·¨¹úÒøÐÐÔ¼120Íò¸öÒøÐÐÕË»§ÐÅϢй¶

°ä²¼¹¦·ò 2026-02-26

1. ·¨¹úÒøÐÐÔ¼120Íò¸öÒøÐÐÕË»§ÐÅϢй¶


2ÔÂ19ÈÕ £¬·¨¹ú¾­¼Ã²¿Åû¶һ·³Á´óÊý¾Ýй¶ÊÂÎñ £¬Éæ¼°Ô¼120Íò¸öÒøÐÐÕË»§ÐÅÏ¢ £¬Òý·¢Éç»á¿í·º¹Ø×¢¡£¾Ýµ÷²é £¬Õâ´ÎÊÂÎñÔ´ÓÚÍþвÐÐΪÕßͨ¹ýÇÔȡij¹ÙԱƾ֤ £¬Î´¾­ÊÚȨ½Ó¼ûÁ˹ú¶ÈÒøÐÐÕË»§µÇ¼ÇϵͳFICOBA¡£¸ÃÊý¾Ý¿â´æ´¢ÁËËùÓÐÔÚ·¨¹ú¿ªÉèµÄÒøÐÐÕË»§ÐÅÏ¢ £¬Ô̺¬IBAN¹ú¼ÊÒøÐÐÕ˺š¢ÕË»§³ÖÓÐÈËÐÕÃû¡¢µØÖ·¼°²¿ÃÅ˰Îñ¼ø±ðºÅµÈÃô¸ÐÊý¾Ý¡£ÊÂÎñ²úÉúÓÚ1ÔÂÏÂÑ® £¬¹¥»÷ÕߵĽӼûȨÏÞÒѱ»ÊµÊ±ÖÕÖ¹ £¬ÊÜÓ°ÏìÕË»§³ÖÓÐÕßÕýÂ½ÐøÊÕµ½Í¨Öª £¬²¢±»ÌáÐѾ¯ÌèºóÐø¿ÉÄܵÄÚ¿Æ­¼°ÍøÂç´¹µöÐÐΪ¡£·¨¹ú¾­¼Ã²¿Ç¿µ÷ £¬Ö»¹Ü¹¥»÷Õß»ñÈ¡ÁËÕË»§»ù´¡ÐÅÏ¢ £¬µ«ÏµÍ³Éè¼ÆÏÞ¶ÈʹÆäÎÞ·¨Ö´ÐÐÒøÐвÙ×÷»ò²é¿´ÕË»§Óà¶î £¬×î´óÏ޶ȽµµÍÁËÖ±½Ó¾­¼ÃËðʧ·çÏÕ¡£È»¶ø £¬Õâ´ÎÊÂÎñ¶³ö³öϵͳȨÏÞÖÎÀíµÄ½á¹¹ÐÔȱµã £¬µ¥Ò»Éí·Ýƾ֤¼´¿É½Ó¼ûº£Á¿Ãô¸ÐÊý¾Ý £¬²»×ã¶àµµ´Î°²È«ÑéÖ¤»úÔì¡£


https://www.securityweek.com/french-government-says-1-2-million-bank-accounts-exposed-in-breach/


2. µÂ¹úÌú·Ôâ·ê´ó¹æÄ£DDoS¹¥»÷ÖÂϵͳ̱»¾


2ÔÂ19ÈÕ £¬µÂ¹úÌú·ÔËÓªÉ̵¹úÌú·¹«Ë¾£¨Deutsche Bahn£©½üÈÕÔâ·ê´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ £¬µ¼ÖÂÆäÐÅÏ¢ºÍԤԼϵͳÓÚ2ÔÂ17ÈÕÖÁ18ÈÕÆÚ¼ä̱»¾ÊýÓ×ʱ £¬Ôì³ÉÁгµÑÓÎó¡¢·þÎñÖжϼ°³Ë¿Í³öÐлìÂÒ¡£Õâ´Î¹¥»÷²¨¼°¸Ã¹«Ë¾Ö÷ÌâITϵͳ¡¢¹Ù·½ÍøÕ¾bahn.de¼°Òƶ¯ÀûÓÃDB Navigator £¬´óÁ¿Óû§ÎÞ·¨Õý³£²éÎʳµ´Î¡¢Ô¤Ô¼³µÆ±»ò»ñȡʵʱ½»Í¨Ñ¶Ï¢¡£µÂ¹úÌú·ÔÚ×´Ì¬Ò³Ãæ°ä²¼ÉêÃ÷³Æ £¬ITר¼ÒÒÑ´¹Î£È¾Ö¸·ÖÎöÔ­Òò²¢½¨¸´ÏµÍ³ £¬½ØÖÁ2ÔÂ18ÈÕÍí¼ä £¬ÊÜÓ°ÏìϵͳÒѸù»ù¸´Ô­²»±ä £¬ÔËÓªÈ«Ãæ³ÁÆô¡£¾Ý¹«¿ªÐÅÏ¢ £¬±¾´ÎDDoS¹¥»÷ͨ¹ýÏòÖ¸±ê·þÎñÆ÷·¢Ëͺ£Á¿ÐéαҪÇó £¬ºÄ¾¡ÆäÍøÂç´ø¿íºÍÍÆËã×ÊÔ´ £¬×îÖÕµ¼ÖºϷ¨Óû§ÎÞ·¨½Ó¼û·þÎñ¡£Ä¿Ç° £¬µÂ¹úÁª¹úÐÅÏ¢°²È«°ì¹«ÊÒ£¨BSI£©ÒÑȾָµ÷²é £¬µ«ÉÐÎ´Ëø¶¨¾ßÌå¹¥»÷ÕßÉí·Ý¡£


https://securityaffairs.com/188254/breaking-news/germanys-national-rail-operator-deutsche-bahn-hit-by-a-ddos-attack.html


3. ÈÕ±¾Ð¾Æ¬²âÊÔ¾ÞÍ·AdvantestÔâÀÕË÷Èí¼þ¹¥»÷


2ÔÂ20ÈÕ £¬ÈÕ±¾Ð¾Æ¬²âÊÔÉ豸¾ÞÍ·AdvantestÖêʽ»áÉ磨¶«¾©Ö¤È¯ÂòÂôËù´úÂ룺6857£©ÓÚ2ÔÂ15ÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬Òý·¢È«Çò°ëµ¼Ìå²úÒµÁ´°²È«¾¯±¨¡£×÷ÎªÓ¢ÌØ¶û¡¢ÈýÐÇ¡¢Ì¨»ýµçµÈÖØÒªÐ¾Æ¬Ôì×÷É̵ÄÖ÷Ì⹩¸øÉÌ £¬¸Ã¹«Ë¾³ö²úµÄ×Ô¶¯»¯²âÊÔÉ豸¶Ô°ëµ¼Ìå³ö²úÁ÷³ÌÖÁ¹Ø³ÁÒª¡£¾ÝAdvantest¹Ù·½ÉêÃ÷ £¬¹«Ë¾ÔÚ¼ì²âµ½ITÍøÂçÒì³£ºóµ±¼´Æô¶¯ÊÂÎñÏìÓ¦ºÍ̸ £¬³õ´ëÊ©²éÏÔʾ¡°Î´¾­ÊÚȨµÄµÚÈý·½¿ÉÄܽӼûÁËÍøÂ粿ÃÅÄÚÈݲ¢²¿ÊðÁËÀÕË÷Èí¼þ¡±¡£Ä¿Ç°Éв»Ã÷È·¹¥»÷ÕßÊÇ·ñÇÔÈ¡Á˿ͻ§»òÔ±¹¤Ãô¸ÐÐÅÏ¢ £¬µ«¹«Ë¾³ÐŵÈôÈ·ÈÏÊý¾ÝÊÜÓ°Ï콫ֱ½Ó֪ͨÓйØÈËÔ±²¢Ìṩ±£»¤Áìµ¼¡£Õâ´Î¹¥»÷²úÉúÔÚÈÕ±¾µ±¾Ö°ä²¼°ëµ¼Ì幤³§ÔËÓª¼¼Êõ£¨OT£©°²È«ÐÂÖ¸ÄÏÊýÔÂÖ®ºó £¬Í¹ÏÔÕþ²ßÂäʵÓëÏÖʵ·À»¤Ö®¼äµÄ²î¾à¡£Õâ´Î¹¥»÷²úÉú²»µ½Ò»ÖÜ £¬ÉÐÎÞÒÑÖªÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÕÆ¹Ü £¬·ÖÎöÒÔΪ¹¥»÷Õß¿ÉÄÜÕýÆÚ´ýÊê½ð½»Éæ´°¿ÚÆÚ¡£


https://www.securityweek.com/chip-testing-giant-advantest-hit-by-ransomware/


4. ÃÜÎ÷Î÷±È´óѧҽѧÖÐÐÄÔâÀÕË÷Èí¼þ¹¥»÷ÖÂÈ«ÖÝÕïËù¹Ø¹Ø


2ÔÂ20ÈÕ £¬ÃÜÎ÷Î÷±È´óѧҽѧÖÐÐÄ£¨UMMC£©ÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈ¹Ø¹ØÆäÔÚÈ«ÖݵÄ35¼ÒÕïËù¼°200¶à¸öÔ¶³ÌÒ½ÁÆÕ¾µã¡£×÷ΪÃÜÎ÷Î÷±ÈÖÝ×î´óµÄ¹ÍÖ÷Ö®Ò» £¬UMMCÕ¼Óг¬¹ý10,000ÃûÔ±¹¤ £¬ÔËÓª×Å7¼ÒÒ½Ôº £¬²¢³Ðµ£×ŸÃÖÝΨһµÄ¶ùͯҽԺ¡¢I¼¶´´ÉËÖÐÐÄ¡¢Æ÷¹ÙºÍ¹ÇËèÒÆÖ²ÏîÄ¿ÒÔ¼°È«ÃÀ½öÓеÄÁ½¼ÒÔ¶³ÌÒ½ÁÆ×¿Ô½ÖÐÐÄÖ®Ò»µÄÖ°ÄÜ¡£Õâ´ÎÍøÂç¹¥»÷µ¼ÖÂÆä¶à¸öITϵͳ̱»¾ £¬Ô̺¬¹Ø¼üµÄEpicµç×Ó²¡Àúϵͳ½Ó¼ûÖÐ¶Ï £¬ÆÈʹUMMCÈ¡µÞÃÅÕï¡¢ÈÕ¼äÊÖÊõ¡¢Ó°Ïñ²é³­µÈÔ¤Ô¼ £¬µ«Ò½ÔºÖ÷Ìâ·þÎñÈÔͨ¹ýÓ¦¼±·¨Ê½Î¬³ÖÔËÐС£UMMCÔÚ¹¥»÷²úÉúºóµ±¼´Æô¶¯Ó¦¼±´òËã £¬ÓëÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©¡¢Áª¹úµ÷²é¾Ö£¨FBI£©¼°ºÓɽ°²È«Êý·¢Õ¹ºÏ×÷µ÷²é¡£½ØÖÁĿǰ £¬Æä¹Ù·½ÍøÕ¾ÈÔÎÞ·¨½Ó¼û £¬ËùÓÐITϵͳ±»¹Ø¹ØÒÔÆÀ¹ÀÓ°Ïì¡£Ôº·½Ç¿µ÷ £¬Ö»¹Üϵͳ̱»¾ £¬µ«ÁÙ´²É豸ÔËÐÐÕý³£ £¬¼¹Øï¿ÆºÍסԺ·þÎñδÊÜÓ°Ïì £¬ÃæÊڿγÌÒ²°´´òËã½øÐС£¾Ý±¨Â· £¬ÀÕË÷Èí¼þ×éÖ¯ÒÑÓëUMMCÁªÏµ £¬Ë«·½Õý¾ÍÊê½ðÎÊÌâ½øÐн»Éæ¡£


https://www.bleepingcomputer.com/news/security/university-of-mississippi-medical-center-closes-clinics-after-ransomware-attack/


5. PayPalÒòÈí¼þÃýÎóÖ¿ͻ§Ãô¸ÐÐÅϢй¶½ü°ëÄê


2ÔÂ20ÈÕ £¬PayPalÒòPayPal Working Capital£¨PPWC£©´û¿îÀûÓ÷¨Ê½ÖеÄÈí¼þÃýÎó £¬µ¼ÖÂ2025Äê7ÔÂ1ÈÕÖÁ12ÔÂ13ÈÕÆÚ¼äÔ¼100Ãû¿Í»§µÄÃô¸ÐÓ×ÎÒÐÅÏ¢£¨Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°¡¢¹«Ë¾µØÖ·¡¢Éç»á±£ÏÕºÅÂë¼°µ®ÉúÈÕÆÚ£©Ð¹Â¶¡£¸ÃÊÂÎñÓÚ2025Äê12ÔÂ12ÈÕ±»·¢ÏÖ £¬PayPal´ÎÈÕ¼´³·ÏúÒý·¢ÎÊÌâµÄ´úÂëµ÷»» £¬×èÖ¹ÁËÊý¾Ý½øÒ»²½Â¶³ö¡£Ö»¹ÜϵͳδÔâÈëÇÖ £¬µ«PayPalÈÔ×Ô¶¯Í¨ÖªÊÜÓ°ÏìÓû§ £¬²¢³ÁÖÃÆäÕË»§ÃÜÂë £¬ÒªÇóÓû§µÇ¼ʱ´´½¨ÐÂÍ´´¦¡£Õâ´Îй¶ֱ½Óµ¼ÖÂÉÙÊý¿Í»§ÕË»§³öÏÖδ¾­ÊÚȨÂòÂô £¬PayPalÒÑÏòÓйØÓû§·¢·ÅÍ˿×÷ΪÅâ³¥ £¬¹«Ë¾Í¨¹ýEquifaxÌṩΪÆÚÁ½ÄêµÄÃâ·ÑÈý¼ÒÐÅÓþ»ú¹¹ÐÅÓþ¼à¿Ø¼°Éí·Ý¸´Ô­·þÎñ £¬Óû§ÐèÔÚ2026Äê6ÔÂ30ÈÕǰע²á¡£PayPalÇ¿µ÷ £¬Æä¾ø²»»áͨ¹ýµç»°¡¢¶ÌÐÅ»òÓʼþË÷È¡ÕË»§ÃÜÂë¡¢ÑéÖ¤ÂëµÈÑéÖ¤ÐÅÏ¢ £¬ÌáÐÑÓû§¾¯ÌèÍøÂç´¹µö¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/


6. ¶íÓïºÚ¿Í½èAI¹¤¾ß´ó¹æÄ£ÈëÇÖ600̨FortiGateÉ豸


2ÔÂ23ÈÕ £¬Ò»Ãû¾­¼Ã¶¯»úµÄ¶íÓïÍþвÐÐΪÕßÀûÓÃóÒ×ÌìÉúʽÈËΪÖÇÄÜ·þÎñ £¬¶Ô55¸ö¹ú¶ÈµÄ600Óą̀FortiGateÉ豸ÌáÒé×Ô¶¯»¯¹¥»÷ £¬Õâ´Î¹¥»÷»î¶¯²úÉúÔÚ2026Äê1ÔÂ11ÈÕÖÁ2ÔÂ18ÈÕÆÚ¼ä £¬ÑÇÂíÑ·Íþвµý±¨»ã±¨ÏÔʾ £¬¹¥»÷ÕßδÀûÓÃϵͳ·ì϶ £¬¶øÊÇͨ¹ý¶³öµÄÖÎÀí¶Ë¿ÚºÍÓÄ΢µ¥³É·ÖÈÏÖ¤Ö´ÐÐÈëÇÖ £¬Í¹ÏÔAI¼¼ÊõÈôºÎ½µµÍÍøÂç·¸×ïÃż÷¡£¸Ã¹¥»÷ÕßʹÓöàÖÖóÒ×GenAI¹¤¾ß×Ô¶¯»¯É¨Ãè¶³öµÄFortiGateÖÎÀí¶Ë¿Ú £¬ÇÔÈ¡Ô̺¬VPN¡¢ÖÎÀíÔ±¼°ÍøÂçÊý¾ÝµÄÆëÈ«ÅäÖá£ÈëÇÖºó²¿ÊðµÄ¶¨Ôì¿úËŹ¤¾ß£¨Go/Python±àд£©´øÓÐÏÔÖøAIÌìÉúÌØµã£ºÈßÓà×¢½â³Á¸´º¯ÊýÃû¡¢¼Ü¹¹¹ý¶È×¢³ÁÌåʽ¡¢×Ö·û´®Æ¥Åä½âÎöJSON¡¢ÎÞÎĵµµÄ¼æÈݲ¹¶¡µÈ¡£ÕâЩ¹¤¾ßËäÂú×ãÌØ¶¨ÐèÒª £¬µ«Â³°ôÐÔ²»¼° £¬ÔÚ¼«¶Ë³¡¾°Ò×ʧЧ¡£¹¥»÷Á÷³ÌÏÔʾ £¬AI¸¨Öú¾ç±¾½âÎö½âÃÜÊý¾Ýºó £¬¹¥»÷Õßͨ¹ýVPN½Ó¼ûÍøÂç £¬Ö´ÐÐActive DirectoryÈëÇÖ¡¢NTLM¹þÏ£ÇÔÈ¡¡¢ºáÏòÒÆ¶¯ £¬²¢ÊÔͼ¹¥»÷Veeam±¸·Ý·þÎñÆ÷ÒÔ¼õÈõϵͳ¸´Ô­ÄÜÁ¦¡£È»¶ø £¬Ãæ¶ÔÒÑ´ò²¹¶¡»ò¼Ó¹ÌµÄϵͳʱ £¬¹¥»÷³£Òò¼¼Êõ²»¼°¶øÊ§°Ü¡£ÀýÈç £¬³¢ÊÔÀûÓÃCVE-2019-7192¡¢CVE-2023-27532µÈ·ì϶ʱ £¬³ý×îÖ±½Ó×Ô¶¯»¯õè¾¶±í¾ù¸æÊ§°Ü¡£


https://securityaffairs.com/188351/hacking/ai-powered-campaign-compromises-600-fortigate-systems-worldwide.html