网络安全日报 2021年09月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、苹果周四证实了针对旧款 iPhone 的新的0day攻击 https://www.securityweek.com/apple-confirms-new-zero-day-attacks-older-iphones 2、Apple 在 iOS 和 macOS 中弃用过时的 TLS 1.0、 1.1 协议 https://www.securityweek.com/apple-deprecates-outdated-tls-protocols-ios-macos 3、思科修补 IOS XE 软件中的关键漏洞 https://www.securityweek.com/cisco-patches-critical-vulnerabilities-ios-xe-software 4、Microsoft Exchange 自动发现功能漏洞导致数十万域凭据泄露 https://securityaffairs.co/wordpress/122510/hacking/microsoft-exchange-autodiscover-feature-bug.html 5、微软发现名为BulletProofLink 的大规模网络钓鱼即服务 (PHaaS) https://securityaffairs.co/wordpress/122503/cyber-crime/bulletprooflink-phishing-phaas.html 6、研究人员发现NanoMQ 中的0day漏洞,影响上亿个物联网设备 https://threatpost.com/100m-iot-devices-zero-day-bug/174963/ 7、Microsoft WPBT 中一个未修补的漏洞影响Win 8和之后的所有系统 https://thehackernews.com/2021/09/a-new-bug-in-microsoft-windows-could.html 8、Beego 修补开源 Web 框架中的严重 XSS 漏洞 https://portswigger.net/daily-swig/beego-patches-severe-xss-vulnerability-in-open-source-web-framework 9、钓鱼邮件利用恶意PowerPoint文档分发AgentTesla https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-powerpoint-documents-on-the-rise/ 10、行为健康提供商Texoma数据泄露影响超过2.4万人 https://therecord.media/data-breach-at-texas-behavioral-health-center-affects-more-than-24000/
网络安全日报 2021年09月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Netgear 修补小型路由器中的远程代码执行漏洞 https://www.securityweek.com/netgear-patches-remote-code-execution-flaw-soho-routers 2、海康威视摄像头因严重漏洞可能遭受攻击 https://www.securityweek.com/many-hikvision-cameras-exposed-attacks-due-critical-vulnerability 3、研究人员在 AWS WorkSpaces 中发现远程代码执行漏洞 https://www.securityweek.com/remote-code-execution-vulnerability-found-aws-workspaces 4、由于 Microsoft Exchange 协议缺陷导致数十万凭据泄露 https://www.securityweek.com/hundreds-thousands-credentials-leaked-due-microsoft-exchange-protocol-flaw 5、Chrome 94更新修补了19个漏洞包含多个高危漏洞 https://www.securityweek.com/google-working-improving-memory-safety-chrome 6、研究人员在Nagios 网络管理产品发现多个严重漏洞 https://securityaffairs.co/wordpress/122464/hacking/nagios-network-management-systems-flaws.html 7、 VMware 修复了 vCenter Server 中的高危漏洞 https://securityaffairs.co/wordpress/122454/security/vmware-vcenter-server-cve-2021-22005.html 8、以色列通信巨头Voicenter公司遭到黑客入侵 https://www.middleeastmonitor.com/20210921-israel-communications-company-hit-by-major-cyberattack/ 9、美国爱荷华州农民合作社遭到勒索软件攻击 https://threatpost.com/blackmatter-strikes-iowa-farmers-cooperative-demands-5-9m-ransom/174846/ 10、CISA、FBI和NSA警告称Conti 勒索软件攻击正在升级 https://securityaffairs.co/wordpress/122480/security/conti-ransomware-attacks-escalation.html
网络安全日报 2021年09月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Finder 中未修补的高危漏洞影响macOS 用户 https://thehackernews.com/2021/09/unpatched-high-severity-vulnerability.html 2、新的 Capoae 恶意软件渗透 WordPress 网站并安装后门 https://thehackernews.com/2021/09/new-capoae-malware-infiltrates.html 3、Cring Ransomware Gang 利用 11 年前的 ColdFusion 漏洞 https://thehackernews.com/2021/09/cring-ransomware-gang-exploits-11-year.html 4、研究人员在 iOS 15 发布当天披露 iPhone 锁屏绕过 https://therecord.media/researcher-discloses-iphone-lock-screen-bypass-on-ios-15-launch-day/ 