网络安全日报 2020年11月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、勒索软件运营商可能利用最新WebLogic漏洞 https://www.securityweek.com/recent-weblogic-vulnerability-likely-exploited-ransomware-operators 2、朝鲜黑客利用Torisma间谍软件进行攻击 https://thehackernews.com/2020/11/north-korean-hackers-used-torisma.html 3、英国房产商Flagship遭受勒索软件攻击 https://www.theregister.com/2020/11/06/revil_sodinokibi_ransomware_gang_flagship_group_housing/ 4、巴西高等司法法院遭受大规模勒索软件攻击 https://www.hackread.com/ransomware-attack-brazil-top-court-encrypts-backups/ 5、黑客正积极利用Oracle的RCE漏洞部署Cobalt Strike https://www.bleepingcomputer.com/news/security/critical-bug-actively-used-to-deploy-cobalt-strike-on-oracle-servers/ 6、7500个组织的网络访问权限在多个黑客论坛上出售 https://cybernews.com/security/7500-educational-organizations-hacked-access-being-sold-on-russian-hacker-forums/ 7、NETGEAR路由器和WD NAS设备在 Tokyo 2020上被攻破 https://www.securityweek.com/netgear-router-wd-nas-device-hacked-first-day-pwn2own-tokyo-2020 8、与丝绸之路相关的价值10亿美元的比特币被没收 https://www.securityweek.com/us-seizes-1-billion-worth-bitcoin-connected-silk-road 9、勒索软件运营商要求Capcom支付1100万美元 https://www.securityweek.com/hackers-demand-11-million-capcom-after-ransomware-attack 10、Gitpaste-12蠕虫针对Linux服务器和IoT设备 https://threatpost.com/gitpaste-12-worm-linux-servers-iot-devices/161016/
网络安全日报 2020年11月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Maze勒索软件的客户开始利用Egregor作为的替代品 https://www.zdnet.com/article/as-maze-ransomware-group-retires-clients-turn-to-sekhmet-ransomware-spin-off-egregor/ 2、研究人员发现了Windows中的特权提升漏洞 https://www.securityweek.com/games-microsoft-store-can-be-abused-privilege-escalation-windows 3、切萨皮克地区2.3万份医疗保健数据遭到泄露 https://www.wtkr.com/news/chesapeake-regional-healthcare-alerts-over-23k-patients-after-data-security-incident 4、谷歌本周公开了影响GitHub Actions的漏洞详细信息 https://www.securityweek.com/google-discloses-details-github-actions-vulnerability 5、趋势科技修复了IMSA产品中多个漏洞 https://www.securityweek.com/trend-micro-patches-vulnerabilities-interscan-messaging-security-product 6、苹果发布了iOS 14.2,修复了三个被利用的0 day漏洞 https://securityaffairs.co/wordpress/110462/hacking/apple-ios-zero-days.html 7、过去12个月超过1200家公司的VoIP服务器被入侵滥用 https://thehackernews.com/2020/11/premium-rate-phone-fraudsters-hack-voip.html 8、黑客泄露了5.22GB的Mashable数据库 https://www.hackread.com/shinyhunters-hacker-leaks-mashable-database/ 9、Git LFS存在高危漏洞可导致Windows的系统被入侵 https://www.helpnetsecurity.com/2020/11/05/cve-2020-27955/ 10、研究人员发现用于数据分析的容器镜像存在大量漏洞 https://www.darkreading.com/application-security/containers-for-data-analysis-are-rife-with-vulnerabilities/d/d-id/1339372
网络安全日报 2020年11月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、著名的玩具制造商美泰披露受到勒索软件攻击 https://www.bleepingcomputer.com/news/security/leading-toy-maker-mattel-hit-by-ransomware/ 2、新的RegretLocker勒索软件针对Windows虚拟机 https://www.bleepingcomputer.com/news/security/new-regretlocker-ransomware-targets-windows-virtual-machines/ 3、谷歌发布了Android操作系统的每月补丁程序 https://www.securityweek.com/google-patches-30-vulnerabilities-november-2020-android-updates 4、黑客团伙利用Solaris的0day漏洞破坏企业网络 https://www.zdnet.com/article/hacker-group-uses-solaris-zero-day-to-breach-corporate-networks/ 