¹¥»÷ÕßÀÄÓÃFortiGate·À»ðǽ×÷ÎªÍøÂçÈëÇÖÌø°å

Ðû²¼Ê±¼ä 2026-03-11

1. ¹¥»÷ÕßÀÄÓÃFortiGate·À»ðǽ×÷ÎªÍøÂçÈëÇÖÌø°å


3ÔÂ10ÈÕ£¬£¬ £¬ÍøÂçÇå¾²Ñо¿Ö°Ô±½üÆÚ¼à²âµ½Õë¶ÔFortiGateÏÂÒ»´ú·À»ðǽ£¨NGFW£©µÄÐÂÐ͹¥»÷»î¶¯£¬£¬ £¬ÍþвÐÐΪÕßÕýʹÓøÃ×°±¸×÷ΪÈëÇÖÊܺ¦ÕßÍøÂçµÄÈë¿Úµã¡£¡£¡£SentinelOne±¨¸æÖ¸³ö£¬£¬ £¬¹¥»÷Õßͨ¹ý½üÆÚÅû¶µÄÎó²î£¨ÈçCVE-2025-59718¡¢CVE-2025-59719¡¢CVE-2026-24858£©»òÈõƾ֤ÈëÇÖ×°±¸£¬£¬ £¬ÇÔÈ¡°üÀ¨Ð§ÀÍÕË»§Æ¾Ö¤ºÍÍøÂçÍØÆËÐÅÏ¢µÄÉèÖÃÎļþ£¬£¬ £¬Ä¿µÄ¼¯ÖÐÓÚÒ½ÁƱ£½¡¡¢Õþ¸®¼°ÍйÜЧÀÍÌṩÉ̵ÈÃôÇéÐ÷ÐΡ£¡£¡£FortiGate×°±¸Òò¼¯³É·À»ðǽÇå¾²¿ØÖÆÓëAD/LDAPµÈÉí·ÝÑéÖ¤»ù´¡ÉèÊ©»á¼ûȨÏÞ£¬£¬ £¬³£±»°²ÅÅÓÚÒªº¦ÍøÂç½Úµã¡£¡£¡£¹¥»÷ÕßÈëÇֺ󣬣¬ £¬¿É½¨ÉèÍâµØÖÎÀíÔ±ÕË»§£¨Èç¡°support¡±£©£¬£¬ £¬ÉèÖÃÎÞÇøÓòÏÞÖÆµÄ·À»ðǽսÂÔ£¬£¬ £¬ÊµÏÖÈ«Íø×ÔÓɱéÀú¡£¡£¡£ÔÚ2025Äê11ÔµÄÒ»ÆðÊÂÎñÖУ¬£¬ £¬¹¥»÷Õßͨ¹ý´ËÀà²Ù×÷½¨É賤ÆÚ»¯×¤×ãµã£¬£¬ £¬²¢ÓÚ2026Äê2ÔÂÌáÈ¡¼ÓÃܵÄLDAPЧÀÍÕË»§Æ¾Ö¤£¬£¬ £¬½âÃܺóʹÓÃ¸ÃÆ¾Ö¤¶ÔAD¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬ £¬×¢²á¶ñÒâÊÂÇéÕ¾£¬£¬ £¬Æô¶¯ÍøÂçɨÃ裬£¬ £¬×îÖÕ±»¼ì²â²¢×èÖ¹ºáÏòÒÆ¶¯¡£¡£¡£


