ÃÀ¹úHCA Healthcare²úÉúÊý¾Ýй¶ӰÏìÔ¼1100Íò»¼Õß
°ä²¼¹¦·ò 2023-07-131¡¢ÃÀ¹úHCA Healthcare²úÉúÊý¾Ýй¶ӰÏìÔ¼1100Íò»¼Õß
¾ÝýÌå7ÔÂ11ÈÕ±¨Â·£¬ÃÀ¹ú×î´óµÄÒ½ÁÆ»ú¹¹ÔËÓªÉÌÖ®Ò»HCA Healthcare²úÉúÊý¾Ýй¶£¬Ó°ÏìÔ¼1100Íò»¼Õß¡£7ÔÂ5ÈÕ£¬Ò»ÃûºÚ¿ÍÆðÍ·ÔÚºÚ¿ÍÂÛ̳ÉÏÏúÊ۾ݳÆÊôÓÚHCA HealthcareµÄÊý¾Ý¡£»¹°ä²¼Á˱»µÁÊý¾Ý¿âµÄÑù±¾£¬²¢Ðû³ÆÔ̺¬17¸öÎļþºÍ2770Íò±Ê¼Í¼¡£¹¥»÷Õß°µÊ¾³Æ£¬ÕâЩÊý¾ÝÔ̺¬2021ÄêÖÁ2023Äê¼ä´´½¨µÄ»¼Õ߼ͼ¡£Õâ´Îй¶ÊÂÎñËÆºõÊǵÚÈý·½Ôâµ½¹¥»÷µ¼Öµģ¬HCAй©£¬Êý¾ÝÊÇ´ÓÒ»¸öÓÃÓÚ×Ô¶¯Ìåʽ»¯µç×ÓÓʼþµÄÈí¼þϵͳµÄ±í²¿´æ´¢µØÎ»Ð¹Â¶µÄ¡£
https://www.infosecurity-magazine.com/news/patients-healthcare-data-breach/
2¡¢µÂÒâÖ¾ÒøÐгƹ©¸øÉÌÔâµ½¹¥»÷µ¼ÖÂÆä¿Í»§µÄÐÅϢй¶
¾Ý7ÔÂ11ÈÕ£¬µÂÒâÖ¾ÒøÐÐ(Deutsche Bank AG)³ÆÒ»¼Ò·þÎñÌṩÉÌÔâµ½¹¥»÷£¬µ¼ÖÂÆä¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¸ÃÒøÐаµÊ¾£¬ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿ÉÐδȷ¶¨£¬ËûÃÇÔÚµ÷²éÊý¾Ýй¶µÄÔÒò£¬²¢²ÉÈ¡ÓÐÕë¶ÔÐԵĴëÊ©¡£¾ÝϤ£¬±»ÈëÇֵķþÎñÌṩÉÌÃûΪMajorel£¬ÕƹÜÔڵ¹úÔËÓª¸ÃÒøÐеÄÕÊ»§Çл»·þÎñ£¬Ôâµ½ÁËÀûÓÃMOVEit Transfer·ì϶µÄÍøÂç¹¥»÷¡£¸ÃÊÂÎñ»¹Ó°ÏìÁËÆäËü´óÐÍÒøÐкͽðÈÚ·þÎñÌṩÉÌ£¬Ô̺¬µÂ¹úóÒ×ÒøÐÓ×¢ÓÊÕþÒøÐÓ×¢ComdirectºÍING¡£
https://www.bleepingcomputer.com/news/security/deutsche-bank-confirms-provider-breach-exposed-customer-data/
3¡¢Cisco·¢ÏÖÀûÓÃWindowsÕ½Êõ·ì϶¼ÓÔØ¶ñÒâÇý¶¯·¨Ê½µÄ¹¥»÷
Cisco TalosÔÚ7ÔÂ11ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃWindowsÕ½Êõ·ì϶¼ÓÔØ¶ñÒâÄÚºËģʽÇý¶¯·¨Ê½µÄ¹¥»÷»î¶¯¡£¾ßÌåÀ´Ëµ£¬¹¥»÷ÕßÀûÓöàÖÖ¿ªÔ´¹¤¾ßÀ´Å¤×ªÄÚºËģʽÇý¶¯·¨Ê½µÄÊðÃûÈÕÆÚ£¬ÒÔ¼ÓÔØÊ¹ÓùýÆÚÖ¤ÊéÊðÃûµÄ¶ñÒâºÍδ¾ÑéÖ¤µÄÇý¶¯·¨Ê½¡£ÔÚWindows VistaÖУ¬ÒªÇ󿪷¢ÈËÔ±Ìá½»ËûÃǵÄÇý¶¯·¨Ê½½øÐÐÉóºËºÍÊðÃû¡£ÎªÁËÔ¤·À¾É°æÀûÓóöÏÖÎÊÌ⣬΢ÈíÁгöÁËÈýÖÖÀý±íÇé¿ö£¬ÔÊÐí³ÖÐø¼ÓÔØ¾É°æÄÚºËģʽÇý¶¯·¨Ê½¡£¹¥»÷ÕßÀûÓÃÁ˵ÚÈý¸öÕ½Êõ£¬Í¨¹ýʹÓù¤¾ßHookSignToolºÍFuckCertVerify£¬À´¸ü¸Ä¶ñÒâÇý¶¯·¨Ê½µÄÊðÃûÈÕÆÚ¡£
