CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXEÎó²î
Ðû²¼Ê±¼ä 2025-12-161. CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXEÎó²î
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕÐû²¼½ôÆÈÖ¸Á£¬£¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ1ÈÕǰÐÞ¸´GeoServer¿ªÔ´µØÀí¿Õ¼äЧÀÍÆ÷ÖеÄÑÏÖØXMLÍⲿʵÌ壨XXE£©×¢ÈëÎó²î£¨CVE-2025-58360£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚGeoServer 2.26.1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬Í¨¹ýδ³ä·ÖÕûÀíµÄXMLÊäÈë¶Ëµã´¦Öóͷ£ÍⲿʵÌåÒýÓ㬣¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉʵÑé¾Ü¾øÐ§À͹¥»÷¡¢ÇÔÈ¡Ãô¸ÐÎļþ»òÖ´ÐÐЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©»á¼ûÄÚ²¿ÏµÍ³¡£¡£¡£¡£¡£¡£¡£Shadowserver×é֯׷×Ùµ½2451¸ö̻¶µÄGeoServerʵÀý£¬£¬£¬£¬£¬¶øShodanɨÃèÏÔʾȫÇòÁè¼Ý14000¸öЧÀÍÆ÷̻¶ÓÚ¹«Íø£¬£¬£¬£¬£¬±£´æ±»´ó¹æÄ£Ê¹ÓÃΣº¦¡£¡£¡£¡£¡£¡£¡£CISAÒѽ«¸ÃÎó²îÁÐÈëÒÑÖª¿ÉʹÓÃÎó²î£¨KEV£©Ä¿Â¼£¬£¬£¬£¬£¬Ç¿µ÷ÆäÕý±»Æð¾¢ÓÃÓÚÕæÊµ¹¥»÷£¬£¬£¬£¬£¬²¢±Þ²ßËùÓÐÍøÂç·ÀÓùÕßÓÅÏÈÐÞ¸´£¬£¬£¬£¬£¬×ÝÈ»·ÇÁª°î»ú¹¹Ò²Ó¦×ñÕÕ¹©Ó¦ÉÌÖ¸Òý»òÍ£ÓÃδ´ò²¹¶¡µÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/
2. Óë¹þÂí˹¹ØÁªµÄAPT×éÖ¯Ãé×¼Öж«¼°Ä¦Âå¸çÕþ¸®»ú¹¹
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬¾ÝÅÁÂå°¢¶ûÍÐÍøÂ繫˾Unit 42ÍŶÓÖÜËÄÐû²¼µÄ±¨¸æ£¬£¬£¬£¬£¬Óë°ÍÀÕ˹̹Îä×°×éÖ¯¹þÂí˹¹ØÁªµÄºÚ¿Í×éÖ¯¡°»ÒÍá±±»Ö¸¿ØÊ¹Óú¬¶ñÒâÈí¼þµÄÎĵµ£¬£¬£¬£¬£¬ÈëÇÖ°¢Âü¡¢Ä¦Âå¸ç¼°°ÍÀÕ˹̹ȨÁ¦»ú¹¹Ïà¹ØµÄÕþ¸®ÓëÍ⽻ʵÌå¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯»î¶¯Ê¼ÖÕÓë¹þÂí˹սÂÔÀûÒæ¼á³ÖÒ»Ö£¬£¬£¬£¬£¬×Ô2020ÄêÆð¹¥»÷ÊÖ¶ÎÈÕÒæÖØ´ó£¬£¬£¬£¬£¬Éú³¤³ö»ù´¡ÉèÊ©»ìÏýµÈ¸ß¼¶ÊÖÒÕ£¬£¬£¬£¬£¬²¢½ÓÄÉÃûΪAshTagµÄÐÂÐͶñÒâÈí¼þ´ÓÖж«Òªº¦ÊµÌåÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü2025Äê10Ô¼Óɳͣ»£»£»£»ðºóÆäËû¹þÂí˹¹ØÁªºÚ¿Í»î¶¯ïÔÌ£¬£¬£¬£¬£¬¡°»ÒÍá±ÈÔÒ»Á¬»îÔ¾¡£¡£¡£¡£¡£¡£¡£Æä¹¥»÷ͨ³£ÒÔαװ³ÉÉæ¼°ÍÁ¶úÆäÓë°ÍÀÕ˹̹ʵÌå¹ØÏµµÄÕýµ±ÎĵµÎªÓÕ¶ü£¬£¬£¬£¬£¬Í¨¹ýѬȾµÄPDFÎļþÖ¸µ¼Ä¿µÄÏÂÔØº¬¶ñÒâ¸ºÔØµÄRARѹËõ°ü¡£¡£¡£¡£¡£¡£¡£AshTag¶ñÒâÈí¼þÔÊÐíºÚ¿ÍÌáÈ¡Îļþ¡¢ÏÂÔØÄÚÈݲ¢Ö´ÐнøÒ»²½²Ù×÷£¬£¬£¬£¬£¬ÉõÖÁÖ±½Óͨ¹ý¼üÅ̲ٿؾÙÐÐÊý¾ÝÇÔÈ¡£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Ôø·¢Ã÷¹¥»÷Õß´ÓÊܺ¦ÕßÓÊÏäÏÂÔØÌØ¶¨Íâ½»Ïà¹ØÎļþ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/hamas-apt-targeting-government-agencies
3. SoundCloudÇå¾²Îó²îÖÂ2800ÍòÓû§Êý¾Ýй¶
12ÔÂ15ÈÕ£¬£¬£¬£¬£¬ÒôƵÁ÷ýÌåÆ½Ì¨SoundCloud¿ËÈÕ֤ʵ£¬£¬£¬£¬£¬ÒÑÍùÊýÈÕµÄЧÀÍÖÐÖ¹¼°VPNÅþÁ¬Ò쳣ϵÓÉÇå¾²Îó²îÒý·¢£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡Á˰üÀ¨Óû§ÐÅÏ¢µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£´ËǰËÄÌ죬£¬£¬£¬£¬´ó×ÚÓû§Í¨¹ýVPN»á¼ûʱÔâÓö403¡°Õ¥È¡»á¼û¡±¹ýʧ£¬£¬£¬£¬£¬Òý·¢ÆÕ±é¹Ø×¢¡£¡£¡£¡£¡£¡£¡£SoundCloudÔÚÉùÃ÷ÖÐÅû¶£¬£¬£¬£¬£¬Æä¼ì²âµ½Éæ¼°¸¨ÖúЧÀÍÒDZí°åµÄδ¾ÊÚȨ»î¶¯ºó£¬£¬£¬£¬£¬ÒÑÆô¶¯ÊÂÎñÏìÓ¦³ÌÐò¡£¡£¡£¡£¡£¡£¡£¾ÊÓ²ìÈ·ÈÏ£¬£¬£¬£¬£¬ÍþвÐÐΪÕß»á¼ûÁË¡°ÓÐÏÞÊý¾Ý¡±£¬£¬£¬£¬£¬µ«Ç¿µ÷Î´Éæ¼°²ÆÎñÊý¾Ý¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬½ö°üÀ¨µç×ÓÓʼþµØµã¼°¹ûÕæÐ¡ÎÒ˽¼Ò×ÊÁÏÖеÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶ӰÏìÔ¼20%µÄÓû§£¬£¬£¬£¬£¬°´¹ûÕæÊý¾ÝÍÆË㣬£¬£¬£¬£¬Ô¼2800Íò¸öÕË»§Êܲ¨¼°¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÌåÏÖÒÑ×èÖ¹ËùÓÐδ¾ÊÚȨµÄϵͳ»á¼û£¬£¬£¬£¬£¬²¢ÁªºÏµÚÈý·½ÍøÂçÇ徲ר¼Ò½ÓÄÉÇ¿»¯²½·¥£¬£¬£¬£¬£¬°üÀ¨Ë¢ÐÂ¼à¿ØÓëÍþв¼ì²â¡¢Éó²éÉí·Ý»á¼û¿ØÖƼ°ÏµÍ³ÆÀ¹À¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ÕâЩÇå¾²¼Ó¹Ì²½·¥µ¼ÖÂVPNÅþÁ¬ÖÐÖ¹£¬£¬£¬£¬£¬SoundCloudÉÐδÌṩ»Ö¸´Ê±¼ä±í¡£¡£¡£¡£¡£¡£¡£»£»£»£»ØÓ¦Ö®ºó£¬£¬£¬£¬£¬Æ½Ì¨ÔâÓö¾Ü¾øÐ§À͹¥»÷£¬£¬£¬£¬£¬Ôì³ÉЧÀͶÌÔÝ̱»¾¡£¡£¡£¡£¡£¡£¡£ShinyHuntersÀÕË÷ÍÅ»ï¿ÉÄÜΪ´Ë´ÎÈëÇÖµÄÄ»ºóºÚÊÖ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/
4. ÈÕ±¾AskulÔâÀÕË÷¹¥»÷ÖÂ74Íò¿Í»§Êý¾Ýй¶
