<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>台灣產經新聞網 符合關鍵字"攻擊鏈" 最新訊息列表</title>
    <description>台灣產經新聞網 - Taiwan Business News 符合關鍵字「攻擊鏈」 最新訊息列表</description>
    <link>https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=%E6%94%BB%E6%93%8A%E9%8F%88</link>
    <atom:link href="https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=%E6%94%BB%E6%93%8A%E9%8F%88" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">6F8B8D64-D60E-4D0B-BF4A-92345CD35D42</guid>
      <title>DEVCORE 2025 紅隊演練營收成長 14%  2026 持續助力產官資安韌性升級</title>
      <link>https://news.taiwannet.com.tw/news/195472/DEVCORE-2025-%E7%B4%85%E9%9A%8A%E6%BC%94%E7%B7%B4%E7%87%9F%E6%94%B6%E6%88%90%E9%95%B7-14-2026-%E6%8C%81%E7%BA%8C%E5%8A%A9%E5%8A%9B%E7%94%A2%E5%AE%98%E8%B3%87%E5%AE%89%E9%9F%8C%E6%80%A7%E5%8D%87%E7%B4%9A.html</link>
      <pubDate>Wed, 11 Feb 2026 12:27:42 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/195472_b351ae8cdc3e456aa9cbfedf5682fc9d.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">攻擊型資安公司</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">戴夫寇爾今（</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">10</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">）日分享其</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年服務里程碑與</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2026 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年發展策略。回顧</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年，</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">持續深化紅隊演練服務，紅隊演練相關年營收成長</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 14%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">，該服務亦正式納入公部門共同供應契約第二年，並推出客製化的主動式產品安全研究服務（</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">OPSR</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">），顯示進階資安演練與產品安全已成為政府與產業強化資安韌性的關鍵。展望</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2026 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年，隨著紅隊演練市場需求持續升溫，且該服務於公部門共同供應契約的持續上架，</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">預期將進一步帶動政府機關對進階資安演練服務的採用，並挹注相關營收成長。</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><strong><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></strong></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><strong><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">2025 </span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">紅隊回購率逾五成！</span></strong><strong><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">紅隊演練持續助關鍵產業提高資安韌性</span></strong></p>
<p class="MsoNormal" style="margin-right: -9.0pt; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">隨著</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年網路攻擊態勢升溫，攻擊行為更趨頻繁且規模化，資安風險亦由企業內部防護，進一步延伸至供應鏈與產品層級，成為整體營運必須正視的關鍵課題。根據</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年統計，目前最積極導入紅隊演練的三大產業依序為公部門、金融業與高科技製造業，分別佔整體服務比重的</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 37%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">、</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">27% </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">與</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 18%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">，紅隊演練服務回購率不分產業屬性超過</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 50%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">。其中，金融業對紅隊演練的導入成熟度最高，前十大金融機構中七家曾與</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">合作。此外，公部門案量近一年成長幅度顯著，金額成長近</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 300%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">。</span></p>
<p class="MsoNormal" style="margin-right: -9.0pt; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></p>
<p class="MsoNormal" style="margin-right: -9.0pt; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">執行長暨共同創辦人翁浩正表示：「在</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> AI </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">技術降低攻防門檻、加速演進的時代下，企業正面臨更高且更複雜的資安風險。</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">深信厚實的技術是攻擊與防禦的共同根本，唯有真正理解攻擊者的思維與手法，組織才能建立具備前瞻性與韌性的防禦架構。」</span></p>
<p class="MsoNormal" style="margin-right: -9.0pt; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">持續投入人才培育與新型態服務，</span></strong><strong><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE 2026 </span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">持續支持台灣資安生態圈</span></strong></p>
<p class="MsoNormal" style="margin-right: -9.0pt; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">研究團隊長期鑽研世界級資通訊產品的安全研究，歷年來已揭露並回報超過</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 300 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">個漏洞，如今將產品資安研究能量轉化為服務，於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年推出「主動式產品安全研究服務（</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">OPSR</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">）」，由屢獲國際獎項肯定的資安研究團隊領軍，協助企業驗證軟體、硬體與韌體等各類產品的安全性，確保符合高標準資安要求。同時，</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">亦協助公部門更快速導入紅隊演練服務，其紅隊演練服務已正式納入公部門共同供應契約，成為政府機關可透過共契採購的資安服務項目之一，有效降低公部門導入進階資安演練服務的採購門檻。</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">在人才培育方面，</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">延續與全球資安培訓機構</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> OffSec </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">的合作，並於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年底新推出</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> PEN-200</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">（</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">OSCP</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">）課程，由</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">紅隊成員擔任講師提供全中文教學，藉由業界實戰經驗累積的廣度與深度，解構最貼近真實需求的攻擊鏈，從實務培育台灣的資安專業人才。同時，</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年連續第三年榮獲</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> IT Matters Awards</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">「最佳</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> IT </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">雇主獎」，反映其在技術文化與人才環境上的長期投入亦獲產業肯定；「戴夫寇爾全國資安獎學金」則於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2025 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年邁入第四屆，至今資安人才培育相關計劃補助金額累計突破</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 400 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">萬元，持續支持新世代資安人才發展。</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: center;" align="center"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri; mso-no-proof: yes;"> </span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">長期致力於傳遞駭客思維的</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">，亦將於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 2026 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">年持續舉辦專注於攻擊導向的技術研討會</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE CONFERENCE</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">，活動預計於</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 3 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">月</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> 14 </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">日於台北國際會議中心（</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">TICC</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">）舉行，邀集產、官、學各界，聚焦攻擊技術與手法本質，從駭客角度重新檢視防禦策略，並探討針對不同目標與應用場域的資安技術實務，協助業界共同應對不斷演進的網路攻擊威脅。</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri; mso-no-proof: yes;"> </span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;">DEVCORE CONFERENCE 2026&nbsp;</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">現正售票中，更即時及完整的活動資訊，請參考</span><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri;"> DEVCORE CONFERENCE </span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Aptos; mso-hansi-font-family: Aptos; mso-bidi-font-family: Calibri;">官方網站：</span><a href="https://conf.devco.re/2026/"><span style="font-family: 'Aptos',sans-serif; mso-fareast-font-family: 微軟正黑體; mso-bidi-font-family: Calibri; color: #1155cc;">https://conf.devco.re/2026/</span></a></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">48986E11-A8C7-4A62-BA05-718B1EC6F9B5</guid>
      <title>Cynet連續三年於MITRE ATT&amp;CK評估中取得優異成績</title>
      <link>https://news.taiwannet.com.tw/news/191327/Cynet%E9%80%A3%E7%BA%8C%E4%B8%89%E5%B9%B4%E6%96%BCMITRE-ATT-CK%E8%A9%95%E4%BC%B0%E4%B8%AD%E5%8F%96%E5%BE%97%E5%84%AA%E7%95%B0%E6%88%90%E7%B8%BE.html</link>
      <pubDate>Tue, 30 Dec 2025 11:32:54 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/191327_02b62783c31c4808a823b52156a3055d.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Cynet </span><span style="font-family: '微軟正黑體',sans-serif;">在最新發布的<span lang="EN-US"> 2025 </span>年<span lang="EN-US"> MITRE ATT&amp;CK </span>評估（<span lang="EN-US">MITRE ATT&amp;CK Enterprise Evaluations</span>）中，連續第三年取得優異成績，實現<span lang="EN-US"> 100% </span>的保護和<span lang="EN-US"> 100% </span>檢測可視性，樹立了資安產業的新標竿。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><strong><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></strong><span style="font-size: 14pt;"><strong><span style="font-family: '微軟正黑體',sans-serif;">蟬聯三年卓越紀錄，建立行業新標竿</span></strong></span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">2023 </span><span style="font-family: '微軟正黑體',sans-serif;">年，<span lang="EN-US">Cynet </span>在無需任何配置更改的情況下，實現<span lang="EN-US"> 100% </span>的檢測可視性（<span lang="EN-US">Detection Visibility</span>） 和<span lang="EN-US"> 100% </span>的分析覆蓋率（<span lang="EN-US">Analytic Coverage</span>）；<span lang="EN-US">2024 </span>年，又達成<span lang="EN-US"> 100% </span>的檢測可視性 和<span lang="EN-US"> 100% </span>的防護能力（<span lang="EN-US">Protection</span>）。如今，在<span lang="EN-US">2025</span>年最新的<span lang="EN-US"> MITRE ATT&amp;CK </span>評估中，<span lang="EN-US">Cynet </span>進一步鞏固了其領先地位。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Cynet </span><span style="font-family: '微軟正黑體',sans-serif;">在跨<span lang="EN-US"> Windows</span>、<span lang="EN-US">Linux </span>及雲端<span lang="EN-US"> AWS </span>環境的<span lang="EN-US"> 90 </span>個惡意攻擊子步驟，展現了卓越的防禦實力：</span></p>
<ul style="margin-top: 0cm;" type="disc">
<li class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt; mso-list: l2 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">100% </span><span style="font-family: '微軟正黑體',sans-serif;">檢測可視性：在無需任何配置更改的情況下，成功偵測<span lang="EN-US"> 90 </span>個攻擊子步驟中的每個環節。</span></li>
<li class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt; mso-list: l2 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">100% </span><span style="font-family: '微軟正黑體',sans-serif;">技術覆蓋率：在無需任何設定更改下，達成<span lang="EN-US">90</span>項技術中<span lang="EN-US">90</span>項的偵測</span></li>
<li class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt; mso-list: l2 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">100% </span><span style="font-family: '微軟正黑體',sans-serif;">防護率：在評測中成功阻擋所有惡意測試攻擊。</span></li>
<li class="MsoNormal" style="margin-bottom: 0cm; mso-line-height-alt: 0pt; mso-list: l2 level1 lfo1; tab-stops: list 36.0pt;"><span style="font-family: '微軟正黑體',sans-serif;">零誤報偵測：在<span lang="EN-US"> 17 </span>個合法操作測試中，沒有任何一項被誤判為惡意行為。</span><span style="font-family: '微軟正黑體',sans-serif;"><img src="https://www.softnext.com.tw/snadv/images_news/1146-Cynet2025mitre.jpg" alt=""></span></li>
</ul>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="mso-no-proof: yes;"> </span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span style="font-size: 14pt;"><strong><span style="font-family: '微軟正黑體',sans-serif;">經權威驗證的實力</span></strong></span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Cynet </span><span style="font-family: '微軟正黑體',sans-serif;">參與<span lang="EN-US"> MITRE ATT&amp;CK </span>評估，因為客戶需要的是實質的評測驗證，而非空洞的宣稱。<span lang="EN-US">Cynet </span>堅信，獨立測試是客戶的核心優先事項，因為它提供更安全、更值得信賴的資安體驗的關鍵環節。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Cynet </span><span style="font-family: '微軟正黑體',sans-serif;">連續三年取得穩定卓越的成果，充分體現了其對執行和結果的專注。統一的偵測與防禦架構能夠關聯攻擊鏈中的各種訊號，開箱即用地提供高精準度、符合<span lang="EN-US"> ATT&amp;CK </span>標準的偵測結果，並將其轉化為快速可靠的防護措施，幾乎不需額外調校。<span lang="EN-US">Cynet </span>內建<span lang="EN-US">AI</span>人工智慧功能，有助於減少干擾訊息，優先處理關鍵事項，確保大規模部署下其結果仍保持一致性。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">Cynet </span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">是專為資安團隊打造的<span lang="EN-US">AI</span>人工智慧驅動的網路安全平台，可保護來自終端、使用者、網路、身分、雲端、行動裝置和電子郵件的進階威脅。內建<span lang="EN-US">AI</span>人工智慧功能，有助於減少干擾訊息，優先處理關鍵事項，確保大規模部署下其結果仍保持一致性。<span lang="EN-US">Cynet </span>由<span lang="EN-US"> CyOps </span>資安專家提供<span lang="EN-US"> 24x7 </span>全天候支援，可減少工具過多、警報疲勞和事件響應時間，讓資安團隊能夠專注於真正重要的工作。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><strong><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Softnext </span></strong><span style="font-family: '微軟正黑體',sans-serif;"><strong>中華數位科技為<span lang="EN-US"> Cynet </span>亞太第一家加值代理商與技術服務中心</strong>，除在自有研發的郵件安全領域持續精進，亦代理國際資安大廠的專業防護產品，從各個重點缺口著手防禦，以多元的防禦解決方案，協助企業建立更全面的防禦與合規準備。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><span style="font-family: 微軟正黑體, sans-serif; font-size: 14pt;"><strong>中華數位科技 代理產品服務優勢</strong></span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo2; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-family: '微軟正黑體',sans-serif;">將研發專業擴及代理服務，以研發背景及深厚的技術底蘊服務代理；</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo2; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-family: '微軟正黑體',sans-serif;">懂技術的在地支援，具問題排除能力，可減少將問題轉給海外原廠的次數與時間；</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l0 level1 lfo2; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-family: '微軟正黑體',sans-serif;">可基於延伸應用加值開發，更貼近在地企業的實際使用需求。</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt; margin: 12.0pt 0cm 0cm 0cm;"><strong><span style="font-family: '微軟正黑體',sans-serif;">加值安全產品線</span></strong></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo3; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Cynet 360 AutoXDR </span><span style="font-family: '微軟正黑體',sans-serif;">自主安全保護平台：擴展檢測和響應<span lang="EN-US"> (XDR)+</span>自動化響應<span lang="EN-US">+MDR</span>（<span lang="EN-US">24/7 </span>託管檢測和響應）。</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo3; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="https://www.softnext.com.tw/pdt_action1.html"> </a></span></span></span><!--[endif]--><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Action1</span><span style="font-family: '微軟正黑體',sans-serif;">雲原生漏洞修補管理平台：提供漏洞修補管理、遠端存取、<span lang="EN-US">Window</span>與第三方應用軟體部署、端點管理、<span lang="EN-US">IT </span>資產清單。</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo3; margin: 0cm 0cm 0cm 24.0pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial;"><span style="mso-list: Ignore;">&bull;<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Netwrix </span><span style="font-family: '微軟正黑體',sans-serif;">以身分為中心的資料保護：包括<span lang="EN-US"> AD/File Server </span>等存取變更記錄稽核系統、密碼原則強制器等。</span></p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo3; margin: 0cm 0cm 0cm 24.0pt;">&nbsp;</p>
<p class="MsoNormal" style="text-indent: -24.0pt; mso-line-height-alt: 0pt; mso-list: l1 level1 lfo3; margin: 0cm 0cm 0cm 24.0pt;"><span style="font-family: '微軟正黑體',sans-serif;">如有任何產品需求，歡迎聯繫 中華數位科技 02-25422526</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">46EC7FE1-2498-4D6E-A9C4-B4183EAB0C55</guid>
      <title>Fortinet《2026全球資安威脅預測》： 網路犯罪產業化4.0時代，AI引領資安攻防速度戰</title>
      <link>https://news.taiwannet.com.tw/news/187839/Fortinet%E3%80%8A2026%E5%85%A8%E7%90%83%E8%B3%87%E5%AE%89%E5%A8%81%E8%84%85%E9%A0%90%E6%B8%AC%E3%80%8B%EF%BC%9A-%E7%B6%B2%E8%B7%AF%E7%8A%AF%E7%BD%AA%E7%94%A2%E6%A5%AD%E5%8C%964-0%E6%99%82%E4%BB%A3-AI%E5%BC%95%E9%A0%98%E8%B3%87%E5%AE%89%E6%94%BB%E9%98%B2%E9%80%9F%E5%BA%A6%E6%88%B0.html</link>
      <pubDate>Fri, 28 Nov 2025 11:49:50 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/187839_d217910fc17b4bbeaaeb915927f40ca5.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">全方位整合與自動化網路資安領導廠商</span><span lang="EN-US" style="font-size: 11.0pt;"><span style="color: #0070c0;">Fortinet&reg;</span></span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">（</span><span lang="EN-US" style="font-size: 11.0pt;">NASDAQ</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">：</span><span lang="EN-US" style="font-size: 11.0pt;">FTNT</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">發布《</span><span lang="EN-US" style="font-size: 11.0pt;"><span style="color: #0070c0;">2026</span><span lang="EN-US" style="font-family: 'Microsoft JhengHei UI',sans-serif; color: #0070c0;"><span lang="EN-US">全球資安威脅預測</span></span></span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">》（</span><span lang="EN-US" style="font-size: 11.0pt;">Cybersecurity Predictions for 2026</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">），持續分析科技、經濟與人類行為，如何交織影響全球資安風險版圖。報告指出，網路犯罪正持續演變成一個高度組織化的產業，由自動化、專業分工與</span><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">驅動。未來一年，攻防雙方的關鍵，將更著重於行動的「速度」，也就是能多快將情資轉化為攻防行動。近年來，台灣也面臨到更多駭客針對關鍵基礎設施、</span><span lang="EN-US" style="font-size: 11.0pt;">OT</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">、供應鏈所發動的複雜、大規模的攻擊。組織中的資安團隊，必須重新思考資安防禦架構與策略，使其運作能跟上自動化被快速利用的攻擊生態系。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">全球威脅情報副總裁</span><span lang="EN-US" style="font-size: 11.0pt;">Derek Manky</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">表示：「攻擊者越來越關注製造、醫療與關鍵基礎設施等具有高價值的重點產業。今年，我們觀察到台灣的勒索軟體偵測量增加超過</span><span lang="EN-US" style="font-size: 11.0pt;">40%</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">，從年初一波針對大型醫院的攻擊即可佐證。勒索軟體即服務（</span><span lang="EN-US" style="font-size: 11.0pt;">RaaS</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）模式正快速擴張至</span><span lang="EN-US" style="font-size: 11.0pt;">OT</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">環境，結合資料竊取、勒索與服務中斷，早已匯聚於單一攻擊腳本中。台灣身處全球科技供應鏈核心，組織必須在資安治理中，採取與攻擊者相同等級的營運原則、自動化與協同措施，才能有效提升相對應的防禦能力。」</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;">&nbsp;</p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">這一年來，</span><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">在亞太區共偵測到</span><span lang="EN-US" style="font-size: 11.0pt;">5,785</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">億次惡意活動，年增率達</span><span lang="EN-US" style="font-size: 11.0pt;">13.3%</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">。而台灣作為最常受攻擊的區域之一，在</span><span lang="EN-US" style="font-size: 11.0pt;">2025</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年共面臨</span><span lang="EN-US" style="font-size: 11.0pt;">1,534</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">億次惡意活動。其中，入侵防禦系統（</span><span lang="EN-US" style="font-size: 11.0pt;">IPS</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）偵測到</span><span lang="EN-US" style="font-size: 11.0pt;">1,531</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">億次事件、防毒系統（</span><span lang="EN-US" style="font-size: 11.0pt;">AV</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）識別出</span><span lang="EN-US" style="font-size: 11.0pt;">7,810</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">萬次惡意軟體散布、命令與控制（</span><span lang="EN-US" style="font-size: 11.0pt;">C2</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）系統偵測到</span><span lang="EN-US" style="font-size: 11.0pt;">1.64</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">億次殭屍網路活動。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">當前台灣面臨一個高度活躍且快速演進的威脅環境，攻擊者正在將主要目標轉移至對營運的影響和破壞。儘管在漏洞利用嘗試的偵測數量上，自</span><span lang="EN-US" style="font-size: 11.0pt;">2024</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年後下降超過</span><span lang="EN-US" style="font-size: 11.0pt;">7</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">成，但阻斷服務（</span><span lang="EN-US" style="font-size: 11.0pt;">DoS</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）攻擊卻增加了</span><span lang="EN-US" style="font-size: 11.0pt;">61.36%</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">，達</span><span lang="EN-US" style="font-size: 11.0pt;">1,385</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">億次、勒索軟體偵測量也增加</span><span lang="EN-US" style="font-size: 11.0pt;">40.77%</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">，達上萬（</span><span lang="EN-US" style="font-size: 11.0pt;">11,740</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）次。顯示駭客針對台灣的攻擊手法，正轉向更高價值、以癱瘓營運為目的。台灣的企業組織亟需強化防禦韌性與快速應變能力，以應對攻擊更大量、規模升級、且破壞性更強的威脅環境。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;">&nbsp;</p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><strong><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">《</span></strong><strong><span lang="EN-US" style="font-size: 11.0pt;">2026</span></strong><strong><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">全球資安威脅預測》四大關鍵分析：</span></strong></p>
<p class="MsoListParagraph" style="margin-left: 22.0pt; mso-add-space: auto; text-align: justify; text-indent: -22.0pt; mso-list: l0 level1 lfo1; layout-grid-mode: char;"><!-- [if !supportLists]--><span lang="EN-US" style="mso-bidi-font-family: 新細明體;"><span style="mso-list: Ignore;">一、</span></span><!--[endif]--><strong><span lang="EN-US">AI</span></strong><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">驅動的網路犯罪攻擊鏈成形，邁向專業自動化操作</span></strong></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">正在加速網路攻擊的節奏。攻擊模型能夠以遠快於資安分析師的速度，識別並利用防禦系統中的弱點。</span><span lang="EN-US" style="font-size: 11.0pt;">2026</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年，最具決定性的變化是，資安團隊將面臨專為網路犯罪打造的自主網路犯罪代理（</span><span lang="EN-US" style="font-size: 11.0pt;">Autonomous Cybercrime Agents</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）。這些模型設計成負責特定任務，例如憑證竊取、網路釣魚、橫向移動等，可在攻擊鏈多階段自動運作，無需人類監督。這將使初階攻擊者可以操控複雜的攻擊行動，而高階攻擊者則可將攻擊範圍擴大至數千個目標、降低成本且提升頻率。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">同時，生成式</span><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">也將成為攻擊者在成功入侵後的核心工具。攻擊者一旦取得大型資料集的存取權限，就能透過</span><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">在幾分鐘之內分析、關聯資料，精準找到最具價值的勒索或轉售資產。他們可以自動識別關鍵資料、鎖定高價值目標、並大量生成客製化勒索訊息。</span></p>
<p class="MsoListParagraph" style="margin-left: 22.0pt; mso-add-space: auto; text-align: justify; text-indent: -22.0pt; mso-list: l0 level1 lfo1; layout-grid-mode: char;"><!-- [if !supportLists]--><span lang="EN-US" style="mso-bidi-font-family: 新細明體;"><span style="mso-list: Ignore;">二、</span></span><!--[endif]--><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">網路犯罪產業化</span><span lang="EN-US">4.0</span></strong><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">時代，犯罪年均成本將超過</span><span lang="EN-US">24</span></strong><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">兆美元</span></strong></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">根據世界經濟論壇預估，全球網路犯罪的年均成本將在</span><span lang="EN-US" style="font-size: 11.0pt;">2027</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年超過</span><span lang="EN-US" style="font-size: 11.0pt;">24</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">兆美元。產業化的勒索軟體、自動化詐欺、與整合式犯罪模式將是其驅動力。網路犯罪正邁入產業化</span><span lang="EN-US" style="font-size: 11.0pt;">4.0</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">階段，融合了自動化、整合化與專業化。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">憑證竊取將持續演變經過整理的組合清單，其中包含詮釋資料與行為分析。暗網市場的運作模式已越來越接近合法電商平台，具備</span><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">驅動的客戶服務、評價機制與第三方託管服務。殭屍網路將持續是網路犯罪的骨幹，預先遭感染的端點會被打包成現成的滲透套件進行交易，加速了勒索軟體部署或資料外洩。隨著此地下經濟的擴張，使得攻擊者能將憑證竊取、殭屍網路租賃與資料勒索等服務，整合成規模化的商業模式。</span></p>
<p class="MsoListParagraph" style="margin-left: 22.0pt; mso-add-space: auto; text-align: justify; text-indent: -22.0pt; mso-list: l0 level1 lfo1; layout-grid-mode: char;"><!-- [if !supportLists]--><span lang="EN-US" style="mso-bidi-font-family: 新細明體;"><span style="mso-list: Ignore;">三、</span></span><!--[endif]--><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">速度決定安全度，防禦策略與模型須著重整合性及回應速度</span></strong></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">隨著攻擊方透過自動化提升攻擊規模與力道，防禦方也必須同步跟進。未來資安韌性，將取決於一種以威脅為依據的防禦模型，而該模型在統一的營運框架內，連接情資、曝險管理和事件回應。</span><span lang="EN-US" style="font-size: 11.0pt;">FortiGuard Labs</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">的預測型情資，能使用</span><span lang="EN-US" style="font-size: 11.0pt;">MITRE ATT&amp;CK</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">和</span><span lang="EN-US" style="font-size: 11.0pt;">CTEM</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">等框架繪製活躍威脅圖，能成為有效防禦的基礎。在持續性的發現、驗證與修補過程中扮演核心角色，將情資直接連結到營運工作流程。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">此種整合式的資安運作模式，必須有數分鐘內即可完成偵測與回應能力的配合，讓資安團隊的狀態由被動轉為主動。同時，事件回應也必須從單一功能，發展為一項協調能力。此外，跨端點、網路與雲端的統一平台可視性，結合攻擊面情資的分析運用，能有效縮短事件遏止時間、實現更全面的資安態勢感知。</span></p>
<p class="MsoListParagraph" style="margin-left: 22.0pt; mso-add-space: auto; text-align: justify; text-indent: -22.0pt; mso-list: l0 level1 lfo1; layout-grid-mode: char;"><!-- [if !supportLists]--><span lang="EN-US" style="mso-bidi-font-family: 新細明體;"><span style="mso-list: Ignore;">四、</span></span><!--[endif]--><strong><span style="font-family: 'Microsoft JhengHei UI',sans-serif;">身份管理躍升為資安核心，「非人類身份」驗證與控管成關鍵</span></strong></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt;">2026</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年，身份管理將從支援性質的控管，躍升為資安營運的核心。隨著組織採用更多自動化、</span><span lang="EN-US" style="font-size: 11.0pt;">AI </span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">驅動的工作流程與自主決策系統，資安團隊需管理的不僅是其環境中的人類身分，更包括大量的「非人類身分」，如自動化代理、在持續整合</span><span lang="EN-US" style="font-size: 11.0pt;">/</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">部署（</span><span lang="EN-US" style="font-size: 11.0pt;">CI/CD</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）或雲部署期間所建立的暫時性身份、執行</span><span lang="EN-US" style="font-size: 11.0pt;">SecOps</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">任務的</span><span lang="EN-US" style="font-size: 11.0pt;">AI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">驅動流程、以及需身分驗證、授權和稽核的機器對機器工作流程。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">一旦其中一個自動化身份遭入侵，可能在數秒內就能造成大規模橫向移動、權限提升或資料外洩。這些身份管理需要獨特的憑證、策略與行為準則，以確保當責性、並防止跨系統交叉感染。因此，資安團隊必須將身份整合到所有偵測與回應層面中，強化人類與非人類身份的存取控管、監控跨平台身份行為來偵測異常，並在自動化身份與敏感資料互動時，落實嚴格的治理、稽核與隱私控管。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;">&nbsp;</p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><strong><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span></strong><strong><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">持續推動國際公私協力，匯聚社群力量與專業情資打擊網路犯罪</span></strong></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">防禦上的創新，不應侷限於技術層面。面對產業化的網路犯罪，更需全球協作採取應對措施。像是國際刑警組織（</span><span lang="EN-US" style="font-size: 11.0pt;">INTERPOL</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）「塞倫蓋提行動</span><span lang="EN-US" style="font-size: 11.0pt;">2.0</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">」（</span><span lang="EN-US" style="font-size: 11.0pt;">Serengeti 2.0</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）等國際計畫，在</span><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">與其他私部門夥伴的支援下，印證了情報共享和針對性破壞行動，能有效瓦解犯罪基礎設施。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">為有效打擊網路犯罪，防禦行動必須在遭到入侵前就開始。因此</span><span lang="EN-US" style="font-size: 11.0pt;">FortiGuard Labs</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">預計將持續擴大資安教育與網路犯罪嚇阻計畫，鎖定容易被誘導至網路犯罪生態中的青少年與高風險族群，目標是在他們進入網路犯罪鏈之前就將其導正。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">與國際打擊犯罪組織（</span><span lang="EN-US" style="font-size: 11.0pt;">CSI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">，</span><span lang="EN-US" style="font-size: 11.0pt;">Crime Stoppers International</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">）共同推動的「網路犯罪懸賞計畫」，結合了</span><span lang="EN-US" style="font-size: 11.0pt;">CSI</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">的全球社群與</span><span lang="EN-US" style="font-size: 11.0pt;">Fortinet</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">領先業界的威脅情資，提供了精準、可操作的機制來遏制網路犯罪。讓全球民眾能夠安全且匿名地舉報網路犯罪活動，將社群力量與資安意識，轉化為有效的防禦行動。提高全球對網路犯罪的可見性、情資共享與協同回應能力，形成大規模的集體防禦力量。公私協力打擊網路犯罪的模式，證實了追究責任才能有效嚇阻網路犯罪，且嚇阻力道的關鍵在於合作規模。</span></p>
<p class="MsoNormal" style="text-align: justify; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt;">FortiGuard Labs</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">預期，到</span><span lang="EN-US" style="font-size: 11.0pt;">2027</span><span style="font-size: 11.0pt; font-family: 'Microsoft JhengHei UI',sans-serif;">年，網路犯罪將可能以相當於合法全球產業的規模運作。新時代的攻防關鍵將是「速度」與「規模」的掌握，也就是攻擊方能多快地行動、以及防禦方能多廣泛地回應。而未來的資安核心，將取決於如何人機協作，將人類判斷與近乎即時的自動化回應，結合成一個具備韌性、能隨威脅演化的統一整合性框架，並發展出具適應性的協同防禦體系。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">9C38F4C9-AF8E-4433-8ACE-5ADD1AE030E7</guid>
      <title>ASRC 2025 年第三季電子郵件安全觀察：手法更精緻、攻擊鏈更長、以合法服務為跳板</title>
      <link>https://news.taiwannet.com.tw/news/185245/ASRC-2025-%E5%B9%B4%E7%AC%AC%E4%B8%89%E5%AD%A3%E9%9B%BB%E5%AD%90%E9%83%B5%E4%BB%B6%E5%AE%89%E5%85%A8%E8%A7%80%E5%AF%9F%EF%BC%9A%E6%89%8B%E6%B3%95%E6%9B%B4%E7%B2%BE%E7%B7%BB-%E6%94%BB%E6%93%8A%E9%8F%88%E6%9B%B4%E9%95%B7-%E4%BB%A5%E5%90%88%E6%B3%95%E6%9C%8D%E5%8B%99%E7%82%BA%E8%B7%B3%E6%9D%BF.html</link>
      <pubDate>Fri, 07 Nov 2025 09:57:13 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/185245_58e2223127ba4b33a2dd366f46643542.jpg" border="0" style="max-width: 100%;"><p>2025 年第三季，電子郵件攻擊呈現「手法更精緻、攻擊鏈更長、利用合法服務為跳板」的趨勢。攻擊者大量採用 AI/生成式工具強化社交工程，使郵件文案更具說服力且在多語系場景下更難以辨識；同時，他們善用第三方服務，如短網址、雲端平台、電子簽章、以及資安廠商自己的置換連結機制等，來串接、轉向與掩飾攻擊路徑，使既有的靜態過濾與基於來源信譽的防護失效。針對資安廠商的社交工程試探也明顯增加，攻擊者以「少量多次」的方式對公開服務窗口埋伏惡意程式或蒐集情報，嘗試取得長期潛伏的後門。最後，AI 的普及不僅提升釣魚攻擊成功率，也使漏洞挖掘、自動化探針與隱蔽指令的濫用更有效率，導致端到端的電子郵件防護必須由單層規則升級為行為與情境感知、跨通道監控與資料外洩的整合防護體系。<br><br>以下為ASRC 與中華數位科技在這一季的特殊觀察：<br><br></p>
<h4><span style="color: rgb(53, 152, 219); font-size: 14pt;">置換連結防護遭到濫用</span></h4>
<p><br>為降低收件者誤點惡意連結的風險，許多郵件防護機制在郵件傳遞途中執行「置換連結（URL Rewriting）」，將郵件內原始連結改寫為防護服務自有的檢查跳板，以便在使用者點擊時即時檢查最終目的連結的安全性，並記錄使用者與點擊時間，以利事後鑑識或封鎖。這種即時檢測機制在傳統釣魚攻擊中有效降低成功率，並提高事件追溯能力。<br><br>然而在 2025 年第三季出現明顯濫用的趨勢：攻擊者串接多個置換連結與合法跳轉服務（例如短網址、合法雲端或第三方追蹤域名），形成「多段轉址」的攻擊鏈。 其操作邏輯與風險如下：<br><br><strong>． 串接防護跳板以躲避即時檢測：</strong>攻擊者先利用合法服務（或被入侵的服務）生成短網址或跳轉連結，再將這些連結放入釣魚郵件中。當收件者點擊時，第一個被檢查到的 URL 可能是某資安廠商或其它合法防護的置換域名，因其來源被視為「可信」，系統就不會進一步深度解析或標示為可疑，導致最終惡意目的地得以通過。<br><br><strong>． 繞過記錄與追蹤機制：</strong>若多段轉址使中間某些 Click-tracking／置換節點被系統視為正常流量，系統可能不會完整紀錄最終目的地或點擊者資訊，削弱事後鑑識與責任歸屬。<br><br><strong>． 利用合法資源作掩護：</strong>當轉址鏈包含受信任的第三方（例如廣告追蹤、電子簽章或大品牌雲端），攻擊行為顯得更「自然」，讓使用者與系統更難辨認其惡意意圖。<br><br><strong>． 自動化與規模化：</strong>攻擊者可以自動化生成大量多段轉址連結，配合 AI 編寫的人性化文案，顯著提升釣魚效率。<br><br></p>
<div align="center"><img src="https://www.asrc-global.com/asp_img/1142-s01.jpg" width="700" height="297" border="0"></div>
<h6 style="text-align: center;"><span style="color: rgb(126, 140, 141); font-size: 12pt;">釣魚郵件的攻擊者嘗試串起不同防護的置換連結，並搭配縮址、轉址的功能，讓置換連結防護失效！</span></h6>
<p><br><strong>潛在影響</strong><br>防護閘道的「第一層檢查」被合法外殼所迷惑，導致「偽陰性」增加；事後鑑識資訊不完整，延遲事故回應與補救；以及使用者信任度下降（尤其當合法廠商的置換域被濫用時），導致品牌與服務信譽風險。<br><br></p>
<h4><span style="font-size: 14pt; color: rgb(53, 152, 219);">針對資安公司的社交工程攻擊與試探</span></h4>
<p><br>第三季觀察到攻擊者特別將目標瞄準「資安公司」或其公開服務窗口，常見攻擊路徑與手法可區分為兩大類：<br><br><strong>1. 長期潛伏式 Web / 服務窗口滲透</strong><br>攻擊者嘗試以惡意程式感染服務窗口，成功感染後，以小量、頻繁的請求（通常透過 HTTPS/443）取得後續惡意程式，目標是建立可長期維持的後門或定期蒐集目標主機資訊，並定期將資訊上傳到特定外部站點。攻擊行為刻意低調（低頻率、分散來源 IP、混淆 User-Agent），以避免被即時偵測系統標為異常流量。<br><br><strong>2. 社交工程與商務洽談偽裝</strong><br>以「購買服務」、「產品諮詢」或「技術合作」之名接觸業務承辦人，誘導其提供企業內部資訊、技術細節或測試存取權限。手段常結合精緻的語言、模擬的公司文件與偽造聯絡人資訊，單靠表面核查難以立即識破。<br><br><strong>常見破綻</strong><br><br><strong>． 發信來源與真實性不一致：</strong>不少攻擊使用的郵件並非來自他們聲稱的公司域名或官方郵件流程，若針對郵件頭、來源 IP 與 SPF/DKIM/DMARC 進行核查，仍可發現破綻。<br><br><strong>． 表單回應機制缺少驗證：</strong>公司若以網頁表單作為第一接觸點，但未對回覆者進行強制驗證（例如電話回撥、企業郵件網域驗證或商業憑證），將提高被社交工程騙取資訊的風險。<br><br><strong>． 內部資訊過度披露：</strong>公開的 FAQ、技術支援說明或產品文件若包含過多架構或技術細節，能被攻擊者快速收集並用於定向攻擊。</p>
<div align="center"><img src="https://www.asrc-global.com/asp_img/1142-s02.jpg" width="700" height="496" border="0"></div>
<h6 style="text-align: center;"><span style="font-size: 12pt; color: rgb(126, 140, 141);">試圖在服務窗口的電腦上埋入可以長期潛伏並洩資的後門</span></h6>
<p>&nbsp;</p>
<div align="center"><img src="https://www.asrc-global.com/asp_img/1142-s03.jpg" width="700" height="454" border="0"></div>
<h6 style="text-align: center;"><span style="color: rgb(126, 140, 141); font-size: 12pt;">試圖誘騙相關業務承辦人洩露過多的訊息或技術情報</span></h6>
<p><br><br></p>
<h4><span style="font-size: 14pt; color: rgb(53, 152, 219); background-color: rgb(255, 255, 255);">AI 進化帶來的威脅</span></h4>
<p><br>AI 與大型語言模型（LLM）在 2025 年下半年已廣泛被攻防雙方採用，對電子郵件資安的影響主要有三個面向：<br><br><strong>1. 強化社交工程內容產出</strong><br>AI 可生成高品質、針對特定組織或個人語氣與文化語境的郵件文案，包含合理的時間脈絡、專業術語與稱謂，有效提高釣魚與偽冒成功率。並且能自動化 A/B 測試郵件標題、內容與呼籲動作，快速優化可欺騙率。<br><br><strong>2. 自動化漏洞發現與攻擊鏈組合</strong><br>攻擊者利用 AI 加速漏洞掃描、解析郵件伺服器或附件的潛在弱點，並自動生成對應利用代碼或 payload。當 AI 結合自動化工具（如腳本、代理、多段轉址生成器）時，可以大規模產生變異化攻擊，使傳統簽名式防禦失效。<br><br><strong>3. 對企業內部 AI 系統的濫用</strong>（prompt injection / 隱藏指令）<br>隨著企業導入 AI 助手處理郵件（如自動摘要、回覆建議、敏感資訊檢測），攻擊者可能在郵件正文中嵌入隱蔽指令（例如極小字體、白底白字、或特殊格式），誘使 AI 揭露敏感資訊或執行不當行為（稱為 prompt injection）。若 AI 的輸出未經適當的審核或上下文限制，可能成為內部資料外洩或錯誤自動化決策的來源。<br><br></p>
<h4><span style="color: rgb(53, 152, 219); font-size: 14pt;">電子郵件攻防邁入新階段</span></h4>
<p><br>電子郵件攻防正進入「以合法性與自動化為盾與矛」的新階段：攻擊者大量利用 AI 生成社交工程與自動化工具，並利用合法第三方與置換連結的信任層來掩護惡意路徑；同時，資安供應鏈本身與對外窗口成為高價值目標。單一層級的靜態防禦（例如只靠 SPF/DKIM/傳統過濾）已不足以應付這類複合、動態攻擊。<br><br><strong>未來趨勢預測</strong><br>． 多段轉址與合法服務濫用將更加普遍，防護會從「域名信譽」轉向「轉址鏈分析」與「行為得分」。<br>． 攻擊者對資安業者與業務窗口的試探會持續，促使資安公司本身採用更多&ldquo;對抗式&rdquo;自我測試與服務窗口硬化（hardening）。<br>． AI 相關的 prompt injection 與模型濫用將成主要攻擊向量，企業若不設限，AI 反而可能成為資料洩露的幫兇。<br><br><strong>企業防護建議</strong><br>． 強化身分與接觸驗證流程：對外業務/客服/表單回應採用多因子驗證與實體回撥核實。<br>． AI 使用原則與防護：針對內部 AI 處理郵件的流程設計輸入淨化、輸出審核與最小授權。<br>． 釣魚演練與社交工程防禦訓練：針對 VIP/財務/客服進行定向演練與應變流程訓練。<br>． 建立業界協作與即時通報機制：當發現被濫用的第三方或置換域名，應快速通報、分享入侵指標 IoCs 與同步封鎖。</p>
<p>&nbsp;</p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="color: rgb(126, 140, 141);"><strong><span style="font-family: '微軟正黑體',sans-serif;">關於<span lang="EN-US">&nbsp;ASRC&nbsp;</span>垃圾訊息研究中心</span></strong></span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '微軟正黑體',sans-serif;">垃圾訊息研究中心<span lang="EN-US">&nbsp;(Asia Spam-message Research Center)</span>，長期與中華數位科技合作，致力於全球垃圾郵件、惡意郵件、網路攻擊事件等相關研究事宜，並運用相關數據統計、調查、趨勢分析、學術研究、跨業交流、研討活動<span lang="EN-US">..</span>等方式，促成產官學界共同致力於淨化網際網路之電子郵件使用環境。<span lang="EN-US"><br></span>更多資訊請參考</span><span lang="EN-US"><a href="https://www.asrc-global.com/"><span style="font-family: '微軟正黑體',sans-serif;">ASRC </span><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">垃圾訊息研究中心網站</span></a></span></p>
<p class="MsoNormal" style="margin-top: 12.0pt; mso-line-height-alt: 0pt;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">FE8737AE-3B7E-4942-876B-225D384E95FD</guid>
      <title>台灣資安主管聯盟與數聯資安及Cyberbit攜手舉辦企業資安實戰演練</title>
      <link>https://news.taiwannet.com.tw/news/182991/%E5%8F%B0%E7%81%A3%E8%B3%87%E5%AE%89%E4%B8%BB%E7%AE%A1%E8%81%AF%E7%9B%9F%E8%88%87%E6%95%B8%E8%81%AF%E8%B3%87%E5%AE%89%E5%8F%8ACyberbit%E6%94%9C%E6%89%8B%E8%88%89%E8%BE%A6%E4%BC%81%E6%A5%AD%E8%B3%87%E5%AE%89%E5%AF%A6%E6%88%B0%E6%BC%94%E7%B7%B4.html</link>
      <pubDate>Tue, 21 Oct 2025 10:28:18 +0800</pubDate>
      <dc:creator>數聯資安股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/182991_88d29d7232db41e480a90274cd4049d6.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">面對全球資安威脅不斷升溫，尤其高科技產業成為駭客鎖定的主要目標，台灣資安主管<span style="color: rgb(0, 0, 0);">聯盟</span></span><span style="color: rgb(0, 0, 0);"><span style="font-family: 新細明體, serif;">（</span><span style="font-family: 新細明體, serif;">下稱台灣</span><span lang="EN-US">CISO</span><span style="font-family: 新細明體, serif;">聯盟</span><span style="font-family: 新細明體, serif;">）</span></span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;"><span style="color: rgb(0, 0, 0);">與數</span>聯資安攜手共同舉辦「企業資安實戰演練」活動，集結國內多家高科技企業資訊安全主管，針對勒索攻擊、供應鏈滲透與網站入侵等實際案例進行演練與經驗交流，協助企業強化資安防禦與應變能力。</span></p>
<p class="MsoNormal"><span style="color: rgb(0, 0, 0);"><span style="font-family: 新細明體, serif;">台灣</span><span lang="EN-US">CISO</span><span style="font-family: 新細明體, serif;">聯盟</span></span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;"><span style="color: rgb(0, 0, 0);">會</span>長</span> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">金慶柏表示，即使企業不斷增加資安投入，面對攻擊者的組織化、商業化與</span><span lang="EN-US"> AI </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">輔助滲透手法，攻防戰局依然日益激烈。在面對不斷變化的威脅環境，企業需要的不僅是工具與設備，更需要「實戰經驗」來強化防禦與應變能力。</span></p>
<p class="MsoNormal" style="margin-bottom: 6.0pt;"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">演練聚焦「網頁伺服器攻擊鏈」　驗證偵測與應變實力</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">為協助企業全面提升資安防護韌性，本次活動吸引華碩電腦、遠傳電信、台達電、瑞昱半導體、技嘉等</span><span lang="EN-US">12</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">家上市企業團隊報名參與，產業類別涵蓋半導體、通信網路、電腦、電子及光電等，展現各類產業對強化資安韌性與實戰能力的高度重視。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">本次實境攻防演練中，數聯資安專業團隊透過聚焦於網頁伺服器常見攻擊情境，完整還原攻擊者從端口掃描、漏洞利用、憑證竊取、部署惡意程式到導致資料外洩的完整攻擊鏈，驗證企業的偵測與應變能力。</span></p>
<p class="MsoNormal"><span style="color: rgb(0, 0, 0);"><span style="font-family: 新細明體, serif;">台灣</span><span lang="EN-US">CISO</span><span style="font-family: 新細明體, serif;">聯盟</span></span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;"><span style="color: rgb(0, 0, 0);">副</span>會長</span> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">朱建國表示：「在攻擊鏈高度複雜的時代，企業必須從『被動防禦』走向『主動演練』。透過真實攻防模擬，企業能在受控環境中驗證防護措施的有效性、找出偵測盲點，並縮短反應時間與損害範圍。」</span></p>
<p class="MsoNormal" style="margin-bottom: 6.0pt; line-height: normal;"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">12 </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">家上市企業演練成果亮眼　展現台灣資安實戰力</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">數聯資安總經理</span> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">李明憲指出，本次演練中各參與團隊表現亮眼，能在短時間內偵測異常行為並完成事件處置，展現企業資安團隊在實戰應變與跨部門協作上的成熟度與專業性。「透過與</span><span lang="EN-US"> Cyberbit </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的合作，我們期望協助企業建立可持續演練的訓練文化，讓資安團隊真正具備應對未知威脅的能力。」</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">李明憲進一步表示，數聯資安未來將持續與各產業聯盟合作推動資安防護演練與教育訓練，培育更多具備實戰經驗的資安人才，共同打造更具韌性與應變力的資安生態圈。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">4A9DCCBB-3DC5-4F4A-ABAB-2BCFB8D30484</guid>
      <title>全景軟體 Ciot 參與 SEMICON Taiwan 資安館，聚焦嵌入式裝置安全與合規實踐</title>
      <link>https://news.taiwannet.com.tw/news/178168/%E5%85%A8%E6%99%AF%E8%BB%9F%E9%AB%94-Ciot-%E5%8F%83%E8%88%87-SEMICON-Taiwan-%E8%B3%87%E5%AE%89%E9%A4%A8-%E8%81%9A%E7%84%A6%E5%B5%8C%E5%85%A5%E5%BC%8F%E8%A3%9D%E7%BD%AE%E5%AE%89%E5%85%A8%E8%88%87%E5%90%88%E8%A6%8F%E5%AF%A6%E8%B8%90.html</link>
      <pubDate>Tue, 09 Sep 2025 09:56:39 +0800</pubDate>
      <dc:creator> 全景軟體股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/178168_6a1d1764c45d4d1d99c1476b3b67a55d.png" border="0" style="max-width: 100%;"><p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 14.0pt; font-family: '微軟正黑體',sans-serif;">全景軟體<span lang="EN-US"> Ciot </span>參與<span lang="EN-US"> SEMICON Taiwan </span>資安館，聚焦嵌入式裝置安全與合規實踐</span></strong></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-family: '微軟正黑體',sans-serif;">全球<span lang="EN-US"> IoT </span>裝置快速擴張，根據產業研究機構<span lang="EN-US"> Transforma</span></span><span lang="EN-US" style="font-family: 'Arial',sans-serif; mso-fareast-font-family: 微軟正黑體;"> </span><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Insights </span><span style="font-family: '微軟正黑體',sans-serif;">預測，截至<span lang="EN-US"> 2024 </span>年底全球活躍<span lang="EN-US"> IoT </span>裝置數量將達<span lang="EN-US"> 17.7 </span>億台，<span lang="EN-US">2034 </span>年更將突破<span lang="EN-US"> 40.6 </span>億<sup>〔註<span lang="EN-US">1</span>〕</sup>，而超過三分之一的企業資安事件中，<span lang="EN-US">IoT </span>裝置已成為首波入侵點或攻擊鏈的一環<sup>〔註<span lang="EN-US">2</span>〕</sup>，嵌入式系統的資安與控管挑戰日益嚴峻，這些以韌體驅動、專為特定功能設計的小型裝置系統，往往資源有限，卻長期暴露於高度連網環境，導致防護難度升高<strong>。</strong></span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-family: '微軟正黑體',sans-serif;">在<span lang="EN-US"> SEMICON Taiwan 2025 </span>中，全景軟體將於工研院承辦的<span lang="EN-US"> SECPAAS </span>資安館展出「<span lang="EN-US">Ciot</span>安全解決方案」，從金鑰生成、裝置身</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">分</span><span style="font-family: '微軟正黑體',sans-serif;">建置到更新階段的完整防護，協助製造商在產品設計初期即導入資安控管機制，對應供應鏈防護與國際合規的雙重挑戰。</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-family: '微軟正黑體',sans-serif;">「資安與合規不該是設備出廠後才補上的負擔，而應是設計與製造階段的基本條件。」全景軟體<span lang="EN-US"> IoT </span>資深顧問邱志成指出。</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: '微軟正黑體',sans-serif;">生產與營運雙場域保護，設備交付前即具備安全架構</span></strong></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-family: '微軟正黑體',sans-serif;">全景軟體的<span lang="EN-US"> Ciot KMS </span>金鑰管理系統，專為製造商與營運商設計，在生產與營運場域中，高效管理大量裝置的專屬金鑰，</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">可整合</span><span style="font-family: '微軟正黑體',sans-serif;">多種<span lang="EN-US"> HSM </span>與<span lang="EN-US"> MCU Sign Tool</span>，執行金鑰生成、簽章與儲存的完整控管，</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">並</span><span style="font-family: '微軟正黑體',sans-serif;">搭配<span lang="EN-US"> Secure Boot</span>（</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">安全開機）</span><span style="font-family: '微軟正黑體',sans-serif;">驗證防止韌體遭竄改，讓設備在出廠前即完成身份初始化與信任根建置，所有作業皆符<span lang="EN-US">FIPS 140-3</span>、<span lang="EN-US">IEC 62443</span>等國際標準，保</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">障</span><span style="font-family: '微軟正黑體',sans-serif;">設備於不同應用市場皆具備資安交付能力。</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;">&nbsp;</p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: '微軟正黑體',sans-serif;">從設備身分建立到營運更新，<span lang="EN-US">CLM </span>系統全程控管</span></strong><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;"><br></span><span style="font-family: '微軟正黑體',sans-serif;">裝置進入市場後，仍面臨授權管理、通訊安全與身分更新等挑戰，<span lang="EN-US">Ciot CLM</span>憑證生命週期管理系統提供自動化的憑證簽發、管理與撤銷，支援<span lang="EN-US"> ACME </span>協議，讓雲端與伺服器自動完成憑證申請與續期；系統相容多種憑證頒發機構，</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">且能</span><span style="font-family: '微軟正黑體',sans-serif;">透過<span lang="EN-US"> Web </span>管理介面即時掌握憑證狀態，並提供<span lang="EN-US"> RESTful API&nbsp;</span></span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">彈性</span><span style="font-family: '微軟正黑體',sans-serif;">整合企業既有<span lang="EN-US"> IT/IoT </span>系統，適用於跨平台與多地區部署情境。</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: '微軟正黑體',sans-serif;">從晶片到雲端，<span lang="EN-US">Ciot</span>架構應對未來資安標準轉型</span></strong></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">Ciot </span><span style="font-family: '微軟正黑體',sans-serif;">架構具備導入後量子加密（<span lang="EN-US">PQC</span>）演算法的彈性設計，協助製造商應對長期信任與標準轉換挑戰，可應用於智慧家庭、電網、車載、工控、醫療等高安全性</span><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-fareast-language: ZH-HK;">領域</span><span style="font-family: '微軟正黑體',sans-serif;">，全景軟體也將持續深化與晶片廠、設備商的合作，攜手對應國際規範，搶佔高資安應用市場。更多產品資訊，請參考全景軟體官網：<span class="MsoHyperlink"><span lang="EN-US"><a href="https://www.changingtec.com/">https://www.changingtec.com</a></span></span>。</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-bidi-font-weight: bold;">〔</span><span lang="ZH-HK" style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-fareast-language: ZH-HK; mso-bidi-font-weight: bold;">註</span><span lang="EN-US" style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-fareast-language: ZH-HK; mso-bidi-font-weight: bold;">1.</span><span style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-bidi-font-weight: bold;">〕<span lang="EN-US"><a href="https://iotbusinessnews.com/2025/06/11/19501-global-iot-connections-forecast-to-rise-above-40-billion-in-2034/">Global IoT connections forecast to rise above 40 billion in 2034</a></span></span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-bidi-font-weight: bold;">〔</span><span lang="ZH-HK" style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-fareast-language: ZH-HK; mso-bidi-font-weight: bold;">註</span><span lang="EN-US" style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-fareast-language: ZH-HK; mso-bidi-font-weight: bold;">2.</span><span style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-bidi-font-weight: bold;">〕<span lang="EN-US"><a href="file:///D:\Processing\8月新聞稿_半導體展_2025Aug\IoT%20Security%20Statistics%202025&ndash;26:%20Threats,%20Trends%20&amp;%20Safeguards%20in%20a%20Connected%20World">IoT Security Statistics 2025&ndash;26: Threats, Trends &amp; Safeguards in a Connected World</a></span></span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-size: 9.5pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 新細明體; mso-font-kerning: 0pt; mso-bidi-font-weight: bold;">&nbsp;</span></p>
<p class="MsoListParagraph" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: 20.0pt; mso-line-height-rule: exactly; mso-list: l1 level1 lfo2; background: white;"><!-- [if !supportLists]--><span lang="EN-US" style="mso-bidi-font-size: 11.0pt; font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">n<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US" style="mso-bidi-font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-fareast-language: ZH-TW;">SEMICON Taiwan 2025</span></strong><strong style="mso-bidi-font-weight: normal;"><span style="mso-bidi-font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-fareast-language: ZH-TW;">展覽資訊</span></strong></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><span style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-weight: bold;">全景軟體攤位編號</span><span style="font-family: '微軟正黑體',sans-serif;">：<span lang="EN-US">Q5744</span>（<span lang="EN-US">SECPAAS </span>資安主題館）</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><span style="font-family: '微軟正黑體',sans-serif;">展期：<span lang="EN-US">2025.9.10(</span>三<span lang="EN-US">)~9.12(</span>五<span lang="EN-US">)</span></span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><span style="font-family: '微軟正黑體',sans-serif;">地點：南港展覽館<span lang="EN-US"> 2 </span>館<span lang="EN-US"> 1 </span>樓</span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo;">SEMICON Taiwan 2025 - Event Map</span></p>
<p class="MsoListParagraphCxSpFirst" style="margin-left: 0cm; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo; mso-fareast-language: ZH-TW;">&nbsp;</span></strong></p>
<p class="MsoListParagraphCxSpLast" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: 20.0pt; mso-line-height-rule: exactly; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">n<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><strong style="mso-bidi-font-weight: normal;"><span style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo; mso-fareast-language: ZH-TW;">全景</span></strong><strong style="mso-bidi-font-weight: normal;"><span lang="ZH-HK" style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo; mso-fareast-language: ZH-HK;">軟體</span></strong><strong style="mso-bidi-font-weight: normal;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo; mso-fareast-language: ZH-TW;">Ciot</span></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: Meiryo; mso-fareast-language: ZH-TW;">安全解決方案</span></strong></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span class="MsoHyperlink"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">https://www.changingtec.com/iot_security.html</span></span></p>
<p class="MsoNormal" style="line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-family: '微軟正黑體',sans-serif;">&nbsp;</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: 20.0pt; mso-line-height-rule: exactly;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black;">媒體聯絡單位</span></strong></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black; mso-bidi-font-weight: bold;">全景軟體 行銷公關部</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black; mso-bidi-font-weight: bold;">電話：<span lang="EN-US">03-563-0688</span></span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black; mso-bidi-font-weight: bold;">EMAIL</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black; mso-bidi-font-weight: bold;">：</span><span class="MsoHyperlink"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black;"><a href="mailto:marcom@changingtec.com"><span style="color: black;">marcom@changingtec.com</span></a></span></span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: 20.0pt; mso-line-height-rule: exactly;"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; color: black; mso-bidi-font-weight: bold;">&nbsp;</span></p>
<p style="margin: 0cm; margin-bottom: .0001pt; line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 'Times New Roman';">關於全景軟體<span lang="EN-US"> CHANGING Information Technology Inc.</span></span></strong></p>
<p style="margin: 0cm; margin-bottom: .0001pt; line-height: 20.0pt; mso-line-height-rule: exactly; background: white;"><span style="font-family: '微軟正黑體',sans-serif; mso-bidi-font-family: 'Times New Roman';">全景軟體秉持自主研發精神，致力於建立安全且便捷的網路應用環境，核心專業領域包括人、事、物的認證安全，如關鍵驗證<span lang="EN-US">-</span>零信任架構、物聯網安全、科技金融資安及數位轉型應用等，憑藉超過<span lang="EN-US">25</span>年的深厚專業知識，使命在於為各行各業構建更加安全且可信賴的零信任網路環境架構，同時不斷創新，提供多元化的產品與服務，以滿足客戶多樣化的需求，並一同建立更為安全、高效的網路環境，在數位時代中，成為您可以依賴的合作夥伴。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">48ED6E5F-4AED-4A25-BB36-36196B72B817</guid>
      <title>Cynet CyAI 以機器學習即時偵測，在威脅發生前鎖定並阻斷</title>
      <link>https://news.taiwannet.com.tw/news/176084/Cynet-CyAI-%E4%BB%A5%E6%A9%9F%E5%99%A8%E5%AD%B8%E7%BF%92%E5%8D%B3%E6%99%82%E5%81%B5%E6%B8%AC-%E5%9C%A8%E5%A8%81%E8%84%85%E7%99%BC%E7%94%9F%E5%89%8D%E9%8E%96%E5%AE%9A%E4%B8%A6%E9%98%BB%E6%96%B7.html</link>
      <pubDate>Thu, 21 Aug 2025 10:05:09 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>產經商業</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/176084_1898861b1fbb428988d6452a6c7f2245.jpg" border="0" style="max-width: 100%;"><p class="MsoListParagraphCxSpFirst" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><span style="font-family: 微軟正黑體, sans-serif;">隨著網路攻擊的數量和複雜度不斷增加，企業需要精準有效的威脅偵測能力，以確保資源安全與營運連續性。 中華數位科技代理的 <span lang="EN-US">Cynet </span>一體化網路安全平台，所搭載的<span lang="EN-US"> AI </span>引擎<span lang="EN-US"> CyAI </span>可在活躍環境中發現其他防毒軟體未能偵測的新威脅，並透過雲端回饋機制持續優化。</span><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">&nbsp;</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">CyAI </span><span style="font-family: 微軟正黑體, sans-serif;">利用基於「數百萬」個樣本訓練的機器學習模型，分析所有端點上每個可執行檔與行為，結合靜態與行為式分析，在造成損害之前即時檢測已知威脅和零日攻擊。並與<span lang="EN-US"> Cynet </span>的<span lang="EN-US"> EDR/EPP/NDR/MDR </span>等模組自動化整合以完成調查與修復。在最新的<span lang="EN-US"> MITRE ATT&amp;CK </span>評估中，<span lang="EN-US">Cynet </span>是唯一能夠實現<span lang="EN-US"> 100% </span>防護、<span lang="EN-US"> 100% </span>檢測可見度且零誤報的解決方案。</span><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">&nbsp;</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><span style="font-family: 微軟正黑體, sans-serif;">隨著<span lang="EN-US"> CyAI </span>的演進，<span lang="EN-US">Cynet </span>的檢測能力將更加強大。全新設計的<span lang="EN-US"> AI </span>核心提供更精準、更廣泛的威脅覆蓋範圍。由人工智慧驅動的一體化安全平台，加上<span lang="EN-US"> 24/7 </span>全天候<span lang="EN-US"> MDR CyOps </span>專家提供支持，與單一控制台提供人工智慧自動化工作流程，協助企業降低風險。</span><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">&nbsp;</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><strong><span lang="EN-US" style="mso-bidi-font-size: 12.0pt; font-family: '微軟正黑體',sans-serif; color: #156082; mso-themecolor: accent1;">Cynet CyAI </span></strong><strong><span style="mso-bidi-font-size: 12.0pt; font-family: '微軟正黑體',sans-serif; color: #156082; mso-themecolor: accent1;">適用情境與效果</span></strong><strong><span lang="EN-US" style="mso-bidi-font-size: 12.0pt; font-family: '微軟正黑體',sans-serif;">&nbsp;</span></strong></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; line-height: 20pt; padding-left: 40px;"><span style="font-size: 12pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font-style: normal; font-variant: normal; font-size-adjust: none; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span></span><!--[endif]--><strong><span style="font-family: 微軟正黑體, sans-serif;">零日惡意程式<span lang="EN-US"> / </span>新變種惡意程式：</span></strong><span style="font-family: 微軟正黑體, sans-serif;">當攻擊不在特徵庫中時，<span lang="EN-US">CyAI </span>的行為特徵與機器學習判斷能較早標記可疑執行檔與行為，避免被漏掉。</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; line-height: 20pt; padding-left: 40px;"><span style="font-size: 12pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font-style: normal; font-variant: normal; font-size-adjust: none; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span></span><!--[endif]--><strong><span style="font-family: 微軟正黑體, sans-serif;">勒索軟體入侵與快速隔離：</span></strong><span style="font-family: 微軟正黑體, sans-serif;">透過行為監控（如大量檔案異常寫入、加密行為指標）與自動回應，可迅速中斷攻擊鏈並限制蔓延。</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; line-height: 20pt; padding-left: 40px;"><span style="font-size: 12pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font-style: normal; font-variant: normal; font-size-adjust: none; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span></span><!--[endif]--><strong><span style="font-family: 微軟正黑體, sans-serif;">無檔案攻擊：</span></strong><span style="font-family: 微軟正黑體, sans-serif;">對執行時行為做<span lang="EN-US">ML</span>分析，能找出使用合法工具被濫用的可疑流程（例如<span lang="EN-US"> PowerShell </span>或<span lang="EN-US"> WMIC </span>被異常利用）。</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; line-height: 20pt; padding-left: 40px;"><span style="font-size: 12pt;"><!-- [if !supportLists]--><span lang="EN-US" style="font-family: Wingdings;"><span style="mso-list: Ignore;">l<span style="font-style: normal; font-variant: normal; font-size-adjust: none; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal; font-family: 'Times New Roman';">&nbsp; </span></span></span><!--[endif]--><strong><span style="font-family: 微軟正黑體, sans-serif;">降低<span lang="EN-US"> SOC </span>工作量與誤報過濾：</span></strong><span style="font-family: 微軟正黑體, sans-serif;">在大量告警環境中，準確的機器學習偵測可把誤報降低<span lang="EN-US"> 90%</span>，讓人員集中處理高價值事件。</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">Cynet CyAI </span><span style="font-family: 微軟正黑體, sans-serif;">以大規模樣本訓練模型與可持續學習深度回饋機制，即時分析檔案與行為，降低誤報與提高精準度，並與全套防護（<span lang="EN-US">EDR/NDR/EPP/MDR</span>）整合於單一平台。當偵測到威脅後可觸發自動調查與一鍵或自動修復（隔離、阻斷、復原），縮短偵測到回應時間，並由原廠資安分析師<span lang="EN-US"> 24/7 </span>全天候協助威脅獵捕與事件回應，幫助用戶處理超出內部安全人員能力範圍的任務，有效減少<span lang="EN-US"> "</span>告警疲勞<span lang="EN-US">"</span>，大幅降低人力依賴與縮短回應事件調查時間。</span><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">&nbsp;</span></span></p>
<p class="MsoNormal" style="mso-margin-bottom-alt: auto; margin-left: 7.1pt; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt;"><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">Softnext </span><span style="font-family: 微軟正黑體, sans-serif;">中華數位科技長期追蹤資安威脅發展趨勢，深知企業的資安需求不僅限於郵件安全，為提供企業更完善的資安防禦解決方案，除了強化自主研發產品的防禦能力，亦代理國際資安大廠的專業防護產品，從各個重點缺口著手防禦，以多元的防禦解決方案，協助企業打造更完備的防禦環境，降低資安風險。</span></span></p>
<p class="MsoNormal" style="margin-left: 7.1pt; mso-line-height-alt: 0pt;"><span style="font-size: 12pt;"><strong><span lang="EN-US" style="font-family: 微軟正黑體, sans-serif;">Softnext </span></strong><strong><span style="font-family: 微軟正黑體, sans-serif;">中華數位科技重點代理產品：</span></strong></span></p>
<p class="MsoNormal" style="margin-left: 7.1pt; mso-line-height-alt: 0pt;"><span style="font-size: 12pt; font-family: 微軟正黑體, sans-serif;">．<span lang="EN-US">Cynet 360 AutoXDR </span>自主安全保護平台：擴展檢測和響應<span lang="EN-US"> (XDR)+</span>自動化響應<span lang="EN-US">+MDR</span>（<span lang="EN-US">24/7 </span>託管檢測和響應）</span></p>
<p class="MsoNormal" style="margin-left: 7.1pt; mso-line-height-alt: 0pt;"><span style="font-size: 12pt; font-family: 微軟正黑體, sans-serif; color: black;">．<span lang="EN-US">Action1</span>雲原生漏洞修補管理平台：提供漏洞修補管理、遠端存取、<span lang="EN-US">Window/MacOS</span>與第三方應用軟體部署、端點管理、<span lang="EN-US">IT </span>資產清單</span></p>
<p class="MsoListParagraph" style="margin-left: 7.1pt; mso-add-space: auto; line-height: 20.0pt; mso-line-height-rule: exactly;"><span style="font-size: 12pt; font-family: 微軟正黑體, sans-serif; color: black;">．<span lang="EN-US">Netwrix</span>：以身分為中心的資料保護解決方案，保護儲存關鍵資訊及用於存取這些資訊的工具，避免受關鍵攻擊面（資料、身分和端點）的侵害。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">3E80FC66-9E1E-48A5-A345-A41C809DB2CD</guid>
      <title>ASRC 2025年第二季電子郵件安全觀察</title>
      <link>https://news.taiwannet.com.tw/news/174440/ASRC-2025%E5%B9%B4%E7%AC%AC%E4%BA%8C%E5%AD%A3%E9%9B%BB%E5%AD%90%E9%83%B5%E4%BB%B6%E5%AE%89%E5%85%A8%E8%A7%80%E5%AF%9F.html</link>
      <pubDate>Fri, 08 Aug 2025 00:00:00 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/174440_73241a3b849b4dcc9f9b90e8bb036842.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">郵件系統重大安全事件陸續曝光</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">多起郵件系統相關的重大安全事件在這一季被揭露。</span><span lang="EN-US">4 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">月份，日本知名的</span><span lang="EN-US"> Web </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">郵件系統</span><span lang="EN-US"> Active! Mail </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">爆出高風險漏洞</span><span lang="EN-US"> CVE-2025-42599</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。該漏洞屬於堆疊緩衝區溢位問題，因系統未正確限制寫入長度，導致攻擊者可覆寫堆疊記憶體結構，進一步操控程式流程並觸發遠端任意程式碼執行（</span><span lang="EN-US">RCE</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">緊接著在</span><span lang="EN-US"> 6 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">月份，郵件伺服器</span><span lang="EN-US"> Roundcube </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">也被揭露存在幾近滿分的重大漏洞</span><span lang="EN-US"> CVE-2025-49113</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。僅僅三天內，暗網即出現販售該漏洞利用方法的訊息，顯示其風險極高。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">同月，還爆出</span><span lang="EN-US"> Microsoft Office Outlook </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">存在「目錄遍歷」（</span><span lang="EN-US">path traversal</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）漏洞</span><span lang="EN-US"> CVE-2025-47176</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，攻擊者可藉由「&hellip;</span><span lang="EN-US">/</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">&hellip;</span><span lang="EN-US">//</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">」序列繞過路徑限制。此漏洞一般使用者權限即可觸發，無需管理員或更高權限，擴大了潛在攻擊面。</span></p>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">來自合法來源的釣魚郵件，規避傳統安全檢測機制</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">除了上述漏洞外，</span><span lang="EN-US">3 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">至</span><span lang="EN-US"> 5 </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">月間亦觀察到大量濫用合法信任來源的釣魚郵件活動。許多釣魚郵件運用政府、機關組織或學校網域，透過</span><span lang="EN-US"> outlook.com </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">或其他被濫用的郵件伺服器發送，信件中夾帶</span><span lang="EN-US"> forms.clickup.com </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的釣魚連結。這些攻擊行為是利用</span><span lang="EN-US"> ClickUp </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的線上表單功能，發送看似正常的請求，引誘收件者提交敏感資料或點擊惡意連結。</span></p>
<p class="MsoNormal"><span style="font-size: 12.0pt; line-height: 115%; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;">這類郵件可能來自遭入侵的合法帳號，因此具有較高的信任度，較不易被收件者識破。透過</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 115%; font-family: 'Aptos',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;"> forms.clickup.com </span><span style="font-size: 12.0pt; line-height: 115%; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;">所嵌入的表單，攻擊者引導目標至偽造的登入頁面，竊取</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 115%; font-family: 'Aptos',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;"> Microsoft 365 </span><span style="font-size: 12.0pt; line-height: 115%; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;">或其他雲端服務的登入憑證。這種利用合法域名與平台進行繞過式偽裝的釣魚手法，能有效規避許多傳統的安全檢測機制，需特別留意。</span></p>
<p class="MsoNormal"><span style="font-size: 12.0pt; line-height: 115%; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;"><a href="https://media.softnext.com.tw/edm/asrc/2025Q2/s01.jpg" target="_blank" rel="noopener"><img style="display: block; margin-left: auto; margin-right: auto;" src="https://media.softnext.com.tw/edm/asrc/2025Q2/s01.jpg" alt="" width="700" height="253"></a></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: 10pt; line-height: 115%; font-family: 新細明體, serif; color: rgb(53, 152, 219);">forms.clickup.com 表單，被用來收集 Microsoft 365 用戶的敏感資料</span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">低調卻高風險，</span><span lang="EN-US">Open Redirect </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">成為釣魚網站庇護傘</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">此外，大量的開放重新導向（</span><span lang="EN-US">Open Redirect</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）機制正被攻擊者廣泛利用，成為釣魚網站的「庇護傘」。這類漏洞允許使用者透過合法網站的連結，自動跳轉至任意指定的外部網址，原本設計用途多為用戶體驗或流量分析所需，但一旦缺乏驗證機制，即成為攻擊者進行欺騙的工具。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">令人憂心的是，這些被濫用的</span><span lang="EN-US"> Open Redirect </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">通常來自知名網站或大型平台，例如雲端服務供應商、政府或教育機構網站、企業入口頁等，其域名本身具有高度信任度。一旦攻擊者將釣魚網址包裝在這些可信網域的跳轉參數中，就容易騙過收件者、資安掃描機制，甚至繞過瀏覽器的安全警告或封鎖措施。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">實務上，我們觀察到部分服務的開放重新導向漏洞已被濫用多年，但仍持續存在、未被修補，顯示出業界對此類低調卻高風險漏洞的關注仍有所不足。這不僅為釣魚攻擊提供穩定的跳板，也凸顯了在信任機制與網域聲譽管理上仍有加強空間。</span></p>
<p class="MsoNormal" style="text-align: center;"><img style="display: block; margin-left: auto; margin-right: auto;" src="https://media.softnext.com.tw/edm/asrc/2025Q2/s02.jpg" alt="" width="700" height="511"><span style="font-size: 10pt; line-height: 115%; font-family: 新細明體, serif; color: rgb(53, 152, 219);">來自知名的網域或服務，但被用於導向釣魚網站，有機會騙過收件者、資安檢測機制或瀏覽器的安全檢查</span></p>
<p class="MsoNormal" style="text-align: center;">&nbsp;</p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">釣魚郵件濫用合法</span><span lang="EN-US">Edm</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">發送平台，仍難以根除</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">除了釣魚網站經常藏身於各種「庇護傘」之下，釣魚郵件本身也經常濫用合法的</span><span lang="EN-US"> EDM</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（電子郵件行銷）發送平台作為傳遞工具。攻擊者利用這些廣泛使用、信譽良好的發信機制，讓釣魚郵件表面上看起來就像一般正常的促銷信或服務通知，更容易騙過使用者與安全系統的判斷。這種情況已經持續存在多年，至今仍難以根除。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">主要原因在於</span><span lang="EN-US"> EDM </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">平台本身的設計目的就是為了協助企業大規模寄送郵件，因此在機制上往往偏重效率與送達率，較難即時察覺個別帳號是否被濫用或出現異常行為。即便部分平台導入內容掃描與異常行為偵測，也往往無法阻擋針對性強、包裝精緻的釣魚郵件。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">在這樣的風險環境下，我們應重新思考對</span><span lang="EN-US"> EDM </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">發送機制的信任模型。過去多數使用者傾向「信任平台即信任郵件」的思維，特別是來自知名企業或第三方發信商的郵件，往往自動被視為安全。但實際上，這類信任機制已無法抵擋針對性濫用行為的滲透。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">因此，更安全且可控的方式，應是將</span><span lang="EN-US"> EDM </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">的信任基礎由「企業單位」下放到「個人層級」：僅對使用者本人主動訂閱且確認過的寄件來源建立信任，並鼓勵使用者定期檢視、管理自己的訂閱名單。系統層面則應強化對</span><span lang="EN-US"> EDM </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">類郵件的驗證與過濾策略，降低僅因信任平台就放行所有郵件的風險。</span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: 10pt; line-height: 115%; font-family: 新細明體, serif; color: rgb(53, 152, 219);"><img src="https://media.softnext.com.tw/edm/asrc/2025Q2/s03.jpg" alt="" width="700" height="341"></span></p>
<p class="MsoNormal" style="text-align: center;"><span style="font-size: 10pt; line-height: 115%; font-family: 新細明體, serif; color: rgb(53, 152, 219);"><span style="line-height: 115%; font-family: 新細明體, serif;">常見的合法 </span><span lang="EN-US" style="line-height: 115%; font-family: Aptos, sans-serif;">EDM </span><span style="line-height: 115%; font-family: 新細明體, serif;">發送機制遭到濫用</span></span></p>
<p class="MsoNormal" style="text-align: center;">&nbsp;</p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">本季郵件攻擊趨勢可歸納為五個方向</span></strong></p>
<p class="MsoNormal"><strong><span lang="EN-US">1.</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">濫用合法資源：</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者利用知名的雲端服務、郵件平台，甚至是遭入侵的政府或學術機構帳號。除了大幅降低成本，還能藉由「信任轉嫁」繞過傳統的安全偵測機制。相較之下<span style="color: #156082; mso-themecolor: accent1;">，</span>購買專用的惡意資源不僅價格昂貴，還可能在取得過程中暴露身份資訊，一旦遭列為惡意資源，便會立即遭封鎖或失效。</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">2.</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">信任鏈滲透：</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">透過合法的發信來源發送釣魚郵件，並將惡意網站寄生於可信的第三方平台下，不僅難以察覺也更具迷惑性與高成功率。這類攻擊先從平台服務本身或其漏洞著手，將合法資源轉為攻擊跳板，進一步對真正的目標發動攻擊，讓原本處於信任關係中的節點也成為潛在風險源。</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">3.</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">漏洞快速武器化：</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">漏洞一被發現，尤其是</span><span lang="EN-US">CVSS</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">評分高及遠端任意執行代碼的漏洞，發現漏洞的攻擊者除了可能自行利用外，也會在很短的時間內將漏洞武器化並兜售，極短的時間就可獲得實際收益。</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">4.</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">低權限即可入侵：</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">攻擊者無需取得管理員權限，就能透過簡單手法滲透系統、橫向移動甚至植入惡意程式，有效提升攻擊效率並擴大影響範圍。</span></p>
<p class="MsoNormal"><strong><span lang="EN-US">5.</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">多層混合式攻擊：</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">社交工程、假登入頁、跨平台整合等多種技術的組合應用，使得釣魚與入侵手法呈現多層混合、難以單一手段應對。</span></p>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">因此，面對日益複雜與隱蔽的攻擊樣態，僅靠單點式的防禦措施（如僅靠企業建置的防禦機制）已難以有效阻擋整體攻擊鏈。真正有效的防護策略，需仰賴跨單位、跨平台的協作，整合威脅情資、共享信任評級，才能及時發現並阻斷這類複合型攻擊的傳播路徑。</span></p>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><strong><span style="font-size: 13.5pt; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; color: black;">關於</span></strong><strong><span lang="EN-US" style="font-size: 13.5pt; font-family: 'Aptos',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; color: black;"> ASRC </span></strong><strong><span style="font-size: 13.5pt; font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; color: black;">垃圾訊息研究中心</span></strong><strong><span style="font-size: 13.5pt; font-family: 'Aptos',sans-serif; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; color: black;"> </span></strong></p>
<p class="MsoNormal" style="mso-line-height-alt: 0pt;"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">垃圾訊息研究中心</span><span lang="EN-US"> (Asia Spam-message Research Center)</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，長期與中華數位科技合作，致力於全球垃圾郵件、惡意郵件、網路攻擊事件等相關研究事宜，並運用相關數據統計、調查、趨勢分析、學術研究、跨業交流、研討活動</span><span lang="EN-US">..</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等方式，促成產官學界共同致力於淨化網際網路之電子郵件使用環境。</span><span lang="EN-US"><br></span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">更多資訊請參考<a href="https://www.asrc-global.com">ASRC 垃圾訊息研究中心網站</a></span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">ADF1023F-ED1F-4679-8D55-CF2B09254AF1</guid>
      <title>微步入選Gartner®首份NDR魔力象限報告</title>
      <link>https://news.taiwannet.com.tw/news/168302/%E5%BE%AE%E6%AD%A5%E5%85%A5%E9%81%B8Gartner%C2%AE%E9%A6%96%E4%BB%BDNDR%E9%AD%94%E5%8A%9B%E8%B1%A1%E9%99%90%E5%A0%B1%E5%91%8A.html</link>
      <pubDate>Wed, 04 Jun 2025 22:25:00 +0800</pubDate>
      <dc:creator>PR Newswire 美通社</dc:creator>
      <category>大陸港澳</category>
      <description><![CDATA[<p><span class="legendSpanClass">北京</span><span class="legendSpanClass">2025年6月4日</span> /美通社/ -- 歷時近1年調研評估，Gartner於5月29日發布首份《網路檢測與回應魔力象限》報告（Magic Quadrant™ for Network Detection and Response），微步在線（ThreatBook）成為唯一入選的中國企業。</p>  <div class="PRN_ImbeddedAssetReference" id="DivAssetPlaceHolder2528">   <p style="TEXT-ALIGN: center; WIDTH: 100%"><a href="https://mma.prnasia.com/media2/2703087/X_Gartner_MQ_1.html" target="_blank" rel="nofollow" style="color: #0000FF"><img src="https://mma.prnasia.com/media2/2703087/X_Gartner_MQ_1.jpg?p=medium600" title="" alt="" /></a><br /><span></span></p>  </div>  <p>隨著企業加速上雲和網路攻擊日益複雜化，<b>NDR（網路檢測與回應）技術</b>已成為現代安全營運中心（SOC）不可或缺的底層設施。透過持續監控東西向與南北向流量，有效覆蓋傳統安全設備難以檢測的橫向威脅，結合流量阻斷、主機遏制或聯動 SOAR、SIEM 可實現閉環處置，大幅縮短響應時間，同時支援 IaaS 及 SaaS 化部署，靈活適配多雲混合環境，成為了雲化安全的重要基石。微步認為，此次 NDR 魔力象限的發布，不僅標誌著流量檢測響應技術的成熟與市場體量的進階，更是安全範式從「被動防禦」向「主動營運」轉型的標誌。</p>  <p><b>實戰能力：精準檢測、自動響應與雲化優勢</b></p>  <p>微步 TDP 作為深度融合情報的實戰化全流量檢測與響應平台，依托前沿創新技術，有效解決 0day 漏洞檢測、攻擊面識別及失陷主機定位等核心安全問題：</p>  <ul type="disc">   <li><b>精準檢測：</b>&nbsp;全面覆蓋攻擊鏈手法，自動判定攻擊成敗並進行告警關聯分析，將誤報率降至 0.003%；結合高品質漏洞情報、行為分析引擎及雲沙箱，實戰場景下對 0day 攻擊檢出率高達 81%。</li>   <li><b>高效解密與響應：</b>&nbsp;創新融合旁路部署與代理技術，無需調整網絡架構即可實現高性能 TLS 解密，加密通信識別率達 99%；基於情報、攻擊判定及自定義策略自動旁路阻斷後續攻擊，雙向阻斷率 99%，並精準定位威脅至進程級，可聯動 20 餘種第三方安全設備形成閉環響應。</li>   <li><b>雲原生適配：</b>&nbsp;全面支援阿里云、AWS、Azure 等主流雲平台，以輕量級 Agent 替代傳統 NFV 鏡像，大幅降低雲上檢測成本；精準捕捉傳輸過程中的 AK/SK 等敏感憑證洩露風險。</li>  </ul>  <p><b>多場景滲透與高續約驗證價值</b></p>  <p>微步 TDP 針對當前企業面臨的核心流量威脅痛點，提供多場景解決方案：</p>  <ul type="disc">   <li><b>全網高級威脅防護：</b>在網絡結構複雜、具備基礎防護但缺乏高級防禦能力的環境中，不僅能夠聚焦真實威脅，過濾海量無效告警，同時提供高級威脅識別與 APT 抵禦。</li>   <li><b>多分支統一管理：</b>&nbsp;為大型集團實現總部對分支告警數據的集中展示、研判與安全管理，降低維運成本，提升整體安全水位。</li>   <li><b>資產風險監控：</b>&nbsp;自動化梳理網絡資產，識別暴露面及不安全 API，防範數據洩露，提供個性化風險監控與集中告警。</li>  </ul>  <p>憑藉「精準、實戰、閉環、易用」的核心優勢，微步 TDP 已服務於金融、能源、製造、互聯網、地產等多個行業數千家企業，其中包括數十家香港客戶，並保持了高續約率，市場表現領先業界。能力亦獲客戶高度認可，連續兩年入選 Gartner&reg; Peer Insights™ 網絡檢測與響應客戶之聲「強勁表現者」。</p>  <p>微步相信，此次入選 Gartner 首份 NDR 魔力象限，是對微步產品技術實力與服務能力的雙重認可，標誌著微步「技術縱深+場景深耕」路線得到驗證。未來，在複雜多變的網絡安全環境中，微步將繼續聚焦威脅檢測，依托 AI+TI 的核心能力，為行業用戶提供更可信賴的流量檢測支持。</p>  <p>Gartner, Magic Quadrant for Network Detection and Response, <span class="xn-chron">29 May 2025</span></p>  <p>Gartner, Voice of the Customer for Network Detection and Response, <span class="xn-chron">30 August 2024</span></p>  <p>Gartner 並未在其研究報告中支持任何供應商、產品或服務，也並未建議科技用戶只選擇該等獲最高評分或其它稱號的供應商。Gartner 的研究報告含有 Gartner 研究與顧問組織的意見，且該意見不應被視作事實陳述。就該研究報告而言，Gartner 放棄做出所有明示或默示的保證，包括任何有關適銷性或某一特定用途適用性的保證。Gartner 同行洞察是基於最終用戶個人經驗的主觀意見，並不代表 Gartner 或其關聯公司的觀點。 GARTNER、MAGIC QUADRANT 和 PEER INSIGHTS 是 Gartner, Inc. 和/或其關聯公司在美國和國際上的商標，並在獲得許可的情況下在此使用。保留所有權利。</p>  <p><b>關於微步在線</b></p>  <p>微步成立於2015年，是數位時代網路安全技術創新企業，專注於精準、高效、智慧的網路威脅發現和響應，開創並引領中國威脅情報行業的發展，以威脅情報 <b>TI</b> 和人工智慧 <b>AI</b> 為技術內核，提供 <b>TI+AI</b> 驅動的「雲+流量+邊界+端點」新一代智慧安全營運產品及服務，幫助客戶建立全生命週期的威脅監控體系和安全響應能力。</p>  <div class="PRN_ImbeddedAssetReference" id="DivAssetPlaceHolder0">  </div>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">89B7B63B-0B1A-464B-A940-802776BE6761</guid>
      <title>Sophos 發現電子郵件轟炸與語音詐騙攻擊升級且 3AM 勒索軟體趁勢而起</title>
      <link>https://news.taiwannet.com.tw/news/167434/Sophos-%E7%99%BC%E7%8F%BE%E9%9B%BB%E5%AD%90%E9%83%B5%E4%BB%B6%E8%BD%9F%E7%82%B8%E8%88%87%E8%AA%9E%E9%9F%B3%E8%A9%90%E9%A8%99%E6%94%BB%E6%93%8A%E5%8D%87%E7%B4%9A%E4%B8%94-3AM-%E5%8B%92%E7%B4%A2%E8%BB%9F%E9%AB%94%E8%B6%81%E5%8B%A2%E8%80%8C%E8%B5%B7.html</link>
      <pubDate>Tue, 27 May 2025 14:59:16 +0800</pubDate>
      <dc:creator>Wordtech Ltd.</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/167434_47ca44762d924aaa88306cee880fdc03.jpg" border="0" style="max-width: 100%;"><p>Sophos X-Ops 最新研究揭露，多個勒索軟體集團正在進行一項持續性的攻擊行動。攻擊者採用「電子郵件轟炸」(在短短一小時內寄出數千封電子郵件) 與「語音詐騙」(假冒語音訊息) 相結合的手法，企圖滲透企業網路並竊取資料。在這起攻擊行動中，攻擊者偽裝成 Microsoft Teams 的技術支援人員，誘騙員工提供電腦的遠端存取權限；一旦取得存取權，攻擊者便可下載並植入勒索軟體。</p>
<p>Sophos X-Ops 最初於今年一月揭露這起攻擊行動，當時已有 15 間公司受害。自此之後，根據 Sophos MDR 與事件回應 (IR) 的案件資料，Sophos X-Ops 已識別出超過 55 起其他的攻擊嘗試。然而，另一個勒索軟體集團 3AM 也採用了類似的攻擊鏈，不過卻在多個關鍵環節調整手法以提高攻擊成功率： &nbsp;</p>
<ul>
<li>在受害電腦上部署虛擬機器，藉此躲避端點防護軟體的偵測</li>
<li>根據對目標的深入偵察調整攻擊手法：掌握特定員工的電子郵件地址與電話號碼，並透過網路語音電話假裝電話是來自企業內部的客服專線</li>
<li>在發動勒索攻擊前潛伏並進行長達 9 天的偵察&nbsp;</li>
</ul>
<p>Sophos 首席威脅研究員 Sean Gallagher 表示：「語音詐騙 (vishing) 與電子郵件轟炸的組合，依然是勒索軟體攻擊者極具威力且有效的手法，而 3AM 勒索軟體集團如今也找到了方法，透過遠端加密來規避傳統安全軟體的偵測。由於這些社交工程手法已被證實有效，我們預期這兩種語音詐騙/電子郵件轟炸攻擊活動仍將持續活躍。</p>
<p>「為了維護安全，企業首先應該提升員工的資安意識，並嚴格限制遠端存取的行為。其中包括制定政策，禁止員工在不應安裝此類軟體的電腦上執行虛擬機器或遠端存取工具。此外，也應封鎖所有與遠端控制相關的進出站網路流量，僅允許經授權的遠端存取系統連線。」&nbsp;</p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">DC1614FE-88C1-45DA-BF92-856EDFD3FDDA</guid>
      <title>Fortinet公布《2025全球資安威脅預測》： 威脅手法更加強大精準，攻擊鏈專業化、雲端威脅增長，挑戰當前資安防禦極限</title>
      <link>https://news.taiwannet.com.tw/news/151990/Fortinet%E5%85%AC%E5%B8%83%E3%80%8A2025%E5%85%A8%E7%90%83%E8%B3%87%E5%AE%89%E5%A8%81%E8%84%85%E9%A0%90%E6%B8%AC%E3%80%8B%EF%BC%9A-%E5%A8%81%E8%84%85%E6%89%8B%E6%B3%95%E6%9B%B4%E5%8A%A0%E5%BC%B7%E5%A4%A7%E7%B2%BE%E6%BA%96-%E6%94%BB%E6%93%8A%E9%8F%88%E5%B0%88%E6%A5%AD%E5%8C%96-%E9%9B%B2%E7%AB%AF%E5%A8%81%E8%84%85%E5%A2%9E%E9%95%B7-%E6%8C%91%E6%88%B0%E7%95%B6%E5%89%8D%E8%B3%87%E5%AE%89%E9%98%B2%E7%A6%A6%E6%A5%B5%E9%99%90.html</link>
      <pubDate>Fri, 13 Dec 2024 00:00:00 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/151990_710e955df4d540d0990338a3c8df2b0e.jpg" border="0" style="max-width: 100%;"><p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">全方位整合與自動化網路資安領導廠商</span><span style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;"> </span><span lang="EN-US"><span style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體;">Fortinet&reg;</span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">NASDAQ</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">：</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">FTNT</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）旗下</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">FortiGuard Labs</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">威脅情資中心今（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">12</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）日公布</span><span lang="EN-US"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;">《</span><span style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體;">2025</span><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;">全球資安威脅預測》</span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">。報告指出，威脅者將採用更大規模、更大膽的手法，將其攻擊鏈專業化、強化特定攻擊環節，同時發展更具針對性、更複雜的結合虛實世界的攻擊劇本。此外，由於組織上雲趨勢，威脅者也將聚焦關注雲端環境、利用更多相關漏洞，自動化駭客工具也已進入暗網市場，預期將為其網路犯罪即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Cybercrime-as-a-Service</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">，</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">CaaS</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）的強度、規模再提升。</span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; layout-grid-mode: char;">&nbsp;</p>
<p style="margin: 0cm; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">台灣區總經理吳章銘表示：「在</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">AI</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">技術發展的推波助瀾之下，網路犯罪手法持續演進。台灣企業組織處於威脅者關注熱區，更需正視組織全體資訊安全、積極採取行動。未來攻擊力道將不減反增，並以更多元化、複雜的形式出現，防禦方不僅要面對更專業化、更針對性的攻擊，更有涉及跨國犯罪和結合實體威脅的更複雜、大規模攻擊劇本，因此企業組織在每個環節的防禦強度提升更顯重要。除了運用</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">AI</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">驅動的安全營運提升防禦優勢，我們建議跨組織、產業和公私部門之間合作並擴及整體社會，才能確保資訊安全、提升集體韌性。」</span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">《</span></strong><strong><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">2025</span></strong><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">全球資安威脅預測》六大趨勢分析：</span></strong></p>
<p style="margin: 0cm; layout-grid-mode: char;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">網路威脅者持續採用數十年來的「經典」攻擊戰術，</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">2025</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">年的威脅預測聚焦於網路犯罪者如何進一步擴大規模、更加大膽，以及提升其攻擊效率。從網路犯罪即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">CaaS</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）組織逐漸走向專業化、到採用結合虛實世界威脅的複雜劇本，網路犯罪者正在全面提升攻擊手法，執行更具針對性、危害性的攻擊行動。預計在</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">2025</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">年以後將出現六大趨勢：</span></p>
