Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»£»£»£» £»ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬ £¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨

°ä²¼¹¦·ò 2020-09-15

1.Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨


1.png


Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£¡£¡£ ¡£¡£¡£¡£»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬 £¬£¬£¬£¬£¬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬 £¬£¬£¬£¬£¬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£¡£¡£ ¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬ £¬£¬£¬£¬£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£¡£¡£ ¡£¡£¡£¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬ £¬£¬£¬£¬£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬ £¬£¬£¬£¬£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/


2.Êý¾ÝÖÐÐÄEquinixϰȾNetwalker£¬ £¬£¬£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶


2.png


Êý¾ÝÍйÜÖÐÐÄEquinix°ä²¼ÉêÃ÷£¬ £¬£¬£¬£¬£¬°µÊ¾ÆäºÜ¶àÄÚ²¿ÏµÍ³Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬µ«ÆäΪ¿Í»§Ìṩ·þÎñµÄÖØÒªÖ÷ÌⲢδÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯Netwalker°µÊ¾Æä³É¹¦ÈëÇÖÁËEquinix²¢°ä²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬ £¬£¬£¬£¬£¬ÒÔ´ËÍþв֧¸¶450ÍòÃÀÔªµÄÊê½ð¡£¡£¡£ ¡£¡£¡£¡£Õâ´Îй©µÄÊý¾ÝÔ̺¬¹«Ë¾²ÆÕþÐÅÏ¢ºÍÊý¾ÝÖÐÐĻ㱨¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÀ´ÁúÈ¥Âö£¬ £¬£¬£¬£¬£¬Equinix°µÊ¾ÔÚ½øÐе÷²é¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/data-center-giant-equinix-discloses-ransomware-incident/


3.·ÇÖÞÈûÉà¶û¿ª·¢ÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬¿Í»§ÐÅÏ¢¿ÉÄܱ»µÁ


3.png


·ÇÖÞÈûÉà¶ûÖÐÑëÒøÐУ¨CBS£©°ä·¢Ò»·ÝÐÂÎÅÉêÃ÷£¬ £¬£¬£¬£¬£¬ÈûÉà¶û¿ª·¢ÒøÐУ¨DBS£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬¿Í»§ÐÅÏ¢»òÒѱ»µÁ¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÓÚ2020Äê9ÔÂ9ÈÕ£¬ £¬£¬£¬£¬£¬¾ßÌåÐÅÏ¢»¹ÔÚµ÷²éÖ®ÖС£¡£¡£ ¡£¡£¡£¡£¹ÌȻĿǰÉв»Ã÷ÏÔ¹¥»÷ÕßÊÇ·ñÔÚ¼ÓÃÜÒøÐÐϵͳ֮ǰÇÔÈ¡ÁËÊý¾Ý£¬ £¬£¬£¬£¬£¬µ«Æ¾¾Ý¹¥»÷ÖÐʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬ £¬£¬£¬£¬£¬ºÜÓпÉÄܲúÉúÕâÖÖÇé¿ö¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/development-bank-of-seychelles-hit-by-ransomware-attack/


4.ÃÀ¹úÓÊÕþ²¿ÃÅITϵͳ´æÔÚ¶à¸ö·ì϶£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂÊý¾Ýй¶


4.jpg


ÃÀ¹úÓÊÕþ²¿ÃŵÄÒ»·ÝÉó¼Æ»ã±¨·¢ÏÖ£¬ £¬£¬£¬£¬£¬¸Ã²¿ÃŵÄITϵͳ´æÔÚ¶à¸ö·ì϶£¬ £¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܱ»ºÚ¿ÍÀûÓÃÀ´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¼à¹Ü»ú¹¹°µÊ¾£¬ £¬£¬£¬£¬£¬ÕâЩ·ì϶ÖÐÓÐ12¸ö¿àÄÑÐԵģ¬ £¬£¬£¬£¬£¬ËüÃÇ¿ÉÄÜ»á¸ø¸Ã»ú¹¹´øÀ´¾Þ´óµÄ¾­¼ÃËðʧ£¬ £¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³£¼ûµÄ¡¢Òѱ»¹«¿ªÈýÄêµÄ·ì϶¡£¡£¡£ ¡£¡£¡£¡£½ØÖÁĿǰ£¬ £¬£¬£¬£¬£¬»¹Ã»ÓÐÈκÎÖ¤¾ÝÅú×¢ÕâЩ·ì϶Òѱ»ºÚ¿ÍÀûÓᣡ£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/postal-service-inspector-general-cyber-vulnerabilities/


5.×êÑÐÍŶӷ¢ÏÖÀûÓÃOffice 365 API´¹µö¹¥»÷»î¶¯


5.jpg


×êÑÐÍŶӷ¢ÏÖÒ»ÖÖеÄÍøÂç´¹µö¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÉí·ÝÑéÖ¤APIʵʱÑéÖ¤Êܺ¦ÕßµÄOffice 365Í´´¦¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷ÖеĴ¹µöÓʼþÖ¸ÏòÓëOffice 365µÇ¼ҳһÑùµÄ´¹µöÍøÕ¾£¬ £¬£¬£¬£¬£¬²¢ÇÒÓû§ÃûÒÑÔ¤ÏÈÊäÈë¡£¡£¡£ ¡£¡£¡£¡£Ò»µ©Êܺ¦Õß½«ÆäÍ´´¦ÊäÈëµ½ÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬ £¬£¬£¬£¬£¬Azure Active DirectoryµÇ¼ÈÕÖ¾¾Í»áÏÔʾÓëÔÚ¸½¼þÍøÒ³ÉÏÖ´ÐеÄXHRÒªÇóÏà¶ÔÓ¦µÄÁ¢¼´µÇ¼³¢ÊÔ¡£¡£¡£ ¡£¡£¡£¡£ÈôÊÇÉí·ÝÑéÖ¤³É¹¦£¬ £¬£¬£¬£¬£¬Ôò½«Óû§³Á¶¨Ïòµ½zoom.com¡£¡£¡£ ¡£¡£¡£¡£ÈôÊÇÉí·ÝÑé֤ʧ°Ü£¬ £¬£¬£¬£¬£¬Ôò»á½«Óû§³Á¶¨Ïòµ½login.microsoftonline.com¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/office-365-phishing-attack-leverages-real-time-active-directory-validation/159188/


6.ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬ £¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨


6.jpg


ÉÏÖÜÄ©£¬ £¬£¬£¬£¬£¬ÐÅÓþ¿¨ÇÔȡԤ·À¹«Ë¾Sanguine Security·¢´Ë¿Ì´ÓǰËÄÌìÖкڿÍÈëÇÖÁË1904¼ÒMagentoÔÚÏßÉ̵꣬ £¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ʼÓÚÉÏÖÜÎ壬 £¬£¬£¬£¬£¬ÆäʱÓÐ10¼ÒÉ̵êϰȾÁË´Óδ¼û¹ýµÄÐÅÓþ¿¨ÇÔÈ¡¾ç±¾¡£¡£¡£ ¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬¹¥»÷ÔÚÖÜÁù¼¤Ôö£¬ £¬£¬£¬£¬£¬ÓÐ1058¸öÕ¾µã±»ºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬£¬ÔÚÖÜÈÕÓÐ603¸öÕ¾µã±»ÈëÇÖ£¬ £¬£¬£¬£¬£¬ÖÜÒ»ÓÐ233¸ö±»ÈëÇÖ¡£¡£¡£ ¡£¡£¡£¡£Sanguine Security°µÊ¾£¬ £¬£¬£¬£¬£¬ÕâÊÇ×Ô2015ÄêÆðÍ·¼à¿Øµç×ÓÉÌÎñÉ̵êÒÔÀ´£¬ £¬£¬£¬£¬£¬ËûÃÇËù¿´µ½µÄ×î´óµÄMagento¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/magento-stores-hit-by-largest-automated-hacking-attack-since-2015/