WindowsÀÛ»ý¸üе¼Ö²¿ÃÅWin11µÄWi-FiÁ¬½ÓÖжÏ

Ðû²¼Ê±¼ä 2023-12-20
1¡¢WindowsÀÛ»ý¸üе¼Ö²¿ÃÅWin11µÄWi-FiÁ¬½ÓÖжÏ


¾ÝýÌå12ÔÂ18ÈÕ±¨µÀ £¬12ÔÂWindowsÀÛ»ý¸üÐÂKB5033375»áµ¼Ö²¿ÃÅWin 11Éè±¹ØÁ¬ÄWi-FiÁ¬½Ó·ºÆðÎÊÌâ  ¡£Æ¾¾ÝÓû§µÄ³ÂËß £¬´ËÎÊÌâÓ°ÏìÆôÓÃfast-transition/fast-roamingÀ´´Ù½øÎÞÏß½ÓÈëµãÖ®¼äÎÞ·ìÉè±¸ÒÆ¶¯µÄÆóÒµÎÞÏßÍøÂç  ¡£°²×°ÁËKB5033375»òKB50532288µÄ¼ÒÍ¥Óû§ÉÐδ³ÂËßÓöµ½Wi-FiÁ¬½ÓÎÊÌâ  ¡£×÷ΪÁÙʱ½â¾ö·½°¸ £¬½¨ÒéÊÜ´ËÎÊÌâÓ°ÏìµÄÓû§Ð¶ÔØËùÓÐÓÐÎÊÌâµÄWin 11¸üР ¡£µ¼Ö´ËÎÊÌâµÄÔ­ÒòÈÔÔÚÊÓ²ìÖÐ  ¡£


https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/


2¡¢VF CorporationÔâµ½ÀÕË÷¹¥»÷ £¬ÒµÎñÔËÓªÊܵ½Ó°Ïì


¾Ý12ÔÂ18ÈÕ±¨µÀ £¬ÃÀ¹ú·þ×°ºÍЬÀ๫˾VF Corp.Ôâµ½ÍøÂç¹¥»÷ £¬ÒµÎñÔËÓªÊܵ½Ó°Ïì  ¡£¸Ã¹«Ë¾ÓµÓÐSupreme¡¢VansºÍThe North FaceµÈ13¸öÖªÃûÆ·ÅÆ £¬ÄêÊÕÈë¸ß´ï116ÒÚÃÀÔª  ¡£VF͸¶¹¥»÷·¢ÉúÓÚ12ÔÂ13ÈÕ £¬¸Ã¹«Ë¾¹Ø±ÕÁ˲¿ÃÅϵͳ×÷ΪӦ¶Ô´ëÊ©  ¡£È»¶ø £¬¹¥»÷Õß»¹ÊǼÓÃÜÁ˹«Ë¾µÄ²¿ÃżÆËã»ú²¢ÇÔÈ¡Á˸öÈËÊý¾Ý  ¡£ËäÈ»¸Ãʼþ¾ßÓÐÀÕË÷¹¥»÷µÄËùÓÐÌØÕ÷ £¬µ«½ØÖÁĿǰÉÐÎÞÀÕË÷ÍÅ»ïÌåÏÖ¶Ô´ËÊÂÂôÁ¦  ¡£½ØÖÁ18ÈÕ £¬¸Ã¹«Ë¾¹É¼Ûϵø½ü9%  ¡£


https://www.securityweek.com/vf-corp-disrupted-by-cyberattack-online-operations-impacted/


3¡¢ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr.Cooper͸¶1470ÍòÈ˵ÄÊý¾Ýй¶


ýÌå12ÔÂ18ÈÕ³Æ £¬ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr.Cooper½ü1470ÍòÈ˵ÄÐÅϢй¶  ¡£11Ô³õ £¬¸Ã¹«Ë¾Ðû²¼ÔÚ10ÔÂ30ÈÕÔâµ½ÈëÇÖ £¬²¢ÓÚÔ½ÈÕ·¢ÏÖÁËÕâÒ»Çé¿ö  ¡£Ö®ºó £¬¸Ã¹«Ë¾¹Ø±ÕÁ˰üÂÞÓÃÓÚÖ§¸¶´û¿îºÍµÖѺ´û¿îµÄÔÚÏßÖ§¸¶ÃÅ»§ÔÚÄÚµÄËùÓÐϵͳ £¬À´Ó¦¶Ô¹¥»÷  ¡£¾­ÊÓ²ì £¬´Ë´ÎʼþÓ°ÏìÁË14690284ÈË £¬Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë(SSN)¡¢³öÉúÈÕÆÚºÍÒøÐÐÕÊºÅµÈ  ¡£Mr.Cooper½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩ24¸öÔµÄÉí·Ý±£»¤·þÎñ  ¡£


