ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹JAXAµÄAD·þÎñÆ÷Ôâµ½¹¥»÷
°ä²¼¹¦·ò 2023-12-01¾ÝýÌå11ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹(JAXA)Ôâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£JAXAûÓÐй©¹¥»÷²úÉúµÄ¾ßÌ幦·ò£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÐÂÎÅÈËʿй©²úÉúÓÚÏᄀ£¡£¡£¡£¡£¡£¡£µ«Ö±µ½Çï¼¾µ±·¨Âɲ¿ÃÅÁªÏµËûÃÇʱ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃDzÅÒâʶµ½Õâ´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»ñµÃÁ˶Ըûú¹¹Active Directory (AD)·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷ÊǼලJAXAÍøÂçÔËÓªµÄ³ÁÒª×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±¹¤IDºÍÃÜÂëÒÔ¼°²é¿´È¨ÏÞµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÉÐδ֤ʵ´æÔÚÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«JAXA¹¤×÷ÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐAD·þÎñÆ÷±»¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¾ÍºÜÓпÉÄÜ¿´µ½´ó²¿ÃÅÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÇé¿ö¼«¶ÈÑϳÁ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/japan-space-agency-cyberattack
2¡¢Apple°ä²¼´¹Î£°²È«¸üн¨¸´Á½¸öÒѱ»ÀûÓõķì϶
AppleÔÚ11ÔÂ30ÈÕ°ä²¼ÁË´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´iPhone¡¢iPadºÍMacÖÐÁ½¸öÒѱ»ÀûÓõķì϶¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶¶¼ÊÇÔÚWebKitä¯ÀÀÆ÷ÒýÇæÖз¢Ïֵ쬣¬£¬£¬£¬£¬£¬£¬Apple»ñϤ·ì϶¿ÉÄÜÒÑÔÚiOS 16.7.1֮ǰµÄiOS°æ±¾Öб»ÀûÓᣡ£¡£¡£¡£¡£¡£µÚÒ»¸öÊÇÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-42916£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´½Ó¼ûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÊÇÄÚ´æ°Ü»µ·ì϶£¨CVE-2023-42917£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδ°ä²¼ÓйØÔÚÒ°ÀûÓù¥»÷µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×Ô½ñÄêËêÊ×ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬AppleÒѾ½¨¸´ÁË20¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/155026/security/apple-emergency-security-updates-2-zero-day.html
3¡¢Â׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½ÔºÔâµ½RhysidaµÄÀÕË÷¹¥»÷
¾Ý11ÔÂ30ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïRhysidaÐû³ÆÈëÇÖÁËÂ׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½Ôº¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï°ä²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ֤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò½Áƻ㱨¡¢µÇ¼Ç±í¡¢X¹âƬ¡¢Ò½ÁÆ´¦·½ºÍÒ½Áƻ㱨µÈ£¬£¬£¬£¬£¬£¬£¬£¬»¹³ÆÇÔÈ¡ÁËÔ̺¬Ó¢¹ú»ÊÊÒÔÚÄڵĴóÁ¿»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ10 BTCµÄ¼ÛÖµÅÄÂôÇÔÈ¡µÄ´óÁ¿¡°Ãô¸ÐÊý¾Ý¡±¡£¡£¡£¡£¡£¡£¡£ÓëÆ½·²Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬Ëü´òË㽫Êý¾ÝÏúÊÛ¸øÎ¨Ò»µÄÂò¼Ò£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÔÚ²¼¸æ°ä²¼ºóµÄÆßÌìÄÚ¹«¿ª°ä²¼ÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/154999/cyber-crime/rhysida-ransomware-king-edward-viis-hospital.html
4¡¢Black Basta×Ô³õ´Î±»·¢ÏÖÒÔÀ´ÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª
EllipticºÍCorvus InsuranceÔÚ11ÔÂ29ÈÕ°ä²¼µÄ½áºÏ×êÑÐÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬Black BastaÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£Black BastaϰȾÁ˳¬¹ý329¸öÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Capita¡¢ABBºÍDish Network¡£¡£¡£¡£¡£¡£¡£·ÖÎöÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬×Ô2022ËêÊ×ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Black BastaÒÑÊÕµ½ÖÁÉÙ1.07ÒÚÃÀÔªÊê½ð£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°90¸ö±»¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×î´óÒ»±ÊÊê½ðµÄ½ð¶îΪ900ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙ18±ÊÊê½ð³¬¹ý100ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÊê½ð½ð¶îΪ120ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2023ÄêQ3 Black BastaÍøÕ¾ÉÏÁгöµÄ±»¹¥»÷Ö¸±êÊýÁ¿£¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÓÐ35%½»ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£
https://www.corvusinsurance.com/blog/black-basta-ransomware-has-extracted-over-100-million-from-its-victims
5¡¢AhnLabÅû¶KimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯
11ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬AhnLabÅû¶Á˽üÆÚKimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¼Ù×°³É½ø¿Ú±¨¹Øµ¥À´·Ö·¢¶ñÒâJSEÎļþ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÔ̺¬Ò»¸ö»ìºÏµÄPowerShell¾ç±¾¡¢Ò»¸öBase64±àÂëµÄºóÃÅÎļþºÍÒ»¸öºÏ·¨µÄPDFÎļþ¡£¡£¡£¡£¡£¡£¡£PDFÎļþÃûΪ¡°µ¼ÈëÉêÃ÷.PDF¡±£¬£¬£¬£¬£¬£¬£¬£¬ÓÉPowerShell¾ç±¾×Ô¶¯Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔ¤·ÀÓû§·¢ÏÖ¹ý³ÌÖÐÔÚÖ´ÐеĶñÒâºóÃÅÎļþ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÇÔȡϵͳÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ºóÃÅʹÓÃwmicºÅÁî²é³Ö¸±êµÄɱ¶¾Èí¼þ״̬£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýipconfigºÅÁîÍøÂçÍøÂçÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/59387/
6¡¢Symantec°ä²¼¼äµýÈí¼þÀûÓø÷À༼ÊõÈÆ¹ý¶ÈÎöµÄ»ã±¨
11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Symantec°ä²¼Á˼äµýÈí¼þÀûÓø÷Àà»ìºÏ¼¼ÊõÀ´Èƹý¾²Ì¬·ÖÎöµÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¼äµýÈí¼þ¼¯Èº£¬£¬£¬£¬£¬£¬£¬£¬Ñ¡È¡ÁËһϵÁм¼ÊõÀ´Ôö³¤¾²Ì¬·ÖÎöµÄÄѶȡ£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬×ÊÔ´¼Ù×°£¬£¬£¬£¬£¬£¬£¬£¬ÔÚAPKÖд´½¨Óë³ÁÒª×ÊÔ´Ãû³ÆºÍȨÏÞÒ»ÑùµÄĿ¼£»£»£»£»£»Ñ¹ËõºýŪ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý²»ÊÜÖ§³ÖµÄѹËõ²½ÖèÀ´°µ²ØAPKÖеĹؼü×ÊÔ´£»£»£»£»£»Í¨¹ý'ÎÞѹËõ'Êý¾Ý¶ã±ÜÊðÃû¹æ»®£»£»£»£»£»×ÊÔ´»ìºÏ£¬£¬£¬£¬£¬£¬£¬£¬¾¹ý"»ìºÏ"µÄAndroidManifest.xmlºÍresources.arscÎļþ»á·ÛËéÄæÏò¹¤³Ì¹¤¾ß£»£»£»£»£»ÒÔ¼°¼Ù×°³ÉÓÎÏ·¡¢ÀûÓ÷¨Ê½ºÍϵͳÀûÓõȡ£¡£¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyware-obfuscation-static-analysis


¾©¹«Íø°²±¸11010802024551ºÅ