EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢
Ðû²¼Ê±¼ä 2024-11-261. EverestÀÕË÷Èí¼þÍŶÓй¶PPMG»¼ÕßÃô¸ÐÐÅÏ¢
11ÔÂ23ÈÕ£¬¼ÓÀû¸£ÄáÑÇÖݵÄ̫ƽÑó·Î²¿Ò½ÁƼ¯ÍÅ(PPMG)ÔâÓöÁËÑÏÖصÄÊý¾Ýй¶ÊÂÎñ¡£10ÔÂ25ÈÕ£¬EverestÀÕË÷Èí¼þÍŶÓÔÚ°µÍøÉÏÐû²¼ÁËPPMGµÄ»¼ÕßÐÅÏ¢£¬°üÀ¨2021ÖÁ2024ÄêµÄδ¼ÓÃÜСÎÒ˽¼ÒºÍÊܱ£»¤¿µ½¡ÐÅÏ¢¡£Ð¹Â¶µÄÊý¾ÝÒÔ150¶à¸öͼÏñÎļþºÍ¶à¸ö.csvÎļþµÄÐÎʽ±£´æ£¬Í¼ÏñÎļþÖ÷Ҫչʾ»¼ÕßµÄÖ÷´Î°ü¹Ü¿¨¼°²¿·Ö¼ÝÕÕÐÅÏ¢£¬¶ø.csvÎļþÔòº¸ÇÁËÁ½ÖÜÄڵĻ¼Õß¾ÍÕï¼Í¼£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØµã¡¢¿µ½¡ÐÅÏ¢¼°Õ˵¥ÏêÇéµÈÃô¸ÐÄÚÈÝ¡£×îÐÂÒ»ÅúÊý¾Ý×èÖ¹10ÔÂ4ÈÕ£¬Ã¿Á½ÖܵÄ.csvÎļþ¼Í¼×Å300µ½500Ãû»¼ÕߵľÍÕïÇéÐΡ£È»¶ø£¬Ö±ÖÁÐÅÏ¢Ðû²¼Ê±£¬PPMGÍøÕ¾¼°ÃÀ¹úÎÀÉúÓ빫¹²·þÎñ²¿(HHS)µÄ¹«¹²Î¥¹æ¹¤¾ßÉϾùδÐû²¼Ïà¹Ø֪ͨ¡£DataBreachesÒÑÏòPPMGºÍEverest·¢ËÍѯÎÊ£¬µ«ÉÐδÊÕµ½»Ø¸´¡£
https://databreaches.net/2024/11/23/pacific-pulmonary-medical-group-patient-information-dumped-by-everest-ransomware-team/
2. Áè¼Ý2000̨Palo Alto Networks×°±¸ÔâºÚ¿ÍÈëÇÖ
11ÔÂ21ÈÕ£¬Palo Alto Networks ±¨¸æ³ÆÆä¶à´ï2000̨װ±¸¿ÉÄÜÒÑÔ⵽ʹÓÃÐÂÅû¶Çå¾²Îó²îµÄ¹¥»÷¡£¾ÝShadowserver»ù½ð»áͳ¼Æ£¬ÃÀ¹ú£¨554Àý£©ºÍÓ¡¶È£¨461Àý£©µÄѬȾ²¡Àý×î¶à£¬ÆäËûÊÜÓ°Ïì¹ú¼Ò°üÀ¨Ì©¹ú¡¢Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÍÁ¶úÆä¡¢Ó¢¹ú¡¢ÃسºÍÄÏ·Ç¡£CensysÔò·¢Ã÷13,324¸ö¹ûÕæ̻¶µÄÏÂÒ»´ú·À»ðǽ£¨NGFW£©ÖÎÀí½Ó¿Ú£¬ÆäÖÐ34%λÓÚÃÀ¹ú£¬µ«²¢·ÇËùÓÐ̻¶µÄÖ÷»ú¶¼±£´æÎó²î¡£Éæ¼°µÄÇå¾²Îó²î°üÀ¨CVE-2024-0012£¨CVSS·ÖÊý9.3£©ºÍCVE-2024-9474£¨CVSS·ÖÊý6.9£©£¬ËüÃÇ¿ÉÄܵ¼ÖÂÉí·ÝÑéÖ¤ÈƹýºÍȨÏÞÌáÉý£¬Ê¹¹¥»÷ÕßÄÜÖ´ÐжñÒâ²Ù×÷¡£Palo