µÂ¹ú¶à¼ÒÒ½ÔºÊÜLockbitµÄÓ°Ï첿·Ö»¼Õß±»ÆÈ½ôÆÈ×ªÒÆ

Ðû²¼Ê±¼ä 2023-12-29
1¡¢µÂ¹ú¶à¼ÒÒ½ÔºÊÜLockbitµÄÓ°Ï첿·Ö»¼Õß±»ÆÈ½ôÆÈ×ªÒÆ


¾ÝýÌå12ÔÂ27ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬µÂ¹úKatholische Hospitalvereinigung Ostwestfalen(KHO)ºÏÉí·Ý²»Ã÷µÄ¹¥»÷Õß»á¼ûÁËÒ½ÔºµÄIT»ù´¡ÉèÊ©²¢¼ÓÃÜÁËÊý¾Ý¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÓÚ12ÔÂ24ÈÕÆÆÏþ£¬£¬ £¬£¬£¬£¬ÆðÔ´²âÊÔÅú×¢£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÊÇLockbit 3.0µÄ¹¥»÷£¬£¬ £¬£¬£¬£¬ÏÖÔÚÎÞ·¨Ô¤¼Æ»Ö¸´Ê±¼ä¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËKHOÔËÓªµÄÈý¼ÒÒ½ÔºFranziskus Hospital Bielefeld¡¢Sankt Vinzenz Hospital Rheda-Wiedenbr¨¹ckºÍMathilden Hospital Herford£¬£¬ £¬£¬£¬£¬ËüÃÇÎÞ·¨Ìṩ¼±ÕïЧÀÍ£¬£¬ £¬£¬£¬£¬Òò´Ë¼±ÐèÒ½ÁÆÐ§À͵ϼÕß±»ÆÈ×ªÒÆµ½ÆäËüµØ·½¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-disrupts-emergency-care-at-german-hospitals/


2¡¢Eagers AutomotiveÔâµ½¹¥»÷ËùÓÐÉúÒâÓªÒµÔÝʱ×èÖ¹


¾Ý12ÔÂ28ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬Eagers AutomotiveÔâµ½ÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬±»ÆÈ×èÖ¹ÁËÔÚ֤ȯÉúÒâËùµÄÉúÒ⣬£¬ £¬£¬£¬£¬ÒÔÆÀ¹À´Ë´ÎÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£ÕâÊǰĴóÀûÑǺÍÐÂÎ÷À¼×î´óµÄÆû³µ¾­ÏúÉÌ£¬£¬ £¬£¬£¬£¬2023ÄêÉϰëÄêµÄÊÕÈëΪ48.2ÒÚ°ÄÔª£¨32.5ÒÚÃÀÔª£©¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ12ÔÂ27ÈÕÐû²¼×èÖ¹ËùÓÐÉúÒâÓªÒµ£¬£¬ £¬£¬£¬£¬²¢ÔÚ28ÈÕµÄͨ¸æÖÐÖ¸³ö¸ÃÊÂÎñÓ°ÏìÁ˰ĴóÀûÑǺÍÐÂÎ÷À¼µÄ¶à¸öϵͳ£¬£¬ £¬£¬£¬£¬µ«ÍøÂçÊÂÎñµÄËùÓйæÄ£ÉÐÎÞ·¨È·¶¨¡£¡£¡£¡£¡£¡£ÏÖÔÚÈÔûÓй¥»÷ÍÅ»ïÌåÏÖ¶Ô´Ë´ÎÊÂÎñÈÏÕæ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/eagers-automotive-halts-trading-in-response-to-cyberattack/


3¡¢Yakult Australia±»DragonForce¹¥»÷95 GBÊý¾Ýй¶


12ÔÂ27ÈÕ±¨µÀ³Æ£¬£¬ £¬£¬£¬£¬ÒûÆ·¹«Ë¾Yakult Australia͸¶ÆäÔâµ½¹¥»÷£¬£¬ £¬£¬£¬£¬Î»ÓÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳ¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ12ÔÂ15ÈÕÔçÉÏÒâʶµ½Á˹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬ÏÖÔÚ»¹ÎÞ·¨È·ÈÏÊÂÎñµÄÑÏÖØË®Æ½¡£¡£¡£¡£¡£¡£Ö»¹ÜÆä°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳÊܵ½¹¥»÷£¬£¬ £¬£¬£¬£¬µ«ÕâÁ½¸öµØÇøµÄЧÀÍ´¦ÈÔ¼á³Ö¿ª·ÅºÍÕý³£ÔËÓª¡£¡£¡£¡£¡£¡£DragonForceÓÚ12ÔÂ20ÈÕÔÚÆäÍøÕ¾ÁгöÁËYakult Australia£¬£¬ £¬£¬£¬£¬²¢Ð¹Â¶ÁË95.19 GBµÄÊý¾Ý£¬£¬ £¬£¬£¬£¬°üÀ¨¹«Ë¾Êý¾Ý¿â¡¢ÌõÔ¼ºÍ»¤Õյȡ£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/yakult-australia-confirms-cyber-incident-after-95-gb-data-leak/


