网络安全日报 2022年01月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft Edge 添加安全模式以阻止恶意软件攻击 https://www.securityweek.com/microsoft-edge-adds-security-mode-thwart-malware-attacks 2、红十字国际委员会遭大规模网络攻击 https://www.securityweek.com/red-cross-falls-victim-massive-cyberattack 3、研究人员发现针对韩国用户进行DDoS攻击的IRC Bot https://securityaffairs.co/wordpress/126927/malware/irc-bot-ddos.html 4、Zoom 漏洞影响客户端、MMR 服务器 https://www.zdnet.com/article/zoom-vulnerabilities-impact-clients-mmr-servers/ 5、Umbraco CMS 中的安全漏洞可能导致帐户接管 https://portswigger.net/daily-swig/security-vulnerabilities-in-umbraco-cms-could-lead-to-account-takeover 6、新的White Rabbit勒索软件与FIN8黑客组织有关 https://www.bleepingcomputer.com/news/security/new-white-rabbit-ransomware-linked-to-fin8-hacking-group/ 7、VMWare身份验证软件中存在一个SSRF漏洞 https://portswigger.net/daily-swig/ssrf-vulnerability-in-vmware-authentication-software-could-allow-access-to-user-data 8、研究人员披露Box多因素身份验证机制中的漏洞 https://thehackernews.com/2022/01/researchers-bypass-sms-based-multi.html 9、印度Aditya Birla Fashion公司遭黑客入侵数据泄露 https://www.cnbctv18.com/business/companies/aditya-birla-fashion-confirms-data-breach-but-says-no-sensitive-info-was-compromised-12163482.htm 10、《网络安全产业人才岗位能力要求》标准正式发布 https://www.freebuf.com/news/319910.html
网络安全日报 2022年01月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、AlphV/BlackCat 勒索团伙公布了从Moncler 窃取的数据 https://securityaffairs.co/wordpress/126880/cyber-crime/alphv-blackcat-ransomware-hit-moncler.html 2、Earth Lusca APT以全球组织为目标 https://securityaffairs.co/wordpress/126868/hacking/earth-lusca-campaigns.html 3、欧洲刑警组织关闭被许多网络犯罪团伙使用的 VPNLab https://securityaffairs.co/wordpress/126862/cyber-crime/vpn-service-vpnlab-shutdown.html 4、微软针对 WinServer、VPN 问题发布紧急修复补丁 https://securityaffairs.co/wordpress/126856/hacking/windows-out-of-band-emergency-fixes.html 5、英国雨伞公司Parasol Group遭黑客入侵网络中断 https://www.theregister.com/2022/01/17/umbrella_company_parasol_group_confirms/ 6、任天堂警告客户虚假网站冒充官网出售折扣商品 https://www.bleepingcomputer.com/news/security/nintendo-warns-of-spoofed-sites-pushing-fake-switch-discounts/ 7、Zoho修复ManageEngine Desktop Central中漏洞 https://thehackernews.com/2022/01/zoho-releases-patch-for-critical-flaw.html 8、严重的SAP漏洞可能被攻击者滥用于供应链攻击 https://www.securityweek.com/critical-sap-vulnerability-allows-supply-chain-attacks 9、3 个 WordPress 插件中的高危漏洞影响 84,000 个网站 https://securityaffairs.co/wordpress/126821/hacking/wordpress-plugins-flaws-2.html 10、未来三年中国网络安全市场将保持15%以上增速 http://www.cinic.org.cn/xw/schj/1225749.html
网络安全日报 2022年01月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Safari 15 漏洞允许跨站点跟踪用户 https://www.securityweek.com/safari-15-vulnerability-allows-cross-site-tracking-users 2、Oracle 1月重要补丁更新将修复 483 个新漏洞 https://securityaffairs.co/wordpress/126836/security/oracle-critical-patch-update-january-2022.html 3、Zoho 修复了一个 Desktop Central中的严重漏洞 https://securityaffairs.co/wordpress/126828/security/zoho-desktop-central-cve-2021-44757-flaw.html 4、IDEMIA 生物识别读取器中的漏洞允许黑客解锁门 https://www.securityweek.com/vulnerability-idemia-biometric-readers-allows-hackers-unlock-doors 5、eNom数据中心迁移发生错误导致网站离线 https://www.bleepingcomputer.com/news/security/enom-data-center-migration-mistakenly-knocks-sites-offline/ 