Òâ´óÀûÂùÝס¿ÍÉí·ÝÖ¤¼þÔâ´ó¹æÄ£Ð¹Â¶

Ðû²¼Ê±¼ä 2025-08-18

1. Òâ´óÀûÂùÝס¿ÍÉí·ÝÖ¤¼þÔâ´ó¹æÄ£Ð¹Â¶


8ÔÂ14ÈÕ£¬£¬ £¬£¬£¬Òâ´óÀûÕþ¸®¿ËÈÕ·¢³ö½ôÆÈÖÒÑÔ£¬£¬ £¬£¬£¬³Æ¸Ã¹úÊýÍòÃûÂùÝס¿ÍµÄÉí·ÝÖ¤¼þÐÅÏ¢ÔâÍøÂç·¸·¨·Ö×ÓÇÔÈ¡²¢ÔÚµØÏÂÂÛ̳²»·¨³öÊÛ£¬£¬ £¬£¬£¬Òý·¢¶ÔСÎÒ˽¼ÒÊý¾ÝÇå¾²¼°ºóÐøÚ²Æ­Î£º¦µÄÆÕ±é¹Ø×¢¡£¡£¡£¡£¾ÝÒâ´óÀûÊý×Ö»ú¹¹£¨CERT-AGID£©ÅÌËã»úÓ¦¼±ÏìӦС×éת´ï£¬£¬ £¬£¬£¬Ò»ÃûʹÓá°mydocs¡±ÕË»§µÄÍøÂç·¸·¨·Ö×Ó×ÔÉÏÖÜÆð£¬£¬ £¬£¬£¬ÔÚij×ÅÃûµØÏÂÂÛ̳·ÖÅúÊÛÂôÁè¼Ý9Íò·Ý¸ßÇåɨÃèÎļþ£¬£¬ £¬£¬£¬ÕâЩÎļþÔ´×Ô10¼ÒÒâ´óÀûÂùÝ£¬£¬ £¬£¬£¬¾ùΪס¿Í°ìÀíÈëסʱÌá½»µÄ»¤ÕÕ¡¢¹Ù·½Éí·ÝÖ¤µÈÑéÖ¤ÖÊÁϵÄɨÃè¼þ¡£¡£¡£¡£Ö»¹ÜÏêϸÊÜÓ°ÏìÂùÝÃû³ÆÎ´±»¹ûÕæ£¬£¬ £¬£¬£¬ÇÒÊý¾Ý±£´æÄêÏÞÉв»Ã÷È·£¬£¬ £¬£¬£¬µ«CERT-AGIDÈ·ÈÏÎ¥¹æÐÐΪ¼¯Öб¬·¢ÓÚ2025Äê6ÔÂÖÁ7Լ䣬£¬ £¬£¬£¬²¢ÖÒÑÔ¡°Î´À´¼¸Ìì¿ÉÄÜ·ºÆð¸ü¶à´ËÀà°¸¼þ¡±¡£¡£¡£¡£´Ë´ÎÊÂÎñµÄ½¹µãΣº¦ÔÚÓÚ±»µÁÊý¾ÝµÄDZÔÚÀÄÓᣡ£¡£¡£AGIDÖ¸³ö£¬£¬ £¬£¬£¬²»·¨·Ö×Ó¿ÉÄÜʹÓÃÕâЩÉí·ÝÖ¤¼þʵÑéαÔìÎļþ¡¢¿ªÉèÒøÐÐÕË»§¡¢Éç»á¹¤³Ì¹¥»÷¼°Êý×ÖÉí·Ý͵ÇÔµÈÐÐΪ£¬£¬ £¬£¬£¬Êܺ¦Õß»ò½«ÃæÁÙÑÏÖØµÄ¾­¼ÃÓëÖ´·¨Ð§¹û¡£¡£¡£¡£Îª´Ë£¬£¬ £¬£¬£¬Òâ´óÀûÕþ¸®±Þ²ß½üÆÚÈëס¹ýÒâ´óÀûÂùݵÄÓοÍÇ×½ü¼à¿ØÐ¡ÎÒ˽¼ÒÐÅÓüͼ¼°½ðÈÚÕË»§¶¯Ì¬£¬£¬ £¬£¬£¬Ð¡ÐÄÒÔ×ÔÉíÃûÒåÌᳫµÄδ¾­ÊÚȨ²Ù×÷¡£¡£¡£¡£


https://therecord.media/italy-hotel-guests-possible-data-breach-ids


2. CISA½«N-able N-CentralÎó²îÌí¼Óµ½ÒÑÖª±»Ê¹ÓÃÎó²îĿ¼ÖÐ


8ÔÂ14ÈÕ£¬£¬ £¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ½«N-able N-CentralÔ¶³Ì¼à¿ØÓëÖÎÀí£¨RMM£©Æ½Ì¨µÄÁ½¸ö¸ßΣÎó²î£ºCVE-2025-8875²»Çå¾²·´ÐòÁл¯Îó²î¡¢CVE-2025-8876ÏÂÁî×¢ÈëÎó²îÄÉÈëÆä¡°ÒÑÖª±»Ê¹ÓÃÎó²î£¨KEV£©¡±Ä¿Â¼£¬£¬ £¬£¬£¬²¢ÒªÇóÁª°î»ú¹¹ÔÚ2025Äê8ÔÂ20ÈÕǰÍê³ÉÐÞ¸´¡£¡£¡£¡£N-able N-Central×÷ÎªÃæÏòÍйÜЧÀÍÌṩÉÌ£¨MSP£©µÄ¿çƽ̨£¨Windows¡¢Apple¡¢Linux£©¶ËµãÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬Æä2025.3.1°æ±¾ÒÑÐû²¼Òªº¦Çå¾²²¹¶¡£¬£¬ £¬£¬£¬Ö±½ÓÕë¶ÔÉÏÊöÐèÉí·ÝÑéÖ¤·½¿ÉʹÓõÄÎó²î¡£¡£¡£¡£CISAÇ¿µ÷£¬£¬ £¬£¬£¬Ö»¹ÜÎó²îʹÓÃÐèÈÏÖ¤Ìõ¼þ£¬£¬ £¬£¬£¬µ«Î´ÐÞ²¹ÏµÍ³ÈÔ¿ÉÄÜÃæÁÙÊý¾Ýй¶¡¢ÏÂÁîÖ´ÐеÈÇ徲Σº¦¡£¡£¡£¡£³ýN-ableÎó²îÍ⣬£¬ £¬£¬£¬CISAͬÆÚ½«Microsoft Internet Explorer¡¢Office Excel¼°WinRARµÄÀúÊ·Îó²îÁÐÈëKEVĿ¼ÖС£¡£¡£¡£


https://securityaffairs.com/181135/security/u-s-cisa-adds-n-able-n-central-flaws-to-its-known-exploited-vulnerabilities-catalog.html


