ServiceBridgeÊý¾Ý¿âÅäÖôíÎóµ¼ÖÂÊý°ÙÍòÌõÃô¸Ð¼Ç¼̻¶

Ðû²¼Ê±¼ä 2024-08-28
1. ServiceBridgeÊý¾Ý¿âÅäÖôíÎóµ¼ÖÂÊý°ÙÍòÌõÃô¸Ð¼Ç¼̻¶


8ÔÂ26ÈÕ£¬ServiceBridgeÊÇÒ»¼Ò×ܲ¿Î»ÓÚÖ¥¼Ó¸çµÄÖªÃûÏÖ³¡·þÎñ¹ÜÀíƽ̨£¬½üÆÚÒòÒ»´ÎÑÏÖصÄÊý¾Ý¿âÅäÖôíÎó¶øÏÝÈëÊý¾Ýй¶Î£»ú¡£ÍøÂçÄþ¾²×¨¼ÒJeremiah Fowler½Ò¶ÁËÕâһ©¶´£¬µ¼ÖÂÁè¼Ý3100ÍòÌõ¼Ç¼¡¢×ܼÆ2.68TBµÄÃô¸ÐÊý¾Ý̻¶ÓÚ¹«ÖÚÊÓÒ°£¬ÆäÖв»·¦ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëÄËÖÁ²¿ÃÅÐÅÓÿ¨ÐÅÏ¢¼°HIPAA¹æ¶¨µÄ¸öÈ˽¡¿µÐÅÏ¢¡£¸ÃÊý¾Ý¿âÎÞÐèÈκÎÄþ¾²ÈÏÖ¤¼´¿É·ÃÎÊ£¬ÇÒÊý¾Ý¿ç¶È³¤´ïÊ®Ä꣬Éæ¼°¶à¸öÐÐÒµµÄÆóÒµºÍ¸öÈË£¬°üÂÞѧУ¡¢×ڽ̻ú¹¹¡¢Á¬Ëø²ÍÌü¼°Ò½ÁÆ·þÎñÌṩÕߵȡ£´Ë´Î鶵ÄÊý¾Ý¹æÄ£ÅÓ´óÇÒÃô¸Ð¶È¸ß£¬ÒýÆðÁ˹㷺µÄÄþ¾²ºÍÒþ˽µ£ÓÇ¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄܱ»ÓÃÓÚ·¢Æ±ÆÛÕ©¡¢Éí·Ý͵ÇԵȷǷ¨ÐÐΪ£¬²»½öÍþвµ½ÆóÒµµÄ²ÆÕþÄþ¾²ºÍÉùÓþ£¬»¹¿ÉÄܸø¸öÈË´øÀ´ÉîÖصľ­¼ÃËðʧºÍÒþ˽ÇÖ·¸¡£´ËÍ⣬Êý¾Ý¿âÖл¹°üÂÞÎïÀíÄþ¾²Ïà¹ØµÄÃô¸ÐÐÅÏ¢£¬Èç´óÃÅÃÜÂëºÍ·ÃÎʼǼ£¬½øÒ»²½¼Ó¾çÁËDZÔÚµÄÄþ¾²·çÏÕ¡£ServiceBridgeÔÚ½Óµ½Í¨ÖªºóÁ¢¼´¹Ø±ÕÁËÊý¾Ý¿âµÄ¹ûÈ»·ÃÎÊȨÏÞ£¬µ«¹ØÓÚÊý¾Ý鶵ÄÁ¬Ðøʱ¼ä¼°ÊÇ·ñÒÑÓеÚÈý·½½éÈëÈÔ²»µÃ¶øÖª¡£


