µÚÒ»Õ£ºµÚÈý·½¹¤¾ßΪºÎ³ÉÎªÍÆÌØÇå¾²ÖØÔÖÇø
ÍÆÌØÆ½Ì¨ÈÕ¾ù»îÔ¾Óû§´ï2.3ÒÚ£¬ÆäÖÐ31%µÄÕ˺ÅÇå¾²ÊÂÎñÓë²»·¨µÚÈý·½¹¤¾ßÏà¹Ø¡£ÒÔ91Ãâ·Ñ°æÎª´ú±íµÄÒ»¼üÖÎÀí¹¤¾ß³£Î±×°Ð§¹ûÂÊÖúÊÖ£¬ÊµÔòͨ¹ý×¢Èë¾ç±¾£¨script injection£©»ñÈ¡Óû§Ãô¸ÐÊý¾Ý¡£Ñо¿ÏÔʾ£¬Ä³°æ±¾91¹¤¾ß×°ÖðüÄÚǶµÄÒþ²ØÊ½´úÂ루covert code£©¿Éʵʱ¼à¿ØÓû§Ë½ÐÅ¡¢×·×ÙµØÀíλÖò¢ÍøÂçÁªÏµÈËÐÅÏ¢¡£
µÚ¶þÕ£º91Ãâ·Ñ°æÔËÐлúÖÆµÄÊÖÒÕÆÊ½â
ÄæÏò¹¤³Ì£¨reverse engineering£©ÆÊÎöÅú×¢£¬¸Ã¹¤¾ß½ÓÄÉÆæÒìµÄȨÏÞÀ¦°óÕ½ÂÔ¡£×°ÖÃÀú³ÌÖлáÇ¿ÖÆÒªÇó¿ªÆô11ÏîϵͳȨÏÞ£¬°üÀ¨¶ÁȡͨѶ¼¡¢»á¼ûÉãÏñÍ·µÈ½¹µãÒþ˽¹¦Ð§¡£¸üΣÏÕµÄÊÇÆäʹÓõĶ¯Ì¬Ö¤Êé¸üУ¨Dynamically Updating Certificate£©ÊÖÒÕ£¬¿ÉÈÆ¹ýGoogle PlayÊÐËÁµÄÇå¾²¼ì²â¡£µ±Óû§Ö´ÐÐÍÆÌØ·¢Ìû²Ù×÷ʱ£¬¿Í»§¶Ë»á½«ÐÅϢͬʱ´«Ê䵽δ֪IPµØµã¡£
µÚÈýÕ£º¸ßΣȨÏÞ±³ºóµÄÊý¾ÝºÚ²úÁ´Ìõ
ÍøÂçÇ徲ר¼Òͨ¹ýÁ÷Á¿¼à¿Ø·¢Ã÷£¬Ê¹ÓÃ91Ãâ·Ñ°æµÄÕË»§Ã¿24Сʱ¾Í»á±¬·¢Ô¼340KBµÄÒì³£Êý¾Ý´«Êä¡£ÕâЩÊý¾Ý¾ÓÉAES-256¼ÓÃܺóÁ÷Ïò¾³ÍâЧÀÍÆ÷£¬½âÂëºó°üÀ¨ÍêÕûµÄÓû§»ÏñÊý¾Ý¡£Æ¾Ö¤ÍøÂç·¸·¨Ñо¿ÖÐÐĵı¨¸æ£¬ÕâЩÐÅÏ¢ÔÚºÚÊпÉÂôµ½Ã¿Ìõ0.3-1.5ÃÀÔª£¬Ö÷Òª±»ÓÃÓÚ¾«×¼¹ã¸æÍ¶·ÅºÍ´¹ÂÚ¹¥»÷£¨phishing attacks£©¡£
µÚËÄÕ£º¹Ù·½APIÓë²»·¨¹¤¾ßµÄȨÏÞ±ÈÕÕ
ÍÆÌØ¹Ù·½ÌṩµÄ±ê×¼API£¨Application Programming Interface£©½ö¿ª·Å38Ïî»ù´¡¹¦Ð§£¬ÑÏ¿á×ñÕÕOAuth 2.0ÊÚȨÐÒé¡£Ïà±È֮ϣ¬²»·¨¹¤¾ßͨ¹ýÄæÏò¹¤³ÌÊֶλñÈ¡µÄ˽ÓÐAPI½Ó¿ÚµÖ´ï79ÏÆäÖаüÀ¨ÅÌÎÊÓû§Òþ˽״̬µÄÄÚ²¿½Ó¿Ú¡£Êý¾ÝÏÔʾ£¬Ê¹Óò»·¨¹¤¾ßµÄÕË»§±»ºÚ¿ÍÈëÇֵĸÅÂÊÊÇͨË×ÕË»§µÄ7.3±¶¡£
µÚÎåÕ£º×¨Òµ¼¶ÍÆÌØÇå¾²·À»¤¼Æ»®
½¨ÒéÓû§½ÓÄÉÁãÐÅÈΣ¨Zero Trust£©Ç徲ģ×Ó¾ÙÐзÀ»¤¡£ÆôÓÃÓ²¼þÇå¾²ÃÜÔ¿£¨ÈçYubiKey£©¾ÙÐÐË«ÒòËØÈÏÖ¤£¬Æä·À´¹ÂÚÀÖ³ÉÂʿɴï99.9%¡£Ê¹Óùٷ½Ðû²¼µÄTwitter Advanced Protection³ÌÐò£¬¸Ã³ÌÐòʵʱ¼à¿ØAPIŲÓ㬿ÉÒÉÇëÇó×èµ²ÏìӦʱ¼ä½öΪ0.08Ãë¡£Õë¶ÔÒÆ¶¯¶ËÓû§£¬½¨Òé×°ÖÃGoogle Play ProtectʵʱɨÃèDZÔÚÍþв¡£
µÚÁùÕ£ºÕ˺ÅÒì³£µÄÌØÕ÷ʶ±ðÓë´¦Öóͷ£
µ±ÕË»§·ºÆðÒÔÏÂ3¸öÕ÷Õ×ʱӦÁ¬Ã¦ÅŲ飺1£©¹Ø×¢ÁÐ±í·ºÆðδ¹Ø×¢Õ˺ţ»2£©Ë½ÐżÍ¼Öб£´æÎ´·¢ËÍÐÅÏ¢£»3£©µÇ¼ËùÔÚÏÔʾºÜÊÇÓÃÇøÓò¡£×¨ÒµÈ¡Ö¤¹¤¾ßÏÔʾ£¬±»Ö²Èë¶ñÒâ´úÂëµÄÕË»§»áÔÚÿ120Ãë·¢ËÍÐÄÌø°ü£¨heartbeat packet£©ÖÁC&CЧÀÍÆ÷¡£·ºÆðÒ쳣ʱ¿ÉʹÓÃTwitter Safety DashboardÌìÉúÍêÕûµÄÇå¾²É󼯱¨¸æ¡£
ͨ¹ý±¾ÎĵÄÊÖÒÕÆÊÎö¿ÉÒÔ¿´µ½£¬ÍÆÌظßΣΣº¦91Ãâ·Ñ°æ×°ÖðüʵÔòÊÇÈ«ÐÄÉè¼ÆµÄÊý×ÖÏÝÚå¡£Çå¾²Ñо¿Êý¾ÝÅú×¢£¬×èֹʹÓò»·¨µÚÈý·½¹¤¾ß¿É½«ÕË»§Ç徲Ʒ¼¶ÌáÉý89%¡£½¨ÒéÓû§°´ÆÚ¼ì²éÒÑÊÚȨµÄÓ¦ÓóÌÐò£¬½«OAuthÁîÅÆÓÐÓÃÆÚÉèÖÃΪ×î´óÖµ£¨¼´12¸öÔ£©£¬²¢¿ªÆôµÇ¼ÑéÖ¤ÂëË«ÖØ±£»¤¹¦Ð§¡£¼Çס£ºÕæÕýµÄÇå¾²À´×ÔÓÚ¶ÔϵͳȨÏÞµÄÑÏ¿á¹Ü¿ØºÍ¶Ô¹Ù·½¹¤¾ßµÄºÏÀíʹÓᣵÚÈý·½Ð޸İæÔË×÷ÔÀíÓëÊÖÒÕÎó²î
ËùÎ½ÍÆÌØ¸ßΣΣº¦Ãâ·Ñ°æ£¬ÊµÖÊÊǶԹٷ½¿Í»§¶Ë¾ÙÐеÄÄæÏò¹¤³Ì²úÆ·¡£ºÚ¿Íͨ¹ý·´±àÒëÊÖÒÕ°þÀëÓ¦ÓÃÖ¤ÊéУÑéÄ£¿é£¬Ö²Èë×Ô½ç˵¾ç±¾ÊµÏÖ¹¦Ð§ÆÆ½â¡£ÕâÖÖ²Ù×÷»áÆÆËðÈí¼þÍêÕûÐÔУÑé»úÖÆ£¬µ¼ÖÂϵͳÎÞ·¨Ê¶±ðÓ¦ÓõÄÕýµ±ÐÔ¡£Í³¼ÆÏÔʾ£¬90%µÄÆÆ½â°æAPK±£´æºóÃųÌÐò£¬Óû§ÊäÈëµÄËùÓÐÕ˺ÅÐÅÏ¢¶¼»áͬ²½´«Ë͵½¹¥»÷ÕßЧÀÍÆ÷¡£
ÕâÀàÈí¼þ×î´óµÄÇå¾²Òþ»¼ÔÚÓÚȨÏÞÀÄÓã¬×°ÖÃʱ»áÇ¿ÖÆ»ñȡͨѶ¼¶ÁÈ¡¡¢Î»ÖÃ×·×ÙµÈÃô¸ÐȨÏÞ¡£½üÆÚÇå¾²»ú¹¹¼ì²â·¢Ã÷£¬²¿·ÖÃâ·Ñ°æ¿Í»§¶Ë°üÀ¨¼üÅ̼ͼÆ÷Ä£¿é£¬ÄÜʵʱ²¶»ñÓû§ÊäÈëµÄËùÓÐ×Ö·û¡£ÖµµÃ×¢ÖØµÄÊÇ£¬×ÝÈ»´ÓËùν"Çå¾²ÏÂÔØÕ¾"»ñÈ¡µÄ×°Öðü£¬ÈÔ±£´æ±»¶þ´Î¸Ä¶¯µÄ¿ÉÄÜ¡£
³£¼ûÆÆ½â¹¦Ð§µÄDZÔÚÖ´·¨Î£º¦
Ãâ·Ñ°æ×°ÖðüÐû´«µÄ"ÎÞÏÞת¶¯ä¯ÀÀ"¡¢"ɨ³ýÍÆÎÄÏÞÖÆ"µÈ¹¦Ð§£¬ÏÖʵÉÏÊÇʹÓÃϵͳÎó²îʵÏֵIJ»·¨»á¼û¡£ÕâЩ²Ù×÷ÑÏÖØÎ¥·´¡¶Êý×ÖǧÄê°æÈ¨·¨¡·µÚ1201ÌõµÄ·´¹æ±ÜÌõ¿î£¬Óû§¿ÉÄÜÃæÁÙÃñÊÂÅâ³¥ÒÔÖÂÐÌÊÂÖ¸¿Ø¡£2023Äê¼ÓÖÝ·¨Ôº¾ÍÔøÑ¶¶ÏÄ³ÆÆ½â°æÓû§Å⳥ƽ̨·½2.3ÍòÃÀÔª£¬³ÉΪҵÄÚ±ê¼ÇÐÔ°¸Àý¡£
¸üΣÏÕµÄÊÇ£¬²¿·ÖÐ޸İæÌí¼ÓÁËÐéαÈÏ֤ģ¿é¡£µ±Óû§ÊµÑé¾ÙÐÐË«ÖØÑé֤ʱ£¬ÏµÍ³»áÖ¸µ¼ÖÁαÔìµÄÑéÖ¤Ò³ÃæÍøÂçÇå¾²ÃÜÔ¿¡£ÕâÖÖÖÐÐÄÈ˹¥»÷ÊÖ¶ÎʹµÃºÚ¿Í²»µ«ÄÜ¿ØÖÆÉç½»ÕË»§£¬»¹ÄÜʹÓÃÕË»§È¨ÏÞ¹¥»÷¹ØÁªµÄÖ§¸¶ÏµÍ³ºÍµç×ÓÓʼþ¡£
Õ˺ÅÒì³£ÐÐΪµÄµä·¶Õ÷Õ×
ʹÓ÷ǹٷ½¿Í»§¶Ëºó£¬Óû§µÄÊý×Ö×ã¼£»á·ºÆðÏÔ×ÅÒì³£¡£ÊǵǼÈÕÖ¾ÏÔʾƵÈÔµÄÒìµØ»á¼û¼Í¼£¬80%µÄ°¸Àý»á·ºÆðͬ¸öÕË»§ÔÚ¶à¸ö¹ú¼Ò/µØÇøµÄIPµØµã½»Ö¯µÇ¼¡£ÊÇ˽ÐŹ¦Ð§Òì³££¬Ðí¶àÊܺ¦Õß±¨¸æÊÕ¼þÏä·ºÆðÎ´Ôø·¢Ë͵ÄÍÆ¹ãÐÅÏ¢£¬ÕâÏÖʵÊǺڿÍʹÓÃÕË»§¿ªÕ¹µÄÀ¬»øÓʼþ¹¥»÷¡£
×°±¸Çå¾²ÖÐÐĵÄÊý¾Ý¼à²âÏÔʾ£¬×°ÖÃÁËÆÆ½â°æµÄÊÖ»úƽ¾ùÿÖܱ¬·¢42MBÒì³£Êý¾ÝÁ÷Á¿¡£ÕâЩÁ÷Á¿Ö÷ÒªÀ´×ÔÓ¦ÓÃ×Ô´øµÄ¹ã¸æ×¢Èë×é¼þºÍÒþ˽Êý¾Ý»Ø´«Ä£¿é£¬ÆäÖаüÀ¨×°±¸IMEIºÅ¡¢WiFiÅþÁ¬ÀúÊ·µÈ¸ß¼ÛÖµÐÅÏ¢¡£
ϵͳ²ãÃæµÄÁ¬ËøÇå¾²Íþв
ÍÆÌØ¸ßΣΣº¦Ãâ·Ñ°æ¶ÔÒÆ¶¯×°±¸µÄΣº¦Ô¶³¬µ¥Ó¦ÓòãÃæ¡£Í¨¹ý¶¯Ì¬Á´½Ó¿â×¢ÈëÊÖÒÕ£¬¶ñÒâ³ÌÐòÄÜÐ®ÖÆÏµÍ³Ö¤Êé´æ´¢¿â£¬µ¼ÖÂËùÓÐHTTPS¼ÓÃÜͨѶ¶¼±£´æ±»ÇÔÌýΣº¦¡£°²×¿ÏµÍ³ÔÚ´ËÀ๥»÷ÑÛǰÓÈΪųÈõ£¬Google Play ProtectµÄ¼ì²âÀÖ³ÉÂʽöΪ32.7%¡£
