BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ £¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀

°ä²¼¹¦·ò 2024-12-20

1. BadBox¶ñÒâÈí¼þ½©Ê¬ÍøÂç³ÖÐøÀ©ÕÅ £¬È«ÇòϰȾÉ豸³¬19.2Íǫ̀


12ÔÂ19ÈÕ £¬BadBox Android ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÀ©ÕÅ £¬Ï°È¾É豸ÊýÁ¿Òѳ¬¹ý192,000̨ £¬ÆäÖÐÔ̺¬³ÛÃûÆ·ÅÆµÄÖÇÄܵçÊÓºÍÖÇÄÜÊÖ»ú £¬ÈçYandexºÍº£ÐÅ¡£¸Ã¶ñÒâÈí¼þ×î³õͨ¹ý¹©¸øÁ´¹¥»÷ϰȾ²»³ÛÃûÔì×÷É̵ÄÉ豸 £¬ÏÖÒÑÀ©´óµ½ÔÚÏßÏúÊÛµÄÎÞÃû²úÆ·¼°ÆäËû³ÛÃûÆ·ÅÆ¡£ÆäÖ¸±êÖØÒªÊÇ»ñÈ¡¾­¼ÃÀûÒæ £¬Í¨¹ý½«É豸Ôì³Éסլ´úÀí»òÓÃÓÚ¸æ°×ڲƭʵÏÖ¡£Ö»¹ÜµÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©Ôø°ä·¢µ·»ÙBadBoxµÄÐж¯ £¬¶Â½ØÁË30,000̨É豸µÄͨѶ £¬µ«BadBoxÈÔÔÚ³ÖÐø·¢Õ¹¡£BitSight×êÑÐÈËÔ±·¢ÏÖ £¬¸Ã¶ñÒâÈí¼þÒÑ×°ÖÃÔÚ192,000̨É豸ÉÏ £¬ÇÒÊýÁ¿ÈÔÔÚÎȲ½Ôö³¤¡£ÊÜÓ°ÏìµÄÉè±¸ÖØÒªÎ»ÓÚ¶íÂÞ˹¡¢Öйú¡¢Ó¡¶È¡¢°×¶íÂÞ˹¡¢°ÍÎ÷ºÍÎÚ¿ËÀ¼¡£Ïû·ÑÕßÓ¦ÀûÓÃ×îеĹ̼þ°²È«¸üС¢½«ÖÇÄÜÉ豸Óë¹Ø¼üϵͳ¸ôÀë²¢ÔÚ²»Ê¹ÓÃʱ¶Ï¿ªÍøÂçÏνÓ £¬ÒÔ·À±¸BadBoxϰȾ¡£ÈôÉ豸ÎÞ¿ÉÓøüР£¬½¨Òé¶Ï¿ªÍøÂç»ò¹Ø¹ØÉ豸¡£Ï°È¾¼£ÏóÔ̺¬¹ýÈÈ¡¢»úÄܽµÂä¡¢´¦ÖÃÆ÷ʹÓÃÂʸߺÍÍøÂçÁ÷Á¿Òì³£¡£


https://www.bleepingcomputer.com/news/security/badbox-malware-botnet-infects-192-000-android-devices-despite-disruption/


