Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª£»ÃÀ¹úCVS HealthÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý10Òڱʼͼ
°ä²¼¹¦·ò 2021-06-171.Ò˼ҷ¨¹ú¹«Ë¾ÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª

Èðµä¼Ò¾ß¼¯ÍÅÒ˼ҷ¨¹ú·Ö¹«Ë¾ÒòʹÓüäµýÈí¼þ·¸·¨¼à¿ØÔ±¹¤±»·£¿î120ÍòÃÀÔª¡£¸ÃÊÂÎñ²úÉúÔÚ2009ÄêÖÁ2012Äê¼ä£¬Ò˼ҷ¨¹ú¹«Ë¾¿ª·¢ÁËÒ»¸ö¼äµýϵͳÀ´¼à¿ØÔ±¹¤ºÍÌá³ö¾À·×µÄ¿Í»§¡£¸ÃϵͳΪ¹«Ë¾1996ÄêÖÁ2002ÄêµÄÕÆ¹ÜÈËJean-Louis Baillot³ÉÁ¢µÄ£¬Æä±»´¦ÒÔÁ½Ä껺Ð̺Í60630ÃÀÔª·£¿î¡£¼ì²ì¹Ù°µÊ¾£¬Ò˼ҷ¨¹ú¹«Ë¾ÀûÓþ¯·½ÐÂÎÅÆðÔ´£¬ÀñƸÁËÒ»¼Ò¸öÈ˱£°²¹«Ë¾ºÍ¸öÈËÕì̽·¸·¨»ñÈ¡ÆäÔ±¹¤µÄ»úÃÜÐÅÏ¢¡£¸ÃÐÌʵ÷²éÓÚ2012ÄêÆô¶¯£¬Ö±µ½±¾Öܶþ²ÅºÅÁî·£¿î¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/ikea-fined-12m-for-spying-on/
2.ÃÀ¹úCVS HealthÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý10Òڱʼͼ

×êÑÐÍŶÓÓÚ2021Äê3ÔÂ21ÈÕ·¢ÏÖÁËÒ»¸ö²»ÊÜÃÜÂë±£»¤µÄÊý¾Ý¿â¡£¾¹ý½øÒ»²½×êÑУ¬¸ÃÊý¾Ý¿âÓëÃÀ¹úÒ½ÁƱ£½¡¹«Ë¾CVS HealthÓйء£Êý¾Ý¿â´óÓ×Ϊ204GB£¬×ܼÆÓÐ1148327940±Ê¼Í¼£¬Ô̺¬·Ã¿ÍID¡¢»á»°ID¡¢É豸ÐÅÏ¢ºÍÈÕ־ϵͳÈôºÎ´Óºó¶ËÔËÐеÄÀ¶Í¼µÈÄÚÈÝ£¬ÒÔ¼°ÓйØÒ©Îï¡¢COVID-19ÒßÃçºÍCVS¸÷Àà²úÆ·µÄÐÅÏ¢¡£CVS Health°µÊ¾£¬¸ÃÊý¾Ý¿âÓÉÒ»¸öµÚÈý·½¹©¸øÉÌÔÚÖÎÀí£¬´Ë¿ÌÒѾ±»±£»¤ÆðÀ´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/billions-of-records-belonging-to-cvs-health-exposed-online/
3.ÃÀ¹ú±ûÍ鹩¸øÉÌAmeriGas×Ô¶¯Åû¶Æä½üÆÚµÄÊý¾Ýй¶ÊÂÎñ

ÃÀ¹ú×î´óµÄ±ûÍ鹩¸øÉÌAmeriGas×Ô¶¯Åû¶Æä½üÆÚ²úÉúµÄÊý¾Ýй¶ÊÂÎñ¡£AmeriGasÔÚÃÀ¹úµÄ50¸öÖÝΪ³¬¹ý200Íò¿Í»§Ìṩ·þÎñ£¬Õ¼ÓÐ2500¶à¸ö·ÖÏúµã¡£5ÔÂ10ÈÕ£¬ÏòAmeriGasÌṩÔËÊ䲿 (DOT) ºÏ¹æ·þÎñµÄ¹©¸øÉÌJJ KellerÔÚÆäϵͳÉϼì²âµ½¿ÉÒɻ£¬ºó·¢ÏÔìäÔ±¹¤Ôâµ½ÁË´¹µö¹¥»÷µ¼ÖÂÕÊ»§±»µÁ£¬¸Ã¹«Ë¾ÂíÉÏÆðÍ·È·¶¨Õâ´Îй¶µÄÁìÓò¡£5ÔÂ21ÈÕ£¬JJ Keller֪ͨAmeriGas´ËÊÂÎñ¿ÉÄÜй¶ÁËAmeriGasµÄ123ÃûÔ±¹¤µÄ¼Í¼£¬Ô̺¬³¢ÊÔÊÒID¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂëºÍµ®ÉúÈÕÆÚ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/
4.ThroughTek P2P SDKÃ÷ÎÄй¶£¬Ó°ÏìÊý°ÙÍòÉãÏñÍ·

