2025年1月9日星期四

Ivanti Products Multiple Vulnerabilities

Release Date: 9 Jan 2025

RISK: Extremely High Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities have been identified in Ivanti Products. A remote attacker could exploit these vulnerabilities to trigger remote code execution and elevation of privilege on the targeted system.

 

Notes:

CVE-2025-0282 is being exploited in the wild. The vulnerability can lead to remote code execution on targeted device.


Impact

  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

CVE-2025-0282:

 

  • Ivanti Connect Secure (ICS) versions 22.7R2 through 22.7R2.4
  • Ivanti Policy Secure (IPS) versions 22.7R1 through 22.7R1.2
  • Ivanti Neurons for ZTA gateways 22.7R2 through 22.7R2.3 

 

CVE-2025-0283:

 

  • Ivanti Connect Secure (ICS) versions 22.7R2.4 and prior, 9.1R18.9 and prior 
  • Ivanti Policy Secure (IPS) versions 22.7R1.2 and prior
  • Ivanti Neurons for ZTA gateways versions 22.7R2.3 and prior

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

發佈日期: 2025年01月09日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、阻斷服務狀況、遠端執行任意程式碼及彷冒。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 134
  • Firefox ESR 128.6
  • Firefox ESR 115.19
  • Thunderbird 134
  • Thunderbird 128.6
  • Thunderbird 115.19

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 134
  • Firefox ESR 128.6
  • Firefox ESR 115.19
  • Thunderbird 134
  • Thunderbird 128.6
  • Thunderbird 115.19

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 9 Jan 2025

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass, denial of service condition, remote code execution and spoofing on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Firefox 134
  • Firefox ESR 128.6
  • Firefox ESR 115.19
  • Thunderbird 134
  • Thunderbird 128.6
  • Thunderbird 115.19

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 134
  • Firefox ESR 128.6
  • Firefox ESR 115.19
  • Thunderbird 134
  • Thunderbird 128.6
  • Thunderbird 115.19

Vulnerability Identifier


Source


Related Link

SonicWall 產品多個漏洞

發佈日期: 2025年01月09日

風險: 中度風險

類型: 操作系統 - Network

於 SonicWall Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及繞過保安限制。


影響

  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • Gen6 Hardware Firewalls 6.5.5.1-6n 之前的版本

  • Gen7 NSv 7.0.1-5165 之前的版本

  • Gen7 Firewalls 7.1.3-7015 之前的版本

  • TZ80 8.0.0-8037 之前的版本


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SonicWall Products Multiple Vulnerabilities

Release Date: 9 Jan 2025

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in SonicWall Products.  A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • Gen6 Hardware Firewalls version prior to 6.5.5.1-6n

  • Gen7 NSv version prior to 7.0.1-5165

  • Gen7 Firewalls prior to 7.1.3-7015

  • TZ80 prior to 8.0.0-8037


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

網絡釣魚警告

現況及相關趨勢

近日,mickmick.net 發現有騙徒設立釣魚網站,假扮香港景點的購票網站。這些釣魚網站利用誘人的折扣誘騙用戶提供個人資訊來完成購票。在接獲報告後,mickmick.net 迅速辨識出詐騙網站,並向公眾發出保安警報和防禦策略,敦促他們採取預防措施。騙徒經常使用「限時折扣」或「大減價」等字眼,並採用具有欺騙性的、外觀相似的網址來掩蓋釣魚網站的真確性。

 

以下是近期mickmick.net報告的釣魚網址的例子:

 

用戶一旦點擊該詐騙網站,就會出現一個帶有折扣景點門票的頁面。然後,詐騙者會通知用戶進一步點擊以繼續購買。

 

在下一頁,用戶需要選擇門票類型和參觀日期。此後他們被要求繼續付款。

 

點擊「繼續付款」後,騙徒會要求用戶在網站上註冊一個帳戶。然後,他們要求用戶提供姓名、電子郵件和電話號碼,從而試圖收集用戶的個人資料。

mickmick.net呼籲公眾提高網絡安全意識,並採取以下措施防範假冒網站:

 

