ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷ 4G/5GµÈ·þÎñÁÙʱÖжÏ
°ä²¼¹¦·ò 2022-02-11ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷£¬£¬£¬£¬£¬4G/5GµÈ·þÎñÁÙʱÖжÏ
¾ÝýÌå2ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬ÎÖ´ï·áÆÏÌÑÑÀ¹«Ë¾Ôâµ½¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂ4G/5GÊý¾ÝÍøÂç¡¢¹Ì¶¨ÓïÒô¡¢µçÊÓ¡¢¶ÌÐźÍÓïÒô/Êý×ÖÓ¦´ðµÈ·þÎñÖжϡ£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Ö»ÓÐ3GÍøÂç¿ÉÓã¨×î´ó3MB/Ã룩£¬£¬£¬£¬£¬¶ø¸´ÔÆäËü·þÎñÈÔÐè½Ï³¤¹¦·ò¡£¡£¡£¡£¡£¡£ÎÖ´ï·áÔڸùúÕ¼Óг¬¹ý400ÍòÊÖ»úÓû§£¬£¬£¬£¬£¬¼°340Íò¼ÒÍ¥ºÍÆóÒµÓû§£¬£¬£¬£¬£¬Òò¶øÕâ´Î¹¥»÷²úÉúÁË´ó¹æÄ£Ó°Ïì¡£¡£¡£¡£¡£¡£ÎÖ´ï·á²¢Î´Ð¹Â©¹¥»÷ϸ½Ú£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±·ÖÎö³ÆÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/vodafone-portugal-4g-and-5g-services-down-after-cyberattack/
APT×éÖ¯KimsukyÀûÓÃGold DragonºóÃŹ¥»÷º«¹úµÄ×éÖ¯
2ÔÂ8ÈÕ£¬£¬£¬£¬£¬º«¹úASEC·ÖÎöÍŶӹ«¿ªÁËAPT×éÖ¯Kimsuky½üÆÚ»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£KimsukyÊdz¯ÏʵĺڿÍ×éÖ¯£¬£¬£¬£¬£¬Ò²³ÆÎªTA406£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´Ò»Ïò²Î¼ÓÍøÂç¼äµý»î¶¯¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2022Äê1ÔÂ24ÈÕ£¬£¬£¬£¬£¬Ä¿Ç°ÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬KimsukyʹÓÃxRAT£¨»ùÓÚQuasar RATµÄ¿ªÔ´RAT£©ºÍGold DragonµÄбäÌå¶Ôº«¹úµÄ×éÖ¯½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬×êÑÐÈËÔ±³ÆÓʼþ¸½¼þÈÔÊÇKimsuky·Ö·¢¶ñÒâÈí¼þµÄÖØÒªÇþ·£¬£¬£¬£¬£¬Òò¶ø½¨ÒéÓû§²»Òª´ò¿ªÎ´ÖªÆðÔ´µÄÓʼþ¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/31089/
MoleratsÀûÓÃеÄNimbleMamba¹¥»÷Öж«µÄ¹Ù·½»ú¹¹
2ÔÂ8ÈÕ£¬£¬£¬£¬£¬Proofpoint³ÆMolerats£¨±ðÃûTA402£©ÒѾÆðÍ·ÁËÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸ÃºÚ¿ÍÍÅ»ï»òÐíÓë°ÍÀÕ˹̹Óйأ¬£¬£¬£¬£¬ÀûÓÃÁËеĶñÒâÈí¼þNimbleMamba£¬£¬£¬£¬£¬¹¥»÷Öж«È·µ±¾Ö¡¢±í½»»ú¹¹ÒÔ¼°¹úÓк½¿Õ¹«Ë¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬NimbleMamba¿ÉÄÜÊǸÃ×é֮֯ǰʹÓõÄLastConnµÄ´úÌæÆ·£¬£¬£¬£¬£¬²¢ÇÒÕâ´Î»î¶¯ÓµÓи´ÔӵĹ¥»÷Á´£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁ˵ØÀíΧÀ¸ºÍURL³Á¶¨Ïòµ½ºÏ·¨Õ¾µã£¬£¬£¬£¬£¬À´Èƹý°²È«¼ì²â¡£¡£¡£¡£¡£¡£
https://www.proofpoint.com/us/blog/threat-insight/ugg-boots-4-sale-tale-palestinian-aligned-espionage
Kaspersky½üÆÚ·¢ÏÖÕë¶ÔÅ·ÖÞµØÓòµÄSMSishing»î¶¯
KasperskyÔÚ2ÔÂ7ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬·ÖÎöÁËRoaming MantisÕë¶ÔÅ·ÖÞµØÓòµÄ»î¶¯¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2018Äê3Ô³õ´Î³öÏÖ£¬£¬£¬£¬£¬ÆäʱµÄÖ¸±êÖØÒªÊÇÑÇÖÞÓû§£¬£¬£¬£¬£¬ÀûÓÃsmishingÒÔAPKÎļþµÄÌåʽ·Ö·¢¶ñÒâAndroidÀûÓᣡ£¡£¡£¡£¡£¶øÔÚ×îеĻÖУ¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÒ»ÖÖÃûΪWrobaµÄľÂíÀ´¹¥»÷·¨¹úºÍµÂ¹úµÄÓû§¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Í¨¹ý¶ÌÐÅ·¢ËͼÙ×°³É·¢»õÐÅÏ¢µÄ¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬½«Ö¸±ê³Á¶¨Ïòµ½ÇÔÈ¡AppleµÇ¼ƾ֤µÄ´¹µöÒ³Ãæ¡£¡£¡£¡£¡£¡£
https://securelist.com/roaming-mantis-reaches-europe/105596/
×êÑÐÍŶӷ¢ÏÖCapraRATÕë¶ÔÓ¡¶È±í½»ºÍ¾üÊ»ú¹¹µÄ¹¥»÷
ýÌå2ÔÂ7ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Trend Micro·¢ÏÖÀûÓÃCapraRAT¹¥»÷Ó¡¶È±í½»ºÍ¾üÊ»ú¹¹µÄ»î¶¯¡£¡£¡£¡£¡£¡£CapraRATÊÇAndroid RAT£¬£¬£¬£¬£¬ÓëÁíÒ»ÖÖWindows¶ñÒâÈí¼þCrimsonRATµÄ¸ß¶È½»²æ£¬£¬£¬£¬£¬ºóÕßÓë°Í»ù˹̹Earth Karkaddan£¨Ò²³ÆÎªAPT36£©Óйء£¡£¡£¡£¡£¡£CapraRAT¼Ù×°³ÉYouTube£¬£¬£¬£¬£¬¾ÝϤÊÇÒ»¸öÃûΪAndroRATµÄ¿ªÔ´RATµÄ¸Ä½ø°æ£¬£¬£¬£¬£¬ÓµÓжàÖÖÊý¾Ýй¶ְÄÜ£¬£¬£¬£¬£¬Ô̺¬»ñȡָ±êµØÎ»¡¢µç»°ÈÕÖ¾ºÍÁªÏµÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/02/new-caprarat-android-malware-targets.html
CISA½¨ÒéÖÎÀíÔ±½¨¸´SAPÖÐͳ³ÆÎªICMADµÄ¶à¸ö·ì϶
CISAÔÚ2ÔÂ8ÈÕ°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±½¨¸´SAPÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁËÓ°ÏìʹÓÃICMµÄSAPÀûÓõķì϶£¬£¬£¬£¬£¬ËûÃÇͳ³ÆÎªICMAD£¨Internet Communication Manager Advanced Desync£©£¬£¬£¬£¬£¬±ðÀëÊÇCVE-2022-22536£¨CVSSÆÀ·ÖΪ10£©¡¢CVE-2022-22532ºÍCVE-2022-22533¡£¡£¡£¡£¡£¡£CISA³Æ£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܻᵼÖÂÊý¾Ýй¶¡¢½ðÈÚڲơ¢¹Ø¼ü¹¤×÷ÒµÎñÁ÷³ÌÖжϡ¢ÀÕË÷¹¥»÷ÒÔ¼°ËùÓÐÔËÓªÖÕ³¡µÄ·çÏÕ¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/08/critical-vulnerabilities-affecting-sap-applications-employing
