网络安全日报 2021年07月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft Hyper-V 中的严重漏洞可导致 RCE 和 DoS https://securityaffairs.co/wordpress/120654/hacking/critical-microsoft-hyper-v-bug.html 2、黑客利用IE浏览器漏洞在目标 PC 上部署 VBA 恶意软件 https://thehackernews.com/2021/07/hackers-exploit-microsoft-browser-bug.html 3、新的 Android 恶意软件使用 VNC 来监视和窃取密码 https://thehackernews.com/2021/07/new-android-malware-uses-vnc-to-spy-and.html 4、Praying Mantis 现在正在攻击微软的 IIS 服务器 https://cyware.com/news/praying-mantis-is-now-preying-on-microsofts-iis-servers-36788559 5、分析发现XAMPP被用于服务Agent Tesla和Formbook https://www.riskiq.com/blog/external-threat-management/agent-tesla-xampp/ 6、黑客冒充健美操教练用恶意软件攻击国防承包商 https://www.hackread.com/hackers-malware-aerospace-defense-contractor/ 7、研究人员发现多个网络摄像机供应商使用的固件中存在严重漏洞 https://www.securityweek.com/serious-vulnerabilities-found-firmware-used-many-ip-camera-vendors 8、北爱尔兰在数据泄露后暂停疫苗护照系统 https://www.bleepingcomputer.com/news/security/northern-ireland-suspends-vaccine-passport-system-after-data-leak/ 9、安卓证书窃取恶意软件UBEL在野活跃 https://thehackernews.com/2021/07/ubel-is-new-oscorp-android-credential.html 10、最高法:禁止滥用人脸识别,新规定8月1日起施行 http://www.court.gov.cn/fabu-xiangqing-315851.html
网络安全日报 2021年07月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美英澳网络安全机构联合报告发布过去两年最常被利用的漏洞 https://securityaffairs.co/wordpress/120644/hacking/top-routinely-flaws-exploited.html 2、IBM 数据泄露成本研究:数据泄露的平均成本超过 420 万美元 https://securityaffairs.co/wordpress/120627/data-breach/cost-of-data-breach-2021.html 3、BlackMatter 勒索软件组织声称是 Darkside 和 REvil 的继任者 https://securityaffairs.co/wordpress/120611/malware/blackmatter-ransomware.html 4、福昕修复 PDF 阅读器、编辑器中多个安全漏洞 https://www.securityweek.com/foxit-plugs-multiple-security-holes-pdf-reader-editor 5、有争议的PunkSpider工具将在DEFCON上推出新版 https://threatpost.com/punkspider-def-con-debate/168223/ 6、超过 100 名中国台湾政界人士和官员的 LINE 账户遭到黑客攻击 https://therecord.media/line-accounts-for-more-than-100-taiwanese-politicians-were-hacked 7、安天发布“幻鼠”组织针对我国的窃密攻击活动分析 https://mp.weixin.qq.com/s/JoohsUOJXbaEGaYZWv0pnw 8、新的LockBit勒索软件利用组策略加密Windows域 https://www.bleepingcomputer.com/news/security/lockbit-ransomware-now-encrypts-windows-domains-using-group-policies/ 9、Cisco Talos 在CODESYS 开发系统中发现多个漏洞 https://blog.talosintelligence.com/2021/07/vuln-spotlight-codesys-.html 10、 F5 报告称过去五年发生的重大网安事件中有57%利用了Web安全漏洞 https://cyware.com/news/the-state-of-web-application-security-6e551dfc
网络安全日报 2021年07月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CODESYS 修补工业自动化产品中的十几个漏洞 https://www.securityweek.com/codesys-patches-dozen-vulnerabilities-industrial-automation-products 2、Zimbra Webmail 服务器漏洞可导致被入侵 https://www.securityweek.com/vulnerabilities-allow-hacking-zimbra-webmail-servers-single-email 3、Sunhillo 航测产品发现严重漏洞 https://www.securityweek.com/critical-vulnerability-found-sunhillo-aerial-surveillance-product 4、南非物流公司 Transnet SOC 遭受勒索软件攻击 https://securityaffairs.co/wordpress/120596/cyber-crime/transnet-soc-cyber-attack.html 5、研究人员披露Kaseya Unitrends 三个新的0day漏洞 https://securityaffairs.co/wordpress/120591/security/kaseya-unitrends-zero-days.html 6、IDEMIA的生物识别设备中存在多个漏洞 https://portswigger.net/daily-swig/security-vulnerabilities-in-idemia-access-control-devices-could-allow-attackers-to-remotely-open-doors 7、印尼人民银行 (BRI) 保险部门 BRI Life 报告200W用户数据泄露 https://www.reuters.com/business/finance/indonesias-bri-life-probes-reported-data-leak-2-million-users-2021-07-27 8、谷歌推出新的 Bug Hunters 漏洞奖励平台 https://www.bleepingcomputer.com/news/google/google-launches-new-bug-hunters-vulnerability-rewards-platform/ 9、网络犯罪分子使用虚假的 Win 11 安装程序来传播恶意软件 https://www.cyberscoop.com/microsoft-11-fake-installer-kaspersky-malware/ 10、 物联网恶意软件增长700%,Gafgyt 和 Mirai为主要威胁 https://www.freebuf.com/articles/paper/281177.html
网络安全日报 2021年07月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple 修复了今年第 13 个零日漏洞 CVE-2021-30807 https://securityaffairs.co/wordpress/120576/security/apple-cve-2021-30807-zero-day.html 2、微软发布了针对 PetitPotam 攻击的缓解措施 https://securityaffairs.co/wordpress/120550/security/petitpotam-attack-mitigations.html 3、研究人员演示了将恶意软件隐藏在神经网络模型中的技术 https://securityaffairs.co/wordpress/120558/malware/hiding-malware-model-neural-network.html 4、No More Ransom成立 5 周年已为数百万勒索软件受害者恢复了数据 https://securityaffairs.co/wordpress/120567/cyber-crime/no-more-ransom-5th-anniversary.html 5、Firefox 90 不再支持 FTP 协议 https://www.securityweek.com/firefox-90-drops-support-ftp-protocol 6、GitLab 发布开源工具,用于发现程序依赖项中的恶意代码 https://www.securityweek.com/gitlab-releases-open-source-tool-hunting-malicious-code-dependencies 7、Babuk Ransomware 团伙被勒索 https://threatpost.com/babuk-ransomware-gang-ransomed-forum-stuffed-porn/168169/ 8、微软警告垃圾邮件活动利用HTML 走私绕过邮件安全系统 https://therecord.media/microsoft-warns-of-weeks-long-malspam-campaign-abusing-html-smuggling 9、大华和海康威视被退出美国安防行业协会(SIA) https://therecord.media/dahua-hikvision-out-of-security-camera-industry-group 10、Mitre发布了25个最危险的软件漏洞列表 https://www.zdnet.com/article/the-25-most-dangerous-software-vulnerabilities-to-watch-out-for/
网络安全日报 2021年07月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、包含38 亿个电话号码的Clubhouse数据库在暗网出售 https://securityaffairs.co/wordpress/120553/hacking/threat-actor-offers-clubhouse-secret-database-containing-3-8b-phone-numbers.html2、 攻击者通过Argo Workflows在K8s上部署挖矿程序 https://securityaffairs.co/wordpress/120544/malware/kubernetes-attacks-argo-workflows.html3、XCSSET macOS 恶意软件窃取Telegram、Chrome数据 https://securityaffairs.co/wordpress/120532/cyber-crime/xcsset-macos-malware-telegram.html4、2021 年东京奥运会开幕式前遭到恶意软件攻击 https://securityaffairs.co/wordpress/120513/malware/2021-tokyo-olympics-wiper.html5、研究人员发现Windows漏洞 PetitPotam 可获取密码哈希 https://securityaffairs.co/wordpress/120489/hacking/windows-petitpotam-attack.html6、包含居民个人数据在内的 80 多个美国市政敏感信息泄露 https://securityaffairs.co/wordpress/120477/data-breach/us-municipalities-data-breach.html7、Kaseya 获得了 REvil 勒索软件通用解密器 https://securityaffairs.co/wordpress/120467/cyber-crime/kaseya-obtained-revil-universal-decryptor.html8、苹果修复了 iPhone WiFi SSID格式化溢出漏洞 https://www.bleepingcomputer.com/news/security/apple-fixes-bug-that-breaks-iphone-wifi-when-joining-rogue-hotspots/9、Taurus恶意软件利用破解软件站点诱导用户安装 https://blog.minerva-labs.com/taurus-user-guided-infection10、研究显示大量家用路由器仍然使用默认管理员密码 https://www.welivesecurity.com/2021/07/22/popular-wi-fi-router-vulnerable-default-password-attack/
