网络安全日报 2021年12月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Firefox 95 推出新的“RLBox”隔离功能 https://www.securityweek.com/firefox-95-rolls-out-new-isolation-feature-rlbox 2、谷歌修补了 Chrome 中严重的 Use-After-Free 漏洞 https://www.securityweek.com/google-patches-serious-use-after-free-vulnerabilities-chrome 3、谷歌宣布破坏了 Glupteba 僵尸网络 https://securityaffairs.co/wordpress/125377/malware/glupteba-botnet-take-down.html 4、Eltima SDK 漏洞影响多个云服务提供商 https://thehackernews.com/2021/12/eltima-sdk-contain-multiple.html 5、LINE Pay 在 GitHub 上泄露了日本、台湾和泰国用户的支付数据 https://www.theregister.com/2021/12/07/line_pay_leaks_around_133000/ 6、APT组织Nobelium使用Ceeloader恶意软件进行攻击 https://securityaffairs.co/wordpress/125352/apt/nobelium-custom-malware.html 7、古巴勒索软件团伙入侵了 49 个美国关键基础设施组织 https://securityaffairs.co/wordpress/125274/cyber-crime/cuba-ransomware-fbi-flash-alert.html 8、黑客利用虚假的Office 365垃圾邮件警报进行网络钓鱼 https://www.bleepingcomputer.com/news/security/convincing-microsoft-phishing-uses-fake-office-365-spam-alerts/ 9、网络钓鱼攻击者开始利用新冠病毒变种话题 https://www.bleepingcomputer.com/news/security/phishing-actors-start-exploiting-the-omicron-covid-19-variant/ 10、科罗拉多能源公司遭破环性网络攻击后丢失了25年的数据 https://www.zdnet.com/article/colorado-energy-company-loses-25-years-of-data-after-cyberattack-still-rebuilding-network/
网络安全日报 2021年12月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、恶意 KMSPico激活工具窃取用户加密货币钱包 https://thehackernews.com/2021/12/malicious-kmspico-windows-activator.html 2、 Zoho ManageEngine 一个新的高危漏洞正被积极利用 https://thehackernews.com/2021/12/warning-yet-another-zoho-manageengine.html 3、Nobelium APT 组织以法国组织为目标 https://securityaffairs.co/wordpress/125342/apt/nobelium-targets-french-orgs.html 4、330 家 SPAR 商店遭网络攻击后关闭或改用现金支付 https://securityaffairs.co/wordpress/125334/uncategorized/spar-stores-cyberattack.html 5、Kafdrop 漏洞可导致 Kafka 集群数据在线泄露 https://www.helpnetsecurity.com/2021/12/06/kafdrop-flaw/ 6、开源论坛软件 NodeBB 存在 RCE高危漏洞 https://portswigger.net/daily-swig/critical-vulnerabilities-in-open-source-forum-software-nodebb-could-lead-to-rce 7、挖矿工具Tor2mine变种将带来更大的威胁 https://cyware.com/news/tor2mine-cryptominer-evolves-to-pose-a-bigger-threat-31446d09 8、网络犯罪分子发送垃圾邮件分发RedLine木马 https://www.bleepingcomputer.com/news/security/malicious-excel-xll-add-ins-push-redline-password-stealing-malware/ 9、Twitter 删除了 3400 个用于政府宣传活动的帐户 https://www.bleepingcomputer.com/news/security/twitter-removes-3-400-accounts-used-in-govt-propaganda-campaigns/ 10、美国9名官员的iPhone遭到NSO Group间谍软件入侵 https://www.securityweek.com/pegasus-maker-probes-reports-its-spyware-targeted-us-diplomats
网络安全日报 2021年12月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员在九款无线路由器中发现了 226 个漏洞 https://www.securityweek.com/researchers-find-226-vulnerabilities-nine-wi-fi-routers 2、CISA 向联邦机构通报日立能源产品中的漏洞 https://www.securityweek.com/cisa-informs-organizations-about-vulnerabilities-hitachi-energy-products 3、BadgerDAO DeFi 平台被盗取 1.2 亿美元加密货币 https://securityaffairs.co/wordpress/125242/cyber-crime/badgerdao-defi-platform-hack.html 4、Emotet木马通过伪造的Adobe软件安装包进行传播 https://www.2-spyware.com/emotet-trojan-returned-after-the-takedown-detected-in-japan 5、洛杉矶计划生育协会40万名患者的个人信息遭泄露 