https://hackread.com/servicebridge-expose-2tb-records-cloud-misconfiguration/


2. TDECUÔâClopÀÕË÷Èí¼þ¹¥»÷£¬³¬50Íò¸öÈËÐÅϢй¶


8ÔÂ26ÈÕ£¬µÂ¿ËÈø˹ÌÕÊÏÔ±¹¤ÐÅÓúÏ×÷É磨TDECU£©½üÆÚÐû²¼£¬Áè¼Ý50ÍòÃû³ÉÔ±µÄ¸öÈËÐÅÏ¢ÔÚÈ¥ÄêµÄÒ»´ÎÓɶíÓïÀÕË÷Èí¼þ×éÖ¯Clop·¢¶¯µÄºÚ¿Í¹¥»÷Öв»ÐÒй¶¡£´Ë´Î¹¥»÷ÀûÓÃÁËMOVEit Transfer¹ÜÀíÎļþ´«Ê䣨MFT£©Èí¼þÖеÄÁãÈÕ©¶´£¨CVE-2023-34362£©£¬¸Ã©¶´ÓÚ2023Äê5ÔÂ31ÈÕ±»Progress Software¹ûÈ»Åû¶¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Emsisoft¹ÀË㣬´Ë´Îʼþ²¨¼°Áè¼Ý2700¸ö×éÖ¯£¬Ó°ÏìÈËÊý¸ß´ïÔ¼9600Íò¡£TDECUÓÚÉÏÖÜÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ³ÂËߣ¬²¢Ïò500,474ÃûÊÜÓ°Ïì³ÉÔ±·¢ËÍÁË֪ͨÐÅ£¬ÐÅÖÐÏêÊöÁ˺ڿʹÓMOVEitÇÔÈ¡µÄÃô¸ÐÐÅÏ¢·¶Î§£¬°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢ÒøÐÐÕË»§¼°ÐÅÓÿ¨ºÅ¡¢¼ÝÕպŵÈÒªº¦¸öÈËÉí·Ý¼°²ÆÕþÐÅÏ¢¡£¾¡¹ÜTDECUĿǰδ·¢ÏÖÒò¸Ãʼþµ¼ÖµÄÖ±½ÓÉí·Ý»ò½ðÈÚÆÛÕ©°¸Àý£¬µ«ÈÔΪÊÜÓ°Ïì³ÉÔ±ÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓüà¿Ø·þÎñ£¬²¢½¨ÒéËûÃÇÉèÖÃÆÛÕ©¾¯±¨»òÉêÇëÄþ¾²¶³½á£¬ÒÔ·À·¶Ç±ÔÚ·çÏÕ¡£


https://www.securityweek.com/500k-impacted-by-texas-dow-employees-credit-union-data-breach/


3. ARRLÏòÀÕË÷Èí¼þÍÅ»ïÖ§¸¶ÁË100ÍòÃÀÔªÊê½ð


8ÔÂ26ÈÕ£¬È«¹úÒµÓàÎÞÏßµçЭ»áÃÀ¹úÎÞÏßµçÖмÌÁªÃË£¨ARRL£©½üÆÚÅû¶£¬¸Ã×éÖ¯ÔÚ2024Äê5ÔÂ15ÈÕÔâÊÜÁËÒ»³¡ÆÆ»µÐÔµÄÀÕË÷Èí¼þ¹¥»÷£¬ËæºóÖ§¸¶ÁË100ÍòÃÀÔªÊê½ðÒÔ»Ö¸´±»¼ÓÃܵÄÄÚ²¿ÍøÂçϵͳ¡£´Ë´Î¹¥»÷²»½öÉ漰̨ʽ»ú¡¢Ìõ¼Ç±¾µçÄÔ£¬»¹²¨¼°WindowsºÍLinux·þÎñÆ÷£¬ÏÔʾÁ˸߶ȵÄ×éÖ¯ÐÔºÍЭµ÷ÐÔ¡£¹¥»÷ÕßÔÚÊýÖÜÇ°¾ÍÒÑDZÈëARRLµÄÏÖ³¡ºÍÔÆϵͳ£¬ÀûÓðµÍøÐÅϢʵʩÈëÇÖ¡£Ãæ¶ÔÊý°ÙÍòÃÀÔªµÄÀÕË÷ÒªÇó£¬ARRL¾­Ð­É̺óÖ§¸¶ÁË100ÍòÃÀÔª£¬Òò¹¥»÷ÕßδÄÜ»ñÈ¡Ãô¸ÐÊý¾Ý¶ø½µµÍÁËÊê½ð½ð¶î¡£ARRLÇ¿µ÷£¬´Ë¿îÏî¼°ºóÐøÐÞ¸´ÓöÈÖ÷ÒªÓɱ£ÏÕ¸ºµ£¡£·þÎñÖжÏÆڼ䣬°üÂÞ¡°ÊÀ½çÈÕÖ¾¡±£¨LoTW£©ÔÚÄڵĶàÏî·þÎñ±»ÔÝʱ¹Ø±Õ£¬Ö±µ½7ÔÂ1ÈÕLoTW»Ö¸´£¬¾¡¹ÜÆä·þÎñÆ÷×Ô¼ºÎ´Ö±½ÓÊÜË𣬵«ÒÀÀµÆäËûÊÜÓ°ÏìµÄ·þÎñÆ÷¡£Ä¿Ç°£¬ARRL´ó²¿ÃÅϵͳÒѻָ´£¬µ«»ù´¡ÉèÊ©µÄÈ«ÃæÐÞ¸´ÈÔÐèÒ»Á½¸öÔÂʱ¼ä¡£¹ØÓÚ¸öÈËÐÅϢй¶Çé¿ö£¬ARRLδÃ÷ȷ˵Ã÷£¬µ«ÒÑ֪ͨÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ£¬¿ÉÄÜÓÐ150ÃûÔ±¹¤µÄÐÅÏ¢£¨ÈçÐÕÃû¡¢µØÖ·¡¢Éç»áÄþ¾²ºÅÂ룩Êܵ½Ó°Ïì¡£


https://www.securityweek.com/american-radio-relay-league-paid-1-million-to-ransomware-gang/