2. ΢Èí365 OfficeÀûÓÃÏÖ¡°²úÆ·ÒÑÍ£Óá±ÃýÎó £¬Ô´ÓÚÐí¿ÉÖ¤µ÷»»ÎÊÌâ


12ÔÂ19ÈÕ £¬Î¢ÈíÔÚµ÷²éÒ»¸öµ¼ÖÂMicrosoft 365 OfficeÀûÓÃÓû§´¥·¢¡°²úÆ·ÒÑÍ£Óá±ÃýÎóµÄÎÊÌâ¡£¾ÝRedditºÍ΢ÈíÉçÇøÍøÕ¾ÉϵĻ㱨 £¬Óû§ÔÚOfficeÀûÓÃÖÐËæ»úÊÕµ½´ËÃýÎó £¬Ôì³É»ìÂÒºÍÖжÏ¡£ÎÊÌâÔ´ÓÚÖÎÀíÔ±ÌáÒéµÄÐí¿ÉÖ¤µ÷»» £¬ÈçÒÆ¶¯Óû§µ½·ÖÆçµÄÐí¿É×é»ò¸ü¸ÄÓû§¶©ÔÄ¡£µ±ÖÎÀíԱɾ³ý²¢³ÁÐÂÔö³¤Óû§µ½Ðí¿ÉÖ¤×é¡¢µ÷ÕûÐí¿ÉÖ¤»ò·þÎñ´òËãÉèÖà £¬»òÇл»¡°×îа汾µÄ×ÀÃæÀûÓ÷¨Ê½¡±·þÎñ´òËãʱ £¬Ò²»á´¥·¢´ËÎÊÌâ¡£Óû§Äܹ»Í¨¹ýµ¥»÷ÃýÎóºá·ùÉϵġ°³Áм¤»î¡±°´Å¥»òÍ˳ö²¢³ÁÐÂÆô¶¯Microsoft 365ÀûÓÃÀ´½â¾ö´ËÎÊÌâ¡£ÈôÊÇÎÊÌâÒÀÈ»´æÔÚ £¬½¨ÒéÁªÏµÖÎÀíÔ±²é³­¶©ÔÄÊÇ·ñÒѹýÆÚ¡£Î¢Èí½¨ÒéÓÐδ½â¾öÖ§³Ö°¸ÀýµÄÓû§ÌṩʹÓÃOfficeÐí¿ÉÕï¶Ï¹¤¾ßÍøÂçµÄÕï¶ÏÊý¾Ý £¬²¢ÌáÐÑÊÜÓ°ÏìµÄÓû§Ìṩ´æ´¢ÔÚ%temp%/diagnosticsĿ¼ÖеÄÈÕÖ¾¡£¹ÌȻ΢ÈíÉÐδ°ä²¼½¨¸´¹¦·ò±í £¬µ«Æä¹¤³ÌÍŶÓÔÚ»ý¼«µ÷²é´ËÎÊÌâ £¬²¢¼¤ÀøÊÜÓ°ÏìµÄÓû§ºÍÖÎÀíÔ±¹Ø×¢ÆäÖ§³ÖÇþ·ÒÔ»ñÈ¡¸üС£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-users-hit-by-random-product-deactivation-errors/


3. ÑÇÂíÑ·ÀûÓÃÉ̵꾪ÏÖBMI CalculationVsn¶ñÒâ¼äµýÈí¼þ


12ÔÂ19ÈÕ £¬ÔÚÑÇÂíÑ·ÀûÓÃÉ̵êÖÐ £¬Ò»¿îÃûΪ¡°BMI CalculationVsn¡±µÄAndroidÀûÓ÷¨Ê½±»·¢ÏÖÏÖʵÉÏÊÇÒ»¿î¶ñÒâ¼äµýÈí¼þ £¬Ëü¼Ù×°³É½¡È«¹¤¾ßÇÔÈ¡Óû§É豸Êý¾Ý¡£¸ÃÀûÓÃÓÉÂõ¿Ë·Æ³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ £¬²¢Òѱ»´ÓÉ̵êÖÐÒÆ³ý £¬µ«ÒÑ×°ÖõÄÓû§ÐèÊÖ¶¯É¾³ý²¢Ö´ÐÐÆëȫɨÃèÒԶϸù²ÐÁôºÛ¼£¡£¸Ã¼äµýÈí¼þÓÉ¡°PT Visionet Data Internasional¡±°ä²¼ £¬×î³õÐû´«ÎªÉí¶ÎÖÊÁ¿Ö¸Êý£¨BMI£©ÍÆËãÆ÷ £¬µ«ºó¶ÜÖ´ÐжñÒâ²Ù×÷ £¬Ô̺¬Æô¶¯ÆÁϼÔì·þÎñ¡¢É¨ÃèÒÑ×°ÖõÄÀûÓ÷¨Ê½ÒÔ¼°À¹½Ø²¢ÍøÂç¶ÌÐÅ £¬Ô̺¬Ò»´ÎÐÔÃÜÂëºÍÑéÖ¤Âë¡£¼øÓÚ´ËÀàΣÏÕÀûÓÃÈÔÄÜÌӱܺϷ¨ÀûÓÃÉ̵êµÄ´úÂëÉó²é £¬AndroidÓû§Ó¦Ö»×°ÖÃÀ´×Ô³ÛÃû¿¯ÐÐÉ̵ÄÀûÓà £¬²¢×Ðϸ²é³­ËùÒªÇóµÄȨÏÞ £¬ÔÚ×°Öúó³·ÏúÓзçÏÕµÄȨÏÞ¡£Í¬Ê± £¬Î¬³ÖGoogle Play Protect»îԾ״̬¶ÔÓÚ¼ì²â²¢×èÖ¹ÒÑÖª¶ñÒâÈí¼þÖÁ¹Ø³ÁÒª¡£


https://www.bleepingcomputer.com/news/security/android-spyware-found-on-amazon-appstore-disguised-as-health-app/


