网络安全日报 2021年01月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SolarWinds 供应链攻击已影响多达250家政府和企业 https://www.securityweek.com/over-250-organizations-breached-solarwinds-supply-chain-hack-report 2、Apex实验室称患者数据在勒索软件攻击中被盗 https://www.securityweek.com/apex-laboratory-says-patient-data-stolen-ransomware-attack 3、英国法官拒绝美国引渡维基解密创始人阿桑奇 https://www.securityweek.com/uk-judge-refuses-us-extradition-wikileaks-founder-assange 4、MuddyWater攻击从GitHub下载了PowerShell脚本 https://securityaffairs.co/wordpress/112972/hacking/muddywater-attack-github-imgur.html 5、NCA逮捕了21位WeLeakInfo服务的客户 https://securityaffairs.co/wordpress/112935/cyber-crime/nca-arrested-weleakinfo-customers.html 6、研究人员使用Google语音文本API绕过音频reCAPTCHA https://threatpost.com/researcher-breaks-recaptcha-speech-to-text-api/162734/ 7、T-Mobile报告了数据泄露事件 https://threatpost.com/t-mobile-another-data-breach/162703/ 8、微软未发布的Core Polaris操作系统在线泄漏 https://www.bleepingcomputer.com/news/microsoft/microsofts-unreleased-windows-core-polaris-os-leaks-online/ 9、研究人员在暗网发现100万个游戏公司内部账户 https://www.infosecurity-magazine.com/news/one-million-compromised-accounts/ 10、PayPal短信网络钓鱼活动试图窃取用户凭据 https://www.bleepingcomputer.com/news/security/beware-paypal-phishing-texts-state-your-account-is-limited/
网络安全日报 2021年01月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软表示“ SolarWinds”攻击访问了某些内部代码 https://www.securityweek.com/microsoft-says-solarwinds-hackers-viewed-internal-code 2、APT组织StrongPity使用更新的基础设施 https://cybleinc.com/2020/12/31/strongpity-apt-extends-global-reach-with-new-infrastructure/ 3、Smart Grid Gallery插件被注入恶意代码 https://blog.sucuri.net/2020/12/seo-spam-links-in-nulled-plugins.html 4、谷歌Chrome浏览器修复防病毒文件锁定错误 https://www.bleepingcomputer.com/news/security/google-chrome-fixes-antivirus-file-locking-bug-on-windows-10/ 5、黑客访问Mednax公司邮件帐户泄露数据 https://www.beckershospitalreview.com/cybersecurity/mednax-email-hack-exposes-info-of-1-2-million-patients-5-details.html 6、Prestera心理健康服务中心通知数据泄露 https://www.herald-dispatch.com/news/prestera-center-notifies-patients-of-data-security-incident/article_8d844ec5-1272-5ea9-9d5e-2706505b8218.html 7、多个Zyxel防火墙VPN产品中发现秘密后门帐户 https://thehackernews.com/2021/01/secret-backdoor-account-found-in.html 8、新的Golang蠕虫将服务器变成挖矿机器 https://www.scmagazine.com/home/security-news/malware/new-golang-worm-turns-windows-and-linux-servers-into-monero-miners/ 9、2020年最大的数据泄露事件TOP10 https://securityaffairs.co/wordpress/112954/data-breach/top-10-data-breaches-2020.html 10、Ticketmaster因网络攻击竞争对手被罚款1000万美元 https://www.securityweek.com/ticketmaster-pay-10-million-fine-over-hacking-charges
网络安全日报 2020年12月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、T-Mobile数据泄露包括电话号码和通话记录等 https://securityaffairs.co/wordpress/112811/data-breach/t-mobile-data-breach-3.html 2、CISA要求美国政府机构更新SolarWinds Orion软件 https://securityaffairs.co/wordpress/112797/hacking/cisa-solarwinds-guidance-update.html 3、美财政部FinCEN警告对COVID-19疫苗研究的勒索软件攻击 https://securityaffairs.co/wordpress/112783/security/ransomware-covid-19-vaccine-research.html 4、恶意行为者劫持用户的智能设备进行网络直播 https://threatpost.com/fbi-warn-home-security-devices-swatting/162678/ 5、Wasabi云存储服务因托管恶意软件而服务中断 