FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
°ä²¼¹¦·ò 2026-01-221. FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Fortinet¿Í»§Ôâ·êÑϳÁ°²È«ÊÂÎñ£º¹¥»÷ÕßÀûÓÃÒѽ¨¸´µÄFortiGateÉí·ÝÑéÖ¤·ì϶CVE-2025-59718µÄ²¹¶¡Èƹý·ì϶£¬£¬£¬£¬£¬³É¹¦ÈëÇÖÒÑ´ò²¹¶¡µÄ·À»ðǽÉ豸¡£¡£¡£¡£¡£¡£¸Ã·ìÏ¶Éæ¼°FortiCloudµ¥µãµÇ¼(SSO)Ö°ÄÜ£¬£¬£¬£¬£¬Ö»¹ÜFortinetÔÚ³õʼ²¼¸æÖÐÇ¿µ÷£¬£¬£¬£¬£¬Î´×¢²áFortiCareµÄÉ豸ĬÈÏδÆôÓøÃÖ°ÄÜ£¬£¬£¬£¬£¬¿ÉÏ÷¼õÊÜÓ°ÏìÁìÓò£¬£¬£¬£¬£¬µ«Shadowserver»ù½ð»á12ÔÂÖÐÑ®µÄɨÃèÏÔʾ£¬£¬£¬£¬£¬ÈÔÓг¬¹ý25,000̨ÆôÓÃFortiCloud SSOµÄFortinetÉ豸¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰ³¬°ëÊýÉ豸ÒÑÊܱ£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬ÈÔÓг¬¹ý11,000̨É豸¿É±»¹«¿ª½Ó¼û£¬£¬£¬£¬£¬×é³É³Á´ó·çÏÕ¡£¡£¡£¡£¡£¡£ÎªÓ¦¶ÔÍþв£¬£¬£¬£¬£¬Fortinet½¨ÒéÖÎÀíÔ±ÔÚÌṩÆëÈ«½¨¸´µÄFortiOS°æ±¾Ç°£¬£¬£¬£¬£¬ÁÙʱ½ûÓÃFortiCloudµÇ¼ְÄÜ¡£¡£¡£¡£¡£¡£¾ßÌå²Ù×÷¿Éͨ¹ýWeb½çÃæ½øÈë"ϵͳ"¡ú"ÉèÖÃ"£¬£¬£¬£¬£¬¹Ø¹Ø"ÔÊÐíʹÓÃFortiCloud SSO½øÐÐÖÎÀíÔ±µÇ¼"Ñ¡Ï£¬£¬£¬£¬»òͨ¹ýºÅÁîÐÐÖ´ÐÐ"config system global; set admin-forticloud-sso-login disable; end"ʵÏÖ¡£¡£¡£¡£¡£¡£ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö(CISA)Òѽ«¸Ã·ì϶ÁÐÈë"ÔÚ±»ÀûÓõķì϶"Çåµ¥£¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚÒ»ÖÜÄÚʵÏÖ½¨²¹¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fortinet-admins-report-patched-fortigate-firewalls-getting-hacked/
2. ÒÁÀʵçÊǪ́ÔâºÚ¿Í¹¥»÷²¥·ÅÍõ´¢½²»°
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÒÁÀʶà¼ÒµçÊǪ́½ÚÄ¿1ÔÂ18ÈÕÍí¼äÔâºÚ¿ÍÖжϣ¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý°ÍµÂ¶ûÎÀÐÇ´«ÊäϵͳÊÕÊÜÐźţ¬£¬£¬£¬£¬²¥·Å½ÖÍ·¿¹Òé»Ãæ¼°ÍöÃüÍõ´¢ÀñÈø¡¤°ÍÁÐάµÄ¼«¶ÈÖÓÔ¤ÏȼÔì½²»°¡£¡£¡£¡£¡£¡£°ÍÁÐάÔÚÊÓÆµÖкôÓõÒÁÀʹúÃñ¾üÓëÃñ¶àÁª½á£¬£¬£¬£¬£¬Ôð¹Ö°²È«¶ÓÁÓװЧÖÒÒÁ˹À¼¹²ºÍ¹ú¶ø·ÇÒÁÀÊ¡±£¬£¬£¬£¬£¬²¢Ðû³Æ²¿ÃÅÊ¿±øÒѵ¹¸ê£¬£¬£¬£¬£¬µ«Î´Ìṩ֤¾Ý¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËÒÁÀÊÒÁ˹À¼¹²ºÍ¹ú¹ã²¥µçÊǪ́£¨IRIB£©¸²¸Ç´åÂ䵨ÓòµÄÎÀÐÇÐźţ¬£¬£¬£¬£¬ÓйØÊÓÆµÆ¬¶ÎѸËÙ±»°ÍÁÐάÍŶӡ¢ÒÁÀʹú¼ÊµçÊǪ́¼°±¾µØÃ½Ìåת·¢´«²¼¡£¡£¡£¡£¡£¡£ÊÂÎñ²úÉúÔÚÒÁÀÊÉîÏݾ¼ÃΣ»£»£»£»£»£»£»úÖ®¼Ê¡£¡£¡£¡£¡£¡£×Ô2025Äê12ÔÂµ×Æð£¬£¬£¬£¬£¬ÒÁÀÊÇ®±ÒÀïÑǶû´ó·ù±áÖµ£¬£¬£¬£¬£¬Ê³Æ·¼Ûֵʧ¿ØìÉý£¬£¬£¬£¬£¬Ãñ¶à½«¾¼ÃÀ§¾³¹é×ïÓÚµ±¾ÖµòÂä¡£¡£¡£¡£¡£¡£Îª×èÖ¹±©Á¦ÐÂÎÅ´«²¼£¬£¬£¬£¬£¬ÒÁÀʵ±¾Ö¹Ø¹Ø»¥ÁªÍøºÍÒÆ¶¯·þÎñ³¤´ïÁ½ÖÜ¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬²¿ÃžÓÃñͨ¹ýÐÇÁ´ÎÀÐÇÌ×¼þ½«ºÚ¿ÍÇÔÈ¡µÄÊÓÆµ´«²¼ÖÁÈ«Çò¡£¡£¡£¡£¡£¡£ÓëÒÁÀʸïÃüÎÀ¶Ó¹ØÁªµÄ·¨¶û˹ͨѶÉçÔ®Òý¹ú¶È¹ã²¥¹«Ë¾Ëµ·¨£¬£¬£¬£¬£¬³Æ²¿ÃŵØÓòÐźš°Òò²»Ã÷ÔÒò¶ÌÔÝÖжϡ±£¬£¬£¬£¬£¬µ«Î´Ìá¼°¿¹ÒéÊÓÆµ»òÍõ´¢½²»°ÄÚÈÝ¡£¡£¡£¡£¡£¡£
https://hackread.com/iranian-tv-transmission-hacked-exiled-prince-message/
3. Cisco´¹Î£½¨¸´¸ßΣÁãÈÕ·ì϶CVE-2026-20045
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬Ë¼¿Æ¹«Ë¾½üÈÕ½¨¸´ÁËÒ»¸öÑϳÁµÄ¸ßΣÁãÈÕÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2026-20045£¨CVSSÆÀ·Ö8.2£©£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»·¢ÏÖ±»»ý¼«ÀûÓÃÓÚ¹¥»÷¡£¡£¡£¡£¡£¡£´Ë·ì϶ԴÓÚHTTPÒªÇóÖÐÓû§ÊäÈëÐÅÏ¢ÑéÖ¤²»µ±£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸µÄWebÖÎÀí½çÃæ·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇ󣬣¬£¬£¬£¬ÔÚÉ豸µ×²ã²Ù×÷ϵͳִÐÐËÁÒâºÅÁ£¬£¬£¬£¬×îÖÕ¿ÉÄÜ»ñÈ¡rootȨÏÞ¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì²úÆ·Ô̺¬Cisco Unified CM¡¢Unified CM SME¡¢IM & Presence¡¢Unity