网络安全日报 2021年03月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Linux内核修复本地提权漏洞
https://www.securityweek.com/privilege-escalation-bugs-patched-linux-kernel
2、托管服务提供商CompuCom遭恶意软件攻击
https://www.securityweek.com/managed-services-provider-compucom-hit-malware
3、思科多款产品因Snort检测引擎漏洞遭DoS攻击
https://www.securityweek.com/several-cisco-products-exposed-dos-attacks-due-snort-vulnerability
4、多个黑客组织利用Exchange Server 零日漏洞攻击
https://www.securityweek.com/multiple-cyberspy-groups-target-microsoft-exchange-servers-zero-day-flaws
5、500万Adecco.com用户数据泄露
https://cybernews.com/security/5-million-adecco-com-users-data-leaked/
6、FireEye研究人员发现与SolarWinds攻击有关的新恶意软件
https://securityaffairs.co/wordpress/115291/malware/sunshuttle-backdoor-solarwinds-hack.html
7、GRUB项目发布安全更新修复数百个漏洞
https://securityaffairs.co/wordpress/115258/hacking/grub2-boot-loader-flaws.html
8、Group-IB发布报告勒索软件攻击在2020年增长了 150%以上
https://securityaffairs.co/wordpress/115268/cyber-crime/ransomware-landscape-2020.html
9、WiFi Mouse应用存在漏洞可劫持台式电脑
https://threatpost.com/unpatched-bug-in-wifi-mouse-opens-pcs-to-attack/164480/
10、俄罗斯网络犯罪论坛Maza遭数据泄露
https://www.zdnet.com/article/maza-russian-cybercriminal-forum-suffers-data-breach/
网络安全日报 2021年03月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、英特尔为漏洞赏金计划平均每年支付80W美金
https://www.securityweek.com/intel-paid-out-800000-year-through-bug-bounty-program
2、网络安全公司Qualys遭Clop勒索软件攻击并导致数据泄露
https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html
3、100多家意大利银行遭Ursnif Trojan攻击
https://securityaffairs.co/wordpress/115245/cyber-crime/ursnif-targets-italian-banks.html
4、Chrome发布更新修复高危漏洞
https://threatpost.com/google-patches-actively-exploited-flaw-in-chrome-browser/164468/
5、微软发布紧急更新修复Exchange Server 4个0day漏洞
https://thehackernews.com/2021/03/urgent-4-actively-exploited-0-day-flaws.html
6、微软向发现Microsoft账户劫持漏洞的研究员支付5W美元赏金
https://thehackernews.com/2021/03/a-50000-bug-couldve-allowed-hackers.html
7、VMware修补View Planner中的远程执行代码漏洞
https://www.securityweek.com/vmware-patches-remote-code-execution-vulnerability-view-planner
8、Google开始测试替代Cookie跟踪的方法
https://www.securityweek.com/google-vows-stop-tracking-individual-browsing-ads
9、研究人员发现Eclipse Jetty中存在DoS漏洞
https://www.technadu.com/dos-vulnerability-eclipse-jetty-urgent-updates/251662/
10、美国软件公司Mariana Tek泄露了用户的记录
https://cybernews.com/security/fitness-management-platform-mariana-tek-leaked-1-5-million-user-records/
网络安全日报 2021年03月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Google修补了Android中的高危远程代码执行漏洞
https://www.securityweek.com/google-patches-critical-remote-code-execution-vulnerability-android
2、“ Unc0ver”最新版本利用了1月份苹果修复的漏洞
https://www.securityweek.com/new-unc0ver-jailbreak-uses-vulnerability-apple-said-was-exploited
3、法国跨国乳制品公司Lactalis遭网络攻击
https://securityaffairs.co/wordpress/115173/hacking/lactalis-cyber-attack.html
4、Ryuk Ransomware通过SMB共享进行自我传播
https://threatpost.com/ryuk-ransomware-worming-self-propagation/164412/
5、电子售票平台Ticketcounter数据库在黑客论坛公开
https://www.bleepingcomputer.com/news/security/european-e-ticketing-platform-ticketcounter-extorted-in-data-breach/
6、 Gootkit RAT利用SEO通过受损网站传播恶意软件
https://thehackernews.com/2021/03/gootkit-rat-using-seo-to-distribute.html
