È«Çò³¬1200Íò.envÎļþ¹«¿ªÂ¶³ö

°ä²¼¹¦·ò 2026-03-02

1. È«Çò³¬1200Íò.envÎļþ¹«¿ªÂ¶³ö


2ÔÂ27ÈÕ£¬Mysterium VPN×êÑÐÈËÔ±·¢ÏÖÈ«Çò12,088,677¸öIPµØÖ·´æÔڿɹ«¿ª½Ó¼ûµÄ.envÌåʽÎļþ£¬Ð¹Â¶Ô̺¬JWTÊðÃûÃÜÔ¿¡¢APIÃÜÔ¿¡¢Êý¾Ý¿âÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£´ËÀàÎļþÒò´æ´¢ÀûÓ÷¨Ê½»·¾³±äÁ¿£¨ÈçÊý¾Ý¿âURL¡¢ÔƽӼûÃÜÔ¿£©¶ø¿í·ºÊ¹Ó㬵«Æä¼ò½àÐÔÒ²´øÀ´·çÏÕ£¬Èô·þÎñÆ÷δÆÁ±Î°µ²ØÎļþ½Ó¼û£¬¹¥»÷Õß¿ÉÖ±½ÓÒªÇó"/.env"ÏÂÔØÊµÊ±Í´´¦£¬ÎÞÐèÀûÓ÷ì϶¼´¿ÉÈÆ¹ýÈëÇֽ׶Σ¬Ö±½ÓʹÓÃÓÐЧƾ֤µÇ¼ϵͳ¡¢²éÎÊÊý¾Ý¿â¡¢Î±ÔìÁîÅÆ»òÀÄÓÃAPI¡£Õâ´Îй¶³ÊÈ«ÇòÐÔÉ¢²¼£ºÃÀ¹úÊÜÓ°ÏìIP½ü280Íò£¨Õ¼23%£©£¬ÈÕ±¾¡¢µÂ¹ú¡¢Ó¡¶È¡¢·¨¹ú¡¢Ó¢¹úµÈ¹úÒ೬°ÙÍò£¬Åú×¢ÎÊÌâÔ´ÓÚ¿çÐÐÒµµÄÆÕ±éÔËάÃýÎ󣬶ø·Çµ¥Ò»Æ½Ì¨È±µã¡£Ð¹Â¶ºó¹ûÑϳÁ£¬Êý¾Ý¿âƾ֤¿ÉÖÂÊý¾ÝÇÔÈ¡£¬APIÃÜÔ¿¿ÉÄÜÒý·¢½ðÈÚÚ¿Æ­£¬JWTÃÜÔ¿±»ÓÃÓÚÕË»§½Ù³Ö£¬SMTPƾ֤ÔòÖú³¤ÍøÂç´¹µö£¬ÔÆ´æ´¢ÃÜÔ¿¸ü¿ÉÄܶ³ö±¸·ÝÎļþÓëÄÚ²¿Îĵµ¡£µ××ÓÔ­Òò¶àÔ´ÓÚ¿ÉÔ¤·ÀµÄÅäÖÃʧÎó£ºÈ±Ê§°µ²ØÎļþ»Ø¾ø¹æ¶¨¡¢·´Ïò´úÀíת·¢Ãô¸Ðõè¾¶¡¢¾²Ì¬¸ùĿ¼ָÏòÏîĿȫĿ¼¡¢ÈÝÆ÷¾µÏñǶÈëÃÜÔ¿£¬»ò±¸·ÝÎļþ£¨Èç.env.bak£©Î´ËãÕÊ¡£


https://securityaffairs.com/188590/hacking/12-million-exposed-env-files-reveal-widespread-security-failures.html


