2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ£»£»£»£»£»vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2019-10-09
1.Ponemon InstituteÐû²¼¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤ÖܶþPonemon InstituteÐû²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬ £¬£¬£¬È«Çò66%µÄÖÐСÐÍÆóÒµ£¨SMB£©ÔÚÒÑÍù12¸öÔÂÄÚ±¨¸æÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£¡£¡£¡£¡£¡£PonemonÌåÏÖÕâÊÇÒ»Á¬µÚÈýÄêSMB±¨¸æµÄÍøÂçÇå¾²ÊÂÎñ·ºÆð¡°ÏÔÖøÔöÌí¡±¡£¡£¡£¡£¡£¡£Ä¿½ñSMBÃæÁÙµÄ×î³£¼ûÍøÂç¹¥»÷ÐÎʽÊÇÍøÂç´¹ÂÚ¡¢×°±¸ÈëÇÖ»ò±»µÁ¡¢Æ¾Ö¤ÇÔÈ¡¡£¡£¡£¡£¡£¡£Ëæ×Å×Ô´ø×°±¸°ì¹«£¨BYOD£©Ä£Ê½µÄÊ¢ÐУ¬£¬£¬ £¬£¬£¬×°±¸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£¡£¡£¡£¡£¡£ÔÚÒÑÍù12¸öÔÂÖУ¬£¬£¬ £¬£¬£¬¹²ÓÐ63%µÄÆóÒµ±¨¸æÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅϢɥʧÊÂÎñ£¬£¬£¬ £¬£¬£¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬£¬£¬ £¬£¬£¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬½ü100Íò»¼ÕßÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



T¨±Ora Compass HealthÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ £¬£¬£¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¸Ã³õ¼¶ÎÀÉú×éÖ¯£¨PHO£©ÌåÏÖÆä¹ÙÍøÔÚ8Ô·ݱ¬·¢µÄÒ»ÆðÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬£¬£¬ £¬£¬£¬Òò´Ë¶ÔCompass HealthµÄÕûÌåITϵͳºÍÇ徲״̬¾ÙÐÐÁËÊӲ죬£¬£¬ £¬£¬£¬×îÖÕ·¢Ã÷´Ó2016Äêµ½2019Äê3Ô±¬·¢µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£Compass HealthÌåÏÖÈκÎÔÚ2016ÄêÖÁ2019Äêʱ´úÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬£¬£¬ £¬£¬£¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄµØÇøÖ÷ҪΪÐÂÎ÷À¼»ÝÁé¶Ù£¬£¬£¬ £¬£¬£¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨Óû§µÄ¹ú¼ÒÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØµãÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐľÙÐÐ×¢²á¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬¿Í»§ÐÅÓÃÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÄôóTransUnion´ÓÉÏÖÜ×îÏÈÏòÓû§·¢ËÍÊý¾ÝÇå¾²ÊÂÎñ֪ͨ£¬£¬£¬ £¬£¬£¬ÌåÏÖÓû§µÄÐÅÏ¢Ô⵽δÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¸Ãָ֪ͨ³ö£¬£¬£¬ £¬£¬£¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕʱ´úδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Æ¾Ö¤»á¼ûÆäÃÅ»§ÍøÕ¾£¬£¬£¬ £¬£¬£¬²¢¾ÙÐÐÁËÐÅÓñ¨¸æ²éÕÒ¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿ÉÄܲéÕÒµ½µÄÐÅÓÃÎļþÖаüÀ¨Óû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñ¼°ÒÑÍùµÄµØµãÒÔ¼°Õ÷ÐÅÏà¹ØÐÅÏ¢£¬£¬£¬ £¬£¬£¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶ÀúÊ·µÈ£¬£¬£¬ £¬£¬£¬µ«²»°üÀ¨ÏÖʵµÄÕË»§ºÅÂë¡£¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢À´ÊµÑéÉí·Ý͵ÇÔ£¬£¬£¬ £¬£¬£¬Òò´ËTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓÃڲƭ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾöÒéÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬£¬£¬ £¬£¬£¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢»Ö¸´ÆäϵͳµÄÕý³£ÔËÓª¡£¡£¡£¡£¡£¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨°üÀ¨DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬ £¬£¬£¬ÆÈʹËûÃǹرÕÁËÅÌËã»úϵͳ²¢×èÖ¹ÎüÊÕÐµĻ¼Õß¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©DCHÐû²¼¸üÐÂÉùÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÕýÔÚ»Ö¸´Æäϵͳ£¬£¬£¬ £¬£¬£¬DCH²¢Î´Í¸Â¶Êê½ðµÄÏêϸÊý¶î£¬£¬£¬ £¬£¬£¬µ«ÒÑÈ·È϶à¸öЧÀÍÆ÷±»ÀֳɽâÃÜ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúDCHµÄϵͳ½«ÓÚºÎʱÍêÈ«ÉÏÏß¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚÉϸöÔÂÄ©ÐÞ¸´RCE 0dayºó£¬£¬£¬ £¬£¬£¬vBulletinÐû²¼ÁËÒ»¸öеÄÇå¾²²¹¶¡£¬£¬£¬ £¬£¬£¬ÐÞ¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²îÊÇRCEÎó²î£¨CVE-2019-17132£©£¬£¬£¬ £¬£¬£¬±£´æÓÚvBulletin´¦Öóͷ£Óû§¸üÐÂÆäСÎÒ˽¼Ò×ÊÁϵÄÇëÇóÀú³ÌÖУ¬£¬£¬ £¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃδ¾­ÓÉÂ˵IJÎÊýÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×¢Èë²¢Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÊÇSQL×¢ÈëÎÊÌ⣬£¬£¬ £¬£¬£¬ËüÃDZ»·ÖÅÉΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬£¬£¬ £¬£¬£¬¿ÉÔÊÐí¾ßÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÓ°ÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´59¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚÖܶþÐû²¼µÄWindows 10ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË59¸öÎó²î£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨Çå¾²³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1238ºÍCVE-2019-1239£¬£¬£¬ £¬£¬£¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCEÎó²î£¨CVE-2019-1333£¬£¬£¬ £¬£¬£¬ÔÊÐí¶ñÒâЧÀÍÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÅþÁ¬Ê±ÔÚ¿Í»§¶ËÉÏÖ´ÐÐÏÂÁµÈ¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/