AvaddonÍÅ»ïÉù³ÆÒÑ´Ó·¨¹ú±£ÏÕ¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý£»Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃURL·½°¸À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§
Ðû²¼Ê±¼ä 2021-05-181.AvaddonÍÅ»ïÉù³ÆÒÑ´Ó·¨¹ú±£ÏÕ¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý
·¨¹ú±£ÏÕ¹«Ë¾°²Ê¢¼¯ÍÅ£¨AXA Group£©ÉÏÖÜÈÕÐû²¼£¬ÆäÔâµ½AvaddonÀÕË÷Èí¼þµÄ¹¥»÷£¬Ó°ÏìÁËÑÇÖÞÒµÎñ²¿ÃŵÄITÔËÓª¡£AvaddonÍŶÓÔòÔÚÆäÐ¹Â¶ÍøÕ¾ÉÏÉù³Æ£¬ËûÃÇÒѾ´ÓAXA¹«Ë¾ÇÔÈ¡ÁË3TBµÄÃô¸ÐÊý¾Ý£¬°üÂÞ¿Í»§Ò½ÁƳÂËß¡¢Éí·ÝÖ¤¸´Ó¡¼þ¡¢ÒøÐжÔÕʵ¥¡¢Ë÷Åâ±í¡¢¸¶¿î¼Ç¼ºÍºÏͬµÈ£¬²¢¶ÔAXAÔÚÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ïã¸ÛºÍ·ÆÂɱöµÄÍøÕ¾ÌᳫÁËÓÐЧµÄDDoS¹¥»÷¡£AXAÌåÏÖ´Ë´Îʼþ½öй¶ÁËÌ©¹ú¹ú¼ÊºÏ×÷»ï°éÐÖú£¨IPA£©µÄ²¿ÃÅÊý¾Ý£¬ÆäËü·Ö¹«Ë¾Î´ÊÜÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/avaddon-ransomware-french-insurance-axa-data-stolen/
2.°ÍÎ÷¹«Ë¾Rede BahiaÔâµ½ÀÕË÷¹¥»÷£¬ÔËÓªÔÝʱÖжÏ
°ÍÎ÷ÉÌÒµ¼¯ÍÅRede BahiaÔâµ½ÀÕË÷¹¥»÷£¬ÔËÓªÔÝʱÖжϡ£2021Äê5ÔÂ13ÈÕ£¬¸Ã¹«Ë¾Í¨¹ýÓʼþ֪ͨԱ¹¤£¬Òò¹¥»÷ʼþÆä¸öÈËÐÅÏ¢£¨ÀýÈçн×ÊÃ÷ϸµÈ£©¿ÉÄÜÒѾй¶¡£´ËÍ⣬´Ë´Î¹¥»÷»¹×ÌÈÅÁËRede BahiaÆìϵı¨Ö½CorreioÿÈÕµÄÕý³£³öÊ顣Ŀǰ£¬¸Ã¹«Ë¾ÈÔÔÚŬÁ¦»Ö¸´ËùÓй¦Ð§£¬ÉÐδ¹ûÈ»ÓйØÀÕË÷Èí¼þµÄÀàÐÍ»òÀÕË÷ÐèÇóµÄÏêϸÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/br-rede-bahia-suffers-a-cyberattack-and-reported-databreach/
3.±£ÏÕ¹«Ë¾Guard.meÔâµ½¹¥»÷£¬¿Í»§¸öÈËÐÅϢй¶
Guard.meÔâµ½¹¥»÷£¬¿Í»§¸öÈËÐÅϢй¶¡£guard.meÊÇÈ«Çò×î´óµÄ±£ÏÕ¹«Ë¾Ö®Ò»£¬×¨ÃÅΪ³ö¹úÂÃÐлò³ö¹úÁôѧµÄѧÉúÌṩ½¡¿µ±£ÏÕ¡£5ÔÂ12ÈÕ£¬Guard.meÔÚÆäÍøÕ¾ÉÏ·¢ÏÖÁËÒì³£»î¶¯£¬×÷ΪԤ·À´ëÊ©£¬ÆäÁ¢¼´¹Ø±ÕÁ˸ÃÍøÕ¾²¢¶ÔÆä½øÐÐά»¤¡£Ö±µ½5ÔÂ17ÈÕ£¬¸Ã¹«Ë¾Í¨ÖªÆä¿Í»§ÓÐδ¾ÊÚȨµÄ¹¥»÷ÕßÀûÓÃÆäÍøÕ¾ÖеÄ©¶´·ÃÎÊÁËѧÉúµÄÐÅÏ¢£¬°üÂÞÉúÈÕ¡¢ÐÔ±ð¡¢ÃÜÂëÓʼþµØÖ·¡¢ÓʼĵØÖ·ºÍµç»°ºÅÂëµÈ¡£guard.me³ÆÂ©¶´ÏÖÒÑÐÞ¸´£¬²¢ÆôÓÃÁËеĸü¸ß¼¶´ËÍâÄþ¾²¼ÆÄ±¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/student-health-insurance-carrier-guardme-suffers-a-data-breach/
