È«Çò³¬1200Íò.envÎļþ¹«¿ªÂ¶³ö
°ä²¼¹¦·ò 2026-03-021. È«Çò³¬1200Íò.envÎļþ¹«¿ªÂ¶³ö
2ÔÂ27ÈÕ£¬£¬£¬Mysterium VPN×êÑÐÈËÔ±·¢ÏÖÈ«Çò12,088,677¸öIPµØÖ·´æÔڿɹ«¿ª½Ó¼ûµÄ.envÌåʽÎļþ£¬£¬£¬Ð¹Â¶Ô̺¬JWTÊðÃûÃÜÔ¿¡¢¡¢¡¢APIÃÜÔ¿¡¢¡¢¡¢Êý¾Ý¿âÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£´ËÀàÎļþÒò´æ´¢ÀûÓ÷¨Ê½»·¾³±äÁ¿£¨ÈçÊý¾Ý¿âURL¡¢¡¢¡¢ÔƽӼûÃÜÔ¿£©¶ø¿í·ºÊ¹Ó㬣¬£¬µ«Æä¼ò½àÐÔÒ²´øÀ´·çÏÕ£¬£¬£¬Èô·þÎñÆ÷δÆÁ±Î°µ²ØÎļþ½Ó¼û£¬£¬£¬¹¥»÷Õß¿ÉÖ±½ÓÒªÇó"/.env"ÏÂÔØÊµÊ±Í´´¦£¬£¬£¬ÎÞÐèÀûÓ÷ì϶¼´¿ÉÈÆ¹ýÈëÇֽ׶Σ¬£¬£¬Ö±½ÓʹÓÃÓÐЧƾ֤µÇ¼ϵͳ¡¢¡¢¡¢²éÎÊÊý¾Ý¿â¡¢¡¢¡¢Î±ÔìÁîÅÆ»òÀÄÓÃAPI¡£¡£¡£¡£¡£Õâ´Îй¶³ÊÈ«ÇòÐÔÉ¢²¼£º£º£ºÃÀ¹úÊÜÓ°ÏìIP½ü280Íò£¨Õ¼23%£©£¬£¬£¬ÈÕ±¾¡¢¡¢¡¢µÂ¹ú¡¢¡¢¡¢Ó¡¶È¡¢¡¢¡¢·¨¹ú¡¢¡¢¡¢Ó¢¹úµÈ¹úÒ೬°ÙÍò£¬£¬£¬Åú×¢ÎÊÌâÔ´ÓÚ¿çÐÐÒµµÄÆÕ±éÔËάÃýÎ󣬣¬£¬¶ø·Çµ¥Ò»Æ½Ì¨È±µã¡£¡£¡£¡£¡£Ð¹Â¶ºó¹ûÑÏÖØ£¬£¬£¬Êý¾Ý¿âƾ֤¿ÉÖÂÊý¾ÝÇÔÈ¡£¬£¬£¬APIÃÜÔ¿¿ÉÄÜÒý·¢½ðÈÚÚ¿Æ£¬£¬£¬JWTÃÜÔ¿±»ÓÃÓÚÕË»§½Ù³Ö£¬£¬£¬SMTPƾ֤ÔòÖú³¤ÍøÂç´¹µö£¬£¬£¬ÔÆ´æ´¢ÃÜÔ¿¸ü¿ÉÄܶ³ö±¸·ÝÎļþÓëÄÚ²¿Îĵµ¡£¡£¡£¡£¡£µ××ÓÔÒò¶àÔ´ÓÚ¿ÉÔ¤·ÀµÄÅäÖÃʧÎ󣺣º£ºÈ±Ê§°µ²ØÎļþ»Ø¾ø¹æ¶¨¡¢¡¢¡¢·´Ïò´úÀíת·¢Ãô¸Ðõè¾¶¡¢¡¢¡¢¾²Ì¬¸ùĿ¼ָÏòÏîĿȫĿ¼¡¢¡¢¡¢ÈÝÆ÷¾µÏñǶÈëÃÜÔ¿£¬£¬£¬»ò±¸·ÝÎļþ£¨Èç.env.bak£©Î´ËãÕÊ¡£¡£¡£¡£¡£
https://securityaffairs.com/188590/hacking/12-million-exposed-env-files-reveal-widespread-security-failures.html
2. OpenClaw¸ßΣ·ì϶¡°ClawJacked¡±±»Åû¶¼°ÐÞ¸´
