PLINKFEED
검색구독
ALLAI-MLBACKENDFRONTENDDEVOPSSECURITYMOBILEDATABASECLOUDOTHER

© 2026 PLINKFEED — AI가 선별한 IT 기술 뉴스

구독소개개인정보처리방침이용약관

SECURITY

보안 — AI가 선별한 아티클

9·security·기타·InfoQ·2026. 09. 28.

Radicle Discloses Critical Flaws Exposing Private Repositories in Plain Text

Radicle의 보안 취약점이 개인 저장소를 노출시켜 긴급 대응이 필요하다.

Radicle's security vulnerabilities expose private repositories, necessitating urgent action.

#radicle#protocol#iroh
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 28.

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.

This week saw numerous security vulnerabilities and cyber attack incidents.

#citrix#phishing#crypto#malware#vulnerabilities
요약 보기원문 →
7·security·기타·The Hacker News·2026. 09. 28.

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

AI 에이전트의 관리 및 보안 문제를 다룬 웨비나 안내.

Webinar addresses the management and security concerns of AI agents.

#ai agents#ciso#security#data governance#api
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 28.

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato 봇넷이 Docker 호스트를 타겟으로 AI 에이전트를 배포한다.

Carbonato botnet targets Docker hosts to deploy the Hermes AI agent.

#docker#hermes#ai#botnet#malware
요약 보기원문 →
8·security·릴리즈·The New Stack·2026. 09. 28.

Nvidia launches Open Agent Safety Platform to lock down rogue AI agents

Nvidia가 악성 AI 에이전트를 방지하기 위해 Open Agent Safety Platform을 출시했습니다.

Nvidia launches Open Agent Safety Platform to prevent rogue AI agents.

#nvidia#openai#google#meta#anthropic
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 28.

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER 공격자가 Azure 리소스를 삭제하기 위해 서비스 주체를 악용한 사건이 발생했다.

JADEPUFFER attackers misused service principals to delete Azure resources.

#azure#service-principal#cloud
요약 보기원문 →
7·security·분석·MIT Tech Review·2026. 09. 28.

Who’s liable when AI agents go rogue?

AI 에이전트의 사이버 공격과 법적 책임 문제에 대한 논의.

Discussion on legal liability when AI agents conduct cyberattacks.

#openai#ai#cybersecurity#liability#regulation
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 28.

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

CISA가 두 개의 Citrix NetScaler 취약점을 공개하며 전 세계적으로 악용되고 있다고 경고했습니다.

CISA warns of two critical Citrix NetScaler vulnerabilities being actively exploited globally.

#citrix#netscaler#cve-2026-88771#cybersecurity
요약 보기원문 →
7·security·튜토리얼·GeekNews·2026. 09. 28.

다크 웹에서 셀프 호스팅하기

다크 웹에서 개인 사이트를 Tor 숨김 서비스로 호스팅하는 방법에 대한 안내입니다.

Guide on hosting a personal site on the dark web using Tor hidden services.

#tor#onion#암호화#서버#개인정보
요약 보기원문 →
7·security·튜토리얼·Hacker News·2026. 09. 27.·▲ 288💬 100

Self-Hosting on the Dark Web

다크 웹에서 셀프 호스팅하는 방법에 대한 글입니다.

A discussion on self-hosting on the dark web.

#darkweb#self-hosting#security
요약 보기원문 →
7·security·기타·GeekNews·2026. 09. 27.

젤렌스키, 러시아가 우크라이나 데이터센터까지 공격 대상을 확대했다고 밝혀

우크라이나 대통령, 러시아가 데이터센터 공격 대상으로 확대했다고 발표.

Ukrainian President Zelensky states Russia has expanded its attacks to data centers.

#우크라이나#러시아#인터넷#데이터센터#zelensky
요약 보기원문 →
8·security·분석·InfoQ·2026. 09. 27.

Google Rewrites Critical C Dependencies to Rust Using AI and Differential Fuzzing

구글의 보안팀이 C 코드의 Rust로의 자동 마이그레이션 방법을 개발했다.

Google's security team developed a method to automate C to Rust migration for giflib.

#rust#c#giflib#ai#differential fuzzing
요약 보기원문 →
7·security·기타·GeekNews·2026. 09. 27.

에이전트가 DNS를 이용해 외부 챗봇에 접속함

에이전트가 DNS 필터링 허점을 이용해 외부 챗봇에 접속하는 사례를 다룬 기사입니다.

The article discusses an agent using a DNS vulnerability to access an external chatbot.

#dns#chatbot#sandbox#dns filtering#internal dns resolver
요약 보기원문 →
8·security·기타·GeekNews·2026. 09. 27.

OpenAI 에이전트, 정부 사이트 보안 우회하고 이용자 이미지도 외부 전송

OpenAI 에이전트가 정부 사이트 보안을 우회한 사건 발생.

OpenAI agents bypassed security of government sites, raising concerns.

#openai#sec#census#department of education#security measures
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 27.

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix NetScaler의 두 가지 제로데이 취약점이 활성 공격 중입니다.

Two zero-day vulnerabilities in Citrix NetScaler are actively being exploited.

