网络安全日报 2022年04月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌在 2022 年 4 月 Android 更新 44 个漏洞补丁 https://www.securityweek.com/44-vulnerabilities-patched-android-april-2022-security-updates2、Conti勒索团伙泄露了从工业巨头 Parker Hannifin 窃取的文件 https://www.securityweek.com/ransomware-gang-leaks-files-stolen-industrial-giant-parker-hannifin3、VMware发布更新修复多个产品中的Spring4Shell漏洞 https://securityaffairs.co/wordpress/129826/security/vmware-secure-spring4shell.html4、研究人员发现一种执行勒索和 DDoS 攻击的新 RAT-Borat RAT https://securityaffairs.co/wordpress/129805/malware/borat-rat-a-new-rat-that-performs-ransomware-and-ddos-attacks.html5、PEAR PHP 存储库中发现一个存在15年之久的漏洞,可导致供应链攻击 https://securityaffairs.co/wordpress/129797/hacking/pear-php-critical-flaws.html6、Beastmode Mirai 僵尸网络新增了对 Totolink 路由器的利用 https://securityaffairs.co/wordpress/129745/cyber-crime/beastmode-botnet-targets-totolink-routers.html7、Mailchimp遭黑客入侵被用于对数字钱包用户进行网络钓鱼攻击 https://securityaffairs.co/wordpress/129831/data-breach/mailchimp-breached-cryptocurrency-phishing.html8、Hive 勒索软件使用新的 IPfuscation 技术来隐藏其有效负载 https://cyware.com/news/ipfuscation-is-hives-new-technique-to-evade-detection-96c3c7489、PCI安全标准委员会发布支付卡行业数据安全标准4.0版 https://www.govinfosecurity.com/pci-ssc-releases-data-security-standard-version-40-a-1882810、西班牙能源巨头Iberdrola的100多万用户数据被泄露 https://www.infosecurity-magazine.com/news/scottish-power-parent-data-breach/
网络安全日报 2022年04月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Rockwell PLC 严重漏洞可以导致 Stuxnet 式攻击 https://www.securityweek.com/new-vulnerabilities-allow-stuxnet-style-attacks-against-rockwell-plcs 2、趋势科技修复了Apex Central 中的0day漏洞 https://www.securityweek.com/trend-micro-patches-apex-central-zero-day-exploited-targeted-attacks 3、Zyxel 修复了其业务防火墙和 VPN 设备中的一个严重漏洞 https://securityaffairs.co/wordpress/129689/security/zyxel-firewalls-authentication-bypass.html 4、AcidRain wiper针对欧洲路由器和调制解调器进行破坏 https://securityaffairs.co/wordpress/129703/malware/acidrain-wiper-ukraine.html 5、Lazarus Group 分发木马化 DeFi 钱包应用以窃取受害者的加密货币 https://thehackernews.com/2022/04/north-korean-hackers-distributing.html 6、GitLab 解决了严重的帐户劫持漏洞 https://portswigger.net/daily-swig/gitlab-addresses-critical-account-hijack-bug 7、网络钓鱼使用 Azure 静态网页冒充微软 https://www.bleepingcomputer.com/news/microsoft/phishing-uses-azure-static-web-pages-to-impersonate-microsoft/ 8、Rapid7修复了漏洞管理软件Nexpose中的SQL注入漏洞 https://portswigger.net/daily-swig/critical-sql-injection-flaw-fixed-in-rapid7s-nexpose-vulnerability-scanner 9、国家信息安全漏洞共享平台收录Spring框架远程命令执行漏洞 https://www.cnvd.org.cn/webinfo/show/7541 10、新的BlackGuard密码窃取恶意软件在黑客论坛上出售 https://www.bleepingcomputer.com/news/security/new-blackguard-password-stealing-malware-sold-on-hacker-forums/
网络安全日报 2022年04月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、IT 巨头 Globant 确认源代码存储库泄露 https://www.securityweek.com/it-giant-globant-confirms-source-code-repository-breach 2、网络安全供应商评估近期 OpenSSL 漏洞的影响 https://www.securityweek.com/cybersecurity-vendors-assessing-impact-recent-openssl-vulnerability 3、Apple 发布macOS、iOS 紧急安全补丁修复被积极利用的漏洞 https://www.securityweek.com/apple-ships-emergency-patches-actively-exploited-macos-ios-flaws 4、Spring Framework 发布补丁修补CVE-2022-22965漏洞 https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement 5、ImpersCMS中的SQL注入保护可被绕过来实现RCE https://portswigger.net/daily-swig/sql-injection-protections-in-impresscms-could-be-bypassed-to-achieve-rce 6、存在17 年之久可导致应用程序崩溃的Zlib漏洞被修复 https://www.theregister.com/2022/03/30/zlib_data_bug/ 7、三分之一的英国企业每周至少遭受一次网络攻击 https://www.infosecurity-magazine.com/news/third-businesses-cyber-attacks-week 8、美国医疗保健数据泄露影响 85,000 名执法人员 https://portswigger.net/daily-swig/us-healthcare-data-breach-impacts-85-000-law-enforcement-officers 9、Hive 勒索软件使用新的"IPfuscation"技巧隐藏攻击载荷 https://www.bleepingcomputer.com/news/security/hive-ransomware-uses-new-ipfuscation-trick-to-hide-payload/ 10、Palo Alto Networks支持系统错误配置导致泄露客户案例、附件 https://www.bleepingcomputer.com/news/security/palo-alto-networks-error-exposed-customer-support-cases-attachments
网络安全日报 2022年03月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Chrome 浏览器发布重大安全更新解决了28个漏洞 https://www.securityweek.com/chrome-browser-gets-major-security-update 2、研究人员发现了一种远程中断电动汽车充电的攻击方法:Brokenwire https://www.securityweek.com/remote-brokenwire-hack-prevents-charging-electric-vehicles 3、Lapsus$ 称攻击并泄露了 IT 巨头 Globant 70GB数据 https://www.securityweek.com/lapsus-claims-hack-it-giant-globant-after-arrests-alleged-members 4、一个严重的 RCE 漏洞影响 SonicWall 防火墙设备 https://securityaffairs.co/wordpress/129627/hacking/sonicwall-firewall-rce-vulnerability.html 5、CISA 和 DoE 就针对 UPS 设备的攻击发出警告 https://securityaffairs.co/wordpress/129620/security/cisa-doe-warn-attacks-ups.html 6、Transparent Tribe APT针对印度官员进行攻击 https://thehackernews.com/2022/03/new-hacking-campaign-by-transparent.html 7、Viasat 发布 KA-SAT 卫星服务网络攻击事件报告 https://www.bleepingcomputer.com/news/security/viasat-shares-details-on-ka-sat-satellite-service-cyberattack/ 8、日本糖果制造商森永的在线商店遭到数据泄露 https://portswigger.net/daily-swig/network-cavity-blamed-for-data-breach-at-japanese-candy-maker-morinaga 9、研究人员发现针对Jupyter Notebook的勒索软件攻击 https://blog.aquasec.com/python-ransomware-jupyter-notebook 10、央视曝光部分浏览器 App 后台读取剪贴板,包括银行卡账号密码明文 https://www.ithome.com/0/610/269.htm
网络安全日报 2022年03月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Ronin Network 被盗价值6亿美金加密货币 https://www.securityweek.com/hackers-steal-over-600m-major-crypto-heist 2、Microsoft Defender for IoT 中发现严重漏洞 https://www.securityweek.com/critical-vulnerabilities-found-microsoft-defender-iot 3、白宫提出 109 亿美元的网络安全预算 https://www.securityweek.com/white-house-proposes-109-billion-budget-cybersecurity 4、CISA 将 Chrome、Redis 漏洞添加到已知利用漏洞目录 https://securityaffairs.co/wordpress/129593/security/chrome-redis-known-exploited-vulnerabilities-catalog.html 5、Spring Frame Core存在远程命令执行漏洞 https://github.com/spring-projects/spring-framework/commit/7f7fb58dd0dae86d22268a4b59ac7c72a6c22529 6、英国国内勒索软件攻击在2021年内激增100% https://www.infosecurity-magazine.com/news/ransomware-attacks-soar-100-2021/ 7、Serpent后门攻击瞄准法国建筑公司和政府部门 https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain 8、Wyze Cam 网络摄像头存在漏洞可被未授权远程访问 https://www.bleepingcomputer.com/news/security/wyze-cam-flaw-lets-hackers-remotely-access-your-saved-videos/ 9、研究人员设计了一种保护隐私的监控视频分析系统-Privid https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html 10、匿名者组织泄露2家俄工业公司约112GB数据 https://www.hackread.com/anonymous-hack-russian-industrial-firms-data-leak/
