网络安全日报 2021年11月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二补丁日修复了55个漏洞 https://www.securityweek.com/zero-days-under-attack-microsoft-plugs-exchange-server-excel-holes 2、与俄有关联的"Evil Corp"组织利用Serv-U 漏洞 https://www.securityweek.com/russian-cybercrime-group-exploits-solarwinds-serv-u-vulnerability 3、Adobe 修复了 RoboHelp 服务器高危漏洞 https://www.securityweek.com/adobe-patches-critical-robohelp-server-security-flaw 4、西门子和施耐德电气修复了ICS产品中的50多个漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-and-schneider-electric-address-over-50-vulnerabilities-0 5、多种医疗、OT系统受NUCLEUS:13漏洞影响 https://www.securityweek.com/many-healthcare-ot-systems-exposed-attacks-nucleus13-vulnerabilities 6、多个REvil 勒索软件关联公司被警察捣毁 https://securityaffairs.co/wordpress/124372/cyber-crime/revil-ransomware-arrests-romania-and-kuwait.html 7、TeamTNT 通过暴露的Docker API部署挖矿程序 https://www.trendmicro.com/en_us/research/21/k/compromised-docker-hub-accounts-abused-for-cryptomining-linked-t.html 8、 黑客入侵Instagram账户传播比特币骗局 https://www.vice.com/en/article/93bw9z/bitcoin-scam-hostage-videos-instagram 9、CVL公司暴露超过4000万印度投资者数据 https://ciso.economictimes.indiatimes.com/news/data-breach-at-cdsls-kyc-arm-exposed-4-39-cr-investors-data-twice-within-10-days-cyberx9/87577170 10、电子零售巨头MediaMarkt遭勒索软件攻击 https://securityaffairs.co/wordpress/124338/cyber-crime/mediamarkt-ransomware-attack.html
网络安全日报 2021年11月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、股票交易平台 Robinhood 被黑,数百万用户信息泄露 https://www.securityweek.com/robinhood-hacked-millions-names-emails-stolen 2、ADSelfService Plus 0day漏洞影响多家跨国公司 https://www.securityweek.com/global-companies-compromised-adselfservice-plus-exploitation 3、欧洲刑警宣布逮捕与 REvil、GandCrab 勒索软件有关的 7 人 https://www.securityweek.com/europol-announces-arrests-7-people-linked-revil-gandcrab-ransomware 4、飞利浦 TASY EMR 中存在高危SQL注入漏洞 https://thehackernews.com/2021/11/critical-flaws-in-philips-tasy-emr.html 5、新Magecart组使用浏览器脚本逃避虚拟机检测 https://securityaffairs.co/wordpress/124287/hacking/magecart-e-skimmer-avoids-vms.html 6、希腊多家航运公司遭到勒索软件攻击 https://www.maritime-executive.com/article/cyberattack-hits-multiple-greek-shipping-firms 7、Mozilla发布Thunderbird 91.3版本修复数十个漏洞 https://www.bleepingcomputer.com/news/security/mozilla-thunderbird-913-released-to-fix-high-impact-flaws/ 8、Google推出新功能,用户可通过密码保护搜索历史记录 https://www.cnbeta.com/articles/tech/1199195.htm 9、GitLab 服务器被利用发动 DDoS 攻击 https://therecord.media/gitlab-servers-are-being-exploited-in-ddos-attacks-in-excess-of-1-tbps/ 10、报告称,77%的rootkit被网络犯罪分子当作间谍工具使用 https://www.helpnetsecurity.com/2021/11/05/rootkits-espionage/
网络安全日报 2021年11月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现Babuk 勒索软件利用 ProxyShell 漏洞 https://www.securityweek.com/babuk-ransomware-seen-exploiting-proxyshell-vulnerabilities 2、研究人员发布针对 BrakTooth 蓝牙漏洞的 PoC https://www.securityweek.com/researchers-release-poc-tool-targeting-braktooth-bluetooth-vulnerabilities 3、匈牙利官员证实政府购买、使用过Pegasus 间谍软件 https://www.securityweek.com/hungarian-official-government-bought-used-pegasus-spyware 4、美国悬赏 1000 万美元追捕 DarkSide 勒索软件团伙 https://www.securityweek.com/us-gov-offering-10m-reward-data-darkside-ransomware-operators 5、网络犯罪分子冒充网络安全公司 Proofpoint进行钓鱼活动 https://securityaffairs.co/wordpress/124298/cyber-crime/phishing-campaign-proofpoint.html 6、美国国防承包商EWA披露数据泄露 https://securityaffairs.co/wordpress/124236/data-breach/electronic-warfare-associates-data-breach.html 7、研究人员发现流行的“coa”NPM库被劫持 https://www.bleepingcomputer.com/news/security/popular-coa-npm-library-hijacked-to-steal-user-passwords/ 8、思科修复了硬编码凭据和默认SSH密钥的问题 https://securityaffairs.co/wordpress/124198/security/cisco-hard-coded-credentials.html 9、乌克兰确认俄罗斯FSB中五人为黑客组织成员 https://thehackernews.com/2021/11/ukraine-identifies-russian-fsb-officers.html 10、法国CERT发布针对Lockean组织的分析报告 https://www.bleepingcomputer.com/news/security/lockean-multi-ransomware-affiliates-linked-to-attacks-on-french-orgs/
网络安全日报 2021年11月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国悬赏 1000 万美元追捕 DarkSide 勒索软件团伙 https://www.securityweek.com/us-gov-offering-10m-reward-data-darkside-ransomware-operators 2、思科修复了 Catalyst PON 企业交换机的关键漏洞 https://www.securityweek.com/cisco-plugs-critical-holes-catalyst-pon-enterprise-switches 3、Linux修复了内核中的高危漏洞 https://www.securityweek.com/linux-foundation-fixes-dangerous-code-execution-kernel-bug 4、Firefox 94 推出站点隔离功能 https://www.securityweek.com/mozilla-rolling-out-site-isolation-release-firefox-94 5、CISA 敦促供应商解决 BrakTooth 漏洞 https://securityaffairs.co/wordpress/124208/hacking/cisa-braktooth-advisory.html 6、Discord Nitro网络钓鱼活动针对Steam玩家 https://www.bleepingcomputer.com/news/security/beware-free-discord-nitro-phishing-targets-steam-gamers/ 7、企业CMS软件Sitecore XP中存在一个RCE漏洞 https://portswigger.net/daily-swig/rce-vulnerability-found-in-sitecore-enterprise-cms-software 8、英国工党披露遭勒索软件攻击后导致数据泄露 https://securityaffairs.co/wordpress/124162/cyber-crime/labour-party-data-breach.html 9、美国医学培训学校泄露数千名学生个人数据 https://www.zdnet.com/article/medical-school-exposes-personal-data-of-thousands-of-students 10、CERT-FR 警告 Lockean 勒索软件攻击法国公司 https://securityaffairs.co/wordpress/124171/malware/cert-fr-warns-lockean-ransomware.html
网络安全日报 2021年11月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国制裁NSO Group等四家开发监控软件的公司 https://securityaffairs.co/wordpress/124148/laws-and-regulations/us-santioned-nso-group-spyware-hacking-tools.html 2、BlackMatter 勒索软件团伙宣布关闭运营 https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html 3、Mekotio 银行木马以新的攻击和隐藏技术重新出现 https://thehackernews.com/2021/11/mekotio-banking-trojan-resurfaces-with.html 4、CISA 列出了组织需要修补的 300 个被利用的漏洞 https://www.securityweek.com/cisa-lists-300-exploited-vulnerabilities-organizations-need-patch 5、微软宣布面向中小企业终端安全的新解决方案 https://www.securityweek.com/microsoft-announces-new-endpoint-security-solution-smbs 6、攻击者利用 Windows 10 上的Chrome 绕过 UAC https://cyware.com/news/attackers-exploiting-google-chrome-on-windows-10-for-uac-bypass-5ee58e6e 7、Chaos Ransomware 针对日本的 Minecraft 游戏玩家 https://cyware.com/news/chaos-ransomware-targeting-minecraft-gamers-in-japan-6ec628e2 8、Mozilla 修复了 Firefox 94 中的安全漏洞 https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/11/update-now-mozilla-fixes-security-vulnerabilities-in-firefox-94/ 9、攻击者利用ELF可执行文件针对WSL环境 https://blogs.quickheal.com/stay-alert-malware-authors-deploy-elf-as-windows-loaders-to-exploit-wsl-feature/ 10、美国理疗中心数据泄露影响6500多名患者 https://portswigger.net/daily-swig/data-breach-at-us-physical-therapy-center-impacts-more-than-6-500-patients
网络安全日报 2021年11月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Facebook 表示将关闭其面部识别系统并删除数据 https://www.securityweek.com/facebook-shut-down-face-recognition-system-delete-data 2、FBI 发布 Hello Kitty 勒索软件的 IOC https://www.securityweek.com/fbi-publishes-iocs-hello-kitty-ransomware 3、谷歌将发现Linux 内核中提权漏洞的赏金提高了三倍 https://securityaffairs.co/wordpress/124094/hacking/google-bug-bounty-linux-kernel-exploits.html 4、互联网上公开的GitLab有50%仍然受RCE漏洞的影响 https://securityaffairs.co/wordpress/124088/hacking/gitlab-rce.html 5、Pentaho 商业分析软件中存在严重漏洞 https://thehackernews.com/2021/11/critical-flaws-uncovered-in-pentaho.html 6、Android 11 月补丁修复了多个严重漏洞 https://www.bleepingcomputer.com/news/security/android-november-patch-fixes-actively-exploited-kernel-bug 7、巴基斯坦国有商业银行后端系统遭受破坏性攻击 https://therecord.media/destructive-cyberattack-hits-national-bank-of-pakistan/ 8、卡巴斯基修补了可能导致系统无法启动的漏洞 https://www.securityweek.com/kaspersky-patches-vulnerability-can-lead-unbootable-system 9、新的鱼叉式网络钓鱼活动窃取Office 365凭据 https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021_phishing 10、电信堆栈软件FreeSwitch中存在5个安全漏洞 https://portswigger.net/daily-swig/multiple-flaws-in-telecoms-stack-software-freeswitch-uncovered
网络安全日报 2021年11月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌推出新的开源数据隐私协议 https://www.securityweek.com/google-introduces-new-open-source-data-privacy-protocol 2、Android 恶意软件"AbstractEmu"可获取Root权限 https://www.securityweek.com/tens-thousands-download-abstractemu-android-rooting-malware 3、研究人员发现一种新的攻击利用Unicode在源码中隐藏漏洞 https://www.trojansource.codes/ 4、微软警告针对云帐户的密码喷射攻击正在增加 https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-rise-in-password-sprays-targeting-cloud-accounts/ 5、GoCD 修补了高危身份验证漏洞 https://www.securezoo.com/2021/10/gocd-patches-highly-critical-authentication-vulnerability 6、谷歌、Salesforce 等联手启动 MVSP 安全基线项目 https://portswigger.net/daily-swig/google-salesforce-others-team-up-to-launch-mvsp-security-baseline-project 7、Balikbayan Foxes 组织冒充菲律宾政府传播RAT https://securityaffairs.co/wordpress/124017/apt/balikbayan-foxes-campaings.html 8、多伦多交通委员会披露遭到了勒索软件攻击 https://www.cbc.ca/news/canada/toronto/ttc-ransomware-attack-1.6231349 9、研究人员发现基于Golang的勒索软件DECAF https://blog.morphisec.com/decaf-ransomware-a-new-golang-threat-makes-its-appearance 10、警方逮捕造成全球1800起攻击事件的黑客嫌疑人 https://thehackernews.com/2021/10/police-arrest-suspected-ransomware.html
网络安全日报 2021年11月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌发布紧急 Chrome 更新补丁 修复两个被利用的0Day 漏洞 https://thehackernews.com/2021/10/google-releases-urgent-chrome-update-to.html 2、与伊朗有关的黑客入侵以色列互联网公司 https://www.securityweek.com/apparent-iran-linked-hackers-breach-israeli-internet-firm 3、MITRE 和 CISA 公布 2021 年最常见硬件漏洞清单 https://www.securityweek.com/mitre-cisa-announce-2021-list-most-common-hardware-weaknesses 4、Conti 勒索软件团伙攻击了顶级珠宝商Graff https://securityaffairs.co/wordpress/123980/cyber-crime/conti-ransomware-graff-jeweller.html 5、Hive勒索软件出现新变种可以加密Linux核FreeBSD https://securityaffairs.co/wordpress/123931/malware/hive-ransomware-linux-freebsd.html 6、巴布亚新几内亚财政部遭勒索软件攻击 https://securityaffairs.co/wordpress/123927/cyber-crime/papua-new-guinea-ransomware.html 7、 Android间谍软件FakeCop伪装成防病毒软件在日本传播 https://www.bleepingcomputer.com/news/security/android-spyware-spreading-as-antivirus-software-in-japan/ 8、苹果修复了macOS中的安全功能绕过漏洞 https://www.helpnetsecurity.com/2021/10/29/cve-2021-30892/ 9、配置错误的数据库泄露了超过8.8亿条医疗记录 https://www.websiteplanet.com/blog/deep6-leak-report/ 10、REvil和SolarMarker利用SEO中毒传播攻击载荷 https://cyware.com/news/revil-and-solarmarker-employ-seo-poisoning-attacks-4ea4f2ca
