网络安全日报 2021年09月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Zoho 确认其ADSelfService Plus中的身份验证绕过0day漏洞 https://www.securityweek.com/zoho-confirms-zero-day-authentication-bypass-attacks 2、谷歌发布安全更新修补 40 个Android 漏洞 https://www.securityweek.com/google-android-security-update-patches-40-vulnerabilities 3、霍华德大学遭勒索软件攻击后取消课程和封校 https://www.securityweek.com/howard-university-cancels-classes-shuts-campus-after-ransomware-attack 4、700万以色列人的个人信息在暗网出售 https://securityaffairs.co/wordpress/121984/breaking-news/israelis-data-online.html 5、Groove 团伙泄露了50万个Fortinet 设备凭据列表 https://securityaffairs.co/wordpress/121985/cyber-crime/groove-gang-fortinet-leaks.html 6、微软警告 Internet Explorer 中的0day漏洞被积极利用 https://securityaffairs.co/wordpress/121964/security/microsoft-zero-day.html 7、俄罗斯通信监管机构 Roskomnadzor 封禁了多个VPN https://securityaffairs.co/wordpress/121979/intelligence/russian-roskomnadzor-blocks-vpns.html 8、TeamTNT 的新工具针对多个操作系统 https://threatpost.com/teamtnt-target-multiple-os/169279/ 9、HAProxy 披露严重HTTP 请求走私攻击漏洞 https://thehackernews.com/2021/09/haproxy-found-vulnerable-to-critical.html 10、专家发现针对库尔德族群的移动间谍软件攻击 https://thehackernews.com/2021/09/experts-uncover-mobile-spyware-attacks.html
网络安全日报 2021年09月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、德国承认警方使用了有争议的 Pegasus 间谍软件 https://www.securityweek.com/germany-admits-police-used-controversial-pegasus-spyware 2、微软发布紧急补丁公告警告MSHTML 中存在远程代码执行漏洞 https://www.securityweek.com/microsoft-office-zero-day-hit-targeted-attacks 3、REvil勒索软件团伙的服务器再次神秘上线 https://securityaffairs.co/wordpress/121952/cyber-crime/revil-ransomware-gang-servers-back-online.html 4、研究人员发布了 Ghostscript 零日漏洞 PoC 漏洞利用代码 https://securityaffairs.co/wordpress/121940/hacking/ghostscript-poc-exploit.html 5、Jenkins 项目的服务器遭攻击者利用Confluence 漏洞入侵 https://securityaffairs.co/wordpress/121934/hacking/jenkins-server-security-breach.html 6、Ragnar Locker团伙称如果受害者联系执法机构将立即泄露数据 https://securityaffairs.co/wordpress/121924/cyber-crime/ragnar-locker-threatens-victims-fbi.html 7、法国政府签证网站遭网络攻击泄露申请人信息 https://portswigger.net/daily-swig/french-government-visa-website-hit-by-cyber-attack-that-exposed-applicants-personal-data 8、爱尔兰警察局查封HSE网络攻击团伙的基础设施 https://www.irishtimes.com/news/crime-and-law/garda%C3%AD-seize-infrastructure-from-hse-cyber-attack-gang-1.4665454 9、数百万摩洛哥公民个人数据在线泄露 https://www.moroccoworldnews.com/2021/09/344304/personal-data-of-2-million-moroccans-leaked-online 10、Barracuda 的报告显示39% 的互联网流量来自不良爬虫 https://www.helpnetsecurity.com/2021/09/07/bad-bots-internet-traffic
网络安全日报 2021年09月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、恶意软件伪装成破解软件进行传播 https://thehackernews.com/2021/09/traffic-exchange-networks-distributing.html 2、NETGEAR 修复了智能交换机中多个高危漏洞 https://thehackernews.com/2021/09/critical-auth-bypass-bug-affect-netgear.html 3、Apple宣布推迟设备图像扫描计划 https://thehackernews.com/2021/09/critical-auth-bypass-bug-affect-netgear.html 4、一名TrickBot 团伙成员在首尔国际机场被捕 https://securityaffairs.co/wordpress/121909/cyber-crime/trickbot-gang-developer-arrested.html 5、NPM包"pac-resolver"修复远程代码执行漏洞 