HelloFresh Òò·¢ËÍ8000ÍòÀ¬»øÓʼþ±»· £¿î14ÍòÓ¢°÷

Ðû²¼Ê±¼ä 2024-01-15

1. HelloFresh Òò·¢ËÍ8000ÍòÀ¬»øÓʼþ±»· £¿î14ÍòÓ¢°÷


1ÔÂ12ÈÕ £¬Ê³Æ·ÅäË͹«Ë¾ HelloFresh ÊÕµ½Ó¢¹úÊý¾ÝÒþ˽¼à¹Ü»ú¹¹µÄ 14 ÍòÓ¢°÷£¨17.8 ÍòÃÀÔª£©· £¿î £¬ÊӲ췢Ïָù«Ë¾ÔÚ¶Ì¶Ì 7 ¸öÔÂÄÚ·¢ËÍÁËÁè¼Ý 7,900 Íò·âÀ¬»øÓʼþºÍ 100 ÍòÌõ¶ÌÐÅ¡£Õâ¼ÒÉÅʳÌ×¼þ¹«Ë¾Ã¿ÖÜÌṩԤÏȳÆÁ¿µÄÅäÁϺÍʳÆ× £¬ÕâÑùÖ÷¹Ë¾Í¿ÉÒÔ×Ô¼º×¼±¸·¹²Ë £¬¶ø²»ÊÇÔÚÔÓ»õµê¼´ÐË×¼±¸¡£ÐÅϢרԱ°ì¹«ÊÒÌåÏÖ £¬¸Ã¹«Ë¾Éù³ÆÏûÏ¢ÊÇ»ùÓÚÑ¡Ôñ¼ÓÈëÉùÃ÷ £¬µ«¸ÃÉùÃ÷²¢Î´Ìἰͨ¹ýÎı¾·¢ËÍÓªÏúÏûÏ¢¡£ÓÐÈËͬÒâµç×ÓÓʼþÓªÏú £¬µ«ÊÇ £¬Õâ°üÂÞÔÚÄêÁäÈ·ÈÏÉùÃ÷ÖÐ £¬¡°¿ÉÄܻ᲻¹«ÕýµØ¼¤Àø¿Í»§Í¬Ò⡱¡£´ËÍâ £¬¼à¹Ü»ú¹¹Ôö²¹Ëµ £¬¿Í»§ÔÚÈ¡Ïû HelloFresh ¶©ÔĺóµÄÁ½ÄêÄÚ £¬Ã»ÓÐÌṩ×ã¹»µÄÐÅÏ¢±íÃ÷ËûÃǵÄÊý¾Ý½«ÓÃÓÚÓªÏúÐÅÏ¢¡£¸Ã¹«Ë¾ÒòÎ¥·´ PECR ¶ø±»´¦ÒÔ 14 ÍòÓ¢°÷µÄ· £¿î £¬Ê¹×ÔÈ¥Äê 4 ÔÂÒÔÀ´ÏòÀ¬»øÓʼþ·¢ËÍÕß´¦ÒԵķ £¿îÊýÁ¿µ½´ï 244 ÍòÓ¢°÷¡£