Alto NetworksÕý×·×Ù´úºÅΪOperation Lunar PeekµÄÎó²îʹÓÃÇéÐΣ¬²¢ÖÒÑÔ³ÆÕâЩÎó²îÒѱ»ÎäÆ÷»¯£¬¿ÉÄÜÒý·¢¸üÆÕ±éµÄÍþвÔ˶¯¡£¸Ã¹«Ë¾ÒÑÊӲ쵽ÊÖ¶¯ºÍ×Ô¶¯É¨ÃèÔ˶¯£¬²¢±Þ²ßÓû§¾¡¿ìÓ¦ÓÃÐÞ¸´³ÌÐò£¬ÏÞÖÆÖÎÀí½çÃæ»á¼û£¬ÒÔ±ÜÃâÍⲿ»á¼û¡£
https://thehackernews.com/2024/11/warning-over-2000-palo-alto-networks.html
3. Blue YonderÔâÀÕË÷Èí¼þ¹¥»÷£¬¹©Ó¦Á´·þÎñÖÐÖ¹Ó°ÏìÆÕ±é
11ÔÂ25ÈÕ£¬¹©Ó¦Á´ÖÎÀí¹«Ë¾Blue Yonder£¨ÔΪJDA Software£©£¬×÷ΪËÉϵÄ×Ó¹«Ë¾£¬ÄêÊÕÈ볬10ÒÚÃÀÔª£¬ÓµÓÐ6000ÃûÔ±¹¤£¬Îª°üÀ¨DHL¡¢À×ŵ¡¢È¸³²¡¢ÌØÒ×¹º¡¢ÐǰͿ˵È×ÅÃûÆóÒµÔÚÄÚµÄ3000Ãû¿Í»§ÌṩÈ˹¤ÖÇÄÜÇý¶¯µÄ¹©Ó¦Á´½â¾ö¼Æ»®¡£È»¶ø£¬¸Ã¹«Ë¾½üÆÚÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÍйܷþÎñÍйÜÇéÐηºÆðÖÐÖ¹£¬Ó°ÏìÁËÆä¿Í»§£¬ÌØÊâÊÇÓ¢¹úµÄÔÓ»õµêÁ¬Ëøµê¡£Blue YonderÒÑÓëÍⲿÍøÂçÇå¾²¹«Ë¾ÏàÖúÓ¦¶Ô´ËÊÂÎñ£¬²¢ÊµÑéÁ˶àÏî·ÀÓùºÍÈ¡Ö¤ÐÒ飬µ«ÔÚÆ乫¹²ÔÆÇéÐÎÖÐδ¼ì²âµ½¿ÉÒÉÔ˶¯¡£ÏÖÔÚ£¬Blue YonderÈÔÔÚ´¦Öóͷ£¶àÖÖ»Ö¸´Õ½ÂÔ£¬µ«ÉÐδ͸¶ÖÜÈ«»Ö¸´µÄÏêϸʱ¼ä±í¡£ÊÜÓ°ÏìµÄ¿Í»§£¬ÈçMorrisonsºÍSainsbury£¬ÒѽÓÄÉÓ¦¼±²½·¥À´Õ½Ê¤ÕâÒ»ÖÐÖ¹¡£×èÖ¹×îÐÂÐÂÎÅ£¬Blue YonderÉÐδÐû²¼ÓйØÇéÐεÄ×îÐÂÏ£Íû£¬ÍƲâÆäÍйܷþÎñÇéÐÎÈÔÈ»Êܵ½Ó°Ïì¡£ÏÖÔÚ£¬ÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÐû²¼¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/blue-yonder-ransomware-attack-disrupts-grocery-store-supply-chain/
4. MetaÖØȹ¥»÷ɱÖíÕ©Æ£¬¹Ø±Õ200ÍòÚ²ÆÕË»§
