网络安全日报 2022年03月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、乌安全研究人员泄露了较新的 Conti 勒索软件源代码 https://www.securityweek.com/ukrainian-security-researcher-leaks-newer-conti-ransomware-source-code 2、意大利数据隐私监管机构调查卡巴斯基杀毒软件 https://www.securityweek.com/italy-investigates-russias-kaspersky-antivirus-software 3、Lapsus$ 团伙声称入侵了微软源代码存储库 https://securityaffairs.co/wordpress/129312/cyber-crime/lapsus-gang-claims-microsoft-hack.html 4、DirtyMoe僵尸网络使用类似蠕虫的技术进行传播 https://securityaffairs.co/wordpress/129286/malware/dirtymoe-modules-worm-like-techniques.html 5、新的浏览器中浏览器 (BITB) 攻击用于网络钓鱼几乎无法检测到 https://thehackernews.com/2022/03/new-browser-in-browser-bitb-attack.html 6、欧盟和美国机构警告俄可能会攻击卫星通信网络 https://www.freebuf.com/articles/325542.html 7、 2021 年英国的 NFT 诈骗案飙升 400% https://www.infosecurity-magazine.com/news/nft-fraud-uk-soars-400-2021/ 8、俄管道巨头 Transneft 遭攻击,79GB数据泄露 https://www.cnbeta.com/articles/tech/1248347.htm 9、新后门通过开源软件包安装程序针对法国实体公司 https://thehackernews.com/2022/03/new-backdoor-targets-french-entities.html 10、TransUnion南非公司因弱密码被黑,南非公民征信数据全泄露 https://www.secrss.com/articles/40484
网络安全日报 2022年03月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客使用新的 Unix Rootkit 攻击银行网络从 ATM 机中窃取资金 https://thehackernews.com/2022/03/hackers-target-bank-networks-with-new.html 2、Sandworm APT 使用 Cyclops Blink 僵尸网络针对华硕路由器 https://threatpost.com/sandworm-asus-routers-cyclops-blink-botnet/178986/ 3、ISC发布更新修补BIND 服务器中的多个高危漏洞 https://www.securityweek.com/high-severity-vulnerabilities-patched-bind-server 4、Avoslocker 勒索软件团伙以美国关键基础设施为目标 https://securityaffairs.co/wordpress/129232/cyber-crime/avoslocker-ransomware-us-critical-infrastructure.html 5、DarkHotel APT钓鱼活动针对豪华酒店盗取客人数据 https://threatpost.com/darkhotel-apt-wynn-macao-hotels/178989/ 6、Emsisoft 为 Diavol 勒索软件的受害者发布了免费解密器 https://securityaffairs.co/wordpress/129211/malware/emsisoft-releases-free-decryptor-for-the-victims-of-the-diavol-ransomware.html 7、Trickbot在C2基础架构中使用MikroTik设备 https://www.microsoft.com/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/ 8、研究人员发现爱立信网络管理器中存在漏洞 https://securityaffairs.co/wordpress/129188/hacking/ericsson-network-manager-bug.html 9、南非信用机构TransUnion遭黑客入侵数据泄露 https://www.cyberscoop.com/south-africa-transunion-data-breach/ 10、研究人员发现与Conti勒索软件合作的新的初始访问代理Exotic Lily https://securityaffairs.co/wordpress/129216/cyber-crime/exotic-lily-access-broker.html
网络安全日报 2022年03月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软发布用于保护 MikroTik 路由器的开源工具 https://github.com/microsoft/routeros-scanner 2、SolarWinds 警告针对 Web Help Desk 用户的攻击 https://www.securityweek.com/solarwinds-warns-attacks-targeting-web-help-desk-users 3、审计发现大多数 NASA 系统都面临内部威胁的风险 https://www.securityweek.com/most-nasa-systems-risk-insider-threats-audit 4、NIST 为制造商发布 ICS 网络安全实践指南 https://www.securityweek.com/nist-releases-ics-cybersecurity-guidance-manufacturers 5、TrickBot 恶意软件滥用 MikroTik 路由器作为C2代理 https://thehackernews.com/2022/03/trickbot-malware-abusing-hacked-iot.html 6、CRI-O 引擎中的新漏洞可导致Kubernetes 容器逃逸 https://thehackernews.com/2022/03/new-vulnerability-in-cri-o-engine-lets.html 7、由于后端云数据库配置错误,2,113 个移动应用程序泄露用户敏感数据 https://www.infosecurity-magazine.com/news/thousands-mobile-apps-expose-data/ 8、研究人员发现新的勒索软件LokiLocker https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware 9、研究人员发现Parse Server存在一个RCE漏洞 https://portswigger.net/daily-swig/node-js-security-parse-server-remote-code-execution-vulnerability-resolved 10、GoDaddy 托管的数百个WordPress网站,短时间内被部署了后门 https://www.freebuf.com/news/325232.html
