网络安全日报 2021年08月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、VMware修复了 vRealize Operations 中的高危漏洞
https://www.securityweek.com/vmware-patches-high-severity-vulnerabilities-vrealize-operations 2、F5 修复了 BIG-IP 设备中多个高危漏洞
https://securityaffairs.co/wordpress/121454/security/f5-big-ip-critical-flaw.html 3、FIN8 最近的攻击中使用了以前未被发现的"Sardonic" 后门
https://securityaffairs.co/wordpress/121446/cyber-crime/fin8-sardonic-backdoor.html 4、ShinyHunters 声称拥有 7000 万 AT&T 客户个人信息数据
https://securityaffairs.co/wordpress/121439/data-breach/shinyhunters-70m-att-customers.html 5、Firefox 将屏蔽不安全文件下载
https://therecord.media/firefox-follows-chrome-and-prepares-to-block-insecure-downloads/ 6、继雷蛇之后,SteelSeries设备被发现可用于Windows 本地提权
https://threatpost.com/windows-10-admin-rights-steelseries-devices/168927/ 7、思科针对高端 Nexus 设备发布关键漏洞修复补丁
https://threatpost.com/cisco-issues-critical-fixes-for-high-end-nexus-gear/168939/ 8、新的 SideWalk 后门针对美国电脑零售商
https://thehackernews.com/2021/08/new-sidewalk-backdoor-targets-us-based.html 9、DLL侧加载攻击利用Windows搜索顺序注入恶意DLL
https://gbhackers.com/dll-side-loading-attack/ 10、OpenSea 用户成为 Discord 网络钓鱼攻击目标以窃取加密货币
https://www.bleepingcomputer.com/news/security/fake-opensea-support-staff-are-stealing-cryptowallets-and-nfts/
网络安全日报 2021年08月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、诺基亚旗下 SAC Wireless 披露数据泄露
https://www.securityweek.com/nokia-owned-sac-wireless-discloses-data-breach 2、OpenSSL 修补高危漏洞(CVE-2021-3711)
https://www.securityweek.com/openssl-vulnerability-can-be-exploited-change-application-data 3、新的 iOS 零点击漏洞可绕过 Apple 的"BlastDoor"沙盒
https://www.securityweek.com/new-ios-zero-click-exploit-defeats-apple-blastdoor-sandbox 4、FBI 公布"OnePercent Group"勒索软件团伙详细信息
https://www.securityweek.com/fbi-shares-details-onepercent-group-ransomware-operators 5、研究人员披露了价值20万美金的Zoom漏洞详细信息
https://www.securityweek.com/details-disclosed-zoom-exploit-earned-researchers-200000 6、WhatsApp for Android 修改版被发现用于传播 Triada 木马
https://thehackernews.com/2021/08/modified-version-of-whatsapp-for.html 7、黑客可以通过输液泵设备漏洞增加药物剂量
https://www.wired.com/story/infusion-pump-hack-dose-increase/ 8、Mirai 僵尸网络利用 Realtek SDK 漏洞瞄准数十万台设备
https://www.bleepingcomputer.com/news/security/botnet-targets-hundreds-of-thousands-of-devices-using-realtek-sdk/ 9、SNI漏洞影响部分安全产品
https://www.inforisktoday.com/sni-vulnerability-affects-some-security-products-a-17344 10、 勒索软件LockFile 使用 PetitPotam NTLM 中继攻击接管Windows 域
https://cyware.com/news/lockfile-uses-petitpotam-attack-to-target-domain-controllers-4f841cf8
网络安全日报 2021年08月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、研究人员披露了Sophos UTM 一个远程代码执行漏洞技术细节
https://securityaffairs.co/wordpress/121392/hacking/sophos-utm-appliance-rce.html 2、Razer Synapse 中的LPE 0day漏洞可获取Windows管理员权限
https://securityaffairs.co/wordpress/121385/hacking/razer-synapse-zero-day.html 3、Realtek SDK 漏洞在披露数天后已有在野利用
https://www.securityweek.com/realtek-sdk-vulnerabilities-exploited-attacks-days-after-disclosure 4、研究人员披露 ShinyHunters 网络犯罪集团的作案手法
https://thehackernews.com/2021/08/researchers-detail-modus-operandi-of.html 5、研究人员分析发现被用于数百万次入侵Linux系统的15大漏洞
https://thehackernews.com/2021/08/top-15-vulnerabilities-attackers.html 6、与Covid-19相关的3800 万条记录敏感数据在线泄露