12ÔÂ15ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾µç×ÓÉÌÎñ¾ÞÍ·Askul Corporation¿ËÈÕ֤ʵ£¬£¬£¬£¬£¬ÆäÓÚ10ÔÂÔâÊÜRansomHouseÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÔ¼74ÍòÌõ¿Í»§¼Í¼±»µÁ£¬£¬£¬£¬£¬Éæ¼°ÆóÒµ¿Í»§59ÍòÌõ¡¢Ð¡ÎÒ˽¼Ò¿Í»§13.2ÍòÌõ¡¢ÓªÒµÏàÖúͬ°é1.5ÍòÌõ¼°¸ß¹ÜÔ±¹¤2700ÌõÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÓÉRansomHouse×éÖ¯ÈÏÁ죬£¬£¬£¬£¬¸Ã×é֯ͨ¹ýÇÔÈ¡Íâ°üÏàÖúͬ°éÖÎÀíÔ±ÕË»§µÄƾ֤ʵÑéÈëÇÖ£¬£¬£¬£¬£¬¸ÃÕÊ»§Î´ÆôÓöàÒòËØÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÕìÌ½ÍøÂçºóÍøÂçÉí·ÝÑéÖ¤ÐÅÏ¢£¬£¬£¬£¬£¬½ûÓÃÎó²î·ÀÓùÈí¼þÈçEDR£¬£¬£¬£¬£¬ÔÚ¶à¸öЧÀÍÆ÷¼äÒÆ¶¯²¢»ñȡȨÏÞ£¬£¬£¬£¬£¬×îÖÕ¼ÓÃÜÊý¾Ý²¢É¨³ý±¸·ÝÎļþ£¬£¬£¬£¬£¬µ¼ÖÂITϵͳ¹ÊÕÏ£¬£¬£¬£¬£¬ÆÈʹAskulÔÝÍ£Ïò°üÀ¨ÎÞÓ¡Á¼Æ·ÔÚÄڵĿͻ§·¢»õ¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓöàÖÖÀÕË÷Èí¼þ±äÖÖÈÆ¹ý¸üкóµÄEDRÊðÃû£¬£¬£¬£¬£¬Í¹ÏÔÇå¾²·À»¤Îó²î¡£¡£¡£¡£¡£¡£¡£×èÖ¹12ÔÂ15ÈÕ£¬£¬£¬£¬£¬¶©µ¥·¢»õÈÔÊÜÓ°Ï죬£¬£¬£¬£¬ÏµÍ³»Ö¸´ÊÂÇéÒ»Á¬¾ÙÐС£¡£¡£¡£¡£¡£¡£AskulÒÑÏòÊÜÓ°Ïì¿Í»§ºÍÏàÖúͬ°éµ¥¶À֪ͨ£¬£¬£¬£¬£¬²¢ÏòÈÕ±¾Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»¤Î¯Ô±»á±¨¸æÊÂÎñ£¬£¬£¬£¬£¬½¨Éèºã¾Ã¼à¿Ø»úÖÆÒÔ·ÀÊý¾ÝÀÄÓᣡ£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/
5. ÃÀ¹ú700CreditÊý¾Ýй¶ÊÂÎñ²¨¼°580ÍòÈË
12ÔÂ15ÈÕ£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚÃÀ¹úµÄ½ðÈڿƼ¼¹«Ë¾700Credit¿ËÈÕÅû¶£¬£¬£¬£¬£¬ÆäÁè¼Ý580ÍòÃû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ7Ô±¬·¢µÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÔ´ÓÚÆä¼¯³ÉÏàÖúͬ°éµÄϵͳÔâ²»·¨·Ö×ÓÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃδÂÄÀúÖ¤µÄAPIÎó²î£¬£¬£¬£¬£¬ÔÚ5ÔÂÖÁ10ÔÂʱ´úÒ»Á¬ÇÔȡԼ20%µÄÏûºÄÕßÊý¾Ý£¬£¬£¬£¬£¬Ö±ÖÁ700CreditÓÚ10ÔÂ25ÈÕͨ¹ýµÚÈý·½×¨¼ÒÊӲ췢Ã÷¿ÉÒɻ¡£¡£¡£¡£¡£¡£¡£¾ÊÓ²ìÈ·ÈÏ£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÉæ¼°ÐÕÃû¡¢ÏÖʵµØµã¡¢³öÉúÈÕÆÚ¼°Éç»áÇå¾²ºÅÂ루SSN£©µÈ¸ß¶ÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬ÏàÖúͬ°éÔÚϵͳ±»ÈëÇÖºóδʵʱ֪ͨ700Credit£¬£¬£¬£¬£¬µ¼ÖÂÇå¾²ÏìÓ¦ÑÓ³Ù¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Åû¶£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýAPIÎó²îÈÆ¹ýÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬£¬£¬Ö±½Ó¸´ÖƾÏúÉ̿ͻ§ÍøÂçÓ¦ÓÃÖеļͼ¡£¡£¡£¡£¡£¡£¡£700CreditÒÑÖÕֹ̻¶µÄAPI½Ó¿Ú£¬£¬£¬£¬£¬²¢×Ô¶¯´ú±íÊÜÓ°Ïì¾ÏúÉÌÏòÁª°îÉÌҵίԱ»á£¨FTC£©ÌύΥ¹æÍ¨Öª£¬£¬£¬£¬£¬Í¬Ê±¼û¸æÌìÏÂÆû³µ¾ÏúÉÌлᣨNADA£©ÒÔÌáÉý¹«ÖÚÒâʶ¡£¡£¡£¡£¡£¡£¡£Îª½µµÍÊÜÓ°ÏìСÎÒ˽¼ÒΣº¦£¬£¬£¬£¬£¬700Creditͨ¹ýTransUnionÌṩ12¸öÔÂÃâ·ÑÉí·Ý±£»£»£»£»¤¼°ÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬£¬£¬£¬×¢²áÆÚΪ90Ìì¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/
6. ·¨º£ÄÚÕþ²¿Ö¤Êµµç×ÓÓʼþЧÀÍÆ÷Ôâµ½ÍøÂç¹¥»÷
12ÔÂ15ÈÕ£¬£¬£¬£¬£¬·¨º£ÄÚÕþ²¿³¤ÂåÀÊ¡¤Å¬Äù˹ÖÜÎå֤ʵ£¬£¬£¬£¬£¬¸Ã²¿·ÖÓÚ12ÔÂ11ÈÕÖÁ12ÈÕÒ¹¼äÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬µç×ÓÓʼþЧÀÍÆ÷ÔâÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßËäÄÜ»á¼û²¿·ÖÎĵµÎļþ£¬£¬£¬£¬£¬µ«¹Ù·½ÉÐδȷÈÏÊý¾ÝÊÇ·ñ±»µÁ¡£¡£¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎÇå¾²Îó²î£¬£¬£¬£¬£¬ÄÚÕþ²¿ÒÑÉý¼¶Çå¾²ÐÒ鲢ǿ»¯ÐÅϢϵͳ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Í¬Ê±·¨¹úÕþ¸®ÒÑÆô¶¯ÊÓ²ìÒÔÈ·¶¨¹¥»÷ȪԴÓë¹æÄ£¡£¡£¡£¡£¡£¡£¡£Å¬Äù˹ÔÚÉùÃ÷ÖÐÖ¸³ö£¬£¬£¬£¬£¬ÊÓ²ìÖ°Ô±Õý̽Ë÷¶àÖÖ¿ÉÄÜÐÔ£¬£¬£¬£¬£¬°üÀ¨Íâ¹úÊÆÁ¦¸ÉÔ¤¡¢»î¸ÐÈËÊ¿ÊÔͼչʾϵͳÎó²î£¬£¬£¬£¬£¬»òÍøÂç·¸·¨ÄîÍ·¡£¡£¡£¡£¡£¡£¡£ËûÇ¿µ÷£º¡°¹¥»÷ȷʵ±¬·¢£¬£¬£¬£¬£¬ÎļþÒѱ»»á¼û£¬£¬£¬£¬£¬ÎÒÃǽÓÄÉÁËͨÀý±£»£»£»£»¤²½·¥£¬£¬£¬£¬£¬µ«ÏêϸԵ¹ÊÔÓÉÈÔ´ý²éÃ÷¡£¡£¡£¡£¡£¡£¡£¡±×÷Ϊî¿Ïµ¾¯Ô±¡¢ÄÚ²¿Çå¾²¼°ÒÆÃñЧÀ͵Ľ¹µã²¿·Ö£¬£¬£¬£¬£¬ÄÚÕþ²¿ºã¾Ã³ÉΪ¹ú¼ÒÖ§³ÖºÚ¿ÍÓëÍøÂç·¸·¨·Ö×ÓµÄÖØµãÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£ÆÊÎöÖ¸³ö£¬£¬£¬£¬£¬´Ë´ÎÄÚÕþ²¿¹¥»÷¿ÉÄÜÓë´ËÀà¹ú¼ÒÖ§³ÖµÄºÚ¿Í»î¶¯±£´æ¹ØÁª£¬£¬£¬£¬£¬µ«Ðè½øÒ»³ÌÐò²éÈ·ÈÏ¡£¡£¡£¡£¡£¡£¡£·¨¹úÕþ¸®ÕýÁ¬ÏµÊÖÒÕȡ֤Óë¹ú¼ÊÇ鱨ÏàÖú£¬£¬£¬£¬£¬ÊÔͼ׷Ëݹ¥»÷·¾¶¡£¡£¡£¡£¡£¡£¡£ÄÚÕþ²¿¹ÙÍøÒÑÉèÁ¢×¨ÃÅÒ³Ãæ×ª´ïÊÂÎñÏ£Íû£¬£¬£¬£¬£¬²¢ºôÓõ¹«ÖÚ¼á³ÖСÐÄ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/france-interior-ministry-confirms-cyberattack-on-email-servers/


¾©¹«Íø°²±¸11010802024551ºÅ