3ÔÂ1ÈÕ£¬£¬£¬°²È«×êÑÐÈËÔ±Oasis SecurityÅû¶ÁËÊ¢ÐÐ×ÔÍйÜAIƽ̨OpenClawÖÐÃûΪ¡°ClawJacked¡±µÄ¸ßΣ·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚOpenClawÍø¹Ø·þÎñĬÈϰó¶¨localhost²¢Â¶³öWebSocket½Ó¿Ú£¬£¬£¬Òòä¯ÀÀÆ÷¿çÓòÕ½Êõ²»×èÖ¹WebSocketÏνÓlocalhost£¬£¬£¬¶ñÒâÍøÕ¾¿ÉÀûÓÃJavaScript¾²Ä¬³ÉÁ¢Ïνӣ¬£¬£¬³¢ÊÔ±©Á¦ÆÆ½â±¾µØÊµÀýµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£Ö»¹ÜOpenClawÉèÓÐËÙ¶ÈÏÞ¶È£¬£¬£¬µ«Ä¬È϶Իػ·µØÖ·£¨127.0.0.1£©²»ÆôÓÃÏÞ¶È£¬£¬£¬µ¼Ö±¾µØCLI»á»°²»»á´¥·¢Ëø¶¨»úÖÆ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÿÃëÌáÒéÊý°Ù´ÎÃÜÂë²Â²â£¬£¬£¬³£ÓÃÃÜÂëÁбí¿ÉÔÚ1ÃëÄÚ±»ÆÆ½â£¬£¬£¬´óÐÍ×ÖµäÒ²½öÐèÊý·ÖÖÓ¡£¡£¡£¡£¡£Ò»µ©»ñÈ¡ÖÎÀíÔ±ÃÜÂ룬£¬£¬¹¥»÷ÕßÄܾ²Ä¬×¢²áΪÊÜÐÅÀµÉ豸£¬£¬£¬Íø¹Ø»á×Ô¶¯ºË×¼À´×ÔlocalhostµÄÉ豸Åä¶Ô£¬£¬£¬ÎÞÐèÓû§È·ÈÏ¡£¡£¡£¡£¡£¶ûºó£¬£¬£¬¹¥»÷Õß¿ÉÖ±½Ó²Ù¿ØAIƽ̨£¬£¬£¬Ö´ÐÐת´¢Í´´¦¡¢¡¢¡¢ÇÔÈ¡Îļþ¡¢¡¢¡¢¶ÁÈ¡ÈÕÖ¾¡¢¡¢¡¢ËÑË÷ÐÂÎź¹ÇàÖеÄÃô¸ÐÐÅÏ¢£¬£¬£¬ÉõÖÁÔÚÅä¶Ô½ÚµãÉÏÖ´ÐÐËÁÒâshellºÅÁ£¬£¬×îÖÕµ¼ÖÂÓû§¹¤×÷Õ¾±»ÆëÈ«¹¥ÆÆ¡£¡£¡£¡£¡£OpenClawÓÚ2ÔÂ26ÈÕ´¹Î£°ä²¼2026.2.26°æ±¾ÐÞ¸´·ì϶¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/clawjacked-attack-let-malicious-websites-hijack-openclaw-to-steal-data/
3. QuickLens ChromeÀ©´ó±»ºÚÖ¼ÓÃÜÇ®±Ò͵ÇÔ
2ÔÂ28ÈÕ£¬£¬£¬ÃûΪ¡°QuickLens - Search Screen with Google Lens¡±µÄChromeÀ©´ó·¨Ê½Òò±»¶ñÒâÈëÇÖ£¬£¬£¬µ¼ÖÂÔ¼7000ÃûÓû§Ãæ¶Ô¼ÓÃÜÇ®±Ò±»µÁ·çÏÕ£¬£¬£¬×îÖÕ±»¹È¸è´ÓChromeÍøÉÏÀûÓÃÉ̵êϼܡ£¡£¡£¡£¡£¸ÃÀ©´ó×î³õÔÊÐíÓû§Ö±½ÓÔÚä¯ÀÀÆ÷ÖÐÔËÐÐGoogle LensËÑË÷£¬£¬£¬Ôø»ñGoogleÍÆ¼ö»ÕÕ£¬£¬£¬Óû§Á¿Ñ¸ËÙÔö³¤ÖÁ7000ÈË¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬2ÔÂ17ÈÕ°ä²¼µÄ5.8°æ±¾±»Ö²Èë¶ñÒâ¾ç±¾£¬£¬£¬ÒýÈëClickFix¹¥»÷ºÍÐÅÏ¢ÇÔȡְÄÜ£¬£¬£¬³ÉΪ°²È«ÊÂÎñµ¼»ðË÷¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬À©´ó·¨Ê½ÔÚExtensionHubÊг¡¹ÒÅÆÏúÊÛ²¢µ÷»»ËùÓÐȨºó£¬£¬£¬ÐÂËùÓÐÕßÓÚ2ÔÂ1ÈÕÊÕÊÜ£¬£¬£¬²¢ÆôÓôæÔÚÎÊÌâµÄÒþÖÔÕþ²ß¡£¡£¡£¡£¡£Á½Öܺ󣬣¬£¬¶ñÒâ¸üÐÂÍÆËÍ£¬£¬£¬ÒªÇódeclarativeNetRequestWithHostAccessºÍwebRequestµÈÐÂȨÏÞ£¬£¬£¬ÒƳýËùÓÐÒ³ÃæºÍ¿ò¼ÜµÄ°²È«±êÍ·£¬£¬£¬Ê¹¶ñÒâ¾ç±¾¸üÒ×Ö´ÐС£¡£¡£¡£¡£¸Ã°æ±¾»¹ÓëC2·þÎñÆ÷ͨѶ£¬£¬£¬ÌìÉúÓÆ¾ÃÐÔUUID£¬£¬£¬¼ø±ðÓû§ä¯ÀÀÆ÷¡¢¡¢¡¢²Ù×÷ϵͳ¼°¹ú¶È/µØÓò£¬£¬£¬Ã¿Îå·ÖÖÓÂÖѯָÁî¡£¡£¡£¡£¡£Óû§»ã±¨³Æ½Ó¼ûÍøÒ³Ê±ÆµÈÔ³öÏÖÐéαGoogle¸üÐÂÌáÐÑ£¬£¬£¬µã»÷ºó´¥·¢ClickFix¹¥»÷£¬£¬£¬ÏÂÔØÐÅÏ¢ÇÔÈ¡¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/
4. ¼ÓÄôóÂÖÌ¥¹«Ë¾³¬3800ÍòÕË»§Êý¾Ýй¶
2ÔÂ28ÈÕ£¬£¬£¬¼ÓÄôóÁãÊÛ¾ÞÍ·¼ÓÄôóÂÖÌ¥¹«Ë¾£¨CTC£©2025Äê10ÔÂÔâ·êÆäº¹ÇàÉÏ×îÑÏÖØµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬Ó°Ï쳬¹ý3800Íò¸öÕË»§£¬£¬£¬³ÉΪ¼ÓÄôóÁãÊÛÒµ¹æÄ£×î´óµÄÊý¾Ý°²È«ÊÂÎñÖ®Ò»¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÒý·¢¹«¼Ò¶Ô¿Í»§ÒþÖÔ¼°Ãô¸ÐÐÅÏ¢°²È«µÄ¿í·ºÓÇÓô¡£¡£¡£¡£¡£¾Ý¹«Ë¾Åû¶£¬£¬£¬2025Äê10ÔÂ2ÈÕ£¬£¬£¬CTC·¢ÏÖÆäµç×ÓÉÌÎñÊý¾Ý¿âÔâ·¸·¨½Ó¼û£¬£¬£¬µ¼Ö¿ͻ§ÐÅϢй¶¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº¸Ç»ù´¡Ð¡ÎÒÐÅÏ¢£¬£¬£¬Ô̺¬ÐÕÃû¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µ®ÉúÄê·Ý¡¢¡¢¡¢¼ÓÃÜÃÜÂ루ѡȡPBKDF2¹þÏ£Öµ´æ´¢£©£¬£¬£¬²¿ÃÅÕË»§Â¶³ö½Ø¶ÏµÄÐÅÓþ¿¨ºÅÂë¼°²»µ½15ÍòÕË»§µÄÆëÈ«µ®ÉúÈÕÆÚ¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬¹«Ë¾Ç¿µ÷й¶µÄ²ÆÕþÊý¾ÝÎÞ·¨Ö±½ÓÓÃÓÚÕË»§½Ó¼û¡¢¡¢¡¢ÂòÂô»ò²É°ì²Ù×÷£¬£¬£¬ÇÒʵÌåµêÂòÂôϵͳ¡¢¡¢¡¢¼ÓÄôóÂÖÌ¥ÒøÐм°Triangle Rewards¼Î½±´òËãδÊÜÓ°Ï죬£¬£¬µç×ÓÉÌÎñϵͳÈÔÕý³£ÔËÐС£¡£¡£¡£¡£ÊÂÎñ²úÉúºó£¬£¬£¬CTCѸËÙ²ÉȡӦ¶Ô´ëÊ©£º£º£ºÒѶ¨Î»²¢ÐÞ¸´ÏµÍ³·ì϶£¬£¬£¬Í¬²½Ïò¼à¹Ü»ú¹¹´«µÝÇé¿ö£¬£¬£¬²¢´òËã×Ô¶¯ÁªÏµÊÜÓ°ÏìÓû§ÌṩÐÅÓþ¼à¿Ø·þÎñÒÔ½µµÍÉí·Ý͵ÇÔ·çÏÕ¡£¡£¡£¡£¡£
https://securityaffairs.com/188659/data-breach/canadian-tire-2025-data-breach-impacts-38-million-users.html
5. ÈýÐÇÓëµÂ¿ËÈøË¹ÖݾÍÖÇÄܵçÊÓÊý¾Ý°¸ºÍ½â
3ÔÂ1ÈÕ£¬£¬£¬ÈýÐÇÓëÃÀ¹úµÂ¿ËÈøË¹ÖÝ¾ÍÆäÖÇÄܵçÊÓÉæÏÓ·¸·¨ÍøÂçÓû§ÅÔ¹ÛÄÚÈÝÐÅϢһʴï³ÉºÍ½âºÍ̸¡£¡£¡£¡£¡£Õâ´Î¾À·×Ô´Óڵ¿ËÈøË¹ÖÝ×ܼì²ì³¤¿Ï¡¤ÅÁ¿Ë˹¶ÙÓÚÈ¥Äê12Ô¶ÔÈýÐǵȵçÊÓÖÆ×÷ÉÌÌáÆðµÄËßËÏ£¬£¬£¬Ö¸¿ØÆäʹÓÃ×Ô¶¯ÄÚÈݼø±ð£¨ACR£©¼¼ÊõÍøÂçÓû§ÅÔ¹ÛÊý¾Ýʱ£¬£¬£¬Î´ÊÂÏÈ»ñµÃÏû·ÑÕßµÄÃ÷È·ÖªÇéÔ޳ɣ¬£¬£¬Î¥·´ÁË¡¶µÂ¿ËÈøË¹ÖݺýŪÐÔÒµÎñÐÐΪ·¨¡·£¨DTPA£©¡£¡£¡£¡£¡£½ñÄê1Ô£¬£¬£¬·¨ÔºÔøÕë¶ÔÈýÐǰ䲼¶ÌÆÚһʱÏÞ¶ÈÁTRO£©£¬£¬£¬ÒªÇóÆäÖÕ³¡ÔÚ¸ÃÖÝ·¸·¨ÍøÂçÏû·ÑÕßÊý¾Ý£¬£¬£¬Ö»¹Ü¸ÃºÅÁî´ÎÈÕ±»³·Ïú£¬£¬£¬µ«ËßËϳÖÐøÍÆ¶¯¡£¡£¡£¡£¡£Æ¾¾ÝºÍ½âºÍ̸£¬£¬£¬ÈýÐÇÐèÅú¸ÄÆäÒþÖÔÅû¶ÉêÃ÷£¬£¬£¬ÒÔÇ峺Ò×¶®µÄ·½Ê½ÏòÏû·ÑÕßÚ¹ÊÍÊý¾ÝÍøÂçºÍ´¦ÖõľßÌå×ö·¨¡£¡£¡£¡£¡£ºÍ̸Ã÷È·ÒªÇ󣬣¬£¬ÈýÐÇÔÚδ»ñµÃµÂ¿ËÈøË¹ÖÝÏû·ÑÕßÃ÷È·Ô޳ɵÄÇé¿öÏ£¬£¬£¬±ØÐëÖÕ³¡ÍøÂç»ò´¦ÖÃÈκÎACRÅÔ¹ÛÊý¾Ý¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬ÈýÐÇÐèÁ¢¼´¸üÐÂÖÇÄܵçÊÓϵͳ£¬£¬£¬Ö´ÐÐÄܸɵÄÅû¶ºÍÔ޳ɽçÃæ£¬£¬£¬È·±£Óû§¿ÉÄܳä·ÖÖªÇé²¢×ÔÖ÷¾ö¶¨Êý¾ÝʹÓ÷½Ê½¡£¡£¡£¡£¡£×ܼì²ì³¤ÅÁ¿Ë˹¶Ù¶Ô´Ë°µÊ¾ÈϿɣ¬£¬£¬Í¬Ê±Ö¸³öÆäËûÖÇÄܵçÊÓÖÆ×÷ÉÌÈçË÷Äá¡¢¡¢¡¢LG¡¢¡¢¡¢º£ÐźÍTCL¿Æ¼¼ÉÐδ¶Ô´ËÀàËßËϲÉÈ¡ÀàËÆ¸Ä½ø´ëÊ©¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/samsung-tvs-to-stop-collecting-texans-data-without-express-consent/
