µÂ¹ú¶à¼ÒÒ½ÔºÊÜLockbitµÄÓ°Ï첿ÃÅ»¼Õß±»ÆÈ´¹Î£×ªÒÆ

°ä²¼¹¦·ò 2023-12-29
1¡¢µÂ¹ú¶à¼ÒÒ½ÔºÊÜLockbitµÄÓ°Ï첿ÃÅ»¼Õß±»ÆÈ´¹Î£×ªÒÆ


¾ÝýÌå12ÔÂ27ÈÕ±¨Â· £¬µÂ¹úKatholische Hospitalvereinigung Ostwestfalen(KHO)³ÆÉí·Ý²»Ã÷µÄ¹¥»÷Õß½Ó¼ûÁËÒ½ÔºµÄIT»ù´¡ÉèÊ©²¢¼ÓÃÜÁËÊý¾Ý  ¡£¹¥»÷²úÉúÓÚ12ÔÂ24ÈÕÁ賿 £¬³õ²½²âÊÔÅú×¢ £¬Õâ¿ÉÄÜÊÇLockbit 3.0µÄ¹¥»÷ £¬Ä¿Ç°ÎÞ·¨¹À¼Æ¸´Ô­¹¦·ò  ¡£¸ÃÊÂÎñÓ°ÏìÁËKHOÔËÓªµÄÈý¼ÒÒ½ÔºFranziskus Hospital Bielefeld¡¢Sankt Vinzenz Hospital Rheda-Wiedenbr¨¹ckºÍMathilden Hospital Herford £¬ËüÃÇÎÞ·¨Ìṩ¼¹Øï·þÎñ £¬Òò¶ø¼±ÐèÒ½ÁÆ·þÎñµÄ»¼Õß±»ÆÈ×ªÒÆµ½ÆäËü´¦Ëù  ¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-disrupts-emergency-care-at-german-hospitals/


2¡¢Eagers AutomotiveÔâµ½¹¥»÷ËùÓÐÂòÂôÒµÎñÁÙʱÖÕ³¡


¾Ý12ÔÂ28ÈÕ±¨Â· £¬Eagers AutomotiveÔâµ½ÍøÂç¹¥»÷ £¬±»ÆÈÖÕ³¡ÁËÔÚ֤ȯÂòÂôËùµÄÂòÂô £¬ÒÔÆÀ¹ÀÕâ´ÎÊÂÎñµÄÓ°Ïì  ¡£ÕâÊǰĴóÀûÑǺÍÐÂÎ÷À¼×î´óµÄÆû³µ¾­ÏúÉÌ £¬2023ÄêÉϰëÄêµÄÊÕÈëΪ48.2ÒÚ°ÄÔª£¨32.5ÒÚÃÀÔª£©  ¡£¸Ã¹«Ë¾ÓÚ12ÔÂ27ÈÕ°ä·¢ÖÕ³¡ËùÓÐÂòÂôÒµÎñ £¬²¢ÔÚ28ÈյIJ¼¸æÖÐÖ¸³ö¸ÃÊÂÎñÓ°ÏìÁ˰ĴóÀûÑǺÍÐÂÎ÷À¼µÄ¶à¸öϵͳ £¬µ«ÍøÂçÊÂÎñµÄÈ«ÊýÁìÓòÉÐÎÞ·¨È·¶¨  ¡£´Ë¿ÌÈÔûÓй¥»÷ÍŻﰵʾ¶ÔÕâ´ÎÊÂÎñÕÆ¹Ü  ¡£


https://www.bleepingcomputer.com/news/security/eagers-automotive-halts-trading-in-response-to-cyberattack/


3¡¢Yakult Australia±»DragonForce¹¥»÷95 GBÊý¾Ýй¶


12ÔÂ27ÈÕ±¨Â·³Æ £¬ÒûÆ·¹«Ë¾Yakult Australiaй©ÆäÔâµ½¹¥»÷ £¬Î»ÓÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳ¾ùÊܵ½Ó°Ïì  ¡£¸Ã¹«Ë¾ÔÚ12ÔÂ15ÈÕÔçÉÏÒâʶµ½Á˹¥»÷»î¶¯ £¬Ä¿Ç°»¹ÎÞ·¨È·ÈÏÊÂÎñµÄÑϳÁˮƽ  ¡£Ö»¹ÜÆä°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳÊܵ½¹¥»÷ £¬µ«ÕâÁ½¸öµØÓòµÄ´¦Ê´¦ÈÔά³ÖÊ¢¿ªºÍÕý³£ÔËÓª  ¡£DragonForceÓÚ12ÔÂ20ÈÕÔÚÆäÍøÕ¾ÁгöÁËYakult Australia £¬²¢Ð¹Â¶ÁË95.19 GBµÄÊý¾Ý £¬Ô̺¬¹«Ë¾Êý¾Ý¿â¡¢ºÏͬºÍ»¤ÕÕµÈ  ¡£


https://www.bleepingcomputer.com/news/security/yakult-australia-confirms-cyber-incident-after-95-gb-data-leak/


