CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXEÎó²î

Ðû²¼Ê±¼ä 2025-12-16

1. CISAÇ¿ÖÆÒªÇóÐÞ¸´GeoServer¸ßΣXXEÎó²î


12ÔÂ12ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕÐû²¼½ôÆÈÖ¸Á£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ1ÈÕǰÐÞ¸´GeoServer¿ªÔ´µØÀí¿Õ¼äЧÀÍÆ÷ÖеÄÑÏÖØXMLÍⲿʵÌ壨XXE£©×¢ÈëÎó²î£¨CVE-2025-58360£©¡£¡£¡£¸ÃÎó²î±£´æÓÚGeoServer 2.26.1¼°¸üÔç°æ±¾£¬£¬£¬Í¨¹ýδ³ä·ÖÕûÀíµÄXMLÊäÈë¶Ëµã´¦Öóͷ£ÍⲿʵÌåÒýÓ㬣¬£¬Ê¹¹¥»÷Õß¿ÉʵÑé¾Ü¾øÐ§À͹¥»÷¡¢ÇÔÈ¡Ãô¸ÐÎļþ»òÖ´ÐÐЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©»á¼ûÄÚ²¿ÏµÍ³¡£¡£¡£Shadowserver×é֯׷×Ùµ½2451¸ö̻¶µÄGeoServerʵÀý£¬£¬£¬¶øShodanɨÃèÏÔʾȫÇòÁè¼Ý14000¸öЧÀÍÆ÷̻¶ÓÚ¹«Íø£¬£¬£¬±£´æ±»´ó¹æÄ£Ê¹ÓÃΣº¦¡£¡£¡£CISAÒѽ«¸ÃÎó²îÁÐÈëÒÑÖª¿ÉʹÓÃÎó²î£¨KEV£©Ä¿Â¼£¬£¬£¬Ç¿µ÷ÆäÕý±»Æð¾¢ÓÃÓÚÕæÊµ¹¥»÷£¬£¬£¬²¢±Þ²ßËùÓÐÍøÂç·ÀÓùÕßÓÅÏÈÐÞ¸´£¬£¬£¬×ÝÈ»·ÇÁª°î»ú¹¹Ò²Ó¦×ñÕÕ¹©Ó¦ÉÌÖ¸Òý»òÍ£ÓÃδ´ò²¹¶¡µÄ²úÆ·¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/


2. Óë¹þÂí˹¹ØÁªµÄAPT×éÖ¯Ãé×¼Öж«¼°Ä¦Âå¸çÕþ¸®»ú¹¹


12ÔÂ13ÈÕ£¬£¬£¬¾ÝÅÁÂå°¢¶ûÍÐÍøÂ繫˾Unit 42ÍŶÓÖÜËÄÐû²¼µÄ±¨¸æ£¬£¬£¬Óë°ÍÀÕ˹̹Îä×°×éÖ¯¹þÂí˹¹ØÁªµÄºÚ¿Í×éÖ¯¡°»ÒÍá±±»Ö¸¿ØÊ¹Óú¬¶ñÒâÈí¼þµÄÎĵµ£¬£¬£¬ÈëÇÖ°¢Âü¡¢Ä¦Âå¸ç¼°°ÍÀÕ˹̹ȨÁ¦»ú¹¹Ïà¹ØµÄÕþ¸®ÓëÍ⽻ʵÌå¡£¡£¡£¸Ã×éÖ¯»î¶¯Ê¼ÖÕÓë¹þÂí˹սÂÔÀûÒæ¼á³ÖÒ»Ö£¬£¬£¬×Ô2020ÄêÆð¹¥»÷ÊÖ¶ÎÈÕÒæÖØ´ó£¬£¬£¬Éú³¤³ö»ù´¡ÉèÊ©»ìÏýµÈ¸ß¼¶ÊÖÒÕ£¬£¬£¬²¢½ÓÄÉÃûΪAshTagµÄÐÂÐͶñÒâÈí¼þ´ÓÖж«Òªº¦ÊµÌåÇÔÊØÐÅÏ¢¡£¡£¡£Ö»¹Ü2025Äê10Ô¼ÓɳÍ£»£»£»£»ðºóÆäËû¹þÂí˹¹ØÁªºÚ¿Í»î¶¯ïÔÌ­£¬£¬£¬¡°»ÒÍá±ÈÔÒ»Á¬»îÔ¾¡£¡£¡£Æä¹¥»÷ͨ³£ÒÔαװ³ÉÉæ¼°ÍÁ¶úÆäÓë°ÍÀÕ˹̹ʵÌå¹ØÏµµÄÕýµ±ÎĵµÎªÓÕ¶ü£¬£¬£¬Í¨¹ýѬȾµÄPDFÎļþÖ¸µ¼Ä¿µÄÏÂÔØº¬¶ñÒâ¸ºÔØµÄRARѹËõ°ü¡£¡£¡£AshTag¶ñÒâÈí¼þÔÊÐíºÚ¿ÍÌáÈ¡Îļþ¡¢ÏÂÔØÄÚÈݲ¢Ö´ÐнøÒ»²½²Ù×÷£¬£¬£¬ÉõÖÁÖ±½Óͨ¹ý¼üÅ̲ٿؾÙÐÐÊý¾ÝÇÔÈ¡£¬£¬£¬Ñо¿Ö°Ô±Ôø·¢Ã÷¹¥»÷Õß´ÓÊܺ¦ÕßÓÊÏäÏÂÔØÌØ¶¨Íâ½»Ïà¹ØÎļþ¡£¡£¡£


https://therecord.media/hamas-apt-targeting-government-agencies


3. SoundCloudÇå¾²Îó²îÖÂ2800ÍòÓû§Êý¾Ýй¶


12ÔÂ15ÈÕ£¬£¬£¬ÒôƵÁ÷ýÌåÆ½Ì¨SoundCloud¿ËÈÕ֤ʵ£¬£¬£¬ÒÑÍùÊýÈÕµÄЧÀÍÖÐÖ¹¼°VPNÅþÁ¬Ò쳣ϵÓÉÇå¾²Îó²îÒý·¢£¬£¬£¬¹¥»÷ÕßÇÔÈ¡Á˰üÀ¨Óû§ÐÅÏ¢µÄÊý¾Ý¿â¡£¡£¡£´ËǰËÄÌ죬£¬£¬´ó×ÚÓû§Í¨¹ýVPN»á¼ûʱÔâÓö403¡°Õ¥È¡»á¼û¡±¹ýʧ£¬£¬£¬Òý·¢ÆÕ±é¹Ø×¢¡£¡£¡£SoundCloudÔÚÉùÃ÷ÖÐÅû¶£¬£¬£¬Æä¼ì²âµ½Éæ¼°¸¨ÖúЧÀÍÒDZí°åµÄδ¾­ÊÚȨ»î¶¯ºó£¬£¬£¬ÒÑÆô¶¯ÊÂÎñÏìÓ¦³ÌÐò¡£¡£¡£¾­ÊÓ²ìÈ·ÈÏ£¬£¬£¬ÍþвÐÐΪÕß»á¼ûÁË¡°ÓÐÏÞÊý¾Ý¡±£¬£¬£¬µ«Ç¿µ÷Î´Éæ¼°²ÆÎñÊý¾Ý¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬£¬£¬½ö°üÀ¨µç×ÓÓʼþµØµã¼°¹ûÕæÐ¡ÎÒ˽¼Ò×ÊÁÏÖеÄÐÅÏ¢¡£¡£¡£´Ë´ÎÊý¾Ýй¶ӰÏìÔ¼20%µÄÓû§£¬£¬£¬°´¹ûÕæÊý¾ÝÍÆË㣬£¬£¬Ô¼2800Íò¸öÕË»§Êܲ¨¼°¡£¡£¡£¹«Ë¾ÌåÏÖÒÑ×èÖ¹ËùÓÐδ¾­ÊÚȨµÄϵͳ»á¼û£¬£¬£¬²¢ÁªºÏµÚÈý·½ÍøÂçÇ徲ר¼Ò½ÓÄÉÇ¿»¯²½·¥£¬£¬£¬°üÀ¨Ë¢ÐÂ¼à¿ØÓëÍþв¼ì²â¡¢Éó²éÉí·Ý»á¼û¿ØÖƼ°ÏµÍ³ÆÀ¹À¡£¡£¡£È»¶ø£¬£¬£¬ÕâЩÇå¾²¼Ó¹Ì²½·¥µ¼ÖÂVPNÅþÁ¬ÖÐÖ¹£¬£¬£¬SoundCloudÉÐδÌṩ»Ö¸´Ê±¼ä±í¡£¡£¡£»£»£»£»ØÓ¦Ö®ºó£¬£¬£¬Æ½Ì¨ÔâÓö¾Ü¾øÐ§À͹¥»÷£¬£¬£¬Ôì³ÉЧÀͶÌÔÝ̱»¾¡£¡£¡£ShinyHuntersÀÕË÷ÍÅ»ï¿ÉÄÜΪ´Ë´ÎÈëÇÖµÄÄ»ºóºÚÊÖ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/


4. ÈÕ±¾AskulÔâÀÕË÷¹¥»÷ÖÂ74Íò¿Í»§Êý¾Ýй¶


12ÔÂ15ÈÕ£¬£¬£¬ÈÕ±¾µç×ÓÉÌÎñ¾ÞÍ·Askul Corporation¿ËÈÕ֤ʵ£¬£¬£¬ÆäÓÚ10ÔÂÔâÊÜRansomHouseÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ¼ÖÂÔ¼74ÍòÌõ¿Í»§¼Í¼±»µÁ£¬£¬£¬Éæ¼°ÆóÒµ¿Í»§59ÍòÌõ¡¢Ð¡ÎÒ˽¼Ò¿Í»§13.2ÍòÌõ¡¢ÓªÒµÏàÖúͬ°é1.5ÍòÌõ¼°¸ß¹ÜÔ±¹¤2700ÌõÊý¾Ý¡£¡£¡£´Ë´ÎÊÂÎñÓÉRansomHouse×éÖ¯ÈÏÁ죬£¬£¬¸Ã×é֯ͨ¹ýÇÔÈ¡Íâ°üÏàÖúͬ°éÖÎÀíÔ±ÕË»§µÄƾ֤ʵÑéÈëÇÖ£¬£¬£¬¸ÃÕÊ»§Î´ÆôÓöàÒòËØÉí·ÝÑéÖ¤¡£¡£¡£¹¥»÷ÕßÕìÌ½ÍøÂçºóÍøÂçÉí·ÝÑéÖ¤ÐÅÏ¢£¬£¬£¬½ûÓÃÎó²î·ÀÓùÈí¼þÈçEDR£¬£¬£¬ÔÚ¶à¸öЧÀÍÆ÷¼äÒÆ¶¯²¢»ñȡȨÏÞ£¬£¬£¬×îÖÕ¼ÓÃÜÊý¾Ý²¢É¨³ý±¸·ÝÎļþ£¬£¬£¬µ¼ÖÂITϵͳ¹ÊÕÏ£¬£¬£¬ÆÈʹAskulÔÝÍ£Ïò°üÀ¨ÎÞÓ¡Á¼Æ·ÔÚÄڵĿͻ§·¢»õ¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬¹¥»÷ÕßʹÓöàÖÖÀÕË÷Èí¼þ±äÖÖÈÆ¹ý¸üкóµÄEDRÊðÃû£¬£¬£¬Í¹ÏÔÇå¾²·À»¤Îó²î¡£¡£¡£×èÖ¹12ÔÂ15ÈÕ£¬£¬£¬¶©µ¥·¢»õÈÔÊÜÓ°Ï죬£¬£¬ÏµÍ³»Ö¸´ÊÂÇéÒ»Á¬¾ÙÐС£¡£¡£AskulÒÑÏòÊÜÓ°Ïì¿Í»§ºÍÏàÖúͬ°éµ¥¶À֪ͨ£¬£¬£¬²¢ÏòÈÕ±¾Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»¤Î¯Ô±»á±¨¸æÊÂÎñ£¬£¬£¬½¨Éèºã¾Ã¼à¿Ø»úÖÆÒÔ·ÀÊý¾ÝÀÄÓᣡ£¡£


