Struts 2ÑϳÁ·ì϶Äѽ¨¸´£¬ÒÅÁôÏµÍ³Ãæ¶Ô¸ß·çÏÕ
°ä²¼¹¦·ò 2024-12-231. Struts 2ÑϳÁ·ì϶Äѽ¨¸´£¬ÒÅÁôÏµÍ³Ãæ¶Ô¸ß·çÏÕ
12ÔÂ20ÈÕ£¬Apache Struts 2¿ò¼ÜÖз¢ÏÖÁËÒ»¸öÑϳÁµÄзì϶£¨CVE-2024-53677£©£¬Æä½¨¸´ÄѶÈÔ¶³¬µ¥Ò»²¹¶¡¡£Ö»¹ÜStruts 2ÒѹýÆÚ£¬µ«ÔÚ¶à¶àÐÐÒµµÄ¾É°æÏµÍ³ÖÐÈÔ¿í·º´æÔÚ£¬ÕâʹµÃзì϶µÄ½¨¸´±äµÃÀ±ÊÖ¡£ÓÉÓÚStruts 2×é¼þµÄ¿Ý½ßºÍм¼ÊõµÄ·¢Õ¹£¬½¨¸´´Ë·ì϶±ØÒª¸ü¶àµÄÊÖ¶¯²Ù×÷ºÍ¹¦·ò£¬µ¼Ö·ì϶´°¿Úµ¢¸é£¬Ôö³¤Á˹¥»÷ÕßÀûÓôËÈõµãµÄ·çÏÕ¡£¸Ã·ì϶ÊÇÈ¥ÄêÒ»Ñù¹¦·ò¹«¿ªµÄStruts 2·ì϶£¨CVE-2023-50164£©µÄÔÙÉú°æ±¾£¬Î»ÓÚÎļþÉÏ´«À¹½ØÆ÷×é¼þÖУ¬¿ÉÆôÓÃÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£×éÖ¯±ØÒªÉý¼¶µ½×îа汾µÄStruts 6.7.0»òÖÁÉÙ6.4.0£¬µ«´Ë½¨¸´²¢²»Ïòºó¼æÈÝ£¬±ØÒª³Áд´úÂëºÍµ÷ÕûÅäÖ㬿ÉÄÜ»á·ÛËéÏÖÓÐÂß¼ºÍÒÀÀµ¹ØÏµ£¬½øÒ»²½¼Ó¾çÁ˽¨¸´µÄ¸´ÔÓÐÔ¡£°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢¼ÓÄôó¡¢ÐÂ¼ÓÆÂºÍÓ¢¹úµÄ¹ú¶ÈÍøÂ簲ȫÖÐÐͼ°ä²¼ÁË´¹Î£°²È«ÖҸ档Struts 2ÔÚÒÅÁôϵͳÖÐÊ®·Ôìձ飬ÓÈÆäÊÇÔÚÊØ¾ÉÐÐÒµÖУ¬Èç½ðÈÚ¡¢±£ÏÕ¡¢µ±¾ÖºÍ´óÐÍÔì×÷»òÎïÁ÷¡£ÆóÒµ±ØÒª¿¿µÃסµÄ¹¥»÷ÃæÖÎÀíºÍÐÔÃüÖÜÆÚÖÎÀíÕ½Êõ£¬ÒÔÈ·±£¶¨ÆÚ¸üйؼü¿ò¼Ü²¢Ñ¸¿ì²Ã¼õÆúÓõÄ×é¼þ¡£
https://www.darkreading.com/application-security/actively-exploited-bug-struts-2
2. ×·×Ù¹«Ë¾Hapnй¶ÁËÊýǧÃûGPS×·×Ù¿Í»§µÄÐÅÏ¢
12ÔÂ18ÈÕ£¬GPS×·×Ù¹«Ë¾Hapn£¨Ç°ÉíΪSpytec£©ÒòÍøÕ¾·ì϶й¶ÁËÊýǧÃû¿Í»§ÐÕÃû¼°ÓйØÐÅÏ¢¡£11Ôµף¬°²È«×êÑÐÈËÔ±ÏòTechCrunch·¢³öÖҸ棬³Æ¿Í»§ÐÕÃûºÍËùÊôÐÅÏ¢´ÓHapnµÄһ̨·þÎñÆ÷ÖÐй¶¡£HapnÔÊÐíÓû§Ô¶³Ì¼à¿ØGPS×·×ÙÉ豸µÄʵʱµØÎ»£¬ÕâЩÉ豸¿ÉÏνӵ½³µÁ¾»òÆäËûÎïÆ·ÉÏ¡£¾Ý³Æ£¬HapnÄÜ×·×Ù³¬¹ý460,000̨É豸£¬¿Í»§Ô̺¬²Æ¸»500Ç¿ÆóÒµ¡£¸Ã·ì϶ʹÈκÎÈ˶¼ÄܵǼHapnÕÊ»§²¢²é¿´Â¶³öµÄÊý¾Ý£¬Ð¹Â¶ÐÅÏ¢Ô̺¬8600¶à¸öGPS×·×ÙÆ÷µÄIMEIºÅÂë¼°ÊýǧÃû¿Í»§µÄÐÕÃûºÍÒµÎñ¹ØÏµ£¬µ«²»Ô̺¬µØÎ»Êý¾Ý¡£Ö»¹ÜTechCrunchÂÅ´ÎÁªÏµHapn£¬µ«Î´»ñ»Ø¸´¡£HapnÊ×ϯִÐйÙJoe