ServiceBridgeÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂÊý°ÙÍòÌõÃô¸Ð¼Í¼¶³ö

°ä²¼¹¦·ò 2024-08-28
1. ServiceBridgeÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂÊý°ÙÍòÌõÃô¸Ð¼Í¼¶³ö


8ÔÂ26ÈÕ £¬ServiceBridgeÊÇÒ»¼Ò×ܲ¿Î»ÓÚÖ¥¼Ó¸çµÄ³ÛÃûÏÖ³¡·þÎñÖÎÀíÆ½Ì¨ £¬½üÆÚÒòÒ»´ÎÑϳÁµÄÊý¾Ý¿âÅäÖÃÃýÎó¶øÏÝÈëÊý¾Ýй¶Î£»ú ¡£ÍøÂ簲ȫר¼ÒJeremiah Fowler¸æ·¢ÁËÕâÒ»·ì϶ £¬µ¼Ö³¬¹ý3100Íò±Ê¼Í¼¡¢×ܼÆ2.68TBµÄÃô¸ÐÊý¾Ý¶³öÓÚ¹«¼ÒÊÓÒ° £¬ÆäÖв»·¦ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëÉõÖÁ²¿ÃÅÐÅÓþ¿¨ÐÅÏ¢¼°HIPAA»®¶¨µÄÓ×ÎÒ½¡È«ÐÅÏ¢ ¡£¸ÃÊý¾Ý¿âÎÞÐèÈκΰ²È«ÈÏÖ¤¼´¿É½Ó¼û £¬ÇÒÊý¾Ý¿ç¶È³¤´ïÊ®Äê £¬Éæ¼°¶à¸öÐÐÒµµÄÆóÒµºÍÓ×ÎÒ £¬Ô̺¬Ñ§Ìá¢×ڽ̻ú¹¹¡¢Á¬Ëø²ÍÌü¼°Ò½ÁÆ·þÎñÌṩÕßµÈ ¡£Õâ´Îй¶µÄÊý¾Ý¹æÄ£ÖØ´óÇÒÃô¸Ð¶È¸ß £¬ÒýÆðÁË¿í·ºµÄ°²È«ºÍÒþÖÔÓÇÓô ¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄܱ»ÓÃÓÚ·¢Æ±Ú²Æ­¡¢Éí·Ý͵ÇԵȷ¸·¨ÐÐΪ £¬²»½öÍþвµ½ÆóÒµµÄ²ÆÕþ°²È«ºÍÃûÓþ £¬»¹¿ÉÄܸøÓ×ÎÒ´øÀ´ÉîºñµÄ¾­¼ÃËðʧºÍÒþÖÔ¼Óº¦ ¡£´Ë±í £¬Êý¾Ý¿âÖл¹Ô̺¬ÎïÀí°²È«ÓйصÄÃô¸ÐÐÅÏ¢ £¬Èç´óÃÅÃÜÂëºÍ½Ó¼û¼Í¼ £¬½øÒ»²½¼Ó¾çÁËDZÔڵݲȫ·çÏÕ ¡£ServiceBridgeÔÚ½Óµ½Í¨Öªºóµ±¼´¹Ø¹ØÁËÊý¾Ý¿âµÄ¹«¿ª½Ó¼ûȨÏÞ £¬µ«¹ØÓÚÊý¾Ýй¶µÄ³ÖÐø¹¦·ò¼°ÊÇ·ñÒÑÓеÚÈý·½È¾Ö¸ÈÔ²»µÃ¶øÖª ¡£


