ラベル 大安 の投稿を表示しています。 すべての投稿を表示
ラベル 大安 の投稿を表示しています。 すべての投稿を表示

2026年7月9日木曜日

9日 木曜日、大安

+ RHSA-2026:36774 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:36774
CVE-2026-53705

+ RHSA-2026:36732 Moderate: python-urllib3 security update
https://access.redhat.com/errata/RHSA-2026:36732
CVE-2026-44431

+ RHSA-2026:36734 Low: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:36734
CVE-2025-6170

+ RHSA-2026:36733 Moderate: cups security update
https://access.redhat.com/errata/RHSA-2026:36733
CVE-2026-34980

+ RHSA-2026:36728 Low: libtasn1 security update
https://access.redhat.com/errata/RHSA-2026:36728
CVE-2025-13151

+ RHSA-2026:36530 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:36530
CVE-2026-23401
CVE-2026-31402
CVE-2026-31419

+ RHSA-2026:36879 Important: tomcat security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:36879
CVE-2026-29146
CVE-2026-34486

+ RHSA-2026:36832 Important: libreoffice security update
https://access.redhat.com/errata/RHSA-2026:36832
CVE-2026-8357

+ RHSA-2026:36777 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:36777
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-44390

+ RHSA-2026:36674 Moderate: gstreamer1-plugins-ugly-free security update
https://access.redhat.com/errata/RHSA-2026:36674
CVE-2026-53703
CVE-2026-53704

+ RHSA-2026:36617 Important: oci-seccomp-bpf-hook security update
https://access.redhat.com/errata/RHSA-2026:36617
CVE-2026-33811

+ Google Chrome 150.0.7871.114/.115 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html

+ Apache Tomcat 11.0.24, 10.1.57 Released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.24_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.57_(schultz)

+ ProFTPD 1.3.9c released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9c
http://www.proftpd.org/docs/NEWS-1.3.9c

+ OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース
https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/
CVE-2026-59995
CVE-2026-59996
CVE-2026-59997
CVE-2026-59998
CVE-2026-59999

VU#849433 Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls
https://www.kb.cert.org/vuls/id/849433

JVN#62347140 富士電機製Pupsmanのインストーラにおける複数の脆弱性
https://jvn.jp/jp/JVN62347140/index.html

JVNVU#92734392 CISA ICS Advisory / ICS Medical Advisory(2026年07月07日)
https://jvn.jp/vu/JVNVU92734392/index.html

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第1回
出光は36億円を損失か、ランサム並みに深刻な「サイバー詐欺」の実態
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800001/?ST=nxt_thmit_security

3分でわかる必修ワード IT
万全の対策は難しい「シャドーAI」、企業はガバナンスやルール整備を進める
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/070600320/?ST=nxt_thmit_security

2026年7月3日金曜日

3日 金曜日、大安

+ PHP 8.5.8, 8.4.23, 8.3.32, 8.2.32 released
https://www.php.net/ChangeLog-8.php#8.5.8
https://www.php.net/ChangeLog-8.php#8.4.23
https://www.php.net/ChangeLog-8.php#8.3.32
https://www.php.net/ChangeLog-8.php#8.2.32

VU#639124 Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat
https://www.kb.cert.org/vuls/id/639124

UPDATE: JVNVU#92054409 三菱電機製数値制御装置における数値の入力に対する不適切な検証
https://jvn.jp/vu/JVNVU92054409/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIで巧妙化するフィッシング 件数は20%減でも被害額は3倍
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/063000189/?ST=nxt_thmit_security

マルウエア徹底解剖
IoT機器を狙うマルウエア [第79回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/061700080/?ST=nxt_thmit_security

2026年6月15日月曜日

15日 月曜日、大安

+ ■Windows DNSクライアントの脆弱性情報が公開されました(CVE-2026-41108)
https://jprs.jp/tech/security/2026-06-12-windows.html
CVE-2026-41108

ニュース解説
脆弱性対策の猶予は「日」から「時間」へ、Mythosが示すNデイ攻撃の高度化
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11820/?ST=nxt_thmit_security

ニュース解説
AnthropicがFable 5とMythos 5の提供停止 米政府指示、「脱獄」を懸念か
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11825/?ST=nxt_thmit_security

JVNVU#96130756 crypton-x509-validationにおける不適切な証明書検証の脆弱性
https://jvn.jp/vu/JVNVU96130756/index.html

JVNVU#94338291 CISA ICS Advisory / ICS Medical Advisory(2026年06月11日)
https://jvn.jp/vu/JVNVU94338291/index.html

2026年6月11日木曜日

11日 木曜日、大安

+ RHSA-2026:25121 Critical: kernel security update
https://access.redhat.com/errata/RHSA-2026:25121
CVE-2023-53781
CVE-2025-21858
CVE-2025-68366
CVE-2026-22984
CVE-2026-22990
CVE-2026-23392
CVE-2026-31581
CVE-2026-31613
CVE-2026-43037
CVE-2026-43038
CVE-2026-43125
CVE-2026-45852
CVE-2026-46181

+ RHSA-2026:25113 Important: .NET 9.0 security update
https://access.redhat.com/errata/RHSA-2026:25113
CVE-2026-45491
CVE-2026-45591

+ RHSA-2026:25110 Important: .NET 8.0 security update
https://access.redhat.com/errata/RHSA-2026:25110
CVE-2026-45491
CVE-2026-45591

+ RHSA-2026:25090 Important: httpd:2.4 security update
https://access.redhat.com/errata/RHSA-2026:25090
CVE-2026-49975

