网络安全日报 2022年10月11日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Android 10月安全更新修补了大约 50 个漏洞 https://www.securityweek.com/android-security-updates-patch-critical-vulnerabilities 2、vm2 沙盒库中发现严重的远程代码执行漏洞 https://www.securityweek.com/critical-remote-code-execution-vulnerability-found-vm2-sandbox-library 3、英特尔确认 Alder Lake CPU相关源代码泄露 https://thehackernews.com/2022/10/intel-confirms-leak-of-alder-lake-bios.html 4、Solana Phantom安全更新NFT推送恶意软件 https://www.bleepingcomputer.com/news/security/solana-phantom-security-update-nfts-push-password-stealing-malware/ 5、宜家智能照明系统缺陷让攻击者将灯泡全开 https://www.darkreading.com/application-security/ikea-smart-light-system-flaw-lets-attackers-turn-bulbs-on-full-blast 6、Telegram创始人称WhatsApp是被植入了后门的“监视工具” https://www.cnbeta.com/articles/tech/1325013.htm 7、巴西利亚银行遭勒索软件攻击被索要50BTC https://cryptopotato.com/brazils-brb-bank-pays-50btc-after-being-targeted-by-a-ransomware-attack/ 8、暗网市场网站BidenCash放出120万张支付卡数据 https://securityaffairs.co/wordpress/136872/cyber-crime/bidencash-carding-site-leak.html 9、最新统计中国台湾2022年网络诈骗陷阱:假网购网站排第一 http://www.chinanews.com.cn/gn/2022/10-08/9868464.shtml 10、黑客组织"KillNet"攻击了美国几个主要机场的网站 https://securityaffairs.co/wordpress/136894/hacktivism/killnet-targets-us-airports.html
网络安全日报 2022年10月10日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Everest 勒索软件入侵了南非国有电力公司 ESKOM https://securityaffairs.co/wordpress/136866/cyber-crime/south-africa-eskom-everest-ransomware.html 2、美国第二大非营利性连锁医院CommonSpirit 遭勒索软件攻击 https://securityaffairs.co/wordpress/136843/cyber-crime/commonspirit-ransomware-attack.html 3、微软针对未修补的 Exchange Server 漏洞发布缓解措施 https://thehackernews.com/2022/10/microsoft-issues-improved-mitigations.html 4、Atlas VPN发布流行浏览器风险研究报告,Chrome漏洞最多 https://www.hackread.com/apple-safari-google-chrome-browser/ 5、丰田称29.6万使用T-Connect服务的客户信息可能已泄露 https://otomotif.antaranews.com/berita/3166145/toyota-sebut-296-ribu-informasi-pelanggan-mungkin-bocor 6、ADATA(威刚)否认遭到RansomHouse组织攻击 https://www.bleepingcomputer.com/news/security/adata-denies-ransomhouse-cyberattack-says-leaked-data-from-2021-breach/ 7、《信息安全技术 软件供应链安全要求》(征求意见稿)发布 https://www.freebuf.com/news/346297.html 8、Maggie恶意软件已感染亚太地区超250台MS SQL服务器 https://www.secrss.com/articles/47657 9、仅售“50元”:英国首相个人手机号遭曝光 https://www.secrss.com/articles/47628 10、香格里拉酒店遭黑客入侵,29 万港人个人信息受影响 https://www.secrss.com/articles/47617
网络安全日报 2022年10月09日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、LofyGang分发了约200个恶意NPM包来窃取信用卡数据 https://thehackernews.com/2022/10/lofygang-distributed-200-malicious-npm.html2、Facebook检测到400多个Android和iOS应用窃取用户登录凭据 https://thehackernews.com/2022/10/facebook-detects-400-android-and-ios.html3、BidenCash商店泄露超过120万张支付卡信息 https://blog.cyble.com/2022/10/07/bidencash-strikes-again-over-1-2-million-compromised-payment-cards-data-leaked/4、2K Games被盗的数据现已在网上出售 https://www.bleepingcomputer.com/news/security/2k-games-warns-users-their-stolen-data-is-now-up-for-sale-online/5、Avast发布适用于Hades勒索软件变种的免费解密器 https://www.bleepingcomputer.com/news/security/avast-releases-free-decryptor-for-hades-ransomware-variants/6、研究人员发现了一起针对埃及金融机构的黑客活动 