°²È«¹¤¾ß
Pwndora
Pwndora ÊÇÒ»¸öÖØ´óÇÒ¼±¾çµÄ IPv4 µØÖ·ÁìÓòɨÃèÆ÷£¬£¬£¬£¬£¬¼¯³ÉÁ˶àÏ̡߳£¡£¡£¡£¡£¡£
https://github.com/alechilczenko/pwndora
Mandiant Azure AD Investigator
´Ë´æ´¢¿âÔ̺¬Ò»¸ö PowerShell Ä£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬ÓÃÓÚ¼ì²â¿ÉÄÜÊÇ UNC2452 ºÍÆäËûÍþв²Î¼ÓÕ߻ָ±êµÄ¹¤¼þ¡£¡£¡£¡£¡£¡£
https://github.com/mandiant/Mandiant-Azure-AD-Investigator
LDAP Relay Scan
ÓÃÓÚ²é³Óò½ÚÔìÆ÷ÒÔ»ñÈ¡ÓÐ¹Ø NTLM Éí·ÝÑéÖ¤ÖÐ¼ÌµÄ LDAP ·þÎñÆ÷±£»£»£»£»£»£»£»£»¤µÄ¹¤¾ß¡£¡£¡£¡£¡£¡£
https://github.com/zyn3rgy/LdapRelayScan
Incident Response Collection Protocol
һϵÁÐ PowerShell ¾ç±¾£¬£¬£¬£¬£¬ÓÃÓÚ×Ô¶¯»¯ÈËÎªÖÆÆ·ÍøÂç²¢ÐÖúÏìÓ¦ÕßÔÚ»ùÓÚ³¢ÊÔÊÒºÍÏÖ³¡»·¾³ÖÐ¶Ô¶Ëµã½øÐзÖÀà¡£¡£¡£¡£¡£¡£
https://github.com/hackjalstead/IRCP
°²È«·ÖÎö
²¨À¼³ÉÁ¢ÍøÂ簲ȫ¾üʵ¥Ôª
https://www.securityweek.com/poland-launches-cybersecurity-military-unit
Adobe ½¨²¹ Illustrator ÖÐµÄ 13 ¸ö·ì϶
https://www.securityweek.com/adobe-patches-13-vulnerabilities-illustrator
ÃÀ¹ú²é»ñÔÚ 2016 Äê Bitfinex ºÚ¿Í¹¥»÷Öб»µÁµÄ¼ÛÖµ 36 ÒÚÃÀÔª¼ÓÃÜÇ®±Ò
https://securityaffairs.co/wordpress/127805/cyber-crime/bitfinex-stolen-funds-seizure.html
¶íÂÞ˹¿ÛÁôÁËijºÚ¿Í×éÖ¯
https://www.bleepingcomputer.com/news/security/russia-arrests-third-hacking-group-reportedly-seizes-carding-forums/
΢ÈíĬÈϽûÓà Office ÀûÓ÷¨Ê½ÖÐµÄ Internet ºêÒÔ×èÖ¹¶ñÒâÈí¼þ¹¥»÷
https://thehackernews.com/2022/02/microsoft-disables-internet-macros-in.html
¹È¸è½¨¸´ÁË Android ÉϵÄÔ¶³ÌȨÏÞÌáÉýÃýÎó
https://www.bleepingcomputer.com/news/security/google-fixes-remote-escalation-of-privileges-bug-on-android/
΢Èí°ä²¼2Ô·ÝÖܶþ²¹¶¡
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2022-patch-tuesday-fixes-48-flaws-1-zero-day/


¾©¹«Íø°²±¸11010802024551ºÅ