Mimecast³ÆSolarWindsºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂ룻ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Î¥·´GDPR±»·£¿î½üǧÍòÃÀÔª

Ðû²¼Ê±¼ä 2021-03-18

1.Mimecast³ÆSolarWindsºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂë


1.jpg


µç×ÓÓʼþÄþ¾²¹«Ë¾Mimecast³ÆSolarWinds±³ºóµÄºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂë¡£ÔçÔÚ2020Äê1Ô£¬Mimecast·¢ÏÖÆäÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£3ÔÂ16ÈÕ£¬¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆºÚ¿Í»¹ÇÔÈ¡ÁËÓʼþµØÖ·ºÍƾ֤µÈÐÅÏ¢£¬ÒÔ¼°²¿ÃÅÔ´´úÂë¡£µ«ÊǺڿͲ¢Î´¶ÔÔ´´úÂë½øÐÐÈκÎÐ޸쬶øÇÒÓÉÓÚÆäÇÔÈ¡µÄÔ´´úÂë²»ÍêÕû£¬¿ÉÄÜÎÞ·¨¿ª·¢³öMimecast·þÎñµÄÈκÎ×é¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mimecast-solarwinds-hackers-stole-some-of-our-source-code/


2.Descartes AljexÒòAWS S3ÅäÖôíÎóй¶103GBÊý¾Ý


2.jpg


Website Planet·¢ÏÖÔËÊä¹ÜÀíÈí¼þDescartes AljexÒòAWS S3´æ´¢Í°ÅäÖôíÎóй¶ÁË103 GBÊý¾Ý¡£´Ë´ÎʼþÓ°ÏìÁ˸ù«Ë¾µÄ¿Í»§¡¢Ô±¹¤¡¢ÏúÊÛ´ú±íÒÔ¼°ÎªµÚÈý·½Ô±¹¤£¬Ð¹Â¶ÁËÐÕÃû¡¢µç»°ºÅÂ룬µç×ÓÓʼþµØÖ·£¬AljexÓû§ÃûºÍ´¿Îı¾ÃÜÂëµÈ¸öÈËÐÅÏ¢£¬ºÍÊÕ¼þÈËÐÕÃû¡¢»õ¼þÆðÔ˵غÍÄ¿µÄµØ¡¢µØÖ·ºÍµç»°ºÅÂëµÈ»õ¼þÐÅÏ¢¡£Website PlanetÓÚ2020Äê12ÔÂ24ÈÕ·¢ÏÖ¸ÃÎÊÌ⣬Ŀǰ¸Ã´æ´¢Í°ÒѾ­±»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/shipping-management-software-firm-data-online/


3.Sucuri·¢ÏÖÀûÓÃJPGÒþ²ØÐÅÓÿ¨Êý¾ÝµÄMagecart¹¥»÷»î¶¯


3.jpg


ÍøÕ¾Äþ¾²¹«Ë¾SucuriµÄÑо¿ÈËÔ±ÔÚ¶ÔÊÜѬȾµÄMagento 2µç×ÓÉÌÎñÍøÕ¾½øÐÐÊÓ²ìʱ£¬·¢ÏÖMagecart¹¥»÷ÕßÀûÓÃJPGÒþ²ØÐÅÓÿ¨Êý¾Ý¡£Magecart¹¥»÷ʼÓÚ¼¸Äêǰ£¬ºÚ¿ÍÀûÓöñÒâ´úÂëÔÚÓû§½áÕÊʱÇÔÈ¡ÆäÐÅÓÿ¨Êý¾Ý¡£Ôڴ˴εķ¢ÏֵĹ¥»÷»î¶¯ÖУ¬ºÚ¿Í²¢Ã»ÓÐÁ¢¼´½«Êý¾Ý·¢Ë͵½ËûÃǵķþÎñÆ÷£¬¶øÊǽ«ÆäÒþ²ØÔÚÊÜѬȾµÄÍøÕ¾µÄJPGͼÏñÖУ¬´Ó¶ø¼õÉÙ¿ÉÒÉÁ÷Á¿£¬ÒÔÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115655/hacking/magecart-credit-card-jpg.html


