Security Feed Digest (2026-07-28)
Hacker News: Best
- Our position on open-weights models — Mon, 27 Jul 2026 22:03:49 +0000
- Judge Rejects Google’s Attempt to DMCA Its Way Out of Being Scraped — Mon, 27 Jul 2026 18:15:35 +0000
- Canceling “Hey” — Mon, 27 Jul 2026 17:37:02 +0000
- Decathlon Germany adds Wero payment option to decathlon.de website — Mon, 27 Jul 2026 16:49:08 +0000
- Kimi-K3 Technical Report [pdf] — Mon, 27 Jul 2026 15:23:45 +0000
- Apple Will ‘Watch Everything Burn’ When the AI Bubble Bursts — Mon, 27 Jul 2026 14:42:41 +0000
- AI companies spend record sums on Washington lobbying — Mon, 27 Jul 2026 14:07:48 +0000
- AI companies are shredding rare books — Mon, 27 Jul 2026 12:32:12 +0000
- How is the Bun rewrite in Rust going? — Mon, 27 Jul 2026 11:12:26 +0000
- Kimi-K3 on HuggingFace — Mon, 27 Jul 2026 06:18:10 +0000
- PGSimCity - How PostgreSQL Works — Mon, 27 Jul 2026 00:19:04 +0000
- Scriptc by Vercel: TypeScript-to-Native compiler, no JavaScript engine in binary — Sun, 26 Jul 2026 22:46:10 +0000
- US citizen charged after GrapheneOS phone wipes during airport search — Sun, 26 Jul 2026 22:21:41 +0000
- We have proof automation now — Sun, 26 Jul 2026 20:53:26 +0000
- Decker, a platform that builds on the legacy of Hypercard and classic macOS — Sun, 26 Jul 2026 18:23:06 +0000
- Introduction to Data-Oriented Design [pdf] — Sun, 26 Jul 2026 18:11:16 +0000
- French firefighters face ‘pyrocumulonimbus’ for first time — Sun, 26 Jul 2026 17:49:44 +0000
- Design is compromise — Sun, 26 Jul 2026 15:51:12 +0000
- Show HN: Reverse Minesweeper — Sun, 26 Jul 2026 12:51:03 +0000
- DeepSeek pause fundraise after comments on compute gap to US leaked (transcript) [pdf] — Sat, 25 Jul 2026 23:32:50 +0000
BleepingComputer
- Hackers target US firms in FastJson RCE zero-day attacks — Mon, 27 Jul 2026 19:49:44 -0400
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Mon, 27 Jul 2026 18:49:44 -0400
- New Dysphoria DDoS botnet spreads to 200k devices worldwide — Mon, 27 Jul 2026 17:08:15 -0400
- New Certighost PoC exploit lets attackers hijack Windows domains — Mon, 27 Jul 2026 17:00:25 -0400
- Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin — Mon, 27 Jul 2026 13:29:07 -0400
- Coca-Cola confirms data theft in Fairlife ransomware attack — Mon, 27 Jul 2026 11:39:51 -0400
- Ernst & Young data breach claimed by ShinyHunters extortion gang — Mon, 27 Jul 2026 11:12:27 -0400
- Shadow AI agents are multiplying. Here’s how to find and secure them. — Mon, 27 Jul 2026 10:01:11 -0400
Darkreading
- ‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure — Mon, 27 Jul 2026 20:57:26 GMT
- FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown — Mon, 27 Jul 2026 20:33:29 GMT
