网络安全日报 2021年04月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SonicWall修复企业电子邮件安全设备3个0day漏洞 https://securityaffairs.co/wordpress/117075/hacking/sonicwall-es-zerodays.html 2、REvil勒索软件窃取了苹果公司产品图纸并索取赎金 https://securityaffairs.co/wordpress/117083/cyber-crime/revil-ransomware-apple-quanta.html 3、Oracle发布4月更新发布390个安全补丁 https://www.securityweek.com/oracle-delivers-390-security-fixes-april-2021-cpu 4、Chrome 发布紧急更新修复一个新的0day漏洞 https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack 5、超过75W用户从Google Play下载了新的计费欺诈应用 https://thehackernews.com/2021/04/over-750000-users-download-new-billing.html 6、在线约会应用Manhunt遭数据泄露 https://www.infosecurity-magazine.com/news/dating-service-suffers-data-breach/ 7、微软发布Windows 7、Server 2008本地提权漏洞部分补丁 https://www.bleepingcomputer.com/news/security/microsoft-partially-fixes-windows-7-server-2008-vulnerability/ 8、QNAP修复了NAS设备中的关键RCE漏洞 https://portswigger.net/daily-swig/qnap-fixes-critical-rce-vulnerabilities-in-nas-devices 9、Django Debug Toolbar 修复了SQL注入漏洞 https://portswigger.net/daily-swig/django-debug-toolbar-tripped-up-by-sql-injection-flaw 10、能源供应商Eversource泄露客户个人数据 https://www.bleepingcomputer.com/news/security/eversource-energy-data-breach-caused-by-unsecured-cloud-storage/
网络安全日报 2021年04月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现针对全球Facebook Messenger用户的大规模欺诈活动 https://securityaffairs.co/wordpress/117044/cyber-crime/facebook-messenger-scammers.html 2、Lazarus APT将恶意代码隐藏在BMP图像中以逃避检测 https://securityaffairs.co/wordpress/117035/apt/lazarus-apt-bmp-image.html 3、Cisco Talos 安全专家发现Cosori 智能空气炸锅RCE漏洞 https://securityaffairs.co/wordpress/117024/hacking/cosori-smart-air-fryer-flaws.html 4、Chromium 0day漏洞影响电脑版微信 https://securityaffairs.co/wordpress/117017/hacking/wechat-chromium-bug-attack.html 5、Firefox 88发布,修复多个漏洞 https://threatpost.com/mozilla-fixes-firefox-flaw/165501/ 6、美国汽车保险公司Geico泄露客户驾照号码 https://techcrunch.com/2021/04/19/geico-driver-license-numbers-scraped/ 7、专家发现Zebrocy针对哈萨克斯坦的攻击活动 https://labs.sentinelone.com/a-deep-dive-into-zebrocys-dropper-docs/ 8、攻击者伪造Spotify等网站传播恶意软件窃取支付卡信息 https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/ 9、Joker恶意软件影响50W华为安卓手机用户 https://cyware.com/news/joker-malware-pinches-500000-huawei-android-users-97a34741 10、Pulse Secure VPN零日漏洞影响政府机构 https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/
网络安全日报 2021年04月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WordPress 5.7.1修补了PHP 8中的XXE漏洞 https://www.securityweek.com/wordpress-571-patches-xxe-flaw-php-8 2、XCSSET恶意软件重新设计后可感染苹果M1芯片的Mac https://securityaffairs.co/wordpress/116983/malware/xcsset-malware-apple-m1.html 3、FireEye研究人员演示了接管智能电表的过程 https://securityaffairs.co/wordpress/117001/ics-scada/ot-network-hack-smart-meters.html 4、NitroRansomware勒索用户Discord Nitro礼物码 https://securityaffairs.co/wordpress/116975/malware/nitroransomware-discord-gift-code.html 5、软件公司Codecov遭供应链攻击 https://securityaffairs.co/wordpress/116967/hacking/codecov-supply-chain-attack.html 6、卡巴斯基报告称越来越多ICS系统面临勒索软件攻击 https://cyware.com/news/ics-computers-face-increased-ransomware-attacks-kaspersky-report-a50e9ab5 7、西班牙Phone House遭遇Babuk勒索软件攻击 https://www.suspectfile.com/phone-house-spagna-colpita-da-babuk-ransomware-3-milioni-gli-utenti-colpiti/ 8、清洁和餐饮公司Spotless遭数据泄露 https://www.stuff.co.nz/business/124859495/major-data-breach-at-cleaning-and-catering-company-spotless 9、黑客通过群聊传播WhatsApp Pink恶意软件 https://www.hackread.com/whatsapp-pink-malware-spreads-group-chats/ 10、100W印度Domino's Pizza用户信用卡详细信息在暗网出售 https://ciso.economictimes.indiatimes.com/news/dominos-india-hacked-credit-data-of-10l-users-on-sale-for-rs-4-cr/82137529
网络安全日报 2021年04月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、OpENer ENIP协议栈漏洞使工业设备易遭受攻击 https://www.securityweek.com/vulnerabilities-opener-stack-expose-industrial-devices-attacks 2、Juniper修复了一个远程劫持或破坏的严重漏洞 https://www.securityweek.com/critical-vulnerability-can-allow-attackers-hijack-or-disrupt-juniper-devices 3、多国谴责俄罗斯SolarWinds攻击行为 https://www.securityweek.com/more-countries-officially-blame-russia-solarwinds-attack 4、Google Project Zero更新2021年漏洞披露政策 https://www.securityweek.com/google-project-zero-announces-2021-updates-vulnerability-disclosure-policy 5、Monero Cryptocurrency活动利用Exchange漏洞 https://securityaffairs.co/wordpress/116955/cyber-crime/proxylogon-flaws-cryptocurrencyminer.html 6、FIN7小组的一名成员被判处10年徒刑 https://securityaffairs.co/wordpress/116945/cyber-crime/fin7-member-sentenced.html 7、SolarWinds攻击影响6个欧盟机构 https://securityaffairs.co/wordpress/116914/hacking/solarwinds-eu-agencies-hacked.html 8、研究人员发现Lazarus APT使用新的加密货币窃取工具 https://securityaffairs.co/wordpress/116874/apt/lazarus-btc-changer-js-sniffers.html 9、重大BGP泄漏导致4月16日全球数千个网络短暂中断 https://www.bleepingcomputer.com/news/security/major-bgp-leak-disrupts-thousands-of-networks-globally/ 10、流行的Codecov代码覆盖工具遭黑客修改 https://www.bleepingcomputer.com/news/security/popular-codecov-code-coverage-tool-hacked-to-steal-dev-credentials/
网络安全日报 2021年04月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Reddit启动公共漏洞赏金计划 https://www.securityweek.com/reddit-launches-public-bug-bounty-program 2、NVIDIA推出“ Morpheus”网络安全框架 https://www.securityweek.com/nvidia-unveils-morpheus-cybersecurity-framework 3、美国政府因SolarWinds黑客行为对俄罗斯进行制裁 https://securityaffairs.co/wordpress/116866/cyber-warfare-2/us-sanctions-russia-solarwinds.html 4、SAP Commerce修复了一个严重漏洞 https://securityaffairs.co/wordpress/116854/security/sap-commerce-critical-flaw.html 5、2016年交易所Bitfinex被盗的7.26亿美金比特币被转移到新账户 https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html 6、印度B2B包装平台Bizongo泄露643GB敏感数据 https://www.hackread.com/india-bizongo-supply-chain-exposed-data/ 7、超10万恶意谷歌网页投送SolarMarker RAT https://threatpost.com/google-sites-solarmarket-rat/165396/ 8、研究人员本周发布第二个Chrome 0day漏洞PoC https://www.bleepingcomputer.com/news/security/second-google-chrome-zero-day-exploit-dropped-on-twitter-this-week/ 9、风险和合规初创公司LogicGate确认数据泄露 https://techcrunch.com/2021/04/13/logicgate-risk-cloud-data-breach/ 10、研究人员发现影响容器引擎CRI-O和Podman的新漏洞 https://unit42.paloaltonetworks.com/cve-2021-20291/
网络安全日报 2021年04月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WhatsApp修复了两个远程利用漏洞 https://securityaffairs.co/wordpress/116833/hacking/whatsapp-flaws-remote-hack.html 2、Microsoft修复了NSA报告的2个关键Exchange漏洞 https://securityaffairs.co/wordpress/116767/uncategorized/exchange-server-flaws-nsa.html 3、安全研究人员发布QNAP NAS中RCE利用PoC https://securityaffairs.co/wordpress/116750/hacking/qnap-rce-exploit.html 4、NAME:WRECK漏洞影响上亿设备 https://securityaffairs.co/wordpress/116734/reports/namewreck-flaws.html 5、FBI清除了数百个组织的Exchange WebShell https://threatpost.com/fbi-proxylogon-web-shells/165400/ 6、研究人员成功使用JavaScript进行DDR4 Rowhammer攻击 https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html 7、谷歌修复Chrome浏览器中2个0day漏洞 https://thehackernews.com/2021/04/2-new-chrome-0-days-under-attack-update.html 8、勒索软件团伙利用旧VPN设备入侵Capcom https://www.bleepingcomputer.com/news/security/capcom-ransomware-gang-used-old-vpn-device-to-breach-the-network/ 9、Adobe修复Bridge和Photoshop中严重漏洞 https://threatpost.com/adobe-patches-critical-security-holes-bridge-photoshop/165371/ 10、FireEye:2020年追踪了650个新的威胁组织 https://securityaffairs.co/wordpress/116813/cyber-crime/fireeye-report-650-new-threat-groups.html
网络安全日报 2021年04月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、印度公司Upstox公司遭数据泄露250万用户数据 https://thehackernews.com/2021/04/indian-brokerage-firm-upstox-suffers.html 2、Windows、Safari、MS Exchange等在Pwn2Own 2021遭攻破 https://thehackernews.com/2021/04/windows-ubuntu-zoom-safari-ms-exchange.html 3、LinkedIn正式否认最近的数据泄露由安全漏洞引起 https://securityaffairs.co/wordpress/116689/data-breach/linkedin-not-data-breach.html 4、IcedID木马通过表单传播 https://threatpost.com/icedid-web-forms-google-urls/165347/ 5、英国NCSC发出针对Fortinet VPN漏洞的严重警报 https://www.zdnet.com/article/critical-security-alert-if-you-havent-patched-this-two-year-old-vpn-vulnerability-assume-your-network-is-compromised/ 6、Gino集团汽车经销商遭勒索软件攻击 https://www.databreaches.net/it-gino-group-car-dealership-notifies-customers-of-ransomware-attack/ 7、GravCMS修复严重的远程代码执行漏洞 https://portswigger.net/daily-swig/critical-gravcms-vulnerability-offers-lessons-for-software-developers 8、Zoom应用漏洞影响Windows和Mac版本 https://thehackernews.com/2021/04/windows-ubuntu-zoom-safari-ms-exchange.html 9、制药集团Pierre Fabre遭REvil勒索攻击被索取2500W美金赎金 https://www.bleepingcomputer.com/news/security/leading-cosmetics-group-pierre-fabre-hit-with-25-million-ransomware-attack/ 10、思科宣布将不在为某些小型企业路由器发布安全更新 https://securityaffairs.co/wordpress/116598/security/rce-eof-cisco-business-routers.html
网络安全日报 2021年04月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft开源“ CyberBattleSim”企业环境模拟器 https://www.securityweek.com/microsoft-open-sources-cyberbattlesim-enterprise-environment-simulator2、Pwn2Own 2021参与者赢得120万美元奖励 https://www.securityweek.com/pwn2own-2021-participants-earn-over-12-million-their-exploits3、纳坦兹核设施配电网遭网络攻击 https://securityaffairs.co/wordpress/116668/cyber-warfare-2/iran-accident-natanz-cyberattack.html4、130万Clubhouse用户个人数据在线泄露 https://securityaffairs.co/wordpress/116655/data-breach/clubhouse-data-leak.html5、Joker恶意软件感染了超过50W台华为设备 https://securityaffairs.co/wordpress/116643/malware/huawei-store-joker-malware.html6、黑客攻击第三方安卓应用市场APKPure分发恶意软件 https://securityaffairs.co/wordpress/116635/cyber-crime/apkpure-client-malware.html7、一男子涉嫌计划炸毁AWS数据中心被FBI逮捕 https://securityaffairs.co/wordpress/116612/cyber-crime/plot-bomb-attack-aws.html8、CISA发布了检测Microsoft 365威胁的工具 https://www.securityweek.com/cisa-releases-tool-detect-microsoft-365-compromise9、技术支持诈骗活动使用杀毒软件账单通知 https://www.bleepingcomputer.com/news/security/tech-support-scammers-lure-victims-with-fake-antivirus-billing-emails/10、美国肯塔基州失业保险网站遭受网络攻击 https://www.govinfosecurity.com/kentucky-unemployment-insurance-site-shuttered-after-attack-a-16376
网络安全日报 2021年04月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科修补SD-WAN vManage中的严重漏洞 https://www.securityweek.com/cisco-patches-critical-flaw-sd-wan-vmanage 2、开源学习平台Moodle漏洞可导致帐户被接管 https://securityaffairs.co/wordpress/116560/hacking/moodle-account-takeover-threats.html 3、暗网支付卡市场Swarmshop数据遭泄露 https://securityaffairs.co/wordpress/116549/cyber-crime/swarmshop-card-data-leak.html 4、PHP维护者确认在最近的攻击中用户数据库被入侵 https://securityaffairs.co/wordpress/116500/data-breach/php-sites-user-database-hacked.html 5、研究人员发现Azure Functions云容器逃逸提权漏洞 https://threatpost.com/azure-functions-privilege-escalation/165307/ 6、研究人员发现新的Lazarus恶意软件Vyveva https://www.welivesecurity.com/2021/04/08/are-you-afreight-dark-watch-out-vyveva-new-lazarus-backdoor/ 7、Chrome 阻止访问10080端口以防被NAT滑流攻击利用 https://www.bleepingcomputer.com/news/security/google-chrome-blocks-a-new-port-to-stop-nat-slipstreaming-attacks/ 8、CISA发布用于审查Office 365攻击活动的工具 https://www.bleepingcomputer.com/news/security/cisa-releases-tool-to-review-microsoft-365-post-compromise-activity/ 9、Win 10,Chrome和Zoom均在Pwn2Own中被攻破 https://securityaffairs.co/wordpress/116542/hacking/pwn2own-2021-2-day-2.html 10、Google安全研究员批量BleedingTooth攻击详情 https://portswigger.net/daily-swig/bleedingtooth-google-drops-full-details-of-zero-click-linux-bluetooth-bug-chain-leading-to-rce
网络安全日报 2021年04月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、虚假Netflix App恶意软件通过WhatsApp传播 https://threatpost.com/netflix-app-google-play-malware-whatsapp/165288/ 2、德国Gigaset手机上发现预安装的恶意软件 https://thehackernews.com/2021/04/pre-installed-malware-dropper-found-on.html 3、攻击者利用Fortinet VPN 中的漏洞部署Cring勒索软件 https://securityaffairs.co/wordpress/116480/cyber-crime/cring-ransomware-fortinet-vpn-flaw.html 4、攻击者使用TG机器人和Google Forms进行自动化网络钓鱼 https://securityaffairs.co/wordpress/116459/cyber-crime/telegram-bots-google-forms-phishing.html 5、欧盟委员会和其他机构遭受重大网络攻击 https://securityaffairs.co/wordpress/116441/hacking/european-commission-institutions-cyberattack.html 6、Pwn2Own 2021首天白帽黑客获得超过100W美金奖励 https://securityaffairs.co/wordpress/116469/hacking/pwn2own-2021-d1.html 7、Google修补Android中的关键代码执行漏洞 https://www.securityweek.com/google-patches-critical-code-execution-vulnerability-android 8、Accellion Health数据泄露影响了超过100万人 https://www.govinfosecurity.com/more-accellion-health-data-breaches-revealed-a-16350 9、Aurora运动:使用多个RAT攻击阿塞拜疆 https://blog.malwarebytes.com/threat-analysis/2021/04/aurora-campaign-attacking-azerbaijan-using-multiple-rats/ 10、勒索软件攻击了爱尔兰国立大学和都柏林理工大学 https://www.bleepingcomputer.com/news/security/ransomware-hits-tu-dublin-and-national-college-of-ireland/