GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³£»·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬»òÓë¼äµý»î¶¯ÓйØ

°ä²¼¹¦·ò 2020-12-29

1.GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³


1.jpg


GoDaddyÏòÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹µö»î¶¯µÄ·´Ó³¡£¸Ã²âÊÔÓÚ12Ô½øÐУ¬ÓʼþÐû³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬ÒÔÔ®ÊÖÔ±¹¤Ó¦¶ÔÒòCOVID-19·¢×÷¶øµ¼Öµľ­¼ÃÎÊÌ⣬²¢ÒªÇóËûÃÇÌîдÓ×ÎÒÐÅÏ¢±í¸ñ¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬ËûÃǽ«±»ÒªÇó³ÁвÎÓëÉç»á¹¤³Ì°²È«ÒâʶµÄÅàѵ¡£ÓÉÓÚ²âÊÔÖÐʹÓõĵö¶üºÍ·ÂÕÕ¹¦·òµÄÑ¡Ôñ£¬¸Ã²½ÖèÊܵ½Á˲¿ÃÅÍøÂ簲ȫ¼¯ÌåµÄÆ·ÆÀ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html


2.·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬»òÓë¼äµý»î¶¯ÓйØ


2.jpg


·ÒÀ¼Òé»á³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬¶à¸öÒéÔ±µÄµç×ÓÓʼþÕÊ»§Ôâµ½ÈëÇÖ¡£¹¥»÷²úÉúÔÚ2020ÄêÇïÌ죬ͳһ¹¦·ò£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28¹¥»÷Á˲¿ÃÅŲÍþÒé»á´ú±íºÍÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£·ÒÀ¼ÖÐÑëÐ̾¯£¨KRP£©³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÒé»áÄÚ²¿µÄITϵͳÔì³ÉÈκÎÇÖº¦£¬µ«Ò²²»ÊÇÒâ±íÈëÇÖ£¬¿ÉÄÜÊǹú¶ÈºÚ¿Í½øÐеÄÍøÂç¼äµý»î¶¯µÄÒ»²¿ÃÅ¡£Ä¿Ç°£¬KRP°µÊ¾²»ÄÜÈ·¶¨Êܺ¦ÕßÊýÁ¿£¬Ò²Ã»ÓÐÌṩ¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/finland-says-hackers-accessed-mps-emails-accounts/


3.ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶


3.jpg


ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¹¥»÷²úÉúÓÚ2020Äê12ÔÂ21ÈÕ£¬ºÚ¿ÍÈëÇÖÁ˸ÃÍøÕ¾²¢½Ó¼ûÁËNetGalleyÊý¾Ý¿âµÄ±¸·ÝÎļþ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§µÇ¼ÃûºÍÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹ú¶È/µØÓò£¬´Ë±í»¹Óв¿ÃÅÓû§µÄ¼òÀú¡¢ÓʼĵØÖ·¡¢µç»°ºÅÂë¡¢ÉúÈÕ¡¢¹«Ë¾Ãû³ÆºÍKindleµç×ÓÓʼþµØÖ·¡£NetGalley°µÊ¾£¬Ã»ÓÐÈκÎÓë²ÆÕþÓйصÄÊý¾Ýй¶¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/book-promotion-site-netgalley-disclosed-data-breach-following-website-defacement/


4.SolarWinds½¨¸´OrionÖеķì϶£¨CVE-2020-10148£©


4.jpg


SolarWinds½¨¸´ÁËOrionÖб»×·×ÙΪCVE-2020-10148µÄRCE·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤¿ÉÄܱ»Èƹý£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔÚRequest.PathInfoURIÒªÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´ÀûÓô˷ì϶£¬×îÖÕ¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐδ¾­Éí·ÝÑéÖ¤µÄAPIºÅÁĿǰ£¬SolarWindsÒѾ­°ä²¼ÁË´Ë·ì϶µÄ°²È«¸üУ¬ÒÔ½¨¸´SUNBURSTºÍSUPERNOVA·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory-for-new-supernova-malware/


5.Flatfile°ä²¼2020ÄêÊý¾ÝºÏ×÷µÄÌ¬ÊÆ·ÖÎö»ã±¨


5.jpg


Flatfile°ä²¼ÁË2020ÄêÊý¾ÝºÏ×÷µÄÌ¬ÊÆ·ÖÎö»ã±¨¡£Êý¾Ýµ¼È루Data onboarding£©Êǿͻ§ºÏ×÷ÖеÄÒ»¸ö¹Ø¼ü½×¶Î£¬²úÆ·ºÍÖ§³ÖÍŶӱØÒªÎÞ·ìµØ½»¸¶Êý¾Ý£¬À´Îª¿Í»§Ìṩ×î´óµÄÒµÎñ¼ÛÖµ¡£¸Ã»ã±¨¶Ô100¶à¼Ò¹«Ë¾½øÐÐÁ˵÷²é£¬²¢²É·ÃÁË5000¶àÃûÊÜ·ÃÕß¡£»ã±¨ÏÔʾ£¬54£¥µÄÊÜ·ÃÕßÿÌì¶¼ÔÚµ¼Èë»òÉÏ´«Êý¾Ý£¬23£¥µÄÊÜ·ÃÕß°µÊ¾µ¼Èë¿Í»§Êý¾Ý±ØÒªÊýÖÜ»òÊýԵŦ·ò£¬96£¥µÄÊÜ·ÃÕß°µÊ¾ËûÃÇÔøÔÚµ¼ÈëÊý¾ÝʱÓöµ½ÁËÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://flatfile.io/state-of-data-onboarding-2020/


6.DTEX°ä²¼2021ÄêÔ¶³Ì¹¤×÷µÄ°²È«·ÖÎö»ã±¨


6.jpg


DTEX system°ä²¼ÁË2021ÄêÔ¶³Ì¹¤×÷µÄ°²È«·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬½ü75£¥µÄ×éÖ¯²»ºÎÔÚ¼Ò¹¤×÷»á´øÀ´°²È«·çÏÕ£¬73£¥µÄ×éÖ¯ÒÔΪԶ³Ì¹¤×÷Õß½ûÓÃÁËVPNºó£¬ËûÃǵĻ½«±äµÃ²»Ë½¼û¡£´Ë±í£¬µ±Óû§½«Æä¹¤×÷µçÄÔÓÃÓÚÓ×ÎÒÓô¦ºÍ¹«Ë¾Óô¦Ê±£¬Ôö³¤ÁËÇý¶¯ÏÂÔØµÄ·çÏÕ£¨25£¥£©£¬Óû§¸üÈÝÒ×Êܵ½¼ÒÍ¥ÍøÂç´¹µöµÄ¹¥»÷£¨15£¥£©¡£×éÖ¯ÓÅÏÈ˼¿¼Ô¶³ÌÔ±¹¤»î¶¯¿ÉÊÓÐÔ£¨34£¥£©£¬¶øºóÊǸĽøµÄÍøÂç·ÖÎö£¨30£¥£©ºÍɱ¶¾ÒÔ¼°¶Ëµã¼ì²âºÍÏìÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.dtexsystems.com/blog/2021-remote-workforce-security-report-organizations-still-lack-confidence-in-security-practices/