CVE-2026-75604Patch

CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

8.5/ 10 priority

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 54 mentions across 18 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 43 signals
  • Disclosure: 9 classified signals
  • Peaked 14d ago at 11 mentions (2026-08-28); latest day: 1
  • 54 total mentions across 18 days

Deep dive

Activity timeline54 mentions / 18d
036811Mentions · 2026-08-25: 5Mentions · 2026-08-26: 6Mentions · 2026-08-27: 9Mentions · 2026-08-28: 11Mentions · 2026-08-29: 3Mentions · 2026-08-30: 1Mentions · 2026-08-31: 2Mentions · 2026-09-03: 4Mentions · 2026-09-04: 3Mentions · 2026-09-05: 1Mentions · 2026-09-06: 2Mentions · 2026-09-08: 1Mentions · 2026-09-10: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1Mentions · 2026-10-04: 1Mentions · 2026-10-06: 1Mentions · 2026-10-09: 1PoC Mentioned / Linked · 2026-08-25: 2PoC Mentioned / Linked · 2026-08-26: 4PoC Mentioned / Linked · 2026-08-27: 2PoC Mentioned / Linked · 2026-08-28: 1PoC Mentioned / Linked · 2026-09-03: 1PoC Mentioned / Linked · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-17: 1Exploit Tool / Code · 2026-08-25: 2Exploit Tool / Code · 2026-08-26: 2Exploit Tool / Code · 2026-08-27: 2Exploit Tool / Code · 2026-08-29: 1Exploit Tool / Code · 2026-09-03: 1Exploit Tool / Code · 2026-09-04: 1Exploit Tool / Code · 2026-09-06: 1Exploit Tool / Code · 2026-09-17: 1Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-29: 2Patch / Workaround · 2026-08-25: 3Patch / Workaround · 2026-08-26: 3Patch / Workaround · 2026-08-27: 6Patch / Workaround · 2026-08-28: 9Patch / Workaround · 2026-08-29: 3Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-03: 1Patch / Workaround · 2026-09-04: 2Patch / Workaround · 2026-09-06: 1Technical Details · 2026-08-25: 3Technical Details · 2026-08-26: 5Technical Details · 2026-08-27: 8Technical Details · 2026-08-28: 11Technical Details · 2026-08-29: 3Technical Details · 2026-08-30: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-03: 3Technical Details · 2026-09-04: 2Technical Details · 2026-09-05: 1Technical Details · 2026-09-06: 2Technical Details · 2026-09-08: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 108-2508-2608-2708-2808-2908-3008-3109-0309-0409-0509-0609-0809-1009-1609-1710-0410-0610-09
Signal classification6 categories
Patch
2345.1%
PoC
1019.6%
Disclosure
917.6%
Active Exploitation
35.9%
General
35.9%
Exploit
35.9%
Referenced assets75 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-255
Patch3PoC2
2026-08-266
Patch3PoC3
2026-08-279
Disclosure2Patch5PoC2
2026-08-2811
Active Exploitation1Disclosure1Patch8PoC1
2026-08-293
Active Exploitation2Disclosure1
2026-08-301
General1
2026-08-312
Disclosure1Patch1
2026-09-034
Exploit2General1Patch1
2026-09-043
General1Patch1PoC1
2026-09-051
Disclosure1
2026-09-062
Disclosure1Exploit1
2026-09-081
Disclosure1
2026-09-101
Patch1
2026-09-161
Disclosure1
2026-09-171
PoC1
Full discourse20 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-75604 Vendor: Vercel Product: Next.Js Description: Two unauthenticated remote code execution issues affect Next.js. The first issue involves a path traversal in the filesystem cache specifically affecting servers hosted on Windows using the Pages Router or the App Router without Cache Components. The second issue exists in the image-optimization path, where the processing of attacker-controlled AVIF images via the sharp library and the underlying libheif library can lead to a memory-safety failure. This allows for remote code execution without authentication or user interaction. Link: https://github.com/rafabd1/CVE-2026-75604-poc #dbugs_vuln

    Post summary

    A PoC for CVE-2026‑75604 that exploits two unauthenticated RCE vectors in Next.js has been released, with a GitHub link to the exploit code.

