ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹JAXAµÄAD·þÎñÆ÷Ôâµ½¹¥»÷

°ä²¼¹¦·ò 2023-12-01
1¡¢ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹JAXAµÄAD·þÎñÆ÷Ôâµ½¹¥»÷


¾ÝýÌå11ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬ £¬£¬£¬£¬ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹(JAXA)Ôâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£JAXAûÓÐй©¹¥»÷²úÉúµÄ¾ßÌ幦·ò£¬£¬£¬£¬ £¬£¬£¬£¬ÓÐÐÂÎÅÈËʿй©²úÉúÓÚÏᄀ£¡£¡£¡£¡£¡£¡£µ«Ö±µ½Çï¼¾µ±·¨Âɲ¿ÃÅÁªÏµËûÃÇʱ£¬£¬£¬£¬ £¬£¬£¬£¬ËûÃDzÅÒâʶµ½Õâ´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»ñµÃÁ˶Ըûú¹¹Active Directory (AD)·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã·þÎñÆ÷ÊǼලJAXAÍøÂçÔËÓªµÄ³ÁÒª×é¼þ£¬£¬£¬£¬ £¬£¬£¬£¬ÖÎÀíÔ±¹¤IDºÍÃÜÂëÒÔ¼°²é¿´È¨ÏÞµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÉÐδ֤ʵ´æÔÚÊý¾Ýй¶£¬£¬£¬£¬ £¬£¬£¬£¬µ«JAXA¹¤×÷ÈËÔ±°µÊ¾£¬£¬£¬£¬ £¬£¬£¬£¬Ö»ÓÐAD·þÎñÆ÷±»¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬¾ÍºÜÓпÉÄÜ¿´µ½´ó²¿ÃÅÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬ÕâÖÖÇé¿ö¼«¶ÈÑϳÁ¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/japan-space-agency-cyberattack


2¡¢Apple°ä²¼´¹Î£°²È«¸üн¨¸´Á½¸öÒѱ»ÀûÓõķì϶


AppleÔÚ11ÔÂ30ÈÕ°ä²¼ÁË´¹Î£°²È«¸üУ¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´iPhone¡¢iPadºÍMacÖÐÁ½¸öÒѱ»ÀûÓõķì϶¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶¶¼ÊÇÔÚWebKitä¯ÀÀÆ÷ÒýÇæÖз¢Ïֵ쬣¬£¬£¬ £¬£¬£¬£¬Apple»ñϤ·ì϶¿ÉÄÜÒÑÔÚiOS 16.7.1֮ǰµÄiOS°æ±¾Öб»ÀûÓᣡ£¡£¡£¡£¡£¡£µÚÒ»¸öÊÇÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-42916£©£¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÓÃÀ´½Ó¼ûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÊÇÄÚ´æ°Ü»µ·ì϶£¨CVE-2023-42917£©£¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëµÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδ°ä²¼ÓйØÔÚÒ°ÀûÓù¥»÷µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×Ô½ñÄêËêÊ×ÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬£¬AppleÒѾ­½¨¸´ÁË20¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/155026/security/apple-emergency-security-updates-2-zero-day.html


3¡¢Â׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½ÔºÔâµ½RhysidaµÄÀÕË÷¹¥»÷


¾Ý11ÔÂ30ÈÕ±¨Â·£¬£¬£¬£¬ £¬£¬£¬£¬ÀÕË÷ÍÅ»ïRhysidaÐû³ÆÈëÇÖÁËÂ׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½Ôº¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï°ä²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ֤¾Ý£¬£¬£¬£¬ £¬£¬£¬£¬Ô̺¬Ò½Áƻ㱨¡¢µÇ¼Ç±í¡¢X¹âƬ¡¢Ò½ÁÆ´¦·½ºÍÒ½Áƻ㱨µÈ£¬£¬£¬£¬ £¬£¬£¬£¬»¹³ÆÇÔÈ¡ÁËÔ̺¬Ó¢¹ú»ÊÊÒÔÚÄڵĴóÁ¿»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ10 BTCµÄ¼ÛÖµÅÄÂôÇÔÈ¡µÄ´óÁ¿¡°Ãô¸ÐÊý¾Ý¡±¡£¡£¡£¡£¡£¡£¡£ÓëÆ½·²Ò»Ñù£¬£¬£¬£¬ £¬£¬£¬£¬Ëü´òË㽫Êý¾ÝÏúÊÛ¸øÎ¨Ò»µÄÂò¼Ò£¬£¬£¬£¬ £¬£¬£¬£¬²¢½«ÔÚ²¼¸æ°ä²¼ºóµÄÆßÌìÄÚ¹«¿ª°ä²¼ÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/154999/cyber-crime/rhysida-ransomware-king-edward-viis-hospital.html


4¡¢Black Basta×Ô³õ´Î±»·¢ÏÖÒÔÀ´ÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª


EllipticºÍCorvus InsuranceÔÚ11ÔÂ29ÈÕ°ä²¼µÄ½áºÏ×êÑÐÏÔʾ£¬£¬£¬£¬ £¬£¬£¬£¬Black BastaÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£Black BastaϰȾÁ˳¬¹ý329¸öÖ¸±ê£¬£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬Capita¡¢ABBºÍDish Network¡£¡£¡£¡£¡£¡£¡£·ÖÎöÅú×¢£¬£¬£¬£¬ £¬£¬£¬£¬×Ô2022ËêÊ×ÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬£¬Black BastaÒÑÊÕµ½ÖÁÉÙ1.07ÒÚÃÀÔªÊê½ð£¬£¬£¬£¬ £¬£¬£¬£¬Éæ¼°90¸ö±»¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×î´óÒ»±ÊÊê½ðµÄ½ð¶îΪ900ÍòÃÀÔª£¬£¬£¬£¬ £¬£¬£¬£¬ÖÁÉÙ18±ÊÊê½ð³¬¹ý100ÍòÃÀÔª£¬£¬£¬£¬ £¬£¬£¬£¬¾ùÔÈÊê½ð½ð¶îΪ120ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2023ÄêQ3 Black BastaÍøÕ¾ÉÏÁгöµÄ±»¹¥»÷Ö¸±êÊýÁ¿£¬£¬£¬£¬ £¬£¬£¬£¬ÖÁÉÙÓÐ35%½»ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£ 


https://www.corvusinsurance.com/blog/black-basta-ransomware-has-extracted-over-100-million-from-its-victims


5¡¢AhnLabÅû¶KimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯


11ÔÂ30ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬AhnLabÅû¶Á˽üÆÚKimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¼Ù×°³É½ø¿Ú±¨¹Øµ¥À´·Ö·¢¶ñÒâJSEÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÎļþÔ̺¬Ò»¸ö»ìºÏµÄPowerShell¾ç±¾¡¢Ò»¸öBase64±àÂëµÄºóÃÅÎļþºÍÒ»¸öºÏ·¨µÄPDFÎļþ¡£¡£¡£¡£¡£¡£¡£PDFÎļþÃûΪ¡°µ¼ÈëÉêÃ÷.PDF¡±£¬£¬£¬£¬ £¬£¬£¬£¬ÓÉPowerShell¾ç±¾×Ô¶¯Ö´ÐУ¬£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÔ¤·ÀÓû§·¢ÏÖ¹ý³ÌÖÐÔÚÖ´ÐеĶñÒâºóÃÅÎļþ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÇÔȡϵͳÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬ºóÃÅʹÓÃwmicºÅÁî²é³­Ö¸±êµÄɱ¶¾Èí¼þ״̬£¬£¬£¬£¬ £¬£¬£¬£¬²¢Í¨¹ýipconfigºÅÁîÍøÂçÍøÂçÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/59387/


6¡¢Symantec°ä²¼¼äµýÈí¼þÀûÓø÷À༼ÊõÈÆ¹ý¶ÈÎöµÄ»ã±¨


11ÔÂ29ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Symantec°ä²¼Á˼äµýÈí¼þÀûÓø÷Àà»ìºÏ¼¼ÊõÀ´Èƹý¾²Ì¬·ÖÎöµÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬ £¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¼äµýÈí¼þ¼¯Èº£¬£¬£¬£¬ £¬£¬£¬£¬Ñ¡È¡ÁËһϵÁм¼ÊõÀ´Ôö³¤¾²Ì¬·ÖÎöµÄÄѶÈ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬×ÊÔ´¼Ù×°£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚAPKÖд´½¨Óë³ÁÒª×ÊÔ´Ãû³ÆºÍȨÏÞÒ»ÑùµÄĿ¼£»£»£»£»£»Ñ¹ËõºýŪ£¬£¬£¬£¬ £¬£¬£¬£¬Í¨¹ý²»ÊÜÖ§³ÖµÄѹËõ²½ÖèÀ´°µ²ØAPKÖеĹؼü×ÊÔ´£»£»£»£»£»Í¨¹ý'ÎÞѹËõ'Êý¾Ý¶ã±ÜÊðÃû¹æ»®£»£»£»£»£»×ÊÔ´»ìºÏ£¬£¬£¬£¬ £¬£¬£¬£¬¾­¹ý"»ìºÏ"µÄAndroidManifest.xmlºÍresources.arscÎļþ»á·ÛËéÄæÏò¹¤³Ì¹¤¾ß£»£»£»£»£»ÒÔ¼°¼Ù×°³ÉÓÎÏ·¡¢ÀûÓ÷¨Ê½ºÍϵͳÀûÓõÈ¡£¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyware-obfuscation-static-analysis