安全研究 Safety research
Moonstone Sleet组织瞄准区块链、AI等多个行业https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/Hellhounds组织持续攻击俄罗斯https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/hellhounds-operation-lahat-part-2/Sapphire Werewolf组织瞄准俄罗斯关键行业下发窃密程序https://bi.zone/expertise/blog/sapphire-werewolf-ottachivaet-izvestnyy-stiler-dlya-novykh-atak/Anatsa:Google商店中活跃的Android银行恶意软件https://www.zscaler.com/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-googleAllaSenha:一个针对拉丁美洲地区的ALLAKORE银行木马变体https://harfanglab.io/en/insidethelab/allasenha-allakore-variant-azure-c2-steal-banking-latin-america/
发布时间: 2024 - 06 - 03
Sharp Dragon组织进军非洲和加勒比海地区 https://research.checkpoint.com/2024/sharp-dragon-expands-towards-africa-and-the-caribbean/ 攻击活动通过UUE文件分发Remocs RAT https://asec.ahnlab.com/ko/65790/ Kiteshield Packer被多个黑客组织用于绕过杀软检测 https://blog.xlab.qianxin.com/kiteshield_is_being_abused_by_cybercriminals_cn/ Bondnet攻击者将挖矿机器人用作C2服务器 https://asec.ahnlab.com/ko/65885/ Moonstone Sleet组织瞄准区块链、AI等多个行业 https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/
发布时间: 2024 - 05 - 29
Void Manticore组织瞄准以色列实施破坏性攻击活动https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/俄语攻击者利用GitHub存储库传播恶意软件https://go.recordedfuture.com/hubfs/reports/cta-2024-0514.pdfUTG-Q-010:瞄准国内AI和游戏行业https://mp.weixin.qq.com/s/IrSWY5XQ24APFZ4J0E4QYw勒索组织Ransomhub瞄准西班牙生物能源工厂的SCADA系统https://cyble.com/blog/ransomware-menace-amplifies-for-vulnerable-industrial-control-systems-heightened-threats-to-critical-infrastructure/ 云存储服务被应用于传播恶意文件https://asec.ahnlab.com/ko/65684/
发布时间: 2024 - 05 - 27
Void Manticore组织瞄准以色列实施破坏性攻击活动 https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/ 俄语攻击者利用GitHub存储库传播恶意软件 https://go.recordedfuture.com/hubfs/reports/cta-2024-0514.pdf LATRODECTUS恶意软件加载程序揭秘 https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus  SamsStealer:针对Windows系统的新信息窃取程序 https://www.cyfirma.com/research/samsstealer-unveiling-the-information-stealer-targeting-windows-systems/ UTG-Q-010:瞄准国内AI和游戏行业 https://mp.weixin.qq.com/s/IrSWY5XQ24APFZ4J0E4QYw
发布时间: 2024 - 05 - 22
PhantomCore组织向俄罗斯多个行业发起钓鱼攻击 https://www.facct.ru/blog/phantomdl-loader/ Phorpiex僵尸网络正在大规模分发Lockbit Black勒索软件 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware Timitator组织针对国内用户分发Rust特马 https://mp.weixin.qq.com/s/j6aR2AyTdtDB8B-wCVAwjQ 微软补丁日通告:2024年5月版 https://msrc.microsoft.com/update-guide/releaseNote/2024-May 福昕PDF程序存在漏洞遭大量黑客利用 https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
发布时间: 2024 - 05 - 20
PhantomCore组织向俄罗斯多个行业发起钓鱼攻击 https://www.facct.ru/blog/phantomdl-loader/ Phorpiex僵尸网络正在大规模分发Lockbit Black勒索软件 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware 微软补丁日通告:2024年5月版 https://www.proofpoint.com/us/blog/threat-insight/security-brief-millions-messages-distribute-lockbit-black-ransomware Antidot银行木马以Google Play更新程序为诱饵感染移动设备 https://cyble.com/blog/new-antidot-android-banking-trojan-masquerading-as-google-play-updates/ SideCopy组织近期瞄准印度大学生 https://cyble.com/blog/the-overlapping-cyber-strategies-of-transparent-tribe-and-sidecopy-against-india/
发布时间: 2024 - 05 - 17
