾ³ý²¢³ÁÐÂÔö³¤Óû§µ½Ðí¿ÉÖ¤×é¡¢µ÷ÕûÐí¿ÉÖ¤»ò·þÎñ´òËãÉèÖ㬣¬£¬£¬£¬£¬£¬»òÇл»¡°×îа汾µÄ×ÀÃæÀûÓ÷¨Ê½¡±·þÎñ´òËãʱ£¬£¬£¬£¬£¬£¬£¬Ò²»á´¥·¢´ËÎÊÌâ¡£¡£¡£¡£¡£¡£Óû§Äܹ»Í¨¹ýµ¥»÷ÃýÎóºá·ùÉϵġ°³Áм¤»î¡±°´Å¥»òÍ˳ö²¢³ÁÐÂÆô¶¯Microsoft 365ÀûÓÃÀ´½â¾ö´ËÎÊÌâ¡£¡£¡£¡£¡£¡£ÈôÊÇÎÊÌâÒÀÈ»´æÔÚ£¬£¬£¬£¬£¬£¬£¬½¨ÒéÁªÏµÖÎÀíÔ±²é³¶©ÔÄÊÇ·ñÒѹýÆÚ¡£¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÓÐδ½â¾öÖ§³Ö°¸ÀýµÄÓû§ÌṩʹÓÃOfficeÐí¿ÉÕï¶Ï¹¤¾ßÍøÂçµÄÕï¶ÏÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÊÜÓ°ÏìµÄÓû§Ìṩ´æ´¢ÔÚ%temp%/diagnosticsĿ¼ÖеÄÈÕÖ¾¡£¡£¡£¡£¡£¡£¹ÌȻ΢ÈíÉÐδ°ä²¼½¨¸´¹¦·ò±í£¬£¬£¬£¬£¬£¬£¬µ«Æä¹¤³ÌÍŶÓÔÚ»ý¼«µ÷²é´ËÎÊÌ⣬£¬£¬£¬£¬£¬£¬²¢¼¤ÀøÊÜÓ°ÏìµÄÓû§ºÍÖÎÀíÔ±¹Ø×¢ÆäÖ§³ÖÇþ·ÒÔ»ñÈ¡¸üС£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-users-hit-by-random-product-deactivation-errors/
3. ÑÇÂíÑ·ÀûÓÃÉ̵꾪ÏÖBMI CalculationVsn¶ñÒâ¼äµýÈí¼þ
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬ÔÚÑÇÂíÑ·ÀûÓÃÉ̵êÖУ¬£¬£¬£¬£¬£¬£¬Ò»¿îÃûΪ¡°BMI CalculationVsn¡±µÄAndroidÀûÓ÷¨Ê½±»·¢ÏÖÏÖʵÉÏÊÇÒ»¿î¶ñÒâ¼äµýÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ëü¼Ù×°³É½¡È«¹¤¾ßÇÔÈ¡Óû§É豸Êý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÓÉÂõ¿Ë·Æ³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬²¢Òѱ»´ÓÉ̵êÖÐÒÆ³ý£¬£¬£¬£¬£¬£¬£¬µ«ÒÑ×°ÖõÄÓû§ÐèÊÖ¶¯É¾³ý²¢Ö´ÐÐÆëȫɨÃèÒԶϸù²ÐÁôºÛ¼£¡£¡£¡£¡£¡£¡£¸Ã¼äµýÈí¼þÓÉ¡°PT Visionet Data Internasional¡±°ä²¼£¬£¬£¬£¬£¬£¬£¬×î³õÐû´«ÎªÉí¶ÎÖÊÁ¿Ö¸Êý£¨BMI£©ÍÆËãÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ºó¶ÜÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬Æô¶¯ÆÁϼÔì·þÎñ¡¢É¨ÃèÒÑ×°ÖõÄÀûÓ÷¨Ê½ÒÔ¼°À¹½Ø²¢ÍøÂç¶ÌÐÅ£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò»´ÎÐÔÃÜÂëºÍÑéÖ¤Âë¡£¡£¡£¡£¡£¡£¼øÓÚ´ËÀàΣÏÕÀûÓÃÈÔÄÜÌӱܺϷ¨ÀûÓÃÉ̵êµÄ´úÂëÉó²é£¬£¬£¬£¬£¬£¬£¬AndroidÓû§Ó¦Ö»×°ÖÃÀ´×Ô³ÛÃû¿¯ÐÐÉ̵ÄÀûÓ㬣¬£¬£¬£¬£¬£¬²¢×Ðϸ²é³ËùÒªÇóµÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÔÚ×°Öúó³·ÏúÓзçÏÕµÄȨÏÞ¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬Î¬³ÖGoogle Play Protect»îԾ״̬¶ÔÓÚ¼ì²â²¢×èÖ¹ÒÑÖª¶ñÒâÈí¼þÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/android-spyware-found-on-amazon-appstore-disguised-as-health-app/
4. Mirai¶ñÒâÈí¼þÀûÓÃĬÈÏÆ¾Ö¤Ï°È¾Session Smart·ÓÉÆ÷
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬Õ°²©ÍøÂçÏò¿Í»§·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬Ö¸³öMirai¶ñÒâÈí¼þÔÚÀûÓÃĬÈÏÆ¾Ö¤¹¥»÷²¢Ï°È¾Session Smart·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬½ø¶øÌáÒéÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áɨÃèÓµÓÐĬÈϵǼʹ´¦µÄÉ豸£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ»ñµÃ½Ó¼ûȨÏÞºóÔ¶³ÌÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£Õ°²©ÍøÂ罨Òé¿Í»§Á¢¼´¸ü¸ÄËùÓÐSession Smart·ÓÉÆ÷ÉϵÄĬÈÏÍ´´¦£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓùÖÒìÇÒÇ¿µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬Í¬Ê±Î¬³Ö¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬£¬²é³½Ó¼ûÈÕÖ¾ÖеÄÒì³££¬£¬£¬£¬£¬£¬£¬²¢²¿ÊðÈëÇÖ¼ì²âϵͳºÍ·À»ðǽÀ´¼ÓÇ¿°²È«ÐÔ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Õ°²©ÍøÂ绹ÌáÐÑÖÎÀíÔ±°ÑÎÈDZÔÚµÄÈëÇÖÖ¸±ê£¬£¬£¬£¬£¬£¬£¬ÈçɨÃè³£¼û¶Ë¿Ú¡¢SSH·þÎñµÇ¼³¢ÊÔʧ°Ü¡¢³öÕ¾Á÷Á¿¼¤ÔöµÈ¡£¡£¡£¡£¡£¡£ÒѾϰȾµÄ·ÓÉÆ÷±ØÐë³ÁÐÂÓ³Ïñ»¯ÄÜÁ¦³ÁÐÂÉÏÏß¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬£¬Õ°²©ÍøÂçÒ²ÔøÂÅ´ÎÖÒ¸æÆä²úÆ·ÖдæÔÚµÄÔ¶³Ì´úÂëÖ´Ðзì϶ºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ÁËÏàÓ¦µÄ²¹¶¡¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/juniper-warns-of-mirai-botnet-targeting-session-smart-routers/
5. BeyondTrustÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬·¢ÏÖ°²È«·ì϶²¢´¹Î£Ó¦¶Ô
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬BeyondTrustÊÇÒ»¼ÒÌá¹©ÌØÈ¨½Ó¼ûÖÎÀíºÍ°²È«Ô¶³Ì½Ó¼û½â¾ö¹æ»®µÄÍøÂ簲ȫ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÔÚ12Ô³õÔâ·êÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÈëÇÖÁËÆä²¿ÃÅÔ¶³ÌÖ§³ÖSaaSÊ·ý£¬£¬£¬£¬£¬£¬£¬»ñµÃÁËÔ¶³ÌÖ§³ÖSaaS APIÃÜÔ¿µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬Äܹ»³ÁÖñ¾µØÀûÓ÷¨Ê½ÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£¡£BeyondTrustÁ¢¼´³·ÏúÁËAPIÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬Í¨ÖªÁËÊÜÓ°ÏìµÄ¿Í»§£¬£¬£¬£¬£¬£¬£¬²¢ÔÝÍ£ÁËÕâЩÊ·ý¡£¡£¡£¡£¡£¡£ÔÚµ÷²é¹ý³ÌÖУ¬£¬£¬£¬£¬£¬£¬·¢ÏÖÁËÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öΪÑϳÁµÄºÅÁî×¢Èë·ì϶CVE-2024-12356£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öΪÖеÈÑϳÁÐÔ·ì϶CVE-2024-12686¡£¡£¡£¡£¡£¡£BeyondTrustÒÑ×Ô¶¯ÔÚËùÓÐÔÆÊ·ýÉÏÀûÓÃÁËÕë¶ÔÕâÁ½¸öȱµãµÄ²¹¶