4. Mirai¶ñÒâÈí¼þÀûÓÃĬÈÏÆ¾Ö¤Ï°È¾Session Smart·ÓÉÆ÷


12ÔÂ19ÈÕ £¬Õ°²©ÍøÂçÏò¿Í»§·¢³öÖÒ¸æ £¬Ö¸³öMirai¶ñÒâÈí¼þÔÚÀûÓÃĬÈÏÆ¾Ö¤¹¥»÷²¢Ï°È¾Session Smart·ÓÉÆ÷ £¬½ø¶øÌáÒéÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¸Ã¶ñÒâÈí¼þ»áɨÃèÓµÓÐĬÈϵǼʹ´¦µÄÉ豸 £¬²¢ÔÚ»ñµÃ½Ó¼ûȨÏÞºóÔ¶³ÌÖ´ÐкÅÁî¡£Õ°²©ÍøÂ罨Òé¿Í»§Á¢¼´¸ü¸ÄËùÓÐSession Smart·ÓÉÆ÷ÉϵÄĬÈÏÍ´´¦ £¬²¢Ê¹ÓùÖÒìÇÒÇ¿µÄÃÜÂë £¬Í¬Ê±Î¬³Ö¹Ì¼þ¸üР£¬²é³­½Ó¼ûÈÕÖ¾ÖеÄÒì³£ £¬²¢²¿ÊðÈëÇÖ¼ì²âϵͳºÍ·À»ðǽÀ´¼ÓÇ¿°²È«ÐÔ¡£´Ë±í £¬Õ°²©ÍøÂ绹ÌáÐÑÖÎÀíÔ±°ÑÎÈDZÔÚµÄÈëÇÖÖ¸±ê £¬ÈçɨÃè³£¼û¶Ë¿Ú¡¢SSH·þÎñµÇ¼³¢ÊÔʧ°Ü¡¢³öÕ¾Á÷Á¿¼¤ÔöµÈ¡£ÒѾ­Ï°È¾µÄ·ÓÉÆ÷±ØÐë³ÁÐÂÓ³Ïñ»¯ÄÜÁ¦³ÁÐÂÉÏÏß¡£´Ëǰ £¬Õ°²©ÍøÂçÒ²ÔøÂÅ´ÎÖÒ¸æÆä²úÆ·ÖдæÔÚµÄÔ¶³Ì´úÂëÖ´Ðзì϶ºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬²¢°ä²¼ÁËÏàÓ¦µÄ²¹¶¡¡£


https://www.bleepingcomputer.com/news/security/juniper-warns-of-mirai-botnet-targeting-session-smart-routers/


5. BeyondTrustÔâÍøÂç¹¥»÷ £¬·¢ÏÖ°²È«·ì϶²¢´¹Î£Ó¦¶Ô


12ÔÂ19ÈÕ £¬BeyondTrustÊÇÒ»¼ÒÌá¹©ÌØÈ¨½Ó¼ûÖÎÀíºÍ°²È«Ô¶³Ì½Ó¼û½â¾ö¹æ»®µÄÍøÂ簲ȫ¹«Ë¾ £¬ÔÚ12Ô³õÔâ·êÁËÍøÂç¹¥»÷¡£ÍþвÐÐΪÕßÈëÇÖÁËÆä²¿ÃÅÔ¶³ÌÖ§³ÖSaaSÊ·ý £¬»ñµÃÁËÔ¶³ÌÖ§³ÖSaaS APIÃÜÔ¿µÄ½Ó¼ûȨÏÞ £¬Äܹ»³ÁÖñ¾µØÀûÓ÷¨Ê½ÕÊ»§µÄÃÜÂë¡£BeyondTrustÁ¢¼´³·ÏúÁËAPIÃÜÔ¿ £¬Í¨ÖªÁËÊÜÓ°ÏìµÄ¿Í»§ £¬²¢ÔÝÍ£ÁËÕâЩÊ·ý¡£ÔÚµ÷²é¹ý³ÌÖÐ £¬·¢ÏÖÁËÁ½¸ö·ì϶ £¬ÆäÖÐÒ»¸öΪÑϳÁµÄºÅÁî×¢Èë·ì϶CVE-2024-12356 £¬ÁíÒ»¸öΪÖеÈÑϳÁÐÔ·ì϶CVE-2024-12686¡£BeyondTrustÒÑ×Ô¶¯ÔÚËùÓÐÔÆÊ·ýÉÏÀûÓÃÁËÕë¶ÔÕâÁ½¸öȱµãµÄ²¹¶¡ £¬µ«ÔËÐÐ×ÔÍйÜÊ·ýµÄÓû§±ØÒªÊÖ¶¯ÀûÓð²È«¸üС£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇ·ñÀûÓÃÕâЩ·ì϶À´¹¥»÷ÏÂÓοͻ§ £¬µ«CISA°µÊ¾CVE-2024-12356Òѱ»ÀûÓÃÓÚ¹¥»÷¡£BeyondTrust°µÊ¾ £¬ËûÃÇÔÚ³ÖÐøÓë¶ÀÁ¢µÄµÚÈý·½ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½øÐг¹µ×µ÷²é £¬²¢×¨Ò»ÓÚÈ·±£ËùÓпͻ§Ê·ý¶¼µÃµ½È«Ãæ¸üкͰ²È«±£ÏÕ¡£


