×êÑÐÍŶÓÅû¶TelegramµÄ¼ÓÃܺÍ̸ÖеÄ4¸ö°²È«·ì϶£»ZecOpsÅû¶iPhone WiFi·þÎñÖеĿªÊͺóʹÓ÷ì϶

°ä²¼¹¦·ò 2021-07-20
1.×êÑÐÍŶÓÅû¶TelegramµÄ¼ÓÃܺÍ̸ÖеÄ4¸ö°²È«·ì϶


1.jpg


×êÑÐÍŶÓÅû¶ÁËTelegramµÄ¼ÓÃܺÍ̸ÖеÄ4¸ö°²È«·ì϶¡£TelegramÒÀÀµÓÚ×Ô¼ºµÄMTProto¼ÓÃܺÍ̸ £¬¶ø²»Ê¹ÓÃÏñTransport Layer SecurityÕâÑù¸ü¿í·ºµÄºÍ̸¡£×êÑÐÈËÔ±½«·¢ÏÖµÄ×îÑϳÁµÄ·ì϶³ÆÖ®Îª¡°crime pizza¡± £¬¹¥»÷ÕßÀûÓø÷ì϶Äܹ»µÈÏеØÅú¸Ä´Ó¿Í»§¶Ëµ½ÔÆ·þÎñÆ÷µÄÐÂÎÅÐòÁС£´Ë±í £¬×êÑÐÈËÔ±»¹ÑÝʾÁ˹¥»÷ÕßÈôºÎ¶Ô¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄ³õʼÃÜÔ¿ºÍ̸ÌáÒéÖÐÑëÈ˹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://ethz.ch/en/news-and-events/eth-news/news/2021/07/four-cryptographic-vulnerabilities-in-telegram.html


2.ZecOpsÅû¶iPhone WiFi·þÎñÖеĿªÊͺóʹÓ÷ì϶


2.jpg


ZecOpsÅû¶ÁËiPhone WiFi·þÎñÖеĿªÊͺóʹÓ÷ì϶¡£ÉϸöÔ £¬×êÑÐÈËÔ±Carl Schou·¢ÏÖµ±iPhone²ÎÓëSSIDΪ¡°%p%s%s%s%s%n¡±µÄÍøÂçºó £¬É豸»áʧȥWiFiÏνÓÄÜÁ¦¡£Ö®ºó £¬ZecOps¶Ô¸Ã·ì϶½øÐÐÁ˵÷²é £¬·¢Ïָ÷ì϶±ÈÉèÏëµÄÑϳÁµÃ¶à¡£µ±ÔÚSSIDÖÐÔö³¤¡°%@¡±·ûºÅºó £¬¹¥»÷ÕßÄܹ»ÀûÓÃWiFi·þÎñÖеıÀÀ£Ä£Ê½Ñ­»·À´Ö´ÐÐ×Ô½ç˵´úÂë £¬ÕâÄܹ»±»¹éÀàΪ¿ªÊͺóʹÓ÷ì϶¡£ZecOps³Æ £¬¸Ã·ì϶Äܹ»ÓÃÓÚÁãµã»÷¹¥»÷ÖÐ £¬Ö»Ðè´´½¨Ò»¸ö¶ñÒâWiFiÃû³Æ £¬¶øºóÆÚ´ý×ó½üµÄÓû§Ïνӵ½Ëü¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/that-iphone-wifi-crash-bug-is-far-worse-than-initially-thought/


3.¿Æ¼¼¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖÃÃýÎóй¶70¶àÍòÎļþ


3.jpg


±£ÏÕ¼¼Êõ²Ý´´¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖÃÃýÎóй¶ÁË711000¸öÎļþ¡£¸Ã¹«Ë¾ÖØÒª¿ª·¢ºó¶Ü°ì¹«Èí¼þ £¬Îª´óÐͱ£ÏÕ¹«Ë¾·þÎñ¡£Õâ´Îй¶Á˱£ÏÕÉêÇëÈ˼°Æä¼ÒÈ˵ĵÄÓ×ÎÒºÍÒ½ÁÆÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢Ò½ÁÆÕï¶Ï¡¢·þÓõÄÒ©ÎïÒÔ¼°½¡È«Çé¿öµÄ¾ßÌåÇé¿öµÈ¡£ÕâЩй¶µÄÎļþ×îÔçÄܹ»×·Òäµ½2015Äê £¬×î½üµÄÊDZ¾ÔµÄ¡£×êÑÐÈËÔ±ÓÚ6Ô³õ·¢ÏÖÁ˸ô洢Ͱ £¬µ«»ã±¨¸ø¸Ã¹«Ë¾ºóûÓÐÊÕµ½½øÒ»²½»Ø¸´ £¬¶ø´æ´¢Í°Ò²Ò»Ïòά³ÖÊ¢¿ª×´Ì¬ £¬Ö±µ½½üÆÚ²Å¹Ø¹Ø¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2021/07/16/backnine-insurance-applications-exposed/


4.Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.it³ÆÆä¿Í»§Ó×ÎÒÐÅϢй¶


4.jpg


Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.itÈϿɽüÆÚ²úÉúÁËÊý¾Ýй¶ÊÂÎñ £¬µ«Ò»Ð©¿Í»§±§Ô¹³Æ £¬¸Ã¹«Ë¾Î´ÄÜʵʱÏòËûÃÇ´«µÝ¸ÃÎÊÌâ¡£ÔÚÉÏÖܸù«Ë¾Í¨ÖªÆä¿Í»§³Æ £¬ÔÚ4ÔÂ23ÈÕµÄÊý¾Ýй¶ÊÂÎñй¶Á˿ͻ§µÄÕ˵¥ºÍÓ×ÎÒÊý¾Ý £¬Ô̺¬ÐÕÃû¡¢Ë°Îñ´úÂë¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ· £¬ÒÔ¼°¿Í»§µÄÍøÕ¾ÃÜÂë¡£Aruba°µÊ¾ £¬ÆäÔÚ¼ì²âµ½ÈëÇÖºóÁ¢¼´×èÖ¹Á˸òÙ×÷ £¬²¢ÔÚµ÷²éºóÈ·¶¨¹¥»÷ÊÇÓÉÓÚÖÎÀí¿Í»§²úÆ·ÄÚÈݺͷþÎñÓÚÓû§Ö¸ÄϵĵÚÈý·½CMSÈí¼þÖеķì϶µ¼ÖµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/italian-hosting-firm-aruba-it-defends-data-breach-notification-delay 


5.Check Point°ä²¼2021ÄêQ2Æ·ÅÆÍøÂç´¹µö·ÖÎö»ã±¨


5.jpg


Check Point°ä²¼ÁË2021ÄêQ2Æ·ÅÆÍøÂç´¹µö·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬Óë2020ÄêQ4ºÍ2021ÄêQ1Ò»Ñù £¬MicrosoftÔٴγÉÎªÍøÂç·¸×ï·Ö×Ó×î³£Õë¶ÔµÄÆ·ÅÆ £¬45%µÄÆ·ÅÆÍøÂç´¹µö³¢ÊÔ¶¼ÓëMicrosoftÓйØ £¬±ÈQ1Ôö³¤ÁË6%¡£º½Ô˹«Ë¾DHLΪµÚ¶þ´óÖ¸±ê £¬Õ¼±ÈΪ26%¡£Æä´ÎΪÑÇÂíÑ·(11%)¡¢Bestbuy(4%)¡¢¹È¸è(3%)¡¢ÁìÓ¢(3%)¡¢Dropbox(1%)¡¢Chase(1%)¡¢Æ»¹û(%)ºÍPaypal(0.5%)¡£´Ë±í £¬¿Æ¼¼ÒÀÈ»ÊÇÆ·ÅÆÍøÂç´¹µö¹¥»÷×îÖØÒªµÄÖ¸±êÐÐÒµ £¬Æä´ÎÊÇÔËÊäºÍÁãÊÛÐÐÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/07/15/brand-phishing-report-q2-2021-microsoft-continues-reign/


6.Zscaler°ä²¼ÓÐ¹ØÆóÒµÎïÁªÍø°²È«µÄ·ÖÎö»ã±¨


6.jpg


ÍøÂ簲ȫ¹«Ë¾Zscaler°ä²¼ÁËÓÐ¹ØÆóÒµÎïÁªÍø°²È«µÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨Ö¸³ö £¬Õë¶ÔÎïÁªÍøÉ豸µÄÍøÂç¹¥»÷±ÈÈ¥Äêͬ±ÈÔö³¤ÁË700%¡£×êÑÐÈËÔ±ÔÚ18000̨Ö÷»úÉÏ·¢ÏÖÁË900¸ö·ÖÆçµÄpayload £¬ÔÚ70¶à¸ö·ÖÆçÔì×÷É̵ÄÉ豸ÉÏ·¢ÏÖÁ˶ñÒâÈí¼þ¡£ÆäÖÐMirai(Õ¼±È34.1%)ºÍGafgyt(63.1%)ÎªÖØÒªµÄpayload £¬Gafgyt½öÕ¼ËùÓй¥»÷µÄ5% £¬¶øMiraiÕ¼76%¡£´Ë±í £¬Ö»ÓÐ24%µÄÎïÁªÍøÉ豸ÒÔ¼ÓÃÜ·½Ê½´«ÊäÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://info.zscaler.com/resources-reports-threatlabz-iot-2021