网络安全日报 2022年11月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、澳大利亚健康保险公司Medibank 确认数据泄露影响了 970 万客户 https://www.securityweek.com/medibank-confirms-data-breach-impacts-97-million-customers 2、2023年微软将继续向乌克兰提供免费云服务,高达1亿美元 https://www.theregister.com/2022/11/04/microsoft_ukraine_tech_support/ 3、日本宣布正式加入北约网络防御中心 https://www.secrss.com/articles/48669 4、研究人员发现针对印度政府雇员的新恶意软件活动 https://thehackernews.com/2022/11/researchers-detail-new-malware-campaign.html 5、波音子公司遭网络攻击,致使全球多家航司航班规划中断 https://www.secrss.com/articles/48677 6、记者卧底调查:“网课爆破”污秽不堪,涉嫌违法犯罪 https://news.ycwb.com/2022-11/05/content_41149409.htm 7、湖南一公务员非法获取公民个人信息4亿余条:非法获利170余万 https://www.secrss.com/articles/48689 8、Check Point发布Q3全球网络攻击报告,医疗保健行业最易受勒索攻击 http://www.anquan419.com/news/21/1677.html 9、"Justice Blade" 黑客组织针对沙特阿拉伯 https://securityaffairs.co/wordpress/138213/hacking/justice-blade-targets-saudi-arabia.html 10、网络钓鱼活动滥用Microsoft Dynamics 365 客户语音窃取用户凭证 https://securityaffairs.co/wordpress/138147/cyber-crime/microsoft-dynamics-365-customer-voice-phishing.html
网络安全日报 2022年11月07日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LockBit 3.0 团伙声称从 Kearney & Company 窃取了数据 https://securityaffairs.co/wordpress/138136/cyber-crime/lockbit-ransomware-kearney-company.html 2、微软称零日漏洞在越来越短的时间内被大规模利用 https://securityaffairs.co/wordpress/138100/security/treat-actors-zero-day.html 3、智利ALMA天文台因网络攻击而关闭运营 https://www.bleepingcomputer.com/news/security/alma-observatory-shuts-down-operations-due-to-a-cyberattack/ 4、AstraZeneca暴露了对其患者数据信息的访问权限 https://techcrunch.com/2022/11/03/astrazeneca-passwords-exposed-patient-data/ 5、网络攻击导致丹麦国家铁路列车停止运行 https://www.securityweek.com/cyberattack-causes-trains-stop-denmark 6、Robin Banks网络钓鱼活动重新上线 https://www.bleepingcomputer.com/news/security/robin-banks-phishing-service-returns-to-steal-banking-accounts/ 7、英国政府机构正在扫描该国托管的所有互联网设备 https://www.bleepingcomputer.com/news/security/british-govt-is-scanning-all-internet-devices-hosted-in-uk/ 8、研究人员发现多封针对推特认证用户的钓鱼邮件 https://www.bleepingcomputer.com/news/security/as-twitter-brings-on-8-fee-phishing-emails-target-verified-accounts 9、中央网信办印发《关于切实加强网络暴力治理的通知》 https://www.freebuf.com/news/348958.html 10、因对Twitter安全和内容审核不满,马斯克裁撤Twitter整个安全部门 https://www.freebuf.com/news/348957.html
网络安全日报 2022年11月04日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Splunk 修补了 9 个企业产品中的高危漏洞 https://www.securityweek.com/splunk-patches-9-high-severity-vulnerabilities-enterprise-product 2、LockBit 勒索软件团伙声称已入侵跨国集团 Continental https://securityaffairs.co/wordpress/138062/cyber-crime/lockbit-gang-claims-continental-hack.html 3、安全研究人员将 Black Basta 勒索软件与 FIN7 网络犯罪团伙关联 https://securityaffairs.co/wordpress/138037/cyber-crime/black-basta-linked-fin7.html 4、黑客使用恶意版本的 KeePass 和 SolarWinds 软件分发 RomCom RAT https://thehackernews.com/2022/11/hackers-using-rogue-versions-of-keepass.html 5、Drinik 恶意软件现在针对 18 家印度银行 https://cyware.com/news/drinik-malware-now-targets-18-indian-banks-1921d2bc 6、Emotet 僵尸网络在沉寂 5 个月后再次开始传播恶意软件 https://www.bleepingcomputer.com/news/security/emotet-botnet-starts-blasting-malware-again-after-5-month-break/ 7、超过 250 个美国新闻网站遭供应链攻击传播恶意软件 https://www.securityweek.com/over-250-us-news-websites-deliver-malware-supply-chain-attack 8、研究人员在数十个PyPI软件包中发现W4SP窃密木马 https://www.bleepingcomputer.com/news/security/dozens-of-pypi-packages-caught-dropping-w4sp-info-stealing-malware/ 9、研究人员发现新型Laplas Clipper通过SmokeLoader进行传播 https://blog.cyble.com/2022/11/02/new-laplas-clipper-distributed-by-smokeloader/ 10、OPERA1ER APT 黑客针对非洲数十家金融组织 https://thehackernews.com/2022/11/researchers-detail-opera1er-apt-attacks.html
网络安全日报 2022年11月03日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Fortinet 修补影响多个产品的6 个高危漏洞 https://www.securityweek.com/fortinet-patches-6-high-severity-vulnerabilities 2、一种新的安卓恶意软件-SandStrike针对讲波斯语的宗教少数群体 https://securityaffairs.co/wordpress/137990/hacking/sandstrike-malware-cyberespionage.html 3、Dropbox 披露安全漏洞,攻击者未经授权访问了 130 个 GitHub 源码库 https://securityaffairs.co/wordpress/137975/hacking/dropbox-account-hacked-2fa-jpg.html 4、OpenSSL 项目修复了两个高危漏洞 https://securityaffairs.co/wordpress/137965/security/openssl-fixed-two-vulnerabilities.html 5、Checkmk IT Infrastructure监控软件存在多个漏洞 https://thehackernews.com/2022/11/multiple-vulnerabilities-reported-in.html 6、微软修补了Azure Cosmos DB中的漏洞 https://www.securityweek.com/microsoft-patches-azure-cosmos-db-flaw-leading-remote-code-execution 7、Fodcha DDoS 僵尸网络重出江湖,增加勒索功能 https://thehackernews.com/2022/10/fodcha-ddos-botnet-resurfaces-with-new.html 8、澳大利亚国防部通信平台遭黑客攻击 https://www.anquanke.com/post/id/282400 9、Mozilla Firefox 修复了Windows 11新功能导致死机的BUG https://www.bleepingcomputer.com/news/security/mozilla-firefox-fixes-freezes-caused-by-new-windows-11-feature/ 10、美国财政部:2021年金融机构因勒索攻击损失超12亿美元 https://www.secrss.com/articles/48587
网络安全日报 2022年11月02日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、安天发布疑似Lazarus组织针对韩国的攻击活动分析 https://mp.weixin.qq.com/s/w-KF5HUNe8-KlmFl6zLkZw 2、黑客以400万美元的价格出售全球576个企业网络的访问权限 https://www.bleepingcomputer.com/news/security/hackers-selling-access-to-576-corporate-networks-for-4-million/ 3、明年 2 月起,微软 Win10 系统将永久禁用 IE11 https://www.ithome.com/0/649/960.htm 4、工信部拟规定:智能网联汽车生产商应建立车辆产品网络安全等制度 https://www.chinanews.com.cn/cj/2022/10-28/9881839.shtml 5、中国台湾全岛个人信息被放在网上兜售,黑客开价5000美元 https://www.freebuf.com/news/348462.html 6、苹果推出新的安全研究网站,加快对漏洞报告的响应 https://www.ithome.com/0/649/517.htm 7、LockBit 3.0团伙声称从法国国防和技术集团泰雷兹窃取了数据 https://securityaffairs.co/wordpress/137955/cyber-crime/lockbit-3-0-thales.html 8、ConnectWise 解决了服务器备份解决方案中的关键RCE漏洞 https://securityaffairs.co/wordpress/137946/uncategorized/connectwise-rce.html 9、VMware 警告近期针对NSX-V 漏洞的利用 https://www.securityweek.com/vmware-warns-exploit-recent-nsx-v-vulnerability 10、 欧盟委员会推出首个欧盟GDPR认证机制 https://www.secrss.com/articles/48524
网络安全日报 2022年11月01日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、黑客正在对新西兰航空公司发起撞库攻击 https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html 2、0patch发布Windows MoTW零日漏洞非官方补丁 https://www.bleepingcomputer.com/news/microsoft/actively-exploited-windows-motw-zero-day-gets-unofficial-patch/ 3、BlackByte勒索软件攻击了Asahi Group Holdings公司 https://securityaffairs.co/wordpress/137803/cyber-crime/blackbyte-ransomware-asahi-group-holdings.html 4、三星 Galaxy Store 漏洞可能让黑客在目标设备上秘密安装应用 https://thehackernews.com/2022/10/samsung-galaxy-store-bug-couldve-let.html 5、Snatch 勒索团伙声称已入侵军事供应商 HENSOLDT France https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html 6、Fodcha DDoS 僵尸网络以新功能重新出现 https://thehackernews.com/2022/10/fodcha-ddos-botnet-resurfaces-with-new.html 7、2023年1月1日施行!《网络产品安全漏洞收集平台备案管理办法》发布 https://www.freebuf.com/news/348234.html 8、VMware 修补了NSX-V中一个危险等级 9.8/10 高危漏洞 https://www.solidot.org/story?sid=73209 9、新的"Azoz勒索软件"擦拭器试图陷害安全研究人员 https://www.bleepingcomputer.com/news/security/new-azov-data-wiper-tries-to-frame-researchers-and-bleepingcomputer/ 10、谷歌发布紧急 Chrome 107 更新以修补被利用的零日漏洞 https://www.securityweek.com/google-releases-emergency-chrome-107-update-patch-actively-exploited-zero-day
网络安全日报 2022年10月31日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Drinik恶意软件针对印度银行的用户发起攻击 https://blog.cyble.com/2022/10/27/drinik-malware-returns-with-advanced-capabilities-targeting-indian-taxpayers/ 2、疑似TeamTNT组织开启新一轮挖矿行动 https://thehackernews.com/2022/10/new-cryptojacking-campaign-targeting.html 3、微软发现Raspberry Robin蠕虫与Clop勒索软件存在联系 https://www.bleepingcomputer.com/news/security/microsoft-links-raspberry-robin-worm-to-clop-ransomware-attacks/ 4、GitHub修复了将存储库暴露给攻击者的关键漏洞 https://www.hackread.com/github-high-severity-repositories-vulnerability/ 5、Juniper中的Junos OS组件存在严重缺陷 https://thehackernews.com/2022/10/high-severity-flaws-in-juniper-junos-os.html 6、东欧国家首都的议会IT系统遭网络攻击 https://www.govinfosecurity.com/cyber-events-disrupt-polish-slovakian-parliament-systems-a-20358 7、Twilio表示Smishing攻击受害者人数不断增加 https://www.govinfosecurity.com/final-twilio-smishing-victim-count-reaches-209-a-20362 8、欧盟最大铜生产商Aurubis遭受网络攻击 https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/ 9、Azure CLI存在代码注入漏洞 https://securityboulevard.com/2022/10/azure-cli-code-injection-cve-2022-39327-hits-9-8-10-cvss-score/ 10、英国前首相利兹特拉斯的手机被怀疑遭俄罗斯间谍窃听 https://securityaffairs.co/wordpress/137826/intelligence/liz-truss-phone-hacked.html
网络安全日报 2022年10月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Raspberry Robin蠕虫向勒索团伙出售受损企业网络的访问权限 https://securityaffairs.co/wordpress/137722/malware/raspberry-robin-clop-ransomware.html 2、跨国媒体集团 Thomson Reuters泄露了3TB敏感数据 https://securityaffairs.co/wordpress/137718/data-breach/thomson-reuters-database-exposed.html 3、SiriSpy 漏洞允许窃听用户与 Siri 的对话 https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html 4、GitHub 帐户重命名可能导致供应链攻击 https://www.securityweek.com/github-account-renaming-could-have-led-supply-chain-attacks 5、研究人员公开了 80 多个恶意软件ShadowPad的 C2 服务器 https://thehackernews.com/2022/10/researchers-expose-over-80-shadowpad.html 6、安天发布白象组织近期网络攻击活动分析报告 https://mp.weixin.qq.com/s/BXjZ6fEgNmLY_l8cZt1FXQ 7、Vice Society组织使用多种勒索软件发起攻击 https://thehackernews.com/2022/10/vice-society-hackers-are-behind-several.html 8、LV勒索软件利用ProxyShell攻击一家位于约旦的公司 https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html 9、黑客部署RomCom RAT对乌克兰军方发起攻击 https://thehackernews.com/2022/10/romcom-hackers-circulating-malicious.html 10、新的挖矿活动针对易受攻击的Docker和Kubernetes实例 https://thehackernews.com/2022/10/new-cryptojacking-campaign-targeting.html
网络安全日报 2022年10月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌浏览器将于 2023 年 2 月放弃对 Windows 7 / 8.1 的支持 https://www.bleepingcomputer.com/news/google/google-chrome-to-drop-support-for-windows-7-81-in-feb-2023/ 2、 韩首次参加美主导的“网络旗帜”多国联合网络攻防演习 https://m.gmw.cn/baijia/2022-10/25/1303177306.html 3、伊朗原子能组织遭黑客攻击,大量敏感数据泄露 https://www.secrss.com/articles/48251 4、OpenSSL 修补自 2016 年以来的第一个严重漏洞 https://www.securityweek.com/openssl-patch-first-critical-vulnerability-2016 5、国际票务公司 See Tickets 披露数据泄露事件,客户支付卡信息泄露 https://securityaffairs.co/wordpress/137673/data-breach/see-tickets-data-breach.html 6、VMware 修复了 VMware Cloud Foundation 中的严重 RCE漏洞 https://securityaffairs.co/wordpress/137640/hacking/vmware-cloud-foundation-rce.html 7、Cisco AnyConnect 客户端中的两个漏洞被利用 https://securityaffairs.co/wordpress/137654/security/cisco-anyconnect-secure-mobility-flaws.html 8、Melis Platform CMS修补了关键RCE漏洞 https://portswigger.net/daily-swig/melis-platform-cms-patched-for-critical-rce-flaw 9、工业互联网总体网络架构国家标准正式发布 https://www.secrss.com/articles/48266 10、Kimsuky 使用 3 个新的 Android 恶意软件针对韩国人 https://thehackernews.com/2022/10/kimsuky-hackers-spotted-using-3-new.html
网络安全日报 2022年10月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LockBit勒索软件团伙攻击了汽车经销商Pendragon https://www.bleepingcomputer.com/news/security/pendragon-car-dealer-refuses-60-million-lockbit-ransomware-demand/ 2、Abode Home Security Kit中的严重缺陷允许黑客劫持、禁用摄像头 https://cert.gov.ua/article/2394117 3、SQLite 数据库一个存在 22 年之久的高危漏洞被披露 https://thehackernews.com/2022/10/22-year-old-vulnerability-reported-in.html 4、Hive 勒索软件开始泄露从 Tata Power Energy 公司窃取的数据 https://thehackernews.com/2022/10/hive-ransomware-hackers-begin-leaking.html 5、研究人员披露了Windows 事件日志的两个漏洞详细信息 https://thehackernews.com/2022/10/researchers-detail-windows-event-log.html 6、Apple 发布 macOS Ventura 13 修补了 100 多个漏洞 https://www.securityweek.com/apple-patches-over-100-vulnerabilities-release-macos-ventura-13 7、Jira Align 漏洞使 Atlassian 基础设施受到攻击 https://www.securityweek.com/jira-align-vulnerabilities-exposed-atlassian-infrastructure-attacks 8、恶意软件活动Dormant Colors 通过Chrome 扩展程序劫持浏览器 https://www.bleepingcomputer.com/news/security/chrome-extensions-with-1-million-installs-hijack-targets-browsers/ 9、Orca Security披露Azure SFX漏洞FabriXss细节 https://www.anquanke.com/post/id/282019 10、两个 PoS 恶意软件窃取了 167,000 多张信用卡数据 https://securityaffairs.co/wordpress/137608/malware/pos-malware-stolen-card-data.html