ÌØÀÊÆÕ¾ÆµêÊý¾Ýй¶ÊÂÎñÒý·¢¹Ø×¢

°ä²¼¹¦·ò 2025-02-08

1. ÌØÀÊÆÕ¾ÆµêÊý¾Ýй¶ÊÂÎñÒý·¢¹Ø×¢


2ÔÂ6ÈÕ£¬Ò»ÃûÃûΪFutureSeekerµÄÓû§ÔÚºÚ¿ÍÂÛ̳BreachForumsÉϰ䲼ÁËÒ»ÔòÒÉËÆ´ÓTrump Hotels[.]comÇÔÈ¡µÄÊý¾Ý¼¯Ñù±¾Ð¹Â¶ÐÅÏ¢£¬Ô̺¬160,000¶à±Ê¼Í¼¡£¾Ý³Æ£¬ÕâЩÐÅÏ¢À´×ԸþƵêµÄµç×ÓÓʼþ֪ͨϵͳ£¬ÓÃÓÚÌáÐѺÍÑéÖ¤¿ÍÈËÔ¤Ô¼ÏêÇé¡£FutureSeekerÔÚÌû×ÓÖгÆÕâЩ¼Í¼Ϊ¡°ÌØÀÊÆÕ¾ÆµêµÄÔ¼Ç뺯¡±£¬²¢¼¤ÀøÉçÇø³ÉÔ±ÏÂÔØ¡£Ö»¹ÜÉÐÎ´È«ÃæÑéÖ¤£¬µ«Ð¹Â¶µÄÑù±¾ÖÐÔ̺¬ÁËÈ«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢´´½¨ÈÕÆÚµÈÃô¸ÐÐÅÏ¢¡£¶ñÒâÈí¼þ´æ´¢¿âvx-underground¶Ô´ËÊÂÎñ½øÐÐÁË·ÖÎö£¬ÒÔΪÕâ´ÎÈëÇÖ²¢·Ç³öÓÚÕþÖλò¾­¼Ã¶¯»ú£¬¶øÊÇÍþвÐÐΪÕßÊÔͼÔÚ°µµØÊг¡ÉÏÑéÖ¤ÆäºÏ·¨ÐÔµÄÒ»ÖÖ·½Ê½¡£Í¬Ê±Ö¸³ö£¬±»µÁÐÅÏ¢ËÆºõ²¢Î´Ô̺¬ÌØÀÊÆÕ¼¯Íž­Óª¾Æµê¿ÍÈ˵ÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬ÈçÔ¤Ô¼ÈÕÆÚ¡¢ÈëסÈÕÆÚ¡¢ÍË·¿ÈÕÆÚ¼°²ÆÕþÐÅÏ¢µÈ¡£´Ë±í£¬ÕâЩÐÅÏ¢µÄ¹¦·ò¿ç¶È´Ó2018Äê1ÔÂ18ÈÕÖÁ2025Äê1ÔÂ15ÈÕ¡£


https://cybernews.com/security/trump-hotels-data-leak-claim-breach-forums/


2. Trimble Cityworks·ì϶ÔâºÚ¿ÍÀûÓã¬Áª¹ú»ú¹¹´¹Î£ÒªÇ󽨲¹


2ÔÂ8ÈÕ£¬Áª¹úÃñÊ»ú¹¹±»´¹Î£ÒªÇóÓÚ2ÔÂ28ÈÕǰ½¨²¹Ó°ÏìTrimble CityworksµÄCVE-2025-0994·ì϶¡£Trimble CityworksÊÇÒ»¿î¿í·º±»µ±¾ÖºÍ´¦Ëù»ú¹¹Ñ¡È¡µÄ»ù´¡ÉèÊ©×ʲúÖÎÀí¹¤¾ß£¬ÓÃÓÚÖÎÀí»ú³¡¡¢¹«ÓÃÊÂÒµ¼°ÊÐÕþÉèÊ©µÈ¡£ÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ÓëTrimble½áºÏ°ä²¼ÖҸ棬ָ³ö¸Ã·ì϶Õý±»ºÚ¿ÍÀûÓã¬ÔÊÐíÔ¶³Ì´úÂëÖ´ÐУ¬¶ÔMicrosoft Internet ÐÅÏ¢·þÎñ£¨IIS£©ÍøÂç·þÎñÆ÷×é³ÉÍþв¡£TrimbleÔÚµ÷²éδÊÚȨ½Ó¼û³¢ÊÔºó°ä²¼²¹¶¡£¬²¢ÒªÇó¿Í»§²ÉÈ¡¶î±í´ëÊ©± £»¤Êý¾Ý£¬Ô̺¬ÏÞ¶ÈȨÏÞºÍÔ¤·ÀÒÔÖÎÀíȨÏÞÔËÐÐCityworks¡£CISAÓëÈüÃÅÌú¿ËÍþвÁÔÈËÍŶӶԴ˷ì϶²¼¸æÓÐËù¹±Ï×£¬¸Ã·ì϶CVSS v4ÆÀ·Ö¸ß´ï8.4¡£ËùÓÐ15.8.9°æ±¾Ö®Ç°µÄCityworks¾ùÊÜÓ°Ïì¡£TrimbleÊÇÒ»¼ÒÈ«Çò¼¼Êõ¾ÞÍ·£¬Õ¼Óг¬¹ý11,000ÃûÔ±¹¤£¬ÔÚ40¶à¸ö¹ú¶ÈÔËÓª£¬ÉÏÒ»²Æ¼¾ÊÕÈë´ï8.758ÒÚÃÀÔª¡£


https://therecord.media/hackers-exploiting-trimble-cityworks-bug-used-by-local-govs


3. °Í¹þÂí´óѧÔâÀÕË÷Èí¼þ¹¥»÷£¬ÍøÂçµç»°ÏµÍ³Ì±»¾


2ÔÂ8ÈÕ£¬°Í¹þÂí´óѧ½üÈÕÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸ÃУʹÓõĻ¥ÁªÍøºÍµç»°ÏµÍ³±»¹Ø¹Ø£¬Ó°ÏìÁËËùÓÐÔÚÏßÀûÓ÷¨Ê½£¬Ô̺¬µç×ÓÓʼþºÍ½²ÌÃ×÷ҵϵͳ£¬ËùÓÐÔÚÏ߿γ̱»È¡µÞ¡£Ñ§ÌöÔÔÚ»ý¼«µ÷²éÊÂÎñÁìÓò£¬²¢¶½´ÙѧÉú¸ü¸ÄÃÜÂë¡£Ãæ¶ÔÃæÊÚ¿ÎËä¿É³ÖÐø£¬µ«Ñ§Ìñ»ÆÈµ÷ÕûÉêÇë½ØÖ¹ÈÕÆÚºÍ×÷Òµ½ØÖ¹ÈÕÆÚ¡£´Ë±í£¬Ñ§ÌÃ×ÔÖ÷·þÎñֻͤ½ÓÊÜÏÖ½ðÖ§¸¶£¬µç»°ÏµÍ³ÈÔ´¦ÓÚÀëÏß״̬£¬µ«ÒÑÌṩһʱÊÖ»úºÅÂ롣ѧÌÃÍøÕ¾ÒÑÓÚÖÜÎ帴ԭ·þÎñ¡£Ñ§ÌöÔÔÚÖ´Ðзֽ׶εÄÍøÂ縴ԭ²½Ö裬²¢Ñ¡È¡¼ÓÇ¿µÄ°²È«ºÍ̸À´± £»¤ÏµÍ³¡£½ØÖÁÖÜÎåÏÂÎ磬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈϿɶÔÕâ´ÎÊÂÎñÕÆ¹Ü¡£¸Ã´óѧÊǰ͹þÂí×î´óµÄ¹ÍÖ÷Ö®Ò»£¬Õ¼ÓÐ 700 ¶àÃû½ÌÈËÔ±¹¤¡£¸ÃУÉÐδ»ØÓ¦ÓйØÀÕË÷Èí¼þ×éÖ¯ÊÇ·ñÅú×¢Éí·Ý»òÊÇ·ñ»áÖ§¸¶Êê½ðµÄÆÀÂÛÒªÇó¡£