https://therecord.media/mr-cooper-cyberattack-data-breach-notifications


4¡¢Òâ´óÀûWestpole±»LockbitÈëÇÖµ±µØ¶àÏîÊÐÕþ·þÎñÖжÏ


12ÔÂ19ÈÕ±¨µÀ³Æ £¬Òâ´óÀûÔÆ·þÎñÌṩÉÌWestpoleÔâµ½ÁËLockbitµÄÀÕË÷¹¥»÷  ¡£¹¥»÷·¢ÉúÓÚ12ÔÂ8ÈÕ £¬Ó°ÏìÁËWestpoleµÄ¿Í»§¹«Ë¾PA Digitale £¬ËüΪ1300¸ö¹«¹²¹ÜÀí»ú¹¹Ìṩ·þÎñ  ¡£¾ÝϤ £¬¹¥»÷ÕßʹÓÃÁËLockbit 3.0 £¬µ¼ÖÂÐí¶à¹«¹²¹ÜÀí²¿ÃźÍÊÐÕþ»ú¹¹µÄ·þÎñÖжÏ £¬²¿ÃŶ¼Êб»ÆÈ»Ö¸´È˹¤À´Ìṩ·þÎñ  ¡£µ±µØÃ½Ì屨µÀ £¬¹¥»÷¿ÉÄÜ»áÓ°ÏìһЩÕþ¸®»ú¹¹Ô±¹¤12Ô·ÝÈËΪµÄ·¢·Å  ¡£¹¥»÷Ôì³ÉµÄËðʧˮƽÄÑÒÔÆÀ¹À £¬La Repubblica͸¶ £¬Westpole½ö»Ö¸´ÁË50%µÄϵͳ £¬Òâ´óÀûÄþ¾²»ú¹¹ACNÖ¸³ö»Ö¸´¹ý³Ì»ºÂýÇÒ¾ßÓÐÌôÕ½ÐÔ  ¡£


https://securityaffairs.com/156090/cyber-crime/westpole-ransomware-attack.html


5¡¢Xfinity³ÆÆäCitrix·þÎñÆ÷±»ºÚÒÑÒªÇóÓû§ÖØÖÃÃÜÂë


ýÌå12ÔÂ18ÈÕ±¨µÀ £¬ComcastÓÐÏßͨÐŹ«Ë¾£¨ÒÔXfinityÃûÒ忪չҵÎñ£©Í¸Â¶ £¬ÆäCitrix·þÎñÆ÷±»ºÚ £¬²¿Ãſͻ§µÄÐÅϢй¶  ¡£10ÔÂ25ÈÕ £¬¼´CitrixÐÞ¸´Citrix Bleed©¶´£¨CVE-2023-4966£©Á½Öܺó £¬Õâ¼ÒµçÐŹ«Ë¾·¢ÏÖ10ÔÂ16ÈÕÖÁ19ÈյĶñÒâ»î¶¯  ¡£XfinityÓÚ11ÔÂ16ÈÕ·¢ÏÖ £¬¹¥»÷Õß»¹´ÓÆäϵͳÖÐÇÔÈ¡ÁË35879455È˵ÄÊý¾Ý £¬²¢ÓÚ12ÔÂ6ÈÕÈ·¶¨ £¬Ð¹Â¶ÐÅÏ¢°üÂÞÓû§ÃûºÍ¹þÏ£ÃÜÂë  ¡£XfinityÌåÏÖ £¬ÒÑÒªÇóÓû§ÖØÖÃÃÜÂëÀ´±£»¤ËûÃǵÄÕÊ»§  ¡£


https://www.bleepingcomputer.com/news/security/xfinity-discloses-data-breach-after-recent-citrix-server-hack/


6¡¢QualysÐû²¼¹ØÓÚ2023ÄêÍþÐ²Ì¬ÊÆµÄ»Ø¹Ë³ÂËß


12ÔÂ19ÈÕ £¬QualysÐû²¼¹ØÓÚ2023ÄêÍþÐ²Ì¬ÊÆµÄ»Ø¹Ë³ÂËß  ¡£2023Äê¹²Åû¶ÁË26447¸ö©¶´ £¬±È2022Äê¶àÁË1500¶à¸öCVE  ¡£Áè¼Ý7000¸ö©¶´¾ßÓÐPoC £¬µ«ÊÇÀûÓôúÂëµÄÖÊÁ¿Í¨³£½ÏµÍ  ¡£206¸ö©¶´¾ßÓпÉÓõÄÎäÆ÷»¯ÀûÓôúÂë £¬115¸ö©¶´¾­³£±»¹¥»÷ÕßÀûÓà  ¡£½ñÄê©¶´ÀûÓÃµÄÆ½¾ùʱ¼äΪ44Ìì £¬µ«25%µÄ¸ß·çÏÕ©¶´ÔÚÐû²¼µ±Ìì¾Í±»ÀûÓà  ¡£×î³£±»ÀûÓõÄ©¶´°üÂÞCVE-2023-0669ºÍCVE-2023-20887µÈ £¬×î»îÔ¾µÄ¹¥»÷ÕßΪCL0P  ¡£Â©¶´ÀûÓÃÖÐʹÓõÄÖ÷ÒªMITRE ATT&CK¼ÆÄ±ºÍ¼¼Êõ°üÂÞÀûÓÃÔ¶³Ì·þÎñ¡¢ÃæÏò¹«ÖÚµÄÓ¦ÓúÍȨÏÞÌáÉý  ¡£


https://blog.qualys.com/vulnerabilities-threat-research/2023/12/19/2023-threat-landscape-year-in-review-part-one