网络安全日报 2022年12月06日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、严重漏洞迫使社交媒体平台 Hive Social 离线 https://www.securityweek.com/critical-vulnerabilities-force-twitter-alternative-hive-social-offline 2、严重的 Ping 错误可能导致远程接管FreeBSD 系统 https://securityaffairs.co/wordpress/139300/hacking/cve-2022-23093-freebsd-systems-flaw.html 3、Lazarus APT 使用伪造的加密货币应用传播 AppleJeus 恶意软件 https://securityaffairs.co/wordpress/139290/apt/lazarus-apt-bloxholder-campaign.html 4、研究人员在暗网中发现最大的移动端恶意软件市场 https://securityaffairs.co/wordpress/139310/cyber-crime/dark-web-mobile-malware-marketplace.html 5、三星小米等厂商均受影响,谷歌披露威胁数百万安卓设备的高危漏洞 https://www.ithome.com/0/658/513.htm 6、三星 LG 联发科的证书被用于签名恶意程序 https://www.solidot.org/story?sid=73542 7、SANS发布《2022年顶级新攻击和威胁分析报告》 https://www.secrss.com/articles/49653 8、印度泰米尔纳德邦医院 15w名患者的个人数据在暗网出售 https://www.indiatimes.com/technology/news/personal-data-from-tn-hospital-on-dark-web-586554.html 9、DeFi 协议 Ankr 遭受 500 万美元盗窃 https://finance.yahoo.com/news/defi-protocol-ankr-exploited-over-060811318.html 10、全国首例!云南破获域名黑产大案,抓获630人 https://www.freebuf.com/news/351436.html
网络安全日报 2022年12月05日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、IBM Cloud 漏洞使用户面临供应链攻击 https://www.securityweek.com/ibm-cloud-vulnerability-exposed-users-supply-chain-attacks 2、三菱电机 PLC 工程软件被发现严重漏洞可用于入侵系统 https://www.securityweek.com/mitsubishi-electric-plcs-exposed-attacks-engineering-software-flaws 3、谷歌逐步将 Android 迁移到Rust等内存安全的编程语言 https://www.securityweek.com/google-migrating-android-memory-safe-programming-languages 4、美国国土安全部网络安全委员会将审查 Lapsus$ 团伙的运作 https://securityaffairs.co/wordpress/139255/cyber-crime/us-dhs-cyber-safety-board-review-lapsus-attacks.html 5、谷歌发布安全更新以解决一个新的 Chrome 零日漏洞 https://securityaffairs.co/wordpress/139226/security/9-google-chrome-zero-day.html 6、Keralty跨国医疗组织遭受RansomHouse勒索软件攻击 https://www.bleepingcomputer.com/news/security/keralty-ransomware-attack-impacts-colombias-health-care-system/ 7、Cuba勒索软件在美国感染实体数量增加且赎金金额增多 https://www.cisa.gov/uscert/ncas/current-activity/2022/12/01/stopransomware-cuba-ransomware 8、超150个Oracle访问管理系统存在漏洞 https://therecord.media/more-than-150-oracle-access-management-systems-exposed-to-bug-highlighted-by-cisa/ 9、新型CryWiper数据擦除器攻击俄罗斯法院和市长办公室 https://www.bleepingcomputer.com/news/security/new-crywiper-data-wiper-targets-russian-courts-mayor-s-offices/ 10、十年未被发现!现代汽车曝重大安全漏洞可远程解锁、启动汽车 https://www.freebuf.com/news/351422.html
网络安全日报 2022年12月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌指控西班牙间谍软件商利用 Chrome/Firefox/Windows 零日漏洞 https://thehackernews.com/2022/12/google-accuses-spanish-spyware-vendor.html 2、黑客在暗网上泄露了另一组 Medibank 客户数据 https://thehackernews.com/2022/12/hackers-leak-another-set-of-medibank.html 3、Nvidia 修补了 Windows、Linux 显示驱动程序中的29个漏洞 https://www.securityweek.com/nvidia-patches-many-vulnerabilities-windows-linux-display-drivers 4、基于 Go 的 Redigo 恶意软件以 Redis 服务器为目标 https://securityaffairs.co/wordpress/139164/malware/redigo-malware-targets-redis-servers.html 5、Lastpass 披露了今年的第二起安全漏洞 