¸ßͨºÍÁª·¢¿Æ½ôÆÈÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄÎó²î5Ghoul

Ðû²¼Ê±¼ä 2023-12-11

1¡¢¸ßͨºÍÁª·¢¿Æ½ôÆÈÐÞ¸´Ó°Ïì714¿î5GÊÖ»úµÄÎó²î5Ghoul


¾ÝýÌå12ÔÂ8ÈÕ±¨µÀ £¬Ñо¿Ö°Ô±·¢Ã÷Á˸ßͨºÍÁª·¢¿Æ5Gµ÷ÖÆ½âµ÷Æ÷¹Ì¼þÖеÄ14¸öÎó²î £¬Í³³ÆÎª5Ghoul £¬Ó°ÏìÁËÊý°Ù¿îAndroidºÍiOSÊÖ»úÒÔ¼°USBºÍÎïÁªÍøµ÷ÖÆ½âµ÷Æ÷¡£5GhoulÎó²î¿É±»Ê¹ÓÃÀ´Ò»Ö±Ìᳫ¹¥»÷ £¬ÒÔ¶Ï¿ªÅþÁ¬¡¢¶³½áÅþÁ¬£¨Éæ¼°ÊÖ¶¯ÖØÆô£©»ò½«5GÅþÁ¬½µ¼¶Îª4GµÈ¡£ÏÖÒÑÈ·¶¨24¼Ò¹©Ó¦É̵Ä714¿îÖÇÄÜÊÖ»úÊܵ½¸ÃÎó²îµÄÓ°Ïì¡£ÏÖÔÚ £¬Áª·¢¿ÆºÍ¸ßͨ¾ùÒÑÐû²¼Çå¾²¸üР£¬ÒÔÐÞ¸´14¸öÎó²îÖеÄ12¸ö £¬ÁíÍâÁ½¸öÎó²îµÄ²¹¶¡Ô¤¼Æ»áÔÚδÀ´Ðû²¼¡£


https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html


2¡¢ÐÂAutoSpill¹¥»÷·½·¨¿É´ÓAndroidÃÜÂëÖÎÀíÆ÷ÇÔȡƾ֤


¾Ý12ÔÂ9ÈÕ±¨µÀ £¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÐµĹ¥»÷·½·¨AutoSpill £¬¿ÉÔÚ×Ô¶¯Ìî³äʱ´úÇÔÈ¡AndroidÉϵÄÕÊ»§Æ¾Ö¤¡£AutoSpill¹¥»÷Ô´ÓÚAndroidδÄÜÇ¿ÖÆÖ´ÐлòÃ÷È·½ç˵Çå¾²´¦Öóͷ£×Ô¶¯Ìî³äÊý¾ÝµÄÔðÈÎ £¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ýй¶»ò±»Ö÷»úÓ¦ÓóÌÐò²¶»ñ¡£Ôڴ˹¥»÷³¡¾°ÖÐ £¬ÌṩµÇ¼±íµ¥µÄ¶ñÒâÓ¦ÓÿÉÒÔ²¶»ñÓû§µÄƾ֤ £¬¶ø²»»áÁôÏÂÈκι¥»÷¼£Ïó¡£Ñо¿Ö°Ô±ÏòÊÜÓ°ÏìÈí¼þµÄÌṩÉ̺ÍAndroidÍŶÓÅû¶ÁËÎó²î £¬ÕâЩ±¨¸æ±»ÒÔΪÊÇÓÐÓõÄ £¬µ«ÉÐÎÞÏêϸµÄÐÞ¸´ÍýÏë±»¹ûÕæ¡£


https://www.bleepingcomputer.com/news/security/autospill-attack-steals-credentials-from-android-password-managers/


3¡¢ALPHVÍÅ»ïµÄÍøÕ¾ÖÐÖ¹ÊýʮСʱÒÉËÆÓëÖ´·¨Ðж¯ÓйØ


12ÔÂ8ÈÕ±¨µÀ³Æ £¬ÀÕË÷ÍÅ»ïALPHVµÄÍøÕ¾ÒÑÖÐÖ¹30¸öСʱ £¬¾Ý³ÆÓëÖ´·¨Ðж¯ÓйØ¡£ALPHVÓÃÓÚ̸ÅкÍÊý¾Ýй¶µÄÍøÕ¾ÔÚ12ÔÂ7ÈÕͻȻÎÞ·¨»á¼û £¬²¢ÇÒʼÖÕ¼á³Ö¹Ø±Õ״̬¡£ËüΨһµÄÓÃÓÚ̸ÅеÄTor URLÒ²ÒѹرÕ £¬ÕâÅú×¢ÀÕË÷ÍÅ»ïÃæÏò¹«ÖڵĻù´¡ÉèÊ©Ôâµ½ÈëÇÖ £¬ÕýÔÚ¾ÙÐеÄ̸ÅÐÒ²¶¼ÖÕÖ¹ÁË¡£µ±±»Îʼ°ÖÐÖ¹ÇéÐÎʱ £¬ALPHVÖÎÀíÔ±³ÆÕâÐ©ÍøÕ¾¿ÉÄܺܿì¾Í»á»Ö¸´ÉÏÏß¡£Çå¾²¹«Ë¾RedSense Intel͸¶ £¬ÓÉÓÚÖ´·¨Ðж¯ £¬·þÎñÆ÷±»¹Ø±Õ¡£


https://www.bleepingcomputer.com/news/security/alphv-ransomware-site-outage-rumored-to-be-caused-by-law-enforcement/


