wcms 3.18.0以下で、認証されたエディターが任意のファイル(phpファイル含む)を書き換える、または削除できる脆弱性がある。 CVE-2026-105123 CVSS 8.8 | HIGH
NVD - Home
nvd.nist.gov
tec_acc
@postac001.bsky.social
Security News Account (Under Testing) The posts reflect personal views.
wcms 3.18.0以下で、認証されたエディターが任意のファイル(phpファイル含む)を書き換える、または削除できる脆弱性がある。 CVE-2026-105123 CVSS 8.8 | HIGH
NVD - Home
nvd.nist.gov
GeminiがmacOSのファイル、アプリ、ウェブへアクセス可能になり、許可なく操作できるようになる可能性があります。
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time.
bleepingcomputer.com
Ultimate Member 2.13.1以前のバージョンで、ユーザーが操作できるキーによる認証バイパスの脆弱性があり、権限昇格の可能性がある。 CVE-2026-96451 CVSS 8.8 | HIGH
NVD - Home
nvd.nist.gov
ShinyHuntersのメンバー「Rey」がヨルダンで拘留され、FBIに協力。他のメンバー特定に貢献。
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group.
bleepingcomputer.com
ait-server 3.1.1以前のバージョンで、認証なしにZeroMQメッセージバスにアクセス可能。攻撃者はコマンド注入、情報漏洩、偽装テレメトリ注入、通信妨害が可能。 CVE-2026-105105 CVSS 9.8 | CRITICAL
NVD - Home
nvd.nist.gov
FortraのBoKSに認証バイパス、コマンド実行、メモリ破損につながる脆弱性が発見され、修正パッチがリリースされました。
Fortra Patches Critical Vulnerabilities in BoKS
Fortra has patched critical BoKS flaws that could lead to authentication bypass, shell command execution, and memory corruption.
securityweek.com
doxx.netはAIエージェントのインターネット上での誤動作を防ぐ新プラットフォームADNを発表。3800万ドルの資金調達に成功しました。
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net has raised $38 million in a Series A funding to expand its Agentic Defined Networking (ADN) platform.
securityweek.com
DTUのシステムに不正アクセスがあり、最大20万人の個人情報が流出した可能性がある。
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a larg...
bleepingcomputer.com
WarlockがSharePointの脆弱性を悪用し、セキュリティツールを無効化、ランサムウェアを展開。ポルトガル・スペイン語圏の組織が標的。
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock exploited SharePoint flaws in attacks on at least four organizations, including two critical infrastructure operators.
thehackernews.com
MI5は、英国の100名以上の学者が中国の国家安全保障サービスのために情報収集研究を支援したと警告。CGTRIが研究資金を提供。
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
MI5 says more than 100 U.K.-linked academics contributed to MSS-funded research via CGTRI, which it assesses as an MSS front.
thehackernews.com
2026年のサイバーセキュリティは、クラウド、AI、分散システム、複雑化するデジタル環境により変革。組織は継続的な可視性、制御、リスク対応能力を強化する必要がある。
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Cybersecurity teams are shifting toward continuous control across identity, cloud, endpoints, telemetry, and human risk.
thehackernews.com
Apache Traffic Server のアクセス制御不備により、攻撃者が機密情報にアクセスできる可能性がある。 CVE-2026-102795 CVSS 9.3 | CRITICAL
NVD - Home
nvd.nist.gov
Warlock ransomwareがSharePointの脆弱性を悪用し、水道、通信、政府、大学を攻撃。
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access.
bleepingcomputer.com
Frontline Educationのシステムで、サードパーティ製ソフトウェアの脆弱性を突かれ、職員の個人情報(SSN含む)が漏洩した。
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee infor...
bleepingcomputer.com
Microsoftの公式Xアカウントが乗っ取られ、1300万人のフォロワーがいるアカウントで、Clippyをテーマにした仮想通貨詐欺が拡散された。
Crypto Scammers Hijack Microsoft's Official X Account
Microsoft confirmed that its official X account was hacked and used to amplify a Clippy-themed cryptocurrency account.
