CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXE·ì϶

°ä²¼¹¦·ò 2025-12-16

1. CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXE·ì϶


12ÔÂ12ÈÕ£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ö¸Á£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ1ÈÕǰÐÞ¸´GeoServer¿ªÔ´µØÀí¿Õ¼ä·þÎñÆ÷ÖеÄÑÏÖØXMLÍⲿʵÌ壨XXE£©×¢Èë·ì϶£¨CVE-2025-58360£©¡£¸Ã·ì϶´æÔÚÓÚGeoServer 2.26.1¼°¸üÔç°æ±¾£¬£¬£¬Í¨¹ýδ³ä·ÖËãÕʵÄXMLÊäÈë¶Ëµã´¦ÖÃÍⲿʵÌåÒýÓ㬣¬£¬Ê¹¹¥»÷Õß¿ÉÖ´Ðлؾø·þÎñ¹¥»÷¡¢ÇÔÈ¡Ãô¸ÐÎļþ»òÖ´ÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©½Ó¼ûÄÚ²¿ÏµÍ³¡£Shadowserver×é֯׷×Ùµ½2451¸ö¶³öµÄGeoServerʵÀý£¬£¬£¬¶øShodanɨÃèÏÔʾȫÇò³¬¹ý14000¸ö·þÎñÆ÷¶³öÓÚ¹«Íø£¬£¬£¬´æÔÚ±»´ó¹æÄ£ÀûÓ÷çÏÕ¡£CISAÒѽ«¸Ã·ì϶ÁÐÈëÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼£¬£¬£¬Ç¿µ÷ÆäÕý±»»ý¼«ÓÃÓÚÕæÊµ¹¥»÷£¬£¬£¬²¢¶½´ÙËùÓÐÍøÂç·ÀÓùÕßÓÅÏÈÐÞ¸´£¬£¬£¬¼´±ã·ÇÁª°î»ú¹¹Ò²Ó¦×ñÑ­¹©¸øÉÌÖ¸Òý»òÍ£ÓÃδ´ò²¹¶¡µÄ²úÆ·¡£


https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/


2. Óë¹þÂí˹¹ØÁªµÄAPT×éÖ¯¶Ô×¼Öж«¼°Ä¦Âå¸çµ±¾Ö»ú¹¹


12ÔÂ13ÈÕ£¬£¬£¬¾ÝÅÁÂå°¢¶ûÍÐÍøÂ繫˾Unit 42ÍŶÓÖÜËİ䲼µÄ»ã±¨£¬£¬£¬Óë°ÍÀÕ˹̹Îä×°×éÖ¯¹þÂí˹¹ØÁªµÄºÚ¿Í×éÖ¯¡°»ÒÍá±±»Ö¸¿ØÊ¹Óú¬¶ñÒâÈí¼þµÄÎĵµ£¬£¬£¬ÈëÇÖ°¢Âü¡¢Ä¦Âå¸ç¼°°ÍÀÕË¹Ì¹È¨ÊÆ»ú¹¹ÓйØÈ·µ±¾ÖÓëÍ⽻ʵÌå¡£¸Ã×éÖ¯»î¶¯Ê¼ÖÕÓë¹þÂí˹սÊõÀûÒæÎ¬³ÖÒ»Ö£¬£¬£¬×Ô2020ÄêÆð¹¥»÷¼¿Á©ÈÕÒæ¸´ÔÓ£¬£¬£¬·¢Õ¹³ö»ù´¡ÉèÊ©»ìºÏµÈ¸ß¼¶¼¼Êõ£¬£¬£¬²¢Ñ¡È¡ÃûΪAshTagµÄÐÂÐͶñÒâÈí¼þ´ÓÖж«¹Ø¼üʵÌåÇÔÊØÐÅÏ¢¡£Ö»¹Ü2025Äê10Ô¼ÓɳÍ£»£»£»ðºóÆäËû¹þÂí˹¹ØÁªºÚ¿Í»î¶¯Ï÷¼õ£¬£¬£¬¡°»ÒÍá±ÈÔ³ÖÐø»îÔ¾¡£Æä¹¥»÷ͨ³£ÒÔ¼Ù×°³ÉÉæ¼°ÍÁ¶úÆäÓë°ÍÀÕ˹̹ʵÌå¹ØÏµµÄºÏ·¨ÎĵµÎªµö¶ü£¬£¬£¬Í¨¹ýϰȾµÄPDFÎļþÊèµ¼Ö¸±êÏÂÔØº¬¶ñÒâ¸ºÔØµÄRARѹËõ°ü¡£AshTag¶ñÒâÈí¼þÔÊÐíºÚ¿ÍÌáÈ¡Îļþ¡¢ÏÂÔØÄÚÈݲ¢Ö´Ç°½øÒ»²½²Ù×÷£¬£¬£¬ÉõÖÁÖ±½Óͨ¹ý¼üÅ̲ٿؽøÐÐÊý¾ÝÇÔÈ¡£¬£¬£¬×êÑÐÈËÔ±Ôø·¢ÏÖ¹¥»÷Õß´ÓÊܺ¦ÕßÓÊÏäÏÂÔØÌØ¶¨Íâ½»ÓйØÎļþ¡£


https://therecord.media/hamas-apt-targeting-government-agencies


3. SoundCloud°²È«·ì϶ÖÂ2800ÍòÓû§Êý¾Ýй¶


12ÔÂ15ÈÕ£¬£¬£¬ÒôƵÁ÷ýÌåÆ½Ì¨SoundCloud½üÈÕ֤ʵ£¬£¬£¬´ÓǰÊýÈյķþÎñÖжϼ°VPNÏνÓÒ쳣ϵÓɰ²È«·ì϶Òý·¢£¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬Óû§ÐÅÏ¢µÄÊý¾Ý¿â¡£´ËǰËÄÌ죬£¬£¬´óÁ¿Óû§Í¨¹ýVPN½Ó¼ûʱÔâ·ê403¡°²»ÈݽӼû¡±ÃýÎ󣬣¬£¬Òý·¢¿í·º¹Ø×¢¡£SoundCloudÔÚÉêÃ÷ÖÐÅû¶£¬£¬£¬Æä¼ì²âµ½Éæ¼°¸¨Öú·þÎñÒDZí°åµÄδ¾­ÊÚȨ»î¶¯ºó£¬£¬£¬ÒÑÆô¶¯ÊÂÎñÏìÓ¦·¨Ê½¡£¾­µ÷²éÈ·ÈÏ£¬£¬£¬ÍþвÐÐΪÕß½Ó¼ûÁË¡°ÓÐÏÞÊý¾Ý¡±£¬£¬£¬µ«Ç¿µ÷Î´Éæ¼°²ÆÕþÊý¾Ý¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬£¬£¬½öÔ̺¬µç×ÓÓʼþµØÖ·¼°¹«¿ªÐ¡ÎÒ×ʲÂÖеÄÐÅÏ¢¡£Õâ´ÎÊý¾Ýй¶ӰÏìÔ¼20%µÄÓû§£¬£¬£¬°´¹«¿ªÊý¾ÝÍÆË㣬£¬£¬Ô¼2800Íò¸öÕË»§Êܲ¨¼°¡£¹«Ë¾°µÊ¾ÒÑ×èÖ¹ËùÓÐδ¾­ÊÚȨµÄϵͳ½Ó¼û£¬£¬£¬²¢½áºÏµÚÈý·½ÍøÂ簲ȫר¼Ò²Éȡǿ»¯´ëÊ©£¬£¬£¬Ô̺¬¸Ä½ø¼à¿ØÓëÍþв¼ì²â¡¢Éó²éÉí·Ý½Ó¼û½ÚÖÆ¼°ÏµÍ³ÆÀ¹À¡£È»¶ø£¬£¬£¬ÕâЩ°²È«¼Ó¹Ì´ëÊ©µ¼ÖÂVPNÏνÓÖжÏ£¬£¬£¬SoundCloudÉÐδÌṩ¸´Ô­¹¦·ò±í¡£»£»£»ØÓ¦Ö®ºó£¬£¬£¬Æ½Ì¨Ôâ·ê»Ø¾ø·þÎñ¹¥»÷£¬£¬£¬Ôì³É·þÎñ¶ÌÔÝ̱»¾¡£ShinyHuntersÀÕË÷ÍÅ»ï¿ÉÄÜΪÕâ´ÎÈëÇÖµÄÄ»ºóºÚÊÖ¡£


https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/


4. ÈÕ±¾AskulÔâÀÕË÷¹¥»÷ÖÂ74Íò¿Í»§Êý¾Ýй¶


12ÔÂ15ÈÕ£¬£¬£¬ÈÕ±¾µç×ÓÉÌÎñ¾ÞÍ·Askul Corporation½üÈÕ֤ʵ£¬£¬£¬ÆäÓÚ10ÔÂÔâ·êRansomHouseÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ¼ÖÂÔ¼74ÍòÌõ¿Í»§¼Í¼±»µÁ£¬£¬£¬Éæ¼°ÆóÒµ¿Í»§59ÍòÌõ¡¢Ð¡ÎÒ¿Í»§13.2ÍòÌõ¡¢ÒµÎñºÏ×÷ͬ°é1.5ÍòÌõ¼°¸ß¹ÜÔ±¹¤2700ÌõÊý¾Ý¡£Õâ´ÎÊÂÎñÓÉRansomHouse×éÖ¯ÈÏÁ죬£¬£¬¸Ã×é֯ͨ¹ýÇÔÈ¡Íâ°üºÏ×÷ͬ°éÖÎÀíÔ±ÕË»§µÄÍ´´¦Ö´ÐÐÈëÇÖ£¬£¬£¬¸ÃÕÊ»§Î´ÆôÓöà³É·ÖÉí·ÝÑéÖ¤¡£¹¥»÷Õß¿úËÅÍøÂçºóÍøÂçÉí·ÝÑéÖ¤ÐÅÏ¢£¬£¬£¬½ûÓ÷ì϶·ÀÓùÈí¼þÈçEDR£¬£¬£¬ÔÚ¶à¸ö·þÎñÆ÷¼äÒÆ¶¯²¢»ñȡȨÏÞ£¬£¬£¬×îÖÕ¼ÓÃÜÊý¾Ý²¢¶Ï¸ù±¸·ÝÎļþ£¬£¬£¬µ¼ÖÂITϵͳ¹ÊÕÏ£¬£¬£¬ÆÈʹAskulÔÝÍ£ÏòÔ̺¬ÎÞÓ¡Á¼Æ·ÔÚÄڵĿͻ§·¢»õ¡£µ÷²éÏÔʾ£¬£¬£¬¹¥»÷ÕßÀûÓöàÖÖÀÕË÷Èí¼þ±äÖÖÈÆ¹ý¸üкóµÄEDRÊðÃû£¬£¬£¬Í¹ÏÔ°²È«·À»¤·ì϶¡£½ØÖÁ12ÔÂ15ÈÕ£¬£¬£¬¶©µ¥·¢»õÈÔÊÜÓ°Ï죬£¬£¬ÏµÍ³¸´Ô­¹¤×÷³ÖÐø½øÐС£AskulÒÑÏòÊÜÓ°Ïì¿Í»§ºÍºÏ×÷ͬ°éµ¥¶À֪ͨ£¬£¬£¬²¢ÏòÈÕ±¾Ð¡ÎÒÐÅÏ¢±£»£»£»¤Î¯Ô±»á»ã±¨ÊÂÎñ£¬£¬£¬³ÉÁ¢³Ö¾Ã¼à¿Ø»úÖÆÒÔ·ÀÊý¾ÝÀÄÓá£


https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/


5. ÃÀ¹ú700CreditÊý¾Ýй¶ÊÂÎñ²¨¼°580ÍòÈË


12ÔÂ15ÈÕ£¬£¬£¬×ܲ¿Î»ÓÚÃÀ¹úµÄ½ðÈڿƼ¼¹«Ë¾700Credit½üÈÕÅû¶£¬£¬£¬Æä³¬¹ý580ÍòÃû¿Í»§µÄСÎÒÐÅÏ¢ÔÚ7Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£Õâ´ÎÊÂÎñÔ´ÓÚÆä¼¯³ÉºÏ×÷ͬ°éµÄϵͳÔâ·¸·¨·Ö×ÓÈëÇÖ£¬£¬£¬¹¥»÷ÕßÀûÓÃδ¾­ÑéÖ¤µÄAPI·ì϶£¬£¬£¬ÔÚ5ÔÂÖÁ10ÔÂÆÚ¼ä³ÖÐøÇÔȡԼ20%µÄÏû·ÑÕßÊý¾Ý£¬£¬£¬Ö±ÖÁ700CreditÓÚ10ÔÂ25ÈÕͨ¹ýµÚÈý·½×¨¼Òµ÷²é·¢ÏÖ¿ÉÒɻ¡£¾­µ÷²éÈ·ÈÏ£¬£¬£¬Ð¹Â¶Êý¾ÝÉæ¼°ÐÕÃû¡¢ÏÖʵµØÖ·¡¢µ®ÉúÈÕÆÚ¼°Éç»á°²È«ºÅÂ루SSN£©µÈ¸ß¶ÈÃô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬ºÏ×÷ͬ°éÔÚϵͳ±»ÈëÇÖºóδʵʱ֪ͨ700Credit£¬£¬£¬µ¼Ö°²È«ÏìÓ¦ÑÓ³¤¡£¹«Ë¾Åû¶£¬£¬£¬¹¥»÷Õßͨ¹ýAPI·ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬Ö±½Ó¸´Öƾ­ÏúÉ̿ͻ§ÍøÂçÀûÓÃÖеļͼ¡£700CreditÒÑÖÕֹ¶³öµÄAPI½Ó¿Ú£¬£¬£¬²¢×Ô¶¯´ú±íÊÜÓ°Ïì¾­ÏúÉÌÏòÁª°îÒµÎñίԱ»á£¨FTC£©ÌύΥ¹æÍ¨Öª£¬£¬£¬Í¬Ê±·î¸æÈ«¹úÆû³µ¾­ÏúÉÌЭ»á£¨NADA£©ÒÔÌáÉý¹«¼ÒÒâʶ¡£Îª½µµÍÊÜÓ°ÏìСÎÒ·çÏÕ£¬£¬£¬700Creditͨ¹ýTransUnionÌṩ12¸öÔÂÃâ·ÑÉí·Ý±£»£»£»¤¼°ÐÅÓþ¼à¿Ø·þÎñ£¬£¬£¬×¢²áÆÚΪ90Ìì¡£


