GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
AI가 선별한 아티클
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
Anthropic은 중국의 7개 AI 연구소가 클로드에 대한 불법 증류 공격을 감지하고 방지했다고 밝혔다.
Anthropic reports disruption of industrial-scale distillation attacks on Claude from seven AI labs in China.
안소프틱의 클로드 모델이 사이버 범죄에 악용되고 있다.
Anthropic warns that its Claude models are being misused for cyber attacks.
러시아 국가 지원 해커들이 클로드를 사용하여 악성코드를 재구성하는 캠페인을 시작했다.
Russian state-sponsored hackers have launched a campaign to rebuild malware using Claude.
보안 취약점에 대한 새로운 접근법을 제시합니다.
Introduces a new approach to evaluating security vulnerabilities.
공격자들이 JFrog Artifactory의 취약점을 이용해 관리 권한을 탈취하고 백도어를 심었다.
Attackers exploited vulnerabilities in JFrog Artifactory to gain admin access and plant backdoors.
중국 해킹 그룹이 Sogou 입력기 결함을 이용해 GRAYRABBIT 백도어를 설치했다.
A Chinese hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor.
PaperCut가 두 개의 보안 취약점에 대한 긴급 패치를 일반 유지보수 릴리즈로 대체했습니다.
PaperCut replaces emergency patches with regular maintenance releases for two security flaws.
시스코 FMC 취약점이 공격에 이용되어 자격증명이 도용되고 있다.
Cisco FMC vulnerabilities exploited to steal credentials and deploy ransomware.
이번 주 보안 뉴스는 다양한 위협 요인에 대해 다룬다.
This week's security news covers various threat factors.
구글 플레이 얼리 액세스 프로그램이 악용되어 기만적인 안드로이드 앱이 배포되고 있다.
Google Play's Early Access program is being abused to release deceptive Android apps.
Check Point의 VPN 인증서 취약점이 발견되어 원격 코드를 실행할 수 있는 위험이 존재합니다.
Check Point disclosed VPN certificate flaws allowing unauthenticated remote code execution.
종합적 보안 취약점 공격에 AI를 사용하는 해커에 대한 경고.
Warning about hackers using AI to exploit vulnerabilities in PaperCut.
Gigabud 뱅킹 트로이목마가 안드로이드 작업 프로file을 생성하여 은행 앱 악성코드 검사를 우회합니다.
Gigabud banking trojan creates an Android work profile to bypass banking app malware checks.
CISA가 Cisco, Citrix, Fortinet 취약점을 경고하고 2026년 9월 12일까지 패치를 요구합니다.
CISA warns of vulnerabilities in Cisco, Citrix, and Fortinet, requiring patches by September 12, 2026.
LiteLLM 게이트웨이의 10%가 기본 관리자 키인 'sk-1234'를 수용했다는 보고서.
Nearly 10% of exposed LiteLLM gateways accepted the default admin key 'sk-1234'.
Anthropic가 AI 모델의 보안 사고를 공개하며 우려를 표명했습니다.
Anthropic disclosed a fourth AI hacking incident involving Claude Opus 4.6.
미국, Xinbi Guarantee 사기 마켓플레이스를 중단하고 5280만 달러의 암호화폐를 동결했다.
U.S. disrupts the Xinbi Guarantee scam marketplace, freezing $52.8 million in crypto.
Four spy groups가 같은 Chrome 및 Windows 취약점을 사용하여 공격을 감행했습니다.
Four spy groups exploited the same vulnerabilities in Chrome and Windows using the BlueMoon exploit kit.
정보 탈취 로그로 AI 토큰이 유출되어 MFA를 우회할 수 있는 위험이 증가하고 있다.
Info-stealer logs are leaking AI tokens that can bypass MFA, increasing security risks.
CVE 공개 후 신속하게 노출 여부를 확인하는 방법을 배울 수 있는 웨비나 소개.
Introduction to a webinar on how to quickly determine exposure after a CVE disclosure.
DeepSeek Harness의 결함으로 AI 에이전트가 샌드박스를 비활성화할 수 있음.
Flaw in DeepSeek Harness lets AI agents disable their own sandbox without approval.
Alby Hub의 치명적 결함으로 인해 공격자가 인터넷에 노출된 비트코인 지갑을 차지할 수 있는 위험이 있다.
A critical flaw in Alby Hub could allow attackers to take over internet-exposed Bitcoin wallets.
미국 기관들이 중국 AI 기업의 시스템적 기능 추출을 고발했다.
U.S. agencies accuse Chinese AI firms of systematic extraction of U.S. AI model functionalities.
Chrome의 V8 엔진에서 제로데이 취약점이 발견되어 패치가 이루어졌다.
A zero-day vulnerability in Chrome's V8 engine has been patched following active exploitation.
cPanel의 취약점으로 이메일 권한을 가진 계정이 서버의 root 권한으로 코드 실행 가능.
cPanel flaw allows a mail-privileged hosting account to run code as root.
F5 BIG-IP APM 기기에서 PHP 웹 셸이 메모리에 주입되어 디스크 스캔을 회피하는 악성 코드가 발견됨.
Malware on F5 BIG-IP APM injects a PHP web shell into memory, evading disk scans.
Microsoft Defender의 ShieldBreak 취약점이 우회될 수 있음을 보여주는 PoC가 공개되었다.
A PoC demonstrating a bypass for Microsoft Defender's ShieldBreak vulnerability has been released.
SAP가 CVSS 10.0의 커널 결함에 대한 패치를 발표했습니다.
SAP has released patches for a CVSS 10.0 kernel flaw allowing unauthenticated remote code execution.
마이크로소프트가 974개의 취약점을 패치하며 기록을 경신했다.
Microsoft sets a record by patching 974 vulnerabilities, including two actively exploited zero-days.