·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶
Ðû²¼Ê±¼ä 2026-03-201. ·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶
3ÔÂ20ÈÕ£¬£¬£¬·¨¹úýÌå¡¶Ììϱ¨¡·¿ËÈÕÅû¶£¬£¬£¬2026Äê3ÔÂ13ÈÕÉÏÎç10ʱ35·Ö£¬£¬£¬·¨¹úˮʦÄêÇá¾ü¹ÙÑÇɪ£¨¼ÙÃû£©ÔÚº½Ä¸¼×°åÉÏÅܲ½£¬£¬£¬Ê¹ÓÃÖÇÄÜÊÖ±í¼Í¼ÁËÔ¼7¹«Àï¡¢ºÄʱ35·ÖÖÓµÄÔ˶¯Êý¾Ý¡£¡£¡£¡£¡£ÓÉÓڸþü¹ÙµÄStravaСÎÒ˽¼Ò×ÊÁÏÉèÖÃΪ¡°¹ûÕæ¡±£¬£¬£¬ÈκÎÈ˶¼¿ÉÉó²éÆäÔ˶¯¹ì¼££¬£¬£¬´Ó¶øÌ»Â¶ÁË·¨¹úˮʦº½¿Õĸ½¢´÷¸ßÀÖºÅÔÚµØÖк£¿£¿£¿£¿£¿¿½üÈûÆÖ·˹ºÍÍÁ¶úÆäÖÜΧµÄʵʱλÖᣡ£¡£¡£¡£·¨¹ú×ÜͳÂí¿ËÁúÓÚ3ÔÂ3ÈÕÐû²¼°²ÅÅ·¨¹úË®Ê¦ÌØÇ²²½¶Ó£¬£¬£¬°üÀ¨´÷¸ßÀֺź½¿Õĸ½¢¡¢ÈýËÒ»¤ÎÀ½¢ºÍÒ»ËÒ²¹¸ø½¢¡£¡£¡£¡£¡£Æäʱ´÷¸ßÀÖºÅÕýÔÚ²¨Â޵ĺ£¼ÓÈë±±Ô¼ÑÝϰ£¬£¬£¬ÔÍýÏëÍ£ÁôÖÁ5Ô£¬£¬£¬µ«Ëæºó±»°²ÅÅÖÁµØÖк£ÇøÓò¡£¡£¡£¡£¡£´Ë´Î°²ÅÅÕýÖµÒÔÉ«ÁС¢ÃÀ¹úºÍÒÁÀÊÖ®¼äÕ½Õù±¬·¢ºóÊýÈÕ¡£¡£¡£¡£¡£×¨¼ÒÖÒÑÔ£¬£¬£¬´ËÀàÊý¾Ý¿ÉÄÜ×ÊÖúµÐÊÖʶ±ðºÍËø¶¨¾üÊÂÄ¿µÄ£¬£¬£¬Í¹ÏÔ½¡Éí×·×ÙÆ÷´øÀ´µÄÒ»Á¬Òþ˽ÎÊÌâ¡£¡£¡£¡£¡£
https://securityaffairs.com/189696/intelligence/french-aircraft-carrier-charles-de-gaulle-tracked-via-strava-activity-in-opsec-failure.html
2. NaviaÊý¾Ýй¶ӰÏì270ÍòÓû§Ãô¸ÐÐÅÏ¢
3ÔÂ19ÈÕ£¬£¬£¬ÃÀ¹ú¸£ÀûÖÎÃ÷È·¾ö¼Æ»®ÌṩÉÌNavia Benefit Solutions¿ËÈÕ֪ͨ½ü270ÍòÈË£¬£¬£¬ÆäÃô¸ÐÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖб»¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÃÀ¹ú1Íò¶à¼Ò¹ÍÖ÷ÌṩÎÞа֧³öÕË»§£¨FSA£©¡¢¿µ½¡´¢±¸ÕË»§£¨HSA£©¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¡¢Í¨ÇÚ¸£ÀûºÍCOBRAЧÀ͵ȸ£ÀûÖÎÀíЧÀÍ¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬ºÚ¿ÍÔÚ2025Äê12ÔÂ22ÈÕÖÁ2026Äê1ÔÂ15ÈÕʱ´úÄܹ»»á¼û¸Ã¹«Ë¾ÏµÍ³£¬£¬£¬¹«Ë¾ÓÚ1ÔÂ23ÈÕ·¢Ã÷¿ÉÒɻ¡£¡£¡£¡£¡£NaviaÌåÏÖÁ¬Ã¦×ö³öÏìÓ¦²¢Æô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñµÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£ÊÓ²ìÈ·¶¨Î´¾ÊÚȨµÄÐÐΪÕßÔÚÉÏÊöʱ´ú»á¼û²¢»ñÈ¡ÁËÌØ¶¨ÐÅÏ¢¡£¡£¡£¡£¡£±»»á¼ûºÍ¿ÉÄÜÍâйµÄÊý¾ÝÀàÐͰüÀ¨£ºÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¼ÓÈëÐÅÏ¢¡¢ÎÞа֧³öÕË»§£¨FSA£©ÐÅÏ¢¡¢×ÛºÏOmnibusÔ¤Ëãе÷·¨°¸£¨COBRA£©×¢²áÐÅÏ¢¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷Êý¾Ýй¶δ̻¶Ë÷ÅâÏêÇé»ò²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬Ì»Â¶µÄÊý¾Ý×ãÒÔʹÍþвÐÐΪÕßÕë¶ÔÊÜÓ°ÏìСÎÒ˽¼Ò°²ÅÅ´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/
3. Speagle¶ñÒâÈí¼þÐ®ÖÆCobra DocGuardÇÔÈ¡Êý¾Ý
3ÔÂ19ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷ÃûΪSpeagleµÄÐÂÐͶñÒâÈí¼þ£¬£¬£¬¸ÃÈí¼þÐ®ÖÆÕýµ±³ÌÐòCobraDocGuardµÄ¹¦Ð§ºÍ»ù´¡ÉèÊ©¾ÙÐÐÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£CobraDocGuardÊÇÓÉEsafeNet¿ª·¢µÄÎĵµÇå¾²ºÍ¼ÓÃÜÆ½Ì¨¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪRunningcrab£¬£¬£¬ÏÖÔÚÉÐδ¹éÒò¡£¡£¡£¡£¡£SpeagleÖ¼ÔÚÉñÃØÍøÂçÊÜѬȾÅÌËã»úµÄÃô¸ÐÐÅÏ¢£¬£¬£¬²¢½«Æä´«ÊäÖÁ±»¹¥»÷Õß¹¥ÏݵÄCobraDocGuardЧÀÍÆ÷£¬£¬£¬½«Êý¾ÝÍâйÀú³Ìαװ³É¿Í»§¶ËÓëЧÀÍÆ÷Ö®¼äµÄÕýµ±Í¨Ñ¶¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶Ô×°ÖÃÁËCobraDocGuardÊý¾Ý±£»£»£»£»£»£»¤Èí¼þµÄϵͳ£¬£¬£¬Åú×¢¹¥»÷Õß¿ÉÄÜÓÐÒâÕë¶ÔÌØ¶¨×éÖ¯¾ÙÐÐÇé±¨ÍøÂç»ò¹¤ÒµÌع¤»î¶¯¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÕâ×îÓпÉÄÜÊǹú¼ÒÖ§³ÖµÄÐÐΪÕß»ò¿É¹ÍÓ¶µÄ˽Ӫ³Ð°üÉÌËùΪ¡£¡£¡£¡£¡£SpeagleΪ32λ.NET¿ÉÖ´ÐÐÎļþ£¬£¬£¬Æô¶¯ºóÊ×Ïȼì²éCobraDocGuard×°ÖÃÎļþ¼Ð£¬£¬£¬È»ºó·Ö½×¶ÎÍøÂç²¢´«ÊäÊÜѬȾ»úеµÄÊý¾Ý£¬£¬£¬°üÀ¨ÏµÍ³ÏêÇéºÍÌØ¶¨Îļþ¼ÐÖеÄÎļþ£¬£¬£¬Èç°üÀ¨ÍøÒ³ä¯ÀÀÆ÷ÀúÊ·ºÍ×Ô¶¯Ìî³äÊý¾ÝµÄÎļþ¼Ð¡£¡£¡£¡£¡£
https://thehackernews.com/2026/03/speagle-malware-hijacks-cobra-docguard.html
4. Magento PolyShellÎó²îÔÊÐíδÊÚȨ´úÂëÖ´ÐÐ
3ÔÂ19ÈÕ£¬£¬£¬µç×ÓÉÌÎñÇå¾²¹«Ë¾Sansec¿ËÈÕÅû¶ÃûΪ"PolyShell"µÄÐÂÎó²î£¬£¬£¬¸ÃÎó²îÓ°ÏìËùÓÐMagentoOpenSourceºÍAdobeCommerceÎȹ̰æ2.4.9×°Ö㬣¬£¬ÔÊÐíδÊÚȨ¹¥»÷ÕßÖ´ÐдúÂëºÍ½ÓÊÜÕË»§¡£¡£¡£¡£¡£ÏÖÔÚÉÐδ·¢Ã÷¸ÃÎó²îÔÚÒ°Íâ±»Æð¾¢Ê¹Óõļ£Ï󣬣¬£¬µ«SansecÖÒÑÔʹÓÃÒªÁìÒÑÔÚÈö²¥£¬£¬£¬Ô¤¼Æ×Ô¶¯»¯¹¥»÷¼´½«×îÏÈ¡£¡£¡£¡£¡£¸ÃÇå¾²ÎÊÌâÔ´ÓÚMagentoµÄRESTAPI½ÓÊÜÎļþÉÏ´«×÷Ϊ¹ºÎï³µÏîÄ¿×Ô½ç˵ѡÏîµÄÒ»²¿·Ö¡£¡£¡£¡£¡£µ±²úÆ·Ñ¡ÏîÀàÐÍΪ"Îļþ"ʱ£¬£¬£¬Magento»á´¦Öóͷ£Ç¶ÈëµÄfile_info¹¤¾ß£¬£¬£¬ÆäÖаüÀ¨base64±àÂëµÄÎļþÊý¾Ý¡¢MIMEÀàÐͺÍÎļþÃû¡£¡£¡£¡£¡£Îļþ±»Ð´ÈëЧÀÍÆ÷ÉϵÄpub/media/custom_options/quote/Ŀ¼¡£¡£¡£¡£¡£"PolyShell"Ãû³ÆÔ´ÓÚÆäʹÓöà̬Îļþ£¬£¬£¬¸ÃÎļþ¿Éͬʱ×÷ΪͼÏñºÍ¾ç±¾ÔËÐС£¡£¡£¡£¡£Æ¾Ö¤WebЧÀÍÆ÷ÉèÖ㬣¬£¬¸ÃÎó²î¿Éͨ¹ýÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©»ò´æ´¢ÐÍ¿çÕ¾¾ç±¾£¨XSS£©ÊµÏÖÕË»§½ÓÊÜ£¬£¬£¬Ó°ÏìSansecÆÊÎöµÄ´ó´ó¶¼ÊÐËÁ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÊÓ²ìÁËËùÓÐÒÑÖªµÄMagentoºÍAdobeCommerceÊÐËÁ£¬£¬£¬·¢Ã÷Ðí¶àÊÐËÁ̻¶ÁËÉÏ´«Ä¿Â¼ÖеÄÎļþ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/
5. BitrefillÔ⳯ÏÊBluenoroffºÚ¿Í×éÖ¯¹¥»÷
3ÔÂ19ÈÕ£¬£¬£¬¼ÓÃÜÇ®±ÒÀñÎ│ÊÐËÁBitrefill¿ËÈÕÌåÏÖ£¬£¬£¬Ô³õÔâÊܵĹ¥»÷ºÜ¿ÉÄÜÓɳ¯ÏÊBluenoroffºÚ¿Í×é֯ʵÑé¡£¡£¡£¡£¡£ÊÓ²ìʱ´ú£¬£¬£¬¸Ãƽ̨ÊӲ쵽Óë֮ǰ¹éÒòÓÚ³¯ÏÊÍþвÐÐΪÕߵĹ¥»÷ÏàËÆµÄÖ¸±ê£¬£¬£¬°üÀ¨Õ½Êõ¡¢¶ñÒâÈí¼þ¡¢IPºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£BitrefillÊÇÒ»¼ÒÖÐÐ͵ç×ÓÉÌÎñƽ̨£¬£¬£¬ÔÊÐíÓû§Ê¹ÓüÓÃÜÇ®±ÒÔÚ150¸ö¹ú¼ÒµÄÊÐËÁ¹ºÖÃÀñÎ│¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÈ«Çò600¶à¼ÒÒÆ¶¯ÔËÓªÉ̺ÍÊýǧ¸öÆ·ÅÆ¡£¡£¡£¡£¡£3ÔÂ1ÈÕ£¬£¬£¬BitrefillÐû²¼ÍøÕ¾ºÍÓ¦Óûá¼û·ºÆðÊÖÒÕÎÊÌâ¡£¡£¡£¡£¡£Ô½ÈÕ£¬£¬£¬¹«Ë¾Åû¶·¢Ã÷Çå¾²ÎÊÌâ²¢½«ËùÓÐЧÀÍÏÂÏß¡£¡£¡£¡£¡£ÊӲ췢Ã÷£¬£¬£¬¹¥»÷Ô´ÓÚ±»¹¥ÏݵÄÔ±¹¤Ìõ¼Ç±¾µçÄÔ¡£¡£¡£¡£¡£¹¥»÷ÕßÇÔÈ¡ÁË¾É°æÆ¾Ö¤£¬£¬£¬²¢Ê¹ÓÃÕâЩƾ֤»á¼û°üÀ¨Éú²úÃÜÔ¿µÄ¿ìÕÕ£¬£¬£¬Ëæºó½«»á¼ûȨÏÞÉý¼¶ÖÁBitrefill¸ü´óµÄ»ù´¡ÉèÊ©£¬£¬£¬°üÀ¨²¿·ÖÊý¾Ý¿âºÍһЩ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±»·¢Ã÷ÊÇÓÉÓÚBitrefill×¢ÖØµ½¿ÉÒɵũӦÉ̲ɹºÄ£Ê½¡¢ÀñÎ│¿â´æºÍ¹©Ó¦Á´±»Ê¹Ó㬣¬£¬ÒÔ¼°Ò»Ð©"ÈÈ"Ç®°ü±»ÌͿա£¡£¡£¡£¡£Ô¼18,500Ìõ¹ºÖüͼÔÚй¶Öб»Ì»Â¶£¬£¬£¬°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢IPµØµãºÍ¼ÓÃÜÇ®±ÒÖ§¸¶µØµã¡£¡£¡£¡£¡£ÆäÖÐ1,000Ìõ¹ºÖüͼµÄ¿Í»§ÐÕÃûÒ²±»Ì»Â¶¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÐÅÏ¢ÒÔ¼ÓÃÜÐÎʽ´æ´¢£¬£¬£¬BitrefillÖ¸³ö¹¥»÷Õß¿ÉÄÜÒÑ»ñµÃ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/
6. Perseus°²×¿¶ñÒâÈí¼þÇÔÈ¡Óû§Ìõ¼ÇÃô¸ÐÐÅÏ¢
3ÔÂ19ÈÕ£¬£¬£¬Òƶ¯Çå¾²¹«Ë¾ThreatFabric¿ËÈÕ·¢Ã÷ÃûΪPerseusµÄÐÂÐͰ²×¿¶ñÒâÈí¼þ£¬£¬£¬¸ÃÈí¼þרÃżì²éÓû§½¨ÉèµÄÌõ¼ÇÒÔÇÔÈ¡ÃÜÂë¡¢»Ö¸´¶ÌÓï»ò²ÆÎñÊý¾ÝµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÍþвÇ÷ÊÆÔÚÒÑÍù°Ë¸öÔ·ºÆð£¬£¬£¬Óû§×·ÇóÃâ·Ñ»òµÍ±¾Ç®·½·¨Ô¢Ä¿ÌåÓýÖ±²¥¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃIPTVÓ¦ÓÃÓÕ¶ü·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬ÆäÖÐÒ»¿îÈö²¥¶ñÒâÈí¼þµÄÓ¦ÓÃÃûΪRojadirectaTV£¬£¬£¬ÊÇÊ¢ÐеÄÌåÓýÁ÷ýÌåЧÀÍ¡£¡£¡£¡£¡£PerseusµÄ¼ÓÔØÆ÷¿ÉÈÆ¹ý°²×¿13¼°ÒÔÉϰ汾µÄ²àÔØÏÞÖÆ£¬£¬£¬Óë·Ö·¢KlopatraºÍMedusa¶ñÒâÈí¼þµÄ¼ÓÔØÆ÷Ïàͬ¡£¡£¡£¡£¡£PerseusÖ÷ÒªÕë¶ÔÍÁ¶úÆäºÍÒâ´óÀûµÄ½ðÈÚ»ú¹¹ÒÔ¼°¼ÓÃÜÇ®±ÒЧÀÍ¡£¡£¡£¡£¡£Í¨¹ýÀÄÓð²×¿¸¨Öú¹¦Ð§£¬£¬£¬Perseus¸¶Óë²Ù×÷ÕßÍêȫԶ³Ì¿ØÖÆÈ¨ÏÞ£¬£¬£¬¿ÉÒ»Á¬½ØÈ¡ÆÁÄ»½ØÍ¼²¢´®Á÷ÖÁ²Ù×÷¶Ë¡¢Ä£Äâµã»÷ºÍ»¬¶¯¡¢¿ªÆô»ò×èÖ¹Ó¦Óá¢ÆôÓÃºÚÆÁÁýÕÖÒþ²Ø»î¶¯¡¢ÊµÑéÁýÕÖ¹¥»÷ºÍ¼üÅ̼ͼ¡£¡£¡£¡£¡£PerseusµÄ²»Ñ°³£¹¦Ð§ÊÇÕë¶Ô°²×¿Ìõ¼ÇÓ¦Ó㬣¬£¬ÕâÊÇÊ״η¢Ã÷°²×¿¶ñÒâÈí¼þ¼ì²é×°±¸Ð¡ÎÒ˽¼ÒÌõ¼ÇÖеÄÃô¸ÐÏêÇé¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-perseus-android-malware-checks-user-notes-for-secrets/


¾©¹«Íø°²±¸11010802024551ºÅ