市值: $2.2278T 1.13%
體積(24小時): $56.4286B 56.31%
  • 市值: $2.2278T 1.13%
  • 體積(24小時): $56.4286B 56.31%
  • 恐懼與貪婪指數:
  • 市值: $2.2278T 1.13%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

家得寶數據洩露:GitHub 令牌暴露內部系統一年,引發安全擔憂

2025/12/13 18:44

Home Depot 的一次關鍵數據洩露涉及洩露的 GitHub 令牌,導致內部系統暴露了近一年,引發了嚴重的安全問題。

家得寶數據洩露:GitHub 令牌暴露內部系統一年,引發安全擔憂

Home Depot Data Breach: GitHub Token Exposes Internal Systems for a Year, Prompting Security Concerns

家得寶數據洩露:GitHub 令牌暴露內部系統一年,引發安全擔憂

New York, NY - In a startling revelation that underscores the persistent vulnerabilities in corporate cybersecurity, Home Depot has been found to have left its internal systems exposed for nearly a year due to a leaked GitHub access token. This incident, which came to light recently, highlights significant gaps in the retail giant's security response protocols and its handling of responsible disclosure by researchers.

紐約州紐約 - 一項令人震驚的爆料突顯了企業網絡安全中持續存在的漏洞,家得寶 (Home Depot) 被發現因 GitHub 訪問令牌洩露而導致其內部系統暴露近一年。最近曝光的這一事件凸顯了這家零售巨頭的安全響應協議及其對研究人員負責任披露的處理方面的重大差距。

The Exposed Key to Home Depot's Digital Kingdom

家得寶數字王國的暴露鑰匙

The saga began earlier in 2024 when a security expert, Ben Zimmermann, stumbled upon a private GitHub access token belonging to a Home Depot employee. This token, likely published by mistake, served as a digital master key, granting extensive access to hundreds of Home Depot's private source code repositories. The implications were far-reaching, potentially allowing unauthorized individuals to view, and even modify, critical code that governs everything from cloud infrastructure and order fulfillment to inventory management and development pipelines. Given Home Depot's reliance on GitHub for its engineering since 2015, the exposure represented a significant risk.

這個傳奇故事始於 2024 年初,當時安全專家 Ben Zimmermann 偶然發現了屬於 Home Depot 員工的私人 GitHub 訪問令牌。這個令牌可能是錯誤發布的,它充當數字主密鑰,允許廣泛訪問家得寶的數百個私人源代碼存儲庫。其影響是深遠的,可能允許未經授權的個人查看甚至修改控制從雲基礎設施和訂單履行到庫存管理和開發管道等一切事務的關鍵代碼。鑑於 Home Depot 自 2015 年以來一直依賴 GitHub 進行工程設計,因此此次暴露帶來了重大風險。

A Year of Silence: Failed Disclosure and Media Intervention

沉默之年:信息披露失敗和媒體干預

What makes this data breach risk particularly alarming is the company's apparent lack of response to the researcher's warnings. Zimmermann reported the flaw responsibly, sending multiple emails to Home Depot's security contacts and even reaching out to their Chief Information Security Officer on LinkedIn. However, his attempts to alert the company were met with silence for weeks. "Home Depot is the only company that ignored me," Zimmermann stated, noting the absence of a formal bug bounty program which made the disclosure process more challenging. It wasn't until Zimmermann contacted TechCrunch that the company took action. Upon being approached by the news outlet on December 5, the token was promptly revoked. This intervention, nearly a year after the initial exposure, raises questions about whether malicious actors may have exploited the vulnerability during that extended period.

使這種數據洩露風險特別令人擔憂的是該公司明顯缺乏對研究人員警告的回應。 Zimmermann 負責任地報告了該漏洞,向家得寶的安全聯繫人發送了多封電子郵件,甚至在 LinkedIn 上聯繫了他們的首席信息安全官。然而,他試圖向該公司發出警報,但數週以來都沒有得到回應。齊默爾曼表示:“家得寶是唯一一家忽視我的公司。”他指出,由於缺乏正式的漏洞賞金計劃,這使得披露過程更具挑戰性。直到齊默爾曼聯繫 TechCrunch,該公司才採取行動。 12 月 5 日,新聞媒體聯繫後,該代幣立即被撤銷。這次干預是在初次曝光近一年後進行的,引發了人們的疑問:惡意行為者是否可能在這段較長的時間內利用了該漏洞。

Broader Implications and Lessons Learned

更廣泛的影響和經驗教訓

While Home Depot's systems are now reportedly secure, the incident brings into sharp focus the critical importance of robust security response mechanisms. The prolonged period of exposure, coupled with the company's initial lack of engagement with the researcher, paints a concerning picture. Unlike e-commerce giant Coupang, which recently confirmed a data breach affecting millions of accounts and is facing legal action, Home Depot's situation appears to have been averted from a full-blown breach through external intervention. However, the near miss serves as a potent reminder for all organizations. The security expert's findings suggest that a malicious actor could have gained access to and altered internal software managing vital operations. While Home Depot has not commented on whether access logs were reviewed to ascertain potential misuse, the public exposure point is now closed.

雖然據報導家得寶的系統現在是安全的,但該事件使人們清楚地認識到強大的安全響應機制的至關重要性。長時間的暴露,加上該公司最初缺乏與研究人員的接觸,描繪了一幅令人擔憂的畫面。與電子商務巨頭 Coupang 最近確認發生了影響數百萬賬戶的數據洩露事件並面臨法律訴訟不同,家得寶的情況似乎是通過外部干預避免了全面洩露。然而,這次險些發生的事件對所有組織來說都是一個有力的提醒。安全專家的調查結果表明,惡意行為者可能已經訪問並更改了管理重要操作的內部軟件。雖然家得寶尚未就是否審查訪問日誌以確定潛在的濫用行為發表評論,但公開曝光點現已關閉。

So, the next time you're grabbing supplies from Home Depot, remember that while your purchases are safe, the digital keys to their kingdom were once out in the open for all to see. It's a good thing we have vigilant researchers keeping an eye on things, otherwise, who knows what kind of digital shenanigans could have unfolded!

因此,下次您從家得寶 (Home Depot) 購買用品時,請記住,雖然您購買的商品是安全的,但通往他們王國的數字鑰匙曾經公開供所有人查看。幸好我們有警惕的研究人員密切關注,否則,誰知道會發生什麼樣的數字惡作劇!

原始來源:zoombangla

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年07月27日 其他文章發表於