BlackbaudͬÒâÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶Ê¼þµÄÖ¸¿Ø

Ðû²¼Ê±¼ä 2023-10-08

1¡¢BlackbaudͬÒâÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶Ê¼þµÄÖ¸¿Ø


¾Ý10ÔÂ6ÈÕ±¨µÀ £¬ÔƼÆËãÌṩÉÌBlackbaudÓëÃÀ¹ú49¸öÖݸ濢ÁË4950ÍòÃÀÔªµÄЭÒé £¬ÒԺͽâÕë¶Ô2020Äê5ÔµÄÀÕË÷¹¥»÷¼°ÓÉ´ËÒý·¢µÄÊý¾Ýй¶µÄÖ¸¿Ø ¡£¸ÃʼþÓ°ÏìÁËÊý°ÙÍòÓû§ £¬¹¥»÷ÕßÇÔÈ¡ÁËÓû§Î´¼ÓÃܵÄÒøÐÐÐÅÏ¢¡¢µÇ¼ƾ֤ºÍÉç»áÄþ¾²ºÅÂë ¡£BlackbaudÔÚ±»¼û¸æËùÓб»µÁÊý¾ÝÒѱ»Ïú»Ùºó £¬½»ÁËÊê½ð ¡£´Ë´Î¸æ¿¢µÄ4950ÍòÃÀÔªºÍ½âЭÒé½â¾öÁËBlackbaudÎ¥·´ÖÝÏû·ÑÕß±£»¤·¨¡¢Î¥·´Í¨Öª¹æÔòÒÔ¼°½¡¿µ±£ÏÕÁ÷ͨÓëÔðÈη¨°¸(HIPAA)µÄÖ¸¿Ø ¡£


https://www.bleepingcomputer.com/news/security/blackbaud-agrees-to-495-million-settlement-for-ransomware-data-breach/


2¡¢¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»áÔâµ½¹¥»÷²¿ÃÅÑ¡ÃñÐÅϢй¶


¾ÝýÌå10ÔÂ6ÈÕ±¨µÀ £¬¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»á(DCBOE)ĿǰÕýÔÚÊӲ첿ÃÅÑ¡ÃñÐÅϢй¶Ê¼þ ¡£ÊÓ²ìÏÔʾ £¬¹¥»÷Õßͨ¹ýÑ¡¾Ù»ú¹¹µÄÍйÜÌṩÉÌDataNetµÄ·þÎñÆ÷·ÃÎÊÁËÕâЩÐÅÏ¢ £¬µ«DCBOEµÄÄÚ²¿Êý¾Ý¿âºÍ·þÎñÆ÷²¢Î´Êܵ½¹¥»÷ ¡£Ä¿Ç° £¬DCBOEµÄÍøÕ¾Òѹرղ¢ÏÔʾά»¤Ò³Ãæ ¡£RansomedVCÉù³ÆÈëÇÖÁËDCBOE²¢»ñµÃÁËÁè¼Ý60ÍòÌõÃÀ¹úÑ¡ÃñµÄÐÅÏ¢ £¬ËüÔÚ°µÍøÉϳöÊÛ±»µÁÐÅÏ¢ £¬»¹¹ûÈ»ÁËÒ»Ìõ¼Ç¼ÒÔÖ¤Ã÷Êý¾ÝµÄÕæÊµÐÔ ¡£µ«ÊǾݱ¨µÀ £¬DCBOE±»µÁÊý¾Ý¿â×îÏÈÊÇÓÉÃûΪpwncoderµÄÓû§ÔÚºÚ¿ÍÂÛ̳ÖгöÊÛµÄ £¬ÕâЩÌû×ÓÏÖÔÚÒѱ»É¾³ý ¡£


https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/


3¡¢Î¢ÈíÏêÊö¹¥»÷Õßͨ¹ýSQL ServerºáÏòÒÆ¶¯µ½ÔƵķ½Ê½


΢ÈíÔÚ10ÔÂ3ÈÕ³ÆÆä×î½ü·¢ÏÖÁËÒ»´Î¹¥»÷»î¶¯ £¬ÆäÖй¥»÷ÕßÊÔͼͨ¹ýSQL ServerʵÀýºáÏòÒÆ¶¯µ½ÔÆ»·¾³ ¡£ÕâÖÖ¹¥»÷·½Ê½ÔÚÆäËüÔÆ·þÎñ£¨ÀýÈçVMºÍKubernetes£©ÖÐÓз¢ÏÖ¹ý £¬µ«ÔÚSQL ServerÖÐȴûÓÐ ¡£¹¥»÷Õß×î³õÀûÓÃÄ¿±êϵͳµÄÓ¦Ó÷¨Ê½ÖеÄSQL×¢Èë©¶´ £¬À´·ÃÎʲ¿ÊðÔÚAzure ÐéÄâ»ú£¨VM£©ÖеÄMicrosoft SQL ServerʵÀý²¢ÌáÉýÆäȨÏÞ ¡£È»ºó £¬¹¥»÷ÕßÀûÓûñµÃµÄ¸ß¼¶È¨ÏÞ £¬ÊÔͼͨ¹ýÀÄÓ÷þÎñÆ÷µÄÔÆÉí·ÝºáÏòÒÆ¶¯µ½ÆäËüÔÆ×ÊÔ´ ¡£


https://www.microsoft.com/en-us/security/blog/2023/10/03/defending-new-vectors-threat-actors-attempt-sql-server-to-cloud-lateral-movement/


