Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»£»£»£»£»ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨
°ä²¼¹¦·ò 2020-09-151.Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨

Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬£¬£¬£¬£¬£¬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬£¬£¬£¬£¬£¬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£¡£¡£¡£¡£¡£¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬£¬£¬£¬£¬£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öÊ·ý£¬£¬£¬£¬£¬£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/
2.Êý¾ÝÖÐÐÄEquinixϰȾNetwalker£¬£¬£¬£¬£¬£¬Ãô¸ÐÐÅÏ¢»òÒÑй¶

Êý¾ÝÍйÜÖÐÐÄEquinix°ä²¼ÉêÃ÷£¬£¬£¬£¬£¬£¬°µÊ¾ÆäºÜ¶àÄÚ²¿ÏµÍ³Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ«ÆäΪ¿Í»§Ìṩ·þÎñµÄÖØÒªÖ÷ÌⲢδÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯Netwalker°µÊ¾Æä³É¹¦ÈëÇÖÁËEquinix²¢°ä²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬ÒÔ´ËÍþв֧¸¶450ÍòÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¡£¡£Õâ´Îй©µÄÊý¾ÝÔ̺¬¹«Ë¾²ÆÕþÐÅÏ¢ºÍÊý¾ÝÖÐÐĻ㱨¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷µÄÀ´ÁúÈ¥Âö£¬£¬£¬£¬£¬£¬Equinix°µÊ¾ÔÚ½øÐе÷²é¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-center-giant-equinix-discloses-ransomware-incident/
3.·ÇÖÞÈûÉà¶û¿ª·¢ÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÐÅÏ¢¿ÉÄܱ»µÁ

·ÇÖÞÈûÉà¶ûÖÐÑëÒøÐУ¨CBS£©°ä·¢Ò»·ÝÐÂÎÅÉêÃ÷£¬£¬£¬£¬£¬£¬ÈûÉà¶û¿ª·¢ÒøÐУ¨DBS£©Ôâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§ÐÅÏ¢»òÒѱ»µÁ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÓÚ2020Äê9ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬¾ßÌåÐÅÏ¢»¹ÔÚµ÷²éÖ®ÖС£¡£¡£¡£¡£¡£¡£¹ÌȻĿǰÉв»Ã÷ÏÔ¹¥»÷ÕßÊÇ·ñÔÚ¼ÓÃÜÒøÐÐϵͳ֮ǰÇÔÈ¡ÁËÊý¾Ý£¬£¬£¬£¬£¬£¬µ«Æ¾¾Ý¹¥»÷ÖÐʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬£¬£¬£¬£¬£¬ºÜÓпÉÄܲúÉúÕâÖÖÇé¿ö¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/development-bank-of-seychelles-hit-by-ransomware-attack/
4.ÃÀ¹úÓÊÕþ²¿ÃÅITϵͳ´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÊý¾Ýй¶

ÃÀ¹úÓÊÕþ²¿ÃŵÄÒ»·ÝÉó¼Æ»ã±¨·¢ÏÖ£¬£¬£¬£¬£¬£¬¸Ã²¿ÃŵÄITϵͳ´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܱ»ºÚ¿ÍÀûÓÃÀ´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¼à¹Ü»ú¹¹°µÊ¾£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶ÖÐÓÐ12¸ö¿àÄÑÐԵ쬣¬£¬£¬£¬£¬ËüÃÇ¿ÉÄÜ»á¸ø¸Ã»ú¹¹´øÀ´¾Þ´óµÄ¾¼ÃËðʧ£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³£¼ûµÄ¡¢Òѱ»¹«¿ªÈýÄêµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬£¬»¹Ã»ÓÐÈκÎÖ¤¾ÝÅú×¢ÕâЩ·ì϶Òѱ»ºÚ¿ÍÀûÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/postal-service-inspector-general-cyber-vulnerabilities/
5.×êÑÐÍŶӷ¢ÏÖÀûÓÃOffice 365 API´¹µö¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖÒ»ÖÖеÄÍøÂç´¹µö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÉí·ÝÑéÖ¤APIʵʱÑéÖ¤Êܺ¦ÕßµÄOffice 365Í´´¦¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖеĴ¹µöÓʼþÖ¸ÏòÓëOffice 365µÇ¼ҳһÑùµÄ´¹µöÍøÕ¾£¬£¬£¬£¬£¬£¬²¢ÇÒÓû§ÃûÒÑÔ¤ÏÈÊäÈë¡£¡£¡£¡£¡£¡£¡£Ò»µ©Êܺ¦Õß½«ÆäÍ´´¦ÊäÈëµ½ÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬Azure Active DirectoryµÇ¼ÈÕÖ¾¾Í»áÏÔʾÓëÔÚ¸½¼þÍøÒ³ÉÏÖ´ÐеÄXHRÒªÇóÏà¶ÔÓ¦µÄÁ¢¼´µÇ¼³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉí·ÝÑéÖ¤³É¹¦£¬£¬£¬£¬£¬£¬Ôò½«Óû§³Á¶¨Ïòµ½zoom.com¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉí·ÝÑé֤ʧ°Ü£¬£¬£¬£¬£¬£¬Ôò»á½«Óû§³Á¶¨Ïòµ½login.microsoftonline.com¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/office-365-phishing-attack-leverages-real-time-active-directory-validation/159188/
6.ºÚ¿Í¹¥»÷½ü2000¼ÒMagentoÔÚÏßÉ̵꣬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨

ÉÏÖÜÄ©£¬£¬£¬£¬£¬£¬ÐÅÓþ¿¨ÇÔȡԤ·À¹«Ë¾Sanguine Security·¢´Ë¿Ì´ÓǰËÄÌìÖкڿÍÈëÇÖÁË1904¼ÒMagentoÔÚÏßÉ̵꣬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨¡£¡£¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÉÏÖÜÎ壬£¬£¬£¬£¬£¬ÆäʱÓÐ10¼ÒÉ̵êϰȾÁË´Óδ¼û¹ýµÄÐÅÓþ¿¨ÇÔÈ¡¾ç±¾¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬¹¥»÷ÔÚÖÜÁù¼¤Ôö£¬£¬£¬£¬£¬£¬ÓÐ1058¸öÕ¾µã±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ÔÚÖÜÈÕÓÐ603¸öÕ¾µã±»ÈëÇÖ£¬£¬£¬£¬£¬£¬ÖÜÒ»ÓÐ233¸ö±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£Sanguine Security°µÊ¾£¬£¬£¬£¬£¬£¬ÕâÊÇ×Ô2015ÄêÆðÍ·¼à¿Øµç×ÓÉÌÎñÉ̵êÒÔÀ´£¬£¬£¬£¬£¬£¬ËûÃÇËù¿´µ½µÄ×î´óµÄMagento¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magento-stores-hit-by-largest-automated-hacking-attack-since-2015/


¾©¹«Íø°²±¸11010802024551ºÅ