2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ£»£»£»£» £»vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2019-10-09
1.Ponemon InstituteÐû²¼¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤ÖܶþPonemon InstituteÐû²¼µÄ¡¶2019ÄêÈ«ÇòSMBÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬£¬£¬£¬È«Çò66%µÄÖÐСÐÍÆóÒµ£¨SMB£©ÔÚÒÑÍù12¸öÔÂÄÚ±¨¸æÁËÍøÂç¹¥»÷ÊÂÎñ - ÆäÖÐ76%µÄÆóÒµ×ܲ¿Î»ÓÚÃÀ¹ú¡£¡£¡£¡£ ¡£PonemonÌåÏÖÕâÊÇÒ»Á¬µÚÈýÄêSMB±¨¸æµÄÍøÂçÇå¾²ÊÂÎñ·ºÆð¡°ÏÔÖøÔöÌí¡±¡£¡£¡£¡£ ¡£Ä¿½ñSMBÃæÁÙµÄ×î³£¼ûÍøÂç¹¥»÷ÐÎʽÊÇÍøÂç´¹ÂÚ¡¢×°±¸ÈëÇÖ»ò±»µÁ¡¢Æ¾Ö¤ÇÔÈ¡¡£¡£¡£¡£ ¡£Ëæ×Å×Ô´ø×°±¸°ì¹«£¨BYOD£©Ä£Ê½µÄÊ¢ÐУ¬£¬£¬£¬£¬£¬×°±¸µÄ±»µÁÓÈÆä³ÉΪһ¸öÎÊÌâ¡£¡£¡£¡£ ¡£ÔÚÒÑÍù12¸öÔÂÖУ¬£¬£¬£¬£¬£¬¹²ÓÐ63%µÄÆóÒµ±¨¸æÁËÃô¸Ð¹«Ë¾Êý¾Ý»ò¿Í»§ÐÅϢɥʧÊÂÎñ£¬£¬£¬£¬£¬£¬¶øÔÚÃÀ¹úÕâÒ»±ÈÀýÉÏÉýÖÁ69%£¬£¬£¬£¬£¬£¬ÏÔÖø¸ßÓÚËÄÄêǰµÄ50%¡£¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/76-percent-of-us-businesses-have-experienced-a-cyberattack-in-the-past-year/

2.ÐÂÎ÷À¼T¨±Ora CompassÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬½ü100Íò»¼ÕßÐÅϢй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



T¨±Ora Compass HealthÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬µ¼Ö½ü100Íò»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£ ¡£¸Ã³õ¼¶ÎÀÉú×éÖ¯£¨PHO£©ÌåÏÖÆä¹ÙÍøÔÚ8Ô·ݱ¬·¢µÄÒ»ÆðÍøÂçÊÂÎñÖÐÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬Òò´Ë¶ÔCompass HealthµÄÕûÌåITϵͳºÍÇ徲״̬¾ÙÐÐÁËÊӲ죬£¬£¬£¬£¬£¬×îÖÕ·¢Ã÷´Ó2016Äêµ½2019Äê3Ô±¬·¢µÄÍøÂç¹¥»÷¡£¡£¡£¡£ ¡£Compass HealthÌåÏÖÈκÎÔÚ2016ÄêÖÁ2019Äêʱ´úÔÚÒ½ÁÆÖÐÐÄ×¢²áµÄÓû§¶¼¿ÉÄÜÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬ÕâÒ»Êý×Ö¿É´ï100ÍòÈË¡£¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄµØÇøÖ÷ҪΪÐÂÎ÷À¼»ÝÁé¶Ù£¬£¬£¬£¬£¬£¬»³À­À­ÅÁºÍÂíÄÉÍßͼ¡£¡£¡£¡£ ¡£¿ £¿£¿£¿£¿£¿ÉÄÜÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨Óû§µÄ¹ú¼ÒÒ½ÁƱàºÅ¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢µØµãÒÔ¼°ÔÚÄĸöÒ½ÁÆÖÐÐľÙÐÐ×¢²á¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tu-ora-data-breach-exposes-medical-data-of-one-million-new-zealand-residents/

3.¼ÓÄôóTransUnionÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬¿Í»§ÐÅÓÃÐÅϢй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¼ÓÄôóTransUnion´ÓÉÏÖÜ×îÏÈÏòÓû§·¢ËÍÊý¾ÝÇå¾²ÊÂÎñ֪ͨ£¬£¬£¬£¬£¬£¬ÌåÏÖÓû§µÄÐÅÏ¢Ô⵽δÊÚȨ»á¼û¡£¡£¡£¡£ ¡£¸Ãָ֪ͨ³ö£¬£¬£¬£¬£¬£¬2019Äê6ÔÂ28ÈÕÖÁ7ÔÂ11ÈÕʱ´úδ¾­ÊÚȨµÄ¹¥»÷ÕßʹÓñ»µÁµÄÓû§ÕË»§Æ¾Ö¤»á¼ûÆäÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐÁËÐÅÓñ¨¸æ²éÕÒ¡£¡£¡£¡£ ¡£¿ £¿£¿£¿£¿£¿ÉÄܲéÕÒµ½µÄÐÅÓÃÎļþÖаüÀ¨Óû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñ¼°ÒÑÍùµÄµØµãÒÔ¼°Õ÷ÐÅÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈç´û¿î¡¢Ç·¿îºÍÖ§¸¶ÀúÊ·µÈ£¬£¬£¬£¬£¬£¬µ«²»°üÀ¨ÏÖʵµÄÕË»§ºÅÂë¡£¡£¡£¡£ ¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÐÅÏ¢À´ÊµÑéÉí·Ý͵ÇÔ£¬£¬£¬£¬£¬£¬Òò´ËTransUnionÏòÊÜÓ°ÏìµÄÓû§ÌṩÁËÁ½ÄêµÄÐÅÓÃڲƭ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-info-exposed-in-transunion-data-security-incident/

