网络安全日报 2021年10月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软周二补丁日发布71 个漏洞补丁包括一个零日漏洞 https://www.securityweek.com/ms-patch-tuesday-71-vulns-one-exploited-zero-day 2、Adobe 修补了多个产品中的关键代码执行漏洞 https://www.securityweek.com/adobe-patches-critical-code-execution-vulnerabilities-several-products 3、Microsoft Azure 遭受 2.4 Tbps DDoS 攻击 https://www.securityweek.com/microsoft-mitigates-24-tbps-ddos-attack-targeting-azure 4、江森自控 exacqVision 视频监控系统存在漏洞面临远程攻击 https://www.securityweek.com/vulnerabilities-expose-exacqvision-video-surveillance-systems-remote-attacks 5、Necro 僵尸网络现在以 Visual Tools DVR 为目标 https://securityaffairs.co/wordpress/123275/cyber-crime/necro-botnet-dvrs.html 6、奥林巴斯美国公司因网络攻击被迫关闭IT系统 https://securityaffairs.co/wordpress/123263/security/olympus-us-cyberattack.html 7、Git GUI 客户端 GitKraken 修复了生成弱SSH密钥的漏洞 https://securityaffairs.co/wordpress/123255/security/gitkraken-flaw-ssh-keys-generation.html 8、Apple发布iOS 15.0.2 系统修复被积极利用的零日漏洞 https://securityaffairs.co/wordpress/123236/mobile-2/apple-zero-day-vulnerability.html 9、Quest旗下的生育诊所在勒索软件攻击后宣布数据泄露 https://www.zdnet.com/article/quest-owned-fertility-clinic-announces-data-breach-after-august-ransomware-attack/ 10、西门子和施耐德电气周二补丁修复50多个漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-and-schneider-electric-address-over-50-vulnerabilities
网络安全日报 2021年10月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、InHand 路由器漏洞可能使许多工业公司面临远程攻击 https://www.securityweek.com/inhand-router-flaws-could-expose-many-industrial-companies-remote-attacks 2、工程公司 Weir Group 披露勒索软件攻击 https://www.securityweek.com/engineering-company-weir-group-discloses-ransomware-hack 3、微软披露针对美国和以色列国防技术部门的与伊朗有关的 APT https://www.securityweek.com/microsoft-exposes-iran-linked-apt-targeting-us-israeli-defense-tech-sectors 4、NSA 警告通配符TLS证书、ALPACA 攻击带来的风险 https://www.securityweek.com/nsa-warns-risks-posed-wildcard-certificates-alpaca-attacks 5、苹果发布紧急更新修复被积极利用的零日漏洞 https://securityaffairs.co/wordpress/123236/mobile-2/apple-zero-day-vulnerability.html 6、LibreOffice 和 OpenOffice 中证书验证漏洞允许伪造签名文档 https://securityaffairs.co/wordpress/123212/security/libreoffice-openoffice-flaw.html 7、太平洋城市银行披露了AvosLocker勒索软件攻击 https://www.bleepingcomputer.com/news/security/pacific-city-bank-discloses-ransomware-attack-claimed-by-avoslocker/ 8、报告称英国公司在夏季每47秒遭受一次攻击 https://www.infosecurity-magazine.com/news/uk-firms-one-attack-every-47/ 9、全球知名短信发送服务商Syniverse遭黑客入侵长达5年 https://securityboulevard.com/2021/10/syniverse-hack-billions-of-users-data-leaks-over-five-years/ 10、有人在黑客论坛上出售15亿facebook用户数据 https://www.dailysabah.com/business/tech/data-of-over-15-billion-facebook-users-being-sold-on-dark-web
网络安全日报 2021年10月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发布针对Apache CVE-2021-41773漏洞的NMAP脚本 https://securityaffairs.co/wordpress/123148/hacking/nmap-script-cve-apache-2021-41773.html 2、Sky.com 服务器因配置错误而泄露数据 https://securityaffairs.co/wordpress/123143/data-breach/sky-com-server-misconfiguration.html 3、荷兰政府利用情报或军事力量应对勒索软件攻击 https://therecord.media/netherlands-can-use-intelligence-or-armed-forces-to-respond-to-ransomware-attacks/ 4、苏格兰工程公司Weir遭受重大网络攻击 https://www.bbc.com/news/uk-scotland-scotland-business-58801753 5、印度政府发布电力行业网络安全指南 https://ciso.economictimes.indiatimes.com/news/govt-releases-guidelines-for-cybersecurity-in-power-sector/86857960 6、美国媒体集团CMG遭勒索软件攻击后中断了广播 https://securityaffairs.co/wordpress/123136/malware/cox-media-group-ransomware.html 7、Apple 要求所有应用程序都可以让用户轻松删除他们的帐户 https://thehackernews.com/2021/10/apple-requires-devs-to-make-it-easy-for.html 8、美司法部将对未报告网络安全事件的承包商处以罚款 https://www.inforisktoday.com/us-doj-to-fine-contractors-for-failure-to-report-incidents-a-17695 9、研究显示2022年诈骗机器人电话将使消费者损失400亿美元 https://www.helpnetsecurity.com/2021/10/07/fraudulent-robocalls-threat/ 10、微软修复了阻止Azure虚拟桌面安全更新的错误 https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-blocking-azure-virtual-desktops-security-updates/
网络安全日报 2021年10月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌修复 Chrome 中的四个严重漏洞 https://www.securityweek.com/google-patches-four-severe-vulnerabilities-chrome 2、Apache 发布了另一个 HTTP 服务器零日漏洞的补丁 https://www.securityweek.com/apache-releases-another-patch-actively-exploited-http-server-zero-day 3、思科修补安全设备、商业交换机中的高危漏洞 https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-security-appliances-business-switches 4、勒索软件组织 FIN12 针对医疗保健业 https://thehackernews.com/2021/10/ransomware-group-fin12-aggressively.html 5、研究人员警告针对 Linux 的 FontOnLake Rootkit 恶意软件 https://thehackernews.com/2021/10/researchers-warn-of-fontonlake-rootkit.html 6、微软默认禁用 Excel 4.0 宏以保护用户 https://www.bleepingcomputer.com/news/microsoft/microsoft-is-disabling-excel-40-macros-by-default-to-protect-users/ 7、Firefox 93 新增 HTTP 下载阻止和新的用户隐私功能 https://portswigger.net/daily-swig/firefox-93-lands-with-http-download-blocking-new-user-privacy-features 8、德国网络安全监管机构调查小米手机 https://www.solidot.org/story?sid=69109 9、微软称政府资助的网络犯罪攻击中,俄罗斯占58% https://securityaffairs.co/wordpress/123124/apt/russuan-nation-state-attacks.html 10、Python包Yamale存在一个高危的代码注入漏洞 https://thehackernews.com/2021/10/code-execution-bug-affects-yamale.html
网络安全日报 2021年10月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、MalKamak 利用 ShellClient RAT 瞄准航空航天和电信公司 https://www.securityweek.com/iran-linked-malkamak-hackers-targeting-aerospace-telcos-shellclient-rat 2、由于服务器配置错误Twitch 遭数据和源代码泄漏 https://thehackernews.com/2021/10/twitch-suffers-massive-125gb-data-and.html 3、谷歌计划在年底前为 1.5 亿用户自动开启两步验证 https://thehackernews.com/2021/10/google-to-turns-on-2-factor.html 4、霍尼韦尔 Experion PKS 和 ACE 控制器发现多个严重漏洞 https://thehackernews.com/2021/10/multiple-critical-flaws-discovered-in.html 5、大华摄像头2个漏洞的PoC漏洞在网上公开 https://securityaffairs.co/wordpress/123076/hacking/dahua-cameras-flaws.html 6、LANtenna 攻击允许通过以太网电缆从隔离设备中窃取数据 https://securityaffairs.co/wordpress/123008/hacking/lantenna-attack-exfiltration-technique.html 7、Apache 修补了一个被在野外利用的零日漏洞 https://securityaffairs.co/wordpress/122999/hacking/apache-zero-day-flaw.html 8、Apple Pay存在漏洞可被利用于未经授权的支付 https://thehackernews.com/2021/10/apple-pay-can-be-abused-to-make.html 9、美国联合30个国家共同打击影响全球的勒索软件团伙 https://www.bleepingcomputer.com/news/security/us-unites-30-countries-to-disrupt-global-ransomware-attacks/ 10、macOS Gatekeeper绕过的PoC在线发布 https://www.securityweek.com/poc-exploit-released-macos-gatekeeper-bypass