6. ΢Èí¸æ·¢ÓÎÏ·¹¤¾ß´«²¼Ô¶³Ì½Ó¼ûľÂí¹¥»÷Á´
3ÔÂ1ÈÕ£¬£¬£¬Î¢ÈíÍþвµý±¨ÖÐÐĽüÈÕÅû¶£¬£¬£¬¹¥»÷ÕßÕýͨ¹ýαÔìÓÎÏ·¹¤¾ß´«²¼Ô¶³Ì½Ó¼ûľÂí£¨RAT£©£¬£¬£¬Ðγɶà½×¶ÎϰȾÁ´¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃä¯ÀÀÆ÷¡¢¡¢¡¢Ì¸ÌìÆ½Ì¨·Ö·¢Ä¾Âí»¯¿ÉÖ´ÐÐÎļþ£¬£¬£¬ÈçXeno.exe¡¢¡¢¡¢RobloxPlayerBeta.exeµÈ£¬£¬£¬ÕâЩÎļþÀíÂÛ¼Ù×°³ÉºÏ·¨ÓÎÏ·¹¤¾ß£¬£¬£¬ÊµÔò×÷ΪÏÂÔØÆ÷Æô¶¯¹¥»÷¡£¡£¡£¡£¡£³õʼϰȾ½×¶Î£¬£¬£¬ÏÂÔØÆ÷»á×°ÖñãЯʽJavaÔËÐÐʱ»·¾³£¬£¬£¬²¢Ö´ÐжñÒâJava¹éµµÎļþ£¨Èçjd-gui.jar£©¡£¡£¡£¡£¡£¹¥»÷Õ߯æÃîÀûÓÃWindowsÄÚÖù¤¾ß£¨LOLBins£©Èçcmstp.exe£¬£¬£¬Í¨¹ýPowerShellÖ´ÐкÅÁ£¬£¬½«¶ñÒâ²Ù×÷¼Ù×°³ÉÕý³£ÏµÍ³¹ý³Ì£¬£¬£¬½µµÍ±»°²È«Èí¼þ¼ì²âµÄ·çÏÕ¡£¡£¡£¡£¡£PowerShell¾ç±¾Ëæºó³¢ÊÔÏνӶà¸öÔ¶³Ì·þÎñÆ÷£¬£¬£¬½«update.exeÏÂÔØÖÁÓû§±¾µØÀûÓÃÊý¾ÝĿ¼²¢×Ô¶¯ÔËÐС£¡£¡£¡£¡£¶ñÒâÈí¼þÔËÐк󣬣¬£¬Á¢¼´¶Ï¸ùÔʼÏÂÔØÆ÷ºÛ¼££¬£¬£¬²¢´Û¸ÄMicrosoft DefenderÉèÖ㬣¬£¬½«×ÔÉíÔö³¤ÖÁÅųýÁÐ±í£¬£¬£¬¶ã±Ü°²È«ÒýÇæ¼à¿Ø¡£¡£¡£¡£¡£ÎªÊµÏÖÓÆ¾Ã»¯½ÚÖÆ£¬£¬£¬¹¥»÷Õßͨ¹ý´òË㹤×÷ºÍworld.vbsÆô¶¯¾ç±¾´´½¨ÏµÍ³ºóÃÅ£¬£¬£¬È·ÕäÖØÆôºóÈÔÄܳÖÐøÔËÐС£¡£¡£¡£¡£¸ÃRAT¼¯¼ÓÔØÆ÷¡¢¡¢¡¢ÏÂÔØÆ÷¡¢¡¢¡¢Ô¶³Ì½Ó¼ûÖ°ÄÜÓÚÒ»Ì壬£¬£¬ÔÊÐí¹¥»÷Õ߳־òٿØÊÜϰȾÉ豸£¬£¬£¬Ö´ÐÐÇÔÈ¡Êý¾Ý¡¢¡¢¡¢ÍÆËÍÆäËû¶ñÒâÔØºÉµÈ²Ù×÷¡£¡£¡£¡£¡£
https://hackread.com/microsoft-fake-xeno-roblox-utilities-windows-rat/


¾©¹«Íø°²±¸11010802024551ºÅ