¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180808

°ä²¼¹¦·ò 2018-08-08

¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÔìÆ½âWPAºÍWPA2ÎÞÏßÃÜÂëµÄмò»¯²½Öè


Hashcat¿ª·¢ÈËÔ±Jens Steube·¢ÏÖÒ»ÖÔìÆ½âWPA/WPA2ÎÞÏßÃÜÂëµÄ¸ü¿ì¸üµ¥Ò»µÄ²½Öè¡£¡£¡£¡£¡£´ÓÇ°ÆÆ½âWPA/WPA2¼ÓÃܺÍ̸ÊÇÒ»¸ö·±³ÁºÄʱµÄ¹ý³Ì£¬ £¬£¬£¬£¬±ØÒªÆÚ´ýºÏ·¨Óû§µÇ¼²¢À¹½ØÆäËÄ´ÎÎÕÊֵįëÈ«ÐÅÏ¢¡£¡£¡£¡£¡£ÐµĹ¥»÷Õ½ÊõÔÊÐí¹¥»÷ÕßÖ±½Ó´Ó·ÓÉÆ÷ÖлñµÃPMKID£¬ £¬£¬£¬£¬¶øÎÞÐèÆÚ´ýºÏ·¨Óû§µÇ¼£¬ £¬£¬£¬£¬Ò²ÎÞÐè²¶»ñËÄ´ÎÎÕÊÖÐÅÏ¢¡£¡£¡£¡£¡£¹¥»÷Õß¾ùÔÈÖ»±ØÒªÔ¼10·ÖÖÓ¾ÍÄܹ»»ñµÃÆäËùÐèµÄÐÅÏ¢£¬ £¬£¬£¬£¬¶øºóÄܹ»ÆðÍ·±©Á¦ÆÆ½â¹ý³Ì¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-method-simplifies-cracking-wpa-wpa2-passwords-on-80211-networks/


¡¾Êý¾Ýй¶¡¿Ä«Î÷¸çÒ»Ò½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ £¬£¬£¬£¬Ô¼200Íò»¼ÕßµÄÐÅϢй¶


°²È«×êÑÐÔ±Bob Diachenkoͨ¹ýShodan·¢ÏÖÒ»¸öÄ«Î÷¸çÒ½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ £¬£¬£¬£¬¸ÃMongoDBÊý¾Ý¿âÔ̺¬Ô¼200Íò»¼ÕßµÄÒ½ÁÆÐÅÏ¢£¬ £¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢±£ÏÕÐÅÏ¢¡¢²Ð¼²Çé¿öºÍ¼ÒͥסַµÈÐÅÏ¢¡£¡£¡£¡£¡£Diachenko·¢ÏÖ¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþÓòÃûΪhovahealth.comºÍefimed.care£¬ £¬£¬£¬£¬ÔÚ֪ͨHova Health¹«Ë¾ºó£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÔÚÈý¸öÓ×ʱÄڵõ½±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/health-care-data-of-2-million-people-in-mexico-exposed-online/


¡¾Êý¾Ýй¶¡¿TCMÒøÐÐÒòÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÓû§µÄÃô¸ÐÊý¾Ýй¶


TCMÒøÐÐÊÇICBA BancardµÄ×Ó¹«Ë¾£¬ £¬£¬£¬£¬ËüÊÇÃÀ¹ú750¶à¼ÒÓ×ÐͺÍÉçÇøÒøÐеÄÐÅÓþ¿¨¿¯ÐÐÉÌ¡£¡£¡£¡£¡£¸ÃÒøÐа䷢ÆäÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÐÅÓþ¿¨ÉêÇëÈ˵ÄÐÅÏ¢ÔÚ2017Äê3Ô³õÖÁ2018Äê7ÔÂÖÐѮ֮¼äµÄ16¸öÔÂÄÚº­Ïß¶³ö¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬ÉêÇëÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚºÍÉç±£ºÅÂëµÈ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Îª²»µ½1ÍòÈË¡£¡£¡£¡£¡£TCM³ÆÆäÔÚ2018Äê7ÔÂ16ÈÕ·¢ÏÖÁ˸ÃÎÊÌ⣬ £¬£¬£¬£¬²¢ÔÚµÚ¶þÌì½øÐÐÁ˽¨¸´¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75078/data-breach/tcm-bank-data-leak.html


¡¾°²È«²¥±¨¡¿Îå½Ç´óÂ¥²»ÈÝÊ¿±øÔÚÃô¸Ð»ùµØÊ¹ÓÿɽøÐÐGPS¶¨Î»µÄµç×ÓÉ豸


ƾ¾ÝÎå½Ç´óÂ¥µÄкÅÁ £¬£¬£¬£¬ÔÚÃô¸Ð»ùµØ»òijЩ¸ß·çÏÕÕ½µØµØÓòµÄ¾ü¶ÓºÍ¹ú·ÀÈËÔ±½«²»±»ÔÊÐíʹÓÃÄܹ»½øÐеØÀí¶¨Î»µÄ½¡Éí×·×ÙÆ÷ºÍÊÖ»úappµÈ¡£¡£¡£¡£¡£ÕâЩµØÀí¶¨Î»Ö°ÄÜ¿ÉÄܻᶳöÓ×ÎÒÐÅÏ¢¡¢µØÎ»¡¢ÈÕ³£»£»£»£»£»£»î¶¯ºÍ¹ú·ÀÈËÔ±µÄÊýÁ¿µÈÐÅÏ¢£¬ £¬£¬£¬£¬²¢¿ÉÄÜÔì³ÉÒâ±íµÄ°²È«ºó¹ûºÍÔö³¤¹¤×÷·çÏÕ¡£¡£¡£¡£¡£ÕâЩÏÞ¶ÈÔ̺¬½¡Éí×·×ÙÆ÷¡¢ÊÖ»ú¡¢Æ½°åµçÄÔ¡¢ÖÇÄÜÍó±íºÍÆäËüÀûÓ÷¨Ê½µÄGPSÖ°ÄÜ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/pentagon-restricts-use-fitness-trackers-other-devices


¡¾°²È«²¥±¨¡¿Facebook°ä·¢¿ªÔ´¸ß»úÄÜTLS¿âFizz£¬ £¬£¬£¬£¬Ô®ÊÖÍÆ¶¯±é¼°TLS 1.3ºÍ̸


FizzÊÇÓÃC++ 14±àдµÄÒ»¸ö¿¿µÃסµÄ¡¢¸ß»úÄܵÄTLS¿â£¬ £¬£¬£¬£¬ËüÖ§³ÖËùÓеÄÖØÒªÎÕÊÖģʽ£¬ £¬£¬£¬£¬ÓµÓÐ׳´óµÄ¼ÓÃÜËã·¨ºÍÓÅÔ½µÄ»úÄÜ¡£¡£¡£¡£¡£×ÔÉϸöÔµ×ÒÔÀ´£¬ £¬£¬£¬£¬GoogleµÄChromeä¯ÀÀÆ÷ÒÑÆðÍ·½«ËùÓеķÇHTTPSÍøÕ¾ÏóÕ÷Ϊ²»°²È«£¬ £¬£¬£¬£¬ÒÔÆÈÊ¹ÍøÕ¾ÖÎÀíÔ±Çл»µ½HTTPS¡£¡£¡£¡£¡£FacebookÔÚGitHubÉÏ¿ªÔ´ÁËFizz£¬ £¬£¬£¬£¬ÒÔÔ®ÊÖÍÆ¶¯TLS 1.3ºÍ̸µÄ±é¼°¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/fizz-tls-ssl-library.html


¡¾·ì϶²¹¶¡¡¿Google°ä²¼8ÔÂAndroid°²È«¸üУ¬ £¬£¬£¬£¬¹²½¨¸´43¸ö°²È«·ì϶


ƾ¾ÝGoogle×îа䲼µÄAndroid°²È«²¼¸æ£¬ £¬£¬£¬£¬8ÔµÄAndroid°²È«¸üÐÂÔ̺¬2018-08-01ºÍ2018-08-05Á½¸ö°²È«²¹¶¡¼¶±ð£¬ £¬£¬£¬£¬½¨¸´ÁËÔ̺¬¿ò¼Ü¡¢¶àýÌå¿ò¼Ü¡¢ÏµÍ³¡¢Äںˡ¢¸ßͨ×é¼þ¡¢¸ßͨ¹ØÔ´×é¼þµÈ×é¼þÄÚµÄ43¸ö°²È«·ì϶¡£¡£¡£¡£¡£Googleͬʱ»¹°ä²¼ÁËPixel/NexusµÄ8Ô°²È«¸üУ¬ £¬£¬£¬£¬¹²½¨¸´ÁË28¸ö°²È«·ì϶¡£¡£¡£¡£¡£½¨ÒéÓйØÓû§¾¡¿ì½øÐÐÉý¼¶¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://source.android.com/security/bulletin/2018-08-01