2026年7月23日木曜日

23日 木曜日、先負

+ ■(緊急)BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-13321)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-13204)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsecandnsec3.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-12617)
  - バージョンアップを強く推奨 -

https://jprs.jp/tech/security/2026-07-23-bind9-vuln-dnameandcname.html

+ ■(緊急)BIND 9.xの脆弱性(DNSキャッシュポイズニングの危険性)について(CVE-2026-11721)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-wildcard.html

+ ■(緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-11622)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-randomsubdomain.html

+ ■(緊急)BIND 9.xの脆弱性(過剰なCPU負荷の誘発)について(CVE-2026-11605)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-validation.html

+ ■(緊急)BIND 9.xの脆弱性(RPZの設定のバイパス、DNSサービスの停止)について(CVE-2026-11331)
 - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-rpz.html

+ ■BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-10822)
  - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、
    バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-privatedns.html

+ ■BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-10723)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec3.html

+ Google Chrome 151.0.7922.47/.48, 150.0.7871.181/.182 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop_01571975877.html
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html

+ Mozillf Firefox 153.0 released
https://www.firefox.com/en-US/firefox/153.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-68 Security Vulnerabilities fixed in Firefox 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
CVE-2026-16349
CVE-2026-16350
CVE-2026-16362
CVE-2026-16351
CVE-2026-16352
CVE-2026-16363
CVE-2026-16364
CVE-2026-16365
CVE-2026-16366
CVE-2026-16353
CVE-2026-16354
CVE-2026-16367
CVE-2026-16368
CVE-2026-16369
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16370
CVE-2026-16371
CVE-2026-16372
CVE-2026-16373
CVE-2026-16374
CVE-2026-16375
CVE-2026-16376
CVE-2026-16377
CVE-2026-16378
CVE-2026-16379
CVE-2026-16358
CVE-2026-16380
CVE-2026-16381
CVE-2026-16382
CVE-2026-16383
CVE-2026-16384
CVE-2026-16385
CVE-2026-16386
CVE-2026-16387
CVE-2026-16388
CVE-2026-16389
CVE-2026-16390
CVE-2026-16391
CVE-2026-16392
CVE-2026-16393
CVE-2026-16359
CVE-2026-16394
CVE-2026-16395
CVE-2026-16396
CVE-2026-16397
CVE-2026-16398
CVE-2026-16399
CVE-2026-16400
CVE-2026-16401
CVE-2026-16402
CVE-2026-16403
CVE-2026-16404
CVE-2026-16405
CVE-2026-16406
CVE-2026-16407
CVE-2026-16408
CVE-2026-16409
CVE-2026-16410
CVE-2026-16411
CVE-2026-16412
CVE-2026-16360

+ Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/

+ Mozilla Foundation Security Advisory 2026-69 Security Vulnerabilities fixed in Firefox ESR 115.38
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/

+ Mozilla Foundation Security Advisory 2026-71 Security Vulnerabilities fixed in Thunderbird 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/

+ Mozilla Foundation Security Advisory 2026-72 Security Vulnerabilities fixed in Thunderbird 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/

+ Mozilla Thunderbird 153.0 released
https://www.thunderbird.net/en-US/thunderbird/153.0esr/releasenotes/

+ ISC BIND 9.20.26 released
https://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html

+ Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html
CVE-2026-10723
CVE-2026-10822
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321

+ Linux Kernelの脆弱性(IPV6_FRAG_ESCAPE: CVE-2026-53362, CVE-2026-53366)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260723/
CVE-2026-53362
CVE-2026-53366

+ BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260723/
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
CVE-2026-10723
CVE-2026-10822

+ Microsoft Edge <= 150.0.4078.48 (Chromium-based) Type Confusion RCE
https://cxsecurity.com/issue/WLB-2026070009
CVE-2026-58289

VU#847406 Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
https://www.kb.cert.org/vuls/id/847406

VU#360868 Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability
https://www.kb.cert.org/vuls/id/360868

VU#762226 Plane contains multi-tenant authorization bypass vulnerability
https://www.kb.cert.org/vuls/id/762226

JVNVU#98636554 バックアップソフトウェア「Duplicati」における不適切な権限割り当てに関する脆弱性
https://jvn.jp/vu/JVNVU98636554/index.html

JVNVU#98875819 Analog Way製メディアサーバー「Picturall Quad Compact Mark II」におけるローカル権限昇格の脆弱性
https://jvn.jp/vu/JVNVU98875819/index.html

JVN#32082029 リコー製プリンターおよび複合機のSSH通信機能におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN32082029/index.html

JVNVU#90683587 プロジェクト管理ツール「Plane」における認可回避の脆弱性
https://jvn.jp/vu/JVNVU90683587/index.html

JVNVU#98832565 CISA ICS Advisory / ICS Medical Advisory(2026年07月21日)
https://jvn.jp/vu/JVNVU98832565/index.html

JVN#20592637 Drupalプラグイン「AI Agents」における不正な認証の脆弱性
https://jvn.jp/jp/JVN20592637/index.html

JVN#40509781 非接触型ICカード技術FeliCaの一部のICチップにおける脆弱性
https://jvn.jp/jp/JVN40509781/index.html

ニュース&リポート
26年度末開始「SCS評価制度」に脚光 供給網のサイバー対策を客観評価
展示会Interopで関連サービスが多数出展
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/071301466/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第2回
セキュリティー要件は6ステップで定義 LLMを生かしてまずは脅威を理解
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800002/?ST=nxt_thmit_security

