网络安全日报 2022年12月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、俄罗斯发生多起严重的GPS中断事件 https://www.cysecurity.news/2022/12/russian-cities-are-experiencing-gps.html 2、国际警察关闭了约50个提供DDoS租用服务的网站 https://www.cysecurity.news/2022/12/ddos-for-hire-websites-areseized-by.html 3、黑客利用恶意文档攻击渗透拉丁美洲酒店 https://securityboulevard.com/2022/12/cybercriminals-leverage-file-based-attacks-to-infiltrate-critical-networks 4、新西兰医疗人员保险公司MAS遭受网络攻击 https://www.nzherald.co.nz/nz/cyber-attack-on-nzs-largest-insurer-of-doctors-mas-may-have-exposed-members-personal-data/AAJUNLLUZ5GI3KDX2EMQW4JSNA/ 5、Glupteba僵尸网络被Google捣毁一年后再次活跃 https://www.cysecurity.news/2022/12/glupteba-malware-has-returned-after.html 6、福昕修补了PDF工具中的代码执行高危漏洞 https://www.securityweek.com/foxit-patches-code-execution-flaws-pdf-tools 7、恶意 PyPI 模块伪装成 SentinelOne SDK https://www.securityweek.com/malicious-pypi-module-poses-sentinelone-sdk 8、新型跨平台僵尸网络正感染《我的世界》游戏服务器 https://www.freebuf.com/news/352845.html 9、因安装木马化的Windows 10程序,乌克兰政府网络被攻破 https://www.bleepingcomputer.com/news/security/ukrainian-govt-networks-breached-via-trojanized-windows-10-installers/ 10、信标委《个人信息跨境处理活动安全认证规范V2.0》正式发布 https://www.tc260.org.cn/front/postDetail.html?id=20221216161852
网络安全日报 2022年12月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、澳大利亚TPG电信遭网络攻击影响了1.5万企业账户 https://wcsecure.weblink.com.au/pdf/TPG/02612242.pdf 2、FuboTV遭受网络攻击导致世界杯流媒体中断 https://www.bleepingcomputer.com/news/security/fubotv-says-world-cup-streaming-outage-caused-by-a-cyberattack/ 3、黑客出售窃取的社交媒体分析网站-Social Blade数据库 https://www.cysecurity.news/2022/12/social-blade-confirms-data-breach.html 4、开源工具Cacti修复严重的IP欺骗漏洞 https://portswigger.net/daily-swig/critical-ip-spoofing-bug-patched-in-cacti 5、谷歌更新Gmail客户端加密技术 https://thehackernews.com/2022/12/gmail-encryption.html 6、NIST将淘汰已有27年历史的SHA-1安全散列算法 https://www.securityweek.com/nist-retire-27-year-old-sha-1-cryptographic-algorithm 7、BlackCat勒索软件对哥伦比亚能源供应商进行网络攻击 https://www.bleepingcomputer.com/news/security/colombian-energy-supplier-epm-hit-by-blackcat-ransomware-attack 8、Samba发布安全更新以修补多个高危漏洞 https://www.samba.org/samba/history/ 9、加密货币交易所Gemini泄露了570万用户数据 https://www.cysecurity.news/2022/12/hackers-leaked-stolen-data-of-57m.html 10、知名虚拟机备份软件Veeam Backup存在RCE漏洞且被在野利用 https://cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication/
网络安全日报 2022年12月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、CISA 警告 Veeam Backup & Replication 漏洞在攻击中被利用 https://www.securityweek.com/cisa-warns-veeam-backup-replication-vulnerabilities-exploited-attacks 2、谷歌发布了Chrome 108更新修补高危内存安全漏洞 https://www.securityweek.com/high-severity-memory-safety-bugs-patched-latest-chrome-108-update 3、微软将 SPNEGO 扩展协商安全漏洞重新分类为“严重” https://thehackernews.com/2022/12/microsoft-reclassifies-spnego-extended.html 4、黑客用超过 144000 个恶意软件包轰炸开源存储库 https://thehackernews.com/2022/12/hackers-bombard-open-source.html 5、安卓恶意软件仿冒放贷应用程序敲诈受害者 https://thehackernews.com/2022/12/android-malware-campaign-leverages.html 6、FBI的审查信息共享网络InfraGard遭黑客攻击 https://krebsonsecurity.com/2022/12/fbis-vetted-info-sharing-network-infragard-hacked/ 7、黑客使用SVG图像替代HTML Smuggling技术 https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/ 8、日本新版国家安全战略引入“主动网络防御”原则 https://www.secrss.com/articles/49993 9、美国政府机构发布关于 5G 网络切片威胁的指南 https://www.securityweek.com/us-government-agencies-issue-guidance-threats-5g-network-slicing 10、国际乓联泄露数百名运动员护照和疫苗接种证书 https://www.freebuf.com/news/352571.html
网络安全日报 2022年12月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员披露恶意驱动程序POORTRY https://www.mandiant.com/resources/blog/hunting-attestation-signed-malware 2、研究人员披露僵尸网络GoTrim暴力破解WordPress网站 https://www.fortinet.com/blog/threat-research/gotrim-go-based-botnet-actively-brute-forces-wordpress-websites 3、Xnspy应用程序监视了六万部安卓和苹果用户设备 https://techcrunch.com/2022/12/12/xnspy-stalkerware-iphone-android 4、研究人员披露Atlassian产品存在安全漏洞 https://cloudsek.com/security-flaw-in-atlassian-products-jira-confluencetrello-bitbucket-affecting-multiple-companies/ 5、研究人员展示了EDR和反病毒软件如何被用来对付用户 https://thehackernews.com/2022/12/researchers-demonstrate-how-edr-and.html 6、比利时安特卫普市上周遭受网络攻击 https://www.bleepingcomputer.com/news/security/play-ransomware-claims-attack-on-belgium-city-of-antwerp/ 7、印度外交部泄露外籍人士护照详细信息 https://cybernews.com/security/indias-foreign-ministry-leaks-passport-details/ 8、优步在供应商遭到攻击后遭遇新的数据泄露 https://www.bleepingcomputer.com/news/security/uber-suffers-new-data-breach-after-attack-on-vendor-info-leaked-online/ 9、Fortinet 敦促客户修复积极利用的 FortioSSL-VPN 漏洞 https://securityaffairs.co/wordpress/139569/hacking/fortinet-fortios-ssl-vpn-bug.html 10、攻击者失手,自己杀死了僵尸网络 KmsdBot https://www.freebuf.com/articles/network/352252.html
网络安全日报 2022年12月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware 修补了在 Geekpwn中被利用的虚拟机逃逸漏洞 https://www.securityweek.com/vmware-patches-vm-escape-flaw-exploited-geekpwn-event 2、新的基于 Python 的后门针对 VMware ESXi 服务器 https://www.securityweek.com/new-python-based-backdoor-targeting-vmware-esxi-servers 3、微软周二补丁日修补了Windows MOTW漏洞 https://www.securityweek.com/patch-tuesday-microsoft-plugs-windows-hole-exploited-ransomware-attacks 4、Lockbit 勒索软件团伙入侵了加州财政部 https://securityaffairs.co/wordpress/139599/cyber-crime/lockbit-ransomware-california-department-of-finance.html 5、谷歌推出最大的开源漏洞分布式数据库OSV-Scanner https://thehackernews.com/2022/12/google-launches-largest-distributed.html 6、Amazon ECR Public Gallery 披露了一个严重的安全漏洞 https://thehackernews.com/2022/12/serious-attacks-could-have-been-staged.html 7、网络安全研究人员揭开破坏性 Azov 勒索软件的内部工作原理 https://thehackernews.com/2022/12/cybersecurity-experts-uncover-inner.html 8、工信部印发《工业和信息化领域数据安全管理办法 (试行)》 https://www.secrss.com/articles/50009 9、朝鲜黑客使用假身份诱骗西方智库专家为其撰写研究报告 https://www.secrss.com/articles/49998 10、国家能源局印发《电力行业网络安全管理办法》 https://www.secrss.com/articles/49968
