2026年8月6日木曜日

6日 木曜日、大安

+ RHSA-2026:50728 Important: ruby:3.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50728
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50223 Important: Satellite 6.16.12 Async Update
https://access.redhat.com/errata/RHSA-2026:50223
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-48864
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236
CVE-2026-59197

+ RHSA-2026:49927 Moderate: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:49927
CVE-2026-44431

+ RHSA-2026:49922 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:49922
CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412

+ RHSA-2026:49857 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:49857
CVE-2026-52923

+ RHSA-2026:50828 Important: ruby:3.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50828
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50827 Important: ruby:4.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50827
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50817 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:50817
CVE-2026-42169
CVE-2026-66758
CVE-2026-66759

+ RHSA-2026:50263 Important: Satellite 6.18.8 Async Update
https://access.redhat.com/errata/RHSA-2026:50263
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50223 Important: Satellite 6.16.12 Async Update
https://access.redhat.com/errata/RHSA-2026:50223
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-48864
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236
CVE-2026-59197

+ RHSA-2026:50222 Important: Satellite 6.17.10 Async Update
https://access.redhat.com/errata/RHSA-2026:50222
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50221 Important: Satellite 6.19.3 Async Update
https://access.redhat.com/errata/RHSA-2026:50221
CVE-2026-2332
CVE-2026-12515
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50108 Important: ldns security update
https://access.redhat.com/errata/RHSA-2026:50108
CVE-2026-10846

+ RHSA-2026:49921 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:49921
CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412

+ RHSA-2026:49838 Important: osbuild-composer security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:49838
CVE-2026-32280
CVE-2026-32281

+ Google Chrome 151.0.7922.75/.76 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop.html

+ Mozilla Firefox 153.0.3 released
https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/

+ Mozilla Thunderbird 153.0.2 released
https://www.thunderbird.net/en-US/thunderbird/153.0.2/releasenotes/

+ OpenSSLの脆弱性(Low: CVE-2026-54876)
https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260806/
CVE-2026-54876

JVN#28045338 NetKids iMarkにおける複数の脆弱性
https://jvn.jp/jp/JVN28045338/index.html

JVNVU#92898025 CISA ICS Advisory / ICS Medical Advisory(2026年08月04日)
https://jvn.jp/vu/JVNVU92898025/index.html

JVNVU#92804348 ロボット掃除機DEEBOT PRO M1、DEEBOT PRO K1VACおよびスマートフォンアプリECOVACS PROにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92804348/index.html

JVN#52865575 freo2におけるアップロードするファイルの検証が不十分な脆弱性
https://jvn.jp/jp/JVN52865575/index.html

ニュース&リポート
ニチレイの東西両センターで障害 不正アクセスの影響を避けられず
冷蔵倉庫の入出庫業務などに支障
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/072801472/?ST=nxt_thmit_security

記者の眼
シャドーAIにとどまらない企業リスク、三菱電機は「見逃し」契機に体制強化
https://xtech.nikkei.com/atcl/nxt/column/18/00138/072302073/?ST=nxt_thmit_security

ニュース解説
企業秘密を出さずにAIを使う、日本発の「秘匿AI」基盤が本格始動
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11948/?ST=nxt_thmit_security

中部電力で個人情報漏洩の可能性、グループ役職員や取引先など7万人超
https://xtech.nikkei.com/atcl/nxt/news/24/03331/?ST=nxt_thmit_security

日経コンピュータ「ITが危ない」
GitHub内部リポジトリーが標的 漏洩リスクは公開版の6倍に
「非公開だから安全」という思い込みが危険
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/072800200/?ST=nxt_thmit_security

データは語る
過半数がペーパーレス化に課題 取引先との商慣習が障壁に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/072800230/?ST=nxt_thmit_security

AIインフラ最前線 第5回
AI活用で高まるセキュリティーリスク、パッチ作成の自動化など防御も強化へ
https://xtech.nikkei.com/atcl/nxt/column/18/03551/073100005/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
ランサムウエア攻撃者の侵入経路、脆弱性悪用を抜き「メール」が首位に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/072900230/?ST=nxt_thmit_security

EPARKリラク&エステに不正アクセス、顧客情報3300万レコードが漏洩の恐れ
https://xtech.nikkei.com/atcl/nxt/news/24/03330/?ST=nxt_thmit_security

サイバーセキュリティ2026決定、対策強化を「日本成長戦略」の大前提に
https://xtech.nikkei.com/atcl/nxt/news/24/03328/?ST=nxt_thmit_security

2026年8月4日火曜日

4日 火曜日、先負

マルウエア徹底解剖
マルウエアの正体を暴くサンドボックス [第80回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/071600081/?ST=nxt_thmit_security

ケーススタディー
ネットワーク刷新しβ’モデルへ移行 ゼロトラスト型で安全性水準を向上
兵庫県太子町
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600004/072800214/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
シミックヘルスケア、受託運営システムで患者情報が流出 公開ファイルから
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900375/?ST=nxt_thmit_security

2026年8月3日月曜日

3日 月曜日、友引

+ RHSA-2026:49524 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49524
CVE-2026-9538

+ RHSA-2026:49511 Important: frr security update
https://access.redhat.com/errata/RHSA-2026:49511
CVE-2026-37460

+ RHSA-2026:49214 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49214
CVE-2026-31692
CVE-2026-43116
CVE-2026-46150
CVE-2026-64530

+ RHSA-2026:49525 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49525
CVE-2026-9538

+ RHSA-2026:49212 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49212
CVE-2026-52923
CVE-2026-52993
CVE-2026-64530

+ Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit
https://cxsecurity.com/issue/WLB-2026080002
CVE-2026-46215

VU#243636 VPS.org one-click deployment templates contain multiple vulnerabilities
https://www.kb.cert.org/vuls/id/243636

JVNVU#98879231 三菱電機製複数製品で使用しているCC-Link IE TSN通信プロトコルにおける通信チャネルで送受信するメッセージに対する完全性の検証不備に起因する脆弱性
https://jvn.jp/vu/JVNVU98879231/index.html

JVN#72334274 サイボウズ Garoonにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN72334274/index.html

JVNVU#91736352 VPS.orgのone-click deploymentテンプレートにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91736352/index.html

JVNVU#92540957 シャープ製ネットワークスキャナーツールの初期設定がセキュアでない問題
https://jvn.jp/vu/JVNVU92540957/index.html

JVNVU#98759887 シャープ製および東芝テック製複合機(MFP)における複数の脆弱性
https://jvn.jp/vu/JVNVU98759887/index.html

JVNVU#97496464 CISA ICS Advisory / ICS Medical Advisory(2026年07月30日)
https://jvn.jp/vu/JVNVU97496464/index.html

JVNVU#90278463 SGLangにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90278463/index.html

JVNVU#92804348 ロボット掃除機DEEBOT PRO M1、DEEBOT PRO K1VACおよびスマートフォンアプリECOVACS PROにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92804348/index.html

JVNVU#94952030 BaserCMSにおけるCSVファイルインジェクションの脆弱性
https://jvn.jp/vu/JVNVU94952030/index.html

キーワード
Shadow AI(シャドーAI)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/072800228/?ST=nxt_thmit_security

フォーカス
AIエージェントのリスク ID管理とログで統制
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/072800233/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
デジタル庁などが仕様に疑義 マイナ署名関連の一部機能を停止
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/072800212/?ST=nxt_thmit_security

ニュース解説
AnthropicのAIも他社侵入、しかも3件 設定ミスでネットアクセス可能に
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11940/?ST=nxt_thmit_security