网络安全日报 2022年02月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Avast 发布了TargetCompany 勒索软件的免费解密器
https://securityaffairs.co/wordpress/127761/malware/targetcompany-ransomware-decryptor.html 2、微软禁用 ms-appinstaller 协议,因为它被滥用于传播恶意软件
https://securityaffairs.co/wordpress/127755/malware/microsoft-disables-ms-appinstaller.html 3、美国电信供应商申请$5.6B资金更换中国设备
https://securityaffairs.co/wordpress/127749/security/telecom-providers-replace-chinese-gear.html 4、美国国税局停止使用面部识别来识别纳税人
https://www.securityweek.com/irs-end-use-facial-recognition-identify-taxpayers 5、BlackCat勒索软件被证实与BlackMatter和DarkSide相关联
https://www.bleepingcomputer.com/news/security/blackcat-alphv-ransomware-linked-to-blackmatter-darkside-gangs/ 6、区块链基础设施公司Meter遭受网络攻击440万美元被盗
https://www.zdnet.com/article/4-4-million-stolen-in-attack-on-blockchain-infrastructure-meter/ 7、CISA命令联邦机构修补被积极利用的win32k本地提权漏洞
https://thehackernews.com/2022/02/cisa-orders-federal-agencies-to-patch.html 8、监控公司QuaDream利用iMessage零点击漏洞远程入侵iPhone
https://securityaffairs.co/wordpress/127721/malware/surveillance-firm-quadream.html 9、华盛顿州许可证部门遭入侵可能导致个人信息泄露
https://www.securityweek.com/breach-washington-state-database-may-expose-personal-information 10、士Swissport空港服务公司遭勒索软件攻击导致航班延误
https://www.freebuf.com/news/321338.html
网络安全日报 2022年02月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、超过1亿安卓用户安装了Dark Herring诈骗软件
https://www.securityweek.com/over-100-million-android-users-installed-dark-herring-scamware 2、研究人员使用GPU指纹识别技术在线跟踪用户
https://www.bleepingcomputer.com/news/security/researchers-use-gpu-fingerprinting-to-track-users-online/ 3、研究人员使用天然丝纤维生成安全密钥进行强认证
https://thehackernews.com/2022/01/researchers-use-natural-silk-fibers-to.html 4、Samba修复了CVE-2021-44142远程代码执行漏洞
https://securityaffairs.co/wordpress/127457/security/cve-2021-44142-samba-rce.html 5、瑞典安全巨头Securitas AB暴露了3TB机场员工的敏感数据
https://www.hackread.com/security-giant-expose-3tb-airport-employees-data/ 6、英国零食生厂商KP Snacks遭受了勒索软件攻击
https://threatpost.com/kp-snacks-crumbs-ransomware-attack/178176/ 7、npm JavaScript包管理器中被发现1300个恶意包
https://www.securityweek.com/1300-malicious-packages-found-popular-npm-javascript-package-manager 8、攻击者从加密货币公司Wormhole窃取3.2亿美元
https://www.infosecurity-magazine.com/news/online-thieves-steal-320m-crypto/ 9、H2O HTTP服务器项目中的内存泄漏漏洞已被修复
https://portswigger.net/daily-swig/fastly-patches-memory-leak-http-3-vulnerability-in-h2o-http-server-project 10、流行的持续交付平台Argo CD存在目录遍历漏洞
https://threatpost.com/argo-cd-security-bug-kubernetes-cloud-apps/178239/
网络安全日报 2022年01月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、美国FCC以国家安全风险为由撤销中国联通在美运营许可
https://securityaffairs.co/wordpress/127347/security/us-ban-china-unicom-americas.html 2、微软警告利用 Azure AD 的多阶段网络钓鱼活动
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-multi-stage-phishing-campaign-leveraging-azure-ad/ 3、美国宾州将立法禁止苹果 AirTag 类电子防丢器滥用
https://www.ithome.com/0/600/725.htm 4、朝鲜关键服务无法访问 疑似遭到DDoS攻击
https://www.cnbeta.com/articles/tech/1231211.htm 5、QNAP 针对最近一波 DeadBolt 勒索软件感染强制安装更新
https://securityaffairs.co/wordpress/127353/malware/qnap-force-installs-update-deadbolt-ransomware.html 6、黑客利用Github漏洞伪装成Linus称将发布“元宇宙系统”
https://www.cnbeta.com/articles/tech/1230793.htm 7、欺诈检测和预防市场将在2028年达到 751亿美元
https://www.helpnetsecurity.com/2022/01/27/fraud-detection-prevention-2028/ 8、施乐发布更新解决了导致网络打印机崩溃的漏洞
https://portswigger.net/daily-swig/xerox-belatedly-addresses-web-based-printer-bricking-threat 9、白宫和 EPA 发布针对供水运营商的 100 天网络安全计划
https://www.zdnet.com/article/white-house-epa-release-100-day-cybersecurity-plan-for-water-utility-operators 10、2021年超过400亿条数据被泄露
https://cybernews.com/security/more-than-40-billion-records-were-exposed-in-2021/
网络安全日报 2022年01月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、NCSC警告英国实体遭到来自俄罗斯的潜在破坏性网络攻击
https://securityaffairs.co/wordpress/127342/security/ncsc-alerts-destructive-russian-cyberattacks.html 2、芬兰外交官的设备感染了 Pegasus 间谍软件
https://securityaffairs.co/wordpress/127334/breaking-news/pegasus-spyware-finnish-diplomats.html 3、Zerodium 宣布将支付 400,000 美元购买 Outlook 0day
https://securityaffairs.co/wordpress/127327/uncategorized/microsoft-outlook-rce-zero-day-payout.html 4、台达电子遭到 Conti 勒索软件的攻击
https://securityaffairs.co/wordpress/127323/cyber-crime/delta-electronics-conti-ransomware.html 5、Solarwinds修复Web Help Desk软件中的漏洞
https://portswigger.net/daily-swig/solarwinds-fixes-code-execution-bug-in-enterprise-helpdesk-software 6、Mirai僵尸网络被发现针对ZyXEL网络设备
https://www.zdnet.com/article/log4j-mirai-ddos-botnet-targeting-zyxel-networking-devices/ 7、针对亚洲的水坑攻击活动部署macOS恶意软件DazzleSpy
https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/ 8、TrickBot再添新功能,可让浏览器崩溃
https://www.bleepingcomputer.com/news/security/trickbot-now-crashes-researchers-browsers-to-block-malware-analysis/ 9、HackerOne 获得 4900 万美元的 E 系列融资
https://www.securityweek.com/hackerone-bags-49-million-series-e-funding 10、黑客发现瑞士铁路系统存在漏洞
https://www.infosecurity-magazine.com/news/hacker-flags-flaw-in-swiss-railway/
网络安全日报 2022年01月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Outlook 安全功能可被绕过允许发送恶意链接给收件人
https://www.securityweek.com/outlook-security-feature-bypass-allowed-sending-malicious-links 2、LockBit 2.0 勒索软件团伙称已入侵法国司法部并窃取了文件
https://www.securityweek.com/french-ministry-justice-targeted-ransomware-attack 3、REvil 勒索软件遭俄罗斯执法机构破坏后依然活跃
https://www.securityweek.com/revil-ransomware-operations-apparently-unaffected-recent-arrests 4、Lazarus APT 在最近的攻击中使用了 Windows 更新客户端和 GitHub
https://securityaffairs.co/wordpress/127296/apt/lazarus-apt-windows-update-client.html 5、波多黎各遭受重大网络攻击
https://securityaffairs.co/wordpress/127265/hacking/puerto-rico-suffered-cyberattack.html 6、微软缓解了针对Azure客户创纪录的3.47Tbps DDoS攻击
https://securityaffairs.co/wordpress/127279/cyber-crime/record-ddos-attack-azure.html 7、由于Onfido 安全漏洞,数百万用户生物识别数据和ID遭泄露
https://cybernews.com/security/popular-apps-left-biometric-data-ids-of-millions-of-users-in-danger/ 8、Chaes Banking 木马通过恶意扩展劫持 Chrome 浏览器
https://thehackernews.com/2022/01/chaes-banking-trojan-hijacks-chrome.html 9、影响数百万台设备的BotenaGo 僵尸网络源码已泄露到 GitHub
https://threatpost.com/botenago-botnet-code-leaked-to-github/178059/ 10、API和数据库问题导致主要的Discord服务中断
https://www.bleepingcomputer.com/news/technology/major-discord-outage-caused-by-api-and-database-issues/
网络安全日报 2022年01月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、苹果发布安全更新修复了两个零日漏洞
https://securityaffairs.co/wordpress/127240/hacking/apple-fixed-two-zero-day-2022.html 2、新的 DeadBolt 勒索软件针对 QNAP NAS 设备
https://securityaffairs.co/wordpress/127221/malware/deadbolt-ransomware-qnap-nas.html 3、VMware 敦促客户修补Horizon 服务器中的Log4j 漏洞
https://securityaffairs.co/wordpress/127214/security/vmware-horizon-patches-log4j-flaws.html 4、PwnKit:本地提权漏洞影响主流的 Linux 发行版
https://securityaffairs.co/wordpress/127199/security/linux-cve-2021-4034-bug.html 5、PrinterLogic 修复了打印机管理套件中的严重漏洞
https://securityaffairs.co/wordpress/127194/security/printerlogic-printer-management-suite-flaws.html 6、Android 安全工具 APKLeaks 修补严重漏洞
https://portswigger.net/daily-swig/android-security-tool-apkleaks-patches-critical-vulnerability 7、Linux内核漏洞(CVE-2022-0185)可用于逃逸Kubernetes容器
https://www.bleepingcomputer.com/news/security/linux-kernel-bug-can-let-hackers-escape-kubernetes-containers/ 8、黑客利用MSHTML漏洞针对西亚政府和国防目标
https://www.trellix.com/en-gb/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html 9、GitHub iOS和Android 应用启用双因素身份验证机制
https://www.zdnet.com/article/github-enables-two-factor-authentication-mechanism-through-ios-android-app 10、Claroty 发布新的开源工具用于研究分析EtherNet/IP 堆栈
https://www.securityweek.com/new-open-source-tool-helps-identify-ethernetip-stacks-ics-research-analysis
网络安全日报 2022年01月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Segway 电子商店遭受 Magecart 攻击
https://securityaffairs.co/wordpress/127187/cyber-crime/segway-magecart-attack.html 2、英国 NCSC 将发布一组Nmap 脚本以查找未修补的漏洞
https://securityaffairs.co/wordpress/127181/hacking/uk-ncsc-scanning-made-easy-sme.html 3、最新版本的 Android RAT BRATA 在窃取数据后擦除设备
https://securityaffairs.co/wordpress/127131/cyber-crime/new-android-brata-rat.html 4、加拿大外交部在网络攻击后遭受服务中断
https://www.bleepingcomputer.com/news/security/canadas-foreign-affairs-ministry-hacked-some-services-down/ 5、攻击者正在利用 SonicWall SMA 设备RCE 漏洞
https://securityaffairs.co/wordpress/127147/hacking/sonicwall-secure-mobile-access-rce.html 6、Molerats APT组织针对中东发起新的间谍攻击
https://www.zscaler.com/blogs/security-research/new-espionage-attack-molerats-apt-targeting-users-middle-east 7、巴西中央银行的Pix即时支付系统泄露用户数据
https://playcrazygame.com/2022/01/23/central-bank-reports-pix-key-data-leak/ 8、DTPacker恶意软件分发多个木马和信息窃取程序
https://www.proofpoint.com/us/blog/threat-insight/dtpacker-net-packer-curious-password-1 9、黑客组织加密了白俄罗斯铁路公司服务器以示抗议
https://www.bleepingcomputer.com/news/security/hackers-say-they-encrypted-belarusian-railway-servers-in-protest/ 10、《黑暗之魂3》游戏服务器因严重的RCE漏洞而关闭
https://www.kaspersky.com/blog/dark-souls-dangerous-vulnerability/43436/
网络安全日报 2022年01月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Microsoft 在最新Excel中默认禁用所有 Excel 4.0 宏
https://www.securityweek.com/microsoft-restricts-excel-40-macros-default 2、Facebook 母公司 Meta 周一宣布将打造超级计算机
https://www.securityweek.com/facebook-trumpets-massive-new-supercomputer 3、CentOS Web Panel 存在两个严重漏洞可导致服务器被远程攻击
https://www.securityweek.com/cwp-flaws-expose-servers-remote-attacks-possibly-exploited-wild 4、Rust 中的一个高危漏洞可导致文件和目录被删除
https://securityaffairs.co/wordpress/127135/security/rust-programming-language-flaw.html 5、Emotet 垃圾邮件使用非常规IP 地址格式来逃避检测
https://securityaffairs.co/wordpress/127108/malware/emotet-evasion-technique.html 6、WhisperGate和NotPetya恶意软件策略相似
https://thehackernews.com/2022/01/experts-find-strategic-similarities-bw.html 7、CISA在已知被利用漏洞目录新增17个漏洞
https://www.bleepingcomputer.com/news/security/cisa-adds-17-vulnerabilities-to-list-of-bugs-exploited-in-attacks/ 8、研究人员发现jQuery UI库中存在多个漏洞
https://www.securityweek.com/resurrected-jquery-ui-library-haunts-some-websites-enterprise-products 9、钓鱼邮件冒充航运巨头马士基传播STRRAT木马
https://www.bleepingcomputer.com/news/security/phishing-impersonates-shipping-giant-maersk-to-push-strrat-malware/ 10、F5发布安全补丁修复影响其产品的25个漏洞
https://securityaffairs.co/wordpress/127097/security/f5-big-ip-flaws.html
网络安全日报 2022年01月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、F5 修补了 BIG-IP 中的两个漏洞
https://www.securityweek.com/f5-patches-two-dozen-vulnerabilities-big-ip 2、McAfee Enterprise 修补了高危漏洞
https://www.securityweek.com/high-severity-vulnerabilities-patched-mcafee-enterprise-product 3、Spamhaus称DoH 使追踪僵尸网络变得更加困难
https://www.securityweek.com/doh-makes-it-difficult-track-botnets-spamhaus 4、OpenSubtitles 数据泄露影响了 700 万订阅者
https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html 5、荷兰国家网络安全中心 (NCSC) 警告与 Log4J 漏洞相关网络攻击
https://securityaffairs.co/wordpress/127067/security/dutch-ncsc-warns-log4j-attacks.html 6、McAfee Agent 软件中的一个安全漏洞可导致提权
https://securityaffairs.co/wordpress/127044/security/mcafee-agent-code-execution-flaw.html 7、Google Project Zero 披露了两个 Zoom 零日漏洞的细节
https://securityaffairs.co/wordpress/127016/hacking/zoom-zero-day-vulnerabilities.html 8、数十个 WordPress 插件和主题被植入了后门
https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html 9、BHUNT密码窃取恶意软件瞄准加密货币钱包
https://thehackernews.com/2022/01/new-bhunt-password-stealer-malware.html 10、Conti勒索软件团伙泄露印度尼西亚银行数据
https://securityaffairs.co/wordpress/126988/cyber-crime/bank-indonesia-conti-ransomware.html
网络安全日报 2022年01月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、FBI 将 Diavol 勒索软件与 TrickBot 团伙关联
https://securityaffairs.co/wordpress/126979/cyber-crime/fbi-links-diavol-ransomware-trickbot.html 2、Cisco StarOS 漏洞可能允许远程代码执行和信息泄露
https://securityaffairs.co/wordpress/126968/security/cisco-staros-rce-information-disclosure.html 3、Crypto.com 证实网络攻击影响400 多个账户和被盗3300 万美元
https://securityaffairs.co/wordpress/126956/hacking/crypto-com-crypto-heist.html 4、新的 BHUNT Stealer 恶意软件针对加密货币钱包
https://securityaffairs.co/wordpress/126938/malware/bhunt-stealer-targets-cryptocurrency.html 5、微软警告称新的SolarWinds Serv-U 漏洞被在野利用
https://securityaffairs.co/wordpress/126933/security/solarwinds-serv-u-flaw.html 6、 Chrome 97更新修补22个漏洞,包括多个高危漏洞
https://www.securityweek.com/google-pays-out-over-100000-vulnerabilities-patched-chrome-97-update 7、DoNot 黑客团伙针对南亚的政府和军事实体
https://thehackernews.com/2022/01/donot-hacking-team-targeting-government.html 8、钓鱼邮件冒充美国劳工部窃取用户的帐户凭据
https://www.inky.com/blog/fresh-phish-phishers-lure-victims-with-fake-invites-to-bid-on-nonexistent-federal-projects 9、Umbraco CMS中的漏洞可能导致帐户被接管
https://portswigger.net/daily-swig/security-vulnerabilities-in-umbraco-cms-could-lead-to-account-takeover 10、免费字幕网站OpenSubtitles披露遭到黑客攻击
https://therecord.media/opensubtitles-discloses-successful-extortion-attempt-data-breach/
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

