΢ÈíÐû²¼Õë¶ÔPetitPotam NTLMÖм̹¥»÷µÄ»º½â´ëÊ©£»ºÚ¿ÍÔÚ°µÍøÉϳöÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë

Ðû²¼Ê±¼ä 2021-07-26
1.΢ÈíÐû²¼Õë¶ÔPetitPotam NTLMÖм̹¥»÷µÄ»º½â´ëÊ©


1.jpg


΢ÈíÐû²¼Õë¶ÔеÄPetitPotam NTLMÖм̹¥»÷µÄ»º½â´ëÊ©¡£PetitPotamÊÇÓÉ·¨¹úÑо¿ÈËÔ±Gilles Lionel·¢ÏÖµÄÐÂNTLMÖм̹¥»÷ £¬Ê¹ÓÃÁËMicrosoft¼ÓÃÜÎļþϵͳԶ³ÌЭÒé( EFSRPC)À´Ç¿ÖÆÉ豸ÏòÓɺڿͿØÖƵÄÔ¶³ÌNTLMÖмÌÉí·ÝÑéÖ¤ £¬¸Ã¹¥»÷¿ÉÓÃÀ´½Ó¹ÜÓò¿ØÖÆÆ÷»òÆäËûWindows·þÎñÆ÷¡£Î¢Èí½¨ÒéÔÚ²»ÐèÒªµÄµØ·½½ûÓÃNTLM £¬»òÕ߯ôÓÃÉí·ÝÑéÖ¤»úÖÆµÄÀ©Õ¹±£»¤£»²¢½¨ÒéÔÚÆôÓÃÁËNTLMµÄÍøÂçÉÏ £¬ÔÊÐíNTLMÉí·ÝÑé֤ʹÓÃÇ©Ãû¹¦Ð§µÄ·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcompter.com/news/security/microsoft-shares-mitigations-for-new-petitpotam-ntlm-relay-attack/


2.΢Èí³ÆÆä7Ô·ÝÄþ¾²¸üпÉÄÜÓ°Ï첿ÃÅϵͳµÄ´òÓ¡¹¦Ð§


2.jpg


΢ÈíÌåÏÖ £¬ÔÚÓò¿ØÖÆÆ÷(DC)Éϰ²×°2021Äê7ÔÂWindows 10Äþ¾²¸üкó £¬Ê¹ÓÃÖÇÄÜ¿¨(PIV)Éí·ÝÑéÖ¤µÄÉ豸µÄ´òÓ¡ºÍɨÃ蹦Ч¿ÉÄ᷺ܻÆðÎÊÌâ¡£¸ÃÎÊÌâÊÇÓÉÓÚÕë¶ÔÄþ¾²Â©¶´CVE-2021-33764µÄ¼Ó¹ÌËùµ¼ÖµÄ £¬Ó°ÏìÁËÔÚKerberosASÇëÇóÆÚ¼ä²»Ö§³ÖDH»òÖ§³Ödes-ede3-cbc£¨ÈýÖØDES£©µÄÖÇÄÜ¿¨ÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶ๦ЧÉ豸¡£Î¢Èí½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÁªÏµÉ豸µÄÖÆÔìÉ̲¢ÒªÇó½øÐÐÉèÖøü¸Ä»ò¸üР£¬ÒÔÇкÏCVE-2021-33764µÄÄþ¾²¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-july-security-updates-break-printing-on-some-systems/


3.Ñо¿ÍŶÓÅû¶ÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ


3.jpg


Äþ¾²¹«Ë¾MBSDÅû¶ÁËÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÊÇÔÚÉÏÖÜÎå¾ÙÐеÄ2021Äê¶«¾©°ÂÔ˻ῪĻʽǰÁ½Ìì·¢ÏÖµÄ £¬Ëü²»½öÄÜɾ³ýµçÄÔÉϵÄËùÓÐÊý¾Ý £¬»¹ÄÜËÑË÷λÓÚC:/Users/<username>/µÄÓû§¸öÈËÎļþ¼ÐÖеÄÌØ¶¨ÎļþÀàÐÍ¡£ÆäÖÐ £¬Microsoft OfficeÎļþÊÇÒª¸Ã¶ñÒâÈí¼þɾ³ýµÄÖ÷ҪĿ±ê £¬´ËÍ⻹ÓÐTXT¡¢LOGºÍCSVÎļþ £¬ÒòΪÕâЩÎļþÓÐʱ»á´æ´¢ÈÕÖ¾¡¢Êý¾Ý¿â»òÃÜÂëÐÅÏ¢µÈ¡£´ËÍâ £¬¸Ãwiper»¹Õë¶ÔʹÓÃÁËIchitaroÈÕÓïÎÄ×Ö´¦ÖÃÆ÷´´½¨µÄÎļþ £¬ÕâÖ¤Ã÷Ëü¿ÉÄÜרÃÅÕë¶ÔÈÕ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/wiper-malware-targeting-japanese-pcs-discovered-ahead-of-tokyo-olympics-opening/


