Eyeon Security Information security company

보안 동향

㈜아이온시큐리티에서 서비스 이용 고객님들의 안정적인 시스템 운영을 위해
필수적인 주요 보안 조치 사항을 안내해드립니다.

넷앱, 가트너 엔터프라이즈 스토리지 매직 쿼드런트 리더 선정 관리자 2026-08-28 00:51:03
넷앱, 가트너 엔터프라이즈 스토리지 매직 쿼드런트 리더 선정
관리자  2026-08-28 00:51:03
보안 동향 브리핑
SECURITY
DAILY REPORT
Eyeon Security

생성일시: 2026-08-28 00:40

보안뉴스 (신규 5건)
넷앱, 가트너 엔터프라이즈 스토리지 매직 쿼드런트 리더 선정
수집일: 2026-08-28
넷앱이 2026 가트너 엔터프라이즈 스토리지 플랫폼 매직 쿼드런트에서 리더로 선정됐다. 해당 보고서가 처음 발간된 2025년에 이어 연속으로 이 시장의 리더로 인정받았다.이번 평가는 비전 완성도와 실행 능력을 분석하는 기준을 바탕으로 이뤄졌다. 이와 함께 발표된 2026 가트너 엔터프라이즈 스토리지 플랫폼 크리티컬 캐퍼빌리티 보고서에서 넷앱은 하이브리드 클
원문 바로가기 →
태니엄, 차세대 에이전틱 AI 시스템 ‘태니엄 아틀라스’ 공개
수집일: 2026-08-28
태니엄이 연례 컨퍼런스인 컨버지 서울에서 차세대 에이전틱 AI 시스템인 '태니엄 아틀라스'의 강화된 기능을 공개했다.이번에 선보인 태니엄 아틀라스는 태니엄 플랫폼에 기본 탑재되는 네이티브 에이전틱 AI 시스템으로 실시간 엔드포인트 데이터를 기반으로 IT와 보안 환경의 위험을 분석하고 우선순위를 정한 뒤 운영자 승인을 거쳐 실행과 연결한다.오늘날 IT 및 보
원문 바로가기 →
KISA-한국교통안전공단, 자동차 사이버보안 강화 위한 업무협약 체결
수집일: 2026-08-28
한국인터넷진흥원(KISA)이 한국교통안전공단(TS)과 함께 자동차 사이버보안 강화를 위한 업무협약을 경기 화성 자동차안전연구원에서 체결했다.최근 자동차가 소프트웨어와 통신망을 품은 커넥티드 카나 자율주행차로 진화하면서 보안 위협이 커지는 상황에 선제적으로 대응하기 위한 조치다.두 기관은 이번 협약을 통해 정보보호와 자동차 안전 분야의 전문성을 결합한다. 앞
원문 바로가기 →
김현준 한국사회보장정보원장, 지역주민 대상 개인정보 보호 캠페인 펼쳐
수집일: 2026-08-28
한국사회보장정보원은 8월 26일(수) 서울 광진구 보건복지행정타운 무더위쉼터를 찾아 지역주민을 대상으로 개인정보 보호 문화 확산 캠페인을 진행했다.이번 행사는 스마트폰과 디지털 기기 사용이 늘어나면서 스미싱과 개인정보 유출 피해가 증가함에 따라, 주민들이 일상에서 정보를 안전하게 지키도록 돕기 위해 마련됐다.김현준 한국사회보장정보원장이 직접 현장을 방문해
원문 바로가기 →
코오롱베니트, 양자컴퓨팅 해커톤 Quantum Reframing Challenge 2026 참여
수집일: 2026-08-28
코오롱베니트가 한국과학기술정보연구원(KISTI)과 메가존클라우드가 공동 주최·주관한 양자컴퓨팅 해커톤 Quantum Reframing Challenge 2026에 후원사로 참여했다.이번 행사는 과학기술정보통신부가 주무부처, 한국연구재단이 전문기관으로 참여하는 정부 R&D 사업인 양자컴퓨팅 서비스 및 활용체계 구축의 일환으로 열렸다. 본선과 시상식은
원문 바로가기 →
KISA 보안공지 (신규 2건)
Gitea 제품 보안 업데이트 권고
수집일: 2026-08-28

□ 개요
o Gitea에서 발생하는 취약점을 해결한 보안 업데이트 발표 [1]
o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 설명
o Gitea에서 발생하는 Code Injection 취약점(CVE-2026-60004) [1][2]

□ 영향을 받는 제품 및 해결 방안

취약점 제품명 영향받는 버전 해결 버전
CVE-2026-60004 Gitea 1.17 이상 1.27.1 미만 1.27.1 이상

※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1]

□ 참고사이트
[1] https://blog.gitea.com/release-of-1.27.1/
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60004

□ 문의사항
o 한국인터넷진흥원 사이버민원센터 : 국번없이 118

□ 작성 : 디지털위협대응본부 취약점관리센터

원문 바로가기 →
美 CISA 발표 주요 Exploit 정보공유(Update. 2026-08-26)
수집일: 2026-08-28

□ 개요
o 美 CISA에서 현재 자주 악용되고 있는 취약점 목록 발표 [1]
o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 영향을 받는 제품

CVE제조사취약점내용조치사항
CVE-2019-1068MicrosoftMicrosoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-8452CitrixCitrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2022-0995LinuxLinux Kernel Out-of-Bounds Write VulnerabilityLinux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2015-5287Red HatRed Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityRed Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2015-3246Red HatRed Hat Libuser Race Condition VulnerabilityRed Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2021-23758Ajax.NET ProfessionalAjax.NET Professional Deserialization of Untrusted Data VulnerabilityAjax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

※ 하단의 참고 사이트를 확인하여 업데이트 수행 [1]

□ 참고사이트
[1] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

□ 작성 : 디지털위협대응본부 취약점관리센터

원문 바로가기 →
본 메일은 시스템에 의해 자동으로 수집 및 발송된 보안 동향 모니터링 리포트입니다.

첨부 파일 :