ニュース解説
OpenAIのモデルが他社システムに侵入、ゼロデイ悪用でサンドボックス脱出
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11912/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェントによる「ランサムウエア攻撃」出現、侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/column/18/00676/071100229/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第1回
「残念なセキュリティー」を招く要件定義の落とし穴、3大パターンを紹介
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800001/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
顧客情報1354万件漏洩の恐れ SSD紛失、例外運用のリスク露呈
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/071300211/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
シード・プランニング、PHP脆弱性でランサムウエア被害 影響範囲を廃棄
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900373/?ST=nxt_thmit_security

2026年7月17日金曜日

17日 金曜日、先負

+ RHSA-2026:40894 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40894
CVE-2026-14544

+ RHSA-2026:40841 Important: maven:3.8 security update
https://access.redhat.com/errata/RHSA-2026:40841
CVE-2025-67030

+ RHSA-2026:40895 Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
https://access.redhat.com/errata/RHSA-2026:40895
CVE-2026-54512
CVE-2026-54513

+ RHSA-2026:40831 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40831
CVE-2026-14544

+ RHSA-2026:40751 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:40751
CVE-2026-58380
CVE-2026-58384

+ Google Chrome 150.0.7871.128/.129 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html

+ Oracle Critical Patch Update Pre-Release Announcement - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVN#65294474 Tera TermのTTSSH2プラグインにおける複数の脆弱性
https://jvn.jp/jp/JVN65294474/index.html
CVE-2026-58317
CVE-2026-60060

+ JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html
CVE-2026-59083
CVE-2026-59084

VU#885548 Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
https://www.kb.cert.org/vuls/id/885548

VU#326070 SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
https://www.kb.cert.org/vuls/id/326070

JVNVU#90340653 Pegatron製Windows Driver Model (WDM) ドライバー「Tdelo64.sys」における複数の脆弱性
https://jvn.jp/vu/JVNVU90340653/index.html

JVNVU#98998987 JavaScriptライブラリ「Forge」における複数の署名検証不備の脆弱性
https://jvn.jp/vu/JVNVU98998987/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
「AI駆動型ワーム」の脅威 自律的に脆弱性を見つけて感染
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/070700190/?ST=nxt_thmit_security

基礎から分かる、AIエージェントのセキュリティー設計 第3回
何をどう判断しどう行動したのか、AIエージェントを「追跡」するログ設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000003/?ST=nxt_thmit_security

2026年7月16日木曜日

16日 木曜日、友引

+ RHSA-2026:39893 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39893
CVE-2026-15308

+ RHSA-2026:39868 Important: nodejs:24 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39868
CVE-2026-6733
CVE-2026-6734
CVE-2026-9678
CVE-2026-9697
CVE-2026-11525
CVE-2026-12151
CVE-2026-42338
CVE-2026-48615
CVE-2026-48618
CVE-2026-48619
CVE-2026-48928
CVE-2026-48930
CVE-2026-48933
CVE-2026-48934
CVE-2026-48935

+ RHSA-2026:39575 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39575
CVE-2026-12505

+ RHSA-2026:40416 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:40416
CVE-2026-14355

+ RHSA-2026:39879 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:39879
CVE-2026-27145
CVE-2026-39821

+ RHSA-2026:39810 Important: Red Hat OpenStack Services on OpenShift 18.0 (golang-github-openstack-k8s-operators-os-diff) security update
https://access.redhat.com/errata/RHSA-2026:39810
CVE-2025-61726
CVE-2025-61729
CVE-2026-25679
CVE-2026-27137
CVE-2026-32280
CVE-2026-32281
CVE-2026-32282
CVE-2026-32283
CVE-2026-33810
CVE-2026-33811

+ RHSA-2026:39798 Important: python3.9 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39798
CVE-2026-15308

+ RHSA-2026:39771 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39771
CVE-2026-15308

+ RHSA-2026:39576 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39576
CVE-2026-12505

+ Google Chrome 151.0.7922.34/.35 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop.html

+ Mozilla Firefox 152.0.6 released
https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/

+ nginx 1.31.3. 1.30.4 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.30

+ K000162097: NGINX map directive and regex matching vulnerability CVE-2026-42533
https://my.f5.com/manage/s/article/K000162097
CVE-2026-42533

+ K000162100: NGINX ngx_http_slice_module vulnerability CVE-2026-60005
https://my.f5.com/manage/s/article/K000162100
CVE-2026-60005

+ K000162098: NGINX ngx_http_ssi_module vulnerability CVE-2026-56434
https://my.f5.com/manage/s/article/K000162098
CVE-2026-56434

+ Apache PDFBox 2.0.37 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12356771

VU#529388 Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys
https://www.kb.cert.org/vuls/id/529388

VU#725167 node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations
https://www.kb.cert.org/vuls/id/725167

基礎から分かる、AIエージェントのセキュリティー設計 第2回
AIエージェントのID管理に4つの課題、過剰な権限を持たせず「小さく」設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000002/?ST=nxt_thmit_security

ニュース解説
ニチレイ不正アクセス「東西両センターで障害」、井村屋は15日分納品を中止
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11899/?ST=nxt_thmit_security

JVN#59875262 HYPER SBI 2のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN59875262/index.html

JVNVU#91295052 Siemens製品に対するアップデート(2026年7月)
https://jvn.jp/vu/JVNVU91295052/index.html

JVNVU#91675472 CISA ICS Advisory / ICS Medical Advisory(2026年07月14日)
https://jvn.jp/vu/JVNVU91675472/index.html