˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î

Ðû²¼Ê±¼ä 2026-03-05

1. ˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î


3ÔÂ4ÈÕ £¬£¬£¬£¬£¬Ë¼¿Æ¹«Ë¾¿ËÈÕÐÞ¸´ÁËÆäÇå¾²·À»ðǽÖÎÀíÖÐÐÄ£¨FMC£©ÖÐÁ½¸ö×î¸ß¼¶±ð£¨CVSSÆÀ·Ö¾ùΪ10.0£©µÄÑÏÖØÎó²î £¬£¬£¬£¬£¬ÕâÁ½¸öÎó²îÈô±»Ê¹ÓÿÉÄܵ¼Ö¹¥»÷ÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î±àºÅΪCVE-2026-20079 £¬£¬£¬£¬£¬ÊôÓÚÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚFMCÆô¶¯Ê±½¨ÉèµÄϵͳÀú³Ì±£´æÈ±ÏÝ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇó £¬£¬£¬£¬£¬ÈƹýWeb½çÃæµÄÉí·ÝÑéÖ¤»úÖÆ £¬£¬£¬£¬£¬Ö±½ÓÖ´Ðо籾Îļþ²¢»ñÈ¡µ×²ã²Ù×÷ϵͳµÄrootȨÏÞ¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²î±àºÅΪCVE-2026-20131 £¬£¬£¬£¬£¬ÎªÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬£¬£¬£¬£¬Í¬Ê±Ó°ÏìFMC¼°Ë¼¿ÆÇå¾²ÔÆ¿ØÖÆ£¨SCC£©·À»ðǽÖÎÀí¹¦Ð§¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓɲ»Çå¾²µÄJava·´ÐòÁл¯²Ù×÷Òý·¢ £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÏòWebÖÎÀí½çÃæ·¢ËͶñÒâÐòÁл¯Java¹¤¾ß £¬£¬£¬£¬£¬´¥·¢·´ÐòÁл¯Àú³Ì²¢ÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ £¬£¬£¬£¬£¬ÏÖÔÚÉÐδ·¢Ã÷ÕâÁ½¸öÎó²î±»¹ûÕæÅû¶»òÏÖʵʹÓõļ£Ï󡣡£¡£¡£¡£¡£µ«¼øÓÚÎó²îµÄ¸ßΣÐÔ×Ó £¬£¬£¬£¬£¬Ë¼¿ÆÇ¿µ÷±ØÐèͨ¹ý¹Ù·½²¹¶¡¾ÙÐÐÐÞ¸´ £¬£¬£¬£¬£¬Ä¿½ñÎÞÈκÎÔÝʱ½â¾ö¼Æ»®»ò±äͨҪÁì¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/188921/security/cisco-fixes-maximum-severity-secure-fmc-bugs-threatening-firewall-security.html


2. FreeScoutЧÀĮ́ƽ̨ÏÖÁãµã»÷¸ßΣRCEÎó²î


3ÔÂ4ÈÕ £¬£¬£¬£¬£¬FreeScout¿ªÔ´×ÊÖų́ƽ̨¿ËÈÕ±»ÆØ±£´æ×î¸ß¼¶±ðÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28289£© £¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐèÓû§½»»¥»òÉí·ÝÑéÖ¤¼´¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ¸½¼þʵÏÖÁãµã»÷¹¥»÷ £¬£¬£¬£¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¸ÃÎó²îÈÆ¹ýÁË´ËǰCVE-2026-27636Îó²îµÄÐÞ¸´»úÖÆ £¬£¬£¬£¬£¬Ô­ÐÞ¸´Í¨¹ýÏÞÖÆÎļþÀ©Õ¹Ãû×èֹΣÏÕÉÏ´« £¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷ £¬£¬£¬£¬£¬ÔÚÎļþÃûǰÌí¼ÓÁã¿í¶È¿Õ¸ñ×Ö·û¿ÉÈÆ¹ýÑéÖ¤¡£¡£¡£¡£¡£¡£¸Ã×Ö·û±»ÊÓΪ²»¿É¼ûÄÚÈÝ £¬£¬£¬£¬£¬ºóÐø´¦Öóͷ£»áɾ³ý¸Ã×Ö·û £¬£¬£¬£¬£¬Ê¹ÎļþÉúÑÄΪµãÎļþ £¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô­Îó²îʹÓᣡ£¡£¡£¡£¡£FreeScout×÷ΪZendesk/Help ScoutµÄ×ÔÍйÜÌæ»»¼Æ»® £¬£¬£¬£¬£¬ÊÇÆÕ±éʹÓõĿªÔ´Æ½Ì¨ £¬£¬£¬£¬£¬GitHub¿ÍÕ»ÓµÓÐ4100ÐDZꡢ620+·ÖÖ§ £¬£¬£¬£¬£¬ShodanɨÃèÏÔʾ³¬1100¸ö¹ûÕæÌ»Â¶ÊµÀý¡£¡£¡£¡£¡£¡£Îó²îÓ°ÏìËùÓÐ1.8.206¼°¸üÔç°æ±¾ £¬£¬£¬£¬£¬¿Éͨ¹ý·¢ËÍÖÁFreeScoutÉèÖÃÓÊÏäµÄ¶ñÒ⸽¼þ´¥·¢ £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýWeb½çÃæ»á¼ûÓÐÓÃÔØºÉ¼´¿ÉÖ´ÐÐÏÂÁî £¬£¬£¬£¬£¬×é³ÉÁãµã»÷Îó²î¡£¡£¡£¡£¡£¡£FreeScoutÍŶӽ¨ÒéÁ¬Ã¦Éý¼¶ÖÁ1.8.207°æ±¾ £¬£¬£¬£¬£¬Í¬Ê±OX ResearchÔö²¹½¨Òé½ûÓÃApacheÉèÖÃÖеġ°AllowOverrideAll¡±ÒÔÔöÇ¿·À»¤¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/


3. ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPassÔâÍøÂç´¹ÂÚ¹¥»÷


3ÔÂ4ÈÕ £¬£¬£¬£¬£¬ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPass¿ËÈÕ·¢³öÇå¾²ÖÒÑÔ £¬£¬£¬£¬£¬Ö¸³öÆäÓû§ÕýÔâÊÜÐÂÒ»Âָ߷ÂÕæÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì"LastPassÖ§³Ö"ÏÔʾÃû³ÆµÄµç×ÓÓʼþ £¬£¬£¬£¬£¬Ä£Äâ¹Ù·½Óë¿Í»§Ö§³ÖÍŶӵÄÄÚ²¿¶Ô»°³¡¾° £¬£¬£¬£¬£¬ÓÕµ¼Óû§µã»÷"±¨¸æ¿ÉÒɻ""×÷·Ï×°±¸"µÈαװÁ´½Ó¡£¡£¡£¡£¡£¡£ÕâЩÓʼþÖ÷ÌâÈ«ÐÄÉè¼Æ £¬£¬£¬£¬£¬°üÀ¨"¸ü¸ÄÕË»§Ö÷ÒªÓÊÏäÇëÇó"µÈ¿´Ëƹٷ½µÄת·¢¶Ô»°ÄÚÈÝ £¬£¬£¬£¬£¬ÖÆÔì½ôÆÈÆø·Õ´ÙʹÓû§¿ìËÙÏìÓ¦¡£¡£¡£¡£¡£¡£µã»÷Á´½Óºó £¬£¬£¬£¬£¬Óû§»á±»Öض¨ÏòÖÁ"verify-lastpass[.]com"µÈÓòÃûϵÄÐéαµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÓë¹Ù·½½çÃæ¸ß¶ÈÏàËÆ £¬£¬£¬£¬£¬×¨ÃÅÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Í¨¹ý¶à¸ö·¢¼þÈ˵صãºÍÖ÷ÌâÐбäÌåÔöÇ¿¿ÉÐÅ¶È £¬£¬£¬£¬£¬´ó¶¼·¢¼þµØµãÀ´×Ô±»ÈëÇÖÍøÕ¾»ò·ÅÆúÓòÃû £¬£¬£¬£¬£¬½öͨ¹ýÏÔʾÃû³ÆÎ±×°³É¹Ù·½¡£¡£¡£¡£¡£¡£LastPassÔÚÍþвÇ鱨±¨¸æÖÐÇ¿µ÷ £¬£¬£¬£¬£¬Æä»ù´¡ÉèʩδÊÜÈκÎË𺦠£¬£¬£¬£¬£¬ÏµÍ³Ç徲δÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¹«Ë¾Ã÷È·ÌáÐÑÓû§£º¹Ù·½¿Í·þ¾ø²»»áË÷ÒªÖ÷ÃÜÂë £¬£¬£¬£¬£¬Óû§Ó¦ÑϿᱣÃÜÖ÷ÃÜÂë¡£¡£¡£¡£¡£¡£Õë¶Ô´Ë´Î¹¥»÷ £¬£¬£¬£¬£¬LastPassÕýÁªºÏµÚÈý·½ÏàÖúͬ°é½ôÆÈ¹Ø±Õ´¹ÂÚÍøÕ¾ £¬£¬£¬£¬£¬²¢ºôÓõÓû§½«¿ÉÒÉͨѶ¾Ù±¨ÖÁ"mailto:abuse@lastpass.com"¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-lastpass-support-email-threads-try-to-steal-vault-passwords/


4. HungerRushÔâÀÕË÷¹¥»÷ £¬£¬£¬£¬£¬¿Í»§Êý¾ÝÃæÁÙÍþв


3ÔÂ4ÈÕ £¬£¬£¬£¬£¬²ÍÒûÊÖÒÕÌṩÉÌHungerRush¿ËÈÕÔâÓöÀÕË÷¹¥»÷ £¬£¬£¬£¬£¬ÍþвÐÐΪÕßͨ¹ýαÔì¹Ù·½ÓÊÏäÏò²ÍÌüÖ÷¹Ë·¢ËͶà·âÀÕË÷Óʼþ £¬£¬£¬£¬£¬Éù³ÆÈô²»»ØÓ¦½«Ð¹Â¶Êý°ÙÍò¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£ÕâЩÓʼþͨ¹ýTwilio SendGridƽ̨·¢ËÍ £¬£¬£¬£¬£¬¸ÃЧÀÍ´ËǰÓÃÓÚ·¢ËÍHungerRush²ÍÌüÊÕÌõ £¬£¬£¬£¬£¬ÇÒͨ¹ýÁËSPF¡¢DKIMºÍDMARCÉí·ÝÑéÖ¤ £¬£¬£¬£¬£¬ÔöÇ¿ÁËÓʼþ¿ÉÐŶÈ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃmailto:support@hungerrush.comºÍmailto:2019@hungerrush.comµÈµØµã £¬£¬£¬£¬£¬ÖÒÑÔHungerRush×èÖ¹ºöÊÓÀÕË÷ÒªÇó £¬£¬£¬£¬£¬²»È»½«Î£¼°¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£HungerRushЧÀÍÓÚÁè¼Ý16,000¼Ò²ÍÌü £¬£¬£¬£¬£¬°üÀ¨Sbarro¡¢Jet's PizzaµÈ×ÅÃûÆ·ÅÆ £¬£¬£¬£¬£¬ÆäPOS¡¢ÔÚÏß¶©¹º¼°Ö§¸¶´¦Öóͷ£ÏµÍ³±»ÆÕ±éʹÓᣡ£¡£¡£¡£¡£¹¥»÷ÕßÐû³Æ¿É»á¼û¿Í»§ÐÕÃû¡¢ÓÊÏä¡¢ÃÜÂë¡¢µØµã¡¢µç»°¡¢³öÉúÈÕÆÚ¼°ÐÅÓÿ¨ÐÅÏ¢ £¬£¬£¬£¬£¬µ«HungerRush»ØÓ¦³Æ £¬£¬£¬£¬£¬´Ë´ÎÊÂÎñ½öÉæ¼°µç×ÓÓʼþÓªÏúЧÀÍÕË»§±»ÈëÇÖ £¬£¬£¬£¬£¬Î´Ð¹Â¶Ãô¸ÐÐÅÏ¢ÈçÃÜÂë¡¢Ö§¸¶¿¨Êý¾Ý £¬£¬£¬£¬£¬ÇÒÆäϵͳ²»´æ´¢ÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷ £¬£¬£¬£¬£¬Ð¹Â¶µÄ¿Í»§ÁªÏµÐÅÏ¢±»ÓÃÓÚ·¢ËÍδ¾­ÊÚȨÓʼþ £¬£¬£¬£¬£¬µ«ÎÞÖ¤¾ÝÏÔʾÆäËûϵͳÔâÈëÇÖ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/


5. ¹ú¼ÊÁªºÏÐж¯²é·âLeakBaseÍøÂç·¸·¨ÂÛ̳


3ÔÂ4ÈÕ £¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÁªºÏÅ·ÖÞÐ̾¯×éÖ¯µÈ14¹úÖ´·¨»ú¹¹ £¬£¬£¬£¬£¬ÓÚ3ÔÂ3ÈÕÖÁ4ÈÕ¿ªÕ¹"йÃÜÐж¯" £¬£¬£¬£¬£¬Àֳɲé·âÍøÂç·¸·¨ÂÛ̳LeakBase¡£¡£¡£¡£¡£¡£¸ÃÂÛ̳×÷ΪºÚ¿Í¹¤¾ßÉúÒâ¡¢±»µÁÊý¾ÝÉúÒâµÄ½¹µãƽ̨ £¬£¬£¬£¬£¬×Ô2021ÄêÓÉARESÍþв×éÖ¯Ö§³ÖÔËÓªÒÔÀ´ £¬£¬£¬£¬£¬Óû§¹æÄ£Òѳ¬14.2Íò £¬£¬£¬£¬£¬ÌṩÊý¾Ý¿â»á¼û¡¢Îó²îʹÓÃÉúÒâ¡¢µ£±£Ö§¸¶ÏµÍ³¼°ºÚ¿ÍÊÖÒÕÌÖÂÛÇø £¬£¬£¬£¬£¬º­¸ÇÉç»á¹¤³Ìѧ¡¢ÃÜÂëѧµÈרÌâ¡£¡£¡£¡£¡£¡£Ðж¯Ê±´ú £¬£¬£¬£¬£¬Ö´·¨Ö°Ô±ÔÚÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢±ÈÀûʱµÈ8¹úÖ´ÐÐËѲéÁʵÑé¾Ð²¶²¢¿ªÕ¹"ÇÃÃÅ̸»°" £¬£¬£¬£¬£¬È«Çò¹²ÌᳫԼ100´ÎÖ´·¨Ðж¯ £¬£¬£¬£¬£¬´¦·Ö37Ãû×î»îÔ¾Óû§¡£¡£¡£¡£¡£¡£LeakBaseµÄÁ½¸öÓòÃûÏÖÒѱ»FBI½ÓÊÜ £¬£¬£¬£¬£¬ÓòÃûЧÀÍÆ÷Çл»Îªns1.fbi.seized.govºÍns2.fbi.seized.gov £¬£¬£¬£¬£¬Ò³ÃæÏÔʾ²é·â֪ͨ £¬£¬£¬£¬£¬Ç¿µ÷ÂÛ̳ËùÓÐÄÚÈݰüÀ¨Óû§ÕË»§¡¢Ìû×Ó¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Ë½Ðż°IPÈÕÖ¾Òѱ»Çå¾²ÉúÑÄ £¬£¬£¬£¬£¬½«ÓÃÓÚºóÐøÈ¡Ö¤ÊӲ졣¡£¡£¡£¡£¡£ÈκÎÊÔͼ»á¼û»ò×ÌÈÅÍøÕ¾µÄÐÐΪ¿ÉÄÜ×é³ÉÐÂ×ï¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-seizes-leakbase-cybercrime-forum-data-of-142-000-members/


6. ŦԼÂóµÏÑ·¹ã³¡»¨Ô°ÔâCl0pÀÕË÷¹¥»÷


3ÔÂ3ÈÕ £¬£¬£¬£¬£¬Å¦Ô¼µØ±êÂóµÏÑ·¹ã³¡»¨Ô°£¨MSG£©¿ËÈÕÈ·ÈÏÔâÓöÖØ´óÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬Éæ¼°2025ÄêÕë¶Ô¼×¹ÇÎĵç×ÓÉÌÎñÌ×¼þ£¨EBS£©µÄ´ó¹æÄ£ÍøÂç·¸·¨»î¶¯¡£¡£¡£¡£¡£¡£×÷ΪȫÇòÖøÃû¶à¹¦Ð§ÊÒÄÚ³¡¹Ý £¬£¬£¬£¬£¬MSGλÓÚŦԼÊÐ £¬£¬£¬£¬£¬ÊÇNBAÄá¿Ë˹¶ÓºÍNHLÓÎÆï±ø¶ÓÖ÷³¡ £¬£¬£¬£¬£¬³Ð°ìÌåÓýÈüÊ¡¢Ñݳª»á¼°ÓéÀֻ £¬£¬£¬£¬£¬´Ë´ÎÊÂÎñʹÆä³ÉΪʹÓü׹ÇÎÄEBSÎó²îʵÑéºÚ¿Í¹¥»÷µÄÖÚ¶àÊܺ¦×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£2025Äê11Ô £¬£¬£¬£¬£¬Cl0pÀÕË÷Èí¼þ×é֯ʹÓü׹ÇÎÄEBSÖеÄÁãÈÕÎó²îCVE-2025-61882ÈëÇÖ°üÀ¨MSGÔÚÄÚµÄ100¶à¼Ò»ú¹¹¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ØÖƼ׹ÇÎIJ¢·¢´¦Öóͷ£×é¼þ £¬£¬£¬£¬£¬½ø¶øÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£MSG¾Ü¾øÖ§¸¶Êê½ðºó £¬£¬£¬£¬£¬Cl0pй¶³¬210GB¹«Ë¾´æµµÎļþ¡£¡£¡£¡£¡£¡£¾ÝMSGÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»µÄ֪ͨ £¬£¬£¬£¬£¬¼×¹ÇÎÄEBSÓɹ©Ó¦ÉÌÍйÜÖÎÀí £¬£¬£¬£¬£¬ÓÃÓÚ²¿·ÖÈËÁ¦ºÍ²ÆÎñÔËÓª¡£¡£¡£¡£¡£¡£¹©Ó¦ÉÌÊÓ²ìÈ·¶¨ £¬£¬£¬£¬£¬Î´¾­ÊÚȨÕßÓÚ2025Äê8Ô»ñÈ¡²¿·ÖÓ¦ÓÃÊý¾Ý £¬£¬£¬£¬£¬Éæ¼°ÕÐÆ¸»ò¸¶¿îÏà¹ØµÄÓªÒµ¼Í¼Îļþ £¬£¬£¬£¬£¬ÆäÖаüÀ¨ÐÕÃûºÍÉç»á°ü¹ÜºÅµÄÎļþÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¼×¹ÇÎÄÒÑÓÚ2025Äê10ÔÂÐû²¼½ôÆÈ²¹¶¡ÐÞ¸´¸ÃÎó²î £¬£¬£¬£¬£¬µ«´ËǰÒÑÓдó×ÚÊý¾Ýй¶¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/188814/cyber-crime/oracle-ebs-2025-campaign-impacts-madison-square-garden-sensitive-data-leaked.html