Eyeon Security Information security company

보안 동향

㈜아이온시큐리티에서 서비스 이용 고객님들의 안정적인 시스템 운영을 위해
필수적인 주요 보안 조치 사항을 안내해드립니다.

OWASP 서울챕터, ‘2026 오픈소스 AI·SW 커뮤니티’ 선정 관리자 2026-07-29 01:23:15
OWASP 서울챕터, ‘2026 오픈소스 AI·SW 커뮤니티’ 선정
관리자  2026-07-29 01:23:15
보안 동향 브리핑
SECURITY
DAILY REPORT
Eyeon Security

생성일시: 2026-07-29 01:19

보안뉴스 (신규 5건)
OWASP 서울챕터, ‘2026 오픈소스 AI·SW 커뮤니티’ 선정
수집일: 2026-07-29
기사 이미지
과학기술정보통신부 주최 ‘OpenUP’ 지원 사업 합류로 커뮤니티 운영 기반 마련김동현 리더 “커뮤니티 지원 사업을 통해 기여자에게 실질적 가치 돌려줄 것”[보안뉴스 조재호 기자] 글로벌 보안 커뮤니티인 ‘오픈소스 웹 애플리케이션 보안 프로젝트’(OWASP) 서울챕터가 정부 주관 지원 사업 대상으로 선정되며 오픈소스 보안 저변 확대에 나선다.OWASP 서울
원문 바로가기 →
이지서티, 단말 기반 차세대 AI 방화벽 ‘EZRO-AI FIREWALL’ 출시
수집일: 2026-07-29
기사 이미지
프롬프트 인젝션·악성 명령어 삽입 등 신종 위협 양방향 원천 차단무분별한 섀도우 AI 이용 식별하고 부서별 활용 대시보드 시각화 제공[보안뉴스 조재호 기자] 이지서티가 생성형 AI 보안 플랫폼 ‘이지로 AI 방화벽’(EZRO-AI FIREWALL)을 정식 출시했다고 밝혔다. 이번 신제품은 외부 공격자로부터 사내 구축 LLM을 보호하는 기능과 임직원의 외부
원문 바로가기 →
[인사] 과학기술정보통신부
수집일: 2026-07-29
◇과장급 전보△원천기술과장 김동준 (金東俊, 미래인재양성과장)△미래인재양성과장 최진혁 (崔振赫, 과학기술정보통신부)△기계정보통신조정과장 이강우 (李剛雨, 원천기술과장)(2026. 7. 29. 자) [강현주 기자(jjoo@boannews.com)]www.boannews.com) 무단전재-재배포금지>
원문 바로가기 →
“너 야동 봤지?”... 샤이니헌터 사칭, 민망한 영상 유포 협박
수집일: 2026-07-29
기사 이미지
기존 유출된 데이터 악용... “유포 막으려면 2000달러 비트코인 입금” 협박[보안뉴스=김형근 기자] 해킹 조직 ‘샤이니헌터스’(ShinyHunters)가 과거 탈취한 기업 데이터베이스 내 이메일 정보를 악용한 성착취 공갈(Sextortion) 캠페인이 확산되고 있다고 해외 정보보호 매체 블리핑컴퓨터가 보도했다. .공격자들은 피해자 기기를 해킹해 통제권을
원문 바로가기 →
금융보안원, 온라인 ‘금융 AI보안 캠퍼스’ 개설
수집일: 2026-07-29
기사 이미지
수요 높은 AI 보안 과정 오픈 후 내년 초 전면 개시하나의 플랫폼에서 체계적 학습[보안뉴스 강현주 기자] 금융보안원(원장 박상원)은 금융회사 임직원의 AI 보안 역량 강화를 지원하기 위해 온라인 ‘금융 AI보안 캠퍼스’를 개설할 계획이라고 28일 밝혔다. 금융보안원은 금융권의 AI 활용이 빠르게 확산되고 미토스 등 프론티어 AI가 새로운 보안 과제로 부상
원문 바로가기 →
KISA 보안공지 (신규 1건)
美 CISA 발표 주요 Exploit 정보공유(Update. 2026-07-27)
수집일: 2026-07-29

□ 개요
o 美 CISA에서 현재 자주 악용되고 있는 취약점 목록 발표 [1]
o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 영향을 받는 제품

CVE제조사취약점내용조치사항
CVE-2026-16812AristaArista VeloCloud Orchestrator On-Prem OS Command Injection VulnerabilityArista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2025-68686FortinetFortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityFortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1]

□ 참고사이트
[1] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

□ 작성 : 디지털위협대응본부 취약점관리센터

원문 바로가기 →
본 메일은 시스템에 의해 자동으로 수집 및 발송된 보안 동향 모니터링 리포트입니다.

첨부 파일 :