ÃÀ¹úÊ·ÉÏ×î´óÒ½ÁÆÊý¾Ýй¶Ê¼þ£ºChange HealthcareÔâÀÕË÷Èí¼þ¹¥»÷
Ðû²¼Ê±¼ä 2025-02-061. ÃÀ¹úÊ·ÉÏ×î´óÒ½ÁÆÊý¾Ýй¶Ê¼þ£ºChange HealthcareÔâÀÕË÷Èí¼þ¹¥»÷
1ÔÂ25ÈÕ£¬ÁªºÏ½¡¿µ¼¯ÍÅ×Ó¹«Ë¾Change HealthcareÔÚ2024Äê2ÔÂÔâÊÜÁËÀÕË÷Èí¼þ×éÖ¯ALPHV£¨ÓÖÃûBlack Cat£©µÄ¹¥»÷£¬µ¼ÖÂÔ¼1.9ÒÚÃÀ¹úÈ˵ÄÃô¸ÐÒ½ÁÆÊý¾Ýй¶£¬³ÉΪÃÀ¹úÀúÊ·ÉÏ×î´óµÄÒ½ÁÆÊý¾Ýй¶Ê¼þ¡£´Ë´Î¹¥»÷ÀûÓÃÁËȱ·¦¶àÒòËØÉí·ÝÑéÖ¤µÄÊÜѬȾÕÊ»§ºÍCitrixÔ¶³Ì·ÃÎÊÈí¼þÉϵÄÊÜѬȾƾ¾Ý£¬Ôì³ÉÁË8.72ÒÚÃÀÔªµÄ²ÆÕþËðʧºÍ6TBµÄÊý¾Ýй¶¡£¾¡¹ÜºÚ¿Í½üÒ»ÄêÀ´Ò»Ö±ÔÚ·ÃÎʱ»µÁÊý¾Ý£¬µ«UnitedHealthÉù³ÆûÓÐÖ¤¾Ý±íÃ÷Êý¾Ý±»ÀÄÓá£È»¶ø£¬´Ë´ÎÈëÇÖ̻¶ÁË°üÂÞ½¡¿µ±£ÏÕÏêϸÐÅÏ¢¡¢»¼ÕßÕï¶Ï¡¢²âÊÔ½á¹ûºÍÖÎÁÆÐÅÏ¢µÈÔÚÄÚµÄÃô¸ÐÒ½ÁƼǼ£¬ÒÔ¼°¸öÈËÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝÕÕºÅÂëµÈÃô¸ÐÊý¾Ý¡£¹¥»÷·¢Éúºó£¬¸Ã¹«Ë¾Ö§¸¶ÁË2200ÍòÃÀÔªµÄÊê½ð£¬µ«BlackCatÆÛÆÁËʵʩ´Ë´Î¹¥»÷µÄ¹ØÁª¹«Ë¾²¢ÆÈ¡ÁËÊê½ð£¬µ¼Ö±»µÁÊý¾ÝÂäÈëÍøÂç·¸×ï·Ö×ÓÊÖÖС£´Ë´ÎйÃÜʼþ²»½öÖ±½ÓÇÔÈ¡Êý¾Ý£¬»¹ÈÅÂÒÁËÈ«¹úµÄÒ½ÁÆ·þÎñ£¬¸øÔËÓª´øÀ´ÁËÖØ´óÌôÕ½£¬Òý·¢ÁËÈËÃǶԻ¼ÕßÒþ˽ºÍÊý¾ÝÄþ¾²µÄµ£ÓÇ¡£ÎªÁË×ñÊØHIPAA£¬ÁªºÏ½¡¿µ¼¯ÍÅÒÑÏòÊÜÓ°Ïì×îÑÏÖصĸöÈËͨ±¨Á˴˴ι¥»÷ʼþ¡£
https://hackread.com/unitedhealth-groups-data-breach-impacts-americans/
2. TalkTalkÊý¾Ýй¶Ê¼þ£ºÍþвÕßÉù³ÆÇÔÈ¡1880ÍòÓû§Êý¾Ý
1ÔÂ27ÈÕ£¬Ó¢¹úµçÐŹ«Ë¾TalkTalkÔâÓöÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ò»Ãû×Ô³ÆΪ¡°b0nd¡±µÄÍþвÐÐΪÕßÔÚÍøÂç·¸×ïÂÛ̳ÉÏÐû²¼¶Ô´Ë´ÎºÚ¿Í¹¥»÷ÂôÁ¦£¬²¢Éù³ÆÇÔÈ¡ÁËÁè¼Ý1880ÍòTalkTalkÓû§µÄÊý¾Ý£¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢µç»°ºÅÂëºÍPINµÈÃô¸ÐÐÅÏ¢¡£È»¶ø£¬TalkTalk¹«Ë¾·¢ÑÔÈËÌåÏÖÕâһ˵·¨¡°ÍêÈ«½û¾øÈ·ÇÒÑÏÖØ¿ä´ó¡±£¬²¢Ö¸³ö´Ë´Îй¶Éæ¼°µÚÈý·½Æ½Ì¨¡£¾Ý͸¶£¬¸ÃʼþÔ´ÓÚÒ»¸öµÚÈý·½¹©Ó¦É̵Äϵͳ±»ÒâÍâ·ÃÎʺÍÀÄÓã¬TalkTalkÕýÓ빩ӦÉ̺Ï×÷½â¾ö¸ÃÎÊÌ⣬µ«²¢Î´Í¸Â¶¹©Ó¦ÉÌÃû³Æ¡£¾Ý³Æ£¬Ð¹Â¶µÄÊý¾ÝÊÇ´ÓµçÐÅÌṩÉÌʹÓõÄAscendon SaaSƽ̨ÇÔÈ¡µÄ£¬¶ø¸Ãƽ̨ÌṩÉÌCSGÈÏ¿ÉÊý¾ÝÊÇ´ÓÆäƽ̨ÉÏÇÔÈ¡µÄ£¬µ«ÌåÏÖÖ»ÓÐÒ»Ãû¿Í»§Êܵ½Ó°Ï죬ÇÒûÓÐÖ¤¾Ý±íÃ÷Æä¼¼ÊõºÍϵͳÊܵ½ÁËË𺦡£Õâ²¢·ÇTalkTalkÊ×´ÎÔâÓöÊý¾Ýй¶Ê¼þ£¬2015Äê¸Ã¹«Ë¾·þÎñÆ÷Ò²ÔøÔâÊÜÍøÂç¹¥»÷£¬Ó°ÏìÁË400ÍòÓû§¡£
https://securityaffairs.com/173526/cyber-crime/talktalk-confirms-data-breach.html
3. Ê·ÃÜ˹¼¯ÍÅÔâδ֪¹¥»÷ÕßÈëÇÖ£¬Åû¶Äþ¾²Â©¶´
1ÔÂ28ÈÕ£¬×ܲ¿Î»ÓÚÂ׶صĿç¹ú¹¤³Ì¾ÞÍ·Ê·ÃÜ˹¼¯ÍÅ£¨Smiths Group£©½üÆÚÔâÓöÁËδ֪¹¥»÷ÕßµÄϵͳÈëÇÖ£¬µ¼ÖÂÄþ¾²Â©¶´±»Åû¶¡£×÷Ϊһ¼ÒÔÚÂ׶Ø֤ȯ½»Ò×ËùÉÏÊеÄÓ¢¹ú¹«Ë¾£¬Ê·ÃÜ˹¼¯ÍÅÔÚ50¶à¸ö¹ú¼ÒÓµÓÐÁè¼Ý15,000ÃûÔ±¹¤£¬È¥ÄêÓªÊոߴï31.32ÒÚÓ¢°÷£¬Ö÷Òª·þÎñÓÚÄÜÔ´¡¢Äþ¾²¡¢°²±£¡¢º½¿Õº½ÌìºÍ¹ú·ÀÊг¡¡£ÔÚÖܶþÌá½»¸øÂ׶Ø֤ȯ½»Ò×ËùµÄÎļþÖУ¬Ê·ÃÜ˹¼¯ÍÅ͸¶ÕýÔÚÊÓ²ìÒ»ÆðÉæ¼°¡°Î´¾ÊÚȨ·ÃÎʹ«Ë¾ÏµÍ³¡±µÄÍøÂçÄþ¾²Ê¼þ£¬²¢Á¢¼´¸ôÀëÁËÊÜÓ°ÏìµÄϵͳ£¬Æô¶¯ÁËÒµÎñÁ¬ÐøÐԼƻ®¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÕýÓëÍøÂçÄþ¾²×¨¼ÒºÏ×÷£¬Å¬Á¦»Ö¸´ÏµÍ³²¢ÆÀ¹À¶ÔÒµÎñµÄ¹ã·ºÓ°Ï죬ͬʱÔÊÐí½«½ÓÄÉÒ»ÇÐÐëÒª´ëÊ©×ñÊØÏà¹Ø¼à¹ÜÒªÇ󣬲¢ÔÚ»ñµÃ¸ü¶àÐÅϢʱÌṩ¸üС£È»¶ø£¬Ê·ÃÜ˹¼¯ÍÅÉÐδ͸¶ÈëÇֵľßÌåʱ¼äºÍÊÇ·ñÓÐÒµÎñ»ò¿Í»§Êý¾Ý±»µÁ¡£
https://www.bleepingcomputer.com/news/security/engineering-giant-smiths-group-discloses-security-breach/