https://hackread.com/servicebridge-expose-2tb-records-cloud-misconfiguration/


2. TDECUÔâClopÀÕË÷Èí¼þ¹¥»÷ £¬³¬50ÍòÓ×ÎÒÐÅϢй¶


8ÔÂ26ÈÕ £¬µÂ¿ËÈøË¹ÌÕÊÏÔ±¹¤ÐÅÓþºÏ×÷É磨TDECU£©½üÆÚ°ä·¢ £¬³¬¹ý50ÍòÃû³ÉÔ±µÄÓ×ÎÒÐÅÏ¢ÔÚÈ¥ÄêµÄÒ»´ÎÓɶíÓïÀÕË÷Èí¼þ×éÖ¯Clop·¢ÆðµÄºÚ¿Í¹¥»÷Öв»ÐÒй¶ ¡£Õâ´Î¹¥»÷ÀûÓÃÁËMOVEit TransferÖÎÀíÎļþ´«Ê䣨MFT£©Èí¼þÖеÄÁãÈÕ·ì϶£¨CVE-2023-34362£© £¬¸Ã·ì϶ÓÚ2023Äê5ÔÂ31ÈÕ±»Progress Software¹«¿ªÅû¶ ¡£¾ÝÍøÂ簲ȫ¹«Ë¾Emsisoft¹ÀËã £¬Õâ´ÎÊÂÎñ²¨¼°³¬¹ý2700¸ö×éÖ¯ £¬Ó°ÏìÈËÊý¸ß´ïÔ¼9600Íò ¡£TDECUÓÚÉÏÖÜÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«Êһ㱨 £¬²¢Ïò500,474ÃûÊÜÓ°Ïì³ÉÔ±·¢ËÍÁË֪ͨÐÅ £¬ÐÅÖÐÏêÊöÁ˺ڿʹÓMOVEitÇÔÈ¡µÄÃô¸ÐÐÅÏ¢ÁìÓò £¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§¼°ÐÅÓþ¿¨ºÅ¡¢¼ÝÕպŵȹؼüÓ×ÎÒÉí·Ý¼°²ÆÕþÐÅÏ¢ ¡£Ö»¹ÜTDECUĿǰδ·¢ÏÖÒò¸ÃÊÂÎñµ¼ÖµÄÖ±½ÓÉí·Ý»ò½ðÈÚڲƭ°¸Àý £¬µ«ÈÔΪÊÜÓ°Ïì³ÉÔ±ÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ £¬²¢½¨ÒéËûÃÇÉèÖÃڲƭ¾¯±¨»òÉêÖÂÒâÈ«¶³½á £¬ÒÔ·À±¸Ç±ÔÚ·çÏÕ ¡£


https://www.securityweek.com/500k-impacted-by-texas-dow-employees-credit-union-data-breach/


3. ARRLÏòÀÕË÷Èí¼þÍÅ»ïÖ§¸¶ÁË100ÍòÃÀÔªÊê½ð


8ÔÂ26ÈÕ £¬È«¹úÒµÓàÎÞÏßµçЭ»áÃÀ¹úÎÞÏßµçÖмÌͬÃË£¨ARRL£©½üÆÚÅû¶ £¬¸Ã×éÖ¯ÔÚ2024Äê5ÔÂ15ÈÕÔâ·êÁËÒ»³¡·ÛËéÐÔµÄÀÕË÷Èí¼þ¹¥»÷ £¬ËæºóÖ§¸¶ÁË100ÍòÃÀÔªÊê½ðÒÔ¸´Ô­±»¼ÓÃܵÄÄÚ²¿ÍøÂçϵͳ ¡£Õâ´Î¹¥»÷²»½öÉæ¼°Ì¨Ê½»ú¡¢±Ê¼Ç±¾µçÄÔ £¬»¹²¨¼°WindowsºÍLinux·þÎñÆ÷ £¬ÏÔʾÁ˸߶ȵÄ×éÖ¯ÐÔºÍЭµ÷ÐÔ ¡£¹¥»÷ÕßÔÚÊýÖÜǰ¾ÍÒÑDZÈëARRLµÄÏÖ³¡ºÍÔÆÏµÍ³ £¬ÀûÓðµÍøÐÅÏ¢Ö´ÐÐÈëÇÖ ¡£Ãæ¶ÔÊý°ÙÍòÃÀÔªµÄÀÕË÷ÒªÇó £¬ARRL¾­Ð­É̺óÖ§¸¶ÁË100ÍòÃÀÔª £¬Òò¹¥»÷ÕßδÄÜ»ñÈ¡Ãô¸ÐÊý¾Ý¶ø½µµÍÁËÊê½ð½ð¶î ¡£ARRLÇ¿µ÷ £¬´Ë¿î×Ó¼°ºóÐø½¨¸´ÓöÈÖØÒªÓɱ£Ïճе£ ¡£·þÎñÖÐ¶ÏÆÚ¼ä £¬Ô̺¬¡°ÊÀ½çÈÕÖ¾¡±£¨LoTW£©ÔÚÄڵĶàÏî·þÎñ±»ÁÙʱ¹Ø¹Ø £¬Ö±µ½7ÔÂ1ÈÕLoTW¸´Ô­ £¬Ö»¹ÜÆä·þÎñÆ÷×ÔÉíδֱ½ÓÊÜË𠣬µ«ÒÀÀµÆäËûÊÜÓ°ÏìµÄ·þÎñÆ÷ ¡£Ä¿Ç° £¬ARRL´ó²¿ÃÅϵͳÒѸ´Ô­ £¬µ«»ù´¡ÉèÊ©µÄÈ«Ãæ½¨¸´ÈÔÐèÒ»Á½¸öÔ¹¦·ò ¡£¹ØÓÚÓ×ÎÒÐÅϢй¶Çé¿ö £¬ARRLδÃ÷È·×¢Ã÷ £¬µ«ÒÑ֪ͨÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ £¬¿ÉÄÜÓÐ150ÃûÔ±¹¤µÄÐÅÏ¢£¨ÈçÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂ룩Êܵ½Ó°Ïì ¡£


https://www.securityweek.com/american-radio-relay-league-paid-1-million-to-ransomware-gang/


