WeMysticÍøÕ¾Êý¾Ý¿âÅäÖÃÃýÎó1330ÍòÌõÓû§¼Í¼й¶

°ä²¼¹¦·ò 2023-12-05

1¡¢WeMysticÍøÕ¾Êý¾Ý¿âÅäÖÃÃýÎó1330ÍòÌõÓû§¼Í¼й¶


¾ÝýÌå12ÔÂ2ÈÕ±¨Â·£¬WeMysticÍøÕ¾Ò»¸öÊ¢¿ªÇÒÎÞÃÜÂëµÄMongoDBÊý¾Ý¿âй¶ÁË34 GBµÄÊý¾Ý¡£WeMysticÌṩռÐÇѧ¡¢ÐÄÁ齡ȫºÍÉñÃØÑ§µÄÓйØÖªÊ¶£¬»¹ÌṩÌìÈ»±¦Ê¯¡¢ÂöÂÖ¡¢ËþÂÞÅÆºÍÊÖÁ´µÈ²úÆ·µÄÔÚÏßÉ̵ê¡£ÆäÖÐÒ»¸öÃûΪ"users"µÄÊý¾Ý¼¯ÖÐÔ̺¬¶à´ï1330Íò±Ê¼Í¼£¬Éæ¼°ÐÕÃû¡¢ÓʼþµØÖ·¡¢IPµØÖ·ºÍÓû§ÏµÍ³Êý¾ÝµÈ¡£Ä¿Ç°£¬WeMysticÒѽ«¸ÃÊý¾Ý¿â± £»¤ÆðÀ´£¬µ«×êÑÐÈËÔ±°µÊ¾£¬ÕâЩÊý¾ÝÖÁÉÙÄܹ»±»½Ó¼û5Ìì¡£


https://securityaffairs.com/155102/security/wemystic-website-data-leak.html


2¡¢Google°ä²¼AndroidµÄ12Ô·ݸüÐÂ×ܼƽ¨¸´85¸ö·ì϶


GoogleÔÚ12ÔÂ4ÈÕ°ä²¼Á˱¾ÔµÄAndroid°²È«¸üУ¬×ܼƽ¨¸´85¸ö·ì϶¡£ÆäÖÐÔ̺¬Androidϵͳ×é¼þÖз¢ÏÖµÄÒ»¸öÁãµã»÷Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-40088£©£¬²»±ØÒª¶î±íµÄȨÏÞ¼´¿É±»ÀûÓá£´Ë±í£¬Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶»¹Ô̺¬Android¿ò¼ÜÖеÄÌáȨ·ì϶£¨CVE-2023-40077£©¡¢ÐÅϢй¶·ì϶£¨CVE-2023-40076£©ºÍϵͳ×é¼þÖеÄÌáȨ·ì϶£¨CVE-2023-45866£©µÈ¡£


https://www.bleepingcomputer.com/news/security/december-android-updates-fix-critical-zero-click-rce-flaw/


3¡¢PromonÅû¶Õë¶Ô¶«ÄÏÑǽðÈÚÐÐÒµµÄ¶ñÒâÈí¼þFjordPhantom


PromonÔÚ11ÔÂ30ÈÕÅû¶ÁËÒ»ÖÖÃûΪFjordPhantomµÄÐÂAndroid¶ñÒâÈí¼þ£¬ÀûÓÃÐé¹¹»¯ÔÚÈÝÆ÷ÖÐÔËÐжñÒâ´úÂë²¢ÈÆ¹ý¼ì²â¡£Ëüͨ¹ýÓʼþ¡¢¶ÌÐźÍÐÂÎÅÀûÓô«²¼£¬ÖØÒªÕë¶ÔÓ¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹ú¡¢Ô½ÄÏ¡¢ÐÂ¼ÓÆÂºÍÂíÀ´Î÷ÑǵȵØÓò¡£Ö¸±ê±»ÓÕÆ­ÏÂÔØËùνµÄºÏ·¨ÒøÐÐÀûÓ㬵«ÆäÖÐÔ̺¬ÔÚÐé¹¹»·¾³ÖÐÔËÐеĶñÒâ´úÂ룬¿É¹¥»÷ÕæÕýµÄÒøÐÐÀûÓá£FjordPhantomÖ¼ÔÚÇÔÈ¡ÔÚÏßÒøÐÐÕÊ»§Í´´¦²¢Í¨¹ýÖ´ÐÐÉ豸ڲƭÀ´½ÚÔìÂòÂô£¬Promon»¹½éÉÜÁËÒ»¸ö¿Í»§±»Æ­È¡28ÍòÃÀÔªµÄ°¸Àý¡£


https://promon.co/security-news/fjordphantom-android-malware/


4¡¢ÐÂSugarGh0st RAT±»ÓÃÓÚ¹¥»÷ÎÚ×ȱð¿Ë˹̹ºÍº«¹ú


11ÔÂ30ÈÕ£¬Cisco Talos³ÆÆä·¢ÏÖÁËеÄSugarGh0st RAT£¬±»ÓÃÓÚ¹¥»÷ÎÚ×ȱð¿Ë˹̹ºÍº«¹úµÄ»î¶¯¡£Æ¾¾ÝºÅÁî½á¹¹ºÍ´úÂëÖÐʹÓõÄ×Ö·û´®µÄÀàËÆÐÔ£¬×êÑÐÈËÔ±´§¶ÈSugarGh0st RATÊÇGh0st RATµÄÒ»¸öбäÌå¡£¸Ã»î¶¯¿ÉÄÜÔçÔÚ½ñÄê8ÔÂ¾ÍÆðÍ·ÁË£¬×êÑÐÈËÔ±¹Û²ìµ½Á½¸öϰȾÁ´ÀûÓÃǶÈë¶ñÒâJavaScriptµÄWindows¿ì½Ý·½Ê½Ìṩ×é¼þ£¬ÒÔ·Ö·¢ºÍÆô¶¯SugarGh0st payload¡£ÔÚÒ»¸öϰȾÁ´ÖУ¬¹¥»÷ÕßÀûÓÃÁËDynamixWrapperX¹¤¾ßÔÚ¶ñÒâJavaScriptÖÐÆôÓÃWindows APIº¯ÊýŲÓã¬À´ÔËÐÐshellcode¡£


https://blog.talosintelligence.com/new-sugargh0st-rat/


5¡¢ÃÀ¹úCapital HealthÒ½ÔºÔâµ½¹¥»÷ϵͳÖжÏÊýÈÕ


¾Ý11ÔÂ30ÈÕ±¨Â·£¬·ÇͶ»úÐÔ×éÖ¯Capital HealthÔâµ½¹¥»÷£¬µ¼ÖÂÐÂÔóÎ÷Öݸ÷µØµÄCapital HealthÒ½ÔººÍÃÅÕïµÄITϵͳÖжÏ¡£¸Ã»ú¹¹Ð¹Â©£¬Ò½ÔºÄ¿Ç°ÔÚÆ¾¾ÝϵͳÍ £»úºÍ̸½Ó¹ÜÈëÔº»¼Õߣ¬ITÍŶÓÕýרһÓÚ¸´Ô­ÏµÍ³£¬¶øÊÖÊõÔòƾ¾Ý´¹Î£Ë®Æ½ºÍ»¼ÕßÇé¿öÈ·¶¨ÓÅÏȰ¤´Î¡£Capital HealthÔ¤¼ÆÏµÍ³ÖжÏÎÊÌâ¿ÉÄÜ»¹»á³ÖÐøÒ»ÖÜ£¬µ«ÎÞ·¨Ìṩµ±Ç°ÎÊÌâºÎʱÆëÈ«½â¾öµÄ¾ßÌ幦·ò¡£


https://www.bleepingcomputer.com/news/security/capital-health-hospitals-hit-by-cyberattack-causing-it-outages/


6¡¢×êÑÐÈËÔ±¹«¿ªÐÂmacOSÀÕË÷Èí¼þTurtleµÄϸ½ÚÐÅÏ¢


ýÌå12ÔÂ1Èճƣ¬Patrick Wardle¹«¿ªÁ˶ÔÐÂmacOSÀÕË÷Èí¼þTurtleµÄ¾ßÌå·ÖÎö¡£×Ô´ÓTurtle±»ÉÏ´«µ½Virus Totalºó£¬ÒÑÓÐ24¸öɱ¶¾½â¾ö¹æ»®½«ÆäÏóÕ÷Ϊ¶ñÒâÈí¼þ£¬ÕâÅú×¢Ëü²»ÊÇÒ»¸ö¸´ÔӵĶñÒâÈí¼þ¡£ÔÚijЩÇé¿öÏ£¬É±¶¾¹æ»®»á½«¶þ½øÔìÎļþÏóÕ÷ΪWindows¶ñÒâÈí¼þ¡£×êÑÐÈËÔ±´§Ä¦Ëü×î³õÊÇΪWindows¿ª·¢µÄ£¬¶øºóÒÆÖ²µ½ÁËmacOS¡£Turtle½«Îļþ¶ÁÈëÄڴ棬ʹÓÃAES£¨CTRģʽ£©¼ÓÃÜ£¬³Á¶¨ÃûÎļþ£¬¶øºóÓüÓÃÜÊý¾Ý¸²¸ÇÎļþµÄԭʼÄÚÈÝ£¬ÔÚ¼ÓÃÜÎļþµÄÎļþÃûÖÐÔö³¤À©´óÃû"TURTLERANSv0"¡£


https://securityaffairs.com/155075/security/turtleransom-macos-ransomware.html