Ò˼ҷ¨¹ú¹«Ë¾ÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª£»£»£»ÃÀ¹úCVS HealthÊý¾Ý¿âÉèÖùýʧй¶Áè¼Ý10ÒÚÌõ¼Í¼

Ðû²¼Ê±¼ä 2021-06-17

1.Ò˼ҷ¨¹ú¹«Ë¾ÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª


1.jpg


Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓÃÌØ¹¤Èí¼þ²»·¨¼à¿ØÔ±¹¤±»·£¿£¿£¿£¿î120ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2009ÄêÖÁ2012Äê¼ä£¬ £¬£¬£¬£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸öÌØ¹¤ÏµÍ³À´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¡£¡£¡£¡£¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÈÏÕæÈËJean-Louis Baillot½¨ÉèµÄ£¬ £¬£¬£¬£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£Éó²é¹ÙÌåÏÖ£¬ £¬£¬£¬£¬Ò˼ҷ¨¹ú¹«Ë¾Ê¹Óþ¯·½ÐÂÎÅȪԴ£¬ £¬£¬£¬£¬Ô¼ÇëÁËÒ»¼Ò˽È˱£°²¹«Ë¾ºÍ˽ÈËÕì̽²»·¨»ñÈ¡ÆäÔ±¹¤µÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÐÌÊÂÊÓ²ìÓÚ2012ÄêÆô¶¯£¬ £¬£¬£¬£¬Ö±µ½±¾Öܶþ²ÅÏÂÁî·£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/


2.ÃÀ¹úCVS HealthÊý¾Ý¿âÉèÖùýʧй¶Áè¼Ý10ÒÚÌõ¼Í¼


2.jpg


Ñо¿ÍŶÓÓÚ2021Äê3ÔÂ21ÈÕ·¢Ã÷ÁËÒ»¸ö²»ÊÜÃÜÂë±£»£»£»¤µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¾­ÓɽøÒ»²½Ñо¿£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÓëÃÀ¹úÒ½ÁƱ£½¡¹«Ë¾CVS HealthÓйء£¡£¡£¡£¡£¡£Êý¾Ý¿â¾ÞϸΪ204GB£¬ £¬£¬£¬£¬×ܼÆÓÐ1148327940Ìõ¼Í¼£¬ £¬£¬£¬£¬°üÀ¨·Ã¿ÍID¡¢»á»°ID¡¢×°±¸ÐÅÏ¢ºÍÈÕ־ϵͳÔõÑù´Óºó¶ËÔËÐеÄÀ¶Í¼µÈÄÚÈÝ£¬ £¬£¬£¬£¬ÒÔ¼°ÓйØÒ©Îï¡¢COVID-19ÒßÃçºÍCVSÖݪֲúÆ·µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£CVS HealthÌåÏÖ£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÓÉÒ»¸öµÚÈý·½¹©Ó¦ÉÌÔÚÖÎÀí£¬ £¬£¬£¬£¬ÏÖÔÚÒѾ­±»±£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/billions-of-records-belonging-to-cvs-health-exposed-online/


3.ÃÀ¹ú±ûÍ鹩ӦÉÌAmeriGas×Ô¶¯Åû¶Æä½üÆÚµÄÊý¾Ýй¶ÊÂÎñ


3.jpg


ÃÀ¹ú×î´óµÄ±ûÍ鹩ӦÉÌAmeriGas×Ô¶¯Åû¶Æä½üÆÚ±¬·¢µÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£AmeriGasÔÚÃÀ¹úµÄ50¸öÖÝΪÁè¼Ý200Íò¿Í»§ÌṩЧÀÍ£¬ £¬£¬£¬£¬ÓµÓÐ2500¶à¸ö·ÖÏúµã¡£¡£¡£¡£¡£¡£5ÔÂ10ÈÕ£¬ £¬£¬£¬£¬ÏòAmeriGasÌṩÔËÊ䲿 (DOT) ºÏ¹æÐ§À͵ũӦÉÌJJ KellerÔÚÆäϵͳÉϼì²âµ½¿ÉÒɻ£¬ £¬£¬£¬£¬ºó·¢Ã÷ÆäÔ±¹¤Ôâµ½ÁË´¹ÂÚ¹¥»÷µ¼ÖÂÕÊ»§±»µÁ£¬ £¬£¬£¬£¬¸Ã¹«Ë¾Á¬Ã¦×îÏÈÈ·¶¨´Ë´Îй¶µÄ¹æÄ£¡£¡£¡£¡£¡£¡£5ÔÂ21ÈÕ£¬ £¬£¬£¬£¬JJ Keller֪ͨAmeriGas´ËÊÂÎñ¿ÉÄÜй¶ÁËAmeriGasµÄ123ÃûÔ±¹¤µÄ¼Í¼£¬ £¬£¬£¬£¬°üÀ¨ÊµÑéÊÒID¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂëºÍ³öÉúÈÕÆÚ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/


4.ThroughTek P2P SDKÃ÷ÎÄй¶£¬ £¬£¬£¬£¬Ó°ÏìÊý°ÙÍòÉãÏñÍ·


4.jpg


CISAÅû¶ÁËThroughTekµÄP2P SDKÖеÄÃ÷ÎÄй¶Îó²î£¬ £¬£¬£¬£¬Ó°ÏìÁËÊý°ÙÍò¸öÉãÏñÍ·¡£¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-32934£¬ £¬£¬£¬£¬CVSS v3»ù±¾ÆÀ·ÖΪ9.1¡£¡£¡£¡£¡£¡£¸Ã×é¼þÒѱ»¶à¼ÒÇå¾²ÉãÏñÍ·µÄԭʼװ±¸ÖÆÔìÉÌ (OEM) ÒÔ¼°ÎïÁªÍø×°±¸ÖÆÔìÉÌʹÓ㬠£¬£¬£¬£¬Òѱ»×°ÖÃÔÚÊý°ÙÍò¸ö×°±¸ÖУ¬ £¬£¬£¬£¬ÀýÈçÓ¤¶ùºÍ³èÎï¼à¿ØÉãÏñÍ·¡¢»úеÈËºÍµç³Ø×°±¸µÈ¡£¡£¡£¡£¡£¡£CISAÌåÏÖ£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬ÈçÏà»úÒôƵ/ÊÓÆµÔ´µÈ£¬ £¬£¬£¬£¬×èÖ¹ÏÖÔÚ»¹Ã»±»ÔÚҰʹÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ics/advisories/icsa-21-166-01


5.ÒÔÉ«Áйú·À¾üǰÕÕÁϳ¤µÄÅÌËã»úÔâµ½ÒÁÀʺڿ͵ÄÈëÇÖ


5.jpg


±¾Öܶþ£¬ £¬£¬£¬£¬ÒÔÉ«ÁÐʱ±¨³ÆÒÁÀʺڿ͹¥»÷ÁËÒÔÉ«Áйú·À¾üµÄǰÕÕÁϳ¤µÄÅÌËã»ú£¬ £¬£¬£¬£¬²¢»ñµÃÁËËûµÄÕû¸öÅÌËã»úÊý¾Ý¿âµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£Channel 10ÌåÏָúڿÍÊÇYaser Balaghi£¬ £¬£¬£¬£¬¾Ý³ÆËûÔÚØÊºó´µÅõ×Ô¼ºµÄÐÐΪʱ²»Öª²»¾õµØÁôÏÂÁ˺ۼ££¬ £¬£¬£¬£¬µ¼ÖÂÒÁÀÊ×èÖ¹ÁËÕë¶ÔÈ«Çò1800ÈË£¨°üÀ¨ÒÔÉ«Áн¾ü½«¾ü¡¢²¨Ë¹ÍåÈËȨº´ÎÀÕߺÍѧÕߣ©µÄÍøÂçÐж¯¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùµÄÁ½ÄêÖУ¬ £¬£¬£¬£¬ÒÔÉ«ÁÐÒ»Ö±ÊÇÐí¶àÍøÂç¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/iran-said-to-hack-former-israeli-army-chief-of-staff-access-his-entire-computer-533222.shtml


6.CybereasonÐû²¼ÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄÆÊÎö±¨¸æ


6.jpg


CybereasonÐû²¼ÁËÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬Æ½¾ùÿ11Ãë¾Í»á±¬·¢Ò»´ÎÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬Ô¤¼Æ2021Äê×éÖ¯µÄËðʧ½«µÖ´ï200ÒÚÃÀÔª£¬ £¬£¬£¬£¬±È2020ÄêÔöÌí225%¡£¡£¡£¡£¡£¡£66%µÄ×éÖ¯±¨¸æ³ÆÔÚÀÕË÷Èí¼þ¹¥»÷ºóÊÕÈë·ºÆðËðʧ£»£»£»35%ÆóÒµÖ§¸¶ÁË35ÍòÖÁ140ÍòÃÀÔªÊê½ð£¬ £¬£¬£¬£¬7%µÄÆóÒµÖ§¸¶µÄÊê½ðÁè¼Ý140ÍòÃÀÔª£»£»£»53%×éÖ¯³ÆÆäÆ·ÅÆºÍÉùÓþÊÜË𣬠£¬£¬£¬£¬32%×éÖ¯³ÆC¼¶È˲ÅÁ÷ʧ£»£»£»26%×éÖ¯±¨¸æ³Æ¹¥»÷µ¼ÖÂÆóÒµÔÚÒ»¶Îʱ¼äÄÚÍêÈ«¹Ø±Õ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/report-ransomware-attacks-and-the-true-cost-to-business