Windows Bug½«´òÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106

Ðû²¼Ê±¼ä 2023-12-07

1¡¢Windows Bug½«´òÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106


¾ÝýÌå12ÔÂ5ÈÕ±¨µÀ £¬Windows·ºÆðBug½«ËùÓдòÓ¡»úÖØÃüÃûΪHP LaserJet M101-M106 £¬²¢×Ô¶¯°²×°HP SmartÓ¦Óá£×ÔÉÏÖÜÒÔÀ´ £¬Óû§Ò»Ö±ÔÚ³ÂËß´ËÎÊÌâ¡£×îÔÂ˷ЩÓû§ÈÏΪËûÃǵÄϵͳÔâµ½Á˹¥»÷ £¬µ«MicrosoftÏÖÒÑÈ·ÈÏÕâÊÇÒ»¸öÓ°Ïì¿Í»§¶Ë£¨Windows 10 1809¼°¸ü¸ß°æ±¾£©ºÍ·þÎñÆ÷£¨Windows Server 2012¼°¸ü¸ß°æ±¾£©µÄÎÊÌâ¡£ËùÓдòÓ¡»ú £¬ÎÞÂÛÆäÔ­Ê¼ÖÆÔìÉÌÈçºÎ £¬¶¼½«±»ÖØÐ±ê־ΪHP´òÓ¡»ú £¬´òÓ¡»úͼ±êÒ²¿ÉÄÜ»á¸ü¸Ä¡£µ±Óû§ÊµÑé´ò¿ª´òÓ¡»úʱ £¬»¹¿ÉÄÜ¿´µ½´íÎóÏûÏ¢¡°´ËÒ³ÃæÃ»ÓпÉÓõÄÈÎÎñ¡±¡£Ô¤¼Æ´òÓ¡¹ý³Ì²»»áÊܵ½Ó°Ïì £¬ÎÊÌâÈÔÔÚÊÓ²ìÖС£


https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-bug-renames-printers-to-hp-laserjet-m101-m106/


2¡¢ForescoutÅû¶ӰÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸ö©¶´


ForescoutÔÚ12ÔÂ5ÈÕÅû¶ÁËÓ°ÏìSierra OT/IoT·ÓÉÆ÷µÄ21¸ö©¶´ £¬Í³³ÆÎª¡°Sierra:21¡±¡£ÕâЩ©¶´´æÔÚÓÚSierra AirLink·äÎÑ·ÓÉÆ÷ £¬ÒÔ¼°TinyXMLºÍOpenNDS×é¼þÖС£Ñо¿ÈËÔ±³Æ £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÆäÖÐһЩ©¶´ÍêÈ«¿ØÖÆÒªº¦»ù´¡ÉèÊ©ÖеÄOT/IoT·ÓÉÆ÷ £¬´Ó¶øµ¼ÖÂÍøÂçÖжϡ¢¼äµý»î¶¯»òºáÏò×ªÒÆºÍ¶ñÒâÈí¼þ°²×°¡£ShodanɨÃè·¢ÏÖÁËÒªº¦»ù´¡ÉèÊ©ÖÐÁè¼Ý86000¸öÒ×±»¹¥»÷µÄAirLink·ÓÉÆ÷ £¬ÆäÖдó¶àÊýλÓÚÃÀ¹ú£¨Ô¼80%£© £¬Æä´ÎÊǼÓÄô󡢰ĴóÀûÑÇ¡¢·¨¹úºÍÌ©¹ú¡£


https://www.forescout.com/blog/sierra21-supply-chain-vulnerabilities-iot-ot-routers/


3¡¢Äþ¾²»ú¹¹³ÆColdFusion©¶´±»ÀûÓù¥»÷ÃÀ¹úµÄÕþ¸®»ú¹¹


ÃÀ¹úCISAÓÚ12ÔÂ5ÈÕ³Æ £¬¹¥»÷ÕßÀûÓÃAdobe ColdFusion©¶´£¨CVE-2023-26360£©À´»ñÈ¡¶ÔÕþ¸®»ú¹¹·þÎñÆ÷µÄ³õʼ·ÃÎÊȨÏÞ¡£ÕâÊÇÒ»¸ö²»ÕýÈ·µÄ·ÃÎÊ¿ØÖÆÂ©¶´ £¬ÒÑÓÚ½ñÄê3Ô·ݱ»ÐÞ¸´¡£CISA¹ûÈ»ÁËÀûÓøÃ©¶´µÄÁ½´Î¹¥»÷»î¶¯ £¬µÚÒ»Æðʼþ·¢ÉúÔÚ6ÔÂ26ÈÕ £¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2016.0.0.3µÄ·þÎñÆ÷£»µÚ¶þÆðʼþ·¢ÉúÔÚ6ÔÂ2ÈÕ £¬¹¥»÷ÕßÈëÇÖÁËÔËÐÐColdFusion v2021.0.0.2µÄ·þÎñÆ÷¡£Ñо¿ÈËÔ±ÈÏΪÕâÊÇÕì²ì»î¶¯µÄÒ»²¿ÃÅ £¬Éв»Çå³þÁ½´ÎÈëÇÖÊÇ·ñÊÇͬһ¹¥»÷ÕßËùΪ¡£