4¡¢AndroidºóÃÅXamaliciousÒÑѬȾÁè¼Ý30Íǫ̀װ±¸


ýÌå12ÔÂ27Èճƣ¬£¬ £¬£¬£¬£¬McAfee·¢Ã÷ÁËÒ»ÖÖеÄAndroidºóÃÅ£¬£¬ £¬£¬£¬£¬Í¨¹ýGoogle PlayÉϵĶñÒâÓ¦ÓÃѬȾÁËÁè¼Ý30Íǫ̀װ±¸¡£¡£¡£¡£¡£¡£Xamalicious»ùÓÚ.NET£¬£¬ £¬£¬£¬£¬Ç¶ÈëÔÚʹÓÿªÔ´Xamarin¿ò¼Ü¿ª·¢µÄÓ¦ÓÃÖУ¨ÒÔ¡°Core.dll¡±ºÍ¡°GoogleService.dll¡±µÄÐÎʽ£©£¬£¬ £¬£¬£¬£¬ÕâʹµÃ´úÂëÆÊÎö¸ü¾ßÌôÕ½ÐÔ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÑ·¢Ã÷25¸ö±£´æ´ËÀàÍþвµÄÓ¦Ó㬣¬ £¬£¬£¬£¬Ò£²âÊý¾ÝÏÔʾ´ó´ó¶¼Ñ¬È¾Î»ÓÚÃÀ¹ú¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍ°Ä´óÀûÑǵȹú¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/12/new-sneaky-xamalicious-android-malware.html


5¡¢KasperskyÅû¶Èý½ÇÕÉÁ¿¹¥»÷ʹÓõÄÎó²îºÍÊÖÒÕÏêÇé


12ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬KasperskyÅû¶ÁËÕë¶ÔiPhoneµÄÈý½ÇÕÉÁ¿¹¥»÷ʹÓõÄÎó²îºÍÊÖÒÕÏêÇé¡£¡£¡£¡£¡£¡£Õû¸ö¹¥»÷Á´ÊÇÁãµã»÷µÄ£¬£¬ £¬£¬£¬£¬ÕâÒâζ×ÅËü²»ÐèÒªÓû§½»»¥£¬£¬ £¬£¬£¬£¬Ò²²»»áÌìÉúÈκÎÏÔ×ŵĺۼ£¡£¡£¡£¡£¡£¡£¹¥»÷¹²Ê¹ÓÃÁË4¸öÎó²î£ºADJUST TrueType×ÖÌåÖ¸ÁîÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-41990£©¡¢XNUÄÚ´æÓ³ÉäϵͳŲÓÃÖеÄÕûÊýÒç³öÎó²î£¨CVE-2023-32434£©¡¢ÔÚSafariÎó²îʹÓÃÖÐÓÃÓÚÖ´ÐÐshellcodeµÄÎó²î£¨CVE-2023-32435£©ÒÔ¼°Ê¹ÓÃÓ²¼þMMIO¼Ä´æÆ÷ÈÆ¹ýÒ³Ãæ±£»£»£»£»¤²ã(PPL)µÄÎó²î£¨CVE-2023-38606£©¡£¡£¡£¡£¡£¡£


https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/


6¡¢AhnlabÐû²¼KimsukyʹÓÃAppleSeed¹¥»÷µÄÆÊÎö±¨¸æ


12ÔÂ28ÈÕ£¬£¬ £¬£¬£¬£¬AhnlabÐû²¼Á˹ØÓÚKimsukyÍÅ»ïʹÓÃAppleSeed¾ÙÐй¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Ê¹ÓÃAppleSeedµÄ¹¥»÷ÒѾ­±£´æÁËÐí¶àÄ꣬£¬ £¬£¬£¬£¬¸Ã±¨¸æÏÈÈÝÁ˽üÆÚ¹¥»÷°¸ÀýÖÐʹÓõĶñÒâÈí¼þµÄÌØµã£¬£¬ £¬£¬£¬£¬²¢ÓëÒÑÍùµÄ¾ÙÐбÈÕÕ¡£¡£¡£¡£¡£¡£ËäÈ»ÏÖÔÚÈÔÔÚʹÓÃÏàͬµÄAppleSeed£¬£¬ £¬£¬£¬£¬µ«»á¼ì²é²ÎÊýÀ´×ÌÈÅÆÊÎö£¬£¬ £¬£¬£¬£¬²¢ÇÒʹÓÃÃûΪAlphaSeeµÄAppleSeed±äÌå¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ËäÈ»ÒÑÍù¸ÃÍÅ»ïͨ³£ÔÚ×°ÖÃAppleSeedºóʹÓÃRDPÀ´¿ØÖƱ»Ñ¬È¾µÄϵͳ£¬£¬ £¬£¬£¬£¬µ«ÔÚ×î½üµÄ°¸ÀýÖУ¬£¬ £¬£¬£¬£¬ËûÃÇÒ²×°ÖÃÁËChrome Remote Desktop¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/60054/