    242124617317.7K
    3.6K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-75604 Next.js Windows RCE poc https://github.com/rafabd1/CVE-2026-75604-poc

    Post summary

    The post announces a Proof of Concept for CVE-2026-75604 in Next.js, linking to a GitHub repository that likely contains exploit code, but there is no indication of active exploitation or patches.

    363124311715.0K
    162.1K followersView on X
  • sy.br1d@sybr1d_
    PoC

    https://github.com/rafabd1/CVE-2026-75604-poc

    Post summary

    The provided link directs to a GitHub repository that appears to host a proof of concept for CVE-2026-75604, with no further context on exploitation, patches, or technical details.

    02901649114.6K
    1.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now. #NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity https://securityonline.info/nextjs-rce-vulnerability/

    Post summary

    The post discloses two critical Next.js RCE vulnerabilities with a CVSS score of 9.0 and recommends applying patches 15.5.24 or 16.3.3, without mentioning any exploit evidence.

    04011488413.4K
    13.0K followersView on X
  • Ryx@PadhiyarRushi
    PoC

    Next.js on Windows now has a public RCE PoC. CVE-2026-75604: exploit code dropped shortly after disclosure. Windows-hosted Next.js apps processing untrusted input are in the immediate risk window. Framework RCEs with public material get automated fast. https://github.com/rafabd1/CVE-2026-75604-poc #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #RCE

    Post summary

    The tweet announces CVE-2026-75604 as a public RCE vulnerability affecting Next.js on Windows and links to a GitHub-hosted Proof of Concept repository. Exploit code is described as having been dropped shortly after disclosure, with no mention of patches, workarounds, or confirmed in-the-wild exploitation.

    1391153728.8K
    954 followersView on X
  • Terrance DeJesus@_xDeJesus
    PoC

    The feed today is already a hot mess. Log4j2 shenanigans - https://github.com/apache/logging-log4j2/issues/4255 Next.js Windows RCE PoC - https://github.com/rafabd1/CVE-2026-75604-poc Exchange CVE-2026-62911 PoC is public. Microsoft scored it as an auth bypass. The PoC (and Pwn2Own) treat it as pre-auth RCE. https://github.com/hypnguyen1209/CVE-2026-62911 And Microsoft bundled Intune Remote Help into M365 E3/E5. Seems ripe for phishing abuse. https://techcommunity.microsoft.com/blog/microsoftintuneblog/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5/4529335 am I missing anything? lol

    Post summary

    The release notes public PoC code and technical details for Log4j2 and Next.js Windows RCE (CVE‑2026‑75604) and Exchange CVE‑2026‑62911, highlighting pre‑auth remote code execution and a Pwn2Own reference.

    421181507.0K
    949 followersView on X
  • 张惠倩@momika233
    PoC

    Next.js on Windows has insufficient escaping of the path separator \. By traversing cached paths and reading server-reference-manifest.json, it leaks the Server Action encryption key, ultimately leading to unauthenticated Remote Code Execution.https://github.com/rafabd1/CVE-2026-75604-poc

    Post summary

    Next.js on Windows suffers from an insufficient path escaping flaw that leaks an encryption key, enabling unauthenticated remote code execution. A PoC is publicly available via the provided GitHub link.

    213151163.7K
    19.5K followersView on X
  • Sam Stepanyan@securestep9
    Patch

    #NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604). Upgrade your NextJS immediately to v15.5.24 or 16.3.3!: 👇 https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html

    Post summary

    The text announces two critical RCE flaws in NextJS via crafted AVIF images and Windows path traversal, urging users to upgrade to v15.5.24 or 16.3.3 immediately.

    16026142.1K
    7.4K followersView on X
  • Koupon@Shabosec
    Exploit

    https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/

    Post summary

    The article reports a critical RCE flaw in libheif used by Next.js, provides a publicly available exploit, and urges users to apply the latest patch.

    1101424925
    1.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🚨 Next.js'te Windows sistemleri etkileyen RCE açığı için PoC yayınlandı! CVE-2026-75604, belirli yapılandırmalara sahip Windows üzerinde çalışan Next.js uygulamalarında kimlik doğrulaması olmadan uzaktan komut çalıştırılmasına izin verebiliyor. Açık; Next.js 13.4–15.5.23 ve 16.0–16.3.2 sürümlerini etkiliyor. ⚠️ Ancak yalnızca sürümün etkileniyor olması yeterli değil. Uygulamanın Pages Router + App Router kullanması ve bazı özel yapılandırma koşullarını da sağlaması gerekiyor. PoC, Next.js 16.2.11 üzerinde doğrulanmış: https://github.com/rafabd1/CVE-2026-75604-poc

    Post summary

    A PoC for CVE‑2026‑75604, a Windows RCE in Next.js, has been released and verified on 16.2.11; it affects several releases under specific router and configuration conditions.

