GFI KerioControl·À»ðǽÔâÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶Íþв

°ä²¼¹¦·ò 2025-02-11

1. GFI KerioControl·À»ðǽÔâÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶Íþв


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬³¬¹ýÒ»ÍòÁ½Ç§¸ö GFI KerioControl ·À»ðǽÊ·ý±»·¢ÏÖ´æÔÚ±àºÅΪ CVE-2024-52875 µÄÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£KerioControl ÊÇÒ»¿îרΪÖÐÓ×ÐÍÆóÒµÉè¼ÆµÄÍøÂ簲ȫÌ×¼þ£¬ £¬£¬£¬£¬£¬£¬Ö°ÄÜÔ̺¬ VPN¡¢´ø¿íÖÎÀí¡¢»ã±¨¼à¿Ø¡¢Á÷Á¿¹ýÂË¡¢AV ±£»£»£»£»£»£»£»£»¤ºÍÈëÇÖ·ÀÓù¡£¡£¡£¡£¡£¡£´Ë·ì϶Óɰ²È«×êÑÐÔ± Egidio Romano£¨EgiX£©ÓÚ 2024 Äê 12 ÔÂÖÐÑ®·¢ÏÖ£¬ £¬£¬£¬£¬£¬£¬²¢Õ¹Ê¾ÁË¿ÉÄܵÄÒ»¼ü RCE ¹¥»÷¡£¡£¡£¡£¡£¡£Ö»¹Ü GFI Software ÒÑÔÚ 12 Ô 19 ÈÕ°ä²¼ÁËÕë¶Ô¸ÃÎÊÌâµÄ°²È«¸üУ¨9.4.5 Patch 1 °æ±¾£©£¬ £¬£¬£¬£¬£¬£¬µ«Æ¾¾Ý Censys Êý¾Ý£¬ £¬£¬£¬£¬£¬£¬ÈýÖܺóÈÔÓдóÁ¿Ê·ý佨¸´¡£¡£¡£¡£¡£¡£Greynoise ÒѼì²âµ½ÀûÓø÷ì϶µÄ×Ô¶¯¹¥»÷³¢ÊÔ£¬ £¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡ÖÎÀíÔ± CSRF ÁîÅÆ¡£¡£¡£¡£¡£¡£Shadowserver Foundation »ã±¨³Æ£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°ÈÔÓÐ 12,229 ¸ö KerioControl ·À»ðÇ½Ãæ¶Ô´Ë·ì϶Íþв£¬ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµØÓòÔ̺¬ÒÁÀÊ¡¢ÃÀ¹ú¡¢Òâ´óÀû¡¢µÂ¹úµÈ¡£¡£¡£¡£¡£¡£ÓÉÓÚ´æÔÚ¹«¿ªµÄ·ì϶֤Ã÷£¨PoC£©£¬ £¬£¬£¬£¬£¬£¬ÀûÓÃÃż÷¼«µÍ£¬ £¬£¬£¬£¬£¬£¬ÉõÖÁ²»´¿ÊìµÄºÚ¿ÍÒ²¿ÉÄܲμӶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£·ì϶ԭÒòÔÚÓÚÓû§ÊäÈëδµÃµ½Êʵ±ËãÕÊ£¬ £¬£¬£¬£¬£¬£¬¿ÉÄܱ»ÀûÓÃÖ´ÐÐ HTTP ÏìÓ¦²ð·Ö¹¥»÷£¬ £¬£¬£¬£¬£¬£¬½ø¶ø¿ÉÄܵ¼Ö·´ÉäÐÍ¿çÕ¾µã¾ç±¾£¨XSS£©ºÍÆäËû¹¥»÷¡£¡£¡£¡£¡£¡£Òò¶ø£¬ £¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéÉÐδÀûÓøüеÄÓû§×°Öà 2025 Äê 1 Ô 31 ÈÕ°ä²¼µÄ KerioControl °æ±¾ 9.4.5 Patch 2£¬ £¬£¬£¬£¬£¬£¬ÒÔ¼ÓÇ¿°²È«ÐÔ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-12-000-keriocontrol-firewalls-exposed-to-exploited-rce-flaw/


2. HandalaºÚ¿Í×é֝ɿÏÓ¶ÔÒÔÉ«Áо¯·½·¢Æð´ó¹æÄ£ÍøÂç¹¥»÷


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬³ôÃûÔ¶ÑïµÄHandalaºÚ¿Í×éÖ¯£¬ £¬£¬£¬£¬£¬£¬ÉæÏÓÓëÒÁÀʵý±¨»ú¹¹ÓйØÁª£¬ £¬£¬£¬£¬£¬£¬½üÆÚ°ä·¢¶ÔÒÔÉ«Áо¯Ô±¶ÓÁз¢ÆðÁËÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬Ðû³Æ³É¹¦ÇÔÈ¡ÁË2.1TBµÄÃô¸ÐÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬Ô̺¬ÈËʼͼ¡¢±øÆ÷Çåµ¥¡¢Ò½ÁƺÍÉúÀíµµ°¸µÈ£¬ £¬£¬£¬£¬£¬£¬²¢¹«¿ª´«²¼ÁËÆäÖÐ35Íò·ÝÎļþ¡£¡£¡£¡£¡£¡£Ö»¹ÜÒÔÉ«Áо¯·½·ñ¶¨ÏµÍ³Ö±½ÓÔâÈëÇÖ£¬ £¬£¬£¬£¬£¬£¬µ«Õâ´ÎÊý¾Ýй¶ÊÂÎñÁìÓò¿í·º£¬ £¬£¬£¬£¬£¬£¬Éæ¼°´óÁ¿Ãô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬Èçµç×ÓÓʼþµØÖ·¡¢³Öǹ֤¡¢¾¯¹ÙÕÕÆ¬ºÍÓ×ÎÒÁªÏµ·½Ê½µÈ¡£¡£¡£¡£¡£¡£Í¬Ê±£¬ £¬£¬£¬£¬£¬£¬Handala»¹Ö¸¿ØÆä»ñÈ¡Á˾¯Ô±µÄÉúÀíÆÀ¹ÀµÈ¸öÈËÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬²¢ÇÖÈëÁËÒÔÉ«Áйú¶È°²È«ÊýµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÊÇHandalaÕë¶ÔÒÔÉ«ÁÐʵÌåÖ´ÐзÛËéÐÔÍøÂçÐж¯µÄµäÐͰ¸Àý£¬ £¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚÒÔÉ«ÁÐÓë¹þÂí˹ì¶ÜÉý¼¶ºó£¬ £¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÒѳÉΪÒÁÀÊÍøÂçÐж¯µÄÖØÒªÖ¸±ê¡£¡£¡£¡£¡£¡£HandalaµÄ»î¶¯ÆµÈÔ£¬ £¬£¬£¬£¬£¬£¬²»½öÉæÏӲμÓÕë¶ÔÒÔÉ«ÁÐ×éÖ¯ÍøÂ簲ȫÈËÔ±µÄÍøÂç´¹µö»î¶¯£¬ £¬£¬£¬£¬£¬£¬»¹Õë¶ÔÒÔÉ«ÁеÄSoreqºË×êÑÐÖÐÐÄ·¢ÆðÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬×î½üÓÖÈëÇÖÁËÒÔÉ«Áеç×Ó¹«Ë¾ÔËÓªµÄ´¹Î£¾¯±¨ÏµÍ³£¬ £¬£¬£¬£¬£¬£¬Òý·¢´óÁìÓò·¢¼±¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚÌû×ÓÖг°·íÒÔÉ«ÁУ¬ £¬£¬£¬£¬£¬£¬Ç¿µ÷Æä³É¹¦Í»ÆÆ·ÀÓù²¢¸æ·¢°ÂÃØ£¬ £¬£¬£¬£¬£¬£¬³ÁÉêÆä¡°²»»á½¡Íü£¬ £¬£¬£¬£¬£¬£¬²»»áÔ­Á¡±µÄ±êÓï¡£¡£¡£¡£¡£¡£