6、欧盟模拟了针对虚构大型能源公司的网络攻击 https://securityaffairs.co/wordpress/126792/security/eu-simulation-cyber-attack.html 7、Android 用户现可禁用 2G 来阻止 Stingray 攻击 https://www.bleepingcomputer.com/news/security/android-users-can-now-disable-2g-to-block-stingray-attacks/ 8、Linux 恶意软件在 2021 年增长 35% https://www.bleepingcomputer.com/news/security/linux-malware-sees-35-percent-growth-during-2021/ 9、Microsoft Defender 漏洞让黑客绕过恶意软件检测 https://www.bleepingcomputer.com/news/security/microsoft-defender-weakness-lets-hackers-bypass-malware-detection/ 10、乌克兰政府指责俄罗斯对其发动了网络攻击 https://thehackernews.com/2022/01/ukrainian-government-officially-accuses.html
网络安全日报 2022年01月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软发现了针对乌克兰的破坏性恶意软件活动 https://securityaffairs.co/wordpress/126782/apt/destructive-malware-campaign-targets-ukraine.html 2、新一波 Qlocker 勒索软件攻击针对 QNAP NAS 设备 https://securityaffairs.co/wordpress/126776/cyber-crime/qlocker-ransomware-attacks-qnap-nas.html 3、威胁参与者从 Lympo NTF 平台窃取了 1870 万美元 https://securityaffairs.co/wordpress/126766/cyber-crime/lympo-ntf-platform-hacked.html 4、Lorenz 勒索软件团伙窃取了国防承包商 Hensoldt 的文件 https://securityaffairs.co/wordpress/126738/malware/lorenz-ransomware-hit-hensoldt.html 5、俄罗斯 FSB 宣布摧毁了 REvil 勒索软件团伙和逮捕其成员 https://threatpost.com/russian-security-revil-ransomware/177660/ 6、亚马逊修复了 AWS Glue 服务中的安全漏洞 https://www.zdnet.com/article/amazon-fixes-security-flaw-in-aws-glue-service/#ftag=RSSbaffb68 7、钓鱼邮件利用Adobe Cloud针对Office 365用户 https://www.helpnetsecurity.com/2022/01/13/phishers-adobe-cloud/ 8、地下信用卡交易市场UniCC宣布关闭其业务 https://securityaffairs.co/wordpress/126757/cyber-crime/unicc-shutting-down.html 9、npm依赖项新版本导致React应用程序构建失败 https://www.bleepingcomputer.com/news/security/npm-dependency-is-breaking-some-react-apps-today-heres-the-fix/ 10、美国国土安全部前任官员窃取政府员工个人信息 https://www.bleepingcomputer.com/news/security/former-dhs-official-charged-with-stealing-govt-employees-pii/
网络安全日报 2022年01月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科修复了 Unified CCMP 和 Unified CCDM 中的高危漏洞 https://securityaffairs.co/wordpress/126684/security/cisco-unified-ccmp-unified-ccdm-flaw.html 2、Mozilla 修复了 Firefox、Thunderbird 高危漏洞 https://securityaffairs.co/wordpress/126671/security/mozilla-firefox-96-release.html 3、美国网络司令部称MuddyWater APT 与伊朗的情报安全部有关 https://securityaffairs.co/wordpress/126664/apt/muddywater-linked-to-iran-mois.html 4、ZDI 公布 Pwn2Own 2022 规则和奖品 https://www.securityweek.com/zdi-announces-rules-and-prizes-pwn2own-2022 5、2021 年,朝鲜 APT 窃取了约 4 亿美元的加密货币 https://threatpost.com/north-korea-apts-stole-400m-cryptocurrency/177638/ 6、研究人员解密了 Qakbot 银行木马的加密注册表项 https://thehackernews.com/2022/01/researchers-decrypted-qakbot-banking.html 7、海莲花黑客组织利用恶意Web存档文件部署后门 https://www.netskope.com/blog/abusing-microsoft-office-using-malicious-web-archive-files 8、Magniber勒索软件使用签名的APPX文件感染系统 https://www.bleepingcomputer.com/news/security/magniber-ransomware-using-signed-appx-files-to-infect-systems/ 9、苹果发布iOS和iPadOS软件更新修复HomeKit漏洞 https://thehackernews.com/2022/01/apple-releases-iphone-and-ipad-updates.html 10、出于安全原因,Chrome 将限制对私有网络的访问 https://therecord.media/chrome-will-limit-access-to-private-networks-citing-security-reasons/
网络安全日报 2022年01月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国当局警告称与俄有关的攻击者瞄准关键基础设施 https://securityaffairs.co/wordpress/126639/cyber-warfare-2/russia-linked-threat-actors-alert.html 2、APT35 组织利用 Log4Shell 漏洞部署新的PowerShell后门 https://securityaffairs.co/wordpress/126613/apt/apt35-log4shell-backdoor.html 3、Adobe 发布了安全更新以解决影响多个产品的高危漏洞 https://securityaffairs.co/wordpress/126593/security/adobe-reader-tianfu-cup.html 4、黑客使用云服务分发AsyncRAT 等恶意软件 https://thehackernews.com/2022/01/hackers-use-cloud-services-to.html 5、研究人员发现Redline Stealer恶意软件新变种 https://www.fortinet.com/blog/threat-research/omicron-variant-lure-used-to-distribute-redline-stealer 6、SysJoker后门针对Windows、Linux和macOS https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/ 7、微软发布1月补丁更新总共修复了96个漏洞 https://thehackernews.com/2022/01/first-patch-tuesday-of-2022-brings-fix.html 8、美国医学评论研究所数据泄露影响13.4万人信息 https://www.securityweek.com/mrioa-discloses-data-breach-affecting-134000-people 9、菲律宾选举委员会遭到黑客入侵泄露敏感数据 https://mb.com.ph/2022/01/10/comelec-servers-hacked-downloaded-data-may-include-information-that-could-affect-2022-elections/ 10、WordPress 5.8.3 新安全版本修复了四个漏洞 https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html
网络安全日报 2022年01月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft Patch Tuesday 修复了关键的 Office RCE https://securityaffairs.co/wordpress/126582/hacking/microsoft-patch-tuesday-office-rce.html 2、Night Sky 勒索软件 Log4Shell 攻击 VMware Horizon 服务器 https://securityaffairs.co/wordpress/126569/cyber-crime/night-sky-ransomware-log4shell.html 3、WordPress 5.8.3 安全版本修复了四个漏洞 https://securityaffairs.co/wordpress/126556/security/wordpress-5-8-3.html 4、专家发现 Abcbot 和 Xanthe 僵尸网络起源相同 https://securityaffairs.co/wordpress/126540/cyber-crime/abcbot-botnet-investigation.html 5、数百万路由器受 NetUSB 内核漏洞影响 https://www.securityweek.com/millions-routers-impacted-netusb-kernel-vulnerability 6、化妆品公司娇韵诗遭遇数据安全事件 https://www.channelnewsasia.com/singapore/clarins-data-security-incident-singapore-customers-personal-information-log4j-software-vulnerability-2428066 7、Linux版本AvosLocker勒索软件针对VMware ESXi https://www.bleepingcomputer.com/news/security/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers/ 8、研究人员发现广泛使用的URL解析器库中存在漏洞 https://thehackernews.com/2022/01/researchers-find-bugs-in-over-dozen.html 9、新的macOS漏洞可能导致未经授权访问用户数据 https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/ 10、3D打印软件Chitubox的插件存在缓冲区溢出漏洞 https://blog.talosintelligence.com/2022/01/vulnerability-spotlight-buffer-overflow.html
网络安全日报 2022年01月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、学校网站服务提供商Finalsite遭到勒索软件攻击 https://www.infosecurity-magazine.com/news/thousands-of-schools-it-provider/ 2、SonicWall证实其产品受到了Y2K22漏洞影响 https://securityaffairs.co/wordpress/126447/security/sonicwall-y2k22-bug.html 3、英国NHS发现针对VMWare Horizon服务器的攻击 https://therecord.media/uk-nhs-threat-actor-targets-vmware-horizon-servers-using-log4shell-exploits/ 4、Patchwork组织通过钓鱼邮件分发恶意软件 https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/ 5、美国新墨西哥州遭网络攻击关闭部分IT系统 https://www.infosecurity-magazine.com/news/cyberattack-on-new-mexico-county/ 6、快速窗口标题更改会导致电脑进入死机状态 https://www.bleepingcomputer.com/news/security/rapid-window-title-changes-cause-white-screen-of-death-/ 7、NPM库中的错误代码破坏了用户应用程序 https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/ 8、加利福尼亚州草谷市遭到黑客入侵数据泄露 https://yubanet.com/regional/grass-valley-reveals-extent-of-data-breach/ 9、美国在线药房服务公司Ravkoo披露数据泄露 https://www.securityweek.com/online-pharmacy-service-ravkoo-discloses-data-breach 10、美国两家公司联合推出首个量子计算机生成的加密密钥服务 https://www.cnbeta.com/articles/tech/1222981.htm
网络安全日报 2022年01月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新型勒索软件Night Sky以企业网络为目标 https://www.bleepingcomputer.com/news/security/night-sky-is-the-latest-ransomware-targeting-corporate-networks/ 2、在线预约安排平台FlexBooker遭到黑客入侵 https://securityaffairs.co/wordpress/126409/data-breach/flexbooker-data-breach.html 3、攻击者利用谷歌文档的注解功能进行网络钓鱼 https://threatpost.com/attackers-exploit-flaw-google-docs-comments/177412/ 4、不安全的AWS S3存储桶暴露了加纳公民信息 https://portswigger.net/daily-swig/insecure-amazon-s3-bucket-exposed-personal-data-on-500-000-ghanaian-graduates 5、FIN7组织利用恶意USB设备针对美国公司 https://securityaffairs.co/wordpress/126439/breaking-news/fin7-badusb-attacks.html 6、Norton 360在客户计算机安装加密货币矿工 https://securityaffairs.co/wordpress/126414/security/norton-crypto-cryptomining-feature-norton-360.html 7、Apache HTTP服务器中的漏洞可能导致RCE https://portswigger.net/daily-swig/internet-bug-bounty-high-severity-vulnerability-in-apache-http-server-could-lead-to-rce 8、研究人员发现木马化dnSpy应用分发恶意软件 https://www.bleepingcomputer.com/news/security/trojanized-dnspy-app-drops-malware-cocktail-on-researchers-devs/ 9、FluBot恶意软件通过虚假Flash Player应用传播 https://www.bleepingcomputer.com/news/security/flubot-malware-now-targets-europe-posing-as-flash-player-app/ 10、H2数据库控制台中存在一个严重的RCE漏洞 https://thehackernews.com/2022/01/log4shell-like-critical-rce-flaw.html
网络安全日报 2022年01月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、与朝鲜有关的 Konni APT 以俄罗斯外交机构为目标 https://securityaffairs.co/wordpress/126388/apt/konni-apt-russia-entities.html 2、网络攻击者从 17 家知名公司窃取了 110 万个客户账户 https://securityaffairs.co/wordpress/126381/cyber-crime/credential-stuffing-ny-oag-report.html 3、Google Docs 评论功能在网络钓鱼活动中被滥用 https://securityaffairs.co/wordpress/126375/hacking/google-docs-comment-phishing.html 4、法国数据隐私机构对谷歌和 Facebook 处以2.37亿美元罚款 https://securityaffairs.co/wordpress/126371/digital-id/france-cnil-google-facebook-fines.html 5、安全研究员发现Java RMI 服务容易受到 SSRF 攻击 https://portswigger.net/daily-swig/java-rmi-services-often-vulnerable-to-ssrf-attacks 6、开源操作系统FreeRTOS中存在多个安全漏洞 https://cybersguards.com/the-freertos-vulnerability-disaster/ 7、本田和讴歌汽车遭遇Y2K22错误导航系统时间被重置到2002年 https://www.bleepingcomputer.com/news/technology/honda-acura-cars-hit-by-y2k22-bug-that-rolls-back-clocks-to-2002/ 8、FTC警告各公司要确保消费者数据免受 Log4J 攻击 https://www.bleepingcomputer.com/news/security/ftc-warns-companies-to-secure-consumer-data-from-log4j-attacks/ 9、DatPiff 数据泄露会影响到数百万人 https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-datpiff-data-breach-impacting-millions/ 10、FBI 秘密收集全球 GPS 数据 https://www.vice.com/en/article/93b3ay/fbi-backdoor-anom-phones-gps-data