AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪
Ðû²¼Ê±¼ä 2020-12-161.AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î

AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
2.Golang XMLÆÊÎöÆ÷±£´æ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄÎó²î

MattermostÓëGolangÁªºÏÅû¶ÁËGolang XMLÆÊÎöÆ÷ÖеÄ3¸öÒªº¦Îó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»Îȹ̣¨CVE-2020-29509£©¡¢Ö¸Áî²»Îȹ̣¨CVE-2020-29510£©ºÍÔªËØ²»Îȹ̣¨CVE-2020-29511£©Îó²î¡£¡£¡£¡£¡£¡£ÕâÈý¸öÎó²îÊÇÇ×½üÏà¹ØµÄ£¬£¬£¬£¬£¬£¬£¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXML±ê¼ÇÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µÀú³ÌÖб¬·¢Á˱äÒìËùµ¼Öµġ£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÓÕÆÒÀÀµÓÚXMLÆÊÎöÆ÷µÄÖÖÖÖSAMLʵÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÍêÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/
3.GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪

GmailÔÚ24СʱÄÚÓÖ±¬·¢ÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ»á¼ûÆäµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£¡£¡£¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØµãʱ£¬£¬£¬£¬£¬£¬£¬£¬»áÁ¬Ã¦ÊÕµ½Ò»Ìõת´ïʧ°ÜÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÕÒ²»µ½µØµã¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£¡£¡£¡£Æ¾Ö¤DownDetectorÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬´Ë´ÎGmailÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬GoogleÉùÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬£¬£¬£¬£¬£¬µ«ÖÐÖ¹Ôµ¹ÊÔÓÉÉв»Ã÷È·¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒªº¦ÏµÍ³å´»ú

ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶à¸öÒªº¦ÏµÍ³å´»ú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö÷ÒªÔÚÔÚŲÍþº£°¶Ä±»®¶ÉÂÖ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¼«ºÍÄϼ«¾ÙÐк½ÐС£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ´Ë´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³ÉÖØ´óµÄ²ÆÎñÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÓм¸¸öÒªº¦ÏµÍ³·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬¶ø¹«Ë¾Ò²ÒѽÓÄÉ×ۺϲ½·¥ÒÔÏÞÖÆ¹¥»÷Ôì³ÉµÄΣº¦¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826
5.unit42Ðû²¼Ä¾ÂíPyMICROPSIAµÄÆÊÎö±¨¸æ

unit42Ðû²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÇøµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬£¬£¬£¬£¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£¡£¡£¡£¡£¡£PyMICROPSIA¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÎļþÉÏ´«¡¢ÓÐÓøºÔØÏÂÔØºÍÖ´ÐС¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢É¨³ýä¯ÀÀÀúÊ·¼Í¼ºÍÉèÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐÐÏÂÁîµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£ËüÓÉPython±àд£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃPyInstallerÖÆ³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÔËÐÐÑ»·À´ÊµÏÖÆäÖ÷Òª¹¦Ð§¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/pymicropsia/
6.BugcrowdÐû²¼Î´À´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ

BugcrowdÐû²¼ÁËδÀ´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖÜÈ«ÏÈÈÝÁËCOVID-19ÔõÑùÖØÐ½ç˵¿çÐÐÒµµÄÍøÂçÇ徲ʵ¼ù¡£¡£¡£¡£¡£¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬£¬£¬£¬£¬£¬Ç°Ê®¸öÔÂÌá½»µÄÎó²îÊýÄ¿ÔöÌíÁË24£¥¡£¡£¡£¡£¡£¡£ÔÚ2020ÄêÌá½»µÄÊ®´óÎó²îÖУ¬£¬£¬£¬£¬£¬£¬£¬Óа˸öÒ²·ºÆðÔÚ2019ÄêÁбíÖУ¬£¬£¬£¬£¬£¬£¬£¬Õâ˵Ã÷ÖÎÀíÒÑ֪Σº¦ÈÔÈ»ÊÇ´ó´ó¶¼ÆóÒµÃæÁÙµÄÌôÕ½¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ìá½»µÄ×î¶àµÄÎó²îÊÇÓÉÓÚ»á¼û¿ØÖÆÔì³ÉµÄÆÆË𣬣¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾Îó²î£¨XSS£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/


¾©¹«Íø°²±¸11010802024551ºÅ