Builder.aiÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
Ðû²¼Ê±¼ä 2024-12-241. Builder.aiÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ô±Jeremiah Fowler·¢Ã÷ÁËÒ»¸öÖØ´óÇå¾²Òþ»¼£ºÒ»¸ö¿É¹ûÕæ»á¼ûÇÒδ¼ÓÃܵÄ1.29TBÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÊôÓÚÂ׶صÄAI¹«Ë¾Builder.ai£¬£¬£¬£¬£¬£¬ÄÚº¬Áè¼Ý300ÍòÌõ¼Í¼¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨·¢Æ±¡¢±£ÃÜÐÒ顢˰ÎñÎļþ¡¢µç×ÓÓʼþ½ØÍ¼¼°ÔÆ´æ´¢ÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ÑÏÖØÌ»Â¶Á˿ͻ§ºÍ¹«Ë¾µÄÄÚ²¿Êý¾Ý¡£¡£¡£¡£¡£´ËÀàÐÅϢй¶¿ÉÄܵ¼ÖÂÍøÂç´¹ÂÚ¡¢·¢Æ±Ú²Æ¡¢Î´¾ÊÚȨµÄÔÆ»á¼ûµÈΣº¦£¬£¬£¬£¬£¬£¬²¢¶ÔBuilder.aiµÄÉùÓþÔì³ÉË𺦡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ÁîÈ˵£ÐĵÄÊÇ£¬£¬£¬£¬£¬£¬Builder.aiÔÚÊÕµ½Ç徲֪ͨºó½üÒ»¸öÔ²ŽÓÄɲ½·¥±£»£»£»£»£»£»£»¤Êý¾Ý¿â£¬£¬£¬£¬£¬£¬ÕâÒý·¢ÁË¶ÔÆäÊÂÎñÏìӦЧÂʵÄÖÊÒÉ¡£¡£¡£¡£¡£×¨¼ÒÖ¸³ö£¬£¬£¬£¬£¬£¬´ËÀàÊý¾Ý¿âÉèÖùýʧËä³£¼û£¬£¬£¬£¬£¬£¬µ«Ð§¹ûÑÏÖØ£¬£¬£¬£¬£¬£¬×ÝÈ»ÊÇСÐͺڿÍ×éÖ¯Ò²ÄÜʹÓÃÕâЩÐÅÏ¢¾ÙÐжñÒâ¹¥»÷¡£¡£¡£¡£¡£¸üÔã¸âµÄÊÇ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÔÆ´æ´¢ÃÜÔ¿¿ÉÄÜʹºÚ¿ÍÄܹ»»á¼û¸ü¶àÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Ö»¹ÜBuilder.ai½«ÑÓ³Ù¹éÒòÓÚÖØ´óµÄϵͳÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÉæ¼°µÚÈý·½³Ð°üÉÌ£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÈÔÇ¿µ÷¹¹½¨×îСÒÀÀµÐÔµÄϵͳµÄÖ÷ÒªÐÔ£¬£¬£¬£¬£¬£¬²¢½¨Òé×éÖ¯Ó¦Çå¾²´æ´¢¡¢¼ÓÃܲ¢¸ôÀëÖÎÀíÆ¾Ö¤ºÍ»á¼ûÃÜÔ¿£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâ±»¶ñÒâʹÓᣡ£¡£¡£¡£
https://hackread.com/builder-ai-database-misconfiguration-expose-tb-records/
2. Rspack npmÈí¼þ°üÔâ¼ÓÃÜÍÚ¿ó¶ñÒâÈí¼þ¹¥»÷
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷npm°üÔâÊÜÈëÇÖÊÂÎñ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÇÔÈ¡µÄÁîÅÆ½«´øÓмÓÃÜÍÚ¿ó¶ñÒâÈí¼þµÄ°æ±¾Ðû²¼ÖÁ¹Ù·½°ü×¢²á±í¡£¡£¡£¡£¡£RspackµÄ@rspack/coreºÍ@rspack/cliÁ½¸önpm°ü¾ù±»ÈëÇÖ£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß±»°¢Àï°Í°Í¡¢ÑÇÂíÑ·¡¢DiscordºÍ΢ÈíµÈ¹«Ë¾½ÓÄÉ£¬£¬£¬£¬£¬£¬Ã¿ÖÜÏÂÔØÁ¿»®·ÖÁè¼Ý30ÍòºÍ14.5Íò´Î¡£¡£¡£¡£¡£¶ñÒâ°æ±¾°üÀ¨´«ÊäÃô¸ÐÉèÖÃÐÅÏ¢ºÍÍøÂçIPµØµã¡¢Î»ÖÃÐÅÏ¢µÄ´úÂ룬£¬£¬£¬£¬£¬²¢½«CPUʹÓÃÂÊÏÞÖÆÔÚ75%ÒÔÆ½ºâÐÔÄܺÍÒþÃØÐÔ¡£¡£¡£¡£¡£¹¥»÷»¹½«Ñ¬È¾¹æÄ£ÏÞÖÆÔÚÌØ¶¨¹ú¼Ò£¬£¬£¬£¬£¬£¬ÈçÖйú¡¢¶íÂÞ˹µÈ£¬£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýpostinstall¾ç±¾ÔÚ×°ÖÃʱ´¥·¢XMRig¼ÓÃÜÇ®±ÒÍÚ¿óÈí¼þµÄÏÂÔØºÍÖ´ÐС£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¶ñÒâ°æ±¾Òѱ»³·Ï£¬£¬£¬£¬£¬£¬ÐÂÐû²¼ÁËÇå¾²µÄ1.18°æ±¾£¬£¬£¬£¬£¬£¬ÏîĿά»¤Ö°Ô±ÒÑ×÷·ÏËùÓÐÁîÅÆ¡¢¼ì²éȨÏÞ²¢ÉóºËÔ´´úÂë¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÃûΪVantµÄnpm°üÒ²ÔâÊܹ¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö±»Ñ¬È¾µÄ°æ±¾±»Ðû²¼£¬£¬£¬£¬£¬£¬ÏÖÔÚ×îеÄÇå¾²°æ±¾4.9.15ÒÑÐû²¼£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html
3. CISA½«Acclaim Systems USAHERDSÎó²îÁÐΪÒÑÖª±»Ê¹ÓÃÎó²î
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Òѽ«Acclaim Systems¿ª·¢µÄUSAHERDSϵͳÖеÄÎó²î£¨CVE-2021-44207£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.1£©ÁÐÈëÆäÒÑÖª±»Ê¹ÓÃÎó²î£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£USAHERDSÊÇÒ»¿î»ùÓÚÍøÂçµÄÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬ÓÃÓÚÐÖúÃÀ¹ú¸÷ÖÝÕþ¸®¸ú×ÙºÍÖÎÀí¶¯Î￵½¡ºÍ¼²²¡±¬·¢£¬£¬£¬£¬£¬£¬ÊÇAgraGuard²úÆ·Ì×¼þµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÓ²±àÂëÆ¾Ö¤ÎÊÌ⣬£¬£¬£¬£¬£¬Ó°Ïì7.4.0.1¼°¸üÔç°æ±¾µÄAcclaim USAHERDS WebÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßʹÓþ²Ì¬µÄValidationKeyºÍDecryptionKeyÖµÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ÍøÂçÌØ¹¤×éÖ¯APT41ÒÑʹÓôËÎó²îÈëÇÖÁËÃÀ¹ú¶à¸öÖÝÕþ¸®ÍøÂç¡£¡£¡£¡£¡£2021Äê11Ô£¬£¬£¬£¬£¬£¬Acclaim SystemsÐû²¼Á˲¹¶¡ÒÔÐÞ¸´´ËÎÊÌâ¡£¡£¡£¡£¡£Æ¾Ö¤¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬£¬£¬£¬£¬£¬Áª°î»ú¹¹±ØÐèÔÚ2025Äê1ÔÂ13ÈÕ֮ǰ½â¾ö´ËÎó²î£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬×¨¼ÒÒ²½¨Òé˽ÈË×éÖ¯Éó²éCISAµÄÎó²îĿ¼£¬£¬£¬£¬£¬£¬²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÏà¹ØÎÊÌâ¡£¡£¡£¡£¡£
https://securityaffairs.com/172255/hacking/u-s-cisa-acclaim-systems-usaherds-flaw-known-exploited-vulnerabilities-catalog.html
4. AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ColdFusionÑÏÖØÂ·¾¶±éÀúÎó²î
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬Adobe½üÆÚÐû²¼ÁËÒ»Ïî½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬Ö¼ÔÚ½â¾öÆäColdFusion²úÆ·ÖеÄÒ»¸öÑÏÖØÎó²î£¨CVE-2024-53961£©¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìColdFusion 2023ºÍ2021°æ±¾£¬£¬£¬£¬£¬£¬ÊôÓÚ·¾¶±éÀúÈõµã£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¶ÁȡЧÀÍÆ÷ÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£Adobe½«´ËÎó²îµÄÑÏÖØË®Æ½¶¨Îª¡°ÓÅÏȼ¶1¡±£¬£¬£¬£¬£¬£¬²¢ÖÒÑԳƣ¬£¬£¬£¬£¬£¬ÓÉÓÚ±£´æÒ°Íâ¹¥»÷µÄΣº¦£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±Ó¦¾¡¿ì×°ÖÃÇå¾²²¹¶¡£¡£¡£¡£¡£¨ColdFusion 2021 Update 18ºÍColdFusion 2023 Update 12£©£¬£¬£¬£¬£¬£¬²¢ÔÚ72СʱÄÚÓ¦ÓÃÏà¹ØµÄÇå¾²ÉèÖÃÉèÖᣡ£¡£¡£¡£Ö»¹ÜAdobeÉÐδȷÈÏ´ËÎó²îÊÇ·ñÒѱ»Ê¹Ó㬣¬£¬£¬£¬£¬µ«½¨Òé¿Í»§Éó²é¸üеĴ®ÐйýÂËÆ÷Îĵµ£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡¸ü¶à¹ØÓÚ×èÖ¹²»Çå¾²¹¥»÷µÄÐÅÏ¢¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬CISAÔøÖÒÑԳƣ¬£¬£¬£¬£¬£¬Â·¾¶±éÀúÎó²îÊÇÆÕ±é±£´æµÄÇå¾²Îó²îÖֱ𣬣¬£¬£¬£¬£¬±Þ²ßÈí¼þ¹«Ë¾ÔöÇ¿Ìá·À¡£¡£¡£¡£¡£È¥Ä꣬£¬£¬£¬£¬£¬CISA»¹ÏÂÁîÁª°î»ú¹¹±£»£»£»£»£»£»£»¤ÆäAdobe ColdFusionЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÒÔÌá·ÀÁíÍâÁ½¸öÑÏÖØÇå¾²Îó²î£¬£¬£¬£¬£¬£¬²¢Í¸Â¶ºÚ¿ÍÒ»Ö±ÔÚʹÓÃÁíÒ»¸öÒªº¦µÄColdFusionÎó²îÀ´¹¥»÷Õþ¸®Ð§ÀÍÆ÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-bug-with-poc-exploit-code/
5. EFCCͻϮÐж¯½ÒÆÆ´ó¹æÄ£ÍøÂç·¸·¨
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬ÄáÈÕÀûÑÇEFCC½üÆÚÔÚÀ¸÷˹Õö¿ªÁËÒ»ÏîÖØ´óÐж¯£¬£¬£¬£¬£¬£¬¾Ð²¶ÁË792ÃûÉæÏÓ¼ÓÈë¼ÓÃÜÇ®±ÒͶ×ÊڲƺÍÁµ°®È¦Ì×µÄÏÓÒÉÈË¡£¡£¡£¡£¡£´Ë´ÎÐж¯Õë¶ÔµÄÊÇλÓÚά¶àÀûÑǵºµÄÒ»¶°Æß²ãÐÞ½¨£¬£¬£¬£¬£¬£¬½ÒÆÆÁËÒ»¸öÕë¶ÔÈ«ÇòÊܺ¦ÕßµÄÓÐ×éÖ¯ÍøÂç·¸·¨¡£¡£¡£¡£¡£¸Ã·¸·¨¼¯ÍÅͨ¹ýαÔìÉí·Ý½¨ÉèÇéÐ÷¹ØÏµ£¬£¬£¬£¬£¬£¬Ê¹ÓÃÊܺ¦Õß»ã¿î£¬£¬£¬£¬£¬£¬ÒÔ¼°ÒýÓÕÊܺ¦Õß½øÈëÐéα¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨ÆÈ¡×ʽ𡣡£¡£¡£¡£´Ë´ÎÐж¯²»µ«Í¹ÏÔÁËÏÖ´úÍøÂç·¸·¨µÄÖØ´óÐÔºÍÈ«ÇòÐÔ£¬£¬£¬£¬£¬£¬»¹Õ¹ÏÖÁËÍøÂç·¸·¨ÒѾÉú³¤³ÉΪ¸ß¶È×éÖ¯»¯µÄ·¸·¨ÐÐΪ£¬£¬£¬£¬£¬£¬Ó빫˾ÔË×÷ÏàËÆ£¬£¬£¬£¬£¬£¬¾ßÓÐÃ÷È·µÄ²ã¼¶ºÍ½ÇÉ«·Ö¹¤¡£¡£¡£¡£¡£Ëæ×ÅÍøÂç·¸·¨·Ö×Ó±äµÃÔ½À´Ô½ÀÏÁ·£¬£¬£¬£¬£¬£¬Ð¡ÎÒ˽¼Ò±ØÐè½ÓÄÉ×Ô¶¯Õ½ÂÔ±£»£»£»£»£»£»£»¤×Ô¼º£¬£¬£¬£¬£¬£¬ÈçºËÊµÍøÉϹØÏµ¡¢Ñо¿Í¶×ÊÆ½Ì¨¡¢Ê¹ÓÃÇå¾²Êý×ÖͨѶµÈ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬Ö´·¨²¿·ÖÒ²ÐèÒªÔöÇ¿¿ç¾³ÏàÖú¡¢ÊÖÒÕͶ×Ê¡¢Êý×Öȡ֤Åàѵ¡¢¹«ÖÚÒâʶÔ˶¯ºÍÍøÂç·¸·¨´¦·ÖµÈ·½ÃæµÄÆð¾¢£¬£¬£¬£¬£¬£¬ÒÔÓ¦¶ÔÖØ´óµÄÍøÂç·¸·¨¡£¡£¡£¡£¡£
https://www.itsecurityguru.org/2024/12/23/792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise/?utm_source=rss&utm_medium=rss&utm_campaign=792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise
6. LLMÖúÁ¦¶ñÒâÈí¼þ±äÖÖÌӱܼì²â£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÃæÁÙÐÂÌôÕ½
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬´óÐÍÓïÑÔÄ£×Ó£¨LLM£©±»ÓÃÓÚ´ó¹æÄ£ÌìÉú¶ñÒâJavaScript´úÂëµÄбäÖÖ£¬£¬£¬£¬£¬£¬ÒÔÌӱܼì²â¡£¡£¡£¡£¡£Palo Alto Networks Unit 42µÄÑо¿Ö¸³ö£¬£¬£¬£¬£¬£¬ËäÈ»LLMÄÑÒÔÖØÐ½¨Éè¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬µ«·¸·¨·Ö×Ó¿ÉÒÔÇáËÉʹÓÃËüÃÇÖØÐ´»ò»ìÏýÏÖÓжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Ê¹Æä¸üÄѱ»¼ì²â¡£¡£¡£¡£¡£Í¨¹ý×ã¹»¶àµÄת»»£¬£¬£¬£¬£¬£¬ÕâÖÖÒªÁì¿ÉÒÔ½µµÍ¶ñÒâÈí¼þ·ÖÀàϵͳµÄÐÔÄÜ£¬£¬£¬£¬£¬£¬Ê¹ÆäÎóÅжñÒâ´úÂëΪÁ¼ÐÔ¡£¡£¡£¡£¡£²»Á¼ÐÐΪÕß»¹Ê¹ÓÃÈçWormGPTµÈ¹¤¾ß×Ô¶¯±àÐ´ÍøÂç´¹ÂÚÓʼþºÍ½¨ÉèжñÒâÈí¼þ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬¶Ô¿¹ÐÔ»úеѧϰÊÖÒÕͨ¹ýת»»¶ñÒâÈí¼þÀ´Èƹý¼ì²â¡£¡£¡£¡£¡£ÕâÐ©ÖØÐ´µÄJavaScript´úÂë²»µ«ÌÓ¹ýÁËÆäËû¶ñÒâÈí¼þÆÊÎöÆ÷µÄ¼ì²â£¬£¬£¬£¬£¬£¬²¢ÇÒ¿´ÆðÀ´±È¹Å°å»ìÏýÒªÁì¸ü×ÔÈ»¡£¡£¡£¡£¡£Unit 42ÌåÏÖ£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃÏàͬսÂÔÖØÐ´¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬ÌìÉúÌá¸ß»úеѧϰģ×ÓÎȽ¡ÐÔµÄѵÁ·Êý¾Ý¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬±±¿¨ÂÞÀ´ÄÉÖÝÁ¢´óѧѧÕßÉè¼ÆµÄTPUXtract²àÐŵÀ¹¥»÷ÄÜÒÔ¸ß׼ȷÂʶÔGoogle EdgeÕÅÁ¿´¦Öóͷ£µ¥Î»¾ÙÐÐÄ£×ÓÇÔÈ¡¹¥»÷£¬£¬£¬£¬£¬£¬ÓÃÓÚ֪ʶ²úȨ͵ÇÔ»òºóÐøÍøÂç¹¥»÷¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/ai-could-generate-10000-malware.htm


¾©¹«Íø°²±¸11010802024551ºÅ