EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢
Ðû²¼Ê±¼ä 2024-11-261. EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢
11ÔÂ23ÈÕ£¬¼ÓÀû¸£ÄáÑÇÖݵÄ̫ƽÑó·Î²¿Ò½ÁƼ¯ÍÅ(PPMG)ÔâÓöÁËÑÏÖصÄÊý¾Ýй¶Ê¼þ¡£10ÔÂ25ÈÕ£¬EverestÀÕË÷Èí¼þÍŶÓÔÚ°µÍøÉÏÐû²¼ÁËPPMGµÄ»¼ÕßÐÅÏ¢£¬°üÂÞ2021ÖÁ2024ÄêµÄδ¼ÓÃܸöÈ˺ÍÊܱ£»¤½¡¿µÐÅÏ¢¡£Ð¹Â¶µÄÊý¾ÝÒÔ150¶à¸öͼÏñÎļþºÍ¶à¸ö.csvÎļþµÄÐÎʽ´æÔÚ£¬Í¼ÏñÎļþÖ÷Ҫչʾ»¼ÕßµÄÖ÷´Î±£ÏÕ¿¨¼°²¿ÃżÝÕÕÐÅÏ¢£¬¶ø.csvÎļþÔòº¸ÇÁËÁ½ÖÜÄڵĻ¼Õß¾ÍÕï¼Ç¼£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢½¡¿µÐÅÏ¢¼°Õ˵¥ÏêÇéµÈÃô¸ÐÄÚÈÝ¡£×îÐÂÒ»ÅúÊý¾Ý½ØÖÁ10ÔÂ4ÈÕ£¬Ã¿Á½ÖܵÄ.csvÎļþ¼Ç¼×Å300µ½500Ãû»¼ÕߵľÍÕïÇé¿ö¡£È»¶ø£¬Ö±ÖÁÐÅÏ¢Ðû²¼Ê±£¬PPMGÍøÕ¾¼°ÃÀ¹úÎÀÉúÓ빫¹²·þÎñ²¿(HHS)µÄ¹«¹²Î¥¹æ¹¤¾ßÉϾùδÐû²¼Ïà¹Ø֪ͨ¡£DataBreachesÒÑÏòPPMGºÍEverest·¢ËÍѯÎÊ£¬µ«ÉÐδÊÕµ½»Ø¸´¡£
https://databreaches.net/2024/11/23/pacific-pulmonary-medical-group-patient-information-dumped-by-everest-ransomware-team/
2. Áè¼Ý2000̨Palo Alto NetworksÉ豸ÔâºÚ¿ÍÈëÇÖ
11ÔÂ21ÈÕ£¬Palo Alto Networks ³ÂËß³ÆÆä¶à´ï2000̨É豸¿ÉÄÜÒÑÔâµ½ÀûÓÃÐÂÅû¶Äþ¾²Â©¶´µÄ¹¥»÷¡£¾ÝShadowserver»ù½ð»áͳ¼Æ£¬ÃÀ¹ú£¨554Àý£©ºÍÓ¡¶È£¨461Àý£©µÄѬȾ²¡Àý×î¶à£¬ÆäËûÊÜÓ°Ïì¹ú¼Ò°üÂÞÌ©¹ú¡¢Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÍÁ¶úÆä¡¢Ó¢¹ú¡¢ÃسºÍÄÏ·Ç¡£CensysÔò·¢ÏÖ13,324¸ö¹ûȻ̻¶µÄÏÂÒ»´ú·À»ðǽ£¨NGFW£©¹ÜÀí½Ó¿Ú£¬ÆäÖÐ34%λÓÚÃÀ¹ú£¬µ«²¢·ÇËùÓÐ̻¶µÄÖ÷»ú¶¼´æÔÚ©¶´¡£Éæ¼°µÄÄþ¾²Â©¶´°üÂÞCVE-2024-0012£¨CVSS·ÖÊý9.3£©ºÍCVE-2024-9474£¨CVSS·ÖÊý6.9£©£¬ËüÃÇ¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈƹýºÍȨÏÞÌáÉý£¬Ê¹¹¥»÷ÕßÄÜÖ´ÐжñÒâ²Ù×÷¡£Palo Alto NetworksÕý×·×Ù´úºÅΪOperation Lunar PeekµÄ©¶´ÀûÓÃÇé¿ö£¬²¢¾¯¸æ³ÆÕâЩ©¶´Òѱ»ÎäÆ÷»¯£¬¿ÉÄÜÒý·¢¸ü¹ã·ºµÄÍþв»î¶¯¡£¸Ã¹«Ë¾ÒÑÊÓ²ìµÃÊÖ¶¯ºÍ×Ô¶¯É¨Ãè»î¶¯£¬²¢¶Ø´ÙÓû§¾¡¿ìÓ¦ÓÃÐÞ¸´·¨Ê½£¬ÏÞÖƹÜÀí½çÃæ·ÃÎÊ£¬ÒÔ·ÀÖ¹Íⲿ·ÃÎÊ¡£
https://thehackernews.com/2024/11/warning-over-2000-palo-alto-networks.html
3. Blue YonderÔâÀÕË÷Èí¼þ¹¥»÷£¬¹©Ó¦Á´·þÎñÖжÏÓ°Ïì¹ã·º
11ÔÂ25ÈÕ£¬¹©Ó¦Á´¹ÜÀí¹«Ë¾Blue Yonder£¨ÔΪJDA Software£©£¬×÷ΪËÉϵÄ×Ó¹«Ë¾£¬ÄêÊÕÈ볬10ÒÚÃÀÔª£¬ÓµÓÐ6000ÃûÔ±¹¤£¬Îª°üÂÞDHL¡¢À×ŵ¡¢È¸³²¡¢ÌØÒ×¹º¡¢ÐǰͿ˵ÈÖªÃûÆóÒµÔÚÄÚµÄ3000Ãû¿Í»§ÌṩÈ˹¤ÖÇÄÜÇý¶¯µÄ¹©Ó¦Á´½â¾ö·½°¸¡£È»¶ø£¬¸Ã¹«Ë¾½üÆÚÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÍйܷþÎñÍйܻ·¾³·ºÆðÖжϣ¬Ó°ÏìÁËÆä¿Í»§£¬ÌرðÊÇÓ¢¹úµÄÔÓ»õµêÁ¬Ëøµê¡£Blue YonderÒÑÓëÍⲿÍøÂçÄþ¾²¹«Ë¾ºÏ×÷Ó¦¶Ô´Ëʼþ£¬²¢ÊµÊ©Á˶àÏî·ÀÓùºÍÈ¡Ö¤ÐÒ飬µ«ÔÚÆ乫¹²ÔÆ»·¾³ÖÐδ¼ì²âµ½¿ÉÒɻ¡£Ä¿Ç°£¬Blue YonderÈÔÔÚ´¦ÖöàÖÖ»Ö¸´¼Æı£¬µ«ÉÐδ͸¶ȫÃæ»Ö¸´µÄ¾ßÌåʱ¼ä±í¡£ÊÜÓ°ÏìµÄ¿Í»§£¬ÈçMorrisonsºÍSainsbury£¬ÒѽÓÄÉÓ¦¼±´ëÊ©À´¿Ë·þÕâÒ»Öжϡ£½ØÖÁ×îÐÂÏûÏ¢£¬Blue YonderÉÐδÐû²¼ÓйØÇé¿öµÄ×îнøÕ¹£¬ÍƲâÆäÍйܷþÎñ»·¾³ÈÔÈ»Êܵ½Ó°Ï졣Ŀǰ£¬ÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÐû²¼¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£
https://www.bleepingcomputer.com/news/security/blue-yonder-ransomware-attack-disrupts-grocery-store-supply-chain/
