ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾
°ä²¼¹¦·ò 2026-03-101. ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾
3ÔÂ6ÈÕ£¬ÃÀ¹úÐÂÔóÎ÷Öݱ±²¿ÅÁÈûÒÁ¿ËÏØÓÚ2026Äê3ÔÂ4ÈÕÍí¼ä°ä²¼´¹Î£²¼¸æ£¬È·ÈÏÔâ·ê¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂÈ«ÏØµ±²¿ÃÅÃÅITϵͳÓëµç»°ÏßÂ·È«ÃæÖжϡ£¸ÃÏØÕý½áºÏÁª¹ú¼°Öݵ±¾Ö¹ÙԹع¿ªµ÷²é£¬ÊÔͼ½ÚÔìÊÂ̬²¢¸´Ô·þÎñ¡£Õâ´Î¹¥»÷ÊÂÎñʼÓÚ3ÔÂ4ÈÕÉÏÎç³õ´Î»ã±¨µÄµç»°Ïß·¹ÊÕÏ£¬¾µ÷²éºóÓÚµ±ÈÕÏÂÎçÈ·ÒÔÎªÍøÂç¹¥»÷ËùÖ¡£ÅÁÈûÒÁ¿ËÏØ¹ÙԱǿµ÷£¬ÐÂÔóÎ÷ÖÝÄÚ¶à¸ö´¦Ëùµ±¾Ö½üÆÚ¾ùÔâ·êÀàËÆÍøÂç¹¥»÷ÊÂÎñ£¬¿ÉÄÜÉæ¼°´ËǰÔâÀÕË÷Èí¼þ¹¥»÷µÄÈøÄ¬ÈûÌØÏØ¡¢¿¨Ä·µÇÏØ¡¢²®¸ùÏØ¡¢ÃÉÌØ¿ËÀ³¶ûÕò¼°»ô²©¿ÏÊС£ÅÁÈûÒÁ¿ËÏØÊÂÎñÔÙ´Î͹ÏÔ´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·À»¤·½ÃæµÄ´àÈõÐÔ¡£·ÖÎöÖ¸³ö£¬ÖÐÓ×ÐÍ´¦Ëùµ±¾ÖÒò×ÊÔ´ÓÐÏÞ£¬ÍùÍù³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄ¡°ÈíÖ¸±ê¡±¡£Ä¿Ç°£¬ÅÁÈûÒÁ¿ËÏØÉÐδÅû¶¹¥»÷¾ßÌåϸ½Ú¼°ÀÕË÷ÒªÇ󣬵«Ç¿µ÷½«ÓÅÏȸ´Ô¹«¹²·þÎñ²¢¹²Í¬·¨Âɲ¿ÃŲ龿¹¥»÷ÆðÔ´¡£
https://therecord.media/new-jersey-county-says-malware-attack-took-down-phones
2. Nginx UI¸ßΣ·ì϶Ö±¸·ÝÊý¾Ýй¶·çÏÕ
3ÔÂ8ÈÕ£¬Nginx UIÖÎÀí½çÃæÆØ³ö±àºÅΪCVE-2026-27944µÄÑϳÁ·ì϶£¨CVSSÆÀ·Ö9.8£©£¬¹¥»÷Õß¿Éδ¾Éí·ÝÑéÖ¤ÏÂÔØ²¢½âÃÜ·þÎñÆ÷ÆëÈ«±¸·Ý£¬µ¼ÖÂÃô¸ÐÅäÖá¢Í´´¦¼°¼ÓÃÜÃÜԿй¶¡£¸Ã·ì϶ԴÓÚ/api/backup¶ËµãδִÐнӼû½ÚÔ죬ÇÒÏìӦͷֱ½Ó¶³ö½âÃÜËùÐèµÄAES-256¼ÓÃÜÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿£¬Ê¹¹¥»÷ÕßÄÜÖ±½Ó»ñÈ¡Ô̺¬Óû§Í´´¦¡¢»á»°ÁîÅÆ¡¢SSL˽Կ¡¢NginxÅäÖÃÎļþ¡¢Êý¾Ý¿âÏνÓÐÅÏ¢µÈÖ÷ÌâÊý¾ÝµÄ±¸·Ý°ü¡£Nginx UI×÷Ϊ¼ò»¯·þÎñÆ÷ÖÎÀíµÄWeb½ÚÔìÃæ°å£¬±¾Ó¦Í¨¹ýͼÐλ¯½çÃæ½µµÍÅäÖÃÃż÷£¬µ«Õâ´Î·ì϶¶³öÆäÉè¼ÆÈ±µã£¬ÖÎÀí½Ó¿Ú¶³öÓÚ¹«¹²»¥ÁªÍøÊ±£¬²»×ã¸ù»ùµÄ°²È«·À»¤¡£Ò»µ©±¸·Ý±»½âÃÜ£¬¹¥»÷Õß¿ÉÆëÈ«½ÚÔìÖÎÀí½çÃæ£¬´Û¸Ä·´Ïò´úÀí¹æ¶¨¡¢³Á¶¨ÏòÁ÷Á¿»òÖ²Èë¶ñÒâ¾ç±¾£»SSL˽Կй¶½«µ¼ÖÂÍøÕ¾¼ÙÒâ»òÖÐÑëÈ˹¥»÷£»Êý¾Ý¿âÍ´´¦ºÍÅäÖÃÎļþ¿ÉÄÜй¶Óû§Êý¾Ý¼°ÀûÓ÷¨Ê½»úÃÜ£»NginxÅäÖÃϸ½Ú¸ü»á¶³öÄÚ²¿ÍøÂç¼Ü¹¹£¬ÎªºóÐø¹¥»÷Ìṩõè¾¶¡£Ä¿Ç°£¬Nginx¹Ù·½ÒѰ䲼½¨¸´°æ±¾£¬Óû§Ó¦Á¢¼´Éý¼¶²¢Éó²é±¸·Ý´æ´¢Õ½Êõ£¬È·±£¼ÓÃÜÃÜÔ¿Ó뱸·Ý·ÖÀë´æ´¢¡£
https://securityaffairs.com/189123/security/critical-nginx-ui-flaw-cve-2026-27944-exposes-server-backups.html
3. ΢Èí¹¤¾ß³ÉºÚ¿ÍкóÃŹ¥»÷½ðÈÚÒ½ÁÆÔØÌå
3ÔÂ9ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾BlueVoyant×îÐÂÅû¶£¬Õë¶Ô¼ÓÄôó½ðÈÚ»ú¹¹¼°È«ÇòÒ½ÁƱ£½¡×éÖ¯µÄ¶¨Ïò¹¥»÷ÖУ¬ºÚ¿Íͨ¹ýÉç»á¹¤³Ìѧ¼¿Á©½áºÏ΢ÈíÉú̬¹¤¾ßÖ´ÐÐÐÂÐͶñÒâÈí¼þ²¿Êð¡£¹¥»÷ÕßÊ×ÏÈÏòÖ¸±êÔ±¹¤·¢ËÍ´óÁ¿À¬»øÓʼþ³ÉÁ¢ÐÅÀµ£¬Ëæºó¼Ù×°³ÉÆóÒµITÈËԱͨ¹ýMicrosoft TeamsÁªÏµÊܺ¦Õߣ¬ÒÔÐÖú´¦ÖÃÀ¬»øÓʼþΪÓÉÓÕµ¼ÆäÆô¶¯Quick AssistÔ¶³Ì»á»°¡£ÔÚ»ñȡԶ³Ì½Ó¼ûȨÏ޺󣬹¥»÷Õß²¿ÊðÔ̺¬Êý×ÖÊðÃûMSI×°Ö÷¨Ê½µÄ¶ñÒ⹤¾ß¼¯¡£ÕâЩMSIÎļþ¼Ù×°³ÉMicrosoft Teams×é¼þ¼°ºÏ·¨Windows¹¤¾ßCrossDeviceService£¬Í¨¹ýDLL²àÔØ¼¼Êõ½«¶ñÒâ¿âhostfxr.dll×¢ÈëºÏ·¨¶þ½øÔìÎļþ¡£¸Ã¿â¼ÓÔØºó½âÃÜÄÚ´æÖеÄshellcode£¬ÀûÓÃCreateThreadº¯Êý´´½¨´óÁ¿Ïß³Ì×ÌÈŵ÷ÊÔÆ÷·ÖÎö£¬Í¬Ê±Ö´ÐÐɳÏä¼ì²âÒÔ¶ã±ÜÐé¹¹»·¾³¡£¶ñÒâÈí¼þͨ¹ýSHA-256ÅÉÉúÃÜÔ¿½âÃܳöA0Backdoor£¬¸ÃºóÃÅѡȡAES¼ÓÃܱ£»¤Ö÷Ìâ´úÂ룬²¢Ç¨áãÖÁÐÂÄÚ´æÇøÓòÖ´ÐС£Æäͨ¹ýDeviceIoControl¡¢GetUserNameExWµÈWindows APIÍøÂçÖ÷»úÐÅÏ¢£¬ÊµÏÖÖ÷»úÖ¸ÎÆ¼ø±ð¡£ÓëºÅÁî½ÚÔì·þÎñÆ÷£¨C2£©µÄͨѶ°µ²ØÔÚDNSÁ÷Á¿ÖС£
https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/
4. ¶íºÚ¿ÍÀûÓÃSignal/WhatsApp´¹µö¹¥»÷µ±¾Ö¾ü·½¼ÇÕß
3ÔÂ9ÈÕ£¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Õýͨ¹ýÕë¶ÔSignalºÍWhatsAppµÄÍøÂç´¹µö»î¶¯£¬¶Ôµ±¾Ö¹ÙÔ±¡¢¾ü·½ÈËÔ±¼°¼ÇÕßÌáÒ鶨Ïò¹¥»÷£¬Ö¼ÔÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ºÉÀ¼¹ú·Àµý±¨Ó밲ȫ¾Ö£¨MIVD£©Óë×ܵý±¨Ó밲ȫ¾Ö£¨AIVD£©½áºÏ»ã±¨Ö¤Êµ£¬ºÉÀ¼µ±¾Ö¹ÍÔ±ÒѳÉΪϮ»÷Ö¸±ê£¬¹¥»÷Ñ¡È¡ÍøÂç´¹µöÓëÉç»á¹¤³Ì¼¼Êõ£¬ÀÄÓúϷ¨Éí·ÝÑéÖ¤Ö°ÄÜÊÕÊÜÕË»§²¢¼à¿ØÐÂÎÅ¡£Signal¹Ù·½°ä²¼ÖÒ¸æÖ¸³ö£¬¹¥»÷ͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µö»î¶¯ÓÕÆÓû§Ð¹Â¶¶ÌÐÅÑéÖ¤Âë»òPINÂ룬µ¼ÖÂÕË»§±»µÁ¡£Ö»¹ÜSignalµÄ¼ÓÃÜϵͳδ±»·ÛË飬µ«¹¥»÷Õß¿ÉÀûÓÃÑéÖ¤ÂëÔÚ×ÔÉíÉ豸ע²áÕË»§£¬ÆëÈ«½ÚÔìÓû§Õ˺ţ¬ÉõÖÁ½«¹ØÁªµç»°ºÅÂë¸ü¸ÄΪ¼º·½½ÚÔ죬´Ó¶ø½Ó¼ûÁªÏµÈËÁÐ±í¡¢ÈºÁÄÐÂÎÅ£¬²¢¼ÙÒâÊܺ¦Õß·¢ËÍÐÂÎÅ¡£Ò»ÖÖµäÐÍÊÖ·¨ÊǼÙÒâ¡°Signal°²È«Ö§³Ö̸Ìì»úеÈË¡±£¬»Ñ³Æ¼ì²âµ½ÕË»§¿ÉÒɻ£¬ÓÕµ¼Óû§Ê䶯ÊÖ»úÑéÖ¤ÂëʵÏÖ¡°ÑéÖ¤·¨Ê½¡±£»ÁíÒ»ÖÖÔòÊÇ·¢ËͶñÒâ¶þάÂë»òÁ´½Ó£¬¼Ù×°³ÉȺ×éÔ¼Çë»òÉ豸ÏνÓÒªÇó£¬Êܺ¦ÕßɨÃè»òµã»÷ºó£¬¹¥»÷ÕßÉ豸½«ÓëÕË»§¹ØÁª£¬ÊµÊ±½Ó¼û²¢Í¬²½ÐÂÎÅ¡£
https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/
5. °®Á¢ÐÅÃÀ¹ú×Ó¹«Ë¾³¬4000ÃûÐÂÏçÓû§ÐÅÏ¢±»ÇÔ
3ÔÂ9ÈÕ£¬ÈðµäͨѶ¾ÞÍ·°®Á¢ÐŵÄÃÀ¹ú×Ó¹«Ë¾½üÈÕÅû¶һ·³Á´óÊý¾Ýй¶ÊÂÎñ¡£¾ÝÆäÏò¼ÓÖݼ°µÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤Ìá½»µÄÎļþÏÔʾ£¬2025Äê4ÔÂ28ÈÕ£¬Ò»¼ÒΪ°®Á¢ÐÅ´æ´¢Ô±¹¤ºÍ¿Í»§Êý¾ÝµÄµÚÈý·½·þÎñÌṩÉ̼ì²âµ½Òì³£½Ó¼û£¬ËæºóÆô¶¯µ÷²é²¢Í¨ÖªÁª¹úµ÷²é¾Ö£¨FBI£©¡£µ÷²éÈ·ÈÏ£¬2025Äê4ÔÂ17ÈÕÖÁ22ÈÕÆÚ¼ä£¬¹¥»÷Õßδ¾ÊÚȨ½Ó¼û»ò»ñÈ¡Á˲¿ÃÅÎļþ£¬Éæ¼°ÐÕÃû¡¢µØÖ·¡¢Éç»á±£ÏÕºÅÂë¡¢¼ÝÕպ𢻤Õյȵ±¾ÖID¡¢ÒøÐÐÕ˺š¢ÐÅÓþ¿¨ÐÅÏ¢¡¢Ò½ÁƼͼ¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢¡£Õâ´ÎÊÂÎñÔڵ¿ËÈøË¹ÖÝÒÑÈ·ÈÏÓ°Ïì4,377ÈË£¬µ«È«ÇòÊÜÓ°Ïì×ÜÈËÊýÉÐδ¹«¿ª¡£°®Á¢ÐÅÇ¿µ÷£¬Ö»¹ÜÊý¾Ý±»ÇÔÈ¡£¬Ä¿Ç°ÉÐδ·¢ÏÖÐÅÏ¢±»ÀÄÓõÄÖ¤¾Ý¡£Îª±£»¤ÊÜÓ°ÏìÓû§£¬¸Ã¹«Ë¾ÌṩΪÆÚÒ»ÄêµÄÃâ·ÑIDXÉí·Ý±£»¤·þÎñ£¬Ô̺¬ÐÅÓþ¼à¿Ø¡¢°µÍø¼à¿Ø¡¢Éí·Ý͵ÇÔ¸´ÔÖ§³Ö¼°×î¸ß100ÍòÃÀÔªµÄÚ²ÆËðʧÅâ³¥£¬Óû§ÐèÔÚ2026Äê6ÔÂ9ÈÕǰע²á¡£½ØÖÁĿǰ£¬ÎÞÈκÎÍøÂç·¸×ï×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/
6. FBI¾¯Ê¾¹ÙÔ±¼ÙÒâ´¹µö¹¥»÷£¬µØÆ¤Ðí¿ÉÉêÇëÕß³ÉÖ¸±ê
3ÔÂ9ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼¹«¹²·þÎñ²¼¸æ£¬¸æ·¢·¸×ï·Ö×ÓÕýͨ¹ý¼ÙÒâÊÐÏØ¹æ»®ºÍ·ÖÇøÎ¯Ô±»á¹ÙÔ±Ö´ÐÐÍøÂç´¹µö¹¥»÷£¬Ö¸±êËø¶¨ÉêÇëµØÆ¤Ê¹ÓÃÐí¿ÉÖ¤µÄÆóÒµ¼°Ó×ÎÒ¡£¹¥»÷ÕßÀûÓù«¿ªÇþ·»ñÈ¡µÄÊܺ¦ÕßÐí¿ÉÖ¤ÐÅÏ¢¡¢·ÖÇøÉêÇë±àºÅ»ò·¿²úµØÖ·µÈϸ½Ú£¬Î±ÔìºÏ·¨ÓʼþÓÕµ¼Êܺ¦ÕßÖ§¸¶¡°Ðí¿ÉÖ¤ÓйØÓöȡ±£¬²¢ÒªÇóͨ¹ýµç»ã¡¢µã¶ÔµãÖ§¸¶»ò¼ÓÃÜÇ®±ÒʵÏÖÂòÂô£¬ÒÔ´ËÖ´ÐÐڲơ£FBIÖ¸³ö£¬´ËÀàȦÌ×´æÔÚ¶à³Á¿É¼ø±ðÌØµã£ºÓʼþͨ³£À´×Էǵ±¾ÖÓòÃû£¬¸½¼þÒªÇóÊÕ¼þÈËͨ¹ýÓʼþË÷È¡¸ü¶àϸ½Ú£¬ÇÒ³£°éËæ¡°¼Ó¿ì¸¶¿îÒÔÔ¤·ÀÐí¿ÉÖ¤ÑÓÎ󡱵ȶ½´ÙÕ½Êõ¡£Ú¿Æ·Ö×Ó»¹»á¿ÌÒâÑ¡ÔñÓë¹Ù·½°ä²¼·ÖÇøÐí¿ÉÏêÇé֪ͨµÄ¹¦·òͬ²½·¢ËÍ´¹µöÐÅÏ¢£¬¼ÓÇ¿ºýŪÐÔ¡£Îª·À±¸´ËÀ๥»÷£¬·¨ÂÉ»ú¹¹½¨ÒéÆóÒµºÍÓ×ÎÒÑϸñºË²é¡°¹Ù·½¡±ÐÅÏ¢µÄºÏ·¨ÐÔ£¬Í¨¹ýÑéÖ¤ÓòÃû¡¢µç×ÓÓʼþµØÖ·£¬²¢Ö±½ÓÖµçÊÐÏØµ±¾ÖÈ·ÈÏδ½ÉÓöȡ£
https://www.bleepingcomputer.com/news/security/fbi-warns-of-phishing-attacks-impersonating-us-city-county-officials/


¾©¹«Íø°²±¸11010802024551ºÅ