网络安全日报 2022年03月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 将 14 个 Windows 漏洞添加到“必须修补”列表中 https://www.securityweek.com/cisa-adds-14-windows-vulnerabilities-must-patch-list 2、Cloudflare 宣布用于电子邮件、应用程序和 API 的新安全工具 https://www.securityweek.com/cloudflare-announces-new-security-tools-email-applications-apis 3、dompdf 项目中未修补的 RCE 漏洞影响 HTML to PDF 转换器 https://thehackernews.com/2022/03/unpatched-rce-bug-in-dompdf-project.html 4、用于大数据的 ClickHouse OLAP 数据库系统中发现多个漏洞 https://thehackernews.com/2022/03/multiple-flaws-uncovered-in-clickhouse.html 5、大规模网络钓鱼活动使用500多个域来窃取 Naver 的凭据 https://www.bleepingcomputer.com/news/security/massive-phishing-campaign-uses-500-plus-domains-to-steal-credentials 6、脸书母公司Meta因大规模数据泄露被欧盟罚款1860万美元 https://thehackernews.com/2022/03/facebook-hit-with-186-million-gdpr-fine.html 7、汽车零部件制造商DENSO遭到勒索软件攻击和1.4TB文件被盗 https://www.bleepingcomputer.com/news/security/automotive-giant-denso-hit-by-new-pandora-ransomware-gang/ 8、虚假 Windows 防病毒更新用于部署Cobalt Strike https://www.bleepingcomputer.com/news/security/fake-antivirus-updates-used-to-deploy-cobalt-strike-in-ukraine/ 9、微软正在Windows 11文件资源管理器中测试广告 https://www.bleepingcomputer.com/news/microsoft/microsoft-is-testing-ads-in-the-windows-11-file-explorer/ 10、针对RSA密钥新型攻击方式——Fermat Attack https://fermatattack.secvuln.info/
网络安全日报 2022年03月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、OpenSSL修复了 CVE-2022-0778 高危DoS 漏洞 https://securityaffairs.co/wordpress/129104/security/openssl-dos-vulnerability.html 2、德国BSI机构建议消费者不要使用卡巴斯基杀毒软件 https://securityaffairs.co/wordpress/129085/intelligence/bsi-recommends-replace-kaspersky-av.html 3、Veeam Data Backup 软件修复了两个严重漏洞 https://securityaffairs.co/wordpress/129094/hacking/veeam-rce.html 4、研究人员发现新的数据擦除恶意软件CaddyWiper https://securityaffairs.co/wordpress/129069/cyber-warfare-2/caddywiper-wiper-hits-ukraine.html 5、研究人员在泄露的三星源代码中发现数千个密钥 https://www.securityweek.com/thousands-secret-keys-found-leaked-samsung-source-code 6、Dirty Pipe Linux 漏洞影响大多数 QNAP NAS 设备 https://securityaffairs.co/wordpress/129076/hacking/qnap-nas-dirty-pipe.html 7、Raccoon Stealer 使用 Telegram 作为C2 https://cyware.com/news/raccoon-stealer-using-telegram-for-hidden-communications-c4cf31d4 8、国家计算机病毒应急处理中心披露NSA网络间谍武器 https://www.anquanke.com/post/id/270087 9、315晚会聚焦个人信息安全 https://www.freebuf.com/news/325021.html 10、日本电装德国分部大量机密数据被黑客窃取 https://www.cnbeta.com/articles/tech/1246433.htm
