ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ£»£»£»£»£»£»GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿î1.26ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2020-01-21

1.ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿ÔºÐû²¼Òþ˽Σº¦ÖÎÀí¿ò¼Ü1.0°æ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú¹ú¼Ò±ê×¼ÊÖÒÕÑо¿Ôº£¨NIST£©ÉÏÖÜÐû²¼ÁËÒþ˽¿ò¼Ü1.0°æ£¬£¬£¬£¬£¬ £¬¸Ã¹¤¾ßÖ¼ÔÚ×ÊÖú×éÖ¯ÖÎÀíÒþ˽Σº¦¡£¡£¡£¡£NISTÓÚ2019Äê9ÔÂÐû²¼ÁËÒþ˽¿ò¼Ü³õ¸å²¢ÍøÂ繫ÖÚÒâ¼û£¬£¬£¬£¬£¬ £¬¸Ã»ú¹¹×î³õÏ£ÍûÔÚ2019Äêµ×֮ǰÐû²¼1.0°æ£¬£¬£¬£¬£¬ £¬µ«Ö±µ½1ÔÂ16ÈÕ²ÅÕýʽÐû²¼¡£¡£¡£¡£NISTÒþ˽¿ò¼ÜÖ¼ÔÚͨ¹ý¹Ø×¢Èý¸öÖ÷Òª·½ÃæÀ´×ÊÖúÖÖÖÖ¹æÄ£ºÍ¸÷¸ö²¿·ÖµÄ×éÖ¯ÖÎÀíÒþ˽Σº¦£ºÔÚ¿ª·¢²úÆ·»òЧÀÍʱҪ˼Á¿µ½Òþ˽¡¢½»Á÷Òþ˽ÀÏÀýÒÔ¼°¿ç×éÖ¯µÄЭ×÷¡£¡£¡£¡£¸Ã¿ò¼Ü°üÀ¨Èý¸öÖ÷Òª²¿·Ö£º½¹µã¡¢ÌáÒªºÍʵÏֲ㡣¡£¡£¡£½¹µãÌṩһ×éϸ»¯µÄ»î¶¯ºÍЧ¹û£¬£¬£¬£¬£¬ £¬ÆäÄ¿µÄÊÇʵÏÖÄÚ²¿Ïàͬ¡£¡£¡£¡£ÌáÒª²ãÌåÏÖ×éÖ¯ÒÑÈ·¶¨½¹µãÖ°ÄÜ¡¢ÖÖ±ðºÍ×ÓÀà±ðµÄÓÅÏȼ¶±ð¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ £¬ÊµÑé²ã¿É×ÊÖú×éÖ¯ÓÅ»¯ÊµÏÖÌáÒª²ãËùÐèµÄ×ÊÔ´¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nist-releases-framework-privacy-risk-management


2.GDPRî¿Ïµ»ú¹¹Æù½ñΪֹÒÑ·£¿£¿£¿£¿î1.26ÒÚÃÀÔª


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ò»ÏîеÄÊӲ췢Ã÷£¬£¬£¬£¬£¬ £¬Æù½ñΪֹî¿Ïµ»ú¹¹ÒѶÔÊý¾Ýй¶ºÍÆäËûGDPRÇÖȨÐÐΪ´¦ÒÔÁ˼ÛÖµ1.26ÒÚÃÀÔªµÄ·£¿£¿£¿£¿î¡£¡£¡£¡£Æ¾Ö¤DLA PiperµÄGDPRÊý¾ÝÎ¥¹æÊӲ죬£¬£¬£¬£¬ £¬Êý¾Ý±£»£»£»£»£»£»¤î¿Ïµ»ú¹¹ÔÚ2018Äê5ÔÂ25ÈÕÖÁ2020Äê1ÔÂ27ÈÕʱ´ú¶ÔGDPRÏà¹ØµÄ·£¿£¿£¿£¿îΪ1.14ÒÚÅ·Ôª£¨Ô¼ºÏ1.26ÒÚÃÀÔª/ 9,700ÍòÓ¢°÷£©¡£¡£¡£¡£Õâ¼Ò¹ú¼Ê״ʦÊÂÎñËùÖ¸³ö£¬£¬£¬£¬£¬ £¬·¨¹ú¡¢µÂ¹úºÍ°ÂµØÀûµÄ·£¿£¿£¿£¿î×ܶî×î¸ß£¬£¬£¬£¬£¬ £¬»®·ÖΪ5100ÍòÅ·Ôª£¬£¬£¬£¬£¬ £¬2450ÍòÅ·ÔªºÍ1800ÍòÅ·Ôª¡£¡£¡£¡£¸Ã±¨¸æ²¢Î´º­¸ÇÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¶ÔÓ¢¹úº½¿Õ¹«Ë¾£¨British Airways£©´¦ÒÔ1.83ÒÚÓ¢°÷µÄGDPR·£¿£¿£¿£¿î¼°¶ÔÍòºÀ¹ú¼Ê¹«Ë¾£¨Marriott International£©¾ÙÐÐ9990ÍòÓ¢°÷µÄGDPR·£¿£¿£¿£¿î£¬£¬£¬£¬£¬ £¬ÓÉÓÚ×èÖ¹±¨¸æÍê³ÉʱICOÉÐδ×îÖÕÈ·¶¨´¦ÒÔ·£¿£¿£¿£¿î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/gdpr-regulators-have-imposed-126m-in-fines-thus-far-finds-survey/


