Prometheus·þÎñÆ÷ÃæÁÙ¶àÖØÄþ¾²Íþв£¬Ðè¼ÓÇ¿·À»¤
Ðû²¼Ê±¼ä 2024-12-161. Prometheus·þÎñÆ÷ÃæÁÙ¶àÖØÄþ¾²Íþв£¬Ðè¼ÓÇ¿·À»¤
12ÔÂ12ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢³ö¾¯¸æ£¬Ö¸³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨·þÎñÆ÷ÃæÁÙÖØ´óÄþ¾²·çÏÕ¡£ÕâЩ·þÎñÆ÷ÓÉÓÚȱ·¦Êʵ±µÄÉí·ÝÑéÖ¤£¬ÈÝÒ×ÔâÊÜÐÅϢй¶¡¢¾Ü¾ø·þÎñ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¾ÝÔ¤¼Æ£¬ÓÐÊýÊ®Íǫ̀ Prometheus ʵÀýºÍ·þÎñÆ÷¿Éͨ¹ý»¥ÁªÍø¹ûÈ»·ÃÎÊ£¬ÐγÉÁËÒ»¸ö¾Þ´óµÄ¹¥»÷Ã棬¿ÉÄÜʹÊý¾ÝºÍ·þÎñÊܵ½Íþв¡£¹¥»÷Õß¿ÉÒÔÇáËɵØÊÕ¼¯Ãô¸ÐÐÅÏ¢£¬Èçƾ֤ºÍAPIÃÜÔ¿£¬²¢Ö±½Ó²éѯÄÚ²¿Êý¾Ý£¬Ì»Â¶ÃØÃÜ£¬½ø¶øÔÚ×éÖ¯ÖлñµÃ¿ª¶ËÁ¢×ãµã¡£´ËÍ⣬¡°/debug/pprof¡±¶ËµãµÄ̻¶¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌ壬µ¼Ö·þÎñÆ÷Í߽⡣AquaÄþ¾²¹«Ë¾»¹·¢ÏÖ¹©Ó¦Á´Íþв£¬°üÂÞʹÓûعº½Ù³Ö¼¼ÊõÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£×Ô2024Äê9ÔÂÆð£¬PrometheusÄþ¾²ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£Ñо¿ÈËÔ±½¨Òé×éÖ¯½ÓÄÉÊʵ±µÄÉí·ÝÑéÖ¤ÒªÁì±£»¤Prometheus·þÎñÆ÷ºÍµ¼³öÆ÷£¬ÏÞÖƹûÈ»Æع⣬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³£»î¶¯£¬ÒÔÖÆÖ¹Äþ¾²·çÏÕ¡£
https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html
2. Î÷°àÑÀÃس¾¯·½ÁªÊÖ¹¥»÷´ó¹æÄ£ÓïÒôÍøÂçµöÓãÕ©Æ
12ÔÂ12ÈÕ£¬Î÷°àÑÀ¾¯·½ÓëÃس¾¯·½ºÏ×÷£¬Àֳɹ¥»÷ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂçµöÓãÕ©ÆÍŻÁ½¹ú¹²´þ²¶ÁË83Ãû·¸×ïÏÓÒÉÈË¡£ÆäÖУ¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶£¬°üÂÞÂíµÂÀï¡¢°ÍÈûÂÞÄǵȵأ¬ÁíÓÐ48ÈËÔÚÃسÂäÍø¡£ÔÚÐж¯ÖУ¬¾¯·½»¹×¥»ñÁ˸÷¸×ïÍÅ»ïµÄÍ·Ä¿£¬²¢½É»ñÁË´óÁ¿ÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¸ÃÍÅ»ï¾Óª×Å´óÐͺô½ÐÖÐÐÄ£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤£¬Í¨¹ýð³äÒøÐпͷþ£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ½Å±¾£¬ÓÕÆÖÁÉÙ10,000ÈËй¶Ãô¸ÐÒøÐÐÐÅÏ¢£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£ËûÃÇʹÓÃÀ´µçÆÛƼ¼ÊõÔö¼Ó¿ÉÐŶȣ¬ÒÔδ¾ÊÚȨµÄATMÈ¡¿î¾¯±¨ÎªÓÕ¶ü£¬Òýµ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£ÏÖ½ðÌáÈ¡ºó£¬²¿ÃŻᱻÔËÓªÉ̱£Áô£¬ÆäÓàÔòËÍÍùÃسµÄ×éÖ¯¡£¾¯·½Ç¿µ÷£¬·¸×ï·Ö×ÓʹÓÃÑÕÉ«´úÂëʶ±ðÒøÐÐ×éÖ¯£¬ÊèÉ¢Ìع¤µ½²îÒ춼ÊÐÒÔÔö¼Ó×·×ÙÄѶȡ£Îª·ÀÖ¹Õ©Æ£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐÐÊðÀíÈ˽»Ì¸ºó²ÅÌṩ¸öÈËÐÅÏ¢£¬²¢¼ÇסÒøÐоø²»»áÒªÇó͸¶¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/
3. ¶íÂÞ˹ÍøÂç¼äµý×éÖ¯GamaredonÀûÓÃAndroid¼äµýÈí¼þÇÔÈ¡Êý¾Ý
12ÔÂ13ÈÕ£¬¶íÂÞ˹ÍøÂç¼äµý×éÖ¯Gamaredon±»·¢ÏÖʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroid¼äµýÈí¼þϵÁУ¬Õë¶ÔÇ°ËÕÁª¹ú¼ÒµÄ¶íÓïÈËÊ¿½øÐмàÊÓºÍÇÔÈ¡Òƶ¯É豸Êý¾Ý¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Í¨¹ýľÂíTelegramÓ¦Ó÷¨Ê½»òð³äÈýÐÇKnoxÁ÷´«£¬¾ßÓÐÊÕ¼¯¶ÌÐÅ¡¢Â¼Òô¡¢¶¨Î»¡¢ÅÄÕյȶàÖÖ¹¦Ð§¡£¶øPlainGnomeÊÇÒ»¿î½ÏеĶ¨ÖÆAndroid¼à¿Ø¶ñÒâÈí¼þ£¬½ÓÄÉÁ½½×¶Î°²×°¹ý³Ì£¬Ô½·¢ÒþÃØÇÒÓÃ;¹ã·º£¬¾ßÓÐÓëBoneSpyÏàËƵÄÊý¾ÝÊÕ¼¯¹¦Ð§£¬²¢¼¯³ÉÁ˸߼¶¹¦Ð§ÒÔ½µµÍ¼ì²â·çÏÕ¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢ÏÖ£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÒýµ¼Êܺ¦ÕßÏÂÔصġ£Ñо¿ÈËÔ±Ö¸³ö£¬ÕâÏÔʾÁËGamaredon¶ÔAndroidÉ豸µÄÈÕÒæ¹Ø×¢£¬²¢½«Æä¼à¿ØÄÜÁ¦À©Õ¹µ½Òƶ¯É豸¡£¹È¸èÒÑÈ·ÈÏ£¬Google Play Protect¿ÉÒÔ×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£
https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/
4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÒµÎñ²¿ÃÅÔâºÚ¿Í¹¥»÷
12ÔÂ13ÈÕ£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾£¬Ò»¼ÒÔÚ25¸ö¹ú¼ÒÓµÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾£¬×¨ÃÅ´ÓÊÂÆû³µ¸ü»»Áã¼þ¡¢²¿¼þ¼°Î¬ÐÞµ÷Ñø·þÎñ£¬Æä¼ÓÄôóÒµÎñ²¿ÃŽüÆÚÔâÓöºÚ¿Í¹¥»÷¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯ½»Ò×ίԱ»áµÄFORM 8-KÎļþÖÐ͸¶£¬11ÔÂ13ÈÕ£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÒµÎñ²¿ÃŵÄITϵͳÔâÊÜÁËδ¾ÊÚȨµÄ·ÃÎÊ£¬µ¼ÖÂÒµÎñÔËÓªÖжϡ£LKQѸËÙ½ÓÄÉÐж¯£¬°üÂÞÆô¶¯Äþ¾²Ê¼þÏìÓ¦¼Æ»®¡¢ÓëÈ¡Ö¤ÊÓ²ìÔ±ºÏ×÷£¬²¢Í¨ÖªÖ´·¨²¿ÃÅ¡£¾·ÖÎö£¬¹«Ë¾ÈÏΪÒÑÓÐЧֹͣÍþв£¬ÇÒ³ý¸ÃÒµÎñ²¿ÃÅÍ⣬ÆäËûÒµÎñδÊÜÓ°Ï죬Ŀǰ¸Ã²¿ÃÅÒѽӽüÂú¸ººÉÔËת¡£LKQÔ¤¼Æ´Ë´Îʼþ²»»á¶Ô±¾²ÆÄêÊ£Óàʱ¼äµÄ²ÆÕþ»òÔËÓªÔì³ÉÖØ´óÓ°Ï죬²¢½«ÏòÍøÂç±£ÏÕ¹«Ë¾Ñ°ÇóÅâ³¥¡£¾¡¹ÜÄ¿Ç°ÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÉù³Æ¶Ô´Ë´ÎÏ®»÷ÂôÁ¦£¬µ«LKQ¾¯¸æ³Æ£¬ÊÜÓ°ÏìµÄÒµÎñÔÚ¼¸ÖÜÄÚ·ºÆðÖжϣ¬ÏÖÒѻָ´ÔËÓª¡£
https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/
5. Care1Êý¾Ý¿âÔâй¶£¬480Íò»¼ÕßÐÅÏ¢Æعâ
12ÔÂ13ÈÕ£¬ÍøÂçÄþ¾²Ñо¿Ô±Jeremiah Fowler½üÆÚ½Ò¶ÁËÒ»¸öÖØ´óÄþ¾²Òþ»¼£¬Ëû·¢ÏÖ¼ÓÄôóÒ½ÁƼ¼Êõ¹«Ë¾Care1µÄÒ»¸öδÊܱ£»¤Êý¾Ý¿â̻¶ÁËÁè¼Ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢²¡Ê·¼°¸öÈ˽¡¿µºÅÂ루PHN£©µÈ£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£Care1×÷ΪרҵµÄÑÛ¿Æ»¤ÀíAIÈí¼þ½â¾ö·½°¸ÌṩÉÌ£¬ÓµÓÐ170¶àÃûºÏ×÷Ñé¹âʦ£¬¹ÜÀí×ÅÁè¼Ý15Íò´Î»¼Õß¾ÍÕï¡£´Ë´Î鶵ÄÊý¾Ý²»½ö°üÂÞÏêϸµÄÑۿƼì²é³ÂËߣ¬»¹ÓÐCSVºÍXLSµç×Ó±í¸ñ£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈÒªº¦ÐÅÏ¢¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ½¡¿µ±êʶ·û£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚÆÛÕ©£¬µ«¿ÉÄÜΪ·¸×ï·Ö×ÓÌṩ¹¹½¨¸öÈËÈ«Ãæµµ°¸µÄÖØÒªÐÅÏ¢¡£Ä¿Ç°Éв»Çå³þÊý¾Ý¿âµÄ¾ßÌå¹ÜÀí·½¼°Ð¹Â¶Á¬Ðøʱ¼ä£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÂôÁ¦ÈεÄÅû¶֪ͨ£¬²¢´ÙʹÆäѸËÙÏÞÖÆÁ˹«ÖÚ·ÃÎÊ¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯½ø³Ì¼ÓËÙ£¬Êý¾Ýй¶·çÏÕÈÕÒæ͹ÏÔ£¬¸ø»¼Õß´øÀ´¾Þ´óÒþ˽Íþв¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÖØÊÓÍøÂçÄþ¾²£¬½ÓÄÉÇ¿¼ÓÃÜ¡¢Ñϸñ·ÃÎÊ¿ØÖƺͶ¨ÆÚÄþ¾²Éó¼ÆµÈ´ëÊ©£¬È·±£»¼ÕßÐÅÏ¢µÄÄþ¾²¡£
https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/
6. µÂ¹úBSIÆÆ»µ3Íǫ̀Android IoTÉ豸ÖÐBadBox¶ñÒâÈí¼þ
12ÔÂ13ÈÕ£¬µÂ¹úÁª°îÐÅÏ¢Äþ¾²¾Ö£¨BSI£©ÒѽÓÄÉÐж¯£¬ÆÆ»µÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoTÉ豸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢°²×°ÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì·ÃÎʵÄAndroid¶ñÒâÈí¼þ£¬Ö÷ÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌåÉ豸µÈ¡£BSIͨ¹ý³Á¶´´¦Öã¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäÃüÁîºÍ¿ØÖÆ·þÎñÆ÷µÄͨÐÅ£¬´Ó¶øÓÐЧ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐС£ÊÜѬȾÉ豸µÄËùÓÐÕß½«Æ¾¾ÝIPµØÖ·ÊÕµ½Í¨Öª£¬²¢Ó¦Á¢¼´¶Ï¿ªÉ豸ÓëÍøÂçµÄÁ¬½Ó»òֹͣʹÓ㬲¢Í˻ػòÅ×Æú¸ÃÉ豸¡£BSI¾¯¸æ³Æ£¬ËùÓÐÊÜÓ°ÏìµÄÉ豸¶¼ÔËÐÐ׏ýʱµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ£¬Òò´Ë¼´Ê¹ÒÑ·À·¶BadBox£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£Ïû·ÑÕßÓ¦Ö»¹ºÖÃÀ´×ÔÐÅÓþÁ¼ºÃµÄÖÆÔìÉ̵ÄÖÇÄÜÉ豸£¬²¢Ñ°ÕÒÌṩºã¾ÃÄþ¾²Ö§³ÖµÄ²úÎï¡£
https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/