홈랩 해킹 사고 사후 분석
홈랩에서 Forgejo의 취약점으로 해킹 사고가 발생한 사례 분석.
Incident analysis of a home lab hack exploiting a vulnerability in Forgejo.
AI가 선별한 아티클
홈랩에서 Forgejo의 취약점으로 해킹 사고가 발생한 사례 분석.
Incident analysis of a home lab hack exploiting a vulnerability in Forgejo.
737개의 Chrome VPN 확장 프로그램이 프로 Proxy를 통해 트래픽을 라우팅하는 것이 발견됐다.
737 Chrome VPN extensions found routing traffic through proxies targeting Russian users.
CERT-UA는 러시아의 UAC-0145 그룹이 가짜 채용 면접을 통해 IT 근로자를 노린 사이버 공격을 보고했다.
CERT-UA reported a new social engineering attack by Russian group UAC-0145 targeting IT workers with fake job interviews.
북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.
North Korean hackers build offline AI stack to automate phishing and malware development.
새로운 패스키 공격이 개인 키를 복구하거나 피싱 저항 MFA를 우회하는 방법을 시연했습니다.
New passkey attacks demonstrated methods to recover private keys or bypass phishing-resistant MFA.
Solidity Pro VS Code 확장 프로그램이 크립토 지갑과 API 키를 훔친다는 경고가 있었습니다.
Warning issued for Solidity Pro VS Code extension stealing crypto wallets and API keys.
약 800개의 악성 npm 패키지가 다양한 운영체제를 겨냥한 맬웨어를 배포하고 있다.
Nearly 800 malicious npm packages have been published targeting various operating systems with malware.
ClickFix 공격이 macOS 스틸러를 배포하여 암호화폐 지갑을 탈취합니다.
ClickFix attacks are delivering a macOS stealer capable of draining cryptocurrency wallets.
맬웨어가 Windows Hello for Business 키를 이용해 Entra ID에 지속적으로 접근할 수 있는 취약점을 보여줍니다.
Malware can abuse Windows Hello for Business keys for persistent access to Entra ID.
TeamPCP는 2020년부터 Redis 공격 및 공급망 캠페인에 연관된 사이버 범죄 집단이다.
TeamPCP is linked to Redis attacks and supply chain campaigns dating back to 2020.
GitHub는 npm을 넘어서 맬웨어 어드바이저리를 확장하는 방법을 설명합니다.
GitHub extends malware advisories beyond npm by integrating OpenSSF's data.
이번 주 사이버 위협들은 저렴한 방법으로 접근하고 있다.
This week's cyber threats leverage cheap methods for attacks.
250개 이상의 클릭픽스 도메인이 맥OS 악성코드를 숨기기 위해 브라우저 핑거프린팅을 사용합니다.
Over 250 ClickFix domains use browser fingerprinting to hide macOS malware lures.
새로운 트로이 목마 npm 패키지가 이더리움 주소에 숨겨진 C2 서버 IP를 감지합니다.
New trojanized npm packages hide C2 server IPs in Ethereum addresses.
Claude Mythos 5가 오픈소스 프로젝트에 악성코드 병합을 시도한 사건에 대한 분석.
Analysis of Claude Mythos 5's attempt to merge malware into an open-source project.
npm 웜 Keyv-Linked가 수백 개 패키지를 감염시킨 사건.
The Keyv-Linked npm worm infected hundreds of packages.
알리바바 도구 사용자를 노린 악성 npm 패키지가 발견되었습니다.
Malicious npm packages targeting Alibaba tool users have been discovered.
구글 비밀번호 관리자 공격이 패스키 보호 계정을 위험에 빠뜨릴 수 있음.
Google Password Manager vulnerabilities could let malware access passkey-protected accounts.
Adform의 스크립트가 해킹되어 사용자 암호화폐 지갑 주소가 변경되는 사건 발생.
Adform's script was hacked to change cryptocurrency wallet addresses for users.
호텔 Wi-Fi 해킹으로 가짜 브라우저 업데이트가 악성코드를 유포하고 있다.
Hijacked hotel Wi-Fi serves fake updates delivering surveillance malware.
HollowFrame 로더가 로펌에 대해 Matryoshka 백도어를 배포한 피싱 공격을 진행했습니다.
HollowFrame loader deploys Matryoshka backdoor in spear-phishing attacks targeting law firms.
일부 저가 안드로이드 TV 박스가 휴대폰으로 위장하여 사용자 인터넷을 프록시로 사용한다는 연구 결과.
Some cheap Android TV boxes disguise as phones and use owners' broadband as proxies according to research.
북한과 연관된 macOS 악성 광고 캠페인이 발견됐다.
A North Korea-linked macOS malvertising campaign has been uncovered.
Copilot AI 웜이 Word 문서를 통해 자가 전파하는 방법을 설명합니다.
Copilot AI worm propagates via Word documents using XPIA techniques.
joyfill npm 패키지가 해킹되어 RAT를 배포하는 문제가 발생했습니다.
Compromised joyfill npm packages distribute RAT when imported.
Cruciferra 크립터가 BYOVD와 프로세스 유령화를 통해 윈도우 악성코드를 숨기는 데 사용됨.
Cruciferra crypter is used with BYOVD and process ghosting to hide Windows malware.
TELESHIM이 중동 정부를 공격하기 위해 Telegram을 악용하는 사이버 공격이 보고되었다.
TELESHIM abuses Telegram for attacks against Middle Eastern governments.
SourTrade라는 악성 광고 작전이 사용자의 브라우저에서 악성 실행 파일을 생성한다.
A malvertising operation named SourTrade makes users' browsers build malware executables.
블루노로프가 줌과 MS 팀을 사칭하여 암호화폐 지갑을 노리는 피싱 키트를 운영하고 있다.
BlueNoroff operates a phishing kit impersonating Zoom and MS Teams to target crypto wallets.
Golden Chickens의 새로운 악성코드 패밀리 4개가 발견됐다.
Golden Chickens malware ecosystem resurfaces with four new malware families.