网络安全日报 2022年05月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、公安部公布五类高发电信网络诈骗类型,"刷单"占榜首 http://www.gov.cn/xinwen/2022-05/11/content_5689723.htm 2、Play Store 上的 200 多个应用正在分发 Facestealer信息窃取器 https://securityaffairs.co/wordpress/131370/malware/facestealer-info-stealer-play-store.html 3、卡巴斯基研究发现2022 年 HTML 附件在网络钓鱼攻击中仍然很流行 https://www.bleepingcomputer.com/news/security/html-attachments-remain-popular-among-phishing-actors-in-2022/ 4、委内瑞拉心脏病专家被指控经营和销售Thanos勒索软件 https://securityaffairs.co/wordpress/131382/cyber-crime/venezuelan-man-accused-thanos-ransomware.html 5、链家IT管理员删除公司9TB数据,被判7年有期徒刑 https://www.freebuf.com/news/333221.html 6、英国政府制定了《2022年民用核网络安全战略》 https://www.infosecurity-magazine.com/news/uk-sets-out-nuclear-cybersecurity/ 7、虚假移动应用窃取Facebook凭据和加密货币密钥 https://www.trendmicro.com/en_us/research/22/e/fake-mobile-apps-steal-facebook-credentials--crypto-related-keys.html 8、利用已修复的微软SharePoint漏洞可发起RCE攻击 https://portswigger.net/daily-swig/sharepoint-rce-bug-resurfaces-three-months-after-being-patched-by-microsoft 9、自定义PowerShell RAT以乌克兰信息为诱饵针对德国 https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/ 10、NSA 表示美国新加密标准没有后门 https://www.solidot.org/story?sid=71525
网络安全日报 2022年05月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现新型BLE蓝牙中继攻击 https://www.securityweek.com/researchers-devise-new-type-bluetooth-le-relay-attacks 2、勒索软件团伙威胁要推翻哥斯达黎加政府 https://www.securityweek.com/ransomware-gang-threatens-overthrow-costa-rica-government 3、研究人员发现可以利用低功耗模式在关机的iPhone上运行恶意软件 https://www.securityweek.com/hackers-can-abuse-low-power-mode-run-malware-powered-iphones 4、Apple发布更新修复了自 2022 年初以来的第六个0day漏洞 https://securityaffairs.co/wordpress/131346/security/apple-sixth-zero-day-2022.html 5、Armageddon APT组织发起新的网络钓鱼攻击 https://securityaffairs.co/wordpress/131296/breaking-news/cert-ua-warns-armageddon-apt.html 6、虚假Pixelmon NFT网站分发密码窃取恶意软件 https://www.bleepingcomputer.com/news/security/fake-pixelmon-nft-site-infects-you-with-password-stealing-malware/ 7、欧洲宣布采用旨在加强网络安全的新NIS2指令 https://thehackernews.com/2022/05/europe-agrees-to-adopt-new-nis2.html 8、研究人员通过DLL劫持漏洞阻止REvil勒索软件 https://portswigger.net/daily-swig/researcher-stops-revil-ransomware-in-its-tracks-with-dll-hijacking-exploit 9、小伙浏览涉黄APP,5天被骗142万! https://www.anquanke.com/post/id/273098 10、BPFdoor:隐形 Linux 恶意软件绕过防火墙进行远程访问 https://www.bleepingcomputer.com/news/security/bpfdoor-stealthy-linux-malware-bypasses-firewalls-for-remote-access/
网络安全日报 2022年05月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Sysrv 僵尸网络新变种Sysrv-K利用Spring和WordPress漏洞 https://securityaffairs.co/wordpress/131290/cyber-crime/microsoft-sysrv-botnet-new-exploits.html 2、SonicWall 敦促客户修复 SMA 1000 产品中的高危漏洞 https://securityaffairs.co/wordpress/131247/security/sonicwall-urges-customers-to-fix-sma-1000-vulnerabilities.html 3、Zyxel 防火墙修复了一个严重RCE漏洞 https://securityaffairs.co/wordpress/131243/hacking/zyxel-critical-flaw.html 4、伊朗黑客利用 BitLocker 和 DiskCryptor 进行勒索软件攻击 https://thehackernews.com/2022/05/iranian-hackers-leveraging-bitlocker.html 5、西门子楼宇自动化控制器存在漏洞可被黑客攻击 https://www.securityweek.com/hackers-can-make-siemens-building-automation-controllers-unavailable-days 6、InHand Networks 工业路由器存在多个高危漏洞 https://www.securityweek.com/critical-vulnerabilities-provide-root-access-inhand-industrial-routers 7、研究人员披露为期数月的针对 14 家德国汽车制造商的恶意软件活动 https://cyware.com/news/malware-campaign-targets-at-least-14-german-automakers-db0e9ea1 8、RedLine Stealer新活动通过YouTube传播 https://www.netskope.com/blog/redline-stealer-campaign-using-binance-mystery-box-videos-to-spread-github-hosted-payload 9、Legion黑客组织对欧洲歌唱大赛官网发起攻击 https://securityaffairs.co/wordpress/131280/hacktivism/legion-collective-call-attack-eurovision.html 10、谷歌发布更新修复Chrome中的高严重性漏洞 https://www.securityweek.com/chrome-101-update-patches-high-severity-vulnerabilities
网络安全日报 2022年05月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Sysrv 僵尸网络新变种Sysrv-K利用Spring和WordPress漏洞 https://securityaffairs.co/wordpress/131290/cyber-crime/microsoft-sysrv-botnet-new-exploits.html 2、SonicWall 敦促客户修复 SMA 1000 产品中的高危漏洞 https://securityaffairs.co/wordpress/131247/security/sonicwall-urges-customers-to-fix-sma-1000-vulnerabilities.html 3、Zyxel 防火墙修复了一个严重RCE漏洞 https://securityaffairs.co/wordpress/131243/hacking/zyxel-critical-flaw.html 4、伊朗黑客利用 BitLocker 和 DiskCryptor 进行勒索软件攻击 https://thehackernews.com/2022/05/iranian-hackers-leveraging-bitlocker.html 5、西门子楼宇自动化控制器存在漏洞可被黑客攻击 https://www.securityweek.com/hackers-can-make-siemens-building-automation-controllers-unavailable-days 6、InHand Networks 工业路由器存在多个高危漏洞 https://www.securityweek.com/critical-vulnerabilities-provide-root-access-inhand-industrial-routers 7、研究人员披露为期数月的针对 14 家德国汽车制造商的恶意软件活动 https://cyware.com/news/malware-campaign-targets-at-least-14-german-automakers-db0e9ea1 8、RedLine Stealer新活动通过YouTube传播 https://www.netskope.com/blog/redline-stealer-campaign-using-binance-mystery-box-videos-to-spread-github-hosted-payload 9、Legion黑客组织对欧洲歌唱大赛官网发起攻击 https://securityaffairs.co/wordpress/131280/hacktivism/legion-collective-call-attack-eurovision.html 10、谷歌发布更新修复Chrome中的高严重性漏洞 https://www.securityweek.com/chrome-101-update-patches-high-severity-vulnerabilities
网络安全日报 2022年05月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的 Nerbian RAT 通过使用 COVID-19 钓鱼邮件活动传播 https://securityaffairs.co/wordpress/131221/cyber-crime/nerbian-rat-uses-covid-19-lure.html 2、大规模黑客活动破坏了数千个 WordPress 网站 https://securityaffairs.co/wordpress/131202/hacking/wordpress-websites-hacking-campaign.html 3、Red TIM Research (RTR) 披露 2 个影响 F5 Traffix SDC 的漏洞 https://securityaffairs.co/wordpress/131196/hacking/f5-traffix-sdc-flaws.html 4、英特尔内存漏洞对数百种产品构成风险 https://threatpost.com/intel-memory-bug-poses-risk-for-hundreds-of-products/179595/ 5、惠普修补了影响 200 多种型号计算机的 UEFI 漏洞 https://www.securityweek.com/hp-patches-uefi-vulnerabilities-affecting-over-200-computers 6、Malware Builder 利用 Discord Webhook https://threatpost.com/malware-discord-webhooks/179605/ 7、英特尔修补了 BIOS、Boot Guard 中的高危漏洞 https://www.securityweek.com/intel-patches-high-severity-vulnerabilities-bios-boot-guard 8、数十万台柯尼卡打印机容易受到物理访问的黑客攻击 https://www.securityweek.com/konica-minolta-printers-vulnerable-hacking-physical-access 9、APT34使用新的Saitama后门针对约旦政府 https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/ 10、多家意大利机构的网站遭到Killnet黑客组织攻击 https://www.reuters.com/world/europe/pro-russian-hackers-target-italy-defence-ministry-senate-websites-ansa-news-2022-05-11/
网络安全日报 2022年05月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Chrome 101 更新补丁修复高危漏洞 https://www.securityweek.com/chrome-101-update-patches-high-severity-vulnerabilities 2、多个SaaS 应用程序的短URL 可被用于网络钓鱼和社会工程 https://www.securityweek.com/saas-app-vanity-urls-can-be-spoofed-phishing-social-engineering 3、医疗保健技术提供商 Omnicell 遭勒索软件攻击 https://www.securityweek.com/healthcare-technology-provider-omnicell-discloses-ransomware-attack 4、研究人员警告 Nerbian RAT 针对意大利、西班牙和英国的实体 https://thehackernews.com/2022/05/researchers-warn-of-nerbian-rat.html 5、林肯学院遭勒索软件攻击而停课 https://threatpost.com/ransomware-deathblow-college/179574/ 6、FluBot Android 恶意软件以芬兰用户为目标 https://www.bleepingcomputer.com/news/security/flubot-android-malware-targets-finland-in-new-sms-campaigns/ 7、研究人员发现一种新的网络钓鱼即服务Frappo https://securityaffairs.co/wordpress/131136/cyber-crime/frappo-phishing-as-a-service.html 8、新的恶意NPM包针对德国公司进行供应链攻击 https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/ 9、2100万VPN用户的个人信息在Telegram上泄露 https://www.hackread.com/personal-details-supervpn-geckovpn-users-telegram-leaked/ 10、微软修复了所有Windows版本中的新NTLM零日漏洞 https://www.freebuf.com/articles/332788.html
网络安全日报 2022年05月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、周二补丁日:微软警告新的零日漏洞被利用 https://www.securityweek.com/patch-tuesday-microsoft-warns-new-zero-day-being-exploited 2、新的恶意软件样本表明 REvil 勒索软件卷土重来 https://www.securityweek.com/new-malware-samples-indicate-return-revil-ransomware 3、Adobe发布安全补丁修复产品中18个严重漏洞 https://www.securityweek.com/adobe-warns-critical-security-flaws-enterprise-products 4、微软修复了 Azure Synapse 和Data Factory中的 RCE 漏洞 https://securityaffairs.co/wordpress/131159/hacking/azure-synapse-rce.html 5、F5 BIG-IP 中的 CVE-2022-1388 RCE漏洞正在被大规模利用 https://securityaffairs.co/wordpress/131132/hacking/big-ip-cve-2022-1388-exploitation.html 6、美国伊利诺伊州林肯学院遭勒索软件攻击被迫关闭 https://www.nbcnews.com/tech/security/ransomware-attack-covid-combine-shutter-illinois-college-rcna24905 7、感染Joker木马的应用程序通过谷歌Play商店传播 https://thehackernews.com/2022/05/another-set-of-joker-trojan-laced.html 8、行车记录全暴露,高合汽车陷隐私泄露风波 https://www.secrss.com/articles/42165 9、马斯克收购 Twitter 可能面临美国的国家安全调查 https://arstechnica.com/tech-policy/2022/05/musks-foreign-investors-may-trigger-national-security-review-of-twitter-deal/ 10、法拉利子域被劫持以推送伪造的法拉利 NFT收藏 https://www.bleepingcomputer.com/news/security/ferrari-subdomain-hijacked-to-push-fake-ferrari-nft-collection/
网络安全日报 2022年05月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、DarkCrystal RAT 远控木马在黑客论坛便宜出售 https://thehackernews.com/2022/05/experts-sound-alarm-on-dcrat-backdoor.html 2、RubyGems 修复了关键的 Gem 接管漏洞 https://www.securityweek.com/rubygems-fixes-critical-gem-takeover-vulnerability 3、研究人员针对F5 BIG-IP 最新RCE漏洞开发了Exploit https://securityaffairs.co/wordpress/131102/hacking/f5-big-ip-exploit-code.html 4、哥斯达黎加遭勒索软件攻击后全国进入紧急状态 https://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/ 5、匿名者附属组织NB65入侵俄罗斯支付服务Qiwi https://www.hackread.com/anonymous-nb65-hacki-russia-payment-processor-qiwi/ 6、QNAP修复了关键的QVR远程命令执行漏洞 http://www.hackdig.com/05/hack-655230.htm 7、证监会发布《证券期货业网络安全管理办法(征求意见稿)》 https://www.freebuf.com/news/332207.html 8、DeFi 平台 MM.Finance 被盗超过 200 万美元加密货币 https://therecord.media/more-than-2-million-stolen-from-defi-platform-mm-finance/ 9、Emotet 正在测试新的攻击链 https://cyware.com/news/emotet-is-testing-new-attack-chain-25595957 10、新NetDooka恶意软件通过有毒的搜索结果传播 https://www.bleepingcomputer.com/news/security/new-netdooka-malware-spreads-via-poisoned-search-results/
网络安全日报 2022年05月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Conti 勒索软件声称入侵了秘鲁 MOF 情报总局 (DIGIMIN) https://securityaffairs.co/wordpress/131093/cyber-crime/conti-ransomware-peru-direccion-general-de-inteligencia.html2、美国农业机械制造商AGCO遭遇勒索软件攻击 https://securityaffairs.co/wordpress/131058/cyber-crime/agco-suffered-ransomware-attack.html3、研究人员发现首个将 shellcode 隐藏在 Windows 事件中的恶意活动 https://securityaffairs.co/wordpress/131025/hacking/windows-event-logs-malware-campaign.html4、美国悬赏 1500 万美元获取有关 Conti 勒索团伙的信息 https://securityaffairs.co/wordpress/131050/cyber-crime/us-dos-reward-15m-info-conti-ransomware.html5、攻击者劫持法拉利子域以推送虚假的NFT作品 https://www.bleepingcomputer.com/news/security/ferrari-subdomain-hijacked-to-push-fake-ferrari-nft-collection/6、网络钓鱼导致美国国防部损失2300万美元 https://www.bleepingcomputer.com/news/security/us-dod-tricked-into-paying-235-million-to-phishing-actor/7、dotCMS内容管理系统中存在严重的RCE漏洞 https://thehackernews.com/2022/05/critical-rce-bug-reported-in-dotcms.html8、宜家加拿大公司发现数据泄露影响9.5万名客户 https://www.infosecurity-magazine.com/news/data-breach-ikea-canada/9、趋势科技防病毒软件误将Edge更新标记为恶意软件 https://www.bleepingcomputer.com/news/security/trend-micro-antivirus-modified-windows-registry-by-mistake-how-to-fix/10、Xbox在全球范围内服务中断导致用户无法玩游戏 https://www.bleepingcomputer.com/news/technology/xbox-is-down-worldwide-with-users-unable-to-play-games/
网络安全日报 2022年05月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员警告“Raspberry Robin”恶意软件通过USB设备传播 https://thehackernews.com/2022/05/researchers-warn-of-raspberry-robin.html 2、QNAP 修复多个漏洞,包括 QVR RCE 漏洞 https://securityaffairs.co/wordpress/131000/security/qnap-fixes-critical-flaws.html 3、NetDooka恶意软件通过PrivateLoader PPI服务分发 https://thehackernews.com/2022/05/hackers-using-privateloader-ppi-service.html 4、欧洲刑警组织:Deepfakes对网络安全和社会的威胁越来越大 https://www.secrss.com/articles/42015 5、攻击者劫持英国国家卫生系统电子邮件帐户,以窃取微软登录信息 https://securityaffairs.co/wordpress/130865/security/dns-vulnerability.html 6、Heroku 在 OAuth 令牌被盗后承认客户数据库被黑客入侵 https://www.bleepingcomputer.com/news/security/heroku-admits-to-customer-database-hack-after-oauth-token-theft/ 7、NIST 发布修订后的供应链风险管理网络安全指南 https://www.nist.gov/news-events/news/2022/05/nist-updates-cybersecurity-guidance-supply-chain-risk-management 8、攻击者向Pixiv和DeviantArt平台用户传播恶意软件 https://www.bleepingcomputer.com/news/security/pixiv-deviantart-artists-hit-by-nft-job-offers-pushing-malware/ 9、美国佐治亚州律师协会遭到网络攻击网站关闭 https://portswigger.net/daily-swig/state-bar-of-georgia-reels-from-cyber-attack 10、澳大利亚新南威尔士州交通局披露遭到网络攻击 https://www.zdnet.com/article/transport-for-nsw-struck-by-cyber-attack/