网络安全日报 2021年06月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 发布针对威胁情报分析师的 MITRE ATT&CK 映射指南 https://www.securityweek.com/cisa-issues-mitre-attck-mapping-guide-threat-intelligence-analysts 2、思科修复 Webex 和 SD-WAN 中高风险安全漏洞 https://www.securityweek.com/cisco-plugs-high-risk-security-flaws-webex-sd-wan 3、FBI 确认 REvil 勒索软件攻击了 JBS Foods https://www.securityweek.com/fbi-confirms-revil-ransomware-involved-jbs-attack 4、趋势科技发布影响 macOS、iOS 的漏洞PoC https://www.securityweek.com/trend-micro-releases-poc-exploit-vulnerability-affecting-macos-ios 5、研究人员发现Rowhammer 攻击新技术 Half-Double https://cyware.com/news/half-double-a-new-variant-of-rowhammer-attack-eeb20e50 6、FireEye 以 12 亿美元出售其产品业务和品牌名 https://www.cnbc.com/2021/06/02/fireeye-selling-products-business-and-name-for-1point2-billion.html 7、Realtek RTL8170C Wi-Fi 模块多个漏洞可导致通信劫持和提权 https://securityaffairs.co/wordpress/118558/security/realtek-rtl8170c-wi-fi-module-flaws.html 8、FUJIFILM东京总部遭到网络攻击部分网络中断 https://www.bleepingcomputer.com/news/security/fujifilm-shuts-down-network-after-suspected-ransomware-attack/ 9、Accusoft ImageGear中存在多个安全漏洞 https://blog.talosintelligence.com/2021/06/vuln-spotlight-accusoft-.html 10、暴雪公司遭大规模DDoS攻击可能导致游戏高延迟 https://news.softpedia.com/news/blizzard-experiencing-ddos-attack-possible-high-latency-and-disconnections-533100.shtml
网络安全日报 2021年06月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科Talos 披露 macOS SMB 漏洞的详细信息 https://www.securityweek.com/cisco-discloses-details-macos-smb-vulnerabilities 2、JBS 在网络攻击后恢复大部分生产 https://www.securityweek.com/largest-meat-producer-getting-back-online-after-cyberattack 3、微软收购 ReFirm Labs 以增强物联网固件安全 https://www.securityweek.com/microsoft-buys-refirm-labs-expand-iot-firmware-security-push 4、Lasso 库一高危漏洞影响Cisco、Akamai产品及Linux发行版 https://www.securityweek.com/vulnerability-lasso-library-impacts-products-cisco-akamai 5、多个供应商的工业交换机受Korenix 固件漏洞影响 https://www.securityweek.com/industrial-switches-several-vendors-affected-same-vulnerabilities 6、Fancy Product Designer WordPress插件零日漏洞影响上万网站 https://securityaffairs.co/wordpress/118522/hacking/fancy-product-designer-wordpress-plugin-flaw.html 7、Zerodium 出10W赏金寻求 Pidgin 零日漏洞 https://securityaffairs.co/wordpress/118500/breaking-news/zerodium-pidgin-0day.html 8、研究人员发现抢先交易行为每月从以太坊交易中窃取 2.8 亿美元 https://securityaffairs.co/wordpress/118512/hacking/280-million-stolen-per-month-from-crypto-transactions.html 9、研究人员发现针对韩国政府机构的黑客行动 https://thehackernews.com/2021/06/researchers-uncover-hacking-operations.html 10、由于云配置错误,《银河之战》 600 万玩家资料泄露 https://www.infosecurity-magazine.com/news/battle-galaxy-gamers-data-leak/
网络安全日报 2021年06月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、毕马威报告称Accellion 未能及时通知客户 FTA 零日 https://www.securityweek.com/report-accellion-failed-notify-customers-fta-zero-day 2、卡巴斯基报告称2021年Q1网络攻击利用MS Office漏洞最多 https://www.securityweek.com/kaspersky-exploits-ms-office-flaws-most-popular-q1-2021 3、攻击者传播Android恶意软件Teabot和Flubot https://labs.bitdefender.com/2021/06/threat-actors-use-mockups-of-popular-apps-to-spread-teabot-and-flubot-malware-on-android/ 4、瑞典公共卫生局遭黑客攻击后关闭了SmiNet数据库 https://www.bleepingcomputer.com/news/security/swedish-health-agency-shuts-down-sminet-after-hacking-attempts/ 5、印度加尔各答ATM机遭黑客攻击损失400万卢比 https://timesofindia.indiatimes.com/city/kolkata/kol-atms-under-sophisticated-hacking-attack/articleshow/83096894.cms 6、Stanadyne旗下公司遭到Conti勒索软件攻击 https://www.technadu.com/stanadynes-purepower-technologies-conti-ransomware-group/280366/ 7、研究人员发现多种支持EPUB格式的电子阅读系统中存在安全漏洞 https://portswigger.net/daily-swig/epub-vulnerabilities-electronic-reading-systems-riddled-with-browser-like-flaws 8、新兴Prometheus勒索软件团伙出售墨西哥政府数据 https://securityaffairs.co/wordpress/118446/cyber-crime/prometheus-grief-ransomware.html 9、白宫发言人称针对JBS的勒索软件攻击可能来自俄罗斯 https://securityaffairs.co/wordpress/118490/cyber-crime/jbs-attack-russian-origin.html 10、Nobelium 通过新的网络钓鱼活动再次活跃起来 https://cyware.com/news/nobelium-active-again-with-new-phishing-campaign-30bf4eee
网络安全日报 2021年06月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软为亚太地区的公共部门创建网络安全委员会 https://www.securityweek.com/microsoft-creates-cybersecurity-council-public-sector-apac 2、SonicWall 修复了防火墙管理应用程序中的命令注入漏洞 https://www.securityweek.com/sonicwall-patches-command-injection-flaw-firewall-management-application 3、研究人员发现新型勒索软件 Epsilon Red https://www.securityweek.com/cybercriminals-target-companies-new-epsilon-red-ransomware 4、丹麦情报部门帮助美国国家安全局监视欧洲政客 https://securityaffairs.co/wordpress/118434/intelligence/us-nsa-spy-european-politicians.html 5、安全研究人员发现绕过Microsoft PatchGuard安全功能的漏洞 https://securityaffairs.co/wordpress/118427/hacking/microsoft-patchguard-kpp-bypass.html 6、亚马逊设备将启动自动与邻居设备共享你的 Wi-Fi功能 https://thehackernews.com/2021/05/your-amazon-devices-to-automatically.html 7、1.3亿条印度进出口数据记录在暗网中遭泄露 https://cybleinc.com/2021/05/28/130-million-records-of-india-based-import-export-data-allegedly-leaked-in-the-darkweb/ 8、网络钓鱼活动通过虚假电影网站分发BazarLoader https://cyware.com/news/fake-streaming-service-spreads-bazarloader-f8bdeeab 9、肉制品公司JBS Foods因大规模网络攻击而关闭 https://news.softpedia.com/news/jbs-foods-shuts-down-due-to-massive-cyberattack-533076.shtml 10、研究人员开发了一种针对机器学习系统的对抗性攻击-DeepSloth https://cyware.com/news/deepsloth-an-adversarial-attack-on-machine-learning-systems-dbfc5b2e
网络安全日报 2021年05月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现可对Siemens PLC进行远程攻击的严重漏洞 https://www.securityweek.com/newly-disclosed-vulnerability-allows-remote-hacking-siemens-plcs 2、研究人员披露新的攻击技术可更改认证的PDF文档 https://securityaffairs.co/wordpress/118404/hacking/altering-signed-pdf-documents.html 3、 360 NETLAB 发现了针对Linux名为 Facefish 的新后门 https://securityaffairs.co/wordpress/118388/malware/facefish-backdoor.html 4、FBI 将与 HIBP Pwned Passwords 共享调查期间发现的泄露密码 https://securityaffairs.co/wordpress/118377/security/fbi-passwords-hibp-pwned-passwords.html 5、SonicWall 修复了 NSM On-Prem 漏洞 https://securityaffairs.co/wordpress/118372/security/sonicwall-nsm-on-prem-bug.html 6、微软披露了 NOBELIUM 新型复杂鱼叉式网络钓鱼攻击 https://securityaffairs.co/wordpress/118352/apt/spear-phishing-attacks-nobelium.html 7、 研究人员披露浏览器劫持程序Secured Search https://securityaffairs.co/wordpress/118380/security/how-remove-secured-search.html 8、美国士兵使用的抽认卡APP意外泄露核信息 https://www.securityweek.com/nuclear-flash-cards-us-secrets-exposed-learning-apps 9、网络钓鱼活动冒充沃尔玛窃取个人信息 https://www.bleepingcomputer.com/news/security/beware-walmart-phishing-attack-says-your-package-was-not-delivered/ 10、墨西哥在勒索软件DDoS威胁后封锁了国家彩票网站 https://www.bleepingcomputer.com/news/security/mexico-walls-off-national-lottery-sites-after-ransomware-ddos-threat/
