{"id":67581,"date":"2025-09-06T19:54:30","date_gmt":"2025-09-06T22:54:30","guid":{"rendered":"https:\/\/mastertrend.info\/?p=67581"},"modified":"2026-01-21T01:05:13","modified_gmt":"2026-01-21T04:05:13","slug":"tekillik-filtrelemesi","status":"publish","type":"post","link":"https:\/\/mastertrend.info\/tr\/filtracion-s1ngularity\/","title":{"rendered":"S1ngularity filtreleme: 2.180 hesap ve 7.200 depo."},"content":{"rendered":"<h2>S1ngularity s\u0131z\u0131nt\u0131s\u0131: GitHub ve NPM etkilendi \ud83d\udea8<\/h2>\n<div>\n<p style=\"text-align: center\"><img decoding=\"async\" src=\"https:\/\/mastertrend.info\/wp-content\/uploads\/2025\/09\/Malware-impulsado-por-IA-afecto-a-2180-cuentas-de-GitHub.jpg\" alt=\"GitHub \u2014 belirte\u00e7 ve gizli bilgi s\u0131z\u0131nt\u0131s\u0131yla ilgili \u00e7izim\" width=\"1600\" height=\"900\" title=\"\"><\/p>\n<p>Nx&#039;e y\u00f6nelik &quot;s1ngularity&quot; ad\u0131 verilen tedarik zinciri sald\u0131r\u0131s\u0131na y\u00f6nelik son ara\u015ft\u0131rmalar, b\u00fcy\u00fck bir kimlik bilgisi s\u0131z\u0131nt\u0131s\u0131n\u0131 ortaya \u00e7\u0131kard\u0131: binlerce hesap token&#039;\u0131 ve depo s\u0131rr\u0131 if\u015fa oldu ve olay\u0131n bir\u00e7ok a\u015famas\u0131na yans\u0131d\u0131. Wiz&#039;in olay sonras\u0131 raporu, kapsam\u0131n\u0131 belgeliyor ve s\u0131z\u0131nt\u0131n\u0131n nas\u0131l geli\u015fti\u011fine ve etkisine dair bilgiler sunuyor. \ud83d\udea8\ud83d\udcca<\/p>\n<p>Wiz ara\u015ft\u0131rmac\u0131lar\u0131 taraf\u0131ndan yay\u0131nlanan de\u011ferlendirmeye g\u00f6re, ihlal \u00fc\u00e7 ayr\u0131 a\u015famada 2.180 hesab\u0131n ve 7.200 depolama alan\u0131n\u0131n a\u00e7\u0131\u011fa \u00e7\u0131kmas\u0131na neden oldu ve bir\u00e7ok s\u0131r hala ge\u00e7erlili\u011fini koruyor. <a title=\"Chrome Sync 2025&#039;i g\u00fcncelleyin: Taray\u0131c\u0131n\u0131z\u0131 g\u00fcvende tutun.\" href=\"https:\/\/mastertrend.info\/tr\/chrome-sync-2025i-guncelleyin-2\/\" target=\"_blank\" rel=\"noopener\" data-wpil-monitor-id=\"6389\">devam eden hasar riski<\/a>Beyaz b\u00fcltende zaman \u00e7izelgesi, sald\u0131rgan\u0131n teknikleri ve s\u0131zd\u0131r\u0131lan s\u0131rlar\u0131n niteli\u011fi hakk\u0131nda ayr\u0131nt\u0131lar yer al\u0131yor. \ud83d\udd0d\ud83d\udcc8<\/p>\n<h2>Nx Tedarik Zinciri Sald\u0131r\u0131s\u0131 \u26a0\ufe0f\ud83d\ude80<\/h2>\n<p>Nx, kurumsal \u00f6l\u00e7ekli JavaScript\/TypeScript ekosistemlerinde yayg\u0131n olarak kullan\u0131lan, a\u00e7\u0131k kaynakl\u0131, tek depolu bir derleme ve y\u00f6netim sistemidir. NPM kay\u0131t defterinde haftal\u0131k milyonlarca indirmeyle, tehlikeye at\u0131lm\u0131\u015f bir paketin \u00e7ok say\u0131da entegrasyon ve geli\u015ftirme s\u00fcreci \u00fczerinde geni\u015f kapsaml\u0131 bir etkisi vard\u0131r. \u2699\ufe0f<\/p>\n<h3>Uzla\u015fma vekt\u00f6r\u00fc ve olay tarihi \ud83d\udcc5<\/h3>\n<p>El 26 de agosto de 2025, el actor malicioso explot\u00f3 un flujo de trabajo de GitHub Actions vulnerable en el repositorio de Nx para publicar una versi\u00f3n maliciosa del paquete en NPM. El paquete inclu\u00eda un script post-install malicioso llamado \u00abtelemetry.js\u00bb que actu\u00f3 como <a class=\"wpil_keyword_link\" href=\"https:\/\/mastertrend.info\/tr\/androidde-fidye-yazilimi-ve-kotu-amacli-yazilim\/\" target=\"_blank\"  rel=\"noopener\" title=\"Android&#039;de Fidye Yaz\u0131l\u0131mlar\u0131 ve K\u00f6t\u00fc Ama\u00e7l\u0131 Yaz\u0131l\u0131mlar: Kendinizi Korumak \u0130\u00e7in Kolay Bir K\u0131lavuz\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"33585\">k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m<\/a> extractor de credenciales en los sistemas afectados. \ud83d\udd25<\/p>\n<h3>Telemetry.js k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 nas\u0131l \u00e7al\u0131\u015f\u0131r \ud83d\udd75\ufe0f\u200d\u2642\ufe0f<\/h3>\n<p>Telemetry.js k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131, Linux ve macOS&#039;ta kimlik bilgisi h\u0131rs\u0131z\u0131 gibi davranarak GitHub token&#039;lar\u0131n\u0131, npm token&#039;lar\u0131n\u0131, SSH anahtarlar\u0131n\u0131, .env dosyalar\u0131n\u0131, kripto para c\u00fczdanlar\u0131n\u0131 ve di\u011fer gizli bilgileri \u00e7almaya ve ard\u0131ndan bunlar\u0131 &quot;s1ngularity-repository&quot; adl\u0131 genel GitHub depolar\u0131na y\u00fcklemeye \u00e7al\u0131\u015ft\u0131. Bu model, sald\u0131rgan\u0131n \u00e7al\u0131nan bilgileri merkezile\u015ftirip if\u015fa etmesine olanak sa\u011flad\u0131. \ud83d\udd10<\/p>\n<div style=\"text-align: center\">\n<figure class=\"image\"><img decoding=\"async\" src=\"https:\/\/mastertrend.info\/wp-content\/uploads\/2025\/09\/1757188361_133_Malware-impulsado-por-IA-afecto-a-2180-cuentas-de-GitHub.jpg\" alt=\"Kimlik bilgilerini ve s\u0131rlar\u0131 bulmak ve \u00e7almak i\u00e7in kullan\u0131lan \u0130stemli LLM\" width=\"1488\" height=\"600\" title=\"\"><figcaption><strong>LLM&#039;de kimlik bilgilerini ve di\u011fer s\u0131rlar\u0131 bulup s\u0131zd\u0131rmak<\/strong><br \/>\n<em>Kaynak: Wiz<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Sald\u0131rgan ayr\u0131ca, hedefli komut istemlerini kullanarak arama ve veri toplamay\u0131 otomatikle\u015ftirmek i\u00e7in yapay zeka platformlar\u0131 (\u00f6rne\u011fin Claude, Q ve Gemini) i\u00e7in komut sat\u0131r\u0131 ara\u00e7lar\u0131n\u0131 da entegre etti. Wiz, komut isteminin sald\u0131r\u0131 s\u0131ras\u0131nda nas\u0131l geli\u015fti\u011fini, belirli talimatlar i\u00e7in veri \u00e7\u0131karmay\u0131 nas\u0131l optimize etti\u011fini ve model retlerini nas\u0131l a\u015ft\u0131\u011f\u0131n\u0131 belgeliyor ve sald\u0131rgan\u0131n LLM tekniklerine aktif uyumunu yans\u0131t\u0131yor. \u2728\ud83d\udca1<\/p>\n<h2>Etki menzili: hasar yar\u0131\u00e7ap\u0131 ve a\u015famalar\u0131 \ud83d\udcc8\ud83d\udd25<\/h2>\n<p>Olay \u00fc\u00e7 a\u015famada ger\u00e7ekle\u015fti. \u0130lk a\u015famada, 26-27 A\u011fustos tarihleri aras\u0131nda, Nx&#039;in ele ge\u00e7irilmi\u015f s\u00fcr\u00fcmleri 1.700 kullan\u0131c\u0131y\u0131 do\u011frudan etkiledi ve 2.000&#039;den fazla benzersiz s\u0131rr\u0131n s\u0131zd\u0131r\u0131lmas\u0131na neden oldu; ayr\u0131ca, enfekte olmu\u015f sistemlerden yakla\u015f\u0131k 20.000 dosya if\u015fa edildi. GitHub m\u00fcdahale etti, ancak verilerin \u00e7o\u011fu zaten kopyalanm\u0131\u015ft\u0131.