10·security·기타·The Hacker News·2026. 08. 12. SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.
A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.
10·security·기타·The Hacker News·2026. 08. 08. Metabase의 심각한 보안 취약점이 악용되어 인증 없이 관리 접근이 가능함.
A critical vulnerability in Metabase allows admin access without authentication.
10·security·기타·The Hacker News·2026. 07. 29. Ruflo의 중대한 보안 취약점이 발견되어 원격 코드 실행이 가능해졌다.
A critical security flaw in Ruflo allows unauthenticated remote code execution.
10·security·기타·The Hacker News·2026. 07. 11. jscrambler 8.14.0 npm 패키지가 해킹되어 악성코드가 배포됐다.
The jscrambler 8.14.0 npm package was compromised, dropping malware during installation.
9·security·기타·The Hacker News·2026. 08. 13. 새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.
Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.
9·security·기타·The Hacker News·2026. 08. 12. 라자루스 그룹이 윈도우 취약점을 악용하여 백도어를 배포했다.
Lazarus Group exploits Windows zero-day to deploy a backdoor.
9·security·기타·The Hacker News·2026. 08. 12. VMware vCenter의 보안 취약점이 악용되어 원격 접근이 가능해졌다.
VMware vCenter's security flaw is being exploited for remote access.
9·security·기타·The Hacker News·2026. 08. 12. OpenAI와 다른 기업의 API flaw로 AI 모델 간의 비밀이 노출될 위험이 있다.
A flaw in APIs from OpenAI and others risks exposing secrets between AI models.
9·security·기타·The Hacker News·2026. 08. 12. Adobe가 ColdFusion과 Campaign Classic의 주요 보안 취약점을 패치했습니다.
Adobe patches critical security vulnerabilities in ColdFusion and Campaign Classic.
9·security·기타·The Hacker News·2026. 08. 12. Microsoft Defender의 패치 우회 취약점인 ShieldBreak PoC가 공개되었습니다.
A PoC for the ShieldBreak zero-day vulnerability in Microsoft Defender has been released.
9·security·기타·The Hacker News·2026. 08. 11. AI를 활용한 SharePoint 취약점이 확인되었습니다.
An AI-assisted vulnerability in SharePoint allows unauthorized access.
9·security·기타·The Hacker News·2026. 08. 11. 마이크로소프트가 398개의 취약점을 패치했습니다.
Microsoft patches 398 vulnerabilities, including an actively exploited Windows driver zero-day.
9·security·기타·The Hacker News·2026. 08. 11. 줌의 주석 도구에 취약점이 발견되어 회의 참가자가 다른 사용자의 클라이언트를 탈취할 수 있음.
Zoom's annotation tool flaw could allow participants to hijack other attendees' clients.
9·security·기타·Krebs on Security·2026. 08. 11. 마이크로소프트가 398개의 보안 취약점을 수정한 업데이트를 발표했습니다.
Microsoft has released updates to fix 398 security vulnerabilities.
9·security·기타·The Hacker News·2026. 08. 11. 윈도우 11에서 USB 자동 설치 기능을 악용해 시스템 전체를 장악할 수 있는 방법이 발견됐다.
Researchers discovered a way to abuse USB auto-install on Windows 11 for full system takeover.
9·security·기타·The Hacker News·2026. 08. 11. Gunra 랜섬웨어가 Fortinet과 Schneider Electric의 취약점을 악용해 네트워크를 침해합니다.
Gunra ransomware exploits vulnerabilities in Fortinet and Schneider Electric to breach networks.
9·security·기타·The Hacker News·2026. 08. 11. 악성 SIM 카드가 IoT 장치의 모뎀에서 공격자 코드를 실행할 수 있다.
A malicious SIM card can execute attacker code inside IoT device modems.
9·security·기타·The Hacker News·2026. 08. 11. 해커가 폴란드 발전소의 제어 시스템을 해킹하여 터빈을 정지시켰습니다.
Hackers breached Polish power plant controls and shut down a turbine.
9·security·분석·The Hacker News·2026. 08. 11. 악성 MCP 서버가 AI 코딩 에이전트로부터 비밀번호와 데이터를 유출할 수 있는 방법을 설명합니다.
Malicious MCP servers can exfiltrate secrets from AI coding agents through fragmented requests.
9·ai-ml·기타·The Hacker News·2026. 08. 10. OpenAI의 신모델 Astra가 사이버 성능을 발전시키며 내부 활동을 일시 중지하고 보안 조치를 시행한다고 발표했다.
OpenAI pauses activities on its next AI model Astra after cybersecurity advancements call for enhanced security measures.
9·security·기타·The Hacker News·2026. 08. 08. Progress Kemp LoadMaster 보안 결함이 CISA KEV에 등록되었다.
Progress Kemp LoadMaster flaw added to CISA KEV after reported exploits.
9·security·기타·The Hacker News·2026. 08. 07. 약 800개의 악성 npm 패키지가 다양한 운영체제를 겨냥한 맬웨어를 배포하고 있다.
Nearly 800 malicious npm packages have been published targeting various operating systems with malware.
9·security·기타·The New Stack·2026. 08. 07. npm 공급망 공격이 400개 이상 패키지에 영향을 미쳤습니다.
An npm supply chain attack has impacted over 400 packages.
9·security·기타·The Hacker News·2026. 08. 07. Claude Code와 Gemini CLI의 결함이 GitHub CI 비밀을 노출시켰습니다.
Flaws in Claude Code and Gemini CLI exposed CI secrets on GitHub.
9·security·기타·The Hacker News·2026. 08. 07. 워드프레스에서 인증 전 XSS 취약점이 발견되어 패치가 필요합니다.
A pre-auth XSS vulnerability in WordPress requires an urgent patch.
9·security·기타·Hacker News·2026. 08. 07.·▲ 471💬 262 뉴멕시코 법원이 메타에 5억 6,700만 달러 지급 명령을 내렸다.
New Mexico court orders Meta to pay $567 million for harming children's mental health.
9·security·릴리즈·The Hacker News·2026. 08. 06. 시스코가 12개의 SD-WAN 및 IOS XE 취약점을 패치했습니다.
Cisco has released patches for 12 vulnerabilities in SD-WAN and IOS XE software.
9·security·기타·The Hacker News·2026. 08. 06. 새로운 인터럽트 주입 공격이 Spectre v2 방어를 우회할 수 있음을 밝혀냈다.
A new interrupt injection attack can bypass Spectre v2 defenses on Intel and AMD CPUs.
9·security·기타·GeekNews·2026. 08. 06. Meta의 플랫폼에서 AI 생성 아동 성적 학대 이미지가 포함된 광고가 발견됨.
Ads containing AI-generated child sexual abuse images were found on Meta's platforms.
9·security·기타·The Hacker News·2026. 08. 06. CryptoJS의 약한 난수 생성기가 570만 달러 손실의 원인으로 지목되었다.
CryptoJS's weak RNG is linked to $5.7 million in thefts from crypto wallets.