
一 | The Department of Homeland Security is telling state and local governments to update software and beef up security around devices connected to the nationwide Emergency Alert System (EAS). The recommendation comes days after security researcher Ken Pyle revealed vulnerabilities in devices used by officials to encode EAS alerts.,Pyle told KerbsOnSecurity that he first discovered the vulnerabilities in 2019 after buying old EAS equipment on eBay. He quickly found the vulnerabilities and alerted the FBI, DHS, and the manufacturer of the devices. Pyle decided to give the manufacturer and government time to address the issue before going public.,DHS Inspector General Overseeing Jan.6 Secret Service Probe Previously Misled Investigators: Report4 August, 12:27 GMT,He started to worry after the Jan 6, 2021 riot at the US Capitol, fearing that the vulnerabilities could be used “to start a civil war.”,That is because despite a patch being issued in 2019, many of the devices have not been updated either because they are too old for the new firmware or because of simple neglect by the operators. Pyle also says that many operators do not perform basic security measures recommended by the manufacturer, like changing the default password and putting the devices behind a firewall.,This is a problem because of the way EAS messages are distributed. There is no central authority and the process is automated in most cases. This means that someone could issue an alert locally and as long as it is accepted as a real EAS alert, it could spread nationwide.,“These devices are designed such that someone locally can issue an alert, but there’s no central control over whether I am the one person who can send or whatever,” Pyle told KerbsOnSecurity. “If you are a local operator, you can send out nationwide alerts. That’s how easy it is to do this.”,One device obtained by Pyle was a non-functional EAS device, purchased from an electronics recycling company. While the device no longer operated, the person who discarded it and the recycling company neglected to wipe the hard drive, giving Pyle access to cryptographic keys allowing him to broadcast messages on Comcast’s network, the third largest cable company in the US.,Comcast told KerbsOnSecurity in a statement that the EAS was lost by a third-party shipper and that the keys and credentials found on the device will no longer work on their system. They also thanked Pyle for his research and for informing them about the issue.,EAS vulnerabilities have been exploited in the past. In 2013, someone hacked the EAS networks in Great Falls, Montana, and Marquette, Michigan, using their access to issue an alert saying that zombies are rising from their graves. That same prank was repeated in Indiana in 2017. There have been other incidents, though they did not include zombies.。 任天堂尚未官宣的《塞尔达传说:时之笛》Switch 2版本,近日被瑞士零售商wog.ch提前上架。商品页面显示,该作将于2026年12月1日正式发售,定价79.90瑞士法郎。 Reddit社区r/GamingLeaksAndRumours迅速注意到这一信息。有用户指出,该零售商过去曾多次在官方公布前准确列出游戏发售日期,其中最近一次成功案例是Switch版《鬼泣5》——该作的发售日正是由这家零售商提前泄露,随后得到官方证实。目前,任天堂方面尚未对12月1日这一日期作出任何回应。《塞尔达传说:时之笛》Switch 2版本的存在本身也尚未获得官方确认,此次零售商页面的突然上线是否为操作失误还是确有其事,仍有待观察。考虑到该零售商过往的"准确战绩",这一消息的可信度已引发玩家社区的高度关注。

二 | 本文由游民星空制作发布,未经允许禁止转载。

三 | 更多相关资讯请关注:塞尔达传说:时之笛 重制版专区。
Current article:http://hcm.gamajionghuanmuniuzhuanguchu.cyou/list_si840la/m0rtz.html
Published on:01:37:53