网络安全日报 2021年06月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、APT 组织 Kimsuky 利用 VPN 漏洞入侵了韩国核研究机构 KAERI https://securityaffairs.co/wordpress/119147/apt/kimsuky-apt-hacked-south-korea-kaeri.html 2、美国连锁超市 Wegmans 披露数据泄露 https://securityaffairs.co/wordpress/119115/data-breach/wegmans-discloses-data-breach.html 3、专家发现 Cisco Small Business 220 系列产品多个漏洞 https://securityaffairs.co/wordpress/119108/security/cisco-small-business-220-flaw.html 4、游轮运营商嘉年华披露电子邮件账户数据泄露事件 https://securityaffairs.co/wordpress/119102/data-breach/carnival-security-breach.html 5、最近的Akamai 中断是因 Prolexic DDoS 保护服务的问题引起的 https://securityaffairs.co/wordpress/119094/security/akamai-outage-akamai-bug.html 6、研究人员发现iPhone新漏洞可永久破坏其WiFi功能 https://securityaffairs.co/wordpress/119157/hacking/iphone-bug-wifi-connectivity.html 7、波兰称最近的网络攻击来自俄罗斯 https://www.securityweek.com/major-cyberattack-poland-came-russian-territory-kaczynski 8、攻击者利用谷歌文档发送钓鱼链接窃取用户凭据 https://www.avanan.com/blog/attackers-take-advantage-of-new-google-doc-exploit?hs_preview=yDruqEUZ-48384993709 9、数十万Netflix和Disney+的账户在暗网售卖 https://www.technadu.com/hundreds-thousands-netflix-disney-plus-accounts-purchase-dark-web/284336/ 10、GitLab修复了严重的SSRF漏洞 https://portswigger.net/daily-swig/gitlab-fixes-serious-ssrf-flaw-that-exposed-orgs-internal-servers
网络安全日报 2021年06月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、在线零售商 Cosmolog Kozmetik 数十万客户数据泄露 https://securityaffairs.co/wordpress/119067/data-breach/cosmolog-kozmetik-data-breach.html 2、Ferocious Kitten APT利用伪装的Telegram和Psiphon部署RAT https://securityaffairs.co/wordpress/119073/apt/ferocious-kitten-apt-campaign.html 3、UNC2465网络犯罪集团对摄像头厂商大华进行供应链攻击 https://securityaffairs.co/wordpress/119051/cyber-crime/unc2465-supply-chain-attack.html 4、Chrome修复被在野利用的零日漏洞 https://www.securityweek.com/google-confirms-sixth-zero-day-chrome-attack-2021 5、研究人员发现2G网络GPRS存在漏洞,流量或被窃听超过20年 https://www.securityweek.com/security-flaw-found-2g-mobile-data-encryption-standard 6、谷歌推出 SLSA 框架以加强供应链完整性 https://www.securityweek.com/google-intros-slsa-framework-enforce-supply-chain-integrity 7、研究人员披露了一种新的进程篡改攻击技术-Process Ghosting https://thehackernews.com/2021/06/researchers-uncover-process-ghosting.html 8、针对中东政府的Molerats 黑客组织在消失两个月后卷土重来 https://thehackernews.com/2021/06/molerats-hackers-return-with-new.html 9、韩国HMM海运公司电子邮件系统遭网络攻击 https://theloadstar.com/hmm-suffers-security-breach-and-cyber-attack-on-its-email-systems/ 10、攻击者邮寄伪造的Ledger设备窃取加密货币 https://www.bleepingcomputer.com/news/cryptocurrency/criminals-are-mailing-hacked-ledger-devices-to-steal-cryptocurrency/
网络安全日报 2021年06月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国最大的丙烷供应商AmeriGas数据泄露 https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/ 2、微软Teams存严重漏洞可能允许攻击者窃取敏感数据 https://portswigger.net/daily-swig/vulnerability-in-microsoft-teams-granted-attackers-access-to-emails-messages-and-personal-files 3、波兰政府称机构和个人遭受前所未有的一系列网络攻击 https://securityaffairs.co/wordpress/119043/hacking/poland-hit-cyber-attacks.html 4、国际联合行动逮捕了多名Clop 勒索软件成员 https://securityaffairs.co/wordpress/119036/cyber-crime/clop-ransomware-arrest.html 5、谷歌发布全同态加密的开源工具和库 https://www.securityweek.com/google-releases-open-source-tools-and-libraries-fully-homomorphic-encryption 