Struts 2ÑϳÁ·ì϶Äѽ¨¸´£¬£¬£¬£¬£¬ÒÅÁôÏµÍ³Ãæ¶Ô¸ß·çÏÕ
°ä²¼¹¦·ò 2024-12-231. Struts 2ÑϳÁ·ì϶Äѽ¨¸´£¬£¬£¬£¬£¬ÒÅÁôÏµÍ³Ãæ¶Ô¸ß·çÏÕ
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬Apache Struts 2¿ò¼ÜÖз¢ÏÖÁËÒ»¸öÑϳÁµÄзì϶£¨CVE-2024-53677£©£¬£¬£¬£¬£¬Æä½¨¸´ÄѶÈÔ¶³¬µ¥Ò»²¹¶¡¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜStruts 2ÒѹýÆÚ£¬£¬£¬£¬£¬µ«ÔÚ¶à¶àÐÐÒµµÄ¾É°æÏµÍ³ÖÐÈÔ¿í·º´æÔÚ£¬£¬£¬£¬£¬ÕâʹµÃзì϶µÄ½¨¸´±äµÃÀ±ÊÖ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚStruts 2×é¼þµÄ¿Ý½ßºÍм¼ÊõµÄ·¢Õ¹£¬£¬£¬£¬£¬½¨¸´´Ë·ì϶±ØÒª¸ü¶àµÄÊÖ¶¯²Ù×÷ºÍ¹¦·ò£¬£¬£¬£¬£¬µ¼Ö·ì϶´°¿Úµ¢¸é£¬£¬£¬£¬£¬Ôö³¤Á˹¥»÷ÕßÀûÓôËÈõµãµÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÈ¥ÄêÒ»Ñù¹¦·ò¹«¿ªµÄStruts 2·ì϶£¨CVE-2023-50164£©µÄÔÙÉú°æ±¾£¬£¬£¬£¬£¬Î»ÓÚÎļþÉÏ´«À¹½ØÆ÷×é¼þÖУ¬£¬£¬£¬£¬¿ÉÆôÓÃÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£¡£¡£×éÖ¯±ØÒªÉý¼¶µ½×îа汾µÄStruts 6.7.0»òÖÁÉÙ6.4.0£¬£¬£¬£¬£¬µ«´Ë½¨¸´²¢²»Ïòºó¼æÈÝ£¬£¬£¬£¬£¬±ØÒª³Áд´úÂëºÍµ÷ÕûÅäÖ㬣¬£¬£¬£¬¿ÉÄÜ»á·ÛËéÏÖÓÐÂß¼ºÍÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬½øÒ»²½¼Ó¾çÁ˽¨¸´µÄ¸´ÔÓÐÔ¡£¡£¡£¡£¡£¡£¡£°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢¼ÓÄôó¡¢ÐÂ¼ÓÆÂºÍÓ¢¹úµÄ¹ú¶ÈÍøÂ簲ȫÖÐÐͼ°ä²¼ÁË´¹Î£°²È«ÖҸ档¡£¡£¡£¡£¡£¡£Struts 2ÔÚÒÅÁôϵͳÖÐÊ®·Ôìձ飬£¬£¬£¬£¬ÓÈÆäÊÇÔÚÊØ¾ÉÐÐÒµÖУ¬£¬£¬£¬£¬Èç½ðÈÚ¡¢±£ÏÕ¡¢µ±¾ÖºÍ´óÐÍÔì×÷»òÎïÁ÷¡£¡£¡£¡£¡£¡£¡£ÆóÒµ±ØÒª¿¿µÃסµÄ¹¥»÷ÃæÖÎÀíºÍÐÔÃüÖÜÆÚÖÎÀíÕ½Êõ£¬£¬£¬£¬£¬ÒÔÈ·Ë·ÖÝÆÚ¸üйؼü¿ò¼Ü²¢Ñ¸ËٲüõÆúÓõÄ×é¼þ¡£¡£¡£¡£¡£¡£¡£
https://www.darkreading.com/application-security/actively-exploited-bug-struts-2
2. ×·×Ù¹«Ë¾Hapnй¶ÁËÊýǧÃûGPS×·×Ù¿Í»§µÄÐÅÏ¢