- Adversaries Don’t Need a Zero-Day — They Read Your Rulebook — Mon, 27 Jul 2026 17:31:18 GMT
- Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task — Tue, 21 Jul 2026 21:27:37 GMT
The Hacker News
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework — Mon, 27 Jul 2026 23:40:05 +0530
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption — Mon, 27 Jul 2026 22:46:28 +0530
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw — Mon, 27 Jul 2026 20:10:00 +0530
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More — Mon, 27 Jul 2026 19:40:54 +0530
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process — Mon, 27 Jul 2026 18:35:15 +0530
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update — Mon, 27 Jul 2026 18:07:49 +0530
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — Mon, 27 Jul 2026 16:21:45 +0530
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments — Mon, 27 Jul 2026 14:18:47 +0530
- GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption — Mon, 27 Jul 2026 13:31:23 +0530
데일리시큐 - 최근인기기사
- [이혁중 CISO의 현장 보안 인사이트-9] 이제 로그는 넘친다. 그럼 개인정보 유출의 신속한 판단은? — 2026-07-27 09:32:56
- 삼성·SK·네이버, 글로벌 빅테크와 9,500억달러 AI 협력…한국 AI 허브 도약 — 2026-07-27 18:22:57
- 화면 녹화·키 입력·시드 문구까지…‘오코봇’ 가상화폐 사용자 집중 공격 — 2026-07-27 16:16:47
- [이희정 교수 AI 칼럼-15] 기술과 AI: 왜 결국 ‘메모리’인가 — 2026-07-27 09:49:13
- 틱톡, 국내 이용자 945만명 타사 활동정보 무단 활용…과징금 103억원 — 2026-07-27 18:13:02
- [정보보안 연재소설-로그아웃되지 않는 밤] 제11화 ‘낚인 사람들’ — 2026-07-27 09:39:44
- 오픈AI, 이재명 대통령·삼성·SK와 연쇄 회동…한국 AI 인프라 협력 강화 — 2026-07-27 15:54:21
- 넷앤드, Gateway·Agent 결합한 ‘HIWARE UAC’ 출시…우회접속까지 통합 접근통제 — 2026-07-27 11:38:44
- 테라 퀀텀·Apex.AI, 차량·로봇 엣지-클라우드 통신에 양자내성 보안 구현 — 2026-07-27 16:42:03
- 오내피플, 산업부·과기정통부·조달청 ‘혁신 프리미어 1000’ 동시 선정 — 2026-07-27 18:09:21
보안뉴스 > SECURITY
- “익스플로잇 인텔리전스로 AI 위협 방어”… 이테크시스템-벌른체크와 총판 계약 — Mon, 27 Jul 2026 18:23:00 +0900
- 깃랩 RCE 유발한 4년 묵은 Parser 버그… 루비 안전망도 무너졌다 — Mon, 27 Jul 2026 17:29:00 +0900
- 美 국무부, 해외 사이버 사기범 및 가족 대상 비자 제한 조치 시행 — Mon, 27 Jul 2026 16:50:00 +0900
- [한국정보공학기술사 보안을 論하다-44] 스마트팩토리 레거시 시스템의 보안 위기 분석과 방어전략 — Mon, 27 Jul 2026 16:46:00 +0900
- 마명철 포소드 대표이사 “AI 시대, CCTV 영상의 안전을 지켜내겠습니다” — Mon, 27 Jul 2026 16:31:00 +0900
- [해킹을 결제하시겠습니까?] #9. “무료 체험 끝났는데…” 나도 모르게 새 나가는 구독료와 개인정보 막으려면 — Mon, 27 Jul 2026 16:09:00 +0900
- [ISEC 2026 미리보기] 인젠트, 문서중앙화를 통한 N2SF 기반 AI 데이터 보안 및 구축 전략 제시 — Mon, 27 Jul 2026 15:33:00 +0900
- [AI 시대의 인지전-2] 젤렌스키를 사칭한 가짜 항복 영상은 왜 실패했나 — Mon, 27 Jul 2026 14:51:00 +0900
- [ISEC 2026 미리보기] 인스피언, AI 기반 SIEM 플랫폼으로 차세대 보안관제 시장 공략 — Mon, 27 Jul 2026 14:08:00 +0900
- “이메일 열기만 해도 털려”… 러 ‘런드리 베어’ 타깃은 서방 주요국 — Mon, 27 Jul 2026 13:41:00 +0900
Security Feed Digest (2026-07-28)
Hacker News: Best
