ÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ·çÏÕÖÎÀí¿ò¼Ü1.0°æ£»GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª

°ä²¼¹¦·ò 2020-01-21

1.ÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ·çÏÕÖÎÀí¿ò¼Ü1.0°æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¶È³ß¶È¼¼Êõ×êÑÐÔº£¨NIST£©ÉÏÖܰ䲼ÁËÒþÖÔ¿ò¼Ü1.0°æ £¬¸Ã¹¤¾ßÖ¼ÔÚÔ®ÊÖ×éÖ¯ÖÎÀíÒþÖÔ·çÏÕ¡£NISTÓÚ2019Äê9Ô°䲼ÁËÒþÖÔ¿ò¼Ü³õ¸å²¢ÍøÂ繫¼Ò¶¨¼û £¬¸Ã»ú¹¹×î³õµ«Ô¸ÔÚ2019Äêµ×֮ǰ°ä²¼1.0°æ £¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽ°ä²¼¡£NISTÒþÖÔ¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖØÒª·½ÃæÀ´Ô®ÊÖ¸÷Àà¹æÄ£ºÍ¸÷¸ö²¿ÃŵÄ×éÖ¯ÖÎÀíÒþÖÔ·çÏÕ£ºÔÚ¿ª·¢²úÆ·»ò·þÎñʱҪ˼¿¼µ½ÒþÖÔ¡¢»¥»»ÒþÖÔͨÀýÒÔ¼°¿ç×éÖ¯µÄºÏ×÷¡£¸Ã¿ò¼ÜÔ̺¬Èý¸öÖØÒª²¿ÃÅ£ºÖ÷Ìâ¡¢¸ÅÒªºÍʵÏֲ㡣Ö÷ÌâÌṩһ×éϸ»¯µÄ»î¶¯ºÍÁ˾Ö £¬ÆäÖ÷ÕÅÊÇʵÏÖÄÚ²¿¹µÍ¨¡£¸ÅÒª²ã°µÊ¾×éÖ¯ÒÑÈ·¶¨Ö÷ÌâÖ°ÄÜ¡¢Àà±ðºÍ×ÓÀà´ËÍâÓÅÏȼ¶±ð¡£×îºó £¬Ö´Ðвã¿ÉÔ®ÊÖ×éÖ¯ÓÅ»¯ÊµÏÖ¸ÅÒª²ãËùÐèµÄ×ÊÔ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nist-releases-framework-privacy-risk-management


2.GDPR¼à¹Ü»ú¹¹Æù½ñΪֹÒÑ·£¿î1.26ÒÚÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò»Ïîеĵ÷²é·¢ÏÖ £¬Æù½ñΪֹ¼à¹Ü»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿î¡£Æ¾¾ÝDLA PiperµÄGDPRÊý¾ÝÎ¥¹æµ÷²é £¬Êý¾Ý±£»¤¼à¹Ü»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕÆÚ¼ä¶ÔGDPRÓйصķ£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£Õâ¼Ò¹ú¼ÊÂÉʦÊÂÎñËùÖ¸³ö £¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿î×ܶî×î¸ß £¬±ðÀëΪ5100ÍòÅ·Ôª £¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¸Ã»ã±¨²¢Î´º­¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©½øÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿î £¬ÓÉÓÚ½ØÖÁ»ã±¨ÊµÏÖʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿î¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/


3.ÈýÁâµç»úÒÉÔâºÚ¿ÍÍÅ»ïBronze Butler¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÈýÁâµç»ú°ä²¼µÄÒ»·Ý¼ò¶ÌµÄÉêÃ÷ £¬È¥Äê6ÔÂ28Èոù«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ £¬Ö»¹Ü¸Ã¹«Ë¾ÓÚ9ÔÂ·ÝÆðÍ·ÁËÕýʽµÄÄÚ²¿µ÷²é £¬µ«Ö±µ½½üÈÕ±¾µØÃ½Ì屨·Á˸ÃÊÂÎñºó £¬ÈýÁâµç»ú²ÅÅû¶ÁË´ËÊÂÎñ¡£Æ¾¾Ý±¾µØÃ½Ì屨· £¬¹¥»÷ÕßÒÉΪºÚ¿ÍÍÅ»ïBronze Butler £¬ÈëÇÔìðÍ·ÓÚÒ»¸öÊÜϰȾµÄÔ±¹¤ÕË»§¡£¡¶³¯ÈÕÐÂÎÅ¡·ºÍ¡¶ÈÕ¾­ÐÂÎÅ¡·³ÆºÚ¿Í»ñµÃÁËԼĪ14¸ö¹«Ë¾²¿ÃÅ£¨ÀýÈçÏúÊÛºÍ×ܹ«Ë¾£©µÄÍøÂç½Ó¼ûȨÏÞ £¬²¢ÇÔÈ¡ÁËÔ¼200MBµÄÎļþ £¬ÆäÖдó²¿ÃÅÊÇóÒ×Îļþ¡£ÈýÁâµç»ú°µÊ¾ £¬ºÚ¿ÍûÓлñµÃÓйعú·ÀºÏͬµÄÃô¸ÐÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mitsubishi-electric-discloses-security-breach-china-is-main-suspect/


