AvaddonÍÅ»ïÐû³ÆÒÑ´Ó·¨¹ú±£ÏÕ¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý£»×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃURL¹æ»®À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§

°ä²¼¹¦·ò 2021-05-18

1.AvaddonÍÅ»ïÐû³ÆÒÑ´Ó·¨¹ú±£ÏÕ¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý


1.jpg


·¨¹ú±£ÏÕ¹«Ë¾°²Ê¢¼¯ÍÅ£¨AXA Group£©ÉÏÖÜÈÕ°ä·¢£¬ÆäÔâµ½AvaddonÀÕË÷Èí¼þµÄ¹¥»÷£¬Ó°ÏìÁËÑÇÖÞÒµÎñ²¿ÃŵÄITÔËÓª¡£AvaddonÍŶÓÔòÔÚÆäÐ¹Â¶ÍøÕ¾ÉÏÐû³Æ£¬ËûÃÇÒѾ­´ÓAXA¹«Ë¾ÇÔÈ¡ÁË3TBµÄÃô¸ÐÊý¾Ý£¬Ô̺¬¿Í»§Ò½Áƻ㱨¡¢Éí·ÝÖ¤¸´Ó¡¼þ¡¢ÒøÐжÔÕʵ¥¡¢Ë÷Åâ±í¡¢¸¶¿î¼Í¼ºÍºÏÒ»Ö£¬²¢¶ÔAXAÔÚÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ïã¸ÛºÍ·ÆÂɱöµÄÍøÕ¾ÌáÒéÁËÓÐЧµÄDDoS¹¥»÷¡£AXA°µÊ¾Õâ´ÎÊÂÎñ½öй¶ÁËÌ©¹ú¹ú¼ÊºÏ×÷ͬ°éЭÖú£¨IPA£©µÄ²¿ÃÅÊý¾Ý£¬ÆäËü·Ö¹«Ë¾Î´ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/avaddon-ransomware-french-insurance-axa-data-stolen/


2.°ÍÎ÷¹«Ë¾Rede BahiaÔâµ½ÀÕË÷¹¥»÷£¬ÔËÓªÁÙʱÖжÏ


2.jpg


°ÍÎ÷óÒ×¼¯ÍÅRede BahiaÔâµ½ÀÕË÷¹¥»÷£¬ÔËÓªÁÙʱÖжÏ¡£2021Äê5ÔÂ13ÈÕ£¬¸Ã¹«Ë¾Í¨¹ýÓʼþ֪ͨԱ¹¤£¬Òò¹¥»÷ÊÂÎñÆäÓ×ÎÒÐÅÏ¢£¨ÀýÈçн×ÊÃ÷ϸµÈ£©¿ÉÄÜÒѾ­Ð¹Â¶¡£´Ë±í£¬Õâ´Î¹¥»÷»¹×ÌÈÅÁËRede BahiaÆìϵı¨Ö½CorreioÖðÈÕµÄÕý³£³ö°æ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÈÔÔÚÖÂÁ¦¸´Ô­ËùÓÐÖ°ÄÜ£¬ÉÐδ¹«¿ªÓйØÀÕË÷Èí¼þµÄÀàÐÍ»òÀÕË÷ÐèÒªµÄ¾ßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/br-rede-bahia-suffers-a-cyberattack-and-reported-databreach/


3.±£ÏÕ¹«Ë¾Guard.meÔâµ½¹¥»÷£¬¿Í»§Ó×ÎÒÐÅϢй¶


3.jpg


Guard.meÔâµ½¹¥»÷£¬¿Í»§Ó×ÎÒÐÅϢй¶¡£guard.meÊÇÈ«Çò×î´óµÄ±£ÏÕ¹«Ë¾Ö®Ò»£¬×¨ÃÅΪ³ö¹ú¹Û¹â»ò³ö¹úÁôѧµÄѧÉúÌṩ½¡È«±£ÏÕ¡£5ÔÂ12ÈÕ£¬Guard.meÔÚÆäÍøÕ¾ÉÏ·¢ÏÖÁËÒì³£»î¶¯£¬×÷ΪԤ·À´ëÊ©£¬Æäµ±¼´¹Ø¹ØÁ˸ÃÍøÕ¾²¢¶ÔÆä½øÐÐÊØ»¤¡£Ö±µ½5ÔÂ17ÈÕ£¬¸Ã¹«Ë¾Í¨ÖªÆä¿Í»§ÓÐδ¾­ÊÚȨµÄ¹¥»÷ÕßÀûÓÃÆäÍøÕ¾Öеķì϶½Ó¼ûÁËѧÉúµÄÐÅÏ¢£¬Ô̺¬ÉúÈÕ¡¢ÐÔ±ð¡¢ÃÜÂëÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍµç»°ºÅÂëµÈ¡£guard.me³Æ·ì϶ÏÖÒѽ¨¸´£¬²¢ÆôÓÃÁËеĸü¸ß¼¶´ËÍⰲȫսÊõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/student-health-insurance-carrier-guardme-suffers-a-data-breach/