7、ObliqueRAT恶意软件利用图片隐写加载攻击载荷
https://threatpost.com/website-images-obliquerat-malware/164395/
8、马来西亚航空披露长达九年的数据安全事件
https://www.zdnet.com/article/malaysia-airlines-suffers-data-security-incident-spanning-nine-years/
9、UHS披露在去年9月网络攻击中损失6700W美元
https://www.securityweek.com/universal-health-services-takes-67-million-hit-cyberattack
10、Perl.com域在2020年9月已被黑客劫持
https://www.securityweek.com/hackers-control-perlcom-domain-months-hijack
网络安全日报 2021年03月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、SolarWinds高层表示近期供应链攻击是因为实习生使用弱口令
https://securityaffairs.co/wordpress/115134/security/solarwinds-intern-solarwinds123-password-leak.html
2、NSA建议采用零信任安全模型
https://securityaffairs.co/wordpress/115121/security/nsa-zero-trust-security.html
3、加密货币交易所Cryptopia再次遭黑客攻击
https://securityaffairs.co/wordpress/115099/hacking/cryptopia-hacked-twice.html
4、TikTok公司ByteDance同意支付9200万美元隐私和解费
https://securityaffairs.co/wordpress/115115/digital-id/tiktok-us-privacy-settlement.html
5、美国社交网络Gab承认其被黑客入侵
https://www.securityweek.com/us-right-wing-platform-gab-acknowledges-it-was-hacked
6、亚洲食品分销巨头JFC International遭勒索软件攻击
https://www.securityweek.com/asian-food-distribution-giant-jfc-international-hit-ransomware
7、Genua修复了其GenuGate防火墙身份验证绕过漏洞
https://threatpost.com/firewall-critical-security-flaw/164347/
8、 Salt修复了SaltStack minion特权提升漏洞
https://www.zdnet.com/article/minion-hijacking-flaw-patched-in-saltstack-salt-project/
9、2100万Android平台 VPN服务用户数据在黑客论坛出售
https://www.technadu.com/collection-of-user-data-allegedly-sourced-from-android-vpns-appeared-for-sale/250910/
10、印度视频网站ZEE5泄露了900万用户数据
https://www.technadu.com/zee5-leaked-data-nine-million-users-did-not-disclose-it/251211/
网络安全日报 2021年03月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Facebook支付6.5亿美元用于隐私诉讼和解
https://www.securityweek.com/judge-approves-650m-facebook-privacy-lawsuit-settlement
2、研究人员发现大量Android平台Covid-19追踪应用存在漏洞
https://www.securityweek.com/security-privacy-issues-found-tens-covid-19-contact-tracing-apps
3、微软开源查找 SolarWinds 黑客的工具代码
https://www.securityweek.com/microsoft-releases-open-source-resources-solorigate-threat-hunting
4、研究人员发现Rockwell控制器漏洞可被远程攻击
https://www.securityweek.com/unprotected-private-key-allows-remote-hacking-rockwell-controllers
5、勒索软件团伙入侵了厄瓜多尔最大的私人银行和财政部
https://www.bleepingcomputer.com/news/security/ransomware-gang-hacks-ecuadors-largest-private-bank-ministry-of-finance/
6、T-Mobile遭SIM交换攻击导致数据泄露
https://www.bleepingcomputer.com/news/security/t-mobile-discloses-data-breach-after-sim-swapping-attacks/
7、牛津大学进行COVID-19研究的实验室遭受黑客入侵
https://www.zdnet.com/article/oxford-university-biochemical-lab-involved-in-covid-19-research-targeted-by-hackers/
8、谷歌Project Zero团队批量Windows 10 Graphics RCE漏洞细节
https://www.bleepingcomputer.com/news/security/google-shares-poc-exploit-for-critical-windows-10-graphics-rce-bug/
9、H2C请求走私排名2020年10大Web攻击技术之首
https://portswigger.net/daily-swig/h2c-smuggling-named-top-web-hacking-technique-of-2020
10、CD Projekt因网络攻击推迟《赛博朋克2077》补丁发布时间
https://www.reuters.com/article/us-cd-projekt-patch/polands-cd-projekt-delays-cyberpunk-2077-fix-due-to-cyber-attack-idUSKBN2AO2BW
网络安全日报 2021年02月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Kasablanca组织针对孟加拉国多个机构进行攻击
