΢Èí°ä²¼Õë¶ÔPetitPotam NTLMÖм̹¥»÷µÄ»º½â´ëÊ©£»£»£»£»£»£»£»ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë
°ä²¼¹¦·ò 2021-07-26
΢Èí°ä²¼Õë¶ÔеÄPetitPotam NTLMÖм̹¥»÷µÄ»º½â´ëÊ©¡£¡£¡£¡£¡£PetitPotamÊÇÓÉ·¨¹ú×êÑÐÈËÔ±Gilles Lionel·¢ÏÖµÄÐÂNTLMÖм̹¥»÷£¬£¬£¬£¬£¬Ê¹ÓÃÁËMicrosoft¼ÓÃÜÎļþϵͳԶ³ÌºÍ̸( EFSRPC)À´Ç¿ÔìÉ豸ÏòÓɺڿͽÚÔìµÄÔ¶³ÌNTLMÖмÌÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÓÃÀ´ÊÕÊÜÓò½ÚÔìÆ÷»òÆäËûWindows·þÎñÆ÷¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÔÚ²»±ØÒªµÄ´¦Ëù½ûÓÃNTLM£¬£¬£¬£¬£¬»òÕ߯ôÓÃÉí·ÝÑéÖ¤»úÔìµÄÀ©´ó±£»£»£»£»£»£»£»¤£»£»£»£»£»£»£»²¢½¨ÒéÔÚÆôÓÃÁËNTLMµÄÍøÂçÉÏ£¬£¬£¬£¬£¬ÔÊÐíNTLMÉí·ÝÑé֤ʹÓÃÊðÃûÖ°ÄܵķþÎñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcompter.com/news/security/microsoft-shares-mitigations-for-new-petitpotam-ntlm-relay-attack/
2.΢Èí³ÆÆä7Ô·ݰ²È«¸üпÉÄÜÓ°Ï첿ÃÅϵͳµÄ´òÓ¡Ö°ÄÜ

΢Èí°µÊ¾£¬£¬£¬£¬£¬ÔÚÓò½ÚÔìÆ÷(DC)ÉÏ×°ÖÃ2021Äê7ÔÂWindows 10°²È«¸üк󣬣¬£¬£¬£¬Ê¹ÓÃÖÇÄÜ¿¨(PIV)Éí·ÝÑéÖ¤µÄÉ豸µÄ´òÓ¡ºÍɨÃèÖ°ÄÜ¿ÉÄÜ»á³öÏÖÎÊÌâ¡£¡£¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÓÚÕë¶Ô°²È«·ì϶CVE-2021-33764µÄ¼Ó¹ÌËùµ¼Öµģ¬£¬£¬£¬£¬Ó°ÏìÁËÔÚKerberosASÒªÇóÆÚ¼ä²»Ö§³ÖDH»òÖ§³Ödes-ede3-cbc£¨Èý³ÁDES£©µÄÖÇÄÜ¿¨ÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶàÖ°ÄÜÉ豸¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÁªÏµÉ豸µÄÔì×÷É̲¢ÒªÇó½øÐÐÉèÖøü¸Ä»ò¸üУ¬£¬£¬£¬£¬ÒÔÇкÏCVE-2021-33764µÄ°²È«¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-july-security-updates-break-printing-on-some-systems/
3.×êÑÐÍŶÓÅû¶ÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ

°²È«¹«Ë¾MBSDÅû¶ÁËÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÔÚÉÏÖÜÎå½øÐеÄ2021Äê¶«¾©°ÂÔ˻ῪĻʽǰÁ½Ìì·¢Ïֵ쬣¬£¬£¬£¬Ëü²»½öÄÜɾ³ýµçÄÔÉϵÄËùº±¼û¾Ý£¬£¬£¬£¬£¬»¹ÄÜËÑË÷λÓÚC:/Users/<username>/µÄÓû§Ó×ÎÒÎļþ¼ÐÖеÄÌØ¶¨ÎļþÀàÐÍ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬Microsoft OfficeÎļþÊÇÒª¸Ã¶ñÒâÈí¼þɾ³ýµÄÖØÒªÖ¸±ê£¬£¬£¬£¬£¬´Ë±í»¹ÓÐTXT¡¢LOGºÍCSVÎļþ£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÎļþÓÐʱ»á´æ´¢ÈÕÖ¾¡¢Êý¾Ý¿â»òÃÜÂëÐÅÏ¢µÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¸Ãwiper»¹Õë¶ÔʹÓÃÁËIchitaroÈÕÓïÎÄ×Ö´¦ÖÃÆ÷´´½¨µÄÎļþ£¬£¬£¬£¬£¬ÕâÖ¤Ã÷Ëü¿ÉÄÜרÃÅÕë¶ÔÈÕ±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/wiper-malware-targeting-japanese-pcs-discovered-ahead-of-tokyo-olympics-opening/
4.AvananÅû¶ÀûÓúÏ×÷ÀûÓÃMilanoteÈÆ¹ýSEGµÄ´¹µö»î¶¯

