¹úÄÚÍâÊý¾Ý»Æ½ð³Ç¹ÙÍøÏà¹ØÊ¼þ
3.1.¹úÍâÊý¾Ý»Æ½ð³Ç¹ÙÍøÏà¹ØÊ¼þ
3.1.1.Å·ÖÞ·þÎñƽ̨Yoojoй¶ǧÍòÃô¸ÐÎļþ
4ÔÂ1ÈÕ£¬Å·ÖÞ·þÎñÊг¡Æ½Ì¨YoojoÒòÔÆ´æ´¢Í°ÅäÖôíÎ󣬵¼Ö³¬1450Íò·ÝÃô¸ÐÎļþ±©Â¶£¬º¸ÇÓû§»¤ÕÕ¡¢Í¨Ñ¶¼Ç¼¡¢µç»°ºÅÂëµÈºËÐÄÒþ˽Êý¾Ý¡£×÷ΪÁ¬½Ó¸öÈËÓë·þÎñÌṩÉ̵ÄÁ÷ÐÐÆ½Ì¨£¬Yoojo£¨Ç°ÉíΪYoupijobs£©ÔÚÓ¢·¨Î÷ºÉµÈ¶à¹úÔËÓª£¬ÆäÓ¦ÓÃÏÂÔØÁ¿³¬50Íò´Î£¬·þÎñ·¶Î§¸²¸Ç¼ÒÕþ¡¢³èÎï¿´»¤µÈ¶àÁìÓò¡£
À´Ô´£º
hhttps://cybernews.com/security/yoojo-data-leak-exposed-passports/
3.1.2.NexOpt 30ÍòÁ¾Æû³µºÍÊý°ÙÍò´ÎÐгÌÐÅÏ¢ÔâÆØ¹â
4ÔÂ9ÈÕ£¬³µÁ¾¸ú×Ù·þÎñÌṩÉÌNexOpt£¬Ò»¼Ò×ܲ¿ÉèÓڵ¹ú¡¢ÔÚÃÀ¹úºÍ°ÂµØÀûÉèÓаìÊ´¦µÄ¹«Ë¾£¬½üÆÚ·¢ÉúÊý¾Ýй¶Ê¼þ£¬±©Â¶ÁËÉÌÓúͳËÓóµµÄÃô¸ÐʵʱºÍÀúÊ·ÐÐÊ»Êý¾Ý¡£Ð¹Â¶µÄÊý¾ÝËÆºõÀ´×Ô³¬¹ý 30 ÍòÁ¾¶ÀÁ¢³µÁ¾£¬°üÀ¨³µÁ¾Ê¶±ðºÅÂë¡¢NexOptÉ豸IMEI±êʶ·û¡¢³µÁ¾Òƶ¯Êý¾Ý¡¢Ðг̳ö·¢µØ¡¢Ä¿µÄµØÊý¾Ý¡¢º½Ïß¡¢³µÁ¾È¼ÓÍ»òµçÁ¿Êý¾ÝÒÔ¼°¼ÝʻԱ×ùÒÎÊý¾ÝµÈ¡£
À´Ô´£º
https://cybernews.com/security/nexopt-data-leak-exposes-locations-vehicles/
3.1.3.Lemonade±£ÏÕ¹«Ë¾Í¨±¨19ÍòÓû§¼ÝÕÕºÅй¶Ê¼þ
4ÔÂ15ÈÕ£¬Lemonade³ÉÁ¢ÓÚ2015Ä꣬×Գơ°È«Õ»±£ÏÕ¹«Ë¾¡±£¬ÔÚÃÀ¹úºÍÅ·ÖÞÌṩ×â·¿¡¢·¿Ö÷¡¢Æû³µ¡¢³èÎï¼°ÈËÊÙ±£ÏÕ²úÆ·¡£¸Ã¹«Ë¾ÒÔÀûÓÃÈ˹¤ÖÇÄܼ¼Êõ¼¤»î±£µ¥¼°´¦ÀíË÷Åâ¶øÎÅÃû¡£¸Ã¹«Ë¾½üÈÕ֪ͨԼ19ÍòÃû¿Í»§£¬Æä¼ÝÕÕºÅÂë¿ÉÄÜÒò¼¼Êõ¹ÊÕÏÔâй¶¡£¸ÃʼþÉæ¼°Ò»¿îÔÚÏ߯û³µ±£ÏÕÓ¦Ó㬸ÃÓ¦ÓÃÔÊÐíÓû§»ñÈ¡±£ÏÕ±¨¼Û¼°¹ºÂò±£µ¥¡£
À´Ô´£º
https://www.securityweek.com/insurance-firm-lemonade-says-api-glitch-exposed-some-drivers-license-numbers/
3.1.4.¼ÓÖÝÀ¶¶Ü±£ÏÕ¹«Ë¾Ïò¹È¸èй¶ÁË470ÍòÃû»áÔ±µÄ½¡¿µÊý¾Ý
4ÔÂ23ÈÕ£¬¼ÓÖÝÀ¶¶Ü±£ÏÕ¹«Ë¾½üÆÚÔâÓöÖØ´óÊý¾Ýй¶Ê¼þ£¬Æä470Íò»áÔ±µÄÊܱ£»¤½¡¿µÐÅÏ¢±»Ð¹Â¶¸ø¹È¸èµÄ·ÖÎöºÍ¹ã¸æÆ½Ì¨¡£×÷Ϊ¼ÓÖݽü600Íò»áÔ±Ìṩ·þÎñµÄ·ÇÓªÀûÐÔ½¡¿µ¼Æ»®£¬À¶¶ÜÔÚÍøÕ¾ÉÏ·¢²¼ÁËÊý¾Ýй¶֪ͨ£¬Ö¸³öÆäBlue ShieldÍøÕ¾ÉϵÄGoogle AnalyticsÅäÖôíÎ󣬵¼Ö»áÔ±Ãô¸ÐÊý¾ÝÔÚ2021Äê4ÔÂÖÁ2024Äê1ÔÂÆÚ¼ä±»¹²Ïí¸ø¹È¸è¹ã¸æÆ½Ì¨ºÍ¹ã¸æÉÌ¡£Ð¹Â¶µÄÊý¾ÝÀàÐͰüÀ¨±£Ïռƻ®Ãû³Æ¡¢ÀàÐͺÍ×éºÅ¡¢³ÇÊкÍÓÊÕþ±àÂë¡¢ÐԱ𡢼ÒÍ¥¹æÄ£µÈ£¬»¹ÓÐÒ½ÁÆË÷Åâ·þÎñÈÕÆÚ¡¢·þÎñÌṩÕß¡¢»¼ÕßÐÕÃû¼°²ÆÎñÔðÈεÈÒ½ÁÆÏà¹ØÊý¾Ý£¬ÒÔ¼°¡°Ñ°ÕÒÒ½Éú¡±ËÑË÷Ìõ¼þºÍ½á¹ûµÈ¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/blue-shield-of-california-leaked-health-data-of-47-million-members-to-google/
4.1.¹úÄÚÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.1.1.¹ØÓÚÇÖº¦Óû§È¨ÒæÐÐΪµÄAPP£¨SDK£©Í¨±¨
¸ù¾ÝÖÐÑëÍøÐŰ졢¹¤ÒµºÍÐÅÏ¢»¯²¿¡¢¹«°²²¿¡¢Êг¡¼à¹Ü×ֵܾÈËIJ¿ÃÅÁªºÏ·¢²¼µÄ¡¶¹ØÓÚ¿ªÕ¹2025Äê¸öÈËÐÅÏ¢±£»¤ÏµÁÐרÏîÐж¯µÄ¹«¸æ¡·£¬ÒÀ¾Ý¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶µçÐÅÌõÀý¡·¡¶µçÐźͻ¥ÁªÍøÓû§¸öÈËÐÅÏ¢±£»¤¹æ¶¨¡·µÈ·¨ÂÉ·¨¹æ£¬¹¤ÐŲ¿¶ÔAPP¡¢SDKÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢µÈÎÊÌ⿪չÖÎÀí¡£½üÆÚ£¬¾×éÖ¯µÚÈý·½¼ì²â»ú¹¹½øÐгé²é£¬¹²·¢ÏÖ52¿îAPP¼°SDK´æÔÚÇÖº¦Óû§È¨ÒæÐÐΪ¡£
À´Ô´£º
https://www.miit.gov.cn/xwfb/gxdt/sjdt/art/2025/art_863385e3fb894d66be8451066e8ac5b6.html
4.1.2.´æÔÚÒþ˽²»ºÏ¹æÐÐΪ£¬¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐļà²â·¢ÏÖ13¿îÎ¥¹æApp
¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶AppÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢ÐÐΪÈ϶¨·½·¨¡·µÈ·¨ÂÉ·¨¹æ¼°Ïà¹Ø¹ú¼Ò±ê×¼ÒªÇ󣬽üÆÚͨ¹ý»¥ÁªÍø¼à²â·¢ÏÖ13¿îÒÆ¶¯Ó¦ÓôæÔÚÒþ˽²»ºÏ¹æÐÐΪ¡£Õë¶ÔÉÏÊöÇé¿ö£¬¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÌáÐѹã´óÊÖ»úÓû§Ê×ÏȽ÷É÷ÏÂÔØÊ¹ÓÃÒÔÉÏÎ¥¹æÒƶ¯Ó¦Óã¬Í¬Ê±Òª×¢ÒâÈÏÕæÔĶÁÆäÓû§ÐÒéºÍÒþ˽Õþ²ß˵Ã÷£¬²»ËæÒ⿪·ÅºÍͬÒâ²»±ØÒªµÄÒþ˽ȨÏÞ£¬²»ËæÒâÊäÈë¸öÈËÒþ˽ÐÅÏ¢£¬¶¨ÆÚά»¤ºÍÇåÀíÏà¹ØÊý¾Ý£¬±ÜÃâ¸öÈËÒþ˽ÐÅÏ¢±»Ð¹Â¶¡£
https://www.cverc.org.cn/zxdt/report20250417.htm
4.2.¹úÍâÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.2.1.TikTok±»ÆØÔâÈëÇÖ£¬³¬90ÍòÓû§Æ¾Ö¤Òɱ»Ð¹Â¶
ºÚ¿Í×éÖ¯R00TK1T½üÈÕÐû³Æ¶ÔTikTokʵʩÁË´ó¹æÄ£Êý¾ÝÈëÇÖ£¬¾Ý³ÆÐ¹Â¶Á˳¬¹ý90ÍòÓû§µÄÕËºÅÆ¾Ö¤¡£¸Ã×éÖ¯±íʾÒѹ«¿ª·¢²¼ÁË927,000ÌõTikTokÓû§¼Ç¼×÷Ϊ¡°Â©¶´Ö¤Ã÷¡±¡£ÍøÂç»Æ½ð³Ç¹ÙÍø×¨¼Ò±íʾ£¬Èç¹ûµÃµ½ÑéÖ¤£¬Õ⽫´ú±í¸ÃÆ½Ì¨ÃæÁÙµÄÒ»´ÎÖØ´ó»Æ½ð³Ç¹ÙÍøÊ¼þ¡£½ØÖÁ·¢¸åʱ£¬TikTokÉÐδ¶ÔÕâЩ¾ßÌåÖ¸¿Ø×ö³ö¹Ù·½»ØÓ¦¡£´Ëǰ¸Ã¹«Ë¾Ôø·ñÈÏÀàËÆµÄÈëÇÖÉùÃ÷£¬±íʾÆä»Æ½ð³Ç¹ÙÍøÍŶÓÔÚϵͳÖÐδ·¢Ïֻƽð³Ç¹ÙÍøÂ©¶´µÄÖ¤¾Ý¡£»Æ½ð³Ç¹ÙÍø×¨¼Ò½¨ÒéTikTokÓû§Á¢¼´²ÉȡԤ·À´ëÊ©£º¸ü¸ÄÃÜÂë¡¢ÆôÓÃË«ÒòËØÈÏÖ¤¡¢¼à¿ØÕË»§¿ÉÒɻ£¬²¢¾¯ÌèÀûÓÃй¶Êý¾Ý½øÐеÄDZÔÚµöÓã³¢ÊÔ¡£
À´Ô´£º
https://cybernews.com/security/tiktok-hack-passwords/
4.2.2.ÐÂÐͶñÒâÈí¼þ"³¬¼¶¿¨X"ͨ¹ýNFCÖм̹¥»÷Ãé×¼°²×¿É豸
Cleafy»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖÃûΪ"³¬¼¶¿¨X"£¨SuperCard X£©µÄÐÂÐͶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©£¬¸Ã¶ñÒâÈí¼þͨ¹ýNFC£¨½ü³¡Í¨ÐÅ£©Öм̹¥»÷Õë¶Ô°²×¿É豸ʵʩ×ʽðÇÔÈ¡¡£±¨¸æ×ܽáÖ¸³ö£º¡°¸ÃÍþвµÄÍ»³öÌØµã²»ÔÚÓÚ¶ñÒâÈí¼þ±¾ÉíµÄ¸´ÔÓÐÔ£¬¶øÔÚÓÚÆäÒÀÀµNFC¼¼ÊõµÄ´´ÐÂÆÛÕ©»úÖÆ¡£ÕâÖÖ¹¥»÷·½Ê½Ê¹¹¥»÷ÕßÄܹ»¼´Ê±»ñÈ¡±»µÁ×ʽð£¬ÇÒ¿ÉÄÜÈÆ¹ýͨ³£Éæ¼°ÒøÐÐתÕ˵Ĵ«Í³ÆÛÕ©ÇþµÀ¡£ÁíÒ»¸öÖµµÃ×¢ÒâµÄÌØµãÊǸöñÒâÈí¼þ¼«µÍµÄÌØÕ÷Ö¸ÎÆ¡£¡±
À´Ô´£º
https://www.freebuf.com/articles/428204.html?sessionid=2064120351