2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨£»vBulletin°ä²¼°²È«¸üР£¬½¨¸´ÐÂRCEºÍSQL×¢Èë·ì϶

°ä²¼¹¦·ò 2019-10-09
1.Ponemon Institute°ä²¼¡¶2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨¡·

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝÖܶþPonemon Institute°ä²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂ簲ȫÇé¿ö»ã±¨¡· £¬È«Çò66%µÄÖÐÓ×ÐÍÆóÒµ£¨SMB£©ÔÚ´Óǰ12¸öÔÂÄڻ㱨ÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£Ponemon°µÊ¾ÕâÊÇÂ½ÐøµÚÈýÄêSMB»ã±¨µÄÍøÂ簲ȫÊÂÎñ³öÏÖ¡°ÏÔÖøÔö³¤¡±¡£µ±Ç°SMBÃæ¶ÔµÄ×î³£¼ûÍøÂç¹¥»÷´ó¾ÖÊÇÍøÂç´¹µö¡¢É豸ÈëÇÖ»ò±»µÁ¡¢Í´´¦ÇÔÈ¡¡£Ëæ×Å×Ô´øÉ豸°ì¹«£¨BYOD£©Ä£Ê½µÄÁ÷ÐÐ £¬É豸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£ÔÚ´Óǰ12¸öÔÂÖÐ £¬¹²ÓÐ63%µÄÆóÒµ»ã±¨ÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅÏ¢¶ª³öÊÂÎñ £¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69% £¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷ £¬½ü100Íò»¼ÕßÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



T¨±Ora Compass HealthÔâ·êÊý¾Ýй¶ÊÂÎñ £¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¸ÃµÍ¼¶ÎÀÉú×éÖ¯£¨PHO£©°µÊ¾Æä¹ÙÍøÔÚ8Ô·ݲúÉúµÄÒ»Â·ÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ £¬Òò¶ø¶ÔCompass HealthµÄÕûÌåITϵͳºÍ°²È«Çé¿ö½øÐÐÁ˵÷²é £¬×îÖÕ·¢ÏÖ´Ó2016Äêµ½2019Äê3Ô²úÉúµÄÍøÂç¹¥»÷¡£Compass Health°µÊ¾ÈκÎÔÚ2016ÄêÖÁ2019ÄêÆÚ¼äÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ïì £¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£ÊÜÓ°ÏìµÄµØÓòÖØÒªÎªÐÂÎ÷À¼»ÝÁé¶Ù £¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾ÝÔ̺¬Óû§µÄ¹ú¶ÈÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØÖ·ÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐĽøÐÐ×¢²á¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ £¬¿Í»§ÐÅÓþÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÄôóTransUnion´ÓÉÏÖÜÆðÍ·ÏòÓû§·¢ËÍÊý¾Ý°²È«ÊÂÎñ֪ͨ £¬°µÊ¾Óû§µÄÐÅÏ¢Ô⵽δÊÚȨ½Ó¼û¡£¸Ãָ֪ͨ³ö £¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕÆÚ¼äδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Í´´¦½Ó¼ûÆäÃÅ»§ÍøÕ¾ £¬²¢½øÐÐÁËÐÅÓþ»ã±¨²éÕÒ¡£¿ÉÄܲéÕÒµ½µÄÐÅÓþÎļþÖÐÔ̺¬Óû§µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±Ç°¼°´ÓǰµÄµØÖ·ÒÔ¼°Õ÷ÐÅÓйØÐÅÏ¢ £¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶º¹ÇàµÈ £¬µ«²»Ô̺¬ÏÖʵµÄÕË»§ºÅÂë¡£ÓÉÓÚ¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩÐÅÏ¢À´Ö´ÐÐÉí·Ý͵ÇÔ £¬Òò¶øTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓþڲƭ¼à¿Ø·þÎñ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾö¶¨ÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð £¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢¸´Ô­ÆäϵͳµÄÕý³£ÔËÓª¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨Ô̺¬DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷ £¬ÆÈʹËûÃǹعØÁËÍÆËã»úϵͳ²¢ÖÕ³¡½Ó¹ÜÐµĻ¼Õß¡£ÉÏÖÜÄ©DCH°ä²¼¸üÐÂÉêÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÔÚ¸´Ô­Æäϵͳ £¬DCH²¢Î´Ð¹Â©Êê½ðµÄ¾ßÌåÊý¶î £¬µ«ÒÑÈ·È϶à¸ö·þÎñÆ÷±»³É¹¦½âÃÜ¡£Ä¿Ç°Éв»Ã÷ÏÔDCHµÄϵͳ½«ÓÚºÎʱÆëÈ«ÉÏÏß¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletin°ä²¼°²È«¸üР£¬½¨¸´ÐÂRCEºÍSQL×¢Èë·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚÉϸöÔÂÄ©½¨¸´RCE 0dayºó £¬vBulletin°ä²¼ÁËÒ»¸öÐµİ²È«²¹¶¡ £¬½¨¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣ·ì϶¡£µÚÒ»¸ö·ì϶ÊÇRCE·ì϶£¨CVE-2019-17132£© £¬´æÔÚÓÚvBulletin´¦ÖÃÓû§¸üÐÂÆäÓ×ÎÒ×ÊÁϵÄÒªÇó¹ý³ÌÖÐ £¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃδ¾­¹ýÂ˵IJÎÊýÔÚÖ¸±ê·þÎñÆ÷ÉÏ×¢Èë²¢Ö´ÐÐËÁÒâPHP´úÂë¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÓйØPoC¡£Áí±íÁ½¸ö·ì϶ÊÇSQL×¢ÈëÎÊÌâ £¬ËüÃDZ»·ÖÅäΪͳһ¸öCVE ID£¨CVE-2019-17271£© £¬¿ÉÔÊÐíÓµÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£ÕâЩ·ì϶ӰÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾ £¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢Èí°ä²¼10Ô°²È«¸üР£¬½¨¸´59¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÔÚÖܶþ°ä²¼µÄWindows 10Ô°²È«¸üÐÂÖн¨¸´ÁË59¸ö·ì϶ £¬ÆäÖÐÔ̺¬°²È«³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1238ºÍCVE-2019-1239 £¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCE·ì϶£¨CVE-2019-1333 £¬ÔÊÐí¶ñÒâ·þÎñÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÏνÓʱÔÚ¿Í»§¶ËÉÏÖ´ÐкÅÁµÈ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/