ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾

°ä²¼¹¦·ò 2026-03-10

1. ÐÂÔóÎ÷ÅÁÈûÒÁ¿ËÏØÔâÍøÂç¹¥»÷Ö¹«¹²·þÎṉ̃»¾


3ÔÂ6ÈÕ£¬£¬ÃÀ¹úÐÂÔóÎ÷Öݱ±²¿ÅÁÈûÒÁ¿ËÏØÓÚ2026Äê3ÔÂ4ÈÕÍí¼ä°ä²¼´¹Î£²¼¸æ£¬£¬È·ÈÏÔâ·ê¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂÈ«ÏØµ±²¿ÃÅÃÅITϵͳÓëµç»°ÏßÂ·È«ÃæÖжÏ¡£¸ÃÏØÕý½áºÏÁª°î¼°Öݵ±¾Ö¹ÙÔ±·¢Õ¹µ÷²é£¬£¬ÊÔͼ½ÚÖÆÊÂ̬²¢¸´Ô­·þÎñ¡£Õâ´Î¹¥»÷ÊÂÎñʼÓÚ3ÔÂ4ÈÕÉÏÎç³õ´Î»ã±¨µÄµç»°Ïß·¹ÊÕÏ£¬£¬¾­µ÷²éºóÓÚµ±ÈÕÏÂÎçÈ·ÒÔÎªÍøÂç¹¥»÷ËùÖ¡£ÅÁÈûÒÁ¿ËÏØ¹ÙԱǿµ÷£¬£¬ÐÂÔóÎ÷ÖÝÄÚ¶à¸ö´¦Ëùµ±¾Ö½üÆÚ¾ùÔâ·êÀàËÆÍøÂç¹¥»÷ÊÂÎñ£¬£¬¿ÉÄÜÉæ¼°´ËǰÔâÀÕË÷Èí¼þ¹¥»÷µÄÈøÄ¬ÈûÌØÏØ¡¢¡¢¿¨Ä·µÇÏØ¡¢¡¢²®¸ùÏØ¡¢¡¢ÃÉÌØ¿ËÀ³¶ûÕò¼°»ô²©¿ÏÊС£ÅÁÈûÒÁ¿ËÏØÊÂÎñÔÙ´Î͹ÏÔ´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·À»¤·½ÃæµÄ´àÈõÐÔ¡£·ÖÎöÖ¸³ö£¬£¬ÖÐСÐÍ´¦Ëùµ±¾ÖÒò×ÊÔ´ÓÐÏÞ£¬£¬ÍùÍù³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄ¡°ÈíÖ¸±ê¡±¡£Ä¿Ç°£¬£¬ÅÁÈûÒÁ¿ËÏØÉÐδÅû¶¹¥»÷¾ßÌåϸ½Ú¼°ÀÕË÷ÒªÇ󣬣¬µ«Ç¿µ÷½«ÓÅÏȸ´Ô­¹«¹²·þÎñ²¢¹²Í¬·¨Âɲ¿ÃŲ龿¹¥»÷ÆðÔ´¡£


https://therecord.media/new-jersey-county-says-malware-attack-took-down-phones


2. Nginx UI¸ßΣ·ì϶Ö±¸·ÝÊý¾Ýй¶·çÏÕ


3ÔÂ8ÈÕ£¬£¬Nginx UIÖÎÀí½çÃæÆØ³ö±àºÅΪCVE-2026-27944µÄÑÏÖØ·ì϶£¨CVSSÆÀ·Ö9.8£©£¬£¬¹¥»÷Õß¿Éδ¾­Éí·ÝÑéÖ¤ÏÂÔØ²¢½âÃÜ·þÎñÆ÷ÆëÈ«±¸·Ý£¬£¬µ¼ÖÂÃô¸ÐÅäÖᢡ¢Í´´¦¼°¼ÓÃÜÃÜԿй¶¡£¸Ã·ì϶ԴÓÚ/api/backup¶ËµãδִÐнӼû½ÚÖÆ£¬£¬ÇÒÏìӦͷֱ½Ó¶³ö½âÃÜËùÐèµÄAES-256¼ÓÃÜÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿£¬£¬Ê¹¹¥»÷ÕßÄÜÖ±½Ó»ñÈ¡Ô̺¬Óû§Í´´¦¡¢¡¢»á»°ÁîÅÆ¡¢¡¢SSL˽Կ¡¢¡¢NginxÅäÖÃÎļþ¡¢¡¢Êý¾Ý¿âÏνÓÐÅÏ¢µÈÖ÷ÌâÊý¾ÝµÄ±¸·Ý°ü¡£Nginx UI×÷Ϊ¼ò»¯·þÎñÆ÷ÖÎÀíµÄWeb½ÚÖÆÃæ°å£¬£¬±¾Ó¦Í¨¹ýͼÐλ¯½çÃæ½µµÍÅäÖÃÃż÷£¬£¬µ«Õâ´Î·ì϶¶³öÆäÉè¼ÆÈ±µã£¬£¬ÖÎÀí½Ó¿Ú¶³öÓÚ¹«¹²»¥ÁªÍøÊ±£¬£¬²»×ã¸ù»ùµÄ°²È«·À»¤¡£Ò»µ©±¸·Ý±»½âÃÜ£¬£¬¹¥»÷Õß¿ÉÆëÈ«½ÚÖÆÖÎÀí½çÃæ£¬£¬´Û¸Ä·´Ïò´úÀí¹æ¶¨¡¢¡¢Öض¨ÏòÁ÷Á¿»òÖ²Èë¶ñÒâ¾ç±¾£»£»SSL˽Կй¶½«µ¼ÖÂÍøÕ¾¼ÙÒâ»òÖÐÑëÈ˹¥»÷£»£»Êý¾Ý¿âÍ´´¦ºÍÅäÖÃÎļþ¿ÉÄÜй¶Óû§Êý¾Ý¼°ÀûÓ÷¨Ê½»úÃÜ£»£»NginxÅäÖÃϸ½Ú¸ü»á¶³öÄÚ²¿ÍøÂç¼Ü¹¹£¬£¬ÎªºóÐø¹¥»÷Ìṩõè¾¶¡£Ä¿Ç°£¬£¬Nginx¹Ù·½ÒѰ䲼ÐÞ¸´°æ±¾£¬£¬Óû§Ó¦Á¢¼´Éý¼¶²¢Éó²é±¸·Ý´æ´¢Õ½Êõ£¬£¬È·±£¼ÓÃÜÃÜÔ¿Ó뱸·Ý·ÖÀë´æ´¢¡£


https://securityaffairs.com/189123/security/critical-nginx-ui-flaw-cve-2026-27944-exposes-server-backups.html


3. ΢Èí¹¤¾ß³ÉºÚ¿ÍкóÃŹ¥»÷½ðÈÚÒ½ÁÆÔØÌå


3ÔÂ9ÈÕ£¬£¬ÍøÂ簲ȫ¹«Ë¾BlueVoyant×îÐÂÅû¶£¬£¬Õë¶Ô¼ÓÄôó½ðÈÚ»ú¹¹¼°È«ÇòÒ½ÁƱ£½¡×éÖ¯µÄ¶¨Ïò¹¥»÷ÖУ¬£¬ºÚ¿Íͨ¹ýÉç»á¹¤³Ìѧ¼¿Á©½áºÏ΢ÈíÉú̬¹¤¾ßÖ´ÐÐÐÂÐͶñÒâÈí¼þ²¿Êð¡£¹¥»÷ÕßÊ×ÏÈÏòÖ¸±êÔ±¹¤·¢ËÍ´óÁ¿À¬»øÓʼþ³ÉÁ¢ÐÅÀµ£¬£¬Ëæºó¼Ù×°³ÉÆóÒµITÈËԱͨ¹ýMicrosoft TeamsÁªÏµÊܺ¦Õߣ¬£¬ÒÔЭÖú´¦ÖÃÀ¬»øÓʼþΪÓÉÓÕµ¼ÆäÆô¶¯Quick AssistÔ¶³Ì»á»°¡£ÔÚ»ñȡԶ³Ì½Ó¼ûȨÏ޺󣬣¬¹¥»÷Õß²¿ÊðÔ̺¬Êý×ÖÊðÃûMSI×°Ö÷¨Ê½µÄ¶ñÒ⹤¾ß¼¯¡£ÕâЩMSIÎļþ¼Ù×°³ÉMicrosoft Teams×é¼þ¼°ºÏ·¨Windows¹¤¾ßCrossDeviceService£¬£¬Í¨¹ýDLL²àÔØ¼¼Êõ½«¶ñÒâ¿âhostfxr.dll×¢ÈëºÏ·¨¶þ½øÖÆÎļþ¡£¸Ã¿â¼ÓÔØºó½âÃÜÄÚ´æÖеÄshellcode£¬£¬ÀûÓÃCreateThreadº¯Êý´´½¨´óÁ¿Ïß³Ì×ÌÈŵ÷ÊÔÆ÷·ÖÎö£¬£¬Í¬Ê±Ö´ÐÐɳÏä¼ì²âÒÔ¶ã±ÜÐé¹¹»·¾³¡£¶ñÒâÈí¼þͨ¹ýSHA-256ÅÉÉúÃÜÔ¿½âÃܳöA0Backdoor£¬£¬¸ÃºóÃÅѡȡAES¼ÓÃܱ£»£»¤Ö÷Ìâ´úÂ룬£¬²¢Ç¨áãÖÁÐÂÄÚ´æÇøÓòÖ´ÐС£Æäͨ¹ýDeviceIoControl¡¢¡¢GetUserNameExWµÈWindows APIÍøÂçÖ÷»úÐÅÏ¢£¬£¬ÊµÏÖÖ÷»úÖ¸ÎÆ¼ø±ð¡£ÓëºÅÁî½ÚÀñ·þÎñÆ÷£¨C2£©µÄͨѶ°µ²ØÔÚDNSÁ÷Á¿ÖС£


https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/


4. ¶íºÚ¿ÍÀûÓÃSignal/WhatsApp´¹µö¹¥»÷µ±¾Ö¾ü·½¼ÇÕß


3ÔÂ9ÈÕ£¬£¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Õýͨ¹ýÕë¶ÔSignalºÍWhatsAppµÄÍøÂç´¹µö»î¶¯£¬£¬¶Ôµ±¾Ö¹ÙÔ±¡¢¡¢¾ü·½ÈËÔ±¼°¼ÇÕßÌáÒ鶨Ïò¹¥»÷£¬£¬Ö¼ÔÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£º£º £ºÉÀ¼¹ú·Àµý±¨Ó밲ȫ¾Ö£¨MIVD£©Óë×ܵý±¨Ó밲ȫ¾Ö£¨AIVD£©½áºÏ»ã±¨Ö¤Êµ£¬£¬ºÉÀ¼µ±¾Ö¹ÍÔ±ÒѳÉΪϮ»÷Ö¸±ê£¬£¬¹¥»÷Ñ¡È¡ÍøÂç´¹µöÓëÉç»á¹¤³Ì¼¼Êõ£¬£¬ÀÄÓúϷ¨Éí·ÝÑéÖ¤Ö°ÄÜÊÕÊÜÕË»§²¢¼à¿ØÐÂÎÅ¡£Signal¹Ù·½°ä²¼ÖÒ¸æÖ¸³ö£¬£¬¹¥»÷ͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µö»î¶¯ÓÕÆ­Óû§Ð¹Â¶¶ÌÐÅÑéÖ¤Âë»òPINÂ룬£¬µ¼ÖÂÕË»§±»µÁ¡£Ö»¹ÜSignalµÄ¼ÓÃÜϵͳδ±»·ÛË飬£¬µ«¹¥»÷Õß¿ÉÀûÓÃÑéÖ¤ÂëÔÚ×ÔÉíÉ豸ע²áÕË»§£¬£¬ÆëÈ«½ÚÖÆÓû§Õ˺Å£¬£¬ÉõÖÁ½«¹ØÁªµç»°ºÅÂë¸ü¸ÄΪ¼º·½½ÚÖÆ£¬£¬´Ó¶ø½Ó¼ûÁªÏµÈËÁбí¡¢¡¢ÈºÁÄÐÂÎÅ£¬£¬²¢¼ÙÒâÊܺ¦Õß·¢ËÍÐÂÎÅ¡£Ò»ÖÖµäÐÍÊÖ·¨ÊǼÙÒâ¡°Signal°²È«Ö§³Ö̸Ìì»úеÈË¡±£¬£¬»Ñ³Æ¼ì²âµ½ÕË»§¿ÉÒɻ£¬£¬ÓÕµ¼Óû§Ê䶯ÊÖ»úÑéÖ¤ÂëʵÏÖ¡°ÑéÖ¤·¨Ê½¡±£»£»ÁíÒ»ÖÖÔòÊÇ·¢ËͶñÒâ¶þάÂë»òÁ´½Ó£¬£¬¼Ù×°³ÉȺ×éÔ¼Çë»òÉ豸ÏνÓÒªÇ󣬣¬Êܺ¦ÕßɨÃè»òµã»÷ºó£¬£¬¹¥»÷ÕßÉ豸½«ÓëÕË»§¹ØÁª£¬£¬ÊµÊ±½Ó¼û²¢Í¬²½ÐÂÎÅ¡£


https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/


5. °®Á¢ÐÅÃÀ¹ú×Ó¹«Ë¾³¬4000ÃûµÂÖÝÓû§ÐÅÏ¢±»ÇÔ


3ÔÂ9ÈÕ£¬£¬ÈðµäͨѶ¾ÞÍ·°®Á¢ÐŵÄÃÀ¹ú×Ó¹«Ë¾½üÈÕÅûÂ¶Ò»Â·ÖØ´óÊý¾Ýй¶ÊÂÎñ¡£¾ÝÆäÏò¼ÓÖݼ°µÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤Ìá½»µÄÎļþÏÔʾ£¬£¬2025Äê4ÔÂ28ÈÕ£¬£¬Ò»¼ÒΪ°®Á¢ÐÅ´æ´¢Ô±¹¤ºÍ¿Í»§Êý¾ÝµÄµÚÈý·½·þÎñÌṩÉ̼ì²âµ½Òì³£½Ó¼û£¬£¬ËæºóÆô¶¯µ÷²é²¢Í¨ÖªÁª°îµ÷²é¾Ö£¨FBI£©¡£µ÷²éÈ·ÈÏ£¬£¬2025Äê4ÔÂ17ÈÕÖÁ22ÈÕÆÚ¼ä£¬£¬¹¥»÷Õßδ¾­ÊÚȨ½Ó¼û»ò»ñÈ¡Á˲¿ÃÅÎļþ£¬£¬Éæ¼°ÐÕÃû¡¢¡¢µØÖ·¡¢¡¢Éç»á±£ÏÕºÅÂë¡¢¡¢¼ÝÕպ𢡢»¤Õյȵ±¾ÖID¡¢¡¢ÒøÐÐÕ˺Å¡¢¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢¡¢Ò½ÁƼͼ¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢¡£Õâ´ÎÊÂÎñÔڵ¿ËÈøË¹ÖÝÒÑÈ·ÈÏÓ°Ïì4,377ÈË£¬£¬µ«È«ÇòÊÜÓ°Ïì×ÜÈËÊýÉÐδ¹«¿ª¡£°®Á¢ÐÅÇ¿µ÷£¬£¬Ö»¹ÜÊý¾Ý±»ÇÔÈ¡£¬£¬Ä¿Ç°ÉÐδ·¢ÏÖÐÅÏ¢±»ÀÄÓõÄÖ¤¾Ý¡£Îª±£»£»¤ÊÜÓ°ÏìÓû§£¬£¬¸Ã¹«Ë¾ÌṩΪÆÚÒ»ÄêµÄÃâ·ÑIDXÉí·Ý±£»£»¤·þÎñ£¬£¬Ô̺¬ÐÅÓþ¼à¿Ø¡¢¡¢°µÍø¼à¿Ø¡¢¡¢Éí·Ý͵ÇÔ¸´Ô­Ö§³Ö¼°×î¸ß100ÍòÃÀÔªµÄڲƭËðʧÅâ³¥£¬£¬Óû§ÐèÔÚ2026Äê6ÔÂ9ÈÕǰע²á¡£½ØÖÁĿǰ£¬£¬ÎÞÈκÎÍøÂç·¸×ï×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/


6. FBI¾¯Ê¾¹ÙÔ±¼ÙÒâ´¹µö¹¥»÷£¬£¬µØÆ¤Ðí¿ÉÉêÇëÕß³ÉÖ¸±ê


3ÔÂ9ÈÕ£¬£¬ÃÀ¹úÁª°îµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼¹«¹²·þÎñ²¼¸æ£¬£¬¸æ·¢·¸×ï·Ö×ÓÕýͨ¹ý¼ÙÒâÊÐÏØ¹æ»®ºÍ·ÖÇøÎ¯Ô±»á¹ÙÔ±Ö´ÐÐÍøÂç´¹µö¹¥»÷£¬£¬Ö¸±êËø¶¨ÉêÇëµØÆ¤Ê¹ÓÃÐí¿ÉÖ¤µÄÆóÒµ¼°Ð¡ÎÒ¡£¹¥»÷ÕßÀûÓù«¿ªÇþµÀ»ñÈ¡µÄÊܺ¦ÕßÐí¿ÉÖ¤ÐÅÏ¢¡¢¡¢·ÖÇøÉêÇë±àºÅ»ò·¿²úµØÖ·µÈϸ½Ú£¬£¬Î±ÔìºÏ·¨ÓʼþÓÕµ¼Êܺ¦ÕßÖ§¸¶¡°Ðí¿ÉÖ¤ÓйØÓöȡ±£¬£¬²¢ÒªÇóͨ¹ýµç»ã¡¢¡¢µã¶ÔµãÖ§¸¶»ò¼ÓÃÜÇ®±ÒʵÏÖÂòÂô£¬£¬ÒÔ´ËÖ´ÐÐڲƭ¡£FBIÖ¸³ö£¬£¬´ËÀàȦÌ×´æÔÚ¶àÖØ¿É¼ø±ðÌØµã£º£º £ºÓʼþͨ³£À´×Էǵ±¾ÖÓòÃû£¬£¬¸½¼þÒªÇóÊÕ¼þÈËͨ¹ýÓʼþË÷È¡¸ü¶àϸ½Ú£¬£¬ÇÒ³£°éËæ¡°¼Ó¿ì¸¶¿îÒÔÔ¤·ÀÐí¿ÉÖ¤ÑÓÎ󡱵ȶ½´ÙÕ½Êõ¡£Ú¿Æ­·Ö×Ó»¹»á¿ÌÒâÑ¡ÔñÓë¹Ù·½°ä²¼·ÖÇøÐí¿ÉÏêÇé֪ͨµÄ¹¦·òͬ²½·¢ËÍ´¹µöÐÅÏ¢£¬£¬¼ÓÇ¿ºýŪÐÔ¡£Îª·À±¸´ËÀ๥»÷£¬£¬·¨ÂÉ»ú¹¹½¨ÒéÆóÒµºÍСÎÒÑϸñºË²é¡°¹Ù·½¡±ÐÅÏ¢µÄºÏ·¨ÐÔ£¬£¬Í¨¹ýÑéÖ¤ÓòÃû¡¢¡¢µç×ÓÓʼþµØÖ·£¬£¬²¢Ö±½ÓÖµçÊÐÏØµ±¾ÖÈ·ÈÏδ½ÉÓöÈ¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-phishing-attacks-impersonating-us-city-county-officials/