网络安全日报 2021年05月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、古巴勒索软件帮派与Hancitor恶意软件联合 https://securityaffairs.co/wordpress/117638/cyber-crime/cuba-ransomware-hancitor.html2、专家发现针对Windows的新型恶意软件Moriya rootkit https://securityaffairs.co/wordpress/117626/malware/moriya-rootkit-operation-tunnelsnake.html3、高通漏洞影响全球约30%的智能手机 https://securityaffairs.co/wordpress/117620/security/qualcomm-bus-cve-2020-11292.html4、思科修复了SD-WAN 和HyperFlex HX软件中的严重漏洞 https://securityaffairs.co/wordpress/117560/security/cisco-sd-wan-vmanage-hyperflex-hx-flaws.html5、研究人员在HPE Edgeline中发现了严重身份绕过漏洞 https://securityaffairs.co/wordpress/117513/security/hpe-edgeline-infrastructure-manager-flaw.html6、安全研究人员披露影响DNS的高危漏洞TsuNAME https://thehackernews.com/2021/05/new-tsuname-flaw-could-let-attackers.html7、英特尔和AMD CPU的新幽灵漏洞影响数十亿台计算机 https://thehackernews.com/2021/05/new-spectre-flaws-in-intel-and-amd-cpus.html8、Google将自动为某些帐户启用两步验证 https://www.securityweek.com/attackers-use-obscurity-enterprises-should-too9、红帽开源StackRox安全技术 https://www.securityweek.com/red-hat-open-sourcing-stackrox-security-technology10、美国国防部扩展了其漏洞赏金计划的范围 https://www.zdnet.com/article/dod-expands-its-bug-hunting-programme-to-networks-iot-and-more/
网络安全日报 2021年05月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、大规模DDoS导致比利时政府网站瘫痪 https://securityaffairs.co/wordpress/117529/hacking/belgiums-ddos-attack.html2、大多数Exim电子邮件服务器存在21Nails漏洞可被攻击 https://securityaffairs.co/wordpress/117522/security/exim-email-servers-21nails-flaws.html3、数亿台戴尔PC受驱动程序漏洞CVE-2021-21551影响 https://securityaffairs.co/wordpress/117514/security/cve-2021-21551-dell-flaws.html4、苹果修复了WebKit浏览器引擎中的三个零日漏洞 https://securityaffairs.co/wordpress/117500/security/apple-webkit-zero-day-flaws.html5、专家发布了针对Microsoft Exchange 高危漏洞的PoC https://securityaffairs.co/wordpress/117493/hacking/microsoft-exchange.html6、Pulse Secure已修复SSL VPN设备中的零日漏洞 https://securityaffairs.co/wordpress/117484/hacking/pulse-connect-secure-zeroday.html7、新的攻击方式可以破坏目前所有针对Spectre攻击的防御措施 https://threatpost.com/attacks-slaughter-spectre-defenses/165809/8、FiveHands勒索软件中利用SonicWall零日漏洞 https://thehackernews.com/2021/04/hackers-exploit-sonicwall-zero-day-bug.html9、累计超过1亿安装的40个应用程序发现AWS密钥泄漏 https://thehackernews.com/2021/05/over-40-apps-with-more-than-100-million.html10、卫生保健巨头Scripps Health遭勒索软件攻击 https://www.bleepingcomputer.com/news/security/health-care-giant-scripps-health-hit-by-ransomware-attack/
网络安全日报 2021年05月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、TBONE(Tesla 的一些安全漏洞)细节公开 https://kunnamon.io/tbone/2、ATT&CK 发布了 v9 更新 https://medium.com/mitre-attack/attack-april-2021-release-39accaf23c813、AgeLocker勒索软件针对QNAP NAS设备 https://securityaffairs.co/wordpress/117424/malware/qnap-agelocker-ransomware.html4、BIND软件中的缺陷使DNS服务器容易受到攻击 https://securityaffairs.co/wordpress/117414/security/bind-dns-servers-flaws.html5、Babuk团队宣布将停止勒索软件攻击 https://securityaffairs.co/wordpress/117407/cyber-crime/babuk-stops-ransomware-attacks.html6、UNC2447在SonicWall零日漏洞修复之前就利用了该漏洞 https://securityaffairs.co/wordpress/117387/malware/unc2447-sonicwall-zero-day.html7、网络安全社区对GitHub有关漏洞利用相关政策更新不满意 