GitHubÐû²¼2020Äê¶ÈOctoverseÌ¬ÊÆµÄÆÊÎö±¨¸æ£»£»£»£»£»£»£»¹È¸èÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î
Ðû²¼Ê±¼ä 2020-12-04
GitHubÐû²¼ÁË2020Äê¶ÈOctoverseÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¸Ã±¨¸æÖ÷Ҫͳ¼ÆÁËÁè¼Ý5600ÍòÃû¿ª·¢Ö°Ô±ÔÚ2020Ä꽨ÉèµÄÁè¼Ý6000Íò¸öд洢¿â¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬£¬Óë2019ÄêÏà±È£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ94£¥µÄÏîÄ¿ÒÀÀµ¿ªÔ´×é¼þ£¬£¬£¬£¬£¬£¬£¬Æ½¾ùÓп¿½ü700¸öÒÀÀµÏ£¬£¬£¬£¬£¬£¬JavaScriptÖÐÓÐ94£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬£¬¶øRubyºÍ.NETÖÐÓÐ90£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¿ªÔ´Èí¼þÖеĴó´ó¶¼Îó²î²¢²»ÊǶñÒâµÄ£¬£¬£¬£¬£¬£¬£¬Ïà·´£¬£¬£¬£¬£¬£¬£¬GitHub·¢³öµÄCVE¾¯±¨ÖÐÓÐ83£¥µÄÎó²îÊÇÓÉÈËΪ¹ýʧÒýÆðµÄ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://octoverse.github.com/
2.IBMÐû²¼Õë¶ÔCOVID-19ÒßÃ繩ӦÁ´µÄ¹¥»÷»î¶¯µÄ±¨¸æ

IBM X-ForceÐû²¼ÁËÕë¶ÔCOVID-19ÒßÃ繩ӦÁ´µÄ¹¥»÷»î¶¯µÄ±¨¸æ¡£¡£¡£ÔÚCOVID-19×îÏÈʱ£¬£¬£¬£¬£¬£¬£¬IBM X-Force½¨ÉèÁËÍþвÇé±¨ÌØÊâÊÂÇé×飬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚ×·×ÙÕë¶ÔÒßÃ繩ӦÁ´ÔËתµÄ×éÖ¯µÄÍøÂçÍþв£¬£¬£¬£¬£¬£¬£¬¸ÃÍŶÓ×î½ü·¢Ã÷ÁËÒ»³¡Õë¶ÔÓëCOVID-19ÀäÁ´Ïà¹Ø×éÖ¯µÄÈ«Çò´¹Âڻ¡£¡£¡£´Ë´Î¹¥»÷»î¶¯¿çÔ½Áù¸ö¹ú¼Ò£¬£¬£¬£¬£¬£¬£¬Ä¿µÄ¿ÉÄÜÓëÈ«ÇòÒßÃçÃâÒßͬÃË(Gavi)µÄÀäÁ´×°±¸ÓÅ»¯Æ½Ì¨(CCEOP)ÏîÄ¿Óйأ¬£¬£¬£¬£¬£¬£¬»òÓë¹ú¼ÒÌØ¹¤×éÖ¯Óйء£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/
3.XeroxÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´DocuShareÖеÄSSRFºÍXXEÎó²î

XeroxÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆóÒµÎĵµÖÎÀíÆ½Ì¨DocuShareÖеÄSSRFºÍXXEÎó²î¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-27177£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂSolaris¡¢LinuxºÍWindows DucuShareÓû§Ô⵽ЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©¹¥»÷ºÍδ¾Éí·ÝÑéÖ¤µÄÍⲿXMLʵÌå×¢Èë¹¥»÷£¨XXE£©¡£¡£¡£¹¥»÷ÕßÀÖ³ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬¿É»ñµÃ¶ÔÄ¿µÄϵͳÉñÃØÊý¾ÝµÄ»á¼ûȨÏÞ¡£¡£¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶ÏêϸÎó²îÏêÇ飬£¬£¬£¬£¬£¬£¬µ«ÌṩÁËÐÞ¸´³ÌÐòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÊÜÓ°Ïì°æ±¾ÖеÄÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/xerox-docushare-bugs/161791/
4.¹È¸èÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î

Google Project ZeroÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-3843£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓøÃÎó²î¿ÉÒÔ»á¼ûÕÕÆ¬ºÍÆäËûÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþºÍ˽ÈËÐÂÎÅ¡£¡£¡£¹¥»÷Õß½«Ä¿µÄËø¶¨ÔÚAirDrop BTLE¿ò¼ÜÉÏ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÇ¿ÖÆÊ¹Óô洢ÔÚ×°±¸ÖеÄÁªÏµÈ˵ĹþÏ£ÖµÀ´ÆôÓÃAWDL½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬È»ºó´¥·¢»º³åÇøÒç³öÒÔ»ñµÃ¶Ô×°±¸µÄ»á¼ûȨ£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ¸ùÓû§Éí·ÝÖ²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬ÊµÏÖ¶Ô×°±¸µÄÍêÈ«¿ØÖÆ¡£¡£¡£Éв»ÇåÎú¸ÃÎó²îÊÇ·ñ±»ÔÚҰʹÓ㬣¬£¬£¬£¬£¬£¬µ«Ïà¹Ø³§ÉÌÒÑÐû²¼ÐÞ¸´³ÌÐò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111788/mobile-2/iphone-devices-hack.html
5.¶íAPT×éÖ¯TurlaʹÓÃжñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ

¶íÂÞ˹APT×éÖ¯TurlaʹÓÃеĶñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ¡£¡£¡£¸ÃAPT×éÖ¯Turla×Ô2007ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÔÚÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀ¡¢ÄÏÃÀ¡¢ºÍǰËÕÁª¼¯ÍŵĹ«Ë¾ºÍÍâ½»µÈÕþ¸®»ú¹¹¡£¡£¡£ESETÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬TurlaʹÓÃCrutchÔÚÕë¶ÔÅ·ÓѰî¼ÒµÄÍâ½»²¿µÄÍøÂçÌØ¹¤»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬°²ÅźóÃųÌÐò²¢ÇÔÈ¡Ãô¸ÐÎļþ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬CrutchÄܹ»Ê¹ÓÃÕýµ±»ù´¡ÉèÊ©DropboxÀ´ÈƹýijЩÇå¾²²ã£¬£¬£¬£¬£¬£¬£¬ÒÔÈëÇÖÕý³£µÄÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Îĵµ²¢´ÓºÚ¿Í×éÖ¯ÄÇÀïÎüÊÕÏÂÁî¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-hacking-group-uses-dropbox-to-store-malware-stolen-data/
6.¿ªÂüȺµºÒøÐÐÉèÖùýʧµÄAzure Blobй¶Óû§Ð¡ÎÒ˽¼ÒÊý¾Ý

¿ªÂüȺµºÀë°¶ÒøÐÐÉèÖùýʧµÄAzure Blobй¶Óû§Ð¡ÎÒ˽¼ÒÊý¾Ý¡£¡£¡£´Ë´ÎÊÂÎñй¶µÄ±¸·ÝÊý¾Ýº¸ÇÁË5ÒÚÃÀԪͶ×Ê×éºÏ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ð¡ÎÒ˽¼ÒÒøÐÐÐÅÏ¢¡¢»¤ÕÕÊý¾ÝÉõÖÁÊÇÍøÉÏÒøÐеÄPINÂë¡£¡£¡£ÓÉÓÚMicrosoft Azure BlobÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑɾ³ý¶àÄêµÄ±¸·ÝÊý¾Ý·Çµ«Ã»ÓÐÏûÊÅ£¬£¬£¬£¬£¬£¬£¬·´¶øÖ±µ½×î½ü¶¼¿ÉÒÔÇáËÉÔÚÏß»ñµÃ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚй¶Êý¾ÝÒѱ»IT¹©Ó¦ÉÌÒÆ³ý¡£¡£¡£ImmuniWebµÄCEO³Æ£¬£¬£¬£¬£¬£¬£¬´ó´ó¶¼µØÇøµÄ˾·¨²¿·Ö¶¼»á½«ÕâÒ»ÊÂÎñÊÓÎªÖØ´ó¹ýʧ£¬£¬£¬£¬£¬£¬£¬Õ⽫µ¼ÖÂÆóÒµÉùÓþÊÜË𣬣¬£¬£¬£¬£¬£¬ÎÞ·¨ÓëÊÜÓ°ÏìµÄ¿Í»§¼ÌÐøÏàÖú£¬£¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÄÜ»áÐÝÒµ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cayman-islands-bank-records-exposed-azure-blob/161729/


¾©¹«Íø°²±¸11010802024551ºÅ