+ ■(緊急)BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-13321)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec.html
+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-13204)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsecandnsec3.html
+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-12617)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-dnameandcname.html
+ ■(緊急)BIND 9.xの脆弱性(DNSキャッシュポイズニングの危険性)について(CVE-2026-11721)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-wildcard.html
+ ■(緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-11622)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-randomsubdomain.html
+ ■(緊急)BIND 9.xの脆弱性(過剰なCPU負荷の誘発)について(CVE-2026-11605)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-validation.html
+ ■(緊急)BIND 9.xの脆弱性(RPZの設定のバイパス、DNSサービスの停止)について(CVE-2026-11331)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-rpz.html
+ ■BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-10822)
- フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、
バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-privatedns.html
+ ■BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-10723)
- バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec3.html
+ Google Chrome 151.0.7922.47/.48, 150.0.7871.181/.182 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop_01571975877.html
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
+ Mozillf Firefox 153.0 released
https://www.firefox.com/en-US/firefox/153.0/releasenotes/
+ Mozilla Foundation Security Advisory 2026-68 Security Vulnerabilities fixed in Firefox 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
CVE-2026-16349
CVE-2026-16350
CVE-2026-16362
CVE-2026-16351
CVE-2026-16352
CVE-2026-16363
CVE-2026-16364
CVE-2026-16365
CVE-2026-16366
CVE-2026-16353
CVE-2026-16354
CVE-2026-16367
CVE-2026-16368
CVE-2026-16369
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16370
CVE-2026-16371
CVE-2026-16372
CVE-2026-16373
CVE-2026-16374
CVE-2026-16375
CVE-2026-16376
CVE-2026-16377
CVE-2026-16378
CVE-2026-16379
CVE-2026-16358
CVE-2026-16380
CVE-2026-16381
CVE-2026-16382
CVE-2026-16383
CVE-2026-16384
CVE-2026-16385
CVE-2026-16386
CVE-2026-16387
CVE-2026-16388
CVE-2026-16389
CVE-2026-16390
CVE-2026-16391
CVE-2026-16392
CVE-2026-16393
CVE-2026-16359
CVE-2026-16394
CVE-2026-16395
CVE-2026-16396
CVE-2026-16397
CVE-2026-16398
CVE-2026-16399
CVE-2026-16400
CVE-2026-16401
CVE-2026-16402
CVE-2026-16403
CVE-2026-16404
CVE-2026-16405
CVE-2026-16406
CVE-2026-16407
CVE-2026-16408
CVE-2026-16409
CVE-2026-16410
CVE-2026-16411
CVE-2026-16412
CVE-2026-16360
+ Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
+ Mozilla Foundation Security Advisory 2026-69 Security Vulnerabilities fixed in Firefox ESR 115.38
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
+ Mozilla Foundation Security Advisory 2026-71 Security Vulnerabilities fixed in Thunderbird 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/
+ Mozilla Foundation Security Advisory 2026-72 Security Vulnerabilities fixed in Thunderbird 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/
+ Mozilla Thunderbird 153.0 released
https://www.thunderbird.net/en-US/thunderbird/153.0esr/releasenotes/
+ ISC BIND 9.20.26 released
https://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html
+ Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html
+ JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html
CVE-2026-10723
CVE-2026-10822
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
+ Linux Kernelの脆弱性(IPV6_FRAG_ESCAPE: CVE-2026-53362, CVE-2026-53366)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260723/
CVE-2026-53362
CVE-2026-53366
+ BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260723/
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
CVE-2026-10723
CVE-2026-10822
+ Microsoft Edge <= 150.0.4078.48 (Chromium-based) Type Confusion RCE
https://cxsecurity.com/issue/WLB-2026070009
CVE-2026-58289
VU#847406 Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
https://www.kb.cert.org/vuls/id/847406
VU#360868 Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability
https://www.kb.cert.org/vuls/id/360868
VU#762226 Plane contains multi-tenant authorization bypass vulnerability
https://www.kb.cert.org/vuls/id/762226
JVNVU#98636554 バックアップソフトウェア「Duplicati」における不適切な権限割り当てに関する脆弱性
https://jvn.jp/vu/JVNVU98636554/index.html
JVNVU#98875819 Analog Way製メディアサーバー「Picturall Quad Compact Mark II」におけるローカル権限昇格の脆弱性
https://jvn.jp/vu/JVNVU98875819/index.html
JVN#32082029 リコー製プリンターおよび複合機のSSH通信機能におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN32082029/index.html
JVNVU#90683587 プロジェクト管理ツール「Plane」における認可回避の脆弱性
https://jvn.jp/vu/JVNVU90683587/index.html
JVNVU#98832565 CISA ICS Advisory / ICS Medical Advisory(2026年07月21日)
https://jvn.jp/vu/JVNVU98832565/index.html
JVN#20592637 Drupalプラグイン「AI Agents」における不正な認証の脆弱性
https://jvn.jp/jp/JVN20592637/index.html
JVN#40509781 非接触型ICカード技術FeliCaの一部のICチップにおける脆弱性
https://jvn.jp/jp/JVN40509781/index.html
ニュース&リポート
26年度末開始「SCS評価制度」に脚光 供給網のサイバー対策を客観評価
展示会Interopで関連サービスが多数出展
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/071301466/?ST=nxt_thmit_security
LLMを適所で生かす、セキュリティーの要件定義 第2回
セキュリティー要件は6ステップで定義 LLMを生かしてまずは脅威を理解
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800002/?ST=nxt_thmit_security
ニュース解説
OpenAIのモデルが他社システムに侵入、ゼロデイ悪用でサンドボックス脱出
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11912/?ST=nxt_thmit_security
勝村幸博の「今日も誰かが狙われる」
AIエージェントによる「ランサムウエア攻撃」出現、侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/column/18/00676/071100229/?ST=nxt_thmit_security
LLMを適所で生かす、セキュリティーの要件定義 第1回
「残念なセキュリティー」を招く要件定義の落とし穴、3大パターンを紹介
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800001/?ST=nxt_thmit_security
日経コンピュータ「動かないコンピュータ」
顧客情報1354万件漏洩の恐れ SSD紛失、例外運用のリスク露呈
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/071300211/?ST=nxt_thmit_security
piyokangoの週刊システムトラブル
シード・プランニング、PHP脆弱性でランサムウエア被害 影響範囲を廃棄
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900373/?ST=nxt_thmit_security
0 件のコメント:
コメントを投稿