CISAÅû¶ÁËThroughTekµÄP2P SDKÖеÄÃ÷ÎÄй¶·ì϶£¬Ó°ÏìÁËÊý°ÙÍò¸öÉãÏñÍ·¡£¸Ã·ì϶׷×ÙΪCVE-2021-32934£¬CVSS v3¸ù»ùÆÀ·ÖΪ9.1¡£¸Ã×é¼þÒѱ»¶à¼Ò°²È«ÉãÏñÍ·µÄÔʼÉ豸Ôì×÷ÉÌ (OEM) ÒÔ¼°ÎïÁªÍøÉ豸Ôì×÷ÉÌʹÓã¬Òѱ»×°ÖÃÔÚÊý°ÙÍò¸öÉ豸ÖУ¬ÀýÈçÓ¤¶ùºÍ³èÎï¼à¿ØÉãÏñÍ·¡¢»úеÈËºÍµç³ØÉ豸µÈ¡£CISA°µÊ¾£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÃô¸ÐÐÅÏ¢£¬ÈçÏà»úÒôƵ/ÊÓÆµÔ´µÈ£¬½ØÖÁ´Ë¿Ì»¹Ã»±»ÔÚÒ°ÀûÓá£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ics/advisories/icsa-21-166-01
5.ÒÔÉ«Áйú·À¾üǰÕÕ·÷³¤µÄÍÆËã»úÔâµ½ÒÁÀʺڿ͵ÄÈëÇÖ

±¾Öܶþ£¬ÒÔÉ«ÁÐʱ±¨³ÆÒÁÀʺڿ͹¥»÷ÁËÒÔÉ«Áйú·À¾üµÄǰÕÕ·÷³¤µÄÍÆËã»ú£¬²¢»ñµÃÁËËûµÄÕû¸öÍÆËã»úÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ¡£Channel 10°µÊ¾¸ÃºÚ¿ÍÊÇYaser Balaghi£¬¾Ý³ÆËûÔÚºóÀ´´µÅ£×Ô¼ºµÄÐÐΪʱ²»Öª²»¾õµØÁôÏÂÁ˺ۼ££¬µ¼ÖÂÒÁÀÊÖÕ³¡ÁËÕë¶ÔÈ«Çò1800ÈË£¨Ô̺¬ÒÔÉ«Áн¾ü½«¾ü¡¢²¨Ë¹ÍåÈËȨ±£ÎÀÕߺÍѧÕߣ©µÄÍøÂçÐж¯¡£ÔÚ´ÓǰµÄÁ½ÄêÖУ¬ÒÔÉ«ÁÐÒ»ÏòÊǺܶàÍøÂç¹¥»÷µÄÖ¸±ê¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/iran-said-to-hack-former-israeli-army-chief-of-staff-access-his-entire-computer-533222.shtml
6.Cybereason°ä²¼ÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄ·ÖÎö»ã±¨

Cybereason°ä²¼ÁËÆóÒµÔâµ½ÀÕË÷¹¥»÷µÄËðʧµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¾ùÔÈÿ11Ãë¾Í»á²úÉúÒ»´ÎÀÕË÷Èí¼þ¹¥»÷£¬Ô¤¼Æ2021Äê×éÖ¯µÄËðʧ½«´ïµ½200ÒÚÃÀÔª£¬±È2020ÄêÔö³¤225%¡£66%µÄ×éÖ¯»ã±¨³ÆÔÚÀÕË÷Èí¼þ¹¥»÷ºóÊÕÈë³öÏÖËðʧ£»35%ÆóÒµÖ§¸¶ÁË35ÍòÖÁ140ÍòÃÀÔªÊê½ð£¬7%µÄÆóÒµÖ§¸¶µÄÊê½ð³¬¹ý140ÍòÃÀÔª£»53%×éÖ¯³ÆÆäÆ·ÅÆºÍÃûÓþÊÜËð£¬32%×éÖ¯³ÆC¼¶È˲ÅÁ÷ʧ£»26%×éÖ¯»ã±¨³Æ¹¥»÷µ¼ÖÂÆóÒµÔÚÒ»¶Î¹¦·òÄÚÆëÈ«¹Ø¹Ø¡£
ÔÎÄÁ´½Ó£º
https://www.cybereason.com/blog/report-ransomware-attacks-and-the-true-cost-to-business


¾©¹«Íø°²±¸11010802024551ºÅ