EquifaxΪ2017ÄêÊý¾Ýй¶֧¸¶14ÒÚÃÀÔª£»£»£»£»£»Õë¶ÔÃÀ¹ú¶¼»áµÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö£»£»£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë

Ðû²¼Ê±¼ä 2019-05-13
1¡¢Õë¶ÔÃÀ¹ú¶¼»áµÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö£¬£¬£¬£¬£¬½ñÄêÒѱ¬·¢22Æð

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
ƾ֤Recorded FutureµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬Õë¶ÔÃÀ¹úÍâµØÕþ¸®¡¢¶¼»áϵͳ¡¢¾¯¾ÖºÍѧУµÄÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷ÕýÔÚáÈÆð£¬£¬£¬£¬£¬×Ô2013ÄêÒÔÀ´ÖÁÉÙÒÑÓÐ170¸öÏØ¡¢ÊлòÖÝÕþ¸®Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬£¬£¬2019ÄêÒѱ¬·¢ÁË22Æð´ËÀ๥»÷ÊÂÎñ£¬£¬£¬£¬£¬2016ÄêµÄÊý×ÖΪ46Æð£¬£¬£¬£¬£¬2017ÄêΪ38Æð£¬£¬£¬£¬£¬2018ÄêΪ53Æð¡£¡£¡£¡£¡£¡£¡£ÕâÀ๥»÷ÊÂÎñÍùÍù»á¶ÔÍâµØ¶¼»áÔì³ÉÊý°ÙÍòÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://edition.cnn.com/2019/05/10/politics/ransomware-attacks-us-cities/index.html

2¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
×Ô3Ô·ÝÒÔÀ´£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£¡£¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/

3¡¢Fin7 APTÖ÷Òª³ÉÔ±±»²¶ºó£¬£¬£¬£¬£¬2018ÄêÒÑÓÐԼĪ130¸ö¹«Ë¾³ÉΪĿµÄ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
ƾ֤¿¨°Í˹»ùµÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬Ö»¹ÜFin7 APTµÄÏòµ¼ÈËÔÚ18Äê8Ô·ݱ»¾Ð²¶£¬£¬£¬£¬£¬µ«¸ÃÍÅ»ïÈÔ´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£×èÖ¹2018Äêµ×ÒÑÓÐ130¶à¼Ò¹«Ë¾³ÉΪÆäÍøÂç´¹ÂÚ¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÊӲ쵽¸ÃÍÅ»ïÓëAveMaria½©Ê¬ÍøÂçÒÔ¼°CobaltGoblinÍŻﱣ´æ¹ØÁªµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâЩÍŻィÉèÁËÒ»¼ÒÐéαµÄÍøÂçÇå¾²¹«Ë¾£¬£¬£¬£¬£¬²¢Í¨¹ýÕÐÆ¸ÍøÕ¾ÕÐļ²»Ã÷ÕæÏàµÄÎó²îÑо¿Ö°Ô±¡¢¿ª·¢Ö°Ô±ºÍ·­ÒëÖ°Ô±£¬£¬£¬£¬£¬ÆäÖÐһЩÈËÉõÖÁ¿ÉÄܲ»ÖªµÀ¸Ã×éÖ¯ÕýÔÚ¾ÙÐв»·¨»î¶¯¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fin7-apt-targets-130-orgs-after-1-1/

4¡¢Ó¡µÚ°²ÄÉÖݲ½ÐÐÕß¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿·ÖÔ±¹¤ÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Ó¡µÚ°²Äɲ½ÐÐÕß¹«Ë¾Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾Ðû²¼µÄÐÂΟ壬£¬£¬£¬£¬ºÚ¿ÍÔÚ2018Äê10ÔÂ15ÈÕµ½2018Äê12ÔÂ4ÈÕÖ®¼äͨ¹ýÍøÂç´¹ÂÚ¹¥»÷»ñµÃÁ˼¸ÃûPSEÔ±¹¤ÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓÊÏäÕË»§ÖÐй¶ÁËһЩÃô¸ÐµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂë¡¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅÂë¡¢Óû§ÃûºÍÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/indiana-pacers-disclose-security-breach/

5¡¢ÍÁ¶úÆäÒò2018Äê12ÔµÄAPIÎó²î¶ÔFacebook·£¿£¿£¿£¿£¿£¿£¿î27ÍòÃÀÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
ÍÁ¶úÆäСÎÒ˽¼ÒÊý¾Ý±£»£»£»£»£»¤»ú¹¹£¨KVKK£©¶ÔFacebook´¦ÒÔ165ÍòÍÁ¶úÆäÀïÀ­£¨27ÍòÃÀÔª£©µÄ·£¿£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬·£¿£¿£¿£¿£¿£¿£¿îµÄÔ´ÓÉÊÇ2018Äê12ÔÂFacebookµÄAPIÎó²î̻¶ÁË30ÍòÍÁ¶úÆäÓû§µÄСÎÒ˽¼ÒÕÕÆ¬¡£¡£¡£¡£¡£¡£¡£KVKKÌåÏÖFacebookûÓÐʵʱ×ö³ö·´Ó¦ÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¢ÇÒûÓн«Ïà¹ØÊÂÎñ֪ͨÍÁ¶úÆäÕþ¸®¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬KVKK»¹ÔÚÊÓ²ì2018Äê9ÔµÄFacebookÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/turkey-fines-facebook-for-december-2018-api-bug/

6¡¢Equifax²Æ±¨³ÆÎª2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶14ÒÚÃÀÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
EquifaxÅû¶ÁËÓë2017Äê´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÓйصIJƱ¨£¬£¬£¬£¬£¬¸Ã¹«Ë¾×ܹ²Îª¸ÃÊÂÎñÆÆ·ÑÁËÔ¼14ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£2017ÄêµÄEquifaxÊý¾Ýй¶ÊÂÎñ×ܹ²µ¼ÖÂ1.45ÒÚÃÀ¹ú¹«ÃñºÍÊýÊ®Íò¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÕßʹÓõÄÊÇApache StrutsÎó²î£¨CVE-2017-5638£©£¬£¬£¬£¬£¬ËäÈ»¸ÃÎó²îÓÚ2017Äê3Ô±»ÐÞ¸´£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾²¢Î´ÊµÊ±×°ÖÃÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85379/security/equifax-data-breach-cost.html