网络安全日报 2023年01月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、欧洲金融和保险业成为Raspberry Robin蠕虫的攻击目标 https://thehackernews.com/2023/01/raspberry-robin-worm-evolves-to-attack.html 2、报告显示2022年美国105个地方政府遭到勒索软件攻击 https://securityaffairs.com/140242/cyber-crime/ransomware-attacks-emsisoft-report-2022.html 3、黑客论坛出售据称从沃尔沃汽车公司窃取的数据 https://securityaffairs.com/140258/hacking/volvo-cars-data-breach-2.html 4、马来西亚下令调查涉嫌影响约1300万公民的大规模数据泄露事件 https://www.govinfosecurity.com/malaysian-agencies-investigate-alleged-breach-affecting-13-million-a-20839 5、Synology 修复其路由器中的多个严重漏洞 https://securityaffairs.com/140288/security/synology-fixes-critical-flaws-routers.html 6、加拿大铜山矿业公司 (CMMC) 在勒索软件攻击后关闭了工厂 https://securityaffairs.com/140282/cyber-crime/canadian-cmmc-ransomware-attack.html 7、BitRAT 恶意活动利用被盗的敏感银行数据作为诱饵 https://securityaffairs.com/140268/malware/bitrat-bank-data-lures.html 8、谷歌将支付2950万美元解决用户位置跟踪诉讼 https://thehackernews.com/2023/01/google-to-pay-295-million-to-settle.html 9、Chrome浏览器将阻止用户通过不安全HTTP链接下载文件 https://www.anquanke.com/post/id/284830 10、2022年在Windows平台上发现了近 7000 万个新恶意软件样本 https://www.secrss.com/articles/50626
网络安全日报 2023年01月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google Home智能扬声器存在漏洞可导致黑客窥探设备 https://www.bleepingcomputer.com/news/security/google-home-speakers-allowed-hackers-to-snoop-on-conversations/ 2、LockBit勒索组织针对葡萄牙里斯本港进行网络攻击 https://therecord.media/port-of-lisbon-website-still-down-as-lockbit-gang-claims-cyberattack/ 3、Netgear公司建议用户修补最近修复的WiFi路由器高危漏洞 https://www.bleepingcomputer.com/news/security/netgear-warns-users-to-patch-recently-fixed-wifi-router-bug/ 4、研究人员披露SNI代理错误配置可导致SSRF漏洞 https://www.invicti.com/blog/web-security/ssrf-vulnerabilities-caused-by-sni-proxy-misconfigurations/ 5、加拿大矿业公司遭受勒索软件攻击后关闭工厂 https://www.bleepingcomputer.com/news/security/canadian-mining-firm-shuts-down-mill-after-ransomware-attack/ 6、研究人员表示2022年的大规模DDoS攻击增加了81% https://cyware.com/news/large-volume-ddos-attacks-increases-by-81-in-2022-0a9d8cbd 7、PyTorch识别出一个假冒的torchtriton依赖项 https://www.bleepingcomputer.com/news/security/pytorch-discloses-malicious-dependency-chain-compromise-over-holidays/ 8、Lockbit 为 SickKids 儿科医院的攻击道歉并发布免费解密器 https://securityaffairs.com/140193/cyber-crime/lockbit-apologized-attack-sickkids.html 9、PureCoder黑客组织在暗网上出售多种恶意软件 https://cyware.com/news/multiple-malware-for-sale-on-darkweb-forums-d7b8c587 10、新的 Linux 恶意软件通过利用 30 个漏洞来攻击 WordPress 网站 https://securityaffairs.com/140153/cyber-crime/linux-malware-wordpress-websites.html
网络安全日报 2022年12月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、上千台Citrix服务器受到多个严重安全漏洞的影响 https://www.bleepingcomputer.com/news/security/thousands-of-citrix-servers-vulnerable-to-patched-critical-flaws 2、Royal勒索组织声称对Intrado电信提供商发动了网络攻击 https://www.bleepingcomputer.com/news/security/royal-ransomware-claims-attack-on-intrado-telecom-provider/ 3、勒索组织针对路易斯安那州医院的攻击影响超27万名患者数据 https://www.bleepingcomputer.com/news/security/ransomware-attack-at-louisiana-hospital-impacts-270-000-patients/ 4、通过 Google Ads 的新恶意广告活动针对搜索流行软件的用户 