4¡¢Really Simple SystemsÅäÖôíÎóй¶300Íò¿Í»§¼Ç¼


ýÌå10ÔÂ5ÈÕ³Æ £¬Ñо¿ÈËÔ±·¢ÏÖÁËB2B CRM ÌṩÉÌReally Simple Systems°üÂÞ300¶àÍòÌõ¼Ç¼µÄÎÞÃÜÂë±£»¤Êý¾Ý¿â ¡£¸Ã¹«Ë¾ÓµÓÐÁè¼Ý18000¸ö¿Í»§ £¬°üÂ޻ʼÒѧԺ¡¢ºìÊ®×ֻᡢNHSºÍIBMµÈ ¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¾ÝÒ½ÁƼǼ¡¢ÐÅÓóÂËß¡¢Éí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍÖ´·¨ÎļþµÈ £¬Ö÷ÒªÓ°ÏìÁËλÓÚÓ¢¹ú¡¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇµÄÆóÒµ ¡£Ä¿Ç° £¬²»Äþ¾²µÄÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´ £¬Éв»Çå³þ¸ÃÊý¾Ý¿â̻¶µÄʱ¼ä £¬ÒÔ¼°ÊÇ·ñÓÐÈË·ÃÎʹýËü ¡£


https://www.hackread.com/crm-provider-really-simple-systems-data-leak/


5¡¢Checkmarx·¢ÏÖÊý°Ù¸öÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ¶ñÒâPython°ü


10ÔÂ3ÈÕ £¬Checkmarx³ÆÒ»³¡¶ñÒâ»î¶¯ÒÑÔÚ¿ªÔ´Æ½Ì¨ÉÏÖ²ÈëÁËÊý°Ù¸öÐÅÏ¢ÇÔÈ¡°ü £¬ÏÂÔØÁ¿Ô¼Îª75000´Î ¡£×Ô4Ô³õÒÔÀ´ £¬ÔÚPythonÉú̬ϵͳÖÐ £¬¹¥»÷Õßͨ¹ýÖÖÖÖÓû§Ãû²¿ÊðÁËÊý°Ù¸ö¶ñÒâÈí¼þ°ü ¡£×ÔÊ״η¢ÏÖÒÔÀ´ £¬¹¥»÷±äµÃÔ½À´Ô½ÅÓ´ó £¬´ÓÃ÷ÎĹý¶Éµ½¼ÓÃÜ £¬ËæºóÓÖ¹ý¶Éµ½¶à²ã»ìÏýºÍ¶þ´Î·´»ã±àpayload ¡£¶ñÒâ°üÖ¼ÔÚÇÔÈ¡´óÁ¿Ãô¸ÐÊý¾Ý £¬°üÂÞÄ¿±êϵͳ¡¢Ó¦Ó÷¨Ê½¡¢ä¯ÀÀÆ÷ºÍÓû§µÄÊý¾Ý ¡£´ËÍâ £¬ËüÃÇ»¹Í¨¹ýÐ޸ļÓÃÜ»õ±ÒµØÖ·½«½»Ò×ÖØ¶¨Ïòµ½¹¥»÷Õß ¡£


https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/


6¡¢Check PointÐû²¼9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö³ÂËß


10ÔÂ6ÈÕ £¬Check PointÐû²¼ÁË9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö³ÂËß ¡£9Ô·Ý £¬Ñо¿ÈËÔ±·¢ÏÖÁËÕë¶Ô¸çÂ×±ÈÑǶà¸öÐÐÒµµÄ40¶à¼Ò¹«Ë¾µÄ´ó¹æÄ£µöÓã»î¶¯ £¬Ö¼ÔÚ·Ö·¢Remcos RAT ¡£ÔÚQbot±»µ·»Ùºó £¬Æäºã¾ÃÕ¼¾Ý°ñÊ׵ľÖÃæÒѾ­½áÊø £¬9Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ±äΪFormbook £¬Æä´ÎÊÇRemcosºÍEmotet ¡£Ôâµ½¹¥»÷×îÑÏÖØµÄÊǽÌÓýºÍÑо¿ÐÐÒµ £¬Æä´ÎÊÇͨѶÒÔ¼°¾üÕþÁìÓò ¡£×î³£±»ÀûÓõÄ©¶´ÊÇWeb·þÎñÆ÷¶ñÒâURLĿ¼±éÀú©¶´ £¬×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÈÔÈ»ÊÇAnubis ¡£


https://blog.checkpoint.com/security/september-2023s-most-wanted-malware-remcos-wreaks-havoc-in-colombia-and-formbook-takes-top-spot-after-qbot-shutdown/