网络安全日报 2022年12月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Fortinet 为已被利用的 SSL-VPN 漏洞发布紧急补丁 https://www.securityweek.com/fortinet-ships-emergency-patch-already-exploited-vpn-flaw 2、Cryptomining 使用基于Go的CHAOS恶意软件针对 Linux 系统 https://securityaffairs.co/wordpress/139554/cyber-crime/cryptocurrency-mining-campaign-chaos-malware.html 3、谷歌为Chrome 添加无密码登录标准passkeys支持 https://thehackernews.com/2022/12/google-adds-passkey-support-to-chrome.html 4、Royal 勒索软件威胁瞄准美国医疗保健系统 https://thehackernews.com/2022/12/royal-ransomware-threat-takes-aim-at-us.html 5、研究人员披露针对Python、JS开发人员的勒索软件攻击 https://blog.phylum.io/phylum-detects-active-typosquatting-campaign-in-pypi 6、澳大利亚电信公司Telstra泄露13万客户数据 https://www.bleepingcomputer.com/news/security/hackers-earn-989-750-for-63-zero-days-exploited-at-pwn2own-toronto/ 7、苹果改进iCloud数据的端到端加密方式 https://www.cysecurity.news/2022/12/apple-improves-icloud-data-end-to-end.html 8、加拿大安大略省疫苗预订系统的数据泄露影响了数十万人 https://www.cbc.ca/news/canada/toronto/vaccine-data-breach-ontario-1.6680714 9、在披露Log4Shell一年后,大多数公司仍暴露在攻击之下 https://www.freebuf.com/news/352218.html 10、Pwn2Own 2022闭幕,参赛者累计获得近百万美元奖金 https://www.freebuf.com/news/352194.html
网络安全日报 2022年12月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、思科正在为公开披露的 IP 电话漏洞开发补丁 https://www.securityweek.com/cisco-working-patch-publicly-disclosed-ip-phone-vulnerability 2、MuddyWater APT针对中东以及中亚和西亚国家发起新活动 https://securityaffairs.co/wordpress/139505/apt/muddywater-changs-ttps.html 3、超4,000 个易受攻击的 PulseConnect Secure 主机暴露在互联网上 https://www.securityweek.com/over-4000-vulnerable-pulse-connect-secure-hosts-exposed-internet 4、研究人员披露针对电信和BPO公司的入侵活动 https://www.crowdstrike.com/blog/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies/ 5、研究人员披露DEV-0139组织针对加密货币行业发起定向攻击 https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/ 6、Vice Society勒索组织针对教育部门进行网络攻击 https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/ 7、伊朗APT组织运营的Drokbk恶意软件滥用GitHub托管C2服务 https://www.secureworks.com/blog/drokbk-malware-uses-github-as-dead-drop-resolver 8、研究人员称Matrix协议存在可利用的加密漏洞 https://nebuchadnezzar-megolm.github.io/ 9、澳大利亚警方逮捕涉及1亿美元资金的网络犯罪嫌犯 https://www.bleepingcomputer.com/news/security/australia-arrests-pig-butchering-suspects-for-stealing-100-million/ 10、以色列研究人员利用电源辐射实现气隙网络间的数据传输 https://www.bleepingcomputer.com/news/security/air-gapped-pcs-vulnerable-to-data-theft-via-power-supply-radiation/
网络安全日报 2022年12月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、苹果取消了 iCloud 照片的 CSAM 检测工具 https://www.securityweek.com/apple-scraps-csam-detection-tool-icloud-photos 2、照明巨头 Acuity Brands 披露了两起数据泄露事件 https://www.securityweek.com/lighting-giant-acuity-brands-discloses-two-data-breaches 3、下载量超过 500 万的 Android 应用程序泄露了用户浏览历史记录 https://securityaffairs.co/wordpress/139415/mobile-2/android-app-with-over-5m-downloads-leaked-user-browsing-history.html 4、研究人员发现了一种绕过几家主要WAF的通用攻击方法 https://www.securityweek.com/wafs-several-major-vendors-bypassed-generic-attack-method 5、俄黑客组织TAG-53对美军事武器与硬件供应商发动钓鱼攻击 https://www.recordedfuture.com/exposing-tag-53-credential-harvesting-infrastructure-for-russia-aligned-espionage-operations 6、研究人员发现使用机器学习模型可部署恶意软件 https://hiddenlayer.com/research/weaponizing-machine-learning-models-with-ransomware/ 7、大量中文网站被黑,嵌入世界杯相关关键词用于黑帽SEO https://www.freebuf.com/articles/network/351899.html 8、微软向加密货币行业发出有针对性的网络攻击警告 https://thehackernews.com/2022/12/microsoft-alerts-cryptocurrency.html 9、英国罚款五家滥用电话营销的公司,共计43.5万英镑 https://www.infosecurity-magazine.com/news/ico-fines-rogue-nuisance-callers/ 10、报告:Z世代互联网用户使网络犯罪“正常化” https://www.infosecurity-magazine.com/news/gen-z-internet-users-normalize/
网络安全日报 2022年12月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple 为 iCloud 备份添加端到端加密 https://www.securityweek.com/apple-adding-end-end-encryption-icloud-backup 2、Fortinet 修补了 FortiOS 中的高危身份验证绕过漏洞 https://www.securityweek.com/fortinet-patches-high-severity-authentication-bypass-vulnerability-fortios 3、谷歌的威胁分析小组 (TAG) 分享了APT37利用IE 0day漏洞细节 https://www.securityweek.com/google-documents-ie-browser-zero-day-exploited-north-korean-hackers 4、基于Go的僵尸网络"Zerobot"利用Spring4Shell和数十个IoT漏洞 https://www.securityweek.com/self-propagating-zerobot-botnet-targeting-spring4shell-iot-vulnerabilities 5、Pwn2Own Toronto 2022 第一天,三星 Galaxy S22被攻破 https://securityaffairs.co/wordpress/139384/hacking/pwn2own-toronto-2022-day-one.html 6、Sophos Firewall 修复了多个严重漏洞 https://securityaffairs.co/wordpress/139362/security/sophos-firewall-critical-flaw.html 7、新的 Magecart 活动针对至少 44 个电商网站 https://www.scmagazine.com/news/cybercrime/new-magecart-campaign-said-to-target-at-least-44-e-commerce-sites 8、孟加拉黑客组织Team Mysterious Bangladesh攻击印度教育系统 https://cloudsek.com/threatintelligence/indian-central-board-of-higher-education-compromised-by-team-mysterious-bangladesh/ 9、黑客滥用PRoot隔离文件系统劫持Linux设备 https://www.bleepingcomputer.com/news/security/hackers-hijack-linux-devices-using-proot-isolated-filesystems/ 10、本地模式的Eufy家庭摄像头仍会将隐私数据上传云端 https://www.malwarebytes.com/blog/news/2022/12/is-your-home-security-system-storing-data-100-locally
网络安全日报 2022年12月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Sophos防火墙修复多个代码执行漏洞 https://www.securityweek.com/several-code-execution-vulnerabilities-patched-sophos-firewall 2、俄罗斯第二大银行 VTB Bank 遭受 DDoS 攻击 https://securityaffairs.co/wordpress/139354/hacking/vtb-bank-ddos-attack.html 3、美国警方采购汽车取证工具,可破解万款汽车信息娱乐系统提取数据 https://securityaffairs.co/wordpress/139267/hacking/law-enforcement-cars-infotainment-systems.html 4、报告称网络勒索在非洲、中东和中国呈指数级增长 https://www.infosecurity-magazine.com/news/cyber-extortion-growing-africa 5、研究人员披露APT37组织所使用的TTP https://thorcert.notion.site/TTPs-9-f04ce99784874947978bd2947738ac92 6、开源勒索软件工具包Cryptonite具有破坏性数据擦除功能 https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware 7、AMI MegaRAC基板管理控制器供应链漏洞影响数十家制造商的服务器 https://thehackernews.com/2022/12/new-bmc-supply-chain-vulnerabilities.html 8、Android Messages 群聊将支持端对端加密 https://blog.google/products/messages/happy-birthday-sms/ 9、匈牙利政府被指向公民发送大量政治垃圾邮件 https://cybernews.com/privacy/hungary-abused-databases-bombard-citizens-political-spam/ 10、美国南达科他州禁止在政府发放的设备上安装 TikTok https://governor.sd.gov/doc/GovNoem-EO_2022-10.pdf