5、自动化软件销售商SaltStack修复了三个错误 https://www.theregister.com/2020/11/04/saltstack_security/ 6、VMware修复了严重的VMware ESXi漏洞 https://www.securityweek.com/patch-critical-vmware-esxi-vulnerability-incomplete 7、日本视频游戏公司Capcom受网络攻击 https://securityaffairs.co/wordpress/110423/hacking/capcom-hit-by-cyberattack.html 8、思科披露了Cisco AnyConnect移动客户端0day漏洞及Poc https://securityaffairs.co/wordpress/110414/security/zero-day-cisco-anyconnect-secure-mobility-client.html 9、REvil Ransomware成员买下了信息窃取软件KPot的源代码 https://securityaffairs.co/wordpress/110407/malware/revil-ransomware-kpot-stealer.html 10、Cit0day.in泄露了23,600个被黑数据库 https://www.zdnet.com/article/23600-hacked-databases-have-leaked-from-a-defunct-data-breach-index-site/
网络安全日报 2020年11月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Oracle Solaris系统 0day漏洞被利用 https://threatpost.com/oracle-solaris-zero-day-attack/160929/ 2、Adobe修复了Acrobat和Reader中的多个高危漏洞 https://threatpost.com/adobe-windows-macos-critical-acrobat-reader-flaws/160903/ 3、Google修补了多个Chrome高危漏洞 https://www.securityweek.com/google-patches-actively-exploited-chrome-vulnerabilities 4、npm安全团队删除了一个名为“ twilio-npm”的恶意库 https://securityaffairs.co/wordpress/110348/malware/npm-library-backdoor.html 5、FireEye发布了一款用于威胁情报分析的虚拟机 https://www.zdnet.com/article/fireeye-releases-threatpursuit-a-windows-vm-for-threat-intel-analysts/ 6、Ryuk在2020年所有勒索软件攻击中占三分之一 https://www.helpnetsecurity.com/2020/11/03/ryuk-ransomware-2020 7、CERT / CC在Twitter上启用了CVE ID名称生成机器人 https://www.securityweek.com/certcc-seeks-remove-fear-element-named-vulnerabilities 8、2020年公开记录的数据泄露已达360亿条 https://cisomag.eccouncil.org/2020-is-the-worst-year-on-record-in-terms-of-data-breaches-survey 9、Wroba手机银行木马针对美国用户 https://www.scmagazine.com/home/security-news/wroba-mobile-banking-trojan-targets-us-smartphones 10、从第二季度到第三季度Emotet木马攻击激增了1200%以上 https://www.infosecurity-magazine.com/news/ransomware-alert-as-emotet/
网络安全日报 2020年11月3日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、新的NAT /防火墙绕过攻击可以访问任何TCP / UDP服务 https://thehackernews.com/2020/11/new-natfirewall-bypass-attack-lets.html 2、Oracle发布WebLogic漏洞CVE-2020-14750紧急补丁 https://securityaffairs.co/wordpress/110329/hacking/cve-2020-14750-weblogic-server-flaw.html 3、Maze勒索软件运营商宣布正式停止运营 https://securityaffairs.co/wordpress/110318/cyber-crime/maze-ransomware-teminates-operations.html 4、APT团体Kimsuky被发现使用新的恶意软件 https://securityaffairs.co/wordpress/110306/apt/kimsuky-apt-new-malware.html 5、美国在线金银交易商JM Bullion遭遭Magecart攻击 https://securityaffairs.co/wordpress/110290/cyber-crime/jm-bullion-hacked.html 6、英国ICO对万豪酒店2018年数据泄露处以1840W英镑罚款 https://securityaffairs.co/wordpress/110297/data-breach/uk-ico-fines-marriott.html 7、 WeWork打印管理账号被曝使用了弱口令 https://techcrunch.com/2020/11/01/wework-employees-used-an-alarmingly-insecure-printer-password/ 8、网络诈骗通过Google云端硬盘协作功能来发送恶意链接 https://threatpost.com/scammers-google-drive-malicious-links/160832/ 9、研究人员展示了可以感染机器学习模型的“无触发”后门 https://portswigger.net/daily-swig/triggerless-backdoors-can-infect-machine-learning-models-without-leaving-a-trace-research 10、TrickBot死灰复燃 https://cyware.com/news/trickbot-rises-from-the-ashes-d02b0e92
