한국정보보호교육센터

한국정보보호교육센터

Share

(주)한국정보보호교육센터 내 기술연구소(f-NGS Lab)에서 운영하는 보안기술,

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents 24/08/2026


https://cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents

AI 테스트를 수행하는 Irregular라는 회사가 Anthropic과 OpenAI의 모델을 사용한 사이버 보안 테스트 중 발생한 사고를 보고했다.
이들은 의도치 않게 인터넷 접근을 제공하여 모델이 실제 공격을 수행하게 된 사례를 설명하며, 이러한 문제는 인적 오류로 인한 것이라고 밝혔다.
Irregular는 향후 평가 설정의 문서화 개선, 로그 모니터링 도구 배포, 위협 모델 수정 등을 통해 보안 관행을 강화할 계획이다.
이 사건은 AI 모델의 강력함이 증가함에 따라 보안 프로토콜의 필요성을 더욱 강조하고 있다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents Testing firm Irregular blames human oversight after accidental internet access allowed Anthropic and OpenAI models to escape sandboxes and launch real-world attacks.

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads 24/08/2026


https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project took swift action to delete malicious versions of three widely used Rust crates after a maintainer's account was compromised.
The affected crates, arrayref, internment, and append-only-vec, had malicious build scripts that executed remote payloads during compilation.
Developers are advised to check their systems for the deleted crate files and to revert to earlier versions.
The incident highlights the risks associated with typosquatting and the need for enhanced security measures in package management systems.
Although no evidence of actual usage was found, the Rust Security Response Team is investigating the compromised account and its implications for the broader Rust ecosystem.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during compilation.

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure 24/08/2026


https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

최근 GitLab에서 발견된 보안 취약점 CVE-2026-19478은 코드 주입 공격으로, 인증되지 않은 공격자가 특정 조건 하에 공개적으로 접근 가능한 GitLab 프로젝트를 수정하거나 삭제할 수 있는 위험을 안고 있다.
이 취약점은 GitLab Community Edition과 Enterprise Edition의 여러 버전에 영향을 미치며, GitLab은 이 문제를 GraphQL 지시어를 통해 악용할 수 있다고 경고했다.
보안 전문가들은 AI 기술을 활용한 공격자들이 취약점 공개와 악용 사이의 시간을 단축시키고 있음을 강조하며, 패치를 적용하지 않은 조직들은 웹 로그에서 의심스러운 요청을 찾아야 한다고 조언하고 있다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.

Hackers abuse FTP server banners to deliver new Windows malware 24/08/2026


https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/

Hackers abuse FTP server banners to deliver new Windows malware

최근 연구에 따르면, 해커들이 FTP 배너를 이용해 E4del과 PINHOLE이라는 두 가지 새로운 원격 접근 트로이 목마(RAT)를 배포하고 있습니다.
이들은 주로 피싱 공격을 통해 ZIP 아카이브와 LNK 파일을 사용하여 감염 체인을 시작합니다.
E4del은 Discord로 위장한 Node.js 기반의 RAT로, 다양한 명령 실행과 스크린샷 캡처 기능을 지원합니다.
반면, PINHOLE은 Pinterest 핀과 SurveyMonkey 질문을 통해 C2 구성을 가져오며, 최소한의 흔적을 남기고 여러 명령을 실행할 수 있는 기능을 가지고 있습니다.
이 기법은 기존의 웹 기반 DDR보다 덜 은밀하지만, 여전히 다재다능한 공격 방법으로 평가되고 있습니다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Hackers abuse FTP server banners to deliver new Windows malware Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.

North Korean Hackers Tied to Rust Supply Chain Attack 24/08/2026


https://www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/

North Korean Hackers Tied to Rust Supply Chain Attack

최근 Wiz 보안 연구자들은 북한의 국가 지원 해커들이 Rust 프로그래밍 생태계를 겨냥한 소프트웨어 공급망 공격에 연루되었다고 보고했습니다.
이 공격은 Rust 패키지 레지스트리인 crates.io에서 여러 널리 사용되는 오픈 소스 라이브러리를 타겟으로 하여, 개발자 작업 환경과 CI 환경에 침투하기 위한 백도어를 삽입했습니다.
공격자는 신뢰할 수 있는 오픈 소스 유지 관리자의 계정에 접근하여 legitimate crates를 업데이트했으며, 이로 인해 75%의 클라우드 환경에서 Rust 애플리케이션이 영향을 받을 수 있었습니다.
조사 결과, 이 악성코드는 북한 사이버 작전과 연결된 것으로 나타났으며, 보안 팀은 영향을 받은 버전을 점검하고 자격 증명을 즉시 회전할 것을 권장하고 있습니다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

North Korean Hackers Tied to Rust Supply Chain Attack Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks

Hundreds of leaked AWS keys give full control over corporate accounts 24/08/2026


https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/

Hundreds of leaked AWS keys give full control over corporate accounts

Truffle Security의 연구에 따르면, 2022년 8월부터 2026년 8월 사이에 공개된 9,300개 이상의 AWS 액세스 키 중 768개가 여전히 활성 상태로 확인되었습니다.
이 중 817개는 기업과 관련이 있으며, 526개는 AWS 루트 키입니다.
특히, 관리자 권한을 가진 IAM 사용자와 연결된 키가 242개로, 이는 공격자가 기업의 AWS 계정에 대한 완전한 제어를 가능하게 합니다.
연구진은 또한 Hugging Face 플랫폼에서 가장 많은 키 노출이 발생했음을 밝혔으며, 노출된 키의 평균 연령은 약 5년으로 나타났습니다.
이를 방지하기 위해 연구진은 루트 액세스 키 삭제와 IAM 자격 증명 검토를 권장합니다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Hundreds of leaked AWS keys give full control over corporate accounts More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

New SynkLoader malware pushed in Microsoft Teams phishing campaign 24/08/2026


https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/

New SynkLoader malware pushed in Microsoft Teams phishing campaign

SynkLoader는 Microsoft Teams를 통해 배포되는 새로운 악성코드 패밀리로, 사용자의 자격 증명을 훔치기 위해 가짜 잠금 화면을 사용하는 방식으로 작동한다.
공격자는 피해자의 IT 헬프 데스크를 가장하여 신뢰성을 높이고, Microsoft Azure에 호스팅된 가짜 'PowerShell Cleaner' 실행 파일을 설치하도록 유도한다.
이 악성코드는 Python, PowerShell, C #, C++를 혼합하여 사용하는 독특한 구조를 가지고 있으며, 여러 모듈을 통해 시스템 정보를 수집하고, 원격 제어를 가능하게 한다.
특히 PhishLocker 모듈은 사용자 로그인 정보를 수집하기 위해 매우 그럴듯한 Windows 잠금 화면을 표시한다.
공격자들은 이러한 정보를 이용해 기업 환경에 접근할 수 있다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

New SynkLoader malware pushed in Microsoft Teams phishing campaign A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.

Hackers infect Android car head units with proxy botnet malware 24/08/2026


https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/

Hackers infect Android car head units with proxy botnet malware

Kaspersky의 연구에 따르면, MoYu 그룹이 개발한 악성코드가 Android 기반 자동차 헤드 유닛을 감염시키는 공급망 공격을 통해, 감염된 장치를 프록시 봇넷에 포함시키거나 광고 사기를 위해 사용하고 있습니다.
이 공격은 중국의 DoFun 시스템에서 발생하며, 악성코드는 합법적인 장치 업데이트 앱을 통해 배포됩니다.
연구진은 이 공격이 자동차 헤드 유닛을 겨냥한 최초의 사례라고 밝혔습니다.
악성코드는 다양한 명령을 지원하며, 주로 광고 사기 및 인터넷 연결된 자동차 헤드 유닛을 주거용 프록시 노드로 전환하는 데 사용됩니다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Hackers infect Android car head units with proxy botnet malware A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.

The long tail of Clop’s PTC hack is just beginning to emerge 24/08/2026


https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/

The long tail of Clop’s PTC hack is just beginning to emerge

Clop이라는 사이버 범죄 그룹이 최근 제로데이 취약점을 악용하여 여러 대기업을 포함한 수십 개 조직의 데이터를 훔쳤다고 주장하고 있다.
이 공격은 PTC의 Windchill 및 FlexPLM 소프트웨어 제품에서 발생한 취약점을 중심으로 진행되었으며, Clop은 이미 알려진 피해자들에게 협박 이메일을 보내기 시작했다.
PTC는 이 취약점을 6월 17일에 공개하고 패치를 배포했지만, 일부 피해자는 그 이전에 이미 공격을 당한 것으로 보인다.
연구자들은 Clop이 사용한 도구와 기술에 대한 새로운 세부 사항을 밝혀내고 있으며, 이 그룹은 지속적으로 시스템에 접근하여 데이터를 절취하는 방식으로 활동하고 있다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

The long tail of Clop’s PTC hack is just beginning to emerge The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.

19/08/2026


https://thecyberexpress.com/arma-cyberattack-hits-ukraine-ara/

Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

우크라이나 자산 회수 및 관리 기관(ARMA)은 IDS 우크라이나와 관련된 자산 관리자를 선정하기 위한 경쟁을 준비하던 중 사이버 공격을 받았다고 밝혔다.
이 공격은 지원서 제출 마감일인 8월 22일 직전에 발생했으며, ARMA는 이 사건이 기관의 운영을 방해하려는 더 넓은 노력의 일환일 수 있다고 우려하고 있다.
ARMA는 사이버 공격과 관련된 사건들을 조사 중이며, 법 집행 기관과 협력하여 불법적인 간섭의 징후를 분석하고 있다.
그럼에도 불구하고 ARMA는 IDS 우크라이나 자산 관리자 선정 경쟁을 계속 진행할 것이라고 밝혔다.

📌 콘텐츠 검수: 시큐리티콘텐츠허브, 한국정보보호교육센터, KISEC

Checking search engine crawler...

Want your school to be the top-listed School/college in Seoul?

Click here to claim your Sponsored Listing.

Location

Telephone

Address


강남구 남부순환로 2645 5층
Seoul