VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬ÉÐδÐû²¼²¹¶¡£¡£¡£»£»£»£»Tesla Model XÃÜÔ¿¿¨±£´æÎó²î¿ÉÓÃÀ´¿ìËÙ½âËøÆû³µ
Ðû²¼Ê±¼ä 2020-11-251.VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬ÉÐδÐû²¼²¹¶¡
VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁ£¬£¬ÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬£¬£¬CVSSÆ·¼¶Îª9.1£¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£ÏÖÔÚ£¬£¬£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷ǰÑÔ²¢±ÜÃâÎó²îµÄʹÓᣡ£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
2.TikTokÐÞ¸´Á½¸ö¿Éµ¼ÖÂÕË»§½ÓÊܵÄXSSºÍCSRFÎó²î
TikTokÐÞ¸´ÁËÁ½¸ö¿Éµ¼ÖÂÕË»§½ÓÊܵÄXSSºÍCSRFÎó²î¡£¡£¡£µÚÒ»¸öÎó²îΪURL²ÎÊýÖеķdz¤ÆÚÐÔ¿çÕ¾µã¾ç±¾£¨XSS£©Îó²î£¬£¬£¬¸ÃURLµÄ²ÎÊý·µ»ØÁËδ¾Êʵ±´¦Öóͷ£µÄÖµ£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡£¡£¡£µÚ¶þ¸öΪAPI¶ËµãµÄ¿çÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÆä¸ü¸ÄʹÓõÚÈý·½Ó¦ÓóÌÐò×¢²áµÄÓû§µÄÕÊ»§ÃÜÂë¡£¡£¡£ºÚ¿Í¿ÉÒÔÁ¬ÏµÊ¹ÓÃÕâÁ½¸öÎó²î£¬£¬£¬Í¨¹ýÖÆ×÷Ò»¸ö¼òÆÓµÄJavaScriptÓÐÓøºÔØ£¬£¬£¬ÔÚ´¥·¢CSRFºó½«Æä×¢Èëµ½Ò×Êܹ¥»÷µÄURL²ÎÊýÖУ¬£¬£¬È»ºóÒ»¼ü½Ó»á¼Æ»§¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tiktok-fixes-bugs-allowing-account-takeover-with-one-click/
3.FBIÐû²¼ÖÒÑԳƺڿÍαÔìÓëÆäÏà¹ØµÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢
FBI»¥ÁªÍø·¸·¨Í¶ËßÖÐÐÄ£¨IC3£©Ðû²¼ÖÒÑÔ£¬£¬£¬³ÆºÚ¿ÍαÔìÓëÆäÏà¹ØµÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢¡£¡£¡£FBIÐû²¼´Ëͨ¸æ£¬£¬£¬Ö¼ÔÚ×ÊÖú¹«ÖÚʶ±ðºÍ×èÖ¹ÓëFBIÏà¹ØµÄÓÕÆÐÔÓòÃû¡£¡£¡£Æä·¢Ã÷δ¾×¢²áµÄºÚ¿Íͨ¹ýÓÕÆÕýµ±µÄÁª°îÊÓ²ì¾ÖÍøÕ¾×¢²áÁËÐí¶àÓò£¬£¬£¬ÕâÅú×¢ÎúδÀ´µÄ¹¥»÷»î¶¯µÄ¿ÉÄÜÐÔ¡£¡£¡£¹¥»÷Õß»ò½«Ê¹ÓÃαÔìµÄÓòÃûºÍµç×ÓÓʼþÈö²¥ÐéαÐÅÏ¢£¬£¬£¬ÍøÂçÓÐÓõÄÓû§Ãû¡¢ÃÜÂëºÍµç×ÓÓʼþµØµã£¬£¬£¬ÍøÂçСÎÒ˽¼ÒÉí·ÝÐÅÏ¢²¢Èö²¥¶ñÒâÈí¼þ£¬£¬£¬Õâ¿ÉÄܵ¼Ö½øÒ»²½µÄ¹¥»÷»î¶¯ºÍ¿ÉÄܵIJÆÎñËðʧ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-warns-of-recently-registered-domains-spoofing-its-sites/