Core Werewolf组织试图攻击俄罗斯在亚美尼亚的军事基地https://www.facct.ru/blog/core-werewolf/巴基斯坦组织利用Android恶意软件对印度国防军开展间谍活动https://www.cyfirma.com/research/new-pakistan-based-cyber-espionage-groups-year-long-campaign-targeting-indian-defense-forces-with-android-malware/恶意程序仿冒Chrome浏览器针对国内用户https://mp.weixin.qq.com/s/h0Va4Rzq7EMhwif0kgsdxQ多种恶意程序伪装成MS Office破解版进行分发https://asec.ahnlab.com/ko/65307/礼品卡欺诈团伙Storm-0539针对零售公司https://www.bleepingcomputer.com/news/security/fbi-warns-of-gift-card-fraud-ring-targeting-retail-companies/
发布时间: 2024 - 05 - 13
Microsoft Graph API遭攻击者利用的频率正在增加 https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats 巴基斯坦组织利用Android恶意软件对印度国防军开展间谍活动 https://www.cyfirma.com/research/new-pakistan-based-cyber-espionage-groups-year-long-campaign-targeting-indian-defense-forces-with-android-malware/ zEus Stealer通过Crafted Minecraft游戏源包分发 https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack HijackLoader恶意软件更新规避技术 https://www.zscaler.com/blogs/security-research/hijackloader-updates?&web_view=true 恶意程序仿冒Chrome浏览器针对国内用户 https://mp.weixin.qq.com/s/h0Va4Rzq7EMhwif0kgsdxQ
发布时间: 2024 - 05 - 08
超9万个IP地址仍遭PlugX蠕虫控制https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/银狐黑产团伙大规模针对财税人员https://mp.weixin.qq.com/s/XK_UE0uLS26SB_clMqFO4w攻击活动利用IcedID传播Dagon Locker勒索软件https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/数以百万计的Docker Hub存储库被发现推送恶意软件https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/Fletchen Stealer:一个采用复杂反分析技术的信息窃取程序https://www.cyfirma.com/research/fletchen-stealer-an-information-stealer-with-sophisticated-anti-analysis-measures/
发布时间: 2024 - 05 - 06
Kimsuky劫持eScan防病毒更新以部署GuptiMiner恶意软件 https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/?utm_source=rss&utm_medium=rss&utm_campaign=guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining  新银行恶意软件Brokewell揭秘 https://www.threatfabric.com/blogs/brokewell-do-not-go-broke-by-new-banking-malware#conclusion LightSpy恶意软件变种瞄准macOS https://www.huntress.com/blog/lightspy-malware-variant-targeting-macos  SideCopy组织利用钓鱼攻击针对印度政府投递远控木马 https://www.seqrite.com/blog/pakistani-apts-escalate-attacks-on-indian-gov-seqrite-labs-unveils-threats-and-connections/ 新Stealer系列Sharp瞄准游戏玩家 https://www.gdatasoftware.com/blog/2024/04/37894-sharp-info-stealer
发布时间: 2024 - 04 - 29
Makop勒索软件采用loldrivers技术关闭安全软件 https://mp.weixin.qq.com/s/ewo2Lp5arhun3dM94Pcsrw QuasarRAT开源远控工具详情披露 https://mp.weixin.qq.com/s/bAZ8sULaO67Mx2pBRkHQlw APT43组织近期针对韩国的TutorialRAT恶意软件活动分析 https://www.genians.co.kr/blog/threat_intelligence/dropbox 乌克兰20个重要机构遭俄罗斯APT44组织破坏 https://cert.gov.ua/article/6278706 LabHost网络钓鱼即服务平台运营模式披露 https://www.group-ib.com/blog/labhost-operation/
发布时间: 2024 - 04 - 24
未知攻击者以税务主题为诱饵下发XWorm远控木马https://www.esentire.com/blog/dont-take-the-bait-the-xworm-tax-scamLightSpy间谍软件新一轮活动瞄准南亚地区https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india新Android银行恶意软件SoumniBot混淆技术披露https://securelist.com/soumnibot-android-banker-obfuscates-app-manifest/112334/Lazarus组织利用CVE-2024-21338漏洞攻击亚洲技术人员https://decoded.avast.io/luiginocamastra/from-byovd-to-a-0-day-unveiling-advanced-exploits-in-cyber-recruiting-scams/Sandworm组织在攻击东欧的活动中部署新的Kapeka后门https://thehackernews.com/2024/04/russian-apt-deploys-new-kapeka-backdoor.html
发布时间: 2024 - 04 - 22
LightSpy间谍软件新一轮活动瞄准南亚地区 https://blogs.blackberry.com/en/2024/04/lightspy-returns-renewed-espionage-campaign-targets-southern-asia-possibly-india 未知攻击者以税务主题为诱饵下发XWorm远控木马 https://www.esentire.com/blog/dont-take-the-bait-the-xworm-tax-scam Global Protect防火墙零日漏洞遭UTA0218组织利用 https://unit42.paloaltonetworks.com/cve-2024-3400/ 大量攻击者试图利用D-Link NAS漏洞 https://cyble.com/blog/critical-d-link-nas-vulnerability-under-active-exploitation/ Raspberry Robin蠕虫通过Windows脚本文件得到传播 https://threatresearch.ext.hp.com/raspberry-robin-now-spreading-through-windows-script-files/