https://hackread.com/handala-hackers-israeli-police-breach-data-leak/


3. ¾¯·½¿ÛÁô 4 Ãû Phobos ÀÕË÷Èí¼þÏÓÒÉÈË£¬ £¬£¬£¬£¬£¬£¬²é·â 8Base ÍøÕ¾


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬È«Çò·¨ÂÉÐж¯¡°Phobos Aetor¡¹Øë¶ÔPhobosÀÕË÷Èí¼þÍŻ﷢չ£¬ £¬£¬£¬£¬£¬£¬ÒÑÔÚÌ©¹úÆÕ¼ªµº¿ÛÁôËÄÃûÅ·ÖÞºÚ¿ÍÏÓÒÉÈË£¬ £¬£¬£¬£¬£¬£¬²¢²é·â8Base°µÍøÍøÕ¾¡£¡£¡£¡£¡£¡£ÕâЩÏÓÒÉÈ˱»Ö¸¿Ø¶ÔÈ«Çò³¬¹ý1000ÃûÊܺ¦Õß½øÐÐÁËÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÀÕË÷Á˼ÛÖµ1600ÍòÃÀÔªµÄ±ÈÌØ±Ò¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯Éæ¼°¶à¸ö¹ú¶ÈºÍµØÓòµÄ¾¯·½Ð­Í¬Í»Ï®£¬ £¬£¬£¬£¬£¬£¬½É»ñÁ˵ç×ÓÉ豸ºÍ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£¡£8BaseÀÕË÷Èí¼þÍÅ»ï×Ô2022Äê3Ô³ÉÁ¢ÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬Ò»ÏòÏà¶ÔƧ¾²£¬ £¬£¬£¬£¬£¬£¬Ö±µ½2023Äê6ÔÂÆðͷй¶Êܺ¦ÕßÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï»áÈëÇÔìóÒµÍøÂ磬 £¬£¬£¬£¬£¬£¬ÇÔÈ¡Êý¾Ý²¢Ê¹ÓÃPhobosÀÕË÷Èí¼þ¼ÓÃÜÆ÷¼ÓÃÜÉ豸£¬ £¬£¬£¬£¬£¬£¬ÒªÇóÖ§¸¶¸ß¶îÊê½ðÒÔ»»È¡½âÃÜÃÜÔ¿ºÍ²»°ä²¼Êý¾ÝµÄ³Ðŵ¡£¡£¡£¡£¡£¡£³ÛÃûÊܺ¦ÕßÔ̺¬ÈÕ±¾µç²úÖêʽ»áÉçºÍ½áºÏ¹ú¿ª·¢´òËãÊ𡣡£¡£¡£¡£¡£Õâ´ÎÐж¯Åú×¢£¬ £¬£¬£¬£¬£¬£¬È«Çò·¨Âɲ¿ÃÅÔÚ¼ÓÇ¿ºÏ×÷½ø¹¥ÀÕË÷Èí¼þ·¸×ï¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/police-arrests-4-phobos-ransomware-suspects-seizes-8base-sites/