https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/


6. FortiWLMÆØÑϳÁ·ì϶£º¿ÉÔ¶³ÌÊÕÊÜÉ豸


12ÔÂ19ÈÕ £¬FortinetÎÞÏßÖÎÀíÆ÷£¨FortiWLM£©ÖдæÔÚÒ»¸ö±àºÅΪCVE-2023-34990µÄÑϳÁ·ì϶ £¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìWebÒªÇóÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë»òºÅÁî £¬´Ó¶øÊÕÊÜÉ豸¡£´Ë·ì϶ÊÇÒ»¸öÏà¶Ôõè¾¶±éÀú·ì϶ £¬ÆÀ·ÖΪ9.8 £¬ÓÉHorizon3×êÑÐÔ±Zach HanleyÔÚ2023Äê5Ô·¢ÏÖ¡£È»¶ø £¬ÔÚ³¤´ïÊ®¸öԵŦ·òÀï £¬¸Ã·ì϶δµÃµ½½¨¸´ £¬ÆÈʹHanleyÔÚ2024Äê3Ô¹«¿ªÅû¶ÁË·ì϶ÐÅÏ¢ºÍÖ¤Ã÷´úÂ루POC£©¡£ÀûÓô˷ì϶ £¬¹¥»÷ÕßÄܹ»¶ÁÈ¡Ãô¸ÐÈÕÖ¾Îļþ £¬Ô̺¬ÖÎÀíÔ±»á»°ID £¬½ø¶ø½Ù³ÖÖÎÀíÔ±»á»°²¢»ñÈ¡ÌØÈ¨½Ó¼û¡£¸Ã·ì϶ӰÏìÁËFortiWLM°æ±¾8.6.0ÖÁ8.6.5ºÍ8.5.0ÖÁ8.5.4¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑ·¢³öÖÒ¸æ £¬µ«ÓÉÓÚ²»×ãCVE IDºÍ°²È«²¼¸æ £¬Óû§²¢Î´Òâʶµ½·çÏÕ¡£Ö±µ½2024Äê12ÔÂ18ÈÕ £¬Fortinet²Å°ä²¼°²È«²¼¸æ³Æ £¬¸Ã·ì϶ÒÑÔÚ2023Äê9Ôµװ䲼µÄFortiWLM°æ±¾8.6.6ºÍ8.5.5Öеõ½½¨¸´¡£Ë¼¿¼µ½FortiWLM±»¿í·ºÀûÓÃÓÚµ±¾Ö»ú¹¹¡¢Ò½ÁƱ£½¡×éÖ¯¡¢½ÌÓý»ú¹¹ºÍ´óÐÍÆóÒµµÈ¹Ø¼ü»·¾³ÖÐ £¬¸Ã·ì϶µÄ´æÔÚ¿ÉÄܵ¼ÖÂÕû¸öÍøÂçÖжϺÍÃô¸ÐÊý¾Ýй¶¡£Òò¶ø £¬Ç¿ÁÒ½¨ÒéFortiWLMÖÎÀíԱʵʱÀûÓÃËùÓпÉÓøüС£


https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortiwlm-bug-giving-hackers-admin-privileges/