CERT-FR recommends completely deactivate Wi-Fi whenever it’s not in use
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述。好的,我先看看文章说了什么。 文章主要讲的是CERT-FR建议用户在不用Wi-Fi的时候完全关闭它,以减少风险。他们提到Wi-Fi有很多漏洞,包括无线接口、应用、操作系统和硬件层面的。CERT-FR还建议用户只从官方商店下载应用,审查权限,保持设备更新和重启,使用VPN在公共Wi-Fi上,并禁用自动连接到开放网络的功能。 文章还提到智能手机因为处理大量数据和多种功能,成为网络情报攻击的主要目标。各种协议如Wi-Fi、蓝牙、NFC和蜂窝网络都有弱点,可能被用来拦截数据或部署间谍软件。还有零点击漏洞可以让设备在用户不知情的情况下被攻破。 CERT-FR的报告里还提到了保护移动设备的建议,比如关闭不用的Wi-Fi,禁用自动连接,避免使用公共网络,并在必要时使用VPN。 所以总结起来就是:CERT-FR建议用户在不使用Wi-Fi时关闭它,并采取其他安全措施来保护设备免受攻击。 </think> CERT-FR建议用户在不使用Wi-Fi时完全关闭它,并采取其他安全措施(如使用VPN、避免连接公共网络)来降低风险。智能手机因处理大量数据和多种功能而成为网络攻击的主要目标。 2025-12-15 10:1:1 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

CERT-FR recommends completely deactivate Wi-Fi whenever it’s not in use

Pierluigi Paganini December 15, 2025

The CERT-FR (French Computer Emergency Response Team) is advising iPhone and Android users to fully disable Wi-Fi to reduce risk.

CERT-FR warns iPhone and Android users to fully disable Wi-Fi to reduce exposure, citing multiple vulnerabilities across wireless interfaces, apps, OSs, and even hardware. The agency reiterates basic hygiene: install apps only from official stores, review permissions, keep devices updated and rebooted, use a VPN on public Wi-Fi, and disable auto-join on open networks.

Smartphones, handling vast amounts of data and multiple features, are prime targets for cyber intelligence. They have extensive vulnerabilities across wireless interfaces, apps, operating systems, and hardware. Weaknesses in protocols like Wi-Fi, Bluetooth, NFC, and cellular networks allow data interception or spyware deployment. Sophisticated zero-click exploits can compromise devices without user action, leaving minimal traces. State-sponsored actors and Private Sector Offensive Actors (PSOAs) exploit these flaws, increasing threats and complicating attribution. Mobile devices face a broad and growing attack surface from advanced offensive capabilities.

“The ubiquity and systematic use of smartphones, along with the increasing number of features and data they handle, make them targets of interest for the acquisition of cyber intelligence.” reads the report “MOBILE PHONES – THREAT LANDSCAPE SINCE 2015” published by CERT-FR. “These everyday devices exhibit multiple vulnerabilities as well as a significant attack surface across multiple layers of the device architecture. These vulnerabilities may reside within wireless interfaces, applications, operating systems, and even within hardware components. The numerous communication protocols used, such as cellular network, Wi-Fi, Bluetooth and NFC, suffer from several weaknesses facilitating the interception of exchanged information, or even the alteration of data in order to deploy spyware code on the devices.”

The report includes a set of recommendations to protect mobile devices.

Wi-Fi, especially public or poorly configured networks, can be exploited for man-in-the-middle attacks to intercept or alter data on connected devices. Real cases include Wi-Fi flaws used to deploy spyware, commercial interception tools, and fake access points for phishing or malware.

Recommended defenses include turning off Wi-Fi when not needed, disabling auto-connect, avoiding public networks, and using a VPN when necessary.

“Recommendations on Wi-Fi usage:

  • Deactivate Wi-Fi when it is not in use.
  • Disable automatic connection to known or open Wi-Fi networks.
  • Do not connect to public Wi-Fi access points unless it is necessary and if so, use a VPN.” continues the report.

Mobile wireless interfaces (2G–5G, Wi-Fi, Bluetooth, NFC) let devices communicate via radio waves and have exploitable vulnerabilities. Attacks target these interfaces in three ways: passive interception to capture identifiers and data, active interception to decrypt or hijack communications, and data modification to alter exchanges and compromise devices.

CERT-FR

France and the UK launched the Pall Mall Process in late 2023 to curb the misuse of commercial cyber intrusion tools. The initiative promotes cooperation, threat sharing, and legal safeguards.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Wi-Fi)




文章来源: https://securityaffairs.com/185702/hacking/cert-fr-recommends-completely-deactivate-wi-fi-whenever-its-not-in-use.html
如有侵权请联系:admin#unsafe.sh