Apple°ä²¼¸üУ¬£¬£¬£¬£¬ £¬£¬£¬½¨¸´Òѱ»»ý¼«ÀûÓõÄ3¸ö0day£»£»£»£»£»Microsoft²úÉú·þÎñÖжÏ£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö²¿ÃÅÍøÕ¾ÎÞ·¨½Ó¼û

°ä²¼¹¦·ò 2020-11-06

1.Apple°ä²¼¸üУ¬£¬£¬£¬£¬ £¬£¬£¬½¨¸´Òѱ»»ý¼«ÀûÓõÄ3¸ö0day


1.jpg


Apple½¨¸´ÁËÆäiOS 14.2ÖеÄ3¸ö0day£¬£¬£¬£¬£¬ £¬£¬£¬ÕâЩ·ì϶ÒÑÔÚÒ°±í±»»ý¼«ÀûÓò¢Ó°ÏìÁËiPhone¡¢iPadºÍiPod¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪԶ³ÌÖ´ÐдúÂ루RCE£©·ì϶£¨CVE-2020-27930 £©£¬£¬£¬£¬£¬ £¬£¬£¬FontParser¿â´¦ÖöñÒâ×ÖÌåʱÓÉÄÚ´æ°Ü»µÎÊÌâµ¼Ö£»£»£»£»£»ÄÚºËÄÚ´æÐ¹Â©·ì϶£¨CVE-2020-27950£©£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÓÉÄÚ´æ³õʼ»¯ÎÊÌâÒýÆð£¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐí¶ñÒâÀûÓýӼûÄÚºËÄڴ棻£»£»£»£»ÄÚºËÌáȨ·ì϶(CVE-2020-27932)£¬£¬£¬£¬£¬ £¬£¬£¬ÓÉÀàÐÍ»ìºÏµ¼Ö£¬£¬£¬£¬£¬ £¬£¬£¬¿É±»ÀûÓÃÀ´Ê¹ÓÃÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-patches-three-actively-exploited-ios-zero-days/


2.Microsoft²úÉú·þÎñÖжÏ£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö²¿ÃÅÍøÕ¾ÎÞ·¨½Ó¼û


2.jpg


Microsoft·þÎñÖжÏ£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö²¿ÃÅÍøÕ¾ÄÚÈÝÎÞ·¨ÕýÈ·ÏÔʾ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒMicrosoft StoreÎÞ·¨¼ÓÔØ¡£¡£¡£¡£¡£Óû§½Ó¼ûwww.microsoft.com¡¢windows.com»òxbox.com×ÓÓòʱ£¬£¬£¬£¬£¬ £¬£¬£¬»áÓöµ½ÍøÕ¾²¼¾ÖÃýÎó»òÄúµÄÒªÇóÒѱ»×èÖ¹µÄÌáÐÑ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬Microsoft StoreÒ²ÎÞ·¨´Ómicrosoft.com»ñÈ¡Êý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬µ±Óû§³¢ÊÔ½Ó¼û¸ÃÀûÓÃʱ»áÏÔÊ¾Ò³ÃæÎÞ·¨¼ÓÔØµÄÃýÎóÌáÐÑ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÖжÏÒѱ»½¨¸´£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÊÇÖжÏÔ­ÒòÉв»Ã÷È·¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-outage-breaks-sites-windows-store-xbox-and-other-services/


3.ÓÎÏ·¹«Ë¾CapcomÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Æä²¿ÃÅϵͳÊܵ½Ó°Ïì


3.png


ÈÕ±¾ÓÎÏ·¿ª·¢ÉÌCapcomÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬Æä²¿ÃÅϵͳÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬£¬£¬²¢Ð¹Â¶ÁË1TBÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Capcom³Æ´Ó2020Äê11ÔÂ2ÈÕÁ賿ÆðÍ·Æä¹«Ë¾µÄÍøÂç³öÏÖÎÊÌ⣬£¬£¬£¬£¬ £¬£¬£¬²¢Ó°ÏìÁËÔ̺¬µç×ÓÓʼþºÍÎļþ·þÎñÆ÷ÔÚÄÚµÄijЩϵͳ¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±Pancak3ͨ¹ý×êÑÐÀÕË÷Èí¼þÑù±¾£¬£¬£¬£¬£¬ £¬£¬£¬·¢ÏÖ¿ÉÄÜÊÇRagnar Locker¶ÔÆä½øÐÐÁ˹¥»÷¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÀÕË÷ÍÅ»ïÐû³ÆÒÑ´ÓÆäÔÚÈÕ±¾¡¢ÃÀ¹úºÍ¼ÓÄôóµÄ×Ó¹«Ë¾ÇÔÈ¡1 TBµÄÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬¹ÜÕʵµ°¸¡¢ÒøÐб¨±í¡¢Ô¤ËãºÍÊÕÈ롢˰ÎñÎļþ¡¢ÖªÊ¶²úȨ¡¢×¨ÓÐÒµÎñÐÅÏ¢¡¢¿Í»§ºÍÔ±¹¤Ó×ÎÒÐÅÏ¢(È绤ÕÕºÍǩ֤)¡¢¹«Ë¾ºÍ̸ºÍºÏͬ¡¢±£ÃܺÍ̸¡¢ÏúÊÛ×ܽᡢ¹«Ë¾º¯¼þ¡¢µç×ÓÓʼþ¡¢ÓªÏú»ã±¨¡¢Éó¼Æ»ã±¨ºÍºÜ¶àÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/japanese-game-dev-capcom-hit-by-cyberattack-business-impacted/


