GitHubÐû²¼2020Äê¶ÈOctoverseÌ¬ÊÆµÄÆÊÎö±¨¸æ£»¹È¸èÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î

Ðû²¼Ê±¼ä 2020-12-04
1.GitHubÐû²¼2020Äê¶ÈOctoverseÌ¬ÊÆµÄÆÊÎö±¨¸æ


1.jpg


GitHubÐû²¼ÁË2020Äê¶ÈOctoverseÌ¬ÊÆµÄÆÊÎö±¨¸æ ¡£¸Ã±¨¸æÖ÷Ҫͳ¼ÆÁËÁè¼Ý5600ÍòÃû¿ª·¢Ö°Ô±ÔÚ2020Ä꽨ÉèµÄÁè¼Ý6000Íò¸öд洢¿â ¡£Ñо¿·¢Ã÷ £¬Óë2019ÄêÏà±È £¬ÏÖÔÚ94£¥µÄÏîÄ¿ÒÀÀµ¿ªÔ´×é¼þ £¬Æ½¾ùÓп¿½ü700¸öÒÀÀµÏî £¬JavaScriptÖÐÓÐ94£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ £¬¶øRubyºÍ.NETÖÐÓÐ90£¥µÄ¿ªÔ´ÒÀÀµ¹ØÏµ ¡£±ðµÄ £¬¿ªÔ´Èí¼þÖеĴó´ó¶¼Îó²î²¢²»ÊǶñÒâµÄ £¬Ïà·´ £¬GitHub·¢³öµÄCVE¾¯±¨ÖÐÓÐ83£¥µÄÎó²îÊÇÓÉÈËΪ¹ýʧÒýÆðµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://octoverse.github.com/


2.IBMÐû²¼Õë¶ÔCOVID-19ÒßÃ繩ӦÁ´µÄ¹¥»÷Ô˶¯µÄ±¨¸æ


2.jpg


IBM X-ForceÐû²¼ÁËÕë¶ÔCOVID-19ÒßÃ繩ӦÁ´µÄ¹¥»÷Ô˶¯µÄ±¨¸æ ¡£ÔÚCOVID-19×îÏÈʱ £¬IBM X-Force½¨ÉèÁËÍþвÇé±¨ÌØÊâÊÂÇé×é £¬ÖÂÁ¦ÓÚ×·×ÙÕë¶ÔÒßÃ繩ӦÁ´ÔËתµÄ×éÖ¯µÄÍøÂçÍþв £¬¸ÃÍŶÓ×î½ü·¢Ã÷ÁËÒ»³¡Õë¶ÔÓëCOVID-19ÀäÁ´Ïà¹Ø×éÖ¯µÄÈ«Çò´¹ÂÚÔ˶¯ ¡£´Ë´Î¹¥»÷Ô˶¯¿çÔ½Áù¸ö¹ú¼Ò £¬Ä¿µÄ¿ÉÄÜÓëÈ«ÇòÒßÃçÃâÒßͬÃË(Gavi)µÄÀäÁ´×°±¸ÓÅ»¯Æ½Ì¨(CCEOP)ÏîÄ¿ÓйØ £¬»òÓë¹ú¼ÒÌØ¹¤×éÖ¯ÓйØ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/


3.XeroxÐû²¼²¹¶¡ £¬ÐÞ¸´DocuShareÖеÄSSRFºÍXXEÎó²î


3.jpg


XeroxÐû²¼²¹¶¡ £¬ÐÞ¸´ÆóÒµÎĵµ¹ÜÀíÆ½Ì¨DocuShareÖеÄSSRFºÍXXEÎó²î ¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-27177 £¬¿Éµ¼ÖÂSolaris¡¢LinuxºÍWindows DucuShareÓû§Ôâµ½·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©¹¥»÷ºÍδ¾­Éí·ÝÑéÖ¤µÄÍⲿXMLʵÌå×¢Èë¹¥»÷£¨XXE£© ¡£¹¥»÷ÕßÀÖ³ÉʹÓÃÕâЩÎó²î £¬¿É»ñµÃ¶ÔÄ¿µÄϵͳÉñÃØÊý¾ÝµÄ»á¼ûȨÏÞ ¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶ÏêϸÎó²îÏêÇé £¬µ«ÌṩÁËÐÞ¸´³ÌÐòÁ´½Ó £¬ÒÔ½â¾öÊÜÓ°Ïì°æ±¾ÖеÄÎó²î ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/xerox-docushare-bugs/161791/


4.¹È¸èÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î


4.jpg


Google Project ZeroÅû¶iOSÖпÉͨ¹ýWi-Fi½ÓÊÜÖÜΧí§Òâ×°±¸µÄÎó²î ¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-3843 £¬ÊÇÒ»¸öË«ÖØÊÍ·ÅÎó²î £¬ºÚ¿ÍʹÓøÃÎó²î¿ÉÒÔ»á¼ûÕÕÆ¬ºÍÆäËûÃô¸ÐÊý¾Ý £¬°üÀ¨µç×ÓÓʼþºÍ˽ÈËÐÂÎÅ ¡£¹¥»÷Õß½«Ä¿µÄËø¶¨ÔÚAirDrop BTLE¿ò¼ÜÉÏ £¬Í¨¹ýÇ¿ÖÆÊ¹Óô洢ÔÚ×°±¸ÖеÄÁªÏµÈ˵ĹþÏ£ÖµÀ´ÆôÓÃAWDL½Ó¿Ú £¬È»ºó´¥·¢»º³åÇøÒç³öÒÔ»ñµÃ¶Ô×°±¸µÄ»á¼ûȨ £¬²¢ÒÔ¸ùÓû§Éí·ÝÖ²Èë¶ñÒâ´úÂë £¬ÊµÏÖ¶Ô×°±¸µÄÍêÈ«¿ØÖÆ ¡£Éв»ÇåÎú¸ÃÎó²îÊÇ·ñ±»ÔÚҰʹÓà £¬µ«Ïà¹Ø³§ÉÌÒÑÐû²¼ÐÞ¸´³ÌÐò ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111788/mobile-2/iphone-devices-hack.html


5.¶íAPT×éÖ¯TurlaʹÓÃжñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ


5.jpg


¶íÂÞ˹APT×éÖ¯TurlaʹÓÃеĶñÒâÈí¼þCrutchÇÔÈ¡Ãô¸ÐÎļþ ¡£¸ÃAPT×éÖ¯Turla×Ô2007ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬Õë¶ÔÔÚÖж«¡¢ÑÇÖÞ¡¢Å·ÖÞ¡¢±±ÃÀ¡¢ÄÏÃÀ¡¢ºÍǰËÕÁª¼¯ÍŵĹ«Ë¾ºÍÍâ½»µÈÕþ¸®»ú¹¹ ¡£ESETÑо¿Ö°Ô±·¢Ã÷ £¬TurlaʹÓÃCrutchÔÚÕë¶ÔÅ·ÓѰî¼ÒµÄÍâ½»²¿µÄÍøÂçÌØ¹¤Ô˶¯ÖÐ £¬°²ÅźóÃųÌÐò²¢ÇÔÈ¡Ãô¸ÐÎļþ ¡£±ðµÄ £¬CrutchÄܹ»Ê¹ÓÃÕýµ±»ù´¡ÉèÊ©DropboxÀ´ÈƹýijЩÇå¾²²ã £¬ÒÔÈëÇÖÕý³£µÄÍøÂçÁ÷Á¿ £¬ÇÔÈ¡Îĵµ²¢´ÓºÚ¿Í×éÖ¯ÄÇÀïÎüÊÕÏÂÁî ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-hacking-group-uses-dropbox-to-store-malware-stolen-data/


6.¿ªÂüȺµºÒøÐÐÉèÖùýʧµÄAzure Blobй¶Óû§Ð¡ÎÒ˽¼ÒÊý¾Ý


6.jpg


¿ªÂüȺµºÀë°¶ÒøÐÐÉèÖùýʧµÄAzure Blobй¶Óû§Ð¡ÎÒ˽¼ÒÊý¾Ý ¡£´Ë´ÎÊÂÎñй¶µÄ±¸·ÝÊý¾Ýº­¸ÇÁË5ÒÚÃÀԪͶ×Ê×éºÏ £¬°üÀ¨Ð¡ÎÒ˽¼ÒÒøÐÐÐÅÏ¢¡¢»¤ÕÕÊý¾ÝÉõÖÁÊÇÍøÉÏÒøÐеÄPINÂë ¡£ÓÉÓÚMicrosoft Azure BlobÉèÖùýʧ £¬¸Ã¹«Ë¾ÒÑɾ³ý¶àÄêµÄ±¸·ÝÊý¾Ý·Çµ«Ã»ÓÐÏûÊÅ £¬·´¶øÖ±µ½×î½ü¶¼¿ÉÒÔÇáËÉÔÚÏß»ñµÃ ¡£¾ÝϤ £¬ÏÖÔÚй¶Êý¾ÝÒѱ»IT¹©Ó¦ÉÌÒÆ³ý ¡£ImmuniWebµÄCEO³Æ £¬´ó´ó¶¼µØÇøµÄ˾·¨²¿·Ö¶¼»á½«ÕâÒ»ÊÂÎñÊÓÎªÖØ´ó¹ýʧ £¬Õ⽫µ¼ÖÂÆóÒµÉùÓþÊÜË𠣬ÎÞ·¨ÓëÊÜÓ°ÏìµÄ¿Í»§¼ÌÐøºÏ×÷ £¬×îÖÕ¿ÉÄÜ»áÐÝÒµ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cayman-islands-bank-records-exposed-azure-blob/161729/