Windows Bug½«´òÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106
Ðû²¼Ê±¼ä 2023-12-071¡¢Windows Bug½«´òÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106
¾ÝýÌå12ÔÂ5ÈÕ±¨µÀ£¬Windows·ºÆðBug½«ËùÓдòÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106£¬²¢×Ô¶¯×°ÖÃHP SmartÓ¦Óá£×ÔÉÏÖÜÒÔÀ´£¬Óû§Ò»Ö±ÔÚ±¨¸æ´ËÎÊÌâ¡£×îÔÂ˷ЩÓû§ÒÔΪËûÃǵÄϵͳÔâµ½Á˹¥»÷£¬µ«MicrosoftÏÖÒÑÈ·ÈÏÕâÊÇÒ»¸öÓ°Ïì¿Í»§¶Ë£¨Windows 10 1809¼°¸ü¸ß°æ±¾£©ºÍ·þÎñÆ÷£¨Windows Server 2012¼°¸ü¸ß°æ±¾£©µÄÎÊÌâ¡£ËùÓдòÓ¡»ú£¬ÎÞÂÛÆäÔÊ¼ÖÆÔìÉÌÔõÑù£¬¶¼½«±»ÖØÐ±ê¼ÇΪHP´òÓ¡»ú£¬´òÓ¡»úͼ±êÒ²¿ÉÄÜ»á¸ü¸Ä¡£µ±Óû§ÊµÑé·¿ª´òÓ¡»úʱ£¬»¹¿ÉÄÜ¿´µ½¹ýʧÐÂÎÅ¡°´ËÒ³ÃæÃ»ÓпÉÓõÄʹÃü¡±¡£Ô¤¼Æ´òÓ¡Àú³Ì²»»áÊܵ½Ó°Ï죬ÎÊÌâÈÔÔÚÊÓ²ìÖС£
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-bug-renames-printers-to-hp-laserjet-m101-m106/
2¡¢ForescoutÅû¶ӰÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸öÎó²î
ForescoutÔÚ12ÔÂ5ÈÕÅû¶ÁËÓ°ÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸öÎó²î£¬Í³³ÆÎª¡°Sierra:21¡±¡£ÕâЩÎó²î±£´æÓÚSierra AirLink·äÎÑ·ÓÉÆ÷£¬ÒÔ¼°TinyXMLºÍOpenNDS×é¼þÖС£Ñо¿Ö°Ô±³Æ£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆäÖÐһЩÎó²îÍêÈ«¿ØÖÆÒªº¦»ù´¡ÉèÊ©ÖеÄOT/IoT·ÓÉÆ÷£¬´Ó¶øµ¼ÖÂÍøÂçÖÐÖ¹¡¢Ìع¤Ô˶¯»òºáÏò×ªÒÆºÍ¶ñÒâÈí¼þ×°Öá£ShodanɨÃè·¢Ã÷ÁËÒªº¦»ù´¡ÉèÊ©ÖÐÁè¼Ý86000¸öÒ×±»¹¥»÷µÄAirLink·ÓÉÆ÷£¬ÆäÖдó´ó¶¼Î»ÓÚÃÀ¹ú£¨Ô¼80%£©£¬Æä´ÎÊǼÓÄô󡢰ĴóÀûÑÇ¡¢·¨¹úºÍÌ©¹ú¡£
https://www.forescout.com/blog/sierra21-supply-chain-vulnerabilities-iot-ot-routers/
3¡¢Çå¾²»ú¹¹³ÆColdFusionÎó²î±»Ê¹Óù¥»÷ÃÀ¹úµÄÕþ¸®»ú¹¹
ÃÀ¹úCISAÓÚ12ÔÂ5Èճƣ¬¹¥»÷ÕßʹÓÃAdobe ColdFusionÎó²î£¨CVE-2023-26360£©À´»ñÈ¡¶ÔÕþ¸®»ú¹¹·þÎñÆ÷µÄ³õʼ»á¼ûȨÏÞ¡£ÕâÊÇÒ»¸ö²»×¼È·µÄ»á¼û¿ØÖÆÎó²î£¬ÒÑÓÚ½ñÄê3Ô·ݱ»ÐÞ¸´¡£CISA¹ûÕæÁËʹÓøÃÎó²îµÄÁ½´Î¹¥»÷Ô˶¯£¬µÚÒ»ÆðÊÂÎñ±¬·¢ÔÚ6ÔÂ26ÈÕ£¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2016.0.0.3µÄ·þÎñÆ÷£»µÚ¶þÆðÊÂÎñ±¬·¢ÔÚ6ÔÂ2ÈÕ£¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2021.0.0.2µÄ·þÎñÆ÷¡£Ñо¿Ö°Ô±ÒÔΪÕâÊÇÕì̽Ô˶¯µÄÒ»²¿·Ö£¬Éв»ÇåÎúÁ½´ÎÈëÇÖÊÇ·ñÊÇͳһ¹¥»÷ÕßËùΪ¡£
https://securityaffairs.com/155289/security/us-govt-adobe-coldfusion-flaw.html
4¡¢IT·þÎñºÍ×Éѯ¹«Ë¾HTCÔâµ½ALPHV¹¥»÷²¿·ÖÊý¾Ýй¶
¾Ý12ÔÂ5ÈÕ±¨µÀ£¬IT·þÎñºÍÉÌÒµ×Éѯ¹«Ë¾HTC Global ServicesÔâµ½ÁËALPHVµÄ¹¥»÷¡£ALPHVÒѽ«HTCÁÐÔÚÆäÍøÕ¾ÉÏ£¬²¢¸½ÉÏÁ˱»µÁÊý¾ÝµÄ½ØÍ¼£¬°üÀ¨»¤ÕÕ¡¢ÁªÏµÈËÃûµ¥¡¢µç×ÓÓʼþºÍÉñÃØÎļþµÈ¡£ËäÈ»ÓйØHTC¹¥»÷µÄÐÅÏ¢ºÜÉÙ£¬µ«Ñо¿Ö°Ô±ÒÔΪ¹¥»÷Ô´ÓÚCitrix BleedÎó²î¡£¾ÝϤ£¬HTCµÄÓªÒµ²¿·ÖÖ®Ò»CareTechÔËÓª×ű£´æÎó²îµÄCitrix Netscaler×°±¸£¬±»ÓÃÀ´¶Ô¹«Ë¾ÍøÂç¾ÙÐгõʼ»á¼û¡£
https://www.bleepingcomputer.com/news/security/htc-global-services-confirms-cyberattack-after-data-leaked-online/
5¡¢Google PlayÉÏÊ®Êý¸ö¶ñÒâ´û¿îÓ¦ÓÃÏÂÔØÁè¼Ý1200Íò´Î
12ÔÂ5ÈÕ£¬ESETÐû²¼±¨¸æ£¬ÐÎòÁËAndroid¶ñÒâ´û¿îÓ¦ÓõÄÔöÌí¼°ÆäÓÃÀ´ÈƹýGoogle PlayµÄÊÖÒÕ¡£×Ô½ñÄêÄêÍ·ÒÔÀ´£¬ESETÒÑ·¢Ã÷18¸ö¶ñÒâ´û¿îÓ¦ÓóÌÐò£¨Í³³ÆÎªSpyLoan£©£¬ÔÚGoogle PlayµÄÏÂÔØÁ¿Áè¼Ý1200Íò´Î¡£µ«ÓÉÓÚËüÃÇ»¹¿É´ÓµÚÈý·½ÊÐËÁºÍ¿ÉÒÉÍøÕ¾ÉÏÏÂÔØ£¬Òò´ËÏÖʵÏÂÔØÁ¿Òª¶àµÃ¶à¡£SpyLoan»á´Ó×°±¸ÖÐÇÔȡСÎÒ˽¼ÒÐÅÏ¢£¬Ã°³äÕýµ±µÄ´û¿î½ðÈÚ·þÎñ£¬ÓÕÆÓû§½ÓÊܸßÏ¢¸¶¿î£¬È»ºóɧÈŲ¢ÀÕË÷Ä¿µÄ¸¶¿î¡£
https://www.welivesecurity.com/en/eset-research/beware-predatory-fintech-loan-sharks-use-android-apps-reach-new-depths/
6¡¢KasperskyÐû²¼¹ØÓÚÕë¶ÔmacOSµÄÐÂľÂíµÄÆÊÎö±¨¸æ
12ÔÂ5ÈÕ£¬Kaspersky³ÆÆä·¢Ã÷ÁËÕë¶ÔmacOSµÄÐÂÐͶñÒâ¼ÓÔØ³ÌÐò£¬¿ÉÄÜÓëÃûΪRustBucketµÄÔ˶¯Óйء£ÔçÆÚµÄRustBucket°æ±¾Î±×°³ÉPDFÔĶÁÆ÷£¬¶øÕâÖÖбäÌåÊÇÔÚÒ»¸öZIPÎĵµÖз¢Ã÷µÄ£¬ÔªÊý¾ÝÏÔʾӦÓý¨ÉèÓÚ½ñÄê10ÔÂ21ÈÕ¡£¶ñÒâÓ¦Óñ»·¢Ã÷ʱ¾ßÓÐÓÐÓÃÊðÃû£¬µ«Ö¤ÊéÒѱ»×÷·Ï¡£¿ÉÖ´ÐÐÎļþÓÃSwift¿ª·¢£¬ÃûΪ"EdoneViewer"£¬°üÀ¨IntelºÍApple SiliconоƬµÄ°æ±¾¡£²»ÐÒµÄÊÇ£¬Ñо¿Ö°Ô±Ã»ÓÐÊÕµ½À´×Ô·þÎñÆ÷µÄÈκÎÏÂÁÒò´ËÎÞ·¨ÍƶϺóÐø¹¥»÷µÄÄÚÈÝ¡£
https://securelist.com/bluenoroff-new-macos-malware/111290/


¾©¹«Íø°²±¸11010802024551ºÅ