GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó¦£»£»£»£»£»·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬»òÓëÌØ¹¤»î¶¯ÓйØ
Ðû²¼Ê±¼ä 2020-12-291.GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬²âÊÔÔ±¹¤µÄ·´Ó¦

GoDaddyÏòÔ±¹¤·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂç´¹ÂڻµÄ·´Ó¦¡£¡£¡£¡£¸Ã²âÊÔÓÚ12Ô¾ÙÐУ¬£¬£¬£¬ÓʼþÉù³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬£¬£¬£¬ÒÔ×ÊÖúÔ±¹¤Ó¦¶ÔÒòCOVID-19±¬·¢¶øµ¼Öµľ¼ÃÎÊÌ⣬£¬£¬£¬²¢ÒªÇóËûÃÇÌîдСÎÒ˽¼ÒÐÅÏ¢±í¸ñ¡£¡£¡£¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬£¬£¬£¬ËûÃǽ«±»ÒªÇóÖØÐ¼ÓÈëÉç»á¹¤³ÌÇå¾²ÒâʶµÄÅàѵ¡£¡£¡£¡£ÓÉÓÚ²âÊÔÖÐʹÓõÄÓÕ¶üºÍÄ£Äâʱ¼äµÄÑ¡Ôñ£¬£¬£¬£¬¸ÃÒªÁìÊܵ½Á˲¿·ÖÍøÂçÇå¾²ÕûÌåµÄÆ·ÆÀ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html
2.·ÒÀ¼Òé»áµÄϵͳÔâµ½¹¥»÷£¬£¬£¬£¬»òÓëÌØ¹¤»î¶¯ÓйØ

·ÒÀ¼Òé»á³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬¶à¸öÒéÔ±µÄµç×ÓÓʼþÕÊ»§Ôâµ½ÈëÇÖ¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020ÄêÇïÌ죬£¬£¬£¬Í³Ò»Ê±¼ä£¬£¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28¹¥»÷Á˲¿·ÖŲÍþÒé»á´ú±íºÍÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£·ÒÀ¼ÖÐÑëÐ̾¯£¨KRP£©³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÒé»áÄÚ²¿µÄITϵͳÔì³ÉÈκÎË𺦣¬£¬£¬£¬µ«Ò²²»ÊÇÒâÍâÈëÇÖ£¬£¬£¬£¬¿ÉÄÜÊǹú¼ÒºÚ¿Í¾ÙÐеÄÍøÂçÌØ¹¤»î¶¯µÄÒ»²¿·Ö¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬KRPÌåÏÖ²»¿ÉÈ·¶¨Êܺ¦ÕßÊýÄ¿£¬£¬£¬£¬Ò²Ã»ÓÐÌṩ¸ü¶àϸ½Ú¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/finland-says-hackers-accessed-mps-emails-accounts/
3.ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶

ͼÊéÍøÕ¾NetGalleyÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¹¥»÷±¬·¢ÓÚ2020Äê12ÔÂ21ÈÕ£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˸ÃÍøÕ¾²¢»á¼ûÁËNetGalleyÊý¾Ý¿âµÄ±¸·ÝÎļþ¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§µÇ¼ÃûºÍÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹ú¼Ò/µØÇø£¬£¬£¬£¬±ðµÄÉÐÓв¿·ÖÓû§µÄ¼òÀú¡¢Óʼĵص㡢µç»°ºÅÂë¡¢ÉúÈÕ¡¢¹«Ë¾Ãû³ÆºÍKindleµç×ÓÓʼþµØµã¡£¡£¡£¡£NetGalleyÌåÏÖ£¬£¬£¬£¬Ã»ÓÐÈκÎÓë²ÆÎñÓйصÄÊý¾Ýй¶¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/12/27/book-promotion-site-netgalley-disclosed-data-breach-following-website-defacement/
4.SolarWindsÐÞ¸´OrionÖеÄÎó²î£¨CVE-2020-10148£©

