Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶

Ðû²¼Ê±¼ä 2023-12-28

1¡¢Integris HealthÔâµ½¹¥»÷Áè¼Ý200Íò»¼ÕßÐÅϢй¶


¾ÝýÌå12ÔÂ26ÈÕ±¨µÀ£¬¶í¿ËÀ­ºÉÂíÖݵÄIntegris HealthÔâµ½ÀÕË÷¹¥»÷¡£Integris HealthÌåÏÖ£¬ËûÃÇÔÚÒâʶµ½¿ÉÒɻºóÁ¢¼´½ÓÄÉÁË´ëÊ©£¬²¢ÊӲ칥»÷µÄÐÔÖʺͷ¶Î§£¬È·¶¨²¿ÃÅÎļþ¿ÉÄÜÒÑÓÚ11ÔÂ28ÈÕ±»·ÃÎÊ¡£ÔÚ12ÔÂ24ÈÕ·¢Ë͸ø»¼ÕßµÄÀÕË÷ÓʼþÖУ¬ºÚ¿Í³ÆËûÃÇÒÑÇÔÈ¡Áè¼Ý200Íò»¼ÕßµÄÊý¾Ý¡£ËûÃǽ«ÓÚ2024Äê1ÔÂ5ÈÕ³öÊÛ¸ÃÊý¾Ý¿â£¬ÔÚ´Ë֮ǰ»¼ÕßÓлú»áɾ³ý×Ô¼ºµÄÊý¾Ý¡£ÕâЩÓʼþ°üÂÞÒ»¸öTorÍøÕ¾Á´½Ó£¬ÁгöÁËÔ¼4674000È˵ı»µÁÊý¾Ý£¬ÔÊÐí·ÃÎÊÕßÖ§¸¶50ÃÀԪɾ³ýÊý¾Ý»òÖ§¸¶3ÃÀÔª¼ì²ìÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/integris-health-patients-get-extortion-emails-after-cyberattack/


2¡¢BarracudaÐÞ¸´±»UNC4841ÀûÓõÄ©¶´CVE-2023-7102


¾Ý12ÔÂ27ÈÕ±¨µÀ£¬BarracudaÐû²¼ÁËÄþ¾²¸üУ¬ÐÞ¸´µç×ÓÓʼþÄþ¾²Íø¹Ø(ESG)É豸ÖеÄ©¶´£¨CVE-2023-7102£©¡£BarracudaÒÑÈ·¶¨£¬Óй¥»÷ÕßÀûÓõÚÈý·½¿âSpreadsheet::ParseExcelÖеÄÈÎÒâ´úÂëÖ´ÐÐ(ACE)©¶´À´·Ö·¢ÌØÖƵÄExcelÓʼþ¸½¼þ£¬ÒÔ¹¥»÷ESGÉ豸¡£¼ÌUNC4841ÀûÓøÃACE©¶´Ö®ºó£¬Barracuda·¢ÏÖ²¿ÃÅESGÉ豸Éϱ»×°Á˶ñÒâÈí¼þSEASPYºÍSALTWATERµÄбäÌå¡£BarracudaÓÚ12ÔÂ21ÈÕÐÞ¸´Á˸鶴£¬Äþ¾²¸üлá×Ô¶¯Ó¦Óã¬ÎÞÐèÓû§ÊÖ¶¯Ö´ÐС£


https://securityaffairs.com/156502/breaking-news/barracuda-fixed-a-new-esg-zero-day-exploited-by-chinese-group-unc4841.html


3¡¢ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Ç¼±»ÒÔ7.5ÍòÃÀÔª³öÊÛ


ýÌå12ÔÂ26Èճƣ¬ÒÁÀÊ23¼Ò±£ÏÕ¹«Ë¾1.6ÒÚ¿Í»§¼Ç¼ÕýÔÚÒÔԼĪ75000ÃÀÔªµÄ¼Û¸ñ³öÊÛ¡£ÒÁÀÊй¶¸ú×Ùϵͳ£¨Leakfa£©ÒÑ֤ʵºÚ¿Í˵·¨µÄÓÐЧÐÔ£¬²¢ÌåÏÖ¸ÃÐÅÏ¢ÊÇͨ¹ýÈëÇÖר¼ÒÐÅÏ¢¼¼Êõ¹«Ë¾£¨Fanavaran£©µÄ»ù´¡ÉèÊ©»ñµÃµÄ¡£³öÊÛµÄÐÅÏ¢°üÂÞÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÊÖ»úµÈÐÅÏ¢£¬ÒÔ¼°¿ÉÄÜαÔìÉí·ÝËùÐèµÄËùÓÐÊý¾Ý¡£×Ô8ÔÂÒÔÀ´£¬×Ô³Æ"ÒÁÀʱ£ÏÕÒµ×î´óµÄÐÅÏ¢¼¼Êõ¹«Ë¾"µÄFanavaran¹«Ë¾Ò»Ö±½ûÓÃÆäÍøÕ¾µÄ»¥ÁªÍø·ÃÎÊ¡£


https://www.databreaches.net/troves-of-iranian-hacked-insurance-customer-data-on-sale/


