GitHub°ä²¼2020Äê¶ÈOctoverseÌ¬ÊÆµÄ·ÖÎö»ã±¨£»£»£»£»£»¹È¸èÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶
°ä²¼¹¦·ò 2020-12-04
GitHub°ä²¼ÁË2020Äê¶ÈOctoverseÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨ÖØÒªÍ³¼ÆÁ˳¬¹ý5600ÍòÃû¿ª·¢ÈËÔ±ÔÚ2020Äê´´½¨µÄ³¬¹ý6000Íò¸öд洢¿â¡£¡£¡£¡£¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬£¬£¬£¬£¬Óë2019ÄêÏà±È£¬£¬£¬£¬£¬£¬´Ë¿Ì94£¥µÄÏîÄ¿ÒÀÀµ¿ªÔ´×é¼þ£¬£¬£¬£¬£¬£¬¾ùÔÈÓп¿½ü700¸öÒÀÀµÏ£¬£¬£¬£¬£¬JavaScriptÖÐÓÐ94£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬¶øRubyºÍ.NETÖÐÓÐ90£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¿ªÔ´Èí¼þÖеĴóÎÞÊý·ì϶²¢²»ÊǶñÒâµÄ£¬£¬£¬£¬£¬£¬Ïà·´£¬£¬£¬£¬£¬£¬GitHub·¢³öµÄCVE¾¯±¨ÖÐÓÐ83£¥µÄ·ì϶ÊÇÓɱ¨´ðÃýÎóÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://octoverse.github.com/
2.IBM°ä²¼Õë¶ÔCOVID-19ÒßÃ繩¸øÁ´µÄ¹¥»÷»î¶¯µÄ»ã±¨

IBM X-Force°ä²¼ÁËÕë¶ÔCOVID-19ÒßÃ繩¸øÁ´µÄ¹¥»÷»î¶¯µÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£ÔÚCOVID-19Æðͷʱ£¬£¬£¬£¬£¬£¬IBM X-Force³ÉÁ¢ÁËÍþвµý±¨³ö¸ñ¹¤×÷×飬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚ×·×ÙÕë¶ÔÒßÃ繩¸øÁ´ÔËÐеÄ×éÖ¯µÄÍøÂçÍþв£¬£¬£¬£¬£¬£¬¸ÃÍŶÓ×î½ü·¢ÏÖÁËÒ»³¡Õë¶ÔÓëCOVID-19ÀäÁ´ÓйØ×éÖ¯µÄÈ«Çò´¹µö»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÓâÔ½Áù¸ö¹ú¶È£¬£¬£¬£¬£¬£¬Ö¸±ê¿ÉÄÜÓëÈ«ÇòÒßÃçÃâÒßÁªÃË(Gavi)µÄÀäÁ´É豸ÓÅ»¯Æ½Ì¨(CCEOP)ÏîÄ¿Óйأ¬£¬£¬£¬£¬£¬»òÓë¹ú¶È¼äµý×éÖ¯Óйء£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/
3.Xerox°ä²¼²¹¶¡£¬£¬£¬£¬£¬£¬½¨¸´DocuShareÖеÄSSRFºÍXXE·ì϶

Xerox°ä²¼²¹¶¡£¬£¬£¬£¬£¬£¬½¨¸´ÆóÒµÎĵµÖÎÀíÆ½Ì¨DocuShareÖеÄSSRFºÍXXE·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-27177£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂSolaris¡¢LinuxºÍWindows DucuShareÓû§Ôâµ½·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©¹¥»÷ºÍδ¾Éí·ÝÑéÖ¤µÄ±í²¿XMLʵÌå×¢Èë¹¥»÷£¨XXE£©¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬¿É»ñµÃ¶ÔÖ¸±êϵͳ»úÃÜÊý¾ÝµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´Ð¹Â©¾ßÌå·ì϶ÏêÇ飬£¬£¬£¬£¬£¬µ«ÌṩÁ˽¨¸´·¨Ê½Á´½Ó£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÊÜÓ°Ïì°æ±¾Öеķì϶¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/xerox-docushare-bugs/161791/
4.¹È¸èÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶

Google Project ZeroÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-3843£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öË«³Á¿ªÊÍ·ì϶£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓø÷ì϶Äܹ»½Ó¼ûÕÕÆ¬ºÍÆäËûÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþºÍ¸öÈËÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«Ö¸±êËø¶¨ÔÚAirDrop BTLE¿ò¼ÜÉÏ£¬£¬£¬£¬£¬£¬Í¨¹ýÇ¿ÔìʹÓô洢ÔÚÉ豸ÖеÄÁªÏµÈ˵ĹþÏ£Ö·´ÆôÓÃAWDL½Ó¿Ú£¬£¬£¬£¬£¬£¬¶øºó´¥·¢»º³åÇøÒç³öÒÔ»ñµÃ¶ÔÉ豸µÄ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬²¢ÒÔ¸ùÓû§Éí·ÝÖ²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬ÊµÏÖ¶ÔÉ豸µÄÆëÈ«½ÚÔì¡£¡£¡£¡£¡£¡£¡£¡£Éв»Ã÷ÏԸ÷ì϶ÊÇ·ñ±»ÔÚÒ°ÀûÓ㬣¬£¬£¬£¬£¬µ«Óйس§ÉÌÒѰ䲼½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111788/mobile-2/iphone-devices-hack.html
5.¶íAPT×éÖ¯TurlaÀûÓÃжñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ

¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃеĶñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯Turla×Ô2007ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬Õë¶ÔÔÚÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀ¡¢ÄÏÃÀ¡¢ºÍǰËÕÁª¼¯ÍŵĹ«Ë¾ºÍ±í½»µÈµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£ESET×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬TurlaÀûÓÃCrutchÔÚÕë¶ÔÅ·Ã˹ú¶ÈµÄ±í½»²¿µÄÍøÂç¼äµý»î¶¯ÖУ¬£¬£¬£¬£¬£¬²¿ÊðºóÃÅ·¨Ê½²¢ÇÔÈ¡Ãô¸ÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Crutch¿ÉÄÜÀûÓúϷ¨»ù´¡ÉèÊ©DropboxÀ´ÈƹýijЩ°²È«²ã£¬£¬£¬£¬£¬£¬ÒÔÈëÇÖÕý³£µÄÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬£¬ÇÔÈ¡Îĵµ²¢´ÓºÚ¿Í×éÖ¯ÄÇÀï½Ó¹ÜºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-hacking-group-uses-dropbox-to-store-malware-stolen-data/
6.¿ªÂüȺµºÒøÐÐÅäÖÃÃýÎóµÄAzure Blobй¶Óû§Ó×ÎÒÊý¾Ý

¿ªÂüȺµºÀë°¶ÒøÐÐÅäÖÃÃýÎóµÄAzure Blobй¶Óû§Ó×ÎÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñй¶µÄ±¸·ÝÊý¾Ýº¸ÇÁË5ÒÚÃÀԪͶ×Ê×éºÏ£¬£¬£¬£¬£¬£¬Ô̺¬Ó×ÎÒÒøÐÐÐÅÏ¢¡¢»¤ÕÕÊý¾ÝÉõÖÁÊÇÍøÉÏÒøÐеÄPINÂë¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚMicrosoft Azure BlobÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑɾ³ý¶àÄêµÄ±¸·ÝÊý¾Ý·Çµ«Ã»ÓÐÒþû£¬£¬£¬£¬£¬£¬·´¶øÖ±µ½×î½ü¶¼Äܹ»ÇáËÉÔÚÏß»ñµÃ¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Ä¿Ç°Ð¹Â¶Êý¾ÝÒѱ»IT¹©¸øÉÌÒÆ³ý¡£¡£¡£¡£¡£¡£¡£¡£ImmuniWebµÄCEO³Æ£¬£¬£¬£¬£¬£¬´óÎÞÊýµØÓòµÄ˾·¨²¿ÃųÇÊн«ÕâÒ»ÊÂÎñÊÓΪ³Á´ó´íÎ󣬣¬£¬£¬£¬£¬Õ⽫µ¼ÖÂÆóÒµÃûÓþÊÜË𣬣¬£¬£¬£¬£¬ÎÞ·¨ÓëÊÜÓ°ÏìµÄ¿Í»§³ÖÐøºÏ×÷£¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÄÜ»áÆÆ²ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cayman-islands-bank-records-exposed-azure-blob/161729/


¾©¹«Íø°²±¸11010802024551ºÅ