ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷ 4G/5GµÈ·þÎñÔÝʱÖжÏ
Ðû²¼Ê±¼ä 2022-02-11ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷£¬4G/5GµÈ·þÎñÔÝʱÖжÏ
¾ÝýÌå2ÔÂ8ÈÕ±¨µÀ£¬ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷£¬µ¼ÖÂ4G/5GÊý¾ÝÍøÂç¡¢ÀιÌÓïÒô¡¢µçÊÓ¡¢¶ÌÐźÍÓïÒô/Êý×ÖÓ¦´ðµÈ·þÎñÖжϡ£Ä¿Ç°£¬Ö»ÓÐ3GÍøÂç¿ÉÓã¨×î´ó3MB/Ã룩£¬¶ø»Ö¸´ÆäËü·þÎñÈÔÐè½Ï³¤Ê±¼ä¡£ÎÖ´ï·áÔڸùúÓµÓÐÁè¼Ý400ÍòÊÖ»úÓû§£¬¼°340Íò¼ÒÍ¥ºÍÆóÒµÓû§£¬Òò´Ë´Ë´Î¹¥»÷·¢ÉúÁË´ó¹æÄ£Ó°Ïì¡£ÎÖ´ï·á²¢Î´Í¸Â¶¹¥»÷ϸ½Ú£¬µ«Ñо¿ÈËÔ±·ÖÎö³ÆÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/vodafone-portugal-4g-and-5g-services-down-after-cyberattack/
APT×éÖ¯KimsukyÀûÓÃGold DragonºóÃŹ¥»÷º«¹úµÄ×éÖ¯
2ÔÂ8ÈÕ£¬º«¹úASEC·ÖÎöÍŶӹûÈ»ÁËAPT×éÖ¯Kimsuky½üÆÚ»î¶¯µÄϸ½Ú¡£KimsukyÊdz¯ÏʵĺڿÍ×éÖ¯£¬Ò²³ÆÎªTA406£¬×Ô2017ÄêÒÔÀ´Ò»Ö±¼ÓÈëÍøÂç¼äµý»î¶¯¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ2022Äê1ÔÂ24ÈÕ£¬Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬KimsukyʹÓÃxRAT£¨»ùÓÚQuasar RATµÄ¿ªÔ´RAT£©ºÍGold DragonµÄбäÌå¶Ôº«¹úµÄ×éÖ¯½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£´ËÍ⣬Ñо¿ÈËÔ±³ÆÓʼþ¸½¼þÈÔÊÇKimsuky·Ö·¢¶ñÒâÈí¼þµÄÖ÷ÒªÇþµÀ£¬Òò´Ë½¨ÒéÓû§²»Òª´ò¿ªÎ´ÖªÀ´Ô´µÄÓʼþ¡£
https://asec.ahnlab.com/en/31089/
MoleratsÀûÓÃеÄNimbleMamba¹¥»÷Öж«µÄ¹Ù·½»ú¹¹
2ÔÂ8ÈÕ£¬Proofpoint³ÆMolerats£¨ÓÖÃûTA402£©ÒѾ¿ªÊ¼ÁËÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¸ÃºÚ¿ÍÍÅ»ï»òÐíÓë°ÍÀÕ˹̹Óйأ¬ÀûÓÃÁËеĶñÒâÈí¼þNimbleMamba£¬¹¥»÷Öж«µÄÕþ¸®¡¢Íâ½»»ú¹¹ÒÔ¼°¹úÓк½¿Õ¹«Ë¾¡£Ñо¿ÈËÔ±³Æ£¬NimbleMamba¿ÉÄÜÊǸÃ×é֮֯ǰʹÓõÄLastConnµÄÌæ´úÆ·£¬¶øÇҴ˴λ¾ßÓÐÅÓ´óµÄ¹¥»÷Á´£¬¹¥»÷ÕßÀûÓÃÁ˵ØÀíΧÀ¸ºÍURLÖØ¶¨Ïòµ½ºÏ·¨Õ¾µã£¬À´ÈƹýÄþ¾²¼ì²â¡£
