ÃÀ¹úÐÁÆÕÉ­ÖÆÔ칫˾Ôâµ½ÍøÂç¹¥»÷µ¼ÖÂÔËÓªÊܵ½Ó°Ïì

Ðû²¼Ê±¼ä 2023-10-13

1¡¢ÃÀ¹úÐÁÆÕÉ­ÖÆÔ칫˾Ôâµ½ÍøÂç¹¥»÷µ¼ÖÂÔËÓªÊܵ½Ó°Ïì


¾Ý10ÔÂ12ÈÕ±¨µÀ£¬ÐÁÆÕÉ­ÖÆÔ칫˾£¨Simpson Manufacturing£©Ôâµ½¹¥»÷£¬µ¼ÖÂÔËÓªÊܵ½Ó°Ïì ¡£ÕâÊÇÃÀ¹úµÄÒ»¼Ò½¨ÖþºÍ½á¹¹ÖÊÁÏÉú²úÉÌ£¬2022Äê¾»ÏúÊÛ¶îΪ21.2ÒÚÃÀÔª ¡£¸Ã¹«Ë¾ÌåÏÖ£¬10ÔÂ10ÈÕ£¬ËûÃǵÄIT»ù´¡ÉèÊ©ºÍÓ¦Ó÷¨Ê½ÒòÍøÂçÄþ¾²Ê¼þÖжÏ ¡£·¢ÏÖ¶ñÒâ»î¶¯ºó£¬ÖÆÔìÉ̹رÕÁ˲¿ÃÅϵͳÒÔÍ£Ö¹½øÒ»²½µÄ¹¥»÷ ¡£ÓÉÓÚµ÷Í£ÐèҪʱ¼ä£¬Òò´ËÔËÓªµÄÔÝÍ£»¹½«Á¬ÐøÒ»¶Îʱ¼ä ¡£¾¡¹ÜÐÁÆÕɭû͸¶¹¥»÷ÀàÐÍ£¬µ«¹Ø±Õϵͳͨ³£ÊǶÔÀÕË÷¹¥»÷µÄÏìÓ¦ ¡£


https://www.securityweek.com/simpson-manufacturing-takes-systems-offline-following-cyberattack/


2¡¢ÔÆÌṩÉÌShadow PCÁè¼Ý50Íò¿Í»§µÄÐÅÏ¢±»³öÊÛÔÚ°µÍø


¾ÝýÌå10ÔÂ12ÈÕ±¨µÀ£¬ºÚ¿ÍÉù³Æ³öÊ۸߶ËÔƼÆËã·þÎñÌṩÉÌShadow PCÁè¼Ý500000Ãû¿Í»§µÄÊý¾Ý ¡£Shadow͸¶£¬ËûÃǵÄÒ»ÃûÔ±¹¤ÔÚ9Ôµ×Ôâµ½ÁËÉ繤¹¥»÷ ¡£¹¥»÷ʼÓÚDiscordƽ̨£¬ÒÔSteamƽ̨ÉϵÄÒ»¿îÓÎϷΪ»Ï×ÓÏÂÔØÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ ¡£¸Ã¶ñÒâÈí¼þÀÖ³ÉÇÔÈ¡ÁËÉí·ÝÑéÖ¤cookie£¬Ê¹ºÚ¿ÍÄܹ»µÇ¼¸Ã¹«Ë¾µÄSaaSÌṩÉ̵ĹÜÀí½çÃ棬²¢ÀûÓô˷ÃÎÊȨÏÞÇÔÈ¡¿Í»§ÐÅÏ¢ ¡£Ä³ºÚ¿Í³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢³öÊÛ533624ÃûÓû§µÄÊý¾Ý£¬ÌåÏÖ³ýÁËShadowÒѾ­È·ÈϵÄÊý¾ÝÍ⣬ËûÃÇ»¹»ñµÃÁËIPÁ¬½ÓÈÕÖ¾ ¡£


https://www.bleepingcomputer.com/news/security/shadow-pc-warns-of-data-breach-as-hacker-tries-to-sell-gamers-info/


3¡¢BianLianÉù³ÆÒÑÇÔÈ¡¼ÓÄô󺽿չ«Ë¾Ô¼210GBµÄÊý¾Ý


ýÌå10ÔÂ11Èճƣ¬BianLian¶Ô¼ÓÄô󺽿չ«Ë¾Ôâµ½µÄ¹¥»÷ÂôÁ¦£¬²¢ÌåÏÖÒÑÊÕ¼¯Ô¼210GBµÄÊý¾Ý ¡£¸Ã¹«Ë¾ÔÚ9ÔµÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬Ö»Óв¿ÃÅÔ±¹¤ÓÐÏ޵ĸöÈËÐÅϢй¶ ¡£µ«BianLianÉù³ÆÇÔÈ¡ÁË´Ó2008Äêµ½2023ÄêµÄ¼¼ÊõºÍÔËÓªÊý¾Ý£¬°üÂÞ¹«Ë¾¼¼ÊõºÍÄþ¾²µÄÏêϸÐÅÏ¢¡¢SQL±¸·Ý¡¢Ô±¹¤¸öÈËÐÅÏ¢¡¢¹©Ó¦É̺͹©Ó¦É̵ÄÊý¾Ý¡¢»úÃÜÎļþÒÔ¼°¹«Ë¾Êý¾Ý¿âµÄµµ°¸£¬²¢ÌṩÁ˽Øͼ×÷Ϊ֤¾Ý ¡£¼ÓÄô󺽿ÕÌåÏÖ£¬ËûÃÇÖªµÀBianLianµÄÍþв£¬µ«Ã»ÓÐ֤ʵ¸ÃÍÅ»ï¾ÍÊÇ´Ë´ÎʼþµÄÄ»ºóºÚÊÖ ¡£


https://www.bleepingcomputer.com/news/security/bianlian-extortion-group-claims-recent-air-canada-breach/


4¡¢Cofense³ÆÀûÓÃLinkedInÖÇÄÜÁ´½ÓµÄµöÓã»î¶¯¼¤Ôö


CofenseÔÚ10ÔÂ11Èճƣ¬Æä·¢ÏÖÀÄÓÃLinkedInÖÇÄÜÁ´½ÓÀ´Èƹý¼ì²âµÄµöÓã¹¥»÷¼¤Ôö£¬Ö¼ÔÚÇÔÈ¡MicrosoftÕÊ»§Æ¾¾Ý ¡£ÐÂÒ»ÂÖ¹¥»÷·¢ÉúÔÚ7ÔÂÖÁ8ÔÂÆڼ䣬°üÂÞ800¶à·âÓʼþºÍ80¸öÆæÌصÄÖÇÄÜÁ´½Ó£¬Ô´×Ôд´½¨»ò±»ÈëÇÖµÄLinkedInÆóÒµÕÊ»§ ¡£Êý¾ÝÏÔʾ£¬´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔµÄÊǽðÈÚ¡¢ÖÆÔì¡¢ÄÜÔ´¡¢½¨ÖþºÍÒ½ÁƱ£½¡ÁìÓò ¡£ÖÇÄÜÁ´½ÓÊÇLinkedIn Sales Navigator·þÎñµÄÒ»²¿ÃÅ£¬ÓÃÓÚÓªÏúºÍ¸ú×Ù£¬CofenseÔçÔÚ2021Äê¾Í·¢ÏÖ¹ýÀûÓÃLinkedInÖÇÄÜÁ´½ÓµÄ´ó¹æÄ£µöÓã¹¥»÷ ¡£


https://cofense2022stg.wpengine.com/blog/linkedin-smart-links-credential-phishing-campaign/


5¡¢ProofpointÐû²¼2023ÄêÒ½ÁÆÐÐÒµµÄÄþ¾²·ÖÎö³ÂËß


10ÔÂ11ÈÕ£¬ProofpointÓëPonemonºÏ×÷£¬Ðû²¼ÁË2023ÄêÒ½ÁÆÐÐÒµµÄÄþ¾²·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö£¬88%µÄÊÜ·ÃʵÌåÔÚ¹ýÈ¥12¸öÔÂÄÚƽ¾ù¾­ÀúÁË40´Î¹¥»÷£¬Ò½ÁÆ»ú¹¹Ôâµ½¹¥»÷µÄƽ¾ù×ܳɱ¾Îª499ÍòÃÀÔª£¬±ÈÉÏÄêÔö³¤13% ¡£ÀÕË÷Èí¼þÈÔÈ»ÊÇÒ½ÁÆ»ú¹¹Ê¼ÖÕ´æÔÚµÄÍþв£¬54%µÄÊÜ·ÃÕß³ÆÔâµ½ÁËÀÕË÷¹¥»÷£¬¸ßÓÚ2022ÄêµÄ41% ¡£ËùÓÐÊܷûú¹¹ÔÚ¹ýÈ¥Á½ÄêÄÚÖÁÉÙ·¢Éú¹ýÒ»´ÎÉæ¼°Ãô¸ÐºÍ»úÃÜÒ½ÁÆÊý¾ÝµÄ¶ªÊ§»òй¶Ê¼þ ¡£BEC¹¥»÷¸üÊܹØ×¢£¬µ£ÓÇ´ËÀ๥»÷µÄÈË´ÓÈ¥ÄêµÄ46%Ô¾ÉýÖÁ62% ¡£


https://www.proofpoint.com/us/newsroom/press-releases/second-annual-ponemon-institute-report-finds-two-thirds-healthcare


6¡¢Critical StartÐû²¼2023Ï°ëÄêÍþв̬ÊÆ·ÖÎö³ÂËß


10ÔÂ11ÈÕ±¨µÀ³Æ£¬Critical StartÐû²¼ÁË2023Ï°ëÄêÍþв̬ÊƵķÖÎö³ÂËß ¡£³ÂËßµÄÖ÷Òª·¢ÏÖ°üÂÞ£ºÀûÓÃQRÂëµÄµöÓã¹¥»÷³ÊÉÏÉýÇ÷ÊÆ£¬¹¥»÷Õß½«QRÂëǶÈëPNG»òPDFÖУ¬Î±×°³ÉMicrosoft Äþ¾²Í¨Öª£»½ÌÓýÊÇ×îÒ×Ôâµ½¹¥»÷µÄÐÐÒµÖ®Ò»£¬2023Äꩶ´ÀûÓÃÕ¼K-12ѧУÍøÂçʼþµÄ29%£¬¶øµöÓã¹¥»÷Õ¼30%£»ÀÕË÷Èí¼þÍÅÌåµÄºÏ×÷±È֮ǰÏëÏóµÄ¸ü¹ã·º£¬¸üÏêϸµØ·ÖÏíTTP£»Microsoft TeamsÔÊÐíÍⲿÕÊ»§Ö±½ÓÏòÔ±¹¤·¢ËÍÓк¦Îļþ£¬´Ó¶øÈƹýÄþ¾²¼ì²â£¬ÕâÔö¼ÓÁ˹¥»÷ÀֳɵķçÏÕ ¡£


https://www.criticalstart.com/resources/h2-2023-cyber-threat-intelligence-threat-report/