网络安全日报 2022年06月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Firefox 102 修补 19 个漏洞,改善隐私保护策略 https://www.securityweek.com/firefox-102-patches-19-vulnerabilities-improves-privacy 2、Azure Service Fabric 漏洞可能导致集群接管 https://www.securityweek.com/azure-service-fabric-vulnerability-can-lead-cluster-takeover 3、MITRE 发布 2022 年 25 个最危险漏洞列表 https://www.securityweek.com/mitre-publishes-2022-list-25-most-dangerous-vulnerabilities 4、UnRAR 中的路径遍历漏洞可能允许入侵 Zimbra 邮件服务器 https://securityaffairs.co/wordpress/132737/breaking-news/unrar-path-traversal-flaw-zimbra.html 5、新的 YTStealer 恶意软件劫持 YouTube 内容创作者的帐户 https://thehackernews.com/2022/06/new-ytstealer-malware-aims-to-hijack.html 6、AstraLocker 2.0 利用 Office 文档分发勒索软件 https://blog.reversinglabs.com/blog/smash-and-grab-astralocker-2-pushes-ransomware-direct-from-office-docs 7、FBI 警告网络犯罪分子使用 Deepfakes进行身份冒充申请远程工作 https://www.zdnet.com/article/fbi-warning-crooks-are-are-using-deepfakes-to-apply-for-remote-tech-jobs 8、Evilnum黑客组织把目标对准参与国际移民的欧洲组织 https://www.bleepingcomputer.com/news/security/evilnum-hackers-return-in-new-operation-targeting-migration-orgs/ 9、美国、巴西查获272个用于非法下载音乐的网站 https://www.bleepingcomputer.com/news/security/us-brazil-seize-272-websites-used-to-illegally-download-music/ 10、微软将在 7 月为所有用户修复 Windows RRAS、VPN 问题 https://www.bleepingcomputer.com/news/microsoft/microsoft-will-fix-windows-rras-vpn-issues-for-all-users-in-july/
网络安全日报 2022年06月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 表示"PwnKit"Linux 漏洞(CVE-2021-4034)已在攻击中被利用 https://www.securityweek.com/cisa-says-pwnkit-linux-vulnerability-exploited-attacks2、谷歌宣布全面推出 Cloud Armor Web安全功能 https://www.securityweek.com/google-introduces-new-capabilities-cloud-armor-web-security-service3、最新的 OpenSSL 版本受到远程内存损坏漏洞的影响 https://securityaffairs.co/wordpress/132697/security/openssl-remote-memory-corruption-flaw.html4、西部银行在自动取款机上发现借记卡窃取器 https://www.bleepingcomputer.com/news/security/bank-of-the-west-found-debit-card-stealing-skimmers-on-atms/5、立陶宛政府证实它受到了强烈的网络攻击 https://securityaffairs.co/wordpress/132676/cyber-warfare-2/lithuania-massive-ddos.html6、ZuoRAT 恶意软件劫持家庭和办公室路由器以监视目标网络 https://thehackernews.com/2022/06/zuorat-malware-hijacking-home-office.html7、Messenger 聊天机器人被用于窃取 Facebook 帐户 https://www.bleepingcomputer.com/news/security/messenger-chatbots-now-used-to-steal-facebook-accounts/8、《个人信息跨境处理活动安全认证规范》发布,规范个人信息跨境活动 https://www.freebuf.com/news/337414.html9、RansomHouse勒索组织声称拥有从AMD窃取的450Gb数据 https://www.theregister.com/2022/06/28/amd-ransomhouse-data-extortion/10、国家网信办发布《互联网用户账号信息管理规定》 8月1日起施行 http://www.ce.cn/culture/gd/202206/27/t20220627_37807243.shtml
网络安全日报 2022年06月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、NIST 发布新的 macOS 端点和评估安全指南 https://www.securityweek.com/nist-releases-new-macos-security-guidance-organizations 2、众议院通过 ICS 网络安全培训法案 https://www.securityweek.com/house-passes-ics-cybersecurity-training-bill 3、伊朗国有的Khuzestan钢铁公司遭到网络攻击,被迫停止生产 https://securityaffairs.co/wordpress/132658/cyber-warfare-2/iran-khuzestan-steel-company-cyberattack.html 4、乌克兰电信运营商受到 DarkCrystal RAT 恶意软件的攻击 https://securityaffairs.co/wordpress/132651/malware/cert-ua-darkcrystal-rat-attacks.html 5、攻击者从 Harmony 窃取了 1 亿美元的加密货币 https://securityaffairs.co/wordpress/132642/hacking/harmony-crypto-assets.html 6、LockBit 3.0 推出首个勒索软件漏洞赏金计划,最高奖励100万美金 https://www.bleepingcomputer.com/news/security/lockbit-30-introduces-the-first-ransomware-bug-bounty-program/ 7、网络安全审查办公室对知网启动网络安全审查 http://www.cac.gov.cn/2022-06/24/c_1657686783575480.htm 8、德克萨斯州一家液化天然气厂遭网络攻击导致爆炸 https://securityaffairs.co/wordpress/132608/security/liquefied-natural-gas-plant-texas-explosion.html 9、研究人员披露利用微软WebView2应用绕过MFA的钓鱼方法 https://www.bleepingcomputer.com/news/security/clever-phishing-method-bypasses-mfa-using-microsoft-webview2-apps/ 10、攻击者出售50个利用Atlassian漏洞入侵的网络的访问权限 https://securityaffairs.co/wordpress/132637/cyber-crime/access-vulnerable-networks-atlassian-0day.html
网络安全日报 2022年06月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员:Oracle 花了 6 个月时间修补影响许多系统的严重漏洞 https://www.securityweek.com/researchers-it-took-oracle-6-months-patch-mega-vulnerability-affecting-many-systems 2、Codesys 修补了可能影响多个 ICS 供应商的控制器的 11 个漏洞 https://www.securityweek.com/codesys-patches-11-flaws-likely-affecting-controllers-several-ics-vendors 3、美国机构警告组织针对 VMware 产品的 Log4Shell 攻击 https://www.securityweek.com/us-agencies-warn-organizations-log4shell-attacks-against-vmware-products 4、PyPI 存储库中的多个恶意程序包被发现窃取 AWS 凭证 https://securityaffairs.co/wordpress/132598/hacking/pypi-malicious-packages-2.html 5、攻击者利用 Mitel VOIP 设备中的零日漏洞入侵网络 https://securityaffairs.co/wordpress/132588/hacking/mitel-voip-ransomware-attack.html 6、Google TAG透露,意大利间谍软件供应商 RCS Labs 在ISP 的帮助下感染用户设备 https://securityaffairs.co/wordpress/132553/malware/rcs-labs-spyware-spreads.html 7、数据监控和搜索供应商Splunk修复了一个代码执行漏洞 https://portswigger.net/daily-swig/splunk-patches-critical-vulnerability-while-users-push-for-legacy-updates 8、研究发现全球企业因不安全的API面临数十亿美元的损失 https://www.infosecurity-magazine.com/news/unsecured-apis-could-costing-firms/ 9、Jacuzzi SmartTub 应用程序中的漏洞可能允许访问用户数据 https://securityaffairs.co/wordpress/132559/hacking/jacuzzi-smarttub-app-flaws.html 10、大规模用户反馈 QQ 账号被盗,会自动给好友和群发送违法内容 https://www.ithome.com/0/626/475.htm
网络安全日报 2022年06月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、意大利间谍软件Hermit针对Apple和Android手机 https://www.securityweek.com/apple-android-phones-targeted-italian-spyware-google 2、汽车软管制造商 Nichirin 的美国子公司被勒索软件攻击 https://www.securityweek.com/us-subsidiary-automotive-hose-maker-nichirin-hit-ransomware 3、NSO Group透露Pegasus 间谍软件被至少 5 个欧洲国家使用 https://securityaffairs.co/wordpress/132536/malware/nso-group-pegasus-5-eu-countries.html 4、QNAP NAS 设备严重的 PHP 漏洞使其易受远程攻击 https://thehackernews.com/2022/06/critical-php-vulnerability-exposes-qnap.html 5、Conti勒索软件在一个月内入侵了40多家公司 https://www.bleepingcomputer.com/news/security/conti-ransomware-hacking-spree-breaches-over-40-orgs-in-a-month/ 6、Parse Server漏洞可使攻击者绕过苹果游戏中心身份验证 https://portswigger.net/daily-swig/severe-parse-server-bug-impacts-apple-game-center 7、Facebook面临一项集体诉讼,被控私自收集数百万医疗用户信息 https://www.inforisktoday.com/lawsuit-facebook-collecting-patient-data-millions-a-19424 8、研究显示开源代码存在安全隐患:一个项目平均有49个漏洞 https://www.cnbeta.com/articles/tech/1283559.htm 9、威胁行为者利用RIG漏洞传播Dridex银行木马 https://securityaffairs.co/wordpress/132498/malware/rig-exploit-kit-dridex.html 10、欧洲刑警组织捣毁跨国网络钓鱼团伙,缴获数百万美元 https://thehackernews.com/2022/06/europol-busts-phishing-gang-responsible.html
网络安全日报 2022年06月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌发布 Chrome 103 修补了14 个漏洞 https://www.securityweek.com/google-patches-14-vulnerabilities-release-chrome-103 2、Aqua Security 推出用于审计软件供应链的开源工具 https://www.securityweek.com/aqua-security-ships-open-source-tool-auditing-software-supply-chain 3、英国第二大快递公司Yodel 遭破坏性网络攻击 https://www.securityweek.com/delivery-firm-yodel-scrambling-restore-operations-following-cyberattack 4、研究人员发现破解"MEGA"云存储服务加密的方法 https://thehackernews.com/2022/06/researchers-uncover-ways-to-break.html 5、欧洲队成为第一届国际网络安全挑战赛的获胜者 https://www.enisa.europa.eu/news/enisa-news/hats-off-to-team-europe-winners-of-the-1st-international-cybersecurity-challenge 6、Adobe Acrobat试图阻止安全软件查看其打开的PDF文件 https://www.bleepingcomputer.com/news/security/adobe-acrobat-may-block-antivirus-tools-from-monitoring-pdf-files/ 7、浴缸制造商Jacuzzi的SmartTub应用程序存在信息泄露漏洞 https://portswigger.net/daily-swig/jacuzzi-customer-details-could-be-exposed-by-smarttub-web-bugs-claims-researcher 8、西北工业大学电子邮件系统遭受境外网络攻击 https://news.sina.com.cn/c/2022-06-22/doc-imizirau9980154.shtml 9、最新的Windows Server 更新中断了 VPN、RDP、RRAS 连接 https://www.bleepingcomputer.com/news/microsoft/recent-windows-server-updates-break-vpn-rdp-rras-connections/ 10、 谷歌浏览器扩展可用于在线跟踪用户 https://www.infosecurity-magazine.com/news/chrome-extensions-track-users/
网络安全日报 2022年06月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、多个OT设备制造商受到56个“ICEFALL”漏洞的影响 https://therecord.media/siemens-motorola-honeywell-and-more-affected-by-56-icefall-vulnerabilities/ 2、新的DFSCoerce NTLM中继攻击让攻击者可以控制Windows域 https://thehackernews.com/2022/06/new-ntlm-relay-attack-lets-attackers.html 3、BidenCash网站以15美分的价格出售被盗的信用卡 https://www.bleepingcomputer.com/news/security/new-bidencash-site-sells-your-stolen-credit-card-for-just-15-cents/ 4、密歇根州旗星银行数据泄露事件影响超过150万客户 https://www.infosecurity-magazine.com/news/us-bank-data-breach-impacts-15/ 5、新的 ToddyCat APT 针对欧洲和亚洲的知名实体 https://securityaffairs.co/wordpress/132482/apt/toddycat-apt.html 6、网络犯罪分子在网络钓鱼攻击中使用 Azure Front Door https://securityaffairs.co/wordpress/132458/cyber-crime/azure-front-door-phishing.html 7、微软紧急发布更新,修复ARM设备上的Microsoft365登录问题 https://www.freebuf.com/news/336760.html 8、Avos Ransomware Group 将攻击库扩展到 VMware Horizon 访问网关 https://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html 9、VIP3R Campaign 使用 HTML 附件绕过电子邮件安全 https://cyware.com/news/vip3r-campaign-uses-html-attachments-to-bypass-email-security-a2a2008a 10、2021年损失18亿美元!去中心化金融遭网络犯罪重创 https://www.secrss.com/articles/43722
网络安全日报 2022年06月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、AutomationDirect 修补 PLC、HMI 产品中的漏洞 https://www.securityweek.com/automationdirect-patches-vulnerabilities-plc-hmi-products 2、德国绿党称电子邮件系统受到网络攻击 https://www.securityweek.com/germanys-green-party-says-email-system-hit-cyberattack 3、APT28 黑客被指控攻击德国的北约智库 https://securityaffairs.co/wordpress/132452/hacking/apt28-hacked-nato-think-tank.html 4、谷歌Project Zero披露了一个存在 5 年之久被在野利用的Safari 漏洞细节 https://securityaffairs.co/wordpress/132446/hacking/apple-safari-zero-day-2016.html 5、BRATA Android 恶意软件不断发展并针对英国、西班牙和意大利 https://securityaffairs.co/wordpress/132425/malware/brata-android-malware-evolution.html 6、Google 不再允许在第三方电子邮件应用中使用用户名和密码 https://www.neowin.net/news/google-no-longer-allows-username-and-passwords-on-third-party-email-applications 7、浏览器滚动到文本片段 (STTF) 功能可被利用来窃取数据 https://portswigger.net/daily-swig/attackers-can-use-scroll-to-text-fragment-web-browser-feature-to-steal-data-research 8、中国信通院:八成互联网电视系统存非法采集共享用户数据问题 https://www.ithome.com/0/624/914.htm 9、美国FTC:现阶段AI无法对抗网络虚假信息 https://www.secrss.com/articles/43692 10、间谍软件Hermit细节披露:由政府操控的复杂间谍软件 https://www.cnbeta.com/articles/tech/1282123.htm
网络安全日报 2022年06月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、"RSOCKS"僵尸网络基础设施被美国执法部门拆除 https://www.securityweek.com/law-enforcement-dismantle-infrastructure-russian-rsocks-botnet 2、两次修补的 Windows RDP 漏洞的详细信息已披露 https://www.securityweek.com/details-twice-patched-windows-rdp-vulnerability-disclosed 3、Ninja Forms 插件严重漏洞影响数百万WordPress网站 https://www.securityweek.com/exploited-vulnerability-patched-wordpress-plugin-over-1-million-installations 4、研究人员警告针对 QNAP NAS 的新 eCh0raix 勒索软件活动 https://securityaffairs.co/wordpress/132410/cyber-crime/ech0raix-ransomware-attacks.html 5、研究人员将 Hermit 间谍软件与意大利监控公司 RCS Lab关联 https://securityaffairs.co/wordpress/132363/malware/hermit-spyware-italian-surveillance-firm.html 6、黑客以版权为主题的虚假电子邮件针对EI-ISAC的成员 https://www.cisecurity.org/insights/blog/fake-facebook-email-uses-copyrights-to-trick-ei-isac-members 7、研究人员发现了CopperStealer恶意软件的更新样本 https://www.trendmicro.com/en_us/research/22/f/websites-hosting-fake-cracks-spread-updated-copperstealer.html 8、人力资源公司Robert Half称黑客攻击了1058个客户账户 https://www.securityweek.com/staffing-firm-robert-half-says-hackers-targeted-over-1000-customer-accounts 9、西门子工控管理系统发现15个漏洞 https://therecord.media/15-vulnerabilities-discovered-in-siemens-industrial-control-management-system/ 10、思科表示不会修复老旧 VPN 路由器中的RCE漏洞 https://www.bleepingcomputer.com/news/security/cisco-says-it-won-t-fix-zero-day-rce-in-end-of-life-vpn-routers/
网络安全日报 2022年06月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、"MaliBot"安卓恶意软件窃取财务、个人信息 https://www.securityweek.com/malibot-android-malware-steals-financial-personal-information 2、思科修补了电子邮件安全设备中的关键漏洞 https://www.securityweek.com/cisco-patches-critical-vulnerability-email-security-appliance 3、流行的 Fastjson 库修补了一个高危 RCE 漏洞 https://thehackernews.com/2022/06/high-severity-rce-vulnerability.html 4、Microsoft Office 365 功能被勒索软件滥用勒索云存储文件 https://thehackernews.com/2022/06/a-microsoft-office-365-feature-could.html 5、ALPHV/BlackCat 勒索软件团伙开始发布受害者的数据 https://securityaffairs.co/wordpress/132339/malware/blackcat-ransomware-clear-web.html 6、由于 ElasticSearch 配置错误,BeanVPN 暴露了 2500 万条用户记录 https://www.infosecurity-magazine.com/news/beanvpn-leaks-user-records/ 7、RansomHouse 勒索软件攻击了非洲最大连锁超市Shoprite https://www.bleepingcomputer.com/news/security/extortion-gang-ransoms-shoprite-largest-supermarket-chain-in-africa/ 8、酿酒巨头喜力证实在WhatsApp上流传的免费啤酒是场骗局 https://www.theregister.com/2022/06/15/heineken_phishing_scam/ 9、黑客利用三年前的 Telerik 漏洞部署 Cobalt Strike beacon https://www.bleepingcomputer.com/news/security/hackers-exploit-three-year-old-telerik-flaws-to-deploy-cobalt-strike/ 10、美国国防承包商 L3Harris 正在就收购 NSO 集团进行谈判 https://www.cnbeta.com/articles/tech/1280867.htm