4.×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃURL¹æ»®À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§


4.jpg


×êÑÐÈËÔ±¿ª·¢ÁËÒ»ÖÖ²½Ö裬ͨ¹ý²éÎÊÉ豸ÉÏ×°ÖõÄÀûÓ÷¨Ê½£¬Äܹ»×·×Ù·ÖÆçä¯ÀÀÆ÷µÄÓû§¡£ÓÉÓÚijЩÀûÓ÷¨Ê½ÔÚ×°Öúó»á´´½¨×Ô½ç˵URL¹æ»®£¬ä¯ÀÀÆ÷¿ÉʹÓøÃURL¹æ»®ÔÚÌØ¶¨ÀûÓ÷¨Ê½Öдò¿ªURL¡£ FingerprintJS×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓÃ×Ô½ç˵ºÍ̸´¦Ö÷¨Ê½Öеĺ鷺·ì϶£¬ÔÚ·ÖÆçµÄä¯ÀÀÆ÷£¬Ô̺¬Chrome¡¢Firefox¡¢Microsoft Edge¡¢Safari£¬ÉõÖÁÊÇTorÖ®¼ä¸ú×ÙÓû§µÄ¡£Ä¿Ç°£¬Ö»Óйȸèä¯ÀÀÆ÷֮ǰ²ÉÈ¡ÁË»º½â´ëÊ©£¬À´Ô¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cross-browser-tracking-vulnerability-tracks-you-via-installed-apps/


5.Hiscox°ä²¼2021ÄêµÄCyber Readiness·ÖÎö»ã±¨


5.jpg


¹ú¼Ê±£ÏÕ¹«Ë¾Hiscox°ä²¼2021ÄêµÄCyber Readiness·ÖÎö»ã±¨¡£»ã±¨µ÷²éÁ˵÷²éÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢±ÈÀûʱ¡¢·¨¹ú¡¢µÂ¹ú¡¢ºÉÀ¼¡¢Î÷°àÑÀºÍ°®¶ûÀ¼µÄ6000¶à¸öÍøÂç°²È«ÕÆ¹ÜÈËÔ±¡£ »ã±¨ÏÔʾ£¬ÔÚ´ÓǰһÄêÖУ¬ÓÐÃÀ¹ú23£¥µÄÓ×ÐÍÆóÒµÔâ·êÁËÖÁÉÙÒ»´ÎÍøÂç¹¥»÷¡£63£¥µÄÓ×ÐÍÆóÒµÔÚÔ¶³Ì¹¤×÷£¬53£¥ÒÔΪ×Ô¼ºÈÝÒ×Êܵ½ÍøÂç¹¥»÷¡£39£¥µÄÆóÒµ°µÊ¾£¬ËûÃÇÔ¤¼ÆÔö³¤Æä°²È«Ö§³ö£¬49£¥µÄÆóҵ˵ռÓÐÍøÂç±£ÏÕ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.hiscox.com/sites/default/files/content/documents/Hiscox-Cyber-Readiness-Report-2021.pdf


6.CISA°ä²¼ÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÓ¦¶ÔÖ¸ÄÏ


6.jpg


CISA°ä²¼ÁËÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÍøÂçµÄÓ¦¶ÔÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÖ¸³ö£¬Ó¦¶Ô´ëÊ©ÖØÒª·ÖΪÈý²½£º Pre-Eviction½×¶Î£¬¼ì²âºÍ¼ø±ðAPT»î¶¯²¢ÎªÏÂÒ»½×¶Î×öºÃ³ï±¸£»Eviction½×¶Î£¬´Ó±¾µØºÍÔÆ»·¾³ÖÐɾ³ýAPT²Î¼ÓÕߵIJÙ×÷£¬Ô̺¬³Á½¨É豸ºÍϵͳ£»Post-Eviction½×¶Î£¬È·±£±÷³ý³É¹¦²¢ÇÒÍøÂçÓµÓÐÓÅÁ¼µÄ״̬¡£´Ë±í£¬CISAÌáÐѱ¾Ö¸ÄÏÖÐÌṩµÄ²½ÖèºÄ·Ñ×ÊÔ´ÇÒ¼«¶È¸´ÔÓ£¬±ØÒªÆóÒµ½«ÍøÂç´ÓInternet¶Ï¿ª3µ½5Ìì¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/analysis-reports/ar21-134a