网络安全日报 2022年07月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、联想修补了影响700多款型号笔记本电脑的 UEFI 代码执行漏洞 https://www.securityweek.com/lenovo-patches-uefi-code-execution-vulnerability-affecting-many-laptops 2、微软发布用于生成 SBOM (软件材料清单)的开源工具包 https://www.securityweek.com/microsoft-releases-open-source-toolkit-generating-sboms 3、新的推测性执行攻击-Retbleed影响英特尔和AMD处理器 https://www.securityweek.com/retbleed-new-speculative-execution-attack-targets-intel-amd-processors 4、微软警告针对 10,000 多个组织的大规模 AiTM 网络钓鱼攻击 https://thehackernews.com/2022/07/microsoft-warns-of-large-scale-aitm.html 5、研究人员发现了 ChromeLoader 浏览器劫持恶意软件的新变种 https://thehackernews.com/2022/07/researchers-uncover-new-variants-of.html 6、研究人员发现了 Qakbot 恶意软件逃避检测的新手段 https://thehackernews.com/2022/07/researchers-uncover-new-attempts-by.html 7、立陶宛能源公司Ignitis集团遭到大规模DDOS攻击 https://www.infosecurity-magazine.com/news/lithuanian-energy-ddos-attack/ 8、迪士尼Instagram和Facebook帐户被黑,并被攻击者发布恶意内容 https://www.infosecurity-magazine.com/news/disneylands-instagram-facebook-hack/ 9、VMware修补了11月披露的vCenter Server高危提权漏洞 https://www.bleepingcomputer.com/news/security/vmware-patches-vcenter-server-flaw-disclosed-in-november/ 10、AWS 修复了其Kubernetes服务中的身份验证漏洞 https://www.theregister.com/2022/07/12/authentication_bug_aws_kubernetes
网络安全日报 2022年07月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二补丁日修复了84个漏洞,包括已被利用的0day漏洞 https://www.securityweek.com/microsoft-patch-tuesday-84-windows-vulns-including-already-exploited-zero-day 2、西门子、施耐德电气发布补丁解决了 59 个漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-address-59-vulnerabilities 3、日本娱乐公司万代南梦宫遭ALPHV/BlackCat 勒索软件攻击 https://www.cnbeta.com/articles/tech/1291321.htm 4、微软宣布全面推出 Windows Autopatch 功能 https://securityaffairs.co/wordpress/133139/security/microsoft-autopatch.html 5、基于云的挖掘攻击滥用 GitHub Actions 和 Azure VM https://securityaffairs.co/wordpress/133125/malware/cryptocurrency-mining-cloud-infrastructure.html 6、研究人员发现可以通过滥用OAuth流程来执行单击帐户劫持 https://portswigger.net/daily-swig/dirty-dancing-in-oauth-researcher-discloses-how-cyber-attacks-can-lead-to-account-hijacking 7、微软撤回默认屏蔽Office宏的计划 https://www.solidot.org/story?sid=72078 8、美国FBI用于钓鱼的加密通信平台Anom代码被公开 https://www.secrss.com/articles/44525 9、英国格洛斯特议会服务遭网络攻击居民数据泄露 https://www.gloucestershirelive.co.uk/news/gloucester-news/hackers-access-bank-details-signatures-7308173 10、印度果阿邦的洪水监测系统遭到勒索软件攻击 https://ciso.economictimes.indiatimes.com/news/hackers-target-wrds-flood-monitoring-system/92739107
网络安全日报 2022年07月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、专家警告新的 0mega 勒索软件针对全球组织 https://securityaffairs.co/wordpress/133098/malware/0mega-ransomware.html 2、黑客利用虚假工作机会从 Axie Infinity 窃取 5.4 亿美元 https://securityaffairs.co/wordpress/133113/cyber-crime/axie-infinity-hack-fake-job-offer.html 3、研究表明未来五年在线支付欺诈将高达 3430 亿美元 https://www.infosecurity-magazine.com/news/online-payment-fraud-five-years/ 4、PyPl 正在为关键项目推出 2FA https://www.zdnet.com/article/python-programming-pypl-is-rolling-out-2fa-for-critical-projects-giving-away-4000-security-keys/ 5、Anubis Network 携新的 C2 服务器回归大规模网络钓鱼活动 https://securityaffairs.co/wordpress/133115/hacking/anubis-networks-new-c2.html 6、英国金融服务公司Aon遭黑客入侵泄露客户信息 https://www.infosecurity-magazine.com/news/aon-hack-sensitive-information/ 7、欧盟网络安全组织ENISA发布新威胁态势分析法 https://securityaffairs.co/wordpress/132973/security/enis-athreat-landscape-methodology.html 8、QNAP警告说新勒索软件Checkmate正针对NAS设备 https://securityaffairs.co/wordpress/132989/malware/checkmate-ransomware-targets-qnap-nas.html 9、漏洞百出的 "用谷歌登录 "API让加密货币面临账户接管风险 https://www.darkreading.com/application-security/cryptocurrency-api-vulnerability-opens-wallets-to-account-takeovers 10、黑客公布伊朗钢铁制造企业近20G绝密文件 https://www.secrss.com/articles/44473
网络安全日报 2022年07月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的“HavanaCrypt”勒索软件以假谷歌软件更新的形式分发 https://www.securityweek.com/new-havanacrypt-ransomware-distributed-fake-google-software-update 2、Fortinet 修补了多个产品中的高危漏洞 https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities-several-products 3、研究人员演示了如何通过 Rolling-PWN 攻击解锁多款本田车型 https://securityaffairs.co/wordpress/133090/hacking/honda-rolling-pwn-attack.html 4、法国电话运营商 La Poste Mobile 遭受勒索软件攻击 https://securityaffairs.co/wordpress/133080/cyber-crime/la-poste-mobile-ransomware.html 5、Apple 计划推出锁定模式功能以保护用户免受"高度针对性的网络攻击" https://securityaffairs.co/wordpress/133065/mobile-2/apple-lockdown-mode.html 6、Emsisoft发布 AstraLocker 和 Yashma 勒索软件免费解密工具 https://securityaffairs.co/wordpress/133014/malware/emsisoft-astralocker-yashma-decryptor.html 7、Atlassian修复了Jira中的服务器端请求伪造漏洞 https://portswigger.net/daily-swig/atlassian-patches-full-read-ssrf-in-jira 8、思科发布安全更新修复了影响多个产品的漏洞 https://securityaffairs.co/wordpress/133020/security/cisco-cisco-expressway-flaw.html 9、攻击者利用Follina漏洞部署Rozena后门 https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor 10、Node.js修复多个RCE和HTTP请求走私漏洞 https://portswigger.net/daily-swig/node-js-fixes-multiple-bugs-that-could-lead-to-rce-http-request-smuggling
网络安全日报 2022年07月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国防部针对公开资产的重大漏洞推出赏金计划 https://www.securityweek.com/dod-launches-hack-us-bounties-major-flaws-publicly-exposed-assets 2、美国:朝鲜黑客利用 Maui Ransomware 攻击医疗保健行业 https://www.securityweek.com/us-north-korean-hackers-targeting-healthcare-sector-maui-ransomware 3、大规模加密货币挖矿活动针对 NPM JavaScript 包存储库 https://securityaffairs.co/wordpress/132983/cyber-crime/cuteboi-cryptomining-campaign-npm.html 4、研究人员发现一种新的 Linux 恶意软件:OrBit,但未被检测到 https://securityaffairs.co/wordpress/132966/hacking/orbit-linux-malware.html 5、IT 服务巨头 SHI International 遭受破坏性恶意软件攻击 https://www.bleepingcomputer.com/news/security/it-services-giant-shi-hit-by-professional-malware-attack/ 6、由于绑定机制漏洞,黑客可通过"ExpressLRS"协议接管无人机 https://threatpost.com/drone-hack-expresslrs-hijacked/180133/ 7、Bitter APT黑客组织以孟加拉国军事实体为目标 https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh/ 8、黑客滥用Brute Ratel红队工具进行攻击以逃避检测 https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/#Conclusion 9、QNAP 警告针对 NAS 设备的新 Checkmate 勒索软件 https://www.bleepingcomputer.com/news/security/qnap-warns-of-new-checkmate-ransomware-targeting-nas-devices/ 10、微软悄悄修复 ShadowCoerce Windows NTLM Relay 漏洞 https://www.bleepingcomputer.com/news/microsoft/microsoft-quietly-fixes-shadowcoerce-windows-ntlm-relay-bug/
网络安全日报 2022年07月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、用 Rust 编写的Hive勒索软件变种出现 https://www.securityweek.com/evasive-rust-coded-hive-ransomware-variant-emerges 2、万豪国际遭遇新的数据泄露,攻击者窃取了 20GB 数据 https://securityaffairs.co/wordpress/132943/data-breach/marriott-new-data-breach.html 3、OpenSSL 为可能导致 RCE 攻击的高危漏洞发布补丁 https://thehackernews.com/2022/07/openssl-releases-patch-for-high.html 4、NIST 宣布前四种抗量子攻击的密码算法 https://thehackernews.com/2022/07/nist-announces-first-four-quantum.html 5、新的 RedAlert 勒索软件针对 Windows、Linux VMware ESXi 服务器 https://www.bleepingcomputer.com/news/security/new-redalert-ransomware-targets-windows-linux-vmware-esxi-servers/ 6、网络钓鱼诈骗冒充阿联酋政府人力资源部针对中东 https://www.cloudsek.com/threatintelligence/advanced-phishing-scams-target-individuals-businesses-in-the-middle-east/ 7、Spring Data MongoDB修复一个严重的SpEL注入漏洞 https://portswigger.net/daily-swig/spring-data-mongodb-hit-by-another-critical-spel-injection-flaw 8、卡巴斯基推出针对手机跟踪软件检测的免费工具 https://www.bleepingcomputer.com/news/security/astralocker-ransomware-shuts-down-and-releases-decryptors/ 9、PCI DSS 4.0发布以应对新兴威胁和技术 https://www.helpnetsecurity.com/2022/07/05/pci-dss-4-0-released/ 10、调查显示传统数据安全工具面对勒索软件攻击的失败率高达 60% https://www.ithome.com/0/627/965.htm
网络安全日报 2022年07月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、大规模的网络攻击袭击了特拉维夫地铁IT设施 https://securityaffairs.co/wordpress/132897/hacking/tel-aviv-metro-company-attacked.html2、AstraLocker 勒索软件关闭了其运营并放出了解密器 https://securityaffairs.co/wordpress/132871/malware/astralocker-ransomware-shut-down.html3、研究人员发现恶意 NPM 包从应用程序和 Web 表单中窃取数据 https://thehackernews.com/2022/07/researchers-uncover-malicious-npm.html4、德国提出应对卫星网络威胁的计划 https://www.theregister.com/2022/07/05/bsi_satellite_baseline/5、Cyber Europe 2022:欧盟完成超大规模网络战争演习 https://portswigger.net/daily-swig/cyber-europe-2022-eu-completes-large-scale-cyber-war-game-exercise6、Talos研究人员分享了揭露暗网上匿名勒索软件网站的技术 https://thehackernews.com/2022/07/researchers-share-techniques-to-uncover.html7、报告显示2022 年十大高薪紧缺技能:网络安全排名第一 https://www.secrss.com/articles/442958、媒体六问“学习通数据疑泄露”:如何被窃取?平台要担何责? https://www.cnbeta.com/articles/tech/1287461.htm9、招聘网站 51job 个人信息数据库泄露?官方回应称无异常 https://www.secrss.com/articles/4429210、乌克兰核电站遭到物理/网络协同攻击?微软报告遭众多网络专家质疑 https://www.cyberscoop.com/cybersecurity-experts-question-microsofts-ukraine-report/
网络安全日报 2022年07月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Chrome 103 发布紧急更新补丁修复了一个被利用的0day漏洞 https://www.securityweek.com/emergency-chrome-103-update-patches-actively-exploited-vulnerability 2、 Django Web 框架修复了高危SQL注入漏洞 https://securityaffairs.co/wordpress/132853/security/django-framework-sql-injection.html 3、CISA 命令联邦机构在 7 月 22 日之前修补 CVE-2022-26925 https://securityaffairs.co/wordpress/132830/security/cisa-orders-patch-cve-2022-26925.html 4、研究人员发现一群未成年人在Discord平台开发、出售恶意软件 https://www.hackread.com/teen-hackers-discord-sell-malware-for-quick-cash/ 5、英国陆军YouTube和Twitter账户遭黑客入侵 https://www.theverge.com/2022/7/3/23193668/british-army-youtube-twitter-accounts-hacked-promote-crypto-scam-fraud 6、钓鱼邮件伪装成加拿大税务机构窃取用户信息 https://www.welivesecurity.com/2022/07/01/phishing-scam-posing-canadian-tax-agency-canada-day/ 7、俄罗斯政府转向 Linux 操作系统 https://www.solidot.org/story?sid=71998 8、企业SaaS软件Zoho某个工具的关键漏洞遭在野利用 https://www.bleepingcomputer.com/news/security/zoho-manageengine-adaudit-plus-bug-gets-public-rce-exploit/ 9、微软更新Azure AD,支持临时密码 https://www.bleepingcomputer.com/news/microsoft/microsoft-updates-azure-ad-with-support-for-temporary-passcodes/ 10、美国网络安全出口管制文件《信息安全控制:网络安全物项》解读 https://www.freebuf.com/articles/neopoints/337315.html
网络安全日报 2022年07月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google Project Zero 称今年上半年发现的0day有一半是旧漏洞的变种 https://www.securityweek.com/google-half-2022s-zero-days-are-variants-previous-vulnerabilities 2、Jenkins 安全团队披露数十个 Jenkins 插件 0day漏洞 https://securityaffairs.co/wordpress/132836/security/jenkins-plugins-zero-day-flaws.html 3、微软:Windows蠕虫Raspberry Robin 已感染数百个组织的网络 https://securityaffairs.co/wordpress/132826/malware/microsoft-raspberry-robin-spreading.html 4、出版业巨头麦克米伦遭勒索软件攻击,被迫关闭其IT设施 https://securityaffairs.co/wordpress/132792/cyber-crime/macmillan-ransomware-attack.html 5、谷歌改进其密码管理器以提高所有平台的安全性 https://thehackernews.com/2022/07/google-improves-its-password-manager-to.html 6、Gitlab 修补了最新安全版本中的关键 RCE漏洞 https://portswigger.net/daily-swig/gitlab-patches-critical-rce-bug-in-latest-security-release 7、黑客入侵已认证的Twitter帐户以发送虚假通知 https://www.bleepingcomputer.com/news/security/verified-twitter-accounts-hacked-to-send-fake-suspension-notices/ 8、HackerOne披露前员工窃取漏洞报告并出售 https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/ 9、报告称Coinbase向ICE出售用户地理位置数据 https://www.hackread.com/report-coinbase-selling-user-geolocation-data-ice/ 10、超过90万个Kubernetes实例被发现在线暴露 https://www.armosec.io/blog/over-900k-kubernetes-clusters-found-exposed/
网络安全日报 2022年07月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Brocade 软件中发现的漏洞影响几家大公司的存储解决方案 https://www.securityweek.com/brocade-vulnerabilities-could-impact-storage-solutions-several-major-companies 2、Lazarus APT被认为是盗取Harmony 1亿美元加密货币的幕后黑手 https://www.securityweek.com/north-korea-lazarus-hackers-blamed-100-million-horizon-bridge-heist 3、韩国网络安全机构发布了 Hive 勒索软件的免费解密器 https://securityaffairs.co/wordpress/132770/malware/hive-ransomware-decryptor.html 4、美国 FCC 专员要求苹果和谷歌从应用商店中下架 TikTok https://thehackernews.com/2022/06/us-fcc-commissioner-asks-apple-and.html 5、XFiles Infostealer 恶意软件利用 Follina 漏洞进行攻击 https://www.bleepingcomputer.com/news/security/xfiles-info-stealing-malware-adds-support-for-follina-delivery/ 6、Chromium 浏览器容易受到悬挂标记注入的影响 https://portswigger.net/daily-swig/chromium-browsers-vulnerable-to-dangling-markup-injection 7、OpenSea 披露数据泄露,警告用户防范网络钓鱼攻击 https://www.bleepingcomputer.com/news/security/opensea-discloses-data-breach-warns-users-of-phishing-attacks/ 8、经报网络安全审查办公室同意,BOSS 直聘、运满满恢复新用户注册 https://www.ithome.com/0/627/030.htm 9、意大利监管机构称谷歌分析工具侵犯隐私 https://www.inforisktoday.com/italian-watchdog-says-google-analytics-privacy-violation-a-19470 10、挪威国家安全局称挪威多家大型组织遭受DDoS攻击 https://therecord.media/norway-accuses-pro-russian-hackers-of-launching-wave-of-ddos-attacks/