ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ£»£»GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿î1.26ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2020-01-21

1.ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿Ôº£¨NIST£©ÉÏÖÜÐû²¼ÁËÒþ˽¿ò¼Ü1.0°æ£¬£¬£¬ £¬£¬¸Ã¹¤¾ßÖ¼ÔÚ×ÊÖú×éÖ¯ÖÎÀíÒþ˽Σº¦¡£¡£NISTÓÚ2019Äê9ÔÂÐû²¼ÁËÒþ˽¿ò¼Ü³õ¸å²¢ÍøÂ繫ÖÚÒâ¼û£¬£¬£¬ £¬£¬¸Ã»ú¹¹×î³õÏ£ÍûÔÚ2019Äêµ×֮ǰÐû²¼1.0°æ£¬£¬£¬ £¬£¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽÐû²¼¡£¡£NISTÒþ˽¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖ÷Òª·½ÃæÀ´×ÊÖúÖÖÖÖ¹æÄ£ºÍ¸÷¸ö²¿·ÖµÄ×éÖ¯ÖÎÀíÒþ˽Σº¦£ºÔÚ¿ª·¢²úÆ·»òЧÀÍʱҪ˼Á¿µ½Òþ˽¡¢½»Á÷Òþ˽ÀÏÀýÒÔ¼°¿ç×éÖ¯µÄЭ×÷¡£¡£¸Ã¿ò¼Ü°üÀ¨Èý¸öÖ÷Òª²¿·Ö£º½¹µã¡¢ÌáÒªºÍʵÏֲ㡣¡£½¹µãÌṩһ×éϸ»¯µÄ»î¶¯ºÍЧ¹û£¬£¬£¬ £¬£¬ÆäÄ¿µÄÊÇʵÏÖÄÚ²¿Ïàͬ¡£¡£ÌáÒª²ãÌåÏÖ×éÖ¯ÒÑÈ·¶¨½¹µãÖ°ÄÜ¡¢ÖÖ±ðºÍ×ÓÀà±ðµÄÓÅÏȼ¶±ð¡£¡£×îºó£¬£¬£¬ £¬£¬ÊµÑé²ã¿É×ÊÖú×éÖ¯ÓÅ»¯ÊµÏÖÌáÒª²ãËùÐèµÄ×ÊÔ´¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nist-releases-framework-privacy-risk-management


2.GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿î1.26ÒÚÃÀÔª


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ò»ÏîеÄÊӲ췢Ã÷£¬£¬£¬ £¬£¬Æù½ñΪֹî¿Ïµ»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿£¿£¿£¿î¡£¡£Æ¾Ö¤DLA PiperµÄGDPRÊý¾ÝÎ¥¹æÊӲ죬£¬£¬ £¬£¬Êý¾Ý±£»£»¤î¿Ïµ»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕʱ´ú¶ÔGDPRÏà¹ØµÄ·£¿£¿£¿£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£¡£Õâ¼Ò¹ú¼Ê״ʦÊÂÎñËùÖ¸³ö£¬£¬£¬ £¬£¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿£¿£¿£¿î×ܶî×î¸ß£¬£¬£¬ £¬£¬»®·ÖΪ5100ÍòÅ·Ôª£¬£¬£¬ £¬£¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¡£¸Ã±¨¸æ²¢Î´º­¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿£¿£¿£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©¾ÙÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿£¿£¿£¿î£¬£¬£¬ £¬£¬ÓÉÓÚ×èÖ¹±¨¸æÍê³ÉʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿£¿£¿£¿î¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/


3.ÈýÁâµç»úÒÉÔâºÚ¿ÍÍÅ»ïBronze Butler¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤ÈýÁâµç»úÐû²¼µÄÒ»·Ý¼ò¶ÌµÄÉùÃ÷£¬£¬£¬ £¬£¬È¥Äê6ÔÂ28Èոù«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Ö»¹Ü¸Ã¹«Ë¾ÓÚ9Ô·Ý×îÏÈÁËÕýʽµÄÄÚ²¿ÊӲ죬£¬£¬ £¬£¬µ«Ö±µ½¿ËÈÕÍâµØÃ½Ì屨µÀÁ˸ÃÊÂÎñºó£¬£¬£¬ £¬£¬ÈýÁâµç»ú²ÅÅû¶ÁË´ËÊÂÎñ¡£¡£Æ¾Ö¤ÍâµØÃ½Ì屨µÀ£¬£¬£¬ £¬£¬¹¥»÷ÕßÒÉΪºÚ¿ÍÍÅ»ïBronze Butler£¬£¬£¬ £¬£¬ÈëÇÖ×îÏÈÓÚÒ»¸öÊÜѬȾµÄÔ±¹¤ÕË»§¡£¡£¡¶³¯ÈÕÐÂÎÅ¡·ºÍ¡¶ÈÕ¾­ÐÂÎÅ¡·³ÆºÚ¿Í»ñµÃÁËԼĪ14¸ö¹«Ë¾²¿·Ö£¨ÀýÈçÏúÊÛºÍ×ܹ«Ë¾£©µÄÍøÂç»á¼ûȨÏÞ£¬£¬£¬ £¬£¬²¢ÇÔÈ¡ÁËÔ¼200MBµÄÎļþ£¬£¬£¬ £¬£¬ÆäÖд󲿷ÖÊÇÉÌÒµÎļþ¡£¡£ÈýÁâµç»úÌåÏÖ£¬£¬£¬ £¬£¬ºÚ¿ÍûÓлñµÃÓйعú·ÀÌõÔ¼µÄÃô¸ÐÐÅÏ¢¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mitsubishi-electric-discloses-security-breach-china-is-main-suspect/


