网络安全日报 2022年01月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware 修复了 Workstation、Fusion 和 ESXi 中的堆溢出漏洞 https://securityaffairs.co/wordpress/126352/security/vmware-cve-2021-22045-heap-overflow.html 2、微软警告称利用Log4j漏洞进行攻击的活动依然活跃 https://securityaffairs.co/wordpress/126333/breaking-news/log4j-flaws-attacks.html 3、研究人员演示了如何使用 IoT 设备的电磁辐射来检测恶意软件 https://securityaffairs.co/wordpress/126312/malware/electromagnetic-signals-iot-malware-classification.html 4、恶意软件通过“NoReboot”技术伪造iPhone关机 https://www.securityweek.com/malware-can-fake-iphone-shutdown-noreboot-technique 5、Zloader 银行恶意软件利用 Microsoft 签名验证 https://www.securityweek.com/zloader-banking-malware-exploits-microsoft-signature-verification 6、Google Chrome 发布97版本修补 37 个漏洞 https://www.securityweek.com/chrome-97-patches-37-vulnerabilities 7、谷歌发布2022年首次Android更新,修补48个漏洞 https://www.securityweek.com/google-patches-48-vulnerabilities-first-set-2022-android-updates 8、新的供应链攻击中使用Skimmer针对房地产网站 https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/ 9、Windows Server带外更新修复了远程桌面问题 https://www.bleepingcomputer.com/news/microsoft/emergency-windows-server-update-fixes-remote-desktop-issues/ 10、连锁酒店McMenamins遭到勒索软件攻击数据泄露 https://securityaffairs.co/wordpress/126293/data-breach/hospitality-chain-mcmenamins-data-breach.html
网络安全日报 2022年01月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、UScellular 披露一年内第二次数据泄露 https://securityaffairs.co/wordpress/126317/data-breach/uscellular-second-data-breach-2021.html 2、Purple Fox 后门利用虚假 Telegram 应用安装程序传播 https://securityaffairs.co/wordpress/126299/cyber-crime/purple-fox-telegram-installer.html 3、Broward Health 披露影响超过130W人的大规模数据泄露事件 https://securityaffairs.co/wordpress/126285/data-breach/broward-health-data-breach.html 4、十三部门修订发布《网络安全审查办法》将于2022年2月15日施行 https://www.freebuf.com/news/318187.html 5、耶路撒冷邮报和以色列日报Maariv遭黑客攻击 https://www.hackread.com/hackers-jerusalem-post-maariv-hacked-soleimani-anniversary/ 6、专家表示从网页复制粘贴命令可能会被黑客攻击 https://www.bleepingcomputer.com/news/security/dont-copy-paste-commands-from-webpages-you-can-get-hacked/ 7、SEGA Europe由于配置错误暴露用户的个人信息 https://securityaffairs.co/wordpress/126258/data-breach/sega-europe-aws-s3-bucket-data-leak.html 8、日本惠普超算系统出错,京都大学多达77TB数据被误删 https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/ 9、FBI虚假聊天APP——ANOM的推特账户被黑了 https://www.bleepingcomputer.com/news/security/twitter-account-of-fbis-fake-chat-app-anom-seen-trolling-today/ 10、研究人员发现Uber电子邮件系统存在漏洞 https://www.bleepingcomputer.com/news/security/uber-ignores-vulnerability-that-lets-you-send-any-email-from-ubercom/
网络安全日报 2022年01月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、多个漏洞影响 Netgear Nighthawk R6700 路由器 https://www.securityweek.com/multiple-vulnerabilities-impact-netgear-nighthawk-r6700-routers 2、研究人员发现影响 iOS 15.2-14.7 的持久性DoS漏洞-"doorLock" https://securityaffairs.co/wordpress/126275/hacking/doorlock-persistent-dos-ios.html 3、微软发布紧急补丁修复Exchange中的Y2k22 漏洞 https://securityaffairs.co/wordpress/126248/security/y2k22-bug-temporary-fix.html 4、美国宇航局局长推特账户被希腊黑客入侵 https://securityaffairs.co/wordpress/126243/hacking/nasa-director-hacked-by-powerful-greek-army.html 