https://www.latimes.com/california/story/2021-12-01/data-breach-planned-parenthood-los-angeles-patients 6、研究人员发现了14种新的浏览器数据窃取攻击 https://www.bleepingcomputer.com/news/security/researchers-discover-14-new-data-stealing-web-browser-attacks/ 7、谷歌推出Python包安全审计工具-"Pip-audit" https://portswigger.net/daily-swig/pip-audit-google-backed-tool-probes-python-environments-for-vulnerable-packages 8、网络犯罪分子利用深度伪造技术进行网络钓鱼 https://www.govinfosecurity.com/deepfakes-voice-impersonators-used-in-vishing-as-a-service-a-18050 9、网络安全公司SEON 发布了《全球网络犯罪报告》 https://www.freebuf.com/articles/network/306215.html 10、美国发布航空公司和铁路网络安全命令 https://www.infosecurity-magazine.com/news/cybersecurity-directive-airlines/
网络安全日报 2021年12月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 敦促各机构在规定时间修补 Zoho、高通和 Mikrotik 漏洞 https://www.securityweek.com/cisa-adds-zoho-qualcomm-mikrotik-flaws-must-patch-list 2、NSS 密码库中的高危漏洞影响多个应用 https://www.securityweek.com/critical-flaw-nss-cryptographic-library-affects-several-popular-applications 3、俄互联网监管机构 Roskomnadzor 禁止六个 VPN 服务 https://securityaffairs.co/wordpress/125224/laws-and-regulations/russia-roskomnadzor-bans-six-vpn-services.html 4、WooCommerce插件漏洞影响8W个WordPress站点 https://threatpost.com/retail-woocommerce-sites-plugin-xss-bug/176704/ 5、Aberebot恶意软件新变种针对银行和加密钱包 https://www.govinfosecurity.com/report-aberebot-20-hits-banking-apps-crypto-wallets-a-18031 6、研究人员警告伊朗用户注意短信网络钓鱼活动 https://thehackernews.com/2021/12/researchers-warn-iranian-users-of.html 7、谷歌浏览器中的释放后使用漏洞可导致代码执行 https://blog.talosintelligence.com/2021/12/vuln-spotlight-chrome-.html 8、英国工党披露勒索软件攻击后数据泄露 https://www.bleepingcomputer.com/news/security/uk-labour-party-discloses-data-breach-after-ransomware-attack/ 9、欧洲刑警组织在EMMA 7行动中逮捕1803名洗钱犯 https://www.bleepingcomputer.com/news/legal/europol-18k-money-mules-caught-laundering-money-from-online-fraud/ 10、注册300多万个微信账号,山东警方打掉“卖号”团伙 https://www.cnbeta.com/articles/tech/1209213.htm
网络安全日报 2021年12月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VirusTotal 推出"Collections"以简化 IoC 共享 https://www.securityweek.com/virustotal-introduces-collections-simplify-ioc-sharing 2、Sabbath勒索软件以美国和加拿大的关键基础设施为目标 https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html 3、FBI 培训文件揭示了可以从加密通讯应用中提取哪些数据 https://securityaffairs.co/wordpress/125176/security/encrypted-messaging-apps-data-access.html 4、越来越多的黑客在网络钓鱼攻击中使用 RTF 模板注入技术 https://thehackernews.com/2021/12/hackers-increasingly-using-rtf-template.html 5、Twitter禁止未经许可发布他人照片和视频 https://thehackernews.com/2021/11/twitter-bans-users-from-posting-private.html 6、APT37 使用 Chinotto 恶意软件攻击韩国知名人士 https://cyware.com/news/apt37-targets-south-korean-notables-with-chinotto-malware-d4aa8d16 7、Symfony PHP 框架中发现Web 缓存中毒漏洞 https://portswigger.net/daily-swig/web-cache-poisoning-bug-discovered-in-symfony-php-framework 8、Sabbath勒索软件团伙多次更名以逃避检测 https://www.infosecurity-magazine.com/news/ransomware-rebrands-multiple-times/ 9、分析表明儿童智能手表的隐私安全不容乐观 https://securityaffairs.co/wordpress/125155/hacking/opera-turbo-servers-flaw.html 10、 俄亥俄州DNA诊断中心数据泄露影响210万用户 https://www.securityweek.com/21-million-people-affected-breach-dna-testing-company
