Ñо¿Ö°Ô±·¢Ã÷¿ÉÈÆ¹ýWindows HelloµÇ¼µÄÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-11-24
1¡¢Ñо¿Ö°Ô±·¢Ã÷¿ÉÈÆ¹ýWindows HelloµÇ¼µÄÇå¾²Îó²î


¾ÝýÌå11ÔÂ22ÈÕ±¨µÀ £¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Á˶à¸öÎó²î £¬£¬£¬ £¬£¬£¬¿ÉÓÃÀ´ÈƹýDell Inspiron 15¡¢Lenovo ThinkPad T14ºÍMicrosoft Surface Pro XÌõ¼Ç±¾µçÄÔÉϵÄWindows HelloÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£ËùÓвâÊÔµÄÖ¸ÎÆ´«¸ÐÆ÷¶¼ÊÇMatch-on-Chip (MoC)´«¸ÐÆ÷ £¬£¬£¬ £¬£¬£¬ËäÈ»MoC´«¸ÐÆ÷¿ÉÒÔ×èÖ¹½«´æ´¢µÄÖ¸ÎÆÊý¾ÝÖØ·Åµ½Ö÷»ú¾ÙÐÐÆ¥Åä £¬£¬£¬ £¬£¬£¬µ«ËüÃÇ×Ô¼º²¢²»¿É×èÖ¹¶ñÒâ´«¸ÐÆ÷Ä£ÄâÕýµ±´«¸ÐÆ÷ÓëÖ÷»ú¾ÙÐÐͨѶ¡£¡£¡£¡£¡£¡£Õâ¿ÉÄÜ»á¹ýʧµØÏÔʾÓû§Éí·ÝÑéÖ¤ÀÖ³É £¬£¬£¬ £¬£¬£¬»òÖØ·Å֮ǰµÄÖ÷»úºÍ´«¸ÐÆ÷Ö®¼äµÄÁ÷Á¿¡£¡£¡£¡£¡£¡£Îª´Ë £¬£¬£¬ £¬£¬£¬Î¢Èí¿ª·¢ÁËÇå¾²×°±¸ÅþÁ¬Ð­Ò飨SDCP£© £¬£¬£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±ÕÕ¾ÉʹÓÃMiTM¹¥»÷ÀÖ³ÉÈÆ¹ýÁËWindows HelloÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html


2¡¢º«¹úIT¹«Ë¾TmaxSoftÉèÖùýʧÁè¼Ý5000ÍòÌõ¼Í¼й¶


¾Ý11ÔÂ22ÈÕ±¨µÀ £¬£¬£¬ £¬£¬£¬º«¹úIT¹«Ë¾TmaxSoftÔ¼2TBµÄÊý¾ÝÒѹûÕæÁè¼ÝÁ½Äê¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔçÔÚ½ñÄê1Ô¾ͷ¢Ã÷ÁËÒ»¸ö̻¶µÄKibana¿ØÖÆÃæ°å £¬£¬£¬ £¬£¬£¬²¢Ö¸³öÕâ×éÊý¾ÝÓÚ2021Äê6ÔÂÊ״α»·¢Ã÷¡£¡£¡£¡£¡£¡£Êý¾Ý¿â×ܹ²ÓÐÁè¼Ý5600ÍòÌõ¼Í¼ £¬£¬£¬ £¬£¬£¬°üÀ¨Ô±¹¤ÐÕÃûºÍµç»°¡¢¹ÍÓ¶ÌõÔ¼ºÅ¡¢·¢Ë͵ĸ½¼þºÍ¶þ½øÖÆÎļþµÄÔªÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ £¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´ £¬£¬£¬ £¬£¬£¬²¢ÇÒ°üÀ¨´ó×ÚÊý¾ÝµÄ¿ØÖÆÃæ°åÈÔÈ»´¦ÓÚ¹ûÕæ×´Ì¬¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/154567/data-breach/tmaxsoft-leaks-2tb-of-data.html


3¡¢Î¢ÈíÅû¶Diamond SleetʹÓÃCyberLinkµÄ¹©Ó¦Á´¹¥»÷


΢ÈíÔÚ11ÔÂ22ÈÕÅû¶Á˳¯ÏʺڿÍÍÅ»ïDiamond Sleet(ZINC)ÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ10ÔÂ20ÈÕÊӲ쵽Á˴˴οÉÒɻ £¬£¬£¬ £¬£¬£¬Ëü¶ÔÖйų́Íå¶àýÌåÈí¼þ¹«Ë¾CyberLink¿ª·¢µÄÓ¦ÓóÌÐò¾ÙÐÐľÂí»¯¡£¡£¡£¡£¡£¡£¶ñÒâÎļþʹÓÃCyberLink½ÒÏþµÄÓÐÓÃÖ¤Êé¾ÙÐÐÊðÃû £¬£¬£¬ £¬£¬£¬ÍйÜÔڸù«Ë¾ÓµÓеÄÕýµ±µÄ¸üлù´¡ÉèÊ©ÉÏ¡£¡£¡£¡£¡£¡£Æù½ñΪֹ £¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâ»î¶¯ÒÑÓ°Ïì¶à¸ö¹ú¼Ò/µØÇøµÄ100¶ą̀װ±¸ £¬£¬£¬ £¬£¬£¬°üÀ¨ÈÕ±¾¡¢Öйų́Íå¡¢¼ÓÄôóºÍÃÀ¹ú¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/