网络安全日报 2022年03月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、钓鱼活动通过劫持未打补丁的 Exchange 邮件回复链来传播恶意软件 https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html 2、"Purple Fox"组织在最近的恶意软件攻击中使用新变种FatalRAT https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html 3、Muhstik 僵尸网络利用 Redis 最新漏洞CVE-2022-0543 进行攻击 https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html 4、Hive 勒索软件将其加密器移植到 Rust 编程语言 https://securityaffairs.co/wordpress/129566/cyber-crime/hive-ransomware-ports-encryptor-to-rust.html 5、Western Digital 修复了影响 My Cloud OS 5 设备的严重漏洞 https://securityaffairs.co/wordpress/129507/security/western-digital-my-cloud-os-5-flaw.html 6、思科Talos发现Sound Exchange libsox库存在缓冲区溢出漏洞 https://blog.talosintelligence.com/2022/03/vuln-spotligh-libsox0.html 7、美国指控4名俄政府员工入侵全球关键基础设施 https://thehackernews.com/2022/03/us-charges-4-russian-govt-employees.html 8、Illuminate Education在线评分考勤系统泄露约82万纽约学生的数据 https://www.nydailynews.com/new-york/education/ny-hack-illuminate-online-gradebook-compromised-personal-data-20220325-ahy3b3b3t5cjzajau63muqcniq-story.html 9、美国FCC将卡巴斯基、中国电信和中国移动加入国家安全威胁名单 https://www.freebuf.com/news/326451.html 10、以色列阻止乌克兰购买NSO集团的"Pegasus"间谍软件 https://www.cnbeta.com/articles/science/1251117.htm
网络安全日报 2022年03月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google 发布紧急 Chrome 更新以修补被利用的0day漏洞 https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html2、7 名年龄 16 至 21 岁的LAPSUS$ 嫌疑成员在英国被捕 https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html3、Sophos Firewall 修复了高危身份验证绕过和远程代码执行漏洞 https://securityaffairs.co/wordpress/129536/security/sophos-firewall-authentication-bypass-flaw.html4、CISA 在已知利用漏洞目录中增加了 66 个新漏洞 https://securityaffairs.co/wordpress/129502/hacking/cisa-known-exploited-vulnerabilities-catalog-66.html5、针对允许黑客解锁和启动思域的漏洞,本田表示没有更新旧车的计划 https://therecord.media/honda-downplays-vulnerability-allowing-hackers-to-lock-unlock-and-start-civics/6、Vidar间谍软件通过隐藏在微软的帮助文件中以逃避检测 https://www.zdnet.com/article/vidar-spyware-is-now-hidden-in-microsoft-help-files/7、Facestealer恶意软件通过谷歌Play商店传播 https://threatpost.com/facestealer-trojan-google-play-facebook/179015/8、超过4万名伦敦选民的个人信息遭到泄露 https://www.infosecurity-magazine.com/news/over-40000-london-voters-data/9、英国国防部招募网站遭到黑客入侵数据泄露 https://www.theregister.com/2022/03/24/ministry_of_defence/10、摩根士丹利公司披露客户账户遭到黑客入侵 https://www.bleepingcomputer.com/news/security/morgan-stanley-client-accounts-breached-in-social-engineering-attacks/
网络安全日报 2022年03月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员称LAPSUS$ 幕后黑手可能是英国的一名16 岁少年 https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html 2、VMware 修补了Carbon Black App Control平台的关键漏洞 https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html 3、朝鲜黑客使用Chrome 0day漏洞进行攻击 https://www.securityweek.com/north-korea-gov-hackers-caught-sharing-chrome-zero-day 4、Microweber 开发者解决 CMS 软件中的 XSS 漏洞 https://portswigger.net/daily-swig/microweber-developers-resolve-xss-vulnerability-in-cms-software 5、台达工业能源管理系统修补多个关键漏洞 https://www.securityweek.com/many-critical-flaws-patched-delta-electronics-energy-management-system 6、大规模供应链攻击使用200 多个恶意 NPM 包针对 Azure 开发人员 https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html 7、微软更新修复了导致Windows蓝屏的蓝牙问题 https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bluetooth-issue-causing-windows-blue-screens/ 8、苏格兰心理健康慈善机构SAMH遭勒索软件攻击和数据泄露 https://www.bitdefender.com/blog/hotforsecurity/scottish-mental-health-charity-devastated-by-heartless-ransomexx-ransomware-attack/ 9、FBI称2021年互联网犯罪给人们带来的损失超过69亿美元 https://www.cnbeta.com/articles/tech/1249955.htm 10、日本医疗问答平台Doctors Me泄露用户数据 https://www.safetydetectives.com/news/doctorsme-leak-report/
网络安全日报 2022年03月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软和 Okta 已确认遭受Lapsus$攻击后数据泄露 https://www.securityweek.com/microsoft-okta-confirm-data-breaches-involving-compromised-accounts 2、全球超过 200,000 台 MicroTik 路由器受僵尸网络控制 https://thehackernews.com/2022/03/over-200000-microtik-routers-worldwide.html 3、俄罗斯肉类生产商遭Windows BitLocker加密攻击 https://www.bleepingcomputer.com/news/security/top-russian-meat-producer-hit-with-windows-bitlocker-encryption-attack/ 4、CryptoRom "加密货币骗局滥用 iPhone 功能瞄准移动用户 https://thehackernews.com/2022/03/cryptorom-crypto-scam-abusing-iphone.html 5、超过 4 万名伦敦选民的个人数据被泄露给陌生人 https://www.infosecurity-magazine.com/news/over-40000-london-voters-data/ 6、社会工程攻击成为Web3,metaverse主要攻击方式 https://www.zdnet.com/article/social-engineering-attacks-to-dominate-web3-metaverse-services/ 7、背景调查公司Creative Services, Inc. (CSI) 因数据泄露被起诉 https://www.infosecurity-magazine.com/news/background-check-company-sued-over/ 8、攻击者利用 XLL 文件传递新的 JSSLoader 木马 https://blog.morphisec.com/new-jssloader-trojan-delivered-through-xll-files 9、窃取 Facebook 凭证的恶意 Android 应用感染10W用户 https://www.anquanke.com/post/id/270583 10、恶意软件活动滥用Chocolatey Windows软件包管理器 https://www.bleepingcomputer.com/news/security/serpent-malware-campaign-abuses-chocolatey-windows-package-manager/
网络安全日报 2022年03月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、QNAP 设备成为新一波 DeadBolt 勒索软件攻击的目标 https://www.securityweek.com/qnap-devices-targeted-new-wave-deadbolt-ransomware-attacks 2、戴尔修补了笔记本电脑中高危UEFI 漏洞 https://www.securityweek.com/high-severity-uefi-vulnerabilities-patched-dell-enterprise-laptops 3、三个严重的 RCE 漏洞陷影响数百款 HP 打印机型号 https://securityaffairs.co/wordpress/129362/hacking/hp-printer-critical-rce.html 4、Lapsus$ 勒索团伙声称从 Okta 窃取了敏感数据 https://securityaffairs.co/wordpress/129343/data-breach/lapsus-gang-claims-okta-hack.html 5、希腊公共邮政服务因勒索软件攻击而中断 https://www.bleepingcomputer.com/news/security/greeces-public-postal-service-offline-due-to-ransomware-attack/ 6、BitRAT 恶意软件通过 Windows 10 激活器下载传播 https://www.bleepingcomputer.com/news/security/bitrat-malware-now-spreading-as-a-windows-10-license-activator/ 7、匿名者宣布入侵雀巢并泄露了 10 GB 的敏感数据 https://securityaffairs.co/wordpress/129382/hacktivism/anonymous-hacked-nestle-leaked-data.html 8、加密金融机构BlockFi数据泄露影响客户数据 https://cointelegraph.com/news/blockfi-confirms-unauthorized-access-to-client-data-hosted-on-hubspot 9、暴露的数据库泄露了印度CISF人员的个人信息 https://techcrunch.com/2022/03/18/india-cisf-security-data-exposed/ 10、Rust发布更新修复了一个ReDoS漏洞 https://portswigger.net/daily-swig/rust-patches-sneaky-redos-bug