OpenAI confirms ChatGPT is down as logins and signups fail
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. …
公的機関の注意喚起とセキュリティ報道の見出しを集めています。掲載しているのは各配信元が公開した見出し・日付・リンクで、本文は配信元のサイトでご覧ください。見出しは取得したまま掲載し、 当サイトによる評価や補足は加えていません。
読んだ見出しのどれから手を付けるか迷ったら、SSVC 判定ツールを使ってください。悪用の状況・公開範囲・自動化可能性・人への影響を選ぶと、 CERT/CC の決定表から「見送り/定期対応/臨時対応/即時対応」のどれかが決まります。
公的機関・CSIRTの発表(リンク先は各機関のサイト)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.  …
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongo…
PostgreSQLに複数の脆弱性
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. &n…
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. …
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string a…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.  …
画像は各配信元のOGP画像を参照しています(複製はしていません)
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. …
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash…
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulner…
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote acces…
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution o…
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zi…
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and …
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 milli…
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSP…
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearb…
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the atta…
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer…
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations t…
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controll…
NTTスマートコネクトは8月19日、不正アクセスを受けて一部停止中のレンタルサーバサービス「スマイルサーバ」について、9月中旬ごろの復旧環境の提供開始を目標にすると発表した。外部機関による調査の完了は8月末を見込む。
2025年日本国際博覧会協会は8月20日、委託業務の再委託先が不正アクセスを受け、大阪・関西万博の関係者やイベント出演者の個人情報を含むメールと添付ファイルが漏えいしたおそれがあると発表した。
CVE を1件ずつ取り上げ、該当判定・緩和策・恒久対応・検知までを手順として書いています。 CVSS・影響を受けるバージョン・修正版・KEV 収載は、NVD / CISA KEV / ベンダーアドバイザリと突合できた内容だけを載せています。
JVN / JVN iPedia の新着(脆弱性の詳細は各ページで確認してください)
CERT/CCから本件に関するアドバイザリが公表されました。
セイコーエプソン株式会社が提供する複数のプリンターおよびスキャナーには、失効したルート証明書が残存しています。
Joomla!コンポーネントAjax Quiz 1.8には、cidパラメータを通じて悪意のあるコードを注入することで、認証されていない攻撃者が任意のSQLクエリを実行できるSQLインジェクションの脆弱性が存在します。攻撃者はoption=com_ajaxquizおよびview=…
Joomla! コンポーネント Bargain Product VM3 1.0 には、SQLインジェクションの脆弱性が存在します。この脆弱性により、認証されていない攻撃者が product_id パラメータを介して悪意のあるコードを注入し、任意のSQLクエリを実行できます。攻撃…
Joomla! コンポーネント Price Alert 3.0.2 には、認証されていない攻撃者が product_id パラメータを通じて悪意のあるコードを注入し、任意のSQLクエリを実行できるSQLインジェクションの脆弱性があります。攻撃者は、product_id パラメー…
Joomla OSDownloads 1.7.4にはSQLインジェクションの脆弱性が存在し、認証されていない攻撃者がidパラメータを通じて悪意のあるコードを注入することで任意のSQLクエリを実行できます。攻撃者は、option=com_osdownloads&view=item…
Joomla! コンポーネント RPC Responsive Portfolio 1.6.1 には、認証されていない攻撃者が id パラメータを通じて悪意のあるコードを注入し、任意の SQL クエリを実行できる SQL インジェクションの脆弱性が含まれています。攻撃者は opt…
Joomla! コンポーネント Quiz Deluxe 3.7.4 には、ajaxaction.flag_question タスクを通じて認証されていない攻撃者が任意のSQLコマンドを実行できるSQLインジェクションの脆弱性が含まれています。攻撃者は stu_quiz_id ま…
Joomla Survey Force Deluxe 3.2.4には、認証されていない攻撃者がinviteパラメータを通じて悪意のあるコードを注入し、任意のSQLクエリを実行できるSQLインジェクションの脆弱性があります。攻撃者は、inviteパラメータに細工されたSQLペイロ…
Joomla! コンポーネント JB Visa 1.0 には、SQLインジェクションの脆弱性が存在し、認証されていない攻撃者が visatype パラメータを介して悪意のあるコードを注入することで、任意のSQLクエリを実行できます。攻撃者は、option=com_bookpro…
Joomla! コンポーネント User Bench 1.0 には、SQLインジェクションの脆弱性が存在し、認証されていない攻撃者が userid パラメータを通じて悪意のあるコードを注入することで、任意のSQLクエリを実行できます。攻撃者は、option=com_userbe…
Joomla! コンポーネント My Projects 2.0 には SQL インジェクションの脆弱性が存在し、認証されていない攻撃者が VerAyari パラメータを通じて悪意のあるコードを注入することで、任意の SQL クエリを実行することが可能です。攻撃者は SQL イン…
実際にフィードを取得できたものだけを載せています