https://securityaffairs.co/wordpress/136720/hacktivism/egypt-leaks-financial-data.html7、研究人员报告了Packagist PHP存储库中的供应链漏洞 https://thehackernews.com/2022/10/researchers-report-supply-chain.html8、Zimbra 未修补的 RCE 漏洞正在被黑客利用 https://www.bleepingcomputer.com/news/security/hackers-exploiting-unpatched-rce-bug-in-zimbra-collaboration-suite/9、FortiGate 和 FortiProxy 被曝存在新身份验证绕过漏洞 https://thehackernews.com/2022/10/fortinet-warns-of-new-auth-bypass-flaw.html10、VMware 修补了 vCenter Server 中的代码执行漏洞 https://www.securityweek.com/vmware-patches-code-execution-vulnerability-vcenter-server
网络安全日报 2022年10月08日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、微软发现ZINC黑客组织针对多国发起攻击活动 https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/ 2、新的Royal勒索软件勒索金额高达数百万美元 https://www.bleepingcomputer.com/news/security/new-royal-ransomware-emerges-in-multi-million-dollar-attacks/ 3、Drupal更新补丁修复Twig模板引擎中的漏洞 https://www.securityweek.com/drupal-updates-patch-vulnerability-twig-template-engine 4、Swachh City平台遭受黑客攻击泄露1600万条用户记录 https://thehackernews.com/2022/09/swachh-city-platform-suffers-data.html 5、黑客利用Bitbucket Server漏洞进行攻击 https://www.bleepingcomputer.com/news/security/cisa-hackers-exploit-critical-bitbucket-server-flaw-in-attacks/ 6、微软确认新的Exchange零日漏洞被用于攻击 https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-new-exchange-zero-days-are-used-in-attacks/ 7、BlackByte勒索软件通过驱动程序漏洞绕过安全产品 https://news.sophos.com/en-us/2022/10/04/blackbyte-ransomware-returns/ 8、研究人员发现Node.js中的HTTP请求走私漏洞 https://www.helpnetsecurity.com/2022/10/04/http-request-smuggling-vulnerability-cve-2022-35256-video/ 9、RansomEXX勒索软件团伙声称入侵法拉利公司并泄露内部文件 https://securityaffairs.co/wordpress/136571/data-breach/ferrari-alleged-data-breach.html 10、黑客从币安桥窃取了价值5.66亿美元的加密货币 https://www.bleepingcomputer.com/news/security/hacker-steals-566-million-worth-of-crypto-from-binance-bridge/
网络安全日报 2022年09月30日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、基于 Go 的恶意软件Chaos正快速扩张,针对Windows和Linux https://securityaffairs.co/wordpress/136384/malware/chaos-malware-windows-linux.html 2、Drupal 更新补丁修复 Twig 模板引擎中的漏洞 https://www.securityweek.com/drupal-updates-patch-vulnerability-twig-template-engine 3、Prilex 恶意软件从针对 ATM 转为攻击PoS系统 https://securelist.com/prilex-atm-pos-malware-evolution/107551/ 4、研究人员发布Bl00dy勒索软件分析报告 https://blog.cyble.com/2022/09/28/bl00dy-new-ransomware-strain-active-in-the-wild/ 5、研究人员发现针对加密钱包的Doenerium窃密木马 https://blog.cyble.com/2022/09/28/new-information-stealer-targeting-crypto-wallets/ 6、Auth0警告某些源代码存储库可能已被泄露 https://www.bleepingcomputer.com/news/security/auth0-warns-that-some-source-code-repos-may-have-been-stolen/ 7、美国国税局警告美国纳税人遭受的短信网络钓鱼攻击大量增加 https://www.bleepingcomputer.com/news/security/irs-warns-americans-of-massive-rise-in-sms-phishing-attacks/ 8、L2 网络安全控制绕过漏洞影响多个思科产品 https://www.securityweek.com/l2-network-security-control-bypass-flaws-impact-multiple-cisco-products 9、微软将在一年内停用 Exchange Online 客户端访问规则 https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-exchange-online-client-access-rules-in-a-year/ 10、微软在 Windows 11 22H2 中改进了网络钓鱼防护 https://www.theregister.com/2022/09/27/microsoft_phishing_password_protect_windows_11/
