2026年9月14日星期一

GitLab 多個漏洞

GitLab 多個漏洞

發佈日期: 2026年09月14日

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、遠端執行程式碼、跨網站指令碼、阻斷服務狀況及繞過保安限制。

 

注意:

CVE-2026-85706 正在被廣泛利用。在某些情況下,由於儲存庫提交 API 中路徑限制不當和身份驗證強制執行缺失,未經身份驗證的使用者可能會從 GitLab 伺服器讀取任意檔案。因此,此漏洞的風險等級被評為中等風險。


影響

  • 資料洩露
  • 繞過保安限制
  • 遠端執行程式碼
  • 跨網站指令碼
  • 阻斷服務

受影響之系統或技術

  • GitLab Community Edition (CE) 19.3.2, 19.2.6, 19.1.8 以前的版本
  • GitLab Enterprise Edition (EE) 19.3.2, 19.2.6, 19.1.8 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

GitLab Multiple Vulnerabilities

Release Date: 14 Sep 2026

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, cross-site scripting, denial of service condition and security restriction bypass on the targeted system.

 

Note: 

CVE-2026-85706 is being exploited in the wild. Under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. Hence, the risk level is rated as Medium risk.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Remote Code Execution
  • Cross-Site Scripting
  • Denial of Service

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 19.3.2, 19.2.6, 19.1.8
  • GitLab Enterprise Edition (EE) versions prior to 19.3.2, 19.2.6, 19.1.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

釣魚警報 - 提防利用信用卡資料進行未經授權交易的釣魚活動

釣魚警報 - 提防利用信用卡資料進行未經授權交易的釣魚活動

發佈日期: 2026年09月14日

網絡釣魚警告

現況及相關趨勢
mickmick.net 留意到近日有大量香港市民報稱信用卡遭未經授權使用,涉及網上購買電子產品。根據傳媒報道,警方於短時間內接獲超過700宗相關報案,涉及金額約1,470萬港元。部分受影響人士表示未曾進行相關交易,亦有個案指未有收到額外付款驗證通知。
目前事件成因仍有待相關機構調查。雖然暫未有證據顯示涉及特定銀行、支付平台或商戶系統遭入侵,但事件反映不法分子可能透過釣魚網站、釣魚短訊、惡意程式、帳戶入侵或過往資料外洩所得的支付資料進行未經授權交易。

攻擊分析
不法分子可能透過以下方式取得信用卡資料:

1. 釣魚網站
攻擊者建立偽冒銀行、支付平台、網購平台或物流服務網站,誘騙受害人輸入:

信用卡號碼
到期日
CVV安全碼
一次性密碼(OTP)
當相關資料被盜取後,便可能被用於未經授權交易。

2. 釣魚短訊及電郵
攻擊者透過偽冒銀行、商戶或速遞公司發送短訊及電郵,聲稱:

帳戶出現異常活動
付款失敗
需要更新付款資料
可獲退款或獎勵
從而誘使受害人提交支付資料。

3. 資料外洩事件
若受害人曾於第三方網站或網上服務輸入信用卡資料,而有關平台曾發生資料外洩事故,相關資料有機會被犯罪分子轉售或再次利用於未經授權交易。

4. 惡意程式及資訊竊取軟件
受感染裝置可能遭資訊竊取惡意程式收集:
瀏覽器已儲存的信用卡資料
自動填表資料
網上銀行憑證
電子錢包資訊
攻擊者其後可利用有關資料進行詐騙活動或未經授權交易。

可能造成的影響

受害人可能面臨以下風險:
信用卡被進行未經授權交易
個人資料被盜用
帳戶遭進一步入侵
財務損失
信貸及帳戶管理受到影響

企業及服務供應商亦可能因此面臨:
客戶信心受損
詐騙及退款爭議增加
品牌聲譽受影響
對公眾的安全建議:

定期檢查信用卡月結單及交易紀錄;啟用即時交易通知;留意任何未授權交易。
不要透過短訊、電郵或社交平台提交支付資料;僅於可信的網站進行付款。
提高警覺防範釣魚攻擊不要隨意點擊短訊或電郵中的連結。
核實訊息來源真偽;留意偽冒銀行、支付平台及商戶的可疑訊息。
發現可疑交易時立即處理立即凍結或暫停相關信用卡;聯絡發卡銀行;保留相關紀錄及通知;向警方報案。
網購時應只透過官方網站或可信賴的商戶進行交易,避免在來源不明或可信度不足的平台儲存信用卡資料。

避免在公眾 Wi‑Fi 環境下進行網上付款或輸入敏感支付資料。

對機構及企業建議:
加強監察異常交易活動;
定期檢視支付系統安全措施;
持續進行防釣魚及資訊保安教育;
建立資料外洩事故應變程序;
強化客戶身份驗證機制。

Phishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions

Phishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions

Phishing Alert

Current Status and Related Trends
mickmick.net has noted recent reports involving a large number of Hong Kong residents whose credit cards were allegedly used in unauthorised online purchases of electronic products. According to media reports, the Police received more than 700 related reports within a short period, involving approximately HK$14.7 million in losses. Some affected individuals indicated that they had not conducted the transactions in question, while others reported that no additional payment authentication notifications had been received.
The root cause of the incident remains under investigation by the relevant organisations. While there is currently no evidence suggesting that any particular bank, payment platform or merchant system has been compromised, the incident highlights how cybercriminals may exploit payment information obtained through phishing websites, phishing messages, malware, account compromise or previously leaked data to conduct unauthorised transactions.
Attack Analysis
Cybercriminals may obtain credit card information through the following methods:
1. Phishing Websites
Attackers create fraudulent websites impersonating banks, payment service providers, e-commerce platforms or logistics companies to trick victims into submitting:
Credit card numbers
Expiry dates
CVV security codes
One-time passwords (OTPs)
Once obtained, the stolen information may be used to conduct unauthorised transactions.
2. Phishing Messages and Emails
Attackers distribute fraudulent SMS messages and emails impersonating banks, merchants or courier services, claiming that:
Unusual account activity has been detected
A payment has failed
Payment information needs to be updated
A refund or reward is available
The objective is to persuade victims to disclose their payment information.
3. Data Breaches
If victims have previously entered their credit card information on third-party websites or online services that subsequently suffer a data breach, the exposed information may be sold or reused by cybercriminals to carry out unauthorised transactions.
4. Malware and Information-Stealing Software
Compromised devices may be infected with information-stealing malware capable of collecting:
Credit card details stored in web browsers
Autofill information
Online banking credentials
Digital wallet information
The stolen information may subsequently be used for fraudulent activities or unauthorised transactions.
Potential Impact
Individuals may face the following risks:
Unauthorised credit card transactions
Identity theft and misuse of personal information
Further account compromise
Financial losses
Adverse impacts on credit and account management
Businesses and service providers may also face:
Loss of customer confidence
An increase in fraud and chargeback disputes
Reputational damage
Recommendations for the Public
Regularly review credit card statements and transaction records; enable real-time transaction alerts; and pay attention to any unauthorised transactions.
Do not submit payment information via SMS messages, emails or social media platforms. Only make payments through trusted and legitimate websites.
Stay vigilant against phishing attacks and avoid clicking links contained in SMS messages or emails without verification.
Verify the authenticity of message senders and be alert to suspicious messages impersonating banks, payment platforms or merchants.
If any suspicious transaction is identified, immediately freeze or suspend the affected credit card, contact the card issuer, retain relevant records and notifications, and report the incident to the Police.
Only make purchases through official websites or trusted merchants, and avoid storing credit card information on unknown or less reputable platforms.
Avoid making online payments or entering sensitive payment information when connected to public Wi‑Fi networks.
Recommendations for Organisations and Businesses
Strengthen monitoring and detection of suspicious transaction activities.
Regularly review the security controls of payment systems.
Continue providing anti-phishing and cybersecurity awareness training.
Establish incident response procedures for data breach incidents.
Enhance customer authentication and verification mechanisms.

2026年9月10日星期四

MongoDB 多個漏洞

MongoDB 多個漏洞

發佈日期: 2026年09月10日

於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 阻斷服務
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 權限提升
  • 篡改
  • 仿冒

受影響之系統或技術

  • MongoDB Server 7.0.0 至 7.0.41 之前的版本
  • MongoDB Server 8.0.0 至 8.0.30 之前的版本

  • MongoDB Server 8.3.0 至 8.3.9 之前的版本


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

MongoDB Multiple Vulnerabilities

MongoDB Multiple Vulnerabilities

Release Date: 10 Sep 2026

Multiple vulnerabilities were identified in MongoDB. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, spoofing, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Elevation of Privilege
  • Data Manipulation
  • Spoofing

System / Technologies affected

  • MongoDB Server 7.0.0 versions prior to 7.0.41
  • MongoDB Server 8.0.0 versions prior to 8.0.30

  • MongoDB Server 8.3.0 versions prior to 8.3.9

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞

發佈日期: 2026年09月10日

於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、阻斷服務狀況、遠端執行任意程式碼及跨網站指令碼。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 跨網站指令碼
  • 權限提升

受影響之系統或技術

  • Cloud NGFW AWS 及 Azure 所有版本
  • GlobalProtect App 6.0 中 6.0.15 on macOS, Linux and Windows 之前的版本
  • GlobalProtect App 6.2 中 6.2.8-h14 on macOS and Windows 之前的版本
  • GlobalProtect App 6.3 中 6.3.3-h15 on macOS, Linux and Windows 之前的版本
  • GlobalProtect App iOS, Android, ChromeOS 所有版本
  • PAN-OS 10.2 中 10.2.7-h37 之前的版本
  • PAN-OS 10.2 中 10.2.10-h40 之前的版本
  • PAN-OS 10.2 中 10.2.13-h24 之前的版本
  • PAN-OS 10.2 中 10.2.16-h10 之前的版本
  • PAN-OS 10.2 中 10.2.18-h10 之前的版本
  • PAN-OS 11.1 中 11.1.4-h36 之前的版本
  • PAN-OS 11.1 中 11.1.6-h38 之前的版本
  • PAN-OS 11.1 中 11.1.7-h10 之前的版本
  • PAN-OS 11.1 中 11.1.10-h33 之前的版本
  • PAN-OS 11.1 中 11.1.13-h12 之前的版本
  • PAN-OS 11.1 中 11.1.16-h2 之前的版本
  • PAN-OS 11.2 中 11.2.4-h21 之前的版本
  • PAN-OS 11.2 中 11.2.7-h20 之前的版本
  • PAN-OS 11.2 中 11.2.10-h14 之前的版本
  • PAN-OS 11.2 中 11.2.13-h2 之前的版本
  • PAN-OS 12.1 中 12.1.4-h10 之前的版本
  • PAN-OS 12.1 中 12.1.7-h5 之前的版本
  • PAN-OS 12.1 中 12.1.10 之前的版本
  • PAN-OS 12.2 中 12.2.3 之前的版本
  • Prisma Access 10.2 中 10.2.10-h40 之前的版本
  • Prisma Access 11.2 中 11.2.7-h20 之前的版本
  • Prisma Access 12.1 中 12.1.7-h5 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab 多個漏洞

GitLab 多個漏洞 發佈日期: 2026年09月14日 於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、遠端執行程式碼、跨網站指令碼、阻斷服務狀況及繞過保安限制。   注意: CVE-2026-85706 正在被廣泛利用。在某些情況下,由...