4.Sophos·¢ÏÖAPT KillSomeOne¶ÔÃåµéÌáÒéµÄ¹¥»÷»î¶¯


4.png


°²È«¹©¸øÉÌSophos·¢ÏÖAPT×éÖ¯KillSomeOne¶ÔÃåµéÌáÒéµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÇÒ»ÖÖDLL²àÔØ¹¥»÷£¨DLL side-loading attack£©£¬£¬£¬£¬£¬ £¬£¬£¬ËüÓÕʹWindows¿ÉÖ´ÐÐÎļþ¼ÓÔØ¶ñÒâDLL£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬SophosÅú×¢£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÁË´óÐÍÍŶÓËùʹÓõĵäÐÍÖ¸±êËø¶¨ºÍ²¿ÊðÕ½Êõ£¬£¬£¬£¬£¬ £¬£¬£¬µ«Ê¹ÓÃÁ˵¥Ò»µÄ´úÂë¡¢Èõ¼ÓÃܺͰµ²ØµÄÐÂÎÅÀ´½«Õâ´Î»î¶¯¼Ù×°³É¾ç±¾Ó××ÓµÄÐÐΪ¡£¡£¡£¡£¡£SophosÒÔΪÕâ´Î»î¶¯µÄ¶¯»ú¿ÉÄÜÊÇΪ»ñµÃÒøÐÐÕË»§ÃÜÂëÀ´Ä²Àû£¬£¬£¬£¬£¬ £¬£¬£¬»òÕß³öÓÚÕþÖÎÖ÷ÕÅ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/11/05/killsomeone_dll_attack/


5.ApplebotÒò´úÀí·þÎñÆ÷ÅäÖÃÃýÎóй¶ÄÚ²¿IPµØÖ·


5.png


°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ´úÀí·þÎñÆ÷ÅäÖÃÃýÎ󣬣¬£¬£¬£¬ £¬£¬£¬ApplebotÒ»ÏòÔÚй©ÄÚ²¿IPµØÖ·¡£¡£¡£¡£¡£ApplebotÊÇÖ¸AppleµÄWebËÑË÷Æ÷£¬£¬£¬£¬£¬ £¬£¬£¬ËüÄܹ»É¨ÃèÍøÂçÀ´ÎªÆäÓû§²éÕÒÄÚÈÝ£¬£¬£¬£¬£¬ £¬£¬£¬SiriºÍSpotlightµÈ²úÆ·¶¼ÔÚʹÓᣡ£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬Æ»¹ûPodcast»úеÈËʹÓõĴúÀí·¢Ë͵ÄÓÃÀ´Ñ°ÕÒPodcast¸üеÄÒªÇóÖУ¬£¬£¬£¬£¬ £¬£¬£¬ÒªÇóÍ·'Via'ºÍ'X-Forwarded-For'й©ÁËÆäÄÚ²¿IPºÍÖ÷»úÃû¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬£¬Apple¹«Ë¾ÔÚÊÕµ½¸Ã·ì϶»ã±¨µÄ9¸öÔºó¶ÔÆä½øÐÐÁ˽¨¸´¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-search-bot-leaked-internal-ips-via-proxy-configuration/


6.Òѱ»È¡µÞµÄÊý¾Ýй¶Ë÷ÒýÍøÕ¾Ð¹Â¶23600¸ö±»ºÚµÄÊý¾Ý¿â


6.png


Òѱ»È¡µÞµÄÊý¾Ýй¶Ë÷ÒýÍøÕ¾Cit0Day.inй¶ÁË23600¸ö±»ºÚµÄÊý¾Ý¿â¡£¡£¡£¡£¡£Cit0day¿ÉÍøÂç±»ºÚ¿ÍÈëÇÖµÄÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬£¬£¬²¢¶¨ÆÚÏòÆäËûºÚ¿ÍÌṩÓû§Ãû¡¢µç×ÓÓʼþ¡¢µØÖ·ÉõÖÁÃ÷ÎÄÃÜÂëµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÍøÕ¾ÓÚ9ÔÂ14ÈչعØ¡£¡£¡£¡£¡£µ«Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬£¬Cit0dayÖеÄÈ«Êý±»ºÚÊý¾Ý¿â¶¼±»¹«¿ªµ½Á˶íÂÞ˹µÄ°µÍøÉÏ£¬£¬£¬£¬£¬ £¬£¬£¬×ܼÆÎª23618¸öÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬£¬£¬¿Éͨ¹ýMEGAÎļþÍйÜÃÅ»§ÏÂÔØ£¬£¬£¬£¬£¬ £¬£¬£¬Ô¤¼ÆÔ̺¬ÓÐԼĪ50GBµÄÊý¾ÝºÍ130ÒÚÌõÓû§¼Í¼¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/23600-hacked-databases-have-leaked-from-a-defunct-data-breach-index-site/