  • 檢查網址:釣魚網站的網址通常與真實網站相似,但會有細微的差別,如拼寫錯誤或使用不同的域名。用戶應仔細檢查網址,確保其正確無誤。
  • 注意安全證書:雖然釣魚網站也可以使用 HTTPS 協定,但用戶仍應檢查瀏覽器地址欄中的安全鎖標誌,並確保證書信息與網站匹配
  • 留意可疑內容:釣魚網站可能會包含拼寫錯誤、語法錯誤或不一致的設計元素。這些都是潛在的警示信號。
  • 使用反釣魚工具:可利用「CyberDefender 守網者」的「防騙視伏器」,通過檢查網址和IP地址等,來辨識詐騙及網絡陷阱,或者致電香港警務處反詐騙協調中心「防騙易18222」熱線向警方求助。
  • 避免點擊不明連結:不要隨意點擊來自不明來源的連結,尤其是在電子郵件或社交媒體上收到的連結。
  • 在裝置上啟用垃圾短訊攔截:
    對於 Android 手機,前往「設定」 > 「垃圾短訊辨識」。
    對於 IOS 手機,前往「設定」>「訊息」>「未知郵件和垃圾郵件」。
  • 定期更新軟件:確保操作系統和應用程序保持最新,以防止已知漏洞被利用。
  • 啟用多因素認證:為重要賬號啟用多因素認證,以增加額外的安全層。
  • 教育和培訓:企業應定期為員工提供網絡安全培訓,提高他們的防範意識。
  • 監控賬戶活動:定期檢查銀行賬戶和其他重要賬號的活動,及早發現可疑行為。
  • 備份重要數據:定期備份重要數據,以防止因釣魚攻擊或其他網絡威脅造成的數據丟失。

Phishing Alert

Current Status and Related Trends

Recently, mickmick.net has discovered that scammers are creating phishing websites that impersonate online ticket purchasing websites of Hong Kong attractions. These phishing websites exploit users' of attrative discounts by tricking them into providing personal information to complete the ticket purchasing. Upon receiving these reports, mickmick.net identified the fraudulent websites and promptly issued alerts and defensive strategies to the public, urging them to take preventive measures. Scammers often use phrases such as 'limited time discount' or 'big sale' and employ deceptive, similar-looking URLs to obscure the legitimacy of their sites.

 

The following is recent examples of phishing URLs reported by mickmick.net:

 

Once users click on the fraudulent website, a page with ticket to attractions with discount was shown. The scammers then inform users to click further to continue the purchase.

 

On the next page, users are asked to select the type of the ticket and the date of visit. They are asked to proceed payment after that.

 

After clicking 'Proceed to pay', the scammers request users to register an account on the website. Users are asked to provide their name, email and phone number, thereby attempting to collect users' personal information.

mickmkick.net urges the public to increase their awareness of cybersecurity and recommends that Internet users should:

 

  • Check the URL: The URL of a phishing website is usually similar to the real website, but there will be slight differences, such as misspellings or using a different domain name. Users should double check the URL to ensure it is correct.
  • Pay attention to security certificates: Although phishing websites can also use the HTTPS protocol, users should still check the security lock symbol in the browser address bar and ensure that the certificate information matches the website.
  • Watch out for suspicious content: Phishing websites may contain misspellings, grammatical errors, or inconsistent design elements. These are potential warning signs.
  • Use anti-phishing tools: Use the free search engine “Scameter” of Cyberdefender.hk to identify fraud and network traps by checking website addresses and IP addresses, or call the Anti-Fraud Coordination Center of the Hong Kong Police Force. Call the police for help through the anti-fraud hotline 18222.
  • Avoid clicking on unknown links: Don’t click on random links from unknown sources, especially links you receive in email or on social media.
  • Implement SMS spam blocking on devices: 
    for Android phone, go to Settings > SMS Spam Recognition.
    for IOS phone, go to Settings > Messages > Unknown & Spam.
  • Update software regularly: Ensure operating systems and applications are kept up to date to prevent known vulnerabilities from being exploited.
  • Enable multi-factor authentication: Enable multi-factor authentication for important accounts to add an extra layer of security.
  • Education and training: Companies should provide regular cybersecurity training to employees to improve their awareness of prevention.
  • Monitor account activity: Regularly check the activity of bank accounts and other important accounts to detect suspicious behavior early.
  • Back up important data: Back up important data regularly to prevent data loss due to phishing attacks or other cyber threats.

2025年1月8日星期三

Android 多個漏洞

發佈日期: 2025年01月08日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、權限提升及遠端執行程式碼。

 


影響

  • 權限提升
  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • 2025-01-01前的 Android 保安更新級別

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Android Multiple Vulnerabilities

Release Date: 8 Jan 2025

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, elevation of privilege and remote code execution on the targeted system.


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Android security patch level prior to 2025-01-01

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2025年01月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 131.0.6778.264 (Linux) 之前的版本
  • Google Chrome 131.0.6778.264/.265 (Mac) 之前的版本
  • Google Chrome 131.0.6778.264/.265 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 131.0.6778.264 (Linux) 或之後的版本
  • 升級 131.0.6778.264/.265 (Mac) 或之後的版本
  • 升級 131.0.6778.264/.265 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Release Date: 8 Jan 2025

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 131.0.6778.264 (Linux)
  • Google Chrome prior to 131.0.6778.264/.265 (Mac)
  • Google Chrome prior to 131.0.6778.264/.265 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 131.0.6778.264 (Linux) or later
  • Update to version 131.0.6778.264/.265 (Mac) or later
  • Update to version 131.0.6778.264/.265 (Windows) or later

Vulnerability Identifier


Source


Related Link

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...