网络安全日报 2022年10月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Apple 发布 iOS 16.1 补丁修复被利用的零日漏洞 https://www.securityweek.com/apple-fixes-exploited-zero-day-ios-161-patch 2、研究人员发现了数千个 GitHub项目提供虚假PoC分发恶意软件 https://securityaffairs.co/wordpress/137527/hacking/malicious-github-repositories.html 3、SideWinder APT 使用新的 WarHawk 后门攻击巴基斯坦的实体 https://thehackernews.com/2022/10/sidewinder-apt-using-new-warhawk.html 4、Typosquat冒充27个品牌推送Windows和Android恶意软件 https://www.bleepingcomputer.com/news/security/typosquat-campaign-mimics-27-brands-to-push-windows-android-malware/ 5、卡塔尔世界杯官方应用被指是间谍软件 https://www.solidot.org/story?sid=73123 6、Facebook 开发出闽南语 AI 翻译系统 https://www.solidot.org/story?sid=73132 7、得州起诉 Google 非法收集生物识别数据 https://www.solidot.org/story?sid=73127 8、国际刑警组织建立元宇宙总部,关注在虚拟现实中的犯罪 https://www.cnbeta.com/articles/tech/1330087.htm 9、CISA 警告 Daixin Team 黑客使用勒索软件攻击卫生组织 https://thehackernews.com/2022/10/cisa-warns-of-daixin-team-hackers.html 10、名为TommyLeaks和SchoolBoys的新网络勒索组织针对全球多家公司 https://www.freebuf.com/news/347695.html
网络安全日报 2022年10月24日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、OldGremlin黑客使用Linux勒索软件攻击俄罗斯组织 https://www.bleepingcomputer.com/news/security/oldgremlin-hackers-use-linux-ransomware-to-attack-russian-orgs/ 2、Ursnif恶意软件将重点转移到勒索软件和数据盗窃上 https://www.zdnet.com/article/this-old-malware-has-been-rebuilt-with-new-features-to-use-in-ransomware-attacks/ 3、批发巨头METRO遭网络攻击后IT系统中断 https://www.bleepingcomputer.com/news/security/wholesale-giant-metro-hit-by-it-outage-after-cyberattack/ 4、黑客开始利用Text4Shell漏洞发起攻击 https://thehackernews.com/2022/10/hackers-started-exploiting-critical.html 5、多个活动利用VMware漏洞部署加密矿工和勒索软件 https://thehackernews.com/2022/10/multiple-campaigns-exploit-vmware.html 6、Emotet僵尸网络发起新一轮恶意垃圾邮件活动 https://thehackernews.com/2022/10/emotet-botnet-distributing-self.html 7、研究人员披露了Move虚拟机中现已修补漏洞的详细信息 https://thehackernews.com/2022/10/critical-flaw-reported-in-move-virtual.html 8、黑客窃取了伊朗原子能机构的敏感数据 https://securityaffairs.co/wordpress/137513/hacking/hackers-stole-sensitive-data-from-irans-atomic-energy-agency.html 9、《汽车数据处理安全要求》等 14 项网络安全国家标准获批发布 https://www.secrss.com/articles/48092 10、亚马逊因滥用算法在英国面临集体诉讼 https://www.ithome.com/0/647/771.htm
网络安全日报 2022年10月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、谷歌开源【软件供应链安全】工具GUAC https://github.com/guacsec/guac 2、微软确认数据泄露事件,大量客户信息被暴露 https://securityaffairs.co/wordpress/137397/data-breach/microsoft-data-leak-2.html 3、巴西警方逮捕了一名涉嫌参与 LAPSUS$勒索软件团伙的男子 https://securityaffairs.co/wordpress/137381/cyber-crime/brazilian-police-arrested-lapsus-member.html 4、安全研究人员发现了数百万个公开的 .git 文件夹 https://securityaffairs.co/wordpress/137371/security/millions-git-folders-exposed-public.html 5、16款被Clicker 恶意软件感染的 Android 应用下载量超 2000 万次 https://thehackernews.com/2022/10/these-16-clicker-malware-infected.html 6、新的 Ursnif 变体将重点转移到勒索软件和数据盗窃上 https://thehackernews.com/2022/10/latest-ursnif-variant-shifts-focus-from.html 7、德国Stimme Mediengruppe集团遭勒索软件攻击 https://www.malwarebytes.com/blog/news/2022/10/ransomware-attack-freezes-newspaper-printing-system 8、研究人员公布Azure SFX漏洞详细信息 https://thehackernews.com/2022/10/researchers-detail-azure-sfx-flaw-that.html 9、德国网络安全负责人因涉嫌与俄罗斯有联系而被解雇 https://www.inforisktoday.com/german-cybersecurity-head-dismissed-for-alleged-russia-ties-a-20287 10、新加坡成立反勒索软件工作组以应对威胁 https://www.infosecurity-magazine.com/news/singapore-creates-ransomware-task/
