΢Èí³ÆÉý¼¶µ½Android 12ºó²¿ÃÅÉ豸Intune·ºÆðÎÊÌâ

Ðû²¼Ê±¼ä 2022-03-16

΢Èí³ÆÉý¼¶µ½Android 12ºó²¿ÃÅÉ豸Intune·ºÆðÎÊÌâ


¾ÝýÌå3ÔÂ10ÈÕ±¨µÀ£¬MicrosoftÈ·ÈÏ´ÓAndroid 11Éý¼¶µ½Android 12ºó»áµ¼Ö²¿ÃÅÉ豸µÄIntune×¢²á·ºÆðÎÊÌâ¡£ÊÜ´ËÎÊÌâÓ°ÏìµÄ¿Í»§»¹³ÆÆäÔÚÉý¼¶ºóÎÞ·¨·ÃÎÊÍйÜÔÚMicrosoft IntuneµÄ×ÊÔ´¡£µ½Ä¿Ç°ÎªÖ¹£¬MicrosoftÒÑÈ·¶¨OPPO¡¢OnePlusºÍRealmeÉ豸ÊÜ´ËÎÊÌâÓ°Ïì¡£´ËÍ⣬Ñо¿ÈËÔ±ÔÚÈýÐÇGalaxyÉ豸Öз¢ÏÖÒ»¸öÀàËÆÎÊÌ⣬ÔÚÉý¼¶µ½Android 12ºó×¢²áIntune£¬»áÒòÖ¤Êéȱʧµ¼Öµç×ÓÓʼþºÍVPNÁ¬½Ó·ºÆðÎÊÌâ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-intune-enrollment-issue-on-android-devices/


Cisco·¢ÏÖMuddyWaterÕë¶ÔÍÁ¶úÆäµÈ¹úµÄÐÂÒ»ÂÖ¹¥»÷


Cisco TalosÔÚ3ÔÂ10ÈÕÅû¶ÁËÒÁÀÊÍÅ»ïMuddyWaterÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄÏêÇé¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔÍÁ¶úÆäºÍ°¢À­²®°ëµº£¬¹¥»÷ÕßʹÓõöÓãÓʼþ·Ö·¢´øÓжñÒâÈí¼þµÄÎĵµ£¬²¢°²×°»ùÓÚWindows½Å±¾Îļþ (WSF) µÄÔ¶³Ì·ÃÎÊľÂíSloughRAT£¨ÓÖÃûCanopy£©¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁËÁíÍâ2¸ö»ùÓڽű¾µÄÖ²È뷨ʽ£¬Ò»¸öÊÇÓÃVisual Basic±àдµÄ£¬ÁíÒ»¸öÊÇÓÃJavaScript±àÂëµÄ£¬ËüÃǶ¼ÓÃÓÚÔÚÄ¿±êÖ÷»úÉÏÏÂÔØºÍÖ´ÐжñÒâÃüÁî¡£


https://blog.talosintelligence.com/2022/03/iranian-supergroup-muddywater.html


ASEC·¢ÏÖαװ³ÉValorant×÷±×Æ÷·Ö·¢RedLineµÄ»î¶¯


3ÔÂ11ÈÕ£¬ASEC·ÖÎöÍÅ¶Ó³ÆÆä·¢ÏÖÁËÒ»¸öͨ¹ýYouTube·Ö·¢ÐÅÏ¢ÇÔÈ¡·¨Ê½RedLineµÄ»î¶¯¡£¹¥»÷Õß½«¶ñÒâÈí¼þαװ³ÉValorant×÷±×Æ÷£¬²¢ÉÏ´«ÁËÓÎÏ·ÊÓÆµÒÔ¼°¸Ã×÷±×Æ÷µÄÏÂÔØÁ´½Ó¡£ValorantÊÇÒ»¿îÊÊÓÃÓÚWindowsµÄÃâ·ÑµÚÒ»È˳ÆÉä»÷ÓÎÏ·£¬¸Ã×÷±×Æ÷Éù³ÆÊÇÒ»¸ö×Ô¶¯Ãé×¼¹¤¾ß¡£Óû§µã»÷ÏÂÔØºó»á±»Öض¨Ïòµ½anonfiles²¢ÏÂÔØÒ»¸öRARÎļþ£¬ÆäÖаüÂÞCheat installer.exe£¬¸ÃÎļþʵ¼ÊÉÏÊÇRedLineµÄ¸±±¾¡£


