安全研究 Safety research
Google Android存在跨界内存写漏洞 https://nvd.nist.gov/vuln/detail/CVE-2023-32830 Linuxfoundation等厂商的多款产品存在整数溢出或超界折返漏洞 https://cxsecurity.com/cveshow/CVE-2023-32829/ Mediatek等厂商的多款产品存在整数溢出或超界折返漏洞 https://www.cve.org/CVERecord?id=CVE-2023-32828 Ibm Maximo_application_suite存在使用已被攻破或存在风险的密码学算法漏洞 https://exchange.xforce.ibmcloud.com/vulnerabilities/292799 Siemens多款产品存在敏感数据的明文存储漏洞 https://cert-portal.siemens.com/productcert/html/ssa-857368.html
发布时间: 2024 - 09 - 23
Emmenhtal恶意软件加载器分析 https://blog.sekoia.io/webdav-as-a-service-uncovering-the-infrastructure-behind-emmenhtal-loader-distribution/ Citrine Sleet组织向PyPI库投递PondRAT https://unit42.paloaltonetworks.com/gleaming-pisces-applejeus-poolrat-and-pondrat/ 意大利用户遭到SambaSpy恶意软件攻击 https://securelist.com/sambaspy-rat-targets-italian-users/113851/ WhatsUp Gold遭到远程代码执行攻击 https://www.trendmicro.com/en_us/research/24/i/whatsup-gold-rce.html Hadooken恶意软件瞄准Weblogic服务器 https://www.aquasec.com/blog/hadooken-malware-targets-weblogic-applications/
发布时间: 2024 - 09 - 23
https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202406-2956https://nvd.nist.gov/vuln/detail/CVE-2024-45694https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202407-064https://nvd.nist.gov/vuln/detail/CVE-2024-38521https://www.cve.org/CVERecord?id=CVE-2024-20399
发布时间: 2024 - 09 - 18
https://www.genians.co.kr/blog/threat_intelligence/konni_universehttps://news.drweb.com/show/?i=14900&lng=en&c=9https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python-packageshttps://www.cleafy.com/cleafy-labs/a-new-trickmo-saga-from-banking-trojan-to-victims-data-leakhttps://www.esentire.com/blog/poseidon-stealer-uses-sopha-ai-lure-to-infect-macos
发布时间: 2024 - 09 - 18
Zyxel多款产品存在OS命令注入漏洞 https://cxsecurity.com/cveshow/CVE-2024-7261/ Cisco Smart_license_utility存在使用硬编码的凭证漏洞 https://nvd.nist.gov/vuln/detail/CVE-2024-20439 Tenda I29_firmware存在跨界内存写漏洞 https://www.cve.org/CVERecord?id=CVE-2023-50986 Atlassian多款产品存在输入验证不恰当漏洞 https://cxsecurity.com/cveshow/CVE-2023-22515/ Netapp等厂商的多款产品存在释放后使用漏洞 https://access.redhat.com/errata/RHSA-2023:7549
发布时间: 2024 - 09 - 11
朝鲜黑客组织Konni加大对俄罗斯和韩国的攻击力度 https://www.genians.co.kr/blog/threat_intelligence/konni_universe DragonRank:一家利用恶意软件操纵SEO排名服务的运营商 https://blog.talosintelligence.com/dragon-rank-seo-poisoning/ RansomHub勒索团伙利用TDSSKiller和LaZagne禁用EDR软件 https://www.bleepingcomputer.com/news/security/ransomhub-ransomware-abuses-kaspersky-tdsskiller-to-disable-edr-software/ Quad7僵尸网络团伙新动态披露 https://blog.sekoia.io/a-glimpse-into-the-quad7-operators-next-moves-and-associated-botnets/ 微软补丁日通告:2024年9月版 https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep
发布时间: 2024 - 09 - 11
Linux Linux_kernel存在释放后使用漏洞 https://access.redhat.com/security/cve/cve-2024-44974 Ibm多款产品存在内存缓冲区边界内操作的限制不恰当漏洞(CVE-2022-33162) https://nvd.nist.gov/vuln/detail/CVE-2022-33162 Onesoftnet Sudobot存在授权机制缺失漏洞 https://nvd.nist.gov/vuln/detail/CVE-2024-45307 Roxy-wi存在OS命令注入漏洞 https://cxsecurity.com/cveshow/CVE-2024-43804/ Seacms存在跨站脚本漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202408-2769
发布时间: 2024 - 09 - 09
