网络安全日报 2022年08月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、NetModule 路由器软件 (NRSW) 中发现新的严重漏洞 https://www.securityweek.com/organizations-warned-critical-vulnerabilities-netmodule-routers 2、英特尔修补固件、管理软件中的严重漏洞 https://www.securityweek.com/intel-patches-severe-vulnerabilities-firmware-management-software 3、UnRAR 漏洞(CVE-2022-30333)被利用,可用于入侵 Zimbra 服务器 https://www.securityweek.com/unrar-vulnerability-exploited-wild-likely-against-zimbra-servers 4、思科披露5月下旬被Yanluowang勒索组织入侵并窃取了内部数据 https://securityaffairs.co/wordpress/134278/hacking/yanluowang-ransomware-hacked-cisco.html 5、Microsoft Edge 通过增强的安全模式加强对恶意网站的防御 https://portswigger.net/daily-swig/microsoft-edge-deepens-defenses-against-malicious-websites-with-enhanced-security-mode 6、研究人员发现10个恶意PyPI包窃取开发者凭据 https://www.bleepingcomputer.com/news/security/10-malicious-pypi-packages-found-stealing-developers-credentials/ 7、Reddit中的IDOR漏洞允许攻击者提权 https://portswigger.net/daily-swig/simple-idor-vulnerability-in-reddit-allowed-mischief-makers-to-perform-mod-actions 8、微软警告称配备最新 CPU 的 Windows 设备容易受到数据损坏 https://www.bleepingcomputer.com/news/microsoft/windows-devices-with-newest-cpus-are-susceptible-to-data-damage/ 9、ChekPoint报告显示全球网络攻击激增 42%,勒索软件成为头号威胁 https://www.ithome.com/0/633/868.htm 10、电子邮件营销公司Klaviyo被攻击,数据已泄露 https://www.bleepingcomputer.com/news/security/email-marketing-firm-hacked-to-steal-crypto-focused-mailing-lists/
网络安全日报 2022年08月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二修复了118个漏洞,包括一个0day漏洞(CVE-2022-34713) https://www.securityweek.com/already-exploited-zero-day-headlines-microsoft-patch-tuesday 2、VMware确定高危漏洞CVE-2022-31656利用代码已被公开 https://www.securityweek.com/exploit-code-published-critical-vmware-security-flaw 3、研究人员披露了一种新的英特尔 CPU 攻击方法- ÆPIC Leak https://www.securityweek.com/aepic-leak-architectural-bug-intel-cpus-exposes-protected-data 4、 AMD CPU 受"SQUIP"侧信道攻击的影响,可被获取敏感数据 https://www.securityweek.com/amd-processors-expose-sensitive-data-new-squip-attack 5、Adobe发布补丁修复了Acrobat、Reader 中的代码执行漏洞 https://www.securityweek.com/adobe-patch-tuesday-code-execution-flaws-acrobat-reader 6、研究人员将Maui 勒索软件与朝鲜 Andariel APT 关联 https://securityaffairs.co/wordpress/134195/malware/maui-ransomware-andariel-apt.html 7、研究人员在新加坡发现了Classiscam诈骗即服务业务 https://thehackernews.com/2022/08/researchers-uncover-classiscam-scam-as.html 8、黑客使用SHARPEXT浏览器扩展监视Gmail和Aol用户 https://www.hackread.com/nkorea-hackers-sharpext-browser-malware-gmail/ 9、我国 IPv6 网络“高速公路”全面建成:活跃用户达 6.93 亿 https://www.ithome.com/0/633/812.htm 10、以色列警方Pegasus间谍软件原型被曝光 https://www.cnbeta.com/articles/tech/1301271.htm
网络安全日报 2022年08月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国运通和 Snapchat 中的开放重定向漏洞在网络钓鱼攻击中被利用 https://www.securityweek.com/open-redirect-flaws-american-express-and-snapchat-exploited-phishing-attacks 2、员工的登录凭据被骗取后,Twilio 遭到黑客攻击 https://www.securityweek.com/twilio-hacked-after-employees-tricked-giving-login-credentials 3、360 Netlab 发现Orchard 僵尸网络利用比特币交易信息生成 DGA 域 https://securityaffairs.co/wordpress/134155/malware/orchard-botnet.html 4、英国紧急卫生服务因托管商遭受攻击而中断 https://www.bleepingcomputer.com/news/security/uk-nhs-suffers-outage-after-cyberattack-on-managed-service-provider/ 5、Zimbra企业邮件的漏洞已被黑客攻击利用 https://www.securityweek.com/zimbra-credential-theft-vulnerability-exploited-attacks 6、新的GwisinLocker勒索软件加密ESXi虚拟机 https://www.bleepingcomputer.com/news/security/new-gwisinlocker-ransomware-encrypts-windows-and-linux-esxi-servers/ 7、Lazarus组织冒充Coinbase攻击金融行业 https://www.bleepingcomputer.com/news/security/north-korean-hackers-target-crypto-experts-with-fake-coinbase-job-offers/ 8、黑客在Lucidchart上托管网络钓鱼页面 https://www.avanan.com/blog/hackers-host-phishing-pages-on-lucidchart 9、利用隐写术的恶意软件数量逐渐增多 https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors/ 10、超过60%的组织将SSH暴露在互联网上 https://www.infosecurity-magazine.com/news/over-60-organizations-expose-ssh/
网络安全日报 2022年08月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、F5 通过季度安全补丁修复了 21 个漏洞 https://www.securityweek.com/f5-fixes-21-vulnerabilities-quarterly-security-patches 2、Slack 在发现凭据泄露漏洞后强制重置了一部分用户密码 https://www.securityweek.com/slack-forces-password-resets-after-discovering-software-flaw 3、红绿灯协议 (TLP) 发布2.0版本 https://www.securityweek.com/traffic-light-protocol-20-brings-wording-improvements-label-changes 4、大规模的网络攻击袭击了德国工商会 (DIHK) 的网站 https://securityaffairs.co/wordpress/134121/hacking/dihk-cyberattack.html 5、GwisinLocker 勒索软件专门针对韩国 https://securityaffairs.co/wordpress/134105/cyber-crime/gwisinlocker-ransowmare-south-korea.html 6、Twitter 证实最近540 万个账户数据泄露是由于利用了0day漏洞造成的 https://securityaffairs.co/wordpress/134087/data-breach/twitter-zero-day-data-leak.html 7、美国 CISA 和澳大利亚 ACSC 发布 2021 年顶级恶意软件列表 https://www.cisa.gov/uscert/ncas/alerts/aa22-216a 8、研究人员发现劫持网络带宽而非算力的“挖矿”程序 https://blog.aquasec.com/cryptojacking-cloud-network-bandwidth 9、研究人员揭露“C2即服务(C2aaS)”的网络犯罪活动 https://securityaffairs.co/wordpress/134073/hacking/dark-utilities-c2-as-a-service.html 10、Mirai新变种RapperBot利用SSH暴力破解入侵Linux服务器 https://thehackernews.com/2022/08/new-iot-rapperbot-malware-targeting.html
网络安全日报 2022年08月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现影响数十万台 DrayTek Vigor 路由器的严重漏洞 https://www.securityweek.com/smbs-exposed-attacks-critical-vulnerability-draytek-vigor-routers2、思科小型企业路由器发布更新修补严重漏洞 https://www.securityweek.com/critical-vulnerabilities-allow-hacking-cisco-small-business-routers3、印度超过 2.8 亿条记录含 UAN、银行帐号、收入和 PF在网上泄露 https://ciso.economictimes.indiatimes.com/news/breaking-over-280m-records-including-uan-bank-account-info-and-pii-leaked-online/933337544、总部位于阿联酋的零售连锁 Spinneys 遭黑客攻击数据泄露 https://securereading.com/uae-spinneys-customer-data-leak/5、全新的 Woody RAT 恶意软件针对俄罗斯实体 https://securityaffairs.co/wordpress/134014/intelligence/woody-rat-targets-russia-orgs.html6、研究人员发现Go语言编写的LOLI Stealer窃密木马 https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild/7、暗网研究表明 87% 的勒索软件利用恶意宏 https://www.infosecurity-magazine.com/news/87-ransomware-brands-exploit-macros/8、微软宣布新的外部攻击面审计工具 https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-new-external-attack-surface-audit-tool/9、VMware 敦促管理员立即修补关键的身份验证绕过漏洞 https://www.bleepingcomputer.com/news/security/vmware-urges-admins-to-patch-critical-auth-bypass-bug-immediately/10、FEMA 警告紧急警报系统可能被黑客入侵以传输虚假信息 https://edition.cnn.com/2022/08/03/politics/fema-emergency-alert-software-warning/index.html
网络安全日报 2022年08月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、德国半导体制造商赛米控遭勒索软件攻击,攻击者称窃取了2TB资料 https://www.securityweek.com/power-electronics-manufacturer-semikron-targeted-ransomware-attack 2、NOMAD跨链桥遭黑客攻击损失总额接近 2 亿美元,几乎被清空 https://www.securityweek.com/nearly-200-million-stolen-cryptocurrency-bridge-nomad 3、后量子候选算法-SIKE 被轻松破解 https://thehackernews.com/2022/08/single-core-cpu-cracked-post-quantum.html 4、VirusTotal分析显示大多数恶意软件通过图标模拟合法应用诱骗受害者 https://thehackernews.com/2022/08/virustotal-reveals-most-impersonated.html 5、VMWare 敦促用户修补关键身份验证绕过漏洞 https://threatpost.com/vmware-patch-critical-bug/180346/ 6、最新的 Jenkins 插件公告中包含未修补的 XSS、CSRF 漏洞 https://portswigger.net/daily-swig/jenkins-security-unpatched-xss-csrf-bugs-included-in-latest-plugin-advisory 7、Solana钱包遭大规模盗币事件 https://techcrunch.com/2022/08/03/solana-wallet-hack/ 8、数千个GitHub存储库被Fork后其副本被更改为恶意软件 https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/ 9、研究人员警告针对企业用户的大规模AitM攻击 https://thehackernews.com/2022/08/researchers-warns-of-large-scale-aitm.html 10、应用EvolutionCMS、FUDForum和GitBucket中发现XSS漏洞 https://portswigger.net/daily-swig/trio-of-xss-bugs-in-open-source-web-apps-could-lead-to-complete-system-compromise
网络安全日报 2022年08月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware为身份验证绕过安全漏洞发布紧急补丁 https://www.securityweek.com/vmware-ships-urgent-patch-authentication-bypass-security-hole 2、谷歌修补严重的安卓漏洞,允许通过蓝牙远程执行代码 https://www.securityweek.com/google-patches-critical-android-flaw-allowing-remote-code-execution-bluetooth 3、欧洲导弹制造商 MBDA 否认被黑客入侵系统 https://www.securityweek.com/european-missile-maker-mbda-denies-hackers-breached-systems 4、Gootkit AaaS 恶意软件仍然活跃并使用更新的策略 https://securityaffairs.co/wordpress/133918/malware/gootkit-is-still-active.html 5、新的"ParseThru"参数走私漏洞影响基于 Golang 的应用程序 https://thehackernews.com/2022/08/new-parsethru-parameter-smuggling.html 6、研究人员发现利用浏览器书签同步功能作为隐蔽数据泄露通道的方法 https://www.freebuf.com/news/340801.html 7、黑客窃取了访问 140000 个Wiseasy支付终端的密码 https://techcrunch.com/2022/08/01/wiseasy-android-payment-passwords/ 8、Emotet 下载器文档使用 Regsvr32 执行 https://securityboulevard.com/2022/07/emotet-downloader-document-uses-regsvr32-for-execution/ 9、数以百万计的 Arris 路由器易受路径遍历攻击 https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks/ 10、美国众议院通过了《勒索软件法案》 https://www.secrss.com/articles/45306
网络安全日报 2022年08月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、ALPHV声称入侵了欧洲燃气管道公司Creos Luxembourg SA https://securityaffairs.co/wordpress/133899/cyber-crime/alphv-blackcat-ransomware-creos-luxembourg.html 2、研究人员发现近 3,200 个移动应用程序泄露 Twitter API 密钥 https://thehackernews.com/2022/08/researchers-discover-nearly-3200-mobile.html 3、CompleteFTP路径遍历漏洞允许攻击者删除服务器文件 https://portswigger.net/daily-swig/completeftp-path-traversal-flaw-allowed-attackers-to-delete-server-files 4、Google Cloud和Google Play漏洞可能导致账户劫持 https://portswigger.net/daily-swig/xss-vulnerabilities-in-google-cloud-google-play-could-lead-to-account-hijacks 5、Gootkit加载器以新的运营策略重新出现 https://securityaffairs.co/wordpress/133881/data-breach/mbda-alleged-data-breach.html 6、由上万个虚假投资网站瞄准欧洲用户 https://www.bleepingcomputer.com/news/security/huge-network-of-11-000-fake-investment-sites-targets-europe/ 7、Google Play商店现17款DawDropper银行恶意软件 https://www.freebuf.com/news/340693.html 8、西班牙一核安全系统遭黑客攻击,部分地区服务中断数月 https://www.secrss.com/articles/45215 9、CertiK近期发布了《Web3 安全季度报告》攻击数量创历史之最 https://www.freebuf.com/articles/340394.html 10、美国国会议员披露美国司法系统遭到网络攻击,密封文件面临风险 https://www.infosecurity-magazine.com/news/congress-us-court-records-breach/
网络安全日报 2022年08月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软发现USB蠕虫攻击"Raspberry Robin"与"EvilCorp"存在联系 https://www.securityweek.com/microsoft-connects-usb-worm-attacks-evilcorp-ransomware-gang 2、朝鲜APT组织Kimsuky利用恶意浏览器扩展从目标邮箱中窃取数据 https://www.securityweek.com/n-korean-apt-uses-browser-extension-steal-emails-foreign-policy-nuclear-targets 3、OneTouchPoint 披露了影响 30 多家医疗保健公司的数据泄露 https://www.securityweek.com/onetouchpoint-discloses-data-breach-impacting-over-30-healthcare-firms 4、绰号 Adrastea的黑客组织声称已经入侵了欧洲导弹制造商 MBDA https://securityaffairs.co/wordpress/133881/data-breach/mbda-alleged-data-breach.html 5、恶意 Npm 包针对 Discord 用户窃取令牌和银行卡信息 https://threatpost.com/malicious-npm-discord/180327/ 6、大华网络摄像头漏洞可能让攻击者完全控制设备 https://thehackernews.com/2022/07/dahua-ip-camera-vulnerability-could-let.html 7、研究人员警告黑客使用去中心化IPFS网络进行攻击 https://thehackernews.com/2022/07/researchers-warns-of-increase-in.html 8、CISA警告Confluence硬编码凭据漏洞被积极利用 https://thehackernews.com/2022/07/cisa-warns-of-atlassian-confluence-hard.html 9、LockBit勒索软件利用Windows Defender逃避检测 https://www.bleepingcomputer.com/news/security/lockbit-ransomware-abuses-windows-defender-to-load-cobalt-strike/ 10、GitHub Actions工作流漏洞可能导致命令执行 https://portswigger.net/daily-swig/github-actions-workflow-flaws-provided-write-access-to-projects-including-logstash
网络安全日报 2022年07月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、最近修补的 Confluence 高危漏洞(CVE-2022-26138)已被利用 https://www.securityweek.com/exploitation-recent-confluence-vulnerability-underway 2、Moxa NPort存在严重漏洞可能导致工业关键基础设施遭破坏性攻击 https://www.securityweek.com/moxa-nport-device-flaws-can-expose-critical-infrastructure-disruptive-attacks 3、LibreOffice 修复了 3 个漏洞,包括代码执行问题 https://securityaffairs.co/wordpress/133775/security/libreoffice-flaws-2.html 4、ENISA 发布"2021年重大电信安全事件相关数据"报告 https://securityaffairs.co/wordpress/133756/reports/telecom-security-incidents-2021-enisa.html 5、在微软默认禁用宏后,攻击者使用ISO、RAR和LNK文件等新的攻击技术 https://securityaffairs.co/wordpress/133764/hacking/attacks-after-microsoft-blocked-macros.html 6、谷歌将计划在其Chrome 中阻止第三方 Cookie 的时间推迟到 2024 年 https://thehackernews.com/2022/07/google-delays-blocking-3rd-party.html 7、恶意软件Amadey Bot 的新版本利用软件破解站点进行传播 https://cyware.com/news/amadey-bots-new-version-spreads-using-software-cracks-11f2a0ac 8、恶意 NPM 包窃取 Discord 令牌和银行卡数据 https://securelist.com/lofylife-malicious-npm-packages/107014/ 9、黑客使用WebAssembly编码的挖矿程序来逃避检测 https://thehackernews.com/2022/07/hackers-increasingly-using-webassembly.html 10、托管服务提供商NetStandard遭黑客攻击网站关闭 https://www.bleepingcomputer.com/news/security/kansas-msp-shuts-down-cloud-services-to-fend-off-cyberattack/