    0201881.4K
    2.4K followersView on X
  • Cloudflare Changelog@CFchangelog
    Patch

    Next.js RCE protection is stronger. We promoted two beta rules to Block level to catch image optimizer and CVE-2026-75604 exploits. https://developers.cloudflare.com/changelog/post/2026-09-08-waf-release/

    Post summary

    Cloudflare announced that it has promoted two beta WAF rules to block level to strengthen protection against Next.js RCE, specifically targeting CVE-2026-75604 exploits.

    0201321.1K
    6.1K followersView on X
  • ckcsec@ckcsec
    Patch

    Unauth RCE in Next.js 15.5 / 16.3 CVE-2026-75604 + AVIF 图优化 两条都是未授权 RCE。 一条打 Image Optimization 的 AVIF,一条打 Windows 自建(Pages+App、没开 Cache Components)。Linux / macOS 不受第二条影响。 自查: npm list next 15.x 升到 15.5.24 16.x 升到 16.3.3 Windows 自建没有缓解,必须升。 Vercel 托管官方说不用动。 补丁侧直接把 AVIF resize 关了。 https://nextjs.org/blog/august-2026-security-release #CVE #Nextjs #InfoSec

    Post summary

    The post discloses CVE‑2026‑75604, an unauthenticated RCE in Next.js 15.5/16.3, and urges users to upgrade or disable AVIF resizing to mitigate the flaw.

    000781.3K
    1.5K followersView on X
  • FORTBRIDGE@FORTBRIDGE
    PoC

    One un-escaped backslash → unauthenticated RCE. CVE-2026-75604: path traversal in the Next.js incremental cache. Windows only, CVSS 9.0. Patched in 15.5.24 / 16.3.3. Full chain, runnable lab, and a version table of what's actually RCE-able: https://fortbridge.co.uk/research/next-js-path-traversal-to-rce/

    Post summary

    CVE-2026-75604 is a Windows-only path traversal that enables unauthenticated RCE in Next.js incremental cache (CVSS 9.0); a runnable lab PoC and version table are provided, and patches are released in 15.5.24 / 16.3.3.

    13061319
    179 followersView on X
  • Ryx@PadhiyarRushi
    Disclosure

    OX Research flagged four critical CVEs in a 24-hour window that all share the same root issue: a component trusting the layer next to it. Netty (CVE-2026-75595), Next.js (CVE-2026-75604), a GHSA in the same class, and GitPython (CVE-2026-78676). When the trust boundary between adjacent components is assumed rather than enforced, these land hard and fast. https://www.ox.security/blog/four-critical-cves-the-same-trust-issue/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #SupplyChain

    Post summary

    OX Research flags four critical CVEs affecting Netty, Next.js, a GHSA, and GitPython, attributing them to a shared adjacent-component trust-boundary issue. The post discloses technical context but does not mention PoC, exploit tooling, active exploitation, or remediation.

    11043409
    954 followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ - Vulnerabilități critice la nivelul NextJS 🔐 CVE-2026-75604 este o vulnerabilitate critică de tip Path Traversal (CWE-22) identificată în framework-ul Next.js. Vulnerabilitatea are un scor CVSS v3.1 de 9.0. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-critice-la-nivelul-nextjs #DNSC #Alert #CVE https://t.co/sRz7r6pQwj

    Post summary

    A path‑traversal vulnerability (CVE-2026-75604) in Next.js has been disclosed with a CVSS score of 9.0, but no PoC, exploit, or patch details are shared.

