Struts 2ÑÏÖØÎó²îÄÑÐÞ¸´ £¬ÒÅÁôϵͳÃæÁÙ¸ßΣº¦

Ðû²¼Ê±¼ä 2024-12-23

1. Struts 2ÑÏÖØÎó²îÄÑÐÞ¸´ £¬ÒÅÁôϵͳÃæÁÙ¸ßΣº¦


12ÔÂ20ÈÕ £¬Apache Struts 2¿ò¼ÜÖз¢Ã÷ÁËÒ»¸öÑÏÖصÄÐÂÎó²î£¨CVE-2024-53677£© £¬ÆäÐÞ¸´ÄѶÈÔ¶³¬¼òÆÓ²¹¶¡¡£Ö»¹ÜStruts 2Òѹýʱ £¬µ«ÔÚÖÚ¶àÐÐÒµµÄ¾É°æϵͳÖÐÈÔÆձ鱣´æ £¬ÕâʹµÃÐÂÎó²îµÄÐÞ¸´±äµÃ¼¬ÊÖ¡£ÓÉÓÚStruts 2×é¼þµÄ¿Ý½ßºÍÐÂÊÖÒÕµÄÉú³¤ £¬ÐÞ¸´´ËÎó²îÐèÒª¸ü¶àµÄÊÖ¶¯²Ù×÷ºÍʱ¼ä £¬µ¼ÖÂÎó²î´°¿ÚÑÓÉì £¬ÔöÌíÁ˹¥»÷ÕßʹÓôËÈõµãµÄΣº¦¡£¸ÃÎó²îÊÇÈ¥ÄêÏàͬʱ¼ä¹ûÕæµÄStruts 2Îó²î£¨CVE-2023-50164£©µÄÔÙÉú°æ±¾ £¬Î»ÓÚÎļþÉÏ´«×èµ²Æ÷×é¼þÖÐ £¬¿ÉÆôÓÃÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£×éÖ¯ÐèÒªÉý¼¶µ½×îа汾µÄStruts 6.7.0»òÖÁÉÙ6.4.0 £¬µ«´ËÐÞ¸´²¢²»Ïòºó¼æÈÝ £¬ÐèÒªÖØд´úÂëºÍµ÷½âÉèÖà £¬¿ÉÄÜ»áÆÆËðÏÖÓÐÂß¼­ºÍÒÀÀµ¹Øϵ £¬½øÒ»²½¼Ó¾çÁËÐÞ¸´µÄÖØ´óÐÔ¡£°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢¼ÓÄôó¡¢Ð¼ÓƺÍÓ¢¹úµÄ¹ú¼ÒÍøÂçÇå¾²ÖÐÐĶ¼Ðû²¼Á˽ôÆÈÇå¾²ÖÒÑÔ¡£Struts 2ÔÚÒÅÁôϵͳÖкÜÊÇÆÕ±é £¬ÓÈÆäÊÇÔÚÊؾÉÐÐÒµÖÐ £¬Èç½ðÈÚ¡¢°ü¹Ü¡¢Õþ¸®ºÍ´óÐÍÖÆÔì»òÎïÁ÷¡£ÆóÒµÐèÒª¿É¿¿µÄ¹¥»÷ÃæÖÎÀíºÍÉúÃüÖÜÆÚÖÎÀíÕ½ÂÔ £¬ÒÔÈ·±£°´ÆÚ¸üÐÂÒªº¦¿ò¼Ü²¢Ñ¸ËÙïÔÌ­ÆúÓõÄ×é¼þ¡£


https://www.darkreading.com/application-security/actively-exploited-bug-struts-2


2. ×·×Ù¹«Ë¾Hapnй¶ÁËÊýǧÃûGPS×·×Ù¿Í»§µÄÐÅÏ¢


12ÔÂ18ÈÕ £¬GPS×·×Ù¹«Ë¾Hapn£¨Ç°ÉíΪSpytec£©ÒòÍøÕ¾Îó²îй¶ÁËÊýǧÃû¿Í»§ÐÕÃû¼°Ïà¹ØÐÅÏ¢¡£11ÔÂβ £¬Çå¾²Ñо¿Ö°Ô±ÏòTechCrunch·¢³öÖÒÑÔ £¬³Æ¿Í»§ÐÕÃûºÍËùÊôÐÅÏ¢´ÓHapnµÄһ̨·þÎñÆ÷ÖÐй¶¡£HapnÔÊÐíÓû§Ô¶³Ì¼à¿ØGPS×·×Ù×°±¸µÄʵʱλÖà £¬ÕâЩװ±¸¿ÉÅþÁ¬µ½³µÁ¾»òÆäËûÎïÆ·ÉÏ¡£¾Ý³Æ £¬HapnÄÜ×·×ÙÁè¼Ý460,000̨װ±¸ £¬¿Í»§°üÀ¨²Æ²ú500Ç¿ÆóÒµ¡£¸ÃÎó²îʹÈκÎÈ˶¼ÄܵǼHapnÕÊ»§²¢Éó²é̻¶µÄÊý¾Ý £¬Ð¹Â¶ÐÅÏ¢°üÀ¨8600¶à¸öGPS×·×ÙÆ÷µÄIMEIºÅÂë¼°ÊýǧÃû¿Í»§µÄÐÕÃûºÍÓªÒµ¹Øϵ £¬µ«²»°üÀ¨Î»ÖÃÊý¾Ý¡£Ö»¹ÜTechCrunch¶à´ÎÁªÏµHapn £¬µ«Î´»ñ»Ø¸´¡£HapnÊ×ϯִÐйÙJoe BesdinÔÚÎÄÕ½ÒÏþºóÌåÏÖ £¬¹«Ë¾ÔÚÎÄÕ½ÒÏþÇ°¶Ô´Ë´Îй¶ÊÂÎñ¾ø²»ÖªÇé £¬Êý¾Ý½öÏÞÓÚÈý¸ö¿Í»§ÕË»§ £¬Ð¹Â¶¼Í¼Éæ¼°2024Äê4ÔµÄÊý¾Ý £¬²¢³ÆÇå¾²ÎÊÌâÒѽâ¾ö¡£µ±ÁªÏµµ½ÐÕÃûºÍËùÊô»ú¹¹±»ÁÐÔÚй¶Êý¾ÝÖеÄСÎÒ˽¼Òʱ £¬ÓÐÈËÈ·ÈÏÁËÐÅÏ¢µ«¾Ü¾ø̸ÂÛGPS×·×ÙÆ÷ʹÓÃÇéÐΡ£±ðµÄ £¬Çå¾²Ñо¿Ö°Ô±×îÏÈÊÓ²ìÕâ¿îGPS×·×ÙÆ÷ÊÇÓÉÓÚ·¢Ã÷¿Í»§ÔÚÍøÉÏÍƼöÓÃÆä¼à¿ØÅäż»òÅóÙ­¡£


https://techcrunch.com/2024/12/18/tracker-firm-hapn-spilling-names-of-thousands-of-gps-tracking-customers/


3. ÎÚ¿ËÀ¼¹ú¼Ò¹ÒºÅ´¦ÔâÊ·ÉÏ×î´óÍøÂç¹¥»÷ £¬¶í±»Ö¸ÎªÄ»ºóºÚÊÖ


12ÔÂ20ÈÕ £¬ÎÚ¿ËÀ¼Ë¾·¨²¿ÖÎÀíµÄ¹ú¼Ò¹ÒºÅ´¦½üÆÚÔâÓöÁËب¹ÅδÓеĴó¹æÄ£ÍøÂç¹¥»÷ £¬ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SSU£©ÒѶԴËÕö¿ªÐÌÊÂÊÓ²ì £¬²¢Ö¸Ôð¶íÂÞ˹ΪĻºóºÚÊÖ¡£¾Ý¹ú¼ÒÇå¾²¾Ö֤ʵ £¬¶íÂÞ˹Îä×°²½¶Ó×ÜÕÕÁϲ¿Ö÷ÒªÇ鱨¾Ö£¨GRU£©ÏÂÊôµÄÒ»¸öºÚ¿Í×éÖ¯ÉæÏÓ¼ÓÈë´Ë´Î¹¥»÷¡£ÎÚ¿ËÀ¼¸±×ÜÀí¼æ˾·¨²¿³¤°Â¶û¼Ó¡¤Ë¹ÌØ·²ÄáʲÄÈÒ²ÔÚÉ罻ýÌåÉϹûÕæÖ¸Ôð¶íÂÞ˹ £¬³Æ´Ë´ÎÏ®»÷Ö¼ÔÚÆÆËð¹ú¼ÒÒªº¦»ù´¡ÉèÊ©²¢ÖÆÔì¿Ö»Å¡£¶íÂÞ˹·½ÃæÉÐδ»ØÓ¦¡£´Ë´Î¹¥»÷µ¼ÖÂÎÚ¿ËÀ¼Ë¾·¨²¿Í³ÁìµÄͳһ¹ÒºÅ´¦ºÍ¹ú¼Ò¹ÒºÅ°ìÊÂÇéÔÝÍ£ £¬Ë¹ÌØ·²ÄáÏ£ÄÈÌåÏÖÕýÓëÄÚ²¿ÍŶӺÍÆäËû²¿·Öר¼ÒЭµ÷Ó¦¶ÔÍøÂç¹¥»÷²¢»Ö¸´ÏµÍ³¡£SSUÍøÂçÇå¾²²¿·ÖÒѽéÈë×èÖ¹¹¥»÷ £¬²¢Ö¸³öÊÂÇéÖصãΪ»÷Í˹¥»÷¡¢»Ö¸´»ù´¡ÉèÊ©ºÍ¼Í¼սÕù×ïÐС£ÆðÔ´ÆÀ¹ÀÏÔʾ £¬ÆäËû×ÊԴδÊÜÍþв¡£Ë¹ÌØ·²ÄáʲÄÈÇ¿µ÷ £¬ÕýÔÚ¿ØÖÆʱÊÆ £¬²¢¾¡È«Á¦¾¡¿ì»Ö¸´·þÎñ £¬Ê׸öÒª»Ö¸´µÄ¹ÒºÅ²á°üÀ¨¹«ÃñÃñÊÂÉí·ÝÐÐΪ¹ú¼Ò¹ÒºÅ²á¡¢ÆóÒµ·¨È˺ÍСÎÒ˽¼Ò¹ú¼Ò¹ÒºÅ²áÒÔ¼°²»¶¯²úȨÁ¦¹ÒºÅ²á £¬Ô¤¼Æ»Ö¸´Ê±¼äԼΪÁ½ÖÜ¡£


https://www.infosecurity-magazine.com/news/ukraines-probes-gru-linked/


4. AscensionÒ½ÁÆϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬560ÍòÊý¾Ýй¶


12ÔÂ20ÈÕ £¬AscensionÊÇÃÀ¹ú×î´óµÄ˽ÈËÒ½ÁƱ£½¡ÏµÍ³Ö®Ò» £¬½üÆÚÔâÊÜÁËÓëBlack BastaÀÕË÷Èí¼þÐж¯Ïà¹ØµÄÍøÂç¹¥»÷ £¬µ¼Ö½ü560ÍòÃû»¼ÕߺÍÔ±¹¤µÄСÎÒ˽¼Ò¼°¿µ½¡Êý¾Ý±»µÁ¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÔËÓª×Å140¼ÒÒ½ÔººÍ40¼ÒÍíÄêÕչ˻¤Ê¿»ú¹¹ £¬ÄêÊÕÈë¸ß´ï283ÒÚÃÀÔª¡£AscensionÒÑÏòÊÜÓ°Ïì¸öÌåÓʼÄÁËÊý¾Ýй¶֪ͨ £¬²¢Ìṩ24¸öÔµÄÃâ·ÑIDXÉí·Ý͵ÇÔ±£»¤·þÎñ¡£¾ÝAscension͸¶ £¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤ÔÚ¹«Ë¾×°±¸ÉÏÏÂÔØÁ˶ñÒâÎļþ £¬Ö»¹Ü¹«Ë¾ÒÔΪÕâ¿ÉÄÜÊÇÎÞÒâÖ®¾Ù¡£´Ë´Î¹¥»÷Ó°ÏìÁËAscensionµÄMyChartµç×Ó¿µ½¡¼Í¼ϵͳµÈ¶à¸öÒªº¦ÏµÍ³ £¬µ¼ÖÂÔ±¹¤ÐèÔÚÖ½ÉϼͼÊÖÊõºÍÓÃÒ©ÇéÐÎ £¬²¢ÔÝÍ£ÁËһЩ·Ç½ôÆÈÊÖÊõºÍ¼ì²é¡£Ö»¹ÜAscensionδֱ½Ó½«¹¥»÷ÓëBlack BastaÁªÏµÆðÀ´ £¬µ«CNNºÍHealth-ISAC¾ùÖ¸³ö £¬Black Basta½üÆÚ¼ÓËÙÁ˶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷ £¬¶ø¸ÃÀÕË÷Èí¼þÍÅ»ïÒѶà´ÎÀÖ³ÉÈëÇÖ×ÅÃûÆóÒµÍøÂç²¢ÀÕË÷¾Þ¶î×ʽð¡£


https://www.bleepingcomputer.com/news/security/ascension-health-data-of-56-million-stolen-in-ransomware-attack/


5. Lazarus×é֯ʹÓÃÖØ´óѬȾÁ´°²ÅÅCookiePlusºóÃŹ¥»÷


12ÔÂ20ÈÕ £¬Lazarus×éÖ¯ÊÇÒ»¸öÓ볯ÏÊÓйØÁªµÄÍþвÐÐΪÕß £¬ÔÚ2024Äê1ÔÂʹÓÃÖØ´óµÄѬȾÁ´Õë¶ÔÖÁÉÙÁ½ÃûºËÏà¹Ø×éÖ¯Ô±¹¤¾ÙÐй¥»÷ £¬°²ÅÅÁËÃûΪCookiePlusµÄÐÂÄ £¿é»¯ºóÃÅ £¬ÕâÊǺã¾ÃÍøÂçÌع¤Ô˶¯¡°ÃÎÏëÊÂÇéÐж¯¡±µÄÒ»²¿·Ö¡£¸Ã×é֯ͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâÎĵµ»òľÂí»¯µÄÔ¶³Ì»á¼û¹¤¾ß £¬ÓÕʹĿµÄÅþÁ¬µ½Ìض¨·þÎñÆ÷¾ÙÐÐÊÖÒÕÆÀ¹À £¬½ø¶øÈö²¥¶ñÒâÈí¼þ¡£×îй¥»÷Éæ¼°·Ö·¢Ä¾Âí»¯µÄVNCÊÊÓóÌÐò £¬ÒÔISOÓ³ÏñºÍZIPÎļþµÄÐÎʽ·Ö·¢¡£±ðµÄ £¬Lazarus×éÖ¯»¹Ê¹ÓÃÁËÃûΪMISTPENµÄºóÃÅ £¬ÒÔ¼°LPEClient¡¢ServiceChanger¡¢Charamel LoaderµÈ¶ñÒâÈí¼þ¡£CookiePlus¶ñÒâÈí¼þ³äµ±ÏÂÔØÆ÷ £¬´ÓC2·þÎñÆ÷¼ìË÷¼ÓÃܵÄÓÐÓøºÔز¢Ö´ÐС£ÈËÃÇÏÓÒÉCookiePlusÊÇMISTPENµÄ¼ÌÐøÕß¡£ÕâÒ»·¢Ã÷Åú×¢ £¬Lazarus×éÖ¯Ò»Ö±ÔÚÆð¾¢Ë¢ÐÂÆäÎäÆ÷¿âºÍѬȾÁ´ £¬ÒÔÌÓ±ÜÇå¾²²úÆ·µÄ¼ì²â¡£


https://thehackernews.com/2024/12/lazarus-group-spotted-targeting-nuclear.html


6. ACEµ·»ÙÈ«Çò×î¸ÅÂÔÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïMarkkystreams


12ÔÂ20ÈÕ £¬´´ÒâÓëÓéÀÖͬÃË£¨ACE£©Àֳɵ·»ÙÁËÈ«Çò×î´óµÄÌåÓýÈüÊÂÖ±²¥µÁ°æÍÅ»ïÖ®Ò»Markkystreams £¬¸ÃÍÅ»ïÈ¥Äêµã»÷Á¿Áè¼Ý8.21ÒÚ´Î £¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¹ÛÖÚ¡£ACEÌåÏÖ £¬´Ë´ÎÐж¯»ñµÃÁËÆäËùÓгÉÔ±µÄÖ§³Ö £¬°üÀ¨DAZN¡¢beIN SportsºÍCanal+µÈÌåÓý¼¶³ÉÔ±¡£ÃÀ¹úӰϷЭ»áÖ´Ðи±×ܲöԴËÌåÏÖÔÞÉÍ £¬³ÆÕâÊǹ¥»÷ÌåÓýÈüÊÂÖ±²¥µÁ°æµÄÒ»´ÎÖØ´óʤÀû¡£·´µÁ°æ×éÖ¯Ö¸³ö £¬¸ÃÍÅ»ïµÄÔËÓªÉÌÒѽ«¿ØÖÆȨÒƽ»¸ø138¸öÓòÃû £¬±»²é·âµÄÍøÕ¾ÉÏÌùÓÐÒòÇÖÕ¼°æȨ¶ø¹Ø±ÕµÄºá·ù¡£ACEÊÇÒ»¸öÓÉ50¶à¼ÒýÌåºÍÓéÀÖ¹«Ë¾×é³ÉµÄͬÃË £¬×Ô2017ÄêÒÔÀ´Ò»Ö±ÖÂÁ¦Óڹرղ»·¨Á÷ýÌå·þÎñ £¬²¢ÒÑÀֳɹرնà¸öµÁ°æƽ̨¡£±ðµÄ £¬ACE»¹Óë¶à¸öÖ´·¨»ú¹¹ÏàÖú £¬Õë¶Ô´ó¹æÄ£²»·¨Á÷ýÌåÍŻ↑չÐж¯ £¬½ñÄêÒÑ×ÊÖú¹Ø±Õ¶à¸öµÁ°æÁ÷ýÌå·þÎñ £¬°üÀ¨Ò»¸ö×Ô2015ÄêÍƳöÒÔÀ´×¬È¡ÁËÊý°ÙÍòÃÀÔªµÄµÁ°æµçÊÓÁ÷ýÌåÍøÂçºÍÓµÓÐÁè¼Ý2200ÍòÓû§µÄµÁ°æÁ÷ýÌå·þÎñ¡£


https://www.bleepingcomputer.com/news/security/massive-live-sports-piracy-ring-with-812-million-yearly-visits-taken-offline/