https://www.dhakatribune.com/business/2021/02/22/hackershave-eye-on-6-bangladeshi-organisations
2、思科修复了高危的MSO身份验证绕过漏洞
https://www.bleepingcomputer.com/news/security/cisco-fixes-maximum-severity-mso-auth-bypass-vulnerability/
3、专家警告针对QuickBooks文件数据盗窃事件明显增加
https://thehackernews.com/2021/02/experts-warns-of-notable-increase-in.html
4、Google资助Linux进行提高内核安全性开发
https://www.securityweek.com/google-funds-linux-kernel-security-development
5、黑客针对有漏洞的VMware vCenter Server进行大规模扫描
https://www.securityweek.com/hackers-scanning-vmware-vcenter-servers-affected-critical-vulnerability
6、Google披露Windows CVE-2021-24093 RCE漏洞细节
https://www.securityweek.com/google-discloses-details-remote-code-execution-vulnerability-windows
7、 Lazarus APT通过ThreatNeedle后门瞄准国防工业
https://securityaffairs.co/wordpress/115013/apt/lazarus-apt-threatneedle.html
8、印度泄露800W个Covid-19检测信息
https://threatpost.com/health-website-leaks-covid-19-test/164274/
9、能源公司Npower APP遭凭证填充攻击
https://www.bbc.com/news/technology-56195631
10、微软更新了一些基于 Intel CET 的保护机制
https://techcommunity.microsoft.com/t5/windows-kernel-internals/developer-guidance-for-hardware-enforced-stack-protection/ba-p/2163340
网络安全日报 2021年02月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、新的“ LazyScripter”黑客组织针对航空公司
https://www.securityweek.com/new-lazyscripter-hacking-group-targets-airlines
2、飞机制造商庞巴迪证实遭数据泄露
https://www.securityweek.com/hackers-leak-data-stolen-jet-maker-bombardier
3、严重的VMware vCenter漏洞可导致遭受远程攻击
https://www.securityweek.com/critical-vmware-vcenter-server-flaw-can-expose-organizations-remote-attacks
4、Firefox 86新功能可以阻止基于Cookie的跨站点跟踪
https://www.securityweek.com/new-firefox-feature-ups-ante-against-cookie-based-tracking
5、乌克兰政府文件管理系统遭黑客攻击
https://securityaffairs.co/wordpress/114991/cyber-warfare-2/ukraine-hit-cyber-attack.html
6、菲律宾信贷应用Cashalo发生用户数据泄露
https://portswigger.net/daily-swig/filipino-credit-app-cashalo-suffers-data-breach
7、僵尸网络利用BTC区块链交易备份命令和C2地址
https://securityaffairs.co/wordpress/114984/cyber-crime/bitcoin-blockchain-botnet.html
8、越南海莲花组织APT32针对人权组织进行网络间谍活动
https://securityaffairs.co/wordpress/114973/malware/apt32-spyware-human-rights-defenders.html
9、针对大学的勒索软件攻击急剧增加
https://www.zdnet.com/article/ransomware-sharp-rise-in-attacks-against-universities-as-learning-goes-online
10、研究人员发现Nginx配置错误普遍存在
https://portswigger.net/daily-swig/nginx-server-misconfigurations-found-in-the-wild-that-expose-websites-to-attacks
网络安全日报 2021年02月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、VMware修复了vCenter Server中的严重RCE漏洞
https://securityaffairs.co/wordpress/114957/security/vmware-in-vcenter-server-rce.html
2、IBM发布安全补丁修复Kenexa LMS等产品中的漏洞
https://securityaffairs.co/wordpress/114942/security/ibm-security-flaws.html
3、超过1W名微软邮箱用户遭FedEx和DHL Express邮件钓鱼攻击
https://threatpost.com/microsoft-fedex-phishing-attack/164143/
4、芬兰IT巨头TietoEVRY遭勒索软件攻击
https://threatpost.com/finnish-it-giant-ransomware-cyberattack/164193/
5、研究人员发现一种可替换经过数字签名的PDF中内容的新型攻击
https://thehackernews.com/2021/02/shadow-attacks-let-attackers-replace.html
6、Lazarus Group使用AppleJeus恶意软件窃取加密货币
https://cyware.com/news/lazarus-group-using-applejeus-malware-for-cryptocurrency-theft-aac77cae
7、具有新TTP和社会工程学模块的MINEBRIDGE RAT重新活跃
https://www.zscaler.com/blogs/security-research/return-minebridge-rat-new-ttps-and-social-engineering-lures
8、Keybase修复了图像缓存明文存储的安全漏洞
https://www.zdnet.com/article/keybase-patches-bug-that-kept-pictures-in-cleartext-storage-on-mac-windows-clients
9、NASA首次采用Linux操作系统用于火星Ingenuity直升机上
https://in.pcmag.com/drones/141086/linux-is-now-on-mars-thanks-to-nasas-perseverance-rover
10、ServiceNow云平台中漏洞可导致密码泄露
https://portswigger.net/daily-swig/servicenow-admin-credentials-among-hundreds-of-passwords-exposed-in-cloud-security-blunder
网络安全日报 2021年02月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、新的Silver Sparrow恶意软件已感染全球3W台Mac设备
https://www.securityweek.com/mysterious-mac-malware-infected-least-30000-devices-worldwide
2、乌克兰称遭受了来自俄罗斯网络的大规模攻击
https://securityaffairs.co/wordpress/114913/cyber-warfare-2/russian-networks-ukraine-sites.html
3、Clubhouse房间遭音频窃取攻击
https://securityaffairs.co/wordpress/114891/digital-id/clubhouse-privacy-issues.html
4、网络摄像头公司NurseryCam披露了数据泄露
https://news.yahoo.com/parents-alerted-nurserycam-security-breach-164917570.html
5、Accellion FTA零日攻击与FIN11的勒索软件有关
https://threatpost.com/accellion-zero-day-attacks-clop-ransomware-fin11/164150/
6、2020年日本88家公司的个人信息遭到泄露
https://www.japantimes.co.jp/news/2021/02/21/national/crime-legal/computer-viruses-big-data-cybersecurity
7、Python更新以解决远程代码漏洞
https://www.zdnet.com/article/python-programming-language-hurries-out-update-to-tackle-remote-code-vulnerability
8、Chrome for iOS新功能使用Face ID锁定隐身标签页
https://www.bleepingcomputer.com/news/google/new-chrome-for-ios-feature-locks-incognito-tabs-with-face-id/
9、SHAREit修复了严重的代码执行漏洞
https://www.bleepingcomputer.com/news/security/shareit-fixes-security-bugs-in-app-with-1-billion-downloads/
10、加拿大莱克黑德大学遭网络攻击后关闭了学校网络
https://www.bleepingcomputer.com/news/security/lakehead-university-shuts-down-campus-network-after-cyberattack/
网络安全日报 2021年02月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、攻击者滥用Google快讯来伪造Flash更新
https://securityaffairs.co/wordpress/114871/cyber-crime/google-alerts-abuse.html
2、红杉资本披露数据泄露事件
https://securityaffairs.co/wordpress/114831/hacking/sequoia-capital-data-breach.html
3、SonicWall针对SMA 100漏洞发布第二个固件更新
https://securityaffairs.co/wordpress/114818/security/sonicwall-firmware-updates-sma-100.html
4、湖首大学被网络攻击后关闭了其计算机系统
https://hotforsecurity.bitdefender.com/blog/lakehead-university-shuts-down-campuses-and-computers-after-cyberattack-25358.html
5、美国保险商实验室(UL LLC)遭勒索软件攻击
https://www.bleepingcomputer.com/news/security/underwriters-laboratories-ul-certification-giant-hit-by-ransomware
6、Ubuntu安全公告发现Bind9漏洞
https://packetstormsecurity.com/files/161456
7、研究人员发现新型攻击:卡品牌混淆攻击
https://thehackernews.com/2021/02/new-hack-lets-attackers-bypass.html
8、付款处理供应商ATFS遭勒索软件攻击导致多个城市数据泄露
https://www.bleepingcomputer.com/news/security/us-cities-disclose-data-breaches-after-vendors-ransomware-attack/
9、克罗格公司告知客户其数据遭受泄露
https://www.ajc.com/news/breaking-kroger-advises-customers-of-data-breach-affecting-pharmacy/R44FKCSVLNDTJHA53ON36HO2CA/
10、FBI发出有关呼叫中心电话拒绝服务(TDoS)攻击风险的警告
https://securityaffairs.co/wordpress/114856/cyber-crime/fbi-tdos-attacks-warning.html
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

