Yakaomarara, isina njodzi, isina kurongeka: cyber kutyisidzira 2020

Yakaomarara, isina njodzi, isina kurongeka: cyber kutyisidzira 2020

Tekinoroji dzinokura uye dzinowedzera kuoma gore negore, uye pamwe chete navo, maitiro ekurwisa anovandudza. Chokwadi chemazuva ano chinoda maapplication epamhepo, masevhisi emakore uye mapuratifomu ekuona, saka hazvichagoneke kuvanda kuseri kwefirewall yemakambani uye kusanamira mhino yako mu "Internet ine njodzi". Zvese izvi, pamwe nekupararira kweIoT/IIoT, kuvandudzwa kwefintech uye kukurumbira kuri kuita basa riri kure, kwachinja mamiriro ekutyisidzira kupfuura kuzivikanwa. Ngatitaurei nezve cyber kurwiswa kwakatichengeterwa 2020.

Kushandiswa kwe0day kusagadzikana kuchapfuura kuburitswa kwezvigamba

Kuoma kwemasoftware system kuri kukura, saka ivo vane zvikanganiso zvisingaite. Vagadziri vanosunungura zvigadziriso, asi kuti vaite izvi, dambudziko rinofanira kutanga raonekwa, kushandisa nguva yezvikwata zvine hukama - vayedzi vakafanana vanomanikidzwa kuita bvunzo. Asi zvikwata zvakawanda zvine nguva shoma. Mhedzisiro yacho ndeyekurebesa chigamba kuburitswa, kana kunyange chigamba chinoshanda zvishoma.

Yakaburitswa muna 2018 Chigamba chekusagadzikana kwe0day muinjini yeMicrosoft Jet chaive chisina kukwana, i.e. haina kubvisa dambudziko racho zvachose.
Muna 2019, Cisco yakaburitswa zvigamba zvekusagadzikana CVE-2019-1652 uye CVE-2019-1653 mune router firmware iyo isina kugadzirisa zvikanganiso..
MunaGunyana 2019, vaongorori akawana kusagadzikana kwe0day muDropbox yeWindows uye akazivisa vanogadzira nezvazvo, zvisinei, havana kugadzirisa kukanganisa mukati memazuva makumi mapfumbamwe.

Blackhat neWhitehat hackers vakatarisa kutsvaga kusasimba, saka ivo vanogona kunge vari vekutanga kuwana dambudziko. Vamwe vavo vanotsvaga kugashira mibairo kuburikidza neBug Bounty zvirongwa, nepo vamwe vachiteedza zvakanangana zvibodzwa zvakaipa.

More deepfake attack

Neural network uye artificial intelligence zviri kusimukira, zvichigadzira mikana mitsva yekubiridzira. Kutevera enhema mavhidhiyo ezvinonyadzisira nevanhu vane mukurumbira, kurwiswa chaiko nekukuvara kwakakomba kwezvinhu kwakaonekwa.

Muna Kurume 2019Matsotsi akaba $243 kubva kukambani yemagetsi munhare imwe chete. β€œMukuru wekambani yevabereki” akarayira mukuru webazi kuendesa mari kumugadziri wekondirakiti aibva kuHungary. Inzwi raMkuru Mukuru rakanga rakanyepera kushandisa hungwaru hwekugadzira.

Tichifunga nekukurumidza kusimudzira tekinoroji yakadzika, tinogona kutarisira kuti cyber-villains ichabatanidza kusikwa kwemanyepo odhiyo nevhidhiyo mukurwiswa kweBEC uye hunyanzvi hwekutsigira tekinoroji kuwedzera kuvimba kwevashandisi.

Zvinangwa zvikuru zvezvakadzika fakes zvichave vatungamiri vepamusoro, sezvo kurekodha kwehurukuro dzavo uye kutaura kunowanikwa pachena.

Kurwiswa mumabhangi kuburikidza nefintech

Kugamuchirwa kweEuropean payment services directive PSD2 kwakaita kuti zvikwanise kuita mhando itsva dzekurwiswa kumabhanga nevatengi vavo. Izvi zvinosanganisira mishandirapamwe yekunyengedzera kune vashandisi vefintech application, DDoS kurwisa fintech kutanga, uye kuba kwedata kubva kubhangi kuburikidza neyakavhurika API.

Kurwiswa kwakanyanya kuburikidza nevanopa masevhisi

Makambani ari kuramba achidzikisira hunyanzvi hwavo, achiburitsa zvisiri zvepakati zviitiko. Vashandi vavo vanokudziridza kuvimba kune vekunze vanobata accounting, vanopa rutsigiro rwehunyanzvi, kana kupa chengetedzo. Nekuda kweizvozvo, kurwisa kambani, zvakaringana kukanganisa mumwe wevanopa masevhisi kuitira kuti vaunze kodhi ine hutsinye mune inotarirwa zvivakwa kuburikidza nayo uye kuba mari kana ruzivo.

Muna Nyamavhuvhu 2019, matsotsi akapinda muzvivakwa zvemakambani maviri eIT achipa kuchengetedza data uye masevhisi ekuchengetedza, uye kuburikidza nazvo. yakaunza ransomware mumazana akati wandei emahofisi emazino muUnited States.
Kambani yeIT inoshandira Bazi reMapurisa reNew York City yakapwanya dhatabhesi yayo yezvigunwe kwemaawa akati wandei. nekubatanidza ine hutachiona Intel NUC mini-kombuta kune network yemapurisa.

Sezvo macheni ekupa achiwedzera kureba, kune mamwe malink asina kusimba anogona kushandiswa kurwisa mutambo mukuru.
Chimwe chinhu chinozofambisa kurwiswa kweketani ichave kutorwa kwakapararira kwebasa riri kure. Freelancers vanoshanda paruzhinji Wi-Fi kana kubva kumba zviri nyore zvinangwa, uye vanogona kudyidzana nemakambani akati wandei akakomba, saka zvishandiso zvavo zvakakanganisika zvinova chitubu chiri nyore chekugadzirira uye kuita nhanho dzinotevera dzekurwiswa kwecyber.

Kushandiswa kwakapararira kweIoT/IIoT kweespionage uye kupamba

Kukura nekukurumidza kwehuwandu hwemidziyo yeIoT, kusanganisira maTV akangwara, vatauri vakangwara uye vakasiyana-siyana vabatsiri vezwi, pamwe nenhamba huru yekusagadzikana yakaonekwa mavari, ichagadzira mikana yakawanda yekushandiswa kwavo zvisina mvumo.
Kukanganisa zvigadziriso zvine hungwaru uye kuziva kutaura kwevanhu vachishandisa AI kunoita kuti zvikwanise kuona tarisiro yekuongororwa, iyo inoshandura michina yakadaro kuita kit yekubira kana corporate espionage.

Imwe nzira iyo maIoT acharamba achishandiswa kugadzira mabhoti emhando dzakasiyana siyana dzecyber masevhisi: spamming, kusazivikanwa uye kuita. DDoS inorwisa.
Huwandu hwekurwiswa kwezvivakwa zvakakosha zvivakwa zvine zvikamu zvichawedzera indasitiri internet yezvinhu. Chinangwa chavo chinogona kunge chiri, semuenzaniso, kutora rudzikinuro mukutyisidzirwa kwekumisa kushanda kwebhizinesi.

Makore akawanda, njodzi dzinowedzera

Kufamba kukuru kweIT zvivakwa kune gore kunotungamira mukubuda kwezvinangwa zvitsva zvekurwiswa. Zvikanganiso mukuendesa uye kumisikidzwa kwemaseva egore zvinobudirira kushandiswa nevanorwisa. Huwandu hwekuvuza kwakabatana nekusachengeteka dhatabhesi marongero ari mugore ari kukura gore rega rega.