4.Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃURL·½°¸À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§
Ñо¿ÈËÔ±¿ª·¢ÁËÒ»ÖÖÒªÁ죬ͨ¹ý²éѯÉ豸Éϰ²×°µÄÓ¦Ó÷¨Ê½£¬¿ÉÒÔ×·×Ù²îÒìä¯ÀÀÆ÷µÄÓû§¡£ÒòΪijЩӦÓ÷¨Ê½ÔÚ°²×°ºó»á´´½¨×Ô½ç˵URL·½°¸£¬ä¯ÀÀÆ÷¿ÉʹÓøÃURL·½°¸ÔÚÌØ¶¨Ó¦Ó÷¨Ê½Öдò¿ªURL¡£ FingerprintJSÑо¿ÈËÔ±ÑÝʾÁËÈçºÎÀûÓÃ×Ô½ç˵ÐÒé´¦Ö÷¨Ê½Öеĺ鷺©¶´£¬ÔÚ²îÒìµÄä¯ÀÀÆ÷£¬°üÂÞChrome¡¢Firefox¡¢Microsoft Edge¡¢Safari£¬ÉõÖÁÊÇTorÖ®¼ä¸ú×ÙÓû§µÄ¡£Ä¿Ç°£¬Ö»Óйȸèä¯ÀÀÆ÷֮ǰ½ÓÄÉÁË»º½â´ëÊ©£¬À´·ÀÖ¹´ËÀ๥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cross-browser-tracking-vulnerability-tracks-you-via-installed-apps/
5.HiscoxÐû²¼2021ÄêµÄCyber Readiness·ÖÎö³ÂËß
¹ú¼Ê±£ÏÕ¹«Ë¾HiscoxÐû²¼2021ÄêµÄCyber Readiness·ÖÎö³ÂËß¡£³ÂËßÊÓ²ìÁËÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢±ÈÀûʱ¡¢·¨¹ú¡¢µÂ¹ú¡¢ºÉÀ¼¡¢Î÷°àÑÀºÍ°®¶ûÀ¼µÄ6000¶à¸öÍøÂçÄþ¾²ÂôÁ¦ÈËÔ±¡£ ³ÂËßÏÔʾ£¬ÔÚ¹ýÈ¥Ò»ÄêÖУ¬ÓÐÃÀ¹ú23£¥µÄСÐÍÆóÒµÔâÊÜÁËÖÁÉÙÒ»´ÎÍøÂç¹¥»÷¡£63£¥µÄСÐÍÆóÒµÔÚÔ¶³ÌÊÂÇ飬53£¥ÈÏΪ×Ô¼ºÈÝÒ×Êܵ½ÍøÂç¹¥»÷¡£39£¥µÄÆóÒµÌåÏÖ£¬ËûÃÇÔ¤¼ÆÔö¼ÓÆäÄþ¾²Ö§³ö£¬49£¥µÄÆóҵ˵ӵÓÐÍøÂç±£ÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.hiscox.com/sites/default/files/content/documents/Hiscox-Cyber-Readiness-Report-2021.pdf
6.CISAÐû²¼ÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÓ¦¶ÔÖ¸ÄÏ
CISAÐû²¼ÁËÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÍøÂçµÄÓ¦¶ÔÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÖ¸³ö£¬Ó¦¶Ô´ëÊ©Ö÷Òª·ÖΪÈý²½£º Pre-Eviction½×¶Î£¬¼ì²âºÍʶ±ðAPT»î¶¯²¢ÎªÏÂÒ»½×¶Î×öºÃ×¼±¸£»Eviction½×¶Î£¬´Óµ±µØºÍÔÆ»·¾³ÖÐɾ³ýAPT¼ÓÈëÕߵIJÙ×÷£¬°üÂÞÖØ½¨É豸ºÍϵͳ£»Post-Eviction½×¶Î£¬È·±£ÇýÖðÀֳɶøÇÒÍøÂç¾ßÓÐÁ¼ºÃµÄ״̬¡£´ËÍ⣬CISAÌáÐѱ¾Ö¸ÄÏÖÐÌṩµÄ²½ÖèºÄ·Ñ×ÊÔ´Çҷdz£ÅÓ´ó£¬ÐèÒªÆóÒµ½«ÍøÂç´ÓInternet¶Ï¿ª3µ½5Ìì¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/analysis-reports/ar21-134a