보안 최초 · 갱신
Zyxel 취약점 악용돼 데이터 탈취
보안업체는 WordPress도 함께 악용돼 996개 장비와 1만8,500여 건의 기록이 노출됐다고 전했다.
왜 중요한가
해당 스위치와 WordPress를 운영하는 기관은 업데이트하고 저장 자료의 노출 여부를 점검해야 한다.
TODAY SCORE
47.7/ 100
1위와 19.0점 차이
30초 요약
CISA는 Zyxel GS1900 스위치의 취약점 CVE-2026-7273을 알려진 악용 취약점 목록에 추가했다. 해당 취약점은 패치가 제공된 상태라고 보도됐다.
무슨 일이 있었나
SecurityWeek는 중국 해킹 조직이 취약점을 이용해 정보를 빼냈다고 보도했다. BleepingComputer는 중국어권 공격자가 Zyxel과 WordPress를 악용했다고 전했으며, CISA는 연방기관에 패치를 지시했다.
타임라인
CISA가 Zyxel GS1900 취약점을 알려진 악용 취약점 목록에 추가했다고 보도됐다.
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessCISA가 연방기관에 취약점 패치를 지시했다고 보도됐다.
CISA orders feds to patch Zyxel flaw exploited for data theftSecurityWeek가 공격자의 정보 탈취와 영향 범위를 보도했다.
Recent ZyXEL Switch Vulnerability Exploited by Chinese HackersBleepingComputer가 Zyxel과 WordPress 취약점 악용 및 기록 탈취를 보도했다.
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
출처 5곳 · 기사 64건
- The Hacker NewsKiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
- TechCrunchStill running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix
- Hacker NewsKestra Unauthenticated Remote Code Execution CVE-2026-49869
- Hacker NewsMCP Python SDK OAuth flaw enabled account takeover
- BleepingComputerKiteworks patches critical flaw, brings customer systems online
- BleepingComputerApple patches CoreGraphics zero-day flaw exploited in attacks
- Hacker NewsCVE-2026-85706 (CVSS 10.0)
- SecurityWeekApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
- The Hacker NewsOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
- Hacker NewsTaking 'execute logging' a bit too literally CVE-2026-88771
- The Hacker NewsApple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- Hacker NewsElastic Agentic SOC Vulnerable to Credential Theft
- Hacker NewsActive, in-the-wild exploitation of CVE-2026-88771 with IoCs
- The RecordUS, UK warn of exploited Citrix NetScaler zero-day bugs
- Hacker NewsCitrix NetScaler PreAuth Command Injection CVE-2026-88771
- Hacker NewsOne resident login, an entire apartment complex: CVE-2026-75960
- SecurityWeekKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
- Hacker NewsI found an SSRF in Google's official MCP Toolbox (CVE-2026-14540)
- SecurityWeekCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
- The Hacker NewsCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- BleepingComputerCISA orders feds to patch exploited Citrix flaws by Wednesday
- Hacker NewsCitrix NetScaler Remote Code Execution
- BleepingComputerCitrix confirms two NetScaler RCE zero-days exploited in attacks
- SecurityWeekMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
- The Hacker NewsWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Hacker NewsSix Bazel patches from an AI software factory, plus a remote-cache security bug
- The Hacker NewsAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- The Hacker NewsSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- BleepingComputerCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
- Hacker NewsSomeone's attacking a critical 0-day RCE in F5 BIG-IP APM
- Hacker NewsImminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers
- Hacker NewsThe "FREAK" TLS/SSL flaw, and related thoughts
- SecurityWeek‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
- Hacker NewsCVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
- The Hacker NewsWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- Hacker NewsVulnerability Cve-2026-82958
- Hacker NewsDecades-old file security flaws found in Android, Linux, macOS, and Windows
- Hacker NewsCISA active Linux kernel CVEs (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
- BleepingComputerHackers now exploit critical Roundcube flaw in code injection attacks
- BleepingComputerCISA: Ransomware gangs now exploiting critical TeamCity flaw
- SecurityWeekSolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
- Hacker NewsHackers Actively Exploit Check Point VPN Flaw
- BleepingComputerCheck Point warns of hackers exploiting Security Gateway VPN RCE flaw
- The Hacker NewsMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
- BleepingComputerInfraTrust report warns network management systems under attack
- Hacker NewsLatest BGP hijack targets hosting software vendor
- BleepingComputerArista patches actively exploited VeloCloud Orchestrator zero-day
- SecurityWeekAdobe Patches Critical Flaws in Connect, AEM Forms
- SecurityWeekArista Urges Immediate Patching of Exploited VCO Zero-Day
- The Hacker NewsF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- The Hacker NewsChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- SecurityWeekCritical F5 BIG-IP Vulnerability Exploited as Zero-Day
- BleepingComputerF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
- SecurityWeekCheck Point Patches Exploited Management Server Zero-Day
- BleepingComputerChinese hackers exploit WordPress, Zyxel flaws to steal govt data
- The Hacker NewsCheck Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
- The Hacker NewsCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
- BleepingComputerCheck Point warns of Management Server zero-day exploited in attacks
- BleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routers
- The Hacker NewsNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
- SecurityWeekRecent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
- BleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theft
- The Hacker NewsZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
- BleepingComputerCISA alerts of active exploitation of three Linux kernel flaws