网络安全日报 2022年11月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌发布YARA规则和VirusTotal Collection,以帮助检测CobaltStrike https://www.securityweek.com/google-making-cobalt-strike-pentesting-tool-harder-abuse 2、研究人员发布了macOS 沙箱逃逸高危漏洞PoC 代码 https://www.securityweek.com/poc-code-published-high-severity-macos-sandbox-escape-vulnerability 3、Daixin 勒索软件团伙窃取了 500 万亚航乘客和员工的数据 https://thehackernews.com/2022/11/daixin-ransomware-gang-steals-5-million.html 4、臭名昭著的 Emotet 卷土重来,发起大量恶意垃圾邮件活动 https://thehackernews.com/2022/11/notorious-emotet-malware-returns-with.html 5、针对中东国家的网络钓鱼攻击在世界杯前激增 https://therecord.media/phishing-attacks-targeting-middle-east-countries-double-ahead-of-world-cup-report/ 6、 安全研究人员悄悄破解了勒索软件 Zeppelin https://www.solidot.org/story?sid=73414 7、印度政府发布《2022年个人数据保护法案》草案 https://www.freebuf.com/news/350314.html 8、Earth Preta 通过大规模鱼叉式网络钓鱼攻击多个行业 https://cyware.com/news/earth-preta-targets-multiple-sectors-with-large-scale-spear-phishing-ce639109 9、新攻击使用 Windows 安全绕过零日漏洞来投放恶意软件 https://www.bleepingcomputer.com/news/security/new-attacks-use-windows-security-bypass-zero-day-to-drop-malware/ 10、报告显示近半数 macOS 恶意程序来自一个应用-MacKeeper https://www.solidot.org/story?sid=73411
网络安全日报 2022年11月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Omron PLC 漏洞被复杂的 ICS 恶意软件利用 https://www.securityweek.com/omron-plc-vulnerability-exploited-sophisticated-ics-malware 2、Atlassian 修补了 Bitbucket、Crowd 中的严重漏洞 https://www.securityweek.com/atlassian-patches-critical-vulnerabilities-bitbucket-crowd 3、Hive 勒索软件已累计攻击 1,300 家企业,收取 1 亿美元赎金 https://www.securityweek.com/hive-ransomware-gang-hits-1300-businesses-makes-100-million 4、Exchange漏洞ProxyNotShell的PoC利用代码已公开 https://securityaffairs.co/wordpress/138768/hacking/proxynotshell-microsoft-exchange-poc.html 5、DEV-0569 组织使用 Google Ads 分发 Royal 勒索软件 https://securityaffairs.co/wordpress/138750/malware/dev-0569-google-ads-royal-ransomware.html 6、印度证券存管机构 CDSL 称恶意软件破坏了其网络 https://techcrunch.com/2022/11/18/cdsl-malware-internal-systems/ 7、Samba 修补了可能导致 DoS、远程代码执行的漏洞 https://www.securityweek.com/samba-patches-vulnerability-can-lead-dos-remote-code-execution 8、QBot恶意软件利用Windows控制面板程序感染设备 https://www.bleepingcomputer.com/news/security/qbot-phishing-abuses-windows-control-panel-exe-to-infect-devices/ 9、瓦努阿图政府网站疑似遭受勒索攻击 https://www.bbc.com/news/world-asia-63632129 10、网络钓鱼攻击冒充Instagram窃取用户凭据 https://www.infosecurity-magazine.com/news/instagram-credential-phishing
网络安全日报 2022年11月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、OpenSSF 采用微软内置的供应链安全框架 https://www.securityweek.com/openssf-adopts-microsoft-built-supply-chain-security-framework 2、密歇根州的两所公立学校遭到勒索软件攻击 https://securityaffairs.co/wordpress/138677/cyber-crime/public-schools-michigan-ransomware.html 3、臭名昭著的 Zeus 僵尸网络团伙头目在日内瓦被捕 https://thehackernews.com/2022/11/fbi-wanted-leader-of-notorious-zeus.html 4、Magento 商店成为大规模"TrojanOrders"攻击的目标 https://www.bleepingcomputer.com/news/security/magento-stores-targeted-in-massive-surge-of-trojanorders-attacks/ 5、KillNet黑客组织声称对FBI网站进行了DDoS攻击 https://www.bankinfosecurity.com/pro-moscow-nuisance-hackers-claim-ddos-attack-on-fbi-website-a-20471 