网络安全日报 2021年02月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Brave 浏览器泄露了用户访问的union url地址给DNS提供商
https://securityaffairs.co/wordpress/114793/deep-web/privacy-bug-brave-browser.html
2、MassLogger 木马变体窃取Outlook,Chrome等凭据
https://securityaffairs.co/wordpress/114783/malware/masslogger-trojan.html
3、黑客利用Google Apps Script窃取用户支付卡信息
https://securityaffairs.co/wordpress/114750/cyber-crime/googles-apps-script-magecart.html
4、缅甸多个政府机构网站遭受黑客攻击
https://www.securityweek.com/hackers-target-myanmar-government-websites-coup-protest
5、欧洲互联网注册中心遭受了凭证填充攻击
https://cybernews.com/news/internet-registry-for-europe-experienced-a-credential-stuffing-attack-claims-it-was-unsuccessful/
6、NIST数据表明2020年的安全漏洞数量激增创历史新高
https://cyware.com/news/highest-number-of-vulnerabilities-disclosure-reported-in-2020-65eeaf96
7、研究人员报告icloud.com XSS漏洞获$5000奖励
https://www.securityweek.com/stored-xss-vulnerability-icloudcom-earned-researcher-5000
8、苹果为iMessage增加了“ BlastDoor”安全功能
https://www.reuters.com/article/us-apple-cyber/apple-adds-blastdoor-security-feature-to-fight-imessage-hacks-idUSKBN2AI2UJ
9、研究人员发现Microsoft IE零日漏洞
https://threatpost.com/exploit-details-unpatched-microsoft-bug/164083/
10、研究人员发现Gaper应用程序存在严重漏洞
https://portswigger.net/daily-swig/security-researchers-warn-of-critical-zero-day-flaws-in-age-gap-dating-app-gaper
网络安全日报 2021年02月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、苹果发布了最新版本的《平台安全指南》
https://www.securityweek.com/apple-platform-security-guide-gets-biggest-update-date
2、研究人员发现专门针对搭载M1芯片的Mac恶意软件
https://www.securityweek.com/mac-malware-targeting-apples-m1-chip-emerges
3、微软称SolarWinds黑客下载了Azure、Exchange某些组件源代码
https://securityaffairs.co/wordpress/114731/hacking/solarwinds-hackers-microsoft-repositories.html
4、DoppelPaymer勒索软件攻击了起亚汽车并索要2000W美金
https://threatpost.com/kia-motors-ransomware-attack/164085/
5、网络钓鱼者伪造LinkedIn私有共享文件欺骗用户
https://www.helpnetsecurity.com/2021/02/18/linkedin-private-shared-document
6、超过257,000名在线博彩用户敏感数据在黑客论坛上出售
https://cybernews.com/security/sensitive-data-of-more-than-257000-online-gamblers-put-for-sale-on-hacker-forum
7、1400万个亚马逊和eBay账户详细信息在黑客论坛上出售
https://cybernews.com/security/14-million-amazon-and-ebay-accounts-sold-online-in-new-leak/
8、Agora SDK中漏洞允许攻击者悄悄加入音频和视频通话
https://www.zdnet.com/article/bug-in-shared-sdk-can-let-attackers-join-calls-undetected-across-multiple-apps/
9、研究人员发现太阳能网关设备ConnectPort X2e存在两个漏洞
https://www.securityweek.com/research-shows-how-solar-energy-installations-can-be-abused-hackers
10、研究人员披露新型的Office恶意软件-APOMacroSploit
https://thehackernews.com/2021/02/researchers-unmask-hackers-behind.html
网络安全日报 2021年02月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、美国起诉朝鲜 Lazarus APT黑客组织成员
https://www.securityweek.com/us-charges-north-korean-hackers-over-13-billion-bank-heists
2、微软承认KB4535680补丁会触发BitLocker密钥恢复提示
https://www.bleepingcomputer.com/news/microsoft/windows-10-secure-boot-update-triggers-bitlocker-key-recovery/
3、OpenSSL修补了三个新漏洞
https://www.securityweek.com/three-new-vulnerabilities-patched-openssl
4、网络犯罪组织ScamClub利用WebKit零日漏洞
https://securityaffairs.co/wordpress/114689/cyber-crime/scamclub-malvertising-webkit-zero-day.html
5、黑客利用Ngrok平台进行网络钓鱼攻击
https://securityaffairs.co/wordpress/114644/cyber-crime/ngrok-phishing-attacks.html
6、文件共享应用SHAREit存在严重漏洞尚待修复
https://securityaffairs.co/wordpress/114636/mobile-2/shareit-app-flaw.html
7、恶意挖矿木马WatchDog已悄悄传播了两年
https://threatpost.com/windows-linux-devices-hijacked-in-two-year-cryptojacking-campaign/164048/
8、苹果修复了macOS Big Sur严重的数据丢失错误
https://www.zdnet.com/article/apple-patches-severe-macos-big-sur-data-loss-bug/
9、加密货币交易所EXMO遭受DDoS攻击而宕机
https://portswigger.net/daily-swig/uk-cryptocurrency-exchange-exmo-knocked-offline-by-massive-ddos-attack
10、安全专家披露Telegram漏洞可访问用户聊天记录
https://securityaffairs.co/wordpress/114653/hacking/telegram-flaw-access-secret-chats.html
网络安全日报 2021年02月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Adobe修复了在野利用的Adobe Reader漏洞
https://www.securityweek.com/adobe-patches-reader-vulnerability-exploited-wild
2、微软周二发布了56个漏洞修复补丁
https://www.securityweek.com/patch-tuesday-microsoft-warns-under-attack-windows-kernel-flaw
3、赛博朋克2077开发商遭黑客攻击源代码被盗
https://www.securityweek.com/cyberpunk-2077-video-game-developer-hit-hack-attack
4、联合国专家:朝鲜利用网络攻击筹集资金发展核武器
https://www.securityweek.com/un-experts-north-korea-using-cyber-attacks-update-nukes
5、乌克兰警方逮捕了U-Admin网络钓鱼工具包的作者
https://securityaffairs.co/wordpress/114394/cyber-crime/author-u-admin-phishing-arrest.html
6、微软提醒Office 365用户注意国家级黑客活动
https://www.bleepingcomputer.com/news/security/microsoft-to-alert-office-365-users-of-nation-state-hacking-activity/
7、安全厂商披露APT-C-50组织的监控行动
https://securityaffairs.co/wordpress/114353/apt/domestic-kitten-operations.html
8、匹兹堡大学医学中心3.6万名患者健康信息遭受泄露
https://www.infosecurity-magazine.com/news/law-firm-data-breach-impacts-upmc/
9、一项Facebook钓鱼活动在两周内欺骗了50W用户
https://cybernews.com/security/we-uncovered-a-facebook-phishing-campaign-that-tricked-nearly-500000-users-in-two-weeks/
10、东京燃气披露Furo Koi用户数据泄露
https://portswigger.net/daily-swig/tokyo-gas-discloses-data-breach-impacting-anime-style-dating-simulation-game
网络安全日报 2021年02月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、黑客攻击了佛罗里达市一家城市自来水厂
https://www.securityweek.com/remote-hacker-caught-poisoning-florida-city-water-supply
2、Google推出开源软件漏洞数据库
https://www.securityweek.com/google-launches-database-open-source-vulnerabilities
3、新的网络钓鱼使用摩尔斯电码来隐藏恶意URL
https://securityaffairs.co/wordpress/114346/cyber-crime/hishing-technique-morse-code.html
4、Ziggy勒索软件已关闭其运营并释放了解密密钥
https://securityaffairs.co/wordpress/114340/malware/ziggy-ransomware-decryptor.html
5、研究人员开发出一种可以识别假新闻的方法
https://www.helpnetsecurity.com/2021/02/08/recognize-fake-news/
6、神秘的黑客组织破坏了多个斯里兰卡域名
https://www.zdnet.com/article/hacktivists-deface-multiple-sri-lankan-domains-including-google-lk/
7、NextGen Gallery插件漏洞可导致WordPress网站被接管
https://threatpost.com/critical-wordpress-plugin-flaw-site-takeover/163734/
8、微软警告针对Office 365 的OAuth网络钓鱼攻击增多
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-increasing-oauth-office-365-phishing-attacks
9、Firefox 发布 85.0.1 版本更新修复一个高危漏洞
https://www.mozilla.org/en-US/security/advisories/mfsa2021-06/
10、RD Web Access被发现可以通过 Timing Attack 泄露用户名信息
https://raxis.com/blog/rd-web-access-vulnerability
网络安全日报 2021年02月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Google正在测试替代Cookies的新方法
https://www.securityweek.com/google-moves-away-diet-cookies-track-users