https://www.bleepingcomputer.com/news/security/wasabi-cloud-storage-service-knocked-offline-for-hosting-malware/ 6、Voyager加密货币经纪平台遭网络攻击暂停交易 https://www.bleepingcomputer.com/news/security/voyager-cryptocurrency-broker-halted-trading-due-to-cyberattack/ 7、GenRx Pharmacy遭勒索软件攻击导致HIPAA数据泄露 https://portswigger.net/daily-swig/genrx-pharmacy-ransomware-attack-leads-to-hipaa-data-breach-disclosure 8、安特卫普通用医学实验室遭勒索软件攻击 https://www.brusselstimes.com/news/belgium-all-news/147433/antwerp-laboratory-becomes-latest-victim-of-cyber-attack 9、索引服务和文件共享网站NZBGeek遭攻击整个数据库被窃取 https://www.hackread.com/usenet-indexer-nzbgeek-hacked-database-stolen/ 10、金银谷社区学院通知用户数据泄露 https://www.prnewswire.com/news-releases/treasure-valley-community-college-notifies-consumers-of-data-security-incident-301199086.html
网络安全日报 2020年12月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SolarWinds攻击者目标是受害者的云资产 https://securityaffairs.co/wordpress/112773/hacking/solarwinds-solorigate-attack-chain.html 2、日本川崎重工披露安全漏洞和数据泄露 https://securityaffairs.co/wordpress/112765/data-breach/kawasaki-heavy-industries-cyber-attack.html 3、CISA发布工具检测Azure,Microsoft 365中的恶意活动 https://securityaffairs.co/wordpress/112751/security/cisa-azure-microsoft-365-detection-tool.html 4、芬兰确认黑客入侵国会议员的电子邮件帐户 https://securityaffairs.co/wordpress/112731/cyber-warfare-2/finland-security-breach.html 5、Google文档修复了可允许黑客查看你私人文档的漏洞 https://thehackernews.com/2020/12/a-google-docs-bug-could-have-allowed.html 6、针对COVID-19 IP(知识产权)的盗窃攻击激增 https://threatpost.com/hackers-amp-up-covid-19-ip-theft-attacks/162634/ 7、基于AutoHotkey(AHK)的密码窃取攻击针对美国和加拿大银行用户 https://thehackernews.com/2020/12/autohotkey-based-password-stealer.html 8、Neopets虚拟宠物网站泄露了大量敏感数据 https://securityledger.com/2020/12/neopets-is-still-a-thing-and-its-exposing-sensitive-data/ 9、英国NCA访问WeLeakInfo用户,警告他们使用被盗数据 https://www.bleepingcomputer.com/news/security/uk-nca-visits-weleakinfo-users-to-warn-of-using-stolen-data/ 10、Zix收购云备份和恢复提供商CloudAlly以保护SaaS数据 https://searchdatabackup.techtarget.com/news/252494141/Zix-acquires-CloudAlly-backup-for-SaaS-data-protection
网络安全日报 2020年12月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、意大利移动服务提供商Ho mobile的数据库在地下论坛出售 https://securityaffairs.co/wordpress/112740/data-breach/ho-mobile-data-leak.html 2、美国家电制造商Whirlpool受Nefilim勒索软件攻击并泄露数据 https://securityaffairs.co/wordpress/112722/cyber-crime/whirlpool-nefilim-ransomware.html 3、欧洲电商21 Buttons泄露了数百万用户的数据 https://securityaffairs.co/wordpress/112701/data-breach/button-21-data-leak.html 4、一个新的SolarWinds漏洞可被执行远程攻击 https://thehackernews.com/2020/12/a-new-solarwinds-flaw-likely-had-let.html 5、网络钓鱼活动窃取超过61.5万Facebook用户凭据 https://threatnix.io/blog/large-scale-phishing-campaign-affecting-615000-users-worldwide/ 6、钓鱼邮件冒充美国邮政服务窃取用户信用卡凭据 https://abnormalsecurity.com/blog/usps-credential-phishing/ 7、研究人员发现新恶意软件与MuddyWater小组有关 https://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-payload-from-imgur-pic/ 8、多平台支付卡窃取器针对针对Shopify,BigCommerce等多个商店 https://securityaffairs.co/wordpress/112713/hacking/multi-platform-card-skimmer.html 9、HelpSystems收购了数据保护公司Vera https://www.securityweek.com/helpsystems-acquires-data-protection-firm-vera 10、苏格兰环境保护局遭到网络攻击 https://news.stv.tv/scotland/scottish-environment-protection-agency-targeted-in-cyberattack
