AppleÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪
Ðû²¼Ê±¼ä 2020-12-161.AppleÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î

AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
2.Golang XMLÆÊÎöÆ÷±£´æ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄÎó²î

MattermostÓëGolangÁªºÏÅû¶ÁËGolang XMLÆÊÎöÆ÷ÖеÄ3¸öÒªº¦Îó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»Îȹ̣¨CVE-2020-29509£©¡¢Ö¸Áî²»Îȹ̣¨CVE-2020-29510£©ºÍÔªËØ²»Îȹ̣¨CVE-2020-29511£©Îó²î¡£¡£¡£¡£¡£¡£¡£ÕâÈý¸öÎó²îÊÇÇ×½üÏà¹ØµÄ£¬£¬£¬£¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXML±ê¼ÇÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µÀú³ÌÖб¬·¢Á˱äÒìËùµ¼Öµġ£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÓÕÆÒÀÀµÓÚXMLÆÊÎöÆ÷µÄÖÖÖÖSAMLʵÏÖ£¬£¬£¬£¬£¬ÒÔÍêÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/
3.GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪

GmailÔÚ24СʱÄÚÓÖ±¬·¢ÖÐÖ¹£¬£¬£¬£¬£¬Óû§¿ÉÒÔ»á¼ûÆäµç×ÓÓʼþ£¬£¬£¬£¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£¡£¡£¡£¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØµãʱ£¬£¬£¬£¬£¬»áÁ¬Ã¦ÊÕµ½Ò»Ìõת´ïʧ°ÜÐÂÎÅ£¬£¬£¬£¬£¬²¢ÌáÐÑÕÒ²»µ½µØµã¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤DownDetectorÊý¾Ý£¬£¬£¬£¬£¬´Ë´ÎGmailÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬GoogleÉùÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬£¬£¬µ«ÖÐÖ¹Ôµ¹ÊÔÓÉÉв»Ã÷È·¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÒªº¦ÏµÍ³å´»ú

ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¶à¸öÒªº¦ÏµÍ³å´»ú¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö÷ÒªÔÚÔÚŲÍþº£°¶Ä±»®¶ÉÂÖ£¬£¬£¬£¬£¬²¢ÔÚ±±¼«ºÍÄϼ«¾ÙÐк½ÐС£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬Ô¤¼Æ´Ë´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³ÉÖØ´óµÄ²ÆÎñÓ°Ï죬£¬£¬£¬£¬µ«ÏÖÔÚÓм¸¸öÒªº¦ÏµÍ³·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚÌåÏÖ£¬£¬£¬£¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬£¬£¬¶ø¹«Ë¾Ò²ÒѽÓÄÉ×ۺϲ½·¥ÒÔÏÞÖÆ¹¥»÷Ôì³ÉµÄΣº¦¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826
5.unit42Ðû²¼Ä¾ÂíPyMICROPSIAµÄÆÊÎö±¨¸æ

unit42Ðû²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÇøµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬£¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£¡£¡£¡£¡£¡£¡£PyMICROPSIA¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§£¬£¬£¬£¬£¬°üÀ¨ÎļþÉÏ´«¡¢ÓÐÓøºÔØÏÂÔØºÍÖ´ÐС¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢É¨³ýä¯ÀÀÀúÊ·¼Í¼ºÍÉèÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐÐÏÂÁîµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ËüÓÉPython±àд£¬£¬£¬£¬£¬Ê¹ÓÃPyInstallerÖÆ³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬²¢Í¨¹ýÔËÐÐÑ»·À´ÊµÏÖÆäÖ÷Òª¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/pymicropsia/
6.BugcrowdÐû²¼Î´À´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ

BugcrowdÐû²¼ÁËδÀ´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖÜÈ«ÏÈÈÝÁËCOVID-19ÔõÑùÖØÐ½ç˵¿çÐÐÒµµÄÍøÂçÇ徲ʵ¼ù¡£¡£¡£¡£¡£¡£¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬£¬£¬Ç°Ê®¸öÔÂÌá½»µÄÎó²îÊýÄ¿ÔöÌíÁË24£¥¡£¡£¡£¡£¡£¡£¡£ÔÚ2020ÄêÌá½»µÄÊ®´óÎó²îÖУ¬£¬£¬£¬£¬Óа˸öÒ²·ºÆðÔÚ2019ÄêÁбíÖУ¬£¬£¬£¬£¬Õâ˵Ã÷ÖÎÀíÒÑ֪Σº¦ÈÔÈ»ÊÇ´ó´ó¶¼ÆóÒµÃæÁÙµÄÌôÕ½¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ìá½»µÄ×î¶àµÄÎó²îÊÇÓÉÓÚ»á¼û¿ØÖÆÔì³ÉµÄÆÆË𣬣¬£¬£¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾Îó²î£¨XSS£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/


¾©¹«Íø°²±¸11010802024551ºÅ