Ñо¿ÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-11-24
1¡¢Ñо¿ÈËÔ±·¢ÏÖ¿ÉÈÆ¹ýWindows HelloµÇ¼µÄÄþ¾²Â©¶´


¾ÝýÌå11ÔÂ22ÈÕ±¨µÀ £¬Ñо¿ÈËÔ±·¢ÏÖÁ˶à¸ö©¶´ £¬¿ÉÓÃÀ´ÈƹýDell Inspiron 15¡¢Lenovo ThinkPad T14ºÍMicrosoft Surface Pro XÌõ¼Ç±¾µçÄÔÉϵÄWindows HelloÉí·ÝÑéÖ¤¡£ËùÓвâÊÔµÄÖ¸ÎÆ´«¸ÐÆ÷¶¼ÊÇMatch-on-Chip (MoC)´«¸ÐÆ÷ £¬ËäÈ»MoC´«¸ÐÆ÷¿ÉÒÔ×èÖ¹½«´æ´¢µÄÖ¸ÎÆÊý¾ÝÖØ·Åµ½Ö÷»ú½øÐÐÆ¥Åä £¬µ«ËüÃÇ×Ô¼º²¢²»ÄÜ×èÖ¹¶ñÒâ´«¸ÐÆ÷Ä£·ÂºÏ·¨´«¸ÐÆ÷ÓëÖ÷»ú½øÐÐͨÐÅ¡£Õâ¿ÉÄÜ»á´íÎóµØÏÔʾÓû§Éí·ÝÑéÖ¤ÀÖ³É £¬»òÖØ·Å֮ǰµÄÖ÷»úºÍ´«¸ÐÆ÷Ö®¼äµÄÁ÷Á¿¡£Îª´Ë £¬Î¢Èí¿ª·¢ÁËÄþ¾²É豸Á¬½ÓЭÒ飨SDCP£© £¬µ«Ñо¿ÈËÔ±»¹ÊÇÀûÓÃMiTM¹¥»÷ÀÖ³ÉÈÆ¹ýÁËWindows HelloÉí·ÝÑéÖ¤¡£


https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html


2¡¢º«¹úIT¹«Ë¾TmaxSoftÅäÖôíÎóÁè¼Ý5000ÍòÌõ¼Ç¼й¶


¾Ý11ÔÂ22ÈÕ±¨µÀ £¬º«¹úIT¹«Ë¾TmaxSoftÔ¼2TBµÄÊý¾ÝÒѹûÈ»Áè¼ÝÁ½Äê¡£Ñо¿ÈËÔ±ÔçÔÚ½ñÄê1Ô¾ͷ¢ÏÖÁËÒ»¸ö̻¶µÄKibana¿ØÖÆÃæ°å £¬²¢Ö¸³öÕâ×éÊý¾ÝÓÚ2021Äê6ÔÂÊ״α»·¢ÏÖ¡£Êý¾Ý¿â×ܹ²ÓÐÁè¼Ý5600ÍòÌõ¼Ç¼ £¬°üÂÞÔ±¹¤ÐÕÃûºÍµç»°¡¢¹ÍÓ¶ºÏͬºÅ¡¢·¢Ë͵ĸ½¼þºÍ¶þ½øÖÆÎļþµÄÔªÊý¾ÝµÈ¡£²»ÐÒµÄÊÇ £¬¸Ã¹«Ë¾ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´ £¬¶øÇÒ°üÂÞ´óÁ¿Êý¾ÝµÄ¿ØÖÆÃæ°åÈÔÈ»´¦ÓÚ¹ûȻ״̬¡£


https://securityaffairs.com/154567/data-breach/tmaxsoft-leaks-2tb-of-data.html


3¡¢Î¢ÈíÅû¶Diamond SleetÀûÓÃCyberLinkµÄ¹©Ó¦Á´¹¥»÷


΢ÈíÔÚ11ÔÂ22ÈÕÅû¶Á˳¯ÏʺڿÍÍÅ»ïDiamond Sleet(ZINC)ÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£Ñо¿ÈËÔ±ÔÚ10ÔÂ20ÈÕÊӲ쵽Á˴˴οÉÒɻ £¬Ëü¶ÔÖйų́Íå¶àýÌåÈí¼þ¹«Ë¾CyberLink¿ª·¢µÄÓ¦Ó÷¨Ê½½øÐÐľÂí»¯¡£¶ñÒâÎļþʹÓÃCyberLink·¢±íµÄÓÐЧ֤Êé½øÐÐÇ©Ãû £¬ÍйÜÔڸù«Ë¾ÓµÓеĺϷ¨µÄ¸üлù´¡ÉèÊ©ÉÏ¡£Æù½ñΪֹ £¬¸Ã¶ñÒâ»î¶¯ÒÑÓ°Ïì¶à¸ö¹ú¼Ò/µØÓòµÄ100¶ą̀É豸 £¬°üÂÞÈÕ±¾¡¢Öйų́Íå¡¢¼ÓÄôóºÍÃÀ¹ú¡£