网络安全日报 2022年03月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple 修补了iOS、macOS、iPadOS 中的39个安全漏洞 https://www.securityweek.com/apple-patch-day-gaping-security-holes-ios-macos-ipados 2、AMD 在英特尔研究之后更新 Spectre 缓解措施 https://www.securityweek.com/amd-updates-spectre-mitigations-following-intel-research 3、以色列遭遇大规模 DDoS 攻击,导致许多政府网站离线 https://securityaffairs.co/wordpress/129063/cyber-warfare-2/massive-ddos-attack-hit-israel.html 4、乌国防部使用 Clearview AI 的面部识别技术来识别敌方 https://securityaffairs.co/wordpress/129047/cyber-warfare-2/clearview-facial-recognition-ukraine.html 5、Netfilter模块中的漏洞CVE-2022-25636可导致Linux本地提权 https://thehackernews.com/2022/03/new-linux-bug-in-netfilter-firewall.html 6、研究人员发现Aberebot银行木马的新版本 https://www.bleepingcomputer.com/news/security/android-malware-escobar-steals-your-google-authenticator-mfa-codes/ 7、芬兰政府机构警告飞机GPS遭到异常干扰 https://www.bleepingcomputer.com/news/technology/finnish-govt-agency-warns-of-unusual-aircraft-gps-interference/ 8、SDCA医疗机构遭到黑客入侵导致数据泄露 https://www.databreaches.net/287652-south-denver-cardiology-associates-patients-notified-of-breach/ 9、黑客组织Lapsus$发起投票:根据结果公开公司数据 https://www.cnbeta.com/articles/tech/1245685.htm 10、欧洲立法者对欧盟国家使用Pegasus间谍软件展开调查 https://www.cnbeta.com/articles/tech/1245991.htm
网络安全日报 2022年03月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LockBit 勒索软件声称已经入侵了普利司通美洲公司 https://securityaffairs.co/wordpress/128957/cyber-crime/bridgestone-americas-lockbit-ransomware.html 2、攻击者使用网站联系表格传播 BazarLoader 恶意软件 https://securityaffairs.co/wordpress/128942/cyber-crime/phishing-bazarloader-campaign.html 3、俄互联网监管机构 Roskomnadzor 将禁止 Instagram https://securityaffairs.co/wordpress/128935/cyber-warfare-2/russian-roskomnadzor-bans-instagram.html 4、Lapsus$ 团伙声称入侵了游戏巨头育碧公司 https://securityaffairs.co/wordpress/128929/hacking/ubisoft-cyber-security-incident.html 5、东映动画遭受网络攻击延迟发布新的海贼王动漫剧集 https://www.bleepingcomputer.com/news/security/new-one-piece-anime-episodes-delayed-after-toei-cyberattack/ 6、欧姆龙修补修补了 PLC 编程软件中的高危漏洞 https://www.securityweek.com/high-severity-vulnerabilities-patched-omron-plc-programming-software 7、研究人员推测新的Nokoyawa勒索软件与Hive有关 https://www.trendmicro.com/en_us/research/22/c/nokoyawa-ransomware-possibly-related-to-hive-.html 8、约70%的ServiceNow实例配置错误暴露敏感数据 https://threatpost.com/most-servicenow-instances-misconfigured-exposed/178827/ 9、流行的软件包管理器中发现多个安全漏洞 https://thehackernews.com/2022/03/multiple-security-flaws-discovered-in.html 10、为对抗制裁,俄罗斯决定自建TLS根证书 https://www.freebuf.com/news/324501.html
网络安全日报 2022年03月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、意大利对美国面部识别公司Clearview AI 处以 2000 万欧元罚款 https://www.securityweek.com/italy-fines-us-facial-recognition-firm 2、CISA 将 98 个域添加到与 Conti 勒索软件相关的联合警报中 https://securityaffairs.co/wordpress/128885/malware/cisa-alert-conti-ransomware.html 3、新Emotet 僵尸网络正在迅速发展,179 个国家/地区超 13 万主机被感染 https://securityaffairs.co/wordpress/128879/breaking-news/emotet-botnet-rapidly-growing.html 4、攻击Nvidia和三星的Lapsus$入侵了沃达丰并窃取了200GB的源代码 https://www.securityweek.com/vodafone-investigating-source-code-theft-claims 5、研究人员发现RURansom恶意软件针对俄罗斯 https://www.trendmicro.com/en_us/research/22/c/new-ruransom-wiper-targets-russia.html 6、CISA 敦促在 3 月 21 日之前修复被积极利用的 Firefox 零日漏洞 