🚨 ⚠️ Security incident: please update to 5.9.0 and replace your account secret
On September 11, an attacker used a leaked database password to access Geph's account database and copied most of it, including the login details (account secrets) of all existing accounts. No browsing history was exposed, because Geph never stores it.
Anyone with your old account secret could log in to your account. Geph 5.9.0 will ask you to replace your secret, which locks the attacker out. Afterwards, log in on your other devices with the new secret.
Read the full incident report for details. We're sorry for the trouble.
Download 5.9.0 from geph.io or the censorship-free mirror.
Note: If you downloaded Geph from Google Play, please wait for the update to become available through the Play Store.
---
🚨 ⚠️ 安全事件:请更新至 5.9.0 并更换账户密钥
9 月 11 日,攻击者利用泄露的数据库密码访问了迷雾通的账户数据库,并复制了其中大部分内容,包括所有现有账户的登录凭据(账户密钥)。浏览记录没有泄露,因为迷雾通从不存储浏览记录。
任何持有您旧账户密钥的人都可以登录您的账户。迷雾通 5.9.0 会提示您更换密钥,更换后攻击者将无法再登录。之后,请在其他设备上使用新密钥登录。
详情请见完整的事件报告。给您带来不便,我们深表歉意。
前往 geph.io 或 免翻墙镜像 下载 5.9.0。
注意:如果您是从 Google Play 下载的迷雾通,请等待 Play 商店的更新推送。
---
🚨 ⚠️ حادثهٔ امنیتی: لطفاً به ۵.۹.۰ بهروزرسانی کنید و رمز حساب خود را عوض کنید
در ۱۱ سپتامبر، یک مهاجم با استفاده از رمز عبور افشاشدهٔ پایگاه داده به پایگاه دادهٔ حسابهای Geph دسترسی پیدا کرد و بخش بزرگی از آن را، از جمله اطلاعات ورود (رمز حساب) همهٔ حسابهای موجود، کپی کرد. هیچ تاریخچهٔ مروری افشا نشد، زیرا Geph هرگز آن را ذخیره نمیکند.
هر کسی که رمز قدیمی حساب شما را داشته باشد میتواند وارد حساب شما شود. Geph ۵.۹.۰ از شما میخواهد رمز خود را عوض کنید تا دسترسی آنها قطع شود. پس از آن، در دستگاههای دیگر خود با رمز جدید وارد شوید.
برای جزئیات، گزارش کامل حادثه را بخوانید. بابت این دردسر عذرخواهی میکنیم.
نسخهٔ ۵.۹.۰ را از geph.io یا آینهٔ مقاوم به فیلترینگ دانلود کنید.
توجه: اگر Geph را از Google Play دریافت کردهاید، لطفاً منتظر در دسترس قرار گرفتن بهروزرسانی در فروشگاه بمانید.
Post #437
3.36K
Geph Forum / 迷雾通用户论坛 Geph Security Incident Report: September 11, 2026 / 迷雾通安全事件报告:2026 年 9 月 11 日 Geph Security Incident Report: September 11, 2026 中文版本 Summary On September 11, 2026, an attacker used a database password that had been accidentally published on GitHub in 2021 to copy most of Geph's PostgreSQL account database. For the vast majority…
- 😨 44
- 😱 21
- ❤ 6
- 👍 6
- 💩 6
- 🙏 6
- 🤡 3
- 🔥 2
- 🥰 1
- 👾 1