資安週報Security Weekly 攻擊手法通報 × 資安工具Advisories × Tooling

2026-W38

邊界設備與開發工具鏈同期失守,攻擊自動化跨過門檻:本期合併四週,44 則漏洞列入 KEVEdge devices and developer toolchains breached in the same window, as attack automation crosses a threshold: four weeks merged, 44 additions to KEV

2026-W38 · 2026年8月20日Aug 20, 2026 – 2026年9月16日Sep 16, 2026 · 7 則通報7 advisories

本期涵蓋 8 月 20 日至 9 月 16 日共四週。這段期間 CISA 新增 44 則已遭利用漏洞,密度遠高於前幾期,主要集中在兩塊:網路邊界設備(Cisco 郵件閘道與防火牆管理中心、Citrix、Fortinet、SonicWall、MikroTik)與開發工具鏈(JFrog Artifactory、GitLab、Gitea)。

兩者的共同點值得注意:它們都不是端點,而是所有流量或所有程式碼的必經之處。攻擊者選擇打這些位置,是因為一次得手的覆蓋面遠大於逐台入侵。Cisco FMC 的案例最具代表性——三個不同的威脅叢集同時在利用同一個漏洞,其中一個直接部署了勒索軟體。

另一項變化更值得長期關注:攻擊自動化跨過了實用門檻。Anthropic 揭露俄國國家級行為者用其模型在惡意程式被偵測後快速重建,以及多個行為者將模型用於自動化漏洞利用與資料竊取。這不是「AI 可能被濫用」的推測,是已發生事件的事後揭露。

對台灣讀者有兩則直接相關:中國駭客組織 Red Heron 針對 Gitea 漏洞的攻擊行動中,單獨建立了 477 個台灣系統的資料集;MikroTik 路由器全球 260 萬台暴露於網際網路,台灣近 1.9 萬台。

This issue covers four weeks, 20 August to 16 September. CISA added 44 exploited vulnerabilities in that window — far denser than recent issues — concentrated in two areas: network edge devices (Cisco email gateway and firewall management centre, Citrix, Fortinet, SonicWall, MikroTik) and developer toolchains (JFrog Artifactory, GitLab, Gitea).

What they share is worth noting: neither is an endpoint — both are chokepoints through which all traffic, or all code, must pass. Attackers choose these positions because one success covers far more ground than compromising machines one at a time. The Cisco FMC case is the clearest example: three distinct threat clusters exploiting the same flaw simultaneously, one of them deploying ransomware outright.

A second shift deserves longer attention: attack automation has crossed into practical use. Anthropic disclosed that a Russian state-sponsored actor used its models to rebuild malware quickly after detection, and that several actors applied them to automating exploitation and data theft. This is not speculation about AI misuse; it is after-the-fact disclosure of incidents that happened.

Two items bear directly on readers in Taiwan: in the Red Heron campaign against Gitea, the operators maintained a separate dataset of 477 Taiwan-based systems; and of the 2.6 million MikroTik routers exposed to the internet worldwide, close to 19,000 are in Taiwan.

攻擊手法與漏洞通報Advisories

重大Critical CVE-2026-76461 已遭利用・已列入 KEVExploited · In KEV CVSS 9.8

Cisco 郵件閘道 SQL 注入遭實際利用,未驗證攻擊者可取得 root 權限執行指令Cisco email gateway SQL injection exploited in the wild, giving unauthenticated attackers root command execution

受影響Affected Cisco Secure Email Gateway 的 AsyncOS 軟體;請依原廠公告確認受影響版本AsyncOS Software for Cisco Secure Email Gateway — check the vendor advisory for affected releases

發生什麼事What happened

Cisco 警告 Secure Email Gateway 的 AsyncOS 軟體存在重大漏洞並已遭實際利用。編號 CVE-2026-76461,CVSS 9.8,成因是郵件解析邏輯的驗證不足,未經驗證的遠端攻擊者可藉此在底層作業系統上以 root 權限執行任意指令。CISA 於 9 月 14 日將其列入 KEV。

Cisco warned that a critical flaw in AsyncOS Software for Cisco Secure Email Gateway is under active exploitation. Tracked as CVE-2026-76461 with a CVSS score of 9.8, it stems from insufficient validation in the email parsing logic, allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CISA added it to KEV on 14 September.

攻擊手法Attack technique

漏洞位於郵件解析環節,這一點決定了它的嚴重性。郵件閘道的職責就是收下並剖析每一封進來的信——攻擊者不需要誘使任何人點擊、不需要有效憑證,只要把構造過的郵件寄到你的網域,設備在處理它的過程中就被攻陷。

這是一條零點擊的路徑。而且郵件閘道位於網路邊界、通常對全網際網路開放、又持有解密後的郵件內容與寄送憑證。拿下它等同同時取得郵件內容的存取權與一個內網立足點。

The flaw sits in email parsing, and that placement determines its severity. A mail gateway's entire job is to accept and parse every message that arrives — so an attacker needs no click, no valid credentials, only to send a crafted message to your domain. The appliance is compromised in the course of doing its job.

This is a zero-click path. And a mail gateway sits at the network edge, is typically reachable from the whole internet, and holds decrypted message content plus sending credentials. Owning it grants both access to mail and a foothold inside.

影響範圍Who is affected

使用 Cisco Secure Email Gateway 的組織。因為攻擊來自「收信」這個無法關閉的功能,沒有「暫時停用該功能」這個緩解選項,只能修補或下線。

Any organisation running Cisco Secure Email Gateway. Because the attack arrives through receiving mail — a function you cannot switch off — there is no "temporarily disable the feature" mitigation. Patch or take it offline.

該怎麼做What to do

1. 立即套用 Cisco 的修補程式。這是本期優先序最高的項目。
2. 假設已遭入侵並盤查:檢視設備上的異常程序、非預期的設定變更、新增的帳號、對外連線紀錄。
3. 輪換該設備持有的所有憑證,包含與郵件服務、目錄服務、日誌平台之間的認證資訊。
4. 檢視郵件流紀錄,確認有無非預期的轉寄規則或郵件被外送到不明位址。
5. 若設備管理介面對外開放,一併收回到管理網段。

1. Apply Cisco's patch immediately. This is the highest-priority item in this issue.
2. Assume compromise and hunt: anomalous processes on the appliance, unexpected configuration changes, new accounts, outbound connections.
3. Rotate every credential the appliance holds, including authentication to mail services, directory services, and logging platforms.
4. Review mail flow logs for unexpected forwarding rules or messages sent to unfamiliar destinations.
5. If the management interface is internet-facing, pull it back to a management segment.

偵測建議Detection

郵件閘道遭入侵後,最可靠的訊號在設備的對外連線而非郵件內容——正常運作的閘道對外連線目的地相當固定(郵件伺服器、更新來源、信譽查詢服務)。出現其他目的地就值得追查。設備本機日誌在被取得 root 之後不可盡信,請以網路側紀錄比對。

After a gateway compromise, the most reliable signal is the appliance's own outbound connections rather than message content — a healthy gateway talks to a fairly fixed set of destinations (mail servers, update sources, reputation services). Anything else warrants investigation. Do not rely solely on on-box logs once root has been obtained; corroborate from the network side.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 邊界設備Edge device
  • 零點擊Zero-click
  • 立即處理Act now
重大Critical CVE-2026-20079 已遭利用・已列入 KEVExploited · In KEV CVSS 10.0

Cisco 防火牆管理中心認證繞過:三個威脅叢集在利用,其一部署 Qilin 勒索軟體Cisco firewall management centre authentication bypass: three threat clusters exploiting it, one deploying Qilin ransomware

受影響Affected Cisco Secure Firewall Management Center(FMC)軟體,以及 Security Cloud Control 的防火牆管理功能Cisco Secure Firewall Management Center (FMC) software and Security Cloud Control firewall management

發生什麼事What happened

Cisco 揭露有三個不同的威脅叢集正在利用兩個已修補的 FMC 漏洞,這些叢集分別關聯到勒索軟體與國家級攻擊行動。其中 CVE-2026-20079(CVSS 10.0)是 FMC 網頁介面的認證繞過漏洞,未經驗證的遠端攻擊者可藉此繞過驗證。

攻擊活動中已觀察到竊取憑證與部署 Qilin 勒索軟體。CISA 已將相關漏洞列入 KEV。

Cisco disclosed that three distinct threat clusters — variously linked to ransomware and state-sponsored operations — are exploiting two recently patched FMC vulnerabilities. Among them, CVE-2026-20079 (CVSS 10.0) is an authentication bypass in the FMC web interface that lets an unauthenticated remote attacker bypass authentication.

Observed activity includes credential theft and deployment of Qilin ransomware. CISA has added the relevant flaws to KEV.

攻擊手法Attack technique

FMC 是管理整個防火牆機群的中控台。攻陷它的後果不只是多一台被入侵的主機:

- 可以改規則——攻擊者能為自己開一條進出通道,而且這條規則看起來是合法設定
- 握有憑證——FMC 需要與所有受管防火牆及目錄服務認證,這些憑證都在它身上
- 看得見拓撲——整個網路的分段設計、允許的流量、資產分布一覽無遺

三個獨立叢集同時利用同一個漏洞,是一個重要訊號:它代表利用方式已充分擴散,不再是單一行為者的專有能力。這種情況下「還沒被攻擊」通常只是還沒輪到你。

FMC is the console that manages an entire firewall fleet. Compromising it costs more than one more owned host:

- Rules can be changed — an attacker can open a path for themselves, and that rule looks like legitimate configuration
- Credentials are held there — FMC authenticates to every managed firewall and to directory services, so those credentials live on it
- Topology is visible — segmentation design, permitted flows, and asset distribution all in one view

Three independent clusters exploiting the same flaw is a meaningful signal: the technique has diffused well beyond any single actor. In that situation, "we have not been attacked" usually means your turn has not come.

影響範圍Who is affected

使用 Cisco Secure Firewall Management Center 或 Security Cloud Control 防火牆管理功能的組織。由於已有勒索軟體行為者參與,潛在後果包含營運中斷而不僅是資料外洩。

Organisations using Cisco Secure Firewall Management Center or Security Cloud Control firewall management. With ransomware actors involved, the potential outcome includes operational shutdown, not merely data exposure.

該怎麼做What to do

1. 立即套用修補程式(漏洞已修補,遭攻擊的是未更新的環境)。
2. 比對防火牆規則與您的變更紀錄。任何找不到對應工單的規則都要當成入侵跡證處理,這是本則最關鍵的一步。
3. 輪換 FMC 上的所有管理憑證,以及它用來認證受管防火牆與目錄服務的帳號。
4. 確認 FMC 網頁介面未對網際網路開放。管理平面不該從任意位置可及。
5. 檢查備份是否離線或不可變——已有勒索軟體行為者涉入,備份完整性直接決定復原能力。

1. Apply the patches now (fixes exist; the environments being hit are the unpatched ones).
2. Reconcile firewall rules against your change record. Any rule without a matching ticket should be treated as evidence of intrusion — this is the critical step here.
3. Rotate every administrative credential on FMC, plus the accounts it uses to authenticate to managed firewalls and directory services.
4. Confirm the FMC web interface is not internet-facing. A management plane should not be reachable from anywhere.
5. Verify backups are offline or immutable — with ransomware actors involved, backup integrity determines whether you can recover.

偵測建議Detection

把焦點放在設定變更的來源與時間:非管理時段的規則異動、來自非管理網段的登入、以及同一管理帳號在短時間內做出大量變更。這些訊號比在被完全控制的主機上找惡意檔案可靠。

Focus on the source and timing of configuration changes: rule edits outside maintenance windows, sign-ins from outside the management segment, and one administrative account making an unusual volume of changes quickly. These are more reliable than hunting for malicious files on a host the attacker fully controls.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 管理平面Management plane
  • 勒索軟體Ransomware
  • 多方利用Multiple actors
重大Critical CVE-2026-42016 / CVE-2026-42018 已遭利用・已列入 KEVExploited · In KEV CVSS 8.1

JFrog Artifactory 漏洞串接遭利用,攻擊者取得管理權並植入後門Chained JFrog Artifactory flaws exploited to seize admin control and plant backdoors

受影響Affected 自架的 JFrog Artifactory 伺服器(未套用修補者)Self-hosted JFrog Artifactory servers that had not applied the fixes

發生什麼事What happened

資安公司 Wiz 指出,攻擊者串接兩個 JFrog Artifactory 漏洞取得自架伺服器的管理員控制權並植入後門,觀察到的攻擊期間為 8 月 15 日至 9 月 8 日。JFrog 在這之前即已修補兩者,因此受害的是未更新的伺服器。

兩個漏洞分別是 CVE-2026-42016(CVSS 8.1,授權檢查不當——只驗證權杖的簽章與簽發者,未驗證其適用範圍,導致權限提升)與 CVE-2026-42018(驗證不當——在匿名存取已停用的情況下,仍可能將內部匿名使用者權杖回傳給未經驗證的呼叫端)。CISA 於 9 月 11 日將多個 Artifactory 漏洞列入 KEV。

Security firm Wiz reported that attackers chained two JFrog Artifactory flaws to take administrator control of self-hosted servers and plant backdoors, with observed activity running from 15 August to 8 September. JFrog had fixed both beforehand, so the servers being hit were the un-updated ones.

The two are CVE-2026-42016 (CVSS 8.1, incorrect authorization — validating a token's signature and issuer but not its scope, leading to privilege escalation) and CVE-2026-42018 (improper authentication — returning an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled). CISA added several Artifactory flaws to KEV on 11 September.

攻擊手法Attack technique

Artifactory 是建置流程拉取相依套件的來源。這個位置決定了它的價值:攻擊者植入後門之後,不必再攻擊任何一個開發者或 CI 節點——下游所有的建置都會主動來取用被動過手腳的產物。

這也是為什麼「權杖只驗簽章不驗範圍」這種看似技術性的疏失後果如此嚴重。權杖範圍(scope)存在的目的,就是讓一把低權限的鑰匙不能拿去開高權限的門;驗證漏掉這一步,等於整套權限模型失效。

本則與本站先前報導的 npm 蠕蟲屬於同一類問題的不同層次:那一次污染的是公開套件倉庫,這一次是企業自己的內部倉庫。後者更難察覺,因為它本來就是你信任的來源。

Artifactory is where build pipelines pull dependencies from. That position defines its value: once a backdoor is planted, the attacker need not touch a single developer machine or CI runner — every downstream build comes and collects the tampered artefact on its own.

It is also why a seemingly technical oversight — validating a token's signature but not its scope — carries such weight. Scope exists precisely so a low-privilege key cannot open a high-privilege door; skipping that check voids the entire permission model.

This is the same class of problem as the npm worm covered earlier on this site, one layer in: that campaign poisoned a public registry, this one poisons an organisation's own internal repository. The latter is harder to notice, because it is a source you already trust.

影響範圍Who is affected

自架 Artifactory 且未在 8 月中前完成更新的組織。影響不限於伺服器本身——若後門確實植入,凡是在該期間從這台伺服器取用過產物的建置,都需要重新檢視。

Organisations self-hosting Artifactory that had not updated by mid-August. The impact is not confined to the server — if a backdoor was planted, every build that pulled artefacts from it during that window needs review.

該怎麼做What to do

1. 確認 Artifactory 已更新至修補版本。
2. 稽核管理員帳號與存取權杖:有無非預期的新增帳號、權限變更、或您不認得的權杖。
3. 比對 8 月 15 日至 9 月 8 日期間的產物:檢查該期間上傳或變更的產物與其雜湊值,特別是內部套件。
4. 輪換所有存取權杖,包含 CI 使用的服務帳號。
5. 檢視同期間的建置產出,若無法排除污染可能,重新建置比事後追查更快。
6. 中長期:對內部產物導入簽章驗證,讓建置流程能自行辨識未經授權的變更。

1. Confirm Artifactory is updated to a fixed release.
2. Audit administrator accounts and access tokens: unexpected new accounts, permission changes, or tokens you do not recognise.
3. Compare artefacts from 15 August to 8 September: check what was uploaded or modified in that window and verify hashes, internal packages especially.
4. Rotate every access token, including CI service accounts.
5. Review builds produced in the same period; where contamination cannot be excluded, rebuilding is faster than forensic tracing.
6. Longer term: sign internal artefacts so pipelines can detect unauthorised changes themselves.

偵測建議Detection

在 Artifactory 的存取紀錄中尋找匿名或低權限主體成功執行了管理操作的事件——這正是權杖範圍未驗證所產生的痕跡。另外檢查產物的上傳來源 IP 是否都落在預期的 CI 網段內。

In Artifactory's access logs, look for anonymous or low-privilege principals successfully performing administrative operations — the fingerprint left by unvalidated token scope. Also check that artefact upload source IPs all fall within your expected CI ranges.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 供應鏈攻擊Supply chain
  • 開發工具鏈Developer toolchain
  • 權限提升Privilege escalation
重大Critical CVE-2026-60004 已遭利用・已列入 KEVExploited · In KEV

Gitea 重大漏洞遭中國駭客 Red Heron 利用,台灣系統被單獨建檔鎖定Gitea flaw exploited by China-linked Red Heron, with Taiwanese systems catalogued as a separate target set

受影響Affected 對網際網路開放且未更新的 Gitea 執行個體。Gitea 開發團隊已於 7 月底修補Internet-facing Gitea instances that have not been updated. The Gitea team patched it in late July

發生什麼事What happened

Acronis 威脅研究團隊(TRU)指出,疑似中國背景的威脅行為者 Red Heron 迅速利用 Gitea 的重大漏洞 CVE-2026-60004 入侵對外開放的執行個體,發動跨國攻擊行動。

規模數據值得注意:Red Heron 掃描了七個國家共 1,386 個 Gitea 執行個體,並另外維護一份 477 個台灣系統的獨立資料集,最終在六個國家入侵了 13 個組織。

時間軸是典型的「修補已釋出但未套用」:Gitea 於 7 月底修補,一個月後 CISA 警告該漏洞遭積極利用,而實際攻擊在 PoC 公開後不久即展開。

Acronis Threat Research Unit (TRU) attributed rapid exploitation of the critical Gitea flaw CVE-2026-60004 to Red Heron, a suspected Chinese threat actor, compromising internet-facing instances in a multi-national campaign.

The scale figures matter: Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems, ultimately compromising 13 organisations across six countries.

The timeline is the familiar "patch shipped, patch not applied": Gitea fixed it in late July, CISA warned of active exploitation a month later, and the attacks began shortly after proof-of-concept code became public.

攻擊手法Attack technique

「另外維護一份 477 個台灣系統的獨立資料集」這句話值得停下來看。它代表的不是隨機掃描後恰好打到台灣,而是針對台灣的目標篩選與資源配置——攻擊者投入了額外成本來建立這份清單。

自架 Git 服務為什麼是高價值目標?因為它同時裝著三樣東西:原始碼(可用於尋找其他漏洞)、CI/CD 的認證資訊(通往正式環境)、以及歷史提交(常含誤commit 的金鑰)。對情報導向的行為者而言,這比單純的資料外洩有價值得多。

這也是本期第三則與開發工具鏈相關的通報。前兩則(Artifactory、GitLab)加上這一則,共同顯示的趨勢是:開發基礎設施已從「內部工具」變成第一線的攻擊面,但多數組織對它的防護投入仍停留在內部工具的水準。

The phrase "maintained a separate dataset of 477 Taiwan-based systems" is worth pausing on. It does not describe random scanning that happened to hit Taiwan; it describes deliberate target selection and resource allocation — the operators spent extra effort building that list.

Why is a self-hosted Git service such a valuable target? Because it holds three things at once: source code (useful for finding further vulnerabilities), CI/CD credentials (a route into production), and commit history (frequently containing accidentally committed keys). For an intelligence-driven actor that is worth considerably more than a plain data breach.

This is also the third developer-toolchain advisory in this issue. Together with Artifactory and GitLab, the trend is clear: development infrastructure has moved from "internal tooling" to front-line attack surface, while most organisations still protect it at internal-tooling levels.

影響範圍Who is affected

自架 Gitea 且對外開放的組織。台灣的組織應特別檢視——攻擊者已明確將台灣系統列為獨立目標集。

Organisations self-hosting internet-facing Gitea. Those in Taiwan should look particularly closely — the operators explicitly treated Taiwanese systems as a distinct target set.

該怎麼做What to do

1. 立即更新 Gitea 至修補版本。
2. 評估是否真的需要對網際網路開放。多數自架 Git 服務只有內部人員使用,移到 VPN 之後即可消除這整條攻擊路徑。
3. 若曾對外開放:檢視存取紀錄與 webhook 設定,尋找非預期的複製(clone)行為與新增的部署金鑰。
4. 輪換儲存庫中的所有 CI/CD 憑證與部署金鑰,並掃描歷史提交中是否有外洩的密鑰。
5. 檢查有無非預期的新增使用者或權限異動。

1. Update Gitea to a fixed release now.
2. Assess whether internet exposure is actually required. Most self-hosted Git services serve internal users only; moving behind a VPN removes this entire attack path.
3. If it was exposed: review access logs and webhook configuration for unexpected clone activity and newly added deploy keys.
4. Rotate all CI/CD credentials and deploy keys held in repositories, and scan commit history for leaked secrets.
5. Check for unexpected new users or permission changes.

偵測建議Detection

在存取紀錄中尋找單一來源在短時間內複製大量儲存庫的行為——這是資料竊取階段的明確特徵,與正常開發者的使用模式差異極大。另外留意非上班時段、來自境外位址的驗證成功事件。

In access logs, look for one source cloning many repositories in a short window — a clear signature of the collection phase, and very unlike normal developer behaviour. Also watch for successful authentications outside working hours from foreign addresses.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 台灣相關Taiwan-relevant
  • 開發工具鏈Developer toolchain
  • APTAPT
高High CVE-2026-67277 / CVE-2026-86060 已遭利用・已列入 KEVExploited · In KEV

MikroTik RouterOS 兩個漏洞遭利用,全球 260 萬台暴露、台灣近 1.9 萬台Two exploited MikroTik RouterOS flaws, with 2.6 million routers exposed worldwide and nearly 19,000 in Taiwan

受影響Affected MikroTik RouterOS;依 Shadowserver 觀測,全球約 260 萬台暴露於網際網路,台灣近 1.9 萬台MikroTik RouterOS; per Shadowserver, roughly 2.6 million are exposed to the internet worldwide, close to 19,000 of them in Taiwan

發生什麼事What happened

波蘭電腦緊急應變團隊 CERT Polska 於 9 月 5 日警告 RouterOS 存在多個漏洞且部分已遭利用;CISA 於 9 月 10 日將其中兩個列入 KEV:

- CVE-2026-67277——btest 服務缺少關鍵功能的驗證,可導致核心記憶體洩漏與阻斷服務
- CVE-2026-86060——指令參數分隔符號處理不當,攻擊者可變更 RouterOS 的信任政策遮罩,藉此提升權限

Shadowserver 的掃描顯示全球約 260 萬台 MikroTik 路由器暴露於網際網路,台灣約有 1.9 萬台。

CERT Polska warned on 5 September that RouterOS contains multiple vulnerabilities, some already exploited; CISA added two to KEV on 10 September:

- CVE-2026-67277 — missing authentication for a critical function in the btest service, allowing kernel memory disclosure and denial of service
- CVE-2026-86060 — improper neutralisation of argument delimiters in a command, letting an attacker alter the trusted RouterOS policy mask and escalate privileges

Shadowserver scanning puts roughly 2.6 million MikroTik routers on the public internet, about 19,000 of them in Taiwan.

攻擊手法Attack technique

這一則的重點不在漏洞本身的技術細節,而在暴露規模。260 萬台是一個會改變風險計算的數字——它足以支撐大規模自動化利用,也足以組成具規模的殭屍網路或代理節點網路。

MikroTik 設備常見於中小企業、電信商的客戶端設備、以及基礎建設的邊緣。這類設備的共同問題是:部署後就沒有人再管。沒有更新機制、沒有納入資產盤點、管理介面常常直接開在對外埠上——因為當初設定的人就是這樣才能遠端維護。

路由器被攻陷的後果被普遍低估。它不只是「一台設備壞掉」,而是攻擊者取得了網路流量的觀察與操縱位置:可改 DNS 設定把使用者導向假網站、可建立通往內網的通道、可作為攻擊其他目標的跳板讓來源看起來無害。

What matters here is not the technical detail of either flaw but the scale of exposure. 2.6 million is a number that changes the risk calculation — enough to sustain mass automated exploitation, and enough to assemble a substantial botnet or proxy network.

MikroTik devices are common in small businesses, as telco customer-premises equipment, and at infrastructure edges. What such devices share is that nobody looks after them after deployment. No update mechanism, absent from asset inventories, management interfaces often published on a public port — because that is how whoever set it up could maintain it remotely.

The consequence of a compromised router is widely underestimated. It is not "one broken device" but an attacker gaining a position to observe and manipulate traffic: change DNS settings to redirect users to fake sites, build a tunnel into the internal network, or use it to attack others from an innocuous-looking source.

影響範圍Who is affected

使用 MikroTik 設備的組織與個人。台灣的 1.9 萬台暴露設備意味著本地的受影響面相當可觀,且其中相當比例可能屬於缺乏專責 IT 的中小型組織。

Anyone running MikroTik equipment. The 19,000 exposed devices in Taiwan mean the local footprint is considerable, and a substantial share likely belongs to smaller organisations without dedicated IT.

該怎麼做What to do

1. 更新 RouterOS 至已修補版本。
2. 關閉不需要的服務,btest(頻寬測試)尤其應停用——這是本次漏洞之一的所在,而多數環境根本不需要它。
3. 把管理介面(WinBox、SSH、HTTP)從對外埠移除,改以 VPN 存取。這一步能消除絕大部分的曝險。
4. 檢視設備設定有無遭竄改:DNS 設定、防火牆規則、排程指令碼、使用者清單、以及是否有非預期的通道設定。
5. 若設備長期暴露且版本過舊,應假設已遭入侵:重置設定並重新建置,而非僅套用更新。

1. Update RouterOS to a fixed release.
2. Disable services you do not need, btest (bandwidth test) especially — it is where one of these flaws lives, and most environments never use it.
3. Take management interfaces (WinBox, SSH, HTTP) off public ports and reach them over VPN. This single step removes most of the exposure.
4. Review configuration for tampering: DNS settings, firewall rules, scheduled scripts, user list, and any unexpected tunnel configuration.
5. If a device has been exposed for a long time on an old release, assume compromise: reset and rebuild the configuration rather than merely updating.

偵測建議Detection

檢查路由器的 DNS 設定是否指向您指定以外的伺服器——這是最常見也最容易確認的竄改跡證。另外檢視排程指令碼(scheduler)與使用者清單,攻擊者常在此處建立持久化。

Check whether the router's DNS settings point anywhere other than the servers you specified — the most common and most easily verified sign of tampering. Also review scheduler scripts and the user list, where attackers commonly establish persistence.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 台灣相關Taiwan-relevant
  • 邊界設備Edge device
  • 大規模曝險Mass exposure
高High 已發生・事後揭露Occurred · Disclosed after the fact

AI 模型遭用於實際攻擊:國家級行為者用於偵測後重建惡意程式、自動化漏洞利用與資料竊取AI models used in real attacks: rebuilding malware after detection, automating exploitation and data theft

受影響Affected 此則非特定產品漏洞,而是攻擊方法論的變化,影響所有依賴「攻擊需要人力與時間」這項假設的防禦設計Not a product vulnerability but a shift in attacker methodology, affecting any defence that assumes attacks require human effort and time

發生什麼事What happened

Anthropic 於 9 月公布多起其模型遭濫用於網路攻擊的事件,時間橫跨 2025 年 12 月至 2026 年 8 月。該公司將這些行為者統稱為 GTG(Generative Threat Groups,生成式威脅群組),涵蓋國家級、財務動機的犯罪集團與商業行為者。

其中兩項具體揭露:

- 俄國國家級行為者(該公司稱為 GTG-20006) 建立了一套 AI 輔助工作流程,在惡意程式被偵測後快速重建以搶在偵測能力之前
- 多起事件中,模型被用於自動化漏洞利用與跨多個受害者的資料竊取

此外該公司另揭露一起事件:其模型的早期版本曾在實際環境中入侵第三方系統,為同類事件的第四起。

In September, Anthropic published several incidents in which its models were abused for cyber attacks, spanning December 2025 to August 2026. It groups the actors under the label GTG (Generative Threat Groups), covering state-sponsored operations, financially motivated criminals, and commercial actors.

Two specific disclosures:

- A Russian state-sponsored actor (which the company calls GTG-20006) built an AI-assisted workflow to rebuild malware quickly after detection, staying ahead of the detection curve
- Across several incidents, models were used to automate exploitation and data theft across multiple victims

The company separately disclosed an incident in which an early version of one of its models breached third-party systems in the real world — the fourth such case.

攻擊手法Attack technique

這一則的意義不在於「AI 可能被濫用」這個早已存在的論述,而在於它已經從假設變成事後報告。 差別在於防守方該如何調整預期。

最值得注意的是「偵測後重建」這個用法。傳統上,防守方寫出一條偵測規則之後,會有一段時間的優勢——攻擊者要重寫惡意程式、重新測試、重新部署,這需要人力與時間。當重建成本大幅下降,這段優勢窗口就跟著縮短。

這直接衝擊以特徵為基礎的防禦。單一樣本的雜湊值、特定字串、固定的程式碼結構——這些本來就是易變的指標,現在變得更易變。相對地,以行為為基礎的偵測(IOB)價值上升:攻擊者可以換掉程式碼,但要換掉「傾印 LSASS 記憶體」或「從 explorer.exe 生成 PowerShell」這些行為,需要改變整套攻擊流程,成本高得多。

另一個值得記錄的現象是外溢效應:OpenJS 基金會的 CVE 編號授權機構因AI 生成的漏洞通報大量增加,宣布將暫停一般作業近三週。防守側的人力也正被這波變化消耗。

The significance is not the long-standing argument that AI could be misused, but that it has moved from hypothesis to after-action report. The difference lies in what defenders should now expect.

The most notable technique is rebuilding after detection. Traditionally, writing a detection rule bought defenders a window — the attacker had to rewrite, retest, and redeploy, which took people and time. When the cost of rebuilding falls sharply, that window narrows with it.

This bears directly on signature-based defence. A sample's hash, a particular string, a fixed code structure — always fragile indicators, now more so. Behaviour-based detection (IOB) rises in relative value: an attacker can swap out code, but replacing behaviours like dumping LSASS memory or spawning PowerShell from explorer.exe means changing the whole workflow, at far greater cost.

One spillover effect is worth recording: the OpenJS Foundation's CVE Numbering Authority announced a near three-week suspension of routine operations because of a surge in AI-generated vulnerability reports. The defensive side's human capacity is being consumed by the same shift.

影響範圍Who is affected

所有組織,但影響方式是間接的:它改變的是防禦措施的有效期,而非新增一個待修補的項目。過度依賴特徵比對與 IOC 封鎖清單的環境受影響最深。

Every organisation, but indirectly: what changes is how long defensive measures stay effective, not the appearance of one more thing to patch. Environments leaning heavily on signature matching and IOC blocklists are most affected.

該怎麼做What to do

1. 重新檢視偵測規則的組成比例。若您的偵測絕大多數建立在檔案雜湊值與特定字串上,應逐步增加行為型規則的比重。
2. 投資在不易被規避的訊號:程序親子關係、對敏感資源的存取、身分驗證的異常模式、以及出站流量的規律性。
3. 縮短情資的更新週期,並確認閘道與端點防護確實在載入最新情資——這一點可用 BAS 類工具實際驗證,而非相信儀表板。
4. 若您的組織正在導入 AI agent,請一併檢視其權限範圍與工具呼叫紀錄。攻防兩側用的是同一類技術。
5. 不要據此恐慌採購。這則通報的正確結論是「行為型偵測的相對價值上升」,不是「需要買一個 AI 資安產品」。

1. Review the composition of your detection rules. If detection rests overwhelmingly on file hashes and specific strings, shift weight gradually toward behavioural rules.
2. Invest in signals that are hard to evade: process parent-child relationships, access to sensitive resources, anomalous authentication patterns, and outbound traffic regularity.
3. Shorten intelligence refresh cycles and verify that gateways and endpoint protection are genuinely loading current intelligence — validate this with BAS tooling rather than trusting a dashboard.
4. If your organisation is adopting AI agents, review their permission scope and tool-call logging at the same time. Both sides are using the same class of technology.
5. Do not let this drive a panic purchase. The correct conclusion is that behavioural detection has risen in relative value, not that you need to buy an AI security product.

偵測建議Detection

沒有針對此則的特定偵測規則——這正是它的性質。可行的檢視方式是回頭盤點:您現有的偵測規則中,有多少比例在攻擊者更換樣本之後仍然有效?這個比例就是您對這類變化的韌性。

There is no specific detection rule for this item — that is its nature. A practical exercise is to take stock: what proportion of your existing detections still fire after an attacker swaps out the sample? That proportion is your resilience to this shift.

本則涉及的術語Jargon in this advisory

  • 攻擊自動化Attack automation
  • 威脅情報Threat intelligence
  • 偵測工程Detection engineering
高High 攻擊進行中Campaign active

以 passkey 為題材的社交工程劫持 Microsoft 雲端帳號Passkey-themed social engineering used to hijack Microsoft cloud accounts

受影響Affected Microsoft 雲端環境的使用者;手法本身適用於任何支援 passkey 的服務Users of Microsoft cloud environments; the technique applies to any service supporting passkeys

發生什麼事What happened

微軟揭露兩起攻擊行動。其一是濫用第三方郵件遞送基礎設施,在 2026 年 8 月 3 日至 5 日間發出超過一百萬封冒充執行長的詐騙郵件。其二則是本則的重點:攻擊者以 passkey 為題材進行社交工程,藉此入侵雲端環境並竊取資料。

Microsoft disclosed two campaigns. One abused third-party email delivery infrastructure to send over a million scam messages between 3 and 5 August 2026, impersonating chief executives. The other is the focus here: attackers used passkey-themed social engineering to breach cloud environments and exfiltrate data.

