×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú£»GoogleÔÚÂéÊ¡¾ÓÃñ°²×¿ÊÖ»úÇ¿Ôì×°ÖÃCOVID-19¸ú×ÙÀûÓÃ
°ä²¼¹¦·ò 2021-06-211.×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú

×êÑÐÈËÔ±Carl SchouÑÝʾÁËÈôºÎͨ¹ýWiFiÈȵãÀ´¹¥»÷iPhoneÊÖ»ú¡£Carl SchouÔÚÏνÓÓ×ÎÒWiFiÈȵ㡰%p%s%s%s%s%n¡±Ê±£¬·¢ÏÖËûiPhoneµÄWiFiÖ°Äܱ»½ûÓ㬲¢ÇÒÔÙÒ²ÎÞ·¨ÆôÓÃWiFiÖ°ÄÜ£¬¼´±ãËû³ÁÆôÉ豸»ò¸ü¸ÄÈȵãÃû³Æ¡£×êÑÐÈËÔ±³Æ£¬Õâ¿ÉÄÜÊÇÊäÈë½âÎöÎÊÌâµ¼Öµģ¬µ±WiFiÈȵãÃû³ÆÖдæÔÚ´øÓÓ×°%¡±µÄ×Ö·û´®Ê±£¬iOS¿ÉÄÜ»áÃýÎ󵨽«¡°%¡±ºóÃæµÄ×ÖĸڹÊÍΪ×Ö·û´®ÌåʽעÃ÷·û¡£¸´ÔWi-FiÖ°ÄܵÄΨһ²½ÖèÊdzÁÖÃiPhoneµÄÍøÂçÉèÖá£´Ë±í£¬¸Ã·ì϶ÊÇiPhone¶ÀÓеģ¬ÎÞ·¨ÔÚAndroidÊÖ»úÉϳÁÏÖ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iphone-bug-breaks-wifi-when-you-join-hotspot-with-unusual-name/
2.GoogleÔÚÂéÊ¡¾ÓÃñ°²×¿ÊÖ»úÇ¿Ôì×°ÖÃCOVID-19¸ú×ÙÀûÓÃ

ÔÚ´ÓǰµÄ¼¸ÌìÀ´óÁ¿µÄÓû§»ã±¨³ÆGoogleÔÚËûÃǵݲ׿É豸ÉÏ͵¹¶×°ÖÃÁËMassNotify£¬²¢ÇÒÎÞ·¨Ð¶ÔØ¡£MassNotifyÊÇÂíÈøÖîÈûÖݵÄCOVID-19ÁªÏµÈ˸ú×ÙÀûÓ÷¨Ê½£¬ËüÔÊÐíÆôÓÃÁËCOVID-19Åû¶ְ֪ͨÄܵÄAndroidÓû§½Ó¹ÜÖҸ档²¿ÃÅÓû§°µÊ¾Æä²¢Ã»ÓпªÆô¸ÃÖ°ÄÜ£¬µ«Ò²±»Ç¿Ôì×°ÖÃÁ˸ÃÀûÓã»¶øÓÐЩÓû§»ã±¨ÆäÕÒ²»µ½¸ÃÀûÓõÄÈκÎͼ±ê£¬Òò¶øÎÞ·¨½øÐÐÐ¶ÔØ¡£Google³Æ¸ÃÀûÓ÷¨Ê½Ö»ÊÇÒÑ×°Öõ«²¢Î´ÆôÓã¬Ö±µ½Óû§´ò¿ªCOVID-19Åû¶ְ֪ͨÄܲŻáÆôÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-force-installs-massachusetts-massnotify-android-covid-app/
3.MandiantÅû¶DarksideÕë¶Ô¼à¿ØÏµÍ³ÌṩÉ̵Ĺ©¸øÁ´¹¥»÷

Fireeye MandiantÅû¶ÁËDarkside´ÓÊôÍÅ»ïUNC2465Õë¶Ô¼à¿ØÏµÍ³£¨CCTV£©ÌṩÉ̵Ĺ©¸øÁ´¹¥»÷¡£¹¥»÷ʼÓÚ2021Äê5ÔÂ18ÈÕ£¬ÊÜÓ°Ïì×éÖ¯ÖеÄÓû§ä¯ÀÀµ½¶ñÒâÁ´½Ó²¢ÏÂÔØÁ˶ñÒâZIP£¬¶øºó×°ÖÃÁËһϵÁжñÒâÈí¼þ¡£Mandiant·ÖÎö³õÊ¼ÔØÌåÊÇÒ»¸öÀ´×ԺϷ¨ÍøÕ¾µÄ¶ñÒⰲȫÉãÏñÍ·PVR×°Ö÷¨Ê½£¬¹¥»÷ÖØÒª·ÖΪ5¸ö½×¶Î£ºÄ¾Âí°ç×°Ö÷¨Ê½ÏÂÔØ¡¢Nullsoft×°Ö÷¨Ê½¡¢ÏÂÔØVBScriptºÍPowerShell¡¢×°ÖÃSMOKEDHAM DropperºÍSMOKEDHAMºóÃÅ¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html
4.GriefÍÅ»ï³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute

ºÚ¿ÍÍÅ»ïGriefÐû³ÆÒѹ¥»÷ÃÀ¹úÕûÐλú¹¹Woodruff Institute¡£GriefÓÚ6ÔÂ11ÈÕ½«¸ÃÒ½ÔºÔö³¤½øÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢ÔÚ6ÔÂ15ÈÕ¸üÐÂÁËÁÐ±í£¬×ª´¢ÁËÆäÇÔÈ¡µÄÆäËüÊý¾Ý¡£GriefµÄ½²»°ÈËÔÚ6ÔÂ1ÈÕ½ÓÊܲɷÃʱ°µÊ¾²»»á¹¥»÷Ò½ÁÆ×éÖ¯£¬µ«ËƺõÕûÐλú¹¹²»Ô̺¬ÔÚÆäÖС£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬2015-2020ÄêµÄÈÕ³£ÒµÎñÓöÈÎļþ¡¢Ã¿ÄêµÄËðÒæ±í¡¢ÓëPPP´û¿îºÍ´û¿î»íÃâÉêÇëÓйصÄÊý¾ÝµÈ£¬ÒÔ¼°²¡È˵Ľ¡È«ÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢½¡È«±£ÏÕÐÅÏ¢¡¢¼ì²âÀàÐͺÍÖ÷ÕÅ¡¢SSNµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/fl-grief-claims-to-have-breached-the-woodruff-institute/
5.Nexusguard°ä²¼2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

Nexusguard°ä²¼ÁË2020Äê¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬COVID-19½«DDoS¹¥»÷ÍÆÏòÁËеĸ߶ȣº2020Äê3Ô·ÝDDoS¹¥»÷ÊýÁ¿Í¬±ÈÔö³¤341.21%£¬Õ¼2020ÄêËùÓй¥»÷µÄ23.96%£»Q2 DDoS¹¥»÷ÊýÁ¿Õ¼¹¥»÷×ÜÁ¿µÄ38.33%£¬ÊÇ2020Äê¹¥»÷×Öеļ¾¶È¡£ÓÐȤµÄÊÇ£¬DDoS¹¥»÷ÊýÁ¿ÔÚ7Ô·ݽµÂäµ½ÁË6.99%£¬ÕâÖÖ½µÂäÇ÷ÏòÒ»Ïò³ÖÐøµ½12Ô¡£´Ë±í£¬´Ó3ÔÂÆðÍ·£¬Õë¶ÔÈ«Çò¸÷Ðи÷ÒµµÄÀÕË÷ºÍÀÕË÷DDoS (RDDoS) ¹¥»÷¾ùÓÐËùÔö³¤¡£
ÔÎÄÁ´½Ó£º
https://blog.nexusguard.com/threat-report/annual-threat-report-2020
6.NSA°ä²¼ÓйØUCÒÔ¼°IPÓïÒôºÍÊÓÆµÏµÍ³µÄ°²È«Ö¸ÄÏ

ÃÀ¹ú¹ú¶È°²È«¾Ö (NSA)°ä²¼ÁËϵͳÖÎÀíÔ±ÔÚ±£»¤Í³Ò»Í¨Ñ¶ (UC) ÒÔ¼°IPÓïÒôºÍÊÓÆµ (VVoIP) ϵͳʱӦ×ñѵݲȫָÄÏ¡£UCºÍVVoIPÊÇÔÚÆóÒµ»·¾³ÖÐÓÃÓÚ¸÷ÀàÖ÷Õŵĺô½Ð´¦ÖÃϵͳ¡£¸ÃÖ¸ÄÏÌá³öÁËʹÓÃÐé¹¹¾ÖÓòÍø(VLAN) ½«ÓïÒôºÍÊÓÆµÁ÷Á¿ÓëÊý¾ÝÁ÷Á¿·Ö¸ô£»Ê¹ÓýӼû½ÚÔìÁбíºÍ·Óɹ涨À´ÏÞ¶È¿çVLAN¶ÔÉ豸µÄ½Ó¼û£»Ê¼ÖÕά³ÖÈí¼þ´¦ÓÚ×îÐÂ״̬ÒÔÔ¤·ÀUC/VVoIPÈí¼þ·ì϶µÈ½¨Òé¡£
ÔÎÄÁ´½Ó£º
https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2661746/nsa-releases-guidance-on-securing-unified-communications-and-voice-and-video-ov/


¾©¹«Íø°²±¸11010802024551ºÅ