2026年9月2日水曜日

2日 火曜日、先負

+ Google Chrome 152.0.7977.75/.76 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html

+ Mozilla Firefox 155.0 released
https://www.firefox.com/en-US/firefox/155.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-82 Security Vulnerabilities fixed in Firefox 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
CVE-2026-84117
CVE-2026-84118
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84123
CVE-2026-84124
CVE-2026-84125
CVE-2026-84126
CVE-2026-84127
CVE-2026-84128
CVE-2026-84129
CVE-2026-84130
CVE-2026-84131
CVE-2026-84132
CVE-2026-84133
CVE-2026-84134
CVE-2026-84135
CVE-2026-84136
CVE-2026-84137
CVE-2026-84138
CVE-2026-84139
CVE-2026-84140
CVE-2026-84141
CVE-2026-84142
CVE-2026-84143
CVE-2026-84144
CVE-2026-84145

+ Mozilla Foundation Security Advisory 2026-85 Security Vulnerabilities fixed in Firefox ESR 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/

+ Mozilla Foundation Security Advisory 2026-84 Security Vulnerabilities fixed in Firefox ESR 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/

+ Mozilla Foundation Security Advisory 2026-83 Security Vulnerabilities fixed in Firefox ESR 115.40
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/

+ Mozilla Foundation Security Advisory 2026-88 Security Vulnerabilities fixed in Thunderbird 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/

+ Mozilla Foundation Security Advisory 2026-87 Security Vulnerabilities fixed in Thunderbird 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/

+ Mozilla Foundation Security Advisory 2026-86 Security Vulnerabilities fixed in Thunderbird 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/

VU#456290 Hugging Face Transformers library writes remote code to disk prior to consent check
https://www.kb.cert.org/vuls/id/456290

決算が暴くサイバー被害
被害企業の防止策 守りより「復旧力」へ [Part 4]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700004/?ST=nxt_thmit_security

決算が暴くサイバー被害
ランサム損失は28社 1年で倍の236億円に [Part 3]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700003/?ST=nxt_thmit_security

決算が暴くサイバー被害
18社が損失計上 海外拠点が標的に [Part 2]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700002/?ST=nxt_thmit_security

マルウエア徹底解剖
AIを取り巻くサイバー脅威を整理する [第81回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/081800082/?ST=nxt_thmit_security

データは語る
67%がSCS評価制度の取り組み進行 業務システムの共同利用は約9割
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/082700232/?ST=nxt_thmit_security

決算が暴くサイバー被害
「社長の声」装い詐取 不正アクセスなき詐欺 [Part 1]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700001/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が「縄張り争い」、矛盾した指示によるリスク明らかに
https://xtech.nikkei.com/atcl/nxt/column/18/00676/082500232/?ST=nxt_thmit_security

2026年9月1日火曜日

1日 火曜日、友引

+ RHSA-2026:61766 Moderate: glib2 security update
https://access.redhat.com/errata/RHSA-2026:61766
CVE-2026-15588
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015

+ RHSA-2026:61257 Important: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:61257
CVE-2026-71217

+ RHSA-2026:61248 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:61248
CVE-2026-11979

+ RHSA-2026:61623 Moderate: gzip security update
https://access.redhat.com/errata/RHSA-2026:61623
CVE-2026-41991
CVE-2026-41992

+ RHSA-2026:61581 Moderate: tar security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:61581
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508

+ RHSA-2026:61389 Important: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:61389
CVE-2026-71217

+ RHSA-2026:61386 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:61386
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:61383 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2026:61383
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:61379 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:61379
CVE-2026-55194
CVE-2026-67288
CVE-2026-67291
CVE-2026-67301

+ RHSA-2026:61355 Moderate: dbus-broker security update
https://access.redhat.com/errata/RHSA-2026:61355
CVE-2026-16730

+ RHSA-2026:61316 Important: xmlrpc-c security update
https://access.redhat.com/errata/RHSA-2026:61316
CVE-2026-15928

+ RHSA-2026:61247 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:61247
CVE-2026-6653
CVE-2026-11979

piyokangoの週刊システムトラブル
アイドル事務所VOISINGが利用するBIツールから個人情報流出、5万件公開か
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900379/?ST=nxt_thmit_security

ニュース解説
SBOM国際ガイダンスで「最小要素」追加、企業の作成負担増も運用にメリット
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12005/?ST=nxt_thmit_security

ニュース解説
1200体のAIが「裏技」で情報共有、700体が攻撃に参加 OpenAIの侵入事案
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12000/?ST=nxt_thmit_security

JVN#84094853 PALLET CONTROL製品におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN84094853/index.html

JVN#48718197 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)における反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN48718197/index.html

JVN#65118274 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)におけるオープンリダイレクトの脆弱性
https://jvn.jp/jp/JVN65118274/index.html

JVNVU#90210212 ヤマハ製VOCALOID6 Editorにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90210212/index.html

2026年8月31日月曜日

31日 月曜日、先勝

+ ■NSDの脆弱性情報が公開されました(CVE-2026-18664、CVE-2026-18916、CVE-2026-19401、CVE-2026-19538)
CVE-2026-18664
CVE-2026-18916
CVE-2026-19401
CVE-2026-19538

+ PHP 8.5.1, 8.4.25 released
https://www.php.net/ChangeLog-8.php#8.5.10
https://www.php.net/ChangeLog-8.php#8.4.25

JVN#42348352 GROWIにおける複数の脆弱性
https://jvn.jp/jp/JVN42348352/index.html

JVN#04485476 SOYシリーズにおける複数の脆弱性
https://jvn.jp/jp/JVN04485476/index.html

JVN#42011956 Zabbix agentにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN42011956/index.html

JVNVU#98375707 Siemens製品に対するアップデート(2026年8月)
https://jvn.jp/vu/JVNVU98375707/index.html

JVNVU#99593741 CISA ICS Advisory / ICS Medical Advisory(2026年08月27日)
https://jvn.jp/vu/JVNVU99593741/index.html

JVNVU#95523788 三菱電機数値制御装置におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU95523788/index.html

JVNVU#96620683 三菱電機製FA製品のEthernet機能におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU96620683/index.html

JVN#18593874 楽天Koboデスクトップアプリ(Windows版)のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN18593874/index.html

月刊ランサムリポート
ランサムグループ「INC」の存在感が強まる Citrix Bleedを悪用して侵入
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/081800019/?ST=nxt_thmit_security

月刊ランサムリポート 第21回
急増するDeadLock被害、感染すると1対1のチャットにただちに誘導
https://xtech.nikkei.com/atcl/nxt/column/18/03053/082800022/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ホテルからのM365が危ない 公衆Wi-Fi機器への侵害を警告
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/082600193/?ST=nxt_thmit_security

日経コンピュータ 大森敏行のプログラミングで行こう
大手AIベンダーで続々発生 AIの「暴走」は止められるか
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100112/082400145/?ST=nxt_thmit_security

ネットワーク機器利用実態調査2026
企業規模別のシェアが見える
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/081800254/081800001/?ST=nxt_thmit_security

NEWS close-up
狙われるGitHub
内部リポジトリー漏洩リスクは公開版の6倍に 「非公開だから安全」は危険な思い込み
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800336/?ST=nxt_thmit_security

中国テックジャイアント最前線 第67回
アリババのAIコーディングツール「Qoder」、組織力の強化も支援
https://xtech.nikkei.com/atcl/nxt/column/18/02653/082400083/?ST=nxt_thmit_security

ニュース解説
富士通がAI時代のサイバー防衛戦略、「減速防御」を掲げ年内にもサービス化
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11994/?ST=nxt_thmit_security