4. ConnexureÔâBlackSuitÀÕË÷Èí¼þ¹¥»÷ £¬½ü°ÙÍòÈËÊý¾Ýй¶


8ÔÂ27ÈÕ £¬Young Consulting£¨ÏÖ¸ÄÃûΪConnexure£© £¬Ò»¼ÒרһÓÚ¹ÍÖ÷Ö¹ËðÊг¡µÄÑÇÌØÀ¼´óÈí¼þ½â¾ö¹æ»®ÉÌ £¬½üÈÕÆðÍ·ÏòÔ¼954,177ÃûÓû§·¢ËÍÊý¾Ýй¶֪ͨ £¬ÕâÔ´ÓÚ½ñÄê4ÔÂ10ÈÕÔâ·êµÄBlackSuitÀÕË÷Èí¼þ¹¥»÷ ¡£Õâ´Î¹¥»÷µ¼ÖÂÔ̺¬¼ÓÖÝÀ¶¶Ü»áÔ±ÔÚÄÚµÄÓû§Êý¾Ý±»µÁ £¬ÈýÌìºó¹«Ë¾²Å¾õ²ìϵͳ±»¼ÓÃÜ ¡£¾­µ÷²é £¬È·ÈÏй¶ÐÅÏ¢Ô̺¬È«Ãû¡¢Éç»á°²È«ºÅÂë¡¢µ®ÉúÈÕÆÚ¼°±£ÏÕË÷ÅâÏêÇé ¡£Îª¼õÇáÓ°Ïì £¬ConnexureΪÊÜÓ°ÏìµÄÓû§ÌṩCyberScoutµÄ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø·þÎñÖÁ2024Äê11Ôµ× ¡£¼øÓÚBlackSuitÒÑÔÚ°µÍøÀÕË÷ÃÅ»§Éϰ䲼²¿ÃÅÊý¾Ý £¬Óû§Ðèµ±¼´ÀûÓô˷þÎñ²¢¾¯ÌèδÊÚȨͨѶ¡¢ÍøÂç´¹µö¼°Ú¿Æ­Ì°Í¼ ¡£ÍþвÕß²»½öÐû³Æ¶Ô¹¥»÷ÕÆ¹Ü £¬»¹Íþв½øÒ»²½Ð¹Â¶¸ü¶àδÅû¶µÄÐÅÏ¢ £¬ÈçóÒ׺Ïͬ¡¢Ô±¹¤»¤ÕÕ¡¢¼Òͥϸ½Ú¼°²ÆÕþÊý¾ÝµÈ £¬µ«ÓйØËµ·¨ÉÐδ¾­¶ÀÁ¢ÑéÖ¤ ¡£

https://www.bleepingcomputer.com/news/security/blacksuit-ransomware-stole-data-of-950-000-from-software-vendor/


