2026年7月31日金曜日

31日 金曜日、大安

+ RHSA-2026:48790 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:48790
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283
CVE-2026-33186
CVE-2026-34986

+ RHSA-2026:48703 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:48703
CVE-2026-55693
CVE-2026-57455
CVE-2026-57456
CVE-2026-59858

+ RHSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:48197
CVE-2026-14355

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ PHP 8.4.24, 8.3.33 released
https://www.php.net/ChangeLog-8.php#8.4.24
https://www.php.net/ChangeLog-8.php#8.3.33

VU#281278 SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
https://www.kb.cert.org/vuls/id/281278

VU#790363 foreUP golf management platform's web API contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/790363

JVNVU#91587639 Develar製app-builder(zipx.Unzip)における任意のファイルが上書きされる脆弱性
https://jvn.jp/vu/JVNVU91587639/index.html

JVNVU#98815601 トレンドマイクロ製TrendAI Vision Oneに対するセキュリティアップデート(2026年7月)
https://jvn.jp/vu/JVNVU98815601/index.html

月刊ランサムリポート
2026年5月の被害件数は876件で減少傾向 NightSpireは「Mimikatz」悪用して攻撃
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/071600018/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIによる「ランサムウエア攻撃」 侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/072300191/?ST=nxt_thmit_security

どうするSCS評価制度 第2回
SCS評価制度で「チェックシート地獄」は解消できるか、今取り組める2点
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800001/?ST=nxt_thmit_security

月刊ランサムリポート 第20回
ランサムグループ「INC」の存在感が強まる、Citrix Bleedを悪用
https://xtech.nikkei.com/atcl/nxt/column/18/03053/072900021/?ST=nxt_thmit_security

ニュース解説
GPT「暴走」にMicrosoftナデラCEOが言及、単一モデルへの依存に警鐘
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11933/?ST=nxt_thmit_security

2026年7月30日木曜日

30日 木曜日、仏滅

+ Gpg4win 5.1.0 released
https://www.gpg4win.org/change-history.html

+ RHSA-2026:48225 Important: perl:5.32 security update
https://access.redhat.com/errata/RHSA-2026:48225
CVE-2026-9538

+ RHSA-2026:47998 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47998
CVE-2026-64600

+ RHSA-2026:47750 Low: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47750
CVE-2026-14355

+ RHSA-2026:47749 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47749
CVE-2026-14355

+ RHSA-2026:47731 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:47731
CVE-2026-59691
CVE-2026-59692

+ RHSA-2026:47981 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47981
CVE-2026-64600

+ Google Chrome 151.0.7922.71/.72 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

+ Zabbix 7.4.13 released
https://www.zabbix.com/rn/rn7.4.13

+ FreeBSD-SA-26:55.elf  Race condition in ELF core dump segment counting
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:55.elf.asc
CVE-2026-58088

+ FreeBSD-SA-26:54.sysvsem Heap out-of-bounds access in semctl(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:54.sysvsem.asc
CVE-2026-58087

+ FreeBSD-SA-26:53.ktrace ktrace(2) privilege incorrectly validated in jails
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:53.ktrace.asc
CVE-2026-58086

+ FreeBSD-SA-26:52.if_wg Missing MAC validation in wg(4) packet decryption
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc
CVE-2026-58085

+ FreeBSD-SA-26:51.ktimer Kernel stack disclosure via timer_settime(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:51.ktimer.asc
CVE-2026-58084

+ FreeBSD-SA-26:50.kqueue Use-after-free in kqueue copy-on-fork
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:50.kqueue.asc
CVE-2026-58083

+ JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html
CVE-2026-66299

VU#293714 Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
https://www.kb.cert.org/vuls/id/293714

VU#305509 OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
https://www.kb.cert.org/vuls/id/305509

変貌するCDN 第4回
CDNを使うにはDNSから設定する、キャッシュからの情報流出に要注意
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200004/?ST=nxt_thmit_security

どうするSCS評価制度
経産省などが注意喚起、SCS評価制度の開始前に起きた不適切な勧誘
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800002/?ST=nxt_thmit_security

ニュース解説
AI攻撃にAIで対抗、Microsoftが新システム サイバー防御の独自モデルも
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11930/?ST=nxt_thmit_security

JVN#99975039 てがろぐ -Fumy Otegaru Memo Logger-における制限が不十分な正規表現を使用している脆弱性
https://jvn.jp/jp/JVN99975039/index.html

2026年7月29日水曜日

29日 水曜日、先負

+ ■Knot Resolverの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-07-28-knotresolver.html

+ RHSA-2026:47105 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:47105
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412
CVE-2026-56208

+ RHSA-2026:47060 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:47060
CVE-2026-13149
CVE-2026-59873
CVE-2026-59874

+ RHSA-2026:47011 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:47011
CVE-2026-53006

+ RHSA-2026:46990 Important: sssd security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:46990
CVE-2026-14474
CVE-2026-14476

+ Google Chrome 150.0.7871.212 released
https://chromereleases.googleblog.com/2026/07/extended-stable-updates-for-desktop.html

+ Mozilla Firefox 153.0.1 released
https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/

+ Zabbix 7.0.29, 6.0.48 released
https://www.zabbix.com/rn/rn7.0.29
https://www.zabbix.com/rn/rn6.0.48

VU#141367 AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface
https://www.kb.cert.org/vuls/id/141367

変貌するCDN 第3回
セキュリティーからエッジAIまで、「仲介」機能を生かして拡大するCDN
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200003/?ST=nxt_thmit_security

UPDATE: JVN#03037325 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年5月)
https://jvn.jp/jp/JVN03037325/index.html

JVN#24885537 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性
https://jvn.jp/jp/JVN24885537/index.html

JVN#56870912 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年7月)
https://jvn.jp/jp/JVN56870912/index.html