⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.
This week saw numerous security vulnerabilities and cyber attack incidents.
AI가 선별한 아티클
이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.
This week saw numerous security vulnerabilities and cyber attack incidents.
Carbonato 봇넷이 Docker 호스트를 타겟으로 AI 에이전트를 배포한다.
Carbonato botnet targets Docker hosts to deploy the Hermes AI agent.
Lunex Stealer가 AMD 드라이버를 악용해 보안 모니터링을 비활성화하고 브라우저 자격 증명을 탈취하는 공격이 발생했다.
Lunex Stealer abuses AMD drivers to disable security monitoring and steal browser credentials in a multi-stage attack.
해킹된 GitHub Actions가 다시 온라인으로 복구되었으나 다시 비활성화됨.
Compromised GitHub Actions came back online but were disabled again.
PamStealer 맬웨어가 라이브 C2 페이로드 복호화 및 다중 계층 지속성 기능을 추가했습니다.
PamStealer malware adds live C2 payload decryption and multi-layer persistence features.
GitHub이 악성 모방 소프트웨어를 3주 동안 삭제하지 않은 사건 보도.
GitHub failed to remove malicious imitation software for 3 weeks.
원플러스 결함으로 악성 앱이 루트 권한을 획득할 수 있다.
OnePlus flaws allow malicious apps to gain root access without permissions.
물류업체를 겨냥한 Android 스파이웨어 Corp MDM의 배포가 확인됐다.
A new Android spyware, Corp MDM, targets the logistics sector via fake Google Play pages.
ClickFix가 신뢰할 수 있는 웹사이트를 악성 코드 트랩으로 변환하는 방법을 설명하는 보고서입니다.
A report detailing how ClickFix transforms trusted websites into malware traps.
사이버 보안 연구원이 HashiCorp 레지스트리를 통한 Go 기반 악성코드 배포를 발표했습니다.
Cybersecurity researchers report Go-based malware distributed via HashiCorp registry.
Windows 악성코드가 AI 모델에 의해 결정되는 방식으로 작동한다는 보고서.
A Windows malware operates by letting up to four AI models vote on its next move.
중국 해커가 크롬-윈도우 제로데이 취약점을 악용하여 CLEANGULP 악성코드를 배포하고 있다.
Chinese hackers exploit Chrome-Windows zero-day bugs to deploy CLEANGULP malware.
BigDiskBuster라는 제로데이 툴이 Microsoft Defender 업데이트를 차단함.
BigDiskBuster, a zero-day tool, blocks Microsoft Defender updates.
메타 뮤즈 비밀 설정으로 공격자가 AI 어시스턴트를 백도어로 전환할 수 있다.
A hidden Meta Muse setting could let attackers turn the AI assistant into a backdoor.
북한 해커의 캠페인이 3만 대의 기기를 공격해 1,071만 달러의 암호화폐를 훔쳤습니다.
North Korean hackers compromised 30,000 devices and stole $10.71M in cryptocurrency.
저명한 Rust 개발자를 겨냥한 표적 공격이 발생하고 있다.
Targeted attacks against prominent Rust developers are underway.
WeaselBiscuit라는 악성이 13개의 npm 패키지를 통해 확산되고 있습니다.
WeaselBiscuit malware spreads through 13 npm packages to steal Chrome extension data.
LLM을 사용해 PhantomRaven 멀웨어 개발한 버그 바운티 헌터가 발견됐다.
A bug bounty hunter likely used an LLM to develop the PhantomRaven malware.
RatHat 악성코드는 ADB를 이용해 삭제 후에도 지속적으로 접근을 유지합니다.
RatHat malware uses ADB to maintain access after uninstallation.
이란 해커 그룹 Handala가 HEAVYGRAM 맬웨어를 사용해 텔레그램을 통해 패스워드를 훔쳐냅니다.
Iran-linked Handala hackers use HEAVYGRAM malware to steal passwords via Telegram.
KREMLIN 은행 악성코드가 크롬과 엣지를 통해 자격 증명을 탈취합니다.
KREMLIN banking malware hijacks Chrome and Edge to steal credentials.
이란 해커들이 텔레그램으로 제어되는 악성코드를 사용하여 반체제 인사들을 감시하고 있다.
Iranian hackers use Telegram-controlled malware to spy on dissidents and journalists.
BambooToken 멀웨어가 MQTT를 이용해 윈도우와 리눅스 시스템을 제어하는 공격에 대한 보고서.
BambooToken malware uses MQTT to control Windows and Linux systems in targeted attacks.
AI가 사이버 공격에 악용되고 있으며, 여러 보안 취약점이 여전히 존재한다.
AI is being misused in cyberattacks, with many security vulnerabilities still present.
악성 Twitch 브라우저 확장 프로그램이 3만 1천명의 OAuth 토큰을 유출했습니다.
A malicious Twitch browser extension leaked OAuth tokens from nearly 31,000 users.
Gigabud 뱅킹 트로이목마가 안드로이드 작업 프로file을 생성하여 은행 앱 악성코드 검사를 우회합니다.
Gigabud banking trojan creates an Android work profile to bypass banking app malware checks.
Google Ads에 광고를 게재한 개발자가 계정 정지에 처했다.
A developer faced account suspension on Google Ads for promoting software.
구글 광고를 통해 악성 소프트웨어를 광고하는 방법에 대한 기사
An article about advertising malicious software on Google Ads.
F5 BIG-IP APM 기기에서 PHP 웹 셸이 메모리에 주입되어 디스크 스캔을 회피하는 악성 코드가 발견됨.
Malware on F5 BIG-IP APM injects a PHP web shell into memory, evading disk scans.
BengalSEO 캠페인이 Bing 검색 결과를 오염시켜 악성코드와 기술 지원 사기를 유도하고 있다.
BengalSEO campaign poisons Bing search results leading to malware and tech support scams.