GitHub°ä²¼2020Äê¶ÈOctoverseÌ¬ÊÆµÄ·ÖÎö»ã±¨£»¹È¸èÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶
°ä²¼¹¦·ò 2020-12-04
GitHub°ä²¼ÁË2020Äê¶ÈOctoverseÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨ÖØÒªÍ³¼ÆÁ˳¬¹ý5600ÍòÃû¿ª·¢ÈËÔ±ÔÚ2020Äê´´½¨µÄ³¬¹ý6000Íò¸öд洢¿â¡£×êÑз¢ÏÖ£¬Óë2019ÄêÏà±È£¬´Ë¿Ì94£¥µÄÏîÄ¿ÒÀÀµ¿ªÔ´×é¼þ£¬¾ùÔÈÓп¿½ü700¸öÒÀÀµÏJavaScriptÖÐÓÐ94£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ£¬¶øRubyºÍ.NETÖÐÓÐ90£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ¡£´Ë±í£¬¿ªÔ´Èí¼þÖеĴóÎÞÊý·ì϶²¢²»ÊǶñÒâµÄ£¬Ïà·´£¬GitHub·¢³öµÄCVE¾¯±¨ÖÐÓÐ83£¥µÄ·ì϶ÊÇÓɱ¨´ðÃýÎóÒýÆðµÄ¡£
ÔÎÄÁ´½Ó£º
https://octoverse.github.com/
2.IBM°ä²¼Õë¶ÔCOVID-19ÒßÃ繩¸øÁ´µÄ¹¥»÷»î¶¯µÄ»ã±¨

IBM X-Force°ä²¼ÁËÕë¶ÔCOVID-19ÒßÃ繩¸øÁ´µÄ¹¥»÷»î¶¯µÄ»ã±¨¡£ÔÚCOVID-19Æðͷʱ£¬IBM X-Force³ÉÁ¢ÁËÍþвµý±¨³ö¸ñ¹¤×÷×飬ÖÂÁ¦ÓÚ×·×ÙÕë¶ÔÒßÃ繩¸øÁ´ÔËÐеÄ×éÖ¯µÄÍøÂçÍþв£¬¸ÃÍŶÓ×î½ü·¢ÏÖÁËÒ»³¡Õë¶ÔÓëCOVID-19ÀäÁ´ÓйØ×éÖ¯µÄÈ«Çò´¹µö»î¶¯¡£Õâ´Î¹¥»÷»î¶¯ÓâÔ½Áù¸ö¹ú¶È£¬Ö¸±ê¿ÉÄÜÓëÈ«ÇòÒßÃçÃâÒßͬÃË(Gavi)µÄÀäÁ´É豸ÓÅ»¯Æ½Ì¨(CCEOP)ÏîÄ¿Óйأ¬»òÓë¹ú¶È¼äµý×éÖ¯Óйء£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/
3.Xerox°ä²¼²¹¶¡£¬½¨¸´DocuShareÖеÄSSRFºÍXXE·ì϶

Xerox°ä²¼²¹¶¡£¬½¨¸´ÆóÒµÎĵµÖÎÀíÆ½Ì¨DocuShareÖеÄSSRFºÍXXE·ì϶¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-27177£¬¿Éµ¼ÖÂSolaris¡¢LinuxºÍWindows DucuShareÓû§Ôâµ½·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©¹¥»÷ºÍδ¾Éí·ÝÑéÖ¤µÄ±í²¿XMLʵÌå×¢Èë¹¥»÷£¨XXE£©¡£¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶£¬¿É»ñµÃ¶ÔÖ¸±êϵͳ»úÃÜÊý¾ÝµÄ½Ó¼ûȨÏÞ¡£¸Ã¹«Ë¾²¢Î´Ð¹Â©¾ßÌå·ì϶ÏêÇ飬µ«ÌṩÁ˽¨¸´·¨Ê½Á´½Ó£¬ÒÔ½â¾öÊÜÓ°Ïì°æ±¾Öеķì϶¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/xerox-docushare-bugs/161791/
4.¹È¸èÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶

Google Project ZeroÅû¶iOSÖпÉͨ¹ýWi-FiÊÕÊÜ×ó½üËÁÒâÉ豸µÄ·ì϶¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-3843£¬ÊÇÒ»¸öË«³Á¿ªÊÍ·ì϶£¬ºÚ¿ÍÀûÓø÷ì϶Äܹ»½Ó¼ûÕÕÆ¬ºÍÆäËûÃô¸ÐÊý¾Ý£¬Ô̺¬µç×ÓÓʼþºÍ¸öÈËÐÂÎÅ¡£¹¥»÷Õß½«Ö¸±êËø¶¨ÔÚAirDrop BTLE¿ò¼ÜÉÏ£¬Í¨¹ýÇ¿ÔìʹÓô洢ÔÚÉ豸ÖеÄÁªÏµÈ˵ĹþÏ£Ö·´ÆôÓÃAWDL½Ó¿Ú£¬¶øºó´¥·¢»º³åÇøÒç³öÒÔ»ñµÃ¶ÔÉ豸µÄ½Ó¼ûȨ£¬²¢ÒÔ¸ùÓû§Éí·ÝÖ²Èë¶ñÒâ´úÂ룬ʵÏÖ¶ÔÉ豸µÄÆëÈ«½ÚÔì¡£Éв»Ã÷ÏԸ÷ì϶ÊÇ·ñ±»ÔÚÒ°ÀûÓ㬵«Óйس§ÉÌÒѰ䲼½¨¸´·¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111788/mobile-2/iphone-devices-hack.html
5.¶íAPT×éÖ¯TurlaÀûÓÃжñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ

¶íÂÞ˹APT×éÖ¯TurlaÀûÓÃеĶñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ¡£¸ÃAPT×éÖ¯Turla×Ô2007ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Õë¶ÔÔÚÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀ¡¢ÄÏÃÀ¡¢ºÍǰËÕÁª¼¯ÍŵĹ«Ë¾ºÍ±í½»µÈµ±¾Ö»ú¹¹¡£ESET×êÑÐÈËÔ±·¢ÏÖ£¬TurlaÀûÓÃCrutchÔÚÕë¶ÔÅ·Ã˹ú¶ÈµÄ±í½»²¿µÄÍøÂç¼äµý»î¶¯ÖУ¬²¿ÊðºóÃÅ·¨Ê½²¢ÇÔÈ¡Ãô¸ÐÎļþ¡£´Ë±í£¬Crutch¿ÉÄÜÀûÓúϷ¨»ù´¡ÉèÊ©DropboxÀ´ÈƹýijЩ°²È«²ã£¬ÒÔÈëÇÖÕý³£µÄÍøÂçÁ÷Á¿£¬ÇÔÈ¡Îĵµ²¢´ÓºÚ¿Í×éÖ¯ÄÇÀï½Ó¹ÜºÅÁî¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-hacking-group-uses-dropbox-to-store-malware-stolen-data/
6.¿ªÂüȺµºÒøÐÐÅäÖÃÃýÎóµÄAzure Blobй¶Óû§Ó×ÎÒÊý¾Ý

¿ªÂüȺµºÀë°¶ÒøÐÐÅäÖÃÃýÎóµÄAzure Blobй¶Óû§Ó×ÎÒÊý¾Ý¡£Õâ´ÎÊÂÎñй¶µÄ±¸·ÝÊý¾Ýº¸ÇÁË5ÒÚÃÀԪͶ×Ê×éºÏ£¬Ô̺¬Ó×ÎÒÒøÐÐÐÅÏ¢¡¢»¤ÕÕÊý¾ÝÉõÖÁÊÇÍøÉÏÒøÐеÄPINÂë¡£ÓÉÓÚMicrosoft Azure BlobÅäÖÃÃýÎ󣬸ù«Ë¾ÒÑɾ³ý¶àÄêµÄ±¸·ÝÊý¾Ý·Çµ«Ã»ÓÐÒþû£¬·´¶øÖ±µ½×î½ü¶¼Äܹ»ÇáËÉÔÚÏß»ñµÃ¡£¾ÝϤ£¬Ä¿Ç°Ð¹Â¶Êý¾ÝÒѱ»IT¹©¸øÉÌÒÆ³ý¡£ImmuniWebµÄCEO³Æ£¬´óÎÞÊýµØÓòµÄ˾·¨²¿ÃųÇÊн«ÕâÒ»ÊÂÎñÊÓΪ³Á´ó´íÎó£¬Õ⽫µ¼ÖÂÆóÒµÃûÓþÊÜËð£¬ÎÞ·¨ÓëÊÜÓ°ÏìµÄ¿Í»§³ÖÐøºÏ×÷£¬×îÖÕ¿ÉÄÜ»áÆÆ²ú¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cayman-islands-bank-records-exposed-azure-blob/161729/


¾©¹«Íø°²±¸11010802024551ºÅ