3. ˼¿ÆÖÒÑÔFMC RADIUSÎó²îÔÊÐíÔ¶³Ì´úÂëÖ´ÐÐ


8ÔÂ15ÈÕ£¬£¬ £¬£¬£¬Ë¼¿Æ¿ËÈÕÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬Õë¶ÔÆäÇå¾²·À»ðǽÖÎÀíÖÐÐÄ£¨FMC£©Èí¼þ¼°¶à¿îÇå¾²×°±¸²úÆ·ÐÞ¸´Á˹²¼Æ12¸ö¸ßΣÇå¾²Îó²î£¬£¬ £¬£¬£¬ÆäÖÐ×îÑÏÖØµÄCVE-2025-20265Îó²î£¨CVSSÆÀ·Ö10.0£©±»½ç˵Ϊ¡°×î¸ßÑÏÖØÐÔ¡±£¬£¬ £¬£¬£¬¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚFMCµÄRADIUS×ÓϵͳÔÚÉí·ÝÑéÖ¤½×¶Î¶ÔÓû§ÊäÈëȱ·¦ÓÐÓô¦Öóͷ££¬£¬ £¬£¬£¬µ±×°±¸ÉèÖÃΪ»ùÓÚWebÖÎÀí½çÃæ¡¢SSHÖÎÀí»òÁ½ÕßµÄRADIUSÉí·ÝÑé֤ʱ£¬£¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆÊäÈ루ÈçÉèÖõÄRADIUSЧÀÍÆ÷ÈÏ֤ƾ֤£©´¥·¢Îó²î£¬£¬ £¬£¬£¬½ø¶øÒÔ¸ßȨÏÞÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾ÎªË¼¿ÆSecure FMCÈí¼þ7.0.7ºÍ7.7.0£¬£¬ £¬£¬£¬ÏÖÔÚ½öÄÜͨ¹ý¹Ù·½²¹¶¡ÐÞ¸´£¬£¬ £¬£¬£¬ÎÞÆäËûÔÝʱ½â¾ö¼Æ»®¡£¡£¡£¡£³ýCVE-2025-20265Í⣬£¬ £¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁË11¸ö¸ßΣÎó²î£¬£¬ £¬£¬£¬ÁýÕÖ¶à¿î˼¿ÆÇå¾²²úÆ·¡£¡£¡£¡£


https://thehackernews.com/2025/08/cisco-warns-of-cvss-100-fmc-radius-flaw.html


4. Ó¢¹úµçÐŹ©Ó¦ÉÌColtÔâÍøÂç¹¥»÷ÖÂЧÀÍÖÐÖ¹


8ÔÂ16ÈÕ£¬£¬ £¬£¬£¬×ܲ¿Î»ÓÚÂ׶صĿƼ¼ÓëµçÐÅЧÀÍÉÌColt Technology Services¿ËÈÕÔâÓöÍøÂç¹¥»÷£¬£¬ £¬£¬£¬µ¼ÖÂÆä½¹µãЧÀÍÆ½Ì¨·ºÆð´ó¹æÄ£ÖÐÖ¹¡£¡£¡£¡£¸Ã¹«Ë¾ÖÜËÄÈ·ÈÏ£¬£¬ £¬£¬£¬Òò"ÄÚ²¿ÏµÍ³±¬·¢ÍøÂçÊÂÎñ"£¬£¬ £¬£¬£¬ÆäColt OnlineÖÎÀíÆ½Ì¨¼°Voice APIÓïÒôЧÀÍÒÑÖÜÈ«ÏÂÏߣ¬£¬ £¬£¬£¬ÏÖÔÚÈÔ´¦ÓÚ»Ö¸´½×¶Î¡£¡£¡£¡£×÷Ϊ¸»´ïͶ×ʼ¯ÍÅÆìϵĿç¹úÆóÒµ£¬£¬ £¬£¬£¬ColtÓµÓÐÁýÕÖ¹âÏËÍøÂç¡¢ÔÆÐ§ÀÍ¡¢Êý¾ÝÖÐÐļ°Çå¾²¹¤¾ßµÄ¶àÔª»¯ÓªÒµÏµÍ³£¬£¬ £¬£¬£¬´Ë´ÎÊÂÎñËäδֱ½ÓÓ°Ïì¿Í»§»ù´¡¼Ü¹¹£¬£¬ £¬£¬£¬µ«ÈÔ̻¶³öµçÐÅ»ù´¡ÉèÊ©ÃæÁÙµÄÑÏËàÇå¾²ÌôÕ½¡£¡£¡£¡£¾Ý¹«Ë¾×îÐÂÉùÃ÷£¬£¬ £¬£¬£¬ÆäÍøÂç¼à¿ØÄÜÁ¦ÒÑתΪÊÖ¶¯²Ù×÷ģʽ£¬£¬ £¬£¬£¬×Ô¶¯¼à¿ØÏµÍ³µÄÍêÈ«»Ö¸´ÈÔÐèʱ¼ä¡£¡£¡£¡£Colt·½ÃæÇ¿µ÷£¬£¬ £¬£¬£¬Ö»¹ÜÄ¿½ñÏìÓ¦ËÙÂÊ¿ÉÄÜ·Å»º£¬£¬ £¬£¬£¬µ«ÊÖÒÕÍŶÓÕýÈ«Á¦°ü¹Ü¿Í»§Ð§ÀÍ£¬£¬ £¬£¬£¬²¢½¨ÒéÓû§Í¨¹ýÓʼþ»òµç»°¾ÙÐÐÏàͬ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬£¬£¬´Ë´Î¹¥»÷±¬·¢Ç°£¬£¬ £¬£¬£¬ColtÔøÒÔ"ÊÖÒÕÎÊÌâ"ΪÓÉÐû²¼ÏµÁиüУ¬£¬ £¬£¬£¬µ«Î´ÊµÊ±Åû¶ÊÂÎñµÄÍøÂçÇå¾²ÊôÐÔ£¬£¬ £¬£¬£¬Òý·¢Íâ½ç¶ÔÐÅϢ͸Ã÷¶ÈµÄ¹Ø×¢¡£¡£¡£¡£


