Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î£»Ruby¿âstrong_password±»Ö²ÈëºóÃÅ

°ä²¼¹¦·ò 2019-07-09
1¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
±¾µØ¹¦·ò7ÔÂ8ÈÕ £¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©°ä·¢ £¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶ÊÂÎñ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©Ö´ÐÐÒÔÀ´×î´óµÄÒ»±Ê·£µ¥ £¬Ò²ÊǵÚÒ»¸öƾ¾Ýй涨°ä²¼µÄ·£µ¥¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾ö¶¨¸ÐÓ¦Õ𾪡£1.83ÒÚÓ¢°÷ÊÇÆ¾¾Ý¸Ã¹«Ë¾2017²ÆÄêÈ«Çò½»Ò×¶îµÄ1.5%ÍÆËãµÃÀ´ £¬Æ¾¾ÝGDPR £¬ÕâÒ»´¦·£±ÈÀý×î¸ß¿É´ï4%¡£ÔÚ´Ë֮ǰ £¬ICO×î¸ßµÄ·£¿î¶îÊÇ50ÍòÓ¢°÷ £¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html

2¡¢ºÚ¿ÍÈëÇÖCanonical GitHubÕË»§ £¬UbuntuÔ´ÂëδÊÜÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
7ÔÂ6ÈÕCanonicalÕ¼ÓеÄGitHubÕÊ»§ÔâºÚ¿ÍÈëÇÖ £¬¹¥»÷Õß´´½¨ÁË11¸öеĴ洢¿â £¬²¢°´CAN_GOT_HAXXD_1µÄÌåʽ½øÐж¨Ãû¡£CanonicalÔÚÒ»·ÝÉêÃ÷ÖÐ֤ʵ £¬Ä¿Ç°Ã»ÓÐÈκμ£ÏóÅú×¢Ô´´úÂë»òPII¶¼Êܵ½ÁËÓ°Ïì £¬´Ë±í £¬¹¹½¨ºÍÊØ»¤Ubuntu¿¯ÐаæµÄLaunchpad»ù´¡ÉèÊ©ÓëGitHubûÓÐÏÎ½Ó £¬Ò²Ã»Óм£ÏóÅú×¢ËüÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾ÒѾ­É¾³ýÁËÊÜϰȾµÄÕÊ»§ £¬²¢ÔÚµ÷²éÊÜ·ÛËéµÄˮƽ¡£Ubuntu°²È«ÍŶӰµÊ¾ÔÚµ÷²é¡¢Éó¼ÆºÍ²¹¾È´ëʩʵÏÖºó½«ÊµÊ±¸üÐÂÓйØÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/canonical-ubuntu-github-hacked.html

3¡¢ÃÀºÓɽµØ²úȨЭ»áÔâºÚ¿ÍÈëÇÖ £¬½ü600·ÝÃô¸Ð¼Í¼й¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ÃÀºÓɽµØ²úȨЭ»á£¨ALTA£©Ôâ·êÊý¾Ýй¶ÊÂÎñ £¬½ü600¸ö¹«Ë¾µÄÊý¾ÝÌõ¿îй¶¡£Ò»ÃûºÚ¿Íͨ¹ýTwitterÁªÏµÁËALTA²¢ÌṩÁËй¶µÄÎļþ¡£ÕâЩÊý¾ÝÔ̺¬Êý°Ù¼Ò¹«Ë¾µÄÓò±êʶ¡¢IPµØÖ·¡¢Óû§ÃûºÍÃÜÂë¡£¸ÃЭ»á°µÊ¾Ã»Óм£ÏóÅú×¢Êý¾ÝÀ´×ÔÌØ¶¨µÄϵͳÈëÇÖÐÐΪ £¬Ò²Ã»Óм£ÏóÅúעʹ´¦ÒÀÈ»ÓÐЧ»òÈôºÎ»ñµÃ¡£ALTAÕý´òËãÖ´ÐÐÐÅÏ¢°²È«´òËãºÍÏìÓ¦´òËã £¬ÒÔ±£»¤¹«Ë¾µÄÊý¾ÝºÍϵͳÃâÔâÊý¾ÝÇÔÈ¡ºÍй¶¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/american-land-title-association-suffers-data-breach-compromising-over-600-company-records-f6225d25

4¡¢Google PlayÖÐÐéαES File Explorer £¬×°ÖÃÁ¿³¬¹ý1Íò´Î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ESET×êÑÐÈËÔ±Lukas StefankoÔÚGoogle PlayÉ̵êÖз¢ÏÖÒ»¸öÐéαµÄES File ExplorerÀûÓà £¬¸ÃAPP²¢Î´ÌṩÈκÎÎļþÖÎÀíÖ°ÄÜ £¬¶øÊÇʹÓøæ°×ºäÕ¨Óû§¡£¸Ã¶ñÒâÈí¼þµÄ×°ÖÃÁ¿´ï1ÍòÂÅ´Î £¬ÔÚ×°Öúó £¬¸Ã¶ñÒâÈí¼þ»áÔÚ2·ÖÖÓÄÚÏÔʾ9¸öÈ«ÆÁ¸æ°×¡£ÎªÁËÏԵøüÕæÊµ £¬¸Ã¶ñÒâÈí¼þ»¹ÒªÇóÓû§½øÐÐ×¢²á¡£ÕæÊµµÄES File ExplorerÓÉÓÚ±»È϶¨ÎªÉæ¼°µã»÷ڲƭÒÑÔÚ½ñÄêÔçЩʱ³½±»Google PlayÉ̵êɾ³ý¡£

Ô­ÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/fake-es-file-explorer-makes-it-to-play-store-records-more-than-10k-downloads-526651.shtml

5¡¢×êÑÐÍŶӷ¢ÏÖÕë¶ÔFacebook Libra±ÒµÄڲƭ»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Digital Shadows·¢ÏÖÒÑÓÐÀûÓÃFacebook Libra¼ÓÃÜÇ®±Ò¼°CalibraÇ®°üµÄڲƭ»î¶¯¡£¹¥»÷Õßͨ¹ýͬÐÎÒìÒå×Ö¹¥»÷ £¬½áºÏʹÓÃPunycode±àÂëϵͳÀ´´´½¨¿´ËƺϷ¨µÄÓòÃû £¬ºýŪÓû§½Ó¼û¶ñÒâÍøÕ¾¡£×êÑÐÈËÔ±·¢ÏÖÁù¸ö·ÂÕÕLibraÍøÕ¾µÄÓòÃû £¬ÆäÖÐËĸöÓòÃû´¦ÓÚ»îԾ״̬ £¬²¢ÇÒÏÕЩÓëÕæÊµµÄÍøÕ¾Èç³öÒ»ÕÞ¡£ÕâËĸöÓòÃûÔ̺¬calibra[.]ooo¡¢canlibrawallet[.]com¡¢libracoins[.]co[.]ilºÍlibra-ico[.]org £¬ÆäÖÐÒ»¸öȦÌ×Ðû³ÆÌṩÄܹ»½Ó¼ûLibraºÍ̸¼°Ö°ÄܵÄVPS £¬¹¥»÷ÕßÊÔIJÀûÓÃÕâÐ©ÍøÕ¾»ñÈ¡Óû§µÄFacebook»òGoogleµÇ¼ʹ´¦¡¢ÇÔÈ¡ÒÔÌ«·»¼ÓÃÜÇ®±ÒµÈ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/libra-cryptocurrency-scams-already-active-ahead-of-2020-launch/

6¡¢Ruby¿âstrong_password±»Ö²ÈëºóÃÅ £¬Òѱ»ÏÂÔØ537´Î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Ê¢ÐеÄRubyÃÜÂëÇ¿¶È²é³­¿âstrong_password±»ºÚ¿ÍÖ²ÈëºóÃÅ £¬¹¥»÷Õß½«strong_password°æ±¾´Óv0.0.6Éý¼¶µ½v0.0.7 £¬Ð°汾ÖÐÔ̺¬¶ñÒâ´úÂë¡£¸Ã¶ñÒâ´úÂ뽫²é³­ÊÇ·ñÔÚ²âÊÔ»ò³ö²ú»·¾³ÖÐʹÓà £¬ÈôÊÇÊdzö²ú»·¾³ £¬Ëü½«´ÓÎı¾ÍйÜÃÅ»§ÍøÕ¾Pastebin.comÏÂÔØ²¢ÔËÐÐpayload¡£¸ù»ùÉÏ £¬ÕâÔÊÐí¹¥»÷Õ߯¾¾Ý±ØÒªÖ´ÐÐËÁÒâ´úÂë¡£¶ñÒâ´úÂëûÓÐÉÏ´«µ½GithubÕË»§ÖÐ £¬Ö»ÊÇͨ¹ýRubyGem·Ö·¢¡£¾ÝRubyGemsͳ¼Æ £¬537λÓû§ÏÂÔØÁ˸öñÒâ°æ±¾¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/backdoor-found-in-ruby-library-for-checking-for-strong-passwords/