PLINKFEED
검색구독
ALLAI-MLBACKENDFRONTENDDEVOPSSECURITYMOBILEDATABASECLOUDOTHER

© 2026 PLINKFEED — AI가 선별한 IT 기술 뉴스

구독소개개인정보처리방침이용약관

The Hacker News

AI가 선별한 아티클

9·security·기타·The Hacker News·2026. 08. 13.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.

Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.

#sharepoint#cve-2026-55040#authentication#vulnerability#exploit
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

라자루스 그룹이 윈도우 취약점을 악용하여 백도어를 배포했다.

Lazarus Group exploits Windows zero-day to deploy a backdoor.

#windows#zero-day#lazarus#check point research#backdoor
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 12.

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

737개의 Chrome VPN 확장 프로그램이 프로 Proxy를 통해 트래픽을 라우팅하는 것이 발견됐다.

737 Chrome VPN extensions found routing traffic through proxies targeting Russian users.

#vpn#chrome#proxy#browser#malware
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

OpenAI와 다른 기업의 API flaw로 AI 모델 간의 비밀이 노출될 위험이 있다.

A flaw in APIs from OpenAI and others risks exposing secrets between AI models.

#api#openai#google#anthropic#encryption
요약 보기원문 →
7·security·분석·The Hacker News·2026. 08. 12.

Enterprise Defenses Recovered at the Edge and Collapsed Inside

2026년 블루 리포트에 따르면, 기업 방어의 효과는 과거 최고 수준에 도달했다.

The Blue Report 2026 states enterprise defenses are at their strongest yet.

#enterprise#attack-simulation#defense#cybersecurity#threat
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe가 ColdFusion과 Campaign Classic의 주요 보안 취약점을 패치했습니다.

Adobe patches critical security vulnerabilities in ColdFusion and Campaign Classic.

#coldfusion#cve-2026-48362#campaign classic#privilege escalation#arbitrary code execution
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

VMware vCenter의 보안 취약점이 악용되어 원격 접근이 가능해졌다.

VMware vCenter's security flaw is being exploited for remote access.

#vmware#vcenter#cve-2026-59310#vulnerability#security
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 12.

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

PyPI에서 발견된 악성 LiteLLM 릴리스로 2100개 이상의 조직이 노출됐다는 보고.

Malicious LiteLLM releases on PyPI may have exposed over 2,100 organizations.

#pypi#kubernetes#cloud#ssh#litellm
요약 보기원문 →
10·security·기타·The Hacker News·2026. 08. 12.

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.

A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.

#sap#commerce cloud#cve-2026-58231
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 12.

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Microsoft Defender의 패치 우회 취약점인 ShieldBreak PoC가 공개되었습니다.

A PoC for the ShieldBreak zero-day vulnerability in Microsoft Defender has been released.

#microsoft defender#zero-day#vulnerability#cve-2026-50656
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 12.

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco ASA 및 FTD의 새로운 취약점이 악용된 사례가 발견되었다.

A new vulnerability in Cisco ASA and FTD has been exploited in the wild.

#cve-2026-20349#asa#ftd#http#dos
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

마이크로소프트가 398개의 취약점을 패치했습니다.

Microsoft patches 398 vulnerabilities, including an actively exploited Windows driver zero-day.

#windows#cve-2026-68820#kernel#security#zero-day
요약 보기원문 →
7·security·기타·The Hacker News·2026. 08. 11.

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

김울프 v7 안드로이드 봇넷이 DDoS 공격을 개선했습니다.

Kimwolf v7 Android botnet enhances DDoS attack capabilities.

#android#iot#ddos#http2#cybersecurity
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

줌의 주석 도구에 취약점이 발견되어 회의 참가자가 다른 사용자의 클라이언트를 탈취할 수 있음.

Zoom's annotation tool flaw could allow participants to hijack other attendees' clients.

#zoom#security#annotation#vulnerability
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 11.

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

CERT-UA는 러시아의 UAC-0145 그룹이 가짜 채용 면접을 통해 IT 근로자를 노린 사이버 공격을 보고했다.

CERT-UA reported a new social engineering attack by Russian group UAC-0145 targeting IT workers with fake job interviews.

#sandworm#apt44#uac-0145#malware#vpn
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

AI를 활용한 SharePoint 취약점이 확인되었습니다.

An AI-assisted vulnerability in SharePoint allows unauthorized access.

#sharepoint#cve-2026-55040#rce#ai
요약 보기원문 →
7·security·기타·The Hacker News·2026. 08. 11.

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

DeadLock 랜섬웨어가 폴리곤 스마트 계약을 이용하여 extortion 인프라를 강화하고 있습니다.

DeadLock ransomware uses polygon smart contracts to enhance extortion infrastructure.

#deadlock#polygon#blockchain#ransomware#session
요약 보기원문 →
8·security·릴리즈·The Hacker News·2026. 08. 11.

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI가 사이버 보안에 초점을 맞춘 GPT-5.6-Cyber 모델을 출시했다.

OpenAI has launched a cybersecurity-focused model called GPT-5.6-Cyber.

#gpt-5.6#cybersecurity#penetration testing#vulnerability research#incident response
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

악성 SIM 카드가 IoT 장치의 모뎀에서 공격자 코드를 실행할 수 있다.

A malicious SIM card can execute attacker code inside IoT device modems.

#sim#iot#modem#security#telecom
요약 보기원문 →
7·security·기타·The Hacker News·2026. 08. 11.

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

모질라, 파이어폭스와 썬더버드의 Linux 서명 키를 폐기함.

Mozilla revokes Linux signing key for Firefox and Thunderbird.

#firefox#thunderbird#linux#cryptography#security
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 11.

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

연구자들이 가짜 암호화폐 스타트업을 만들어 북한 IT 직원 3명을 고용했다.

Researchers created a fake crypto startup and hired three suspected North Korean operatives.

#cryptocurrency#cybersecurity#virtual machine#north korea#hiring
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

윈도우 11에서 USB 자동 설치 기능을 악용해 시스템 전체를 장악할 수 있는 방법이 발견됐다.

Researchers discovered a way to abuse USB auto-install on Windows 11 for full system takeover.

#windows#plug_and_play#usb#remote_desktop
요약 보기원문 →
9·security·분석·The Hacker News·2026. 08. 11.

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

악성 MCP 서버가 AI 코딩 에이전트로부터 비밀번호와 데이터를 유출할 수 있는 방법을 설명합니다.

Malicious MCP servers can exfiltrate secrets from AI coding agents through fragmented requests.

#mcp#ssh#environment secrets#source code#customer data
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Gunra 랜섬웨어가 Fortinet과 Schneider Electric의 취약점을 악용해 네트워크를 침해합니다.

Gunra ransomware exploits vulnerabilities in Fortinet and Schneider Electric to breach networks.

#fortinet#schneider electric#ransomware#cybersecurity#critical infrastructure
요약 보기원문 →
9·security·기타·The Hacker News·2026. 08. 11.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

해커가 폴란드 발전소의 제어 시스템을 해킹하여 터빈을 정지시켰습니다.

Hackers breached Polish power plant controls and shut down a turbine.

#power plant#cyber attack#cellular network#steam turbine#heat supply
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 11.

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

BdThemes의 공급망 공격으로 WordPress 관리자 계정 생성이 악용됐다.

A supply chain attack on BdThemes creates rogue WordPress admin accounts.

#wordpress#supply chain#vulnerability#cybersecurity#plugin
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 10.

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

중국 해커들이 StormEncryptor 랜섬웨어를 배포했다는 소식입니다.

China-linked hackers have deployed a new ransomware called StormEncryptor.

#c++#ransomware#stormencryptor#medusa#microsoft
요약 보기원문 →
7·security·기타·The Hacker News·2026. 08. 10.

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

이번 주 보안 문제와 관련된 최신 소식과 경향을 다룹니다.

This week covers key topics related to security issues and trends.

#supply-chain#vulnerability#exploit#security#router
요약 보기원문 →
8·security·기타·The Hacker News·2026. 08. 10.

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.

North Korean hackers build offline AI stack to automate phishing and malware development.

#ai#malware#phishing#espionage#north korea
요약 보기원문 →
8·security·분석·The Hacker News·2026. 08. 10.

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.

New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.

#passkey#mfa#windows#authentication#malware
요약 보기원문 →