Apple°²È«¸üУ¬½¨¸´Ó°ÏìiOSºÍiPadOSµÄ11¸ö·ì϶£»GmailÔÚ24Ó×ʱÄÚ²úÉúµÚ¶þ´ÎÖжϣ¬Ä¿Ç°ÔÒòδ֪
°ä²¼¹¦·ò 2020-12-161.Apple°²È«¸üУ¬½¨¸´Ó°ÏìiOSºÍiPadOSµÄ11¸ö·ì϶

Apple°ä²¼ÁËiOSºÍiPadOSµÄ°²È«¸üУ¬½¨¸´Ô̺¬´úÂëÖ´Ðзì϶ÔÚÄÚµÄ11¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄÊÇ´úÂëÖ´Ðзì϶£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬¹¥»÷Õß¿ÉÀûÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄ·ì϶CVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ͨ¹ýÌØÔìͼÏñÖ´ÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
2.Golang XML½âÎöÆ÷´æÔÚ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄ·ì϶

MattermostÓëGolang½áºÏÅû¶ÁËGolang XML½âÎöÆ÷ÖеÄ3¸ö¹Ø¼ü·ì϶¡£ÕâЩ·ì϶±ðÀëΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»²»±ä£¨CVE-2020-29509£©¡¢Ö¸Áî²»²»±ä£¨CVE-2020-29510£©ºÍÔªËØ²»²»±ä£¨CVE-2020-29511£©·ì϶¡£ÕâÈý¸ö·ì϶ÊÇÇ×êÇÓйص쬶¼ÊÇÓÉÓÚ¶ñÒâXMLÏóÕ÷ÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µ¹ý³ÌÖвúÉúÁ˱äÒìËùµ¼Öµġ£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ºýŪÒÀÀµÓÚXML½âÎöÆ÷µÄ¸÷ÀàSAMLʵÏÖ£¬ÒÔÆëÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/
3.GmailÔÚ24Ó×ʱÄÚ²úÉúµÚ¶þ´ÎÖжϣ¬Ä¿Ç°ÔÒòδ֪

GmailÔÚ24Ó×ʱÄÚÓÖ²úÉúÖжϣ¬Óû§Äܹ»½Ó¼ûÆäµç×ÓÓʼþ£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØÖ·Ê±£¬»áµ±¼´ÊÕµ½Ò»Ìõ´«µÝʧ°ÜÐÂÎÅ£¬²¢ÌáÐÑÕÒ²»µ½µØÖ·¡£µ«ÊÇ£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌ⡣ƾ¾ÝDownDetectorÊý¾Ý£¬Õâ´ÎGmailÖжÏÖØÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£Ä¿Ç°£¬GoogleÉêÃ÷ÎÊÌâÒѽâ¾ö£¬µ«ÖжÏÔÒòÉв»Ã÷È·¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬µ¼Ö¹ؼüϵͳ崻ú

ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬µ¼Ö¶à¸ö¹Ø¼üϵͳ崻ú¡£¸Ã¹«Ë¾ÖØÒªÔÚÔÚŲÍþº£°¶¾Óª¶ÉÂÖ£¬²¢ÔÚ±±¼«ºÍÄϼ«½øÐк½ÐС£¸Ã¹«Ë¾°µÊ¾£¬Ô¤¼ÆÕâ´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³É³Á´óµÄ²ÆÕþÓ°Ï죬µ«Ä¿Ç°Óм¸¸ö¹Ø¼üϵͳ³öÏÖ¹ÊÕÏ¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚ°µÊ¾£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬¶ø¹«Ë¾Ò²ÒѲÉÈ¡×ۺϴëÊ©ÒÔÏ޶ȹ¥»÷Ôì³ÉµÄ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826
5.unit42°ä²¼Ä¾ÂíPyMICROPSIAµÄ·ÖÎö»ã±¨

unit42°ä²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄ·ÖÎö»ã±¨¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÓòµÄºÚ¿Í×éÖ¯AridViper£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйء£PyMICROPSIAÓµÓзá˶µÄÐÅÏ¢ÇÔÈ¡ºÍ½ÚÔìÖ°ÄÜ£¬Ô̺¬ÎļþÉÏ´«¡¢ÓÐЧ¸ºÔØÏÂÔØºÍÖ´ÐÓ×¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢¶Ï¸ùä¯ÀÀº¹Çà¼Í¼ºÍÅäÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐкÅÁîµÈÖ°ÄÜ¡£ËüÓÉPython±àд£¬Ê¹ÓÃPyInstallerÔì³ÉWindows¿ÉÖ´ÐÐÎļþ£¬²¢Í¨¹ýÔËÐÐÑ»·À´ÊµÏÔìäÖØÒªÖ°ÄÜ¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/pymicropsia/
6.Bugcrowd°ä²¼½«À´Ê®Äê¶à°ü°²È«µÄÔ¤²â»ã±¨

Bugcrowd°ä²¼Á˽«À´Ê®Äê¶à°ü°²È«µÄÔ¤²â»ã±¨¡£¸Ã»ã±¨È«Ãæ½éÉÜÁËCOVID-19ÈôºÎ³Áнç˵¿çÐÐÒµµÄÍøÂ簲ȫʵ¼Ê¡£Óë2019ÄêÕûÄêÏà±È£¬Ç°Ê®¸öÔÂÌá½»µÄ·ì϶ÊýÁ¿Ôö³¤ÁË24£¥¡£ÔÚ2020ÄêÌá½»µÄÊ®´ó·ì϶ÖУ¬Óа˸öÒ²³Ê´Ë¿Ì2019ÄêÁбíÖУ¬Õâ×¢Ã÷ÖÎÀíÒÑÖª·çÏÕÒÀÈ»ÊÇ´óÎÞÊýÆóÒµÃæ¶ÔµÄÌôÕ½¡£´Ë±í£¬Ìá½»µÄ×î¶àµÄ·ì϶ÊÇÓÉÓÚ½Ó¼û½ÚÔì×÷³ÉµÄ·ÛË飬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾·ì϶£¨XSS£©¡£
ÔÎÄÁ´½Ó£º
https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/


¾©¹«Íø°²±¸11010802024551ºÅ