今天外媒已经报了:https://www.paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/reports/Unit_42/unit42-cool-reaper.pdf Wooyun.org is a vulnerability assessment crowdsourcing website similar to Bugcrowd. On November 19, 2014 an independent white hat researcher named “爱上平顶山” (Aishangpingdingshan) submitted a vulnerability (WooYun-2014-83824) to Coolpad with the title “A critical vulnerability in Coolpad’s official backend platform for silently installing APK functionality” (Figure 12). That same day, Coolpad confirmed the vulnerability, gave it the highest-ranking score (20) and made the comment “Thank you for providing the information, we will fix it ASAP. Thanks.” (Figure 13)
Wooyun.org is a vulnerability assessment crowdsourcing website similar to Bugcrowd. On November 19, 2014 an independent white hat researcher named “爱上平顶山” (Aishangpingdingshan) submitted a vulnerability (WooYun-2014-83824) to Coolpad with the title “A critical vulnerability in Coolpad’s official backend platform for silently installing APK functionality” (Figure 12). That same day, Coolpad confirmed the vulnerability, gave it the highest-ranking score (20) and made the comment “Thank you for providing the information, we will fix it ASAP. Thanks.” (Figure 13)