CISAÇ¿ÔìÒªÇ󽨸´GeoServer¸ßΣXXE·ì϶

°ä²¼¹¦·ò 2025-12-16

1. CISAÇ¿ÔìÒªÇ󽨸´GeoServer¸ßΣXXE·ì϶


12ÔÂ12ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ö¸Áî £¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ1ÈÕǰ½¨¸´GeoServer¿ªÔ´µØÀí¿Õ¼ä·þÎñÆ÷ÖеÄÑϳÁXML±í²¿ÊµÌ壨XXE£©×¢Èë·ì϶£¨CVE-2025-58360£©¡£¸Ã·ì϶´æÔÚÓÚGeoServer 2.26.1¼°¸üÔç°æ±¾ £¬Í¨¹ýδ³ä·ÖËãÕʵÄXMLÊäÈë¶Ëµã´¦ÖÃ±í²¿ÊµÌåÒýÓà £¬Ê¹¹¥»÷Õß¿ÉÖ´Ðлؾø·þÎñ¹¥»÷¡¢ÇÔÈ¡Ãô¸ÐÎļþ»òÖ´ÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©½Ó¼ûÄÚ²¿ÏµÍ³¡£Shadowserver×é֯׷×Ùµ½2451¸ö¶³öµÄGeoServerÊ·ý £¬¶øShodanɨÃèÏÔʾȫÇò³¬¹ý14000¸ö·þÎñÆ÷¶³öÓÚ¹«Íø £¬´æÔÚ±»´ó¹æÄ£ÀûÓ÷çÏÕ¡£CISAÒѽ«¸Ã·ì϶ÁÐÈëÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ £¬Ç¿µ÷ÆäÕý±»»ý¼«ÓÃÓÚÕæÊµ¹¥»÷ £¬²¢¶½´ÙËùÓÐÍøÂç·ÀÓùÕßÓÅÏȽ¨¸´ £¬¼´±ã·ÇÁª¹ú»ú¹¹Ò²Ó¦×ñÑ­¹©¸øÉÌÖ¸Òý»òÍ£ÓÃδ´ò²¹¶¡µÄ²úÆ·¡£


https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/


2. Óë¹þÂí˹¹ØÁªµÄAPT×éÖ¯¶Ô×¼Öж«¼°Ä¦Âå¸çµ±¾Ö»ú¹¹


12ÔÂ13ÈÕ £¬¾ÝÅÁÂå°¢¶ûÍÐÍøÂ繫˾Unit 42ÍŶÓÖÜËİ䲼µÄ»ã±¨ £¬Óë°ÍÀÕ˹̹Îä×°×éÖ¯¹þÂí˹¹ØÁªµÄºÚ¿Í×éÖ¯¡°»ÒÍá±±»Ö¸¿ØÊ¹Óú¬¶ñÒâÈí¼þµÄÎĵµ £¬ÈëÇÖ°¢Âü¡¢Ä¦Âå¸ç¼°°ÍÀÕË¹Ì¹È¨ÊÆ»ú¹¹ÓйØÈ·µ±¾ÖÓë±í½»ÊµÌå¡£¸Ã×éÖ¯»î¶¯Ê¼ÖÕÓë¹þÂí˹սÊõÀûÒæÎ¬³ÖÒ»Ö £¬×Ô2020ÄêÆð¹¥»÷¼¿Á©ÈÕÒæ¸´ÔÓ £¬·¢Õ¹³ö»ù´¡ÉèÊ©»ìºÏµÈ¸ß¼¶¼¼Êõ £¬²¢Ñ¡È¡ÃûΪAshTagµÄÐÂÐͶñÒâÈí¼þ´ÓÖж«¹Ø¼üʵÌåÇÔÊØÐÅÏ¢¡£Ö»¹Ü2025Äê10Ô¼ÓɳÍ£»ðºóÆäËû¹þÂí˹¹ØÁªºÚ¿Í»î¶¯Ï÷¼õ £¬¡°»ÒÍá±ÈÔ³ÖÐø»îÔ¾¡£Æä¹¥»÷ͨ³£ÒÔ¼Ù×°³ÉÉæ¼°ÍÁ¶úÆäÓë°ÍÀÕ˹̹ʵÌå¹ØÏµµÄºÏ·¨ÎĵµÎªµö¶ü £¬Í¨¹ýϰȾµÄPDFÎļþÊèµ¼Ö¸±êÏÂÔØº¬¶ñÒâ¸ºÔØµÄRARѹËõ°ü¡£AshTag¶ñÒâÈí¼þÔÊÐíºÚ¿ÍÌáÈ¡Îļþ¡¢ÏÂÔØÄÚÈݲ¢Ö´Ç°½øÒ»²½²Ù×÷ £¬ÉõÖÁÖ±½Óͨ¹ý¼üÅ̲ٿؽøÐÐÊý¾ÝÇÔÈ¡ £¬×êÑÐÈËÔ±Ôø·¢ÏÖ¹¥»÷Õß´ÓÊܺ¦ÕßÓÊÏäÏÂÔØÌØ¶¨±í½»ÓйØÎļþ¡£


https://therecord.media/hamas-apt-targeting-government-agencies


3. SoundCloud°²È«·ì϶ÖÂ2800ÍòÓû§Êý¾Ýй¶


12ÔÂ15ÈÕ £¬ÒôƵÁ÷ýÌåÆ½Ì¨SoundCloud½üÈÕ֤ʵ £¬´ÓǰÊýÈյķþÎñÖжϼ°VPNÏνÓÒ쳣ϵÓɰ²È«·ì϶Òý·¢ £¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬Óû§ÐÅÏ¢µÄÊý¾Ý¿â¡£´ËǰËÄÌì £¬´óÁ¿Óû§Í¨¹ýVPN½Ó¼ûʱÔâ·ê403¡°²»ÈݽӼû¡±ÃýÎó £¬Òý·¢¿í·º¹Ø×¢¡£SoundCloudÔÚÉêÃ÷ÖÐÅû¶ £¬Æä¼ì²âµ½Éæ¼°¸¨Öú·þÎñÒDZí°åµÄδ¾­ÊÚȨ»î¶¯ºó £¬ÒÑÆô¶¯ÊÂÎñÏìÓ¦·¨Ê½¡£¾­µ÷²éÈ·ÈÏ £¬ÍþвÐÐΪÕß½Ó¼ûÁË¡°ÓÐÏÞÊý¾Ý¡± £¬µ«Ç¿µ÷Î´Éæ¼°²ÆÕþÊý¾Ý¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢ £¬½öÔ̺¬µç×ÓÓʼþµØÖ·¼°¹«¿ªÓ×ÎÒ×ʲÂÖеÄÐÅÏ¢¡£Õâ´ÎÊý¾Ýй¶ӰÏìÔ¼20%µÄÓû§ £¬°´¹«¿ªÊý¾ÝÍÆËã £¬Ô¼2800Íò¸öÕË»§Êܲ¨¼°¡£¹«Ë¾°µÊ¾ÒÑ×èÖ¹ËùÓÐδ¾­ÊÚȨµÄϵͳ½Ó¼û £¬²¢½áºÏµÚÈý·½ÍøÂ簲ȫר¼Ò²Éȡǿ»¯´ëÊ© £¬Ô̺¬¸Ä½ø¼à¿ØÓëÍþв¼ì²â¡¢Éó²éÉí·Ý½Ó¼û½ÚÔ켰ϵͳÆÀ¹À¡£È»¶ø £¬ÕâЩ°²È«¼Ó¹Ì´ëÊ©µ¼ÖÂVPNÏνÓÖжÏ £¬SoundCloudÉÐδÌṩ¸´Ô­¹¦·ò±í¡£»ØÓ¦Ö®ºó £¬Æ½Ì¨Ôâ·ê»Ø¾ø·þÎñ¹¥»÷ £¬Ôì³É·þÎñ¶ÌÔÝ̱»¾¡£ShinyHuntersÀÕË÷ÍÅ»ï¿ÉÄÜΪÕâ´ÎÈëÇÖµÄÄ»ºóºÚÊÖ¡£


https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/


4. ÈÕ±¾AskulÔâÀÕË÷¹¥»÷ÖÂ74Íò¿Í»§Êý¾Ýй¶


12ÔÂ15ÈÕ £¬ÈÕ±¾µç×ÓÉÌÎñ¾ÞÍ·Askul Corporation½üÈÕ֤ʵ £¬ÆäÓÚ10ÔÂÔâ·êRansomHouseÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÔ¼74ÍòÌõ¿Í»§¼Í¼±»µÁ £¬Éæ¼°ÆóÒµ¿Í»§59ÍòÌõ¡¢Ó×ÎÒ¿Í»§13.2ÍòÌõ¡¢ÒµÎñºÏ×÷ͬ°é1.5ÍòÌõ¼°¸ß¹ÜÔ±¹¤2700ÌõÊý¾Ý¡£Õâ´ÎÊÂÎñÓÉRansomHouse×éÖ¯ÈÏÁì £¬¸Ã×é֯ͨ¹ýÇÔÈ¡±í°üºÏ×÷ͬ°éÖÎÀíÔ¹ØË»§µÄÍ´´¦Ö´ÐÐÈëÇÖ £¬¸ÃÕÊ»§Î´ÆôÓöà³É·ÖÉí·ÝÑéÖ¤¡£¹¥»÷Õß¿úËÅÍøÂçºóÍøÂçÉí·ÝÑéÖ¤ÐÅÏ¢ £¬½ûÓ÷ì϶·ÀÓùÈí¼þÈçEDR £¬ÔÚ¶à¸ö·þÎñÆ÷¼äÒÆ¶¯²¢»ñȡȨÏÞ £¬×îÖÕ¼ÓÃÜÊý¾Ý²¢¶Ï¸ù±¸·ÝÎļþ £¬µ¼ÖÂITϵͳ¹ÊÕÏ £¬ÆÈʹAskulÔÝÍ£ÏòÔ̺¬ÎÞÓ¡Á¼Æ·ÔÚÄڵĿͻ§·¢»õ¡£µ÷²éÏÔʾ £¬¹¥»÷ÕßÀûÓöàÖÖÀÕË÷Èí¼þ±äÖÖÈÆ¹ý¸üкóµÄEDRÊðÃû £¬Í¹ÏÔ°²È«·À»¤·ì϶¡£½ØÖÁ12ÔÂ15ÈÕ £¬¶©µ¥·¢»õÈÔÊÜÓ°Ïì £¬ÏµÍ³¸´Ô­¹¤×÷³ÖÐø½øÐС£AskulÒÑÏòÊÜÓ°Ïì¿Í»§ºÍºÏ×÷ͬ°éµ¥¶À֪ͨ £¬²¢ÏòÈÕ±¾Ó×ÎÒÐÅÏ¢±£»¤Î¯Ô±»á»ã±¨ÊÂÎñ £¬³ÉÁ¢³Ö¾Ã¼à¿Ø»úÔìÒÔ·ÀÊý¾ÝÀÄÓá£


https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/


5. ÃÀ¹ú700CreditÊý¾Ýй¶ÊÂÎñ²¨¼°580ÍòÈË


12ÔÂ15ÈÕ £¬×ܲ¿Î»ÓÚÃÀ¹úµÄ½ðÈڿƼ¼¹«Ë¾700Credit½üÈÕÅû¶ £¬Æä³¬¹ý580ÍòÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢ÔÚ7Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£Õâ´ÎÊÂÎñÔ´ÓÚÆä¼¯³ÉºÏ×÷ͬ°éµÄϵͳÔâ·¸·¨·Ö×ÓÈëÇÖ £¬¹¥»÷ÕßÀûÓÃδ¾­ÑéÖ¤µÄAPI·ì϶ £¬ÔÚ5ÔÂÖÁ10ÔÂÆÚ¼ä³ÖÐøÇÔȡԼ20%µÄÏû·ÑÕßÊý¾Ý £¬Ö±ÖÁ700CreditÓÚ10ÔÂ25ÈÕͨ¹ýµÚÈý·½×¨¼Òµ÷²é·¢ÏÖ¿ÉÒɻ¡£¾­µ÷²éÈ·ÈÏ £¬Ð¹Â¶Êý¾ÝÉæ¼°ÐÕÃû¡¢ÏÖʵµØÖ·¡¢µ®ÉúÈÕÆÚ¼°Éç»á°²È«ºÅÂ루SSN£©µÈ¸ß¶ÈÃô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ £¬ºÏ×÷ͬ°éÔÚϵͳ±»ÈëÇÖºóδʵʱ֪ͨ700Credit £¬µ¼Ö°²È«ÏìÓ¦ÑÓ³¤¡£¹«Ë¾Åû¶ £¬¹¥»÷Õßͨ¹ýAPI·ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤»úÔì £¬Ö±½Ó¸´Ôì¾­ÏúÉ̿ͻ§ÍøÂçÀûÓÃÖеļͼ¡£700CreditÒÑÖÕֹ¶³öµÄAPI½Ó¿Ú £¬²¢×Ô¶¯´ú±íÊÜÓ°Ïì¾­ÏúÉÌÏòÁª¹úÒµÎñίԱ»á£¨FTC£©ÌύΥ¹æÍ¨Öª £¬Í¬Ê±·î¸æÈ«¹úÆû³µ¾­ÏúÉÌЭ»á£¨NADA£©ÒÔÌáÉý¹«¼ÒÒâʶ¡£Îª½µµÍÊÜÓ°ÏìÓ×ÎÒ·çÏÕ £¬700Creditͨ¹ýTransUnionÌṩ12¸öÔÂÃâ·ÑÉí·Ý±£»¤¼°ÐÅÓþ¼à¿Ø·þÎñ £¬×¢²áÆÚΪ90Ìì¡£


