PrometheusЧÀÍÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв£¬£¬£¬£¬£¬£¬ÐèÔöÇ¿·À»¤
Ðû²¼Ê±¼ä 2024-12-161. PrometheusЧÀÍÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв£¬£¬£¬£¬£¬£¬ÐèÔöÇ¿·À»¤
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢³öÖÒÑÔ£¬£¬£¬£¬£¬£¬Ö¸³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨ЧÀÍÆ÷ÃæÁÙÖØ´óÇ徲Σº¦¡£¡£¡£¡£¡£¡£ÕâЩЧÀÍÆ÷ÓÉÓÚȱ·¦Êʵ±µÄÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÈÝÒ×ÔâÊÜÐÅϢй¶¡¢¾Ü¾øÐ§ÀÍ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¡£¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬£¬£¬£¬ÓÐÊýÊ®Íǫ̀ Prometheus ʵÀýºÍЧÀÍÆ÷¿Éͨ¹ý»¥ÁªÍø¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬ÐγÉÁËÒ»¸öÖØ´óµÄ¹¥»÷Ãæ£¬£¬£¬£¬£¬£¬¿ÉÄÜʹÊý¾ÝºÍЧÀÍÊܵ½Íþв¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÇáËɵØÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿£¬£¬£¬£¬£¬£¬²¢Ö±½ÓÅÌÎÊÄÚ²¿Êý¾Ý£¬£¬£¬£¬£¬£¬Ì»Â¶ÉñÃØ£¬£¬£¬£¬£¬£¬½ø¶øÔÚ×éÖ¯ÖлñµÃÆðԴפ×ãµã¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¡°/debug/pprof¡±¶ËµãµÄ̻¶¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌ壬£¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÆ÷Í߽⡣¡£¡£¡£¡£¡£AquaÇå¾²¹«Ë¾»¹·¢Ã÷¹©Ó¦Á´Íþв£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓûعºÐ®ÖÆÊÖÒÕÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ£¬£¬£¬£¬£¬£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£¡£¡£¡£¡£¡£×Ô2024Äê9ÔÂÆð£¬£¬£¬£¬£¬£¬PrometheusÇå¾²ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½¨Òé×éÖ¯½ÓÄÉÊʵ±µÄÉí·ÝÑéÖ¤ÒªÁì±£»£»£»£»£»£»£»¤PrometheusЧÀÍÆ÷ºÍµ¼³öÆ÷£¬£¬£¬£¬£¬£¬ÏÞÖÆ¹ûÕæÆØ¹â£¬£¬£¬£¬£¬£¬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³£»£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹Ç徲Σº¦¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html
2. Î÷°àÑÀÃØÂ³¾¯·½ÁªÊÖ¹¥»÷´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©Æ
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Î÷°àÑÀ¾¯·½ÓëÃØÂ³¾¯·½ÏàÖú£¬£¬£¬£¬£¬£¬Àֳɹ¥»÷ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©ÆÍŻ£¬£¬£¬£¬£¬Á½¹ú¹²¾Ð²¶ÁË83Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶£¬£¬£¬£¬£¬£¬°üÀ¨ÂíµÂÀï¡¢°ÍÈûÂÞÄǵȵأ¬£¬£¬£¬£¬£¬ÉÐÓÐ48ÈËÔÚÃØÂ³ÂäÍø¡£¡£¡£¡£¡£¡£ÔÚÐж¯ÖУ¬£¬£¬£¬£¬£¬¾¯·½»¹×¥»ñÁ˸÷¸·¨ÍÅ»ïµÄÍ·Ä¿£¬£¬£¬£¬£¬£¬²¢½É»ñÁË´ó×ÚÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïı»®×Å´óÐͺô½ÐÖÐÐÄ£¬£¬£¬£¬£¬£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬Í¨¹ýð³äÒøÐпͷþ£¬£¬£¬£¬£¬£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ¾ç±¾£¬£¬£¬£¬£¬£¬ÓÕÆÖÁÉÙ10,000ÈËй¶Ãô¸ÐÒøÐÐÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£¡£¡£¡£¡£¡£ËûÃÇʹÓÃÀ´µçÓÕÆÊÖÒÕÔöÌí¿ÉÐŶȣ¬£¬£¬£¬£¬£¬ÒÔδ¾ÊÚȨµÄATMÈ¡¿î¾¯±¨ÎªÓÕ¶ü£¬£¬£¬£¬£¬£¬Ö¸µ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£¡£¡£¡£¡£¡£ÏÖ½ðÌáÈ¡ºó£¬£¬£¬£¬£¬£¬²¿·Ö»á±»ÔËÓªÉ̱£´æ£¬£¬£¬£¬£¬£¬ÆäÓàÔòËÍÍùÃØÂ³µÄ×éÖ¯¡£¡£¡£¡£¡£¡£¾¯·½Ç¿µ÷£¬£¬£¬£¬£¬£¬·¸·¨·Ö×ÓʹÓÃÑÕÉ«´úÂëʶ±ðÒøÐÐ×éÖ¯£¬£¬£¬£¬£¬£¬ÊèÉ¢ÌØ¹¤µ½²î±ð¶¼»áÒÔÔöÌí×·×ÙÄѶȡ£¡£¡£¡£¡£¡£Îª±ÜÃâÕ©Æ£¬£¬£¬£¬£¬£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐÐÊðÀíÈËÅÊ̸ºó²ÅÌṩСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢¼Ç×ÅÒøÐоø²»»áÒªÇó͸¶¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/
3. ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯GamaredonʹÓÃAndroidÌØ¹¤Èí¼þÇÔÈ¡Êý¾Ý
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯Gamaredon±»·¢Ã÷ʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroidÌØ¹¤Èí¼þϵÁУ¬£¬£¬£¬£¬£¬Õë¶ÔǰËÕÁª¹ú¼ÒµÄ¶íÓïÈËÊ¿¾ÙÐмàÊÓºÍÇÔÈ¡ÒÆ¶¯×°±¸Êý¾Ý¡£¡£¡£¡£¡£¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬Í¨¹ýľÂíTelegramÓ¦ÓóÌÐò»òð³äÈýÐÇKnoxÈö²¥£¬£¬£¬£¬£¬£¬¾ßÓÐÍøÂç¶ÌÐÅ¡¢Â¼Òô¡¢¶¨Î»¡¢ÕÕÏàµÈ¶àÖÖ¹¦Ð§¡£¡£¡£¡£¡£¡£¶øPlainGnomeÊÇÒ»¿î½ÏÐµĶ¨ÖÆAndroid¼à¿Ø¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬½ÓÄÉÁ½½×¶Î×°ÖÃÀú³Ì£¬£¬£¬£¬£¬£¬Ô½·¢ÒþÃØÇÒÓÃ;ÆÕ±é£¬£¬£¬£¬£¬£¬¾ßÓÐÓëBoneSpyÏàËÆµÄÊý¾ÝÍøÂ繦Ч£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁׯ߼¶¹¦Ð§ÒÔ½µµÍ¼ì²âΣº¦¡£¡£¡£¡£¡£¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢Ã÷£¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÖ¸µ¼Êܺ¦ÕßÏÂÔØµÄ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬£¬£¬ÕâÏÔʾÁËGamaredon¶ÔAndroid×°±¸µÄÈÕÒæ¹Ø×¢£¬£¬£¬£¬£¬£¬²¢½«Æä¼à¿ØÄÜÁ¦À©Õ¹µ½Òƶ¯×°±¸¡£¡£¡£¡£¡£¡£¹È¸èÒÑÈ·ÈÏ£¬£¬£¬£¬£¬£¬Google Play Protect¿ÉÒÔ×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/
