2026年8月26日水曜日

26日 水曜日、友引

+ RHSA-2026:59487 Important: gstreamer1-plugins-base security update
https://access.redhat.com/errata/RHSA-2026:59487
CVE-2026-18297

+ RHSA-2026:59241 Important: python-pyasn1 security update
https://access.redhat.com/errata/RHSA-2026:59241
CVE-2026-59886

+ RHSA-2026:59216 Important: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:59216
CVE-2026-56434
CVE-2026-60005

+ RHSA-2026:59179 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:59179
CVE-2026-18295
CVE-2026-18296
CVE-2026-18298
CVE-2026-18299

+ RHSA-2026:59146 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:59146
CVE-2026-43499
CVE-2026-45984
CVE-2026-46116
CVE-2026-46227

+ RHSA-2026:58898 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:58898
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74949
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74969
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74983
CVE-2026-74987
CVE-2026-74990

+ RHSA-2026:58562 Important: python-urwid security update
https://access.redhat.com/errata/RHSA-2026:58562
CVE-2026-9323

+ RHSA-2026:59490 Important: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:59490
CVE-2026-56434
CVE-2026-60005

+ RHSA-2026:59347 Low: httpd security update
https://access.redhat.com/errata/RHSA-2026:59347
CVE-2026-29167

+ RHSA-2026:59152 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:59152
CVE-2026-18295
CVE-2026-18296
CVE-2026-18298
CVE-2026-18299

+ RHSA-2026:59149 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:59149
CVE-2026-43499
CVE-2026-45984
CVE-2026-46116
CVE-2026-46227
CVE-2026-64531

+ RHSA-2026:58982 Moderate: grafana security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:58982
CVE-2026-33376
CVE-2026-33377

+ RHSA-2026:58897 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:58897
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74949
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74969
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74983
CVE-2026-74987
CVE-2026-74990

+ Google Chrome 152.0.7977.64/.65 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html

+ Mozilla Firefox 154.0.1 released
https://www.firefox.com/en-US/firefox/154.0.1/releasenotes/

+ Zabbix 7.4.14, 7.0.30 released
https://www.zabbix.com/rn/rn7.4.14
https://www.zabbix.com/rn/rn7.0.30

+ OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22 released
https://github.com/openssl/openssl/releases#release-openssl-4.0.2
https://github.com/openssl/openssl/releases#release-openssl-3.6.4
https://github.com/openssl/openssl/releases#release-openssl-3.5.8
https://github.com/openssl/openssl/releases#release-openssl-3.4.7
https://github.com/openssl/openssl/releases#release-openssl-3.0.22

+ AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75803
CVE-2026-75803

+ RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-14457
CVE-2026-14457

+ QUIC Server May Trigger Double Free When Processing INITIAL Packet
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-18798
CVE-2026-18798

+ Excessive Memory Use Buffering DTLS Records for a Future Epoch
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54874
CVE-2026-54874

+ Heap Buffer Overflow in CMS Key Unwrapping
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63072
CVE-2026-63072

+ Untrusted Sender DN Used as Format String in CMP Response Validation
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63073
CVE-2026-63073

+ CMP Indefinite Cache Growth of ExtraCerts
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63074
CVE-2026-63074

+ QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63075
CVE-2026-63075

+ Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63076
CVE-2026-63076

+ JVN#08517956 Apache Struts 2におけるリソース枯渇の脆弱性
https://jvn.jp/jp/JVN08517956/index.html

VU#308749 Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
https://www.kb.cert.org/vuls/id/308749

当事者が語る! トラブルからの脱出
社内システムが使えない ランサム攻撃者がデータ暗号化
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800004/081800104/?ST=nxt_thmit_security

AI時代に必須の備えとは~AIリスク教本 第4回
法を守れば十分とは言い切れず、AIリスク対応が難しい理由
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00004/?ST=nxt_thmit_security

AIパソコン「DGX Spark」試用リポート 第3回
生成AIの学習もこなすDGX Spark、雑誌記事を学ばせて実際に書かせてみた
https://xtech.nikkei.com/atcl/nxt/column/18/03726/081900003/?ST=nxt_thmit_security

ニュース解説
中国AIモデル「Kimi K3」もサンドボックス脱出、評価環境の設定不備を突く
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11984/?ST=nxt_thmit_security

JVNVU#95422936 古野電気製FA-50(簡易型船舶自動識別装置、AIS)におけるハードコードされた認証情報使用および認証欠如の脆弱性
https://jvn.jp/vu/JVNVU95422936/index.html

JVNVU#96980428 KONAMI製METAL GEAR ONLINE 3におけるヒープベースのバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU96980428/index.html

2026年8月25日火曜日

25日 火曜日、先勝

VU#728712 Konami's Metal Gear Online 3 contains a heap-based buffer overflow
https://www.kb.cert.org/vuls/id/728712

AI時代に必須の備えとは~AIリスク教本 第3回
AIリスクが発生する根本要因は? 従来のソフトウエア品質管理が通用せず
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00003/?ST=nxt_thmit_security

AIパソコン「DGX Spark」試用リポート 第2回
DGX Sparkの本命用途は「ローカル推論」、GUIを使った操作も可能に
https://xtech.nikkei.com/atcl/nxt/column/18/03726/081900002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
小売のREXTでランサムウエア被害、一部休業から全店営業 ポイント停止続く
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900378/?ST=nxt_thmit_security

JVN#33423625 SKYSEA Client ViewおよびSKYMEC IT Managerにおける複数の脆弱性
https://jvn.jp/jp/JVN33423625/index.html

JVN#84326763 SKYSEA Client Viewにおける複数の脆弱性
https://jvn.jp/jp/JVN84326763/index.html

JVN#74538868 サクラエディタにおけるOSコマンドインジェクションの脆弱性
https://jvn.jp/jp/JVN74538868/index.html

2026年8月24日月曜日

24日 月曜日、赤口

+ Apache Tomcat 10.1.59 Released
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.59_(schultz)

VU#756733 Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
https://www.kb.cert.org/vuls/id/756733

JVN#81414813 UNIVERGE IX-R/IX-Vシリーズルータにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/jp/JVN81414813/index.html

JVN#09266484 スマートフォンアプリ「日本科学未来館アシストアプリ」におけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN09266484/index.html

JVNVU#90210212 ヤマハ製VOCALOID6 Editorにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90210212/index.html

JVNVU#97889580 CISA ICS Advisory / ICS Medical Advisory(2026年08月20日)
https://jvn.jp/vu/JVNVU97889580/index.html

AIパソコン「DGX Spark」試用リポート 第1回
AIパソコンDGX Sparkを使ってみよう、基本は「普通」のLinuxパソコン
https://xtech.nikkei.com/atcl/nxt/column/18/03726/081900001/?ST=nxt_thmit_security

記者の眼
量子の脅威をビジネスチャンスに、迫る「Qデー」と日本企業の技術力
https://xtech.nikkei.com/atcl/nxt/column/18/00138/082002086/?ST=nxt_thmit_security

AI時代に必須の備えとは~AIリスク教本 第2回
仮想リスクシナリオ2:「顧客の嘘」を勝手に捏造し始めた保険金査定AI?
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00002/?ST=nxt_thmit_security

2026年8月21日金曜日

21日 金曜日、先負

+ Google Chrome 151.0.7922.173/.174 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html

+ Microsoft Drivers for PHP for SQL Server 5.13.3 released
https://learn.microsoft.com/ja-jp/sql/connect/php/release-notes-php-sql-driver?view=sql-server-ver17&source=recommendations

AI時代に必須の備えとは~AIリスク教本 第1回
仮想リスクシナリオ1:小売りチェーンの販売戦略AIがSNS裏工作?
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00001/?ST=nxt_thmit_security

JVNVU#91609598 複数のセイコーエプソン製プリンターおよびスキャナーにおける失効したルート証明書が残存している問題
https://jvn.jp/vu/JVNVU91609598/index.html

JVNVU#91551881 RDK-BのWebUIにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91551881/index.html

2026年8月20日木曜日

20日 木曜日、友引

+ RHSA-2026:56966 Moderate: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:56966
CVE-2026-18649
CVE-2026-73433
CVE-2026-73434

+ RHSA-2026:56936 Important: mysql:8.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:56936
CVE-2026-46936
CVE-2026-47012
CVE-2026-47023
CVE-2026-47052
CVE-2026-47064
CVE-2026-60145
CVE-2026-60163
CVE-2026-60177
CVE-2026-60178
CVE-2026-60182
CVE-2026-60183
CVE-2026-60184
CVE-2026-60185
CVE-2026-60186
CVE-2026-60187
CVE-2026-60188
CVE-2026-60189
CVE-2026-60190
CVE-2026-60191
CVE-2026-60315
CVE-2026-60316
CVE-2026-60331
CVE-2026-60332
CVE-2026-60585
CVE-2026-60747
CVE-2026-61081
CVE-2026-61094
CVE-2026-61096
CVE-2026-61109

+ RHSA-2026:57149 Important: ansible-core security update
https://access.redhat.com/errata/RHSA-2026:57149
CVE-2026-11332

+ RHSA-2026:56970 Important: perl-Date-Manip security update
https://access.redhat.com/errata/RHSA-2026:56970
CVE-2026-60075

+ Google Chrome 152.0.7977.54/.55 released
https://chromereleases.googleblog.com/2026/08/early-stable-update-for-desktop_02031437787.html

+ ISC BIND 9.20.27 released
https://downloads.isc.org/isc/bind9/9.20.27/doc/arm/html/notes.html

VU#874418 RDK-B WebUI contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/874418

JVNVU#91551881 RDK-BのWebUIにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91551881/index.html

JVN#47716829 acmailerにおける複数の脆弱性
https://jvn.jp/jp/JVN47716829/index.html

JVNVU#90536447 CISA ICS Advisory / ICS Medical Advisory(2026年08月18日)
https://jvn.jp/vu/JVNVU90536447/index.html

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第4回
「一人情シス」を支える国産セキュリティー、運用力で海外勢と勝負
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700002/?ST=nxt_thmit_security

ニュース解説
デジ庁など7省庁がSNS大手5社に詐欺広告の対策要請、焦点は追跡可能性
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11971/?ST=nxt_thmit_security

2026年8月19日水曜日

19日 水曜日、先勝

+ RHSA-2026:56521 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:56521
CVE-2026-19387

+ RHSA-2026:56219 Important: python3 security update
https://access.redhat.com/errata/RHSA-2026:56219
CVE-2026-11940

+ RHSA-2026:56131 Moderate: pam security update
https://access.redhat.com/errata/RHSA-2026:56131
CVE-2026-54411

+ RHSA-2026:56133 Moderate: attr security update
https://access.redhat.com/errata/RHSA-2026:56133
CVE-2026-54371

+ RHSA-2026:56130 Important: sg3_utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:56130
CVE-2026-16313

+ RHSA-2026:55764 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:55764
CVE-2025-39902
CVE-2026-17523
CVE-2026-43206
CVE-2026-53016
CVE-2026-53136
CVE-2026-53329
CVE-2026-53374
CVE-2026-63879
CVE-2026-63884
CVE-2026-64219

+ RHSA-2026:55560 Important: pcp security update
https://access.redhat.com/errata/RHSA-2026:55560
CVE-2026-16524
CVE-2026-16526
CVE-2026-16527
CVE-2026-16529

+ RHSA-2026:55530 Important: 389-ds:1.4 security update
https://access.redhat.com/errata/RHSA-2026:55530
CVE-2026-11770
CVE-2026-11788
CVE-2026-15722

+ RHSA-2026:55865 Important: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update
https://access.redhat.com/errata/RHSA-2026:55865
CVE-2026-19387
CVE-2026-19389

+ RHSA-2026:55841 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:55841
CVE-2026-44690
CVE-2026-55973

+ RHSA-2026:55772 Important: haproxy security update
https://access.redhat.com/errata/RHSA-2026:55772
CVE-2026-55203
CVE-2026-55204

+ RHSA-2026:55763 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:55763
CVE-2026-43038
CVE-2026-43125
CVE-2026-43329
CVE-2026-46244
CVE-2026-64530

+ RHSA-2026:55603 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:55603
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-54272
CVE-2026-69152
CVE-2026-69192

+ RHSA-2026:55601 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2026:55601
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-69152
CVE-2026-69192

+ About the security content of Safari 26.6.1
https://support.apple.com/en-us/148286
CVE-2026-64784
CVE-2026-43795
CVE-2026-65338
CVE-2026-65341
CVE-2026-64782
CVE-2026-64781
CVE-2026-65351
CVE-2026-65340
CVE-2026-65337
CVE-2026-65336
CVE-2026-65335
CVE-2026-65333
CVE-2026-65332
CVE-2026-65331
CVE-2026-64715
CVE-2026-64780
CVE-2026-65334
CVE-2026-43794
CVE-2026-64787
CVE-2026-64778
CVE-2026-64779

+ Google Chrome 151.0.7922.169/.170, 150.0.7871.250 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html
https://chromereleases.googleblog.com/2026/08/extended-stable-update-for-desktop_01726425345.html

+ Mozilla Firefox 154.0 released
https://www.firefox.com/en-US/firefox/154.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-74 Security Vulnerabilities fixed in Firefox 154
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/
CVE-2026-75874
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74937
CVE-2026-74938
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74947
CVE-2026-74948
CVE-2026-74949
CVE-2026-74950
CVE-2026-74951
CVE-2026-74952
CVE-2026-74953
CVE-2026-74954
CVE-2026-74955
CVE-2026-74956
CVE-2026-74957
CVE-2026-74958
CVE-2026-74959
CVE-2026-74960
CVE-2026-74961
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74966
CVE-2026-74967
CVE-2026-74968
CVE-2026-74969
CVE-2026-74970
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74975
CVE-2026-74976
CVE-2026-74977
CVE-2026-74978
CVE-2026-74979
CVE-2026-74980
CVE-2026-74981
CVE-2026-74982
CVE-2026-74983
CVE-2026-74984
CVE-2026-74985
CVE-2026-74986
CVE-2026-74987
CVE-2026-74988
CVE-2026-74989
CVE-2026-74990

+ Mozilla Thunderbird 154.0 released
https://www.thunderbird.net/en-US/thunderbird/154.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-78 Security Vulnerabilities fixed in Thunderbird 154
https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/

+ Mozilla Foundation Security Advisory 2026-77 Security Vulnerabilities fixed in Firefox ESR 153.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/

+ Mozilla Foundation Security Advisory 2026-76 Security Vulnerabilities fixed in Firefox ESR 140.14
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/

+ Mozilla Foundation Security Advisory 2026-75 Security Vulnerabilities fixed in Firefox ESR 115.39
https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/

+ Mozilla Foundation Security Advisory 2026-80 Security Vulnerabilities fixed in Thunderbird 153.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/

+ Mozilla Foundation Security Advisory 2026-79 Security Vulnerabilities fixed in Thunderbird 140.14
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/

+ Apache Tomcat 11.0.25, 9.0.121 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.25_(markt)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.121_(remm)

+ Linux Kernelの脆弱性(CVE-2026-68081~CVE-2026-68479)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260819/

JVN#06609828 Apache Alluraにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/jp/JVN06609828/index.html

勝村幸博の「今日も誰かが狙われる」
ホテルからのMicrosoft 365利用が危ない、公衆Wi-Fi機器への侵害を警告
https://xtech.nikkei.com/atcl/nxt/column/18/00676/080600231/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋
国内に軸足、海外の拠点や人材を生かす国産セキュリティーの現実解
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700005/?ST=nxt_thmit_security

未成年保護から選挙対策まで、世界で強まるSNS規制 第3回
選挙偽情報対策で法改正、企業SNS運用に投稿・拡散の新リスク
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500003/?ST=nxt_thmit_security

2026年8月18日火曜日

18日 火曜日、赤口

+ About the security content of iOS 26.6.1 and iPadOS 26.6.1
https://support.apple.com/en-us/148282
CVE-2026-65339
CVE-2026-65347
CVE-2026-65346
CVE-2026-64788
CVE-2026-65343
CVE-2026-65349
CVE-2026-65330
CVE-2026-65329
CVE-2026-64784
CVE-2026-43795
CVE-2026-65338
CVE-2026-65341
CVE-2026-64782
CVE-2026-64781
CVE-2026-65351
CVE-2026-65340
CVE-2026-65337
CVE-2026-65336
CVE-2026-65335
CVE-2026-65333
CVE-2026-65332
CVE-2026-65331
CVE-2026-64715
CVE-2026-64780
CVE-2026-65334
CVE-2026-43794
CVE-2026-64787
CVE-2026-64778
CVE-2026-64779

+ About the security content of iOS 18.7.10 and iPadOS 18.7.10
https://support.apple.com/en-us/148287

+ About the security content of macOS Tahoe 26.6.2
https://support.apple.com/en-us/148281

+ visionOS 26.6.1 released
https://support.apple.com/en-us/100100

記者の眼
「不正アクセス」に他責の響き、ニュースリリースがぼかす管理不備
https://xtech.nikkei.com/atcl/nxt/column/18/00138/081402080/?ST=nxt_thmit_security

未成年保護から選挙対策まで、世界で強まるSNS規制 第2回
米豪のSNS規制、若年層への情報発信に壁 日本企業は広報戦略見直しも
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
Eストアーで885万件超漏洩、配送先や店舗のFTPパスワードも対象
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900377/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第2回
価格や日本語対応だけではない、国産セキュリティーが選ばれる強み
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700004/?ST=nxt_thmit_security

JVN#58692577 F-RevoCRMにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN58692577/index.html

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

2026年8月17日月曜日

17日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-70330、他15件)
https://jprs.jp/tech/security/2026-08-14-windows.html

+ PuTTY 0.85 released
https://www.chiark.greenend.org.uk/~sgtatham/putty/releases/0.85.html

+ S2-070 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334417/S2-070
CVE-2026-73631

+ S2-071 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334419/S2-071
CVE-2026-73632

+ S2-073 Struts 2 developers and users whose applications expose an endpoint collecting Content Security Policy violation reports
https://cwiki.apache.org/confluence/spaces/WW/pages/444334431/S2-073
CVE-2026-73634

+ S2-074 All Struts 2 developers and users
https://cwiki.apache.org/confluence/spaces/WW/pages/444334689/S2-074
CVE-2026-73635

+ ProFTPD 1.3.9d released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9d
http://www.proftpd.org/docs/NEWS-1.3.9d

+ Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632)
https://security.sios.jp/vulnerability/struts-security-vulnerability-20260814/
CVE-2026-73631
CVE-2026-73633
CVE-2026-73634
CVE-2026-73635
CVE-2026-73632

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

JVNVU#97860021 CISA ICS Advisory / ICS Medical Advisory(2026年08月13日)
https://jvn.jp/vu/JVNVU97860021/index.html

未成年保護から選挙対策まで、世界で強まるSNS規制 第1回
EUのSNS規制、日本企業にも波及 未成年保護で広告とUIに制約
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500001/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第1回
海外製品が止まっても日本を守る、国産セキュリティー振興の全貌を徹底解説
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080600001/?ST=nxt_thmit_security

2026年8月14日金曜日

14日 金曜日、友引

+ RHSA-2026:54654 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54654
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54575 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54575
CVE-2026-15816

+ RHSA-2026:54542 Important: .NET 10.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54542
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54538 Important: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54538
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54509 Important: bind9.16 security update
https://access.redhat.com/errata/RHSA-2026:54509
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54485 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54485
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54662 Moderate: nghttp2 security update
https://access.redhat.com/errata/RHSA-2026:54662
CVE-2026-58055

+ RHSA-2026:54571 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54571
CVE-2026-15816

+ RHSA-2026:54510 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54510
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54487 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54487
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54484 Moderate: python-idna security update
https://access.redhat.com/errata/RHSA-2026:54484
CVE-2026-45409

+ Microsoft Drivers for PHP for SQL Server 5.13.2 released
https://learn.microsoft.com/ja-jp/sql/connect/php/download-drivers-php-sql-server?view=sql-server-ver17

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ Unbounded Memory Growth in QUIC Server Incoming Channel Queue
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-14456
CVE-2026-14456

+ PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24 and 19 Beta 3 Released!
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
https://www.postgresql.org/docs/18/release-18-6.html
https://www.postgresql.org/docs/17/release-17-11.html
https://www.postgresql.org/docs/16/release-16-15.html
https://www.postgresql.org/docs/15/release-15-19.html
https://www.postgresql.org/docs/14/release-14-24.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ランサムウエア攻撃者の侵入経路 脆弱性悪用を抜きメールが首位に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/080500192/?ST=nxt_thmit_security

JVN#00941257 VoiceTraにおける接続先の制限が不適切な脆弱性
https://jvn.jp/jp/JVN00941257/index.html

2026年8月13日木曜日

13日 木曜日、先勝

+ ■PowerDNS Authoritative Serverの脆弱性情報が公開されました (CVE-2026-52682)
https://jprs.jp/tech/security/2026-08-12-powerdns-auth.html

+ ■PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52682)
https://jprs.jp/tech/security/2026-08-12-powerdns-recursor.html

+ RHSA-2026:54371 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:54371
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-54272
CVE-2026-69152
CVE-2026-69192

+ RHSA-2026:54290 Moderate: python-idna security update
https://access.redhat.com/errata/RHSA-2026:54290
CVE-2026-45409

+ RHSA-2026:54272 Important: abrt security update
https://access.redhat.com/errata/RHSA-2026:54272
CVE-2026-54228
CVE-2026-54229
CVE-2026-54230
CVE-2026-54231

+ RHSA-2026:54246 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:54246
CVE-2026-45991
CVE-2026-53009

+ RHSA-2026:54243 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:54243
CVE-2026-33377
CVE-2026-42127

+ RHSA-2026:54268 Important: python3.9 security update
https://access.redhat.com/errata/RHSA-2026:54268
CVE-2026-11940

+ RHSA-2026:54184 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:54184
CVE-2026-42127

+ Google Chrome 152.0.7977.42/.43 released
https://chromereleases.googleblog.com/2026/08/early-stable-update-for-desktop.html

+ Mozilla Firefox 153.0.4 released
https://www.firefox.com/en-US/firefox/153.0.4/releasenotes/

+ Wireshark 4.6.8, 4.4.18 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.8.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.18.html

+ 2026 年 8 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/08/202608-security-update

+ OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース
https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
CVE-2026-73282
CVE-2026-73281
CVE-2026-73283

現場から始めるデータ活用 当事者意識の持ち方・持たせ方
「Excelでこっそり共有」はやめよう 現場のセキュリティー意識が鍵に [第7回]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/022000534/080600007/?ST=nxt_thmit_security

ニュース解説
OpenAIが先端AIのガードレール緩和、一部個人・組織で 中国モデルに危機感
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11962/?ST=nxt_thmit_security

JVNVU#96623328 TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)
https://jvn.jp/vu/JVNVU96623328/index.html

JVNVU#96740507 ECプラットフォーム「Opencart」におけるディレクトリトラバーサルの脆弱性
https://jvn.jp/vu/JVNVU96740507/index.html

JVNVU#98375707 Siemens製品に対するアップデート(2026年8月)
https://jvn.jp/vu/JVNVU98375707/index.html

JVNVU#95587179 CISA ICS Advisory / ICS Medical Advisory(2026年08月11日)
https://jvn.jp/vu/JVNVU95587179/index.html

2026年8月12日水曜日

12日 水曜日、大安

+ RHSA-2026:53848 Important: isns-utils security update
https://access.redhat.com/errata/RHSA-2026:53848
CVE-2026-55995

+ RHSA-2026:53363 Important: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:53363
CVE-2026-59886

+ RHSA-2026:52949 Important: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2026:52949
CVE-2026-8400
CVE-2026-16243
CVE-2026-16439
CVE-2026-16441
CVE-2026-41254
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-47057
CVE-2026-47058
CVE-2026-47059
CVE-2026-47063
CVE-2026-60147

+ RHSA-2026:52772 Important: perl-DBI:1.641 security update
https://access.redhat.com/errata/RHSA-2026:52772
CVE-2026-14380
CVE-2026-14739

+ RHSA-2026:52765 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:52765
CVE-2026-64496

+ RHSA-2026:52396 Important: postgresql:12 security update
https://access.redhat.com/errata/RHSA-2026:52396
CVE-2026-6479

+ RHSA-2026:53847 Important: isns-utils security update
https://access.redhat.com/errata/RHSA-2026:53847
CVE-2026-55995

+ RHSA-2026:53452 Moderate: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:53452
CVE-2026-18649

+ RHSA-2026:53329 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:53329
CVE-2025-54518
CVE-2026-31530
CVE-2026-64368
CVE-2026-64531

+ RHSA-2026:52674 Moderate: libarchive security update
https://access.redhat.com/errata/RHSA-2026:52674
CVE-2026-14164

+ Google Chrome 151.0.7922.137/.138, 150.0.7871.230 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01815628406.html
https://chromereleases.googleblog.com/2026/08/extended-stable-update-for-desktop_01657873926.html

+ Mozilla Thunderbird 153.0.3 released
https://www.thunderbird.net/en-US/thunderbird/153.0.3/releasenotes/

+ OpenSSH 10.5 released
https://www.openssh.org/releasenotes.html#10.5

+ Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27
https://www.postfix.org/announcements/postfix-3.11.6.html

VU#431093 TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
https://www.kb.cert.org/vuls/id/431093

VU#614868 Opencart ecommerce platform contains directory traversal vulnerability
https://www.kb.cert.org/vuls/id/614868

ニュース解説
OpenAI、次世代AI「Astra」の開発を一部停止 高いサイバー攻撃能力を懸念
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11960/?ST=nxt_thmit_security

JVN#40467227 LINE PC版(Windows版)のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN40467227/index.html

JVNVU#91804527 CISA ICS Advisory / ICS Medical Advisory(2026年08月07日)
https://jvn.jp/vu/JVNVU91804527/index.html

JVNVU#95261826 nothingsのstb TrueTypeライブラリにおけるヒープベースのバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU95261826/index.html

2026年8月10日月曜日

10日 月曜日、仏滅

VU#987105 The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
https://www.kb.cert.org/vuls/id/987105

ニュース解説
ニチレイ、サイバー被害で特損10億円も詳細語らず 専門家に聞く公表リスク
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11958/?ST=nxt_thmit_security

2026年8月7日金曜日

7日 金曜日、赤口

+ RHSA-2026:51105 Important: LibRaw security update
https://access.redhat.com/errata/RHSA-2026:51105
CVE-2026-51235

+ RHSA-2026:51035 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:51035
CVE-2026-23415
CVE-2026-43450

+ About the security content of macOS Tahoe 26.6.1
https://support.apple.com/en-us/148170
CVE-2026-65400

+ About the security content of macOS Sequoia 15.7.9
https://support.apple.com/en-us/148171

+ About the security content of macOS Sonoma 14.8.9
https://support.apple.com/en-us/148172

+ Google Chrome 151.0.7922.108/.109, 150.0.7871.224 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html
https://chromereleases.googleblog.com/2026/08/extended-stable-update-for-desktop.html

+ OpenLDAP 2.7.0, 2.6.14 released
https://www.openldap.org/software/release/changes.html
https://www.openldap.org/software/release/changes_lts.html

+ JVNVU#92139835 OpenSSLのOCSPレスポンス検証におけるクライアント側のメモリリークの脆弱性(CVE-2026-54876)
https://jvn.jp/vu/JVNVU92139835/index.html
CVE-2026-54876

VU#487613 Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
https://www.kb.cert.org/vuls/id/487613

ダークサイドAI 第5回
企業AIの「闇落ち」を防げ、擬似的な攻撃でシステムの弱点をあぶり出す
https://xtech.nikkei.com/atcl/nxt/column/18/03673/072700006/?ST=singleview

ニュース解説
Mythosが実在の開発者攻撃 なりすましでマルウエア混入図り、発覚後は弁明
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11952/?ST=nxt_thmit_security

JVNVU#92842469 CISA ICS Advisory / ICS Medical Advisory(2026年08月06日)
https://jvn.jp/vu/JVNVU92842469/index.html

JVNVU#96816564 Alinto SOGo v5.12.7における不正な形式のICSカレンダー招待を介したクロスサイトスクリプティングの脆弱性
https://jvn.jp/vu/JVNVU96816564/index.html

2026年8月6日木曜日

6日 木曜日、大安

+ RHSA-2026:50728 Important: ruby:3.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50728
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50223 Important: Satellite 6.16.12 Async Update
https://access.redhat.com/errata/RHSA-2026:50223
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-48864
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236
CVE-2026-59197

+ RHSA-2026:49927 Moderate: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:49927
CVE-2026-44431

+ RHSA-2026:49922 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:49922
CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412

+ RHSA-2026:49857 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:49857
CVE-2026-52923

+ RHSA-2026:50828 Important: ruby:3.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50828
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50827 Important: ruby:4.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:50827
CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

+ RHSA-2026:50817 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:50817
CVE-2026-42169
CVE-2026-66758
CVE-2026-66759

+ RHSA-2026:50263 Important: Satellite 6.18.8 Async Update
https://access.redhat.com/errata/RHSA-2026:50263
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50223 Important: Satellite 6.16.12 Async Update
https://access.redhat.com/errata/RHSA-2026:50223
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-48864
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236
CVE-2026-59197

+ RHSA-2026:50222 Important: Satellite 6.17.10 Async Update
https://access.redhat.com/errata/RHSA-2026:50222
CVE-2025-9230
CVE-2026-2332
CVE-2026-12515
CVE-2026-48526
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50221 Important: Satellite 6.19.3 Async Update
https://access.redhat.com/errata/RHSA-2026:50221
CVE-2026-2332
CVE-2026-12515
CVE-2026-54059
CVE-2026-54060
CVE-2026-54297
CVE-2026-55379
CVE-2026-55380
CVE-2026-57236

+ RHSA-2026:50108 Important: ldns security update
https://access.redhat.com/errata/RHSA-2026:50108
CVE-2026-10846

+ RHSA-2026:49921 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:49921
CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412

+ RHSA-2026:49838 Important: osbuild-composer security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:49838
CVE-2026-32280
CVE-2026-32281

+ Google Chrome 151.0.7922.75/.76 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop.html

+ Mozilla Firefox 153.0.3 released
https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/

+ Mozilla Thunderbird 153.0.2 released
https://www.thunderbird.net/en-US/thunderbird/153.0.2/releasenotes/

+ OpenSSLの脆弱性(Low: CVE-2026-54876)
https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260806/
CVE-2026-54876

JVN#28045338 NetKids iMarkにおける複数の脆弱性
https://jvn.jp/jp/JVN28045338/index.html

JVNVU#92898025 CISA ICS Advisory / ICS Medical Advisory(2026年08月04日)
https://jvn.jp/vu/JVNVU92898025/index.html

JVNVU#92804348 ロボット掃除機DEEBOT PRO M1、DEEBOT PRO K1VACおよびスマートフォンアプリECOVACS PROにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92804348/index.html

JVN#52865575 freo2におけるアップロードするファイルの検証が不十分な脆弱性
https://jvn.jp/jp/JVN52865575/index.html

ニュース&リポート
ニチレイの東西両センターで障害 不正アクセスの影響を避けられず
冷蔵倉庫の入出庫業務などに支障
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/072801472/?ST=nxt_thmit_security

記者の眼
シャドーAIにとどまらない企業リスク、三菱電機は「見逃し」契機に体制強化
https://xtech.nikkei.com/atcl/nxt/column/18/00138/072302073/?ST=nxt_thmit_security

ニュース解説
企業秘密を出さずにAIを使う、日本発の「秘匿AI」基盤が本格始動
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11948/?ST=nxt_thmit_security

中部電力で個人情報漏洩の可能性、グループ役職員や取引先など7万人超
https://xtech.nikkei.com/atcl/nxt/news/24/03331/?ST=nxt_thmit_security

日経コンピュータ「ITが危ない」
GitHub内部リポジトリーが標的 漏洩リスクは公開版の6倍に
「非公開だから安全」という思い込みが危険
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/072800200/?ST=nxt_thmit_security

データは語る
過半数がペーパーレス化に課題 取引先との商慣習が障壁に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/072800230/?ST=nxt_thmit_security

AIインフラ最前線 第5回
AI活用で高まるセキュリティーリスク、パッチ作成の自動化など防御も強化へ
https://xtech.nikkei.com/atcl/nxt/column/18/03551/073100005/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
ランサムウエア攻撃者の侵入経路、脆弱性悪用を抜き「メール」が首位に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/072900230/?ST=nxt_thmit_security

EPARKリラク&エステに不正アクセス、顧客情報3300万レコードが漏洩の恐れ
https://xtech.nikkei.com/atcl/nxt/news/24/03330/?ST=nxt_thmit_security

サイバーセキュリティ2026決定、対策強化を「日本成長戦略」の大前提に
https://xtech.nikkei.com/atcl/nxt/news/24/03328/?ST=nxt_thmit_security

2026年8月4日火曜日

4日 火曜日、先負

マルウエア徹底解剖
マルウエアの正体を暴くサンドボックス [第80回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/071600081/?ST=nxt_thmit_security

ケーススタディー
ネットワーク刷新しβ’モデルへ移行 ゼロトラスト型で安全性水準を向上
兵庫県太子町
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600004/072800214/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
シミックヘルスケア、受託運営システムで患者情報が流出 公開ファイルから
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900375/?ST=nxt_thmit_security

2026年8月3日月曜日

3日 月曜日、友引

+ RHSA-2026:49524 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49524
CVE-2026-9538

+ RHSA-2026:49511 Important: frr security update
https://access.redhat.com/errata/RHSA-2026:49511
CVE-2026-37460

+ RHSA-2026:49214 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49214
CVE-2026-31692
CVE-2026-43116
CVE-2026-46150
CVE-2026-64530

+ RHSA-2026:49525 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49525
CVE-2026-9538

+ RHSA-2026:49212 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49212
CVE-2026-52923
CVE-2026-52993
CVE-2026-64530

+ Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit
https://cxsecurity.com/issue/WLB-2026080002
CVE-2026-46215

VU#243636 VPS.org one-click deployment templates contain multiple vulnerabilities
https://www.kb.cert.org/vuls/id/243636

JVNVU#98879231 三菱電機製複数製品で使用しているCC-Link IE TSN通信プロトコルにおける通信チャネルで送受信するメッセージに対する完全性の検証不備に起因する脆弱性
https://jvn.jp/vu/JVNVU98879231/index.html

JVN#72334274 サイボウズ Garoonにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN72334274/index.html

JVNVU#91736352 VPS.orgのone-click deploymentテンプレートにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91736352/index.html

JVNVU#92540957 シャープ製ネットワークスキャナーツールの初期設定がセキュアでない問題
https://jvn.jp/vu/JVNVU92540957/index.html

JVNVU#98759887 シャープ製および東芝テック製複合機(MFP)における複数の脆弱性
https://jvn.jp/vu/JVNVU98759887/index.html