5. Microsoft SwayÔÚ´ó¹æÄ£¶þάÂëÍøÂç´¹µö»î¶¯Öб»ÀÄÓÃ


8ÔÂ27ÈÕ £¬NetskopeÍþв³¢ÊÔÊÒ½üÆÚ¸æ·¢ÁËһ·´ó¹æÄ£µÄÍøÂç´¹µö»î¶¯ £¬¸Ã»î¶¯ÀûÓÃMicrosoft SwayÕâÒ»ÔÚÏßÑÝʾƽ̨ £¬Í¨¹ýÍйܴ¹µöµÇÂ¼Ò³Ãæ £¬Õë¶ÔMicrosoft 365Óû§Ö´ÐÐÆ¾Ö¤ÇÔÈ¡ ¡£×Ô2024Äê7ÔÂÒÔÀ´ £¬´ËÀ๥»÷ÊýÁ¿¼±¾çì­Éý £¬ÖØÒª²¨¼°ÑÇÖÞÓë±±ÃÀµØÓò £¬¿Æ¼¼¡¢Ôì×÷¼°½ðÈÚµÈÐÐÒµ³ÉΪ³ÁÔÖÇø ¡£¹¥»÷ÕßÓÕµ¼Êܺ¦ÕßɨÃè¶þάÂë £¬½ø¶øÌø×ªÖÁ¶ñÒâÍøÕ¾ £¬ÓÈÆäÀûÓÃÒÆ¶¯É豸°²È«ÓÄ΢µÄÌØµã £¬Èƹý°²È«¼ì²â ¡£¹¥»÷¼¿Á©Ô̺¬Í¨Ã÷ÍøÂç´¹µö £¬ÇÔÈ¡¶à³É·ÖÈÏÖ¤ÐÅÏ¢ £¬Ê¹Êܺ¦ÕßÔÚ²»ÖªÇéϵǼÆäÕË»§ ¡£´Ë±í £¬¹¥»÷Õß»¹ÀûÓÃCloudflare Turnstile¹¤¾ß £¬°µ²Ø´¹µöÄÚÈÝ £¬ÊØ»¤ÓòÃûÃûÓþ £¬ÌÓ±ÜÍøÂç¹ýÂË·þÎñÀ¹½Ø ¡£Õâ´ÎÊÂÎñÓëÎåÄêǰµÄPerSwaysionÍøÂç´¹µö»î¶¯ÀàËÆ £¬¾ùͨ¹ýMaaS²Ù×÷ £¬³É¹¦ÉøÈë¶à¼ÒÆóÒµ¸ß²ãÕË»§ £¬Ô̺¬ÃÀ¹ú¡¢¼ÓÄôóµÈ¶à¹ú¹«Ë¾¸ß¹Ü ¡£ÕâÔÙ´ÎÌáÐÑÓû§ÐèÌá¸ß¾¯Ìè £¬·À±¸¶þάÂëÍøÂç´¹µö·çÏÕ ¡£


https://www.bleepingcomputer.com/news/security/microsoft-sway-abused-in-massive-qr-code-phishing-campaign/


6. ¶ñÒâÈí¼þMalAgent.AutoITBot £¬Gmail¼°¶àƽ̨ÕÊ»§µÄÒþÃØÍþв


8ÔÂ27ÈÕ £¬SonicWall Capture Labs ×î½ü½ÒʾÁËÃûΪ MalAgent.AutoITBot µÄÐÂÐͶñÒâÈí¼þ £¬ËüרÃÅÕë¶Ô Gmail ÕË»§ÌáÒé¹¥»÷ £¬µ«ÍþвÁìÓòÔ¶²»Ö¹ÓÚ´Ë ¡£Õâ¿îͨ¹ý AutoIT ±àÒëµÄ¡°File.exe¡±·¨Ê½ £¬ÀûÓöÁÈ¡¼ôÌù°å¡¢²¶»ñ°´¼üÉõÖÁ½ÚÔì¼üÅÌÊó±êµÈ¸´ÔÓ¼¿Á©ÈëÇÖÓû§ÏµÍ³ ¡£MalAgent ²»½öÊÔͼͨ¹ýÖ÷Á÷ä¯ÀÀÆ÷½Ó¼û Gmail £¬»¹Õ¹Ê¾³öÊý¾ÝÇÔÈ¡¡¢ÏµÍ³°Ñ³Ö¼°·´·ÖÎöÄÜÁ¦µÄ¶àÃæÐÔ £¬Ê¹ÆäÄÜÇáËÉÍøÂçÃô¸ÐÐÅÏ¢²¢¹ÊÕϰ²È«·ÖÎö ¡£SonicWall ʹÓÃרҵ¹¤¾ß½âÎöÆäÐÐΪ £¬·¢ÏÔìä¸ß¶È»ìºÏµÄ´úÂëºÍ¶¯Ì¬C2ÏνÓÉèÖà £¬Ôö³¤ÁË×·×ÙÄѶÈ ¡£¸Ã¶ñÒâÈí¼þ»¹Ô̺¬Õë¶ÔÆäËûÉ罻ýÌåÆ½Ì¨µÄµÇ¼Á´½Ó £¬ÏÔʾ³öÆä¶àÖ¸±ê¹¥»÷µÄ¸öÐÔ ¡£ÁîÈËÓÇÓôµÄÊÇ £¬MalAgent Äܾ²Ä¬ÔËÐжà¸ö¹ý³Ì £¬Èç°µ²ØÒ³Ãæ²Ù×÷ºÍÍøÂçÌ×½Ó×Ö³¢ÊÔ £¬ÒÔÌӱܼì²â ¡£ÕâÒ»·¢ÏÖÇ¿µ÷ÁËÔÚ´¦ÖÃδ֪ÎļþʱÐèά³Ö¸ß¶È¾¯Ìè £¬ÒÔÃâ³ÉΪÆäDZÔÚÊܺ¦Õß ¡£


https://securityonline.info/sonicwall-warns-new-malware-targets-gmail/