+ RHSA-2026:25030 Important: postgresql-jdbc security update
https://access.redhat.com/errata/RHSA-2026:25030
CVE-2026-42198

+ RHSA-2026:24984 Important: poppler security update
https://access.redhat.com/errata/RHSA-2026:24984
CVE-2026-10118

+ RHSA-2026:25058 Important: poppler security update
https://access.redhat.com/errata/RHSA-2026:25058
CVE-2026-10118

+ RHSA-2026:25057 Important: mod_http2 security update
https://access.redhat.com/errata/RHSA-2026:25057
CVE-2026-49975

+ 2026 年 6 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/06/202606-security-update

ニュース&リポート
IT大手、地銀セキュリティーに照準 総合サービスを相次ぎ投入
Mythos登場で高まる脅威、需要も拡大
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/060301444/?ST=nxt_thmit_security

最新セキュリティ事情と対策 第8回
パソコンやスマホを守る「設定」、OS更新と画面ロックを確認
https://xtech.nikkei.com/atcl/nxt/column/18/03598/042000008/?ST=nxt_thmit_security

ニュース解説
AnthropicがMythosクラス「Fable」を公開、悪用リスクには他モデルが応答
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11815/?ST=nxt_thmit_security

JVNVU#91880087 CISA ICS Advisory / ICS Medical Advisory(2026年06月09日)
https://jvn.jp/vu/JVNVU91880087/index.html

JVNVU#93818675 Siemens製品に対するアップデート(2026年6月)
https://jvn.jp/vu/JVNVU93818675/index.html

2026年6月5日金曜日

5日 金曜日、大安

+ RHSA-2026:23470 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:23470
CVE-2026-46300
CVE-2026-46333

+ RHSA-2026:23360 Important: bind9.16 security update
https://access.redhat.com/errata/RHSA-2026:23360
CVE-2026-3039
CVE-2026-5946

+ RHSA-2026:23258 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:23258
CVE-2026-46243

+ RHSA-2026:23332 Moderate: mysql security update
https://access.redhat.com/errata/RHSA-2026:23332
CVE-2026-21998
CVE-2026-22001
CVE-2026-22002
CVE-2026-22004
CVE-2026-22005
CVE-2026-22009
CVE-2026-22015
CVE-2026-22017
CVE-2026-34267
CVE-2026-34270
CVE-2026-34271
CVE-2026-34276
CVE-2026-34278
CVE-2026-34293
CVE-2026-34303
CVE-2026-34304
CVE-2026-34308
CVE-2026-35236
CVE-2026-35237
CVE-2026-35238
CVE-2026-35239
CVE-2026-35240

+ PHP 8.5.7, 8.4.22 released
https://www.php.net/ChangeLog-8.php#8.5.7
https://www.php.net/ChangeLog-8.php#8.4.22

JVNVU#97035938 Securly Chrome Extensionにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97035938/index.html

JVNVU#95215075 CISA ICS Advisory / ICS Medical Advisory(2026年06月02日)
https://jvn.jp/vu/JVNVU95215075/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
登録セキスペの「8万円講習」 一部免除で価値の低下を懸念
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/060100187/?ST=nxt_thmit_security

最新セキュリティ事情と対策 第5回
フリーWi-Fiだけじゃない、外出時のネット利用に潜む危険
https://xtech.nikkei.com/atcl/nxt/column/18/03598/042000005/?ST=nxt_thmit_security

2026年5月18日月曜日

18日 月曜日、大安

+ ■Windows DNSクライアントの脆弱性情報が公開されました(CVE-2026-41096)
https://jprs.jp/tech/security/2026-05-15-windows.html
CVE-2026-41096

+ Postfix stable release 3.11.3 and legacy releases 3.10.10, 3.9.11, 3.8.17
https://www.postfix.org/announcements/postfix-3.11.3.html

+ Linux Kernelの脆弱性(ssh-keygen-pwn: Important: CVE-2026-46333)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260517/
CVE-2026-46333

JVN#69128376 Musetheque V4 情報公開 for IPKNOWLEDGEにおける複数の脆弱性
https://jvn.jp/jp/JVN69128376/index.html

JVNVU#94687621 CISA ICS Advisory / ICS Medical Advisory(2026年05月14日)
https://jvn.jp/vu/JVNVU94687621/index.html

2026年5月13日水曜日

13日 水曜日、大安

+ RHSA-2026:16252 Important: jq security update
https://access.redhat.com/errata/RHSA-2026:16252
CVE-2026-39979
CVE-2026-40164

+ RHSA-2026:16484 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:16484
CVE-2026-4150
CVE-2026-4151
CVE-2026-4152
CVE-2026-4153
CVE-2026-4154
CVE-2026-4887

+ RHSA-2026:16206 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:16206
CVE-2026-43284

+ Google Chrome 148.0.7778.167/168 released
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html

+ Mozilla Foundation Security Advisory 2026-45 Security Vulnerabilities fixed in Firefox 150.0.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-45/
CVE-2026-8388
CVE-2026-8389
CVE-2026-8390
CVE-2026-8391
CVE-2026-8401

+ Apache Tomcat 10.1.55 Released
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.55_(schultz)

+ Tcl/Tk 8.6.18 released
https://www.tcl-lang.org/software/tcltk/8.6.html

+ Apache Tomcatの脆弱性(Moderate: CVE-2026-43512, CVE-2026-43515, Low: CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43513, CVE-2026-43514)
https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260513/
CVE-2026-43512
CVE-2026-43515
CVE-2026-41284
CVE-2026-41293
CVE-2026-42498
CVE-2026-43513
CVE-2026-43514

