EquifaxΪ2017ÄêÊý¾Ýй¶֧¸¶14ÒÚÃÀÔª£»£»£»£»Õë¶ÔÃÀ¹ú¶¼»áµÄÀÕË÷¹¥»÷ÊÂÎñ¼¤Ôö£»£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë
Ðû²¼Ê±¼ä 2019-05-13
ƾ֤Recorded FutureµÄͳ¼ÆÊý¾Ý£¬£¬£¬Õë¶ÔÃÀ¹úÍâµØÕþ¸®¡¢¶¼»áϵͳ¡¢¾¯¾ÖºÍѧУµÄÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷ÕýÔÚáÈÆð£¬£¬£¬×Ô2013ÄêÒÔÀ´ÖÁÉÙÒÑÓÐ170¸öÏØ¡¢ÊлòÖÝÕþ¸®Êܵ½¹¥»÷¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬2019ÄêÒѱ¬·¢ÁË22Æð´ËÀ๥»÷ÊÂÎñ£¬£¬£¬2016ÄêµÄÊý×ÖΪ46Æð£¬£¬£¬2017ÄêΪ38Æð£¬£¬£¬2018ÄêΪ53Æð¡£¡£¡£ÕâÀ๥»÷ÊÂÎñÍùÍù»á¶ÔÍâµØ¶¼»áÔì³ÉÊý°ÙÍòÃÀÔªµÄËðʧ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://edition.cnn.com/2019/05/10/politics/ransomware-attacks-us-cities/index.html
×Ô3Ô·ÝÒÔÀ´£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/
3¡¢Fin7 APTÖ÷Òª³ÉÔ±±»²¶ºó£¬£¬£¬2018ÄêÒÑÓÐԼĪ130¸ö¹«Ë¾³ÉΪĿµÄ
ƾ֤¿¨°Í˹»ùµÄÒ»·Ýб¨¸æ£¬£¬£¬Ö»¹ÜFin7 APTµÄÏòµ¼ÈËÔÚ18Äê8Ô·ݱ»¾Ð²¶£¬£¬£¬µ«¸ÃÍÅ»ïÈÔ´¦ÓÚ»îԾ״̬¡£¡£¡£×èÖ¹2018Äêµ×ÒÑÓÐ130¶à¼Ò¹«Ë¾³ÉΪÆäÍøÂç´¹ÂÚ¹¥»÷µÄÄ¿µÄ¡£¡£¡£Ñо¿Ö°Ô±»¹ÊӲ쵽¸ÃÍÅ»ïÓëAveMaria½©Ê¬ÍøÂçÒÔ¼°CobaltGoblinÍŻﱣ´æ¹ØÁªµÄÖ¤¾Ý¡£¡£¡£ÕâЩÍŻィÉèÁËÒ»¼ÒÐéαµÄÍøÂçÇå¾²¹«Ë¾£¬£¬£¬²¢Í¨¹ýÕÐÆ¸ÍøÕ¾ÕÐļ²»Ã÷ÕæÏàµÄÎó²îÑо¿Ö°Ô±¡¢¿ª·¢Ö°Ô±ºÍ·ÒëÖ°Ô±£¬£¬£¬ÆäÖÐһЩÈËÉõÖÁ¿ÉÄܲ»ÖªµÀ¸Ã×éÖ¯ÕýÔÚ¾ÙÐв»·¨»î¶¯¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fin7-apt-targets-130-orgs-after-1-1/
4¡¢Ó¡µÚ°²ÄÉÖݲ½ÐÐÕß¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·ÖÔ±¹¤ÐÅϢй¶
Ó¡µÚ°²Äɲ½ÐÐÕß¹«Ë¾Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾Ðû²¼µÄÐÂΟ壬£¬£¬ºÚ¿ÍÔÚ2018Äê10ÔÂ15ÈÕµ½2018Äê12ÔÂ4ÈÕÖ®¼äͨ¹ýÍøÂç´¹ÂÚ¹¥»÷»ñµÃÁ˼¸ÃûPSEÔ±¹¤ÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£ÊÜÓ°ÏìµÄÓÊÏäÕË»§ÖÐй¶ÁËһЩÃô¸ÐµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂë¡¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅÂë¡¢Óû§ÃûºÍÃÜÂëµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/indiana-pacers-disclose-security-breach/
5¡¢ÍÁ¶úÆäÒò2018Äê12ÔµÄAPIÎó²î¶ÔFacebook·£¿£¿£¿£¿£¿£¿î27ÍòÃÀÔª
ÍÁ¶úÆäСÎÒ˽¼ÒÊý¾Ý±£»£»£»£»¤»ú¹¹£¨KVKK£©¶ÔFacebook´¦ÒÔ165ÍòÍÁ¶úÆäÀïÀ£¨27ÍòÃÀÔª£©µÄ·£¿£¿£¿£¿£¿£¿î£¬£¬£¬·£¿£¿£¿£¿£¿£¿îµÄÔ´ÓÉÊÇ2018Äê12ÔÂFacebookµÄAPIÎó²î̻¶ÁË30ÍòÍÁ¶úÆäÓû§µÄСÎÒ˽¼ÒÕÕÆ¬¡£¡£¡£KVKKÌåÏÖFacebookûÓÐʵʱ×ö³ö·´Ó¦ÐÞ¸´Îó²î£¬£¬£¬²¢ÇÒûÓн«Ïà¹ØÊÂÎñ֪ͨÍÁ¶úÆäÕþ¸®¡£¡£¡£±ðµÄ£¬£¬£¬KVKK»¹ÔÚÊÓ²ì2018Äê9ÔµÄFacebookÊý¾Ýй¶ÊÂÎñ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/turkey-fines-facebook-for-december-2018-api-bug/
6¡¢Equifax²Æ±¨³ÆÎª2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶14ÒÚÃÀÔª
EquifaxÅû¶ÁËÓë2017Äê´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÓйصIJƱ¨£¬£¬£¬¸Ã¹«Ë¾×ܹ²Îª¸ÃÊÂÎñÆÆ·ÑÁËÔ¼14ÒÚÃÀÔª¡£¡£¡£2017ÄêµÄEquifaxÊý¾Ýй¶ÊÂÎñ×ܹ²µ¼ÖÂ1.45ÒÚÃÀ¹ú¹«ÃñºÍÊýÊ®Íò¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄÃô¸ÐÐÅϢй¶£¬£¬£¬Æäʱ¹¥»÷ÕßʹÓõÄÊÇApache StrutsÎó²î£¨CVE-2017-5638£©£¬£¬£¬ËäÈ»¸ÃÎó²îÓÚ2017Äê3Ô±»ÐÞ¸´£¬£¬£¬µ«¸Ã¹«Ë¾²¢Î´ÊµÊ±×°ÖÃÐÞ¸´²¹¶¡¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85379/security/equifax-data-breach-cost.html


¾©¹«Íø°²±¸11010802024551ºÅ