̸ÌìȺ×éSlack·þÎñÖжÏ£¬²¨¼°È«ÇòÓû§£»×êÑÐÈËÔ±ÔÚ°µÍø·¢ÏÖ½ü1ÒÚ¸öÓ¡¶ÈÈ˵ÄÐÅÓþ¿¨Êý¾Ý

°ä²¼¹¦·ò 2021-01-06
1.̸ÌìȺ×éSlack·þÎñÖжÏ£¬²¨¼°È«ÇòÓû§


1.jpg


̸ÌìȺ×éSlack·þÎñ²úÉúÁË2021ÄêµÄ³õ´ÎÖжÏ£¬²¨¼°È«ÇòÓû§¡£ÐÂÄêºóµÄµÚÒ»¸ö¹¤×÷ÈÕ£¬ÃÀ¹ú¶«²¿¹¦·ò1ÔÂ4ÈÕÉÏÎç10µãSlack³öÏÖÁËÖжÏ£¬Ó°ÏìÁË×ÀÃæ¿Í»§¶ËºÍWeb½çÃæ£¬Óû§ÎÞ·¨ÏνӷþÎñÆ÷¡¢ÎÞ·¨·¢ËͺͽӹÜÐÂÎŲ¢ÇÒÎÞ·¨¼ìË÷Ƶ·º¹Çà¼Í¼¡£×î³õ²úÉúÖжÏʱSlack³ÆÕâÖ»Ó°ÏìÁËÐÂÎÅ´«µÝ£¬µ«ËæºóSlackµÄËùÓзþÎñµÄ¶¼³öÏÖÁËÖжÏ¡£Ä¿Ç°Slack¸´Ô­Á˿ͻ§¶ËµÄ²¿ÃÅÖ°ÄÜ£¬Èç½Ó¹ÜºÍ·¢ËÍÐÂÎÅ£¬µ«GoogleÈÕÀúºÍOutlookÈÕÀúµÈ·þÎñÈÔÎÞ·¨Õý³£¹¤×÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/slack-suffers-its-first-massive-outage-of-2021/


2.Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý


2.png


×êÑÐÈËÔ±Nikolai Tschacher·¢ÏÖGoogle reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý¡£ReCaptchaÊÇGoogle×Ô¼ºµÄÃâ·Ñ·þÎñ£¬Ê¹ÓÃͼÏñ¡¢ÒôƵ»òÎÄÕý±¾ÑéÖ¤ÈËÃÇÊÇ·ñÔڵǼÕÊ»§¡£Tschacher³Æ¹¥»÷µÄ²½Ö輫¶Èµ¥Ò»£¬Ö»Ðè»ñÈ¡reCAPTCHAµÄMP3ÒôƵÎļþ£¬¶øºó½«ÆäÌá½»¸øGoogleµÄÓïÒôÎı¾API¡£ÔÚ³¬¹ý97£¥µÄÇé¿öÏ£¬Google³ÇÊзµ»ØÕýÈ·µÄ´ð°¸£¬ÕâÖÖ¹¥»÷²½ÖèÉõÖÁºÏÓÃÓÚ×îа汾µÄreCAPTCHA v3¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/researcher-breaks-recaptcha-speech-to-text-api/162734/


3.еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´¼ø±ðÊܺ¦Õß


3.png


SANS Internet Storm CenterµÄ×êÑÐÈËÔ±·¢ÏÖеĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´¼ø±ðÊܺ¦Õß¡£BSSIDΪ¸ù»ù·þÎñ¼¯±êʶ·û£¬ÊÇÓû§ÓÃÀ´Í¨¹ýWiFiÏνӵÄÎÞÏß·ÓÉÆ÷»ò½ÓÈëµãµÄMACÎïÀíµØÖ·¡£×êÑÐÈËÔ±³Æ£¬¸Ã¶ñÒâÈí¼þÔÚÍøÂçÓû§µÄBSSID£¬²¢½«ÆäÓëAlexander MylnikovÊØ»¤µÄBSSID-geoÊý¾Ý¿â½øÐбÈÁ¦£¬ÒÔÈ·¶¨Êܺ¦ÕßÓÃÀ´½Ó¼ûInternetµÄWiFi½ÓÈëµãµÄÎïÀíµØÀíµØÎ»¡£Í¨¹ýÕâÖÖ·½Ê½£¬Ä³Ð©¹ú¶ÈºÚ¿ÍÄܹ»È·¶¨Êܺ¦ÕßÊôÓÚÌØ¶¨µÄ¹ú¶ÈºÍµØÓò£¬»òÕß²¿ÃŲ»Ïë¹¥»÷±¾¹úÊܺ¦ÕߵĺڿÍÄܹ»Ô¤·ÀÒýÆð±¾µØÈËÈ·°ÑÎÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/malware-uses-wifi-bssid-for-victim-identification


