Ñо¿ÍŶÓÅû¶TelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÇå¾²Îó²î£» £»£»£»£»£»ZecOpsÅû¶iPhone WiFiЧÀÍÖеÄÊͷźóʹÓÃÎó²î

Ðû²¼Ê±¼ä 2021-07-20
1.Ñо¿ÍŶÓÅû¶TelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÇå¾²Îó²î


1.jpg


Ñо¿ÍŶÓÅû¶ÁËTelegramµÄ¼ÓÃÜЭÒéÖеÄ4¸öÇå¾²Îó²î¡£¡£¡£¡£¡£TelegramÒÀÀµÓÚ×Ô¼ºµÄMTProto¼ÓÃÜЭÒ飬 £¬£¬£¬£¬£¬¶ø²»Ê¹ÓÃÏñTransport Layer SecurityÕâÑù¸üÆÕ±éµÄЭÒé¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½«·¢Ã÷µÄ×îÑÏÖØµÄÎó²î³ÆÖ®Îª¡°crime pizza¡±£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔÈÝÒ×µØÐ޸Ĵӿͻ§¶Ëµ½ÔÆÐ§ÀÍÆ÷µÄÐÂÎÅÐòÁС£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÑÝʾÁ˹¥»÷ÕßÔõÑù¶Ô¿Í»§¶ËºÍЧÀÍÆ÷Ö®¼äµÄ³õʼÃÜԿЭÒéÌᳫÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ethz.ch/en/news-and-events/eth-news/news/2021/07/four-cryptographic-vulnerabilities-in-telegram.html


2.ZecOpsÅû¶iPhone WiFiЧÀÍÖеÄÊͷźóʹÓÃÎó²î


2.jpg


ZecOpsÅû¶ÁËiPhone WiFiЧÀÍÖеÄÊͷźóʹÓÃÎó²î¡£¡£¡£¡£¡£ÉϸöÔ£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±Carl Schou·¢Ã÷µ±iPhone¼ÓÈëSSIDΪ¡°%p%s%s%s%s%n¡±µÄÍøÂçºó£¬ £¬£¬£¬£¬£¬×°±¸»áʧȥWiFiÅþÁ¬ÄÜÁ¦¡£¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬ZecOps¶Ô¸ÃÎó²î¾ÙÐÐÁËÊӲ죬 £¬£¬£¬£¬£¬·¢Ã÷¸ÃÎó²î±ÈÏëÏóµÄÑÏÖØµÃ¶à¡£¡£¡£¡£¡£µ±ÔÚSSIDÖÐÌí¼Ó¡°%@¡±·ûºÅºó£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃWiFiЧÀÍÖеÄÍß½âģʽѭ»·À´Ö´ÐÐ×Ô½ç˵´úÂ룬 £¬£¬£¬£¬£¬Õâ¿ÉÒÔ±»¹éÀàΪÊͷźóʹÓÃÎó²î¡£¡£¡£¡£¡£ZecOps³Æ£¬ £¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÒÔÓÃÓÚÁãµã»÷¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬Ö»Ð轨ÉèÒ»¸ö¶ñÒâWiFiÃû³Æ£¬ £¬£¬£¬£¬£¬È»ºóÆÚ´ýÖÜΧµÄÓû§ÅþÁ¬µ½Ëü¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/that-iphone-wifi-crash-bug-is-far-worse-than-initially-thought/


3.¿Æ¼¼¹«Ë¾BackNineÔÆÐ§ÀÍÆ÷ÉèÖùýʧй¶70¶àÍòÎļþ


3.jpg


°ü¹ÜÊÖÒÕÊ×´´¹«Ë¾BackNineÔÆÐ§ÀÍÆ÷ÉèÖùýʧй¶ÁË711000¸öÎļþ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö÷Òª¿ª·¢ºǫ́°ì¹«Èí¼þ£¬ £¬£¬£¬£¬£¬Îª´óÐͰü¹Ü¹«Ë¾Ð§ÀÍ¡£¡£¡£¡£¡£´Ë´Îй¶Á˰ü¹ÜÉêÇëÈ˼°Æä¼ÒÈ˵ĵÄСÎÒ˽¼ÒºÍÒ½ÁÆÐÅÏ¢£¬ £¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµãºÍµç»°ºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢Ò½ÁÆÕï¶Ï¡¢·þÓõÄÒ©ÎïÒÔ¼°¿µ½¡×´Ì¬µÄÏêϸÇéÐεȡ£¡£¡£¡£¡£ÕâЩй¶µÄÎļþ×îÔç¿ÉÒÔ×·Ëݵ½2015Ä꣬ £¬£¬£¬£¬£¬×î½üµÄÊDZ¾Ôµġ£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ6Ô³õ·¢Ã÷Á˸ô洢Ͱ£¬ £¬£¬£¬£¬£¬µ«±¨¸æ¸ø¸Ã¹«Ë¾ºóûÓÐÊÕµ½½øÒ»²½»Ø¸´£¬ £¬£¬£¬£¬£¬¶ø´æ´¢Í°Ò²Ò»Ö±¼á³Ö¿ª·Å״̬£¬ £¬£¬£¬£¬£¬Ö±µ½½üÆÚ²Å¹Ø±Õ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2021/07/16/backnine-insurance-applications-exposed/


4.Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.it³ÆÆä¿Í»§Ð¡ÎÒ˽¼ÒÐÅϢй¶


4.jpg


Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.itÈϿɽüÆÚ±¬·¢ÁËÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬£¬µ«Ò»Ð©¿Í»§Ëß¿à³Æ£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾Î´ÄÜʵʱÏòËûÃÇת´ï¸ÃÎÊÌâ¡£¡£¡£¡£¡£ÔÚÉÏÖܸù«Ë¾Í¨ÖªÆä¿Í»§³Æ£¬ £¬£¬£¬£¬£¬ÔÚ4ÔÂ23ÈÕµÄÊý¾Ýй¶ÊÂÎñй¶Á˿ͻ§µÄÕ˵¥ºÍСÎÒ˽¼ÒÊý¾Ý£¬ £¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢Ë°Îñ´úÂë¡¢ÎïÀíµØµã¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØµã£¬ £¬£¬£¬£¬£¬ÒÔ¼°¿Í»§µÄÍøÕ¾ÃÜÂë¡£¡£¡£¡£¡£ArubaÌåÏÖ£¬ £¬£¬£¬£¬£¬ÆäÔÚ¼ì²âµ½ÈëÇÖºóÁ¬Ã¦×èÖ¹Á˸òÙ×÷£¬ £¬£¬£¬£¬£¬²¢ÔÚÊÓ²ìºóÈ·¶¨¹¥»÷ÊÇÓÉÓÚÖÎÀí¿Í»§²úÆ·ÄÚÈݺÍЧÀÍÓÚÓû§Ö¸ÄϵĵÚÈý·½CMSÈí¼þÖеÄÎó²îµ¼Öµġ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/italian-hosting-firm-aruba-it-defends-data-breach-notification-delay 


5.Check PointÐû²¼2021ÄêQ2Æ·ÅÆÍøÂç´¹ÂÚÆÊÎö±¨¸æ


5.jpg


Check PointÐû²¼ÁË2021ÄêQ2Æ·ÅÆÍøÂç´¹ÂÚÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬Óë2020ÄêQ4ºÍ2021ÄêQ1Ò»Ñù£¬ £¬£¬£¬£¬£¬MicrosoftÔٴγÉÎªÍøÂç·¸·¨·Ö×Ó×î³£Õë¶ÔµÄÆ·ÅÆ£¬ £¬£¬£¬£¬£¬45%µÄÆ·ÅÆÍøÂç´¹ÂÚʵÑé¶¼ÓëMicrosoftÓйأ¬ £¬£¬£¬£¬£¬±ÈQ1ÔöÌíÁË6%¡£¡£¡£¡£¡£º½Ô˹«Ë¾DHLΪµÚ¶þ´óÄ¿µÄ£¬ £¬£¬£¬£¬£¬Õ¼±ÈΪ26%¡£¡£¡£¡£¡£Æä´ÎΪÑÇÂíÑ·(11%)¡¢Bestbuy(4%)¡¢¹È¸è(3%)¡¢ÁìÓ¢(3%)¡¢Dropbox(1%)¡¢Chase(1%)¡¢Æ»¹û(%)ºÍPaypal(0.5%)¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬¿Æ¼¼ÈÔÈ»ÊÇÆ·ÅÆÍøÂç´¹ÂÚ¹¥»÷×îÖ÷ÒªµÄÄ¿µÄÐÐÒµ£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇÔËÊäºÍÁãÊÛÐÐÒµ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/07/15/brand-phishing-report-q2-2021-microsoft-continues-reign/


6.ZscalerÐû²¼ÓÐ¹ØÆóÒµÎïÁªÍøÇå¾²µÄÆÊÎö±¨¸æ


6.jpg


ÍøÂçÇå¾²¹«Ë¾ZscalerÐû²¼ÁËÓÐ¹ØÆóÒµÎïÁªÍøÇå¾²µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬Õë¶ÔÎïÁªÍø×°±¸µÄÍøÂç¹¥»÷±ÈÈ¥Äêͬ±ÈÔöÌíÁË700%¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ18000̨Ö÷»úÉÏ·¢Ã÷ÁË900¸ö²î±ðµÄpayload£¬ £¬£¬£¬£¬£¬ÔÚ70¶à¸ö²î±ðÖÆÔìÉ̵Ä×°±¸ÉÏ·¢Ã÷Á˶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÆäÖÐMirai(Õ¼±È34.1%)ºÍGafgyt(63.1%)ΪÖ÷ÒªµÄpayload£¬ £¬£¬£¬£¬£¬Gafgyt½öÕ¼ËùÓй¥»÷µÄ5%£¬ £¬£¬£¬£¬£¬¶øMiraiÕ¼76%¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬Ö»ÓÐ24%µÄÎïÁªÍø×°±¸ÒÔ¼ÓÃÜ·½·¨´«ÊäÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://info.zscaler.com/resources-reports-threatlabz-iot-2021