PLINKFEED
검색구독
ALLAI-MLBACKENDFRONTENDDEVOPSSECURITYMOBILEDATABASECLOUDOTHER

© 2026 PLINKFEED — AI가 선별한 IT 기술 뉴스

구독소개개인정보처리방침이용약관

알아야 할 것

보안·AI 이슈 중 챙겨봐야 할 소식

알아야 할 것보안 · AI 이슈시도해볼 것따라 해보는 기술
10·security·기타·The Hacker News·2026. 08. 12.

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.

A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.

#sap#commerce cloud#cve-2026-58231
요약 보기원문 →
10·security·기타·The Hacker News·2026. 08. 08.

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase의 심각한 보안 취약점이 악용되어 인증 없이 관리 접근이 가능함.

A critical vulnerability in Metabase allows admin access without authentication.

#metabase#sql#vulnerability#zero-day
요약 보기원문 →
10·security·기타·The Hacker News·2026. 07. 29.

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Ruflo의 중대한 보안 취약점이 발견되어 원격 코드 실행이 가능해졌다.

A critical security flaw in Ruflo allows unauthenticated remote code execution.

#ruflo#anthropic#openai#cve-2026-59726#rce
요약 보기원문 →
10·security·기타·The Hacker News·2026. 07. 11.

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

jscrambler 8.14.0 npm 패키지가 해킹되어 악성코드가 배포됐다.

The jscrambler 8.14.0 npm package was compromised, dropping malware during installation.

#jscrambler#npm#infostealer#rust#malware
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 13.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.

Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.

#sharepoint#cve-2026-55040#authentication#vulnerability#exploit
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

라자루스 그룹이 윈도우 취약점을 악용하여 백도어를 배포했다.

Lazarus Group exploits Windows zero-day to deploy a backdoor.

#windows#zero-day#lazarus#check point research#backdoor
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

VMware vCenter의 보안 취약점이 악용되어 원격 접근이 가능해졌다.

VMware vCenter's security flaw is being exploited for remote access.

#vmware#vcenter#cve-2026-59310#vulnerability#security
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

OpenAI와 다른 기업의 API flaw로 AI 모델 간의 비밀이 노출될 위험이 있다.

A flaw in APIs from OpenAI and others risks exposing secrets between AI models.

#api#openai#google#anthropic#encryption
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe가 ColdFusion과 Campaign Classic의 주요 보안 취약점을 패치했습니다.

Adobe patches critical security vulnerabilities in ColdFusion and Campaign Classic.

#coldfusion#cve-2026-48362#campaign classic#privilege escalation#arbitrary code execution
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Microsoft Defender의 패치 우회 취약점인 ShieldBreak PoC가 공개되었습니다.

A PoC for the ShieldBreak zero-day vulnerability in Microsoft Defender has been released.

#microsoft defender#zero-day#vulnerability#cve-2026-50656
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

AI를 활용한 SharePoint 취약점이 확인되었습니다.

An AI-assisted vulnerability in SharePoint allows unauthorized access.

#sharepoint#cve-2026-55040#rce#ai
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

마이크로소프트가 398개의 취약점을 패치했습니다.

Microsoft patches 398 vulnerabilities, including an actively exploited Windows driver zero-day.

#windows#cve-2026-68820#kernel#security#zero-day
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

줌의 주석 도구에 취약점이 발견되어 회의 참가자가 다른 사용자의 클라이언트를 탈취할 수 있음.

Zoom's annotation tool flaw could allow participants to hijack other attendees' clients.

#zoom#security#annotation#vulnerability
요약 보기원문 →
9·security·기타·Krebs on Security·2026. 08. 11.

Microsoft Plugs Nearly 400 Security Holes

마이크로소프트가 398개의 보안 취약점을 수정한 업데이트를 발표했습니다.

Microsoft has released updates to fix 398 security vulnerabilities.

#windows#vulnerability#exploit#security
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

윈도우 11에서 USB 자동 설치 기능을 악용해 시스템 전체를 장악할 수 있는 방법이 발견됐다.

Researchers discovered a way to abuse USB auto-install on Windows 11 for full system takeover.

#windows#plug_and_play#usb#remote_desktop
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Gunra 랜섬웨어가 Fortinet과 Schneider Electric의 취약점을 악용해 네트워크를 침해합니다.

