网络安全日报 2022年08月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、流媒体平台 Plex 确认数据库泄露、数据被盗 https://www.securityweek.com/plex-confirms-database-breach-data-theft 2、加利福尼亚州北区针对甲骨文的数据收集做法提起集体诉讼 https://www.securityweek.com/class-action-lawsuit-filed-against-oracle-over-data-collection-practices 3、IBM 修补了 IBM MQ 消息中间件中的严重漏洞 https://www.securityweek.com/ibm-patches-severe-vulnerabilities-mq-messaging-middleware 4、研究人员警告针对 Google G-Suite 企业用户的 AiTM 攻击 https://thehackernews.com/2022/08/researchers-warn-of-aitm-attack.html 5、盗版 3DMark 基准测试工具传播信息窃取恶意软件 https://www.bleepingcomputer.com/news/security/pirated-3dmark-benchmark-tool-delivering-info-stealer-malware/ 6、Cyber发现针对金融的剪贴板劫持器IBAN Clipper https://blog.cyble.com/2022/08/22/dissecting-iban-clipper/ 7、近一年利用SaaS平台的网络钓鱼增加了11倍 https://www.bleepingcomputer.com/news/security/phishing-attacks-abusing-saas-platforms-see-a-massive-1-100-percent-growth/ 8、恶意 PyPI 包对 Counter Strike 服务器发起 DDoS 攻击 https://cyware.com/news/malicious-pypi-packages-launch-ddos-attacks-against-counter-strike-servers-b4d84c69 9、推特前安全主管控诉推特存在 "令人震惊"的安全漏洞 https://www.freebuf.com/news/342774.html 10、Varonis披露新出现的Solidbit勒索软件 https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
网络安全日报 2022年08月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现可以利用以太网口LED灯进行数据窃取的方法 https://www.securityweek.com/ethernet-leds-can-be-used-exfiltrate-data-air-gapped-systems 2、VMware 周二发布了补丁修复了 VMware Tools 提权漏洞 https://www.securityweek.com/privilege-escalation-flaw-haunts-vmware-tools 3、GitLab 修补了高危远程代码执行漏洞 https://www.securityweek.com/gitlab-patches-critical-remote-code-execution-vulnerability 4、希腊最大天然气供应商 Desfa遭Ragnar Locker勒索攻击和数据窃取 https://www.securityweek.com/ransomware-gang-leaks-data-allegedly-stolen-greek-gas-supplier 5、 研究人员发现超过8万台海康威视摄像头易受高危命令注入漏洞攻击 https://securityaffairs.co/wordpress/134756/security/hikvision-cameras-vulnerability.html 6、研究人员称Java 库存在许多反序列化安全漏洞 https://www.theregister.com/2022/08/22/java_library_flaws/ 7、错误的Meta Pixel配置暴露医疗公司Novant 130万用户数据 https://www.bleepingcomputer.com/news/security/misconfigured-meta-pixel-exposed-healthcare-data-of-13m-patients/ 8、研究发现 RTLS 系统容易受到中间人攻击和位置篡改 https://thehackernews.com/2022/08/rtls-systems-found-vulnerable-to-mitm.html 9、意大利纺织公司Sferra公布数据泄露事件 https://www.securityweek.com/textile-company-sferra-discloses-data-breach 10、某些廉价安卓设备中存在针对WhatsApp的系统后门 https://securityaffairs.co/wordpress/134735/malware/counterfeit-versions-mobile-devices-target-whatsapp.html
网络安全日报 2022年08月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、纺织公司 Sferra 披露数据泄露 https://www.securityweek.com/textile-company-sferra-discloses-data-breach 2、微软发布了关键 ChromeOS 漏洞的技术细节 https://www.securityweek.com/microsoft-shares-details-critical-chromeos-vulnerability 3、以色列飞马间谍软件公司NSO Group首席执行官下台 https://www.securityweek.com/ceo-israeli-pegasus-spyware-firm-step-down 4、在 Entrust 被Lockbit攻击后,Lockbit 泄漏站点遭到神秘 DDoS 攻击 https://securityaffairs.co/wordpress/134707/cyber-crime/lockbit-hacked-entrust.html 5、研究人员披露了 Linux 内核中一个存在8年之久的漏洞(DirtyCred)详情 https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169 6、Donot Team 网络间谍组织更新其 Windows 恶意软件框架 https://securityaffairs.co/wordpress/134674/apt/donot-team-improves-jaca-framework.html 7、Escanor恶意软件通过Office文档传播 https://www.helpnetsecurity.com/2022/08/22/escanor-malware-delivered-in-weaponized-microsoft-office-documents/ 8、密码长度超过64字节的加密ZIP文件可能有两个正确的密码 https://www.bleepingcomputer.com/news/security/an-encrypted-zip-file-can-have-two-correct-passwords-heres-why/ 9、研究发现使用应用内浏览器访问第三方网站时存在植入跟踪代码的情况 https://www.solidot.org/story?sid=72526 10、美军探索网络安全新范式,由合规清单转向自动化红队 https://www.secrss.com/articles/46059
网络安全日报 2022年08月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、TA558 网络犯罪集团针对酒店和旅游组织 https://securityaffairs.co/wordpress/134622/cyber-crime/ta558-targets-hospitality-travel.html 2、Cozy Bear 使用规避技术攻击北约国家 Microsoft 365 用户 https://securityaffairs.co/wordpress/134609/apt/cozy-bear-targets-microsoft-365-users.html 3、Amazon Ring 中的一个漏洞可能会暴露用户的相机记录 https://securityaffairs.co/wordpress/134588/hacking/amazon-ring-vulnerability-camera-recordings.html 4、DEF CON上白帽黑客控制了一颗退役卫星播放了会议演讲和黑客电影 https://securityaffairs.co/wordpress/134637/hacking/hackers-take-control-decommissioned-satellite.html 5、黑客入侵WordPress显示虚假DDoS防护页面分发恶意软件 https://securityaffairs.co/wordpress/134686/hacking/fake-ddos-protection-pages-wordpress.html 6、Chainalysis报告黑客在 2022 年已经窃取了价值近 20 亿美元加密货币 https://www.cnbc.com/2022/08/19/crypto-hackers-stole-billions-why-its-a-growing-problem.html 7、新的 Grandoreiro 银行恶意软件活动针对西班牙语国家工业制造商 https://thehackernews.com/2022/08/new-grandoreiro-banking-malware.html 8、微软发布Sysmon 14可监控可执行文件的创建 https://www.bleepingcomputer.com/news/microsoft/microsoft-sysmon-can-now-block-malicious-exes-from-being-created/ 9、音乐Rhythm Nation会导致某些硬盘驱动器发生故障和崩溃 https://www.bleepingcomputer.com/news/security/janet-jacksons-music-video-is-now-a-vulnerability-for-crashing-hard-disks/ 10、黑客利用零日漏洞从General Bytes 比特币ATM服务器窃取加密货币 https://www.bleepingcomputer.com/news/security/hackers-steal-crypto-from-bitcoin-atms-by-exploiting-zero-day-bug/
网络安全日报 2022年08月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Safari 15.6.1 修复了被利用的0day漏洞 https://securityaffairs.co/wordpress/134553/security/safari-15-6-1-fixes-zero-day.html 2、谷歌宣布阻止了有史以来最大(4600 万次RPS)的 HTTPS DDoS 攻击 https://securityaffairs.co/wordpress/134542/hacking/google-blocked-largest-ever-https-ddos.html 3、Realtek RCE 漏洞的 PoC 利用代码已在线发布 https://securityaffairs.co/wordpress/134515/breaking-news/realtek-rce-poc-exploit.html 4、黑客使用 Bumblebee Loader 破坏 Active Directory 服务 https://thehackernews.com/2022/08/hackers-using-bumblebee-loader-to.html 5、BlackByte 2.0勒索软件采用新的勒索策略重新归来 https://www.bleepingcomputer.com/news/security/blackbyte-ransomware-gang-is-back-with-new-extortion-tactics/ 6、Mandiant称伊朗UNC3890组织攻击以色列航运和其他关键部门 https://www.securityweek.com/iranian-group-targeting-israeli-shipping-and-other-key-sectors 7、自2020年以来,近700万人尝试下载恶意浏览器扩展 https://www.bleepingcomputer.com/news/security/malicious-browser-extensions-targeted-almost-7-million-people/ 8、微软提醒客户注意俄黑客组织SEABORGIUM的网络钓鱼攻击 https://www.cnbeta.com/articles/tech/1305201.htm 9、卡巴斯基实验室正开发防黑客自主品牌手机 https://www.ithome.com/0/635/532.htm 10、报告称大多数经期和孕期跟踪应用在保护用户隐私方面做得很差 https://www.cnbeta.com/articles/tech/1305529.htm
网络安全日报 2022年08月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple 修补新的 macOS、iOS 零日漏洞 https://www.securityweek.com/apple-patches-new-macos-ios-zero-days 2、霍尼韦尔报告称针对工业设施的恶意软件52%是通过USB设备进行传播的 https://www.securityweek.com/81-malware-seen-usb-drives-industrial-facilities-can-disrupt-ics-honeywell 3、安卓恶意软件Bugdrop dropper 包含绕过 Google 安全控制的功能 https://securityaffairs.co/wordpress/134508/malware/bugdrop-android-malware.html 4、谷歌修复了被利用的新 Chrome 零日漏洞 https://securityaffairs.co/wordpress/134501/security/google-fifth-chrome-zero-day-exploited.html 5、Electron框架漏洞影响数十个应用程序 https://www.securityweek.com/security-analysis-leads-discovery-vulnerabilities-18-electron-applications 6、英特尔CPU构架漏洞ÆPIC Leak影响大多数10至12代CPU https://securityaffairs.co/wordpress/134478/security/aepic-leak-architecturally-flaw.html 7、微软将在下个月默认禁用Edge中的TLS1.0/1.1支持 https://news.softpedia.com/news/microsoft-to-disable-tls-1-0-and-1-1-next-month-535935.shtml 8、研究人员发现多个影响UWB和RTLS通信的漏洞 https://www.bleepingcomputer.com/news/security/rtls-systems-vulnerable-to-mitm-attacks-location-manipulation/ 9、CS GO皮肤交易网站CS.MONEY约600万美元用户资产遭黑客攻击被盗 https://www.bleepingcomputer.com/news/security/cs-go-trading-site-hacked-to-steal-6-million-worth-of-skins/ 10、Lazarus Group针对使用macOS的求职者投放恶意软件 https://securityaffairs.co/wordpress/134491/malware/north-korea-mac-malware-m1.html
网络安全日报 2022年08月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Zoom MacOS版本修补了在 DEF CON 上被披露的严重漏洞 https://www.securityweek.com/zoom-patches-serious-macos-app-vulnerabilities-disclosed-def-con 2、英国饮用水公司South Staffordshire Water遭Clop 勒索软件攻击 https://securityaffairs.co/wordpress/134450/cyber-crime/south-staffordshire-water-cyberattack.html 3、受Twilio 安全漏洞影响,1900名Signal用户电话号码被泄露 https://securityaffairs.co/wordpress/134428/mobile-2/twilio-hack-signal-impacy.html 4、新的 Evil PLC 攻击利用PLC 以破坏 OT 和企业网络 https://thehackernews.com/2022/08/new-evil-plc-attack-weaponizes-plcs-to.html 5、印度金融服务公司 BharatPay 泄露了用户的 PII 和敏感财务数据 https://ciso.economictimes.indiatimes.com/news/bharatpay-finance-services-breached-personal-data-transaction-details-of-37000-users-leaked-online/93586873 6、Andariel在攻击中使用DTrack和Maui勒索软件 https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/ 7、卡巴斯基发布2022 Q2威胁演变报告 https://securelist.com/it-threat-evolution-q2-2022/107099/ 8、"五眼"联盟国家参与美国网络司令部大型年度演习 https://www.secrss.com/articles/45833 9、网信办发布国内互联网算法备案清单,含微信、淘宝、抖音等30款App http://www.cac.gov.cn/2022-08/12/c_1661927474338504.htm 10、硬件付费订阅引众怒,黑客向宝马宣战:将免费破解给车主使用 https://www.cnbeta.com/articles/tech/1304555.htm
网络安全日报 2022年08月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌提高了针对 Linux 内核漏洞的漏洞赏金奖励 https://www.securityweek.com/google-boosts-bug-bounty-rewards-linux-kernel-vulnerabilities 2、微软破坏了与俄有关的 APT组织SEABORGIUM的黑客行动 https://securityaffairs.co/wordpress/134414/apt/seaborgiums-targets-nato.html 3、CopperStealer利用Chromium恶意扩展窃取加密货币 https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html 4、以Evernote为诱饵的网络钓鱼针对医疗供应商 https://www.hipaajournal.com/healthcare-providers-targeted-in-evernote-phishing-campaign/ 5、SOVA安卓银行木马中出现新型勒索软件模块 https://www.darkreading.com/endpoint/ransomware-sova-android-banking-trojan 6、卡巴斯基报告DeathStalker使用的VileRAT程序 https://securelist.com/vilerat-deathstalkers-continuous-strike/107075/ 7、研究人员在商业安全产品中发现盗用OverSight算法 https://www.securityweek.com/researchers-find-stolen-algorithms-commercial-cybersecurity-products 8、恶意PyPI包secretslib在Linux系统执行无文件挖矿程序 https://thehackernews.com/2022/08/newly-uncovered-pypi-package-drops.html 9、 Instagram 被曝通过 App 内浏览器跟踪用户网络活动 https://www.ithome.com/0/634/976.htm 10、利用macOS端Zoom安装器漏洞,黑客可接管用户Mac https://www.cnbeta.com/articles/tech/1304009.htm
网络安全日报 2022年08月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、洛克希德·马丁公司遭Killnet攻击并被窃取数据 https://www.securityweek.com/killnet-releases-proof-its-attack-against-lockheed-martin 2、微软过去的12个月内为漏洞赏金计划支付了 1370 万美元 https://www.securityweek.com/microsoft-paid-137-million-bug-bounty-programs-over-past-year 3、美国政府分享涉嫌 Conti Ransomware 嫌疑人的照片 https://www.securityweek.com/us-government-shares-photo-alleged-conti-ransomware-associate 4、Realtek SDK 高危堆栈溢出漏洞影响20多家厂商生成的路由器 https://www.securityweek.com/realtek-sdk-vulnerability-exposes-routers-many-vendors-remote-attacks 5、使用联发科芯片的小米手机存在漏洞可能允许伪造交易 https://securityaffairs.co/wordpress/134331/hacking/xiaomi-phones-flaw.html 6、CISA、FBI 发布联合公告,警告 Zeppelin 勒索软件攻击 https://securityaffairs.co/wordpress/134350/cyber-crime/zeppelin-ransomware-joint-alert.html 7、0day漏洞被利用入侵超过 1,000 台 Zimbra 电子邮件服务器 https://securityaffairs.co/wordpress/134314/hacking/zimbra-rce-actively-exploited.html 8、研究人员发现三个漏洞允许攻击者绕过 UEFI 安全启动功能 https://securityaffairs.co/wordpress/134334/hacking/uefi-secure-boot-feature-flaw.html 9、英特尔推出针对物理故障注入攻击的保护 https://www.securityweek.com/intel-introduces-protection-against-physical-fault-injection-attacks 10、Black Hat USA 展示了新型 HTTP 请求走私攻击 https://portswigger.net/daily-swig/browser-powered-desync-new-class-of-http-request-smuggling-attacks-showcased-at-black-hat-usa
网络安全日报 2022年08月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Device42 IT资产管理平台被发现多个严重漏洞 https://www.securityweek.com/critical-vulnerabilities-found-device42-asset-management-platform 2、Palo Alto Networks PAN-OS存在漏洞被用于反射型放大DoS攻击 https://www.securityweek.com/palo-alto-networks-firewalls-targeted-reflected-amplified-ddos-attack 3、思科修补了ASA和Firepower软件中的高危RSA私钥泄露漏洞 https://www.securityweek.com/cisco-patches-high-severity-vulnerability-security-solutions 4、Cuba勒索软件的攻击者使用新的远控木马 https://thehackernews.com/2022/08/hackers-behind-cuba-ransomware-attacks.html 5、公安部:刷单类电信网络诈骗案持续高发,占全部电诈案四成 https://www.ithome.com/0/634/257.htm 6、美国对朝鲜黑客关联加密货币 Tornado Cash 实施制裁 https://www.secrss.com/articles/45636 7、Cloudflare 员工也受到 Twilio 泄露事件背后的黑客攻击 https://www.bleepingcomputer.com/news/security/cloudflare-employees-also-hit-by-hackers-behind-twilio-breach/ 8、PyPI 中发现新的窃取用户凭证的恶意 Python 库 https://www.infosecurity-magazine.com/news/malicious-python-libraries-found/ 9、因客户信息安全管理不到位,农行被罚 30 万一人被禁业 3 年 https://www.mpaypass.com.cn/news/202208/10111401.html 10、《云计算安全责任共担模型》行业标准正式发布 https://www.secrss.com/articles/45623