网络安全日报 2021年11月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、恶意软件已经在尝试利用新的 Windows Installer 零日漏洞 https://securityaffairs.co/wordpress/124940/malware/windows-installer-zero-day-malware.html 2、Android.Cynos.7.origin 木马感染 900 多万台安卓设备 https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html 3、专家警告 Imunify360 安全平台存在 RCE 漏洞 https://securityaffairs.co/wordpress/124922/security/imunify360-rce.html 4、研究人员发布Exchange CVE-2021-42321 RCE 漏洞的 PoC 代码 https://securityaffairs.co/wordpress/124917/hacking/microsoft-exchange-cve-2021-42321-rce-poc.html 5、加密货币交易所BTC-Alpha遭到勒索软件攻击 https://www.techtarget.com/searchsecurity/news/252509877/Cryptocurrency-exchange-BTC-Alpha-confirms-ransomware-attack 6、WSpot Wi-Fi管理软件公司泄露数百万巴西人数据 https://www.zdnet.com/article/millions-of-brazilians-exposed-in-wi-fi-management-software-firm-leak/ 7、Facebook要求洛杉矶警方停止使用虚假账户监视其用户 https://tech.slashdot.org/story/21/11/19/1930212/facebook-tells-la-police-to-stop-spying-on-users-with-fake-accounts 8、飞利浦、CISA 就医疗器械产品安全漏洞发出警告 https://www.inforisktoday.com/philips-cisa-warn-medical-device-product-security-flaws-a-17958 9、加州Pizza Kitchen遭遇数据泄露 https://securityaffairs.co/wordpress/124785/data-breach/california-pizza-kitchen-data-breach.html 10、“幼象”组织在南亚地区的网络攻击活动分析 https://mp.weixin.qq.com/s/9emBT2btFA811QLRjU54tA
网络安全日报 2021年11月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、严重的代码执行漏洞影响基于 OpenVPN 的应用程序 https://www.securityweek.com/severe-code-execution-vulnerabilities-affect-openvpn-based-applications 2、研究人员破解 Conti 勒索软件基础设施 https://www.securityweek.com/researchers-hack-conti-ransomware-infrastructure 3、GoDaddy 泄露了 120 万个托管的 WordPress 客户帐户 https://securityaffairs.co/wordpress/124894/data-breach/godaddy-data-breach.html 4、伊朗最大的私人航空公司-马汉航空遭网络攻击 https://www.securityweek.com/irans-mahan-air-says-hit-cyberattack 5、印度旁遮普国民银行服务器漏洞暴露客户数据 https://www.livemint.com/industry/banking/pnb-customers-data-exposed-for-seven-months-due-to-server-vulnerability-report-11637486043143.html 6、英国数据存储公司Stor-A-File遭黑客攻击泄露客户信息 https://www.dailymail.co.uk/news/article-10225281/Highly-sensitive-medical-documents-leaked-online-hackers-3million-Bitcoin-ransom-rejected.html 7、美国银行业监管机构要求银行在36小时内通报网络安全事件 https://securityaffairs.co/wordpress/124826/laws-and-regulations/u-s-banking-regulators-rule.html 8、企业间谍黑客组织RedCurl回归 https://thehackernews.com/2021/11/redcurl-corporate-espionage-hackers.html 9、美国证券交易委员会警告称诈骗者冒充SEC官员 https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/ 10、印尼国家警察服务器遭黑客入侵泄露警察数据 https://www.databreaches.net/indonesia-probe-police-hack-in-latest-cyber-breach/
网络安全日报 2021年11月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的"SharkBot"安卓银行木马以美国、英国和意大利为目标 https://www.securityweek.com/new-%E2%80%98sharkbot%E2%80%99-android-banking-malware-hitting-us-uk-and-italy-targets 2、恶意Python包窃取Discord令牌并且安装shell https://securityaffairs.co/wordpress/124861/hacking/malicious-pypi-python-packages.html 3、攻击者破坏 Exchange 服务器以劫持内部电子邮件 https://securityaffairs.co/wordpress/124838/hacking/microsoft-exchange-servers-hack.html 4、研究揭示了最常见的前 200 个密码 https://securityaffairs.co/wordpress/124815/security/top-used-passwords.html 5、600 万台 Sky 路由器遭受攻击近 1.5 年 