Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶
Ðû²¼Ê±¼ä 2023-12-281¡¢Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶
¾ÝýÌå12ÔÂ26ÈÕ±¨µÀ£¬¶í¿ËÀºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷¡£Integris HealthÌåÏÖ£¬ËûÃÇÔÚÒâʶµ½¿ÉÒÉÔ˶¯ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬²¢ÊӲ칥»÷µÄÐÔ×Ӻ͹æÄ££¬È·¶¨²¿·ÖÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»»á¼û¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖУ¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡Áè¼Ý200Íò»¼ÕßµÄÊý¾Ý¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕ³öÊÛ¸ÃÊý¾Ý¿â£¬ÔÚ´Ë֮ǰ»¼ÕßÓÐʱ»úɾ³ý×Ô¼ºµÄÊý¾Ý¡£ÕâЩÓʼþ°üÀ¨Ò»¸öTorÍøÕ¾Á´½Ó£¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý£¬ÔÊÐí»á¼ûÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔªÉó²éÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/
2¡¢BarracudaÐÞ¸´±»UNC4841ʹÓõÄÎó²îCVE-2023-7102
¾Ý12ÔÂ27ÈÕ±¨µÀ£¬BarracudaÐû²¼ÁËÇå¾²¸üУ¬ÐÞ¸´µç×ÓÓʼþÇå¾²Íø¹Ø(ESG)×°±¸ÖеÄÎó²î£¨CVE-2023-7102£©¡£BarracudaÒÑÈ·¶¨£¬Óй¥»÷ÕßʹÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄí§Òâ´úÂëÖ´ÐÐ(ACE)Îó²îÀ´·Ö·¢ÌØÖƵÄExcelÓʼþ¸½¼þ£¬ÒÔ¹¥»÷ESG×°±¸¡£¼ÌUNC4841ʹÓøÃACEÎó²îÖ®ºó£¬Barracuda·¢Ã÷²¿·ÖESG×°±¸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå¡£BarracudaÓÚ12ÔÂ21ÈÕÐÞ¸´Á˸ÃÎó²î£¬Çå¾²¸üлá×Ô¶¯Ó¦Óã¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐС£
https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html
3¡¢ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼±»ÒÔ7.5ÍòÃÀÔª³öÊÛ
ýÌå12ÔÂ26Èճƣ¬ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼ÕýÔÚÒÔԼĪ75000ÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐÓÃÐÔ£¬²¢ÌåÏÖ¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢ÊÖÒÕ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ¡£³öÊÛµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢£¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùÓÐÊý¾Ý¡£×Ô8ÔÂÒÔÀ´£¬×Ô³Æ"ÒÁÀÊ°ü¹ÜÒµ×î´óµÄÐÅÏ¢ÊÖÒÕ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ö±½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø»á¼û¡£
https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/
4¡¢EasyPark²¿·Ö¿Í»§µÄÊý¾Ýй¶½¨ÒéСÐÄ´¹ÂÚÕ©Æ
ýÌå12ÔÂ26ÈÕ±¨µÀ£¬Å·ÖÞ×î´óµÄÍ£³µÓ¦ÓÃÔËÓªÉÌEasyPark Group²¿·Ö¿Í»§µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØµãºÍÐÅÓÿ¨ºÅµÈÐÅϢй¶¡£¸ÃÊÂÎñÉæ¼°IBAN»òÐÅÓÿ¨ºÅÂ룬½¨Òé¿Í»§Ð¡ÐÄÍøÂç´¹ÂÚÕ©Æ¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°ÏìÓû§µÄÊýÄ¿£¬µ«Æä½²»°È˳ƣ¬´ó´ó¶¼ÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ¡£µ½ÏÖÔÚΪֹ£¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó£¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»Ê¹Óûòй¶¡£
https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/
5¡¢NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ
12ÔÂ21ÈÕ£¬NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à£¬Îª146Æð£¨Õ¼±È33%£©£¬±È10Ô£¨114Æð£©ÔöÌíÁË28%£¬Æä´ÎÊÇÖÜÆÚÐÔÏûºÄÆ·£¨18%£©ºÍÒ½ÁƱ£½¡£¨11%£©ÐÐÒµ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍŻÆäÔ˶¯½Ï10ԼͼµÄ66Æð¹¥»÷»·±ÈÔöÌí73%¡£±ðµÄ£¬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁÖØÀ´£¬½ÓÄɵÄй¥»÷Á´£¬Ã°³äÁË¿Í»§¹ØϵÖÎÀíƽ̨HubSpot¡¢Êý¾ÝÖÎÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈÖÖÖÖÓªÒµÏà¹ØÈí¼þÀ´Èö²¥¡£
https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/
6¡¢ResecurityÐû²¼2024ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ
12ÔÂ21ÈÕ£¬ResecurityÐû²¼ÁË2024ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ¡£±¨¸æÕ¹ÍûµÄÖ÷ÒªÇ÷ÊÆ°üÀ¨£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷Ô˶¯ÔöÌí¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍ×ÔÈ»Æø£©ºÍºË²¿·ÖµÄÍøÂç¹¥»÷ÔöÌí¡¢È˹¤ÖÇÄÜ£¨AI£©ÎäÆ÷»¯½«·ÉËÙÉú³¤¡¢Öǻ۶¼»áºÍÈÕÒæÑÏËàµÄÍøÂçÇå¾²ÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö¡£¶Ô2024ÄêµÄÕ¹ÍûÕ¹ÏÖÁËһֱת±äµÄÍþв̬ÊÆ£¬±Þ²ß×éÖ¯ºÍÕþ²ßÖƶ©Õß¼á³ÖСÐIJ¢Ñ¸ËÙ˳ӦзºÆðµÄÌôÕ½¡£
https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast