Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª£»ÃÀ¹úCVS HealthÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý10ÒÚÌõ¼Ç¼
Ðû²¼Ê±¼ä 2021-06-171.Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª
Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓüäµýÈí¼þ·Ç·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª¡£¸Ãʼþ·¢ÉúÔÚ2009ÄêÖÁ2012Äê¼ä£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸ö¼äµýϵͳÀ´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÂôÁ¦ÈËJean-Louis Baillot½¨Á¢µÄ£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿î¡£¼ì²ì¹ÙÌåÏÖ£¬Ò˼ҷ¨¹ú¹«Ë¾ÀûÓþ¯·½ÏûÏ¢À´Ô´£¬Æ¸ÇëÁËÒ»¼Ò˽È˱£°²¹«Ë¾ºÍ˽ÈËÕì̽·Ç·¨»ñÈ¡ÆäÔ±¹¤µÄ»úÃÜÐÅÏ¢¡£¸ÃÐÌÊÂÊÓ²ìÓÚ2012ÄêÆô¶¯£¬Ö±µ½±¾Öܶþ²ÅÏÂÁî·£¿î¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/
2.ÃÀ¹úCVS HealthÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý10ÒÚÌõ¼Ç¼
Ñо¿ÍŶÓÓÚ2021Äê3ÔÂ21ÈÕ·¢ÏÖÁËÒ»¸ö²»ÊÜÃÜÂë±£»¤µÄÊý¾Ý¿â¡£¾¹ý½øÒ»²½Ñо¿£¬¸ÃÊý¾Ý¿âÓëÃÀ¹úÒ½ÁƱ£½¡¹«Ë¾CVS HealthÓйء£Êý¾Ý¿â¾ÞϸΪ204GB£¬×ܼÆÓÐ1148327940Ìõ¼Ç¼£¬°üÂ޷ÿÍID¡¢»á»°ID¡¢É豸ÐÅÏ¢ºÍÈÕ־ϵͳÈçºÎ´Óºó¶ËÔËÐеÄÀ¶Í¼µÈÄÚÈÝ£¬ÒÔ¼°ÓйØÒ©Îï¡¢COVID-19ÒßÃçºÍCVSÖÖÖÖ²úÎïµÄÐÅÏ¢¡£CVS HealthÌåÏÖ£¬¸ÃÊý¾Ý¿âÓÉÒ»¸öµÚÈý·½¹©Ó¦ÉÌÔÚ¹ÜÀí£¬ÏÖÔÚÒѾ±»±£»¤ÆðÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/billions-of-records-belonging-to-cvs-health-exposed-online/
3.ÃÀ¹ú±ûÍ鹩ӦÉÌAmeriGasÖ÷¶¯Åû¶Æä½üÆÚµÄÊý¾Ýй¶Ê¼þ
ÃÀ¹ú×î´óµÄ±ûÍ鹩ӦÉÌAmeriGasÖ÷¶¯Åû¶Æä½üÆÚ·¢ÉúµÄÊý¾Ýй¶Ê¼þ¡£AmeriGasÔÚÃÀ¹úµÄ50¸öÖÝΪÁè¼Ý200Íò¿Í»§Ìṩ·þÎñ£¬ÓµÓÐ2500¶à¸ö·ÖÏúµã¡£5ÔÂ10ÈÕ£¬ÏòAmeriGasÌṩÔËÊ䲿 (DOT) ºÏ¹æ·þÎñµÄ¹©Ó¦ÉÌJJ KellerÔÚÆäϵͳÉϼì²âµ½¿ÉÒɻ£¬ºó·¢ÏÖÆäÔ±¹¤Ôâµ½Á˵öÓã¹¥»÷µ¼ÖÂÕÊ»§±»µÁ£¬¸Ã¹«Ë¾Á¢¿Ì¿ªÊ¼È·¶¨´Ë´Îй¶µÄ·¶Î§¡£5ÔÂ21ÈÕ£¬JJ Keller֪ͨAmeriGas´Ëʼþ¿ÉÄÜй¶ÁËAmeriGasµÄ123ÃûÔ±¹¤µÄ¼Ç¼£¬°üÂÞʵÑéÊÒID¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂëºÍ³öÉúÈÕÆÚ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/
