µÂ¹ú¶à¼ÒÒ½ÔºÊÜLockbitµÄÓ°Ï첿ÃÅ»¼Õß±»ÆȽô¼±×ªÒÆ
Ðû²¼Ê±¼ä 2023-12-29¾ÝýÌå12ÔÂ27ÈÕ±¨µÀ£¬µÂ¹úKatholische Hospitalvereinigung Ostwestfalen(KHO)³ÆÉí·Ý²»Ã÷µÄ¹¥»÷Õß·ÃÎÊÁËÒ½ÔºµÄIT»ù´¡ÉèÊ©²¢¼ÓÃÜÁËÊý¾Ý¡£¹¥»÷·¢ÉúÓÚ12ÔÂ24ÈÕÁ賿£¬¿ª¶Ë²âÊÔ±íÃ÷£¬Õâ¿ÉÄÜÊÇLockbit 3.0µÄ¹¥»÷£¬Ä¿Ç°ÎÞ·¨Ô¤¼Æ»Ö¸´Ê±¼ä¡£¸ÃʼþÓ°ÏìÁËKHOÔËÓªµÄÈý¼ÒÒ½ÔºFranziskus Hospital Bielefeld¡¢Sankt Vinzenz Hospital Rheda-Wiedenbr¨¹ckºÍMathilden Hospital Herford£¬ËüÃÇÎÞ·¨Ìṩ¼±Õï·þÎñ£¬Òò´Ë¼±ÐèÒ½ÁÆ·þÎñµÄ»¼Õß±»ÆÈתÒƵ½ÆäËüµØ·½¡£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-disrupts-emergency-care-at-german-hospitals/
2¡¢Eagers AutomotiveÔâµ½¹¥»÷ËùÓн»Ò×ÒµÎñÔÝʱֹͣ
¾Ý12ÔÂ28ÈÕ±¨µÀ£¬Eagers AutomotiveÔâµ½ÍøÂç¹¥»÷£¬±»ÆÈÍ£Ö¹ÁËÔÚ֤ȯ½»Ò×ËùµÄ½»Ò×£¬ÒÔÆÀ¹À´Ë´ÎʼþµÄÓ°Ïì¡£ÕâÊÇ°Ä´óÀûÑǺÍÐÂÎ÷À¼×î´óµÄÆû³µ¾ÏúÉÌ£¬2023ÄêÉÏ°ëÄêµÄÊÕÈëΪ48.2ÒÚ°ÄÔª£¨32.5ÒÚÃÀÔª£©¡£¸Ã¹«Ë¾ÓÚ12ÔÂ27ÈÕÐû²¼Í£Ö¹ËùÓн»Ò×ÒµÎñ£¬²¢ÔÚ28ÈÕµÄͨ¸æÖÐÖ¸³ö¸ÃʼþÓ°ÏìÁË°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄ¶à¸öϵͳ£¬µ«ÍøÂçʼþµÄÈ«²¿·¶Î§ÉÐÎÞ·¨È·¶¨¡£ÏÖÔÚÈÔûÓй¥»÷ÍÅ»ïÌåÏÖ¶Ô´Ë´ÎʼþÂôÁ¦¡£
https://www.bleepingcomputer.com/news/security/eagers-automotive-halts-trading-in-response-to-cyberattack/
3¡¢Yakult Australia±»DragonForce¹¥»÷95 GBÊý¾Ýй¶
12ÔÂ27ÈÕ±¨µÀ³Æ£¬ÒûÆ·¹«Ë¾Yakult Australia͸¶ÆäÔâµ½¹¥»÷£¬Î»ÓÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳ¾ùÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾ÔÚ12ÔÂ15ÈÕÔçÉÏÒâʶµ½Á˹¥»÷»î¶¯£¬Ä¿Ç°»¹ÎÞ·¨È·ÈÏʼþµÄÑÏÖØˮƽ¡£¾¡¹ÜÆä°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄϵͳÊܵ½¹¥»÷£¬µ«ÕâÁ½¸öµØÓòµÄ·þÎñ´¦ÈÔ±£³Ö¿ª·ÅºÍÕý³£ÔËÓª¡£DragonForceÓÚ12ÔÂ20ÈÕÔÚÆäÍøÕ¾ÁгöÁËYakult Australia£¬²¢Ð¹Â¶ÁË95.19 GBµÄÊý¾Ý£¬°üÂÞ¹«Ë¾Êý¾Ý¿â¡¢ºÏͬºÍ»¤Õյȡ£
https://www.bleepingcomputer.com/news/security/yakult-australia-confirms-cyber-incident-after-95-gb-data-leak/
4¡¢AndroidºóÃÅXamaliciousÒÑѬȾÁè¼Ý30Íǫ̀É豸
ýÌå12ÔÂ27Èճƣ¬McAfee·¢ÏÖÁËÒ»ÖÖеÄAndroidºóÃÅ£¬Í¨¹ýGoogle PlayÉϵĶñÒâÓ¦ÓÃѬȾÁËÁè¼Ý30Íǫ̀É豸¡£Xamalicious»ùÓÚ.NET£¬Ç¶ÈëÔÚʹÓÿªÔ´Xamarin¿ò¼Ü¿ª·¢µÄÓ¦ÓÃÖУ¨ÒÔ¡°Core.dll¡±ºÍ¡°GoogleService.dll¡±µÄÐÎʽ£©£¬ÕâʹµÃ´úÂë·ÖÎö¸ü¾ßÌôÕ½ÐÔ¡£Ñо¿ÈËÔ±ÒÑ·¢ÏÖ25¸ö´æÔÚ´ËÀàÍþвµÄÓ¦Óã¬Ò£²âÊý¾ÝÏÔʾ´ó¶àÊýѬȾλÓÚÃÀ¹ú¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍ°Ä´óÀûÑǵȹú¡£
https://thehackernews.com/2023/12/new-sneaky-xamalicious-android-malware.html
5¡¢KasperskyÅû¶Èý½ÇÕÉÁ¿¹¥»÷ʹÓõÄ©¶´ºÍ¼¼ÊõÏêÇé
12ÔÂ27ÈÕ£¬KasperskyÅû¶ÁËÕë¶ÔiPhoneµÄÈý½ÇÕÉÁ¿¹¥»÷ʹÓõÄ©¶´ºÍ¼¼ÊõÏêÇé¡£Õû¸ö¹¥»÷Á´ÊÇÁãµã»÷µÄ£¬ÕâÒâζ×ÅËü²»ÐèÒªÓû§½»»¥£¬Ò²²»»áÉú³ÉÈκÎÃ÷ÏԵĺۼ£¡£¹¥»÷¹²ÀûÓÃÁË4¸ö©¶´£ºADJUST TrueType×ÖÌåÖ¸ÁîÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-41990£©¡¢XNUÄÚ´æÓ³Éäϵͳµ÷ÓÃÖеÄÕûÊýÒç³ö©¶´£¨CVE-2023-32434£©¡¢ÔÚSafari©¶´ÀûÓÃÖÐÓÃÓÚÖ´ÐÐshellcodeµÄ©¶´£¨CVE-2023-32435£©ÒÔ¼°ÀûÓÃÓ²¼þMMIO¼Ä´æÆ÷ÈƹýÒ³Ãæ±£»¤²ã(PPL)µÄ©¶´£¨CVE-2023-38606£©¡£
https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/
6¡¢AhnlabÐû²¼KimsukyÀûÓÃAppleSeed¹¥»÷µÄ·ÖÎö³ÂËß
12ÔÂ28ÈÕ£¬AhnlabÐû²¼Á˹ØÓÚKimsukyÍÅ»ïÀûÓÃAppleSeed½øÐй¥»÷µÄÇ÷ÊÆ·ÖÎö³ÂËß¡£ÀûÓÃAppleSeedµÄ¹¥»÷ÒѾ´æÔÚÁ˺ܶàÄ꣬¸Ã³ÂËß½éÉÜÁ˽üÆÚ¹¥»÷°¸ÀýÖÐʹÓõĶñÒâÈí¼þµÄÌص㣬²¢Óë¹ýÈ¥µÄ½øÐжԱȡ£ËäÈ»ÏÖÔÚÈÔÔÚʹÓÃÏàͬµÄAppleSeed£¬µ«»á¼ì²é²ÎÊýÀ´×ÌÈÅ·ÖÎö£¬¶øÇÒʹÓÃÃûΪAlphaSeeµÄAppleSeed±äÌå¡£´ËÍ⣬ËäÈ»¹ýÈ¥¸ÃÍÅ»ïͨ³£ÔÚ°²×°AppleSeedºóʹÓÃRDPÀ´¿ØÖƱ»Ñ¬È¾µÄϵͳ£¬µ«ÔÚ×î½üµÄ°¸ÀýÖУ¬ËûÃÇÒ²°²×°ÁËChrome Remote Desktop¡£
https://asec.ahnlab.com/en/60054/