4. ConnexureÔâBlackSuitÀÕË÷Èí¼þ¹¥»÷£¬½ü°ÙÍòÈËÊý¾Ýй¶


8ÔÂ27ÈÕ£¬Young Consulting£¨ÏÖ¸üÃûΪConnexure£©£¬Ò»¼ÒרעÓÚ¹ÍÖ÷Ö¹ËðÊг¡µÄÑÇÌØÀ¼´óÈí¼þ½â¾ö·½°¸ÉÌ£¬½üÈÕ¿ªÊ¼ÏòÔ¼954,177ÃûÓû§·¢ËÍÊý¾Ýй¶֪ͨ£¬ÕâÔ´ÓÚ½ñÄê4ÔÂ10ÈÕÔâÊܵÄBlackSuitÀÕË÷Èí¼þ¹¥»÷¡£´Ë´Î¹¥»÷µ¼Ö°üÂÞ¼ÓÖÝÀ¶¶Ü»áÔ±ÔÚÄÚµÄÓû§Êý¾Ý±»µÁ£¬ÈýÌìºó¹«Ë¾²Å²ì¾õϵͳ±»¼ÓÃÜ¡£¾­ÊӲ죬ȷÈÏй¶ÐÅÏ¢°üÂÞÈ«Ãû¡¢Éç»áÄþ¾²ºÅÂë¡¢³öÉúÈÕÆÚ¼°±£ÏÕË÷ÅâÏêÇ顣Ϊ¼õÇáÓ°Ï죬ConnexureΪÊÜÓ°ÏìµÄÓû§ÌṩCyberScoutµÄ12¸öÔÂÃâ·ÑÐÅÓüà¿Ø·þÎñÖÁ2024Äê11Եס£¼øÓÚBlackSuitÒÑÔÚ°µÍøÀÕË÷ÃÅ»§ÉÏÐû²¼²¿ÃÅÊý¾Ý£¬Óû§ÐèÁ¢¼´ÀûÓô˷þÎñ²¢¾¯ÌèδÊÚȨͨÐÅ¡¢ÍøÂçµöÓã¼°Õ©Æ­Æóͼ¡£ÍþвÕß²»½öÐû³Æ¶Ô¹¥»÷ÂôÁ¦£¬»¹Íþв½øÒ»²½Ð¹Â¶¸ü¶àδÅû¶µÄÐÅÏ¢£¬ÈçÉÌÒµºÏͬ¡¢Ô±¹¤»¤ÕÕ¡¢¼Òͥϸ½Ú¼°²ÆÕþÊý¾ÝµÈ£¬µ«Ïà¹Ø˵·¨ÉÐδ¾­¶ÀÁ¢ÑéÖ¤¡£

https://www.bleepingcomputer.com/news/security/blacksuit-ransomware-stole-data-of-950-000-from-software-vendor/


