EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢

Ðû²¼Ê±¼ä 2024-11-26

1. EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢


11ÔÂ23ÈÕ£¬¼ÓÀû¸£ÄáÑÇÖݵÄ̫ƽÑó·Î²¿Ò½ÁƼ¯ÍÅ(PPMG)ÔâÓöÁËÑÏÖصÄÊý¾Ýй¶Ê¼þ¡£10ÔÂ25ÈÕ£¬EverestÀÕË÷Èí¼þÍŶÓÔÚ°µÍøÉÏÐû²¼ÁËPPMGµÄ»¼ÕßÐÅÏ¢£¬°üÂÞ2021ÖÁ2024ÄêµÄδ¼ÓÃܸöÈ˺ÍÊܱ£»¤½¡¿µÐÅÏ¢¡£Ð¹Â¶µÄÊý¾ÝÒÔ150¶à¸öͼÏñÎļþºÍ¶à¸ö.csvÎļþµÄÐÎʽ´æÔÚ£¬Í¼ÏñÎļþÖ÷Ҫչʾ»¼ÕßµÄÖ÷´Î±£ÏÕ¿¨¼°²¿ÃżÝÕÕÐÅÏ¢£¬¶ø.csvÎļþÔòº­¸ÇÁËÁ½ÖÜÄڵĻ¼Õß¾ÍÕï¼Ç¼£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢½¡¿µÐÅÏ¢¼°Õ˵¥ÏêÇéµÈÃô¸ÐÄÚÈÝ¡£×îÐÂÒ»ÅúÊý¾Ý½ØÖÁ10ÔÂ4ÈÕ£¬Ã¿Á½ÖܵÄ.csvÎļþ¼Ç¼×Å300µ½500Ãû»¼ÕߵľÍÕïÇé¿ö¡£È»¶ø£¬Ö±ÖÁÐÅÏ¢Ðû²¼Ê±£¬PPMGÍøÕ¾¼°ÃÀ¹úÎÀÉúÓ빫¹²·þÎñ²¿(HHS)µÄ¹«¹²Î¥¹æ¹¤¾ßÉϾùδÐû²¼Ïà¹Ø֪ͨ¡£DataBreachesÒÑÏòPPMGºÍEverest·¢ËÍѯÎÊ£¬µ«ÉÐδÊÕµ½»Ø¸´¡£


https://databreaches.net/2024/11/23/pacific-pulmonary-medical-group-patient-information-dumped-by-everest-ransomware-team/


2. Áè¼Ý2000̨Palo Alto NetworksÉ豸ÔâºÚ¿ÍÈëÇÖ


11ÔÂ21ÈÕ£¬Palo Alto Networks ³ÂËß³ÆÆä¶à´ï2000̨É豸¿ÉÄÜÒÑÔâµ½ÀûÓÃÐÂÅû¶Äþ¾²Â©¶´µÄ¹¥»÷¡£¾ÝShadowserver»ù½ð»áͳ¼Æ£¬ÃÀ¹ú£¨554Àý£©ºÍÓ¡¶È£¨461Àý£©µÄѬȾ²¡Àý×î¶à£¬ÆäËûÊÜÓ°Ïì¹ú¼Ò°üÂÞÌ©¹ú¡¢Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÍÁ¶úÆä¡¢Ó¢¹ú¡¢ÃسºÍÄÏ·Ç¡£CensysÔò·¢ÏÖ13,324¸ö¹ûȻ̻¶µÄÏÂÒ»´ú·À»ðǽ£¨NGFW£©¹ÜÀí½Ó¿Ú£¬ÆäÖÐ34%λÓÚÃÀ¹ú£¬µ«²¢·ÇËùÓÐ̻¶µÄÖ÷»ú¶¼´æÔÚ©¶´¡£Éæ¼°µÄÄþ¾²Â©¶´°üÂÞCVE-2024-0012£¨CVSS·ÖÊý9.3£©ºÍCVE-2024-9474£¨CVSS·ÖÊý6.9£©£¬ËüÃÇ¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈƹýºÍȨÏÞÌáÉý£¬Ê¹¹¥»÷ÕßÄÜÖ´ÐжñÒâ²Ù×÷¡£Palo Alto NetworksÕý×·×Ù´úºÅΪOperation Lunar PeekµÄ©¶´ÀûÓÃÇé¿ö£¬²¢¾¯¸æ³ÆÕâЩ©¶´Òѱ»ÎäÆ÷»¯£¬¿ÉÄÜÒý·¢¸ü¹ã·ºµÄÍþв»î¶¯¡£¸Ã¹«Ë¾ÒÑÊÓ²ìµÃÊÖ¶¯ºÍ×Ô¶¯É¨Ãè»î¶¯£¬²¢¶Ø´ÙÓû§¾¡¿ìÓ¦ÓÃÐÞ¸´·¨Ê½£¬ÏÞÖƹÜÀí½çÃæ·ÃÎÊ£¬ÒÔ·ÀÖ¹Íⲿ·ÃÎÊ¡£


