΢Èí°ä²¼12Ô·ݰ²È«¸üн¨¸´ÒÑÅû¶µÄAMD·ì϶
°ä²¼¹¦·ò 2023-12-13΢ÈíÔÚ12ÔÂ12ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬½¨¸´Á˶à¸öÑϳÁµÄ·ì϶¡£Õâ´Î¸üн¨¸´ÁË8Ô·ÝÅû¶µÄÒ»¸öAMD´§Ä¦Ö´Ðзì϶£¨CVE-2023-20588£©£¬ÕâÊÇÌØ¶¨AMD´¦ÖÃÆ÷ÖеÄÒ»¸ödivision-by-zero·ì϶£¬¿ÉÄܻ᷵»ØÃô¸ÐÊý¾Ý¡£´Ë±í£¬»¹½¨¸´Á˶à¸öÑϳÁµÄ·ì϶£¬Ô̺¬Microsoft Power PlatformÏÎ½ÓÆ÷ºýŪ·ì϶£¨CVE-2023-36019£©¡¢ICSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-35630ºÍCVE-2023-35641£©ÒÔ¼°Windows MSHTMLƽ̨Զ³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-35628£©¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/
2¡¢Apple°ä²¼¸üн¨¸´iOSºÍmacOSµÈ²úÆ·µÄ¶à¸ö·ì϶
¾ÝýÌå12ÔÂ12ÈÕ±¨Â·£¬Apple°ä²¼ÁËÕë¶ÔiOS¡¢iPadOS¡¢macOS¡¢tvOS¡¢watchOSºÍSafariä¯ÀÀÆ÷µÄ°²È«²¹¶¡¡£ÆäÖÐÖµÍ×ÌùÐĵÄÊÇmacOS SonomaÖеķì϶£¨CVE-2023-45866£©£¬¹¥»÷ÕßÄܹ»Í¨¹ýºýŪ¼üÅÌÀ´×¢Èë¡£´Ë±í£¬Apple»¹½¨¸´Á˾ɰæiOS 16.7.3ºÍiPadOS 16.7.3ÖеĶà¸ö·ì϶£¬Ô̺¬WebKitÒýÇæÖÐÁ½¸öÒѱ»ÀûÓõķì϶£¨CVE-2023-42916ºÍCVE-2023-42917£©¡£
https://thehackernews.com/2023/12/apple-releases-security-updates-to.html
3¡¢Americold¹«Ë¾Ôâµ½Cactus¹¥»÷й¶½ü13ÍòÈËÐÅÏ¢
¾Ý12ÔÂ12ÈÕ±¨Â·£¬ÃÀ¹úοزִ¢ºÍÔËÊ乫˾Americold³Æ£¬4Ô·ݵĹ¥»÷µ¼ÖÂÆä½ü13ÍòÃûÔ±¹¤¼°¾ìÊôµÄÐÅϢй¶¡£¹¥»÷²úÉúÓÚ4ÔÂ26ÈÕ£¬µ¼ÖÂϵͳÖжϣ¬Ó°ÏìÁ˹«Ë¾µÄÕý³£ÔËÓª¡£ÀÕË÷ÍÅ»ïCactusÓÚ7ÔÂ21ÈÕÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬»¹Ð¹Â¶Á˸ù«Ë¾6 GB¹ÜÕʺͲÆÕþÎļþµµ°¸£¬ÆäÖÐÔ̺¬¸öÈ˺ͻúÃÜÐÅÏ¢¡£Americoldƾ¾Ý11ÔÂ8ÈÕ½øÐв¢×îÖÕʵÏֵķÖÎöÈ·¶¨ÁËÊý¾Ýй¶ÁìÓò£¬²¢ÓÚ12ÔÂ8ÈÕÏòÊܵ½Ó°ÏìµÄ129611ÃûÔ±¹¤¼°Æä¾ìÊô·¢ËÍÁË֪ͨ¡£
https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-discloses-data-breach-after-april-malware-attack/
