728x90
반응형

보안위협 (악성코드, 취약점) 409

특정 TV박스, 스마트폰으로 위장해 광고 클릭

TV박스가 안드로이드폰으로 가장해 광고 클릭이 발견되었습니다. The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids’ Coding Blockshttps://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks Uncovering the Fuyao Enterprise: A Shift in Modern Ad-FraudCut through the noise—get monthly actionable cyber threat research and industry insights from Bitsight's blog.www.bitsight...

Google (Mandiant) 새로운 위협행위자 (Threat Actor ) 이름 체계 계획 - APTxx의 종료

Mandiant는 전통적으로(?) APTxx 으로 위협행위자 (Threat Actor) 이름을 부여했습니다. 2026년 7월 25일 맨디언트를 인수한 구글은 새로운 위협그룹 이름 체계를 공개했습니다. Updated Cyber Threat Actor Naming Systemhttps://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/?hl=en Updated Cyber Threat Actor Naming System | Google Cloud BlogIntroduction Today, Google Threat Intelligence Group (GTIG) will begin rolling ..

오퍼레이션 더블 배럴 (Operation Double Barrel) - 국가배후 해킹조직의 한국 공격 주의 권고

2026년 7월 30일 합동사이버 보안 권고문을 공개했습니다. (합동사이버보안권고문) 국가배후 해킹조직의 우리 국민·기업 해킹 공격 주의 권고https://www.boho.or.kr/kr/bbs/view.do?searchCnd=&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=72144 KISA 보호나라&KrCERT/CCKISA 보호나라&KrCERT/CCwww.boho.or.kr:443 보고서 안랩, 엔키, S2W, 플레인비트에서 보고서를 공개했습니다. GROK으로 이미지 만들었는데, 마음에 안드네요 ㅋ AI를 통해 각 회사 보고서를 비교했습니다. 💡 4개 보고서 종합 보고서핵심 고유 기여AhnLab ASEC..

2026년 3월 말 액시오스 (Axios) 공급망 공격

2026년 3월 말 액시오스 (Axios) 공급망 공격이 발생했습니다. Axios npm Supply Chain Compromise — Full Analysis Package (2026.03.31)https://gist.github.com/N3mes1s/0c0fc7a0c23cdb5e1c8f66b208053ed6 북한발 공급망 공격: 널리 사용되는 Axios NPM 패키지 침해 사태 분석 (2026.04.01)https://cloud.google.com/blog/ko/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package Axios npm Supply Chain Compromise (2026-03-31) — ..

일부 LG 모니터, 동의 없이 McAfee 구독 홍보 소프트웨어 설치

특정 LG 모니터를 Windows PC에 연결하면, 동의 화면 없이 Windows Update를 통해 "LG Monitor App Installer"가 자동 설치되고, 이 앱이 McAfee 유료 구독을 홍보하는 광고를 표시하는 현상이 확인됐습니다. LG monitors silently install software through Windows Update without user consent (2026.07.17)https://videocardz.com/newz/lg-monitors-silently-install-software-through-windows-update-without-user-consent LG monitors silently install software through Windows ..

허깅 페이스 (Hugging Face) 침해 사건 - 공격자는 OpenAI 테스트 AI 그리고 파장

2026년 7월 Hugging Face가 사이버 공격 당했습니다. Hugging Face 침해사고 Security incident disclosure — July 2026 https://huggingface.co/blog/security-incident-july-2026 Security incident disclosure — July 2026We’re on a journey to advance and democratize artificial intelligence through open source and open science.huggingface.co 1️⃣ Hugging Face의 최초 발표 (7/16) — "미지의 자율 AI 침입자"이번 주 초, Hugging Face는 프로덕션 인프라 일부에 ..

Jadepuffer - AI Agent를 이용한 랜섬웨어 공격 ?!

(AI로 작성한 내용을 수정했습니다.) 2026년 7월 1일 Sysdig가 "최초의 완전 자율형(agentic) 랜섬웨어 작전"을 발견했다고 발표했습니다. 며칠 뒤, Truesec이 같은 사건을 다시 들여다보며 "글쎄, 그렇게 단정할 수 있을까?"라는 반박에 가까운 평가를 내놨습니다. 두 보고서를 나란히 놓고, 무엇이 주장이고 무엇이 반박인지 정리해봤습니다. Jadepuffer JADEPUFFER: Agentic ransomware for automated database extortionhttps://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion JADEPUFFER: Agentic ransomwar..

개발자 노린 악성코드 - 바이러스 같은 전염성과 정보유출 기능까지

러시아 Dr. Web은 소프트웨어 개발자를 노린 새로운 악성코드 정보를 공개했습니다. Software developers are the target. New trojan attacks supply chains and inflicts multifaceted damage on infected PCs https://news.drweb.com/show/?i=15276&lng=en&c=5 Software developers are the target. New trojan attacks supply chains and inflicts multifaceted damage on infected PCsA new trojan engaging in supply chain attacks has recently come und..

Operation Endgame - 인포스틸러 차단 작전

Operation Endgame CRITICAL: StealC Historical Bot Infections Special Reporthttps://www.shadowserver.org/what-we-do/network-reporting/critical-stealc-historical-bot-infections-special-report/ CRITICAL: StealC Historical Bot Infections Special Report | The Shadowserver FoundationLAST UPDATED: 2026-06-24 DEFAULT SEVERITY LEVEL: CRITICAL The data in this Special Report is being shared as an output ..

유럽 의회 페가수스 (Pegasus) 공격 받아 - 조사자를 감시

전 유럽의회 의원 Stelios Kouloglou가 Pegasus 및 유사 스파이웨어 남용을 조사하던 바로 그 PEGA 위원회 활동 중 NSO Group의 Pegasus 스파이웨어에 반복 감염됐습니다. 감염 시점이 위원회의 핵심 심의 기간과 정확히 겹쳐, 공격자가 비공개 문서와 위원회 심의 내용에 접근했을 가능성이 있습니다. Espionage Against the European Parliament Member of Committee Investigating Spyware Hacked with Pegasus (2026.07.03)https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/ Espi..

클로드 (Claude) 중국 감시 ? - 백도어 소동

클로드가 중국 사용자에 대한 백도어(?) 소동이 있었습니다. Claude Code accused of hiding China proxy fingerprints inside system prompts https://www.internationalcyberdigest.com/claude-code-accused-of-hiding-china-proxy-fingerprints-inside-system-prompts/ Claude Code accused of hiding China proxy fingerprints inside system promptsA Reddit leak and GitHub-hosted verification report allege that recent Claude Code builds ..

일본 자위대, 기밀 시스템에 악성코드 감염 USB 드라이브 1년 간 사용

일본 자위대에서 기밀 시스템에 악성코드 감염 USB 드라이브를 사용했습니다. 악성코드 감염 USB 드라이브 2026년 6월 25일 일본 닛케이신문은 일본 자위대가 기밀 시스템에 악성코드 감염 USB를 사용했다고 보도했습니다. 自衛隊、機密システムに感染USB接続 中国系ウイルス1年気づかずhttps://www.nikkei.com/article/DGXZQOCD075JJ0X00C26A5000000/ 自衛隊、機密システムに感染USB接続 中国系ウイルス1年気づかず - 日本経済新聞誰もがスマートフォンや人工知能(AI)などデジタル技術の恩恵を受ける時代では、安価で手軽な製品に国の安全や個人の安心を揺るがしかねないリスクが潜む。テック社会の「罠(わな)www.nikkei.com닛케이가 단독 입수한 자위대 내부 문서에 따르면, 육상자위대가 20..

중국 슈퍼컴퓨터 해킹 의혹 - 관리 업체 해킹 ?

2026년 4월 중국 슈퍼컴퓨터 해킹 의혹이 알려졌습니다. https://edition.cnn.com/2026/04/08/china/china-supercomputer-hackers-hnk-intl AI로 요약한 내용입니다. ------------- FlamingChina / NSCC 티엔진 슈퍼컴퓨터 침해 사건 요약 기본 개요FlamingChina라는 계정이 2026년 2월 6일 익명 텔레그램 채널에 샘플 데이터를 올리며 국가슈퍼컴퓨팅센터(NSCC) 티엔진에서 10 페타바이트(PB) 규모의 민감 데이터를 탈취했다고 주장했습니다. 항공우주공학, 군사 연구, 바이오인포매틱스, 핵융합 시뮬레이션 등의 연구 자료가 포함되어 있다고 밝혔습니다. CNN 이후 추가로 확인된 내용들판매 채널 확인 (Breac..

브라질 재난 경보 시스템 침해 의혹 - 현재 조사 중

6월 19일 브라질 여러 주에서 외계인 침공, 인간 혐오 등의 메시지를 담은 재난 경보가 발송되었습니다. The "Misantropia" Alert: Was It Really the Civil Defence?https://meuuniversonerd.com.br/en/?view=article&id=490:fake-defesa-civil-misantropia-alert-cell-broadcast-curitiba&catid=11 🚨 The "Misantropia" Alert: Was It Really the Civil Defence?It was nearly midnight on Friday, 19 June 2026, when several phones across Curitiba started goin..

앤트로픽 클로드 페이블(Fable) 5 외국 사용 중단과 한국 통신사 연계 소식 ?

Anthropic에서 새로운 AI 모델을 공개했습니다.하지만, 미국 정부의 지시로 곧 페이블 5 사용이 중단되었습니다. Statement on the US government directive to suspend access to Fable 5 and Mythos 5https://www.anthropic.com/news/fable-mythos-access Statement on the US government directive to suspend access to Fable 5 and Mythos 5The US government has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any forei..

Atomic Arch - 아치 리눅스 AUR 패키지 내 악성코드 감염

AUR(Arch User Repository)에서 관리자가 버려진 패키지를 통해 악성코드가 유포되었습니다. 2025년에도 아치 피눅스 저장소를 통해 악성코드가 배포된 적이 있습니다.이때는 신규 패키지에 악성코드가 포함된 경우로 차이가 있습니다. https://xcoolcat7.tistory.com/91762 아치 (Arch) 리눅스 저장소에서 악성코드 포함된 패키지 발견Arch 리눅스는 스팀OS 3에서 사용되어 게이머들이 많이 사용하고 있습니다.https://namu.wiki/w/SteamOS SteamOS밸브 코퍼레이션 이 개발한 게임에 특화된 컴퓨터 운영체제 이다. 상세 Arch Linux + KDE Plasnamu.wikxcoolcat7.tistory.com Atomic Arch Atomic ..

오퍼레이션 사프론 (Operation Saffron) - First VPN 서비스 중단

2026년 5월 Operation Saffron이 공개됩니다. 법집행 기관은 사이버범죄 전용 first VPN 서비스를 폐쇄했습니다. https://operation-saffron.eu/ First VPN Service — Website Seized by Law EnforcementOPERATION SAFFRONoperation-saffron.eu 다음은 AI로 요약한 내용입니다. Operation Saffron: First VPN 서비스 테이크다운공격 대상 (피해 조직)First VPN (도메인: 1vpns.com, 1vpns.net, 1vpns.org 및 관련 .onion 도메인)2014년부터 운영된 사이버범죄 전용 VPN 서비스, 5,000개 이상 계정 보유러시아어권 사이버범죄 포럼에서 독점 광..

728x90
반응형