GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó¦£»£»·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬»òÓëÌØ¹¤»î¶¯ÓйØ

Ðû²¼Ê±¼ä 2020-12-29

1.GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó¦


1.jpg


GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹ÂڻµÄ·´Ó¦¡£¡£¡£¡£¡£¡£¸Ã²âÊÔÓÚ12Ô¾ÙÐУ¬£¬£¬£¬£¬£¬ÓʼþÉù³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖúÔ±¹¤Ó¦¶ÔÒòCOVID-19±¬·¢¶øµ¼Öµľ­¼ÃÎÊÌ⣬£¬£¬£¬£¬£¬²¢ÒªÇóËûÃÇÌîдСÎÒ˽¼ÒÐÅÏ¢±í¸ñ¡£¡£¡£¡£¡£¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬£¬£¬£¬£¬£¬ËûÃǽ«±»ÒªÇóÖØÐ¼ÓÈëÉç»á¹¤³ÌÇå¾²ÒâʶµÄÅàѵ¡£¡£¡£¡£¡£¡£ÓÉÓÚ²âÊÔÖÐʹÓõÄÓÕ¶üºÍÄ£Äâʱ¼äµÄÑ¡Ôñ£¬£¬£¬£¬£¬£¬¸ÃÒªÁìÊܵ½Á˲¿·ÖÍøÂçÇå¾²ÕûÌåµÄÆ·ÆÀ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html


2.·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬»òÓëÌØ¹¤»î¶¯ÓйØ


2.jpg


·ÒÀ¼Òé»á³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸öÒéÔ±µÄµç×ÓÓʼþÕÊ»§Ôâµ½ÈëÇÖ¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020ÄêÇïÌ죬£¬£¬£¬£¬£¬Í³Ò»Ê±¼ä£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28¹¥»÷Á˲¿·ÖŲÍþÒé»á´ú±íºÍÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£·ÒÀ¼ÖÐÑëÐ̾¯£¨KRP£©³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÒé»áÄÚ²¿µÄITϵͳÔì³ÉÈκÎË𺦣¬£¬£¬£¬£¬£¬µ«Ò²²»ÊÇÒâÍâÈëÇÖ£¬£¬£¬£¬£¬£¬¿ÉÄÜÊǹú¼ÒºÚ¿Í¾ÙÐеÄÍøÂçÌØ¹¤»î¶¯µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬KRPÌåÏÖ²»¿ÉÈ·¶¨Êܺ¦ÕßÊýÄ¿£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÌṩ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/finland-says-hackers-accessed-mps-emails-accounts/


3.ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶


3.jpg


ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÓÚ2020Äê12ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˸ÃÍøÕ¾²¢»á¼ûÁËNetGalleyÊý¾Ý¿âµÄ±¸·ÝÎļþ¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§µÇ¼ÃûºÍÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹ú¼Ò/µØÇø£¬£¬£¬£¬£¬£¬±ðµÄÉÐÓв¿·ÖÓû§µÄ¼òÀú¡¢Óʼĵص㡢µç»°ºÅÂë¡¢ÉúÈÕ¡¢¹«Ë¾Ãû³ÆºÍKindleµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¡£NetGalleyÌåÏÖ£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÓë²ÆÎñÓйصÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/book-promotion-site-netgalley-disclosed-data-breach-following-website-defacement/


4.SolarWindsÐÞ¸´OrionÖеÄÎó²î£¨CVE-2020-10148£©


4.jpg


SolarWindsÐÞ¸´ÁËOrionÖб»×·×ÙΪCVE-2020-10148µÄRCEÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤Äܹ»±»Èƹý£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚRequest.PathInfoURIÇëÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐδ¾­Éí·ÝÑéÖ¤µÄAPIÏÂÁî¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬SolarWindsÒѾ­Ðû²¼ÁË´ËÎó²îµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´SUNBURSTºÍSUPERNOVAÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory-for-new-supernova-malware/


5.FlatfileÐû²¼2020ÄêÊý¾ÝЭ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ


5.jpg


FlatfileÐû²¼ÁË2020ÄêÊý¾ÝЭ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Êý¾Ýµ¼È루Data onboarding£©Êǿͻ§Ð­×÷ÖеÄÒ»¸öÒªº¦½×¶Î£¬£¬£¬£¬£¬£¬²úÆ·ºÍÖ§³ÖÍŶÓÐèÒªÎÞ·ìµØ½»¸¶Êý¾Ý£¬£¬£¬£¬£¬£¬À´Îª¿Í»§Ìṩ×î´óµÄÓªÒµ¼ÛÖµ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶Ô100¶à¼Ò¹«Ë¾¾ÙÐÐÁËÊӲ죬£¬£¬£¬£¬£¬²¢²É·ÃÁË5000¶àÃûÊÜ·ÃÕß¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬54£¥µÄÊÜ·ÃÕßÌìÌì¶¼ÔÚµ¼Èë»òÉÏ´«Êý¾Ý£¬£¬£¬£¬£¬£¬23£¥µÄÊÜ·ÃÕßÌåÏÖµ¼Èë¿Í»§Êý¾ÝÐèÒªÊýÖÜ»òÊýÔµÄʱ¼ä£¬£¬£¬£¬£¬£¬96£¥µÄÊÜ·ÃÕßÌåÏÖËûÃÇÔøÔÚµ¼ÈëÊý¾ÝʱÓöµ½ÁËÎÊÌâ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://flatfile.io/state-of-data-onboarding-2020/


6.DTEXÐû²¼2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ


6.jpg


DTEX systemÐû²¼ÁË2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬½ü75£¥µÄ×éÖ¯µ£ÐÄÔÚ¼ÒÊÂÇé»á´øÀ´Ç徲Σº¦£¬£¬£¬£¬£¬£¬73£¥µÄ×éÖ¯ÒÔΪԶ³ÌÊÂÇéÕß½ûÓÃÁËVPNºó£¬£¬£¬£¬£¬£¬ËûÃǵĻ½«±äµÃ²»¿É¼û¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬µ±Óû§½«ÆäÊÂÇéµçÄÔÓÃÓÚСÎÒ˽¼ÒÓÃ;ºÍ¹«Ë¾ÓÃ;ʱ£¬£¬£¬£¬£¬£¬ÔöÌíÁËÇý¶¯ÏÂÔØµÄΣº¦£¨25£¥£©£¬£¬£¬£¬£¬£¬Óû§¸üÈÝÒ×ÊּܵÒÍ¥ÍøÂç´¹ÂڵĹ¥»÷£¨15£¥£©¡£¡£¡£¡£¡£¡£×éÖ¯ÓÅÏÈ˼Á¿Ô¶³ÌÔ±¹¤»î¶¯¿ÉÊÓÐÔ£¨34£¥£©£¬£¬£¬£¬£¬£¬È»ºóÊÇˢеÄÍøÂçÆÊÎö£¨30£¥£©ºÍɱ¶¾ÒÔ¼°¶Ëµã¼ì²âºÍÏìÓ¦¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.dtexsystems.com/blog/2021-remote-workforce-security-report-organizations-still-lack-confidence-in-security-practices/