Connection¼°Webex Calling Dedicated Instance¡£¡£¡£¡£¡£¡£¾ßÌ彨¸´°æ±¾ÈçÏ£ºUnified CMµÈϵÁÐ12.5°æ±¾ÐèǨáãÖÁ¹Ì¶¨°æ±¾£»£»£»£»£»£»£»14°æ±¾ÐèÉý¼¶ÖÁ14SU5»òÀûÓò¹¶¡Îļþ£»£»£»£»£»£»£»15°æ±¾ÐèÉý¼¶ÖÁ2026Äê3Ô°䲼µÄ15SU4»òÀûÓöÔÓ¦²¹¶¡¡£¡£¡£¡£¡£¡£Unity ConnectionͬÑùÐèÆ¾¾Ý°æ±¾Éý¼¶ÖÁ14SU5»ò15SU4²¢ÀûÓò¹¶¡¡£¡£¡£¡£¡£¡£Ë¼¿ÆÇ¿µ÷²¹¶¡Óë°æ±¾Ñϸñ¶ÔÓ¦£¬£¬£¬£¬£¬Óû§Ðè²Î¿¼²¹¶¡READMEÎļþ²Ù×÷¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬Õâ´Î½¨¸´ÎÞһʱ½â¾ö¹æ»®£¬£¬£¬£¬£¬Ë¼¿Æ°²È«Ó¦¼±ÏìÓ¦Ó××飨PSIRT£©ÒÑÈ·ÈÏ´æÔÚÀûÓó¢ÊÔ£¬£¬£¬£¬£¬Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶ÖÁ½¨¸´°æ±¾¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/187177/security/cisco-fixed-actively-exploited-unified-communications-zero-day.html
4. Zendesk¹¤µ¥ÏµÍ³ÔâÈ«Çò´ó¹æÄ£À¬»øÓʼþ¹¥»÷
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬È«ÇòÓû§Ôâ·êÓÉZendeskÖ§³ÖϵͳÒý·¢µÄ´ó¹æÄ£À¬»øÓʼþ¹¥»÷£¬£¬£¬£¬£¬Êܺ¦ÕßÊÕµ½Êý°Ù·âÖ÷Ìâ¹îÒìÇÒÄÚÈÝ»ìÂÒµÄÓʼþ£¬£¬£¬£¬£¬Òý·¢¿í·º²ÂÒÉÓë·¢¼±¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ô´ÓÚZendeskÔÊÐíδ¾ÑéÖ¤Óû§Ìá½»Ö§³Ö¹¤µ¥µÄ·ì϶£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý±éÀúº£Á¿ÓʼþµØÖ·ÁÐ±í´´½¨Ðéα¹¤µ¥£¬£¬£¬£¬£¬´¥·¢ÏµÍ³×Ô¶¯·¢ËÍÈ·ÈÏÓʼþ£¬£¬£¬£¬£¬½«ºÏ·¨ÆóÒµµÄZendeskƽ̨±äΪÀ¬»øÓʼþÖмÌÕ¾¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÆóÒµº¸Ç¿Æ¼¼¡¢ÓÎÏ·¡¢ÕþÎñµÈ¶àÁìÓò£¬£¬£¬£¬£¬Ô̺¬Discord¡¢Tinder¡¢Riot Games¡¢Dropbox¡¢CD Projekt¡¢ÌïÄÉÎ÷ÖÝÀ͹¤²¿µÈ³¬20¼Ò»ú¹¹¡£¡£¡£¡£¡£¡£ÓʼþÖ÷Ìâ³öÏָ߶ȹƻóÐÔÌØµã£º²¿ÃżÙ×°·¨ÂÉ֪ͨ¡¢²¿ÃųÐŵÃâ·Ñ¸£Àû¡¢¸üÓдóÁ¿Ê¹ÓÃUnicode×°è«×ÖÌå±àдµÄÂÒÂëÄÚÈÝ¡£¡£¡£¡£¡£¡£ÓÉÓÚÓʼþÔ´×ÔÕý¹æÆóҵϵͳ£¬£¬£¬£¬£¬Æä¿ÉÐŶÈÔ¶³¬Í¨³£À¬»øÓʼþ£¬£¬£¬£¬£¬³É¹¦ÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬£¬£¬£¬Ðγɸü´óÇÖÈÅÐÔ¡£¡£¡£¡£¡£¡£ÉæÊÂÆóҵѸËÙ»ØÓ¦£ºDropbox¡¢2KµÈÃ÷È·°µÊ¾ÓʼþΪϵͳÀÄÓòúÆ·£¬£¬£¬£¬£¬Ç¿µ÷Æä"ŷʤµ¥Ìá½»"Õþ²ßËä·½±ãµ«´æÔÚ·çÏÕ£¬£¬£¬£¬£¬³Ðŵδ¾ÕË»§³ÖÓÐÈËÑéÖ¤²»»á´¦ÖÃÃô¸ÐÒªÇ󣬣¬£¬£¬£¬½¨ÒéÓû§Ö±½ÓºöÂÔÒì³£Óʼþ¡£¡£¡£¡£¡£¡£Zendesk¹Ù·½Åû¶£¬£¬£¬£¬£¬¹«Ë¾ÒÑ´¹Î£²¿ÊðÐÂÐͰ²È«Ö°ÄÜ£¬£¬£¬£¬£¬Í¨¹ý¼ÓÇ¿¼à¿ØËã·¨ÓëÖ´ÐлÏÞ¶È£¬£¬£¬£¬£¬ÌáÉý¶ÔÒì³£¹¤µ¥µÄ¼ì²âÓëÀ¹½ØÐ§ÄÜ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/zendesk-ticket-systems-hijacked-in-massive-global-spam-wave/
5. ÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾ÂíÀûÓÃTensorFlow¼¼Êõ´«²¼
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Ò»ÖÖÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾Âíͨ¹ýÓ×Ã×¹Ù·½ÀûÓÃÉ̵êGetApps´«²¼£¬£¬£¬£¬£¬ÀûÓÃTensorFlow»úе½ø½¨Ä£ÐÍ×Ô¶¯¼ì²â²¢½»»¥¸æ°×ÔªËØ£¬£¬£¬£¬£¬Òý·¢°²È«¹Ø×¢¡£¡£¡£¡£¡£¡£¸ÃľÂíѡȡÁ½ÖÖÔËÐÐģʽ£º"»ÃÓ°"ģʽͨ¹ý°µ²ØµÄWebViewä¯ÀÀÆ÷¼ÓÔØÖ¸±êÒ³Ãæ£¬£¬£¬£¬£¬½ØÈ¡ÆÁÄ»½ØÍ¼ºóÓÉTensorFlow.js·ÖÎö¸æ°×ÔªËØ£¬£¬£¬£¬£¬Ä£ÄâÓû§µã»÷£»£»£»£»£»£»£»"ÐźŴ«µÝ"ģʽÔòͨ¹ýWebRTC´«ÊäʵʱÊÓÆµÁ÷ÖÁ¹¥»÷Õߣ¬£¬£¬£¬£¬Ö§³ÖÔ¶³Ì²Ù×÷µã»÷¡¢¹ö¶¯µÈÐÐΪ¡£¡£¡£¡£¡£¡£ÕâÖÖ»ùÓÚÊÓ¾õ·ÖÎöµÄ»úÔìÍ»ÆÆÁË´«Í³¾ç±¾DOM½»»¥µÄÏÞ¶È£¬£¬£¬£¬£¬Äܸü¸ßЧӦ¶Ô¶¯Ì¬¸æ°×µÄƵÈԽṹ±ä¶¯¡£¡£¡£¡£¡£¡£Ä¾Âí´«²¼õè¾¶Òñ±Î£º¹¥»÷ÕßÊ×ÏȽ«Õý³£ÓÎÏ·ÀûÓÃÌá½»ÖÁGetApps£¬£¬£¬£¬£¬ºóÐøÍ¨¹ý¸üÐÂÔö³¤¶ñÒâ×é¼þ¡£¡£¡£¡£¡£¡£Dr.Web×êÑÐÏÔʾ£¬£¬£¬£¬£¬ÊÜϰȾÓÎÏ·Ô̺¬¡¶ÏÀµÁÁÔ³µÊÖ£ººÚÊÖµ³¡·£¨6.1Íò´ÎÏÂÔØ£©¡¢¡¶¿É°®³èÎïÎÝ¡·£¨3.4Íò´ÎÏÂÔØ£©µÈ£¬£¬£¬£¬£¬¸²¸Ç¶à¸öÈȵãÓÎÏ·¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ä¾Âí»¹Í¨¹ýµÚÈý·½APKÍøÕ¾£¨ÈçApkmody¡¢Moddroid£©¡¢TelegramƵ·¼°Õ¼ÓÐ2.4Íò¶©ÔÄÕßµÄDiscord·þÎñÆ÷À©É¢£¬£¬£¬£¬£¬Éæ¼°Spotify Pro¡¢Netflix modµÈÅú¸Ä°æÀûÓᣡ£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-android-malware-uses-ai-to-click-on-hidden-browser-ads/
6. Î÷°àÑÀPcComponentes·ñ¶¨1600Íò¿Í»§Êý¾Ýй¶
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬Î÷°àÑÀ¿Æ¼¼ÁãÊÛÉÌPcComponentes½üÈÕ·ñ¶¨ÆäϵͳÔâ·ê´ó¹æÄ£Êý¾Ýй¶ӰÏì1600Íò¿Í»§µÄ˵·¨£¬£¬£¬£¬£¬µ«Ö¤ÊµÔâ·êײ¿â¹¥»÷¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯"daghetiaw"Ðû³ÆÇÔÈ¡¸Ã¹«Ë¾1630ÍòÌõ¿Í»§¼Í¼£¬£¬£¬£¬£¬²¢Ð¹Â¶50ÍòÌõÑù±¾£¬£¬£¬£¬£¬Ôü×Ҽͼ´ý¼Û¶ø¹Á¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¶©µ¥ÏêÇé¡¢ÏÖʵµØÖ·¡¢È«Ãû¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢²úÆ·ÓûÍûÇåµ¥¼°ZendeskÖ§³Ö¶Ô»°¼Í¼¡£¡£¡£¡£¡£¡£PcComponentesÔÚµ÷²éºóÉêÃ÷£¬£¬£¬£¬£¬ÆäÊý¾Ý¿âºÍÄÚ²¿ÏµÍ³Î´·¢ÏÖ·¸·¨½Ó¼ûÖ¤¾Ý£¬£¬£¬£¬£¬Ç¿µ÷"1600ÍòÊÜÓ°Ïì¿Í»§"Êý×Ö²»Êµ£¬£¬£¬£¬£¬Òò»îÔ¾ÕË»§ÊýÁ¿Ô¶µÍÓÚ´Ë£¬£¬£¬£¬£¬ÇÒϵͳÖдÓδ´æ´¢²ÆÕþÐÅÏ¢»ò¿Í»§ÃÜÂë¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¹«Ë¾ÈϿɼì²âµ½×²¿â¹¥»÷ºÛ¼££¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÆäËûƽ̨й¶µÄÓÊÏäÃÜÂë×éºÏ£¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯¹¤¾ß³¢ÊԵǼPcComponentesÕË»§¡£¡£¡£¡£¡£¡£Íþвµý±¨¹«Ë¾Hudson Rock·ÖÎö·¢ÏÖ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜͨ¹ýϰȾÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÍÆËã»úÍøÂçµÇ¼ƾ֤£¬£¬£¬£¬£¬²¿ÃżÍ¼¿É×·ÒäÖÁ2020Äê¡£¡£¡£¡£¡£¡£ÆäÑéÖ¤µÄÁù¸öÓÊÏä¾ùÔÚÒÑÖªÇÔÃÜÈÕÖ¾ÖдæÔÚ£¬£¬£¬£¬£¬Ö¤Êµ¹¥»÷Ó뺹Çàй¶Êý¾Ý´æÔÚ¹ØÁª¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/online-retailer-pccomponentes-says-data-breach-claims-are-fake/


¾©¹«Íø°²±¸11010802024551ºÅ