Python JSON Logger¿â·ìÏ¶ÆØ¹â£º4300Íò×°ÖÃÃæ¶ÔRCE·çÏÕ

°ä²¼¹¦·ò 2025-03-13

1. Python JSON Logger¿â·ìÏ¶ÆØ¹â£º4300Íò×°ÖÃÃæ¶ÔRCE·çÏÕ


3ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Python JSON Logger ¿âÖÐÅû¶ÁËÒ»¸öÑϳÁ·ì϶£¨GHSA-wmxh-pxcx-9w24£©£¬£¬£¬£¬£¬£¬£¬£¬CVSS v3 ÑϳÁÐԵȼ¶Îª8.8/10£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¼4300Íò¸ö×°ÖÃÃæ¶ÔÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚδע²áµÄÒÀÀµÏî¡°msgspec-python313-pre¡±£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÖ´ÐÐÊÜÓ°Ïì°æ±¾£¨3.2.0ºÍ3.2.1£©µÄÈÕ־ʵÓ÷¨Ê½µÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒÀÀµ»ìºÏ¹¥»÷µÄµäÐÍÀý×Ó£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÈí¼þ¹©¸øÁ´Öеķì϶¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜûÓÐÖ¤¾ÝÅú×¢ÔÚ·ì϶´°¿ÚÆÚ¼ä²úÉúÁ˶ñÒâÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«¸Ã¿âµÄ¿í·ºÑ¡È¡·Å´óÁËDZÔÚÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶½«Ê¹¹¥»÷Õß»ñµÃ¶ÔϵͳµÄÆëÈ«½ÚÔìȨ¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»º½â´ëÊ©Ô̺¬°ä²¼v3.3.0°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÆëÈ«½â³ýÁËmsgspec-python313-preÒÀÀµÐÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ó밲ȫ×êÑÐԱЭµ÷×ªÒÆÓÐÕùÒéµÄÈí¼þ°üÃû³ÆµÄËùÓÐȨ¡£¡£¡£¡£¡£¡£¡£¡£°²È«ÍŶӽ¨ÒéÁ¢¼´Éý¼¶µ½v3.3.0£¬£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨Á¢¼´¸üеÄ×éÖ¯Ó¦ÉóºËÆäPython»·¾³¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶͹ÏÔÁËPythonÉú̬ϵͳÔÚÆ½ºâ¿ÉÓÃÐԺͰ²È«ÐÔ·½ÃæÃæ¶ÔµÄ³ÖÐøÌôÕ½£¬£¬£¬£¬£¬£¬£¬£¬²¢´ÙÊ¹ÖØÒª¿ªÔ´ÉçÇø³ÁÐÂÉóÊÓÒÀÀµÖÎÀíʵ¼Ê¡£¡£¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/popular-python-library-vulnerability/