5、Mirai 在野外利用 OMIGOD 漏洞 https://cyware.com/news/mirai-exploits-omigod-flaws-in-the-wild-6c743051 6、Turla APT 组织使用新后门攻击阿富汗、德国和美国 https://securityaffairs.co/wordpress/122437/apt/turla-apt-new-backdoor-afghanistan.html 7、Apache OpenOffice 存在远程代码执行漏洞 https://securityaffairs.co/wordpress/122426/security/apache-openoffice-rce-cve-2021-33035.html 8、1.06亿泰国游客数据在网上泄露 https://securityaffairs.co/wordpress/122418/data-breach/thailand-visitors-leaked-online.html 9、Numando 银行木马利用YouTube、Pastebin等公共平台作为C2 https://securityaffairs.co/wordpress/122371/malware/numando-banking-trojan.html 10、9月Windows安全更新导致网络打印机故障 https://www.bleepingcomputer.com/news/security/new-windows-security-updates-break-network-printing/
网络安全日报 2021年09月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新恶意软件利用 Windows WSL 子系统以逃避检测 https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html 2、Ryuk Ransomware Gang 利用 Microsoft MSHTML 漏洞 https://threatpost.com/microsoft-mshtml-ryuk-ransomware/174780/ 3、AMD CPU 驱动程序漏洞可被利用获取敏感数据 https://www.securityweek.com/amd-chipset-driver-vulnerability-can-allow-hackers-obtain-sensitive-data 4、Mirai 僵尸网络开始利用 OMIGOD 漏洞 https://www.securityweek.com/mirai-botnet-starts-exploiting-omigod-flaw-microsoft-issues-more-guidance 5、互联网协会引入 MANRS 计划以提高路由安全性 https://www.helpnetsecurity.com/2021/09/17/internet-society-manrs-initiative 6、黑客窃取了巴黎医院约140万名患者的个人数据 https://www.securityweek.com/mass-personal-data-theft-paris-covid-tests-hospitals 7、黑客破坏了德国大选管理机构的网站 https://www.securityweek.com/german-election-authority-confirms-likely-cyber-attack 8、一项针对航空业的恶意软件攻击活动在两年后被发现 https://thehackernews.com/2021/09/malware-attack-on-aviation-sector.html 9、FBI:今年美国网恋诈骗损失1.13亿美元 https://www.freebuf.com/news/288898.html 10、新的 Zloader 攻击可以禁用Windows Defender https://www.bleepingcomputer.com/news/security/new-zloader-attacks-disable-windows-defender-to-evade-detection/
网络安全日报 2021年09月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Netgear 智能交换机严重漏洞详情和 PoC 发布 https://thehackernews.com/2021/09/third-critical-bug-affects-netgear.html 2、Travis CI 漏洞暴露了数千个开源项目的重要信息 https://thehackernews.com/2021/09/travis-ci-flaw-exposes-secrets-of.html 3、工信部发布关于加强车联网网络安全和数据安全工作通知 http://www.gov.cn/zhengce/zhengceku/2021-09/16/content_5637709.htm 4、Windows MSHTML 0Day 漏洞被利用部署Cobalt Strike Beacon https://thehackernews.com/2021/09/windows-mshtml-0-day-exploited-to.html 5、REvil/Sodinokibi 勒索软件通用解密器已放出 https://threatpost.com/revil-sodinokibi-ransomware-universal-decryptor/169498/ 6、Drupal 更新修复了多个访问绕过、CSRF 漏洞 https://www.securityweek.com/several-access-bypass-csrf-vulnerabilities-patched-drupal 7、FBI、CISA警告称 Zoho 漏洞CVE-2021-40539 被APT广泛利用 https://securityaffairs.co/wordpress/122293/security/cve-2021-40539-zoho-bug-attacks.html 8、Kali Linux 2021.3 发布,新增渗透测试工具和改进 https://www.kali.org/blog/kali-linux-2021-3-release/ 9、旧版IBM System x服务器存在高严重性漏洞且无安全补丁 https://threatpost.com/no-patch-for-ibm-system-x-servers/169491/ 10、SAP发布2021年9月安全更新修补关键漏洞 https://www.securityweek.com/sap-patches-critical-vulnerabilities-september-2021-security-updates
网络安全日报 2021年09月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft 推出无密码身份验证 https://www.securityweek.com/regular-users-can-now-remove-password-their-microsoft-account 2、微软修补影响Azure用户的OMI软件高危漏洞 https://www.securityweek.com/severe-vulnerabilities-could-expose-thousands-azure-users-attacks 3、Zoom 推出端到端加密电话 https://www.securityweek.com/zoom-introduces-end-end-encrypted-phone-calls 4、西门子、施耐德电气修补 40 多个ICS产品漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-address-over-40-vulnerabilities 5、摩托罗拉 Halo+ 婴儿监视器存在远程代码执行漏洞 https://portswigger.net/daily-swig/remote-code-execution-flaw-allowed-hijack-of-motorola-halo-baby-monitors 6、错误配置的 Firebase 数据库导致大量数据泄漏 https://cyware.com/news/misconfigured-firebase-databases-causing-massive-leaks-609ee158 7、Talos团队在 Nitro Pro PDF 中发现代码执行漏洞 https://blog.talosintelligence.com/2021/09/nitro-pro-code-execution.html 8、Adobe发布更新共修复其核心产品的59个漏洞 https://threatpost.com/adobe-bugs-acrobat-experience-manager/169467/ 9、SAP 通过 2021 年 9 月的安全更新修补关键漏洞 https://www.securityweek.com/sap-patches-critical-vulnerabilities-september-2021-security-updates 10、网络犯罪者在钓鱼活动中冒充 USDOT https://threatpost.com/attackers-impersonate-dot-phishing-scam/169484/
网络安全日报 2021年09月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、恶意软件 ZLoader 变体通过假TeamViewer 下载广告进行传播 https://thehackernews.com/2021/09/new-stealthier-zloader-variant.html 2、HP OMEN 游戏中心漏洞影响数百万台 Windows https://thehackernews.com/2021/09/hp-omen-gaming-hub-flaw-affects.html 3、微软修补了被积极利用的 Windows 零日漏洞 https://threatpost.com/microsoft-patch-tuesday-exploited-windows-zero-day/169459/ 4、研究人员在 PyPI 中发现了逻辑炸弹攻击 https://securityintelligence.com/articles/cryptominers-snuck-logic-bomb-into-python-packages/ 5、谷歌修复了一个被广泛利用的新 Chrome 零日漏洞 https://securityaffairs.co/wordpress/122192/hacking/google-zero-day-10.html 6、超过 6000 万条可穿戴设备、健身追踪记录在线泄露 https://www.zdnet.com/article/over-60-million-records-exposed-in-wearable-fitness-tracking-data-breach-via-unsecured-database/ 7、恶意软件针对墨西哥金融机构窃取用户凭证 https://www.mcafee.com/blogs/other-blogs/mcafee-labs/android-malware-distributed-in-mexico-uses-covid-19-to-steal-financial-credentials/ 8、APT-C-36的新垃圾邮件活动针对南美实体 https://www.trendmicro.com/en_us/research/21/i/apt-c-36-updates-its-long-term-spam-campaign-against-south-ameri.html 9、MikroTik 确认 Mēris 僵尸网络利用了多年前遭入侵的路由器 https://www.securityweek.com/mikrotik-confirms-m%C4%93ris-botnet-targets-routers-compromised-years-ago 10、研究人员发现一种充气新型光纤可用于量子密钥传输 https://www.zdnet.com/article/quantum-cryptography-this-air-filled-fiber-optic-cable-can-transport-un-hackable-keys-say-researchers/
网络安全日报 2021年09月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现面向Linux的CS Beancon -Vermilion Strike https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/ 2、NPM 包:Pac-Resolver 修复高危远程代码执行漏洞 https://thehackernews.com/2021/09/critical-bug-reported-in-npm-package.html 3、Apple 为 NSO 利用的iMessage 零交互0day发布紧急修复程序 https://threatpost.com/apple-emergency-fix-nso-zero-click-zero-day/169416/ 4、WooCommerce 插件漏洞允许随意改价 https://threatpost.com/woocommerce-multi-currency-bug-pricing/169394/ 5、历经3年, OpenSSL 3.0 发布 https://www.securityweek.com/openssl-30-released-after-3-years-development 6、谷歌警告 Chrome 浏览器中的零日漏洞 https://www.securityweek.com/google-warns-exploited-zero-days-chrome-browser 7、研究人员发现诱骗用户连接恶意 AP 的新方法:SSID Stripping https://www.securityweek.com/ssid-stripping-new-method-tricking-users-connecting-rogue-aps 8、BlackMatter 勒索软件团伙攻击了奥林巴斯 https://securityaffairs.co/wordpress/122140/cyber-crime/blackmatter-ransomware-olympus.html 9、REvil勒索软件团伙再次出现并泄露数据 https://www.bleepingcomputer.com/news/security/revil-ransomware-is-back-in-full-attack-mode-and-leaking-data/ 10、新型银行木马"maxtrilha"针对欧洲和南美银行客户 https://securityaffairs.co/wordpress/122134/malware/maxtrilha-banking-trojan.html
网络安全日报 2021年09月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WhatsApp 推出用户聊天记录云端加密备份支持 https://thehackernews.com/2021/09/whatsapp-to-finally-let-users-encrypt.html 2、思科修补 IOS XR 中的高危安全漏洞 https://www.securityweek.com/cisco-patches-high-severity-security-flaws-ios-xr 3、HAProxy 修复了高危 HTTP 请求走私漏洞( CVE-2021-40346) https://www.haproxy.com/blog/september-2021-duplicate-content-length-header-fixed/ 4、新的 SOVA Android 银行木马正在迅速扩张 https://securityaffairs.co/wordpress/122090/cyber-crime/sova-android-banking-trojan.html 5、微软修复了 Azure 容器实例中的 Azurescape 漏洞 https://securityaffairs.co/wordpress/122081/hacking/microsoft-azurescape-flaw.html 6、专家证实联合国在今年早些时候遭黑客攻击和数据泄露 https://www.infosecurity-magazine.com/news/hackers-steal-data-from-united/ 7、南非国家航天局披露公共FTP服务器数据泄露 https://www.technadu.com/sansa-responds-data-leak-incident-its-nothing-serious/300375/ 8、WordPress发布更新共修复了61个安全漏洞 https://portswigger.net/daily-swig/wordpress-5-8-1-security-release-addresses-clutch-of-vulnerabilities 9、新侧信道攻击可以绕过谷歌Chrome的保护 https://portswigger.net/daily-swig/spook-js-new-side-channel-attack-can-bypass-google-chromes-protections-against-spectre-style-exploits 10、CISA警告称三菱的工业控制器易受远程攻击 https://www.technadu.com/a-widely-deployed-mitsubishi-industrial-controller-is-vulnerable-to-remote-exploitation/300011/
网络安全日报 2021年09月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软警告 Azure 容器实例中存在信息泄漏漏洞 https://www.securityweek.com/microsoft-warns-information-leak-flaw-azure-container-instances 2、美国政府就零信任架构战略草案征求公众意见 https://www.securityweek.com/us-gov-seeks-public-feedback-draft-federal-zero-trust-strategy 3、 Mēris 僵尸网络针对Yandex发动了大规模DDoS攻击 https://securityaffairs.co/wordpress/122048/malware/meris-botnet-ddos.html 4、TeamTNT 黑客组织扩大其武器库瞄准全球数千个组织 https://securityaffairs.co/wordpress/122037/cyber-crime/teamtnt-expands-arsenal.html 5、研究人员发现全球有超过200万台老旧易受攻击的IIS Web服务器 https://securityaffairs.co/wordpress/122044/security/millions-microsoft-servers-exposed-online.html 6、澳大利亚COVID-19数字疫苗应用中存在漏洞可伪造疫苗证明 https://threatpost.com/spoofing-bug-cybersecurity-vaccine-passports/169287/ 7、NCCoE 发布应急响应人员网络安全指南 https://www.infosecurity-magazine.com/news/nccoe-cybersecurity-guide-first/ 8、Fortinet证实 87,000 台FortiGate设备VPN 帐户密码泄露 https://thehackernews.com/2021/09/hackers-leak-vpn-account-passwords-from.html 9、特斯拉(TSLA)全自动驾驶测试版软件泄露 https://electrek.co/2021/09/07/tesla-tsla-full-self-driving-beta-software-leaked/ 10、GitHub 在"tar"和"@npmcli/arborist"包中发现 7 个代码执行漏洞 https://www.bleepingcomputer.com/news/security/github-finds-7-code-execution-vulnerabilities-in-tar-and-npm-cli