시스코, Unified CM의 CVE‑2026‑20230 취약점 패치… 익스플로잇 코드 공개됨
Overview Cisco has patched a vulnerability in Unified Communications Manager Unified CM that allowed an unauthenticated attacker on the network to write files...
130 posts from this source
Overview Cisco has patched a vulnerability in Unified Communications Manager Unified CM that allowed an unauthenticated attacker on the network to write files...
Swati KhandelwalJun 04, 2026Vulnerability / AI Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiaBF9jAklPh1ncr_eVPGnV229BSTNgAjkScVm-yTX...
Image: Agentic AI Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challen...
다시 어리석게 되었어. 인터넷은 여전히 테이프로 붙여진 듯한 느낌이다. 형편없는 플러그인, 오래된 버그, 가짜 도구, 신뢰받는 앱이 수상한 행동을 한다. 같은 혼란, 새로운 wrappe...
A new China‑linked cybercrime group known as TA4922 has expanded its targeting focus to European organizations in the United Kingdom, Germany, Italy, and South...
markdown !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFQkJElJQpI5ODTBzh1EzrxsRYamFN0ntC9V6vF4b4FfEJ0svPhI_1TnKm960eIsewSFT-DR1RtNk3M511OQK6I-k3...
Cybersecurity researchers have flagged a large‑scale operation that impersonates open‑source and freeware projects to funnel unsuspecting users through a Traffi...
Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small,...
Ravie Lakshmanan June 4, 2026 – Cryptocurrency / Law Enforcement !Police crypto imagehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTf5wAHnoXtVauil...
사이버 보안 연구원들은 브라질 최대 협동조합 중 하나인 Sicoob를 위한 C 소프트웨어 개발 키트로 위장한 악성 NuGet 패키지를 발견했습니다.
A critical security vulnerability has been disclosed in Gogs, a popular open‑source self‑hosted Git service. The flaw allows any authenticated user to achieve r...
위협 행위자들은 현재 패치된 FortiClient Endpoint Management Server EMS의 중요한 보안 결함을 악용하여 자격 증명을 탈취하는 악성 페이로드를 전달하고 있습니다.
!Microsoft 및 GitHub 이미지https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIMDR_KVt17sFMXeEhMvDYHLwBX_Aix1bz3y0izMs7PsVIuGSQhOLX_khN3Ckl_eRm9OEMAlVm...
산업계가 마침내 무모하고 저노력적인 쓰레기를 그만두었다고 생각할 때마다, 누군가가 스케치한 로더와 가짜 설치 프로그램으로 가득 찬 새로운 박스를 가동합니다.
State of AI Usage Report 2026 full report here by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't...
Overview Latin America and Europe have become the target of two banking‑trojan campaigns designed to infect Windows and Android devices with Grandoreiro and BT...
CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control C2 channels associ...
Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents...
Introduction When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool,...
!Gitea main interfacehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtYSLWixSGb7jW2drND6NlHzXB4eHO0QyZNOovK9iVyaHGS6fSN4eqhWkijIhevhInH56hv03c29ziWC...
Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence AI chatbot interactions as a mechanism for surfacing maliciou...
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents i...
매일매일 해커들은 웹사이트를 다운시키고 데이터를 훔치는 새로운 방법을 찾고 있습니다. 하지만 지금은 상황이 달라졌습니다. 해커들은 더 이상 혼자 일하지 않습니다—
!SharePointhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi34meakbjhvY3-jNVG7Q8tPJ5Xk1a-vtGSeKgfVDApX6pn88G7gYhK2oz34my6QeWHsldmSJuV4o8tlBOmw-9Ul32E...
The Indian Computer Emergency Response Team CERT‑In has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet‑exp...
Ravie Lakshmanan May 26 2026 – Artificial Intelligence / Cloud Security !Indian CERThttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9yN2AliOVdy0oCCM...
The Iranian state‑sponsored threat actor known as Nimbus Manticore also referred to as Screening Serpens and UNC1549 has been linked to a new campaign that uses...
죄송합니다. 번역할 텍스트를 제공해 주시겠어요?
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from t...
위협 개요: 위협 행위자들은 최근 공개된 Ghost CMS의 중요한 보안 결함을 악용하여 악성 JavaScript 코드를 주입하고, 이를 통해 C...
네트워크 탐지 및 대응(NDR)에 대해 사이버 보안 전문가에게 물어보면 여전히 “소음이 많다”, “데이터가 너무 많다”는 말을 들을 수 있습니다. 하지만 NDR를 실제로 운영하고 있는 팀에게 물어보면…
Cybersecurity 연구원들은 North Korea‑linked Lazarus Group이 공격에 사용한 RemotePE라는 cross‑platform 악성코드에 대해 밝혀냈다.
새로운 협조된 크로스‑에코시스템 소프트웨어 공급망 공격 캠페인이 npm, PyPI 및 Crates.io를 표적으로 삼아 자격 증명 탈취 악성코드를 배포하고 있습니다. 이 캠...
Ravie LakshmananMay 23, 2026Software Supply Chain / DevSecOps !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4rnMZgOYbsYr65UN9AZ3oFzcAwqXSYqgRfj...
Ravie LakshmananMay 23, 2026Malware / DevSecOps !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ5LyRYJIkEVUSrrBV-_qvrXIKC-B4h0JAxyV4IalzuiEzXi6K...
Ravie LakshmananMay 23, 2026Artificial Intelligence / Vulnerability !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOPcHXcMRS-BJNvy9aeoCz5H2Mmdh6...
Ravie LakshmananMay 23, 2026Supply Chain Attack / Malware !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkqwlAgmL-HrE2pSx8xqfY4-AyYZ59wK4x5AWtnC...
Ravie LakshmananMay 23, 2026Vulnerability / Web Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM0W1UqsbcZ-8IV_n8ov3V24MQ74VaKe3auGFWNun...
Ravie LakshmananMay 23, 2026Vulnerability / Website Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKqQ4Uk8lGWwF7f6lrmP6dRHkEmQTJsqFs8xv...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8yN-yeHodasj_piRqdUbE1MGyOfiyAzo-x6KZ_V9oilxP_v_kFNoyLVU7oNmG05F5g49pLeMY_jgJtU0mFk9ft_0qi4oLFgTxm0...
Ravie LakshmananMay 22, 2026Malware / Artificial Intelligence !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNDmjcnVzVIqFFB-CQU7L6G8XVTifkZGmIMc...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjC_sjVeLejyyBZJ0DWW2y9-Z2Jvmrzz9h-5XEIKPFTcJvDj49Jlt-z1FNbSp51K9XcQ8FqC9MBDFPPPdZuzRfjqtYvKNaqT0Qzd6...
Ravie LakshmananMay 22, 2026Cybercrime / Law Enforcement !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5VYMnsK-UMv3L8TZp1KhZ4PQti0VtUXkbDREtK-R...
Ravie LakshmananMay 22, 2026Vulnerability / Cyber Attack !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi04a_rowIzNPvHHvDTUE34d3bZlOhBeQXtC0UdXyj...
Cisco has rolled out updates for a maximum‑severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensi...
Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications pr...
This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you...
Overview Microsoft has disclosed that a privilege‑escalation flaw and a denial‑of‑service flaw in Microsoft Defender are being actively exploited in the wild....