https://thehackernews.com/2022/12/new-malvertising-campaign-via-google.html 5、罗克韦尔自动化控制器中发现多个 DoS、代码执行漏洞 https://www.securityweek.com/several-dos-code-execution-vulnerabilities-found-rockwell-automation-controllers 6、俄亥俄州法院、警察局遭到 LockBit 勒索软件攻击 https://www.freebuf.com/news/353816.html 7、安全专家指责 LastPass 公告:存在 14 点疑问,避重就轻 https://www.ithome.com/0/663/960.htm 8、美国司法部正在调查 FTX 黑客攻击 https://www.inforisktoday.com/us-department-justice-reportedly-investigates-ftx-hack-a-20809 9、调查显示,金融服务行业是 2022 年最受网络攻击影响的行业之一 https://www.inforisktoday.com/financial-services-was-among-most-breached-sectors-in-2022-a-20760 10、APT 黑客越来越多的转向恶意 Excel 加载项作为初始入侵向量 https://thehackernews.com/2022/12/apt-hackers-turn-to-malicious-excel-add.html
网络安全日报 2022年12月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 加密钱包 BitKeep 因网络攻击损失超过 900 万美元 https://securityaffairs.com/140099/cyber-crime/bitkeep-9m-stolen.html 2、Meta支付 7.25 亿美元,了结剑桥分析公司数据泄露诉讼 https://thehackernews.com/2022/12/facebook-to-pay-725-million-to-settle.html 3、视频会议的风险与日俱增,中小型企业成为网络攻击的目标 https://www.darkreading.com/application-security/videoconferencing-worries-grow-with-smbs-in-cyberattack-crosshairs 4、研究人员披露使用了窃取的证书签名的勒索软件和擦除器 https://securelist.com/ransomware-and-wiper-signed-with-stolen-certificates/108350/ 5、Lazarus APT组织创建了 70 个虚假银行、风险投资公司域名 https://www.securityweek.com/north-korean-hackers-created-70-fake-bank-venture-capital-firm-domains 6、印度铁路公司3000 万客户数据在暗网上出售 https://economictimes.indiatimes.com/news/new-updates/indian-railway-data-leak-30-million-railway-customers-data-for-sale-on-the-dark-web/articleshow/96569440.cms 7、美国政府立法推动改善内存安全问题 https://www.secrss.com/articles/50499 8、最高人民法院发布公民个人信息保护指导性案例 https://www.secrss.com/articles/50472 9、苏黎世保险CEO:网络攻击将“无法投保” https://www.anquanke.com/post/id/284719 10、FBI的受审查信息共享网络“InfraGard”被黑 https://www.4hou.com/posts/jJ1y
网络安全日报 2022年12月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、 PrivateLoader PPI服务被用于分发 RisePro 信息窃取软件 https://securityaffairs.com/140045/cyber-crime/privateloader-ppi-risepro-stealer.html 2、FBI警告网络犯罪分子使用搜索引擎广告服务冒充品牌并欺骗用户 https://securityaffairs.com/140051/cyber-crime/search-engine-advertisement-services-abuse.html 3、BlueNoroff APT 使用新方法绕过 Windows MotW 保护 https://thehackernews.com/2022/12/bluenoroff-apt-hackers-using-new-ways.html 4、Lazarus APT 使用网络钓鱼域名来瞄准 NFT 投资者 https://cyware.com/news/lazarus-apt-uses-phishing-domains-to-target-nft-investors-e2863fbf 5、EarSpy 攻击通过运动传感器窃听 Android 手机 https://www.bleepingcomputer.com/news/security/earspy-attack-eavesdrops-on-android-phones-via-motion-sensors 6、XLL 文件越来越多地被攻击者利用 https://cyware.com/news/xll-files-increasingly-getting-abused-by-attackers-41606bf1 7、欧盟隐私监管机构正调查大规模 Twitter 数据泄露事件 https://www.bleepingcomputer.com/news/security/massive-twitter-data-leak-investigated-by-eu-privacy-watchdog/ 8、容器验证漏洞允许恶意镜像云化 Kubernetes https://www.darkreading.com/cloud/container-verification-bug-malicious-images-free-rein-kubernetes 9、Mozilla 修复了一个存在 18 年的 Firefox 浏览器漏洞 https://www.ithome.com/0/663/375.htm 10、黑客在最新的 DeFi 漏洞中从 Bitkeep 钱包中窃取了 800 万美元的资产 https://cointelegraph.com/news/hackers-drain-8m-in-assets-from-bitkeep-wallets-in-latest-defi-exploit
