市值: $2.2269T 1.08%
成交额(24h): $51.7314B 36.39%
  • 市值: $2.2269T 1.08%
  • 成交额(24h): $51.7314B 36.39%
  • 恐惧与贪婪指数:
  • 市值: $2.2269T 1.08%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

家得宝数据泄露:GitHub 令牌暴露内部系统一年,引发安全担忧

2025/12/13 18:44

Home Depot 的一次关键数据泄露涉及泄露的 GitHub 令牌,导致内部系统暴露了近一年,引发了严重的安全问题。

家得宝数据泄露:GitHub 令牌暴露内部系统一年,引发安全担忧

Home Depot Data Breach: GitHub Token Exposes Internal Systems for a Year, Prompting Security Concerns

家得宝数据泄露:GitHub 令牌暴露内部系统一年,引发安全担忧

New York, NY - In a startling revelation that underscores the persistent vulnerabilities in corporate cybersecurity, Home Depot has been found to have left its internal systems exposed for nearly a year due to a leaked GitHub access token. This incident, which came to light recently, highlights significant gaps in the retail giant's security response protocols and its handling of responsible disclosure by researchers.

纽约州纽约 - 一项令人震惊的爆料突显了企业网络安全中持续存在的漏洞,家得宝 (Home Depot) 被发现因 GitHub 访问令牌泄露而导致其内部系统暴露近一年。最近曝光的这一事件凸显了这家零售巨头的安全响应协议及其对研究人员负责任披露的处理方面的重大差距。

The Exposed Key to Home Depot's Digital Kingdom

家得宝数字王国的暴露钥匙

The saga began earlier in 2024 when a security expert, Ben Zimmermann, stumbled upon a private GitHub access token belonging to a Home Depot employee. This token, likely published by mistake, served as a digital master key, granting extensive access to hundreds of Home Depot's private source code repositories. The implications were far-reaching, potentially allowing unauthorized individuals to view, and even modify, critical code that governs everything from cloud infrastructure and order fulfillment to inventory management and development pipelines. Given Home Depot's reliance on GitHub for its engineering since 2015, the exposure represented a significant risk.

这个传奇故事始于 2024 年初,当时安全专家 Ben Zimmermann 偶然发现了属于 Home Depot 员工的私人 GitHub 访问令牌。这个令牌可能是错误发布的,它充当数字主密钥,允许广泛访问家得宝的数百个私人源代码存储库。其影响是深远的,可能允许未经授权的个人查看甚至修改控制从云基础设施和订单履行到库存管理和开发管道等一切事务的关键代码。鉴于 Home Depot 自 2015 年以来一直依赖 GitHub 进行工程设计,因此此次暴露带来了重大风险。

A Year of Silence: Failed Disclosure and Media Intervention

沉默之年:信息披露失败和媒体干预

What makes this data breach risk particularly alarming is the company's apparent lack of response to the researcher's warnings. Zimmermann reported the flaw responsibly, sending multiple emails to Home Depot's security contacts and even reaching out to their Chief Information Security Officer on LinkedIn. However, his attempts to alert the company were met with silence for weeks. "Home Depot is the only company that ignored me," Zimmermann stated, noting the absence of a formal bug bounty program which made the disclosure process more challenging. It wasn't until Zimmermann contacted TechCrunch that the company took action. Upon being approached by the news outlet on December 5, the token was promptly revoked. This intervention, nearly a year after the initial exposure, raises questions about whether malicious actors may have exploited the vulnerability during that extended period.

使这种数据泄露风险特别令人担忧的是该公司明显缺乏对研究人员警告的回应。 Zimmermann 负责任地报告了该漏洞,向家得宝的安全联系人发送了多封电子邮件,甚至在 LinkedIn 上联系了他们的首席信息安全官。然而,他试图向该公司发出警报,但数周以来都没有得到回应。齐默尔曼表示:“家得宝是唯一一家忽视我的公司。”他指出,由于缺乏正式的漏洞赏金计划,这使得披露过程更具挑战性。直到齐默尔曼联系 TechCrunch,该公司才采取行动。 12 月 5 日,新闻媒体联系后,该代币立即被撤销。这次干预是在初次曝光近一年后进行的,引发了人们的疑问:恶意行为者是否可能在这段较长的时间内利用了该漏洞。

Broader Implications and Lessons Learned

更广泛的影响和经验教训

While Home Depot's systems are now reportedly secure, the incident brings into sharp focus the critical importance of robust security response mechanisms. The prolonged period of exposure, coupled with the company's initial lack of engagement with the researcher, paints a concerning picture. Unlike e-commerce giant Coupang, which recently confirmed a data breach affecting millions of accounts and is facing legal action, Home Depot's situation appears to have been averted from a full-blown breach through external intervention. However, the near miss serves as a potent reminder for all organizations. The security expert's findings suggest that a malicious actor could have gained access to and altered internal software managing vital operations. While Home Depot has not commented on whether access logs were reviewed to ascertain potential misuse, the public exposure point is now closed.

虽然据报道家得宝的系统现在是安全的,但该事件使人们清楚地认识到强大的安全响应机制的至关重要性。长时间的暴露,加上该公司最初缺乏与研究人员的接触,描绘了一幅令人担忧的景象。与电子商务巨头 Coupang 最近确认发生了影响数百万账户的数据泄露事件并面临法律诉讼不同,家得宝的情况似乎是通过外部干预避免了全面泄露。然而,这次险些发生的事件对所有组织来说都是一个有力的提醒。安全专家的调查结果表明,恶意行为者可能已经访问并更改了管理重要操作的内部软件。虽然家得宝尚未就是否审查访问日志以确定潜在的滥用行为发表评论,但公开曝光点现已关闭。

So, the next time you're grabbing supplies from Home Depot, remember that while your purchases are safe, the digital keys to their kingdom were once out in the open for all to see. It's a good thing we have vigilant researchers keeping an eye on things, otherwise, who knows what kind of digital shenanigans could have unfolded!

因此,下次您从家得宝 (Home Depot) 购买用品时,请记住,虽然您购买的商品是安全的,但通往他们王国的数字钥匙曾经公开供所有人查看。幸好我们有警惕的研究人员密切关注,否则,谁知道会发生什么样的数字恶作剧!

原文来源:zoombangla

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月28日 发表的其他文章