보안 동향 브리핑
|
SECURITY
DAILY REPORT
Eyeon Security
|
|
|
생성일시: 2026-07-29 01:19
|
|
보안뉴스 (신규 5건)
|
OWASP 서울챕터, ‘2026 오픈소스 AI·SW 커뮤니티’ 선정
수집일: 2026-07-29
과학기술정보통신부 주최 ‘OpenUP’ 지원 사업 합류로 커뮤니티 운영 기반 마련김동현 리더 “커뮤니티 지원 사업을 통해 기여자에게 실질적 가치 돌려줄 것”[보안뉴스 조재호 기자] 글로벌 보안 커뮤니티인 ‘오픈소스 웹 애플리케이션 보안 프로젝트’(OWASP) 서울챕터가 정부 주관 지원 사업 대상으로 선정되며 오픈소스 보안 저변 확대에 나선다.OWASP 서울
|
|
이지서티, 단말 기반 차세대 AI 방화벽 ‘EZRO-AI FIREWALL’ 출시
수집일: 2026-07-29
프롬프트 인젝션·악성 명령어 삽입 등 신종 위협 양방향 원천 차단무분별한 섀도우 AI 이용 식별하고 부서별 활용 대시보드 시각화 제공[보안뉴스 조재호 기자] 이지서티가 생성형 AI 보안 플랫폼 ‘이지로 AI 방화벽’(EZRO-AI FIREWALL)을 정식 출시했다고 밝혔다. 이번 신제품은 외부 공격자로부터 사내 구축 LLM을 보호하는 기능과 임직원의 외부
|
|
[인사] 과학기술정보통신부
수집일: 2026-07-29
◇과장급 전보△원천기술과장 김동준 (金東俊, 미래인재양성과장)△미래인재양성과장 최진혁 (崔振赫, 과학기술정보통신부)△기계정보통신조정과장 이강우 (李剛雨, 원천기술과장)(2026. 7. 29. 자) [강현주 기자(jjoo@boannews.com)]www.boannews.com) 무단전재-재배포금지>
|
|
“너 야동 봤지?”... 샤이니헌터 사칭, 민망한 영상 유포 협박
수집일: 2026-07-29
기존 유출된 데이터 악용... “유포 막으려면 2000달러 비트코인 입금” 협박[보안뉴스=김형근 기자] 해킹 조직 ‘샤이니헌터스’(ShinyHunters)가 과거 탈취한 기업 데이터베이스 내 이메일 정보를 악용한 성착취 공갈(Sextortion) 캠페인이 확산되고 있다고 해외 정보보호 매체 블리핑컴퓨터가 보도했다. .공격자들은 피해자 기기를 해킹해 통제권을
|
|
금융보안원, 온라인 ‘금융 AI보안 캠퍼스’ 개설
수집일: 2026-07-29
수요 높은 AI 보안 과정 오픈 후 내년 초 전면 개시하나의 플랫폼에서 체계적 학습[보안뉴스 강현주 기자] 금융보안원(원장 박상원)은 금융회사 임직원의 AI 보안 역량 강화를 지원하기 위해 온라인 ‘금융 AI보안 캠퍼스’를 개설할 계획이라고 28일 밝혔다. 금융보안원은 금융권의 AI 활용이 빠르게 확산되고 미토스 등 프론티어 AI가 새로운 보안 과제로 부상
|
KISA 보안공지 (신규 1건)
|
美 CISA 발표 주요 Exploit 정보공유(Update. 2026-07-27)
수집일: 2026-07-29
□ 개요 o 美 CISA에서 현재 자주 악용되고 있는 취약점 목록 발표 [1] o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고 □ 영향을 받는 제품 | CVE | 제조사 | 취약점 | 내용 | 조치사항 |
|---|
| CVE-2026-16812 | Arista | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | | CVE-2025-68686 | Fortinet | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1] □ 참고사이트 [1] https://www.cisa.gov/known-exploited-vulnerabilities-catalog □ 작성 : 디지털위협대응본부 취약점관리센터 |
|
|
|
본 메일은 시스템에 의해 자동으로 수집 및 발송된 보안 동향 모니터링 리포트입니다.
|
|
|