https://www.zdnet.com/article/this-npm-package-with-millions-of-weekly-downloads-has-fixed-a-remote-code-execution-flaw 6、报告称2021 年上半年勒索软件攻击增加了 288% https://www.helpnetsecurity.com/2021/09/06/ransomware-attacks-increased-2021/ 7、FBI警告针对食品和农业领域的勒索软件攻击 https://www.hackread.com/fbi-somware-attack-food-agriculture-sectors/ 8、O.MG充电电缆可以从苹果设备远程窃取数据 https://www.hackread.com/o-mg-malicious-lighting-cable-log-keystrokes-malware/ 9、包含3900万法国人详细信息的数据库在暗网出售 https://www.technadu.com/massive-pack-containing-details-of-39-million-french-is-for-sale-on-the-darkweb/299454/ 10、新的恶意软件使用CLFS日志文件来躲避检测 https://thehackernews.com/2021/09/this-new-malware-family-using-clfs-log.html
网络安全日报 2021年09月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Pacific City Bank遭 AVOS Locker 勒索软件攻击 https://securityaffairs.co/wordpress/121872/cyber-crime/pacific-city-bank-avos-locker-ransomware.html 2、WhatsApp 因 违反GDPR 相关规定被罚款 2.25 亿欧元 https://securityaffairs.co/wordpress/121866/security/whatsapp-fined-e225m-gdpr.html 3、新西兰第三大运营商Vocus ISP遭大规模DDoS攻击 https://securityaffairs.co/wordpress/121856/hacking/new-zealand-ddos.html 4、Babuk 勒索软件源码在黑客论坛出售 https://securityaffairs.co/wordpress/121831/cyber-crime/babuk-source-code-leak.html 5、Conti 勒索软件利用ProxyShell漏洞攻击Exchange服务器 https://securityaffairs.co/wordpress/121815/cyber-crime/conti-ransomware-gang-proxyshell.html 6、FIN7黑客利用Windows 11主题文档钓鱼攻击传播后门 https://thehackernews.com/2021/09/fin7-hackers-using-windows-11-themed.html 7、攻击者可利用Comcast遥控器中的漏洞进行射频攻击 https://threatpost.com/comcast-rf-attack-remotes-surveillance/169133 8、新的恶意软件使用CLFS日志文件来逃避检测 https://thehackernews.com/2021/09/this-new-malware-family-using-clfs-log.html 9、研究人员设计了一种阻止USB恶意软件的设备 https://www.infosecurity-magazine.com/news/invent-device-thwart-usb-malware/ 10、美国迪尔菲尔德镇数据泄露暴露居民个人信息 https://www.recorder.com/Deerfield-residents-victim-of-security-breach-42259800
网络安全日报 2021年09月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Moxa 铁路通信设备受60个漏洞影响 https://www.securityweek.com/flaws-moxa-railway-devices-could-allow-hackers-cause-disruptions 2、BrakTooth:新的蓝牙漏洞可能影响数百万台设备 https://www.securityweek.com/braktooth-new-bluetooth-vulnerabilities-could-affect-millions-devices 3、Mozi 僵尸网络的作者已被抓捕 https://blog.netlab.360.com/the_death_of_mozi_cn/ 4、WhatApp 修复图像过滤功能可能导致数据泄露的高危漏洞 https://securityaffairs.co/wordpress/121778/security/whatsapp-cve-2020-1910-data-exposure.html 5、攻击者正在积极利用 Confluence 最近修补的漏洞 https://securityaffairs.co/wordpress/121760/hacking/confluence-cve-2021-26084-rce.html 6、Autodesk 证实遭 SolarWinds 供应链攻击 https://www.bleepingcomputer.com/news/security/autodesk-reveals-it-was-targeted-by-russian-solarwinds-hackers 7、法国药店在线平台泄露了70万Covid检测结果 https://www.connexionfrance.com/French-news/700000-French-pharmacy-Covid-test-results-left-publicly-available 8、英国 VoIP 运营商VoIP Unlimited 和 Voipfone 遭 DDoS 攻击中断 https://www.theregister.com/2021/09/02/uk_voip_telcos_revil_ransom/ 9、Node.js修补高危tar处理漏洞 https://portswigger.net/daily-swig/node-js-archives-serious-tar-handling-vulnerabilities-with-software-update 10、FTC 禁止 SpyFone 销售 Stalkerware 监视软件 https://www.securityweek.com/ftc-bans-spyfone-surveillance-business-selling-stalkerware
网络安全日报 2021年09月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新加坡政府科技局在HackerOne上推出新的漏洞奖励计划 https://www.securityweek.com/singapore%E2%80%99s-govtech-announces-new-vulnerability-rewards-programme 2、谷歌发布 Chrome 93 ,修复27个安全漏洞 https://www.securityweek.com/google-awards-over-130000-flaws-patched-release-chrome-93 3、 Linphone SIP 客户端belle-sip库存严重漏洞 https://www.securityweek.com/vulnerability-allows-remote-dos-attacks-against-apps-using-linphone-sip-stack 4、 研究人员提出基于机器学习的蓝牙认证方案 https://thehackernews.com/2021/08/researchers-propose-machine-learning.html 5、Cream Finance加密货币交易平台遭到黑客攻击 https://threatpost.com/cream-finance-defi-29m/169077/ 6、Market黑客组织在暗网出售日本富士通的数据 https://www.zdnet.com/article/fujitsu-says-stolen-data-being-sold-on-dark-web-related-to-customers/ 7、印度尼西亚COVID-19追踪应用程序泄露用户信息 https://www.technadu.com/indonesia-launches-investigation-possible-breach-covid-19-tracing-app/298229/ 8、QNAP 正在为受OpenSSL 漏洞影响的产品开发安全补丁 https://securityaffairs.co/wordpress/121724/iot/qnap-openssl-nas.html 9、Gutenberg 模板库和 Redux 框架插件漏洞影响数百万WordPress站点 https://threatpost.com/gutenberg-template-library-redux-bugs-wordpress/169111/ 10、本田雅阁、思域等多款车存在密钥重放攻击安全漏洞 https://github.com/hackingintoyourheart/unoriginal-rice-patty
网络安全日报 2021年09月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Fortress Security Store 家庭安全系统中发现严重漏洞 https://www.securityweek.com/vulnerabilities-can-allow-hackers-disarm-fortress-home-security-systems 2、研究人员发现GitHub Copilot 生成的代码中约有 40% 存在漏洞 https://www.securityweek.com/code-generated-github-copilot-can-introduce-vulnerabilities-researchers 3、QNAP 设备受最新 OpenSSL 漏洞影响 https://threatpost.com/qnap-openssl-bugs/169054/ 4、LockFile勒索软件利用间歇性加密技术绕过防护 https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html 5、开源Python机器学习框架TensorFlow存在RCE漏洞 https://portswigger.net/daily-swig/deserialization-bug-in-tensorflow-machine-learning-framework-allowed-arbitrary-code-execution 6、诈骗者冒充OpenSea数字资产市场的客服窃取加密货币 https://www.govinfosecurity.com/scammers-impersonate-opensea-customer-support-a-17414 7、WooCommerce定价插件允许恶意代码注入 https://threatpost.com/woocommerce-plugin-malicious/169063/ 8、美国SEC 将监控 DeFi 平台上的非法活动 https://www.govinfosecurity.com/sec-to-monitor-illicit-activity-on-defi-platforms-a-17410 9、AMD Zen+、Zen2 系列处理器易受Meltdown侧信道攻击 https://www.theregister.com/2021/08/30/amd_meltdown_zen 10、Puma 1GB被盗数据在暗网上公开拍卖 https://www.freebuf.com/news/286723.html
网络安全日报 2021年08月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美司法部宣布设立奖学金计划用于检察官和律师的网络安全培训 https://securityaffairs.co/wordpress/121646/security/us-doj-cyber-fellowship-program.html 2、CISA 敦促企业修复 Microsoft Azure Cosmos DB 漏洞 https://securityaffairs.co/wordpress/121638/security/cisa-microsoft-azure-cosmos-db-flaw.html 3、台达工业能源管理系统存多个高危漏洞影响生产安全 https://www.securityweek.com/exploitation-flaws-delta-energy-management-system-could-have-dire-consequences 4、HPE 警告 Sudo 漏洞影响AirWave 管理平台 https://threatpost.com/hpe-sudo-bug-aruba-platform/169038/ 5、新的 Mirai 变体利用 WebSVN 命令注入漏洞 https://unit42.paloaltonetworks.com/cve-2021-32305-websvn 6、ProxyToken 漏洞可修改 Exchange 服务器配置 https://therecord.media/proxytoken-vulnerability-can-modify-exchange-server-configs/ 7、曼谷航空公司遭LockBit勒索软件攻击导致数据泄露 https://www.zdnet.com/article/bangkok-airways-apologizes-for-passport-info-breach-as-lockbit-ransomware-group-threatens-release-of-more-data/ 8、Phorpiex僵尸网络停止运营并在暗网出售源码 https://securityaffairs.co/wordpress/121560/malware/phorpiex-botnet.html 9、研究人员发现了新版本的DirtyMoe僵尸网络 https://cyware.com/news/dirtymoe-botnet-returns-with-new-tricks-ba3ef2b8 10、网信办:算法推荐服务提供者不得利用算法屏蔽信息、过度推荐 https://www.freebuf.com/news/286454.html
网络安全日报 2021年08月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、FBI 共享"HIVE"勒索软件的 IOC https://www.securityweek.com/fbi-shares-iocs-hive-ransomware-attacks 2、Annke 视频监控产品高危漏洞可被远程攻击 https://www.securityweek.com/vulnerability-allows-remote-hacking-annke-video-surveillance-product 3、Azure Cosmos DB 存在未授权即可接管的严重漏洞 https://www.securityweek.com/critical-vulnerability-exposed-azure-cosmos-dbs-months 4、一些 Synology 产品受到最近披露的 OpenSSL 漏洞影响 https://securityaffairs.co/wordpress/121600/security/synology-synology-openssl-flaws.html 5、EskyFun 遭数据泄露,超过 100 万玩家受到影响 https://securityaffairs.co/wordpress/121589/data-breach/eskyfun-data-leak.html 6、研究人员演示了万事达和Visa卡PIN绕过攻击 https://securityaffairs.co/wordpress/121571/hacking/pin-bypass-attack-mastercard-maestro.html 7、Ragnarok 勒索软件停止运营并发布了解密密钥 https://securityaffairs.co/wordpress/121512/cyber-crime/ragnarok-ransomware-master-key.html 8、Verizon移动消息服务Vzwpix被利用于网络钓鱼 https://cofense.com/blog/mobile-messaging-phish/ 9、Parallels Desktop针对其权限提升漏洞发布解决方法 https://threatpost.com/parallels-inconvenient-fix/168997/ 10、波士顿公共图书馆遭到网络攻击导致系统中断 https://www.bleepingcomputer.com/news/security/boston-public-library-discloses-cyberattack-system-wide-technical-outage/
网络安全日报 2021年08月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Atlassian 修补 Confluence 中的高危代码执行漏洞 https://www.securityweek.com/atlassian-patches-critical-code-execution-vulnerability-confluence 2、Microsoft 发布有关 ProxyShell 漏洞的指南 https://www.securityweek.com/microsoft-issues-guidance-proxyshell-vulnerabilities 3、思科修补数据中心产品中的严重漏洞 https://securityaffairs.co/wordpress/121485/breaking-news/cisco-apic-flaw.html 4、CISA 发布针对 Pulse Secure 设备的恶意软件分析报告 https://securityaffairs.co/wordpress/121492/security/pulse-secure-cisa-mars.html 5、约会应用 Bumble 中的"三角测量"漏洞可定位用户精确位置 https://portswigger.net/daily-swig/trilateration-vulnerability-in-dating-app-bumble-leaked-users-exact-location 6、Kaseya 修补 Unitrends 服务器零日漏洞 https://www.bleepingcomputer.com/news/security/kaseya-patches-unitrends-server-zero-days-issues-client-mitigations 7、三星证实手机默认应用将停止展示广告 https://www.theverge.com/2021/8/18/22630332/samsung-ads-default-stock-apps-weather-pay-theme-confirmed 8、Poly Network向归还数字货币的黑客发放奖金和Offer https://www.bleepingcomputer.com/news/security/hacker-gets-500k-reward-for-returning-stolen-cryptocurrency/ 9、美国白宫与微软、谷歌等多家公司商议共同改善国家网络安全 https://www.freebuf.com/news/286317.html 10、工信部通报下架67款侵害用户权益APP https://www.freebuf.com/news/286230.html