<\/p>\n<ul>\n<li>\ud83d\udd39 <strong>A\u015fama 1 (26-27 A\u011fustos):<\/strong> 1.700 kullan\u0131c\u0131 etkilendi, yakla\u015f\u0131k 2.000 s\u0131r s\u0131zd\u0131r\u0131ld\u0131, 20.000 dosya tehlikeye at\u0131ld\u0131.<\/li>\n<li>\ud83d\udd38 <strong>A\u015fama 2 (28-29 A\u011fustos):<\/strong> S\u0131zd\u0131r\u0131lan token&#039;lar kullan\u0131larak \u00f6zel veri depolar\u0131 halka a\u00e7\u0131k hale getirildi; 480 ek hesap tehlikeye at\u0131ld\u0131 ve 6.700 veri deposu if\u015fa edildi.<\/li>\n<li>\ud83d\udd39 <strong>A\u015fama 3 (31 A\u011fustos&#039;tan itibaren):<\/strong> kurban bir kurulu\u015fu hedef alan sald\u0131r\u0131 <a title=\"Bilgisayar\u0131n\u0131z\u0131 Genel Wi-Fi A\u011flar\u0131nda Koruyun: 2025 Rehberi\" href=\"https:\/\/mastertrend.info\/tr\/halka-acik-wi-fi-aglari\/\" target=\"_blank\" rel=\"noopener\" data-wpil-monitor-id=\"6388\">yay\u0131nlamak i\u00e7in hesaplar tehlikeye at\u0131ld\u0131<\/a> 500&#039;den fazla \u00f6zel depo.<\/li>\n<\/ul>\n<p>\u0130kinci a\u015famada, sald\u0131rganlar \u00e7al\u0131nan GitHub token&#039;lar\u0131n\u0131 kullanarak \u00f6zel depolar\u0131 herkese a\u00e7\u0131k hale getirdi ve &#039;s1ngularity&#039; dizesiyle yeniden adland\u0131rarak if\u015fay\u0131 g\u00fc\u00e7lendirdi. \u00dc\u00e7\u00fcnc\u00fc a\u015famada ise, belirli bir hedef, sald\u0131rgan\u0131n \u0131srarc\u0131l\u0131\u011f\u0131n\u0131 ve ilerlemesini kan\u0131tlayan y\u00fczlerce ek \u00f6zel depo yay\u0131nlamak i\u00e7in kullan\u0131ld\u0131. \ud83c\udfaf<\/p>\n<div style=\"text-align: center\">\n<figure class=\"image\"><img decoding=\"async\" src=\"https:\/\/mastertrend.info\/wp-content\/uploads\/2025\/09\/1757188361_498_Malware-impulsado-por-IA-afecto-a-2180-cuentas-de-GitHub.jpg\" alt=\"Sald\u0131r\u0131n\u0131n genel g\u00f6r\u00fcn\u00fcm\u00fc ve etkisi\" width=\"1100\" height=\"600\" title=\"\"><figcaption><strong>s1ngularity sald\u0131r\u0131s\u0131n\u0131n g\u00f6rsel \u00f6zeti<\/strong><br \/>\n<em>Kaynak: Wiz<\/em><\/figcaption><\/figure>\n<\/div>\n<h2>Nx Projesi M\u00fcdahale ve Azaltma \ud83d\udd27\u2705<\/h2>\n<p>Nx ekibi, bir \u00e7ekme iste\u011finin ba\u015fl\u0131\u011f\u0131na yap\u0131lan bir enjeksiyonun, g\u00fcvenli olmayan pull_request_target kullan\u0131m\u0131yla bir araya geldi\u011finde, keyfi kodun y\u00fckseltilmi\u015f izinlerle y\u00fcr\u00fct\u00fclmesine, yay\u0131nlama hatt\u0131n\u0131n tetiklenmesine ve npm yay\u0131nlama belirtecinin d\u0131\u015far\u0131 s\u0131zd\u0131r\u0131lmas\u0131na nas\u0131l olanak sa\u011flad\u0131\u011f\u0131n\u0131 a\u00e7\u0131klayan bir temel neden analizini GitHub&#039;da yay\u0131nlad\u0131.<\/p>\n<p>Uygulanan eylemler aras\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 paketlerin kald\u0131r\u0131lmas\u0131, tehlikeye at\u0131lm\u0131\u015f token&#039;lar\u0131n iptal edilip d\u00f6nd\u00fcr\u00fclmesi ve t\u00fcm yay\u0131nc\u0131 hesaplar\u0131 i\u00e7in iki fakt\u00f6rl\u00fc kimlik do\u011frulaman\u0131n zorunlu hale getirilmesi yer ald\u0131. Ayr\u0131ca, Nx, NPM&#039;nin G\u00fcvenilir Yay\u0131nc\u0131 modelini benimsedi ve PR tetiklemeli i\u015f ak\u0131\u015flar\u0131 i\u00e7in manuel onay ekledi. \ud83d\udd10\ud83d\udccc<\/p>\n<h3>H\u0131zl\u0131 ipu\u00e7lar\u0131 ve \u00f6nemli noktalar \u270f\ufe0f<\/h3>\n<ul>\n<li>\u2705 Tehlikeye girildi\u011finde token ve gizli bilgileri derhal inceleyin ve d\u00f6nd\u00fcr\u00fcn.<\/li>\n<li>\ud83d\udccc pull_request_target&#039;\u0131n g\u00fcvenli olmayan kullan\u0131m\u0131ndan ka\u00e7\u0131n\u0131n ve hassas ak\u0131\u015flarda manuel onaylar\u0131 zorunlu k\u0131l\u0131n.<\/li>\n<li>\ud83d\udd27 \u00c7ok fakt\u00f6rl\u00fc kimlik do\u011frulamay\u0131 ve G\u00fcvenilir Yay\u0131nc\u0131 gibi g\u00fcvenilir yay\u0131nlama modellerini uygulay\u0131n.<\/li>\n<li>\u26a1 Genel veri depolar\u0131n\u0131 izleyin ve erken tespit i\u00e7in otomatik gizli aramalar ger\u00e7ekle\u015ftirin.<\/li>\n<\/ul>\n<section>\n<h3>Par\u00e7ac\u0131klar\u0131 ve SSS&#039;leri Tan\u0131mlama \u2728<\/h3>\n<h4>Telemetry.js nedir?<\/h4>\n<p>telemetry.js, Nx paketinin tehlikeye at\u0131lm\u0131\u015f s\u00fcr\u00fcm\u00fcnde bulunan k\u00f6t\u00fc ama\u00e7l\u0131 kurulum sonras\u0131 beti\u011finin ad\u0131d\u0131r; sald\u0131rgan\u0131n kontrol etti\u011fi genel depolar \u00fczerinden gizli bilgileri toplamak ve s\u0131zd\u0131rmak i\u00e7in Linux ve macOS sistemlerinde kimlik bilgisi h\u0131rs\u0131z\u0131 olarak hareket etmi\u015ftir. \ud83d\udd0d<\/p>\n<h4>Ka\u00e7 hesap ve depo etkilendi?<\/h4>\n<p>Wiz&#039;in raporuna g\u00f6re, sald\u0131r\u0131, olay\u0131n belgelenen \u00fc\u00e7 a\u015famas\u0131 boyunca 2.180 hesab\u0131 ve 7.200 veri deposunu a\u00e7\u0131\u011fa \u00e7\u0131kard\u0131; bir\u00e7ok s\u0131r hala ge\u00e7erlili\u011fini koruyor ve etkilerin devam etme riski bulunuyor. \ud83d\udcca<\/p>\n<\/section>\n<div class=\"ia_ad\">\n<div class=\"ia_rig\">\n<p>46% de entornos presentaron <a class=\"wpil_keyword_link\" href=\"https:\/\/mastertrend.info\/tr\/google-chrome-sifreleri\/\" target=\"_blank\"  rel=\"noopener\" title=\"Google Chrome \u015fifreleri: Sorunu \u015fimdi kolayca \u00e7\u00f6z\u00fcn! \u26a1\ufe0f\ud83d\udd27\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"34437\">\u015fifreler<\/a> comprometidas, casi el doble respecto al 25% del a\u00f1o anterior. Obt\u00e9n el Picus Blue Report 2025 para un an\u00e1lisis completo sobre prevenci\u00f3n, detecci\u00f3n y tendencias en exfiltraci\u00f3n de datos. \ud83d\udcc8<\/p>\n<p>Raporda, savunmalar\u0131 g\u00fc\u00e7lendirmek ve gizli s\u0131z\u0131nt\u0131lara kar\u015f\u0131 m\u00fcdahaleyi iyile\u015ftirmek i\u00e7in \u00f6l\u00e7\u00fcmler, \u00f6neriler ve vaka \u00e7al\u0131\u015fmalar\u0131 sunuluyor.<\/p>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>s1ngularity s\u0131z\u0131nt\u0131s\u0131: telemetry.js tokenlar\u0131, SSH anahtarlar\u0131n\u0131 ve .env dosyalar\u0131n\u0131 \u00e7ald\u0131; s\u0131rlar herkese a\u00e7\u0131k depolar\u0131na y\u00fcklendi.<\/p>","protected":false},"author":1,"featured_media":67790,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","iawp_total_views":16,"jnews-multi-image_gallery":[],"jnews_single_post":{"format":"standard","override":[{"template":"1","parallax":"1","fullscreen":"1","layout":"right-sidebar","sidebar":"default-sidebar","second_sidebar":"default-sidebar","sticky_sidebar":"1","share_position":"top","share_float_style":"share-monocrhome","show_share_counter":"1","show_view_counter":"1","show_featured":"1","show_post_meta":"1","show_post_author":"1","show_post_author_image":"1","show_post_date":"1","post_date_format":"default","post_date_format_custom":"Y\/m\/d","show_post_category":"1","show_post_reading_time":"1","post_reading_time_wpm":"300","post_calculate_word_method":"str_word_count","show_zoom_button":"1","zoom_button_out_step":"2","zoom_button_in_step":"3","show_post_tag":"1","show_prev_next_post":"1","show_popup_post":"1","number_popup_post":"1","show_author_box":"1","show_post_related":"0","show_inline_post_related":"0","show_comment_section":"1"}],"image_override":[{"single_post_thumbnail_size":"crop-500","single_post_gallery_size":"crop-500"}],"trending_post_position":"meta","trending_post_label":"Trending","sponsored_post_label":"Sponsored by","disable_ad":"0","subtitle":""},"jnews_primary_category":[],"jnews_social_meta":[],"jnews_review":[],"enable_review":"","type":"percentage","name":"","summary":"","brand":"","sku":"","good":[],"bad":[],"score_override":"","override_value":"","rating":[],"price":[],"jnews_override_counter":{"view_counter_number":"0","share_counter_number":"0","like_counter_number":"0","dislike_counter_number":"0"},"footnotes":""},"categories":[308],"tags":[1639,1445,1425],"class_list":["post-67581","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguridad","tag-ciberseguridad","tag-evergreencontent","tag-malware"],"_links":{"self":[{"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/posts\/67581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/comments?post=67581"}],"version-history":[{"count":44,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/posts\/67581\/revisions"}],"predecessor-version":[{"id":105480,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/posts\/67581\/revisions\/105480"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/media\/67790"}],"wp:attachment":[{"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/media?parent=67581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/categories?post=67581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mastertrend.info\/tr\/wp-json\/wp\/v2\/tags?post=67581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}