¸ßͨºÍÁª·¢¿Æ½ô¼±ÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄ©¶´5Ghoul

Ðû²¼Ê±¼ä 2023-12-11

1¡¢¸ßͨºÍÁª·¢¿Æ½ô¼±ÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄ©¶´5Ghoul


¾ÝýÌå12ÔÂ8ÈÕ±¨µÀ £¬Ñо¿ÈËÔ±·¢ÏÖÁ˸ßͨºÍÁª·¢¿Æ5Gµ÷ÖÆ½âµ÷Æ÷¹Ì¼þÖеÄ14¸ö©¶´ £¬Í³³ÆÎª5Ghoul £¬Ó°ÏìÁËÊý°Ù¿îAndroidºÍiOSÊÖ»úÒÔ¼°USBºÍÎïÁªÍøµ÷ÖÆ½âµ÷Æ÷ ¡£5Ghoul©¶´¿É±»ÀûÓÃÀ´²»Í£Ìᳫ¹¥»÷ £¬ÒÔ¶Ï¿ªÁ¬½Ó¡¢¶³½áÁ¬½Ó£¨Éæ¼°ÊÖ¶¯ÖØÆô£©»ò½«5GÁ¬½Ó½µ¼¶Îª4GµÈ ¡£ÏÖÒÑÈ·¶¨24¼Ò¹©Ó¦É̵Ä714¿îÖÇÄÜÊÖ»úÊܵ½¸Ã©¶´µÄÓ°Ïì ¡£Ä¿Ç° £¬Áª·¢¿ÆºÍ¸ßͨ¾ùÒÑÐû²¼Äþ¾²¸üР£¬ÒÔÐÞ¸´14¸ö©¶´ÖеÄ12¸ö £¬ÁíÍâÁ½¸ö©¶´µÄ²¹¶¡Ô¤¼Æ»áÔÚδÀ´Ðû²¼ ¡£


https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html


2¡¢ÐÂAutoSpill¹¥»÷·½Ê½¿É´ÓAndroidÃÜÂë¹ÜÀíÆ÷ÇÔȡƾ¾Ý


¾Ý12ÔÂ9ÈÕ±¨µÀ £¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÐµĹ¥»÷·½Ê½AutoSpill £¬¿ÉÔÚ×Ô¶¯Ìî³äÆÚ¼äÇÔÈ¡AndroidÉϵÄÕÊ»§Æ¾¾Ý ¡£AutoSpill¹¥»÷Ô´ÓÚAndroidδÄÜÇ¿ÖÆÖ´ÐлòÃ÷È·½ç˵Äþ¾²´¦ÖÃ×Ô¶¯Ìî´ÕÊý¾ÝµÄÔðÈÎ £¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ýй¶»ò±»Ö÷»úÓ¦Ó÷¨Ê½²¶×½ ¡£Ôڴ˹¥»÷³¡¾°ÖÐ £¬ÌṩµÇ¼±íµ¥µÄ¶ñÒâÓ¦ÓÿÉÒÔ²¶×½Óû§µÄƾ¾Ý £¬¶ø²»»áÁôÏÂÈκι¥»÷¼£Ïó ¡£Ñо¿ÈËÔ±ÏòÊÜÓ°ÏìÈí¼þµÄÌṩÉ̺ÍAndroidÍŶÓÅû¶ÁË©¶´ £¬ÕâЩ³ÂËß±»ÈÏΪÊÇÓÐЧµÄ £¬µ«ÉÐÎÞÏêϸµÄÐÞ¸´¼Æ»®±»¹ûÈ» ¡£


https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/


3¡¢ALPHVÍÅ»ïµÄÍøÕ¾ÖжÏÊýʮСʱÒÉËÆÓëÖ´·¨Ðж¯ÓйØ


12ÔÂ8ÈÕ±¨µÀ³Æ £¬ÀÕË÷ÍÅ»ïALPHVµÄÍøÕ¾ÒÑÖжÏ30¸öСʱ £¬¾Ý³ÆÓëÖ´·¨Ðж¯ÓÐ¹Ø ¡£ALPHVÓÃÓÚ̸ÅкÍÊý¾Ýй¶µÄÍøÕ¾ÔÚ12ÔÂ7ÈÕͻȻÎÞ·¨·ÃÎÊ £¬¶øÇÒʼÖÕ±£³Ö¹Ø±Õ״̬ ¡£ËüΨһµÄÓÃÓÚ̸ÅеÄTor URLÒ²ÒѹرÕ £¬Õâ±íÃ÷ÀÕË÷ÍÅ»ïÃæÏò¹«ÖڵĻù´¡ÉèÊ©Ôâµ½ÈëÇÖ £¬ÕýÔÚ½øÐеÄ̸ÅÐÒ²¶¼ÖÕÖ¹ÁË ¡£µ±±»Îʼ°ÖжÏÇé¿öʱ £¬ALPHV¹ÜÀíÔ±³ÆÕâÐ©ÍøÕ¾¿ÉÄܺܿì¾Í»á»Ö¸´ÉÏÏß ¡£Äþ¾²¹«Ë¾RedSense Intel͸¶ £¬ÓÉÓÚÖ´·¨Ðж¯ £¬·þÎñÆ÷±»¹Ø±Õ ¡£


https://www.bleepingcomputer.com/news/security/alphv-ransomware-site-outage-rumored-to-be-caused-by-law-enforcement/


4¡¢Norton HealthcarÅûÂ¶Éæ¼°Ô±¹¤ºÍ»¼ÕßÐÅÏ¢µÄÊý¾Ýй¶


ýÌå12ÔÂ9ÈÕ³Æ £¬Norton HealthcarÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ £¬Ó°ÏìÁË»¼Õß¡¢Ô±¹¤ºÍ¼ÒÊôµÄ¸öÈËÐÅÏ¢ ¡£Ð¹Â¶Ô´ÓÚ5ÔÂ9ÈÕµÄÀÕË÷¹¥»÷ £¬ºó¾­ÊÓ²ìÈ·¶¨ £¬¹¥»÷ÕßÔÚ5ÔÂ7ÈÕÖÁ5ÔÂ9ÈÕ·ÃÎÊÁËÄ³Ð©ÍøÂç´æ´¢É豸 £¬µ«Î´·ÃÎʸûú¹¹µÄÒ½ÁƼǼϵͳ»òNorton MyChart ¡£ALPHVÔøÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬ÌåÏÖÒÑÇÔÈ¡ÆäÒ½ÁƱ£½¡ÏµÍ³ÖеÄ4.7TBÊý¾Ý £¬»¹¹ûÈ»ÁËÊýÊ®¸öÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý ¡£Norton Healthcare½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿Ø ¡£


https://securityaffairs.com/155495/data-breach/norton-healthcare-ransomware-attack.html


5¡¢Unit 42Ðû²¼APT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶à´Î¹¥»÷µÄ·ÖÎö³ÂËß


12ÔÂ7ÈÕ £¬Unit 42Ðû²¼ÁËAPT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶àÂÖ¹¥»÷»î¶¯µÄ·ÖÎö ¡£ÔÚ¹ýÈ¥20¸öÔÂÖÐ £¬¸ÃÍÅ»ïÀûÓé¶´CVE-2023-23397 £¬Õë¶Ô14¸ö¹ú¼ÒµÄÖÁÉÙ30¸ö»ú¹¹¿ªÕ¹ÁËÈýÂֻ ¡£µÚÒ»´Î¹¥»÷·¢ÉúÔÚ2022Äê3ÔÂÖÁ12Ô £¬µÚ¶þÂÖ¹¥»÷·¢ÉúÔÚ½ñÄê3Ô ¡£×î½üÒ»´Î¹¥»÷·¢ÉúÓÚ9ÔÂÖÁ10Ô £¬¹¥»÷ÁË7¸ö¹ú¼ÒµÄ9¸ö»ú¹¹ ¡£´Ë´ÎÊܹ¥»÷µÄÅ·ÖÞ¹ú¼Ò´ó²¿ÃŶ¼ÊDZ±Ô¼(NATO)³ÉÔ±¹ú £¬Éæ¼°Òªº¦»ù´¡ÉèÊ©ºÍÔÚÍâ½»¡¢¾­¼ÃºÍ¾üÊÂÊÂÎñÖÐÌṩÐÅÏ¢ÓÅÊÆµÄ»ú¹¹ ¡£


https://unit42.paloaltonetworks.com/russian-apt-fighting-ursa-exploits-cve-2023-233397/


6¡¢TrendMicroÐû²¼¶Ô2023ÄêÍøÂçÄþ¾²µÄ»Ø¹ËºÍ·´Ë¼³ÂËß


12ÔÂ7ÈÕ £¬Trend MicroÐû²¼Á˶Ô2023ÄêÍøÂçÄþ¾²Ç÷ÊÆµÄ»Ø¹ËºÍ·´Ë¼³ÂËß ¡£³ÂËßÖ¸³ö £¬2023ÄêÉú³ÉʽAIÔÚ¼ÓÇ¿ÏÖÓй¥»÷ģʽ£¨ÈçµöÓã¹¥»÷£©µÄ·½Ãæ·¢»ÓÁË×÷Óà £¬¸øÄþ¾²ÍŶӴøÀ´²¢½«¼ÌÐø´øÀ´ÌôÕ½ ¡£¹¤¾ßÂûÑÓÈÔÈ»ÊÇÄþ¾²Ç÷ÊÆ £¬Æóҵƽ¾ù²¿ÊðÁË20µ½50¸ö¶ÀÁ¢µÄÄþ¾²½â¾ö·½°¸ £¬´æÔÚÑÏÖØµÄÈßÓà ¡£ÈËÀ಻ÊÇ×îµ¥±¡µÄ»·½Ú ¡£ËõСÀͶ¯Á¦ºÍÆóÒµÖ®¼äµÄ¼¼Äܲî¾à £¬ÕâÊÇØ½´ý½â¾öµÄÍøÂçÄþ¾²Ç÷ÊÆ ¡£


https://www.trendmicro.com/en_us/research/23/l/2023-review-reflecting-on-cybersecurity-trends.html