BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø

°ä²¼¹¦·ò 2023-10-08

1¡¢BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø


¾Ý10ÔÂ6ÈÕ±¨Â·£¬ £¬ £¬£¬£¬ÔÆÍÆËãÌṩÉÌBlackbaudÓëÃÀ¹ú49¸öÖÝ´ï³ÉÁË4950ÍòÃÀÔªµÄºÍ̸£¬ £¬ £¬£¬£¬ÒԺͽâÕë¶Ô2020Äê5ÔµÄÀÕË÷¹¥»÷¼°ÓÉ´ËÒý·¢µÄÊý¾Ýй¶µÄÖ¸¿Ø ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËÊý°ÙÍòÓû§£¬ £¬ £¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁËÓû§Î´¼ÓÃܵÄÒøÐÐÐÅÏ¢¡¢µÇ¼ƾ֤ºÍÉç»á°²È«ºÅÂë ¡£¡£¡£¡£¡£¡£¡£BlackbaudÔÚ±»·î¸æËùÓб»µÁÊý¾ÝÒѱ»Ïú»Ùºó£¬ £¬ £¬£¬£¬½»ÁËÊê½ð ¡£¡£¡£¡£¡£¡£¡£Õâ´Î´ï³ÉµÄ4950ÍòÃÀÔªºÍ½âºÍ̸½â¾öÁËBlackbaudÎ¥·´ÖÝÏû·ÑÕß±£»£»£»£»£»¤·¨¡¢Î¥·´Í¨ÖªÂÉÀýÒÔ¼°½¡È«±£ÏÕÁ÷ͨÓëÔðÈη¨°¸(HIPAA)µÄÖ¸¿Ø ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/blackbaud-agrees-to-495-million-settlement-for-ransomware-data-breach/


2¡¢¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»áÔâµ½¹¥»÷²¿ÃÅÑ¡ÃñÐÅϢй¶


¾ÝýÌå10ÔÂ6ÈÕ±¨Â·£¬ £¬ £¬£¬£¬¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»á(DCBOE)ĿǰÔÚµ÷²é²¿ÃÅÑ¡ÃñÐÅϢй¶ÊÂÎñ ¡£¡£¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬ £¬ £¬£¬£¬¹¥»÷Õßͨ¹ýÑ¡¾Ù»ú¹¹µÄÍйÜÌṩÉÌDataNetµÄ·þÎñÆ÷½Ó¼ûÁËÕâЩÐÅÏ¢£¬ £¬ £¬£¬£¬µ«DCBOEµÄÄÚ²¿Êý¾Ý¿âºÍ·þÎñÆ÷²¢Î´Êܵ½¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬ £¬£¬£¬DCBOEµÄÍøÕ¾Òѹعز¢ÏÔÊ¾ÊØ»¤Ò³Ãæ ¡£¡£¡£¡£¡£¡£¡£RansomedVCÐû³ÆÈëÇÖÁËDCBOE²¢»ñµÃÁ˳¬¹ý60ÍòÌõÃÀ¹úÑ¡ÃñµÄÐÅÏ¢£¬ £¬ £¬£¬£¬ËüÔÚ°µÍøÉÏÏúÊÛ±»µÁÐÅÏ¢£¬ £¬ £¬£¬£¬»¹¹«¿ªÁËÒ»±Ê¼Í¼ÒÔÖ¤Ã÷Êý¾ÝµÄÕæÊµÐÔ ¡£¡£¡£¡£¡£¡£¡£µ«ÊǾݱ¨Â·£¬ £¬ £¬£¬£¬DCBOE±»µÁÊý¾Ý¿â×îÏÈÊÇÓÉÃûΪpwncoderµÄÓû§ÔÚºÚ¿ÍÂÛ̳ÖÐÏúÊ۵ģ¬ £¬ £¬£¬£¬ÕâЩÌû×Ó´Ë¿ÌÒѱ»É¾³ý ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/


3¡¢Î¢ÈíÏêÊö¹¥»÷Õßͨ¹ýSQL ServerºáÏòÒÆ¶¯µ½ÔƵķ½Ê½


΢ÈíÔÚ10ÔÂ3ÈÕ³ÆÆä×î½ü·¢ÏÖÁËÒ»´Î¹¥»÷»î¶¯£¬ £¬ £¬£¬£¬ÆäÖй¥»÷ÕßÊÔͼͨ¹ýSQL ServerÊ·ýºáÏòÒÆ¶¯µ½ÔÆ»·¾³ ¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷·½Ê½ÔÚÆäËüÔÆ·þÎñ£¨ÀýÈçVMºÍKubernetes£©ÖÐÓз¢ÏÖ¹ý£¬ £¬ £¬£¬£¬µ«ÔÚSQL ServerÖÐȴûÓÐ ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß×î³õÀûÓÃÖ¸±êϵͳµÄÀûÓ÷¨Ê½ÖеÄSQL×¢Èë·ì϶£¬ £¬ £¬£¬£¬À´½Ó¼û²¿ÊðÔÚAzure Ðé¹¹»ú£¨VM£©ÖеÄMicrosoft SQL ServerÊ·ý²¢ÌáÉýÆäȨÏÞ ¡£¡£¡£¡£¡£¡£¡£¶øºó£¬ £¬ £¬£¬£¬¹¥»÷ÕßÀûÓûñµÃµÄ¸ß¼¶È¨ÏÞ£¬ £¬ £¬£¬£¬ÊÔͼͨ¹ýÀÄÓ÷þÎñÆ÷µÄÔÆÉí·ÝºáÏòÒÆ¶¯µ½ÆäËüÔÆ×ÊÔ´ ¡£¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/10/03/defending-new-vectors-threat-actors-attempt-sql-server-to-cloud-lateral-movement/


4¡¢Really Simple SystemsÅäÖÃÃýÎóй¶300Íò¿Í»§¼Í¼


ýÌå10ÔÂ5Èճƣ¬ £¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËB2B CRM ÌṩÉÌReally Simple SystemsÔ̺¬300¶àÍò±Ê¼Í¼µÄÎÞÃÜÂë±£»£»£»£»£»¤Êý¾Ý¿â ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Õ¼Óг¬¹ý18000¸ö¿Í»§£¬ £¬ £¬£¬£¬Ô̺¬»Ê¼ÒѧԺ¡¢ºìÊ®×ֻᡢNHSºÍIBMµÈ ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¾ÝÒ½ÁƼͼ¡¢ÐÅÓþ»ã±¨¡¢Éí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍ˾·¨ÎļþµÈ£¬ £¬ £¬£¬£¬ÖØÒªÓ°ÏìÁËλÓÚÓ¢¹ú¡¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇµÄÆóÒµ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬ £¬£¬£¬²»°²È«µÄÊý¾Ý¿âÒѱ»±£»£»£»£»£»¤ÆðÀ´£¬ £¬ £¬£¬£¬Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿â¶³öµÄ¹¦·ò£¬ £¬ £¬£¬£¬ÒÔ¼°ÊÇ·ñÓÐÈ˽Ӽû¹ýËü ¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/crm-provider-really-simple-systems-data-leak/


5¡¢Checkmarx·¢ÏÖÊý°Ù¸öÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ¶ñÒâPython°ü


10ÔÂ3ÈÕ£¬ £¬ £¬£¬£¬Checkmarx³ÆÒ»³¡¶ñÒâ»î¶¯ÒÑÔÚ¿ªÔ´Æ½Ì¨ÉÏÖ²ÈëÁËÊý°Ù¸öÐÅÏ¢ÇÔÈ¡°ü£¬ £¬ £¬£¬£¬ÏÂÔØÁ¿Ô¼Îª75000´Î ¡£¡£¡£¡£¡£¡£¡£×Ô4Ô³õÒÔÀ´£¬ £¬ £¬£¬£¬ÔÚPythonÉú̬ϵͳÖУ¬ £¬ £¬£¬£¬¹¥»÷Õßͨ¹ý¸÷ÀàÓû§Ãû²¿ÊðÁËÊý°Ù¸ö¶ñÒâÈí¼þ°ü ¡£¡£¡£¡£¡£¡£¡£×Ô³õ´Î·¢ÏÖÒÔÀ´£¬ £¬ £¬£¬£¬¹¥»÷±äµÃÔ½À´Ô½¸´ÔÓ£¬ £¬ £¬£¬£¬´ÓÃ÷ÎĹý¶Éµ½¼ÓÃÜ£¬ £¬ £¬£¬£¬ËæºóÓÖ¹ý¶Éµ½¶à²ã»ìºÏºÍ¶þ´Î·´»ã±àpayload ¡£¡£¡£¡£¡£¡£¡£¶ñÒâ°üÖ¼ÔÚÇÔÈ¡´óÁ¿Ãô¸ÐÊý¾Ý£¬ £¬ £¬£¬£¬Ô̺¬Ö¸±êϵͳ¡¢ÀûÓ÷¨Ê½¡¢ä¯ÀÀÆ÷ºÍÓû§µÄÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬ËüÃÇ»¹Í¨¹ýÅú¸Ä¼ÓÃÜÇ®±ÒµØÖ·½«ÂòÂô³Á¶¨Ïòµ½¹¥»÷Õß ¡£¡£¡£¡£¡£¡£¡£


https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/


6¡¢Check Point°ä²¼9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨


10ÔÂ6ÈÕ£¬ £¬ £¬£¬£¬Check Point°ä²¼ÁË9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£¡£9Ô·Ý£¬ £¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ô¸çÂ×±ÈÑǶà¸öÐÐÒµµÄ40¶à¼Ò¹«Ë¾µÄ´ó¹æÄ£´¹µö»î¶¯£¬ £¬ £¬£¬£¬Ö¼ÔÚ·Ö·¢Remcos RAT ¡£¡£¡£¡£¡£¡£¡£ÔÚQbot±»µ·»Ùºó£¬ £¬ £¬£¬£¬Æä³Ö¾ÃÕ¼¾Ý°ñÊ׵ľÖÃæÒѾ­ÊµÏÖ£¬ £¬ £¬£¬£¬9Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ±äΪFormbook£¬ £¬ £¬£¬£¬Æä´ÎÊÇRemcosºÍEmotet ¡£¡£¡£¡£¡£¡£¡£Ôâµ½¹¥»÷×îÑϳÁµÄÊǽÌÓýºÍ×êÑÐÐÐÒµ£¬ £¬ £¬£¬£¬Æä´ÎÊÇͨѶÒÔ¼°¾üÕþÁìÓò ¡£¡£¡£¡£¡£¡£¡£×î³£±»ÀûÓõķì϶ÊÇWeb·þÎñÆ÷¶ñÒâURLĿ¼±éÀú·ì϶£¬ £¬ £¬£¬£¬×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÒÀÈ»ÊÇAnubis ¡£¡£¡£¡£¡£¡£¡£


https://blog.checkpoint.com/security/september-2023s-most-wanted-malware-remcos-wreaks-havoc-in-colombia-and-formbook-takes-top-spot-after-qbot-shutdown/