커뮤니티
보안 솔루션에 대한 정보와 경험을 공유하세요
보안 전문가가 필요하신가요?
에이블 시큐리티에서 검증된 다양한 분야의 보안 전문가와 멘토들을 만나보세요.
업무 고민 상담부터 커리어 조언까지, 여러분에게 필요한 전문가가 기다리고 있습니다.
...
스크롤하여 더 보기
보안 솔루션에 대한 정보와 경험을 공유하세요
에이블 시큐리티에서 검증된 다양한 분야의 보안 전문가와 멘토들을 만나보세요.
업무 고민 상담부터 커리어 조언까지, 여러분에게 필요한 전문가가 기다리고 있습니다.
...
스크롤하여 더 보기
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208563)
Picus will show how teams can validate whether a CVE is exploitable in their environment without always running live exploit code. 출처: [The Hacker News](https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html)
In security research, Claude Opus 5 helped chain forum and login flaws to take over OpenAI staff accounts and reach an internal repository. 출처: [The Hacker News](https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html)
기업의 핵심 업무가 네트워크와 로컬 애플리케이션에서 웹·SaaS·생성형 AI를 사용하는 브라우저 중심으로 이동하면서 기존 EDR(Endpoint Detection 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208554)
Public exploits for four patched Linux kernel flaws let local users gain root; three require unprivileged user namespaces. 출처: [The Hacker News](https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html)
사이버보안 전문기업 엔피코어(대표 한승철)는 9월 15일부터 16일까지 인도네시아 자카르타에서 열린 ‘인도섹 2026(IndoSEC 2026)’에 참가해 주요 사 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208548)
Check Point patched CVE-2026-91843, a critical login stack overflow that can let unauthenticated attackers run code as root on management servers. 출처: [The Hacker News](https://thehackernews.com/2026/09/critical-check-point-management-server.html)
사이버보안 전문기업 지니언스(대표 이동범)가 18일 서울 여의도 한국거래소에서 열린 ‘2026 한국IR대상’에서 코스닥 시장 부문 IR우수기업으로 선정됐다고 밝혔 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208544)
국가정보원과 국가보안기술연구소가 공동 주최하는 글로벌 사이버안보 행사 ‘사이버 서밋 코리아(Cyber Summit Korea, CSK 2026)’가 17일 서울 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208523)
Issabel Framework flaw CVE-2026-89026 is under active exploitation and can enable unauthenticated OS command execution via a hard-coded JWT key. 출처: [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html)
KREMLIN targets Brazilian bank users with malicious Chrome and Edge extensions that steal credentials, session tokens, cookies, and browser data. 출처: [The Hacker News](https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208501)
AI 보안 전문기업 스틸리언(대표 박찬암)이 웹 보안 솔루션 ‘웹수트(WebSuit)’와 보안 키패드 솔루션 ‘앱수트 키패드(AppSuit Keypad)’에 양자 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208471)
DDRop uses server control and a DDR5 interposer to replay stale encrypted data in Intel TDX, Scalable SGX, and AMD SEV-SNP. 출처: [The Hacker News](https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html)
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled data exfiltration. 출처: [The Hacker News](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)
이 전까지 내용들은 거의 IT와 관련된 보안에 대해서 언급해 보았다. 일반 사용자 입장에서 많이 접하기도 하고 언론에 많이 나오는 것이 IT이기 때문이기도 한데 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208435)
CISA adds five exploited flaws in Artifactory, ScreenConnect, and RouterOS to KEV, with fixes due by September 25. 출처: [The Hacker News](https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html)
시선AI가 공군 국방망에 적용되는 AI 코딩 및 보안 자동화 플랫폼 구축에 나선다.시선AI는 과학기술정보통신부 산하 정보통신기획평가원(IITP)이 주관하는 국방 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208408)
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began. 출처: [The Hacker News](https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html)
This week’s cyber threats span phishing abuse, malicious extensions, exposed systems, old flaws, AI attacks, and supply-chain risk. 출처: [The Hacker News](https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html)
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208403)
U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant network. 출처: [The Hacker News](https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html)
구글위협인텔리전스그룹(GTIG)이 2026년 2분기 최신 AI 위협 동향을 분석한 'AI 위협 추적 보고서(AI Threat Tracker)'를 공개했다.이번 보 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208399)
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208373)
Slim Spider attacks Brazilian financial firms, stealing cloud credentials and crypto custody secrets while targeting Pix payment infrastructure. 출처: [The Hacker News](https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html)
PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution. 출처: [The Hacker News](https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html)
카스퍼스키가 분기별 익스플로잇 및 취약점 보고서를 통해 인공지능(AI) 서비스 도입 확대에 따른 보안 취약점 증가세를 경고했다. 산업 전반에서 AI와 대규모 언어 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208350)
Attackers gain full administrative control of MikroTik routers through internet-exposed SSH without authentication, CERT Polska says. 출처: [The Hacker News](https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html)
Sansec says attackers exploit an unpatched Magento and Adobe Commerce flaw to run server code without authentication and install persistent backdoors. 출처: [The Hacker News](https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html)
한국인공지능·소프트웨어산업협회(KOSA)가 사우디아라비아 리야드에서 열린 글로벌 빅테크 전시회 'LEAP 2026'에 참가해 '한국 풀스택 AI 공동관'을 운영했 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208343)
글로벌파운드리의 자회사인 프로세서 IP 및 피지컬 AI 컴퓨팅 플랫폼 기업 MIPS가 산업용 기계와 자동차, 임베디드 기기에서 피지컬 AI를 구현하기 위한 개발 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208344)
A phishing campaign sent up to 2.37 million weekday emails using invisible Unicode tags to split financial lure words and bypass filters. 출처: [The Hacker News](https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html)
This week’s ThreatsDay Bulletin tracks fake IT calls, abused remote tools, phishing kits, unsafe downloads, ransomware, stolen data, and weak settings 출처: [The Hacker News](https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html)
소만사(대표 김대환)가 메모리 가상화 기술을 적용해 VDI(Virtual Desktop Infrastructure) 서버 하드웨어 비용을 50% 이상 절감한 자사 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208334)
Google launches Gemini 3.8 Flash Cyber for trusted defenders as OpenAI says Astra meets its Critical cybersecurity capability threshold. 출처: [The Hacker News](https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html)
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208317)
최근 과학기술정보통신부가 사이버보안에 특화된 인공지능(AI) 파운데이션 모델 개발을 추진하고 있다. AI가 사이버공격과 방어 양쪽에서 빠르게 활용되고 있다는 점을 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208301)
Attackers exploit a JFrog Artifactory authentication bypass to mint admin tokens and enumerate users on default configurations. 출처: [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html)
한국인터넷진흥원이 서로 다른 제조사와 기종의 물리보안 시스템이 공통 표준에 따라 연동될 수 있도록 물리보안 시스템 상호운용성 시험을 시행한다.최근 CCTV, 보안 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208293)
North Korean workers are expanding remote-job fraud beyond IT into healthcare and sales, using false identities, proxies, and laptop farms. 출처: [The Hacker News](https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html)
지란지교시큐리티가 사이버 보안 스타트업 필상과 업무협약을 맺고 모바일 보안 사업 협력에 나선다. 양사는 최근 증가하는 피싱, 스미싱, 악성앱 등 모바일 사이버 위 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208271)
Microsoft says TerminalFix uses fake Cloudflare CAPTCHAs to trigger PowerShell and deploy a reverse-tunnel backdoor for internal network access. 출처: [The Hacker News](https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html)
인공지능 에이전트 수백 개가 서로 정보를 공유하고 역할을 나눠 실제 외부 기업 시스템을 공격한 사건의 구체적인 내용이 공개됐다.오픈AI와 독립 평가기관 METR가 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208262)
