ㅂ ㅂㄹㄱ
BlogPortfolioAbout
시작하기

카테고리

전체보기
Develop 1
IT Trend 9
Infra 8

인기 태그

#2fa#adsense#ai-policy#ai-regulation#ai-security#anthropic#anycast#audit-log#authentication#authoritative-ns#authz#automation#aws#axios#boringtun

#security-incident

총 2개 게시물

Security
2026-05-18 7분

Mini Shai-Hulud 재림 — SLSA 증명까지 위조한 npm 자가전파 웜

2026년 5월 11일 npm 생태계에 유효한 SLSA Build Level 3 증명서를 단 자가전파 웜이 풀렸다. TanStack 84개 버전을 포함해 @uipath·@mistralai 등이 감염됐고, 탈취한 OIDC 토큰으로 정상 CI/CD 파이프라인을 통째로 하이재킹하는 4단계 체인 공격이다.

#ci-cd#credential-theft#github-actions#infra#malware#mini-shai-hulud#npm#npm-worm#oidc#security-incident#slsa#supply-chain#tanstack#teampcp
Security
2026-04-20 5분

Vercel 보안 침해 분석 — Context.ai OAuth 탈취로 배포 파이프라인까지 뚫렸다

2026년 4월 Vercel 내부 시스템이 침해됐다. 제3자 AI 에이전트 플랫폼 Context.ai의 Google Workspace OAuth 앱이 공격 진입점이 됐고, 공격자는 직원 계정에서 환경 변수·NPM 토큰·GitHub 토큰·배포 파이프라인까지 접근 범위를 단계적으로 확장했다. Vercel은 Mandiant를 투입하고 법 집행기관에 신고했다.

#breach#cicd#context-ai#deployment#environment-variables#github-token#google-workspace#infra#npm-token#oauth#security-incident#shinyhunters#supply-chain#vercel
ㅂ ㅂㄹㄱ

생각과 경험을 기록하는 개인 블로그입니다. 새로운 기술과 디자인에 대해 이야기합니다.

네비게이션

Blog Portfolio About Search 개인정보 처리방침

소셜

© 2026 ㅂㄹㄱ. All rights reserved.