网络安全日报 2020年11月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、GO SMS Pro暴露了数百万用户的消息
https://www.securityweek.com/go-sms-pro-exposes-messages-millions-users
2、近50,000个Fortinet VPN凭证在线泄露
https://securityaffairs.co/wordpress/111309/hacking/leak-vulnerable-fortinet-vpns.html
3、数百名女性体育明星和名人的裸体照片和视频在线泄露
https://securityaffairs.co/wordpress/111297/hacking/sports-stars-celebrities-naked-photos.html
4、圣约翰市遭大规模网络攻击破坏了整个IT市政基础设施
https://securityaffairs.co/wordpress/111259/cyber-crime/saint-john-cyber-attack.html
5、研究人员发现Apache Unomi存在RCE漏洞
https://portswigger.net/daily-swig/two-critical-bugs-in-apache-unomi-allowed-attackers-to-run-os-commands-on-vulnerable-servers
6、IBM POWER9处理器被发现数据泄露漏洞
https://www.theregister.com/2020/11/20/ibm_power9_specex_flaw/
7、QakBot银行木马开始部署新的Egregor勒索软件
https://securityaffairs.co/wordpress/111197/cyber-crime/qakbot-egregor-ransomware.html
8、英国曼联足球俱乐部的系统遭到网络攻击
https://securityaffairs.co/wordpress/111231/hacking/manchester-united-cyber-attack.html
9、VMware修补了在天府杯中被利用的严重漏洞
https://www.securityweek.com/vmware-patches-vulnerabilities-exploited-chinese-hacking-contest
10、僵尸网络在大规模扫描互联网上暴露的ENV文件
https://www.zdnet.com/article/botnets-have-been-silently-mass-scanning-the-internet-for-unsecured-env-files/
网络安全日报 2020年11月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、Emotet从银行木马演变为恶意软件分发平台
https://thehackernews.com/2020/11/anyrun-emotet-malware-analysis.html
2、GO SMS Pro存在安全漏洞可泄露用户聊天记录
https://thehackernews.com/2020/11/warning-unpatched-bug-in-go-sms-pro-app.html
3、LidarPhone攻击:利用扫地机器人LiDAR传感器窃听对话准确度达90%
https://threatpost.com/robot-vacuums-audio-lidarphone-hack/161421/
4、Google将为 Android Messages提供端到端加密
https://www.securityweek.com/google-launches-strong-encryption-android-messages
5、Drupal修复高危远程执行代码漏洞CVE-2020-13671
https://www.securityweek.com/remote-code-execution-vulnerability-patched-drupal
6、Firefox 83发布推出“HTTPS-Only”模式
https://www.securityweek.com/mozilla-boosts-security-firefox-https-only-mode
7、Palo Alto Networks推出新的5G安全产品
https://www.zdnet.com/article/palo-alto-networks-rolls-out-new-5g-security-offering/
8、REvil勒索软件要求Managed.com支付50W赎金
https://securityaffairs.co/wordpress/111154/cyber-crime/managed-com-revil-ransomware.html
9、安全研究人员开发出最快的开源IDS/IPS
https://www.darkreading.com/attacks-breaches/researchers-say-theyve-developed-fastest-open-source-ids-ips/d/d-id/1339472
10、Google要求Chrome扩展程序必须发布隐私政策
https://www.securityweek.com/google-asks-chrome-extensions-post-privacy-policies
网络安全日报 2020年11月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、微软发布针对Linux的EDR预览版本
https://www.securityweek.com/microsoft-releases-edr-linux-public-preview
2、AWS 宣布AWS Network Firewall全面上市
https://www.securityweek.com/aws-network-firewall-now-generally-available
3、思科修复了WebEx中的高危漏洞
https://securityaffairs.co/wordpress/111145/hacking/cisco-webex-meetings-flaws.html
4、安装Epsilon Framework主题的WordPress网站易受攻击
https://securityaffairs.co/wordpress/111104/hacking/epsilon-framework-themes-attacks.html
5、Chrome 87版本修复了多个高危漏洞和阻止NAT Slipstream攻击
https://threatpost.com/google-chrome-87-nat-slipstreaming-flaw/161344/
6、DarkSide勒索软件运营商宣布为会员提供分布式存储平台
https://hotforsecurity.bitdefender.com/blog/darkside-ransomware-operators-plan-to-open-distributed-storage-system-for-stolen-files-24560.html
7、虚拟主机提供商Managed.com遭勒索软件攻击
