˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î
Ðû²¼Ê±¼ä 2026-03-051. ˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î
3ÔÂ4ÈÕ£¬£¬£¬Ë¼¿Æ¹«Ë¾¿ËÈÕÐÞ¸´ÁËÆäÇå¾²·À»ðǽÖÎÀíÖÐÐÄ£¨FMC£©ÖÐÁ½¸ö×î¸ß¼¶±ð£¨CVSSÆÀ·Ö¾ùΪ10.0£©µÄÑÏÖØÎó²î£¬£¬£¬ÕâÁ½¸öÎó²îÈô±»Ê¹ÓÿÉÄܵ¼Ö¹¥»÷ÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£µÚÒ»¸öÎó²î±àºÅΪCVE-2026-20079£¬£¬£¬ÊôÓÚÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚFMCÆô¶¯Ê±½¨ÉèµÄϵͳÀú³Ì±£´æÈ±ÏÝ£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬ÈƹýWeb½çÃæµÄÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬Ö±½ÓÖ´Ðо籾Îļþ²¢»ñÈ¡µ×²ã²Ù×÷ϵͳµÄrootȨÏÞ¡£¡£¡£µÚ¶þ¸öÎó²î±àºÅΪCVE-2026-20131£¬£¬£¬ÎªÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Í¬Ê±Ó°ÏìFMC¼°Ë¼¿ÆÇå¾²ÔÆ¿ØÖÆ£¨SCC£©·À»ðǽÖÎÀí¹¦Ð§¡£¡£¡£¸ÃÎó²îÓɲ»Çå¾²µÄJava·´ÐòÁл¯²Ù×÷Òý·¢£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÏòWebÖÎÀí½çÃæ·¢ËͶñÒâÐòÁл¯Java¹¤¾ß£¬£¬£¬´¥·¢·´ÐòÁл¯Àú³Ì²¢ÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ£¬£¬£¬ÏÖÔÚÉÐδ·¢Ã÷ÕâÁ½¸öÎó²î±»¹ûÕæÅû¶»òÏÖʵʹÓõļ£Ï󡣡£¡£µ«¼øÓÚÎó²îµÄ¸ßΣÐÔ×Ó£¬£¬£¬Ë¼¿ÆÇ¿µ÷±ØÐèͨ¹ý¹Ù·½²¹¶¡¾ÙÐÐÐÞ¸´£¬£¬£¬Ä¿½ñÎÞÈκÎÔÝʱ½â¾ö¼Æ»®»ò±äͨҪÁì¡£¡£¡£
https://securityaffairs.com/188921/security/cisco-fixes-maximum-severity-secure-fmc-bugs-threatening-firewall-security.html
2. FreeScoutЧÀĮ́ƽ̨ÏÖÁãµã»÷¸ßΣRCEÎó²î
3ÔÂ4ÈÕ£¬£¬£¬FreeScout¿ªÔ´×ÊÖų́ƽ̨¿ËÈÕ±»ÆØ±£´æ×î¸ß¼¶±ðÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28289£©£¬£¬£¬¹¥»÷ÕßÎÞÐèÓû§½»»¥»òÉí·ÝÑéÖ¤¼´¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ¸½¼þʵÏÖÁãµã»÷¹¥»÷£¬£¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¸ÃÎó²îÈÆ¹ýÁË´ËǰCVE-2026-27636Îó²îµÄÐÞ¸´»úÖÆ£¬£¬£¬ÔÐÞ¸´Í¨¹ýÏÞÖÆÎļþÀ©Õ¹Ãû×èֹΣÏÕÉÏ´«£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ÔÚÎļþÃûǰÌí¼ÓÁã¿í¶È¿Õ¸ñ×Ö·û¿ÉÈÆ¹ýÑéÖ¤¡£¡£¡£¸Ã×Ö·û±»ÊÓΪ²»¿É¼ûÄÚÈÝ£¬£¬£¬ºóÐø´¦Öóͷ£»áɾ³ý¸Ã×Ö·û£¬£¬£¬Ê¹ÎļþÉúÑÄΪµãÎļþ£¬£¬£¬´Ó¶ø´¥·¢ÔÎó²îʹÓᣡ£¡£FreeScout×÷ΪZendesk/Help ScoutµÄ×ÔÍйÜÌæ»»¼Æ»®£¬£¬£¬ÊÇÆÕ±éʹÓõĿªÔ´Æ½Ì¨£¬£¬£¬GitHub¿ÍÕ»ÓµÓÐ4100ÐDZꡢ620+·ÖÖ§£¬£¬£¬ShodanɨÃèÏÔʾ³¬1100¸ö¹ûÕæÌ»Â¶ÊµÀý¡£¡£¡£Îó²îÓ°ÏìËùÓÐ1.8.206¼°¸üÔç°æ±¾£¬£¬£¬¿Éͨ¹ý·¢ËÍÖÁFreeScoutÉèÖÃÓÊÏäµÄ¶ñÒ⸽¼þ´¥·¢£¬£¬£¬¹¥»÷Õßͨ¹ýWeb½çÃæ»á¼ûÓÐÓÃÔØºÉ¼´¿ÉÖ´ÐÐÏÂÁ£¬£¬×é³ÉÁãµã»÷Îó²î¡£¡£¡£FreeScoutÍŶӽ¨ÒéÁ¬Ã¦Éý¼¶ÖÁ1.8.207°æ±¾£¬£¬£¬Í¬Ê±OX ResearchÔö²¹½¨Òé½ûÓÃApacheÉèÖÃÖеġ°AllowOverrideAll¡±ÒÔÔöÇ¿·À»¤¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/
3. ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPassÔâÍøÂç´¹ÂÚ¹¥»÷
3ÔÂ4ÈÕ£¬£¬£¬ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPass¿ËÈÕ·¢³öÇå¾²ÖÒÑÔ£¬£¬£¬Ö¸³öÆäÓû§ÕýÔâÊÜÐÂÒ»Âָ߷ÂÕæÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì"LastPassÖ§³Ö"ÏÔʾÃû³ÆµÄµç×ÓÓʼþ£¬£¬£¬Ä£Äâ¹Ù·½Óë¿Í»§Ö§³ÖÍŶӵÄÄÚ²¿¶Ô»°³¡¾°£¬£¬£¬ÓÕµ¼Óû§µã»÷"±¨¸æ¿ÉÒɻ""×÷·Ï×°±¸"µÈαװÁ´½Ó¡£¡£¡£ÕâЩÓʼþÖ÷ÌâÈ«ÐÄÉè¼Æ£¬£¬£¬°üÀ¨"¸ü¸ÄÕË»§Ö÷ÒªÓÊÏäÇëÇó"µÈ¿´Ëƹٷ½µÄת·¢¶Ô»°ÄÚÈÝ£¬£¬£¬ÖÆÔì½ôÆÈÆø·Õ´ÙʹÓû§¿ìËÙÏìÓ¦¡£¡£¡£µã»÷Á´½Óºó£¬£¬£¬Óû§»á±»Öض¨ÏòÖÁ"verify-lastpass[.]com"µÈÓòÃûϵÄÐéαµÇÂ¼Ò³Ãæ¡£¡£¡£¸ÃÒ³ÃæÓë¹Ù·½½çÃæ¸ß¶ÈÏàËÆ£¬£¬£¬×¨ÃÅÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤¡£¡£¡£¹¥»÷Õß»¹Í¨¹ý¶à¸ö·¢¼þÈ˵صãºÍÖ÷ÌâÐбäÌåÔöÇ¿¿ÉÐŶȣ¬£¬£¬´ó¶¼·¢¼þµØµãÀ´×Ô±»ÈëÇÖÍøÕ¾»ò·ÅÆúÓòÃû£¬£¬£¬½öͨ¹ýÏÔʾÃû³ÆÎ±×°³É¹Ù·½¡£¡£¡£LastPassÔÚÍþвÇ鱨±¨¸æÖÐÇ¿µ÷£¬£¬£¬Æä»ù´¡ÉèʩδÊÜÈκÎË𺦣¬£¬£¬ÏµÍ³Ç徲δÊÜÓ°Ïì¡£¡£¡£¹«Ë¾Ã÷È·ÌáÐÑÓû§£º¹Ù·½¿Í·þ¾ø²»»áË÷ÒªÖ÷ÃÜÂ룬£¬£¬Óû§Ó¦ÑϿᱣÃÜÖ÷ÃÜÂë¡£¡£¡£Õë¶Ô´Ë´Î¹¥»÷£¬£¬£¬LastPassÕýÁªºÏµÚÈý·½ÏàÖúͬ°é½ôÆÈ¹Ø±Õ´¹ÂÚÍøÕ¾£¬£¬£¬²¢ºôÓõÓû§½«¿ÉÒÉͨѶ¾Ù±¨ÖÁ"mailto:abuse@lastpass.com"¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-lastpass-support-email-threads-try-to-steal-vault-passwords/
4. HungerRushÔâÀÕË÷¹¥»÷£¬£¬£¬¿Í»§Êý¾ÝÃæÁÙÍþв
3ÔÂ4ÈÕ£¬£¬£¬²ÍÒûÊÖÒÕÌṩÉÌHungerRush¿ËÈÕÔâÓöÀÕË÷¹¥»÷£¬£¬£¬ÍþвÐÐΪÕßͨ¹ýαÔì¹Ù·½ÓÊÏäÏò²ÍÌüÖ÷¹Ë·¢ËͶà·âÀÕË÷Óʼþ£¬£¬£¬Éù³ÆÈô²»»ØÓ¦½«Ð¹Â¶Êý°ÙÍò¿Í»§Êý¾Ý¡£¡£¡£ÕâЩÓʼþͨ¹ýTwilio SendGridƽ̨·¢ËÍ£¬£¬£¬¸ÃЧÀÍ´ËǰÓÃÓÚ·¢ËÍHungerRush²ÍÌüÊÕÌõ£¬£¬£¬ÇÒͨ¹ýÁËSPF¡¢DKIMºÍDMARCÉí·ÝÑéÖ¤£¬£¬£¬ÔöÇ¿ÁËÓʼþ¿ÉÐŶȡ£¡£¡£¹¥»÷ÕßʹÓÃmailto:support@hungerrush.comºÍmailto:2019@hungerrush.comµÈµØµã£¬£¬£¬ÖÒÑÔHungerRush×èÖ¹ºöÊÓÀÕË÷ÒªÇ󣬣¬£¬²»È»½«Î£¼°¿Í»§Êý¾Ý¡£¡£¡£HungerRushЧÀÍÓÚÁè¼Ý16,000¼Ò²ÍÌü£¬£¬£¬°üÀ¨Sbarro¡¢Jet's PizzaµÈ×ÅÃûÆ·ÅÆ£¬£¬£¬ÆäPOS¡¢ÔÚÏß¶©¹º¼°Ö§¸¶´¦Öóͷ£ÏµÍ³±»ÆÕ±éʹÓᣡ£¡£¹¥»÷ÕßÐû³Æ¿É»á¼û¿Í»§ÐÕÃû¡¢ÓÊÏä¡¢ÃÜÂë¡¢µØµã¡¢µç»°¡¢³öÉúÈÕÆÚ¼°ÐÅÓÿ¨ÐÅÏ¢£¬£¬£¬µ«HungerRush»ØÓ¦³Æ£¬£¬£¬´Ë´ÎÊÂÎñ½öÉæ¼°µç×ÓÓʼþÓªÏúЧÀÍÕË»§±»ÈëÇÖ£¬£¬£¬Î´Ð¹Â¶Ãô¸ÐÐÅÏ¢ÈçÃÜÂë¡¢Ö§¸¶¿¨Êý¾Ý£¬£¬£¬ÇÒÆäϵͳ²»´æ´¢ÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¹«Ë¾Ç¿µ÷£¬£¬£¬Ð¹Â¶µÄ¿Í»§ÁªÏµÐÅÏ¢±»ÓÃÓÚ·¢ËÍδ¾ÊÚȨÓʼþ£¬£¬£¬µ«ÎÞÖ¤¾ÝÏÔʾÆäËûϵͳÔâÈëÇÖ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/
5. ¹ú¼ÊÁªºÏÐж¯²é·âLeakBaseÍøÂç·¸·¨ÂÛ̳
3ÔÂ4ÈÕ£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÁªºÏÅ·ÖÞÐ̾¯×éÖ¯µÈ14¹úÖ´·¨»ú¹¹£¬£¬£¬ÓÚ3ÔÂ3ÈÕÖÁ4ÈÕ¿ªÕ¹"йÃÜÐж¯"£¬£¬£¬Àֳɲé·âÍøÂç·¸·¨ÂÛ̳LeakBase¡£¡£¡£¸ÃÂÛ̳×÷ΪºÚ¿Í¹¤¾ßÉúÒâ¡¢±»µÁÊý¾ÝÉúÒâµÄ½¹µãƽ̨£¬£¬£¬×Ô2021ÄêÓÉARESÍþв×éÖ¯Ö§³ÖÔËÓªÒÔÀ´£¬£¬£¬Óû§¹æÄ£Òѳ¬14.2Íò£¬£¬£¬ÌṩÊý¾Ý¿â»á¼û¡¢Îó²îʹÓÃÉúÒâ¡¢µ£±£Ö§¸¶ÏµÍ³¼°ºÚ¿ÍÊÖÒÕÌÖÂÛÇø£¬£¬£¬º¸ÇÉç»á¹¤³Ìѧ¡¢ÃÜÂëѧµÈרÌâ¡£¡£¡£Ðж¯Ê±´ú£¬£¬£¬Ö´·¨Ö°Ô±ÔÚÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢±ÈÀûʱµÈ8¹úÖ´ÐÐËѲéÁʵÑé¾Ð²¶²¢¿ªÕ¹"ÇÃÃÅ̸»°"£¬£¬£¬È«Çò¹²ÌᳫԼ100´ÎÖ´·¨Ðж¯£¬£¬£¬´¦·Ö37Ãû×î»îÔ¾Óû§¡£¡£¡£LeakBaseµÄÁ½¸öÓòÃûÏÖÒѱ»FBI½ÓÊÜ£¬£¬£¬ÓòÃûЧÀÍÆ÷Çл»Îªns1.fbi.seized.govºÍns2.fbi.seized.gov£¬£¬£¬Ò³ÃæÏÔʾ²é·â֪ͨ£¬£¬£¬Ç¿µ÷ÂÛ̳ËùÓÐÄÚÈݰüÀ¨Óû§ÕË»§¡¢Ìû×Ó¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Ë½Ðż°IPÈÕÖ¾Òѱ»Çå¾²ÉúÑÄ£¬£¬£¬½«ÓÃÓÚºóÐøÈ¡Ö¤ÊӲ졣¡£¡£ÈκÎÊÔͼ»á¼û»ò×ÌÈÅÍøÕ¾µÄÐÐΪ¿ÉÄÜ×é³ÉÐÂ×ï¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fbi-seizes-leakbase-cybercrime-forum-data-of-142-000-members/
6. ŦԼÂóµÏÑ·¹ã³¡»¨Ô°ÔâCl0pÀÕË÷¹¥»÷
3ÔÂ3ÈÕ£¬£¬£¬Å¦Ô¼µØ±êÂóµÏÑ·¹ã³¡»¨Ô°£¨MSG£©¿ËÈÕÈ·ÈÏÔâÓöÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬Éæ¼°2025ÄêÕë¶Ô¼×¹ÇÎĵç×ÓÉÌÎñÌ×¼þ£¨EBS£©µÄ´ó¹æÄ£ÍøÂç·¸·¨»î¶¯¡£¡£¡£×÷ΪȫÇòÖøÃû¶à¹¦Ð§ÊÒÄÚ³¡¹Ý£¬£¬£¬MSGλÓÚŦԼÊУ¬£¬£¬ÊÇNBAÄá¿Ë˹¶ÓºÍNHLÓÎÆï±ø¶ÓÖ÷³¡£¬£¬£¬³Ð°ìÌåÓýÈüÊ¡¢Ñݳª»á¼°ÓéÀֻ£¬£¬£¬´Ë´ÎÊÂÎñʹÆä³ÉΪʹÓü׹ÇÎÄEBSÎó²îʵÑéºÚ¿Í¹¥»÷µÄÖÚ¶àÊܺ¦×éÖ¯Ö®Ò»¡£¡£¡£2025Äê11Ô£¬£¬£¬Cl0pÀÕË÷Èí¼þ×é֯ʹÓü׹ÇÎÄEBSÖеÄÁãÈÕÎó²îCVE-2025-61882ÈëÇÖ°üÀ¨MSGÔÚÄÚµÄ100¶à¼Ò»ú¹¹¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ØÖƼ׹ÇÎIJ¢·¢´¦Öóͷ£×é¼þ£¬£¬£¬½ø¶øÇÔÈ¡Êý¾Ý¡£¡£¡£MSG¾Ü¾øÖ§¸¶Êê½ðºó£¬£¬£¬Cl0pй¶³¬210GB¹«Ë¾´æµµÎļþ¡£¡£¡£¾ÝMSGÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬£¬£¬¼×¹ÇÎÄEBSÓɹ©Ó¦ÉÌÍйÜÖÎÀí£¬£¬£¬ÓÃÓÚ²¿·ÖÈËÁ¦ºÍ²ÆÎñÔËÓª¡£¡£¡£¹©Ó¦ÉÌÊÓ²ìÈ·¶¨£¬£¬£¬Î´¾ÊÚȨÕßÓÚ2025Äê8Ô»ñÈ¡²¿·ÖÓ¦ÓÃÊý¾Ý£¬£¬£¬Éæ¼°ÕÐÆ¸»ò¸¶¿îÏà¹ØµÄÓªÒµ¼Í¼Îļþ£¬£¬£¬ÆäÖаüÀ¨ÐÕÃûºÍÉç»á°ü¹ÜºÅµÄÎļþÊÜÓ°Ïì¡£¡£¡£¼×¹ÇÎÄÒÑÓÚ2025Äê10ÔÂÐû²¼½ôÆÈ²¹¶¡ÐÞ¸´¸ÃÎó²î£¬£¬£¬µ«´ËǰÒÑÓдó×ÚÊý¾Ýй¶¡£¡£¡£
https://securityaffairs.com/188814/cyber-crime/oracle-ebs-2025-campaign-impacts-madison-square-garden-sensitive-data-leaked.html


¾©¹«Íø°²±¸11010802024551ºÅ