EquifaxΪ2017ÄêÊý¾Ýй¶֧¸¶14ÒÚÃÀÔª£»£»£»Õë¶ÔÃÀ¹ú¶¼»áµÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë
Ðû²¼Ê±¼ä 2019-05-13
ƾ֤Recorded FutureµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬Õë¶ÔÃÀ¹úÍâµØÕþ¸®¡¢¶¼»áϵͳ¡¢¾¯¾ÖºÍѧУµÄÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷ÕýÔÚáÈÆð£¬£¬£¬£¬£¬£¬×Ô2013ÄêÒÔÀ´ÖÁÉÙÒÑÓÐ170¸öÏØ¡¢ÊлòÖÝÕþ¸®Êܵ½¹¥»÷¡£¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬2019ÄêÒѱ¬·¢ÁË22Æð´ËÀ๥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬2016ÄêµÄÊý×ÖΪ46Æð£¬£¬£¬£¬£¬£¬2017ÄêΪ38Æð£¬£¬£¬£¬£¬£¬2018ÄêΪ53Æð¡£¡£¡£¡£ÕâÀ๥»÷ÊÂÎñÍùÍù»á¶ÔÍâµØ¶¼»áÔì³ÉÊý°ÙÍòÃÀÔªµÄËðʧ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://edition.cnn.com/2019/05/10/politics/ransomware-attacks-us-cities/index.html
×Ô3Ô·ÝÒÔÀ´£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬£¬£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/
3¡¢Fin7 APTÖ÷Òª³ÉÔ±±»²¶ºó£¬£¬£¬£¬£¬£¬2018ÄêÒÑÓÐԼĪ130¸ö¹«Ë¾³ÉΪĿµÄ
ƾ֤¿¨°Í˹»ùµÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬£¬Ö»¹ÜFin7 APTµÄÏòµ¼ÈËÔÚ18Äê8Ô·ݱ»¾Ð²¶£¬£¬£¬£¬£¬£¬µ«¸ÃÍÅ»ïÈÔ´¦ÓÚ»îԾ״̬¡£¡£¡£¡£×èÖ¹2018Äêµ×ÒÑÓÐ130¶à¼Ò¹«Ë¾³ÉΪÆäÍøÂç´¹ÂÚ¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÊӲ쵽¸ÃÍÅ»ïÓëAveMaria½©Ê¬ÍøÂçÒÔ¼°CobaltGoblinÍŻﱣ´æ¹ØÁªµÄÖ¤¾Ý¡£¡£¡£¡£ÕâЩÍŻィÉèÁËÒ»¼ÒÐéαµÄÍøÂçÇå¾²¹«Ë¾£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÕÐÆ¸ÍøÕ¾ÕÐļ²»Ã÷ÕæÏàµÄÎó²îÑо¿Ö°Ô±¡¢¿ª·¢Ö°Ô±ºÍ·ÒëÖ°Ô±£¬£¬£¬£¬£¬£¬ÆäÖÐһЩÈËÉõÖÁ¿ÉÄܲ»ÖªµÀ¸Ã×éÖ¯ÕýÔÚ¾ÙÐв»·¨»î¶¯¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fin7-apt-targets-130-orgs-after-1-1/
4¡¢Ó¡µÚ°²ÄÉÖݲ½ÐÐÕß¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬²¿·ÖÔ±¹¤ÐÅϢй¶
Ó¡µÚ°²Äɲ½ÐÐÕß¹«Ë¾Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾Ðû²¼µÄÐÂΟ壬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2018Äê10ÔÂ15ÈÕµ½2018Äê12ÔÂ4ÈÕÖ®¼äͨ¹ýÍøÂç´¹ÂÚ¹¥»÷»ñµÃÁ˼¸ÃûPSEÔ±¹¤ÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓÊÏäÕË»§ÖÐй¶ÁËһЩÃô¸ÐµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂë¡¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅÂë¡¢Óû§ÃûºÍÃÜÂëµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/indiana-pacers-disclose-security-breach/
5¡¢ÍÁ¶úÆäÒò2018Äê12ÔµÄAPIÎó²î¶ÔFacebook·£¿£¿£¿î27ÍòÃÀÔª
ÍÁ¶úÆäСÎÒ˽¼ÒÊý¾Ý±£»£»£»¤»ú¹¹£¨KVKK£©¶ÔFacebook´¦ÒÔ165ÍòÍÁ¶úÆäÀïÀ£¨27ÍòÃÀÔª£©µÄ·£¿£¿£¿î£¬£¬£¬£¬£¬£¬·£¿£¿£¿îµÄÔ´ÓÉÊÇ2018Äê12ÔÂFacebookµÄAPIÎó²î̻¶ÁË30ÍòÍÁ¶úÆäÓû§µÄСÎÒ˽¼ÒÕÕÆ¬¡£¡£¡£¡£KVKKÌåÏÖFacebookûÓÐʵʱ×ö³ö·´Ó¦ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¢ÇÒûÓн«Ïà¹ØÊÂÎñ֪ͨÍÁ¶úÆäÕþ¸®¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬KVKK»¹ÔÚÊÓ²ì2018Äê9ÔµÄFacebookÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/turkey-fines-facebook-for-december-2018-api-bug/
6¡¢Equifax²Æ±¨³ÆÎª2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶14ÒÚÃÀÔª
EquifaxÅû¶ÁËÓë2017Äê´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÓйصIJƱ¨£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾×ܹ²Îª¸ÃÊÂÎñÆÆ·ÑÁËÔ¼14ÒÚÃÀÔª¡£¡£¡£¡£2017ÄêµÄEquifaxÊý¾Ýй¶ÊÂÎñ×ܹ²µ¼ÖÂ1.45ÒÚÃÀ¹ú¹«ÃñºÍÊýÊ®Íò¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÕßʹÓõÄÊÇApache StrutsÎó²î£¨CVE-2017-5638£©£¬£¬£¬£¬£¬£¬ËäÈ»¸ÃÎó²îÓÚ2017Äê3Ô±»ÐÞ¸´£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾²¢Î´ÊµÊ±×°ÖÃÐÞ¸´²¹¶¡¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85379/security/equifax-data-breach-cost.html


¾©¹«Íø°²±¸11010802024551ºÅ