https://therecord.media/uk-colt-outages-cyber-incident


5. Fundamental Executive Services 5.6Íò»¼ÕßÐÅÏ¢ÔâÇÔ


8ÔÂ16ÈÕ£¬£¬ £¬£¬£¬ÃÀ¹úÂíÀïÀ¼Öݺã¾ÃÕչ˻¤Ê¿»ú¹¹Ð§ÀÍÌṩÉÌFundamental Executive Services, LLC¿ËÈÕÅû¶һÆðÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬£¬Éæ¼°56,325Ãû»¼ÕßÃô¸ÐÐÅÏ¢±»ÇÔ¡£¡£¡£¡£ÊÂÎñÔ´ÓÚ2024Äê10ÔÂ27ÈÕÖÁ2025Äê1ÔÂ13ÈÕʱ´ú£¬£¬ £¬£¬£¬Î´Öª¹¥»÷Õßδ¾­ÊÚȨ»á¼ûÆäÍøÂ磬£¬ £¬£¬£¬µ«¸Ã¹«Ë¾Ö±ÖÁ2025Äê1ÔÂ20ÈղŲì¾õÒì³££¬£¬ £¬£¬£¬ÑÓ³Ù¼ì²â½üÈý¸öÔ¡£¡£¡£¡£Æ¾Ö¤FundamentalÏòÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿£¨HHS£©Ìá½»µÄ¸üб¨¸æ¼°Ðû²¼µÄÐÂΟ壬£¬ £¬£¬£¬Ð¹Â¶Êý¾Ýº­¸Ç»¼ÕßÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕ/ÖÝʶÓÖÃûÂë¡¢½ðÈÚÕË»§ÐÅÏ¢¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢¿µ½¡°ü¹Üµ¥ºÅÂë¼°Ò½Áưü¹Ü/Ò½ÁƽòÌùÍýÏëÐÅÏ¢µÈ¸ß¶ÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°¸Ã¹«Ë¾ÆìÏÂÊýÊ®¼ÒÕչ˻¤Ê¿»ú¹¹£¬£¬ £¬£¬£¬°üÀ¨°¢À­Äª¸ßµØ¿µ½¡Ó뿵¸´ÖÐÐÄ¡¢±¾ÄÚ´Äά¶û¿µ½¡Ó뿵¸´ÖÐÐÄ¡¢À­Ë¹Î¬¼Ó˹µØÆ½Ïßר¿ÆÒ½ÔºµÈ±é²¼È«ÃÀµÄºã¾ÃÕչ˻¤Ê¿ÉèÊ©¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬FundamentalÒÑͨ¹ýÍøÕ¾Ðû²¼Ì滻֪ͨ£¬£¬ £¬£¬£¬²¢ÔÊÐíΪÊÜÓ°Ïì¸öÌåÌṩÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬ £¬£¬£¬µ«Î´Ìá¼°ÊÇ·ñ¶ÔµÚÈý·½¹©Ó¦É̾ÙÐÐ×·Ôð»òÉý¼¶Çå¾²²½·¥¡£¡£¡£¡£