https://www.securityweek.com/cybersecurity-community-unhappy-githubs-proposed-policy-updates8、微软警告OT、物联网设备中的BadAlloc漏洞 https://securityaffairs.co/wordpress/117372/iot/badalloc-vulnerabilities-ot-iot.html9、SolarMarket RAT使用Google SEO策略引诱受害者 https://cyware.com/news/solarmarket-rat-uses-google-seo-tactics-to-lure-victims-46b85a6410、Water Pamola通过恶意订单攻击在线商店 https://www.trendmicro.com/en_us/research/21/d/water-pamola-attacked-online-shops-via-malicious-orders.html
网络安全日报 2021年04月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、安全研究人员发现IoT和OT设备中的多个高危安全漏洞 https://www.securityweek.com/badalloc-microsoft-flags-major-security-holes-ot-iot-devices 2、DigitalOcean通知客户某些账单信息遭泄露 https://www.securityweek.com/digitalocean-discloses-breach-involving-billing-information 3、苹果修复了影响M1芯片Mac的安全绕过漏洞 https://www.securityweek.com/apple-patches-security-bypass-vulnerability-impacting-macs-m1-chip 4、Cisco修复了影响其防火墙产品的多个高危漏洞 https://www.securityweek.com/several-high-severity-vulnerabilities-expose-cisco-firewalls-remote-attacks 5、PHP Composer修复了可导致供应链攻击的高危命令注入漏洞 https://securityaffairs.co/wordpress/117366/security/php-composer-flaw.html 6、意大利最大的合作信贷银行之一BCC遭勒索软件攻击 https://securityaffairs.co/wordpress/117360/cyber-crime/banca-di-credito-cooperativo-darkside-ransomware.html 7、卡巴斯基发现与CIA关联的新型恶意软件Purple Lambert https://securityaffairs.co/wordpress/117340/apt/purple-lambert-cia-arsenal.html 8、360 Netlab发现了隐藏3年名为RotaJakiro 的Linux后门 https://securityaffairs.co/wordpress/117332/breaking-news/rotajakiro-linux-backdoor.html 9、Experian API泄露了大多数美国人的信用评分 https://threatpost.com/experian-api-leaks-american-credit-scores/165731/ 10、流行的OGUsers黑客论坛再次遭到黑客入侵 https://www.bleepingcomputer.com/news/security/fourth-times-a-charm-ogusers-hacking-forum-hacked-again/
网络安全日报 2021年04月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google在Chrome中修补了一个严重的V8漏洞 https://www.securityweek.com/google-patches-yet-another-serious-v8-vulnerability-chrome2、英国铁路网络Merseyrail遭勒索软件攻击 https://securityaffairs.co/wordpress/117312/malware/merseyrail-lockbit-ransomware.html3、研究发现云配置错误是云安全的主要风险 https://securityaffairs.co/wordpress/117305/security/cloud-misconfiguration-risks.html4、CISA和NIST联合发布有关供应链攻击的咨询报告 https://securityaffairs.co/wordpress/117286/hacking/cisa-nist-supply-chain-attacks.html5、RedLine Stealer恶意软件伪装成电报安装程序 https://blog.minerva-labs.com/redline-stealer-masquerades-as-telegram-installer6、DARPA展示了将零知识证明用于软件漏洞披露过程 https://www.scmagazine.com/home/security-news/vulnerabilities/darpa-is-creating-zero-knowledge-proofs-for-vulnerability-disclosure/7、新的WickrMe勒索软件针对SharePoint服务器以渗透企业网络 https://therecord.media/ransomware-gang-targets-microsoft-sharepoint-servers/8、F5 BIG-IP被发现容易受到Kerberos KDC欺骗漏洞的攻击 https://thehackernews.com/2021/04/f5-big-ip-found-vulnerable-to-kerberos.html9、FluBot Android银行恶意软件在欧洲迅速蔓延 https://thehackernews.com/2021/04/attention-flubot-android-banking.html10、安全团队在Linux内核发现信息泄露漏洞 https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html
网络安全日报 2021年04月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、FBI / DHS针对俄罗斯黑客入侵联合发布防御指南 https://www.securityweek.com/fbidhs-issue-guidance-network-defenders-mitigate-russian-gov-hacking2、美国空军采用零信任来改善和保护其飞行线路运营 https://www.securityweek.com/us-air-force-adopts-zero-trust-secure-flightline-operations3、Adobe发布开源异常检测工具“ OSAS” https://www.securityweek.com/adobe-releases-open-source-anomaly-detection-tool-osas4、Eaton产品中存在可允许黑客破坏电源的漏洞 https://www.securityweek.com/vulnerabilities-eaton-product-can-allow-hackers-disrupt-power-supply5、Apple修补了“ Shlayer”恶意软件利用的macOS安全绕过漏洞 https://www.securityweek.com/apple-patches-macos-security-bypass-vulnerability-exploited-shlayer-malware6、奥尔巴尼附近的Guilderland中央学区遭勒索软件攻击 https://securityaffairs.co/wordpress/117281/cyber-crime/school-district-albany-ransomware.html7、Microsoft Defender使用Intel TDT技术来对抗挖矿恶意软件 https://securityaffairs.co/wordpress/117272/security/microsoft-defender-tdt.html8、FBI与HIBP共享了Emotet恶意活动中的400万个电子邮件地址 https://securityaffairs.co/wordpress/117294/malware/emotet-hibp.html9、哥伦比亚特区大都会警察局遭勒索软件攻击 https://thehackernews.com/2021/04/hackers-threaten-to-leak-dc-police.html10、Nvidia披露GPU驱动和vGPU软件中存在严重漏洞 https://threatpost.com/nvidia-security-bugs-gpu-vgpu/165597/
网络安全日报 2021年04月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple iOS 14.5修补了50个安全漏洞 https://www.securityweek.com/apple-ios-145-patches-50-security-vulnerabilities2、一种新发现的NTLM中继攻击利用RPC协议漏洞提权 https://www.securityweek.com/ntlm-relay-attack-abuses-windows-rpc-protocol-vulnerability3、明尼苏达大学研究人员向Linux内核维护者道歉 https://thehackernews.com/2021/04/minnesota-university-apologizes-for.html4、32亿个密码泄露并包含150W与政府邮件地址相关的密码 https://thehackernews.com/2021/04/32-billion-leaked-passwords-contain-15.html5、2.5亿美国人敏感信息在黑客论坛泄露 https://www.hackread.com/hacker-dumps-household-records-of-americans/6、NFC论坛规范为NFC应用程序开发提供加密安全性 https://www.helpnetsecurity.com/2021/04/26/nfc-forum-specifications/7、美国防部通过BGP通告了数百万个IP地址 https://www.washingtonpost.com/technology/2021/04/24/pentagon-internet-address-mystery/8、勒索团伙利用7zip加密文件获利26万美元 https://www.bleepingcomputer.com/news/security/a-ransomware-gang-made-260-000-in-5-days-using-the-7zip-utility/9、法国香槟集团Laurent Perrier遭网络攻击 https://www.reuters.com/article/uk-france-champagne-laurentperrier/french-champagne-group-laurent-perrier-has-been-victim-of-cyber-attack-idUKKBN2CB0L510、采矿技术公司Gyrodata受勒索软件攻击-员工数据泄漏 https://portswigger.net/daily-swig/mining-technology-company-gyrodata-hit-by-ransomware-attack-employee-data-leaked
网络安全日报 2021年04月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客利用FileZen文件共享服务器漏洞窃取敏感数据 https://securityaffairs.co/wordpress/117208/hacking/soliton-filezen-file-sharing-servers.html2、ABUS Secvest家庭安防系统存在漏洞可被远程禁用 https://securityaffairs.co/wordpress/117190/hacking/10000-vulnerable-abus-secvest.html3、Valve修复Steam游戏平台中一个RCE漏洞 https://portswigger.net/daily-swig/valve-belatedly-fixes-steam-gaming-platform-rce-vulnerability4、研究人员在Kubernetes中发现恶意活动 https://unit42.paloaltonetworks.com/unsecured-kubernetes-instances/5、黑客创建虚假DirectX 12网站被用于分发恶意软件 https://www.bleepingcomputer.com/news/security/fake-microsoft-directx-12-site-pushes-crypto-stealing-malware/6、Avast研究人员揭示VB恶意代码隐藏数据常用手段 https://decoded.avast.io/davidzimmer/binary-data-hiding-in-vb6-executables/7、专家演示了利用吸尘器隐藏攻击设备的Evil Maid Attack https://securityaffairs.co/wordpress/117139/hacking/evil-maid-attack-vacuum-hack.html8、Darkside勒索软件团伙正加强其勒索策略以影响受害者股价 https://securityaffairs.co/wordpress/117130/malware/darkside-ransomware-stock-price.html9、黑客泄露大约2000万个BigBasket用户数据 https://www.bleepingcomputer.com/news/security/hacker-leaks-20-million-alleged-bigbasket-user-records-for-free/10、Emotet恶意软件已从全球所有受感染的计算机中自我卸载 https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/
网络安全日报 2021年04月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新型勒索软件Qlocker每天感染数百台QNAP NAS设备 https://securityaffairs.co/wordpress/117144/malware/qlocker-ransomware-infections.html2、新的Linux僵尸网络滥用IaC工具进行传播 https://securityaffairs.co/wordpress/117155/malware/linux-botnet-emerging-techniques.html3、Homebrew软件包管理器发现了严重的RCE漏洞 https://thehackernews.com/2021/04/critical-rce-bug-found-in-homebrew.html4、Prometei僵尸网络利用未修复的Exchange Server https://thehackernews.com/2021/04/prometei-botnet-exploiting-unpatched.html5、CocoaPods供应链攻击影响多达300W个移动应用 https://portswigger.net/daily-swig/cocoapods-rce-exploit-exposed-keys-to-repo-used-by-three-million-mobile-apps6、Passwordstate密码管理器遭受供应链攻击 https://www.csis.dk/newsroom-blog-overview/2021/moserpass-supply-chain/7、网络钓鱼活动冒充招聘公司分发恶意软件 https://www.bleepingcomputer.com/news/security/phishing-impersonates-global-recruitment-firm-to-push-malware/8、美国连锁零售商超Costco发布网络诈骗警告 https://www.infosecurity-magazine.com/news/costco-issues-scam-warning/9、基于Golang的新挖矿僵尸网络Sysrv针对流行的企业应用 https://therecord.media/sysrv-a-new-crypto-mining-botnet-is-silently-growing-in-the-shadows/10、工信部勒令腾讯小米华为等五家应用商店整改 https://mp.weixin.qq.com/s/1v_bJum4hcCgmU4oR75FSw
网络安全日报 2021年04月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、趋势科技反病毒软件漏洞在野利用 https://securityaffairs.co/wordpress/117105/hacking/trend-micro-flaw-cve-2020-24557.html 2、Cellebrite移动取证工具存在任意代码执行漏洞 https://securityaffairs.co/wordpress/117116/mobile-2/cellebrite-forensics-tool-flaw.html 3、研究人员发现感染数百万Android设备的僵尸网络Pareto https://securityaffairs.co/wordpress/117110/malware/pareto-botnet.html 4、网络犯罪者利用TG控制ToxicEye恶意软件 https://thehackernews.com/2021/04/cybercriminals-using-telegram-messenger.html 5、恶意软件FlixOnline冒充Netflix窃取WhatsApp对话数据 https://cyware.com/news/flixonline-poses-as-netflix-to-steal-whatsapp-conversations-data-a0ef3286 6、网络罪犯使用电报僵尸程序和Google表单自动进行网上诱骗 https://cyware.com/news/cybercriminals-use-telegram-bots-and-google-forms-for-automated-phishing-6bdaba1e 7、罗克韦尔工业交换机受思科软件中漏洞的影响 https://www.securityweek.com/rockwell-industrial-switches-affected-more-vulnerabilities-cisco-software 8、研究人员发现AirDrop存在泄露双方联系信息的风险 https://www.theregister.com/2021/04/22/airdrop_contact_leaks/ 9、Rapid7 宣布收购Velociraptor https://www.crn.com/news/security/rapid7-buys-velociraptor-to-attack-incident-response-market 10、安全团队发现针对彭博BNA用户的Fajan活动 https://blog.talosintelligence.com/2021/04/a-year-of-fajan-evolution-and-bloomberg.html