网络安全日报 2020年12月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware 修复Workspace ONE Access 零日漏洞 https://www.securityweek.com/vmware-patches-workspace-one-access-vulnerability-reported-nsa 2、加拿大运输公司TransLink遭到勒索软件攻击 https://www.securityweek.com/metro-vancouver-transportation-agency-translink-hit-ransomware 3、LockBit勒索软件攻击了瑞士直升机制造商Kopter https://securityaffairs.co/wordpress/111998/cyber-crime/lockbit-ransomware-kopter.html 4、跨国人力资源咨询公司Randstad NV遭Egregor勒索软件攻击 https://securityaffairs.co/wordpress/111952/cyber-crime/randstad-egregor-ransomware.html 5、有人在暗网上销售辉瑞COVID-19疫苗 https://securityaffairs.co/wordpress/111980/deep-web/pfizer-covid19-vaccine-darknet.html 6、MetaMask网络钓鱼通过谷歌广告窃取用户加密货币 https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/ 7、暗网公开320万条在线电视服务Pluto TV用户记录 https://www.technadu.com/thousands-pluto-tv-users-confirm-cybersecurity-incident/229516/ 8、伊朗黑客获取了以色列水利设施ICS访问权 https://securityaffairs.co/wordpress/111934/ics-scada/israeli-water-facility-breached.html 9、Chrome修复了多个高危漏洞 https://threatpost.com/google_chrome_bugs_patched/161907/ 10、因未及时更新Play Core库数亿安卓用户受CVE-2020-8913漏洞影响 https://securityaffairs.co/wordpress/111911/mobile-2/android-cve-2020-8913-flaw.html
网络安全日报 2020年12月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、GitHub表示某些软件生态系统中的漏洞需要数年才能解决 https://www.securityweek.com/github-says-vulnerabilities-some-ecosystems-take-years-fix 2、新版本的TrickBot可以篡改UEFI / BIOS固件 https://www.zdnet.com/article/new-trickbot-version-can-tamper-with-uefibios-firmware/ 3、施乐发布修复程序解决DocuShare中漏洞 https://threatpost.com/xerox-docushare-bugs/161791/ 4、美国房地产巨头Long & Foster遭勒索攻击泄露了客户信息 https://www.technadu.com/long-and-foster-suffered-catastrophic-data-breach-incident/228685/ 5、IBM X-Force专家警告黑客攻击COVID-19疫苗冷链相关组织 https://securityaffairs.co/wordpress/111858/apt/covid-19-cold-chain-attacks.html 6、Clop勒索运营商声称从E-Land Retail窃取了200W张信用卡数据 https://securityaffairs.co/wordpress/111842/malware/clop-ransomware-e-land.html 7、攻击者使用伪装Zoom邮件窃取凭证信息 https://threatpost.com/zoom-impersonation-attacks-credentials/161718/ 8、MANRS将对BGP安全性进行改进和加强 https://www.wired.com/story/bgp-routing-manrs-google-fix/ 9、网络钓鱼使用FINRA相似域来攻击美国证券公司 https://www.bleepingcomputer.com/news/security/phishing-targets-us-brokerage-firms-using-finra-lookalike-domain 10、思科Talos报告EIP Stack Group OpENer中的DoS和代码执行漏洞 https://blog.talosintelligence.com/2020/12/vuln-spotlight-stack-group-opener-dec-2020.html
网络安全日报 2020年12月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现2个恶意npm软件包分发njRAT木马 https://www.zdnet.com/article/malicious-npm-packages-caught-installing-remote-access-trojans/ 2、微软删除18个在网页中插入广告的恶意Edge扩展 https://www.zdnet.com/article/microsoft-removes-18-malicious-edge-extensions-for-injecting-ads-into-web-pages/ 3、对400万个Docker镜像的分析显示一半存在严重漏洞 https://www.securityweek.com/analysis-4-million-docker-images-shows-half-have-critical-vulnerabilities 4、最新发现的Turla Crutch后门用于政府攻击 https://www.securityweek.com/newly-discovered-turla-backdoor-used-government-attacks 5、Google Project Zero披露了通过Wi-Fi远程利用的iOS漏洞 https://www.securityweek.com/google-details-iphone-zero-click-exploit-allowing-theft-user-data 6、荷兰皇家骑自行车联盟批量受到的勒索攻击和数据泄露 https://portswigger.net/daily-swig/royal-dutch-cycling-union-refuses-to-pay-ransom-following-data-breach 7、研究人员发现针对Docker 服务的新挖矿软件-Xanthe https://blog.talosintelligence.com/2020/12/xanthe-docker-aware-miner.html 8、不完善的“ Go SMS Pro”补丁使其仍然暴露了数百万的用户数据 https://thehackernews.com/2020/12/incomplete-go-sms-pro-patch-left.html 9、研究人员发现利用多向量攻击和具有SSH横向移动的僵尸网络-Tsunami https://securityaffairs.co/wordpress/111761/malware/multi-vector-miner-tsunami-botnet.html 10、研究人员发现25个国家/地区使用移动间谍软件 https://www.cyberscoop.com/circles-mobile-spyware-citizen-lab/
网络安全日报 2020年12月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Magecart使用新的技术劫持PayPal交易 https://threatpost.com/magecart-hijacks-paypal-transactions/161697/ 2、Bismuth组织的间谍活动针对越南企业和政府机构 https://thehackernews.com/2020/12/nation-state-hackers-caught-hiding.html 3、医疗保健提供商AspenPointe泄露29.5万患者数据 https://www.bleepingcomputer.com/news/security/healthcare-provider-aspenpointe-data-breach-affects-295k-patients/ 4、罗克韦尔自动化产品中的漏洞使工程工作站易受攻击 https://www.securityweek.com/flaws-rockwell-automation-product-expose-engineering-workstations-attacks 5、巴西航空工业公司披露网络攻击 https://www.securityweek.com/brazilian-plane-maker-embraer-targeted-cyberattack 6、法国医药供应链管理平台Apodis Pharma泄漏1.7 TB以上机密数据 https://securityaffairs.co/wordpress/111756/data-breach/apodis-pharma-data-leak.html 7、DarkIRC僵尸网络正在积极利用WebLogic CVE-2020-14882 漏洞 https://securityaffairs.co/wordpress/111743/hacking/darkirc-oracle-weblogic-cve-2020-14882.html 8、Shirbit保险公司遭网络攻击后泄露用户信息 https://www.jpost.com/israel-news/personal-information-leaked-in-suspected-cyberattack-on-shirbit-insurance-650781 9、在线学习公司K12 Inc.遭勒索软件攻击后支付了赎金 https://www.securityweek.com/online-learning-company-k12-paying-ransom-following-ransomware-attack 10、巴尔的摩县学校在勒索软件攻击后被迫关校 https://securityaffairs.co/wordpress/111732/cyber-crime/baltimore-county-schools-ransomware.html
网络安全日报 2020年12月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现RTA的ENIP堆栈存在严重漏洞 https://securityaffairs.co/wordpress/111646/ics-scada/automation-systems-opens-flaw.html 2、执法机构阻止了暗网上大规模的被盗信用数据交易 https://www.hackread.com/authorities-disrupt-dark-web-credit-card-trading-scam/ 3、特拉华县向DoppelPaymer勒索软件团伙支付赎金 https://www.bleepingcomputer.com/news/security/pennsylvania-county-pays-500k-ransom-to-doppelpaymer-ransomware/ 4、研究人员发现OceanLotus 组织使用了新的macOS后门 https://threatpost.com/macos-users-targeted-oceanlotus-backdoor/161655/ 5、WebKit浏览器内核存在多个漏洞可被进行远程代码执行 https://www.securityweek.com/webkit-vulnerabilities-allow-remote-code-execution-malicious-websites 6、媒体制作巨头Banijay遭勒索软件攻击 https://www.securityweek.com/media-production-giant-banijay-hit-ransomware 7、研究人员发现多家厂商的SD-WAN产品严重漏洞 https://www.securityweek.com/sd-wan-product-vulnerabilities-allow-hackers-steer-traffic-shut-down-networks 8、研究人员在Schneider Electric StruxureWare中发现6个零日漏洞 https://securityaffairs.co/wordpress/111692/hacking/schneider-electric-zero-days.html 9、恶意软件绕过DNA筛选并导致“生物黑客”攻击 https://securityaffairs.co/wordpress/111681/hacking/biohacking-attacks-dna-screening.html 10、TrickBot在遭拆除后已经迅速修复和重新发展 https://www.cyberscoop.com/trickbot-status-microsoft-cyber-command-takedown/
网络安全日报 2020年11月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、TurkeyBombing针对Zoom用户 https://threatpost.com/turkeybombing-zoom-abuse/161646/ 2、佳能披露2020年8月遭勒索软件攻击导致数据被盗 https://www.securityweek.com/canon-says-data-stolen-august-2020-ransomware-attack 3、ACROS Security发布针对Windows 7零日漏洞的非官方补丁 https://www.securityweek.com/unofficial-patch-released-windows-7-zero-day-vulnerability 4、Drupal发布带外安全更新修复远程代码执行漏洞 https://www.securityweek.com/drupal-releases-out-band-security-updates-due-availability-exploits 5、安全研究人员解释如何防范SMB中继攻击 https://heimdalsecurity.com/blog/what-is-an-smb-relay-attack/ 6、Bandook恶意软件发动对多个行业的新一轮攻击 https://thehackernews.com/2020/11/digitally-signed-bandook-malware-once.html 7、黑客正在出售数百名高管的电子邮件账户密码 https://www.zdnet.com/article/a-hacker-is-selling-access-to-the-email-accounts-of-hundreds-of-c-level-executives/ 8、网络犯罪组织利用黑匣子攻击技术意大利的ATM机中盗走了80万欧元 https://securityaffairs.co/wordpress/111659/cyber-crime/black-box-attack-italy.html 9、IIoT芯片制造商Advantech遭Conti勒索软件攻击 https://securityaffairs.co/wordpress/111606/security/advantech-conti-ransomware.html 10、工业自动化系统易受黑客的远程攻击 https://securityaffairs.co/wordpress/111646/ics-scada/automation-systems-opens-flaw.html
网络安全日报 2020年11月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、澳大利亚法律服务提供商遭受勒索软件攻击 https://www.itnews.com.au/news/law-in-order-hit-by-ransomware-attack-558197 2、Stantinko僵尸网络正在针对Linux服务器 https://thehackernews.com/2020/11/stantinko-botnet-now-targeting-linux.html 3、黑客利用与FBI相似的域名窃取用户信息 https://www.securityweek.com/fbi-warns-spoofed-fbi-related-domains 4、丹麦最大的新闻通讯社Ritzau遭到勒索软件攻击 https://securityaffairs.co/wordpress/111507/cyber-crime/ritzau-ransomware-attack.html 5、网络安全公司Sophos遭数据泄露 https://securityaffairs.co/wordpress/111495/data-breach/sophos-data-leak.html 6、安全研究人员发现Windows 7和Server 2008中的零日漏洞 https://securityaffairs.co/wordpress/111485/hacking/windows-7-server-2008-0day.html 7、Acronis与世界经济论坛合作打击全球网络犯罪 https://www.infosecurity-magazine.com/news/acronis-world-economic-forum?&web_view=true 8、印度在线求职网站IIMJobs的140万条记录在暗网上出售 https://inc42.com/buzz/data-of-1-4-mn-users-on-iimjobs-allegedly-leaked-on-dark-web/ 9、澳大利亚间谍机构收集了COVID-19应用程序数据 https://techcrunch.com/2020/11/24/australia-spy-agencies-covid-19-app-data/ 10、新的 Egregor勒索软件加入Maze https://www.infosecurity-magazine.com/news/egregor-ransomware-steps-maze/
网络安全日报 2020年11月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究团队发现3.8亿条涉及Spotify用户数据的记录 https://www.vpnmentor.com/blog/report-spotify-scam/2、房地产公司科可兰集团大量客户信息遭受泄露 https://securethoughts.com/real-estate-firm-exposed-vast-database-to-meow-bot-attack/3、黑客组织Anonymous攻击了乌干达警察网站 https://www.infosecurity-magazine.com/news/anonymous-hacks-uganda-police/4、研究人员发现多款视频门铃存在多个安全漏洞 https://www.darkreading.com/iot/security-researchers-sound-alarm-on-smart-doorbells/d/d-id/13395235、cPanel修复了2FA绕过漏洞 https://www.securityweek.com/2fa-bypass-vulnerability-patched-cpanel-webhost-manager6、网络和电缆制造商Belden披露数据泄露 https://www.securityweek.com/belden-discloses-data-breach-affecting-employee-business-information7、研究人员用激光入远距离入侵控制Amazon Alexa设备 https://threatpost.com/light-based-attacks-digital-home/161583/8、MobileIron 移动设备管理系统存在高危漏洞 https://threatpost.com/critical-mobileiron-rce-flaw-attack/161600/9、安全研究人员发现CNAME配置错误使数千个组织易受子域接管攻击 https://portswigger.net/daily-swig/rampant-cname-misconfiguration-leaves-thousands-of-organizations-open-to-subdomain-takeover-attacks-nbsp-research10、NPM中的Frenchbread Private-ip存在输入验证错误可导致SSRF攻击 https://securityledger.com/2020/11/exploitable-flaw-in-npm-private-ip-app-lurks-everywhere-anywhere/
网络安全日报 2020年11月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现新的CursedGrabber恶意软件 https://securityaffairs.co/wordpress/111321/malware/cursedgrabber-malware-campaign.html 2、英国国会议员每月受到近三百万次电子邮件攻击 https://www.infosecurity-magazine.com/news/mps-bombarded-three-million-email/ 3、黑客诱骗GoDaddy员工以更改某些加密货币网站的DNS设置 https://www.securityweek.com/hackers-trick-godaddy-employees-operation-targeting-cryptocurrency-services 4、cPanel中的2FA绕过漏洞影响上千万网站 https://securityaffairs.co/wordpress/111415/hacking/2fa-bypass-cpanel.html 5、新Stantinko Bot伪造成httpd针对Linux服务器 https://securityaffairs.co/wordpress/111393/malware/stantinkos-linux-variant.html 6、Microsoft通过带外更新修复了Kerberos身份验证问题 https://securityaffairs.co/wordpress/111375/security/microsoft-kerberos-authentication-issues.html 7、TA416 APT使用由Golang编写的PlugX恶意软件加载程序 https://threatpost.com/ta416-apt-plugx-malware-variant/161505/ 8、新的WAPDropper恶意软件针对Android用户进行WAP欺诈 https://www.zdnet.com/article/new-wapdropper-malware-abuses-android-devices-for-wap-fraud/ 9、百度两款应用程序因隐私策略被Google Play下架 https://www.zdnet.com/article/baidus-android-apps-caught-collecting-sensitive-user-details/ 10、活动票务平台Peatix的420万用户数据在线泄露 https://www.zdnet.com/article/hacker-leaks-the-user-data-of-event-management-app-peatix/
网络安全日报 2020年11月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员表明特斯拉Model X可能在几分钟内被盗 https://www.securityweek.com/researchers-show-tesla-model-x-can-be-stolen-minutes 2、VMware披露 Workspace One组件中的0day漏洞 https://securityaffairs.co/wordpress/111355/security/vmware-cve-2020-4006-zero-day.html 3、TikTok修复了可能导致帐户接管的安全漏洞 https://securityaffairs.co/wordpress/111336/hacking/tiktok-domains-security-flaws.html 4、基督教信仰应用Pray.com泄露超1000W用户数据 https://threatpost.com/10m-impacted-pray-com-data-exposure/161459/ 5、Spotify用户遭凭证填充攻击 https://threatpost.com/spotify-account-takeovers/161495/ 6、ImageMagick 被发现 Shell 注入漏洞 https://portswigger.net/daily-swig/imagemagick-pdf-parsing-flaw-allowed-attacker-to-nbsp-execute-shell-commands-via-maliciously-crafted-image 7、GitHub修复了Google发现的高危漏洞 https://www.zdnet.com/article/github-fixes-high-severity-security-flaw-spotted-by-google/ 8、韩国零售集团E-Land Group遭勒索软件攻击被迫关闭一半商店 https://www.koreatimes.co.kr/www/tech/2020/11/694_299692.html 9、下一代WAF将取代传统的Web应用程序防火墙 https://thehackernews.com/2020/11/why-replace-traditional-web-application.html 10、Drupal存在文件解析漏洞 https://www.helpnetsecurity.com/2020/11/23/cve-2020-13671/