¡£¬£¬£¬£¬£¬£¬£¬µ«ÔËÐÐ×ÔÍйÜÊ·ýµÄÓû§±ØÒªÊÖ¶¯ÀûÓð²È«¸üС£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇ·ñÀûÓÃÕâЩ·ì϶À´¹¥»÷ÏÂÓοͻ§£¬£¬£¬£¬£¬£¬£¬µ«CISA°µÊ¾CVE-2024-12356Òѱ»ÀûÓÃÓÚ¹¥»÷¡£¡£¡£¡£¡£¡£BeyondTrust°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ³ÖÐøÓë¶ÀÁ¢µÄµÚÈý·½ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½øÐг¹µ×µ÷²é£¬£¬£¬£¬£¬£¬£¬²¢×¨Ò»ÓÚÈ·±£ËùÓпͻ§Ê·ý¶¼µÃµ½È«Ãæ¸üкͰ²È«±£ÏÕ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/
6. FortiWLMÆØÑϳÁ·ì϶£º¿ÉÔ¶³ÌÊÕÊÜÉ豸
12ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬FortinetÎÞÏßÖÎÀíÆ÷£¨FortiWLM£©ÖдæÔÚÒ»¸ö±àºÅΪCVE-2023-34990µÄÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìWebÒªÇóÖ´ÐÐδ¾ÊÚȨµÄ´úÂë»òºÅÁ£¬£¬£¬£¬£¬£¬´Ó¶øÊÕÊÜÉ豸¡£¡£¡£¡£¡£¡£´Ë·ì϶ÊÇÒ»¸öÏà¶Ôõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬ÓÉHorizon3×êÑÐÔ±Zach HanleyÔÚ2023Äê5Ô·¢ÏÖ¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ÔÚ³¤´ïÊ®¸öԵŦ·òÀ£¬£¬£¬£¬£¬£¬¸Ã·ì϶δµÃµ½½¨¸´£¬£¬£¬£¬£¬£¬£¬ÆÈʹHanleyÔÚ2024Äê3Ô¹«¿ªÅû¶ÁË·ì϶ÐÅÏ¢ºÍÖ¤Ã÷´úÂ루POC£©¡£¡£¡£¡£¡£¡£ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»¶ÁÈ¡Ãô¸ÐÈÕÖ¾Îļþ£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÖÎÀíÔ±»á»°ID£¬£¬£¬£¬£¬£¬£¬½ø¶ø½Ù³ÖÖÎÀíÔ±»á»°²¢»ñÈ¡ÌØÈ¨½Ó¼û¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËFortiWLM°æ±¾8.6.0ÖÁ8.6.5ºÍ8.5.0ÖÁ8.5.4¡£¡£¡£¡£¡£¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑ·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚ²»×ãCVE IDºÍ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬Óû§²¢Î´Òâʶµ½·çÏÕ¡£¡£¡£¡£¡£¡£Ö±µ½2024Äê12ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬Fortinet²Å°ä²¼°²È«²¼¸æ³Æ£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ2023Äê9Ôµװ䲼µÄFortiWLM°æ±¾8.6.6ºÍ8.5.5Öеõ½½¨¸´¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£Ë¼¿¼µ½FortiWLM±»¿í·ºÀûÓÃÓÚµ±¾Ö»ú¹¹¡¢Ò½ÁƱ£½¡×éÖ¯¡¢½ÌÓý»ú¹¹ºÍ´óÐÍÆóÒµµÈ¹Ø¼ü»·¾³ÖУ¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄ´æÔÚ¿ÉÄܵ¼ÖÂÕû¸öÍøÂçÖжϺÍÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéFortiWLMÖÎÀíԱʵʱÀûÓÃËùÓпÉÓøüС£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortiwlm-bug-giving-hackers-admin-privileges/


¾©¹«Íø°²±¸11010802024551ºÅ