<p style="margin: 0cm; layout-grid-mode: char;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">趨勢一、攻擊鏈專業化程度日漸增強：</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">近年來，網路犯罪者逐漸將更多精力投注於攻擊前（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Left of boom</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）的偵察與武器化階段，使其威脅行動更精準高效。過去，許多網路犯罪即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">CaaS</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）組織提供全方位攻擊工具包，如網路釣魚套件與惡意軟體。然而，</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">預測這些組織將更專注於攻擊鏈中的某一環節，提供更專業化的服務。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">趨勢二、雲端環境成攻擊新焦點：</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">雖然邊緣設備仍是威脅者的主要目標，但雲端環境是另一個值得組織未來幾年內密切關注的攻擊面。雲端環境雖然並非新技術，但越來越多的網路犯罪者對其表現出濃厚興趣。由於大多數組織依賴多家雲端服務供應商，</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">觀察到攻擊者利用更多與雲端相關的漏洞，並預期這一趨勢在未來將持續增長。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">趨勢三、自動化駭客工具進軍暗網市場：</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">在當今網路犯罪即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">CaaS</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）市場中，似乎有無窮的攻擊媒介、及相關程式碼可供選擇，例如網路釣魚工具包、勒索軟體即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Ransomware-as-a-Service</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）、分散式阻斷服務攻擊即服務（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">DDoS-as-a-Service</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）等。</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">已經看到一些網路犯罪組織以人工智慧（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">AI</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）來支持其服務，預期這一趨勢將更加蓬勃。攻擊者將利用大型語言模型（</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">LLM</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">）生成的自動化內容來強化其服務、擴大市場規模，例如將社群媒體偵查結果自動化，形成整合完善的網路釣魚工具包。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">趨勢四、攻擊劇本「實境化」：</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">網路犯罪者的攻擊劇本正持續改寫優化，使攻擊變得更具侵略性和破壞性。</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">預測他們將擴大行動範圍，將網路攻擊與現實生活中的威脅結合。目前我們已觀察到一些網路犯罪組織，在某些情況下對企業的高層和員工，進行涉及實體人身安全的威脅，並預估此種做法將成許多攻擊手法中的常見一環。此外，我們也預測，毒品走私、人口或貨物的非法運輸等跨國犯罪將成為更常見的複雜攻擊手法之一，網路犯罪組織與跨國犯罪集團之間的合作將越來越頻繁。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">趨勢五、拓展反制對手框架：</span></strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">面對不斷演變的威脅策略，網路安全社群也需同步進化，以應對威脅。推動全球合作、建立公私部門合作夥伴關係，以及開發應對威脅的框架，對於增強集體韌性至關重要。目前已有許多相關行動正在推進，例如由</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">Fortinet</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">作為創始成員之一所參與的「</span><span lang="EN-US"><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;">世界經濟論壇網路犯罪地圖（</span><span style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體;">Cybercrime Atlas</span><span lang="EN-US" style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;">）</span></span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">」計畫。預計未來將有更多此類協作或倡議出現，以有效打擊網路犯罪。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char;"><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">趨勢六、防禦方能</span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">贏得平均回應</span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">時間</span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">（</span></strong><strong><span lang="EN-US" style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">Mean-Time-to-Respond, MTTR</span></strong><strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">）賽局：</span></strong><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">隨著機器學習（</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">ML</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">）與人工智慧（</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">AI</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">）技術的普及</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">，</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">防禦方戰術也正迅速提升，更有機會在與攻擊者的軍備競賽中勝出。根據我們最新發現，漏洞被利用的平均時間僅有</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">4.76</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">天，這比之前觀察到的加快了</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">43%</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">，因此，防禦者必須比以前反應得更快。得益於</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">AI</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">技術，安全團隊正加強其即時偵測、分析和回應的能力與速度。我們預測將有更多組織整合</span><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">AI</span><span style="font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1; mso-fareast-language: ZH-TW;">技術至其網路安全平台，以處理大量資料、快速識別模式與異常行為，並自動化日常任務。</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char;"><strong><span lang="EN-US" style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">&nbsp;</span></strong><span style="font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1; mso-no-proof: yes;"><!--[endif]--></span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><strong><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">組織需提升集體韌性，迎接不斷演變的威脅形勢</span></strong></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">網路犯罪者總會找到新方法來滲透組織。但透過網路安全社群之間的合作，可以更精準預測威脅者的下一步行動，並有效地中斷其行動。整個產業的共同努力、與公私部門合作的重要性不容忽視，我們預期未來將有越來越多組織參與這些協作。</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">&nbsp;</span></p>
<p style="margin: 0cm; layout-grid-mode: char; mso-layout-grid-align: none;"><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">此外，組織也需謹記資安是每個人的責任，而不僅僅是安全和</span><span lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-fareast-font-family: 微軟正黑體; color: black; mso-themecolor: text1;">IT</span><span style="font-size: 11.0pt; font-family: '微軟正黑體',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-themecolor: text1;">團隊的工作。例如，推動整個企業組織內的安全意識與訓練，也是風險管理的重要一環。最後，其他相關單位，包括從政府、到我們所仰賴的安全產品製造商，也有責任推廣、並堅實遵守資安實踐。沒有任何單一組織或安全團隊，能獨自打擊網路犯罪。透過合作與跨產業情資分享，整個生態系可以更有效地共同應對威脅者的挑戰，並全面性地保護整個社會。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">28FD6864-D962-495F-9A66-EAE6A0E18E6B</guid>
      <title>CyberArk收購機器身分管理領導者Venafi</title>
      <link>https://news.taiwannet.com.tw/news/130518/CyberArk%E6%94%B6%E8%B3%BC%E6%A9%9F%E5%99%A8%E8%BA%AB%E5%88%86%E7%AE%A1%E7%90%86%E9%A0%98%E5%B0%8E%E8%80%85Venafi.html</link>
      <pubDate>Thu, 23 May 2024 00:00:00 +0800</pubDate>
      <dc:creator>APR</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/130518_86428d8806d941fdb9bb6330253d9776.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="line-height: normal;"><span lang="EN"><span lang="EN-US" style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;"><span lang="EN-US">身分安全</span></span></span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的全球領導者</span><span lang="EN"><a href="https://www.cyberark.com/"><span style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span></a></span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">（納斯達克代碼：</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CYBR</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）今日宣布已簽署最終協議，將從</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Thoma Bravo</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">收購機器身分管理領導者</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">。此項收購將結合</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">頂尖的機器身分管理能力與</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">領先的身分安全能力，建立企業級端對端機器身分安全的統一平台。</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">數位轉型和持續的雲端遷移導致機器身分數量呈指數級增長，例如工作負載、程式碼、應用程式、物聯網設備和容器。機器數量的增長速度正在迅速超過人數的增長速度，每個人類身分對應超過</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">40</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">個機器身分，如果不加以保護，它們就會成為網路犯罪者利潤豐厚的獵場。這些機器身分必須被發現、管理、保護和自動化，以確保它們的連接和通訊安全。如果將憑證生命週期縮短（從</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">398</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">天到</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">90</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">天），並且還需為量子計算作好準備，這將使得情況變得更加複雜。</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">根據</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Forrester</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的報告</span><sup><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">1</span></sup><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">，「相較於人類身分，企業向來對於管理機器身分的興趣較低，部分原因是機器身分具有不同的需求和更複雜的生命周期挑戰。然而，包括設備和雲端工作負載等機器身分的指數級增長，已經引起了人們對改進機器身分管理的關注和急迫感，以減少因威脅面擴大所帶來的風險。機器身分的增長將超過人類身分，因此需要先進且自動化的方法來有效管理機器身分及相關風險。」</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的憑證生命週期管理、</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">公開</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">金鑰基礎建設（</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">PKI</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）、物聯網身分管理和程式碼加密簽章，結合</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的秘密資訊管理功能，將使企業能夠防止機器身分的濫用和洩露，大幅提升安全性並避免代價高昂的停機事件。將機器身分安全的各種選項整合在一個解決方案中，無論部署為</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">SaaS</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">或混合模式，將能協助各種規模企業更快速地降低雲端環境的風險。</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">作為</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">公開</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">金鑰基礎建設（</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">PKI</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）和憑證管理方面的創新領導者，並在現代雲端環境中擁有強大影響力的</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">，提供了擴展</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">整體潛在市場（</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">TAM</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）的互補解決方案，將市場規模擴大近</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">100</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元，達到約</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">600</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元。</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk </span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">執行長</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;"> Matt Cohen </span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">表示：「這次收購對</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">來說是個重要的里程碑，使我們能夠進一步實現我們的願景，也就是透過適當的權限控制來保護每個人和機器身分的安全。透過與</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">聯手，我們得以擴展我們在雲端優先、生成式</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">AI</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">、後量子世界中保護機器身分的能力。我們的技術整合、能力和專業知識將滿足全球企業的需求，並賦予資安長足夠的能力，來防禦那些利用人類和機器身分作為攻擊鏈一部分的複雜攻擊。</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">擁有世界一流的人才，未來將共同實踐</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">以客戶為中心、以人為本的文化和安全第一的理念。我們非常高興能與</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">團隊合作，抓住身分安全市場中巨大的成長機會。」</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Thoma Bravo</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">合夥人</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Chip Virnig</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">表示：「我們很高興能與</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">團隊合作，並運用我們的營運專業進一步鞏固了</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">作為機器身分管理領導者的地位。在我們的投資期間，</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">在</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">SaaS</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">服務有大幅度的成長，利潤</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">增加</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">，並成功創造了一流的</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">SaaS</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">服務，為持續創新奠定了基礎。我們相信</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">是</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的絕佳合作夥伴，這次策略性結合所創建的規模化端對端機器身分安全平台將為股東創造巨大價值。」</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><strong><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></strong></p>
<p class="MsoNormal" style="line-height: normal;"><strong><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">有關擬議收購的詳細訊息</span></strong></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">計劃以約</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">15.4</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元的企業價值收購</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">，這筆交易將以現金和</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">股票組成（約</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">10</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元現金和約</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">5.4</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元股票）。</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">CyberArk</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">和</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的董事會均已批准該交易。</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal;"><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">該交易預計將在</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">2024</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">年下半年完成，具體取決於必要的監管批准、許可和其他慣例成交條件。其他細節包括：</span></p>
<p class="MsoNormal" style="line-height: normal;"><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">&nbsp;</span></p>
<p class="MsoListParagraphCxSpFirst" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: normal; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span lang="EN" style="font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">預計將</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW;">注入</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">約</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">1.5</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元的年度經常性收入（</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">ARR</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）。</span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: normal; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span lang="EN" style="font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">帶來了一個強大的商業模式，</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">95%</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">的收入為經常性收入，包括</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">SaaS</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">和定期的授權收入。</span></p>
<p class="MsoListParagraphCxSpMiddle" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: normal; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span lang="EN" style="font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">此交易預計將立即增加利潤率</span><sup><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">2</span></sup><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">，並透過交叉銷售、追加銷售和銷售區域擴展產生顯著的收入綜效。</span></p>
<p class="MsoListParagraphCxSpLast" style="margin-left: 24.0pt; mso-add-space: auto; text-indent: -24.0pt; line-height: normal; mso-list: l0 level1 lfo1;"><!-- [if !supportLists]--><span lang="EN" style="font-family: Wingdings; mso-fareast-font-family: Wingdings; mso-bidi-font-family: Wingdings; mso-fareast-language: ZH-TW;"><span style="mso-list: Ignore;">l<span style="font: 7.0pt 'Times New Roman';">&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">Venafi</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">帶來了保護機器身分的互補功能，並將總潛在市場（</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">TAM</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">）從</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">500</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元擴展到</span><span lang="EN" style="font-family: Roboto; mso-fareast-font-family: 'Noto Sans CJK TC Light'; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">600</span><span style="font-family: 'Noto Sans CJK TC Light',sans-serif; mso-ascii-font-family: Roboto; mso-hansi-font-family: Roboto; mso-bidi-font-family: 'Noto Sans'; mso-fareast-language: ZH-TW;">億美元。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">DD8D8882-241F-4BDB-96DE-3012116D89E7</guid>
      <title>Hillstone Networks 被 Gartner® 《網絡偵測與回應市場指南》評為代表性供應商</title>
      <link>https://news.taiwannet.com.tw/news/126400/Hillstone-Networks-%E8%A2%AB-Gartner%C2%AE-%E3%80%8A%E7%B6%B2%E7%B5%A1%E5%81%B5%E6%B8%AC%E8%88%87%E5%9B%9E%E6%87%89%E5%B8%82%E5%A0%B4%E6%8C%87%E5%8D%97%E3%80%8B%E8%A9%95%E7%82%BA%E4%BB%A3%E8%A1%A8%E6%80%A7%E4%BE%9B%E6%87%89%E5%95%86.html</link>
      <pubDate>Fri, 12 Apr 2024 08:00:00 +0800</pubDate>
      <dc:creator>PR Newswire 美通社</dc:creator>
      <category>大陸港澳</category>
      <description><![CDATA[<table name="logo_release" border="0" cellspacing="10" cellpadding="5" align="right">   <tbody>    <tr>     <td><img src="https://mma.prnasia.com/media2/765968/4639401/Hillstone_Logo.jpg?p=medium600" border="0" alt="" title="logo" hspace="0" vspace="0" width="118" /></td>    </tr>   </tbody>  </table>  <p><span class="legendSpanClass">加州聖克拉拉</span><span class="legendSpanClass">2024年4月12日</span> /美通社/ -- 網絡安全解決方案的領先供應商 <a href="https://c212.net/c/link/?t=0&amp;l=zh-hant&amp;o=4136951-1&amp;h=3468866852&amp;u=https%3A%2F%2Fc212.net%2Fc%2Flink%2F%3Ft%3D0%26l%3Den%26o%3D4136951-1%26h%3D410300660%26u%3Dhttps%253A%252F%252Fwww.hillstonenet.com%252F%26a%3DHillstone%2BNetworks&amp;a=Hillstone+Networks" target="_blank" rel="nofollow">Hillstone Networks</a> 在 Gartner《網絡偵測與回應 (NDR) 市場指南》中再次被評為代表性供應商。網絡偵測與回應 (NDR) 作為安全營運中心 (SOC) 工具的常見補充，在偵測和遏制勒索軟件和內部威脅等後期入侵活動方面發揮著至關重要的作用，是依賴規則和簽名的技術的有力補充。</p>  <p>Gartner 針對特定技術細分市場的《市場指南》提供了網絡偵測與回應的市場定義，並解釋了客戶對現有解決方案的短期成效可以有什麼預期。根據 Gartner 的說法，「網絡偵測與回應必須透過實體或虛擬感測器提供與內部和雲端網絡相容的形式因素，以分析原始網絡資料包流量或流量流……為正常網絡流量建模，並突出顯示超出正常範圍的異常流量活動……將單一警報彙總為結構化事件，以推進威脅調查，並提供自動或手動回應功能，以便對惡意網絡流量的偵測做出反應。」</p>  <p>「CISO 及其安全團隊面臨著日益複雜的針對性攻擊、難以追蹤和修補已知漏洞、無法檢測龐大網絡中的橫向移動等問題，」Hillstone Networks 技術總監兼聯合創辦人Tim Liu 表示，「我們相信，我們之所以被列入 Gartner《市場指南》，是因為我們的解決方案將網絡漏洞偵測系統與一流的智能安全操作平台有力地結合在一起，能夠滿足客戶不斷變化的網絡安全需求。」</p>  <p>我們根據 Gartner 的《市場指南》總結了網絡偵測與回應領域的一些重要發現：</p>  <ul type="disc">   <li>網絡偵測與回應通常與其他安全營運中心工具一起部署，而不是單獨部署。</li>   <li>「AI 增強分析疊加」可提供來源資料的彙總視圖，為安全營運中心管理員提供有用的見解。</li>   <li>根據使用案例，客戶通常會在部署大型供應商解決方案的同時，與「新興本地參與者」合作，以獲得更強大的解決方案。</li>  </ul>  <p>從偵測、可見性、取證到緩解，Hillstone 的網絡偵測與回應解決方案套件整合了廣泛的安全功能，可提供最強大的保護：</p>  <ul type="disc">   <li>全面的流量可見性，涵蓋整個企業範圍。</li>   <li>豐富的威脅和異常偵測功能，以及複雜的視覺化功能，可提高安全營運團隊的態勢感知能力。</li>   <li>與 SOAR、SIEM 和第三方系統整合，同時提供最低組態，方便部署。</li>  </ul>  <p>Hillstone 的網絡偵測與回應解決方案包括 Hillstone 漏洞偵測系統保護解決方案，可對資料中心或園區網絡的南北向和東西向流量進行可見性偵測，並與其 XDR 解決方案 iSource（一個用於安全操作、威脅偵測和回應的大數據分析平台）結合。兩者的結合實現了高效能的網絡偵測與回應解決方案，其高階 AI/ML&nbsp;可以映射網絡攻擊鏈和 MITRE ATT&amp;CK 框架中不同要素的攻擊，從而提供對已知威脅和新威脅的可見性。</p>  <p>按<a href="https://c212.net/c/link/?t=0&amp;l=zh-hant&amp;o=4136951-1&amp;h=906911627&amp;u=https%3A%2F%2Fc212.net%2Fc%2Flink%2F%3Ft%3D0%26l%3Den%26o%3D4136951-1%26h%3D891675772%26u%3Dhttps%253A%252F%252Fwww.hillstonenet.com%252Fproducts%252Fbreach-prevention%252F%26a%3Dhere&amp;a=%E6%AD%A4" target="_blank" rel="nofollow"><b>此</b></a>了解更多有關 Hillstone 網絡偵測與回應的資訊。</p>  <p>Gartner，《網路偵測與回應市場指南》，2024 年 3 月 29 日</p>  <p>Gartner 並不認可其研究出版物中敘述的任何供應商、產品或服務，亦不建議技術使用者僅選擇評分最高或有其他稱號的供應商。Gartner 研究出版物包含 Gartner&nbsp;研究組織的觀點，不應解讀為事實陳述。Gartner 對本研究並不提供任何明示或暗示的擔保，包括對適銷性或針對特定用途適用性的任何擔保。<br />GARTNER 是 Gartner, Inc. 和/或其關聯公司在美國和國際上的註冊商標和服務標誌，經許可在此處使用。保留一切權利。</p>  <p><b>關於 Hillstone Networks </b></p>  <p>Hillstone Networks 的整合式網絡安全方法基於有遠見的、AI 驅動的和可存取的平台，為全球 28,000 多家企業提供全面、可控和整合的安全保護。Hillstone 是值得信賴的網絡安全領導者，保護從邊緣到雲端的關鍵資產和基礎設施，不論工作負載位於何處。如欲進一步了解，請瀏覽 <a href="https://c212.net/c/link/?t=0&amp;l=zh-hant&amp;o=4136951-1&amp;h=3524948798&amp;u=https%3A%2F%2Fc212.net%2Fc%2Flink%2F%3Ft%3D0%26l%3Den%26o%3D4136951-1%26h%3D2987503619%26u%3Dhttp%253A%252F%252Fwww.hillstonenet.com%252F%26a%3Dwww.hillstonenet.com&amp;a=www.hillstonenet.com" target="_blank" rel="nofollow">www.hillstonenet.com</a>。</p>  <p><b>媒體聯絡<br /></b><span class="xn-person">Valeria Duran</span><br />+1 4085086750<br /><a href="mailto:inquiry@hillstonenet.com" target="_blank" rel="nofollow">inquiry@hillstonenet.com</a></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">AD95DAA0-3763-4C5E-B40F-840B8E9A9415</guid>
      <title>Sophos 發現許多勒索軟體集團蓄意發動遠端加密攻擊</title>
      <link>https://news.taiwannet.com.tw/news/116844/Sophos-%E7%99%BC%E7%8F%BE%E8%A8%B1%E5%A4%9A%E5%8B%92%E7%B4%A2%E8%BB%9F%E9%AB%94%E9%9B%86%E5%9C%98%E8%93%84%E6%84%8F%E7%99%BC%E5%8B%95%E9%81%A0%E7%AB%AF%E5%8A%A0%E5%AF%86%E6%94%BB%E6%93%8A.html</link>
      <pubDate>Wed, 27 Dec 2023 00:00:00 +0800</pubDate>
      <dc:creator>Wordtech Ltd.</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/116844_8a8ff08e3bf54db196d4092cd6c3ba9e.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US"><a href="https://www.sophos.com/en-us"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">是創新和提供新一代網路安全即服務的全球領導者，今天發布一份《</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><a href="https://news.sophos.com/en-us/2023/12/20/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle"><span style="mso-fareast-language: ZH-TW;">CryptoGuard</span><span lang="EN-US" style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"><span lang="EN-US">：一種非對稱的勒索軟體防禦方式</span></span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">》報告。報告指出，一些最活躍且影響幅度大的勒索軟體集團，包括</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Akira</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">、</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><a href="https://news.sophos.com/en-us/2022/07/14/blackcat-ransomware-attacks-not-merely-a-byproduct-of-bad-luck/"><span style="mso-fareast-language: ZH-TW;">ALPHV/BlackCat</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">、</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><a href="https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack/"><span style="mso-fareast-language: ZH-TW;">LockBit</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">、</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><a href="https://news.sophos.com/en-us/2023/08/08/a-series-of-ransomware-attacks-made-by-different-groups-share-curiously-similar-characteristics/"><span style="mso-fareast-language: ZH-TW;">Royal</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">和</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Black Basta </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">等，均會蓄意在攻擊時進行遠端加密。在遠端加密攻擊</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">也稱為遠端勒索軟體</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">中，攻擊者會利用已經遭入侵且通常保護不足的端點，對連線到同一網路的其他裝置進行資料加密。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/12/07/sophos-endpoint-industry-leading-protection-against-remote-ransomware-attacks/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoGuard</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">是</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">在</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2015 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年收購的反勒索軟體技術，已整合到所有</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://www.sophos.com/en-us/products/endpoint-antivirus/xdr"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">端點</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">授權中。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoGuard </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">會監控惡意加密檔案的行為，提供即時保護和回復原功能，即使勒索軟體本身未出現在受保護的主機上也能加以防禦。這種獨特的反勒索軟體技術是</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">多層式端點保護的「最後一道」防線，只會在攻擊者在攻擊鏈中觸發時才會啟用。自</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2022 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年以來，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoGuard </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">偵測到的蓄意遠端加密攻擊年增率達</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 62%</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">威脅研究副總裁兼</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> CryptoGuard </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">共同開發者</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Mark Loman </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">表示：「企業可能有成千上萬台連線到公司網路的電腦，而在遠端勒索軟體中，只要一台設備保護不足，就足以危及整個網路。攻擊者知道這一點，所以他們會尋找『弱點』下手，而大多數公司中都至少有一個。遠端加密將是防禦人員必須持續面對的問題，而且根據我們所看到的警示，這種攻擊方法正在穩定增加。」</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">這類攻擊涉及遠端檔案加密，傳統部署在遠端裝置上的反勒索軟體保護無法「看到」惡意檔案或其活動，因此無法阻止未經授權的加密和潛在的資料外洩。不過，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos CryptoGuard </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">技術採取創新的方式來阻止遠端勒索軟體，正如</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/12/20/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos X-Ops </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">文章</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">所解釋的：分析檔案內容，檢查是否有任何資料被加密，以便在網路的任何裝置上偵測出勒索軟體活動，即使該裝置上沒有惡意軟體。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">在</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2013 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoLocker </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">是第一個大量使用遠端加密和非對稱加密</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">也被稱為公開金鑰加密</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的勒索軟體。從那時起，由於全球組織普遍存在安全漏洞以及加密貨幣出現，攻擊者更頻繁地使用勒索軟體了。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Loman </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">表示：「</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">10</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年前，當我們首次注意到</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7104887098519781377/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoLocker</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">利用遠端加密時，我們就預見到這種手法將成為防禦人員的一大挑戰，而其他解決方案都只專注於偵測惡意二進位檔案或執行的動作。在從遠端加密的情況下，惡意軟體是存在於一台未受保護的電腦，而非檔案被加密的電腦。唯一阻止它的方式是監視並保護這些檔案。這就是為什麼我們研發了</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> CryptoGuard</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">CryptoGuard </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">並不會尋找勒索軟體；相反地，它把重心放在主要目標，也就是檔案。它會對文件進行數學運算，偵測其是否被竄改和加密。值得注意的是，這種獨立作業的策略刻意不依賴入侵指標、威脅特徵、人工智慧、雲端查找結果或先前的情報，以達到預期效果。透過專心監控檔案，我們可以改變攻擊者和防禦者之間的平衡。我們讓攻擊者成功加密資料的成本和複雜性增加，讓他們放棄原本的目標。這是我們非對稱防禦策略的一部分。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「遠端勒索軟體對組織來說是一個重要的問題，也是勒索軟體長期存在的原因之一。由於透過連線讀取資料要比從本機磁碟讀取慢，我們看到像</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2022/11/30/lockbit-3-0-black-attacks-and-leaks-reveal-wormable-capabilities-and-tooling/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">LockBit</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">和</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Akira</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">等攻擊者會策略性地僅加密每個檔案的一小部份。這種方法的目的是在最短時間內造成最大的破壞，進一步縮小防禦人員察覺攻擊並做出反應的空窗期。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的反勒索軟體技術可以阻止遠端攻擊，以及這類僅加密檔案的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 3% </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的攻擊。我們希望提醒防禦人員注意這種持續的攻擊方法，讓他們能夠適當地保護裝置。」</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">如需了解更多資訊，請到</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos.com </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">閱讀《</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"><a href="https://news.sophos.com/en-us/2023/12/20/cryptoguard-an-asymmetric-approach-to-the-ransomware-battle"><span style="mso-fareast-language: ZH-TW;">CryptoGuard</span><span lang="EN-US" style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"><span lang="EN-US">：一種非對稱的勒索軟體防禦方式</span></span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">》。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">4915C3B6-CB76-41F3-B7CC-A877C168E7E0</guid>
      <title>人工智慧資安助理上工！Fortinet Advisor 加速資安威脅調查和回應緩解措施</title>
      <link>https://news.taiwannet.com.tw/news/116082/%E4%BA%BA%E5%B7%A5%E6%99%BA%E6%85%A7%E8%B3%87%E5%AE%89%E5%8A%A9%E7%90%86%E4%B8%8A%E5%B7%A5%EF%BC%81Fortinet-Advisor-%E5%8A%A0%E9%80%9F%E8%B3%87%E5%AE%89%E5%A8%81%E8%84%85%E8%AA%BF%E6%9F%A5%E5%92%8C%E5%9B%9E%E6%87%89%E7%B7%A9%E8%A7%A3%E6%8E%AA%E6%96%BD.html</link>
      <pubDate>Wed, 13 Dec 2023 00:00:00 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>產經商業</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/116082_e178754da78a4221aff1fc5abbdab3aa.png" border="0" style="max-width: 100%;"><p class="ql-align-justify">全方位整合與自動化網路資安領導廠商&nbsp;<a class="my-link" href="https://www.fortinet.com/tw">Fortinet</a>&reg;（NASDAQ：FTNT）今（12）日宣布推出生成式人工智慧助理<a class="my-link" href="https://www.fortinet.com/tw/products/fortinet-advisor?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortinet-advisor">Fortinet Advisor</a>，擴展其超過40個人工智慧驅動的產品解決方案。過去十多年來，人工智慧一直是<a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-fabric.html?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=security-fabric">Fortinet Security Fabric</a>安全織網和<a class="my-link" href="https://www.fortinet.com/tw/fortiguard/labs?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortiguard-labs-service">FortiGuard Labs威脅情資及安全服務</a>的中樞，而生成式人工智慧的應用則是Fortinet為了保護客戶和確保其營運穩定的創新解決方案。首次推出的Fortinet Advisor將有助於支持和引導安全營運（SecOps）團隊，使其能夠用前有未有的速度調查和應對威脅。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">Fortinet台灣區總經理吳章銘表示：「Fortinet持續在網路安全領域深耕，並透過人工智慧提供創新解決方案，我們期待透過Fortinet Advisor將領先業界的人工智慧資安技術帶給台灣客戶。這個人工智慧助理將有助於轉化企業資安態勢為主動、快速偵測威脅、並提升資安團隊生產力和進一步提供威脅應對策略。對於台灣許多中小企業來說，將是不可多得的資安策略規劃工具。」</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>Fortinet Advisor人工智慧資安助理，從解析到策略規劃提供全方位資安協助</strong></p>
<p class="ql-align-justify">Fortinet Advisor現在已於<a class="my-link" href="https://www.fortinet.com/tw/products/siem/fortisiem?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortisiem">FortiSIEM</a>，Fortinet的安全資訊和事件管理解決方案、以及<a class="my-link" href="https://www.fortinet.com/tw/products/fortisoar?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortisoar">FortiSOAR</a>，Fortinet的安全協作、自動化和回應解決方案中開放客戶使用。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-operations?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=security-operations">Fortinet安全營運解決方案</a>已成功協助客戶將辨識和控制威脅所需的時間，從超過20天大幅縮短至不到1小時，更能將資安威脅調查和回應緩解措施所需的時間，從超過18小時縮短至15分鐘或甚至更短<a class="my-link" href="file:///C:/Users/JasmineHsieh/AppData/Local/Microsoft/Windows/INetCache/Content.Outlook/MYODDXU5/%E3%80%90Fortinet%20%E6%96%B0%E8%81%9E%E5%BF%AB%E8%A8%8A%E3%80%91%E4%BA%BA%E5%B7%A5%E6%99%BA%E6%85%A7%E8%B3%87%E5%AE%89%E5%8A%A9%E7%90%86%E4%B8%8A%E5%B7%A5%EF%BC%81Fortinet%20Advisor%20%E5%8A%A0%E9%80%9F%E8%B3%87%E5%AE%89%E5%A8%81%E8%84%85%E8%AA%BF%E6%9F%A5%E5%92%8C%E5%9B%9E%E6%87%89%E7%B7%A9%E8%A7%A3%E6%8E%AA%E6%96%BD.docx#_ftn1">[1]</a>。藉由提供具備情境感知的事件分析、緩解措施指南和回應劇本的範本，Fortinet Advisor能在短短幾秒之間就用自然語言提供關鍵資訊，使安全營運團隊可以進一步縮短威脅偵測和即時反應的平均時間，並提高企業組織的整體資安態勢，來應對潛在資安風險。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">Fortinet Advisor人工智慧資安助理四大顧問級服務，助企業組織迅速擬定資安計畫：</p>
<ul>
<li class="ql-align-justify"><strong>解析資安威脅告警事件：</strong>Fortinet Advisor能快速分析資安告警，在短短幾秒內就能用自然語言提供容易理解的事件分析摘要，包括情境說明和潛在影響的解釋。</li>
<li class="ql-align-justify"><strong>建構有效分析調查查詢：</strong>Fortinet Advisor能幫助資安分析人員設計出有助於資安事件調查的高效率查詢。分析人員只需使用自然語言輸入提問，就能向Fortinet Advisor諮詢資安建議，它將以精確的句法來建構回覆，用具有建設性的回應提供建議。</li>
<li class="ql-align-justify"><strong>制定回應緩解調控措施：</strong>透過提供應對資安威脅的回應緩解調控措施建議，Fortinet Advisor能協助企業組織迅速應對資安威脅。此外，它也可以根據分析人員的即時回饋，來最佳化調整建議的回應緩解調控措施。</li>
<li class="ql-align-justify"><strong>建立強化資安回應劇本：</strong>安全架構師可以透過諮詢Fortinet Advisor來獲得資安威脅回應劇本的範本，並迅速將範本流程轉化為可執行的計劃。</li>
</ul>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">Fortinet Advisor將持續由Fortinet的人工智慧和產品專家持續更新和最佳化。Fortinet專家會定期更新人工智慧助理的知識庫，提供最新的威脅情資、並不斷最佳化其互動和結果。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>Fortinet擁有超過十年的人工智慧驅動威脅研究、預防、偵測和應對經驗</strong></p>
<p class="ql-align-justify">Fortinet在運用人工智慧創新方面，已走在產業浪潮最前端逾十年，有超過70萬客戶已經受益於人工智慧驅動的產品，包括FortiGuard AI 驅動的安全服務、<a class="my-link" href="https://www.fortinet.com/tw/products/fortiaiops?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortiaiops">FortiAIOps</a>、<a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/endpoint-security.html?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=endpoint">FortiEDR</a>和<a class="my-link" href="https://www.fortinet.com/tw/products/management/fortianalyzer?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortianalyzer">FortiAnalyzer</a>等。Fortinet Security Fabric安全織網橫跨了整個Fortinet網路安全平台，有助於偵測零日威脅，協助應對現今最複雜的攻擊，使IT團隊能在企業組織受到攻擊的影響之前，最佳化應對策略並解決網路和安全問題。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>Fortinet安全織網，創造領先業界的網路安全平台</strong></p>
<p class="ql-align-justify">Fortinet Security Operations安全營運解決方案，是Fortinet網路安全平台&mdash;Fortinet安全織網（Fortinet Security Fabric）的一部分。也由於兩者的緊密結合，使得企業組織可以從被動轉變為主動的資安態勢，進而迅速偵測和阻斷網路威脅。Fortinet的安全營運解決方案利用人工智慧和領先業界的分析技術，在網路攻擊鏈前期即能辨識複雜的潛在威脅，並在整個Fortinet安全織網上自動執行應對策略，加速資安威脅調查和緩解調控措施執行。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">Enterprise Strategy Group特聘分析師暨研究員Jon Oltsik表示：「生成式人工智慧能協助資安團隊變得更聰明、更有效率和生產力。Fortinet Advisor以Fortinet長期耕耘的人工智慧創新和進階威脅的專業知識為後盾，可以幫助組織改善營運並強化自身資安體質來對抗攻擊，特別是對於一些在網路安全技術落差方面苦苦掙扎的組織。」</p>
<p class="ql-align-justify">&nbsp;</p>
<p><strong>參考資訊</strong></p>
<ul>
<li class="ql-align-justify">了解更多<a class="my-link" href="https://www.fortinet.com/tw/products/fortinet-advisor?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortinet-advisor">Fortinet Advisor</a>和<a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-operations?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=security-operations">Fortinet的安全營運產品解決方案</a></li>
<li class="ql-align-justify">完整閱讀Enterprise Strategy Group對Fortinet SecOps平台效能的<a class="my-link" href="https://www.fortinet.com/tw/demand/gated/esg-economic-validation-fortinet-security-operations">研究結果</a></li>
<li class="ql-align-justify">深入了解<a class="my-link" href="https://www.fortinet.com/tw/fortiguard/labs?utm_source=website&amp;utm_medium=pr&amp;utm_campaign=fglabs">FortiGuard Labs</a>的威脅情報和研究，以及<a class="my-link" href="https://www.fortinet.com/tw/fortiguard/outbreak-alert?utm_source=website&amp;utm_medium=pr&amp;utm_campaign=outbreak">資安警報</a>，為您提供能即時應對網路攻擊的安全措施</li>
<li class="ql-align-justify">深入了解Fortinet的<a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-as-a-service/fortiguard-subscriptions?utm_source=pr&amp;utm_medium=pr&amp;utm_campaign=fortiguard-security-services">FortiGuard 安全服務解決方案</a></li>
<li class="ql-align-justify">在&nbsp;<a class="my-link" href="https://liff.line.me/1645278921-kWRPP32q/?accountId=fortinet">Line</a>、<a class="my-link" href="https://www.linkedin.com/company/fortinet">LinkedIn</a><strong>、</strong><a class="my-link" href="https://www.facebook.com/FortinetTaiwan">Facebook</a>、<a class="my-link" href="https://www.instagram.com/behindthefirewall/">Instagram</a>、<a class="my-link" href="https://www.fortinet.com/blog?utm_source=website&amp;utm_medium=pr&amp;utm_campaign=blog">官方網站部落格</a>和<a class="my-link" href="https://www.youtube.com/channel/UCm0oqRiOhTtbrddV9wH2uLg/featured">YouTube</a>上訂閱和追蹤Fortinet。</li>
</ul>
<p class="ql-align-justify"><strong>&nbsp;</strong></p>
<p class="ql-align-justify"><strong>關於Fortinet</strong></p>
<p class="ql-align-justify"><a class="my-link" href="https://www.fortinet.com/tw">Fortinet</a>（NASDAQ：FTNT）引領資安防護全面升級，推動網路與安全無縫整合。Fortinet 的任務是確保全球使用者、設備、資料的安全性，並透過業界最完整的資安產品組合，以涵蓋逾 50 種企業級解決方案，隨時隨地保障客戶的網路安全。作為企業部署最廣泛、獲得專利與權威機構認證最多的全方位資安領導品牌，Fortinet 解決方案深受全球超過 50 萬家客戶信賴。<a class="my-link" href="https://www.fortinet.com/tw/nse-training">Fortinet 培訓學院</a>是業界規模最大、企業最廣泛採用的資安培訓計畫之一，致力於提供全球民眾參與資安培訓課程及開啟全新職涯的機會。<a class="my-link" href="https://fortiguard.com/">FortiGuard 實驗室</a>為 Fortinet 旗下威脅情資中心與專業研究機構，開發並運用頂尖的人工智慧和機器學習技術，提供客戶即時且業界領先的安全防護及威脅情資。如欲瞭解更多詳細資訊，請至&nbsp;<a class="my-link" href="https://www.fortinet.com/tw/training/cybersecurity-professionals">Fortinet 台灣官網</a>、<a class="my-link" href="https://www.youtube.com/channel/UCm0oqRiOhTtbrddV9wH2uLg">YouTube</a>、<a class="my-link" href="https://www.facebook.com/FortinetTaiwan/?locale=zh_TW">Facebook</a>、<a class="my-link" href="https://www.fortinet.com/content/dam/fortinet/images/footer/tw-line-qr-code.png">LINE@</a>、<a class="my-link" href="https://blog.fortinet.com/">Fortinet 部落格</a>與&nbsp;<a class="my-link" href="https://fortiguard.com/">FortiGuard 實驗室</a>。</p>
<p class="ql-align-justify"><em>&nbsp;</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">096B093F-91DC-4711-B150-F5D817FF57CE</guid>
      <title>2023 Fortinet 資安嘉年華：人工智慧協作守護未來資安創造堅實防線</title>
      <link>https://news.taiwannet.com.tw/news/114398/2023-Fortinet-%E8%B3%87%E5%AE%89%E5%98%89%E5%B9%B4%E8%8F%AF%EF%BC%9A%E4%BA%BA%E5%B7%A5%E6%99%BA%E6%85%A7%E5%8D%94%E4%BD%9C%E5%AE%88%E8%AD%B7%E6%9C%AA%E4%BE%86%E8%B3%87%E5%AE%89%E5%89%B5%E9%80%A0%E5%A0%85%E5%AF%A6%E9%98%B2%E7%B7%9A.html</link>
      <pubDate>Mon, 27 Nov 2023 00:00:00 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/114398_1621909cba544db3a84af0ffa74fd6f4.jpg" border="0" style="max-width: 100%;"><p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="color: rgb(33, 31, 34);">全方位整合與自動化網路資安領導廠商</span><span lang="EN-US" style="color: rgb(33, 31, 34);"> Fortinet&reg;</span><span style="color: rgb(33, 31, 34);">（</span><span lang="EN-US" style="color: rgb(33, 31, 34);">NASDAQ</span><span style="color: rgb(33, 31, 34);">：</span><span lang="EN-US" style="color: rgb(33, 31, 34);">FTNT</span><span style="color: rgb(33, 31, 34);">）</span><span lang="EN-US" style="color: rgb(33, 31, 34);">23</span><span style="color: rgb(33, 31, 34);">日舉辦資安界年度交流盛會「</span><span lang="EN-US"><a href="https://event.fortinet.com.tw/security-carnival-2023/">Fortinet<span lang="EN-US">資安嘉年華</span></a></span><span style="color: rgb(33, 31, 34);">」，吸引超過</span><span lang="EN-US" style="color: rgb(33, 31, 34);">400</span><span style="color: rgb(33, 31, 34);">人次共襄盛舉。本次活動特別邀請</span><span lang="EN-US" style="color: rgb(33, 31, 34);">KPMG</span><span style="color: rgb(33, 31, 34);">安侯建業、中華資安國際、調查局資安工作站、加雲聯網、彰化基督教醫院、</span><span lang="EN-US" style="color: rgb(33, 31, 34);">Google Cloud</span><span style="color: rgb(33, 31, 34);">等產官學夥伴攜手</span><span lang="EN-US" style="color: rgb(33, 31, 34);">Fortinet</span><span style="color: rgb(33, 31, 34);">資安專家，針對人工智慧浪潮下的資安應用與防護、新型網路威脅趨勢、資安與永續未來、數位轉型與</span><span lang="EN-US" style="color: rgb(33, 31, 34);">OT</span><span style="color: rgb(33, 31, 34);">資安，以及公私部門資安應用等五大面向來解讀未來資安趨勢，分享各產業如何透過人類洞察和人工智慧協作，創造無與倫比的資安防護。</span></span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: normal;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><strong><span style="color: rgb(53, 53, 53);">人工智慧與數位轉型利弊並存，專家剖析新時代企業組織資安趨勢共創無與倫比資安防護</span></strong></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="color: rgb(53, 53, 53);">新興人工智慧發展和關鍵產業基礎設施的數位轉型，為企業和組織帶來優勢的同時也伴隨新型資安風險。</span><span lang="EN-US" style="color: black;">Fortinet</span><span style="color: black;">台灣區總經理吳章銘表示：「經典網路威脅策略透過人工智慧一再進化，攻擊目標與戰術也更多元化，並將注意力轉向越來越多聯網的關鍵產業基礎設施，一旦發動攻擊將造成重大影響，攻擊者也比以往更容易行動，企業組織在防禦部署上需要向左思考</span><span lang="EN-US" style="color: black;"> (Shift to Left) </span><span style="color: black;">，在攻擊鏈的各層面都要更敏捷、主動。今年</span><span lang="EN-US" style="color: black;">Fortinet</span><span style="color: black;">資安嘉年華，我們與台灣各產業資安專業人員一起全面探討與人工智慧共存的資安未來，並以多元視角剖析資安趨勢，共創面對新世代威脅型態的堅實資安防線。」</span></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;">&nbsp;</p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 微軟正黑體; font-size: 12pt; color: rgb(0, 0, 0);">新興資安風險隨企業組織聯網性不斷提升，量身打造的資安防禦和驗證流程將有助企業組織強化防護並維持競爭力。而跨越公私領域偵蒐與共享威脅情資，將有助應對新時代各企業組織聯網設施的資安需求。<span lang="EN-US">KPMG </span>安侯建業執行副總經理林大馗分享，應以「相信」人工智慧會做出正確決策為前提發展人工智慧解決方案。中華資安國際副總經理王信富則說明，企業應建立自動化通報系統、導入零信任架構並進一步驗證資安防禦有效性。彰化基督教醫院資安中心主任粘良祁，則分享了從攻防演練驗證其資安部署的成果，表示網頁攻擊的初步攔截和封鎖都是資安流程中重要環節。此外，調查局資安工作站主任鄭健行和加雲聯網智慧電力事業部專案經理林千博分別以公部門和關鍵產業視角，分享自訂資安管理規則以及自動化通報的重要性。</span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: normal;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><strong><span lang="EN-US" style="color: rgb(53, 53, 53);">FortiSASE</span></strong><strong><span style="color: rgb(53, 53, 53);">實現地端雲端協同合作零死角防護，</span></strong><strong><span lang="EN-US" style="color: rgb(53, 53, 53);">Fortinet</span></strong><strong><span style="color: rgb(53, 53, 53);">雙軸轉型助企業組織掌握資安永續未來</span></strong><strong><span style="color: rgb(53, 53, 53);"> </span></strong></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span lang="EN-US" style="color: black;">Fortinet </span><span style="color: black;">首席工程師林裕祥亦於本次大會分享，升級的</span><span lang="EN-US" style="color: black;">FortiSASE</span><span style="color: black;">如何確保未來雲端安全、優化用戶上網體驗、更彈性連接</span><span lang="EN-US" style="color: black;"> SASE </span><span style="color: black;">雲服務。解析</span><span lang="EN-US" style="color: black;">FortiSASE</span><span style="color: black;">升級關鍵三大面向，包含擴展企業資安防護至微型分支機構與</span><span lang="EN-US" style="color: black;">IoT/OT </span><span style="color: black;">設備、多層次資料外洩防護服務再升級、無縫融合端到端數位體驗監控平台。在持續投入基礎設施及不斷強化、創新技術後，</span><span lang="EN-US" style="color: black;">Fortinet </span><span style="color: black;">榮膺</span><span lang="EN-US" style="color: black;"> Gartner </span><span style="color: black;">魔力象限</span><span lang="EN-US" style="color: black;"> SASE </span><span style="color: black;">單一供應商。針對雲端安全，</span><span lang="EN-US" style="color: black;">Fortinet </span><span style="color: black;">技術顧問王仁德亦分享，</span><span lang="EN-US" style="color: black;">Fortinet </span><span style="color: black;">動態雲解決方案可以透過單一</span><span lang="EN-US" style="color: black;">FortiGate</span><span style="color: black;">、建構全面整合安全織網以及統一的資安政策助力企業化繁為簡輕鬆管理雲。</span></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span lang="EN-US" style="font-size: 12pt; font-family: 微軟正黑體; color: black;">&nbsp;</span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="color: black;">資安管理已成企業落實</span><span lang="EN-US" style="color: black;">ESG</span><span style="color: black;">關鍵要素，雙軸轉型更是企業營運重要趨勢。</span><span lang="EN-US" style="color: black;">Fortinet </span><span style="color: black;">全球產品與永續發展部資深經理</span><span lang="EN-US" style="color: black;">Carrie Chen</span><span style="color: black;">於會中說明了</span><span lang="EN-US" style="color: black;">Fortinet</span><span style="color: black;">如何持續以「提昇效能</span><span lang="EN-US" style="color: black;"> + </span><span style="color: black;">降低耗能」的方向實現產品創新，助力企業組織實踐數位和永續雙軸轉型。</span><span lang="EN-US" style="color: black;">Fortinet</span><span style="color: black;">為許多不同產業的組織提供完整資安防護軟硬體解決方案，也推出獨家碳足跡資安解決方案，確保客戶鞏固資安的同時也在永續轉型軌道上穩定前行。</span></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph;"><span lang="EN-US" style="font-size: 12pt; font-family: 微軟正黑體; color: black;">&nbsp;</span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; background: #FDFDFD;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="color: black;">面對新時代人工智慧帶來的企業組織發展優勢和資安風險，</span><span lang="EN-US" style="color: black;">Fortinet</span><span style="color: black;">將持續致力攜手產官學界專家共同強化台灣資安韌性、迎戰新型網路攻擊。透過推出更多完善且專業的全方位資安解決方案、持續倡議落實針對整個企業組織的網路安全教育訓練，及持續推動資安人才培育。與台灣和全球夥伴共同守護未來資安。</span></span></p>
<p style="margin: 0cm; text-align: justify; text-justify: inter-ideograph; background: #FDFDFD;"><span lang="EN-US" style="font-size: 12pt; font-family: 微軟正黑體; background: lightgrey;">&nbsp;</span></p>
<p style="margin: 0cm;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><strong style="mso-bidi-font-weight: normal;"><span style="color: black;">參考資訊</span></strong></span></p>
<ul>
<li class="MsoNormal" style="text-align: justify; text-indent: -18pt; line-height: normal; background: white;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;"><span style="mso-bookmark: _Hlk119340473;"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span>有關更多</span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;">2023 Fortinet </span></span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;">資安嘉年華的議程資訊與講座內容，可參閱</span></span></span><a href="https://event.fortinet.com.tw/security-carnival-2023/"><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;">活動網站</span></span></a></span></li>
<li class="MsoNormal" style="text-align: justify; text-indent: -18pt; line-height: normal; background: white;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><!-- [if !supportLists]--><span style="color: black;"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span style="color: black;">有關更多</span></span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;">2024</span></span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;">全球資安威脅預測的詳細資訊，可參閱</span></span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;"><span style="color: black;"> </span></span></span><a href="https://www.fortinet.com/blog/threat-research/2024-threat-predictions-chained-ai-and-caas-operations"><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;">Fortinet </span></span><span style="mso-bookmark: _Hlk119340473;"><span style="mso-bookmark: _Hlk119340503;">部落格文章</span></span></a></span></li>
<li class="MsoNormal" style="text-align: justify; text-indent: -18pt; line-height: normal; background: white;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><!-- [if !supportLists]--><span style="color: black;"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="ZH-CN" style="color: black;">深入了解</span><span lang="ZH-CN" style="color: black;"> </span><span style="color: black; mso-color-alt: windowtext;"><a href="https://www.fortinet.com/tw/fortiguard/labs">FortiGuard Labs</a></span><span style="color: black;"> </span><span lang="ZH-CN" style="color: black;">的威脅研究和情報組織與</span><span style="color: black;"> FortiGuard </span><span lang="ZH-CN" style="color: black;">安全訂閱服務</span><span style="color: black; mso-color-alt: windowtext;"><a href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-as-a-service/fortiguard-subscriptions"><span lang="ZH-CN">產品組合</span></a></span></span></li>
<li class="MsoNormal" style="text-align: justify; text-indent: -18pt; line-height: normal; background: white;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><!-- [if !supportLists]--><span class="MsoHyperlink"><span style="color: black; text-decoration: none;"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span></span><!--[endif]--><span style="color: black;">訂閱</span><span style="color: black; mso-color-alt: windowtext;"><a href="https://www.fortinet.com/fortiguard/labs?utm_source=website&amp;utm_medium=fortiguardlabssp&amp;utm_campaign=oa-fortiguard-labs&amp;utm_content=outbreak-alerts-subscribe#subscribe-outbreak">FortiGuard資安警報</a></span><span style="color: black;">，隨時掌握並了解最新威脅情報</span></span></li>
<li class="MsoListParagraphCxSpFirst" style="text-align: justify; text-indent: -18pt; line-height: normal;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><!-- [if !supportLists]--><span class="MsoHyperlink"><span lang="EN-US" style="text-decoration: none;"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span></span><!--[endif]-->深入了解 Fortinet <a href="https://www.fortinet.com/tw/nse-training">網路資安培訓學院</a>，包含<a href="https://www.fortinet.com/blog/business-and-technology/why-cybersecurity-training-is-more-important-than-ever.html">免費網路資安培訓</a>、<a href="https://www.fortinet.com/tw/training-certification">網路資安學院計畫</a>、<a href="https://www.uuu.com.tw/Course/Partner/Fortinet/%E7%B3%BB%E5%88%97%E8%AA%B2%E7%A8%8BCourses">合作夥伴認證課程</a>、<a href="https://www.fortinet.com/tw/training/academic-partner-program">學術合作夥伴計劃</a>與<a href="https://www.fortinet.com/tw/training/education-outreach-program">教育推廣計劃</a></span></li>
<li class="MsoListParagraphCxSpLast" style="text-align: justify; text-indent: -18pt; line-height: normal;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><!-- [if !supportLists]--><span lang="EN-US"><span style="mso-list: Ignore;">●<span style="font-style: normal; font-variant: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-weight: normal; font-stretch: normal; line-height: normal;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><!--[endif]--><span lang="ZH-CN">在</span> <a href="https://www.facebook.com/FortinetTaiwan">Facebook</a><span lang="ZH-CN">、</span><a href="https://www.youtube.com/channel/UCm0oqRiOhTtbrddV9wH2uLg/featured">YouTube</a><span lang="ZH-CN">、</span><a href="https://liff.line.me/1645278921-kWRPP32q/?accountId=fortinet">LINE</a> <span lang="ZH-CN">與</span> <a href="https://www.linkedin.com/company/fortinet">LinkedIn</a> <span lang="ZH-CN">上追蹤</span> Fortinet</span></li>
</ul>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: normal; background: white;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><strong style="mso-bidi-font-weight: normal;"><span style="color: black;">關於</span></strong><strong style="mso-bidi-font-weight: normal;"><span style="color: black;">Fortinet</span></strong></span></p>
<p class="MsoNormal" style="text-align: justify; text-justify: inter-ideograph; line-height: normal;"><span style="font-family: 微軟正黑體; font-size: 12pt;"><a href="https://www.fortinet.com/tw"><span lang="EN-US">Fortinet</span></a>（<span lang="EN-US">NASDAQ</span>：<span lang="EN-US">FTNT</span>）引領資安防護全面升級，推動網路與安全無縫整合。<span lang="EN-US">Fortinet </span>的任務是確保全球使用者、設備、資料的安全性，並透過業界最完整的資安產品組合，以涵蓋逾<span lang="EN-US"> 50 </span>種企業級解決方案，隨時隨地保障客戶的網路安全。作為企業部署最廣泛、獲得專利與權威機構認證最多的全方位資安領導品牌，<span lang="EN-US">Fortinet </span>解決方案深受全球超過<span lang="EN-US"> 50 </span>萬家客戶信賴。<a href="https://www.fortinet.com/tw/nse-training"><span lang="EN-US" style="color: rgb(5, 99, 193);">Fortinet </span><span style="color: rgb(5, 99, 193);">培訓學院</span></a>是業界規模最大、企業最廣泛採用的資安培訓計畫之一，致力於提供全球民眾參與資安培訓課程及開啟全新職涯的機會。<a href="https://fortiguard.com/"><span lang="EN-US" style="color: rgb(5, 99, 193);">FortiGuard </span><span style="color: rgb(5, 99, 193);">實驗室</span></a>為<span lang="EN-US"> Fortinet </span>旗下威脅情資中心與專業研究機構，開發並運用頂尖的人工智慧和機器學習技術，提供客戶即時且業界領先的安全防護及威脅情資。如欲瞭解更多詳細資訊，請至 <a href="https://www.fortinet.com/tw/training/cybersecurity-professionals"><span lang="EN-US" style="color: rgb(5, 99, 193);">Fortinet </span><span style="color: rgb(5, 99, 193);">台灣官網</span></a>、<a href="https://www.youtube.com/channel/UCm0oqRiOhTtbrddV9wH2uLg"><span lang="EN-US" style="color: rgb(5, 99, 193);">YouTube</span></a>、<a href="https://www.facebook.com/FortinetTaiwan/?locale=zh_TW"><span lang="EN-US" style="color: rgb(5, 99, 193);">Facebook</span></a>、<a href="https://www.fortinet.com/content/dam/fortinet/images/footer/tw-line-qr-code.png"><span lang="EN-US" style="color: rgb(5, 99, 193);">LINE@</span></a>、<a href="https://blog.fortinet.com/"><span lang="EN-US" style="color: rgb(5, 99, 193);">Fortinet </span><span style="color: rgb(5, 99, 193);">部落格</span></a>與 <a href="https://fortiguard.com/"><span lang="EN-US" style="color: rgb(5, 99, 193);">FortiGuard </span><span style="color: rgb(5, 99, 193);">實驗室</span></a>。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">9688975F-CA5B-4249-8301-3112E252DBD8</guid>
      <title>Fortinet 公布《2024全球資安威脅預測》： 經典攻擊靠AI進化、漏洞掮客現身、從內部滲透，攻擊者將更輕鬆扣下板機</title>
      <link>https://news.taiwannet.com.tw/news/113198/Fortinet-%E5%85%AC%E5%B8%83%E3%80%8A2024%E5%85%A8%E7%90%83%E8%B3%87%E5%AE%89%E5%A8%81%E8%84%85%E9%A0%90%E6%B8%AC%E3%80%8B%EF%BC%9A-%E7%B6%93%E5%85%B8%E6%94%BB%E6%93%8A%E9%9D%A0AI%E9%80%B2%E5%8C%96-%E6%BC%8F%E6%B4%9E%E6%8E%AE%E5%AE%A2%E7%8F%BE%E8%BA%AB-%E5%BE%9E%E5%85%A7%E9%83%A8%E6%BB%B2%E9%80%8F-%E6%94%BB%E6%93%8A%E8%80%85%E5%B0%87%E6%9B%B4%E8%BC%95%E9%AC%86%E6%89%A3%E4%B8%8B%E6%9D%BF%E6%A9%9F.html</link>
      <pubDate>Wed, 15 Nov 2023 00:00:00 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>產經商業</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/113198_16165442115a46a9a0ee27a43289353d.jpg" border="0" style="max-width: 100%;"><p class="ql-align-justify">全方位整合與自動化網路資安領導廠商&nbsp;<a class="my-link" href="https://www.fortinet.com/tw">Fortinet</a>&reg;（NASDAQ：FTNT）旗下FortiGuard Labs威脅情資中心今（14）日公布 《<a class="my-link" href="https://www.fortinet.com/content/dam/maindam/PUBLIC/02_MARKETING/08_Report/report_cyberthreat-predictions-2024.pdf?utm_source=blog&amp;utm_medium=blog&amp;utm_campaign=cyberthreat-predictions-2024">2024 全球資安威脅預測</a>》報告顯示，透過「網路犯罪即服務（Cybercrime-as-a-Service，CaaS）」的攻擊案例增加，加上生成式人工智慧的出現，威脅者比過往任何時候都更容易發動攻擊。同時，攻擊者各自仰賴的工具不斷演進，更一再提升攻擊行動的複雜性，目前已經可以發動更具針對性且更隱匿的攻擊，並且有能力規避一些強大的安全防護，其攻擊週期中每個戰術循環也變得更加靈活。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">Fortinet 台灣區總經理吳章銘表示：「人工智慧、5G基礎設施等新興科技的演進，使得威脅型態不斷演變，網路攻擊行動日益規模化和多元化，不僅複雜度提升、破壞力道也更強，為各行各業帶來前所未有的挑戰。我們看到網路攻擊者正利用新的技術進化成新的攻擊型態，瞄準地緣政治動盪之時發動攻擊，充分利用越來越多相互連結的基礎設施，並將目標轉向一些關鍵產業，企圖對社會造成重大的影響。同時，攻擊者也運用更多的平台或軟體漏洞、甚至由企業組織內部進行滲透，對其內外夾擊試圖突破企業組織日漸升級的安全防護。因此，我們建議企業組織的防守策略不僅需持續研究攻擊者戰術、技術和程序來找到對策，還要透過公私部門共享的威脅情報，以預測攻擊者最新動向並干擾其攻擊行動，強化資安韌性。」</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>經典攻擊策略再進化，人工智慧武器化、攻擊目標與戰術更多元化</strong></p>
<p class="ql-align-justify">Fortinet多年來持續觀察並探討許多常見的攻擊策略，「經典」攻擊策略不僅不會消失，反而正隨著攻擊者獲得新的資源也不斷演進。舉例來說，除了越來越多進階持續性威脅（Advanced Persistent Threat，APT）之外，網路犯罪組織進行APT的目標對象和攻擊戰術會更多樣化，並更專注複雜性和破壞性更高的攻擊手法，且其目的將轉向阻斷服務和勒索。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">除此之外，我們也觀察到，網路犯罪的「地盤爭奪戰」仍在繼續，多個攻擊組織鎖定相同目標，並時常能在不到24小時的時間內將勒索軟體變種，FBI亦於今年稍早也向企業組織發出了<a class="my-link" href="https://www.ic3.gov/Media/News/2023/230928.pdf">相應警告</a>。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify">此外，因生成式人工智慧的演進所造成的威脅也不容忽視。AI武器化的現象正使本就猛烈的資安威脅攻勢又再更上層樓，為攻擊者提供了輕鬆增強多階段攻擊的手段。網路犯罪者越來越常運用AI以新的方式支持惡意活動，範圍涉及阻礙社交工程檢測，甚至到<a class="my-link" href="https://www.fortinet.com/resources/cyberglossary/deepfake">模仿人類行為</a>。</p>
<p class="ql-align-justify">&nbsp;</p>
<p><strong>FortiGuard Labs威脅情資中心《2024全球資安威脅預測》六大趨勢包括：</strong></p>
<p class="ql-align-justify">儘管網路犯罪者總會仰賴經過實際操作可行的手法和技術，來實現短時間內快速得手獲利，然而現今攻擊者擁有越來越多的工具可用於協助攻擊執行。隨著網路犯罪的演變，我們預計2024年後將有一些新趨勢會顯現。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>趨勢一、攻擊者不攻則已、攻則勢大迅猛襲向關鍵產業</strong></p>
<p class="ql-align-justify">過去幾年全球勒索軟體攻擊急遽增加，使得每個企業組織，不論規模或產業都成為攻擊目標。然而，隨著越來越多網路犯罪者都能發動勒索軟體攻擊，以獲取可觀的報酬，較小、容易得手的攻擊目標將很快被耗盡。未來，我們預測攻擊者將採取「不攻則已、攻則勢大迅猛」的策略，將注意力轉向關鍵產業，如醫療、金融、交通運輸和公共事業，一旦攻擊得手，將對國家社會產生重大的影響，攻擊者也將得到豐厚報酬。同時，他們也將擴大攻擊策略，使其活動更加針對個人、更具侵略性和破壞性。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>趨勢二、零日漏洞新時代到來，「零日掮客」將現身</strong></p>
<p class="ql-align-justify">隨著企業組織擴大應用日常營運所需的各種平台、應用軟體或科技的種類，網路犯罪者也因此有機會去發現並進而利用這些軟體的漏洞。我們觀察到2023年零日漏洞和新的通用漏洞揭露（Common Vulnerabilities and Exposures，CVEs）數量<a class="my-link" href="https://www.cve.org/">創下歷史新高</a>，而這一數字仍在不斷上升。有鑑於零日漏洞為攻擊者帶來的價值，我們預計在網路犯罪即服務（CaaS）社群中將出現「零日掮客」，也就是網路犯罪者將在暗網上向買家仲介出售零日漏洞。而N日漏洞仍將持續使企業組織暴露於重大風險中。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>趨勢三、滲透威脅日增，著重從內部的資訊偵蒐達成初始滲透的目的</strong></p>
<p class="ql-align-justify">由於許多企業組織正在提升其安全控制，採用新技術和流程以升級其資安防禦力。這些強化的安全控制使得攻擊者更難以從外部滲透至企業組織的網路中，因此網路犯罪者必將尋找新方法來達成目的。有鑑於此，我們預測攻擊者攻擊戰術將持續「向左靠攏」，包括資安攻擊鏈中事前偵蒐和武器化階段，開始從目標對象企業組織的內部獲取有用的資訊，藉以找到初始滲透的關鍵。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>趨勢四、更加地透過地緣政治與其他重大事件來創造攻擊機會，瞄準進攻時機</strong></p>
<p class="ql-align-justify">當前全球政治局勢動盪，我們也預測攻擊者在未來將利用更多地緣政治議題和相關事件所驅動的機會，例如2024年的台灣、美國大選和巴黎奧運。儘管一直以來都瞄準重大事件，但現在網路犯罪者這擁有了新工具&mdash;特別是生成式AI，來支持他們的活動。</p>
<p class="ql-align-justify">&nbsp;</p>
<p class="ql-align-justify"><strong>趨勢五、防守方鑽研攻擊者TTPs，縮小戰場找到潛在棋局瓶頸</strong></p>
<p class="ql-align-justify">無可避免地，攻擊者將繼續擴展他們用來威脅目標對象的戰術、技術和程序（TTPs：Tactics, Techniques, and Procedures）。然而，防守方可透過尋找一些方法來干擾這些活動進而取得優勢。由網路安全防守方日常進行的工作大多與封鎖威脅指標（indicators of compromise）有關，但深入研究攻擊者經常使用的TTPs是很有價值的，有助於縮小戰場並找到潛在的「棋局瓶頸」。</p>
<p>&nbsp;</p>
<p><strong>趨勢六、關鍵產業設施聯網漸增，使更多針對5G的攻擊有機可趁</strong></p>
<p>隨著越來越多的互連技術的出現，網路犯罪者必然會發現新的威脅機會。在越來越多設備連網的趨勢下，我們預計網路犯罪者將會加倍利用這層連結進行攻擊。對5G基礎設施的一次成功攻擊，可能輕而易舉地就破壞了關鍵產業，如石油、天然氣、交通、公共安全、金融和醫療等。</p>
<p>&nbsp;</p>
<p><strong>Fortinet建議公私領域共享威脅情資，強化網路安全韌性，迎戰新時代的網路攻擊</strong></p>
<p>網路犯罪會對每個人都產生影響，一旦遭受侵害往往後果影響深遠。然而，若我們的安全社群採取更多行動，來更好地預測網路犯罪者的下一步並干擾他們的活動，威脅者將未必能佔據上風，例如跨越公私領域<a class="my-link" href="https://www.fortinet.com/blog/ciso-collective/partnerships-essential-for-cybersecurity">合作</a>、分享威脅情資、採用標準化資安事故報告評估措施等等。</p>
<p>&nbsp;</p>
<p class="ql-align-justify">企業組織在干擾網路犯罪上也將扮演更重要的角色。這始於創造具有網路安全韌性的文化，透過持續倡議實行針對整個企業組織的網路安全教育訓練，和更聚焦性的高層管理者的桌上資安演習&mdash;將網路安全視為每個人的職責。同時，也要找到能夠縮小內部資安技能落差的方法，例如運用<a class="my-link" href="https://www.fortinet.com/blog/industry-trends/thinking-outside-the-box-to-fill-the-skills-gap">新的人才</a>來填補空缺，可以幫助企業組織應對IT和資安人員過勞的情況、以及不斷擴展的威脅格局。</p>
<p class="ql-align-justify">&nbsp;</p>
<p><strong>參考資訊</strong></p>
<p class="ql-align-justify">●&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;閱讀完整的<a class="my-link" href="https://www.fortinet.com/content/dam/maindam/PUBLIC/02_MARKETING/08_Report/report_cyberthreat-predictions-2024.pdf?utm_source=blog&amp;utm_medium=blog&amp;utm_campaign=blog-report_cyberthreat-predictions-2024.pdf">《2024 全球資安威脅預測》</a></p>
<p class="ql-align-justify">●&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;深入了解&nbsp;<a class="my-link" href="https://www.fortinet.com/tw/fortiguard/labs">FortiGuard Labs</a>&nbsp;的威脅研究和情報組織與 FortiGuard 安全訂閱服務<a class="my-link" href="https://www.fortinet.com/tw/solutions/enterprise-midsize-business/security-as-a-service/fortiguard-subscriptions">產品組合</a></p>
<p class="ql-align-justify">●&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;訂閱<a class="my-link" href="https://www.fortinet.com/fortiguard/labs?utm_source=website&amp;utm_medium=fortiguardlabssp&amp;utm_campaign=oa-fortiguard-labs&amp;utm_content=outbreak-alerts-subscribe#subscribe-outbreak">FortiGuard資安警報</a>，隨時掌握並了解最新威脅情報</p>
<p class="ql-align-justify">●&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;深入了解 Fortinet&nbsp;<a class="my-link" href="https://www.fortinet.com/tw/nse-training">網路資安培訓學院</a>，包含<a class="my-link" href="https://www.fortinet.com/blog/business-and-technology/why-cybersecurity-training-is-more-important-than-ever.html">免費網路資安培訓</a>、<a class="my-link" href="https://www.fortinet.com/tw/training-certification">網路資安學院計畫</a>、<a class="my-link" href="https://www.uuu.com.tw/Course/Partner/Fortinet/%E7%B3%BB%E5%88%97%E8%AA%B2%E7%A8%8BCourses">合作夥伴認證課程</a>、<a class="my-link" href="https://www.fortinet.com/tw/training/academic-partner-program">學術合作夥伴計劃</a>與<a class="my-link" href="https://www.fortinet.com/tw/training/education-outreach-program">教育推廣計劃</a></p>
<p class="ql-align-justify">●&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;在&nbsp;<a class="my-link" href="https://www.facebook.com/FortinetTaiwan">Facebook</a>、<a class="my-link" href="https://www.youtube.com/channel/UCm0oqRiOhTtbrddV9wH2uLg/featured">YouTube</a>、<a class="my-link" href="https://liff.line.me/1645278921-kWRPP32q/?accountId=fortinet">LINE</a>&nbsp;與&nbsp;<a class="my-link" href="https://www.linkedin.com/company/fortinet">LinkedIn</a>&nbsp;上追蹤 Fortinet</p>
<p>&nbsp;</p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">0C8FCA0C-5CBA-40FC-B557-744432E03D19</guid>
      <title>在 Sophos 主動攻擊者報告分析的案例中，在 82% 的攻擊中駭客停用或清除了日誌，導致缺乏遙測數據</title>
      <link>https://news.taiwannet.com.tw/news/113191/%E5%9C%A8-Sophos-%E4%B8%BB%E5%8B%95%E6%94%BB%E6%93%8A%E8%80%85%E5%A0%B1%E5%91%8A%E5%88%86%E6%9E%90%E7%9A%84%E6%A1%88%E4%BE%8B%E4%B8%AD-%E5%9C%A8-82-%E7%9A%84%E6%94%BB%E6%93%8A%E4%B8%AD%E9%A7%AD%E5%AE%A2%E5%81%9C%E7%94%A8%E6%88%96%E6%B8%85%E9%99%A4%E4%BA%86%E6%97%A5%E8%AA%8C-%E5%B0%8E%E8%87%B4%E7%BC%BA%E4%B9%8F%E9%81%99%E6%B8%AC%E6%95%B8%E6%93%9A.html</link>
      <pubDate>Wed, 15 Nov 2023 00:00:00 +0800</pubDate>
      <dc:creator>Wordtech Ltd.</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/113191_39ebea98cdd34dbca1e4942c2dc3f0bc.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US"><a href="http://www.sophos.com/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">是創新和提供新一代網路安全即服務的全球領導者，今日發佈了《</span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/11/14/active-adversary-for-security-practitioners"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">2023 </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年給安全從業人士的主動攻擊者報告</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">》，該研究發現在近</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 42% </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的攻擊案例中缺乏遙測日誌數據。在這些案例中的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 82%</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">，駭客停用或刪除了遙測數據以隱藏其蹤跡。該報告涵蓋了</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">從</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2022 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月分析到</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年上半年的事件回應</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (IR) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">案例。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">缺乏遙測數據會影響我們迫切需要的組織網路和系統可見性，尤其是攻擊者</span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/08/23/active-adversary-for-tech-leaders/"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">停留時間</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">從初始進入到被偵測到的時間</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">繼續下降，縮短了防守方有效回應事件的時間。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">現場技術長</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> John Shier </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">表示：「在回應主動威脅時，時間非常重要；從發現初始進入事件到全面緩解威脅之間時間應該盡可能縮短。攻擊者在攻擊鏈中越深入，回應人員的困難度就越大。缺少遙測數據只會增加組織負擔不起的補救時間。這就是為什麼完整而準確的日誌記錄極其重要，但我們太常見到組織並沒有他們所需的這些資料。」</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">在報告中，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">將停留時間為</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> <span lang="EN-US">5 </span></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天或更短的勒索軟體攻擊歸類為「快速攻擊」，佔研究案例的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 38%</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">。停留時間超過</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> <span lang="EN-US">5 </span></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天的勒索軟體攻擊則被歸於「慢速攻擊」，佔研究案例的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 62%</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">仔細檢視這些「快速」和「慢速」的勒索軟體攻擊時，攻擊者使用的工具、技術和就地取材二進位檔</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (LOLBins) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">並沒有太大的變化，這表明雖然停留時間縮短，防守方無需重新制定新的防禦策略。然而，防守方需要意識到，快速攻擊和遙測數據缺乏可能妨礙快速反應，使得破壞增加。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Shier </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">補充：「駭客只有在必要時才會創新，而且僅會做到足以達到他們目標的程度。攻擊者不會改變有效的方法，即使他們在從進入到被偵測到的時間越來越快。對組織來說，這是一個好消息，因為即使攻擊者加快時間表，他們亦無需徹底改變防禦策略。適用於快速攻擊的偵測同樣適用於所有攻擊，無論速度快慢。而這包括完整的遙測、全面的保護和無所不在的監控。關鍵是在可能的情況下增加阻力</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">&mdash;&mdash;</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">如果你讓攻擊者的工作變得更難，那麼你就可以爭取回應的寶貴時間，拉長攻擊的每個階段。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「例如，在勒索軟體攻擊中，如果有更多的阻力，你就可以延遲資料外洩的時間；外洩通常發生在其被偵測出來之前，也是攻擊中代價最高的部分。我們在</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Cuba </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">勒索軟體的兩起事件中見到了這種情況。一家公司</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (A </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">公司</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">已經部署</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> MDR </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">持續監控，因此我們能夠在數小時內發現惡意活動，阻擋攻擊並防止任何資料被竊。另一家公司</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (B </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">公司</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">沒有這種防禦；他們直到初始入侵後幾週才發現攻擊，而此時</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Cuba </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">已外洩了</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 75GB </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的敏感資料。那時他們才趕快聯絡我們的事件回應團隊。一個月後，他們仍在努力恢復正常運作。」</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">《</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">給安全從業人士的主動攻擊者報告》是根據從</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2022 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">日到</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 6 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 30 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">日的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 232 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">個</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">回應</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (IR) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">案例，涵蓋</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 25 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">個不同行業。被攻擊的組織分佈在六大洲的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 34 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">個不同國家。其中</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 83% </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的案例來自擁有不到</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1,000 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">名員工的組織。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">《</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">給安全從業人士的主動攻擊者報告》提供可行的情報，指導安全從業人士如何妥善制定他們的防禦策略。</span></p>
<p><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;">若要了解更多攻擊者行為、工具和技術的資訊，請閱讀位於</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;"> Sophos.com </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA;">的《給安全從業人士的主動攻擊者》。</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">EDFB75D5-2B4C-4F56-926F-14E159BC266B</guid>
      <title>DEVCORE 實習生勇奪 Pwn2Own 全球駭客競賽第三名</title>
      <link>https://news.taiwannet.com.tw/news/113039/DEVCORE-%E5%AF%A6%E7%BF%92%E7%94%9F%E5%8B%87%E5%A5%AA-Pwn2Own-%E5%85%A8%E7%90%83%E9%A7%AD%E5%AE%A2%E7%AB%B6%E8%B3%BD%E7%AC%AC%E4%B8%89%E5%90%8D.html</link>
      <pubDate>Wed, 01 Nov 2023 00:00:00 +0800</pubDate>
      <dc:creator>香港商霍夫曼公關顧問股份有限公司</dc:creator>
      <category>展覽藝文</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/113039_77c668ed90c043359bd64fe0a139c6df.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; color: black; font-size: 12pt;">全球白帽駭客最高殿堂 Pwn2Own Toronto 2023 漏洞研究競賽甫於上週落幕，攻擊型資安公司 DEVCORE 實習生組隊參賽，兩位選手首次參與國際駭客大賽，即奪下第三名的優秀成績，向世界大展台灣新秀實力及豐厚資安能量！</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;">&nbsp;</p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-size: 12pt;"><span style="font-family: 'Microsoft JhengHei UI',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-ansi-language: EN-US;">Pwn2Own 競賽為 Zero Day Initia<span style="color: rgb(0, 0, 0);">tive（</span></span><span style="font-family: 新細明體, serif; color: rgb(0, 0, 0);"><span style="font-family: 'Microsoft JhengHei UI', sans-serif;">ZDI</span></span><span style="font-family: 'Microsoft JhengHei UI',sans-serif; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; color: black; mso-ansi-language: EN-US;"><span style="color: rgb(0, 0, 0);">）漏洞懸</span>賞計畫所舉辦的駭客挑戰賽，邀請世界各地頂尖白帽駭客從廣泛使用的軟體和行動裝置中找出 0-day 漏洞。今年 Pwn2Own Toronto 2023 於 10 月 24 日至 27 日舉辦，為期 4 天的賽程中，攻擊目標共包含手機裝置、智慧家居裝置、智慧揚聲器、印表機等 8 大類別。</span></span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; font-size: 12pt;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; color: rgb(34, 34, 34); font-size: 12pt;">本年度由 DEVCORE 研究部實習生 LJP、YingMuo 組成的隊伍，首次踏上世界舞台與各國好手較勁，運用 TP-Link Omada Gigabit Router 和 QNAP TS-464 設備上的漏洞串連成攻擊鏈，以 10 分的總積分榮登排行榜第三名，勇奪今年度 Pwn2Own Toronto 2023 的季軍，獲得高達 50,000 美元（約合新台幣 162 萬元）的高額獎金。</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; font-size: 12pt;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; color: rgb(34, 34, 34); font-size: 12pt;">延續 2022 年 DEVCORE 團隊所獲得的冠軍及破解大師的佳績，2023 年度出戰的實習生團隊同樣選擇挑戰 SOHO SMASHUP 積分類別，此類別模擬小型辦公室、家庭辦公室（SOHO）場景，要求參賽者需從外網（WAN）駭入路由器，再藉此轉移至內網（LAN）破解如智慧喇叭、NAS 設備或印表機等第二台設備。過程中，DEVCORE 參賽團隊藉由 TP-Link Omada Gigabit Router 的堆疊緩衝區溢位（Stack Buffer Overflow）和 QNAP TS-464 設備上的漏洞串連成攻擊鏈，成功斬獲 10 分總積分並奪下第三名的殊榮。</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; font-size: 12pt;">&nbsp;</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; color: black; font-size: 12pt;">參賽選手 LJP、YingMuo 得獎後表示，「這次在參賽過程中有遇到不少困難和挫折，很感謝 Orange、Angelboy 和研究部全體的指導和幫忙，我們才能有驚無險地拿下這次的好成績，希望未來持續運用這些養分，鑽研更深的資安技能、找出更多漏洞！」</span></p>
<p class="MsoNormal" style="line-height: normal; layout-grid-mode: char; background: white;"><span style="font-family: 'Microsoft JhengHei UI', sans-serif; font-size: 12pt;">&nbsp;</span></p>
<p><span style="font-size: 12pt; line-height: 115%; font-family: 'Microsoft JhengHei UI', sans-serif; color: black;">負責指導參賽成員的 DEVCORE 首席資安研究員蔡政達（Orange Tsai）則表示，「他們真的很厲害，在短短不到兩個月的實習期間，成功在 Omada Gigabit Router 和 QNAP TS-464 設備找到漏洞並且串成攻擊鏈成功拿下很棒的成績。希望這些實習生能持續享受尋找漏洞的快樂，跟我們一起讓世界變得更安全！」</span></p>]]></description>
    </item>
    <item>
      <guid isPermaLink="false">C7B0146D-A4B1-4544-B747-C0AE1C058C84</guid>
      <title>Sophos 發現 2023 年上半年攻擊者的停留時間縮短至 8 天</title>
      <link>https://news.taiwannet.com.tw/news/104604/Sophos-%E7%99%BC%E7%8F%BE-2023-%E5%B9%B4%E4%B8%8A%E5%8D%8A%E5%B9%B4%E6%94%BB%E6%93%8A%E8%80%85%E7%9A%84%E5%81%9C%E7%95%99%E6%99%82%E9%96%93%E7%B8%AE%E7%9F%AD%E8%87%B3-8-%E5%A4%A9.html</link>
      <pubDate>Thu, 24 Aug 2023 00:00:00 +0800</pubDate>
      <dc:creator>Wordtech Ltd.</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/104604_ef0319b941cd46f9a0e17db936458467.png" border="0" style="max-width: 100%;"><p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US"><a href="http://www.sophos.com/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">是一家全球領先的創新和提供安全服務的公司，今日發佈了《</span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/08/23/active-adversary-for-tech-leaders"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">2023 </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年給科技領袖的主動攻擊者報告</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">》，深入探討了在</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年上半年的攻擊者行為和工具。在分析</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月至</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 7 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">事件回應案例後，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos X-Ops </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">發現攻擊者停留時間</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">即從攻擊開始到被偵測到的時間</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的中位數有所變化。對所有攻擊而言，時間從</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 10 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天縮短至</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 8 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天，勒索軟體攻擊則是縮短至</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 5 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天。在</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/04/25/2023-active-adversary-report-for-business-leaders/"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">2022</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年，攻擊者停留時間的中位數從</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 15 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天減少至</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 10 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">此外，</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">Sophos X-Ops </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">發現攻擊者平均只需不到一天的時間</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> (</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">大約</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> 16 </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">小時</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">) </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">就能夠進入</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> Active Directory (AD)</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">，而</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> AD </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">是企業最關鍵的資產之一。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">AD </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">通常負責在組織內管理身分和資源存取，這意味著攻擊者可以利用</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> AD </span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;">輕鬆提升他們在系統上的權限，僅需登入即可進行各種惡意活動。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">現場技術長</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> John Shier </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">表示：「從攻擊的角度來看，攻擊組織的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Active Directory </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">基礎架構是有道理的。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">AD </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">通常是網路中最強大和權限最高的系統，可存取多種系統、應用程式、資源和資料，而它們正是攻擊者的目標。只要攻擊者控制了</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> AD</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">，就能夠控制整個組織。</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Active Directory </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的影響力、權限提升能力和復原成本，正是它成為攻擊目標的原因。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「在攻擊鏈中，只要能進入並控制</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Active Directory </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">伺服器，就能讓攻擊者取得幾項優勢。他們可以在不被察覺的情況下徘徊，擬定下一步行動。一旦準備就緒，便可以毫不受阻地在受害者的網路中移動。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「當一個網域受到入侵到完全復原，可能需要長時間且艱辛的努力。這種攻擊會損害組織基礎架構所依賴的安全基礎。很多情況下，只要</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> AD </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">被攻陷，安全團隊就必須從零開始。」</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">勒索軟體攻擊的停留時間也縮短了。在我們分析的事件回應案例中，勒索軟體攻擊是最常見的攻擊類型，佔所有案例的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 69%</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">，而這些攻擊的中位停留時間僅有</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 5 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">天。在</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 81% </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的勒索軟體攻擊中，最後的裝載都是上班時間外發動的，而那些在上班時間內部署的攻擊，僅有</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 5 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">起會在發生在上班時間發動。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">一週開始後，我們偵測到攻擊數量逐漸增加，尤其是勒索軟體攻擊更為明顯。將近一半</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (43%) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的勒索軟體攻擊是在週五或週六被偵測到的。</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Shier </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">補充說：「從某些方面來看，過去的成功為我們自己帶來了更多挑戰。隨著越來越多組織採用像</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> XDR (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">擴展式偵測和回應</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">和</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> MDR (</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">託管式偵測和回應</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">等技術，我們能夠更快偵測到攻擊。但偵測時間縮短導致對方反應更快，因為對攻擊者來說意味著可以操作的空窗期更短。同時，犯罪分子仍不斷精進他們的策略，特別是經驗豐富且資源充足的勒索軟體集團成員。在用戶防禦能力提升的情況下，他們還能持續加快各種會觸發警示的攻擊。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"><span style="mso-spacerun: yes;">&nbsp;</span></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">「不過，這並不意味著我們更安全了。非勒索軟體攻擊的停留時間趨於平穩證明了這一點。攻擊者仍能進入我們的網路，而且當他們沒有被發現時，往往會逗留不去。然而，即使擁有全世界的工具，如果警覺性不夠，也無法獲得保護。適當的工具和持續主動的監控，能確保您總是領先犯罪分子一步。這正是</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> MDR </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">能夠真正縮小攻擊者與防禦人員之間的差距的地方，因為即使您下班了，我們還在。」</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">針對企業領袖的《主動攻擊者報告》是一份針對全球</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 25 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">個不同行業的</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> Sophos </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">事件回應</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> (IR) </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">案件所做的調查，時間範圍從</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月至</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 7 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">月。受調查的組織分佈在六大洲、</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">33 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">個不同國家。其中</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 88% </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">的案例來自擁有</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> 1000 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">名員工以下的組織。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos</span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">《</span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/08/23/active-adversary-for-tech-leaders/" target="_blank" rel="noopener"><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">給技術領袖的主動攻擊者報告</span></a></span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">》能為安全專業人員提供具體的威脅情報和深入資訊，可幫助組織更有效地實施他們的安全策略。</span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt;"><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">若要深入瞭解攻擊者行為、工具和技巧，請閱讀</span><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span lang="EN-US"><a href="https://news.sophos.com/en-us/2023/08/23/active-adversary-for-tech-leaders/" target="_blank" rel="noopener"><span style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">Sophos.com</span></a></span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;"> </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">上的《時光飛逝：</span><span lang="EN-US" style="font-size: 12.0pt; line-height: 107%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">2023 </span><span style="font-size: 12.0pt; line-height: 107%; font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW;">年給科技領袖的主動攻擊者報告》。</span></p>]]></description>
    </item>
  </channel>
</rss>