3.ÈýÁâµç»úÒÉÔâºÚ¿ÍÍÅ»ïBronze Butler¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤ÈýÁâµç»úÐû²¼µÄÒ»·Ý¼ò¶ÌµÄÉùÃ÷£¬£¬£¬£¬£¬ £¬È¥Äê6ÔÂ28Èոù«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ £¬Ö»¹Ü¸Ã¹«Ë¾ÓÚ9Ô·Ý×îÏÈÁËÕýʽµÄÄÚ²¿ÊӲ죬£¬£¬£¬£¬ £¬µ«Ö±µ½¿ËÈÕÍâµØÃ½Ì屨µÀÁ˸ÃÊÂÎñºó£¬£¬£¬£¬£¬ £¬ÈýÁâµç»ú²ÅÅû¶ÁË´ËÊÂÎñ¡£¡£¡£¡£Æ¾Ö¤ÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒÉΪºÚ¿ÍÍÅ»ïBronze Butler£¬£¬£¬£¬£¬ £¬ÈëÇÖ×îÏÈÓÚÒ»¸öÊÜѬȾµÄÔ±¹¤ÕË»§¡£¡£¡£¡£¡¶³¯ÈÕÐÂÎÅ¡·ºÍ¡¶ÈÕ¾­ÐÂÎÅ¡·³ÆºÚ¿Í»ñµÃÁËԼĪ14¸ö¹«Ë¾²¿·Ö£¨ÀýÈçÏúÊÛºÍ×ܹ«Ë¾£©µÄÍøÂç»á¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬²¢ÇÔÈ¡ÁËÔ¼200MBµÄÎļþ£¬£¬£¬£¬£¬ £¬ÆäÖд󲿷ÖÊÇÉÌÒµÎļþ¡£¡£¡£¡£ÈýÁâµç»úÌåÏÖ£¬£¬£¬£¬£¬ £¬ºÚ¿ÍûÓлñµÃÓйعú·ÀÌõÔ¼µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mitsubishi-electric-discloses-security-breach-china-is-main-suspect/


4.ÃÀ¹ú¶ùͯ´ò°çÖÆÔìºÍÁãÊÛÉÌHanna AnderssonÔâµ½Magecart¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú¶ùͯ´ò°çÖÆÔìºÍÔÚÏßÁãÊÛÉ̺ºÄÈ¡¤°²µÂÉ­£¨Hanna Andersson£©ÌåÏÖÆäÔÚÏß¹ºÎïÆ½Ì¨Ôâµ½Magecart¹¥»÷¡£¡£¡£¡£ÊÂÎñÔµ¹ÊÔ­ÓÉÊÇHanna AnderssonʹÓõĵÚÈý·½µç×ÓÉÌÎñƽ̨Salesforce Commerce CloudѬȾÁËÇÔÈ¡¿Í»§Ö§¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂ룬£¬£¬£¬£¬ £¬ÊÓ²ìְԱȷÈϵÄ×îÔçΣº¦ÈÕÆÚÊÇ2019Äê9ÔÂ16ÈÕ£¬£¬£¬£¬£¬ £¬¸Ã¶ñÒâ´úÂëÓÚ2019Äê11ÔÂ11ÈÕ±»É¾³ý¡£¡£¡£¡£Hanna Andersson֪ͨ³Æ¸ÃÊÂÎñ¿ÉÄÜÓ°ÏìÁ˿ͻ§ÔÚwww.hannaandersson.comÉÏÌá½»µÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬°üÀ¨ÐÕÃû¡¢ÔËÊ䵨µã¡¢Õ˵¥µØµã¡¢¸¶¿î¿¨ºÅ¡¢CVVÂëºÍÓÐÓÃÆÚ¡£¡£¡£¡£ÏÖÔÚÖ´·¨²¿·ÖÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ졣¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-retailer-hanna-andersson-hacked-to-steal-credit-cards/


5.Ó¢¹úÕþ¸®Ïò²©²Ê¹«Ë¾Ìṩ2800Íò¶ùͯÐÅÏ¢µÄ»á¼ûȨÏÞ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤¡¶ÐÇÆÚÈÕÌ©ÎîÊ¿±¨¡·¾ÙÐеÄÒ»ÏîÊӲ죬£¬£¬£¬£¬ £¬²©²Ê¹«Ë¾±»²»ÊÊÍâµØÌṩÁË´ÓÕþ¸®Êý¾Ý¿âÖлá¼û¶ùͯÐÅÏ¢µÄȨÏÞ£¬£¬£¬£¬£¬ £¬¸ÃÊý¾Ý¿â°üÀ¨2800Íò¶ùͯµÄÐÅÏ¢¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÉÓ¢¹ú½ÌÓý²¿£¨DfE£©ÈÏÕæ£¬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨¹«Á¢ºÍ˽Á¢Ñ§Ð£ÒÔ¼°È«Ó¢¸÷´óѧÖÐ14Ëê¼°ÒÔÉÏδ³ÉÄêÈ˵ÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬ £¬Ö¼ÔÚÓÃÓÚÅàѵºÍ½ÌÓýÓÃ;¡£¡£¡£¡£Æ¾Ö¤ÊӲ죬£¬£¬£¬£¬ £¬Ò»¼ÒÏàÖúͬ°é¹«Ë¾Î´¾­ÔÊÐí¾Í½«Êý¾Ý¿âÖеÄÐÅÏ¢»á¼ûȨÏÞÌṩӦÁ˲©²Ê¼¯ÍÅ£¬£¬£¬£¬£¬ £¬Ê¹¶Ä²©¹«Ë¾¿ÉÒÔʹÓÃÕâЩÊý¾Ý¾ÙÐпìËÙµÄÔÚÏßÉí·ÝÑéÖ¤ºÍÄêËê¼ì²é¡£¡£¡£¡£¾Ý³ÆÐ¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢ÄêËêºÍÏÖʵµØµã¡£¡£¡£¡£ÒԺ󣬣¬£¬£¬£¬ £¬DfEÒѽûÓöԸÃÊý¾Ý¿âµÄ»á¼û¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/betting-companies-given-free-rein-with-data-of-28-million-children/


6.WP Database Reset²å¼þÎó²î¿Éµ¼ÖÂÍøÕ¾±»½ÓÊÜ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


WordfenceÇå¾²Ñо¿Ö°Ô±ÔÚWordPress²å¼þWP Database ResetÖз¢Ã÷ÁËÁ½¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î½ÓÊÜÊÜÓ°ÏìµÄÍøÕ¾¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2020-7048£©µÄCVSSÆÀ·ÖΪ9.1·Ö£¬£¬£¬£¬£¬ £¬ÆäÔµ¹ÊÔ­ÓÉÊÇûÓб£»£»£»£»£»£»¤ÈκÎÊý¾Ý¿âÖØÖù¦Ð§£¬£¬£¬£¬£¬ £¬Õâ¿ÉÄÜʹµÃÈκÎÓû§ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÖØÖÃÈκÎÊý¾Ý¿â±í¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2020-7047£©µÄCVSSÆÀ·ÖΪ8.1·Ö£¬£¬£¬£¬£¬ £¬Èκξ­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¾ù¿Éͨ¹ýÖØÖÃwp_users±íÀ´É¾³ýËùÓÐÆäËûÓû§ºÍÉý¼¶ÎªÖÎÀíÌØÈ¨¡£¡£¡£¡£¿£¿£¿£¿ª·¢ÍŶÓÒѾ­ÔÚWP Database Reset×îа汾3.15ÖÐÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96611/hacking/wp-database-reset-wordpress-flaws.html