Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶

Ðû²¼Ê±¼ä 2023-12-28

1¡¢Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶


¾ÝýÌå12ÔÂ26ÈÕ±¨µÀ£¬¶í¿ËÀ­ºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷ ¡£Integris HealthÌåÏÖ£¬ËûÃÇÔÚÒâʶµ½¿ÉÒÉÔ˶¯ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬²¢ÊӲ칥»÷µÄÐÔ×Ӻ͹æÄ££¬È·¶¨²¿·ÖÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»»á¼û ¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖУ¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡Áè¼Ý200Íò»¼ÕßµÄÊý¾Ý ¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕ³öÊÛ¸ÃÊý¾Ý¿â£¬ÔÚ´Ë֮ǰ»¼ÕßÓÐʱ»úɾ³ý×Ô¼ºµÄÊý¾Ý ¡£ÕâЩÓʼþ°üÀ¨Ò»¸öTorÍøÕ¾Á´½Ó£¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý£¬ÔÊÐí»á¼ûÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔªÉó²éÊý¾Ý ¡£


https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/


2¡¢BarracudaÐÞ¸´±»UNC4841ʹÓõÄÎó²îCVE-2023-7102


¾Ý12ÔÂ27ÈÕ±¨µÀ£¬BarracudaÐû²¼ÁËÇå¾²¸üУ¬ÐÞ¸´µç×ÓÓʼþÇå¾²Íø¹Ø(ESG)×°±¸ÖеÄÎó²î£¨CVE-2023-7102£© ¡£BarracudaÒÑÈ·¶¨£¬Óй¥»÷ÕßʹÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄí§Òâ´úÂëÖ´ÐÐ(ACE)Îó²îÀ´·Ö·¢ÌØÖƵÄExcelÓʼþ¸½¼þ£¬ÒÔ¹¥»÷ESG×°±¸ ¡£¼ÌUNC4841ʹÓøÃACEÎó²îÖ®ºó£¬Barracuda·¢Ã÷²¿·ÖESG×°±¸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå ¡£BarracudaÓÚ12ÔÂ21ÈÕÐÞ¸´Á˸ÃÎó²î£¬Çå¾²¸üлá×Ô¶¯Ó¦Óã¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐÐ ¡£


https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html


3¡¢ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼±»ÒÔ7.5ÍòÃÀÔª³öÊÛ


ýÌå12ÔÂ26Èճƣ¬ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼ÕýÔÚÒÔԼĪ75000ÃÀÔªµÄ¼ÛÇ®³öÊÛ ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐÓÃÐÔ£¬²¢ÌåÏÖ¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢ÊÖÒÕ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ ¡£³öÊÛµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢£¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùÓÐÊý¾Ý ¡£×Ô8ÔÂÒÔÀ´£¬×Ô³Æ"ÒÁÀÊ°ü¹ÜÒµ×î´óµÄÐÅÏ¢ÊÖÒÕ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ö±½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø»á¼û ¡£


https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/


4¡¢EasyPark²¿·Ö¿Í»§µÄÊý¾Ýй¶½¨ÒéСÐÄ´¹ÂÚÕ©Æ­


ýÌå12ÔÂ26ÈÕ±¨µÀ£¬Å·ÖÞ×î´óµÄÍ£³µÓ¦ÓÃÔËÓªÉÌEasyPark Group²¿·Ö¿Í»§µÄÐÅϢй¶ ¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØµãºÍÐÅÓÿ¨ºÅµÈÐÅϢй¶ ¡£¸ÃÊÂÎñÉæ¼°IBAN»òÐÅÓÿ¨ºÅÂ룬½¨Òé¿Í»§Ð¡ÐÄÍøÂç´¹ÂÚÕ©Æ­ ¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°ÏìÓû§µÄÊýÄ¿£¬µ«Æä½²»°È˳Æ£¬´ó´ó¶¼ÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ ¡£µ½ÏÖÔÚΪֹ£¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó£¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»Ê¹Óûòй¶ ¡£


https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/


5¡¢NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ


12ÔÂ21ÈÕ£¬NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ ¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à£¬Îª146Æð£¨Õ¼±È33%£©£¬±È10Ô£¨114Æð£©ÔöÌíÁË28%£¬Æä´ÎÊÇÖÜÆÚÐÔÏûºÄÆ·£¨18%£©ºÍÒ½ÁƱ£½ ¡£¨11%£©ÐÐÒµ ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍŻÆäÔ˶¯½Ï10ԼͼµÄ66Æð¹¥»÷»·±ÈÔöÌí73% ¡£±ðµÄ£¬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁÖØÀ´£¬½ÓÄɵÄй¥»÷Á´£¬Ã°³äÁË¿Í»§¹ØϵÖÎÀíƽ̨HubSpot¡¢Êý¾ÝÖÎÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈÖÖÖÖÓªÒµÏà¹ØÈí¼þÀ´Èö²¥ ¡£


https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/


6¡¢ResecurityÐû²¼2024ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ


12ÔÂ21ÈÕ£¬ResecurityÐû²¼ÁË2024ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ ¡£±¨¸æÕ¹ÍûµÄÖ÷ÒªÇ÷ÊÆ°üÀ¨£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷Ô˶¯ÔöÌí¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍ×ÔÈ»Æø£©ºÍºË²¿·ÖµÄÍøÂç¹¥»÷ÔöÌí¡¢È˹¤ÖÇÄÜ£¨AI£©ÎäÆ÷»¯½«·ÉËÙÉú³¤¡¢Öǻ۶¼»áºÍÈÕÒæÑÏËàµÄÍøÂçÇå¾²ÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö ¡£¶Ô2024ÄêµÄÕ¹ÍûÕ¹ÏÖÁËһֱת±äµÄÍþв̬ÊÆ£¬±Þ²ß×éÖ¯ºÍÕþ²ßÖƶ©Õß¼á³ÖСÐIJ¢Ñ¸ËÙ˳ӦзºÆðµÄÌôÕ½ ¡£


https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast