ContiÍÅ»ïÒѱøÆ÷»¯Log4Shell²¢³ÉÁ¢ÆëÈ«µÄ¹¥»÷Á´

°ä²¼¹¦·ò 2021-12-22

ContiÍÅ»ïÒѱøÆ÷»¯Log4Shell²¢³ÉÁ¢ÆëÈ«µÄ¹¥»÷Á´


ContiÍÅ»ïÒѱøÆ÷»¯Log4Shell²¢³ÉÁ¢ÆëÈ«µÄ¹¥»÷Á´.png


12ÔÂ18ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Advanced Intelligence³ÆConti³ÉΪÊ׸ö½«Log4j2±øÆ÷»¯µÄרҵ¼¶ÀÕË÷ÔËÓªÍŻ £¬£¬£¬£¬£¬£¬£¬ÏÖÒÑÕ¼ÓÐÆëÈ«µÄ¹¥»÷Á´¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁ12ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïµÄ¸Ã¹¥»÷Á´Îª£ºEmotet -> Cobalt Strike -> Human Exploitation -> ¶ÌȱADMIN$¹²Ïí -> Kerberoast -> VMWare vCenter·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Conti×Ô8ÔÂ·ÝÆðÍ·½øÐÐÁËÂŴθüУ¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬Ê¹ÓÃеĺóÃźͱ¸·Ýɾ³ýÕ½ÊõµÈ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/conti-ransomware-gang-has-full-log4shell-attack-chain/177173/


FBI³Æ¹¥»÷Õß»ý¼«ÀûÓÃZohoÖзì϶CVE-2021-44515


FBI³Æ¹¥»÷Õß»ý¼«ÀûÓÃZohoÖзì϶CVE-2021-44515.png


12ÔÂ17ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬FBI°ä²¼¾¯±¨³ÆÓÐAPT×éÖ¯×Ô10ÔÂÏÂÑ®ÆðÍ·Ò»ÏòÔÚ»ý¼«ÀûÓÃZohoÖеķì϶CVE-2021-44515¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇManageEngine Desktop CentralÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÈƹýÉí·ÝÑéÖ¤²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£FBI³Æ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÈëÇÖDesktop Central·þÎñÆ÷ºó×°Öø²¸ÇÆäºÏ·¨Ö°ÄܵÄwebshell£¬ £¬£¬£¬£¬£¬£¬£¬¶øºóÏÂÔØÀûÓù¤¾ß£¬ £¬£¬£¬£¬£¬£¬£¬ÁоÙÓòÓû§ºÍȺ×飬 £¬£¬£¬£¬£¬£¬£¬½øÐÐÍøÂç¿úËÅ£¬ £¬£¬£¬£¬£¬£¬£¬×îºóÊÔͼºáÏòÒÆ¶¯ºÍת´¢Æ¾Ö¤¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125821/hacking/zoho-zero-day-cve-2021-44515-fbi-alert.html


΢Èí¶½´ÙÓû§½¨¸´Active DirectoryÖÐ2¸öÌáȨ·ì϶


΢Èí¶½´ÙÓû§½¨¸´Active DirectoryÖÐ2¸öÌáȨ·ì϶.png


΢ÈíÔÚ12ÔÂ20ÈÕ°ä²¼°²È«²¼¸æ£¬ £¬£¬£¬£¬£¬£¬£¬¶½´ÙÓû§¾¡¿ì½¨¸´Active DirectoryÖÐ2¸öÌáȨ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ2¸ö·ì϶ΪCVE-2021-42287ºÍCVE-2021-42278£¬ £¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ2021Äê11ÔµÄÖܶþ²¹¶¡Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬ £¬£¬£¬£¬£¬£¬£¬½áºÏʹÓÃÕâÁ½¸ö·ì϶¿ÉÔÚActive Directory»·¾³Öд´½¨Ò»¸öÖ±½Ó½Ó¼ûÓòÖÎÀíÔ±Óû§µÄõè¾¶¡£¡£¡£¡£¡£¡£¡£¡£12ÔÂ11ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±°ä²¼ÁËÀûÓÃÕâЩ·ì϶µÄ¸ÅÏëÑéÖ¤(PoC)¹¤¾ß£¬ £¬£¬£¬£¬£¬£¬£¬¾­²âÊÔÈ·¶¨¸Ã¹¤¾ßÄܹ»ÇáËɵؽ«Óû§È¨ÏÞÌáÉýÖÁÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/