4.ÃÀ¹ú¶ùͯ´ò°çÖÆÔìºÍÁãÊÛÉÌHanna AnderssonÔâµ½Magecart¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú¶ùͯ´ò°çÖÆÔìºÍÔÚÏßÁãÊÛÉ̺ºÄÈ¡¤°²µÂÉ­£¨Hanna Andersson£©ÌåÏÖÆäÔÚÏß¹ºÎïÆ½Ì¨Ôâµ½Magecart¹¥»÷¡£¡£ÊÂÎñÔµ¹ÊÔ­ÓÉÊÇHanna AnderssonʹÓõĵÚÈý·½µç×ÓÉÌÎñƽ̨Salesforce Commerce CloudѬȾÁËÇÔÈ¡¿Í»§Ö§¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂ룬£¬£¬ £¬£¬ÊÓ²ìְԱȷÈϵÄ×îÔçΣº¦ÈÕÆÚÊÇ2019Äê9ÔÂ16ÈÕ£¬£¬£¬ £¬£¬¸Ã¶ñÒâ´úÂëÓÚ2019Äê11ÔÂ11ÈÕ±»É¾³ý¡£¡£Hanna Andersson֪ͨ³Æ¸ÃÊÂÎñ¿ÉÄÜÓ°ÏìÁ˿ͻ§ÔÚwww.hannaandersson.comÉÏÌá½»µÄÐÅÏ¢£¬£¬£¬ £¬£¬°üÀ¨ÐÕÃû¡¢ÔËÊ䵨µã¡¢Õ˵¥µØµã¡¢¸¶¿î¿¨ºÅ¡¢CVVÂëºÍÓÐÓÃÆÚ¡£¡£ÏÖÔÚÖ´·¨²¿·ÖÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ졣¡£



Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-retailer-hanna-andersson-hacked-to-steal-credit-cards/


5.Ó¢¹úÕþ¸®Ïò²©²Ê¹«Ë¾Ìṩ2800Íò¶ùͯÐÅÏ¢µÄ»á¼ûȨÏÞ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤¡¶ÐÇÆÚÈÕÌ©ÎîÊ¿±¨¡·¾ÙÐеÄÒ»ÏîÊӲ죬£¬£¬ £¬£¬²©²Ê¹«Ë¾±»²»ÊÊÍâµØÌṩÁË´ÓÕþ¸®Êý¾Ý¿âÖлá¼û¶ùͯÐÅÏ¢µÄȨÏÞ£¬£¬£¬ £¬£¬¸ÃÊý¾Ý¿â°üÀ¨2800Íò¶ùͯµÄÐÅÏ¢¡£¡£¸ÃÊý¾Ý¿âÓÉÓ¢¹ú½ÌÓý²¿£¨DfE£©ÈÏÕæ£¬£¬£¬ £¬£¬ÆäÖаüÀ¨¹«Á¢ºÍ˽Á¢Ñ§Ð£ÒÔ¼°È«Ó¢¸÷´óѧÖÐ14Ëê¼°ÒÔÉÏδ³ÉÄêÈ˵ÄÏêϸÐÅÏ¢£¬£¬£¬ £¬£¬Ö¼ÔÚÓÃÓÚÅàѵºÍ½ÌÓýÓÃ;¡£¡£Æ¾Ö¤ÊӲ죬£¬£¬ £¬£¬Ò»¼ÒÏàÖúͬ°é¹«Ë¾Î´¾­ÔÊÐí¾Í½«Êý¾Ý¿âÖеÄÐÅÏ¢»á¼ûȨÏÞÌṩӦÁ˲©²Ê¼¯ÍÅ£¬£¬£¬ £¬£¬Ê¹¶Ä²©¹«Ë¾¿ÉÒÔʹÓÃÕâЩÊý¾Ý¾ÙÐпìËÙµÄÔÚÏßÉí·ÝÑéÖ¤ºÍÄêËê¼ì²é¡£¡£¾Ý³ÆÐ¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢ÄêËêºÍÏÖʵµØµã¡£¡£ÒԺ󣬣¬£¬ £¬£¬DfEÒѽûÓöԸÃÊý¾Ý¿âµÄ»á¼û¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/betting-companies-given-free-rein-with-data-of-28-million-children/


6.WP Database Reset²å¼þÎó²î¿Éµ¼ÖÂÍøÕ¾±»½ÓÊÜ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


WordfenceÇå¾²Ñо¿Ö°Ô±ÔÚWordPress²å¼þWP Database ResetÖз¢Ã÷ÁËÁ½¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î½ÓÊÜÊÜÓ°ÏìµÄÍøÕ¾¡£¡£µÚÒ»¸öÎó²î£¨CVE-2020-7048£©µÄCVSSÆÀ·ÖΪ9.1·Ö£¬£¬£¬ £¬£¬ÆäÔµ¹ÊÔ­ÓÉÊÇûÓб£»£»¤ÈκÎÊý¾Ý¿âÖØÖù¦Ð§£¬£¬£¬ £¬£¬Õâ¿ÉÄÜʹµÃÈκÎÓû§ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÖØÖÃÈκÎÊý¾Ý¿â±í¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2020-7047£©µÄCVSSÆÀ·ÖΪ8.1·Ö£¬£¬£¬ £¬£¬Èκξ­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¾ù¿Éͨ¹ýÖØÖÃwp_users±íÀ´É¾³ýËùÓÐÆäËûÓû§ºÍÉý¼¶ÎªÖÎÀíÌØÈ¨¡£¡£¿£¿£¿£¿ª·¢ÍŶÓÒѾ­ÔÚWP Database Reset×îа汾3.15ÖÐÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96611/hacking/wp-database-reset-wordpress-flaws.html