4. MetaÖØȹ¥»÷ɱÖíÕ©Æ£¬¹Ø±Õ200ÍòÆÛÕ©ÕË»§
11ÔÂ24ÈÕ£¬×Ô½ñÄêÄê³õÒÔÀ´£¬MetaÒѹرÕÆäƽ̨ÉÏ200Íò¸öÓëɱÖíթƺÍÆäËûÆÛÕ©ÐÐΪÏà¹ØµÄÕË»§£¬ÕâЩÕË»§Ö÷ÒªÀ´×ÔÃåµé¡¢ÀÏÎΡ¢°¢ÁªÇõ¡¢·ÆÂɱöºÍ¼íÆÒÕ¯µÈÒÔ¡°Õ©ÆÅ«Á¥¡±»î¶¯ÎÅÃûµÄ¹ú¼Ò¡£ÕâЩթÆÖÐÐÄͨ¹ýÐû²¼Ðé¼ÙÕÐƸÐÅÏ¢ÒýÓÕÇóÖ°Õߣ¬Ç¿ÆÈËûÃÇ´ÓÊÂÍøÂçÕ©Æ£¬²¢ÒÔÈËÉíÅ°´ý×÷ΪÍþв¡£MetaÓëÕâЩ¹ú¼ÒµÄÖ´·¨»ú¹¹ºÏ×÷£¬·ÖÏíÇ鱨£¬¹¥»÷Õ©ÆÐÐΪ¡£ÆäÖУ¬¡°É±Öí¡±Õ©ÆÊÇÒ»ÖÖÆÆ»µÐԵĽðÈÚͶ×Êƾ֣¬ÒÀÀµÓÚºã¾ÃÀûÓú͸߼¶ÆÛÆ£¬Ä¿±êÓû§±é²¼È«Çò¡£ËäÈ»¿´ËÆÏÝÈëƾֵÄÈËÊý²»¶à£¬µ«ÒѳÉΪÕâЩÓÐ×éÖ¯·¸×OÍŵľ޶îÊÕÈëÀ´Ô´¡£Meta½ÓÄÉÁËһϵÁдëÊ©£¬°üÂÞÖ´ÐÐΣÏÕ×éÖ¯ºÍ¸öÈËÕþ²ß¡¢ÀûÓÃÐÐΪºÍ¼¼ÊõÐźÅʶ±ðºÍ×èÖ¹Õ©ÆÏà¹ØÕË»§ºÍ»ù´¡ÉèÊ©¡¢ÓëÈ«ÇòÖ´·¨²¿ÃźÏ×÷¡¢Óë¿Æ¼¼¹«Ë¾ºÍ×éÖ¯ºÏ×÷¡¢ÌṩÓû§±£»¤¹¦Ð§ºÍ½¨ÒéµÈ£¬ÒÔ¼ì²âºÍ×èÖ¹ÕâЩƾ֣¬±£»¤Óû§ÃâÊÜÆÛÕ©¡£MetaÌáÐÑÓû§½÷É÷¿´´ýδ¾ÇëÇóµÄͨÐÅ£¬ÖÆÖ¹ÔÚÉ罻ýÌåºÍͨѶƽ̨ÉϽèÇ®»ò¼ÓÈë¿ÉÒÉͶ×ʼƻ®¡£
https://www.bleepingcomputer.com/news/security/meta-removes-over-2-million-accounts-pushing-pig-butchering-scams/
5. Ì©¹ú¾¯·½ÆÆ»ñ´ó¹æÄ£¶ÌÐŵöÓãÕ©Æ°¸£¬´þ²¶»õ³µË¾»ú
11ÔÂ24ÈÕ£¬Ì©¹ú¾¯·½ÀÖ³ÉÆÆ»ñÒ»Æð´ó¹æÄ£¶ÌÐÅÕ©Æ°¸£¬´þ²¶ÁË»õ³µË¾»ú¡£¸Ã»õ³µ×°±¸Á˶ÌÐÅ·¢ÉäÆ÷£¬Äܹ»ÔÚ3¹«ÀﷶΧÄÚÿСʱ·¢ËÍ10ÍòÌõµöÓã¶ÌÐÅ¡£Õ©Æ¶ÌÐÅÉù³ÆÓû§µÄ»ý·Ö¼´½«¹ýÆÚ£¬ÒýÓÕËûÃǵã»÷°üÂÞ¡°aisthailand¡±×Ö·û´®µÄµöÓãÍøÕ¾Á´½Ó£¬¸ÃÁ´½Óαװ³ÉÌ©¹ú×î´óÒƶ¯µç»°ÔËÓªÉÌAISµÄ¹Ù·½ÍøÕ¾¡£Óû§Ò»µ©µã»÷Á´½Ó²¢ÊäÈëÐÅÓÿ¨ÐÅÏ¢£¬ÕâЩÐÅÏ¢¾Í»á±»·¢»Ø¸øÕ©ÆÍŻÓÃÓÚÔÚÆäËû¹ú¼Ò½øÐÐδ¾ÊÚȨµÄ½»Òס£¾ÝϤ£¬¸ÃÕ©ÆÍŻﲿÃųÉÔ±ÔÚÌ©¹ú£¬²¿ÃÅÔÚº£Í⣬ͨ¹ý˽ÈËTelegramƵµÀе÷Ðж¯¡£ÔÚÈýÌìÄÚ£¬¸ÃÍÅ»ïÏòÂü¹È¾ÓÃñ·¢ËÍÁ˽üÒ»°ÙÍòÌõթƶÌÐÅ¡£¾¯·½ÕýÔÚ×·²¶ÖÁÉÙÁíÍâÁ½ÃûÍÅ»ï³ÉÔ±£¬²¢µÃµ½ÁËAISµÄÐÖú¶¨Î»¶ÌÐÅ·¢ÉäÆ÷¡£¾¡¹ÜÍøÂçµöÓãÐÅÏ¢µÄÀÖ³ÉÂÊÒò¹«ÖÚÒâʶÌá¸ß¶ø½µµÍ£¬µ«ÔÚÈË¿ÚÃܼ¯µØÓòÒÔ¸ßËÙÁ÷´«Ê±£¬ÈÔÄÜΪ·¸×ïÕß´øÀ´¿É¹ÛÊÕÒæ¡£
https://www.bleepingcomputer.com/news/security/bangkok-busts-sms-blaster-sending-1-million-scam-texts-from-a-van/
6. ΢Èí¶àÏîºËÐÄ·þÎñÔâÓöÈ«ÇòÐÔ´ó¹æÄ£ÖжÏ
11ÔÂ25ÈÕ£¬Î¢ÈíµÄ¶àÏîºËÐÄ·þÎñ£¬°üÂÞMicrosoft 365¡¢Exchange Online¡¢TeamsºÍOutlook£¬ÔâÓöÁËÈ«ÇòÐԵĴó¹æÄ£Öжϣ¬µ¼ÖÂÓû§ÔÚÉ罻ýÌåÉϷ׷׳ÂËßÎÞ·¨·¢ËÍÓʼþ¡¢ÍøÕ¾Í߽⼰´íÎóÒ³ÃæµÈÎÊÌâ¡£ÔÚÁùСʱÄÚ£¬DowndetectorÒÑÊÕµ½Êýǧ·ÝÓû§³ÂËߣ¬ÊÜÓ°ÏìµÄÓû§»¹ÌåÏÖÔÚÁ¬½ÓOneDrive¡¢Purview¡¢CopilotµÈ·þÎñʱҲÓöµ½ÁËÕÏ°¡£Î¢ÈíËæºóÈÏ¿ÉÎÊÌâ´æÔÚ£¬²¢ÔÚƽ̨ÉÏÐû²¼ÉùÃ÷³ÆÕýÔڻعöÏà¹Ø±ä»»²¢Ñ°ÕÒÆäËû»º½â´ëÊ©£¬Í¬Ê±ÁгöÁËÊÜÓ°ÏìµÄ·þÎñºÍʹÓó¡¾°¡£¹ÊÕÏÁ¬Ðø11¸öСʱºó£¬Î¢ÈíÑ¡ÔñÊÖ¶¯ÖØÆô·þÎñÆ÷£¬²¢ÔÚ¹ÜÀíÖÐÐĵÄʼþ³ÂËßÖÐÈ·ÈϸÃÖжÏ×èÖ¹ÁË¿Í»§Í¨¹ý¶àÖÖ·½Ê½·ÃÎÊExchange Online¡£Í¬Ê±£¬Ò»Ð©¿Í»§ÔÚʹÓÃMicrosoft Fabric¡¢Microsoft BookingsºÍMicrosoft Defender for Office 365µÈ·þÎñʱҲÓöµ½ÁËÎÊÌ⡣΢ÈíÌåÏÖÒÑ¿ªÊ¼²¿ÊðÐÞ¸´·¨Ê½£¬²¢ÊÖ¶¯ÖØÆô²¿ÃŲ»½¡¿µµÄ»úÆ÷£¬µ«Ö±µ½25ÈÕ12µã33·Ö£¨EST£©£¬²¿ÊðµÄÐÞ¸´·¨Ê½ÉÐδµ¼ÖÂÍêÈ«µÄ·þÎñ»Ö¸´¡£18µã25·Ö£¨EST£©£¬Î¢Èí½øÒ»²½·ÖÏíÁËʼþÐÅÏ¢£¬³ÆʹÊÊÇÓÉÒ»¸öµ¼Ö·þÎñÆ÷·ÓÉÖØÊÔÇëÇó¼¤ÔöµÄ¸ü¸ÄÒýÆðµÄ£¬ÍŶÓÕýÔÚ»ý¼«Ö´ÐкóÐøÐж¯£¬²¢Å¬Á¦»Ö¸´È«²¿¹¦Ð§¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-impacts-exchange-online-teams-sharepoint/