4¡¢Norton HealthcarÅûÂ¶Éæ¼°Ô±¹¤ºÍ»¼ÕßÐÅÏ¢µÄÊý¾Ýй¶


ýÌå12ÔÂ9ÈÕ³Æ £¬Norton HealthcarÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁË»¼Õß¡¢Ô±¹¤ºÍ¾ìÊôµÄСÎÒ˽¼ÒÐÅÏ¢¡£Ð¹Â¶Ô´ÓÚ5ÔÂ9ÈÕµÄÀÕË÷¹¥»÷ £¬ºó¾­ÊÓ²ìÈ·¶¨ £¬¹¥»÷ÕßÔÚ5ÔÂ7ÈÕÖÁ5ÔÂ9ÈÕ»á¼ûÁËÄ³Ð©ÍøÂç´æ´¢×°±¸ £¬µ«Î´»á¼û¸Ã»ú¹¹µÄÒ½ÁƼͼϵͳ»òNorton MyChart¡£ALPHVÔøÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ £¬ÌåÏÖÒÑÇÔÈ¡ÆäÒ½ÁƱ£½¡ÏµÍ³ÖеÄ4.7TBÊý¾Ý £¬»¹¹ûÕæÁËÊýÊ®¸öÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£Norton Healthcare½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿Ø¡£


https://securityaffairs.com/155495/data-breach/norton-healthcare-ransomware-attack.html


5¡¢Unit 42Ðû²¼APT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶à´Î¹¥»÷µÄÆÊÎö±¨¸æ


12ÔÂ7ÈÕ £¬Unit 42Ðû²¼ÁËAPT28Õë¶Ô±±Ô¼¹ú¼ÒµÄ¶àÂÖ¹¥»÷Ô˶¯µÄÆÊÎö¡£ÔÚÒÑÍù20¸öÔÂÖÐ £¬¸ÃÍÅ»ïʹÓÃÎó²îCVE-2023-23397 £¬Õë¶Ô14¸ö¹ú¼ÒµÄÖÁÉÙ30¸ö»ú¹¹¿ªÕ¹ÁËÈýÂÖÔ˶¯¡£µÚÒ»´Î¹¥»÷±¬·¢ÔÚ2022Äê3ÔÂÖÁ12Ô £¬µÚ¶þÂÖ¹¥»÷±¬·¢ÔÚ½ñÄê3Ô¡£×î½üÒ»´Î¹¥»÷±¬·¢ÓÚ9ÔÂÖÁ10Ô £¬¹¥»÷ÁË7¸ö¹ú¼ÒµÄ9¸ö»ú¹¹¡£´Ë´ÎÊܹ¥»÷µÄÅ·ÖÞ¹ú¼Ò´ó²¿·Ö¶¼ÊDZ±Ô¼(NATO)³ÉÔ±¹ú £¬Éæ¼°Òªº¦»ù´¡ÉèÊ©ºÍÔÚÍâ½»¡¢¾­¼ÃºÍ¾üÊÂÊÂÎñÖÐÌṩÐÅÏ¢ÓÅÊÆµÄ»ú¹¹¡£


https://unit42.paloaltonetworks.com/russian-apt-fighting-ursa-exploits-cve-2023-233397/


6¡¢TrendMicroÐû²¼¶Ô2023ÄêÍøÂçÇå¾²µÄ»ØÊ׺ͷ´Ë¼±¨¸æ


12ÔÂ7ÈÕ £¬Trend MicroÐû²¼Á˶Ô2023ÄêÍøÂçÇå¾²Ç÷ÊÆµÄ»ØÊ׺ͷ´Ë¼±¨¸æ¡£±¨¸æÖ¸³ö £¬2023ÄêÌìÉúʽAIÔÚÔöÇ¿ÏÖÓй¥»÷ģʽ£¨Èç´¹ÂÚ¹¥»÷£©µÄ·½ÃæÊ©Õ¹ÁË×÷Óà £¬¸øÇå¾²ÍŶӴøÀ´²¢½«¼ÌÐø´øÀ´ÌôÕ½¡£¹¤¾ßÉìÕÅÈÔÈ»ÊÇÇå¾²Ç÷ÊÆ £¬Æóҵƽ¾ù°²ÅÅÁË20µ½50¸ö×ÔÁ¦µÄÇå¾²½â¾ö¼Æ»® £¬±£´æÑÏÖØµÄÈßÓà¡£ÈËÀ಻ÊÇ×ÈõµÄ»·½Ú¡£ËõСÀͶ¯Á¦ºÍÆóÒµÖ®¼äµÄÊÖÒÕ²î±ð £¬ÕâÊÇØ½´ý½â¾öµÄÍøÂçÇå¾²Ç÷ÊÆ¡£


https://www.trendmicro.com/en_us/research/23/l/2023-review-reflecting-on-cybersecurity-trends.html