BesdinÔÚÎÄÕ°䷢ºó°µÊ¾£¬¹«Ë¾ÔÚÎÄÕ°䷢ǰ¶ÔÕâ´Îй¶ÊÂÎñ¾ø²»ÖªÇ飬Êý¾Ý½öÏÞÓÚÈý¸ö¿Í»§ÕË»§£¬Ð¹Â¶¼ÍÂ¼Éæ¼°2024Äê4ÔµÄÊý¾Ý£¬²¢³Æ°²È«ÎÊÌâÒѽâ¾ö¡£µ±ÁªÏµµ½ÐÕÃûºÍËùÊô»ú¹¹±»ÁÐÔÚй¶Êý¾ÝÖеÄÓ×ÎÒʱ£¬ÓÐÈËÈ·ÈÏÁËÐÅÏ¢µ«»Ø¾øÌÖÂÛGPS×·×ÙÆ÷ʹÓÃÇé¿ö¡£´Ë±í£¬°²È«×êÑÐÈËÔ±ÆðÍ·µ÷²éÕâ¿îGPS×·×ÙÆ÷ÊÇÓÉÓÚ·¢ÏÖ¿Í»§ÔÚÍøÉÏÍÆ¼öÓÃÆä¼à¿ØÅäż»ò°é¡£
https://techcrunch.com/2024/12/18/tracker-firm-hapn-spilling-names-of-thousands-of-gps-tracking-customers/
3. ÎÚ¿ËÀ¼¹ú¶ÈµÇ¼Ç´¦ÔâÊ·ÉÏ×î´óÍøÂç¹¥»÷£¬¶í±»Ö¸ÎªÄ»ºóºÚÊÖ
12ÔÂ20ÈÕ£¬ÎÚ¿ËÀ¼Ë¾·¨²¿ÖÎÀíµÄ¹ú¶ÈµÇ¼Ç´¦½üÆÚÔâ·êÁËǰËùδÓеĴó¹æÄ£ÍøÂç¹¥»÷£¬ÎÚ¿ËÀ¼°²È«¾Ö£¨SSU£©ÒѶԴ˷¢Õ¹ÐÌʵ÷²é£¬²¢Ôð¹Ö¶íÂÞ˹ΪĻºóºÚÊÖ¡£¾Ý¹ú¶È°²È«¾Ö֤ʵ£¬¶íÂÞ˹Îä×°¶ÓÁÐ×ÜÕÕ·÷²¿ÖØÒªµý±¨¾Ö£¨GRU£©ÏÂÊôµÄÒ»¸öºÚ¿Í×é֝ɿÏӲμÓÕâ´Î¹¥»÷¡£ÎÚ¿ËÀ¼¸±×ÜÀí¼æË¾·¨²¿³¤°Â¶û¼Ó¡¤Ë¹ÌØ·²ÄáʲÄÈÒ²ÔÚÉ罻ýÌåÉϹ«¿ªÔð¹Ö¶íÂÞ˹£¬³ÆÕâ´ÎÏ®»÷Ö¼ÔÚ·ÛËé¹ú¶È¹Ø¼ü»ù´¡ÉèÊ©²¢Ôì×÷·¢¼±¡£¶íÂÞ˹·½ÃæÉÐδ»ØÓ¦¡£Õâ´Î¹¥»÷µ¼ÖÂÎÚ¿ËÀ¼Ë¾·¨²¿¹ÜϽµÄͳһµÇ¼Ç´¦ºÍ¹ú¶ÈµÇ¼Ç´¦¹¤×÷ÔÝÍ££¬Ë¹ÌØ·²ÄáÏ£ÄȰµÊ¾ÕýÓëÄÚ²¿ÍÅ¶ÓºÍÆäËû²¿ÃÅר¼Òе÷Ó¦¶ÔÍøÂç¹¥»÷²¢¸´Ôϵͳ¡£SSUÍøÂ簲ȫÊýÃÅÒÑȾָ¶ôÔì¹¥»÷£¬²¢Ö¸³ö¹¤×÷³ÁµãΪ»÷Í˹¥»÷¡¢¸´Ô»ù´¡ÉèÊ©ºÍ¼Í¼սÕù×ï×´¡£³õ²½ÆÀ¹ÀÏÔʾ£¬ÆäËû×ÊԴδÊÜÍþв¡£Ë¹ÌØ·²ÄáʲÄÈÇ¿µ÷£¬ÔÚ½ÚÔì´óÊÆ£¬²¢¾¡È«Á¦¾¡¿ì¸´Ô·þÎñ£¬Ê׸öÒª¸´ÔµÄµÇ¼Ç²áÔ̺¬¹«ÃñÃñÊÂÉí·ÝÐÐΪ¹ú¶ÈµÇ¼Ç²á¡¢ÆóÒµ·¨È˺ÍÓ×ÎÒ¹ú¶ÈµÇ¼Ç²áÒÔ¼°²»¶¯²úÈ¨ÊÆµÇ¼Ç²á£¬Ô¤¼Æ¸´Ô¹¦·òԼΪÁ½ÖÜ¡£
