¹¥»÷ÕßÀÄÓÃFortiGate·À»ðǽ×÷ÎªÍøÂçÈëÇÖÌø°å

°ä²¼¹¦·ò 2026-03-11

1. ¹¥»÷ÕßÀÄÓÃFortiGate·À»ðǽ×÷ÎªÍøÂçÈëÇÖÌø°å


3ÔÂ10ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÆÚ¼à²âµ½Õë¶ÔFortiGateÏÂÒ»´ú·À»ðǽ£¨NGFW£©µÄÐÂÐ͹¥»÷»î¶¯£¬ÍþвÐÐΪÕßÕýÀûÓøÃÉ豸×÷ΪÈëÇÖÊܺ¦ÕßÍøÂçµÄÈë¿Úµã¡£SentinelOne»ã±¨Ö¸³ö£¬¹¥»÷Õßͨ¹ý½üÆÚÅû¶µÄ·ì϶£¨ÈçCVE-2025-59718¡¢CVE-2025-59719¡¢CVE-2026-24858£©»òÈõÍ´´¦ÈëÇÖÉ豸£¬ÇÔÈ¡Ô̺¬·þÎñÕË»§Í´´¦ºÍÍøÂçÍØÆËÐÅÏ¢µÄÅäÖÃÎļþ£¬Ö¸±ê¼¯ÖÐÓÚÒ½ÁƱ£½¡¡¢µ±¾ÐİÍйܷþÎñÌṩÉ̵ÈÃô¸Ð»·¾³¡£FortiGateÉ豸Òò¼¯³É·À»ðǽ°²È«½ÚÔìÓëAD/LDAPµÈÉí·ÝÑéÖ¤»ù´¡ÉèÊ©½Ó¼ûȨÏÞ£¬³£±»²¿ÊðÓڹؼüÍøÂç½Úµã¡£¹¥»÷ÕßÈëÇֺ󣬿ɴ´½¨±¾µØÖÎÀíÔ¹ØË»§£¨Èç¡°support¡±£©£¬ÉèÖÃÎÞÇøÓòÏ޶ȵķÀ»ðǽսÊõ£¬ÊµÏÖÈ«Íø×ÔÓɱéÀú¡£ÔÚ2025Äê11ÔµÄһ·ÊÂÎñÖУ¬¹¥»÷Õßͨ¹ý´ËÀà²Ù×÷³ÉÁ¢Óƾû¯°²Éíµã£¬²¢ÓÚ2026Äê2ÔÂÌáÈ¡¼ÓÃܵÄLDAP·þÎñÕË»§Í´´¦£¬½âÃܺóʹÓøÃÍ´´¦¶ÔAD½øÐÐÉí·ÝÑéÖ¤£¬×¢²á¶ñÒ⹤×÷Õ¾£¬Æô¶¯ÍøÂçɨÃ裬×îÖÕ±»¼ì²â²¢×èÖ¹ºáÏòÒÆ¶¯¡£


https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html


2. ¶íÓïÍþвÐÐΪÕßÀûÓÃBlackSanta EDRɱÊÖ¹¥»÷HR²¿ÃÅ


3ÔÂ10ÈÕ£¬Ò»Äê¶àÒÔÀ´£¬½²¶íÓïµÄÍþвÐÐΪÕßÕë¶ÔÈËÁ¦×ÊÔ´²¿ÃÅÌáÒ龫ÐIJ߶¯µÄ¹¥»÷»î¶¯£¬Í¨¹ýÓã²æÊ½ÍøÂç´¹µöÓʼþ´«²¼¼Ù×°³É¼òÀúµÄISO¾µÏñÎļþ¡£¸Ã¶ñÒâÈí¼þ¼¯³ÉÉç»á¹¤³ÌѧÓëÏȽø¶ã±Ü¼¼Êõ£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢²¢²¿ÊðÃûΪBlackSantaµÄÐÂÐÍEDRɱÊÖ¡£¹¥»÷Á´ÖУ¬ISOÎļþÔ̺¬¼Ù×°³ÉPDFµÄLNK¿ì½Ý·½Ê½¡¢PowerShell¾ç±¾¡¢Í¼Ïñ¼°ICOÎļþ¡£LNKÆô¶¯PowerShellÖ´Ðо籾£¬ÀûÓÃÒþдÊõ´ÓͼÏñÌáÈ¡Êý¾Ý²¢ÔÚÄÚ´æÔËÐУ¬ËæºóÏÂÔØº¬ºÏ·¨SumatraPDFÓë¶ñÒâDWrite.dllµÄZIP°ü£¬Í¨¹ýDLL²à¼ÓÔØ¼ÓÔØ¶ñÒâ´úÂë¡£¸Ã¶ñÒâÈí¼þÖ´ÐÐÏµÍ³Ö¸ÎÆ¼ø±ð£¬½«ÐÅÏ¢·¢ËÍÖÁC2·þÎñÆ÷£¬²¢¼ì²âɳÏä¡¢Ðé¹¹»ú»òµ÷ÊÔ¹¤¾ßÒÔ¶ã±Ü·ÖÎö¡£BlackSantaµÄÖ÷ÌâÖ°ÄÜÊÇʹ¶Ëµã°²È«½â¾ö¹æ»®Ê§Ð§£ºÍ¨¹ýÔö³¤Microsoft DefenderÅųýÏî¡¢Åú¸Ä×¢²á±íÏ÷¼õÒ£²âÊý¾ÝÌá½»¡¢ÒÖÔìWindows֪ͨ£¬²¢ÖÕÖ¹°²È«¹ý³Ì¡£Æäͨ¹ýö¾Ù¹ý³Ì²¢Óë·À²¡¶¾/EDR/SIEM¹¤¾ßÁбí±È¶Ô£¬»ñÈ¡¹ý³ÌIDºóʹÓüÓÔØµÄÇý¶¯·¨Ê½ÔÚÄں˼¶½âËø²¢ÖÕÖ¹¹ý³Ì¡£


https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/


3. BeatBanker¼Ù×°³ÉStarlinkÀûÓÃÖ´Ðй¥»÷


3ÔÂ10ÈÕ£¬¿¨°Í˹»ù×êÑÐÈËÔ±½üÈÕ·¢ÏÖÕë¶Ô°ÍÎ÷Óû§µÄBeatBankerÐÂÐÍAndroid¶ñÒâÈí¼þ£¬¸ÃÈí¼þͨ¹ý¼Ù×°³ÉStarlinkÀûÓÃÓÕµ¼Óû§½Ó¼û¼ÙðµÄGoogle PlayÉ̵êÍøÕ¾½øÐÐ×°Ö㬼¯ÒøÐÐľÂíÓëÃÅÂÞ±ÒÍÚ¿óÖ°ÄÜÓÚÒ»Ìå¡£Æä×îа汾²¿ÊðÁËBTMOB RATͨÓÃÔ¶³Ì½Ó¼ûľÂí£¬¾ß±¸É豸ȫ¿Ø¡¢¼üÅ̼ͼ¡¢ÆÁϼÔì¡¢ÉãÏñÍ·½Ó¼û¡¢GPS¸ú×Ù¼°Æ¾Ö¤²¶»ñµÈÄÜÁ¦¡£BeatBankerÒÔAPKÎļþ·Ö·¢£¬ÀûÓñ¾µØ¿â½âÃܰµ²ØµÄDEX´úÂëÖ±½Ó¼ÓÔØµ½ÄÚ´æÒÔ¶ã±Ü¼ì²â¡£×°ÖÃǰ»á½øÐл·¾³²é³­£¬Í¨¹ýºóÏÔʾαÔìµÄPlayÉ̵ê¸üÐÂÒ³Ãæ£¬ÓÕÆ­Óû§ÊÚÓè×°ÖÃÆäËû¶ñÒⷨʽµÄȨÏÞ¡£ÎªÔ¤·À´¥·¢¾¯±¨£¬¸Ã¶ñÒâÈí¼þ»áÑÓ³¤¶ñÒâ²Ù×÷£¬²¢Í¨¹ý³ÖÐø²¥·ÅÏÕЩÌý²»¼ûµÄ5ÃëÖÐÎÄMP3¹àÒôά³ÖÓÆ¾ÃÐÔ¡£ÔÚÍÚ¿ó·½Ã棬BeatBankerʹÓÃרΪARMÉ豸±àÒëµÄXMRig 6.17.0Åú¸Ä°æ£¬Í¨¹ý¼ÓÃÜTLSÏνӹ¥»÷Õß½ÚÔìµÄ¿ó³Ø½øÐÐÃÅÂÞ±ÒÍڿ󣬲¢Ö§³ÖÖ÷µØÖ·¹ÊÕÏʱ»ØÍ˵½´úÀíµØÖ·¡£ÍÚ¿óÄ£¿é»áƾ¾ÝÉ豸Çé¿ö¶¯Ì¬Æô¶¯»òÖÕ³¡£¬²Ù×÷ÈËԱͨ¹ýFirebaseÔÆÐÂÎÅ´«µÝ£¨FCM£©³ÖÐø¼à¿ØÉ豸µç³ØµçÁ¿¡¢Î¶ȡ¢³äµç״̬¼°Ê¹ÓÃÇé¿ö£¬ÔÚÉ豸ʹÓÃʱÖÕ³¡ÍÚ¿óÒÔÏ÷¼õÎïÀíÓ°Ï죬ά³ÖÒñ±ÎÐÔ¡£


https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/


4. ½©Ê¬ZIP¼¼Êõ£º´Û¸ÄÎļþÍ·ÈÆ°²È«É¨Ãè


3ÔÂ10ÈÕ£¬°²È«×êÑÐÔ±Chris AzizÉè¼ÆµÄ¡°½©Ê¬ZIP¡±¼¼Êõͨ¹ý´Û¸ÄZIPÎļþÍ·£¬½«Ñ¹ËõÊý¾Ý¼Ù×°³ÉδѹËõÊý¾Ý£¬³É¹¦Èƹý51¸öɱ¶¾ÒýÇæÖеÄ50¸ö£¨VirusTotal²âÊÔ£©¡£¸Ã¼¼ÊõÀûÓ÷À²¡¶¾Èí¼þ¶ÔZIPÎļþ¡°²½Öè×ֶΡ±µÄÐÅÀµ£¬µ±²½Öè×Ö¶ÎÏóÕ÷Ϊ¡°´æ´¢£¨Method=0£©¡±Ê±£¬°²È«¹¤¾ß»áÖ±½ÓɨÃèԭʼ×Ö½Ú£¬µ«ÏÖʵÊý¾ÝÊǾ­¹ýDEFLATEѹËõµÄ£¬µ¼ÖÂɨÃèÆ÷½ö¿´µ½¡°Ñ¹ËõÔëÉù¡±¶øÎÞ·¨¼ì²â¶ñÒâÌØµãÂë¡£ÍþвÐÐΪÕ߿ɴ´½¨×¨ÓüÓÔØÆ÷£¬ºöÂÔ±»´Û¸ÄµÄ±êÍ·£¬Ö±½ÓÒÔDEFLATEËã·¨½âѹÎļþ£¬ÃÀÂú¸´Ô­ÓÐÐ§ÔØºÉ¡£¶ø³ß¶È½âѹ¹¤¾ß£¨ÈçWinRAR¡¢7-Zip£©³¢ÊÔ½âѹʱ»áÒòÎļþÍ·ÃýÎ󱨴í»òÊý¾Ý°Ü»µ£¬Ðγɡ°°²È«¹¤¾ßÎóÅÓ×¢½âѹ¹¤¾ßʧЧ¡±µÄË«³ÁÒñ±Î³ÉЧ¡£CERT/CC½¨Ò鰲ȫ¹¤¾ß¹©¸øÉÌÐèÑé֤ѹËõ²½Öè×Ö¶ÎÓëÏÖʵÊý¾ÝÒ»ÖÂÐÔ£¬Ôö³¤¹éµµ½á¹¹Ò»ÖÂÐÔ¼ì²â£¬²¢Ñ¡È¡¸ü»ý¼«µÄ½âѹ²é³­Ä£Ê½£»Óû§ÔòÐèÉóÉ÷´¦ÖÃδ֪ÆðÔ´µÄѹËõÎļþ£¬Èô½âѹʱ³öÏÖ¡°²»Ö§³ÖµÄ²½Ö衱ÃýÎó£¬Ó¦Á¢¼´É¾³ýÎļþ¡£


https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/


5. KadNap½©Ê¬ÍøÂçÀûÓÃKademliaºÍ̸ϰȾ»ªË¶Â·ÓÉÆ÷


3ÔÂ10ÈÕ£¬ÐÂÐͽ©Ê¬ÍøÂçKadNap×Ô2025Äê8ÔÂÆðÒÑϰȾ14,000̨»ªË¶Â·ÓÉÆ÷¼°ÆäËû±ßÔµÉ豸£¬Í¨¹ý×Ô½ç˵KademliaÉ¢²¼Ê½¹þÏ£±í£¨DHT£©ºÍ̸¹¹½¨µã¶ÔµãÍøÂ磬ÏνÓC2»ù´¡ÉèÊ©¡£¸ÃÍøÂç½ü°ëÉ豸¹ØÁª»ªË¶×¨ÓÃC2£¬ÆäÓàÓëÁ½¸ö¶ÀÁ¢½ÚÔì·þÎñÆ÷ͨѶ£¬60%µÄÊÜϰȾÉ豸λÓÚÃÀ¹ú£¬Ì¨Íå¡¢Ïã¸Û¡¢¶íÂÞ˹ÒàÕ¼ÏÔÖø±ÈÀý¡£Ï°È¾Ê¼ÓÚ´Ó212.104.141[.]140ÏÂÔØ¶ñÒâ¾ç±¾aic.sh£¬Í¨¹ýÿ55·ÖÖÓÔËÐеÄcron¹¤×÷³ÉÁ¢Óƾû¯£¬×îÖÕ×°ÖÃkad ELF¶þ½øÔìÎļþ×÷Ϊ¿Í»§¶Ë¡£¼¤»îºó£¬¶ñÒâÈí¼þ»ñÈ¡Ö÷»ú±í²¿IP£¬ÁªÏµNTP·þÎñÆ÷»ñÈ¡¹¦·ò¼°ÏµÍ³ÔËÐй¦·ò£¬²¢ÀûÓÃÅú¸ÄºóµÄKademlia DHTºÍ̸¶¨Î»½ÚµãÓëC2£¬¾Ý·ÖÉ¢´æ´¢Ê¹C2¼ø±ðÓë·ÛËé¸üÄÑÌ⡣Ȼ¶ø£¬ÆäKademliaʵÏÖ´æÔÚȱµã£ºÔÚ´ïµ½C2ǰÓëÁ½¸öÌØ¶¨½Úµã³ÖÐøÏνÓ£¬½µµÍÁËÈ¥ÖÐÐÄ»¯Ë®Æ½£¬Ê¹½ÚÔì»ù´¡ÉèÊ©¿É±»¼ø±ð¡£


https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/


6. Cal AIÔâºÚ¿ÍÈëÇÖÖÂ300ÍòÓû§Êý¾Ýй¶


3ÔÂ10ÈÕ£¬»¯Ãû¡°vibecodelegend¡±µÄºÚ¿Íͨ¹ýÍøÂç·¸×ïÆ½Ì¨BreachForumsÐû³ÆÈëÇÖCal AI£¬ÕâÊÇÒ»¿îÀûÓÃAI·ÖÎöʳƷͼƬ׷×Ù¿¨Â·ÀïÓëÓªÑøÐÅÏ¢µÄÈȵ㽡ȫÀûÓ㬲¢Ð¹Â¶³¬300ÍòÓû§µÄ12GBÓ×ÎÒÊý¾Ý¡£Cal AI½üÆÚÒòÊÕ¹º½¡ÉíÀûÓÃMyFitnessPal½øÒ»²½À©´óÊг¡·Ý¶î£¬¶øMyFitnessPalÔÚ2018ÄêÔøÒòǰËùÓÐÕßUnder ArmourÅû¶Ôâ·ê´ó¹æÄ£Êý¾Ýй¶£¬³¬1.5ÒÚÓû§ÐÅÏ¢±»ÇÔ¡£¾ÝºÚ¿ÍÐû³Æ£¬Ð¹Â¶Êý¾Ýº­¸ÇÓû§µ®ÉúÈÕÆÚ¡¢ÐÕÃû¡¢ÐÔ±ð¡¢Óû§Ãû¡¢É罻ýÌå×ÊÁÏ¡¢PINÂë¡¢¶©ÔÄÏêÇé¡¢Éí¸ßÌå³ÁµÈÉúÎïÌØµã£¬ÒÔ¼°³¬280Íò¸öµç×ÓÓʼþµØÖ·£¬ÆäÖнü120ÍòʹÓÃApple˽ÓÐÖм̷þÎñ@privaterelay.appleid.comÒÔ°µ²ØÕæÊµÓÊÏä¡£´Ë±í£¬Êý¾Ý»¹Ô̺¬´¶Ê¼Í¼¡¢½ø²Í¹¦·ò¼°¿¨Â·Àï×·×ÙµÈÐÐΪÐÅÏ¢£¬¿ÉÄܶ³öÓû§ÒûʳģʽÓ뽡ȫϰ¹ß¡£Ä¿Ç°£¬ÓйØÊý¾ÝÒÑÔÚ¶íÓïÆ½Ì¨¼°¶à¸öTelegramƵ·Á÷´«£¬Òý·¢ÒþÖÔ°²È«ÓÇÓô¡£


https://hackread.com/cal-ai-myfitnesspal-data-breach-3m-users/