Ñо¿ÍŶÓÅû¶TelegramµÄ¼ÓÃÜÐÒéÖеÄ4¸öÄþ¾²Â©¶´£»ZecOpsÅû¶iPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´
Ðû²¼Ê±¼ä 2021-07-20Ñо¿ÍŶÓÅû¶ÁËTelegramµÄ¼ÓÃÜÐÒéÖеÄ4¸öÄþ¾²Â©¶´¡£TelegramÒÀÀµÓÚ×Ô¼ºµÄMTProto¼ÓÃÜÐÒ飬¶ø²»Ê¹ÓÃÏñTransport Layer SecurityÕâÑù¸ü¹ã·ºµÄÐÒé¡£Ñо¿ÈËÔ±½«·¢ÏÖµÄ×îÑÏÖØµÄ©¶´³ÆÖ®Îª¡°crime pizza¡±£¬¹¥»÷ÕßÀûÓøÃ©¶´¿ÉÒÔÇáÒ×µØÐ޸Ĵӿͻ§¶Ëµ½ÔÆ·þÎñÆ÷µÄÏûÏ¢ÐòÁС£´ËÍ⣬Ñо¿ÈËÔ±»¹ÑÝʾÁ˹¥»÷ÕßÈçºÎ¶Ô¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄ³õʼÃÜÔ¿ÐÒéÌᳫÖмäÈ˹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://ethz.ch/en/news-and-events/eth-news/news/2021/07/four-cryptographic-vulnerabilities-in-telegram.html
2.ZecOpsÅû¶iPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´
ZecOpsÅû¶ÁËiPhone WiFi·þÎñÖеÄÊͷźóʹÓé¶´¡£ÉϸöÔ£¬Ñо¿ÈËÔ±Carl Schou·¢ÏÖµ±iPhone¼ÓÈëSSIDΪ¡°%p%s%s%s%s%n¡±µÄÍøÂçºó£¬É豸»áʧȥWiFiÁ¬½ÓÄÜÁ¦¡£Ö®ºó£¬ZecOps¶Ô¸Ã©¶´½øÐÐÁËÊӲ죬·¢Ïָé¶´±ÈÏëÏóµÄÑÏÖØµÃ¶à¡£µ±ÔÚSSIDÖÐÌí¼Ó¡°%@¡±·ûºÅºó£¬¹¥»÷Õß¿ÉÒÔÀûÓÃWiFi·þÎñÖеÄÍß½âģʽѻ·À´Ö´ÐÐ×Ô½ç˵´úÂ룬Õâ¿ÉÒÔ±»¹éÀàΪÊͷźóʹÓé¶´¡£ZecOps³Æ£¬¸Ã©¶´¿ÉÒÔÓÃÓÚÁãµã»÷¹¥»÷ÖУ¬Ö»Ðè´´½¨Ò»¸ö¶ñÒâWiFiÃû³Æ£¬È»ºóÆÚ´ýËÄÖܵÄÓû§Á¬½Óµ½Ëü¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/that-iphone-wifi-crash-bug-is-far-worse-than-initially-thought/
3.¿Æ¼¼¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖôíÎóй¶70¶àÍòÎļþ
±£ÏÕ¼¼Êõ³õ´´¹«Ë¾BackNineÔÆ·þÎñÆ÷ÅäÖôíÎóй¶ÁË711000¸öÎļþ¡£¸Ã¹«Ë¾Ö÷Òª¿ª·¢ºǫ́°ì¹«Èí¼þ£¬Îª´óÐͱ£ÏÕ¹«Ë¾·þÎñ¡£´Ë´Îй¶Á˱£ÏÕÉêÇëÈ˼°Æä¼ÒÈ˵ĵĸöÈ˺ÍÒ½ÁÆÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢Ò½ÁÆÕï¶Ï¡¢·þÓõÄÒ©ÎïÒÔ¼°½¡¿µ×´¿öµÄÏêϸÇé¿öµÈ¡£ÕâЩй¶µÄÎļþ×îÔç¿ÉÒÔ×·Ëݵ½2015Ä꣬×î½üµÄÊDZ¾Ôµġ£Ñо¿ÈËÔ±ÓÚ6Ô³õ·¢ÏÖÁ˸ô洢Ͱ£¬µ«³ÂË߸ø¸Ã¹«Ë¾ºóûÓÐÊÕµ½½øÒ»²½»Ø¸´£¬¶ø´æ´¢Í°Ò²Ò»Ö±±£³Ö¿ª·Å״̬£¬Ö±µ½½üÆÚ²Å¹Ø±Õ¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2021/07/16/backnine-insurance-applications-exposed/
4.Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.it³ÆÆä¿Í»§¸öÈËÐÅϢй¶
Òâ´óÀûÍøÂçÍйܹ«Ë¾Aruba.itÈϿɽüÆÚ·¢ÉúÁËÊý¾Ýй¶Ê¼þ£¬µ«Ò»Ð©¿Í»§Ëß¿à³Æ£¬¸Ã¹«Ë¾Î´Äܼ°Ê±ÏòËûÃÇͨ±¨¸ÃÎÊÌâ¡£ÔÚÉÏÖܸù«Ë¾Í¨ÖªÆä¿Í»§³Æ£¬ÔÚ4ÔÂ23ÈÕµÄÊý¾Ýй¶Ê¼þй¶Á˿ͻ§µÄÕ˵¥ºÍ¸öÈËÊý¾Ý£¬°üÂÞÐÕÃû¡¢Ë°Îñ´úÂë¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·£¬ÒÔ¼°¿Í»§µÄÍøÕ¾ÃÜÂë¡£ArubaÌåÏÖ£¬ÆäÔÚ¼ì²âµ½ÈëÇÖºóÁ¢¼´×èÖ¹Á˸òÙ×÷£¬²¢ÔÚÊÓ²ìºóÈ·¶¨¹¥»÷ÊÇÓÉÓÚ¹ÜÀí¿Í»§²úÎïÄÚÈݺͷþÎñÓÚÓû§Ö¸ÄϵĵÚÈý·½CMSÈí¼þÖеÄ©¶´µ¼Öµġ£
ÔÎÄÁ´½Ó£º
https://portswigger.net/daily-swig/italian-hosting-firm-aruba-it-defends-data-breach-notification-delay
5.Check PointÐû²¼2021ÄêQ2Æ·ÅÆÍøÂçµöÓã·ÖÎö³ÂËß
Check PointÐû²¼ÁË2021ÄêQ2Æ·ÅÆÍøÂçµöÓã·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Óë2020ÄêQ4ºÍ2021ÄêQ1Ò»Ñù£¬MicrosoftÔٴγÉÎªÍøÂç·¸×ï·Ö×Ó×î³£Õë¶ÔµÄÆ·ÅÆ£¬45%µÄÆ·ÅÆÍøÂçµöÓãʵÑé¶¼ÓëMicrosoftÓйأ¬±ÈQ1Ôö¼ÓÁË6%¡£º½Ô˹«Ë¾DHLΪµÚ¶þ´óÄ¿±ê£¬Õ¼±ÈΪ26%¡£Æä´ÎΪÑÇÂíÑ·(11%)¡¢Bestbuy(4%)¡¢¹È¸è(3%)¡¢ÁìÓ¢(3%)¡¢Dropbox(1%)¡¢Chase(1%)¡¢Æ»¹û(%)ºÍPaypal(0.5%)¡£´ËÍ⣬¿Æ¼¼ÈÔÈ»ÊÇÆ·ÅÆÍøÂçµöÓã¹¥»÷×îÖ÷ÒªµÄÄ¿±êÐÐÒµ£¬Æä´ÎÊÇÔËÊäºÍÁãÊÛÐÐÒµ¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/07/15/brand-phishing-report-q2-2021-microsoft-continues-reign/
6.ZscalerÐû²¼ÓÐ¹ØÆóÒµÎïÁªÍøÄþ¾²µÄ·ÖÎö³ÂËß
ÍøÂçÄþ¾²¹«Ë¾ZscalerÐû²¼ÁËÓÐ¹ØÆóÒµÎïÁªÍøÄþ¾²µÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÖ¸³ö£¬Õë¶ÔÎïÁªÍøÉ豸µÄÍøÂç¹¥»÷±ÈÈ¥Äêͬ±ÈÔö¼ÓÁË700%¡£Ñо¿ÈËÔ±ÔÚ18000̨Ö÷»úÉÏ·¢ÏÖÁË900¸ö²îÒìµÄpayload£¬ÔÚ70¶à¸ö²îÒìÖÆÔìÉ̵ÄÉ豸ÉÏ·¢ÏÖÁ˶ñÒâÈí¼þ¡£ÆäÖÐMirai(Õ¼±È34.1%)ºÍGafgyt(63.1%)ΪÖ÷ÒªµÄpayload£¬Gafgyt½öÕ¼ËùÓй¥»÷µÄ5%£¬¶øMiraiÕ¼76%¡£´ËÍ⣬ֻÓÐ24%µÄÎïÁªÍøÉ豸ÒÔ¼ÓÃÜ·½Ê½´«ÊäÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://info.zscaler.com/resources-reports-threatlabz-iot-2021