网络安全日报 2022年10月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现大量恶意应用程序窃取Facebook登录信息 https://www.malwarebytes.com/blog/news/2022/10/warning-facestealer-ios-and-android-apps-steal-your-facebook-login 2、研究人员发现针对开源存储库的网络攻击增加了633% https://portswigger.net/daily-swig/researchers-find-633-increase-in-cyber-attacks-aimed-at-open-source-repositories 3、研究人员称RansomCartel勒索团伙与REvil勒索团伙有关 https://www.bleepingcomputer.com/news/security/ransom-cartel-linked-to-notorious-revil-ransomware-operation/ 4、Apache Commons Text中存在严重的安全漏洞 https://blog.aquasec.com/cve-2022-42889-text2shell-apache-commons-vulnerability 5、研究人员发现了新的完全无法检测到的PowerShell后门 https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/ 6、VisionWeb数据泄露影响多达35900人 https://www.hipaajournal.com/visionweb-data-breach-affects-up-to-35900-individuals/ 7、Lazarus APT在日本利用网络钓鱼攻击加密货币交易所 https://cryptopotato.com/north-korean-hacker-group-lazarus-phishing-for-crypto-in-japan-report/ 8、八块RTX 4090显卡阵列可在60分钟内破解八位密码 https://www.cnbeta.com/articles/tech/1328407.htm 9、黑客称他们从英国一保险公司窃取了 1.4TB 数据 https://cybernews.com/news/hackers-stole-data-from-kingfisher-insurance/ 10、施耐德 UMAS 协议中的漏洞被发现 https://www.itweb.co.za/content/WnxpE74YYExMV8XL
网络安全日报 2022年10月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、欧洲风险投资和私募股权公司 Smartfin收购了Hex-Rays https://www.securityweek.com/ida-pro-owner-hex-rays-acquired-european-vc-firm 2、工业网络安全市场预计将在未来十年以显着速度增长 https://www.securityweek.com/industrial-cybersecurity-market-expected-soar-next-decade 3、超过 17000 台在线 Fortinet 设备易受到 CVE-2022-40684 的攻击 https://securityaffairs.co/wordpress/137273/hacking/fortinet-cve-2022-40684-vulnerable-systems.html 4、欧洲警方逮捕了一个黑入无线遥控钥匙偷车的团伙 https://thehackernews.com/2022/10/european-police-arrest-gang-that-hacked.html 5、黑客利用Qakbot银行木马部署Brute Ratel C4框架 https://thehackernews.com/2022/10/black-basta-ransomware-hackers.html 6、墨西哥调查“飞马”间谍软件的购买是否经过授权 https://www.cnbeta.com/articles/tech/1327983.htm 7、研究人员发现微软Office 365消息加密方法存在漏洞 https://www.hackread.com/office-365-encryption-flaw-message-confidentiality/ 8、红队工具Cobalt Strike发布更新修复了一个远程代码执行漏洞 https://thehackernews.com/2022/10/critical-rce-vulnerability-discovered.html 9、新的PHP信息窃取恶意软件针对Facebook帐户 https://www.bleepingcomputer.com/news/security/new-php-information-stealing-malware-targets-facebook-accounts/ 10、苹果承认部分iPhone 14存在“不支持SIM卡”问题 https://www.cnbeta.com/articles/tech/1327955.htm
网络安全日报 2022年10月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员绕过了微软更新的"ProxyNotShell "漏洞修复指导方案 https://www.4hou.com/posts/q8nR 2、Zoom for macOS 推出补丁修复高危漏洞 https://www.securityweek.com/zoom-macos-contains-high-risk-security-flaw 3、新 UEFI rootkit Black Lotus 售价 5,000 美元 https://securityaffairs.co/wordpress/137252/malware/black-lotus-uefi-rootkit.html 4、日本科技公司 Oomiya 的 IT 基础设施遭 LockBit 3.0 勒索软件攻击 https://securityaffairs.co/wordpress/137243/cyber-crime/oomiya-lockbit-3-0-ransomware.html 5、国际刑警组织逮捕了网络犯罪团伙 Black Axe 的 75 名成员 https://securityaffairs.co/wordpress/137220/cyber-crime/interpol-arrests-black-axe-members.html 6、Venus勒索软件对公开暴露的远程桌面服务发起攻击 https://www.bleepingcomputer.com/news/security/venus-ransomware-targets-publicly-exposed-remote-desktop-services/ 7、CISA发布RedEye开源分析工具 https://www.helpnetsecurity.com/2022/10/17/cisa-redeye-open-source-analytic-tool/ 8、公网中超过45000台ESXi服务器生命周期结束,易受攻击 https://www.bleepingcomputer.com/news/security/over-45-000-vmware-esxi-servers-just-reached-end-of-life/ 9、0path补丁服务为Windows 7系统额外提供2年支持至2025年 https://www.cnbeta.com/articles/tech/1326971.htm 10、关键 Fortinet 身份验证绕过漏洞的POC已经发布 https://thehackernews.com/2022/10/poc-exploit-released-for-critical.html
网络安全日报 2022年10月17日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Magniber勒索软件通过JavaScript文件感染Windows用户 https://www.bleepingcomputer.com/news/security/magniber-ransomware-now-infects-windows-users-via-javascript-files/ 2、GitLab修复GitHub导入功能中的RCE漏洞 https://portswigger.net/daily-swig/gitlab-patches-rce-bug-in-github-import-function 3、荷兰警方伪造赎金支付诱骗DeadBolt勒索软件团伙获得155个解密密钥 https://www.bleepingcomputer.com/news/security/police-tricks-deadbolt-ransomware-out-of-155-decryption-keys/ 4、Microsoft电子邮件加密协议存在严重的安全漏洞 https://www.govinfosecurity.com/microsoft-email-encryption-vulnerable-to-structural-leaks-a-20262 5、黑客使用Zimbra零日漏洞攻击近900台服务器 https://www.bleepingcomputer.com/news/security/almost-900-servers-hacked-using-zimbra-zero-day-flaw/ 6、Mango Markets同意向黑客支付4700万美元作为漏洞赏金 https://www.govinfosecurity.com/mango-markets-set-to-pay-47m-bug-bounty-to-hacker-a-20275 7、BAE 为 F-16 战斗机发布新的网络安全系统 https://www.securityweek.com/bae-releases-new-cybersecurity-system-f-16-fighter-aircraft 8、印度最大电力公司 Tata Power 的 IT 基础设施受到网络攻击 https://thehackernews.com/2022/10/indian-energy-company-tata-powers-it.html 9、Palo Alto Networks修复了PAN-OS中的高危身份验证绕过漏洞 https://securityaffairs.co/wordpress/137138/security/palo-alto-networks-pan-os-flaw-3.html 10、研究人员发现冒充Convertio网站传播恶意软件的活动 https://blog.cyble.com/2022/10/14/online-file-converter-phishing-page-spreads-redline-stealer/
网络安全日报 2022年10月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Cloudflare 阻止了针对 Minecraft 服务器的 2.5 Tbps DDoS 攻击 https://securityaffairs.co/wordpress/137062/hacking/ddos-attack-record-q3-2022.html 2、研究人员发现一种新的攻击框架,包括一个名为 Alchimist 的 C2 工具 https://securityaffairs.co/wordpress/137046/hacking/alchimist-c2-tool.html 3、Mango Markets 在闪电贷攻击中损失超过 1 亿美元 https://therecord.media/crypto-trading-platform-mango-markets-drained-of-more-than-100-million-in-flash-loan-attack/ 4、Robustel R1510 工业蜂窝网络路由器存在多个严重漏洞 https://blog.talosintelligence.com/2022/10/vuln-spotlight-robustel-router.html 