·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶

Ðû²¼Ê±¼ä 2026-03-20

1. ·¨¹ú´÷¸ßÀֺź½Ä¸Î»ÖÃÒòStravaÓ¦ÓÃй¶


3ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬·¨¹úýÌå¡¶Ììϱ¨¡·¿ËÈÕÅû¶£¬ £¬£¬£¬£¬£¬£¬2026Äê3ÔÂ13ÈÕÉÏÎç10ʱ35·Ö£¬ £¬£¬£¬£¬£¬£¬·¨¹úˮʦÄêÇá¾ü¹ÙÑÇɪ£¨¼ÙÃû£©ÔÚº½Ä¸¼×°åÉÏÅܲ½£¬ £¬£¬£¬£¬£¬£¬Ê¹ÓÃÖÇÄÜÊÖ±í¼Í¼ÁËÔ¼7¹«Àï¡¢ºÄʱ35·ÖÖÓµÄÔ˶¯Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸþü¹ÙµÄStravaСÎÒ˽¼Ò×ÊÁÏÉèÖÃΪ¡°¹ûÕæ¡±£¬ £¬£¬£¬£¬£¬£¬ÈκÎÈ˶¼¿ÉÉó²éÆäÔ˶¯¹ì¼££¬ £¬£¬£¬£¬£¬£¬´Ó¶øÌ»Â¶ÁË·¨¹úˮʦº½¿Õĸ½¢´÷¸ßÀÖºÅÔÚµØÖк£¿£¿£¿£¿¿½üÈûÆÖ·˹ºÍÍÁ¶úÆäÖÜΧµÄʵʱλÖᣡ£¡£¡£¡£¡£¡£·¨¹ú×ÜͳÂí¿ËÁúÓÚ3ÔÂ3ÈÕÐû²¼°²ÅÅ·¨¹úË®Ê¦ÌØÇ²²½¶Ó£¬ £¬£¬£¬£¬£¬£¬°üÀ¨´÷¸ßÀֺź½¿Õĸ½¢¡¢ÈýËÒ»¤ÎÀ½¢ºÍÒ»ËÒ²¹¸ø½¢¡£¡£¡£¡£¡£¡£¡£Æäʱ´÷¸ßÀÖºÅÕýÔÚ²¨Â޵ĺ£¼ÓÈë±±Ô¼ÑÝϰ£¬ £¬£¬£¬£¬£¬£¬Ô­ÍýÏëÍ£ÁôÖÁ5Ô£¬ £¬£¬£¬£¬£¬£¬µ«Ëæºó±»°²ÅÅÖÁµØÖк£ÇøÓò¡£¡£¡£¡£¡£¡£¡£´Ë´Î°²ÅÅÕýÖµÒÔÉ«ÁС¢ÃÀ¹úºÍÒÁÀÊÖ®¼äÕ½Õù±¬·¢ºóÊýÈÕ¡£¡£¡£¡£¡£¡£¡£×¨¼ÒÖÒÑÔ£¬ £¬£¬£¬£¬£¬£¬´ËÀàÊý¾Ý¿ÉÄÜ×ÊÖúµÐÊÖʶ±ðºÍËø¶¨¾üÊÂÄ¿µÄ£¬ £¬£¬£¬£¬£¬£¬Í¹ÏÔ½¡Éí×·×ÙÆ÷´øÀ´µÄÒ»Á¬Òþ˽ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/189696/intelligence/french-aircraft-carrier-charles-de-gaulle-tracked-via-strava-activity-in-opsec-failure.html


2. NaviaÊý¾Ýй¶ӰÏì270ÍòÓû§Ãô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÃÀ¹ú¸£ÀûÖÎÃ÷È·¾ö¼Æ»®ÌṩÉÌNavia Benefit Solutions¿ËÈÕ֪ͨ½ü270ÍòÈË£¬ £¬£¬£¬£¬£¬£¬ÆäÃô¸ÐÐÅÏ¢ÔÚÊý¾Ýй¶ÊÂÎñÖб»¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÃÀ¹ú1Íò¶à¼Ò¹ÍÖ÷ÌṩÎÞа֧³öÕË»§£¨FSA£©¡¢¿µ½¡´¢±¸ÕË»§£¨HSA£©¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¡¢Í¨ÇÚ¸£ÀûºÍCOBRAЧÀ͵ȸ£ÀûÖÎÀíЧÀÍ¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2025Äê12ÔÂ22ÈÕÖÁ2026Äê1ÔÂ15ÈÕʱ´úÄܹ»»á¼û¸Ã¹«Ë¾ÏµÍ³£¬ £¬£¬£¬£¬£¬£¬¹«Ë¾ÓÚ1ÔÂ23ÈÕ·¢Ã÷¿ÉÒɻ¡£¡£¡£¡£¡£¡£¡£NaviaÌåÏÖÁ¬Ã¦×ö³öÏìÓ¦²¢Æô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñµÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÈ·¶¨Î´¾­ÊÚȨµÄÐÐΪÕßÔÚÉÏÊöʱ´ú»á¼û²¢»ñÈ¡ÁËÌØ¶¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±»»á¼ûºÍ¿ÉÄÜÍâйµÄÊý¾ÝÀàÐͰüÀ¨£ºÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¿µ½¡±¨Ïú°²ÅÅ£¨HRA£©¼ÓÈëÐÅÏ¢¡¢ÎÞа֧³öÕË»§£¨FSA£©ÐÅÏ¢¡¢×ÛºÏOmnibusÔ¤ËãЭµ÷·¨°¸£¨COBRA£©×¢²áÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷Êý¾Ýй¶δ̻¶Ë÷ÅâÏêÇé»ò²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬ £¬£¬£¬£¬£¬£¬Ì»Â¶µÄÊý¾Ý×ãÒÔʹÍþвÐÐΪÕßÕë¶ÔÊÜÓ°ÏìСÎÒ˽¼Ò°²ÅÅ´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/


3. Speagle¶ñÒâÈí¼þÐ®ÖÆCobra DocGuardÇÔÈ¡Êý¾Ý


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷ÃûΪSpeagleµÄÐÂÐͶñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬¸ÃÈí¼þÐ®ÖÆÕýµ±³ÌÐòCobraDocGuardµÄ¹¦Ð§ºÍ»ù´¡ÉèÊ©¾ÙÐÐÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£CobraDocGuardÊÇÓÉEsafeNet¿ª·¢µÄÎĵµÇå¾²ºÍ¼ÓÃÜÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪRunningcrab£¬ £¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ¹éÒò¡£¡£¡£¡£¡£¡£¡£SpeagleÖ¼ÔÚÉñÃØÍøÂçÊÜѬȾÅÌËã»úµÄÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬²¢½«Æä´«ÊäÖÁ±»¹¥»÷Õß¹¥ÏݵÄCobraDocGuardЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬£¬½«Êý¾ÝÍâйÀú³Ìαװ³É¿Í»§¶ËÓëЧÀÍÆ÷Ö®¼äµÄÕýµ±Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶Ô×°ÖÃÁËCobraDocGuardÊý¾Ý±£»£»£»£»£»£»¤Èí¼þµÄϵͳ£¬ £¬£¬£¬£¬£¬£¬Åú×¢¹¥»÷Õß¿ÉÄÜÓÐÒâÕë¶ÔÌØ¶¨×éÖ¯¾ÙÐÐÇé±¨ÍøÂç»ò¹¤ÒµÌع¤»î¶¯¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪÕâ×îÓпÉÄÜÊǹú¼ÒÖ§³ÖµÄÐÐΪÕß»ò¿É¹ÍÓ¶µÄ˽Ӫ³Ð°üÉÌËùΪ¡£¡£¡£¡£¡£¡£¡£SpeagleΪ32λ.NET¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬£¬£¬£¬Æô¶¯ºóÊ×Ïȼì²éCobraDocGuard×°ÖÃÎļþ¼Ð£¬ £¬£¬£¬£¬£¬£¬È»ºó·Ö½×¶ÎÍøÂç²¢´«ÊäÊÜѬȾ»úеµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬°üÀ¨ÏµÍ³ÏêÇéºÍÌØ¶¨Îļþ¼ÐÖеÄÎļþ£¬ £¬£¬£¬£¬£¬£¬Èç°üÀ¨ÍøÒ³ä¯ÀÀÆ÷ÀúÊ·ºÍ×Ô¶¯Ìî³äÊý¾ÝµÄÎļþ¼Ð¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2026/03/speagle-malware-hijacks-cobra-docguard.html


4. Magento PolyShellÎó²îÔÊÐíδÊÚȨ´úÂëÖ´ÐÐ


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬µç×ÓÉÌÎñÇå¾²¹«Ë¾Sansec¿ËÈÕÅû¶ÃûΪ"PolyShell"µÄÐÂÎó²î£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìËùÓÐMagentoOpenSourceºÍAdobeCommerceÎȹ̰æ2.4.9×°Ö㬠£¬£¬£¬£¬£¬£¬ÔÊÐíδÊÚȨ¹¥»÷ÕßÖ´ÐдúÂëºÍ½ÓÊÜÕË»§¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐδ·¢Ã÷¸ÃÎó²îÔÚÒ°Íâ±»Æð¾¢Ê¹Óõļ£Ïó£¬ £¬£¬£¬£¬£¬£¬µ«SansecÖÒÑÔʹÓÃÒªÁìÒÑÔÚÈö²¥£¬ £¬£¬£¬£¬£¬£¬Ô¤¼Æ×Ô¶¯»¯¹¥»÷¼´½«×îÏÈ¡£¡£¡£¡£¡£¡£¡£¸ÃÇå¾²ÎÊÌâÔ´ÓÚMagentoµÄRESTAPI½ÓÊÜÎļþÉÏ´«×÷Ϊ¹ºÎï³µÏîÄ¿×Ô½ç˵ѡÏîµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£µ±²úÆ·Ñ¡ÏîÀàÐÍΪ"Îļþ"ʱ£¬ £¬£¬£¬£¬£¬£¬Magento»á´¦Öóͷ£Ç¶ÈëµÄfile_info¹¤¾ß£¬ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨base64±àÂëµÄÎļþÊý¾Ý¡¢MIMEÀàÐͺÍÎļþÃû¡£¡£¡£¡£¡£¡£¡£Îļþ±»Ð´ÈëЧÀÍÆ÷ÉϵÄpub/media/custom_options/quote/Ŀ¼¡£¡£¡£¡£¡£¡£¡£"PolyShell"Ãû³ÆÔ´ÓÚÆäʹÓöà̬Îļþ£¬ £¬£¬£¬£¬£¬£¬¸ÃÎļþ¿Éͬʱ×÷ΪͼÏñºÍ¾ç±¾ÔËÐС£¡£¡£¡£¡£¡£¡£Æ¾Ö¤WebЧÀÍÆ÷ÉèÖ㬠£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿Éͨ¹ýÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©»ò´æ´¢ÐÍ¿çÕ¾¾ç±¾£¨XSS£©ÊµÏÖÕË»§½ÓÊÜ£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìSansecÆÊÎöµÄ´ó´ó¶¼ÊÐËÁ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÊÓ²ìÁËËùÓÐÒÑÖªµÄMagentoºÍAdobeCommerceÊÐËÁ£¬ £¬£¬£¬£¬£¬£¬·¢Ã÷Ðí¶àÊÐËÁ̻¶ÁËÉÏ´«Ä¿Â¼ÖеÄÎļþ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/


5. BitrefillÔ⳯ÏÊBluenoroffºÚ¿Í×éÖ¯¹¥»÷


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬¼ÓÃÜÇ®±ÒÀñÎ│ÊÐËÁBitrefill¿ËÈÕÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬Ô³õÔâÊܵĹ¥»÷ºÜ¿ÉÄÜÓɳ¯ÏÊBluenoroffºÚ¿Í×é֯ʵÑé¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìʱ´ú£¬ £¬£¬£¬£¬£¬£¬¸Ãƽ̨ÊӲ쵽Óë֮ǰ¹éÒòÓÚ³¯ÏÊÍþвÐÐΪÕߵĹ¥»÷ÏàËÆµÄÖ¸±ê£¬ £¬£¬£¬£¬£¬£¬°üÀ¨Õ½Êõ¡¢¶ñÒâÈí¼þ¡¢IPºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¡£¡£BitrefillÊÇÒ»¼ÒÖÐÐ͵ç×ÓÉÌÎñƽ̨£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÓû§Ê¹ÓüÓÃÜÇ®±ÒÔÚ150¸ö¹ú¼ÒµÄÊÐËÁ¹ºÖÃÀñÎ│¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÈ«Çò600¶à¼ÒÒÆ¶¯ÔËÓªÉ̺ÍÊýǧ¸öÆ·ÅÆ¡£¡£¡£¡£¡£¡£¡£3ÔÂ1ÈÕ£¬ £¬£¬£¬£¬£¬£¬BitrefillÐû²¼ÍøÕ¾ºÍÓ¦Óûá¼û·ºÆðÊÖÒÕÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Ô½ÈÕ£¬ £¬£¬£¬£¬£¬£¬¹«Ë¾Åû¶·¢Ã÷Çå¾²ÎÊÌâ²¢½«ËùÓÐЧÀÍÏÂÏß¡£¡£¡£¡£¡£¡£¡£ÊӲ췢Ã÷£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Ô´ÓÚ±»¹¥ÏݵÄÔ±¹¤Ìõ¼Ç±¾µçÄÔ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÇÔÈ¡ÁË¾É°æÆ¾Ö¤£¬ £¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÕâЩƾ֤»á¼û°üÀ¨Éú²úÃÜÔ¿µÄ¿ìÕÕ£¬ £¬£¬£¬£¬£¬£¬Ëæºó½«»á¼ûȨÏÞÉý¼¶ÖÁBitrefill¸ü´óµÄ»ù´¡ÉèÊ©£¬ £¬£¬£¬£¬£¬£¬°üÀ¨²¿·ÖÊý¾Ý¿âºÍһЩ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±»·¢Ã÷ÊÇÓÉÓÚBitrefill×¢ÖØµ½¿ÉÒɵũӦÉ̲ɹºÄ£Ê½¡¢ÀñÎ│¿â´æºÍ¹©Ó¦Á´±»Ê¹Ó㬠£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò»Ð©"ÈÈ"Ç®°ü±»ÌͿա£¡£¡£¡£¡£¡£¡£Ô¼18,500Ìõ¹ºÖüͼÔÚй¶Öб»Ì»Â¶£¬ £¬£¬£¬£¬£¬£¬°üÀ¨¿Í»§µç×ÓÓʼþµØµã¡¢IPµØµãºÍ¼ÓÃÜÇ®±ÒÖ§¸¶µØµã¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ1,000Ìõ¹ºÖüͼµÄ¿Í»§ÐÕÃûÒ²±»Ì»Â¶¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÐÅÏ¢ÒÔ¼ÓÃÜÐÎʽ´æ´¢£¬ £¬£¬£¬£¬£¬£¬BitrefillÖ¸³ö¹¥»÷Õß¿ÉÄÜÒÑ»ñµÃ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bitrefill-blames-north-korean-lazarus-group-for-cyberattack/


6. Perseus°²×¿¶ñÒâÈí¼þÇÔÈ¡Óû§Ìõ¼ÇÃô¸ÐÐÅÏ¢


3ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬Òƶ¯Çå¾²¹«Ë¾ThreatFabric¿ËÈÕ·¢Ã÷ÃûΪPerseusµÄÐÂÐͰ²×¿¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬¸ÃÈí¼þרÃżì²éÓû§½¨ÉèµÄÌõ¼ÇÒÔÇÔÈ¡ÃÜÂë¡¢»Ö¸´¶ÌÓï»ò²ÆÎñÊý¾ÝµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÍþвÇ÷ÊÆÔÚÒÑÍù°Ë¸öÔ·ºÆð£¬ £¬£¬£¬£¬£¬£¬Óû§×·ÇóÃâ·Ñ»òµÍ±¾Ç®·½·¨Ô¢Ä¿ÌåÓýÖ±²¥¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃIPTVÓ¦ÓÃÓÕ¶ü·Ö·¢¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¿îÈö²¥¶ñÒâÈí¼þµÄÓ¦ÓÃÃûΪRojadirectaTV£¬ £¬£¬£¬£¬£¬£¬ÊÇÊ¢ÐеÄÌåÓýÁ÷ýÌåЧÀÍ¡£¡£¡£¡£¡£¡£¡£PerseusµÄ¼ÓÔØÆ÷¿ÉÈÆ¹ý°²×¿13¼°ÒÔÉϰ汾µÄ²àÔØÏÞÖÆ£¬ £¬£¬£¬£¬£¬£¬Óë·Ö·¢KlopatraºÍMedusa¶ñÒâÈí¼þµÄ¼ÓÔØÆ÷Ïàͬ¡£¡£¡£¡£¡£¡£¡£PerseusÖ÷ÒªÕë¶ÔÍÁ¶úÆäºÍÒâ´óÀûµÄ½ðÈÚ»ú¹¹ÒÔ¼°¼ÓÃÜÇ®±ÒЧÀÍ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÀÄÓð²×¿¸¨Öú¹¦Ð§£¬ £¬£¬£¬£¬£¬£¬Perseus¸¶Óë²Ù×÷ÕßÍêȫԶ³Ì¿ØÖÆÈ¨ÏÞ£¬ £¬£¬£¬£¬£¬£¬¿ÉÒ»Á¬½ØÈ¡ÆÁÄ»½ØÍ¼²¢´®Á÷ÖÁ²Ù×÷¶Ë¡¢Ä£Äâµã»÷ºÍ»¬¶¯¡¢¿ªÆô»ò×èÖ¹Ó¦Óá¢ÆôÓÃºÚÆÁÁýÕÖÒþ²Ø»î¶¯¡¢ÊµÑéÁýÕÖ¹¥»÷ºÍ¼üÅ̼ͼ¡£¡£¡£¡£¡£¡£¡£PerseusµÄ²»Ñ°³£¹¦Ð§ÊÇÕë¶Ô°²×¿Ìõ¼ÇÓ¦Ó㬠£¬£¬£¬£¬£¬£¬ÕâÊÇÊ״η¢Ã÷°²×¿¶ñÒâÈí¼þ¼ì²é×°±¸Ð¡ÎÒ˽¼ÒÌõ¼ÇÖеÄÃô¸ÐÏêÇé¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-perseus-android-malware-checks-user-notes-for-secrets/