https://www.wired.com/story/microsoft-power-apps-data-exposed/ 7、巴西最大的服装连锁店Lojas Renner遭勒索软件攻击
https://securityaffairs.co/wordpress/121333/cyber-crime/lojas-renner-ransomware.html 8、美国国务院遭遇网络攻击可能导致严重泄密
https://www.cnbc.com/2021/08/21/us-state-department-reportedly-hit-by-a-cyberattack-in-recent-weeks.html 9、世界银行启动全球网络安全基金
https://www.inforisktoday.com/world-bank-launches-global-cybersecurity-fund-a-17341 10、Poly Network 称黑客已归还被盗的 6 亿美元数字货币
https://cybernews.com/crypto/poly-network-claims-a-hacker-returned-stolen-600-million/
网络安全日报 2021年08月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、《中华人民共和国个人信息保护法》将于2021年11月1日起施行
http://www.xinhuanet.com/politics/2021-08/20/c_1127779295.htm 2、谷歌披露未打补丁的 Windows AppContainer 漏洞详情
https://www.securityweek.com/google-discloses-details-unpatched-windows-appcontainer-flaw 3、BIND DNS 软件修复高危 DoS 漏洞
https://www.securityweek.com/high-severity-dos-vulnerability-patched-bind-dns-software 4、第三方补丁解决 PetitPotam 更多攻击向量
https://www.securityweek.com/third-party-patches-available-more-petitpotam-attack-vectors 5、T-Mobile 数据泄露事件最新数据显示超过 5400 万人受影响
https://securityaffairs.co/wordpress/121361/data-breach/t-mobile-data-breach-update.html 6、Emsisoft 发布免费的 SynAck 勒索软件解密器
https://securityaffairs.co/wordpress/121328/malware/synack-ransomware-decryptor.html 7、物联网僵尸网络Mozi针对网件、华为中兴等设备
https://thehackernews.com/2021/08/mozi-iot-botnet-now-also-targets.html 8、 包含超过7000万客户记录的AT&T数据库遭泄露
https://www.hackread.com/att-breach-shinyhunters-database-selling-70-million-ssn/ 9、LockFile勒索软件使用PetitPotam攻击劫持Windows域
https://www.bleepingcomputer.com/news/security/lockfile-ransomware-uses-petitpotam-attack-to-hijack-windows-domains/ 10、Cloudflare成功缓解了Mirai僵尸网络每秒1720万次请求的DDoS攻击
https://thehackernews.com/2021/08/cloudflare-mitigated-one-of-largest.html
网络安全日报 2021年08月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、 Google Project Zero 批量Windows 中的特权提升 (EoP) 漏洞
https://threatpost.com/windows-eop-bug-detailed-by-google-project-zero/168823/ 2、印第安纳州Covid-19接触者追踪系统泄露超75万个人数据
https://threatpost.com/covid-contact-tracing-exposed-fake-vax-cards/168821/ 3、思科称多款旧版路由器存在高危代码执行漏洞但不打算修复
https://www.securityweek.com/cisco-critical-flaw-older-smb-routers-will-remain-unpatched 4、2021 上半年披露了 600 多个影响工控系统 (ICS) 产品的漏洞
https://www.securityweek.com/over-600-ics-vulnerabilities-disclosed-first-half-2021-report 5、GitHub 敦促用户采用双因素身份验证
https://www.securityweek.com/github-encourages-users-adopt-two-factor-authentication 6、日本加密货币交易所 Liquid 遭攻击被窃取9700万美金数字货币
https://securityaffairs.co/wordpress/121282/cyber-crime/liquid-cryptocurency-exchange-data-theft.html 7、NK-linked InkySquid APT 在最近的攻击中利用 IE 漏洞
https://securityaffairs.co/wordpress/121262/apt/inkysquid-apt-ie-exploirs.html 8、日本保险公司Tokio Marine披露了勒索软件攻击
https://www.cyberscoop.com/tokio-marine-ryan-specialty-group-ransomware-cyber-insurance/ 9、黑客在2020年利用Citrix漏洞入侵了美国人口普查局
https://www.bleepingcomputer.com/news/security/us-census-bureau-hacked-in-january-2020-using-citrix-exploit/ 10、CISA 发布关于防止勒索软件数据泄露的指南
https://www.bleepingcomputer.com/news/security/cisa-shares-guidance-on-how-to-prevent-ransomware-data-breaches/
网络安全日报 2021年08月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、伊朗 APT Hexane 瞄准以色列公司
https://www.securityweek.com/report-iranian-apt-hexane-targets-israeli-companies 2、T-Mobile 确认数据泄露影响数4860万客户
https://www.securityweek.com/t-mobile-confirms-data-breach-impacts-millions-customers 3、黑莓QNX 系统BadAlloc 漏洞影响上亿汽车、医疗、工控设备
https://www.securityweek.com/badalloc-flaw-impacts-many-systems-running-blackberrys-qnx-embedded-os 4、研究人员发现 Diavol 勒索软件与 TrickBot 僵尸网络团队关联
https://securityaffairs.co/wordpress/121251/malware/diavol-ransomware-trickbot-gang.html 5、德国DPA 警告说,公共机构使用 Zoom 违反欧盟 GDPR
https://securityaffairs.co/wordpress/121232/digital-id/hamburg-dpa-zoom-gdpr.html 6、研究人员发现Neurevt木马针对墨西哥用户
https://blog.talosintelligence.com/2021/08/neurevt-trojan-takes-aim-at-mexican.html 7、安卓恶意软件FLUBOT瞄准德国和波兰的银行
https://kkhacklabs.com/resurgent-flubot-malware-targets-german-and-polish-banks/ 8、巴西财政部遭到勒索软件攻击
https://www.zdnet.com/article/brazilian-national-treasury-hit-with-ransomware-attack/ 9、大通银行客户信息意外泄露给其他客户
https://www.bleepingcomputer.com/news/security/chase-bank-accidentally-leaked-customer-info-to-other-customers/ 10、Trickbot 新攻击伪装成 1Password 安装程序以提取数据
https://www.hackread.com/trickbot-installs-fake-1password-manager-extract-data/
网络安全日报 2021年08月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、恶意广告传播Cinobi 银行木马窃取加密货币
https://thehackernews.com/2021/08/malicious-ads-target-cryptocurrency.html 2、Adobe 修复Photoshop 高危漏洞
https://www.securityweek.com/adobe-plugs-critical-photoshop-security-flaws 3、FortiWeb Web 防火墙发现高危命令注入漏洞
https://www.securityweek.com/high-severity-command-injection-vulnerability-found-fortinet-firewall 4、FBI 泄露了190万条其监视的“恐怖分子”相关记录
https://www.securityweek.com/fbi-reportedly-exposed-secret-terrorist-watchlist 5、LockBit 2.0 勒索软件在全球扩散
https://threatpost.com/lockbit-ransomware-proliferates-globally/168746/ 6、SEOPress WordPress 插件XSS漏洞影响数十万网站
https://threatpost.com/xss-bug-seopress-wordpress-plugin/168702/ 7、Valve 修复可以向 Steam 钱包添加无限资金的严重漏洞
https://threatpost.com/valve-bug-unlimited-funds/168710/ 8、 Kalay 云平台严重漏洞影响数百万物联网设备
https://securityaffairs.co/wordpress/121226/hacking/kalay-cloud-platform-critical-flaw.html 9、谷歌为两个严重的 Chrome 漏洞支付 42,000 美元
https://www.securityweek.com/google-awards-42000-two-serious-chrome-vulnerabilities 10、Trickbot恶意软件利用伪造的安装程序收集信息
https://www.hackread.com/trickbot-installs-fake-1password-manager-extract-data/
网络安全日报 2021年08月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、T-Mobile 承认客户数据泄露,已启动调查
https://www.securityweek.com/t-mobile-acknowledges-breach-customer-data-launches-probe 2、Colonial Pipeline 通知受勒索攻击影响的个人信息泄露
https://www.securityweek.com/colonial-pipeline-confirms-personal-information-impacted-ransomware-attack 3、Realtek SDK多个严重漏洞影响数百万设备
https://www.securityweek.com/devices-many-vendors-can-be-hacked-remotely-due-flaws-realtek-sdk 4、攻击者可利用防火墙、入侵防御等系统进行DDoS反射放大攻击
https://thehackernews.com/2021/08/attackers-can-weaponize-firewalls-and.html 5、 STARTTLS 数十个漏洞影响Apple Mail、Gmail等多个邮件客户端
https://thehackernews.com/2021/08/dozens-of-starttls-related-flaws-found.html 6、福特网站漏洞泄露内部系统客户和员工记录
https://www.bleepingcomputer.com/news/security/ford-bug-exposed-customer-and-employee-records-from-internal-systems/ 7、美国金融业监管局警告冒充其官员的网络钓鱼活动
https://www.bleepingcomputer.com/news/security/us-brokers-warned-of-ongoing-phishing-attacks-impersonating-finra/ 8、GitHub 废除基于密码的 Git 身份验证
https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/ 9、AI造出9张“万能人脸”,可冒充超40%的人
https://www.ithome.com/0/569/495.htm 10、勒索软件团伙正积极利用WindowsPrint Spooler漏洞
https://thehackernews.com/2021/08/ransomware-gangs-exploiting-windows.html
网络安全日报 2021年08月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、AMD 芯片的电压故障攻击影响云环境
https://www.securityweek.com/voltage-glitching-attack-amd-chips-poses-risk-cloud-environments 2、英国国防部发布的招聘广告揭露了一个秘密黑客小组
https://securityaffairs.co/wordpress/121172/cyber-warfare-2/uk-ministry-of-defence-secret-hacking-squad.html 3、暗网市场 AlphaBay 在遭执法机构关闭4年后重新活跃
https://securityaffairs.co/wordpress/121143/deep-web/alphabay-marketplace-revamped.html 4、立陶宛外交部机密文件在暗网出售
https://securityaffairs.co/wordpress/121131/data-breach/lithuanian-ministry-of-foreign-affairs-data-leak.html 5、SynAck 勒索软件团伙为老受害者发布主解密密钥
https://securityaffairs.co/wordpress/121116/malware/synack-ransomware-decryption-keys.html 6、谷歌开源 Allstar 工具来保护 GitHub 存储库
https://securityaffairs.co/wordpress/121102/security/allstar-tool-open-source.html 7、研究人员发明了一种新的攻击技术可利用电源指示灯恢复设备声音
https://securityaffairs.co/wordpress/121158/hacking/glowworm-attack-spy-conversations.html 8、新版Mimikatz可从Windows 365 云 PC提取Azure 凭证
https://securityaffairs.co/wordpress/121124/hacking/windows-365-mimikaz-credentials.html 9、Facebook 为 Messenger 中的音视频通话添加端到端加密
https://thehackernews.com/2021/08/facebook-adds-end-to-end-encryption-for.html 10、研究人员发现针对苹果的新AdLoad恶意软件活动
https://www.zdnet.com/article/researchers-discover-new-adload-malware-campaigns-against-macs-and-apple-products/
网络安全日报 2021年08月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、微软确认(又一个)新的Print Spooler 漏洞-CVE-2021-36958
https://www.securityweek.com/microsoft-confirms-yet-another-printnightmare-flaw-ransomware-actors-pounce 2、趋势科技确认针对其 Apex One产品的在野零日攻击
https://www.securityweek.com/trend-micro-confirms-wild-zero-day-attacks 3、Magniber Ransomware利用PrintNightmare漏洞感染服务器
https://securityaffairs.co/wordpress/121076/malware/magniber-ransomware-printnightmare-exploits.html 4、攻击者正逐步归还从Poly Network 盗取的资产
https://securityaffairs.co/wordpress/121057/hacking/poly-network-hackers.html 5、研究人员发布CobaltSpam工具可破坏CobaltStrike 服务器
https://therecord.media/cobaltspam-tool-can-flood-cobalt-strike-malware-servers/ 6、Node.js 修复了可被远程域劫持的高危漏洞
https://portswigger.net/daily-swig/node-js-developers-fix-high-risk-vulnerability-that-could-allow-remote-domain-hijacking 7、假COVID疫苗卡在暗网上的销量激增
https://www.techrepublic.com/article/fake-covid-vaccine-card-sales-ramp-up-on-dark-web/ 8、AT&T实验室的Xmill实用程序被发现存在多个漏洞
https://blog.talosintelligence.com/2021/08/vuln-spotlight-att.html 9、非独立组网的5G 让手机暴露在 Stingray 监视之下
https://www.wired.com/story/5g-network-stingray-surveillance-non-standalone/ 10、西门子和施耐德电气发布补丁修复工控产品中的50多个漏洞
https://www.securityweek.com/august-2021-ics-patch-tuesday-siemens-schneider-address-over-50-flaws
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

