ºÚ¿ÍÀûÓð²È«²âÊÔÀûÓ÷¨Ê½ÈëÇֲƸ»500Ç¿ÆóÒµ
°ä²¼¹¦·ò 2026-01-231. ºÚ¿ÍÀûÓð²È«²âÊÔÀûÓ÷¨Ê½ÈëÇֲƸ»500Ç¿ÆóÒµ
1ÔÂ21ÈÕ£¬£¬£¬×Ô¶¯»¯ÉøÈë²âÊÔ¹«Ë¾Pentera×îе÷²éÏÔʾ£¬£¬£¬ÍþвÐÐΪÕßÕýÀûÓÃÓÐÒâÉèÖ÷ì϶µÄ°²È«Åàѵ¼°ÉøÈë²âÊÔWebÀûÓã¨ÈçDVWA¡¢OWASP Juice ShopµÈ£©£¬£¬£¬¶Ô²Æ¸»500Ç¿ÆóÒµ¼°°²È«³§É̵ÄÔÆ»·¾³Ö´ÐÐÈëÇÖ¡£¡£¡£ÕâЩÀûÓÃÒòÅäÖÃÃýÎó¶³öÓÚ¹«¹²»¥ÁªÍø£¬£¬£¬²¢ÓëȨÏÞ¹ý¸ßµÄIAM½ÇÉ«¹ØÁª£¬£¬£¬²¿ÊðÔÚAWS¡¢GCP¡¢AzureµÈÔÆÆ½Ì¨£¬£¬£¬ÐγÉÑÏÖØ°²È«·çÏÕ¡£¡£¡£×êÑÐÍŶÓÔÚ¹«¹²ÍøÂç·¢ÏÖ1926¸ö´æÔÚ·ì϶µÄ»îÔ¾ÀûÓÃʵÀý£¬£¬£¬²¿ÃÅÊôÓÚCloudflare¡¢F5¡¢Palo Alto NetworksµÈ³ÛÃûÆóÒµ¡£¡£¡£ÕâЩʵÀýÖУ¬£¬£¬³¬°ëÊýÈÔʹÓÃĬÈÏÆ¾Ö¤£¬£¬£¬Î´×ñÑ"×îСȨÏÞ"×¼Ôò£¬£¬£¬µ¼Ö¹¥»÷Õ߿ɵÈÏлñÈ¡S3´æ´¢Í°¡¢Secrets Manager¶ÁдȨÏÞ£¬£¬£¬ÉõÖÁ»ñµÃÔÆ»·¾³ÖÎÀíÔ±½Ó¼ûȨ¡£¡£¡£Pentera֤ʵ£¬£¬£¬ºÚ¿ÍÒÑÀûÓÃÕâЩÈë¿Úµã²¿Êð¼ÓÃÜÇ®±ÒÍÚ¿ó·¨Ê½£¨ÈçXMRig£©¡¢webshell¼°Óƾû¯»úÖÆ¡£¡£¡£´ËÍ⣬£¬£¬×êÑÐÈËÔ±·¢ÏÖÃûΪ"filemanager.php"µÄwebshellÖ§³ÖÎļþ²Ù×÷ÓëºÅÁîÖ´ÐУ¬£¬£¬ÆäÊ±ÇøÉèÖÃΪŷÖÞ/Ã÷˹¿Ë£¨UTC+3£©£¬£¬£¬¿ÉÄܰµÊ¾¹¥»÷Õ߯ðÔ´¡£¡£¡£ÕâЩ¶ñÒⷨʽÔÚPentera֪ͨÓйع«Ë¾ºóÈÔ³ÖÐø»î¶¯£¬£¬£¬Ö±ÖÁÆóÒµÐÞ¸´ÎÊÌâ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-security-testing-apps-to-breach-fortune-500-firms/
2. LastPass´¹µö¹¥»÷ÀûÓÃÊØ»¤Í¨ÖªÓÕÆÓû§±¸·Ý
1ÔÂ21ÈÕ£¬£¬£¬½üÈÕ£¬£¬£¬ÃÜÂëÖÎÀíÆ½Ì¨LastPass°ä²¼°²È«ÖҸ棬£¬£¬¸æ·¢Ò»ÖÖ¼Ù×°³É·þÎñÊØ»¤Í¨ÖªµÄÐÂÐÍÍøÂç´¹µö¹¥»÷¡£¡£¡£¹¥»÷Õß×Ô1ÔÂ19ÈÕÆð£¬£¬£¬Í¨¹ý·¢ËÍÖ÷ÌâΪ"LastPass»ù´¡¼Ü¹¹¸üУº£º£ºÁ¢¼´±£»¤ÄúµÄ±£ÏÕ¿â""ÊØ»¤Ç°±¸·ÝÄúµÄ±£Ïտ⣨24Сʱ´°¿ÚÆÚ£©"µÈÓʼþ£¬£¬£¬ÓÕµ¼Óû§ÔÚ24СʱÄÚ±¸·ÝÊý¾Ý±£ÏÕ¿â¡£¡£¡£ÕâЩÓʼþ¼Ù×°³É¹Ù·½Í¨Ñ¶£¬£¬£¬Ðû³ÆÒò»ù´¡ÉèÊ©ÊØ»¤Ðè´´½¨±¾µØ±¸·ÝÒÔÈ·±£Êý¾Ý°²È«£¬£¬£¬²¢Ç¿µ÷"ÍòÒ»³öÏÖ¼¼ÊõÄÑÌ⣬£¬£¬±¸·Ý¿É±£ÏÕÐÅÏ¢°²È«¿É¸´Ô"£¬£¬£¬¿ÌÒâÖÆ×÷½ôÆÈ¸ÐÒÔÖ´ÐÐÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¾ÝLastPassÍþвµý±¨ÍŶÓÅû¶£¬£¬£¬¶ñÒâÓʼþÆðÔ´Ô̺¬"support@lastpass[.]server8""support@sr22vegas[.]com"µÈ·ÂðµØÖ·¡£¡£¡£Óû§µã»÷ÓʼþÖеÄ"Á¢¼´´´½¨±¸·Ý"°´Å¥ºó£¬£¬£¬½«±»Öض¨ÏòÖÁ"mail-lastpass[.]com"´¹µöÍøÕ¾¡£¡£¡£¸ÃÍøÕ¾ËäĿǰÒÑÀëÏߣ¬£¬£¬µ«¹¥»÷ÕßÒâͼͨ¹ýÓÕµ¼Óû§ÊäÈëÖ÷ÃÜÂë»òÖ´ÐжñÒâ²Ù×÷£¬£¬£¬ÊµÏÖÕË»§½Ù³Ö»òƾ֤ÇÔÈ¡¡£¡£¡£LastPassÇ¿µ÷£¬£¬£¬¹«Ë¾¾ø²»»áÒªÇóÓû§Í¨¹ýÓʼþ±¸·Ý±£Ïտ⣬£¬£¬¸ü²»»áË÷ÒªÖ÷ÃÜÂ룬£¬£¬Óû§Ó¦Ö±½Óͨ¹ý¹Ù·½ÇþµÀ»ã±¨¿ÉÒÉÊÂÎñÖÁ"mailto:abuse@lastpass.com"¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-lastpass-emails-pose-as-password-vault-backup-alerts/
3. Chainlit AI¿ò¼Ü·ì϶µ¼ÖºڿÍÈëÇÖÔÆ»·¾³
1ÔÂ21ÈÕ£¬£¬£¬¿ªÔ´¶Ô»°Ê½AI¿ò¼ÜChainlit±»ÆØ´æÔÚÁ½¸ö¸ßΣ·ì϶"ChainLeak"£¨CVE-2026-22218¡¢CVE-2026-22219£©£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÀûÓ㬣¬£¬Ó°ÏìÈ«Çò¶à¸öÐÐÒµ²¿ÊðµÄ»¥ÁªÍøAIϵͳ¡£¡£¡£¸Ã¿ò¼ÜÔÚPyPIÔ¾ùÏÂÔØÁ¿´ï70Íò´Î£¬£¬£¬ÄêÏÂÔØÁ¿³¬500Íò´Î£¬£¬£¬¿í·ºÓÃÓÚÆóÒµ¡¢Ñ§Êõ»ú¹¹µÄAIÀûÓù¹½¨£¬£¬£¬ÌṩÏÖ³É̸Ìì½çÃæ¡¢Éí·ÝÑéÖ¤¼°ÔƲ¿ÊðÖ§³Ö¡£¡£¡£·ì϶ϸ½ÚÏÔʾ£¬£¬£¬CVE-2026-22218ΪËÁÒâÎļþ¶ÁÈ¡·ì϶£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃ/project/element¶ËµãÌá·´Ä¿Òâ"path"²ÎÊý£¬£¬£¬Ç¿Àñ·þÎñÆ÷½«Ö¸¶¨õè¾¶Îļþ¸´ÖÆÖÁ¹¥»÷Õ߻Ự£¬£¬£¬´Ó¶øÇÔÈ¡APIÃÜÔ¿¡¢ÔÆÆ¾Ö¤¡¢Ô´´úÂë¡¢SQLiteÊý¾Ý¿âµÈÃô¸ÐÐÅÏ¢¡£¡£¡£CVE-2026-22219Ϊ·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬£¬£¬Ó°ÏìʹÓÃSQLAlchemyÊý¾Ý²ãµÄ²¿Ê𣬣¬£¬¹¥»÷Õßͨ¹ý"url"×Ö¶ÎÓÕµ¼·þÎñÆ÷ÌáÒéÍⲿGETÒªÇó²¢´æ´¢ÏìÓ¦£¬£¬£¬½ø¶øÍ¨¹ýÔªËØÏÂÔØ¶Ëµã»ñÈ¡Êý¾Ý£¬£¬£¬ÊµÏÖÄÚ²¿·þÎñ̽²â¼°REST API½Ó¼û¡£¡£¡£Zafran Labs×êÑÐÈËԱ֤ʵ£¬£¬£¬Á½·ì϶¿É×éºÏ³É¹¥»÷Á´£¬£¬£¬µ¼ÖÂϵͳÆëÈ«ÈëÇÖ¼°ÔÆ»·¾³ºáÏòÒÆ¶¯¡£¡£¡£·ì϶ÓÚ2025Äê11ÔÂ23ÈÕ³õ´Î»ã±¨£¬£¬£¬12ÔÂ9ÈÕ»ñÊØ»¤ÕßÈ·ÈÏ£¬£¬£¬12ÔÂ24ÈÕͨ¹ýChainlit 2.9.4°æ±¾ÐÞ¸´£¬£¬£¬×îа汾Ϊ2.9.6¡£¡£¡£
https://www.bleepingcomputer.com/news/security/chainlit-ai-framework-bugs-let-hackers-breach-cloud-environments/
4. ÐÂÐÍOsirisÀÕË÷Èí¼þÏÖÉí£¬£¬£¬POORTRYÇý¶¯Ö´ÐÐBYOVD¹¥»÷
1ÔÂ22ÈÕ£¬£¬£¬¶«ÄÏÑÇÒ»¼Ò´óÐÍʳƷ·þÎñÌØÐí¾ÓªÉÌ2025Äê11ÔÂÔâ·êÐÂÐÍÀÕË÷Èí¼þOsiris¹¥»÷¡£¡£¡£ÈüÃÅÌú¿ËÓëCarbon BlackÍŶÓÅû¶£¬£¬£¬¸Ã¹¥»÷ÀûÓÃÃûΪPOORTRYµÄ¶ñÒâÇý¶¯·¨Ê½£¬£¬£¬Í¨¹ý"×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½£¨BYOVD£©"¼¼Êõ½ûÓð²È«Èí¼þ£¬£¬£¬Óë2016ÄêLocky±äÖÖÎ޹ء£¡£¡£Osirisѡȡ»ìºÏ¼ÓÃܹ滮£¬£¬£¬ÎªÃ¿¸öÎļþÌìÉúΨһÃÜÔ¿£¬£¬£¬¾ß±¸ÖÕ³¡·þÎñ¡¢Ö¸¶¨¼ÓÃÜÁìÓò¡¢ÖÕÖ¹¹ý³Ì¼°Í¶·ÅÀÕË÷ÐŵÈÄÜÁ¦£¬£¬£¬Ä¬ÈÏÖÕÖ¹Office¡¢Exchange¡¢VeeamµÈ¹ý³Ì£¬£¬£¬±»ÆÀ¹ÀΪ¾Ñé·á˶¹¥»÷ÕߵĸßЧ¹¤¾ß¡£¡£¡£¹¥»÷Õßͨ¹ýRclone½«Ãô¸ÐÊý¾ÝÇÔÈ¡ÖÁWasabiÔÆ´æ´¢£¬£¬£¬Ê¹ÓÃNetscan¡¢Netexec¡¢MeshAgent¼°¶¨ÖÆRustdeskµÈË«Óô¦¹¤¾ß£¬£¬£¬²¢²¿ÊðKillAV¹¤¾ßÌáÉýȨÏÞ¡£¡£¡£ÏßË÷ÏÔʾÆä¿ÉÄÜÓëINCÀÕË÷Èí¼þ£¨±ðºÅWarble£©´æÔÚ¹ØÁª£¬£¬£¬ÒòʹÓÃÁËÒ»Ñù°æ±¾µÄMimikatz¹¤¾ß£¨kaz.exe£©¡£¡£¡£
https://thehackernews.com/2026/01/new-osiris-ransomware-emerges-as-new.html
5. SmarterMailÖÎÀíÔ±ÃÜÂëÖØÖ÷ì϶ÔâºÚ²úÄæÏòÀûÓÃ
1ÔÂ22ÈÕ£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾watchTowr 1ÔÂ8ÈÕÅû¶SmarterToolsÆìÏÂSmarterMailÓʼþ·þÎñÆ÷´æÔÚ¸ßΣÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¸Ã·ì϶λÓÚ"force-reset-password"API¶Ëµã£¬£¬£¬¹¥»÷ÕßÎÞÐèÈÏÖ¤¼´¿Éͨ¹ý·¢ËÍÔ̺¬"IsSysAdmin":trueµÄJSONÊý¾Ý£¬£¬£¬Ç¿ÖÆÖØÖÃϵͳÖÎÀíÔ±ÃÜÂë²¢»ñµÃÆëÈ«½ÚÖÆÈ¨ÏÞ¡£¡£¡£Ö»¹ÜSmarterMailÔÚ1ÔÂ15ÈÕ´¹Î£°ä²¼Build 9511°æ±¾ÐÞ¸´´Ë·ì϶£¬£¬£¬µ«×êÑÐÈËÔ±·¢ÏÖ¹¥»÷Õß½öÓÃÁ½Ìì±ãÄæÏò²¹¶¡²¢Ö´ÐÐÀûÓ㬣¬£¬Ó¡Ö¤ºÚ²ú¶Ô²¹¶¡µÄ¸ßÐ§ÄæÏòÄÜÁ¦¡£¡£¡£¼¼Êõ·ÖÎöÏÔʾ£¬£¬£¬¸ÃAPI¶ËµãδÑéÖ¤¾ÉÃÜÂë×ֶΣ¬£¬£¬¹¥»÷ÕßÖ»Ðèͨ´ïÖÎÀíÔ±Óû§Ãû¼´¿ÉʵÏÖÃÜÂë½Ù³Ö¡£¡£¡£³É¹¦ÈëÇֺ󣬣¬£¬¹¥»÷Õß¿ÉÖ´ÐвÙ×÷ϵͳºÅÁîʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£watchTowrͨ¹ý¸ÅÄîÑéÖ¤ÑÝʾÁËϵͳ¼¶shell½Ó¼û£¬£¬£¬²¢´ÓÄäÃû¶úÄ¿´¦»ñÖªÏÖʵ¹¥»÷°¸Àý£¬£¬£¬ÂÛ̳Ìû×ÓÏÔʾÓй¥»÷ÕßÕýÔÚÅúÁ¿ÖØÖÃÖÎÀíÔ±ÃÜÂ룬£¬£¬ÈÕÖ¾·ÖÎö֤ʵ¹¥»÷Ö¸±êȷΪ"force-reset-password"¶Ëµã¡£¡£¡£
https://www.bleepingcomputer.com/news/security/smartermail-auth-bypass-flaw-now-exploited-to-hijack-admin-accounts/
6. Á¢Ñ¶¾«ÃÜÔâÀÕË÷¹¥»÷£¬£¬£¬Æ»¹ûµÈÆóÒµÖ÷Ìâ˼ÃÜÃæ¶Ôй¶·çÏÕ
1ÔÂ19ÈÕ£¬£¬£¬Æ»¹ûÖ÷Ìâ´ú¹¤³§Á¢Ñ¶¾«ÃÜ2025Äê12ÔÂ15ÈÕÔâ·êÒÉËÆÓÉRansomHubºÚ¿Í×éÖ¯ÌáÒéµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸Ã×éÖ¯ÔÚ°µÍøÂÛ̳Ðû³ÆÒѼÓÃÜÁ¢Ñ¶¾«ÃÜÊý¾Ý£¬£¬£¬²¢ÍþвÈô²»Ö§¸¶Êê½ð½«Ð¹Â¶Æ»¹û¡¢Ó¢Î°´ï¡¢LGµÈÆóÒµ»úÃÜÊý¾Ý¡£¡£¡£Á¢Ñ¶¾«ÃÜ×÷Ϊƻ¹ûÖØÒªºÏ×÷ͬ°é£¬£¬£¬ÕƹÜiPhone¡¢AirPods¡¢Apple Watch¼°Í·ÏÔÉ豸×é×°£¬£¬£¬°ÑÎÕ´óÁ¿Ö÷Ìâ˼ÃÜÐÅÏ¢¡£¡£¡£×êÑÐÍŶӷÖÎöºÚ¿ÍÅû¶µÄÊý¾ÝÑù±¾·¢ÏÖ£¬£¬£¬Ð¹Â¶ÄÚÈݺ¸Ç2019-2025Äê¼äÆ»¹ûÓëÁ¢Ñ¶¾«ÃܺÏ×÷µÄÉ豸άÐÞ¡¢ÎïÁ÷ÔËÊäµÈÏîĿϸ½Ú£¬£¬£¬Ô̺¬¹¦·ò¹æ»®¡¢¾ßÌåÁ÷³Ì¼°¿Í»§×ÊÁÏ¡£¡£¡£´ËÍ⣬£¬£¬Êý¾ÝÖÐÔ̺¬Ô±¹¤ÐÕÃû¡¢Ö°Î»¡¢¹¤×÷ÓÊÏäµÈÃô¸ÐСÎÒÐÅÏ¢£¬£¬£¬ÒÔ¼°.dwg¡¢GerberµÈÉè¼ÆÎļþ£¬£¬£¬Éæ¼°3D CADÄ£ÐÍ¡¢µç·°åÖÆ×÷Êý¾Ý¡¢µçÆø¼Ü¹¹µÈ¸ß¶ÈÃô¸ÐóÒ×ÔËÓªÄÚÈÝ¡£¡£¡£RansomHubÐû³ÆÒÑ»ñȡƻ¹û¡¢Ó¢Î°´ï¡¢LG¡¢¼ªÀû¡¢ÌØË¹ÀµÈ¶à¼ÒÆóÒµµÄ3D¹¤³ÌÉè¼Æ¡¢2D×é¼þͼֽ¡¢PDF¹¤³Ìͼ¼°Ó¡Ë¢µç·°åÖÆ×÷Êý¾Ý£¬£¬£¬ÕâЩÊܱ£ÃܺÍ̸±£»¤µÄ³ö²úÑз¢ÐÅÏ¢Èô±»Ð¹Â¶£¬£¬£¬¿ÉÄܱ»¾ºÕùµÐÊÖÓÃÓÚ·´ÏòÑз¢»òÖÆ×÷·Âð²úÆ·£¬£¬£¬½Ú¼óÊýÄêÑз¢³É±¾¡£¡£¡£
https://cybernews.com/security/luxshare-apple-iphone-assembler-breach/


¾©¹«Íø°²±¸11010802024551ºÅ