2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ£»£»£»£»£»£»£»vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ £¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2019-10-09
1.Ponemon InstituteÐû²¼¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤ÖܶþPonemon InstituteÐû²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬£¬ £¬ £¬È«Çò66%µÄÖÐСÐÍÆóÒµ£¨SMB£©ÔÚÒÑÍù12¸öÔÂÄÚ±¨¸æÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£PonemonÌåÏÖÕâÊÇÒ»Á¬µÚÈýÄêSMB±¨¸æµÄÍøÂçÇå¾²ÊÂÎñ·ºÆð¡°ÏÔÖøÔöÌí¡±¡£¡£¡£¡£¡£¡£¡£Ä¿½ñSMBÃæÁÙµÄ×î³£¼ûÍøÂç¹¥»÷ÐÎʽÊÇÍøÂç´¹ÂÚ¡¢×°±¸ÈëÇÖ»ò±»µÁ¡¢Æ¾Ö¤ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£Ëæ×Å×Ô´ø×°±¸°ì¹«£¨BYOD£©Ä£Ê½µÄÊ¢ÐУ¬£¬£¬£¬ £¬ £¬×°±¸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ÔÚÒÑÍù12¸öÔÂÖУ¬£¬£¬£¬ £¬ £¬¹²ÓÐ63%µÄÆóÒµ±¨¸æÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅϢɥʧÊÂÎñ£¬£¬£¬£¬ £¬ £¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬£¬£¬£¬ £¬ £¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬ £¬½ü100Íò»¼ÕßÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



T¨±Ora Compass HealthÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬ £¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£¸Ã³õ¼¶ÎÀÉú×éÖ¯£¨PHO£©ÌåÏÖÆä¹ÙÍøÔÚ8Ô·ݱ¬·¢µÄÒ»ÆðÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬£¬£¬£¬ £¬ £¬Òò´Ë¶ÔCompass HealthµÄÕûÌåITϵͳºÍÇ徲״̬¾ÙÐÐÁËÊӲ죬£¬£¬£¬ £¬ £¬×îÖÕ·¢Ã÷´Ó2016Äêµ½2019Äê3Ô±¬·¢µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£Compass HealthÌåÏÖÈκÎÔÚ2016ÄêÖÁ2019Äêʱ´úÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬£¬£¬£¬ £¬ £¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄµØÇøÖ÷ҪΪÐÂÎ÷À¼»ÝÁé¶Ù£¬£¬£¬£¬ £¬ £¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨Óû§µÄ¹ú¼ÒÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØµãÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐľÙÐÐ×¢²á¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬ £¬¿Í»§ÐÅÓÃÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÄôóTransUnion´ÓÉÏÖÜ×îÏÈÏòÓû§·¢ËÍÊý¾ÝÇå¾²ÊÂÎñ֪ͨ£¬£¬£¬£¬ £¬ £¬ÌåÏÖÓû§µÄÐÅÏ¢Ô⵽δÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¡£¸Ãָ֪ͨ³ö£¬£¬£¬£¬ £¬ £¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕʱ´úδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Æ¾Ö¤»á¼ûÆäÃÅ»§ÍøÕ¾£¬£¬£¬£¬ £¬ £¬²¢¾ÙÐÐÁËÐÅÓñ¨¸æ²éÕÒ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÄܲéÕÒµ½µÄÐÅÓÃÎļþÖаüÀ¨Óû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñ¼°ÒÑÍùµÄµØµãÒÔ¼°Õ÷ÐÅÏà¹ØÐÅÏ¢£¬£¬£¬£¬ £¬ £¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶ÀúÊ·µÈ£¬£¬£¬£¬ £¬ £¬µ«²»°üÀ¨ÏÖʵµÄÕË»§ºÅÂë¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢À´ÊµÑéÉí·Ý͵ÇÔ£¬£¬£¬£¬ £¬ £¬Òò´ËTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓÃڲƭ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾöÒéÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬£¬£¬£¬ £¬ £¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢»Ö¸´ÆäϵͳµÄÕý³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨°üÀ¨DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬ £¬ £¬ÆÈʹËûÃǹرÕÁËÅÌËã»úϵͳ²¢×èÖ¹ÎüÊÕÐµĻ¼Õß¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©DCHÐû²¼¸üÐÂÉùÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÕýÔÚ»Ö¸´Æäϵͳ£¬£¬£¬£¬ £¬ £¬DCH²¢Î´Í¸Â¶Êê½ðµÄÏêϸÊý¶î£¬£¬£¬£¬ £¬ £¬µ«ÒÑÈ·È϶à¸öЧÀÍÆ÷±»ÀֳɽâÃÜ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúDCHµÄϵͳ½«ÓÚºÎʱÍêÈ«ÉÏÏß¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ £¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚÉϸöÔÂÄ©ÐÞ¸´RCE 0dayºó£¬£¬£¬£¬ £¬ £¬vBulletinÐû²¼ÁËÒ»¸öеÄÇå¾²²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬ £¬ÐÞ¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²îÊÇRCEÎó²î£¨CVE-2019-17132£©£¬£¬£¬£¬ £¬ £¬±£´æÓÚvBulletin´¦Öóͷ£Óû§¸üÐÂÆäСÎÒ˽¼Ò×ÊÁϵÄÇëÇóÀú³ÌÖУ¬£¬£¬£¬ £¬ £¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃδ¾­ÓÉÂ˵IJÎÊýÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×¢Èë²¢Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£¡£¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÊÇSQL×¢ÈëÎÊÌ⣬£¬£¬£¬ £¬ £¬ËüÃDZ»·ÖÅÉΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬£¬£¬£¬ £¬ £¬¿ÉÔÊÐí¾ßÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÓ°ÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬£¬£¬£¬ £¬ £¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬ £¬ £¬ÐÞ¸´59¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚÖܶþÐû²¼µÄWindows 10ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË59¸öÎó²î£¬£¬£¬£¬ £¬ £¬ÆäÖаüÀ¨Çå¾²³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1238ºÍCVE-2019-1239£¬£¬£¬£¬ £¬ £¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCEÎó²î£¨CVE-2019-1333£¬£¬£¬£¬ £¬ £¬ÔÊÐí¶ñÒâЧÀÍÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÅþÁ¬Ê±ÔÚ¿Í»§¶ËÉÏÖ´ÐÐÏÂÁµÈ¡£¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/