·¨¹ú´÷¸ßÀֺź½Ä¸µØÎ»ÒòStravaÀûÓÃй¶

°ä²¼¹¦·ò 2026-03-20

1. ·¨¹ú´÷¸ßÀֺź½Ä¸µØÎ»ÒòStravaÀûÓÃй¶


3ÔÂ20ÈÕ£¬ £¬£¬£¬£¬·¨¹úýÌå¡¶ÊÀ½ç±¨¡·½üÈÕÅû¶£¬ £¬£¬£¬£¬2026Äê3ÔÂ13ÈÕÉÏÎç10ʱ35·Ö£¬ £¬£¬£¬£¬·¨¹úˮʦÄêÇá¾ü¹ÙÑÇɪ£¨»¯Ãû£©ÔÚº½Ä¸´¬ÃæÉÏÅܲ½£¬ £¬£¬£¬£¬Ê¹ÓÃÖÇÄÜÍó±í¼Í¼ÁËÔ¼7¹«Àï¡¢ºÄʱ35·ÖÖӵĻÊý¾Ý¡£¡£¡£¡£¡£ÓÉÓڸþü¹ÙµÄStravaÓ×ÎÒ×ÊÁÏÉèÖÃΪ¡°¹«¿ª¡±£¬ £¬£¬£¬£¬ÈκÎÈ˶¼¿É²é¿´Æä»î¶¯¹ì¼££¬ £¬£¬£¬£¬´Ó¶øÂ¶³öÁË·¨¹úˮʦº½¿Õĸ½¢´÷¸ßÀÖºÅÔÚµØÖк£¿£¿£¿£¿£¿£¿¿½üÈûÆÖ·˹ºÍÍÁ¶úÆä×ó½üµÄʵʱµØÎ»¡£¡£¡£¡£¡£·¨¹ú×ÜͳÂí¿ËÁúÓÚ3ÔÂ3ÈÕ°ä·¢²¿Ê𷨹úË®Ê¦ÌØÇ²¶ÓÁУ¬ £¬£¬£¬£¬Ô̺¬´÷¸ßÀֺź½¿Õĸ½¢¡¢ÈýËÒ»¤ÎÀ½¢ºÍÒ»ËÒ²¹¸ø½¢¡£¡£¡£¡£¡£Æäʱ´÷¸ßÀÖºÅÔÚ²¨Â޵ĺ£²ÎÓë±±Ô¼ÑÝϰ£¬ £¬£¬£¬£¬Ô­´òËãÍ£¶ÙÖÁ5Ô£¬ £¬£¬£¬£¬µ«Ëæºó±»²¿ÊðÖÁµØÖк£ÇøÓò¡£¡£¡£¡£¡£Õâ´Î²¿ÊðÕýÖµÒÔÉ«ÁÓ×¢ÃÀ¹úºÍÒÁÀÊÖ®¼äÕ½Õù·¢×÷ºóÊýÈÕ¡£¡£¡£¡£¡£×¨¼ÒÖҸ棬 £¬£¬£¬£¬´ËÀàÊý¾Ý¿ÉÄÜÔ®ÊÖµÐÊÖ¼ø±ðºÍËø¶¨¾üÊÂÖ¸±ê£¬ £¬£¬£¬£¬Í¹ÏÔ½¡Éí×·×ÙÆ÷´øÀ´µÄ³ÖÐøÒþÖÔÎÊÌâ¡£¡£¡£¡£¡£


https://securityaffairs.com/189696/intelligence/french-aircraft-carrier-charles-de-gaulle-tracked-via-strava-activity-in-opsec-failure.html


