Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î £»Ruby¿âstrong_password±»Ö²ÈëºóÃÅ

°ä²¼¹¦·ò 2019-07-09
1¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
±¾µØ¹¦·ò7ÔÂ8ÈÕ£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©°ä·¢£¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶ÊÂÎñ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥ ¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý± £»¤ÌõÀý¡·£¨GDPR£©Ö´ÐÐÒÔÀ´×î´óµÄÒ»±Ê·£µ¥£¬Ò²ÊǵÚÒ»¸öƾ¾Ýй涨°ä²¼µÄ·£µ¥ ¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾ö¶¨¸ÐÓ¦Õ𾪠¡£1.83ÒÚÓ¢°÷ÊÇÆ¾¾Ý¸Ã¹«Ë¾2017²ÆÄêÈ«Çò½»Ò×¶îµÄ1.5%ÍÆËãµÃÀ´£¬Æ¾¾ÝGDPR£¬ÕâÒ»´¦·£±ÈÀý×î¸ß¿É´ï4% ¡£ÔÚ´Ë֮ǰ£¬ICO×î¸ßµÄ·£¿î¶îÊÇ50ÍòÓ¢°÷£¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html

2¡¢ºÚ¿ÍÈëÇÖCanonical GitHubÕË»§£¬UbuntuÔ´ÂëδÊÜÓ°Ïì

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
7ÔÂ6ÈÕCanonicalÕ¼ÓеÄGitHubÕÊ»§ÔâºÚ¿ÍÈëÇÖ£¬¹¥»÷Õß´´½¨ÁË11¸öеĴ洢¿â£¬²¢°´CAN_GOT_HAXXD_1µÄÌåʽ½øÐж¨Ãû ¡£CanonicalÔÚÒ»·ÝÉêÃ÷ÖÐ֤ʵ£¬Ä¿Ç°Ã»ÓÐÈκμ£ÏóÅú×¢Ô´´úÂë»òPII¶¼Êܵ½ÁËÓ°Ï죬´Ë±í£¬¹¹½¨ºÍÊØ»¤Ubuntu¿¯ÐаæµÄLaunchpad»ù´¡ÉèÊ©ÓëGitHubûÓÐÏνÓ£¬Ò²Ã»Óм£ÏóÅú×¢ËüÊܵ½Ó°Ïì ¡£¸Ã¹«Ë¾ÒѾ­É¾³ýÁËÊÜϰȾµÄÕÊ»§£¬²¢ÔÚµ÷²éÊÜ·ÛËéµÄˮƽ ¡£Ubuntu°²È«ÍŶӰµÊ¾ÔÚµ÷²é¡¢Éó¼ÆºÍ²¹¾È´ëʩʵÏÖºó½«ÊµÊ±¸üÐÂÓйØÐÅÏ¢ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/canonical-ubuntu-github-hacked.html

3¡¢ÃÀºÓɽµØ²úȨЭ»áÔâºÚ¿ÍÈëÇÖ£¬½ü600·ÝÃô¸Ð¼Í¼й¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
ÃÀºÓɽµØ²úȨЭ»á£¨ALTA£©Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬½ü600¸ö¹«Ë¾µÄÊý¾ÝÌõ¿îй¶ ¡£Ò»ÃûºÚ¿Íͨ¹ýTwitterÁªÏµÁËALTA²¢ÌṩÁËй¶µÄÎļþ ¡£ÕâЩÊý¾ÝÔ̺¬Êý°Ù¼Ò¹«Ë¾µÄÓò±êʶ¡¢IPµØÖ·¡¢Óû§ÃûºÍÃÜÂë ¡£¸ÃЭ»á°µÊ¾Ã»Óм£ÏóÅú×¢Êý¾ÝÀ´×ÔÌØ¶¨µÄϵͳÈëÇÖÐÐΪ£¬Ò²Ã»Óм£ÏóÅúעʹ´¦ÒÀÈ»ÓÐЧ»òÈôºÎ»ñµÃ ¡£ALTAÕý´òËãÖ´ÐÐÐÅÏ¢°²È«´òËãºÍÏìÓ¦´òË㣬ÒÔ± £»¤¹«Ë¾µÄÊý¾ÝºÍϵͳÃâÔâÊý¾ÝÇÔÈ¡ºÍй¶ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/american-land-title-association-suffers-data-breach-compromising-over-600-company-records-f6225d25