网络安全日报 2021年07月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、荷兰警方逮捕网络钓鱼 Fraud Family 开发团伙成员 https://securityaffairs.co/wordpress/120428/cyber-crime/fraud-family-members-identified.html 2、美国保险巨头 Humana 客户的敏感数据在线泄露 https://securityaffairs.co/wordpress/120402/data-breach/humana-data-leak.html 3、意大利票务平台TicketClub数据在暗网出售 https://securityaffairs.co/wordpress/120406/data-breach/ticketclub-italy-data-leak.html 4、CISA警告在被黑的Pulse Secure设备上发现隐蔽的恶意软件 https://securityaffairs.co/wordpress/120412/hacking/pulse-secure-cisa-malware.html 5、Atlassian 修补了 Jira 产品中的关键漏洞 https://www.securityweek.com/atlassian-patches-critical-vulnerability-jira-data-center-products 6、Google Cloud 推出新的 SOC、IDS 解决方案 https://www.securityweek.com/google-cloud-unveils-new-soc-ids-solutions 7、微软发布 Windows 10 修复"SeriousSAM"漏洞的解决方法 https://threatpost.com/win-10-serioussam/168034/ 8、2020年推特黑客事件的第四名嫌疑人被捕 https://thehackernews.com/2021/07/another-hacker-arrested-for-2020.html 9、新的 XCSSET 恶意软件变体针对 Telegram、Evernote、Skype 等 https://www.trendmicro.com/en_us/research/21/g/updated-xcsset-malware-targets-telegram--other-apps.html 10、英格兰北方铁路售票机遭受勒索软件攻击 https://www.reuters.com/world/uk/uks-northern-rails-self-service-ticket-machines-hit-by-ransomware-cyber-attack-2021-07-19/
网络安全日报 2021年07月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CNCERT发布2020年中国互联网网络安全报告 https://mp.weixin.qq.com/s/jAhWZzaq6mpyYt50L78Bhg 2、Kelihos僵尸网络作者被判入狱 https://securityaffairs.co/wordpress/120374/cyber-crime/kelihos-botnetmaster-peter-levashov-sentence.html 3、Linux 内核中的 LPE 漏洞影响大多数Linux发行版 https://securityaffairs.co/wordpress/120365/security/lpe-flaw-linux-kernel.html 4、Google Cloud 推出新的政务零信任产品 https://www.securityweek.com/google-cloud-introduces-new-zero-trust-offerings-government 5、Oracle 发布 2021 年 7 月更新含 342 个安全补丁 https://www.securityweek.com/oracle-releases-july-2021-cpu-342-security-patches 6、Chrome 92 带来多项隐私、安全改进 https://www.securityweek.com/chrome-92-brings-several-privacy-security-improvements 7、沙特阿美因数据泄露面临5000W美元勒索赎金 https://www.securityweek.com/saudi-aramco-facing-50m-cyber-extortion-over-leaked-data 8、XLoader 恶意软件现已升级可攻击 macOS 系统 https://thehackernews.com/2021/07/xloader-windows-infostealer-malware-now.html 9、恶意 NPM 包从Chrome浏览器中窃取用户保存的密码 https://thehackernews.com/2021/07/malicious-npm-package-caught-stealing.html 10、Aruba Networks路由器被发现存在多个漏洞
网络安全日报 2021年07月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、存在16年的漏洞影响数百万台HP、施乐和三星打印机 https://securityaffairs.co/wordpress/120358/security/cve-2021-3438-printer-driver-flaw.html 2、Fortinet 修复了 FortiManager 和 FortiAnalyzer 中的高危漏洞 https://securityaffairs.co/wordpress/120350/security/fortinet-fortimanager-fortianalyzer-bug.html 3、微软获得法院授权,删除 BEC 活动中使用的相似文字域名 https://securityaffairs.co/wordpress/120334/cyber-crime/microsoft-bec-campaign.html 4、罗克韦尔自动化 MicroLogix PLC 存在漏洞可导致远程DoS攻击 https://www.securityweek.com/vulnerability-exposes-micrologix-plcs-remote-dos-attacks 5、网络安全研究人员披露一个名为“ MosaicLoader ”的新的恶意软件 https://thehackernews.com/2021/07/this-new-malware-hides-itself-among.html 6、马克龙等13位国家元首和政府首脑都是Pegasus 项目监控对象 https://www.theguardian.com/world/2021/jul/20/emmanuel-macron-identified-in-leaked-pegasus-project-data 7、网络钓鱼活动利用Word文档分发恶意软件 https://www.fortinet.com/blog/threat-research/fresh-malware-hunts-for-crypto-wallet-and-credentials 8、Umbraco即将修复其表单包中的RCE漏洞 https://portswigger.net/daily-swig/umbraco-flags-pending-security-patch-for-rce-vulnerability-in-forms-package 9、美国一著名律师事务所披露勒索软件攻击 https://www.securityweek.com/law-firm-campbell-conroy-oneil-discloses-ransomware-attack 10、微软将 Teams 移动应用程序添加到漏洞赏金计划 https://www.securityweek.com/microsoft-adds-teams-mobile-applications-bug-bounty-program
网络安全日报 2021年07月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Cisco Talos 披露研华路由器监控工具存在严重漏洞 https://securityaffairs.co/wordpress/120307/iot/advantech-router-monitoring-tool-flaws.html 2、攻击者称从沙特阿美公司窃取了 1 TB 的敏感数据 https://securityaffairs.co/wordpress/120301/data-breach/saudi-aramco-data-breach.html 3、Pegasus项目-针对记者的大规模监控活动 https://securityaffairs.co/wordpress/120291/malware/pegasus-project-nso-pegasus-spywar.html 4、iOS WiFi SSID 格式化字符串拒绝服务漏洞可实现RCE攻击 https://thehackernews.com/2021/07/turns-out-that-low-risk-ios-wi-fi.html 5、TeaBot 木马瞄准更多欧洲银行 https://cyware.com/news/teabot-trojan-striking-harder-targeting-more-european-banks-5704aa3c 6、WooCommerce修复了使500万个网站数据被盗的漏洞 https://www.bleepingcomputer.com/news/security/woocommerce-fixes-vulnerability-exposing-5-million-sites-to-data-theft/ 7、施耐德修复了EVlink电动汽车充电站的漏洞 https://portswigger.net/daily-swig/schneider-electric-fixes-critical-vulnerabilities-in-evlink-electric-vehicle-charging-stations 8、Artwork Archive云存储桶配置错误泄露用户信息 https://www.zdnet.com/article/artwork-archive-cloud-storage-misconfiguration-exposed-user-data-revenue-records/ 9、SolarWinds黑客利用iOS 0day漏洞入侵iPhone https://www.hackread.com/solarwinds-hackers-ios-zero-day-hack-iphones/ 10、RansomEXX勒索软件攻击了厄瓜多尔CNT国营电信公司 https://www.bleepingcomputer.com/news/security/ecuadors-state-run-cnt-telco-hit-by-ransomexx-ransomware/
网络安全日报 2021年07月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Instagram实施“安全检查”帮助用户恢复受损账户 https://securityaffairs.co/wordpress/120260/security/instagram-security-checkup.html 2、思科修复ASA、FTD软件中的高危DoS漏洞 https://securityaffairs.co/wordpress/120231/security/cisco-dos-flaw-asa-ftd.html 3、D-Link针对DIR-3040路由器中的多个漏洞发布测试版修补程序 https://securityaffairs.co/wordpress/120224/hacking/d-link-dir-3040-flaws.html 4、Microsoft发布新的 Windows Print Spooler 漏洞警报 https://securityaffairs.co/wordpress/120212/security/new-windows-print-spooler-vulnerability.html 5、Chrome更新修复了一个在野利用的0day漏洞 https://securityaffairs.co/wordpress/120205/security/google-chrome-zero-day-2.html 6、CloudFlare CDNJS 漏洞可能导致广泛的供应链攻击 https://thehackernews.com/2021/07/cloudflare-cdnjs-bug-could-have-led-to.html 7、HelloKitty 勒索软件针对易受攻击的 SonicWall 设备 https://securityaffairs.co/wordpress/120249/malware/hellokitty-ransomware-sonicwall-devices.html 8、密码学家发现 Telegram 加密协议中的漏洞 https://www.cyberscoop.com/telegram-app-security-encryption/ 9、美国政府计划从加密货币着手打击网络犯罪 https://www.cyberscoop.com/us-government-crypocurrency-ransomware-criminals-treasury-state-reward/ 10、工业自动化系统MDT AutoSave 修复了多个高危漏洞 https://www.securityweek.com/several-vulnerabilities-patched-mdt-autosave-industrial-automation-product