https://www.zdnet.com/article/web-hosting-provider-managed-shuts-down-after-ransomware-attack
8、Malsmoke活动利用社会工程技术传播恶意软件
https://blog.malwarebytes.com/threat-analysis/2020/11/malsmoke-operators-abandon-exploit-kits-in-favor-of-social-engineering-scheme/
9、调查数据显示2020年使用最多的密码是123456
https://www.zdnet.com/article/the-worst-passwords-of-2020-show-we-are-as-lazy-about-security-as-ever
10、Chaes Malware活动针对南美最大电商平台MercadoLivre的用户
https://securityaffairs.co/wordpress/111133/cyber-crime/chaes-malware.html
网络安全日报 2020年11月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、数百个特斯拉Powerwall网关可能受到黑客攻击
https://www.securityweek.com/hundreds-tesla-powerwall-gateways-potentially-exposed-hacker-attacks
2、Capcom证实在最近的勒索攻击中被窃取了数据
https://www.securityweek.com/capcom-confirms-hackers-stole-data-recent-attack
3、微软推出用于个人电脑的“ Pluton”安全芯片
https://www.securityweek.com/microsoft-unveils-pluton-security-processor-pcs
4、研究人员披露Cisco Security Manager中RCE漏洞
https://thehackernews.com/2020/11/researcher-discloses-critical-rce-flaws.html
5、世界冷库巨头Americold遭受了网络攻击
https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-hit-by-cyberattack-services-impacted/
6、黑客对流行的Telegram频道进行大规模攻击
https://www.itsecuritynews.info/hackers-attacked-major-telegram-channels-via-video-on-yandex/
7、微软披露超过20W个Windows系统仍易受到BlueKeep漏洞的攻击
https://securityaffairs.co/wordpress/111051/hacking/windows-vulnerable-bluekeep.html
8、区块链公司Origin Protocol遭黑客攻击
https://portswigger.net/daily-swig/origin-dollar-cryptocurrency-hacked-to-the-tune-of-7m-less-than-two-months-after-launch
9、美国银行系统(ABS)遭受到勒索软件攻击泄露50GB数据
https://securityreport.com/american-bank-systems-hit-by-ransomware-attack-full-53-gb-data-dump-leaked
10、研究人员发现AWS基于资源的策略API中存在信息泄漏漏洞
https://unit42.paloaltonetworks.com/aws-resource-based-policy-apis
网络安全日报 2020年11月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、VoltPillager:通过控制CPU电压破坏英特尔SGX的新型攻击
https://www.securityweek.com/voltpillager-new-hardware-based-voltage-manipulation-attack-against-intel-sgx
2、macOS Big Sur 11.0.1修补了60个漏洞
https://www.securityweek.com/macos-big-sur-1101-patches-60-vulnerabilities
3、制造业正在成为勒索软件攻击的主要目标
https://www.zdnet.com/article/manufacturing-is-becoming-a-major-target-for-ransomware-attacks/
4、新型skimmer攻击利用WebSocket逃避检测
https://securityaffairs.co/wordpress/110982/hacking/skimmer-attack-websockets.html
5、研究人员发现数十万被盗Facebook账号凭证
https://securityaffairs.co/wordpress/111018/cyber-crime/100k-facebook-accounts-scam.html
6、生物技术公司Miltenyi Biotec披露恶意软件攻击
https://www.securityweek.com/biotech-company-miltenyi-biotec-discloses-malware-attack
7、Citrix SD-WAN存在远程代码执行漏洞
https://threatpost.com/citrix-sd-wan-bugs-remote-code-execution/161274/
8、研究人员发现新型恶意软件:Jupyter
https://securityaffairs.co/wordpress/110967/malware/jupyter-malware.html
9、Lazarus 供应链攻击针对韩国用户
https://www.securityweek.com/lazarus-group-targets-south-korea-supply-chain-attack
10、特拉华州公共卫生部披露了数据泄露事件
https://www.databreaches.net/delaware-division-of-public-health-announces-data-breach-incident-involving-covid-19-results/
网络安全日报 2020年11月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、零售业巨头The North Face网站遭受凭证填充攻击
https://securityaffairs.co/wordpress/110952/data-breach/the-north-face-credential-stuffing.html
2、智利零售巨头Cencosud遭勒索软件攻击
https://securityaffairs.co/wordpress/110941/cyber-crime/cencosud-egregor-ransomware.html
3、Pluto TV遭入侵,320W个用户被泄露