https://www.infosecurity-magazine.com/news/ukraines-probes-gru-linked/
4. AscensionÒ½ÁÆÏµÍ³ÔâÀÕË÷Èí¼þ¹¥»÷£¬560ÍòÊý¾Ýй¶
12ÔÂ20ÈÕ£¬AscensionÊÇÃÀ¹ú×î´óµÄ¸öÈËÒ½ÁƱ£½¡ÏµÍ³Ö®Ò»£¬½üÆÚÔâ·êÁËÓëBlack BastaÀÕË÷Èí¼þÐж¯ÓйصÄÍøÂç¹¥»÷£¬µ¼Ö½ü560ÍòÃû»¼ÕߺÍÔ±¹¤µÄÓ×ÎÒ¼°½¡È«Êý¾Ý±»µÁ¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÔËÓª×Å140¼ÒÒ½ÔººÍ40¼ÒÀÏÄ껤Àí»ú¹¹£¬ÄêÊÕÈë¸ß´ï283ÒÚÃÀÔª¡£AscensionÒÑÏòÊÜÓ°Ïì¸ö±ðÓʼÄÁËÊý¾Ýй¶֪ͨ£¬²¢Ìṩ24¸öÔµÄÃâ·ÑIDXÉí·Ý͵ÇÔ±£»¤·þÎñ¡£¾ÝAscensionй©£¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤ÔÚ¹«Ë¾É豸¸ßµÍÔØÁ˶ñÒâÎļþ£¬Ö»¹Ü¹«Ë¾ÒÔΪÕâ¿ÉÄÜÊÇÎÞÒâÖ®¾Ù¡£Õâ´Î¹¥»÷Ó°ÏìÁËAscensionµÄMyChartµç×Ó½¡È«¼Í¼ϵͳµÈ¶à¸ö¹Ø¼üϵͳ£¬µ¼ÖÂÔ±¹¤ÐèÔÚÖ½ÉϼͼÊÖÊõºÍÓÃÒ©Çé¿ö£¬²¢ÔÝÍ£ÁËһЩ·Ç´¹Î£ÊÖÊõºÍ²é³¡£Ö»¹ÜAscensionδֱ½Ó½«¹¥»÷ÓëBlack BastaÁªÏµÆðÀ´£¬µ«CNNºÍHealth-ISAC¾ùÖ¸³ö£¬Black Basta½üÆÚ¼Ó¿ìÁ˶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷£¬¶ø¸ÃÀÕË÷Èí¼þÍÅ»ïÒÑÂŴγɹ¦ÈëÇÖ³ÛÃûÆóÒµÍøÂç²¢ÀÕË÷¾Þ¶î×ʽð¡£
https://www.bleepingcomputer.com/news/security/ascension-health-data-of-56-million-stolen-in-ransomware-attack/
5. Lazarus×éÖ¯ÀûÓø´ÔÓϰȾÁ´²¿ÊðCookiePlusºóÃŹ¥»÷
12ÔÂ20ÈÕ£¬Lazarus×éÖ¯ÊÇÒ»¸öÓ볯ÏÊÓйØÁªµÄÍþвÐÐΪÕߣ¬ÔÚ2024Äê1ÔÂÀûÓø´ÔÓµÄϰȾÁ´Õë¶ÔÖÁÉÙÁ½ÃûºËÓйØ×éÖ¯Ô±¹¤½øÐй¥»÷£¬²¿ÊðÁËÃûΪCookiePlusµÄÐÂÄ£¿é»¯ºóÃÅ£¬ÕâÊdz־ÃÍøÂç¼äµý»î¶¯¡°ÍýÏ빤×÷Ðж¯¡±µÄÒ»²¿ÃÅ¡£¸Ã×é֯ͨ¹ýÏòÖ¸±ê·¢ËͶñÒâÎĵµ»òľÂí»¯µÄÔ¶³Ì½Ó¼û¹¤¾ß£¬ÓÕʹָ±êÏνӵ½Ìض¨·þÎñÆ÷½øÐм¼ÊõÆÀ¹À£¬½ø¶ø´«²¼¶ñÒâÈí¼þ¡£×îй¥»÷Éæ¼°·Ö·¢Ä¾Âí»¯µÄVNCʵÓ÷¨Ê½£¬ÒÔISOÓ³ÏñºÍZIPÎļþµÄ´ó¾Ö·Ö·¢¡£´Ë±í£¬Lazarus×éÖ¯»¹Ê¹ÓÃÁËÃûΪMISTPENµÄºóÃÅ£¬ÒÔ¼°LPEClient¡¢ServiceChanger¡¢Charamel