Ñо¿ÍŶÓÅû¶TelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÄþ¾²Â©¶´ £»ZecOpsÅû¶iPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´

Ðû²¼Ê±¼ä 2021-07-20
1.Ñо¿ÍŶÓÅû¶TelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÄþ¾²Â©¶´


1.jpg


Ñо¿ÍŶÓÅû¶ÁËTelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÄþ¾²Â©¶´¡£TelegramÒÀÀµÓÚ×Ô¼ºµÄMTProto¼ÓÃÜЭÒé £¬¶ø²»Ê¹ÓÃÏñTransport Layer SecurityÕâÑù¸ü¹ã·ºµÄЭÒé¡£Ñо¿ÈËÔ±½«·¢ÏÖµÄ×îÑÏÖØµÄ©¶´³ÆÖ®Îª¡°crime pizza¡± £¬¹¥»÷ÕßÀûÓøÃ©¶´¿ÉÒÔÇáÒ×µØÐ޸Ĵӿͻ§¶Ëµ½ÔÆ·þÎñÆ÷µÄÏûÏ¢ÐòÁС£´ËÍâ £¬Ñо¿ÈËÔ±»¹ÑÝʾÁ˹¥»÷ÕßÈçºÎ¶Ô¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄ³õʼÃÜԿЭÒéÌᳫÖмäÈ˹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://ethz.ch/en/news-and-events/eth-news/news/2021/07/four-cryptographic-vulnerabilities-in-telegram.html


2.ZecOpsÅû¶iPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´


2.jpg


ZecOpsÅû¶ÁËiPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´¡£ÉϸöÔ £¬Ñо¿ÈËÔ±Carl Schou·¢ÏÖµ±iPhone¼ÓÈëSSIDΪ¡°%p%s%s%s%s%n¡±µÄÍøÂçºó £¬É豸»áʧȥWiFiÁ¬½ÓÄÜÁ¦¡£Ö®ºó £¬ZecOps¶Ô¸Ã©¶´½øÐÐÁËÊÓ²ì £¬·¢Ïָé¶´±ÈÏëÏóµÄÑÏÖØµÃ¶à¡£µ±ÔÚSSIDÖÐÌí¼Ó¡°%@¡±·ûºÅºó £¬¹¥»÷Õß¿ÉÒÔÀûÓÃWiFi·þÎñÖеÄÍß½âģʽѭ»·À´Ö´ÐÐ×Ô½ç˵´úÂë £¬Õâ¿ÉÒÔ±»¹éÀàΪÊͷźóʹÓé¶´¡£ZecOps³Æ £¬¸Ã©¶´¿ÉÒÔÓÃÓÚÁãµã»÷¹¥»÷ÖÐ £¬Ö»Ðè´´½¨Ò»¸ö¶ñÒâWiFiÃû³Æ £¬È»ºóÆÚ´ýËÄÖܵÄÓû§Á¬½Óµ½Ëü¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/that-iphone-wifi-crash-bug-is-far-worse-than-initially-thought/


3.¿Æ¼¼¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖôíÎóй¶70¶àÍòÎļþ


3.jpg


±£ÏÕ¼¼Êõ³õ´´¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖôíÎóй¶ÁË711000¸öÎļþ¡£¸Ã¹«Ë¾Ö÷Òª¿ª·¢ºǫ́°ì¹«Èí¼þ £¬Îª´óÐͱ£ÏÕ¹«Ë¾·þÎñ¡£´Ë´Îй¶Á˱£ÏÕÉêÇëÈ˼°Æä¼ÒÈ˵ĵĸöÈ˺ÍÒ½ÁÆÐÅÏ¢ £¬°üÂÞÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢Ò½ÁÆÕï¶Ï¡¢·þÓõÄÒ©ÎïÒÔ¼°½¡¿µ×´¿öµÄÏêϸÇé¿öµÈ¡£ÕâЩй¶µÄÎļþ×îÔç¿ÉÒÔ×·Ëݵ½2015Äê £¬×î½üµÄÊDZ¾Ôµġ£Ñо¿ÈËÔ±ÓÚ6Ô³õ·¢ÏÖÁ˸ô洢Ͱ £¬µ«³ÂË߸ø¸Ã¹«Ë¾ºóûÓÐÊÕµ½½øÒ»²½»Ø¸´ £¬¶ø´æ´¢Í°Ò²Ò»Ö±±£³Ö¿ª·Å״̬ £¬Ö±µ½½üÆÚ²Å¹Ø±Õ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2021/07/16/backnine-insurance-applications-exposed/


4.Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.it³ÆÆä¿Í»§¸öÈËÐÅϢй¶


4.jpg


Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.itÈϿɽüÆÚ·¢ÉúÁËÊý¾Ýй¶Ê¼þ £¬µ«Ò»Ð©¿Í»§Ëß¿à³Æ £¬¸Ã¹«Ë¾Î´Äܼ°Ê±ÏòËûÃÇͨ±¨¸ÃÎÊÌâ¡£ÔÚÉÏÖܸù«Ë¾Í¨ÖªÆä¿Í»§³Æ £¬ÔÚ4ÔÂ23ÈÕµÄÊý¾Ýй¶Ê¼þй¶Á˿ͻ§µÄÕ˵¥ºÍ¸öÈËÊý¾Ý £¬°üÂÞÐÕÃû¡¢Ë°Îñ´úÂë¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ· £¬ÒÔ¼°¿Í»§µÄÍøÕ¾ÃÜÂë¡£ArubaÌåÏÖ £¬ÆäÔÚ¼ì²âµ½ÈëÇÖºóÁ¢¼´×èÖ¹Á˸òÙ×÷ £¬²¢ÔÚÊÓ²ìºóÈ·¶¨¹¥»÷ÊÇÓÉÓÚ¹ÜÀí¿Í»§²úÎïÄÚÈݺͷþÎñÓÚÓû§Ö¸ÄϵĵÚÈý·½CMSÈí¼þÖеÄ©¶´µ¼Öµġ£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/italian-hosting-firm-aruba-it-defends-data-breach-notification-delay 


5.Check PointÐû²¼2021ÄêQ2Æ·ÅÆÍøÂçµöÓã·ÖÎö³ÂËß


5.jpg


Check PointÐû²¼ÁË2021ÄêQ2Æ·ÅÆÍøÂçµöÓã·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬Óë2020ÄêQ4ºÍ2021ÄêQ1Ò»Ñù £¬MicrosoftÔٴγÉÎªÍøÂç·¸×ï·Ö×Ó×î³£Õë¶ÔµÄÆ·ÅÆ £¬45%µÄÆ·ÅÆÍøÂçµöÓãʵÑé¶¼ÓëMicrosoftÓйØ £¬±ÈQ1Ôö¼ÓÁË6%¡£º½Ô˹«Ë¾DHLΪµÚ¶þ´óÄ¿±ê £¬Õ¼±ÈΪ26%¡£Æä´ÎΪÑÇÂíÑ·(11%)¡¢Bestbuy(4%)¡¢¹È¸è(3%)¡¢ÁìÓ¢(3%)¡¢Dropbox(1%)¡¢Chase(1%)¡¢Æ»¹û(%)ºÍPaypal(0.5%)¡£´ËÍâ £¬¿Æ¼¼ÈÔÈ»ÊÇÆ·ÅÆÍøÂçµöÓã¹¥»÷×îÖ÷ÒªµÄÄ¿±êÐÐÒµ £¬Æä´ÎÊÇÔËÊäºÍÁãÊÛÐÐÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/07/15/brand-phishing-report-q2-2021-microsoft-continues-reign/


6.ZscalerÐû²¼ÓÐ¹ØÆóÒµÎïÁªÍøÄþ¾²µÄ·ÖÎö³ÂËß


6.jpg


ÍøÂçÄþ¾²¹«Ë¾ZscalerÐû²¼ÁËÓÐ¹ØÆóÒµÎïÁªÍøÄþ¾²µÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÖ¸³ö £¬Õë¶ÔÎïÁªÍøÉ豸µÄÍøÂç¹¥»÷±ÈÈ¥Äêͬ±ÈÔö¼ÓÁË700%¡£Ñо¿ÈËÔ±ÔÚ18000̨Ö÷»úÉÏ·¢ÏÖÁË900¸ö²îÒìµÄpayload £¬ÔÚ70¶à¸ö²îÒìÖÆÔìÉ̵ÄÉ豸ÉÏ·¢ÏÖÁ˶ñÒâÈí¼þ¡£ÆäÖÐMirai(Õ¼±È34.1%)ºÍGafgyt(63.1%)ΪÖ÷ÒªµÄpayload £¬Gafgyt½öÕ¼ËùÓй¥»÷µÄ5% £¬¶øMiraiÕ¼76%¡£´ËÍâ £¬Ö»ÓÐ24%µÄÎïÁªÍøÉ豸ÒÔ¼ÓÃÜ·½Ê½´«ÊäÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://info.zscaler.com/resources-reports-threatlabz-iot-2021