https://databreaches.net/2025/08/16/data-breach-at-fundamental-administrative-services-affected-56235-patients-at-long-term-care-facilities/?pk_campaign=feed&pk_kwd=data-breach-at-fundamental-administrative-services-affected-56235-patients-at-long-term-care-facilities


6. ¶íÂÞ˹ºÚ¿Í×éÖ¯EncryptHubʹÓÃWindowsÎó²î·¢¶¯ÍøÂç¹¥»÷


8ÔÂ16ÈÕ£¬£¬ £¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯EncryptHub£¨ÓÖÃûLARVA-208¡¢Water Gamayun£©Õýͨ¹ýÒÑÐÞ²¹µÄMicrosoft WindowsÎó²î£¨CVE-2025-26633£©·¢¶¯ÐÂÒ»ÂÖ¹¥»÷£¬£¬ £¬£¬£¬Á¬ÏµÉç»á¹¤³ÌѧÓëϵͳÎó²îʵÑéÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¾ÝTrustwave SpiderLabsÑо¿£¬£¬ £¬£¬£¬¸Ã×éÖ¯×Ô2024ÄêÖÐÆÚ»îÔ¾ÒÔÀ´£¬£¬ £¬£¬£¬ÒÔ¾­¼ÃÀûÒæÎªµ¼Ïò£¬£¬ £¬£¬£¬½ÓÄɶàά¶ÈÊÖ¶ÎѬȾĿµÄ£¬£¬ £¬£¬£¬°üÀ¨ÐéαÊÂÇéʱ»ú¡¢×÷Æ·¼¯ÉóºË¼°ÈëÇÖSteamÓÎϷƽ̨£¬£¬ £¬£¬£¬½üÆÚ¸üʹÓÃ΢ÈíÖÎÀí¿ØÖÆÌ¨£¨MMC£©¿ò¼ÜÎó²îÈö²¥¶ñÒâ¸ºÔØ¡£¡£¡£¡£×îй¥»÷ÖУ¬£¬ £¬£¬£¬EncryptHubαװ³ÉIT²¿·ÖÏòÄ¿µÄ·¢ËÍMicrosoft TeamsÇëÇ󣬣¬ £¬£¬£¬ÓÕµ¼Óû§Ö´ÐжñÒâMSCÎļþ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃͬÃûÁ¼ÐÔÎļþÑÚÊζñÒâMSC£¬£¬ £¬£¬£¬´¥·¢CVE-2025-26633Îó²îºó£¬£¬ £¬£¬£¬Í¨¹ýPowerShell¾ç±¾´ÓÍⲿЧÀÍÆ÷ÏÂÔØ²¢Ö´ÐÐÇÔÈ¡³ÌÐòFickle Stealer¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÍøÂçϵͳÐÅÏ¢¡¢½¨É賤ÆÚÐÔ£¬£¬ £¬£¬£¬²¢Óë¼ÓÃܵÄC2ЧÀÍÆ÷ͨѶÒÔÎüÊÕÖ¸Á£¬ £¬£¬£¬ÉõÖÁÌìÉúÐéαä¯ÀÀÆ÷Á÷Á¿»ìÏýÁ÷Á¿ÌØÕ÷¡£¡£¡£¡£


https://thehackernews.com/2025/08/russian-group-encrypthub-exploits-msc.html