JVNVU#97496464 CISA ICS Advisory / ICS Medical Advisory(2026年07月30日)
https://jvn.jp/vu/JVNVU97496464/index.html

JVNVU#90278463 SGLangにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90278463/index.html

JVNVU#92804348 ロボット掃除機DEEBOT PRO M1、DEEBOT PRO K1VACおよびスマートフォンアプリECOVACS PROにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92804348/index.html

JVNVU#94952030 BaserCMSにおけるCSVファイルインジェクションの脆弱性
https://jvn.jp/vu/JVNVU94952030/index.html

キーワード
Shadow AI(シャドーAI)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/072800228/?ST=nxt_thmit_security

フォーカス
AIエージェントのリスク ID管理とログで統制
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/072800233/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
デジタル庁などが仕様に疑義 マイナ署名関連の一部機能を停止
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/072800212/?ST=nxt_thmit_security

ニュース解説
AnthropicのAIも他社侵入、しかも3件 設定ミスでネットアクセス可能に
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11940/?ST=nxt_thmit_security

2026年7月31日金曜日

31日 金曜日、大安

+ RHSA-2026:48790 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:48790
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283
CVE-2026-33186
CVE-2026-34986

+ RHSA-2026:48703 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:48703
CVE-2026-55693
CVE-2026-57455
CVE-2026-57456
CVE-2026-59858

+ RHSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:48197
CVE-2026-14355

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ PHP 8.4.24, 8.3.33 released
https://www.php.net/ChangeLog-8.php#8.4.24
https://www.php.net/ChangeLog-8.php#8.3.33

VU#281278 SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
https://www.kb.cert.org/vuls/id/281278

VU#790363 foreUP golf management platform's web API contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/790363

JVNVU#91587639 Develar製app-builder(zipx.Unzip)における任意のファイルが上書きされる脆弱性
https://jvn.jp/vu/JVNVU91587639/index.html

JVNVU#98815601 トレンドマイクロ製TrendAI Vision Oneに対するセキュリティアップデート(2026年7月)
https://jvn.jp/vu/JVNVU98815601/index.html

月刊ランサムリポート
2026年5月の被害件数は876件で減少傾向 NightSpireは「Mimikatz」悪用して攻撃
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/071600018/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIによる「ランサムウエア攻撃」 侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/072300191/?ST=nxt_thmit_security

どうするSCS評価制度 第2回
SCS評価制度で「チェックシート地獄」は解消できるか、今取り組める2点
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800001/?ST=nxt_thmit_security

月刊ランサムリポート 第20回
ランサムグループ「INC」の存在感が強まる、Citrix Bleedを悪用
https://xtech.nikkei.com/atcl/nxt/column/18/03053/072900021/?ST=nxt_thmit_security

ニュース解説
GPT「暴走」にMicrosoftナデラCEOが言及、単一モデルへの依存に警鐘
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11933/?ST=nxt_thmit_security

2026年7月30日木曜日

30日 木曜日、仏滅

+ Gpg4win 5.1.0 released
https://www.gpg4win.org/change-history.html

+ RHSA-2026:48225 Important: perl:5.32 security update
https://access.redhat.com/errata/RHSA-2026:48225
CVE-2026-9538

+ RHSA-2026:47998 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47998
CVE-2026-64600

+ RHSA-2026:47750 Low: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47750
CVE-2026-14355

+ RHSA-2026:47749 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47749
CVE-2026-14355

+ RHSA-2026:47731 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:47731
CVE-2026-59691
CVE-2026-59692

+ RHSA-2026:47981 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47981
CVE-2026-64600

+ Google Chrome 151.0.7922.71/.72 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

+ Zabbix 7.4.13 released
https://www.zabbix.com/rn/rn7.4.13

+ FreeBSD-SA-26:55.elf  Race condition in ELF core dump segment counting
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:55.elf.asc
CVE-2026-58088

+ FreeBSD-SA-26:54.sysvsem Heap out-of-bounds access in semctl(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:54.sysvsem.asc
CVE-2026-58087

+ FreeBSD-SA-26:53.ktrace ktrace(2) privilege incorrectly validated in jails
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:53.ktrace.asc
CVE-2026-58086

+ FreeBSD-SA-26:52.if_wg Missing MAC validation in wg(4) packet decryption
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc
CVE-2026-58085

+ FreeBSD-SA-26:51.ktimer Kernel stack disclosure via timer_settime(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:51.ktimer.asc
CVE-2026-58084

+ FreeBSD-SA-26:50.kqueue Use-after-free in kqueue copy-on-fork
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:50.kqueue.asc
CVE-2026-58083

+ JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html
CVE-2026-66299

VU#293714 Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
https://www.kb.cert.org/vuls/id/293714

VU#305509 OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
https://www.kb.cert.org/vuls/id/305509

変貌するCDN 第4回
CDNを使うにはDNSから設定する、キャッシュからの情報流出に要注意
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200004/?ST=nxt_thmit_security

どうするSCS評価制度
経産省などが注意喚起、SCS評価制度の開始前に起きた不適切な勧誘
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800002/?ST=nxt_thmit_security

ニュース解説
AI攻撃にAIで対抗、Microsoftが新システム サイバー防御の独自モデルも
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11930/?ST=nxt_thmit_security

JVN#99975039 てがろぐ -Fumy Otegaru Memo Logger-における制限が不十分な正規表現を使用している脆弱性
https://jvn.jp/jp/JVN99975039/index.html

2026年7月29日水曜日

29日 水曜日、先負

+ ■Knot Resolverの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-07-28-knotresolver.html

+ RHSA-2026:47105 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:47105
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412
CVE-2026-56208

+ RHSA-2026:47060 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:47060
CVE-2026-13149
CVE-2026-59873
CVE-2026-59874

+ RHSA-2026:47011 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:47011
CVE-2026-53006

+ RHSA-2026:46990 Important: sssd security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:46990
CVE-2026-14474
CVE-2026-14476

+ Google Chrome 150.0.7871.212 released
https://chromereleases.googleblog.com/2026/07/extended-stable-updates-for-desktop.html

+ Mozilla Firefox 153.0.1 released
https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/

+ Zabbix 7.0.29, 6.0.48 released
https://www.zabbix.com/rn/rn7.0.29
https://www.zabbix.com/rn/rn6.0.48

VU#141367 AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface
https://www.kb.cert.org/vuls/id/141367

変貌するCDN 第3回
セキュリティーからエッジAIまで、「仲介」機能を生かして拡大するCDN
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200003/?ST=nxt_thmit_security

UPDATE: JVN#03037325 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年5月)
https://jvn.jp/jp/JVN03037325/index.html

JVN#24885537 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性
https://jvn.jp/jp/JVN24885537/index.html

JVN#56870912 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年7月)
https://jvn.jp/jp/JVN56870912/index.html

2026年7月28日火曜日

28日 火曜日、友引

+ ■PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52688、CVE-2026-52686)
https://jprs.jp/tech/security/2026-07-27-powerdns-recursor.html

+ About the security content of iOS 26.6 and iPadOS 26.6
https://support.apple.com/en-us/128066
CVE-2026-64733
CVE-2026-43801
CVE-2026-28928
CVE-2026-43776
CVE-2026-64725
CVE-2026-43730
CVE-2026-64747
CVE-2026-64707
CVE-2026-43811
CVE-2026-43813
CVE-2026-64746
CVE-2026-64734
CVE-2026-43797
CVE-2026-43673
CVE-2026-43744
CVE-2026-43803
CVE-2026-43711
CVE-2026-3784
CVE-2026-3783
CVE-2026-43753
CVE-2026-43714
CVE-2026-64742
CVE-2026-64740
CVE-2026-43796
CVE-2026-64692
CVE-2026-43780
CVE-2026-43818
CVE-2026-64716
CVE-2026-64758
CVE-2026-64754
CVE-2026-64693
CVE-2026-43805
CVE-2026-64749
CVE-2026-43778
CVE-2026-64709
CVE-2026-64735
CVE-2026-43739
CVE-2026-43816
CVE-2026-43822
CVE-2026-64729
CVE-2026-43814
CVE-2026-64700
CVE-2026-43799
CVE-2026-28931
CVE-2026-43817
CVE-2026-43769
CVE-2026-43810
CVE-2026-64775
CVE-2026-64720
CVE-2026-64751
CVE-2026-64721
CVE-2026-4424
CVE-2026-28973
CVE-2026-64739
CVE-2026-64743
CVE-2026-64724
CVE-2026-43723
CVE-2026-43733
CVE-2026-43729
CVE-2026-64772
CVE-2026-64771
CVE-2026-64722
CVE-2026-64774
CVE-2026-64770
CVE-2026-64769
CVE-2026-64768
CVE-2026-64711
CVE-2026-43812
CVE-2026-64741
CVE-2026-64766
CVE-2026-64765
CVE-2026-64764
CVE-2026-64763
CVE-2026-43800
CVE-2026-43740
CVE-2026-64713
CVE-2026-64730
CVE-2026-64728
CVE-2026-64783
CVE-2026-64757
CVE-2026-43804
CVE-2026-43821
CVE-2026-64718
CVE-2026-64719
CVE-2026-64726
CVE-2026-64755