网络安全日报 2021年10月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科修补 ASA、FTD 软件中的高危 DoS 漏洞 https://www.securityweek.com/cisco-patches-high-severity-dos-vulnerabilities-asa-ftd-software 2、FBI 发布 Ranzy Locker 勒索软件 IOC https://www.securityweek.com/fbi-publishes-indicators-compromise-ranzy-locker-ransomware 3、严重的 GoCD 身份验证漏洞可导致供应链攻击 https://www.securityweek.com/critical-gocd-authentication-flaw-exposes-software-supply-chain 4、美国以国家安全为由禁止中国电信在该国运营 https://www.securityweek.com/us-bans-china-telecom-over-national-security-concerns 5、微软安全研究员在 macOS 中发现 Shrootless 漏洞,可绕过SIP https://securityaffairs.co/wordpress/123898/hacking/macos-shrootless-cve-2021-30892-flaw.html 6、超100万个网站受OptinMonster 插件漏洞影响 https://securityaffairs.co/wordpress/123886/hacking/wordpress-optinmonster-plugin-flaws.html 7、研究人员发现新的恶意软件加载程序-Wslink https://securityaffairs.co/wordpress/123878/malware/wslink-loader.html 8、德国调查人员确定了一名 REvil 勒索软件团伙核心成员 https://www.bleepingcomputer.com/news/security/german-investigators-identify-revil-ransomware-gang-core-member 9、用于签署欧盟数字 Covid 证书的私钥遭泄露 https://www.bleepingcomputer.com/news/security/eu-investigating-leak-of-private-key-used-to-forge-covid-passes/ 10、攻击者从 Cream Finance DeFi 平台窃取了1.3亿美金资产 https://securityaffairs.co/wordpress/123861/cyber-crime/cream-finance-cyber-heist-130m.html
网络安全日报 2021年10月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客使用 Squirrelwaffle Loader 部署 Qakbot 和 Cobalt Strike https://thehackernews.com/2021/10/hackers-using-squirrelwaffle-loader-to.html 2、恶意 Firefox 附加组件阻止浏览器下载安全更新 https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html 3、富士电机修补工厂监控软件中的漏洞 https://www.securityweek.com/fuji-electric-patches-vulnerabilities-factory-monitoring-software 4、苹果发布iOS 15.1 补丁修复了 iPhone 的 22 个安全漏洞 https://www.securityweek.com/apple-patches-22-security-flaws-haunting-iphones 5、 Avast 发布了 AtomSilo 和 LockFile 勒索软件解密器 https://securityaffairs.co/wordpress/123854/malware/atomsilo-lockfile-ransomware-decryptor.html 6、Grief 勒索软件攻击了美国全国步枪协会 (NRA) https://securityaffairs.co/wordpress/123849/cyber-crime/grief-ransomware-hit-nra.html 7、TA551 使用 Silver Red-Teaming 工具渗透网络 https://cyware.com/news/ta551-using-silver-red-teaming-tool-to-penetrate-networks-e5c83e78 6、Squid Game壁纸应用程序被用于传播Joker恶意软件 https://www.financialexpress.com/industry/technology/beware-squid-game-app-caught-infecting-android-devices-check-details/2356500/ 7、英国VoIP提供商Voipfone再次遭受DDoS攻击 https://www.ispreview.co.uk/index.php/2021/10/voip-provider-voipfone-uk-knocked-out-by-ddos-attack-again.html 8、多国联合执法逮捕了150名在暗网从事非法商品交易的嫌犯 https://www.securityweek.com/150-people-arrested-us-europe-darknet-drug-probe 9、一项调查显示过去一年,72%的组织受到过DNS攻击 https://www.helpnetsecurity.com/2021/10/26/organizations-dns-attacks/ 10、美国政府要求谷歌跟踪搜索某些关键词的人 https://www.dailymail.co.uk/news/article-10063665/Government-orders-Google-track-searching-certain-names-addresses-phone-numbers.html