2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ£»£»vBulletinÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2019-10-09
1.Ponemon InstituteÐû²¼¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤ÖܶþPonemon InstituteÐû²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬È«Çò66%µÄÖÐСÐÍÆóÒµ£¨SMB£©ÔÚÒÑÍù12¸öÔÂÄÚ±¨¸æÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£ ¡£¡£¡£PonemonÌåÏÖÕâÊÇÒ»Á¬µÚÈýÄêSMB±¨¸æµÄÍøÂçÇå¾²ÊÂÎñ·ºÆð¡°ÏÔÖøÔöÌí¡±¡£ ¡£¡£¡£Ä¿½ñSMBÃæÁÙµÄ×î³£¼ûÍøÂç¹¥»÷ÐÎʽÊÇÍøÂç´¹ÂÚ¡¢×°±¸ÈëÇÖ»ò±»µÁ¡¢Æ¾Ö¤ÇÔÈ¡¡£ ¡£¡£¡£Ëæ×Å×Ô´ø×°±¸°ì¹«£¨BYOD£©Ä£Ê½µÄÊ¢ÐУ¬£¬×°±¸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£ ¡£¡£¡£ÔÚÒÑÍù12¸öÔÂÖУ¬£¬¹²ÓÐ63%µÄÆóÒµ±¨¸æÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅϢɥʧÊÂÎñ£¬£¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬£¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£ ¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬£¬½ü100Íò»¼ÕßÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



T¨±Ora Compass HealthÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£ ¡£¡£¡£¸Ã³õ¼¶ÎÀÉú×éÖ¯£¨PHO£©ÌåÏÖÆä¹ÙÍøÔÚ8Ô·ݱ¬·¢µÄÒ»ÆðÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬£¬Òò´Ë¶ÔCompass HealthµÄÕûÌåITϵͳºÍÇ徲״̬¾ÙÐÐÁËÊӲ죬£¬×îÖÕ·¢Ã÷´Ó2016Äêµ½2019Äê3Ô±¬·¢µÄÍøÂç¹¥»÷¡£ ¡£¡£¡£Compass HealthÌåÏÖÈκÎÔÚ2016ÄêÖÁ2019Äêʱ´úÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬£¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£ ¡£¡£¡£ÊÜÓ°ÏìµÄµØÇøÖ÷ҪΪÐÂÎ÷À¼»ÝÁé¶Ù£¬£¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£ ¡£¡£¡£¿£¿£¿£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨Óû§µÄ¹ú¼ÒÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØµãÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐľÙÐÐ×¢²á¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬£¬¿Í»§ÐÅÓÃÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¼ÓÄôóTransUnion´ÓÉÏÖÜ×îÏÈÏòÓû§·¢ËÍÊý¾ÝÇå¾²ÊÂÎñ֪ͨ£¬£¬ÌåÏÖÓû§µÄÐÅÏ¢Ô⵽δÊÚȨ»á¼û¡£ ¡£¡£¡£¸Ãָ֪ͨ³ö£¬£¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕʱ´úδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Æ¾Ö¤»á¼ûÆäÃÅ»§ÍøÕ¾£¬£¬²¢¾ÙÐÐÁËÐÅÓñ¨¸æ²éÕÒ¡£ ¡£¡£¡£¿£¿£¿£¿ÉÄܲéÕÒµ½µÄÐÅÓÃÎļþÖаüÀ¨Óû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñ¼°ÒÑÍùµÄµØµãÒÔ¼°Õ÷ÐÅÏà¹ØÐÅÏ¢£¬£¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶ÀúÊ·µÈ£¬£¬µ«²»°üÀ¨ÏÖʵµÄÕË»§ºÅÂë¡£ ¡£¡£¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢À´ÊµÑéÉí·Ý͵ÇÔ£¬£¬Òò´ËTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓÃڲƭ¼à¿ØÐ§ÀÍ¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾöÒéÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬£¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢»Ö¸´ÆäϵͳµÄÕý³£ÔËÓª¡£ ¡£¡£¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨°üÀ¨DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬ÆÈʹËûÃǹرÕÁËÅÌËã»úϵͳ²¢×èÖ¹ÎüÊÕÐµĻ¼Õß¡£ ¡£¡£¡£ÉÏÖÜÄ©DCHÐû²¼¸üÐÂÉùÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÕýÔÚ»Ö¸´Æäϵͳ£¬£¬DCH²¢Î´Í¸Â¶Êê½ðµÄÏêϸÊý¶î£¬£¬µ«ÒÑÈ·È϶à¸öЧÀÍÆ÷±»ÀֳɽâÃÜ¡£ ¡£¡£¡£ÏÖÔÚÉв»ÇåÎúDCHµÄϵͳ½«ÓÚºÎʱÍêÈ«ÉÏÏß¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletinÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÔÚÉϸöÔÂÄ©ÐÞ¸´RCE 0dayºó£¬£¬vBulletinÐû²¼ÁËÒ»¸öеÄÇå¾²²¹¶¡£ ¡£¡£¡£¬£¬ÐÞ¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣÎó²î¡£ ¡£¡£¡£µÚÒ»¸öÎó²îÊÇRCEÎó²î£¨CVE-2019-17132£©£¬£¬±£´æÓÚvBulletin´¦Öóͷ£Óû§¸üÐÂÆäСÎÒ˽¼Ò×ÊÁϵÄÇëÇóÀú³ÌÖУ¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃδ¾­ÓÉÂ˵IJÎÊýÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×¢Èë²¢Ö´ÐÐí§ÒâPHP´úÂë¡£ ¡£¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£ ¡£¡£¡£ÁíÍâÁ½¸öÎó²îÊÇSQL×¢ÈëÎÊÌ⣬£¬ËüÃDZ»·ÖÅÉΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬£¬¿ÉÔÊÐí¾ßÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£ ¡£¡£¡£ÕâЩÎó²îÓ°ÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬ÐÞ¸´59¸öÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÔÚÖܶþÐû²¼µÄWindows 10ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË59¸öÎó²î£¬£¬ÆäÖаüÀ¨Çå¾²³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1238ºÍCVE-2019-1239£¬£¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCEÎó²î£¨CVE-2019-1333£¬£¬ÔÊÐí¶ñÒâЧÀÍÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÅþÁ¬Ê±ÔÚ¿Í»§¶ËÉÏÖ´ÐÐÏÂÁµÈ¡£ ¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/