PrometheusЧÀÍÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв £¬£¬£¬ÐèÔöÇ¿·À»¤

Ðû²¼Ê±¼ä 2024-12-16

1. PrometheusЧÀÍÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв £¬£¬£¬ÐèÔöÇ¿·À»¤


12ÔÂ12ÈÕ £¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢³öÖÒÑÔ £¬£¬£¬Ö¸³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨ЧÀÍÆ÷ÃæÁÙÖØ´óÇ徲Σº¦¡£¡£¡£ ¡£¡£ÕâЩЧÀÍÆ÷ÓÉÓÚȱ·¦Êʵ±µÄÉí·ÝÑéÖ¤ £¬£¬£¬ÈÝÒ×ÔâÊÜÐÅϢй¶¡¢¾Ü¾øÐ§ÀÍ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¡£¡£ ¡£¡£¾ÝÔ¤¼Æ £¬£¬£¬ÓÐÊýÊ®Íǫ̀ Prometheus ʵÀýºÍЧÀÍÆ÷¿Éͨ¹ý»¥ÁªÍø¹ûÕæ»á¼û £¬£¬£¬ÐγÉÁËÒ»¸öÖØ´óµÄ¹¥»÷Ãæ £¬£¬£¬¿ÉÄÜʹÊý¾ÝºÍЧÀÍÊܵ½Íþв¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔÇáËɵØÍøÂçÃô¸ÐÐÅÏ¢ £¬£¬£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿ £¬£¬£¬²¢Ö±½ÓÅÌÎÊÄÚ²¿Êý¾Ý £¬£¬£¬Ì»Â¶ÉñÃØ £¬£¬£¬½ø¶øÔÚ×éÖ¯ÖлñµÃÆðԴפ×ãµã¡£¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬¡°/debug/pprof¡±¶ËµãµÄ̻¶¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌå £¬£¬£¬µ¼ÖÂЧÀÍÆ÷Í߽⡣¡£¡£ ¡£¡£AquaÇå¾²¹«Ë¾»¹·¢Ã÷¹©Ó¦Á´Íþв £¬£¬£¬°üÀ¨Ê¹ÓûعºÐ®ÖÆÊÖÒÕÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ £¬£¬£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£¡£¡£ ¡£¡£×Ô2024Äê9ÔÂÆð £¬£¬£¬PrometheusÇå¾²ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±½¨Òé×éÖ¯½ÓÄÉÊʵ±µÄÉí·ÝÑéÖ¤ÒªÁì± £»£»£»£»£»¤PrometheusЧÀÍÆ÷ºÍµ¼³öÆ÷ £¬£¬£¬ÏÞÖÆ¹ûÕæÆØ¹â £¬£¬£¬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³ £»£»£»£»£»î¶¯ £¬£¬£¬ÒÔ×èÖ¹Ç徲Σº¦¡£¡£¡£ ¡£¡£


https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html


2. Î÷°àÑÀÃØÂ³¾¯·½ÁªÊÖ¹¥»÷´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©Æ­


12ÔÂ12ÈÕ £¬£¬£¬Î÷°àÑÀ¾¯·½ÓëÃØÂ³¾¯·½ÏàÖú £¬£¬£¬Àֳɹ¥»÷ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©Æ­ÍÅ»ï £¬£¬£¬Á½¹ú¹²¾Ð²¶ÁË83Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£ ¡£¡£ÆäÖÐ £¬£¬£¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶ £¬£¬£¬°üÀ¨ÂíµÂÀï¡¢°ÍÈûÂÞÄÇµÈµØ £¬£¬£¬ÉÐÓÐ48ÈËÔÚÃØÂ³ÂäÍø¡£¡£¡£ ¡£¡£ÔÚÐж¯ÖÐ £¬£¬£¬¾¯·½»¹×¥»ñÁ˸÷¸·¨ÍÅ»ïµÄÍ·Ä¿ £¬£¬£¬²¢½É»ñÁË´ó×ÚÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¡£¡£ ¡£¡£¸ÃÍÅ»ïı»®×Å´óÐͺô½ÐÖÐÐÄ £¬£¬£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤ £¬£¬£¬Í¨¹ýð³äÒøÐпͷþ £¬£¬£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ¾ç±¾ £¬£¬£¬ÓÕÆ­ÖÁÉÙ10,000ÈËй¶Ãô¸ÐÒøÐÐÐÅÏ¢ £¬£¬£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£¡£¡£ ¡£¡£ËûÃÇʹÓÃÀ´µçÓÕÆ­ÊÖÒÕÔöÌí¿ÉÐÅ¶È £¬£¬£¬ÒÔδ¾­ÊÚȨµÄATMÈ¡¿î¾¯±¨ÎªÓÕ¶ü £¬£¬£¬Ö¸µ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£¡£¡£ ¡£¡£ÏÖ½ðÌáÈ¡ºó £¬£¬£¬²¿·Ö»á±»ÔËÓªÉ̱£´æ £¬£¬£¬ÆäÓàÔòËÍÍùÃØÂ³µÄ×éÖ¯¡£¡£¡£ ¡£¡£¾¯·½Ç¿µ÷ £¬£¬£¬·¸·¨·Ö×ÓʹÓÃÑÕÉ«´úÂëʶ±ðÒøÐÐ×éÖ¯ £¬£¬£¬ÊèÉ¢ÌØ¹¤µ½²î±ð¶¼»áÒÔÔöÌí×·×ÙÄѶȡ£¡£¡£ ¡£¡£Îª±ÜÃâÕ©Æ­ £¬£¬£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐÐÊðÀíÈËÅÊ̸ºó²ÅÌṩСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬²¢¼Ç×ÅÒøÐоø²»»áÒªÇó͸¶¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/


3. ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯GamaredonʹÓÃAndroidÌØ¹¤Èí¼þÇÔÈ¡Êý¾Ý


12ÔÂ13ÈÕ £¬£¬£¬¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯Gamaredon±»·¢Ã÷ʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroidÌØ¹¤Èí¼þϵÁÐ £¬£¬£¬Õë¶ÔǰËÕÁª¹ú¼ÒµÄ¶íÓïÈËÊ¿¾ÙÐмàÊÓºÍÇÔÈ¡ÒÆ¶¯×°±¸Êý¾Ý¡£¡£¡£ ¡£¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬£¬£¬Í¨¹ýľÂíTelegramÓ¦ÓóÌÐò»òð³äÈýÐÇKnoxÈö²¥ £¬£¬£¬¾ßÓÐÍøÂç¶ÌÐÅ¡¢Â¼Òô¡¢¶¨Î»¡¢ÕÕÏàµÈ¶àÖÖ¹¦Ð§¡£¡£¡£ ¡£¡£¶øPlainGnomeÊÇÒ»¿î½ÏÐµĶ¨ÖÆAndroid¼à¿Ø¶ñÒâÈí¼þ £¬£¬£¬½ÓÄÉÁ½½×¶Î×°ÖÃÀú³Ì £¬£¬£¬Ô½·¢ÒþÃØÇÒÓÃ;ÆÕ±é £¬£¬£¬¾ßÓÐÓëBoneSpyÏàËÆµÄÊý¾ÝÍøÂ繦Ч £¬£¬£¬²¢¼¯³ÉÁׯ߼¶¹¦Ð§ÒÔ½µµÍ¼ì²âΣº¦¡£¡£¡£ ¡£¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢Ã÷ £¬£¬£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÖ¸µ¼Êܺ¦ÕßÏÂÔØµÄ¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ö¸³ö £¬£¬£¬ÕâÏÔʾÁËGamaredon¶ÔAndroid×°±¸µÄÈÕÒæ¹Ø×¢ £¬£¬£¬²¢½«Æä¼à¿ØÄÜÁ¦À©Õ¹µ½Òƶ¯×°±¸¡£¡£¡£ ¡£¡£¹È¸èÒÑÈ·ÈÏ £¬£¬£¬Google Play Protect¿ÉÒÔ×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/


4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÓªÒµ²¿·ÖÔâºÚ¿Í¹¥»÷


12ÔÂ13ÈÕ £¬£¬£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾ £¬£¬£¬Ò»¼ÒÔÚ25¸ö¹ú¼ÒÓµÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾ £¬£¬£¬×¨ÃÅ´ÓÊÂÆû³µÌæ»»Áã¼þ¡¢²¿¼þ¼°Î¬ÐÞ±£ÑøÐ§ÀÍ £¬£¬£¬Æä¼ÓÄôóÓªÒµ²¿·Ö½üÆÚÔâÓöºÚ¿Í¹¥»÷¡£¡£¡£ ¡£¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄFORM 8-KÎļþÖÐ͸¶ £¬£¬£¬11ÔÂ13ÈÕ £¬£¬£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÓªÒµ²¿·ÖµÄITϵͳÔâÊÜÁËδ¾­ÊÚȨµÄ»á¼û £¬£¬£¬µ¼ÖÂÓªÒµÔËÓªÖÐÖ¹¡£¡£¡£ ¡£¡£LKQѸËÙ½ÓÄÉÐж¯ £¬£¬£¬°üÀ¨Æô¶¯Çå¾²ÊÂÎñÏìÓ¦ÍýÏë¡¢Óëȡ֤ÊÓ²ìÔ±ÏàÖú £¬£¬£¬²¢Í¨ÖªÖ´·¨²¿·Ö¡£¡£¡£ ¡£¡£¾­ÆÊÎö £¬£¬£¬¹«Ë¾ÒÔΪÒÑÓÐÓÃ×èÖ¹Íþв £¬£¬£¬ÇÒ³ý¸ÃÓªÒµ²¿·ÖÍâ £¬£¬£¬ÆäËûӪҵδÊÜÓ°Ïì £¬£¬£¬ÏÖÔڸò¿·ÖÒÑ¿¿½üÂú¸ººÉÔËת¡£¡£¡£ ¡£¡£LKQÔ¤¼Æ´Ë´ÎÊÂÎñ²»»á¶Ô±¾²ÆÄêÊ£Óàʱ¼äµÄ²ÆÎñ»òÔËÓªÔì³ÉÖØ´óÓ°Ïì £¬£¬£¬²¢½«ÏòÍøÂç°ü¹Ü¹«Ë¾×·ÇóÅâ³¥¡£¡£¡£ ¡£¡£Ö»¹ÜÏÖÔÚÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÉù³Æ¶Ô´Ë´ÎÏ®»÷ÈÏÕæ £¬£¬£¬µ«LKQÖÒÑÔ³Æ £¬£¬£¬ÊÜÓ°ÏìµÄÓªÒµÔÚ¼¸ÖÜÄÚ·ºÆðÖÐÖ¹ £¬£¬£¬ÏÖÒѻָ´ÔËÓª¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/


5. Care1Êý¾Ý¿âÔâй¶ £¬£¬£¬480Íò»¼ÕßÐÅÏ¢ÆØ¹â


12ÔÂ13ÈÕ £¬£¬£¬ÍøÂçÇå¾²Ñо¿Ô±Jeremiah Fowler½üÆÚ½ÒÆÆÁËÒ»¸öÖØ´óÇå¾²Òþ»¼ £¬£¬£¬Ëû·¢Ã÷¼ÓÄôóÒ½ÁÆÊÖÒÕ¹«Ë¾Care1µÄÒ»¸öδÊܱ £»£»£»£»£»¤Êý¾Ý¿â̻¶ÁËÁè¼Ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢ £¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡Ê·¼°Ð¡ÎÒ˽¼Ò¿µ½¡ºÅÂ루PHN£©µÈ £¬£¬£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£¡£¡£ ¡£¡£Care1×÷ΪרҵµÄÑÛ¿ÆÕչ˻¤Ê¿AIÈí¼þ½â¾ö¼Æ»®ÌṩÉÌ £¬£¬£¬ÓµÓÐ170¶àÃûÏàÖúÑé¹âʦ £¬£¬£¬ÖÎÀí×ÅÁè¼Ý15Íò´Î»¼Õß¾ÍÕï¡£¡£¡£ ¡£¡£´Ë´Îй¶µÄÊý¾Ý²»µ«°üÀ¨ÏêϸµÄÑۿƼì²é±¨¸æ £¬£¬£¬ÉÐÓÐCSVºÍXLSµç×Ó±í¸ñ £¬£¬£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈÒªº¦ÐÅÏ¢¡£¡£¡£ ¡£¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ¿µ½¡±êʶ·û £¬£¬£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚڲƭ £¬£¬£¬µ«¿ÉÄÜΪ·¸·¨·Ö×ÓÌṩ¹¹½¨Ð¡ÎÒ˽¼ÒÖÜÈ«µµ°¸µÄÖ÷ÒªÐÅÏ¢¡£¡£¡£ ¡£¡£ÏÖÔÚÉв»ÇåÎúÊý¾Ý¿âµÄÏêϸÖÎÀí·½¼°Ð¹Â¶Ò»Á¬Ê±¼ä £¬£¬£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÈÏÕæÈεÄÅû¶֪ͨ £¬£¬£¬²¢´ÙʹÆäѸËÙÏÞÖÆÁ˹«ÖÚ»á¼û¡£¡£¡£ ¡£¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯Àú³Ì¼ÓËÙ £¬£¬£¬Êý¾Ýй¶Σº¦ÈÕÒæÍ¹ÏÔ £¬£¬£¬¸ø»¼Õß´øÀ´ÖØ´óÒþ˽Íþв¡£¡£¡£ ¡£¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÖØÊÓÍøÂçÇå¾² £¬£¬£¬½ÓÄÉÇ¿¼ÓÃÜ¡¢ÑÏ¿á»á¼û¿ØÖƺͰ´ÆÚÇå¾²Éó¼ÆµÈ²½·¥ £¬£¬£¬È·± £»£»£»£»£»¼ÕßÐÅÏ¢µÄÇå¾²¡£¡£¡£ ¡£¡£


https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/


6. µÂ¹úBSIÆÆËð3Íǫ̀Android IoT×°±¸ÖÐBadBox¶ñÒâÈí¼þ


12ÔÂ13ÈÕ £¬£¬£¬µÂ¹úÁª°îÐÅÏ¢Çå¾²¾Ö£¨BSI£©ÒѽÓÄÉÐж¯ £¬£¬£¬ÆÆËðÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoT×°±¸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢×°ÖÃÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì»á¼ûµÄAndroid¶ñÒâÈí¼þ £¬£¬£¬Ö÷ÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌå×°±¸µÈ¡£¡£¡£ ¡£¡£BSIͨ¹ý³Á¶´´¦Öóͷ££¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷µÄͨѶ £¬£¬£¬´Ó¶øÓÐÓÃ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐС£¡£¡£ ¡£¡£ÊÜѬȾװ±¸µÄËùÓÐÕß½«Æ¾Ö¤IPµØµãÊÕµ½Í¨Öª £¬£¬£¬²¢Ó¦Á¬Ã¦¶Ï¿ª×°±¸ÓëÍøÂçµÄÅþÁ¬»ò×èֹʹÓà £¬£¬£¬²¢Í˻ػòÑïÆú¸Ã×°±¸¡£¡£¡£ ¡£¡£BSIÖÒÑÔ³Æ £¬£¬£¬ËùÓÐÊÜÓ°ÏìµÄ×°±¸¶¼ÔËÐÐ׏ýʱµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ £¬£¬£¬Òò´Ë×ÝÈ»ÒÑÌá·ÀBadBox £¬£¬£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£ ¡£¡£ÏûºÄÕßÓ¦Ö»¹ºÖÃÀ´×ÔÐÅÓþÓÅÒìµÄÖÆÔìÉ̵ÄÖÇÄÜ×°±¸ £¬£¬£¬²¢Ñ°ÕÒÌṩºã¾ÃÇå¾²Ö§³ÖµÄ²úÆ·¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/