网络安全日报 2022年04月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、联想发布补丁修复影响 110 多种型号笔记本电脑的 UEFI 固件严重漏洞 https://www.securityweek.com/firmware-flaws-allow-disabling-secure-boot-lenovo-laptops 2、卡巴斯基发布针对Yanluowang勒索软件的免费解密器 https://securityaffairs.co/wordpress/130369/malware/yanluowang-ransomware-free-decryptor.html 3、Pegasus 间谍软件在最近的攻击中利用了新的零点击 iPhone 漏洞 https://securityaffairs.co/wordpress/130360/malware/nso-group-pegasus-click-iphone-exploit.html 4、英国:2021-2022 年,超过 4200 万人的财务数据遭到泄露 https://www.techrepublic.com/article/over-42-million-people-in-the-uk-had-financial-data-compromised 5、专家发现一个出售被盗数据的新市场Industrial Spy https://securityaffairs.co/wordpress/130323/cyber-crime/industrial-spy-marketplace.html 6、领英成为网络钓鱼攻击中被模仿得最多的品牌 https://www.infosecurity-magazine.com/news/linkedin-impersonated-brand/ 7、SolarMarker恶意软件新变种使用新的技术逃避检测 https://thehackernews.com/2022/04/new-solarmarker-malware-variant-using.html 8、GitHub封锁了两家大型俄罗斯银行的账户 https://www.hackread.com/github-blocks-large-russian-banks-accounts-us-sanctions/ 9、金融科技平台中的SSRF漏洞或导致银行账户信息泄露 https://threatpost.com/ssrf-flaw-fintech-bank-accounts/179247/ 10、索尼、尼康、Adobe和英特尔等公司成立C2PA联盟对抗"深度伪造" https://www.cnbeta.com/articles/tech/1259571.htm
网络安全日报 2022年04月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Juniper修复了多个Contrail 和 Junos OS 中的严重漏洞 https://www.securityweek.com/juniper-networks-patches-vulnerabilities-contrail-networking-junos-os 2、Lazarus Group 针对韩国的化工行业 https://cyware.com/news/lazarus-eyes-chemical-sector-in-south-korea-f26c757a 3、Nozomi Networks Labs 研究人员发现新的 BotenaGo 变种 https://securityboulevard.com/2022/04/new-botenago-variant-discovered-by-nozomi-networks-labs 4、Lakeview Loan Service 遭数据泄露,影响 250 万用户 https://www.nationalmortgagenews.com/news/mortgage-servicer-reveals-data-breach-affecting-2-5-million-users 5、研究人员分享了对PYSA勒索软件组织的深入分析 https://thehackernews.com/2022/04/researchers-share-in-depth-analysis-of.html 6、Beanstalk Farms遭受网络攻击损失了1.8亿美元 https://cryptopotato.com/beanstalk-farms-lost-180m-in-flash-loan-attack-hacker-donates-250k-usdc-to-ukraine 7、 2022 年初以来,谷歌修复了Chrome 中的第三个0day漏洞 https://securityaffairs.co/wordpress/130213/security/google-chrome-zeroday-cve-2022-1364.html 8、PrivateBin修复了其XSS漏洞 https://portswigger.net/daily-swig/xss-vulnerability-in-open-source-tool-privatebin-patched 9、ZLoader C2 服务器在全球运营中中断 https://cyware.com/news/zloader-c2-servers-disrupted-in-global-operation-8763d42f 10、Windows RPC CVE-2022-26809 漏洞引起了安全研究人员的关注 https://www.bleepingcomputer.com/news/microsoft/critical-windows-rpc-cve-2022-26809-flaw-raises-concerns-patch-now/
网络安全日报 2022年04月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、GitHub 称黑客使用被盗的 OAuth 访问令牌入侵了数十个组织 https://thehackernews.com/2022/04/github-says-hackers-breach-dozens-of.html 2、Conti Ransomware Gang 声称对 Nordex 黑客事件负责 https://securityaffairs.co/wordpress/130238/cyber-crime/conti-ransomware-claims-nordex-attack.html 3、Haskers Gang 将 ZingoStealer 恶意软件免费分享给同行 https://thehackernews.com/2022/04/haskers-gang-gives-away-zingostealer.html 4、新的"Enemybot"DDoS 僵尸网络以路由器、Web 服务器为目标 https://www.securityweek.com/new-enemybot-ddos-botnet-targets-routers-web-servers 5、研究人员发现NFT市场Rarible漏洞可导致用户NFT被盗 https://therecord.media/researchers-find-vulnerability-in-rarible-nft-platform/ 6、Conti勒索软件和Karakurt数据勒索组织存在联系 