Builder.aiÊý¾Ý¿âÅäÖôíÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
Ðû²¼Ê±¼ä 2024-12-241. Builder.aiÊý¾Ý¿âÅäÖôíÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
12ÔÂ20ÈÕ£¬ÍøÂçÄþ¾²Ñо¿Ô±Jeremiah Fowler·¢ÏÖÁËÒ»¸öÖØ´óÄþ¾²Òþ»¼£ºÒ»¸ö¿É¹ûÈ»·ÃÎÊÇÒδ¼ÓÃܵÄ1.29TBÊý¾Ý¿â£¬ÊôÓÚÂ׶صÄAI¹«Ë¾Builder.ai£¬ÄÚº¬Áè¼Ý300ÍòÌõ¼Ç¼¡£ÕâЩ¼Ç¼°üÂÞ·¢Æ±¡¢±£ÃÜÐÒ顢˰ÎñÎļþ¡¢µç×ÓÓʼþ½Øͼ¼°ÔÆ´æ´¢ÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬ÑÏÖØ̻¶ÁË¿Í»§ºÍ¹«Ë¾µÄÄÚ²¿Êý¾Ý¡£´ËÀàÐÅϢй¶¿ÉÄܵ¼ÖÂÍøÂçµöÓã¡¢·¢Æ±ÆÛÕ©¡¢Î´¾ÊÚȨµÄÔÆ·ÃÎʵȷçÏÕ£¬²¢¶ÔBuilder.aiµÄÉùÓþÔì³ÉË𺦡£È»¶ø£¬ÁîÈ˵£ÓǵÄÊÇ£¬Builder.aiÔÚÊÕµ½Äþ¾²Í¨Öªºó½üÒ»¸öÔ²ŽÓÄÉ´ëÊ©±£»¤Êý¾Ý¿â£¬ÕâÒý·¢Á˶ÔÆäʼþÏìӦЧÂʵÄÖÊÒÉ¡£×¨¼ÒÖ¸³ö£¬´ËÀàÊý¾Ý¿âÅäÖôíÎóËä³£¼û£¬µ«ºó¹ûÑÏÖØ£¬¼´Ê¹ÊÇСÐͺڿÍ×éÖ¯Ò²ÄÜÀûÓÃÕâЩÐÅÏ¢½øÐжñÒâ¹¥»÷¡£¸üÔã¸âµÄÊÇ£¬Ð¹Â¶µÄÔÆ´æ´¢ÃÜÔ¿¿ÉÄÜʹºÚ¿ÍÄܹ»·ÃÎʸü¶àÃô¸ÐÊý¾Ý¡£¾¡¹ÜBuilder.ai½«ÑÓ³Ù¹éÒòÓÚÅÓ´óµÄϵͳÒÀÀµ¹Øϵ£¬Õâ¿ÉÄÜÉæ¼°µÚÈý·½³Ð°üÉÌ£¬µ«Ñо¿ÈËÔ±ÈÔÇ¿µ÷¹¹½¨×îСÒÀÀµÐÔµÄϵͳµÄÖØÒªÐÔ£¬²¢½¨Òé×éÖ¯Ó¦Äþ¾²´æ´¢¡¢¼ÓÃܲ¢¸ôÀë¹ÜÀíƾ¾ÝºÍ·ÃÎÊÃÜÔ¿£¬ÒÔ·ÀÖ¹±»¶ñÒâÀûÓá£
https://hackread.com/builder-ai-database-misconfiguration-expose-tb-records/
2. Rspack npmÈí¼þ°üÔâ¼ÓÃÜÍÚ¿ó¶ñÒâÈí¼þ¹¥»÷
12ÔÂ20ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖnpm°üÔâÊÜÈëÇÖʼþ£¬¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄÁîÅƽ«´øÓмÓÃÜÍÚ¿ó¶ñÒâÈí¼þµÄ°æ±¾Ðû²¼ÖÁ¹Ù·½°ü×¢²á±í¡£RspackµÄ@rspack/coreºÍ@rspack/cliÁ½¸önpm°ü¾ù±»ÈëÇÖ£¬¸Ã¹¤¾ß±»°¢Àï°Í°Í¡¢ÑÇÂíÑ·¡¢DiscordºÍ΢ÈíµÈ¹«Ë¾½ÓÄÉ£¬Ã¿ÖÜÏÂÔØÁ¿·Ö±ðÁè¼Ý30ÍòºÍ14.5Íò´Î¡£¶ñÒâ°æ±¾°üÂÞ´«ÊäÃô¸ÐÅäÖÃÐÅÏ¢ºÍÊÕ¼¯IPµØÖ·¡¢Î»ÖÃÐÅÏ¢µÄ´úÂ룬²¢½«CPUʹÓÃÂÊÏÞÖÆÔÚ75%ÒÔƽºâÐÔÄܺÍÒþÃØÐÔ¡£¹¥»÷»¹½«Ñ¬È¾·¶Î§ÏÞÖÆÔÚÌض¨¹ú¼Ò£¬ÈçÖйú¡¢¶íÂÞ˹µÈ£¬Ö¼ÔÚͨ¹ýpostinstall½Å±¾ÔÚ°²×°Ê±´¥·¢XMRig¼ÓÃÜ»õ±ÒÍÚ¿óÈí¼þµÄÏÂÔغÍÖ´ÐС£Ä¿Ç°£¬¶ñÒâ°æ±¾Òѱ»³·Ï£¬ÐÂÐû²¼ÁËÄþ¾²µÄ1.18°æ±¾£¬ÏîĿά»¤ÈËÔ±ÒÑ×÷·ÏËùÓÐÁîÅÆ¡¢¼ì²éȨÏÞ²¢ÉóºËÔ´´úÂë¡£´ËÍ⣬ÁíÒ»¸öÃûΪVantµÄnpm°üÒ²ÔâÊܹ¥»÷£¬¶à¸ö±»Ñ¬È¾µÄ°æ±¾±»Ðû²¼£¬Ä¿Ç°×îеÄÄþ¾²°æ±¾4.9.15ÒÑÐû²¼£¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±Éý¼¶¡£
https://thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html
3. CISA½«Acclaim Systems USAHERDS©¶´ÁÐΪÒÑÖª±»ÀûÓ鶴
12ÔÂ23ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©Òѽ«Acclaim Systems¿ª·¢µÄUSAHERDSϵͳÖеÄ©¶´£¨CVE-2021-44207£¬CVSSÆÀ·Ö8.1£©ÁÐÈëÆäÒÑÖª±»ÀûÓ鶴£¨KEV£©Ä¿Â¼¡£USAHERDSÊÇÒ»¿î»ùÓÚÍøÂçµÄÓ¦Ó÷¨Ê½£¬ÓÃÓÚÐÖúÃÀ¹ú¸÷ÖÝÕþ¸®¸ú×ٺ͹ÜÀí¶¯Î。¿µºÍ¼²²¡·¢×÷£¬ÊÇAgraGuard²úÎïÌ×¼þµÄÒ»²¿ÃÅ¡£¸Ã©¶´Ô´ÓÚÓ²±àÂëƾ֤ÎÊÌ⣬ӰÏì7.4.0.1¼°¸üÔç°æ±¾µÄAcclaim USAHERDS WebÓ¦Ó÷¨Ê½£¬ÔÊÐí¹¥»÷ÕßÀûÓþ²Ì¬µÄValidationKeyºÍDecryptionKeyÖµÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£ÍøÂç¼äµý×éÖ¯APT41ÒÑÀûÓôË©¶´ÈëÇÖÁËÃÀ¹ú¶à¸öÖÝÕþ¸®ÍøÂç¡£2021Äê11Ô£¬Acclaim SystemsÐû²¼Á˲¹¶¡ÒÔÐÞ¸´´ËÎÊÌ⡣ƾ¾Ý¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬Áª°î»ú¹¹±ØÐëÔÚ2025Äê1ÔÂ13ÈÕ֮ǰ½â¾ö´Ë©¶´£¬ÒÔ±£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£Í¬Ê±£¬×¨¼ÒÒ²½¨Òé˽ÈË×éÖ¯Éó²éCISAµÄ©¶´Ä¿Â¼£¬²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÏà¹ØÎÊÌâ¡£
