˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î

Ðû²¼Ê±¼ä 2026-03-05

1. ˼¿Æ½ôÆÈÐÞ¸´FMCƽ̨Á½¸ö¸ßΣÎó²î


3ÔÂ4ÈÕ£¬£¬£¬ £¬£¬Ë¼¿Æ¹«Ë¾¿ËÈÕÐÞ¸´ÁËÆäÇå¾²·À»ðǽÖÎÀíÖÐÐÄ£¨FMC£©ÖÐÁ½¸ö×î¸ß¼¶±ð£¨CVSSÆÀ·Ö¾ùΪ10.0£©µÄÑÏÖØÎó²î£¬£¬£¬ £¬£¬ÕâÁ½¸öÎó²îÈô±»Ê¹ÓÿÉÄܵ¼Ö¹¥»÷ÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£µÚÒ»¸öÎó²î±àºÅΪCVE-2026-20079£¬£¬£¬ £¬£¬ÊôÓÚÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚFMCÆô¶¯Ê±½¨ÉèµÄϵͳÀú³Ì±£´æÈ±ÏÝ£¬£¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬ £¬£¬ÈƹýWeb½çÃæµÄÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬ £¬£¬Ö±½ÓÖ´Ðо籾Îļþ²¢»ñÈ¡µ×²ã²Ù×÷ϵͳµÄrootȨÏÞ¡£¡£¡£¡£µÚ¶þ¸öÎó²î±àºÅΪCVE-2026-20131£¬£¬£¬ £¬£¬ÎªÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬£¬Í¬Ê±Ó°ÏìFMC¼°Ë¼¿ÆÇå¾²ÔÆ¿ØÖÆ£¨SCC£©·À»ðǽÖÎÀí¹¦Ð§¡£¡£¡£¡£¸ÃÎó²îÓɲ»Çå¾²µÄJava·´ÐòÁл¯²Ù×÷Òý·¢£¬£¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÏòWebÖÎÀí½çÃæ·¢ËͶñÒâÐòÁл¯Java¹¤¾ß£¬£¬£¬ £¬£¬´¥·¢·´ÐòÁл¯Àú³Ì²¢ÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÌåÏÖ£¬£¬£¬ £¬£¬ÏÖÔÚÉÐδ·¢Ã÷ÕâÁ½¸öÎó²î±»¹ûÕæÅû¶»òÏÖʵʹÓõļ£Ï󡣡£¡£¡£µ«¼øÓÚÎó²îµÄ¸ßΣÐÔ×Ó£¬£¬£¬ £¬£¬Ë¼¿ÆÇ¿µ÷±ØÐèͨ¹ý¹Ù·½²¹¶¡¾ÙÐÐÐÞ¸´£¬£¬£¬ £¬£¬Ä¿½ñÎÞÈκÎÔÝʱ½â¾ö¼Æ»®»ò±äͨҪÁì¡£¡£¡£¡£


https://securityaffairs.com/188921/security/cisco-fixes-maximum-severity-secure-fmc-bugs-threatening-firewall-security.html


2. FreeScoutЧÀĮ́ƽ̨ÏÖÁãµã»÷¸ßΣRCEÎó²î


3ÔÂ4ÈÕ£¬£¬£¬ £¬£¬FreeScout¿ªÔ´×ÊÖų́ƽ̨¿ËÈÕ±»ÆØ±£´æ×î¸ß¼¶±ðÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28289£©£¬£¬£¬ £¬£¬¹¥»÷ÕßÎÞÐèÓû§½»»¥»òÉí·ÝÑéÖ¤¼´¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ¸½¼þʵÏÖÁãµã»÷¹¥»÷£¬£¬£¬ £¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¸ÃÎó²îÈÆ¹ýÁË´ËǰCVE-2026-27636Îó²îµÄÐÞ¸´»úÖÆ£¬£¬£¬ £¬£¬Ô­ÐÞ¸´Í¨¹ýÏÞÖÆÎļþÀ©Õ¹Ãû×èֹΣÏÕÉÏ´«£¬£¬£¬ £¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ £¬£¬ÔÚÎļþÃûǰÌí¼ÓÁã¿í¶È¿Õ¸ñ×Ö·û¿ÉÈÆ¹ýÑéÖ¤¡£¡£¡£¡£¸Ã×Ö·û±»ÊÓΪ²»¿É¼ûÄÚÈÝ£¬£¬£¬ £¬£¬ºóÐø´¦Öóͷ£»áɾ³ý¸Ã×Ö·û£¬£¬£¬ £¬£¬Ê¹ÎļþÉúÑÄΪµãÎļþ£¬£¬£¬ £¬£¬´Ó¶ø´¥·¢Ô­Îó²îʹÓᣡ£¡£¡£FreeScout×÷ΪZendesk/Help ScoutµÄ×ÔÍйÜÌæ»»¼Æ»®£¬£¬£¬ £¬£¬ÊÇÆÕ±éʹÓõĿªÔ´Æ½Ì¨£¬£¬£¬ £¬£¬GitHub¿ÍÕ»ÓµÓÐ4100ÐDZꡢ620+·ÖÖ§£¬£¬£¬ £¬£¬ShodanɨÃèÏÔʾ³¬1100¸ö¹ûÕæÌ»Â¶ÊµÀý¡£¡£¡£¡£Îó²îÓ°ÏìËùÓÐ1.8.206¼°¸üÔç°æ±¾£¬£¬£¬ £¬£¬¿Éͨ¹ý·¢ËÍÖÁFreeScoutÉèÖÃÓÊÏäµÄ¶ñÒ⸽¼þ´¥·¢£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýWeb½çÃæ»á¼ûÓÐÓÃÔØºÉ¼´¿ÉÖ´ÐÐÏÂÁ£¬£¬ £¬£¬×é³ÉÁãµã»÷Îó²î¡£¡£¡£¡£FreeScoutÍŶӽ¨ÒéÁ¬Ã¦Éý¼¶ÖÁ1.8.207°æ±¾£¬£¬£¬ £¬£¬Í¬Ê±OX ResearchÔö²¹½¨Òé½ûÓÃApacheÉèÖÃÖеġ°AllowOverrideAll¡±ÒÔÔöÇ¿·À»¤¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mail2shell-zero-click-attack-lets-hackers-hijack-freescout-mail-servers/


3. ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPassÔâÍøÂç´¹ÂÚ¹¥»÷


3ÔÂ4ÈÕ£¬£¬£¬ £¬£¬ÃÜÂëÖÎÀíÈí¼þÌṩÉÌLastPass¿ËÈÕ·¢³öÇå¾²ÖÒÑÔ£¬£¬£¬ £¬£¬Ö¸³öÆäÓû§ÕýÔâÊÜÐÂÒ»Âָ߷ÂÕæÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì"LastPassÖ§³Ö"ÏÔʾÃû³ÆµÄµç×ÓÓʼþ£¬£¬£¬ £¬£¬Ä£Äâ¹Ù·½Óë¿Í»§Ö§³ÖÍŶӵÄÄÚ²¿¶Ô»°³¡¾°£¬£¬£¬ £¬£¬ÓÕµ¼Óû§µã»÷"±¨¸æ¿ÉÒɻ""×÷·Ï×°±¸"µÈαװÁ´½Ó¡£¡£¡£¡£ÕâЩÓʼþÖ÷ÌâÈ«ÐÄÉè¼Æ£¬£¬£¬ £¬£¬°üÀ¨"¸ü¸ÄÕË»§Ö÷ÒªÓÊÏäÇëÇó"µÈ¿´Ëƹٷ½µÄת·¢¶Ô»°ÄÚÈÝ£¬£¬£¬ £¬£¬ÖÆÔì½ôÆÈÆø·Õ´ÙʹÓû§¿ìËÙÏìÓ¦¡£¡£¡£¡£µã»÷Á´½Óºó£¬£¬£¬ £¬£¬Óû§»á±»Öض¨ÏòÖÁ"verify-lastpass[.]com"µÈÓòÃûϵÄÐéαµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¸ÃÒ³ÃæÓë¹Ù·½½çÃæ¸ß¶ÈÏàËÆ£¬£¬£¬ £¬£¬×¨ÃÅÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤¡£¡£¡£¡£¹¥»÷Õß»¹Í¨¹ý¶à¸ö·¢¼þÈ˵صãºÍÖ÷ÌâÐбäÌåÔöÇ¿¿ÉÐŶÈ£¬£¬£¬ £¬£¬´ó¶¼·¢¼þµØµãÀ´×Ô±»ÈëÇÖÍøÕ¾»ò·ÅÆúÓòÃû£¬£¬£¬ £¬£¬½öͨ¹ýÏÔʾÃû³ÆÎ±×°³É¹Ù·½¡£¡£¡£¡£LastPassÔÚÍþвÇ鱨±¨¸æÖÐÇ¿µ÷£¬£¬£¬ £¬£¬Æä»ù´¡ÉèʩδÊÜÈκÎË𺦣¬£¬£¬ £¬£¬ÏµÍ³Ç徲δÊÜÓ°Ïì¡£¡£¡£¡£¹«Ë¾Ã÷È·ÌáÐÑÓû§£º¹Ù·½¿Í·þ¾ø²»»áË÷ÒªÖ÷ÃÜÂ룬£¬£¬ £¬£¬Óû§Ó¦ÑϿᱣÃÜÖ÷ÃÜÂë¡£¡£¡£¡£Õë¶Ô´Ë´Î¹¥»÷£¬£¬£¬ £¬£¬LastPassÕýÁªºÏµÚÈý·½ÏàÖúͬ°é½ôÆÈ¹Ø±Õ´¹ÂÚÍøÕ¾£¬£¬£¬ £¬£¬²¢ºôÓõÓû§½«¿ÉÒÉͨѶ¾Ù±¨ÖÁ"mailto:abuse@lastpass.com"¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-lastpass-support-email-threads-try-to-steal-vault-passwords/


