最新消息公告
 公告單位  教學支援組
 公告日期  2026/9/21
 主  旨  【電算中心】2026年9月資安與防詐電子報:慎防假登入、AI冒充與惡意郵件[Computer Center] September 2026 Cybersecurity & Anti-Fraud Newsletter: Beware of Fake Logins, AI Impersonation & Malicious Emails
 內  容 




  • 1.Microsoft 365 釣魚攻擊可繞過 MFA




    • 摘要: BigBear 2.0 釣魚攻擊透過偽造 Microsoft 365 登入頁面,以 AiTM 技術攔截登入階段 Cookie,即使使用者完成 MFA,帳號仍可能遭接管。已有 40 多國、461 個組織成為攻擊目標,其中 258 個組織確認至少有帳號遭入侵。




    • 建議行動: 不要因已啟用 MFA 就降低警覺;收到要求重新登入 Microsoft 365 的郵件或連結時,應直接從官方網站或既有書籤登入,不要透過郵件連結登入。




    • 參考連結: iThome-BigBear 2.0 網釣攻擊鎖定 Microsoft 365

      https://www.ithome.com.tw/news/178815






  • 2.AI 協助冒充主管、偽造發票與郵件往來




    • 摘要: 微軟揭露攻擊者利用生成式 AI 提升商務郵件詐騙的真實度,冒充 CEO、CFO 等主管,搭配偽造發票、簽名與完整郵件對話,誘導財務人員付款。




    • 建議行動: 遇到匯款、帳戶變更、採購付款或異常緊急要求時,不應僅依 Email 判斷身分,應透過電話、校內分機或其他既有管道再次確認。




    • 參考連結: iThome-駭客濫用 AI 冒充高階主管進行詐騙

      https://www.ithome.com.tw/news/178954






  • 3.駭客冒充大學生,以實習、會議名義發動釣魚攻擊




    • 摘要: BlueMoon 攻擊活動中,駭客冒充大學生,以「尋找實習機會」、「參與會議」等理由寄送郵件,引誘受害者點擊惡意連結,並利用瀏覽器或 Windows 漏洞植入惡意程式。部分惡意擴充套件甚至偽裝成 Google Gemini AI 助理。




    • 建議行動: 收到陌生學生、實習申請、研討會或學術交流郵件時,應先確認寄件者與連結來源;不要隨意安裝郵件推薦的瀏覽器擴充套件或軟體。




    • 參考連結: iThome-BlueMoon 漏洞利用套件攻擊多國組織

      https://www.ithome.com.tw/news/178919






  • 4.Chrome 零時差漏洞已遭實際利用,應儘速更新




    • 摘要: Google 於 9 月推出 Chrome 153,一次修補 230 個安全漏洞,其中包含已遭實際攻擊利用的零時差漏洞。其他採用 Chromium 核心的瀏覽器也可能受到相關影響。




    • 建議行動: 定期更新 Chrome、Edge 等瀏覽器;看到「重新啟動以完成更新」通知時,應儘速完成更新,不要長期延後。




    • 參考連結: iThome-Google 推出 Chrome 153,修補 230 個漏洞

      https://www.ithome.com.tw/news/178795






  • 5.假贈品、假名人與假付款頁持續大量出現




    • 摘要: 數位發展部統計 9 月上旬一週即確認超過 2.2 萬件詐騙訊息,常見手法包括「免費手機」、「留言抽獎」、「明星周邊」等誘因,引導民眾點擊假網站、提供個資或付款。




    • 建議行動: 對免費贈品、限時優惠、抽獎及要求立即付款的訊息保持警覺;不要透過陌生連結輸入帳號、信用卡或個人資料。




    • 參考連結: 數位發展部-網路詐騙通報查詢網週快訊

      https://moda.gov.tw/ADI/news/latest-news/20644








 






  • 1. Microsoft 365 Phishing Can Bypass MFA

    • Summary: BigBear 2.0 uses fake Microsoft 365 sign-in pages and AiTM techniques to steal session cookies, allowing account takeover even after MFA. More than 461 organizations in 40+ countries were targeted, with 258 confirmed compromised.

    • Action: Do not trust login links just because MFA is enabled. Open Microsoft 365 from the official site or a saved bookmark instead of email links.

    • Reference: iThome


  • 2. AI Helps Impersonate Executives and Fake Invoices

    • Summary: Microsoft reported scams using generative AI to imitate executives, create fake invoices, signatures, and realistic email threads, then pressure finance staff to make payments.

    • Action: Verify payment, account-change, procurement, or urgent requests through a second channel such as phone or an internal extension.

    • Reference: iThome


  • 3. Attackers Impersonate Students in Internship and Meeting Emails

    • Summary: BlueMoon campaigns impersonated university students seeking internships or meetings. Victims were lured to malicious links exploiting browser or Windows flaws; some extensions even posed as Google Gemini tools.

    • Action: Verify unfamiliar student, internship, conference, or academic emails before opening links or installing browser extensions or software.

    • Reference: iThome


  • 4. Chrome Zero-Day Exploited in the Wild

    • Summary: Google released Chrome 153 in September with fixes for 230 security flaws, including a zero-day already exploited in attacks. Other Chromium-based browsers may also be affected.

    • Action: Keep Chrome, Edge, and other browsers updated and restart promptly when an update requires it.

    • Reference: iThome


  • 5. Fake Giveaways and Payment Pages Remain Widespread

    • Summary: Taiwan is Ministry of Digital Affairs confirmed over 22,000 scam messages in one week in early September. Common lures included free phones, prize draws, celebrity merchandise, and fake payment pages.

    • Action: Be cautious with giveaways, urgent offers, and payment requests. Do not enter account, card, or personal information through unfamiliar links.

    • Reference: MODA




 附  件  : 無附件
 相關連結  : https://cc.tcu.edu.tw/?p=6246
 公告起始 :2026/9/21
 公告迄止 :2026/10/21
 主辦單位 
 協辦單位 
 活動地點