Eyeon Security Information security company

보안 동향

㈜아이온시큐리티에서 서비스 이용 고객님들의 안정적인 시스템 운영을 위해
필수적인 주요 보안 조치 사항을 안내해드립니다.

유니트리 G1 휴머노이드 로봇서 원격 해킹 취약점…주변 로봇으로 공격 확산 가능 관리자 2026-08-31 02:13:56
유니트리 G1 휴머노이드 로봇서 원격 해킹 취약점…주변 로봇으로 공격 확산 가능
관리자  2026-08-31 02:13:56
보안 동향 브리핑
SECURITY
DAILY REPORT
Eyeon Security

생성일시: 2026-08-31 02:04

보안뉴스 (신규 5건)
유니트리 G1 휴머노이드 로봇서 원격 해킹 취약점…주변 로봇으로 공격 확산 가능
수집일: 2026-08-31
중국 로봇 기업 유니트리(Unitree)의 휴머노이드 로봇 G1 EDU에서 공격자가 인증 없이 로봇의 최고 관리자 권한을 확보할 수 있는 보안 취약점 2건이 공개됐다. 연구 과정에서는 한 대의 로봇을 장악한 뒤 블루투스 범위 안에 있는 다른 G1까지 공격할 수 있는 가능성도 확인됐다.보안 연구원 올리비에 라플람은 약 3개월간 G1을 분석한 결과를 8월 27
원문 바로가기 →
영국 3개 공항 운영사 MAG 사이버공격…고객 870만명 정보 노출
수집일: 2026-08-31
영국 맨체스터공항, 런던 스탠스테드공항, 이스트미들랜즈공항을 운영하는 맨체스터 에어포츠 그룹이 사이버공격을 받아 약 870만명의 고객 정보가 외부에 노출됐다.MAG는 지난 8월 27일 사이버보안 사고 발생 사실을 공식 공개했다. 공격자는 주차장과 공항 라운지, 패스트트랙 예약 정보와 공항 내 와이파이 가입 정보가 저장된 시스템에 무단으로 접근했다.노출된 정
원문 바로가기 →
700개 AI 에이전트가 허깅 페이스 공격…스스로 역할 나누고 취약점 공략
수집일: 2026-08-31
인공지능 에이전트 수백 개가 서로 정보를 공유하고 역할을 나눠 실제 외부 기업 시스템을 공격한 사건의 구체적인 내용이 공개됐다.오픈AI와 독립 평가기관 METR가 8월 26일 공개한 조사 결과에 따르면, 약 1,200개의 AI 에이전트가 비인가 메시지 공간을 이용해 7만건이 넘는 메시지와 파일을 주고받았다. 이 가운데 약 700개 에이전트가 허깅 페이스(H
원문 바로가기 →
안드로이드 17, 접속 사이트 노출 줄인다...웹 접속 도메인 추적 차단 강화
수집일: 2026-08-31
구글이 안드로이드 17에 암호화 클라이언트 헬로를 지원하면서 모바일 인터넷 접속정보 보호를 강화했다.구글은 8월 27일 안드로이드 17에 ECH를 비롯해 로컬 네트워크 보호, 인증서 투명성, 2G 네트워크 차단 기능 등을 적용한다고 공개했다.ECH는 HTTPS 연결 과정에서 외부에 노출될 수 있었던 서버 이름 표시를 암호화하는 기술이다. HTTPS가 통신
원문 바로가기 →
러시아 해킹 조직 APT28, 유럽 정부·외교기관 공격…신종 백도어 ‘HOOKEDGE’ 사용
수집일: 2026-08-31
러시아 연계 해킹그룹 APT28이 유럽 정부와 외교기관을 대상으로 새로운 백도어 ‘훅엣지(HOOKEDGE)’를 사용한 사이버 스파이 활동을 벌인 정황이 확인됐다. 공격은 2025년 9월 말부터 2026년 4월 초까지 스페인, 루마니아, 튀르키예의 정부·외교·방산 관련 조직을 중심으로 관측됐다.이번 공격에 대한 상세 분석은 2026년 8월 27일 공개됐다.
원문 바로가기 →
KISA 보안공지 (신규 1건)
美 CISA 발표 주요 Exploit 정보공유(Update. 2026-08-27)
수집일: 2026-08-31

□ 개요
o 美 CISA에서 현재 자주 악용되고 있는 취약점 목록 발표 [1]
o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 영향을 받는 제품

CVE제조사취약점내용조치사항
CVE-2026-66384JFrogJFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory VulnerabilityJFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-53362LinuxLinux Kernel Unspecified VulnerabilityLinux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2023-49105ownCloudownCloud Improper Authentication VulnerabilityownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1]

□ 참고사이트
[1] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

□ 작성 : 디지털위협대응본부 취약점관리센터

원문 바로가기 →
본 메일은 시스템에 의해 자동으로 수집 및 발송된 보안 동향 모니터링 리포트입니다.

첨부 파일 :