网络安全日报 2021年09月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 Facebook开源Mariana Trench代码分析工具 https://www.securityweek.com/facebook-open-sources-mariana-trench-code-analysis-tool2、Google宣布为Tsunami扫描器编写插件的人提供奖励 https://www.securityweek.com/google-announces-rewards-tsunami-security-scanner-plugins3、GriftHorse恶意软件感染了70个国家/地区超1000万部安卓手机 https://securityaffairs.co/wordpress/122730/malware/grifthorse-malware-campaign.html4、Apple AirTag 中未修复的漏洞可导致凭据收集、点击劫持等攻击 https://threatpost.com/apple-airtag-zero-day-trackers/175143/5、开源软件Cachet中的RCE漏洞可能使用户面临风险 https://portswigger.net/daily-swig/rce-vulnerabilities-in-open-source-software-cachet-could-put-users-at-risk6、Microsoft Edge 中的多个漏洞可能允许任意代码执行 https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-microsoft-edge-could-allow-for-arbitrary-code-execution_2021-1237、Twitter机器人诱骗用户通过PayPal和Venmo付款 https://portswigger.net/daily-swig/social-media-scam-twitter-bots-are-tricking-users-into-making-paypal-and-venmo-payments-into-fraudsters-accounts8、网络钓鱼攻击利用伪造的Zix加密电子邮件 https://www.armorblox.com/blog/blox-tales-zix-credential-phishing/9、儿童故事书应用FarFaria暴露290万用户数据 https://www.hackread.com/storybooks-for-children-app-farfaria-exposed-data/10、俄罗斯警方逮捕了 Group-IB 的首席执行官 https://securityaffairs.co/wordpress/122710/cyber-crime/group-ib-ceo-arrested-treason-changes.html
网络安全日报 2021年09月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 VMware vCenter CVE-2021-22005 漏洞的PoC已公开发布 https://securityaffairs.co/wordpress/122686/hacking/cve-2021-22005-exploit-vmware-vcenter.html2、新的恶意软件BloodyStealer针对游戏行业 https://securityaffairs.co/wordpress/122646/cyber-crime/bloodystealer-malware-targets-gamers.html3、趋势科技修补了ServerProtect 解决方案中一个严重漏洞 https://securityaffairs.co/wordpress/122694/security/trend-micro-serverprotec-solution-flaw.html4、德国联邦信息安全办公室(BSI)调查中国手机 https://securityaffairs.co/wordpress/122604/intelligence/bsi-investigates-chinese-mobile-phones.html5、Confluence RCE 漏洞在多个网络攻击活动中被利用 https://thehackernews.com/2021/09/atlassian-confluence-rce-flaw-abused-in.html6、微软警告针对 Active Directory FS 服务器的 FoggyWeb 恶意软件 https://thehackernews.com/2021/09/microsoft-warns-of-foggyweb-malware.html7、ImmuniWeb 推出用于识别未受保护的云存储的免费工具 https://www.securityweek.com/immuniweb-launches-free-tool-identifying-unprotected-cloud-storage8、FinSpy 监视间谍软件劫持并替换UEFI引导程序安装Bootkit https://www.securityweek.com/finspy-surveillance-spyware-fitted-uefi-bootkit9、OWASP Top 10 更新了三个新类别 https://www.securityweek.com/owasp-top-10-updated-three-new-categories10、Mirai_ptea_Rimasuta变种利用锐捷路由器0day传播 https://blog.netlab.360.com/rimasuta-spread-with-ruijie-0day-en/
网络安全日报 2021年09月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Visual Studio Code 远程开发插件中存在RCE漏洞 https://securityaffairs.co/wordpress/122638/hacking/rce-visual-studio-code-remote-development-extension.html2、Jupyter恶意软件新版本通过MSI安装程序分发 https://securityaffairs.co/wordpress/122627/cyber-crime/jupyter-infostealer-msi-installers.html3、俄罗斯 APT 组织Turla在目标系统上部署新后门 https://thehackernews.com/2021/09/russian-turla-apt-group-deploying-new.html4、新的安卓恶意软件窃取来自 378 个银行和钱包应用程序数据 https://thehackernews.com/2021/09/new-android-malware-steals-financial.html5、VMware确认最近修补的vCenter Server漏洞已被在野利用 https://www.securityweek.com/vmware-confirms-wild-exploitation-vcenter-server-vulnerability6、Cring 勒索软件利用十多年前的Adobe漏洞 