安全研究 Safety research
Void Manticore组织瞄准以色列实施破坏性攻击活动 https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/ 俄语攻击者利用GitHub存储库传播恶意软件 https://go.recordedfuture.com/hubfs/reports/cta-2024-0514.pdf LATRODECTUS恶意软件加载程序揭秘 https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus  SamsStealer:针对Windows系统的新信息窃取程序 https://www.cyfirma.com/research/samsstealer-unveiling-the-information-stealer-targeting-windows-systems/ UTG-Q-010:瞄准国内AI和游戏行业 https://mp.weixin.qq.com/s/IrSWY5XQ24APFZ4J0E4QYw
发布时间: 2024 - 05 - 22
Google多款产品存在认证机制不恰当漏洞 https://www.cve.org/CVERecord?id=CVE-2023-2626 Linux Linux_kernel存在数值计算不正确漏洞 https://www.cve.org/CVERecord?id=CVE-2023-2163 Redhat多款产品存在开放式重定向漏洞 https://www.auscert.org.au/bulletins/ESB-2023.7509 Dompdf Php-svg-lib存在可信数据的反序列化漏洞 https://cxsecurity.com/cveshow/CVE-2023-50252/ Eprosima等厂商的多款产品存在可达断言漏洞 https://packetstormsecurity.com/files/174247/Debian-Security-Advisory-5481-1.html
发布时间: 2024 - 05 - 22
Dlink多款产品存在授权机制不正确漏洞 https://www.cnvd.org.cn/flaw/show/CNVD-2021-94835 Codeigniter存在SQL注入漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202210-266 Linux等厂商的多款产品存在竞争条件漏洞 https://access.redhat.com/security/cve/CVE-2023-6531 Furukawa多款产品存在漏洞 https://nvd.nist.gov/vuln/detail/CVE-2021-37384 Intel等厂商的多款产品存在缺省权限不正确漏洞 https://www.cve.org/CVERecord?id=CVE-2023-27305
发布时间: 2024 - 05 - 20
PhantomCore组织向俄罗斯多个行业发起钓鱼攻击 https://www.facct.ru/blog/phantomdl-loader/ Phorpiex僵尸网络正在大规模分发Lockbit Black勒索软件 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware Timitator组织针对国内用户分发Rust特马 https://mp.weixin.qq.com/s/j6aR2AyTdtDB8B-wCVAwjQ 微软补丁日通告:2024年5月版 https://msrc.microsoft.com/update-guide/releaseNote/2024-May 福昕PDF程序存在漏洞遭大量黑客利用 https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
发布时间: 2024 - 05 - 20
Google Fuchsia存在关键资源的权限授予不正确漏洞 https://www.cve.org/CVERecord?id=CVE-2021-22566 Netapp等厂商的多款产品存在内存缓冲区边界内操作的限制不恰当漏洞 https://www.auscert.org.au/bulletins/ESB-2021.2691 Prefect存在跨站请求伪造漏洞 https://www.cve.org/CVERecord?id=CVE-2023-6022 用友网络科技股份有限公司U8 Cloud存在SQL注入漏洞 https://security.yonyou.com/#/noticeInfo?id=520 Webkitgtk等厂商的多款产品存在漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202101-2438
发布时间: 2024 - 05 - 17
PhantomCore组织向俄罗斯多个行业发起钓鱼攻击 https://www.facct.ru/blog/phantomdl-loader/ Phorpiex僵尸网络正在大规模分发Lockbit Black勒索软件 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware 微软补丁日通告:2024年5月版 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware Antidot银行木马以Google Play更新程序为诱饵感染移动设备 https://cyble.com/blog/new-antidot-android-banking-trojan-masquerading-as-google-play-updates/ SideCopy组织近期瞄准印度大学生 https://cyble.com/blog/the-overlapping-cyber-strategies-of-transparent-tribe-and-sidecopy-against-india/
发布时间: 2024 - 05 - 17
SUBNET Substation Server漏洞预警https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-02 PTC Codebeamer漏洞预警https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-017-zip存在特权管理不恰当漏洞https://www.cnvd.org.cn/flaw/show/CNVD-2018-09648Totolink多款产品存在漏洞https://cxsecurity.com/cveshow/CVE-2023-51026/Nvidia多款产品存在关键资源的权限授予不正确漏洞https://nvd.nist.gov/vuln/detail/CVE-2022-21819
发布时间: 2024 - 05 - 13