SolarWindsÐÞ¸´ÁËOrionÖб»×·×ÙΪCVE-2020-10148µÄRCEÎó²î¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚSolarWinds Orion APIÉí·ÝÑéÖ¤Äܹ»±»Èƹý£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚRequest.PathInfoURIÇëÇóÖÐʹÓÃÌØ¶¨²ÎÊýÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬×îÖÕ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐδ¾Éí·ÝÑéÖ¤µÄAPIÏÂÁî¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬SolarWindsÒѾÐû²¼ÁË´ËÎó²îµÄÇå¾²¸üУ¬£¬£¬£¬ÒÔÐÞ¸´SUNBURSTºÍSUPERNOVAÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory-for-new-supernova-malware/
5.FlatfileÐû²¼2020ÄêÊý¾ÝÐ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ

FlatfileÐû²¼ÁË2020ÄêÊý¾ÝÐ×÷µÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£Êý¾Ýµ¼È루Data onboarding£©Êǿͻ§Ð×÷ÖеÄÒ»¸öÒªº¦½×¶Î£¬£¬£¬£¬²úÆ·ºÍÖ§³ÖÍŶÓÐèÒªÎÞ·ìµØ½»¸¶Êý¾Ý£¬£¬£¬£¬À´Îª¿Í»§Ìṩ×î´óµÄÓªÒµ¼ÛÖµ¡£¡£¡£¡£¸Ã±¨¸æ¶Ô100¶à¼Ò¹«Ë¾¾ÙÐÐÁËÊӲ죬£¬£¬£¬²¢²É·ÃÁË5000¶àÃûÊÜ·ÃÕß¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬54£¥µÄÊÜ·ÃÕßÌìÌì¶¼ÔÚµ¼Èë»òÉÏ´«Êý¾Ý£¬£¬£¬£¬23£¥µÄÊÜ·ÃÕßÌåÏÖµ¼Èë¿Í»§Êý¾ÝÐèÒªÊýÖÜ»òÊýÔµÄʱ¼ä£¬£¬£¬£¬96£¥µÄÊÜ·ÃÕßÌåÏÖËûÃÇÔøÔÚµ¼ÈëÊý¾ÝʱÓöµ½ÁËÎÊÌâ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://flatfile.io/state-of-data-onboarding-2020/
6.DTEXÐû²¼2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ

DTEX systemÐû²¼ÁË2021ÄêÔ¶³ÌÊÂÇéµÄÇå¾²ÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬½ü75£¥µÄ×éÖ¯µ£ÐÄÔÚ¼ÒÊÂÇé»á´øÀ´Ç徲Σº¦£¬£¬£¬£¬73£¥µÄ×éÖ¯ÒÔΪԶ³ÌÊÂÇéÕß½ûÓÃÁËVPNºó£¬£¬£¬£¬ËûÃǵĻ½«±äµÃ²»¿É¼û¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬µ±Óû§½«ÆäÊÂÇéµçÄÔÓÃÓÚСÎÒ˽¼ÒÓÃ;ºÍ¹«Ë¾ÓÃ;ʱ£¬£¬£¬£¬ÔöÌíÁËÇý¶¯ÏÂÔØµÄΣº¦£¨25£¥£©£¬£¬£¬£¬Óû§¸üÈÝÒ×ÊּܵÒÍ¥ÍøÂç´¹ÂڵĹ¥»÷£¨15£¥£©¡£¡£¡£¡£×éÖ¯ÓÅÏÈ˼Á¿Ô¶³ÌÔ±¹¤»î¶¯¿ÉÊÓÐÔ£¨34£¥£©£¬£¬£¬£¬È»ºóÊÇˢеÄÍøÂçÆÊÎö£¨30£¥£©ºÍɱ¶¾ÒÔ¼°¶Ëµã¼ì²âºÍÏìÓ¦¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.dtexsystems.com/blog/2021-remote-workforce-security-report-organizations-still-lack-confidence-in-security-practices/


¾©¹«Íø°²±¸11010802024551ºÅ