BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø

°ä²¼¹¦·ò 2023-10-08

1¡¢BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø


¾Ý10ÔÂ6ÈÕ±¨Â· £¬ÔÆÍÆËãÌṩÉÌBlackbaudÓëÃÀ¹ú49¸öÖÝ´ï³ÉÁË4950ÍòÃÀÔªµÄºÍ̸ £¬ÒԺͽâÕë¶Ô2020Äê5ÔµÄÀÕË÷¹¥»÷¼°ÓÉ´ËÒý·¢µÄÊý¾Ýй¶µÄÖ¸¿Ø¡£¸ÃÊÂÎñÓ°ÏìÁËÊý°ÙÍòÓû§ £¬¹¥»÷ÕßÇÔÈ¡ÁËÓû§Î´¼ÓÃܵÄÒøÐÐÐÅÏ¢¡¢µÇ¼ƾ֤ºÍÉç»á°²È«ºÅÂë¡£BlackbaudÔÚ±»·î¸æËùÓб»µÁÊý¾ÝÒѱ»Ïú»Ùºó £¬½»ÁËÊê½ð¡£Õâ´Î´ï³ÉµÄ4950ÍòÃÀÔªºÍ½âºÍ̸½â¾öÁËBlackbaudÎ¥·´ÖÝÏû·ÑÕß±£»¤·¨¡¢Î¥·´Í¨ÖªÂÉÀýÒÔ¼°½¡È«±£ÏÕÁ÷ͨÓëÔðÈη¨°¸(HIPAA)µÄÖ¸¿Ø¡£


https://www.bleepingcomputer.com/news/security/blackbaud-agrees-to-495-million-settlement-for-ransomware-data-breach/


2¡¢¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»áÔâµ½¹¥»÷²¿ÃÅÑ¡ÃñÐÅϢй¶


¾ÝýÌå10ÔÂ6ÈÕ±¨Â· £¬¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»á(DCBOE)ĿǰÔÚµ÷²é²¿ÃÅÑ¡ÃñÐÅϢй¶ÊÂÎñ¡£µ÷²éÏÔʾ £¬¹¥»÷Õßͨ¹ýÑ¡¾Ù»ú¹¹µÄÍйÜÌṩÉÌDataNetµÄ·þÎñÆ÷½Ó¼ûÁËÕâЩÐÅÏ¢ £¬µ«DCBOEµÄÄÚ²¿Êý¾Ý¿âºÍ·þÎñÆ÷²¢Î´Êܵ½¹¥»÷¡£Ä¿Ç° £¬DCBOEµÄÍøÕ¾Òѹعز¢ÏÔÊ¾ÊØ»¤Ò³Ãæ¡£RansomedVCÐû³ÆÈëÇÖÁËDCBOE²¢»ñµÃÁ˳¬¹ý60ÍòÌõÃÀ¹úÑ¡ÃñµÄÐÅÏ¢ £¬ËüÔÚ°µÍøÉÏÏúÊÛ±»µÁÐÅÏ¢ £¬»¹¹«¿ªÁËÒ»±Ê¼Í¼ÒÔÖ¤Ã÷Êý¾ÝµÄÕæÊµÐÔ¡£µ«ÊǾݱ¨Â· £¬DCBOE±»µÁÊý¾Ý¿â×îÏÈÊÇÓÉÃûΪpwncoderµÄÓû§ÔÚºÚ¿ÍÂÛ̳ÖÐÏúÊÛµÄ £¬ÕâЩÌû×Ó´Ë¿ÌÒѱ»É¾³ý¡£


https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/


3¡¢Î¢ÈíÏêÊö¹¥»÷Õßͨ¹ýSQL ServerºáÏòÒÆ¶¯µ½ÔƵķ½Ê½


΢ÈíÔÚ10ÔÂ3ÈÕ³ÆÆä×î½ü·¢ÏÖÁËÒ»´Î¹¥»÷»î¶¯ £¬ÆäÖй¥»÷ÕßÊÔͼͨ¹ýSQL ServerÊ·ýºáÏòÒÆ¶¯µ½ÔÆ»·¾³¡£ÕâÖÖ¹¥»÷·½Ê½ÔÚÆäËüÔÆ·þÎñ£¨ÀýÈçVMºÍKubernetes£©ÖÐÓз¢ÏÖ¹ý £¬µ«ÔÚSQL ServerÖÐȴûÓС£¹¥»÷Õß×î³õÀûÓÃÖ¸±êϵͳµÄÀûÓ÷¨Ê½ÖеÄSQL×¢Èë·ì϶ £¬À´½Ó¼û²¿ÊðÔÚAzure Ðé¹¹»ú£¨VM£©ÖеÄMicrosoft SQL ServerÊ·ý²¢ÌáÉýÆäȨÏÞ¡£¶øºó £¬¹¥»÷ÕßÀûÓûñµÃµÄ¸ß¼¶È¨ÏÞ £¬ÊÔͼͨ¹ýÀÄÓ÷þÎñÆ÷µÄÔÆÉí·ÝºáÏòÒÆ¶¯µ½ÆäËüÔÆ×ÊÔ´¡£


https://www.microsoft.com/en-us/security/blog/2023/10/03/defending-new-vectors-threat-actors-attempt-sql-server-to-cloud-lateral-movement/


4¡¢Really Simple SystemsÅäÖÃÃýÎóй¶300Íò¿Í»§¼Í¼


ýÌå10ÔÂ5ÈÕ³Æ £¬×êÑÐÈËÔ±·¢ÏÖÁËB2B CRM ÌṩÉÌReally Simple SystemsÔ̺¬300¶àÍò±Ê¼Í¼µÄÎÞÃÜÂë±£»¤Êý¾Ý¿â¡£¸Ã¹«Ë¾Õ¼Óг¬¹ý18000¸ö¿Í»§ £¬Ô̺¬»Ê¼ÒѧԺ¡¢ºìÊ®×ֻᡢNHSºÍIBMµÈ¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¾ÝÒ½ÁƼͼ¡¢ÐÅÓþ»ã±¨¡¢Éí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍ˾·¨ÎļþµÈ £¬ÖØÒªÓ°ÏìÁËλÓÚÓ¢¹ú¡¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇµÄÆóÒµ¡£Ä¿Ç° £¬²»°²È«µÄÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´ £¬Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿â¶³öµÄ¹¦·ò £¬ÒÔ¼°ÊÇ·ñÓÐÈ˽Ӽû¹ýËü¡£


https://www.hackread.com/crm-provider-really-simple-systems-data-leak/


5¡¢Checkmarx·¢ÏÖÊý°Ù¸öÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ¶ñÒâPython°ü


10ÔÂ3ÈÕ £¬Checkmarx³ÆÒ»³¡¶ñÒâ»î¶¯ÒÑÔÚ¿ªÔ´Æ½Ì¨ÉÏÖ²ÈëÁËÊý°Ù¸öÐÅÏ¢ÇÔÈ¡°ü £¬ÏÂÔØÁ¿Ô¼Îª75000´Î¡£×Ô4Ô³õÒÔÀ´ £¬ÔÚPythonÉú̬ϵͳÖÐ £¬¹¥»÷Õßͨ¹ý¸÷ÀàÓû§Ãû²¿ÊðÁËÊý°Ù¸ö¶ñÒâÈí¼þ°ü¡£×Ô³õ´Î·¢ÏÖÒÔÀ´ £¬¹¥»÷±äµÃÔ½À´Ô½¸´ÔÓ £¬´ÓÃ÷ÎĹý¶Éµ½¼ÓÃÜ £¬ËæºóÓÖ¹ý¶Éµ½¶à²ã»ìºÏºÍ¶þ´Î·´»ã±àpayload¡£¶ñÒâ°üÖ¼ÔÚÇÔÈ¡´óÁ¿Ãô¸ÐÊý¾Ý £¬Ô̺¬Ö¸±êϵͳ¡¢ÀûÓ÷¨Ê½¡¢ä¯ÀÀÆ÷ºÍÓû§µÄÊý¾Ý¡£´Ë±í £¬ËüÃÇ»¹Í¨¹ýÅú¸Ä¼ÓÃÜÇ®±ÒµØÖ·½«ÂòÂô³Á¶¨Ïòµ½¹¥»÷Õß¡£


https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/


6¡¢Check Point°ä²¼9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨


10ÔÂ6ÈÕ £¬Check Point°ä²¼ÁË9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨¡£9Ô·Ý £¬×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ô¸çÂ×±ÈÑǶà¸öÐÐÒµµÄ40¶à¼Ò¹«Ë¾µÄ´ó¹æÄ£´¹µö»î¶¯ £¬Ö¼ÔÚ·Ö·¢Remcos RAT¡£ÔÚQbot±»µ·»Ùºó £¬Æä³Ö¾ÃÕ¼¾Ý°ñÊ׵ľÖÃæÒѾ­ÊµÏÖ £¬9Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ±äΪFormbook £¬Æä´ÎÊÇRemcosºÍEmotet¡£Ôâµ½¹¥»÷×îÑϳÁµÄÊǽÌÓýºÍ×êÑÐÐÐÒµ £¬Æä´ÎÊÇͨѶÒÔ¼°¾üÕþÁìÓò¡£×î³£±»ÀûÓõķì϶ÊÇWeb·þÎñÆ÷¶ñÒâURLĿ¼±éÀú·ì϶ £¬×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÒÀÈ»ÊÇAnubis¡£


https://blog.checkpoint.com/security/september-2023s-most-wanted-malware-remcos-wreaks-havoc-in-colombia-and-formbook-takes-top-spot-after-qbot-shutdown/