日経コンピュータ「ITが危ない」
サイバー対処強化法10月施行 対応遅れ、取引停止のリスクも
260社を除くサプライチェーンにも波及の恐れ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/050700194/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
Mythosが引き起こす「脆弱性の嵐」に備えよ、専門家250人が対策を提言
https://xtech.nikkei.com/atcl/nxt/column/18/00676/050700224/?ST=nxt_thmit_security

UPDATE: JVN#94012927 エレコム無線LAN関連製品における複数の脆弱性
https://jvn.jp/jp/JVN94012927/index.html

UPDATE: JVN#24885537 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性
https://jvn.jp/jp/JVN24885537/index.html

UPDATE: JVN#06672778 エレコム製無線LANルーターにおける複数の脆弱性
https://jvn.jp/jp/JVN06672778/index.html

UPDATE: JVNVU#95381465 エレコム製無線LANルーターにおける複数の脆弱性
https://jvn.jp/vu/JVNVU95381465/index.html

UPADTE: JVNVU#90908488 エレコム製無線LANルーターにおけるOSコマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU90908488/index.html

UPDATE: JVNVU#91630351 エレコム製およびロジテック製ネットワーク機器における複数の脆弱性
https://jvn.jp/vu/JVNVU91630351/index.html

JVN#03037325 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年5月)
https://jvn.jp/jp/JVN03037325/index.html

2026年5月7日木曜日

7日 木曜日、大安

+ RHSA-2026:14087 Moderate: libsoup security update
https://access.redhat.com/errata/RHSA-2026:14087
CVE-2026-5119

+ RHSA-2026:13830 Important: dovecot security update
https://access.redhat.com/errata/RHSA-2026:13830
CVE-2025-59032
CVE-2026-27857
CVE-2026-27858

+ RHSA-2026:13537 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:13537
CVE-2026-6746
CVE-2026-6747
CVE-2026-6748
CVE-2026-6749
CVE-2026-6750
CVE-2026-6751
CVE-2026-6752
CVE-2026-6753
CVE-2026-6754
CVE-2026-6757
CVE-2026-6759
CVE-2026-6761
CVE-2026-6762
CVE-2026-6763
CVE-2026-6764
CVE-2026-6765
CVE-2026-6766
CVE-2026-6767
CVE-2026-6769
CVE-2026-6770
CVE-2026-6771
CVE-2026-6772
CVE-2026-6776
CVE-2026-6785
CVE-2026-6786

+ RHSA-2026:13414 Important: tigervnc security update
https://access.redhat.com/errata/RHSA-2026:13414
CVE-2026-33999
CVE-2026-34001
CVE-2026-34003
CVE-2026-34352

+ RHSA-2026:13383 Important: openssh security update
https://access.redhat.com/errata/RHSA-2026:13383
CVE-2026-35385
CVE-2026-35386
CVE-2026-35387
CVE-2026-35388
CVE-2026-35414

+ RHSA-2026:13285 Important: libcap security update
https://access.redhat.com/errata/RHSA-2026:13285
CVE-2026-4878

+ RHSA-2026:13284 Important: LibRaw security update
https://access.redhat.com/errata/RHSA-2026:13284
CVE-2026-20889
CVE-2026-21413
CVE-2026-24660

+ RHSA-2026:14200 Important: git-lfs security update
https://access.redhat.com/errata/RHSA-2026:14200
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283

+ RHSA-2026:13978 Moderate: libsoup security update
https://access.redhat.com/errata/RHSA-2026:13978
CVE-2026-5119

+ RHSA-2026:13917 Important: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:13917
CVE-2026-30922

+ RHSA-2026:13857 Important: dovecot security update
https://access.redhat.com/errata/RHSA-2026:13857
CVE-2025-59032
CVE-2026-27857
CVE-2026-27858

+ RHSA-2026:13677 Moderate: systemd security update
https://access.redhat.com/errata/RHSA-2026:13677
CVE-2026-29111

+ RHSA-2026:13673 Moderate: corosync security update
https://access.redhat.com/errata/RHSA-2026:13673
CVE-2026-35091
CVE-2026-35092

+ RHSA-2026:13672 Important: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:13672
CVE-2026-26007
CVE-2026-32597

+ RHSA-2026:13671 Important: image-builder security update
https://access.redhat.com/errata/RHSA-2026:13671
CVE-2026-25679

+ RHSA-2026:13670 Moderate: python-tornado security update
https://access.redhat.com/errata/RHSA-2026:13670
CVE-2026-31958
CVE-2026-35536

+ RHSA-2026:13565 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:13565
CVE-2026-23136
CVE-2026-23270
CVE-2026-31402
CVE-2026-31431

+ RHSA-2026:13381 Important: openssh security update
https://access.redhat.com/errata/RHSA-2026:13381
CVE-2026-35385
CVE-2026-35386
CVE-2026-35387
CVE-2026-35388
CVE-2026-35414

+ Google Chrome 148.0.7778.96/97 released
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html

+ Zabbix 7.4.10, 7.0.26, 6.0.46 released
https://www.zabbix.com/rn/rn7.4.10
https://www.zabbix.com/rn/rn7.0.26
https://www.zabbix.com/rn/rn6.0.46

+ Mozilla Thunderbird 150.0.1 released
https://www.thunderbird.net/en-US/thunderbird/150.0.1/releasenotes/

+ Microsoft Drivers for PHP for SQL Server 5.13.1 released
https://learn.microsoft.com/ja-jp/sql/connect/php/release-notes-php-sql-driver?view=sql-server-ver17&source=recommendations

+ Apache HTTP Server 2.4.67 released
https://downloads.apache.org/httpd/CHANGES_2.4.67
https://downloads.apache.org/httpd/Announcement2.4.html

+ Postfix stable release 3.11.2 and legacy releases 3.10.9, 3.9.10, 3.8.16
https://www.postfix.org/announcements/postfix-3.11.2.html

+ Apache HTTP Serverの脆弱性(Important: CVE-2026-23918, Moderate: CVE-2026-24072, CVE-2026-33006, Low:複数)と2.4.67リリース
https://security.sios.jp/vulnerability/apache-security-vulnerability-20260505/
CVE-2026-23918
CVE-2026-24072
CVE-2026-33006
CVE-2026-28780
CVE-2026-29168
CVE-2026-29169
CVE-2026-33007
CVE-2026-33523
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059

+ Linux Kernel Local Privilege Escalation via Memory Handling and Access Control Weakness
https://cxsecurity.com/issue/WLB-2026050003

+ Linux Kernel proc_readdir_de() 6.18-rc5 Local Privilege Escalation
https://cxsecurity.com/issue/WLB-2026050001
CVE-2025-40271
CVE-2023-3269
CVE-2023-32233

ニュース解説
総務省が自治体にサイバー対策「義務化」、中国製品排除せずも選定を厳格に
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11706/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
マツダ病院の患者情報が閲覧可能に、委託先はミス把握も1年超報告せず
https://xtech.nikkei.com/atcl/nxt/column/18/00598/011300395/?ST=nxt_thmit_security

マルウエア徹底解剖
Androidを狙うマルウエア [第77回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/041700078/?ST=nxt_thmit_security

JVNVU#96268711 CISA ICS Advisory / ICS Medical Advisory(2026年04月30日)
https://jvn.jp/vu/JVNVU96268711/index.html

2026年5月1日金曜日

1日 金曜日、大安

+ RHSA-2026:12176 Important: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:12176
CVE-2026-26007
CVE-2026-30922
CVE-2026-32597

+ RHSA-2026:12441 Important: libcap security update
https://access.redhat.com/errata/RHSA-2026:12441
CVE-2026-4878

+ RHSA-2026:12310 Important: sudo security update
https://access.redhat.com/errata/RHSA-2026:12310
CVE-2026-35535

+ RHSA-2026:12271 Important: libtiff security update
https://access.redhat.com/errata/RHSA-2026:12271
CVE-2026-4775

+ Mozilla Foundation Security Advisory 2026-38 Security Vulnerabilities fixed in Thunderbird 150.0.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-38/
CVE-2026-7320
CVE-2026-7322
CVE-2026-7323
CVE-2026-7324

+ Mozilla Foundation Security Advisory 2026-39 Security Vulnerabilities fixed in Thunderbird 140.10.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-39/

+ Wireshark 4.6.5, 4.4.15 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.15.html

+ Linux Kernelのローカルユーザによる権限昇格の脆弱性(Copy Fail: CVE-2026-31431)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260501/
CVE-2026-31431

NEWS close-up
兵庫県太子町がゼロトラスト導入
β'モデルでネットワークを刷新 移行後にはLGWAN-ASP起因のトラブルも
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/041700325/?ST=nxt_thmit_security

月刊ランサムリポート
2026年2月のランサム被害は初の1000件超え 「The Gentlemen」は2重脅迫使う
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/041700015/?ST=nxt_thmit_security

JVN#65118274 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)におけるオープンリダイレクトの脆弱性
https://jvn.jp/jp/JVN65118274/index.html

JVNVU#98147762 CISA ICS Advisory / ICS Medical Advisory(2026年04月28日)
https://jvn.jp/vu/JVNVU98147762/index.html

JVNVU#91813693 IDrive Cloud Backup Client for Windowsにおける権限昇格の脆弱性
https://jvn.jp/vu/JVNVU91813693/index.html

2026年4月15日水曜日

15日 水曜日、大安

+ RHSA-2026:8155 Important: bind9.16 security update
https://access.redhat.com/errata/RHSA-2026:8155
CVE-2026-1519

+ RHSA-2026:8052 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:8052
CVE-2026-5731
CVE-2026-5732
CVE-2026-5734
CVE-2026-33416
CVE-2026-33636

+ RHSA-2026:7681 Important: perl-XML-Parser security update
https://access.redhat.com/errata/RHSA-2026:7681
CVE-2006-10002
CVE-2006-10003

+ RHSA-2026:7674 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:7674
CVE-2026-25679

+ RHSA-2026:7667 Important: nghttp2 security update
https://access.redhat.com/errata/RHSA-2026:7667
CVE-2026-27135

+ RHSA-2026:8075 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:8075
CVE-2026-1519

+ RHSA-2026:7915 Important: bind9.18 security update
https://access.redhat.com/errata/RHSA-2026:7915
CVE-2026-1519

+ RHSA-2026:7896 Important: nodejs:20 security update
https://access.redhat.com/errata/RHSA-2026:7896
CVE-2026-21710
CVE-2026-26996
CVE-2026-27135
CVE-2026-27904

+ RHSA-2026:7671 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:7671
CVE-2026-5731
CVE-2026-5732
CVE-2026-5734
CVE-2026-33416
CVE-2026-33636

+ nginx 1.30.0 released
https://nginx.org/en/CHANGES-1.30

+ 2026 年 4 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update

JVNVU#96334293 Dynabook製Bluetooth ACPIドライバーにおけるスタックベースのバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU96334293/index.html

JVNVU#90646130 複数の三菱電機製品における重要情報の平文保存の脆弱性
https://jvn.jp/vu/JVNVU90646130/index.html

日経コンピュータ「ITが危ない」
不可視文字でマルウエア混入 開発基盤の信頼性揺らぐ
「GlassWorm」が猛威、GitHubなど汚染拡大
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/040900192/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
「悪魔のツール」Claude Mythos、防御側に恩恵をもたらす盾ともなるか
https://xtech.nikkei.com/atcl/nxt/column/18/00676/041200223/?ST=nxt_thmit_security

ランサム被害の東山産業、リークサイト掲載認める 被害報告相次ぐ
https://xtech.nikkei.com/atcl/nxt/news/24/03176/?ST=nxt_thmit_security

記者の眼
「閉域網神話」は過去のもの、人ごとではない医療機関のセキュリティー
https://xtech.nikkei.com/atcl/nxt/column/18/00138/041001998/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
マイナビが利用するクラウドに不正アクセス 対策回避で侵入、監視を強化
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900360/?ST=nxt_thmit_security

2026年4月9日木曜日

9日 木曜日、大安

+ RHSA-2026:7123 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2026:7123
CVE-2026-1525
CVE-2026-1526
CVE-2026-1528
CVE-2026-2229
CVE-2026-21710
CVE-2026-25547
CVE-2026-26996
CVE-2026-27135
CVE-2026-27904

+ RHSA-2026:6949 Important: go-toolset:rhel8 security update
https://access.redhat.com/errata/RHSA-2026:6949
CVE-2025-61731
CVE-2026-25679

+ RHSA-2026:7002 Important: nginx security update
https://access.redhat.com/errata/RHSA-2026:7002
CVE-2026-27651
CVE-2026-27654
CVE-2026-27784
CVE-2026-32647

+ iOS 26.4.1 and iPadOS 26.4.1 released
https://support.apple.com/en-us/100100

+ Google Chrome 146.0.7680.188 released
https://chromereleases.googleblog.com/2026/04/extended-stable-updates-for-desktop.html

+ OpenSSLの複数の脆弱性(Moderate: CVE-2026-31790, Low: CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789)と3.6.2, 3.5.6, 3.4.5, 3.3.7, 3.0.20, 1.1.1zg, 1.0.2zpリリース
https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260408/
CVE-2026-31790
CVE-2026-28386
CVE-2026-28387
CVE-2026-28388
CVE-2026-28389
CVE-2026-28390
CVE-2026-31789

JVN#66473735 Movable Typeにおける複数の脆弱性
https://jvn.jp/jp/JVN66473735/index.html

JVNVU#95093977 Xerox FreeFlow Coreにおける複数の脆弱性(XRX26-005)
https://jvn.jp/vu/JVNVU95093977/index.html

JVNVU#90253343 Xerox FreeFlow Coreにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90253343/index.html

JVN#33581068 抹茶シリーズにおける複数の脆弱性
https://jvn.jp/jp/JVN33581068/index.html

JVNVU#93934287 CISA ICS Advisory / ICS Medical Advisory(2026年04月07日)
https://jvn.jp/vu/JVNVU93934287/index.html

記者の眼
AIが「善良な開発者」装う時代、LLM製マルウエアがOSS文化揺さぶる
https://xtech.nikkei.com/atcl/nxt/column/18/00138/040701995/?ST=nxt_thmit_security

2026年4月3日金曜日

3日 金曜日、大安

+ RHSA-2026:6473 Important: python3 security update
https://access.redhat.com/errata/RHSA-2026:6473
CVE-2026-4519

+ RHSA-2026:6445 Important: libpng12 security update
https://access.redhat.com/errata/RHSA-2026:6445
CVE-2026-25646

+ RHSA-2026:6439 Important: libpng15 security update
https://access.redhat.com/errata/RHSA-2026:6439
CVE-2026-25646

+ RHSA-2026:6436 Moderate: rsync security update
https://access.redhat.com/errata/RHSA-2026:6436
CVE-2025-10158

+ OpenSSH 10.3 released
https://www.openssh.org/releasenotes.html#10.3

VU#951662 MuPDF by Artifex contains integer overflow vulnerability.
https://www.kb.cert.org/vuls/id/951662

JVNVU#90448293 富士電機製V-SFTにおける複数の脆弱性(2026年4月)
https://jvn.jp/vu/JVNVU90448293/index.html

中田敦のGAFA深読み
ビットコインの暗号解読は予想より早く実現、Googleが警告する根拠とは
https://xtech.nikkei.com/atcl/nxt/column/18/00692/040200185/?ST=nxt_thmit_security

2026年3月17日火曜日

17日 火曜日、大安

+ MantisBT 2.28.1 Released
https://mantisbt.org/blog/archives/mantisbt/811https://mantisbt.org/blog/archives/mantisbt/811

+ Gpg4win 5.0.2 released
https://www.gpg4win.org/change-history.html

VU#624941 LibreChat RAG API contains a log-injection vulnerability
https://www.kb.cert.org/vuls/id/624941

JVN#46373837 GROWIのOpenAIスレッド・メッセージ APIにおける権限チェック欠如の脆弱性
https://jvn.jp/jp/JVN46373837/index.html

JVN#22152812 OpenLiteSpeedおよびLSWS EnterpriseにおけるOSコマンドインジェクションの脆弱性
https://jvn.jp/jp/JVN22152812/index.html

日経コンピュータ インタビュー
自前回線網とネットワーク技術が強み コアビジネスを強化し成長へ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600001/030900204/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
トンボ飲料、ランサム被害調査結果を公表 侵入手口はリモート接続ソフト
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900356/?ST=nxt_thmit_security

ニュース解説
サイバー対策は情シスで済まない、警察庁報告が映す「止まる経営」の真実
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11586/?ST=nxt_thmit_security

乱立するAIエージェント、管理ツール徹底解剖 第3回
Oktaは不審AIエージェントを即時検知、ツールのセキュリティーが進化
https://xtech.nikkei.com/atcl/nxt/column/18/03541/030900004/?ST=nxt_thmit_security

2026年3月11日水曜日

11日 水曜日、大安

+ RHSA-2026:4146 Important: python-pyasn1 security update
https://access.redhat.com/errata/RHSA-2026:4146
CVE-2026-23490

+ RHSA-2026:4064 Important: postgresql:12 security update
https://access.redhat.com/errata/RHSA-2026:4064
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006

+ RHSA-2026:4063 Important: postgresql:16 security update
https://access.redhat.com/errata/RHSA-2026:4063
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006

+ RHSA-2026:4059 Important: postgresql:15 security update
https://access.redhat.com/errata/RHSA-2026:4059
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006

+ RHSA-2026:4024 Important: postgresql:13 security update
https://access.redhat.com/errata/RHSA-2026:4024
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006

+ RHSA-2026:3963 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:3963
CVE-2025-71085
CVE-2026-23001

+ RHSA-2026:4235 Moderate: nginx:1.26 security update
https://access.redhat.com/errata/RHSA-2026:4235
CVE-2026-1642

+ RHSA-2026:4173 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:4173
CVE-2026-0797
CVE-2026-2044
CVE-2026-2045
CVE-2026-2047
CVE-2026-2048

+ RHSA-2026:4165 Moderate: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:4165
CVE-2025-15366
CVE-2025-15367
CVE-2026-1299

+ RHSA-2026:3987 Important: kpatch-patch-5_14_0-611_9_1 security update
https://access.redhat.com/errata/RHSA-2026:3987
CVE-2025-40248

+ RHSA-2026:3966 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:3966
CVE-2025-38106
CVE-2026-23001

+ macOS Tahoe 26.3.2 released
https://support.apple.com/en-us/100100

+ Google Chrome 146.0.7680.71/72 released
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_10.html

+ Mozilla Firefox 148.0.2 released
https://www.firefox.com/en-US/firefox/148.0.2/releasenotes/

+ Mozilla Foundation Security Advisory 2026-19 Security Vulnerabilities fixed in Firefox 148.0.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-19/
CVE-2026-3845
CVE-2026-3846
CVE-2026-3847

+ Apache Tomcat Native 2.0.14, 1.3.7 released
https://tomcat.apache.org/native-doc/miscellaneous/changelog.html#2.0.14
https://tomcat.apache.org/native-1.3-doc/miscellaneous/changelog.html#1.3.7

+ FreeBSD 14.4-RELEASE Announcement
https://www.freebsd.org/releases/14.4R/announce/

JVNVU#95523788 三菱電機数値制御装置におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU95523788/index.html

乱立するAIエージェント、管理ツール徹底解剖 第1回
群雄割拠のAIエージェント管理、UiPathはツール連携 Salesforceは二刀流
https://xtech.nikkei.com/atcl/nxt/column/18/03541/030900001/?ST=nxt_thmit_security

2026年3月5日木曜日

5日 木曜日、大安

+ RHSA-2026:3753 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:3753
CVE-2025-61726
CVE-2025-61728
CVE-2025-61729
CVE-2025-68121

+ RHSA-2026:3730 Important: postgresql security update
https://access.redhat.com/errata/RHSA-2026:3730
CVE-2026-2004
CVE-2026-2005
CVE-2026-2006

+ iOS 26.3.1 and iPadOS 26.3.1 released
https://support.apple.com/en-us/100100

+ iOS 18.7.6 released
https://support.apple.com/en-us/100100

+ macOS Tahoe 26.3.1 released
https://support.apple.com/en-us/100100

+ ClamAV 1.5.2 and 1.4.4 security patch versions published
https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html

JVNVU#90487775 Hitachi Energy製RTU500シリーズにおける規定されたセキュリティチェックの実装が不適切な脆弱性
https://jvn.jp/vu/JVNVU90487775/index.html

JVN#56544509 UPS Multi-UPS Management Console(MUMC)における複数の脆弱性
https://jvn.jp/jp/JVN56544509/index.html

マルウエア徹底解剖
macOSを狙うマルウエア [第75回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/021700076/?ST=nxt_thmit_security

新任セキュリティー担当者が知っておくべき基礎知識 第2回
VPNとADとポート、新米セキュリティー担当者が守るべき3つを教えよう
https://xtech.nikkei.com/atcl/nxt/column/18/03523/022700002/?ST=nxt_thmit_security

2026年2月27日金曜日

27日 金曜日、大安

+ RHSA-2026:3428 Important: container-tools:rhel8 security update
https://access.redhat.com/errata/RHSA-2026:3428
CVE-2024-24785
CVE-2025-61729
CVE-2025-65637

+ RHSA-2026:3405 Important: libpng security update
https://access.redhat.com/errata/RHSA-2026:3405
CVE-2026-22695
CVE-2026-22801
CVE-2026-25646

+ visionOS 26.3.1 released
https://support.apple.com/en-us/100100

+ PostgreSQL 18.3, 17.9, 16.13, 15.17, and 14.22 Released!
https://www.postgresql.org/about/news/postgresql-183-179-1613-1517-and-1422-released-3246/
https://www.postgresql.org/docs/18/release-18-3.html
https://www.postgresql.org/docs/17/release-17-9.html
https://www.postgresql.org/docs/16/release-16-13.html
https://www.postgresql.org/docs/15/release-15-17.html
https://www.postgresql.org/docs/14/release-14-22.html

日経NETWORK 特別リポート
今すぐやるべき「緊急点検10項目」
ランサムウエアに負けない
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/021700100/?ST=nxt_thmit_security

NEWS close-up
P2Pの権利侵害の実態が明らかに
ISPへの開示請求は15万件 大半はBitTorrentを利用
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/021700316/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
社長をかたる「CEO詐欺」が猛威 国内6000社以上に偽メール
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/022500180/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
GPUとは異質のアーキテクチャーに手を出したNVIDIA、「住み分け」進むか
https://xtech.nikkei.com/atcl/nxt/column/18/02598/021800030/?ST=nxt_thmit_security

月刊ランサムリポート 第15回
新顔犯罪グループ「0APT」に要注意、26年1月のランサム被害を分析
https://xtech.nikkei.com/atcl/nxt/column/18/03053/022500016/?ST=nxt_thmit_security

JVN#48498976 FinalCode Clientのインストーラーにおける複数の脆弱性
https://jvn.jp/jp/JVN48498976/index.html

2026年2月10日火曜日

10日 火曜日、大安

piyokangoの週刊システムトラブル
エプソン販売、ユーザーの問い合わせに4年超回答できず システム不具合で
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900351/?ST=nxt_thmit_security

認証の転換点 第2回
セキュリティー通知が来たら即対応、多要素認証に用いる「3つの材料」
https://xtech.nikkei.com/atcl/nxt/column/18/03490/020800003/?ST=nxt_thmit_security

JVN#55395471 沖電気工業製品およびそのOEM製品における引用符で囲まれていないファイルパスの脆弱性
https://jvn.jp/jp/JVN55395471/index.html

JVNVU#97860540 横河電機製FAST/TOOLSにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97860540/index.html

2026年2月5日木曜日

5日 木曜日、大安

+ Googlg Chrome 145.0.7632.45/.46 released
https://chromereleases.googleblog.com/2026/02/early-stable-update-for-desktop.html

+ nginx 1.29.5, 1.28.2 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.28

+ K000159824: NGINX vulnerability CVE-2026-1642
https://my.f5.com/manage/s/article/K000159824
CVE-2026-1642

UPDATE: JVNVU#96418385 Hitachi Energy製Relion 670, 650およびSAM600-IO Seriesにおけるデータの信頼性確認が不十分な脆弱性
https://jvn.jp/vu/JVNVU96418385/index.html

UPDATE: JVNVU#97100330 Hitachi Energy製IEC 61850 MMS-Serverにおけるリソースの不適切なシャットダウンまたはリリースの脆弱性
https://jvn.jp/vu/JVNVU97100330/index.html

UPDATE: JVNVU#91729891 Rockwell Automation製Arenaにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91729891/index.html

UPDATE: JVNVU#97613753 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU97613753/index.html

UPDATE: JVNVU#91447205 Ubia製Uboxにおける認証情報の不十分な保護の脆弱性
https://jvn.jp/vu/JVNVU91447205/index.html

JVNVU#92010848 Avation Light Engine Proにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU92010848/index.html

JVNVU#98535143 RISS SRL製MOMA Seismic Stationにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU98535143/index.html

JVN#45405689 Movable Typeにおける複数の脆弱性
https://jvn.jp/jp/JVN45405689/index.html

JVN#89992160 Roland Cloud ManagerのインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN89992160/index.html

JVN#64883963 三菱小容量UPS用シャットダウンソフトウェア FREQSHIP-mini for Windowsにおけるインストール時の不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN64883963/index.html

ニュース&リポート
サイバー攻撃者が「スループット」重視 大手ITが26年セキュリティー予測
自律型犯罪エージェントで攻撃範囲と頻度が拡大
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/012801384/?ST=nxt_thmit_security

607社が回答、企業のAI活用状況・意向調査
生成AIがもたらす機会と脅威、企業の認識を聞く
https://xtech.nikkei.com/atcl/nxt/column/18/03475/011900004/?ST=nxt_thmit_security

2026年1月30日金曜日

30日 金曜日、大安

+ RHSA-2026:1592 Moderate: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:1592
CVE-2025-54349

+ RHSA-2026:1574 Important: gimp:2.8 security update
https://access.redhat.com/errata/RHSA-2026:1574
CVE-2025-14422

+ RHSA-2026:1595 Moderate: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:1595
CVE-2025-54349

+ RHSA-2026:1536 Moderate: Red Hat Ceph Storage 9.0 Security and Enhancement update
https://access.redhat.com/errata/RHSA-2026:1536
CVE-2023-25153
CVE-2024-11831
CVE-2024-31884
CVE-2025-30204
CVE-2025-52555