https://threatpost.com/6m-sky-routers-exposed-18-months/176483/ 6、新Aggah活动劫持剪贴板以替换加密货币地址 https://www.riskiq.com/blog/external-threat-management/aggah-clipboard-hijack-crypto/ 7、Memento勒索软件将文件锁定在加密WinRAR中 https://www.bleepingcomputer.com/news/security/new-memento-ransomware-switches-to-winrar-after-failing-at-encryption/ 8、钓鱼邮件冒充TSA PreCheck网站欺骗美国旅客 https://www.bleepingcomputer.com/news/security/fake-tsa-precheck-sites-scam-us-travelers-with-fake-renewals/ 9、Vestas公司遭到网络攻击关闭部分IT系统 https://www.reuters.com/markets/europe/vestas-hit-by-cyber-security-incident-shuts-some-it-systems-2021-11-20/ 10、CKEditor修复影响Drupal和下游应用的漏洞 https://portswigger.net/daily-swig/ckeditor-vulnerabilities-pose-xss-threat-to-drupal-and-other-downstream-applications
网络安全日报 2021年11月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft 解决了 Azure AD 中的一个高危漏洞 https://securityaffairs.co/wordpress/124755/security/microsoft-azure-ad-flaw.html 2、FBI 警告 FatPipe 产品中一个零日漏洞已被利用 https://securityaffairs.co/wordpress/124742/security/zero-day-fatpipe.html 3、以色列国防部长的清洁工被控为伊朗黑客从事间谍活动 https://www.securityweek.com/israel-defence-ministers-cleaner-charged-spying-iran 4、基于 Golang 的恶意软件高速增长 https://cyware.com/news/the-rising-popularity-of-golang-based-malware-87b9e7d7 5、新的鱼叉式网络钓鱼活动利用 Glitch 平台窃取员工凭据 https://threatpost.com/spear-phishing-exploits-glitch-steal-credentials/176449/ 6、研究人员发现BrazKing Android银行木马新版本 https://securityintelligence.com/posts/brazking-android-malware-upgraded-targeting-brazilian-banks/ 7、钓鱼邮件伪装成Netflix服务窃取用户信用卡信息 https://threatpost.com/netflix-bait-phishers-fake-signups/176422/ 8、网络钓鱼活动以 Tiktok KOL用户为目标 https://securityaffairs.co/wordpress/124728/hacking/tiktok-influencer-phishing-campaign.html 9、LibreCAD 中发现多个代码执行漏洞 https://blog.talosintelligence.com/2021/11/libre-cad-vuln-spotlight-.html 10、朝鲜APT组织 TA406针对外交专家、记者和NGO https://www.proofpoint.com/us/blog/threat-insight/triple-threat-north-korea-aligned-ta406-scams-spies-and-steals
网络安全日报 2021年11月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Netgear 修补影响多个产品的代码执行漏洞 https://www.securityweek.com/netgear-patches-code-execution-vulnerability-affecting-many-products 2、英国下令对 NVIDIA 收购 Arm 的交易进行国家安全审查 https://www.securityweek.com/uk-orders-national-security-review-nvidia-deal-buy-arm 3、CISA 为联邦机构发布了事件和漏洞响应手册 https://securityaffairs.co/wordpress/124705/security/cisa-incident-response-playbook.html 4、StripChat 数百万用户数据遭泄露 https://securityaffairs.co/wordpress/124665/data-breach/adult-cam-site-stripchat-exposes-the-data-of-millions-of-users-and-cam-models.html 5、攻击者利用 "域前置" 技术重定向缅甸政府网站流量 http://blog.talosintelligence.com/2021/11/attackers-use-domain-fronting-technique.html 6、Microsoft 修复了 Exchange Server 中的反射型 XSS漏洞 https://portswigger.net/daily-swig/microsoft-fixes-reflected-xss-in-exchange-server 7、Concrete CMS 存在多个安全漏洞 https://portswigger.net/daily-swig/server-side-vulnerabilities-in-concrete-cms-put-thousands-of-websites-under-threat 8、Lantronix PremierWave 2050 中的漏洞可导致代码执行、文件删除 https://blog.talosintelligence.com/2021/11/lantronix-premier-wave-vuln-spotlight.html 9、新的Emotet垃圾邮件活动向全球发送恶意文档 https://www.bleepingcomputer.com/news/security/here-are-the-new-emotet-spam-campaigns-hitting-mailboxes-worldwide/ 10、黑客入侵WordPress网站显示虚假的加密通知 https://www.bleepingcomputer.com/news/security/wordpress-sites-are-being-hacked-in-fake-ransomware-attacks/
网络安全日报 2021年11月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Chrome 96 修复多个高危漏洞 https://www.securityweek.com/chrome-96-plugs-high-risk-browser-flaws 2、英特尔 CPU 漏洞可导致加密密钥泄露 https://www.securityweek.com/intel-cpu-vulnerability-can-expose-cryptographic-keys 3、SharkBot:一种针对欧洲银行的新型安卓木马 https://securityaffairs.co/wordpress/124650/mobile-2/sharkbot-android-trojan.html 4、NPM 修复私有包名泄露和未授权问题 https://securityaffairs.co/wordpress/124671/security/github-npm-package-flaws.html 5、微软为 Defender 添加了 AI 驱动的勒索软件保护 https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-ai-driven-ransomware-protection-to-defender/ 6、新的攻击手法可完全绕过DRAM内存Rowhammer漏洞现有保护措施 https://www.securityweek.com/blacksmith-rowhammer-fuzzer-bypasses-existing-protections 7、 700 万 Robinhood 客户数据被在线出售 https://www.bleepingcomputer.com/news/security/7-million-robinhood-user-email-addresses-for-sale-on-hacker-forum/ 8、MosesStaff组织针对以色列公司窃取敏感数据 https://research.checkpoint.com/2021/mosesstaff-targeting-israeli-companies/ 9、CISA发布工业控制系统警报敦促修补关键漏洞 https://www.infosecurity-magazine.com/news/cisa-patch-these-ics-flaws-across/ 10、VMware披露vCenter Server中的权限提升漏洞 https://securityaffairs.co/wordpress/124465/security/vmware-vcenter-server-flaw.html
网络安全日报 2021年11月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、在被国际行动摧毁十个月后,Emotet 僵尸网络重新活跃 https://securityaffairs.co/wordpress/124642/cyber-crime/operation-reacharound-emotet-return.html 2、Cloudflare 宣布缓解迄今为止最大的2Tbps DDoS攻击 https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html 3、微软紧急更新以修复 Windows Server 身份验证失败问题 https://securityaffairs.co/wordpress/124625/security/microsoft-windows-server-auth-failures.html 4、Diebold Nixdorf ATM 漏洞允许攻击者修改固件窃取现金 https://www.securityweek.com/diebold-nixdorf-atm-flaws-allowed-attackers-modify-firmware-steal-cash 5、Nasa、西门子和大众使用的物联网DDS协议漏洞可能被黑客利用 https://www.securityweek.com/iot-protocol-used-nasa-siemens-and-volkswagen-can-be-exploited-hackers 6、研究人员展示了新的 Tor 加密流量指纹攻击技术 https://thehackernews.com/2021/11/researchers-demonstrate-new.html 7、网络犯罪分子针对阿里云ECS实例进行挖矿和植入恶意软件 https://threatpost.com/cybercriminals-alibaba-cloud-cryptomining-malware/176348/ 8、Magniber 勒索软件利用IE漏洞 https://cyware.com/news/magniber-is-now-exploiting-internet-explorer-flaws-48b860e6 9、酒店预订网站 RedDoorz 数百万新加坡和东南亚客户数据泄露 https://www.straitstimes.com/tech/tech-news/59m-customers-of-reddoorz-hotel-booking-site-leaked-in-spores-largest-data-breach 10、研究人员发现针对哈萨克斯坦的多阶段攻击 https://blog.malwarebytes.com/threat-intelligence/2021/11/a-multi-stage-powershell-based-attack-targets-kazakhstan/
网络安全日报 2021年11月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、英特尔、AMD 修补多个高危安全漏洞 https://www.securityweek.com/intel-amd-patch-high-severity-security-flaws 2、"BotenaGo"利用33个漏洞攻击数百万路由器和物联网设备 https://www.securityweek.com/botenago-malware-targets-routers-iot-devices-over-30-exploits 3、Zoom 修补多个软件组件高危漏洞 https://www.securityweek.com/zoom-patches-high-risk-flaws-meeting-connector-keybase-client 4、谷歌、Adobe 发布新的开源安全工具 https://www.securityweek.com/google-adobe-announce-new-open-source-security-tools 5、 FBI 电子邮件服务器遭入侵被用来发送虚假警告钓鱼邮件 https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html 6、零售巨头 Costco 披露数据泄露,支付卡数据泄露 https://securityaffairs.co/wordpress/124534/data-breach/costco-data-breach.html 7、新的 Abcbot DDoS 僵尸网络以 Linux 系统为目标 https://securityaffairs.co/wordpress/124542/security/abcbot-ddos-botnet-linux.html 8、越来越多的钓鱼活动利用HTML走私技术 https://thehackernews.com/2021/11/hackers-increasingly-using-html.html 9、攻击者可利用GoCD中的漏洞发起供应链攻击 https://portswigger.net/daily-swig/gocd-bug-chain-provides-second-springboard-for-supply-chain-attacks 10、TrickBot团伙通过钓鱼邮件部署BazarLoader https://www.bleepingcomputer.com/news/security/windows-10-app-installer-abused-in-bazarloader-malware-attacks/
网络安全日报 2021年11月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、一项 18 个月的研究发现了近 100 个 TCP/IP 堆栈漏洞 https://www.securityweek.com/nearly-100-tcpip-stack-vulnerabilities-found-during-18-month-research-project 2、PS5 根密钥被窃取和内核漏洞被利用 https://threatpost.com/playstation-5-hacks-same-day/176240/ 3、新僵尸网络-Abcbot 正在形成 https://cyware.com/news/abcbot-a-new-botnet-in-the-making-f79494e1 4、HPE 称黑客使用窃取的密钥入侵了 Aruba Central https://www.bleepingcomputer.com/news/security/hpe-says-hackers-breached-aruba-central-using-stolen-access-key/ 5、TeamTNT 使用新的复杂技术入侵Docker 服务器 https://cyware.com/news/teamtnt-uses-new-sophisticated-techniques-against-docker-systems-5d295e64 6、Lazarus Group 利用植入后门的IDA Pro攻击安全研究人员 https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/ 7、VoIP 提供商 Telnyx 遭DDoS攻击 https://cisomag.eccouncil.org/ddos-attack-on-voip-provider-telnyx-impacts-global-telephony-services 8、Apache Storm修复了两个预认证RCE漏洞 https://portswigger.net/daily-swig/apache-storm-maintainers-patch-two-pre-auth-rce-vulnerabilities 9、Palo Alto Networks修复产品中的零日漏洞 https://www.randori.com/blog/cve-2021-3064/ 10、Citrix发布安全更新修复ADC中的关键漏洞 https://securityaffairs.co/wordpress/124452/security/citrix-dos-adc-gateway.html
网络安全日报 2021年11月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Palo Alto GlobalProtect VPN 中存在远程代码执行漏洞 https://www.securityweek.com/remote-code-execution-flaw-palo-alto-globalprotect-vpn 2、VMware 正在开发针对高危 vCenter Server 漏洞的补丁 https://www.securityweek.com/vmware-working-patches-serious-vcenter-server-vulnerability 3、Citrix 修补了 ADC网关中的严重漏洞 https://www.securityweek.com/citrix-patches-critical-vulnerability-adc-gateway 4、WP Reset PRO 插件存在严重漏洞可删除数据库 https://www.securityweek.com/critical-flaw-wordpress-plugin-leads-database-wipe 5、被称为"勒索软件终结者"的RPC 防火墙发布开源版本 https://www.securityweek.com/rpc-firewall-dubbed-ransomware-kill-switch-released-open-source 6、恶意软件"PhoneSpy"针对韩国Android手机用户 https://www.securityweek.com/south-korean-users-targeted-android-spyware-phonespy 7、BusyBox 被发现了 14 个新漏洞,影响数百万设备 https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/ 8、研究人员发现Lyceum组织针对中东电信提供商 https://www.accenture.com/us-en/blogs/cyber-defense/iran-based-lyceum-campaigns 9、德国医疗软件巨头Medatixx遭到勒索软件攻击 https://www.bleepingcomputer.com/news/security/medical-software-firm-urges-password-resets-after-ransomware-attack/ 10、TrickBot Gang 与 TA551 Group 合作提供 Conti 勒索软件 https://securityboulevard.com/2021/11/threat-analysis-report-from-shatak-emails-to-the-conti-ransomware/