AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»£»£»GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪
Ðû²¼Ê±¼ä 2020-12-161.AppleÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î

AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
2.Golang XMLÆÊÎöÆ÷±£´æ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄÎó²î

MattermostÓëGolangÁªºÏÅû¶ÁËGolang XMLÆÊÎöÆ÷ÖеÄ3¸öÒªº¦Îó²î¡£¡£¡£ÕâЩÎó²î»®·ÖΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»Îȹ̣¨CVE-2020-29509£©¡¢Ö¸Áî²»Îȹ̣¨CVE-2020-29510£©ºÍÔªËØ²»Îȹ̣¨CVE-2020-29511£©Îó²î¡£¡£¡£ÕâÈý¸öÎó²îÊÇÇ×½üÏà¹ØµÄ£¬£¬£¬£¬£¬£¬£¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXML±ê¼ÇÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µÀú³ÌÖб¬·¢Á˱äÒìËùµ¼Öµġ£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÓÕÆÒÀÀµÓÚXMLÆÊÎöÆ÷µÄÖÖÖÖSAMLʵÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÍêÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/
3.GmailÔÚ24СʱÄÚ±¬·¢µÚ¶þ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔµ¹ÊÔÓÉδ֪

GmailÔÚ24СʱÄÚÓÖ±¬·¢ÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ»á¼ûÆäµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØµãʱ£¬£¬£¬£¬£¬£¬£¬£¬»áÁ¬Ã¦ÊÕµ½Ò»Ìõת´ïʧ°ÜÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÕÒ²»µ½µØµã¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£Æ¾Ö¤DownDetectorÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬´Ë´ÎGmailÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬GoogleÉùÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬£¬£¬£¬£¬£¬µ«ÖÐÖ¹Ôµ¹ÊÔÓÉÉв»Ã÷È·¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒªº¦ÏµÍ³å´»ú

ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¶à¸öÒªº¦ÏµÍ³å´»ú¡£¡£¡£¸Ã¹«Ë¾Ö÷ÒªÔÚÔÚŲÍþº£°¶Ä±»®¶ÉÂÖ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¼«ºÍÄϼ«¾ÙÐк½ÐС£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼Æ´Ë´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³ÉÖØ´óµÄ²ÆÎñÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÓм¸¸öÒªº¦ÏµÍ³·ºÆð¹ÊÕÏ¡£¡£¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬¶ø¹«Ë¾Ò²ÒѽÓÄÉ×ۺϲ½·¥ÒÔÏÞÖÆ¹¥»÷Ôì³ÉµÄΣº¦¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826
5.unit42Ðû²¼Ä¾ÂíPyMICROPSIAµÄÆÊÎö±¨¸æ

unit42Ðû²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄÆÊÎö±¨¸æ¡£¡£¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÇøµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬£¬£¬£¬£¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£¡£¡£PyMICROPSIA¾ßÓи»ºñµÄÐÅÏ¢ÇÔÈ¡ºÍ¿ØÖƹ¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÎļþÉÏ´«¡¢ÓÐÓøºÔØÏÂÔØºÍÖ´ÐС¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢É¨³ýä¯ÀÀÀúÊ·¼Í¼ºÍÉèÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐÐÏÂÁîµÈ¹¦Ð§¡£¡£¡£ËüÓÉPython±àд£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃPyInstallerÖÆ³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÔËÐÐÑ»·À´ÊµÏÖÆäÖ÷Òª¹¦Ð§¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/pymicropsia/
6.BugcrowdÐû²¼Î´À´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ

BugcrowdÐû²¼ÁËδÀ´Ê®ÄêÖÚ°üÇå¾²µÄÕ¹Íû±¨¸æ¡£¡£¡£¸Ã±¨¸æÖÜÈ«ÏÈÈÝÁËCOVID-19ÔõÑùÖØÐ½ç˵¿çÐÐÒµµÄÍøÂçÇ徲ʵ¼ù¡£¡£¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬£¬£¬£¬£¬£¬Ç°Ê®¸öÔÂÌá½»µÄÎó²îÊýÄ¿ÔöÌíÁË24£¥¡£¡£¡£ÔÚ2020ÄêÌá½»µÄÊ®´óÎó²îÖУ¬£¬£¬£¬£¬£¬£¬£¬Óа˸öÒ²·ºÆðÔÚ2019ÄêÁбíÖУ¬£¬£¬£¬£¬£¬£¬£¬Õâ˵Ã÷ÖÎÀíÒÑ֪Σº¦ÈÔÈ»ÊÇ´ó´ó¶¼ÆóÒµÃæÁÙµÄÌôÕ½¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ìá½»µÄ×î¶àµÄÎó²îÊÇÓÉÓÚ»á¼û¿ØÖÆÔì³ÉµÄÆÆË𣬣¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾Îó²î£¨XSS£©¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/


¾©¹«Íø°²±¸11010802024551ºÅ