+ About the security content of macOS Tahoe 26.6
https://support.apple.com/en-us/128067

+ About the security content of macOS Sequoia 15.7.8
https://support.apple.com/en-us/128071

+ About the security content of macOS Sonoma 14.8.8
https://support.apple.com/en-us/128072

+ About the security content of tvOS 26.6
https://support.apple.com/en-us/128069

+ About the security content of watchOS 26.6
https://support.apple.com/en-us/128068

+ About the security content of visionOS 26.6
https://support.apple.com/en-us/128070

+ About the security content of Safari 26.6
https://support.apple.com/en-us/128073

NEWS close-up
注目高まる「SCS評価制度」
Interopでも売り文句が飛び交った PマークやISMSと何が違うのか
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/071700334/?ST=nxt_thmit_security

変貌するCDN 第2回
CDNで「近い」サーバーに通信を導く仕組み、DNSとBGPを活用
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
日本交通、流出疑いの情報をネット上で確認 マルウエア感染で電話配車停止
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900374/?ST=nxt_thmit_security

2026年7月27日月曜日

27日 月曜日、先勝

+ ■Unboundの脆弱性情報が公開されました(CVE-2026-14586、他23件)
https://jprs.jp/tech/security/2026-07-24-unbound.html

+ RHSA-2026:46396 Important: libreswan security update
https://access.redhat.com/errata/RHSA-2026:46396
CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722

+ RHSA-2026:46391 Important: grafana security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:46391
CVE-2026-44740

+ RHSA-2026:45115 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:45115
CVE-2025-40026
CVE-2026-52993
CVE-2026-53059

+ RHSA-2026:46397 Important: libreswan security update
https://access.redhat.com/errata/RHSA-2026:46397
CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722

+ RHSA-2026:45192 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:45192
CVE-2025-40026
CVE-2026-52950
CVE-2026-52976
CVE-2026-53006
CVE-2026-53059

+ Mozilla Thunderbird 153.0.1 released
https://www.thunderbird.net/en-US/thunderbird/153.0.1esr/releasenotes/

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ Linux Kernelの脆弱性(RefluXFS:CVE-2026-64600)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260724/
CVE-2026-64600

JVNVU#93636354 CISA ICS Advisory / ICS Medical Advisory(2026年07月23日)
https://jvn.jp/vu/JVNVU93636354/index.html

JVNVU#99418634 Silverhand製Logtoにおける認証や認可に影響する複数の脆弱性
https://jvn.jp/vu/JVNVU99418634/index.html

piyokangoの月刊システムトラブル
UPSIDERに不正アクセス サプライチェーン攻撃に遭う
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/071600089/?ST=nxt_thmit_security

変貌するCDN 第1回
今やコンテンツ配信だけではないCDN、Web発展とともに多機能化
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200001/?ST=nxt_thmit_security

吉川孝志のマルウエア徹底解剖 第30回
生成AI時代に重要性が高まるサンドボックス、仕組みから包括的に解説する
https://xtech.nikkei.com/atcl/nxt/column/18/02805/071700031/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
「電話と紙」で育った技術記者が顧みる、情報収集方法の変遷
https://xtech.nikkei.com/atcl/nxt/column/18/02598/071700035/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第4回
セキュリティー要件の抜け漏れを防ぐ鉄則、まず検討項目を洗い出す
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800004/?ST=nxt_thmit_security

2026年7月24日金曜日

24日 金曜日、仏滅

+ Google Chrome 150.0.7871.186/.187 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

VU#492466 Logto Identity Platform has authentication and authorization failures in core protocol handling
https://www.kb.cert.org/vuls/id/492466

LLMを適所で生かす、セキュリティーの要件定義 第3回
要件決めの前に「保護ニーズ」を知ろう、対策のジャンルはLLMで把握
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800003/?ST=nxt_thmit_security

2026年7月23日木曜日

23日 木曜日、先負

+ ■(緊急)BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-13321)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-13204)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsecandnsec3.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-12617)
  - バージョンアップを強く推奨 -

https://jprs.jp/tech/security/2026-07-23-bind9-vuln-dnameandcname.html

+ ■(緊急)BIND 9.xの脆弱性(DNSキャッシュポイズニングの危険性)について(CVE-2026-11721)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-wildcard.html

+ ■(緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-11622)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-randomsubdomain.html

+ ■(緊急)BIND 9.xの脆弱性(過剰なCPU負荷の誘発)について(CVE-2026-11605)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-validation.html

+ ■(緊急)BIND 9.xの脆弱性(RPZの設定のバイパス、DNSサービスの停止)について(CVE-2026-11331)
 - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-rpz.html

+ ■BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-10822)
  - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、
    バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-privatedns.html

+ ■BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-10723)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec3.html

+ Google Chrome 151.0.7922.47/.48, 150.0.7871.181/.182 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop_01571975877.html
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html

+ Mozillf Firefox 153.0 released
https://www.firefox.com/en-US/firefox/153.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-68 Security Vulnerabilities fixed in Firefox 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
CVE-2026-16349
CVE-2026-16350
CVE-2026-16362
CVE-2026-16351
CVE-2026-16352
CVE-2026-16363
CVE-2026-16364
CVE-2026-16365
CVE-2026-16366
CVE-2026-16353
CVE-2026-16354
CVE-2026-16367
CVE-2026-16368
CVE-2026-16369
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16370
CVE-2026-16371
CVE-2026-16372
CVE-2026-16373
CVE-2026-16374
CVE-2026-16375
CVE-2026-16376
CVE-2026-16377
CVE-2026-16378
CVE-2026-16379
CVE-2026-16358
CVE-2026-16380
CVE-2026-16381
CVE-2026-16382
CVE-2026-16383
CVE-2026-16384
CVE-2026-16385
CVE-2026-16386
CVE-2026-16387
CVE-2026-16388
CVE-2026-16389
CVE-2026-16390
CVE-2026-16391
CVE-2026-16392
CVE-2026-16393
CVE-2026-16359
CVE-2026-16394
CVE-2026-16395
CVE-2026-16396
CVE-2026-16397
CVE-2026-16398
CVE-2026-16399
CVE-2026-16400
CVE-2026-16401
CVE-2026-16402
CVE-2026-16403
CVE-2026-16404
CVE-2026-16405
CVE-2026-16406
CVE-2026-16407
CVE-2026-16408
CVE-2026-16409
CVE-2026-16410
CVE-2026-16411
CVE-2026-16412
CVE-2026-16360

+ Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/

+ Mozilla Foundation Security Advisory 2026-69 Security Vulnerabilities fixed in Firefox ESR 115.38
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/

+ Mozilla Foundation Security Advisory 2026-71 Security Vulnerabilities fixed in Thunderbird 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/

+ Mozilla Foundation Security Advisory 2026-72 Security Vulnerabilities fixed in Thunderbird 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/

+ Mozilla Thunderbird 153.0 released
https://www.thunderbird.net/en-US/thunderbird/153.0esr/releasenotes/

+ ISC BIND 9.20.26 released
https://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html

+ Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html
CVE-2026-10723
CVE-2026-10822
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321

+ Linux Kernelの脆弱性(IPV6_FRAG_ESCAPE: CVE-2026-53362, CVE-2026-53366)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260723/
CVE-2026-53362
CVE-2026-53366

+ BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260723/
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
CVE-2026-10723
CVE-2026-10822

+ Microsoft Edge <= 150.0.4078.48 (Chromium-based) Type Confusion RCE
https://cxsecurity.com/issue/WLB-2026070009
CVE-2026-58289

VU#847406 Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
https://www.kb.cert.org/vuls/id/847406

VU#360868 Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability
https://www.kb.cert.org/vuls/id/360868

VU#762226 Plane contains multi-tenant authorization bypass vulnerability
https://www.kb.cert.org/vuls/id/762226

JVNVU#98636554 バックアップソフトウェア「Duplicati」における不適切な権限割り当てに関する脆弱性
https://jvn.jp/vu/JVNVU98636554/index.html

JVNVU#98875819 Analog Way製メディアサーバー「Picturall Quad Compact Mark II」におけるローカル権限昇格の脆弱性
https://jvn.jp/vu/JVNVU98875819/index.html

JVN#32082029 リコー製プリンターおよび複合機のSSH通信機能におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN32082029/index.html

JVNVU#90683587 プロジェクト管理ツール「Plane」における認可回避の脆弱性
https://jvn.jp/vu/JVNVU90683587/index.html

