̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬²¨¼°È«ÇòÓû§£»£»£»£»£»Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚ¸öÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý

Ðû²¼Ê±¼ä 2021-01-06
1.̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬²¨¼°È«ÇòÓû§


1.jpg


̸ÌìȺ×éSlackЧÀͱ¬·¢ÁË2021ÄêµÄÊ×´ÎÖÐÖ¹£¬£¬£¬£¬£¬²¨¼°È«ÇòÓû§¡£¡£ÐÂÄêºóµÄµÚÒ»¸öÊÂÇéÈÕ£¬£¬£¬£¬£¬ÃÀ¹ú¶«²¿Ê±¼ä1ÔÂ4ÈÕÉÏÎç10µãSlack·ºÆðÁËÖÐÖ¹£¬£¬£¬£¬£¬Ó°ÏìÁË×ÀÃæ¿Í»§¶ËºÍWeb½çÃæ£¬£¬£¬£¬£¬Óû§ÎÞ·¨ÅþÁ¬Ð§ÀÍÆ÷¡¢ÎÞ·¨·¢ËͺÍÎüÊÕÐÂÎŲ¢ÇÒÎÞ·¨¼ìË÷ƵµÀÀúÊ·¼Í¼¡£¡£×î³õ±¬·¢ÖÐֹʱSlack³ÆÕâÖ»Ó°ÏìÁËÐÂÎÅת´ï£¬£¬£¬£¬£¬µ«ËæºóSlackµÄËùÓÐЧÀ͵ͼ·ºÆðÁËÖÐÖ¹¡£¡£ÏÖÔÚSlack»Ö¸´Á˿ͻ§¶ËµÄ²¿·Ö¹¦Ð§£¬£¬£¬£¬£¬ÈçÎüÊպͷ¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬µ«GoogleÈÕÀúºÍOutlookÈÕÀúµÈЧÀÍÈÔÎÞ·¨Õý³£ÊÂÇé¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/slack-suffers-its-first-massive-outage-of-2021/


2.Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý


2.png


Ñо¿Ö°Ô±Nikolai Tschacher·¢Ã÷Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý¡£¡£ReCaptchaÊÇGoogle×Ô¼ºµÄÃâ·ÑЧÀÍ£¬£¬£¬£¬£¬Ê¹ÓÃͼÏñ¡¢ÒôƵ»òÎÄÔ­À´ÑéÖ¤ÈËÃÇÊÇ·ñÔڵǼÕÊ»§¡£¡£Tschacher³Æ¹¥»÷µÄÒªÁìºÜÊǼòÆÓ£¬£¬£¬£¬£¬Ö»Ðè»ñÈ¡reCAPTCHAµÄMP3ÒôƵÎļþ£¬£¬£¬£¬£¬È»ºó½«ÆäÌá½»¸øGoogleµÄÓïÒôÎı¾API¡£¡£ÔÚÁè¼Ý97£¥µÄÇéÐÎÏ£¬£¬£¬£¬£¬Google¶¼»á·µ»Ø×¼È·µÄÃÕµ×£¬£¬£¬£¬£¬ÕâÖÖ¹¥»÷ÒªÁìÉõÖÁÊÊÓÃÓÚ×îа汾µÄreCAPTCHA v3¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/researcher-breaks-recaptcha-speech-to-text-api/162734/


3.еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß


3.png


SANS Internet Storm CenterµÄÑо¿Ö°Ô±·¢Ã÷еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß¡£¡£BSSIDΪ»ù±¾Ð§Àͼ¯±êʶ·û£¬£¬£¬£¬£¬ÊÇÓû§ÓÃÀ´Í¨¹ýWiFiÅþÁ¬µÄÎÞÏß·ÓÉÆ÷»ò½ÓÈëµãµÄMACÎïÀíµØµã¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÕýÔÚÍøÂçÓû§µÄBSSID£¬£¬£¬£¬£¬²¢½«ÆäÓëAlexander Mylnikovά»¤µÄBSSID-geoÊý¾Ý¿â¾ÙÐнÏÁ¿£¬£¬£¬£¬£¬ÒÔÈ·¶¨Êܺ¦ÕßÓÃÀ´»á¼ûInternetµÄWiFi½ÓÈëµãµÄÎïÀíµØÀíλÖᣡ£Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬£¬£¬Ä³Ð©¹ú¼ÒºÚ¿Í¿ÉÒÔÈ·¶¨Êܺ¦ÕßÊôÓÚÌØ¶¨µÄ¹ú¼ÒºÍµØÇø£¬£¬£¬£¬£¬»òÕß²¿·Ö²»Ïë¹¥»÷±¾¹úÊܺ¦ÕߵĺڿͿÉÒÔ×èÖ¹ÒýÆðÍâµØÈ˵Ä×¢ÖØ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/malware-uses-wifi-bssid-for-victim-identification


4.Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý


4.png


Çå¾²Ñо¿Ô±Rajshekhar RajahariaÖÜÈÕÉù³Æ£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛ½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý£¬£¬£¬£¬£¬¼ÛǮδ¹ûÕæ¡£¡£¾ÝRajahariaËù˵£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÀ´×ÔλÓÚ°à¼ÓÂÞ¶ûµÄÊý×ÖÖ§¸¶Íø¹ØJuspay¡£¡£JusPayÌåÏÖ£¬£¬£¬£¬£¬ÔÚÍøÂç¹¥»÷Àú³ÌÖв¢Ã»Óп¨ºÅ»ò²ÆÎñÐÅϢй¶£¬£¬£¬£¬£¬ÏÖʵÊýĿԶµÍÓÚËù±¨¸æµÄ1ÒÚ¡£¡£µ«ºÚ¿Íȷʵ¿ÉÒÔ»á¼ûJuspayµÄ¿ª·¢Ö°Ô±µÄÃÜÔ¿£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÆäÕÊ»§½¨Éèϵͳ£¬£¬£¬£¬£¬À´ÊÔͼ»ñµÃ¶ÔËùÓпɻá¼ûÊý¾ÝµÄ»á¼ûȨÏÞ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/technology/10-crore-indians-card-data-selling-on-dark-web-researcher/articleshow/80093994.cms


5.KelaÐû²¼ÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ


5.png


KelaÐû²¼ÁËÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬Ëæ×ÅÓÎÏ·Íæ¼ÒºÍ¹ºÖÃÈËÊýµÄÔöÌí£¬£¬£¬£¬£¬µ½2022ÄêÔÚÏßÓÎÏ·ÐÐÒµµÄÔ¤¼ÆÊÕÈ뽫µÖ´ï1960ÒÚÃÀÔª£¬£¬£¬£¬£¬ÕâÒ²ÎüÒýÁËÍøÂç·¸·¨·Ö×ӵĹØ×¢¡£¡£KELA·¢Ã÷Á˽ü100Íò¸öÓëÍæ¼ÒºÍÔ±¹¤Ïà¹ØµÄ±»µÁÕË»§£¬£¬£¬£¬£¬ÆäÖÐ50%ÔÚ2020Äê³öÊÛ£»£»£»£»£»¼ì²âµ½Áè¼Ý500000¸öÓëÓÎÏ·ÐÐÒµ¹«Ë¾µÄÔ±¹¤µÄƾ֤й¶£»£»£»£»£»ºÚ¿ÍÕýÔÚÆð¾¢×·ÇóÈëÇÖÓÎÏ·¹«Ë¾µÄʱ»ú¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ke-la.com/darknet-threat-actors-are-not-playing-games-with-the-gaming-industry/


6.NSAÐû²¼ÓйØ×÷·Ï¹ýʱµÄTLSЭÒéÉèÖõÄÖ¸ÄÏ


6.png


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©Ðû²¼ÁËÒ»·ÝÍøÂçÇå¾²ÐÅÏ¢£¨CSI£©±í£¬£¬£¬£¬£¬ÄÚÈÝÉæ¼°µ½×÷·Ï¹ýʱµÄ´«Êä²ãÇå¾²ÐÔ£¨TLS£©ÉèÖᣡ£¸ÃÖ¸ÄÏÈ·¶¨ÁËÓÃÓÚ¼ì²â¹ýʱµÄÃÜÂëÌ×¼þºÍÃÜÔ¿½»Á÷»úÖÆµÄÕ½ÂÔ£¬£¬£¬£¬£¬ÌÖÂÛÁ˽¨ÒéµÄTLSÉèÖ㬣¬£¬£¬£¬²¢ÎªÊ¹ÓùýʱµÄTLSÉèÖõÄ×éÖ¯ÌṩÁ˵÷½â½¨Òé¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬£¬£¬£¬£¬ÒѾ­ÓÐÐí¶àÕë¶ÔTLS¼°ÆäʹÓõÄËã·¨µÄй¥»÷£¬£¬£¬£¬£¬Ê¹ÓùýʱЭÒéµÄÍøÂçÅþÁ¬±»µÐÊÖʹÓõÄΣº¦½Ï¸ß£¬£¬£¬£¬£¬Òò´ËNSAÇ¿ÁÒ½¨ÒéÓÃÇ¿¼ÓÃܺÍÈÏÖ¤À´±£»£»£»£»£»¤ËùÓÐÃô¸ÐÐÅÏ¢µÄЭÒéÉèÖÃÈ¡´ú¹ýʱµÄЭÒéÉèÖᣡ£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol