AvaddonÍÅ»ïÉù³ÆÒÑ´Ó·¨¹ú°ü¹Ü¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý£»£»£»£»£»£»Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃURL¼Æ»®À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§

Ðû²¼Ê±¼ä 2021-05-18

1.AvaddonÍÅ»ïÉù³ÆÒÑ´Ó·¨¹ú°ü¹Ü¹«Ë¾AXAÇÔÈ¡3TBµÄÊý¾Ý


1.jpg


·¨¹ú°ü¹Ü¹«Ë¾°²Ê¢¼¯ÍÅ£¨AXA Group£©ÉÏÖÜÈÕÐû²¼£¬£¬ £¬ÆäÔâµ½AvaddonÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬ £¬Ó°ÏìÁËÑÇÖÞÓªÒµ²¿·ÖµÄITÔËÓª¡£ ¡£¡£AvaddonÍŶÓÔòÔÚÆäÐ¹Â¶ÍøÕ¾ÉÏÉù³Æ£¬£¬ £¬ËûÃÇÒѾ­´ÓAXA¹«Ë¾ÇÔÈ¡ÁË3TBµÄÃô¸ÐÊý¾Ý£¬£¬ £¬°üÀ¨¿Í»§Ò½ÁƱ¨¸æ¡¢Éí·ÝÖ¤¸´Ó¡¼þ¡¢ÒøÐжÔÕʵ¥¡¢Ë÷Åâ±í¡¢¸¶¿î¼Í¼ºÍÌõÔ¼µÈ£¬£¬ £¬²¢¶ÔAXAÔÚÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ïã¸ÛºÍ·ÆÂɱöµÄÍøÕ¾ÌᳫÁËÓÐÓõÄDDoS¹¥»÷¡£ ¡£¡£AXAÌåÏÖ´Ë´ÎÊÂÎñ½öй¶ÁËÌ©¹ú¹ú¼ÊÏàÖúͬ°éЭÖú£¨IPA£©µÄ²¿·ÖÊý¾Ý£¬£¬ £¬ÆäËü·Ö¹«Ë¾Î´ÊÜÓ°Ïì¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/avaddon-ransomware-french-insurance-axa-data-stolen/


2.°ÍÎ÷¹«Ë¾Rede BahiaÔâµ½ÀÕË÷¹¥»÷£¬£¬ £¬ÔËÓªÔÝʱÖÐÖ¹


2.jpg


°ÍÎ÷ÉÌÒµ¼¯ÍÅRede BahiaÔâµ½ÀÕË÷¹¥»÷£¬£¬ £¬ÔËÓªÔÝʱÖÐÖ¹¡£ ¡£¡£2021Äê5ÔÂ13ÈÕ£¬£¬ £¬¸Ã¹«Ë¾Í¨¹ýÓʼþ֪ͨԱ¹¤£¬£¬ £¬Òò¹¥»÷ÊÂÎñÆäСÎÒ˽¼ÒÐÅÏ¢£¨ÀýÈçн×ÊÃ÷ϸµÈ£©¿ÉÄÜÒѾ­Ð¹Â¶¡£ ¡£¡£±ðµÄ£¬£¬ £¬´Ë´Î¹¥»÷»¹×ÌÈÅÁËRede BahiaÆìϵı¨Ö½CorreioÖðÈÕµÄÕý³£³öÊé¡£ ¡£¡£ÏÖÔÚ£¬£¬ £¬¸Ã¹«Ë¾ÈÔÔÚÆð¾¢»Ö¸´ËùÓй¦Ð§£¬£¬ £¬ÉÐδ¹ûÕæÓйØÀÕË÷Èí¼þµÄÀàÐÍ»òÀÕË÷ÐèÇóµÄÏêϸÐÅÏ¢¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/br-rede-bahia-suffers-a-cyberattack-and-reported-databreach/


3.°ü¹Ü¹«Ë¾Guard.meÔâµ½¹¥»÷£¬£¬ £¬¿Í»§Ð¡ÎÒ˽¼ÒÐÅϢй¶


3.jpg


Guard.meÔâµ½¹¥»÷£¬£¬ £¬¿Í»§Ð¡ÎÒ˽¼ÒÐÅϢй¶¡£ ¡£¡£guard.meÊÇÈ«Çò×î´óµÄ°ü¹Ü¹«Ë¾Ö®Ò»£¬£¬ £¬×¨ÃÅΪ³ö¹úÂÃÐлò³ö¹úÁôѧµÄѧÉúÌṩ¿µ½¡°ü¹Ü¡£ ¡£¡£5ÔÂ12ÈÕ£¬£¬ £¬Guard.meÔÚÆäÍøÕ¾ÉÏ·¢Ã÷ÁËÒì³£»£»£»£»£»£»î¶¯£¬£¬ £¬×÷ΪԤ·À²½·¥£¬£¬ £¬ÆäÁ¬Ã¦¹Ø±ÕÁ˸ÃÍøÕ¾²¢¶ÔÆä¾ÙÐÐά»¤¡£ ¡£¡£Ö±µ½5ÔÂ17ÈÕ£¬£¬ £¬¸Ã¹«Ë¾Í¨ÖªÆä¿Í»§ÓÐδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓÃÆäÍøÕ¾ÖеÄÎó²î»á¼ûÁËѧÉúµÄÐÅÏ¢£¬£¬ £¬°üÀ¨ÉúÈÕ¡¢ÐÔ±ð¡¢ÃÜÂëÓʼþµØµã¡¢ÓʼĵصãºÍµç»°ºÅÂëµÈ¡£ ¡£¡£guard.me³ÆÎó²îÏÖÒÑÐÞ¸´£¬£¬ £¬²¢ÆôÓÃÁËеĸü¸ß¼¶±ðµÄÇå¾²Õ½ÂÔ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/student-health-insurance-carrier-guardme-suffers-a-data-breach/


