Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶

Ðû²¼Ê±¼ä 2023-12-28

1¡¢Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶


¾ÝýÌå12ÔÂ26ÈÕ±¨µÀ £¬¶í¿ËÀ­ºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷¡£Integris HealthÌåÏÖ £¬ËûÃÇÔÚÒâʶµ½¿ÉÒɻºóÁ¬Ã¦½ÓÄÉÁ˲½·¥ £¬²¢ÊӲ칥»÷µÄÐÔ×Ӻ͹æÄ£ £¬È·¶¨²¿·ÖÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»»á¼û¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖÐ £¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡Áè¼Ý200Íò»¼ÕßµÄÊý¾Ý¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕ³öÊÛ¸ÃÊý¾Ý¿â £¬ÔÚ´Ë֮ǰ»¼ÕßÓÐʱ»úɾ³ý×Ô¼ºµÄÊý¾Ý¡£ÕâЩÓʼþ°üÀ¨Ò»¸öTorÍøÕ¾Á´½Ó £¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý £¬ÔÊÐí»á¼ûÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔªÉó²éÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/


2¡¢BarracudaÐÞ¸´±»UNC4841ʹÓõÄÎó²îCVE-2023-7102


¾Ý12ÔÂ27ÈÕ±¨µÀ £¬BarracudaÐû²¼ÁËÇå¾²¸üР£¬ÐÞ¸´µç×ÓÓʼþÇå¾²Íø¹Ø(ESG)×°±¸ÖеÄÎó²î£¨CVE-2023-7102£©¡£BarracudaÒÑÈ·¶¨ £¬Óй¥»÷ÕßʹÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄí§Òâ´úÂëÖ´ÐÐ(ACE)Îó²îÀ´·Ö·¢ÌØÖƵÄExcelÓʼþ¸½¼þ £¬ÒÔ¹¥»÷ESG×°±¸¡£¼ÌUNC4841ʹÓøÃACEÎó²îÖ®ºó £¬Barracuda·¢Ã÷²¿·ÖESG×°±¸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå¡£BarracudaÓÚ12ÔÂ21ÈÕÐÞ¸´Á˸ÃÎó²î £¬Çå¾²¸üлá×Ô¶¯Ó¦Óà £¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐС£


https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html


3¡¢ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼±»ÒÔ7.5ÍòÃÀÔª³öÊÛ


ýÌå12ÔÂ26ÈÕ³Æ £¬ÒÁÀÊ23¼Ò°ü¹Ü¹«Ë¾1.6ÒÚ¿Í»§¼Í¼ÕýÔÚÒÔԼĪ75000ÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐÓÃÐÔ £¬²¢ÌåÏÖ¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢ÊÖÒÕ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ¡£³öÊÛµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢ £¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùÓÐÊý¾Ý¡£×Ô8ÔÂÒÔÀ´ £¬×Ô³Æ"ÒÁÀʰü¹ÜÒµ×î´óµÄÐÅÏ¢ÊÖÒÕ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ö±½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø»á¼û¡£


https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/


4¡¢EasyPark²¿·Ö¿Í»§µÄÊý¾Ýй¶½¨ÒéСÐÄ´¹ÂÚÕ©Æ­


ýÌå12ÔÂ26ÈÕ±¨µÀ £¬Å·ÖÞ×î´óµÄÍ£³µÓ¦ÓÃÔËÓªÉÌEasyPark Group²¿·Ö¿Í»§µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ £¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍÐÅÓÿ¨ºÅµÈÐÅϢй¶¡£¸ÃÊÂÎñÉæ¼°IBAN»òÐÅÓÿ¨ºÅÂë £¬½¨Òé¿Í»§Ð¡ÐÄÍøÂç´¹ÂÚÕ©Æ­¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°ÏìÓû§µÄÊýÄ¿ £¬µ«Æä½²»°ÈË³Æ £¬´ó´ó¶¼ÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ¡£µ½ÏÖÔÚΪֹ £¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó £¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»Ê¹Óûòй¶¡£


https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/


5¡¢NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ21ÈÕ £¬NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à £¬Îª146Æð£¨Õ¼±È33%£© £¬±È10Ô£¨114Æð£©ÔöÌíÁË28% £¬Æä´ÎÊÇÖÜÆÚÐÔÏûºÄÆ·£¨18%£©ºÍÒ½ÁƱ£½¡£¨11%£©ÐÐÒµ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍÅ»ï £¬Æä»î¶¯½Ï10ԼͼµÄ66Æð¹¥»÷»·±ÈÔöÌí73%¡£±ðµÄ £¬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁÖØÀ´ £¬½ÓÄɵÄй¥»÷Á´ £¬Ã°³äÁ˿ͻ§¹ØÏµ¹ÜÀíÆ½Ì¨HubSpot¡¢Êý¾Ý¹ÜÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈÖÖÖÖÓªÒµÏà¹ØÈí¼þÀ´Èö²¥¡£


https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/


6¡¢ResecurityÐû²¼2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ


12ÔÂ21ÈÕ £¬ResecurityÐû²¼ÁË2024ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ¡£±¨¸æÕ¹ÍûµÄÖ÷ÒªÇ÷ÊÆ°üÀ¨£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷»î¶¯ÔöÌí¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍ×ÔÈ»Æø£©ºÍºË²¿·ÖµÄÍøÂç¹¥»÷ÔöÌí¡¢È˹¤ÖÇÄÜ£¨AI£©ÎäÆ÷»¯½«·ÉËÙÉú³¤¡¢Öǻ۶¼»áºÍÈÕÒæÑÏËàµÄÍøÂçÇå¾²ÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö¡£¶Ô2024ÄêµÄÕ¹ÍûÕ¹ÏÖÁËһֱת±äµÄÍþÐ²Ì¬ÊÆ £¬±Þ²ß×éÖ¯ºÍÕþ²ßÖÆ¶©Õß¼á³ÖСÐIJ¢Ñ¸ËÙ˳ӦзºÆðµÄÌôÕ½¡£


https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast