Prometheus·þÎñÆ÷Ãæ¶Ô¶à³Á°²È«Íþв£¬£¬£¬£¬£¬£¬£¬Ðè¼ÓÇ¿·À»¤
°ä²¼¹¦·ò 2024-12-161. Prometheus·þÎñÆ÷Ãæ¶Ô¶à³Á°²È«Íþв£¬£¬£¬£¬£¬£¬£¬Ðè¼ÓÇ¿·À»¤
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬Ö¸³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨·þÎñÆ÷Ãæ¶Ô³Á´ó°²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·þÎñÆ÷ÓÉÓÚ²»×ãÊʵ±µÄÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬ÈÝÒ×Ôâ·êÐÅϢй¶¡¢»Ø¾ø·þÎñ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬£¬£¬£¬£¬£¬º±¼ûÊ®Íǫ̀ Prometheus Ê·ýºÍ·þÎñÆ÷¿Éͨ¹ý»¥ÁªÍø¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬ÐγÉÁËÒ»¸ö¾Þ´óµÄ¹¥»÷Ãæ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜʹÊý¾ÝºÍ·þÎñÊܵ½Íþв¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÇáËɵØÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬²¢Ö±½Ó²éÎÊÄÚ²¿Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Â¶³ö°ÂÃØ£¬£¬£¬£¬£¬£¬£¬½ø¶øÔÚ×éÖ¯ÖлñµÃ³õ²½°²Éíµã¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¡°/debug/pprof¡±¶ËµãµÄ¶³ö¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌ壬£¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÆ÷±ÀÀ£¡£¡£¡£¡£¡£¡£¡£Aqua°²È«¹«Ë¾»¹·¢ÏÖ¹©¸øÁ´Íþв£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ê¹Óûعº½Ù³Ö¼¼ÊõÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ£¬£¬£¬£¬£¬£¬£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£¡£¡£¡£¡£¡£¡£×Ô2024Äê9ÔÂÆð£¬£¬£¬£¬£¬£¬£¬Prometheus°²È«ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½¨Òé×éÖ¯²ÉÈ¡Êʵ±µÄÉí·ÝÑéÖ¤²½Öè±£»£»£»£»£»£»¤Prometheus·þÎñÆ÷ºÍµ¼³öÆ÷£¬£¬£¬£¬£¬£¬£¬Ï޶ȹ«¿ªÆØ¹â£¬£¬£¬£¬£¬£¬£¬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À°²È«·çÏÕ¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html
2. Î÷°àÑÀÃØÂ³¾¯·½ÁªÊÖ½ø¹¥´ó¹æÄ£ÓïÒôÍøÂç´¹µöÚ¿Æ
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬Î÷°àÑÀ¾¯·½ÓëÃØÂ³¾¯·½ºÏ×÷£¬£¬£¬£¬£¬£¬£¬³É¹¦½ø¹¥ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂç´¹µöÚ¿ÆÍŻ£¬£¬£¬£¬£¬£¬Á½¹ú¹²¿ÛÁôÁË83Ãû·¸×ïÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÂíµÂÀï¡¢°ÍÈûÂÞÄǵȵأ¬£¬£¬£¬£¬£¬£¬»¹ÓÐ48ÈËÔÚÃØÂ³ÂäÍø¡£¡£¡£¡£¡£¡£¡£ÔÚÐж¯ÖУ¬£¬£¬£¬£¬£¬£¬¾¯·½»¹×¥»ñÁ˸÷¸×ïÍÅ»ïµÄÍ·×Ó£¬£¬£¬£¬£¬£¬£¬²¢½É»ñÁË´óÁ¿ÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï¾Óª×Å´óÐͺô½ÐÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¼ÙÒâÒøÐпͷþ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÓÕÆÖÁÉÙ10,000ÈËй¼ûô¸ÐÒøÐÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£¡£¡£¡£¡£¡£¡£ËûÃÇʹÓÃÀ´µçºýŪ¼¼ÊõÔö³¤¿ÉÐŶȣ¬£¬£¬£¬£¬£¬£¬ÒÔδ¾ÊÚȨµÄATMÈ¡¿î¾¯±¨Îªµö¶ü£¬£¬£¬£¬£¬£¬£¬Êèµ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÏÖ½ðÌáÈ¡ºó£¬£¬£¬£¬£¬£¬£¬²¿ÃŻᱻÔËÓªÉ̱£Áô£¬£¬£¬£¬£¬£¬£¬ÆäÓàÔòËÍÍùÃØÂ³µÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¾¯·½Ç¿µ÷£¬£¬£¬£¬£¬£¬£¬·¸×ï·Ö×ÓʹÓÃÉ«²Ê´úÂë¼ø±ðÒøÐÐ×éÖ¯£¬£¬£¬£¬£¬£¬£¬·ÖÉ¢¼éϸµ½·ÖÆç³ÇÊÐÒÔÔö³¤×·×ÙÄѶȡ£¡£¡£¡£¡£¡£¡£ÎªÔ¤·ÀÚ¿Æ£¬£¬£¬£¬£¬£¬£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐдúÀíÈ˽»Ì¸ºó²ÅÌṩÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢¼Ç×¡ÒøÐоø²»»áÒªÇóй©¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/
3. ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯GamaredonÀûÓÃAndroid¼äµýÈí¼þÇÔÈ¡Êý¾Ý
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂç¼äµý×éÖ¯Gamaredon±»·¢ÏÖʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroid¼äµýÈí¼þϵÁУ¬£¬£¬£¬£¬£¬£¬Õë¶ÔǰËÕÁª¹ú¶ÈµÄ¶íÓïÈËÊ¿½øÐмලºÍÇÔÈ¡ÒÆ¶¯É豸Êý¾Ý¡£¡£¡£¡£¡£¡£¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬Í¨¹ýľÂíTelegramÀûÓ÷¨Ê½»ò¼ÙÒâÈýÐÇKnox´«²¼£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÍøÂç¶ÌÐÅ¡¢¹àÒô¡¢¶¨Î»¡¢ÅÄÕյȶàÖÖÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¶øPlainGnomeÊÇÒ»¿î½ÏÐµĶ¨ÔìAndroid¼à¿Ø¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ñ¡È¡Á½½×¶Î×°Öùý³Ì£¬£¬£¬£¬£¬£¬£¬Ô½·¢ÒþÃØÇÒÓô¦¿í·º£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÓëBoneSpyÀàËÆµÄÊý¾ÝÍøÂçÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁ¶¯ß¼¶Ö°ÄÜÒÔ½µµÍ¼ì²â·çÏÕ¡£¡£¡£¡£¡£¡£¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÊèµ¼Êܺ¦ÕßÏÂÔØµÄ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÕâÏÔʾÁËGamaredon¶ÔAndroidÉ豸µÄÈÕÒæ¹Ø×¢£¬£¬£¬£¬£¬£¬£¬²¢½«Æä¼à¿ØÄÜÁ¦À©´óµ½Òƶ¯É豸¡£¡£¡£¡£¡£¡£¡£¹È¸èÒÑÈ·ÈÏ£¬£¬£¬£¬£¬£¬£¬Google Play ProtectÄܹ»×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/
4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÒµÎñ²¿ÃÅÔâºÚ¿Í¹¥»÷
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬Ò»¼ÒÔÚ25¸ö¹ú¶ÈÕ¼ÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾£¬£¬£¬£¬£¬£¬£¬×¨ÃÅ´ÓÊÂÆû³µ¸ü»»Áã¼þ¡¢²¿¼þ¼°Î¬½¨±£Ñø·þÎñ£¬£¬£¬£¬£¬£¬£¬Æä¼ÓÄôóÒµÎñ²¿ÃŽüÆÚÔâ·êºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¡£¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄFORM 8-KÎļþÖÐй©£¬£¬£¬£¬£¬£¬£¬11ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÒµÎñ²¿ÃŵÄITϵͳÔâ·êÁËδ¾ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒµÎñÔËÓªÖжϡ£¡£¡£¡£¡£¡£¡£LKQѸËÙ²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬£¬Ô̺¬Æô¶¯°²È«ÊÂÎñÏìÓ¦´òËã¡¢Óëȡ֤µ÷²éÔ±ºÏ×÷£¬£¬£¬£¬£¬£¬£¬²¢Í¨Öª·¨Âɲ¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¾·ÖÎö£¬£¬£¬£¬£¬£¬£¬¹«Ë¾ÒÔΪÒÑÓÐЧ¶ôÔìÍþв£¬£¬£¬£¬£¬£¬£¬ÇÒ³ý¸ÃÒµÎñ²¿ÃÅ±í£¬£¬£¬£¬£¬£¬£¬ÆäËûÒµÎñδÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ã²¿ÃÅÒÑ¿¿½üÂú¸ººÉÔËÐС£¡£¡£¡£¡£¡£¡£LKQÔ¤¼ÆÕâ´ÎÊÂÎñ²»»á¶Ô±¾²ÆÄêÔü×Ò¹¦·òµÄ²ÆÕþ»òÔËÓªÔì³É³Á´óÓ°Ï죬£¬£¬£¬£¬£¬£¬²¢½«ÏòÍøÂç±£ÏÕ¹«Ë¾×·ÇóÅâ³¥¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÐû³Æ¶ÔÕâ´ÎÏ®»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬µ«LKQÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÒµÎñÔÚ¼¸ÖÜÄÚ³öÏÖÖжϣ¬£¬£¬£¬£¬£¬£¬ÏÖÒѸ´ÔÔËÓª¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/
5. Care1Êý¾Ý¿âÔâй¶£¬£¬£¬£¬£¬£¬£¬480Íò»¼ÕßÐÅÏ¢ÆØ¹â
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah Fowler½üÆÚ¸æ·¢ÁËÒ»¸ö³Á´ó°²È«Òþ»¼£¬£¬£¬£¬£¬£¬£¬Ëû·¢ÏÖ¼ÓÄôóÒ½ÁƼ¼Êõ¹«Ë¾Care1µÄÒ»¸öδÊܱ£»£»£»£»£»£»¤Êý¾Ý¿â¶³öÁ˳¬¹ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢²¡Ê·¼°Ó×ÎÒ½¡È«ºÅÂ루PHN£©µÈ£¬£¬£¬£¬£¬£¬£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£¡£¡£¡£¡£¡£¡£Care1×÷ΪרҵµÄÑÛ¿Æ»¤ÀíAIÈí¼þ½â¾ö¹æ»®ÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬Õ¼ÓÐ170¶àÃûºÏ×÷Ñé¹âʦ£¬£¬£¬£¬£¬£¬£¬ÖÎÀí×ų¬¹ý15Íò´Î»¼Õß¾ÍÕï¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾Ý²»½öÔ̺¬¾ßÌåµÄÑۿƲ鳻㱨£¬£¬£¬£¬£¬£¬£¬»¹ÓÐCSVºÍXLSµç×Ó±í¸ñ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈ¹Ø¼üÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ½¡È«±êʶ·û£¬£¬£¬£¬£¬£¬£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚڲƣ¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄÜΪ·¸×ï·Ö×ÓÌṩ¹¹½¨Ó×ÎÒÈ«Ãæµµ°¸µÄ³ÁÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾Ý¿âµÄ¾ßÌåÖÎÀí·½¼°Ð¹Â¶³ÖÐø¹¦·ò£¬£¬£¬£¬£¬£¬£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÕÆ¹ÜÈεÄÅû¶֪ͨ£¬£¬£¬£¬£¬£¬£¬²¢´ÙʹÆäѸËÙÏÞ¶ÈÁ˹«¼Ò½Ó¼û¡£¡£¡£¡£¡£¡£¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯¹ý³Ì¼Ó¿ì£¬£¬£¬£¬£¬£¬£¬Êý¾Ýй¶·çÏÕÈÕÒæÍ¹ÏÔ£¬£¬£¬£¬£¬£¬£¬¸ø»¼Õß´øÀ´¾Þ´óÒþÖÔÍþв¡£¡£¡£¡£¡£¡£¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÆ÷³ÁÍøÂ簲ȫ£¬£¬£¬£¬£¬£¬£¬²Éȡǿ¼ÓÃÜ¡¢Ñϸñ½Ó¼û½ÚÔìºÍ¶¨ÆÚ°²È«Éó¼ÆµÈ´ëÊ©£¬£¬£¬£¬£¬£¬£¬È·±£»£»£»£»£»£»¼ÕßÐÅÏ¢µÄ°²È«¡£¡£¡£¡£¡£¡£¡£
https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/
6. µÂ¹úBSI·ÛËé3Íǫ̀Android IoTÉ豸ÖÐBadBox¶ñÒâÈí¼þ
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬µÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©ÒѲÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬£¬·ÛËéÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoTÉ豸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢×°ÖÃÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì½Ó¼ûµÄAndroid¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌåÉ豸µÈ¡£¡£¡£¡£¡£¡£¡£BSIͨ¹ý³Á¶´´¦Öã¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäºÅÁîºÍ½ÚÔì·þÎñÆ÷µÄͨѶ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÓÐЧ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐÓ×£¡£¡£¡£¡£¡£¡£ÊÜϰȾÉ豸µÄËùÓÐÕß½«Æ¾¾ÝIPµØÖ·ÊÕµ½Í¨Öª£¬£¬£¬£¬£¬£¬£¬²¢Ó¦Á¢¼´¶Ï¿ªÉ豸ÓëÍøÂçµÄÏνӻòÖÕ³¡Ê¹Ó㬣¬£¬£¬£¬£¬£¬²¢Í˻ػòÅׯú¸ÃÉ豸¡£¡£¡£¡£¡£¡£¡£BSIÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬ËùÓÐÊÜÓ°ÏìµÄÉ豸¶¼ÔËÐÐ׏ýÆÚµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ£¬£¬£¬£¬£¬£¬£¬Òò¶ø¼´±ãÒÑ·À±¸BadBox£¬£¬£¬£¬£¬£¬£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ïû·ÑÕßÓ¦Ö»²É°ìÀ´×Ô¸ºÓþÓÅÁ¼µÄÔì×÷É̵ÄÖÇÄÜÉ豸£¬£¬£¬£¬£¬£¬£¬²¢Ñ°ÕÒÌṩ³Ö¾Ã°²È«Ö§³ÖµÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/


¾©¹«Íø°²±¸11010802024551ºÅ