JVNVU#98832565 CISA ICS Advisory / ICS Medical Advisory(2026年07月21日)
https://jvn.jp/vu/JVNVU98832565/index.html

JVN#20592637 Drupalプラグイン「AI Agents」における不正な認証の脆弱性
https://jvn.jp/jp/JVN20592637/index.html

JVN#40509781 非接触型ICカード技術FeliCaの一部のICチップにおける脆弱性
https://jvn.jp/jp/JVN40509781/index.html

ニュース&リポート
26年度末開始「SCS評価制度」に脚光 供給網のサイバー対策を客観評価
展示会Interopで関連サービスが多数出展
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/071301466/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第2回
セキュリティー要件は6ステップで定義 LLMを生かしてまずは脅威を理解
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800002/?ST=nxt_thmit_security

ニュース解説
OpenAIのモデルが他社システムに侵入、ゼロデイ悪用でサンドボックス脱出
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11912/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェントによる「ランサムウエア攻撃」出現、侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/column/18/00676/071100229/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第1回
「残念なセキュリティー」を招く要件定義の落とし穴、3大パターンを紹介
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800001/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
顧客情報1354万件漏洩の恐れ SSD紛失、例外運用のリスク露呈
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/071300211/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
シード・プランニング、PHP脆弱性でランサムウエア被害 影響範囲を廃棄
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900373/?ST=nxt_thmit_security

2026年7月17日金曜日

17日 金曜日、先負

+ RHSA-2026:40894 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40894
CVE-2026-14544

+ RHSA-2026:40841 Important: maven:3.8 security update
https://access.redhat.com/errata/RHSA-2026:40841
CVE-2025-67030

+ RHSA-2026:40895 Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
https://access.redhat.com/errata/RHSA-2026:40895
CVE-2026-54512
CVE-2026-54513

+ RHSA-2026:40831 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40831
CVE-2026-14544

+ RHSA-2026:40751 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:40751
CVE-2026-58380
CVE-2026-58384

+ Google Chrome 150.0.7871.128/.129 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html

+ Oracle Critical Patch Update Pre-Release Announcement - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVN#65294474 Tera TermのTTSSH2プラグインにおける複数の脆弱性
https://jvn.jp/jp/JVN65294474/index.html
CVE-2026-58317
CVE-2026-60060

+ JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html
CVE-2026-59083
CVE-2026-59084

VU#885548 Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
https://www.kb.cert.org/vuls/id/885548

VU#326070 SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
https://www.kb.cert.org/vuls/id/326070

JVNVU#90340653 Pegatron製Windows Driver Model (WDM) ドライバー「Tdelo64.sys」における複数の脆弱性
https://jvn.jp/vu/JVNVU90340653/index.html

JVNVU#98998987 JavaScriptライブラリ「Forge」における複数の署名検証不備の脆弱性
https://jvn.jp/vu/JVNVU98998987/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
「AI駆動型ワーム」の脅威 自律的に脆弱性を見つけて感染
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/070700190/?ST=nxt_thmit_security

基礎から分かる、AIエージェントのセキュリティー設計 第3回
何をどう判断しどう行動したのか、AIエージェントを「追跡」するログ設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000003/?ST=nxt_thmit_security

2026年7月16日木曜日

16日 木曜日、友引

+ RHSA-2026:39893 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39893
CVE-2026-15308

+ RHSA-2026:39868 Important: nodejs:24 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39868
CVE-2026-6733
CVE-2026-6734
CVE-2026-9678
CVE-2026-9697
CVE-2026-11525
CVE-2026-12151
CVE-2026-42338
CVE-2026-48615
CVE-2026-48618
CVE-2026-48619
CVE-2026-48928
CVE-2026-48930
CVE-2026-48933
CVE-2026-48934
CVE-2026-48935

+ RHSA-2026:39575 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39575
CVE-2026-12505

+ RHSA-2026:40416 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:40416
CVE-2026-14355

+ RHSA-2026:39879 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:39879
CVE-2026-27145
CVE-2026-39821

+ RHSA-2026:39810 Important: Red Hat OpenStack Services on OpenShift 18.0 (golang-github-openstack-k8s-operators-os-diff) security update
https://access.redhat.com/errata/RHSA-2026:39810
CVE-2025-61726
CVE-2025-61729
CVE-2026-25679
CVE-2026-27137
CVE-2026-32280
CVE-2026-32281
CVE-2026-32282
CVE-2026-32283
CVE-2026-33810
CVE-2026-33811

+ RHSA-2026:39798 Important: python3.9 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39798
CVE-2026-15308

+ RHSA-2026:39771 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39771
CVE-2026-15308

+ RHSA-2026:39576 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39576
CVE-2026-12505

+ Google Chrome 151.0.7922.34/.35 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop.html

+ Mozilla Firefox 152.0.6 released
https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/

+ nginx 1.31.3. 1.30.4 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.30

+ K000162097: NGINX map directive and regex matching vulnerability CVE-2026-42533
https://my.f5.com/manage/s/article/K000162097
CVE-2026-42533

+ K000162100: NGINX ngx_http_slice_module vulnerability CVE-2026-60005
https://my.f5.com/manage/s/article/K000162100
CVE-2026-60005

+ K000162098: NGINX ngx_http_ssi_module vulnerability CVE-2026-56434
https://my.f5.com/manage/s/article/K000162098
CVE-2026-56434

+ Apache PDFBox 2.0.37 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12356771

VU#529388 Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys
https://www.kb.cert.org/vuls/id/529388

VU#725167 node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations
https://www.kb.cert.org/vuls/id/725167

基礎から分かる、AIエージェントのセキュリティー設計 第2回
AIエージェントのID管理に4つの課題、過剰な権限を持たせず「小さく」設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000002/?ST=nxt_thmit_security

ニュース解説
ニチレイ不正アクセス「東西両センターで障害」、井村屋は15日分納品を中止
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11899/?ST=nxt_thmit_security

JVN#59875262 HYPER SBI 2のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN59875262/index.html

JVNVU#91295052 Siemens製品に対するアップデート(2026年7月)
https://jvn.jp/vu/JVNVU91295052/index.html

JVNVU#91675472 CISA ICS Advisory / ICS Medical Advisory(2026年07月14日)
https://jvn.jp/vu/JVNVU91675472/index.html

2026年7月15日水曜日

15日 水曜日、先勝

+ RHSA-2026:39320 Important: python3 security update
https://access.redhat.com/errata/RHSA-2026:39320
CVE-2026-15308

+ RHSA-2026:39266 Important: git-lfs security update
https://access.redhat.com/errata/RHSA-2026:39266
CVE-2026-33811

+ RHSA-2026:39127 Important: python-pillow security update
https://access.redhat.com/errata/RHSA-2026:39127
CVE-2026-54059
CVE-2026-54060
CVE-2026-55379
CVE-2026-55380

+ RHSA-2026:39083 Important: kernel update
https://access.redhat.com/errata/RHSA-2026:39083
CVE-2025-71066
CVE-2025-71089
CVE-2026-31411
CVE-2026-43499
CVE-2026-46113
CVE-2026-53166
CVE-2026-53266
CVE-2026-53359

+ RHSA-2026:38995 Important: go-toolset:rhel8 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:38995
CVE-2026-27145
CVE-2026-39821
CVE-2026-39822

+ RHSA-2026:38901 Important: perl-DBI:1.641 security update
https://access.redhat.com/errata/RHSA-2026:38901
CVE-2026-9698

+ RHSA-2026:38847 Important: nginx:1.24 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:38847
CVE-2026-42055

+ RHSA-2026:38488 Important: xorg-x11-server-Xwayland security update
https://access.redhat.com/errata/RHSA-2026:38488
CVE-2026-55999

+ RHSA-2026:38485 Important: gegl security update
https://access.redhat.com/errata/RHSA-2026:38485
CVE-2026-2050

+ RHSA-2026:39553 Important: perl-XML-LibXML security update
https://access.redhat.com/errata/RHSA-2026:39553
CVE-2026-8177

+ RHSA-2026:39319 Important: git-lfs security update
https://access.redhat.com/errata/RHSA-2026:39319
CVE-2026-33811

+ RHSA-2026:39309 Low: capstone security update
https://access.redhat.com/errata/RHSA-2026:39309
CVE-2025-68114

+ RHSA-2026:38493 Important: buildah security update
https://access.redhat.com/errata/RHSA-2026:38493
CVE-2026-39822

+ RHSA-2026:38490 Important: xorg-x11-server-Xwayland security update
https://access.redhat.com/errata/RHSA-2026:38490
CVE-2026-55999
CVE-2026-56000

+ Google Chrome 150.0.7871.124/.125 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html

+ Mozilla Foundation Security Advisory 2026-67 Security Vulnerabilities fixed in Firefox 152.0.6
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
CVE-2026-15718
CVE-2026-15719

+ 2026 年 7 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/07/202607-security-update

基礎から分かる、AIエージェントのセキュリティー設計 第1回
AIエージェントは何が「危ない」のか、自律レベルとリスクの関係を理解する
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000001/?ST=nxt_thmit_security

2026年7月14日火曜日

14日 火曜日、赤口

+ JVNVU#94203999 GNU Wgetにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/vu/JVNVU94203999/index.html
CVE-2026-15146

JVNVU#94039788 iOS版LINEにおけるサービス運用妨害(DoS)につながる脆弱性
https://jvn.jp/vu/JVNVU94039788/index.html

piyokangoの週刊システムトラブル
オーミケンシ、有価証券報告書の提出延期 VPN経由侵入で基幹システム停止
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900372/?ST=nxt_thmit_security

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第4回
アサヒなど被害企業20社超の再発防止策を分析、レジリエンス重視が鮮明に
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800004/?ST=nxt_thmit_security

2026年7月13日月曜日

13日 月曜日、先負

+ Apache PDFBox 3.0.8 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12356674

VU#564823 GNU Wget enables SSRF via unvalidated FTP PASV IPs
https://www.kb.cert.org/vuls/id/564823

JVNVU#91295052 Siemens製品に対するアップデート(2026年7月)
https://jvn.jp/vu/JVNVU91295052/index.html

JVNVU#94281476 CISA ICS Advisory / ICS Medical Advisory(2026年07月09日)
https://jvn.jp/vu/JVNVU94281476/index.html

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第3回
サイバー攻撃の損失を新たに28社が計上、アサヒらの影響で総額は236億円に
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800003/?ST=nxt_thmit_security

2026年7月10日金曜日

10日 金曜日、赤口

+ gawk 5.4.1 released
https://ftp.gnu.org/gnu/gawk/?C=M;O=D

+ RHSA-2026:37282 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:37282
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-44390

+ RHSA-2026:37130 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:37130
CVE-2026-52720
CVE-2026-52722

+ RHSA-2026:37435 Important: golang security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:37435
CVE-2026-39821
CVE-2026-39822

+ RHSA-2026:37410 Important: buildah security update
https://access.redhat.com/errata/RHSA-2026:37410
CVE-2026-39832
CVE-2026-39835

+ RHSA-2026:37207 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:37207
CVE-2026-45700

+ RHSA-2026:37123 Important: podman security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:37123
CVE-2026-25681
CVE-2026-27136
CVE-2026-39829
CVE-2026-39832
CVE-2026-39835
CVE-2026-42508
CVE-2026-57231

+ RHSA-2026:36957 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:36957
CVE-2025-71066
CVE-2026-46113
CVE-2026-53359

+ Wireshark 4.6.7, 4.4.17 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.7.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.17.html

VU#152953 PayRange Android app version 7.0.7 contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/152953

VU#734812 Xerte Online Toolkit contains an authentication bypass that allows for RCE
https://www.kb.cert.org/vuls/id/734812

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第2回
サイバー詐欺で18社が損失を計上 海外拠点で頻発、支払い統制がカギか
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800002/?ST=nxt_thmit_security

JVNVU#99220646 Adalo App Builderにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99220646/index.html

JVN#48718197 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)における反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN48718197/index.html

2026年7月9日木曜日

9日 木曜日、大安

+ RHSA-2026:36774 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:36774
CVE-2026-53705

+ RHSA-2026:36732 Moderate: python-urllib3 security update
https://access.redhat.com/errata/RHSA-2026:36732
CVE-2026-44431

+ RHSA-2026:36734 Low: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:36734
CVE-2025-6170

+ RHSA-2026:36733 Moderate: cups security update
https://access.redhat.com/errata/RHSA-2026:36733
CVE-2026-34980

+ RHSA-2026:36728 Low: libtasn1 security update
https://access.redhat.com/errata/RHSA-2026:36728
CVE-2025-13151

+ RHSA-2026:36530 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:36530
CVE-2026-23401
CVE-2026-31402
CVE-2026-31419

+ RHSA-2026:36879 Important: tomcat security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:36879
CVE-2026-29146
CVE-2026-34486

+ RHSA-2026:36832 Important: libreoffice security update
https://access.redhat.com/errata/RHSA-2026:36832
CVE-2026-8357

+ RHSA-2026:36777 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:36777
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-44390

+ RHSA-2026:36674 Moderate: gstreamer1-plugins-ugly-free security update
https://access.redhat.com/errata/RHSA-2026:36674
CVE-2026-53703
CVE-2026-53704

+ RHSA-2026:36617 Important: oci-seccomp-bpf-hook security update
https://access.redhat.com/errata/RHSA-2026:36617
CVE-2026-33811

+ Google Chrome 150.0.7871.114/.115 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html

+ Apache Tomcat 11.0.24, 10.1.57 Released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.24_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.57_(schultz)

+ ProFTPD 1.3.9c released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9c
http://www.proftpd.org/docs/NEWS-1.3.9c

+ OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース
https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/
CVE-2026-59995
CVE-2026-59996
CVE-2026-59997
CVE-2026-59998
CVE-2026-59999

VU#849433 Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls
https://www.kb.cert.org/vuls/id/849433

JVN#62347140 富士電機製Pupsmanのインストーラにおける複数の脆弱性
https://jvn.jp/jp/JVN62347140/index.html

JVNVU#92734392 CISA ICS Advisory / ICS Medical Advisory(2026年07月07日)
https://jvn.jp/vu/JVNVU92734392/index.html

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第1回
出光は36億円を損失か、ランサム並みに深刻な「サイバー詐欺」の実態
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800001/?ST=nxt_thmit_security

3分でわかる必修ワード IT
万全の対策は難しい「シャドーAI」、企業はガバナンスやルール整備を進める
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/070600320/?ST=nxt_thmit_security

2026年7月8日水曜日

8日 水曜日、仏滅

+ RHSA-2026:36366 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:36366
CVE-2026-43112

+ RHSA-2026:36349 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:36349
CVE-2025-10263
CVE-2026-43198
CVE-2026-43450
CVE-2026-46209
CVE-2026-46227
CVE-2026-46259

+ RHSA-2026:36307 Moderate: freeipmi security update
https://access.redhat.com/errata/RHSA-2026:36307
CVE-2026-50031

+ RHSA-2026:36215 Important: compat-openssl10 security update
https://access.redhat.com/errata/RHSA-2026:36215
CVE-2026-45447

+ RHSA-2026:36201 Important: 389-ds:1.4 security update
https://access.redhat.com/errata/RHSA-2026:36201
CVE-2026-11610
CVE-2026-11774

+ RHSA-2026:36315 Important: python3.14-pip security update
https://access.redhat.com/errata/RHSA-2026:36315
CVE-2026-8643

+ RHSA-2026:36210 Moderate: freeipmi security update
https://access.redhat.com/errata/RHSA-2026:36210
CVE-2026-50031

+ RHSA-2026:36195 Important: 389-ds-base security update
https://access.redhat.com/errata/RHSA-2026:36195
CVE-2026-11610
CVE-2026-11774

+ RHSA-2026:36172 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:36172
CVE-2026-31419

+ Google Chrome 150.0.7871.100/.101 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop.html

+ Mozilla Firefox 152.0.5 released
https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/

+ Zabbix 7.0.28, 6.0.47 released
https://www.zabbix.com/rn/rn7.0.28
https://www.zabbix.com/rn/rn6.0.47

+ Apache Tomcat 9.0.120 Released
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.120_(remm)

+ Linux Kernelの脆弱性(Januscape: CVE-2026-53359)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260707/
CVE-2026-53359

UPDATE: JVN#90566559 Apache Jena Fusekiにおけるパストラバーサルの脆弱性
https://jvn.jp/jp/JVN90566559/index.html

JVN#87285119 複数のセイコーエプソン製プリンターおよびスキャナーのWeb Configにおけるクロスサイトリクエストフォージェリの脆弱性
https://jvn.jp/jp/JVN87285119/index.html

JVNVU#93316066 Tenda製品の複数のファームウェアにおけるセキュリティ上問題のある隠し機能の脆弱性
https://jvn.jp/vu/JVNVU93316066/index.html

JVNVU#90409906 HP Deskjet 2800プリンターシリーズにおける認証不備の脆弱性
https://jvn.jp/vu/JVNVU90409906/index.html

日経コンピュータ「ITが危ない」
シャドーAIのリスクが顕在化 国内企業の7割超が対策できず
放置で情報漏洩・法令違反のリスクも
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/070100198/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
「AI駆動型ワーム」の脅威 自律的に脆弱性を見つけて感染、特定率は8割超
https://xtech.nikkei.com/atcl/nxt/column/18/00676/070100228/?ST=nxt_thmit_security

KDDIメール基盤から1223万人分のアドレス漏洩、ソフト会社も脆弱性認識せず
https://xtech.nikkei.com/atcl/nxt/news/24/03297/?ST=nxt_thmit_security