ÃÀ¹úijERPÈí¼þÌṩÉÌÅäÖÃÃýÎóй¶50ÍòÓ¡¶Å×û§Êý¾Ý

°ä²¼¹¦·ò 2023-01-04
1¡¢ÃÀ¹úijERPÈí¼þÌṩÉÌÅäÖÃÃýÎóй¶50ÍòÓ¡¶Å×û§Êý¾Ý

      

¾ÝýÌå1ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬×êÑÐÈËԱɨÃèµ½ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝijÆóÒµ×ÊÔ´¹æ»®(ERP)Èí¼þÌṩÉÌÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷¡£¡£ ¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÉæ¼°50¶àÍòÓ¡¶ÈÇóÖ°Õß¡¢¸Ã¹«Ë¾Ô±¹¤ÒÔ¼°¸Ã¹«Ë¾µÄ¿Í»§£¬£¬£¬£¬£¬ £¬Ô̺¬Æ»¹ûºÍÈýÐǵȡ£¡£ ¡£¡£¡£¡£¡£¡£·ÖÎöÏÔʾ£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬³¬¹ý575000È˵ÄÊý¾Ý£¬£¬£¬£¬£¬ £¬´óÓ׳¬¹ý6.3GB£¬£¬£¬£¬£¬ £¬²¢ÇÒÿÌì¶¼ÔÚÔö³¤ÐµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±²¢Î´¹«¿ª¸Ã¹«Ë¾µÄÃû³Æ£¬£¬£¬£¬£¬ £¬ÓÉÓÚ·þÎñÆ÷ĿǰÒÀÈ»Äܹ»¹«¿ª½Ó¼û¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.hackread.com/erp-firm-expose-india-job-seekers-data/


2¡¢Synology½¨¸´VPN Plus ServerÖзì϶CVE-2022-43931

      

¾Ý1ÔÂ3ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬ £¬NASÔì×÷ÉÌSynology½¨¸´ÁËÓ°ÏìÆäÅäÖÃΪVPN·þÎñÆ÷ÔËÐеÄ·ÓÉÆ÷ÖеÄÔ½½çдÈë·ì϶£¨CVE-2022-43931£©¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ1.4.3-0534ºÍ1.4.4-0635֮ǰµÄSynology VPN Plus ServerµÄÔ¶³Ì×ÀÃæÖ°ÄÜÖУ¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£¡£ ¡£¡£¡£¡£¡£¡£·ì϶µÄCVSSÆÀ·ÖΪ10£¬£¬£¬£¬£¬ £¬¿ÉÔڵ͸´ÔÓÐÔ¹¥»÷Öб»ÀûÓ㬣¬£¬£¬£¬ £¬¶øÎÞÐèÖ¸±ê·ÓÉÆ÷µÄȨÏÞ»òÓû§µÄ½»»¥¡£¡£ ¡£¡£¡£¡£¡£¡£VPN Plus ServerÔÊÐíÖÎÀíÔ±½«Synology·ÓÉÆ÷ÉèÖÃΪVPN·þÎñÆ÷£¬£¬£¬£¬£¬ £¬À´Ô¶³Ì½Ó¼û×ÊÔ´¡£¡£ ¡£¡£¡£¡£¡£¡£Õâ´Î¸üл¹½¨¸´ÁËSRMÖеĶà¸ö·ì϶¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/synology-fixes-maximum-severity-vulnerability-in-vpn-routers/


3¡¢LockBitΪ¼ÓÄôó¶ù¿ÆÒ½ÔºSickKids°ä²¼Ãâ·ÑµÄ½âÃÜÆ÷

      

ýÌå1ÔÂ1Èճƣ¬£¬£¬£¬£¬ £¬ÀÕË÷ÍÅ»ïLockBitΪÕë¶Ô¼ÓÄôó¶ù¿ÆÒ½ÔºSickKidsµÄ¹¥»÷·Ǹ£¬£¬£¬£¬£¬ £¬²¢°ä²¼Ãâ·ÑµÄ½âÃÜÆ÷¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÍŻﰵʾ£¬£¬£¬£¬£¬ £¬ËüµÄÒ»¸öºÏ×÷ͬ°éÎ¥·´Á˲»ÈݶԿÉÄܵ¼ÖÂÓ×ÎÒéæÃüµÄ×é֯ϵͳ½øÐмÓÃܵĹ涨£¬£¬£¬£¬£¬ £¬Ä¿Ç°Òѱ»¹Ø±Õ¡£¡£ ¡£¡£¡£¡£¡£¡£SickKidsÔÚ2022Äê12ÔÂ18ÈÕÔâµ½¹¥»÷ £¬£¬£¬£¬£¬ £¬Æäϵͳ¡¢µç»°Ïß·ºÍÍøÕ¾Êܵ½Ó°Ïì¡£¡£ ¡£¡£¡£¡£¡£¡£LockBitÌṩµÄÊÇLinux/VMware ESXi½âÃÜÆ÷£¬£¬£¬£¬£¬ £¬ÓÉÓÚûÓжî±íµÄWindows½âÃÜÆ÷£¬£¬£¬£¬£¬ £¬ÕâÅú×¢¹¥»÷ÕßÖ»ÄܶÔÒ½ÔºÍøÂçÉϵÄÐé¹¹»ú½øÐмÓÃÜ¡£¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/140193/cyber-crime/lockbit-apologized-attack-sickkids.html


4¡¢ÂíÀ´Î÷ÑǵçÐųƳ¬¹ý25ÍòUnifi Mobile¿Í»§µÄÊý¾Ýй¶

      

2022Äê12ÔÂ30ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬ÂíÀ´Î÷ÑǵçÐÅ£¨Telekom Malaysia Bhd£©Ð¹Â©£¬£¬£¬£¬£¬ £¬12ÔÂ28ÈÕÓÐ250248¸öUnifi Mobile¿Í»§Êܵ½Êý¾Ýй¶µÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£¡£ÆäÖмÈÔ̺¬Unifi MobileµÄÓ×ÎÒ¿Í»§£¬£¬£¬£¬£¬ £¬Ò²Ô̺¬ÖÐÓ×ÐÍÆóÒµ(SME)¡£¡£ ¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÀàÐÍÖØÒªÉæ¼°ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþ£¬£¬£¬£¬£¬ £¬Ã»ÓÐÆäËüÐÅϢй¶¡£¡£ ¡£¡£¡£¡£¡£¡£TM°µÊ¾ÒÑ֪ͨÊÜÓ°ÏìÓû§£¬£¬£¬£¬£¬ £¬²¢ÏòÓйص±¾Ö»ã±¨´ËÊ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´×¢Ã÷ÕâÊǺÎÖÖÎ¥¹æÐÐΪ»òÊÇÈôºÎ²úÉú¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.nst.com.my/business/2022/12/865784/250248-unifi-mobile-customers-affected-data-breach-says-tm


5¡¢Emisoft°ä²¼2022ÄêÃÀ¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄͳ¼Æ·ÖÎö»ã±¨

      

1ÔÂ2ÈÕ£¬£¬£¬£¬£¬ £¬Emisoft°ä²¼Á˹ØÓÚ2022ÄêÃÀ¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄͳ¼Æ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬2022ÄêµÄÀÕË÷¹¥»÷Ó°ÏìÁËÃÀ¹úµ±¾Ö¡¢½ÌÓýºÍÒ½ÁÆ´¹Ö±ÁìÓò¹«¹²²¿ÃŵÄ200¶à¸ö´óÐÍ×éÖ¯¡£¡£ ¡£¡£¡£¡£¡£¡£Óë2021ÄêÏà±È£¬£¬£¬£¬£¬ £¬Õë¶Ô´¦Ëùµ±¾ÖµÄÀÕË÷¹¥»÷´Ó77ÆðÔö³¤µ½105Æð £»£»£»£»£»ÀÕË÷Èí¼þϰȾÁËÃÀ¹ú89¼Ò½ÌÓý»ú¹¹¡¢44Ëù´óѧºÍ45¸öÑ§Çø£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÔÚÖÁÉÙ58´Î¹¥»÷ÖÐÇÔÈ¡ÁËÊý¾Ý £»£»£»£»£»Õë¶ÔÒ½ÔººÍ¶àÒ½ÔºÎÀÉúϵͳµÄ¹¥»÷2022ÄêÔö³¤µ½24Æð£¬£¬£¬£¬£¬ £¬¿ÉÄÜÓ°Ïì¶à´ï289¼ÒÒ½Ôº¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.emsisoft.com/en/blog/43258/the-state-of-ransomware-in-the-us-report-and-statistics-2022/


6¡¢Imperva°ä²¼2022ÄêDDoS¹¥»÷ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£

      

ImpervaÔÚ2022Äê12ÔÂ27ÈÕ°ä²¼ÁË2022ÄêDDoS¹¥»÷ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£×Ô2021ÄêÒÔÀ´£¬£¬£¬£¬£¬ £¬DDoS¹¥»÷ÔÚÊýÁ¿ºÍƵÂÊÉ϶¼ÓÐÉÏÉýµÄÇ÷Ïò£¬£¬£¬£¬£¬ £¬Ã¿ÃëÖÁÉÙ50ÍòRPSµÄµÚ7²ãDDoS¹¥»÷ÔÚ´ÓǰһÄêÖÐÔö³¤ÁË81%¡£¡£ ¡£¡£¡£¡£¡£¡£³ýÁËÆµÂʸü¸ßÖ®±í£¬£¬£¬£¬£¬ £¬2022Äê×î´ó¹¥»÷±È2021ÄêµÄ´ó4.5±¶¡£¡£ ¡£¡£¡£¡£¡£¡£2021ÄêϰëÄ꣬£¬£¬£¬£¬ £¬¾ùÔÈÿÔ²úÉú2.2´Î´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬ £¬2022Äê¾ùÔÈÿÔ²úÉú4´Î´ó¹æÄ£¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£2021ÄêµÄËùÓй¥»÷¾ùµÍÓÚ100ÍòRPS£¬£¬£¬£¬£¬ £¬µ«2022Äê´ó¹æÄ£DDoS¹¥»÷µÄ¾ùÔÈֵΪ145ÍòRPS£¬£¬£¬£¬£¬ £¬ÆäÖÐ×î´ó¹¥»÷´ïµ½1000ÍòRPS¡£¡£ ¡£¡£¡£¡£¡£¡£2021Ä꣬£¬£¬£¬£¬ £¬´ó¹æÄ£¹¥»÷ÖØÒªÕë¶Ôµ±¾Ö¡¢½ðÈÚºÍÆû³µÍøÕ¾£¬£¬£¬£¬£¬ £¬2022ÄêÔòÊÇÕë¶ÔÆû³µ¡¢ÍÆËãºÍµçÐÅÁìÓò¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.imperva.com/blog/81-increase-in-large-volume-ddos-attacks/