5、Lapsus$ 勒索软件攻击了葡萄牙最大的媒体集团 Impresa https://securityaffairs.co/wordpress/126236/cyber-crime/impresa-lapsus-ransomware.html 6、RedLine 恶意软件从多种浏览器中窃取保存的密码 https://cyware.com/news/redline-malware-pilfer-passwords-saved-in-multiple-browsers-20a370e4 7、研究人员介绍了如何在SSD隐藏区域中植入恶意软件 https://securityaffairs.co/wordpress/126170/hacking/ssds-flex-capacity-feature-attacks.html 8、日本京都大学由于备份系统出现错误丢失了约77TB数据 https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/ 9、Cox媒体集团证实遭到了伊朗黑客的攻击 https://therecord.media/iranian-hackers-behind-cox-media-group-ransomware-attack/ 10、在线商店PulseTV披露客户信用卡泄露事件 https://www.bleepingcomputer.com/news/security/pulsetv-discloses-potential-compromise-of-200-000-credit-cards/
网络安全日报 2021年12月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、DataVault 加密软件中的漏洞影响多个品牌的存储设备 https://securityaffairs.co/wordpress/126166/hacking/datavault-encryption-software-flaws.html 2、新的iLOBleed Rootkit针对 HP Enterprise 服务器进行攻击 https://securityaffairs.co/wordpress/126157/malware/ilobleed-wiper-hp-servers.html 3、附属机构攻击美国政府机构后,AvosLocker发布了免费解密器 https://securityaffairs.co/wordpress/126154/cyber-crime/avoslocker-ransomware-gang-free-decryptor.html 4、RedLine恶意软件可窃取存储在浏览器中的密码 https://www.bleepingcomputer.com/news/security/redline-malware-shows-why-passwords-shouldnt-be-saved-in-browsers/ 5、密码管理器LastPass在调查后确认没有帐户被盗 https://www.govinfosecurity.com/lastpass-no-user-accounts-have-been-compromised-a-18218 6、T-Mobile遭受SIM交换攻击导致客户数据被泄露 https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/ 7、好购App未经许可读取用户手机剪贴板内容,法院认定侵害隐私权 http://epaper.legaldaily.com.cn/fzrb/content/20211229/Articel06002GN.htm 8、六部门“净网”行动成果数据公布:清理网络有害信息1000 余万条 https://www.ithome.com/0/595/099.htm 9、【2021中国白帽子调查报告】正式发布 https://www.freebuf.com/articles/paper/317785.html 10、波兰政客被NSO Group间谍软件攻击 https://www.zdnet.com/article/nso-spyware-used-to-hack-polish-politicians-wife-of-khashoggi-un-war-crimes-investigator-and-more/
网络安全日报 2021年12月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、T-Mobile 披露了新的数据泄露事件 https://securityaffairs.co/wordpress/126140/cyber-crime/t-mobile-suffered-data-breach.html 2、Apache Log4j 2.17.1 修复了新的任意代码执行漏洞 https://securityaffairs.co/wordpress/126135/hacking/new-apache-log4j-cve-2021-44832.html 3、挪威媒体公司 Amedia遭网络攻击导致报纸无法按时发行 https://securityaffairs.co/wordpress/126130/hacking/amedia-cyberattack.html 4、越南最大的加密交易平台之一ONUS遭受网络攻击 https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/ 5、三星Galaxy商店存在恶意的Android流媒体应用程序 https://www.bleepingcomputer.com/news/security/riskware-android-streaming-apps-found-on-samsungs-galaxy-store/ 6、波兰政府被指使用Pegasus入侵反对派团体成员设备 https://www.cnbeta.com/articles/tech/1219459.htm 7、报告:近七成网民感到被算法算计 https://finance.sina.com.cn/tech/2021-12-28/doc-ikyamrmz1696681.shtml 8、Apache联合创始人呼吁合作防止Log4Shell问题再次发生 https://www.cnbeta.com/articles/tech/1219713.htm 9、MinIO存在权限提升漏洞 https://nvd.nist.gov/vuln/detail/CVE-2021-43858 10、隐瞒数据泄露,前优步CSO面临重罪指控 https://www.secrss.com/articles/37647
网络安全日报 2021年12月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LastPass 证实其用户遭撞库攻击 https://securityaffairs.co/wordpress/126116/hacking/lastpass-hacking-attempts.html 2、攻击者利用MSBuild 来执行 Cobalt Strike Beacons https://securityaffairs.co/wordpress/126104/hacking/msbuild-cobalt-strike-beacons.html 3、 跨国物流巨头 DW Morgan 遭数据泄露 https://securityaffairs.co/wordpress/126086/data-breach/d-w-morgan-data-leak.html 4、QNAP NAS设备遭eCh0raix 勒索软件攻击数量激增 https://www.bleepingcomputer.com/news/security/qnap-nas-devices-hit-in-surge-of-ech0raix-ransomware-attacks 5、研究人员发现超过1200个能够绕过2FA的网络钓鱼工具包 https://therecord.media/more-than-1200-phishing-toolkits-capable-of-intercepting-2fa-detected-in-the-wild/ 6、DuckDuckGo发展迅速,2021年使用量增长46% https://www.freebuf.com/news/317458.html 7、研究人员介绍了名为DoubleFeature的受害者机器诊断工具 https://thehackernews.com/2021/12/experts-detail-logging-tool-of.html 8、Telegram 被滥用于窃取加密货币钱包凭据 https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/ 9、RSA 会议推迟到2022年6月 https://therecord.media/rsa-conference-postponed-to-june/ 10、Dridex网络钓鱼活动利用COVID-19葬礼援助热线引诱目标 https://cyware.com/news/not-so-funny-funeral-scam-by-dridex-818858df
网络安全日报 2021年12月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新一波 ech0raix 勒索软件攻击以 QNAP NAS 设备为目标 https://securityaffairs.co/wordpress/126081/malware/ech0raix-ransomware-targeting-qnap-nas.html 2、DuckDuckGo 将发布桌面浏览器 https://www.securityweek.com/duckduckgo-signals-entry-desktop-browser-market 3、EVlink 电动汽车充电站存在漏洞可导致远程攻击 https://www.securityweek.com/new-flaws-expose-evlink-electric-vehicle-charging-stations-remote-hacking 4、新的 Blister 恶意软件活动针对 Windows https://cyware.com/news/new-blister-campaign-stealthily-targets-windows-c9297496 5、摄影和个性化照片巨头Shutterfly遭受Conti勒索软件攻击 https://www.bleepingcomputer.com/news/security/shutterfly-services-disrupted-by-conti-ransomware-attack/ 6、俄罗斯社交软件VK强制上线双因素认证 https://www.bleepingcomputer.com/news/security/vk-introduces-2fa-and-plans-to-make-it-mandatory-in-2022/ 7、研究人员发现Rook勒索软件和Babuk有很多相似之处 https://securityaffairs.co/wordpress/125988/malware/rook-ransomware-based-on-babuk.html 8、央视曝光部分App禁止全部权限仍可获取用户信息 https://www.cnbeta.com/articles/tech/1218775.htm 9、阿尔巴尼亚总理就近期政府数据大规模泄露致歉 https://www.securityweek.com/albanian-prime-minister-apologizes-over-database-leak 10、新的 Android 银行恶意软件针对巴西 Itaú Unibanco 银行 https://securityaffairs.co/wordpress/126040/malware/android-banking-malware-brazil.html
网络安全日报 2021年12月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客利用Echelon信息窃取程序针对Telegram用户的加密钱包 https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/ 2、法国 IT 服务提供商 Inetum 遭受 BlackCat 勒索软件攻击 https://securityaffairs.co/wordpress/126022/cyber-crime/inetum-hit-by-blackcat-ransomware.html 3、Apple 修复了 macOS 的 Gatekeeper 安全功能绕过漏洞 https://securityaffairs.co/wordpress/126004/security/macos-gatekeeper-bypass-2.html 4、Fisher Price Chatter 蓝牙电话存在严重的隐私问题 https://securityaffairs.co/wordpress/125967/hacking/fisher-price-chatter-bluetooth-telephone-bugs.html 5、WordPress平台Flywheel存在子域名接管漏洞 https://portswigger.net/daily-swig/popular-wordpress-platform-flywheel-vulnerable-to-subdomain-takeover-researcher-claims 6、Apache发布安全更新修复了HTTP Server的两个漏洞 https://www.zdnet.com/article/apaches-new-security-update-for-http-server-fixes-two-flaws/ 