AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»£»GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔ­ÓÉδ֪

Ðû²¼Ê±¼ä 2020-12-16

1.AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î


1.jpg


AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£ ¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html


2.Golang XMLÆÊÎöÆ÷±£´æ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄÎó²î


2.jpg


MattermostÓëGolangÁªºÏÅû¶ÁËGolang XMLÆÊÎöÆ÷ÖеÄ3¸öÒªº¦Îó²î¡£¡£¡£¡£ ¡£ÕâЩÎó²î»®·ÖΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»Îȹ̣¨CVE-2020-29509£©¡¢Ö¸Áî²»Îȹ̣¨CVE-2020-29510£©ºÍÔªËØ²»Îȹ̣¨CVE-2020-29511£©Îó²î¡£¡£¡£¡£ ¡£ÕâÈý¸öÎó²îÊÇÇ×½üÏà¹ØµÄ£¬£¬£¬£¬£¬£¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXML±ê¼ÇÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µÀú³ÌÖб¬·¢Á˱äÒìËùµ¼Öµġ£¡£¡£¡£ ¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÓÕÆ­ÒÀÀµÓÚXMLÆÊÎöÆ÷µÄÖÖÖÖSAMLʵÏÖ£¬£¬£¬£¬£¬£¬£¬ÒÔÍêÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£¡£ ¡£  


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/


3.GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔ­ÓÉδ֪


3.png


GmailÔÚ24СʱÄÚÓÖ±¬·¢ÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ»á¼ûÆäµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£¡£ ¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØµãʱ£¬£¬£¬£¬£¬£¬£¬»áÁ¬Ã¦ÊÕµ½Ò»Ìõת´ïʧ°ÜÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÕÒ²»µ½µØµã¡£¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£¡£ ¡£Æ¾Ö¤DownDetectorÊý¾Ý£¬£¬£¬£¬£¬£¬£¬´Ë´ÎGmailÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬GoogleÉùÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬£¬£¬£¬£¬µ«ÖÐÖ¹Ôµ¹ÊÔ­ÓÉÉв»Ã÷È·¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/


4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒªº¦ÏµÍ³å´»ú


4.png


ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶à¸öÒªº¦ÏµÍ³å´»ú¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾Ö÷ÒªÔÚÔÚŲÍþº£°¶Ä±»®¶ÉÂÖ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¼«ºÍÄϼ«¾ÙÐк½ÐС£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ´Ë´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³ÉÖØ´óµÄ²ÆÎñÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÓм¸¸öÒªº¦ÏµÍ³·ºÆð¹ÊÕÏ¡£¡£¡£¡£ ¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬£¬£¬£¬£¬¶ø¹«Ë¾Ò²ÒѽÓÄÉ×ۺϲ½·¥ÒÔÏÞÖÆ¹¥»÷Ôì³ÉµÄΣº¦¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826


5.unit42Ðû²¼Ä¾ÂíPyMICROPSIAµÄÆÊÎö±¨¸æ


5.png


unit42Ðû²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÇøµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬£¬£¬£¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£¡£¡£¡£ ¡£PyMICROPSIA¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÎļþÉÏ´«¡¢ÓÐÓøºÔØÏÂÔØºÍÖ´ÐС¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢É¨³ýä¯ÀÀÀúÊ·¼Í¼ºÍÉèÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐÐÏÂÁîµÈ¹¦Ð§¡£¡£¡£¡£ ¡£ËüÓÉPython±àд£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃPyInstallerÖÆ³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÔËÐÐÑ­»·À´ÊµÏÖÆäÖ÷Òª¹¦Ð§¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/pymicropsia/


6.BugcrowdÐû²¼Î´À´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ


6.png


BugcrowdÐû²¼ÁËδÀ´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£ ¡£¸Ã±¨¸æÖÜÈ«ÏÈÈÝÁËCOVID-19ÔõÑùÖØÐ½ç˵¿çÐÐÒµµÄÍøÂçÇ徲ʵ¼ù¡£¡£¡£¡£ ¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬£¬£¬£¬£¬Ç°Ê®¸öÔÂÌá½»µÄÎó²îÊýÄ¿ÔöÌíÁË24£¥¡£¡£¡£¡£ ¡£ÔÚ2020ÄêÌá½»µÄÊ®´óÎó²îÖУ¬£¬£¬£¬£¬£¬£¬Óа˸öÒ²·ºÆðÔÚ2019ÄêÁбíÖУ¬£¬£¬£¬£¬£¬£¬Õâ˵Ã÷ÖÎÀíÒÑ֪Σº¦ÈÔÈ»ÊÇ´ó´ó¶¼ÆóÒµÃæÁÙµÄÌôÕ½¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ìá½»µÄ×î¶àµÄÎó²îÊÇÓÉÓÚ»á¼û¿ØÖÆÔì³ÉµÄÆÆË𣬣¬£¬£¬£¬£¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾Îó²î£¨XSS£©¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/