网络安全日报 2022年06月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、白俄罗斯政府网站遭到匿名者黑客组织攻击 https://www.infosecurity-magazine.com/news/anonymous-claims-attacks-against/ 2、微软发布了针对Office零日漏洞的缓解措施 https://www.infosecurity-magazine.com/news/turkish-airline-exposes-flight/ 3、澳大利亚养老金提供商Spirit Super数据泄露 https://portswigger.net/daily-swig/data-breach-at-australian-pension-provider-spirit-super-impacts-50k-victims-following-phishing-attack 4、土耳其飞马航空公司泄漏了6.5TB数据,包括航班和机组人员信息 https://www.infosecurity-magazine.com/news/turkish-airline-exposes-flight/ 5、微软发现Android 预装应用受高危漏洞影响 https://www.bleepingcomputer.com/news/security/microsoft-finds-severe-bugs-in-android-apps-from-large-mobile-providers/ 6、FluBot 移动恶意软件席卷欧洲,安卓苹果都不放过 https://www.bitdefender.com/blog/labs/new-flubot-campaign-sweeps-through-europe-targeting-android-and-ios-users-alike/ 7、CISA 发布 5G 安全评估流程计划 https://www.infosecurity-magazine.com/news/cisa-5g-security-evaluation-process/ 8、EnemyBot 恶意软件增加了关键 VMware、F5 BIG-IP 漏洞的攻击 https://www.bleepingcomputer.com/news/security/enemybot-malware-adds-exploits-for-critical-vmware-f5-big-ip-flaws/ 9、SideWinder APT组织在过去 2 年发起了超过 1,000 次网络攻击 https://thehackernews.com/2022/05/sidewinder-hackers-launched-over-1000.html 10、澳大利亚电子驾照可在几分钟内被破解 https://www.theregister.com/2022/05/30/nsw_digital_drivers_licenses_hackable/
网络安全日报 2022年05月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、一个新的 WhatsApp OTP 骗局可能允许劫持用户的帐户 https://securityaffairs.co/wordpress/131807/hacking/whatsapp-otp-scam.html 2、多个Microsoft Office版本存在远程命令执行漏洞 https://securityaffairs.co/wordpress/131800/hacking/multiple-microsoft-office-versions-zero-day.html 3、EnemyBot新增CMS和Android设备漏洞利用 https://securityaffairs.co/wordpress/131783/malware/enemybot-botnet-new-exploits.html 4、Clop勒索软件卷土重来,4月添加了21名新受害者 https://www.bleepingcomputer.com/news/security/clop-ransomware-gang-is-back-hits-21-victims-in-a-single-month/ 5、加拿大卡尔加里城市项目协会证实遭到数据泄露 https://globalnews.ca/news/8872996/calgary-charity-data-breach/ 6、淘宝宣布禁止销售修改/代理/伪造IP的软件与服务 https://www.cnbeta.com/articles/tech/1274789.htm 7、咚动、自如、康珂诺等12款移动App违法被通报,隐私不合规 https://www.cnaac.org.cn/newShowData.html?id=258 8、FBI 发出警告称黑客正出售美国大学的网络凭证 https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-selling-credentials-for-us-college-networks/ 9、曝通用汽车受黑客攻击,用户信息遭泄露 https://www.pcauto.com.cn/news/3081/30810284.html 10、谷歌、苹果等科技公司喜欢谈论隐私,但同时试图扼杀隐私立法 https://www.theregister.com/2022/05/27/big_tech_privacy/
网络安全日报 2022年05月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 VMware高危漏洞CVE-2022-22972 PoC已公开 https://www.securityweek.com/exploitation-vmware-vulnerability-imminent-following-release-poc 2、GitHub:近10万名 NPM 用户的凭据在 4 月的 OAuth 令牌攻击中被盗 https://securityaffairs.co/wordpress/131733/hacking/100k-npm-credential-github-oauth-breach.html 3、研究人员设计了一种名为GhostTouch的技术:使用电磁干扰攻击触摸屏 https://securityaffairs.co/wordpress/131714/hacking/ghosttouch-touchscreens-attack.html 4、ERMAC Android 银行木马2.0针对 400 多个应用程序 https://securityaffairs.co/wordpress/131705/malware/ermac-2-0-android-banking-trojan.html 5、Cheerscrypt 勒索软件针对 VMware ESXi 服务器 https://cyware.com/news/cheerscrypt-ransomware-targets-vmware-esxi-servers-d5f3f79a 6、黑客通过远程访问窃取了数百名 Verizon 员工的数据库 https://www.vice.com/en/article/wxdwxn/hacker-steals-database-of-hundreds-of-verizon-employees 7、加拿大医疗服务提供商SHN遭黑客入侵数据泄露 https://portswigger.net/daily-swig/canadian-healthcare-provider-issues-data-breach-warning-after-server-hack 8、维护人员修复Guzzle的跨域cookie泄漏漏洞 https://portswigger.net/daily-swig/patch-released-for-cross-domain-cookie-leakage-flaw-in-guzzle 9、基于WSL的恶意软件窃取浏览器验证cookie https://www.bleepingcomputer.com/news/security/new-windows-subsystem-for-linux-malware-steals-browser-auth-cookies/ 10、研究人员发现谷歌Chrome中存在RCE漏洞 https://thehackernews.com/2022/05/experts-detail-new-rce-vulnerability.html
网络安全日报 2022年05月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 QCT 服务器受"Pantsdown" BMC漏洞的影响 https://www.securityweek.com/qct-servers-affected-pantsdown-bmc-vulnerability 2、芯片巨头博通610亿美元收购VMware https://www.securityweek.com/vmware-absorb-broadcom-security-solutions-following-61-billion-deal 3、Open Automation Software平台中发现多个严重漏洞 https://www.securityweek.com/critical-vulnerabilities-found-open-automation-software-platform 4、Twitter 因用户数据隐私被罚款 1.5 亿美元 https://www.securityweek.com/twitter-pay-150m-penalty-over-privacy-users-data 5、Zyxel 解决了影响 AP、AP 控制器和防火墙的多个漏洞 https://securityaffairs.co/wordpress/131691/security/zyxel-flaws.html 6、新的 ChromeLoader 恶意软件激增威胁全球浏览器 https://www.bleepingcomputer.com/news/security/new-chromeloader-malware-surge-threatens-browsers-worldwide/ 7、基于Linux的勒索软件Cheerscrypt针对ESXi设备 https://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html 8、印度SpiceJet航空公司遭勒索软件攻击航班延误 https://www.bleepingcomputer.com/news/security/spicejet-airline-passengers-stranded-after-ransomware-attack/ 9、伦敦港管理局网站遭到黑客攻击导致被迫关闭 https://www.hackread.com/pro-iran-altahrea-hit-port-of-london-website-ddos-attack/ 10、配置错误的服务器泄露了上千万俄罗斯和乌克兰人的数据 https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/
网络安全日报 2022年05月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 Chrome 发布102 版本,修复了 32 个漏洞 https://www.securityweek.com/chrome-102-patches-32-vulnerabilities 2、Google Project Zero披露了 Zoom 零点击远程代码执行漏洞详情 https://www.securityweek.com/google-discloses-details-zoom-zero-click-remote-code-execution-exploit 3、 SilverTerrier 网络犯罪集团头目在尼日利亚被捕 https://securityaffairs.co/wordpress/131659/cyber-crime/silverterrier-leader-arrested.html 4、华盛顿大学医学院通知患者数据泄露 https://www.beckershospitalreview.com/cybersecurity/washington-university-school-of-medicine-notifies-patients-of-data-breach-2.html 5、BPFDoor 恶意软件利用 Solaris 漏洞获取 root 权限 https://www.bleepingcomputer.com/news/security/bpfdoor-malware-uses-solaris-vulnerability-to-get-root-privileges/ 6、Telegram上泄露了 1.42 亿条米高梅客户记录,影响大约 3000 万人 https://www.hackread.com/142-million-mgm-resorts-records-leak-telegram-download/ 7、严重的Argo CD漏洞可能允许攻击者获得管理员权限 https://portswigger.net/daily-swig/critical-argo-cd-vulnerability-could-allow-attackers-admin-privileges 8、国际刑警组织:国家网络武器将很快在暗网上出现 https://www.secrss.com/articles/42740 9、美国德克萨斯州交通部遭黑客攻击导致员工信息泄露 https://www.databreaches.net/another-texas-state-agency-data-breach-this-time-its-the-department-of-transportation/ 10、CISA 在其已知被利用漏洞目录中增加了 41 个漏洞 https://securityaffairs.co/wordpress/131646/security/known-exploited-vulnerabilities-catalog-flaws-2.html
网络安全日报 2022年05月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、被广泛使用的"Ctx"Python 包遭入侵被替换为恶意版本 https://www.securityweek.com/pypi-served-malicious-version-popular-ctx-python-package 2、帐户预劫持攻击可以在用户注册之前劫持其账户 https://www.bleepingcomputer.com/news/security/hackers-can-hack-your-online-accounts-before-you-even-register-them/ 3、Mozilla 修复了在 Pwn2Own 上被利用的 Firefox零日漏洞 https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/ 4、Fronton僵尸网络被用于进行社交媒体虚假宣传活动 https://securityaffairs.co/wordpress/131574/cyber-warfare-2/fronton-botnet-disinformation.html 5、钓鱼邮件冒充沙特阿拉伯采购订单传播GuLoader https://www.fortinet.com/blog/threat-research/spoofed-saudi-purchase-order-drops-guloader 6、美国通用汽车公司遭到凭证填充攻击暴露车主信息 https://www.bleepingcomputer.com/news/security/gm-credential-stuffing-attack-exposed-car-owners-personal-info/ 7、马克·扎克伯格因数据泄露事件被起诉 https://www.securityweek.com/dc-sues-zuckerberg-over-cambridge-analytica-privacy-breach 8、Turla APT以奥地利、爱沙尼亚和北约平台为目标 https://www.bleepingcomputer.com/news/security/russian-hackers-perform-reconnaissance-against-austria-estonia/ 9、RansomHouse 集团设立勒索市场,新增了第一批受害者 https://www.bleepingcomputer.com/news/security/new-ransomhouse-group-sets-up-extortion-market-adds-first-victims/ 10、委内瑞拉总统称该国一大型水电站系统遭黑客攻击 http://www.cankaoxiaoxi.com/world/20220524/2480275.shtml
网络安全日报 2022年05月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、PayPal 中的一个漏洞可以让攻击者从用户的账户中窃取资金 https://securityaffairs.co/wordpress/131569/hacking/paypal-clickjacking-attack.html 2、Cytrox 的 Predator 间谍软件在 3 个活动中使用了零日漏洞 https://securityaffairs.co/wordpress/131561/hacking/predator-spyware-zero-day-exploits.html 3、面部识别公司 Clearview AI 被英国监管机构罚款 940 万美元 https://www.securityweek.com/facial-recognition-firm-clearview-ai-fined-94-million-uk-regulator 4、50 万芝加哥学生和教职员工数据泄露 https://www.securityweek.com/breach-exposed-data-half-million-chicago-students-staff 5、研究人员发现跨链协议Wormhole 漏洞,获得1000W美元奖金 https://portswigger.net/daily-swig/blockchain-bridge-wormhole-pays-record-10m-bug-bounty-reward 6、恶意PDF附件分发Snake Keylogger恶意软件 https://www.bleepingcomputer.com/news/security/pdf-smuggles-microsoft-word-doc-to-drop-snake-keylogger-malware/ 7、攻击者利用虚假PoC针对infoSec社区 https://blog.cyble.com/2022/05/20/malware-campaign-targets-infosec-community-threat-actor-uses-fake-proof-of-concept-to-deliver-cobalt-strike-beacon/ 8、格陵兰披露遭到网络攻击导致其卫生服务严重受限 https://therecord.media/greenland-cyberattack-healthcare-systems/ 9、微软发布带外更新修复微软商店应用程序问题 https://www.bleepingcomputer.com/news/microsoft/emergency-windows-10-updates-fix-microsoft-store-app-issues/ 10、2022年第一季度《App违规收集个人信息风险分析报告》发布 https://www.qianxin.com/threat/reportdetail?report_id=155
网络安全日报 2022年05月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国CFAA迎来重大修订,白帽黑客或将无责 https://www.freebuf.com/news/333764.html 2、Nikkei 披露了可能影响客户数据的勒索软件攻击 https://www.securityweek.com/nikkei-says-customer-data-likely-impacted-ransomware-attack 3、Lazarus APT 使用 Log4JShell 攻击 VMware 服务器 https://securityaffairs.co/wordpress/131483/apt/lazarus-apt-log4j-vmware-servers.html 4、思科修复了一个被积极利用的 IOS XR 漏洞 https://securityaffairs.co/wordpress/131516/security/cisco-ios-xr-flaw.html 5、Linux XorDdos bot 的活动在过去六个月中增加了 254% https://securityaffairs.co/wordpress/131478/hacking/linux-bornet-xorddos-254-surge.html 6、Conti 勒索软件团伙关闭了其运营 https://securityaffairs.co/wordpress/131464/cyber-crime/conti-ransomware-shut-down.html 7、印度Razorpay公司遭黑客入侵损失约7383万卢比 https://www.thehindu.com/news/national/hacker-steals-73-crore-from-payment-gateway-company-razorpay-in-bengaluru/article65426835.ece 8、Netgear修复锁定管理控制台的错误Orbi固件更新 https://www.bleepingcomputer.com/news/technology/netgear-fixes-bad-orbi-firmware-update-that-locked-admin-console/ 9、WordPress的School Management Pro插件中被发现存在后门 https://thehackernews.com/2022/05/researchers-find-backdoor-in-school.html 10、Swagger-UI库中漏洞可导致DOM XSS攻击 https://portswigger.net/daily-swig/widespread-swagger-ui-library-vulnerability-leads-to-dom-xss-attacks
网络安全日报 2022年05月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现针对 GitLab CI 管道的供应链攻击 https://www.securityweek.com/researchers-spot-supply-chain-attack-targeting-gitlab-ci-pipelines 2、Pwn2Own 2022:微软Teams 的漏洞利用获得了45万美元 https://www.securityweek.com/microsoft-teams-exploits-earn-hackers-450000-pwn2own-2022 3、Google 的Java OAuth 客户端库漏洞允许部署恶意负载 https://securityaffairs.co/wordpress/131459/security/google-oauth-client-library-flaw.html 4、一种新型的蓝牙中继攻击可以让攻击者远程解锁智能锁和汽车 https://thehackernews.com/2022/05/new-bluetooth-hack-could-let-attackers.html 5、Jupiter 和 JupiterX Core 插件提权漏洞影响9万多个WordPress站点 https://threatpost.com/vulnerability-wordpress-themes-site-takeover/179672/ 6、连锁药房Dis-Chem遭数据泄露,影响 360 万客户 https://www.infosecurity-magazine.com/news/pharmacy-giant-data-breach/ 7、CISA 分享安全指南以阻止正在进行的 F5 BIG-IP 攻击 https://www.bleepingcomputer.com/news/security/cisa-shares-guidance-to-block-ongoing-f5-big-ip-attacks/ 8、Kingminer 僵尸网络攻击 Microsoft SQL Server https://www.trendmicro.com/en_us/research/22/e/uncovering-a-kingminer-botnet-attack-using-trend-micro-managed-x.html 9、近 200 万德州人的个人信息被暴露了近三年 https://www.infosecurity-magazine.com/news/personal-information-two-million/ 10、勒索软件袭击美国医疗保健公司 Omnicell https://www.infosecurity-magazine.com/news/ransomware-healthcare-omnicell/
网络安全日报 2022年05月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、超过 380,000 台 Kubernetes API 暴露在互联网上 https://www.securityweek.com/over-380000-kubernetes-api-servers-exposed-internet-shadowserver 2、NVIDIA 修复了GPU驱动程序中的代码执行漏洞 https://www.securityweek.com/nvidia-patches-code-execution-vulnerabilities-graphics-driver 3、大规模攻击活动利用Tatsu Builder WordPress 插件漏洞 https://www.securityweek.com/large-scale-attack-targeting-tatsu-builder-wordpress-plugin 4、VMware 解决了多个产品中身份验证绕过漏洞 https://securityaffairs.co/wordpress/131429/security/vmware-critical-auth-bypass-issue.html 5、研究人员披露了"Wizard Spider"网络犯罪组织的运作流程 https://thehackernews.com/2022/05/researchers-expose-inner-working-of.html 6、微软警告针对加密钱包的“Cryware”信息窃取恶意软件 https://thehackernews.com/2022/05/microsoft-warns-of-cryware-info.html 7、新的 SYK Crypter 通过 Discord 传播 https://cyware.com/news/new-syk-crypter-propagates-via-discord-d5115d1e 8、2250 万马来西亚人的数据在暗网以 10,000 美元价格出售 https://www.straitstimes.com/asia/se-asia/data-of-225-million-malaysians-born-1940-2004-allegedly-being-sold-for-us10k 9、研究人员发现UpdateAgent macOS恶意软件新变种 https://www.jamf.com/blog/updateagent-adapts-again/ 10、Conti团伙声称将删除哥斯达黎加政府的解密密钥 https://thehackernews.com/2022/05/russian-conti-ransomware-gang-threatens.html