https://www.bleepingcomputer.com/news/security/karakurt-revealed-as-data-extortion-arm-of-conti-cybercrime-syndicate/ 7、VMWare修复了其Cloud Director产品中一个高危漏洞 https://www.securityweek.com/critical-code-execution-flaw-haunts-vmware-cloud-director 8、网络钓鱼活动利用SMS向T-Mobile客户发送恶意链接 https://www.bleepingcomputer.com/news/security/t-mobile-customers-warned-of-unblockable-sms-phishing-attacks/ 9、西班牙皇家足球协会的电子邮件帐户和文件被盗 https://www.espn.in/football/spain-esp/story/4642921/spanish-fa-report-cyber-attack-to-police-after-email-accounts-private-texts-stolen 10、研究表明多个会议应用在用户按下禁麦按钮后仍然在监听 https://www.bleepingcomputer.com/news/security/mute-button-in-conferencing-apps-may-not-actually-mute-your-mic/
网络安全日报 2022年04月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Elementor 插件的严重漏洞影响数百万 WordPress 网站 https://www.securityweek.com/critical-vulnerability-elementor-plugin-impacts-millions-wordpress-sites2、思科修补了WLAN 控制器中的严重漏洞 https://www.securityweek.com/cisco-patches-critical-vulnerability-wireless-lan-controller3、微软已采取法律和技术措施拆除 Zloader 僵尸网络 https://securityaffairs.co/wordpress/130181/malware/microsoft-disrupts-zloader-malware-infrastructure.html4、基于恶意软件的网络钓鱼活动以非洲银行业为目标 https://portswigger.net/daily-swig/african-banking-sector-targeted-by-malware-based-phishing-campaign5、美政府表示6亿美金Ronin Validator盗窃案与Lazarus Group有关 https://www.securityweek.com/us-gov-blames-north-korea-hackers-600m-cryptocurrency-heist6、Lazarus 瞄准化工行业 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lazarus-dream-job-chemical7、研究人员发现针对韩国人的类似于“Kitty 网络钓鱼行动”的活动 https://cyware.com/news/campaign-similar-to-operation-kitty-phishing-found-targeting-south-koreans-95e317d78、新的 EnemyBot DDoS 僵尸网络借用 Mirai 和 Gafgyt 的漏洞利用代码 https://thehackernews.com/2022/04/new-enemybot-ddos-botnet-borrows.html9、关键的 VMware Workspace ONE漏洞被广泛利用 https://securityaffairs.co/wordpress/130188/hacking/vmware-workspace-one-access-flaw-attacks.html10、以色列监控软件被用来监视欧盟官员 https://securityaffairs.co/wordpress/130139/malware/eu-officials-surveillance-software.html
网络安全日报 2022年04月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMWare 确认 Workspace One 漏洞正在被广泛利用 https://www.securityweek.com/vmware-confirms-workspace-one-exploits-wild2、ABB 网络接口模块的缺陷可导致工业系统面临 DoS 攻击 https://www.securityweek.com/flaws-abb-network-interface-modules-expose-industrial-systems-dos-attacks3、Citrix 修补了多个产品中的漏洞 https://www.securityweek.com/citrix-patches-vulnerabilities-several-products4、Apache 解决了Struts 的一个严重RCE漏洞(CVE-2021-31805) https://securityaffairs.co/wordpress/130173/security/critical-apache-struts-rce-flaw.html5、 研究人员发现影响医院使用的Aethon TUG 自主移动机器人5个漏洞 https://securityaffairs.co/wordpress/130157/security/jekyllbot5-flaws-tug-autonomous-mobile-robots.html6、LockBit勒索软件潜伏在美国政府网络中数月 https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-lurked-in-a-us-gov-network-for-months/7、Keksec Hacker Group 部署的新 Enemybot DDoS 僵尸网络 https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet8、西门子、施耐德修复了多个关键漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-fix-several-critical-vulnerabilities9、严重的 HP Teradici PCoIP 漏洞影响 1500 万个终端 https://www.bleepingcomputer.com/news/security/critical-hp-teradici-pcoip-flaws-impact-15-million-endpoints10、Industroyer2 恶意软件针对乌克兰能源部门 https://cyware.com/news/industroyer2-found-targeting-energy-sector-in-ukraine-20a5aff4
网络安全日报 2022年04月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二补丁日修复了 128 个 Windows 漏洞,包括一个0day漏洞 https://www.securityweek.com/microsoft-patches-128-windows-flaws-new-zero-day-reported-nsa 2、TOURNIQUET 行动,暗网市场 RaidForums 被关闭 https://securityaffairs.co/wordpress/130131/deep-web/authorities-shut-down-raidforums.html 3、NGINX 项目维护者修复了 LDAP 认证模块中的0day漏洞 https://securityaffairs.co/wordpress/130117/hacking/nginx-ldap-reference-implementation-bug.html 4、Hashnode 博客平台报告的严重 LFI 漏洞 https://thehackernews.com/2022/04/critical-lfi-vulnerability-reported-in.html 5、松下的加拿大业务遭受勒索软件攻击 https://techcrunch.com/2022/04/11/panasonic-canada-ransomware/ 6、Chrome 100 更新补丁修复高危漏洞 https://www.securityweek.com/chrome-100-update-patches-high-severity-vulnerabilities 7、恶意Web重定向服务感染16500个站点以分发恶意软件 https://thehackernews.com/2022/04/over-16500-sites-hacked-to-distribute.html 8、Android银行木马Fakecalls可拦截客户对银行的呼叫 https://www.bleepingcomputer.com/news/security/android-banking-malware-intercepts-calls-to-customer-support/ 9、AWS RDS的本地文件读取漏洞导致内部AWS服务凭证泄露 https://securityboulevard.com/2022/04/aws-rds-vulnerability-leads-to-aws-internal-service-credentials/ 10、恶意软件Qbot启用新的Windows安装程序感染载体 https://www.bleepingcomputer.com/news/security/qbot-malware-switches-to-new-windows-installer-infection-vector/
网络安全日报 2022年04月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、匿名者入侵俄文化部并泄露 446 GB数据 https://securityaffairs.co/wordpress/130106/hacktivism/anonymous-hacked-russia-ministry-of-culture.html 2、SuperCare Health 披露影响超过 30 万人的数据泄露事件 https://securityaffairs.co/wordpress/130089/data-breach/supercare-health-data-breach.html 3、Microsoft 的新 Autopatch 功能可帮助企业保持系统最新 https://thehackernews.com/2022/04/microsofts-new-autopatch-feature-to.html 4、Directus数据引擎平台修复XSS漏洞 https://www.zdnet.com/article/xss-vulnerability-patched-in-directus-data-engine-platform 5、OpenSSH 9采用新的密钥交换方法以抵御量子计算机攻击 https://www.zdnet.com/article/openssh-now-defaults-to-protecting-against-quantum-computer-attacks/ 6、全球供应链攻击在2021年下半年激增51% https://www.infosecurity-magazine.com/news/global-supply-chain-attacks-surge/ 7、全球76%的公司在过去一年中曾遭遇因技术问题导致的业务中断 https://www.cnbeta.com/articles/tech/1255705.htm 8、FIN7 黑客组织成员被判处5年有期徒刑 https://www.bleepingcomputer.com/news/security/fin7-hacking-group-pen-tester-sentenced-to-5-years-in-prison/ 9、英特尔关闭了在俄的所有业务运营 https://www.bleepingcomputer.com/news/technology/intel-shuts-down-all-business-operations-in-russia/ 10、爱尔兰银行因数据泄露被罚款46.3万欧元 https://www.infosecurity-magazine.com/news/bank-of-ireland-fined-463000-over/
网络安全日报 2022年04月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Mirai 僵尸网络利用 Spring4Shell 漏洞 https://www.securityweek.com/spring4shell-vulnerability-exploited-mirai-botnet 2、谷歌更新针对 Android 应用程序的目标 API 级别要求 https://www.securityweek.com/google-updates-target-api-level-requirements-android-apps 3、大规模的 DDoS 攻击导致芬兰政府网站瘫痪 https://securityaffairs.co/wordpress/130032/hacking/ddos-took-down-finnish-govt-sites.html 4、研究人员发现 AutoDesk 产品中的多个漏洞 https://www.fortinet.com/blog/threat-research/fortinet-security-researchers-discover-multiple-vulnerabilities-in-autodesk-products-dwg-trueview-navisworks-and-design-review 5、新的Octo银行木马通过Google Play上的假应用程序传播 https://thehackernews.com/2022/04/new-octo-banking-trojan-spreading-via.html 6、俄石油巨头Gazprom Neft的网站因网络攻击而关闭 https://www.infosecurity-magazine.com/news/russian-oil-gazprom-neft-hack/ 7、研究人员发现影响苹果Web应用程序的HTTP请求走私漏洞 https://portswigger.net/daily-swig/apple-paid-out-36-000-bug-bounty-for-http-request-smuggling-flaws-on-core-web-apps-research 8、研究人员发现BlackCat勒索软件与BlackMatter存在关联 https://thehackernews.com/2022/04/researchers-connect-blackcat-ransomware.html 9、树莓派的更新删除了默认用户以阻止暴力攻击 https://www.bleepingcomputer.com/news/security/raspberry-pi-removes-default-user-to-hinder-brute-force-attacks/ 10、北爱尔兰TrustFord网站遭到Conti勒索软件攻击 https://www.infosecurity-magazine.com/news/northern-ireland-trustford/
网络安全日报 2022年04月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌与 GitHub 合作推进供应链安全 https://www.securityweek.com/google-teams-github-supply-chain-security 2、微软将本地部署的Exchange/SharePoint/Skype添加到漏洞赏金计划 https://www.securityweek.com/microsoft-adds-premises-exchange-sharepoint-skype-bug-bounty-program 3、BlackCat 勒索软件针对工业组织 https://www.securityweek.com/blackcat-ransomware-targets-industrial-companies 4、CVE-2022-22292 漏洞可能允许三星 Android 设备被入侵 https://securityaffairs.co/wordpress/129942/hacking/cve-2022-22292-hack-samsung-android-devices.html 5、OpenSSL 漏洞(CVE-2022-0778)影响多个 Palo Alto 设备 https://securityaffairs.co/wordpress/129935/hacking/palo-alto-networks-devices-openssl-flaws.html 6、VMware 针对影响多个产品的新漏洞发布了重要补丁 https://thehackernews.com/2022/04/vmware-releases-critical-patches-for.html 7、福克斯新闻泄露了 1300 万条内部记录,包括员工信息 https://www.infosecurity-magazine.com/news/employee-info-13-million-records/ 8、FFDroider恶意软件窃取Facebook、Twitter等多个社交应用的帐户 https://www.bleepingcomputer.com/news/security/new-ffdroider-malware-steals-facebook-instagram-twitter-accounts/ 9、黑客利用恶意应用程序攻击马来西亚8家银行的客户 https://therecord.media/hackers-use-malicious-apps-to-target-customers-of-8-malaysian-banks-researchers-say/ 10、Apple 仅针对 macOS Monterey 修补了关键的0day漏洞 https://www.theregister.com/2022/04/06/apple_patched_zerodays_in_macos/
网络安全日报 2022年04月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现首个专门针对 AWS Lambda 的恶意软件-Denonia https://www.securityweek.com/denonia-first-malware-targeting-aws-lambda 2、FBI拆除了Sandworm APT运营的 Cyclops Blink 僵尸网络 https://securityaffairs.co/wordpress/129911/cyber-warfare-2/us-disrupts-cyclops-blink-botnet.html 3、Block披露涉及Cash App的数据泄露可能影响820万美国客户 https://securityaffairs.co/wordpress/129892/data-breach/block-cash-app-data-breach.html 4、风力涡轮机制造商Nordex Group遭网络攻击关闭部分IT系统 https://securityaffairs.co/wordpress/129875/security/a-cyber-attack-forced-the-wind-turbine-manufacturer-nordex-group-to-shut-down-some-of-it-systems.html 5、FIN7 黑客利用密码重用和软件供应链攻击 https://thehackernews.com/2022/04/fin7-hackers-leveraging-password-reuse.html 6、微软在其云服务中检测到 Spring4Shell 攻击 https://www.bleepingcomputer.com/news/security/microsoft-detects-spring4shell-attacks-across-its-cloud-services 7、德国关闭了全球最大暗网市场 Hydra https://www.freebuf.com/news/327478.html 8、横河电机修复了其控制系统产品中的一系列漏洞 https://www.securityweek.com/yokogawa-patches-flaws-allowing-disruption-manipulation-physical-processes 9、英国零售商The Works遭网络攻击后关闭了部分门店 https://www.bitdefender.com/blog/hotforsecurity/the-works-hit-by-hackers-uk-retailer-shuts-some-stores-after-problems-with-payment-tills/ 10、得克萨斯州保险部暴露了 180 万人的数据 https://www.securityweek.com/texas-department-insurance-exposed-data-18-million-people