+ Nginx 1.25.x Server Version Information Disclosure
https://cxsecurity.com/issue/WLB-2026010018

セキュリティー担当者 1年目の教科書
まず守りたい認証情報 多要素認証で堅固にする
Part4 認証の防御を知る
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/011900237/011900004/?ST=nxt_thmit_security

セキュリティー担当者 1年目の教科書
マルウエアと攻撃手法の基礎 ランサムウエア攻撃から学ぶ
Part3 攻撃を知る
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/011900237/011900003/?ST=nxt_thmit_security

セキュリティー担当者 1年目の教科書
基本は「境界」を重視 重要な保護対象は3つある
Part2 守る対象を知る
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/011900237/011900002/?ST=nxt_thmit_security

セキュリティー担当者 1年目の教科書
企業の情報やシステムを守る 基本の3つの視点
Part1 基礎を知る
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/011900237/011900001/?ST=nxt_thmit_security

月刊ランサムリポート
2025年11月のランサム被害は70件減少 「Qilin」は活動減速も攻撃数トップ
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/011900012/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
フィッシング詐欺が記者を直撃 事例で学ぶ「だまし」の常とう手段
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/012800178/?ST=nxt_thmit_security

月刊ランサムリポート 第14回
活動再開した「LockBit」の被害急増、25年12月のランサム被害
https://xtech.nikkei.com/atcl/nxt/column/18/03053/012800015/?ST=nxt_thmit_security

UPDATE: JVNVU#94456756 Siemens製品に対するアップデート(2026年1月)
https://jvn.jp/vu/JVNVU94456756/index.html

JVNVU#92878805 ブラザー製複合機(MFP)における複数の脆弱性
https://jvn.jp/vu/JVNVU92878805/index.html

JVNVU#91636632 iba Systems製ibaPDAにおける重要なリソースに対する不適切なアクセス権の割り当ての脆弱性
https://jvn.jp/vu/JVNVU91636632/index.html

JVNVU#92170350 Festo Didactic SE製MES PCにプリインストールされたXAMPPにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92170350/index.html

JVNVU#94266166 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU94266166/index.html

JVNVU#99454170 複数のJohnson Controls製品におけるコマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU99454170/index.html

2026年1月13日火曜日

13日 火曜日、大安

+ libssh key passphrase bypass without agent set
https://curl.se/docs/CVE-2025-15224.html
CVE-2025-15224

+ libssh global known_hosts override
https://curl.se/docs/CVE-2025-15079.html
CVE-2025-15079

+ OpenSSL partial chain store policy bypass
https://curl.se/docs/CVE-2025-14819.html
CVE-2025-14819

+ bearer token leak on cross-protocol redirect
https://curl.se/docs/CVE-2025-14524.html
CVE-2025-14524

+ broken TLS options for threaded LDAPS
https://curl.se/docs/CVE-2025-14017.html
CVE-2025-14017

+ No QUIC certificate pinning with GnuTLS
https://curl.se/docs/CVE-2025-13034.html
CVE-2025-13034

+ RHSA-2026:0444 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:0444
CVE-2025-39993
CVE-2025-40240
CVE-2025-68285

+ RHSA-2026:0421 Important: libsoup security update
https://access.redhat.com/errata/RHSA-2026:0421
CVE-2025-14523

+ RHSA-2026:0470 Important: podman security update
https://access.redhat.com/errata/RHSA-2026:0470
CVE-2025-47913

+ RHSA-2026:0458 Moderate: libpq security update
https://access.redhat.com/errata/RHSA-2026:0458
CVE-2025-12818

+ RHSA-2026:0445 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:0445
CVE-2025-39806
CVE-2025-39840
CVE-2025-39883
CVE-2025-40240

+ RHSA-2026:0422 Important: libsoup security update
https://access.redhat.com/errata/RHSA-2026:0422
CVE-2025-14523

+ Apache Tomcat Native 2.0.12, 1.3.4 released
https://tomcat.apache.org/native-doc/miscellaneous/changelog.html
https://tomcat.apache.org/native-1.3-doc/miscellaneous/changelog.html

+ libpng versions 1.6.26 through 1.6.53 have one or both of a pair of recently discovered security vulnerabilities:
https://www.libpng.org/pub/png/libpng.html
CVE-2026-22695
CVE-2026-22801

+ libpng 1.6.54 released
https://www.libpng.org/pub/png/src/libpng-1.6.54-README.txt

+ Apache StrutsのXXE脆弱性(CVE-2025-68493)
https://security.sios.jp/vulnerability/struts-security-vulnerability-20260112/
CVE-2025-68493

VU#361400 BeeS Software Solutions BeeS Examination Tool (BET) portal contains SQL injection vulnerability
https://www.kb.cert.org/vuls/id/361400

JVN#12770174 RICOH Streamline NXにおける不適切な認可処理の脆弱性
https://jvn.jp/jp/JVN12770174/index.html

ネットワーク図の描き方入門 第2回
見よう見まねはもう卒業、ネットワーク図を悩まず描ける基本の6ステップ
https://xtech.nikkei.com/atcl/nxt/column/18/03451/122200002/?ST=nxt_thmit_security

ランサムウエアに負けない、今すぐやるべき「緊急点検10項目」第1回
待ったなしのランサム対策、事業を守る「緊急点検10項目」を一挙公開
https://xtech.nikkei.com/atcl/nxt/column/18/03461/010700002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
島根の公益財団で個人情報漏洩、同時ログインが不具合誘発しメール誤送信
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900347/?ST=nxt_thmit_security