网络安全日报 2021年07月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、以色列公司 Candiru 使用 Windows 零日漏洞部署间谍软件
https://securityaffairs.co/wordpress/120175/malware/candiru-windows-zero-days-spyware.html 2、漏洞交易平台Zerodium正在寻找VMware vCenter 漏洞利用
https://securityaffairs.co/wordpress/120170/security/zerodium-vmware-vcenter-server-exploits.html 3、研究人员发现新的Diavol勒索软件会窃取数据
https://securityaffairs.co/wordpress/120165/malware/diavol-ransomware-analysis.html 4、Hellokitty勒索软件现针对VMware ESXi服务器
https://securityaffairs.co/wordpress/120158/cyber-crime/hellokitty-ransomware-linux-variant.html 5、Coinbase 用户面临持续的网络钓鱼攻击
https://www.securityweek.com/coinbase-users-face-ongoing-phishing-attacks 6、开源WooCommerce 电商平台和相关插件存在零日漏洞
https://threatpost.com/zero-day-attacks-woocommerce-databases/167846/ 7、美国悬赏1000万美元获取攻击者信息
https://www.securityweek.com/us-offers-10-million-rewards-information-foreign-hackers 8、Cisco Talos 团队在研华 R-SeeNet 监控软件种发现多个漏洞
https://blog.talosintelligence.com/2021/07/vuln-spotlight-r-see-net.html 9、Google Chrome 将添加 HTTPS 优先模式
https://www.bleepingcomputer.com/news/security/google-chrome-will-add-https-first-mode-to-keep-your-data-safe/ 10、医疗服务提供商Practicefirst披露数据泄露
https://www.govinfosecurity.com/supply-chain-ransomware-breach-affects-12-million-a-17062
网络安全日报 2021年07月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Google Project Zero 研究人员透露4个零日漏洞已被广泛利用
https://securityaffairs.co/wordpress/120116/apt/zero-day-russia-apt.html 2、REvil 勒索软件团伙用于其运营的基础设施和泄漏站点神秘离线
https://securityaffairs.co/wordpress/120080/cyber-crime/revil-ransomware-gang-sites-down.html 3、Trickbot 在最近的攻击中改进了其 VNC 模块
https://securityaffairs.co/wordpress/120090/malware/trickbot-botnet-vnc-module.html 4、SonicWall 警告针对固件漏洞的勒索软件攻击
https://www.securityweek.com/sonicwall-warns-imminent-ransomware-attacks-targeting-firmware-flaw 5、西门子和施耐德电气周二发布补丁修复其产品的大约100个漏洞
https://www.securityweek.com/ics-patch-tuesday-siemens-and-schneider-electric-address-100-vulnerabilities 6、Mekotio和Grandoreiro银行木马背后的16名网络罪犯在西班牙被捕
https://thehackernews.com/2021/07/16-cybercriminals-behind-mekotio-and.html 7、VMware 修补 ESXi、ThinApp 中的漏洞
https://www.securityweek.com/vmware-patches-vulnerabilities-esxi-thinapp 8、微软修复了 Windows Hello 身份验证绕过漏洞
https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-hello-authentication-bypass-vulnerability/ 9、2021 年网络攻击导致医疗保健数据泄露激增 185%
https://www.scmagazine.com/home/health-care/report-cyberattacks-drive-185-spike-in-health-care-data-breaches-in-2021/ 10、CISA发布常见攻击策略的应对技巧
https://www.nextgov.com/cybersecurity/2021/07/cisa-issues-mitigation-tips-common-attack-tactics/183676/
网络安全日报 2021年07月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Adobe 修补了 Reader、Acrobat 和 Illustrator 中的关键漏洞
https://securityaffairs.co/wordpress/120062/security/adobe-reader-acrobat-illustrator-flaws.html 2、Modicon PLC 中的 ModiPwn 漏洞可绕过安全机制
https://securityaffairs.co/wordpress/120045/security/modipwn-modipwn-plcs.html 3、美国零售商 Guess 披露遭勒索软件攻击后数据泄露
https://securityaffairs.co/wordpress/120029/cyber-crime/guess-discloses-data-breach.html 4、谷歌被法国监管机构罚款 5.93 亿美元
https://cybernews.com/news/google-fined-593-million-by-french-regulator/ 5、微软周二补丁修复了 3 个受到攻击的Windows 零日漏洞