https://securityaffairs.com/155289/security/us-govt-adobe-coldfusion-flaw.html


4¡¢IT·þÎñºÍ×Éѯ¹«Ë¾HTCÔâµ½ALPHV¹¥»÷²¿ÃÅÊý¾Ýй¶


¾Ý12ÔÂ5ÈÕ±¨µÀ £¬IT·þÎñºÍÉÌÒµ×Éѯ¹«Ë¾HTC Global ServicesÔâµ½ÁËALPHVµÄ¹¥»÷¡£ALPHVÒѽ«HTCÁÐÔÚÆäÍøÕ¾ÉÏ £¬²¢¸½ÉÏÁ˱»µÁÊý¾ÝµÄ½ØÍ¼ £¬°üÂÞ»¤ÕÕ¡¢ÁªÏµÈËÃûµ¥¡¢µç×ÓÓʼþºÍ»úÃÜÎļþµÈ¡£ËäÈ»ÓйØHTC¹¥»÷µÄÐÅÏ¢ºÜÉÙ £¬µ«Ñо¿ÈËÔ±ÈÏΪ¹¥»÷Ô´ÓÚCitrix Bleed©¶´¡£¾ÝϤ £¬HTCµÄÒµÎñ²¿ÃÅÖ®Ò»CareTechÔËÓª×Å´æÔÚ©¶´µÄCitrix NetscalerÉ豸 £¬±»ÓÃÀ´¶Ô¹«Ë¾ÍøÂç½øÐгõʼ·ÃÎÊ¡£ 


https://www.bleepingcomputer.com/news/security/htc-global-services-confirms-cyberattack-after-data-leaked-online/


5¡¢Google PlayÉÏÊ®Êý¸ö¶ñÒâ´û¿îÓ¦ÓÃÏÂÔØÁè¼Ý1200Íò´Î


12ÔÂ5ÈÕ £¬ESETÐû²¼³ÂËß £¬ÃèÊöÁËAndroid¶ñÒâ´û¿îÓ¦ÓõÄÔö³¤¼°ÆäÓÃÀ´ÈƹýGoogle PlayµÄ¼¼Êõ¡£×Ô½ñÄêÄê³õÒÔÀ´ £¬ESETÒÑ·¢ÏÖ18¸ö¶ñÒâ´û¿îÓ¦Ó÷¨Ê½£¨Í³³ÆÎªSpyLoan£© £¬ÔÚGoogle PlayµÄÏÂÔØÁ¿Áè¼Ý1200Íò´Î¡£µ«ÓÉÓÚËüÃÇ»¹¿É´ÓµÚÈý·½É̵êºÍ¿ÉÒÉÍøÕ¾ÉÏÏÂÔØ £¬Òò´Ëʵ¼ÊÏÂÔØÁ¿Òª¶àµÃ¶à¡£SpyLoan»á´ÓÉ豸ÖÐÇÔÈ¡¸öÈËÐÅÏ¢ £¬Ã°³äºÏ·¨µÄ´û¿î½ðÈÚ·þÎñ £¬ÓÕÆ­Óû§½ÓÊܸßÏ¢¸¶¿î £¬È»ºóɧÈŲ¢ÀÕË÷Ä¿±ê¸¶¿î¡£


https://www.welivesecurity.com/en/eset-research/beware-predatory-fintech-loan-sharks-use-android-apps-reach-new-depths/


6¡¢KasperskyÐû²¼¹ØÓÚÕë¶ÔmacOSµÄÐÂľÂíµÄ·ÖÎö³ÂËß


12ÔÂ5ÈÕ £¬Kaspersky³ÆÆä·¢ÏÖÁËÕë¶ÔmacOSµÄÐÂÐͶñÒâ¼ÓÔØ·¨Ê½ £¬¿ÉÄÜÓëÃûΪRustBucketµÄ»î¶¯ÓйØ¡£ÔçÆÚµÄRustBucket°æ±¾Î±×°³ÉPDFÔĶÁÆ÷ £¬¶øÕâÖÖбäÌåÊÇÔÚÒ»¸öZIPÎĵµÖз¢ÏÖµÄ £¬ÔªÊý¾ÝÏÔʾӦÓô´½¨ÓÚ½ñÄê10ÔÂ21ÈÕ¡£¶ñÒâÓ¦Óñ»·¢ÏÖʱ¾ßÓÐÓÐЧǩÃû £¬µ«Ö¤ÊéÒѱ»È¡Ïû¡ £¿ÉÖ´ÐÐÎļþÓÃSwift¿ª·¢ £¬ÃûΪ"EdoneViewer" £¬°üÂÞIntelºÍApple SiliconоƬµÄ°æ±¾¡£²»ÐÒµÄÊÇ £¬Ñо¿ÈËԱûÓÐÊÕµ½À´×Ô·þÎñÆ÷µÄÈκÎÃüÁî £¬Òò´ËÎÞ·¨ÍƶϺóÐø¹¥»÷µÄÄÚÈÝ¡£


https://securelist.com/bluenoroff-new-macos-malware/111290/