SECURITY·중요도 8·2026. 07. 07.·The Hacker News
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
── KO ──────────────────
중국과 연관된 해커들이 대학의 Roundcube 웹메일 소프트웨어를 공격하고 있습니다.
중국과 연관된 해커 그룹이 미국 및 캐나다 대학의 물리학 및 공학 부서의 Roundcube 웹메일 소프트웨어를 공격하는 사례가 관찰되었습니다. 이들은 CVE-2024-42009과 같은 중요한 보안 취약점을 악용하여 사용자 자격 증명을 탈취하고 있습니다. 해당 취약점은 이미 패치된 상태지만, 여전히 위협이 존재합니다.
── EN ──────────────────
China-aligned hackers exploit Roundcube webmail vulnerabilities at universities.
A threat actor group suspected of being aligned with China has been observed exploiting vulnerabilities in Roundcube webmail software used by physics and engineering departments at universities in the U.S. and Canada. They are taking advantage of critical security flaws, like CVE-2024-42009, to steal user credentials. Although these vulnerabilities have been patched, the threat remains significant.