12ÔÂ18ÈÕ£¬£¬£¬£¬£¬GPS×·×Ù¹«Ë¾Hapn£¨Ç°ÉíΪSpytec£©ÒòÍøÕ¾·ì϶й¶ÁËÊýǧÃû¿Í»§ÐÕÃû¼°ÓйØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£11Ôµף¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÏòTechCrunch·¢³öÖҸ棬£¬£¬£¬£¬³Æ¿Í»§ÐÕÃûºÍËùÊôÐÅÏ¢´ÓHapnµÄһ̨·þÎñÆ÷ÖÐй¶¡£¡£¡£¡£¡£¡£¡£HapnÔÊÐíÓû§Ô¶³Ì¼à¿ØGPS×·×ÙÉ豸µÄʵʱµØÎ»£¬£¬£¬£¬£¬ÕâЩÉ豸¿ÉÏνӵ½³µÁ¾»òÆäËûÎïÆ·ÉÏ¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬HapnÄÜ×·×Ù³¬¹ý460,000̨É豸£¬£¬£¬£¬£¬¿Í»§Ô̺¬²Æ¸»500Ç¿ÆóÒµ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ʹÈκÎÈ˶¼ÄܵǼHapnÕÊ»§²¢²é¿´Â¶³öµÄÊý¾Ý£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢Ô̺¬8600¶à¸öGPS×·×ÙÆ÷µÄIMEIºÅÂë¼°ÊýǧÃû¿Í»§µÄÐÕÃûºÍÒµÎñ¹ØÏµ£¬£¬£¬£¬£¬µ«²»Ô̺¬µØÎ»Êý¾Ý¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜTechCrunchÂÅ´ÎÁªÏµHapn£¬£¬£¬£¬£¬µ«Î´»ñ»Ø¸´¡£¡£¡£¡£¡£¡£¡£HapnÊ×ϯִÐйÙJoe BesdinÔÚÎÄÕ°䷢ºó°µÊ¾£¬£¬£¬£¬£¬¹«Ë¾ÔÚÎÄÕ°䷢ǰ¶ÔÕâ´Îй¶ÊÂÎñ¾ø²»ÖªÇ飬£¬£¬£¬£¬Êý¾Ý½öÏÞÓÚÈý¸ö¿Í»§ÕË»§£¬£¬£¬£¬£¬Ð¹Â¶¼ÍÂ¼Éæ¼°2024Äê4ÔµÄÊý¾Ý£¬£¬£¬£¬£¬²¢³Æ°²È«ÎÊÌâÒѽâ¾ö¡£¡£¡£¡£¡£¡£¡£µ±ÁªÏµµ½ÐÕÃûºÍËùÊô»ú¹¹±»ÁÐÔÚй¶Êý¾ÝÖеÄÓ×ÎÒʱ£¬£¬£¬£¬£¬ÓÐÈËÈ·ÈÏÁËÐÅÏ¢µ«»Ø¾øÌÖÂÛGPS×·×ÙÆ÷ʹÓÃÇé¿ö¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÆðÍ·µ÷²éÕâ¿îGPS×·×ÙÆ÷ÊÇÓÉÓÚ·¢ÏÖ¿Í»§ÔÚÍøÉÏÍÆ¼öÓÃÆä¼à¿ØÅäż»ò°é¡£¡£¡£¡£¡£¡£¡£
https://techcrunch.com/2024/12/18/tracker-firm-hapn-spilling-names-of-thousands-of-gps-tracking-customers/
3. ÎÚ¿ËÀ¼¹ú¶ÈµÇ¼Ç´¦ÔâÊ·ÉÏ×î´óÍøÂç¹¥»÷£¬£¬£¬£¬£¬¶í±»Ö¸ÎªÄ»ºóºÚÊÖ
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼Ë¾·¨²¿ÖÎÀíµÄ¹ú¶ÈµÇ¼Ç´¦½üÆÚÔâ·êÁËǰËùδÓеĴó¹æÄ£ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼°²È«¾Ö£¨SSU£©ÒѶԴ˷¢Õ¹ÐÌʵ÷²é£¬£¬£¬£¬£¬²¢Ôð¹Ö¶íÂÞ˹ΪĻºóºÚÊÖ¡£¡£¡£¡£¡£¡£¡£¾Ý¹ú¶È°²È«¾Ö֤ʵ£¬£¬£¬£¬£¬¶íÂÞ˹Îä×°¶ÓÁÐ×ÜÕÕ·÷²¿ÖØÒªµý±¨¾Ö£¨GRU£©ÏÂÊôµÄÒ»¸öºÚ¿Í×é֝ɿÏӲμÓÕâ´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¸±×ÜÀí¼æË¾·¨²¿³¤°Â¶û¼Ó¡¤Ë¹ÌØ·²ÄáʲÄÈÒ²ÔÚÉ罻ýÌåÉϹ«¿ªÔð¹Ö¶íÂÞ˹£¬£¬£¬£¬£¬³ÆÕâ´ÎÏ®»÷Ö¼ÔÚ·ÛËé¹ú¶È¹Ø¼ü»ù´¡ÉèÊ©²¢Ôì×÷·¢¼±¡£¡£¡£¡£¡£¡£¡£¶íÂÞ˹·½ÃæÉÐδ»ØÓ¦¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼ÖÂÎÚ¿ËÀ¼Ë¾·¨²¿¹ÜϽµÄͳһµÇ¼Ç´¦ºÍ¹ú¶ÈµÇ¼Ç´¦¹¤×÷ÔÝÍ££¬£¬£¬£¬£¬Ë¹ÌØ·²ÄáÏ£ÄȰµÊ¾ÕýÓëÄÚ²¿ÍÅ¶ÓºÍÆäËû²¿ÃÅר¼Òе÷Ó¦¶ÔÍøÂç¹¥»÷²¢¸´Ôϵͳ¡£¡£¡£¡£¡£¡£¡£SSUÍøÂ簲ȫÊýÃÅÒÑȾָ¶ôÔì¹¥»÷£¬£¬£¬£¬£¬²¢Ö¸³ö¹¤×÷³ÁµãΪ»÷Í˹¥»÷¡¢¸´Ô»ù´¡ÉèÊ©ºÍ¼Í¼սÕù×ï×´¡£¡£¡£¡£¡£¡£¡£³õ²½ÆÀ¹ÀÏÔʾ£¬£¬£¬£¬£¬ÆäËû×ÊԴδÊÜÍþв¡£¡£¡£¡£¡£¡£¡£Ë¹ÌØ·²ÄáʲÄÈÇ¿µ÷£¬£¬£¬£¬£¬ÔÚ½ÚÔì´óÊÆ£¬£¬£¬£¬£¬²¢¾¡È«Á¦¾¡¿ì¸´Ô·þÎñ£¬£¬£¬£¬£¬Ê׸öÒª¸´ÔµÄµÇ¼Ç²áÔ̺¬¹«ÃñÃñÊÂÉí·ÝÐÐΪ¹ú¶ÈµÇ¼Ç²á¡¢ÆóÒµ·¨È˺ÍÓ×ÎÒ¹ú¶ÈµÇ¼Ç²áÒÔ¼°²»¶¯²úÈ¨ÊÆµÇ¼Ç²á£¬£¬£¬£¬£¬Ô¤¼Æ¸´Ô¹¦·òԼΪÁ½ÖÜ¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/ukraines-probes-gru-linked/
4. AscensionÒ½ÁÆÏµÍ³ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬560ÍòÊý¾Ýй¶
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬AscensionÊÇÃÀ¹ú×î´óµÄ¸öÈËÒ½ÁƱ£½¡ÏµÍ³Ö®Ò»£¬£¬£¬£¬£¬½üÆÚÔâ·êÁËÓëBlack BastaÀÕË÷Èí¼þÐж¯ÓйصÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö½ü560ÍòÃû»¼ÕߺÍÔ±¹¤µÄÓ×ÎÒ¼°½¡È«Êý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÔËÓª×Å140¼ÒÒ½ÔººÍ40¼ÒÀÏÄ껤Àí»ú¹¹£¬£¬£¬£¬£¬ÄêÊÕÈë¸ß´ï283ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£AscensionÒÑÏòÊÜÓ°Ïì¸ö±ðÓʼÄÁËÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬²¢Ìṩ24¸öÔµÄÃâ·ÑIDXÉí·Ý͵ÇÔ±£»£»£»£»£»£»£»¤·þÎñ¡£¡£¡£¡£¡£¡£¡£¾ÝAscensionй©£¬£¬£¬£¬£¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤ÔÚ¹«Ë¾É豸¸ßµÍÔØÁ˶ñÒâÎļþ£¬£¬£¬£¬£¬Ö»¹Ü¹«Ë¾ÒÔΪÕâ¿ÉÄÜÊÇÎÞÒâÖ®¾Ù¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËAscensionµÄMyChartµç×Ó½¡È«¼Í¼ϵͳµÈ¶à¸ö¹Ø¼üϵͳ£¬£¬£¬£¬£¬µ¼ÖÂÔ±¹¤ÐèÔÚÖ½ÉϼͼÊÖÊõºÍÓÃÒ©Çé¿ö£¬£¬£¬£¬£¬²¢ÔÝÍ£ÁËһЩ·Ç´¹Î£ÊÖÊõºÍ²é³¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜAscensionδֱ½Ó½«¹¥»÷ÓëBlack BastaÁªÏµÆðÀ´£¬£¬£¬£¬£¬µ«CNNºÍHealth-ISAC¾ùÖ¸³ö£¬£¬£¬£¬£¬Black Basta½üÆÚ¼Ó¿ìÁ˶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷£¬£¬£¬£¬£¬¶ø¸ÃÀÕË÷Èí¼þÍÅ»ïÒÑÂŴγɹ¦ÈëÇÖ³ÛÃûÆóÒµÍøÂç²¢ÀÕË÷¾Þ¶î×ʽ𡣡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ascension-health-data-of-56-million-stolen-in-ransomware-attack/
5. Lazarus×éÖ¯ÀûÓø´ÔÓϰȾÁ´²¿ÊðCookiePlusºóÃŹ¥»÷
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬Lazarus×éÖ¯ÊÇÒ»¸öÓ볯ÏÊÓйØÁªµÄÍþвÐÐΪÕߣ¬£¬£¬£¬£¬ÔÚ2024Äê1ÔÂÀûÓø´ÔÓµÄϰȾÁ´Õë¶ÔÖÁÉÙÁ½ÃûºËÓйØ×éÖ¯Ô±¹¤½øÐй¥»÷£¬£¬£¬£¬£¬²¿ÊðÁËÃûΪCookiePlusµÄÐÂÄ£¿£¿£¿£¿£¿£¿£¿é»¯ºóÃÅ£¬£¬£¬£¬£¬ÕâÊdz־ÃÍøÂç¼äµý»î¶¯¡°ÍýÏ빤×÷Ðж¯¡±µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¸Ã×é֯ͨ¹ýÏòÖ¸±ê·¢ËͶñÒâÎĵµ»òľÂí»¯µÄÔ¶³Ì½Ó¼û¹¤¾ß£¬£¬£¬£¬£¬ÓÕʹָ±êÏνӵ½Ìض¨·þÎñÆ÷½øÐм¼ÊõÆÀ¹À£¬£¬£¬£¬£¬½ø¶ø´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£×îй¥»÷Éæ¼°·Ö·¢Ä¾Âí»¯µÄVNCʵÓ÷¨Ê½£¬£¬£¬£¬£¬ÒÔISOÓ³ÏñºÍZIPÎļþµÄ´ó¾Ö·Ö·¢¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Lazarus×éÖ¯»¹Ê¹ÓÃÁËÃûΪMISTPENµÄºóÃÅ£¬£¬£¬£¬£¬ÒÔ¼°LPEClient¡¢ServiceChanger¡¢Charamel