2. Ñо¿ÍÅÌ峯ºÚ¿Í¿ÉÒÔ½Ù³Ö²©ÊÀºãÎÂÆ÷²¢°²×°¶ñÒâÈí¼þ


1ÔÂ12ÈÕ £¬Bitdefender ʵÑéÊÒ·¢ÏÖÁ÷ÐеIJ©ÊÀºãÎÂÆ÷ÐͺŠBCC100 ÈÝÒ×Êܵ½ÍøÂç¹¥»÷¡£´Ë©¶´¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓÃÉèÖò¢ÔÚÉ豸Éϰ²×°¶ñÒâÈí¼þ £¬¹ØÓÚÎïÁªÍøÉ豸Ò×Êܹ¥»÷״̬µÄ×îÐÂÅû¶Ӧ¸Ã²»×ãÎªÆæ¡£´Óµç×Ó»¬°åµ½¿§·È»ú £¬´ÓÅܲ½»úµ½·¿¼äÀïµÄÄþ¾²ÉãÏñÍ· £¬ËùÓÐÁ¬½Óµ½»¥ÁªÍøµÄ¹¤¾ß¶¼ÈÝÒ×Êܵ½Ç±ÔÚÍþв¡£×îÐÂÑо¿½ÒʾÁ˲©ÊÀ BCC100 ºãÎÂÆ÷ÖеÄ©¶´ £¬Ó°Ïì°æ±¾ 1.7.0 ¨C HD °æ±¾ 4.13.22¡£ÒªÁ˽â¸ÃȱÏÝ £¬±ØÐëÁ˽â BCC100 ºãÎÂÆ÷µÄÊÂÇéÔ­Àí¡£¸ÃºãÎÂÆ÷ʹÓÃÁ½¸ö΢¿ØÖÆÆ÷£ºÓÃÓÚ Wi-Fi ¹¦Ð§µÄº£·ÉоƬ (HF-LPT230) ºÍÓÃÓÚʵÏÖÖ÷Âß¼­µÄÒâ·¨°ëµ¼ÌåоƬ (STM32F103)¡£STMоƬȱ·¦ÁªÍø¹¦Ð§ £¬ÒÀÀµWi-FiоƬ½øÐÐͨÐÅ¡£Wi-Fi оƬÕìÌý LAN É쵀 TCP ¶Ë¿Ú 8899 £¬²¢Í¨¹ý UART Êý¾Ý×ÜÏß½«Ö±½Ó½ÓÊÕµ½µÄÈκÎÏûÏ¢¾µÏñµ½Ö÷΢¿ØÖÆÆ÷¡£¾¡¹Ü·ºÆð´íÎó´úÂë £¬É豸ÈÔ½ÓÊÜαÔìµÄÏìÓ¦ £¬ÆäÖаüÂ޹̼þ¸üÐÂÏêϸÐÅÏ¢ £¬°üÂÞ URL¡¢¾Þϸ¡¢MD5 УÑéºÍºÍ°æ±¾¡£È»ºó £¬É豸ÇëÇóÔÆ·þÎñÆ÷ÏÂÔØ¹Ì¼þ²¢Í¨¹ý WebSocket ·¢ËÍ £¬È·±£ URL ¿É·ÃÎÊ¡£Ò»µ©É豸ÊÕµ½Îļþ £¬Ëü¾Í»áÖ´ÐÐÉý¼¶¡£


3. ·ÒÀ¼NCSC-FI³ÆÀÕË÷Èí¼þAkira»áɾ³ýNASºÍ´Å´ø±¸·Ý


1ÔÂ11ÈÕ £¬·ÒÀ¼¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ (NCSC-FI) ͨ±¨ Akira ÀÕË÷Èí¼þ»î¶¯ÔÚ2023Äê12Ô·ÝÓÐËùÔö¼Ó £¬¸Ã»î¶¯Õë¶Ô¸Ã¹úµÄ¹«Ë¾²¢É¾³ý±¸·Ý¡£¸Ã»ú¹¹ÌåÏÖ £¬ÉϸöÔ³ÂËßµÄ 7 ÆðÀÕË÷Èí¼þʼþÖÐ £¬ÓÐ 6 ÆðÊÇÓÉÍþвÐÐΪÕßÌᳫµÄ¡£É¾³ý±¸·Ý»á·Å´ó¹¥»÷µÄЧ¹û £¬²¢µ¼ÖÂÍþвÐÐΪÕßÏòÊܺ¦ÕßÊ©¼Ó¸ü´óµÄѹÁ¦ £¬ÒòΪËûÃÇÏû³ýÁËÎÞÐèÖ§¸¶Êê½ð¼´¿É»Ö¸´Êý¾ÝµÄÑ¡Ïî¡£¹¥»÷Õß»¹Õë¶Ô´Å´ø±¸·ÝÉ豸 £¬ÕâЩÉ豸ͨ³£ÓÃ×÷´æ´¢Êý¾ÝÊý×Ö±¸·ÝµÄ¸¨Öúϵͳ¡£·ÒÀ¼»ú¹¹ÌåÏÖ £¬Akira ÀÕË÷Èí¼þ¹¥»÷ÔÚÀûÓà CVE-2023-20269 ºó»ñµÃÁ˶ÔÊܺ¦ÕßÍøÂçµÄ·ÃÎÊȨÏÞ £¬¸Ã©¶´Ó°Ïì˼¿Æ×ÔÊÊÓ¦Äþ¾²É豸 (ASA) ºÍ˼¿Æ Firepower Íþв·ÀÓù (FTD) ²úÎïÖÐµÄ VPN ¹¦Ð§¡£


