Guardian HealthcareÖØ×éʱ´úÔâStormousÀÕË÷Èí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2024-11-12

1. Guardian HealthcareÖØ×éʱ´úÔâStormousÀÕË÷Èí¼þ¹¥»÷


11ÔÂ8ÈÕ£¬±öϦ·¨ÄáÑÇÖݵÄGuardian HealthcareÔÚÖØ×éʱ´úÔâÓöÁËStormousÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ3GB°üÀ¨Êܱ£»¤µÄ»¼Õß¿µ½¡ÐÅÏ¢µÄÎļþ±»Ð¹Â¶£¬Ö»¹ÜδÉæ¼°EMRϵͳ»òÕû¸öÊý¾Ý¿â¡£DataBreachesÊÔͼÁªÏµGuardian HealthcareÏàʶӦ¶Ô²½·¥£¬µ«Î´»ñ»ØÓ¦¡£¾ÝStormous½²»°ÈË͸¶£¬¹¥»÷Õßͨ¹ýOffice»ñÈ¡Á˶à¸öÕË»§»á¼ûȨÏÞ£¬Ã°³äÕË»§Õë¶ÔGuardianµÄÒ»×éÒªº¦Ô±¹¤»òȺ×éÌᳫ¹¥»÷£¬7GBÊý¾Ý±»ÌáÈ¡£¬ÆäÖÐ3GB±»Ð¹Â¶¡£Ö»¹ÜGuardianÒÑÖªÏþÈëÇÖÊÂÎñ²¢ÓëStormousÓйý½Ó´¥£¬µ«Î´½ÓÄÉÖØ´ó·´Ó¦£¬µ¼ÖÂÊý¾Ý×îÖÕ±»Ð¹Â¶¡£Stormous»¹Ö¤Êµ£¬GuardianµÄÎļþÔÚ¹¥»÷ʱ´ú±»¼ÓÃÜ¡£È»¶ø£¬ÏÖÔÚÉв»ÇåÎúGuardianÊÇ·ñÓпÉÓñ¸·Ý»ò»¼ÕßÊý¾ÝÊÇ·ñÒò¹¥»÷¶øÊÜËð»òɥʧ£¬ÊÜÓ°Ï컼Õß¿ÉÄÜÒ²²»ÖªÇé¡£


https://databreaches.net/2024/11/08/in-the-midst-of-restructuring-guardian-healthcare-hit-by-ransomware-attack/


2. AT&TÔâÓö´ó¹æÄ£Êý¾Ýй¶£¬Êý°ÙÍò¿Í»§ÐÅÏ¢ÃæÁÙΣº¦


11ÔÂ8ÈÕ£¬AT&T½üÆÚÔâÓöÁË´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Êý°ÙÍò¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ2022Äê5ÔÂÖÁ10Ô¼°2023Äê1ÔÂʱ´ú±»µÁ£¬²¢ÓÚ2024Äê4Ô±»·¢Ã÷¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëºÍÕË»§ÏêϸÐÅÏ¢£¬µ«²»º¬Í¨»°ÄÚÈÝ¡¢¶ÌÐÅ»òÉç»áÇå¾²ºÅÂë¡£´Ë´ÎÊÂÎñÓ°ÏìÉîÔ¶£¬Ê¹¿Í»§ÃæÁÙÉí·Ý͵ÇÔºÍڲƭµÄΣº¦£¬Í¬Ê±Ëðº¦ÁËAT&TµÄÉùÓþ¡£¾ÝÐÅ£¬Ð¹Â¶ÊÂÎñÓëδ¾­ÊÚȨµÄСÎÒ˽¼Ò»á¼ûAT&TϵͳÓйØ£¬¶øÏêϸµÄÈëÇÖϸ½ÚÉв»ÇåÎú¡£´Ë´ÎйÃÜÊÂÎñ»¹Òý·¢ÁËÈËÃǶÔAT&TÊÇ·ñ×ñÊØÐÐÒµ±ê×¼ºÍ¹æÔòµÄÖÊÒÉ¡£ÎªÓ¦¶Ô´Ë´ÎÊÂÎñ£¬AT&TÏòÊÜÓ°ÏìµÄ¿Í»§ÌṩÃâ·ÑÐÅÓüà¿Ø·þÎñ£¬²¢ÊµÑéÁËÌØÁíÍâÇå¾²²½·¥¡£Í¬Ê±£¬¸ÃÊÂÎñÒ²ÌáÐÑÎÒÃÇÍøÂçÇå¾²²½·¥µÄÖ÷ÒªÐÔ£¬×éÖ¯±ØÐè½ÓÄÉ×Ô¶¯²½·¥±£»¤¿Í»§ÐÅÏ¢£¬²¢´ÓÒ»×îÏȾͱÜÃâйÃÜÊÂÎñ±¬·¢¡£×÷Ϊ¿Í»§£¬ÎÒÃÇÒ²Ó¦¼á³ÖСÐÄ£¬Ç×½ü¼à¿ØÕË»§Ô˶¯£¬¸ü¸ÄÃÜÂë²¢ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤£¬Ë¼Á¿¶³½áÐÅÓñ¨¸æ£¬ÒÔ¼°ÊµÊ±ÏàʶÍøÂçÇå¾²ÐÂÎźÍ×î¼Ñʵ¼ù£¬ÒÔ½µµÍ³ÉΪÍøÂç·¸·¨Êܺ¦ÕßµÄΣº¦¡£


https://www.cyberdefensemagazine.com/the-att-phone-records-stolen/


3. ÑÇÂíÑ·¼°¶à¼Ò×ÅÃûÆóÒµÔâMOVEitÊý¾Ý͵ÇÔ¹¥»÷£¬Ô±¹¤ÐÅϢй¶


11ÔÂ11ÈÕ£¬ÑÇÂíѷ֤ʵ£¬ÔÚ2023Äê5Ô±¬·¢ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°280¶àÍòÐÐÔ±¹¤ÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢ÐÞ½¨Î»Öú͵ç×ÓÓʼþµØµãµÈ£¬ÕâЩÊý¾ÝÊÇ´ÓÒ»¼ÒµÚÈý·½·þÎñÌṩÉ̵ÄϵͳÖб»µÁµÄ£¬²¢ÔÚºÚ¿ÍÂÛ̳Éϱ»Ð¹Â¶¡£¾Ý³Æ£¬´Ë´Îй¶ÊÇÓÉÍþвÐÐΪÕßNam3L3ssËùΪ£¬Ëû»¹Ð¹Â¶ÁËÆäËû25¼Ò¹«Ë¾µÄÊý¾Ý¡£ÕâЩÊý¾Ý͵ÇÔ¹¥»÷ʹÓÃÁËMOVEit TransferÇå¾²Îļþ´«Êäƽ̨ÖеÄÁãÈÕÇå¾²Îó²î£¬Ó°ÏìÁËÈ«ÇòÊý°Ù¼Ò×éÖ¯£¬°üÀ¨åÚÏë¡¢»ÝÆÕ¡¢TIAA¡¢Ê©Íß²¼¡¢»ã·áÒøÐС¢´ïÃÀº½¿Õ¡¢Âóµ±Àͺʹ󶼻áÈËÊÙµÈ×ÅÃû¹«Ë¾¡£¾Ý³Æ£¬ÕâЩÊý¾ÝÊÇ´ÓÒ»¼Ò¹©Ó¦ÉÌÄÇÀï±»µÁµÄ£¬ÏÖÔÚÒÑ×÷ΪÊÜÓ°Ïì¿Í»§µÄµ¥¶ÀÊý¾Ý¼¯Ðû²¼¡£ÍøÂç·¸·¨ÍÅ»ïËæºó×îÏÈÀÕË÷Êܺ¦Õߣ¬²¢ÔÚ°µÍø×ß©ÍøÕ¾ÉÏ̻¶ÁËËûÃǵÄÃû×Ö¡£ÕâЩ¹¥»÷µÄЧ¹ûÑÏÖØ£¬µ¼ÖÂÊýÍòÍòÈ˵ÄÊý¾Ý±»µÁ£¬±»ÓÃÓÚÀÕË÷ÍýÏë»ò鶵½ÍøÉÏ¡£ÑÇÂíÑ·ÌåÏÖ£¬±»ÈëÇֵĹ©Ó¦ÉÌÖ»ÄÜ»á¼ûÔ±¹¤ÁªÏµÐÅÏ¢£¬Ã»ÓÐÃô¸ÐµÄÔ±¹¤ÐÅÏ¢±»»á¼û»òÇÔÈ¡£¬¸Ã¹©Ó¦ÉÌÒѾ­ÐÞ²¹ÁËÇå¾²Îó²î¡£


https://www.bleepingcomputer.com/news/security/amazon-confirms-employee-data-breach-after-vendor-hack/