网络安全日报 2022年12月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客组织Guacamaya泄露拉丁美洲国家数据产生军事等方面影响 https://therecord.media/guacamaya-leaks-spark-debate-about-militarization-spyware-but-no-accountability/ 2、T-Mobile零售店老板因提供手机解锁方案获刑10年 https://www.bleepingcomputer.com/news/security/t-mobile-hacker-gets-10-years-for-25-million-phone-unlock-scheme/ 3、新的窃密软件通过虚假破解站点感染盗版软件使用者 https://www.bleepingcomputer.com/news/security/new-info-stealer-malware-infects-software-pirates-via-fake-cracks-sites/ 4、黑客组织再次向Python包索引(PyPI)平台发布恶意软件包 https://thehackernews.com/2022/12/w4sp-stealer-discovered-in-multiple.html 5、WordPress插件存在严重漏洞导致超过5万个网站面临攻击 https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/ 6、美国国会通过法案禁止政府设备安装 TikTok https://www.freebuf.com/articles/353538.html 7、一种名为 GuLoader 的高级恶意软件下载器采用新的规避技术 https://securityaffairs.co/wordpress/140028/cyber-crime/guloader-evasion-techniques.html 8、微软因未经同意使用广告 cookie 在法国被罚款 6000 万欧元 https://securityaffairs.co/wordpress/139982/breaking-news/microsoft-fined-e60m.html 9、俄罗斯黑客劫持美国机场出租车调度系统搞黑产 https://www.secrss.com/articles/50352 10、研究人员警告针对印度政府的Kavach 2FA网络钓鱼攻击 https://thehackernews.com/2022/12/researchers-warn-of-kavach-2fa-phishing.html
网络安全日报 2022年12月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软修补 Azure 跨租户数据访问漏洞 https://www.securityweek.com/microsoft-patches-azure-cross-tenant-data-access-flaw 2、Facebook 同意支付 7.25 亿美元和解隐私诉讼 https://www.securityweek.com/facebook-agrees-pay-725-million-settle-privacy-suit 3、严重的 Linux 内核漏洞影响启用了 ksmbd 的 SMB 服务器 https://securityaffairs.co/wordpress/140013/hacking/critical-linux-kernel-vulnerability.html 4、4 亿 Twitter 用户数据在黑客论坛出售 https://securityaffairs.co/wordpress/139993/data-breach/twitter-400-million-users-leak.html 5、专家在 ZyXEL LTE3301 M209路由器中发现硬编码凭据 https://securityaffairs.co/wordpress/139974/hacking/backdoor-credentials-zyxel-lte3301-m209.html 6、LastPass 承认严重数据泄露,加密密码库被盗 https://thehackernews.com/2022/12/lastpass-admits-to-severe-data-breach.html 7、IcedID僵尸网络滥用Google PPC服务分发恶意软件 https://www.trendmicro.com/en_us/research/22/l/icedid-botnet-distributors-abuse-google-ppc-to-distribute-malware.html 8、APT组织SideCopy针对印度政府官员进行网络攻击 https://www.securonix.com/blog/new-steppykavach-attack-campaign/ 9、黑客利用泄露的Conti源代码制造多个勒索软件新变种 https://blog.cyble.com/2022/12/22/new-ransomware-strains-emerging-from-leaked-contis-source-code/ 10、Lazarus组织使用经证书签名的恶意软件攻击macOS用户 https://labs.k7computing.com/index.php/lazarus-apts-operation-interception-uses-signed-binary/
网络安全日报 2022年12月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员披露Web3 IPFS可用于网络钓鱼 https://www.trendmicro.com/en_us/research/22/l/web3-ipfs-only-used-for-phishing---so-far.html2、俄罗斯黑客Killnet声称FBI特工的数据被盗 https://www.hackread.com/russian-killnet-hackers-fbi-agents3、研究人员发布FIN7黑客组织在勒索领域的详细报告 https://www.prodaft.com/resource/detail/fin7-unveiled-deep-dive-notorious-cybercrime-gang4、研究人员披露企业密码管理器Passwordstate多个高危漏洞 https://www.modzero.com/modlog/archives/2022/12/19/better_make_sure_your_password_manager_is_secure/index.html5、Zerobot