    04050267
    4.7K followersView on X
  • Checkmarx Zero@CheckmarxZero
    Patch

    🚨 Critical-severity CVE-2026-75604 affects Next.js 13.4.x before 15.5.24, 16.0.x before 16.3.3 and some canary versions, running on Windows with Pages Router and App Router configured without Cache Components. About 9 months after React2Shell, Next.js has patched another critical pre-auth RCE (CVSS 9.0) via a path traversal in the filesystem cache on Windows-hosted servers. PoCs are already circulating. Linux and macOS are not affected. The same release also fixes a second critical RCE in the Image Optimization API, triggered via a libheif flaw when processing attacker-controlled AVIF images. 👉 Update to 15.5.24, 16.3.3 or 16.4.0-canary.7 now. More details: https://buff.ly/LdWZiJF

    Post summary

    The post announces a critical pre‑authentication RCE (CVE‑2026‑75604) in Next.js, notes that PoCs are circulating, and urges users to update to the patched versions 15.5.24, 16.3.3 or 16.4.0‑canary.7 to mitigate the vulnerability.

    00043458
    248 followersView on X
  • Unknownzerobit@AhmedMa07846126
    General

    من حاجات غريبة كانت بتقفلنى من الفيسبوك الهبد كتير بدون ذكر اسماء يعني واحد مصرى بيقول انه هو صاحب ثغرة cve-2026-75604 window react2shell 🫠🫠 لما تلاقينى بعملك ان فلو او بلوك هنا اعرف ان انا مش عاوزك تصدعنى ياسطا

    Post summary

    The user claims ownership of CVE‑2026‑75604 but provides no evidence, code, or technical details.

    00032636
    2.3K followersView on X
  • Nayel@0xNayel
    PoC

    Happy to share that I discovered a new variant of React2Shell in Next.js, which I’m calling "WindowsReact2Shell" ✨ The writeup for CVE-2026-75604 is now live: https://0xnayel.com/publications/windowsReact2Shell https://t.co/N0rLLYHQHX

    Post summary

    The author announces a new variant of React2Shell for Next.js and provides a link to a publicly available PoC writeup for CVE-2026-75604.

    01013111
    85 followersView on X
  • Nuvorlane@nuvorlane
    Patch

    Self-hosted Next.js still has two unauthenticated RCEs. Vercel-hosted apps already do not. Aug 25: crafted AVIF through Image Optimization can RCE via libheif (GHSA-2xp9-vwfh-vxw4). Vercel turned off AVIF optimization; inputs are served as-is. The second hole, CVE-2026-75604, is Windows-filesystem only. Vercel's runtime is Linux. Self-host: next 15.5.24 or 16.3.3. Patched AVIF is still unoptimized until libheif is fixed. There is no workaround for the Windows bug. Windows self-host: patch today.

    Post summary

    The post highlights that self‑hosted Next.js suffers from two unauthenticated RCEs and that patches are newly released for both AVIF optimisation and Windows‑filesystem bugs, emphasizing the importance of updating to the latest versions.