LoaderµÈ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£CookiePlus¶ñÒâÈí¼þ³äÈÎÏÂÔØÆ÷£¬£¬£¬£¬£¬´ÓC2·þÎñÆ÷¼ìË÷¼ÓÃܵÄÓÐЧ¸ºÔز¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£ÈËÃÇÒÉ»óCookiePlusÊÇMISTPENµÄ¼Ì³ÐÕß¡£¡£¡£¡£¡£¡£¡£ÕâÒ»·¢ÏÖÅú×¢£¬£¬£¬£¬£¬Lazarus×éÖ¯Ò»ÏòÔÚÖÂÁ¦¸Ä½øÆä±øÆ÷¿âºÍϰȾÁ´£¬£¬£¬£¬£¬ÒÔÌӱܰ²È«²úÆ·µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/lazarus-group-spotted-targeting-nuclear.html
6. ACEµ·»ÙÈ«Çò×î´óÌåÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïMarkkystreams
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬´´ÒâÓëÓéÀÖÁªÃË£¨ACE£©³É¹¦µ·»ÙÁËÈ«Çò×î´óµÄÌåÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïÖ®Ò»Markkystreams £¬£¬£¬£¬£¬¸ÃÍÅ»ïÈ¥Äêµã»÷Á¿³¬¹ý8.21ÒڴΣ¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¹Û¶à¡£¡£¡£¡£¡£¡£¡£ACE°µÊ¾£¬£¬£¬£¬£¬Õâ´ÎÐж¯µÃµ½ÁËÆäËùÓгÉÔ±µÄÖ§³Ö£¬£¬£¬£¬£¬Ô̺¬DAZN¡¢beIN SportsºÍCanal+µÈÌåÓý¼¶³ÉÔ±¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úµçӰлáÖ´Ðи±×ܲöԴ˰µÊ¾ÔÞÉÍ£¬£¬£¬£¬£¬³ÆÕâÊǽø¹¥ÌåÓýÈüÊÂÖ±²¥µÁ°æµÄÒ»´Î¾Þ´ó³É¹¦¡£¡£¡£¡£¡£¡£¡£·´µÁ°æ×éÖ¯Ö¸³ö£¬£¬£¬£¬£¬¸ÃÍÅ»ïµÄÔËÓªÉÌÒѽ«½ÚÔìÈ¨ÒÆ½»¸ø138¸öÓòÃû£¬£¬£¬£¬£¬±»²é·âµÄÍøÕ¾ÉÏÌùÓÐÒò¼Óº¦°æÈ¨¶ø¹Ø¹ØµÄºá·ù¡£¡£¡£¡£¡£¡£¡£ACEÊÇÒ»¸öÓÉ50¶à¼ÒýÌåºÍÓéÀÖ¹«Ë¾×é³ÉµÄÁªÃË£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´Ò»ÏòÖÂÁ¦Óڹعط¸·¨Á÷ýÌå·þÎñ£¬£¬£¬£¬£¬²¢Òѳɹ¦¹Ø¹Ø¶à¸öµÁ°æÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ACE»¹Óë¶à¸ö·¨ÂÉ»ú¹¹ºÏ×÷£¬£¬£¬£¬£¬Õë¶Ô´ó¹æÄ£·¸·¨Á÷ýÌåÍŻ﷢չÐж¯£¬£¬£¬£¬£¬½ñÄêÒÑÔ®Êֹعضà¸öµÁ°æÁ÷ýÌå·þÎñ£¬£¬£¬£¬£¬Ô̺¬Ò»¸ö×Ô2015ÄêÍÆ³öÒÔÀ´×¬È¡ÁËÊý°ÙÍòÃÀÔªµÄµÁ°æµçÊÓÁ÷ýÌåÍøÂçºÍÕ¼Óг¬¹ý2200ÍòÓû§µÄµÁ°æÁ÷ýÌå·þÎñ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/massive-live-sports-piracy-ring-with-812-million-yearly-visits-taken-offline/


¾©¹«Íø°²±¸11010802024551ºÅ