΢ÈíÐû²¼12Ô·ÝÇå¾²¸üÐÂÐÞ¸´ÒÑÅû¶µÄAMDÎó²î

Ðû²¼Ê±¼ä 2023-12-13
1¡¢Î¢ÈíÐû²¼12Ô·ÝÇå¾²¸üÐÂÐÞ¸´ÒÑÅû¶µÄAMDÎó²î


΢ÈíÔÚ12ÔÂ12ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬£¬£¬ £¬£¬£¬ÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î¡£¡£´Ë´Î¸üÐÂÐÞ¸´ÁË8Ô·ÝÅû¶µÄÒ»¸öAMDÍÆ²âÖ´ÐÐÎó²î£¨CVE-2023-20588£©£¬£¬£¬ £¬£¬£¬ÕâÊÇÌØ¶¨AMD´¦Öóͷ£Æ÷ÖеÄÒ»¸ödivision-by-zeroÎó²î£¬£¬£¬ £¬£¬£¬¿ÉÄܻ᷵»ØÃô¸ÐÊý¾Ý¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬»¹ÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î£¬£¬£¬ £¬£¬£¬°üÀ¨Microsoft Power PlatformÅþÁ¬Æ÷ÓÕÆ­Îó²î£¨CVE-2023-36019£©¡¢ICSÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-35630ºÍCVE-2023-35641£©ÒÔ¼°Windows MSHTMLƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-35628£©¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/


2¡¢AppleÐû²¼¸üÐÂÐÞ¸´iOSºÍmacOSµÈ²úÆ·µÄ¶à¸öÎó²î


¾ÝýÌå12ÔÂ12ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬AppleÐû²¼ÁËÕë¶ÔiOS¡¢iPadOS¡¢macOS¡¢tvOS¡¢watchOSºÍSafariä¯ÀÀÆ÷µÄÇå¾²²¹¶¡¡£¡£ÆäÖÐÖµµÃ×¢ÖØµÄÊÇmacOS SonomaÖеÄÎó²î£¨CVE-2023-45866£©£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕÆ­¼üÅÌÀ´×¢Èë¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Apple»¹ÐÞ¸´Á˾ɰæiOS 16.7.3ºÍiPadOS 16.7.3ÖеĶà¸öÎó²î£¬£¬£¬ £¬£¬£¬°üÀ¨WebKitÒýÇæÖÐÁ½¸öÒѱ»Ê¹ÓõÄÎó²î£¨CVE-2023-42916ºÍCVE-2023-42917£©¡£¡£


https://thehackernews.com/2023/12/apple-releases-security-updates-to.html


3¡¢Americold¹«Ë¾Ôâµ½Cactus¹¥»÷й¶½ü13ÍòÈËÐÅÏ¢


¾Ý12ÔÂ12ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬ÃÀ¹úοزִ¢ºÍÔËÊ乫˾Americold³Æ£¬£¬£¬ £¬£¬£¬4Ô·ݵĹ¥»÷µ¼ÖÂÆä½ü13ÍòÃûÔ±¹¤¼°¾ìÊôµÄÐÅϢй¶¡£¡£¹¥»÷±¬·¢ÓÚ4ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬µ¼ÖÂϵͳÖÐÖ¹£¬£¬£¬ £¬£¬£¬Ó°ÏìÁ˹«Ë¾µÄÕý³£ÔËÓª¡£¡£ÀÕË÷ÍÅ»ïCactusÓÚ7ÔÂ21ÈÕÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬ £¬£¬£¬»¹Ð¹Â¶Á˸ù«Ë¾6 GB»á¼ÆºÍ²ÆÎñÎļþµµ°¸£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨Ë½È˺ÍÉñÃØÐÅÏ¢¡£¡£Americoldƾ֤11ÔÂ8ÈÕ¾ÙÐв¢×îÖÕÍê³ÉµÄÆÊÎöÈ·¶¨ÁËÊý¾Ýй¶¹æÄ££¬£¬£¬ £¬£¬£¬²¢ÓÚ12ÔÂ8ÈÕÏòÊܵ½Ó°ÏìµÄ129611ÃûÔ±¹¤¼°Æä¾ìÊô·¢ËÍÁË֪ͨ¡£¡£


https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-discloses-data-breach-after-april-malware-attack/


4¡¢CiscoÅû¶LazarusʹÓÃLog4Shell·Ö·¢ÐÂRATµÄ»î¶¯


Cisco TalosÔÚ12ÔÂ11ÈÕÅû¶ÁËLazarus GroupµÄÒ»Ïîл£¬£¬£¬ £¬£¬£¬±»³ÆÎª¡°Operation Blacksmith¡±¡£¡£¸Ã»î¶¯Ê¼ÓÚ½ñÄê3ÔÂ×óÓÒ£¬£¬£¬ £¬£¬£¬Õë¶ÔÈ«ÇòÖÆÔ졢ũҵºÍÎïÀíÇå¾²¹«Ë¾¡£¡£Lazarus¼ÌÐøÊ¹ÓÃCVE-2021-44228£¨ÓÖÃûLog4Shell£©£¬£¬£¬ £¬£¬£¬·Ö·¢ÁË3¸öÓÃDLang¿ª·¢µÄжñÒâÈí¼þ¡£¡£Ð¶ñÒâÈí¼þÊÇÁ½¸öÔ¶³Ì»á¼ûľÂíNineRATºÍDLRAT£¬£¬£¬ £¬£¬£¬ÒÔ¼°Ò»¸ö¶ñÒâÈí¼þÏÂÔØ³ÌÐòBottomLoader¡£¡£ÆäÖУ¬£¬£¬ £¬£¬£¬NineRATʹÓÃTelegram API¾ÙÐÐC2ͨѶ¡£¡£


https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/


5¡¢SentinelOneÐû²¼¹ØÓÚSandman APTµÄÆÊÎö±¨¸æ


12ÔÂ11ÈÕ£¬£¬£¬ £¬£¬£¬SentinelOneÐû²¼Á˹ØÓÚSandman APT¹éÒòµÄÆÊÎö±¨¸æ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬Sandman APTºÜ¿ÉÄÜÓëʹÓÃKEYPLUGºóÃŵÄÍÅ»ïÓйØ£¬£¬£¬ £¬£¬£¬ÌØÊâÊÇ΢ÈíºÍPwC×·×ÙΪSTORM-0866/Red Dev 40µÄÍŻ¡£¾ÝÊӲ죬£¬£¬ £¬£¬£¬SandmanÍÅ»ï»ùÓÚLuaµÄ¶ñÒâÈí¼þLuaDreamºÍKEYPLUGºóÃű£´æÓÚͳһ±»¹¥»÷ÇéÐÎÖС£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬SandmanºÍSTORM-0866/Red Dev 40ÓÐÏàͬµÄ»ù´¡ÉèÊ©¿ØÖƺÍÖÎÀí·½·¨£¬£¬£¬ £¬£¬£¬°üÀ¨ÍйÜÌṩÉ̵ÄÑ¡ÔñºÍÓòÃûÃüÃû¹æÔò¡£¡£


https://www.sentinelone.com/labs/sandman-apt-china-based-adversaries-embrace-lua/


6¡¢KasperskyÐû²¼È˹¤ÖÇÄܶÔÍøÂçÇå¾²µÄÓ°ÏìµÄ±¨¸æ


12ÔÂ11ÈÕ£¬£¬£¬ £¬£¬£¬KasperskyÐû²¼Á˹ØÓÚÈ˹¤ÖÇÄܶÔÍøÂçÇå¾²µÄÓ°ÏìµÄÄê¶ÈÆÊÎö±¨¸æ¡£¡£È˹¤ÖÇÄÜ´øÀ´»úÔµµÄͬʱҲ´øÀ´ÁËеÄΣº¦£¬£¬£¬ £¬£¬£¬°üÀ¨ÐÅÈκͿɿ¿ÐÔµÄÎÊÌ⡢רÓÐÔÆÐ§À͵ÄΣº¦¡¢Õë¶Ô´óÐÍÓïÑÔÄ£×Ó£¨LLM£©µÄÎó²î¡¢¿ÉÄܱ»ÍøÂç¹¥»÷ÕßʹÓõÄΣº¦ÒÔ¼°Éî¶ÈαÔì±»ÓÃÓÚÖÖÖÖȦÌס£¡£¿ÉÊÇÌìÉúʽÈ˹¤ÖÇÄÜÒ²»áÔöÇ¿·ÀÓùʵÁ¦£¬£¬£¬ £¬£¬£¬ÀýÈçÌìÉúʽÈ˹¤ÖÇÄÜ(GenAI)¸³ÄÜ·ÀÓùÖ°Ô±µÈ¡£¡£¶Ô2024ÄêµÄÕ¹Íû°üÀ¨¿ÉÄ᷺ܻÆð¸üÖØ´óµÄÎó²î£¬£¬£¬ £¬£¬£¬ÒÔ¼°Éñ¾­ÍøÂ罫ԽÀ´Ô½¶àµØÓÃÓÚÌìÉúÕ©Æ­ÊÓ¾õЧ¹ûµÈ¡£¡£


https://securelist.com/story-of-the-year-2023-ai-impact-on-cybersecurity/111341/