4. HungerRushÔâÀÕË÷¹¥»÷£¬£¬£¬ £¬£¬¿Í»§Êý¾ÝÃæÁÙÍþв


3ÔÂ4ÈÕ£¬£¬£¬ £¬£¬²ÍÒûÊÖÒÕÌṩÉÌHungerRush¿ËÈÕÔâÓöÀÕË÷¹¥»÷£¬£¬£¬ £¬£¬ÍþвÐÐΪÕßͨ¹ýαÔì¹Ù·½ÓÊÏäÏò²ÍÌüÖ÷¹Ë·¢ËͶà·âÀÕË÷Óʼþ£¬£¬£¬ £¬£¬Éù³ÆÈô²»»ØÓ¦½«Ð¹Â¶Êý°ÙÍò¿Í»§Êý¾Ý¡£¡£¡£¡£ÕâЩÓʼþͨ¹ýTwilio SendGridƽ̨·¢ËÍ£¬£¬£¬ £¬£¬¸ÃЧÀÍ´ËǰÓÃÓÚ·¢ËÍHungerRush²ÍÌüÊÕÌõ£¬£¬£¬ £¬£¬ÇÒͨ¹ýÁËSPF¡¢DKIMºÍDMARCÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬ÔöÇ¿ÁËÓʼþ¿ÉÐŶÈ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃmailto:support@hungerrush.comºÍmailto:2019@hungerrush.comµÈµØµã£¬£¬£¬ £¬£¬ÖÒÑÔHungerRush×èÖ¹ºöÊÓÀÕË÷ÒªÇ󣬣¬£¬ £¬£¬²»È»½«Î£¼°¿Í»§Êý¾Ý¡£¡£¡£¡£HungerRushЧÀÍÓÚÁè¼Ý16,000¼Ò²ÍÌü£¬£¬£¬ £¬£¬°üÀ¨Sbarro¡¢Jet's PizzaµÈ×ÅÃûÆ·ÅÆ£¬£¬£¬ £¬£¬ÆäPOS¡¢ÔÚÏß¶©¹º¼°Ö§¸¶´¦Öóͷ£ÏµÍ³±»ÆÕ±éʹÓᣡ£¡£¡£¹¥»÷ÕßÐû³Æ¿É»á¼û¿Í»§ÐÕÃû¡¢ÓÊÏä¡¢ÃÜÂë¡¢µØµã¡¢µç»°¡¢³öÉúÈÕÆÚ¼°ÐÅÓÿ¨ÐÅÏ¢£¬£¬£¬ £¬£¬µ«HungerRush»ØÓ¦³Æ£¬£¬£¬ £¬£¬´Ë´ÎÊÂÎñ½öÉæ¼°µç×ÓÓʼþÓªÏúЧÀÍÕË»§±»ÈëÇÖ£¬£¬£¬ £¬£¬Î´Ð¹Â¶Ãô¸ÐÐÅÏ¢ÈçÃÜÂë¡¢Ö§¸¶¿¨Êý¾Ý£¬£¬£¬ £¬£¬ÇÒÆäϵͳ²»´æ´¢ÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¹«Ë¾Ç¿µ÷£¬£¬£¬ £¬£¬Ð¹Â¶µÄ¿Í»§ÁªÏµÐÅÏ¢±»ÓÃÓÚ·¢ËÍδ¾­ÊÚȨÓʼþ£¬£¬£¬ £¬£¬µ«ÎÞÖ¤¾ÝÏÔʾÆäËûϵͳÔâÈëÇÖ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/


5. ¹ú¼ÊÁªºÏÐж¯²é·âLeakBaseÍøÂç·¸·¨ÂÛ̳


3ÔÂ4ÈÕ£¬£¬£¬ £¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÁªºÏÅ·ÖÞÐ̾¯×éÖ¯µÈ14¹úÖ´·¨»ú¹¹£¬£¬£¬ £¬£¬ÓÚ3ÔÂ3ÈÕÖÁ4ÈÕ¿ªÕ¹"йÃÜÐж¯"£¬£¬£¬ £¬£¬Àֳɲé·âÍøÂç·¸·¨ÂÛ̳LeakBase¡£¡£¡£¡£¸ÃÂÛ̳×÷ΪºÚ¿Í¹¤¾ßÉúÒâ¡¢±»µÁÊý¾ÝÉúÒâµÄ½¹µãƽ̨£¬£¬£¬ £¬£¬×Ô2021ÄêÓÉARESÍþв×éÖ¯Ö§³ÖÔËÓªÒÔÀ´£¬£¬£¬ £¬£¬Óû§¹æÄ£Òѳ¬14.2Íò£¬£¬£¬ £¬£¬ÌṩÊý¾Ý¿â»á¼û¡¢Îó²îʹÓÃÉúÒâ¡¢µ£±£Ö§¸¶ÏµÍ³¼°ºÚ¿ÍÊÖÒÕÌÖÂÛÇø£¬£¬£¬ £¬£¬º­¸ÇÉç»á¹¤³Ìѧ¡¢ÃÜÂëѧµÈרÌâ¡£¡£¡£¡£Ðж¯Ê±´ú£¬£¬£¬ £¬£¬Ö´·¨Ö°Ô±ÔÚÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢±ÈÀûʱµÈ8¹úÖ´ÐÐËѲéÁʵÑé¾Ð²¶²¢¿ªÕ¹"ÇÃÃÅ̸»°"£¬£¬£¬ £¬£¬È«Çò¹²ÌᳫԼ100´ÎÖ´·¨Ðж¯£¬£¬£¬ £¬£¬´¦·Ö37Ãû×î»îÔ¾Óû§¡£¡£¡£¡£LeakBaseµÄÁ½¸öÓòÃûÏÖÒѱ»FBI½ÓÊÜ£¬£¬£¬ £¬£¬ÓòÃûЧÀÍÆ÷Çл»Îªns1.fbi.seized.govºÍns2.fbi.seized.gov£¬£¬£¬ £¬£¬Ò³ÃæÏÔʾ²é·â֪ͨ£¬£¬£¬ £¬£¬Ç¿µ÷ÂÛ̳ËùÓÐÄÚÈݰüÀ¨Óû§ÕË»§¡¢Ìû×Ó¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢Ë½Ðż°IPÈÕÖ¾Òѱ»Çå¾²ÉúÑÄ£¬£¬£¬ £¬£¬½«ÓÃÓÚºóÐøÈ¡Ö¤ÊӲ졣¡£¡£¡£ÈκÎÊÔͼ»á¼û»ò×ÌÈÅÍøÕ¾µÄÐÐΪ¿ÉÄÜ×é³ÉÐÂ×ï¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-seizes-leakbase-cybercrime-forum-data-of-142-000-members/


6. ŦԼÂóµÏÑ·¹ã³¡»¨Ô°ÔâCl0pÀÕË÷¹¥»÷


3ÔÂ3ÈÕ£¬£¬£¬ £¬£¬Å¦Ô¼µØ±êÂóµÏÑ·¹ã³¡»¨Ô°£¨MSG£©¿ËÈÕÈ·ÈÏÔâÓöÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ £¬£¬Éæ¼°2025ÄêÕë¶Ô¼×¹ÇÎĵç×ÓÉÌÎñÌ×¼þ£¨EBS£©µÄ´ó¹æÄ£ÍøÂç·¸·¨»î¶¯¡£¡£¡£¡£×÷ΪȫÇòÖøÃû¶à¹¦Ð§ÊÒÄÚ³¡¹Ý£¬£¬£¬ £¬£¬MSGλÓÚŦԼÊУ¬£¬£¬ £¬£¬ÊÇNBAÄá¿Ë˹¶ÓºÍNHLÓÎÆï±ø¶ÓÖ÷³¡£¬£¬£¬ £¬£¬³Ð°ìÌåÓýÈüÊ¡¢Ñݳª»á¼°ÓéÀֻ£¬£¬£¬ £¬£¬´Ë´ÎÊÂÎñʹÆä³ÉΪʹÓü׹ÇÎÄEBSÎó²îʵÑéºÚ¿Í¹¥»÷µÄÖÚ¶àÊܺ¦×éÖ¯Ö®Ò»¡£¡£¡£¡£2025Äê11Ô£¬£¬£¬ £¬£¬Cl0pÀÕË÷Èí¼þ×é֯ʹÓü׹ÇÎÄEBSÖеÄÁãÈÕÎó²îCVE-2025-61882ÈëÇÖ°üÀ¨MSGÔÚÄÚµÄ100¶à¼Ò»ú¹¹¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ØÖƼ׹ÇÎIJ¢·¢´¦Öóͷ£×é¼þ£¬£¬£¬ £¬£¬½ø¶øÇÔÈ¡Êý¾Ý¡£¡£¡£¡£MSG¾Ü¾øÖ§¸¶Êê½ðºó£¬£¬£¬ £¬£¬Cl0pй¶³¬210GB¹«Ë¾´æµµÎļþ¡£¡£¡£¡£¾ÝMSGÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬£¬£¬ £¬£¬¼×¹ÇÎÄEBSÓɹ©Ó¦ÉÌÍйÜÖÎÀí£¬£¬£¬ £¬£¬ÓÃÓÚ²¿·ÖÈËÁ¦ºÍ²ÆÎñÔËÓª¡£¡£¡£¡£¹©Ó¦ÉÌÊÓ²ìÈ·¶¨£¬£¬£¬ £¬£¬Î´¾­ÊÚȨÕßÓÚ2025Äê8Ô»ñÈ¡²¿·ÖÓ¦ÓÃÊý¾Ý£¬£¬£¬ £¬£¬Éæ¼°ÕÐÆ¸»ò¸¶¿îÏà¹ØµÄÓªÒµ¼Í¼Îļþ£¬£¬£¬ £¬£¬ÆäÖаüÀ¨ÐÕÃûºÍÉç»á°ü¹ÜºÅµÄÎļþÊÜÓ°Ïì¡£¡£¡£¡£¼×¹ÇÎÄÒÑÓÚ2025Äê10ÔÂÐû²¼½ôÆÈ²¹¶¡ÐÞ¸´¸ÃÎó²î£¬£¬£¬ £¬£¬µ«´ËǰÒÑÓдó×ÚÊý¾Ýй¶¡£¡£¡£¡£


https://securityaffairs.com/188814/cyber-crime/oracle-ebs-2025-campaign-impacts-madison-square-garden-sensitive-data-leaked.html