Head Mare黑客组织揭秘 https://securelist.com/head-mare-hacktivists/113555/ Stone Wolf组织向俄罗斯公司投递Meduza Stealer https://bi-zone.medium.com/stone-wolf-employs-meduza-stealer-to-hack-russian-companies-db3fd0e7af02 Underground勒索软件信息公开 https://www.fortinet.com/blog/threat-research/ransomware-roundup-underground 俄罗斯APT29对蒙古政府网站实施水坑攻击 https://blog.google/threat-analysis-group/state-backed-attackers-and-commercial-surveillance-vendors-repeatedly-use-the-same-exploits/ 马来西亚政府人员遭到Babylon木马攻击 https://cyble.com/blog/the-intricate-babylon-rat-campaign-targets-malaysian-politicians-government/
发布时间: 2024 - 09 - 09
Linux版本的新Cicada勒索软件对VMware ESXi服务器构成威胁 https://www.truesec.com/hub/blog/dissecting-the-cicada 新银行木马Rocinante详情披露 https://www.threatfabric.com/blogs/the-trojan-horse-that-wanted-to-fly-rocinante#rocinante-or-pegasus 攻击者通过黑神话悟空修改器传播恶意木马 https://mp.weixin.qq.com/s/yArqTngBt-lGg4T7HEE0sw Delta Electronics DTN Soft漏洞预警 https://www.cisa.gov/news-events/ics-advisories/icsa-24-242-02 HZ Rat后门macOS版本瞄准中国钉钉和微信用户 https://securelist.com/hz-rat-attacks-wechat-and-dingtalk/113513/
发布时间: 2024 - 09 - 04
Barix Sip_client_firmware存在信息暴露漏洞 https://cxsecurity.com/cveshow/CVE-2024-41700/ Tenda Fh1201_firmware存在跨界内存写漏洞 https://www.tendacn.com/download/detail-3322.html Dreamer_cms_project Dreamer_cms存在跨站请求伪造漏洞 https://nvd.nist.gov/vuln/detail/CVE-2023-48060 Live555存在释放后使用漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202401-1162 Python存在低效的正则表达式复杂性漏洞 https://github.com/python/cpython/pull/123075
发布时间: 2024 - 09 - 04
Siamonhasan Warehouse_inventory_system存在跨站请求伪造漏洞 https://gist.github.com/topsky979/ed59fb8b35a220dfa064a3a3cb1ecb1b Pligg Pligg_cms存在跨站请求伪造漏洞 https://cxsecurity.com/cveshow/CVE-2024-42608/ Tenda Fh1206_firmware存在跨界内存写漏洞 https://www.cve.org/CVERecord?id=CVE-2024-7614 Ltcms存在服务器端请求伪造漏洞 https://github.com/DeepMountains/Mirage/blob/main/CVE14-1.mdApple Macos存在释放后使用漏洞 https://nvd.nist.gov/vuln/detail/CVE-2023-42892
发布时间: 2024 - 08 - 26
UTG-Q-010组织对中国实体发起钓鱼攻击 https://cyble.com/blog/analysing-the-utg-q-010-campaign/ ValleyRAT多阶段恶意软件瞄准中文使用者 https://www.fortinet.com/blog/threat-research/valleyrat-campaign-targeting-chinese-speakers 俄罗斯Tusk组织假冒品牌网站传播DanaBot与StealC恶意软件 https://securelist.com/tusk-infostealers-campaign/113367/ Xeon Sender云攻击工具被用于开展大规模短信钓鱼活动 https://www.sentinelone.com/labs/xeon-sender-sms-spam-shipping-multi-tool-targeting-saas-credentials/ UULoader恶意软件攻击韩语和中文使用者 https://cyberint.com/blog/research/meet-uuloader-an-emerging-and-evasive-malicious-installer/
发布时间: 2024 - 08 - 26
Wurmlab Sequenceserver存在命令注入漏洞https://cxsecurity.com/cveshow/CVE-2024-42360/Zohocorp Manageengine_adaudit_plus存在SQL注入漏洞 https://www.manageengine.com/products/active-directory-audit/cve-2024-5487.html Asus Download_master存在危险类型文件的不加限制上传漏洞 https://cxsecurity.com/cveshow/CVE-2024-31161/ Skyworth多款产品存在敏感数据加密缺失漏洞 https://www.cnvd.org.cn/flaw/show/CNVD-2021-06537 Stitionai Devika存在路径遍历漏洞 https://www.exploit-db.com/exploits/52066
发布时间: 2024 - 08 - 19
Rockwell Automation Micro850/870漏洞预警https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-07摩诃草组织Spyder下载器新变种揭秘https://mp.weixin.qq.com/s/M6xoCfqMCSDsv32S0vrGEw UAC-0198组织向乌克兰政府投递ANONVNC恶意软件https://cert.gov.ua/article/6280345攻击者在新社会工程学活动中更新有效负载https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/Earth Baku组织近期活动详情披露https://www.trendmicro.com/en_us/research/24/h/earth-baku-latest-campaign.html