网络安全日报 2020年12月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SolarWinds发布有关SUPERNOVA后门的公告 https://securityaffairs.co/wordpress/112668/security/solarwinds-supernova-malware-advisory.html 2、HackerOne宣布第一个获得超200万美元赏金的白帽子 https://securityaffairs.co/wordpress/112678/hacking/hackerone-bug-bounty-hunter-2m.html 3、佛蒙特州医院证实了遭勒索软件攻击 https://securityaffairs.co/wordpress/112694/malware/vermont-hospital-ransomware-attack.html 4、CrowdStrike发布免费的Azure安全工具 https://securityaffairs.co/wordpress/112628/security/crowdstrike-azure-tool.html 5、The Hospital Group遭到REvil勒索软件攻击 https://securityaffairs.co/wordpress/112637/cyber-crime/the-hospital-group-revil.html 6、日本游戏开发商Koei Tecmo遭黑客入侵数据泄露 https://www.bleepingcomputer.com/news/security/koei-tecmo-discloses-data-breach-after-hacker-leaks-stolen-data/ 7、研究人员发现新的恶意活动滥用Chrome扩展 https://www.kaspersky.com/blog/chrome-plugins-alert/38242/ 8、Citrix确认DDoS攻击针对ADC网络设备 https://securityaffairs.co/wordpress/112597/hacking/citrix-ddos.html 9、基于VBA的攻击技术越来越多被利用 https://cyware.com/news/attackers-increasingly-adopting-vba-based-attack-techniques-b0ba9e55 10、僵尸网络Gitpaste-12增加了新功能 https://cyware.com/news/gitpaste-12-adds-new-features-to-its-arsenal-b4c23625
网络安全日报 2020年12月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、FireEye被盗工具所利用的漏洞可以攻击数百万台设备 https://securityaffairs.co/wordpress/112588/hacking/fireeye-tools-exploits.html 2、Project Zero公开微软超90天未修复Windows 零日漏洞信息 https://securityaffairs.co/wordpress/112578/hacking/google-windows-zero-day-flaw.html 3、QNAP修复了高危的QTS,QES和QuTS漏洞 https://www.bleepingcomputer.com/news/security/qnap-fixes-high-severity-qts-qes-and-quts-hero-vulnerabilities 4、佛蒙特州医院遭勒索软件攻击 https://www.securityweek.com/vermont-hospital-says-cyberattack-was-ransomware 5、钓鱼邮件冒充Chase的安全通知窃取用户凭据 https://www.bleepingcomputer.com/news/security/psa-active-chase-phishing-scam-pretends-to-be-fraud-alerts/ 6、研究人员发现Emotet僵尸网络的新恶意文档活动 https://cofense.com/emotet-is-back-for-the-holidays-with-updated-tactics/ 7、跨层攻击可用于DNS缓存中毒和设备跟踪 https://portswigger.net/daily-swig/cross-layer-attacks-new-hacking-technique-raises-dns-cache-poisoning-user-tracking-risk 8、F5 Labs报告称针对WordPress的暴破攻击中92%针对以色列网站 https://www.jpost.com/jpost-tech/92-percent-of-all-wordpress-attacks-are-on-israeli-sites-report-653015 9、UltraRank团伙针对数十个电子商务网站窃取支付卡数据 https://www.inforisktoday.com/ultrarank-targets-more-e-commerce-sites-a-15657 10、时尚购物社交网站21 Buttons泄露了数百万用户数据 https://www.hackread.com/fashion-marketplace-21-buttons-expose-users-data/
网络安全日报 2020年12月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现Kepware工控产品中存在严重漏洞 https://www.securityweek.com/critical-flaws-kepware-products-can-facilitate-attacks-industrial-firms 2、Lazarus针对COVID-19研究机构进行网络攻击 https://www.securityweek.com/north-korean-hackers-target-covid-19-research 3、Treck TCP / IP堆栈中的漏洞影响数百万IoT设备 https://thehackernews.com/2020/12/new-critical-flaws-in-treck-tcpip-stack.html 4、Emotet僵尸网络每天针对数十万个目标进行攻击 https://threatpost.com/emotet-returns-100k-mailboxes/162584/ 5、越南科技公司iSofH泄露了1200万患者记录 https://www.infosecurity-magazine.com/news/leaky-server-12m-medical-records/ 6、执法机构关闭三种VPN服务的网络域名和服务器 