https://securityaffairs.co/wordpress/139136/data-breach/lastpass-second-security-breach.html 6、朝鲜黑客组织APT37使用新的Dolphin后门来监视韩国目标 https://www.welivesecurity.com/2022/11/30/whos-swimming-south-korean-waters-meet-scarcrufts-dolphin/ 7、Schoolyard Bully木马窃取了超过30万安卓用户的Facebook凭据 https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/ 8、智能汽车服务提供商SiriusXM的产品存在授权漏洞可导致远程解锁车门 https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/ 9、Trigona 勒索软件在全球范围内不断发起攻击 https://www.bleepingcomputer.com/news/security/trigona-ransomware-spotted-in-increasing-attacks-worldwide/ 10、Lockbit 3.0 具有 BlackMatter 勒索软件代码、可蠕虫特征 https://www.techtarget.com/searchsecurity/news/252527864/Lockbit-30-has-BlackMatter-ransomware-code-wormable-traits
网络安全日报 2022年12月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、索尼、雷克沙等闪存设备加密提供商被曝泄露敏感数据一年有余 https://cybernews.com/security/encsecurity-leaked-sensitive-data/ 2、因泄露5.33亿用户隐私,Facebook被罚2.65亿欧元 https://www.freebuf.com/news/351014.html 3、美国国会研究服务处发布新版《电子战》报告 https://www.secrss.com/articles/49491 4、摩洛哥和科威特宜家商场数据被勒索团伙发布至网站 https://cybernews.com/news/ikea-posted-ransomware-gang/ 5、Chrome 108 发布补丁修复了严重的内存安全漏洞 https://www.securityweek.com/chrome-108-patches-high-severity-memory-safety-bugs 6、Quarkus Java 框架中存在严重的远程代码执行漏洞 https://www.securityweek.com/developers-warned-critical-remote-code-execution-flaw-quarkus-java-framework 7、Delta Electronics 修补了工业网络设备中的严重漏洞 https://www.securityweek.com/delta-electronics-patches-serious-flaws-industrial-networking-devices 8、研究人员发现针对智利用户的Punisher勒索软件新变种 https://heimdalsecurity.com/blog/punisher-ransomware-uses-a-covid-lure-to-spread/ 9、研究人员发现针对金融服务业Web应用程序和API的攻击激增 https://www.infosecurity-magazine.com/news/web-app-api-attacks-257-financial/ 10、元宇宙可能成为 2023 年网络攻击的主要途径 https://www.freebuf.com/news/351133.html
网络安全日报 2022年11月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Oracle Access Manager漏洞被黑客攻击广泛利用 https://www.securityweek.com/oracle-fusion-middleware-vulnerability-exploited-wild 2、网络犯罪分子利用最近的 Fortinet 漏洞出售网络访问权 https://www.securityweek.com/cybercriminals-selling-access-networks-compromised-recent-fortinet-vulnerability 3、研究人员披露AWS AppSync服务中的跨租户漏洞 https://securityaffairs.co/wordpress/139045/hacking/amazon-web-services-flaw.html 4、黑客利用流行的 TikTok的热门挑战活动诱骗用户下载恶意软件 https://thehackernews.com/2022/11/hackers-using-trending-invisible.html 5、北卡罗来纳大学证实勒索软件集团窃取了敏感数据 https://therecord.media/north-carolina-college-confirms-ransomware-group-stole-sensitive-data/ 6、研究人员发现针对中东个人和企业的网络钓鱼活动 https://www.infosecurity-magazine.com/news/phishing-impersonating-uae/ 7、德国隐私监管机构认为 Microsoft 365 不兼容 GDPR https://www.solidot.org/story?sid=73491 8、NordPass 公布2022 年最常用的密码,"password"居榜首 https://www.theregister.com/2022/11/25/infosec_roundup/ 9、RansomEXX更新Rust恶意软件以提高规避能力 https://www.inforisktoday.com/ransomexx-updates-to-rust-malware-to-improve-evasion-a-20554 10、研究人员在Google Play中发现用于非法创建账户的恶意应用程序 https://www.bleepingcomputer.com/news/security/malicious-android-app-found-powering-account-creation-service/
