WeMysticÍøÕ¾Êý¾Ý¿âÅäÖôíÎó1330ÍòÌõÓû§¼Ç¼й¶
Ðû²¼Ê±¼ä 2023-12-051¡¢WeMysticÍøÕ¾Êý¾Ý¿âÅäÖôíÎó1330ÍòÌõÓû§¼Ç¼й¶
¾ÝýÌå12ÔÂ2ÈÕ±¨µÀ£¬WeMysticÍøÕ¾Ò»¸ö¿ª·ÅÇÒÎÞÃÜÂëµÄMongoDBÊý¾Ý¿âй¶ÁË34 GBµÄÊý¾Ý¡£WeMysticÌṩռÐÇѧ¡¢¾«Éñ½¡¿µºÍÉñÃØÑ§µÄÏà¹ØÖªÊ¶£¬»¹ÌṩÌìÈ»±¦Ê¯¡¢ÂöÂÖ¡¢ËþÂÞÅÆºÍÊÖÁ´µÈ²úÎïµÄÔÚÏßÉ̵ꡣÆäÖÐÒ»¸öÃûΪ"users"µÄÊý¾Ý¼¯ºÏ°üÂÞ¶à´ï1330ÍòÌõ¼Ç¼£¬Éæ¼°ÐÕÃû¡¢ÓʼþµØÖ·¡¢IPµØÖ·ºÍÓû§ÏµÍ³Êý¾ÝµÈ¡£Ä¿Ç°£¬WeMysticÒѽ«¸ÃÊý¾Ý¿â±£»¤ÆðÀ´£¬µ«Ñо¿ÈËÔ±ÌåÏÖ£¬ÕâЩÊý¾ÝÖÁÉÙ¿ÉÒÔ±»·ÃÎÊ5Ìì¡£
https://securityaffairs.com/155102/security/wemystic-website-data-leak.html
2¡¢GoogleÐû²¼AndroidµÄ12Ô·ݸüÐÂ×ܼÆÐÞ¸´85¸ö©¶´
GoogleÔÚ12ÔÂ4ÈÕÐû²¼Á˱¾ÔµÄAndroidÄþ¾²¸üУ¬×ܼÆÐÞ¸´85¸ö©¶´¡£ÆäÖаüÂÞAndroidϵͳ×é¼þÖз¢ÏÖµÄÒ»¸öÁãµã»÷Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-40088£©£¬²»ÐèÒªÌØ±ðµÄȨÏÞ¼´¿É±»ÀûÓᣴËÍ⣬´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄ©¶´»¹°üÂÞAndroid¿ò¼ÜÖеÄÌáȨ©¶´£¨CVE-2023-40077£©¡¢ÐÅϢй¶©¶´£¨CVE-2023-40076£©ºÍϵͳ×é¼þÖеÄÌáȨ©¶´£¨CVE-2023-45866£©µÈ¡£
https://www.bleepingcomputer.com/news/security/december-android-updates-fix-critical-zero-click-rce-flaw/
3¡¢PromonÅû¶Õë¶Ô¶«ÄÏÑǽðÈÚÐÐÒµµÄ¶ñÒâÈí¼þFjordPhantom
PromonÔÚ11ÔÂ30ÈÕÅû¶ÁËÒ»ÖÖÃûΪFjordPhantomµÄÐÂAndroid¶ñÒâÈí¼þ£¬ÀûÓÃÐéÄ⻯ÔÚÈÝÆ÷ÖÐÔËÐжñÒâ´úÂë²¢ÈÆ¹ý¼ì²â¡£Ëüͨ¹ýÓʼþ¡¢¶ÌÐźÍÏûÏ¢Ó¦ÓÃÁ÷´«£¬Ö÷ÒªÕë¶ÔÓ¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹ú¡¢Ô½ÄÏ¡¢ÐÂ¼ÓÆÂºÍÂíÀ´Î÷ÑǵȵØÓò¡£Ä¿±ê±»ÓÕÆÏÂÔØËùνµÄºÏ·¨ÒøÐÐÓ¦Ó㬵«ÆäÖаüÂÞÔÚÐéÄâ»·¾³ÖÐÔËÐеĶñÒâ´úÂ룬¿É¹¥»÷ÕæÕýµÄÒøÐÐÓ¦Óá£FjordPhantomÖ¼ÔÚÇÔÈ¡ÔÚÏßÒøÐÐÕÊ»§Æ¾¾Ý²¢Í¨¹ýÖ´ÐÐÉ豸ÆÛÕ©À´¿ØÖƽ»Ò×£¬Promon»¹½éÉÜÁËÒ»¸ö¿Í»§ÊÜÆÈ¡28ÍòÃÀÔªµÄ°¸Àý¡£
