Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.
Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.
AI가 선별한 아티클
새롭게 공개된 SharePoint 취약점을 공격자들이 이용하고 있다는 보고서입니다.
Attackers are exploiting a newly disclosed SharePoint vulnerability after the PoC release.
라자루스 그룹이 윈도우 취약점을 악용하여 백도어를 배포했다.
Lazarus Group exploits Windows zero-day to deploy a backdoor.
737개의 Chrome VPN 확장 프로그램이 프로 Proxy를 통해 트래픽을 라우팅하는 것이 발견됐다.
737 Chrome VPN extensions found routing traffic through proxies targeting Russian users.
OpenAI와 다른 기업의 API flaw로 AI 모델 간의 비밀이 노출될 위험이 있다.
A flaw in APIs from OpenAI and others risks exposing secrets between AI models.
2026년 블루 리포트에 따르면, 기업 방어의 효과는 과거 최고 수준에 도달했다.
The Blue Report 2026 states enterprise defenses are at their strongest yet.
Adobe가 ColdFusion과 Campaign Classic의 주요 보안 취약점을 패치했습니다.
Adobe patches critical security vulnerabilities in ColdFusion and Campaign Classic.
VMware vCenter의 보안 취약점이 악용되어 원격 접근이 가능해졌다.
VMware vCenter's security flaw is being exploited for remote access.
PyPI에서 발견된 악성 LiteLLM 릴리스로 2100개 이상의 조직이 노출됐다는 보고.
Malicious LiteLLM releases on PyPI may have exposed over 2,100 organizations.
SAP Commerce Cloud의 심각한 보안 취약점으로 인해 공격자가 임의의 코드를 실행할 수 있습니다.
A critical vulnerability in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code.
Microsoft Defender의 패치 우회 취약점인 ShieldBreak PoC가 공개되었습니다.
A PoC for the ShieldBreak zero-day vulnerability in Microsoft Defender has been released.
Cisco ASA 및 FTD의 새로운 취약점이 악용된 사례가 발견되었다.
A new vulnerability in Cisco ASA and FTD has been exploited in the wild.
마이크로소프트가 398개의 취약점을 패치했습니다.
Microsoft patches 398 vulnerabilities, including an actively exploited Windows driver zero-day.
김울프 v7 안드로이드 봇넷이 DDoS 공격을 개선했습니다.
Kimwolf v7 Android botnet enhances DDoS attack capabilities.
줌의 주석 도구에 취약점이 발견되어 회의 참가자가 다른 사용자의 클라이언트를 탈취할 수 있음.
Zoom's annotation tool flaw could allow participants to hijack other attendees' clients.
CERT-UA는 러시아의 UAC-0145 그룹이 가짜 채용 면접을 통해 IT 근로자를 노린 사이버 공격을 보고했다.
CERT-UA reported a new social engineering attack by Russian group UAC-0145 targeting IT workers with fake job interviews.
AI를 활용한 SharePoint 취약점이 확인되었습니다.
An AI-assisted vulnerability in SharePoint allows unauthorized access.
DeadLock 랜섬웨어가 폴리곤 스마트 계약을 이용하여 extortion 인프라를 강화하고 있습니다.
DeadLock ransomware uses polygon smart contracts to enhance extortion infrastructure.
OpenAI가 사이버 보안에 초점을 맞춘 GPT-5.6-Cyber 모델을 출시했다.
OpenAI has launched a cybersecurity-focused model called GPT-5.6-Cyber.
악성 SIM 카드가 IoT 장치의 모뎀에서 공격자 코드를 실행할 수 있다.
A malicious SIM card can execute attacker code inside IoT device modems.
모질라, 파이어폭스와 썬더버드의 Linux 서명 키를 폐기함.
Mozilla revokes Linux signing key for Firefox and Thunderbird.
연구자들이 가짜 암호화폐 스타트업을 만들어 북한 IT 직원 3명을 고용했다.
Researchers created a fake crypto startup and hired three suspected North Korean operatives.
윈도우 11에서 USB 자동 설치 기능을 악용해 시스템 전체를 장악할 수 있는 방법이 발견됐다.
Researchers discovered a way to abuse USB auto-install on Windows 11 for full system takeover.
악성 MCP 서버가 AI 코딩 에이전트로부터 비밀번호와 데이터를 유출할 수 있는 방법을 설명합니다.
Malicious MCP servers can exfiltrate secrets from AI coding agents through fragmented requests.
Gunra 랜섬웨어가 Fortinet과 Schneider Electric의 취약점을 악용해 네트워크를 침해합니다.
Gunra ransomware exploits vulnerabilities in Fortinet and Schneider Electric to breach networks.
해커가 폴란드 발전소의 제어 시스템을 해킹하여 터빈을 정지시켰습니다.
Hackers breached Polish power plant controls and shut down a turbine.
BdThemes의 공급망 공격으로 WordPress 관리자 계정 생성이 악용됐다.
A supply chain attack on BdThemes creates rogue WordPress admin accounts.
중국 해커들이 StormEncryptor 랜섬웨어를 배포했다는 소식입니다.
China-linked hackers have deployed a new ransomware called StormEncryptor.
이번 주 보안 문제와 관련된 최신 소식과 경향을 다룹니다.
This week covers key topics related to security issues and trends.
북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.
North Korean hackers build offline AI stack to automate phishing and malware development.
새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.
New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.