EquifaxΪ2017ÄêÊý¾Ýй¶֧¸¶14ÒÚÃÀÔª£»Õë¶ÔÃÀ¹ú³ÇÊеÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö£»¶íÂÞ˹ºÚ¿Í×éÖ¯ÏúÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë

°ä²¼¹¦·ò 2019-05-13
1¡¢Õë¶ÔÃÀ¹ú³ÇÊеÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö  £¬½ñÄêÒѲúÉú22Æð

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
ƾ¾ÝRecorded FutureµÄͳ¼ÆÊý¾Ý  £¬Õë¶ÔÃÀ¹ú±¾µØµ±¾Ö¡¢³ÇÊÐϵͳ¡¢¾¯¾ÖºÍѧÌõÄÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷ÔÚáÈÆð  £¬×Ô2013ÄêÒÔÀ´ÖÁÉÙÒÑÓÐ170¸öÏØ¡¢ÊлòÖݵÐÔÖÊܵ½¹¥»÷ ¡£½ØÖÁĿǰΪֹ  £¬2019ÄêÒѲúÉúÁË22Æð´ËÀ๥»÷ÊÂÎñ  £¬2016ÄêµÄÊý×ÖΪ46Æð  £¬2017ÄêΪ38Æð  £¬2018ÄêΪ53Æð ¡£ÕâÀ๥»÷ÊÂÎñÍùÍù»á¶Ô±¾µØ³ÇÊÐÔì³ÉÊý°ÙÍòÃÀÔªµÄËðʧ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://edition.cnn.com/2019/05/10/politics/ransomware-attacks-us-cities/index.html

2¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯ÏúÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
×Ô3Ô·ÝÒÔÀ´  £¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³ÆÏúÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç½Ó¼ûȨÏÞ ¡£³õ²½µÄ¼ÛÖµÊǽӼûȨÏÞ25ÍòÃÀÔª  £¬Ô´´úÂë15ÍòÃÀÔª  £¬µ«±¨¼Û²¢²»¹Ì¶¨ ¡£Fxmsp²¢Î´Ö¸³ö¾ßÌåµÄ¹«Ë¾Ãû³Æ  £¬µ«ÌṩÁËÔ̺¬30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ  £¬¾Ý³ÆÕâЩÊý¾ÝÔ̺¬¿ª·¢Îĵµ¡¢ÈËΪÖÇÄÜÄ£ÐÍ¡¢Web°²È«Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/

3¡¢Fin7 APT³ÁÒª³ÉÔ±±»²¶ºó  £¬2018ÄêÒÑÓÐԼĪ130¸ö¹«Ë¾³ÉΪָ±ê

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
ƾ¾Ý¿¨°Í˹»ùµÄÒ»·Ýл㱨  £¬Ö»¹ÜFin7 APTµÄ¸¨µ¼ÈËÔÚ18Äê8Ô·ݱ»¿ÛÁô  £¬µ«¸ÃÍÅ»ïÈÔ´¦ÓÚ»îԾ״̬ ¡£½ØÖ¹2018Äêµ×ÒÑÓÐ130¶à¼Ò¹«Ë¾³ÉΪÆäÍøÂç´¹µö¹¥»÷µÄÖ¸±ê ¡£×êÑÐÈËÔ±»¹¹Û²ìµ½¸ÃÍÅ»ïÓëAveMaria½©Ê¬ÍøÂçÒÔ¼°CobaltGoblinÍÅ»ï´æÔÚ¹ØÁªµÄÖ¤¾Ý ¡£ÕâЩÍŻﴴ½¨ÁËÒ»¼ÒÐéαµÄÍøÂ簲ȫ¹«Ë¾  £¬²¢Í¨¹ýÕÐÆ¸ÍøÕ¾ÕÐļ²»Ã÷ÕæÏàµÄ·ì϶×êÑÐÈËÔ±¡¢¿ª·¢ÈËÔ±ºÍ·­ÒëÈËÔ±  £¬ÆäÖÐһЩÈËÉõÖÁ¿ÉÄܲ»ÖªÂ·¸Ã×éÖ¯ÔÚ½øÐз¸·¨»î¶¯ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fin7-apt-targets-130-orgs-after-1-1/

4¡¢Ó¡µÚ°²ÄÉÖݲ½ÐÐÕß¹«Ë¾ÔâºÚ¿ÍÈëÇÖ  £¬²¿ÃÅÔ±¹¤ÐÅϢй¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Ó¡µÚ°²Äɲ½ÐÐÕß¹«Ë¾Ôâµ½ºÚ¿Í¹¥»÷  £¬Æ¾¾Ý¸Ã¹«Ë¾°ä²¼µÄÐÂΟå  £¬ºÚ¿ÍÔÚ2018Äê10ÔÂ15ÈÕµ½2018Äê12ÔÂ4ÈÕÖ®¼äͨ¹ýÍøÂç´¹µö¹¥»÷»ñµÃÁ˼¸ÃûPSEÔ±¹¤ÕË»§µÄ½Ó¼ûȨÏÞ ¡£ÊÜÓ°ÏìµÄÓÊÏäÕË»§ÖÐй¶ÁËһЩÃô¸ÐµÄÓ×ÎÒÐÅÏ¢  £¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂë¡¢ÐÅÓþ¿¨/½è¼Ç¿¨ºÅÂë¡¢Óû§ÃûºÍÃÜÂëµÈ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/indiana-pacers-disclose-security-breach/

5¡¢ÍÁ¶úÆäÒò2018Äê12ÔµÄAPI·ì϶¶ÔFacebook·£¿î27ÍòÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
ÍÁ¶úÆäÓ×ÎÒÊý¾Ý±£»¤»ú¹¹£¨KVKK£©¶ÔFacebook´¦ÒÔ165ÍòÍÁ¶úÆäÀïÀ­£¨27ÍòÃÀÔª£©µÄ·£¿î  £¬·£¿îµÄÔ´ÓÉÊÇ2018Äê12ÔÂFacebookµÄAPI·ì϶¶³öÁË30ÍòÍÁ¶úÆäÓû§µÄÓ×ÎÒÕÕÆ¬ ¡£KVKK°µÊ¾FacebookûÓÐʵʱ×ö³ö·´Ó³½¨¸´·ì϶  £¬²¢ÇÒûÓн«ÓйØÊÂÎñ֪ͨÍÁ¶úÆäµ±¾Ö ¡£´Ë±í  £¬KVKK»¹ÔÚµ÷²é2018Äê9ÔµÄFacebookÊý¾Ýй¶ÊÂÎñ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/turkey-fines-facebook-for-december-2018-api-bug/

6¡¢Equifax²Æ±¨³ÆÎª2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶14ÒÚÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
EquifaxÅû¶ÁËÓë2017Äê´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÓйصIJƱ¨  £¬¸Ã¹«Ë¾×ܹ²Îª¸ÃÊÂÎñÆÆ·ÑÁËÔ¼14ÒÚÃÀÔª ¡£2017ÄêµÄEquifaxÊý¾Ýй¶ÊÂÎñ×ܹ²µ¼ÖÂ1.45ÒÚÃÀ¹ú¹«ÃñºÍÊýÊ®Íò¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄÃô¸ÐÐÅϢй¶  £¬Æäʱ¹¥»÷ÕßÀûÓõÄÊÇApache Struts·ì϶£¨CVE-2017-5638£©  £¬¹ÌÈ»¸Ã·ì϶ÓÚ2017Äê3Ô±»½¨¸´  £¬µ«¸Ã¹«Ë¾²¢Î´ÊµÊ±×°Öý¨¸´²¹¶¡ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85379/security/equifax-data-breach-cost.html