VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡£¡£¡£¡£ ¡£¡£¡£»£» £»£»£»£»£»Tesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ

°ä²¼¹¦·ò 2020-11-25

1.VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡


1.png


VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐкÅÁ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδ°ä²¼Óйز¹¶¡·¨Ê½¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-4006£¬£¬£¬£¬£¬£¬£¬£¬CVSSµÈ¼¶Îª9.1£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢½Ó¼ûÏÎ½ÓÆ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÏÎ½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÐÔÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬VMwareÒѰ䲼һʱ½â¾ö·¨×ÓÒÔ½â³ý¹¥»÷ý½é²¢Ô¤·À·ì϶µÄÀûÓᣡ£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/vmware-zero-day-patch-pending/161523/


2.TikTok½¨¸´Á½¸ö¿Éµ¼ÖÂÕË»§ÊÕÊܵÄXSSºÍCSRF·ì϶


2.png


TikTok½¨¸´ÁËÁ½¸ö¿Éµ¼ÖÂÕË»§ÊÕÊܵÄXSSºÍCSRF·ì϶¡£¡£¡£¡£ ¡£¡£¡£µÚÒ»¸ö·ì϶ΪURL²ÎÊýÖеķÇÓÆ¾ÃÐÔ¿çÕ¾µã¾ç±¾£¨XSS£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸ÃURLµÄ²ÎÊý·µ»ØÁËδ¾­Êʵ±´¦ÖõÄÖµ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£ ¡£¡£¡£µÚ¶þ¸öΪAPI¶ËµãµÄ¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÆä¸ü¸ÄʹÓõÚÈý·½ÀûÓ÷¨Ê½×¢²áµÄÓû§µÄÕÊ»§ÃÜÂë¡£¡£¡£¡£ ¡£¡£¡£ºÚ¿ÍÄܹ»½áºÏÀûÓÃÕâÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔì×÷Ò»¸öµ¥Ò»µÄJavaScriptÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ´¥·¢CSRFºó½«Æä×¢Èëµ½Ò×Êܹ¥»÷µÄURL²ÎÊýÖУ¬£¬£¬£¬£¬£¬£¬£¬¶øºóÒ»¼üÊÕÊÜÕÊ»§¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tiktok-fixes-bugs-allowing-account-takeover-with-one-click/


3.FBI°ä²¼ÖÒ¸æ³ÆºÚ¿ÍαÔìÓëÆäÓйصÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢


3.jpg


FBI»¥ÁªÍø·¸×ïͶËßÖÐÐÄ£¨IC3£©°ä²¼ÖҸ棬£¬£¬£¬£¬£¬£¬£¬³ÆºÚ¿ÍαÔìÓëÆäÓйصÄÓòÃûÀ´ÇÔÈ¡Óû§ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£FBI°ä²¼´Ë²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔ®ÊÖ¹«¼Ò¼ø±ðºÍÔ¤·ÀÓëFBIÓйصĺýŪÐÔÓòÃû¡£¡£¡£¡£ ¡£¡£¡£Æä·¢ÏÖδ¾­×¢²áµÄºÚ¿Íͨ¹ýºýŪºÏ·¨µÄÁª¹úµ÷²é¾ÖÍøÕ¾×¢²áÁ˺ܶàÓò£¬£¬£¬£¬£¬£¬£¬£¬Õâ½²ÁËÈ»½«À´µÄ¹¥»÷»î¶¯µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß»ò½«Ê¹ÓÃαÔìµÄÓòÃûºÍµç×ÓÓʼþ´«²¼ÐéαÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÓÐЧµÄÓû§Ãû¡¢ÃÜÂëºÍµç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÓ×ÎÒÉí·ÝÐÅÏ¢²¢´«²¼¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö½øÒ»²½µÄ¹¥»÷»î¶¯ºÍ¿ÉÄܵIJÆÕþËðʧ¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-warns-of-recently-registered-domains-spoofing-its-sites/


4.Tesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ


4.jpg


±ÈÀûʱ°²È«×êÑÐÈËÔ±Lennert Wouters·¢ÏÖTesla Model XÃÜÔ¿¿¨´æÔÚ·ì϶¿ÉÓÃÀ´¼±¾ç½âËøÆû³µ¡£¡£¡£¡£ ¡£¡£¡£Wouters³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓôӾɵÄModel X³µÁ¾ÖлØÊյĵç×Ó½ÚÔìµ¥Ôª£¨ECU£©À´ÀûÓô˷ì϶¡£¡£¡£¡£ ¡£¡£¡£Ê×ÏȸÄ×°»ØÊÕµÄECUÀ´»½ÄܸɱêÃÜÔ¿¿¨£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÆäÏàПÃECUÊôÓÚÆäÅä¶Ô³µÁ¾¡£¡£¡£¡£ ¡£¡£¡£¶øºóͨ¹ýBLE£¨À¶ÑÀµÍÄܺģ©ºÍ̸½«¶ñÒâ¹Ì¼þ¸üÐÂÍÆË͵½¸ÃÃÜÔ¿¿¨¡£¡£¡£¡£ ¡£¡£¡£Ò»µ©³É¹¦ÈëÇÖÃÜÔ¿¿¨£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻá´ÓÖÐÌáÈ¡Æû³µ½âËøÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬¶øºóÀûÓÃÕâЩ½âËøÐÅÏ¢½øÈëÖ¸±ê³µÁ¾¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tesla-model-x-hacked-and-stolen-in-minutes-using-new-key-fob-hack/