https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/


6. ·¨¹úÄÚÕþ²¿Ö¤Êµµç×ÓÓʼþ·þÎñÆ÷Ôâµ½ÍøÂç¹¥»÷


12ÔÂ15ÈÕ£¬£¬£¬·¨¹úÄÚÕþ²¿³¤ÂåÀÊ¡¤Å¬Äù˹ÖÜÎå֤ʵ£¬£¬£¬¸Ã²¿ÃÅÓÚ12ÔÂ11ÈÕÖÁ12ÖçÒ¹¼äÔâ·êÍøÂç¹¥»÷£¬£¬£¬µç×ÓÓʼþ·þÎñÆ÷ÔâÈëÇÖ¡£¹¥»÷ÕßËäÄܽӼû²¿ÃÅÎĵµÎļþ£¬£¬£¬µ«¹Ù·½ÉÐδȷÈÏÊý¾ÝÊÇ·ñ±»µÁ¡£ÎªÓ¦¶ÔÕâ´Î°²È«·ì϶£¬£¬£¬ÄÚÕþ²¿ÒÑÉý¼¶°²È«ºÍ̸²¢Ç¿»¯ÐÅϢϵͳ½Ó¼û½ÚÖÆ£¬£¬£¬Í¬Ê±·¨¹úµ±¾ÖÒÑÆô¶¯µ÷²éÒÔÈ·¶¨¹¥»÷ÆðÔ´ÓëÁìÓò¡£Å¬Äù˹ÔÚÉêÃ÷ÖÐÖ¸³ö£¬£¬£¬µ÷²éÈËÔ±ÕýË÷Çó¶àÖÖ¿ÉÄÜÐÔ£¬£¬£¬Ô̺¬Íâ¹úÈ¨ÊÆ¹ýÎÊ¡¢»î¶¯ÈËÊ¿ÊÔͼչʾϵͳ·ì϶£¬£¬£¬»òÍøÂç·¸×ﶯ»ú¡£ËûÇ¿µ÷£º£º£º¡°¹¥»÷µÄÈ·²úÉú£¬£¬£¬ÎļþÒѱ»½Ó¼û£¬£¬£¬ÎÒÃDzÉÈ¡ÁËͨÀý±£»£»£»¤´ëÊ©£¬£¬£¬µ«¾ßÌåÔ­ÒòÈÔ´ý²éÃ÷¡£¡£¡±×÷Ϊ¼à¹Ü¾¯Ô±¡¢ÄÚ²¿°²È«¼°ÒÆÃñ·þÎñµÄÖ÷ÌⲿÃÅ£¬£¬£¬ÄÚÕþ²¿³Ö¾Ã³ÉΪ¹ú¶ÈÖ§³ÖºÚ¿ÍÓëÍøÂç·¸×ï·Ö×ÓµÄÖØµãÖ¸±ê¡£·ÖÎöÖ¸³ö£¬£¬£¬Õâ´ÎÄÚÕþ²¿¹¥»÷¿ÉÄÜÓë´ËÀà¹ú¶ÈÖ§³ÖµÄºÚ¿Í»î¶¯´æÔÚ¹ØÁª£¬£¬£¬µ«Ðè½øÒ»´ëÊ©²éÈ·ÈÏ¡£·¨¹úµ±¾ÖÕý½áºÏ¼¼Êõȡ֤Óë¹ú¼Êµý±¨ºÏ×÷£¬£¬£¬ÊÔͼ׷Òä¹¥»÷õè¾¶¡£ÄÚÕþ²¿¹ÙÍøÒÑÉèÁ¢×¨ÃÅÒ³Ãæ´«µÝÊÂÎñ½øÕ¹£¬£¬£¬²¢ºôÓõ¹«¼Òά³Ö¾¯Ìè¡£


https://www.bleepingcomputer.com/news/security/france-interior-ministry-confirms-cyberattack-on-email-servers/