2、2020年ICS漏洞的数量比2019年增加24.72%
https://securityaffairs.co/wordpress/114302/ics-scada/ics-flaws-report-2.html
3、欧洲某些Nespresso咖啡机可被攻击无限金额购买咖啡
https://securityaffairs.co/wordpress/114314/hacking/nespresso-hack.html
4、美国两家医院的数万份详细医疗记录在暗网泄露
https://www.nbcnews.com/tech/security/hackers-post-detailed-patient-medical-records-two-hospitals-dark-web-n1256887
5、Contact Form 7 Style插件漏洞影响50K个网站
https://threatpost.com/unpatched-wordpress-plugin-code-injection/163706/
6、Otorio发布用于加固常用HMI / SCADA系统的开源工具
https://www.helpnetsecurity.com/2021/02/05/hardening-ge-cimplicity/
7、研究人员在多款Geeni/Merkury 摄像头和智能门铃中发现漏洞
https://www.cyberscoop.com/geeni-merkury-smart-doorbells-cameras-flaws-research/
8、巴西能源公司Eletrobras,Copel遭勒索软件攻击
https://www.bleepingcomputer.com/news/security/eletrobras-copel-energy-companies-hit-by-ransomware-attacks
9、安全人员发现Skype 存在“欺骗漏洞”可被用作社工攻击
https://portswigger.net/daily-swig/skype-spoofing-vulnerabilities-are-a-haven-for-social-engineering-attacks-security-researcher-claims
10、Spotify在三个月内遭第二次凭证填充攻击
https://threatpost.com/spotify-credential-stuffing-cyberattack/163672/
网络安全日报 2021年02月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、包装业巨头WestRock遭勒索软件攻击
https://www.securityweek.com/packaging-giant-westrock-says-ransomware-attack-hit-production
2、Plex Media Server被用作反射型DDoS攻击
https://www.securityweek.com/plex-media-server-abused-ddos-attacks
3、谷歌在2020年支付了670万美元的漏洞赏金
https://www.securityweek.com/google-paid-out-67-million-bug-bounty-rewards-2020
4、The Great Suspender插件包含恶意软件
https://securityaffairs.co/wordpress/114272/malware/the-great-suspender-extension-malware.html
5、Fortinet修复了FortiWeb应用防火墙中的4个漏洞
https://securityaffairs.co/wordpress/114233/hacking/fortinet-fortiweb-flaws.html
6、恶意软件Hildegard针对Kubernetes集群
https://securityaffairs.co/wordpress/114241/malware/teamtnt-hildegard-malware-kubernetes.html
7、Chainalysis 团队分析发现多个勒索软件团伙存在合作关系
https://blog.chainalysis.com/reports/ransomware-connections-maze-egregor-suncrypt-doppelpaymer
8、Google Chrome同步功能被攻击者滥用以窃取数据
https://www.zdnet.com/article/google-chrome-syncing-features-can-be-abused-for-c-c-and-data-exfiltration/
9、Web开发教程网站SitePoint用户数据遭泄露
https://www.bleepingcomputer.com/news/security/sitepoint-discloses-data-breach-after-stolen-info-used-in-attacks/
10、Google警告其V8 引擎中存在零日漏洞 已被利用
https://threatpost.com/google-chrome-zero-day-windows-mac/163688/
网络安全日报 2021年02月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、空客网络安全子公司Stormshield披露数据泄露
https://www.securityweek.com/airbus-cybersecurity-subsidiary-stormshield-discloses-data-breach
2、思科修复了小型企业路由器,SD-WAN中的关键漏洞
https://www.securityweek.com/cisco-patches-critical-vulnerabilities-small-business-routers-sd-wan
3、Realtek RTL8195A Wi-Fi模块漏洞使许多设备面临远程攻击
https://www.securityweek.com/vulnerabilities-realtek-wi-fi-module-expose-many-devices-remote-attacks
4、Google修复了在野利用的Chrome零日漏洞
https://securityaffairs.co/wordpress/114224/hacking/google-chrome-zero-day.html
5、Matryosh DDoS僵尸网络通过ADB感染Android设备
https://securityaffairs.co/wordpress/114216/malware/matryosh-ddos-botnet-android.html
6、SonicWall发布了SMA 100零日漏洞的补丁
https://securityaffairs.co/wordpress/114197/hacking/sonicwall-zero-day-patch.html
7、攻击者利用Google Firebase对Office 365 用户进行钓鱼攻击
