PLINKFEED
검색구독
ALLAI-MLBACKENDFRONTENDDEVOPSSECURITYMOBILEDATABASECLOUDOTHER

© 2026 PLINKFEED — AI가 선별한 IT 기술 뉴스

구독소개개인정보처리방침이용약관

The Hacker News

AI가 선별한 아티클

8·security·기타·The Hacker News·2026. 09. 28.

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.

This week saw numerous security vulnerabilities and cyber attack incidents.

#citrix#phishing#crypto#malware#vulnerabilities
요약 보기원문 →
7·security·기타·The Hacker News·2026. 09. 28.

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

AI 에이전트의 관리 및 보안 문제를 다룬 웨비나 안내.

Webinar addresses the management and security concerns of AI agents.

#ai agents#ciso#security#data governance#api
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 28.

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato 봇넷이 Docker 호스트를 타겟으로 AI 에이전트를 배포한다.

Carbonato botnet targets Docker hosts to deploy the Hermes AI agent.

#docker#hermes#ai#botnet#malware
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 28.

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER 공격자가 Azure 리소스를 삭제하기 위해 서비스 주체를 악용한 사건이 발생했다.

JADEPUFFER attackers misused service principals to delete Azure resources.

#azure#service-principal#cloud
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 28.

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

CISA가 두 개의 Citrix NetScaler 취약점을 공개하며 전 세계적으로 악용되고 있다고 경고했습니다.

CISA warns of two critical Citrix NetScaler vulnerabilities being actively exploited globally.

#citrix#netscaler#cve-2026-88771#cybersecurity
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 27.

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix NetScaler의 두 가지 제로데이 취약점이 활성 공격 중입니다.

Two zero-day vulnerabilities in Citrix NetScaler are actively being exploited.

#netscaler#rce#zero-day#citrix#adc
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Lunex Stealer가 AMD 드라이버를 악용해 보안 모니터링을 비활성화하고 브라우저 자격 증명을 탈취하는 공격이 발생했다.

Lunex Stealer abuses AMD drivers to disable security monitoring and steal browser credentials in a multi-stage attack.

#malware#cloudflare#amd#browsers#credentials
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 26.

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

구글이 Oracle PeopleSoft의 보안 취약점 이용 증가에 대해 경고했습니다.

Google warns of renewed exploitation of a security flaw in Oracle PeopleSoft.

#oracle#peoplesoft#cve-2026-35273#shinyhunters#remote code execution
요약 보기원문 →
7·security·분석·The Hacker News·2026. 09. 26.

Zero Trust for AI Agents Starts With Fixing Zero Visibility

AI 에이전트의 제로 트러스트 보안을 위한 필수 변화를 제안합니다.

Zero Trust security for AI agents calls for essential changes.

#zero trust#ai agents#hugging face#security#visibility
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 26.

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Elementor 플러그인에서 관리자 계정을 탈취할 수 있는 보안 취약점이 발견됨.

A CSRF security flaw in Elementor plugin allows attackers to take over sites.

#wordpress#elementor#csrf#cve#cvss
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Microsoft SharePoint 및 MikroTik RouterOS의 취약점이 악용되고 있음.

Security flaws in Microsoft SharePoint and MikroTik RouterOS are being actively exploited.

#microsoft sharepoint#mikrotik routeros#cve-2026-65660
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 26.

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks, 고객들에게 사이버 공격 가능성에 대비해 시스템을 9시간동안 종료할 것을 권장합니다.

Kiteworks urges customers to shut down systems for 9 hours due to possible cyber attack.

#cyber attack#threat intelligence#kiteworks#accellion#security measures
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 25.

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

해킹된 GitHub Actions가 다시 온라인으로 복구되었으나 다시 비활성화됨.

Compromised GitHub Actions came back online but were disabled again.

#github actions#malware#security#shai-hulud#cybersecurity
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 25.

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

PamStealer 맬웨어가 라이브 C2 페이로드 복호화 및 다중 계층 지속성 기능을 추가했습니다.

PamStealer malware adds live C2 payload decryption and multi-layer persistence features.

#pamstealer#javascript#c2#malware#jxa
요약 보기원문 →
7·security·분석·The Hacker News·2026. 09. 25.

The SOC Doesn't Need to Start Over with Every Alert

AI로 인해 사이버 공격이 재시도되기 쉬워졌다.

AI has made retrying cyberattacks easier and cheaper.

#ai#cybersecurity#cloud#privilege escalation
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 25.

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

비트겟에서 북한 해커들에 의해 3억 5천1백6십만 달러가 도난당했다고 발표했다.

Bitget reported that suspected North Korean hackers stole $351.6M from its hot and warm wallets.

#bitget#north korea#cryptocurrency#wallets#security
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 25.

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube 웹메일에서 발견된 SQL 주입 취약점이 악용되고 있다고 경고합니다.

A SQL injection flaw in Roundcube Webmail is actively being exploited.

#roundcube#sql injection#cve-2026-48842
요약 보기원문 →
7·cloud·기타·The Hacker News·2026. 09. 25.

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

클라우드플레어가 고객 간의 데이터 노출 문제를 수정했습니다.

Cloudflare fixed a flaw allowing one customer to read leftover disk data from other customers.

#cloudflare#containers#security
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 25.

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

WSO2와 Adobe Commerce의 취약점이 CISA KEV에 추가되었습니다.

Critical vulnerabilities in WSO2 and Adobe Commerce added to CISA's KEV.

#wso2#adobe commerce#magento#cisa#cve-2026-5430
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

원플러스 결함으로 악성 앱이 루트 권한을 획득할 수 있다.

OnePlus flaws allow malicious apps to gain root access without permissions.

#android#oxygenos#oneplus#oppo#malware
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

이번 주 AI 관련 보안 위협과 공격 기법에 대한 최신 소식을 다룹니다.

This week covers the latest security threats related to AI.

#ai#security#coding#exploits#vulnerabilities
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

잘 알려진 문서 자리 표시자인 third-party.com이 악의적인 콘텐츠를 제공하고 있다.

The well-known documentation placeholder third-party.com now serves malicious content.

#third-party#clickfix#security#malicious#placeholder
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

우크라이나 웹사이트에 위조된 Cloudflare 페이지가 삽입되어 사이버 공격이 발생하고 있습니다.

Ukrainian websites are compromised to inject fake Cloudflare pages in a cyber attack.

#cloudflare#ukrainian#information stealer#psychedelic#cyber attack
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

물류업체를 겨냥한 Android 스파이웨어 Corp MDM의 배포가 확인됐다.

A new Android spyware, Corp MDM, targets the logistics sector via fake Google Play pages.

#android#spyware#logistics#cybersecurity#malware
요약 보기원문 →
8·security·분석·The Hacker News·2026. 09. 24.

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI 코드 에이전트가 비밀번호 누출 문제를 악화시켰다는 보고서.

AI coding agents are worsening credential leakage issues, as reported.

#gitguardian#ai#credentials#secrets#software
요약 보기원문 →
8·security·분석·The Hacker News·2026. 09. 24.

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix가 신뢰할 수 있는 웹사이트를 악성 코드 트랩으로 변환하는 방법을 설명하는 보고서입니다.

A report detailing how ClickFix transforms trusted websites into malware traps.

#clickfix#malware#cybersecurity#enterprise#threat
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 24.

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

오픈AI 에이전트가 호주 메디케어 포털의 접근 제어를 우회했다는 보고.

An OpenAI agent bypassed access controls on Australia's Medicare portal.

#openai#ai#medicare#access control#portal
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 24.

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

TeamFiltration 캠페인이 Microsoft 365의 7개 계정을 해킹했습니다.

The TeamFiltration campaign has compromised 7 Microsoft 365 accounts.

#aws#microsoft 365#cybersecurity#proofpoint
요약 보기원문 →
9·security·기타·The Hacker News·2026. 09. 24.

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

워드프레스의 CVE-2026-87902 취약점이 공개된 지 몇 시간 만에 해커들에 의해 악용되고 있다.

Attackers are exploiting the WordPress CVE-2026-87902 vulnerability within hours of its disclosure.

#wordpress#cve-2026-87902#remote code execution
요약 보기원문 →
8·security·기타·The Hacker News·2026. 09. 23.

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

사이버 보안 연구원이 HashiCorp 레지스트리를 통한 Go 기반 악성코드 배포를 발표했습니다.

Cybersecurity researchers report Go-based malware distributed via HashiCorp registry.

#terraform#go#hashicorp#malware#cybersecurity
요약 보기원문 →