Ñо¿ÈËÔ±ÑÝʾÇÔÈ¡AMDºÍIntel CPUÊý¾ÝµÄSLAM¹¥»÷
Ðû²¼Ê±¼ä 2023-12-08¾ÝýÌå12ÔÂ6ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±¿ª·¢ÁËÒ»ÖÖÃûΪSLAMµÄÐÂÐͲàͨµÀ¹¥»÷£¬ÀûÓÃIntel¡¢AMDºÍArm¼´½«ÍƳöµÄÓÃÓÚÌá¸ßCPUÄþ¾²ÐÔµÄÓ²¼þ¹¦Ð§£¬´ÓÄÚºËÄÚ´æÖÐÇÔÈ¡rootÃÜÂë¡£SLAMÊÇÒ»ÖÖ˲ִ̬Ðй¥»÷£¬ËüÀûÓÃÁËÔÊÐíÈí¼þʹÓÃ64λÏßÐÔµØÖ·ÖеÄδ·ÒëµØÖ·Î»À´´æ´¢ÔªÊý¾ÝµÄÄڴ湦Ч¡£CPU¹©Ó¦ÉÌÒÔ²îÒìµÄ·½Ê½ÊµÏÖÕâÒ»µã£¬Intel½«Æä³ÆÎªLAM£¬AMD³ÆÎªUAI£¬¶øArm³ÆÎªTBI¡£Ñо¿ÈËÔ±³Æ£¬SLAMÖ÷ÒªÓ°ÏìÁËÂú×ãÌØ¶¨³ß¶ÈµÄδÀ´Ð¾Æ¬£¬ËäÈ»ÏȽøµÄÓ²¼þ¹¦Ð§Ìá¸ßÁËÄÚ´æÄþ¾²ÐԺ͹ÜÀí£¬µ«Ò²ÒýÈëÁË¿ÉÀûÓõÄ΢¼Ü¹¹¾ºÕùÌõ¼þ¡£
https://www.bleepingcomputer.com/news/security/new-slam-attack-steals-sensitive-data-from-amd-future-intel-cpus/
2¡¢ÈÕ²ú´óÑóÖÞ·Ö¹«Ë¾Ôâµ½¹¥»÷Êý¾Ý¿ÉÄÜй¶´æÔÚÕ©Æ·çÏÕ
ýÌå12ÔÂ7Èճƣ¬ÈÕ±¾Æû³µÖÆÔìÉÌÈÕ²úÕýÔÚÊÓ²ìÕë¶ÔÆä´óÑóÖÞ·Ö¹«Ë¾µÄ¹¥»÷»î¶¯¡£ÈÕ²ú´óÑóÖÞ¹«Ë¾Ö÷ÒªÂôÁ¦°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄ·ÖÏú¡¢ÓªÏú¡¢ÏúÊۺͷþÎñ¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷¼û¸æ°Ä´óÀûÑǺÍÐÂÎ÷À¼ÈÕ²ú¹«Ë¾ºÍ½ðÈÚ·þÎñ¹«Ë¾µÄϵͳÔâµ½ÁËÒ»ÆðÍøÂçʼþ£¬Ä¿Ç°ÕýÔÚÈ·¶¨¹¥»÷µÄÓ°Ïì¡£¾¡¹Ü¸ÃÍøÕ¾µÄ¹¦Ð§ËƺõδÊÜÓ°Ï죬µ«ÈÕ²úÌåÏÖÕýÔÚŬÁ¦»Ö¸´ÊÜÓ°Ïìϵͳ¡£¸öÈËÐÅÏ¢¿ÉÄÜй¶£¬ÈÕ²ú¹«Ë¾ÌáÐѿͻ§¶ÔÆäÕË»§±£³Ö¾¯Ì裬ÁôÒâÈκÎÒì³£»òթƻ¡£
https://securityaffairs.com/155360/security/nissan-oceania-suffers-cyberattack.html
3¡¢ÃÀ¹úº£¾ü³Ð°üÉÌAustal USA±»Hunters International¹¥»÷
¾Ý12ÔÂ6ÈÕ±¨µÀ£¬ÃÀ¹úÔì´¬¹«Ë¾Austal USAÔâµ½Hunters InternationalµÄ¹¥»÷¡£Austal USAÊÇÃÀ¹ú¹ú·À²¿ºÍ¹úÍÁÄþ¾²²¿µÄ³Ð°üÉÌ£¬ËûÌåÏÖÒÑѸËÙ»º½â¸Ãʼþ£¬Î´¶ÔÔËÓªÔì³ÉÓ°Ï죬¹¥»÷ÕßҲûÓзÃÎÊ»ò»ñÈ¡ÈκθöÈË»ò»úÃÜÐÅÏ¢¡£Hunters InternationalÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢¹ûÈ»ÁËһЩÊý¾Ý×÷Ϊ֤¾Ý£¬»¹Íþв½«ÔÚδÀ´¼¸ÌìÐû²¼¸ü¶àÊý¾Ý£¬°üÂ޺ϹæÎļþ¡¢ÕÐÆ¸ÐÅÏ¢¡¢²ÆÕþÏêϸÐÅÏ¢¡¢ÈÏÖ¤ºÍ¹¤³ÌÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/navy-contractor-austal-usa-confirms-cyberattack-after-data-leak/
4¡¢Î¢ÈíÅû¶¹ØÓÚStar Blizzard×îÐÂTTPµÄÏêϸÐÅÏ¢
΢ÈíÔÚ12ÔÂ7ÈÕÅû¶Á˹ØÓÚ¶íÂÞ˹ÍÅ»ïStar BlizzardµÄ×îÐÂTTP¡£×Ô2022ÄêÒÔÀ´£¬Star Blizzard¸ïÐÂÁ˼ì²âÈÆ¹ý¹¦Ð§£¬ÈÔȻרעÓÚµç×ÓÓʼþƾ¾Ýй¶¡£Î¢ÈíÈ·ÈÏÁ˸ÃÍÅ»ïµÄ5ÖÖÐÂÈÆ¹ý¼¼Êõ£¬°üÂÞʹÓ÷þÎñÆ÷¶Ë½ÅÔÀ´·ÀÖ¹×Ô¶¯É¨Ã衢ʹÓÃÓʼþÓªÏúƽ̨·þÎñÒþ²ØÕæÊµµÄ·¢¼þÈ˵ØÖ·¡¢Ê¹ÓÃDNSÌṩÉÌÀ´Òþ²ØVPS»ù´¡ÉèÊ©µÄIP¡¢Ê¹ÓÃÓÐÃÜÂë±£»¤µÄPDFÓÕ¶ü»òÍйÜPDFÓÕ¶üµÄ»ùÓÚÔÆµÄÎļþ¹²ÏíÆ½Ì¨µÄÁ´½ÓÒÔ¼°Îª¼ÓÈëÕß×¢²áµÄÓòתÏòÔ½·¢Ëæ»úµÄÓòÉú³ÉËã·¨(DGA)¡£
https://www.microsoft.com/en-us/security/blog/2023/12/07/star-blizzard-increases-sophistication-and-evasion-in-ongoing-attacks/
5¡¢Group-IB·¢ÏÖÕë¶ÔÌ©¹úµçÐŹ«Ë¾µÄLinuxľÂíKrasue
12ÔÂ7ÈÕ£¬Group-IB³ÆÆä·¢ÏÖÁËÕë¶ÔµçÐŹ«Ë¾LinuxϵͳµÄľÂíKrasue£¬×Ô2021ÄêÒÔÀ´Ò»Ö±Ã»Óб»·¢ÏÖ¡£KrasueµÄ¶þ½øÖÆÎļþ°üÂÞÒ»¸örootkitµÄ7¸ö±äÖÖ£¬¸ÃrootkitÖ§³Ö¶à¸öLinuxÄں˰汾£¬²¢»ùÓÚ3¸ö¿ªÔ´ÏîÄ¿µÄ´úÂë¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¸Ã¶ñÒâÈí¼þµÄÖ÷Òª¹¦Ð§ÊÇά³Ö¶ÔÖ÷»úµÄ·ÃÎÊ£¬Õâ¿ÉÄܱíÃ÷ËüÊÇͨ¹ý½©Ê¬ÍøÂ粿ÊðµÄ£¬»òÕßÓɳõʼ·ÃÎÊÊðÀí³öÊÛ¸ø¹¥»÷Õß¡£Ä¿Ç°£¬KrasueËÆºõ½öÕë¶ÔÌ©¹úµÄµçÐŹ«Ë¾¡£
https://www.group-ib.com/blog/krasue-rat/
6¡¢ZeroFoxÐû²¼½ü7¸ö¼¾¶ÈLockBit¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß
12ÔÂ6ÈÕýÌ峯£¬ZeroFoxÐû²¼Á˹ØÓÚ2022Äê1ÔÂÖÁ2023Äê9ÔµÄ7¸ö¼¾¶ÈÖÐLockBit¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£ÔÚÕâ¶Îʱ¼ä£¬È«ÇòÁè¼ÝËÄ·ÖÖ®Ò»µÄÀÕË÷Èí¼þºÍÊý×ÖÀÕË÷£¨R&DE£©¹¥»÷ÀûÓÃÁËLockBit£¬Å·Ö޺ͱ±ÃÀ·Ö±ðÓÐ30%ºÍ25%µÄR&DE¹¥»÷ÀûÓÃLockBit¡£Õë¶Ô±±ÃÀµÄLockBit¹¥»÷Õë¶Ô×î¶àµÄÐÐÒµÊÇÖÆÔì¡¢½¨Öþ¡¢ÁãÊÛ¡¢Ö´·¨ºÍ×ÉѯÒÔ¼°Ò½ÁƱ£½¡¡£LockBitËùÕ¼µÄ±ÈÀý³ÊϽµÇ÷ÊÆ£¬Õâ¿ÉÄÜÊÇÓÉÓÚR&DEÈÕÒæ¶àÑù»¯£¬RaaS²úÎï½µµÍÁ˹¥»÷ÕߵĽøÈëÃż÷¡£
https://www.zerofox.com/resources/lockbit-targeting-ransomware-digital-extortion/