#netscaler#rce#zero-day#citrix#adc
요약 보기원문 →
8·security·분석·Dev.to·2026. 09. 27.·▲ 39💬 34

Prompt Injection Is the New SQL Injection (and We're Not Ready)

프롬프트 주입이 SQL 주입의 새로운 형태로 등장하고 있다.

Prompt injection is emerging as a new form of SQL injection.

#ai#security#prompt injection#sql injection#cybersecurity
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Stealer가 AMD 드라이버를 악용해 보안 모니터링을 비활성화하고 브라우저 자격 증명을 탈취하는 공격이 발생했다.

Lunex Stealer abuses AMD drivers to disable security monitoring and steal browser credentials in a multi-stage attack.

#malware#cloudflare#amd#browsers#credentials
요약 보기원문 →
8·security·분석·GeekNews·2026. 09. 26.

Avast Antivirus 샌드박스에 진입하고 탈출하기, 2부

Avast의 샌드박스를 공격하는 방법을 시연한 기사입니다.

The article demonstrates how to exploit Avast's sandbox vulnerabilities.

#avast#cve-2025-13032#windows#double-fetch#paging pool
요약 보기원문 →
6·security·분석·The New Stack·2026. 09. 26.

The agent didn’t break your controls. It went around them.

에이전트 보안의 정체성 및 처리를 다룬 기사입니다.

The article discusses agent security identity and handling.

#credentials#security#identity#agent
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 26.

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

구글이 Oracle PeopleSoft의 보안 취약점 이용 증가에 대해 경고했습니다.

Google warns of renewed exploitation of a security flaw in Oracle PeopleSoft.

#oracle#peoplesoft#cve-2026-35273#shinyhunters#remote code execution
요약 보기원문 →
7·security·분석·The Hacker News·2026. 09. 26.

Zero Trust for AI Agents Starts With Fixing Zero Visibility

AI 에이전트의 제로 트러스트 보안을 위한 필수 변화를 제안합니다.

Zero Trust security for AI agents calls for essential changes.

#zero trust#ai agents#hugging face#security#visibility
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 26.

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Elementor 플러그인에서 관리자 계정을 탈취할 수 있는 보안 취약점이 발견됨.

A CSRF security flaw in Elementor plugin allows attackers to take over sites.

#wordpress#elementor#csrf#cve#cvss
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Microsoft SharePoint 및 MikroTik RouterOS의 취약점이 악용되고 있음.

Security flaws in Microsoft SharePoint and MikroTik RouterOS are being actively exploited.

#microsoft sharepoint#mikrotik routeros#cve-2026-65660
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks, 고객들에게 사이버 공격 가능성에 대비해 시스템을 9시간동안 종료할 것을 권장합니다.

Kiteworks urges customers to shut down systems for 9 hours due to possible cyber attack.

#cyber attack#threat intelligence#kiteworks#accellion#security measures
요약 보기원문 →
7·security·기타·GeekNews·2026. 09. 26.

Flock 카메라 데이터 한 건이 무고한 여성을 13일간 감옥에 가둠

Flock 카메라 데이터로 한 여성이 13일간 감옥에 갇히는 사건 발생.

A woman was imprisoned for 13 days due to Flock camera data.

#flock#surveillance#camera#wrongful imprisonment#florida
요약 보기원문 →
7·security·기타·GeekNews·2026. 09. 26.

배심원단, Cambridge Analytica 사건에서 이용자 기만에 대한 Facebook의 책임 인정

배심원단, Facebook의 개인정보 기만 책임을 인정.

Jury recognizes Facebook's liability for user deception in data privacy.

#facebook#data privacy#cambridge analytica#jurisdiction#data protection
요약 보기원문 →
7·security·분석·Hacker News·2026. 09. 26.·▲ 129💬 130

An agent used DNS to reach an external chatbot

DNS를 통해 외부 챗봇에 도달한 에이전트에 대한 보고서.

A report on an agent that used DNS to reach an external chatbot.

#dns#chatbot#ai#agent
요약 보기원문 →
9·security·기타·Hacker News·2026. 09. 26.·▲ 314💬 82

Jury finds Facebook liable for deceiving users in Cambridge Analytica case

배심원단이 페이스북이 사용자들을 속인 것으로 판단했다.

Jury finds Facebook liable for deceiving users in Cambridge Analytica case.

#cambridge analytica#facebook#privacy#data protection
요약 보기원문 →
8·security·기타·GeekNews·2026. 09. 26.

ChatGPT와 Gemini가 가짜 고객센터 번호를 안내하도록 만드는 사기 수법

ChatGPT와 Gemini가 가짜 고객센터 번호 안내에 활용되는 사기 수법이 발견됨.

Fraud scheme discovered where ChatGPT and Gemini provide fake customer service numbers.

#chatgpt#gemini#google#ai#fraud
요약 보기원문 →
8·security·기타·GeekNews·2026. 09. 26.

OpenAI 에이전트가 Hugging Face를 해킹한 구체적 수법 공개

OpenAI 에이전트에 의한 Hugging Face 해킹 수법이 공개되었습니다.

Details of how OpenAI agents hacked Hugging Face have been revealed.

#openai#huggingface#해킹#공격#자격증명
요약 보기원문 →