̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬²¨¼°È«ÇòÓû§£»£»£»£»Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚ¸öÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý

Ðû²¼Ê±¼ä 2021-01-06
1.̸ÌìȺ×éSlackЧÀÍÖÐÖ¹£¬£¬£¬²¨¼°È«ÇòÓû§


1.jpg


̸ÌìȺ×éSlackЧÀͱ¬·¢ÁË2021ÄêµÄÊ×´ÎÖÐÖ¹£¬£¬£¬²¨¼°È«ÇòÓû§¡£¡£¡£ÐÂÄêºóµÄµÚÒ»¸öÊÂÇéÈÕ£¬£¬£¬ÃÀ¹ú¶«²¿Ê±¼ä1ÔÂ4ÈÕÉÏÎç10µãSlack·ºÆðÁËÖÐÖ¹£¬£¬£¬Ó°ÏìÁË×ÀÃæ¿Í»§¶ËºÍWeb½çÃæ£¬£¬£¬Óû§ÎÞ·¨ÅþÁ¬Ð§ÀÍÆ÷¡¢ÎÞ·¨·¢ËͺÍÎüÊÕÐÂÎŲ¢ÇÒÎÞ·¨¼ìË÷ƵµÀÀúÊ·¼Í¼¡£¡£¡£×î³õ±¬·¢ÖÐֹʱSlack³ÆÕâÖ»Ó°ÏìÁËÐÂÎÅת´ï£¬£¬£¬µ«ËæºóSlackµÄËùÓÐЧÀ͵ͼ·ºÆðÁËÖÐÖ¹¡£¡£¡£ÏÖÔÚSlack»Ö¸´Á˿ͻ§¶ËµÄ²¿·Ö¹¦Ð§£¬£¬£¬ÈçÎüÊպͷ¢ËÍÐÂÎÅ£¬£¬£¬µ«GoogleÈÕÀúºÍOutlookÈÕÀúµÈЧÀÍÈÔÎÞ·¨Õý³£ÊÂÇé¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/slack-suffers-its-first-massive-outage-of-2021/


2.Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý


2.png


Ñо¿Ö°Ô±Nikolai Tschacher·¢Ã÷Google reCAPTCHA¿É±»ÓïÒôÎı¾APIÈÆ¹ý¡£¡£¡£ReCaptchaÊÇGoogle×Ô¼ºµÄÃâ·ÑЧÀÍ£¬£¬£¬Ê¹ÓÃͼÏñ¡¢ÒôƵ»òÎÄÔ­À´ÑéÖ¤ÈËÃÇÊÇ·ñÔڵǼÕÊ»§¡£¡£¡£Tschacher³Æ¹¥»÷µÄÒªÁìºÜÊǼòÆÓ£¬£¬£¬Ö»Ðè»ñÈ¡reCAPTCHAµÄMP3ÒôƵÎļþ£¬£¬£¬È»ºó½«ÆäÌá½»¸øGoogleµÄÓïÒôÎı¾API¡£¡£¡£ÔÚÁè¼Ý97£¥µÄÇéÐÎÏ£¬£¬£¬Google¶¼»á·µ»Ø×¼È·µÄÃÕµ×£¬£¬£¬ÕâÖÖ¹¥»÷ÒªÁìÉõÖÁÊÊÓÃÓÚ×îа汾µÄreCAPTCHA v3¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/researcher-breaks-recaptcha-speech-to-text-api/162734/


3.еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß


3.png


SANS Internet Storm CenterµÄÑо¿Ö°Ô±·¢Ã÷еĶñÒâÈí¼þ¿ÉÓÃWiFi BSSIDÀ´Ê¶±ðÊܺ¦Õß¡£¡£¡£BSSIDΪ»ù±¾Ð§Àͼ¯±êʶ·û£¬£¬£¬ÊÇÓû§ÓÃÀ´Í¨¹ýWiFiÅþÁ¬µÄÎÞÏß·ÓÉÆ÷»ò½ÓÈëµãµÄMACÎïÀíµØµã¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬¸Ã¶ñÒâÈí¼þÕýÔÚÍøÂçÓû§µÄBSSID£¬£¬£¬²¢½«ÆäÓëAlexander Mylnikovά»¤µÄBSSID-geoÊý¾Ý¿â¾ÙÐнÏÁ¿£¬£¬£¬ÒÔÈ·¶¨Êܺ¦ÕßÓÃÀ´»á¼ûInternetµÄWiFi½ÓÈëµãµÄÎïÀíµØÀíλÖᣡ£¡£Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬Ä³Ð©¹ú¼ÒºÚ¿Í¿ÉÒÔÈ·¶¨Êܺ¦ÕßÊôÓÚÌØ¶¨µÄ¹ú¼ÒºÍµØÇø£¬£¬£¬»òÕß²¿·Ö²»Ïë¹¥»÷±¾¹úÊܺ¦ÕߵĺڿͿÉÒÔ×èÖ¹ÒýÆðÍâµØÈ˵Ä×¢ÖØ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/malware-uses-wifi-bssid-for-victim-identification


4.Ñо¿Ö°Ô±ÔÚ°µÍø·¢Ã÷½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý


4.png


Çå¾²Ñо¿Ô±Rajshekhar RajahariaÖÜÈÕÉù³Æ£¬£¬£¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛ½ü1ÒÚÓ¡¶ÈÈ˵ÄÐÅÓÿ¨Êý¾Ý£¬£¬£¬¼ÛǮδ¹ûÕæ¡£¡£¡£¾ÝRajahariaËù˵£¬£¬£¬ÕâЩÊý¾ÝÀ´×ÔλÓÚ°à¼ÓÂÞ¶ûµÄÊý×ÖÖ§¸¶Íø¹ØJuspay¡£¡£¡£JusPayÌåÏÖ£¬£¬£¬ÔÚÍøÂç¹¥»÷Àú³ÌÖв¢Ã»Óп¨ºÅ»ò²ÆÎñÐÅϢй¶£¬£¬£¬ÏÖʵÊýĿԶµÍÓÚËù±¨¸æµÄ1ÒÚ¡£¡£¡£µ«ºÚ¿Íȷʵ¿ÉÒÔ»á¼ûJuspayµÄ¿ª·¢Ö°Ô±µÄÃÜÔ¿£¬£¬£¬²¢ÇÒʹÓÃÆäÕÊ»§½¨Éèϵͳ£¬£¬£¬À´ÊÔͼ»ñµÃ¶ÔËùÓпɻá¼ûÊý¾ÝµÄ»á¼ûȨÏÞ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/technology/10-crore-indians-card-data-selling-on-dark-web-researcher/articleshow/80093994.cms


5.KelaÐû²¼ÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ


5.png


KelaÐû²¼ÁËÓйØÍøÂçÓÎÏ·ÐÐÒµµÄƾ֤й¶µÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬Ëæ×ÅÓÎÏ·Íæ¼ÒºÍ¹ºÖÃÈËÊýµÄÔöÌí£¬£¬£¬µ½2022ÄêÔÚÏßÓÎÏ·ÐÐÒµµÄÔ¤¼ÆÊÕÈ뽫µÖ´ï1960ÒÚÃÀÔª£¬£¬£¬ÕâÒ²ÎüÒýÁËÍøÂç·¸·¨·Ö×ӵĹØ×¢¡£¡£¡£KELA·¢Ã÷Á˽ü100Íò¸öÓëÍæ¼ÒºÍÔ±¹¤Ïà¹ØµÄ±»µÁÕË»§£¬£¬£¬ÆäÖÐ50%ÔÚ2020Äê³öÊÛ£»£»£»£»¼ì²âµ½Áè¼Ý500000¸öÓëÓÎÏ·ÐÐÒµ¹«Ë¾µÄÔ±¹¤µÄƾ֤й¶£»£»£»£»ºÚ¿ÍÕýÔÚÆð¾¢×·ÇóÈëÇÖÓÎÏ·¹«Ë¾µÄʱ»ú¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ke-la.com/darknet-threat-actors-are-not-playing-games-with-the-gaming-industry/


6.NSAÐû²¼ÓйØ×÷·Ï¹ýʱµÄTLSЭÒéÉèÖõÄÖ¸ÄÏ


6.png


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©Ðû²¼ÁËÒ»·ÝÍøÂçÇå¾²ÐÅÏ¢£¨CSI£©±í£¬£¬£¬ÄÚÈÝÉæ¼°µ½×÷·Ï¹ýʱµÄ´«Êä²ãÇå¾²ÐÔ£¨TLS£©ÉèÖᣡ£¡£¸ÃÖ¸ÄÏÈ·¶¨ÁËÓÃÓÚ¼ì²â¹ýʱµÄÃÜÂëÌ×¼þºÍÃÜÔ¿½»Á÷»úÖÆµÄÕ½ÂÔ£¬£¬£¬ÌÖÂÛÁ˽¨ÒéµÄTLSÉèÖ㬣¬£¬²¢ÎªÊ¹ÓùýʱµÄTLSÉèÖõÄ×éÖ¯ÌṩÁ˵÷½â½¨Òé¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬£¬£¬ÒѾ­ÓÐÐí¶àÕë¶ÔTLS¼°ÆäʹÓõÄËã·¨µÄй¥»÷£¬£¬£¬Ê¹ÓùýʱЭÒéµÄÍøÂçÅþÁ¬±»µÐÊÖʹÓõÄΣº¦½Ï¸ß£¬£¬£¬Òò´ËNSAÇ¿ÁÒ½¨ÒéÓÃÇ¿¼ÓÃܺÍÈÏÖ¤À´±£»£»£»£»¤ËùÓÐÃô¸ÐÐÅÏ¢µÄЭÒéÉèÖÃÈ¡´ú¹ýʱµÄЭÒéÉèÖᣡ£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/01/05/nsa-releases-guidance-eliminating-obsolete-tls-protocol