网络安全日报 2021年12月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软敦促客户修补最近的 Active Directory 漏洞 https://www.securityweek.com/microsoft-urges-customers-patch-recent-active-directory-vulnerabilities 2、Garrett 步行通过式金属探测器受潜在严重漏洞的影响 https://www.securityweek.com/vulnerabilities-can-allow-hackers-tamper-walk-through-metal-detectors 3、研究人员在德国 Auerswald VoIP 系统中发现秘密后门 https://thehackernews.com/2021/12/secret-backdoors-found-in-german-made.html 4、育碧披露《舞力全开》游戏涉及客户信息的数据泄露 https://portswigger.net/daily-swig/ubisoft-confirms-just-dance-video-game-data-breach 5、新的 Abcbot 僵尸网络以阿里、腾讯等云平台托管的 Linux 服务器为目标 https://therecord.media/new-abcbot-botnet-goes-after-chinese-cloud-providers/ 6、WSL 中运行的 Visual Studio Code server 被发现存在 RCE 漏洞 https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit/ 7、网络钓鱼活动冒充辉瑞公司窃取商业和财务信息 https://www.bleepingcomputer.com/news/security/phishing-attacks-impersonate-pfizer-in-fake-requests-for-quotation/ 8、英国国家犯罪署与HIBP网站分享了超过5.85亿个被盗密码 https://therecord.media/the-nca-shares-585-million-passwords-with-have-i-been-pwned/ 9、美国医疗保健提供商Texas ENT超50万患者数据遭泄露 https://portswigger.net/daily-swig/healthcare-provider-texas-ent-alerts-535-000-patients-to-data-breach 10、研究发现多个K-12学校应用存在严重的安全风险 https://therecord.media/study-finds-serious-security-risks-in-k-12-school-apps/
网络安全日报 2021年12月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、勒索软件运营商泄露了从物流巨头 Hellmann 窃取的数据 https://www.securityweek.com/ransomware-operators-leak-data-stolen-logistics-giant-hellmann 2、比利时国防部遭受利用 Log4Shell 的网络攻击 https://securityaffairs.co/wordpress/125813/cyber-warfare-2/belgian-defense-ministry-hit-cyberattack.html 3、研究人员发现新的安全漏洞影响 2G 及之后所有蜂窝网络 https://thehackernews.com/2021/12/new-mobile-network-vulnerabilities.html 4、一种新的攻击方法可利用本地服务器上的 Log4Shell 漏洞 https://securityaffairs.co/wordpress/125800/hacking/log4shell-vulnerability-attack-vector.html 5、Apache已发布Log4j 2.17版本修复了一个拒绝服务漏洞 https://www.govinfosecurity.com/time-to-patch-again-apache-releases-217-fixing-dos-a-18153 6、西部数据敦促客户更新他们的My Cloud设备 https://www.bleepingcomputer.com/news/security/western-digital-warns-customers-to-update-their-my-cloud-devices/ 7、德国音响科技巨头森海塞尔55GB客户数据遭泄露 https://www.hackread.com/german-audio-tech-sennheiser-expose-customers-data/ 8、VMware 修补 Workspace ONE Access 中的多个漏洞 https://www.securityweek.com/vmware-patches-vulnerabilities-workspace-one-access 9、TellYouThePass 勒索软件正利用 Log4Shell卷土重来 https://www.freebuf.com/articles/316267.html 10、国家工信安全中心发布《网络安全威胁情报行业发展报告(2021年)》 http://www.etiri.com.cn/web_root/webpage/articlecontent_101006_1470613962792898561.html
网络安全日报 2021年12月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware 修补了 Workspace ONE UEM 控制台中的严重漏洞 https://www.securityweek.com/vmware-patches-critical-flaw-workspace-one-uem-console 2、Clop 勒索软件团伙正在泄露英国警方的机密数据 https://securityaffairs.co/wordpress/125792/cyber-crime/clop-ransomware-uk-police.html 3、Apache 发布第三个补丁修复新的 Log4j2 漏洞 https://securityaffairs.co/wordpress/125760/hacking/log4j-third-flaw.html 4、Conti 勒索软件利用Log4Shell漏洞攻击vCenter服务器 https://securityaffairs.co/wordpress/125741/cyber-crime/conti-ransomware-exploit-log4shell.html 5、无文件恶意软件DarkWatchman利用Windows注册表逃避检测 https://thehackernews.com/2021/12/new-fileless-malware-uses-windows.html 6、NSO零点击iMessage漏洞影响iOS 14.7.1及更早版本 https://www.hackread.com/nso-zero-click-imessage-exploit-hack-iphone-no-click/ 7、Hive勒索软件团伙在四个月内入侵了数百个组织 https://www.bleepingcomputer.com/news/security/hive-ransomware-enters-big-league-with-hundreds-breached-in-four-months/ 8、Joker恶意软件潜伏在Color Message应用程序中向用户收费 https://threatpost.com/malicious-joker-app-downloads-google-play/177139/ 9、网络安全公司Avast在美国联邦机构网络中发现后门 https://www.govinfosecurity.com/backdoor-discovered-in-us-federal-agency-network-a-18147 10、谷歌表示超过35000个Java包受Log4j漏洞的影响 https://therecord.media/google-more-than-35000-java-packages-impacted-by-log4j-vulnerabilities/
网络安全日报 2021年12月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新型"PseudoManuscrypt"间谍软件针对数千计的工业系统 https://www.securityweek.com/thousands-industrial-systems-targeted-new-pseudomanuscrypt-spyware 2、MuddyWater组织利用Aclip后门攻击航空公司 https://www.securityweek.com/iran-linked-apt-abuses-slack-attacks-asian-airline 3、联想笔记本电脑ImControllerService服务存在漏洞可用于提权 https://securityaffairs.co/wordpress/125711/hacking/lenovo-laptops-privileges-escalation-flaws.html 4、丙烷气体分销商Superior Plus遭到勒索软件攻击 https://www.darkreading.com/attacks-breaches/propane-distributor-hit-with-ransomware 5、研究表明对抗性攻击会使人工智能和医生作出错误诊断 https://www.govinfosecurity.com/study-attacks-manipulate-medical-imaging-ai-outcomes-a-18131 6、攻击者利用网络钓鱼活动分发Agent Tesla恶意程序 https://www.bleepingcomputer.com/news/security/phishing-campaign-uses-powerpoint-macros-to-drop-agent-tesla/ 7、FBI 意外发现HelloKitty 勒索软件团伙疑似在乌克兰境外活动 https://securityaffairs.co/wordpress/125675/cyber-crime/hellokitty-ransomware-ukraine.html 8、黑客利用 Log4J 漏洞发动大规模网络攻击 https://arstechnica.com/information-technology/2021/12/hackers-launch-over-840000-attacks-through-log4j-flaw/ 9、攻击者通过击溃Ubuntu 的AccountsService 获得 root https://www.bleepingcomputer.com/news/security/grafana-fixes-zero-day-vulnerability-after-exploits-spread-over-twitter/ 10、Ascendex加密货币交易所遭到黑客攻击-7700万美元被盗 https://www.hackread.com/ascendex-cryptocurrency-exchange-hacked/
网络安全日报 2021年12月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软发现多个利用 Log4j2 漏洞的国家级别 APT https://www.securityweek.com/microsoft-spots-multiple-nation-state-apts-exploiting-log4j-flaw 2、SAP 修补了受 Log4Shell 漏洞影响的20 个应用程序 https://www.securityweek.com/sap-patches-log4shell-vulnerability-20-applications 3、黑客使用恶意 IIS 模块窃取 Microsoft Exchange 凭据 https://thehackernews.com/2021/12/hackers-using-malicious-iis-server.html 4、Anubis安卓银行木马针对数百个金融应用程序进行攻击 https://thehackernews.com/2021/12/update-google-chrome-to-patch-new-zero.html 5、美国阿片类药物门诊治疗中心BHG遭受网络攻击 https://www.bleepingcomputer.com/news/security/cyberattack-on-bhg-opioid-treatment-network-disrupts-patient-care/ 6、勒索软件Khonsari和Nemesis Kitten正在利用Log4j2漏洞 https://www.zdnet.com/article/khonsari-ransomware-iranian-group-nemesis-kitten-seen-exploiting-log4j/ 7、Log4j2 被发现新的DoS漏洞(CVE-2021-45046) https://thehackernews.com/2021/12/second-log4j-vulnerability-cve-2021.html 8、美国国土安全部宣布推出"Hack DHS"漏洞赏金计划 https://securityaffairs.co/wordpress/125646/security/hack-dhs-bug-bounty-program.html 9、quebec因Log4Shell漏洞被披露而关闭了数千个网站 https://securityaffairs.co/wordpress/125556/hacking/quebec-shut-down-sites-log4shell.html 10、REvil 勒索软件分支机构在罗马尼亚被捕 https://thehackernews.com/2021/12/ransomware-affiliate-arrested-in.html
网络安全日报 2021年12月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二补丁日修复了7个关键安全漏洞 https://threatpost.com/exploited-microsoft-zero-day-spoofing-malware/177045/ 2、已有数十个僵尸网络在利用Log4j2漏洞进行攻击 https://threatpost.com/log4shell-attacks-origin-botnet/176977/ 3、Apple iOS 更新修复了 iPhone 远程越狱漏洞 https://thehackernews.com/2021/12/latest-apple-ios-update-patches-remote.html 4、伊朗 APT 在网络间谍活动中瞄准中东电信运营商 https://www.securityweek.com/iranian-apt-targets-middle-east-telecoms-operators-espionage-campaign 5、Chrome 96 更新补丁修复了0day漏洞 https://www.securityweek.com/chrome-96-update-patches-exploited-zero-day-vulnerability 6、制造业和工控软件受Log4j2漏洞影响 https://www.securityweek.com/industrial-organizations-targeted-log4shell-attacks 7、Adobe更新修复了多个产品中的 60 多个漏洞 https://securityaffairs.co/wordpress/125640/security/adobe-60-vulnerabilities-multiple-products.html 8、TinyNuke银行恶意软件针对法国实体进行攻击 https://www.proofpoint.com/us/blog/threat-insight/tinynuke-banking-malware-targets-french-entities 9、加密货币交易所Ascendex遭受网络攻击 https://www.hackread.com/ascendex-cryptocurrency-exchange-hacked/ 10、CISA 命令联邦机构在 12 月 24 日之前修复 Log4j2 漏洞 https://securityaffairs.co/wordpress/125623/security/cisa-log4shell-actions.html
网络安全日报 2021年12月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、苹果在最新的 iOS 更新中修补了 42 个安全漏洞 https://www.securityweek.com/apple-patches-42-security-flaws-latest-ios-refresh 2、CISA 将 Log4Shell添加到已知被利用漏洞目录 https://securityaffairs.co/wordpress/125577/security/log4shell-known-exploited-vulnerabilities-catalog.html 3、Log4Shell 至少在公开披露前 9 天就已被在野利用 https://securityaffairs.co/wordpress/125567/hacking/log4shell-log4j-exploitation.html 4、 Muhstik 和 Mirai 僵尸网络已经利用Log4Shell进行攻击 https://securityaffairs.co/wordpress/125562/malware/linux-botnets-log4shell-flaw.html 5、研究人员发现新的WiFi芯片漏洞,影响数十亿设备 https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html 6、食品巨头遭勒索软件攻击导致美国陷入奶油奶酪供应短缺 https://gizmodo.com/ransomware-jerks-helped-cause-the-cream-cheese-shortage-1848195368 7、Hillrom心脏保健设备中的漏洞可导致攻击者控制设备 https://portswigger.net/daily-swig/zero-day-vulnerability-in-hillrom-cardiology-devices-could-allow-attackers-full-control 8、考克斯通信向受到数据泄露影响的客户发送通知 https://www.forbes.com/sites/leemathews/2021/12/11/hacker-poses-as-support-rep-to-breach-cox-communications/ 9、Qakbot木马在其构建模块中添加了勒索功能 https://www.zdnet.com/article/this-decade-old-malware-has-picked-up-some-nasty-new-tricks/ 10、恶意Notepad++安装程序推送StrongPity恶意软件 https://www.bleepingcomputer.com/news/security/malicious-notepad-plus-plus-installers-push-strongpity-malware/
网络安全日报 2021年12月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WD 更新 SanDisk SecureAccess 以防止字典和暴力攻击 https://www.securityweek.com/wd-updates-sandisk-secureaccess-prevent-dictionary-brute-force-attacks 2、黑客窃取了瑞典沃尔沃汽车的研究数据 https://www.securityweek.com/hackers-steal-research-data-swedens-volvo-cars 3、研究人员发现一种新的基于 Rust 的勒索软件:BlackCat https://thehackernews.com/2021/12/blackcat-new-rust-based-ransomware.html 4、网络钓鱼活动针对使用二维码的德国银行客户 https://securityaffairs.co/wordpress/125540/cyber-crime/phishing-qr-codes.html 5、新的"Karakurt"网络犯罪团伙专注于数据盗窃和勒索 https://securityaffairs.co/wordpress/125518/cyber-crime/karakurt-cybercrime-gang.html 6、过去几天 160 万个 WordPress 网站遭大规模攻击 https://securityaffairs.co/wordpress/125469/hacking/wordpress-sites-under-attack.html 7、巴西卫生部遭受网络攻击,COVID-19疫苗接种数据被删除 https://www.zdnet.com/article/brazilian-ministry-of-health-suffers-cyberattack-and-covid-19-vaccination-data-vanishes/ 8、研究表明有一半的网站仍在使用旧版加密密钥 https://www.infosecurity-magazine.com/news/half-of-websites-still-using/ 9、富士通在日本政府数据泄露后停止使用ProjectWEB工具 https://www.zdnet.com/article/fujitsu-attributes-data-breaches-to-projectweb-vulnerabilities/ 10、俄罗斯封锁隐私服务Tor以加强互联网控制 https://thehackernews.com/2021/12/russia-blocks-tor-privacy-service-in.html
网络安全日报 2021年12月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、广泛应用的日志框架Log4j2 被发现严重远程代码执行漏洞 https://help.aliyun.com/noticelist/articleid/1060971232.html 2、Mozilla 修补 Firefox 和 Thunderbird 中的高危漏洞 https://www.securityweek.com/mozilla-patches-high-severity-vulnerabilities-firefox-thunderbird 3、"Moobot"僵尸网络通过最近的漏洞攻击海康威视设备 https://www.securityweek.com/moobot-botnet-targets-hikvision-devices-recent-vulnerability 4、Dark Mirai 僵尸网络利用 TP-Link 路由器的 RCE 漏洞进行传播 https://securityaffairs.co/wordpress/125450/malware/dark-mirai-botnet-tp-link.html 5、数十个恶意 NPM 包劫持 Discord 令牌 https://threatpost.com/malicious-npm-code-packages-discord/176886/ 6、微软温哥华服务器上的DS_STORE文件泄露网站凭据 https://securityaffairs.co/wordpress/125420/data-breach/microsoft-vancouver-data-leak.html 7、微软和 GitHub 的 OAuth 2.0 实现存在缺陷可被恶意利用 https://www.proofpoint.com/us/blog/cloud-security/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection 8、Salt安全报告揭示了GraphQL API的漏洞 https://securityboulevard.com/2021/12/salt-security-report-surfaces-graphql-api-vulnerabilities/ 9、超过 300,000 台 MikroTik 设备易受到远程利用漏洞攻击 https://thehackernews.com/2021/12/over-300000-mikrotik-devices-found.html 10、 新型Cerber 勒索软件以 Confluence 和 GitLab 服务器为目标 https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/
网络安全日报 2021年12月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Android 安全更新修补了 46 个漏洞 https://www.securityweek.com/android-security-updates-patch-46-vulnerabilities 2、SonicWall 敦促客户为 SMA 100 设备安装安全补丁 https://securityaffairs.co/wordpress/125400/security/sonicwall-sma-100-devices-flaws.html 3、Grafana 发布紧急安全补丁修复高危漏洞 https://therecord.media/grafana-releases-security-patch-after-exploit-for-severe-bug-goes-public 4、苹果移动设备管理平台Jamf Pro存在SSRF漏洞 https://portswigger.net/daily-swig/ssrf-vulnerability-patched-in-jamf-pro-mobile-security-platform 5、谷歌发布Chrome安全更新修复了20个漏洞 https://www.securityweek.com/google-patches-serious-use-after-free-vulnerabilities-chrome 6、呼叫中心软件套件GOautodial被发现多个漏洞 https://www.infosecurity-magazine.com/news/vulnerabilities-found-in-goautodial/ 7、Gartner预测,到2025年30%的关基设施将遭遇安全漏洞 https://www.gartner.com/en/newsroom/press-releases/2021-12-2-gartner-predicts-30--of-critical-infrastructure-organi 8、恶意的Excel XLL插件推送RedLine密码窃取恶意软件 https://www.bleepingcomputer.com/news/security/malicious-excel-xll-add-ins-push-redline-password-stealing-malware/ 9、新的推特网络钓鱼活动针对已验证的帐户 https://www.bleepingcomputer.com/news/security/new-twitter-phishing-campaign-targets-verified-accounts/ 10、Emotet 改变策略,直接投放 Cobalt Strike Beacons https://cyware.com/news/emotet-needs-no-intermediate-trojan-drops-cobalt-strike-beacons-directly-7d55fb47