https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/


6. ·¨¹úÄÚÕþ²¿Ö¤Êµµç×ÓÓʼþ·þÎñÆ÷Ôâµ½ÍøÂç¹¥»÷


12ÔÂ15ÈÕ £¬·¨¹úÄÚÕþ²¿³¤ÂåÀÊ¡¤Å¬Äù˹ÖÜÎå֤ʵ £¬¸Ã²¿ÃÅÓÚ12ÔÂ11ÈÕÖÁ12ÖçÒ¹¼äÔâ·êÍøÂç¹¥»÷ £¬µç×ÓÓʼþ·þÎñÆ÷ÔâÈëÇÖ¡£¹¥»÷ÕßËäÄܽӼû²¿ÃÅÎĵµÎļþ £¬µ«¹Ù·½ÉÐδȷÈÏÊý¾ÝÊÇ·ñ±»µÁ¡£ÎªÓ¦¶ÔÕâ´Î°²È«·ì϶ £¬ÄÚÕþ²¿ÒÑÉý¼¶°²È«ºÍ̸²¢Ç¿»¯ÐÅϢϵͳ½Ó¼û½ÚÔì £¬Í¬Ê±·¨¹úµ±¾ÖÒÑÆô¶¯µ÷²éÒÔÈ·¶¨¹¥»÷ÆðÔ´ÓëÁìÓò¡£Å¬Äù˹ÔÚÉêÃ÷ÖÐÖ¸³ö £¬µ÷²éÈËÔ¹ØýË÷Çó¶àÖÖ¿ÉÄÜÐÔ £¬Ô̺¬±í¹úÈ¨ÊÆ¹ýÎÊ¡¢»î¶¯ÈËÊ¿ÊÔͼչʾϵͳ·ì϶ £¬»òÍøÂç·¸×ﶯ»ú¡£ËûÇ¿µ÷£º¡°¹¥»÷µÄÈ·²úÉú £¬ÎļþÒѱ»½Ó¼û £¬ÎÒÃDzÉÈ¡ÁËͨÀý±£»¤´ëÊ© £¬µ«¾ßÌåÔ­ÒòÈÔ´ý²éÃ÷¡£¡±×÷Ϊ¼à¹Ü¾¯Ô±¡¢ÄÚ²¿°²È«¼°ÒÆÃñ·þÎñµÄÖ÷ÌⲿÃÅ £¬ÄÚÕþ²¿³Ö¾Ã³ÉΪ¹ú¶ÈÖ§³ÖºÚ¿ÍÓëÍøÂç·¸×ï·Ö×ӵijÁµãÖ¸±ê¡£·ÖÎöÖ¸³ö £¬Õâ´ÎÄÚÕþ²¿¹¥»÷¿ÉÄÜÓë´ËÀà¹ú¶ÈÖ§³ÖµÄºÚ¿Í»î¶¯´æÔÚ¹ØÁª £¬µ«Ðè½øÒ»´ëÊ©²éÈ·ÈÏ¡£·¨¹úµ±¾ÖÕý½áºÏ¼¼Êõȡ֤Óë¹ú¼Êµý±¨ºÏ×÷ £¬ÊÔͼ׷Òä¹¥»÷õè¾¶¡£ÄÚÕþ²¿¹ÙÍøÒÑÉèÁ¢×¨ÃÅÒ³Ãæ´«µÝÊÂÎñ½øÕ¹ £¬²¢ºôÓõ¹«¼Òά³Ö¾¯Ìè¡£


https://www.bleepingcomputer.com/news/security/france-interior-ministry-confirms-cyberattack-on-email-servers/