网络安全日报 2022年11月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Twitter 数据泄露比最初报告的更大,可能超过 1 亿用户受到影响 https://www.securityweek.com/twitter-data-breach-bigger-initially-reported 2、爱尔兰数据监管机构因Meta数据泄露问题对其处以 2.65 亿欧元罚款 https://www.securityweek.com/irish-regulator-fines-meta-265-million-euros-over-data-breach 3、十多个新的 BMC 固件漏洞使 OT 和 IoT 设备面临远程攻击 https://thehackernews.com/2022/11/over-dozen-new-bmc-firmware-flaws.html 4、某些 Acer 笔记本电脑中的漏洞可用于绕过UEFI安全启动 https://securityaffairs.co/wordpress/139055/hacking/acer-flaw-uefi-secure-boot.html 5、酒店管理公司Sonder遭遇数据泄露 https://www.infosecurity-magazine.com/news/sonder-confirms-data-breach/ 6、加拿大安大略省中学教师联合会遭受勒索软件攻击 https://www.thepeterboroughexaminer.com/ts/news/gta/2022/11/23/osstf-victim-of-ransomware-attack-notifies-members-of-personal-data-compromised.html 7、Maple Leaf Foods承认受到勒索攻击并表示不会支付赎金 https://www.itworldcanada.com/article/black-basta-ransomware-group-claims-it-hit-maple-leaf-foods/515358 8、研究人员发现Koxic勒索软件正在韩国传播 https://asec.ahnlab.com/en/42343/ 9、研究人员称网络犯罪团伙正在非洲各地扩张 https://www.pehalnews.in/gangs-of-cybercriminals-are-expanding-across-africa-investigators-say/2645667/ 10、一团伙假装应聘潜入电商公司安装木马软件,盗取物流信息 https://www.secrss.com/articles/49375
网络安全日报 2022年11月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国FCC以国家安全风险为由禁止进口华为、中兴等五家公司的电子设备 https://securityaffairs.co/wordpress/138998/breaking-news/fcc-bans-import-chinese-equipment.html 2、戴尔、惠普和联想的设备使用过时的 OpenSSL 版本 https://securityaffairs.co/wordpress/138986/security/dell-hp-lenovo-openssl-outdated.html 3、谷歌修复了今年以来第八个chrome零日漏洞 https://securityaffairs.co/wordpress/138977/hacking/8-google-chrome-zero-day.html 4、专家调查 WhatsApp 数据泄露:5 亿用户记录待售 https://securityaffairs.co/wordpress/138967/data-breach/whatsapp-data-leak-500m.html 5、英国警方逮捕了 142 个与"iSpoof"电话欺骗服务有关的嫌疑人 https://thehackernews.com/2022/11/uk-police-arrest-142-in-global.html 6、Windows IKE v1协议扩展被发现存在远程代码执行漏洞 https://www.infosecurity-magazine.com/news/rce-vulnerability-in-windows-ike/ 7、新德里的全印度医学科学研究所遭受勒索软件攻击 https://techcrunch.com/2022/11/24/india-aiims-outages-cyberattack/ 8、BlackBasta勒索组织利用Qakbot传播勒索软件 https://www.infosecurity-magazine.com/news/qakbot-linked-to-black-basta/ 9、Docker Hub存储库中存在1650个以上的恶意容器 https://www.bleepingcomputer.com/news/security/docker-hub-repositories-hide-over-1-650-malicious-containers/ 10、攻击者利用仿冒的MSI Afterburner程序攻击Windows游戏玩家 https://www.bleepingcomputer.com/news/security/fake-msi-afterburner-targets-windows-gamers-with-miners-info-stealers/
网络安全日报 2022年11月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员称 iPhone 的分析数据不是匿名的 https://securityaffairs.co/wordpress/138884/digital-id/iphone-found-collecting-personal-data.html 2、数以百万计的 Android 设备仍然没有更新 Mali GPU 漏洞补丁 https://thehackernews.com/2022/11/million-of-android-devices-still-dont.html 3、Qakbot 感染与 Black Basta 勒索软件活动有关 https://www.infosecurity-magazine.com/news/qakbot-linked-to-black-basta/ 4、20万Roblox玩家安装了恶意Chrome扩展程序"SearchBlox" https://www.bleepingcomputer.com/news/security/backdoored-chrome-extension-installed-by-200-000-roblox-players/ 