https://therecord.media/bahamas-university-ransomware-attack


4. HPEÔâ¶íÂÞ˹µ±¾ÖÖ§³ÖºÚ¿Í¹¥»÷£¬Office 365Êý¾ÝÔâÇÔÈ¡


2ÔÂ7ÈÕ£¬»ÝÆÕÆóÒµ£¨HPE£©½üÈÕÈ·ÈÏ£¬ÔÚ2023Äê5ÔÂÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬¶íÂÞ˹µ±¾ÖÖ§³ÖµÄºÚ¿Í×éÖ¯Cozy Bear£¨ÓÖ³ÆMidnight Blizzard¡¢APT29ºÍNobelium£©´ÓÆäOffice 365µç×ÓÓʼþ»·¾³ÖÐÇÔÈ¡ÁËÊý¾Ý¡£¸Ã×éÖ¯¾ÝÐÅÊǶíÂÞ˹¶Ô±íµý±¨¾Ö(SVR)µÄÒ»²¿ÃÅ£¬Ò²Ôø²Î¼Ó2020ÄêSolarWinds¹©¸øÁ´¹¥»÷µÈ±¸ÊÜÖõÖ÷ÕÅÎ¥¹æÐÐΪ¡£HPEÒÑÏòÖÁÉÙ16ÃûÓ×ÎÒÐÅÏ¢±»µÁµÄÔ±¹¤·¢ËÍÁËÎ¥¹æÍ¨ÖªÐÅ£¬Ô̺¬¼ÝÕÕ¡¢ÐÅÓþ¿¨ºÅºÍÉç»á±£ÏպŵÈÃô¸ÐÐÅÏ¢¡£¾ÝHPE½²»°ÈËй©£¬Ö»ÓÐÓÐÏÞÒ»²¿ÃÅÍŶӳÉÔ±µÄÓÊÏä±»½Ó¼û£¬ÇÒÊÜÓ°ÏìµÄÊÇÕâЩÓÊÏäÖÐÔ̺¬µÄÐÅÏ¢¡£´Ë±í£¬HPE»¹°µÊ¾£¬Õâ´Î¹¥»÷¿ÉÄÜÓëÁíһ·Υ¹æÐÐΪÓйØ£¬ÆäʱÍþвÐÐΪÕß½Ó¼ûÁ˹«Ë¾µÄSharePoint·þÎñÆ÷²¢ÇÔÈ¡ÁËÎļþ¡£×î½ü£¬ÔÚʹÓÃIntelBroker¾ä±úµÄÍþвÐÐΪÕßÐû³ÆÇÔÈ¡HPEƾ֤¡¢Ô´´úÂëºÍÆäËûÃô¸ÐÐÅÏ¢ºó£¬¸Ã¹«Ë¾Ò²ÆðÍ·µ÷²éÆäËûDZÔڵݲȫ·ì϶¡£


https://www.bleepingcomputer.com/news/security/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/


