2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ£»£» £»£»£»vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2019-10-09
1.Ponemon InstituteÐû²¼¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤ÖܶþPonemon InstituteÐû²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬£¬£¬È«Çò66%µÄÖÐСÐÍÆóÒµ£¨SMB£©ÔÚÒÑÍù12¸öÔÂÄÚ±¨¸æÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£¡£PonemonÌåÏÖÕâÊÇÒ»Á¬µÚÈýÄêSMB±¨¸æµÄÍøÂçÇå¾²ÊÂÎñ·ºÆð¡°ÏÔÖøÔöÌí¡±¡£¡£Ä¿½ñSMBÃæÁÙµÄ×î³£¼ûÍøÂç¹¥»÷ÐÎʽÊÇÍøÂç´¹ÂÚ¡¢×°±¸ÈëÇÖ»ò±»µÁ¡¢Æ¾Ö¤ÇÔÈ¡¡£¡£Ëæ×Å×Ô´ø×°±¸°ì¹«£¨BYOD£©Ä£Ê½µÄÊ¢ÐУ¬£¬£¬£¬£¬×°±¸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£¡£ÔÚÒÑÍù12¸öÔÂÖУ¬£¬£¬£¬£¬¹²ÓÐ63%µÄÆóÒµ±¨¸æÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅϢɥʧÊÂÎñ£¬£¬£¬£¬£¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬£¬£¬£¬£¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬½ü100Íò»¼ÕßÐÅϢй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



T¨±Ora Compass HealthÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¸Ã³õ¼¶ÎÀÉú×éÖ¯£¨PHO£©ÌåÏÖÆä¹ÙÍøÔÚ8Ô·ݱ¬·¢µÄÒ»ÆðÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬Òò´Ë¶ÔCompass HealthµÄÕûÌåITϵͳºÍÇ徲״̬¾ÙÐÐÁËÊӲ죬£¬£¬£¬£¬×îÖÕ·¢Ã÷´Ó2016Äêµ½2019Äê3Ô±¬·¢µÄÍøÂç¹¥»÷¡£¡£Compass HealthÌåÏÖÈκÎÔÚ2016ÄêÖÁ2019Äêʱ´úÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬£¬£¬£¬£¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£¡£ÊÜÓ°ÏìµÄµØÇøÖ÷ҪΪÐÂÎ÷À¼»ÝÁé¶Ù£¬£¬£¬£¬£¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¡£¿£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨Óû§µÄ¹ú¼ÒÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØµãÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐľÙÐÐ×¢²á¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¿Í»§ÐÅÓÃÐÅϢй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¼ÓÄôóTransUnion´ÓÉÏÖÜ×îÏÈÏòÓû§·¢ËÍÊý¾ÝÇå¾²ÊÂÎñ֪ͨ£¬£¬£¬£¬£¬ÌåÏÖÓû§µÄÐÅÏ¢Ô⵽δÊÚȨ»á¼û¡£¡£¸Ãָ֪ͨ³ö£¬£¬£¬£¬£¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕʱ´úδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Æ¾Ö¤»á¼ûÆäÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬²¢¾ÙÐÐÁËÐÅÓñ¨¸æ²éÕÒ¡£¡£¿£¿ÉÄܲéÕÒµ½µÄÐÅÓÃÎļþÖаüÀ¨Óû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñ¼°ÒÑÍùµÄµØµãÒÔ¼°Õ÷ÐÅÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶ÀúÊ·µÈ£¬£¬£¬£¬£¬µ«²»°üÀ¨ÏÖʵµÄÕË»§ºÅÂë¡£¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢À´ÊµÑéÉí·Ý͵ÇÔ£¬£¬£¬£¬£¬Òò´ËTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓÃڲƭ¼à¿ØÐ§ÀÍ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾöÒéÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬£¬£¬£¬£¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢»Ö¸´ÆäϵͳµÄÕý³£ÔËÓª¡£¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨°üÀ¨DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬ÆÈʹËûÃǹرÕÁËÅÌËã»úϵͳ²¢×èÖ¹ÎüÊÕÐµĻ¼Õß¡£¡£ÉÏÖÜÄ©DCHÐû²¼¸üÐÂÉùÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÕýÔÚ»Ö¸´Æäϵͳ£¬£¬£¬£¬£¬DCH²¢Î´Í¸Â¶Êê½ðµÄÏêϸÊý¶î£¬£¬£¬£¬£¬µ«ÒÑÈ·È϶à¸öЧÀÍÆ÷±»ÀֳɽâÃÜ¡£¡£ÏÖÔÚÉв»ÇåÎúDCHµÄϵͳ½«ÓÚºÎʱÍêÈ«ÉÏÏß¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÔÚÉϸöÔÂÄ©ÐÞ¸´RCE 0dayºó£¬£¬£¬£¬£¬vBulletinÐû²¼ÁËÒ»¸öеÄÇå¾²²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣÎó²î¡£¡£µÚÒ»¸öÎó²îÊÇRCEÎó²î£¨CVE-2019-17132£©£¬£¬£¬£¬£¬±£´æÓÚvBulletin´¦Öóͷ£Óû§¸üÐÂÆäСÎÒ˽¼Ò×ÊÁϵÄÇëÇóÀú³ÌÖУ¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃδ¾­ÓÉÂ˵IJÎÊýÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×¢Èë²¢Ö´ÐÐí§ÒâPHP´úÂë¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£¡£ÁíÍâÁ½¸öÎó²îÊÇSQL×¢ÈëÎÊÌ⣬£¬£¬£¬£¬ËüÃDZ»·ÖÅÉΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬£¬£¬£¬£¬¿ÉÔÊÐí¾ßÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£ÕâЩÎó²îÓ°ÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´59¸öÎó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


΢ÈíÔÚÖܶþÐû²¼µÄWindows 10ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË59¸öÎó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨Çå¾²³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1238ºÍCVE-2019-1239£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCEÎó²î£¨CVE-2019-1333£¬£¬£¬£¬£¬ÔÊÐí¶ñÒâЧÀÍÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÅþÁ¬Ê±ÔÚ¿Í»§¶ËÉÏÖ´ÐÐÏÂÁµÈ¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/