4¡¢EasyPark²¿ÃÅ¿Í»§µÄÊý¾Ýй¶½¨Ò龯ÌèµöÓãÕ©Æ­


ýÌå12ÔÂ26ÈÕ±¨µÀ£¬Å·ÖÞ×î´óµÄÍ£³µÓ¦ÓÃÔËÓªÉÌEasyPark Group²¿ÃÅ¿Í»§µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÓÚ12ÔÂ10ÈÕ·¢ÏÖÁËÕâһʼþ£¬¹¥»÷µ¼Ö¿ͻ§ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍÐÅÓÿ¨ºÅµÈÐÅϢй¶¡£¸ÃʼþÉæ¼°IBAN»òÐÅÓÿ¨ºÅÂ룬½¨Òé¿Í»§¾¯ÌèÍøÂçµöÓãÕ©Æ­¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°ÏìÓû§µÄÊýÁ¿£¬µ«Æä·¢ÑÔÈ˳Æ£¬´ó¶àÊýÊÜÓ°ÏìÓû§Î»ÓÚÅ·ÖÞ¡£µ½Ä¿Ç°ÎªÖ¹£¬ºÚ¿ÍÉÐδÌá³öÊê½ðÒªÇó£¬Ò²Ã»ÓÐÖ¤¾Ý±íÃ÷Êý¾ÝÒѱ»ÀûÓûòй¶¡£


https://www.hackread.com/ringgo-parkmobile-easypark-data-breach-data-stolen/


5¡¢NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵķÖÎö³ÂËß


12ÔÂ21ÈÕ£¬NCC GroupÐû²¼¹ØÓÚ11Ô·ÝÀÕË÷¹¥»÷̬ÊƵķÖÎö³ÂËß¡£¹¤¿ØÐÐÒµÔÚ11Ô·ÝÔâµ½¹¥»÷×î¶à£¬Îª146Æð£¨Õ¼±È33%£©£¬±È10Ô£¨114Æð£©Ôö¼ÓÁË28%£¬Æä´ÎÊÇÖÜÆÚÐÔÏû·ÑÆ·£¨18%£©ºÍÒ½ÁƱ£½¡£¨11%£©ÐÐÒµ¡£LockBitÊÇ×î»îÔ¾µÄ¹¥»÷ÍŻÆä»î¶¯½Ï10ԼǼµÄ66Æð¹¥»÷»·±ÈÔö³¤73%¡£´ËÍ⣬CarbanakÔÚ11ÔµÄÀÕË÷¹¥»÷ÖоíÍÁÖØÀ´£¬½ÓÄɵÄй¥»÷Á´£¬Ã°³äÁË¿Í»§¹Øϵ¹ÜÀíƽ̨HubSpot¡¢Êý¾Ý¹ÜÀíÈí¼þVeeamºÍÕË»§¹¤¾ßXeroµÈÖÖÖÖÒµÎñÏà¹ØÈí¼þÀ´Á÷´«¡£


https://www.nccgroup.com/us/newsroom/ncc-group-monthly-threat-pulse-november-2023/


6¡¢ResecurityÐû²¼2024ÄêÍøÂçÍþв̬ÊƵÄÔ¤²â³ÂËß


12ÔÂ21ÈÕ£¬ResecurityÐû²¼ÁË2024ÄêÍøÂçÍþв̬ÊƵÄÔ¤²â³ÂËß¡£³ÂËßÔ¤²âµÄÖ÷ÒªÇ÷ÊÆ°üÂÞ£ºÕë¶ÔÉÏÊй«Ë¾µÄÀÕË÷¹¥»÷»î¶¯Ôö¼Ó¡¢Õë¶ÔÄÜÔ´£¨Ê¯ÓͺÍÌìÈ»Æø£©ºÍºË²¿ÃŵÄÍøÂç¹¥»÷Ôö¼Ó¡¢È˹¤ÖÇÄÜ£¨AI£©ÎäÆ÷»¯½«·ÉËÙÉú³¤¡¢Öǻ۶¼ÊкÍÈÕÒæÑϾþµÄÍøÂçÄþ¾²ÌôÕ½ÒÔ¼°Õë¶ÔÊý×ÖÉí·ÝµÄ¹¥»÷½«»á¼¤Ôö¡£¶Ô2024ÄêµÄÔ¤²â½ÒʾÁ˲»Í£±ä»¯µÄÍþв̬ÊÆ£¬¶Ø´Ù×éÖ¯ºÍÕþ²ßÖƶ¨Õß±£³Ö¾¯Ì貢ѸËÙÊÊӦзºÆðµÄÌôÕ½¡£


https://www.resecurity.com/blog/article/2024-cyber-threat-landscape-forecast