Integris HealthÔâµ½¹¥»÷³¬¹ý200Íò»¼ÕßÐÅϢй¶

°ä²¼¹¦·ò 2023-12-28

1¡¢Integris HealthÔâµ½¹¥»÷³¬¹ý200Íò»¼ÕßÐÅϢй¶


¾ÝýÌå12ÔÂ26ÈÕ±¨Â· £¬¶í¿ËÀ­ºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷ ¡£Integris Health°µÊ¾ £¬ËûÃÇÔÚÒâʶµ½¿ÉÒɻºóÁ¢¼´²ÉÈ¡ÁË´ëÊ© £¬²¢µ÷²é¹¥»÷µÄÐÔÖʺÍÁìÓò £¬È·¶¨²¿ÃÅÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»½Ó¼û ¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖÐ £¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡³¬¹ý200Íò»¼ÕßµÄÊý¾Ý ¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕÏúÊÛ¸ÃÊý¾Ý¿â £¬ÔÚ´Ë֮ǰ»¼ÕßÓлúÓöɾ³ý×Ô¼ºµÄÊý¾Ý ¡£ÕâЩÓʼþÔ̺¬Ò»¸öTorÍøÕ¾Á´½Ó £¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý £¬ÔÊÐí½Ó¼ûÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔª²é¿´Êý¾Ý ¡£


https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/


2¡¢Barracuda½¨¸´±»UNC4841ÀûÓõķì϶CVE-2023-7102


¾Ý12ÔÂ27ÈÕ±¨Â· £¬Barracuda°ä²¼Á˰²È«¸üР£¬½¨¸´µç×ÓÓʼþ°²È«Íø¹Ø(ESG)É豸Öеķì϶£¨CVE-2023-7102£© ¡£BarracudaÒÑÈ·¶¨ £¬Óй¥»÷ÕßÀûÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄËÁÒâ´úÂëÖ´ÐÐ(ACE)·ì϶À´·Ö·¢ÌØÔìµÄExcelÓʼþ¸½¼þ £¬ÒÔ¹¥»÷ESGÉ豸 ¡£¼ÌUNC4841ÀûÓøÃACE·ì϶֮ºó £¬Barracuda·¢ÏÖ²¿ÃÅESGÉ豸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå ¡£BarracudaÓÚ12ÔÂ21ÈÕ½¨¸´Á˸÷ì϶ £¬°²È«¸üлá×Ô¶¯ÀûÓà £¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐÐ ¡£


https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html


3¡¢ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Í¼±»ÒÔ7.5ÍòÃÀÔªÏúÊÛ


ýÌå12ÔÂ26ÈÕ³Æ £¬ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Í¼ÔÚÒÔԼĪ75000ÃÀÔªµÄ¼ÛÖµÏúÊÛ ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐЧÐÔ £¬²¢°µÊ¾¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢¼¼Êõ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ ¡£ÏúÊÛµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢ £¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùº±¼û¾Ý ¡£×Ô8ÔÂÒÔÀ´ £¬×Ô³Æ"ÒÁÀʱ£ÏÕÒµ×î´óµÄÐÅÏ¢¼¼Êõ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ïò½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø½Ó¼û ¡£


https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/


4¡¢EasyPark²¿Ãſͻ§µÄÊý¾Ýй¶½¨Ò龯Ìè´¹µöÚ¿Æ­


ýÌå12ÔÂ26ÈÕ±¨Â· £¬Å·ÖÞ×î´óµÄÍ£³µÀûÓÃÔËÓªÉÌEasyPark Group²¿Ãſͻ§µÄÐÅϢй¶ ¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ £¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍÐÅÓþ¿¨ºÅµÈÐÅϢй¶ ¡£¸ÃÊÂÎñÉæ¼°IBAN»òÐÅÓþ¿¨ºÅÂë £¬½¨Òé¿Í»§¾¯ÌèÍøÂç´¹µöÚ¿Æ­ ¡£¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°ÏìÓû§µÄÊýÁ¿ £¬µ«Æä½²»°È˳Æ £¬´óÎÞÊýÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ ¡£µ½Ä¿Ç°ÎªÖ¹ £¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó £¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»ÀûÓûòй¶ ¡£


https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/


5¡¢NCC Group°ä²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


12ÔÂ21ÈÕ £¬NCC Group°ä²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à £¬Îª146Æð£¨Õ¼±È33%£© £¬±È10Ô£¨114Æð£©Ôö³¤ÁË28% £¬Æä´ÎÊÇÖÜÆÚÐÔÏû·ÑÆ·£¨18%£©ºÍÒ½ÁƱ£½ ¡£¨11%£©ÐÐÒµ ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍÅ»ï £¬Æä»î¶¯½Ï10ԼͼµÄ66Æð¹¥»÷»·±ÈÔö³¤73% ¡£´Ë±í £¬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁ³ÁÀ´ £¬Ñ¡È¡µÄй¥»÷Á´ £¬¼ÙÒâÁ˿ͻ§¹ØÏµÖÎÀíÆ½Ì¨HubSpot¡¢Êý¾ÝÖÎÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈ¸÷ÀàÒµÎñÓйØÈí¼þÀ´´«²¼ ¡£


https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/


6¡¢Resecurity°ä²¼2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨


12ÔÂ21ÈÕ £¬Resecurity°ä²¼ÁË2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨ ¡£»ã±¨Ô¤²âµÄÖØÒªÇ÷ÏòÔ̺¬£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷»î¶¯Ôö³¤¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍÌìÈ»Æø£©ºÍºË²¿ÃŵÄÍøÂç¹¥»÷Ôö³¤¡¢ÈËΪÖÇÄÜ£¨AI£©±øÆ÷»¯½«·ÉËÙ·¢Õ¹¡¢Öǻ۳ÇÊкÍÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö ¡£¶Ô2024ÄêµÄÔ¤²â½ÒʾÁ˲»Ðݱ䶯µÄÍþÐ²Ì¬ÊÆ £¬¶½´Ù×éÖ¯ºÍÕþ²ßÔì¶©Õßά³Ö¾¯Ì貢ѸËÙÊÊӦгöÏÖµÄÌôÕ½ ¡£


https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast