SpeedXй¶ÊýÒڱʼͼ£º¿Í»§×¡Ö·Óë˾»ú¼ÝÕÕÆØ¹â

°ä²¼¹¦·ò 2026-05-29
1. SpeedXй¶ÊýÒڱʼͼ£º¿Í»§×¡Ö·Óë˾»ú¼ÝÕÕÆØ¹â


5ÔÂ27ÈÕ£¬½üÆÚ£¬×êÑÐÍŶӷ¢ÏÖÃÀ¹ú×îºóÒ»¹«Àï°ü¹üµÝË͹«Ë¾SpeedXÔÚÍøÉÏй¶ÁËÊýÒڱʼͼ£¬Â¶³öÁ˶à¶àÃÀ¹ú¾ÓÃñµÄÓ×ÎÒÊý¾Ý¡£Õë¶Ô´ËÊ£¬SpeedX»ØÓ¦³Æ£¬¶ÔAzure BlobÅäÖõÄÉó²é½ö·¢ÏÖ¡°ÈÝÆ÷ÔªÊý¾ÝÏìÓ¦ÓÐÏÞ¡±£¬µ«²¢Î´·¢ÏÖÈκζñÒâ»î¶¯¡£¹«Ë¾Ç¿µ÷£¬µ÷²éûÓз¢ÏÖδ¾­ÊÚȨ½Ó¼ûÃô¸Ð¿Í»§Êý¾ÝµÄÖ¤¾Ý£¬Ò²Ã»Óз¢ÏÖÈκΰ²È«·ì϶£¬ÒÔΪÕâÖ»ÊÇÒ»¸ö´æ´¢ÅäÖÃÎÊÌâ¶ø·ÇÊý¾Ýй¶£¬²¢Ðû³Æ½Ó¼û¶ÔÏóÈÔÐèÏàʶ¾ßÌåõè¾¶£¬²»µÅ×Ú²»ÊÜÏ޶ȵĹ«¿ª½Ó¼û¡£È»¶ø£¬×êÑÐÈËÔ±±ç²µ³Æ£¬ÈκÎÈËÖ»Ðè֪·´æ´¢Í°Ãû³Æ¾ÍÄܽӼû³¬¹ý8.4ÒÚ¸öÎļþ£¬ÎÞÐèÈκξßÌåõè¾¶ÐÅÏ¢¡£Ð¹Â¶µÄAzure´æ´¢Í°Ô̺¬11¸öǰ׺£¬ÎļþÊýÁ¿´Ó¼¸¸öµ½½ü6.2ÒÚ¸ö²»µÈ¡£×î´óµÄÊý¾Ý¿âÔ̺¬6.18ÒÚ¸öÎļþ£¬ÖØÒªÊǰü¹üºÍÔËÊä±êÇ©µÄÕÕÆ¬£¬½ÒʾÁËÊÕ¼þÈËÐÅÏ¢¡£ÁíÒ»¸ö³¬¹ý2.2ÒڱʼͼµÄǰ׺Ô̺¬»õÔ˱êÇ©PDFÎļþ£¬¼Í¼Á˰ü¹üµÄÔËÊä½×¶Î¼°×îÖÕÖ÷ÕŵØÊý¾Ý£¬ÆäÖв¿ÃűêÇ©ÊôÓÚ¼ÓÄôó¿ìµÝ¹«Ë¾Raven Force Couriers£¬¿ÉÄÜÊÇSpeedXµÄºÏ×÷ͬ°é¡£»¹ÓÐ380Íò±Ê¼Í¼Åû¶Á˽»¸¶Åú´Î»ã±¨£¬Ð¹Â¶Á˸ú×ÙºÅÂë¡¢´¦ÖÃÉèÊ©µØÖ·¼°ÊÕ¼þÈËÓ×ÎÒÐÅÏ¢¡£×îÁîÈËÓÇÓôµÄÊÇ£¬×êÑÐÈËÔ±»¹·¢ÏÖÁ˽ü10.5Íò±Ê¼Í¼£¬Ô̺¬Ë¾»ú¼ÝÕÕÕÕÆ¬ºÍSpeedXÀûÓÃÆ¾Ö¤½ØÍ¼£¬ºÜ¿ÉÄÜÊÇ˾»úÌá½»µÄ×ʸñÈ·ÈÏÐÅÏ¢¡£


https://cybernews.com/security/speedx-delivery-data-leak-840-million-exposed/


2. ¶íºÚ¿Í×éÖ¯¡°GreyVibe¡±½èAI·¢Õ¹ÍøÂç¼äµý»î¶¯


5ÔÂ28ÈÕ£¬Ò»¸öÃûΪGreyVibeµÄÒÉËÆ¶íÂÞ˹Íþв×éÖ¯×Ô2025Äê8ÔÂÒÔÀ´£¬ÀûÓÃÈËΪÖÇÄÜÌìÉúµÄµö¶üºÍÒ»Ì×¶¨Ôì¶ñÒâÈí¼þ¹¤¾ß£¬Õë¶Ô¾üÊ¡¢µ±¾Ö¡¢Ãñ¼ä¼°Ã³Ò×ʵÌå·¢Õ¹Á˳ÖÐøµÄÍøÂç¼äµý»î¶¯¡£Ö»¹Ü¸Ã×éÖ¯µÄÐÐΪÓë¶íÂÞ˹¹ú¶ÈÀûÒæ¸ß¶È·ûºÏ£¬µ«ÍøÂ簲ȫ¹«Ë¾WithSecure°µÊ¾£¬ÉÐÎÞ·¨È·¶¨ÐԵؽ«Æä¹éÀàΪ¹ú¶ÈÐÐΪ¡£GreyVibeÉè¼ÆÁ˶àÖÖ¹¥»÷Á´£¬ÆäÖÐÔ̺¬PhantomMail£ºÍ¨¹ý¼Ù×°³ÉÎÚ¿ËÀ¼µ±¾Ö¡¢Ó¦¼±¡¢µçÐźÍÄÜÔ´»ú¹¹µÄ´¹µöÓʼþ£¬ÀûÓÃGoogle DriveºÍ4syncÁ´½Ó´«²¼¶ñÒâѹËõ°ü£»PhantomClick£ºÎ±ÔìZoomºÍLAPASÍøÕ¾µÄCAPTCHAÒ³Ãæ£¬ÓÕµ¼Óû§Ö´ÐÐ×ÔϰȾºÅÁPrincessClub£ºÉèÁ¢Ðéα½»ÓÑÍøÕ¾£¬´«²¼FallSpy°²×¿¼äµýÈí¼þºÍPhantomRelay¡¢LegionRelayµÈWindows¶ñÒâÈí¼þ£»DroneLink£ºÒÔFPVÎÞÈË»úΪÖ÷ÌâµÄÐéα´È±¯ÍøÕ¾£¬ÓëPrincessClub¹²Ïí»ù´¡ÉèÊ©£»Nebo£ºÎ±Ôì¶íÂÞ˹¾üÊÂͨѶµÇÂ¼Ò³Ãæ£¬Ì°Í¼ºýŪÎÚ¿ËÀ¼¾ü·½ÈËÔ±¡£ÕâЩµö¶üÄÚÈÝÕæÇУ¬µÃÒæÓÚ¶ÔChatGPT¡¢Ideogram AIºÍGoogle GeminiµÈAI¹¤¾ßµÄ¿í·ºÀûÓá£


https://www.bleepingcomputer.com/news/security/greyvibe-hackers-use-chatgpt-gemini-to-power-cyberattacks/


3. ÃÀ¾üʵØÎ»Êý¾Ýй¶£¬Îå½Ç´óÂ¥±»ÅúÓ¦¶Ô»ºÂý


5ÔÂ28ÈÕ£¬Ò»·Ý×îÐÂÅû¶µÄÃÀ¹ú¹ú·À²¿ÎļþÏÔʾ£¬±í¹úµÐÊÖÒѳɹ¦ÀûÓôÓóÒ×Êý¾Ý¾­¼ÍÈË´¦²É°ìµÄµØÀíλÏàÐÅÏ¢£¬¶ÔפÖж«ÃÀÎäʿԱ½øÐж¨Î»ºÍ¼à¶½¡£Ö»¹ÜÕâÒ»ÎÊÌâÖÁÉÙ´Ó2016ÄêÆð¾ÍÒÑÏò¾ü·½¸¨µ¼²ã»ã±¨£¬µ«Îå½Ç´óÂ¥±»Ö¸Ðж¯»ºÂý£¬Î´ÄÜÓÐЧ±£»¤ÎäÊ¿ÒþÖÔÓëÐж¯°²È«¡£²ÎÒéÔ±ÂÞ¶÷¡¤»³µÇÓë¶àÒéÔ±ÅÁÌØ¡¤¹þÀï¸ùµÈÊ®ÓàÃû¹ú»áÒéÔ±½üÈÕÁªÃûÖÂÐŹú·À²¿Ê×ϯÐÅÏ¢¹Ù£¬ÒªÇó¸÷±øÖÖ´¹Î£µ÷ÕûÖÇÄÜÊÖ»ú°²È«Õ½Êõ¡£ÐÅÖÐÖ¸³ö£¬ÃÀ¹úÖÐÑë˾ÁÒÑÊÕµ½¶àÆðÍþв»ã±¨£¬È·Èϵз½ÀûÓÃóÒ×µØÎ»Êý¾ÝÕë¶ÔÕ½ÇøÄÚÃÀÎäʿԱ¡£ÕâЩÊý¾ÝµÄÆðÔ´Óëͨ³£Ã³Ò×Âò¼ÒÒ»Ñù£¬¼´ÖÇÄÜÊÖ»ú¸æ°××ÊÁÏ¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬¾ü·½²¢Î´²»ÈÝ×÷Õ½ÇøÓòÄÚµÄÎäʿʹÓÃÓ×ÎÒÉ豸£¬Ò²Ã»ÓÐÕþ²ßÒªÇóËûÃÇÔÚ»îÔ¾Õ½Çø¹Ø¹ØµØÀíµØÎ»Ö°ÄÜ¡£¹ú·À²¿Ëä°ä²¼ÁËÓйطçÏÕÖ¸ÄÏ£¬µ«ÈÏ¿ÉÖ¸Äϲ¢²»×ÜÄÜÆëÈ«½ûÓö¨Î»·þÎñ¡£¼´¾ÍÊǹú·À²¿Åä·¢µÄÖÇÄÜÊÖ»ú£¬Ò²Î´½ûÓøæ°×ÅäÖÃÎļþ¡£¹ú·À²¿°µÊ¾ÔÚǨáãеÄÒÆ¶¯É豸ÖÎÀí½â¾ö¹æ»®£¬ÒÔ±ãÆëÈ«½ûÓö¨Î»·þÎñ£¬µ«´òËãÓÚ5Ô³õʵÏÖµÄǨáãÊÇ·ñÂäʵÈÔ²»Ë¬ÀÊ¡£Óë´Ëͬʱ£¬Â½¾üÈ´ÔÚÍÆ¶¯¸ü¿í·ºµÄ×Ô´øÉ豸Õþ²ß£¬Ê¹ÎÊÌâÔ½·¢¸´ÔÓ¡£


https://www.theregister.com/security/2026/05/28/troops-phones-leaked-location-data-to-foreign-adversaries/5248108


