网络安全日报 2020年12月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客使用移动设备仿真器攻击银行窃取了数百万美元 https://securityaffairs.co/wordpress/112487/cyber-crime/massive-fraud-operation.html 2、SolarWinds供应链攻击曾入侵美国国家核安全局核机构 https://securityaffairs.co/wordpress/112469/hacking/nnsa-nuclear-agency-hacked.html 3、黑客针对COVID-19疫苗供应链并在Darkweb中出售疫苗 https://securityaffairs.co/wordpress/112433/hacking/covid-19-attacks-2.html 4、微软确认遭SolarWinds供应链攻击但否认其客户受到影响 https://securityaffairs.co/wordpress/112416/hacking/microsoft-breached-solarwinds-hack.html 5、CoderWare勒索软件伪装成《Cyberpunk 2077》进行传播 https://securityaffairs.co/wordpress/112412/malware/fake-cyberpunk-2077-spreads-ransomware.html 6、Bouncy Castle加密库修补了身份验证绕过漏洞 https://www.securityweek.com/authentication-bypass-vulnerability-patched-bouncy-castle-library 7、英国能源供应商People's Energy披露数据泄露 https://www.securityweek.com/uk-energy-startup-peoples-energy-discloses-data-breach 8、Joker's Stash少量服务器被FBI和国际刑警组织控制 https://www.zdnet.com/article/fbi-interpol-disrupt-jokers-stash-the-internets-largest-carding-marketplace/ 9、Pay2Key勒索软件与伊朗APT组织Fox Kitten有关 https://www.bleepingcomputer.com/news/security/iranian-nation-state-hackers-linked-to-pay2key-ransomware/ 10、Magecart组织恶意软件泄露被黑客攻击的商店列表 https://www.bleepingcomputer.com/news/security/stealthy-magecart-malware-mistakenly-leaks-list-of-hacked-stores/
网络安全日报 2020年12月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、DoppelPaymer勒索软件针对关键基础设施 https://www.securityweek.com/fbi-warns-doppelpaymer-ransomware-targeting-critical-infrastructure 2、趋势科技更新补丁修复IWSA产品中的严重漏洞 https://www.securityweek.com/trend-micro-patches-serious-flaws-product-used-companies-governments 3、GitHub将在明年禁止基于密码的Git操作身份验证 https://www.theregister.com/2020/12/17/github_bans_passwords/ 4、新证据表明SolarWinds的代码库被黑客注入了后门程序 https://thehackernews.com/2020/12/new-evidence-suggests-solarwinds.html 5、Contact Form 7 WordPress插件漏洞影响超500W个网站 https://securityaffairs.co/wordpress/112407/hacking/contact-form-7-flaw.html 6、研究人员发现了针对Instagram,Facebook等的浏览器恶意扩展 https://securityaffairs.co/wordpress/112393/malware/browser-malicious-extensions.html 7、一种利用IRS表单的网络钓鱼针对Google G Suite用户 https://www.darkreading.com/attacks-breaches/new-irs-form-fraud-campaign-targets-g-suite-users/d/d-id/1339743 8、Ryuk和Egregor勒索软件攻击利用SystemBC后门 https://threatpost.com/ryuk-egregor-ransomware-systembc-backdoor/162333/ 9、Verifone和Ingenico POS设备制造商发布漏洞补丁 https://www.inforisktoday.com/pos-device-makers-push-patches-for-vulnerabilities-a-15598 10、RubyGems仓库删除了两个恶意软件包 https://www.securityweek.com/two-malware-laced-gems-found-rubygems-repository
网络安全日报 2020年12月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、iOS间谍软件长期存在于勒索活动中 https://www.securityweek.com/ios-spyware-emerges-longstanding-extortion-campaign 2、微软,FireEye和GoDaddy合作接管SolarWinds攻击所用域名 https://securityaffairs.co/wordpress/112376/apt/solarwinds-backdoor-kill-switch.html 3、HPE披露了Systems Insight Manager中的零日漏洞 https://securityaffairs.co/wordpress/112370/security/hpe-flaw-systems-insight-manager.html 4、研究人员发现名为Goontact的间谍软件可同时监视Android和iOS用户 https://securityaffairs.co/wordpress/112351/malware/goontact-spyware-android-ios.html 