- 作者:王建
- 来源:血战钢锯岭
- 发布时间:2026-08-26
lol
Researcher: National Emergency Alert System is Easy To Exploit_我的网站

一 | The Department of Homeland Security is telling state and local governments to update software and beef up security around devices connected to the nationwide Emergency Alert System (EAS). The recommendation comes days after security researcher Ken Pyle revealed vulnerabilities in devices used by officials to encode EAS alerts.,Pyle told KerbsOnSecurity that he first discovered the vulnerabilities in 2019 after buying old EAS equipment on eBay. He quickly found the vulnerabilities and alerted the FBI, DHS, and the manufacturer of the devices. Pyle decided to give the manufacturer and government time to address the issue before going public.,DHS Inspector General Overseeing Jan.6 Secret Service Probe Previously Misled Investigators: Report4 August, 12:27 GMT,He started to worry after the Jan 6, 2021 riot at the US Capitol, fearing that the vulnerabilities could be used “to start a civil war.”,That is because despite a patch being issued in 2019, many of the devices have not been updated either because they are too old for the new firmware or because of simple neglect by the operators. Pyle also says that many operators do not perform basic security measures recommended by the manufacturer, like changing the default password and putting the devices behind a firewall.,This is a problem because of the way EAS messages are distributed. There is no central authority and the process is automated in most cases. This means that someone could issue an alert locally and as long as it is accepted as a real EAS alert, it could spread nationwide.,“These devices are designed such that someone locally can issue an alert, but there’s no central control over whether I am the one person who can send or whatever,” Pyle told KerbsOnSecurity. “If you are a local operator, you can send out nationwide alerts. That’s how easy it is to do this.”,One device obtained by Pyle was a non-functional EAS device, purchased from an electronics recycling company. While the device no longer operated, the person who discarded it and the recycling company neglected to wipe the hard drive, giving Pyle access to cryptographic keys allowing him to broadcast messages on Comcast’s network, the third largest cable company in the US.,Comcast told KerbsOnSecurity in a statement that the EAS was lost by a third-party shipper and that the keys and credentials found on the device will no longer work on their system. They also thanked Pyle for his research and for informing them about the issue.,EAS vulnerabilities have been exploited in the past. In 2013, someone hacked the EAS networks in Great Falls, Montana, and Marquette, Michigan, using their access to issue an alert saying that zombies are rising from their graves. That same prank was repeated in Indiana in 2017. There have been other incidents, though they did not include zombies.。 8 月 25 日消息,如今电信网络诈骗形成了“线上诱骗被害人、线下专人取现”的完整链条,为躲避警方抓捕,取现团伙不断翻新手段。据央视新闻报道,今年 6 月,甘肃兰州警方就破获了一起案件:电诈团伙利用无人机和无线监控设备,“空地协同”对警方行动进行盯梢。报道提到,今年 6 月初,兰州市公安局安宁分局低空综合治理中心的侦测系统频频发出预警:在辖区内,多次侦测到未经报备许可的轻型无人机异常活动(注:即“黑飞”活动)。

二 | 而在飞行期间,这些“黑飞”无人机也多次超过 120 米的限飞高度进行飞行。

三 | 安宁警方新投入使用的公安智能体,在对“黑飞”无人机的监测数据与最近的刑事警情数据进行串并分析后,得出了一个令人意外的结果 —— 电诈团伙为了确保取现人员与资金的安全,竟然用上了无人机。民警调取公共场所视频还发现,该团伙还在取现点位装监控。空中无人机盯警车,地面监控盯现场,让抓捕每次都“只差一步”。警方摸清作案套路后决定将计就计,提前布控,将取现的嫌疑人及“黑飞”团伙一网打尽。最终,警方现场查获作案手机 4 部、红外摄像机 2 台、便携摄像头 7 台、无人机设备 2 套、移动 Wi-Fi 设备 2 部,另外还有 35,000 元涉案赃款。

四 | 据 3 名犯罪嫌疑人交代,从今年 5 月起,他们在甘肃和青海多地利用无人机、便携监控等设备作案 42 起,取现被骗资金 100 余万元,非法获利 7 万余元。目前,这 3 名犯罪嫌疑人已被依法刑事拘留,案件正在进一步侦办当中。广告声明:文内含有的对外跳转链接(包括不限于超链接、二维码、口令等形式),用于传递更多信息,节省甄选时间,结果仅供参考,包含外链的文章均包含本声明。

五 |
Current article:http://vhxz51.recuigoutoubaozukai.pics/5t1/20260826/8240859.html
Published on:00:16:14
- 本文标签:
- 金婚
