Builder.aiÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
°ä²¼¹¦·ò 2024-12-241. Builder.aiÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
12ÔÂ20ÈÕ£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah Fowler·¢ÏÖÁËÒ»¸ö³Á´ó°²È«Òþ»¼£ºÒ»¸ö¿É¹«¿ª½Ó¼ûÇÒδ¼ÓÃܵÄ1.29TBÊý¾Ý¿â£¬ÊôÓÚÂ׶صÄAI¹«Ë¾Builder.ai£¬ÄÚº¬³¬¹ý300Íò±Ê¼Í¼¡£ÕâЩ¼Í¼Ô̺¬·¢Æ±¡¢±£ÃܺÍ̸¡¢Ë°ÎñÎļþ¡¢µç×ÓÓʼþ½ØÍ¼¼°ÔÆ´æ´¢ÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬ÑϳÁ¶³öÁ˿ͻ§ºÍ¹«Ë¾µÄÄÚ²¿Êý¾Ý¡£´ËÀàÐÅϢй¶¿ÉÄܵ¼ÖÂÍøÂç´¹µö¡¢·¢Æ±Ú²Æ¡¢Î´¾ÊÚȨµÄÔÆ½Ó¼ûµÈ·çÏÕ£¬²¢¶ÔBuilder.aiµÄÃûÓþÔì³ÉÇÖº¦¡£È»¶ø£¬ÁîÈËÓÇÓôµÄÊÇ£¬Builder.aiÔÚÊÕµ½°²È«Í¨Öªºó½üÒ»¸öÔ²ŲÉÈ¡´ëÊ©±£»¤Êý¾Ý¿â£¬ÕâÒý·¢ÁË¶ÔÆäÊÂÎñÏìӦЧÄܵÄÖÊÒÉ¡£×¨¼ÒÖ¸³ö£¬´ËÀàÊý¾Ý¿âÅäÖÃÃýÎóËä³£¼û£¬µ«ºó¹ûÑϳÁ£¬¼´±ãÊÇÓ×ÐͺڿÍ×éÖ¯Ò²ÄÜÀûÓÃÕâЩÐÅÏ¢½øÐжñÒâ¹¥»÷¡£¸üÔã¸âµÄÊÇ£¬Ð¹Â¶µÄÔÆ´æ´¢ÃÜÔ¿¿ÉÄÜʹºÚ¿Í¿ÉÄܽӼû¸ü¶àÃô¸ÐÊý¾Ý¡£Ö»¹ÜBuilder.ai½«ÑÓ³¤¹éÒòÓÚ¸´ÔÓµÄϵͳÒÀÀµ¹ØÏµ£¬Õâ¿ÉÄÜÉæ¼°µÚÈý·½³Ð°üÉÌ£¬µ«×êÑÐÈËÔ±ÈÔÇ¿µ÷¹¹½¨×îÓ×ÒÀÀµÐÔµÄϵͳµÄ³ÁÒªÐÔ£¬²¢½¨Òé×éÖ¯Ó¦°²È«´æ´¢¡¢¼ÓÃܲ¢¸ôÀëÖÎÀíÍ´´¦ºÍ½Ó¼ûÃÜÔ¿£¬ÒÔÔ¤·À±»¶ñÒâÀûÓá£
https://hackread.com/builder-ai-database-misconfiguration-expose-tb-records/
2. Rspack npmÈí¼þ°üÔâ¼ÓÃÜÍÚ¿ó¶ñÒâÈí¼þ¹¥»÷
12ÔÂ20ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖnpm°üÔâ·êÈëÇÖÊÂÎñ£¬¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄÁîÅÆ½«´øÓмÓÃÜÍÚ¿ó¶ñÒâÈí¼þµÄ°æ±¾°ä²¼ÖÁ¹Ù·½°ü×¢²á±í¡£RspackµÄ@rspack/coreºÍ@rspack/cliÁ½¸önpm°ü¾ù±»ÈëÇÖ£¬¸Ã¹¤¾ß±»°¢Àï°Í°Í¡¢ÑÇÂíÑ·¡¢DiscordºÍ΢ÈíµÈ¹«Ë¾Ñ¡È¡£¬Ã¿ÖÜÏÂÔØÁ¿±ðÀ볬¹ý30ÍòºÍ14.5Íò´Î¡£¶ñÒâ°æ±¾Ô̺¬´«ÊäÃô¸ÐÅäÏàÐÅÏ¢ºÍÍøÂçIPµØÖ·¡¢Î»ÏàÐÅÏ¢µÄ´úÂ룬²¢½«CPUʹÓÃÂÊÏÞ¶ÈÔÚ75%ÒÔÆ½ºâ»úÄܺÍÒþÃØÐÔ¡£¹¥»÷»¹½«Ï°È¾ÁìÓòÏÞ¶ÈÔÚÌØ¶¨¹ú¶È£¬ÈçÖйú¡¢¶íÂÞ˹µÈ£¬Ö¼ÔÚͨ¹ýpostinstall¾ç±¾ÔÚ×°ÖÃʱ´¥·¢XMRig¼ÓÃÜÇ®±ÒÍÚ¿óÈí¼þµÄÏÂÔØºÍÖ´ÐС£Ä¿Ç°£¬¶ñÒâ°æ±¾Òѱ»³·Ï£¬Ð°䲼Á˰²È«µÄ1.18°æ±¾£¬ÏîÄ¿ÊØ»¤ÈËÔ±ÒÑ×÷·ÏËùÓÐÁîÅÆ¡¢²é³È¨ÏÞ²¢ÉóºËÔ´´úÂë¡£´Ë±í£¬ÁíÒ»¸öÃûΪVantµÄnpm°üÒ²Ôâ·ê¹¥»÷£¬¶à¸ö±»Ï°È¾µÄ°æ±¾±»°ä²¼£¬Ä¿Ç°×îÐµİ²È«°æ±¾4.9.15ÒѰ䲼£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¡£
https://thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html
3. CISA½«Acclaim Systems USAHERDS·ì϶ÁÐΪÒÑÖª±»ÀûÓ÷ì϶
12ÔÂ23ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Acclaim Systems¿ª·¢µÄUSAHERDSϵͳÖеķì϶£¨CVE-2021-44207£¬CVSSÆÀ·Ö8.1£©ÁÐÈëÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£USAHERDSÊÇÒ»¿î»ùÓÚÍøÂçµÄÀûÓ÷¨Ê½£¬ÓÃÓÚÐÖúÃÀ¹ú¸÷Öݵ±¾Ö¸ú×ÙºÍÖÎÀí¶¯Î。ȫºÍ¼²²¡·¢×÷£¬ÊÇAgraGuard²úÆ·Ì×¼þµÄÒ»²¿ÃÅ¡£¸Ã·ì϶ԴÓÚÓ²±àÂëÆ¾Ö¤ÎÊÌ⣬ӰÏì7.4.0.1¼°¸üÔç°æ±¾µÄAcclaim USAHERDS WebÀûÓ÷¨Ê½£¬ÔÊÐí¹¥»÷ÕßÀûÓþ²Ì¬µÄValidationKeyºÍDecryptionKeyÖµÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÍøÂç¼äµý×éÖ¯APT41ÒÑÀûÓô˷ì϶ÈëÇÖÁËÃÀ¹ú¶à¸öÖݵ±¾ÖÍøÂç¡£2021Äê11Ô£¬Acclaim Systems°ä²¼Á˲¹¶¡ÒÔ½¨¸´´ËÎÊÌ⡣ƾ¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬Áª¹ú»ú¹¹±ØÐëÔÚ2025Äê1ÔÂ13ÈÕ֮ǰ½â¾ö´Ë·ì϶£¬ÒÔ±£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£Í¬Ê±£¬×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²éCISAµÄ·ì϶Ŀ¼£¬²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÓйØÎÊÌâ¡£
https://securityaffairs.com/172255/hacking/u-s-cisa-acclaim-systems-usaherds-flaw-known-exploited-vulnerabilities-catalog.html
4. Adobe°ä²¼´¹Î£°²È«¸üУ¬½¨¸´ColdFusionÑϳÁõè¾¶±éÀú·ì϶
12ÔÂ23ÈÕ£¬Adobe½üÆÚ°ä²¼ÁËÒ»ÏΣ°²È«¸üУ¬Ö¼ÔÚ½â¾öÆäColdFusion²úÆ·ÖеÄÒ»¸öÑϳÁ·ì϶£¨CVE-2024-53961£©¡£¸Ã·ì϶ӰÏìColdFusion 2023ºÍ2021°æ±¾£¬ÊôÓÚõè¾¶±éÀúÈõµã£¬¿ÉÄܵ¼Ö¹¥»÷Õß¶ÁÈ¡·þÎñÆ÷ÉϵÄËÁÒâÎļþ¡£Adobe½«´Ë·ì϶µÄÑϳÁˮƽ¶¨Îª¡°ÓÅÏȼ¶1¡±£¬²¢ÖÒ¸æ³Æ£¬ÓÉÓÚ´æÔÚÒ°±í¹¥»÷µÄ·çÏÕ£¬ÖÎÀíÔ±Ó¦¾¡¿ì×°Öð²È«²¹¶¡£¨ColdFusion 2021 Update 18ºÍColdFusion 2023 Update 12£©£¬²¢ÔÚ72Ó×ʱÄÚÀûÓÃÓйصݲȫÅäÖÃÉèÖá£Ö»¹ÜAdobeÉÐδȷÈÏ´Ë·ì϶ÊÇ·ñÒѱ»ÀûÓ㬵«½¨Òé¿Í»§²é¿´¸üеĴ®ÐйýÂËÆ÷Îĵµ£¬ÒÔ»ñÈ¡¸ü¶à¹ØÓÚ×èÖ¹²»°²È«¹¥»÷µÄÐÅÏ¢¡£´Ëǰ£¬CISAÔøÖÒ¸æ³Æ£¬õè¾¶±éÀú·ì϶ÊÇÆÕ±é´æÔڵݲȫ·ì϶Àà±ð£¬¶½´ÙÈí¼þ¹«Ë¾¼ÓÇ¿·À±¸¡£È¥Ä꣬CISA»¹ºÅÁîÁª¹ú»ú¹¹±£»¤ÆäAdobe ColdFusion·þÎñÆ÷£¬ÒÔ·À±¸Áí±íÁ½¸öÑϳÁ°²È«·ì϶£¬²¢Ð¹Â©ºÚ¿ÍÒ»ÏòÔÚÀûÓÃÁíÒ»¸ö¹Ø¼üµÄColdFusion·ì϶À´¹¥»÷µ±¾Ö·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-bug-with-poc-exploit-code/
5. EFCCͻϮÐж¯¸æ·¢´ó¹æÄ£ÍøÂç·¸×ï
12ÔÂ23ÈÕ£¬ÄáÈÕÀûÑÇEFCC½üÆÚÔÚÀ¸÷˹·¢Õ¹ÁËÒ»Ïî³Á´óÐж¯£¬¿ÛÁôÁË792ÃûÉæÏӲμӼÓÃÜÇ®±ÒͶ×ÊڲƺͰ®ÇéȦÌ×µÄÏÓÒÉÈË¡£Õâ´ÎÐж¯Õë¶ÔµÄÊÇλÓÚά¶àÀûÑǵºµÄÒ»¶°Æß²ã¹¹Öþ£¬¸æ·¢ÁËÒ»¸öÕë¶ÔÈ«ÇòÊܺ¦ÕßµÄÓÐ×éÖ¯ÍøÂç·¸×ï¡£¸Ã·¸×OÍÅͨ¹ýαÔìÉí·Ý³ÉÁ¢¸ÐÇé¹ØÏµ£¬°Ñ³ÖÊܺ¦Õß»ã¿î£¬ÒÔ¼°ÒýÓÕÊܺ¦Õß½øÈëÐéα¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨ÆÈ¡×ʽð¡£Õâ´ÎÐж¯²»½ö͹ÏÔÁËÏÖ´úÍøÂç·¸×ïµÄ¸´ÔÓÐÔºÍÈ«ÇòÐÔ£¬»¹½ÒʾÁËÍøÂç·¸×ïÒѾ·¢Õ¹³ÉΪ¸ß¶È×éÖ¯»¯µÄ·¸×ï״Ϊ£¬Ó빫˾ÔË×÷ÀàËÆ£¬ÓµÓÐÃ÷È·µÄ²ã¼¶ºÍ½ÇÉ«·Ö¹¤¡£Ëæ×ÅÍøÂç·¸×ï·Ö×Ó±äµÃÔ½À´Ô½¸ÉÁ·£¬Ó×ÎÒ±ØÐë²ÉÈ¡×Ô¶¯Õ½Êõ±£»¤×Ô¼º£¬ÈçºËÊµÍøÉϹØÏµ¡¢×êÑÐͶ×ÊÆ½Ì¨¡¢Ê¹Óð²È«Êý×ÖͨѶµÈ¡£Í¬Ê±£¬·¨Âɲ¿ÃÅÒ²±ØÒª¼ÓÇ¿¿ç¾³ºÏ×÷¡¢¼¼ÊõͶ×Ê¡¢Êý×Öȡ֤Åàѵ¡¢¹«¼ÒÒâʶ»î¶¯ºÍÍøÂç·¸×ï³ÍÖεȷ½ÃæµÄÖÂÁ¦£¬ÒÔÓ¦¶Ô¸´ÔÓµÄÍøÂç·¸×ï¡£
https://www.itsecurityguru.org/2024/12/23/792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise/?utm_source=rss&utm_medium=rss&utm_campaign=792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise
6. LLMÖúÁ¦¶ñÒâÈí¼þ±äÖÖÌӱܼì²â£¬ÍøÂç°²È«Ãæ¶ÔÐÂÌôÕ½
12ÔÂ23ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ£¬´óÐÍ˵»°Ä£ÐÍ£¨LLM£©±»ÓÃÓÚ´ó¹æÄ£ÌìÉú¶ñÒâJavaScript´úÂëµÄбäÖÖ£¬ÒÔÌӱܼì²â¡£Palo Alto Networks Unit 42µÄ×êÑÐÖ¸³ö£¬¹ÌÈ»LLMÄÑÒÔÖØÐ´´½¨¶ñÒâÈí¼þ£¬µ«·¸×ï·Ö×ÓÄܹ»ÇáËÉÀûÓÃËüÃdzÁд»ò»ìºÏÏÖÓжñÒâÈí¼þ£¬Ê¹Æä¸üÄѱ»¼ì²â¡£Í¨¹ý×ã¹»¶àµÄת»»£¬ÕâÖÖ²½ÖèÄܹ»½µµÍ¶ñÒâÈí¼þ·ÖÀàϵͳµÄ»úÄÜ£¬Ê¹ÆäÎóÅжñÒâ´úÂëΪÁ¼ÐÔ¡£²»Á¼ÐÐΪÕß»¹Ê¹ÓÃÈçWormGPTµÈ¹¤¾ß×Ô¶¯±àÐ´ÍøÂç´¹µöÓʼþºÍ´´½¨Ð¶ñÒâÈí¼þ¡£Í¬Ê±£¬Æ¥µÐÐÔ»úе½ø½¨¼¼Êõͨ¹ýת»»¶ñÒâÈí¼þÀ´Èƹý¼ì²â¡£ÕâЩ³ÁдµÄJavaScript´úÂë²»½öÌÓ¹ýÁËÆäËû¶ñÒâÈí¼þ·ÖÎöÆ÷µÄ¼ì²â£¬²¢ÇÒ¿´ÆðÀ´±È´«Í³»ìºÏ²½Öè¸üÌìÈ»¡£Unit 42°µÊ¾£¬Äܹ»ÀûÓÃÒ»ÑùÕ½Êõ³Áд¶ñÒâ´úÂ룬ÌìÉúÌá¸ß»úе½ø½¨Ä£ÐÍÎÈÖØÐÔµÄѵÁ·Êý¾Ý¡£´Ë±í£¬±±¿¨ÂÞÀ´ÄÉÖÝÁ¢´óѧѧÕßÉè¼ÆµÄTPUXtract²àÐÅ·¹¥»÷ÄÜÒÔ¸ßÕýÈ·ÂʶÔGoogle EdgeÕÅÁ¿´¦Öõ¥Ôª½øÐÐÄ£ÐÍÇÔÈ¡¹¥»÷£¬ÓÃÓÚ֪ʶ²úȨ͵ÇÔ»òºóÐøÍøÂç¹¥»÷¡£
https://thehackernews.com/2024/12/ai-could-generate-10000-malware.htm


¾©¹«Íø°²±¸11010802024551ºÅ