4.Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃURL¼Æ»®À´¿çä¯ÀÀÆ÷¸ú×ÙÓû§


4.jpg


Ñо¿Ö°Ô±¿ª·¢ÁËÒ»ÖÖÒªÁ죬£¬ £¬Í¨¹ýÅÌÎÊ×°±¸ÉÏ×°ÖõÄÓ¦ÓóÌÐò£¬£¬ £¬¿ÉÒÔ×·×Ù²î±ðä¯ÀÀÆ÷µÄÓû§¡£ ¡£¡£ÓÉÓÚijЩӦÓóÌÐòÔÚ×°Öúó»á½¨Éè×Ô½ç˵URL¼Æ»®£¬£¬ £¬ä¯ÀÀÆ÷¿ÉʹÓøÃURL¼Æ»®ÔÚÌØ¶¨Ó¦ÓóÌÐòÖз­¿ªURL¡£ ¡£¡£ FingerprintJSÑо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃ×Ô½ç˵ЭÒé´¦Öóͷ£³ÌÐòÖеĺ鷺Îó²î£¬£¬ £¬ÔÚ²î±ðµÄä¯ÀÀÆ÷£¬£¬ £¬°üÀ¨Chrome¡¢Firefox¡¢Microsoft Edge¡¢Safari£¬£¬ £¬ÉõÖÁÊÇTorÖ®¼ä¸ú×ÙÓû§µÄ¡£ ¡£¡£ÏÖÔÚ£¬£¬ £¬Ö»Óйȸèä¯ÀÀÆ÷֮ǰ½ÓÄÉÁË»º½â²½·¥£¬£¬ £¬À´±ÜÃâ´ËÀ๥»÷¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cross-browser-tracking-vulnerability-tracks-you-via-installed-apps/


5.HiscoxÐû²¼2021ÄêµÄCyber ReadinessÆÊÎö±¨¸æ


5.jpg


¹ú¼Ê°ü¹Ü¹«Ë¾HiscoxÐû²¼2021ÄêµÄCyber ReadinessÆÊÎö±¨¸æ¡£ ¡£¡£±¨¸æÊÓ²ìÁËÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢±ÈÀûʱ¡¢·¨¹ú¡¢µÂ¹ú¡¢ºÉÀ¼¡¢Î÷°àÑÀºÍ°®¶ûÀ¼µÄ6000¶à¸öÍøÂçÇå¾²ÈÏÕæÖ°Ô±¡£ ¡£¡£ ±¨¸æÏÔʾ£¬£¬ £¬ÔÚÒÑÍùÒ»ÄêÖУ¬£¬ £¬ÓÐÃÀ¹ú23£¥µÄСÐÍÆóÒµÔâÊÜÁËÖÁÉÙÒ»´ÎÍøÂç¹¥»÷¡£ ¡£¡£63£¥µÄСÐÍÆóÒµÔÚÔ¶³ÌÊÂÇ飬£¬ £¬53£¥ÒÔΪ×Ô¼ºÈÝÒ×Êܵ½ÍøÂç¹¥»÷¡£ ¡£¡£39£¥µÄÆóÒµÌåÏÖ£¬£¬ £¬ËûÃÇÔ¤¼ÆÔöÌíÆäÇå¾²Ö§³ö£¬£¬ £¬49£¥µÄÆóҵ˵ӵÓÐÍøÂç°ü¹Ü¡£ ¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.hiscox.com/sites/default/files/content/documents/Hiscox-Cyber-Readiness-Report-2021.pdf


6.CISAÐû²¼ÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÓ¦¶ÔÖ¸ÄÏ


6.jpg


CISAÐû²¼ÁËÊÜSolarWindsºÍAD/M365Ó°ÏìµÄÍøÂçµÄÓ¦¶ÔÖ¸ÄÏ¡£ ¡£¡£¸ÃÖ¸ÄÏÖ¸³ö£¬£¬ £¬Ó¦¶Ô²½·¥Ö÷Òª·ÖΪÈý²½£º Pre-Eviction½×¶Î£¬£¬ £¬¼ì²âºÍʶ±ðAPT»î¶¯²¢ÎªÏÂÒ»½×¶Î×öºÃ×¼±¸£»£»£»£»£»£»Eviction½×¶Î£¬£¬ £¬´ÓÍâµØºÍÔÆÇéÐÎÖÐɾ³ýAPT¼ÓÈëÕߵIJÙ×÷£¬£¬ £¬°üÀ¨ÖØÐÞ×°±¸ºÍϵͳ£»£»£»£»£»£»Post-Eviction½×¶Î£¬£¬ £¬È·±£ÇýÖðÀֳɲ¢ÇÒÍøÂç¾ßÓÐÓÅÒìµÄ״̬¡£ ¡£¡£±ðµÄ£¬£¬ £¬CISAÌáÐѱ¾Ö¸ÄÏÖÐÌṩµÄ°ì·¨ãýÃð×ÊÔ´ÇÒºÜÊÇÖØ´ó£¬£¬ £¬ÐèÒªÆóÒµ½«ÍøÂç´ÓInternet¶Ï¿ª3µ½5Ìì¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/analysis-reports/ar21-134a