4.Tesla Model XÃÜÔ¿¿¨±£´æÎó²î¿ÉÓÃÀ´¿ìËÙ½âËøÆû³µ
±ÈÀûʱÇå¾²Ñо¿Ö°Ô±Lennert Wouters·¢Ã÷Tesla Model XÃÜÔ¿¿¨±£´æÎó²î¿ÉÓÃÀ´¿ìËÙ½âËøÆû³µ¡£¡£¡£Wouters³Æ£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôӾɵÄModel X³µÁ¾ÖнÓÄɵĵç×Ó¿ØÖƵ¥Î»£¨ECU£©À´Ê¹ÓôËÎó²î¡£¡£¡£Ê×ÏȸÄ×°½ÓÄɵÄECUÀ´½ÐÐÑÄ¿µÄÃÜÔ¿¿¨£¬£¬£¬Ê¹ÆäÏàПÃECUÊôÓÚÆäÅä¶Ô³µÁ¾¡£¡£¡£È»ºóͨ¹ýBLE£¨À¶ÑÀµÍÄܺģ©ÐÒ齫¶ñÒâ¹Ì¼þ¸üÐÂÍÆË͵½¸ÃÃÜÔ¿¿¨¡£¡£¡£Ò»µ©ÀÖ³ÉÈëÇÖÃÜÔ¿¿¨£¬£¬£¬¹¥»÷Õ߾ͻá´ÓÖÐÌáÈ¡Æû³µ½âËøÐÂÎÅ£¬£¬£¬È»ºóʹÓÃÕâЩ½âËøÐÅÏ¢½øÈëÄ¿µÄ³µÁ¾¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/tesla-model-x-hacked-and-stolen-in-minutes-using-new-key-fob-hack/
5.Å·ÃËENISAÐû²¼È·±£ÎïÁªÍø¹©Ó¦Á´Çå¾²µÄÖ¸ÄÏ
Å·ÃËÍøÂçÇå¾²»ú¹¹£¨ENISA)Ðû²¼ÁËÈ·±£ÎïÁªÍø¹©Ó¦Á´Çå¾²µÄÖ¸ÄÏ¡£¡£¡£¸ÃÖ¸ÄÏÌá³öÁËÓ빩ӦÁ´Ïà¹ØµÄΣº¦ÆÊÎöµÄЧ¹û£¬£¬£¬ÕâÊÇ»ùÓÚ¶ÔÓ°Ï칩ӦÁ´¼ÓÈëÕß¡¢Á÷³ÌºÍÊÖÒÕµÄÏÖ´úÍþвµÄÇ°ÑØÑо¿¡£¡£¡£Æ¾Ö¤ÆÊÎöЧ¹ûµÃ³ö½áÂÛ£¬£¬£¬ÎªÈ·±£ÎïÁªÍø¹©Ó¦Á´Çå¾²Ó¦ÔÚ¹©Ó¦Á´¼ÓÈëÕßÖ®¼ä½¨Éè¸üºÃµÄ¹ØÏµ£»£»£»£»Ò»Ö±ÖÜÈ«Ôöǿϵͳ¿ª·¢Ö°Ô±ºÍÓû§µÄÍøÂçÇ徲רҵ֪ʶ£»£»£»£»½ÓÄÉÉè¼ÆÇå¾²ÔÔò£»£»£»£»¶ÔÇå¾²½ÓÄÉÖÜÈ«¶øÃ÷È·µÄÒªÁ죬£¬£¬Ã÷ȷ˼Á¿ËùÓÐÏà¹ØÍþв²¢½ÓÄÉÏìÓ¦²½·¥£»£»£»£»Ê¹ÓÃÏÖÓеÄÇå¾²±ê×¼ºÍÓÅÒì×ö·¨¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://ics-cert.kaspersky.com/news/2020/11/23/enisa-publishes-guidelines-for-securing-internet-of-things-supply-chain/
6.GBGÐû²¼2020Äê¶ÈÓйØÊý×ÖÉí·ÝµÄÌ¬ÊÆÆÊÎö±¨¸æ
GBGÐû²¼2020Äê¶ÈÊý×ÖÉí·ÝÌ¬ÊÆµÄÆÊÎö±¨¸æ£¬£¬£¬²¢³Æ2020ÄêÓÐÎå·ÖÖ®Ò»µÄÏûºÄÕßÊܵ½Éí·ÝڲƵÄÓ°Ïì¡£¡£¡£¸Ã±¨¸æ·¢Ã÷£¬£¬£¬ÓÉÓÚCOVID-19ÒÔÀ´Éí·Ý͵ÇÔÊÂÎñµÄÔöÌí£¬£¬£¬ÆóÒµºÍÏûºÄÕßÖ®¼äµÄÐÅÈβî±ð¿ÉÄÜ»áÀ©´ó¡£¡£¡£ÓÉÓÚÉç»á¸ôÀëµÄÏÞÖÆ£¬£¬£¬ÈËÃÇÔ½À´Ô½ÒÀÀµÊý×ÖЧÀÍ¡£¡£¡£GBGÖ¸³ö£¬£¬£¬µ½2020Ä꣬£¬£¬ÓÐ47£¥µÄÈË¿ªÉèÁËеÄÔÚÏß¹ºÎïÕÊ»§£¬£¬£¬¶ø35£¥µÄÈË¿ªÉèÁËеÄÉ罻ýÌåÕÊ»§£¬£¬£¬ÓÐ31£¥µÄÈË¿ªÉèÁËÔÚÏßÒøÐÐÕÊ»§¡£¡£¡£±ðµÄ£¬£¬£¬ÓÐ33£¥µÄ¹«ÖÚÒÔΪËûÃǵÄСÎÒ˽¼ÒÐÅÏ¢ÏÖÔÚÕýÔÚ°µÍøÉϳöÊÛ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.gbgplc.com/the-gbg-state-of-digital-identity-2020/