https://securityaffairs.co/wordpress/128803/security/cisa-firefox-zerodays-known-exploited-vulnerabilities-catalog.html 7、谷歌以 54 亿美元收购网络安全公司Mandiant https://www.leiphone.com/category/industrynews/UmpSJjGqdNYB30zn.html 8、近 30% 的关键 WordPress 插件漏洞没有更新补丁 https://www.bleepingcomputer.com/news/security/nearly-30-percent-of-critical-wordpress-plugin-bugs-dont-get-a-patch 9、1Password 将漏洞赏金最高奖励增加到 100 万美元 https://www.securityweek.com/1password-increases-top-bug-bounty-reward-1-million 10、Adobe 修补了 Illustrator、After Effects 中的严重漏洞 https://www.securityweek.com/adobe-patches-critical-security-flaws-illustrator-after-effects
网络安全日报 2022年03月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、西门子解决了 90 多个因第三方组件引入的漏洞 https://www.securityweek.com/siemens-addresses-over-90-vulnerabilities-affecting-third-party-components 2、Mitel 设备被滥用于 DDoS攻击,放大率达到创纪录的4,294,967,296:1 https://www.securityweek.com/mitel-devices-abused-ddos-vector-record-breaking-amplification-ratio 3、APC Smart-UPS 设备中的严重漏洞可导致被远程入侵 https://thehackernews.com/2022/03/critical-bugs-could-let-attackers.html 4、研究人员披露了影响 Pascom 云电话系统 ( CPS ) 的三个严重漏洞 https://thehackernews.com/2022/03/critical-rce-bugs-found-in-pascom-cloud.html 5、Android 2022 年 3 月安全更新补丁修复了39个漏洞 https://www.securityweek.com/androids-march-2022-security-updates-patch-39-vulnerabilities 6、电子商务技术巨头 Mercado Libre 确认源代码数据泄露 https://www.bleepingcomputer.com/news/security/e-commerce-giant-mercado-libre-confirms-source-code-data-breach/ 7、在线学习平台Moodle中存在SQL注入漏洞 https://portswigger.net/daily-swig/sql-injection-vulnerability-in-e-learning-platform-moodle-could-enable-database-takeover 8、英伟达泄露数据正被用来制作伪装成驱动的病毒 http://www.cnbeta.com/articles/tech/1244419.htm 9、MITRE Engage 发布了 V1 版本 https://www.anquanke.com/post/id/269504 10、新的攻击绕过了针对 Intel 和 ARM CPU 中 Spectre 漏洞的硬件防御 https://www.csoonline.com/article/3652525/new-attack-bypasses-hardware-defenses-for-spectre-flaw-in-intel-and-arm-cpus.html
网络安全日报 2022年03月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SAP 修补监控解决方案中的关键安全漏洞 https://www.securityweek.com/sap-patches-critical-security-flaws-monitoring-solutions 2、周二补丁日:微软修复74个漏洞含多个代码执行漏洞 https://www.securityweek.com/patch-tuesday-microsoft-fixes-multiple-code-execution-flaws 3、 Axeda 平台中七个严重漏洞影响100多家制造商的150多种设备型号 https://securityaffairs.co/wordpress/128810/hacking/access7-flaws.html 4、Ragnar Locker 勒索软件团伙入侵了美国52个关键基础设施网络 https://www.freebuf.com/news/324094.html 5、工信部发布《车联网网络安全和数据安全标准体系建设指南》 https://www.freebuf.com/news/324069.html 6、研究人员披露了惠普UEFI固件16个高危漏洞,影响数百万台惠普设备 https://thehackernews.com/2022/03/new-16-high-severity-uefi-firmware.html 7、PROPHET SPIDER 利用 Citrix ShareFile 漏洞攻击IIS Web服务器 https://www.crowdstrike.com/blog/prophet-spider-exploits-citrix-sharefile 8、Rompetrol加油站网络遭到Hive勒索软件攻击 https://www.bleepingcomputer.com/news/security/rompetrol-gas-station-network-hit-by-hive-ransomware/ 9、PressReader平台遭到网络攻击导致系统中断 https://www.zdnet.com/article/pressreader-service-partially-returns-after-cyberattack-causes-outage/ 10、微软Azure漏洞可能允许攻击者访问客户账户 https://thehackernews.com/2022/03/microsoft-azure-autowarp-bug-could-have.html