+ RHSA-2026:73511 Moderate: gawk security update
https://access.redhat.com/errata/RHSA-2026:73511
CVE-2026-40467
CVE-2026-40468
+ RHSA-2026:73425 Important: gdb security update
https://access.redhat.com/errata/RHSA-2026:73425
CVE-2026-13732
+ RHSA-2026:72468 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:72468
CVE-2025-40323
CVE-2026-45942
CVE-2026-46199
CVE-2026-46204
CVE-2026-46230
CVE-2026-63875
CVE-2026-64034
CVE-2026-64556
CVE-2026-68155
CVE-2026-68156
CVE-2026-68159
CVE-2026-68273
CVE-2026-74753
+ RHSA-2026:72448 Important: expat security update
https://access.redhat.com/errata/RHSA-2026:72448
CVE-2026-66046
CVE-2026-93990
+ iOS 27.0.1 and iPadOS 27.0.1 released
https://support.apple.com/en-us/100100
+ About the security content of iOS 26.7.1 and iPadOS 26.7.1
https://support.apple.com/en-us/149226
CVE-2026-86950
+ Google Chrome 154.0.8037.92/.93, 152.0.7977.149 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_01748636441.html
+ Mozill Firefox 157.0 released
https://www.firefox.com/en-US/firefox/157.0/releasenotes/
+ Mozilla Foundation Security Advisory 2026-97 Security Vulnerabilities fixed in Firefox 157
https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/
CVE-2026-100756
CVE-2026-100757
CVE-2026-100758
CVE-2026-100759
CVE-2026-100760
CVE-2026-100761
CVE-2026-100762
CVE-2026-100763
CVE-2026-100764
CVE-2026-100765
CVE-2026-100766
CVE-2026-100767
CVE-2026-100768
CVE-2026-100769
CVE-2026-100770
CVE-2026-100771
CVE-2026-100772
CVE-2026-100773
CVE-2026-100774
CVE-2026-100775
CVE-2026-100776
CVE-2026-100777
CVE-2026-100778
CVE-2026-100779
CVE-2026-100780
CVE-2026-100781
CVE-2026-100782
CVE-2026-100783
CVE-2026-100784
CVE-2026-100785
CVE-2026-100786
CVE-2026-100787
CVE-2026-100788
CVE-2026-100789
CVE-2026-100790
CVE-2026-100791
CVE-2026-100792
CVE-2026-100793
CVE-2026-100794
CVE-2026-96869
CVE-2026-100795
CVE-2026-100796
CVE-2026-100797
CVE-2026-100798
CVE-2026-100799
CVE-2026-100800
CVE-2026-100801
CVE-2026-100802
CVE-2026-100803
CVE-2026-100804
CVE-2026-100805
CVE-2026-100806
CVE-2026-100807
CVE-2026-100808
CVE-2026-100809
CVE-2026-100810
CVE-2026-100811
CVE-2026-100812
CVE-2026-100813
CVE-2026-100814
CVE-2026-100815
CVE-2026-100816
CVE-2026-100817
CVE-2026-100818
CVE-2026-100819
CVE-2026-100820
CVE-2026-100821
CVE-2026-100822
CVE-2026-100823
CVE-2026-100824
CVE-2026-100825
CVE-2026-100826
CVE-2026-100828
CVE-2026-100829
CVE-2026-100830
CVE-2026-100831
+ Mozilla Foundation Security Advisory 2026-100 Security Vulnerabilities fixed in Firefox ESR 153.4
https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/
+ Mozilla Foundation Security Advisory 2026-99 Security Vulnerabilities fixed in Firefox ESR 140.17
https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/
+ Mozilla Foundation Security Advisory 2026-98 Security Vulnerabilities fixed in Firefox ESR 115.42
https://www.mozilla.org/en-US/security/advisories/mfsa2026-98/
+ FreeBSD-SA-26:69.udp IPv6 UDP sendto(2) bypasses jail loopback restriction
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:69.udp.asc
CVE-2026-101303
+ FreeBSD-SA-26:68.openssl Out-of-bounds read in OpenSSL DTLS retransmission
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:68.openssl.asc
CVE-2026-84782
+ FreeBSD-SA-26:67.ktls Remote DoS via receive-side kernel TLS
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:67.ktls.asc
CVE-2026-101302
+ FreeBSD-SA-26:66.jail Multiple jail filesystem root escapes
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:66.jail.asc
CVE-2026-101304
CVE-2026-101305
CVE-2026-101306
+ FreeBSD-SA-26:65.kqueue Memory safety bugs in kqueue copy-on-fork implementation
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:65.kqueue.asc
CVE-2026-58099
CVE-2026-58100
+ FreeBSD-SA-26:64.sysvsem Heap out-of-bounds access in semop(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:64.sysvsem.asc
CVE-2026-58098
+ OpenSSL 4.0.3 released
https://github.com/openssl/openssl/releases/tag/openssl-4.0.3
+ Excessive Memory Allocation in Relative CRLDP Processing