https://securityaffairs.com/172255/hacking/u-s-cisa-acclaim-systems-usaherds-flaw-known-exploited-vulnerabilities-catalog.html
4. AdobeÐû²¼½ô¼±Äþ¾²¸üУ¬ÐÞ¸´ColdFusionÑÏÖØ·¾¶±éÀú©¶´
12ÔÂ23ÈÕ£¬Adobe½üÆÚÐû²¼ÁËÒ»Ïî½ô¼±Äþ¾²¸üУ¬Ö¼ÔÚ½â¾öÆäColdFusion²úÎïÖеÄÒ»¸öÑÏÖØ©¶´£¨CVE-2024-53961£©¡£¸Ã©¶´Ó°ÏìColdFusion 2023ºÍ2021°æ±¾£¬ÊôÓÚ·¾¶±éÀúÈõµã£¬¿ÉÄܵ¼Ö¹¥»÷Õ߶ÁÈ¡·þÎñÆ÷ÉϵÄÈÎÒâÎļþ¡£Adobe½«´Ë©¶´µÄÑÏÖØˮƽ¶¨Îª¡°ÓÅÏȼ¶1¡±£¬²¢¾¯¸æ³Æ£¬ÓÉÓÚ´æÔÚÒ°Íâ¹¥»÷µÄ·çÏÕ£¬¹ÜÀíÔ±Ó¦¾¡¿ì°²×°Äþ¾²²¹¶¡£¨ColdFusion 2021 Update 18ºÍColdFusion 2023 Update 12£©£¬²¢ÔÚ72СʱÄÚÓ¦ÓÃÏà¹ØµÄÄþ¾²ÅäÖÃÉèÖ᣾¡¹ÜAdobeÉÐδȷÈÏ´Ë©¶´ÊÇ·ñÒѱ»ÀûÓ㬵«½¨Òé¿Í»§¼ì²ì¸üеĴ®ÐйýÂËÆ÷Îĵµ£¬ÒÔ»ñÈ¡¸ü¶à¹ØÓÚ×èÖ¹²»Äþ¾²¹¥»÷µÄÐÅÏ¢¡£´ËÇ°£¬CISAÔø¾¯¸æ³Æ£¬Â·¾¶±éÀú©¶´ÊÇÆÕ±é´æÔÚµÄÄþ¾²Â©¶´Àà±ð£¬¶Ø´ÙÈí¼þ¹«Ë¾¼ÓÇ¿·À·¶¡£È¥Ä꣬CISA»¹ÃüÁîÁª°î»ú¹¹±£»¤ÆäAdobe ColdFusion·þÎñÆ÷£¬ÒÔ·À·¶ÁíÍâÁ½¸öÑÏÖØÄþ¾²Â©¶´£¬²¢Í¸Â¶ºÚ¿ÍÒ»Ö±ÔÚÀûÓÃÁíÒ»¸öÒªº¦µÄColdFusion©¶´À´¹¥»÷Õþ¸®·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-bug-with-poc-exploit-code/
5. EFCCͻϮÐж¯½Ò¶´ó¹æÄ£ÍøÂç·¸×ï
12ÔÂ23ÈÕ£¬ÄáÈÕÀûÑÇEFCC½üÆÚÔÚÀ¸÷˹չ¿ªÁËÒ»ÏîÖØ´óÐж¯£¬´þ²¶ÁË792ÃûÉæÏÓ¼ÓÈë¼ÓÃÜ»õ±ÒͶ×ÊÆÛÕ©ºÍÁµ°®Æ¾ÖµÄÏÓÒÉÈË¡£´Ë´ÎÐж¯Õë¶ÔµÄÊÇλÓÚά¶àÀûÑǵºµÄÒ»¶°Æ߲㽨Öþ£¬½Ò¶ÁËÒ»¸öÕë¶ÔÈ«ÇòÊܺ¦ÕßµÄÓÐ×éÖ¯ÍøÂç·¸×ï¡£¸Ã·¸×OÍÅͨ¹ýαÔìÉí·Ý½¨Á¢Çé¸Ð¹Øϵ£¬ÀûÓÃÊܺ¦Õß»ã¿î£¬ÒÔ¼°ÒýÓÕÊܺ¦Õß½øÈëÐé¼Ù¼ÓÃÜ»õ±ÒͶ×Êƽ̨ÆÈ¡×ʽ𡣴˴ÎÐж¯²»½ö͹ÏÔÁËÏÖ´úÍøÂç·¸×ïµÄÅÓ´óÐÔºÍÈ«ÇòÐÔ£¬»¹½ÒʾÁËÍøÂç·¸×ïÒѾÉú³¤³ÉΪ¸ß¶È×éÖ¯»¯µÄ·¸×ïÐÐΪ£¬Ó빫˾ÔË×÷ÏàËÆ£¬¾ßÓÐÃ÷È·µÄ²ã¼¶ºÍ½ÇÉ«·Ö¹¤¡£Ëæ×ÅÍøÂç·¸×ï·Ö×Ó±äµÃÔ½À´Ô½ÀÏÁ·£¬¸öÈ˱ØÐë½ÓÄÉÖ÷¶¯¼Æı±£»¤×Ô¼º£¬ÈçºËʵÍøÉϹØϵ¡¢Ñо¿Í¶×Êƽ̨¡¢Ê¹ÓÃÄþ¾²Êý×ÖͨÐŵȡ£Í¬Ê±£¬Ö´·¨²¿ÃÅÒ²ÐèÒª¼ÓÇ¿¿ç¾³ºÏ×÷¡¢¼¼ÊõͶ×Ê¡¢Êý×ÖÈ¡Ö¤Åàѵ¡¢¹«ÖÚÒâʶÔ˶¯ºÍÍøÂç·¸×ï´¦·£µÈ·½ÃæµÄŬÁ¦£¬ÒÔÓ¦¶ÔÅÓ´óµÄÍøÂç·¸×ï¡£
https://www.itsecurityguru.org/2024/12/23/792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise/?utm_source=rss&utm_medium=rss&utm_campaign=792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise
6. LLMÖúÁ¦¶ñÒâÈí¼þ±äÖÖÌӱܼì²â£¬ÍøÂçÄþ¾²ÃæÁÙÐÂÌôÕ½
12ÔÂ23ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖ£¬´óÐÍÓïÑÔÄ£ÐÍ£¨LLM£©±»ÓÃÓÚ´ó¹æÄ£Éú³É¶ñÒâJavaScript´úÂëµÄбäÖÖ£¬ÒÔÌӱܼì²â¡£Palo Alto Networks Unit 42µÄÑо¿Ö¸³ö£¬ËäÈ»LLMÄÑÒÔÖØд´½¨¶ñÒâÈí¼þ£¬µ«·¸×ï·Ö×Ó¿ÉÒÔÇáËÉÀûÓÃËüÃÇÖØд»ò»ìÏýÏÖÓжñÒâÈí¼þ£¬Ê¹Æä¸üÄѱ»¼ì²â¡£Í¨¹ý×ã¹»¶àµÄת»»£¬ÕâÖÖÒªÁì¿ÉÒÔ½µµÍ¶ñÒâÈí¼þ·ÖÀàϵͳµÄÐÔÄÜ£¬Ê¹ÆäÎóÅжñÒâ´úÂëΪÁ¼ÐÔ¡£²»Á¼ÐÐΪÕß»¹Ê¹ÓÃÈçWormGPTµÈ¹¤¾ß×Ô¶¯±àдÍøÂçµöÓãÓʼþºÍ´´½¨Ð¶ñÒâÈí¼þ¡£Í¬Ê±£¬·´¿¹ÐÔ»úÆ÷ѧϰ¼¼Êõͨ¹ýת»»¶ñÒâÈí¼þÀ´Èƹý¼ì²â¡£ÕâЩÖØдµÄJavaScript´úÂë²»½öÌÓ¹ýÁËÆäËû¶ñÒâÈí¼þ·ÖÎöÆ÷µÄ¼ì²â£¬¶øÇÒ¿´ÆðÀ´±È´«Í³»ìÏýÒªÁì¸ü×ÔÈ»¡£Unit 42ÌåÏÖ£¬¿ÉÒÔÀûÓÃÏàͬ¼ÆıÖØд¶ñÒâ´úÂ룬Éú³ÉÌá¸ß»úÆ÷ѧϰģÐÍÎȽ¡ÐÔµÄѵÁ·Êý¾Ý¡£´ËÍ⣬±±¿¨ÂÞÀ´ÄÉÖÝÁ¢´óѧѧÕßÉè¼ÆµÄTPUXtract²àÐŵÀ¹¥»÷ÄÜÒÔ¸ß׼ȷÂʶÔGoogle EdgeÕÅÁ¿´¦Öõ¥Ôª½øÐÐÄ£ÐÍÇÔÈ¡¹¥»÷£¬ÓÃÓÚ֪ʶ²úȨ͵ÇÔ»òºóÐøÍøÂç¹¥»÷¡£
https://thehackernews.com/2024/12/ai-could-generate-10000-malware.htm