5、黑客组织Polonium使用恶意软件针对以色列发起攻击 https://thehackernews.com/2022/10/researchers-uncover-custom-backdoors.html 6、npm定时攻击可能威胁供应链安全 https://www.bleepingcomputer.com/news/security/new-npm-timing-attack-could-lead-to-supply-chain-attacks/ 7、NIST 牵头组建商用卫星利益共同体,推进混合卫星网络安全指南研制 https://www.secrss.com/articles/47824 8、西门子SIMATIC PLC中的严重漏洞可能让攻击者窃取加密密钥 https://thehackernews.com/2022/10/critical-bug-in-siemens-simatic-plcs.html 9、QBot恶意软件在新的攻击活动中感染了800多名企业用户 https://www.securityweek.com/qbot-malware-infects-over-800-corporate-users-new-ongoing-campaign 10、Aruba修复了EdgeConnect Enterprise Orchestrator中的关键漏洞 https://securityaffairs.co/wordpress/137000/security/aruba-edgeconnect-flaws.html
网络安全日报 2022年10月13日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Google 向 Android 和 Chrome 推出 Passkey 无密码登录支持 https://thehackernews.com/2022/10/google-rolling-out-passkey-passwordless.html 2、VMware 尚未修复一年前披露的 vCenter Server 中的提权漏洞 https://securityaffairs.co/wordpress/136979/hacking/vmware-unpatched-cve-2021-22048.html 3、LockBit 附属公司入侵 Microsoft Exchange 服务器以部署勒索软件 https://securityaffairs.co/wordpress/136968/cyber-crime/microsoft-exchange-lockbit-ransomware.html 4、网络犯罪分子使用 Vishing 诱骗受害者安装 Android 银行恶意软件 https://thehackernews.com/2022/10/hackers-using-vishing-tactics-to-trick.html 5、微软更新策略阻止对本地管理账户的暴力攻击 https://www.bleepingcomputer.com/news/microsoft/all-windows-versions-can-now-block-admin-brute-force-attacks/ 6、诈骗者伪装成加密货币发起新一轮PayPal诈骗攻击 https://www.infosecurity-magazine.com/news/paypal-invoice-scams-using-crypto/ 7、五角大楼将360、大疆、知道创宇和中科曙光等 13 家中国公司列入黑名单 https://www.solidot.org/story?sid=73010 8、英国将耗资5000万英镑建立新的“国防网络学院” https://www.secrss.com/articles/47745 9、键盘余热可能泄露密码,20秒内拍下键盘热像图,密码泄露86% https://www.freebuf.com/articles/database/346627.html 10、Deepfake成网络犯罪经济的新高峰 https://securityaffairs.co/wordpress/136927/cyber-crime/deepfakes-services-cybercrime.html
网络安全日报 2022年10月12日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现一种名为 Caffeine 的新型网络钓鱼即服务 (PhaaS) https://securityaffairs.co/wordpress/136953/cyber-crime/caffeine-phishing-platform.html 2、Emotet在近期攻击中使用新的传播和规避技术 https://thehackernews.com/2022/10/new-report-uncovers-emotets-delivery.html 3、诈骗者利用Zoom进行网络钓鱼窃取Exchange凭据 https://www.hackread.com/zoom-phishing-scam-ms-exchange-credentials/ 4、新加坡电信面临多起数据泄露事件 https://www.govinfosecurity.com/singtel-confronts-multiple-data-leaks-a-20243 5、国家标准《信息安全技术 智能手机预装应用程序基本安全要求》公开征求意见 https://www.secrss.com/articles/47735 6、伊朗抗议者劫持国有电视台直播 https://www.solidot.org/story?sid=72997 7、Fortinet警告防火墙和代理产品的0day漏洞正在被广泛利用 https://www.securityweek.com/fortinet-confirms-zero-day-vulnerability-exploited-one-attack 8、西门子称不排除黑客未来利用全局私钥进行 PLC攻击的可能性 https://www.securityweek.com/siemens-not-ruling-out-future-attacks-exploiting-global-private-keys-plc-hacking 9、微软周二补丁日修复了90多个安全漏洞 https://www.securityweek.com/microsoft-warns-new-zero-day-no-fix-yet-exploited-exchange-server-flaws 10、印尼大规模数据泄露事件频发 https://www.cnbeta.com/articles/tech/1325467.htm