4. FNFµÄ130Íò¿Í»§ÐÅÏ¢ÒÑÔÚ2023ÄêÀÕË÷Èí¼þ¹¥»÷ÖÐ̻¶


1ÔÂ11ÈÕ £¬Fidelity National Financial (FNF) ͸¶ £¬Ô¼Äª 130 Íò¿Í»§µÄÊý¾Ý¿ÉÄÜÔÚ 2023 ÄêÔâÊܵÄÀÕË÷Èí¼þ¹¥»÷ÖÐÔ⵽й¶¡£¸Ã¹«Ë¾Îª·¿µØ²úºÍµÖѺ´û¿îÐÐÒµÌṩ²úȨ±£ÏÕ·þÎñ £¬ÔÚ 2024 Äê 1 Ô 9 ÈÕ¸üеÄÎļþÖÐÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»á (SEC) ͨ±¨ÁË¿ÉÄÜÊÜÓ°ÏìµÄÏû·ÑÕßÊýÁ¿¡£¸ÃʼþÓÚ 2023 Äê 11 ÔÂÊ×´ÎÅû¶ £¬²¢ÆÈʹ FNF ¹Ø±ÕijЩϵͳ £¬µ¼ÖÂÆäÒµÎñÔËÓªÖжÏ¡£ALPHV/BlackCat ÀÕË÷Èí¼þ×éÖ¯ËæºóÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬²¢Ðû²¼ FNF Òѱ»ÄÉÈëÆäÐ¹Â¶ÍøÕ¾¡£FNF ÌåÏÖ £¬ÒÑ֪ͨԼĪ 130 Íò¿ÉÄÜÊÜÓ°ÏìµÄÏû·ÑÕß £¬²¢ÕýÔÚΪËûÃÇÌṩÐÅÓÃ¼à¿Ø¡¢ÍøÂç¼à¿ØºÍÉí·Ý͵ÇÔ»Ö¸´·þÎñ¡£Ëü»¹¼ÌÐøÓëÖ´·¨²¿ÃÅ¡¢¼à¹Ü»ú¹¹ºÍÆäËûÀûÒæÏà¹ØÕß½øÐÐЭµ÷¡£¸Ã¹«Ë¾ÌåÏÖ £¬Ã»ÓÐÖ¤¾Ý±íÃ÷Èκοͻ§ÓµÓеÄϵͳÔÚ¸ÃʼþÖÐÊܵ½Ö±½ÓÓ°Ïì £¬Ò²Ã»ÓÐÊÕµ½Èκοͻ§³ÂËß±íÃ÷·¢ÉúÁËÕâÖÖÇé¿ö¡£


5. ¡°Áãµã»÷¡±À¶ÑÀ¹¥»÷¶ÔÖ÷Á÷µÄ²Ù×÷ϵͳ×é³ÉÑÏÖØÍþв


1ÔÂ14ÈÕ £¬À¶ÑÀ¼¼ÊõΪȫÇòÊýÊ®ÒÚÉ豸ʹÓõÄÎÞÏß¼üÅÌ¡¢Êó±ê¡¢ÓÎÏ·¿ØÖÆÆ÷ºÍÆäËüÍâΧÉ豸Ìṩ֧³Ö¡£È»¶ø £¬ÐµÄÑо¿½ÒʾÁËÓ°Ïì Android¡¢iOS¡¢Linux¡¢macOS ºÍ Windows µÄÒªº¦À¶ÑÀ©¶´ £¬ÕâЩ©¶´¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õß½«É豸×÷ΪÀ¶ÑÀ¼üÅ̽øÐÐÅä¶Ô £¬²¢×¢Èë»÷¼üÀ´Ö´ÐжñÒâ²Ù×÷¡£Äþ¾²Ñо¿Ô± Marc Newlin ( @marcnewlin ) ÔÚ ShmooCon 2024 µÄÑݽ²ÖÐÅû¶ÁËÕâЩ©¶´ £¬²¢ÔÚËûµÄ²©¿ÍÉÏÐû²¼Á˼¼Êõϸ½Ú¡£ÕâЩ©¶´£¨±àºÅΪCVE-2023-45866¡¢  CVE-2024-0230ºÍCVE-2024-21306£©ÀûÓÃÁËËùÓÐÖ÷Á÷²Ù×÷ϵͳÖнÏÈõµÄÀ¶ÑÀÅä¶ÔÒªÇó¡£ÀýÈçËø¶¨Ä£Ê½¡£ÕâЩÎÊÌâ͹ÏÔÁËÀ¶ÑÀ´¦ÖÃÉí·ÝÑéÖ¤·½Ê½µÄ¹ÌÓзçÏÕ¡£³ýÁËÍêÈ«½ûÓÃÀ¶ÑÀÖ®Íâ £¬¸öÈ˼¸ºõÎÞ·¨½ÓÄÉ´ëÊ©À´·À·¶Õë¶ÔÕâЩȱÏݵÄÅÓ´ó¹¥»÷¡£Èç¹ûÀ¶ÑÀÁ¬½ÓµÄ½¨Á¢·½Ê½Ã»Óз¢Éú¸ùÌìÐԵĸıä £¬ÎÞÏßÍâΧÉ豸½«ÈÔÈ»ÊÇѰÇóÎÞÉù·ÃÎÊÈ«ÇòÊÖ»ú¡¢Ìõ¼Ç±¾µçÄÔ¡¢Æû³µºÍÖÇÄܼҾÓÖÐÐĵĹ¥»÷ÕßµÄÖ÷ҪĿ±ê¡£


6. Ñо¿ÍŶÓÅû¶Õë¶ÔLinux IoT É豸µÄÈ䳿NoaBot


1ÔÂ14ÈÕ £¬ÍøÂçÄþ¾²¹«Ë¾ Akamai ÔÚ×î½üµÄÒ»·Ý³ÂËßÖÐ͸¶ £¬¹ýÈ¥Ò»ÄêÖÐ £¬Ò»ÖÖǰËùδÓеÄ×ÔÎÒÐÞ¸´¶ñÒâÈí¼þÒѾ­Î£º¦ÁËÈ«ÇòµÄ Linux É豸 £¬ÃØÃܰ²×°Á˼ÓÃÜÍÚ¾ò·¨Ê½ £¬ÇÉÃîµØÒþ²ØÁËÆä²Ù×÷¡£¸ÃÈ䳿ÊÇ Mirai ½©Ê¬ÍøÂçµÄÐ޸İ汾 £¬Mirai ½©Ê¬ÍøÂçÊÇÒ»ÖÖ¶ñÒâÈí¼þ £¬»áѬȾÔÚ Linux ÉÏÔËÐеķþÎñÆ÷¡¢Â·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·ºÍÆäËûÎïÁªÍø (IoT) É豸¡£Mirai ÓÚ 2016 ÄêÊ״ηºÆð £¬Òò³ïı´ó¹æÄ£ DDoS ¹¥»÷¶øÎÛÃûÕÑÖø¡£ÓëÕë¶Ô DDoS ¹¥»÷µÄMirai²îÒì £¬ÕâÖÖÃûΪ NoaBot µÄÐÂÈ䳿»á°²×°¼ÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½ £¬Ê¹¹¥»÷ÕßÄܹ»ÀûÓÃÊÜѬȾÉ豸µÄ×ÊÔ´½øÐмÓÃÜ»õ±ÒÍÚ¿ó¡£NoaBot ʹÓ÷dz߶ȿâºÍ×Ö·û´®»ìÏýÀ´ÑÚ¸ÇÆä»î¶¯ £¬´Ó¶øÊ¹Æä¸üÄѱ»·À²¡¶¾Èí¼þ¼ì²âµ½²¢·ÖÎö´úÂë¡£¾¡¹ÜºÜ¼òµ¥ £¬NoaBot ȴչʾÁËÒþ²ØÆä»î¶¯²¢Ê¹·ÖÎöÅӴ󻯵ÄÅÓ¸ÅÂÔÁì¡£Akamai ¼à¿ØÁ˸ÃÈä³æÒ»ÄêÀ´µÄ»î¶¯ £¬²¢¼Ç¼ÁËÀ´×ÔÈ«Çò 849 ¸ö²îÒì IP µØÖ·µÄ¹¥»÷ £¬±íÃ÷ѬȾ·¶Î§¹ã·º¡£Akamai Ðû²¼ÁËÏêϸµÄΣº¦Ö¸±ê (IoC) £¬¿ÉÓÃÓÚ¼ì²éÉ豸ÊÇ·ñÊܵ½Ñ¬È¾¡£¸ÃÈ䳿µÄÁ÷´«Ë®Æ½ÈÔ²»È·¶¨ £¬µ«Æä·ÇͨÀýµÄÒªÁìÒýÆðÁËÑо¿ÈËÔ±µÄµ£ÓÇ¡£