https://www.zdnet.com/article/law-enforcement-take-down-three-bulletproof-vpn-providers/ 7、SolarWinds黑客入侵美国财政部官员的电子邮件帐户 https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breached-us-treasury-officials-email-accounts/ 8、NOW: Pensions公司数据泄露影响170W客户个人信息 https://www.theregister.com/2020/12/22/data_breach_now_pensions/ 9、美国罗阿诺克学院遭网络攻击推迟春季开学时间 https://www.bleepingcomputer.com/news/security/roanoke-college-delays-spring-semester-after-cyberattack/ 10、德国Funke媒体集团遭网络攻击 https://www.washingtonpost.com/world/europe/german-regional-newspaper-group-hit-by-cyberattack/2020/12/23/236810da-4516-11eb-ac2a-3ac0f2b8ceeb_story.html
网络安全日报 2020年12月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、虚拟货币交易所EXMO通知客户资金被盗 https://www.securityweek.com/crypto-exchange-exmo-says-funds-stolen-security-incident 2、研究人员公开了SolarWinds供应链攻击受害组织名单 https://securityaffairs.co/wordpress/112555/hacking/solarwinds-victims-lists.html 3、VMware和Cisco透露受到SolarWinds供应链攻击的影响 https://securityaffairs.co/wordpress/112535/security/solarwinds-vmware-cisco.html 4、IMF研究人员称可以跟踪用户的浏览历史记录以确定信用评级 https://www.hackread.com/imf-track-your-browsing-history-credit-score/ 5、Firefox 85推出Network Partitioning功能作为反跟踪保护 https://www.zdnet.com/article/firefox-to-ship-network-partitioning-as-a-new-anti-tracking-defense/ 6、英国地铁营销系统遭入侵并被向其客户发送Trickbot的钓鱼邮件 https://cyware.com/news/subway-uk-marketing-system-hacked-to-send-trickbot-laden-phishing-emails-719ccc5b 7、新的网络钓鱼活动冒充纽约劳工部窃取公民信息 https://hotforsecurity.bitdefender.com/blog/phishing-campaign-uses-new-york-department-of-labor-logo-and-pandemic-aid-info-to-steal-private-information-24946.html 8、货运物流公司Forward Air遭Hades勒索软件攻击 https://www.bleepingcomputer.com/news/security/trucking-giant-forward-air-hit-by-new-hades-ransomware-gang/ 9、研究人员发现了假冒宠物销售网站骗取用户资金 https://www.anomali.com/blog/anomali-threat-research-warns-consumers-dont-use-bitcoin-to-buy-hatched-german-shepherds-this-holiday-season 10、Kubernetes披露了一个影响所有版本的中间人攻击漏洞 https://unit42.paloaltonetworks.com/cve-2020-8554/
网络安全日报 2020年12月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、多位新闻记者的手机被 NSO 的 iMessage 0Day Exploit 攻击 https://thehackernews.com/2020/12/iphones-of-36-journalists-hacked-using.html 2、研究人员发现Dell Wyse Thin客户端两个高危漏洞 https://thehackernews.com/2020/12/two-critical-flaws-cvss-score-10-affect.html 3、NCC Group评估发现多款智能门铃存在严重漏洞 https://threatpost.com/smart-doorbell-vulnerable-to-attack/162527/ 4、新的AridViper恶意软件针对Outlook用户 https://cyware.com/news/new-aridviper-malware-targets-outlook-users-1de90a3f 5、新版本的Gitpaste-12蠕虫僵尸网络新增30多个漏洞利用程序 https://www.bleepingcomputer.com/news/security/gitpaste-12-worm-botnet-returns-with-30-plus-vulnerability-exploits 6、研究人员调查SolarWinds供应链攻击时发现了另一个后门SUPERNOVA https://securityaffairs.co/wordpress/112512/malware/supernova-backdoor-solarwinds-hack.html 7、香精香料生产商Symrise遭Clop勒索软件攻击 https://securityaffairs.co/wordpress/112494/malware/clop-ransomware-symrise.html 8、Pay2Key勒索软件针对以色列公司 https://www.securityweek.com/iranian-hackers-target-israeli-companies-pay2key-ransomware 9、Facebook漏洞暴露Instagram用户的邮件地址 https://www.hackread.com/facebook-bug-exposed-instagram-user-email-addresses/ 10、黑客论坛上泄露了27万Ledger用户的个人信息 https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/