˼¿Æ´¹Î£½¨¸´FMCƽ̨Á½¸ö¸ßΣ·ì϶
°ä²¼¹¦·ò 2026-03-051. ˼¿Æ´¹Î£½¨¸´FMCƽ̨Á½¸ö¸ßΣ·ì϶
3ÔÂ4ÈÕ£¬£¬£¬£¬£¬Ë¼¿Æ¹«Ë¾½üÈÕ½¨¸´ÁËÆä°²È«·À»ðǽÖÎÀíÖÐÐÄ£¨FMC£©ÖÐÁ½¸öµÚÒ»Á÷±ð£¨CVSSÆÀ·Ö¾ùΪ10.0£©µÄÑϳÁ·ì϶£¬£¬£¬£¬£¬ÕâÁ½¸ö·ì϶Èô±»ÀûÓÿÉÄܵ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔìÉ豸¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶±àºÅΪCVE-2026-20079£¬£¬£¬£¬£¬ÊôÓÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚFMCÆô¶¯Ê±´´½¨µÄϵͳ¹ý³Ì´æÔÚȱµã£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇ󣬣¬£¬£¬£¬ÈƹýWeb½çÃæµÄÉí·ÝÑéÖ¤»úÔ죬£¬£¬£¬£¬Ö±½ÓÖ´Ðо籾Îļþ²¢»ñÈ¡µ×²ã²Ù×÷ϵͳµÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶±àºÅΪCVE-2026-20131£¬£¬£¬£¬£¬ÎªÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬Í¬Ê±Ó°ÏìFMC¼°Ë¼¿Æ°²È«ÔƽÚÔ죨SCC£©·À»ðǽÖÎÀíÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Óɲ»°²È«µÄJava·´ÐòÁл¯²Ù×÷Òý·¢£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÏòWebÖÎÀí½çÃæ·¢ËͶñÒâÐòÁл¯Java¶ÔÏ󣬣¬£¬£¬£¬´¥·¢·´ÐòÁл¯¹ý³Ì²¢ÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©°µÊ¾£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδ·¢ÏÖÕâÁ½¸ö·ì϶±»¹«¿ªÅû¶»òÏÖʵÀûÓõļ£Ï󡣡£¡£¡£¡£¡£¡£¡£µ«¼øÓÚ·ì϶µÄ¸ßΣÐÔÖÊ£¬£¬£¬£¬£¬Ë¼¿ÆÇ¿µ÷±ØÐëͨ¹ý¹Ù·½²¹¶¡½øÐн¨¸´£¬£¬£¬£¬£¬µ±Ç°ÎÞÈκÎһʱ½â¾ö¹æ»®»ò±äͨ²½Öè¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/188921/security/cisco-fixes-maximum-severity-secure-fmc-bugs-threatening-firewall-security.html
2. FreeScout·þÎñ̨ƽ̨ÏÖÁãµã»÷¸ßΣRCE·ì϶
3ÔÂ4ÈÕ£¬£¬£¬£¬£¬FreeScout¿ªÔ´Ô®ÊǪ̈ƽ̨½üÈÕ±»ÆØ´æÔÚµÚÒ»Á÷±ðÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2026-28289£©£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐèÓû§½»»¥»òÉí·ÝÑéÖ¤¼´¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ¸½¼þʵÏÖÁãµã»÷¹¥»÷£¬£¬£¬£¬£¬Ö±½Ó½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ìÏ¶ÈÆ¹ýÁË´ËǰCVE-2026-27636·ì϶µÄ½¨¸´»úÔ죬£¬£¬£¬£¬Ô½¨¸´Í¨¹ýÏÞ¶ÈÎļþÀ©´óÃû×èֹΣÏÕÉÏ´«£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬ÔÚÎļþÃûǰÔö³¤Áã¿í¶È¿Õ¸ñ×Ö·û¿ÉÈÆ¹ýÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×Ö·û±»ÊÓΪ²»Ë½¼ûÄÚÈÝ£¬£¬£¬£¬£¬ºóÐø´¦ÖòÇɾ³ý¸Ã×Ö·û£¬£¬£¬£¬£¬Ê¹Îļþ±£ÁôΪµãÎļþ£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô·ì϶ÀûÓᣡ£¡£¡£¡£¡£¡£¡£FreeScout×÷ΪZendesk/Help ScoutµÄ×ÔÍйܴúÌæ¹æ»®£¬£¬£¬£¬£¬ÊÇ¿í·ºÊ¹ÓõĿªÔ´Æ½Ì¨£¬£¬£¬£¬£¬GitHub²Ö¿âÕ¼ÓÐ4100ÐDZꡢ620+·ÖÖ§£¬£¬£¬£¬£¬ShodanɨÃèÏÔʾ³¬1100¸ö¹«¿ªÂ¶³öÊ·ý¡£¡£¡£¡£¡£¡£¡£¡£·ì϶ӰÏìËùÓÐ1.8.206¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬¿Éͨ¹ý·¢ËÍÖÁFreeScoutÅäÖÃÓÊÏäµÄ¶ñÒ⸽¼þ´¥·¢£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýWeb½çÃæ½Ó¼ûÓÐÐ§ÔØºÉ¼´¿ÉÖ´ÐкÅÁ£¬£¬£¬£¬×é³ÉÁãµã»÷·ì϶¡£¡£¡£¡£¡£¡£¡£¡£FreeScoutÍŶӽ¨ÒéÁ¢¼´Éý¼¶ÖÁ1.8.207°æ±¾£¬£¬£¬£¬£¬Í¬Ê±OX Research²¹³ä½¨Òé½ûÓÃApacheÅäÖÃÖеġ°AllowOverrideAll¡±ÒÔ¼ÓÇ¿·À»¤¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/
3. ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPassÔâÍøÂç´¹µö¹¥»÷
3ÔÂ4ÈÕ£¬£¬£¬£¬£¬ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPass½üÈÕ·¢³ö°²È«ÖҸ棬£¬£¬£¬£¬Ö¸³öÆäÓû§ÕýÔâ·êÐÂÒ»Âָ߷ÂÕæÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì"LastPassÖ§³Ö"ÏÔʾÃû³ÆµÄµç×ÓÓʼþ£¬£¬£¬£¬£¬·ÂÕÕ¹Ù·½Óë¿Í»§Ö§³ÖÍŶӵÄÄÚ²¿¶Ô»°³¡¾°£¬£¬£¬£¬£¬ÓÕµ¼Óû§µã»÷"»ã±¨¿ÉÒɻ""³·ÏúÉ豸"µÈ¼Ù×°Á´½Ó¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÓʼþÖ÷Ì⾫ÐÄÉè¼Æ£¬£¬£¬£¬£¬Ô̺¬"¸ü¸ÄÕË»§ÖØÒªÓÊÏäÒªÇó"µÈ¿´Ëƹٷ½µÄת·¢¶Ô»°ÄÚÈÝ£¬£¬£¬£¬£¬Ôì×÷´¹Î£·ÕΧ´ÙʹÓû§¼±¾çÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¡£µã»÷Á´½Óºó£¬£¬£¬£¬£¬Óû§»á±»³Á¶¨ÏòÖÁ"verify-lastpass[.]com"µÅ×òÃûϵÄÐéαµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÓë¹Ù·½½çÃæ¸ß¶ÈÀàËÆ£¬£¬£¬£¬£¬×¨ÃÅÓÃÓÚÇÔÈ¡Óû§Í´´¦¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Í¨¹ý¶à¸ö·¢¼þÈ˵ØÖ·ºÍÖ÷ÌâÐбäÌå¼ÓÇ¿¿ÉÐŶȣ¬£¬£¬£¬£¬ÎÞÊý·¢¼þµØÖ·À´×Ô±»ÈëÇÖÍøÕ¾»ò°Î³ýÓòÃû£¬£¬£¬£¬£¬½öͨ¹ýÏÔʾÃû³Æ¼Ù×°³É¹Ù·½¡£¡£¡£¡£¡£¡£¡£¡£LastPassÔÚÍþвµý±¨»ã±¨ÖÐÇ¿µ÷£¬£¬£¬£¬£¬Æä»ù´¡ÉèʩδÊÜÈκÎÇÖº¦£¬£¬£¬£¬£¬ÏµÍ³°²È«Î´ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ã÷È·ÌáÐÑÓû§£º¹Ù·½¿Í·þ¾ø²»»áË÷ÒªÖ÷ÃÜÂ룬£¬£¬£¬£¬Óû§Ó¦Ñϸñ±£ÃÜÖ÷ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Õë¶ÔÕâ´Î¹¥»÷£¬£¬£¬£¬£¬LastPassÕý½áºÏµÚÈý·½ºÏ×÷ͬ°é´¹Î£¹Ø¹Ø´¹µöÍøÕ¾£¬£¬£¬£¬£¬²¢ºôÓõÓû§½«¿ÉÒÉͨѶ¾Ù±¨ÖÁ"mailto:abuse@lastpass.com"¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-lastpass-support-email-threads-try-to-steal-vault-passwords/
4. HungerRushÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬¿Í»§Êý¾ÝÃæ¶ÔÍþв
3ÔÂ4ÈÕ£¬£¬£¬£¬£¬²ÍÒû¼¼ÊõÌṩÉÌHungerRush½üÈÕÔâ·êÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ÍþвÐÐΪÕßͨ¹ýαÔì¹Ù·½ÓÊÏäÏò²ÍÌü¹Ë¿Í·¢ËͶà·âÀÕË÷Óʼþ£¬£¬£¬£¬£¬Ðû³ÆÈô²»»ØÓ¦½«Ð¹Â¶Êý°ÙÍò¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÓʼþͨ¹ýTwilio SendGridƽ̨·¢ËÍ£¬£¬£¬£¬£¬¸Ã·þÎñ´ËǰÓÃÓÚ·¢ËÍHungerRush²ÍÌüÊÕÌõ£¬£¬£¬£¬£¬ÇÒͨ¹ýÁËSPF¡¢DKIMºÍDMARCÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬¼ÓÇ¿ÁËÓʼþ¿ÉÐŶȡ£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃmailto:support@hungerrush.comºÍmailto:2019@hungerrush.comµÈµØÖ·£¬£¬£¬£¬£¬ÖÒ¸æHungerRushÖÕ³¡ºöÊÓÀÕË÷ÒªÇ󣬣¬£¬£¬£¬²»È»½«Î£¼°¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£HungerRush·þÎñÓÚ³¬¹ý16,000¼Ò²ÍÌü£¬£¬£¬£¬£¬Ô̺¬Sbarro¡¢Jet's PizzaµÈ³ÛÃûÆ·ÅÆ£¬£¬£¬£¬£¬ÆäPOS¡¢ÔÚÏß¶©¹º¼°Ö§¸¶´¦ÖÃϵͳ±»¿í·ºÊ¹Óᣡ£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐû³Æ¿É½Ó¼û¿Í»§ÐÕÃû¡¢ÓÊÏä¡¢ÃÜÂë¡¢µØÖ·¡¢µç»°¡¢µ®ÉúÈÕÆÚ¼°ÐÅÓþ¿¨ÐÅÏ¢£¬£¬£¬£¬£¬µ«HungerRush»ØÓ¦³Æ£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ½öÉæ¼°µç×ÓÓʼþÓªÏú·þÎñÕË»§±»ÈëÇÖ£¬£¬£¬£¬£¬Î´Ð¹Â¼ûô¸ÐÐÅÏ¢ÈçÃÜÂë¡¢Ö§¸¶¿¨Êý¾Ý£¬£¬£¬£¬£¬ÇÒÆäϵͳ²»´æ´¢ÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷£¬£¬£¬£¬£¬Ð¹Â¶µÄ¿Í»§ÁªÏµÐÅÏ¢±»ÓÃÓÚ·¢ËÍδ¾ÊÚȨÓʼþ£¬£¬£¬£¬£¬µ«ÎÞÖ¤¾ÝÏÔʾÆäËûϵͳÔâÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/
5. ¹ú¼Ê½áºÏÐж¯²é·âLeakBaseÍøÂç·¸×ïÂÛ̳
3ÔÂ4ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½áºÏÅ·ÖÞÐ̾¯×éÖ¯µÈ14¹ú·¨ÂÉ»ú¹¹£¬£¬£¬£¬£¬ÓÚ3ÔÂ3ÈÕÖÁ4ÈÕ·¢Õ¹"йÃÜÐж¯"£¬£¬£¬£¬£¬³É¹¦²é·âÍøÂç·¸×ïÂÛ̳LeakBase¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÂÛ̳×÷ΪºÚ¿Í¹¤¾ßÂòÂô¡¢±»µÁÊý¾ÝÂòÂôµÄÖ÷ÌâÆ½Ì¨£¬£¬£¬£¬£¬×Ô2021ÄêÓÉARESÍþв×éÖ¯Ö§³ÖÔËÓªÒÔÀ´£¬£¬£¬£¬£¬Óû§¹æÄ£Òѳ¬14.2Íò£¬£¬£¬£¬£¬ÌṩÊý¾Ý¿â½Ó¼û¡¢·ì϶ÀûÓÃÂòÂô¡¢µ£±£Ö§¸¶ÏµÍ³¼°ºÚ¿Í¼¼Êõ»áÉÌÇø£¬£¬£¬£¬£¬º¸ÇÉç»á¹¤³Ìѧ¡¢ÃÜÂëѧµÈרÌâ¡£¡£¡£¡£¡£¡£¡£¡£Ðж¯ÆÚ¼ä£¬£¬£¬£¬£¬·¨ÂÉÈËÔ±ÔÚÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢±ÈÀûʱµÈ8¹úÖ´ÐÐËѲéÁî¡¢Ö´ÐпÛÁô²¢·¢Õ¹"ÇÃÃÅ·¢ÑÔ"£¬£¬£¬£¬£¬È«Çò¹²ÌáÒéÔ¼100´Î·¨ÂÉÐж¯£¬£¬£¬£¬£¬´¦·£37Ãû×î»îÔ¾Óû§¡£¡£¡£¡£¡£¡£¡£¡£LeakBaseµÄÁ½¸öÓòÃûÏÖÒѱ»FBIÊÕÊÜ£¬£¬£¬£¬£¬ÓòÃû·þÎñÆ÷Çл»Îªns1.fbi.seized.govºÍns2.fbi.seized.gov£¬£¬£¬£¬£¬Ò³ÃæÏÔʾ²é·â֪ͨ£¬£¬£¬£¬£¬Ç¿µ÷ÂÛ̳ËùÓÐÄÚÈÝÔ̺¬Óû§ÕË»§¡¢Ìû×Ó¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢Ë½Ðż°IPÈÕÖ¾Òѱ»°²È«±£Áô£¬£¬£¬£¬£¬½«ÓÃÓÚºóÐøÈ¡Ö¤µ÷²é¡£¡£¡£¡£¡£¡£¡£¡£ÈκÎÊÔͼ½Ó¼û»ò×ÌÈÅÍøÕ¾µÄÐÐΪ¿ÉÄÜ×é³ÉÐÂ×ï¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fbi-seizes-leakbase-cybercrime-forum-data-of-142-000-members/
6. ŦԼÂóµÏÑ·¹ã³¡»¨ÆÔÔâCl0pÀÕË÷¹¥»÷
3ÔÂ3ÈÕ£¬£¬£¬£¬£¬Å¦Ô¼µØ±êÂóµÏÑ·¹ã³¡»¨ÆÔ£¨MSG£©½üÈÕÈ·ÈÏÔâ·ê³Á´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Éæ¼°2025ÄêÕë¶Ô¼×¹ÇÎĵç×ÓÉÌÎñÌ×¼þ£¨EBS£©µÄ´ó¹æÄ£ÍøÂç·¸×ï»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£×÷ΪȫÇò³ÛÃû¶àÖ°ÄÜÊÒÄÚ³¡¹Ý£¬£¬£¬£¬£¬MSGλÓÚŦԼÊУ¬£¬£¬£¬£¬ÊÇNBAÄá¿Ë˹¶ÓºÍNHLÓÎÂí¶Ó¶ÓÖ÷³¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬³Ð°ìÌåÓýÈüÊ¡¢Ñݳª»á¼°ÓéÀֻ£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñʹÆä³ÉΪÀûÓü׹ÇÎÄEBS·ì϶ִÐкڿ͹¥»÷µÄ¶à¶àÊܺ¦×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£¡£¡£2025Äê11Ô£¬£¬£¬£¬£¬Cl0pÀÕË÷Èí¼þ×éÖ¯ÀûÓü׹ÇÎÄEBSÖеÄÁãÈÕ·ì϶CVE-2025-61882ÈëÇÖÔ̺¬MSGÔÚÄÚµÄ100¶à¼Ò»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß½ÚÔì¼×¹ÇÎIJ¢·¢´¦ÖÃ×é¼þ£¬£¬£¬£¬£¬½ø¶øÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£MSG»Ø¾øÖ§¸¶Êê½ðºó£¬£¬£¬£¬£¬Cl0pй¶³¬210GB¹«Ë¾´æµµÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¾ÝMSGÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬£¬£¬£¬£¬¼×¹ÇÎÄEBSÓɹ©¸øÉÌÍйÜÖÎÀí£¬£¬£¬£¬£¬ÓÃÓÚ²¿ÃÅÈËÁ¦ºÍ²ÆÕþÔËÓª¡£¡£¡£¡£¡£¡£¡£¡£¹©¸øÉ̵÷²éÈ·¶¨£¬£¬£¬£¬£¬Î´¾ÊÚȨÕßÓÚ2025Äê8Ô»ñÈ¡²¿ÃÅÀûÓÃÊý¾Ý£¬£¬£¬£¬£¬Éæ¼°ÕÐÆ¸»ò¸¶¿îÓйصÄÒµÎñ¼Í¼Îļþ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÐÕÃûºÍÉç»á±£ÏպŵÄÎļþÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¼×¹ÇÎÄÒÑÓÚ2025Äê10Ô°䲼´¹Î£²¹¶¡½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬µ«´ËǰÒÑÓдóÁ¿Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/188814/cyber-crime/oracle-ebs-2025-campaign-impacts-madison-square-garden-sensitive-data-leaked.html


¾©¹«Íø°²±¸11010802024551ºÅ