网络安全日报 2022年06月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Splunk Enterprise 修补了的关键代码执行漏洞 https://www.securityweek.com/critical-code-execution-vulnerability-patched-splunk-enterprise 2、Internet Explorer浏览器今天起停止服务 https://www.securityweek.com/so-long-internet-explorer-browser-retires-today 3、新的Hertzbleed侧信道攻击可远程窃取 AMD 和 Intel 芯片的加密密钥 https://securityaffairs.co/wordpress/132316/hacking/hertzbleed-side-channel-attack-allows-to-remotely-steal-encryption-keys-from-amd-and-intel-chips.html 4、Citrix ADM 中的一个严重漏洞允许重置管理员密码 https://securityaffairs.co/wordpress/132299/security/citrix-application-delivery-management-flaw.html 5、Panchan Golang P2P 僵尸网络针对 Linux 服务器 https://securityaffairs.co/wordpress/132290/cyber-crime/panchan-p2p-botnet.html 6、Cloudflare阻止了破纪录的HTTPS DDoS攻击(2600万RPS) https://thehackernews.com/2022/06/cloudflare-saw-record-breaking-ddos.html 7、SAP 修补高危 NetWeaver 漏洞 https://www.securityweek.com/sap-patches-high-severity-netweaver-vulnerabilities 8、Phosphorus组织针对以色列和美国官员进行鱼叉式网络钓鱼 https://www.infosecurity-magazine.com/news/iran-spearphishers-hijack-email/ 9、卡塔尔加强网络安全为世界杯做准备 https://www.computerweekly.com/news/252521418/Qatar-bolsters-cyber-security-in-preparation-for-World-Cup 10、Firefox 现在默认阻止所有用户的跨站点跟踪 https://www.bleepingcomputer.com/news/security/firefox-now-blocks-cross-site-tracking-by-default-for-all-users/
网络安全日报 2022年06月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Windows 周二补丁日更新修复50个漏洞,包括"Follina"漏洞 https://www.securityweek.com/windows-updates-patch-actively-exploited-follina-vulnerability 2、西门子和施耐德电气解决了 80 多个漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-address-over-80-vulnerabilities 3、Zimbra 电子邮件中的一个漏洞允许窃取用户的登录凭据 https://securityaffairs.co/wordpress/132269/hacking/zimbra-email-suite-flaw.html 4、未修补的 Travis CI API 漏洞暴露了数以万计的用户令牌 https://thehackernews.com/2022/06/unpatched-travis-ci-api-bug-exposes.html 5、ESET 研究人员发现了一种专门破坏电网的恶意软件:Industroyer https://www.welivesecurity.com/2022/06/13/industroyer-cyber-weapon-brought-down-power-grid 6、DragonForce黑客组织攻击了至少70个印度网站 https://www.govinfosecurity.com/malaysian-hacktivists-target-indian-websites-as-payback-a-19325 7、网络犯罪分子使用反向隧道和URL缩短器发起网络钓鱼活动 https://portswigger.net/daily-swig/cybercriminals-use-reverse-tunneling-and-url-shorteners-to-launch-virtually-undetectable-phishing-campaigns 8、乌干达证券交易所被发现泄露32GB敏感数据 https://www.hackread.com/scoop-uganda-security-exchange-leaking-sensitive-records/ 9、伊朗黑客在攻击中发现新的 DNS劫持恶意软件 https://thehackernews.com/2022/06/iranian-hackers-spotted-using-new-dns.html 10、索尼 PS5、PS4、PS3 主机存在重大漏洞,可执行任意代码 https://www.ithome.com/0/623/615.htm
网络安全日报 2022年06月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员展示了特斯拉钥匙卡功能如何被滥用来偷车 https://www.securityweek.com/researcher-shows-how-tesla-key-card-feature-can-be-abused-steal-cars 2、Drupal 修补了"高危"第三方库漏洞 https://www.securityweek.com/drupal-patches-high-risk-third-party-library-flaws 3、HelloXD 勒索软件在目标系统上部署持久访问后门 https://securityaffairs.co/wordpress/132207/malware/helloxd-ransomware-installs-microbackdoor.html 4、研究人员证明WiFi 连接探测请求会暴露用户数据 https://securityaffairs.co/wordpress/132193/mobile-2/wifi-probe-requests-track-users.html 5、与俄有关的 APT 利用 Follina RCE 漏洞攻击乌克兰 https://securityaffairs.co/wordpress/132227/apt/cert-ua-sandworm-follina-rce.html 6、研究人员披露了 Mitel 企业 IP 电话中的两个漏洞 https://thehackernews.com/2022/06/researchers-disclose-rooting-backdoor.html 7、多个勒索软件正在利用Atlassian Confluence中的漏洞 https://securityaffairs.co/wordpress/132186/cyber-crime/ransomware-gangs-cve-2022-26134-rce-atlassian-confluence.html 8、华盛顿州7万名凯萨医疗机构患者的个人信息被泄露 https://portswigger.net/daily-swig/kaiser-permanente-data-breach-exposed-healthcare-records-of-70-000-patients 9、FBI表示不到25%的NetWalker勒索软件受害者报告了事件 https://therecord.media/fbi-doj-say-less-than-25-of-netwalker-ransomware-victims-reported-incidents/ 10、 尼日利亚警方破获计划对10家银行进行网络攻击的团伙 https://www.govinfosecurity.com/nigerian-police-bust-gang-planning-cyberattacks-on-10-banks-a-19320
网络安全日报 2022年06月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LenelS2 HID Mercury门禁控制器中的漏洞允许黑客解锁门 https://www.securityweek.com/vulnerabilities-hid-mercury-access-controllers-allow-hackers-unlock-doors 2、Chrome 102 更新修复高危漏洞 https://www.securityweek.com/chrome-102-update-patches-high-severity-vulnerabilities 3、研究人员发现一种针对 Apple M1 CPU 的新攻击技术:PACMAN https://securityaffairs.co/wordpress/132154/hacking/pacman-attack-apple-m1-cpus.html 4、研究人员发现可以对蓝牙信号进行指纹识别以跟踪智能手机 https://thehackernews.com/2022/06/researchers-find-bluetooth-signals-can.html 5、MakeMoney恶意广告活动诱导用户安装虚假的Firefox更新 https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template/ 6、研究人员表示越来越多的恶意软件团伙开始利用Follina漏洞 https://www.theregister.com/2022/06/09/symantec-follina-microsoft/ 7、Lycaeum组织利用基于.NET的DNS后门攻击能源和电信行业 https://www.bleepingcomputer.com/news/security/iranian-hackers-target-energy-sector-with-new-dns-backdoor/ 8、研究人员分享了Linux恶意软件Symbiote的详细信息 https://www.securityweek.com/highly-evasive-linux-malware-symbiote-infects-all-running-processes 9、富士通云存储漏洞可使攻击者破坏虚拟备份 https://portswigger.net/daily-swig/separate-fujitsu-cloud-storage-vulnerabilities-could-enable-attackers-to-destroy-virtual-backups 10、针对Atlassian RCE漏洞的PoC已在线发布 https://cyware.com/news/poc-exploits-for-atlassian-rce-bug-exploit-released-online-463354a9
网络安全日报 2022年06月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、'Follina' 漏洞被Qbot、AsyncRAT 和其他恶意软件利用 https://www.securityweek.com/follina-vulnerability-exploited-deliver-qbot-asyncrat-other-malware 2、研究人员发现了一种高度隐蔽的 Linux 恶意软件Symbiote https://securityaffairs.co/wordpress/132113/malware/symbiote-linux-malware.html 3、新的 Emotet 变体从 Google Chrome 窃取用户信用卡数据 https://securityaffairs.co/wordpress/132090/cyber-crime/emotet-google-chrome-info-stealer.html 4、Black Basta勒索软件现在支持加密VMware ESXi服务器 https://securityaffairs.co/wordpress/132037/hacking/black-basta-ransomware-vmware-esxi.html 5、网络钓鱼活动利用Facebook Messenger诱导用户查看广告 https://www.bleepingcomputer.com/news/security/massive-facebook-messenger-phishing-operation-generates-millions/ 6、Linux僵尸网络正在利用Atlassian Confluence的高危漏洞 https://www.bleepingcomputer.com/news/security/linux-botnets-now-exploit-critical-atlassian-confluence-bug/ 7、谷歌因侵犯隐私向居民赔偿1 亿美元 https://www.freebuf.com/news/335570.html 8、网络犯罪者使用自动 Bot 服务在大规模范围内绕过 2FA 身份验证 https://www.techrepublic.com/article/cybercriminals-automated-bot-bypass-2fa 9、MyEasyDocs 暴露了 30GB 的以色列和印度学生 PII 数据 https://www.hackread.com/myeasydocs-exposed-30gb-israel-india-students-pii-data 10、越来越多的自动驾驶汽车引发网络安全担忧 https://thehill.com/driving-into-the-future/3514634-increasingly-autonomous-cars-raise-cybersecurity-fears/
网络安全日报 2022年06月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究发现 80% 的勒索软件受害者遭二次攻击 https://www.securityweek.com/it-doesnt-pay-pay-study-finds-eighty-percent-ransomware-victims-attacked-again 2、美国司法部和FBI查封了 SSNDOB 网络犯罪市场 https://securityaffairs.co/wordpress/132061/cyber-crime/us-seized-ssndob-marketplace.html 3、Owl Labs 修补了视频会议设备中的严重漏洞 https://www.securityweek.com/owl-labs-patches-severe-vulnerability-video-conferencing-devices 4、0Patch 为新 DogWalk Windows 0day漏洞发布非官方安全补丁 https://securityaffairs.co/wordpress/132070/hacking/unofficial-security-patch-dogwalk.html 5、Apple 推出用于应用程序和网站的无密码身份验证 https://www.helpnetsecurity.com/2022/06/07/apple-passkeys/ 6、FakeCrack恶意软件通过中毒的CCleaner搜索结果进行传播 https://www.bleepingcomputer.com/news/security/poisoned-ccleaner-search-results-spread-information-stealing-malware/ 7、马萨诸塞州一医疗公司的数据泄露影响了200万患者 https://www.securityweek.com/data-breach-shields-health-care-group-impacts-2-million-patients 8、Mandiant否认被 LockBit 勒索组织窃取数据 https://www.bleepingcomputer.com/news/security/mandiant-no-evidence-we-were-hacked-by-lockbit-ransomware/ 9、SVCReady恶意软件正在发起新的钓鱼邮件攻击 https://thehackernews.com/2022/06/researchers-warn-of-spam-campaign.html 10、Red TIM Research发现Resi上一个命令注入高危漏洞 https://securityaffairs.co/wordpress/131985/security/resi-critical-command-injection.html
网络安全日报 2022年06月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发布了最近修补的 Zyxel 防火墙漏洞技术细节 https://www.securityweek.com/technical-details-released-recently-patched-zyxel-firewall-vulnerabilities 2、Evil Corp 团伙开始使用 LockBit Ransomware 以逃避制裁 https://securityaffairs.co/wordpress/132031/cyber-crime/evil-corp-lockbit-ransomware.html 3、Black Basta 勒索软件利用 QBot恶意软件进行横向扩展攻击 https://securityaffairs.co/wordpress/132018/hacking/black-basta-ransomware-qbot.html 4、Follina 在网络钓鱼攻击中被利用 https://cyware.com/news/follina-exploited-in-phishing-attacks-16fca1ae 5、苹果的新功能将自动安装安全更新,无需完整的操作系统更新 https://thehackernews.com/2022/06/apples-new-feature-will-install.html 6、意大利巴勒莫市关闭所有系统以抵御网络攻击 https://www.bleepingcomputer.com/news/security/italian-city-of-palermo-shuts-down-all-systems-to-fend-off-cyberattack/ 7、格洛斯特市议会的IT系统遭黑客攻击近六个月后仍未完全运行 https://www.infosecurity-magazine.com/news/gloucester-council-it-systems/ 8、研究人员观察到传播SVCReady恶意软件的网络钓鱼活动 https://thehackernews.com/2022/06/researchers-warn-of-spam-campaign.html 9、谷歌通过 2022 年 6 月更新修补了关键的 Android 漏洞 https://www.securityweek.com/google-patches-critical-android-vulnerabilities-june-2022-updates 10、加密货币骗局在美或已造成超10亿美元损失 https://www.bleepingcomputer.com/news/security/americans-report-losing-over-1-billion-to-cryptocurrency-scams/
网络安全日报 2022年06月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、GitLab 企业版修复了高危帐户接管漏洞 https://www.securityweek.com/critical-account-takeover-vulnerability-patched-gitlab-enterprise-edition 2、U-Boot存在严重漏洞可通过本地网络写入任意数据 https://www.securityweek.com/critical-u-boot-vulnerability-allows-rooting-embedded-systems 3、Lockbit 勒索软件团伙声称已入侵网络安全巨头 Mandiant https://securityaffairs.co/wordpress/132011/cyber-crime/lockbit-claims-mandiant-hack.html 4、微软摧毁了与伊朗有关的 Bohrium APT 使用的 41 个域名 https://securityaffairs.co/wordpress/132002/apt/microsoft-seized-bohrium-apt-domains.html 5、暗网市场AlphaBay被国际执法行动捣毁5年后,重新回归 https://www.wired.com/story/alphabay-dark-web-market-ranking/ 6、匿名者黑客组织泄露了1TB俄罗斯顶级律师事务所数据 https://www.hackread.com/anonymous-hacktivists-leak-1tb-russia-law-firm-data/ 7、挖矿木马WatchDog新一轮活动瞄准Docker 和 Redis 服务器 https://cyware.com/news/watchdog-targets-docker-and-redis-servers-in-new-cryptojacking-campaign-a5681a92 8、CISA 发出警告:美国多州使用的投票机存在软件漏洞 https://www.cnbeta.com/articles/tech/1276043.htm 9、在过去一年中,近四分之三的公司因DNS攻击而停工 https://www.infosecurity-magazine.com/news/threequarters-suffer-downtime/ 10、数百个Elasticsearch数据库遭到勒索攻击 https://www.bleepingcomputer.com/news/security/hundreds-of-elasticsearch-databases-targeted-in-ransom-attacks/
网络安全日报 2022年06月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 警告 Illumina 基因分析设备存在严重漏洞 https://www.securityweek.com/cisa-warns-critical-vulnerabilities-illumina-genetic-analysis-devices 2、Atlassian Confluence 服务器0day漏洞(CVE-2022-26134)被广泛利用 https://www.securityweek.com/atlassian-confluence-servers-hacked-zero-day-vulnerability 3、数百万使用 UNISOC 芯片的廉价智能手机易受远程 DoS 攻击 https://www.securityweek.com/millions-budget-smartphones-unisoc-chips-vulnerable-remote-dos-attacks 4、匿名博客平台Telegraph正被网络钓鱼者积极利用 https://www.bleepingcomputer.com/news/security/telegram-s-blogging-platform-abused-in-phishing-attacks/ 5、Korenix JetPort工业串行设备服务器存在后门帐户 https://www.securityweek.com/vendor-refuses-remove-backdoor-account-can-facilitate-attacks-industrial-firms 6、美国国家安全局将军证实美国在俄乌战争中的进攻性网络行动 https://www.theregister.com/2022/06/02/nakasone_us_hacking_russia/ 7、Conti勒索软件团伙拥有利用英特尔固件漏洞的PoC https://www.theregister.com/2022/06/02/conti_rasomware_intel_firmware/ 8、639个含有银行木马的金融应用程序被下载超过10亿次 https://www.bleepingcomputer.com/news/security/top-10-android-banking-trojans-target-apps-with-1-billion-downloads/ 9、微软破坏了Bohrium黑客组织的鱼叉式网络钓鱼攻击 https://www.bleepingcomputer.com/news/security/microsoft-disrupts-bohrium-hackers-spear-phishing-operation/ 10、报告显示勒索软件和社会工程是网络安全人员面临的主要挑战 https://threatpost.com/old-hacks-die-hard-ransomware-social-engineering-top-verizon-dbir-threats-again/179864/
网络安全日报 2022年06月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Horde Webmail 服务器存在高危漏洞 https://www.securityweek.com/unpatched-vulnerability-exposes-horde-webmail-servers-attacks 2、LockBit 2.0 勒索软件攻击了富士康在墨西哥的一家工厂 https://www.securityweek.com/ransomware-group-claims-have-breached-foxconn-factory 3、欧洲刑警组织宣布摧毁了FluBot 移动间谍软件 https://www.securityweek.com/europol-announces-takedown-flubot-mobile-spyware 4、新的 XLoader 僵尸网络版本使用新技术来隐藏其 C2 服务器 https://securityaffairs.co/wordpress/131860/cyber-crime/xloader-botnet-obscures-c2.html 5、研究人员在全球范围内发现了超过 360 万台可访问的 MySQL 服务器 https://securityaffairs.co/wordpress/131851/security/3-6-million-mysql-servers-accessible-online.html 6、Hive 勒索软件团伙攻击了哥斯达黎加的公共卫生服务 https://securityaffairs.co/wordpress/131837/cyber-crime/costa-rica-cccs-hive-ransomware.html 7、FDA 发布医疗器械网络安全指南 https://www.meddeviceonline.com/doc/fda-releases-guidance-on-cybersecurity-in-medical-devices-0001 8、乌克兰在2022年第一季度观察到近1400万起网络安全事件 https://www.govinfosecurity.com/ukraine-observed-nearly-14m-cyber-incidents-in-q1-2022-a-19175 9、英国政府就云、数据中心安全征求意见 https://www.theregister.com/2022/05/30/uk_government_security_consultation/ 10、南非总统的个人信贷数据泄露 https://www.secrss.com/articles/42993