IoT 僵尸网络增加了更多漏洞利用和 DDoS 功能 https://www.securityweek.com/zerobot-iot-botnet-adds-more-exploits-ddos-capabilities6、LastPass 称密码库数据在数据泄露中被盗 https://www.securityweek.com/lastpass-says-password-vault-data-stolen-data-breach7、德国工业巨头蒂森克虏伯成为新网络攻击的目标 https://securityaffairs.co/wordpress/139870/hacking/thyssenkrupp-targeted-cyberattack.html8、研究人员将 Royal 勒索软件与 Conti Group 关联 https://www.securityweek.com/researchers-link-royal-ransomware-conti-group9、与朝鲜有关的黑客在 2022 年窃取了 6.26 亿美元的虚拟资产 https://securityaffairs.co/wordpress/139909/intelligence/north-korea-cryptocurrency-theft.html10、研究人员披露博客软件Ghost CMS中两个安全漏洞 https://blog.talosintelligence.com/vulnerability-spotlight-authentication-bypass-and-enumeration-vulnerabilities-in-ghost-cms/
网络安全日报 2022年12月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、安卓恶意软件GodFather针对400家银行和加密交易所进行网络攻击 https://www.bleepingcomputer.com/news/security/godfather-android-malware-targets-400-banks-crypto-exchanges/ 2、Okta公司的私有GitHub存储库遭网络攻击后源代码被盗 https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/ 3、勒索软件团伙使用新的Microsoft Exchange漏洞进行网络攻击 https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-new-microsoft-exchange-exploit-to-breach-servers/ 4、微软将于2023年1月关闭Exchange Online基本身份验证 https://www.bleepingcomputer.com/news/microsoft/microsoft-will-turn-off-exchange-online-basic-auth-in-january/ 5、欺诈者利用谷歌广告传播恶意内容赚取数百万美元 https://www.bleepingcomputer.com/news/security/google-ad-fraud-campaign-used-adult-content-to-make-millions/ 6、黑客利用Excel加载项功能发动网络攻击 https://blog.talosintelligence.com/xlling-in-excel-malicious-add-ins/ 7、Epic Games 同意支付 5.2 亿美元和解 FTC 的指控 https://www.solidot.org/story?sid=73698 8、Play 勒索软件声称对德国连锁酒店 H-Hotels 进行攻击 https://www.bleepingcomputer.com/news/security/play-ransomware-claims-attack-on-german-hotel-chain-h-hotels/ 9、Cisco警告称产品中的旧漏洞被广泛利用 https://securityaffairs.co/wordpress/139821/security/cisco-old-vulnerabilities-exploitation.html 10、Raspberry Robin病毒再次来袭,瞄准电信和政府系统 https://thehackernews.com/2022/12/raspberry-robin-worm-strikes-again.html
网络安全日报 2022年12月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软披露macOS系统中的Gatekeeper Bypass漏洞详情 https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/ 2、研究人员披露针对巴西用户的新型安卓恶意软件BrasDex https://www.threatfabric.com/blogs/brasdex-a-new-brazilian-ats-malware.html 3、国会采取行动禁止使用美国政府设备的TikTok https://www.securityweek.com/congress-moves-ban-tiktok-us-government-devices 4、哥伦比亚能源供应商EPM遭受BlackCat勒索软件攻击 https://www.secrss.com/articles/50129 5、570 万 Gemini 用户数据可在黑客论坛上出售 https://securityaffairs.co/wordpress/139742/data-breach/5-7m-gemini-users-leak.html 6、GitHub 宣布对所有公共仓库进行免费秘密扫描 https://thehackernews.com/2022/12/github-announces-free-secret-scanning.html 7、WordPress 6.0.3 发布 涉及多个安全修复 https://www.cnbeta.com.tw/articles/soft/1328365.htm 8、蔚来汽车用户数据大规模泄露 https://finance.sina.com.cn/nextauto/hydt/2022-12-21/doc-imxxkviv6379549.shtml 9、LEGO Marketplace 中发现了API 漏洞 https://www.infosecurity-magazine.com/news/api-vulnerabilities-lego/ 10、FTC以违反儿童隐私法对《堡垒之夜》制造商处以2.75亿美元的罚款 https://www.freebuf.com/articles/game/352951.html