̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬£¬ £¬£¬²¨¼°È«ÇòÓû§£»£»Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚ¸öÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý

Ðû²¼Ê±¼ä 2021-01-06
1.̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬£¬ £¬£¬²¨¼°È«ÇòÓû§


1.jpg


̸ÌìȺ×éSlackЧÀͱ¬·¢ÁË2021ÄêµÄÊ×´ÎÖÐÖ¹£¬£¬£¬£¬ £¬£¬²¨¼°È«ÇòÓû§¡£¡£¡£¡£¡£¡£ÐÂÄêºóµÄµÚÒ»¸öÊÂÇéÈÕ£¬£¬£¬£¬ £¬£¬ÃÀ¹ú¶«²¿Ê±¼ä1ÔÂ4ÈÕÉÏÎç10µãSlack·ºÆðÁËÖÐÖ¹£¬£¬£¬£¬ £¬£¬Ó°ÏìÁË×ÀÃæ¿Í»§¶ËºÍWeb½çÃæ£¬£¬£¬£¬ £¬£¬Óû§ÎÞ·¨ÅþÁ¬Ð§ÀÍÆ÷¡¢ÎÞ·¨·¢ËͺÍÎüÊÕÐÂÎŲ¢ÇÒÎÞ·¨¼ìË÷ƵµÀÀúÊ·¼Í¼¡£¡£¡£¡£¡£¡£×î³õ±¬·¢ÖÐֹʱSlack³ÆÕâÖ»Ó°ÏìÁËÐÂÎÅת´ï£¬£¬£¬£¬ £¬£¬µ«ËæºóSlackµÄËùÓÐЧÀ͵ͼ·ºÆðÁËÖÐÖ¹¡£¡£¡£¡£¡£¡£ÏÖÔÚSlack»Ö¸´Á˿ͻ§¶ËµÄ²¿·Ö¹¦Ð§£¬£¬£¬£¬ £¬£¬ÈçÎüÊպͷ¢ËÍÐÂÎÅ£¬£¬£¬£¬ £¬£¬µ«GoogleÈÕÀúºÍOutlookÈÕÀúµÈЧÀÍÈÔÎÞ·¨Õý³£ÊÂÇé¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/slack-suffers-its-first-massive-outage-of-2021/


2.Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý


2.png


Ñо¿Ö°Ô±Nikolai Tschacher·¢Ã÷Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý¡£¡£¡£¡£¡£¡£ReCaptchaÊÇGoogle×Ô¼ºµÄÃâ·ÑЧÀÍ£¬£¬£¬£¬ £¬£¬Ê¹ÓÃͼÏñ¡¢ÒôƵ»òÎÄÔ­À´ÑéÖ¤ÈËÃÇÊÇ·ñÔڵǼÕÊ»§¡£¡£¡£¡£¡£¡£Tschacher³Æ¹¥»÷µÄÒªÁìºÜÊǼòÆÓ£¬£¬£¬£¬ £¬£¬Ö»Ðè»ñÈ¡reCAPTCHAµÄMP3ÒôƵÎļþ£¬£¬£¬£¬ £¬£¬È»ºó½«ÆäÌá½»¸øGoogleµÄÓïÒôÎı¾API¡£¡£¡£¡£¡£¡£ÔÚÁè¼Ý97£¥µÄÇéÐÎÏ£¬£¬£¬£¬ £¬£¬Google¶¼»á·µ»Ø×¼È·µÄÃÕµ×£¬£¬£¬£¬ £¬£¬ÕâÖÖ¹¥»÷ÒªÁìÉõÖÁÊÊÓÃÓÚ×îа汾µÄreCAPTCHA v3¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/researcher-breaks-recaptcha-speech-to-text-api/162734/


3.еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß


3.png


SANS Internet Storm CenterµÄÑо¿Ö°Ô±·¢Ã÷еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß¡£¡£¡£¡£¡£¡£BSSIDΪ»ù±¾Ð§Àͼ¯±êʶ·û£¬£¬£¬£¬ £¬£¬ÊÇÓû§ÓÃÀ´Í¨¹ýWiFiÅþÁ¬µÄÎÞÏß·ÓÉÆ÷»ò½ÓÈëµãµÄMACÎïÀíµØµã¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þÕýÔÚÍøÂçÓû§µÄBSSID£¬£¬£¬£¬ £¬£¬²¢½«ÆäÓëAlexander Mylnikovά»¤µÄBSSID-geoÊý¾Ý¿â¾ÙÐнÏÁ¿£¬£¬£¬£¬ £¬£¬ÒÔÈ·¶¨Êܺ¦ÕßÓÃÀ´»á¼ûInternetµÄWiFi½ÓÈëµãµÄÎïÀíµØÀíλÖᣡ£¡£¡£¡£¡£Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬£¬ £¬£¬Ä³Ð©¹ú¼ÒºÚ¿Í¿ÉÒÔÈ·¶¨Êܺ¦ÕßÊôÓÚÌØ¶¨µÄ¹ú¼ÒºÍµØÇø£¬£¬£¬£¬ £¬£¬»òÕß²¿·Ö²»Ïë¹¥»÷±¾¹úÊܺ¦ÕߵĺڿͿÉÒÔ×èÖ¹ÒýÆðÍâµØÈ˵Ä×¢ÖØ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/malware-uses-wifi-bssid-for-victim-identification


4.Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý


4.png


Çå¾²Ñо¿Ô±Rajshekhar RajahariaÖÜÈÕÉù³Æ£¬£¬£¬£¬ £¬£¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛ½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý£¬£¬£¬£¬ £¬£¬¼ÛǮδ¹ûÕæ¡£¡£¡£¡£¡£¡£¾ÝRajahariaËù˵£¬£¬£¬£¬ £¬£¬ÕâЩÊý¾ÝÀ´×ÔλÓÚ°à¼ÓÂÞ¶ûµÄÊý×ÖÖ§¸¶Íø¹ØJuspay¡£¡£¡£¡£¡£¡£JusPayÌåÏÖ£¬£¬£¬£¬ £¬£¬ÔÚÍøÂç¹¥»÷Àú³ÌÖв¢Ã»Óп¨ºÅ»ò²ÆÎñÐÅϢй¶£¬£¬£¬£¬ £¬£¬ÏÖʵÊýĿԶµÍÓÚËù±¨¸æµÄ1ÒÚ¡£¡£¡£¡£¡£¡£µ«ºÚ¿Íȷʵ¿ÉÒÔ»á¼ûJuspayµÄ¿ª·¢Ö°Ô±µÄÃÜÔ¿£¬£¬£¬£¬ £¬£¬²¢ÇÒʹÓÃÆäÕÊ»§½¨Éèϵͳ£¬£¬£¬£¬ £¬£¬À´ÊÔͼ»ñµÃ¶ÔËùÓпɻá¼ûÊý¾ÝµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/technology/10-crore-indians-card-data-selling-on-dark-web-researcher/articleshow/80093994.cms


5.KelaÐû²¼ÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ


5.png


KelaÐû²¼ÁËÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬£¬Ëæ×ÅÓÎÏ·Íæ¼ÒºÍ¹ºÖÃÈËÊýµÄÔöÌí£¬£¬£¬£¬ £¬£¬µ½2022ÄêÔÚÏßÓÎÏ·ÐÐÒµµÄÔ¤¼ÆÊÕÈ뽫µÖ´ï1960ÒÚÃÀÔª£¬£¬£¬£¬ £¬£¬ÕâÒ²ÎüÒýÁËÍøÂç·¸·¨·Ö×ӵĹØ×¢¡£¡£¡£¡£¡£¡£KELA·¢Ã÷Á˽ü100Íò¸öÓëÍæ¼ÒºÍÔ±¹¤Ïà¹ØµÄ±»µÁÕË»§£¬£¬£¬£¬ £¬£¬ÆäÖÐ50%ÔÚ2020Äê³öÊÛ£»£»¼ì²âµ½Áè¼Ý500000¸öÓëÓÎÏ·ÐÐÒµ¹«Ë¾µÄÔ±¹¤µÄƾ֤й¶£»£»ºÚ¿ÍÕýÔÚÆð¾¢×·ÇóÈëÇÖÓÎÏ·¹«Ë¾µÄʱ»ú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ke-la.com/darknet-threat-actors-are-not-playing-games-with-the-gaming-industry/


6.NSAÐû²¼ÓйØ×÷·Ï¹ýʱµÄTLSЭÒéÉèÖõÄÖ¸ÄÏ


6.png


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©Ðû²¼ÁËÒ»·ÝÍøÂçÇå¾²ÐÅÏ¢£¨CSI£©±í£¬£¬£¬£¬ £¬£¬ÄÚÈÝÉæ¼°µ½×÷·Ï¹ýʱµÄ´«Êä²ãÇå¾²ÐÔ£¨TLS£©ÉèÖᣡ£¡£¡£¡£¡£¸ÃÖ¸ÄÏÈ·¶¨ÁËÓÃÓÚ¼ì²â¹ýʱµÄÃÜÂëÌ×¼þºÍÃÜÔ¿½»Á÷»úÖÆµÄÕ½ÂÔ£¬£¬£¬£¬ £¬£¬ÌÖÂÛÁ˽¨ÒéµÄTLSÉèÖ㬣¬£¬£¬ £¬£¬²¢ÎªÊ¹ÓùýʱµÄTLSÉèÖõÄ×éÖ¯ÌṩÁ˵÷½â½¨Òé¡£¡£¡£¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬£¬£¬£¬ £¬£¬ÒѾ­ÓÐÐí¶àÕë¶ÔTLS¼°ÆäʹÓõÄËã·¨µÄй¥»÷£¬£¬£¬£¬ £¬£¬Ê¹ÓùýʱЭÒéµÄÍøÂçÅþÁ¬±»µÐÊÖʹÓõÄΣº¦½Ï¸ß£¬£¬£¬£¬ £¬£¬Òò´ËNSAÇ¿ÁÒ½¨ÒéÓÃÇ¿¼ÓÃܺÍÈÏÖ¤À´±£»£»¤ËùÓÐÃô¸ÐÐÅÏ¢µÄЭÒéÉèÖÃÈ¡´ú¹ýʱµÄЭÒéÉèÖᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol