Ôì´¬³§Beneteau³ÆÆäÔâµ½ÈëÇÖ£¬ÏµÍ³ÈÔÔÚ»Ö¸´ÖУ»SolarWinds¸ß¹Ü³ÆÆäÔâµ½µÄ¹©Ó¦Á´¹¥»÷Ô´ÓÚÈõ¿ÚÁîй¶

Ðû²¼Ê±¼ä 2021-03-03
1.Ôì´¬³§Beneteau³ÆÆäÔâµ½ÈëÇÖ£¬ÏµÍ³ÈÔÔÚ»Ö¸´ÖÐ


1.jpg


·¨¹ú´¬Ö»ÖÆÔìÉÌGroupe Beneteau³ÆÆäÔâµ½ÈëÇÖ£¬ÏµÍ³ÈÔÔÚ»Ö¸´ÖС£¸Ã¹«Ë¾½¨ÉèÓÚ1884Ä꣬×ܲ¿Î»ÓÚ·¨¹úÍúµÂ£¬ÔÚ·¨¹ú¡¢ÃÀ¹ú¡¢²¨À¼¡¢Òâ´óÀûºÍÖйú¾ùÓзֹ«Ë¾¡£ÉÏÖÜ£¬BeneteauÐû²¼ÆäÔâµ½¹¥»÷£¬Îª´ËÆäÒѾ­¶Ï¿ªËùÓÐÐÅϢϵͳµÄÅþÁ¬£¬ÒÔ±ÜÃâ¶ñÒâÈí¼þÈö²¥¡£¸Ã¹«Ë¾ÌåÏÖÆäÊý¸öÉú²ú²¿·ÖµÄÉú²úÔ˶¯±»ÆÈ×èÖ¹£¬ÌØÊâÊÇλÓÚ·¨¹úµÄ²¿·Ö¡£ÏÖÔÚ£¬¸Ã¼¯ÍÅÕýÔÚ¼ÌÐø¾ÙÐÐÊӲ죬ÒÔ½«ÆäITϵͳ»Ö¸´µ½Õý³£ÇÒÇå¾²µÄÔËӪģʽ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/boat-building-giant-beneteau-says-cyberattack-disrupted-production


2.ƱÎñƽ̨TicketcounterµÄ190Íò¸öÓû§µÄÐÅϢй¶


2.jpg


TicketcounterÔâµ½¹¥»÷£¬190Íò¸öÓû§µÄÐÅϢй¶¡£TicketcounterÊǺÉÀ¼µç×ÓÆ±Îñƽ̨£¬Ëü³öÊÛÖîÈ綯ÎïÔ°¡¢¹«Ô°¡¢²©Îï¹ÝºÍÖÖÖÖÔ˶¯µÄÔÚÏßÃÅÆ±¡£2ÔÂ21ÈÕ£¬ºÚ¿ÍÔÚ°µÍø³öÊÛ±»µÁµÄTicketcounterÊý¾Ý¿â£¬ÆäÖаüÀ¨Óû§ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢IPµØµãºÍ¹þÏ£ÃÜÂëµÈÐÅÏ¢¡£Ö®ºó£¬ºÚ¿ÍºÜ¿ìɾ³ýÁË´ËÊý¾Ý¿â£¬²¢ÏòTicketcounterÀÕË÷7¸ö±ÈÌØ±Ò£¨Ô¼ºÏ33.7ÍòÃÀÔª£©¡£Ôڸù«Ë¾¾Ü¾ø¸¶¿îºó£¬ºÚ¿ÍÔÙ´ÎÔÚ°µÍøÉϹûÕæ¸ÃÊý¾Ý¿â¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/european-e-ticketing-platform-ticketcounter-extorted-in-data-breach/


3.ÐÂÄÏÍþ¶ûÊ¿Öݽ»Í¨¾ÖÔâµ½¹¥»÷£¬Êý¾Ý²¢ÔÚClopÍøÕ¾¹ûÕæ


3.jpg


°Ä´óÀûÑÇÐÂÄÏÍþ¶ûÊ¿ÖݵÄÔËÊäϵͳÔâµ½¹¥»÷£¬µ¼ÖÂÊý¾Ýй¶¡£¸ÃÔËÊäϵͳÈÏÕæÐÂÄÏÍþ¶ûÊ¿ÖݵĹ«¹²Æû³µ¡¢¶ÉÂÖ¡¢ÇøÓòº½¿ÕÔËÓªÉ̺ͻõÎïÔËÊä¡£ÐÂÄÏÍþ¶ûÊ¿Öݽ»Í¨¾Ö£¨Transport for NSW£©Åû¶£¬´Ë´ÎÊý¾Ýй¶ԴÓÚÆäÇå¾²Îļþ¹²ÏíϵͳAccellion FTAÔâµ½¹¥»÷¡£ÏÖÔڸûú¹¹ÕýÔÚÊÓ²ì´ËÊÂÎñ£¬ÒÔÈ·¶¨ÊÜÓ°ÏìÊý¾ÝµÄ¹æÄ£¡£±ðµÄ£¬ºÚ¿ÍÒÑÔÚClopÍøÕ¾ÉÏÐû²¼±»µÁÊý¾ÝµÄ½ØÍ¼£¬ÆäÖаüÀ¨ÉñÃØÎļþ¡¢Ö¸µ¼Î¯Ô±»áÎļþºÍÖÖÖÖµç×ÓÓʼþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nsw-transport-agency-extorted-by-ransomware-gang-after-accellion-attack/


4.Sophos·¢Ã÷GootloaderʹÓÃSEO·Ö·¢¶àÖÖ¶ñÒâÈí¼þ


4.jpg


Sophos·¢Ã÷Gootkit½»¸¶Æ½Ì¨GootloaderʹÓÃSEO·Ö·¢¶àÖÖ¶ñÒâÈí¼þ¡£GootloaderÊÇ»ùÓÚJavascriptµÄѬȾ¿ò¼Ü£¬ÔÚ´Ë´ÎË¢ÐÂÖ®ºó¿ÉÒÔ·Ö·¢¸üÆÕ±éµÄ¶ñÒâÈí¼þ£¬°üÀ¨ÀÕË÷Èí¼þ¡£¸Ã¿ò¼ÜʹÓÃÁËËÑË÷ÒýÇæÓÅ»¯£¨SEO£©ÊÖÒÕÀ´¶¾»¯GoogleËÑË÷Ч¹û²¢Èö²¥Ö¸Ïò¶ñÒâÈí¼þµÄÁ´½Ó¡£SophosÔ¤¼Æ£¬Gootloader¿ÉËæÊ±¿ØÖÆÔ¼400̨Ô˶¯·þÎñÆ÷£¬À´ÍйÜÒѱ»ÈëÇÖµÄÕýµ±ÍøÕ¾¡£¸ÃÔ˶¯Ö÷ÒªÕë¶Ôº«¹ú¡¢µÂ¹ú¡¢·¨¹úºÍÕû¸ö±±ÃÀµØÇø¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115144/cyber-crime/gootkit-gootloader-evolution.html    


5.UHSÉù³ÆÈ¥ÄêµÄRyukÀÕË÷¹¥»÷Ôì³É6700ÍòÃÀÔªµÄËðʧ


5.jpg


Universal Health Services£¨UHS£©Éù³ÆÈ¥Äê9ÔµÄRyukÀÕË÷¹¥»÷¸øÆäÔì³ÉÁË6700ÍòÃÀÔªµÄËðʧ¡£UHSµÄ×Ó¹«Ë¾ÆÕ±éÃÀ¹ú38¸öÖÝ£¬ÓµÓÐ26¼Ò¼±ÕïÒ½ÔºÒÔ¼°42¼ÒÃÅÕïÉèÊ©ºÍÃÅÕï·þÎñÖÐÐÄ£¬Òò´ËÍøÂç¹¥»÷µÄÓ°ÏìÉîÔ¶¡£¸Ã¹«Ë¾ÌåÏÖ£¬´ó²¿·ÖÓ°ÏìÓëÆä¼±Õï·þÎñÓйØ£¬ÀýÈçÒò»¼ÕßÔ˶¯ïÔÌ­ÒÔ¼°Ïà¹ØµÄÕʵ¥ÑÓ³Ù¶øµ¼ÖµÄÓªÒµÊÕÈëµÄËðʧ¡£±ðµÄ£¬IT·þÎñÌṩÉÌCognizantºÍÂÁÉú²úÉÌNorsk HydroÈ¥ÄêÒ²Åû¶ÁËÀàËÆµÄÊÂÎñ£¬Ëðʧ»®·Ö¸ß´ï7000ÍòÃÀÔªºÍ4000ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/universal-health-services-lost-67-million-due-to-ryuk-ransomware-attack/


6.SolarWinds¸ß¹Ü³ÆÆäÔâµ½µÄ¹©Ó¦Á´¹¥»÷Ô´ÓÚÈõ¿ÚÁîй¶


6.jpg


Èí¼þ¹«Ë¾SolarWindsµÄÒ»Ãû¸ß¹Ü³ÆÆäÔâµ½¹©Ó¦Á´¹¥»÷µÄ»ù´¡Ôµ¹ÊÔ­ÓÉÊÇÒ»ÃûʵϰÉúʹÓÃÁËÈõÃÜÂë¡£³õ³ÌÐò²éÏÔʾ£¬×Ô2018Äê6ÔÂ17ÈÕÒÔÀ´£¬ÉèÖùýʧµÄGitHub´æ´¢¿âй¶ÁËÃÜÂësolarwinds123£¬¸ÃÎÊÌâÒÑÔÚ2019Äê11ÔÂ22ÈÕ½â¾ö£¬¶ø×î³õµÄ¹¥»÷¿ÉÄܱ¬·¢ÓÚ2019Äê9ÔÂ4ÈÕ¡£¸Ã¹«Ë¾µÄCEOÌåÏÖ£¬Õâ¿ÉÄÜÊÇÒ»ÃûʵϰÉúÓÚ2017ÄêÔÚËûµÄһ̨·þÎñÆ÷ÉÏʹÓõÄÃÜÂ룬²¢Ë½×Ô½«ÃÜÂëÐû²¼µ½ÁËÆäÄÚ²¿Github˽ÈËÕÊ»§ÉÏ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115134/security/solarwinds-intern-solarwinds123-password-leak.html