🌍 国际网络安全每日情报 – 2026年03月22日
本文档由系统自动生成,汇总国际最新网络安全漏洞情报、安全新闻和技术解读。
内容策略:聚焦国际网络安全动态,涵盖The Hacker News、BleepingComputer、CISA等权威来源。
🌍 国际网络安全动态
📰 联邦调查局警告俄罗斯黑客在大规模网络钓鱼攻击中瞄准信号WhatsApp
来源:The Hacker News
全球领先网络安全新闻
与俄罗斯相关的网络钓鱼通过虚假的支持策略攻击数千个消息帐户,从而实现模拟和数据访问。
Original: Russian-linked phishing hits thousands of messaging accounts via fake support tactics, enabling impersonation and data access.
Original Title: FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
📰 Oracle关键补丁CVE-2026-21992在Identity Manager中启用未经身份验证的RCE
来源:The Hacker News
全球领先网络安全新闻
Oracle修复了通过HTTP启用未经身份验证的RCE的CVE-2026-21992 ( CVSS 9.8 )缺陷,存在整个系统受损的风险。
Original: Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.
Original Title: Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
📰 Trivy Supply Chain Attack在47 npm包装中触发自扩展的CanisterWorm
来源:The Hacker News
全球领先网络安全新闻
CanisterWorm通过基于ICP的C2感染28 npm软件包,实现跨开发人员系统的自我传播和持久后门访问。
Original: CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across developer systems.
Original Title: Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
📰 CISA标记Apple、Craft CMS、KEV中的Laravel Bug ,订单在2026年4月3日前修补
来源:The Hacker News
全球领先网络安全新闻
CISA向KEV添加了5个利用漏洞( CVSS最高可达10.0 ) ,并要求在2026年4月3日进行修补,以防止恶意软件和间谍攻击。
Original: CISA adds 5 exploited flaws (CVSS up to 10.0) to KEV, mandates April 3, 2026 patching to prevent malware and espionage attacks.
Original Title: CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
📰 Trivy Security Scanner GitHub操作被违反, 75个标签被劫持以窃取CI/CD机密
来源:The Hacker News
全球领先网络安全新闻
微妙的攻击力通过GitHub Actions推送了75个标签,暴露了CI/CD机密,实现了跨开发人员系统的数据窃取和持久化。
Original: Trivy attack force-pushed 75 tags via GitHub Actions, exposing CI/CD secrets, enabling data theft and persistence across developer systems.
Original Title: Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
📰 [CVE-2025-32432] Craft CMS Craft CMS – Craft CMS代码注入漏洞
来源:CISA KEV
CISA 已知被利用漏洞 | 添加日期:2026-03-20 | 修复期限:2026-04-03
Craft CMS包含一个代码注入漏洞,允许远程攻击者执行任意代码。
Original: Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Original Title: [CVE-2025-32432] Craft CMS Craft CMS – Craft CMS Code Injection Vulnerability
📰 [CVE-2025-54068] 拉拉维尔 Livewire – Laravel Livewire代码注入漏洞
来源:CISA KEV
CISA 已知被利用漏洞 | 添加日期:2026-03-20 | 修复期限:2026-04-03
Laravel Livewire包含一个代码注入漏洞,可能允许未经身份验证的攻击者在特定场景下实现远程命令执行。
Original: Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
Original Title: [CVE-2025-54068] Laravel Livewire – Laravel Livewire Code Injection Vulnerability
📰 [CVE-2025-43510] 苹果 多个分类 – Apple多产品不当锁定漏洞
来源:CISA KEV
CISA 已知被利用漏洞 | 添加日期:2026-03-20 | 修复期限:2026-04-03
Apple watchOS、iOS、iPadOS、macOS、visionOS和tvOS包含一个不正确的锁定漏洞,该漏洞可能允许恶意应用程序导致进程之间共享的内存发生意外更改。
Original: Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
Original Title: [CVE-2025-43510] Apple Multiple Products – Apple Multiple Products Improper Locking Vulnerability
📰 [CVE-2025-43520] 苹果 多个分类 – Apple多个产品经典缓冲区溢出漏洞
来源:CISA KEV
CISA 已知被利用漏洞 | 添加日期:2026-03-20 | 修复期限:2026-04-03
Apple watchOS、iOS、iPadOS、macOS、visionOS、tvOS和iPadOS包含一个经典的缓冲区溢出漏洞,该漏洞可能允许恶意应用程序导致意外的系统终止或写入内核内存。
Original: Apple watchOS, iOS, iPadOS, macOS, visionOS, tvOS, and iPadOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
Original Title: [CVE-2025-43520] Apple Multiple Products – Apple Multiple Products Classic Buffer Overflow Vulnerability
📰 [CVE-2025-31277] 苹果 多个分类 – Apple多个产品缓冲区溢出漏洞
来源:CISA KEV
CISA 已知被利用漏洞 | 添加日期:2026-03-20 | 修复期限:2026-04-03
Apple Safari、iOS、watchOS、visionOS、iPadOS、macOS和tvOS包含一个缓冲区溢出漏洞,该漏洞可能允许处理恶意制作的网络内容,从而导致内存损坏。
Original: Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
Original Title: [CVE-2025-31277] Apple Multiple Products – Apple Multiple Products Buffer Overflow Vulnerability
本文档自动生成于 2026-03-22 09:00:47 | 专注中国网络安全新闻

















暂无评论内容