网络安全日报 2022年02月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员找到了一种解密 Hive 勒索软件加密数据的方法 https://www.securityweek.com/researchers-devise-method-decrypt-hive-ransomware-encrypted-data 2、 Xenomorph银行木马通过Google Play分发,针对 56 家欧洲银行 https://securityaffairs.co/wordpress/128253/malware/xenomorph-android-banking-trojan.html 3、SMS PVA 服务被滥用以绕过 SMS 验证机制 https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html 4、伊朗国家广播公司 IRIB 被破坏性 Wiper 恶意软件攻击 https://thehackernews.com/2022/02/iranian-state-broadcaster-irib-hits-by_21.html 5、微软警告Web3和去中心化网络上的冰式网络钓鱼威胁 https://thehackernews.com/2022/02/microsoft-warns-of-ice-phishing-threat.html 6、研究表明开源软件包中的漏洞通常需要很长时间才能修复 https://portswigger.net/daily-swig/lagging-behind-new-study-highlights-weaknesses-in-open-source-patch-process 7、CISA发布用于业务保护的免费安全工具清单 https://www.theregister.com/2022/02/18/cisa_free_security/ 8、针对乌克兰组织的DDoS攻击被归咎于俄罗斯情报部门 https://www.infosecurity-magazine.com/news/russia-prepositioning-attacks/ 9、攻击者仿冒NFT市场OpenSea向其用户发送钓鱼邮件 https://www.zdnet.com/article/opensea-scam-artists-swindle-nfts-worth-millions-in-phishing-attack/ 10、新的网络钓鱼活动针对Monzo网上银行用户 https://www.bleepingcomputer.com/news/security/new-phishing-campaign-targets-monzo-online-banking-customers/
网络安全日报 2022年02月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、英特尔发布软件和固件更新补丁修复了18个高危漏洞 https://www.securityweek.com/intel-software-and-firmware-updates-patch-18-high-severity-vulnerabilities 2、VMware NSX Data Center高危漏洞可能使虚拟机受到攻击 https://www.securityweek.com/vmware-nsx-data-center-flaw-can-expose-virtual-systems-attacks 3、Trickbot 操作现在由 Conti 勒索软件控制 https://securityaffairs.co/wordpress/128190/cyber-crime/conti-ransomware-takes-over-trickbot.html 4、UpdraftPlus 插件修复了一个高危漏洞,影响300万个站点 https://securityaffairs.co/wordpress/128170/hacking/updraftplus-forced-update.html 5、Snap包管理中发现新的 Linux 权限提升漏洞 https://securityaffairs.co/wordpress/128150/hacking/cve-2021-44731-linux-privilege-escalation.html 6、伊朗黑客利用Log4j漏洞针对VMware Horizon 部署勒索软件 https://thehackernews.com/2022/02/iranian-hackers-targeting-vmware.html 7、攻击者利用Microsoft Teams传播恶意软件 https://securityaffairs.co/wordpress/128136/hacking/microsoft-teams-attack-vector.html 8、研究揭示了一种新型抗攻击量子密钥分发网络的可行性 https://www.csoonline.com/article/3650748/new-quantum-key-distribution-network-resistant-to-quantum-attacks.html 9、SonicWall在2021年检测到超过6.2亿次勒索软件攻击 https://www.infosecurity-magazine.com/news/over-620-million-ransomware/ 10、开源监控软件Zabbix中的两个漏洞允许攻击者绕过身份验证 https://portswigger.net/daily-swig/critical-vulnerabilities-in-zabbix-web-frontend-allow-authentication-bypass-code-execution-on-servers
网络安全日报 2022年02月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、攻击者利用 Microsoft Teams 传播恶意软件 https://securityaffairs.co/wordpress/128136/hacking/microsoft-teams-attack-vector.html 2、特制电子邮件可能使 Cisco ESA 设备崩溃 https://securityaffairs.co/wordpress/128131/hacking/cisco-esa-dos.html 3、欧洲数据保护监督机构呼吁禁止像 Pegasus 这样的间谍软件 https://securityaffairs.co/wordpress/128123/security/edps-surveillance-spyware-pegasus.html 4、攻击者利用 Zoho 漏洞入侵了红十字国际委员会 https://securityaffairs.co/wordpress/128110/hacking/nation-state-actors-hacked-red-cross-exploiting-a-zoho-bug.html 5、Trickbot 针对 60 家知名公司的客户 https://securityaffairs.co/wordpress/128087/malware/trickbot-targets-60-high-profile-companies.html 6、谷歌将隐私沙盒引入 Android 以限制用户数据的共享 https://thehackernews.com/2022/02/google-bringing-privacy-sandbox-to.html 7、Moses Staff黑客组织针对以色列进行网络间谍活动 https://thehackernews.com/2022/02/moses-staff-hackers-targeting-israeli.html 8、研究人员发现了基于Golang的新僵尸网络Kraken https://securityaffairs.co/wordpress/128116/malware/golang-kraken-botnet.html 9、印度储备银行副行长呼吁禁止加密货币 https://www.theregister.com/2022/02/16/india_cryptocurrency_ban_call/ 10、乌克兰:军事防御机构和银行正受到网络攻击 https://securityaffairs.co/wordpress/128051/hacking/ukraine-military-agencies-banks-hit-by-ddos-attacks-defacements.html
网络安全日报 2022年02月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、向日葵个人版for Windows存在高危命令执行漏洞 https://www.cnvd.org.cn/flaw/show/CNVD-2022-10270 2、专家披露 Apache Cassandra DB RCE 的细节 https://securityaffairs.co/wordpress/128079/breaking-news/apache-cassandra-rce.html 3、VMware修复了4个在天府杯黑客大赛中披露的高危漏洞 https://securityaffairs.co/wordpress/128063/security/vmware-fixes-flaws-demonstrated-at-chinese-tianfu-cup-hacking-contest.html 4、BlackCat 团伙声称对 Swissport 勒索软件攻击负责 https://securityaffairs.co/wordpress/128039/cyber-crime/blackcat-swissport-ransomware-attack.html 5、研究人员披露了TA2541组织的一系列网络间谍活动 https://threatpost.com/ta2541-apt-rats-aviation/178422/ 6、研究人员展示了如何恢复使用像素化技术编辑过的文本 https://portswigger.net/daily-swig/new-tool-can-uncover-redacted-pixelated-text-to-reveal-sensitive-data 7、FritzFrog 僵尸网络疯狂扩张,近四成受害者在中国 https://www.freebuf.com/articles/network/321848.html 8、西班牙警方逮捕SIM卡金融欺诈犯罪团伙 https://thehackernews.com/2022/02/spanish-police-arrest-sim-swappers-who.html 9、FBI称BlackByte勒索软件入侵了3个美国关键基础设施组织 https://securityaffairs.co/wordpress/128013/malware/blackbyte-ransomware-breached-at-least-3-us-critical-infrastructure-organizations.html 10、新的MyloBot恶意软件变体发送勒索邮件 https://thehackernews.com/2022/02/new-mylobot-malware-variant-sends.html
网络安全日报 2022年02月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Chrome更新修复了2022年的第一个0day漏洞 https://threatpost.com/google-chrome-zero-day-under-attack/178428/ 2、乌克兰国防机构和两家国有银行遭DDoS攻击 https://securityaffairs.co/wordpress/128051/hacking/ukraine-military-agencies-banks-hit-by-ddos-attacks-defacements.html 3、虚假微软网站声称提供Windows 11以传播恶意软件 https://www.hackread.com/fake-windows-website-redline-malware-windows-11/ 4、黑客利用BGP劫持从韩国加密货币平台KLAYswap窃取约190万美元 https://therecord.media/klayswap-crypto-users-lose-funds-after-bgp-hijack/ 5、Grafana被发现存在跨站请求伪造漏洞 https://portswigger.net/daily-swig/grafana-web-security-vulnerability-opened-a-plethora-of-attack-possibilities 6、国际互联网协会由于配置错误泄露了超8万名成员的个人数据 https://portswigger.net/daily-swig/internet-society-data-leak-exposed-80-000-members-login-details 7、体育品牌美津浓遭勒索软件攻击致订单延期 https://www.freebuf.com/news/321945.html 8、修订后的《网络安全审查办法》2月14日起施行 https://www.ithome.com/0/602/836.htm 9、知乎声明:未使用“行为感知系统”监测员工 https://tech.ifeng.com/c/8DcyZPCVDn5 10、严重 Magento 零日漏洞 CVE-2022-24086 被积极利用 https://securityaffairs.co/wordpress/127999/hacking/cve-2022-24086-zero-day.html
网络安全日报 2022年02月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、香港海逸酒店遭网络攻击,120万客人数据遭泄露 https://www.scmp.com/news/hong-kong/law-and-crime/article/3166739/cyberattack-harbour-plaza-hotels-hong-kong-exposes 2、微软增强从内存中窃取 Windows 密码的难度 https://www.bleepingcomputer.com/news/microsoft/microsoft-is-making-it-harder-to-steal-windows-passwords-from-memory/ 3、报告称2021 年有超过 28,000 个漏洞被披露 https://www.securityweek.com/over-28000-vulnerabilities-disclosed-2021-report 4、FBI透露BlackByte勒索软件组织入侵美国关键基础设施 https://www.bleepingcomputer.com/news/security/fbi-blackbyte-ransomware-breached-us-critical-infrastructure/ 6、欧洲中央银行警告可能会发生与俄罗斯有关的网络攻击 https://securityaffairs.co/wordpress/128004/breaking-news/european-central-bank-warns-russia-cyberattacks.html 7、欧洲汽车经销商Emil Frey遭到勒索软件攻击 https://www.zdnet.com/article/europes-biggest-car-dealer-hit-with-ransomware-attack/ 8、Adobe修复了其Commerce和Magento开源产品的关键漏洞 https://thehackernews.com/2022/02/critical-magento-0-day-vulnerability.html 9、上海29岁程序员离职当天“删库跑路” 被判刑10个月 https://news.mydrivers.com/1/814/814048.htm 10、因发现以太坊关键漏洞, iOS 越狱之父Jay Freeman获 200 万美元奖金 https://www.ithome.com/0/602/761.htm
网络安全日报 2022年02月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、2021 年,组织机构向勒索软件团伙支付了至少 6.02 亿美元 https://securityaffairs.co/wordpress/127974/cyber-crime/ransomware-payments-600m-2021.html 2、 BlackByte 勒索软件攻击了旧金山四九人球队IT网络 https://securityaffairs.co/wordpress/127961/cyber-crime/blackbyte-ransomware-hit-san-francisco-49ers.html 3、克罗地亚电话运营商 A1 Hrvatska 披露数据泄露 https://securityaffairs.co/wordpress/127919/data-breach/a1-hrvatska-data-breach.html 4、Adobe 发布针对被利用零日漏洞的紧急补丁 https://www.securityweek.com/adobe-releases-emergency-patch-exploited-commerce-zero-day 5、Maze团伙声称不再使用勒索软件并且已销毁其所有源代码 https://threatpost.com/decryptor-keys-maze-egregor-sekhmet-ransomwares/178363/ 6、攻击者利用regsvr32.exe通过Microsoft Office文档传播恶意软件 https://securityaffairs.co/wordpress/127871/hacking/attackers-adopting-regsvr32-office-documents.html 7、Moxa MXview的网络管理系统被发现存在5个漏洞 https://threatpost.com/critical-mqtt-bugs-industrial-rce-moxa/178399/ 8、数字日程安排平台FlexBooker泄露了数百万客户的数据 https://www.zdnet.com/article/amazon-steps-in-to-close-exposed-flexbooker-bucket-after-december-data-breach/ 9、数以千计的npm帐户使用域名过期的电子邮件地址 https://therecord.media/thousands-of-npm-accounts-use-email-addresses-with-expired-domains/ 10、研究人员发现乔治亚州使用的投票机存在安全漏洞 https://www.securityweek.com/feds-oppose-immediate-release-voting-machine-report
网络安全日报 2022年02月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、攻击者入侵了500多家基于 Magento 的电商平台 https://securityaffairs.co/wordpress/127874/cyber-crime/magento-based-e-stores-mass-compromise.html 2、PHP Everywhere 插件RCE漏洞影响数千个WordPress站点 https://securityaffairs.co/wordpress/127848/hacking/rce-php-everywhere-wordpress-plugin.html 3、苹果称 WebKit 0day漏洞被用来攻击 iOS、macOS 设备 https://www.securityweek.com/apple-says-webkit-zero-day-hitting-ios-macos-devices 4、FritzFrog P2P 僵尸网络攻击医疗保健、教育和政府部门 https://thehackernews.com/2022/02/fritzfrog-p2p-botnet-attacking.html 5、俄罗斯打击了4个被盗信用卡的暗网市场 https://thehackernews.com/2022/02/russia-cracks-down-on-4-dark-web.html 