文章总结: 本周蓝军技术推送汇总了多个网络安全领域的最新工具和漏洞分析,包括Web安全中的FortiWeb认证绕过漏洞和AngularCSP防御XSS攻击,内网渗透工具impacket-jump,终端对抗系列工具如SAMDump和Ryujin,以及Chromev8漏洞和tokio-tar库路径遍历漏洞分析。同时介绍了AI在安全领域的应用,如god-eye子域名枚举工具和Forta后渗透应用,为安全从业者提供了实用的技术资源和参考。
综合评分: 85
文章分类: 漏洞分析,WEB安全,内网渗透,终端对抗,AI安全
每周蓝军技术推送(2025.11.15-11.21)
原创
天元实验室
M01N Team
2025年11月21日 18:01
北京
Web安全
CVE-2025-64446:Fortinet FortiWeb认证绕过漏洞分析
https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/
Angular Auto-CSP自动生成内容安全策略配置,防御XSS攻击
https://bughunters.google.com/blog/5457130561798144/effortless-web-security-secure-by-design-in-the-wild
内网渗透
impacket-jump:基于Impacket的横向移动工具
https://github.com/MaorSabag/impacket-jump
终端对抗
SAMDump:使用VSS和NTAPI提取SAM和SYSTEM文件的工具
https://github.com/ricardojoserf/SAMDump
Ryujin:Windows PE文件混淆保护工具
https://github.com/keowu/Ryujin
Regstoration:Rust实现的注册表覆盖工具,演示RegRestoreKey技术
https://github.com/preludeorg/Regstoration
RegPersist:BOF实现的多种注册表持久化方法
https://github.com/leftp/RegPersist
GoDefender:Windows平台AntiVM和反调试检测包
https://github.com/EvilBytecode/GoDefender
CobaltStrike 4.12发布,引入UDC2自定义命令控制、新进程注入技术及MCP支持
漏洞相关
CVE-2025-6554:Chrome v8 the_hole 漏洞分析
https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html
Astral-tokio-tar库路径遍历漏洞,允许任意文件写入
https://github.com/google/security-research/security/advisories/GHSA-9p78-p5g6-gcj8
人工智能和安全
god-eye:AI赋能的子域名枚举与分析工具
https://github.com/Vyntral/god-eye
Forta:人工智能在后渗透的应用
AWS re:Invent 2025安全会议指南,涵盖AI安全防护和红队测试等主题
https://aws.amazon.com/blogs/security/aws-reinvent-2025-your-guide-to-security-sessions-across-four-transformative-themes/
NCC Group对Google Private AI Compute系统的安全架构与组件评估报告
https://www.nccgroup.com/research-blog/public-report-google-private-ai-compute-review/
使用Promptfoo复现Claude Code攻击,展示AI安全测试方法
https://www.promptfoo.dev/blog/claude-code-attack/
Google发布Gemini 3 AI模型,增强推理和多模态能力
https://blog.google/products/gemini/gemini-3/
其他
Hex-Rays推出IDA Pro命令行管理工具HCLI
https://hex-rays.com/blog/introducing-hcli
heisenberg-ssc-health-check:GitHub仓库依赖安全漏洞与供应链健康风险分析工具
https://github.com/AppOmni-Labs/heisenberg-ssc-health-check
MAD-CAT:数据库数据损坏攻击工具,支持单目标和批量攻击
https://github.com/karlvbiron/MAD-CAT
分析密钥扫描工具漏报问题及改进方法
https://semgrep.dev/blog/2025/secrets-story-and-prefixed-secrets/
威胁检测质量保证自动化工具及KQL测试实现
https://medium.com/@BlakeHensleyy/automation-for-threat-detection-quality-assurance-4a7d9acbcc4e
比较威胁狩猎与威胁情报的区别与互补关系
https://www.recordedfuture.com/blog/threat-hunting-vs-threat-intelligence
M01N Team公众号
聚焦高级攻防对抗热点技术
绿盟科技蓝军技术研究战队
官方攻防交流群
网络安全一手资讯
攻防技术答疑解惑
扫码加好友即可拉群
往期推荐
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:M01N Team 天元实验室《每周蓝军技术推送(2025.11.15-11.21)》