7、捷克工业自动化公司mySCADA的myPRO产品存在多个漏洞 https://www.securityweek.com/several-critical-vulnerabilities-found-mypro-hmiscada-product 8、新的Blister恶意软件使用代码签名证书来逃避检测 https://thehackernews.com/2021/12/new-blister-malware-using-code-signing.html 9、Blackmagic修复了关键的DaVinci Resolve代码执行漏洞 https://www.bleepingcomputer.com/news/security/blackmagic-fixes-critical-davinci-resolve-code-execution-flaws/ 10、Android银行木马通过虚假的Google Play页面传播 https://www.bleepingcomputer.com/news/security/android-banking-trojan-spreads-via-fake-google-play-store-page/
网络安全日报 2021年12月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、AvosLocker 勒索软件重启系统到安全模式并安装远控 https://securityaffairs.co/wordpress/125937/malware/avoslocker-ransomware-safe-mode.html 2、研究人员披露 Microsoft Teams 软件中未修补的漏洞 https://thehackernews.com/2021/12/researchers-disclose-unpatched.html 3、NVIDIA、HPE 产品受 Log4j 漏洞影响 https://www.securityweek.com/nvidia-hpe-products-affected-log4j-vulnerabilities 4、攻击者利用《蜘蛛侠:英雄无归》钓鱼传播Cryptominer恶意软件 https://threatpost.com/spider-man-no-way-home-download-installs-cryptominer/177254 5、攻击者绕过Office 补丁( CVE-2021-40444)传播 Formbook 恶意软件 https://securityaffairs.co/wordpress/125927/malware/ms-office-cve-2021-40444-bypass-malware.html 6、费森尤斯卡比的Agilia Connect输液系统被发现存在十几个漏洞 https://www.govinfosecurity.com/fda-cisa-warn-fresenius-kabi-infusion-pump-flaws-a-18185 7、加纳国家服务秘书处由于数据库配置错误泄露了55GB公民数据 https://www.hackread.com/ghana-govt-agency-citizens-data-leak/ 8、严重的 Apache HTTPD 漏洞可能导致 RCE、DoS https://threatpost.com/apache-httpd-server-bugs-rce-dos/177234/ 9、五眼联盟发布关于 Log4j 漏洞的联合指南 https://www.securityweek.com/five-eyes-nations-issue-joint-guidance-log4j-vulnerabilities 10、研究人员在 myPRO HMI/SCADA 产品中发现多个严重漏洞 https://www.securityweek.com/several-critical-vulnerabilities-found-mypro-hmiscada-product
网络安全日报 2021年12月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 发布扫描器以识别受Log4jShell影响的 Web 服务 https://securityaffairs.co/wordpress/125892/security/cisa-scanner-log4j-flaws.html2、微软确认"NotLegit" Azure 漏洞导致源代码库暴露 https://www.securityweek.com/microsoft-confirms-notlegit-azure-flaw-exposed-source-code-repositories3、PYSA团伙是11月最活跃的勒索软件团伙 https://securityaffairs.co/wordpress/125877/malware/pysa-ranomware-spike-nov-2021.html4、新漏洞可绕过关键 Microsoft MSHTML 漏洞的补丁 https://thehackernews.com/2021/12/new-exploit-lets-malware-attackers.html5、NVIDIA 披露受 Log4jShell影响的应用程序 https://www.bleepingcomputer.com/news/security/nvidia-discloses-applications-impacted-by-log4j-vulnerability/6、Evil Corp 伪装成 REvil 来逃避制裁 https://www.scmagazine.com/analysis/ransomware/evil-corp-is-dodging-sanctions-by-dressing-up-as-revil7、谷歌修复了 Chrome 站点隔离绕过漏洞 https://portswigger.net/daily-swig/safe-browsing-google-fixes-chrome-site-isolation-bypass-bug8、All in One SEO 插件严重漏洞影响数百万个WordPress网站 https://blog.sucuri.net/2021/12/critical-vulnerabilities-in-all-in-one-seo-plugin-affects-millions-of-wordpress-websites.html9、DaVinci Resolve 视频编辑软件中存在代码执行漏洞 https://blog.talosintelligence.com/2021/12/vuln-spotlight-davinci-resolve.html10、Android版本的Facebook存在不安全的直接对象引用漏洞 https://www.securityweek.com/facebook-patches-vulnerability-exposing-page-admin-identity