发布时间: 2024 - 04 - 19
Latrodectus遭到黑客组织TA577和TA578组织大量使用https://www.proofpoint.com/us/blog/threat-insight/latrodectus-spider-bytes-ice金融相关人员近期遭游蛇团伙攻击https://mp.weixin.qq.com/s/slKYeKIk5HIbmlUVbtAGtwStarryAddax组织正利用新恶意软件瞄准北非的人权活动人士https://blog.talosintelligence.com/starry-addax/TA547疑似使用大模型工具生成脚本向德国实体分发Rhadamanthys恶意软件https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta547-targets-german-organizations-rhadamanthys-stealer《WallpaperEngine:壁纸引擎》存在恶意壁纸文件https://mp.weixin.qq.com/s/LFrxlo_Ik0FcvNvc3Oavhg
发布时间: 2024 - 04 - 15
针对拉丁美洲的网络钓鱼活动追踪https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/phishing-deception-suspended-domains-reveal-malicious-payload-for-latin-american-region/ 微软补丁日通告:2024年4月版https://www.zerodayinitiative.com/blog/2024/4/9/the-april-2024-security-updates-review Byakugan多功能恶意软件分析https://www.fortinet.com/blog/threat-research/byakugan-malware-behind-a-phishing-attack Starry Addax组织正利用新恶意软件瞄准北非的人权活动人士https://blog.talosintelligence.com/starry-addax/ SUBNET PowerSYSTEM Server and Substation Server漏洞预警https://www.cisa.gov/news-events/ics-advisories/icsa-24-100-01
发布时间: 2024 - 04 - 10
虚拟专用网络安装包“引狼入室”:疑似金眼狗(APT-Q-27)团伙的窃密行动https://www.freebuf.com/articles/paper/396978.html Chrome 将通过设备绑定会话凭证阻止黑客盗用 cookiehttps://www.anquanke.com/post/id/295289 智能冰箱变身加密货币矿工,导致全球厨房崩溃https://www.freebuf.com/news/396741.html 黑客滥用谷歌虚假广告传播恶意软件https://www.freebuf.com/news/396864.html 俄罗斯称利用WinRAR 漏洞的攻击活动与乌克兰有关https://www.freebuf.com/news/396604.html
发布时间: 2024 - 04 - 08
国家网信办公布《促进和规范数据跨境流动规定》https://www.freebuf.com/articles/395806.html GitLab收购初创安全公司Oxeyehttps://www.freebuf.com/news/395784.htm 95%的公司面临API安全问题https://www.freebuf.com/news/395770.html StrelaStealer恶意软件“浮出水面”,数百个美国和欧盟组织遭殃https://www.freebuf.com/news/395752.html 全国网安标委发布GBT 43697-2024《数据安全技术 数据分类分级规则》https://www.freebuf.com/news/395695.html
发布时间: 2024 - 03 - 26
Flipper Zero在加拿大要被禁用了https://www.freebuf.com/news/395475.html 谷歌Firebase泄露1900万明文密码,2.2亿条数据记录https://www.freebuf.com/news/395473.html 从深度伪造到恶意软件:网络安全迎来AI新挑战https://www.freebuf.com/news/395324.html 涉及1亿被盗账户,乌克兰警方逮捕3名黑客https://www.freebuf.com/news/395328.html 无功而返:Lockbit残党对美国制药组织Crinetics的攻击被有效遏制https://www.anquanke.com/post/id/294185
发布时间: 2024 - 03 - 22
突发!纳斯达克交易中断超过两小时https://www.freebuf.com/news/395193.html 微软:87%的英国企业极易受到网络攻击,AI或成破局“解药”https://www.freebuf.com/news/395194.html 日本科技巨头富士通遭遇网络攻击,客户数据被窃https://www.freebuf.com/news/395198.html 麦当劳全球系统宕机,影响数千家门店https://www.freebuf.com/news/395076.html 谷歌升级Safe Browsing,为用户增强实时URL保护https://www.freebuf.com/news/395061.html
发布时间: 2024 - 03 - 19
宏碁又遭网络袭击,菲律宾分公司大量数据被盗https://www.freebuf.com/articles/394654.html 欧盟地区iOS DMA更新后,Brave浏览器安装量激增https://www.freebuf.com/news/394645.html 印度一金融公司泄露用户信息,数据量超过3TBhttps://www.freebuf.com/news/394649.html Airbnb将禁止在房源内安装监控摄像头https://www.freebuf.com/news/394640.html 美洲免税店遭Black Basta勒索软件攻击,1.5TB数据泄露https://www.secrss.com/articles/64406
发布时间: 2024 - 03 - 15
友情连接:
免费服务热线 ree service hotline 400-613-1868 手机端
法律声明 Copyright  西安交大捷普网络科技有限公司  陕ICP备18022218号-1

陕公网安备 61019002000857号

犀牛云提供云计算服务