4.AvananÅû¶ÀûÓÃЭ×÷Ó¦ÓÃMilanoteÈÆ¹ýSEGµÄµöÓã»î¶¯


4.jpg


AvananÑо¿ÈËÔ±Åû¶ÁËÀûÓÃЭ×÷Ó¦ÓÃMilanoteÈÆ¹ýSEGµÄµöÓã»î¶¯¡£Avanan³Æ £¬½üÆÚ´ËÀàÍøÂçµöÓã¹¥»÷µÄÊýÁ¿¼±¾çÔö¼Ó £¬ËûÃÇÔÚͨÐÅÍøÂçÖзÖÎöÁË1430·â°üÂÞMilanoteÁ´½ÓµÄÓʼþ £¬ÆäÖÐ1367·âÊÇÍøÂçµöÓã»î¶¯µÄÒ»²¿ÃÅ£¨¸ß´ï95.5%£©¡£´Ë´Î»î¶¯Ê¹ÓÃÁËÒÔÏîÄ¿Ìá°¸·¢Æ±ÎªÖ÷ÌâµÄµöÓãÓʼþ £¬ÓÕʹĿ±ê´ò¿ªÁ¬½ÓÖеÄÎĵµ²¢±»Öض¨Ïòµ½MilanoteÖеÄÒ³Ãæ¡£¹¥»÷Õßͨ¹ýÕâÖÖ·½Ê½½«payloadǶÌ×ÔںϷ¨·þÎñÖÐÀ´ÈƹýÕâЩ¼ì²â»úÖÆ £¬°üÂÞ¾²Ì¬É¨ÃèÆ÷¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/07/hacker-employ-milanote-app-for.html


5.ºÚ¿ÍÔÚ°µÍøÉϳöÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë


5.jpg


ºÚ¿ÍÔÚ°µÍøÉϳöÊÛÁËClubhouse°üÂÞ38ÒÚ¸öµç»°ºÅÂëµÄÊý¾Ý¿â¡£Âô¼ÒÉù³Æ¸ÃÊý¾Ý¿â°üÂÞ38ÒÚ¸öµç»°ºÅÂë £¬°üÂÞÊÖ»ú¡¢Àι̵绰¡¢Ë½È˵绰ºÍרҵµç»° £¬¶øÇÒÿ¸öºÅÂë¶¼°´Ìض¨µÄ·ÖÊý£¨Ôڵ绰²¾ÖÐÓµÓд˵绰ºÅÂëµÄ»áËùÓû§ÊýÁ¿£©½øÐÐÁËÅÅÃû¡£ºÚ¿Í»¹Ðû²¼Á˸ÃÊý¾Ý¿âµÄÑù±¾µÄ £¬°üÂÞÁè¼Ý8350Íò¸öÈÕ±¾Óû§µÄµç»°ºÅÂë¡£ÔçÔÚ2021Äê4Ô £¬Cyber NewsµÄÑо¿ÈËÔ±Ôø·¢ÏÖÁË130Íò¸öClubhouseÓû§µÄ¸öÈËÐÅϢй¶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120553/hacking/threat-actor-offers-clubhouse-secret-database-containing-3-8b-phone-numbers.html


6.KasperskyÐû²¼2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)³ÂËß


6.jpg


KasperskyÐû²¼ÁË2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬ÔÚ2020ÄêµÚËļ¾¶È £¬´Óһ̨Ö÷»úÊÕ¼¯µÄԭʼʼþµÄƽ¾ùÊýÁ¿Ô¼Îª15000¡£Æ¾¾ÝMDRʼþÑÏÖØÐÔ·ÖÀà £¬¸ßÑÏÖØÐÔʼþÓë¾ßÓиßÓ°ÏìµÄÈËΪ¹¥»÷»ò¶ñÒâÈí¼þÓйØ £¬ÆäÖдËÀàʼþµÄÓÕÒò¿ÉÄÜΪ£ºAPT--Õë¶ÔÐÔ¹¥»÷¡¢½ø¹¥ÐԻ¡¢Ó°ÏìÑÏÖØµÄ¶ñÒâÈí¼þ¡¢¿É±»ÀûÓõÄ©¶´¡¢DDOS/DOS¡¢ÄÚ²¿Íþв£¨ÆÛÕ©µÈ£©ÒÔ¼°Éç»á¹¤³Ì¹¥»÷µÈ¡£´ËÍâ £¬¼¸ºõËùÓд¹Ö±ÐÐÒµ¶¼ÓÐÊܺ¦Õß £¬¶øÇ°3ÃûΪITÐÐÒµ¡¢Õþ¸®×éÖ¯ºÍ¹¤Òµ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/managed-detection-and-response-in-q4-2020/103387/