发布时间: 2024 - 08 - 19
Vmware Vcenter_server存在跨界内存写漏洞 https://www.vmware.com/security/advisories/VMSA-2023-0023.html F5等厂商的多款产品存在资源穷尽漏洞 https://github.com/microsoft/CBL-Mariner/pull/6381 Nextgen Mirth_connect存在OS命令注入漏洞 http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html Ivanti多款产品存在服务器端请求伪造漏洞 https://cxsecurity.com/cveshow/CVE-2024-21893/ Idccms存在跨站请求伪造漏洞 https://cxsecurity.com/cveshow/CVE-2024-36549/
发布时间: 2024 - 08 - 14
微软补丁日通告:2024年8月版 https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug AVEVA SuiteLink Server漏洞预警 https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-01 Rockwell Automation Micro850/870漏洞预警 https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-07 UAC-0198组织向乌克兰政府投递ANONVNC恶意软件 https://cert.gov.ua/article/6280345 伊朗APT42加强对以色列和美国的钓鱼攻击力度 https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/
发布时间: 2024 - 08 - 14
1、Totolink多款产品存在经典缓冲区溢出漏洞 https://www.cve.org/CVERecord?id=CVE-2024-7337  2、Changingtec Tcb_servisign存在输入验证不恰当漏洞 https://www.cnnvd.org.cn/home/globalSearch?keyword=CNNVD-202408-153  3、Angeljudesuarez Placement_management_system存在SQL注入漏洞 https://nvd.nist.gov/vuln/detail/CVE-2024-7452  4、Apple多款产品存在释放后使用漏洞 https://support.apple.com/kb/HT214039  5、Samsung Notes存在跨界内存写漏洞 https://cxsecurity.com/cveshow/CVE-2024-34622/
发布时间: 2024 - 08 - 12
1、StackExchange平台被用于传播恶意Python包https://checkmarx.com/blog/stackexchange-abused-to-spread-malicious-python-package-that-drains-victims-crypto-wallets/ 2、Hunters International组织使用新木马SharpRhino https://www.quorumcyber.com/insights/sharprhino-new-hunters-international-rat-identified-by-quorum-cyber/ 3、攻击者利用TryCloudflare向政府部门分发多种恶意软件 https://www.esentire.com/blog/quartet-of-trouble-xworm-asyncrat-venomrat-and-purelogs-stealer-leverage-trycloudflare 4、BlankBot安卓银行木马瞄准土耳其用户 https://intel471.com/blog/blankbot-a-new-android-banking-trojan-with-screen-recording-keylogging-and-remote-control-capabilities 5、Bloody Wolf利用STRRAT商业恶意软件攻击哈萨克斯坦https://bi.zone/eng/expertise/blog/bloody-wolf-primenyaet-kommercheskoe-vpo-strrat-protiv-organizatsiy-v-kazakhstane/
发布时间: 2024 - 08 - 12
1、Destiny Chat存在跨站请求伪造漏洞https://vuldb.com/?id.2165212、Zenphoto存在危险类型文件的不加限制上传漏洞https://cxsecurity.com/ascii/WLB-20210201693、Batflat存在代码注入漏洞https://nvd.nist.gov/vuln/detail/CVE-2020-357344、Mersive多款产品存在敏感数据加密缺失漏洞https://attack.mitre.org/techniques/T1444/5、Zend Zend_framework存在可信数据的反序列化漏https://cxsecurity.com/cveshow/CVE-2020-29312/
发布时间: 2024 - 08 - 05
1、Rockwell Automation Logix Controllers漏洞预警https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-092、SEXi、Key Group、Mallox勒索软件信息公开https://securelist.com/sexi-key-group-mallox-ransomware/113183/3、Cloudflare被用于传播RAT木马https://www.proofpoint.com/us/blog/threat-insight/threat-actor-abuses-cloudflare-tunnels-deliver-rats4、ModiLoader钓鱼攻击瞄准波兰中小企业https://www.welivesecurity.com/en/eset-research/phishing-targeting-polish-smbs-continues-modiloader/5、XDSpy间谍组织对俄罗斯IT公司发动新网络攻击https://habr.com/ru/companies/f_a_c_c_t/news/831420/
发布时间: 2024 - 08 - 05
友情连接:
免费服务热线 ree service hotline 400-613-1868 手机端
法律声明 Copyright  西安交大捷普网络科技有限公司  陕ICP备18022218号-1

陕公网安备 61019002000857号

犀牛云提供云计算服务