¸ßͨºÍÁª·¢¿Æ´¹Î£½¨¸´Ó°Ïì714¿î5GÊÖ»úµÄ·ì϶5Ghoul
°ä²¼¹¦·ò 2023-12-111¡¢¸ßͨºÍÁª·¢¿Æ´¹Î£½¨¸´Ó°Ïì714¿î5GÊÖ»úµÄ·ì϶5Ghoul
¾ÝýÌå12ÔÂ8ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖÁ˸ßͨºÍÁª·¢¿Æ5Gµ÷Ôì½âµ÷Æ÷¹Ì¼þÖеÄ14¸ö·ì϶£¬Í³³ÆÎª5Ghoul£¬Ó°ÏìÁËÊý°Ù¿îAndroidºÍiOSÊÖ»úÒÔ¼°USBºÍÎïÁªÍøµ÷Ôì½âµ÷Æ÷¡£5Ghoul·ì϶¿É±»ÀûÓÃÀ´²»ÐÝÌáÒé¹¥»÷£¬ÒÔ¶Ï¿ªÏνӡ¢¶³½áÏνӣ¨Éæ¼°ÊÖ¶¯³ÁÆô£©»ò½«5GÏνӽµ¼¶Îª4GµÈ¡£ÏÖÒÑÈ·¶¨24¼Ò¹©¸øÉ̵Ä714¿îÖÇÄÜÊÖ»úÊܵ½¸Ã·ì϶µÄÓ°Ï졣Ŀǰ£¬Áª·¢¿ÆºÍ¸ßͨ¾ùÒѰ䲼°²È«¸üУ¬ÒÔ½¨¸´14¸ö·ì϶ÖеÄ12¸ö£¬Áí±íÁ½¸ö·ì϶µÄ²¹¶¡Ô¤¼Æ»áÔÚ½«À´°ä²¼¡£
https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html
2¡¢ÐÂAutoSpill¹¥»÷·½Ê½¿É´ÓAndroidÃÜÂëÖÎÀíÆ÷ÇÔȡʹ´¦
¾Ý12ÔÂ9ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÐµĹ¥»÷·½Ê½AutoSpill£¬¿ÉÔÚ×Ô¶¯Ìî³äÆÚ¼äÇÔÈ¡AndroidÉϵÄÕÊ»§Í´´¦¡£AutoSpill¹¥»÷Ô´ÓÚAndroidδÄÜÇ¿ÔìÖ´ÐлòÃ÷È·½ç˵°²È«´¦ÖÃ×Ô¶¯Ìî³äÊý¾ÝµÄÔðÈΣ¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ýй¶»ò±»Ö÷»úÀûÓ÷¨Ê½²¶»ñ¡£Ôڴ˹¥»÷³¡¾°ÖУ¬ÌṩµÇ¼±íµ¥µÄ¶ñÒâÀûÓÃÄܹ»²¶»ñÓû§µÄÍ´´¦£¬¶ø²»»áÁôÏÂÈκι¥»÷¼£Ïó¡£×êÑÐÈËÔ±ÏòÊÜÓ°ÏìÈí¼þµÄÌṩÉ̺ÍAndroidÍŶÓÅû¶ÁË·ì϶£¬ÕâЩ»ã±¨±»ÒÔΪÊÇÓÐЧµÄ£¬µ«ÉÐÎÞ¾ßÌåµÄ½¨¸´´òËã±»¹«¿ª¡£
https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/
3¡¢ALPHVÍÅ»ïµÄÍøÕ¾ÖжÏÊýÊ®Ó×ʱÒÉËÆÓë·¨ÂÉÐж¯ÓйØ
12ÔÂ8ÈÕ±¨Â·³Æ£¬ÀÕË÷ÍÅ»ïALPHVµÄÍøÕ¾ÒÑÖжÏ30¸öÓ×ʱ£¬¾Ý³ÆÓë·¨ÂÉÐж¯Óйء£ALPHVÓÃÓÚ½»ÉæºÍÊý¾Ýй¶µÄÍøÕ¾ÔÚ12ÔÂ7ÈÕºöÈ»ÎÞ·¨½Ó¼û£¬²¢ÇÒʼÖÕά³Ö¹Ø¹Ø×´Ì¬¡£ËüΨһµÄÓÃÓÚ½»ÉæµÄTor URLÒ²Òѹعأ¬ÕâÅú×¢ÀÕË÷ÍÅ»ïÃæÏò¹«¼ÒµÄ»ù´¡ÉèÊ©Ôâµ½ÈëÇÖ£¬ÔÚ½øÐеĽ»ÉæÒ²¶¼ÖÕÖ¹ÁË¡£µ±±»Îʼ°ÖжÏÇé¿öʱ£¬ALPHVÖÎÀíÔ±³ÆÕâÐ©ÍøÕ¾¿ÉÄܺܿì¾Í»á¸´ÔÉÏÏß¡£°²È«¹«Ë¾RedSense Intelй©£¬ÓÉÓÚ·¨ÂÉÐж¯£¬·þÎñÆ÷±»¹Ø¹Ø¡£
https://www.bleepingcomputer.com/news/security/alphv-ransomware-site-outage-rumored-to-be-caused-by-law-enforcement/