Muna Gumiguru 2019, sevha yeElasticSearch ine 4 bhiriyoni marekodhi ane data rako pachako.
Pakupera kwaNovember 2019 muMicrosoft Azure gore, dhatabhesi yekambani yeChokwadi Dialog yakawanikwa munzvimbo yeruzhinji, ine marekodhi angangoita bhiriyoni., iyo yaiva nemazita akazara evanyoreri, kero dzeemail uye nhamba dzenhare, pamwe chete nemagwaro emashoko eSMS.

Kudonha kwedata rakachengetwa mumakore hakuzongokuvadza mukurumbira wemakambani, asi zvakare kunotungamira mukuiswa kwefaindi uye zvirango.

Kusakwana kwezvirambidzo zvekupinda, kutadza kutonga kwemvumo, uye kutema miti zvisina hanya ndezvimwe zvikanganiso zvichaitwa nemakambani pakumisikidza Cloud network. Sezvo kutama kwegore kuchienderera mberi, vechitatu-bato vanopa masevhisi vane hunyanzvi hwekuchengetedzeka vanozowedzera kubatanidzwa, vachipa imwe nzvimbo yekurwisa.

Kuwedzera kwezvinetso zve virtualization

Containerization yemasevhisi inoita kuti zvive nyore kugadzira, kuchengetedza uye kuendesa software, asi panguva imwechete inogadzira dzimwe njodzi. Kusagadzikana mumifananidzo yemidziyo ine mukurumbira kucharamba kuri dambudziko kune chero munhu anoashandisa.

Makambani anozofanirwawo kukwikwidza nekusagadzikana muzvikamu zvakasiyana zvezvivakwa zvemidziyo, kubva panguva yekumhanyisa bugs kuenda kune orchestrators uye kuvaka nharaunda. Vanorwisa vachatsvaga uye kushandisa chero kusasimba kukanganisa maitiro eDevOps.

Imwe maitiro ane hukama ne virtualization is serverless computing. Maererano naGartner, muna 2020, anopfuura 20% emakambani achashandisa tekinoroji iyi. Aya mapuratifomu anopa vanogadzira kugona kumhanya kodhi sevhisi, kubvisa kudiwa kwekubhadhara maseva ese kana midziyo. Nekudaro, kutamira kune serverless komputa hakupe dziviriro kubva kune yekuchengetedza nyaya.

Mapoinzi ekupinda ekurwiswa kweasina server maapplication achave echinyakare uye akanganisa maraibhurari uye zvisizvo zvakagadziriswa nharaunda. Vanorwisa vanovashandisa kuunganidza zvakavanzika ruzivo uye kupinda mumabhizinesi network.

Maitiro ekutarisana nekutyisidzirwa muna 2020

Nekuda kwekuwedzera kuoma kwekukanganisa kwecybercriminal, makambani anozoda kuwedzera kudyidzana nevashandi vezvekuchengetedza kudzikamisa njodzi kumativi ese ezvivakwa zvavo. Izvi zvinobvumira vadziviriri nevagadziri kuti vawane rumwe ruzivo uye zvirinani kudzora network-yakabatana zvishandiso uye kubvisa kusasimba kwavo.

Iyo inogara ichichinja mamiriro etyisidziro inoda kuitiswa kweakawanda-layered dziviriro zvichibva panzira dzekuchengetedza dzakadai se:

  • kuziva kurwiswa kwakabudirira uye kuderedza mhedzisiro yazvo,
  • kudzora kuona uye kudzivirira kurwiswa,
  • Kutarisisa maitiro: kuvharika kwekuvhara kwekutyisidzira kutsva, uye kuona maitiro asina kunaka,
  • endpoint protection.

Kushomeka kwehunyanzvi uye yakaderera yemhando yepamusoro cybersecurity ruzivo inotaridza huwandu hwese kuchengetedzeka kwemasangano, saka kwakarongeka kudzidziswa kwemaitiro akachengeteka evashandi pamwe nekuwedzera kuziva mumunda wekuchengetedza ruzivo kunofanirwa kuve chimwe chinangwa chekutungamira kwavo.

Source: www.habr.com

Voeg