网络安全日报 2021年04月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、攻击者利用SAP应用漏洞攻击企业 https://threatpost.com/sap-bugs-cyberattack-compromise/165265/ 2、美国国防部启动针对承包商网络的Vuln披露计划 https://www.securityweek.com/us-dod-launches-vuln-disclosure-program-contractor-networks 3、APT小组在鱼叉式钓鱼活动中使用语音更改软件 https://www.securityweek.com/apt-group-using-voice-changing-software-spear-phishing-campaign 4、Umbraco CMS中发现特权提升漏洞 https://securityaffairs.co/wordpress/116381/security/privilege-escalation-umbraco-cms.html 5、罗克韦尔修复了FactoryTalk AssetCentre中的严重漏洞 https://securityaffairs.co/wordpress/116391/ics-scada/rockwell-factorytalk-assetcentre-flaws.html 6、5亿LinkedIn用户数据被泄露 https://cybernews.com/news/stolen-data-of-500-million-linkedin-users-being-sold-online-2-million-leaked-as-proof-2/ 7、新的Janeleiro银行木马针对巴西公司 https://www.zdnet.com/article/meet-janeleiro-a-new-banking-trojan-striking-corporate-targets/#ftag=RSSbaffb68 8、数百名OnlyFans创作者的私人内容在线泄露 https://www.bleepingcomputer.com/news/security/adult-content-from-hundreds-of-onlyfans-creators-leaked-online/ 9、Apple Mail零点击漏洞可导致邮件被窃取和账户劫持 https://threatpost.com/apple-mail-zero-click-security-vulnerability/165238/ 10、黑客从ForceDAO窃取36.7万美元的加密货币 https://www.infosecurity-magazine.com/news/engineering-oversight-costs/
网络安全日报 2021年04月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LinkedIn鱼叉式网络钓鱼活动以求职者为目标 https://threatpost.com/linkedin-spear-phishing-job-hunters/165240/ 2、用户现可查询是否在Facebook数据泄漏中 https://securityaffairs.co/wordpress/116371/data-breach/facebook-leak-check.html 3、卡巴斯基研究发现2020年下半年 33.4%的ICS计算机受到网络攻击 https://securityaffairs.co/wordpress/116360/ics-scada/ics-statistics-data.html 4、恶意软件攻击了车辆检查服务提供商Applus https://securityaffairs.co/wordpress/116338/malware/malware-attack-on-applus.html 5、Clop勒索软件盗取并泄漏多所美国大学数据 https://securityaffairs.co/wordpress/116325/uncategorized/clop-ransomware-us-universities.html 6、FactoryTalk产品存在九个高严重性漏洞 https://www.securityweek.com/nine-critical-flaws-factorytalk-product-pose-serious-risk-industrial-firms 7、Capital One银行通知更多客户数据泄露 https://securityaffairs.co/wordpress/116309/data-breach/capital-one-ssns.html 8、Phobos勒索软件变种使用新无文件技术 https://blog.morphisec.com/the-fair-upgrade-variant-of-phobos-ransomware 9、医疗机构TriHealth确认第三方数据泄露 https://www.trihealth.com/dailyhealthwire/news/trihealth-confirms-third-party-data-breach 10、研究人员发现税收主题的网络钓鱼活动 https://www.fortinet.com/blog/threat-research/did-you-file-your-taxes-yet
网络安全日报 2021年04月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、RCE漏洞影响成千上万个QNAP SOHO NAS设备 https://www.securityweek.com/unpatched-rce-flaws-affect-tens-thousands-qnap-soho-nas-devices 2、堪萨斯州男子被控入侵公共供水系统 https://www.securityweek.com/kansas-man-charged-tampering-public-water-system 3、Dark Web Portal的管理员承认洗钱罪 https://www.securityweek.com/administrator-dark-web-portal-pleads-guilty-money-laundering 4、VMware修复了Carbon Black Cloud Workload中的严重漏洞 https://securityaffairs.co/wordpress/116233/security/vmware-carbon-black-cloud-flaw.html 5、Ubiquiti安全漏洞影响被严重低估 https://securityaffairs.co/wordpress/116196/data-breach/ubiquiti-security-breach.html 6、与朝鲜有关的黑客组织再次发起针对安全研究人员的社工活动 https://securityaffairs.co/wordpress/116183/apt/north-korea-hackers-target-researchers.html 7、攻击者利用Windows BITS启动后门实现持久性 https://thehackernews.com/2021/04/hackers-using-windows-os-feature-to.html 8、网络犯罪分子针对印尼银行客户进行大规模欺诈活动 https://securityaffairs.co/wordpress/116173/cyber-crime/5-star-customer-service-fraudsters-launch-massive-campaign-against-indonesias-major-banks-on-twitter.html 9、TA453对美国和以色列医学研究人员发起钓鱼攻击 https://www.proofpoint.com/us/blog/threat-insight/badblood-ta453-targets-us-and-israeli-medical-research-personnel-credential 10、BazarCall恶意软件使用恶意呼叫中心感染受害者 https://www.bleepingcomputer.com/news/security/bazarcall-malware-uses-malicious-call-centers-to-infect-victims/
网络安全日报 2021年04月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Citrix修补Hypervisor中的DoS漏洞 https://www.securityweek.com/citrix-patches-dos-vulnerabilities-hypervisor 2、朝鲜APT组织冒充渗透测试公司 https://www.securityweek.com/north-korean-gov-hackers-back-fake-pen-test-company 3、IETF弃用TLS 1.0和TLS 1.1,更新为最新版本 https://securityaffairs.co/wordpress/116151/security/ietf-deprecates-tls-1-0-tls-1-1.html 4、印度MIDC的服务器遭SYNack勒索软件攻击 https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html 5、美国国税局警告钓鱼攻击冒充IRS针对教育机构 https://www.bleepingcomputer.com/news/security/scammers-target-universities-in-ongoing-irs-phishing-attacks/ 6、新加坡家具零售连锁店Vhive遭到勒索软件攻击 https://www.databreaches.net/sg-vhive-alerts-consumers-to-cyberattack/ 7、数以百计的Fleeceware应用程序骗取了数百万美金 https://cyware.com/news/hundreds-of-fleeceware-apps-earning-millions-of-dollars-dead669b 8、犯罪分子将照片转为视频欺骗国家税务平台身份验证系统 https://www.theregister.com/2021/03/31/tax_scammers_fool_ai_facial_recognition 9、攻击者以大学为目标进行持续的IRS网络钓鱼攻击 https://www.bleepingcomputer.com/news/security/scammers-target-universities-in-ongoing-irs-phishing-attacks/ 10、卡巴斯基研究发现支付勒索软件赎金的受害者1/5无法恢复数据 https://portswigger.net/daily-swig/ransomware-nearly-a-fifth-of-victims-who-pay-off-extortionists-fail-to-get-their-data-back
网络安全日报 2021年03月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、OAuth Apps 正在成为厂商以及用户的新安全攻击面 https://www.proofpoint.com/us/blog/cloud-security/oauth-abuse-think-solarwindssolorigate-campaign-focus-cloud-applications 2、网络犯罪分子从壳牌和多所大学窃取数据 https://www.securityweek.com/cybercriminals-publish-data-allegedly-stolen-shell-multiple-universities 3、VMware解决了vRealize Operations中的SSRF漏洞 https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html 4、WP插件Ivory Search 中的XSS漏洞影响了6万多个站点 https://securityaffairs.co/wordpress/116140/hacking/reflected-xss-ivory-search-wp-plugin.html 5、30个恶意挖矿Docker镜像被下载2000万次 https://securityaffairs.co/wordpress/116111/cyber-crime/docker-cryptojacking-attacks.html 6、报告称SolarWinds攻击访问了DHS的电子邮件 https://threatpost.com/solarwinds-attackers-dhs-emails/165110/ 7、印度移动支付服务MobiKwik遭重大数据泄露影响350W用户 https://thehackernews.com/2021/03/mobikwik-suffers-major-breach-kyc-data.html 8、安全服务提供商Akamai观察到了迄今为止最大的DDoS勒索攻击 https://www.securityweek.com/akamai-sees-largest-ddos-extortion-attack-known-date 9、研究人员发现SAML XML注入漏洞 https://research.nccgroup.com/2021/03/29/saml-xml-injection/ 10、Clop勒索软件团伙发布马里兰大学和加州大学数据 https://www.zdnet.com/article/ransomware-group-targets-universities-of-maryland-california-in-new-data-leaks/
网络安全日报 2021年03月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客论坛出售8.2 TB MobiKwik用户敏感数据 https://www.technadu.com/8-2-tb-sensitive-data-of-mobikwik-users-sold-on-hacker-forum/259858/ 2、PHP的Git服务器遭到黑客攻击代码库被篡改 https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/ 3、澳大利亚第九频道的IT网络遭到黑客攻击 https://securityaffairs.co/wordpress/116053/breaking-news/channel-nine-cyber-attack.html 4、研究人员批量 npm netmask 库存在严重漏洞 https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/ 5、巴西一家保险公司泄露了3600万客户的数据 https://www.defcon-lab.org/data-breach-seguradora/ 6、研究人员披露Linux新漏洞可绕过Spectre攻击缓解措施 https://thehackernews.com/2021/03/new-bugs-could-let-hackers-bypass.html 7、Ziggy勒索软件管理员宣布将退还受害者支付的赎金 https://securityaffairs.co/wordpress/116079/malware/ziggy-ransomware-refunds-victims.html 8、Ovarro的TBox远程终端单元(RTU)被发现多个严重漏洞 https://thehackernews.com/2021/03/flaws-in-ovarro-tbox-rtus-could-open.html 9、200 Networks 公司呼叫中心遭重大数据泄露 https://www.hackread.com/call-center-provider-experiences-data-leak 10、研究人员发现新的基于DCCP请求的DDoS攻击向量 https://cyware.com/news/new-dccp-request-based-ddos-attack-vector-emerges-382cf003
网络安全日报 2021年03月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple发布紧急安全更新修复严重零日漏洞 https://www.securityweek.com/apple-patches-under-attack-ios-zero-day 2、欧盟与美国达成隐私数据交换协议 https://www.securityweek.com/eu-us-make-new-attempt-data-privacy-deal 3、卡巴斯基报告称针对发达国家的ICS设备勒索攻击呈上升趋势 https://www.securityweek.com/kaspersky-sees-rise-ransomware-attacks-ics-devices-developed-countries 4、官方“ Facebook for WordPress”插件中发现严重漏洞 https://www.securityweek.com/severe-flaws-official-facebook-wordpress-plugin 5、Weintek HMI 存在远程攻击漏洞 https://www.securityweek.com/vulnerabilities-can-allow-attackers-remotely-gain-control-weintek-hmis 6、Hades勒索软件团伙针对美国的大型组织 https://securityaffairs.co/wordpress/115994/cyber-crime/hades-ransomware.html 7、QNAP警告正在针对NAS设备的暴力破解活动 https://www.bleepingcomputer.com/news/security/qnap-warns-of-ongoing-brute-force-attacks-against-nas-devices/ 8、研究人员发现英特尔处理器新的严重漏洞 https://www.ehackingnews.com/2021/03/black-code-two-critical-vulnerabilities.html 9、美国军事承包商PDI集团遭勒索软件攻击数据泄露 https://therecord.media/ransomware-gang-leaks-data-from-us-military-contractor-the-pdi-group/ 10、专家发现新的复杂Android间谍软件冒充系统更新 https://securityaffairs.co/wordpress/116016/malware/android-spyware-system-update.html
网络安全日报 2021年03月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Solarwinds 发布更新修复新的严重漏洞 https://www.securityweek.com/new-code-execution-flaws-solarwinds-orion-platform 2、OpenSSL 发布1.1.1k修补了两个高危漏洞 https://www.securityweek.com/openssl-111k-patches-two-high-severity-vulnerabilities 3、黑客开始利用Thrive Theme WordPress插件中的最新漏洞 https://www.securityweek.com/hackers-start-exploiting-recent-vulnerabilities-thrive-theme-wordpress-plugins 4、Mamba Ransomware利用DiskCryptor进行加密 https://www.securityweek.com/mamba-ransomware-leverages-diskcryptor-encryption-fbi-warns 5、3000万美国人受Astoria公司数据泄露的影响 https://securityaffairs.co/wordpress/115934/breaking-news/astoria-company-data-leak.html 6、Microsoft修复Windows PSExec特权提升漏洞 https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-psexec-privilege-elevation-vulnerability 7、英国服装零售商Fat Face遭黑客入侵数据泄露 https://www.inforisktoday.com/british-clothing-retailer-fat-face-discloses-data-breach-a-16249 8、安全机构在互联网上的Exchange中检测到数十万个Webshell https://searchsecurity.techtarget.com/news/252498373/Nearly-100000-web-shells-detected-on-Exchange-servers 9、XcodeSpy 通过Xcode项目传播恶意软件 https://cyware.com/news/trojanized-xcode-project-spreads-macos-malware-1a2f1982 10、Slack Connect DM新功能存在安全隐患 https://www.securityweek.com/new-slack-connect-dm-feature-raises-security-concerns
网络安全日报 2021年03月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、航空租赁公司Solairus Aviation遭受数据泄露 https://www.securityweek.com/air-charter-firm-solairus-aviation-suffers-data-breach 2、TBox RTU中漏洞可能会使工业组织遭受远程攻击 https://www.securityweek.com/vulnerabilities-tbox-rtus-can-expose-industrial-organizations-remote-attacks 3、霍尼韦尔表示IT系统遭恶意软件破坏 https://www.securityweek.com/honeywell-says-malware-disrupted-it-systems 4、思科修复了Cisco Jabber客户端软件中的严重漏洞 https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html 5、外汇经纪商FBS泄露数百万用户详细数据 https://securityaffairs.co/wordpress/115925/data-breach/fbs-data-breach.html 6、选举前,黑客泄露了数百万以色列选民的详细信息 https://securityaffairs.co/wordpress/115918/hacking/israeli-voters-leak.html 7、微软透露全球92% Exchange已得到修补或缓解 https://securityaffairs.co/wordpress/115896/security/microsoft-exchange-patched.html 8、TrickBot利用网络钓鱼加速传播 https://cyware.com/news/trickbot-spreading-actively-launches-phishing-schemes-ba2f050b 9、服务器制造商Stratus Technologies遭勒索软件攻击 https://www.bleepingcomputer.com/news/security/high-availability-server-maker-stratus-hit-by-ransomware/ 10、美国保险公司CNA遭网络攻击导致网络中断 https://www.securityweek.com/insurer-cna-says-cyberattack-caused-network-disruption
网络安全日报 2021年03月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、IDA 7.6 版本发布原生支持 Apple M1 芯片 https://www.hex-rays.com/blog/ida-7-6-released/ 2、Purple Fox恶意软件通过Windows SMB进行蠕虫传播 https://www.securityweek.com/purple-fox-malware-squirms-worm-windows 3、研究人员将新的APT组织SilverFish与SolarWinds攻击关联 https://www.securityweek.com/researchers-dive-operations-silverfish-cyber-espionage-group 4、物联网公司Sierra Wireless 遭勒索软件攻击导致停产 https://www.securityweek.com/sierra-wireless-says-ransomware-disrupted-production-manufacturing-facilities 5、Google警告Android用户已修补的漏洞正被利用 https://www.securityweek.com/recently-patched-android-vulnerability-exploited-attacks 6、MangaDex漫画网站遭网络攻击后暂时关闭 https://www.bleepingcomputer.com/news/security/mangadex-manga-site-temporarily-shut-down-after-cyberattack/ 7、Black Kingdom勒索软件针对微软Exchange服务器 https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-now-targeted-by-black-kingdom-ransomware/ 8、Flagstar银行通知客户遭勒索软件后导致SSN丢失 https://www.vice.com/en/article/xgznxw/ransomwared-bank-tells-customers-it-lost-their-ssns 9、Facebook表示在2020年10月至12月关闭了13亿虚假帐号 https://telecom.economictimes.indiatimes.com/news/facebook-says-took-down-1-3-billion-fake-accounts-in-oct-dec/81633136 10、网络犯罪分子在暗网上提供伪造的COVID-19测试结果和疫苗接种证书 https://blog.checkpoint.com/2021/03/22/a-passport-to-freedom-fake-covid-19-test-results-and-vaccination-certificates-offered-on-darknet-and-hacking-forums