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-35189
CVE-2026-35189
+ QUIC Unvalidated Amplification Credit may be Over Accounted
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-35191
CVE-2026-35191
+ Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42772
CVE-2026-42772
+ Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54872
CVE-2026-54872
+ QUIC STREAM Fragment Metadata DoS
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54873
CVE-2026-54873
+ Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54875
CVE-2026-54875
+ Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-72897
CVE-2026-72897
+ QUIC Connection-Level Flow Control is Not Enforced for Streams
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75804
CVE-2026-75804
+ NULL Pointer Dereference in CMP Client Revocation Response Handling
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75805
CVE-2026-75805
+ Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75806
CVE-2026-75806
+ Timing Side-Channel in SM2 Signature Generation
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-77696
CVE-2026-77696
+ DTLS Retransmits Handshake Messages From a Stale Buffer Offset
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84782
CVE-2026-84782
+ Use-After-Free in X.509 Extension Cache Under Concurrent Use
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84783
CVE-2026-84783
+ QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84784
CVE-2026-84784
+ JVNVU#97703430 ISC BINDにおける複数の脆弱性(2026年9月)
https://jvn.jp/vu/JVNVU97703430/index.html
VU#762428 Authlib library contains a signature?verification bypass vulnerability
https://www.kb.cert.org/vuls/id/762428
データは語る
企業のセキュリティー対策動向 外部委託と内製で方針二分
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/092400234/?ST=nxt_thmit_security
NEWS close-up
ランサム攻撃者の侵入経路に異変
脆弱性悪用を抜き「メール」が首位に 身代金の要求額は平均313万ドル
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/091400342/?ST=nxt_thmit_security
国産セキュリティー製品の勝ち筋
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091400256/091400001/?ST=nxt_thmit_security
勝村幸博の「今日も誰かが狙われる」
AIが発見した脆弱性は約3万件、修正済みはわずか421件 人手の対応限界に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/091700234/?ST=nxt_thmit_security
ニュース解説
統計数理研がプライバシー保護の新技術、注目集めるTEEの弱点を防止
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12048/?ST=nxt_thmit_security
月刊ランサムリポート
「Dire Wolf」の攻撃が急増、高速な暗号化が特徴 26年8月のランサム被害
https://xtech.nikkei.com/atcl/nxt/column/18/03053/092900023/?ST=nxt_thmit_security
タイムズカー、最大660万件の個人情報が漏洩 免許証に加え学生証も対象
https://xtech.nikkei.com/atcl/nxt/news/24/03399/?ST=nxt_thmit_security
ダークサイドAI
AIの闇落ちを防ぐ 弱点をあぶり出せ[Part 5]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700005/?ST=nxt_thmit_security
ダークサイドAI
スキル形成を阻害 「丸投げ」は厳禁[Part 4]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700004/?ST=nxt_thmit_security
ダークサイドAI
脆弱性の嵐が始まる 担当者が燃え尽きる[Part 3]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700003/?ST=nxt_thmit_security
ダークサイドAI
AI利用で思考力低下 粘り強さもなくなる[Part 2]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700002/?ST=nxt_thmit_security
ダークサイドAI
AIエージェント暴走 本番データを全削除[Part 1]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700001/?ST=nxt_thmit_security
日経NETWORK 特別リポート
どうするSCS評価制度
開始見込みまであと半年
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/091400107/?ST=nxt_thmit_security
piyokangoの週刊システムトラブル
さくらインターネットに不正アクセス、136万超の会員情報に影響
https://xtech.nikkei.com/atcl/nxt/column/18/00598/011300383/?ST=nxt_thmit_security
JVNVU#96968110 PFU製Image Scanner Driver for Linuxにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96968110/index.html
JVN#22475874 Pgpool-IIにおける複数の脆弱性
https://jvn.jp/jp/JVN22475874/index.html
JVNVU#99151548 Authlibライブラリにおける署名検証が回避される脆弱性
https://jvn.jp/vu/JVNVU99151548/index.html
JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html
JVNVU#94863997 バッファロー製Wi-Fi製品における複数の脆弱性
https://jvn.jp/vu/JVNVU94863997/index.html
JVNVU#96520526 Androidアプリ「Readwise Reader」における複数のクロスサイトスクリプティングの脆弱性
https://jvn.jp/vu/JVNVU96520526/index.html
0 件のコメント:
コメントを投稿