每日安全快讯 2026-07-28
以下为今日精选安全资讯,内容基于公开来源整理。建议结合自身资产范围判断影响。
一、安全新闻
1. PTC Windchill Vulnerability Exploited in Ransomware Campaign
来源:SecurityWeek时间:2026-07-27 21:19影响:疑似在野利用或KEV、勒索风险、高危漏洞
摘要:The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomwar...
原文链接:https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/
2. Hackers target US firms in FastJson RCE zero-day attacks
来源:BleepingComputer Security时间:2026-07-28 07:49影响:疑似在野利用或KEV、高危漏洞
摘要:Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
原文链接:https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
3. FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
来源:Dark Reading时间:2026-07-28 04:33影响:勒索风险、高危漏洞
摘要:An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
原文链接:https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
4. Ernst & Young data breach claimed by ShinyHunters extortion gang
来源:BleepingComputer Security时间:2026-07-27 23:12影响:供应链影响、数据泄露事件
摘要:The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems v...
原文链接:https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
5. Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
来源:SecurityWeek时间:2026-07-27 19:29影响:勒索风险、数据泄露事件
摘要:The Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared fi...
原文链接:https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/
二、漏洞与风险通告
1. USN-8619-1: Linux kernel (HWE) vulnerabilities
来源:Ubuntu Security Notices时间:2026-07-28 15:28影响:涉及CVE、高危漏洞、广泛使用产品
摘要:It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose...
原文链接:https://ubuntu.com/security/notices/USN-8619-1
2. USN-8620-1: Linux kernel vulnerabilities
来源:Ubuntu Security Notices时间:2026-07-28 15:31影响:涉及CVE、广泛使用产品
摘要:Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-boun...
原文链接:https://ubuntu.com/security/notices/USN-8620-1
3. CVE-2023-37465 / org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
来源:GitHub Security Advisories时间:2026-07-28 01:04影响:涉及CVE、高危漏洞
摘要:GitHub Advisory: GHSA-4j38-rw27-97gx;严重性:medium;### Impact It's possible to forge a request to delete a message. ### Patches The problem has been patched in version 2.0-rc-1 of...
原文链接:https://github.com/advisories/GHSA-4j38-rw27-97gx
4. n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
来源:The Hacker News时间:2026-07-27 21:05影响:涉及CVE
摘要:n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation...
原文链接:https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html
5. CVE-2026-64785 / swift-nio-http2: Missing CR/LF/NUL validation in header values
来源:GitHub Security Advisories时间:2026-07-25 05:52影响:涉及CVE、高危漏洞
摘要:GitHub Advisory: GHSA-q3g2-m552-3r9c;严重性:medium;## Summary SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters...
原文链接:https://github.com/advisories/GHSA-q3g2-m552-3r9c
声明:本文为公开信息整理,不复现攻击细节,不构成漏洞利用指导。
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……




还没有评论,来说两句吧...