https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/


4¡¢Blender͸¶Á¬ÐøµÄDDoS¹¥»÷µ¼ÖÂÆä·þÎñÆ÷å´»úÊýÈÕ


ýÌå11ÔÂ22ÈÕ³Æ £¬Blender͸¶×î½üµÄÍøÕ¾·þÎñÖжÏÊÇÁ¬ÐøµÄDDoS¹¥»÷µ¼ÖµÄ¡£¸ÃÏîÄ¿ÍŶÓÌåÏÖ £¬×Ô11ÔÂ18ÈÕÒÔÀ´ £¬blender.org·þÎñÆ÷¾ÍÔâµ½DDoS¹¥»÷ £¬Æä·þÎñÆ÷ÒòÇëÇó¹ýÔØ¶øå´»ú¡£¼´Ê¹ÔÚ¹¥»÷ÕßÔÝÍ£¹¥»÷µÄʱºò £¬BlenderµÄ»ù´¡ÉèÊ©ÈÔÈ»Òò´óÁ¿´ý´¦ÖõĺϷ¨ÇëÇó¶ø¹ýÔØ¡£×îÖÕ £¬ÔÚ¾­ÀúÁË4ÌìµÄÁ¬ÐøÖÐ¶Ïºó £¬¸ÃÍŶӽ«ÆäÖ÷ÍøÕ¾×ªÒÆµ½ÁËCloudFlareÉÏ £¬Õâ¼õÉÙ¹¥»÷µÄÓ°Ïì¡£Blender·ÖÏíµÄͳ¼ÆÊý¾ÝÏÔʾ £¬¹¥»÷ÈÔÔÚÁ¬Ðø £¬Õë¶Ô¸ÃÏîÄ¿·þÎñÆ÷µÄÐé¼ÙÇëÇóÁè¼Ý2.4ÒڴΡ£


https://www.bleepingcomputer.com/news/security/open-source-blender-project-battling-ddos-attacks-since-saturday/


5¡¢AkamaiÐû²¼Ð½©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö³ÂËß


11ÔÂ21ÈÕ £¬AkamaiÐû²¼»ùÓÚMiraiµÄн©Ê¬ÍøÂçInfectedSlursµÄ·ÖÎö³ÂËß¡£InfectedSlursÒ»Ö±ÔÚÀûÓÃÁ½¸öRCE©¶´À´Ñ¬È¾Â·ÓÉÆ÷ºÍ¼Ïñ»ú(NVR)É豸 £¬Ñо¿ÈËÔ±ÓÚ½ñÄê10Ô·¢ÏÖÁ˸ý©Ê¬ÍøÂç £¬²¢ÈÏΪËüÖÁÉÙ´Ó2022ÄêÆð¾ÍÒ»Ö±»îÔ¾¡£ËüÊÇJenX MiraiµÄ±äÌå £¬ÓÉÓÚÔÚC2ÓòºÍÓ²±àÂë×Ö·û´®ÖÐʹÓù¥»÷ÐÔÓïÑÔ¶øµÃÃû¡£ÆäC2»ù´¡ÉèÊ©Ïà¶Ô¼¯ÖÐ £¬ËƺõÒ²Ö§³ÖhailBotµÄÔËÐС£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°Ï칩ӦÉ̵ÄÃû³Æ £¬µ«¹©Ó¦ÉÌÔÊÐí½«ÓÚ12ÔÂÐû²¼Äþ¾²¸üС£


https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days


6¡¢KasperskyÐû²¼2024ÄêÏû·ÑÕßÍøÂçÍþвµÄÔ¤²â³ÂËß


11ÔÂ23ÈÕ £¬KasperskyÐû²¼Á˹ØÓÚ2024ÄêÏû·ÑÕßÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß¡£Ñо¿ÈËÔ±¶Ô2024Äê×ö³öÁËÕ¹Íû £¬°üÂÞ¸ü¶à´ÈÉÆÏà¹ØµÄÕ©Æ­¼´½«À´ÁÙ¡¢ÍøÉÏÉ̵꽫Óë´ÈÉÆ»ú¹¹µÄºÏ×÷¡¢»¥ÁªÍø»®·Ö¸üϸ¡¢VPN·þÎñ³ÊÉÏÉýÇ÷ÊÆ¡¢Äþ¾²ÐÔ¸ßÓÚÓû§ÊæÊʶȽ«´ßÉúеÄÄþ¾²ÎÊÌâ¡¢ÍøÂç¹¥»÷Õß½«Õë¶ÔP2E¡¢¿ª·¢Í¨ÓõÄDeepfake¼ì²é¹¤¾ß¡¢ÓïÒôDeepfakeʼþÔö¶àÒÔ¼°ÒÔÓ°Ï·Ê×ӳΪÓÕ¶üµÄÆ­¾ÖÔö¶àµÈ¡£


https://securelist.com/kaspersky-security-bulletin-consumer-threats-2024/111135/