LoaderµÈ¶ñÒâÈí¼þ¡£CookiePlus¶ñÒâÈí¼þ³äÈÎÏÂÔØÆ÷£¬´ÓC2·þÎñÆ÷¼ìË÷¼ÓÃܵÄÓÐЧ¸ºÔز¢Ö´ÐС£ÈËÃÇÒÉ»óCookiePlusÊÇMISTPENµÄ¼Ì³ÐÕß¡£ÕâÒ»·¢ÏÖÅú×¢£¬Lazarus×éÖ¯Ò»ÏòÔÚÖÂÁ¦¸Ä½øÆä±øÆ÷¿âºÍϰȾÁ´£¬ÒÔÌӱܰ²È«²úÆ·µÄ¼ì²â¡£
https://thehackernews.com/2024/12/lazarus-group-spotted-targeting-nuclear.html
6. ACEµ·»ÙÈ«Çò×î´óÌåÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïMarkkystreams
12ÔÂ20ÈÕ£¬´´ÒâÓëÓéÀÖͬÃË£¨ACE£©³É¹¦µ·»ÙÁËÈ«Çò×î´óµÄÌåÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïÖ®Ò»Markkystreams £¬¸ÃÍÅ»ïÈ¥Äêµã»÷Á¿³¬¹ý8.21ÒڴΣ¬ÖØÒªÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¹Û¶à¡£ACE°µÊ¾£¬Õâ´ÎÐж¯µÃµ½ÁËÆäËùÓгÉÔ±µÄÖ§³Ö£¬Ô̺¬DAZN¡¢beIN SportsºÍCanal+µÈÌåÓý¼¶³ÉÔ±¡£ÃÀ¹úµçӰлáÖ´Ðи±×ܲöԴ˰µÊ¾ÔÞÉÍ£¬³ÆÕâÊǽø¹¥ÌåÓýÈüÊÂÖ±²¥µÁ°æµÄÒ»´Î¾Þ´ó³É¹¦¡£·´µÁ°æ×éÖ¯Ö¸³ö£¬¸ÃÍÅ»ïµÄÔËÓªÉÌÒѽ«½ÚÔìÈ¨ÒÆ½»¸ø138¸öÓòÃû£¬±»²é·âµÄÍøÕ¾ÉÏÌùÓÐÒò¼Óº¦°æÈ¨¶ø¹Ø¹ØµÄºá·ù¡£ACEÊÇÒ»¸öÓÉ50¶à¼ÒýÌåºÍÓéÀÖ¹«Ë¾×é³ÉµÄͬÃË£¬×Ô2017ÄêÒÔÀ´Ò»ÏòÖÂÁ¦Óڹعط¸·¨Á÷ýÌå·þÎñ£¬²¢Òѳɹ¦¹Ø¹Ø¶à¸öµÁ°æÆ½Ì¨¡£´Ë±í£¬ACE»¹Óë¶à¸ö·¨ÂÉ»ú¹¹ºÏ×÷£¬Õë¶Ô´ó¹æÄ£·¸·¨Á÷ýÌåÍŻ﷢չÐж¯£¬½ñÄêÒÑÔ®Êֹعضà¸öµÁ°æÁ÷ýÌå·þÎñ£¬Ô̺¬Ò»¸ö×Ô2015ÄêÍÆ³öÒÔÀ´×¬È¡ÁËÊý°ÙÍòÃÀÔªµÄµÁ°æµçÊÓÁ÷ýÌåÍøÂçºÍÕ¼Óг¬¹ý2200ÍòÓû§µÄµÁ°æÁ÷ýÌå·þÎñ¡£
https://www.bleepingcomputer.com/news/security/massive-live-sports-piracy-ring-with-812-million-yearly-visits-taken-offline/


¾©¹«Íø°²±¸11010802024551ºÅ