FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
°ä²¼¹¦·ò 2026-01-221. FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
1ÔÂ21ÈÕ£¬£¬½üÆÚ£¬£¬Fortinet¿Í»§Ôâ·êÑÏÖØ°²È«ÊÂÎñ£º¹¥»÷ÕßÀûÓÃÒÑÐÞ¸´µÄFortiGateÉí·ÝÑéÖ¤·ì϶CVE-2025-59718µÄ²¹¶¡Èƹý·ì϶£¬£¬³É¹¦ÈëÇÖÒÑ´ò²¹¶¡µÄ·À»ðǽÉ豸¡£¡£¸Ã·ìÏ¶Éæ¼°FortiCloudµ¥µãµÇ¼(SSO)Ö°ÄÜ£¬£¬Ö»¹ÜFortinetÔÚ³õʼ²¼¸æÖÐÇ¿µ÷£¬£¬Î´×¢²áFortiCareµÄÉ豸ĬÈÏδÆôÓøÃÖ°ÄÜ£¬£¬¿ÉÏ÷¼õÊÜÓ°ÏìÁìÓò£¬£¬µ«Shadowserver»ù½ð»á12ÔÂÖÐÑ®µÄɨÃèÏÔʾ£¬£¬ÈÔÓг¬¹ý25,000̨ÆôÓÃFortiCloud SSOµÄFortinetÉ豸¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£Ö»¹ÜĿǰ³¬°ëÊýÉ豸ÒÑÊܱ£»¤£¬£¬ÈÔÓг¬¹ý11,000̨É豸¿É±»¹«¿ª½Ó¼û£¬£¬×é³ÉÖØ´ó·çÏÕ¡£¡£ÎªÓ¦¶ÔÍþв£¬£¬Fortinet½¨ÒéÖÎÀíÔ±ÔÚÌṩÆëÈ«ÐÞ¸´µÄFortiOS°æ±¾Ç°£¬£¬ÁÙʱ½ûÓÃFortiCloudµÇ¼ְÄÜ¡£¡£¾ßÌå²Ù×÷¿Éͨ¹ýWeb½çÃæ½øÈë"ϵͳ"¡ú"ÉèÖÃ"£¬£¬¹Ø±Õ"ÔÊÐíʹÓÃFortiCloud SSO½øÐÐÖÎÀíÔ±µÇ¼"Ñ¡Ï£¬»òͨ¹ýºÅÁîÐÐÖ´ÐÐ"config system global; set admin-forticloud-sso-login disable; end"ʵÏÖ¡£¡£ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö(CISA)Òѽ«¸Ã·ì϶ÁÐÈë"ÕýÔÚ±»ÀûÓõķì϶"Çåµ¥£¬£¬ÒªÇóÁª°î»ú¹¹ÔÚÒ»ÖÜÄÚʵÏÖÐÞ²¹¡£¡£
https://www.bleepingcomputer.com/news/security/fortinet-admins-report-patched-fortigate-firewalls-getting-hacked/
2. ÒÁÀʵçÊǪ́ÔâºÚ¿Í¹¥»÷²¥·ÅÍõ´¢½²»°
1ÔÂ21ÈÕ£¬£¬ÒÁÀʶà¼ÒµçÊǪ́½ÚÄ¿1ÔÂ18ÈÕÍí¼äÔâºÚ¿ÍÖжϣ¬£¬¹¥»÷Õßͨ¹ý°ÍµÂ¶ûÎÀÐÇ´«ÊäϵͳÊÕÊÜÐźţ¬£¬²¥·Å½ÖÍ·¿¹Òé»Ãæ¼°ÍöÃüÍõ´¢ÀñÈø¡¤°ÍÁÐάµÄ¼«¶ÈÖÓÔ¤ÏÈÂ¼ÖÆ½²»°¡£¡£°ÍÁÐάÔÚÊÓÆµÖкôÓõÒÁÀʹúÃñ¾üÓëÃñÖÚÁª½á£¬£¬Ôð¹Ö°²È«¶ÓÁС°Ð§ÖÒÒÁ˹À¼¹²ºÍ¹ú¶ø·ÇÒÁÀÊ¡±£¬£¬²¢Ðû³Æ²¿ÃÅÊ¿±øÒѵ¹¸ê£¬£¬µ«Î´Ìṩ֤¾Ý¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËÒÁÀÊÒÁ˹À¼¹²ºÍ¹ú¹ã²¥µçÊǪ́£¨IRIB£©¸²¸Ç´åÂ䵨ÓòµÄÎÀÐÇÐźţ¬£¬ÓйØÊÓÆµÆ¬¶ÎѸËÙ±»°ÍÁÐάÍŶӡ¢¡¢¡¢ÒÁÀʹú¼ÊµçÊǪ́¼°±¾µØÃ½Ìåת·¢´«²¼¡£¡£ÊÂÎñ²úÉúÔÚÒÁÀÊÉîÏݾ¼ÃΣ»úÖ®¼Ê¡£¡£×Ô2025Äê12ÔÂµ×Æð£¬£¬ÒÁÀÊÇ®±ÒÀïÑǶû´ó·ù±áÖµ£¬£¬Ê³Æ·¼Ûֵʧ¿ØìÉý£¬£¬ÃñÖÚ½«¾¼ÃÀ§¾³¹é×ïÓÚµ±¾ÖµòÂä¡£¡£Îª×èÖ¹±©Á¦ÐÂÎÅ´«²¼£¬£¬ÒÁÀʵ±¾Ö¹Ø±Õ»¥ÁªÍøºÍÒÆ¶¯·þÎñ³¤´ïÁ½ÖÜ¡£¡£È»¶ø£¬£¬²¿ÃžÓÃñͨ¹ýÐÇÁ´ÎÀÐÇÌ×¼þ½«ºÚ¿ÍÇÔÈ¡µÄÊÓÆµ´«²¼ÖÁÈ«Çò¡£¡£ÓëÒÁÀʸïÃüÎÀ¶Ó¹ØÁªµÄ·¨¶û˹ͨѶÉçÔ®Òý¹ú¶È¹ã²¥¹«Ë¾Ëµ·¨£¬£¬³Æ²¿ÃŵØÓòÐźš°Òò²»Ã÷ÔÒò¶ÌÔÝÖжϡ±£¬£¬µ«Î´Ìá¼°¿¹ÒéÊÓÆµ»òÍõ´¢½²»°ÄÚÈÝ¡£¡£
https://hackread.com/iranian-tv-transmission-hacked-exiled-prince-message/
3. Cisco´¹Î£ÐÞ¸´¸ßΣÁãÈÕ·ì϶CVE-2026-20045
1ÔÂ21ÈÕ£¬£¬Ë¼¿Æ¹«Ë¾½üÈÕÐÞ¸´ÁËÒ»¸öÑÏÖØµÄ¸ßΣÁãÈÕÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2026-20045£¨CVSSÆÀ·Ö8.2£©£¬£¬¸Ã·ì϶Òѱ»·¢ÏÖ±»»ý¼«ÀûÓÃÓÚ¹¥»÷¡£¡£´Ë·ì϶ԴÓÚHTTPÒªÇóÖÐÓû§ÊäÈëÐÅÏ¢ÑéÖ¤²»µ±£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸µÄWebÖÎÀí½çÃæ·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇ󣬣¬ÔÚÉ豸µ×²ã²Ù×÷ϵͳִÐÐËÁÒâºÅÁ£¬×îÖÕ¿ÉÄÜ»ñÈ¡rootȨÏÞ¡£¡£ÊÜÓ°Ïì²úÆ·Ô̺¬Cisco Unified CM¡¢¡¢¡¢Unified CM SME¡¢¡¢¡¢IM & Presence¡¢¡¢¡¢Unity Connection¼°Webex Calling Dedicated Instance¡£¡£¾ßÌåÐÞ¸´°æ±¾ÈçÏ£ºUnified CMµÈϵÁÐ12.5°æ±¾ÐèǨáãÖÁ¹Ì¶¨°æ±¾£»14°æ±¾ÐèÉý¼¶ÖÁ14SU5»òÀûÓò¹¶¡Îļþ£»15°æ±¾ÐèÉý¼¶ÖÁ2026Äê3Ô°䲼µÄ15SU4»òÀûÓöÔÓ¦²¹¶¡¡£¡£Unity ConnectionͬÑùÐèÆ¾¾Ý°æ±¾Éý¼¶ÖÁ14SU5»ò15SU4²¢ÀûÓò¹¶¡¡£¡£Ë¼¿ÆÇ¿µ÷²¹¶¡Óë°æ±¾Ñϸñ¶ÔÓ¦£¬£¬Óû§Ðè²Î¿¼²¹¶¡READMEÎļþ²Ù×÷¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬Õâ´ÎÐÞ¸´ÎÞһʱ½â¾ö¹æ»®£¬£¬Ë¼¿Æ°²È«Ó¦¼±ÏìӦС×飨PSIRT£©ÒÑÈ·ÈÏ´æÔÚÀûÓó¢ÊÔ£¬£¬Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶ÖÁÐÞ¸´°æ±¾¡£¡£
https://securityaffairs.com/187177/security/cisco-fixed-actively-exploited-unified-communications-zero-day.html
4. Zendesk¹¤µ¥ÏµÍ³ÔâÈ«Çò´ó¹æÄ£À¬»øÓʼþ¹¥»÷
1ÔÂ21ÈÕ£¬£¬È«ÇòÓû§Ôâ·êÓÉZendeskÖ§³ÖϵͳÒý·¢µÄ´ó¹æÄ£À¬»øÓʼþ¹¥»÷£¬£¬Êܺ¦ÕßÊÕµ½Êý°Ù·âÖ÷Ìâ¹îÒìÇÒÄÚÈÝ»ìÂÒµÄÓʼþ£¬£¬Òý·¢¿í·º²ÂÒÉÓë·¢¼±¡£¡£Õâ´Î¹¥»÷Ô´ÓÚZendeskÔÊÐíδ¾ÑéÖ¤Óû§Ìá½»Ö§³Ö¹¤µ¥µÄ·ì϶£¬£¬¹¥»÷Õßͨ¹ý±éÀúº£Á¿ÓʼþµØÖ·ÁÐ±í´´½¨Ðéα¹¤µ¥£¬£¬´¥·¢ÏµÍ³×Ô¶¯·¢ËÍÈ·ÈÏÓʼþ£¬£¬½«ºÏ·¨ÆóÒµµÄZendeskƽ̨±äΪÀ¬»øÓʼþÖмÌÕ¾¡£¡£ÊÜÓ°ÏìÆóÒµº¸Ç¿Æ¼¼¡¢¡¢¡¢ÓÎÏ·¡¢¡¢¡¢ÕþÎñµÈ¶àÁìÓò£¬£¬Ô̺¬Discord¡¢¡¢¡¢Tinder¡¢¡¢¡¢Riot Games¡¢¡¢¡¢Dropbox¡¢¡¢¡¢CD Projekt¡¢¡¢¡¢ÌïÄÉÎ÷ÖÝÀ͹¤²¿µÈ³¬20¼Ò»ú¹¹¡£¡£ÓʼþÖ÷Ìâ³öÏָ߶ȹƻóÐÔÌØµã£º²¿ÃżÙ×°·¨ÂÉ֪ͨ¡¢¡¢¡¢²¿ÃųÐŵÃâ·Ñ¸£Àû¡¢¡¢¡¢¸üÓдóÁ¿Ê¹ÓÃUnicode×°è«×ÖÌå±àдµÄÂÒÂëÄÚÈÝ¡£¡£ÓÉÓÚÓʼþÔ´×ÔÕý¹æÆóҵϵͳ£¬£¬Æä¿ÉÐŶÈÔ¶³¬Í¨³£À¬»øÓʼþ£¬£¬³É¹¦ÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬Ðγɸü´óÇÖÈÅÐÔ¡£¡£ÉæÊÂÆóҵѸËÙ»ØÓ¦£ºDropbox¡¢¡¢¡¢2KµÈÃ÷È·°µÊ¾ÓʼþΪϵͳÀÄÓòúÆ·£¬£¬Ç¿µ÷Æä"ŷʤµ¥Ìá½»"Õþ²ßËä·½±ãµ«´æÔÚ·çÏÕ£¬£¬³Ðŵδ¾ÕË»§³ÖÓÐÈËÑéÖ¤²»»á´¦ÖÃÃô¸ÐÒªÇ󣬣¬½¨ÒéÓû§Ö±½ÓºöÂÔÒì³£Óʼþ¡£¡£Zendesk¹Ù·½Åû¶£¬£¬¹«Ë¾ÒÑ´¹Î£²¿ÊðÐÂÐͰ²È«Ö°ÄÜ£¬£¬Í¨¹ý¼ÓÇ¿¼à¿ØËã·¨ÓëÖ´ÐлÏÞ¶È£¬£¬ÌáÉý¶ÔÒì³£¹¤µ¥µÄ¼ì²âÓëÀ¹½ØÐ§ÄÜ¡£¡£
https://www.bleepingcomputer.com/news/security/zendesk-ticket-systems-hijacked-in-massive-global-spam-wave/
5. ÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾ÂíÀûÓÃTensorFlow¼¼Êõ´«²¼
1ÔÂ21ÈÕ£¬£¬½üÆÚ£¬£¬Ò»ÖÖÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾Âíͨ¹ýСÃ×¹Ù·½ÀûÓÃÉ̵êGetApps´«²¼£¬£¬ÀûÓÃTensorFlow»úеѧϰģÐÍ×Ô¶¯¼ì²â²¢½»»¥¸æ°×ÔªËØ£¬£¬Òý·¢°²È«¹Ø×¢¡£¡£¸ÃľÂíѡȡÁ½ÖÖÔËÐÐģʽ£º"»ÃÓ°"ģʽͨ¹ý°µ²ØµÄWebViewä¯ÀÀÆ÷¼ÓÔØÖ¸±êÒ³Ãæ£¬£¬½ØÈ¡ÆÁÄ»½ØÍ¼ºóÓÉTensorFlow.js·ÖÎö¸æ°×ÔªËØ£¬£¬·ÂÕÕÓû§µã»÷£»"ÐźŴ«µÝ"ģʽÔòͨ¹ýWebRTC´«ÊäʵʱÊÓÆµÁ÷ÖÁ¹¥»÷Õߣ¬£¬Ö§³ÖÔ¶³Ì²Ù×÷µã»÷¡¢¡¢¡¢¹ö¶¯µÈÐÐΪ¡£¡£ÕâÖÖ»ùÓÚÊÓ¾õ·ÖÎöµÄ»úÖÆÍ»ÆÆÁË´«Í³¾ç±¾DOM½»»¥µÄÏÞ¶È£¬£¬Äܸü¸ßЧӦ¶Ô¶¯Ì¬¸æ°×µÄƵÈԽṹ±ä¶¯¡£¡£Ä¾Âí´«²¼õè¾¶Òñ±Î£º¹¥»÷ÕßÊ×ÏȽ«Õý³£ÓÎÏ·ÀûÓÃÌá½»ÖÁGetApps£¬£¬ºóÐøÍ¨¹ý¸üÐÂÔö³¤¶ñÒâ×é¼þ¡£¡£Dr.Web×êÑÐÏÔʾ£¬£¬ÊÜϰȾÓÎÏ·Ô̺¬¡¶ÏÀµÁÁÔ³µÊÖ£ººÚÊÖµ³¡·£¨6.1Íò´ÎÏÂÔØ£©¡¢¡¢¡¢¡¶¿É°®³èÎïÎÝ¡·£¨3.4Íò´ÎÏÂÔØ£©µÈ£¬£¬¸²¸Ç¶à¸öÈȵãÓÎÏ·¡£¡£´ËÍ⣬£¬Ä¾Âí»¹Í¨¹ýµÚÈý·½APKÍøÕ¾£¨ÈçApkmody¡¢¡¢¡¢Moddroid£©¡¢¡¢¡¢TelegramƵµÀ¼°Õ¼ÓÐ2.4Íò¶©ÔÄÕßµÄDiscord·þÎñÆ÷À©É¢£¬£¬Éæ¼°Spotify Pro¡¢¡¢¡¢Netflix modµÈÅú¸Ä°æÀûÓᣡ£
https://www.bleepingcomputer.com/news/security/new-android-malware-uses-ai-to-click-on-hidden-browser-ads/
6. Î÷°àÑÀPcComponentes·ñ¶¨1600Íò¿Í»§Êý¾Ýй¶
1ÔÂ21ÈÕ£¬£¬Î÷°àÑÀ¿Æ¼¼ÁãÊÛÉÌPcComponentes½üÈÕ·ñ¶¨ÆäϵͳÔâ·ê´ó¹æÄ£Êý¾Ýй¶ӰÏì1600Íò¿Í»§µÄ˵·¨£¬£¬µ«Ö¤ÊµÔâ·êײ¿â¹¥»÷¡£¡£´Ëǰ£¬£¬ºÚ¿Í×éÖ¯"daghetiaw"Ðû³ÆÇÔÈ¡¸Ã¹«Ë¾1630ÍòÌõ¿Í»§¼Í¼£¬£¬²¢Ð¹Â¶50ÍòÌõÑù±¾£¬£¬Ôü×Ҽͼ´ý¼Û¶ø¹Á¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¶©µ¥ÏêÇé¡¢¡¢¡¢ÏÖʵµØÖ·¡¢¡¢¡¢È«Ãû¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢IPµØÖ·¡¢¡¢¡¢²úÆ·ÓûÍûÇåµ¥¼°ZendeskÖ§³Ö¶Ô»°¼Í¼¡£¡£PcComponentesÔÚµ÷²éºóÉêÃ÷£¬£¬ÆäÊý¾Ý¿âºÍÄÚ²¿ÏµÍ³Î´·¢ÏÖ·¸·¨½Ó¼ûÖ¤¾Ý£¬£¬Ç¿µ÷"1600ÍòÊÜÓ°Ïì¿Í»§"Êý×Ö²»Êµ£¬£¬Òò»îÔ¾ÕË»§ÊýÁ¿Ô¶µÍÓÚ´Ë£¬£¬ÇÒϵͳÖдÓδ´æ´¢²ÆÕþÐÅÏ¢»ò¿Í»§ÃÜÂë¡£¡£È»¶ø£¬£¬¹«Ë¾ÈϿɼì²âµ½×²¿â¹¥»÷ºÛ¼££¬£¬¹¥»÷ÕßÀûÓÃÆäËûƽ̨й¶µÄÓÊÏäÃÜÂë×éºÏ£¬£¬Í¨¹ý×Ô¶¯»¯¹¤¾ß³¢ÊԵǼPcComponentesÕË»§¡£¡£Íþвµý±¨¹«Ë¾Hudson Rock·ÖÎö·¢ÏÖ£¬£¬¹¥»÷Õß¿ÉÄÜͨ¹ýϰȾÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÍÆËã»úÍøÂçµÇ¼ƾ֤£¬£¬²¿ÃżÍ¼¿É×·ÒäÖÁ2020Äê¡£¡£ÆäÑéÖ¤µÄÁù¸öÓÊÏä¾ùÔÚÒÑÖªÇÔÃÜÈÕÖ¾ÖдæÔÚ£¬£¬Ö¤Êµ¹¥»÷Ó뺹Çàй¶Êý¾Ý´æÔÚ¹ØÁª¡£¡£
https://www.bleepingcomputer.com/news/security/online-retailer-pccomponentes-says-data-breach-claims-are-fake/


¾©¹«Íø°²±¸11010802024551ºÅ