网络安全日报 2021年12月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Opera 修复了Turbo服务器中的一个漏洞 https://securityaffairs.co/wordpress/125155/hacking/opera-turbo-servers-flaw.html 2、360 Netlab发现新的 EwDoor 僵尸网络针对 AT&T 客户 https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html 3、150 种型号的HP打印机受"Printing Shellz"漏洞影响 https://securityaffairs.co/wordpress/125140/hacking/printing-shellz-flaws-hp-printer-models.html 4、攻击者通过 Google Play 分发恶意软件感染超过 30 万设备 https://securityaffairs.co/wordpress/125127/malware/4-banking-trojans-google-play.html 5、WIRTE 黑客组织针对中东的政府、法律、金融实体 https://thehackernews.com/2021/11/wirte-hacker-group-targets-government.html 6、澳大利亚CS Energy公司遭到勒索软件攻击 https://esdnews.com.au/breaking-cs-energy-hit-by-ransomware-attack/ 7、暗网市场Cannazon遭到DDoS攻击后关闭 https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/ 8、收集用户数据“透明度”过低,苹果、谷歌遭意大利巨额罚款 https://securityaffairs.co/wordpress/125056/laws-and-regulations/italys-antitrust-fined-google-apple.html 9、新墨西哥True Health公司的医疗数据被泄露 https://www.databreachtoday.com/medical-data-exposed-in-breach-at-true-health-new-mexico-a-18001 10、APT-Q-12:针对贸易行业的情报刺探活动 https://mp.weixin.qq.com/s/Hzq4_tWmunDpKfHTlZNM-A
网络安全日报 2021年11月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Zoom发布安全补丁修补高危漏洞 https://www.securityweek.com/project-zero-flags-high-risk-zoom-security-flaw 2、CISA 发布关于保护企业移动设备的指南 https://www.securityweek.com/cisa-releases-guidance-securing-enterprise-mobile-devices 3、最近修补的 Apache HTTP 服务器漏洞在攻击中被利用 https://www.securityweek.com/recently-patched-apache-http-server-vulnerability-exploited-attacks 4、制药公司 Supernus Pharmaceuticals 遭Hive勒索攻击和数据泄露 https://www.securityweek.com/ransomware-operators-threaten-leak-15tb-supernus-pharmaceuticals-data 5、松下披露网络攻击和数据泄露 https://securityaffairs.co/wordpress/125114/data-breach/panasonic-data-breach.html 6、黑客冒充金融机构针对美国Zelle手机应用用户 https://cyware.com/news/the-rise-in-banking-scams-zelle-fraud-and-other-threats-a9a36977 7、黑客利用不安全的Google Cloud账户挖矿并部署勒索软件 https://thehackernews.com/2021/11/hackers-using-compromised-google-cloud.html 8、工信部、公安部约谈阿里云和百度云,接入涉诈网站数量居高不下 https://www.miit.gov.cn/xwdt/gxdt/sjdt/art/2021/art_cef918baaec44bc88b6a5b37a0331c00.html 9、部分美国国防承包商极易遭受勒索软件攻击 https://www.helpnetsecurity.com/2021/11/25/defense-contractors-ransomware/ 10、TrickBot网络钓鱼检查屏幕分辨率以逃避研究人员 https://www.bleepingcomputer.com/news/security/trickbot-phishing-checks-screen-resolution-to-evade-researchers/
网络安全日报 2021年11月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、与朝鲜有关的APT冒充三星招聘人员进行钓鱼活动 https://securityaffairs.co/wordpress/125071/apt/north-korea-zinc-targets-security-firms.html 2、0patch 发布Windows 0day漏洞非官方补丁 https://securityaffairs.co/wordpress/125061/security/unofficial-patches-cve-2021-24084-zeroday.html 3、代号为HAEICHI-II的国际行动逮捕了1000多名网络犯罪嫌疑人 https://securityaffairs.co/wordpress/125044/cyber-crime/interpol-arrested-1003-individuals.html 4、海事服务提供商SPO遭 CL0P 勒索软件攻击导致公司数据被盗 https://securityaffairs.co/wordpress/125034/cyber-crime/swire-pacific-offshore-clop-ransomware.html 5、 Babadeda 恶意软件针对加密货币和NFT社区 https://securityaffairs.co/wordpress/125025/malware/babadeda-crypter-cryptocurrency-nft.html 