¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190305

°ä²¼¹¦·ò 2019-03-05
1¡¢Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û £¬500¶àÍòÓû§Êý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VPNMentor×êÑÐÍŶӷ¢ÏÖÉ³ÌØ°¢À­²®Í¨Ñ¶APP DalilµÄMongoDBÊý¾Ý¿â¿É¹«¿ª½Ó¼û £¬µ¼Ö³¬¹ý500ÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£Dalilͨ¹ýÍøÂçÓû§ÐÅÏ¢ £¬Äܹ»Ô®ÊÖÓû§¼ø±ðδ֪µÄµç»°ºÅÂë £¬´Ó¶øÔ¤·ÀɧÈŵ绰»òÍÆÏúµç»°µÈ¡£×êÑÐÈËÔ±·¢ÏÔìäMongoDBÊý¾Ý¿âδÉèÃÜÂë £¬ÕâÒâζÕß¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É½Ó¼ûÓû§µÄÊý¾Ý £¬Ô̺¬ÊÖ»úºÅÂë¡¢IPµØÖ·¡¢É豸Ðͺš¢ÐòÁкš¢²Ù×÷ϵͳ¡¢IMEI¡¢SIM¿¨ÐÅÏ¢¡¢GPSÐÅÏ¢ÒÔ¼°ÓÊÏäÕË»§¡¢ÐÕÃû¡¢ÐÔ±ðºÍÖ°ÒµµÈ¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dalil-data-breach/

2¡¢À­ÌØÀ¼Ò½ÁÆÖÐÐÄÔâºÚ¿ÍÈëÇÖ £¬³¬¹ý7ÍòÃû»¼ÕßµÄÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý±¨Â· £¬ÃÀ¹úÀ­ÌØÀ¼µØÓòÒ½ÁÆÖÐÐÄ£¨RRMC£©µÄÔ±¹¤ÓÊÏäÔ⵽δÊÚȨ½Ó¼û £¬³¬¹ý7ÍòÃû»¼ÕßµÄÐÅϢй¶¡£´§Ä¦ÕâÒ»ÊÂÎñ²úÉúÔÚ2018Äê12ÔÂ31ÈÕ £¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢ÁªÏµÐÅÏ¢ºÍÒ½ÁƼͼºÅÂë £¬´Ë±í £¬»¹Óг¬¹ý4000¸öÉç»á°²È«ºÅÂ루SSN£©Ð¹Â¶¡£RRMCÒѾ­ÏòÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿´«µÝÁËÓйØÊÂÎñ £¬²¢³ÐŵΪSSNй¶µÄ»¼ÕßÌṩÐÅÓþ¼à¿ØºÍ¸´Ô­·þÎñ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/data-breach-affects-over-72000-patients-of-rutland-regional-medical-center-79d12a09

3¡¢Ë¼¿Æ°ä²¼2019Äê¶ÈCISO»ù×¼×êÑл㱨 £¬Ì½Çó°²È«Ç÷ÏòµÄ±ä¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

˼¿Æ°ä²¼2019Äê¶ÈCISO»ù×¼×êÑл㱨 £¬¸Ã»ã±¨Õë¶ÔÈ«Çò·ÖÆçÒµÒµºÍ·ÖÆç¹æÄ£µÄÆóÒµµÄÊ×ϯÐÅÏ¢°²È«¹Ù½øÐÐÁ˵÷ÑÐ £¬¹²ÓÐ18¸ö¹ú¶È/µØÓòµÄ3200¶àÃûÊÜ·ÃÕß½ÓÊÜÁ˵÷ÑС£µ÷Ñз¢ÏÔìóÒµµÄÍøÂçÍŶӺͰ²È«ÍŶӽøÐкÏ×÷Äܹ»ÏÔÖø½µµÍ°²È«ÊÂÎñµÄ³É±¾-µÍÓÚ10ÍòÃÀÔª¡£´Ë±í £¬93£¥µÄÊ×ϯÐÅÏ¢°²È«¹Ù³ÆÇ¨áãµ½ÔÆ»·¾³Äܹ»Ìá¸ßÍŶӵÄЧÄÜ¡£µ÷²é»¹·¢ÏÖ £¬·çÏÕÆÀ¹À΢·çÏÕÖ¸±ê¹áͨÁËÆóÒµµÄÒµÎñÁ÷³Ì¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.cisco.com/c/dam/m/digital/elq-cmcglobal/witb/1963786/2019CISOBenchmarkReportCiscoCybersecuritySeries.pdf