https://threatpost.com/microsoft-office-365-attacks-google-firebase/163666/
8、SoftMaker Office PlanMaker中发现多个漏洞
https://blog.talosintelligence.com/2021/02/vuln-spotlight-softmaker-office-planmaker.html
9、克什米尔地区巴帝电信250万用户的数据遭受泄露
https://ciso.economictimes.indiatimes.com/news/data-of-25-lakh-airtel-customers-in-j-k-allegedly-leaked-telco-claims-no--in-server/80661483
10、Clearview面部识别技术在加拿大被裁定为非法
https://threatpost.com/clearview-facial-recognition-canada/163650/
网络安全日报 2021年02月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、sudo CVE-2021-3156漏洞影响Apple,Cisco产品
https://www.securityweek.com/recent-sudo-vulnerability-affects-apple-cisco-products
2、研究人员发现SolarWinds产品中新高危漏洞
https://www.securityweek.com/solarwinds-product-vulnerabilities-allow-hackers-take-full-control-systems
3、Adobe ColdFusion 存在特权升级漏洞
https://www.securityweek.com/weak-acls-adobe-coldfusion-allow-privilege-escalation
4、Google发布Android安全补丁修复了40多个漏洞
https://www.securityweek.com/google-patches-16-high-severity-privilege-escalation-vulnerabilities-android
5、研究人员发现Limit Login Attempts Reloaded 插件零日漏洞
https://securityaffairs.co/wordpress/114186/hacking/zero-day-wordpress.html
6、Hildegard恶意软件劫持Kubernetes集群进行挖矿
https://threatpost.com/new-malware-hijacks-kubernetes-clusters-to-mine-monero/163629/
7、28个Chrome插件劫持了数百万人的Google搜索结果
https://thehackernews.com/2021/02/over-dozen-chrome-extensions-caught.html
8、32亿条邮箱和密码明文对在黑客论坛上泄露
https://cybernews.com/news/largest-compilation-of-emails-and-passwords-leaked-free/
9、新的XS-Leak攻击利用浏览器重定向来窃取用户隐私
https://portswigger.net/daily-swig/playing-fetch-new-xs-leak-exploits-browser-redirects-to-break-user-privacy
10、DriveSure 320W客户数据泄露
https://www.scmagazine.com/home/security-news/data-on-3-2-million-drivesure-users-exposed-on-hacking-forum/
网络安全日报 2021年02月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、嵌入式软件开发商Wind River披露数据泄露
https://www.securityweek.com/embedded-software-developer-wind-river-discloses-data-breach
2、复杂的多平台恶意软件“ Kobalos”针对超级计算机
https://www.securityweek.com/sophisticated-multiplatform-malware-kobalos-targets-supercomputers
3、华盛顿州审计署160万用户数据遭泄露
https://www.securityweek.com/over-1-million-impacted-data-breach-washington-state-auditor
4、SonicWall证实零日漏洞已导致上千台设备受到攻击
https://www.securityweek.com/sonicwall-says-few-thousand-devices-impacted-zero-day-vulnerability
5、苹果发布NAT Slipstreaming 2.0攻击补丁
https://www.securityweek.com/apple-issues-patches-nat-slipstreaming-20-attack
6、RansomExx勒索软件利用VMWare ESXi漏洞来加密VM磁盘
https://www.zdnet.com/article/ransomware-gangs-are-abusing-vmware-esxi-exploits-to-encrypt-virtual-hard-disks/
7、警察考试数据库泄露了50万印度公民的PII
https://securityaffairs.co/wordpress/114148/data-breach/police-exam-database-exposes-500k-indian-citizens-pii.html
8、新的Trickbot模块使用Masscan进行本地网络侦察
https://www.zdnet.com/article/new-trickbot-module-uses-masscan-for-local-network-reconnaissance/
9、CISA:许多SolarWinds 攻击受害者与SolarWinds没有直接关系
https://securityaffairs.co/wordpress/114114/hacking/solarwinds-hackers-victims-no-direct-link.html
10、网络钓鱼活动通过伪造的PPP贷款引诱美国企业
https://www.bleepingcomputer.com/news/security/phishing-campaign-lures-us-businesses-with-fake-ppp-loans/
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

