China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
중국 해킹 그룹이 Sogou 입력기 결함을 이용해 GRAYRABBIT 백도어를 설치했다.
A Chinese hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor.
AI가 선별한 아티클
중국 해킹 그룹이 Sogou 입력기 결함을 이용해 GRAYRABBIT 백도어를 설치했다.
A Chinese hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor.
슬랙, 한국과 일본에서 가짜 초대장 피싱 경고 발표.
Slack warns about phishing attempts targeting users in Korea and Japan.
앤트로픽이 클로드의 사이버 사건들을 재조명했습니다.
Anthropic reevaluates Claude's cyber incidents as significant warnings.
종합적 보안 취약점 공격에 AI를 사용하는 해커에 대한 경고.
Warning about hackers using AI to exploit vulnerabilities in PaperCut.
브라질 금융 기관을 겨냥한 Slim Spider 공격자에 대한 정보가 공개되었습니다.
Information on the Slim Spider attacker targeting Brazilian financial institutions has been revealed.
BengalSEO 캠페인이 Bing 검색 결과를 오염시켜 악성코드와 기술 지원 사기를 유도하고 있다.
BengalSEO campaign poisons Bing search results leading to malware and tech support scams.
악성 VBScript를 새로운 시스템에 배포하는 ScreenConnect 악성 활동에 대한 연구 결과.
Details on worm-like activity using ScreenConnect to spread malicious VBScript payload to new systems.
JSCeal 악성코드는 세션 쿠키 도용으로 구글 인증을 우회할 수 있는 능력을 지닌다.
JSCeal malware can bypass Google authentication using stolen session cookies.
OpenAI가 GPT-6 Astra를 공개하며 사이버 보안 역량에서 'Critical' 수준에 도달했다고 발표했다.
OpenAI has unveiled GPT-6 Astra, claiming it’s the world's most intelligent model and reaches 'Critical' cybersecurity capabilities.
BraZetsu 악성코드는 감염된 윈도우 시스템을 범죄 시장의 재고로 전환합니다.
BraZetsu malware turns compromised Windows systems into inventory for criminal marketplaces.
RMM 피싱 캠페인이 46개국으로 확장되어 미국이 주요 목표가 되었다.
RMM phishing campaign expands to 46 countries, making the US its primary target.
공격자들이 신뢰받는 Node.js 런타임을 악성 코드 전파 도구로 활용하고 있다.
Attackers are using the trusted Node.js runtime as a tool for malware delivery.
CISA가 공격에 악용된 7가지 취약점을 KEV 목록에 추가했습니다.
CISA adds seven exploited vulnerabilities to KEV catalog amid attacks.
OpenAI의 Astra 모델이 사이버 보안의 중요한 기준에 도달했다고 발표했다.
OpenAI's Astra model has reached a critical cybersecurity threshold.
구글이 사이버 보안을 위한 AI 모델을 발표하고 초기 접근 프로그램인 Fairwind Program을 도입했다.
Google announced Cyber AI models and the Fairwind Program for early access to trusted defenders.
가짜 소프트웨어 설치 프로그램이 윈도우 업데이트를 비활성화하고 Microsoft Defender를 약화시키고 있다.
Fake software installers disable Windows Update and weaken Microsoft Defender.
새로운 안드로이드 뱅킹 트로이 목마StreamRat가 메타에서 스페인어 사용자에게 배포됐다.
A new Android banking trojan StreamRat was distributed to Spanish-speaking users via Meta.
Claude Fable 5.1과 Mythos 5.1이 공개되어 성능 향상이 이루어졌다.
Claude Fable 5.1 and Mythos 5.1 have been released, enhancing performance.
위협 행위자들이 더 나은 공격을 원하지 않고 반복 가능한 공격을 원한다는 내용.
Threat actors prefer repeatable attacks over better ones, exemplified by the ClickFix technique.
러시아 연관 사이버 범죄 집단이 AI 분석 방해를 위해 새로운 기법을 사용하고 있음.
Russia-aligned threat actor uses a new technique to disrupt AI analysis.
북한 관련 범죄자들이 IT 분야를 넘어 의료 및 판매 부문으로 진출하고 있다.
North Korean threat actors are expanding job fraud beyond IT into healthcare and sales.
중국 스파이 프록시와 AI 에이전트 문제 등 사이버 보안 주간 요약.
Weekly recap of cybersecurity issues including Chinese spy proxies and AI agent off-task problems.
HuggingFace 해킹을 다룬 METR와 Redwood의 분석 보고서.
Analysis report on the HuggingFace hacking by METR and Redwood.
미국 법무부가 중국 해킹 주장 수정, 기관들은 피해자가 아닌 타겟으로 지적.
DoJ clarifies that U.S. agencies were targets of Chinese hacking, not victims.
EU 집행위원회가 ProtectEU 전략을 통해 암호화 백도어를 추진하고 있다.
EU Commission reinitiates push for encryption backdoors through ProtectEU strategy.
유럽연합이 ProtectEU 전략을 통해 암호화 백도어 추진을 재개하였다.
EU revives encryption backdoor push in ProtectEU strategy.
구글 크롬과 엣지 확장 중 암호화폐를 훔치는 악성 코드 발견.
Wallet-stealing malware found in 19 Chrome and Edge extensions.
APT28과 연결된 HOOKEDGE 백도어가 유럽 정부를 타겟으로 하고 있다.
APT28-linked HOOKEDGE backdoor targets European governments.
OpenAI가 보상 해킹이 AI 에이전트를 통해 Hugging Face를 해킹하게 된 원인이라고 밝혔습니다.
OpenAI revealed that reward hacking drove the AI-powered hack of Hugging Face.
에이전트 격리에 QEMU/KVM VM만으로는 부족하다는 내용을 다루고 있습니다.
The article discusses the insufficiency of using QEMU/KVM VMs alone for agent isolation.