2026年7月31日金曜日

31日 金曜日、大安

+ RHSA-2026:48790 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:48790
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283
CVE-2026-33186
CVE-2026-34986

+ RHSA-2026:48703 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:48703
CVE-2026-55693
CVE-2026-57455
CVE-2026-57456
CVE-2026-59858

+ RHSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:48197
CVE-2026-14355

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ PHP 8.4.24, 8.3.33 released
https://www.php.net/ChangeLog-8.php#8.4.24
https://www.php.net/ChangeLog-8.php#8.3.33

VU#281278 SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
https://www.kb.cert.org/vuls/id/281278

VU#790363 foreUP golf management platform's web API contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/790363

JVNVU#91587639 Develar製app-builder(zipx.Unzip)における任意のファイルが上書きされる脆弱性
https://jvn.jp/vu/JVNVU91587639/index.html

JVNVU#98815601 トレンドマイクロ製TrendAI Vision Oneに対するセキュリティアップデート(2026年7月)
https://jvn.jp/vu/JVNVU98815601/index.html

月刊ランサムリポート
2026年5月の被害件数は876件で減少傾向 NightSpireは「Mimikatz」悪用して攻撃
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/071600018/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIによる「ランサムウエア攻撃」 侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/072300191/?ST=nxt_thmit_security

どうするSCS評価制度 第2回
SCS評価制度で「チェックシート地獄」は解消できるか、今取り組める2点
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800001/?ST=nxt_thmit_security

月刊ランサムリポート 第20回
ランサムグループ「INC」の存在感が強まる、Citrix Bleedを悪用
https://xtech.nikkei.com/atcl/nxt/column/18/03053/072900021/?ST=nxt_thmit_security

ニュース解説
GPT「暴走」にMicrosoftナデラCEOが言及、単一モデルへの依存に警鐘
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11933/?ST=nxt_thmit_security

0 件のコメント:

コメントを投稿