11ÔÂ24ÈÕ£¬×Ô½ñÄêÄêÍ·ÒÔÀ´£¬MetaÒѹرÕÆäƽ̨ÉÏ200Íò¸öÓëɱÖíթƺÍÆäËûÚ²ÆÐÐΪÏà¹ØµÄÕË»§£¬ÕâЩÕË»§Ö÷ÒªÀ´×ÔÃåµé¡¢ÀÏÎΡ¢°¢ÁªÇõ¡¢·ÆÂɱöºÍ¼íÆÒÕ¯µÈÒÔ¡°Õ©ÆÆÍ´Ó¡±Ô˶¯ÖøÃûµÄ¹ú¼Ò¡£ÕâЩթÆÖÐÐÄͨ¹ýÐû²¼ÐéαÕÐƸÐÅÏ¢ÒýÓÕÇóÖ°Õߣ¬Ç¿ÆÈËûÃÇ´ÓÊÂÍøÂçÕ©Æ£¬²¢ÒÔÈËÉíݱ¶¾×÷ΪÍþв¡£MetaÓëÕâЩ¹ú¼ÒµÄÖ´·¨»ú¹¹ÏàÖú£¬·ÖÏíÇ鱨£¬¹¥»÷Õ©ÆÐÐΪ¡£ÆäÖУ¬¡°É±Öí¡±Õ©ÆÊÇÒ»ÖÖÆÆËðÐԵĽðÈÚͶ×ÊȦÌ×£¬ÒÀÀµÓÚºã¾ÃʹÓú͸߼¶ÓÕÆ£¬Ä¿µÄÓû§±é²¼È«Çò¡£ËäÈ»¿´ËÆÏÝÈëȦÌ×µÄÈËÊýδ¼¸£¬µ«ÒѳÉΪÕâЩÓÐ×éÖ¯·¸·¨¼¯Íŵľ޶îÊÕÈëȪԴ¡£Meta½ÓÄÉÁËһϵÁв½·¥£¬°üÀ¨Ö´ÐÐΣÏÕ×éÖ¯ºÍСÎÒ˽¼ÒÕþ²ß¡¢Ê¹ÓÃÐÐΪºÍÊÖÒÕÐźÅʶ±ðºÍ×èÖ¹Õ©ÆÏà¹ØÕË»§ºÍ»ù´¡ÉèÊ©¡¢ÓëÈ«ÇòÖ´·¨²¿·ÖÏàÖú¡¢Óë¿Æ¼¼¹«Ë¾ºÍ×éÖ¯ÏàÖú¡¢ÌṩÓû§±£»¤¹¦Ð§ºÍ½¨ÒéµÈ£¬ÒÔ¼ì²âºÍ×èÖ¹ÕâЩȦÌ×£¬±£»¤Óû§ÃâÊÜڲơ£MetaÌáÐÑÓû§ÉóÉ÷¿´´ýδ¾ÇëÇóµÄͨѶ£¬×èÖ¹ÔÚÉ罻ýÌåºÍͨѶƽ̨ÉÏÆò´û»ò¼ÓÈë¿ÉÒÉͶ×ÊÍýÏë¡£
https://www.bleepingcomputer.com/news/security/meta-removes-over-2-million-accounts-pushing-pig-butchering-scams/
5. Ì©¹ú¾¯·½ÆÆ»ñ´ó¹æÄ£¶ÌÐÅ´¹ÂÚÕ©Æ°¸£¬¾Ð²¶»õ³µË¾»ú
11ÔÂ24ÈÕ£¬Ì©¹ú¾¯·½ÀÖ³ÉÆÆ»ñÒ»Æð´ó¹æÄ£¶ÌÐÅÕ©Æ°¸£¬¾Ð²¶ÁË»õ³µË¾»ú¡£¸Ã»õ³µ×°±¸Á˶ÌÐÅ·¢ÉäÆ÷£¬Äܹ»ÔÚ3¹«Àï¹æÄ£ÄÚÿСʱ·¢ËÍ10ÍòÌõ´¹ÂÚ¶ÌÐÅ¡£Õ©Æ¶ÌÐÅÉù³ÆÓû§µÄ»ý·Ö¼´½«ÓâÆÚ£¬ÒýÓÕËûÃǵã»÷°üÀ¨¡°aisthailand¡±×Ö·û´®µÄ´¹ÂÚÍøÕ¾Á´½Ó£¬¸ÃÁ´½Óαװ³ÉÌ©¹ú×î´óÒƶ¯µç»°ÔËÓªÉÌAISµÄ¹Ù·½ÍøÕ¾¡£Óû§Ò»µ©µã»÷Á´½Ó²¢ÊäÈëÐÅÓÿ¨ÐÅÏ¢£¬ÕâЩÐÅÏ¢¾Í»á±»·¢»Ø¸øÕ©ÆÍŻÓÃÓÚÔÚÆäËû¹ú¼Ò¾ÙÐÐδ¾ÊÚȨµÄÉúÒâ¡£¾ÝϤ£¬¸ÃÕ©ÆÍŻﲿ·Ö³ÉÔ±ÔÚÌ©¹ú£¬²¿·ÖÔÚÍâÑó£¬Í¨¹ý˽ÈËTelegramƵµÀе÷Ðж¯¡£ÔÚÈýÌìÄÚ£¬¸ÃÍÅ»ïÏòÂü¹ÈסÃñ·¢ËÍÁ˽üÒ»°ÙÍòÌõթƶÌÐÅ¡£¾¯ÆÓÖ±ÔÚ×·²¶ÖÁÉÙÁíÍâÁ½ÃûÍÅ»ï³ÉÔ±£¬²¢»ñµÃÁËAISµÄÐÖú¶¨Î»¶ÌÐÅ·¢ÉäÆ÷¡£Ö»¹ÜÍøÂç´¹ÂÚÐÅÏ¢µÄÀÖ³ÉÂÊÒò¹«ÖÚÒâʶÌá¸ß¶ø½µµÍ£¬µ«ÔÚÉú³Ý÷缯µØÇøÒÔ¸ßËÙÈö²¥Ê±£¬ÈÔÄÜΪ·¸·¨Õß´øÀ´¿É¹ÛÊÕÒæ¡£
https://www.bleepingcomputer.com/news/security/bangkok-busts-sms-blaster-sending-1-million-scam-texts-from-a-van/
6. ΢Èí¶àÏî½¹µã·þÎñÔâÓöÈ«ÇòÐÔ´ó¹æÄ£ÖÐÖ¹
11ÔÂ25ÈÕ£¬Î¢ÈíµÄ¶àÏî½¹µã·þÎñ£¬°üÀ¨Microsoft 365¡¢Exchange Online¡¢TeamsºÍOutlook£¬ÔâÓöÁËÈ«ÇòÐԵĴó¹æÄ£ÖÐÖ¹£¬µ¼ÖÂÓû§ÔÚÉ罻ýÌåÉÏ·×·×±¨¸æÎÞ·¨·¢ËÍÓʼþ¡¢ÍøÕ¾Í߽⼰¹ýʧҳÃæµÈÎÊÌâ¡£ÔÚÁùСʱÄÚ£¬DowndetectorÒÑÊÕµ½Êýǧ·ÝÓû§±¨¸æ£¬ÊÜÓ°ÏìµÄÓû§»¹ÌåÏÖÔÚÅþÁ¬OneDrive¡¢Purview¡¢CopilotµÈ·þÎñʱҲÓöµ½ÁËÕÏ°¡£Î¢ÈíËæºóÈÏ¿ÉÎÊÌâ±£´æ£¬²¢ÔÚƽ̨ÉÏÐû²¼ÉùÃ÷³ÆÕýÔڻعöÏà¹Ø±ä»»²¢Ñ°ÕÒÆäËû»º½â²½·¥£¬Í¬Ê±ÁгöÁËÊÜÓ°ÏìµÄ·þÎñºÍʹÓó¡¾°¡£¹ÊÕÏÒ»Á¬11¸öСʱºó£¬Î¢ÈíÑ¡ÔñÊÖ¶¯ÖØÆô·þÎñÆ÷£¬²¢ÔÚÖÎÀíÖÐÐĵÄÊÂÎñ±¨¸æÖÐÈ·ÈϸÃÖÐÖ¹×èÖ¹ÁË¿Í»§Í¨¹ý¶àÖÖ·½·¨»á¼ûExchange Online¡£Í¬Ê±£¬Ò»Ð©¿Í»§ÔÚʹÓÃMicrosoft Fabric¡¢Microsoft BookingsºÍMicrosoft Defender for Office 365µÈ·þÎñʱҲÓöµ½ÁËÎÊÌ⡣΢ÈíÌåÏÖÒÑ×îÏÈ°²ÅÅÐÞ¸´³ÌÐò£¬²¢ÊÖ¶¯ÖØÆô²¿·Ö²»¿µ½¡µÄ»úе£¬µ«Ö±µ½25ÈÕ12µã33·Ö£¨EST£©£¬°²ÅŵÄÐÞ¸´³ÌÐòÉÐδµ¼ÖÂÍêÈ«µÄ·þÎñ»Ö¸´¡£18µã25·Ö£¨EST£©£¬Î¢Èí½øÒ»²½·ÖÏíÁËÊÂÎñÐÅÏ¢£¬³ÆʹÊÊÇÓÉÒ»¸öµ¼Ö·þÎñÆ÷·ÓÉÖØÊÔÇëÇó¼¤ÔöµÄ¸ü¸ÄÒýÆðµÄ£¬ÍŶÓÕýÔÚÆð¾¢Ö´ÐкóÐøÐж¯£¬²¢Æð¾¢»Ö¸´ËùÓй¦Ð§¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-impacts-exchange-online-teams-sharepoint/