网络安全日报 2022年07月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国悬赏 1000 万美元以获取有关朝鲜黑客的信息 https://www.securityweek.com/us-offers-10-million-information-north-korean-hackers 2、Nuki 智能锁被发现11个漏洞,包括可能允许攻击者开门 https://www.securityweek.com/nuki-smart-lock-vulnerabilities-allow-hackers-open-doors 3、IBM Security 研究表明数据泄露平均成本超400万美元,创历史新高 https://www.securityweek.com/ibm-security-cost-data-breach-hitting-all-time-highs 4、Google Play 中发现30个应用包含恶意软件,累计下载量超1000 万次 https://thehackernews.com/2022/07/these-28-android-apps-with-10-million.html 5、钓鱼网站假冒DHL追踪页面窃取用户的个人信息 https://blog.sucuri.net/2022/07/dhl-phishing-page-uses-telegram-bot-for-exfiltration.html 6、美国乔治敦大学发布重磅报告,揭露政府持续监视民众的阴谋 https://www.freebuf.com/news/340270.html 7、 美国政府修订发布运输管道网络安全指令文件 https://www.secrss.com/articles/45064 8、报告显示漏洞披露后 15 分钟内,黑客就开始寻找受害者 https://www.zdnet.com/article/race-against-time-hackers-start-hunting-for-victims-just-15-minutes-after-a-bug-is-disclosed/ 9、攻击者越来越多的利用 IIS 扩展来建立隐蔽的后门 https://securityaffairs.co/wordpress/133727/hacking/iis-extensions-backdoors.html 10、微软披露了利用 Windows、Adobe 0day漏洞的奥地利雇佣黑客公司 https://www.securityweek.com/microsoft-catches-austrian-company-exploiting-windows-adobe-zero-days
网络安全日报 2022年07月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的钓鱼活动针对LinkedIn上的Facebook 企业帐户 https://www.securityweek.com/new-ducktail-infostealer-targets-facebook-business-accounts-linkedin 2、安全研究人员在技嘉和华硕主板中发现被植入的UEFI Rootkit https://www.securityweek.com/chinese-uefi-rootkit-found-gigabyte-and-asus-motherboards 3、Grails 中的严重安全漏洞可能导致远程代码执行 https://portswigger.net/daily-swig/critical-security-vulnerability-in-grails-could-lead-to-remote-code-execution 4、网络钓鱼攻击猛增,微软和 Facebook 成为被冒充最多的品牌 https://threatpost.com/popular-bait-in-phishing-attacks/180281/ 5、研究人员发现新 LockBit 3.0 和 BlackMatter 勒索软件非常相似 https://thehackernews.com/2022/07/experts-find-similarities-between.html 6、印度保险门户网站Policybazaar遭到入侵数据泄露 https://www.infosecurity-magazine.com/news/indian-insurance-policybazaar/ 7、Windows版Coremail邮件客户端RCE 0day漏洞已被在野利用 https://mp.weixin.qq.com/s/nq3yIInv8-79J_vTnQUzSw 8、美国与英国达成协议,将可互相访问互联网用户数据 https://www.ithome.com/0/631/220.htm 9、企业应用 Confluence 的硬编码密码泄露 https://arstechnica.com/information-technology/2022/07/atlassian-warns-hardcoded-password-flaw-is-likely-to-be-exploited-in-the-wild/ 10、Drupal 开发人员修复了 CMS 中的代码执行漏洞 https://securityaffairs.co/wordpress/133625/security/drupal-flaws-2.html
网络安全日报 2022年07月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、开源电商平台PrestaShop 确认0day漏洞会导致电商服务器被攻击 https://www.securityweek.com/prestashop-confirms-zero-day-attacks-hitting-ecommerce-servers 2、FileWave 移动设备管理 (MDM) 产品漏洞影响1000多个组织 https://www.securityweek.com/1000-organizations-exposed-remote-attacks-filewave-mdm-vulnerabilities 3、勒索软件组织 Lockbit 声称入侵了意大利税务局并窃取了78GB文件 https://securityaffairs.co/wordpress/133640/cyber-crime/lockbit-ransomware-italian-revenue-agency.html 4、T-Mobile 同意向数据泄露的客户支付 3.5 亿美元 https://www.securityweek.com/t-mobile-settles-pay-350m-customers-data-breach 5、新版本Amadey恶意软件通过SmokeLoader传播 https://asec.ahnlab.com/en/36634/ 6、QBot使用Windows 7计算器侧加载来感染设备 https://www.bleepingcomputer.com/news/security/qbot-phishing-uses-windows-calculator-sideloading-to-infect-devices/ 7、威胁行为者在黑客论坛上推广的新 Redeemer 勒索软件版本 https://www.bleepingcomputer.com/news/security/new-redeemer-ransomware-version-promoted-on-hacker-forums/ 8、Conti 勒索软件入侵并加密哥斯达黎加政府 https://www.bleepingcomputer.com/news/security/how-conti-ransomware-hacked-and-encrypted-the-costa-rican-government/ 9、加拿大圣玛丽小镇遭到LockBit勒索软件攻击数据泄露 https://www.databreaches.net/an-entire-canadian-town-is-being-extorted-by-ransomware-cyber-criminals/ 10、Magecart 活动入侵订餐平台以窃取 300 多家餐厅的付款数据 https://thehackernews.com/2022/07/magecart-hacks-online-food-ordering.html
网络安全日报 2022年07月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SonicWall 警告严重的 GMS SQL 注入漏洞 https://www.securityweek.com/sonicwall-warns-critical-gms-sql-injection-vulnerability 2、以色列间谍软件公司利用的 Chrome 漏洞也影响 Edge、Safari https://www.securityweek.com/chrome-flaw-exploited-israeli-spyware-firm-also-impacts-edge-safari 3、新版Windows 11 默认启用帐户锁定策略防止暴力攻击 https://www.securityweek.com/new-default-account-lockout-policy-windows-11-blocks-brute-force-attacks 4、Drupal 中修补的代码执行和其他漏洞 https://www.securityweek.com/code-execution-and-other-vulnerabilities-patched-drupal 5、540 万个 Twitter 帐户数据遭泄露 https://securityaffairs.co/wordpress/133593/data-breach/twitter-leaked-data.html 6、Grafana 修补可能导致管理员帐户接管的漏洞 https://portswigger.net/daily-swig/grafana-patches-vulnerability-that-could-lead-to-admin-account-takeover 7、TA4563利用EvilNum恶意软件针对欧洲金融实体 https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities 8、乌克兰广播运营商遭到黑客入侵导致播放虚假新闻 https://thehackernews.com/2022/07/ukrainian-radio-stations-hacked-to.html 9、美国数字安全巨头Entrust遭勒索软件攻击数据泄露 https://www.bleepingcomputer.com/news/security/digital-security-giant-entrust-breached-by-ransomware-gang/ 10、攻击者滥用谷歌广告将用户重定向到恶意网站 https://blog.malwarebytes.com/threat-intelligence/2022/07/google-ads-lead-to-major-malvertising-campaign/
网络安全日报 2022年07月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、QakBot新变种通过钓鱼邮件中的HTML文件传播 https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails 2、根据网络安全审查结果,国家网信办对滴滴罚款80.26亿元 https://www.freebuf.com/news/339722.html 3、Atlassian 修补影响多个产品的 Servlet 过滤器漏洞 https://www.securityweek.com/atlassian-patches-servlet-filter-vulnerabilities-impacting-multiple-products 4、思科修补了 Nexus 仪表板中的严重漏洞 https://www.securityweek.com/cisco-patches-severe-vulnerabilities-nexus-dashboard 5、2021 年上半年有600 多个ICS漏洞被披露,超60% 为严重或高危漏洞 https://www.securityweek.com/hundreds-ics-vulnerabilities-disclosed-first-half-2022 6、以往未被检测到的Lightning Framework新恶意软件针对Linux系统 https://www.intezer.com/blog/research/lightning-framework-new-linux-threat/ 7、 8220 Gang 云僵尸网络感染了全球3万多台主机 https://securityaffairs.co/wordpress/133462/cyber-crime/8220-gang-cloud-botnet-spike.html 8、苹果发布安全更新总共修复不同组件的37个漏洞 https://thehackernews.com/2022/07/apple-releases-security-patches-for-all.html 9、英国高温天气导致谷歌和甲骨文云服务中断 https://thehackernews.com/2022/07/us-ftc-vows-to-crack-down-on-illegal.html 10、前Conti 勒索软件成员仍在活跃进行活动 https://www.secrss.com/articles/44699
网络安全日报 2022年07月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google 在 Android 中引入 DNS-over-HTTP/3 https://www.securityweek.com/google-introduces-dns-over-http3-android 2、Apple 为 macOS、iOS 发布紧急安全补丁 https://www.securityweek.com/apple-ships-urgent-security-patches-macos-ios 3、Nubeva 正在开发基于密钥拦截技术的勒索加密数据恢复技术 https://www.securityweek.com/can-encryption-key-intercepts-solve-ransomware-epidemic 4、Chrome 103 更新补丁修复高危漏洞 https://www.securityweek.com/chrome-103-update-patches-high-severity-vulnerabilities 5、新的基于Rust的Luna 勒索软件针对 Windows、Linux 和 ESXi 系统 https://securityaffairs.co/wordpress/133454/cyber-crime/luna-ransomware-rust.html 6、建材巨头可耐福遭到 Black Basta 勒索软件攻击 https://www.bleepingcomputer.com/news/security/building-materials-giant-knauf-hit-by-black-basta-ransomware-gang/ 7、Linus Torvalds称 Linux 内核已经解决了"Retbleed"问题 https://www.theregister.com/2022/07/17/linux_5_19_rc7/ 8、FBI将全面升级网络基础设施,拥抱SD-WAN和SASE https://www.secrss.com/articles/44814 9、公安部网安局召开全国网安部门“百日行动”推进会 https://mp.weixin.qq.com/s/sKrHNBeLwlotHJXk-bC4YQ 10、新文件显示美国政府的手机定位数据追踪规模“巨大”,远超之前的认知 https://www.cnbeta.com/articles/tech/1293871.htm
网络安全日报 2022年07月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软解决了 Azure Storage SDK 中的 Padding Oracle 漏洞 https://www.securityweek.com/microsoft-resolves-padding-oracle-vulnerability-azure-storage-sdk 2、广泛使用的 Micodus GPS跟踪器存在严重漏洞允许黑客远程禁用汽车 https://www.securityweek.com/unpatched-micodus-gps-tracker-vulnerabilities-allow-hackers-remotely-disable-cars 3、研究人员发现隐藏多年的macOS 间谍软件-"CloudMensis" https://www.securityweek.com/new-cloudmensis-macos-spyware-used-targeted-attacks 4、APT29 利用 Google Drive、Dropbox 来逃避检测 https://securityaffairs.co/wordpress/133409/apt/apt29-google-drive-dropbox.html 5、新的气隙攻击使用 SATA 电缆作为天线传输无线电信号 https://thehackernews.com/2022/07/new-air-gap-attack-uses-sata-cable-as.html 6、FBI 警告虚假加密货币应用程序正在欺骗数百万投资者 https://threatpost.com/fbi-warns-fake-crypto-apps/180245/ 7、印度旅游预订平台 Cleartrip 确认数据泄露 https://techcrunch.com/2022/07/18/cleartrip-data-breach-dark-web/ 8、Blitz.js中的原型污染漏洞可能导致远程代码执行 https://portswigger.net/daily-swig/prototype-pollution-in-blitz-js-leads-to-remote-code-execution 9、Accusoft ImageGear 中的安全问题可能导致内存损坏、代码执行 https://blog.talosintelligence.com/2022/07/accusoft-vuln-spotlight-.html 10、UNI token空投钓鱼攻击成功窃取Uniswap 800万美元 https://www.4hou.com/posts/MB9G
网络安全日报 2022年07月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Juniper 修复了200多个第三方组件漏洞 https://www.securityweek.com/juniper-networks-patches-over-200-third-party-component-vulnerabilities 2、阿尔巴尼亚政府遭大规模网络攻击 https://securityaffairs.co/wordpress/133363/cyber-warfare-2/albania-cyber-attack.html 3、研究人员发布Windows NFS 远程代码执行漏洞分析报告 https://securityaffairs.co/wordpress/133355/security/cve-2022-30136-windows-nfs-rce.html 4、FPL 增加2FA缓解账号被黑客接管的安全风险 https://portswigger.net/daily-swig/fantasy-premier-league-football-app-introduces-2fa-to-tackle-account-takeover-hacks 5、黑客通过欺骗性提交元数据创建恶意GitHub存储库 https://www.hackread.com/hackers-spoof-commit-metadata-false-github-repositories/ 6、研究人员发现西门子解决方案中存在多个零日漏洞 https://www.fortinet.com/blog/threat-research/fortinet-researchers-discover-vulnerabilities-in-siemens-solutions 7、加拿大蒙莫伦西学院遭到网络攻击导致数据泄露 https://www.zataz.com/le-college-canadien-montmorency-sous-les-coups-dune-fuite-de-donnees/ 8、公安机关网安部门:重拳打击窃听窃照及偷拍偷窥违法犯罪 https://www.ithome.com/0/629/618.htm 9、 调查:智慧工厂未做好网络攻击应对准备 https://www.secrss.com/articles/44717 10、科技公司纷纷反对,英国网络安全法案搁置 https://www.cnbeta.com/articles/tech/1292687.htm
网络安全日报 2022年07月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、'Mantis' DDoS 僵尸网络在一个月内攻击了1000多个组织 https://www.securityweek.com/powerful-mantis-ddos-botnet-hits-1000-organizations-one-month 2、Google Play将删除"应用程序权限列表"以添加新的"数据安全"部分 https://thehackernews.com/2022/07/google-removes-app-permissions-list.html 3、流行的 NFT 平台 Premint NFT 被窃取了 314 个 NFT https://securityaffairs.co/wordpress/133339/cyber-crime/crooks-stole-375k-from-premint-nft-it-is-one-of-the-biggest-nft-hacks-ever.html 4、Netwrix Auditor 应用程序中的严重漏洞允许任意代码执行 https://securityaffairs.co/wordpress/133310/hacking/netwrix-auditor-flaw.html 5、圣灵勒索软件 (H0lyGh0st) 与朝鲜黑客有关 https://securityaffairs.co/wordpress/133255/hacking/holy-ghost-ransomware-north-korea.html 6、黑客利用 Digium 电话软件中的漏洞攻击 VoIP 服务器 https://securityaffairs.co/wordpress/133293/hacking/digium-phones-attacks.html 7、软件供应商开始修补 Retbleed CPU 漏洞 https://www.securityweek.com/software-vendors-start-patching-retbleed-cpu-vulnerabilities 8、新的缓存侧通道攻击可以对目标在线用户进行去匿名化 https://thehackernews.com/2022/07/new-cache-side-channel-attack-can-de.html 9、美国DHS 发布关于 Log4j 漏洞和响应的报告,漏洞影响可能会持续数年 https://www.infosecurity-magazine.com/news/dhs-report-log4j-vlnerabilities/ 10、密码破解工具部署Sality恶意软件感染工业系统 https://www.bleepingcomputer.com/news/security/password-recovery-tool-infects-industrial-systems-with-sality-malware/
网络安全日报 2022年07月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、日本电子游戏发行商万代南梦宫确认遭网络攻击 https://www.securityweek.com/japanese-video-game-publisher-bandai-namco-confirms-cyberattack 2、前 CIA 程序员因 2017 年将"Vault 7"泄露给维基解密被定罪 https://www.securityweek.com/cia-coder-convicted-massive-leak-us-hacking-tools 3、微软发布 macOS App 沙盒逃逸漏洞(CVE-2022-26706)的PoC https://securityaffairs.co/wordpress/133211/hacking/macos-sandbox-bypass-exploit.html 4、Cloudflare缓解的6 月最大HTTPS DDoS 攻击是由Mantis 僵尸网络发起的 https://securityaffairs.co/wordpress/133233/hacking/mantis-botnet-record-ddos-attack.html 5、SAP 修补 Business One 产品中的高危漏洞 https://www.securityweek.com/sap-patches-high-severity-vulnerabilities-business-one-product 6、研究人员开发并发布了 Hive 勒索软件解密工具 https://www.techtarget.com/searchsecurity/news/252522715/Researcher-develops-Hive-ransomware-decryption-tool 7、澳大利亚迪肯大学遭到黑客入侵导致学生信息泄露 https://blogs.deakin.edu.au/deakinlife/2022/07/12/deakin-has-been-targeted-in-a-cyber-attack-this-week-heres-what-happened-and-what-you-should-do/ 8、 QQ安全中心揭秘新的盗号手段:利用好友互助渠道与同情心 https://www.cnbeta.com/articles/tech/1291505.htm 9、Retbleed推测性执行攻击缓解代码已并入Linux内核 https://www.cnbeta.com/articles/tech/1291757.htm 10、WPS 回应删除用户本地文件事件,重申不会侵犯用户隐私 https://www.ithome.com/0/629/303.htm