Core Werewolf组织试图攻击俄罗斯在亚美尼亚的军事基地https://www.facct.ru/blog/core-werewolf/巴基斯坦组织利用Android恶意软件对印度国防军开展间谍活动https://www.cyfirma.com/research/new-pakistan-based-cyber-espionage-groups-year-long-campaign-targeting-indian-defense-forces-with-android-malware/恶意程序仿冒Chrome浏览器针对国内用户https://mp.weixin.qq.com/s/h0Va4Rzq7EMhwif0kgsdxQ多种恶意程序伪装成MS Office破解版进行分发https://asec.ahnlab.com/ko/65307/礼品卡欺诈团伙Storm-0539针对零售公司https://www.bleepingcomputer.com/news/security/fbi-warns-of-gift-card-fraud-ring-targeting-retail-companies/
发布时间: 2024 - 05 - 13
PTC Codebeamer漏洞预警 https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-01 SUBNET Substation Server漏洞预警 https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-02 Pytest Py存在低效的正则表达式复杂性漏洞 https://cxsecurity.com/cveshow/CVE-2022-42969/ Tp-link多款产品存在漏洞 https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/ Apple多款产品存在漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202403-3045
发布时间: 2024 - 05 - 08
Microsoft Graph API遭攻击者利用的频率正在增加 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats 巴基斯坦组织利用Android恶意软件对印度国防军开展间谍活动 https://www.cyfirma.com/research/new-pakistan-based-cyber-espionage-groups-year-long-campaign-targeting-indian-defense-forces-with-android-malware/ zEus Stealer通过Crafted Minecraft游戏源包分发 https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack HijackLoader恶意软件更新规避技术 https://www.zscaler.com/blogs/security-research/hijackloader-updates?&web_view=true 恶意程序仿冒Chrome浏览器针对国内用户 https://mp.weixin.qq.com/s/h0Va4Rzq7EMhwif0kgsdxQ
发布时间: 2024 - 05 - 08
Perl等厂商的多款产品存在跨界内存写漏洞https://access.redhat.com/security/cve/cve-2023-47038Quarkus等厂商的多款产品存在授权机制不正确漏洞https://cxsecurity.com/cveshow/CVE-2023-4853/Qemu等厂商的多款产品存在不恰当的同步机制漏洞https://lists.gnu.org/archive/html/qemu-devel/2023-08/msg03883.htmlX.org等厂商的多款产品存在跨界内存写漏洞https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202310-2162Redhat多款产品存在资源分配缺少限制或调节漏洞https://bugzilla.redhat.com/show_bug.cgi?id=2242099
发布时间: 2024 - 05 - 06
超9万个IP地址仍遭PlugX蠕虫控制https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/银狐黑产团伙大规模针对财税人员https://mp.weixin.qq.com/s/XK_UE0uLS26SB_clMqFO4w攻击活动利用IcedID传播Dagon Locker勒索软件https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/数以百万计的Docker Hub存储库被发现推送恶意软件https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/Fletchen Stealer:一个采用复杂反分析技术的信息窃取程序https://www.cyfirma.com/research/fletchen-stealer-an-information-stealer-with-sophisticated-anti-analysis-measures/
发布时间: 2024 - 05 - 06
Google Chrome存在内存缓冲区边界内操作的限制不恰当漏洞 https://issues.chromium.org/issues/330760873 Redaxo存在代码注入漏洞 https://github.com/evildrummer/MyOwnCVEs/tree/main/CVE-2021-39459 Oracle等厂商的多款产品存在漏洞 http://www.youtube.com/watch?v=1U0Saabf3nA Apache Derby存在注入漏洞 https://lists.apache.org/thread/q23kvvtoohgzwybxpwozmvvk17rp0td3 Frrouting存在安全漏洞 https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf
发布时间: 2024 - 04 - 29
Kimsuky劫持eScan防病毒更新以部署GuptiMiner恶意软件 https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/?utm_source=rss&utm_medium=rss&utm_campaign=guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining  新银行恶意软件Brokewell揭秘 https://www.threatfabric.com/blogs/brokewell-do-not-go-broke-by-new-banking-malware#conclusion LightSpy恶意软件变种瞄准macOS https://www.huntress.com/blog/lightspy-malware-variant-targeting-macos  SideCopy组织利用钓鱼攻击针对印度政府投递远控木马 https://www.seqrite.com/blog/pakistani-apts-escalate-attacks-on-indian-gov-seqrite-labs-unveils-threats-and-connections/ 新Stealer系列Sharp瞄准游戏玩家 https://www.gdatasoftware.com/blog/2024/04/37894-sharp-info-stealer
