Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬ÒÔÇÔÊØÐÅÓþ¿¨
°ä²¼¹¦·ò 2020-09-151.Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨

Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£»ã±¨ÏÔʾ£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£ÆäÖУ¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
2.Êý¾ÝÖÐÐÄEquinixϰȾNetwalker£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶

Êý¾ÝÍйÜÖÐÐÄEquinix°ä²¼ÉêÃ÷£¬°µÊ¾ÆäºÜ¶àÄÚ²¿ÏµÍ³Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬µ«ÆäΪ¿Í»§Ìṩ·þÎñµÄÖØÒªÖ÷ÌⲢδÊܵ½Ó°Ïì¡£Ö®ºó£¬ºÚ¿Í×éÖ¯Netwalker°µÊ¾Æä³É¹¦ÈëÇÖÁËEquinix²¢°ä²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬ÒÔ´ËÍþв֧¸¶450ÍòÃÀÔªµÄÊê½ð¡£Õâ´Îй©µÄÊý¾ÝÔ̺¬¹«Ë¾²ÆÕþÐÅÏ¢ºÍÊý¾ÝÖÐÐĻ㱨¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÀ´ÁúÈ¥Âö£¬Equinix°µÊ¾ÔÚ½øÐе÷²é¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-center-giant-equinix-discloses-ransomware-incident/
3.·ÇÖÞÈûÉà¶û¿ª·¢ÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅÏ¢¿ÉÄܱ»µÁ

·ÇÖÞÈûÉà¶ûÖÐÑëÒøÐУ¨CBS£©°ä·¢Ò»·ÝÐÂÎÅÉêÃ÷£¬ÈûÉà¶û¿ª·¢ÒøÐУ¨DBS£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§ÐÅÏ¢»òÒѱ»µÁ¡£Õâ´Î¹¥»÷²úÉúÓÚ2020Äê9ÔÂ9ÈÕ£¬¾ßÌåÐÅÏ¢»¹ÔÚµ÷²éÖ®ÖС£¹ÌȻĿǰÉв»Ã÷ÏÔ¹¥»÷ÕßÊÇ·ñÔÚ¼ÓÃÜÒøÐÐϵͳ֮ǰÇÔÈ¡ÁËÊý¾Ý£¬µ«Æ¾¾Ý¹¥»÷ÖÐʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬ºÜÓпÉÄܲúÉúÕâÖÖÇé¿ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/development-bank-of-seychelles-hit-by-ransomware-attack/
4.ÃÀ¹úÓÊÕþ²¿ÃÅITϵͳ´æÔÚ¶à¸ö·ì϶£¬¿Éµ¼ÖÂÊý¾Ýй¶

ÃÀ¹úÓÊÕþ²¿ÃŵÄÒ»·ÝÉó¼Æ»ã±¨·¢ÏÖ£¬¸Ã²¿ÃŵÄITϵͳ´æÔÚ¶à¸ö·ì϶£¬ÕâЩ·ì϶¿ÉÄܱ»ºÚ¿ÍÀûÓÃÀ´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¼à¹Ü»ú¹¹°µÊ¾£¬ÕâЩ·ì϶ÖÐÓÐ12¸ö¿àÄÑÐԵģ¬ËüÃÇ¿ÉÄÜ»á¸ø¸Ã»ú¹¹´øÀ´¾Þ´óµÄ¾¼ÃËðʧ£¬ÆäÖÐÔ̺¬³£¼ûµÄ¡¢Òѱ»¹«¿ªÈýÄêµÄ·ì϶¡£½ØÖÁĿǰ£¬»¹Ã»ÓÐÈκÎÖ¤¾ÝÅú×¢ÕâЩ·ì϶Òѱ»ºÚ¿ÍÀûÓá£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/postal-service-inspector-general-cyber-vulnerabilities/
5.×êÑÐÍŶӷ¢ÏÖÀûÓÃOffice 365 API´¹µö¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖÒ»ÖÖеÄÍøÂç´¹µö¹¥»÷»î¶¯£¬¹¥»÷Õß¿ÉÀûÓÃÉí·ÝÑéÖ¤APIʵʱÑéÖ¤Êܺ¦ÕßµÄOffice 365Í´´¦¡£Õâ´Î¹¥»÷ÖеĴ¹µöÓʼþÖ¸ÏòÓëOffice 365µÇ¼ҳһÑùµÄ´¹µöÍøÕ¾£¬²¢ÇÒÓû§ÃûÒÑÔ¤ÏÈÊäÈë¡£Ò»µ©Êܺ¦Õß½«ÆäÍ´´¦ÊäÈëµ½ÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬Azure Active DirectoryµÇ¼ÈÕÖ¾¾Í»áÏÔʾÓëÔÚ¸½¼þÍøÒ³ÉÏÖ´ÐеÄXHRÒªÇóÏà¶ÔӦȷµ±¼´µÇ¼³¢ÊÔ¡£ÈôÊÇÉí·ÝÑéÖ¤³É¹¦£¬Ôò½«Óû§³Á¶¨Ïòµ½zoom.com¡£ÈôÊÇÉí·ÝÑé֤ʧ°Ü£¬Ôò»á½«Óû§³Á¶¨Ïòµ½login.microsoftonline.com¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/office-365-phishing-attack-leverages-real-time-active-directory-validation/159188/
6.ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬ÒÔÇÔÊØÐÅÓþ¿¨

ÉÏÖÜÄ©£¬ÐÅÓþ¿¨ÇÔȡԤ·À¹«Ë¾Sanguine Security·¢´Ë¿Ì´ÓǰËÄÌìÖкڿÍÈëÇÖÁË1904¼ÒMagentoÔÚÏßÉ̵꣬ÒÔÇÔÊØÐÅÓþ¿¨¡£¹¥»÷ʼÓÚÉÏÖÜÎ壬ÆäʱÓÐ10¼ÒÉ̵êϰȾÁË´Óδ¼û¹ýµÄÐÅÓþ¿¨ÇÔÈ¡¾ç±¾¡£Ö®ºó£¬¹¥»÷ÔÚÖÜÁù¼¤Ôö£¬ÓÐ1058¸öÕ¾µã±»ºÚ¿ÍÈëÇÖ£¬ÔÚÖÜÈÕÓÐ603¸öÕ¾µã±»ÈëÇÖ£¬ÖÜÒ»ÓÐ233¸ö±»ÈëÇÖ¡£Sanguine Security°µÊ¾£¬ÕâÊÇ×Ô2015ÄêÆðÍ·¼à¿Øµç×ÓÉÌÎñÉ̵êÒÔÀ´£¬ËûÃÇËù¿´µ½µÄ×î´óµÄMagento¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magento-stores-hit-by-largest-automated-hacking-attack-since-2015/


¾©¹«Íø°²±¸11010802024551ºÅ