4. ¼ÎÄ껪ÓÊÂÖÔâÍøÂç¹¥»÷£¬½ü600Íò¿Í»§Êý¾Ýй¶


5ÔÂ28ÈÕ£¬¼ÎÄ껪ÓÊÂÖ¹«Ë¾½üÈÕ´«µÝÁËһ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬ÊÜÓ°Ïì×ÜÈËÊý¸ß´ï5,995,277ÈË¡£¾Ý¸Ã¹«Ë¾ÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬¹¥»÷ÕßÓÚ2026Äê4ÔÂ14ÈÕÀûÓÃÉç½»¹¤³Ì¼¿Á©³É¹¦ÈëÇÖÒ»ÃûÔ±¹¤ÕË»§£¬Ëæºó½Ó¼ûÄÚ²¿ÏµÍ³²¢ÇÔÈ¡ÁËÔ̺¬¿Í»§Êý¾ÝµÄÎļþ¡£¹«Ë¾IT°²È«ÍŶӵ±Ìì·¢ÏÖÒì³£»î¶¯ºóѸËÙ×èÖ¹ÈëÇÖ£¬²¢Á¢¼´ÓëµÚÈý·½°²È«×¨¼ÒºÏ×÷·¢Õ¹µ÷²é¡£µ÷²é֤ʵ£¬¹¥»÷Õß»ñÈ¡µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ£¬ÒÔ¼°»¤ÕպͼÝÊ»ÅÆÕÕºÅÂëµÈµ±¾ÖÉí·ÝÖ¤¼þÐÅÏ¢¡£¼ÎÄ껪ÓÚ2026Äê5ÔÂ27ÈÕÆðͷ֪ͨÊÜÓ°ÏìÓ×ÎÒ£¬²¢ÎªÇкÏǰÌáµÄÃÀ¹ú¿Í»§ÌṩΪÆÚÁ½ÄêµÄÃâ·ÑTransUnionÐÅÓþ¼à¿Ø·þÎñ¡£¹«Ë¾°µÊ¾£¬ÊÂÎñ²úÉúºóÒѸĽø°²È«ºÍ¼à¿ØÏµÍ³£¬²¢½«³ÖÐø¼ÓÇ¿Êý¾Ý±£»¤´ëÊ©£¬Í¬Ê±¶½´Ù¿Í»§Ç×êǹØ×¢ÒøÐÐÕË»§ºÍÐÅÓþ»ã±¨£¬Èç·¢ÏÖ¿ÉÒɻӦÁ¢¼´±¨¾¯¡£½ñÄê4Ô£¬³ÛÃûÍøÂç·¸×ï×éÖ¯ShinyHuntersÐû³Æ¶ÔÕâ´Î¹¥»÷¼°870Íò±Ê¼Í¼±»µÁÕÆ¹Ü¡£


https://securityaffairs.com/192833/uncategorized/carnival-data-breach-exposes-personal-data-of-nearly-6-million-customers.html


5. 2026ÄêÊÀ½ç±­ÁÚ½ü£¬FBIÖÒ¸æÐéαƱÎñÍøÕ¾¼¤Ôö


5ÔÂ28ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö½üÈÕ°ä²¼ÖÒ¸æ³Æ£¬ÔÚ2026ÄêÊÀ½ç±­¿ªÈüǰ£¬´óÁ¿ÐéÎ±ÍøÕ¾¼ÙÒâ¹ú¼Ê×ãÁª£¬ÒÔÏúÊÛ¼ÙÃÅÆ±ºÍÕдýÌײÍΪÃû£¬ÇÔÈ¡Ó×ÎÒ¼°²ÆÕþÐÅÏ¢¡£±¾½ìÊÀ½ç±­½«ÓÚ6ÔÂ11ÈÕÖÁ7ÔÂ19ÈÕÔÚÃÀ¹ú¡¢¼ÓÄôóºÍÄ«Î÷¸ç½øÐУ¬ÍøÂç·¸×ï·Ö×ÓÒÑΪ´Ë³ï±¸ÁËÊý°Ù¸ö´¹µöÍøÕ¾¡£ÕâЩÐéαÓòÃû·ÂÕÕ¹Ù·½fifa.com£¬Í¨¹ýÇá΢ƴд¸ü¸ÄÈçfiffa[.]com£¬»òʹÓÃ.org¡¢.xyz¡¢.live¡¢.saleµÈ´úÌæ¶¥¼¶ÓòÃû£¬ÒÔ¼°ÐéαÕÐÆ¸ÃÅ»§Èç¡°jobs-fifa[.]com¡±µÈ£¬ÓÕÆ­Óû§ÖмÆ¡£FBIÖ¸³ö£¬ºÜ¶àÚ²Æ­ÍøÕ¾»áÍøÂç½Ó¼ûÕßµÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¼°ÒøÐÐÖ§¸¶ÐÅÏ¢£¬ÕâЩÊý¾Ý¿ÉÓÃÓÚÉí·Ý͵ÇԺͽðÈÚÚ¿Æ­¡£ÍøÂ簲ȫ¹«Ë¾Bitdefender·¢ÏÖ£¬×Ô2ÔÂ·ÝÆð£¬Õë¶ÔÓ¢¹ú¡¢ÆÏÌÑÑÀ¡¢ÃÀ¹ú¡¢¼ÓÄôó¡¢Ä«Î÷¸çµÈ¶à¹úÓû§µÄڲƭ»î¶¯¼¤Ôö£¬Éæ¼°¼ÙðÉÌÆ·¡¢ÇòÒ¡¢Á÷ýÌå·þÎñµÈ¡£ÎªÔ®ÊÖÇòÃÔ¶ã±Ü·çÏÕ£¬FBI½¨Ò飺ÊÖ¶¯ÔÚä¯ÀÀÆ÷ÊäÈëfifa.com£¬Ô¤·ÀʹÓø¶·ÑËÑË÷¸æ°×»òÆôÓøæ°×À¹½ØÆ÷£»È·ÈÏÍøÖ·ÒÔ.com½áβ£»Ê¹ÓÃÊéÇ©½Ó¼û¹Ù·½Ò³Ã棻²»µã»÷˽ÐÅÖеĿÉÒÉÁ´½Ó£»Î´¾­ÑéÖ¤µÄÍøÕ¾¾ø²»ÊäÈëÃô¸ÐÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fifa-websites-running-world-cup-fraud-schemes/


6. ºÚ¿ÍÀûÓÃFortiClient·ì϶´«²¼EKZÇÔÃÜ·¨Ê½


5ÔÂ28ÈÕ£¬ºÚ¿ÍÔÚÀûÓÃFortiClientÆóÒµÖÎÀí·þÎñÆ÷ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2026-35616£©£¬´«²¼Ò»ÖÖÃûΪEKZµÄδ¹«¿ªÍ´´¦ÇÔÈ¡·¨Ê½¡£¹¥»÷Õß½«¶ñÒâÈí¼þ¼Ù×°³ÉFortinet¶Ëµã¸üУ¬²¢Í¨¹ýFortiClientÖÎÀíµÄVPN¾ç±¾¹¤×÷Á÷Ö´ÐС£¸Ã·ì϶ÊôÓÚ²»µ±½Ó¼û½ÚÔìȱµã£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý¾«ÐÄ»ú¹ØµÄÒªÇóÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£FortinetÓÚ4Ô³õÈ·ÈÏ·ì϶´æÔÚ£¬²¢°ä²¼ÁË7.4.5ºÍ7.4.6°æ±¾µÄÈȽ¨¸´·¨Ê½¡£±¾Ô³õ£¬Arctic Wolf¹«Ë¾·¢ÏÖ¹¥»÷ÕßÀûÓø÷ì϶´«²¼EKZ¶ñÒâÈí¼þ¡£ÈëÇÖʼÓÚÀÄÓö˵ãAPI£¬ÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÖ´ÐÐÖÎÀí²Ù×÷¡£¹¥»÷ÕßËæºóÅú¸ÄEMSÅäÖúÍVPNÕ½ÊõÒÔÖ´ÐжñÒâ¾ç±¾¡£ÖÕ¶ËÓëFortiGate·À»ðǽ³ÉÁ¢IPsecËí·ºó£¬ºÏ·¨µÄfortitray.exe¹ý³Ìͨ¹ýºÅÁîÌáÐÑ·ûÆô¶¯¶ñÒâÅú´¦Öþ籾£¬Ö´ÐÐbase64±àÂëµÄPowerShellÔØºÉ£¬ÏÂÔØ²¢ÔËÐмÙ×°³ÉFortinet²¹¶¡µÄ¶ñÒâÈí¼þ£¬ÔÙͨ¹ýHTTP½«Êý¾Ýй¶ÖÁ¹¥»÷Õß½ÚÔìµÄVPS¡£EKZÐÅÏ¢ÇÔÈ¡·¨Ê½Ö°ÄܵäÐÍ£¬Í¬Ê¹Øë¶ÔChromiumºÍFirefoxä¯ÀÀÆ÷£¬½«´æ´¢µÄÊý¾ÝÌáÈ¡µ½Îı¾Îļþ£¬Èƹý¼ÓÃÜÃÜÂë±£»¤£¬Ö¸±êÔ̺¬Í´´¦¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢µØÖ·¡¢µç»°ºÅÂëºÍcookie£¬¹¥»÷Õ߿ɽè´Ë½Ó¼ûÊܶà³É·ÖÈÏÖ¤±£»¤µÄÕË»§¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/