4¡¢AndroidºóÃÅXamaliciousÒÑϰȾ³¬¹ý30Íǫ̀É豸


ýÌå12ÔÂ27ÈÕ³Æ £¬McAfee·¢ÏÖÁËÒ»ÖÖеÄAndroidºóÃÅ £¬Í¨¹ýGoogle PlayÉϵĶñÒâÀûÓÃϰȾÁ˳¬¹ý30Íǫ̀É豸  ¡£Xamalicious»ùÓÚ.NET £¬Ç¶ÈëÔÚʹÓÿªÔ´Xamarin¿ò¼Ü¿ª·¢µÄÀûÓÃÖУ¨ÒÔ¡°Core.dll¡±ºÍ¡°GoogleService.dll¡±µÄ´ó¾Ö£© £¬ÕâʹµÃ´úÂë·ÖÎö¸ü¾ßÌôÕ½ÐÔ  ¡£×êÑÐÈËÔ±ÒÑ·¢ÏÖ25¸ö´æÔÚ´ËÀàÍþвµÄÀûÓà £¬Ò£²âÊý¾ÝÏÔʾ´óÎÞÊýϰȾλÓÚÃÀ¹ú¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍ°Ä´óÀûÑǵȹú  ¡£


https://thehackernews.com/2023/12/new-sneaky-xamalicious-android-malware.html


5¡¢KasperskyÅû¶Èý½ÇÕÉÁ¿¹¥»÷ʹÓõķì϶ºÍ¼¼ÊõÏêÇé


12ÔÂ27ÈÕ £¬KasperskyÅû¶ÁËÕë¶ÔiPhoneµÄÈý½ÇÕÉÁ¿¹¥»÷ʹÓõķì϶ºÍ¼¼ÊõÏêÇé  ¡£Õû¸ö¹¥»÷Á´ÊÇÁãµã»÷µÄ £¬ÕâÒâζ×ÅËü²»±ØÒªÓû§½»»¥ £¬Ò²²»»áÌìÉúÈκÎÏÔÖøµÄºÛ¼£  ¡£¹¥»÷¹²ÀûÓÃÁË4¸ö·ì϶£ºADJUST TrueType×ÖÌåÖ¸ÁîÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-41990£©¡¢XNUÄÚ´æÓ³ÉäϵͳŲÓÃÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2023-32434£©¡¢ÔÚSafari·ì϶ÀûÓÃÖÐÓÃÓÚÖ´ÐÐshellcodeµÄ·ì϶£¨CVE-2023-32435£©ÒÔ¼°ÀûÓÃÓ²¼þMMIO¼Ä·ÅÆ÷ÈÆ¹ýÒ³Ãæ±£»¤²ã(PPL)µÄ·ì϶£¨CVE-2023-38606£©  ¡£


https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/


6¡¢Ahnlab°ä²¼KimsukyÀûÓÃAppleSeed¹¥»÷µÄ·ÖÎö»ã±¨


12ÔÂ28ÈÕ £¬Ahnlab°ä²¼Á˹ØÓÚKimsukyÍÅ»ïÀûÓÃAppleSeed½øÐй¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨  ¡£ÀûÓÃAppleSeedµÄ¹¥»÷ÒѾ­´æÔÚÁ˺öàÄê £¬¸Ã»ã±¨½éÉÜÁ˽üÆÚ¹¥»÷°¸ÀýÖÐʹÓõĶñÒâÈí¼þµÄÌØµã £¬²¢Óë´ÓǰµÄ½øÐжԱÈ  ¡£¹ÌÈ»´Ë¿ÌÈÔÔÚʹÓÃÒ»ÑùµÄAppleSeed £¬µ«»á²é³­²ÎÊýÀ´×ÌÈÅ·ÖÎö £¬²¢ÇÒʹÓÃÃûΪAlphaSeeµÄAppleSeed±äÌå  ¡£´Ë±í £¬¹ÌÈ»´Óǰ¸ÃÍÅ»ïͨ³£ÔÚ×°ÖÃAppleSeedºóʹÓÃRDPÀ´½ÚÔ챻ϰȾµÄϵͳ £¬µ«ÔÚ×î½üµÄ°¸ÀýÖÐ £¬ËûÃÇÒ²×°ÖÃÁËChrome Remote Desktop  ¡£


https://asec.ahnlab.com/en/60054/