发布时间: 2024 - 04 - 29
Livesite存在安全漏洞 https://nvd.nist.gov/vuln/detail/CVE-2024-22638 Gxcms_project Gxcms存在危险类型文件的不加限制上传漏洞 https://nvd.nist.gov/vuln/detail/CVE-2022-30007 Google Chrome存在释放后使用漏洞 https://issues.chromium.org/issues/41491379 Netapp等厂商的多款产品存在内存缓冲区边界内操作的限制不恰当漏洞 https://packetstormsecurity.com/files/164075/Red-Hat-Security-Advisory-2021-3447-01.html
发布时间: 2024 - 04 - 24
Makop勒索软件采用loldrivers技术关闭安全软件 https://mp.weixin.qq.com/s/ewo2Lp5arhun3dM94Pcsrw QuasarRAT开源远控工具详情披露 https://mp.weixin.qq.com/s/bAZ8sULaO67Mx2pBRkHQlw APT43组织近期针对韩国的TutorialRAT恶意软件活动分析 https://www.genians.co.kr/blog/threat_intelligence/dropbox 乌克兰20个重要机构遭俄罗斯APT44组织破坏 https://cert.gov.ua/article/6278706 LabHost网络钓鱼即服务平台运营模式披露 https://www.group-ib.com/blog/labhost-operation/
发布时间: 2024 - 04 - 24
Debian等厂商的多款产品存在释放后使用漏洞https://github.com/torvalds/linux/commit/24e90b9e34f9e039f56b5f25f6e6eb92cdd8f4b3Postgresql等厂商的多款产品存在SQL注入漏洞https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56Fedoraproject等厂商的多款产品存在代码注入漏洞http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79409Oracle多款产品存在漏洞https://www.cve.org/CVERecord?id=CVE-2021-2103Djangoproject Django存在安全漏洞https://nvd.nist.gov/vuln/detail/CVE-2024-24680
发布时间: 2024 - 04 - 22
未知攻击者以税务主题为诱饵下发XWorm远控木马https://www.esentire.com/blog/dont-take-the-bait-the-xworm-tax-scamLightSpy间谍软件新一轮活动瞄准南亚地区https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india新Android银行恶意软件SoumniBot混淆技术披露https://securelist.com/soumnibot-android-banker-obfuscates-app-manifest/112334/Lazarus组织利用CVE-2024-21338漏洞攻击亚洲技术人员https://decoded.avast.io/luiginocamastra/from-byovd-to-a-0-day-unveiling-advanced-exploits-in-cyber-recruiting-scams/Sandworm组织在攻击东欧的活动中部署新的Kapeka后门https://thehackernews.com/2024/04/russian-apt-deploys-new-kapeka-backdoor.html
发布时间: 2024 - 04 - 22
Jenkins存在源验证错误漏洞https://cxsecurity.com/cveshow/CVE-2024-23898/ Redhat等厂商的多款产品存在空指针解引用漏洞https://bugzilla.redhat.com/show_bug.cgi?id=2254052 Linux kernel n_gsm模块存在多个本地提权漏洞https://github.com/YuriiCrimson/ExploitGSM Jenkins存在安全漏洞https://www.cve.org/CVERecord?id=CVE-2024-23897 Djangoproject Django存在安全漏洞https://nvd.nist.gov/vuln/detail/CVE-2024-24680
发布时间: 2024 - 04 - 19
LightSpy间谍软件新一轮活动瞄准南亚地区 https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india 未知攻击者以税务主题为诱饵下发XWorm远控木马 https://www.esentire.com/blog/dont-take-the-bait-the-xworm-tax-scam Global Protect防火墙零日漏洞遭UTA0218组织利用 https://unit42.paloaltonetworks.com/cve-2024-3400/ 大量攻击者试图利用D-Link NAS漏洞 https://cyble.com/blog/critical-d-link-nas-vulnerability-under-active-exploitation/ Raspberry Robin蠕虫通过Windows脚本文件得到传播 https://threatresearch.ext.hp.com/raspberry-robin-now-spreading-through-windows-script-files/
发布时间: 2024 - 04 - 19
友情连接:
免费服务热线 ree service hotline 400-613-1868 手机端
法律声明 Copyright  西安交大捷普网络科技有限公司  陕ICP备18022218号-1

陕公网安备 61019002000857号

犀牛云提供云计算服务