网络安全日报 2021年03月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Adobe紧急更新修复了关键的ColdFusion漏洞 https://threatpost.com/adobe-critical-coldfusion-flaw-update/164946/2、CISA警告GE电源管理设备中的安全漏洞 https://threatpost.com/cisa-security-flaws-ge-power-management/164961/3、流行的Netop远程教学监控软件易受黑客攻击 https://thehackernews.com/2021/03/popular-netops-remote-learning-software.html4、Apache OFBiz ERP软件中发现严重的RCE漏洞 https://thehackernews.com/2021/03/critical-rce-vulnerability-found-in.html5、壳牌称在2020年12月网络攻击中公司数据被盗 https://www.securityweek.com/shell-says-personal-corporate-data-stolen-accellion-security-incident6、恶意软件CopperStealer针对亚马逊、苹果、Google等服务 https://cyware.com/news/a-new-account-stealing-malware-targets-global-tech-giants-e2995d5a7、攻击者发送《生化危机8》为诱饵的钓鱼邮件 https://blog.malwarebytes.com/scams/2021/03/resident-evil-8-just-the-latest-game-plagued-by-fake-demos-and-early-access-scams/8、黑客利用11个零日攻击Windows、iOS和Android用户 https://www.bleepingcomputer.com/news/security/hacking-group-used-11-zero-days-to-attack-windows-ios-android-users/9、DDoS-for-hire滥用DTLS服务器放大DDoS攻击 https://www.bleepingcomputer.com/news/security/ddos-booters-now-abuse-dtls-servers-to-amplify-attacks/10、Firefox将调整来源网址策略以增强用户隐私 https://www.zdnet.com/article/mozilla-firefox-tweaks-referrer-policy-to-shore-up-user-privacy/
网络安全日报 2021年03月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Zoom 存在敏感数据泄露漏洞 https://threatpost.com/zoom-glitch-leaks-data/164876/ 2、攻击者利用F5 BIG-IP 最近的高危漏洞进行攻击 https://threatpost.com/critical-f5-big-ip-flaw-now-under-active-attack/164940/ 3、CISA发布检测SolarWinds恶意活动的工具 https://securityaffairs.co/wordpress/115821/security/cisa-chirp-solarwinds-tool.html 4、Acer遭REvil勒索软件攻击并索取5000万美元赎金 https://securityaffairs.co/wordpress/115777/cyber-crime/acer-revil-ransomware.html 5、Defender现在可以保护服务器免受Exchange漏洞攻击 https://securityaffairs.co/wordpress/115801/hacking/microsoft-defender-microsoft-exchange.html 6、研究人员发现恶意加密程序OnionCrypter https://decoded.avast.io/jakubkaloc/onion-crypter/ 7、波兰国家网站遭黑客入侵被用来传播虚假信息 https://www.securityweek.com/polish-state-websites-hacked-and-used-spread-false-info 8、虚假PlayStation 5赠品网站窃取用户详细信息 https://www.technadu.com/dont-be-fooled-fake-playstation-5-giveaways/256837/ 9、虚假的Android Clubhouse应用从458个服务中窃取凭证 https://threatpost.com/android-clubhouse-app-malware/164915/ 10、新的Office 365网络钓鱼攻击针对保险和金融行业高管 https://threatpost.com/office-365-phishing-attack-financial-execs/164925/
网络安全日报 2021年03月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的XcodeSpy Mac恶意软件针对软件开发人员 https://www.securityweek.com/new-xcodespy-mac-malware-targets-software-developers 2、遭拆除5个月后,TrickBot仍然活跃 https://www.securityweek.com/five-months-after-takedown-attempt-cisa-and-fbi-warn-ongoing-trickbot-attacks 3、研究人员发现TikTok Android应用RCE漏洞 https://securityaffairs.co/wordpress/115714/hacking/rce-tiktok-android-app.html 4、研究人员发现在Twitter图片中隐藏zip、mp3文件的方法 https://threatpost.com/researcher-hides-files-in-png-twitter/164881/ 5、MyBB报告了严重的RCE漏洞 https://thehackernews.com/2021/03/critical-rce-flaw-reported-in-mybb.html 6、Google透露Chrome及其应用收集哪些个人数据 https://thehackernews.com/2021/03/google-to-reveals-what-personal-data.html 7、Mekotio Tojan使用AutoHotKey逃避检测和窃取用户信息 https://cyware.com/news/mekotio-tojan-is-using-autohotkey-to-avoid-detection-d9d237d4 8、WordPress Tutor LMS 插件存在多个SQL注入高危漏洞 https://threatpost.com/tutor-lms-wordpress-security-holes/164868/ 9、钓鱼邮件冒充美国国税局分发Dridex银行木马 https://threatpost.com/covid-19-relief-checks-dridex-malware/164853/ 10、Descartes Aljex软件公司泄露了103 GB的数据 https://www.hackread.com/shipping-management-software-firm-data-online/
网络安全日报 2021年03月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新Mirai Variant利用数十个漏洞来劫持IoT设备 https://www.securityweek.com/new-mirai-variant-leverages-10-vulnerabilities-hijack-iot-devices 2、Mimecast称SolarWinds黑客窃取了源代码 https://www.securityweek.com/mimecast-says-solarwinds-hackers-stole-source-code 3、思科修复小型企业路由器安全漏洞 https://threatpost.com/cisco-security-hole-small-business-routers/164859/ 4、DuckDuckGo扩展漏洞使Edge用户容易被监听 https://portswigger.net/daily-swig/duckduckgo-browser-extension-vulnerability-leaves-edge-users-open-to-potential-cyber-snooping 5、英国伯明翰南方城市学院遭到勒索软件攻击 https://feweek.co.uk/2021/03/15/college-group-closes-all-campuses-for-a-week-following-major-cyber-attack/ 6、Twitter账户劫持攻击策划者被判入狱 https://thehill.com/policy/cybersecurity/543515-twitter-hacker-to-serve-three-years-in-prison 7、荷兰当局表示至少1200台服务器受Exchange攻击影响 https://www.reuters.com/article/us-netherland-cyber-microsoft/microsoft-hack-fallout-substantial-for-dutch-servers-watchdog-says-idUSKBN2B82K4 8、支付卡窃取程序将获取的数据隐藏在JPG文件中 https://securityaffairs.co/wordpress/115655/hacking/magecart-credit-card-jpg.html 9、Twitter启用2FA支持多个安全密钥保护账户安全 https://www.securityweek.com/twitter-users-can-now-secure-accounts-multiple-security-keys 10、研究发现大多数安全机构发布的PDF文件包含敏感信息 https://www.securityweek.com/research-security-agencies-expose-information-improperly-sanitized-pdfs
网络安全日报 2021年03月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、因内容安全问题俄罗斯计划在一个月之内封禁Twitter https://www.securityweek.com/russia-threatens-block-twitter-month 2、研究人员发现一系列利用Mirai新变体的攻击 https://securityaffairs.co/wordpress/115664/uncategorized/mirai-botnet-variant-2.html 3、Microsoft回滚更新以修复365和其他服务无法访问故障 https://www.reuters.com/article/us-microsoft-teams-outages/microsoft-rolls-back-update-to-fix-access-issues-for-thousands-idUSKBN2B72MJ 4、NFT数字艺术平台造账户接管和盗取攻击 https://www.cyberscoop.com/nft-nifty-gateway-hackers-digital-art-theft/ 5、FBI警告称针对教育机构的Pysa勒索软件活动不断增加 https://www.bleepingcomputer.com/news/security/fbi-warns-of-escalating-pysa-ransomware-attacks-on-education-orgs 6、研究人员发现与Taurus窃取程序有关的新活动 https://blog.minerva-labs.com/taurus-stealers-evolution 7、钓鱼网站利用JS检查是否在虚拟机中以逃避检测 https://www.bleepingcomputer.com/news/security/phishing-sites-now-detect-virtual-machines-to-bypass-detection/ 8、Guns.com的完整数据库及其源代码遭黑客转储 https://www.hackread.com/hacker-dumps-guns-com-database-customers-admin-data/ 9、Blender官方网站遭到黑客攻击关闭了部分内容 https://www.bleepingcomputer.com/news/security/blender-website-in-maintenance-mode-after-hacking-attempt/ 10、加拿大税务局因安全问题锁定了80多万纳税人的账号 https://www.cbc.ca/news/politics/cra-accounts-locked-1.5947714
