FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
°ä²¼¹¦·ò 2026-01-221. FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦
1ÔÂ21ÈÕ£¬½üÆÚ£¬Fortinet¿Í»§Ôâ·êÑϳÁ°²È«ÊÂÎñ£º¹¥»÷ÕßÀûÓÃÒѽ¨¸´µÄFortiGateÉí·ÝÑéÖ¤·ì϶CVE-2025-59718µÄ²¹¶¡Èƹý·ì϶£¬³É¹¦ÈëÇÖÒÑ´ò²¹¶¡µÄ·À»ðǽÉ豸¡£¸Ã·ìÏ¶Éæ¼°FortiCloudµ¥µãµÇ¼(SSO)Ö°ÄÜ£¬Ö»¹ÜFortinetÔÚ³õʼ²¼¸æÖÐÇ¿µ÷£¬Î´×¢²áFortiCareµÄÉ豸ĬÈÏδÆôÓøÃÖ°ÄÜ£¬¿ÉÏ÷¼õÊÜÓ°ÏìÁìÓò£¬µ«Shadowserver»ù½ð»á12ÔÂÖÐÑ®µÄɨÃèÏÔʾ£¬ÈÔÓг¬¹ý25,000̨ÆôÓÃFortiCloud SSOµÄFortinetÉ豸¶³öÔÚ»¥ÁªÍøÉÏ¡£Ö»¹ÜĿǰ³¬°ëÊýÉ豸ÒÑÊܱ£»¤£¬ÈÔÓг¬¹ý11,000̨É豸¿É±»¹«¿ª½Ó¼û£¬×é³É³Á´ó·çÏÕ¡£ÎªÓ¦¶ÔÍþв£¬Fortinet½¨ÒéÖÎÀíÔ±ÔÚÌṩÆëÈ«½¨¸´µÄFortiOS°æ±¾Ç°£¬ÁÙʱ½ûÓÃFortiCloudµÇ¼ְÄÜ¡£¾ßÌå²Ù×÷¿Éͨ¹ýWeb½çÃæ½øÈë"ϵͳ"¡ú"ÉèÖÃ"£¬¹Ø¹Ø"ÔÊÐíʹÓÃFortiCloud SSO½øÐÐÖÎÀíÔ±µÇ¼"Ñ¡Ï»òͨ¹ýºÅÁîÐÐÖ´ÐÐ"config system global; set admin-forticloud-sso-login disable; end"ʵÏÖ¡£ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö(CISA)Òѽ«¸Ã·ì϶ÁÐÈë"ÔÚ±»ÀûÓõķì϶"Çåµ¥£¬ÒªÇóÁª¹ú»ú¹¹ÔÚÒ»ÖÜÄÚʵÏÖ½¨²¹¡£
https://www.bleepingcomputer.com/news/security/fortinet-admins-report-patched-fortigate-firewalls-getting-hacked/
2. ÒÁÀʵçÊǪ́ÔâºÚ¿Í¹¥»÷²¥·ÅÍõ´¢½²»°
1ÔÂ21ÈÕ£¬ÒÁÀʶà¼ÒµçÊǪ́½ÚÄ¿1ÔÂ18ÈÕÍí¼äÔâºÚ¿ÍÖжϣ¬¹¥»÷Õßͨ¹ý°ÍµÂ¶ûÎÀÐÇ´«ÊäϵͳÊÕÊÜÐźţ¬²¥·Å½ÖÍ·¿¹Òé»Ãæ¼°ÍöÃüÍõ´¢ÀñÈø¡¤°ÍÁÐάµÄ¼«¶ÈÖÓÔ¤ÏȼÔì½²»°¡£°ÍÁÐάÔÚÊÓÆµÖкôÓõÒÁÀʹúÃñ¾üÓëÃñ¶àÁª½á£¬Ôð¹Ö°²È«¶ÓÁÓװЧÖÒÒÁ˹À¼¹²ºÍ¹ú¶ø·ÇÒÁÀÊ¡±£¬²¢Ðû³Æ²¿ÃÅÊ¿±øÒѵ¹¸ê£¬µ«Î´Ìṩ֤¾Ý¡£Õâ´Î¹¥»÷Ó°ÏìÁËÒÁÀÊÒÁ˹À¼¹²ºÍ¹ú¹ã²¥µçÊǪ́£¨IRIB£©¸²¸Ç´åÂ䵨ÓòµÄÎÀÐÇÐźţ¬ÓйØÊÓÆµÆ¬¶ÎѸ¿ì±»°ÍÁÐάÍŶӡ¢ÒÁÀʹú¼ÊµçÊǪ́¼°±¾µØÃ½Ìåת·¢´«²¼¡£ÊÂÎñ²úÉúÔÚÒÁÀÊÉîÏݾ¼ÃΣ»úÖ®¼Ê¡£×Ô2025Äê12ÔÂµ×Æð£¬ÒÁÀÊÇ®±ÒÀïÑǶû´ó·ù±áÖµ£¬Ê³Æ·¼Ûֵʧ¿ØìÉý£¬Ãñ¶à½«¾¼ÃÀ§¾³¹é×ïÓÚµ±¾ÖµòÂ䡣Ϊ×èÖ¹±©Á¦ÐÂÎÅ´«²¼£¬ÒÁÀʵ±¾Ö¹Ø¹Ø»¥ÁªÍøºÍÒÆ¶¯·þÎñ³¤´ïÁ½ÖÜ¡£È»¶ø£¬²¿ÃžÓÃñͨ¹ýÐÇÁ´ÎÀÐÇÌ×¼þ½«ºÚ¿ÍÇÔÈ¡µÄÊÓÆµ´«²¼ÖÁÈ«Çò¡£ÓëÒÁÀʸïÃüÎÀ¶Ó¹ØÁªµÄ·¨¶û˹ͨѶÉçÔ®Òý¹ú¶È¹ã²¥¹«Ë¾Ëµ·¨£¬³Æ²¿ÃŵØÓòÐźš°Òò²»Ã÷ÔÒò¶ÌÔÝÖжϡ±£¬µ«Î´Ìá¼°¿¹ÒéÊÓÆµ»òÍõ´¢½²»°ÄÚÈÝ¡£
https://hackread.com/iranian-tv-transmission-hacked-exiled-prince-message/
3. Cisco´¹Î£½¨¸´¸ßΣÁãÈÕ·ì϶CVE-2026-20045
1ÔÂ21ÈÕ£¬Ë¼¿Æ¹«Ë¾½üÈÕ½¨¸´ÁËÒ»¸öÑϳÁµÄ¸ßΣÁãÈÕÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2026-20045£¨CVSSÆÀ·Ö8.2£©£¬¸Ã·ì϶Òѱ»·¢ÏÖ±»»ý¼«ÀûÓÃÓÚ¹¥»÷¡£´Ë·ì϶ԴÓÚHTTPÒªÇóÖÐÓû§ÊäÈëÐÅÏ¢ÑéÖ¤²»µ±£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸µÄWebÖÎÀí½çÃæ·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇó£¬ÔÚÉ豸µ×²ã²Ù×÷ϵͳִÐÐËÁÒâºÅÁ×îÖÕ¿ÉÄÜ»ñÈ¡rootȨÏÞ¡£ÊÜÓ°Ïì²úÆ·Ô̺¬Cisco Unified CM¡¢Unified CM SME¡¢IM & Presence¡¢Unity Connection¼°Webex Calling Dedicated Instance¡£¾ßÌ彨¸´°æ±¾ÈçÏ£ºUnified CMµÈϵÁÐ12.5°æ±¾ÐèǨáãÖÁ¹Ì¶¨°æ±¾£»14°æ±¾ÐèÉý¼¶ÖÁ14SU5»òÀûÓò¹¶¡Îļþ£»15°æ±¾ÐèÉý¼¶ÖÁ2026Äê3Ô°䲼µÄ15SU4»òÀûÓöÔÓ¦²¹¶¡¡£Unity ConnectionͬÑùÐèÆ¾¾Ý°æ±¾Éý¼¶ÖÁ14SU5»ò15SU4²¢ÀûÓò¹¶¡¡£Ë¼¿ÆÇ¿µ÷²¹¶¡Óë°æ±¾Ñϸñ¶ÔÓ¦£¬Óû§Ðè²Î¿¼²¹¶¡READMEÎļþ²Ù×÷¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´Î½¨¸´ÎÞһʱ½â¾ö¹æ»®£¬Ë¼¿Æ°²È«Ó¦¼±ÏìÓ¦Ó××飨PSIRT£©ÒÑÈ·ÈÏ´æÔÚÀûÓó¢ÊÔ£¬Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶ÖÁ½¨¸´°æ±¾¡£
https://securityaffairs.com/187177/security/cisco-fixed-actively-exploited-unified-communications-zero-day.html
4. Zendesk¹¤µ¥ÏµÍ³ÔâÈ«Çò´ó¹æÄ£À¬»øÓʼþ¹¥»÷
1ÔÂ21ÈÕ£¬È«ÇòÓû§Ôâ·êÓÉZendeskÖ§³ÖϵͳÒý·¢µÄ´ó¹æÄ£À¬»øÓʼþ¹¥»÷£¬Êܺ¦ÕßÊÕµ½Êý°Ù·âÖ÷Ìâ¹îÒìÇÒÄÚÈÝ»ìÂÒµÄÓʼþ£¬Òý·¢¿í·º²ÂÒÉÓë·¢¼±¡£Õâ´Î¹¥»÷Ô´ÓÚZendeskÔÊÐíδ¾ÑéÖ¤Óû§Ìá½»Ö§³Ö¹¤µ¥µÄ·ì϶£¬¹¥»÷Õßͨ¹ý±éÀúº£Á¿ÓʼþµØÖ·ÁÐ±í´´½¨Ðéα¹¤µ¥£¬´¥·¢ÏµÍ³×Ô¶¯·¢ËÍÈ·ÈÏÓʼþ£¬½«ºÏ·¨ÆóÒµµÄZendeskƽ̨±äΪÀ¬»øÓʼþÖмÌÕ¾¡£ÊÜÓ°ÏìÆóÒµº¸Ç¿Æ¼¼¡¢ÓÎÏ·¡¢ÕþÎñµÈ¶àÁìÓò£¬Ô̺¬Discord¡¢Tinder¡¢Riot Games¡¢Dropbox¡¢CD Projekt¡¢ÌïÄÉÎ÷ÖÝÀ͹¤²¿µÈ³¬20¼Ò»ú¹¹¡£ÓʼþÖ÷Ìâ³öÏָ߶ȹƻóÐÔÌØµã£º²¿ÃżÙ×°·¨ÂÉ֪ͨ¡¢²¿ÃųÐŵÃâ·Ñ¸£Àû¡¢¸üÓдóÁ¿Ê¹ÓÃUnicode×°è«×ÖÌå±àдµÄÂÒÂëÄÚÈÝ¡£ÓÉÓÚÓʼþÔ´×ÔÕý¹æÆóҵϵͳ£¬Æä¿ÉÐŶÈÔ¶³¬Í¨³£À¬»øÓʼþ£¬³É¹¦ÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷£¬Ðγɸü´óÇÖÈÅÐÔ¡£ÉæÊÂÆóҵѸ¿ì»ØÓ¦£ºDropbox¡¢2KµÈÃ÷È·°µÊ¾ÓʼþΪϵͳÀÄÓòúÆ·£¬Ç¿µ÷Æä"ŷʤµ¥Ìá½»"Õþ²ßËä·½±ãµ«´æÔÚ·çÏÕ£¬³Ðŵδ¾ÕË»§³ÖÓÐÈËÑéÖ¤²»»á´¦ÖÃÃô¸ÐÒªÇ󣬽¨ÒéÓû§Ö±½ÓºöÂÔÒì³£Óʼþ¡£Zendesk¹Ù·½Åû¶£¬¹«Ë¾ÒÑ´¹Î£²¿ÊðÐÂÐͰ²È«Ö°ÄÜ£¬Í¨¹ý¼ÓÇ¿¼à¿ØËã·¨ÓëÖ´ÐлÏÞ¶È£¬ÌáÉý¶ÔÒì³£¹¤µ¥µÄ¼ì²âÓëÀ¹½ØÐ§ÄÜ¡£
https://www.bleepingcomputer.com/news/security/zendesk-ticket-systems-hijacked-in-massive-global-spam-wave/
5. ÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾ÂíÀûÓÃTensorFlow¼¼Êõ´«²¼
1ÔÂ21ÈÕ£¬½üÆÚ£¬Ò»ÖÖÐÂÐͰ²×¿µã»÷Ú²ÆÄ¾Âíͨ¹ýÓ×Ã×¹Ù·½ÀûÓÃÉ̵êGetApps´«²¼£¬ÀûÓÃTensorFlow»úе½ø½¨Ä£ÐÍ×Ô¶¯¼ì²â²¢½»»¥¸æ°×ÔªËØ£¬Òý·¢°²È«¹Ø×¢¡£¸ÃľÂíѡȡÁ½ÖÖÔËÐÐģʽ£º"»ÃÓ°"ģʽͨ¹ý°µ²ØµÄWebViewä¯ÀÀÆ÷¼ÓÔØÖ¸±êÒ³Ãæ£¬½ØÈ¡ÆÁÄ»½ØÍ¼ºóÓÉTensorFlow.js·ÖÎö¸æ°×ÔªËØ£¬·ÂÕÕÓû§µã»÷£»"ÐźŴ«µÝ"ģʽÔòͨ¹ýWebRTC´«ÊäʵʱÊÓÆµÁ÷ÖÁ¹¥»÷Õߣ¬Ö§³ÖÔ¶³Ì²Ù×÷µã»÷¡¢¹ö¶¯µÈÐÐΪ¡£ÕâÖÖ»ùÓÚÊÓ¾õ·ÖÎöµÄ»úÔìÍ»ÆÆÁË´«Í³¾ç±¾DOM½»»¥µÄÏÞ¶È£¬Äܸü¸ßЧӦ¶Ô¶¯Ì¬¸æ°×µÄƵÈԽṹ±ä¶¯¡£Ä¾Âí´«²¼õè¾¶Òñ±Î£º¹¥»÷ÕßÊ×ÏȽ«Õý³£ÓÎÏ·ÀûÓÃÌá½»ÖÁGetApps£¬ºóÐøÍ¨¹ý¸üÐÂÔö³¤¶ñÒâ×é¼þ¡£Dr.Web×êÑÐÏÔʾ£¬ÊÜϰȾÓÎÏ·Ô̺¬¡¶ÏÀµÁÁÔ³µÊÖ£ººÚÊÖµ³¡·£¨6.1Íò´ÎÏÂÔØ£©¡¢¡¶¿É°®³èÎïÎÝ¡·£¨3.4Íò´ÎÏÂÔØ£©µÈ£¬¸²¸Ç¶à¸öÈȵãÓÎÏ·¡£´Ë±í£¬Ä¾Âí»¹Í¨¹ýµÚÈý·½APKÍøÕ¾£¨ÈçApkmody¡¢Moddroid£©¡¢TelegramƵ·¼°Õ¼ÓÐ2.4Íò¶©ÔÄÕßµÄDiscord·þÎñÆ÷À©É¢£¬Éæ¼°Spotify Pro¡¢Netflix modµÈÅú¸Ä°æÀûÓá£
https://www.bleepingcomputer.com/news/security/new-android-malware-uses-ai-to-click-on-hidden-browser-ads/
6. Î÷°àÑÀPcComponentes·ñ¶¨1600Íò¿Í»§Êý¾Ýй¶
1ÔÂ21ÈÕ£¬Î÷°àÑÀ¿Æ¼¼ÁãÊÛÉÌPcComponentes½üÈÕ·ñ¶¨ÆäϵͳÔâ·ê´ó¹æÄ£Êý¾Ýй¶ӰÏì1600Íò¿Í»§µÄ˵·¨£¬µ«Ö¤ÊµÔâ·êײ¿â¹¥»÷¡£´Ëǰ£¬ºÚ¿Í×éÖ¯"daghetiaw"Ðû³ÆÇÔÈ¡¸Ã¹«Ë¾1630ÍòÌõ¿Í»§¼Í¼£¬²¢Ð¹Â¶50ÍòÌõÑù±¾£¬Ôü×Ҽͼ´ý¼Û¶ø¹Á¡£Ð¹Â¶Êý¾ÝÔ̺¬¶©µ¥ÏêÇé¡¢ÏÖʵµØÖ·¡¢È«Ãû¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢²úÆ·ÓûÍûÇåµ¥¼°ZendeskÖ§³Ö¶Ô»°¼Í¼¡£PcComponentesÔÚµ÷²éºóÉêÃ÷£¬ÆäÊý¾Ý¿âºÍÄÚ²¿ÏµÍ³Î´·¢ÏÖ·¸·¨½Ó¼ûÖ¤¾Ý£¬Ç¿µ÷"1600ÍòÊÜÓ°Ïì¿Í»§"Êý×Ö²»Êµ£¬Òò»îÔ¾ÕË»§ÊýÁ¿Ô¶µÍÓÚ´Ë£¬ÇÒϵͳÖдÓδ´æ´¢²ÆÕþÐÅÏ¢»ò¿Í»§ÃÜÂ롣Ȼ¶ø£¬¹«Ë¾ÈϿɼì²âµ½×²¿â¹¥»÷ºÛ¼££¬¹¥»÷ÕßÀûÓÃÆäËûƽ̨й¶µÄÓÊÏäÃÜÂë×éºÏ£¬Í¨¹ý×Ô¶¯»¯¹¤¾ß³¢ÊԵǼPcComponentesÕË»§¡£Íþвµý±¨¹«Ë¾Hudson Rock·ÖÎö·¢ÏÖ£¬¹¥»÷Õß¿ÉÄÜͨ¹ýϰȾÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÍÆËã»úÍøÂçµÇ¼ƾ֤£¬²¿ÃżÍ¼¿É×·ÒäÖÁ2020Äê¡£ÆäÑéÖ¤µÄÁù¸öÓÊÏä¾ùÔÚÒÑÖªÇÔÃÜÈÕÖ¾ÖдæÔÚ£¬Ö¤Êµ¹¥»÷Ó뺹Çàй¶Êý¾Ý´æÔÚ¹ØÁª¡£
https://www.bleepingcomputer.com/news/security/online-retailer-pccomponentes-says-data-breach-claims-are-fake/


¾©¹«Íø°²±¸11010802024551ºÅ