4.×êÑÐÈËÔ±ÔÚ°µÍø·¢ÏÖ½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓþ¿¨Êý¾Ý


4.png


°²È«×êÑÐÔ±Rajshekhar RajahariaÖÜÈÕÐû³Æ£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛ½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓþ¿¨Êý¾Ý£¬¼Ûֵδ¹«¿ª¡£¾ÝRajahariaËù˵£¬ÕâЩÊý¾ÝÀ´×ÔλÓÚ°à¼ÓÂÞ¶ûµÄÊý×ÖÖ§¸¶Íø¹ØJuspay¡£JusPay°µÊ¾£¬ÔÚÍøÂç¹¥»÷¹ý³ÌÖв¢Ã»Óп¨ºÅ»ò²ÆÕþÐÅϢй¶£¬ÏÖʵÊýÁ¿Ô¶µÍÓÚËù»ã±¨µÄ1ÒÚ¡£µ«ºÚ¿ÍµÄÈ·Äܹ»½Ó¼ûJuspayµÄ¿ª·¢ÈËÔ±µÄÃÜÔ¿£¬²¢ÇÒÀûÓÃÆäÕÊ»§´´½¨ÏµÍ³£¬À´ÊÔͼ»ñµÃ¶ÔËùÓпɽӼûÊý¾ÝµÄ½Ó¼ûȨÏÞ¡£


Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/technology/10-crore-indians-card-data-selling-on-dark-web-researcher/articleshow/80093994.cms


5.Kela°ä²¼ÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄ·ÖÎö»ã±¨


5.png


Kela°ä²¼ÁËÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Ëæ×ÅÓÎÏ·Íæ¼ÒºÍ²É°ìÈËÊýµÄÔö³¤£¬µ½2022ÄêÔÚÏßÓÎÏ·ÐÐÒµµÄÔ¤¼ÆÊÕÈ뽫´ïµ½1960ÒÚÃÀÔª£¬ÕâÒ²ÎüÒýÁËÍøÂç·¸×ï·Ö×ӵĹØ×¢¡£KELA·¢ÏÖÁ˽ü100Íò¸öÓëÍæ¼ÒºÍÔ±¹¤Óйصı»µÁÕË»§£¬ÆäÖÐ50%ÔÚ2020ÄêÏúÊÛ£»¼ì²âµ½³¬¹ý500000¸öÓëÓÎÏ·ÐÐÒµ¹«Ë¾µÄÔ±¹¤µÄƾ֤й¶£»ºÚ¿ÍÔÚÖÂÁ¦×·ÇóÈëÇÖÓÎÏ·¹«Ë¾µÄ»úÓö¡£


Ô­ÎÄÁ´½Ó£º

https://ke-la.com/darknet-threat-actors-are-not-playing-games-with-the-gaming-industry/


6.NSA°ä²¼ÓйØÈ¡µÞ¹ýÆÚµÄTLSºÍ̸ÅäÖõÄÖ¸ÄÏ


6.png


ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©°ä²¼ÁËÒ»·ÝÍøÂ簲ȫÐÅÏ¢£¨CSI£©±í£¬ÄÚÈÝÉæ¼°µ½È¡µÞ¹ýÆÚµÄ´«Êä²ã°²È«ÐÔ£¨TLS£©ÅäÖ᣸ÃÖ¸ÄÏÈ·¶¨ÁËÓÃÓÚ¼ì²â¹ýÆÚµÄÃÜÂëÌ×¼þºÍÃÜÔ¿»¥»»»úÔìµÄÕ½Êõ£¬»áÉÌÁ˽¨ÒéµÄTLSÅäÖ㬲¢ÎªÊ¹ÓùýÆÚµÄTLSÅäÖõÄ×éÖ¯ÌṩÁ˲¹¾È½¨Òé¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬ÒѾ­ÓкöàÕë¶ÔTLS¼°ÆäʹÓõÄËã·¨µÄй¥»÷£¬Ê¹ÓùýÆÚºÍ̸µÄÍøÂçÏνӱ»µÐÊÖÀûÓõķçÏսϸߣ¬Òò¶øNSAÇ¿ÁÒ½¨ÒéÓÃÇ¿¼ÓÃܺÍÈÏÖ¤À´±£»¤ËùÓÐÃô¸ÐÐÅÏ¢µÄºÍ̸ÅäÖÃÈ¡´ú¹ýÆÚµÄºÍ̸ÅäÖá£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol