声之形
分类: 爱在旅途

A | The Department of Homeland Security is telling state and local governments to update software and beef up security around devices connected to the nationwide Emergency Alert System (EAS). The recommendation comes days after security researcher Ken Pyle revealed vulnerabilities in devices used by officials to encode EAS alerts.,Pyle told KerbsOnSecurity that he first discovered the vulnerabilities in 2019 after buying old EAS equipment on eBay. He quickly found the vulnerabilities and alerted the FBI, DHS, and the manufacturer of the devices. Pyle decided to give the manufacturer and government time to address the issue before going public.,DHS Inspector General Overseeing Jan.6 Secret Service Probe Previously Misled Investigators: Report4 August, 12:27 GMT,He started to worry after the Jan 6, 2021 riot at the US Capitol, fearing that the vulnerabilities could be used “to start a civil war.”,That is because despite a patch being issued in 2019, many of the devices have not been updated either because they are too old for the new firmware or because of simple neglect by the operators. Pyle also says that many operators do not perform basic security measures recommended by the manufacturer, like changing the default password and putting the devices behind a firewall.,This is a problem because of the way EAS messages are distributed. There is no central authority and the process is automated in most cases. This means that someone could issue an alert locally and as long as it is accepted as a real EAS alert, it could spread nationwide.,“These devices are designed such that someone locally can issue an alert, but there’s no central control over whether I am the one person who can send or whatever,” Pyle told KerbsOnSecurity. “If you are a local operator, you can send out nationwide alerts. That’s how easy it is to do this.”,One device obtained by Pyle was a non-functional EAS device, purchased from an electronics recycling company. While the device no longer operated, the person who discarded it and the recycling company neglected to wipe the hard drive, giving Pyle access to cryptographic keys allowing him to broadcast messages on Comcast’s network, the third largest cable company in the US.,Comcast told KerbsOnSecurity in a statement that the EAS was lost by a third-party shipper and that the keys and credentials found on the device will no longer work on their system. They also thanked Pyle for his research and for informing them about the issue.,EAS vulnerabilities have been exploited in the past. In 2013, someone hacked the EAS networks in Great Falls, Montana, and Marquette, Michigan, using their access to issue an alert saying that zombies are rising from their graves. That same prank was repeated in Indiana in 2017. There have been other incidents, though they did not include zombies.。 三名新加坡籍男子因涉嫌参与与诈骗有关的洗钱活动,于8月24日(星期六)被控上法庭。据新加坡警察部队8月23日(星期五)晚间发布的公告,这起案件源自警方在8月初接获的一起冒充政府官员的诈骗案。

B | 受害者在骗子的指示下,将近3万8000元转入一个本地银行账户。经过进一步调查,反诈骗指挥处的执法人员确认了一名26岁男子的身份,他涉嫌协助诈骗团伙获取银行账户并进行洗钱活动。该男子于8月22日(星期四)在后港一带被捕。警方在行动中起获了超过40部手机、一台点钞机和超过60张电话卡。此外,执法人员在进一步调查中发现并逮捕了另外两名试图从兀兰关卡出境的男子,年龄分别为34岁和36岁。这两名男子涉嫌为诈骗团伙获取手机和电话卡以协助诈骗。警方从他们身上查获了五部手机、四张电话卡及约3万元现金。三人已在8月24日被控上法庭,罪名为共谋欺骗罪。如果罪名成立,初犯者最高可被判处三年监禁、罚款或两者兼施。目前三人还押接受调查,案件将于8月30日再次开庭审理。

C |
Current article:http://wqndc.minshixuanhabing.bond/news/20260826_7010733.html
Published on:11:36:53