2. OpenClaw¸ßΣ·ì϶¡°ClawJacked¡±±»Åû¶¼°½¨¸´


3ÔÂ1ÈÕ£¬°²È«×êÑÐÈËÔ±Oasis SecurityÅû¶ÁËÊ¢ÐÐ×ÔÍйÜAIƽ̨OpenClawÖÐÃûΪ¡°ClawJacked¡±µÄ¸ßΣ·ì϶¡£¸Ã·ì϶ԴÓÚOpenClawÍø¹Ø·þÎñĬÈϰó¶¨localhost²¢Â¶³öWebSocket½Ó¿Ú£¬Òòä¯ÀÀÆ÷¿çÓòÕ½Êõ²»×èÖ¹WebSocketÏνÓlocalhost£¬¶ñÒâÍøÕ¾¿ÉÀûÓÃJavaScript¾²Ä¬³ÉÁ¢ÏνÓ£¬³¢ÊÔ±©Á¦ÆÆ½â±¾µØÊ·ýµÄ½Ó¼ûȨÏÞ¡£Ö»¹ÜOpenClawÉèÓпìÂÊÏÞ¶È£¬µ«Ä¬È϶Իػ·µØÖ·£¨127.0.0.1£©²»ÆôÓÃÏÞ¶È£¬µ¼Ö±¾µØCLI»á»°²»»á´¥·¢Ëø¶¨»úÔì¡£¹¥»÷Õß¿ÉÿÃëÌáÒéÊý°Ù´ÎÃÜÂë²Â²â£¬³£ÓÃÃÜÂëÁбí¿ÉÔÚ1ÃëÄÚ±»ÆÆ½â£¬´óÐÍ×ÖµäÒ²½öÐèÊý·ÖÖÓ¡£Ò»µ©»ñÈ¡ÖÎÀíÔ±ÃÜÂ룬¹¥»÷ÕßÄܾ²Ä¬×¢²áΪÊÜÐÅÀµÉ豸£¬Íø¹Ø»á×Ô¶¯ºË×¼À´×ÔlocalhostµÄÉ豸Åä¶Ô£¬ÎÞÐèÓû§È·ÈÏ¡£¶ûºó£¬¹¥»÷Õß¿ÉÖ±½Ó²Ù¿ØAIƽ̨£¬Ö´ÐÐת´¢Í´´¦¡¢ÇÔÈ¡Îļþ¡¢¶ÁÈ¡ÈÕÖ¾¡¢ËÑË÷ÐÂÎź¹ÇàÖеÄÃô¸ÐÐÅÏ¢£¬ÉõÖÁÔÚÅä¶Ô½ÚµãÉÏÖ´ÐÐËÁÒâshellºÅÁ×îÖÕµ¼ÖÂÓû§¹¤×÷Õ¾±»ÆëÈ«¹¥ÆÆ¡£OpenClawÓÚ2ÔÂ26ÈÕ´¹Î£°ä²¼2026.2.26°æ±¾½¨¸´·ì϶¡£


https://www.bleepingcomputer.com/news/security/clawjacked-attack-let-malicious-websites-hijack-openclaw-to-steal-data/


3. QuickLens ChromeÀ©´ó±»ºÚÖ¼ÓÃÜÇ®±Ò͵ÇÔ


2ÔÂ28ÈÕ£¬ÃûΪ¡°QuickLens - Search Screen with Google Lens¡±µÄChromeÀ©´ó·¨Ê½Òò±»¶ñÒâÈëÇÖ£¬µ¼ÖÂÔ¼7000ÃûÓû§Ãæ¶Ô¼ÓÃÜÇ®±Ò±»µÁ·çÏÕ£¬×îÖÕ±»¹È¸è´ÓChromeÍøÉÏÀûÓÃÉ̵êϼÜ¡£¸ÃÀ©´ó×î³õÔÊÐíÓû§Ö±½ÓÔÚä¯ÀÀÆ÷ÖÐÔËÐÐGoogle LensËÑË÷£¬Ôø»ñGoogleÍÆ¼ö»ÕÕ£¬Óû§Á¿Ñ¸¿ìÔö³¤ÖÁ7000ÈË¡£È»¶ø£¬2ÔÂ17ÈÕ°ä²¼µÄ5.8°æ±¾±»Ö²Èë¶ñÒâ¾ç±¾£¬ÒýÈëClickFix¹¥»÷ºÍÐÅÏ¢ÇÔȡְÄÜ£¬³ÉΪ°²È«ÊÂÎñµ¼»ðË÷¡£°²È«×êÑÐÈËÔ±·¢ÏÖ£¬À©´ó·¨Ê½ÔÚExtensionHubÊг¡¹ÒÅÆÏúÊÛ²¢µ÷»»ËùÓÐȨºó£¬ÐÂËùÓÐÕßÓÚ2ÔÂ1ÈÕÊÕÊÜ£¬²¢ÆôÓôæÔÚÎÊÌâµÄÒþÖÔÕþ²ß¡£Á½Öܺ󣬶ñÒâ¸üÐÂÍÆËÍ£¬ÒªÇódeclarativeNetRequestWithHostAccessºÍwebRequestµÈÐÂȨÏÞ£¬ÒƳýËùÓÐÒ³ÃæºÍ¿ò¼ÜµÄ°²È«±êÍ·£¬Ê¹¶ñÒâ¾ç±¾¸üÒ×Ö´ÐС£¸Ã°æ±¾»¹ÓëC2·þÎñÆ÷ͨѶ£¬ÌìÉúÓÆ¾ÃÐÔUUID£¬¼ø±ðÓû§ä¯ÀÀÆ÷¡¢²Ù×÷ϵͳ¼°¹ú¶È/µØÓò£¬Ã¿Îå·ÖÖÓÂÖѯָÁî¡£Óû§»ã±¨³Æ½Ó¼ûÍøÒ³Ê±ÆµÈÔ³öÏÖÐéαGoogle¸üÐÂÌáÐÑ£¬µã»÷ºó´¥·¢ClickFix¹¥»÷£¬ÏÂÔØÐÅÏ¢ÇÔÈ¡¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£


https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/


4. ¼ÓÄôóÂÖÌ¥¹«Ë¾³¬3800ÍòÕË»§Êý¾Ýй¶


2ÔÂ28ÈÕ£¬¼ÓÄôóÁãÊÛ¾ÞÍ·¼ÓÄôóÂÖÌ¥¹«Ë¾£¨CTC£©2025Äê10ÔÂÔâ·êÆäº¹ÇàÉÏ×îÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬Ó°Ï쳬¹ý3800Íò¸öÕË»§£¬³ÉΪ¼ÓÄôóÁãÊÛÒµ¹æÄ£×î´óµÄÊý¾Ý°²È«ÊÂÎñÖ®Ò»¡£Õâ´ÎÊÂÎñÒý·¢¹«¼Ò¶Ô¿Í»§ÒþÖÔ¼°Ãô¸ÐÐÅÏ¢°²È«µÄ¿í·ºÓÇÓô¡£¾Ý¹«Ë¾Åû¶£¬2025Äê10ÔÂ2ÈÕ£¬CTC·¢ÏÔìäµç×ÓÉÌÎñÊý¾Ý¿âÔâ·¸·¨½Ó¼û£¬µ¼Ö¿ͻ§ÐÅϢй¶¡£Ð¹Â¶Êý¾Ýº­¸Ç»ù´¡Ó×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÄê·Ý¡¢¼ÓÃÜÃÜÂ루ѡȡPBKDF2¹þÏ£Öµ´æ´¢£©£¬²¿ÃÅÕË»§Â¶³ö½Ø¶ÏµÄÐÅÓþ¿¨ºÅÂë¼°²»µ½15ÍòÕË»§µÄÆëÈ«µ®ÉúÈÕÆÚ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¹«Ë¾Ç¿µ÷й¶µÄ²ÆÕþÊý¾ÝÎÞ·¨Ö±½ÓÓÃÓÚÕË»§½Ó¼û¡¢ÂòÂô»ò²É°ì²Ù×÷£¬ÇÒʵÌåµêÂòÂôϵͳ¡¢¼ÓÄôóÂÖÌ¥ÒøÐм°Triangle Rewards¼Î½±´òËãδÊÜÓ°Ï죬µç×ÓÉÌÎñϵͳÈÔÕý³£ÔËÐС£ÊÂÎñ²úÉúºó£¬CTCѸ¿ì²ÉȡӦ¶Ô´ëÊ©£ºÒѶ¨Î»²¢½¨¸´ÏµÍ³·ì϶£¬Í¬²½Ïò¼à¹Ü»ú¹¹´«µÝÇé¿ö£¬²¢´òËã×Ô¶¯ÁªÏµÊÜÓ°ÏìÓû§ÌṩÐÅÓþ¼à¿Ø·þÎñÒÔ½µµÍÉí·Ý͵ÇÔ·çÏÕ¡£


https://securityaffairs.com/188659/data-breach/canadian-tire-2025-data-breach-impacts-38-million-users.html


5. ÈýÐÇÓëµÂ¿ËÈøË¹ÖݾÍÖÇÄܵçÊÓÊý¾Ý°¸ºÍ½â


3ÔÂ1ÈÕ£¬ÈýÐÇÓëÃÀ¹úµÂ¿ËÈøË¹ÖÝ¾ÍÆäÖÇÄܵçÊÓÉæÏÓ·¸·¨ÍøÂçÓû§ÅÔ¹ÛÄÚÈÝÐÅϢһʴï³ÉºÍ½âºÍ̸¡£Õâ´Î¾À·×Ô´Óڵ¿ËÈøË¹ÖÝ×ܼì²ì³¤¿Ï¡¤ÅÁ¿Ë˹¶ÙÓÚÈ¥Äê12Ô¶ÔÈýÐǵȵçÊÓÔì×÷ÉÌÌáÆðµÄËßËÏ£¬Ö¸¿ØÆäʹÓÃ×Ô¶¯ÄÚÈݼø±ð£¨ACR£©¼¼ÊõÍøÂçÓû§ÅÔ¹ÛÊý¾Ýʱ£¬Î´ÊÂÏÈ»ñµÃÏû·ÑÕßµÄÃ÷È·ÖªÇéÔ޳ɣ¬Î¥·´ÁË¡¶µÂ¿ËÈøË¹ÖݺýŪÐÔÒµÎñÐÐΪ·¨¡·£¨DTPA£©¡£½ñÄê1Ô£¬·¨ÔºÔøÕë¶ÔÈýÐǰ䲼¶ÌÆÚһʱÏÞ¶ÈÁTRO£©£¬ÒªÇóÆäÖÕ³¡ÔÚ¸ÃÖÝ·¸·¨ÍøÂçÏû·ÑÕßÊý¾Ý£¬Ö»¹Ü¸ÃºÅÁî´ÎÈÕ±»³·Ïú£¬µ«ËßËϳÖÐøÍÆ¶¯¡£Æ¾¾ÝºÍ½âºÍ̸£¬ÈýÐÇÐèÅú¸ÄÆäÒþÖÔÅû¶ÉêÃ÷£¬ÒÔÇ峺Ò×¶®µÄ·½Ê½ÏòÏû·ÑÕßÚ¹ÊÍÊý¾ÝÍøÂçºÍ´¦ÖõľßÌå×ö·¨¡£ºÍ̸Ã÷È·ÒªÇó£¬ÈýÐÇÔÚδ»ñµÃµÂ¿ËÈøË¹ÖÝÏû·ÑÕßÃ÷È·Ô޳ɵÄÇé¿öÏ£¬±ØÐëÖÕ³¡ÍøÂç»ò´¦ÖÃÈκÎACRÅÔ¹ÛÊý¾Ý¡£Í¬Ê±£¬ÈýÐÇÐèµ±¼´¸üÐÂÖÇÄܵçÊÓϵͳ£¬Ö´ÐÐÄܸɵÄÅû¶ºÍÔ޳ɽçÃæ£¬È·±£Óû§¿ÉÄܳä·ÖÖªÇé²¢×ÔÖ÷¾ö¶¨Êý¾ÝʹÓ÷½Ê½¡£×ܼì²ì³¤ÅÁ¿Ë˹¶Ù¶Ô´Ë°µÊ¾ÈϿɣ¬Í¬Ê±Ö¸³öÆäËûÖÇÄܵçÊÓÔì×÷ÉÌÈçË÷Äá¡¢LG¡¢º£ÐźÍTCL¿Æ¼¼ÉÐδ¶Ô´ËÀàËßËϲÉÈ¡ÀàËÆ¸Ä½ø´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/samsung-tvs-to-stop-collecting-texans-data-without-express-consent/


6. ΢Èí¸æ·¢ÓÎÏ·¹¤¾ß´«²¼Ô¶³Ì½Ó¼ûľÂí¹¥»÷Á´


3ÔÂ1ÈÕ£¬Î¢ÈíÍþвµý±¨ÖÐÐĽüÈÕÅû¶£¬¹¥»÷ÕßÕýͨ¹ýαÔìÓÎÏ·¹¤¾ß´«²¼Ô¶³Ì½Ó¼ûľÂí£¨RAT£©£¬Ðγɶà½×¶ÎϰȾÁ´¡£¹¥»÷ÕßÀûÓÃä¯ÀÀÆ÷¡¢Ì¸ÌìÆ½Ì¨·Ö·¢Ä¾Âí»¯¿ÉÖ´ÐÐÎļþ£¬ÈçXeno.exe¡¢RobloxPlayerBeta.exeµÈ£¬ÕâЩÎļþ±í±í¼Ù×°³ÉºÏ·¨ÓÎÏ·¹¤¾ß£¬ÊµÔò×÷ΪÏÂÔØÆ÷Æô¶¯¹¥»÷¡£³õʼϰȾ½×¶Î£¬ÏÂÔØÆ÷»á×°ÖñãЯʽJavaÔËÐÐʱ»·¾³£¬²¢Ö´ÐжñÒâJava¹éµµÎļþ£¨Èçjd-gui.jar£©¡£¹¥»÷Õ߯æÃîÀûÓÃWindowsÄÚÖù¤¾ß£¨LOLBins£©Èçcmstp.exe£¬Í¨¹ýPowerShellÖ´ÐкÅÁ½«¶ñÒâ²Ù×÷¼Ù×°³ÉÕý³£ÏµÍ³¹ý³Ì£¬½µµÍ±»°²È«Èí¼þ¼ì²âµÄ·çÏÕ¡£PowerShell¾ç±¾Ëæºó³¢ÊÔÏνӶà¸öÔ¶³Ì·þÎñÆ÷£¬½«update.exeÏÂÔØÖÁÓû§±¾µØÀûÓÃÊý¾ÝĿ¼²¢×Ô¶¯ÔËÐС£¶ñÒâÈí¼þÔËÐк󣬵±¼´¶Ï¸ùԭʼÏÂÔØÆ÷ºÛ¼££¬²¢´Û¸ÄMicrosoft DefenderÉèÖ㬽«×ÔÉíÔö³¤ÖÁÅųýÁбí£¬¶ã±Ü°²È«ÒýÇæ¼à¿Ø¡£ÎªÊµÏÖÓÆ¾Ã»¯½ÚÔ죬¹¥»÷Õßͨ¹ý´òË㹤×÷ºÍworld.vbsÆô¶¯¾ç±¾´´½¨ÏµÍ³ºóÃÅ£¬È·±£³ÁÆôºóÈÔÄܳÖÐøÔËÐС£¸ÃRAT¼¯¼ÓÔØÆ÷¡¢ÏÂÔØÆ÷¡¢Ô¶³Ì½Ó¼ûÖ°ÄÜÓÚÒ»Ì壬ÔÊÐí¹¥»÷Õ߳־òٿØÊÜϰȾÉ豸£¬Ö´ÐÐÇÔÈ¡Êý¾Ý¡¢ÍÆËÍÆäËû¶ñÒâÔØºÉµÈ²Ù×÷¡£


https://hackread.com/microsoft-fake-xeno-roblox-utilities-windows-rat/