5. HSHS³¬88Íò»¼ÕßÊý¾ÝÒò2023Äê8ÔÂÍøÂç¹¥»÷й¶


2ÔÂ7ÈÕ£¬Ò½Ôº½ãÃý¡È«ÏµÍ³£¨HSHS£©ÔÚ2023Äê8ÔÂÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬µ¼Ö³¬¹ý882,000Ãû»¼ÕßµÄÓ×ÎҺͽ¡È«ÐÅϢй¶¡£¸Ã·ÇͶ»úÐÔÒ½ÁƱ£½¡ÏµÍ³ÔËÓª×ÅÒÁÀûŵÒÁÖݺÍÍþ˹¿µÐÇÖݵÄ15¼ÒÒ½ÔººÍÒ½ÉúÕïËùÍøÂç¡£¹¥»÷ÕßÔÚ2023Äê8ÔÂ16ÈÕÖÁ8ÔÂ27ÈÕÆÚ¼ä½Ó¼ûÁËÊÜϰȾϵͳÉϵÄÎļþ£¬µ¼ÖÂҽԺϵͳ´óÃæ»ýÖжÏ£¬ÏÕЩËùÓвÙ×÷ϵͳºÍµç»°ÏµÍ³Ì±»¾¡£HSHSÀñƸÁË±í²¿°²È«×¨¼Ò½øÐе÷²éºÍ¸´Ô­¹¤×÷£¬µ«Ä¿Ç°ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´ËÊÂÎñÕÆ¹Ü¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƼͼºÅ¡¢Ò½ÖÎÐÅÏ¢¡¢½¡È«±£ÏÕÐÅÏ¢¡¢Éç»á°²È«ºÅÂëºÍ¼ÝÊ»ÅÆÕÕºÅÂëµÈ¡£HSHSÖÒ¸æÊÜÓ°ÏìµÄÓ×ÎÒ¼à¿ØÕË»§±¨±íºÍÐÅÓþ»ã±¨£¬²¢ÌṩÁËÒ»ÄêµÄÃâ·ÑEquifaxÐÅÓþ¼à¿Ø¡£½üÆÚ£¬¶à¸öÒ½ÁƱ£½¡ÌṩÉÌÒ²Ôâ·êÁËÊý¾Ýй¶ºÍÀÕË÷Èí¼þ¹¥»÷£¬Òý·¢Á˶Ի¼Õß½¡È«Êý¾Ý°²È«µÄÓÇÓô¡£ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿ÌáÒé¶ÔHIPAA½øÐиüУ¬ÒÔÓ¦¶Ô´óÁ¿Ò½ÁƱ£½¡°²È«·ì϶µÄ²úÉú¡£


https://www.bleepingcomputer.com/news/security/us-health-system-notifies-882-000-patients-of-august-2023-breach/


6. Âó½ðÄáÊÐÊýǧ¾ÓÃñÊý¾ÝÒòʮԷÝÍøÂç¹¥»÷й¶


2ÔÂ6ÈÕ£¬µÂ¿ËÈøË¹ÖÝÂó½ðÄáÊвúÉúÁËһ·Êý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁËÊýǧÃû¾ÓÃñ¡£¸ÃÊÐÈ·µ±¾ÖϵͳÔÚ10ÔÂ31ÈÕÔâµ½ÍøÂç¹¥»÷£¬µ«Ö±µ½11ÔÂ14Èղŷ¢ÏÖ¡£Ö»¹ÜÊе±¾Ö¹ÙԱδй©ÊÇ·ñΪÀÕË÷Èí¼þ¹¥»÷»òºÚ¿ÍÉí·Ý£¬µ«ÊÂÎñ²úÉúºó£¬ITÍŶÓѸ¿ì¶Â½ØÁËδ¾­ÊÚȨµÄ»î¶¯£¬²¢ÁªÏµÁËÓйط¨Âɲ¿ÃÅ¡£¾­¹ýµ÷²é£¬Êе±¾ÖÈ·Èϲ¿ÃÅÎļþ¿ÉÄÜÒѱ»Ð¹Â¶£¬×ܹ²ÓÐ17,751Ãû¾ÓÃñÊܵ½Õâ´ÎÈëÇÖµÄÓ°Ï졣й¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢½ðÈÚÕË»§Êý¾ÝºÍÒ½ÁƱ£ÏÕÐÅÏ¢µÈÃô¸ÐÊý¾Ý¡£Êܺ¦Õß½«»ñµÃÒ»ÄêµÄÉí·Ý± £»¤·þÎñ¡£Õâ´ÎÊÂÎñ¿ÉÄÜ»¹Éæ¼°Ãô¸ÐµÄÔ±¹¤ÐÅÏ¢¡£Ä¿Ç°£¬Ã»ÓÐÈκÎÀÕË÷Èí¼þÍÅ»ï»òºÚ¿Í×éÖ¯ÈϿɶÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£ÕâÆðÊÂÎñÊÇ´ïÀ­Ë¹-ÎÖ˹±¤µØÓò½üÆÚ²úÉúµÄ¶àÆðÍøÂç¹¥»÷Ö®Ò»£¬ÏÔʾ³ö´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·½ÃæÃæ¶ÔµÄÑϸñÌôÕ½¡£


https://therecord.media/thousands-mckinney-texas-residents-impacted