<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FortiSIEM &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/fortisiem/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Thu, 14 Aug 2025 04:00:24 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>FortiSIEM &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fortinet旗下FortiSIEM驚爆CVSS 9.8分資安漏洞 多個版本受牽連</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/188235/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/188235/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Thu, 14 Aug 2025 03:59:07 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[FortiSIEM]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=188235</guid>

					<description><![CDATA[<p><img width="1449" height="1058" src="https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Fortinet" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet.jpg 1449w, https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet-300x219.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet-1024x748.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet-768x561.jpg 768w" sizes="(max-width: 1449px) 100vw, 1449px" title="Fortinet旗下FortiSIEM驚爆CVSS 9.8分資安漏洞 多個版本受牽連 1"></p>
<p>Fortinet指出其FortiSIEM產品中存在一項高風險漏洞，可能讓未經身分驗證的駭客，遠端執行任意指令並完全控制系統。<content><span style="font-weight: 400;">記者孫敬／編譯</span></p>
<p><span style="font-weight: 400;">全球資安大廠<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://www.technice.com.tw/?s=Fortinet" target="_blank" rel="noopener">Fortinet</a></span>近日向客戶發出<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-152" target="_blank" rel="noopener">警告</a>，指出其FortiSIEM產品中存在一項高風險漏洞，可能讓未經身分驗證的駭客，遠端執行任意指令並完全控制系統。這項漏洞編號為CVE-2025-25256，CVSS評分高達9.8分，且Fortinet已證實有「實際的攻擊程式碼已在野外被發現」，顯示此漏洞已遭到駭客利用。</span></p>
<p><b>延伸閱讀：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://www.technice.com.tw/techmanage/infosecurity/188023/" target="_blank" rel="noopener">Zoom Windows版本驚爆CVSS 9.6高風險漏洞 一點連結、檔案就中標</a></span></b></p>
<p>[caption id="attachment_188250" align="aligncenter" width="1449"]<img class="wp-image-188250 size-full" src="https://www.technice.com.tw/wp-content/uploads/2025/08/Fortinet.jpg" alt="" width="1449" height="1058" /> Fortinet的安全資訊及事件管理系統FortiSIEM，傳漏洞已被駭客利用。（圖／Fortinet）[/caption]</p>
<h2><b>駭客恐完全接管系統，Fortinet籲立即更新</b></h2>
<p><span style="font-weight: 400;">這項漏洞屬於「OS命令注入（OS-command-injection）」類型，影響FortiSIEM的多個版本（7.3.0-7.3.1、7.2.0-7.2.5、7.1.0-7.1.7、7.0.0-7.0.3，以及6.7.9以前版本）。駭客可藉由精心設計的CLI請求，在未經身分驗證的情況下，在作業系統上執行任意指令，進而完全接管整個系統。</span></p>
<p><span style="font-weight: 400;">Fortinet強烈建議所有受影響的客戶立即升級至已修復的版本。同時，原廠也提供了一項暫時性的應急措施，限制對phMonitor連接埠（7900）的存取，以降低被攻擊的風險。</span></p>
<h2><b>先暴力破解、再轉變目標？駭客行動模式受關注</b></h2>
<p><span style="font-weight: 400;">在Fortinet發布這項漏洞警告之前，資安情報公司GreyNoise曾觀察到一波針對Fortinet SSL VPN的「暴力破解（Brute-Force）」攻擊流量激增，並創下數月來單日最高紀錄。雖然Fortinet在週二發布漏洞公告後，針對VPN產品的暴力破解再度激增，但未達8月3日的高峰。</span></p>
<p><span style="font-weight: 400;">GreyNoise分析指出，在兩週內，駭客攻擊呈現「兩種截然不同的模式」。第一波攻擊是長期、穩定的流量，第二波攻擊則是在8月5日突然且集中的爆發。資安分析師在深入調查後發現，駭客的行為模式有所轉變：</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">8月3日：攻擊主要針對FortiOS。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">8月5日：攻擊目標轉向FortiManager，這顯示駭客可能使用了同樣的工具或基礎設施，但已將攻擊焦點轉移到Fortinet的其他服務上。</span></li>
</ul>
<p><span style="font-weight: 400;">儘管GreyNoise無法證實這波攻擊與FortiSIEM的新漏洞有直接關聯，但專家強調，歷史研究顯示這類惡意掃描或暴力破解攻擊的激增，有時會在不久後伴隨著相關產品的漏洞出現。因此，兩事件在時間上的緊密性仍值得高度警惕。</span></p>
<p><span style="font-weight: 400;">資料來源：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://www.theregister.com/2025/08/13/fortinet_discloses_critical_bug/" target="_blank" rel="noopener">The Register</a></span></span></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/188235/">Fortinet旗下FortiSIEM驚爆CVSS 9.8分資安漏洞 多個版本受牽連</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/188235/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
