·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶

Ðû²¼Ê±¼ä 2026-03-20

1. ·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶


3ÔÂ20ÈÕ £¬£¬£¬·¨¹úýÌå¡¶Ììϱ¨¡·¿ËÈÕÅû¶ £¬£¬£¬2026Äê3ÔÂ13ÈÕÉÏÎç10ʱ35·Ö £¬£¬£¬·¨¹úˮʦÄêÇá¾ü¹ÙÑÇɪ£¨¼ÙÃû£©ÔÚº½Ä¸¼×°åÉÏÅܲ½ £¬£¬£¬Ê¹ÓÃÖÇÄÜÊÖ±í¼Í¼ÁËÔ¼7¹«Àï¡¢ºÄʱ35·ÖÖÓµÄÔ˶¯Êý¾Ý¡£¡£¡£¡£¡£ÓÉÓڸþü¹ÙµÄStravaСÎÒ˽¼Ò×ÊÁÏÉèÖÃΪ¡°¹ûÕæ¡± £¬£¬£¬ÈκÎÈ˶¼¿ÉÉó²éÆäÔ˶¯¹ì¼£ £¬£¬£¬´Ó¶øÌ»Â¶ÁË·¨¹úˮʦº½¿Õĸ½¢´÷¸ßÀÖºÅÔÚµØÖк£¿£¿£¿£¿£¿¿½üÈûÆÖ·˹ºÍÍÁ¶úÆäÖÜΧµÄʵʱλÖᣡ£¡£¡£¡£·¨¹ú×ÜͳÂí¿ËÁúÓÚ3ÔÂ3ÈÕÐû²¼°²ÅÅ·¨¹úË®Ê¦ÌØÇ²²½¶Ó £¬£¬£¬°üÀ¨´÷¸ßÀֺź½¿Õĸ½¢¡¢ÈýËÒ»¤ÎÀ½¢ºÍÒ»ËÒ²¹¸ø½¢¡£¡£¡£¡£¡£Æäʱ´÷¸ßÀÖºÅÕýÔÚ²¨Â޵ĺ£¼ÓÈë±±Ô¼ÑÝϰ £¬£¬£¬Ô­ÍýÏëÍ£ÁôÖÁ5Ô £¬£¬£¬µ«Ëæºó±»°²ÅÅÖÁµØÖк£ÇøÓò¡£¡£¡£¡£¡£´Ë´Î°²ÅÅÕýÖµÒÔÉ«ÁС¢ÃÀ¹úºÍÒÁÀÊÖ®¼äÕ½Õù±¬·¢ºóÊýÈÕ¡£¡£¡£¡£¡£×¨¼ÒÖÒÑÔ £¬£¬£¬´ËÀàÊý¾Ý¿ÉÄÜ×ÊÖúµÐÊÖʶ±ðºÍËø¶¨¾üÊÂÄ¿µÄ £¬£¬£¬Í¹ÏÔ½¡Éí×·×ÙÆ÷´øÀ´µÄÒ»Á¬Òþ˽ÎÊÌâ¡£¡£¡£¡£¡£


https://securityaffairs.com/189696/intelligence/french-aircraft-carrier-charles-de-gaulle-tracked-via-strava-activity-in-opsec-failure.html


2. NaviaÊý¾Ýй¶ӰÏì270ÍòÓû§Ãô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ £¬£¬£¬ÃÀ¹ú¸£ÀûÖÎÃ÷È·¾ö¼Æ»®ÌṩÉÌNavia Benefit Solutions¿ËÈÕ֪ͨ½ü270ÍòÈË £¬£¬£¬ÆäÃô¸ÐÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖб»¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÃÀ¹ú1Íò¶à¼Ò¹ÍÖ÷ÌṩÎÞа֧³öÕË»§£¨FSA£©¡¢¿µ½¡´¢±¸ÕË»§£¨HSA£©¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¡¢Í¨ÇÚ¸£ÀûºÍCOBRAЧÀ͵ȸ£ÀûÖÎÀíЧÀÍ¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ £¬£¬£¬ºÚ¿ÍÔÚ2025Äê12ÔÂ22ÈÕÖÁ2026Äê1ÔÂ15ÈÕʱ´úÄܹ»»á¼û¸Ã¹«Ë¾ÏµÍ³ £¬£¬£¬¹«Ë¾ÓÚ1ÔÂ23ÈÕ·¢Ã÷¿ÉÒɻ¡£¡£¡£¡£¡£NaviaÌåÏÖÁ¬Ã¦×ö³öÏìÓ¦²¢Æô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñµÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£ÊÓ²ìÈ·¶¨Î´¾­ÊÚȨµÄÐÐΪÕßÔÚÉÏÊöʱ´ú»á¼û²¢»ñÈ¡ÁËÌØ¶¨ÐÅÏ¢¡£¡£¡£¡£¡£±»»á¼ûºÍ¿ÉÄÜÍâйµÄÊý¾ÝÀàÐͰüÀ¨£ºÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¼ÓÈëÐÅÏ¢¡¢ÎÞа֧³öÕË»§£¨FSA£©ÐÅÏ¢¡¢×ÛºÏOmnibusÔ¤ËãЭµ÷·¨°¸£¨COBRA£©×¢²áÐÅÏ¢¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷Êý¾Ýй¶δ̻¶Ë÷ÅâÏêÇé»ò²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ £¬£¬£¬Ì»Â¶µÄÊý¾Ý×ãÒÔʹÍþвÐÐΪÕßÕë¶ÔÊÜÓ°ÏìСÎÒ˽¼Ò°²ÅÅ´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/


3. Speagle¶ñÒâÈí¼þÐ®ÖÆCobra DocGuardÇÔÈ¡Êý¾Ý


3ÔÂ19ÈÕ £¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷ÃûΪSpeagleµÄÐÂÐͶñÒâÈí¼þ £¬£¬£¬¸ÃÈí¼þÐ®ÖÆÕýµ±³ÌÐòCobraDocGuardµÄ¹¦Ð§ºÍ»ù´¡ÉèÊ©¾ÙÐÐÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£CobraDocGuardÊÇÓÉEsafeNet¿ª·¢µÄÎĵµÇå¾²ºÍ¼ÓÃÜÆ½Ì¨¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪRunningcrab £¬£¬£¬ÏÖÔÚÉÐδ¹éÒò¡£¡£¡£¡£¡£SpeagleÖ¼ÔÚÉñÃØÍøÂçÊÜѬȾÅÌËã»úµÄÃô¸ÐÐÅÏ¢ £¬£¬£¬²¢½«Æä´«ÊäÖÁ±»¹¥»÷Õß¹¥ÏݵÄCobraDocGuardЧÀÍÆ÷ £¬£¬£¬½«Êý¾ÝÍâйÀú³Ìαװ³É¿Í»§¶ËÓëЧÀÍÆ÷Ö®¼äµÄÕýµ±Í¨Ñ¶¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶Ô×°ÖÃÁËCobraDocGuardÊý¾Ý± £»£»£»£»£»£»¤Èí¼þµÄϵͳ £¬£¬£¬Åú×¢¹¥»÷Õß¿ÉÄÜÓÐÒâÕë¶ÔÌØ¶¨×éÖ¯¾ÙÐÐÇé±¨ÍøÂç»ò¹¤ÒµÌع¤»î¶¯¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÕâ×îÓпÉÄÜÊǹú¼ÒÖ§³ÖµÄÐÐΪÕß»ò¿É¹ÍÓ¶µÄ˽Ӫ³Ð°üÉÌËùΪ¡£¡£¡£¡£¡£SpeagleΪ32λ.NET¿ÉÖ´ÐÐÎļþ £¬£¬£¬Æô¶¯ºóÊ×Ïȼì²éCobraDocGuard×°ÖÃÎļþ¼Ð £¬£¬£¬È»ºó·Ö½×¶ÎÍøÂç²¢´«ÊäÊÜѬȾ»úеµÄÊý¾Ý £¬£¬£¬°üÀ¨ÏµÍ³ÏêÇéºÍÌØ¶¨Îļþ¼ÐÖеÄÎļþ £¬£¬£¬Èç°üÀ¨ÍøÒ³ä¯ÀÀÆ÷ÀúÊ·ºÍ×Ô¶¯Ìî³äÊý¾ÝµÄÎļþ¼Ð¡£¡£¡£¡£¡£


https://thehackernews.com/2026/03/speagle-malware-hijacks-cobra-docguard.html


4. Magento PolyShellÎó²îÔÊÐíδÊÚȨ´úÂëÖ´ÐÐ


3ÔÂ19ÈÕ £¬£¬£¬µç×ÓÉÌÎñÇå¾²¹«Ë¾Sansec¿ËÈÕÅû¶ÃûΪ"PolyShell"µÄÐÂÎó²î £¬£¬£¬¸ÃÎó²îÓ°ÏìËùÓÐMagentoOpenSourceºÍAdobeCommerceÎȹ̰æ2.4.9×°Öà £¬£¬£¬ÔÊÐíδÊÚȨ¹¥»÷ÕßÖ´ÐдúÂëºÍ½ÓÊÜÕË»§¡£¡£¡£¡£¡£ÏÖÔÚÉÐδ·¢Ã÷¸ÃÎó²îÔÚÒ°Íâ±»Æð¾¢Ê¹Óõļ£Ïó £¬£¬£¬µ«SansecÖÒÑÔʹÓÃÒªÁìÒÑÔÚÈö²¥ £¬£¬£¬Ô¤¼Æ×Ô¶¯»¯¹¥»÷¼´½«×îÏÈ¡£¡£¡£¡£¡£¸ÃÇå¾²ÎÊÌâÔ´ÓÚMagentoµÄRESTAPI½ÓÊÜÎļþÉÏ´«×÷Ϊ¹ºÎï³µÏîÄ¿×Ô½ç˵ѡÏîµÄÒ»²¿·Ö¡£¡£¡£¡£¡£µ±²úÆ·Ñ¡ÏîÀàÐÍΪ"Îļþ"ʱ £¬£¬£¬Magento»á´¦Öóͷ£Ç¶ÈëµÄfile_info¹¤¾ß £¬£¬£¬ÆäÖаüÀ¨base64±àÂëµÄÎļþÊý¾Ý¡¢MIMEÀàÐͺÍÎļþÃû¡£¡£¡£¡£¡£Îļþ±»Ð´ÈëЧÀÍÆ÷ÉϵÄpub/media/custom_options/quote/Ŀ¼¡£¡£¡£¡£¡£"PolyShell"Ãû³ÆÔ´ÓÚÆäʹÓöà̬Îļþ £¬£¬£¬¸ÃÎļþ¿Éͬʱ×÷ΪͼÏñºÍ¾ç±¾ÔËÐС£¡£¡£¡£¡£Æ¾Ö¤WebЧÀÍÆ÷ÉèÖà £¬£¬£¬¸ÃÎó²î¿Éͨ¹ýÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©»ò´æ´¢ÐÍ¿çÕ¾¾ç±¾£¨XSS£©ÊµÏÖÕË»§½ÓÊÜ £¬£¬£¬Ó°ÏìSansecÆÊÎöµÄ´ó´ó¶¼ÊÐËÁ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÊÓ²ìÁËËùÓÐÒÑÖªµÄMagentoºÍAdobeCommerceÊÐËÁ £¬£¬£¬·¢Ã÷Ðí¶àÊÐËÁ̻¶ÁËÉÏ´«Ä¿Â¼ÖеÄÎļþ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/


5. BitrefillÔ⳯ÏÊBluenoroffºÚ¿Í×éÖ¯¹¥»÷


3ÔÂ19ÈÕ £¬£¬£¬¼ÓÃÜÇ®±ÒÀñÎ│ÊÐËÁBitrefill¿ËÈÕÌåÏÖ £¬£¬£¬Ô³õÔâÊܵĹ¥»÷ºÜ¿ÉÄÜÓɳ¯ÏÊBluenoroffºÚ¿Í×é֯ʵÑé¡£¡£¡£¡£¡£ÊÓ²ìʱ´ú £¬£¬£¬¸Ãƽ̨ÊӲ쵽Óë֮ǰ¹éÒòÓÚ³¯ÏÊÍþвÐÐΪÕߵĹ¥»÷ÏàËÆµÄÖ¸±ê £¬£¬£¬°üÀ¨Õ½Êõ¡¢¶ñÒâÈí¼þ¡¢IPºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£BitrefillÊÇÒ»¼ÒÖÐÐ͵ç×ÓÉÌÎñƽ̨ £¬£¬£¬ÔÊÐíÓû§Ê¹ÓüÓÃÜÇ®±ÒÔÚ150¸ö¹ú¼ÒµÄÊÐËÁ¹ºÖÃÀñÎ│¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÈ«Çò600¶à¼ÒÒÆ¶¯ÔËÓªÉ̺ÍÊýǧ¸öÆ·ÅÆ¡£¡£¡£¡£¡£3ÔÂ1ÈÕ £¬£¬£¬BitrefillÐû²¼ÍøÕ¾ºÍÓ¦Óûá¼û·ºÆðÊÖÒÕÎÊÌâ¡£¡£¡£¡£¡£Ô½ÈÕ £¬£¬£¬¹«Ë¾Åû¶·¢Ã÷Çå¾²ÎÊÌâ²¢½«ËùÓÐЧÀÍÏÂÏß¡£¡£¡£¡£¡£ÊӲ췢Ã÷ £¬£¬£¬¹¥»÷Ô´ÓÚ±»¹¥ÏݵÄÔ±¹¤Ìõ¼Ç±¾µçÄÔ¡£¡£¡£¡£¡£¹¥»÷ÕßÇÔÈ¡ÁË¾É°æÆ¾Ö¤ £¬£¬£¬²¢Ê¹ÓÃÕâЩƾ֤»á¼û°üÀ¨Éú²úÃÜÔ¿µÄ¿ìÕÕ £¬£¬£¬Ëæºó½«»á¼ûȨÏÞÉý¼¶ÖÁBitrefill¸ü´óµÄ»ù´¡ÉèÊ© £¬£¬£¬°üÀ¨²¿·ÖÊý¾Ý¿âºÍһЩ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±»·¢Ã÷ÊÇÓÉÓÚBitrefill×¢ÖØµ½¿ÉÒɵũӦÉ̲ɹºÄ£Ê½¡¢ÀñÎ│¿â´æºÍ¹©Ó¦Á´±»Ê¹Óà £¬£¬£¬ÒÔ¼°Ò»Ð©"ÈÈ"Ç®°ü±»ÌͿա£¡£¡£¡£¡£Ô¼18,500Ìõ¹ºÖüͼÔÚй¶Öб»Ì»Â¶ £¬£¬£¬°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢IPµØµãºÍ¼ÓÃÜÇ®±ÒÖ§¸¶µØµã¡£¡£¡£¡£¡£ÆäÖÐ1,000Ìõ¹ºÖüͼµÄ¿Í»§ÐÕÃûÒ²±»Ì»Â¶¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÐÅÏ¢ÒÔ¼ÓÃÜÐÎʽ´æ´¢ £¬£¬£¬BitrefillÖ¸³ö¹¥»÷Õß¿ÉÄÜÒÑ»ñµÃ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/


6. Perseus°²×¿¶ñÒâÈí¼þÇÔÈ¡Óû§Ìõ¼ÇÃô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ £¬£¬£¬Òƶ¯Çå¾²¹«Ë¾ThreatFabric¿ËÈÕ·¢Ã÷ÃûΪPerseusµÄÐÂÐͰ²×¿¶ñÒâÈí¼þ £¬£¬£¬¸ÃÈí¼þרÃżì²éÓû§½¨ÉèµÄÌõ¼ÇÒÔÇÔÈ¡ÃÜÂë¡¢»Ö¸´¶ÌÓï»ò²ÆÎñÊý¾ÝµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÍþвÇ÷ÊÆÔÚÒÑÍù°Ë¸öÔ·ºÆð £¬£¬£¬Óû§×·ÇóÃâ·Ñ»òµÍ±¾Ç®·½·¨Ô¢Ä¿ÌåÓýÖ±²¥¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃIPTVÓ¦ÓÃÓÕ¶ü·Ö·¢¶ñÒâÈí¼þ £¬£¬£¬ÆäÖÐÒ»¿îÈö²¥¶ñÒâÈí¼þµÄÓ¦ÓÃÃûΪRojadirectaTV £¬£¬£¬ÊÇÊ¢ÐеÄÌåÓýÁ÷ýÌåЧÀÍ¡£¡£¡£¡£¡£PerseusµÄ¼ÓÔØÆ÷¿ÉÈÆ¹ý°²×¿13¼°ÒÔÉϰ汾µÄ²àÔØÏÞÖÆ £¬£¬£¬Óë·Ö·¢KlopatraºÍMedusa¶ñÒâÈí¼þµÄ¼ÓÔØÆ÷Ïàͬ¡£¡£¡£¡£¡£PerseusÖ÷ÒªÕë¶ÔÍÁ¶úÆäºÍÒâ´óÀûµÄ½ðÈÚ»ú¹¹ÒÔ¼°¼ÓÃÜÇ®±ÒЧÀÍ¡£¡£¡£¡£¡£Í¨¹ýÀÄÓð²×¿¸¨Öú¹¦Ð§ £¬£¬£¬Perseus¸¶Óë²Ù×÷ÕßÍêȫԶ³Ì¿ØÖÆÈ¨ÏÞ £¬£¬£¬¿ÉÒ»Á¬½ØÈ¡ÆÁÄ»½ØÍ¼²¢´®Á÷ÖÁ²Ù×÷¶Ë¡¢Ä£Äâµã»÷ºÍ»¬¶¯¡¢¿ªÆô»ò×èÖ¹Ó¦Óá¢ÆôÓÃºÚÆÁÁýÕÖÒþ²Ø»î¶¯¡¢ÊµÑéÁýÕÖ¹¥»÷ºÍ¼üÅ̼ͼ¡£¡£¡£¡£¡£PerseusµÄ²»Ñ°³£¹¦Ð§ÊÇÕë¶Ô°²×¿Ìõ¼ÇÓ¦Óà £¬£¬£¬ÕâÊÇÊ״η¢Ã÷°²×¿¶ñÒâÈí¼þ¼ì²é×°±¸Ð¡ÎÒ˽¼ÒÌõ¼ÇÖеÄÃô¸ÐÏêÇé¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-perseus-android-malware-checks-user-notes-for-secrets/