网络安全日报 2021年07月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、REvil勒索软件在Kaseya 供应链攻击中利用了零日漏洞 https://securityaffairs.co/wordpress/119688/cyber-crime/kaseya-zero-day-revil.html 2、攻击者入侵了蒙古 CA MonPass 服务器并利用其传播恶意软件 https://securityaffairs.co/wordpress/119677/malware/mongolian-ca-monpass-hack.html 3、 Kaseya VSA 供应链勒索攻击影响了数百家公司 https://securityaffairs.co/wordpress/119650/cyber-crime/kaseya-vsa-supply-chain-ransomware-attack.html 4、微软敦促Azure用户更新PowerShell以修复RCE漏洞 https://securityaffairs.co/wordpress/119629/security/microsoft-azure-powershell-rce-flaw.html 5、微软警告PrintNightmare漏洞已被利用 https://thehackernews.com/2021/07/microsoft-warns-of-critical.html 6、TrickBot 升级改进其银行木马模块 https://threatpost.com/trickbot-banking-trojan-module/167521/ 7、美国保险巨头 AJG 报告勒索软件攻击后数据泄露 https://www.bleepingcomputer.com/news/security/us-insurance-giant-ajg-reports-data-breach-after-ransomware-attack/ 8、滴滴出行APP存在严重违法违规收集个人信息问题被下架 https://finance.sina.com.cn/stock/relnews/us/2021-07-05/doc-ikqcfnca4936032.shtml 9、PurpleFox漏洞利用包利用WPAD感染用户 https://www.trendmicro.com/en_us/research/21/g/purplefox-using-wpad-to-targent-indonesian-users.html 10、研究人员发现投送Warzone RAT的攻击活动 https://blogs.quickheal.com/warzone-rat-beware-of-the-trojan-malware-stealing-data-triggering-from-various-office-documents/
网络安全日报 2021年07月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、英美机构警告俄罗斯 APT 进行大规模暴力攻击 https://securityaffairs.co/wordpress/119595/apt/russia-apt-brute-force-attacks.html 2、内华达州大学医学中心医院遭入侵导致数据泄露 https://securityaffairs.co/wordpress/119591/data-breach/university-medical-center-data-breach.html 3、微软专家披露Netgear 路由器中身份验证绕过等多个高危漏洞 https://securityaffairs.co/wordpress/119574/hacking/netgear-flaws-router-takeover.html 4、CISA发布新的勒索软件自我评估安全审计工具 https://securityaffairs.co/wordpress/119568/security/cisa-ransomware-readiness-assessment.html 5、受勒索软件团伙青睐的 DoubleVPN 的服务器被查封 https://thehackernews.com/2021/06/authorities-seize-doublevpn-service.html 6、安全厂商披露Indexsinas攻击活动新细节 https://www.guardicore.com/labs/smb-worm-indexsinas/ 7、超过120万俄罗斯人登录凭据在网上泄露 https://www.ehackingnews.com/2021/06/logins-and-passwords-of-at-least-12.html 8、Android木马窃取Facebook用户登录凭据 https://news.drweb.com/show/?i=14244&lng=en&c=5&& 9、Windows 11 新增 DNS-over-HTTPS 功能 https://www.bleepingcomputer.com/news/microsoft/windows-11-includes-the-dns-over-https-privacy-feature-how-to-use/ 10、恶意软件攻击者利用 AutoHotkey 脚本进行攻击 https://securityintelligence.com/news/malware-using-autohotkey-scripts/
网络安全日报 2021年07月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、普京与Rossiya-24电视台的电话直播遭大规模网络攻击 https://securityaffairs.co/wordpress/119559/hacking/putin-call-massive-attack.html 2、SolarWinds 黑客攻击了丹麦中央银行并已隐匿数月之久 https://securityaffairs.co/wordpress/119527/cyber-warfare-2/denmarks-central-bank-solarwinds-hackers.html 3、WD确认最近针对其存储设备的攻击中利用了零日漏洞 https://www.securityweek.com/zero-day-vulnerability-exploited-recent-attacks-wd-storage-devices 4、GitHub 推出“Copilot”——人工智能驱动的代码完成工具 https://thehackernews.com/2021/06/github-launches-copilot-ai-powered-code.html 5、Adobe Experience Manager 修复高危零日漏洞 https://www.infosecurity-magazine.com/news/zero-day-exploit-found-in-adobe/ 6、 PJobRAT 