网络安全日报 2022年09月29日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、信标委发布《信息安全技术 网络安全众测服务要求》(征求意见稿) https://www.freebuf.com/news/345854.html 2、澳大利亚在发生大规模数据泄露后将全面修订隐私法 https://www.cnbeta.com/articles/tech/1321095.htm 3、欧盟 ENISA 发布网络安全技能框架,以发展网络安全人才 https://www.secrss.com/articles/47399 4、Lazarus APT针对加密货币行业工作者发起网络钓鱼活动 https://thehackernews.com/2022/09/north-koreas-lazarus-hackers-targeting.html 5、谷歌发布Chrome 106 稳定版,修复多个高危严重漏洞 https://www.securityweek.com/chrome-106-patches-high-severity-vulnerabilities 6、Bl00dy 勒索软件团伙开始使用泄露的 LockBit 3.0 构建器进行攻击 https://securityaffairs.co/wordpress/136345/cyber-crime/bl00dy-ransomware-lockbit-3-encryptor.html 7、以太网 VLAN Stacking 漏洞可导致被DoS、MiTM 攻击 https://www.bleepingcomputer.com/news/security/ethernet-vlan-stacking-flaws-let-hackers-launch-dos-mitm-attacks/ 8、Java 模板引擎 Pebble 易受命令注入漏洞影响 https://portswigger.net/daily-swig/java-template-framework-pebble-vulnerable-to-command-injection 9、网络犯罪分子使用 Quantum Builder 来传递 Agent Tesla 恶意软件 https://securityaffairs.co/wordpress/136370/uncategorized/quantum-builder-agent-tesla-rat.html 10、Meta关闭了多个发布虚假信息的社交账户 https://www.bleepingcomputer.com/news/security/meta-dismantles-massive-russian-network-spoofing-western-news-sites/
网络安全日报 2022年09月28日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、美国国防公司 Elbit Systems 披露数据泄露 https://securityaffairs.co/wordpress/136310/cyber-crime/elbit-systems-of-america-data-breach.html 2、WhatsApp 修复了两个严重远程代码执行漏洞 https://securityaffairs.co/wordpress/136300/hacking/whatsapp-critical-vulnerabilities.html 3、Erbium 信息窃取器通过破解软件和游戏外挂进行传播 https://securityaffairs.co/wordpress/136285/malware/erbium-info-stealing-malware.html 4、安全研究人员利用众包模式追踪神秘的 Metador APT https://www.securityweek.com/researchers-crowdsourcing-effort-identify-mysterious-metador-apt 5、黑客利用PowerPoint文件中的鼠标移动触发恶意脚本 https://www.bleepingcomputer.com/news/security/hackers-use-powerpoint-files-for-mouseover-malware-delivery/ 6、Mozilla修复Firefox、Firefox ESR和Thunderbird中的高危漏洞 https://www.malwarebytes.com/blog/news/2022/09/update-firefox-and-thunderbird-now-mozilla-patches-several-high-risk-vulnerabilities 7、因儿童隐私数据保护问题,TikTok面临英国2700万英镑罚款 https://www.cnbeta.com/articles/tech/1320875.htm 8、美国警告借猴痘之名对公共卫生组织发起的网络钓鱼攻击 https://www.inforisktoday.com/hhs-hc3-warns-health-sector-monkeypox-phishing-schemes-a-20140 9、勒索团伙采取新策略,利用Exmatter工具损坏数据 https://securityaffairs.co/wordpress/136226/cyber-crime/exmatter-tool-shift-extortion-tactics.html 10、新的 NullMixer 恶意软件活动窃取用户的支付数据和凭证 https://thehackernews.com/2022/09/new-nullmixer-malware-campaign-stealing.html
网络安全日报 2022年09月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Lazarus组织使用BYOVD技术发起新的攻击活动 https://asec.ahnlab.com/en/38993/ 2、研究人员在谷歌Play商店发现伪装成应用程序的Harley木马 https://www.cysecurity.news/2022/09/harley-trojan-affecting-users-by.html 3、Netlify中的漏洞可能导致XSS、SSRF攻击 https://portswigger.net/daily-swig/netlify-vulnerable-to-xss-ssrf-attacks-via-cache-poisoning 4、加密货币交易所使用的npm包遭到泄露 https://www.bleepingcomputer.com/news/security/npm-packages-used-by-crypto-exchanges-compromised/ 5、Windows 11 Insider默认启用SMB身份验证速率限制器 