https://asec.ahnlab.com/en/32499/


Ñо¿ÍŶÓÐû²¼ÒøÐÐľÂíLampion¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


ýÌå3ÔÂ13ÈÕ±¨µÀ£¬segurancaÑо¿ÍŶӷ¢ÏÖ½üÆÚÒøÐÐľÂíLampionµÄ¹¥»÷»î¶¯¡£Lampion×Ô2019Ä꿪ʼ»îÔ¾£¬Ö÷ҪʹÓÃÆÏÌÑÑÀÕþ¸®²ÆÕþºÍ˰ÎñµöÓãÓʼþÔÚÄ¿±êϵͳÖÐÏÂÔØ¼ÓÔØ·¨Ê½£¨VBSÎļþ£©¡£´Ë´Î»î¶¯µÄ¶ñÒâÈí¼þTTP¼°Æä¹¦Ð§Óë֮ǰÏàËÆ£¬µ«Ä¾Âí¼ÓÔØ·¨Ê½´æÔÚÏÔÖø²îÒì¡£¹¥»÷Õß½«À¬»øÎļþµÄ¾ÞϸÀ©´óµ½56MBÓÒ£¬ÒÔÈÆ¹ý¼ì²â£¨2019Äê½öΪ13.20KB£©£¬»¹É¾³ýÁËVBSÎļþÖÐ31.7MBÎÞÓôúÂë¡£´ËÍ⣬LampionÔÚÁè¼ÝÁ½ÄêµÄʱ¼äÖÐʹÓÃÁËλÓÚ¶íÂÞ˹µÄͬһ¸öC2·þÎñÆ÷¡£


https://securityaffairs.co/wordpress/128975/malware/hidden-c2-lampion-trojan-release-212.html


AvastÐû²¼¶ñÒâÈí¼þRaccoon StealerµÄ·ÖÎö³ÂËß


3ÔÂ9ÈÕ£¬AvastÐû²¼Raccoon StealerµÄ¼¼Êõ·ÖÎö³ÂËß¡£¸Ã¶ñÒâÈí¼þÓÚ2019Äê4ÔÂÊ״ηºÆð£¬ÓÃÀ´ÇÔÈ¡ÃÜÂëºÍcookieµÈÖÖÖÖÀàÐ͵ÄÊý¾Ý¡£Ñо¿ÈËÔ±·¢ÏÖ£¬ËüÕýÔÚʹÓÃTelegramÀ´´æ´¢ºÍ¸üÐÂC2µØÖ·£¬ÇÒÐÂÔöÁ˶à¸ö·Ö·¢ÇþµÀ¡£³ýÁËʹÓÃ2¸ö¼ÓÔØ·¨Ê½Buer LoaderºÍGCleanerÖ®Í⣬»¹Í¨¹ýÓÎÏ·×÷±×Æ÷¡¢ÆÆ½âÈí¼þ²¹¶¡µÈÈí¼þ½øÐÐÁ÷´«¡£´ËÍ⣬¹¥»÷Õß»¹ÀûÓÃThemidaµÈ´ò°ü·¨Ê½À´Èƹý¼ì²â£¬¼ì²âµ½µÄ²¿ÃÅÑù±¾±»Í¬Ò»¸ö´ò°ü·¨Ê½´ò°üÁËÁè¼Ý5´Î¡£


