΢Èí³ÆÉý¼¶µ½Android 12ºó²¿·Ö×°±¸Intune·ºÆðÎÊÌâ

Ðû²¼Ê±¼ä 2022-03-16

΢Èí³ÆÉý¼¶µ½Android 12ºó²¿·Ö×°±¸Intune·ºÆðÎÊÌâ


¾ÝýÌå3ÔÂ10ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬MicrosoftÈ·ÈÏ´ÓAndroid 11Éý¼¶µ½Android 12ºó»áµ¼Ö²¿·Ö×°±¸µÄIntune×¢²á·ºÆðÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£ÊÜ´ËÎÊÌâÓ°ÏìµÄ¿Í»§»¹³ÆÆäÔÚÉý¼¶ºóÎÞ·¨»á¼ûÍйÜÔÚMicrosoft IntuneµÄ×ÊÔ´ ¡£¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬MicrosoftÒÑÈ·¶¨OPPO¡¢OnePlusºÍRealme×°±¸ÊÜ´ËÎÊÌâÓ°Ïì ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚÈýÐÇGalaxy×°±¸Öз¢Ã÷Ò»¸öÀàËÆÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÔÚÉý¼¶µ½Android 12ºó×¢²áIntune£¬£¬£¬£¬£¬£¬£¬»áÒòÖ¤Êéȱʧµ¼Öµç×ÓÓʼþºÍVPNÅþÁ¬·ºÆðÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-intune-enrollment-issue-on-android-devices/


Cisco·¢Ã÷MuddyWaterÕë¶ÔÍÁ¶úÆäµÈ¹úµÄÐÂÒ»ÂÖ¹¥»÷


Cisco TalosÔÚ3ÔÂ10ÈÕÅû¶ÁËÒÁÀÊÍÅ»ïMuddyWaterÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄÏêÇé ¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔÍÁ¶úÆäºÍ°¢À­²®°ëµº£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓô¹ÂÚÓʼþ·Ö·¢´øÓжñÒâÈí¼þµÄÎĵµ£¬£¬£¬£¬£¬£¬£¬²¢×°ÖûùÓÚWindows¾ç±¾Îļþ (WSF) µÄÔ¶³Ì»á¼ûľÂíSloughRAT£¨ÓÖÃûCanopy£© ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÁíÍâ2¸ö»ùÓھ籾µÄÖ²Èë³ÌÐò£¬£¬£¬£¬£¬£¬£¬Ò»¸öÊÇÓÃVisual Basic±àдµÄ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇÓÃJavaScript±àÂëµÄ£¬£¬£¬£¬£¬£¬£¬ËüÃǶ¼ÓÃÓÚÔÚÄ¿µÄÖ÷»úÉÏÏÂÔØºÍÖ´ÐжñÒâÏÂÁî ¡£¡£¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2022/03/iranian-supergroup-muddywater.html


ASEC·¢Ã÷αװ³ÉValorant×÷±×Æ÷·Ö·¢RedLineµÄ»î¶¯


3ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬ASECÆÊÎöÍÅ¶Ó³ÆÆä·¢Ã÷ÁËÒ»¸öͨ¹ýYouTube·Ö·¢ÐÅÏ¢ÇÔÈ¡³ÌÐòRedLineµÄ»î¶¯ ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«¶ñÒâÈí¼þαװ³ÉValorant×÷±×Æ÷£¬£¬£¬£¬£¬£¬£¬²¢ÉÏ´«ÁËÓÎÏ·ÊÓÆµÒÔ¼°¸Ã×÷±×Æ÷µÄÏÂÔØÁ´½Ó ¡£¡£¡£¡£¡£¡£¡£ValorantÊÇÒ»¿îÊÊÓÃÓÚWindowsµÄÃâ·ÑµÚÒ»È˳ÆÉä»÷ÓÎÏ·£¬£¬£¬£¬£¬£¬£¬¸Ã×÷±×Æ÷Éù³ÆÊÇÒ»¸ö×Ô¶¯Ãé×¼¹¤¾ß ¡£¡£¡£¡£¡£¡£¡£Óû§µã»÷ÏÂÔØºó»á±»Öض¨Ïòµ½anonfiles²¢ÏÂÔØÒ»¸öRARÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Cheat installer.exe£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÏÖʵÉÏÊÇRedLineµÄ¸±±¾ ¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/32499/


Ñо¿ÍŶÓÐû²¼ÒøÐÐľÂíLampion¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


ýÌå3ÔÂ13ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬segurancaÑо¿ÍŶӷ¢Ã÷½üÆÚÒøÐÐľÂíLampionµÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£¡£¡£Lampion×Ô2019Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃÆÏÌÑÑÀÕþ¸®²ÆÎñºÍ˰Îñ´¹ÂÚÓʼþÔÚÄ¿µÄϵͳÖÐÏÂÔØ¼ÓÔØ³ÌÐò£¨VBSÎļþ£© ¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯µÄ¶ñÒâÈí¼þTTP¼°Æä¹¦Ð§Óë֮ǰÏàËÆ£¬£¬£¬£¬£¬£¬£¬µ«Ä¾Âí¼ÓÔØ³ÌÐò±£´æÏÔÖø²î±ð ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«À¬»øÎļþµÄ¾ÞϸÀ©´óµ½56MBÓÒ£¬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ý¼ì²â£¨2019Äê½öΪ13.20KB£©£¬£¬£¬£¬£¬£¬£¬»¹É¾³ýÁËVBSÎļþÖÐ31.7MBÎÞÓôúÂë ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬LampionÔÚÁè¼ÝÁ½ÄêµÄʱ¼äÖÐʹÓÃÁËλÓÚ¶íÂÞ˹µÄͳһ¸öC2ЧÀÍÆ÷ ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/128975/malware/hidden-c2-lampion-trojan-release-212.html


AvastÐû²¼¶ñÒâÈí¼þRaccoon StealerµÄÆÊÎö±¨¸æ


3ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬AvastÐû²¼Raccoon StealerµÄÊÖÒÕÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2019Äê4ÔÂÊ״ηºÆð£¬£¬£¬£¬£¬£¬£¬ÓÃÀ´ÇÔÈ¡ÃÜÂëºÍcookieµÈÖÖÖÖÀàÐ͵ÄÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ËüÕýÔÚʹÓÃTelegramÀ´´æ´¢ºÍ¸üÐÂC2µØµã£¬£¬£¬£¬£¬£¬£¬ÇÒÐÂÔöÁ˶à¸ö·Ö·¢ÇþµÀ ¡£¡£¡£¡£¡£¡£¡£³ýÁËʹÓÃ2¸ö¼ÓÔØ³ÌÐòBuer LoaderºÍGCleanerÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹Í¨¹ýÓÎÏ·×÷±×Æ÷¡¢ÆÆ½âÈí¼þ²¹¶¡µÈÈí¼þ¾ÙÐÐÈö²¥ ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃThemidaµÈ´ò°ü³ÌÐòÀ´Èƹý¼ì²â£¬£¬£¬£¬£¬£¬£¬¼ì²âµ½µÄ²¿·ÖÑù±¾±»Í³Ò»¸ö´ò°ü³ÌÐò´ò°üÁËÁè¼Ý5´Î ¡£¡£¡£¡£¡£¡£¡£


https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/


LinuxµÄnetfilter×é¼þÖÐÔ½½çдÈëÎó²îCVE-2022-25636


¾Ý3ÔÂ14ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Capsule8Ñо¿Ö°Ô±·¢Ã÷ÁËLinuxÄÚºËÖÐnetfilter×Ó×é¼þÖеĶÑÔ½½çдÈëÎó²î£¨CVE-2022-25636£© ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚ¶Ô¿ò¼ÜÓ²¼þÐ¶ÔØ¹¦Ð§µÄ´¦Öóͷ£¹ýʧµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬ÍâµØ¹¥»÷Õ߿ɽ«ÆäÎäÆ÷»¯£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂDoS»òÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£Red HatÔÚ2ÔÂ22ÈÕÐû²¼Í¨¸æÌåÏÖ£¬£¬£¬£¬£¬£¬£¬´ËÎó²î¿Éµ¼ÖÂϵͳ±ÀÀ£»£» £»òȨÏÞÌáÉý£¬£¬£¬£¬£¬£¬£¬²¢ÌṩÁË»º½â²½·¥ ¡£¡£¡£¡£¡£¡£¡£Debian¡¢Oracle Linux¡¢SUSEºÍUbuntuÒ²Ðû²¼ÁËÀàËÆµÄͨ¸æ ¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/new-linux-bug-in-netfilter-firewall.html



Çå¾²¹¤¾ß


GoodHound


ʹÓà Sharphound¡¢Bloodhound ºÍ Neo4j ÌìÉú¿É²Ù×÷µÄ¹¥»÷·¾¶ÁбíÒÔ¾ÙÐÐÓÐÕë¶ÔÐԵĵ÷½â ¡£¡£¡£¡£¡£¡£¡£


https://github.com/idnahacks/GoodHound


Dome


×ÓÓòö¾Ù¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔ¾ÙÐÐ×Ô¶¯ºÍ/»ò±»¶¯É¨ÃèÒÔ»ñÈ¡×ÓÓò²¢ËÑË÷¿ª·Å¶Ë¿Ú ¡£¡£¡£¡£¡£¡£¡£


https://github.com/v4d1/Dome


BlueTeam.Lab


¸ÃÏîÄ¿°üÀ¨Ò»×é Terraform ºÍ Ansible ¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½¨ÉèЭµ÷µÄ BlueTeam Lab ¡£¡£¡£¡£¡£¡£¡£


https://github.com/op7ic/BlueTeam.Lab


factual-rules-generator


ÊÇÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÕýÔÚÔËÐеIJÙ×÷ϵͳÌìÉúÓйØÒÑ×°ÖÃÈí¼þµÄYARA ¹æÔò ¡£¡£¡£¡£¡£¡£¡£


https://github.com/CIRCL/factual-rules-generator



Çå¾²ÆÊÎö


²éÕÒä¯ÀÀÆ÷É쵀 WhatsApp Web ´úÂëÊÇ·ñ±»ÈëÇÖ


https://thehackernews.com/2022/03/heres-how-to-find-if-whatsapp-web-code.html


DuckDuckGo ½«Ðû´«¶íÂÞ˹µÄÍøÕ¾½µ¼¶


https://www.bleepingcomputer.com/news/technology/duckduckgo-down-ranks-sites-spreading-russian-propaganda/


¹È¸èÊÔͼڹÊÍ Chrome ÁãÈÕÎó²îʹÓõļ¤Ôö


https://www.securityweek.com/google-attempts-explain-surge-chrome-zero-day-exploitation


VPNÌṩÉÌÔÚ±»Ó°Ï·ÖÆÆ¬³§ÆðËߺóեȡBitTorrent


https://www.bleepingcomputer.com/news/security/vpn-provider-bans-bittorrent-after-getting-sued-by-film-studios/


Link11 µÄРDDoS ±¨¸æ


https://www.darkreading.com/attacks-breaches/the-fight-against-the-hydra-new-ddos-report-from-link11-


HBO ÒòÓë Facebook ¹²ÏíÓû§Êý¾Ý¶ø±»ÆðËß


https://blog.malwarebytes.com/privacy-2/2022/03/hbo-sued-for-sharing-subscriber-data-with-facebook/