¸ßͨºÍÁª·¢¿Æ½ô¼±ÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄ©¶´5Ghoul
Ðû²¼Ê±¼ä 2023-12-111¡¢¸ßͨºÍÁª·¢¿Æ½ô¼±ÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄ©¶´5Ghoul
¾ÝýÌå12ÔÂ8ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁ˸ßͨºÍÁª·¢¿Æ5Gµ÷ÖÆ½âµ÷Æ÷¹Ì¼þÖеÄ14¸ö©¶´£¬Í³³ÆÎª5Ghoul£¬Ó°ÏìÁËÊý°Ù¿îAndroidºÍiOSÊÖ»úÒÔ¼°USBºÍÎïÁªÍøµ÷ÖÆ½âµ÷Æ÷¡£5Ghoul©¶´¿É±»ÀûÓÃÀ´²»Í£Ìᳫ¹¥»÷£¬ÒÔ¶Ï¿ªÁ¬½Ó¡¢¶³½áÁ¬½Ó£¨Éæ¼°ÊÖ¶¯ÖØÆô£©»ò½«5GÁ¬½Ó½µ¼¶Îª4GµÈ¡£ÏÖÒÑÈ·¶¨24¼Ò¹©Ó¦É̵Ä714¿îÖÇÄÜÊÖ»úÊܵ½¸Ã©¶´µÄÓ°Ï졣Ŀǰ£¬Áª·¢¿ÆºÍ¸ßͨ¾ùÒÑÐû²¼Äþ¾²¸üУ¬ÒÔÐÞ¸´14¸ö©¶´ÖеÄ12¸ö£¬ÁíÍâÁ½¸ö©¶´µÄ²¹¶¡Ô¤¼Æ»áÔÚδÀ´Ðû²¼¡£
https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html
2¡¢ÐÂAutoSpill¹¥»÷·½Ê½¿É´ÓAndroidÃÜÂë¹ÜÀíÆ÷ÇÔȡƾ¾Ý
¾Ý12ÔÂ9ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÐµĹ¥»÷·½Ê½AutoSpill£¬¿ÉÔÚ×Ô¶¯Ìî³äÆÚ¼äÇÔÈ¡AndroidÉϵÄÕÊ»§Æ¾¾Ý¡£AutoSpill¹¥»÷Ô´ÓÚAndroidδÄÜÇ¿ÖÆÖ´ÐлòÃ÷È·½ç˵Äþ¾²´¦ÖÃ×Ô¶¯Ìî´ÕÊý¾ÝµÄÔðÈΣ¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ýй¶»ò±»Ö÷»úÓ¦Ó÷¨Ê½²¶×½¡£Ôڴ˹¥»÷³¡¾°ÖУ¬ÌṩµÇ¼±íµ¥µÄ¶ñÒâÓ¦ÓÿÉÒÔ²¶×½Óû§µÄƾ¾Ý£¬¶ø²»»áÁôÏÂÈκι¥»÷¼£Ïó¡£Ñо¿ÈËÔ±ÏòÊÜÓ°ÏìÈí¼þµÄÌṩÉ̺ÍAndroidÍŶÓÅû¶ÁË©¶´£¬ÕâЩ³ÂËß±»ÈÏΪÊÇÓÐЧµÄ£¬µ«ÉÐÎÞÏêϸµÄÐÞ¸´¼Æ»®±»¹ûÈ»¡£
https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/
3¡¢ALPHVÍÅ»ïµÄÍøÕ¾ÖжÏÊýʮСʱÒÉËÆÓëÖ´·¨Ðж¯ÓйØ
12ÔÂ8ÈÕ±¨µÀ³Æ£¬ÀÕË÷ÍÅ»ïALPHVµÄÍøÕ¾ÒÑÖжÏ30¸öСʱ£¬¾Ý³ÆÓëÖ´·¨Ðж¯Óйء£ALPHVÓÃÓÚ̸ÅкÍÊý¾Ýй¶µÄÍøÕ¾ÔÚ12ÔÂ7ÈÕͻȻÎÞ·¨·ÃÎÊ£¬¶øÇÒʼÖÕ±£³Ö¹Ø±Õ״̬¡£ËüΨһµÄÓÃÓÚ̸ÅеÄTor URLÒ²Òѹرգ¬Õâ±íÃ÷ÀÕË÷ÍÅ»ïÃæÏò¹«ÖڵĻù´¡ÉèÊ©Ôâµ½ÈëÇÖ£¬ÕýÔÚ½øÐеÄ̸ÅÐÒ²¶¼ÖÕÖ¹ÁË¡£µ±±»Îʼ°ÖжÏÇé¿öʱ£¬ALPHV¹ÜÀíÔ±³ÆÕâÐ©ÍøÕ¾¿ÉÄܺܿì¾Í»á»Ö¸´ÉÏÏß¡£Äþ¾²¹«Ë¾RedSense Intel͸¶£¬ÓÉÓÚÖ´·¨Ðж¯£¬·þÎñÆ÷±»¹Ø±Õ¡£
https://www.bleepingcomputer.com/news/security/alphv-ransomware-site-outage-rumored-to-be-caused-by-law-enforcement/
4¡¢Norton HealthcarÅûÂ¶Éæ¼°Ô±¹¤ºÍ»¼ÕßÐÅÏ¢µÄÊý¾Ýй¶
ýÌå12ÔÂ9Èճƣ¬Norton HealthcarÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁË»¼Õß¡¢Ô±¹¤ºÍ¼ÒÊôµÄ¸öÈËÐÅÏ¢¡£Ð¹Â¶Ô´ÓÚ5ÔÂ9ÈÕµÄÀÕË÷¹¥»÷£¬ºó¾ÊÓ²ìÈ·¶¨£¬¹¥»÷ÕßÔÚ5ÔÂ7ÈÕÖÁ5ÔÂ9ÈÕ·ÃÎÊÁËÄ³Ð©ÍøÂç´æ´¢É豸£¬µ«Î´·ÃÎʸûú¹¹µÄÒ½ÁƼǼϵͳ»òNorton MyChart¡£ALPHVÔøÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬ÌåÏÖÒÑÇÔÈ¡ÆäÒ½ÁƱ£½¡ÏµÍ³ÖеÄ4.7TBÊý¾Ý£¬»¹¹ûÈ»ÁËÊýÊ®¸öÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£Norton Healthcare½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿Ø¡£
https://securityaffairs.com/155495/data-breach/norton-healthcare-ransomware-attack.html
5¡¢Unit 42Ðû²¼APT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶à´Î¹¥»÷µÄ·ÖÎö³ÂËß
12ÔÂ7ÈÕ£¬Unit 42Ðû²¼ÁËAPT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶àÂÖ¹¥»÷»î¶¯µÄ·ÖÎö¡£ÔÚ¹ýÈ¥20¸öÔÂÖУ¬¸ÃÍÅ»ïÀûÓé¶´CVE-2023-23397£¬Õë¶Ô14¸ö¹ú¼ÒµÄÖÁÉÙ30¸ö»ú¹¹¿ªÕ¹ÁËÈýÂֻ¡£µÚÒ»´Î¹¥»÷·¢ÉúÔÚ2022Äê3ÔÂÖÁ12Ô£¬µÚ¶þÂÖ¹¥»÷·¢ÉúÔÚ½ñÄê3Ô¡£×î½üÒ»´Î¹¥»÷·¢ÉúÓÚ9ÔÂÖÁ10Ô£¬¹¥»÷ÁË7¸ö¹ú¼ÒµÄ9¸ö»ú¹¹¡£´Ë´ÎÊܹ¥»÷µÄÅ·ÖÞ¹ú¼Ò´ó²¿ÃŶ¼ÊDZ±Ô¼(NATO)³ÉÔ±¹ú£¬Éæ¼°Òªº¦»ù´¡ÉèÊ©ºÍÔÚÍâ½»¡¢¾¼ÃºÍ¾üÊÂÊÂÎñÖÐÌṩÐÅÏ¢ÓÅÊÆµÄ»ú¹¹¡£
https://unit42.paloaltonetworks.com/russian-apt-fighting-ursa-exploits-cve-2023-233397/
6¡¢TrendMicroÐû²¼¶Ô2023ÄêÍøÂçÄþ¾²µÄ»Ø¹ËºÍ·´Ë¼³ÂËß
12ÔÂ7ÈÕ£¬Trend MicroÐû²¼Á˶Ô2023ÄêÍøÂçÄþ¾²Ç÷ÊÆµÄ»Ø¹ËºÍ·´Ë¼³ÂËß¡£³ÂËßÖ¸³ö£¬2023ÄêÉú³ÉʽAIÔÚ¼ÓÇ¿ÏÖÓй¥»÷ģʽ£¨ÈçµöÓã¹¥»÷£©µÄ·½Ãæ·¢»ÓÁË×÷Ó㬸øÄþ¾²ÍŶӴøÀ´²¢½«¼ÌÐø´øÀ´ÌôÕ½¡£¹¤¾ßÂûÑÓÈÔÈ»ÊÇÄþ¾²Ç÷ÊÆ£¬Æóҵƽ¾ù²¿ÊðÁË20µ½50¸ö¶ÀÁ¢µÄÄþ¾²½â¾ö·½°¸£¬´æÔÚÑÏÖØµÄÈßÓà¡£ÈËÀ಻ÊÇ×îµ¥±¡µÄ»·½Ú¡£ËõСÀͶ¯Á¦ºÍÆóÒµÖ®¼äµÄ¼¼Äܲî¾à£¬ÕâÊÇØ½´ý½â¾öµÄÍøÂçÄþ¾²Ç÷ÊÆ¡£
https://www.trendmicro.com/en_us/research/23/l/2023-review-reflecting-on-cybersecurity-trends.html