Builder.aiÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
°ä²¼¹¦·ò 2024-12-241. Builder.aiÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ1.29TBÊý¾Ý¿âй¶
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah Fowler·¢ÏÖÁËÒ»¸ö³Á´ó°²È«Òþ»¼£ºÒ»¸ö¿É¹«¿ª½Ó¼ûÇÒδ¼ÓÃܵÄ1.29TBÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬ÊôÓÚÂ׶صÄAI¹«Ë¾Builder.ai£¬£¬£¬£¬£¬£¬£¬£¬ÄÚº¬³¬¹ý300Íò±Ê¼Í¼¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼Ô̺¬·¢Æ±¡¢±£ÃܺÍ̸¡¢Ë°ÎñÎļþ¡¢µç×ÓÓʼþ½ØÍ¼¼°ÔÆ´æ´¢ÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÑϳÁ¶³öÁ˿ͻ§ºÍ¹«Ë¾µÄÄÚ²¿Êý¾Ý¡£¡£¡£¡£¡£¡£¡£´ËÀàÐÅϢй¶¿ÉÄܵ¼ÖÂÍøÂç´¹µö¡¢·¢Æ±Ú²Æ¡¢Î´¾ÊÚȨµÄÔÆ½Ó¼ûµÈ·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢¶ÔBuilder.aiµÄÃûÓþÔì³ÉÇÖº¦¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬ÁîÈËÓÇÓôµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Builder.aiÔÚÊÕµ½°²È«Í¨Öªºó½üÒ»¸öÔ²ŲÉÈ¡´ëÊ©±£»£»£»£»£»£»¤Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒý·¢ÁË¶ÔÆäÊÂÎñÏìӦЧÄܵÄÖÊÒÉ¡£¡£¡£¡£¡£¡£¡£×¨¼ÒÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬´ËÀàÊý¾Ý¿âÅäÖÃÃýÎóËä³£¼û£¬£¬£¬£¬£¬£¬£¬£¬µ«ºó¹ûÑϳÁ£¬£¬£¬£¬£¬£¬£¬£¬¼´±ãÊÇÓ×ÐͺڿÍ×éÖ¯Ò²ÄÜÀûÓÃÕâЩÐÅÏ¢½øÐжñÒâ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸üÔã¸âµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÔÆ´æ´¢ÃÜÔ¿¿ÉÄÜʹºÚ¿Í¿ÉÄܽӼû¸ü¶àÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜBuilder.ai½«ÑÓ³¤¹éÒòÓÚ¸´ÔÓµÄϵͳÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÉæ¼°µÚÈý·½³Ð°üÉÌ£¬£¬£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÈÔÇ¿µ÷¹¹½¨×îÓ×ÒÀÀµÐÔµÄϵͳµÄ³ÁÒªÐÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨Òé×éÖ¯Ó¦°²È«´æ´¢¡¢¼ÓÃܲ¢¸ôÀëÖÎÀíÍ´´¦ºÍ½Ó¼ûÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À±»¶ñÒâÀûÓᣡ£¡£¡£¡£¡£¡£
https://hackread.com/builder-ai-database-misconfiguration-expose-tb-records/
2. Rspack npmÈí¼þ°üÔâ¼ÓÃÜÍÚ¿ó¶ñÒâÈí¼þ¹¥»÷
12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖnpm°üÔâ·êÈëÇÖÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄÁîÅÆ½«´øÓмÓÃÜÍÚ¿ó¶ñÒâÈí¼þµÄ°æ±¾°ä²¼ÖÁ¹Ù·½°ü×¢²á±í¡£¡£¡£¡£¡£¡£¡£RspackµÄ@rspack/coreºÍ@rspack/cliÁ½¸önpm°ü¾ù±»ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß±»°¢Àï°Í°Í¡¢ÑÇÂíÑ·¡¢DiscordºÍ΢ÈíµÈ¹«Ë¾Ñ¡È¡£¬£¬£¬£¬£¬£¬£¬£¬Ã¿ÖÜÏÂÔØÁ¿±ðÀ볬¹ý30ÍòºÍ14.5Íò´Î¡£¡£¡£¡£¡£¡£¡£¶ñÒâ°æ±¾Ô̺¬´«ÊäÃô¸ÐÅäÏàÐÅÏ¢ºÍÍøÂçIPµØÖ·¡¢Î»ÏàÐÅÏ¢µÄ´úÂ룬£¬£¬£¬£¬£¬£¬£¬²¢½«CPUʹÓÃÂÊÏÞ¶ÈÔÚ75%ÒÔÆ½ºâ»úÄܺÍÒþÃØÐÔ¡£¡£¡£¡£¡£¡£¡£¹¥»÷»¹½«Ï°È¾ÁìÓòÏÞ¶ÈÔÚÌØ¶¨¹ú¶È£¬£¬£¬£¬£¬£¬£¬£¬ÈçÖйú¡¢¶íÂÞ˹µÈ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýpostinstall¾ç±¾ÔÚ×°ÖÃʱ´¥·¢XMRig¼ÓÃÜÇ®±ÒÍÚ¿óÈí¼þµÄÏÂÔØºÍÖ´ÐС£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâ°æ±¾Òѱ»³·Ï£¬£¬£¬£¬£¬£¬£¬£¬Ð°䲼Á˰²È«µÄ1.18°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÏîÄ¿ÊØ»¤ÈËÔ±ÒÑ×÷·ÏËùÓÐÁîÅÆ¡¢²é³È¨ÏÞ²¢ÉóºËÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÃûΪVantµÄnpm°üÒ²Ôâ·ê¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¶à¸ö±»Ï°È¾µÄ°æ±¾±»°ä²¼£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°×îÐµİ²È«°æ±¾4.9.15ÒѰ䲼£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html
3. CISA½«Acclaim Systems USAHERDS·ì϶ÁÐΪÒÑÖª±»ÀûÓ÷ì϶
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Acclaim Systems¿ª·¢µÄUSAHERDSϵͳÖеķì϶£¨CVE-2021-44207£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.1£©ÁÐÈëÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£¡£¡£USAHERDSÊÇÒ»¿î»ùÓÚÍøÂçµÄÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÐÖúÃÀ¹ú¸÷Öݵ±¾Ö¸ú×ÙºÍÖÎÀí¶¯Î。ȫºÍ¼²²¡·¢×÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÇAgraGuard²úÆ·Ì×¼þµÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚÓ²±àÂëÆ¾Ö¤ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Ó°Ïì7.4.0.1¼°¸üÔç°æ±¾µÄAcclaim USAHERDS WebÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÀûÓþ²Ì¬µÄValidationKeyºÍDecryptionKeyÖµÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÍøÂç¼äµý×éÖ¯APT41ÒÑÀûÓô˷ì϶ÈëÇÖÁËÃÀ¹ú¶à¸öÖݵ±¾ÖÍøÂç¡£¡£¡£¡£¡£¡£¡£2021Äê11Ô£¬£¬£¬£¬£¬£¬£¬£¬Acclaim Systems°ä²¼Á˲¹¶¡ÒÔ½¨¸´´ËÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬£¬£¬£¬£¬£¬£¬£¬Áª¹ú»ú¹¹±ØÐëÔÚ2025Äê1ÔÂ13ÈÕ֮ǰ½â¾ö´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²éCISAµÄ·ì϶Ŀ¼£¬£¬£¬£¬£¬£¬£¬£¬²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÓйØÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/172255/hacking/u-s-cisa-acclaim-systems-usaherds-flaw-known-exploited-vulnerabilities-catalog.html
4. Adobe°ä²¼´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ColdFusionÑϳÁõè¾¶±éÀú·ì϶
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Adobe½üÆÚ°ä²¼ÁËÒ»ÏΣ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½â¾öÆäColdFusion²úÆ·ÖеÄÒ»¸öÑϳÁ·ì϶£¨CVE-2024-53961£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìColdFusion 2023ºÍ2021°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÊôÓÚõè¾¶±éÀúÈõµã£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¶ÁÈ¡·þÎñÆ÷ÉϵÄËÁÒâÎļþ¡£¡£¡£¡£¡£¡£¡£Adobe½«´Ë·ì϶µÄÑϳÁˮƽ¶¨Îª¡°ÓÅÏȼ¶1¡±£¬£¬£¬£¬£¬£¬£¬£¬²¢ÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´æÔÚÒ°±í¹¥»÷µÄ·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±Ó¦¾¡¿ì×°Öð²È«²¹¶¡£¡£¡£¡£¡£¡£¡£¨ColdFusion 2021 Update 18ºÍColdFusion 2023 Update 12£©£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ72Ó×ʱÄÚÀûÓÃÓйصݲȫÅäÖÃÉèÖᣡ£¡£¡£¡£¡£¡£Ö»¹ÜAdobeÉÐδȷÈÏ´Ë·ì϶ÊÇ·ñÒѱ»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«½¨Òé¿Í»§²é¿´¸üеĴ®ÐйýÂËÆ÷Îĵµ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡¸ü¶à¹ØÓÚ×èÖ¹²»°²È«¹¥»÷µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬£¬£¬CISAÔøÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬õè¾¶±éÀú·ì϶ÊÇÆÕ±é´æÔڵݲȫ·ì϶Àà±ð£¬£¬£¬£¬£¬£¬£¬£¬¶½´ÙÈí¼þ¹«Ë¾¼ÓÇ¿·À±¸¡£¡£¡£¡£¡£¡£¡£È¥Ä꣬£¬£¬£¬£¬£¬£¬£¬CISA»¹ºÅÁîÁª¹ú»ú¹¹±£»£»£»£»£»£»¤ÆäAdobe ColdFusion·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ·À±¸Áí±íÁ½¸öÑϳÁ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢Ð¹Â©ºÚ¿ÍÒ»ÏòÔÚÀûÓÃÁíÒ»¸ö¹Ø¼üµÄColdFusion·ì϶À´¹¥»÷µ±¾Ö·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-bug-with-poc-exploit-code/
5. EFCCͻϮÐж¯¸æ·¢´ó¹æÄ£ÍøÂç·¸×ï
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÄáÈÕÀûÑÇEFCC½üÆÚÔÚÀ¸÷˹·¢Õ¹ÁËÒ»Ïî³Á´óÐж¯£¬£¬£¬£¬£¬£¬£¬£¬¿ÛÁôÁË792ÃûÉæÏӲμӼÓÃÜÇ®±ÒͶ×ÊڲƺͰ®ÇéȦÌ×µÄÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯Õë¶ÔµÄÊÇλÓÚά¶àÀûÑǵºµÄÒ»¶°Æß²ã¹¹Öþ£¬£¬£¬£¬£¬£¬£¬£¬¸æ·¢ÁËÒ»¸öÕë¶ÔÈ«ÇòÊܺ¦ÕßµÄÓÐ×éÖ¯ÍøÂç·¸×ï¡£¡£¡£¡£¡£¡£¡£¸Ã·¸×OÍÅͨ¹ýαÔìÉí·Ý³ÉÁ¢¸ÐÇé¹ØÏµ£¬£¬£¬£¬£¬£¬£¬£¬°Ñ³ÖÊܺ¦Õß»ã¿î£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÒýÓÕÊܺ¦Õß½øÈëÐéα¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨ÆÈ¡×ʽ𡣡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯²»½ö͹ÏÔÁËÏÖ´úÍøÂç·¸×ïµÄ¸´ÔÓÐÔºÍÈ«ÇòÐÔ£¬£¬£¬£¬£¬£¬£¬£¬»¹½ÒʾÁËÍøÂç·¸×ïÒѾ·¢Õ¹³ÉΪ¸ß¶È×éÖ¯»¯µÄ·¸×ï״Ϊ£¬£¬£¬£¬£¬£¬£¬£¬Ó빫˾ÔË×÷ÀàËÆ£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÃ÷È·µÄ²ã¼¶ºÍ½ÇÉ«·Ö¹¤¡£¡£¡£¡£¡£¡£¡£Ëæ×ÅÍøÂç·¸×ï·Ö×Ó±äµÃÔ½À´Ô½¸ÉÁ·£¬£¬£¬£¬£¬£¬£¬£¬Ó×ÎÒ±ØÐë²ÉÈ¡×Ô¶¯Õ½Êõ±£»£»£»£»£»£»¤×Ô¼º£¬£¬£¬£¬£¬£¬£¬£¬ÈçºËÊµÍøÉϹØÏµ¡¢×êÑÐͶ×ÊÆ½Ì¨¡¢Ê¹Óð²È«Êý×ÖͨѶµÈ¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬·¨Âɲ¿ÃÅÒ²±ØÒª¼ÓÇ¿¿ç¾³ºÏ×÷¡¢¼¼ÊõͶ×Ê¡¢Êý×Öȡ֤Åàѵ¡¢¹«¼ÒÒâʶ»î¶¯ºÍÍøÂç·¸×ï³ÍÖεȷ½ÃæµÄÖÂÁ¦£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÓ¦¶Ô¸´ÔÓµÄÍøÂç·¸×ï¡£¡£¡£¡£¡£¡£¡£
https://www.itsecurityguru.org/2024/12/23/792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise/?utm_source=rss&utm_medium=rss&utm_campaign=792-syndicate-suspects-arrested-in-massive-crypto-and-romance-scam-the-rise-of-cybercrime-as-a-corporate-enterprise
6. LLMÖúÁ¦¶ñÒâÈí¼þ±äÖÖÌӱܼì²â£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç°²È«Ãæ¶ÔÐÂÌôÕ½
12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬´óÐÍ˵»°Ä£ÐÍ£¨LLM£©±»ÓÃÓÚ´ó¹æÄ£ÌìÉú¶ñÒâJavaScript´úÂëµÄбäÖÖ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÌӱܼì²â¡£¡£¡£¡£¡£¡£¡£Palo Alto Networks Unit 42µÄ×êÑÐÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬¹ÌÈ»LLMÄÑÒÔÖØÐ´´½¨¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬µ«·¸×ï·Ö×ÓÄܹ»ÇáËÉÀûÓÃËüÃdzÁд»ò»ìºÏÏÖÓжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Æä¸üÄѱ»¼ì²â¡£¡£¡£¡£¡£¡£¡£Í¨¹ý×ã¹»¶àµÄת»»£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖ²½ÖèÄܹ»½µµÍ¶ñÒâÈí¼þ·ÖÀàϵͳµÄ»úÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÆäÎóÅжñÒâ´úÂëΪÁ¼ÐÔ¡£¡£¡£¡£¡£¡£¡£²»Á¼ÐÐΪÕß»¹Ê¹ÓÃÈçWormGPTµÈ¹¤¾ß×Ô¶¯±àÐ´ÍøÂç´¹µöÓʼþºÍ´´½¨Ð¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬£¬Æ¥µÐÐÔ»úе½ø½¨¼¼Êõͨ¹ýת»»¶ñÒâÈí¼þÀ´Èƹý¼ì²â¡£¡£¡£¡£¡£¡£¡£ÕâЩ³ÁдµÄJavaScript´úÂë²»½öÌÓ¹ýÁËÆäËû¶ñÒâÈí¼þ·ÖÎöÆ÷µÄ¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿´ÆðÀ´±È´«Í³»ìºÏ²½Öè¸üÌìÈ»¡£¡£¡£¡£¡£¡£¡£Unit 42°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓÃÒ»ÑùÕ½Êõ³Áд¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÌìÉúÌá¸ß»úе½ø½¨Ä£ÐÍÎÈÖØÐÔµÄѵÁ·Êý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬±±¿¨ÂÞÀ´ÄÉÖÝÁ¢´óѧѧÕßÉè¼ÆµÄTPUXtract²àÐÅ·¹¥»÷ÄÜÒÔ¸ßÕýÈ·ÂʶÔGoogle EdgeÕÅÁ¿´¦Öõ¥Ôª½øÐÐÄ£ÐÍÇÔÈ¡¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ֪ʶ²úȨ͵ÇÔ»òºóÐøÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/ai-could-generate-10000-malware.htm


¾©¹«Íø°²±¸11010802024551ºÅ