GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó³£»£»£»£»£»£»·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬»òÓë¼äµý»î¶¯ÓйØ

°ä²¼¹¦·ò 2020-12-29

1.GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó³


1.jpg


GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬£¬£¬£¬£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹µö»î¶¯µÄ·´Ó³¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²âÊÔÓÚ12Ô½øÐУ¬£¬£¬£¬£¬ÓʼþÐû³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬£¬£¬£¬£¬ÒÔÔ®ÊÖÔ±¹¤Ó¦¶ÔÒòCOVID-19·¢×÷¶øµ¼Öµľ­¼ÃÎÊÌ⣬£¬£¬£¬£¬²¢ÒªÇóËûÃÇÌîдÓ×ÎÒÐÅÏ¢±í¸ñ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬£¬£¬£¬£¬ËûÃǽ«±»ÒªÇó³ÁвÎÓëÉç»á¹¤³Ì°²È«ÒâʶµÄÅàѵ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ²âÊÔÖÐʹÓõĵö¶üºÍÄ£Ä⹦·òµÄÑ¡Ôñ£¬£¬£¬£¬£¬¸Ã²½ÖèÊܵ½Á˲¿ÃÅÍøÂ簲ȫ¼¯ÌåµÄÆ·ÆÀ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html


2.·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬»òÓë¼äµý»î¶¯ÓйØ


2.jpg


·ÒÀ¼Òé»á³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬¶à¸öÒéÔ±µÄµç×ÓÓʼþÕÊ»§Ôâµ½ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2020ÄêÇïÌ죬£¬£¬£¬£¬Í³Ò»¹¦·ò£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28¹¥»÷Á˲¿ÃÅŲÍþÒé»á´ú±íºÍÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£·ÒÀ¼ÖÐÑëÐ̾¯£¨KRP£©³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÒé»áÄÚ²¿µÄITϵͳÔì³ÉÈκÎÇÖº¦£¬£¬£¬£¬£¬µ«Ò²²»ÊÇÒâ±íÈëÇÖ£¬£¬£¬£¬£¬¿ÉÄÜÊǹú¶ÈºÚ¿Í½øÐеÄÍøÂç¼äµý»î¶¯µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬KRP°µÊ¾²»ÄÜÈ·¶¨Êܺ¦ÕßÊýÁ¿£¬£¬£¬£¬£¬Ò²Ã»ÓÐÌṩ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/finland-says-hackers-accessed-mps-emails-accounts/


3.ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶


3.jpg


ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÓÚ2020Äê12ÔÂ21ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˸ÃÍøÕ¾²¢½Ó¼ûÁËNetGalleyÊý¾Ý¿âµÄ±¸·ÝÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§µÇ¼ÃûºÍÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹ú¶È/µØÓò£¬£¬£¬£¬£¬´Ë±í»¹Óв¿ÃÅÓû§µÄ¼òÀú¡¢ÓʼĵØÖ·¡¢µç»°ºÅÂë¡¢ÉúÈÕ¡¢¹«Ë¾Ãû³ÆºÍKindleµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£NetGalley°µÊ¾£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÓë²ÆÕþÓйصÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/book-promotion-site-netgalley-disclosed-data-breach-following-website-defacement/


4.SolarWinds½¨¸´OrionÖеķì϶£¨CVE-2020-10148£©


4.jpg


SolarWinds½¨¸´ÁËOrionÖб»×·×ÙΪCVE-2020-10148µÄRCE·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤¿ÉÄܱ»Èƹý£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔÚRequest.PathInfoURIÒªÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬×îÖÕ¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐδ¾­Éí·ÝÑéÖ¤µÄAPIºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬SolarWindsÒѾ­°ä²¼ÁË´Ë·ì϶µÄ°²È«¸üУ¬£¬£¬£¬£¬ÒÔ½¨¸´SUNBURSTºÍSUPERNOVA·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory-for-new-supernova-malware/


5.Flatfile°ä²¼2020ÄêÊý¾ÝºÏ×÷µÄÌ¬ÊÆ·ÖÎö»ã±¨


5.jpg


Flatfile°ä²¼ÁË2020ÄêÊý¾ÝºÏ×÷µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£Êý¾Ýµ¼È루Data onboarding£©Êǿͻ§ºÏ×÷ÖеÄÒ»¸ö¹Ø¼ü½×¶Î£¬£¬£¬£¬£¬²úÆ·ºÍÖ§³ÖÍŶӱØÒªÎÞ·ìµØ½»¸¶Êý¾Ý£¬£¬£¬£¬£¬À´Îª¿Í»§Ìṩ×î´óµÄÒµÎñ¼ÛÖµ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨¶Ô100¶à¼Ò¹«Ë¾½øÐÐÁ˵÷²é£¬£¬£¬£¬£¬²¢²É·ÃÁË5000¶àÃûÊÜ·ÃÕß¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬54£¥µÄÊÜ·ÃÕßÿÌì¶¼ÔÚµ¼Èë»òÉÏ´«Êý¾Ý£¬£¬£¬£¬£¬23£¥µÄÊÜ·ÃÕß°µÊ¾µ¼Èë¿Í»§Êý¾Ý±ØÒªÊýÖÜ»òÊýԵŦ·ò£¬£¬£¬£¬£¬96£¥µÄÊÜ·ÃÕß°µÊ¾ËûÃÇÔøÔÚµ¼ÈëÊý¾ÝʱÓöµ½ÁËÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://flatfile.io/state-of-data-onboarding-2020/


6.DTEX°ä²¼2021ÄêÔ¶³Ì¹¤×÷µÄ°²È«·ÖÎö»ã±¨


6.jpg


DTEX system°ä²¼ÁË2021ÄêÔ¶³Ì¹¤×÷µÄ°²È«·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬½ü75£¥µÄ×éÖ¯²»ºÎÔÚ¼Ò¹¤×÷»á´øÀ´°²È«·çÏÕ£¬£¬£¬£¬£¬73£¥µÄ×éÖ¯ÒÔΪԶ³Ì¹¤×÷Õß½ûÓÃÁËVPNºó£¬£¬£¬£¬£¬ËûÃǵĻ½«±äµÃ²»Ë½¼û¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬µ±Óû§½«Æä¹¤×÷µçÄÔÓÃÓÚÓ×ÎÒÓô¦ºÍ¹«Ë¾Óô¦Ê±£¬£¬£¬£¬£¬Ôö³¤ÁËÇý¶¯ÏÂÔØµÄ·çÏÕ£¨25£¥£©£¬£¬£¬£¬£¬Óû§¸üÈÝÒ×Êܵ½¼ÒÍ¥ÍøÂç´¹µöµÄ¹¥»÷£¨15£¥£©¡£¡£¡£¡£¡£¡£¡£¡£×éÖ¯ÓÅÏÈ˼¿¼Ô¶³ÌÔ±¹¤»î¶¯¿ÉÊÓÐÔ£¨34£¥£©£¬£¬£¬£¬£¬¶øºóÊǸĽøµÄÍøÂç·ÖÎö£¨30£¥£©ºÍɱ¶¾ÒÔ¼°¶Ëµã¼ì²âºÍÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.dtexsystems.com/blog/2021-remote-workforce-security-report-organizations-still-lack-confidence-in-security-practices/