https://thehackernews.com/2024/11/warning-over-2000-palo-alto-networks.html


3. Blue YonderÔâÀÕË÷Èí¼þ¹¥»÷£¬¹©Ó¦Á´·þÎñÖжÏÓ°Ïì¹ã·º


11ÔÂ25ÈÕ£¬¹©Ó¦Á´¹ÜÀí¹«Ë¾Blue Yonder£¨Ô­ÎªJDA Software£©£¬×÷ΪËÉϵÄ×Ó¹«Ë¾£¬ÄêÊÕÈ볬10ÒÚÃÀÔª£¬ÓµÓÐ6000ÃûÔ±¹¤£¬Îª°üÂÞDHL¡¢À×ŵ¡¢È¸³²¡¢ÌØÒ×¹º¡¢ÐǰͿ˵ÈÖªÃûÆóÒµÔÚÄÚµÄ3000Ãû¿Í»§ÌṩÈ˹¤ÖÇÄÜÇý¶¯µÄ¹©Ó¦Á´½â¾ö·½°¸¡£È»¶ø£¬¸Ã¹«Ë¾½üÆÚÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÍйܷþÎñÍйܻ·¾³·ºÆðÖжÏ£¬Ó°ÏìÁËÆä¿Í»§£¬ÌرðÊÇÓ¢¹úµÄÔÓ»õµêÁ¬Ëøµê¡£Blue YonderÒÑÓëÍⲿÍøÂçÄþ¾²¹«Ë¾ºÏ×÷Ó¦¶Ô´Ëʼþ£¬²¢ÊµÊ©Á˶àÏî·ÀÓùºÍȡ֤ЭÒ飬µ«ÔÚÆ乫¹²ÔÆ»·¾³ÖÐδ¼ì²âµ½¿ÉÒɻ¡£Ä¿Ç°£¬Blue YonderÈÔÔÚ´¦ÖöàÖÖ»Ö¸´¼Æı£¬µ«ÉÐδ͸¶ȫÃæ»Ö¸´µÄ¾ßÌåʱ¼ä±í¡£ÊÜÓ°ÏìµÄ¿Í»§£¬ÈçMorrisonsºÍSainsbury£¬ÒѽÓÄÉÓ¦¼±´ëÊ©À´¿Ë·þÕâÒ»ÖжÏ¡£½ØÖÁ×îÐÂÏûÏ¢£¬Blue YonderÉÐδÐû²¼ÓйØÇé¿öµÄ×îнøÕ¹£¬ÍƲâÆäÍйܷþÎñ»·¾³ÈÔÈ»Êܵ½Ó°Ï졣Ŀǰ£¬ÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÐû²¼¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£


https://www.bleepingcomputer.com/news/security/blue-yonder-ransomware-attack-disrupts-grocery-store-supply-chain/