4.°ÍÈûÂÞÄÇÒÉËÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÊÐÕþϵͳ̱»¾


4.jpg


°ÍÈûÂÞÄÇ£¨AMB£©ÒÉËÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÆäÊý×Ö·þÎñ±»ÆÈÔÝÍ£¡£¸ÃÊÐÓÚ3ÔÂ10ÈÕ¼ì²âµ½´Ë´Î¹¥»÷£¬ÎªÁË·ÀÖ¹¶ñÒâÈí¼þµÄÁ÷´«£¬¸ÃÊÐÖжÏÁËÊÐÕþϵͳ£¬°üÂ޵绰·þÎñ¡¢ÆäËûÊý×Ö·þÎñºÍÍøÕ¾¡£AMB·¢ÑÔÈËÌåÏÖ£¬´Ë´Î¹¥»÷»î¶¯ÓëSEPEÉÏÖÜÔâÊܵĹ¥»÷ÓÐËù²îÒ죬µ«·Ç³£ÏàËÆ¡£Ä¿Ç°£¬¸ÃʼþÈÔÔÚÊÓ²ìÖС£


Ô­ÎÄÁ´½Ó£º

https://www.muyseguridad.net/2021/03/16/area-metropolitana-de-barcelona/amp/


5.ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Î¥·´GDPR±»·£¿î½üǧÍòÃÀÔª


5.jpg


µçÐŹ«Ë¾ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾ÒòÎ¥·´GDPR±»·£¿î½üǧÍòÃÀÔª¡£¸Ã¹«Ë¾ÒòʹÓò»Êʵ±µÄµç»°ÏúÊÛ¼ÆÄ±ÒÔ¼°Î´Äܱ£»¤Êý¾Ý¶øµ¼ÖÂÁË4Ïî·£¿î£¬¹²¼Æ972ÍòÃÀÔª¡£ ǰÁ½Ïî·£¿îÓ롶ͨÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©ÓйØ£¬×ܼÆ716ÍòÃÀÔª¡£µÚÈýÏî·£¿îÓëÎ÷°àÑÀÊý×Ö°æÈ¨ºÍµçÐŵÄÖ´·¨ÒÔ¼°GDPRÓйØ£¬Îª239ÍòÃÀÔª¡£µÚËÄÏî·£¿îÉæ¼°Î÷°àÑÀCookieµÄÖ´·¨£¬Îª17.9ÍòÃÀÔª¡£´Ó2018Äê1Ôµ½2020Äê2Ô£¬ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Òѱ»¾¯¸æ»ò·£¿î50¶à´Î¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/aepd-issues-highest-ever-fine/


6.CISAºÍFBIÁªºÏÐû²¼¹ØÓÚTrickBot¶ñÒâÈí¼þµÄÄþ¾²×Éѯ


6.jpg


CISAºÍÁª°îÊÓ²ì¾Ö£¨FBI£©Ðû²¼ÁËÓйØTrickBot¶ñÒâÈí¼þµÄÁªºÏÍøÂçÄþ¾²×Éѯ£¨CSA£©¡£¸Ã×Éѯ½éÉÜÁËTrickBotµÄ¼¼Êõϸ½Ú¡¢MITRE ATT&CK Techniques¡¢Õì²ìÊý¾ÝÒÔ¼°»º½â´ëÊ©¡£TrickBotÊÇÒ»Öָ߼¶Ä¾Âí£¬Í¨¹ýÓã²æÊ½µöÓã»î¶¯£¬Ê¹ÓðüÂÞ¶ñÒ⸽¼þ»òÁ´½ÓµÄÌØÖÆµç×ÓÓʼþÀ´Á÷´«¡£¸ÃÄþ¾²×Éѯ½¨Òé×éÖ¯×èÖ¹¿ÉÒɵÄInternetЭÒ鵨ַ¡¢Ê¹ÓÃɱ¶¾Èí¼þÒÔ¼°ÎªÔ±¹¤ÌṩÉç»á¹¤³ÌºÍÍøÂçµöÓãÅàѵµÈ·½Ê½À´·À·¶´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/03/17/cisa-fbi-joint-advisory-trickbot-malware-0