Ñо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú£»£»£» £»£»GoogleÔÚÂéʡסÃñ°²×¿ÊÖ»úÇ¿ÖÆ×°ÖÃCOVID-19¸ú×ÙÓ¦ÓÃ

Ðû²¼Ê±¼ä 2021-06-21

1.Ñо¿Ö°Ô±ÑÝʾÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú


1.jpg


Ñо¿Ö°Ô±Carl SchouÑÝʾÁËÔõÑùͨ¹ýWiFiÈÈÃÅÀ´¹¥»÷iPhoneÊÖ»ú ¡£¡£¡£Carl SchouÔÚÅþÁ¬Ð¡ÎÒ˽¼ÒWiFiÈÈÃÅ¡°%p%s%s%s%s%n¡±Ê±£¬£¬£¬£¬£¬·¢Ã÷ËûiPhoneµÄWiFi¹¦Ð§±»½ûÓ㬣¬£¬£¬£¬²¢ÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFi¹¦Ð§£¬£¬£¬£¬£¬×ÝÈ»ËûÖØÆô×°±¸»ò¸ü¸ÄÈÈÃÅÃû³Æ ¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÊäÈëÆÊÎöÎÊÌ⵼ֵ쬣¬£¬£¬£¬µ±WiFiÈÈÃÅÃû³ÆÖб£´æ´øÓС°%¡±µÄ×Ö·û´®Ê±£¬£¬£¬£¬£¬iOS¿ÉÄÜ»á¹ýʧµØ½«¡°%¡±ºóÃæµÄ×ÖĸڹÊÍΪ×Ö·û´®ÃûÌÃ˵Ã÷·û ¡£¡£¡£»£»£» £»£»Ö¸´Wi-Fi¹¦Ð§µÄΨһҪÁìÊÇÖØÖÃiPhoneµÄÍøÂçÉèÖà ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸ÃÎó²îÊÇiPhone¶ÀÍ̵Ä£¬£¬£¬£¬£¬ÎÞ·¨ÔÚAndroidÊÖ»úÉÏÖØÏÖ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/


2.GoogleÔÚÂéʡסÃñ°²×¿ÊÖ»úÇ¿ÖÆ×°ÖÃCOVID-19¸ú×ÙÓ¦ÓÃ


2.jpg


ÔÚÒÑÍùµÄ¼¸ÌìÀ£¬£¬£¬£¬´ó×ÚµÄÓû§±¨¸æ³ÆGoogleÔÚËûÃǵݲ׿װ±¸ÉÏÇÄÇÄ×°ÖÃÁËMassNotify£¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨Ð¶ÔØ ¡£¡£¡£MassNotifyÊÇÂíÈøÖîÈûÖݵÄCOVID-19ÁªÏµÈ˸ú×ÙÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ËüÔÊÐíÆôÓÃÁËCOVID-19Åû¶֪ͨ¹¦Ð§µÄAndroidÓû§ÎüÊÕÖÒÑÔ ¡£¡£¡£²¿·ÖÓû§ÌåÏÖÆä²¢Ã»ÓпªÆô¸Ã¹¦Ð§£¬£¬£¬£¬£¬µ«Ò²±»Ç¿ÖÆ×°ÖÃÁ˸ÃÓ¦Ó㻣»£» £»£»¶øÓÐЩÓû§±¨¸æÆäÕÒ²»µ½¸ÃÓ¦ÓõÄÈκÎͼ±ê£¬£¬£¬£¬£¬Òò´ËÎÞ·¨¾ÙÐÐÐ¶ÔØ ¡£¡£¡£Google³Æ¸ÃÓ¦ÓóÌÐòÖ»ÊÇÒÑ×°Öõ«²¢Î´ÆôÓ㬣¬£¬£¬£¬Ö±µ½Óû§·­¿ªCOVID-19Åû¶֪ͨ¹¦Ð§²Å»áÆôÓà ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-force-installs-massachusetts-massnotify-android-covid-app/


3.MandiantÅû¶DarksideÕë¶Ô¼à¿ØÏµÍ³ÌṩÉ̵ũӦÁ´¹¥»÷


3.jpg


Fireeye MandiantÅû¶ÁËDarksideÁ¥ÊôÍÅ»ïUNC2465Õë¶Ô¼à¿ØÏµÍ³£¨CCTV£©ÌṩÉ̵ũӦÁ´¹¥»÷ ¡£¡£¡£¹¥»÷ʼÓÚ2021Äê5ÔÂ18ÈÕ£¬£¬£¬£¬£¬ÊÜÓ°Ïì×éÖ¯ÖеÄÓû§ä¯ÀÀµ½¶ñÒâÁ´½Ó²¢ÏÂÔØÁ˶ñÒâZIP£¬£¬£¬£¬£¬È»ºó×°ÖÃÁËһϵÁжñÒâÈí¼þ ¡£¡£¡£MandiantÆÊÎö³õÊ¼ÔØÌåÊÇÒ»¸öÀ´×ÔÕýµ±ÍøÕ¾µÄ¶ñÒâÇå¾²ÉãÏñÍ·PVR×°ÖóÌÐò£¬£¬£¬£¬£¬¹¥»÷Ö÷Òª·ÖΪ5¸ö½×¶Î£ºÄ¾Âí»¯×°ÖóÌÐòÏÂÔØ¡¢Nullsoft×°ÖóÌÐò¡¢ÏÂÔØVBScriptºÍPowerShell¡¢×°ÖÃSMOKEDHAM DropperºÍSMOKEDHAMºóÃÅ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html


4.GriefÍÅ»ï³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute


44.jpg


ºÚ¿ÍÍÅ»ïGriefÉù³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute ¡£¡£¡£GriefÓÚ6ÔÂ11ÈÕ½«¸ÃÒ½ÔºÌí¼Ó½øÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬²¢ÔÚ6ÔÂ15ÈÕ¸üÐÂÁËÁбí£¬£¬£¬£¬£¬×ª´¢ÁËÆäÇÔÈ¡µÄÆäËüÊý¾Ý ¡£¡£¡£GriefµÄ½²»°ÈËÔÚ6ÔÂ1ÈÕ½ÓÊܲɷÃʱÌåÏÖ²»»á¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬£¬µ«ËƺõÕûÐλú¹¹²»°üÀ¨ÔÚÆäÖÐ ¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨2015-2020ÄêµÄÒ»Ñùƽ³£ÓªÒµÓöÈÎļþ¡¢Ã¿ÄêµÄËðÒæ±í¡¢ÓëPPP´û¿îºÍ´û¿î¿íÃâÉêÇëÓйصÄÊý¾ÝµÈ£¬£¬£¬£¬£¬ÒÔ¼°²¡È˵Ŀµ½¡ÐÅÏ¢£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢¼ì²âÀàÐͺÍÄ¿µÄ¡¢SSNµÈ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/fl-grief-claims-to-have-breached-the-woodruff-institute/


5.NexusguardÐû²¼2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


NexusguardÐû²¼ÁË2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬COVID-19½«DDoS¹¥»÷ÍÆÏòÁËеĸ߶ȣº2020Äê3Ô·ÝDDoS¹¥»÷ÊýĿͬ±ÈÔöÌí341.21%£¬£¬£¬£¬£¬Õ¼2020ÄêËùÓй¥»÷µÄ23.96%£»£»£» £»£»Q2 DDoS¹¥»÷ÊýĿռ¹¥»÷×ÜÁ¿µÄ38.33%£¬£¬£¬£¬£¬ÊÇ2020Äê¹¥»÷×Öеļ¾¶È ¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬DDoS¹¥»÷ÊýÄ¿ÔÚ7Ô·ÝϽµµ½ÁË6.99%£¬£¬£¬£¬£¬ÕâÖÖϽµÇ÷ÊÆÒ»Ö±Ò»Á¬µ½12Ô ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬´Ó3ÔÂ×îÏÈ£¬£¬£¬£¬£¬Õë¶ÔÈ«Çò¸÷Ðи÷ÒµµÄÀÕË÷ºÍÀÕË÷DDoS (RDDoS) ¹¥»÷¾ùÓÐËùÔöÌí ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.nexusguard.com/threat-report/annual-threat-report-2020


6.NSAÐû²¼ÓйØUCÒÔ¼°IPÓïÒôºÍÊÓÆµÏµÍ³µÄÇå¾²Ö¸ÄÏ


6.jpg


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö (NSA)Ðû²¼ÁËϵͳÖÎÀíÔ±ÔÚ±£»£»£» £»£»¤Í³Ò»Í¨Ñ¶ (UC) ÒÔ¼°IPÓïÒôºÍÊÓÆµ (VVoIP) ϵͳʱӦ×ñÕÕµÄÇå¾²Ö¸ÄÏ ¡£¡£¡£UCºÍVVoIPÊÇÔÚÆóÒµÇéÐÎÖÐÓÃÓÚÖÖÖÖÄ¿µÄµÄºô½Ð´¦Öóͷ£ÏµÍ³ ¡£¡£¡£¸ÃÖ¸ÄÏÌá³öÁËʹÓÃÐéÄâ¾ÖÓòÍø(VLAN) ½«ÓïÒôºÍÊÓÆµÁ÷Á¿ÓëÊý¾ÝÁ÷Á¿ÍÑÀ룻£»£» £»£»Ê¹Óûá¼û¿ØÖÆÁбíºÍ·ÓɹæÔòÀ´ÏÞÖÆ¿çVLAN¶Ô×°±¸µÄ»á¼û£»£»£» £»£»Ê¼ÖÕ¼á³ÖÈí¼þ´¦ÓÚ×îÐÂ״̬ÒÔÔ¤·ÀUC/VVoIPÈí¼þÎó²îµÈ½¨Òé ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2661746/nsa-releases-guidance-on-securing-unified-communications-and-voice-and-video-ov/