Prometheus·þÎñÆ÷Ãæ¶Ô¶à³Á°²È«Íþв£¬Ðè¼ÓÇ¿·À»¤
°ä²¼¹¦·ò 2024-12-161. Prometheus·þÎñÆ÷Ãæ¶Ô¶à³Á°²È«Íþв£¬Ðè¼ÓÇ¿·À»¤
12ÔÂ12ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢³öÖҸ棬ָ³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨·þÎñÆ÷Ãæ¶Ô³Á´ó°²È«·çÏÕ¡£ÕâЩ·þÎñÆ÷ÓÉÓÚ²»×ãÊʵ±µÄÉí·ÝÑéÖ¤£¬ÈÝÒ×Ôâ·êÐÅϢй¶¡¢»Ø¾ø·þÎñ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¾Ý¹À¼Æ£¬º±¼ûÊ®Íǫ̀ Prometheus Ê·ýºÍ·þÎñÆ÷¿Éͨ¹ý»¥ÁªÍø¹«¿ª½Ó¼û£¬ÐγÉÁËÒ»¸ö¾Þ´óµÄ¹¥»÷Ãæ£¬¿ÉÄÜʹÊý¾ÝºÍ·þÎñÊܵ½Íþв¡£¹¥»÷ÕßÄܹ»ÇáËɵØÍøÂçÃô¸ÐÐÅÏ¢£¬ÈçÆ¾Ö¤ºÍAPIÃÜÔ¿£¬²¢Ö±½Ó²éÎÊÄÚ²¿Êý¾Ý£¬Â¶³ö°ÂÃØ£¬½ø¶øÔÚ×éÖ¯ÖлñµÃ³õ²½°²Éíµã¡£´Ë±í£¬¡°/debug/pprof¡±¶ËµãµÄ¶³ö¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌ壬µ¼Ö·þÎñÆ÷±ÀÀ£¡£Aqua°²È«¹«Ë¾»¹·¢ÏÖ¹©¸øÁ´Íþв£¬Ô̺¬Ê¹Óûعº½Ù³Ö¼¼ÊõÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£×Ô2024Äê9ÔÂÆð£¬Prometheus°²È«ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£×êÑÐÈËÔ±½¨Òé×éÖ¯²ÉÈ¡Êʵ±µÄÉí·ÝÑéÖ¤²½Öè±£»¤Prometheus·þÎñÆ÷ºÍµ¼³öÆ÷£¬Ï޶ȹ«¿ªÆØ¹â£¬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³£»î¶¯£¬ÒÔÔ¤·À°²È«·çÏÕ¡£
https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html
2. Î÷°àÑÀÃØÂ³¾¯·½ÁªÊÖ½ø¹¥´ó¹æÄ£ÓïÒôÍøÂç´¹µöÚ¿Æ
12ÔÂ12ÈÕ£¬Î÷°àÑÀ¾¯·½ÓëÃØÂ³¾¯·½ºÏ×÷£¬³É¹¦½ø¹¥ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂç´¹µöÚ¿ÆÍŻÁ½¹ú¹²¿ÛÁôÁË83Ãû·¸×ïÏÓÒÉÈË¡£ÆäÖУ¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶£¬Ô̺¬ÂíµÂÀï¡¢°ÍÈûÂÞÄǵȵأ¬»¹ÓÐ48ÈËÔÚÃØÂ³ÂäÍø¡£ÔÚÐж¯ÖУ¬¾¯·½»¹×¥»ñÁ˸÷¸×ïÍÅ»ïµÄÍ·×Ó£¬²¢½É»ñÁË´óÁ¿ÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¸ÃÍÅ»ï¾Óª×Å´óÐͺô½ÐÖÐÐÄ£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤£¬Í¨¹ý¼ÙÒâÒøÐпͷþ£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ¾ç±¾£¬ÓÕÆÖÁÉÙ10,000ÈËй¼ûô¸ÐÒøÐÐÐÅÏ¢£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£ËûÃÇʹÓÃÀ´µçºýŪ¼¼ÊõÔö³¤¿ÉÐŶȣ¬ÒÔδ¾ÊÚȨµÄATMÈ¡¿î¾¯±¨Îªµö¶ü£¬Êèµ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£ÏÖ½ðÌáÈ¡ºó£¬²¿ÃŻᱻÔËÓªÉ̱£Áô£¬ÆäÓàÔòËÍÍùÃØÂ³µÄ×éÖ¯¡£¾¯·½Ç¿µ÷£¬·¸×ï·Ö×ÓʹÓÃÉ«²Ê´úÂë¼ø±ðÒøÐÐ×éÖ¯£¬·ÖÉ¢¼éϸµ½·ÖÆç³ÇÊÐÒÔÔö³¤×·×ÙÄѶȡ£ÎªÔ¤·ÀÚ¿Æ£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐдúÀíÈ˽»Ì¸ºó²ÅÌṩÓ×ÎÒÐÅÏ¢£¬²¢¼Ç×¡ÒøÐоø²»»áÒªÇóй©¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/
3. ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯GamaredonÀûÓÃAndroid¼äµýÈí¼þÇÔÈ¡Êý¾Ý
12ÔÂ13ÈÕ£¬¶íÂÞË¹ÍøÂç¼äµý×éÖ¯Gamaredon±»·¢ÏÖʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroid¼äµýÈí¼þϵÁУ¬Õë¶ÔǰËÕÁª¹ú¶ÈµÄ¶íÓïÈËÊ¿½øÐмලºÍÇÔÈ¡ÒÆ¶¯É豸Êý¾Ý¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Í¨¹ýľÂíTelegramÀûÓ÷¨Ê½»ò¼ÙÒâÈýÐÇKnox´«²¼£¬ÓµÓÐÍøÂç¶ÌÐÅ¡¢¹àÒô¡¢¶¨Î»¡¢ÅÄÕյȶàÖÖÖ°ÄÜ¡£¶øPlainGnomeÊÇÒ»¿î½ÏÐµĶ¨ÔìAndroid¼à¿Ø¶ñÒâÈí¼þ£¬Ñ¡È¡Á½½×¶Î×°Öùý³Ì£¬Ô½·¢ÒþÃØÇÒÓô¦¿í·º£¬ÓµÓÐÓëBoneSpyÀàËÆµÄÊý¾ÝÍøÂçÖ°ÄÜ£¬²¢¼¯³ÉÁ¶¯ß¼¶Ö°ÄÜÒÔ½µµÍ¼ì²â·çÏÕ¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢ÏÖ£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÊèµ¼Êܺ¦ÕßÏÂÔØµÄ¡£×êÑÐÈËÔ±Ö¸³ö£¬ÕâÏÔʾÁËGamaredon¶ÔAndroidÉ豸µÄÈÕÒæ¹Ø×¢£¬²¢½«Æä¼à¿ØÄÜÁ¦À©´óµ½Òƶ¯É豸¡£¹È¸èÒÑÈ·ÈÏ£¬Google Play ProtectÄܹ»×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£
https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/
4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÒµÎñ²¿ÃÅÔâºÚ¿Í¹¥»÷
12ÔÂ13ÈÕ£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾£¬Ò»¼ÒÔÚ25¸ö¹ú¶ÈÕ¼ÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾£¬×¨ÃÅ´ÓÊÂÆû³µ¸ü»»Áã¼þ¡¢²¿¼þ¼°Î¬½¨±£Ñø·þÎñ£¬Æä¼ÓÄôóÒµÎñ²¿ÃŽüÆÚÔâ·êºÚ¿Í¹¥»÷¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄFORM 8-KÎļþÖÐй©£¬11ÔÂ13ÈÕ£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÒµÎñ²¿ÃŵÄITϵͳÔâ·êÁËδ¾ÊÚȨµÄ½Ó¼û£¬µ¼ÖÂÒµÎñÔËÓªÖжϡ£LKQѸ¿ì²ÉÈ¡Ðж¯£¬Ô̺¬Æô¶¯°²È«ÊÂÎñÏìÓ¦´òËã¡¢Óëȡ֤µ÷²éÔ±ºÏ×÷£¬²¢Í¨Öª·¨Âɲ¿ÃÅ¡£¾·ÖÎö£¬¹«Ë¾ÒÔΪÒÑÓÐЧ¶ôÔìÍþв£¬ÇÒ³ý¸ÃÒµÎñ²¿ÃÅ±í£¬ÆäËûÒµÎñδÊÜÓ°Ï죬Ŀǰ¸Ã²¿ÃÅÒÑ¿¿½üÂú¸ººÉÔËÐС£LKQÔ¤¼ÆÕâ´ÎÊÂÎñ²»»á¶Ô±¾²ÆÄêÔü×Ò¹¦·òµÄ²ÆÕþ»òÔËÓªÔì³É³Á´óÓ°Ï죬²¢½«ÏòÍøÂç±£ÏÕ¹«Ë¾×·ÇóÅâ³¥¡£Ö»¹ÜĿǰÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÐû³Æ¶ÔÕâ´ÎÏ®»÷ÕÆ¹Ü£¬µ«LKQÖÒ¸æ³Æ£¬ÊÜÓ°ÏìµÄÒµÎñÔÚ¼¸ÖÜÄÚ³öÏÖÖжϣ¬ÏÖÒѸ´ÔÔËÓª¡£
https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/
5. Care1Êý¾Ý¿âÔâй¶£¬480Íò»¼ÕßÐÅÏ¢ÆØ¹â
12ÔÂ13ÈÕ£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah Fowler½üÆÚ¸æ·¢ÁËÒ»¸ö³Á´ó°²È«Òþ»¼£¬Ëû·¢ÏÖ¼ÓÄôóÒ½ÁƼ¼Êõ¹«Ë¾Care1µÄÒ»¸öδÊܱ£»¤Êý¾Ý¿â¶³öÁ˳¬¹ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢²¡Ê·¼°Ó×ÎÒ½¡È«ºÅÂ루PHN£©µÈ£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£Care1×÷ΪרҵµÄÑÛ¿Æ»¤ÀíAIÈí¼þ½â¾ö¹æ»®ÌṩÉÌ£¬Õ¼ÓÐ170¶àÃûºÏ×÷Ñé¹âʦ£¬ÖÎÀí×ų¬¹ý15Íò´Î»¼Õß¾ÍÕï¡£Õâ´Îй¶µÄÊý¾Ý²»½öÔ̺¬¾ßÌåµÄÑۿƲ鳻㱨£¬»¹ÓÐCSVºÍXLSµç×Ó±í¸ñ£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈ¹Ø¼üÐÅÏ¢¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ½¡È«±êʶ·û£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚڲƣ¬µ«¿ÉÄÜΪ·¸×ï·Ö×ÓÌṩ¹¹½¨Ó×ÎÒÈ«Ãæµµ°¸µÄ³ÁÒªÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾Ý¿âµÄ¾ßÌåÖÎÀí·½¼°Ð¹Â¶³ÖÐø¹¦·ò£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÕÆ¹ÜÈεÄÅû¶֪ͨ£¬²¢´ÙʹÆäѸ¿ìÏÞ¶ÈÁ˹«¼Ò½Ó¼û¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯¹ý³Ì¼Ó¿ì£¬Êý¾Ýй¶·çÏÕÈÕÒæÍ¹ÏÔ£¬¸ø»¼Õß´øÀ´¾Þ´óÒþÖÔÍþв¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÆ÷³ÁÍøÂ簲ȫ£¬²Éȡǿ¼ÓÃÜ¡¢Ñϸñ½Ó¼û½ÚÔìºÍ¶¨ÆÚ°²È«Éó¼ÆµÈ´ëÊ©£¬È·±£»¼ÕßÐÅÏ¢µÄ°²È«¡£
https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/
6. µÂ¹úBSI·ÛËé3Íǫ̀Android IoTÉ豸ÖÐBadBox¶ñÒâÈí¼þ
12ÔÂ13ÈÕ£¬µÂ¹úÁª¹úÐÅÏ¢°²È«¾Ö£¨BSI£©ÒѲÉÈ¡Ðж¯£¬·ÛËéÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoTÉ豸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢×°ÖÃÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì½Ó¼ûµÄAndroid¶ñÒâÈí¼þ£¬ÖØÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌåÉ豸µÈ¡£BSIͨ¹ý³Á¶´´¦Öã¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäºÅÁîºÍ½ÚÔì·þÎñÆ÷µÄͨѶ£¬´Ó¶øÓÐЧ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐС£ÊÜϰȾÉ豸µÄËùÓÐÕß½«Æ¾¾ÝIPµØÖ·ÊÕµ½Í¨Öª£¬²¢¸Ãµ±¼´¶Ï¿ªÉ豸ÓëÍøÂçµÄÏνӻòÖÕ³¡Ê¹Ó㬲¢Í˻ػòÅׯú¸ÃÉ豸¡£BSIÖÒ¸æ³Æ£¬ËùÓÐÊÜÓ°ÏìµÄÉ豸¶¼ÔËÐÐ׏ýÆÚµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ£¬Òò¶ø¼´±ãÒÑ·À±¸BadBox£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£Ïû·ÑÕßÓ¦Ö»²É°ìÀ´×Ô¸ºÓþÓÅÁ¼µÄÔì×÷É̵ÄÖÇÄÜÉ豸£¬²¢Ñ°ÕÒÌṩ³Ö¾Ã°²È«Ö§³ÖµÄ²úÆ·¡£
https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/


¾©¹«Íø°²±¸11010802024551ºÅ