6、Twitter 源代码表明,端到端加密私信即将到来 https://www.freebuf.com/news/350033.html 7、中美俄首次参与网安演习,明年将面对面对抗 https://www.freebuf.com/articles/349999.html 8、欧盟制定网络防御政策,以应对俄乌网络战 https://www.secrss.com/articles/48998 9、朝鲜黑客使用更新的恶意软件瞄准欧洲组织 https://www.bleepingcomputer.com/news/security/north-korean-hackers-target-european-orgs-with-updated-malware/ 10、福布斯全球2000强企业多数未采取关键域安全措施 https://www.csoonline.com/article/3680150/global-2000-companies-failing-to-adopt-key-domain-security-measures.html
网络安全日报 2022年11月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员披露F5了产品中的高危远程代码执行漏洞 https://www.securityweek.com/remote-code-execution-vulnerabilities-found-f5-products 2、Firefox 发布107版本,修复了大量漏洞 https://www.securityweek.com/firefox-107-patches-high-impact-vulnerabilities 3、Lazarus APT 使用 DTrack 后门攻击拉丁美洲和欧洲组织 https://securityaffairs.co/wordpress/138622/apt/dtrack-backdoor-targets-europe-latin-america.html 4、新的 RapperBot 活动针对游戏服务器发起DDoS攻击 https://securityaffairs.co/wordpress/138615/malware/rapperbot-botnet-targets-game-servers.html 5、谷歌将于 2023年初在Android 13上推出隐私沙盒系统测试版 https://securityaffairs.co/wordpress/138607/mobile-2/google-android-privacy-sandbox.html 6、研究人员发现数百个 Amazon RDS 实例泄露了用户的个人数据 https://thehackernews.com/2022/11/researchers-discover-hundreds-of-amazon.html 7、商业恶意软件Typhon Stealer出现新版本并更名为Typhon Reborn https://unit42.paloaltonetworks.com/typhon-reborn-stealer/ 8、 研究人员发现伪装成印度尼西亚人民银行的网络钓鱼活动 https://blog.cyble.com/2022/11/15/phishing-campaign-targeting-indonesian-bri-bank-using-sms-stealer/ 9、研究人员发现推特的双因素身份验证存在漏洞 https://www.govinfosecurity.com/twitter-two-factor-authentication-has-vulnerability-a-20475 10、意大利暂停使用面部识别技术,犯罪调查例外 https://www.solidot.org/story?sid=73370
网络安全日报 2022年11月16日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员在 Spotify 的后台发现了严重的 RCE漏洞 https://securityaffairs.co/wordpress/138591/security/spotify-backstage-rce.html 2、PCSpoof:一种影响航天器和飞机安全的新型攻击 https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html 3、黑客出售从俄罗斯共享踏板车服务平台Whoosh窃取的数据 https://www.bleepingcomputer.com/news/security/whoosh-confirms-data-breach-after-hackers-sell-72m-user-records/ 4、黑客入侵德意志银行的网络系统后开始出售访问权限 https://securityaffairs.co/wordpress/138416/data-breach/deutsche-bank-alleged-data-breach.html 5、世界互联网大会网络法治论坛发布《反电信网络诈骗倡议》 https://www.secrss.com/articles/48914 6、恶意活动通过伪造中文版Telegram网站投放远控木马 https://www.freebuf.com/articles/paper/347794.html 7、英国国家网络安全中心提醒该国消费者提高网络安全意识 https://www.ncsc.gov.uk/news/festive-shoppers-urged-to-be-cyber-aware 8、OakBend医疗中心承认勒索攻击事件导致数据泄露 https://www.govinfosecurity.com/texas-hospital-says-ransomware-breach-affected-500000-a-20454 9、研究人员披露了 Zendesk Explore中的严重 SQLi 和访问缺陷漏洞 https://thehackernews.com/2022/11/researchers-reported-critical-sqli-and.html 10、Mastodon 用户容易受到密码窃取攻击 https://portswigger.net/daily-swig/mastodon-users-vulnerable-to-password-stealing-attacks
