AppleÇå¾²¸üУ¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»£»£»£»GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪
Ðû²¼Ê±¼ä 2020-12-161.AppleÇå¾²¸üУ¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î
AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
2.Golang XMLÆÊÎöÆ÷±£´æ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄÎó²î
MattermostÓëGolangÁªºÏÅû¶ÁËGolang XMLÆÊÎöÆ÷ÖеÄ3¸öÒªº¦Îó²î¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»Îȹ̣¨CVE-2020-29509£©¡¢Ö¸Áî²»Îȹ̣¨CVE-2020-29510£©ºÍÔªËØ²»Îȹ̣¨CVE-2020-29511£©Îó²î¡£¡£¡£¡£¡£ÕâÈý¸öÎó²îÊÇÇ×½üÏà¹ØµÄ£¬£¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXML±ê¼ÇÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µÀú³ÌÖб¬·¢Á˱äÒìËùµ¼Öµġ£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÓÕÆÒÀÀµÓÚXMLÆÊÎöÆ÷µÄÖÖÖÖSAMLʵÏÖ£¬£¬£¬ÒÔÍêÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/
3.GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪
GmailÔÚ24СʱÄÚÓÖ±¬·¢ÖÐÖ¹£¬£¬£¬Óû§¿ÉÒÔ»á¼ûÆäµç×ÓÓʼþ£¬£¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£¡£¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØµãʱ£¬£¬£¬»áÁ¬Ã¦ÊÕµ½Ò»Ìõת´ïʧ°ÜÐÂÎÅ£¬£¬£¬²¢ÌáÐÑÕÒ²»µ½µØµã¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£¡£¡£Æ¾Ö¤DownDetectorÊý¾Ý£¬£¬£¬´Ë´ÎGmailÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬GoogleÉùÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬µ«ÖÐÖ¹Ôµ¹ÊÔÓÉÉв»Ã÷È·¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬µ¼ÖÂÒªº¦ÏµÍ³å´»ú
ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬µ¼Ö¶à¸öÒªº¦ÏµÍ³å´»ú¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö÷ÒªÔÚÔÚŲÍþº£°¶Ä±»®¶ÉÂÖ£¬£¬£¬²¢ÔÚ±±¼«ºÍÄϼ«¾ÙÐк½ÐС£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬Ô¤¼Æ´Ë´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³ÉÖØ´óµÄ²ÆÎñÓ°Ï죬£¬£¬µ«ÏÖÔÚÓм¸¸öÒªº¦ÏµÍ³·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚÌåÏÖ£¬£¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬¶ø¹«Ë¾Ò²ÒѽÓÄÉ×ۺϲ½·¥ÒÔÏÞÖÆ¹¥»÷Ôì³ÉµÄΣº¦¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826
5.unit42Ðû²¼Ä¾ÂíPyMICROPSIAµÄÆÊÎö±¨¸æ
unit42Ðû²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÇøµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£¡£¡£¡£¡£PyMICROPSIA¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§£¬£¬£¬°üÀ¨ÎļþÉÏ´«¡¢ÓÐÓøºÔØÏÂÔØºÍÖ´ÐС¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢É¨³ýä¯ÀÀÀúÊ·¼Í¼ºÍÉèÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐÐÏÂÁîµÈ¹¦Ð§¡£¡£¡£¡£¡£ËüÓÉPython±àд£¬£¬£¬Ê¹ÓÃPyInstallerÖÆ³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬²¢Í¨¹ýÔËÐÐÑ»·À´ÊµÏÖÆäÖ÷Òª¹¦Ð§¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/pymicropsia/
6.BugcrowdÐû²¼Î´À´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ
BugcrowdÐû²¼ÁËδÀ´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æÖÜÈ«ÏÈÈÝÁËCOVID-19ÔõÑùÖØÐ½ç˵¿çÐÐÒµµÄÍøÂçÇ徲ʵ¼ù¡£¡£¡£¡£¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬Ç°Ê®¸öÔÂÌá½»µÄÎó²îÊýÄ¿ÔöÌíÁË24£¥¡£¡£¡£¡£¡£ÔÚ2020ÄêÌá½»µÄÊ®´óÎó²îÖУ¬£¬£¬Óа˸öÒ²·ºÆðÔÚ2019ÄêÁбíÖУ¬£¬£¬Õâ˵Ã÷ÖÎÀíÒÑ֪Σº¦ÈÔÈ»ÊÇ´ó´ó¶¼ÆóÒµÃæÁÙµÄÌôÕ½¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ìá½»µÄ×î¶àµÄÎó²îÊÇÓÉÓÚ»á¼û¿ØÖÆÔì³ÉµÄÆÆË𣬣¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾Îó²î£¨XSS£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/