Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [..…
公的機関の注意喚起とセキュリティ報道の見出しを集めています。掲載しているのは各配信元が公開した見出し・日付・リンクで、本文は配信元のサイトでご覧ください。見出しは取得したまま掲載し、 当サイトによる評価や補足は加えていません。
読んだ見出しのどれから手を付けるか迷ったら、SSVC 判定ツールを使ってください。悪用の状況・公開範囲・自動化可能性・人への影響を選ぶと、 CERT/CC の決定表から「見送り/定期対応/臨時対応/即時対応」のどれかが決まります。
公的機関・CSIRTの発表(リンク先は各機関のサイト)
情報処理推進機構(IPA)の「NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等)」に関する情報です。
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitatio…
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: C…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitatio…
画像は各配信元のOGP画像を参照しています(複製はしていません)
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [..…
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Softwar…
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the …
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and…
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disru…
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnera…
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, pass…
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclos…
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $1…
米マサチューセッツ大学アマースト校に所属する研究者らがセキュリティ分野の国際会議「USENIX Security Symposium 2026」で発表した論文「Zombie Cards Back Online: Reviving Expired Credit Cards for…
日本郵便は9月25日、国際郵便物の調査請求Web受付サービスのサーバに外部から不正アクセスを受けた可能性があると発表した。原因と影響範囲は調査中で、サービス再開の時期は決まっていない。
イープラス社は9月29日、電子チケット「スマチケ」の払い戻し情報を管理するシステムに不正アクセスがあり、利用者の個人情報1463件が漏えいしたと発表した。うち751件は、振込先の口座番号なども含む。
CVE を1件ずつ取り上げ、該当判定・緩和策・恒久対応・検知までを手順として書いています。 CVSS・影響を受けるバージョン・修正版・KEV 収載は、NVD / CISA KEV / ベンダーアドバイザリと突合できた内容だけを載せています。
JVN / JVN iPedia の新着(脆弱性の詳細は各ページで確認してください)
Pgpool Global Development Groupが提供するPgpool-IIには、複数の脆弱性が存在します。
株式会社PFUが提供するImage Scanner Driver for Linuxには、複数の脆弱性が存在します。
CERT/CCから本件に関するアドバイザリが公表されました。
Cisco IOS XEソフトウェアのNetwork-Based Application Recognition(NBAR)機能に存在する脆弱性により、認証されていないリモートの攻撃者が影響を受けるデバイスを再起動させ、サービス拒否(DoS)状態を引き起こす可能性があります。こ…
Cisco IOS XEソフトウェアのInternet Key Exchangeバージョン1(IKEv1)実装に存在する脆弱性により、認証済みのリモート攻撃者がサービス拒否(DoS)状態を引き起こす可能性があります。攻撃者はこの脆弱性を悪用するために有効なIKEv1 VPN認証…
Cisco IOS XE ソフトウェアの TLS ライブラリに存在する脆弱性により、認証されていない隣接する攻撃者が影響を受けるデバイスの利用可能なメモリを枯渇させてしまう可能性があります。この脆弱性は、TLS 接続のセットアップ中にメモリリソースが適切に管理されていないことが…
GitLabはGitLab CE/EEのバージョン19.0から19.1.8未満、19.2から19.2.6未満、および19.3から19.3.2未満すべてに影響する問題を修正しました。この問題は特定の条件下で、未認証ユーザーがContent Editor内に貼り付けられたHTMLコ…
GitLabは、GitLab EEのバージョン18.11から19.1.8未満、19.2から19.2.6未満、および19.3から19.3.2未満のすべてのバージョンに影響を与える問題を修正しました。この問題では、特定の条件下において、Security Managerロールを持つ認…
googleapis/mcp-toolboxのcloud-healthcare-fhir-fetch-pageツールには、サーバーサイドリクエストフォージェリ(SSRF)および認証情報漏洩の脆弱性が存在します。このツールは、クライアントから検証されていないpageURLパラメー…
GitLabは、GitLab CE/EEのバージョン15.7から19.1.8未満、19.2から19.2.6未満、および19.3から19.3.2未満のすべてのバージョンに影響する問題を修正しました。本問題では、特定の条件下で認証済みユーザーが環境スコープのパターンマッチャーにおけ…
GitLabは、GitLab CE/EEのバージョン18.6から19.1.8未満、19.2から19.2.6未満、および19.3から19.3.2未満のすべてのバージョンに影響する問題を修正しました。この問題は特定の条件下で、認証済みユーザーがSAML SSOのサインイン制限を回避…
GitLabは、GitLab CE/EEのバージョン18.4.6から19.1.8未満、19.2から19.2.6未満、および19.3から19.3.2未満のすべてのバージョンに影響する問題を修正しました。この問題は特定の条件下で、認証されていないユーザーがGraphQLの複雑度計算…
実際にフィードを取得できたものだけを載せています