6、Resecurity 研究人员在 TP-Link Wi-Fi 6 设备中发现了 0day 漏洞 https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html 7、以色列禁止向 65 个国家销售黑客和监视工具 https://thehackernews.com/2021/11/israel-bans-sales-of-hacking-and.html 8、新的Fuzz工具揭示了新的 HTTP 请求走私技术 https://portswigger.net/daily-swig/new-differential-fuzzing-tool-reveals-novel-http-request-smuggling-techniques 9、恶意软件通过YouTube上的免费游戏视频传播 https://blog.malwarebytes.com/scams/2021/11/free-steam-games-videos-promise-much-deliver-malware/ 10、家具零售商宜家的电子邮件系统遭受网络攻击 https://www.bleepingcomputer.com/news/security/ikea-email-systems-hit-by-ongoing-cyberattack/
网络安全日报 2021年11月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的 Linux CronRAT 利用任务计划逃避检测 https://securityaffairs.co/wordpress/125000/cyber-crime/linux-cronrat-magecart-attacks.html 2、伊朗黑客利用MSHTML 漏洞窃取 Google 和 Instagram 凭据 https://securityaffairs.co/wordpress/124984/apt/iran-apt-microsoft-mshtml-exploit.html 3、新型JavaScript恶意软件利用RAT感染目标设备 https://www.bleepingcomputer.com/news/security/stealthy-new-javascript-malware-infects-windows-pcs-with-rats/ 4、法国Bureau Veritas公司遭网络攻击服务器离线 https://www.ship-technology.com/news/bureau-veritas-hit-cyberattack/ 5、Cronin公司暴露了9200万条员工和客户的数据 https://www.websiteplanet.com/blog/cronin-leak-report/ 6、乌克兰逮捕了苹果钓鱼攻击黑客组织"Phoenix"成员 https://www.infosecurity-magazine.com/news/ukrainian-cops-bust-mobile-device/ 7、FBI警告针对知名品牌客户的网络钓鱼 https://www.bleepingcomputer.com/news/security/fbi-warns-of-phishing-targeting-high-profile-brands-customers/ 8、最多缩水90% 安全研究人员对微软漏洞赏金感到失望 https://www.cnbeta.com/articles/tech/1206729.htm 9、安全人员在研华 R-SeeNet 监控软件中发现了多个漏洞 https://blog.talosintelligence.com/2021/11/re-see-net-advantched-vuln-spotlight.html 10、威胁组织利用Tardigrade恶意软件攻击疫苗制造商 https://www.bleepingcomputer.com/news/security/hackers-target-biomanufacturing-with-stealthy-tardigrade-malware/
网络安全日报 2021年11月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware 修补了vCenter Server 中的文件读取和SSRF 漏洞 https://www.securityweek.com/vmware-patches-file-read-ssrf-vulnerabilities-vcenter-server 2、苹果起诉 NSO Group滥用Pegasus间谍软件 https://securityaffairs.co/wordpress/124954/laws-and-regulations/apple-sues-nso-group.html 3、VirtualBox 拒绝服务漏洞细节披露 https://securityaffairs.co/wordpress/124944/security/oracle-virtualbox-flaws.html 4、APT C-23 利用新的 Android 间谍软件变种攻击中东用户 https://thehackernews.com/2021/11/apt-c-23-hackers-using-new-android.html 5、黑客利用Tardigrade恶意软件针对生物制造业 https://www.bleepingcomputer.com/news/security/hackers-target-biomanufacturing-with-stealthy-tardigrade-malware/ 6、联发科芯片多个漏洞可导致被窃听,影响全球37%的手机和物理网设备 https://thehackernews.com/2021/11/eavesdropping-bugs-in-mediatek-chips.html 7、超过4000家英国零售商受到Magecart攻击 https://www.infosecurity-magazine.com/news/4000-uk-retailers-compromised/ 8、研究人员警告名为Printjack的三种打印机攻击 https://www.bleepingcomputer.com/news/security/researchers-warn-of-severe-risks-from-printjack-printer-attacks/ 9、思科新漏洞影响防火墙安全 https://www.infosecurity-magazine.com/news/cisco-flaw-affects-firewalls/ 10、研究人员发现使用指纹照片、打印机和胶水,便可绕过生物识别验证 https://www.bleepingcomputer.com/news/security/biometric-auth-bypassed-using-fingerprint-photo-printer-and-glue/