4.ÃÀ¹ú¶ùͯ·þ×°Ôì×÷ºÍÁãÊÛÉÌHanna AnderssonÔâµ½Magecart¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¶ùͯ·þ×°Ôì×÷ºÍÔÚÏßÁãÊÛÉ̺ºÄÈ¡¤°²µÂÉ­£¨Hanna Andersson£©°µÊ¾ÆäÔÚÏß¹ºÎïÆ½Ì¨Ôâµ½Magecart¹¥»÷¡£ÊÂÎñÔ­ÒòÊÇHanna AnderssonʹÓõĵÚÈý·½µç×ÓÉÌÎñƽ̨Salesforce Commerce CloudϰȾÁËÇÔÈ¡¿Í»§Ö§¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂë £¬µ÷²éÈËԱȷÈϵÄ×îÔç·çÏÕÈÕÆÚÊÇ2019Äê9ÔÂ16ÈÕ £¬¸Ã¶ñÒâ´úÂëÓÚ2019Äê11ÔÂ11ÈÕ±»É¾³ý¡£Hanna Andersson֪ͨ³Æ¸ÃÊÂÎñ¿ÉÄÜÓ°ÏìÁ˿ͻ§ÔÚwww.hannaandersson.comÉÏÌá½»µÄÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢ÔËÊ䵨ַ¡¢Õ˵¥µØÖ·¡¢¸¶¿î¿¨ºÅ¡¢CVVÂëºÍÓÐЧÆÚ¡£Ä¿Ç°·¨Âɲ¿ÃÅÔÚ¶Ô´ËÊÂÎñ½øÐе÷²é¡£



Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-retailer-hanna-andersson-hacked-to-steal-credit-cards/


5.Ó¢¹úµ±¾ÖÏò²©²Ê¹«Ë¾Ìṩ2800Íò¶ùͯÐÅÏ¢µÄ½Ó¼ûȨÏÞ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¡¶ÐÇÆÚÈÕÌ©ÎîÊ¿±¨¡·½øÐеÄÒ»Ïîµ÷²é £¬²©²Ê¹«Ë¾±»²»Êʱ¾µØÌṩÁË´ÓµÐÔÖÊý¾Ý¿âÖнӼû¶ùͯÐÅÏ¢µÄȨÏÞ £¬¸ÃÊý¾Ý¿âÔ̺¬2800Íò¶ùͯµÄÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÉÓ¢¹ú½ÌÓý²¿£¨DfE£©ÕƹÜ £¬ÆäÖÐÔ̺¬¹«Á¢ºÍ˽Á¢Ñ§ÌÃÒÔ¼°È«Ó¢¸÷´óѧÖÐ14Ëê¼°ÒÔÉÏδ³ÉÄêÈ˵ľßÌåÐÅÏ¢ £¬Ö¼ÔÚÓÃÓÚÅàѵºÍ½ÌÓýÓô¦¡£Æ¾¾Ýµ÷²é £¬Ò»¼ÒºÏ×÷ͬ°é¹«Ë¾Î´¾­Ðí¿É¾Í½«Êý¾Ý¿âÖеÄÐÅÏ¢½Ó¼ûȨÏÞÌṩ¸øÁ˲©²Ê¼¯ÍÅ £¬Ê¹´ò¶Ä¹«Ë¾Äܹ»ÀûÓÃÕâЩÊý¾Ý½øÐм±¾çµÄÔÚÏßÉí·ÝÑéÖ¤ºÍ´ºÇï²é³­¡£¾Ý³ÆÐ¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢´ºÇïºÍÏÖʵµØÖ·¡£¶ûºó £¬DfEÒѽûÓöԸÃÊý¾Ý¿âµÄ½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/betting-companies-given-free-rein-with-data-of-28-million-children/


6.WP Database Reset²å¼þ·ì϶¿Éµ¼ÖÂÍøÕ¾±»ÊÕÊÜ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Wordfence°²È«×êÑÐÈËÔ±ÔÚWordPress²å¼þWP Database ResetÖз¢ÏÖÁËÁ½¸ö°²È«·ì϶ £¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ÊÕÊÜÊÜÓ°ÏìµÄÍøÕ¾¡£µÚÒ»¸ö·ì϶£¨CVE-2020-7048£©µÄCVSSÆÀ·ÖΪ9.1·Ö £¬ÆäÔ­ÒòÊÇûÓб£»¤ÈκÎÊý¾Ý¿â³ÁÖÃÖ°ÄÜ £¬Õâ¿ÉÄÜʹµÃÈκÎÓû§ÎÞÐèÉí·ÝÑéÖ¤¼´¿É³ÁÖÃÈκÎÊý¾Ý¿â±í¡£µÚ¶þ¸ö·ì϶£¨CVE-2020-7047£©µÄCVSSÆÀ·ÖΪ8.1·Ö £¬Èκξ­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¾ù¿Éͨ¹ý³ÁÖÃwp_users±íÀ´É¾³ýËùÓÐÆäËûÓû§ºÍÉý¼¶ÎªÖÎÀíÌØÈ¨¡£¿ª·¢ÍŶÓÒѾ­ÔÚWP Database Reset×îа汾3.15Öн¨¸´ÁËÕâÁ½¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96611/hacking/wp-database-reset-wordpress-flaws.html