4. ÐÂÀÕË÷Èí¼þ¼Ò×å¡°Ymir¡±Õ¸Â¶Í·½Ç£¬ÓëRustyStealer¶ñÒâÈí¼þÓйØÁª


11ÔÂ11ÈÕ£¬½üÆÚÒ»ÖÖÃûΪ¡°Ymir¡±µÄÐÂÐÍÀÕË÷Èí¼þ¼Ò×åÔÚÒ°Íâ±»·¢Ã÷£¬ËüÓëÒÑÖªµÄRustyStealer¶ñÒâÈí¼þ¼Ò×åÓйØÁª¡£YmirÀÕË÷Èí¼þÒÔÆäÄÚ´æÖ´ÐС¢Ê¹Ó÷ÇÖÞÁÖ¼ÓÀ­Óï×¢ÊÍ¡¢PDFÀÕË÷Ìõ¼Ç¼°À©Õ¹ÉèÖÃÑ¡ÏîµÈÌصãÖø³Æ¡£¾Ý¿¨°Í˹»ùʵÑéÊÒÑо¿Ö°Ô±ÆÊÎö£¬Ymirͨ³£ÔÚRustyStealerƾ֤ÍøÂ繤¾ßÉø͸ĿµÄϵͳºó°²ÅÅ£¬Ê¹ÓøßȨÏÞÕÊ»§¾ÙÐÐδÊÚȨ»á¼ûºÍºáÏòÒƶ¯¡£¹¥»÷ÕßʹÓÃWinRM¡¢PowerShellµÈ¹¤¾ß£¬²¢×°ÖÃProcess Hacker¡¢Advanced IP ScannerµÈ£¬Ö´ÐÐÓëSystemBC¶ñÒâÈí¼þÏà¹ØµÄ¾ç±¾£¬½¨ÉèÉñÃØͨµÀ¡£ÔÚÀο¿×¤×ãµã²¢¿ÉÄÜÇÔÈ¡Êý¾Ýºó£¬Ymir×÷Ϊ×îÖÕÓÐÓÃÔغɱ»°²ÅÅ¡£YmirÍêÈ«´ÓÄÚ´æÖÐÔËÐУ¬Ê¹ÓÃÌض¨º¯ÊýÌӱܼì²â£¬Ö´ÐÐϵͳÕì̽£¬×èÖ¹¼ÓÃÜÒªº¦ÏµÍ³Îļþ£¬²¢Ê¹ÓÃChaCha20Á÷ÃÜÂë¼ÓÃÜÎļþ¡£Ëü»¹ÐÞ¸ÄWindows×¢²á±íÒÔÏÔʾÀÕË÷ÇëÇ󣬲¢¿ÉÄÜʹÓÃPowerShellɾ³ý¿ÉÖ´ÐÐÎļþÒÔÌÓ±ÜÆÊÎö¡£Ö»¹ÜYmirÉÐ佨ÉèÊý¾Ýй¶ÍøÕ¾£¬µ«¿¨°Í˹»ùÖÒÑԳƣ¬Ëü¿ÉÄÜѸËÙ³ÉΪһÖÖÆÕ±éµÄÍþв¡£


https://www.bleepingcomputer.com/news/security/new-ymir-ransomware-partners-with-rustystealer-in-attacks/


5. Hot TopicµÈÈýÆ·ÅÆÊý¾Ýй¶£¬5690ÍòÕË»§ÐÅÏ¢ÔâÆعâ


11ÔÂ11ÈÕ£¬¾ÝHave I Been PwnedÖÒÑÔ£¬Hot Topic¡¢Box LunchºÍTorrid¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢Ô⵽й¶£¬Éæ¼°56904909¸öÕË»§¡£Ð¹Â¶ÐÅÏ¢°üÀ¨È«Ãû¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÏÖʵµØµã¡¢¹ºÖÃÀúÊ·ÒÔ¼°²¿·ÖÐÅÓÿ¨Êý¾Ý¡£2024Äê10ÔÂ21ÈÕ£¬Ò»ÃûÍþв·Ö×ÓÔÚBreachForumsÉÏÉù³Æ´ÓÕâÈý¼Ò¹«Ë¾ÇÔÈ¡ÁË3.5ÒÚÌõÓû§¼Í¼£¬²¢ÊÔͼÒÔ2ÍòÃÀÔª³öÊÛÊý¾Ý¿â£¬Í¬Ê±ÒªÇóHot TopicÖ§¸¶10ÍòÃÀÔªÊê½ð¡£Hot TopicÊÇÒ»¼ÒÃÀ¹úÁãÊÛÁ¬Ëøµê£¬×¨ÃÅ´ÓÊ·´Ö÷Á÷ÎÄ»¯Ïà¹ØµÄ´ò°ç¡¢ÅäÊκÍÌØÐíÒôÀÖÉÌÆ·¡£Hot Topicδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£Êý¾ÝÆÊÎö¹«Ë¾Atlas Privacy±¨¸æ³Æ£¬ÏÖʵÊÜÓ°Ïì¿Í»§ÊýΪ5400Íò£¬°üÀ¨2500Íò¸öÈõÃÜÂë¼ÓÃܵÄÐÅÓÿ¨ºÅÂë¡£Êý¾Ýй¶Ëƺõ±¬·¢ÔÚ10ÔÂ19ÈÕ£¬Êý¾Ý¿ç¶È´Ó2011Äêµ½¸ÃÈÕÆÚ¡£Hot TopicÒѽ¨ÉèÍøÕ¾¹©¿Í»§¼ì²éÐÅÏ¢ÊÇ·ñй¶¡ £¿ÉÄÜÊÜÓ°ÏìµÄ¿Í»§Ó¦Ð¡ÐÄÍøÂç´¹ÂÚ¹¥»÷£¬²¢Ç×½ü¼à¿Ø²ÆÎñÕË»§¡£


https://www.bleepingcomputer.com/news/security/hibp-notifies-57-million-people-of-hot-topic-data-breach/


6. ¹þÀï²®¶ÙÔâÀÕË÷Èí¼þ¹¥»÷£¬Ëðʧ3500ÍòÃÀÔª²¢ÃæÁÙÊý¾Ýй¶Σº¦


11ÔÂ11ÈÕ£¬¹þÀï²®¶ÙÊÇÒ»¼ÒÔÚ70¸ö¹ú¼ÒÓµÓÐ48000ÃûÔ±¹¤¡¢ÄêÊÕÈëÁè¼Ý230.2ÒÚÃÀÔªµÄÈ«ÇòÄÜÔ´ÐÐÒµ²úÆ·ºÍ·þÎñ¹©Ó¦ÉÌ£¬ÔÚ2024Äê8ÔÂÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷¡£´Ë´Î¹¥»÷µ¼Ö¸ù«Ë¾¹Ø±ÕITϵͳ²¢¶Ï¿ª¿Í»§ÅþÁ¬£¬Ôì³ÉÔ¼3500ÍòÃÀÔªµÄËðʧ¡£¾ÝÏòÃÀ¹ú֤ȯÉúÒâίԱ»áÌá½»µÄÎļþÏÔʾ£¬Î´¾­ÊÚȨµÄµÚÈý·½»á¼ûÁËÆäϵͳ£¬¹þÀï²®¶ÙËæºó¹Ø±ÕÁ˲¿·ÖIT»ù´¡ÉèÊ©ÒÔÓ¦¶ÔÕâÒ»Îó²î¡£¼¸Ììºó£¬ÀÕË÷Èí¼þÍÅ»ïRansomHub¶Ô´Ë´ÎÏ®»÷ÈÏÕ棬²¢´Ó¹«Ë¾ÍøÂçÖÐÇÔÈ¡ÁËÊý¾Ý£¬µ«ÏêϸÐÅÏ¢ÀàÐͺ͹æÄ£ÈÔÔÚÊÓ²ìÖС£Ö»¹Ü¸ÃÊÂÎñ¶Ô¹þÀï²®¶ÙµÄ²ÆÎñÓ°ÏìÓÐÏÞ£¬µ«ÈôÊÇÀÕË÷ÍÅ»ï³öÊÛ»òй¶¹þÀï²®¶Ù¿Í»§µÄÊý¾Ý£¬¸Ã¹«Ë¾¿ÉÄÜÅöÃæÁÙÖ´·¨ËßËϺÍÌØÁíÍâ²ÆÎñ±¾Ç®¡£¹þÀï²®¶Ù¹«Ë¾¶­Ê³¤¡¢×ܲüæÊ×ϯִÐйٽܷò¡¤Ã×ÀÕÌåÏÖ£¬Ö»¹ÜÊܵ½ÍøÂçÇå¾²ÊÂÎñºÍ·ç±©µÄÓ°Ï죬¹«Ë¾¶Ô×ÔÓÉÏÖ½ðÁ÷ºÍ¹É¶«ÏÖ½ð»Ø±¨µÄÕûÄêÔ¤ÆÚ¼á³ÖÎȹÌ¡£


https://www.bleepingcomputer.com/news/security/halliburton-reports-35-million-loss-after-ransomware-attack/