Integris HealthÔâµ½¹¥»÷³¬¹ý200Íò»¼ÕßÐÅϢй¶

°ä²¼¹¦·ò 2023-12-28

1¡¢Integris HealthÔâµ½¹¥»÷³¬¹ý200Íò»¼ÕßÐÅϢй¶


¾ÝýÌå12ÔÂ26ÈÕ±¨Â· £¬¶í¿ËÀ­ºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷¡£Integris Health°µÊ¾ £¬ËûÃÇÔÚÒâʶµ½¿ÉÒɻºóÁ¢¼´²ÉÈ¡ÁË´ëÊ© £¬²¢µ÷²é¹¥»÷µÄÐÔÖʺÍÁìÓò £¬È·¶¨²¿ÃÅÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»½Ó¼û¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖÐ £¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡³¬¹ý200Íò»¼ÕßµÄÊý¾Ý¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕÏúÊÛ¸ÃÊý¾Ý¿â £¬ÔÚ´Ë֮ǰ»¼ÕßÓлúÓöɾ³ý×Ô¼ºµÄÊý¾Ý¡£ÕâЩÓʼþÔ̺¬Ò»¸öTorÍøÕ¾Á´½Ó £¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý £¬ÔÊÐí½Ó¼ûÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔª²é¿´Êý¾Ý¡£


https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/


2¡¢Barracuda½¨¸´±»UNC4841ÀûÓõķì϶CVE-2023-7102


¾Ý12ÔÂ27ÈÕ±¨Â· £¬Barracuda°ä²¼Á˰²È«¸üР£¬½¨¸´µç×ÓÓʼþ°²È«Íø¹Ø(ESG)É豸Öеķì϶£¨CVE-2023-7102£©¡£BarracudaÒÑÈ·¶¨ £¬Óй¥»÷ÕßÀûÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄËÁÒâ´úÂëÖ´ÐÐ(ACE)·ì϶À´·Ö·¢ÌØÔìµÄExcelÓʼþ¸½¼þ £¬ÒÔ¹¥»÷ESGÉ豸¡£¼ÌUNC4841ÀûÓøÃACE·ì϶֮ºó £¬Barracuda·¢ÏÖ²¿ÃÅESGÉ豸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå¡£BarracudaÓÚ12ÔÂ21ÈÕ½¨¸´Á˸÷ì϶ £¬°²È«¸üлá×Ô¶¯ÀûÓà £¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐС£


https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html


3¡¢ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Í¼±»ÒÔ7.5ÍòÃÀÔªÏúÊÛ


ýÌå12ÔÂ26ÈÕ³Æ £¬ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Í¼ÔÚÒÔԼĪ75000ÃÀÔªµÄ¼ÛÖµÏúÊÛ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐЧÐÔ £¬²¢°µÊ¾¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢¼¼Êõ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ¡£ÏúÊÛµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢ £¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùº±¼û¾Ý¡£×Ô8ÔÂÒÔÀ´ £¬×Ô³Æ"ÒÁÀʱ£ÏÕÒµ×î´óµÄÐÅÏ¢¼¼Êõ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ïò½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø½Ó¼û¡£


https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/


4¡¢EasyPark²¿Ãſͻ§µÄÊý¾Ýй¶½¨Ò龯Ìè´¹µöÚ¿Æ­


ýÌå12ÔÂ26ÈÕ±¨Â· £¬Å·ÖÞ×î´óµÄÍ£³µÀûÓÃÔËÓªÉÌEasyPark Group²¿Ãſͻ§µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ £¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍÐÅÓþ¿¨ºÅµÈÐÅϢй¶¡£¸ÃÊÂÎñÉæ¼°IBAN»òÐÅÓþ¿¨ºÅÂë £¬½¨Òé¿Í»§¾¯ÌèÍøÂç´¹µöÚ¿Æ­¡£¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°ÏìÓû§µÄÊýÁ¿ £¬µ«Æä½²»°È˳Æ £¬´óÎÞÊýÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ¡£µ½Ä¿Ç°ÎªÖ¹ £¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó £¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»ÀûÓûòй¶¡£


https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/


5¡¢NCC Group°ä²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


12ÔÂ21ÈÕ £¬NCC Group°ä²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à £¬Îª146Æð£¨Õ¼±È33%£© £¬±È10Ô£¨114Æð£©Ôö³¤ÁË28% £¬Æä´ÎÊÇÖÜÆÚÐÔÏû·ÑÆ·£¨18%£©ºÍÒ½ÁƱ£½¡£¨11%£©ÐÐÒµ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍÅ»ï £¬Æä»î¶¯½Ï10ԼͼµÄ66Æð¹¥»÷»·±ÈÔö³¤73%¡£´Ë±í £¬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁ³ÁÀ´ £¬Ñ¡È¡µÄй¥»÷Á´ £¬¼ÙÒâÁ˿ͻ§¹ØÏµÖÎÀíÆ½Ì¨HubSpot¡¢Êý¾ÝÖÎÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈ¸÷ÀàÒµÎñÓйØÈí¼þÀ´´«²¼¡£


https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/


6¡¢Resecurity°ä²¼2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨


12ÔÂ21ÈÕ £¬Resecurity°ä²¼ÁË2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨¡£»ã±¨Ô¤²âµÄÖØÒªÇ÷ÏòÔ̺¬£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷»î¶¯Ôö³¤¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍÌìÈ»Æø£©ºÍºË²¿ÃŵÄÍøÂç¹¥»÷Ôö³¤¡¢ÈËΪÖÇÄÜ£¨AI£©±øÆ÷»¯½«·ÉËÙ·¢Õ¹¡¢Öǻ۳ÇÊкÍÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö¡£¶Ô2024ÄêµÄÔ¤²â½ÒʾÁ˲»Ðݱ䶯µÄÍþÐ²Ì¬ÊÆ £¬¶½´Ù×éÖ¯ºÍÕþ²ßÔì¶©Õßά³Ö¾¯Ì貢ѸËÙÊÊӦгöÏÖµÄÌôÕ½¡£


https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast