网络安全日报 2022年05月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、GitHub 宣布对代码贡献者强制执行 2FA https://www.securityweek.com/github-announces-mandatory-2fa-code-contributors 2、Android 2022 年 5 月安全补丁更新修复 36 漏洞 https://www.securityweek.com/androids-may-2022-security-updates-patch-36-vulnerabilities 3、美国政府发布关于量子计算风险的安全备忘录 https://www.securityweek.com/us-gov-issues-security-memo-quantum-computing-risks 4、研究人员发现两个影响 Avast 和 AVG杀软并存在数十年之久的严重漏洞 https://securityaffairs.co/wordpress/130944/security/avast-avg-antivirus-flaws.html 5、超过 1800 万个 IP 易受网络中间件 TCP 反射攻击 https://cyware.com/news/over-18-million-ips-found-vulnerable-to-middlebox-tcp-reflection-attacks-af0bdb10 6、谷歌将向 Android 和 Chrome 添加无密码身份验证支持 https://thehackernews.com/2022/05/google-to-add-passwordless.html 7、英国国家医疗服务体系遭大规模网络钓鱼攻击 https://www.inky.com/en/blog/fresh-phish-britains-national-health-service-infected-by-massive-phishing-campaign 8、思科针对影响企业NFVIS软件的漏洞发布补丁 https://thehackernews.com/2022/05/cisco-issues-patches-for-3-new-flaws.html 9、研究人员发现苹果芯片中存在Augury漏洞 https://www.techspot.com/news/94452-augury-vulnerability-discovered-apple-silicon-mobile-chips.html 10、F5发布补丁修复了严重的远程代码执行漏洞 https://thehackernews.com/2022/05/f5-warns-of-new-critical-big-ip-remote.html
网络安全日报 2022年05月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、F5 向 BIG-IP 客户通报 18 个严重漏洞 https://www.securityweek.com/f5-informs-big-ip-customers-about-18-serious-vulnerabilities 2、专家将多个勒索软件与朝鲜APT38 组织关联 https://securityaffairs.co/wordpress/130892/apt/ransomware-strains-linked-to-nk-apt38.html 3、研究人员发现可以通过 DLL 劫持阻止Conti等流行的勒索软件 https://securityaffairs.co/wordpress/130883/malware/stoppin-ransomware-with-dll-hijacking.html 4、uClibc 库的DNS组件存在漏洞影响数百万物联网产品 https://securityaffairs.co/wordpress/130865/security/dns-vulnerability.html 5、dotCMS 内容管理软件披露严重 RCE 漏洞 https://thehackernews.com/2022/05/critical-rce-bug-reported-in-dotcms.html 6、严重的 TLStorm 2.0 漏洞影响Aruba 和 Avaya 网络交换机 https://thehackernews.com/2022/05/critical-tlstorm-20-bugs-affect-widely.html 7、破解网站上的虚假Windows 10更新被用于分发Magniber勒索软件 https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/ 8、西班牙首相和国防部长的手机感染Pegasus https://therecord.media/spyware-attack-targeted-spanish-prime-ministers-phone/ 9、汽车租赁公司Sixt遭到网络攻击业务暂时中断 https://securityaffairs.co/wordpress/130820/security/sixt-suffered-cyber-attack.html 10、美国能源供应商Riviera Utilities泄露客户个人信息 https://portswigger.net/daily-swig/data-breach-at-us-energy-supplier-riviera-utilities-exposes-customer-information
网络安全日报 2022年04月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科修补了安全产品中的 11 个高危漏洞 https://www.securityweek.com/cisco-patches-11-high-severity-vulnerabilities-security-products 2、Wiz发现Azure PostgreSQL中跨账户数据库漏洞-ExtraReplica https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/ 3、CloudFlare 阻止了创纪录的 HTTPs DDoS 攻击,峰值为 1530 万RPS https://securityaffairs.co/wordpress/130685/hacking/cloudflare-record-https-ddos.html 4、多个网络犯罪组织使用新的恶意软件加载器:Bumblebee https://securityaffairs.co/wordpress/130699/cyber-crime/new-bumblebee-loader.html 5、Twitter 的新东家 Elon Musk 希望私聊能像 Signal 一样端到端加密 https://thehackernews.com/2022/04/twitters-new-owner-elon-musk-wants-dms.html 6、美国牙科支持服务提供商Smile Brands披露了数据泄露 https://www.infosecurity-magazine.com/news/smile-brands-breach-impacts-25m/ 7、谷歌4月27日起强制实施安卓APP隐私保护新政 https://thehackernews.com/2022/04/googles-new-safety-section-shows-what.html 8、纽约参议员提出新法案,将加密货币相关犯罪加入刑法 https://therecord.media/new-york-mulling-move-to-add-crypto-fraud-to-penal-code/ 9、欧洲漏洞赏金平台Intigriti推出按小时计费的漏洞众测新模式 https://www.secrss.com/articles/41852 10、Conti勒索软件仍然四处作案 https://securityaffairs.co/wordpress/130640/cyber-crime/conti-ransomware-operations-continues.html
网络安全日报 2022年04月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌发布Chrome 101 版本修复 30 个漏洞 https://www.securityweek.com/chrome-101-patches-30-vulnerabilities 2、微软披露了两个 Linux 权限提升漏洞,统称为 Nimbuspwn https://securityaffairs.co/wordpress/130662/hacking/nimbuspwn-linux-flaws.html 3、数以百万计的 Java 应用程序仍容易受到 Log4Shell 的攻击 https://threatpost.com/java-apps-vulnerable-log4shell/179397/ 4、Group-IB研究发现公开暴露的数据库实例数量再创新高 https://www.bleepingcomputer.com/news/security/number-of-publicly-exposed-database-instances-hits-new-record/ 5、多国网络安全机构联合揭示了 2021 年最常被利用的漏洞 https://www.bleepingcomputer.com/news/security/cybersecurity-agencies-reveal-top-exploited-vulnerabilities-of-2021/ 6、美国牙科协会遭受新的Black Basta勒索软件的攻击 https://www.bleepingcomputer.com/news/security/american-dental-association-hit-by-new-black-basta-ransomware/ 7、NPM漏洞允许攻击者将恶意软件作为合法软件包分发 https://thehackernews.com/2022/04/npm-bug-allowed-attackers-to-distribute.html 8、研究人员发现北美许多牵引车的制动控制器易受黑客攻击 https://www.securityweek.com/tractor-trailer-brake-controllers-vulnerable-remote-hacker-attacks 9、CISA在漏洞利用列表中增加了7个新漏洞 https://www.bleepingcomputer.com/news/security/cisa-adds-7-vulnerabilities-to-list-of-bugs-exploited-in-attacks/ 10、希腊教育平台 UniverSIS 存在SQL注入可篡改学生成绩 https://portswigger.net/daily-swig/student-grades-stored-in-greek-education-platform-universis-could-be-manipulated-via-sqli
网络安全日报 2022年04月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国悬赏 1000 万美元获取有关 NotPetya 网络攻击的情报 https://www.securityweek.com/us-offers-10-million-reward-russian-intelligence-officers-behind-notpetya-cyberattacks 2、Rocket Kitten APT组织利用最近修补的VMware 漏洞 https://securityaffairs.co/wordpress/130630/apt/iran-apt-exploiting-vmware-rce.html 3、Stormous 勒索软件声称已入侵了饮料公司可口可乐公司 https://securityaffairs.co/wordpress/130614/cyber-crime/stormous-ransomware-hit-coca-cola.html 4、The Intercept 披露美国监控公司Anomaly Six可实时跟踪30亿台设备 https://theintercept.com/2022/04/22/anomaly-six-phone-tracking-zignal-surveillance-cia-nsa/ 5、IBM 数据库DB2更新解决了第三方 XML 解析器中的关键漏洞 https://portswigger.net/daily-swig/ibm-database-updates-address-critical-vulnerabilities-in-third-party-xml-parser 6、在微软禁用宏之后,Emotet利用OneDrive URL和XLL文件进行感染 https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques 7、德国风力涡轮公司遭到"有针对性的专业网络攻击" https://www.securityweek.com/german-wind-turbine-firm-discloses-targeted-professional-cyberattack 8、研究人员披露了Prynt Stealer信息窃取恶意软件 https://www.bleepingcomputer.com/news/security/new-powerful-prynt-stealer-malware-sells-for-just-100-per-month/ 9、研究人员展示机器学习模型可植入无法检测到的后门 https://arxiv.org/abs/2204.06974v1 10、十年增长三倍!安全漏洞数量创纪录增长 https://www.secrss.com/articles/41635
网络安全日报 2022年04月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、BlackCat 勒索软件团伙在全球范围内入侵了 60 多个组织 https://securityaffairs.co/wordpress/130582/reports/fbi-blackcat-ransomware.html 2、研究人员披露了谷歌 VirusTotal 平台中的高危RCE 漏洞 https://thehackernews.com/2022/04/researchers-report-critical-rce.html 3、Everscale 钱包中的严重漏洞可能让攻击者窃取加密货币 https://thehackernews.com/2022/04/critical-bug-in-everscale-wallet.html 4、遭网络攻击后法国 GHT 医院集团被迫断开互联网连接 https://www.bleepingcomputer.com/news/security/french-hospital-group-disconnects-internet-after-hackers-steal-data/ 5、QNAP固件更新修复其 NAS 中的 Apache HTTP 漏洞 https://securityaffairs.co/wordpress/130481/hacking/qnap-nas-firmware-fix-apache-http-flaws.html 6、研究人员分析了Quantum勒索软件攻击的技术细节 https://www.bleepingcomputer.com/news/security/quantum-ransomware-seen-deployed-in-rapid-network-attacks/ 7、伊朗称挫败了针对其公共服务的大规模网络攻击 https://www.securityweek.com/state-tv-says-iran-foiled-cyberattacks-public-services 8、黑客将“More_Eggs”恶意软件植入招聘简历中 https://thehackernews.com/2022/04/hackers-sneak-moreeggs-malware-into.html 9、APT37使用新的恶意软件GOLDBACKDOOR针对记者 https://www.bleepingcomputer.com/news/security/north-korean-hackers-targeting-journalists-with-novel-malware/ 10、调查发现41% 的企业在过去一年中发生过 API 安全事件 https://www.helpnetsecurity.com/2022/04/25/apis-security-challenges/
网络安全日报 2022年04月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、网络攻击导致哥斯达黎加政府系统混乱 https://www.securityweek.com/cyberattack-causes-chaos-costa-rica-government-systems 2、对俄发起网络战以来,匿名者共泄露了 5.8 TB 的俄方数据 https://securityaffairs.co/wordpress/130554/hacktivism/anonymous-leaked-5-8-tb-russian-data.html 3、谷歌:2021年是0-day攻击创记录之年 https://www.infosecurity-magazine.com/news/google-record-year-for-zero-days/ 4、未打补丁的Exchange服务器遭Hive勒索攻击 逾期就公开数据 https://www.cnbeta.com/articles/tech/1261193.htm 5、FBI 警告针对美国农业的勒索软件攻击激增 https://www.infosecurity-magazine.com/news/fbi-warns-us-farmers-of-ransomware/ 6、美国国土安全部宣布Hack DHS的第一阶段发现了122个漏洞 https://therecord.media/first-phase-of-hack-dhs-finds-over-120-vulnerabilities/ 7、安全研究人员发现了最新的REvil泄密网站 https://www.theregister.com/2022/04/22/revil_ransomware_returns/ 8、美国能源部提供1200万美元资助6个大学团队开发网络攻击防御工具 https://www.bleepingcomputer.com/news/security/atlassian-fixes-critical-jira-authentication-bypass-vulnerability/ 9、Emotet恶意软件改造使用新的攻击载荷 https://cyware.com/news/emotet-revamp-new-payloads-and-64-bit-modules-8905bdd7 10、SuperCare Health 面临数据泄露起诉 https://www.infosecurity-magazine.com/news/supercare-health-faces-lawsuits/
网络安全日报 2022年04月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、T-Mobile 证实 Lapsus$ 获得了对其内部工具和源码的访问权限 https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html 2、Atlassian 发布漏洞补丁修复了高危Jira身份验证绕过漏洞 https://thehackernews.com/2022/04/atlassian-drops-patches-for-critical.html 3、研究人员发布了高危Java数字签名绕过漏洞PoC https://thehackernews.com/2022/04/researcher-releases-poc-for-recent-java.html 4、Conti 勒索软件声称对哥斯达黎加的勒索攻击负责 https://securityaffairs.co/wordpress/130505/cyber-crime/costa-rica-conti-ransomware.html 5、Lemon_Duck 挖矿僵尸网络以 Docker 服务器为目标 https://securityaffairs.co/wordpress/130470/cyber-crime/lemon_duck-cryptomining-botnet-targets-docker.html 6、多个严重漏洞影响 SmartPTT、SmartICS 工业产品 https://www.securityweek.com/several-critical-vulnerabilities-affect-smartppt-smartics-industrial-products 7、在被关闭一年多后Emotet恶意软件正在卷土重来 https://www.theregister.com/2022/04/21/emotet-resurgence-email/ 8、网络犯罪分子冒充政府供应商进行IRS税务诈骗 https://securityaffairs.co/wordpress/130451/cyber-crime/cybercriminals-deliver-irs-tax-scams-phishing.html 9、里约热内卢财政部门遭到LockBit勒索软件攻击 https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/ 10、Killnet黑客组织对捷克多个实体发起DDoS攻击 https://www.govinfosecurity.com/conti-ransomware-targets-costa-rican-government-entities-a-18939
网络安全日报 2022年04月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Pwn2Own Miami 2022 为参赛者提供了40万美元奖金 https://www.securityweek.com/ics-exploits-earn-hackers-400000-pwn2own-miami-2022 2、Drupal 修复了访问绕过、数据覆盖漏洞 https://www.securityweek.com/access-bypass-data-overwrite-vulnerabilities-patched-drupal 3、FBI 分享了有关 BlackCat 勒索软件的IOC信息 https://www.securityweek.com/fbi-shares-information-blackcat-ransomware-attacks 4、新的 BotenaGo 变种用 Mirai 感染 Lilin 摄像头 https://www.securityweek.com/new-botenago-variant-infects-lilin-security-cameras-mirai 5、思科修复了Cisco Umbrella 虚拟设备中的一个高危漏洞 https://securityaffairs.co/wordpress/130443/hacking/cisco-umbrella-default-ssh-key.html 6、高通和联发科芯片ALAC解码器严重RCE漏洞影响全球2/3的安卓设备 https://securityaffairs.co/wordpress/130459/hacking/critical-bug-popular-chipsets-android-hack.html 7、Lazarus APT 使用 TraderTraitor 恶意软件攻击加密货币公司 https://cyware.com/news/lazarus-apt-uses-tradertraitor-malware-to-target-cryptocurrency-organizations-b4c1eb47 8、加拿大航空公司Sunwing Airlines Inc遭到黑客攻击 https://www.infosecurity-magazine.com/news/cyberattackers-hit-sunwing-airlines/ 9、RainLoop邮件客户端的漏洞可以让黑客访问所有电子邮件 https://thehackernews.com/2022/04/unpatched-bug-in-rainloop-webmail-could.html 10、思科修补了 NSA 报告的虚拟会议软件漏洞 https://www.securityweek.com/cisco-patches-virtual-conference-software-vulnerability-reported-nsa
网络安全日报 2022年04月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、AWS 的 Log4Shell 热补丁被发现严重漏洞,可导致容器逃逸和提权 https://www.securityweek.com/serious-vulnerabilities-found-awss-log4shell-hot-patches 2、CISA警告最近修补的Windows Print Spooler 漏洞已被利用 https://www.securityweek.com/organizations-warned-attacks-exploiting-recently-patched-windows-vulnerability 3、Oracle 2022 年 4 月重要更新发布 520 个新安全补丁 https://www.securityweek.com/oracle-releases-520-new-security-patches-april-2022-cpu 4、Snort Modbus预处理器中被发现一个严重DoS漏洞(CVE-2022-20685) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-dos-9D3hJLuj 5、加密货币交易所Currency遭受分布式拒绝服务攻击 https://www.govinfosecurity.com/crypto-firm-currencycom-mitigates-ddos-attack-a-18922 6、Okta表示Lapsus$的入侵行为仅影响了两名客户 https://www.zdnet.com/article/okta-says-lapsus-breach-hit-just-two-customers/ 7、研究人员:英政府内部网络曾遭“飞马”间谍软件攻击 https://www.cnbeta.com/articles/tech/1259993.htm 8、7-Zip被爆0day漏洞:可用于本地提权和执行代码 https://www.cnbeta.com/articles/tech/1259869.htm 9、恶意信息窃取软件Inno Stealer通过虚假Windows 11升级网站进行传播 https://cyware.com/news/inno-stealer-fake-windows-11-upgrade-spreads-infostealer-74a72e5d 10、QNAP 敦促客户禁用路由器上的 UPnP 端口转发 https://www.bleepingcomputer.com/news/security/qnap-urges-customers-to-disable-upnp-port-forwarding-on-routers/