CISAÇ¿ÔìÒªÇ󽨸´GeoServer¸ßΣXXE·ì϶
°ä²¼¹¦·ò 2025-12-161. CISAÇ¿ÔìÒªÇ󽨸´GeoServer¸ßΣXXE·ì϶
12ÔÂ12ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ö¸ÁҪÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ1ÈÕǰ½¨¸´GeoServer¿ªÔ´µØÀí¿Õ¼ä·þÎñÆ÷ÖеÄÑϳÁXML±í²¿ÊµÌ壨XXE£©×¢Èë·ì϶£¨CVE-2025-58360£©¡£¸Ã·ì϶´æÔÚÓÚGeoServer 2.26.1¼°¸üÔç°æ±¾£¬Í¨¹ýδ³ä·ÖËãÕʵÄXMLÊäÈë¶Ëµã´¦ÖÃ±í²¿ÊµÌåÒýÓã¬Ê¹¹¥»÷Õß¿ÉÖ´Ðлؾø·þÎñ¹¥»÷¡¢ÇÔÈ¡Ãô¸ÐÎļþ»òÖ´ÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©½Ó¼ûÄÚ²¿ÏµÍ³¡£Shadowserver×é֯׷×Ùµ½2451¸ö¶³öµÄGeoServerÊ·ý£¬¶øShodanɨÃèÏÔʾȫÇò³¬¹ý14000¸ö·þÎñÆ÷¶³öÓÚ¹«Íø£¬´æÔÚ±»´ó¹æÄ£ÀûÓ÷çÏÕ¡£CISAÒѽ«¸Ã·ì϶ÁÐÈëÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼£¬Ç¿µ÷ÆäÕý±»»ý¼«ÓÃÓÚÕæÊµ¹¥»÷£¬²¢¶½´ÙËùÓÐÍøÂç·ÀÓùÕßÓÅÏȽ¨¸´£¬¼´±ã·ÇÁª¹ú»ú¹¹Ò²Ó¦×ñѹ©¸øÉÌÖ¸Òý»òÍ£ÓÃδ´ò²¹¶¡µÄ²úÆ·¡£
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/
2. Óë¹þÂí˹¹ØÁªµÄAPT×éÖ¯¶Ô×¼Öж«¼°Ä¦Âå¸çµ±¾Ö»ú¹¹
12ÔÂ13ÈÕ£¬¾ÝÅÁÂå°¢¶ûÍÐÍøÂ繫˾Unit 42ÍŶÓÖÜËİ䲼µÄ»ã±¨£¬Óë°ÍÀÕ˹̹Îä×°×éÖ¯¹þÂí˹¹ØÁªµÄºÚ¿Í×éÖ¯¡°»ÒÍá±±»Ö¸¿ØÊ¹Óú¬¶ñÒâÈí¼þµÄÎĵµ£¬ÈëÇÖ°¢Âü¡¢Ä¦Âå¸ç¼°°ÍÀÕË¹Ì¹È¨ÊÆ»ú¹¹ÓйØÈ·µ±¾ÖÓë±í½»ÊµÌå¡£¸Ã×éÖ¯»î¶¯Ê¼ÖÕÓë¹þÂí˹սÊõÀûÒæÎ¬³ÖÒ»Ö£¬×Ô2020ÄêÆð¹¥»÷¼¿Á©ÈÕÒæ¸´ÔÓ£¬·¢Õ¹³ö»ù´¡ÉèÊ©»ìºÏµÈ¸ß¼¶¼¼Êõ£¬²¢Ñ¡È¡ÃûΪAshTagµÄÐÂÐͶñÒâÈí¼þ´ÓÖж«¹Ø¼üʵÌåÇÔÊØÐÅÏ¢¡£Ö»¹Ü2025Äê10Ô¼Óɳͣ»ðºóÆäËû¹þÂí˹¹ØÁªºÚ¿Í»î¶¯Ï÷¼õ£¬¡°»ÒÍá±ÈÔ³ÖÐø»îÔ¾¡£Æä¹¥»÷ͨ³£ÒÔ¼Ù×°³ÉÉæ¼°ÍÁ¶úÆäÓë°ÍÀÕ˹̹ʵÌå¹ØÏµµÄºÏ·¨ÎĵµÎªµö¶ü£¬Í¨¹ýϰȾµÄPDFÎļþÊèµ¼Ö¸±êÏÂÔØº¬¶ñÒâ¸ºÔØµÄRARѹËõ°ü¡£AshTag¶ñÒâÈí¼þÔÊÐíºÚ¿ÍÌáÈ¡Îļþ¡¢ÏÂÔØÄÚÈݲ¢Ö´Ç°½øÒ»²½²Ù×÷£¬ÉõÖÁÖ±½Óͨ¹ý¼üÅ̲ٿؽøÐÐÊý¾ÝÇÔÈ¡£¬×êÑÐÈËÔ±Ôø·¢ÏÖ¹¥»÷Õß´ÓÊܺ¦ÕßÓÊÏäÏÂÔØÌØ¶¨±í½»ÓйØÎļþ¡£
https://therecord.media/hamas-apt-targeting-government-agencies
3. SoundCloud°²È«·ì϶ÖÂ2800ÍòÓû§Êý¾Ýй¶
12ÔÂ15ÈÕ£¬ÒôƵÁ÷ýÌåÆ½Ì¨SoundCloud½üÈÕ֤ʵ£¬´ÓǰÊýÈյķþÎñÖжϼ°VPNÏνÓÒ쳣ϵÓɰ²È«·ì϶Òý·¢£¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬Óû§ÐÅÏ¢µÄÊý¾Ý¿â¡£´ËǰËÄÌ죬´óÁ¿Óû§Í¨¹ýVPN½Ó¼ûʱÔâ·ê403¡°²»ÈݽӼû¡±ÃýÎó£¬Òý·¢¿í·º¹Ø×¢¡£SoundCloudÔÚÉêÃ÷ÖÐÅû¶£¬Æä¼ì²âµ½Éæ¼°¸¨Öú·þÎñÒDZí°åµÄδ¾ÊÚȨ»î¶¯ºó£¬ÒÑÆô¶¯ÊÂÎñÏìÓ¦·¨Ê½¡£¾µ÷²éÈ·ÈÏ£¬ÍþвÐÐΪÕß½Ó¼ûÁË¡°ÓÐÏÞÊý¾Ý¡±£¬µ«Ç¿µ÷Î´Éæ¼°²ÆÕþÊý¾Ý¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬½öÔ̺¬µç×ÓÓʼþµØÖ·¼°¹«¿ªÓ×ÎÒ×ʲÂÖеÄÐÅÏ¢¡£Õâ´ÎÊý¾Ýй¶ӰÏìÔ¼20%µÄÓû§£¬°´¹«¿ªÊý¾ÝÍÆË㣬Լ2800Íò¸öÕË»§Êܲ¨¼°¡£¹«Ë¾°µÊ¾ÒÑ×èÖ¹ËùÓÐδ¾ÊÚȨµÄϵͳ½Ó¼û£¬²¢½áºÏµÚÈý·½ÍøÂ簲ȫר¼Ò²Éȡǿ»¯´ëÊ©£¬Ô̺¬¸Ä½ø¼à¿ØÓëÍþв¼ì²â¡¢Éó²éÉí·Ý½Ó¼û½ÚÔ켰ϵͳÆÀ¹À¡£È»¶ø£¬ÕâЩ°²È«¼Ó¹Ì´ëÊ©µ¼ÖÂVPNÏνÓÖжϣ¬SoundCloudÉÐδÌṩ¸´Ô¹¦·ò±í¡£»ØÓ¦Ö®ºó£¬Æ½Ì¨Ôâ·ê»Ø¾ø·þÎñ¹¥»÷£¬Ôì³É·þÎñ¶ÌÔÝ̱»¾¡£ShinyHuntersÀÕË÷ÍÅ»ï¿ÉÄÜΪÕâ´ÎÈëÇÖµÄÄ»ºóºÚÊÖ¡£
https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/
4. ÈÕ±¾AskulÔâÀÕË÷¹¥»÷ÖÂ74Íò¿Í»§Êý¾Ýй¶
12ÔÂ15ÈÕ£¬ÈÕ±¾µç×ÓÉÌÎñ¾ÞÍ·Askul Corporation½üÈÕ֤ʵ£¬ÆäÓÚ10ÔÂÔâ·êRansomHouseÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÔ¼74ÍòÌõ¿Í»§¼Í¼±»µÁ£¬Éæ¼°ÆóÒµ¿Í»§59ÍòÌõ¡¢Ó×ÎÒ¿Í»§13.2ÍòÌõ¡¢ÒµÎñºÏ×÷ͬ°é1.5ÍòÌõ¼°¸ß¹ÜÔ±¹¤2700ÌõÊý¾Ý¡£Õâ´ÎÊÂÎñÓÉRansomHouse×éÖ¯ÈÏÁ죬¸Ã×é֯ͨ¹ýÇÔÈ¡±í°üºÏ×÷ͬ°éÖÎÀíÔ¹ØË»§µÄÍ´´¦Ö´ÐÐÈëÇÖ£¬¸ÃÕÊ»§Î´ÆôÓöà³É·ÖÉí·ÝÑéÖ¤¡£¹¥»÷Õß¿úËÅÍøÂçºóÍøÂçÉí·ÝÑéÖ¤ÐÅÏ¢£¬½ûÓ÷ì϶·ÀÓùÈí¼þÈçEDR£¬ÔÚ¶à¸ö·þÎñÆ÷¼äÒÆ¶¯²¢»ñȡȨÏÞ£¬×îÖÕ¼ÓÃÜÊý¾Ý²¢¶Ï¸ù±¸·ÝÎļþ£¬µ¼ÖÂITϵͳ¹ÊÕÏ£¬ÆÈʹAskulÔÝÍ£ÏòÔ̺¬ÎÞÓ¡Á¼Æ·ÔÚÄڵĿͻ§·¢»õ¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÀûÓöàÖÖÀÕË÷Èí¼þ±äÖÖÈÆ¹ý¸üкóµÄEDRÊðÃû£¬Í¹ÏÔ°²È«·À»¤·ì϶¡£½ØÖÁ12ÔÂ15ÈÕ£¬¶©µ¥·¢»õÈÔÊÜÓ°Ï죬ϵͳ¸´Ô¹¤×÷³ÖÐø½øÐС£AskulÒÑÏòÊÜÓ°Ïì¿Í»§ºÍºÏ×÷ͬ°éµ¥¶À֪ͨ£¬²¢ÏòÈÕ±¾Ó×ÎÒÐÅÏ¢±£»¤Î¯Ô±»á»ã±¨ÊÂÎñ£¬³ÉÁ¢³Ö¾Ã¼à¿Ø»úÔìÒÔ·ÀÊý¾ÝÀÄÓá£
https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/
5. ÃÀ¹ú700CreditÊý¾Ýй¶ÊÂÎñ²¨¼°580ÍòÈË
12ÔÂ15ÈÕ£¬×ܲ¿Î»ÓÚÃÀ¹úµÄ½ðÈڿƼ¼¹«Ë¾700Credit½üÈÕÅû¶£¬Æä³¬¹ý580ÍòÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢ÔÚ7Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£Õâ´ÎÊÂÎñÔ´ÓÚÆä¼¯³ÉºÏ×÷ͬ°éµÄϵͳÔâ·¸·¨·Ö×ÓÈëÇÖ£¬¹¥»÷ÕßÀûÓÃδ¾ÑéÖ¤µÄAPI·ì϶£¬ÔÚ5ÔÂÖÁ10ÔÂÆÚ¼ä³ÖÐøÇÔȡԼ20%µÄÏû·ÑÕßÊý¾Ý£¬Ö±ÖÁ700CreditÓÚ10ÔÂ25ÈÕͨ¹ýµÚÈý·½×¨¼Òµ÷²é·¢ÏÖ¿ÉÒɻ¡£¾µ÷²éÈ·ÈÏ£¬Ð¹Â¶Êý¾ÝÉæ¼°ÐÕÃû¡¢ÏÖʵµØÖ·¡¢µ®ÉúÈÕÆÚ¼°Éç»á°²È«ºÅÂ루SSN£©µÈ¸ß¶ÈÃô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ºÏ×÷ͬ°éÔÚϵͳ±»ÈëÇÖºóδʵʱ֪ͨ700Credit£¬µ¼Ö°²È«ÏìÓ¦ÑÓ³¤¡