4¡¢Blender͸¶һÁ¬µÄDDoS¹¥»÷µ¼ÖÂÆäЧÀÍÆ÷å´»úÊýÈÕ


ýÌå11ÔÂ22ÈÕ³Æ £¬£¬£¬ £¬£¬£¬Blender͸¶×î½üµÄÍøÕ¾Ð§ÀÍÖÐÖ¹ÊÇÒ»Á¬µÄDDoS¹¥»÷µ¼Öµġ£¡£¡£¡£¡£¡£¸ÃÏîÄ¿ÍŶÓÌåÏÖ £¬£¬£¬ £¬£¬£¬×Ô11ÔÂ18ÈÕÒÔÀ´ £¬£¬£¬ £¬£¬£¬blender.orgЧÀÍÆ÷¾ÍÔâµ½DDoS¹¥»÷ £¬£¬£¬ £¬£¬£¬ÆäЧÀÍÆ÷ÒòÇëÇó¹ýÔØ¶øå´»ú¡£¡£¡£¡£¡£¡£×ÝÈ»ÔÚ¹¥»÷ÕßÔÝÍ£¹¥»÷µÄʱ¼ä £¬£¬£¬ £¬£¬£¬BlenderµÄ»ù´¡ÉèÊ©ÈÔÈ»Òò´ó×Ú´ý´¦Öóͷ£µÄÕýµ±ÇëÇó¶ø¹ýÔØ¡£¡£¡£¡£¡£¡£×îÖÕ £¬£¬£¬ £¬£¬£¬ÔÚÂÄÀúÁË4ÌìµÄÒ»Á¬ÖÐÖ¹ºó £¬£¬£¬ £¬£¬£¬¸ÃÍŶӽ«ÆäÖ÷ÍøÕ¾×ªÒÆµ½ÁËCloudFlareÉÏ £¬£¬£¬ £¬£¬£¬ÕâïÔÌ­¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£Blender·ÖÏíµÄͳ¼ÆÊý¾ÝÏÔʾ £¬£¬£¬ £¬£¬£¬¹¥»÷ÈÔÔÚÒ»Á¬ £¬£¬£¬ £¬£¬£¬Õë¶Ô¸ÃÏîĿЧÀÍÆ÷µÄÐéαÇëÇóÁè¼Ý2.4ÒڴΡ£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/open-source-blender-project-battling-ddos-attacks-since-saturday/


5¡¢AkamaiÐû²¼Ð½©Ê¬ÍøÂçInfectedSlursµÄÆÊÎö±¨¸æ


11ÔÂ21ÈÕ £¬£¬£¬ £¬£¬£¬AkamaiÐû²¼»ùÓÚMiraiµÄн©Ê¬ÍøÂçInfectedSlursµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£InfectedSlursÒ»Ö±ÔÚʹÓÃÁ½¸öRCEÎó²îÀ´Ñ¬È¾Â·ÓÉÆ÷ºÍ¼Ïñ»ú(NVR)×°±¸ £¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÓÚ½ñÄê10Ô·¢Ã÷Á˸ý©Ê¬ÍøÂç £¬£¬£¬ £¬£¬£¬²¢ÒÔΪËüÖÁÉÙ´Ó2022ÄêÆð¾ÍÒ»Ö±»îÔ¾¡£¡£¡£¡£¡£¡£ËüÊÇJenX MiraiµÄ±äÌå £¬£¬£¬ £¬£¬£¬ÓÉÓÚÔÚC2ÓòºÍÓ²±àÂë×Ö·û´®ÖÐʹÓù¥»÷ÐÔÓïÑÔ¶øµÃÃû¡£¡£¡£¡£¡£¡£ÆäC2»ù´¡ÉèÊ©Ïà¶Ô¼¯ÖÐ £¬£¬£¬ £¬£¬£¬ËƺõÒ²Ö§³ÖhailBotµÄÔËÐС£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°Ï칩ӦÉ̵ÄÃû³Æ £¬£¬£¬ £¬£¬£¬µ«¹©Ó¦ÉÌÔÊÐí½«ÓÚ12ÔÂÐû²¼Çå¾²¸üС£¡£¡£¡£¡£¡£


https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days


6¡¢KasperskyÐû²¼2024ÄêÏûºÄÕßÍøÂçÍþвµÄÕ¹Íû±¨¸æ


11ÔÂ23ÈÕ £¬£¬£¬ £¬£¬£¬KasperskyÐû²¼Á˹ØÓÚ2024ÄêÏûºÄÕßÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô2024Äê×ö³öÁËÕ¹Íû £¬£¬£¬ £¬£¬£¬°üÀ¨¸ü¶à´ÈÉÆÏà¹ØµÄÕ©Æ­¼´Î´À´ÁÙ¡¢ÍøÉÏÊÐËÁ½«Óë´ÈÉÆ»ú¹¹µÄÏàÖú¡¢»¥ÁªÍø»®·Ö¸üϸ¡¢VPNЧÀͳÊÉÏÉýÇ÷ÊÆ¡¢Çå¾²ÐÔ¸ßÓÚÓû§Ìñ¾²¶È½«´ßÉúеÄÇå¾²ÎÊÌâ¡¢ÍøÂç¹¥»÷Õß½«Õë¶ÔP2E¡¢¿ª·¢Í¨ÓõÄDeepfake¼ì²é¹¤¾ß¡¢ÓïÒôDeepfakeÊÂÎñÔö¶àÒÔ¼°ÒÔÓ°Ï·Ê×ӳΪÓÕ¶üµÄȦÌ×Ôö¶àµÈ¡£¡£¡£¡£¡£¡£


https://securelist.com/kaspersky-security-bulletin-consumer-threats-2024/111135/