网络安全日报 2021年05月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、QNAP设备持续受到网络攻击 https://cyware.com/news/qnap-devices-bombarded-by-cyberattacks-7af9e3bc2、日本预计俄黑客将在东京夏季奥运会时发动网络攻击 https://news.softpedia.com/news/japan-expects-russian-cyberattacks-on-tokyo-summer-olympics-533044.shtml3、俄罗斯情报局FSB报告针对政府机构的黑客攻击活动 https://www.usnews.com/news/technology/articles/2021-05-26/russias-fsb-reports-unprecedented-hacking-campaign-aimed-at-government-agencies4、西门子解决了影响其Solid Edge产品的CAD库漏洞 https://www.securityweek.com/siemens-addresses-code-execution-vulnerabilities-found-popular-cad-library5、富士通SaaS平台遭黑客入侵,日本政府文件被盗 https://therecord.media/fujitsu-suspends-projectweb-platform-after-japanese-government-hacks/6、VSCode扩展中新发现的严重漏洞可能导致供应链攻击 https://thehackernews.com/2021/05/newly-discovered-bugs-in-vscode.html7、FBI称APT组织通过未修补的Fortinet VPN入侵了美国地方政府网络 https://securityaffairs.co/wordpress/118338/apt/fortinet-vpn-us-municipal-government.html8、美国DHS宣布了针对关键管道所有者和运营商的新网络安全要求 https://securityaffairs.co/wordpress/118332/security/dhs-critical-pipeline-industry.html9、HPE修复了去年12月披露的关键0day漏洞 https://www.bleepingcomputer.com/news/security/hpe-fixes-critical-zero-day-vulnerability-disclosed-in-december/10、GraphQL存在跨站请求伪造攻击的风险 https://portswigger.net/daily-swig/overlooked-vulnerabilities-in-graphql-open-the-door-to-cross-site-request-forgery-attacks
网络安全日报 2021年05月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Vmware修复了vCenter Server一个高危漏洞 https://www.securityweek.com/vmware-urges-customers-immediately-patch-critical-vsphere-vulnerability2、Google Chrome 91发行版修补了32个漏洞 https://www.securityweek.com/google-patches-32-vulnerabilities-release-chrome-913、法国警方查封了黑暗网络市场Le MondeParallèle https://securityaffairs.co/wordpress/118295/deep-web/le-monde-parallele-dark-web.html4、谷歌安全人员发现了Rowhammer攻击新变种Half-Double https://securityaffairs.co/wordpress/118284/hacking/rowhammer-variant-dubbed-half-double.html5、比利时内政部遭复杂的网络攻击 https://securityaffairs.co/wordpress/118275/breaking-news/belgium-interior-ministry-cyber-attack.html6、CNCERT发布2020年我国互联网网络安全态势综述报告 https://mp.weixin.qq.com/s/a2nFajrBk3bxCynfC6hdQQ7、达美乐的印度公司披露了一起数据泄露事件 https://www.bleepingcomputer.com/news/security/dominos-india-discloses-data-breach-after-hackers-sell-data-online/8、美国非营利医疗保健服务提供商20万私人信息遭泄露 https://portswigger.net/daily-swig/us-healthcare-non-profit-reports-data-breach-impacting-200-000-patients-employees9、NIST首个后量子密码标准将于今年晚些时候确定 https://www.scmagazine.com/home/government/post-quantum-cryptographic-standards-to-be-finalized-later-this-year/10、安全人员发现数千个Chrome扩展程序篡改HTTP 安全标头 https://therecord.media/thousands-of-chrome-extensions-are-tampering-with-security-headers/
网络安全日报 2021年05月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Bose遭勒索攻击和数据泄露 https://www.securityweek.com/bose-says-personal-information-compromised-ransomware-attack2、苹果发布macOS和iOS等系统更新修复零日漏洞 https://securityaffairs.co/wordpress/118227/breaking-news/apple-zero-day-flaws.html3、Ivanti修复了Pulse Connect Secure VPN中的严重漏洞 https://securityaffairs.co/wordpress/118257/security/pulse-connect-secure-vpn-flaw.html4、美国银行开始尝试使用人脸识别技术 https://securityaffairs.co/wordpress/118230/security/us-banks-facial-recognition.html5、趋势科技修复了家庭网络安全设备中的漏洞 https://www.securityweek.com/trend-micro-patches-vulnerabilities-home-network-security-devices6、塔尔萨市计算机系统遭受勒索软件攻击 https://www.securityweek.com/tulsa-computer-system-hacks-stopped-security-shutdown7、黑客承认窃取了超过65000名UPMC员工的敏感数据 https://www.infosecurity-magazine.com/news/michigan-man-admits-selling-upmc/8、MountLocker勒索软件利用Windows API进行传播 https://cyware.com/news/mountlocker-using-windows-api-to-spread-as-worm-9e1055679、1300万DailyQuiz用户个人详细信息在线泄露 https://therecord.media/8-3-million-plaintext-passwords-exposed-in-dailyquiz-data-breach10、TeamTNT以Kubernetes集群为目标,超5W个IP遭攻击 https://www.trendmicro.com/en_us/research/21/e/teamtnt-targets-kubernetes--nearly-50-000-ips-compromised.html
网络安全日报 2021年05月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员将CryptoCore活动与Lazarus Group 关联 https://thehackernews.com/2021/05/researchers-link-cryptocore-attacks-on.html 2、研究人员披露了Nagios的13个漏洞详情 https://thehackernews.com/2021/05/details-disclosed-on-critical-flaws.html 3、FBI分析师被指控窃取反恐和网络威胁信息 https://thehackernews.com/2021/05/fbi-analyst-charged-with-stealing.html 4、法国ANSSI的研究人员发现了Bluetooth Core和Mesh的多个漏洞 https://securityaffairs.co/wordpress/118219/hacking/bluetooth-core-mesh-specs-flaws.html 5、Zeppelin勒索软件即服务(RaaS)运营商卷土重来 https://securityaffairs.co/wordpress/118215/cyber-crime/zeppelin-ransomware-return.html 6、CVE-2021-31166 HTTP协议栈漏洞也影响WinRM服务器 https://securityaffairs.co/wordpress/118189/security/cve-2021-31166-windows-http-flaw.html 7、研究人员在波音747上实现了持久的Shell访问 https://www.theregister.com/2021/05/21/boeing_747_ife_windows_nt4_shell_access/ 8、Anker修复了Eufy摄像机泄露视频流的问题 https://securityaffairs.co/wordpress/118197/security/eufy-video-camera-flaw.html 9、由于SSL证书过期导致Exchange管理门户无法访问 https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-admin-portal-blocked-by-expired-ssl-certificate/ 10、研究人员开发了针对神经网络的DeepSloth攻击 https://portswigger.net/daily-swig/deepsloth-researchers-find-denial-of-service-equivalent-against-machine-learning-systems
网络安全日报 2021年05月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、印度航空遭黑客入侵并泄露数据,450W客户受影响 https://www.securityweek.com/indias-national-carrier-says-hack-leaked-passengers-data2、Microsoft推出SimuLand:开源的攻击场景模拟器 https://www.securityweek.com/microsoft-unveils-simuland-open-source-attack-techniques-simulator3、阿拉斯加卫生部网站遭恶意软件攻击而被迫下线 https://securityaffairs.co/wordpress/118184/cyber-crime/alaska-health-department-malware.html4、FBI称Conti 勒索软件攻击了美国的16个医疗和紧急服务部门 https://securityaffairs.co/wordpress/118167/cyber-crime/conti-ransomware-flash-alert.html5、FSB称外国黑客已入侵了俄罗斯联邦机构网络 https://securityaffairs.co/wordpress/118169/intelligence/fsb-says-russian-agencies-hacked.html6、保险巨头CNA Financial支付4000W赎金以恢复被勒索软件破坏的文件 https://securityaffairs.co/wordpress/118142/cyber-crime/cna-financial-ransomware.html7、Qlocker勒索软件利用HBS漏洞感染QNAP NAS设备 https://securityaffairs.co/wordpress/118179/malware/qlocker-ransomware-qnap-nas.html8、Python软件包存储库PyPI遭垃圾邮件轰炸 https://www.bleepingcomputer.com/news/security/spammers-flood-pypi-with-pirated-movie-links-and-bogus-packages/9、Comcast现已部署RPKI防范BGP劫持和路由泄漏 https://www.bleepingcomputer.com/news/security/comcast-now-blocks-bgp-hijacking-attacks-and-route-leaks-with-rpki/10、数据表明2020年全球范围内撞库攻击达1930亿次 https://www.infosecurity-magazine.com/news/global-credential-stuffing-193/