https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/


5. ÃÀ¹ú700CreditÊý¾Ýй¶ÊÂÎñ²¨¼°580ÍòÈË


12ÔÂ15ÈÕ£¬£¬£¬×ܲ¿Î»ÓÚÃÀ¹úµÄ½ðÈڿƼ¼¹«Ë¾700Credit¿ËÈÕÅû¶£¬£¬£¬ÆäÁè¼Ý580ÍòÃû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ7Ô±¬·¢µÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£¡£¡£´Ë´ÎÊÂÎñÔ´ÓÚÆä¼¯³ÉÏàÖúͬ°éµÄϵͳÔâ²»·¨·Ö×ÓÈëÇÖ£¬£¬£¬¹¥»÷ÕßʹÓÃδÂÄÀúÖ¤µÄAPIÎó²î£¬£¬£¬ÔÚ5ÔÂÖÁ10ÔÂʱ´úÒ»Á¬ÇÔȡԼ20%µÄÏûºÄÕßÊý¾Ý£¬£¬£¬Ö±ÖÁ700CreditÓÚ10ÔÂ25ÈÕͨ¹ýµÚÈý·½×¨¼ÒÊӲ췢Ã÷¿ÉÒɻ¡£¡£¡£¾­ÊÓ²ìÈ·ÈÏ£¬£¬£¬Ð¹Â¶Êý¾ÝÉæ¼°ÐÕÃû¡¢ÏÖʵµØµã¡¢³öÉúÈÕÆÚ¼°Éç»áÇå¾²ºÅÂ루SSN£©µÈ¸ß¶ÈÃô¸ÐÐÅÏ¢¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬ÏàÖúͬ°éÔÚϵͳ±»ÈëÇÖºóδʵʱ֪ͨ700Credit£¬£¬£¬µ¼ÖÂÇå¾²ÏìÓ¦ÑÓ³Ù¡£¡£¡£¹«Ë¾Åû¶£¬£¬£¬¹¥»÷Õßͨ¹ýAPIÎó²îÈÆ¹ýÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬Ö±½Ó¸´Öƾ­ÏúÉ̿ͻ§ÍøÂçÓ¦ÓÃÖеļͼ¡£¡£¡£700CreditÒÑÖÕֹ̻¶µÄAPI½Ó¿Ú£¬£¬£¬²¢×Ô¶¯´ú±íÊÜÓ°Ïì¾­ÏúÉÌÏòÁª°îÉÌҵίԱ»á£¨FTC£©ÌύΥ¹æÍ¨Öª£¬£¬£¬Í¬Ê±¼û¸æÌìÏÂÆû³µ¾­ÏúÉÌЭ»á£¨NADA£©ÒÔÌáÉý¹«ÖÚÒâʶ¡£¡£¡£Îª½µµÍÊÜÓ°ÏìСÎÒ˽¼ÒΣº¦£¬£¬£¬700Creditͨ¹ýTransUnionÌṩ12¸öÔÂÃâ·ÑÉí·Ý±£»£»£»£»¤¼°ÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬£¬×¢²áÆÚΪ90Ìì¡£¡£¡£


https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/


6. ·¨º£ÄÚÕþ²¿Ö¤Êµµç×ÓÓʼþЧÀÍÆ÷Ôâµ½ÍøÂç¹¥»÷


12ÔÂ15ÈÕ£¬£¬£¬·¨º£ÄÚÕþ²¿³¤ÂåÀÊ¡¤Å¬Äù˹ÖÜÎå֤ʵ£¬£¬£¬¸Ã²¿·ÖÓÚ12ÔÂ11ÈÕÖÁ12ÈÕÒ¹¼äÔâÓöÍøÂç¹¥»÷£¬£¬£¬µç×ÓÓʼþЧÀÍÆ÷ÔâÈëÇÖ¡£¡£¡£¹¥»÷ÕßËäÄÜ»á¼û²¿·ÖÎĵµÎļþ£¬£¬£¬µ«¹Ù·½ÉÐδȷÈÏÊý¾ÝÊÇ·ñ±»µÁ¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎÇå¾²Îó²î£¬£¬£¬ÄÚÕþ²¿ÒÑÉý¼¶Ç徲ЭÒ鲢ǿ»¯ÐÅϢϵͳ»á¼û¿ØÖÆ£¬£¬£¬Í¬Ê±·¨¹úÕþ¸®ÒÑÆô¶¯ÊÓ²ìÒÔÈ·¶¨¹¥»÷ȪԴÓë¹æÄ£¡£¡£¡£Å¬Äù˹ÔÚÉùÃ÷ÖÐÖ¸³ö£¬£¬£¬ÊÓ²ìÖ°Ô±Õý̽Ë÷¶àÖÖ¿ÉÄÜÐÔ£¬£¬£¬°üÀ¨Íâ¹úÊÆÁ¦¸ÉÔ¤¡¢»î¸ÐÈËÊ¿ÊÔͼչʾϵͳÎó²î£¬£¬£¬»òÍøÂç·¸·¨ÄîÍ·¡£¡£¡£ËûÇ¿µ÷£º¡°¹¥»÷ȷʵ±¬·¢£¬£¬£¬ÎļþÒѱ»»á¼û£¬£¬£¬ÎÒÃǽÓÄÉÁËͨÀý±£»£»£»£»¤²½·¥£¬£¬£¬µ«ÏêϸԵ¹ÊÔ­ÓÉÈÔ´ý²éÃ÷¡£¡£¡£¡±×÷Ϊî¿Ïµ¾¯Ô±¡¢ÄÚ²¿Çå¾²¼°ÒÆÃñЧÀ͵Ľ¹µã²¿·Ö£¬£¬£¬ÄÚÕþ²¿ºã¾Ã³ÉΪ¹ú¼ÒÖ§³ÖºÚ¿ÍÓëÍøÂç·¸·¨·Ö×ÓµÄÖØµãÄ¿µÄ¡£¡£¡£ÆÊÎöÖ¸³ö£¬£¬£¬´Ë´ÎÄÚÕþ²¿¹¥»÷¿ÉÄÜÓë´ËÀà¹ú¼ÒÖ§³ÖµÄºÚ¿Í»î¶¯±£´æ¹ØÁª£¬£¬£¬µ«Ðè½øÒ»³ÌÐò²éÈ·ÈÏ¡£¡£¡£·¨¹úÕþ¸®ÕýÁ¬ÏµÊÖÒÕȡ֤Óë¹ú¼ÊÇ鱨ÏàÖú£¬£¬£¬ÊÔͼ׷Ëݹ¥»÷·¾¶¡£¡£¡£ÄÚÕþ²¿¹ÙÍøÒÑÉèÁ¢×¨ÃÅÒ³Ãæ×ª´ïÊÂÎñÏ£Íû£¬£¬£¬²¢ºôÓõ¹«ÖÚ¼á³ÖСÐÄ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/france-interior-ministry-confirms-cyberattack-on-email-servers/