£¹«Ë¾Åû¶£¬¹¥»÷Õßͨ¹ýAPI·ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤»úÔ죬ֱ½Ó¸´Ôì¾ÏúÉ̿ͻ§ÍøÂçÀûÓÃÖеļͼ¡£700CreditÒÑÖÕֹ¶³öµÄAPI½Ó¿Ú£¬²¢×Ô¶¯´ú±íÊÜÓ°Ïì¾ÏúÉÌÏòÁª¹úÒµÎñίԱ»á£¨FTC£©ÌύΥ¹æÍ¨Öª£¬Í¬Ê±·î¸æÈ«¹úÆû³µ¾ÏúÉÌлᣨNADA£©ÒÔÌáÉý¹«¼ÒÒâʶ¡£Îª½µµÍÊÜÓ°ÏìÓ×ÎÒ·çÏÕ£¬700Creditͨ¹ýTransUnionÌṩ12¸öÔÂÃâ·ÑÉí·Ý±£»¤¼°ÐÅÓþ¼à¿Ø·þÎñ£¬×¢²áÆÚΪ90Ìì¡£
https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/
6. ·¨¹úÄÚÕþ²¿Ö¤Êµµç×ÓÓʼþ·þÎñÆ÷Ôâµ½ÍøÂç¹¥»÷
12ÔÂ15ÈÕ£¬·¨¹úÄÚÕþ²¿³¤ÂåÀÊ¡¤Å¬Äù˹ÖÜÎå֤ʵ£¬¸Ã²¿ÃÅÓÚ12ÔÂ11ÈÕÖÁ12ÖçÒ¹¼äÔâ·êÍøÂç¹¥»÷£¬µç×ÓÓʼþ·þÎñÆ÷ÔâÈëÇÖ¡£¹¥»÷ÕßËäÄܽӼû²¿ÃÅÎĵµÎļþ£¬µ«¹Ù·½ÉÐδȷÈÏÊý¾ÝÊÇ·ñ±»µÁ¡£ÎªÓ¦¶ÔÕâ´Î°²È«·ì϶£¬ÄÚÕþ²¿ÒÑÉý¼¶°²È«ºÍ̸²¢Ç¿»¯ÐÅϢϵͳ½Ó¼û½ÚÔ죬ͬʱ·¨¹úµ±¾ÖÒÑÆô¶¯µ÷²éÒÔÈ·¶¨¹¥»÷ÆðÔ´ÓëÁìÓò¡£Å¬Äù˹ÔÚÉêÃ÷ÖÐÖ¸³ö£¬µ÷²éÈËÔ¹ØýË÷Çó¶àÖÖ¿ÉÄÜÐÔ£¬Ô̺¬±í¹úÈ¨ÊÆ¹ýÎÊ¡¢»î¶¯ÈËÊ¿ÊÔͼչʾϵͳ·ì϶£¬»òÍøÂç·¸×ﶯ»ú¡£ËûÇ¿µ÷£º¡°¹¥»÷µÄÈ·²úÉú£¬ÎļþÒѱ»½Ó¼û£¬ÎÒÃDzÉÈ¡ÁËͨÀý±£»¤´ëÊ©£¬µ«¾ßÌåÔÒòÈÔ´ý²éÃ÷¡£¡±×÷Ϊ¼à¹Ü¾¯Ô±¡¢ÄÚ²¿°²È«¼°ÒÆÃñ·þÎñµÄÖ÷ÌⲿÃÅ£¬ÄÚÕþ²¿³Ö¾Ã³ÉΪ¹ú¶ÈÖ§³ÖºÚ¿ÍÓëÍøÂç·¸×ï·Ö×ӵijÁµãÖ¸±ê¡£·ÖÎöÖ¸³ö£¬Õâ´ÎÄÚÕþ²¿¹¥»÷¿ÉÄÜÓë´ËÀà¹ú¶ÈÖ§³ÖµÄºÚ¿Í»î¶¯´æÔÚ¹ØÁª£¬µ«Ðè½øÒ»´ëÊ©²éÈ·ÈÏ¡£·¨¹úµ±¾ÖÕý½áºÏ¼¼Êõȡ֤Óë¹ú¼Êµý±¨ºÏ×÷£¬ÊÔͼ׷Òä¹¥»÷õè¾¶¡£ÄÚÕþ²¿¹ÙÍøÒÑÉèÁ¢×¨ÃÅÒ³Ãæ´«µÝÊÂÎñ½øÕ¹£¬²¢ºôÓõ¹«¼Òά³Ö¾¯Ìè¡£
https://www.bleepingcomputer.com/news/security/france-interior-ministry-confirms-cyberattack-on-email-servers/


¾©¹«Íø°²±¸11010802024551ºÅ