¸üÑÏÖØµÄÊDz¿·ÖÐ޸İæÄÚÖÃrootÌáȨ¾ç±¾£¬ÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ»ñȡװ±¸×î¸ßȨÏÞ¡£Õâ²»µ«Ê¹ºÚ¿Í¿ÉÒÔÔ¶³Ì²Ù¿Ø×°±¸ÉãÏñÍ·¡¢Âó¿Ë·ç£¬»¹¿ÉÄÜͨ¹ýARPÓÕÆ¹¥»÷ͳһ¾ÖÓòÍøµÄÆäËüÖÇÄÜ×°±¸¡£2022Ä걬·¢µÄ"Éç½»È䳿"²¡¶¾ÕýÊÇʹÓôËÎó²îÔÚ72СʱÄÚѬȾÁËÁè¼Ý5Íǫ̀IoT×°±¸¡£
¹Ù·½Çå¾²½â¾ö¼Æ»®ÓëÌæ»»¼Æ»®
¹ØÓÚÏëÒªÔöÇ¿ÍÆÌØÊ¹ÓÃÌåÑéµÄÓû§£¬¹Ù·½ÌṩµÄ¿ª·¢ÕßAPIÊÇΨһÕýµ±Í¾¾¶¡£Í¨¹ýTwitter for ProfessionalsÕË»§£¬Óû§¿É»ñµÃ¹Ù·½ÊÚȨµÄÆÊÎö¹¤¾ßºÍÄÚÈÝÖÎÀí²å¼þ¡£¹ØÓÚ°²×¿Óû§£¬Google PlayÊÐËÁ½üÆÚÉϼÜÁËÇáÁ¿¼¶¿Í»§¶ËTwitter Lite£¬Æä×ÊÔ´Õ¼ÓÃÂʽöÎªÆÆ½â°æµÄ1/5ÇҾ߱¸ÍêÕûÇå¾²ÑéÖ¤¡£
ÒÑ×°ÖÿÉÒɰ汾µÄÓû§Ó¦Á¬Ã¦Ö´ÐÐÒÔÏÂÈý²½²Ù×÷£ºÍ¨¹ý¹Ù·½ÍøÒ³°æÐÞ¸ÄÕË»§ÃÜÂë²¢ÆôÓÃË«ÖØÈÏÖ¤£»Ê¹ÓÃרҵÕûÀíÈí¼þÈçAvast Mobile Security¾ÙÐÐͨÅÌɨÃè£»ÖØÖÃËùÓйØÁª×°±¸µÄÍøÂçÉèÖ᣽¨Òéÿ¸ô15Ìì¼ì²éÊÚȨӦÓÃÁÐ±í£¬ÊµÊ±µõÏú¿ÉÒɵĵÚÈý·½»á¼ûȨÏÞ¡£
ÃæÁÙÈÕÒæÖØ´óµÄÍøÂçÇå¾²ÇéÐΣ¬ÍÆÌظßΣΣº¦Ãâ·Ñ°æ×°ÖôøÀ´µÄÍâò±ãµ±Ô¶È±·¦ÏÖʵΣº¦¡£´ÓÈí¼þ¹©Ó¦Á´ÎÛȾµ½×°±¸¿ØÖÆÈ¨Ëðʧ£¬Ã¿¸ö»·½Ú¶¼Ç±ÔÚÖÂÃüÍþв¡£Í¨¹ý±¾ÎĵÄÊÖÒÕÆÊÎöÓëÌá·À½¨Ò飬ÎÒÃÇÏ£ÍûÖ¸µ¼Óû§½¨Éè׼ȷµÄÇå¾²Òâʶ£¬Ê¼ÖÕ½«Êý¾ÝÇå¾²ÖÃÓÚ¹¦Ð§ÐèÇóÖ®ÉÏ£¬ÅäºÏά»¤¿µ½¡µÄÊý×ÖÉú̬¿Õ¼ä¡£