⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.
This week saw numerous security vulnerabilities and cyber attack incidents.
AI가 선별한 아티클
이번 주, 여러 보안 취약점과 사이버 공격 사건이 발생했다.
This week saw numerous security vulnerabilities and cyber attack incidents.
마이크로소프트가 12,000개의 이메일 침해와 관련된 EvilTokens 피싱 서비스를 차단했다.
Microsoft has taken down the EvilTokens phishing service linked to 12,000 email compromises.
패스키의 장점과 단점에 대해 논의합니다.
Discusses the advantages and disadvantages of passkeys.
RatHat 악성코드는 ADB를 이용해 삭제 후에도 지속적으로 접근을 유지합니다.
RatHat malware uses ADB to maintain access after uninstallation.
N0va가 미국과 유럽 기업을 대상으로 피싱 캠페인을 진행하고 있습니다.
N0va is targeting US and EU businesses with phishing campaigns.
공격 체인 분석의 중요성을 강조하며, 개별 기술 테스트의 한계를 지적합니다.
Emphasizes the importance of analyzing attack chains and critiques the limitations of testing individual techniques.
중국 해킹 팀이 Chrome와 Windows의 제로데이 취약점을 이용해 GRIMWEDGE를 배포했습니다.
Chinese hackers exploit Chrome and Windows zero-day flaws to deploy GRIMWEDGE.
악성 행위자들이 패스키를 이용한 피싱 공격으로 마이크로소프트 클라우드 계정을 탈취하고 있습니다.
Threat actors use passkey phishing to hijack Microsoft cloud accounts and exfiltrate data.
피싱 공격의 원인은 사용자나 DNS가 아니라 기업 로그인 방식에 있다.
Phishing attacks result from corporate login methods, not users or DNS.
슬랙, 한국과 일본에서 가짜 초대장 피싱 경고 발표.
Slack warns about phishing attempts targeting users in Korea and Japan.
이번 주 보안 뉴스는 다양한 위협 요인에 대해 다룬다.
This week's security news covers various threat factors.
악성 VBScript를 새로운 시스템에 배포하는 ScreenConnect 악성 활동에 대한 연구 결과.
Details on worm-like activity using ScreenConnect to spread malicious VBScript payload to new systems.
마이크로소프트의 프롬프트 주입 탐지기가 피싱 캠페인을 포착했다.
Microsoft's prompt injection detector caught a phishing campaign.
마이크로소프트가 필터를 우회하는 피싱 캠페인을 경고했습니다.
Microsoft warns of a phishing campaign using invisible Unicode to evade filters.
소셜 엔지니어링 공격과 피싱 관련 최신 동향을 다룬 기사.
The article discusses recent trends in social engineering attacks and phishing.
RMM 피싱 캠페인이 46개국으로 확장되어 미국이 주요 목표가 되었다.
RMM phishing campaign expands to 46 countries, making the US its primary target.
NovaCookies는 Microsoft 365 세션을 훔치기 위한 새로운 피싱 도구입니다.
NovaCookies is a new phishing tool aimed at stealing Microsoft 365 sessions.
가짜 애플 지원 AI 전화를 이용한 피싱 공격이 노출되었습니다.
Fake Apple Support AI calls targeting stolen-device owners have been disclosed.
Mirage2FA 캠페인이 4,500개 이상의 미국 및 EU 기업을 타겟으로 하여 2단계 인증을 우회하고 있습니다.
The Mirage2FA campaign targets 4,500+ US and EU companies by bypassing two-factor authentication on Microsoft 365.
24개의 npm 패키지가 가짜 CAPTCHA 페이지를 호스팅하기 위해 악용되고 있다.
24 npm packages are abused to host fake CAPTCHA pages for phishing.
WordlistLoader와 SynkLoader라는 두 종류의 새로운 맬웨어가 발견되었습니다.
Two new malware families, WordlistLoader and SynkLoader, have been discovered.
피싱 3.0에서 이메일 방어는 AI로 변화된 위협에 취약하다.
In Phishing 3.0, email defenses are vulnerable to threats evolving with AI.
Ransom Busters라는 랜섬웨어 제휴자가 피해자에게 데이터 복구를 돕겠다고 제안하고 있습니다.
A ransomware affiliate called Ransom Busters is offering to help victims recover data for a fee.
CTM360가 브라우저 내 브라우저 기법을 이용한 채용 피싱 캠페인을 밝혀냈습니다.
CTM360 uncovers a large-scale recruitment phishing campaign using Browser-in-the-Browser techniques.
북한 해커 그룹이 오프라인 AI 스택을 구축하여 피싱 및 악성코드 개발을 자동화하고 있다.
North Korean hackers build offline AI stack to automate phishing and malware development.
Microsoft 365를 겨냥한 AitM 피싱 공격에 대한 경고.
Warning about AitM phishing attacks targeting Microsoft 365.
FedEx의 결제 문자, 피싱으로 오인된 이유 분석.
Analysis of why FedEx's payment SMS was mistaken for phishing.
Kali365가 마이크로소프트 인증을 악용하여 기업 데이터를 위협하고 있다.
Kali365 weaponizes Microsoft authentication to threaten corporate data access.
Cloudflare의 Wallet 서비스는 피싱 공격과 유사한 보안 이슈를 드러냄.
Cloudflare's Wallet service reveals security issues resembling phishing attacks.
PhaaS 툴킷 Greatness가 MFA를 우회하는 장치 코드 피싱을 추가했습니다.
The PhaaS toolkit Greatness adds device code phishing to bypass MFA.