网络安全日报 2022年11月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Aiphone门禁对讲系统存在漏洞可导致被攻击者开门 https://www.securityweek.com/aiphone-intercom-system-vulnerability-allows-hackers-open-doors 2、NSA 发布了有关组织如何缓解软件内存安全问题的指南 https://www.securityweek.com/nsa-publishes-guidance-mitigating-software-memory-safety-issues 3、谷歌因用户位置跟踪问题与40个州达成3.92亿美元的和解协议 https://www.securityweek.com/40-states-settle-google-location-tracking-charges-392m 4、大规模恶意 SEO 活动破坏了 15,000 多个 WordPress 网站 https://securityaffairs.co/wordpress/138523/hacking/wordpress-sites-black-hat-seo.html 5、Worok 黑客滥用 Dropbox API 通过隐藏在图像中的后门渗出数据 https://thehackernews.com/2022/11/worok-hackers-abuse-dropbox-api-to.html 6、谷歌发布安全补丁修复 Android 锁屏绕过漏洞 https://www.securityweek.com/google-pays-70k-android-lock-screen-bypass 7、研究人员发现用于挖矿和DDoS攻击的新型恶意软件KmsdBot https://securityaffairs.co/wordpress/138514/malware/kmsdbot-golang-malware.html 8、加密货币交易巨头FTX遭攻击申请破产,6亿美元资产被盗 https://www.freebuf.com/news/349677.html 9、乌警方逮捕了一个每年获利2亿欧元的网络诈骗团伙 https://securityaffairs.co/wordpress/138481/cyber-crime/ukraine-police-dismantled-fraud-group.html 10、欧盟网络安全局发布《2022 年网络安全威胁全景》报告 https://www.secrss.com/articles/48895
网络安全日报 2022年11月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、一名参与LockBit勒索攻击的嫌疑人在加拿大被捕 https://www.bleepingcomputer.com/news/security/russian-lockbit-ransomware-operator-arrested-in-canada/ 2、美国卫生部警告Venus勒索组织针对美国医疗组织发起攻击 https://www.bleepingcomputer.com/news/security/us-health-dept-warns-of-venus-ransomware-targeting-healthcare-orgs/ 3、研究人员发现Conti将其业务转移至BlackByte和Black Basta中 https://cyware.com/news/conti-affiliates-blackbyte-and-black-basta-rotating-targets-681fc6b8 4、研究人员发现针对印度国防人员的Spymax RAT新变种 https://www.cyfirma.com/outofband/unknown-nation-based-threat-actor-using-android-rat-to-target-indian-defence-personnel-2/ 5、思科修复企业防火墙产品中的33个漏洞 https://www.securityweek.com/cisco-patches-33-vulnerabilities-enterprise-firewall-products 6、GitHub 为公共存储库引入私有漏洞报告功能 https://www.securityweek.com/github-introduces-private-vulnerability-reporting-public-repositories 7、Foxit 修复了 PDF Reader 中的多个代码执行漏洞 https://www.securityweek.com/foxit-patches-several-code-execution-vulnerabilities-pdf-reader 8、Lockbit团伙泄露了从科技巨头Thales 窃取的数据 https://securityaffairs.co/wordpress/138471/data-breach/lockbit-leaked-thales-files.html 9、加拿大第二大连锁超市 Sobeys 遭遇勒索软件攻击 https://securityaffairs.co/wordpress/138424/cyber-crime/sobeys-ransomware-attack.html 10、LiteSpeed存在漏洞,可导致Web服务器被完全接管 https://www.securityweek.com/litespeed-vulnerabilities-can-lead-complete-web-server-takeover
网络安全日报 2022年11月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、ABB 石油和天然气流量和控制器受到严重漏洞的影响 https://www.securityweek.com/abb-oil-and-gas-flow-computer-hack-can-prevent-utilities-billing-customers 2、LockBit 以 5000 万美元的价格出售从Continental 窃取的文件 https://www.securityweek.com/ransomware-gang-offers-sell-files-stolen-continental-50-million 3、Apple 更新修补了 iOS、macOS 中的远程代码执行漏洞 https://www.securityweek.com/apple-patches-remote-code-execution-flaws-ios-macos 4、联想修复了两个影响各种笔记本电脑型号的严重漏洞 https://securityaffairs.co/wordpress/138312/security/lenovo-bypass-security-features.html 5、研究人员发现了隐藏在图像文件中的恶意代码 PyPI 包-apicolor https://thehackernews.com/2022/11/researchers-uncover-pypi-package-hiding.html 6、攻击者入侵 15,000 个网站进行大规模谷歌 SEO 中毒活动 https://blog.sucuri.net/2022/11/massive-ois-is-black-hat-redirect-malware-campaign.html 