网络安全日报 2021年02月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、机器学习提供了解决SQL注入漏洞的新方法 https://portswigger.net/daily-swig/machine-learning-offers-fresh-approach-to-tackling-sql-injection-vulnerabilities 2、SpamCop反垃圾邮件服务在其域名过期后发生中断 https://www.bleepingcomputer.com/news/security/spamcop-anti-spam-service-suffers-an-outage-after-its-domain-expired/ 3、针对SonicWall网络设备中的0day漏洞已被在野利用 https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/ 4、YouPHPTube和AVideo中的多个漏洞可致远程代码执行 https://portswigger.net/daily-swig/vulnerabilities-in-open-source-streaming-platforms-youphptube-and-avideo-could-lead-to-rce 5、研究人员发现了用于横向移动的新型Trickbot模块 https://securityaffairs.co/wordpress/114103/malware/trickbot-new-module.html 6、针对NoxPlayer 安卓模拟器的供应链攻击-NightScout行动 https://securityaffairs.co/wordpress/114090/hacking/noxplayer-supply-chain-attack.html 7、谷歌披露了广泛使用的Libgcrypt加密库严重漏洞 https://securityaffairs.co/wordpress/114076/security/libgcrypt-encryption-library-flaw.html 8、专家披露Azure Functions 漏洞可造成Docker逃逸 https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html 9、外包服务集团Serco Group遭勒索软件攻击 https://www.infosecurity-magazine.com/news/global-government-outsourcer-serco/ 10、网络犯罪组织Rocke正积极利用恶意软件Pro-Ocean https://securityaffairs.co/wordpress/114005/malware/pro-ocean-miner.html
网络安全日报 2021年02月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Popup Builder插件漏洞影响20万WordPress网站 https://threatpost.com/wordpress-pop-up-builder-plugin-flaw-plagues-200k-sites/163500/ 2、新的挖矿软件Pro-Ocean针对ActiveMQ、WebLogic等 https://securityaffairs.co/wordpress/114005/malware/pro-ocean-miner.html 3、美国电信运营商UScellular披露数据泄露 https://securityaffairs.co/wordpress/114023/data-breach/uscellular-data-breach.html 5、Fonix勒索软件关闭并释放主解密密钥 https://www.bleepingcomputer.com/news/security/fonix-ransomware-shuts-down-and-releases-master-decryption-key 6、英国研究与创新局(UKRI)遭勒索软件攻击 https://securityaffairs.co/wordpress/114026/hacking/ukri-ransomware-attack.html 7、编程网站Perl.com的域名被劫持 https://securityaffairs.co/wordpress/114006/hacking/website-perl-com-hijacked.html 8、研究人员发现用于卫星影像的NITRO开源库存在多个漏洞 https://www.scmagazine.com/home/security-news/vulnerabilities/flaws-in-open-source-library-used-by-dod-ic-for-satellite-imagery-could-lead-to-system-takeovers/ 9、Windows Installer零日漏洞补丁已发布 https://www.bleepingcomputer.com/news/security/windows-installer-zero-day-vulnerability-gets-free-micropatch 10、GnuPG加密软件中漏洞可致远程代码执行 https://nakedsecurity.sophos.com/2021/01/31/gnupg-crypto-library-can-be-pwned-during-decryption-patch-now/
网络安全日报 2021年01月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、苹果添加“ BlastDoor”以保护iPhone免受零点击攻击 https://www.securityweek.com/apple-adds-blastdoor-secure-iphones-zero-click-attacks 2、微软过去1年中安全业务相关收入超过100亿美金 https://www.securityweek.com/microsoft-security-10-billion-business 3、苹果将在春季推出新的隐私控制措施 https://www.securityweek.com/apple-crack-down-tracking-iphone-users-early-spring 4、新的Android恶意软件Oscorp针对意大利用户 https://securityaffairs.co/wordpress/113983/malware/oscorp-android-malware.html 5、爆炸雪松APT小组入侵全球电信、托管服务商 https://securityaffairs.co/wordpress/113975/apt/lebanese-cedar-apt-attacks.html 6、Stack Overflow披露了2019年被黑事件详情 https://stackoverflow.blog/2021/01/25/a-deeper-dive-into-our-may-2019-security-incident/ 7、研究人员发现新型网络钓鱼工具包LogoKit https://threatpost.com/logokit-simplifies-office-365-sharepoint-login-phishing-pages/163430/ 8、TeamTNT使用新逃避检测工具投送恶意软件 https://cybersecurity.att.com/blogs/labs-research/teamtnt-delivers-malware-with-new-detection-evasion-tool 9、安全研究员发现Node.js应用程序远程执行代码漏洞 https://portswigger.net/daily-swig/potential-remote-code-execution-vulnerability-uncovered-in-node-js-apps 10、Windows 7 仍易受Blind TCP/IP 劫持攻击 https://portswigger.net/daily-swig/blind-tcp-ip-hijacking-is-resurrected-for-windows-7
网络安全日报 2021年01月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、欧美执法部门联合宣布对NetWalker Ransomware采取行动 https://securityaffairs.co/wordpress/113944/cyber-crime/netwalker-ransowmare-dismantled.html 2、国际联合行动捣毁了Emotet僵尸网络 https://securityaffairs.co/wordpress/113933/cyber-crime/emotet-global-takedown.html 3、Pwn2Own 2021 提供超过150万美元的现金和其他奖品 https://www.securityweek.com/pwn2own-2021-hackers-offered-200000-zoom-microsoft-teams-exploits 4、Linux Sudo中堆缓冲区溢出漏洞可使普通用户获得root特权 https://securityaffairs.co/wordpress/113900/hacking/sudo-vulnerability-cve-2021-3156.html 5、研究人员披露了ADT的LifeShield DIY视频门铃漏洞 https://threatpost.com/adt-security-camera-flaw-opened-homes-stores-to-eavesdropping/163378/ 6、CISA发布有关富士电机HMI产品的高严重漏洞通报 https://www.securityweek.com/cisa-issues-advisory-high-severity-vulnerabilities-fuji-electric-hmi-products 7、零售巨头Dairy Farm遭REvil勒索软件攻击 https://www.bleepingcomputer.com/news/security/pan-asian-retail-giant-dairy-farm-suffers-revil-ransomware-attack/ 8、Nefilim勒索软件利用目标已故员工账户进行攻击 https://news.sophos.com/en-us/2021/01/26/nefilim-ransomware-attack-uses-ghost-credentials/ 9、超过1.76亿巴基斯坦手机用户信息在黑客论坛上出售 https://www.hackread.com/pakistani-mobile-phone-users-database-sold-online/ 10、上百工业组织在SolarWinds攻击中感染了Sunburst恶意软件 https://www.securityweek.com/hundreds-industrial-organizations-received-sunburst-malware-solarwinds-attack
网络安全日报 2021年01月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Firefox阻止Supercookies以改善用户隐私 https://www.securityweek.com/firefox-cracks-down-supercookies-improve-user-privacy 2、苹果发布了针对iOS零日漏洞的紧急修复程序 https://www.securityweek.com/apple-ships-emergency-fixes-under-attack-ios-zero-day 3、更多网络安全公司确认被SolarWinds Hack攻击 https://www.securityweek.com/more-cybersecurity-firms-confirm-being-hit-solarwinds-hack 4、NAT Slipstreaming 2.0可远程攻击内网的设备 https://www.securityweek.com/nat-slipstreaming-20-exposes-devices-internal-networks-remote-attacks 5、DanaBot恶意软件在消失七个月后重新活跃 https://threatpost.com/danabot-malware-roars-back/163358/ 6、思科DNA中心高危漏洞使企业易受到远程攻击 https://threatpost.com/cisco-dna-center-bug-remote-attack/163302/ 7、VIPGames泄漏2300万条玩家记录 https://threatpost.com/gamer-records-exposed-vipgames-leak/163352/ 8、APT组织Lazarus针对安全研究人员进行社工攻击 https://securityaffairs.co/wordpress/113855/apt/north-korea-security-experts.html 9、起重机制造商Palfinger遭遇全球网络攻击 https://www.bleepingcomputer.com/news/security/leading-crane-maker-palfinger-hit-in-global-cyberattack/ 10、Nvidia修复Jetson产品中的高危DoS漏洞 https://threatpost.com/nvidia-squashes-high-severity-jetson-dos-flaw/163360/
网络安全日报 2021年01月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、勒索软件攻击了WestRock的 IT和OT系统 https://securityaffairs.co/wordpress/113843/malware/westrock-ransomware.html 2、挖矿僵尸网络DreamBus针对Linux服务器 https://securityaffairs.co/wordpress/113832/malware/dreambus-botnet-linux-servers.html 3、新Dovecat恶意软件针对QNAP设备 https://cyware.com/news/qnap-network-devices-targeted-by-new-dovecat-malware-950680eb 4、Matrikon OPC产品存在严重漏洞 https://www.securityweek.com/industrial-firms-informed-about-serious-vulnerabilities-matrikon-opc-product 5、CrowdStrike披露Windows NTLM漏洞详细信息 https://www.securityweek.com/crowdstrike-discloses-details-recently-patched-windows-ntlm-vulnerability 6、网络钓鱼者伪造Office 365密码过期报告盗取C-Suite凭证 https://www.securityweek.com/phishers-target-c-suite-fake-office-365-password-expiration-reports 7、Shazam应用漏洞暴露Android和iOS用户的位置 https://www.hackread.com/shazam-vulnerability-exposed-android-ios-users-location/ 8、荷兰警方逮捕了两名非法出售COVID-19患者数据的人 https://securityaffairs.co/wordpress/113846/cyber-crime/covid-19-patient-data-sale.html 9、服装品牌Bonobos通知用户数据泄露 https://www.securityweek.com/clothing-brand-bonobos-informs-users-data-breach 10、SonicWall称攻击可能利用了SMA 100产品中的零日漏洞 https://threatpost.com/sonicwall-breach-zero-days-in-remote-access/163290/
网络安全日报 2021年01月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、网络安全公司SonicWall内部系统遭协同攻击 https://thehackernews.com/2021/01/exclusive-sonicwall-hacked-using-0-day.html 2、英国政府资助的笔记本电脑存在Gamarue病毒 https://www.hackread.com/uk-govt-funded-laptops-homeschoolers-gamarue-malware/ 3、勒索软件攻击者发布苏格兰环境保护局文件 https://threatpost.com/attackers-publish-private-scottish-gov-files/163254/ 4、英特尔未发布财务数据遭泄露 https://www.securityweek.com/chipmaker-intel-corp-blames-internal-error-data-leak 5、200万MyFreeCams用户数据在黑客论坛出售 https://securityaffairs.co/wordpress/113734/data-breach/myfreecams-data-breach.html 6、Edge添加了密码生成器删除了对Flash,FTP的支持 https://www.securityweek.com/microsoft-edge-adds-password-generator-drops-support-flash-ftp 7、特斯拉起诉前雇员涉嫌窃取敏感文件 https://securityaffairs.co/wordpress/113808/cyber-crime/tesla-sues-former-employee.html 8、KindleDrip漏洞–通过电子邮件入侵Kindle设备 https://securityaffairs.co/wordpress/113743/hacking/kindle-kindledrip-exploit.html 9、约会网站MeetMindful 228万用户数据在黑客论坛上泄漏 https://securityaffairs.co/wordpress/113803/uncategorized/meetmindful-data-leak.html 10、Drupal发布关键漏洞修复程序 https://www.bleepingcomputer.com/news/security/drupal-releases-fix-for-critical-vulnerability-with-known-exploits/
网络安全日报 2021年01月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Microsoft发布SolarWinds供应链攻击详细报告 https://www.securityweek.com/microsoft-details-opsec-anti-forensic-techniques-used-solarwinds-hackers 2、思科修复了SD-WAN,DNA中心,SSMS产品中的关键漏洞 https://www.securityweek.com/cisco-patches-critical-vulnerabilities-sd-wan-dna-center-ssms-products 3、SAP Solution Manager严重漏洞利用程序公开 https://www.securityweek.com/scanning-activity-detected-after-release-exploit-critical-sap-solman-flaw 4、Dovecat恶意软件针对QNAP NAS设备进行挖矿 https://securityaffairs.co/wordpress/113710/malware/qnap-dovecat-malware.html 5、网络钓鱼活动盗取的数千公司员工的凭据在线泄露 https://securityaffairs.co/wordpress/113705/hacking/phishing-stolen-pwd-google-search.html 6、FIN11攻击者正在使用Clop勒索软件 https://cyware.com/news/fin11-attackers-are-now-using-clop-ransomware-6be5cedc 7、黑客在论坛泄露7700万Nitro PDF用户记录 https://www.bleepingcomputer.com/news/security/hacker-leaks-full-database-of-77-million-nitro-pdf-user-records/ 8、安全厂商发现三个发布到npm的恶意软件包 https://blog.sonatype.com/cursedgrabber-strikes-again-sonatype-spots-new-malware-campaign-against-software-supply-chains 9、数字货币交易所BuyUCoin 32.5万用户的敏感数据泄露 https://ciso.economictimes.indiatimes.com/news/key-data-of-over-3-25-lakh-indian-users-leaked-in-buyucoin-hack/80387325 10、网络诈骗者发送虚假工作机会以获取银行信息 https://www.vice.com/en/article/3an74y/scammers-are-sending-fake-job-offers-on-linkedin
网络安全日报 2021年01月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Oracle 1月的重要补丁更新包含329个新的安全补丁 https://www.securityweek.com/oracles-january-2021-cpu-contains-329-new-security-patches 2、Snort 3正式版发布 https://www.securityweek.com/snort-3-becomes-generally-available 3、Chrome 88修补了严重漏洞并不再支持 Flash https://www.securityweek.com/chrome-88-drops-flash-patches-critical-vulnerability 4、 LuckyBoy恶意广告针对iOS,Android和XBox用户 https://www.securityweek.com/luckyboy-malvertising-campaign-hits-ios-android-xbox-users 5、加密货币交易所Livecoin在12月网络攻击后停止了运营 https://securityaffairs.co/wordpress/113650/digital-id/livecoin-halted-operations.html 6、网络安全机构介绍了Lazarus APT组织常用的工具 https://blogs.jpcert.or.jp/en/2021/01/Lazarus_tools.html 7、安全研究员发现视频会议应用多个漏洞包括Signal和FB Messenger https://securityaffairs.co/wordpress/113657/hacking/signal-fb-messenger-logical-flaws.html 8、严重的Cisco SD-WAN漏洞可导致RCE攻击 https://threatpost.com/critical-cisco-sd-wan-bugs-rce-attacks/163204/ 9、基于Golang的多平台新恶意软件ElectroRAT https://cyware.com/news/electrorat-yet-another-golang-multi-platform-malware-12406d32 10、黑客在论坛上公开发布140万个Pixlr用户记录 https://www.bleepingcomputer.com/news/security/hacker-posts-14-million-pixlr-user-records-for-free-on-forum/
网络安全日报 2021年01月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、FireEye发布新的开源工具以应对SolarWinds Hack https://www.securityweek.com/fireeye-releases-new-open-source-tool-response-solarwinds-hack2、研究人员称VPNFilter恶意软件仍然存在于数百个网络 https://www.securityweek.com/hundreds-networks-still-host-devices-infected-vpnfilter-malware3、发现与SolarWinds 攻击有关的第四种恶意软件-Raindrop https://www.securityweek.com/solarwinds-hackers-used-raindrop-malware-lateral-movement4、Malwarebytes称电子邮件系统遭SolarWinds供应链攻击 https://securityaffairs.co/wordpress/113628/hacking/malwarebytes-solarwinds-attack.html5、FreakOut僵尸网络利用近期3种危害Linux设备的漏洞 https://securityaffairs.co/wordpress/113606/cyber-crime/freakout-botnet.html6、研究人员发现Dnsmasq中多个漏洞影响数百万设备 https://thehackernews.com/2021/01/a-set-of-severe-flaws-affect-popular.html7、CoTURN修补VoIP系统访问控制绕过漏洞 https://portswigger.net/daily-swig/voip-vulnerability-coturn-patches-access-control-protection-bypass8、FBI警告窃取凭据的语音网络钓鱼活动 https://www.bleepingcomputer.com/news/security/fbi-warns-of-vishing-attacks-stealing-corporate-accounts/9、AnyVan披露数据泄露 https://www.theregister.com/2021/01/19/anyvan_confirms_digital_breakin_says/10、Microsoft 启用 Defender for Endpoint自动威胁修复 https://www.securityweek.com/microsoft-enables-automatic-remediation-defender-endpoint