BianLianÀÕË÷Èí¼þʹÓÃSVG´¹ÂÚ¹¥»÷ίÄÚÈðÀÆóÒµ
Ðû²¼Ê±¼ä 2026-03-311. BianLianÀÕË÷Èí¼þʹÓÃSVG´¹ÂÚ¹¥»÷ίÄÚÈðÀÆóÒµ
3ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬WatchGuardÑо¿Ö°Ô±¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬BianLianÀÕË÷Èí¼þ×éÖ¯ÕýÕë¶ÔίÄÚÈðÀÆóÒµÌᳫÐÂÐÍÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâSVGͼÏñÎļþºÍÇÉÃîÖØ¶¨ÏòÊÖÒÕÈÆ¹ý¹Å°åÇå¾²·À»¤£¬£¬£¬£¬£¬£¬ÊµÑé¸ßËÙAES¼ÓÃÜÀÕË÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷¸ß¶È¼¯ÖÐÔÚίÄÚÈðÀ£¬£¬£¬£¬£¬£¬¹¥»÷Á´Ê¼ÓÚαװ³É·¢Æ±»òÔ¤ËãµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬¸½¼þΪʹÓÃÎ÷°àÑÀÓïÃüÃûµÄSVGÎļþ£¬£¬£¬£¬£¬£¬¿´ËÆÍ¨Ë×ͼƬʵÔòǶÈëXML´úÂë¡£¡£¡£¡£¡£¡£¡£Óû§·¿ªÎļþºó£¬£¬£¬£¬£¬£¬»áÉñÃØÅþÁ¬ÍⲿURL£¬£¬£¬£¬£¬£¬ÏÂÔØÓÉGoÓïÑÔ±àдµÄÒþ²ØWindows³ÌÐò×÷ΪÓÐÓÃÔØºÉ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß½ÓÄÉ16λÁîÅÆÏµÍ³×ª´ï¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬¸Ã³ÌÐò¾ß±¸·´¼à¿ØÄÜÁ¦£¬£¬£¬£¬£¬£¬»á¼ì²âWine¹¤¾ßÒÔÅжÏÊÇ·ñ´¦ÓÚÇå¾²ÆÊÎöÇéÐΣ¬£¬£¬£¬£¬£¬²¢ÔÚϵͳ¡°¹ÒÆð¡±Ê±Ò»Á¬¼àÊÓ£¬£¬£¬£¬£¬£¬Ê¹Ó÷ÀÓùåÐÒ£Ö´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£Æä½¹µãÎäÆ÷ÊǸßËÙAES¼ÓÃÜÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬¿É¿ìËÙËø¶¨ÎļþʵÑéÀÕË÷¡£¡£¡£¡£¡£¡£¡£ÊÖÒÕϸ½ÚÏÔʾ£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ͨ¹ýËõ¶ÌÁ´½ÓЧÀÍja.cat¾ÙÐÐÁ÷Á¿Öض¨Ïò£¬£¬£¬£¬£¬£¬×îÖÕÖ¸Ïò±»ÈëÇֵİÍÎ÷ÓòÃû£¬£¬£¬£¬£¬£¬Ðγɶà²ãÌø°å¹æ±Ü×·×Ù¡£¡£¡£¡£¡£¡£¡£WatchGuardÑо¿Ö¸³ö£¬£¬£¬£¬£¬£¬ÕâЩսÂÔÓëBianLian×éÖ¯×Ô2022ÄêÒÔÀ´µÄ×÷°¸ÊÖ·¨¸ß¶ÈÎǺϡ£¡£¡£¡£¡£¡£¡£
https://hackread.com/bianlian-ransomware-fake-invoice-svg-images-attacks/
2. Î÷°àÑÀά¸ê¸ÛÔâÀÕË÷Èí¼þ¹¥»÷
3ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬Î÷°àÑÀά¸ê¸Û¿ËÈÕÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÊý×ÖϵͳÑÏÖØÊÜË𡣡£¡£¡£¡£¡£¡£¹¥»÷ÓÚÖܶþÇåÔç±»·¢Ã÷£¬£¬£¬£¬£¬£¬Ó°Ïì¼ÓÀûÎ÷ÑǵØÇø¿Ú°¶ÓÃÓÚ»õÎïÔËÊäÖÎÀí¼°ÆäËûÊý×ÖЧÀ͵ÄÅÌËã»úЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£²¿·Ö×°±¸±»Ëø¶¨£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇóÖ§¸¶Êê½ðÒÔ»Ö¸´ÏµÍ³»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£Îª×èÖ¹¹¥»÷À©É¢£¬£¬£¬£¬£¬£¬¸ÛÎñ¾ÖÊÖÒÕÍŶÓѸËÙ½«ÊÜÓ°ÏìϵͳÓëÍâ²¿ÍøÂç¸ôÀ룬£¬£¬£¬£¬£¬²¢ÆôÏÂÊÖÐж¯ÒµÄ£Ê½¡£¡£¡£¡£¡£¡£¡£¿Ú°¶×ܲÿ¨Âå˹¡¤²©ËþÄÉÇ¿µ÷£¬£¬£¬£¬£¬£¬ÔÚÇå¾²ÍŶÓÈ·ÈÏϵͳ¾ø¶ÔÇ徲ǰ£¬£¬£¬£¬£¬£¬²»»áÖØÐÂÅþÁ¬ÈκÎÊý×Öϵͳ£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐÎÞ»Ö¸´Êý×ÖÔËÓªµÄʱ¼ä±í¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü´¬²°º½ÐкͻõÎïװжµÈʵÌåÔËÓªÈÔÔÚ¼ÌÐø£¬£¬£¬£¬£¬£¬µ«ÒÀÀµÊý×ÖÆ½Ì¨µÄÎïÁ÷е÷ÊÂÇéÊܵ½ÏÔÖøÓ°Ï죬£¬£¬£¬£¬£¬²¿·Ö²Ù×÷Ö°Ô±ÒÑתΪÈ˹¤²Ù×÷²¢ÒÀÀµÖ½ÖÊÎļþÍê³ÉÊÂÇé¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨¹¥»÷ÕßÔõÑùÈëÇÖÍøÂçÒÔ¼°ÊÇ·ñ±£´æÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£²©ËþÄɽ«´Ë´ÎÊÂÎñ¶¨ÐÔΪ¾¼ÃÄîÍ·µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÉÐÎÞÈκÎÍøÂç·¸·¨×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/port-of-vigo-ransomware
3. FortiClient EMS¸ßΣSQL×¢ÈëÎó²îÔâ»îԾʹÓÃ
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ÍþвÇ鱨¹«Ë¾Defused¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÕýÆð¾¢Ê¹ÓÃFortinet FortiClient EMSƽ̨µÄCVE-2026-21643ÑÏÖØSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÍþвÐÐΪÕßͨ¹ý½á¹¹¶ñÒâHTTPÇëÇ󣬣¬£¬£¬£¬£¬ÔÚδÐÞ²¹µÄFortiClient EMS 7.4.4°æ±¾Web½çÃæÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ¡£¡£¡£¡£¡£¡£¡£DefusedÇ¿µ÷£¬£¬£¬£¬£¬£¬Ö»¹ÜCISA¼°ÆäËûÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼ÈÔ±ê¼Ç¸ÃÎó²îΪ¡°Î´±»Ê¹Óá±£¬£¬£¬£¬£¬£¬µ«ÆäÄÚ²¿Êý¾ÝÒÑ֤ʵËÄÌìǰ·ºÊ×ÏÈ´ÎʹÓð¸Àý¡£¡£¡£¡£¡£¡£¡£Îó²îÓÉFortinetÇå¾²ÍŶÓÄÚ²¿·¢Ã÷£¬£¬£¬£¬£¬£¬Ó°Ïì7.4.4°æ±¾£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÉý¼¶ÖÁ7.4.5»ò¸ü¸ß°æ±¾ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬FortinetÉÐδ¸üÐÂÇ徲ͨ¸æ»òÈ·ÈÏÎó²îÒѱ»ÏÖʵʹÓᣡ£¡£¡£¡£¡£¡£¾ÝShodanɨÃ裬£¬£¬£¬£¬£¬½ü1000¸öFortiClient EMSʵÀýÒѹûÕæÌ»Â¶£»£»£»£»£»£»£»Shadowserver×·×Ùµ½³¬2000¸ö̻¶ʵÀý£¬£¬£¬£¬£¬£¬ÆäÖÐ1400¸öIPµØµãλÓÚÃÀ¹úºÍÅ·ÖÞ£¬£¬£¬£¬£¬£¬´ó¶¼¼¯ÖÐÔÚÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/critical-fortinet-forticlient-ems-flaw-now-exploited-in-attacks/
4. ¶íTA446ʹÓÃDarkSwordÎó²î¶ÔiOS×°±¸Ìᳫ´¹ÂÚ¹¥»÷
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬Óë¶íÂÞ˹¹ØÁªµÄ¸ß¼¶Ò»Á¬Íþв×éÖ¯TA446£¨ÓÖÃûSEABORGIUM¡¢ColdRiverµÈ£©ÕýʹÓÃDarkSwordÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬£¬£¬Õë¶ÔiOS×°±¸Ìᳫ¶¨ÏòÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2017ÄêÆðÒ»Á¬»îÔ¾£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô±±Ô¼¹ú¼Ò¼°¶«Å·µØÇø£¨º¬ÎÚ¿ËÀ¼£©£¬£¬£¬£¬£¬£¬Ä¿µÄº¸Ç¹ú·À/Ç鱨¹«Ë¾¡¢·ÇÕþ¸®×éÖ¯¡¢Õþ¸®¼ä×éÖ¯¡¢Öǿ⡢¸ßУ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ç°Ç鱨¹ÙÔ±¡¢¶íÂÞ˹ÊÂÎñר¼ÒºÍÍâÑó¶í¹«Ãñ£¬£¬£¬£¬£¬£¬Í¨¹ýÇÔȡƾ֤ÓëÇ鱨ʵÏÖÈëÇÖºÍÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬TA446ͨ¹ýαÔì´óÎ÷ÑóÀíÊ»áÓʼþ·¢ËÍÁ´½Ó£¬£¬£¬£¬£¬£¬Á´½ÓÖ¸Ïò¿´ËÆÎÞº¦µÄPDFÓÕ¶üÎļþ£¬£¬£¬£¬£¬£¬Ê¹ÓÃЧÀÍÆ÷¶Ë¹ýÂË»úÖÆ½«Óû§Öض¨ÏòÖÁDarkSwordÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬£¬£¬ÊµÑ鶨ÏòͶ·ÅÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß°ü°üÀ¨Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¡¢PACÈÆ¹ýµÈ×é¼þ£¬£¬£¬£¬£¬£¬Ëäδ·¢Ã÷ɳÏäÌÓÒÝ£¬£¬£¬£¬£¬£¬µ«ÒÑ֤ʵͨ¹ý¼ÓÔØÆ÷MD5¹ØÁªTA446µÚ¶þ½×¶ÎÓòÃû£¬£¬£¬£¬£¬£¬ÏÔʾ×Åʵ¼ÊʹÓᣡ£¡£¡£¡£¡£¡£
https://securityaffairs.com/190139/apt/russia-linked-apt-ta446-uses-darksword-exploit-to-target-iphone-users-in-phishing-wave.html
5. Ò½ÁƿƼ¼¹«Ë¾CareCloud³ÆºÚ¿ÍÇÔÈ¡ÁË»¼ÕßÊý¾Ý
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬Ò½ÁÆÐÅÏ¢ÊÖÒÕ¹«Ë¾CareCloud¿ËÈÕÅû¶һÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Òý¿¯ÐÐÒµ¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ܲ¿Î»ÓÚÃÀ¹úÐÂÔóÎ÷ÖÝ£¬£¬£¬£¬£¬£¬×÷Ϊ¹ûÕæÉÏÊеÄÒ½ÁƱ£½¡ITЧÀÍÉÌ£¬£¬£¬£¬£¬£¬Ö÷ÒªÌṩSaaSÈí¼þ¡¢ÊÕÈëÖÜÆÚÖÎÀí¡¢µç×Ó¿µ½¡¼Í¼£¨EHR£©µÈ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£¾ÝCareCloudÏòÃÀ¹ú֤ȯÉúÒâίԱ»áÌá½»µÄÎļþÏÔʾ£¬£¬£¬£¬£¬£¬2026Äê3ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬ÆäÆìÏÂCareCloud Health²¿·ÖÔâÓöÍøÂçÖÐÖ¹£¬£¬£¬£¬£¬£¬µ¼ÖÂÁù¸öµç×Ó¿µ½¡¼Í¼ÇéÐÎÖ®Ò»µÄ¹¦Ð§ºÍÊý¾Ý»á¼ûÊÜ×裬£¬£¬£¬£¬£¬Ò»Á¬Ô¼8СʱºóÍêÈ«»Ö¸´¡£¡£¡£¡£¡£¡£¡£¾ÊÓ²ìÈ·ÈÏ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÈëÇÖʱ´ú»á¼ûÁ˸ù«Ë¾IT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢Ôì³É´æ´¢¿Í»§»¼Õß¿µ½¡¼Í¼µÄÌØ¶¨ÇéÐÎÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹«Ë¾Ç¿µ÷δ¾ÊÚȨµÄÊý¾Ý»á¼û¹æÄ£ÓÐÏÞ£¬£¬£¬£¬£¬£¬µ«ÏêϸÊÜÓ°ÏìÈËÊý¼°Êý¾ÝÀàÐÍÈÔ´ý½øÒ»³ÌÐò²éÈ·ÈÏ¡£¡£¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ºó£¬£¬£¬£¬£¬£¬CareCloudѸËÙÆô¶¯Ó¦¼±ÏìÓ¦»úÖÆ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷´Ë´ÎÊÂÎñ䲨¼°ÆäËûƽ̨¡¢²¿·Ö»òϵͳ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÎÞ·¨¼ÌÐø»á¼ûÆäÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ËùÓÐÊÜÓ°Ïìϵͳ¾ùÒÑÍêÈ«»Ö¸´¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/healthcare-tech-firm-carecloud-says-hackers-stole-patient-data/
6. RoadK1ll£ºWebSocket·´ÏòËíµÀʵÏÖÒþ²ØÉøÍ¸
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬Íйܼì²âºÍÏìÓ¦£¨MDR£©ÌṩÉÌBlackpointÔÚÊÂÎñÏìÓ¦Öз¢Ã÷ÁËÃûΪRoadK1llµÄÐÂÐÍNode.js¶ñÒâÖ²Èë³ÌÐò£¬£¬£¬£¬£¬£¬¸Ã³ÌÐòͨ¹ý×Ô½ç˵WebSocketÐÒéʵÏÖ¹¥»÷ÕßÓëÊÜѬȾÖ÷»úµÄÒ»Á¬Í¨Ñ¶£¬£¬£¬£¬£¬£¬¾ß±¸¸ß¶ÈÒþ²ØÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£¡£RoadK1ll±»½ç˵ΪÇáÁ¿¼¶·´ÏòËíµÀÖ²ÈëÎ£¬£¬£¬£¬£¬Æä½¹µã¹¦Ð§Êǽ«ÊÜËðÖ÷»úת»¯Îª¿É¿ØÖм̵㡣¡£¡£¡£¡£¡£¡£Í¨¹ý½¨Éèµ½¹¥»÷Õß¿ØÖÆ»ù´¡ÉèÊ©µÄ³öÕ¾WebSocketÅþÁ¬£¬£¬£¬£¬£¬£¬¸Ã³ÌÐò¿É°´Ðèת·¢TCPÁ÷Á¿£¬£¬£¬£¬£¬£¬Ê¹ÍþвÐÐΪÕßÎÞÐèÒÀÀµ¹Å°åÈëÕ¾¼àÌýÆ÷¼´¿É»á¼ûÄÚ²¿ÍøÂç×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÉè¼ÆÊ¹¹¥»÷ÕßÄÜÈÆ¹ý½çÏß¿ØÖÆ£¬£¬£¬£¬£¬£¬ÓÉÓÚÅþÁ¬Ô´×Ô±»ÈëÇÖ»úе£¬£¬£¬£¬£¬£¬¿É¼ÌÐøÆäÍøÂçÐÅÈκÍλÖ㬣¬£¬£¬£¬£¬ÓÐÓûá¼ûÔ±¾ÎÞ·¨´ÓÍⲿֱ½Ó»á¼ûµÄÄÚ²¿ÏµÍ³¡¢Ð§Àͼ°ÍøÂç¶Î¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶à²¢·¢ÅþÁ¬ÄÜÁ¦£¬£¬£¬£¬£¬£¬ÔÊÐíͬʱÓë¶à¸öÄ¿µÄͨѶ¡£¡£¡£¡£¡£¡£¡£ÆäÏÂÁ°üÀ¨ÅþÁ¬¡¢Êý¾Ýת·¢¡¢ÅþÁ¬È·ÈÏ¡¢ÅþÁ¬ÖÕÖ¹¼°¹ýʧ·´ÏìµÈ»ù´¡Ö¸Á£¬£¬£¬£¬£¬ÆäÖÐCONNECTÏÂÁî¿É´¥·¢ÏòÖ¸¶¨Ö÷»úºÍ¶Ë¿ÚµÄ³öÕ¾TCPÅþÁ¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¹¥»÷¹æÄ£µÄºáÏòÀ©Õ¹¡£¡£¡£¡£¡£¡£¡£ÈôͨѶÖÐÖ¹£¬£¬£¬£¬£¬£¬³ÌÐò»á×Ô¶¯Æô¶¯ÖØÁ¬»úÖÆ»Ö¸´ËíµÀ£¬£¬£¬£¬£¬£¬È·±£¹¥»÷Ò»Á¬ÐÔÇÒïÔÌÊÖ¶¯¸ÉÔ¤±¬·¢µÄÔëÒô¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-roadk1ll-websocket-implant-used-to-pivot-on-breached-networks/


¾©¹«Íø°²±¸11010802024551ºÅ