网络安全日报 2022年03月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Firefox 紧急更新修补了两个被积极利用的零日漏洞 https://www.securityweek.com/emergency-firefox-update-patches-two-actively-exploited-zero-day-vulnerabilities 2、SharkBot 银行木马伪装成反病毒软件通过Google Play传播 https://securityaffairs.co/wordpress/128765/malware/sharkbot-trojan-google-play.html 3、Coinbase 阻止访问 25,000 个与俄罗斯个人和实体相关的加密货币地址 https://securityaffairs.co/wordpress/128775/digital-id/coinbase-blocked-25000-russian-addresses.html 4、铁威马存储 (TNAS) 设备中的高危漏洞可导致被远程攻击 https://thehackernews.com/2022/03/critical-bugs-in-terramaster-tos-could.html 5、钓鱼邮件针对石油和天然气公司分发恶意软件 https://blog.malwarebytes.com/threat-intelligence/2022/03/beware-of-malware-offering-warm-greetings-from-saudi-aramco/ 6、Adafruit公司遭到数据泄露暴露用户的信息 https://www.bleepingcomputer.com/news/security/adafruit-discloses-data-leak-from-ex-employees-github-repo/ 7、美国医疗保健提供商DRH Health数据泄露 https://www.duncanbanner.com/community/affected-patients-to-receive-information-about-drh-data-security-incident/article_4e5b6b88-9c19-11ec-b6af-8353d6989d4c.html 8、俄乌战争双方大量使用 Telegram进行虚假信息和黑客活动 https://thehackernews.com/2022/03/both-sides-in-russia-ukraine-war.html 9、FBI 获得了 Sci-Hub 创始人 Google 账号数据 https://torrentfreak.com/fbi-gains-access-to-sci-hub-founders-google-account-data-220303/ 10、因申请系统漏洞,日本6万人份外籍入境者信息遭泄露 http://d.youth.cn/shrgch/202203/t20220304_13497978.htm
网络安全日报 2022年03月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、71,000 名 NVIDIA 员工的用户凭证泄露 https://www.securityweek.com/credentials-71000-nvidia-employees-leaked-following-cyberattack 2、Linux 内核 cgroups 中的 CVE-2022-0492 漏洞允许容器逃逸 https://securityaffairs.co/wordpress/128742/security/cve-2022-0492-linux-kernel-flaw.html 3、Lapsus$ 团伙泄露从三星电子窃取的数据 https://securityaffairs.co/wordpress/128712/cyber-crime/samsung-electronics-lapsus-ransomware.html 4、CISA 在已知利用漏洞目录中增加了 95 个漏洞 https://securityaffairs.co/wordpress/128686/security/catalog-of-actively-exploited.html 5、俄发布使用 DDoS 攻击攻击其基础设施的 IP 和域列表 https://thehackernews.com/2022/03/russia-releases-list-of-ips-domains.html 6、思科修复Expressway和TelePresenceVCS中的高危漏洞 https://www.securityweek.com/cisco-patches-critical-vulnerabilities-expressway-telepresence-vcs-products 7、日本美容零售商Acro披露遭到黑客入侵 https://portswigger.net/daily-swig/japanese-beauty-retailer-acro-blames-third-party-hack-for-breach-of-100k-payment-cards 8、大规模Meris僵尸网络嵌入来自REvil的勒索信 https://threatpost.com/massive-meris-botnet-embeds-ransomware-notes-revil/178769/ 9、Dynamicweb软件中漏洞可导致服务器受损 https://portswigger.net/daily-swig/rce-vulnerability-in-dynamicweb-enterprise-software-could-allow-server-compromise 10、恶意软件使用被盗的英伟达代码签名证书 https://www.bleepingcomputer.com/news/security/malware-now-using-stolen-nvidia-code-signing-certificates/
网络安全日报 2022年03月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、英特尔推出适用于第 12 代核心处理器的博锐安全增强功能 https://www.securityweek.com/intel-unveils-vpro-security-enhancements-12th-gen-core-processors 2、医疗保健公司 Mon Health 披露第二次数据泄露 https://www.securityweek.com/healthcare-company-mon-health-discloses-second-data-breach 3、Avast 发布了HermeticRansom 免费解密器 https://securityaffairs.co/wordpress/128652/breaking-news/free-decryptor-hermeticransom-ukraine.html 4、研究人员发现超10万个医用输液泵受高危漏洞影响 https://securityaffairs.co/wordpress/128633/hacking/medical-infusion-pumps-flaws.html 5、乌克兰 WordPress 网站遭受大规模复杂攻击 https://securityaffairs.co/wordpress/128613/cyber-warfare-2/ukrainian-wordpress-sites-attacks.html 6、研究人员展示了针对同态加密的新侧信道攻击 https://thehackernews.com/2022/03/researchers-demonstrate-new-side.html 7、Avast研究人员警告不要加入 DDoS 攻击以帮助乌克兰 https://blog.avast.com/avast-threatlabs-warns-against-ddos-attacks-ukraine 8、Hashnode博客平台中存在远程代码执行漏洞 https://portswigger.net/daily-swig/remote-code-execution-vulnerability-uncovered-in-hashnode-blogging-platform 9、苹果禁用俄罗斯 iPhone 核心功能,暂停在俄销售产品 http://finance.sina.com.cn/stock/relnews/us/2022-03-02/doc-imcwipih6147063.shtml 10、俄媒:俄罗斯准备启用本国互联网 https://www.secrss.com/articles/39831
网络安全日报 2022年03月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Conti Ransomware 源代码被泄露 https://www.securityweek.com/conti-ransomware-source-code-leaked 2、谷歌发布Chrome 99,共修复28个漏洞 https://www.securityweek.com/google-paid-out-over-100000-vulnerabilities-patched-chrome-99 3、VoIPmonitor 监控软件中发现的严重安全漏洞 https://thehackernews.com/2022/03/critical-security-bugs-uncovered-in.html 4、TeaBot Android 银行恶意软件通过 Google Play 商店应用传播 https://thehackernews.com/2022/03/teabot-android-banking-malware-spreads.html 5、卫星通信巨头Viasat遭到网络攻击服务中断 https://www.zdnet.com/article/viasat-confirms-cyberattack-causing-outages-across-europe/ 6、研究人员发现大量的垃圾邮件针对微软帐户 https://threatpost.com/microsoft-accounts-targeted-russian-credential-harvesting/178698/ 7、2021 年针对编程 API 的攻击增长了 600% 以上 https://www.bleepingcomputer.com/news/security/attacks-abusing-programming-apis-grew-over-600-percent-in-2021/ 8、新型芯片可防止黑客从智能设备中提取隐藏信息 https://www.cnbeta.com/articles/tech/1241121.htm 9、莫斯科交易所被网络攻击而被迫下线 https://www.infosecurity-magazine.com/news/moscow-exchange-cyber-attack/ 10、2022 年可能是网络犯罪将重心转向消费者的一年 https://www.bleepingcomputer.com/news/security/2022-may-be-the-year-cybercrime-returns-its-focus-to-consumers/
网络安全日报 2022年03月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、NVIDIA 确认员工凭证在网络攻击中被盗 https://www.securityweek.com/nvidia-confirms-employee-credentials-stolen-cyberattack 2、DDoS 攻击滥用网络中间设备进行反射、放大 https://www.securityweek.com/ddos-attacks-abuse-network-middleboxes-reflection-amplification 3、施耐德继电器缺陷可能允许黑客禁用电网保护 https://www.securityweek.com/schneider-relay-flaws-can-allow-hackers-disable-electrical-network-protections 4、研究人员发现了针对乌克兰网络攻击的新数据擦除器-IsaacWiper https://securityaffairs.co/wordpress/128553/malware/isaacwiper-data-wiper.html 5、900 万安装量的 Chrome Skype 扩展程序被发现泄露用户信息 https://portswigger.net/daily-swig/private-chat-chrome-skype-extension-with-9m-installs-found-to-be-leaking-user-info 6、Lansweeper 中的漏洞可能导致 JavaScript、SQL 注入 https://blog.talosintelligence.com/2022/03/vuln-spotlight-.html 7、严重的 GitLab 漏洞可能允许攻击者窃取运行者注册令牌 https://portswigger.net/daily-swig/critical-gitlab-vulnerability-could-allow-attackers-to-steal-runner-registration-tokens 8、PJSIP库存在高危RCE漏洞影响WhatsApp和其他VoIP应用 https://threatpost.com/rce-bugs-whatsapp-popular-voip-apps-patch-now/178719/ 9、CISA在已知被利用漏洞目录增加了4个漏洞 https://thehackernews.com/2022/02/cisa-adds-recently-disclosed-zimbra-bug.html 10、三周被罚一个亿!苹果向荷兰“妥协”:首次开放第三方支付 https://news.mydrivers.com/1/817/817246.htm
网络安全日报 2022年03月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、针对乌克兰民用数字目标的网络攻击激增 https://www.securityweek.com/microsoft-cyberattacks-ukraine-hitting-civilian-digital-targets 2、丰田在日本的全部生产线因其供应商遭网络攻击而停止 https://www.securityweek.com/toyotas-japan-production-halted-over-suspected-cyberattack 3、UNC2596 通过Exchange Server 漏洞部署 Cuba勒索软件 https://cyware.com/news/unc2596-deploys-cuba-ransomware-via-microsoft-exchange-server-vulnerabilities-280b72bd 4、Gerbv 中发现的漏洞可能导致代码执行、信息泄露 https://blog.talosintelligence.com/2022/02/vuln-spotlight-gerbv-g.html 5、研究人员构建Apple Airtag克隆版本成功绕过反跟踪保护技术 https://thehackernews.com/2022/02/experts-create-apple-airtag-clone-that.html 6、6万多条属于Conti勒索软件团伙的内部消息遭泄露 https://www.bleepingcomputer.com/news/security/conti-ransomwares-internal-chats-leaked-after-siding-with-russia/ 7、Android 上的 Visual Voice Mail 可能容易被窃听 https://www.bleepingcomputer.com/news/security/visual-voice-mail-on-android-may-be-vulnerable-to-eavesdropping/ 8、臭名昭著的黑客论坛Raidforums据称被当局查封 https://www.hackread.com/hacking-forum-raidforums-com-seized-by-authorities/ 9、俄克拉荷马州的DNA解决方案公司的个人数据被泄露 https://portswigger.net/daily-swig/dna-data-of-sexual-assault-victims-exposed-in-breach-at-us-laboratory 10、俄乌冲突加剧,网络安全股价大涨,最高涨幅超110% https://www.secrss.com/articles/39667
网络安全日报 2022年02月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、匿名者声称破坏了白俄罗斯铁路的内部网络 https://securityaffairs.co/wordpress/128486/hacktivism/anonymous-breached-belarusian-railways.html 2、芯片制造商巨头英伟达遭受勒索软件攻击 https://securityaffairs.co/wordpress/128456/cyber-crime/nvidia-ransomware-attack.html 3、Fileless SockDetour 后门针对美国国防承包商 https://securityaffairs.co/wordpress/128446/apt/sockdetour-backdoor-targets-us-defense.html 4、Okta Advanced Server Access 客户端中存在 RCE漏洞 https://securityaffairs.co/wordpress/128418/security/nhs-okta-advanced-server-access-rce.html 5、TrickBot 恶意软件团伙关闭了其僵尸网络基础设施 https://thehackernews.com/2022/02/notorious-trickbot-malware-gang-shuts.html 6、GE Digital修复了Proficy CIMPLICITY HMI/SCADA软件的漏洞 https://www.securityweek.com/ge-scada-product-vulnerabilities-show-importance-secure-configurations 7、Zenly社交媒体应用程序中被发现存在两个漏洞 https://threatpost.com/zenly-bugs-account-takeover/178646/ 8、Electron Bot恶意软件通过仿冒流行游戏进入微软官方商店 https://www.bleepingcomputer.com/news/security/malware-infiltrates-microsoft-store-via-clones-of-popular-games/ 9、IBM的数据显示亚洲成为2021年受网络攻击的最多的地区 https://www.zdnet.com/article/asia-most-targeted-region-in-2021-taking-on-one-in-four-cybersecurity-attacks/ 10、Cuba勒索软件团伙频繁利用Microsoft Exchange漏洞 https://threatpost.com/microsoft-exchange-exploited-cuba-ransomware/178665/
网络安全日报 2022年02月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Deadbolt 勒索软件针对 ASUSTOR 和QNap NAS 设备 https://thehackernews.com/2022/02/warning-deadbolt-ransomware-targeting.html 2、 Cisco Nexus 交换机存在 DoS 漏洞 https://www.securityweek.com/nsa-informs-cisco-vulnerability-exposing-nexus-switches-dos-attacks 3、大规模网络钓鱼活动针对花旗银行客户 https://www.bleepingcomputer.com/news/security/citibank-phishing-baits-customers-with-fake-suspension-alerts/ 4、乌克兰政府机构和银行网站再次遭受 DDoS 攻击 https://www.bleepingcomputer.com/news/security/ukrainian-government-and-banks-once-again-hit-by-ddos-attacks/ 5、Sandworm黑客组织利用Cyclops