2. NaviaÊý¾Ýй¶ӰÏì270ÍòÓû§Ãô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬ÃÀ¹ú¸£ÀûÖÎÀí½â¾ö¹æ»®ÌṩÉÌNavia Benefit Solutions½üÈÕ֪ͨ½ü270ÍòÈË£¬ £¬£¬£¬£¬ÆäÃô¸ÐÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖб»¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÃÀ¹ú1Íò¶à¼Ò¹ÍÖ÷Ìṩ½Ã½ÝÖ§³öÕË»§£¨FSA£©¡¢½¡È«´¢ÐîÕË»§£¨HSA£©¡¢½¡È«±¨ÏúÆÌÅÅ£¨HRA£©¡¢Í¨ÇÚ¸£ÀûºÍCOBRA·þÎñµÈ¸£ÀûÖÎÀí·þÎñ¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬ £¬£¬£¬£¬ºÚ¿ÍÔÚ2025Äê12ÔÂ22ÈÕÖÁ2026Äê1ÔÂ15ÈÕÆÚ¼ä¿ÉÄܽӼû¸Ã¹«Ë¾ÏµÍ³£¬ £¬£¬£¬£¬¹«Ë¾ÓÚ1ÔÂ23ÈÕ·¢ÏÖ¿ÉÒɻ¡£¡£¡£¡£¡£Navia°µÊ¾Á¢¼´×ö³öÏìÓ¦²¢Æô¶¯µ÷²éÒÔÈ·¶¨ÊÂÎñµÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£µ÷²éÈ·¶¨Î´¾­ÊÚȨµÄÐÐΪÕßÔÚÉÏÊöÆÚ¼ä½Ó¼û²¢»ñÈ¡ÁËÌØ¶¨ÐÅÏ¢¡£¡£¡£¡£¡£±»½Ó¼ûºÍ¿ÉÄܱíйµÄÊý¾ÝÀàÐÍÔ̺¬£ºÈ«Ãû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂ루SSN£©¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢½¡È«±¨ÏúÆÌÅÅ£¨HRA£©²Î¼ÓÐÅÏ¢¡¢½Ã½ÝÖ§³öÕË»§£¨FSA£©ÐÅÏ¢¡¢×ÛºÏOmnibusÔ¤ËãЭµ÷·¨°¸£¨COBRA£©×¢²áÐÅÏ¢¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷Êý¾Ýй¶δ¶³öË÷ÅâÏêÇé»ò²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹ÜÈç´Ë£¬ £¬£¬£¬£¬Â¶³öµÄÊý¾Ý×ãÒÔʹÍþвÐÐΪÕßÕë¶ÔÊÜÓ°ÏìÓ×ÎÒ²¿Êð´¹µöºÍÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/


3. Speagle¶ñÒâÈí¼þ½Ù³ÖCobra DocGuardÇÔÈ¡Êý¾Ý


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕ·¢ÏÖÃûΪSpeagleµÄÐÂÐͶñÒâÈí¼þ£¬ £¬£¬£¬£¬¸ÃÈí¼þ½Ù³ÖºÏ·¨·¨Ê½CobraDocGuardµÄÖ°Äܺͻù´¡ÉèÊ©½øÐÐÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£CobraDocGuardÊÇÓÉEsafeNet¿ª·¢µÄÎĵµ°²È«ºÍ¼ÓÃÜÆ½Ì¨¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯±»×·×ÙΪRunningcrab£¬ £¬£¬£¬£¬Ä¿Ç°ÉÐδ¹éÒò¡£¡£¡£¡£¡£SpeagleÖ¼ÔÚ°ÂÃØÍøÂçÊÜÏ°È¾ÍÆËã»úµÄÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬²¢½«Æä´«ÊäÖÁ±»¹¥»÷Õß¹¥ÏµÄCobraDocGuard·þÎñÆ÷£¬ £¬£¬£¬£¬½«Êý¾Ý±íй¹ý³Ì¼Ù×°³É¿Í»§¶ËÓë·þÎñÆ÷Ö®¼äµÄºÏ·¨Í¨Ñ¶¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶Ô×°ÖÃÁËCobraDocGuardÊý¾Ý±£»£»£»£»£»£»¤Èí¼þµÄϵͳ£¬ £¬£¬£¬£¬Åú×¢¹¥»÷Õß¿ÉÄÜÓÐÒâÕë¶ÔÌØ¶¨×éÖ¯½øÐеý±¨ÍøÂç»ò¹¤Òµ¼äµý»î¶¯¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪÕâ×îÓпÉÄÜÊǹú¶ÈÖ§³ÖµÄÐÐΪÕß»ò¿É¹ÍÓ¶µÄ˽Ӫ³Ð°üÉÌËùΪ¡£¡£¡£¡£¡£SpeagleΪ32λ.NET¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬£¬Æô¶¯ºóÊ×ÏȲ鳭CobraDocGuard×°ÖÃÎļþ¼Ð£¬ £¬£¬£¬£¬¶øºó·Ö½×¶ÎÍøÂç²¢´«ÊäÊÜϰȾ»úеµÄÊý¾Ý£¬ £¬£¬£¬£¬Ô̺¬ÏµÍ³ÏêÇéºÍÌØ¶¨Îļþ¼ÐÖеÄÎļþ£¬ £¬£¬£¬£¬ÈçÔ̺¬ÍøÒ³ä¯ÀÀÆ÷º¹ÇàºÍ×Ô¶¯Ìî³äÊý¾ÝµÄÎļþ¼Ó×£¡£¡£¡£¡£


https://thehackernews.com/2026/03/speagle-malware-hijacks-cobra-docguard.html


4. Magento PolyShell·ì϶ÔÊÐíδÊÚȨ´úÂëÖ´ÐÐ


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬µç×ÓÉÌÎñ°²È«¹«Ë¾Sansec½üÈÕÅû¼ûûΪ"PolyShell"µÄзì϶£¬ £¬£¬£¬£¬¸Ã·ì϶ӰÏìËùÓÐMagentoOpenSourceºÍAdobeCommerce²»±ä°æ2.4.9×°Ö㬠£¬£¬£¬£¬ÔÊÐíδÊÚȨ¹¥»÷ÕßÖ´ÐдúÂëºÍÊÕÊÜÕË»§¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδ·¢Ïָ÷ì϶ÔÚÒ°±í±»»ý¼«ÀûÓõļ£Ïó£¬ £¬£¬£¬£¬µ«SansecÖÒ¸æÀûÓò½ÖèÒÑÔÚ´«²¼£¬ £¬£¬£¬£¬Ô¤¼Æ×Ô¶¯»¯¹¥»÷¼´½«ÆðÍ·¡£¡£¡£¡£¡£¸Ã°²È«ÎÊÌâÔ´ÓÚMagentoµÄRESTAPI½ÓÊÜÎļþÉÏ´«×÷Ϊ¹ºÎï³µÏîÄ¿×Ô½ç˵ѡÏîµÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£µ±²úÆ·Ñ¡ÏîÀàÐÍΪ"Îļþ"ʱ£¬ £¬£¬£¬£¬Magento»á´¦ÖÃǶÈëµÄfile_info¶ÔÏó£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬base64±àÂëµÄÎļþÊý¾Ý¡¢MIMEÀàÐͺÍÎļþÃû¡£¡£¡£¡£¡£Îļþ±»Ð´Èë·þÎñÆ÷ÉϵÄpub/media/custom_options/quote/Ŀ¼¡£¡£¡£¡£¡£"PolyShell"Ãû³ÆÔ´ÓÚÆäʹÓöà̬Îļþ£¬ £¬£¬£¬£¬¸ÃÎļþ¿Éͬʱ×÷ΪͼÏñºÍ¾ç±¾ÔËÐÓ×£¡£¡£¡£¡£Æ¾¾ÝWeb·þÎñÆ÷ÅäÖ㬠£¬£¬£¬£¬¸Ã·ì϶¿Éͨ¹ýÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©»ò´æ´¢ÐÍ¿çÕ¾¾ç±¾£¨XSS£©ÊµÏÖÕË»§ÊÕÊÜ£¬ £¬£¬£¬£¬Ó°ÏìSansec·ÖÎöµÄ´óÎÞÊýÉ̵ꡣ¡£¡£¡£¡£×êÑÐÈËÔ±µ÷²éÁËËùÓÐÒÑÖªµÄMagentoºÍAdobeCommerceÉ̵꣬ £¬£¬£¬£¬·¢ÏֺܶàÉ̵ê¶³öÁËÉÏ´«Ä¿Â¼ÖеÄÎļþ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/