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution. 출처: [The Hacker News](https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html)
스노우플레이크가 지난 27일 서울 코엑스에서 국내 주요 기업 경영진을 초청해 '이그제큐티브 라운드테이블 서울'을 개최했다.'From AI Ambition to E 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208253)
Berlin confirms an extortion attempt after data theft from its state network, while the scope of the exfiltrated data remains under review. 출처: [The Hacker News](https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html)
cPanel patches CVE-2026-65643, a critical flaw that lets authenticated accounts with domain controls execute code as root. 출처: [The Hacker News](https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html)
세일즈포스와 앤트로픽이 클로드에 세일즈포스의 엔터프라이즈 하네스를 결합한 '클로드포스'를 발표했다.양사는 기업의 데이터, 워크플로, 비즈니스 로직, 실행 및 거버 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208254)
넷앱이 2026 가트너 엔터프라이즈 스토리지 플랫폼 매직 쿼드런트에서 리더로 선정됐다. 해당 보고서가 처음 발간된 2025년에 이어 연속으로 이 시장의 리더로 인 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208238)
CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days. 출처: [The Hacker News](https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html)
올해 AI 분야의 주요 화두로 ‘에이전틱 AI(Agentic AI)’가 떠오르고 있다. 사람이 직접 업무를 수행하는 것처럼 AI 에이전트가 PC의 다양한 리소스를 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208197)
U.S. Treasury sanctions Iran-linked cyber actors under Operation Economic Outcast, targeting MOIS-linked hackers tied to U.S. infrastructure breaches. 출처: [The Hacker News](https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html)
중국어권 사이버 범죄조직이 인공지능(AI)을 활용해 전 세계 윈도와 리눅스 웹서버를 대규모로 공격한 정황이 확인됐다. AI를 취약점 분석과 공격 코드 수정, 침투 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208173)
ActiveState surveys 300 security and engineering leaders on AI coding, open-source remediation debt, governance, and business risk. 출처: [The Hacker News](https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html)
BTR Reforged uses Defender's signed BTR.sys with an administrator account and SeLoadDriverPrivilege for kernel file and registry operations. 출처: [The Hacker News](https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html)
스틸리언이 인도네시아 사이버보안 전문인력 양성을 담당할 현지 교수진을 대상으로 21주간의 집중 연수를 마쳤다.사이버보안 전문기업 스틸리언(대표 박찬암)은 인도네시 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208159)
시스코 네트워크 관리·보안 제품에서 치명적인 취약점 9건이 발견됐다. 이 가운데 5건은 위험도가 가장 높은 CVSS 10.0점을 받았다.영향을 받는 제품은 크로스 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208149)
TikTok will pay $400 million to settle a U.S. child privacy case alleging COPPA violations involving users under 13 and Kids Mode. 출처: [The Hacker News](https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html)
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and payload execution. 출처: [The Hacker News](https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html)
전시작전통제권 전환을 이야기하면 흔히 무기부터 떠올린다. 우리 군이 북한의 핵과 미사일을 탐지하고 대응할 능력이 있는지, 충분한 감시·정찰자산을 갖추고 있는지, 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208145)
모의 해킹이나 취약점 진단·분석, 버그바운티 등 보안 업무에 LLM을 기반으로 AI Agent를 설계하고 구축하는 방법과 어떻게 적용할 수 있는지1. Local LLM 구축(회사 정책상 클라우드 AI를 사용하지 못하는 경우가 있음)2. whiterabbitneo3. wormgpt4. [LLM] 취약점 진단 에이전트 팀 구성하기https://gomguk.tistory.com/319Reference1.DEFCON 34 AI 버그바운티https://news.hada.io/topic?id=323682. AI는 버그바운티를 어떻게 바꾸고 있을까? (from DEF CON 34) (윤석찬 화이트해커)https://new-blog.ch4n3.kr/def-con-ai-assisted-submissions-panel-ko/3. $5짜리 프롬프트로 $2,418짜리 취약점 찾은 썰https://new-blog.ch4n3.kr/llm-found-security-issues-from-django-ko/4. 버그바운티 공부 8일https://velog.io/@chltkddud03/%EB%B2%84%EA%B7%B8%EB%B0%94%EC%9A%B4%ED%8B%B0-%EA%B3%B5%EB%B6%80-8%EC%9D%BC5. LOCAL LLM2026년 코드 리뷰용 최고 로컬 LLM: 정확도 vs 속도 | PromptQuorum6. 사이버 보안 업무 관련해서 현지 LLM 조언 좀 구하고 싶어요.https://www.reddit.com/r/LocalLLaMA/comments/1tg1mr7/seeking_local_llm_advice_for_cybersecurity_work/?tl=ko
Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during compilation. 출처: [The Hacker News](https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html)
데일리시큐는 7월부터 장삼봉 작가(필명)의 정보보안 소설《로그아웃되지 않는 밤》을 매주 4편씩 연재한다. 화려한 디지털 서비스 뒤에서 보이지 않는 위협과 맞서는 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208146)
Researchers leak a JWT from a co-located Cloudflare Worker via Spectre at up to 12 bits per second; Cloudflare says the attack is mitigated. 출처: [The Hacker News](https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html)
오픈AI(OpenAI)가 최신 프런티어 인공지능(AI) 모델의 사이버 공격 능력이 빠르게 높아지자 강화학습 훈련을 2주간 중단하고 내부 보안 체계를 대폭 강화했다 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208123)
+ 취업자 분들 중채용 시기가 8월 18일 이후인 경우취업축하금(10만원) 지원해 드리는 무료보안교육 운영충북과학기술혁신원 SEPHERD 세퍼드 취업 이직 창업자 취업축하금 지원CBIST SEPHERD
CVE-2026-24301 lets crafted Copilot Personal links auto-run prompts that can pull data from connected apps and exfiltrate it via URL fetches. 출처: [The Hacker News](https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html)
라온시큐어가 업스테이지가 주도하는 ‘독자 AI 파운데이션 모델 프로젝트(독파모)’ 최종 단계 컨소시엄에 보안 파트너로 합류했다.라온시큐어는 업스테이지의 거대언어모 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208107)
통합 IT보안 기업 SGA솔루션즈(대표 최영철)는 2026년 상반기 연결 기준 매출 751억원, 영업이익 21억3,000만원을 기록했다고 밝혔다.매출은 전년 동기 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208085)
GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data 출처: [The Hacker News](https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html)
미라이(Mirai) 악성코드를 기반으로 한 새로운 리눅스 봇넷 ‘에부원봇(Evooo1Bot)’이 인터넷에 노출된 공유기와 네트워크 장비를 공격하고 있는 것으로 확 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208073)
오픈소스 지리정보 서버 지오서버(GeoServer)에서 아직 패치되지 않은 제로데이 취약점이 공개된 가운데, 공격자들이 인터넷에 노출된 서버를 찾아 공격을 시도하 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208067)
737 Chrome VPN extensions with 75,486 installs route browser traffic through SOCKS5 proxies, putting the operator in an AitM position. 출처: [The Hacker News](https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html)
엔피코어가 지난 8월 12일 코스타리카 산호세 컨벤션센터에서 열린 'Cybersec Summit 2026'에 참가해 AI 기반 보안 솔루션을 공개했다.'Cyber 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208063)
Attackers exploit SharePoint CVE-2026-55040 after a Rapid7 PoC release, forging JWTs to impersonate site users or admins. 출처: [The Hacker News](https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html)
오펜시브 사이버보안 전문기업 티오리(Theori)가 개발한 AI 기반 모의해킹 솔루션 ‘진트(Xint)’가 글로벌 시장조사기관 IDC의 자율 침투 테스트 분야 ‘ 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208052)
오픈AI, 앤트로픽, 구글의 인공지능 API에서 암호화된 내부 추론 과정을 복원할 수 있었던 보안 문제가 발견됐다. 공개된 AI 에이전트 작업 로그에서는 API 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208029)
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms. 출처: [The Hacker News](https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html)
Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs. 출처: [The Hacker News](https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html)
[3편] AI보다 느린 보안은 무엇을 바꿔야 하는가"속도는 기술에, 판단은 사람에게"보안의 속도는 점점 중요해지고 있다.공격은 자동화되고, AI는 분석과 실행의 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=208012)
에스넷그룹이 AI 전환(AX)을 본격적으로 추진하며 조직 역량 강화에 나섰다.가치경영실 주관 아래 진행되는 이번 전환은 임직원 역량 강화와 활용 문화 확산, 시스 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207986)
AI-driven development can raise code output 10 to 50 times, forcing security teams to rethink review, remediation, and governance. 출처: [The Hacker News](https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html)
Outlook CSS techniques can spoof Microsoft sign-in and capture passwords, while Gmail image-set() can trigger external requests from malicious email c 출처: [The Hacker News](https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html)