攻擊手法Attack technique

passkey 常被介紹為「防釣魚的驗證方式」,這個說法是對的,但保護範圍比多數人以為的窄。

它保護的是登入的那一刻:因為簽章綁定來源網域,攻擊者架設的代理網域驗不過,代理式釣魚(AiTM)因此失效。這是真實且重要的進步。

但它不保護身分生命週期的其他環節,其中最脆弱的是註冊。如果攻擊者能誘使受害者在他控制的情境下新增一把 passkey,那把金鑰從此合法有效——後續的每一次登入都會完美通過驗證,因為它確實是一把有效的 passkey。密碼學沒有被破解,被繞過的是信任建立的流程。

這類攻擊的話術通常圍繞著「安全性升級」:宣稱公司要導入新的登入方式、請您依指示完成設定。受害者以為自己在強化安全,實際上是在為攻擊者註冊憑證。過程中的每一個技術步驟都是正確的,這使得傳統的釣魚辨識訓練完全失效。

Passkeys are routinely described as phishing-resistant authentication. That is true, but the protection is narrower than most people assume.

What they protect is the moment of sign-in: because the signature is bound to the origin domain, an attacker's proxy domain fails validation, and adversary-in-the-middle phishing stops working. That is a real and important advance.

What they do not protect is the rest of the identity lifecycle, and the weakest point is enrolment. If an attacker can induce a victim to add a passkey under their control, that key is legitimate from then on — every subsequent sign-in passes perfectly, because it genuinely is a valid passkey. The cryptography was never broken; what was bypassed is the process of establishing trust.

The pretext usually centres on a security upgrade: the company is rolling out a new sign-in method, please follow these steps. The victim believes they are improving their security while registering a credential for the attacker. Every technical step in the process is correct, which is exactly why traditional phishing-recognition training fails here.

影響範圍Who is affected

已導入或正在導入 passkey 的組織——特別是正在推行的階段,因為此時使用者本來就預期會收到關於新登入方式的指示,攻擊話術與真實通知難以區分。

Organisations that have adopted passkeys or are adopting them — the rollout period especially, because users then genuinely expect instructions about a new sign-in method, making the pretext hard to separate from real notices.

該怎麼做What to do

1. 對「新增驗證方式」這個動作本身要求既有的強驗證,並在完成後向使用者發出獨立通道的通知。這是本則最關鍵的一項控制。
2. 監控 passkey 註冊事件,特別留意來源位置或裝置與既有紀錄不符者。
3. 移除弱備援方式。若帳號仍保留簡訊或安全問題作為復原手段,passkey 的防護就被繞過了。
4. 推行期間主動告知使用者真實的通知管道:明確說明公司只會透過哪一個管道發出設定指示,其餘一律不予理會。
5. 使用者教育要更新:強調「任何要求您現在立刻新增登入方式的訊息都應先向 IT 查證」,而不是繼續教「檢查網址列」——在這類攻擊中網址列是正確的。

1. Require existing strong authentication for the act of adding an authentication method, and notify the user through an independent channel afterwards. This is the single most important control here.
2. Monitor passkey registration events, watching for source locations or devices that do not match existing records.
3. Remove weak fallbacks. If accounts still keep SMS or security questions for recovery, passkey protection is simply bypassed.
4. During rollout, tell users which channel is genuine: state explicitly that setup instructions come through one named channel and nothing else should be acted on.
5. Update training: emphasise that any message urging you to add a sign-in method right now should be verified with IT first, rather than continuing to teach address-bar checks — in this attack the address bar is correct.

偵測建議Detection

在身分提供者的稽核紀錄中,把驗證方式的新增事件當成獨立的監控項目——這類事件在正常情況下頻率很低、基數小,訊噪比極佳。特別關注「新增驗證方式」後緊接著出現大量資料存取的序列。

In identity provider audit logs, treat authentication-method registration events as a monitored category of their own — they are rare in normal operation, giving a small baseline and excellent signal-to-noise. Pay particular attention to a registration event followed closely by a burst of data access.

MITRE ATT&CK

本則涉及的術語Jargon in this advisory

  • 身分攻擊Identity attack
  • 社交工程Social engineering
  • 認知修正Corrects a misconception

本期工具介紹Tools

事件應變Incident response AGPL-3.0

Velociraptor

以查詢語言驅動的端點鑑識平台,能同時對上千台主機提問「你身上有沒有這個跡證」並在數分鐘內收到答案。A query-driven endpoint forensics platform that asks thousands of hosts "do you have this artefact" at once and answers within minutes.

  • 數位鑑識Digital forensics
  • 威脅獵捕Threat hunting
  • 藍隊Defensive
  • 跨平台Cross-platform

延伸閱讀Further reading