4.ÃÀ¹ú°¢À­°ÍÂíÖÝDCHÒ½ÔºÏòRyuk¹¥»÷ÕßÖ§¸¶Êê½ð


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú°¢À­°ÍÂíÖݵÄDCHÒ½ÔºÒѾöÒéÏòÀÕË÷Èí¼þRyukµÄ¹¥»÷ÕßÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡½âÃÜÃÜÔ¿²¢»Ö¸´ÆäϵͳµÄÕý³£ÔËÓª¡£¡£¡£¡£ ¡£10ÔÂ1ÈÕDCHµÄÒ½ÁÆÏµÍ³£¨°üÀ¨DCHÇøÓòÒ½ÁÆÖÐÐÄ¡¢NorthportÒ½ÁÆÖÐÐÄ¡¢Î÷°¢À­°ÍÂíÖݵÄFayetteÒ½ÁÆÖÐÐÄ£©Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬£¬ÆÈʹËûÃǹرÕÁËÅÌËã»úϵͳ²¢×èÖ¹ÎüÊÕÐµĻ¼Õß¡£¡£¡£¡£ ¡£ÉÏÖÜÄ©DCHÐû²¼¸üÐÂÉùÃ÷³ÆËûÃÇÖ§¸¶ÁËÊê½ð²¢ÕýÔÚ»Ö¸´Æäϵͳ£¬£¬£¬£¬£¬£¬DCH²¢Î´Í¸Â¶Êê½ðµÄÏêϸÊý¶î£¬£¬£¬£¬£¬£¬µ«ÒÑÈ·È϶à¸öЧÀÍÆ÷±»ÀֳɽâÃÜ¡£¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎúDCHµÄϵͳ½«ÓÚºÎʱÍêÈ«ÉÏÏß¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dch-hospital-pays-ryuk-ransomware-for-decryption-key/

5.vBulletinÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÐÂRCEºÍSQL×¢ÈëÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÔÚÉϸöÔÂÄ©ÐÞ¸´RCE 0dayºó£¬£¬£¬£¬£¬£¬vBulletinÐû²¼ÁËÒ»¸öеÄÇå¾²²¹¶¡£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÂÛ̳Èí¼þÖеÄ3¸ö¸ßΣÎó²î¡£¡£¡£¡£ ¡£µÚÒ»¸öÎó²îÊÇRCEÎó²î£¨CVE-2019-17132£©£¬£¬£¬£¬£¬£¬±£´æÓÚvBulletin´¦Öóͷ£Óû§¸üÐÂÆäСÎÒ˽¼Ò×ÊÁϵÄÇëÇóÀú³ÌÖУ¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃδ¾­ÓÉÂ˵IJÎÊýÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×¢Èë²¢Ö´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£¡£¡£¡£ ¡£ÁíÍâÁ½¸öÎó²îÊÇSQL×¢ÈëÎÊÌ⣬£¬£¬£¬£¬£¬ËüÃDZ»·ÖÅÉΪͳһ¸öCVE ID£¨CVE-2019-17271£©£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¾ßÓÐÊÜÏÞÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£ ¡£ÕâЩÎó²îÓ°ÏìÁËvBulletin 5.5.4¼°Ö®Ç°µÄ°æ±¾£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/vBulletin-hacking-exploit.html

6.΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´59¸öÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÔÚÖܶþÐû²¼µÄWindows 10ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË59¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Çå¾²³§ÉÌPreemptÅû¶µÄÁ½¸öNTLMÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE 2019-1166ºÍCVE-2019-1338£©¡¢VBScriptÒýÇæÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1238ºÍCVE-2019-1239£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâOfficeÎĵµ»ò¶ñÒâÍøÕ¾´¥·¢£©¡¢Ô¶³Ì×ÀÃæ¿Í»§¶ËÖеÄRCEÎó²î£¨CVE-2019-1333£¬£¬£¬£¬£¬£¬ÔÊÐí¶ñÒâЧÀÍÆ÷ÔÚ¿Í»§¶Ëͨ¹ýRDPÅþÁ¬Ê±ÔÚ¿Í»§¶ËÉÏÖ´ÐÐÏÂÁµÈ¡£¡£¡£¡£ ¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-october-2019-patch-tuesday-fixes-59-vulnerabilities/