https://www.bleepingcomputer.com/news/microsoft/windows-11-gets-better-protection-against-smb-brute-force-attacks/ 6、公安部网安局即日起开展“断号”行动,重拳打击整治网络账号黑产 https://www.ithome.com/0/642/722.htm 7、Meta被指控违法秘密跟踪iPhone用户 https://www.theregister.com/2022/09/23/meta_app_tracking/ 8、欧盟启动开放Web搜索项目,希望替代Google https://www.secrss.com/articles/47327 9、研究人员发现新的针对IoT设备的恶意挖矿软件 https://www.cnbeta.com/articles/tech/1320439.htm 10、TargetCompany 勒索软件攻击针对微软 SQL 服务器 https://www.bleepingcomputer.com/news/security/microsoft-sql-servers-hacked-in-targetcompany-ransomware-attacks/
网络安全日报 2022年09月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、攻击者冒充 CircleCI 平台窃取GitHub 帐户 https://securityaffairs.co/wordpress/136211/hacking/phishing-circleci-github-accounts.html2、ISC 修复了 BIND DNS 软件中的六个高危漏洞 https://securityaffairs.co/wordpress/136164/security/bind-dns-software-flaws-2.html3、Sophos 警告防火墙产品中一个新的漏洞被黑客利用 https://securityaffairs.co/wordpress/136135/security/sophos-user-portal-webadmin-bug.html4、伦敦警方逮捕了涉嫌入侵Uber和Rockstar Games 的17岁少年 https://securityaffairs.co/wordpress/136146/cyber-crime/uber-rockstar-games-hacker-arrest.html5、匿名者(anonymous)声称入侵了俄罗斯国防部的网站 https://securityaffairs.co/wordpress/136127/hacktivism/anonymous-russian-ministry-of-defense.html6、InsydeH2O UEFI 固件中的高危漏洞影响数百万设备 https://www.securityweek.com/new-firmware-vulnerabilities-affecting-millions-devices-allow-persistent-access7、BlackCat勒索软件对其使用的数据泄露工具进行了更新 https://www.bleepingcomputer.com/news/security/blackcat-ransomware-s-data-exfiltration-tool-gets-an-upgrade/8、葡萄牙航空公司遭受勒索攻击后拒绝与黑客谈判 https://www.govinfosecurity.com/portuguese-airliner-vows-defiance-against-extortion-hackers-a-201349、Windows 11推出名为增强网络钓鱼防护的新功能 https://www.bleepingcomputer.com/news/microsoft/windows-11-now-warns-when-typing-your-password-in-notepad-websites/10、攻击者利用Magento漏洞发起新一轮攻击 https://www.bleepingcomputer.com/news/security/critical-magento-vulnerability-targeted-in-new-surge-of-attacks/
网络安全日报 2022年09月23日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Oracle 云基础设施漏洞暴露敏感数据 https://www.securityweek.com/oracle-cloud-infrastructure-vulnerability-exposed-sensitive-data 2、存在15年之久的Python "tarfile"模块漏洞影响超35万个项目 https://www.securityweek.com/15-year-old-python-vulnerability-present-350000-projects-resurrected 3、Confluence 漏洞 CVE-2022-26134 被恶意挖矿活动利用 https://securityaffairs.co/wordpress/136071/malware/atlassian-confluence-flaw-cryptomining.html 4、Lockbit 3.0勒索软件最新生成器在线泄漏 https://securityaffairs.co/wordpress/136056/data-breach/lockbit-3-0-builder-leak.html 5、Windows 11 22H2 将内核漏洞利用保护添加到安全基线 https://www.bleepingcomputer.com/news/microsoft/windows-11-22h2-adds-kernel-exploit-protection-to-security-baseline/ 6、Cobalt Strike 发布安全更新修复了XSS漏洞 https://www.techtarget.com/searchsecurity/news/252525204/Cobalt-Strike-gets-emergency-patch 7、澳大利亚电信公司Optus遭大规模网络攻击导致客户个人数据被盗 https://www.securityweek.com/australian-telecoms-firm-optus-discloses-breach-impacting-customer-data 8、过去一年中大约五分之二美国消费者的个人信息被盗、泄露或滥用 https://www.freebuf.com/news/345281.html 9、万代最新回应7月黑客入侵进展,不排除模玩部数据流失可能 https://hot.cnbeta.com/articles/game/1318869.htm 10、一黑客兜售印尼13亿手机卡用户数据,公开嘲讽多名高官 https://www.secrss.com/articles/47128