GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó¦ £»·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬»òÓëÌØ¹¤Ô˶¯ÓйØ

Ðû²¼Ê±¼ä 2020-12-29

1.GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó¦


1.jpg


GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹ÂÚÔ˶¯µÄ·´Ó¦¡£¸Ã²âÊÔÓÚ12Ô¾ÙÐУ¬ÓʼþÉù³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬ÒÔ×ÊÖúÔ±¹¤Ó¦¶ÔÒòCOVID-19±¬·¢¶øµ¼Öµľ­¼ÃÎÊÌ⣬²¢ÒªÇóËûÃÇÌîдСÎÒ˽¼ÒÐÅÏ¢±í¸ñ¡£Õâ´Î²âÊÔÔ˶¯Ô¼Äª500ÃûÔ±¹¤ÖÐÕУ¬ËûÃǽ«±»ÒªÇóÖØÐ¼ÓÈëÉç»á¹¤³ÌÇå¾²ÒâʶµÄÅàѵ¡£ÓÉÓÚ²âÊÔÖÐʹÓõÄÓÕ¶üºÍÄ£Äâʱ¼äµÄÑ¡Ôñ£¬¸ÃÒªÁìÊܵ½Á˲¿·ÖÍøÂçÇå¾²ÕûÌåµÄÆ·ÆÀ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html


2.·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬»òÓëÌØ¹¤Ô˶¯ÓйØ


2.jpg


·ÒÀ¼Òé»á³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬¶à¸öÒéÔ±µÄµç×ÓÓʼþÕÊ»§Ôâµ½ÈëÇÖ¡£¹¥»÷±¬·¢ÔÚ2020ÄêÇïÌ죬ͳһʱ¼ä£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28¹¥»÷Á˲¿·ÖŲÍþÒé»á´ú±íºÍÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£·ÒÀ¼ÖÐÑëÐ̾¯£¨KRP£©³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÒé»áÄÚ²¿µÄITϵͳÔì³ÉÈκÎË𺦣¬µ«Ò²²»ÊÇÒâÍâÈëÇÖ£¬¿ÉÄÜÊǹú¼ÒºÚ¿Í¾ÙÐеÄÍøÂçÌØ¹¤Ô˶¯µÄÒ»²¿·Ö¡£ÏÖÔÚ£¬KRPÌåÏÖ²»¿ÉÈ·¶¨Êܺ¦ÕßÊýÄ¿£¬Ò²Ã»ÓÐÌṩ¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/finland-says-hackers-accessed-mps-emails-accounts/


3.ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶


3.jpg


ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¹¥»÷±¬·¢ÓÚ2020Äê12ÔÂ21ÈÕ£¬ºÚ¿ÍÈëÇÖÁ˸ÃÍøÕ¾²¢»á¼ûÁËNetGalleyÊý¾Ý¿âµÄ±¸·ÝÎļþ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§µÇ¼ÃûºÍÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹ú¼Ò/µØÇø£¬±ðµÄÉÐÓв¿·ÖÓû§µÄ¼òÀú¡¢Óʼĵص㡢µç»°ºÅÂë¡¢ÉúÈÕ¡¢¹«Ë¾Ãû³ÆºÍKindleµç×ÓÓʼþµØµã¡£NetGalleyÌåÏÖ£¬Ã»ÓÐÈκÎÓë²ÆÎñÓйصÄÊý¾Ýй¶¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/book-promotion-site-netgalley-disclosed-data-breach-following-website-defacement/


4.SolarWindsÐÞ¸´OrionÖеÄÎó²î£¨CVE-2020-10148£©


4.jpg


SolarWindsÐÞ¸´ÁËOrionÖб»×·×ÙΪCVE-2020-10148µÄRCEÎó²î¡£¸ÃÎó²îÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤Äܹ»±»Èƹý£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚRequest.PathInfoURIÇëÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´Ê¹ÓôËÎó²î£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐδ¾­Éí·ÝÑéÖ¤µÄAPIÏÂÁî¡£ÏÖÔÚ£¬SolarWindsÒѾ­Ðû²¼ÁË´ËÎó²îµÄÇå¾²¸üУ¬ÒÔÐÞ¸´SUNBURSTºÍSUPERNOVAÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory-for-new-supernova-malware/


5.FlatfileÐû²¼2020ÄêÊý¾ÝЭ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ


5.jpg


FlatfileÐû²¼ÁË2020ÄêÊý¾ÝЭ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£Êý¾Ýµ¼È루Data onboarding£©Êǿͻ§Ð­×÷ÖеÄÒ»¸öÒªº¦½×¶Î£¬²úÆ·ºÍÖ§³ÖÍŶÓÐèÒªÎÞ·ìµØ½»¸¶Êý¾Ý£¬À´Îª¿Í»§Ìṩ×î´óµÄÓªÒµ¼ÛÖµ¡£¸Ã±¨¸æ¶Ô100¶à¼Ò¹«Ë¾¾ÙÐÐÁËÊӲ죬²¢²É·ÃÁË5000¶àÃûÊÜ·ÃÕß¡£±¨¸æÏÔʾ£¬54£¥µÄÊÜ·ÃÕßÌìÌì¶¼ÔÚµ¼Èë»òÉÏ´«Êý¾Ý£¬23£¥µÄÊÜ·ÃÕßÌåÏÖµ¼Èë¿Í»§Êý¾ÝÐèÒªÊýÖÜ»òÊýÔµÄʱ¼ä£¬96£¥µÄÊÜ·ÃÕßÌåÏÖËûÃÇÔøÔÚµ¼ÈëÊý¾ÝʱÓöµ½ÁËÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://flatfile.io/state-of-data-onboarding-2020/


6.DTEXÐû²¼2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ


6.jpg


DTEX systemÐû²¼ÁË2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ¡£±¨¸æÏÔʾ£¬½ü75£¥µÄ×éÖ¯µ£ÐÄÔÚ¼ÒÊÂÇé»á´øÀ´Ç徲Σº¦£¬73£¥µÄ×éÖ¯ÒÔΪԶ³ÌÊÂÇéÕß½ûÓÃÁËVPNºó£¬ËûÃǵÄÔ˶¯½«±äµÃ²»¿É¼û¡£±ðµÄ£¬µ±Óû§½«ÆäÊÂÇéµçÄÔÓÃÓÚСÎÒ˽¼ÒÓÃ;ºÍ¹«Ë¾ÓÃ;ʱ£¬ÔöÌíÁËÇý¶¯ÏÂÔØµÄΣº¦£¨25£¥£©£¬Óû§¸üÈÝÒ×ÊּܵÒÍ¥ÍøÂç´¹ÂڵĹ¥»÷£¨15£¥£©¡£×éÖ¯ÓÅÏÈ˼Á¿Ô¶³ÌÔ±¹¤Ô˶¯¿ÉÊÓÐÔ£¨34£¥£©£¬È»ºóÊÇˢеÄÍøÂçÆÊÎö£¨30£¥£©ºÍɱ¶¾ÒÔ¼°¶Ëµã¼ì²âºÍÏìÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.dtexsystems.com/blog/2021-remote-workforce-security-report-organizations-still-lack-confidence-in-security-practices/