https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html


2. ¶íÓïÍþвÐÐΪÕßʹÓÃBlackSanta EDRɱÊÖ¹¥»÷HR²¿·Ö


3ÔÂ10ÈÕ£¬£¬ £¬Ò»Äê¶àÒÔÀ´£¬£¬ £¬½²¶íÓïµÄÍþвÐÐΪÕßÕë¶ÔÈËÁ¦×ÊÔ´²¿·ÖÌᳫȫÐIJ߻®µÄ¹¥»÷»î¶¯£¬£¬ £¬Í¨¹ýÓã²æÊ½ÍøÂç´¹ÂÚÓʼþÈö²¥Î±×°³É¼òÀúµÄISO¾µÏñÎļþ¡£¡£¡£¸Ã¶ñÒâÈí¼þ¼¯³ÉÉç»á¹¤³ÌѧÓëÏȽø¹æ±ÜÊÖÒÕ£¬£¬ £¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢²¢°²ÅÅÃûΪBlackSantaµÄÐÂÐÍEDRɱÊÖ¡£¡£¡£¹¥»÷Á´ÖУ¬£¬ £¬ISOÎļþ°üÀ¨Î±×°³ÉPDFµÄLNK¿ì½Ý·½·¨¡¢PowerShell¾ç±¾¡¢Í¼Ïñ¼°ICOÎļþ¡£¡£¡£LNKÆô¶¯PowerShellÖ´Ðо籾£¬£¬ £¬Ê¹ÓÃÒþдÊõ´ÓͼÏñÌáÈ¡Êý¾Ý²¢ÔÚÄÚ´æÔËÐУ¬£¬ £¬ËæºóÏÂÔØº¬Õýµ±SumatraPDFÓë¶ñÒâDWrite.dllµÄZIP°ü£¬£¬ £¬Í¨¹ýDLL²à¼ÓÔØ¼ÓÔØ¶ñÒâ´úÂë¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ´ÐÐÏµÍ³Ö¸ÎÆÊ¶±ð£¬£¬ £¬½«ÐÅÏ¢·¢ËÍÖÁC2ЧÀÍÆ÷£¬£¬ £¬²¢¼ì²âɳÏä¡¢ÐéÄâ»ú»òµ÷ÊÔ¹¤¾ßÒÔ¹æ±ÜÆÊÎö¡£¡£¡£BlackSantaµÄ½¹µã¹¦Ð§ÊÇʹ¶ËµãÇå¾²½â¾ö¼Æ»®Ê§Ð§£ºÍ¨¹ýÌí¼ÓMicrosoft Defenderɨ³ýÏî¡¢ÐÞ¸Ä×¢²á±íïÔÌ­Ò£²âÊý¾ÝÌá½»¡¢ÒÖÖÆWindows֪ͨ£¬£¬ £¬²¢ÖÕÖ¹Çå¾²Àú³Ì¡£¡£¡£Æäͨ¹ýö¾ÙÀú³Ì²¢Óë·À²¡¶¾/EDR/SIEM¹¤¾ßÁбí±È¶Ô£¬£¬ £¬»ñÈ¡Àú³ÌIDºóʹÓüÓÔØµÄÇý¶¯³ÌÐòÔÚÄں˼¶½âËø²¢ÖÕÖ¹Àú³Ì¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/


3. BeatBankerαװ³ÉStarlinkÓ¦ÓÃʵÑé¹¥»÷


3ÔÂ10ÈÕ£¬£¬ £¬¿¨°Í˹»ùÑо¿Ö°Ô±¿ËÈÕ·¢Ã÷Õë¶Ô°ÍÎ÷Óû§µÄBeatBankerÐÂÐÍAndroid¶ñÒâÈí¼þ£¬£¬ £¬¸ÃÈí¼þͨ¹ýαװ³ÉStarlinkÓ¦ÓÃÓÕµ¼Óû§»á¼ûð³äµÄGoogle PlayÊÐËÁÍøÕ¾¾ÙÐÐ×°Ö㬣¬ £¬¼¯ÒøÐÐľÂíÓëÃÅÂÞ±ÒÍÚ¿ó¹¦Ð§ÓÚÒ»Ìå¡£¡£¡£Æä×îа汾°²ÅÅÁËBTMOB RATͨÓÃÔ¶³Ì»á¼ûľÂí£¬£¬ £¬¾ß±¸×°±¸È«¿Ø¡¢¼üÅ̼ͼ¡¢ÆÁÄ»Â¼ÖÆ¡¢ÉãÏñÍ·»á¼û¡¢GPS¸ú×Ù¼°Æ¾Ö¤²¶»ñµÈÄÜÁ¦¡£¡£¡£BeatBankerÒÔAPKÎļþ·Ö·¢£¬£¬ £¬Ê¹ÓÃÍâµØ¿â½âÃÜÒþ²ØµÄDEX´úÂëÖ±½Ó¼ÓÔØµ½ÄÚ´æÒÔ¹æ±Ü¼ì²â¡£¡£¡£×°ÖÃǰ»á¾ÙÐÐÇéÐμì²é£¬£¬ £¬Í¨ÊºóÏÔʾαÔìµÄPlayÊÐËÁ¸üÐÂÒ³Ãæ£¬£¬ £¬ÓÕÆ­Óû§ÊÚÓè×°ÖÃÆäËû¶ñÒâ³ÌÐòµÄȨÏÞ¡£¡£¡£Îª×èÖ¹´¥·¢¾¯±¨£¬£¬ £¬¸Ã¶ñÒâÈí¼þ»áÑÓ³Ù¶ñÒâ²Ù×÷£¬£¬ £¬²¢Í¨¹ýÒ»Á¬²¥·ÅÏÕЩÌý²»¼ûµÄ5ÃëÖÐÎÄMP3¼Òôά³Ö³¤ÆÚÐÔ¡£¡£¡£ÔÚÍÚ¿ó·½Ã棬£¬ £¬BeatBankerʹÓÃרΪARM×°±¸±àÒëµÄXMRig 6.17.0Ð޸İæ£¬£¬ £¬Í¨¹ý¼ÓÃÜTLSÅþÁ¬¹¥»÷Õß¿ØÖÆµÄ¿ó³Ø¾ÙÐÐÃÅÂÞ±ÒÍڿ󣬣¬ £¬²¢Ö§³ÖÖ÷µØµã¹ÊÕÏʱ»ØÍ˵½ÊðÀíµØµã¡£¡£¡£ÍÚ¿óÄ£¿£¿ £¿£¿ £¿£¿é»áƾ֤װ±¸×´Ì¬¶¯Ì¬Æô¶¯»ò×èÖ¹£¬£¬ £¬²Ù×÷ְԱͨ¹ýFirebaseÔÆÐÂÎÅת´ï£¨FCM£©Ò»Á¬¼à¿Ø×°±¸µç³ØµçÁ¿¡¢Î¶ȡ¢³äµç״̬¼°Ê¹ÓÃÇéÐΣ¬£¬ £¬ÔÚ×°±¸Ê¹ÓÃʱ×èÖ¹ÍÚ¿óÒÔïÔÌ­ÎïÀíÓ°Ï죬£¬ £¬¼á³ÖÒþ²ØÐÔ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/


4. ½©Ê¬ZIPÊÖÒÕ£º¸Ä¶¯ÎļþÍ·ÈÆÇ徲ɨÃè


3ÔÂ10ÈÕ£¬£¬ £¬Çå¾²Ñо¿Ô±Chris AzizÉè¼ÆµÄ¡°½©Ê¬ZIP¡±ÊÖÒÕͨ¹ý¸Ä¶¯ZIPÎļþÍ·£¬£¬ £¬½«Ñ¹ËõÊý¾Ýαװ³ÉδѹËõÊý¾Ý£¬£¬ £¬ÀÖ³ÉÈÆ¹ý51¸öɱ¶¾ÒýÇæÖеÄ50¸ö£¨VirusTotal²âÊÔ£©¡£¡£¡£¸ÃÊÖÒÕʹÓ÷À²¡¶¾Èí¼þ¶ÔZIPÎļþ¡°ÒªÁì×ֶΡ±µÄÐÅÈΣ¬£¬ £¬µ±ÒªÁì×ֶαê¼ÇΪ¡°´æ´¢£¨Method=0£©¡±Ê±£¬£¬ £¬Çå¾²¹¤¾ß»áÖ±½ÓɨÃèԭʼ×Ö½Ú£¬£¬ £¬µ«ÏÖʵÊý¾ÝÊǾ­ÓÉDEFLATEѹËõµÄ£¬£¬ £¬µ¼ÖÂɨÃèÆ÷½ö¿´µ½¡°Ñ¹ËõÔëÉù¡±¶øÎÞ·¨¼ì²â¶ñÒâÌØÕ÷Âë¡£¡£¡£ÍþвÐÐΪÕ߿ɽ¨ÉèרÓüÓÔØÆ÷£¬£¬ £¬ºöÂÔ±»¸Ä¶¯µÄ±êÍ·£¬£¬ £¬Ö±½ÓÒÔDEFLATEËã·¨½âѹÎļþ£¬£¬ £¬ÍêÉÆ»Ö¸´ÓÐÓÃÔØºÉ¡£¡£¡£¶ø±ê×¼½âѹ¹¤¾ß£¨ÈçWinRAR¡¢7-Zip£©ÊµÑé½âѹʱ»áÒòÎļþÍ·¹ýʧ±¨´í»òÊý¾ÝË𻵣¬£¬ £¬Ðγɡ°Çå¾²¹¤¾ßÎóÅС¢½âѹ¹¤¾ßʧЧ¡±µÄË«ÖØÒþ²ØÐ§¹û¡£¡£¡£CERT/CC½¨ÒéÇå¾²¹¤¾ß¹©Ó¦ÉÌÐèÑé֤ѹËõÒªÁì×Ö¶ÎÓëÏÖʵÊý¾ÝÒ»ÖÂÐÔ£¬£¬ £¬ÔöÌí¹éµµ½á¹¹Ò»ÖÂÐÔ¼ì²â£¬£¬ £¬²¢½ÓÄɸüÆð¾¢µÄ½âѹ¼ì²éģʽ£»£»£»Óû§ÔòÐèÉóÉ÷´¦Öóͷ£Î´ÖªÈªÔ´µÄѹËõÎļþ£¬£¬ £¬Èô½âѹʱ·ºÆð¡°²»Ö§³ÖµÄÒªÁ족¹ýʧ£¬£¬ £¬Ó¦Á¬Ã¦É¾³ýÎļþ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-zombie-zip-technique-lets-malware-slip-past-security-tools/


5. KadNap½©Ê¬ÍøÂçʹÓÃKademliaЭÒéѬȾ»ªË¶Â·ÓÉÆ÷


3ÔÂ10ÈÕ£¬£¬ £¬ÐÂÐͽ©Ê¬ÍøÂçKadNap×Ô2025Äê8ÔÂÆðÒÑѬȾ14,000̨»ªË¶Â·ÓÉÆ÷¼°ÆäËû±ßÑØ×°±¸£¬£¬ £¬Í¨¹ý×Ô½ç˵KademliaÂþÑÜʽ¹þÏ£±í£¨DHT£©Ð­Òé¹¹½¨µã¶ÔµãÍøÂ磬£¬ £¬ÅþÁ¬C2»ù´¡ÉèÊ©¡£¡£¡£¸ÃÍøÂç½ü°ë×°±¸¹ØÁª»ªË¶×¨ÓÃC2£¬£¬ £¬ÆäÓàÓëÁ½¸ö×ÔÁ¦¿ØÖÆÐ§ÀÍÆ÷ͨѶ£¬£¬ £¬60%µÄÊÜѬȾװ±¸Î»ÓÚÃÀ¹ú£¬£¬ £¬Ì¨Íå¡¢Ïã¸Û¡¢¶íÂÞ˹ÒàÕ¼ÏÔÖø±ÈÀý¡£¡£¡£Ñ¬È¾Ê¼ÓÚ´Ó212.104.141[.]140ÏÂÔØ¶ñÒâ¾ç±¾aic.sh£¬£¬ £¬Í¨¹ýÿ55·ÖÖÓÔËÐеÄcronʹÃü½¨É賤ÆÚ»¯£¬£¬ £¬×îÖÕ×°ÖÃkad ELF¶þ½øÖÆÎļþ×÷Ϊ¿Í»§¶Ë¡£¡£¡£¼¤»îºó£¬£¬ £¬¶ñÒâÈí¼þ»ñÈ¡Ö÷»úÍⲿIP£¬£¬ £¬ÁªÏµNTPЧÀÍÆ÷»ñȡʱ¼ä¼°ÏµÍ³ÔËÐÐʱ¼ä£¬£¬ £¬²¢Ê¹ÓÃÐ޸ĺóµÄKademlia DHTЭÒ鶨λ½ÚµãÓëC2£¬£¬ £¬¾ÝÊèÉ¢´æ´¢Ê¹C2ʶ±ðÓëÆÆËð¸üÄÑÌâ¡£¡£¡£È»¶ø£¬£¬ £¬ÆäKademliaʵÏÖ±£´æÈ±ÏÝ£ºÔÚµÖ´ïC2ǰÓëÁ½¸öÌØ¶¨½ÚµãÒ»Á¬ÅþÁ¬£¬£¬ £¬½µµÍÁËÈ¥ÖÐÐÄ»¯Ë®Æ½£¬£¬ £¬Ê¹¿ØÖÆ»ù´¡ÉèÊ©¿É±»Ê¶±ð¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/


6. Cal AIÔâºÚ¿ÍÈëÇÖÖÂ300ÍòÓû§Êý¾Ýй¶


3ÔÂ10ÈÕ£¬£¬ £¬¼ÙÃû¡°vibecodelegend¡±µÄºÚ¿Íͨ¹ýÍøÂç·¸·¨Æ½Ì¨BreachForumsÐû³ÆÈëÇÖCal AI£¬£¬ £¬ÕâÊÇÒ»¿îʹÓÃAIÆÊÎöʳÎïͼƬ׷×Ù¿¨Â·ÀïÓëÓªÑøÐÅÏ¢µÄÈÈÃÅ¿µ½¡Ó¦Ó㬣¬ £¬²¢Ð¹Â¶³¬300ÍòÓû§µÄ12GBСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£Cal AI½üÆÚÒòÊÕ¹º½¡ÉíÓ¦ÓÃMyFitnessPal½øÒ»²½À©´óÊг¡·Ý¶î£¬£¬ £¬¶øMyFitnessPalÔÚ2018ÄêÔøÒòǰËùÓÐÕßUnder ArmourÅû¶ÔâÓö´ó¹æÄ£Êý¾Ýй¶£¬£¬ £¬³¬1.5ÒÚÓû§ÐÅÏ¢±»ÇÔ¡£¡£¡£¾ÝºÚ¿ÍÉù³Æ£¬£¬ £¬Ð¹Â¶Êý¾Ýº­¸ÇÓû§³öÉúÈÕÆÚ¡¢ÐÕÃû¡¢ÐÔ±ð¡¢Óû§Ãû¡¢É罻ýÌå×ÊÁÏ¡¢PINÂë¡¢¶©ÔÄÏêÇé¡¢Éí¸ßÌåÖØµÈÉúÎïÌØÕ÷£¬£¬ £¬ÒÔ¼°³¬280Íò¸öµç×ÓÓʼþµØµã£¬£¬ £¬ÆäÖнü120ÍòʹÓÃApple˽ÓÐÖмÌЧÀÍ@privaterelay.appleid.comÒÔÒþ²ØÕæÊµÓÊÏä¡£¡£¡£±ðµÄ£¬£¬ £¬Êý¾Ý»¹°üÀ¨ÉÅʳ¼Í¼¡¢½ø²Íʱ¼ä¼°¿¨Â·Àï×·×ÙµÈÐÐΪÐÅÏ¢£¬£¬ £¬¿ÉÄÜ̻¶Óû§ÒûʳģʽÓ뿵½¡Ï°¹ß¡£¡£¡£ÏÖÔÚ£¬£¬ £¬Ïà¹ØÊý¾ÝÒÑÔÚ¶íÓïÆ½Ì¨¼°¶à¸öTelegramƵµÀÈö²¥£¬£¬ £¬Òý·¢Òþ˽Çå¾²µ£ÐÄ¡£¡£¡£


https://hackread.com/cal-ai-myfitnesspal-data-breach-3m-users/