Ñо¿ÈËÔ±ÑÝʾÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú£»GoogleÔÚÂéÊ¡¾ÓÃñ°²×¿ÊÖ»úÇ¿ÖÆ°²×°COVID-19¸ú×ÙÓ¦ÓÃ
Ðû²¼Ê±¼ä 2021-06-211.Ñо¿ÈËÔ±ÑÝʾÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú
Ñо¿ÈËÔ±Carl SchouÑÝʾÁËÈçºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú¡£Carl SchouÔÚÁ¬½Ó¸öÈËWiFiÈȵ㡰%p%s%s%s%s%n¡±Ê±£¬·¢ÏÖËûiPhoneµÄWiFi¹¦Ð§±»½ûÓ㬶øÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFi¹¦Ð§£¬¼´Ê¹ËûÖØÆôÉ豸»ò¸ü¸ÄÈȵãÃû³Æ¡£Ñо¿ÈËÔ±³Æ£¬Õâ¿ÉÄÜÊÇÊäÈë½âÎöÎÊÌâµ¼Öµģ¬µ±WiFiÈȵãÃû³ÆÖдæÔÚ´øÓС°%¡±µÄ×Ö·û´®Ê±£¬iOS¿ÉÄÜ»á´íÎ󵨽«¡°%¡±ºóÃæµÄ×Öĸ½âÊÍΪ×Ö·û´®¸ñʽ˵Ã÷·û¡£»Ö¸´Wi-Fi¹¦Ð§µÄΨһҪÁìÊÇÖØÖÃiPhoneµÄÍøÂçÉèÖᣴËÍ⣬¸Ã©¶´ÊÇiPhone¶ÀÕ¼µÄ£¬ÎÞ·¨ÔÚAndroidÊÖ»úÉÏÖØÏÖ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/
2.GoogleÔÚÂéÊ¡¾ÓÃñ°²×¿ÊÖ»úÇ¿ÖÆ°²×°COVID-19¸ú×ÙÓ¦ÓÃ
ÔÚ¹ýÈ¥µÄ¼¸ÌìÀ´óÁ¿µÄÓû§³ÂËß³ÆGoogleÔÚËûÃǵݲ׿É豸ÉÏÇÄÇݲװÁËMassNotify£¬¶øÇÒÎÞ·¨Ð¶ÔØ¡£MassNotifyÊÇÂíÈøÖîÈûÖݵÄCOVID-19ÁªÏµÈ˸ú×ÙÓ¦Ó÷¨Ê½£¬ËüÔÊÐíÆôÓÃÁËCOVID-19Åû¶֪ͨ¹¦Ð§µÄAndroidÓû§½ÓÊÕ¾¯¸æ¡£²¿ÃÅÓû§ÌåÏÖÆä²¢Ã»ÓпªÆô¸Ã¹¦Ð§£¬µ«Ò²±»Ç¿Öư²×°Á˸ÃÓ¦Óã»¶øÓÐЩÓû§³ÂË߯äÕÒ²»µ½¸ÃÓ¦ÓõÄÈκÎͼ±ê£¬Òò´ËÎÞ·¨½øÐÐÐ¶ÔØ¡£Google³Æ¸ÃÓ¦Ó÷¨Ê½Ö»ÊÇÒѰ²×°µ«²¢Î´ÆôÓã¬Ö±µ½Óû§´ò¿ªCOVID-19Åû¶֪ͨ¹¦Ð§²Å»áÆôÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-force-installs-massachusetts-massnotify-android-covid-app/
3.MandiantÅû¶DarksideÕë¶Ô¼à¿ØÏµÍ³ÌṩÉ̵ũӦÁ´¹¥»÷
Fireeye MandiantÅû¶ÁËDarksideÁ¥ÊôÍÅ»ïUNC2465Õë¶Ô¼à¿ØÏµÍ³£¨CCTV£©ÌṩÉ̵ũӦÁ´¹¥»÷¡£¹¥»÷ʼÓÚ2021Äê5ÔÂ18ÈÕ£¬ÊÜÓ°Ïì×éÖ¯ÖеÄÓû§ä¯ÀÀµ½¶ñÒâÁ´½Ó²¢ÏÂÔØÁ˶ñÒâZIP£¬È»ºó°²×°ÁËһϵÁжñÒâÈí¼þ¡£Mandiant·ÖÎö³õÊ¼ÔØÌåÊÇÒ»¸öÀ´×ԺϷ¨ÍøÕ¾µÄ¶ñÒâÄþ¾²ÉãÏñÍ·PVR°²×°·¨Ê½£¬¹¥»÷Ö÷Òª·ÖΪ5¸ö½×¶Î£ºÄ¾Âí»¯°²×°·¨Ê½ÏÂÔØ¡¢Nullsoft°²×°·¨Ê½¡¢ÏÂÔØVBScriptºÍPowerShell¡¢°²×°SMOKEDHAM DropperºÍSMOKEDHAMºóÃÅ¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html
4.GriefÍÅ»ï³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute
ºÚ¿ÍÍÅ»ïGriefÉù³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute¡£GriefÓÚ6ÔÂ11ÈÕ½«¸ÃÒ½ÔºÌí¼Ó½øÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢ÔÚ6ÔÂ15ÈÕ¸üÐÂÁËÁÐ±í£¬×ª´¢ÁËÆäÇÔÈ¡µÄÆäËüÊý¾Ý¡£GriefµÄ·¢ÑÔÈËÔÚ6ÔÂ1ÈÕ½ÓÊܲɷÃʱÌåÏÖ²»»á¹¥»÷Ò½ÁÆ×éÖ¯£¬µ«ËƺõÕûÐλú¹¹²»°üÂÞÔÚÆäÖС£´Ë´Îй¶µÄÐÅÏ¢°üÂÞ2015-2020ÄêµÄÈÕ³£ÒµÎñÓöÈÎļþ¡¢Ã¿ÄêµÄËðÒæ±í¡¢ÓëPPP´û¿îºÍ´û¿î»íÃâÉêÇëÓйصÄÊý¾ÝµÈ£¬ÒÔ¼°²¡È˵Ľ¡¿µÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢½¡¿µ±£ÏÕÐÅÏ¢¡¢¼ì²âÀàÐͺÍÄ¿µÄ¡¢SSNµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/fl-grief-claims-to-have-breached-the-woodruff-institute/
5.NexusguardÐû²¼2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
NexusguardÐû²¼ÁË2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬COVID-19½«DDoS¹¥»÷ÍÆÏòÁËеĸ߶ȣº2020Äê3Ô·ÝDDoS¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤341.21%£¬Õ¼2020ÄêËùÓй¥»÷µÄ23.96%£»Q2 DDoS¹¥»÷ÊýÁ¿Õ¼¹¥»÷×ÜÁ¿µÄ38.33%£¬ÊÇ2020Äê¹¥»÷×Öеļ¾¶È¡£ÓÐȤµÄÊÇ£¬DDoS¹¥»÷ÊýÁ¿ÔÚ7Ô·ÝϽµµ½ÁË6.99%£¬ÕâÖÖϽµÇ÷ÊÆÒ»Ö±Á¬Ðøµ½12Ô¡£´ËÍ⣬´Ó3Ô¿ªÊ¼£¬Õë¶ÔÈ«Çò¸÷Ðи÷ÒµµÄÀÕË÷ºÍÀÕË÷DDoS (RDDoS) ¹¥»÷¾ùÓÐËùÔö¼Ó¡£
ÔÎÄÁ´½Ó£º
https://blog.nexusguard.com/threat-report/annual-threat-report-2020
6.NSAÐû²¼ÓйØUCÒÔ¼°IPÓïÒôºÍÊÓÆµÏµÍ³µÄÄþ¾²Ö¸ÄÏ
ÃÀ¹ú¹ú¼ÒÄþ¾²¾Ö (NSA)Ðû²¼ÁËϵͳ¹ÜÀíÔ±ÔÚ±£»¤Í³Ò»Í¨ÐÅ (UC) ÒÔ¼°IPÓïÒôºÍÊÓÆµ (VVoIP) ϵͳʱӦ×ñѵÄÄþ¾²Ö¸ÄÏ¡£UCºÍVVoIPÊÇÔÚÆóÒµ»·¾³ÖÐÓÃÓÚÖÖÖÖÄ¿µÄµÄºô½Ð´¦ÖÃϵͳ¡£¸ÃÖ¸ÄÏÌá³öÁËʹÓÃÐéÄâ¾ÖÓòÍø(VLAN) ½«ÓïÒôºÍÊÓÆµÁ÷Á¿ÓëÊý¾ÝÁ÷Á¿À뿪£»Ê¹Ó÷ÃÎÊ¿ØÖÆÁбíºÍ·ÓɹæÔòÀ´ÏÞÖÆ¿çVLAN¶ÔÉ豸µÄ·ÃÎÊ£»Ê¼ÖÕ±£³ÖÈí¼þ´¦ÓÚ×îÐÂ״̬ÒÔÔ¤·ÀUC/VVoIPÈí¼þ©¶´µÈ½¨Òé¡£
ÔÎÄÁ´½Ó£º
https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2661746/nsa-releases-guidance-on-securing-unified-communications-and-voice-and-video-ov/