5、SolarWinds发布了Orion平台漏洞修补程序 https://thehackernews.com/2020/12/solarwinds-issues-second-hotfix-for_15.html 6、研究报告5G网络存严重漏洞可跟踪用户位置和窃取数据 https://thehackernews.com/2020/12/new-5g-network-flaws-let-attackers.html 7、CybelAngel分析团队发现在线暴露的超4500万张医学图像和相关信息 https://threatpost.com/million-medical-images-online/162284/ 8、Bronze Bit Attack 可绕过Kerberos 认证 https://cyware.com/news/the-bronze-bit-attack-can-bypass-kerberos-protocol-7853a276 9、以色列公司Cellebrite可以入侵Signal https://www.haaretz.com/israel-news/tech-news/.premium-israeli-spy-tech-firm-says-it-can-break-into-signal-app-previously-considered-safe-1.9368581 10、Zebrocy恶意软件新变体使用Golang编码和VHD文件躲避安全软件 https://cyware.com/news/zebrocys-evolution-with-golang-based-version-enjoys-low-detection-d5033888
网络安全日报 2020年12月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Gitpaste-12僵尸网络针对Linux服务器和物联网设备 https://thehackernews.com/2020/12/wormable-gitpaste-12-botnet-returns-to.html 2、研究人员发现了一种通过Wi-Fi信号频段进行窃取数据的侧信道攻击-AIR-FI攻击 https://thehackernews.com/2020/12/exfiltrating-data-from-air-gapped.html 3、专家发现了一个新的Windows信息窃取软件PyMICROPSIA https://securityaffairs.co/wordpress/112335/apt/pymicropsia-malware.html 4、Medtronic MyCareLink存在漏洞可使攻击者控制植入的心脏设备 https://securityaffairs.co/wordpress/112328/hacking/medtronic-mycarelink-flaws.html 5、攻击者利用SolarWinds 攻击绕过MFA访问美国智库的电子邮件 https://www.securityweek.com/group-behind-solarwinds-hack-bypassed-mfa-access-emails-us-think-tank 6、数百万的工业设备受Urgent / 11漏洞和CDPwn漏洞影响 https://www.securityweek.com/vast-majority-ot-devices-affected-urgent11-vulnerabilities-still-unpatched 7、Firefox修补了严重的漏洞,也影响Google Chrome https://threatpost.com/firefox-patches-critical-mystery-bug-also-impacting-google-chrome/162294/ 8、Spotify遭数据泄露后强制用户更改密码 https://threatpost.com/spotify-changes-passwords-data-breach/162256/ 9、越来越多的制造业成为网络攻击目标 https://cyware.com/news/cyber-threats-crawling-across-manufacturing-organizations-3b967aaf 10、钓鱼邮件冒充eFax等企业窃取用户Office 365凭证 https://abnormalsecurity.com/blog/spear-phishing-campaign-targets-enterprises/
网络安全日报 2020年12月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、SolarWinds确认可能有18,000个客户受供应链攻击影响 https://securityaffairs.co/wordpress/112294/hacking/solarwinds-sec-filing.html 2、美多个政府机构和公司因SolarWinds软件供应链攻击而被黑客入侵 https://securityaffairs.co/wordpress/112275/apt/solarwinds-supply-chain-attack.html 3、机器人流程自动化供应商UiPath披露数据泄露 https://securityaffairs.co/wordpress/112267/data-breach/uipath-data-leak.html 4、Apple修复了iOS和iPadOS的代码执行漏洞 https://www.securityweek.com/apple-patches-code-execution-flaws-ios-and-ipados 5、挪威邮轮公司Hurtigruten遭勒索软件攻击 https://www.securityweek.com/norwegian-cruise-company-hurtigruten-hit-cyberattack 6、Sophos和ReversingLabs发布了2000万样本数据集用于恶意软件研究 https://github.com/sophos-ai/SOREL-20M 7、研究人员发现新的Windows 木马窃取浏览器凭据和Outlook文件 https://threatpost.com/windows-trojan-steals-browser-credentials-outlook-files/162223/ 8、研究人员发现Steam漏洞允许远程接管用户计算机 https://www.hackread.com/steam-vulnerabilities-remote-take-over-users-computers/ 9、谷歌周一遭全球大规模宕机,YouTube和Gmail等服务中断 https://techcrunch.com/2020/12/14/gmail-youtube-google-docs-and-other-services-go-down-simultaneously-in-multiple-countries/ 10、专家发现WinZip 24的不安全通信可被黑客利用 https://cybersguards.com/insecure-communication-from-winzip-24-lets-hackers-drop-malware/
网络安全日报 2020年12月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WordPress SMTP插件中的零日漏洞被修复 https://securityaffairs.co/wordpress/112156/hacking/kerberos-bronze-bit-attack.html 2、攻击者公开了属于松下印度公司的4GB数据 https://www.zdnet.com/article/zero-day-in-wordpress-smtp-plugin-abused-to-reset-admin-account-passwords/ 3、TSYS公司遭到Conti勒索软件攻击数据泄露 https://www.govinfosecurity.com/panasonic-indias-data-released-in-extortion-plot-a-15573 4、Pay2Key勒索软件窃取了英特尔Habana Labs的数据 https://securityaffairs.co/wordpress/112258/data-breach/pay2key-hacked-habana-labs.html 5、英国地铁(Subway UK)销售系统遭黑客入侵 https://securityaffairs.co/wordpress/112248/data-breach/subway-uk-trickbot-phishing.html 6、NI控制器中的漏洞可能允许黑客远程中断生产 https://www.securityweek.com/vulnerability-ni-controller-can-allow-hackers-remotely-disrupt-production 7、研究人员发现Adrozek恶意软件劫持多种主流浏览器 https://thehackernews.com/2020/12/watch-out-adrozek-malware-hijacking.html 8、Microsoft Office安全更新修复了关键的SharePoint RCE漏洞 https://www.bleepingcomputer.com/news/security/microsoft-office-security-updates-fix-critical-sharepoint-rce-bugs/ 9、Mount Locker勒索软件为其他黑客提供双重勒索方案 https://thehackernews.com/2020/12/mount-locker-ransomware-offering-double.html 10、Facebook封禁越南APT组织海莲花相关账户 https://thehackernews.com/2020/12/facebook-tracks-apt32-oceanlotus.html
网络安全日报 2020年12月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科修复了Jabber中的严重RCE漏洞 https://securityaffairs.co/wordpress/112163/hacking/cisco-jabber-rce.html 2、Kerberos Bronze Bit攻击PoC已在线发布 https://securityaffairs.co/wordpress/112156/hacking/kerberos-bronze-bit-attack.html 3、njRAT RAT利用Pastebin 作为C2隧道来避免检测 https://securityaffairs.co/wordpress/112147/cyber-crime/njrat-rat-pastebin-c2.html 4、研究人员发现针对PDF文件的新型注入攻击技术 https://www.securityweek.com/new-injection-technique-exposes-data-pdfs 5、勒索软件攻击联网的MySQL数据库 https://www.securityweek.com/ransomware-gang-hits-exposed-mysql-databases 6、Valve修复了Steam游戏客户端中的严重漏洞 https://threatpost.com/critical-steam-flaws-crash-opponents-computers/162100/ 7、MoleRats APT使用Facebook,Dropbox作为C2隧道 https://threatpost.com/molerats-apt-espionage-facebook-dropbox/162162/ 8、攻击者利用”免费Cyberpunk 2077“进行信息收集和安装恶意软件 https://threatpost.com/free-cyberpunk-2077-downloads/161963/ 9、PGMiner:利用PostgreSQL漏洞的挖矿僵尸网络 https://unit42.paloaltonetworks.com/pgminer-postgresql-cryptocurrency-mining-botnet/ 10、星巴克移动平台中发现了远程代码执行漏洞 https://www.zdnet.com/article/remote-code-execution-vulnerability-uncovered-in-starbucks-mobile-platform/
网络安全日报 2020年12月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Android 本月补丁修复 Wi-Fi 组件高危漏洞 https://threatpost.com/google-patches-critical-wi-fi-and-audio-bugs-in-android-handsets/162060/ 2、Google 将对能证明可利用性的 V8 Exploit 提供额外奖金 https://security.googleblog.com/2020/12/announcing-bonus-rewards-for-v8-exploits.html 3、D-Link路由器被发现零日漏洞 https://threatpost.com/d-link-routers-zero-day-flaws/162064/ 4、安全研究人员发现多种TCP / IP栈存在漏洞影响数百万物联网设备 https://threatpost.com/amnesia33-tcp-ip-flaws-iot-devices/161928/ 5、微软发布2020年12月更新修复58个安全漏洞 https://thehackernews.com/2020/12/microsoft-releases-windows-update-dec.html 6、APT28使用COVID-19疫苗钓鱼邮件分发Zebrocy恶意软件 https://thehackernews.com/2020/12/russian-apt28-hackers-using-covid-19-as.html 7、暗网上泄露了印度700万银行持卡人的信息 https://ciso.economictimes.indiatimes.com/news/data-of-70-lakh-indian-cardholders-leaked-on-dark-web/79640281 8、欧洲药品管理局遭到网络攻击 https://securityaffairs.co/wordpress/112125/intelligence/european-medicines-agency-cyberattack.html 9、研究人员发现了一种将信用卡窃取器隐藏在CSS文件中的新技术 https://securityaffairs.co/wordpress/112117/malware/skimmer-inside-css-files.html 10、所有Kubernetes版本均受未修补的MiTM漏洞影响 https://threatpost.com/microsoft-patch-tuesday-holidays/162041/
网络安全日报 2020年12月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、大规模的网络钓鱼活动针对全球2亿多Microsoft 365用户 https://www.darkreading.com/threat-intelligence/phishing-campaign-targets-200m-microsoft-365-accounts/d/d-id/1339637 2、QNAP修复了八个可能导致NAS设备被接管的漏洞 https://securityaffairs.co/wordpress/112041/security/qnap-nas-flaws.html 3、Apache发布Struts 2安全更新修复远程代码执行漏洞 https://www.securityweek.com/possible-code-execution-flaw-apache-struts 4、网络安全公司FireEye遭攻击被盗走一系列红队工具 https://www.securityweek.com/fireeye-says-sophisticated-hacker-stole-red-team-tools 5、研究人员发现Rana Android恶意软件新变种 https://threatpost.com/rana-android-malware-updates-allow-whatsapp-telegram-im-snooping/161971/ 6、黑客强行打开莫斯科各地2732个快递寄存柜 https://www.zdnet.com/article/hacker-opens-2732-pickpoint-package-lockers-across-moscow/ 7、PlayStation Now云游戏Windows应用存在漏洞 https://www.bleepingcomputer.com/news/security/playstation-now-bugs-let-sites-run-malicious-code-on-windows-pcs/ 8、严重漏洞影响100多种GE Healthcare设备 https://www.securityweek.com/over-100-ge-healthcare-devices-affected-critical-vulnerability 9、OpenSSL发布“高危”安全补丁 https://www.securityweek.com/openssl-ships-%E2%80%98high-severity%E2%80%99-security-patch 10、安全专家披露了Microsoft Teams中一个可蠕虫零交互漏洞 https://securityaffairs.co/wordpress/112062/hacking/microsoft-teams-wormable-flaw.html
网络安全日报 2020年12月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Skimmer攻击团伙利用Raccoon恶意软件窃取信息 https://thehackernews.com/2020/12/payment-card-skimmer-group-using.html 2、哈萨克斯坦政府利用数字证书拦截公民HTTPS流量 https://www.zdnet.com/article/kazakhstan-government-is-intercepting-https-traffic-in-its-capital/ 3、富士康墨西哥工厂遭DoppelPaymer勒索软件攻击 https://securityaffairs.co/wordpress/112033/cyber-crime/foxconn-doppelpaymer-ransomware.html 4、Cisco Security Manager修复了可利用的RCE https://securityaffairs.co/wordpress/112023/security/cisco-security-manager-flaws.html 5、美国巴尔的摩市区医疗中心遭到勒索软件攻击 https://securityaffairs.co/wordpress/112017/malware/greater-baltimore-medical-center-ransomware.html 6、美国和澳大利亚共同开发网络攻击训练平台 https://securityaffairs.co/wordpress/111988/cyber-warfare-2/us-cyber-command-iwd-cyber-range.html 7、NSA警告称俄罗斯黑客正在利用最近修补的VMware漏洞 https://www.securityweek.com/russian-hackers-exploiting-recently-patched-vmware-flaw-nsa-warns 8、Google推出XS-Leaks知识库普及跨站泄露网络安全知识 https://www.securityweek.com/google-launches-xs-leaks-vulnerability-knowledge-base 9、RansomExx勒索软件团伙在暗网发布巴西航空工业公司数据 https://threatpost.com/ransomexx-ransomware-gang-dumps-stolen-embraer-data-report/161918/ 10、Flight Center泄露了近7000名客户的个人详细信息 https://www.zdnet.com/article/oaic-finds-flight-centre-breached-privacy-of-almost-7000-customers-in-2017/