4. Lee Enterprises±¨Òµ¼¯ÍÅÔâÍøÂç¹¥»÷ÖÂÔËÓªÖжÏ


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÃÀ¹ú±¨Òµ¼¯ÍÅLee EnterprisesÔÚ2025Äê2ÔÂ3ÈÕÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÒµÎñÔËÓªÖжϡ£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø¹ØÁ˺ܶàÍøÂ磬 £¬£¬£¬£¬£¬£¬ÇÖÈÅÁËÊýÊ®ÖÖ±¨Ö½µÄÓ¡Ë¢ºÍ¿¯ÐУ¬ £¬£¬£¬£¬£¬£¬²¢ÇÒʹµÃ¼ÇÕߺͱà×ëÎÞ·¨½Ó¼ûËûÃǵÄÎļþ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»µÄÎļþÖÐÈ·ÈÏÁËÕâ´Î¹¥»÷£¬ £¬£¬£¬£¬£¬£¬²¢°µÊ¾ÔÚµ÷²éÄÄЩÐÅÏ¢¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¶à¼ÒLee Enterprises³ö°æÎïÔÚÍøÕ¾¶¥²¿ÏÔÊ¾ÊØ»¤ºá·ù£¬ £¬£¬£¬£¬£¬£¬Ïò¶ÁÕß·Ǹ²¢°µÊ¾ÔÚÖÂÁ¦½â¾öÎÊÌâ¡£¡£¡£¡£¡£¡£Lee EnterprisesÔÚ26¸öÖݳö°æ77·ÝÈÕ±¨ºÍ350·ÝÖÜ¿¯¼°×¨Òµ¿¯Î £¬£¬£¬£¬£¬£¬Õ¼Óг¬¹ý120ÍòµÄÈÕ¿¯ÐÐÁ¿ºÍ³¬¹ý4400ÍòµÄÊý×Ö°æ¶ÀÁ¢·Ã¿Í¡£¡£¡£¡£¡£¡£ÎåÄêǰ£¬ £¬£¬£¬£¬£¬£¬¸Ã¼¯ÍÅÒ²ÔøÔâ·êÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÆäʱÒÁÀʺڿÍÈëÇÖÁËÆäÍøÂç×÷Ϊ´«²¼ÐéαÐÅÏ¢»î¶¯µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cyberattack-disrupts-lee-newspapers-operations-across-the-us/


5. Facebook³ÉÍøÂç´¹µöÐÂÖ¸±ê£¬ £¬£¬£¬£¬£¬£¬Êý°Ù¼ÒÆóÒµÓʼþµØÖ·Ôâ½Ù³Ö


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬Check Point ResearchµÄ×îÐÂ×êÑÐÏÔʾ£¬ £¬£¬£¬£¬£¬£¬È«Çòµ±ÏȵÄÉ罻ýÌåÆ½Ì¨Facebook³ÉΪÁËÐÂÒ»ÂÖÍøÂç´¹µö»î¶¯µÄÖ¸±ê£¬ £¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ö¼ÔÚÇÔÈ¡Êý°Ù¼ÒÆóÒµµÄ12,000¶à¸öµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Ê¼ÓÚ2024Äê12ÔÂ20ÈÕ×óÓÒ£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÅ·ÃË¡¢ÃÀ¹úºÍ°Ä´óÀûÑǵĹ«Ë¾£¬ £¬£¬£¬£¬£¬£¬µ«Ò²Ó°Ïìµ½ÁËÈ«ÇòÆäËûµØÓò¡£¡£¡£¡£¡£¡£Ú¿Æ­ÕßÀûÓÃSalesforceµÄ×Ô¶¯Óʼþ·þÎñ·¢ËͺýŪÐÔµç×ÓÓʼþ£¬ £¬£¬£¬£¬£¬£¬ÓʼþÖдøÓмÙðµÄFacebook»Õ±ê£¬ £¬£¬£¬£¬£¬£¬²¢Ö¸¿ØÊÕ¼þÈ˼Ӻ¦°æÈ¨¡£¡£¡£¡£¡£¡£³ý·ÇÊÕ¼þÈËÔڶ̹¦·òÄÚÌá³öÒìÒ飬 £¬£¬£¬£¬£¬£¬²»È»½«Ãæ¶ÔÕË»§Ï޶ȵÄÍþв¡£¡£¡£¡£¡£¡£ÓʼþÖÐÔ̺¬ÐéαµÄFacebookÖ§³ÖÒ³ÃæÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬ÓÕÆ­Êܺ¦ÕßÊäÈëµÇ¼ʹ´¦£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÌáÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâÖÖºýŪÐÐΪÍþв×ÅÈ«ÇòÒÀÀµFacebookµÄÆóÒµ£¬ £¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÆäÖÎÀíÔ¹ØË»§±»½ÚÔì¡¢ÄÚÈݱ»¸ü¸Ä¡¢ÐÂÎű»°Ñ³Ö¡¢Ìû×Ó±»É¾³ýºÍ°²È«ÉèÖñ»Åú¸Ä£¬ £¬£¬£¬£¬£¬£¬½ø¶øÔì³É¿Í»§ÐÅÀµ¶È½µÂä¡¢¿Í»§Á÷ʧºÍDZÔÚµÄ˾·¨ËßËϵȺó¹û¡£¡£¡£¡£¡£¡£¶ÔÓÚÒ½ÁƱ£½¡ºÍ½ðÈÚµÈÊܼà¹ÜÐÐÒµµÄÆóÒ·´Ëµ£¬ £¬£¬£¬£¬£¬£¬»¹¿ÉÄܵ¼Ö²»ºÏ¹æ¡¢· £¿£¿ £¿£¿£¿£¿îºÍ˾·¨ÌôÕ½¡£¡£¡£¡£¡£¡£Òò¶ø£¬ £¬£¬£¬£¬£¬£¬×éÖ¯Ó¦Ö´ÐÐÃ÷È·µÄÊÂÎñÏìÓ¦´òË㣬 £¬£¬£¬£¬£¬£¬ÒÔ½µµÍÊܵ½¹¥»÷µÄ·çÏÕ¡£¡£¡£¡£¡£¡£


https://hackread.com/scammers-use-fake-facebook-copyright-notices-to-hijack-accounts/


6. ÁôÏëÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬12Íò»¼ÕßÐÅÏ¢Ôâй¶


2ÔÂ10ÈÕ£¬ £¬£¬£¬£¬£¬£¬×ôÖÎÑÇÖݰ಼ÀïÆæµÄÒ»¼ÒÓ×ÐÍ´åÂäÒ½ÔºÁôÏëÒ½ÔººÍׯ԰ÔÚ2024Äê11ÔÂÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÆäϵͳ̱»¾£¬ £¬£¬£¬£¬£¬£¬²»µÃ²»Ñ¡È¡Ö½ÖÊÁ÷³Ì¼Í¼»¼ÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£Ö»¹ÜÔËӪδÖжϣ¬ £¬£¬£¬£¬£¬£¬µ«ÆÚ´ý¹¦·òµ¢¸é¡£¡£¡£¡£¡£¡£¹¥»÷Õ߾ݳƴÓҽԺϵͳÖÐÇÔÈ¡ÁË1.15TBµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬²¢ÔÚTorйÃÜÍøÕ¾ÉϹ«¿ª£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬120,085È˵ÄÓ×ÎÒÐÅÏ¢ºÍ½¡È«ÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢²¡Ê·¡¢Ò½ÖÎÐÅÏ¢ºÍ½¡È«±£ÏÕÐÅÏ¢¡£¡£¡£¡£¡£¡£EmbargoÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£ÁôÏëÒ½ÔºÒÑÏòÊÜÓ°ÏìÓ×ÎÒ·¢ËÍÊéÃæÍ¨Öª£¬ £¬£¬£¬£¬£¬£¬²¢Ìṩ12¸öÔµÄÃâ·ÑÉí·Ý±£»£»£»£»£»£»£»£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰûÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÐÅÏ¢±»ÀÄÓ㬠£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚÊý¾Ý¿É¹«¿ªÏÂÔØ£¬ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÈËȺ¿ÉÄÜÃæ¶ÔÍøÂç´¹µöºÍÆäËûÀàÐ͹¥»÷µÄ·çÏÕ¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/information-of-120000-stolen-in-ransomware-attack-on-georgia-hospital/