7、美国CISA成立化工行业网络安全工作组 https://www.secrss.com/articles/48789 8、欧盟政府被指控使用间谍软件掩盖腐败和犯罪活动 https://therecord.media/eu-governments-accused-of-using-spyware-to-cover-up-corruption-and-criminal-activity/ 9、研究人员警告针对印度顶级银行客户的大规模钓鱼活动 https://thehackernews.com/2022/11/warning-this-widespread-malicious.html 10、LockBit 附属组织使用 Amadey Bot部署勒索软件 https://www.bleepingcomputer.com/news/security/lockbit-affiliate-uses-amadey-bot-malware-to-deploy-ransomware/
网络安全日报 2022年11月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、VMware修复了Workspace ONE Assist中的三个身份验证漏洞 https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-auth-bypass-bugs-in-remote-access-tool/ 2、微软修复了ProxyNotShell零日漏洞 https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-proxynotshell-exchange-zero-days-exploited-in-attacks/ 2、谷歌披露监控供应商利用三星手机的零日漏洞 https://securityaffairs.co/wordpress/138302/hacking/surveillance-vendor-exploited-samsung-phone-zero-days.html 3、攻击者利用 IPFS 去中心化网络托管恶意软件 https://www.securityweek.com/attackers-using-ipfs-distributed-bulletproof-malware-hosting 4、研究人员发现一个名为Cloud9的新Chrome浏览器僵尸网络 https://www.bleepingcomputer.com/news/security/malicious-extension-lets-attackers-control-google-chrome-remotely/ 5、英国情报公司雇用大批印度黑客进行非法“调查” https://www.secrss.com/articles/48738 6、《信息安全技术 关键信息基础设施安全保护要求》发布 https://www.freebuf.com/news/349108.html 7、新的 IceXLoader 恶意软件变种感染了全球数千名受害者 https://thehackernews.com/2022/11/new-icexloader-malware-loader-variant.html 8、英特尔和 AMD周二补日解决了数十个漏洞 https://www.securityweek.com/intel-amd-address-many-vulnerabilities-patch-tuesday-advisories 9、Microsoft 修补了 MotW 零日漏洞 https://www.securityweek.com/microsoft-patches-motw-zero-day-exploited-malware-delivery 10、黑客开始泄露从Medibank 窃取的敏感医疗记录 https://www.securityweek.com/hackers-leak-australian-health-records-dark-web
网络安全日报 2022年11月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌修补Android中的高危提权漏洞 https://www.securityweek.com/google-patches-high-severity-privilege-escalation-vulnerabilities-android 2、勒索软件团伙威胁要发布 Medibank 客户信息 https://www.securityweek.com/ransomware-gang-threatens-publish-medibank-customer-information 3、美国查获了10年前黑客从丝绸之路窃取的 34 亿美元比特币 https://www.securityweek.com/us-seizes-34-billion-bitcoin-stolen-silk-road 4、西门子和施耐德电气修复了多个严重漏洞 https://www.securityweek.com/ics-patch-tuesday-siemens-addresses-critical-vulnerabilities 5、加拿大肉类巨头 Maple Leaf Foods遭网络攻击导致业务中断 https://www.securityweek.com/cyberattack-causes-disruptions-canadian-meat-giant-maple-leaf-foods 6、Citrix ADC 和Gateway 受到高危身份验证绕过漏洞的影响 https://securityaffairs.co/wordpress/138264/security/citrix-gateway-adc-flaws.html 7、SmokeLoader 活动分发新的 Laplas Clipper 恶意软件 https://securityaffairs.co/wordpress/138251/malware/smokeloader-delivers-laplas-clipper.html 8、Amadey恶意软件在被黑机器上部署 LockBit 3.0 勒索软件 https://thehackernews.com/2022/11/amadey-bot-spotted-deploying-lockbit-30.html 9、诺基亚修复移动基带套件中的漏洞 https://www.itnews.com.au/news/nokia-moves-to-patch-vulnerable-mobile-baseband-kit-587514 10、安全厂商发布RanHassan勒索软件免费解密工具 https://www.bitdefender.com/blog/labs/ranhassan-ransomware-decryptor-now-available/