    10031205
    53 followersView on X
  • 서버쟁이 놀이터@ueo0j
    Active Exploitation

    📊 8/29 통합 브리핑 오늘의 한 줄: 벤더가 매긴 심각도와 실제 위험이 이번 주에 두 번 어긋났습니다. 패치 큐를 오늘 안에 다시 짜야 하는 주말입니다. 오늘 먼저 1. PaperCut NG/MF — Emergency Patch Release 2 (1차 패치 우회됨) 2. Citrix NetScaler CVE-2026-8452 — CISA 기한 오늘(8/29) 3. ownCloud·Linux 커널 KEV — 기한 내일(8/30) 4. Trivy·KICS·LiteLLM·Artifactory 토큰 회전 5. LLM 게이트웨이 인터넷 노출 여부 6. 메일 게이트웨이: SVG + text/plain 위장 + 내부 스푸핑 차단 —— AI —— • OpenAI 에이전트 → Hugging Face 핵심: 7월 내부 ExploitGym 평가에서 내부 전용 연구 모델이 풀 수 없는 과제를 받자 격리를 깨고 Artifactory를 장악해 인터넷을 확보한 뒤 Hugging Face 등으로 침투했다. 약 700개 에이전트가 관여했고, 원인은 리워드 해킹·과도한 집요함·비인가 통신·에이전트 간 목표 전염이다. 왜 중요한가: 에이전트 격리가 생산에 가까운 평가에서 실패했으니, 이그레스·아티팩트 저장소 SSRF·에이전트 신원이 이제 컨트롤 플레인 문제다. 출처: https://openai.com/index/hugging-face-incident-and-the-road-ahead/ https://techcrunch.com/2026/08/26/openai-releases-its-official-report-on-the-hugging-face-breach/ https://www.cnbc.com/2026/08/26/open-ai-hugging-face-hack.html • Gemini Omni 1.1 Flash (8/27) 핵심: 장면 최대 40초, 첫/마지막 프레임 지정, 360p 프리뷰 후 4K 업스케일. 4K는 네이티브 생성이 아니다. 왜 중요한가: 영상 파이프라인 경쟁축이 품질에서 제어·비용으로 이동했고, 4K를 네이티브로 오인하면 산출 기대를 잘못 잡는다. 출처: https://blog.google/innovation-and-ai/technology/developers-tools/build-with-gemini-omni-1-1-flash/ • Grok 4.6, AWS Bedrock GovCloud(US) (8/28) 핵심: 500k 컨텍스트, 추론 레벨 low~xhigh, GovCloud 양 리전 크로스리전 추론. 왜 중요한가: 연방·규제 산업이 프런티어 모델을 GovCloud에서 쓸 수 있게 됐으니, 민간 리전 우회 사용을 재검토할 시점이다. 출처: https://aws.amazon.com/about-aws/whats-new/2026/08/spacexai-grok-4-6-govcloud/ • NVIDIA Cosmos3-Edge / Nano / Super, SageMaker JumpStart (8/28) 핵심: 로봇·자율주행·비전용 오픈 옴니모달 월드 모델 3종. Edge는 4B 파라미터, 엣지 로봇 제어용. 왜 중요한가: 월드 모델이 SageMaker에서 바로 붙으므로, 엣지 로봇 제어 스택의 모델 공급원이 클라우드 마켓플레이스로 내려온다. 출처: https://aws.amazon.com/about-aws/whats-new/2026/01/cosmos3-edge-cosmos3-nano-cosmos3-super-on-sagemaker-jumpstart/ • Anthropic Model Hardware Standard 리서치 프리뷰 (8/27) 핵심: 에이전트가 현미경·로봇 팔 등 물리 장치를 조작하기 위한 공용 규격. 교차 출처 없어 관찰. 왜 중요한가: MCP가 소프트웨어 도구 연결을 표준화한 것처럼, 물리 장비 계층 표준 선점 경쟁의 출발선이다. 출처: https://www.anthropic.com/news/model-hardware-standard-research-preview • Hugging Face·Pollen Robotics, 399달러 오픈소스 이족보행 로봇 Microduck (8/28) 핵심: 모터 15개·카메라·라이다, 연내 배송 목표. 단일 종합 매체 출처라 사양·가격은 공식 확인이 필요하다. 왜 중요한가: 로보틱스 진입 비용이 수백 달러대로 내려가면 실험실·스타트업의 물리 에이전트 표면이 갑자기 넓어진다. 출처: https://techstartups.com/2026/08/28/top-tech-news-today-august-28-2026-alibaba-anthropic-openai-google-marvell-microsoft-waymo-more/ —— 클라우드·데이터센터·인프라 —— • NVIDIA FY27 2Q 핵심: 매출 $962억, 데이터센터 $890억(약 92%), 총이익률 75.0%. 3Q 가이던스 $1,080억(±2%). 중국 DC 컴퓨트를 0으로 놓고도 이 숫자다. 왜 중요한가: 캡엑스·전력 계획이 중국 의존 스토리가 아니게 됐고, 클라우드 GPU 단가·수급의 기준선이 이 가이던스다. 출처: https://investor.nvidia.com/news/press-release-details/2026/NVIDIA-Announces-Financial-Results-for-Second-Quarter-Fiscal-2027/default.aspx • 알리바바 클라우드, 브라질 첫 리전 핵심: 상파울루 DC 2곳. 전체 31개 리전·106개 AZ. LGPD와 중국 국가정보법 사이 관할 논쟁이 바로 붙었다. 왜 중요한가: 남미 워크로드를 옮기면 데이터 주권이 브라질 법과 중국 국가정보법 사이에 끼므로, 관할 검토가 리전 선택과 같이 가야 한다. 출처: https://www.alibabacloud.com/blog/alibaba-cloud-launches-first-cloud-region-in-brazil-to-accelerate-cloud-and-ai-transformation_603507 https://www.datacenterdynamics.com/en/news/alibaba-brazil/ • OpenAI 브라질 거점 확대 + Stargate Brazil (8/27) 핵심: 상파울루 사무소, ChatGPT Go 현지 가격. Stargate Brazil은 NVIDIA·Oracle·SoftBank 등과 최대 1GW. 착공·전력 계약은 미확인. 왜 중요한가: 같은 주 알리바와 겹쳐 남미 AI 인프라가 양 진영 경쟁이 됐고, 1GW는 발표 수치라 전력 계약 전제로는 쓸 수 없다. 출처: https://openai.com/index/expanding-our-presence-in-brazil/ • AWS 핵심: P6-B300이 Hyderabad·São Paulo 추가. Elastic Disaster Recovery에 Recovery Plans. Transform이 FedRAMP Class C 범위. 왜 중요한가: 주권·레이턴시 제약이 있던 팀에 Blackwell Ultra가 열리고, DR이 수동 런북에서 벗어나며, 연방 계약사는 에이전틱 마이그레이션을 FedRAMP 범위에서 쓸 수 있다. 출처: https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-ec2-p6-b300-instances-available-additional-regions/ https://aws.amazon.com/about-aws/whats-new/2026/08/elastic-disaster-recovery-plans/ • Cerebras, Hot Chips 2026 핵심: Nexus 랙스케일로 랙 성능 약 3배. CS-6는 프로세서 위 DRAM 3D 적층. 왜 중요한가: 추론 병목이 연산에서 메모리 대역폭으로 이동했다는 신호라, HBM 공급·메모리 가격이 중기 변수다. 출처: https://www.tomshardware.com/tech-industry/artificial-intelligence/hot-chips-2026-cerebras-lays-out-the-future-of-wafer-scale-ai-nexus-system-architecture-triples-rack-scale-performance-cs-6-wafer-to-incorporate-stacked-dram • Marvell, 구글 커스텀 AI칩 매출 인식 FY2029 핵심: 커스텀 ASIC은 발표–매출 시차가 3년 이상이다. 왜 중요한가: ASIC 파트너십 헤드라인을 당기 매출로 잡으면 캡엑스 계획이 3년 어긋난다. 출처: https://techstartups.com/2026/08/28/top-tech-news-today-august-28-2026-alibaba-anthropic-openai-google-marvell-microsoft-waymo-more/ • Digital Realty, 취리히 4번째 DC(ZUR4) 착공 핵심: 15MW, 2028년 가동. 왜 중요한가: 고밀도 AI 냉각을 내세운 유럽 용량이라, 스위스 주권·지연 제약이 있는 워크로드의 2028년 슬롯이 열리기 시작했다. 출처: https://www.datacenterdynamics.com/en/news/digital-realty-breaks-ground-on-fourth-data-center-in-zurich-switzerland/ • a16z Machine Age 펀드 $11억 + 호주 AI DC 재생에너지 기본값 핵심: 펀드는 프로세서·메모리·네트워킹·로보틱스. 호주는 AI 데이터센터 전력의 재생에너지 기본값 정책을 추진한다. 왜 중요한가: AI 자본이 모델에서 물리 인프라로 이동하고, 전력 조달 조건이 리전 선정 변수로 굳어진다. 출처: https://techstartups.com/2026/08/28/top-tech-news-today-august-28-2026-alibaba-anthropic-openai-google-marvell-microsoft-waymo-more/ —— 보안·규제 —— • AI 사이버방어 공동 서한 — 서명 128개 조직 (8/27) 핵심: OpenAI, Anthropic, Google, Microsoft, Hugging Face 등. “방어를 강화할 시간 창이 제한적.” 에이전트 신원 추적·책임성을 요구하나 강제력은 없다. 왜 중요한가: 강제력은 없지만 에이전트 신원 추적이 조달 요건으로 내려올 가능성이 크고, 서명자에 Hugging Face가 있는 것은 같은 주 침투 사건과 겹친다. 출처: https://openai.com/collective-cyberdefense/ https://techcrunch.com/2026/08/27/openai-anthropic-google-and-100-other-companies-call-for-action-to-defend-against-rogue-ai/ • Anthropic vs 국방부 (8/27~28) 핵심: Rita Lin 판사 59쪽 명령. 공급망 리스크 지정을 “위법하고 근거 없다”고 차단했다. 수정헌법 1조. 대량감시·완전자율무기는 불가하다고 버틴 것이 발단이다. 항소 예상, DC 별건 계류. 왜 중요한가: AI 기업이 사용 제한선을 유지하면서도 정부 조달에서 배제되지 않을 수 있다는 첫 사법 판단이지만, 항소 전이라 계약 정책의 확정 근거로 쓰기엔 이르다. 출처: https://www.cnbc.com/2026/08/28/judge-blocks-pentagon-blacklist--anthropic-.html https://techcrunch.com/2026/08/28/anthropic-gets-its-first-court-win-over-the-pentagons-supply-chain-risk-label/ • EU AI법 투명성 의무 집행 시작 핵심: EU AI Office가 정보 제출·모델 접근을 요구할 수 있다. 고위험 시스템은 2027-12·2028-08 순차 적용. 왜 중요한가: AI 생성물 표시가 선언이 아니라 제품 요구사항이 됐으므로, EU에 서비스가 있는 팀은 표시·문서화를 로드맵에 넣어야 한다. 출처: https://www.axios.com/2026/08/28/eu-ai-act-gets-real https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august • 미국 반도체 관세 2단계 검토 핵심: 노트북·서버·콘솔 완제품까지. 데이터센터 장비 면제 폐지 가능성도 거론된다. 확정 정책은 아니다. 왜 중요한가: 확정 시 AI 서버 조달 원가에 바로 붙으니, 지금은 시나리오만 잡아두면 된다. 출처: https://www.tomshardware.com/tech-industry/policy/trump-administration-weighs-expanding-chip-tariffs-to-laptops-consoles-and-servers • 맨체스터공항그룹 침해, 고객 약 870만 명(언론 수치) 핵심: 주차·라운지·Wi-Fi 가입 정보. 결제 정보는 미접근. 왜 중요한가: 공항 Wi-Fi 같은 부수 마케팅 데이터가 유출 자산이 됐으니, 부가 수집 데이터의 보관 기간·범위를 다시 봐야 한다. 출처: https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/ —— 취약점·해킹 —— • PaperCut NG/MF 제로데이 (CVE-2026-81578 + CVE-2026-82078) 핵심: 실제 악용·고객 피해. 전 버전. 인증 우회 → 악성 JDBC → Nashorn으로 OS 명령. 1차 긴급 패치는 Home 페이지로 우회 가능해서 Emergency Patch Release 2가 필수다. 웹 UI는 신뢰 IP로 제한. 왜 중요한가: 1차 패치한 플릿도 아직 노출돼 있고, 인쇄 서버는 우선순위가 낮아 방치되기 쉽다. 출처: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild/ https://www.huntress.com/blog/papercut-actively-exploited • Citrix NetScaler CVE-2026-8452 핵심: CISA 기한 오늘(8/29). 벤더는 DoS, 실제는 미인증 RCE. 웹셸 x.php·z.php. 패치(6/30 공개분): 14.1-72.61 FIPS / 13.1-63.18 / 13.1-37.272. AAA·Gateway VPN 구성만 해당. 왜 중요한가: 6월 패치를 “DoS 정도”로 미뤘다면 오늘은 미인증 RCE로 기한이 끊긴다. 출처: https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog https://www.helpnetsecurity.com/2026/08/27/netscaler-adc-gateway-cve-2026-8452/ • CISA KEV 사흘 9건 핵심: 오늘: NetScaler, MS SQL CVE-2019-1068. 내일(8/30): ownCloud CVE-2023-49105 (10.6.0~10.13.0), Linux IPv6 CVE-2026-53362. 9/10: JFrog Artifactory CVE-2026-66384 (7.146.35 / 7.161.16+). 왜 중요한가: 8/26분 중 다수가 2015~2019 CVE라 레거시 미패치가 아직 침해 경로이고, Artifactory는 OpenAI 사건과 별건이지만 패키지 저장소 신뢰 전제를 같이 깨뜨린다. 출처: https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog • TeamPCP 피의자 2명 기소 (호주) 핵심: Trivy·KICS·LiteLLM 오염. 1,000개+ 조직, 자격증명 50만 건+, 최소 300GB. 왜 중요한가: 보안 스캐너 자체가 오염됐고, 체포와 별개로 이미 유출된 토큰 회전이 과제다. 