4¡¢Norton HealthcarÅûÂ¶Éæ¼°Ô±¹¤ºÍ»¼ÕßÐÅÏ¢µÄÊý¾Ýй¶
ýÌå12ÔÂ9Èճƣ¬Norton HealthcarÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁË»¼Õß¡¢Ô±¹¤ºÍ¾ìÊôµÄÓ×ÎÒÐÅÏ¢¡£Ð¹Â¶Ô´ÓÚ5ÔÂ9ÈÕµÄÀÕË÷¹¥»÷£¬ºó¾µ÷²éÈ·¶¨£¬¹¥»÷ÕßÔÚ5ÔÂ7ÈÕÖÁ5ÔÂ9ÈÕ½Ó¼ûÁËÄ³Ð©ÍøÂç´æ´¢É豸£¬µ«Î´½Ó¼û¸Ã»ú¹¹µÄÒ½ÁƼͼϵͳ»òNorton MyChart¡£ALPHVÔøÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬°µÊ¾ÒÑÇÔÈ¡ÆäÒ½ÁƱ£½¡ÏµÍ³ÖеÄ4.7TBÊý¾Ý£¬»¹¹«¿ªÁËÊýÊ®¸öÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£Norton Healthcare½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩΪÆÚÁ½ÄêµÄÐÅÓþ¼à¿Ø¡£
https://securityaffairs.com/155495/data-breach/norton-healthcare-ransomware-attack.html
5¡¢Unit 42°ä²¼APT28Õë¶Ô±±Ô¼¹ú¶ÈµÄÂŴι¥»÷µÄ·ÖÎö»ã±¨
12ÔÂ7ÈÕ£¬Unit 42°ä²¼ÁËAPT28Õë¶Ô±±Ô¼¹ú¶ÈµÄ¶àÂÖ¹¥»÷»î¶¯µÄ·ÖÎö¡£ÔÚ´Óǰ20¸öÔÂÖУ¬¸ÃÍÅ»ïÀûÓ÷ì϶CVE-2023-23397£¬Õë¶Ô14¸ö¹ú¶ÈµÄÖÁÉÙ30¸ö»ú¹¹·¢Õ¹ÁËÈýÂֻ¡£µÚÒ»´Î¹¥»÷²úÉúÔÚ2022Äê3ÔÂÖÁ12Ô£¬µÚ¶þÂÖ¹¥»÷²úÉúÔÚ½ñÄê3Ô¡£×î½üÒ»´Î¹¥»÷²úÉúÓÚ9ÔÂÖÁ10Ô£¬¹¥»÷ÁË7¸ö¹ú¶ÈµÄ9¸ö»ú¹¹¡£Õâ´ÎÊܹ¥»÷µÄÅ·ÖÞ¹ú¶È´ó²¿ÃŶ¼ÊDZ±Ô¼(NATO)³ÉÔ±¹ú£¬Éæ¼°¹Ø¼ü»ù´¡ÉèÊ©ºÍÔÚ±í½»¡¢¾¼ÃºÍ¾üÊÂÊÂÎñÖÐÌṩÐÅÏ¢ÓÅÊÆµÄ»ú¹¹¡£
https://unit42.paloaltonetworks.com/russian-apt-fighting-ursa-exploits-cve-2023-233397/
6¡¢TrendMicro°ä²¼¶Ô2023ÄêÍøÂ簲ȫµÄ»ØÊ׺ͷ´Ë¼»ã±¨
12ÔÂ7ÈÕ£¬Trend Micro°ä²¼Á˶Ô2023ÄêÍøÂ簲ȫÇ÷ÏòµÄ»ØÊ׺ͷ´Ë¼»ã±¨¡£»ã±¨Ö¸³ö£¬2023ÄêÌìÉúʽAIÔÚ¼ÓÇ¿ÏÖÓй¥»÷ģʽ£¨Èç´¹µö¹¥»÷£©µÄ·½Ãæ²ûÑïÁË×÷Ó㬸ø°²È«ÍŶӴøÀ´²¢½«³ÖÐø´øÀ´ÌôÕ½¡£¹¤¾ßÊæÕ¹ÒÀÈ»Êǰ²È«Ç÷Ïò£¬ÆóÒµ¾ùÔȲ¿ÊðÁË20µ½50¸ö¶ÀÁ¢µÄ°²È«½â¾ö¹æ»®£¬´æÔÚÑϳÁµÄÈßÓà¡£ÈËÀ಻ÊÇ×îÓÄ΢µÄ»·½Ú¡£ËõÓ×ÀͶ¯Á¦ºÍÆóÒµÖ®¼äµÄ¼¼Êõ²î¾à£¬ÕâÊÇØ½´ý½â¾öµÄÍøÂ簲ȫÇ÷Ïò¡£
https://www.trendmicro.com/en_us/research/23/l/2023-review-reflecting-on-cybersecurity-trends.html


¾©¹«Íø°²±¸11010802024551ºÅ