2. ³¬¹ý300¸ö¹Ø¼ü»ù´¡ÉèÊ©×éÖ¯Êܵ½MedusaÀÕË÷Èí¼þ¹¥»÷


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬CISA¡¢FBIºÍ¶àÖÝÐÅÏ¢¹²ÏíÓë·ÖÎöÖÐÐÄ(MS-ISAC)½áºÏ°ä²¼²¼¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁ2025Äê2Ô£¬£¬£¬£¬£¬£¬£¬£¬MedusaÀÕË÷Èí¼þÐж¯ÒÑÓ°ÏìÃÀ¹ú300¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©ÁìÓòµÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°Ò½ÁÆ¡¢½ÌÓý¡¢Ë¾·¨¡¢±£ÏÕ¡¢¼¼ÊõºÍÔì×÷ÒµµÈ¶à¸öÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£Îª·ÀÓùMedusaÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé×éÖ¯²ÉÈ¡»º½â´ëÊ©£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬½¨²¹°²È«·ì϶¡¢·Ö¶ÎÍøÂç¡¢¹ýÂËÍøÂçÁ÷Á¿µÈ¡£¡£¡£¡£¡£¡£¡£¡£MedusaÀÕË÷Èí¼þÍÅ»ï×Ô2021Äê1Ô³öÏÖ£¬£¬£¬£¬£¬£¬£¬£¬2023ÄêÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚÈ«ÇòÔì³É400¶àÃûÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýйÃÜÍøÕ¾ºÍºÚ°Â·ÕË÷ÃÅ»§ÍøÕ¾ÏòÊܺ¦ÕßʩѹҪÇóÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïѡȡÀÕË÷Èí¼þ¼´·þÎñ(RaaS)ÔËÓªºÍÁªÃËģʽ£¬£¬£¬£¬£¬£¬£¬£¬ÕÐļ³õʼ½Ó¼û¾­¼ÍÈËÒÔ»ñµÃ¶ÔDZÔÚÊܺ¦Õߵijõʼ½Ó¼ûȨ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¶à¸ö¶ñÒâÈí¼þ¼Ò×åºÍÍøÂç·¸×ï×´¶¯¶¼×Ô³ÆÊÇMedusa£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹ØÓÚMedusaÀÕË÷Èí¼þµÄ±¨Â·³öÏÖ»ìºÏ¡£¡£¡£¡£¡£¡£¡£¡£ÉϸöÔ£¬£¬£¬£¬£¬£¬£¬£¬CISAºÍFBI»¹°ä²¼Á˹ØÓÚGhostÀÕË÷Èí¼þ¹¥»÷µÄ½áºÏ¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬³Æ¶à¸öÐÐÒµÁìÓòµÄÊܺ¦Õß¶¼Êܵ½Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-300-critical-infrastructure-orgs/


3. ³¯ÏÊAPT37×éÖ¯ÍÆ³öÐÂÐÍAndroid¼äµýÈí¼þKoSpy


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪ¡°KoSpy¡±µÄÐÂÐÍAndroid¼äµýÈí¼þÓ볯ÏÊÍþв×éÖ¯APT37£¨±ðÃû¡°ScarCruft¡±£©Óйأ¬£¬£¬£¬£¬£¬£¬£¬¸Ã×é֯ͨ¹ýÖÁÉÙÎå¸ö¶ñÒâÀûÓ÷¨Ê½ÉøÈëµ½Google PlayºÍµÚÈý·½ÀûÓÃÉ̵êAPKPure¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÀûÓ÷¨Ê½¼Ù×°³ÉÎļþÖÎÀíÆ÷¡¢°²È«¹¤¾ßºÍÈí¼þ¸üз¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ôº«ÓïºÍÓ¢ÓïÓû§¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©¼¤»î£¬£¬£¬£¬£¬£¬£¬£¬KoSpy»á´ÓFirebase FirestoreÊý¾Ý¿âÖмìË÷¼ÓÃÜÅäÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ïνӵ½ºÅÁîºÍ½ÚÔì·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔËÐи÷ÀàÊý¾ÝÍøÂçÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÀ¹½Ø¶ÌÐźÍͨ»°¼Í¼¡¢ÊµÊ±×·×ÙGPSµØÎ»¡¢ÇÔÈ¡Îļþ¡¢Â¼ÔìÒôƵºÍÊÓÆµµÈ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÀûÓ÷¨Ê½ÒÑ´ÓGoogle PlayºÍAPKPureÖÐÒÆ³ý£¬£¬£¬£¬£¬£¬£¬£¬µ«Óû§ÈÔÐèÊÖ¶¯Ð¶Ôز¢Ê¹Óð²È«¹¤¾ßɨÃèÉ豸¡£¡£¡£¡£¡£¡£¡£¡£Google Play Protect¿ÉÄÜ×èÖ¹ÒÑÖªµÄ¶ñÒâÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Ô®ÊÖ·À±¸KoSpy¡£¡£¡£¡£¡£¡£¡£¡£¹È¸èÒÑÈ·ÈÏËùÓÐKoSpyÀûÓÃÒÑ´ÓGoogle PlayÖÐɾ³ý£¬£¬£¬£¬£¬£¬£¬£¬ÏàÓ¦µÄFirebaseÏîĿҲÒѱ»³·Ï¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÇøÓò˵»°Åú×¢ÕâÊÇÓÐÕë¶ÔÐԵĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Google Play Protect»á×Ô¶¯±£»£»£»£»£»£»¤AndroidÓû§ÃâÊÜÒÑÖª°æ±¾µÄ¶ñÒâÈí¼þÇÖº¦¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-north-korean-android-spyware-slips-onto-google-play/


4. MozillaÖҸ棺FirefoxÓû§Ðè¸üÐÂä¯ÀÀÆ÷ÒÔÔ¤·À°²È«·çÏÕ


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Mozilla½üÆÚÖÒ¸æFirefoxÓû§£¬£¬£¬£¬£¬£¬£¬£¬Îñ±Ø½«Æää¯ÀÀÆ÷¸üе½×îа汾£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÒò¹«Ë¾µÄÒ»¸ö¸ùÖ¤Êé¼´½«µ½ÆÚ¶ø¿ÉÄܵ¼ÖµÄÖжϺͰ²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¸ùÖ¤ÊéÓÃÓÚÇ©ÊðÔ̺¬Firefox×ÔÉí¼°MozillaÏîÄ¿¸½¼Ó×é¼þÔÚÄÚµÄÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬£¬½«ÓÚ2025Äê3ÔÂ14ÈÕµ½ÆÚ¡£¡£¡£¡£¡£¡£¡£¡£ÎªÈ·±£Õý³£Ê¹Óø½¼Ó×é¼þ²¢Ô¤·À°²È«·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬Óû§Ð轫ä¯ÀÀÆ÷¸üÐÂÖÁFirefox 128£¨2024Äê7Ô°䲼£©»ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¡°À©´óÖ§³Ö°æ±¾¡±£¨ESR£©Óû§µÄESR 115.13»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·çÏÕÔ̺¬¶ñÒâ²å¼þ¿ÉÄÜÈÆ¹ý°²È«±£»£»£»£»£»£»¤Ð¹Â¶Óû§Êý¾Ý¡¢²»ÊÜÐÅÀµµÄÖ¤Êé¿ÉÄÜÔÊÐíÓû§½Ó¼ûڲƭ»ò²»°²È«µÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÃÜÂëй¶¾¯±¨¿ÉÄÜÖÕ³¡¹¤×÷µÈ¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýä¯ÀÀÆ÷²Ëµ¥²é³­²¢È·Èϰ汾£¬£¬£¬£¬£¬£¬£¬£¬´Ë²Ù×÷Ò²»á×Ô¶¯´¥·¢¸üв鳭¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÓ°ÏìËùÓÐÆ½Ì¨ÉϵÄFirefox£¬£¬£¬£¬£¬£¬£¬£¬µ«iOSÖ®±í¡£¡£¡£¡£¡£¡£¡£¡£Mozilla½¨ÒéÓû§¸üе½×îа汾ÒÔÈ·±£ä¯ÀÀÆ÷°²È«¸ßЧ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÎªÓöµ½ÎÊÌâµÄÓû§ÉèÖÃÁËÖ§³ÖÏ̡߳£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬»ùÓÚFirefoxµÄä¯ÀÀÆ÷ÈçTor¡¢LibreWolfºÍWaterfoxµÄÓû§Ò²Ó¦È·±£ÔËÐеÄÊÇ»ùÓÚFirefox 128¼°¸ü¸ß°æ±¾µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/software/mozilla-warns-users-to-update-firefox-before-certificate-expires/


5. ÈÕ±¾Ôâ¡°MirrorFace¡±APT¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃWindows SandboxÌӱܼì²â


