WEEKLY SELECTION

本周精选线报

过去七天内从公开信源中自动筛选的高优先级与热点变化,仍应以原始信源为准。

P1
慢雾被黑档案

Coinsbuy 遭攻击,损失 790 万美元

Coinsbuy(B2B 加密支付处理平台)关联的 Ethereum 和 TRON 热钱包于 2026 年 8 月 9 日约 13:00 UTC被盗,损失超 790 万美元。攻击者迅速通过交易所将部分资金洗入门罗币(XMR),ChangeNOW 协助冻结六位数资金;Coinsbuy 临时暂停充提后已恢复服务。

P1
BleepingComputer 安全新闻

COLDCARD安全审计网络钓鱼攻击安装远程访问工具

一场网络钓鱼活动正在利用用户对近期披露的COLDCARD钱包漏洞以及疑似价值$88.6 million的比特币盗窃事件的担忧,诱骗用户安装ScreenConnect远程访问软件。 [...]

P1
Halborn Web3 安全研究

Explained: The Coldcard Hack (July 2026)

Starting on July 30, 2026, the wallets of users of the Coldcard hardware wallet began being drained. The attackers took advantage of a bug in the cold wallet’s key-generation code, which allowed them to reconstruct private keys and steal a…

P1
BleepingComputer 安全新闻

Valve notifies Steam hardware customers of a data breach

Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]

P1
SecurityWeek 安全新闻

Corporate Data Stolen in Levi Strauss Cyberattack

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .

P1
CISA Known Exploited Vulnerabilities

CVE-2026-72898:Metabase SQL注入漏洞

Metabase存在SQL注入漏洞,未经身份验证的远程攻击者可向Metabase应用程序数据库注入任意SQL,从而可能获得该实例的管理员权限。攻击者随后可以更改应用程序配置、窃取连接数据库中存储的凭据、读取这些连接可访问的任何数据,并导出数据。必要行动:按照厂商说明采取缓解措施,并确保符合CISA BOD 26-04《关于根据风险确定安全更新优先级》的指导要求(参见Notes中的URL)以及CISA《取证分诊要求》(参见Notes中的URL)。对于云服务,遵循适用的BOD…

P1
CISA Known Exploited Vulnerabilities

CVE-2026-20349:Cisco Secure Firewall Adaptive Security Appliance (ASA) 和 Secure Firewall Threat Defense (FTD) 堆检查漏洞

Cisco Secure Firewall Adaptive Security Appliance (ASA) 和 Secure Firewall Threat Defense (FTD) 存在堆检查漏洞,未经身份验证的远程攻击者可能利用该漏洞导致设备意外重新加载,从而造成拒绝服务(DoS)状况。;所需行动:根据供应商说明采取缓解措施,确保遵守 CISA 的《BOD 26-04:根据风险确定安全更新优先级》(参见备注中的 URL)指南以及 CISA 的《取证分类要求》(参见…

P1
CISA Known Exploited Vulnerabilities

CVE-2026-68820:Microsoft Windows WinSock 辅助功能驱动程序释放后使用漏洞

Microsoft Windows WinSock 辅助功能驱动程序存在释放后使用漏洞,已获授权的攻击者可利用该漏洞在本地提升权限。;所需行动:根据供应商说明采取缓解措施,确保遵守 CISA 的《BOD 26-04:根据风险确定安全更新优先级》(参见备注中的 URL)指南以及 CISA 的《取证分类要求》(参见备注中的 URL)。对于云服务,遵循适用的 BOD 26-04 指南;如果无法采取缓解措施,则停止使用该产品。相关方负责评估各资产的互联网暴露情况,并确保遵守 BOD…

P1
蓝点网科技资讯

印度VPS服务器提供商HostDzire被勒索软件攻击 用户必须使用自己的备份恢复数据

#云计算 印度 VPS 服务器提供商 HostDzire 遭到勒索软件攻击,直接格式化磁盘重装系统和重建节点,所有客户数据灰飞烟灭。事实证明使用各类 VPS 服务器时日常做好数据备份是非常重要的,此前 CloudCone 被勒索软件攻击后也是直接重装系统。如果用户没有备份数据,潜在损失不可估量。查看全文:https://ourl.co/114215

P1
蓝点网科技资讯

慎用API中转站!有开发者使用Codex中转站被投毒 窃取开发者环境各类敏感信息

#人工智能 慎用 API 中转站!有开发者发现中转站投毒,在模型回复中夹带超长恶意命令用于窃取本地开发环境中的各类敏感信息。黑客通过 Shell 命令读取本地开发环境中的敏感信息,包括但不限于各类 API KEY、AWS 等云环境凭证、本机留存的各类 SSH 私钥和已知主机名单、Shell 历史等。查看全文:https://ourl.co/114270

P1
SecurityWeek 安全新闻

New Jersey, Alabama Join States Targeted in Water Cyberattacks

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .

P1
CISA Known Exploited Vulnerabilities

CVE-2026-63077:JetBrains TeamCity 不可信数据反序列化漏洞

JetBrains TeamCity 存在不可信数据反序列化漏洞,未经身份验证的远程攻击者可能通过代理轮询协议执行远程代码。;所需行动:按照供应商说明采取缓解措施,并确保遵守 CISA《根据风险确定安全更新优先级》(BOD 26-04,参见备注中的 URL)指南以及 CISA《取证分诊要求》(参见备注中的 URL)。对于云服务,请遵循适用的 BOD 26-04 指南;如果无法采取缓解措施,则停止使用该产品。相关方负责评估每项资产的互联网暴露情况,并确保遵守 BOD 26-0…

P1
SecurityWeek 安全新闻

Metabase 修复了被作为零日漏洞利用的安全漏洞

该安全缺陷允许未经身份验证的远程攻击者获得 Metabase 实例的管理员权限。文章《Metabase 修复了被作为零日漏洞利用的安全漏洞》最初发表于 SecurityWeek。

P1
CISA Known Exploited Vulnerabilities

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Required action…