BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø
°ä²¼¹¦·ò 2023-10-081¡¢BlackbaudÔÞ³ÉÒÔ4950ÍòÃÀÔª½â¾öÊý¾Ýй¶ÊÂÎñµÄÖ¸¿Ø
¾Ý10ÔÂ6ÈÕ±¨Â·£¬£¬£¬£¬£¬ÔÆÍÆËãÌṩÉÌBlackbaudÓëÃÀ¹ú49¸öÖÝ´ï³ÉÁË4950ÍòÃÀÔªµÄºÍ̸£¬£¬£¬£¬£¬ÒԺͽâÕë¶Ô2020Äê5ÔµÄÀÕË÷¹¥»÷¼°ÓÉ´ËÒý·¢µÄÊý¾Ýй¶µÄÖ¸¿Ø¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËÊý°ÙÍòÓû§£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁËÓû§Î´¼ÓÃܵÄÒøÐÐÐÅÏ¢¡¢µÇ¼ƾ֤ºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£¡£¡£BlackbaudÔÚ±»·î¸æËùÓб»µÁÊý¾ÝÒѱ»Ïú»Ùºó£¬£¬£¬£¬£¬½»ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£Õâ´Î´ï³ÉµÄ4950ÍòÃÀÔªºÍ½âºÍ̸½â¾öÁËBlackbaudÎ¥·´ÖÝÏû·ÑÕß±£»£»£»£»£»¤·¨¡¢Î¥·´Í¨ÖªÂÉÀýÒÔ¼°½¡È«±£ÏÕÁ÷ͨÓëÔðÈη¨°¸(HIPAA)µÄÖ¸¿Ø¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/blackbaud-agrees-to-495-million-settlement-for-ransomware-data-breach/
2¡¢¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»áÔâµ½¹¥»÷²¿ÃÅÑ¡ÃñÐÅϢй¶
¾ÝýÌå10ÔÂ6ÈÕ±¨Â·£¬£¬£¬£¬£¬¸çÂ×±ÈÑÇÌØÇøÑ¡¾ÙίԱ»á(DCBOE)ĿǰÔÚµ÷²é²¿ÃÅÑ¡ÃñÐÅϢй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÑ¡¾Ù»ú¹¹µÄÍйÜÌṩÉÌDataNetµÄ·þÎñÆ÷½Ó¼ûÁËÕâЩÐÅÏ¢£¬£¬£¬£¬£¬µ«DCBOEµÄÄÚ²¿Êý¾Ý¿âºÍ·þÎñÆ÷²¢Î´Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬DCBOEµÄÍøÕ¾Òѹعز¢ÏÔÊ¾ÊØ»¤Ò³Ãæ¡£¡£¡£¡£¡£¡£¡£RansomedVCÐû³ÆÈëÇÖÁËDCBOE²¢»ñµÃÁ˳¬¹ý60ÍòÌõÃÀ¹úÑ¡ÃñµÄÐÅÏ¢£¬£¬£¬£¬£¬ËüÔÚ°µÍøÉÏÏúÊÛ±»µÁÐÅÏ¢£¬£¬£¬£¬£¬»¹¹«¿ªÁËÒ»±Ê¼Í¼ÒÔÖ¤Ã÷Êý¾ÝµÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£µ«ÊǾݱ¨Â·£¬£¬£¬£¬£¬DCBOE±»µÁÊý¾Ý¿â×îÏÈÊÇÓÉÃûΪpwncoderµÄÓû§ÔÚºÚ¿ÍÂÛ̳ÖÐÏúÊ۵쬣¬£¬£¬£¬ÕâЩÌû×Ó´Ë¿ÌÒѱ»É¾³ý¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/
3¡¢Î¢ÈíÏêÊö¹¥»÷Õßͨ¹ýSQL ServerºáÏòÒÆ¶¯µ½ÔƵķ½Ê½
΢ÈíÔÚ10ÔÂ3ÈÕ³ÆÆä×î½ü·¢ÏÖÁËÒ»´Î¹¥»÷»î¶¯£¬£¬£¬£¬£¬ÆäÖй¥»÷ÕßÊÔͼͨ¹ýSQL ServerÊ·ýºáÏòÒÆ¶¯µ½ÔÆ»·¾³¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷·½Ê½ÔÚÆäËüÔÆ·þÎñ£¨ÀýÈçVMºÍKubernetes£©ÖÐÓз¢ÏÖ¹ý£¬£¬£¬£¬£¬µ«ÔÚSQL ServerÖÐȴûÓС£¡£¡£¡£¡£¡£¡£¹¥»÷Õß×î³õÀûÓÃÖ¸±êϵͳµÄÀûÓ÷¨Ê½ÖеÄSQL×¢Èë·ì϶£¬£¬£¬£¬£¬À´½Ó¼û²¿ÊðÔÚAzure Ðé¹¹»ú£¨VM£©ÖеÄMicrosoft SQL ServerÊ·ý²¢ÌáÉýÆäȨÏÞ¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓûñµÃµÄ¸ß¼¶È¨ÏÞ£¬£¬£¬£¬£¬ÊÔͼͨ¹ýÀÄÓ÷þÎñÆ÷µÄÔÆÉí·ÝºáÏòÒÆ¶¯µ½ÆäËüÔÆ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/en-us/security/blog/2023/10/03/defending-new-vectors-threat-actors-attempt-sql-server-to-cloud-lateral-movement/
4¡¢Really Simple SystemsÅäÖÃÃýÎóй¶300Íò¿Í»§¼Í¼
ýÌå10ÔÂ5Èճƣ¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËB2B CRM ÌṩÉÌReally Simple SystemsÔ̺¬300¶àÍò±Ê¼Í¼µÄÎÞÃÜÂë±£»£»£»£»£»¤Êý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Õ¼Óг¬¹ý18000¸ö¿Í»§£¬£¬£¬£¬£¬Ô̺¬»Ê¼ÒѧԺ¡¢ºìÊ®×ֻᡢNHSºÍIBMµÈ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¾ÝÒ½ÁƼͼ¡¢ÐÅÓþ»ã±¨¡¢Éí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍ˾·¨ÎļþµÈ£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÁËλÓÚÓ¢¹ú¡¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇµÄÆóÒµ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬²»°²È«µÄÊý¾Ý¿âÒѱ»±£»£»£»£»£»¤ÆðÀ´£¬£¬£¬£¬£¬Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿â¶³öµÄ¹¦·ò£¬£¬£¬£¬£¬ÒÔ¼°ÊÇ·ñÓÐÈ˽Ӽû¹ýËü¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/crm-provider-really-simple-systems-data-leak/
5¡¢Checkmarx·¢ÏÖÊý°Ù¸öÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ¶ñÒâPython°ü
10ÔÂ3ÈÕ£¬£¬£¬£¬£¬Checkmarx³ÆÒ»³¡¶ñÒâ»î¶¯ÒÑÔÚ¿ªÔ´Æ½Ì¨ÉÏÖ²ÈëÁËÊý°Ù¸öÐÅÏ¢ÇÔÈ¡°ü£¬£¬£¬£¬£¬ÏÂÔØÁ¿Ô¼Îª75000´Î¡£¡£¡£¡£¡£¡£¡£×Ô4Ô³õÒÔÀ´£¬£¬£¬£¬£¬ÔÚPythonÉú̬ϵͳÖУ¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¸÷ÀàÓû§Ãû²¿ÊðÁËÊý°Ù¸ö¶ñÒâÈí¼þ°ü¡£¡£¡£¡£¡£¡£¡£×Ô³õ´Î·¢ÏÖÒÔÀ´£¬£¬£¬£¬£¬¹¥»÷±äµÃÔ½À´Ô½¸´ÔÓ£¬£¬£¬£¬£¬´ÓÃ÷ÎĹý¶Éµ½¼ÓÃÜ£¬£¬£¬£¬£¬ËæºóÓÖ¹ý¶Éµ½¶à²ã»ìºÏºÍ¶þ´Î·´»ã±àpayload¡£¡£¡£¡£¡£¡£¡£¶ñÒâ°üÖ¼ÔÚÇÔÈ¡´óÁ¿Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬Ö¸±êϵͳ¡¢ÀûÓ÷¨Ê½¡¢ä¯ÀÀÆ÷ºÍÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ËüÃÇ»¹Í¨¹ýÅú¸Ä¼ÓÃÜÇ®±ÒµØÖ·½«ÂòÂô³Á¶¨Ïòµ½¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£
https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/
6¡¢Check Point°ä²¼9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨
10ÔÂ6ÈÕ£¬£¬£¬£¬£¬Check Point°ä²¼ÁË9Ô·ݵÄÈ«ÇòÍþвָÊý·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£9Ô·ݣ¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ô¸çÂ×±ÈÑǶà¸öÐÐÒµµÄ40¶à¼Ò¹«Ë¾µÄ´ó¹æÄ£´¹µö»î¶¯£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢Remcos RAT¡£¡£¡£¡£¡£¡£¡£ÔÚQbot±»µ·»Ùºó£¬£¬£¬£¬£¬Æä³Ö¾ÃÕ¼¾Ý°ñÊ׵ľÖÃæÒѾʵÏÖ£¬£¬£¬£¬£¬9Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ±äΪFormbook£¬£¬£¬£¬£¬Æä´ÎÊÇRemcosºÍEmotet¡£¡£¡£¡£¡£¡£¡£Ôâµ½¹¥»÷×îÑϳÁµÄÊǽÌÓýºÍ×êÑÐÐÐÒµ£¬£¬£¬£¬£¬Æä´ÎÊÇͨѶÒÔ¼°¾üÕþÁìÓò¡£¡£¡£¡£¡£¡£¡£×î³£±»ÀûÓõķì϶ÊÇWeb·þÎñÆ÷¶ñÒâURLĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÒÀÈ»ÊÇAnubis¡£¡£¡£¡£¡£¡£¡£
https://blog.checkpoint.com/security/september-2023s-most-wanted-malware-remcos-wreaks-havoc-in-colombia-and-formbook-takes-top-spot-after-qbot-shutdown/


¾©¹«Íø°²±¸11010802024551ºÅ