Avast·¢ÏÖÃÀ¹úij¹Ù·½×éÖ¯Ôâµ½APT¹¥»÷ºó±»Ö²ÈëºóÃÅ


Avast·¢ÏÖÃÀ¹úij¹Ù·½×éÖ¯Ôâµ½APT¹¥»÷ºó±»Ö²ÈëºóÃÅ.png


½Ý¿Ë°²È«¹«Ë¾AvastÔÚ12ÔÂ16ÈÕÅû¶ÁËÕë¶ÔÃÀ¹úij¹Ù·½×éÖ¯µÄAPT¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£Avast²¢Î´¹«¿ªÖ¸±ê×éÖ¯µÄÃû³Æ£¬ £¬£¬£¬£¬£¬£¬£¬¾ÝThe Record´§Ä¦ÓëÃÀ¹ú¹ú¼Ê×Ú½Ì×ÔÓÉίԱ»á(USCIRF)Óйء£¡£¡£¡£¡£¡£¡£¡£×êÑÐÍŶӷ¢ÏÖ¹¥»÷»î¶¯ÖÐʹÓõÄ2¸ö¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬£¬µÚÒ»¸ö¼Ù×°³Éoci.dll²¢ÀûÓúϷ¨ÀûÓÃWinDivertÀ´ÕìÌýInternetͨѶ£»£»£»£»£»£»£»£»µÚ¶þ¸öÒ²¼Ù×°³ÉÁËoci.dll£¬ £¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö½âÃÜÆ÷£¬ £¬£¬£¬£¬£¬£¬£¬Óëred signatureÐж¯ÖÐʹÓõĶñÒâÈí¼þ¼«¶ÈÀàËÆ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/12/experts-discover-backdoor-deployed-on.html



T-MobileÐû³ÆÆäÔÚ2021ÄêÒÑÀ¹½ØÔ¼210ÒÚ¸öÚ¿Æ­µç»°


T-MobileÐû³ÆÆäÔÚ2021ÄêÒÑÀ¹½ØÔ¼210ÒÚ¸öÚ¿Æ­µç»°.png


12ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬T-Mobile°µÊ¾ÆäÔÚ2021ÄêÒÑÀ¹½ØÔ¼210ÒÚ¸öÚ¿Æ­µç»°£¬ £¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿ¸öÔ¼ø±ð»òÀ¹½ØÁË18ÒÚ¸öÚ¿Æ­µç»°¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2021Äê12ÔÂÉÏÑ®µÄÊý¾ÝÏÔʾ£¬ £¬£¬£¬£¬£¬£¬£¬Ú¿Æ­µç»°µÄÁ÷Á¿ÒÑ´ïµ½º¹Çà×î¸ßˮƽ£¬ £¬£¬£¬£¬£¬£¬£¬´ïµ½Ã¿ÖÜԼĪ4.25Òڴγ¢ÊÔ£¬ £¬£¬£¬£¬£¬£¬£¬½ÏÖ®2020ÄêÔö·ù³¬¹ý116%¡£¡£¡£¡£¡£¡£¡£¡£Á÷Á¿×îµÍµÄÊÇ1Ô£¬ £¬£¬£¬£¬£¬£¬£¬ÓÐ11ÒÚ¸öÚ¿Æ­µç»°£»£»£»£»£»£»£»£»µ½11Ô£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý³ÊÖ¸ÊýÔö³¤£¬ £¬£¬£¬£¬£¬£¬£¬Ú¿Æ­µç»°µÄÊýÁ¿ÊÇ1Ô·ݵÄÒ»±¶£¬ £¬£¬£¬£¬£¬£¬£¬´ïµ½ÁË25ÒÚ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-says-it-blocked-21-billion-scam-calls-this-year/


Dell×îÐÂBIOS¸üе¼Ö¶à¿îÍÆËã»úÐͺųÊÏÔìô¶¯ÎÊÌâ


Dell×îÐÂBIOS¸üе¼Ö¶à¿îÍÆËã»úÐͺųÊÏÔìô¶¯ÎÊÌâ.png


¾Ý±¨Â·£¬ £¬£¬£¬£¬£¬£¬£¬×î½ü°ä²¼µÄDell BIOS¸üе¼Ö¶à¿î±Ê¼Ç±¾µçÄÔºĮ́ʽ»ú³öÏÖÑϳÁµÄÆô¶¯ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÐͺÅÔ̺¬Dell Latitude±Ê¼Ç±¾µçÄÔ£¨5320ºÍ5520£©£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Dell Inspiron 5680 ºÍAlienware Aurora R8̨ʽ»ú¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓû§³Æµ±ËûÃÇÆô¶¯É豸ʱ£¬ £¬£¬£¬£¬£¬£¬£¬»áÖ±½Ó½øÈëÀ¶ÆÁ²¢Ôٴιعء£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚDell°ä²¼½â¾ö¹æ»®Ö®Ç°£¬ £¬£¬£¬£¬£¬£¬£¬×îµ¥Ò»µÄ½¨¸´²½ÖèÊǽµµ½ÒÔǰµÄ¹Ì¼þ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/new-dell-bios-updates-cause-laptops-and-desktops-not-to-boot/