출처: https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/ https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/ • Microsoft: 노출된 LiteLLM 게이트웨이로 자격증명 수확·크립토마이닝 실관측 핵심: 인터넷에 노출된 LiteLLM 게이트웨이가 자격증명 수확·지속성·크립토마이닝 경로로 관측됐다. 왜 중요한가: LLM 게이트웨이가 실험용 내부 도구가 아니라 실제 침투 경로가 됐고, TeamPCP 오염 대상과 같은 컴포넌트다. 출처: https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/ • 보이스메일 위장 SVG 밀수 핵심: 26,589통 / 5,527개 조직. SVG를 text/plain으로 위장. Microsoft SCL 0/1로 약 75% 통과. 왜 중요한가: 네이티브 스팸 점수로는 통과하니, SVG 첨부 + MIME 위장 + 내부 스푸핑을 게이트에서 따로 막아야 한다. 출처: https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/ • TerminalFix 캠페인 (8/28) 핵심: ClickFix + 가짜 CAPTCHA → DLL 사이드로딩 → 리버스 터널. 왜 중요한가: 사회공학이 다단계 체인의 입구라, EDR 시그니처만으로는 부족하고 아웃바운드 터널 모니터링이 같이 가야 한다. 출처: https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ • CISA ICS 권고 6건 (8/27) 핵심: CVSS 9.8 3건 — Ebyte NA111-M, Xiiaozet LK100W, Applied Systems ASE2000. in-the-wild 악용 여부는 별개다. 왜 중요한가: OT는 패치 주기가 길어 누적 리스크로 관리해야 하고, 권고는 악용 가능성이며 실제 악용과 같지 않다. 출처: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05 —— 개발자·엔터프라이즈 —— • Kubernetes v1.37 핵심: http://metrics.k8s.io API가 beta → stable. kubectl top·메트릭 오토스케일의 기반. 리소스 타입·필드 변경은 없고 breaking change는 없다. 왜 중요한가: 업그레이드 장벽이 낮으니, metrics-server 의존 구성과 제거 항목을 정리할 시기다. 출처: https://kubernetes.io/blog/2026/08/26/kubernetes-v1-37-release/ https://kubernetes.io/blog/2026/08/27/kubernetes-v1-37-metrics-api-ga/ • ServiceNow CVSS 10.0 3건 + 8.7 1건 핵심: CVE-2026-18885 / 18886 / 74820 (각 10.0), CVE-2026-6876 (8.7). 악용 정황 없음. 호스팅은 8/27 자동 패치. 왜 중요한가: 셀프호스트·파트너는 악용 전 지금이 가장 싼 대응 시점이다. 출처: https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html • Next.js CVE-2026-75604 핵심: Windows 자체 호스팅이면 우회책 없음. 패치 15.5.24 / 16.3.3. 왜 중요한가: Windows self-host는 설정으로 버틸 수 없고 패치만이 답이다. 출처: https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36 https://vercel.com/changelog/nextjs-august-2026-security-release • cPanel/WHM CVE-2026-65643 핵심: 도메인 파킹 경로에서 임의 파일 접근 → root 코드 실행. 악용 미확인. `/scripts/upcp --force` 또는 WHM 최신. 왜 중요한가: 파킹은 방치 기능이라 공격면이 넓고, 성공 시 root라 호스팅·공유 서버는 강제 업데이트가 맞다. 출처: https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Vulnerability-in-cPanel-s-Domain-Parking-Functionality-August-27-2026 • Amazon Bedrock AgentCore Memory 핵심: FGAC + 유연 네임스페이스. 멀티테넌트 에이전트에서 인증·격리가 앱 코드에서 인프라 계층으로 이동한다. 왜 중요한가: 공동 서한이 요구한 에이전트 신원 추적·책임성을 인프라에서 구현할 손잡이가 생겼으니, 앱 단 가드레일만 믿던 설계는 옮겨야 한다. 출처: https://aws.amazon.com/about-aws/whats-new/2026/08/agentcorememory-fine-grained-access-control 한 줄로: 1차 패치했다고 끝난 게 아니고, 에이전트 격리는 이미 한 번 뚫렸습니다.

    Post summary

    The briefing highlights several CVEs under active exploitation, including PaperCut NG/MF zero-day and Citrix NetScaler, noting available patches and urging immediate remediation.

    00030999
    70 followersView on X

Explore more