GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
보안·AI 이슈 중 챙겨봐야 할 소식
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
SAP가 CVSS 10.0의 커널 결함에 대한 패치를 발표했습니다.
SAP has released patches for a CVSS 10.0 kernel flaw allowing unauthenticated remote code execution.
Cisco Nexus 9000에서 심각한 취약점 발견, 원격으로 악성 코드 실행 가능.
A critical flaw in Cisco Nexus 9000 allows remote attackers to run code as root.
Microsoft Entra ID에서 원격 코드 실행 취약점이 발견되었습니다.
A critical remote code execution vulnerability in Microsoft Entra ID has been exploited in the wild.
Rust crate Arrayref의 빌드 타임 페이로드를 포함하는 악성 코드에 대한 공격
Malicious Rust crate Arrayref contains a build-time payload attack.
SAP Commerce Cloud의 CVE-2026-58231 취약점이 공격 대상이 되고 있습니다.
CVE-2026-58231 vulnerability in SAP Commerce Cloud is being actively exploited.
폼인에이터 워드프레스 플러그인에서 치명적인 원격 코드 실행 취약점이 발견됨.
A critical RCE vulnerability found in the Forminator WordPress plugin.
SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.
A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.
Metabase의 심각한 보안 취약점이 악용되어 인증 없이 관리 접근이 가능함.
A critical vulnerability in Metabase allows admin access without authentication.
Ruflo의 중대한 보안 취약점이 발견되어 원격 코드 실행이 가능해졌다.
A critical security flaw in Ruflo allows unauthenticated remote code execution.
jscrambler 8.14.0 npm 패키지가 해킹되어 악성코드가 배포됐다.
The jscrambler 8.14.0 npm package was compromised, dropping malware during installation.
시스코 FMC 취약점이 공격에 이용되어 자격증명이 도용되고 있다.
Cisco FMC vulnerabilities exploited to steal credentials and deploy ransomware.
Forgejo의 16.0.3 이하 버전에 심각한 RCE 취약점이 발견됨.
A serious RCE vulnerability found in Forgejo versions 16.0.3 and below.
Forgejo <=16.0.3에서 발견된 심각한 원격 코드 실행 취약점.
Critical RCE vulnerability found in Forgejo <=16.0.3.
CISA가 Cisco, Citrix, Fortinet 취약점을 경고하고 2026년 9월 12일까지 패치를 요구합니다.
CISA warns of vulnerabilities in Cisco, Citrix, and Fortinet, requiring patches by September 12, 2026.
Check Point의 VPN 인증서 취약점이 발견되어 원격 코드를 실행할 수 있는 위험이 존재합니다.
Check Point disclosed VPN certificate flaws allowing unauthenticated remote code execution.
cPanel의 취약점으로 이메일 권한을 가진 계정이 서버의 root 권한으로 코드 실행 가능.
cPanel flaw allows a mail-privileged hosting account to run code as root.
CISA가 N-able N-central의 심각한 보안 결함을 알려드렸습니다.
CISA warns of a severe security flaw in N-able N-central.
F5 BIG-IP APM 기기에서 PHP 웹 셸이 메모리에 주입되어 디스크 스캔을 회피하는 악성 코드가 발견됨.
Malware on F5 BIG-IP APM injects a PHP web shell into memory, evading disk scans.
Chrome의 V8 엔진에서 제로데이 취약점이 발견되어 패치가 이루어졌다.
A zero-day vulnerability in Chrome's V8 engine has been patched following active exploitation.
마이크로소프트가 974개의 취약점을 패치하며 기록을 경신했다.
Microsoft sets a record by patching 974 vulnerabilities, including two actively exploited zero-days.
Microsoft Defender의 ShieldBreak 취약점이 우회될 수 있음을 보여주는 PoC가 공개되었다.
A PoC demonstrating a bypass for Microsoft Defender's ShieldBreak vulnerability has been released.
정보 탈취 로그로 AI 토큰이 유출되어 MFA를 우회할 수 있는 위험이 증가하고 있다.
Info-stealer logs are leaking AI tokens that can bypass MFA, increasing security risks.
AI를 활용한 해킹 그룹이 6시간 만에 자격증명 수천 개를 탈취했습니다.
AI-driven hackers stole thousands of credentials in just six hours.
ChatGPT의 취약점을 통해 사용자의 Gmail 데이터가 공격자에게 전송될 수 있음.
A flaw in ChatGPT can cause a victim's Gmail data to be sent to an attacker.
마이크로소프트가 보안 취약점 974개를 수정하는 패치를 발표했다.
Microsoft issued updates to fix 974 security vulnerabilities, the largest patch batch ever.
Adobe가 Magento의 제로데이 취약점에 대한 보안 패치를 발표했습니다.
Adobe released security patches for a zero-day vulnerability in Magento.
OpenAI의 수석 과학자가 AI가 인간을 속일 수 있다고 경고했습니다.
OpenAI's chief scientist warns that AI could trick and blackmail humans.
LG 스마트 TV에서 주요 보안 문제가 발견되었습니다.
Major security issues found in LG Smart TVs.
강남언니에서 22만 명의 개인정보가 유출되었습니다.
220,000 personal data records were leaked from Gangnam Unni.