ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾

°ä²¼¹¦·ò 2026-03-10

1. ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾


3ÔÂ6ÈÕ £¬ÃÀ¹úÐÂÔóÎ÷Öݱ±²¿ÅÁÈûÒÁ¿ËÏØÓÚ2026Äê3ÔÂ4ÈÕÍí¼ä°ä²¼´¹Î£²¼¸æ £¬È·ÈÏÔâ·ê¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂÈ«ÏØµ±²¿ÃÅÃÅITϵͳÓëµç»°ÏßÂ·È«ÃæÖжÏ ¡£¸ÃÏØÕý½áºÏÁª¹ú¼°Öݵ±¾Ö¹ÙԹع¿ªµ÷²é £¬ÊÔͼ½ÚÔìÊÂ̬²¢¸´Ô­·þÎñ ¡£Õâ´Î¹¥»÷ÊÂÎñʼÓÚ3ÔÂ4ÈÕÉÏÎç³õ´Î»ã±¨µÄµç»°Ïß·¹ÊÕÏ £¬¾­µ÷²éºóÓÚµ±ÈÕÏÂÎçÈ·ÒÔÎªÍøÂç¹¥»÷ËùÖ ¡£ÅÁÈûÒÁ¿ËÏØ¹ÙԱǿµ÷ £¬ÐÂÔóÎ÷ÖÝÄÚ¶à¸ö´¦Ëùµ±¾Ö½üÆÚ¾ùÔâ·êÀàËÆÍøÂç¹¥»÷ÊÂÎñ £¬¿ÉÄÜÉæ¼°´ËǰÔâÀÕË÷Èí¼þ¹¥»÷µÄÈøÄ¬ÈûÌØÏØ¡¢¿¨Ä·µÇÏØ¡¢²®¸ùÏØ¡¢ÃÉÌØ¿ËÀ³¶ûÕò¼°»ô²©¿ÏÊÐ ¡£ÅÁÈûÒÁ¿ËÏØÊÂÎñÔÙ´Î͹ÏÔ´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·À»¤·½ÃæµÄ´àÈõÐÔ ¡£·ÖÎöÖ¸³ö £¬ÖÐÓ×ÐÍ´¦Ëùµ±¾ÖÒò×ÊÔ´ÓÐÏÞ £¬ÍùÍù³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄ¡°ÈíÖ¸±ê¡± ¡£Ä¿Ç° £¬ÅÁÈûÒÁ¿ËÏØÉÐδÅû¶¹¥»÷¾ßÌåϸ½Ú¼°ÀÕË÷ÒªÇó £¬µ«Ç¿µ÷½«ÓÅÏȸ´Ô­¹«¹²·þÎñ²¢¹²Í¬·¨Âɲ¿ÃŲ龿¹¥»÷ÆðÔ´ ¡£


https://therecord.media/new-jersey-county-says-malware-attack-took-down-phones


2. Nginx UI¸ßΣ·ì϶Ö±¸·ÝÊý¾Ýй¶·çÏÕ


3ÔÂ8ÈÕ £¬Nginx UIÖÎÀí½çÃæÆØ³ö±àºÅΪCVE-2026-27944µÄÑϳÁ·ì϶£¨CVSSÆÀ·Ö9.8£© £¬¹¥»÷Õß¿Éδ¾­Éí·ÝÑéÖ¤ÏÂÔØ²¢½âÃÜ·þÎñÆ÷ÆëÈ«±¸·Ý £¬µ¼ÖÂÃô¸ÐÅäÖá¢Í´´¦¼°¼ÓÃÜÃÜԿй¶ ¡£¸Ã·ì϶ԴÓÚ/api/backup¶ËµãδִÐнӼû½ÚÔì £¬ÇÒÏìӦͷֱ½Ó¶³ö½âÃÜËùÐèµÄAES-256¼ÓÃÜÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿ £¬Ê¹¹¥»÷ÕßÄÜÖ±½Ó»ñÈ¡Ô̺¬Óû§Í´´¦¡¢»á»°ÁîÅÆ¡¢SSL˽Կ¡¢NginxÅäÖÃÎļþ¡¢Êý¾Ý¿âÏνÓÐÅÏ¢µÈÖ÷ÌâÊý¾ÝµÄ±¸·Ý°ü ¡£Nginx UI×÷Ϊ¼ò»¯·þÎñÆ÷ÖÎÀíµÄWeb½ÚÔìÃæ°å £¬±¾Ó¦Í¨¹ýͼÐλ¯½çÃæ½µµÍÅäÖÃÃż÷ £¬µ«Õâ´Î·ì϶¶³öÆäÉè¼ÆÈ±µã £¬ÖÎÀí½Ó¿Ú¶³öÓÚ¹«¹²»¥ÁªÍøÊ± £¬²»×ã¸ù»ùµÄ°²È«·À»¤ ¡£Ò»µ©±¸·Ý±»½âÃÜ £¬¹¥»÷Õß¿ÉÆëÈ«½ÚÔìÖÎÀí½çÃæ £¬´Û¸Ä·´Ïò´úÀí¹æ¶¨¡¢³Á¶¨ÏòÁ÷Á¿»òÖ²Èë¶ñÒâ¾ç±¾ £»SSL˽Կй¶½«µ¼ÖÂÍøÕ¾¼ÙÒâ»òÖÐÑëÈ˹¥»÷ £»Êý¾Ý¿âÍ´´¦ºÍÅäÖÃÎļþ¿ÉÄÜй¶Óû§Êý¾Ý¼°ÀûÓ÷¨Ê½»úÃÜ £»NginxÅäÖÃϸ½Ú¸ü»á¶³öÄÚ²¿ÍøÂç¼Ü¹¹ £¬ÎªºóÐø¹¥»÷Ìṩõè¾¶ ¡£Ä¿Ç° £¬Nginx¹Ù·½ÒѰ䲼½¨¸´°æ±¾ £¬Óû§Ó¦Á¢¼´Éý¼¶²¢Éó²é±¸·Ý´æ´¢Õ½Êõ £¬È·±£¼ÓÃÜÃÜÔ¿Ó뱸·Ý·ÖÀë´æ´¢ ¡£


https://securityaffairs.com/189123/security/critical-nginx-ui-flaw-cve-2026-27944-exposes-server-backups.html


3. ΢Èí¹¤¾ß³ÉºÚ¿ÍкóÃŹ¥»÷½ðÈÚÒ½ÁÆÔØÌå


3ÔÂ9ÈÕ £¬ÍøÂ簲ȫ¹«Ë¾BlueVoyant×îÐÂÅû¶ £¬Õë¶Ô¼ÓÄôó½ðÈÚ»ú¹¹¼°È«ÇòÒ½ÁƱ£½¡×éÖ¯µÄ¶¨Ïò¹¥»÷ÖÐ £¬ºÚ¿Íͨ¹ýÉç»á¹¤³Ìѧ¼¿Á©½áºÏ΢ÈíÉú̬¹¤¾ßÖ´ÐÐÐÂÐͶñÒâÈí¼þ²¿Êð ¡£¹¥»÷ÕßÊ×ÏÈÏòÖ¸±êÔ±¹¤·¢ËÍ´óÁ¿À¬»øÓʼþ³ÉÁ¢ÐÅÀµ £¬Ëæºó¼Ù×°³ÉÆóÒµITÈËԱͨ¹ýMicrosoft TeamsÁªÏµÊܺ¦Õß £¬ÒÔЭÖú´¦ÖÃÀ¬»øÓʼþΪÓÉÓÕµ¼ÆäÆô¶¯Quick AssistÔ¶³Ì»á»° ¡£ÔÚ»ñȡԶ³Ì½Ó¼ûȨÏÞºó £¬¹¥»÷Õß²¿ÊðÔ̺¬Êý×ÖÊðÃûMSI×°Ö÷¨Ê½µÄ¶ñÒ⹤¾ß¼¯ ¡£ÕâЩMSIÎļþ¼Ù×°³ÉMicrosoft Teams×é¼þ¼°ºÏ·¨Windows¹¤¾ßCrossDeviceService £¬Í¨¹ýDLL²àÔØ¼¼Êõ½«¶ñÒâ¿âhostfxr.dll×¢ÈëºÏ·¨¶þ½øÔìÎļþ ¡£¸Ã¿â¼ÓÔØºó½âÃÜÄÚ´æÖеÄshellcode £¬ÀûÓÃCreateThreadº¯Êý´´½¨´óÁ¿Ïß³Ì×ÌÈŵ÷ÊÔÆ÷·ÖÎö £¬Í¬Ê±Ö´ÐÐɳÏä¼ì²âÒÔ¶ã±ÜÐé¹¹»·¾³ ¡£¶ñÒâÈí¼þͨ¹ýSHA-256ÅÉÉúÃÜÔ¿½âÃܳöA0Backdoor £¬¸ÃºóÃÅѡȡAES¼ÓÃܱ £»¤Ö÷Ìâ´úÂë £¬²¢Ç¨áãÖÁÐÂÄÚ´æÇøÓòÖ´ÐÐ ¡£Æäͨ¹ýDeviceIoControl¡¢GetUserNameExWµÈWindows APIÍøÂçÖ÷»úÐÅÏ¢ £¬ÊµÏÖÖ÷»úÖ¸ÎÆ¼ø±ð ¡£ÓëºÅÁî½ÚÔì·þÎñÆ÷£¨C2£©µÄͨѶ°µ²ØÔÚDNSÁ÷Á¿ÖÐ ¡£


https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/


4. ¶íºÚ¿ÍÀûÓÃSignal/WhatsApp´¹µö¹¥»÷µ±¾Ö¾ü·½¼ÇÕß


3ÔÂ9ÈÕ £¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Õýͨ¹ýÕë¶ÔSignalºÍWhatsAppµÄÍøÂç´¹µö»î¶¯ £¬¶Ôµ±¾Ö¹ÙÔ±¡¢¾ü·½ÈËÔ±¼°¼ÇÕßÌáÒ鶨Ïò¹¥»÷ £¬Ö¼ÔÚÇÔÈ¡Ãô¸ÐÐÅÏ¢ ¡£ºÉÀ¼¹ú·Àµý±¨Ó밲ȫ¾Ö£¨MIVD£©Óë×ܵý±¨Ó밲ȫ¾Ö£¨AIVD£©½áºÏ»ã±¨Ö¤Êµ £¬ºÉÀ¼µ±¾Ö¹ÍÔ±ÒѳÉΪϮ»÷Ö¸±ê £¬¹¥»÷Ñ¡È¡ÍøÂç´¹µöÓëÉç»á¹¤³Ì¼¼Êõ £¬ÀÄÓúϷ¨Éí·ÝÑéÖ¤Ö°ÄÜÊÕÊÜÕË»§²¢¼à¿ØÐÂÎÅ ¡£Signal¹Ù·½°ä²¼ÖÒ¸æÖ¸³ö £¬¹¥»÷ͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µö»î¶¯ÓÕÆ­Óû§Ð¹Â¶¶ÌÐÅÑéÖ¤Âë»òPINÂë £¬µ¼ÖÂÕË»§±»µÁ ¡£Ö»¹ÜSignalµÄ¼ÓÃÜϵͳδ±»·ÛËé £¬µ«¹¥»÷Õß¿ÉÀûÓÃÑéÖ¤ÂëÔÚ×ÔÉíÉ豸ע²áÕË»§ £¬ÆëÈ«½ÚÔìÓû§Õ˺Å £¬ÉõÖÁ½«¹ØÁªµç»°ºÅÂë¸ü¸ÄΪ¼º·½½ÚÔì £¬´Ó¶ø½Ó¼ûÁªÏµÈËÁÐ±í¡¢ÈºÁÄÐÂÎÅ £¬²¢¼ÙÒâÊܺ¦Õß·¢ËÍÐÂÎÅ ¡£Ò»ÖÖµäÐÍÊÖ·¨ÊǼÙÒâ¡°Signal°²È«Ö§³Ö̸Ìì»úеÈË¡± £¬»Ñ³Æ¼ì²âµ½ÕË»§¿ÉÒɻ £¬ÓÕµ¼Óû§Ê䶯ÊÖ»úÑéÖ¤ÂëʵÏÖ¡°ÑéÖ¤·¨Ê½¡± £»ÁíÒ»ÖÖÔòÊÇ·¢ËͶñÒâ¶þάÂë»òÁ´½Ó £¬¼Ù×°³ÉȺ×éÔ¼Çë»òÉ豸ÏνÓÒªÇó £¬Êܺ¦ÕßɨÃè»òµã»÷ºó £¬¹¥»÷ÕßÉ豸½«ÓëÕË»§¹ØÁª £¬ÊµÊ±½Ó¼û²¢Í¬²½ÐÂÎÅ ¡£


https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/


5. °®Á¢ÐÅÃÀ¹ú×Ó¹«Ë¾³¬4000ÃûÐÂÏçÓû§ÐÅÏ¢±»ÇÔ


3ÔÂ9ÈÕ £¬ÈðµäͨѶ¾ÞÍ·°®Á¢ÐŵÄÃÀ¹ú×Ó¹«Ë¾½üÈÕÅû¶һ·³Á´óÊý¾Ýй¶ÊÂÎñ ¡£¾ÝÆäÏò¼ÓÖݼ°µÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤Ìá½»µÄÎļþÏÔʾ £¬2025Äê4ÔÂ28ÈÕ £¬Ò»¼ÒΪ°®Á¢ÐÅ´æ´¢Ô±¹¤ºÍ¿Í»§Êý¾ÝµÄµÚÈý·½·þÎñÌṩÉ̼ì²âµ½Òì³£½Ó¼û £¬ËæºóÆô¶¯µ÷²é²¢Í¨ÖªÁª¹úµ÷²é¾Ö£¨FBI£© ¡£µ÷²éÈ·ÈÏ £¬2025Äê4ÔÂ17ÈÕÖÁ22ÈÕÆÚ¼ä £¬¹¥»÷Õßδ¾­ÊÚȨ½Ó¼û»ò»ñÈ¡Á˲¿ÃÅÎļþ £¬Éæ¼°ÐÕÃû¡¢µØÖ·¡¢Éç»á±£ÏÕºÅÂë¡¢¼ÝÕպ𢻤Õյȵ±¾ÖID¡¢ÒøÐÐÕ˺š¢ÐÅÓþ¿¨ÐÅÏ¢¡¢Ò½ÁƼͼ¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢ ¡£Õâ´ÎÊÂÎñÔڵ¿ËÈøË¹ÖÝÒÑÈ·ÈÏÓ°Ïì4,377ÈË £¬µ«È«ÇòÊÜÓ°Ïì×ÜÈËÊýÉÐδ¹«¿ª ¡£°®Á¢ÐÅÇ¿µ÷ £¬Ö»¹ÜÊý¾Ý±»ÇÔÈ¡ £¬Ä¿Ç°ÉÐδ·¢ÏÖÐÅÏ¢±»ÀÄÓõÄÖ¤¾Ý ¡£Îª± £»¤ÊÜÓ°ÏìÓû§ £¬¸Ã¹«Ë¾ÌṩΪÆÚÒ»ÄêµÄÃâ·ÑIDXÉí·Ý± £»¤·þÎñ £¬Ô̺¬ÐÅÓþ¼à¿Ø¡¢°µÍø¼à¿Ø¡¢Éí·Ý͵ÇÔ¸´Ô­Ö§³Ö¼°×î¸ß100ÍòÃÀÔªµÄڲƭËðʧÅâ³¥ £¬Óû§ÐèÔÚ2026Äê6ÔÂ9ÈÕǰע²á ¡£½ØÖÁĿǰ £¬ÎÞÈκÎÍøÂç·¸×ï×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü ¡£


https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/


6. FBI¾¯Ê¾¹ÙÔ±¼ÙÒâ´¹µö¹¥»÷ £¬µØÆ¤Ðí¿ÉÉêÇëÕß³ÉÖ¸±ê


3ÔÂ9ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼¹«¹²·þÎñ²¼¸æ £¬¸æ·¢·¸×ï·Ö×ÓÕýͨ¹ý¼ÙÒâÊÐÏØ¹æ»®ºÍ·ÖÇøÎ¯Ô±»á¹ÙÔ±Ö´ÐÐÍøÂç´¹µö¹¥»÷ £¬Ö¸±êËø¶¨ÉêÇëµØÆ¤Ê¹ÓÃÐí¿ÉÖ¤µÄÆóÒµ¼°Ó×ÎÒ ¡£¹¥»÷ÕßÀûÓù«¿ªÇþ·»ñÈ¡µÄÊܺ¦ÕßÐí¿ÉÖ¤ÐÅÏ¢¡¢·ÖÇøÉêÇë±àºÅ»ò·¿²úµØÖ·µÈϸ½Ú £¬Î±ÔìºÏ·¨ÓʼþÓÕµ¼Êܺ¦ÕßÖ§¸¶¡°Ðí¿ÉÖ¤ÓйØÓöȡ± £¬²¢ÒªÇóͨ¹ýµç»ã¡¢µã¶ÔµãÖ§¸¶»ò¼ÓÃÜÇ®±ÒʵÏÖÂòÂô £¬ÒÔ´ËÖ´ÐÐڲƭ ¡£FBIÖ¸³ö £¬´ËÀàȦÌ×´æÔÚ¶à³Á¿É¼ø±ðÌØµã£ºÓʼþͨ³£À´×Էǵ±¾ÖÓòÃû £¬¸½¼þÒªÇóÊÕ¼þÈËͨ¹ýÓʼþË÷È¡¸ü¶àϸ½Ú £¬ÇÒ³£°éËæ¡°¼Ó¿ì¸¶¿îÒÔÔ¤·ÀÐí¿ÉÖ¤ÑÓÎ󡱵ȶ½´ÙÕ½Êõ ¡£Ú¿Æ­·Ö×Ó»¹»á¿ÌÒâÑ¡ÔñÓë¹Ù·½°ä²¼·ÖÇøÐí¿ÉÏêÇé֪ͨµÄ¹¦·òͬ²½·¢ËÍ´¹µöÐÅÏ¢ £¬¼ÓÇ¿ºýŪÐÔ ¡£Îª·À±¸´ËÀ๥»÷ £¬·¨ÂÉ»ú¹¹½¨ÒéÆóÒµºÍÓ×ÎÒÑϸñºË²é¡°¹Ù·½¡±ÐÅÏ¢µÄºÏ·¨ÐÔ £¬Í¨¹ýÑéÖ¤ÓòÃû¡¢µç×ÓÓʼþµØÖ· £¬²¢Ö±½ÓÖµçÊÐÏØµ±¾ÖÈ·ÈÏδ½ÉÓöÈ ¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-phishing-attacks-impersonating-us-city-county-officials/