4.ThroughTek P2P SDKÃ÷ÎÄй¶£¬Ó°ÏìÊý°ÙÍòÉãÏñÍ·
CISAÅû¶ÁËThroughTekµÄP2P SDKÖеÄÃ÷ÎÄй¶©¶´£¬Ó°ÏìÁËÊý°ÙÍò¸öÉãÏñÍ·¡£¸Ã©¶´×·×ÙΪCVE-2021-32934£¬CVSS v3»ù±¾ÆÀ·ÖΪ9.1¡£¸Ã×é¼þÒѱ»¶à¼ÒÄþ¾²ÉãÏñÍ·µÄÔʼÉè±¸ÖÆÔìÉÌ (OEM) ÒÔ¼°ÎïÁªÍøÉè±¸ÖÆÔìÉÌʹÓã¬Òѱ»°²×°ÔÚÊý°ÙÍò¸öÉ豸ÖУ¬ÀýÈçÓ¤¶ùºÍ³èÎï¼à¿ØÉãÏñÍ·¡¢»úÆ÷ÈËºÍµç³ØÉ豸µÈ¡£CISAÌåÏÖ£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´·ÃÎÊÃô¸ÐÐÅÏ¢£¬ÈçÏà»úÒôƵ/ÊÓÆµÔ´µÈ£¬½ØÖÁÏÖÔÚ»¹Ã»±»ÔÚÒ°ÀûÓá£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ics/advisories/icsa-21-166-01
5.ÒÔÉ«Áйú·À¾üǰÕÕÁϳ¤µÄ¼ÆËã»úÔâµ½ÒÁÀʺڿ͵ÄÈëÇÖ
±¾Öܶþ£¬ÒÔÉ«ÁÐʱ±¨³ÆÒÁÀʺڿ͹¥»÷ÁËÒÔÉ«Áйú·À¾üµÄǰÕÕÁϳ¤µÄ¼ÆËã»ú£¬²¢»ñµÃÁËËûµÄÕû¸ö¼ÆËã»úÊý¾Ý¿âµÄ·ÃÎÊȨÏÞ¡£Channel 10ÌåÏָúڿÍÊÇYaser Balaghi£¬¾Ý³ÆËûÔÚºóÀ´´µÐê×Ô¼ºµÄÐÐΪʱ²»Öª²»¾õµØÁôÏÂÁ˺ۼ££¬µ¼ÖÂÒÁÀÊÍ£Ö¹ÁËÕë¶ÔÈ«Çò1800ÈË£¨°üÂÞÒÔÉ«Áн¾ü½«¾ü¡¢²¨Ë¹ÍåÈËȨº´ÎÀÕߺÍѧÕߣ©µÄÍøÂçÐж¯¡£ÔÚ¹ýÈ¥µÄÁ½ÄêÖУ¬ÒÔÉ«ÁÐÒ»Ö±ÊÇÐí¶àÍøÂç¹¥»÷µÄÄ¿±ê¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/iran-said-to-hack-former-israeli-army-chief-of-staff-access-his-entire-computer-533222.shtml
6.CybereasonÐû²¼ÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄ·ÖÎö³ÂËß
CybereasonÐû²¼ÁËÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Æ½¾ùÿ11Ãë¾Í»á·¢ÉúÒ»´ÎÀÕË÷Èí¼þ¹¥»÷£¬Ô¤¼Æ2021Äê×éÖ¯µÄËðʧ½«µ½´ï200ÒÚÃÀÔª£¬±È2020ÄêÔö¼Ó225%¡£66%µÄ×éÖ¯³ÂËß³ÆÔÚÀÕË÷Èí¼þ¹¥»÷ºóÊÕÈë·ºÆðËðʧ£»35%ÆóÒµÖ§¸¶ÁË35ÍòÖÁ140ÍòÃÀÔªÊê½ð£¬7%µÄÆóÒµÖ§¸¶µÄÊê½ðÁè¼Ý140ÍòÃÀÔª£»53%×éÖ¯³ÆÆäÆ·ÅÆºÍÉùÓþÊÜËð£¬32%×éÖ¯³ÆC¼¶È˲ÅÁ÷ʧ£»26%×éÖ¯³ÂË߳ƹ¥»÷µ¼ÖÂÆóÒµÔÚÒ»¶Îʱ¼äÄÚÍêÈ«¹Ø±Õ¡£
ÔÎÄÁ´½Ó£º
https://www.cybereason.com/blog/report-ransomware-attacks-and-the-true-cost-to-business