BianLianÀÕË÷Èí¼þʹÓÃSVG´¹ÂÚ¹¥»÷ίÄÚÈðÀÆóÒµ
Ðû²¼Ê±¼ä 2026-03-311. BianLianÀÕË÷Èí¼þʹÓÃSVG´¹ÂÚ¹¥»÷ίÄÚÈðÀÆóÒµ
3ÔÂ27ÈÕ£¬£¬£¬£¬£¬WatchGuardÑо¿Ö°Ô±¿ËÈÕÅû¶£¬£¬£¬£¬£¬BianLianÀÕË÷Èí¼þ×éÖ¯ÕýÕë¶ÔίÄÚÈðÀÆóÒµÌᳫÐÂÐÍÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâSVGͼÏñÎļþºÍÇÉÃîÖØ¶¨ÏòÊÖÒÕÈÆ¹ý¹Å°åÇå¾²·À»¤£¬£¬£¬£¬£¬ÊµÑé¸ßËÙAES¼ÓÃÜÀÕË÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷¸ß¶È¼¯ÖÐÔÚίÄÚÈðÀ£¬£¬£¬£¬£¬¹¥»÷Á´Ê¼ÓÚαװ³É·¢Æ±»òÔ¤ËãµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬¸½¼þΪʹÓÃÎ÷°àÑÀÓïÃüÃûµÄSVGÎļþ£¬£¬£¬£¬£¬¿´ËÆÍ¨Ë×ͼƬʵÔòǶÈëXML´úÂë¡£¡£¡£¡£¡£¡£¡£Óû§·¿ªÎļþºó£¬£¬£¬£¬£¬»áÉñÃØÅþÁ¬ÍⲿURL£¬£¬£¬£¬£¬ÏÂÔØÓÉGoÓïÑÔ±àдµÄÒþ²ØWindows³ÌÐò×÷ΪÓÐÓÃÔØºÉ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½ÓÄÉ16λÁîÅÆÏµÍ³×ª´ï¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬¸Ã³ÌÐò¾ß±¸·´¼à¿ØÄÜÁ¦£¬£¬£¬£¬£¬»á¼ì²âWine¹¤¾ßÒÔÅжÏÊÇ·ñ´¦ÓÚÇå¾²ÆÊÎöÇéÐΣ¬£¬£¬£¬£¬²¢ÔÚϵͳ¡°¹ÒÆð¡±Ê±Ò»Á¬¼àÊÓ£¬£¬£¬£¬£¬Ê¹Ó÷ÀÓùåÐÒ£Ö´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£Æä½¹µãÎäÆ÷ÊǸßËÙAES¼ÓÃÜÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬¿É¿ìËÙËø¶¨ÎļþʵÑéÀÕË÷¡£¡£¡£¡£¡£¡£¡£ÊÖÒÕϸ½ÚÏÔʾ£¬£¬£¬£¬£¬¸Ã¹¥»÷ͨ¹ýËõ¶ÌÁ´½ÓЧÀÍja.cat¾ÙÐÐÁ÷Á¿Öض¨Ïò£¬£¬£¬£¬£¬×îÖÕÖ¸Ïò±»ÈëÇֵİÍÎ÷ÓòÃû£¬£¬£¬£¬£¬Ðγɶà²ãÌø°å¹æ±Ü×·×Ù¡£¡£¡£¡£¡£¡£¡£WatchGuardÑо¿Ö¸³ö£¬£¬£¬£¬£¬ÕâЩսÂÔÓëBianLian×éÖ¯×Ô2022ÄêÒÔÀ´µÄ×÷°¸ÊÖ·¨¸ß¶ÈÎǺϡ£¡£¡£¡£¡£¡£¡£
https://hackread.com/bianlian-ransomware-fake-invoice-svg-images-attacks/
2. Î÷°àÑÀά¸ê¸ÛÔâÀÕË÷Èí¼þ¹¥»÷
3ÔÂ26ÈÕ£¬£¬£¬£¬£¬Î÷°àÑÀά¸ê¸Û¿ËÈÕÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆäÊý×ÖϵͳÑÏÖØÊÜË𡣡£¡£¡£¡£¡£¡£¹¥»÷ÓÚÖܶþÇåÔç±»·¢Ã÷£¬£¬£¬£¬£¬Ó°Ïì¼ÓÀûÎ÷ÑǵØÇø¿Ú°¶ÓÃÓÚ»õÎïÔËÊäÖÎÀí¼°ÆäËûÊý×ÖЧÀ͵ÄÅÌËã»úЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£²¿·Ö×°±¸±»Ëø¶¨£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇóÖ§¸¶Êê½ðÒÔ»Ö¸´ÏµÍ³»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£Îª×èÖ¹¹¥»÷À©É¢£¬£¬£¬£¬£¬¸ÛÎñ¾ÖÊÖÒÕÍŶÓѸËÙ½«ÊÜÓ°ÏìϵͳÓëÍâ²¿ÍøÂç¸ôÀ룬£¬£¬£¬£¬²¢ÆôÏÂÊÖÐж¯ÒµÄ£Ê½¡£¡£¡£¡£¡£¡£¡£¿Ú°¶×ܲÿ¨Âå˹¡¤²©ËþÄÉÇ¿µ÷£¬£¬£¬£¬£¬ÔÚÇå¾²ÍŶÓÈ·ÈÏϵͳ¾ø¶ÔÇ徲ǰ£¬£¬£¬£¬£¬²»»áÖØÐÂÅþÁ¬ÈκÎÊý×Öϵͳ£¬£¬£¬£¬£¬ÏÖÔÚÉÐÎÞ»Ö¸´Êý×ÖÔËÓªµÄʱ¼ä±í¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü´¬²°º½ÐкͻõÎïװжµÈʵÌåÔËÓªÈÔÔÚ¼ÌÐø£¬£¬£¬£¬£¬µ«ÒÀÀµÊý×ÖÆ½Ì¨µÄÎïÁ÷е÷ÊÂÇéÊܵ½ÏÔÖøÓ°Ï죬£¬£¬£¬£¬²¿·Ö²Ù×÷Ö°Ô±ÒÑתΪÈ˹¤²Ù×÷²¢ÒÀÀµÖ½ÖÊÎļþÍê³ÉÊÂÇé¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬ÒÔÈ·¶¨¹¥»÷ÕßÔõÑùÈëÇÖÍøÂçÒÔ¼°ÊÇ·ñ±£´æÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£²©ËþÄɽ«´Ë´ÎÊÂÎñ¶¨ÐÔΪ¾¼ÃÄîÍ·µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬Ö¼ÔÚÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬ÉÐÎÞÈκÎÍøÂç·¸·¨×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/port-of-vigo-ransomware
3. FortiClient EMS¸ßΣSQL×¢ÈëÎó²îÔâ»îԾʹÓÃ
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬ÍþвÇ鱨¹«Ë¾Defused¿ËÈÕÅû¶£¬£¬£¬£¬£¬¹¥»÷ÕßÕýÆð¾¢Ê¹ÓÃFortinet FortiClient EMSƽ̨µÄCVE-2026-21643ÑÏÖØSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÍþвÐÐΪÕßͨ¹ý½á¹¹¶ñÒâHTTPÇëÇ󣬣¬£¬£¬£¬ÔÚδÐÞ²¹µÄFortiClient EMS 7.4.4°æ±¾Web½çÃæÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ¡£¡£¡£¡£¡£¡£¡£DefusedÇ¿µ÷£¬£¬£¬£¬£¬Ö»¹ÜCISA¼°ÆäËûÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼ÈÔ±ê¼Ç¸ÃÎó²îΪ¡°Î´±»Ê¹Óá±£¬£¬£¬£¬£¬µ«ÆäÄÚ²¿Êý¾ÝÒÑ֤ʵËÄÌìǰ·ºÊ×ÏÈ´ÎʹÓð¸Àý¡£¡£¡£¡£¡£¡£¡£Îó²îÓÉFortinetÇå¾²ÍŶÓÄÚ²¿·¢Ã÷£¬£¬£¬£¬£¬Ó°Ïì7.4.4°æ±¾£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÉý¼¶ÖÁ7.4.5»ò¸ü¸ß°æ±¾ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬FortinetÉÐδ¸üÐÂÇ徲ͨ¸æ»òÈ·ÈÏÎó²îÒѱ»ÏÖʵʹÓᣡ£¡£¡£¡£¡£¡£¾ÝShodanɨÃ裬£¬£¬£¬£¬½ü1000¸öFortiClient EMSʵÀýÒѹûÕæÌ»Â¶£»£»£»£»Shadowserver×·×Ùµ½³¬2000¸ö̻¶ʵÀý£¬£¬£¬£¬£¬ÆäÖÐ1400¸öIPµØµãλÓÚÃÀ¹úºÍÅ·ÖÞ£¬£¬£¬£¬£¬´ó¶¼¼¯ÖÐÔÚÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/critical-fortinet-forticlient-ems-flaw-now-exploited-in-attacks/
4. ¶íTA446ʹÓÃDarkSwordÎó²î¶ÔiOS×°±¸Ìᳫ´¹ÂÚ¹¥»÷
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬Óë¶íÂÞ˹¹ØÁªµÄ¸ß¼¶Ò»Á¬Íþв×éÖ¯TA446£¨ÓÖÃûSEABORGIUM¡¢ColdRiverµÈ£©ÕýʹÓÃDarkSwordÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬£¬Õë¶ÔiOS×°±¸Ìᳫ¶¨ÏòÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2017ÄêÆðÒ»Á¬»îÔ¾£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô±±Ô¼¹ú¼Ò¼°¶«Å·µØÇø£¨º¬ÎÚ¿ËÀ¼£©£¬£¬£¬£¬£¬Ä¿µÄº¸Ç¹ú·À/Ç鱨¹«Ë¾¡¢·ÇÕþ¸®×éÖ¯¡¢Õþ¸®¼ä×éÖ¯¡¢Öǿ⡢¸ßУ£¬£¬£¬£¬£¬ÒÔ¼°Ç°Ç鱨¹ÙÔ±¡¢¶íÂÞ˹ÊÂÎñר¼ÒºÍÍâÑó¶í¹«Ãñ£¬£¬£¬£¬£¬Í¨¹ýÇÔȡƾ֤ÓëÇ鱨ʵÏÖÈëÇÖºÍÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬TA446ͨ¹ýαÔì´óÎ÷ÑóÀíÊ»áÓʼþ·¢ËÍÁ´½Ó£¬£¬£¬£¬£¬Á´½ÓÖ¸Ïò¿´ËÆÎÞº¦µÄPDFÓÕ¶üÎļþ£¬£¬£¬£¬£¬Ê¹ÓÃЧÀÍÆ÷¶Ë¹ýÂË»úÖÆ½«Óû§Öض¨ÏòÖÁDarkSwordÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬£¬ÊµÑ鶨ÏòͶ·ÅÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß°ü°üÀ¨Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¡¢PACÈÆ¹ýµÈ×é¼þ£¬£¬£¬£¬£¬Ëäδ·¢Ã÷ɳÏäÌÓÒÝ£¬£¬£¬£¬£¬µ«ÒÑ֤ʵͨ¹ý¼ÓÔØÆ÷MD5¹ØÁªTA446µÚ¶þ½×¶ÎÓòÃû£¬£¬£¬£¬£¬ÏÔʾ×Åʵ¼ÊʹÓᣡ£¡£¡£¡£¡£¡£
https://securityaffairs.com/190139/apt/russia-linked-apt-ta446-uses-darksword-exploit-to-target-iphone-users-in-phishing-wave.html
5. Ò½ÁƿƼ¼¹«Ë¾CareCloud³ÆºÚ¿ÍÇÔÈ¡ÁË»¼ÕßÊý¾Ý
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬Ò½ÁÆÐÅÏ¢ÊÖÒÕ¹«Ë¾CareCloud¿ËÈÕÅû¶һÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Òý¿¯ÐÐÒµ¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ܲ¿Î»ÓÚÃÀ¹úÐÂÔóÎ÷ÖÝ£¬£¬£¬£¬£¬×÷Ϊ¹ûÕæÉÏÊеÄÒ½ÁƱ£½¡ITЧÀÍÉÌ£¬£¬£¬£¬£¬Ö÷ÒªÌṩSaaSÈí¼þ¡¢ÊÕÈëÖÜÆÚÖÎÀí¡¢µç×Ó¿µ½¡¼Í¼£¨EHR£©µÈ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£¾ÝCareCloudÏòÃÀ¹ú֤ȯÉúÒâίԱ»áÌá½»µÄÎļþÏÔʾ£¬£¬£¬£¬£¬2026Äê3ÔÂ16ÈÕ£¬£¬£¬£¬£¬ÆäÆìÏÂCareCloud Health²¿·ÖÔâÓöÍøÂçÖÐÖ¹£¬£¬£¬£¬£¬µ¼ÖÂÁù¸öµç×Ó¿µ½¡¼Í¼ÇéÐÎÖ®Ò»µÄ¹¦Ð§ºÍÊý¾Ý»á¼ûÊÜ×裬£¬£¬£¬£¬Ò»Á¬Ô¼8СʱºóÍêÈ«»Ö¸´¡£¡£¡£¡£¡£¡£¡£¾ÊÓ²ìÈ·ÈÏ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÈëÇÖʱ´ú»á¼ûÁ˸ù«Ë¾IT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬²¢Ôì³É´æ´¢¿Í»§»¼Õß¿µ½¡¼Í¼µÄÌØ¶¨ÇéÐÎÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹«Ë¾Ç¿µ÷δ¾ÊÚȨµÄÊý¾Ý»á¼û¹æÄ£ÓÐÏÞ£¬£¬£¬£¬£¬µ«ÏêϸÊÜÓ°ÏìÈËÊý¼°Êý¾ÝÀàÐÍÈÔ´ý½øÒ»³ÌÐò²éÈ·ÈÏ¡£¡£¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ºó£¬£¬£¬£¬£¬CareCloudѸËÙÆô¶¯Ó¦¼±ÏìÓ¦»úÖÆ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷´Ë´ÎÊÂÎñ䲨¼°ÆäËûƽ̨¡¢²¿·Ö»òϵͳ£¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÎÞ·¨¼ÌÐø»á¼ûÆäÊý¾Ý¿â£¬£¬£¬£¬£¬ËùÓÐÊÜÓ°Ïìϵͳ¾ùÒÑÍêÈ«»Ö¸´¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/healthcare-tech-firm-carecloud-says-hackers-stole-patient-data/
6. RoadK1ll£ºWebSocket·´ÏòËíµÀʵÏÖÒþ²ØÉøÍ¸
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬Íйܼì²âºÍÏìÓ¦£¨MDR£©ÌṩÉÌBlackpointÔÚÊÂÎñÏìÓ¦Öз¢Ã÷ÁËÃûΪRoadK1llµÄÐÂÐÍNode.js¶ñÒâÖ²Èë³ÌÐò£¬£¬£¬£¬£¬¸Ã³ÌÐòͨ¹ý×Ô½ç˵WebSocketÐÒéʵÏÖ¹¥»÷ÕßÓëÊÜѬȾÖ÷»úµÄÒ»Á¬Í¨Ñ¶£¬£¬£¬£¬£¬¾ß±¸¸ß¶ÈÒþ²ØÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£¡£RoadK1ll±»½ç˵ΪÇáÁ¿¼¶·´ÏòËíµÀÖ²ÈëÎ£¬£¬£¬£¬Æä½¹µã¹¦Ð§Êǽ«ÊÜËðÖ÷»úת»¯Îª¿É¿ØÖм̵㡣¡£¡£¡£¡£¡£¡£Í¨¹ý½¨Éèµ½¹¥»÷Õß¿ØÖÆ»ù´¡ÉèÊ©µÄ³öÕ¾WebSocketÅþÁ¬£¬£¬£¬£¬£¬¸Ã³ÌÐò¿É°´Ðèת·¢TCPÁ÷Á¿£¬£¬£¬£¬£¬Ê¹ÍþвÐÐΪÕßÎÞÐèÒÀÀµ¹Å°åÈëÕ¾¼àÌýÆ÷¼´¿É»á¼ûÄÚ²¿ÍøÂç×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÉè¼ÆÊ¹¹¥»÷ÕßÄÜÈÆ¹ý½çÏß¿ØÖÆ£¬£¬£¬£¬£¬ÓÉÓÚÅþÁ¬Ô´×Ô±»ÈëÇÖ»úе£¬£¬£¬£¬£¬¿É¼ÌÐøÆäÍøÂçÐÅÈκÍλÖ㬣¬£¬£¬£¬ÓÐÓûá¼ûÔ±¾ÎÞ·¨´ÓÍⲿֱ½Ó»á¼ûµÄÄÚ²¿ÏµÍ³¡¢Ð§Àͼ°ÍøÂç¶Î¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶à²¢·¢ÅþÁ¬ÄÜÁ¦£¬£¬£¬£¬£¬ÔÊÐíͬʱÓë¶à¸öÄ¿µÄͨѶ¡£¡£¡£¡£¡£¡£¡£ÆäÏÂÁ°üÀ¨ÅþÁ¬¡¢Êý¾Ýת·¢¡¢ÅþÁ¬È·ÈÏ¡¢ÅþÁ¬ÖÕÖ¹¼°¹ýʧ·´ÏìµÈ»ù´¡Ö¸Á£¬£¬£¬£¬ÆäÖÐCONNECTÏÂÁî¿É´¥·¢ÏòÖ¸¶¨Ö÷»úºÍ¶Ë¿ÚµÄ³öÕ¾TCPÅþÁ¬£¬£¬£¬£¬£¬ÊµÏÖ¹¥»÷¹æÄ£µÄºáÏòÀ©Õ¹¡£¡£¡£¡£¡£¡£¡£ÈôͨѶÖÐÖ¹£¬£¬£¬£¬£¬³ÌÐò»á×Ô¶¯Æô¶¯ÖØÁ¬»úÖÆ»Ö¸´ËíµÀ£¬£¬£¬£¬£¬È·±£¹¥»÷Ò»Á¬ÐÔÇÒïÔÌÊÖ¶¯¸ÉÔ¤±¬·¢µÄÔëÒô¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-roadk1ll-websocket-implant-used-to-pivot-on-breached-networks/


¾©¹«Íø°²±¸11010802024551ºÅ