5. BitrefillÔ⳯ÏÊBluenoroffºÚ¿Í×éÖ¯¹¥»÷


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬¼ÓÃÜÇ®±ÒÀñÎ│É̵êBitrefill½üÈÕ°µÊ¾£¬ £¬£¬£¬£¬Ô³õÔâ·êµÄ¹¥»÷ºÜ¿ÉÄÜÓɳ¯ÏÊBluenoroffºÚ¿Í×é֯ʩÐÓ×£¡£¡£¡£¡£µ÷²éÆÚ¼ä£¬ £¬£¬£¬£¬¸Ãƽ̨¹Û²ìµ½Óë֮ǰ¹éÒòÓÚ³¯ÏÊÍþвÐÐΪÕߵĹ¥»÷ÀàËÆµÄÖ¸±ê£¬ £¬£¬£¬£¬Ô̺¬Õ½Êõ¡¢¶ñÒâÈí¼þ¡¢IPºÍµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£BitrefillÊÇÒ»¼ÒÖÐÐ͵ç×ÓÉÌÎñƽ̨£¬ £¬£¬£¬£¬ÔÊÐíÓû§Ê¹ÓüÓÃÜÇ®±ÒÔÚ150¸ö¹ú¶ÈµÄÉ̵ê²É°ìÀñÎ│¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÈ«Çò600¶à¼ÒÒÆ¶¯ÔËÓªÉ̺ÍÊýǧ¸öÆ·ÅÆ¡£¡£¡£¡£¡£3ÔÂ1ÈÕ£¬ £¬£¬£¬£¬Bitrefill°ä·¢ÍøÕ¾ºÍÀûÓýӼû³öÏÖ¼¼ÊõÎÊÌâ¡£¡£¡£¡£¡£´ÎÈÕ£¬ £¬£¬£¬£¬¹«Ë¾Åû¶·¢ÏÖ°²È«ÎÊÌâ²¢½«ËùÓзþÎñÏÂÏß¡£¡£¡£¡£¡£µ÷²é·¢ÏÖ£¬ £¬£¬£¬£¬¹¥»÷Ô´ÓÚ±»¹¥ÏµÄÔ±¹¤±Ê¼Ç±¾µçÄÔ¡£¡£¡£¡£¡£¹¥»÷ÕßÇÔÈ¡Á˾ɰæÍ´´¦£¬ £¬£¬£¬£¬²¢Ê¹ÓÃÕâЩʹ´¦½Ó¼ûÔ̺¬³ö²úÃÜÔ¿µÄ¿ìÕÕ£¬ £¬£¬£¬£¬Ëæºó½«½Ó¼ûȨÏÞÉý¼¶ÖÁBitrefill¸ü´óµÄ»ù´¡ÉèÊ©£¬ £¬£¬£¬£¬Ô̺¬²¿ÃÅÊý¾Ý¿âºÍһЩ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£Õâ´Î¹¥»÷±»·¢ÏÖÊÇÓÉÓÚBitrefill°ÑÎȵ½¿ÉÒɵĹ©¸øÉ̲ɹºÄ£Ê½¡¢ÀñÎ│¿â´æºÍ¹©¸øÁ´±»ÀûÓ㬠£¬£¬£¬£¬ÒÔ¼°Ò»Ð©"ÈÈ"Ç®°ü±»ÌͿա£¡£¡£¡£¡£Ô¼18,500Ìõ²É°ì¼Í¼ÔÚй¶Öб»Â¶³ö£¬ £¬£¬£¬£¬Ô̺¬¿Í»§µç×ÓÓʼþµØÖ·¡¢IPµØÖ·ºÍ¼ÓÃÜÇ®±ÒÖ§¸¶µØÖ·¡£¡£¡£¡£¡£ÆäÖÐ1,000Ìõ²É°ì¼Í¼µÄ¿Í»§ÐÕÃûÒ²±»Â¶³ö¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÐÅÏ¢ÒÔ¼ÓÃÜ´ó¾Ö´æ´¢£¬ £¬£¬£¬£¬BitrefillÖ¸³ö¹¥»÷Õß¿ÉÄÜÒÑ»ñµÃ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/