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÈÕ±¾¹ú¶È¾¯Ô±ÌüºÍ¹ú¶ÈÍøÂ簲ȫÊÂÎñ³ï±¸ºÍÕ½ÊõÖÐÐİ䲼ÁËÒ»·Ý°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÈÕ±¾×éÖ¯Ãæ¶ÔÀ´×Ô¡°MirrorFace¡¹ØâÒ»APT10×Ó×éÖ¯µÄ¸ß¼¶³ÖÐøÐÔÍþв¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÀûÓÃWindows SandboxºÍVisual Studio CodeÖ´ÐжñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁËÃûΪ¡°LilimRAT¡±µÄ¶¨Ôì¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬×¨ÃÅÉè¼ÆÔÚWindows SandboxÖÐÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔÌÓ±ÜÖ÷»úϵͳÉϰ²È«¹¤¾ßµÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÆôÓÃWindows Sandbox¡¢´´½¨×Ô½ç˵ÅäÖÃÎļþºÍÔÚ¸ôÀë»·¾³ÖÐÖ´ÐжñÒâÈí¼þµÈ¸´ÔӵĶà½×¶Î¹¥»÷Á÷³Ì£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÊÜϰȾϵͳÉÏά³ÖÓÆ¾ÃÐÔ²¢×î´óÏ޶ȵØÏ÷¼õ»î¶¯ºÛ¼£¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚWindows SandboxĬÈϽûÓÃÇÒWindows DefenderÔÚÆäÖÐҲĬÈϽûÓ㬣¬£¬£¬£¬£¬£¬£¬Îª¹¥»÷ÕßÌṩÁËÒ»¸ö²»°²È«µÄ²Ù×÷»·¾³¡£¡£¡£¡£¡£¡£¡£¡£°²È«×¨¼Ò½¨Òéά³ÖWindows Sandbox½ûÓÃ״̬£¬£¬£¬£¬£¬£¬£¬£¬¼à¿ØÓйعý³Ì£¬£¬£¬£¬£¬£¬£¬£¬ÏÞ¶ÈÖÎÀíȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐAppLockerÕ½Êõ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·Àδ¾­ÊÚȨִÐÐWindows Sandbox¡£¡£¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/mirrorface-apt-hackers-exploited-windows-sandbox-visual-studio-code/


6. FacebookÖҸ棺FreeType×ÖÌå¿â¸ßΣ·ì϶Ð费ΣÉý¼¶


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Facebook½üÈÕ·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬£¬Ö¸³öÔÚFreeType 2.13¼°ÒÔÉϰ汾ÖдæÔÚÒ»¸ö¸ßΣ·ì϶£¨CVE-2025-27363£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬ÇÒÒÑÓл㱨³Æ¸Ã·ì϶ÔÚ±»»ý¼«ÀûÓýøÐй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£FreeTypeÊÇÒ»¸ö¿í·ºÊ¹ÓõĿªÔ´×ÖÌåäÖȾ¿â£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃÔÚÔ̺¬Linux¡¢AndroidµÈ¶à¸öϵͳºÍ·þÎñÖÓ×£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚ³¢ÊÔ½âÎöTrueType GXºÍ¿É±ä×ÖÌåÎļþÓйصÄ×ÖÌå×Ó×ÖÐνṹʱ²úÉúÔ½½çдÈ룬£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚFreeType 2.13.0¼°ÒÔϰ汾ÖУ¬£¬£¬£¬£¬£¬£¬£¬µ«ÒÑÔÚ2.13.0°æ±¾µÄ¸üÐÂÖеÃÒÔ½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü×îеÄÒ×Êܹ¥»÷°æ±¾ÒÑÓÐÁ½Ä꺹Ç࣬£¬£¬£¬£¬£¬£¬£¬µ«¾ÉµÄ¿â°æ±¾ÔÚÈí¼þÏîÄ¿ÖпÉÄܳ־ôæÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÈí¼þ¿ª·¢ÈËÔ±ºÍÏîÄ¿ÖÎÀíÔ±Ð辡¿ìÉý¼¶µ½×îа汾FreeType 2.13.3£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀDZÔڵݲȫ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Facebook°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇ·¢ÏÖ´Ë·ì϶ºó½øÐÐÁ˻㱨£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼ÓǿÿÓ×ÎÒµÄÔÚÏß°²È«£¬£¬£¬£¬£¬£¬£¬£¬²¢ÖÂÁ¦ÓÚ±£»£»£»£»£»£»¤Óû§µÄ¸öÈËͨѶ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ £Ë¼¿¼µ½FreeTypeµÄ¿í·ºÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¾¡¿ì½â¾ö¸Ã·ì϶¶ÔÓÚ±£ÏÕÍøÂ簲ȫÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/facebook-discloses-freetype-2-flaw-exploited-in-attacks/