https://securityaffairs.co/wordpress/110931/data-breach/pluto-tv-database-shinyhunters.html
4、生物技术研究公司Miltenyi Biotec披露遭勒索软件攻击
https://securityaffairs.co/wordpress/110900/malware/miltenyi-biotec-ransomware-attack.html
5、施耐德电气警告Drovorub Linux恶意软件攻击
https://www.securityweek.com/schneider-electric-warns-customers-drovorub-linux-malware
6、微软警告称三个APT小组针对7个COVID-19疫苗生产商
https://securityaffairs.co/wordpress/110871/apt/apt-groups-covid-19-vaccine.html
7、图片库网站123RF的830万条用户记录遭受泄露
https://www.bleepingcomputer.com/news/security/popular-stock-photo-service-hit-by-data-breach-83m-records-for-sale/
8、研究人员发现以太坊智能合约存在严重漏洞
https://cybernews.com/security/ethereum-smart-contract-vulnerabilities/
9、保险软件提供商Vertafore遭受了数据泄露
https://www.zdnet.com/article/info-of-27-7-million-texas-drivers-exposed-in-vertafore-data-breach/
10、加利福尼亚大学和清华大学发现一种新的DNS缓存中毒攻击-SAD DNS
https://thehackernews.com/2020/11/sad-dns-new-flaws-re-enable-dns-cache.html
网络安全日报 2020年11月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、CostaRicto APT使用新的恶意软件进行攻击
https://securityaffairs.co/wordpress/110818/apt/costaricto-apt-cyber-mercenaries.html
2、模块化PoS恶意软件ModPipe针对餐厅和酒店业
https://securityaffairs.co/wordpress/110802/hacking/modpipe-backdoor-pos.html
3、Google解决了两个新的Chrome零日漏洞
https://securityaffairs.co/wordpress/110793/hacking/google-chrome-zero-day-flaws.html
4、施耐德Electric PLC存在加密和身份验证漏洞可被黑客利用
https://www.securityweek.com/encryption-vulnerabilities-allow-hackers-take-control-schneider-electric-plcs
5、 Ubuntu修复了gdm3本地提权漏洞
https://arstechnica.com/information-technology/2020/11/ubuntu-fixes-bugs-that-standard-users-could-use-to-become-root/
6、动物果酱被入侵4600W账户信息被泄露
https://threatpost.com/animal-jam-hack-data-breach/161177/
7、研究人员发表针对飞机ADS-B信号的射频指纹识别方法
https://www.theregister.com/2020/11/10/adsb_fingerprinting_research/
8、Silver Peak SD-WAN漏洞可导致网络被接管
https://threatpost.com/silver-peak-sd-wan-bugs-network-takeover/161142
9、KuCoin首席执行官表示84%的被盗加密货币已经被追回
https://www.zdnet.com/article/kucoin-ceo-says-84-of-stolen-cryptocurrency-has-been-recovered/
10、医疗账单服务Timberline账单遭受勒索软件攻击
https://www.infosecurity-magazine.com/news/ransomware-attack-on-medical/
网络安全日报 2020年11月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、英伟达GeForce NOW中存在高危漏洞
https://threatpost.com/nvidia-windows-gamers-geforce-now-flaw/161132/
2、菲律宾COVID-KAYA应用程序泄露用户数据
https://threatpost.com/covid-19-data-leaked-healthcare-worker-info/161108/
3、Firefox,Chrome修复了在天府杯中被利用的漏洞
https://www.securityweek.com/vulnerabilities-exploited-chinese-hacking-contest-patched-firefox-chrome
4、WD研究人员发现RPMB协议存在漏洞影响多个供应商
https://www.securityweek.com/western-digital-finds-replay-attack-protection-flaw-affecting-multiple-vendors
5、Cobalt Strike 4.0 反编译源代码遭泄露
https://securityaffairs.co/wordpress/110782/hacking/cobalt-strike-source-code.html
6、巴基斯坦航空公司网络的访问权已在暗网上出售
https://www.infosecurity-magazine.com/news/hacker-sells-access-to-pakistani/
7、新的Slipstream NAT旁路攻击将被浏览器阻止
https://www.bleepingcomputer.com/news/security/new-slipstream-nat-bypass-attacks-to-be-blocked-by-browsers/
8、Muhstik僵尸网络增加了WebLogic和Drupal漏洞利用
https://securityaffairs.co/wordpress/110763/uncategorized/muhstik-botnet-weblogic-drupal.html
9、超过2800多家在线商店遭Magento信用卡窃取攻击
https://thehackernews.com/2020/11/over-2800-e-shops-running-outdated.html
10、DDoS攻击正在演变为以勒索为主导的RDoS
https://www.infosecurity-magazine.com/news/edgelive-ddos-rdos/
网络安全日报 2020年11月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、微软11月周二补丁日更新解决了110多个漏洞
https://www.securityweek.com/microsoft-patches-windows-vulnerability-chained-attacks-chrome-bug
2、研究人员披露通过监视CPU功耗来获取加密密钥的侧信道攻击
https://www.securityweek.com/platypus-hackers-can-obtain-crypto-keys-monitoring-cpu-power-consumption
3、Adobe修补了Connect,Reader Mobile中的漏洞
https://www.securityweek.com/adobe-patches-vulnerabilities-connect-reader-mobile
4、580万条RedDoorz用户记录在黑客论坛上出售
https://www.bleepingcomputer.com/news/security/58-million-reddoorz-user-records-for-sale-on-hacking-forum/
5、CERT-in向印度公司发出有关Egregor的警告
https://www.ciol.com/cert-in-warns-indian-companies-egregor-sweeps-system-organisations-steals-data/
6、恶意NPM项目窃取浏览器信息和Discord帐户
https://securityaffairs.co/wordpress/110705/hacking/malicious-npm-project-discord-dll.html
7、勒索软件利用虚假的Teams更新来部署Cobalt Strike
https://securityaffairs.co/wordpress/110693/malware/fake-microsoft-teams-cobalt-strike.html
8、卡巴斯基发现名为Ghimob的安卓木马可从112中金融APP中窃取数据
https://securityaffairs.co/wordpress/110671/cyber-crime/ghimob-banking-trojan.html
9、英特尔在周二发布了40条安全公告,涉及多个高危漏洞
https://threatpost.com/intel-update-critical-privilege-escalation-bugs/161087/
10、Ultimate Member插件漏洞影响超过2.5W个WordPress网站
https://securityaffairs.co/wordpress/110717/hacking/wordpress-ultimate-member-flaws.html
网络安全日报 2020年11月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。
1、EOL Windows源代码泄露使IOT设备易受攻击
https://unit42.paloaltonetworks.com/windows-xp-server-2003-source-code-leak/
2、攻击者仿冒HMRC的页面对英国公民进行网络诈骗
https://www.bleepingcomputer.com/news/security/hmrc-smishing-tax-scam-targets-uk-banking-customers/
3、酒店预订平台泄露Booking等在线预订网站的用户数据
https://www.hackread.com/hotel-reservation-platform-data-leak-online-booking-sites/
4、电子商务软件平台X-Cart在10月底遭受勒索软件攻击
https://securityaffairs.co/wordpress/110623/malware/x-cart-ransomware-attack.html
5、研究人员发现了Linux版本的RansomEXX勒索软件
https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/
6、windows 10,iOS,Chrome等多种产品在天府杯中被攻破
https://thehackernews.com/2020/11/windows-10-ios-chrome-firefox-and.html
7、全球第二笔记本电脑制造商仁宝遭勒索软件攻击
https://securityaffairs.co/wordpress/110638/malware/compal-ransomware-attack.html
8、xHunt黑客利用两个新后门攻击了Microsoft Exchange
https://securityaffairs.co/wordpress/110644/apt/xhunt-attackers-hit-microsoft-exchange.html
9、WordPress插件Welcart存在注入漏洞
https://threatpost.com/wordpress_open_to_attacks_welcart_bug/161037
10、Zoom Snooping - 通过视频会议时对方的肩膀移动来侧信道猜测密码
https://sec.today/pulses/c54980db-66c9-4f29-a923-509a8bbcb288/
第2页 第3页 第4页 第5页 第6页 第7页 第8页 第9页 第10页 第11页 第12页 第13页 第14页 第15页 第16页 第17页 第18页 第19页 第20页 第21页 第22页 第23页 第24页 第25页 第26页 第27页 第28页 第29页 第30页 第31页 第32页 第33页 第34页 第35页 第36页 第37页 第38页 第39页 第40页 第41页 第42页 第43页 第44页 第45页 第46页 第47页 第48页 第49页 第50页 第51页 第52页 第53页 第54页 第55页 第56页 第57页 第58页 第59页 第60页 第61页 第62页 第63页 第64页 第65页 第66页 第67页 第68页 第69页 第70页 第71页 第72页 第73页 第74页 第75页 第76页 第77页 第78页 第79页 第80页 第81页 第82页 第83页 第84页 第85页 第86页 第87页 第88页 第89页 第90页 第91页 第92页 第93页 第94页 第95页 第96页 第97页 第98页 第99页 第100页 第101页 第102页 第103页 第104页 第105页 第106页 第107页 第108页 第109页 第110页 第111页 第112页 第113页 第114页 第115页 第116页 第117页 第118页 第119页 第120页 第121页 第122页 第123页 第124页 第125页 第126页 第127页 第128页 第129页 第130页 第131页 第132页 第133页 第134页 第135页 第136页 第137页 第138页 第139页 第140页 第141页 第142页 第143页 第144页 第145页 第146页 第147页 第148页
蚁景网安学院火热招生中,限时领取大额优惠券,快来抢购吧~
扫码咨询客服了解招生最新内容和活动