5.Å·ÃËENISA°ä²¼È·±£ÎïÁªÍø¹©¸øÁ´°²È«µÄÖ¸ÄÏ


5.jpg


Å·ÃËÍøÂ簲ȫ»ú¹¹£¨ENISA)°ä²¼ÁËÈ·±£ÎïÁªÍø¹©¸øÁ´°²È«µÄÖ¸ÄÏ¡£¡£¡£¡£ ¡£¡£¡£¸ÃÖ¸ÄÏÌá³öÁËÓ빩¸øÁ´ÓйصķçÏÕ·ÖÎöµÄÁ˾Ö£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇ»ùÓÚ¶ÔÓ°Ï칩¸øÁ´²Î¼ÓÕß¡¢Á÷³ÌºÍ¼¼ÊõµÄÏÖ´úÍþвµÄÇ°ÑØ×êÑÓ×£¡£¡£¡£ ¡£¡£¡£Æ¾¾Ý·ÖÎöÁ˾ֵóö½áÂÛ£¬£¬£¬£¬£¬£¬£¬£¬ÎªÈ·±£ÎïÁªÍø¹©¸øÁ´°²È«Ó¦ÔÚ¹©¸øÁ´²Î¼ÓÕßÖ®¼ä³ÉÁ¢¸üºÃµÄ¹ØÏµ£»£» £»£»£»£»£»²»ÐÝÈ«Ãæ¼Óǿϵͳ¿ª·¢ÈËÔ±ºÍÓû§µÄÍøÂ簲ȫרҵ֪ʶ£»£» £»£»£»£»£»Ñ¡È¡Éè¼Æ°²È«×¼Ôò£»£» £»£»£»£»£»¶Ô°²È«²ÉÈ¡È«Ãæ¶øÃ÷È·µÄ²½Ö裬£¬£¬£¬£¬£¬£¬£¬Ã÷ȷ˼¿¼ËùÓÐÓйØÍþв²¢²ÉÈ¡ÏàÓ¦´ëÊ©£»£» £»£»£»£»£»ÀûÓÃÏÖÓеݲȫ³ß¶ÈºÍÓÅÁ¼×ö·¨¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ics-cert.kaspersky.com/news/2020/11/23/enisa-publishes-guidelines-for-securing-internet-of-things-supply-chain/


6.GBG°ä²¼2020Äê¶Å×йØÊý×ÖÉí·ÝµÄÌ¬ÊÆ·ÖÎö»ã±¨


6.jpg


GBG°ä²¼2020Äê¶ÈÊý×ÖÉí·ÝÌ¬ÊÆµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬²¢³Æ2020ÄêÓÐÎå·ÖÖ®Ò»µÄÏû·ÑÕßÊܵ½Éí·ÝڲƭµÄÓ°Ïì¡£¡£¡£¡£ ¡£¡£¡£¸Ã»ã±¨·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚCOVID-19ÒÔÀ´Éí·Ý͵ÇÔÊÂÎñµÄÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ÆóÒµºÍÏû·ÑÕßÖ®¼äµÄÐÅÀµ²î¾à¿ÉÄÜ»áÀ©´ó¡£¡£¡£¡£ ¡£¡£¡£ÓÉÓÚÉç»á¸ôÀëµÄÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬ÈËÃÇÔ½À´Ô½ÒÀÀµÊý×Ö·þÎñ¡£¡£¡£¡£ ¡£¡£¡£GBGÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬µ½2020Ä꣬£¬£¬£¬£¬£¬£¬£¬ÓÐ47£¥µÄÈË¿ªÉèÁËеÄÔÚÏß¹ºÎïÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬¶ø35£¥µÄÈË¿ªÉèÁËеÄÉ罻ýÌåÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬ÓÐ31£¥µÄÈË¿ªÉèÁËÔÚÏßÒøÐÐÕÊ»§¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÓÐ33£¥µÄ¹«¼ÒÒÔΪËûÃǵÄÓ×ÎÒÐÅϢĿǰÔÚ°µÍøÉÏÏúÊÛ¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.gbgplc.com/the-gbg-state-of-digital-identity-2020/