5、Ducktail组织利用WhatsApp进行钓鱼活动以窃取Facebook商业账户 https://www.bleepingcomputer.com/news/security/ducktail-hackers-now-use-whatsapp-to-phish-for-facebook-ad-accounts/ 6、美国国防部发布零信任网络战略和路线图 https://www.secrss.com/articles/49269 7、黑客通过已停产的Boa Web服务器漏洞破坏能源组织 https://securityaffairs.co/wordpress/138916/hacking/boa-web-servers-attacks.html 8、印度证券业关键机构遭恶意软件入侵,部分设备已隔离 https://www.secrss.com/articles/49261 9、Nighthawk可能成为继CobaltStrike后新的黑客后渗透工具 https://thehackernews.com/2022/11/nighthawk-likely-to-become-hackers-new.html 10、D0nut勒索组织正对企业部署双重勒索 https://www.freebuf.com/news/350528.html
网络安全日报 2022年11月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、深圳发布首个公共数据安全领域标准《公共数据安全要求》 https://www.freebuf.com/news/350609.html 2、LockBit 3.攻击了加拿大韦斯特蒙市政服务平台,导致其瘫痪 https://www.freebuf.com/news/350538.html 3、黑客组织 Killnet 对英国网站发起多次攻击 https://www.express.co.uk/news/uk/1699778/Killnet-hackers-Russia-war-UK-websites-Royal-Family-latest-update 4、 恶意安卓应用伪装成文件管理器传播Sharkbot窃密木马 https://www.bleepingcomputer.com/news/security/android-file-manager-apps-infect-thousands-with-sharkbot-malware/ 5、以世界杯为主题的钓鱼网站大幅增加 https://securityboulevard.com/2022/11/surge-of-fake-fifa-world-cup-streaming-sites-targets-virtual-fans/ 6、Windows 8.1 将于明年 1 月 10 日停止支持 https://www.solidot.org/story?sid=73442 7、勒索软件RansomExx2 已使用 Rust 完全重写 https://securityintelligence.com/posts/ransomexx-upgrades-rust/ 8、澳大利亚慈善机构The Smith Family遭受网络攻击 https://www.govinfosecurity.com/australian-childrens-charity-breach-affects-80000-donors-a-20528 9、研究人员发现新的勒索软件-Donut https://www.bleepingcomputer.com/news/security/donut-extortion-group-also-targets-victims-with-ransomware/ 10、支付宝等5家机构首批通过“个人金融信息保护能力”认证 http://www.news.cn/tech/20221122/3452a998efbb4e91b1b8417de8ea0db5/c.html
网络安全日报 2022年11月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、数千个应用泄露了 AlgoliaAPI 密钥,数百万用户数据受到威胁 https://www.securityweek.com/leaked-algolia-api-keys-exposed-data-millions-users 2、BMC 固件漏洞使 OT、物联网设备遭受远程攻击 https://www.securityweek.com/bmc-firmware-vulnerabilities-expose-ot-iot-devices-remote-attacks 3、微软在安全补丁导致 Kerberos 问题后发布带外更新 https://www.securityweek.com/microsoft-releases-out-band-update-after-security-patch-causes-kerberos-issues 4、基于Go的新型恶意软件“Aurora”被至少七个黑客组织采用 https://www.bleepingcomputer.com/news/security/aurora-infostealer-malware-increasingly-adopted-by-cybergangs/ 5、研究人员发现用于窃取加密货币的谷歌浏览器恶意扩展程序 https://www.bleepingcomputer.com/news/security/google-chrome-extension-used-to-steal-cryptocurrency-passwords/ 6、思科安全电子邮件网关存在漏洞而被绕过 https://www.securityweek.com/cisco-secure-email-gateway-filters-bypassed-due-malware-scanner-issue 7、AWS解决了影响 AWS AppSync 的漏洞 https://therecord.media/amazon-addresses-vulnerability-affecting-aws-appsync/ 8、大连警方侦破利用“跑马机”设备非法控制计算机信息系统案 https://www.anquanke.com/post/id/283506 9、DTrack开始针对欧洲和拉丁美洲发起攻击 https://www.4hou.com/posts/JXMv 10、黑客在对DraftKings的撞库攻击中窃取30万美元 https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack/