FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦

°ä²¼¹¦·ò 2026-01-22

1. FortiGate·ì϶²¹¶¡Èƹý¹¥»÷Òý·¢´¹Î£ÏìÓ¦


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬½üÆÚ £¬£¬£¬£¬£¬Fortinet¿Í»§Ôâ·êÑϳÁ°²È«ÊÂÎñ£º¹¥»÷ÕßÀûÓÃÒѽ¨¸´µÄFortiGateÉí·ÝÑéÖ¤·ì϶CVE-2025-59718µÄ²¹¶¡Èƹý·ì϶ £¬£¬£¬£¬£¬³É¹¦ÈëÇÖÒÑ´ò²¹¶¡µÄ·À»ðǽÉ豸¡£¡£ ¡£¡£¡£¡£¸Ã·ìÏ¶Éæ¼°FortiCloudµ¥µãµÇ¼(SSO)Ö°ÄÜ £¬£¬£¬£¬£¬Ö»¹ÜFortinetÔÚ³õʼ²¼¸æÖÐÇ¿µ÷ £¬£¬£¬£¬£¬Î´×¢²áFortiCareµÄÉ豸ĬÈÏδÆôÓøÃÖ°ÄÜ £¬£¬£¬£¬£¬¿ÉÏ÷¼õÊÜÓ°ÏìÁìÓò £¬£¬£¬£¬£¬µ«Shadowserver»ù½ð»á12ÔÂÖÐÑ®µÄɨÃèÏÔʾ £¬£¬£¬£¬£¬ÈÔÓг¬¹ý25,000̨ÆôÓÃFortiCloud SSOµÄFortinetÉ豸¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£ ¡£¡£¡£¡£Ö»¹ÜĿǰ³¬°ëÊýÉ豸ÒÑÊܱ£»£»£»£»£»£»£»¤ £¬£¬£¬£¬£¬ÈÔÓг¬¹ý11,000̨É豸¿É±»¹«¿ª½Ó¼û £¬£¬£¬£¬£¬×é³É³Á´ó·çÏÕ¡£¡£ ¡£¡£¡£¡£ÎªÓ¦¶ÔÍþв £¬£¬£¬£¬£¬Fortinet½¨ÒéÖÎÀíÔ±ÔÚÌṩÆëÈ«½¨¸´µÄFortiOS°æ±¾Ç° £¬£¬£¬£¬£¬ÁÙʱ½ûÓÃFortiCloudµÇ¼ְÄÜ¡£¡£ ¡£¡£¡£¡£¾ßÌå²Ù×÷¿Éͨ¹ýWeb½çÃæ½øÈë"ϵͳ"¡ú"ÉèÖÃ" £¬£¬£¬£¬£¬¹Ø¹Ø"ÔÊÐíʹÓÃFortiCloud SSO½øÐÐÖÎÀíÔ±µÇ¼"Ñ¡Ïî £¬£¬£¬£¬£¬»òͨ¹ýºÅÁîÐÐÖ´ÐÐ"config system global; set admin-forticloud-sso-login disable; end"ʵÏÖ¡£¡£ ¡£¡£¡£¡£ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö(CISA)Òѽ«¸Ã·ì϶ÁÐÈë"ÔÚ±»ÀûÓõķì϶"Çåµ¥ £¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚÒ»ÖÜÄÚʵÏÖ½¨²¹¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fortinet-admins-report-patched-fortigate-firewalls-getting-hacked/


2. ÒÁÀʵçÊǪ́ÔâºÚ¿Í¹¥»÷²¥·ÅÍõ´¢½²»°


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬ÒÁÀʶà¼ÒµçÊǪ́½ÚÄ¿1ÔÂ18ÈÕÍí¼äÔâºÚ¿ÍÖÐ¶Ï £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý°ÍµÂ¶ûÎÀÐÇ´«ÊäϵͳÊÕÊÜÐźŠ£¬£¬£¬£¬£¬²¥·Å½ÖÍ·¿¹Òé»­Ãæ¼°ÍöÃüÍõ´¢ÀñÈø¡¤°ÍÁÐάµÄ¼«¶ÈÖÓÔ¤ÏȼÔì½²»°¡£¡£ ¡£¡£¡£¡£°ÍÁÐάÔÚÊÓÆµÖкôÓõÒÁÀʹúÃñ¾üÓëÃñ¶àÁª½á £¬£¬£¬£¬£¬Ôð¹Ö°²È«¶ÓÁÓװЧÖÒÒÁ˹À¼¹²ºÍ¹ú¶ø·ÇÒÁÀÊ¡± £¬£¬£¬£¬£¬²¢Ðû³Æ²¿ÃÅÊ¿±øÒѵ¹¸ê £¬£¬£¬£¬£¬µ«Î´Ìṩ֤¾Ý¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËÒÁÀÊÒÁ˹À¼¹²ºÍ¹ú¹ã²¥µçÊǪ́£¨IRIB£©¸²¸Ç´åÂ䵨ÓòµÄÎÀÐÇÐźŠ£¬£¬£¬£¬£¬ÓйØÊÓÆµÆ¬¶ÎѸËÙ±»°ÍÁÐάÍŶӡ¢ÒÁÀʹú¼ÊµçÊǪ́¼°±¾µØÃ½Ìåת·¢´«²¼¡£¡£ ¡£¡£¡£¡£ÊÂÎñ²úÉúÔÚÒÁÀÊÉîÏݾ­¼ÃΣ»£»£»£»£»£»£»úÖ®¼Ê¡£¡£ ¡£¡£¡£¡£×Ô2025Äê12ÔÂµ×Æð £¬£¬£¬£¬£¬ÒÁÀÊÇ®±ÒÀïÑǶû´ó·ù±áÖµ £¬£¬£¬£¬£¬Ê³Æ·¼Ûֵʧ¿Øì­Éý £¬£¬£¬£¬£¬Ãñ¶à½«¾­¼ÃÀ§¾³¹é×ïÓÚµ±¾ÖµòÂä¡£¡£ ¡£¡£¡£¡£Îª×èÖ¹±©Á¦ÐÂÎÅ´«²¼ £¬£¬£¬£¬£¬ÒÁÀʵ±¾Ö¹Ø¹Ø»¥ÁªÍøºÍÒÆ¶¯·þÎñ³¤´ïÁ½ÖÜ¡£¡£ ¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬²¿ÃžÓÃñͨ¹ýÐÇÁ´ÎÀÐÇÌ×¼þ½«ºÚ¿ÍÇÔÈ¡µÄÊÓÆµ´«²¼ÖÁÈ«Çò¡£¡£ ¡£¡£¡£¡£ÓëÒÁÀʸïÃüÎÀ¶Ó¹ØÁªµÄ·¨¶û˹ͨѶÉçÔ®Òý¹ú¶È¹ã²¥¹«Ë¾Ëµ·¨ £¬£¬£¬£¬£¬³Æ²¿ÃŵØÓòÐźš°Òò²»Ã÷Ô­Òò¶ÌÔÝÖжϡ± £¬£¬£¬£¬£¬µ«Î´Ìá¼°¿¹ÒéÊÓÆµ»òÍõ´¢½²»°ÄÚÈÝ¡£¡£ ¡£¡£¡£¡£


https://hackread.com/iranian-tv-transmission-hacked-exiled-prince-message/


3. Cisco´¹Î£½¨¸´¸ßΣÁãÈÕ·ì϶CVE-2026-20045


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬Ë¼¿Æ¹«Ë¾½üÈÕ½¨¸´ÁËÒ»¸öÑϳÁµÄ¸ßΣÁãÈÕÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2026-20045£¨CVSSÆÀ·Ö8.2£© £¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»·¢ÏÖ±»»ý¼«ÀûÓÃÓÚ¹¥»÷¡£¡£ ¡£¡£¡£¡£´Ë·ì϶ԴÓÚHTTPÒªÇóÖÐÓû§ÊäÈëÐÅÏ¢ÑéÖ¤²»µ± £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÊÜÓ°ÏìÉ豸µÄWebÖÎÀí½çÃæ·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇó £¬£¬£¬£¬£¬ÔÚÉ豸µ×²ã²Ù×÷ϵͳִÐÐËÁÒâºÅÁî £¬£¬£¬£¬£¬×îÖÕ¿ÉÄÜ»ñÈ¡rootȨÏÞ¡£¡£ ¡£¡£¡£¡£ÊÜÓ°Ïì²úÆ·Ô̺¬Cisco Unified CM¡¢Unified CM SME¡¢IM & Presence¡¢Unity Connection¼°Webex Calling Dedicated Instance¡£¡£ ¡£¡£¡£¡£¾ßÌ彨¸´°æ±¾ÈçÏ£ºUnified CMµÈϵÁÐ12.5°æ±¾ÐèǨáãÖÁ¹Ì¶¨°æ±¾£»£»£»£»£»£»£»14°æ±¾ÐèÉý¼¶ÖÁ14SU5»òÀûÓò¹¶¡Îļþ£»£»£»£»£»£»£»15°æ±¾ÐèÉý¼¶ÖÁ2026Äê3Ô°䲼µÄ15SU4»òÀûÓöÔÓ¦²¹¶¡¡£¡£ ¡£¡£¡£¡£Unity ConnectionͬÑùÐèÆ¾¾Ý°æ±¾Éý¼¶ÖÁ14SU5»ò15SU4²¢ÀûÓò¹¶¡¡£¡£ ¡£¡£¡£¡£Ë¼¿ÆÇ¿µ÷²¹¶¡Óë°æ±¾Ñϸñ¶ÔÓ¦ £¬£¬£¬£¬£¬Óû§Ðè²Î¿¼²¹¶¡READMEÎļþ²Ù×÷¡£¡£ ¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ £¬£¬£¬£¬£¬Õâ´Î½¨¸´ÎÞһʱ½â¾ö¹æ»® £¬£¬£¬£¬£¬Ë¼¿Æ°²È«Ó¦¼±ÏìÓ¦Ó××飨PSIRT£©ÒÑÈ·ÈÏ´æÔÚÀûÓó¢ÊÔ £¬£¬£¬£¬£¬Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶ÖÁ½¨¸´°æ±¾¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.com/187177/security/cisco-fixed-actively-exploited-unified-communications-zero-day.html


4. Zendesk¹¤µ¥ÏµÍ³ÔâÈ«Çò´ó¹æÄ£À¬»øÓʼþ¹¥»÷


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬È«ÇòÓû§Ôâ·êÓÉZendeskÖ§³ÖϵͳÒý·¢µÄ´ó¹æÄ£À¬»øÓʼþ¹¥»÷ £¬£¬£¬£¬£¬Êܺ¦ÕßÊÕµ½Êý°Ù·âÖ÷Ìâ¹îÒìÇÒÄÚÈÝ»ìÂÒµÄÓʼþ £¬£¬£¬£¬£¬Òý·¢¿í·º²ÂÒÉÓë·¢¼±¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷Ô´ÓÚZendeskÔÊÐíδ¾­ÑéÖ¤Óû§Ìá½»Ö§³Ö¹¤µ¥µÄ·ì϶ £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý±éÀúº£Á¿ÓʼþµØÖ·ÁÐ±í´´½¨Ðéα¹¤µ¥ £¬£¬£¬£¬£¬´¥·¢ÏµÍ³×Ô¶¯·¢ËÍÈ·ÈÏÓʼþ £¬£¬£¬£¬£¬½«ºÏ·¨ÆóÒµµÄZendeskƽ̨±äΪÀ¬»øÓʼþÖмÌÕ¾¡£¡£ ¡£¡£¡£¡£ÊÜÓ°ÏìÆóÒµº­¸Ç¿Æ¼¼¡¢ÓÎÏ·¡¢ÕþÎñµÈ¶àÁìÓò £¬£¬£¬£¬£¬Ô̺¬Discord¡¢Tinder¡¢Riot Games¡¢Dropbox¡¢CD Projekt¡¢ÌïÄÉÎ÷ÖÝÀ͹¤²¿µÈ³¬20¼Ò»ú¹¹¡£¡£ ¡£¡£¡£¡£ÓʼþÖ÷Ìâ³öÏָ߶ȹƻóÐÔÌØµã£º²¿ÃżÙ×°·¨ÂÉ֪ͨ¡¢²¿ÃųÐŵÃâ·Ñ¸£Àû¡¢¸üÓдóÁ¿Ê¹ÓÃUnicode×°è«×ÖÌå±àдµÄÂÒÂëÄÚÈÝ¡£¡£ ¡£¡£¡£¡£ÓÉÓÚÓʼþÔ´×ÔÕý¹æÆóҵϵͳ £¬£¬£¬£¬£¬Æä¿ÉÐŶÈÔ¶³¬Í¨³£À¬»øÓʼþ £¬£¬£¬£¬£¬³É¹¦ÈƹýÀ¬»øÓʼþ¹ýÂËÆ÷ £¬£¬£¬£¬£¬Ðγɸü´óÇÖÈÅÐÔ¡£¡£ ¡£¡£¡£¡£ÉæÊÂÆóҵѸËÙ»ØÓ¦£ºDropbox¡¢2KµÈÃ÷È·°µÊ¾ÓʼþΪϵͳÀÄÓòúÆ· £¬£¬£¬£¬£¬Ç¿µ÷Æä"Å­·Å¹¤µ¥Ìá½»"Õþ²ßËä·½±ãµ«´æÔÚ·çÏÕ £¬£¬£¬£¬£¬³Ðŵδ¾­ÕË»§³ÖÓÐÈËÑéÖ¤²»»á´¦ÖÃÃô¸ÐÒªÇó £¬£¬£¬£¬£¬½¨ÒéÓû§Ö±½ÓºöÂÔÒì³£Óʼþ¡£¡£ ¡£¡£¡£¡£Zendesk¹Ù·½Åû¶ £¬£¬£¬£¬£¬¹«Ë¾ÒÑ´¹Î£²¿ÊðÐÂÐͰ²È«Ö°ÄÜ £¬£¬£¬£¬£¬Í¨¹ý¼ÓÇ¿¼à¿ØËã·¨ÓëÖ´ÐлÏÞ¶È £¬£¬£¬£¬£¬ÌáÉý¶ÔÒì³£¹¤µ¥µÄ¼ì²âÓëÀ¹½ØÐ§ÄÜ¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zendesk-ticket-systems-hijacked-in-massive-global-spam-wave/


5. ÐÂÐͰ²×¿µã»÷ڲƭľÂíÀûÓÃTensorFlow¼¼Êõ´«²¼


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬½üÆÚ £¬£¬£¬£¬£¬Ò»ÖÖÐÂÐͰ²×¿µã»÷ڲƭľÂíͨ¹ýÓ×Ã×¹Ù·½ÀûÓÃÉ̵êGetApps´«²¼ £¬£¬£¬£¬£¬ÀûÓÃTensorFlow»úе½ø½¨Ä£ÐÍ×Ô¶¯¼ì²â²¢½»»¥¸æ°×ÔªËØ £¬£¬£¬£¬£¬Òý·¢°²È«¹Ø×¢¡£¡£ ¡£¡£¡£¡£¸ÃľÂíѡȡÁ½ÖÖÔËÐÐģʽ£º"»ÃÓ°"ģʽͨ¹ý°µ²ØµÄWebViewä¯ÀÀÆ÷¼ÓÔØÖ¸±êÒ³Ãæ £¬£¬£¬£¬£¬½ØÈ¡ÆÁÄ»½ØÍ¼ºóÓÉTensorFlow.js·ÖÎö¸æ°×ÔªËØ £¬£¬£¬£¬£¬Ä£ÄâÓû§µã»÷£»£»£»£»£»£»£»"ÐźŴ«µÝ"ģʽÔòͨ¹ýWebRTC´«ÊäʵʱÊÓÆµÁ÷ÖÁ¹¥»÷Õß £¬£¬£¬£¬£¬Ö§³ÖÔ¶³Ì²Ù×÷µã»÷¡¢¹ö¶¯µÈÐÐΪ¡£¡£ ¡£¡£¡£¡£ÕâÖÖ»ùÓÚÊÓ¾õ·ÖÎöµÄ»úÔìÍ»ÆÆÁË´«Í³¾ç±¾DOM½»»¥µÄÏÞ¶È £¬£¬£¬£¬£¬Äܸü¸ßЧӦ¶Ô¶¯Ì¬¸æ°×µÄƵÈԽṹ±ä¶¯¡£¡£ ¡£¡£¡£¡£Ä¾Âí´«²¼õè¾¶Òñ±Î£º¹¥»÷ÕßÊ×ÏȽ«Õý³£ÓÎÏ·ÀûÓÃÌá½»ÖÁGetApps £¬£¬£¬£¬£¬ºóÐøÍ¨¹ý¸üÐÂÔö³¤¶ñÒâ×é¼þ¡£¡£ ¡£¡£¡£¡£Dr.Web×êÑÐÏÔʾ £¬£¬£¬£¬£¬ÊÜϰȾÓÎÏ·Ô̺¬¡¶ÏÀµÁÁÔ³µÊÖ£ººÚÊÖµ³¡·£¨6.1Íò´ÎÏÂÔØ£©¡¢¡¶¿É°®³èÎïÎÝ¡·£¨3.4Íò´ÎÏÂÔØ£©µÈ £¬£¬£¬£¬£¬¸²¸Ç¶à¸öÈȵãÓÎÏ·¡£¡£ ¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬Ä¾Âí»¹Í¨¹ýµÚÈý·½APKÍøÕ¾£¨ÈçApkmody¡¢Moddroid£©¡¢TelegramƵ·¼°Õ¼ÓÐ2.4Íò¶©ÔÄÕßµÄDiscord·þÎñÆ÷À©É¢ £¬£¬£¬£¬£¬Éæ¼°Spotify Pro¡¢Netflix modµÈÅú¸Ä°æÀûÓᣡ£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-android-malware-uses-ai-to-click-on-hidden-browser-ads/


6. Î÷°àÑÀPcComponentes·ñ¶¨1600Íò¿Í»§Êý¾Ýй¶


1ÔÂ21ÈÕ £¬£¬£¬£¬£¬Î÷°àÑÀ¿Æ¼¼ÁãÊÛÉÌPcComponentes½üÈÕ·ñ¶¨ÆäϵͳÔâ·ê´ó¹æÄ£Êý¾Ýй¶ӰÏì1600Íò¿Í»§µÄ˵·¨ £¬£¬£¬£¬£¬µ«Ö¤ÊµÔâ·êײ¿â¹¥»÷¡£¡£ ¡£¡£¡£¡£´Ëǰ £¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯"daghetiaw"Ðû³ÆÇÔÈ¡¸Ã¹«Ë¾1630ÍòÌõ¿Í»§¼Í¼ £¬£¬£¬£¬£¬²¢Ð¹Â¶50ÍòÌõÑù±¾ £¬£¬£¬£¬£¬Ôü×Ҽͼ´ý¼Û¶ø¹Á¡£¡£ ¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¶©µ¥ÏêÇé¡¢ÏÖʵµØÖ·¡¢È«Ãû¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢²úÆ·ÓûÍûÇåµ¥¼°ZendeskÖ§³Ö¶Ô»°¼Í¼¡£¡£ ¡£¡£¡£¡£PcComponentesÔÚµ÷²éºóÉêÃ÷ £¬£¬£¬£¬£¬ÆäÊý¾Ý¿âºÍÄÚ²¿ÏµÍ³Î´·¢ÏÖ·¸·¨½Ó¼ûÖ¤¾Ý £¬£¬£¬£¬£¬Ç¿µ÷"1600ÍòÊÜÓ°Ïì¿Í»§"Êý×Ö²»Êµ £¬£¬£¬£¬£¬Òò»îÔ¾ÕË»§ÊýÁ¿Ô¶µÍÓÚ´Ë £¬£¬£¬£¬£¬ÇÒϵͳÖдÓδ´æ´¢²ÆÕþÐÅÏ¢»ò¿Í»§ÃÜÂë¡£¡£ ¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬¹«Ë¾ÈϿɼì²âµ½×²¿â¹¥»÷ºÛ¼£ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÆäËûƽ̨й¶µÄÓÊÏäÃÜÂë×éºÏ £¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯¹¤¾ß³¢ÊԵǼPcComponentesÕË»§¡£¡£ ¡£¡£¡£¡£Íþвµý±¨¹«Ë¾Hudson Rock·ÖÎö·¢ÏÖ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜͨ¹ýϰȾÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÍÆËã»úÍøÂçµÇ¼ƾ֤ £¬£¬£¬£¬£¬²¿ÃżÍ¼¿É×·ÒäÖÁ2020Äê¡£¡£ ¡£¡£¡£¡£ÆäÑéÖ¤µÄÁù¸öÓÊÏä¾ùÔÚÒÑÖªÇÔÃÜÈÕÖ¾ÖдæÔÚ £¬£¬£¬£¬£¬Ö¤Êµ¹¥»÷Ó뺹Çàй¶Êý¾Ý´æÔÚ¹ØÁª¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/online-retailer-pccomponentes-says-data-breach-claims-are-fake/