4¡¢FireEye°ä²¼¹ØÓÚ·¸×ïÍÅ»ïAPT40µÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

FireEye°ä²¼¹ØÓÚ·¸×ïÍÅ»ïAPT40µÄ·ÖÎö»ã±¨ £¬¸ÃÍÅ»ïÖÁÉÙ´Ó2013ÄêÆðÍ·ÔË×÷ £¬ÖØÒªÕë¶Ô¹¤³Ì¡¢ÔËÊäºÍ¹ú·À¹¤Òµ £¬ÓÈÆäÊÇÕâЩÐÐÒµÓ뺣ʼ¼Êõ³ÁµþµÄ·½Ã档һЩ¾ßÌåÖ¸±êÔ̺¬¼íÆÒÕ¯¡¢±ÈÀûʱ¡¢µÂ¹ú¡¢ÖйúÏã¸Û¡¢·ÆÂɱö¡¢ÂíÀ´Î÷ÑÇ¡¢Å²Íþ¡¢É³Ìذ¢À­²®¡¢ÈðÊ¿¡¢ÃÀ¹úºÍÓ¢¹ú¡£APT40ÖØÒªÍ¨¹ý´¹µö»î¶¯½øÐй¥»÷ £¬ÆäÖØÒªÀûÓ÷ì϶CVE-2012-0158¡¢CVE-2017-0199¡¢CVE-2017-8759ºÍCVE-2017-11882¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2019/03/apt40-examining-a-china-nexus-espionage-actor.html

5¡¢IBM×êÑÐÍŶÓÔÚ¶à¸ö·Ã¿ÍÖÎÀíϵͳÖз¢ÏÖ19¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

IBM X-Force×êÑÐÍŶÓÔÚÎå¸öÊ¢ÐеķÿÍÖÎÀíϵͳÖз¢ÏÖ19¸ö°²È«·ì϶¡£ÊÜÓ°ÏìµÄϵͳÔ̺¬HID Global£¨EasyLobby Solo£©¡¢Threshold£¨eVisitorPass£©¡¢Envoy£¨Envoy Passport£©ºÍThe Receptionist£¨The Receptionist£©¡£·ì϶µÄÁìÓò´ÓÊý¾Ýй¶¡¢·¨Ê½ÊÕÊܵ½·Ã¿ÍÀûÓÃWindowsÈȼü½øÈëÖÕ¶Ë»·¾³µÈ¡£Óйع©¸øÉÌÒѾ­½¨¸´ÁËÕâЩ·ì϶ £¬ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/visitor-kiosk-bugs/142433/

6¡¢Õë¶ÔÒÔÉ«ÁеĹ¥»÷»î¶¯#OpJerusalem £¬ÖØÒª·Ö·¢JCry

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÄ© £¬Êý°Ù¸öÒÔÉ«ÁÐÍøÕ¾³ÉΪ#OpJerusalemµÄ¹¥»÷Ö¸±ê £¬¹¥»÷ÕßÊÔͼʹÓÃÀÕË÷Èí¼þJCryϰȾWindowsÓû§¡£µ«ÓÉÓÚ¹¥»÷ÕߵĴúÂë·¸´í £¬ÕâÐ©ÍøÕ¾Ö»ÊDZ»´Û¸ÄÁËÒ³Ãæ £¬²¢Ã»Óзַ¢JCry¡£¹¥»÷ÕßÅú¸ÄÁËÉÏÍø²å¼þnagichµÄDNS¼Í¼ £¬µ±Óû§Ê¹Óøòå¼þ½Ó¼ûÍøÕ¾Ê± £¬¹¥»÷Õߵľ籾½«¼ì²âä¯ÀÀÆ÷´úÀíÒÔÈ·ÈÏÊÇ·ñWindowsϵͳ £¬ÈôÊÇÊÇ £¬Ôòͨ¹ýÐéαAdobe¸üзַ¢JCry¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/opjerusalem-targeted-israeli-windows-users-with-jcry-ransomware/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù