2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨£»vBulletin°ä²¼°²È«¸üУ¬½¨¸´ÐÂRCEºÍSQL×¢Èë·ì϶

°ä²¼¹¦·ò 2019-10-09
1.Ponemon Institute°ä²¼¡¶2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨¡·

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÖܶþPonemon Institute°ä²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨¡·£¬È«Çò66%µÄÖÐÓ×ÐÍÆóÒµ£¨SMB£©ÔÚ´Óǰ12¸öÔÂÄڻ㱨ÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£Ponemon°µÊ¾ÕâÊÇÂ½ÐøµÚÈýÄêSMB»ã±¨µÄÍøÂ簲ȫÊÂÎñ³öÏÖ¡°ÏÔÖøÔö³¤¡±¡£µ±Ç°SMBÃæ¶ÔµÄ×î³£¼ûÍøÂç¹¥»÷´ó¾ÖÊÇÍøÂç´¹µö¡¢É豸ÈëÇÖ»ò±»µÁ¡¢Í´´¦ÇÔÈ¡¡£Ëæ×Å×Ô´øÉ豸°ì¹«£¨BYOD£©Ä£Ê½µÄÁ÷ÐУ¬É豸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£ÔÚ´Óǰ12¸öÔÂÖУ¬¹²ÓÐ63%µÄÆóÒµ»ã±¨ÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅÏ¢¶ª³öÊÂÎñ£¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬½ü100Íò»¼ÕßÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



T¨±Ora Compass HealthÔâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¸ÃµÍ¼¶ÎÀÉú×éÖ¯£¨PHO£©°µÊ¾Æä¹ÙÍøÔÚ8Ô·ݲúÉúµÄÒ»Â·ÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬Òò¶ø¶ÔCompass HealthµÄÕûÌåITϵͳºÍ°²È«Çé¿ö½øÐÐÁ˵÷²é£¬×îÖÕ·¢ÏÖ´Ó2016Äêµ½2019Äê3Ô²úÉúµÄÍøÂç¹¥»÷¡£Compass Health°µÊ¾ÈκÎÔÚ2016ÄêÖÁ2019ÄêÆÚ¼äÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£ÊÜÓ°ÏìµÄµØÓòÖØÒªÎªÐÂÎ÷À¼»ÝÁé¶Ù£¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾ÝÔ̺¬Óû§µÄ¹ú¶ÈÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØÖ·ÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐĽøÐÐ×¢²á¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬¿Í»§ÐÅÓþÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôóTransUnion´ÓÉÏÖÜÆðÍ·ÏòÓû§·¢ËÍÊý¾Ý°²È«ÊÂÎñ֪ͨ£¬°µÊ¾Óû§µÄÐÅÏ¢Ô⵽δÊÚȨ½Ó¼û¡£¸Ãָ֪ͨ³ö£¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕÆÚ¼äδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Í´´¦½Ó¼ûÆäÃÅ»§ÍøÕ¾£¬²¢½øÐÐÁËÐÅÓþ»ã±¨²éÕÒ¡£¿ÉÄܲéÕÒµ½µÄÐÅÓþÎļþÖÐÔ̺¬Óû§µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±Ç°¼°´ÓǰµÄµØÖ·ÒÔ¼°Õ÷ÐÅÓйØÐÅÏ¢£¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶º¹ÇàµÈ£¬µ«²»Ô̺¬ÏÖʵµÄÕË»§ºÅÂë¡£ÓÉÓÚ¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩÐÅÏ¢À´Ö´ÐÐÉí·Ý͵ÇÔ£¬Òò¶øTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓþڲƭ¼à¿Ø·þÎñ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾö¶¨ÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢¸´Ô­ÆäϵͳµÄÕý³£ÔËÓª¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨Ô̺¬DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬ÆÈʹËûÃǹعØÁËÍÆËã»úϵͳ²¢ÖÕ³¡½Ó¹ÜÐµĻ¼Õß¡£ÉÏÖÜÄ©DCH°ä²¼¸üÐÂÉêÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÔÚ¸´Ô­Æäϵͳ£¬DCH²¢Î´Ð¹Â©Êê½ðµÄ¾ßÌåÊý¶î£¬µ«ÒÑÈ·È϶à¸ö·þÎñÆ÷±»³É¹¦½âÃÜ¡£Ä¿Ç°Éв»Ã÷ÏÔDCHµÄϵͳ½«ÓÚºÎʱÆëÈ«ÉÏÏß¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletin°ä²¼°²È«¸üУ¬½¨¸´ÐÂRCEºÍSQL×¢Èë·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÉϸöÔÂÄ©½¨¸´RCE 0dayºó£¬vBulletin°ä²¼ÁËÒ»¸öÐµİ²È«²¹¶¡£¬½¨¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣ·ì϶¡£µÚÒ»¸ö·ì϶ÊÇRCE·ì϶£¨CVE-2019-17132£©£¬´æÔÚÓÚvBulletin´¦ÖÃÓû§¸üÐÂÆäÓ×ÎÒ×ÊÁϵÄÒªÇó¹ý³ÌÖУ¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃδ¾­¹ýÂ˵IJÎÊýÔÚÖ¸±ê·þÎñÆ÷ÉÏ×¢Èë²¢Ö´ÐÐËÁÒâPHP´úÂë¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÓйØPoC¡£Áí±íÁ½¸ö·ì϶ÊÇSQL×¢ÈëÎÊÌ⣬ËüÃDZ»·ÖÅäΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬¿ÉÔÊÐíÓµÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£ÕâЩ·ì϶ӰÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢Èí°ä²¼10Ô°²È«¸üУ¬½¨¸´59¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÔÚÖܶþ°ä²¼µÄWindows 10Ô°²È«¸üÐÂÖн¨¸´ÁË59¸ö·ì϶£¬ÆäÖÐÔ̺¬°²È«³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1238ºÍCVE-2019-1239£¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCE·ì϶£¨CVE-2019-1333£¬ÔÊÐí¶ñÒâ·þÎñÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÏνÓʱÔÚ¿Í»§¶ËÉÏÖ´ÐкÅÁµÈ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/