4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÓªÒµ²¿·ÖÔâºÚ¿Í¹¥»÷
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾£¬£¬£¬£¬£¬£¬Ò»¼ÒÔÚ25¸ö¹ú¼ÒÓµÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾£¬£¬£¬£¬£¬£¬×¨ÃÅ´ÓÊÂÆû³µÌæ»»Áã¼þ¡¢²¿¼þ¼°Î¬ÐÞ±£ÑøÐ§ÀÍ£¬£¬£¬£¬£¬£¬Æä¼ÓÄôóÓªÒµ²¿·Ö½üÆÚÔâÓöºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄFORM 8-KÎļþÖÐ͸¶£¬£¬£¬£¬£¬£¬11ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÓªÒµ²¿·ÖµÄITϵͳÔâÊÜÁËδ¾ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬µ¼ÖÂÓªÒµÔËÓªÖÐÖ¹¡£¡£¡£¡£¡£¡£LKQѸËÙ½ÓÄÉÐж¯£¬£¬£¬£¬£¬£¬°üÀ¨Æô¶¯Çå¾²ÊÂÎñÏìÓ¦ÍýÏë¡¢Óëȡ֤ÊÓ²ìÔ±ÏàÖú£¬£¬£¬£¬£¬£¬²¢Í¨ÖªÖ´·¨²¿·Ö¡£¡£¡£¡£¡£¡£¾ÆÊÎö£¬£¬£¬£¬£¬£¬¹«Ë¾ÒÔΪÒÑÓÐÓÃ×èÖ¹Íþв£¬£¬£¬£¬£¬£¬ÇÒ³ý¸ÃÓªÒµ²¿·ÖÍ⣬£¬£¬£¬£¬£¬ÆäËûӪҵδÊÜÓ°Ï죬£¬£¬£¬£¬£¬ÏÖÔڸò¿·ÖÒÑ¿¿½üÂú¸ººÉÔËת¡£¡£¡£¡£¡£¡£LKQÔ¤¼Æ´Ë´ÎÊÂÎñ²»»á¶Ô±¾²ÆÄêÊ£Óàʱ¼äµÄ²ÆÎñ»òÔËÓªÔì³ÉÖØ´óÓ°Ï죬£¬£¬£¬£¬£¬²¢½«ÏòÍøÂç°ü¹Ü¹«Ë¾×·ÇóÅâ³¥¡£¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÉù³Æ¶Ô´Ë´ÎÏ®»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬µ«LKQÖÒÑԳƣ¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓªÒµÔÚ¼¸ÖÜÄÚ·ºÆðÖÐÖ¹£¬£¬£¬£¬£¬£¬ÏÖÒѻָ´ÔËÓª¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/
5. Care1Êý¾Ý¿âÔâй¶£¬£¬£¬£¬£¬£¬480Íò»¼ÕßÐÅÏ¢ÆØ¹â
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ô±Jeremiah Fowler½üÆÚ½ÒÆÆÁËÒ»¸öÖØ´óÇå¾²Òþ»¼£¬£¬£¬£¬£¬£¬Ëû·¢Ã÷¼ÓÄôóÒ½ÁÆÊÖÒÕ¹«Ë¾Care1µÄÒ»¸öδÊܱ£»£»£»£»£»£»£»¤Êý¾Ý¿â̻¶ÁËÁè¼Ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡Ê·¼°Ð¡ÎÒ˽¼Ò¿µ½¡ºÅÂ루PHN£©µÈ£¬£¬£¬£¬£¬£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£¡£¡£¡£¡£¡£Care1×÷ΪרҵµÄÑÛ¿ÆÕչ˻¤Ê¿AIÈí¼þ½â¾ö¼Æ»®ÌṩÉÌ£¬£¬£¬£¬£¬£¬ÓµÓÐ170¶àÃûÏàÖúÑé¹âʦ£¬£¬£¬£¬£¬£¬ÖÎÀí×ÅÁè¼Ý15Íò´Î»¼Õß¾ÍÕï¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý²»µ«°üÀ¨ÏêϸµÄÑۿƼì²é±¨¸æ£¬£¬£¬£¬£¬£¬ÉÐÓÐCSVºÍXLSµç×Ó±í¸ñ£¬£¬£¬£¬£¬£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈÒªº¦ÐÅÏ¢¡£¡£¡£¡£¡£¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ¿µ½¡±êʶ·û£¬£¬£¬£¬£¬£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚڲƣ¬£¬£¬£¬£¬£¬µ«¿ÉÄÜΪ·¸·¨·Ö×ÓÌṩ¹¹½¨Ð¡ÎÒ˽¼ÒÖÜÈ«µµ°¸µÄÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÊý¾Ý¿âµÄÏêϸÖÎÀí·½¼°Ð¹Â¶Ò»Á¬Ê±¼ä£¬£¬£¬£¬£¬£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÈÏÕæÈεÄÅû¶֪ͨ£¬£¬£¬£¬£¬£¬²¢´ÙʹÆäѸËÙÏÞÖÆÁ˹«ÖÚ»á¼û¡£¡£¡£¡£¡£¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯Àú³Ì¼ÓËÙ£¬£¬£¬£¬£¬£¬Êý¾Ýй¶Σº¦ÈÕÒæÍ¹ÏÔ£¬£¬£¬£¬£¬£¬¸ø»¼Õß´øÀ´ÖØ´óÒþ˽Íþв¡£¡£¡£¡£¡£¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÖØÊÓÍøÂçÇå¾²£¬£¬£¬£¬£¬£¬½ÓÄÉÇ¿¼ÓÃÜ¡¢ÑÏ¿á»á¼û¿ØÖƺͰ´ÆÚÇå¾²Éó¼ÆµÈ²½·¥£¬£¬£¬£¬£¬£¬È·±£»£»£»£»£»£»£»¼ÕßÐÅÏ¢µÄÇå¾²¡£¡£¡£¡£¡£¡£
https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/
6. µÂ¹úBSIÆÆËð3Íǫ̀Android IoT×°±¸ÖÐBadBox¶ñÒâÈí¼þ
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬µÂ¹úÁª°îÐÅÏ¢Çå¾²¾Ö£¨BSI£©ÒѽÓÄÉÐж¯£¬£¬£¬£¬£¬£¬ÆÆËðÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoT×°±¸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢×°ÖÃÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì»á¼ûµÄAndroid¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌå×°±¸µÈ¡£¡£¡£¡£¡£¡£BSIͨ¹ý³Á¶´´¦Öóͷ££¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷µÄͨѶ£¬£¬£¬£¬£¬£¬´Ó¶øÓÐÓÃ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐС£¡£¡£¡£¡£¡£ÊÜѬȾװ±¸µÄËùÓÐÕß½«Æ¾Ö¤IPµØµãÊÕµ½Í¨Öª£¬£¬£¬£¬£¬£¬²¢Ó¦Á¬Ã¦¶Ï¿ª×°±¸ÓëÍøÂçµÄÅþÁ¬»ò×èֹʹÓ㬣¬£¬£¬£¬£¬²¢Í˻ػòÑïÆú¸Ã×°±¸¡£¡£¡£¡£¡£¡£BSIÖÒÑԳƣ¬£¬£¬£¬£¬£¬ËùÓÐÊÜÓ°ÏìµÄ×°±¸¶¼ÔËÐÐ׏ýʱµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ£¬£¬£¬£¬£¬£¬Òò´Ë×ÝÈ»ÒÑÌá·ÀBadBox£¬£¬£¬£¬£¬£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ÏûºÄÕßÓ¦Ö»¹ºÖÃÀ´×ÔÐÅÓþÓÅÒìµÄÖÆÔìÉ̵ÄÖÇÄÜ×°±¸£¬£¬£¬£¬£¬£¬²¢Ñ°ÕÒÌṩºã¾ÃÇå¾²Ö§³ÖµÄ²úÆ·¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/


¾©¹«Íø°²±¸11010802024551ºÅ