4. MetaÖØÈ­¹¥»÷ɱÖíÕ©Æ­£¬¹Ø±Õ200ÍòÆÛÕ©ÕË»§


11ÔÂ24ÈÕ£¬×Ô½ñÄêÄê³õÒÔÀ´£¬MetaÒѹرÕÆäƽ̨ÉÏ200Íò¸öÓëɱÖíÕ©Æ­ºÍÆäËûÆÛÕ©ÐÐΪÏà¹ØµÄÕË»§£¬ÕâЩÕË»§Ö÷ÒªÀ´×ÔÃåµé¡¢ÀÏÎΡ¢°¢ÁªÇõ¡¢·ÆÂɱöºÍ¼íÆÒÕ¯µÈÒÔ¡°Õ©Æ­Å«Á¥¡±»î¶¯ÎÅÃûµÄ¹ú¼Ò¡£ÕâЩթƭÖÐÐÄͨ¹ýÐû²¼Ðé¼ÙÕÐƸÐÅÏ¢ÒýÓÕÇóÖ°Õߣ¬Ç¿ÆÈËûÃÇ´ÓÊÂÍøÂçÕ©Æ­£¬²¢ÒÔÈËÉíÅ°´ý×÷ΪÍþв¡£MetaÓëÕâЩ¹ú¼ÒµÄÖ´·¨»ú¹¹ºÏ×÷£¬·ÖÏíÇ鱨£¬¹¥»÷Õ©Æ­ÐÐΪ¡£ÆäÖУ¬¡°É±Öí¡±Õ©Æ­ÊÇÒ»ÖÖÆÆ»µÐԵĽðÈÚͶ×ÊÆ­¾Ö£¬ÒÀÀµÓÚºã¾ÃÀûÓú͸߼¶ÆÛÆ­£¬Ä¿±êÓû§±é²¼È«Çò¡£ËäÈ»¿´ËÆÏÝÈëÆ­¾ÖµÄÈËÊý²»¶à£¬µ«ÒѳÉΪÕâЩÓÐ×éÖ¯·¸×OÍŵľ޶îÊÕÈëÀ´Ô´¡£Meta½ÓÄÉÁËһϵÁдëÊ©£¬°üÂÞÖ´ÐÐΣÏÕ×éÖ¯ºÍ¸öÈËÕþ²ß¡¢ÀûÓÃÐÐΪºÍ¼¼ÊõÐźÅʶ±ðºÍ×èÖ¹Õ©Æ­Ïà¹ØÕË»§ºÍ»ù´¡ÉèÊ©¡¢ÓëÈ«ÇòÖ´·¨²¿ÃźÏ×÷¡¢Óë¿Æ¼¼¹«Ë¾ºÍ×éÖ¯ºÏ×÷¡¢ÌṩÓû§±£»¤¹¦Ð§ºÍ½¨ÒéµÈ£¬ÒÔ¼ì²âºÍ×èÖ¹ÕâЩƭ¾Ö£¬±£»¤Óû§ÃâÊÜÆÛÕ©¡£MetaÌáÐÑÓû§½÷É÷¿´´ýδ¾­ÇëÇóµÄͨÐÅ£¬ÖÆÖ¹ÔÚÉ罻ýÌåºÍͨѶƽ̨ÉϽèÇ®»ò¼ÓÈë¿ÉÒÉͶ×ʼƻ®¡£


https://www.bleepingcomputer.com/news/security/meta-removes-over-2-million-accounts-pushing-pig-butchering-scams/


5. Ì©¹ú¾¯·½ÆÆ»ñ´ó¹æÄ£¶ÌÐŵöÓãÕ©Æ­°¸£¬´þ²¶»õ³µË¾»ú


11ÔÂ24ÈÕ£¬Ì©¹ú¾¯·½ÀÖ³ÉÆÆ»ñÒ»Æð´ó¹æÄ£¶ÌÐÅÕ©Æ­°¸£¬´þ²¶ÁË»õ³µË¾»ú¡£¸Ã»õ³µ×°±¸Á˶ÌÐÅ·¢ÉäÆ÷£¬Äܹ»ÔÚ3¹«ÀﷶΧÄÚÿСʱ·¢ËÍ10ÍòÌõµöÓã¶ÌÐÅ¡£Õ©Æ­¶ÌÐÅÉù³ÆÓû§µÄ»ý·Ö¼´½«¹ýÆÚ£¬ÒýÓÕËûÃǵã»÷°üÂÞ¡°aisthailand¡±×Ö·û´®µÄµöÓãÍøÕ¾Á´½Ó£¬¸ÃÁ´½Óαװ³ÉÌ©¹ú×î´óÒƶ¯µç»°ÔËÓªÉÌAISµÄ¹Ù·½ÍøÕ¾¡£Óû§Ò»µ©µã»÷Á´½Ó²¢ÊäÈëÐÅÓÿ¨ÐÅÏ¢£¬ÕâЩÐÅÏ¢¾Í»á±»·¢»Ø¸øÕ©Æ­ÍŻÓÃÓÚÔÚÆäËû¹ú¼Ò½øÐÐδ¾­ÊÚȨµÄ½»Òס£¾ÝϤ£¬¸ÃÕ©Æ­ÍŻﲿÃųÉÔ±ÔÚÌ©¹ú£¬²¿ÃÅÔÚº£Í⣬ͨ¹ý˽ÈËTelegramƵµÀЭµ÷Ðж¯¡£ÔÚÈýÌìÄÚ£¬¸ÃÍÅ»ïÏòÂü¹È¾ÓÃñ·¢ËÍÁ˽üÒ»°ÙÍòÌõÕ©Æ­¶ÌÐÅ¡£¾¯·½ÕýÔÚ×·²¶ÖÁÉÙÁíÍâÁ½ÃûÍÅ»ï³ÉÔ±£¬²¢µÃµ½ÁËAISµÄЭÖú¶¨Î»¶ÌÐÅ·¢ÉäÆ÷¡£¾¡¹ÜÍøÂçµöÓãÐÅÏ¢µÄÀÖ³ÉÂÊÒò¹«ÖÚÒâʶÌá¸ß¶ø½µµÍ£¬µ«ÔÚÈË¿ÚÃܼ¯µØÓòÒÔ¸ßËÙÁ÷´«Ê±£¬ÈÔÄÜΪ·¸×ïÕß´øÀ´¿É¹ÛÊÕÒæ¡£