6. Perseus°²×¿¶ñÒâÈí¼þÇÔÈ¡Óû§±Ê¼ÇÃô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬Òƶ¯°²È«¹«Ë¾ThreatFabric½üÈÕ·¢ÏÖÃûΪPerseusµÄÐÂÐͰ²×¿¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬¸ÃÈí¼þרÃŲ鳭Óû§´´½¨µÄ±Ê¼ÇÒÔÇÔÈ¡ÃÜÂë¡¢¸´Ô­¶ÌÓï»ò²ÆÕþÊý¾ÝµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÍþвÇ÷ÏòÔÚ´Óǰ°Ë¸öÔ³öÏÖ£¬ £¬£¬£¬£¬Óû§×·ÇóÃâ·Ñ»òµÍ³É±¾·½Ê½ÅÔ¹ÛÌåÓýÖ±²¥¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃIPTVÀûÓõö¶ü·Ö·¢¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬ÆäÖÐÒ»¿î´«²¼¶ñÒâÈí¼þµÄÀûÓÃÃûΪRojadirectaTV£¬ £¬£¬£¬£¬ÊÇÊ¢ÐеÄÌåÓýÁ÷ýÌå·þÎñ¡£¡£¡£¡£¡£PerseusµÄ¼ÓÔØÆ÷¿ÉÈÆ¹ý°²×¿13¼°ÒÔÉϰ汾µÄ²àÔØÏÞ¶È£¬ £¬£¬£¬£¬Óë·Ö·¢KlopatraºÍMedusa¶ñÒâÈí¼þµÄ¼ÓÔØÆ÷Ò»Ñù¡£¡£¡£¡£¡£PerseusÖØÒªÕë¶ÔÍÁ¶úÆäºÍÒâ´óÀûµÄ½ðÈÚ»ú¹¹ÒÔ¼°¼ÓÃÜÇ®±Ò·þÎñ¡£¡£¡£¡£¡£Í¨¹ýÀÄÓð²×¿¸¨ÖúÖ°ÄÜ£¬ £¬£¬£¬£¬Perseus¸³Óè²Ù×÷Õ߯ëȫԶ³Ì½ÚÔìȨÏÞ£¬ £¬£¬£¬£¬¿ÉÂ½Ðø½ØÈ¡ÆÁÄ»½ØÍ¼²¢´®Á÷ÖÁ²Ù×÷¶Ë¡¢Ä£Äâµã»÷ºÍ»¬¶¯¡¢¿ªÆô»ò×èÖ¹ÀûÓá¢ÆôÓÃºÚÆÁ¸²¸Ç°µ²Ø»î¶¯¡¢Ö´Ðи²¸Ç¹¥»÷ºÍ¼üÅ̼ͼ¡£¡£¡£¡£¡£PerseusµÄ²»Ñ°³£Ö°ÄÜÊÇÕë¶Ô°²×¿±Ê¼ÇÀûÓ㬠£¬£¬£¬£¬ÕâÊdzõ´Î·¢ÏÖ°²×¿¶ñÒâÈí¼þ²é³­É豸Ó×ÎұʼÇÖеÄÃô¸ÐÏêÇé¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-perseus-android-malware-checks-user-notes-for-secrets/