Weerarkii phishing-ka ee shaqaalaha Dropbox ayaa horseedaya in 130 goobood oo khaas ah la daadiyo

Dropbox ayaa daaha ka qaaday macluumaadka ku saabsan dhacdo ay weeraryahannadu geliyeen 130 goobood oo gaar loo leeyahay oo lagu marti galiyay GitHub. Waxaa lagu eedeeyay in kaydadka la jabsaday ay ka kooban yihiin mudacyo laga keenay maktabado il furan oo hadda jira oo loogu talagalay baahiyaha Dropbox, qaar ka mid ah noocyada gudaha, iyo sidoo kale agabka iyo faylalka qaabeynta ee ay adeegsadaan kooxda ammaanku. Weerarku ma saameyn bakhaarrada leh koodka codsiyada aasaasiga ah iyo walxaha kaabayaasha muhiimka ah, kuwaas oo si gaar ah loo sameeyay. Falanqaynta ayaa muujisay in weerarku aanu u horseedin in la daadiyo saldhigga isticmaala ama hoos u dhigista kaabayaasha.

Gelitaanka bakhaarrada ayaa la helay iyadoo ay sabab u tahay ka-hortagga aqoonsiga mid ka mid ah shaqaalaha oo noqday dhibane phishing. Weeraryahanadu waxay u direen shaqaalaha warqad iyagoo gashanaaya digniin ka timid nidaamka is-dhexgalka joogtada ah ee CircleCI oo leh shuruudo lagu xaqiijinayo heshiiska isbeddelka xeerarka adeegga. Isku xirka iimaylka ayaa horseeday degel been abuur ah oo loo qaabeeyey inuu u ekaado isku xirka CircleCI. Bogga gelitaanka ayaa la waydiistay inuu ka galo magaca isticmaalaha iyo erayga sirta ah ee GitHub, iyo sidoo kale adeegso furaha qalabka si uu u soo saaro erayga sirta ah ee hal mar ah si uu u gudbiyo xaqiijinta laba-geesoodka ah.

Source: opennet.ru

Add a comment