网络安全日报2020年11月2日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、安全专家已提取用于加密英特尔CPU微代码的密钥 https://arstechnica.com/gadgets/2020/10/in-a-first-researchers-extract-secret-key-used-to-encrypt-intel-cpu-code/ 2、严重的OpenEMR漏洞使黑客可以远程访问健康记录 https://www.securityweek.com/critical-openemr-vulnerabilities-give-hackers-remote-access-health-records 3、黑客正在出售从17家公司窃取的3400万份用户记录 https://www.bleepingcomputer.com/news/security/hacker-is-selling-34-million-user-records-stolen-from-17-companies/ 4、NVIDIA修补了影响多个主要供应商的AMI BMC漏洞 https://www.securityweek.com/nvidia-patches-ami-bmc-vulnerabilities-impacting-several-major-vendors 5、微软称超过10台在线计算机仍容易受到SMBGhost攻击 https://securityaffairs.co/wordpress/110247/hacking/smbghost-vulnerable-machines-dangers.html 6、REvil勒索软件入侵了游戏公司GPI https://securityaffairs.co/wordpress/110237/cyber-crime/gaming-partners-international-revil-ransomware.html7、谷歌披露了正在被利用的Windows 0day漏洞 https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html 8、WordPress发布新版修复了数十个安全漏洞 https://threatpost.com/wordpress-patches-rce-bug/160812/ 9、攻击者正在劫持普渡大学等热门高校的电子邮件帐户 https://threatpost.com/university-email-hijacking-phishing-malwarephishing-malware/160735/ 10、FreeBSD 修复 icmp6 的一个远程 UAF 漏洞 https://lists.freebsd.org/pipermail/freebsd-net/2020-October/057124.html
网络安全日报 2020年10月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、KashmirBlack僵尸网络劫持了数十万个主流CMS网站 https://thehackernews.com/2020/10/kashmirblack-botnet-hijacks-thousands.html 2、StackRox发布用于查找Kubernetes错误配置的开源工具 https://www.securityweek.com/stackrox-releases-open-source-tool-finding-kubernetes-misconfigurations 3、Hörmann制造的网关设备存在漏洞可远程打开车库门 https://www.securityweek.com/hackers-can-open-doors-exploiting-vulnerabilities-h%C3%B6rmann-device 4、FBI和CISA发布联合警报警告医疗保健部门即将面临勒索软件攻击 https://securityaffairs.co/wordpress/110147/cyber-crime/ransomware-attacks-healthcare-sector.html 5、Oracle WebLogic严重漏洞CVE-2020-14882已被在野利用 https://securityaffairs.co/wordpress/110137/hacking/weblogic-flaw-cve-2020-14882-attacks.html 6、安全厂商披露Turla APT攻击欧洲政府组织 https://securityaffairs.co/wordpress/110127/apt/turla-target-eu-gov-org.html 7、瑞典领先的安全公司Gunnebo AB遭勒索软件攻击后数据被泄露 https://www.hackread.com/mount-locker-ransomware-group-gunnebo-ab-data/ 8、伊朗组织Phosphorous攻击潜在会议参与者 https://blogs.microsoft.com/on-the-issues/2020/10/28/cyberattacks-phosphorus-t20-munich-security-conference/ 9、虚假COVID-19调查针对大学传播勒索软件 https://blog.malwarebytes.com/cybercrime/2020/10/fake-covid-19-survey-hides-ransomware-in-canadian-university-attack/ 10、Maze勒索软件正打算关闭其业务 https://www.bleepingcomputer.com/news/security/maze-ransomware-is-shutting-down-its-cybercrime-operation/
网络安全日报 2020年10月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 US-CERT披露朝鲜APT组织Kimsuky的TTP https://us-cert.cisa.gov/ncas/alerts/aa20-301a 2、网络钓鱼活动针对公共和私营部门窃取凭据 https://www.recordedfuture.com/fiercephish-credential-harvesting-campaign/ 3、家具巨头Steelcase遭到Ryuk勒索软件攻击 https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/ 4、黑客入侵安全公司窃取瑞典当局和银行数据 https://ciso.economictimes.indiatimes.com/news/swedish-authorities-banks-hit-by-security-data-leak-report/78891782 5、研究人员发现PACS服务器超过2PB医疗数据可随意访问 https://www.securityweek.com/exclusive-medical-records-35-million-us-patients-can-be-accessed-and-manipulated-anyone 6、川普竞选网站遭黑客入侵被挂索要门罗币页面 https://www.securityweek.com/trump-campaign-website-broken-hackers 7、研究人员发现新的TrickBot Linux变体 https://securityaffairs.co/wordpress/110092/cyber-crime/trickbot-linux-variant.html 8、Enel Group今年遭受了第二次勒索软件攻击 https://securityaffairs.co/wordpress/110067/malware/enel-group-netwalker-ransomware.html 9、FBI称黑客通过SonarQube从美国政府机构和企业组织窃取数据 https://www.bleepingcomputer.com/news/security/fbi-hackers-stole-government-source-code-via-sonarqube-instances/ 10、黑客利用"侵犯版权"通知钓鱼窃取Facebook凭证 https://nakedsecurity.sophos.com/2020/10/27/facebook-copyright-violation-tries-to-get-past-2fa-dont-fall-for-it/
网络安全日报 2020年10月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google从Play商店中删除了21个恶意Android应用 https://thehackernews.com/2020/10/google-android-malwar.html 2、研究人员发现Microsoft 365用户中有97%没有启用MFA https://threatpost.com/microsoft-365-admins-mfa/160592/ 3、Microsoft为Azure引入了新的密码喷涂攻击检测 https://www.securityweek.com/microsoft-introduces-new-password-spray-detection-azure 4、Enel Group今年遭受了第二次勒索软件攻击 https://securityaffairs.co/wordpress/110067/malware/enel-group-netwalker-ransomware.html 5、Fragomen律师事务所数据泄露暴露谷歌员工信息 https://techcrunch.com/2020/10/26/fragomen-data-breach-google-employees/ 6、黑客在Harvest Finance盗窃2400万美元后被发现 https://securityaffairs.co/wordpress/110043/cyber-crime/harvest-finance-cyber-heist.html 7、研究人员发现100多个运行ICC PRO的智能灌溉系统可被攻击 https://securityaffairs.co/wordpress/110032/iot/irrigation-systems-exposed-online.html 8、研究人员发现Mirai的新变体-Katana https://www.darkreading.com/iot/avira-researchers-discover-a-new-variant-of-mirai/d/d-id/1339277 9、Winston Privacy设备中存在漏洞可被远程攻击 https://www.securityweek.com/flaws-winston-privacy-devices-can-expose-networks-remote-attacks 10、亚马逊解雇了一名泄露客户信息的员工 https://threatpost.com/amazon-fires-employee-customer-data/160610/
网络安全日报 2020年10月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国制裁开发Triton的俄罗斯研究所 https://www.securityweek.com/us-treasury-sanctions-russian-institute-linked-triton-malware 2、即时通讯应用中链接预览存在隐私风险 https://thehackernews.com/2020/10/mobile-messaging-apps.html 3、英国餐馆Nando客户受到凭证填充攻击 https://www.infosecurity-magazine.com/news/nandos-customers-hit-credential/ 4、印度报业托拉斯遭到勒索软件攻击 https://www.thehindubusinessline.com/info-tech/pti-services-disrupted-after-massive-ransomware-attack-on-servers/article32940254.ece 5、芬兰心理治疗中心Vastaamo遭入侵导致数据泄露 https://www.securityweek.com/private-psychotherapy-notes-leaked-major-finnish-hack 6、Nitro PDF遭受严重数据泄露影响包括Apple,花旗银行,谷歌等公司 https://securityaffairs.co/wordpress/110025/data-breach/nitro-pdf-data-breach.html 7、安全专家发现了一个新的僵尸网络KashmirBlack https://securityaffairs.co/wordpress/110014/cyber-crime/kashmirblack-botnet.html 8、TikiWiki身份验证绕过漏洞使攻击者可以完全控制网站 https://portswigger.net/daily-swig/tikiwiki-authentication-bypass-flaw-gives-attackers-full-control-of-websites-intranets 9、研究人员警告AI安全系统存在漏洞 https://www.zdnet.com/article/australian-and-korean-researchers-warn-of-loopholes-in-ai-security-systems/ 10、HPE修复了SSMC控制台中的严重身份验证绕过漏洞 https://securityaffairs.co/wordpress/109962/security/ssmc-critical-auth-bypass-issue.html