https://www.proofpoint.com/us/blog/threat-insight/ugg-boots-4-sale-tale-palestinian-aligned-espionage
Kaspersky½üÆÚ·¢ÏÖÕë¶ÔÅ·ÖÞµØÓòµÄSMSishing»î¶¯
KasperskyÔÚ2ÔÂ7ÈÕÐû²¼³ÂËߣ¬·ÖÎöÁËRoaming MantisÕë¶ÔÅ·ÖÞµØÓòµÄ»î¶¯¡£¸ÃÍÅ»ïÓÚ2018Äê3ÔÂÊ״ηºÆð£¬ÆäʱµÄÄ¿±êÖ÷ÒªÊÇÑÇÖÞÓû§£¬ÀûÓÃsmishingÒÔAPKÎļþµÄ¸ñʽ·Ö·¢¶ñÒâAndroidÓ¦Ó᣶øÔÚ×îеĻÖУ¬¹¥»÷ÕßʹÓÃÁËÒ»ÖÖÃûΪWrobaµÄľÂíÀ´¹¥»÷·¨¹úºÍµÂ¹úµÄÓû§¡£´Ë´Î»î¶¯Í¨¹ý¶ÌÐÅ·¢ËÍαװ³É·¢»õÐÅÏ¢µÄ¶ñÒâÁ´½Ó£¬½«Ä¿±êÖØ¶¨Ïòµ½ÇÔÈ¡AppleµÇ¼ƾ֤µÄµöÓãÒ³Ãæ¡£
https://securelist.com/roaming-mantis-reaches-europe/105596/
Ñо¿ÍŶӷ¢ÏÖCapraRATÕë¶ÔÓ¡¶ÈÍâ½»ºÍ¾üÊ»ú¹¹µÄ¹¥»÷
ýÌå2ÔÂ7ÈÕ±¨µÀ³Æ£¬Trend Micro·¢ÏÖÀûÓÃCapraRAT¹¥»÷Ó¡¶ÈÍâ½»ºÍ¾üÊ»ú¹¹µÄ»î¶¯¡£CapraRATÊÇAndroid RAT£¬ÓëÁíÒ»ÖÖWindows¶ñÒâÈí¼þCrimsonRATµÄ¸ß¶È½»²æ£¬ºóÕßÓë°Í»ù˹̹Earth Karkaddan£¨Ò²³ÆÎªAPT36£©Óйء£CapraRATαװ³ÉYouTube£¬¾ÝϤÊÇÒ»¸öÃûΪAndroRATµÄ¿ªÔ´RATµÄ¸ïа棬¾ßÓжàÖÖÊý¾Ýй¶¹¦Ð§£¬°üÂÞ»ñȡĿ±êλÖᢵ绰ÈÕÖ¾ºÍÁªÏµÐÅÏ¢µÈ¡£
https://thehackernews.com/2022/02/new-caprarat-android-malware-targets.html
CISA½¨Òé¹ÜÀíÔ±ÐÞ¸´SAPÖÐͳ³ÆÎªICMADµÄ¶à¸ö©¶´
CISAÔÚ2ÔÂ8ÈÕÐû²¼Äþ¾²Í¨¸æ£¬½¨Òé¹ÜÀíÔ±ÐÞ¸´SAPÖеĶà¸ö©¶´¡£Ñо¿ÈËÔ±·¢ÏÖÁËÓ°ÏìʹÓÃICMµÄSAPÓ¦ÓõÄ©¶´£¬ËûÃÇͳ³ÆÎªICMAD£¨Internet Communication Manager Advanced Desync£©£¬·Ö±ðÊÇCVE-2022-22536£¨CVSSÆÀ·ÖΪ10£©¡¢CVE-2022-22532ºÍCVE-2022-22533¡£CISA³Æ£¬ÕâЩ©¶´¿ÉÄܻᵼÖÂÊý¾Ýй¶¡¢½ðÈÚÆÛÕ©¡¢Òªº¦ÈÎÎñÒµÎñÁ÷³ÌÖжϡ¢ÀÕË÷¹¥»÷ÒÔ¼°ËùÓÐÔËӪֹͣµÄ·çÏÕ¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/08/critical-vulnerabilities-affecting-sap-applications-employing
Äþ¾²¹¤¾ß
Pwndora
Pwndora ÊÇÒ»¸öÅÓ´óÇÒ¿ìËÙµÄ IPv4 µØÖ··¶Î§É¨ÃèÆ÷£¬¼¯³ÉÁ˶àÏ̡߳£
https://github.com/alechilczenko/pwndora
Mandiant Azure AD Investigator
´Ë´æ´¢¿â°üÂÞÒ»¸ö PowerShell Ä£¿é£¬ÓÃÓÚ¼ì²â¿ÉÄÜÊÇ UNC2452 ºÍÆäËûÍþв¼ÓÈëÕ߻ָ±êµÄ¹¤¼þ¡£
https://github.com/mandiant/Mandiant-Azure-AD-Investigator
LDAP Relay Scan
ÓÃÓÚ¼ì²éÓò¿ØÖÆÆ÷ÒÔ»ñÈ¡ÓÐ¹Ø NTLM Éí·ÝÑéÖ¤ÖÐ¼ÌµÄ LDAP ·þÎñÆ÷±£»¤µÄ¹¤¾ß¡£
https://github.com/zyn3rgy/LdapRelayScan
Incident Response Collection Protocol
һϵÁÐ PowerShell ½Å±¾£¬ÓÃÓÚ×Ô¶¯»¯È˹¤ÖÆÆ·ÊÕ¼¯²¢ÐÖúÏìÓ¦ÕßÔÚ»ùÓÚʵÑéÊÒºÍÏÖ³¡»·¾³ÖÐ¶Ô¶Ëµã½øÐзÖÀà¡£
https://github.com/hackjalstead/IRCP
Äþ¾²·ÖÎö
²¨À¼½¨Á¢ÍøÂçÄþ¾²¾üʵ¥Ôª
https://www.securityweek.com/poland-launches-cybersecurity-military-unit
Adobe ÐÞ²¹ Illustrator ÖÐµÄ 13 ¸ö©¶´
https://www.securityweek.com/adobe-patches-13-vulnerabilities-illustrator
ÃÀ¹ú²é»ñÔÚ 2016 Äê Bitfinex ºÚ¿Í¹¥»÷Öб»µÁµÄ¼ÛÖµ 36 ÒÚÃÀÔª¼ÓÃÜ»õ±Ò
https://securityaffairs.co/wordpress/127805/cyber-crime/bitfinex-stolen-funds-seizure.html
¶íÂÞ˹´þ²¶ÁËijºÚ¿Í×éÖ¯
https://www.bleepingcomputer.com/news/security/russia-arrests-third-hacking-group-reportedly-seizes-carding-forums/
΢ÈíĬÈϽûÓà Office Ó¦Ó÷¨Ê½ÖÐµÄ Internet ºêÒÔ×èÖ¹¶ñÒâÈí¼þ¹¥»÷
https://thehackernews.com/2022/02/microsoft-disables-internet-macros-in.html
¹È¸èÐÞ¸´ÁË Android ÉϵÄÔ¶³ÌȨÏÞÌáÉý´íÎó
https://www.bleepingcomputer.com/news/security/google-fixes-remote-escalation-of-privileges-bug-on-android/
΢ÈíÐû²¼2Ô·ÝÖܶþ²¹¶¡
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2022-patch-tuesday-fixes-48-flaws-1-zero-day/