4¡¢Google PlayÖÐÐéαES File Explorer£¬×°ÖÃÁ¿³¬¹ý1Íò´Î

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
ESET×êÑÐÈËÔ±Lukas StefankoÔÚGoogle PlayÉ̵êÖз¢ÏÖÒ»¸öÐéαµÄES File ExplorerÀûÓ㬸ÃAPP²¢Î´ÌṩÈκÎÎļþÖÎÀíÖ°ÄÜ£¬¶øÊÇʹÓøæ°×ºäÕ¨Óû§ ¡£¸Ã¶ñÒâÈí¼þµÄ×°ÖÃÁ¿´ï1ÍòÂŴΣ¬ÔÚ×°Öú󣬸öñÒâÈí¼þ»áÔÚ2·ÖÖÓÄÚÏÔʾ9¸öÈ«ÆÁ¸æ°× ¡£ÎªÁËÏԵøüÕæÊµ£¬¸Ã¶ñÒâÈí¼þ»¹ÒªÇóÓû§½øÐÐ×¢²á ¡£ÕæÊµµÄES File ExplorerÓÉÓÚ±»È϶¨ÎªÉæ¼°µã»÷ڲƭÒÑÔÚ½ñÄêÔçЩʱ³½±»Google PlayÉ̵êɾ³ý ¡£

Ô­ÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/fake-es-file-explorer-makes-it-to-play-store-records-more-than-10k-downloads-526651.shtml

5¡¢×êÑÐÍŶӷ¢ÏÖÕë¶ÔFacebook Libra±ÒµÄڲƭ»î¶¯

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Digital Shadows·¢ÏÖÒÑÓÐÀûÓÃFacebook Libra¼ÓÃÜÇ®±Ò¼°CalibraÇ®°üµÄڲƭ»î¶¯ ¡£¹¥»÷Õßͨ¹ýͬÐÎÒìÒå×Ö¹¥»÷£¬½áºÏʹÓÃPunycode±àÂëϵͳÀ´´´½¨¿´ËƺϷ¨µÄÓòÃû£¬ºýŪÓû§½Ó¼û¶ñÒâÍøÕ¾ ¡£×êÑÐÈËÔ±·¢ÏÖÁù¸ö·ÂÕÕLibraÍøÕ¾µÄÓòÃû£¬ÆäÖÐËĸöÓòÃû´¦ÓÚ»îԾ״̬£¬²¢ÇÒÏÕЩÓëÕæÊµµÄÍøÕ¾Èç³öÒ»ÕÞ ¡£ÕâËĸöÓòÃûÔ̺¬calibra[.]ooo¡¢canlibrawallet[.]com¡¢libracoins[.]co[.]ilºÍlibra-ico[.]org£¬ÆäÖÐÒ»¸öȦÌ×Ðû³ÆÌṩÄܹ»½Ó¼ûLibraºÍ̸¼°Ö°ÄܵÄVPS£¬¹¥»÷ÕßÊÔIJÀûÓÃÕâÐ©ÍøÕ¾»ñÈ¡Óû§µÄFacebook»òGoogleµÇ¼ʹ´¦¡¢ÇÔÈ¡ÒÔÌ«·»¼ÓÃÜÇ®±ÒµÈ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/libra-cryptocurrency-scams-already-active-ahead-of-2020-launch/

6¡¢Ruby¿âstrong_password±»Ö²ÈëºóÃÅ£¬Òѱ»ÏÂÔØ537´Î

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Ê¢ÐеÄRubyÃÜÂëÇ¿¶È²é³­¿âstrong_password±»ºÚ¿ÍÖ²ÈëºóÃÅ£¬¹¥»÷Õß½«strong_password°æ±¾´Óv0.0.6Éý¼¶µ½v0.0.7£¬Ð°汾ÖÐÔ̺¬¶ñÒâ´úÂë ¡£¸Ã¶ñÒâ´úÂ뽫²é³­ÊÇ·ñÔÚ²âÊÔ»ò³ö²ú»·¾³ÖÐʹÓã¬ÈôÊÇÊdzö²ú»·¾³£¬Ëü½«´ÓÎı¾ÍйÜÃÅ»§ÍøÕ¾Pastebin.comÏÂÔØ²¢ÔËÐÐpayload ¡ £¸ù»ùÉÏ£¬ÕâÔÊÐí¹¥»÷Õ߯¾¾Ý±ØÒªÖ´ÐÐËÁÒâ´úÂë ¡£¶ñÒâ´úÂëûÓÐÉÏ´«µ½GithubÕË»§ÖУ¬Ö»ÊÇͨ¹ýRubyGem·Ö·¢ ¡£¾ÝRubyGemsͳ¼Æ£¬537λÓû§ÏÂÔØÁ˸öñÒâ°æ±¾ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/backdoor-found-in-ruby-library-for-checking-for-strong-passwords/