VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδ°ä²¼²¹¶¡£»Tesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ
°ä²¼¹¦·ò 2020-11-251.VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδ°ä²¼²¹¶¡

VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐкÅÁĿǰÉÐδ°ä²¼Óйز¹¶¡·¨Ê½¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-4006£¬CVSSµÈ¼¶Îª9.1£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢½Ó¼ûÏÎ½ÓÆ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÏÎ½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÐÔÃüÖÜÆÚÖÎÀíÆ÷¡£Ä¿Ç°£¬VMwareÒѰ䲼һʱ½â¾ö·¨×ÓÒÔ½â³ý¹¥»÷ý½é²¢Ô¤·À·ì϶µÄÀûÓá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
2.TikTok½¨¸´Á½¸ö¿Éµ¼ÖÂÕË»§ÊÕÊܵÄXSSºÍCSRF·ì϶

TikTok½¨¸´ÁËÁ½¸ö¿Éµ¼ÖÂÕË»§ÊÕÊܵÄXSSºÍCSRF·ì϶¡£µÚÒ»¸ö·ì϶ΪURL²ÎÊýÖеķÇÓÆ¾ÃÐÔ¿çÕ¾µã¾ç±¾£¨XSS£©·ì϶£¬¸ÃURLµÄ²ÎÊý·µ»ØÁËδ¾Êʵ±´¦ÖõÄÖµ£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡£µÚ¶þ¸öΪAPI¶ËµãµÄ¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÆä¸ü¸ÄʹÓõÚÈý·½ÀûÓ÷¨Ê½×¢²áµÄÓû§µÄÕÊ»§ÃÜÂë¡£ºÚ¿ÍÄܹ»½áºÏÀûÓÃÕâÁ½¸ö·ì϶£¬Í¨¹ýÔì×÷Ò»¸öµ¥Ò»µÄJavaScriptÓÐЧ¸ºÔØ£¬ÔÚ´¥·¢CSRFºó½«Æä×¢Èëµ½Ò×Êܹ¥»÷µÄURL²ÎÊýÖУ¬¶øºóÒ»¼üÊÕÊÜÕÊ»§¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tiktok-fixes-bugs-allowing-account-takeover-with-one-click/
3.FBI°ä²¼ÖÒ¸æ³ÆºÚ¿ÍαÔìÓëÆäÓйصÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢

FBI»¥ÁªÍø·¸×ïͶËßÖÐÐÄ£¨IC3£©°ä²¼ÖҸ棬³ÆºÚ¿ÍαÔìÓëÆäÓйصÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢¡£FBI°ä²¼´Ë²¼¸æ£¬Ö¼ÔÚÔ®ÊÖ¹«¼Ò¼ø±ðºÍÔ¤·ÀÓëFBIÓйصĺýŪÐÔÓòÃû¡£Æä·¢ÏÖδ¾×¢²áµÄºÚ¿Íͨ¹ýºýŪºÏ·¨µÄÁª¹úµ÷²é¾ÖÍøÕ¾×¢²áÁ˺ܶàÓò£¬Õâ½²ÁËÈ»½«À´µÄ¹¥»÷»î¶¯µÄ¿ÉÄÜÐÔ¡£¹¥»÷Õß»ò½«Ê¹ÓÃαÔìµÄÓòÃûºÍµç×ÓÓʼþ´«²¼ÐéαÐÅÏ¢£¬ÍøÂçÓÐЧµÄÓû§Ãû¡¢ÃÜÂëºÍµç×ÓÓʼþµØÖ·£¬ÍøÂçÓ×ÎÒÉí·ÝÐÅÏ¢²¢´«²¼¶ñÒâÈí¼þ£¬Õâ¿ÉÄܵ¼Ö½øÒ»²½µÄ¹¥»÷»î¶¯ºÍ¿ÉÄܵIJÆÕþËðʧ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-warns-of-recently-registered-domains-spoofing-its-sites/
4.Tesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ

±ÈÀûʱ°²È«×êÑÐÈËÔ±Lennert Wouters·¢ÏÖTesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ¡£Wouters³Æ£¬¹¥»÷ÕßÄܹ»Ê¹ÓôӾɵÄModel X³µÁ¾ÖлØÊյĵç×Ó½ÚÔìµ¥Ôª£¨ECU£©À´ÀûÓô˷ì϶¡£Ê×ÏȸÄ×°»ØÊÕµÄECUÀ´»½ÄܸɱêÃÜÔ¿¿¨£¬Ê¹ÆäÏàПÃECUÊôÓÚÆäÅä¶Ô³µÁ¾¡£¶øºóͨ¹ýBLE£¨À¶ÑÀµÍÄܺģ©ºÍ̸½«¶ñÒâ¹Ì¼þ¸üÐÂÍÆË͵½¸ÃÃÜÔ¿¿¨¡£Ò»µ©³É¹¦ÈëÇÖÃÜÔ¿¿¨£¬¹¥»÷Õ߾ͻá´ÓÖÐÌáÈ¡Æû³µ½âËøÐÂÎÅ£¬¶øºóÀûÓÃÕâЩ½âËøÐÅÏ¢½øÈëÖ¸±ê³µÁ¾¡£Ä¿Ç°£¬¸Ã·ì϶Òѱ»½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/tesla-model-x-hacked-and-stolen-in-minutes-using-new-key-fob-hack/
5.Å·ÃËENISA°ä²¼È·±£ÎïÁªÍø¹©¸øÁ´°²È«µÄÖ¸ÄÏ

Å·ÃËÍøÂ簲ȫ»ú¹¹£¨ENISA)°ä²¼ÁËÈ·±£ÎïÁªÍø¹©¸øÁ´°²È«µÄÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÌá³öÁËÓ빩¸øÁ´ÓйصķçÏÕ·ÖÎöµÄÁ˾֣¬ÕâÊÇ»ùÓÚ¶ÔÓ°Ï칩¸øÁ´²Î¼ÓÕß¡¢Á÷³ÌºÍ¼¼ÊõµÄÏÖ´úÍþвµÄÇ°ÑØ×êÑС£Æ¾¾Ý·ÖÎöÁ˾ֵóö½áÂÛ£¬ÎªÈ·±£ÎïÁªÍø¹©¸øÁ´°²È«Ó¦ÔÚ¹©¸øÁ´²Î¼ÓÕßÖ®¼ä³ÉÁ¢¸üºÃµÄ¹ØÏµ£»²»ÐÝÈ«Ãæ¼Óǿϵͳ¿ª·¢ÈËÔ±ºÍÓû§µÄÍøÂ簲ȫרҵ֪ʶ£»Ñ¡È¡Éè¼Æ°²È«×¼Ôò£»¶Ô°²È«²ÉÈ¡È«Ãæ¶øÃ÷È·µÄ²½Ö裬Ã÷ȷ˼¿¼ËùÓÐÓйØÍþв²¢²ÉÈ¡ÏàÓ¦´ëÊ©£»ÀûÓÃÏÖÓеݲȫ³ß¶ÈºÍÓÅÁ¼×ö·¨¡£
ÔÎÄÁ´½Ó£º
https://ics-cert.kaspersky.com/news/2020/11/23/enisa-publishes-guidelines-for-securing-internet-of-things-supply-chain/
6.GBG°ä²¼2020Äê¶Å×йØÊý×ÖÉí·ÝµÄÌ¬ÊÆ·ÖÎö»ã±¨

GBG°ä²¼2020Äê¶ÈÊý×ÖÉí·ÝÌ¬ÊÆµÄ·ÖÎö»ã±¨£¬²¢³Æ2020ÄêÓÐÎå·ÖÖ®Ò»µÄÏû·ÑÕßÊܵ½Éí·ÝڲƵÄÓ°Ïì¡£¸Ã»ã±¨·¢ÏÖ£¬ÓÉÓÚCOVID-19ÒÔÀ´Éí·Ý͵ÇÔÊÂÎñµÄÔö³¤£¬ÆóÒµºÍÏû·ÑÕßÖ®¼äµÄÐÅÀµ²î¾à¿ÉÄÜ»áÀ©´ó¡£ÓÉÓÚÉç»á¸ôÀëµÄÏÞ¶È£¬ÈËÃÇÔ½À´Ô½ÒÀÀµÊý×Ö·þÎñ¡£GBGÖ¸³ö£¬µ½2020Ä꣬ÓÐ47£¥µÄÈË¿ªÉèÁËеÄÔÚÏß¹ºÎïÕÊ»§£¬¶ø35£¥µÄÈË¿ªÉèÁËеÄÉ罻ýÌåÕÊ»§£¬ÓÐ31£¥µÄÈË¿ªÉèÁËÔÚÏßÒøÐÐÕÊ»§¡£´Ë±í£¬ÓÐ33£¥µÄ¹«¼ÒÒÔΪËûÃǵÄÓ×ÎÒÐÅϢĿǰÔÚ°µÍøÉÏÏúÊÛ¡£
ÔÎÄÁ´½Ó£º
https://www.gbgplc.com/the-gbg-state-of-digital-identity-2020/


¾©¹«Íø°²±¸11010802024551ºÅ