Blink恶意软件攻击防火墙设备 https://www.zdnet.com/article/security-warning-hackers-are-using-this-new-malware-to-target-firewall-appliances/ 6、Dridex恶意软件在被黑电脑上部署Entropy勒索软件 https://thehackernews.com/2022/02/dridex-malware-deploying-entropy.html 7、Horde网络邮件客户端的XSS漏洞可通过文件预览功能触发 https://portswigger.net/daily-swig/zero-day-xss-vulnerability-in-horde-webmail-client-can-be-triggered-by-file-preview-function 8、华硕子公司ASUSTOR遭勒索攻击,被索要上千万元赎金 https://www.freebuf.com/news/323073.html 9、NVIDIA RTX 30显卡挖矿被100%破解?其实是恶意软件 http://www.cnbeta.com/articles/tech/1240357.htm 10、谷歌浏览器允许用户在保存的密码中添加注释 https://www.bleepingcomputer.com/news/google/google-chrome-to-allow-users-to-add-notes-to-saved-passwords/
网络安全日报 2022年02月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、中国研究员披露美国NSA方程式的顶级后门Bvp47技术细节 https://www.pangulab.cn/post/the_bvp47_a_top-tier_backdoor_of_us_nsa_equation_group 2、Sophos 将 Entropy 勒索软件与 Dridex 恶意软件相关联 https://securityaffairs.co/wordpress/128323/cyber-crime/entropy-ransomware-dridex-link.html 3、Horde Webmail 软件中被发现了一个存在 9 年之久的未修补漏洞 https://securityaffairs.co/wordpress/128314/hacking/horde-webmail-xss.html 4、Kostovite、Petrovite 和 Erythrite 黑客组织正在攻击工业、OT系统 https://www.zdnet.com/article/these-new-hacking-groups-are-striking-industrial-operational-tech-targets/ 5、加密缺陷影响超过1亿部三星手机可能受到初始向量重用攻击 https://threatpost.com/samsung-shattered-encryption-on-100m-phones/178606/ 6、CryptBot 的新变种针对所有 Chrome 版本 https://cyware.com/news/new-variant-of-cryptbot-targets-all-chrome-versions-ff58a9f5 7、研究人员使用 Find My Protocol 绕过 Apple Airtags 克隆的跟踪保护 https://www.theregister.com/2022/02/22/apple_airtags_protections_bypass/ 8、研究人员在NPM包存储库中发现25个恶意JavaScript库 https://thehackernews.com/2022/02/25-malicious-javascript-libraries.html 9、研究人员揭示了利用VNC屏幕共享软件绕过MFA的方法 https://www.bleepingcomputer.com/news/security/devious-phishing-method-bypasses-mfa-using-remote-access-software/ 10、加密货币交易平台Coinbase因存在漏洞短暂停止了其服务 https://www.govinfosecurity.com/market-nuking-coinbase-api-bug-halted-new-trading-orders-a-18582
网络安全日报 2022年02月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、物流巨头 Expeditors International遭勒索攻击导致全球运营系统中断 https://www.securityweek.com/cyberattack-hits-global-operations-logistics-giant-expeditors-international 2、炊具巨头 Meyer Corporation 披露网络攻击和数据泄露 https://securityaffairs.co/wordpress/128289/malware/meyer-corporation-discloses-data-breach.html 3、2021 年 91% 的英国组织遭到电子邮件网络钓鱼攻击 https://www.infosecurity-magazine.com/news/uk-organizations-email-phishing/ 4、新版本的CryptBot恶意软件通过盗版软件网站传播 https://www.bleepingcomputer.com/news/security/revamped-cryptbot-malware-spread-by-pirated-software-sites/ 5、黑客针对Microsoft SQL服务器部署Cobalt Strike Beacon https://thehackernews.com/2022/02/hackers-backdoor-unpatched-microsoft.html 6、《日本东京奥运会网络安全报告》官网瘫痪1小时,共遭4.5亿次网络攻击 https://mp.weixin.qq.com/s/Sar-NeGK7jyh-mWTwMrUGQ 7、谷歌实验室称Linux开发者修复安全漏洞的速度最快 https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html 8、攻击者通过NFT话题分发木马BitRAT https://www.fortinet.com/blog/threat-research/nft-lure-used-to-distribute-bitrat 9、豆瓣被爆APP内截图生成盲水印含个人敏感信息,回应称系新功能 https://www.cnbeta.com/articles/tech/1239027.htm 10、工信部部署做好工业领域数据安全管理试点工作 https://mp.weixin.qq.com/s/u5qtJkkTpDgW2UnnBldHXQ