https://promon.co/security-news/fjordphantom-android-malware/
4¡¢ÐÂSugarGh0st RAT±»ÓÃÓÚ¹¥»÷ÎÚ×ȱð¿Ë˹̹ºÍº«¹ú
11ÔÂ30ÈÕ£¬Cisco Talos³ÆÆä·¢ÏÖÁËеÄSugarGh0st RAT£¬±»ÓÃÓÚ¹¥»÷ÎÚ×ȱð¿Ë˹̹ºÍº«¹úµÄ»î¶¯¡£Æ¾¾ÝÃüÁî½á¹¹ºÍ´úÂëÖÐʹÓõÄ×Ö·û´®µÄÏàËÆÐÔ£¬Ñо¿ÈËÔ±ÍÆ¶ÏSugarGh0st RATÊÇGh0st RATµÄÒ»¸öбäÌå¡£¸Ã»î¶¯¿ÉÄÜÔçÔÚ½ñÄê8Ô¾ͿªÊ¼ÁË£¬Ñо¿ÈËÔ±ÊӲ쵽Á½¸öѬȾÁ´ÀûÓÃǶÈë¶ñÒâJavaScriptµÄWindows¿ì½Ý·½Ê½Ìṩ×é¼þ£¬ÒÔ·Ö·¢ºÍÆô¶¯SugarGh0st payload¡£ÔÚÒ»¸öѬȾÁ´ÖУ¬¹¥»÷ÕßÀûÓÃÁËDynamixWrapperX¹¤¾ßÔÚ¶ñÒâJavaScriptÖÐÆôÓÃWindows APIº¯Êýµ÷Óã¬À´ÔËÐÐshellcode¡£
https://blog.talosintelligence.com/new-sugargh0st-rat/
5¡¢ÃÀ¹úCapital HealthÒ½ÔºÔâµ½¹¥»÷ϵͳÖжÏÊýÈÕ
¾Ý11ÔÂ30ÈÕ±¨µÀ£¬·ÇÓªÀûÐÔ×éÖ¯Capital HealthÔâµ½¹¥»÷£¬µ¼ÖÂÐÂÔóÎ÷Öݸ÷µØµÄCapital HealthÒ½ÔººÍÃÅÕïµÄITϵͳÖжϡ£¸Ã»ú¹¹Í¸Â¶£¬Ò½ÔºÄ¿Ç°ÕýÔÚÆ¾¾Ýϵͳͣ»úÐÒé½ÓÊÕÈëÔº»¼Õߣ¬ITÍŶÓÕýרעÓÚ»Ö¸´ÏµÍ³£¬¶øÊÖÊõÔòƾ¾Ý½ô¼±Ë®Æ½ºÍ»¼Õß×´¿öÈ·¶¨ÓÅÏÈ˳Ðò¡£Capital HealthÔ¤¼ÆÏµÍ³ÖжÏÎÊÌâ¿ÉÄÜ»¹»áÁ¬ÐøÒ»ÖÜ£¬µ«ÎÞ·¨Ìṩµ±Ç°ÎÊÌâºÎʱÍêÈ«½â¾öµÄ¾ßÌåʱ¼ä¡£
https://www.bleepingcomputer.com/news/security/capital-health-hospitals-hit-by-cyberattack-causing-it-outages/
6¡¢Ñо¿ÈËÔ±¹ûÈ»ÐÂmacOSÀÕË÷Èí¼þTurtleµÄϸ½ÚÐÅÏ¢
ýÌå12ÔÂ1Èճƣ¬Patrick Wardle¹ûÈ»Á˶ÔÐÂmacOSÀÕË÷Èí¼þTurtleµÄÏêϸ·ÖÎö¡£×Ô´ÓTurtle±»ÉÏ´«µ½Virus Totalºó£¬ÒÑÓÐ24¸öɱ¶¾½â¾ö·½°¸½«Æä±ê־Ϊ¶ñÒâÈí¼þ£¬Õâ±íÃ÷Ëü²»ÊÇÒ»¸öÅÓ´óµÄ¶ñÒâÈí¼þ¡£ÔÚijЩÇé¿öÏ£¬É±¶¾·½°¸»á½«¶þ½øÖÆÎļþ±ê־ΪWindows¶ñÒâÈí¼þ¡£Ñо¿ÈËÔ±ÍÆ²âËü×î³õÊÇΪWindows¿ª·¢µÄ£¬È»ºóÒÆÖ²µ½ÁËmacOS¡£Turtle½«Îļþ¶ÁÈëÄڴ棬ʹÓÃAES£¨CTRģʽ£©¼ÓÃÜ£¬ÖØÃüÃûÎļþ£¬È»ºóÓüÓÃÜÊý¾ÝÁýÕÖÎļþµÄÔʼÄÚÈÝ£¬ÔÚ¼ÓÃÜÎļþµÄÎļþÃûÖÐÌí¼ÓÀ©Õ¹Ãû"TURTLERANSv0"¡£
https://securityaffairs.com/155075/security/turtleransom-macos-ransomware.html