Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾ÝÐ¹Â¶ÃæÁÙ1.83ÒÚÓ¢°÷·£¿£¿£¿ £¿£¿ £¿£¿î£»£»£»Ruby¿âstrong_password±»Ö²ÈëºóÃÅ

Ðû²¼Ê±¼ä 2019-07-09
1¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾ÝÐ¹Â¶ÃæÁÙ1.83ÒÚÓ¢°÷·£¿£¿£¿ £¿£¿ £¿£¿î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
ÍâµØÊ±¼ä7ÔÂ8ÈÕ£¬ £¬ £¬ £¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©Ðû²¼£¬ £¬ £¬ £¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶ÊÂÎñ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥¡£ ¡£¡£¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý±£»£»£»¤ÌõÀý¡·£¨GDPR£©ÊµÑéÒÔÀ´×î´óµÄÒ»±Ê·£µ¥£¬ £¬ £¬ £¬Ò²ÊǵÚÒ»¸öƾ֤йæÔòÐû²¼µÄ·£µ¥¡£ ¡£¡£¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾öÒé¸ÐÓ¦Õ𾪡£ ¡£¡£¡£1.83ÒÚÓ¢°÷ÊÇÆ¾Ö¤¸Ã¹«Ë¾2017²ÆÄêÈ«ÇòÓªÒµ¶îµÄ1.5%ÅÌËãµÃÀ´£¬ £¬ £¬ £¬Æ¾Ö¤GDPR£¬ £¬ £¬ £¬ÕâÒ»´¦·Ö±ÈÀý×î¸ß¿É´ï4%¡£ ¡£¡£¡£ÔÚ´Ë֮ǰ£¬ £¬ £¬ £¬ICO×î¸ßµÄ·£¿£¿£¿ £¿£¿ £¿£¿î¶îÊÇ50ÍòÓ¢°÷£¬ £¬ £¬ £¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿ £¿£¿ £¿£¿î¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html

2¡¢ºÚ¿ÍÈëÇÖCanonical GitHubÕË»§£¬ £¬ £¬ £¬UbuntuÔ´ÂëδÊÜÓ°Ïì

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
7ÔÂ6ÈÕCanonicalÓµÓеÄGitHubÕÊ»§ÔâºÚ¿ÍÈëÇÖ£¬ £¬ £¬ £¬¹¥»÷Õß½¨ÉèÁË11¸öеĴ洢¿â£¬ £¬ £¬ £¬²¢°´CAN_GOT_HAXXD_1µÄÃûÌþÙÐÐÃüÃû¡£ ¡£¡£¡£CanonicalÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵ£¬ £¬ £¬ £¬ÏÖÔÚûÓÐÈκμ£ÏóÅú×¢Ô´´úÂë»òPII¶¼Êܵ½ÁËÓ°Ï죬 £¬ £¬ £¬±ðµÄ£¬ £¬ £¬ £¬¹¹½¨ºÍά»¤Ubuntu¿¯ÐаæµÄLaunchpad»ù´¡ÉèÊ©ÓëGitHubûÓÐÅþÁ¬£¬ £¬ £¬ £¬Ò²Ã»Óм£ÏóÅú×¢ËüÊܵ½Ó°Ïì¡£ ¡£¡£¡£¸Ã¹«Ë¾ÒѾ­É¾³ýÁËÊÜѬȾµÄÕÊ»§£¬ £¬ £¬ £¬²¢ÔÚÊÓ²ìÊÜÆÆËðµÄˮƽ¡£ ¡£¡£¡£UbuntuÇå¾²ÍŶÓÌåÏÖÔÚÊӲ졢Éó¼ÆºÍµ÷½â²½·¥Íê³Éºó½«ÊµÊ±¸üÐÂÏà¹ØÐÅÏ¢¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/canonical-ubuntu-github-hacked.html

3¡¢ÃÀÁìÍÁµØ²úȨЭ»áÔâºÚ¿ÍÈëÇÖ£¬ £¬ £¬ £¬½ü600·ÝÃô¸Ð¼Í¼й¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
ÃÀÁìÍÁµØ²úȨЭ»á£¨ALTA£©ÔâÓöÊý¾Ýй¶ÊÂÎñ£¬ £¬ £¬ £¬½ü600¸ö¹«Ë¾µÄÊý¾ÝÌõĿй¶¡£ ¡£¡£¡£Ò»ÃûºÚ¿Íͨ¹ýTwitterÁªÏµÁËALTA²¢ÌṩÁËй¶µÄÎļþ¡£ ¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨Êý°Ù¼Ò¹«Ë¾µÄÓò±êʶ¡¢IPµØµã¡¢Óû§ÃûºÍÃÜÂë¡£ ¡£¡£¡£¸ÃЭ»áÌåÏÖûÓм£ÏóÅú×¢Êý¾ÝÀ´×ÔÌØ¶¨µÄϵͳÈëÇÖÐÐΪ£¬ £¬ £¬ £¬Ò²Ã»Óм£ÏóÅúעƾ֤ÈÔÈ»ÓÐÓûòÔõÑù»ñµÃ¡£ ¡£¡£¡£ALTAÕýÍýÏëʵÑéÐÅÏ¢Çå¾²ÍýÏëºÍÏìÓ¦ÍýÏ룬 £¬ £¬ £¬ÒÔ±£»£»£»¤¹«Ë¾µÄÊý¾ÝºÍϵͳÃâÔâÊý¾ÝÇÔÈ¡ºÍй¶¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/american-land-title-association-suffers-data-breach-compromising-over-600-company-records-f6225d25

4¡¢Google PlayÖÐÐéαES File Explorer£¬ £¬ £¬ £¬×°ÖÃÁ¿Áè¼Ý1Íò´Î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
ESETÑо¿Ö°Ô±Lukas StefankoÔÚGoogle PlayÊÐËÁÖз¢Ã÷Ò»¸öÐéαµÄES File ExplorerÓ¦Ó㬠£¬ £¬ £¬¸ÃAPP²¢Î´ÌṩÈκÎÎļþÖÎÀí¹¦Ð§£¬ £¬ £¬ £¬¶øÊÇʹÓÃ¹ã¸æºäÕ¨Óû§¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ×°ÖÃÁ¿´ï1Íò¶à´Î£¬ £¬ £¬ £¬ÔÚ×°Öúó£¬ £¬ £¬ £¬¸Ã¶ñÒâÈí¼þ»áÔÚ2·ÖÖÓÄÚÏÔʾ9¸öÈ«ÆÁ¹ã¸æ¡£ ¡£¡£¡£ÎªÁËÏԵøüÕæÊµ£¬ £¬ £¬ £¬¸Ã¶ñÒâÈí¼þ»¹ÒªÇóÓû§¾ÙÐÐ×¢²á¡£ ¡£¡£¡£ÕæÊµµÄES File ExplorerÓÉÓÚ±»È϶¨ÎªÉæ¼°µã»÷ڲƭÒÑÔÚ½ñÄêÔçЩʱ¼ä±»Google PlayÊÐËÁɾ³ý¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/fake-es-file-explorer-makes-it-to-play-store-records-more-than-10k-downloads-526651.shtml

5¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶ÔFacebook Libra±ÒµÄڲƭ»î¶¯

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Digital Shadows·¢Ã÷ÒÑÓÐʹÓÃFacebook Libra¼ÓÃÜÇ®±Ò¼°CalibraÇ®°üµÄڲƭ»î¶¯¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýͬÐÎÒìÒå×Ö¹¥»÷£¬ £¬ £¬ £¬Á¬ÏµÊ¹ÓÃPunycode±àÂëϵͳÀ´½¨Éè¿´ËÆÕýµ±µÄÓòÃû£¬ £¬ £¬ £¬ÓÕÆ­Óû§»á¼û¶ñÒâÍøÕ¾¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Áù¸öÄ£ÄâLibraÍøÕ¾µÄÓòÃû£¬ £¬ £¬ £¬ÆäÖÐËĸöÓòÃû´¦ÓÚ»îԾ״̬£¬ £¬ £¬ £¬²¢ÇÒÏÕЩÓëÕæÊµµÄÍøÕ¾Ò»Ä£Ò»Ñù¡£ ¡£¡£¡£ÕâËĸöÓòÃû°üÀ¨calibra[.]ooo¡¢canlibrawallet[.]com¡¢libracoins[.]co[.]ilºÍlibra-ico[.]org£¬ £¬ £¬ £¬ÆäÖÐÒ»¸öȦÌ×Éù³ÆÌṩ¿ÉÒÔ»á¼ûLibraЭÒé¼°¹¦Ð§µÄVPS£¬ £¬ £¬ £¬¹¥»÷ÕßÊÔͼʹÓÃÕâÐ©ÍøÕ¾»ñÈ¡Óû§µÄFacebook»òGoogleµÇ¼ƾ֤¡¢ÇÔÈ¡ÒÔÌ«·»¼ÓÃÜÇ®±ÒµÈ¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/libra-cryptocurrency-scams-already-active-ahead-of-2020-launch/

6¡¢Ruby¿âstrong_password±»Ö²ÈëºóÃÅ£¬ £¬ £¬ £¬Òѱ»ÏÂÔØ537´Î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Ê¢ÐеÄRubyÃÜÂëÇ¿¶È¼ì²é¿âstrong_password±»ºÚ¿ÍÖ²ÈëºóÃÅ£¬ £¬ £¬ £¬¹¥»÷Õß½«strong_password°æ±¾´Óv0.0.6Éý¼¶µ½v0.0.7£¬ £¬ £¬ £¬Ð°汾ÖаüÀ¨¶ñÒâ´úÂë¡£ ¡£¡£¡£¸Ã¶ñÒâ´úÂ뽫¼ì²éÊÇ·ñÔÚ²âÊÔ»òÉú²úÇéÐÎÖÐʹÓ㬠£¬ £¬ £¬ÈôÊÇÊÇÉú²úÇéÐΣ¬ £¬ £¬ £¬Ëü½«´ÓÎı¾ÍйÜÃÅ»§ÍøÕ¾Pastebin.comÏÂÔØ²¢ÔËÐÐpayload¡£ ¡£¡£¡£»£»£»ù±¾ÉÏ£¬ £¬ £¬ £¬ÕâÔÊÐí¹¥»÷Õ߯¾Ö¤ÐèÒªÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¶ñÒâ´úÂëûÓÐÉÏ´«µ½GithubÕË»§ÖУ¬ £¬ £¬ £¬Ö»ÊÇͨ¹ýRubyGem·Ö·¢¡£ ¡£¡£¡£¾ÝRubyGemsͳ¼Æ£¬ £¬ £¬ £¬537λÓû§ÏÂÔØÁ˸öñÒâ°æ±¾¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/backdoor-found-in-ruby-library-for-checking-for-strong-passwords/