网络安全日报 2021年03月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft推出针对Exchange攻击的一键缓解工具 https://www.securityweek.com/microsoft-ships-one-click-mitigation-tool-exchange-attacks 2、AMD为新的EPYC 7003系列处理器增加了新的安全功能 https://www.securityweek.com/amd-unveils-new-security-features-launch-epyc-7003-series-processors 3、美国司法部起诉Sky Global首席执行官协助犯罪分子 https://securityaffairs.co/wordpress/115629/cyber-crime/sky-global-ceo-indicted.html 4、黑客利用Exchange 漏洞攻击了32家印度公司 https://ciso.economictimes.indiatimes.com/news/hackers-hit-32-indian-firms-via-microsoft-email-servers-ld/81510202 5、以色列K.L.S汽车信贷公司遭黑客攻击数据泄露 https://www.jpost.com/jpost-tech/israeli-car-financing-company-hacked-private-information-held-for-ransom-661865 6、研究人员发布了微软Exchange漏洞的新PoC https://www.bleepingcomputer.com/news/security/new-poc-for-microsoft-exchange-bugs-puts-attacks-in-reach-of-anyone/ 7、PHP信用卡窃取程序将信息保存在JPG文件中 https://blog.sucuri.net/2021/03/magento-2-php-credit-card-skimmer-saves-to-jpg.html 8、RTM银行木马和Quoter勒索软件合作 https://cyware.com/news/rtm-and-quoter-ransomware-a-deadly-combo-2b1072f6 9、超8W台Exchange 仍受到漏洞的影响 https://www.securityweek.com/over-80000-exchange-servers-still-affected-actively-exploited-vulnerabilities 10、Fastway Couriers快递公司泄露用户联系方式 https://www.irishtimes.com/news/ireland/irish-news/cyberattack-on-fastway-couriers-compromises-contact-details-1.4508084
网络安全日报 2021年03月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Netgear 发布安全补丁修复JGS516PE交换机高危漏洞 https://securityaffairs.co/wordpress/115586/hacking/netgear-soho-flaws.html 2、谷歌发布适用于Chrome浏览器的Spectre PoC https://securityaffairs.co/wordpress/115573/hacking/google-chrome-spectre-poc.html 3、研究人员在Linux内核模块中发现了三个有15年历史的漏洞 https://securityaffairs.co/wordpress/115565/security/linux-kernel-flaws.html 4、研究人员发现适用M1芯片的XCSSET mac恶意软件新变种 https://securityaffairs.co/wordpress/115552/hacking/xcsset-mac-malware-m1-chips.html 5、WeLeakInfo 上万用户详细信息造泄露 https://securityaffairs.co/wordpress/115544/data-breach/weleakinfo-leaked-data.html 6、Chrome更新修复已被利用的零日漏洞 https://thehackernews.com/2021/03/another-google-chrome-0-day-bug-found.html 7、研究人员通过暴露的git和env文件入侵印度政府网站 https://www.bleepingcomputer.com/news/security/researchers-hacked-indian-govt-sites-via-exposed-git-and-env-files/ 8、Woodcreek供应商服务公司泄露约20万患者信息 https://www.securityweek.com/breach-exposes-data-200k-health-system-staff-patients 9、骗子通过推特广告宣传虚假加密货币赠品网站 https://www.bleepingcomputer.com/news/security/scammers-promote-fake-cryptocurrency-giveaways-via-twitter-ads/ 10、Lemon_Duck挖矿僵尸网络利用Exchange漏洞 https://www.bleepingcomputer.com/news/security/microsoft-exchange-exploits-now-used-by-cryptomining-malware/
网络安全日报 2021年03月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、施耐德智能电表中发现严重漏洞 https://www.securityweek.com/serious-vulnerabilities-found-schneider-electric-power-meters 2、Facebook暂停到香港海底数据光缆项目 https://www.securityweek.com/facebook-halts-project-undersea-data-cable-hong-kong 3、研究人员发布针对Exchange漏洞的PoC https://securityaffairs.co/wordpress/115513/hacking/microsoft-exchange-exploit-code.html 4、数十个APT组织利用Exchange漏洞进行攻击 https://threatpost.com/microsoft-exchange-servers-apt-attack/164695/ 5、Lazarus Group利用Mata 框架部署TFlower勒索软件 https://cyware.com/news/lazarus-group-using-mata-framework-to-deliver-tflower-ransomware-17319d23 6、WordPress插件中严重漏洞可导致网站被接管 https://securityaffairs.co/wordpress/115451/hacking/the-plus-addons-for-elementor-wordpress-flaw.html 7、西班牙政府劳工部办公室遭Ryuk勒索软件攻击 https://www.bleepingcomputer.com/news/security/ryuk-ransomware-hits-700-spanish-government-labor-agency-offices/ 8、英特尔和微软与DARPA合作研发DPRIVE计划 https://www.helpnetsecurity.com/2021/03/09/intel-darpa-dprive/ 9、恶意NPM包利用依赖关系混淆漏洞针对Amazon、Zillow等应用 https://cyware.com/news/dependency-confusion-exploit-being-used-to-create-more-copycat-packages-09f4133d 10、CISA将在4月接管gov顶级域名管理权 https://www.govinfosecurity.com/cisa-will-manage-gov-domain-in-effort-to-enhance-security-a-16159
网络安全日报 2021年03月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、F5修补了Big-IP Suite中的四个高危漏洞 https://www.securityweek.com/f5-patches-four-critical-bugs-big-ip-suite 2、研究人员证明和测试了针对苹果M1芯片的侧信道攻击 https://www.securityweek.com/researchers-show-first-side-channel-attack-against-apple-m1-chips 3、白帽黑客获取了包括特斯拉、银行、学校等超过15W个摄像头权限 https://securityaffairs.co/wordpress/115466/hacking/surveillance-cameras-hacked.html 4、欧洲最大的托管服务提供商OVH一座数据中心遭大火摧毁 https://securityaffairs.co/wordpress/115457/breaking-news/ovh-data-centers-fire.html 5、基于Nim的恶意软件加载器通过鱼叉钓鱼邮件传播 https://threatpost.com/nim-based-malware-loader-spreads-via-spear-phishing-emails/164643/ 6、 Adobe发布更新修复了产品中任意代码执行漏洞 https://threatpost.com/adobe-critical-flaws-windows/164611/ 7、Clast82恶意软件通过谷歌Play商店分发间谍木马 https://thehackernews.com/2021/03/9-android-apps-on-google-play-caught.html 8、西门子修复了第三方组件中的漏洞 https://www.securityweek.com/siemens-releases-several-advisories-vulnerabilities-third-party-components 9、苹果发布安全补丁程序修复了远程代码执行漏洞 https://securityaffairs.co/wordpress/115423/hacking/apple-cve-2021-1844-rce.html 10、SAP修复了MII,NetWeaver产品中关键漏洞 https://www.securityweek.com/sap-patches-critical-flaws-mii-netweaver-products
网络安全日报 2021年03月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft周二发布安全更新修复了89个漏洞 https://www.securityweek.com/microsoft-ships-massive-security-patch-bundle 2、苹果发布更新修复WebKit中远程代码执行漏洞 https://www.securityweek.com/apple-patches-remote-code-execution-bug-webkit 3、GitHub通知用户严重的身份验证漏洞 https://www.securityweek.com/github-informs-users-potentially-serious-authentication-bug 4、研究人员发现针对Intel CPU新的侧通道攻击方法 https://www.securityweek.com/new-side-channel-attack-targets-intel-cpu-ring-interconnect 5、法国Oloron-Sainte-Marie医院遭勒索软件攻击 https://securityaffairs.co/wordpress/115434/cyber-crime/french-hospital-ransomware-attack.html 6、欧洲银行管理局(EBA)Exchange服务器遭黑客攻击 https://securityaffairs.co/wordpress/115396/data-breach/eba-microsoft-exchange-hacked.html 7、UnityMiner挖矿活动针对QNAP NAS设备 https://securityaffairs.co/wordpress/115403/hacking/unityminer-qnap-nas-devices.html 8、新的Sarbloh勒索软件针对印度特定的政治实体 https://www.technadu.com/sarbloh-ransomware-targets-specific-political-entities-india/253061/ 9、Guardians应用存在漏洞泄露了用户的实时位置 https://ciso.economictimes.indiatimes.com/news/truecallers-guardians-app-was-leaking-live-location-details-issue-fixed/81394070 10、威廉姆斯新FW43B汽车发布会遭黑客破坏 https://securityaffairs.co/wordpress/115377/hacking/williams-fw43b-launch-hackers.html