6、伊朗APT组织在Out to Sea间谍活动中使用新的Marlin后门 https://thehackernews.com/2022/02/iranian-hackers-using-new-marlin.html 7、美国查获2016年Bitfinex黑客事件中被盗的价值36亿美元的加密货币 https://securityaffairs.co/wordpress/127805/cyber-crime/bitfinex-stolen-funds-seizure.html 8、Mozilla公司修复了火狐浏览器中允许获得Windows管理员权限的bug https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-bug-letting-you-get-windows-admin-privileges/ 9、NetWalker勒索软件成员被判80个月监禁 https://www.bleepingcomputer.com/news/security/netwalker-ransomware-affiliate-sentenced-to-80-months-in-prison/ 10、ExpressVPN提供10万美元给第一个入侵其服务器的人 https://www.bleepingcomputer.com/news/security/expressvpn-offering-100-000-to-first-person-who-hacks-its-servers/
网络安全日报 2022年02月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 警告要立即解决 SAP ICMAD 漏洞 https://securityaffairs.co/wordpress/127832/hacking/cisa-sap-icmad-flaw.html 2、Maze、Egregor 和 Sekhmet 勒索软件的主解密密钥在线泄露 https://securityaffairs.co/wordpress/127826/malware/egregor-sekhmet-decryption-keys.html 3、波兰成立网络安全军事单位 https://www.securityweek.com/poland-launches-cybersecurity-military-unit 4、西门子和施耐德电气修复了近 50 个 ICS 漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-address-nearly-50-vulnerabilities 5、Nooie婴儿监视器中的安全漏洞允许攻击者访问摄像头 https://portswigger.net/daily-swig/zero-day-vulnerabilities-in-nooie-baby-monitors-could-allow-video-feed-hijack 6、BazarBackdoor 通过恶意 CSV 文件传播 https://cyware.com/news/bazarbackdoor-spreads-via-malicious-csv-files-41282197 7、Nobelium 黑客使用 COVID-19 诱饵来攻击欧洲外交人员 https://thehackernews.com/2022/02/russian-apt-hackers-used-covid-19-lures.html 8、Zerodium 花费巨额资金购买0day漏洞 https://cyware.com/news/zerodium-offers-huge-money-for-zero-day-exploits-2cfeab3e 9、盗版海盗湾网站针对数百万用户投放恶意软件和恶意广告 https://securityaffairs.co/wordpress/127810/cyber-crime/pirate-bay-clones-malware.html 10、多个恶意软件家族使用安装付费服务扩大其目标 https://thehackernews.com/2022/02/several-malware-families-using-pay-per.html
网络安全日报 2022年02月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、沃达丰葡萄牙遭受大规模网络攻击 https://securityaffairs.co/wordpress/127799/cyber-crime/vodafone-portugal-massive-cyberattack.html 2、6K+ Puma 员工数据在 12 月的 Kronos Ransomware 攻击中被盗 https://securityaffairs.co/wordpress/127791/cyber-crime/puma-kronos-ransomware-attack.html 3、Roaming Mantis SMS网络钓鱼活动现在针对欧洲 https://securityaffairs.co/wordpress/127773/cyber-crime/roaming-mantis-targets-europe.html 4、微软发布 51 个 Windows 安全漏洞补丁 https://www.securityweek.com/microsoft-patches-51-windows-security-defects 5、Android 2022 年 2 月安全更新补丁 36 漏洞 https://www.securityweek.com/androids-february-2022-security-update-patches-36-vulnerabilities 6、Medusa银行木马针对多地区进行凭证窃取并进行金融欺诈 https://www.bleepingcomputer.com/news/security/medusa-malware-ramps-up-android-sms-phishing-attacks/ 7、FBI公布了LockBit 2.0勒索软件攻击的IOC https://www.securityweek.com/fbi-publishes-iocs-lockbit-20-ransomware-attacks 8、服务全球100强的公司Morley遭勒索攻击泄露大量用户信息 https://www.freebuf.com/news/321403.html 9、思科RV系列路由器被曝存在严重安全漏洞 https://thehackernews.com/2022/02/critical-flaws-discovered-in-cisco.html 10、教育行业成2021年网络攻击重灾区 https://netsecurity.51cto.com/article/700597.html