https://www.bleepingcomputer.com/news/security/bangkok-busts-sms-blaster-sending-1-million-scam-texts-from-a-van/


6. ΢Èí¶àÏîºËÐÄ·þÎñÔâÓöÈ«ÇòÐÔ´ó¹æÄ£ÖжÏ


11ÔÂ25ÈÕ£¬Î¢ÈíµÄ¶àÏîºËÐÄ·þÎñ£¬°üÂÞMicrosoft 365¡¢Exchange Online¡¢TeamsºÍOutlook£¬ÔâÓöÁËÈ«ÇòÐԵĴó¹æÄ£ÖжÏ£¬µ¼ÖÂÓû§ÔÚÉ罻ýÌåÉϷ׷׳ÂËßÎÞ·¨·¢ËÍÓʼþ¡¢ÍøÕ¾Í߽⼰´íÎóÒ³ÃæµÈÎÊÌâ¡£ÔÚÁùСʱÄÚ£¬DowndetectorÒÑÊÕµ½Êýǧ·ÝÓû§³ÂËߣ¬ÊÜÓ°ÏìµÄÓû§»¹ÌåÏÖÔÚÁ¬½ÓOneDrive¡¢Purview¡¢CopilotµÈ·þÎñʱҲÓöµ½ÁËÕÏ°­¡£Î¢ÈíËæºóÈÏ¿ÉÎÊÌâ´æÔÚ£¬²¢ÔÚƽ̨ÉÏÐû²¼ÉùÃ÷³ÆÕýÔڻعöÏà¹Ø±ä»»²¢Ñ°ÕÒÆäËû»º½â´ëÊ©£¬Í¬Ê±ÁгöÁËÊÜÓ°ÏìµÄ·þÎñºÍʹÓó¡¾°¡£¹ÊÕÏÁ¬Ðø11¸öСʱºó£¬Î¢ÈíÑ¡ÔñÊÖ¶¯ÖØÆô·þÎñÆ÷£¬²¢ÔÚ¹ÜÀíÖÐÐĵÄʼþ³ÂËßÖÐÈ·ÈϸÃÖжÏ×èÖ¹ÁË¿Í»§Í¨¹ý¶àÖÖ·½Ê½·ÃÎÊExchange Online¡£Í¬Ê±£¬Ò»Ð©¿Í»§ÔÚʹÓÃMicrosoft Fabric¡¢Microsoft BookingsºÍMicrosoft Defender for Office 365µÈ·þÎñʱҲÓöµ½ÁËÎÊÌ⡣΢ÈíÌåÏÖÒÑ¿ªÊ¼²¿ÊðÐÞ¸´·¨Ê½£¬²¢ÊÖ¶¯ÖØÆô²¿ÃŲ»½¡¿µµÄ»úÆ÷£¬µ«Ö±µ½25ÈÕ12µã33·Ö£¨EST£©£¬²¿ÊðµÄÐÞ¸´·¨Ê½ÉÐδµ¼ÖÂÍêÈ«µÄ·þÎñ»Ö¸´¡£18µã25·Ö£¨EST£©£¬Î¢Èí½øÒ»²½·ÖÏíÁËʼþÐÅÏ¢£¬³ÆʹÊÊÇÓÉÒ»¸öµ¼Ö·þÎñÆ÷·ÓÉÖØÊÔÇëÇó¼¤ÔöµÄ¸ü¸ÄÒýÆðµÄ£¬ÍŶÓÕýÔÚ»ý¼«Ö´ÐкóÐøÐж¯£¬²¢Å¬Á¦»Ö¸´È«²¿¹¦Ð§¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-impacts-exchange-online-teams-sharepoint/