https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/


LinuxµÄnetfilter×é¼þÖÐÔ½½çдÈë©¶´CVE-2022-25636


¾Ý3ÔÂ14ÈÕ±¨µÀ£¬Capsule8Ñо¿ÈËÔ±·¢ÏÖÁËLinuxÄÚºËÖÐnetfilter×Ó×é¼þÖеĶÑÔ½½çдÈë©¶´£¨CVE-2022-25636£©¡£¸Ã©¶´ÊÇÓÉÓÚ¶Ô¿ò¼ÜÓ²¼þÐ¶ÔØ¹¦Ð§µÄ´¦ÖôíÎóµ¼ÖµÄ£¬µ±µØ¹¥»÷Õ߿ɽ«ÆäÎäÆ÷»¯£¬µ¼ÖÂDoS»òÖ´ÐÐÈÎÒâ´úÂë¡£Red HatÔÚ2ÔÂ22ÈÕÐû²¼Í¨¸æÌåÏÖ£¬´Ë©¶´¿Éµ¼ÖÂϵͳ±ÀÀ£»òȨÏÞÌáÉý£¬²¢ÌṩÁË»º½â´ëÊ©¡£Debian¡¢Oracle Linux¡¢SUSEºÍUbuntuÒ²Ðû²¼ÁËÀàËÆµÄͨ¸æ¡£


https://thehackernews.com/2022/03/new-linux-bug-in-netfilter-firewall.html



Äþ¾²¹¤¾ß


GoodHound


ʹÓà Sharphound¡¢Bloodhound ºÍ Neo4j Éú³É¿É²Ù×÷µÄ¹¥»÷·¾¶ÁбíÒÔ½øÐÐÓÐÕë¶ÔÐԵĵ÷Í£¡£


https://github.com/idnahacks/GoodHound


Dome


×ÓÓòö¾Ù¹¤¾ß£¬Ëü¿ÉÒÔ½øÐÐÖ÷¶¯ºÍ/»ò±»¶¯É¨ÃèÒÔ»ñÈ¡×ÓÓò²¢ËÑË÷¿ª·Å¶Ë¿Ú¡£


https://github.com/v4d1/Dome


BlueTeam.Lab


¸ÃÏîÄ¿°üÂÞÒ»×é Terraform ºÍ Ansible ½Å±¾£¬ÓÃÓÚ´´½¨Ð­µ÷µÄ BlueTeam Lab¡£


https://github.com/op7ic/BlueTeam.Lab


factual-rules-generator


ÊÇÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ö¼ÔÚ´ÓÕýÔÚÔËÐеIJÙ×÷ϵͳÉú³ÉÓйØÒѰ²×°Èí¼þµÄYARA ¹æÔò¡£


https://github.com/CIRCL/factual-rules-generator



Äþ¾²·ÖÎö


²éÕÒä¯ÀÀÆ÷É쵀 WhatsApp Web ´úÂëÊÇ·ñ±»ÈëÇÖ


https://thehackernews.com/2022/03/heres-how-to-find-if-whatsapp-web-code.html


DuckDuckGo ½«Ðû´«¶íÂÞ˹µÄÍøÕ¾½µ¼¶


https://www.bleepingcomputer.com/news/technology/duckduckgo-down-ranks-sites-spreading-russian-propaganda/


¹È¸èÊÔͼ½âÊÍ Chrome ÁãÈÕ©¶´ÀûÓõļ¤Ôö


https://www.securityweek.com/google-attempts-explain-surge-chrome-zero-day-exploitation


VPNÌṩÉÌÔÚ±»Ó°Ï·ÖÆÆ¬³§ÆðËߺó½ûÖ¹BitTorrent


https://www.bleepingcomputer.com/news/security/vpn-provider-bans-bittorrent-after-getting-sued-by-film-studios/


Link11 µÄРDDoS ³ÂËß


https://www.darkreading.com/attacks-breaches/the-fight-against-the-hydra-new-ddos-report-from-link11-


HBO ÒòÓë Facebook ¹²ÏíÓû§Êý¾Ý¶ø±»ÆðËß


https://blog.malwarebytes.com/privacy-2/2022/03/hbo-sued-for-sharing-subscriber-data-with-facebook/