Gunra ransomware exploits vulnerabilities in Fortinet and Schneider Electric to breach networks.

#fortinet#schneider electric#ransomware#cybersecurity#critical infrastructure
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

악성 SIM 카드가 IoT 장치의 모뎀에서 공격자 코드를 실행할 수 있다.

A malicious SIM card can execute attacker code inside IoT device modems.

#sim#iot#modem#security#telecom
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

해커가 폴란드 발전소의 제어 시스템을 해킹하여 터빈을 정지시켰습니다.

Hackers breached Polish power plant controls and shut down a turbine.

#power plant#cyber attack#cellular network#steam turbine#heat supply
요약 보기원문 →
9·security·분석·The Hacker News·2026. 08. 11.

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

악성 MCP 서버가 AI 코딩 에이전트로부터 비밀번호와 데이터를 유출할 수 있는 방법을 설명합니다.

Malicious MCP servers can exfiltrate secrets from AI coding agents through fragmented requests.

#mcp#ssh#environment secrets#source code#customer data
요약 보기원문 →
9·ai-ml·기타·The Hacker News·2026. 08. 10.

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI의 신모델 Astra가 사이버 성능을 발전시키며 내부 활동을 일시 중지하고 보안 조치를 시행한다고 발표했다.

OpenAI pauses activities on its next AI model Astra after cybersecurity advancements call for enhanced security measures.

#openai#astra#cybersecurity#ai
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 08.

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster 보안 결함이 CISA KEV에 등록되었다.

Progress Kemp LoadMaster flaw added to CISA KEV after reported exploits.

#cisa#vulnerability#cve-2026-8037#command injection#loadmaster
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 07.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

약 800개의 악성 npm 패키지가 다양한 운영체제를 겨냥한 맬웨어를 배포하고 있다.

Nearly 800 malicious npm packages have been published targeting various operating systems with malware.

#npm#malware#rat#infostealer#typo-squatting
요약 보기원문 →
9·security·기타·The New Stack·2026. 08. 07.

The npm attack that turned provenance attestations into camouflage

npm 공급망 공격이 400개 이상 패키지에 영향을 미쳤습니다.

An npm supply chain attack has impacted over 400 packages.

#npm#keyv#supply-chain#security
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 07.

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Claude Code와 Gemini CLI의 결함이 GitHub CI 비밀을 노출시켰습니다.

Flaws in Claude Code and Gemini CLI exposed CI secrets on GitHub.

#github#ci#anthropic#google#openai
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 07.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

워드프레스에서 인증 전 XSS 취약점이 발견되어 패치가 필요합니다.

A pre-auth XSS vulnerability in WordPress requires an urgent patch.

#wordpress#xss#php#cve-2026-64638
요약 보기원문 →
9·security·기타·Hacker News·2026. 08. 07.·▲ 471💬 262

New Mexico court orders Meta to pay $567m over harms to children’s mental health

뉴멕시코 법원이 메타에 5억 6,700만 달러 지급 명령을 내렸다.

New Mexico court orders Meta to pay $567 million for harming children's mental health.

요약 보기원문 →
9·security·릴리즈·The Hacker News·2026. 08. 06.

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

시스코가 12개의 SD-WAN 및 IOS XE 취약점을 패치했습니다.

Cisco has released patches for 12 vulnerabilities in SD-WAN and IOS XE software.

#catalyst#sd-wan#ios#ios-xe#cvss
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 06.

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

새로운 인터럽트 주입 공격이 Spectre v2 방어를 우회할 수 있음을 밝혀냈다.

A new interrupt injection attack can bypass Spectre v2 defenses on Intel and AMD CPUs.

#linux#amd#intel#spectre#branch predictor
요약 보기원문 →
9·security·기타·GeekNews·2026. 08. 06.

Meta, AI 생성 아동 성적 학대 이미지가 포함된 광고 게재

Meta의 플랫폼에서 AI 생성 아동 성적 학대 이미지가 포함된 광고가 발견됨.

Ads containing AI-generated child sexual abuse images were found on Meta's platforms.

#meta#facebook#instagram#messenger#threads#csam
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 06.

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

CryptoJS의 약한 난수 생성기가 570만 달러 손실의 원인으로 지목되었다.

CryptoJS's weak RNG is linked to $5.7 million in thefts from crypto wallets.

#cryptojs#javascript#cryptography#wallets#security
요약 보기원문 →