6、谷歌为 Android 消息应用推出 E2EE(端到端加密) https://www.securityweek.com/google-rolls-out-e2ee-android-messages-app 7、施耐德 PowerLogic 设备存在漏洞可被黑客控制和利用 https://www.securityweek.com/vulnerabilities-allow-hackers-disrupt-hijack-schneider-powerlogic-devices 8、STEM 会议免提电话存在漏洞可被用于窃听对话 https://www.securityweek.com/flaws-stem-conference-room-speakerphone-can-be-exploited-spy-users 9、Peloton Bike+ 存严重漏洞可被黑客完全控制 https://threatpost.com/peloton-bike-bug-hackers-control/166960/ 10、超过 10 亿条属于 CVS Health 的数据在线泄露 https://www.zdnet.com/article/billions-of-records-belonging-to-cvs-health-exposed-online
网络安全日报 2021年06月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Paradise Ransomware 源代码在 XSS 黑客论坛泄露 https://securityaffairs.co/wordpress/119006/cyber-crime/paradise-ransomware-code-leaked.html 2、Instagram修复了查看任意用户私人动态的漏洞 https://securityaffairs.co/wordpress/118994/security/instagram-flaw-2.html 3、富士胶片在勒索软件攻击后恢复服务 https://www.securityweek.com/fujifilm-restores-services-following-ransomware-attack 4、数以百万计联网摄像头受ThroughTek组件漏洞影响 https://threatpost.com/millions-connected-cameras-eavesdropping/166950/ 5、微软破坏了大规模、基于云的 BEC 活动 https://threatpost.com/microsoft-disrupts-cloud-bec-campaign/166937/ 6、TeaBot 木马通过冒充防病毒应用程序进行传播 https://cyware.com/news/teabot-trojan-spreads-via-fake-antivirus-apps-d59f7630 7、攻击者利用SEO中毒分发SolarMarker恶意软件 https://www.bleepingcomputer.com/news/security/microsoft-seo-poisoning-used-to-backdoor-targets-with-malware/ 8、黑客出售法国电信供应商Free的数据库访问权 https://www.technadu.com/hacker-broke-into-french-isp-free-selling-database-access/283142/ 9、Facebook Messenger Rooms中存在安全漏洞 https://portswigger.net/daily-swig/android-screen-lock-protection-thwarted-by-facebook-messenger-rooms-exploit 10、SIP通信协议可能被滥用来执行跨站脚本攻击 https://portswigger.net/daily-swig/sip-protocol-abused-to-trigger-xss-attacks-via-voip-call-monitoring-software
网络安全日报 2021年06月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌为Google Workspace推出客户端加密 https://thehackernews.com/2021/06/google-workspace-now-offers-client-side.html 2、NoxPlayer 供应链攻击与Gelsemium黑客组织有关 https://thehackernews.com/2021/06/noxplayer-supply-chain-attack-is-likely.html 3、Mirai 僵尸网络变体 Moobot利用Tenda路由器漏洞进行传播 https://threatpost.com/moobot-tenda-router-bugs/166902/ 4、大众汽车供应商泄露了330万名客户的个人数据 https://threatpost.com/vw-data-3m-audi-drivers/166892/ 5、美国核武器承包商Sol Oriens 遭REvil勒索软件攻击 https://threatpost.com/revil-hits-us-nuclear-weapons-contractor-sol-oriens/166858/ 6、CD Projekt Red证实在遭攻击四个月后,相关被盗数据在线泄露 https://threatpost.com/cyberpunk-2077-hacked-data-online/166852/ 7、苹果称WebKit 漏洞被利用来破解旧款 iPhone,已发布更新补丁 https://www.securityweek.com/apple-webkit-bugs-exploited-hack-older-iphones 8、麦当劳披露美国、台湾和韩国的数据泄露事件 https://securityaffairs.co/wordpress/118894/data-breach/mcdonalds-data-breach.html 9、 polkit 身份验证系统漏洞影响大多数Linux发行版 https://securityaffairs.co/wordpress/118877/security/polkit-auth-linux-distros.html 10、Avaddon 勒索软件团伙关闭其运营并释放解密密钥 https://securityaffairs.co/wordpress/118872/cyber-crime/avaddon-ransomware-shuts-down-operations.html
网络安全日报 2021年06月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、攻击者利用 SonicWall VPN 漏洞破坏 SRA 设备 https://www.securityweek.com/attackers-leverage-sonicwall-vpn-flaw-compromise-sra-appliances 2、GitHub 开始扫描RubyGems、PyPI等开源包中可能泄露的凭证 https://www.securityweek.com/github-starts-scanning-exposed-package-registry-credentials 3、霍尼韦尔推出 OT 网络安全监控和响应服务 https://www.securityweek.com/honeywell-launches-ot-cybersecurity-monitoring-and-response-service 4、谷歌修复了被利用的Chrome零日漏洞 https://www.securityweek.com/google-patches-chrome-zero-day-used-commercial-exploit-company 5、 JBS 确认向REvil勒索团队支付了 1100 万美元的赎金 https://www.securityweek.com/meat-company-jbs-confirms-it-paid-11m-ransom-cyberattack 6、游戏巨头EA遭黑客入侵被窃取780GB数据,包括游戏源码和工具 https://securityaffairs.co/wordpress/118820/data-breach/electronic-arts-data-breach.html 7、 2017 年荷兰调查MH-17事件时,与俄相关APT入侵了荷兰警方网络 https://securityaffairs.co/wordpress/118794/apt/russia-linked-apt-dutch-police.html 8、Group-IB 发布报告称诈骗已经成为在线犯罪之首 https://securityaffairs.co/wordpress/118828/cyber-crime/scams-online-crime.html 9、神秘的恶意软件收集了数十亿个凭证 https://threatpost.com/custom-malware-stolen-data/166753/ 10、谷歌Play中存在《我的世界》模组包恶意软件 https://www.kaspersky.co.uk/blog/minecraft-mod-adware-google-play-revisited/22887/
网络安全日报 2021年06月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的恶意活动攻击Kubeflow用于挖矿 https://www.securityweek.com/kubeflow-deployments-targeted-new-crypto-mining-campaign 2、英特尔本周发布多个产品的73个漏洞补丁 https://www.securityweek.com/intel-releases-29-advisories-describe-73-vulnerabilities-affecting-its-products 3、西门子和施耐德电气告知客户影响其产品的数十个漏洞 https://www.securityweek.com/siemens-schneider-electric-inform-customers-about-tens-vulnerabilities 4、在发出警告5年后,思科智能安装协议仍在攻击中被滥用 https://www.securityweek.com/cisco-smart-install-protocol-still-abused-attacks-5-years-after-first-warning 5、西班牙劳动和社会经济部遭网络攻击 https://securityaffairs.co/wordpress/118768/hacking/spains-ministry-of-labor-cyberattack.html 6、新型 TLS 攻击可以对安全站点发起跨域和跨协议攻击 https://thehackernews.com/2021/06/new-tls-attack-lets-attackers-launch.html 7、内存和存储制造商威刚遭到 Ragnar Locker 勒索软件攻击 https://www.techradar.com/news/adata-struck-by-ragnar-locker-ransomware-attack 8、研究人员发现Linktree被滥用以发送钓鱼链接 https://cofense.com/blog/linktree-phishing-links/ 9、Joomla CMS中的两个漏洞可导致系统被入侵 https://portswigger.net/daily-swig/dual-vulnerability-combo-in-popular-cms-joomla-could-lead-to-full-system-compromise 10、WAGO控制器漏洞可被黑客利用破坏工业流程 https://www.securityweek.com/wago-controller-flaws-can-allow-hackers-disrupt-industrial-processes
网络安全日报 2021年06月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SAP 修补了 NetWeaver 中的关键漏洞 https://www.securityweek.com/sap-patches-critical-vulnerabilities-netweaver2、微软对新的 Windows 零日攻击发出警报 https://www.securityweek.com/microsoft-raises-alarm-new-windows-zero-day-attacks3、Adobe 修补 PDF Reader 和 Photoshop 中的高危漏洞 https://www.securityweek.com/adobe-patches-major-security-flaws-pdf-reader-photoshop4、RabbitMQ等流行的开源消息代理存在 DoS漏洞 https://www.securityweek.com/organizations-warned-about-dos-flaws-popular-open-source-message-brokers5、 CISA 发布漏洞披露平台允许道德黑客向联邦机构报告安全漏洞 https://www.securityweek.com/cisa-announces-vulnerability-disclosure-policy-platform6、 Google发布Android 6月更新修补了多个严重漏洞 https://www.securityweek.com/critical-vulnerabilities-patched-android-june-2021-security-updates7、Fastly CDN 故障影响了Reddit、GitHub、Paypal等多个网站访问 https://securityaffairs.co/wordpress/118732/breaking-news/fastly-cdn-outage.html8、Trojan Shield行动:警方运行加密通信平台抓捕犯罪团伙 https://securityaffairs.co/wordpress/118706/cyber-crime/trojan-shield-op.html9、专家在 Microsoft Office 套件中发现了四个高危漏洞 https://securityaffairs.co/wordpress/118741/breaking-news/microsoft-office-component-flaws.html10、Hyperkitty中的安全漏洞可能会暴露私人数据 https://portswigger.net/daily-swig/security-vulnerability-in-hyperkitty-could-expose-private-data
网络安全日报 2021年06月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美司法部已收回Colonial Pipeline支付的大部分赎金 https://www.securityweek.com/us-has-recovered-ransom-payment-made-after-pipeline-hack 2、“Siloscape”恶意软件以 Windows Server 容器为目标 https://www.securityweek.com/siloscape-malware-targets-windows-server-containers 3、军用车辆制造商 Navistar 报告其遭网络攻击数据被盗 https://www.securityweek.com/military-vehicles-maker-navistar-reports-data-theft-cyberattack 4、RockYou2021:有史以来最大的密码集合在线泄露,共84亿条 https://securityaffairs.co/wordpress/118696/data-breach/rockyou2021-largest-password-compilation-of-all-time-leaked-online-with-8-4-billion-entries.html 5、乌克兰称俄罗斯黑客对其进行大规模鱼叉式钓鱼活动 https://securityaffairs.co/wordpress/118675/apt/ukraine-hit-russia-spear-phishing.html 6、安全研究人员在 QNAP Q'center 中发现 RCE 漏洞 https://securityaffairs.co/wordpress/118668/hacking/qnap-qcenter-rce.html 7、GitHub 更新策略以删除在主动攻击中使用的漏洞利用代码 https://thehackernews.com/2021/06/github-updates-policy-to-remove-exploit.html 8、开源学校管理软件Fedena中发现严重零日漏洞 https://portswigger.net/daily-swig/critical-zero-day-vulnerabilities-found-in-unsupported-fedena-school-management-software 9、新的网络钓鱼活动劫持比特币地址并分发Agent Tesla https://www.fortinet.com/blog/threat-research/phishing-malware-hijacks-bitcoin-addresses-delivers-new-agent-tesla-variant 10、英国Furniture Village家具零售商遭到网络攻击 https://www.theregister.com/2021/06/04/furniture_village_confirms_cyberattack/
网络安全日报 2021年06月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、越来越多的 STUN 服务器被 DDoS 攻击滥用 https://www.securityweek.com/organizations-warned-stun-servers-increasingly-abused-ddos-attacks 2、多款ICS产品使用的CODESYS软件存在严重漏洞 https://www.securityweek.com/serious-vulnerabilities-found-codesys-software-used-many-ics-products 3、研究人员发现新的恶意软件BlackCocaine Ransomware https://securityaffairs.co/wordpress/118617/malware/blackcocaine-ransomware.html 4、Colonial Pipeline遭攻击是因为员工密码泄露 https://www.bloombergquint.com/business/hackers-breached-colonial-pipeline-using-compromised-password 5、黑客扫描易受CVE-2021-21985 RCE攻击的 vCenter Server https://securityaffairs.co/wordpress/118594/hacking/hackers-vmware-vcenter-cve-2021-21985.html 6、APT28利用SkinnyBoy恶意软件入侵敏感组织 https://www.bleepingcomputer.com/news/security/new-skinnyboy-malware-used-by-russian-hackers-to-breach-sensitive-orgs/ 7、考克斯媒体集团广播和电视台遭到网络攻击 https://therecord.media/live-streams-go-down-across-cox-radio-tv-stations-in-apparent-ransomware-attack/ 8、Korenix更新修补了网络设备中的多个关键漏洞 https://portswigger.net/daily-swig/korenix-patches-multiple-critical-vulnerabilities-in-networking-devices 9、约170名东京奥运会工作人员的数据被黑客窃取 https://www.technadu.com/tokyo-olympics-organizers-data-stolen-hackers/281267/ 10、美国UF Health医院遭到网络攻击关闭部分网络 https://www.bleepingcomputer.com/news/security/uf-health-florida-hospitals-back-to-pen-and-paper-after-cyberattack/