4¡¢CiscoÅû¶LazarusÀûÓÃLog4Shell·Ö·¢ÐÂRATµÄ»î¶¯
Cisco TalosÔÚ12ÔÂ11ÈÕÅû¶ÁËLazarus GroupµÄÒ»Ïîл£¬±»³ÆÎª¡°Operation Blacksmith¡±¡£¸Ã»î¶¯Ê¼ÓÚ½ñÄê3ÔÂ×óÓÒ£¬Õë¶ÔÈ«ÇòÔì×÷¡¢Å©ÒµºÍÎïÀí°²È«¹«Ë¾¡£Lazarus³ÖÐøÀûÓÃCVE-2021-44228£¨±ðÃûLog4Shell£©£¬·Ö·¢ÁË3¸öÓÃDLang¿ª·¢µÄжñÒâÈí¼þ¡£Ð¶ñÒâÈí¼þÊÇÁ½¸öÔ¶³Ì½Ó¼ûľÂíNineRATºÍDLRAT£¬ÒÔ¼°Ò»¸ö¶ñÒâÈí¼þÏÂÔØ·¨Ê½BottomLoader¡£ÆäÖУ¬NineRATʹÓÃTelegram API½øÐÐC2ͨѶ¡£
https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/
5¡¢SentinelOne°ä²¼¹ØÓÚSandman APTµÄ·ÖÎö»ã±¨
12ÔÂ11ÈÕ£¬SentinelOne°ä²¼Á˹ØÓÚSandman APT¹éÒòµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Sandman APTºÜ¿ÉÄÜÓëʹÓÃKEYPLUGºóÃŵÄÍÅ»ïÓйأ¬³ö¸ñÊÇ΢ÈíºÍPwC×·×ÙΪSTORM-0866/Red Dev 40µÄÍŻ¾Ý¹Û²ì£¬SandmanÍÅ»ï»ùÓÚLuaµÄ¶ñÒâÈí¼þLuaDreamºÍKEYPLUGºóÃÅ´æÔÚÓÚͳһ±»¹¥»÷»·¾³ÖС£´Ë±í£¬SandmanºÍSTORM-0866/Red Dev 40ÓÐÒ»ÑùµÄ»ù´¡ÉèÊ©½ÚÔìºÍÖÎÀí·½Ê½£¬Ô̺¬ÍйÜÌṩÉ̵ÄÑ¡ÔñºÍÓòÃû¶¨Ãû¹æ¶¨¡£
https://www.sentinelone.com/labs/sandman-apt-china-based-adversaries-embrace-lua/
6¡¢Kaspersky°ä²¼ÈËΪÖÇÄܶÔÍøÂ簲ȫµÄÓ°ÏìµÄ»ã±¨
12ÔÂ11ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚÈËΪÖÇÄܶÔÍøÂ簲ȫµÄÓ°ÏìµÄÄê¶È·ÖÎö»ã±¨¡£ÈËΪÖÇÄÜ´øÀ´»úÔµµÄͬʱҲ´øÀ´ÁËеķçÏÕ£¬Ô̺¬ÐÅÀµºÍ¿¿µÃסÐÔµÄÎÊÌ⡢רÓÐÔÆ·þÎñµÄ·çÏÕ¡¢Õë¶Ô´óÐÍ˵»°Ä£ÐÍ£¨LLM£©µÄ·ì϶¡¢¿ÉÄܱ»ÍøÂç¹¥»÷ÕßÀûÓõķçÏÕÒÔ¼°Éî¶ÈαÔì±»ÓÃÓÚ¸÷ÀàȦÌס£µ«ÊÇÌìÉúʽÈËΪÖÇÄÜÒ²»á¼ÓÇ¿·ÀÓùÁ¦Á¿£¬ÀýÈçÌìÉúʽÈËΪÖÇÄÜ(GenAI)¸³ÄÜ·ÀÓùÈËÔ±µÈ¡£¶Ô2024ÄêµÄÔ¤²âÔ̺¬¿ÉÄÜ»á³öÏÖ¸ü¸´Ôӵķì϶£¬ÒÔ¼°Éñ¾ÍøÂ罫ԽÀ´Ô½¶àµØÓÃÓÚÌìÉúÚ¿ÆÊÓ¾õ³ÉЧµÈ¡£
https://securelist.com/story-of-the-year-2023-ai-impact-on-cybersecurity/111341/


¾©¹«Íø°²±¸11010802024551ºÅ