间谍软件伪装成Android约会应用窃取用户数据 https://gbhackers.com/pjobrat/ 7、鱼叉式网络钓鱼活动针对航空公司分发AsyncRAT https://www.fortinet.com/blog/threat-research/spear-phishing-campaign-with-new-techniques-aimed-at-aviation-companies 8、WordPress插件多个漏洞可导致远程代码执行 https://portswigger.net/daily-swig/multiple-vulnerabilities-in-wordpress-plugin-pose-website-remote-code-execution-risk 9、钓鱼邮件冒充Indeed就业网站以窃取用户凭据 https://hotforsecurity.bitdefender.com/blog/cyber-crooks-hunt-for-indeed-job-seekers-account-credentials-in-latest-phishing-campaign-26054.html 10、趋势科技报告称越来越多地工业系统遭勒索软件攻击 https://www.securityweek.com/ransomware-increasingly-detected-industrial-systems-report
网络安全日报 2021年06月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、影响所有 Windows 的 CVE-2021-1675 RCE PoC 在线发布 https://securityaffairs.co/wordpress/119502/hacking/2021-1675-rce-poc.html 2、Linux 版本的 REvil 勒索软件以 ESXi 虚拟机为目标 https://securityaffairs.co/wordpress/119497/cyber-crime/revil-ransomware-linux.html 3、研究人员为 Lorenz 勒索软件开发了免费解密器 https://securityaffairs.co/wordpress/119492/cyber-crime/lorenz-ransomware-free-decryptor.html 4、Malvuln 项目在恶意软件中发现 260 个漏洞 https://www.securityweek.com/malvuln-project-catalogues-260-vulnerabilities-found-malware5、谷歌宣布针对 Google Play 开发者帐户新的安全措施 https://www.securityweek.com/new-security-measures-announced-google-play-developer-accounts 6、Phoenix Contact多款工业产品存在高危漏洞 https://www.securityweek.com/high-severity-vulnerabilities-found-several-phoenix-contact-industrial-products 7、联合国安理会首次举行关于网络安全的公开会 https://www.securityweek.com/un-security-council-confronts-growing-threat-cyber-attacks 8、未修补的虚拟机接管漏洞影响 Google Compute Engine https://thehackernews.com/2021/06/unpatched-virtual-machine-takeover-bug.html 9、Zzoomm互联网服务提供商遭遇DDoS攻击 https://www.technadu.com/uk-isp-zzoomm-hiy-ddos-actors-suffered-service-disruption/286118/ 10、以色列AcadeME网站泄露约28万学生的信息 https://www.jpost.com/israel-news/details-of-over-200000-students-leaked-in-cyberattack-672179
网络安全日报 2021年06月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软调查分发恶意 Netfilter 驱动程序的攻击者 https://securityaffairs.co/wordpress/119476/malware/netfilter-driver-microsoft-attack.html 2、Babuk Locker 勒索软件构建器在线泄露 https://securityaffairs.co/wordpress/119467/cyber-crime/babuk-locker-ransomware-builder.html 3、ATM的NFC系统和POS中存在一个严重漏洞 https://gbhackers.com/researcher-managed-to-hack-atms/ 4、新闻阅读器NewsBlur遭黑客入侵数据被清除 https://www.securityweek.com/newsblur-restores-service-after-hacker-wipes-database 5、Edge修复了UXSS高危漏洞 https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html 6、Mozilla 推出注重隐私的数据共享研究平台-Rally https://www.securityweek.com/mozilla-launches-privacy-focused-browsing-data-sharing-platform 7、Google 计划推动 OSV采用统一规范的数据格式 https://security.googleblog.com/2021/06/announcing-unified-vulnerability-schema.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+GoogleOnlineSecurityBlog+%28Google+Online+Security+Blog%29&& 8、NVIDIA 修补GeForce软件中的高危性欺骗攻击漏洞 https://threatpost.com/nvidia-high-severity-geforce-spoof-bug/167345/ 9、新闻阅读器NewsBlur遭黑客入侵数据被清除 https://www.securityweek.com/newsblur-restores-service-after-hacker-wipes-database 10、7 亿 LinkedIn 用户的数据在暗网论坛出售 https://threatpost.com/data-700m-linkedin-users-cyber-underground/167362/
网络安全日报 2021年06月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Crackonosh挖矿恶意软件感染了超22W台Windows系统 https://securityaffairs.co/wordpress/119450/malware/crackonosh-monero-miner.html 2、 黑客利用Cisco ASA XSS漏洞进行攻击 https://securityaffairs.co/wordpress/119442/hacking/cisco-asa-under-attack.html 3、微软发现与俄有关的 SolarWinds 黑客入侵了三个新实体 https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html 4、Hive勒索软件泄露了 Altus Group 公司数据 https://securityaffairs.co/wordpress/119418/cyber-crime/new-ransomware-group-hive-leaks-altus-group-sample-files.html 5、FortiWeb WAF修复了一个任意命令执行高危漏洞 https://securityaffairs.co/wordpress/119387/security/fortinet-fortiweb-waf-flaw.html 6、黑客利用 3 年前的漏洞擦除WD设备的数据 https://securityaffairs.co/wordpress/119392/iot/hackers-wipe-western-digital-devices.html 7、梅赛德斯-奔驰批量数据泄露 https://securityaffairs.co/wordpress/119436/data-breach/mercedes-benz-data-breach.html 8、攻击者利用ReverseRat针对南亚和中亚能源组织 https://blog.lumen.com/suspected-pakistani-actor-compromises-indian-power-company-with-new-reverserat/ 9、攻击者可以利用One-Click攻击劫持Atlassian账户 https://thehackernews.com/2021/06/one-click-exploit-could-have-let.html 10、超过8亿条与WordPress用户相关的记录被泄露 https://www.infosecurity-magazine.com/news/cloud-database-exposes-800m/
网络安全日报 2021年06月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Dell BIOSConnect 功能中的严重漏洞影响128 款设备 https://securityaffairs.co/wordpress/119369/security/dell-biosconnect-flaws.html 2、VMware 修复Carbon Black App Control中严重漏洞 https://securityaffairs.co/wordpress/119362/security/vmware-carbon-black-app-control-flaw.html 3、Zyxel 警告客户防范针对其防火墙和VPN设备的攻击 https://securityaffairs.co/wordpress/119351/hacking/zyxel-firewall-vpn-attacks.html 4、PYSA勒索软件团伙使用ChaChi RAT针对教育组织 https://securityaffairs.co/wordpress/119338/malware/chachi-rat-us-schools.html 5、谷歌宣布扩展其开源漏洞数据库(OSV) https://www.securityweek.com/google-expands-open-source-vulnerabilities-database 6、 Atlassian 严重漏洞可导致帐户被劫持 https://thehackernews.com/2021/06/one-click-exploit-could-have-let.html 7、网络钓鱼活动利用PDF窃取用户Office365凭据 https://cofense.com/blog/security-update-phishing-pdf/ 8、美国塔尔萨遭勒索软件攻击泄露超过1.8万份文件 https://edition.cnn.com/2021/06/23/us/tulsa-cyberattack-personal-information-dark-web/index.html 9、网络安全公司联手对抗 DMCA 有争议的部分 https://www.securityweek.com/cybersecurity-companies-join-forces-against-controversial-dmca-section 10、谷歌将逐步淘汰cookie跟踪技术计划推迟 2 年 https://www.securityweek.com/google-delays-phase-out-tracking-tech-nearly-2-years
网络安全日报 2021年06月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、与巴基斯坦有关的黑客攻击印度电力公司 https://thehackernews.com/2021/06/pakistan-linked-hackers-targeted-indian.html 2、Linux Pling Store 中未修补的漏洞可能导致供应链攻击 https://thehackernews.com/2021/06/unpatched-critical-flaw-affects-pling.html 3、Revil勒索软件代码被竞争对手窃取 https://threatpost.com/revil-ransomware-code-rivals/167167/ 4、VMware修复了VMware Tools for Windows权限提升漏洞 https://securityaffairs.co/wordpress/119294/security/vmware-fixes-privilege-escalation-issue-in-vmware-tools-for-windows.html 5、Palo Alto 修复了 Cortex XSOAR产品中关键漏洞 https://securityaffairs.co/wordpress/119276/security/palo-alto-networks-cve-2021-3044-cortex-xsoar.html 6、受疫情影响,针对游戏行业和玩家的黑客攻击激增 https://www.securityweek.com/games-gaming-and-gamers-are-rapidly-growing-target-hackers 7、网络犯罪分子以Covid-19疫苗接种计划进行网络钓鱼部署恶意软件 https://cyware.com/news/a-covid-19-themed-campaign-delivering-agent-tesla-d5779a3f 8、Lexmark打印机中存在一个任意代码执行漏洞 https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/ 9、SonicWall VPN应用中已修补的漏洞仍存在问题 https://thehackernews.com/2021/06/sonicwall-left-vpn-flaw-partially.html 10、亚太互联网络信息中心由于配置错误数据泄露 https://portswigger.net/daily-swig/asia-pacific-internet-registry-apnic-says-whois-admin-passwords-were-mistakenly-exposed-for-three-months
网络安全日报 2021年06月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新型勒索软件DarkRadiation针对Linux和Docker容器 https://securityaffairs.co/wordpress/119256/uncategorized/wormable-bash-darkradiation-ransomware.html 2、恶意PyPI包劫持开发人员设备进行挖矿活动 https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/ 3、Tor 浏览器修补通过已安装应用追踪用户的漏洞 https://www.securityweek.com/tor-browser-patches-application-probing-vulnerability 4、DirtyMoe 僵尸网络在2021年上半年已感染超10W个Windows系统 https://securityaffairs.co/wordpress/119230/malware/dirtymoe-botnet-growing.html 5、研究人员开发DroidMorph工具,可创建Android应用克隆(恶意/良性) https://securityaffairs.co/wordpress/119206/malware/droidmorph-tool-generates-android-malware-clones-that.html 6、比利时列日市政府IT网络遭受勒索软件攻击 https://securityaffairs.co/wordpress/119240/malware/city-of-liege-ransomware.html 7、MITRE 将NSA开发的 D3FEND 防御策略知识库添加到 ATT&CK 框架 https://www.securityweek.com/mitre-adds-d3fend-countermeasures-attck-framework 8、Zephyr 的蓝牙 LE 堆栈中多个漏洞可能导致 DoS 攻击、信息泄露 https://www.securityweek.com/vulnerabilities-zephyrs-bluetooth-le-stack-may-lead-dos-attacks 9、电子邮件服务器软件Dovecot高危漏洞可导致消息侦听、凭据盗窃 https://threatpost.com/email-bug-message-snooping-credential-theft/167125/ 10、研究人员设计了一种对抗人脸识别的攻击-ADVERSARIAL OCTOPUS https://securityaffairs.co/wordpress/119248/hacking/adversarial-octopus-facial-recognition.html
网络安全日报 2021年06月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Ragnar Locker 发布了700GB从ADATA窃取的数据 https://securityaffairs.co/wordpress/119196/cyber-crime/ragnar-locker-ransomware-adata.html 2、军情五处因担心安全风险没收了约翰逊的手机 https://securityaffairs.co/wordpress/119174/security/mi5-seized-boris-johnson-phone.html 3、NSA 发布保护企业通信系统的指南 https://www.securityweek.com/nsa-releases-guidance-securing-enterprise-communication-systems 4、Nvidia Jetson Soc框架存高危漏洞可导致DoS攻击和数据窃取 https://threatpost.com/nvidia-jetson-chipset-dos-data-theft/167093/ 5、Wire Messaging App 高危漏洞可导致用户帐号被完全控制 https://portswigger.net/daily-swig/xss-flaw-in-wire-messaging-app-allowed-attackers-to-fully-control-user-accounts 6、北约使用的云平台被入侵和盗取数据 https://news.softpedia.com/news/nato-s-cloud-platform-has-been-hacked-533282.shtml 7、Google App 漏洞可被用于从设备中窃取个人数据 https://techcrunch.com/2021/06/17/a-security-bug-in-googles-android-app-installed-on-billions-of-devices-put-user-data-at-risk/ 8、研究人员发现iCloud忘记密码功能可通过大规模并发连接实现爆破 https://thezerohack.com/apple-vulnerability-bug-bounty 9、Zoll修补除颤器管理软件中的多个高风险漏洞 https://portswigger.net/daily-swig/healthcare-vendor-zoll-patches-high-risk-vulnerabilities-in-defibrillator-management-software 10、网络安全公司Cognyte暴露50亿条数据泄露记录 https://www.hackread.com/cybersecurity-firm-expose-data-breach-records/