금융보안원(원장 박상원) 소속 화이트해커들이 세계적인 해킹방어대회 ‘DEF CON 34 CTF’에서 2위부터 4위까지 상위권을 차지했다.8월 7일부터 9일까지(현 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207968)
보안회사 방향금융보안원 압박 > 잉카인터넷 포함해서 전반적인 금융권 설치형 서비스 매출하락sk쉴더스 매출 올려서 pef(사모펀드) 팔자[기업분석] 엑스게이트, AI 차세대 방화벽·양자보안·홈네트워크 구독 플랫폼의 3축https://www.youtube.com/watch?v=TwdkeIfAErM안랩https://www.youtube.com/watch?v=aMHxARF8xWQ국내 대표 보안기업 안랩이 해외 사업을 시작한 지 20년이 넘었지만, 매출 구조는 여전히 국내 시장에 집중된 것으로 나타났습니다. 일본과 중국 법인에 이어 중동 합작법인까지 세웠는데 올해 1분기 해외 매출 비중은 6%대에 그쳤습니다. 글로벌 진출 전략에 대한 점검이 필요2026 1분기 매출 590억 수출 6.3%보안 상장인스피언아이씨티케이안랩윈스아이씨티케이> 양자내성암호> 보안 팹리스 업체> ICTK 고유 기술인 비아 퍼프(VIA PUF)는 물리적 복제와 해킹으로부터 안전하며 양자컴퓨터나 AI 공격에도 내성을 가진다https://www.youtube.com/shorts/oMK__88GYi8정보보안회사 평균 연봉 TOP 10https://www.youtube.com/shorts/g_4UFNhHZJI윈스 > 보안 클라우드https://www.youtube.com/watch?v=CgoBC3Q0nvQ슈프리마출입통제/영상분석 통합 플랫폼바이오메트릭 출입통제물리보안 > 현대자동차 로보틱스랩 협업, 삼성전자 협업아톤 모바일 OTP / 인증서비스ATON-mOTP (주요 금융권)매출 2023년 500억 / 2024 650억https://www.youtube.com/shorts/TiLoLKL24es
클라이온이 AI 전환(AX)과 클라우드 사업 확장을 위해 김주성 전 가온아이 전략사업부 CSO를 신임 대표이사 겸 총괄사장으로 선임했다.김주성 신임 대표는 KT와 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207964)
Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers. One path is fixed; another remained unresolved on August 5. 출처: [The Hacker News](https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html)
안녕하십니까 *** 강사님방금 전화드렸던 ***** 팀장입니다.미팅 중 전화로 말씀드려 송구합니다.방금 유선으로 말씀드렸던 강의에 대해 간략히 남겨드리고자 합니다. - 강의명 : 기업수요기반 화이트해커 양성과정 中 디지털 포렌식 트랙 'AI 기반 클라우드 위협탐지 및 사고 대응' 과목 - 주요 강의 내용 : AWS/Azure/GCP 로그 분석, M365 Audit 분석, IAM 및 계정행위 분석, 클라우드 기반 침해행위 분석 등 * 상기 내용이 필수 고정은 아니며, 저희와 논의 후 일부 수정 가능합니다. - 강의일정 : ****** - 강의장소 : 부산시 해운대구 ***** - 강의수당 : 시간당 20만원
Nearly 800 malicious npm packages deliver a cross-platform RAT and infostealer, using WEL1DROPPER to target Windows, macOS, and Linux systems. 출처: [The Hacker News](https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html)
최근 인공지능(AI)의 발전을 보면서 필자가 가장 우려하는 것 중 하나는 ‘해킹의 대중화’다. 과거에는 소프트웨어의 취약점을 분석하고 실제 공격에 활용하려면 상당 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207961)
Zapscape could let guest root escape nested KVM and execute code on the Linux host through a shadow-MMU use-after-free; no in-wild exploitation is cla 출처: [The Hacker News](https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html)
개인정보보호위원회가 인공지능(AI)과 데이터 활용 환경 변화에 맞춰 개인정보 보호 제도를 전면 재검토한다. 반복적인 개인정보 동의 절차와 가명정보의 국외이전 제한 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207954)
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and serve selected Mac users. 출처: [The Hacker News](https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html)
[라스베이거스=데일리시큐 길민권 기자] 공격자가 개별 기업을 직접 침투하는 대신 오픈소스 패키지와 개발도구, 보안 솔루션 등 조직이 이미 신뢰하는 공급망을 장악하 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207937)
[라스베이거스=데일리시큐 길민권 기자] 글로벌 사이버보안 행사 ‘블랙햇 USA 2026(Black Hat USA 2026)’이 8월 1일부터 6일까지 미국 라스베 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207922)
Greatness PhaaS adds device code phishing to bypass MFA and steal OAuth tokens alongside AiTM and consent abuse. 출처: [The Hacker News](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
Malicious npm packages impersonate Alibaba tools to deliver a cross-platform RAT with command execution, persistence, and lateral movement. 출처: [The Hacker News](https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html)
키페어(대표 이창근)와 KB국민은행이 양자컴퓨팅 시대 보안위협에 대응하기 위한 공동 연구에 나선다.양자내성암호(PQC) 전문기업 키페어와 KB국민은행은 양자내성암 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207893)
Attackers altered Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron wallet addresses across customer sites. 출처: [The Hacker News](https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html)
어도비가 기업용 마케팅 자동화 플랫폼인 캠페인 클래식에서 최고 위험도(CVSS 10.0)의 보안 취약점을 수정하는 긴급 보안 업데이트를 발표했다. 해당 취약점은 출처: [데일리시큐](https://www.dailysecu.com/news/articleView.html?idxno=207877)