Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client
메타의 Muse 클라이언트에서 보안 취약점이 발견되었습니다.
A zero-day vulnerability was discovered in Meta's Muse desktop client for macOS.
AI가 선별한 아티클
메타의 Muse 클라이언트에서 보안 취약점이 발견되었습니다.
A zero-day vulnerability was discovered in Meta's Muse desktop client for macOS.
WHOOP은 취약점 경고의 피로감에 직면했지만, 해결책으로 인간의 개입을 유지합니다.
WHOOP faced alert fatigue but maintains human oversight in its solution.
WordPress가 사이트 공격에 대한 취약점을 수정했습니다.
WordPress has patched a critical vulnerability that allows code execution by attackers.
Microsoft의 SharePoint 결함이 인증된 원격 코드 실행을 가능하게 하였습니다.
A SharePoint flaw initially classified by Microsoft as spoofing enables authenticated remote code execution.
WordPress에서 새로운 Click2Shell flaw를 패치하여 코드 실행 가능성을 차단했습니다.
WordPress patches a Click2Shell flaw that allows theme installs without clicks, preventing potential code execution.
연구자들이 Anthropic의 Claude를 사용해 OpenAI의 보안 취약점을 악용했다.
Researchers exploited OpenAI's vulnerabilities using Anthropic's Claude.
AI의 남용과 보안 패치의 중요성을 강조한 기사.
Highlights the abuse of AI and the importance of applying security patches.
GPT-5.6-Cyber 테스트로 가상 머신의 보안 취약점이 드러났다.
Testing with GPT-5.6-Cyber revealed security vulnerabilities in virtual machines.
OpenAI는 GPT-6 Astra를 사이버 보안에 대해 '치명적'로 분류했다.
OpenAI classified GPT-6 Astra as 'Critical' for cybersecurity.
DeepSeek V4.1 Flash가 Enclave 해킹 모델에서 모든 타깃에 성공적으로 코드 실행.
DeepSeek V4.1 Flash successfully executed code on all targets in the Enclave hacking model.
PS2의 보안 칩이 역공학을 통해 완전히 뚫렸다.
The PS2 security chip has been fully breached through reverse engineering.
Parallels Desktop의 취약점이 비관리자 Mac 사용자에게 루트 권한 부여.
A flaw in Parallels Desktop allows non-admin Mac users to gain root access.
위협 정보만으로는 공격 비율 격차를 해소할 수 없다.
Threat intelligence alone cannot close the exploitation gap.
WSO2 API Manager의 JWT 우회 취약점이 적극적으로 악용되고 있다는 보고.
A critical JWT bypass vulnerability in WSO2 API Manager is under active exploitation in the wild.
Baseten의 프로덕션 GitHub에 25분 만에 관리자 접근을 얻었다는 글입니다.
The article details gaining admin access to Baseten's production GitHub in just 25 minutes.
AI가 취약점을 이용하는 시간을 단축시키며, 해커가 신속하게 SSH에 접근하는 사례를 소개합니다.
AI is reducing the time to exploit vulnerabilities, enabling hackers to quickly access SSH as shown in a recent case.
LiteSpeed 웹 서버의 취약점으로 한 사용자가 루트 권한을 얻을 수 있다.
A vulnerability in LiteSpeed Web Server allows one user to gain root access on a shared server.
중국의 위협 행위자가 Gitea 취약점을 악용하여 13개 조직을 공격했습니다.
Chinese threat actor Red Heron exploited Gitea vulnerability to compromise 13 organizations.
Tesla가 사이버 공격의 주요 대상이 되고 있다는 보도.
Reports indicate Tesla is becoming a major target of cyber attacks.
macOS 패키지 관리자 Homebrew의 새로운 버전 7 소식과 기능.
News about the new version 7 of the macOS package manager Homebrew.
보안 취약점에 대한 새로운 접근법을 제시합니다.
Introduces a new approach to evaluating security vulnerabilities.
공격자들이 JFrog Artifactory의 취약점을 이용해 관리 권한을 탈취하고 백도어를 심었다.
Attackers exploited vulnerabilities in JFrog Artifactory to gain admin access and plant backdoors.
중국 해킹 그룹이 Sogou 입력기 결함을 이용해 GRAYRABBIT 백도어를 설치했다.
A Chinese hacking group exploited a flaw in Sogou Input Method to install the GRAYRABBIT backdoor.
CVE 공개 후 신속하게 노출 여부를 확인하는 방법을 배울 수 있는 웨비나 소개.
Introduction to a webinar on how to quickly determine exposure after a CVE disclosure.
보안 취약점을 조기에 발견할 시간이 1년으로 단축되고 있다는 경고.
A warning that the time to fix security vulnerabilities is rapidly shrinking to just one year.
GitLab은 AI 에이전트 샌드박스의 안전성이 네트워크 접근에 따라 다르다는 경고를 전했습니다.
GitLab warns that sandboxes for AI agents are only as secure as their network access.
위챗 제로 클릭 웜이 아이폰과 안드로이드 계정을 장악했다.
WeChat zero-click worm compromised accounts on iPhone and Android via incoming calls.
취약점 보고서 처리 방법에 대한 가이드를 제시합니다.
Provides a guide on handling vulnerability reports.
Google이 Mantis를 오픈소스하여 소프트웨어 취약점 생애 주기를 자동화합니다.
Google open-sources Mantis, an AI-agent framework to automate the software vulnerability lifecycle.
CISA가 공격에 악용된 7가지 취약점을 KEV 목록에 추가했습니다.
CISA adds seven exploited vulnerabilities to KEV catalog amid attacks.