Avanan×êÑÐÈËÔ±Åû¶ÁËÀûÓúÏ×÷ÀûÓÃMilanoteÈÆ¹ýSEGµÄ´¹µö»î¶¯¡£¡£¡£¡£¡£Avanan³Æ£¬£¬£¬£¬£¬½üÆÚ´ËÀàÍøÂç´¹µö¹¥»÷µÄÊýÁ¿¼±¾çÔö³¤£¬£¬£¬£¬£¬ËûÃÇÔÚÍ¨Ñ¶ÍøÂçÖзÖÎöÁË1430·âÔ̺¬MilanoteÁ´½ÓµÄÓʼþ£¬£¬£¬£¬£¬ÆäÖÐ1367·âÊÇÍøÂç´¹µö»î¶¯µÄÒ»²¿ÃÅ£¨¸ß´ï95.5%£©¡£¡£¡£¡£¡£Õâ´Î»î¶¯Ê¹ÓÃÁËÒÔÏîÄ¿Ìá°¸·¢Æ±ÎªÖ÷ÌâµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬ÓÕʹָ±ê´ò¿ªÏνÓÖеÄÎĵµ²¢±»³Á¶¨Ïòµ½MilanoteÖеÄÒ³Ãæ¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÕâÖÖ·½Ê½½«payloadǶÌ×ÔںϷ¨·þÎñÖÐÀ´ÈƹýÕâЩ¼ì²â»úÔ죬£¬£¬£¬£¬Ô̺¬¾²Ì¬É¨ÃèÆ÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/07/hacker-employ-milanote-app-for.html
5.ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë

ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛÁËClubhouseÔ̺¬38ÒÚ¸öµç»°ºÅÂëµÄÊý¾Ý¿â¡£¡£¡£¡£¡£Âô¼ÒÐû³Æ¸ÃÊý¾Ý¿âÔ̺¬38ÒÚ¸öµç»°ºÅÂ룬£¬£¬£¬£¬Ô̺¬ÊÖ»ú¡¢¹Ì¶¨µç»°¡¢¸öÈ˵绰ºÍרҵµç»°£¬£¬£¬£¬£¬²¢ÇÒÿ¸öºÅÂë¶¼°´Ìض¨µÄ·ÖÊý£¨Ôڵ绰²¾ÖÐÕ¼Óд˵绰ºÅÂëµÄ»áËùÓû§ÊýÁ¿£©½øÐÐÁËÅÅÃû¡£¡£¡£¡£¡£ºÚ¿Í»¹°ä²¼Á˸ÃÊý¾Ý¿âµÄÑù±¾µÄ£¬£¬£¬£¬£¬Ô̺¬³¬¹ý8350Íò¸öÈÕ±¾Óû§µÄµç»°ºÅÂë¡£¡£¡£¡£¡£ÔçÔÚ2021Äê4Ô£¬£¬£¬£¬£¬Cyber NewsµÄ×êÑÐÈËÔ±Ôø·¢ÏÖÁË130Íò¸öClubhouseÓû§µÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120553/hacking/threat-actor-offers-clubhouse-secret-database-containing-3-8b-phone-numbers.html
6.Kaspersky°ä²¼2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)»ã±¨

Kaspersky°ä²¼ÁË2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÔÚ2020ÄêµÚËÄʱ¶È£¬£¬£¬£¬£¬´Óһ̨Ö÷»úÍøÂçµÄÔʼÊÂÎñµÄ¾ùÔÈÊýÁ¿Ô¼Îª15000¡£¡£¡£¡£¡£Æ¾¾ÝMDRÊÂÎñÑϳÁÐÔ·ÖÀ࣬£¬£¬£¬£¬¸ßÑϳÁÐÔÊÂÎñÓëÓµÓиßÓ°ÏìµÄ±¨´ð¹¥»÷»ò¶ñÒâÈí¼þÓйأ¬£¬£¬£¬£¬ÆäÖдËÀàÊÂÎñµÄÓÕÒò¿ÉÄÜΪ£ºAPT--Õë¶ÔÐÔ¹¥»÷¡¢½ø¹¥ÐԻ¡¢Ó°ÏìÑϳÁµÄ¶ñÒâÈí¼þ¡¢¿É±»ÀûÓõķì϶¡¢DDOS/DOS¡¢ÄÚ²¿Íþв£¨Ú²ÆµÈ£©ÒÔ¼°Éç»á¹¤³Ì¹¥»÷µÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÏÕЩËùÓд¹Ö±ÐÐÒµ¶¼ÓÐÊܺ¦Õߣ¬£¬£¬£¬£¬¶øÇ°3ÃûΪITÐÐÒµ¡¢µ±¾Ö×éÖ¯ºÍ¹¤Òµ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/managed-detection-and-response-in-q4-2020/103387/


¾©¹«Íø°²±¸11010802024551ºÅ