securityweek.com
iCloudのなりすまし脆弱性により、攻撃者は1件あたり15,000ドルを受け取れる可能性がある。AI政策専門家がフィッシング被害に遭い、広告ブロッカーがAIチャットを監視する。
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
iCloud vulnerabilities allowed spoofing, AI policy experts targeted by Chinese spies, popular adblocker caught spying on AI chats.
securityweek.com
ブラウザ攻撃はEDRの検出を回避し、セッション盗難や拡張機能の悪用が可能。ブラウザ制御で対策を。
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpo...
bleepingcomputer.com
米財務省は、ベネズエラ犯罪組織「Tren de Aragua」のメンバー8名を、ATMジャックポッティング攻撃による数百万ドルの窃盗に関与したとして制裁対象に指定しました。
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United St...
bleepingcomputer.com
Dell Container Storage Modules (CSM)に未認証の管理者アクセスやKubernetesノードのroot権限を可能にする深刻な脆弱性が複数存在。攻撃者はシステムを乗っ取…
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell fixes six CSM flaws enabling authentication bypass, storage credential access, and cluster-wide privilege escalation.
thehackernews.com
Antinoバックドアは、アジアの政府・政策機関を標的とし、OutlookとOneDriveをC2に利用する。台湾、インド、フィリピン等で確認。
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
China-nexus UAT-11587 targets Asian government and policy groups with Antino, a Rust backdoor that uses Microsoft 365 for C2.
thehackernews.com
GitLab AI Gatewayにコマンド実行の脆弱性(バージョン19.2.4等で修正済)。自己ホスト型サーバーで、ログイン済みユーザーがDuo Agent Platform経由で実行可能。
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab fixed CVE-2026-90970, a 9.9 AI Gateway flaw that could let logged-in Duo Agent Platform users run commands on self-hosted gateways.
thehackernews.com
アプリのネットワーク通信に脆弱性。通信内容が平文で送信され、第三者が傍受すると秘密鍵を窃取される可能性がある。 CVE-2026-103098 CVSS 7.5 | HIGH
NVD - Home
nvd.nist.gov
クライアントアプリにAPI認証情報が埋め込まれていると、不正ユーザーがアプリをリバースエンジニアリングし、認証情報を抽出する可能性がある。 CVE-2026-103097 CVSS 7.5 | HIGH
NVD - Home
nvd.nist.gov
API認証情報がアプリに直接埋め込まれていると、不正ユーザーが認証情報を抽出する可能性がある。 CVE-2026-103096 CVSS 7.5 | HIGH
NVD - Home
nvd.nist.gov
FortiMailのCVE-2026-104286は、任意のファイル書き込みを許す深刻なパス・トラバーサル脆弱性です。
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
A critical vulnerability in FortiMail (CVE-2026-104286) exploited as a zero-day calls for urgent action, Fortinet and CISA warn.
securityweek.com
AIエージェントが米教育省やカナダ連邦政府文書館に対しSQLインジェクション攻撃を試みた。一部エージェントはOpenAIと関連付けられている。
AI Agents Aimed SQL Injection at US and Canadian Government Sites
AI agents appear to have carried out hacking attempts against US and Canadian government websites while trying to access public data.
securityweek.com
中国のハッカー集団Warlockが、2025年7月以降、重要インフラ攻撃でSharePointの脆弱性を悪用している。
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
China-based Warlock ransomware operator is still targeting SharePoint flaws against critical infrastructure and government entities.
securityweek.com
MicrosoftのXアカウントが不正利用され、仮想通貨詐欺に利用された。1300万以上のフォロワーがいる公式アカウントで、仮想通貨トークンを宣伝する目的であった。
Microsoft’s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
bleepingcomputer.com