https://blog.talosintelligence.com/old-certificate-new-signature/
4¡¢Unit 42ÔÚPyPIÖмì²âµ½6¸öÖ¼ÔÚÇÔȡָ±êÐÅÏ¢µÄ¶ñÒâ°ü
7ÔÂ11ÈÕ£¬Unit 42й©ÆäÔÚPython°üË÷Òý(PyPI)°üÖÎÀíÆ÷ÉÏ·¢ÏÖÁË6¸ö¶ñÒâ°ü¡£ÕâЩ°üÖ¼ÔÚÇÔÈ¡WindowsÓû§µÄÀûÓ÷¨Ê½Í´´¦¡¢Ó×ÎÒÊý¾ÝºÍ¼ÓÃÜÇ®°üµÄ¸ú×ÙÐÅÏ¢¡£×êÑÐÈËÔ±°µÊ¾£¬Õâ´Î¹¥»÷ÊÇ·ÂÕÕÁ˺ڿÍÍÅ»ïW4SP£¬¸ÃÍÅ»ï´ËÇ°ÔøÀûÓöñÒâÈí¼þ°üÖ´ÐйýÂŴι©¸øÁ´¹¥»÷¡£Í¨¹ý¶ÈÎö´úÂë²¢×·×Ù°üµÄ¿ª·¢Õߣ¬·¢ÏÖ¿ª·¢ÕßµÄÓû§ÃûÓÃÁËÒ»ÖÖģʽ£¬ÒÔ1337×÷Ϊºó׺£¬ÕâÅú×¢ÊÇͨ¹ý×Ô¶¯¹ý³Ì´´½¨ÁËÕâЩÓû§¡£
https://unit42.paloaltonetworks.com/malicious-packages-in-pypi/
5¡¢×êÑÐÈËÔ±Åû¶ÐÂÎÞÎļþ¶ñÒâÈí¼þPyLooseµÄ¶ñÒâÍÚ¿ó»î¶¯
7ÔÂ11ÈÕ±¨Â·³Æ£¬×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÃûΪPyLooseµÄÐÂÐÍÎÞÎļþ¶ñÒâÈí¼þÕë¶ÔÔÆworkload£¬½Ù³ÔìäÍÆËã×ÊÔ´ÒÔ½øÐÐÃÅÂÞ±Ò¼ÓÃÜÇ®±ÒÍÚ¾ò¡£PyLoose»ùÓÚPython£¬´øÓÐÔ¤±àÒëµÄÇÒbase64 ±àÂëµÄXMRigÍÚ¿ó·¨Ê½¡£PyLoose´ÓÄÚ´æÖÐÖ±½ÓÖ´ÐУ¬Òò¶ø¼«ÆäÒñ±Î£¬ºÜÄѱ»°²È«¹¤¾ß¼ì²âµ½¡£WizÓÚ6ÔÂ22ÈÕ³õ´Î¼ì²âµ½PyLoose¹¥»÷£¬¶ûºóÒÑÈ·ÈÏÖÁÉÙ200Æð´ËÀàÐÂÐͶñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£Ä¿Ç°ÎÞ·¨½«PyLoose¹éÒòÓÚÈκι¥»÷ÍŻ
https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads
6¡¢ESET°ä²¼2023ÉϰëÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
7ÔÂ11ÈÕ£¬ESET°ä²¼2023ÉϰëÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£ÔÚ2023ÄêÉϰëÄ꣬ÐéαµÄAndroid´û¿îÀûÓ÷¨Ê½Ôö³¤Á˽ü90%¡£EmotetÔÚÉϰëÄê½øÐÐÁËÈý´Î·ÖÆçµÄ¶ñÒâÓʼþ»î¶¯£¬Ö¼ÔÚѰÕÒÒ»ÖÖÓÐЧµÄ¹¥»÷ÔØÌå¡£¼¸¸ö±¸ÊÜÖõÖ÷ÕŶñÒâÈí¼þ¼Ò×åÔÚ²âÊÔ½«OneNote×÷ΪһÖÖ´«²¼»úÔì¡£ÀÕË÷ڿƺÍÍøÂç´¹µöÓÐËùÔö³¤¡£Õë¶ÔMSSQLµÄ¹¥»÷³ÊÉÏÉýÇ÷Ïò£¬´Ó2022ÄêϰëÄêµÄ9.4ÒÚ´ÎÔö³¤µ½2023ÄêÉϰëÄêµÄ17ÒڴΡ£
https://www.welivesecurity.com/wp-content/uploads/2023/07/eset_threat_report_h12023.pdf


¾©¹«Íø°²±¸11010802024551ºÅ