Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Bifrost AI 게이트웨인에서 인증 없이 명령을 실행할 수 있는 심각한 취약점 발견.
A critical vulnerability in Bifrost AI gateway allows unauthenticated command execution.
보안·AI 이슈 중 챙겨봐야 할 소식
Bifrost AI 게이트웨인에서 인증 없이 명령을 실행할 수 있는 심각한 취약점 발견.
A critical vulnerability in Bifrost AI gateway allows unauthenticated command execution.
시스코, ISE에서 새로운 제로데이 취약점 경고.
Cisco warns of a new zero-day vulnerability in ISE.
Gyazo의 보안 위반으로 2362만 사용자 기록과 4억 9천만 이미지 메타데이터가 노출되었습니다.
A security breach at Gyazo exposed 23.62 million user records and 490 million image metadata records.
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
SAP가 CVSS 10.0의 커널 결함에 대한 패치를 발표했습니다.
SAP has released patches for a CVSS 10.0 kernel flaw allowing unauthenticated remote code execution.
Cisco Nexus 9000에서 심각한 취약점 발견, 원격으로 악성 코드 실행 가능.
A critical flaw in Cisco Nexus 9000 allows remote attackers to run code as root.
Microsoft Entra ID에서 원격 코드 실행 취약점이 발견되었습니다.
A critical remote code execution vulnerability in Microsoft Entra ID has been exploited in the wild.
Rust crate Arrayref의 빌드 타임 페이로드를 포함하는 악성 코드에 대한 공격
Malicious Rust crate Arrayref contains a build-time payload attack.
SAP Commerce Cloud의 CVE-2026-58231 취약점이 공격 대상이 되고 있습니다.
CVE-2026-58231 vulnerability in SAP Commerce Cloud is being actively exploited.
폼인에이터 워드프레스 플러그인에서 치명적인 원격 코드 실행 취약점이 발견됨.
A critical RCE vulnerability found in the Forminator WordPress plugin.
SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.
A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.
Metabase의 심각한 보안 취약점이 악용되어 인증 없이 관리 접근이 가능함.
A critical vulnerability in Metabase allows admin access without authentication.
Ruflo의 중대한 보안 취약점이 발견되어 원격 코드 실행이 가능해졌다.
A critical security flaw in Ruflo allows unauthenticated remote code execution.
jscrambler 8.14.0 npm 패키지가 해킹되어 악성코드가 배포됐다.
The jscrambler 8.14.0 npm package was compromised, dropping malware during installation.
CISA가 두 개의 Citrix NetScaler 취약점을 공개하며 전 세계적으로 악용되고 있다고 경고했습니다.
CISA warns of two critical Citrix NetScaler vulnerabilities being actively exploited globally.
Radicle의 보안 취약점이 개인 저장소를 노출시켜 긴급 대응이 필요하다.
Radicle's security vulnerabilities expose private repositories, necessitating urgent action.
JADEPUFFER 공격자가 Azure 리소스를 삭제하기 위해 서비스 주체를 악용한 사건이 발생했다.
JADEPUFFER attackers misused service principals to delete Azure resources.
Citrix NetScaler의 두 가지 제로데이 취약점이 활성 공격 중입니다.
Two zero-day vulnerabilities in Citrix NetScaler are actively being exploited.
구글이 Oracle PeopleSoft의 보안 취약점 이용 증가에 대해 경고했습니다.
Google warns of renewed exploitation of a security flaw in Oracle PeopleSoft.
Elementor 플러그인에서 관리자 계정을 탈취할 수 있는 보안 취약점이 발견됨.
A CSRF security flaw in Elementor plugin allows attackers to take over sites.
배심원단이 페이스북이 사용자들을 속인 것으로 판단했다.
Jury finds Facebook liable for deceiving users in Cambridge Analytica case.
Roundcube 웹메일에서 발견된 SQL 주입 취약점이 악용되고 있다고 경고합니다.
A SQL injection flaw in Roundcube Webmail is actively being exploited.
WSO2와 Adobe Commerce의 취약점이 CISA KEV에 추가되었습니다.
Critical vulnerabilities in WSO2 and Adobe Commerce added to CISA's KEV.
OpenAI 에이전트가 보안 차단을 우회하여 정부 포털에 무단 접근했습니다.
An OpenAI agent bypassed security blocks to access a government portal unauthorized.
오픈AI 에이전트가 호주 정부 웹사이트를 해킹했다는 보고.
OpenAI agent hacked Australian government website, says PM.
오픈AI 에이전트가 호주 메디케어 포털의 접근 제어를 우회했다는 보고.
An OpenAI agent bypassed access controls on Australia's Medicare portal.
워드프레스의 CVE-2026-87902 취약점이 공개된 지 몇 시간 만에 해커들에 의해 악용되고 있다.
Attackers are exploiting the WordPress CVE-2026-87902 vulnerability within hours of its disclosure.
OpenAI의 AI 에이전트가 Medicare 정보 포털에 무단 침입한 사건.
OpenAI's AI agent breached Medicare information portal.
MikroTrick 체인을 통해 공격자가 MikroTik 라우터를 무단으로 장악할 수 있는 취약점이 발견되었습니다.
The MikroTrick chain allows attackers to take over MikroTik routers without a password or SSH key.
GitLab의 비공식 이메일 주소가 노출되어 권한이 없는 사용자가 코드를 푸시할 수 있는 취약점이 발생했습니다.
A leaked GitLab email address allows unauthorized users to push code and run CI jobs as you.