4. ËþËþ¿Æ¼¼ÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅIT·þÎñ¶ÌÔÝÖжÏ
1ÔÂ31ÈÕ£¬ËþËþ¿Æ¼¼ÓÐÏÞ¹«Ë¾£¨Tata Technologies Ltd.£©£¬×÷ΪËþËþÆû³µµÄ×Ó¹«Ë¾£¬ÊÇÒ»¼ÒרעÓÚÆû³µÉè¼Æ¡¢º½¿Õº½Ì칤³Ì¼°×ÛºÏÑз¢¹¤³ÌµÄÓ¡¶ÈÉÏÊпç¹ú¿Æ¼¼¹«Ë¾¡£½üÈÕ£¬¸Ã¹«Ë¾ÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö²¿ÃÅIT·þÎñ²»µÃ²»ÔÝÍ£¡£¾¡¹ÜËþËþ¿Æ¼¼Ñ¸ËÙ½ÓÄÉÐж¯²¢Ðû²¼IT×ʲúÒѻָ´£¬µ«´Ë´Î¹¥»÷µÄ¾ßÌåϸ½ÚºÍÓ°ÏìÈÔÔÚÊÓ²ìÖС£ÖµµÃ×¢ÒâµÄÊÇ£¬¿Í»§½»¸¶·þÎñÔÚÍøÂç¹¥»÷Æڼ䱣³ÖÈ«ÃæÔËÐУ¬Î´¶Ô¿Í»§ÔËÓªÔì³ÉÓ°Ï졣ĿǰÉв»Çå³þ¹¥»÷ÕßÊÇ·ñÀÖ³ÉÇÔÈ¡Á˸ù«Ë¾µÄÈκÎÊý¾Ý£¬µ«ÀÕË÷Èí¼þ¹¥»÷ͨ³£Éæ¼°Êý¾Ý͵ÇÔ£¬¶Ô¿Æ¼¼¹«Ë¾¶øÑÔ£¬´ËÀàʼþ¿ÉÄܵ¼Ö¹«Ë¾»úÃÜÊý¾Ýй¶£¬Ëðº¦ÖªÊ¶²úȨºÍ¼¼Êõ×éºÏ¡£´ËÇ°£¬HiveÀÕË÷Èí¼þ×éÖ¯Ôø¶ÔÓ¡¶È×î´óµÄ×ۺϵçÁ¦¹«Ë¾ËþËþµçÁ¦·¢¶¯¹¥»÷£¬ÇÔÈ¡²¢Ð¹Â¶ÁË°üÂÞ¹¤³ÌʾÒâͼ¡¢²ÆÕþ¼Ç¼ºÍ¸öÈË¿Í»§ÐÅÏ¢ÔÚÄÚµÄÃô¸ÐÊý¾Ý¡£´Ë´ÎËþËþ¿Æ¼¼ÔâÊܵĹ¥»÷ÔÙ´ÎÌáÐÑÆóÒµÐè¼ÓÇ¿ÍøÂçÄþ¾²·À»¤¡£
https://www.bleepingcomputer.com/news/security/indian-tech-giant-tata-technologies-hit-by-ransomware-attack/
5. GrubHubÔâÊý¾Ýй¶£¬¹¥»÷ÕßÀûÓõÚÈý·½ÕË»§ÈëÇÖϵͳ
2ÔÂ4ÈÕ£¬Ê³Æ·ÅäË͹«Ë¾GrubHubÔâÓöÁËÒ»´ÎÊý¾Ýй¶Ê¼þ£¬¹¥»÷Õßͨ¹ýµÚÈý·½·þÎñÌṩÉ̵ÄÕË»§ÈëÇÖÁËGrubHubϵͳ£¬Ó°ÏìÁË¿Í»§¡¢É̼ҺÍ˾»úµÄ¸öÈËÐÅÏ¢£¬µ«¾ßÌåÊÜÓ°ÏìÊýÁ¿Î´¹ûÈ»¡£GrubHubѸËÙ½ÓÄÉÐж¯£¬ÖÕÖ¹ÁËÈëÇÖÕË»§µÄ·ÃÎÊȨÏÞ£¬²¢É¾³ýÁ˸÷þÎñÌṩÉÌ£¬Í¬Ê±Æ¸ÇëÍⲿר¼ÒÆÀ¹ÀÓ°Ïì¡¢ÂÖ»»ÃÜÂë²¢¼ÓÇ¿ÁËÄÚ²¿·þÎñµÄÒì³£¼ì²â¡£ÊÓ²ìÏÔʾ£¬¹¥»÷Õßδ»ñÈ¡Ãô¸ÐµÄ¸öÈ˺ͲÆÕþÐÅÏ¢£¬µ«¿ÉÄÜ»ñÈ¡Á˲¿ÃÅУ԰ʳÌÃÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¼°²¿ÃÅÖ§¸¶¿¨ÐÅÏ¢£¨°üÂÞ¿¨ÀàÐͺÍ×îºóËÄλ¿¨ºÅ£©¡£´ËÍ⣬¹¥»÷Õß»¹·ÃÎÊÁËijЩÒÅÁôϵͳµÄÉ¢ÁÐÃÜÂ룬GrubHubÒÑÖ÷¶¯ÂÖ»»¿ÉÄÜ´æÔÚ·çÏÕµÄÃÜÂ룬²¢¶Ø´Ù¿Í»§Ê¹ÓÃÆæÌØÃÜÂëÒÔ½µµÍ·çÏÕ¡£GrubHubÔÚÈ«¹ú4000¶à¸ö¶¼ÊÐÓµÓÐÁè¼Ý375000¼ÒÉ̼ҺÍ200000ÃûÅäËͺÏ×÷»ï°é£¬È¥ÄêÒò¶àÏîÎ¥·¨ÐÐΪ֧¸¶ÁË2500ÍòÃÀÔªºÍ½â½ð¡£
https://www.bleepingcomputer.com/news/security/grubhub-data-breach-impacts-customers-drivers-and-merchants/
6. CISA ½«Ëĸö±»»ý¼«ÀûÓõÄ©¶´Ìí¼Óµ½ KEV Ŀ¼ÖÐ
2ÔÂ5ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©ÖܶþÐû²¼ÁËÒ»ÏîÖØÒªÄþ¾²Í¨¸æ£¬ÏòÆäÒÑÖª±»ÀûÓ鶴£¨KEV£©Ä¿Â¼ÖÐÐÂÔöÁËËĸöÄþ¾²Â©¶´£¬²¢¾¯¸æÕâЩ©¶´Õý±»»ý¼«ÀûÓá£ÕâЩ©¶´°üÂÞ£ºCVE-2024-45195£¬Ò»¸öApache OFBizÖеÄÇ¿ÖÆä¯ÀÀ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñȡδÊÚȨ·ÃÎÊȨÏÞ²¢Ö´ÐÐÈÎÒâ´úÂ루ÒÑÐÞ¸´£©£»CVE-2024-29059£¬Microsoft .NET FrameworkÖеÄÐÅϢ鶩¶´£¬¿ÉÄÜ̻¶Ãô¸ÐÐÅÏ¢²¢µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨ÒÑÐÞ¸´£©£»CVE-2018-9276£¬Paessler PRTGÍøÂç¼àÊÓÆ÷ÖеIJÙ×÷ϵͳÃüÁî×¢È멶´£¬ÔÊÐí¹ÜÀíȨÏ޵Ĺ¥»÷ÕßÖ´ÐÐÃüÁÒÑÐÞ¸´£©£»ÒÔ¼°CVE-2018-19410£¬Í¬ÑùÊÇPaessler PRTGÖеĵ±µØÎļþ°üÂÞ©¶´£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´´½¨¾ßÓжÁдȨÏÞµÄÓû§£¨ÒÑÐÞ¸´£©¡£¾¡¹ÜÕâЩ©¶´ÒÑÓɸ÷×Ô¹©Ó¦ÉÌÐÞ¸´£¬µ«Ä¿Ç°ÉÐÎÞ¹ØÓÚËüÃÇÈçºÎÔÚÕæʵ¹¥»÷Öб»ÀûÓõľßÌå¹ûÈ»³ÂËß¡£Îª´Ë£¬Áª°îÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©ÏÂÊô»ú¹¹±»½ô¼±¶Ø´ÙÔÚ2025Äê2ÔÂ25ÈÕÇ°Ó¦ÓÃÐëÒªµÄÐÞ¸´´ëÊ©£¬ÒÔÓÐЧ·À·¶ÕâЩÖ÷¶¯Íþв£¬È·±£ÍøÂçÄþ¾²¡£
https://thehackernews.com/2025/02/cisa-adds-four-actively-exploited.html