https://www.securityweek.com/microsoft-patches-3-under-attack-windows-zero-days 6、Firefox 90 添加跨域保护和高级跟踪器拦截器
https://www.securityweek.com/firefox-90-adds-cross-origin-protections-advanced-tracker-blocker 7、网络安全研究人员披露了 Etherpad 文本编辑器高危漏洞
https://thehackernews.com/2021/07/critical-flaws-reported-in-etherpad.html 8、ForgeRock OpenAM存在远程代码执行漏洞
https://thehackernews.com/2021/07/critical-rce-flaw-in-forgerock-access.html 9、研究表明多个供应商使用的IP摄像机固件存在漏洞
https://portswigger.net/daily-swig/research-exposes-vulnerabilities-in-ip-camera-firmware-used-by-multiple-vendors 10、电商平台Spreadshop遭到恶意网络攻击导致数据泄露
https://www.privacysharks.com/spreadshop-hit-by-cyber-attack-payment-details-emails-and-passwords-breached/
网络安全日报 2021年07月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、工信部发布发展网络安全行业的三年行动计划草案
http://wap.miit.gov.cn/gzcy/yjzj/art/2021/art_34f89fff961b4862bf0c393532e2bf63.html 2、SolarWinds 修复了在野外被利用的关键 Serv-U 零日漏洞
https://securityaffairs.co/wordpress/120020/security/solarwinds-serv-u-zero-day.html 3、 6 亿份 LinkedIn 个人资料被抓取和在线出售
https://securityaffairs.co/wordpress/120009/cyber-crime/600m-linkedin-profiles-scraped.html 4、Kaseya 发布安全更新修复被利用的VSA零日漏洞
https://securityaffairs.co/wordpress/119980/security/kaseya-fix-flaws-ransomware-attack.html 5、三菱电机修复了多个空调产品(控制器)高危漏洞
https://www.securityweek.com/mitsubishi-electric-patches-vulnerabilities-air-conditioning-systems 6、BIOPASS RAT通过博彩网站传播并滥用OBS实时录制传输屏幕
https://threatpost.com/biopass-rat-live-streaming/167695/ 7、Bandidos恶意软件活动针对拉丁美洲国家企业网络
https://cyware.com/news/bandidos-targeting-latin-america-spying-on-victims-b275c80e 8、研究人员发现新的Joker木马变种
https://cybleinc.com/2021/07/09/android-app-disguised-as-a-qr-scanner-spreads-joker-variant-trojan/ 9、挖矿管理平台Hive OS遭恶意软件攻击
https://www.hackread.com/hive-os-cryptomining-malware-steal-wallet-funds/ 10、Less语言中的漏洞导致网站泄露AWS密钥
https://portswigger.net/daily-swig/flaw-in-preprocessor-language-less-js-causes-website-to-leak-aws-secret-keys
网络安全日报 2021年07月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Mint Mobile 披露了一起数据泄露事件
https://securityaffairs.co/wordpress/119954/data-breach/mint-mobile-data-breach.html 2、伊朗铁路系统遭网络攻击,黑客发布虚假延误信息
https://securityaffairs.co/wordpress/119942/hacking/irans-railroad-system-cyberattack.html 3、Zloader恶意软件使用新技术来禁用宏安全警告
https://securityaffairs.co/wordpress/119902/hacking/malspam-new-evasion-technique-macro.html 4、Magecart 黑客将窃取的信用卡数据隐藏到图像中以规避审查
https://thehackernews.com/2021/07/magecart-hackers-hide-stolen-credit.html 5、微软称紧急补丁正确修复了PrintNightmare漏洞
https://www.bleepingcomputer.com/news/security/microsoft-printnightmare-security-updates-work-start-patching/ 6、Kaseya警告网络钓鱼活动推送虚假安全更新
https://www.bleepingcomputer.com/news/security/kaseya-warns-of-phishing-campaign-pushing-fake-security-updates/ 7、保险公司CNA在勒索软件攻击后披露数据泄露
https://securityaffairs.co/wordpress/119913/data-breach/cna-data-breach.html 8、Coursera在线学习平台存在多个安全漏洞
https://www.zdnet.com/article/coursera-api-vulnerabilities-disclosed-by-researchers/ 9、黑客使用假冒俄罗斯政府域发送钓鱼邮件
https://www.itsecuritynews.info/cyber-criminals-sending-phishing-mails-pretending-to-be-from-russian-government-domain/ 10、联邦调查局警告针对虚拟资产的攻击活动
https://www.bleepingcomputer.com/news/security/mint-mobile-hit-by-a-data-breach-after-numbers-ported-data-accessed/
网络安全日报 2021年07月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、西部数据 MyCloud 网络存储存在 RCE 漏洞
https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/ 2、Cisco Talos 发布对 InSideCopy APT 组织的分析报告
https://blog.talosintelligence.com/2021/07/sidecopy.html 3、摩根士丹利披露因第三方供应商遭黑客入侵导致数据泄露
https://securityaffairs.co/wordpress/119865/data-breach/morgan-stanley-data-breach.html 4、研究人员绕过了微软的 PrintNightmare 紧急补丁
https://securityaffairs.co/wordpress/119839/hacking/printnightmare-patch-bypass.html 5、思科修补了 BPA、WSA 产品中的高危漏洞
https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-bpa-wsa 6、2021 年 7 月 Android 更新补丁修复了数十个高危漏洞
https://www.securityweek.com/android-updates-july-2021-patch-tens-high-severity-vulnerabilities 7、专家发现新的针对拉丁美洲企业网络的恶意软件攻击
https://thehackernews.com/2021/07/experts-uncover-malware-attacks.html 8、IOBit Advanced SystemCare Ultimate 中发现了提权等多个漏洞
https://blog.talosintelligence.com/2021/07/vuln-spotlight-iobit0-.html 9、澳大利亚新南威尔士州教育部遭网络攻击导致系统停用
https://www.zdnet.com/article/nsw-department-of-education-struck-by-cyber-attack/ 10、荷兰漏洞披露研究所称4月就发现了Kaseya中的漏洞并通知了该公司
https://thehill.com/policy/cybersecurity/561927-cybersecurity-researchers-warned-kaseya-of-flaw-in-april-report?rl=1
网络安全日报 2021年07月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、黑客在线泄露特朗普粉丝新社交平台GETTR的成员信息
https://securityaffairs.co/wordpress/119775/data-breach/gettr-data-breach.html 2、WildPressure APT 使用新的恶意软件针对Windows和macOS
https://securityaffairs.co/wordpress/119812/apt/wildpressure-apt-macos-malware.html 3、研究人员发布了对REVil 勒索软件的调查报告
https://securityaffairs.co/wordpress/119799/cyber-crime/researchers-infrastructure-revil-ransomware-gang.html 4、卡巴斯基密码管理器默认生成的密码可在几秒内被暴力破解
https://www.securityweek.com/kaspersky-password-manager-generated-passwords-could-quickly-be-brute-forced 5、CISA披露飞利浦Vue医疗产品15个漏洞
https://www.securityweek.com/cisa-says-philips-vue-healthcare-products-affected-15-vulnerabilities 6、ERP系统Sage X3 高危RCE漏洞可导致系统被完全接管
https://threatpost.com/critical-sage-x3-rce-bug-allows-full-system-takeovers/167612/ 7、Mirai_ptea: Mirai 变种的最新僵尸网络
https://cyware.com/news/mirai_ptea-the-latest-mirai-inspired-botnet-a958db6d 8、SideCopy APT使用新的木马攻击印度军方
https://www.zdnet.com/article/sidecopy-cybercriminals-use-custom-trojans-in-india-attacks/ 9、Lazarus组织新活动针对工程求职者和员工
https://cybersecurity.att.com/blogs/labs-research/lazarus-campaign-ttps-and-evolution 10、国际刑警组织在摩洛哥逮捕网络罪犯分子
https://www.interpol.int/News-and-Events/News/2021/Moroccan-police-arrest-suspected-cybercriminal-after-INTERPOL-probe
网络安全日报 2021年07月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、SonicWall 修复NSM 设备中的高危漏洞 CVE-2021-20026
https://securityaffairs.co/wordpress/119767/security/sonicwall-fixes-cve-2021-20026-flaw.html 2、Kaseya 证实大约1500家企业受Kaseya供应链勒索攻击影响
https://securityaffairs.co/wordpress/119759/cyber-crime/kaseya-attack-impacted-1500-businesses.html 3、QNAP 解决了一个可导致 NAS 设备受攻击的严重漏洞
https://securityaffairs.co/wordpress/119750/hacking/qnap-nas-critical-flaw.html 4、ENISA 发布中小企业网络安全指南
https://www.enisa.europa.eu/publications/cybersecurity-guide-for-smes 5、微软发布针对高危 漏洞'PrintNightmare' 的紧急补丁
https://msrc-blog.microsoft.com/2021/07/06/out-of-band-oob-security-update-available-for-cve-2021-34527/ 6、OWASP ModSecurity 核心规则集 (CRS) 存在漏洞可导致WAF绕过
https://portswigger.net/daily-swig/waf-bypass-severe-owasp-modsecurity-core-rule-set-bug-was-present-for-several-years 7、五角大楼取消与微软有争议的 JEDI 云合同
https://www.securityweek.com/pentagon-cancels-disputed-jedi-cloud-contract-microsoft 8、针对 ICS 网络的勒索软件攻击活动迅速增长
https://cyware.com/news/attackers-accelerating-ransomware-attacks-on-ics-networks-57bd4aff 9、梭子鱼收购 Skout Cybersecurity 进军 XDR 市场
https://techcrunch.com/2021/07/01/barracuda-enters-xdr-market-with-skout-cybersecurity-acquisition/ 10、调查发现针对菲律宾媒体的 DDoS 攻击与其政府机构有关
https://therecord.media/investigation-links-ddos-attack-on-filipino-media-outlets-to-government-agencies
网络安全日报 2021年07月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、CISA 和 FBI 发布了针对 Kaseya供应链攻击的受害者缓解指南
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html 2、Revil 勒索软件团伙攻击了西班牙电信巨头 MasMovil
https://securityaffairs.co/wordpress/119719/cyber-crime/masmovil-ransomware-attack.html 3、Revil勒索软件要求支付7000W美金才肯解锁被感染的Kaseya系统
https://securityaffairs.co/wordpress/119709/cyber-crime/revil-ransomware-kaseya-decryptor.html 4、360 Vulcan Team 发现Windows 11 高危本地提权漏洞
https://mp.weixin.qq.com/s/_PjO4_wpe2LQc4BMfg-FGg 5、新Covid-19主题网络钓鱼活动可绕过SEG检测
https://cofense.com/blog/covid-19-variant-malware/ 6、美国水务公司WSSC Water遭到勒索软件攻击
https://securityaffairs.co/wordpress/119700/cyber-crime/wssc-water-ransomware-attack.html 7、WAGO设备漏洞可导致工业企业受到远程攻击
https://www.securityweek.com/vulnerabilities-wago-devices-expose-industrial-firms-remote-attacks 8、Diavol Ransomware 与 Wizard Spider 的关联被揭露
https://cyware.com/news/diavol-ransomwares-connection-with-wizard-spider-revealed-b718ce77 9、安装总量达500W的多个安卓应用窃取Facebook凭证
https://thehackernews.com/2021/07/android-apps-with-58-million-installs.html 10、TrickBot 僵尸网络部署了一种名为 Diavol 的新型勒索软件
https://thehackernews.com/2021/07/trickbot-botnet-found-deploying-new.html
网络安全日报 2021年07月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、CISA 和 FBI 发布了针对 Kaseya供应链攻击的受害者缓解指南
https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html 2、Revil 勒索软件团伙攻击了西班牙电信巨头 MasMovil
https://securityaffairs.co/wordpress/119719/cyber-crime/masmovil-ransomware-attack.html 3、Revil勒索软件要求支付7000W美金才肯解锁被感染的Kaseya系统
https://securityaffairs.co/wordpress/119709/cyber-crime/revil-ransomware-kaseya-decryptor.html 4、360 Vulcan Team 发现Windows 11 高危本地提权漏洞
https://mp.weixin.qq.com/s/_PjO4_wpe2LQc4BMfg-FGg 5、新Covid-19主题网络钓鱼活动可绕过SEG检测
https://cofense.com/blog/covid-19-variant-malware/ 6、美国水务公司WSSC Water遭到勒索软件攻击
https://securityaffairs.co/wordpress/119700/cyber-crime/wssc-water-ransomware-attack.html 7、WAGO设备漏洞可导致工业企业受到远程攻击
https://www.securityweek.com/vulnerabilities-wago-devices-expose-industrial-firms-remote-attacks 8、Diavol Ransomware 与 Wizard Spider 的关联被揭露
https://cyware.com/news/diavol-ransomwares-connection-with-wizard-spider-revealed-b718ce77 9、安装总量达500W的多个安卓应用窃取Facebook凭证
https://thehackernews.com/2021/07/android-apps-with-58-million-installs.html 10、TrickBot 僵尸网络部署了一种名为 Diavol 的新型勒索软件
https://thehackernews.com/2021/07/trickbot-botnet-found-deploying-new.html
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