5. Microsoft SwayÔÚ´ó¹æÄ£¶þάÂëÍøÂçµöÓã»î¶¯Öб»ÀÄÓÃ


8ÔÂ27ÈÕ£¬NetskopeÍþвʵÑéÊÒ½üÆÚ½Ò¶ÁËÒ»Æð´ó¹æÄ£µÄÍøÂçµöÓã»î¶¯£¬¸Ã»î¶¯ÀûÓÃMicrosoft SwayÕâÒ»ÔÚÏßÑÝʾƽ̨£¬Í¨¹ýÍйܵöÓãµÇ¼ҳÃ棬Õë¶ÔMicrosoft 365Óû§ÊµÊ©Æ¾Ö¤ÇÔÈ¡¡£×Ô2024Äê7ÔÂÒÔÀ´£¬´ËÀ๥»÷ÊýÁ¿¼±¾çì­Éý£¬Ö÷Òª²¨¼°ÑÇÖÞÓë±±ÃÀµØÓò£¬¿Æ¼¼¡¢ÖÆÔì¼°½ðÈÚµÈÐÐÒµ³ÉΪÖØÔÖÇø¡£¹¥»÷ÕßÓÕµ¼Êܺ¦ÕßɨÃè¶þάÂ룬½ø¶øÌøתÖÁ¶ñÒâÍøÕ¾£¬ÓÈÆäÀûÓÃÒƶ¯É豸Äþ¾²µ¥±¡µÄÌص㣬ÈƹýÄþ¾²¼ì²â¡£¹¥»÷ÊֶΰüÂÞ͸Ã÷ÍøÂçµöÓ㣬ÇÔÈ¡¶àÒòËØÈÏÖ¤ÐÅÏ¢£¬Ê¹Êܺ¦ÕßÔÚ²»ÖªÇéϵǼÆäÕË»§¡£´ËÍ⣬¹¥»÷Õß»¹ÀûÓÃCloudflare Turnstile¹¤¾ß£¬Òþ²ØµöÓãÄÚÈÝ£¬Î¬»¤ÓòÃûÉùÓþ£¬ÌÓ±ÜÍøÂç¹ýÂË·þÎñÀ¹½Ø¡£´Ë´ÎʼþÓëÎåÄêÇ°µÄPerSwaysionÍøÂçµöÓã»î¶¯ÀàËÆ£¬¾ùͨ¹ýMaaS²Ù×÷£¬ÀÖ³ÉÉø͸¶à¼ÒÆóÒµ¸ß²ãÕË»§£¬°üÂÞÃÀ¹ú¡¢¼ÓÄôóµÈ¶à¹ú¹«Ë¾¸ß¹Ü¡£ÕâÔÙ´ÎÌáÐÑÓû§ÐèÌá¸ß¾¯Ì裬·À·¶¶þάÂëÍøÂçµöÓã·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/microsoft-sway-abused-in-massive-qr-code-phishing-campaign/


6. ¶ñÒâÈí¼þMalAgent.AutoITBot£¬Gmail¼°¶àƽ̨ÕÊ»§µÄÒþÃØÍþв


8ÔÂ27ÈÕ£¬SonicWall Capture Labs ×î½ü½ÒʾÁËÃûΪ MalAgent.AutoITBot µÄÐÂÐͶñÒâÈí¼þ£¬ËüרÃÅÕë¶Ô Gmail ÕË»§Ìᳫ¹¥»÷£¬µ«Íþв·¶Î§Ô¶²»Ö¹ÓÚ´Ë¡£Õâ¿îͨ¹ý AutoIT ±àÒëµÄ¡°File.exe¡±·¨Ê½£¬ÀûÓöÁÈ¡¼ôÌù°å¡¢²¶×½°´¼üÄËÖÁ¿ØÖƼüÅÌÊó±êµÈÅÓ´óÊÖ¶ÎÈëÇÖÓû§ÏµÍ³¡£MalAgent ²»½öÊÔͼͨ¹ýÖ÷Á÷ä¯ÀÀÆ÷·ÃÎÊ Gmail£¬»¹Õ¹ÏÖ³öÊý¾ÝÇÔÈ¡¡¢ÏµÍ³ÀûÓü°·´·ÖÎöÄÜÁ¦µÄ¶àÃæÐÔ£¬Ê¹ÆäÄÜÇáËÉÊÕ¼¯Ãô¸ÐÐÅÏ¢²¢×è°­Äþ¾²·ÖÎö¡£SonicWall ʹÓÃרҵ¹¤¾ß½âÎöÆäÐÐΪ£¬·¢ÏÖÆä¸ß¶È»ìÏýµÄ´úÂëºÍ¶¯Ì¬C2Á¬½ÓÉèÖã¬Ôö¼ÓÁË×·×ÙÄѶÈ¡£¸Ã¶ñÒâÈí¼þ»¹°üÂÞÕë¶ÔÆäËûÉ罻ýÌåƽ̨µÄµÇ¼Á´½Ó£¬ÏÔʾ³öÆä¶àÄ¿±ê¹¥»÷µÄÌØÐÔ¡£ÁîÈ˵£ÓǵÄÊÇ£¬MalAgent Äܾ²Ä¬ÔËÐжà¸ö½ø³Ì£¬ÈçÒþ²ØÒ³Ãæ²Ù×÷ºÍÍøÂçÌ×½Ó×ÖʵÑ飬ÒÔÌӱܼì²â¡£ÕâÒ»·¢ÏÖÇ¿µ÷ÁËÔÚ´¦ÖÃδ֪ÎļþʱÐè±£³Ö¸ß¶È¾¯Ì裬ÒÔÃâ³ÉΪÆäDZÔÚÊܺ¦Õß¡£


https://securityonline.info/sonicwall-warns-new-malware-targets-gmail/