https://cyware.com/news/cring-ransomware-targets-a-decade-old-adobe-flaw-caf2c4127、Safepal Wallet恶意附加组件窃取用户加密货币 https://www.bleepingcomputer.com/news/security/malicious-safepal-wallet-firefox-add-on-stole-cryptocurrency/8、攻击者利用虚假Uber安全警报窃取用户信息 https://blog.malwarebytes.com/malwarebytes-news/2021/09/beware-uber-scam-lures-victims-with-alert-from-a-real-uber-number/9、Desorden团伙从ABX Express窃取200GB数据 https://www.databreaches.net/desorden-group-claims-to-have-stolen-200-gb-of-data-from-abx-express/10、QNAP 修复 QVR 视频监控解决方案中的高危漏洞 https://www.bleepingcomputer.com/news/security/qnap-fixes-critical-bugs-in-qvr-video-surveillance-solution/
网络安全日报 2021年09月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、JSC GREC Makeyev 和其他俄罗斯实体受到网络攻击 https://securityaffairs.co/wordpress/122589/hacking/jsc-grec-makeyev-russia-orgs-attacks.html2、谷歌TAG团队发现攻击者使用新的代码签名技巧来逃避检测 https://securityaffairs.co/wordpress/122576/hacking/code-signing-avoid-detection.html3、苹果iCloud Private Relay泄露用户真实IP https://thehackernews.com/2021/09/apples-new-icloud-private-relay-service.html4、 Mac ZuRu 恶意软件利用百度推广进行传播 https://cyware.com/news/zuru-malware-exploits-baidu-search-results-7c48549c5、欧盟将Ghostwriter 黑客活动归咎于俄罗斯 https://www.bleepingcomputer.com/news/security/eu-officially-blames-russia-for-ghostwriter-hacking-activities/6、报告发现 68% 的恶意软件来自云应用程序 https://securityintelligence.com/news/cloud-security-malware-cloud-apps/7、Let's Encrypt 的根证书 将于 9 月 30 日到期 https://portswigger.net/daily-swig/device-breakage-concerns-persist-days-before-lets-encrypt-root-cert-expiry8、思科Talos发现攻击者使用商业RAT针对印度次大陆 https://blog.talosintelligence.com/2021/09/operation-armor-piercer.html9、网络钓鱼活动冒充WhatsApp分发恶意软件 https://portswigger.net/daily-swig/fake-whatsapp-backup-message-delivers-malware-to-spanish-speakers-devices10、微软WPBT漏洞允许黑客在Windows设备安装rootkit https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/
网络安全日报 2021年09月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SonicWall 修补 SMA 设备中的关键漏洞 https://www.securityweek.com/sonicwall-patches-critical-vulnerability-sma-appliances 2、欧洲主要呼叫中心提供商之一的 GSS 遭受勒索软件攻击 https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html 3、 Chrome 发布紧急更新修补了一个被在野利用的0day漏洞 https://securityaffairs.co/wordpress/122561/security/google-chrome-zero-day-flaw.html 4、研究人员发布了针对 3 个 iOS 0day的 PoC https://securityaffairs.co/wordpress/122545/hacking/poc-exploit-code-ios-zero-day.html 5、一份包含 38 亿条 Clubhouse 和 Facebook 用户数据在线出售 https://securityaffairs.co/wordpress/122532/cyber-crime/clubhouse-facebook-data-scraping.html 6、新的 FamousSparrow APT使用ProxyLogon漏洞进行攻击 https://securityaffairs.co/wordpress/122525/apt/famoussparrow-apt-target-hotels.html 7、一种新的零日漏洞被利用来危害 Mac 系统 https://www.helpnetsecurity.com/2021/09/24/cve-2021-30869/ 8、开发人员修复了 Apache HTTP Server 中的多个漏洞 https://portswigger.net/daily-swig/developers-fix-multitude-of-vulnerabilities-in-apache-http-server 9、TangleBot恶意软件针对美国和加拿大移动用户 https://www.cloudmark.com/en/blog/mobile/tanglebot-new-advanced-sms-malware-targets-mobile-users-across-us-and-canada-covid-19 10、Debt-IN公司遭勒索软件攻击泄露南非公民数据 https://portswigger.net/daily-swig/millions-of-south-africans-caught-up-in-security-incident-after-debt-recovery-firm-suffers-significant-data-breach