- OpenAI just open-sourced Codex Security — Tue, 28 Jul 2026 20:52:55 +0000
- Deflock Casa Grande — Tue, 28 Jul 2026 18:41:48 +0000
- Substack writers, you need a website — Tue, 28 Jul 2026 16:58:31 +0000
- A walk through of the DeltaNet family of linear attention variants — Tue, 28 Jul 2026 16:02:07 +0000
- Kimi K3 Architecture Overview and Notes — Tue, 28 Jul 2026 15:48:34 +0000
- Stop Killing the Internet: No Digital ID and No Age Verification — Tue, 28 Jul 2026 14:58:15 +0000
- New HIV vaccine shows unprecedented success in preclinical study — Tue, 28 Jul 2026 13:12:01 +0000
- Kimi Linear: An Expressive, Efficient Attention Architecture (2025) — Tue, 28 Jul 2026 10:52:30 +0000
- 7.1 Earthquake in Japan — Tue, 28 Jul 2026 07:44:24 +0000
- Using an open model feels surprisingly good — Tue, 28 Jul 2026 02:37:14 +0000
- A $500 RL fine-tune of a 9B open model beat frontier models on catalog review — Tue, 28 Jul 2026 02:18:53 +0000
- Netflix employee fired for sharing personal details in retreat trust exercise — Mon, 27 Jul 2026 23:21:37 +0000
- Benchmarking Opus 5 on SlopCodeBench — Mon, 27 Jul 2026 22:37:52 +0000
- A missing underscore sent innocent man to prison for 18 months — Mon, 27 Jul 2026 22:10:15 +0000
- Paged Out #9 [pdf] — Mon, 27 Jul 2026 14:22:34 +0000
- Should you wash your solar panels? — Mon, 27 Jul 2026 13:04:11 +0000
- Removing React.js from the codebase and adapting Htmx for UI interactivity (2023) — Mon, 27 Jul 2026 09:58:50 +0000
BleepingComputer
- CubePilot drone software dev hit by DNS hijacking to intercept traffic — Tue, 28 Jul 2026 17:17:39 -0400
- OpenAI models used Artifactory zero-days to escape to the internet — Tue, 28 Jul 2026 16:37:06 -0400
- CISA shares advice on isolating vital systems during cyberattacks — Tue, 28 Jul 2026 14:41:04 -0400
- vBulletin fixes critical pre-auth RCE flaw with public exploit — Tue, 28 Jul 2026 14:08:50 -0400
- Is Your SSO Protected Against Modern Credential Attacks? — Tue, 28 Jul 2026 10:00:10 -0400
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw — Tue, 28 Jul 2026 08:10:23 -0400
- Data breach at medical billing firm MCBS affects 1.26 million people — Tue, 28 Jul 2026 05:10:03 -0400
Darkreading
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks — Tue, 28 Jul 2026 21:33:23 GMT
- Thousands of Data Center Controllers Open to Takeover — Tue, 28 Jul 2026 21:07:55 GMT
- When AI Agents Escape Sandboxes, Old Security Rules Apply — Tue, 28 Jul 2026 20:27:36 GMT
- Stronger AI Safety Requires Peeking Inside the ‘Black Box’ — Tue, 28 Jul 2026 20:05:32 GMT
- ‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates — Tue, 28 Jul 2026 16:38:48 GMT
- Former Citigroup CISO Blauner on What Makes A Great Security Leader — Tue, 28 Jul 2026 12:30:00 GMT
- AI Agent Drives Espionage Attack on Thai Ministry of Finance — Tue, 28 Jul 2026 01:00:00 GMT
- Agentic Browsers Rewind Web Security by 20 Years — Mon, 27 Jul 2026 21:39:09 GMT
- Why Resetting Passwords No Longer Stops Attackers — Mon, 27 Jul 2026 18:39:50 GMT
The Hacker News
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack — Wed, 29 Jul 2026 00:29:07 +0530
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process — Tue, 28 Jul 2026 20:31:33 +0530
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login — Tue, 28 Jul 2026 20:11:36 +0530
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach — Tue, 28 Jul 2026 19:03:47 +0530
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root — Tue, 28 Jul 2026 18:26:14 +0530
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — Tue, 28 Jul 2026 17:25:20 +0530
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — Tue, 28 Jul 2026 13:41:22 +0530
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit — Tue, 28 Jul 2026 13:34:44 +0530
- Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost — Tue, 28 Jul 2026 11:37:22 +0530
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — Tue, 28 Jul 2026 10:13:53 +0530
데일리시큐 - 최근인기기사
- 호텔 와이파이 접속했는데 계정 탈취…DNS 바꿔 마이크로소프트 365 로그인 가로채 — 2026-07-28 01:04:25
- 중동 정부기관 뚫은 ‘텔레심’…텔레그램에 숨어 명령 받고 추가 악성코드 설치 — 2026-07-28 01:11:48
- 샤이니헌터스, EY 고객 세무자료 탈취 주장…공급망 공격 가능성 제기 — 2026-07-28 01:24:06
- 샤이니헌터스 유출정보 악용한 협박메일 확산…“48시간 내 비트코인 2천달러 보내라” — 2026-07-28 01:32:34
- 금융보안원, 온라인 ‘금융 AI보안 캠퍼스’ 개설…금융권 AI 보안 교육 본격 확대 — 2026-07-28 09:23:21
- 디스포리아 봇넷 확산…20만대 IoT 기기감염·최대 4테라 디도스 공격 — 2026-07-28 13:59:19
- 기업 노린 패스트제이슨 제로데이 공격 확산…금융·의료 집중 타격 — 2026-07-28 13:39:02
- 라온시큐어 화이트해커 23명, 데프콘 CTF 본선 대거 진출 — 2026-07-28 13:14:50
- 엔비디아, 마이크로소프트·시스코 등 37개사와 ‘오픈 시큐어 AI 얼라이언스’ 출범…AI 에이전트 보안 표준 경쟁 본격화 — 2026-07-28 13:29:40
- [인터뷰] 김진수 KISIA 회장 “성과 중심 KISIA로…K-시큐리티 국가전략산업화에 역량 쏟을 것” — 2026-07-28 20:01:11
보안뉴스 > SECURITY
- [부고] 안재천 트루엔 대표 처상 — Wed, 29 Jul 2026 08:15:00 +0900
- OWASP 서울챕터, ‘2026 오픈소스 AI·SW 커뮤니티’ 선정 — Tue, 28 Jul 2026 16:02:00 +0900
- 이지서티, 단말 기반 차세대 AI 방화벽 ‘EZRO-AI FIREWALL’ 출시 — Tue, 28 Jul 2026 16:00:00 +0900
- [ISEC 2026 미리보기] 엑스게이트, 양자·AI 축으로 미래 네트워크 보안 본격 선도 — Tue, 28 Jul 2026 15:28:00 +0900
- [ISEC 20226 미리보기] 싸이터, 선박 전 생애주기 아우르는 해양 사이버보안 솔루션 선보인다 — Tue, 28 Jul 2026 15:24:00 +0900
- [인사] 과학기술정보통신부 — Tue, 28 Jul 2026 15:16:00 +0900
- “너 야동 봤지?”… 샤이니헌터스 사칭, 민망한 영상 유포 협박 — Tue, 28 Jul 2026 14:21:00 +0900
- 금융보안원, 온라인 ‘금융 AI보안 캠퍼스’ 개설 — Tue, 28 Jul 2026 14:05:00 +0900
- 디사일로 LLM 추론 프레임워크 ‘토르’, 국제 FHE 벤치마킹 스위트 등재 — Tue, 28 Jul 2026 13:52:00 +0900
- ‘파수 DSPM’ 지원 확대… 원드라이브·쉐어포인트·아웃룩·슬랙까지 — Tue, 28 Jul 2026 13:21:00 +0900