サイバーセキュリティニュース by ずんだもん

daily-news-by-yukkuri

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん

  1. 2日前

    裁判所の封印記録も流出?供給網攻撃と重大脆弱性7選【2026/09/04】

    裁判所バックアップ侵害、供給網攻撃の容疑者逮捕、シスコとHPEの重大脆弱性、開発環境乗っ取りなど7件を対策まで解説します。 ▼ 今日のトピック ・米裁判所システム侵害と社会保障番号流出の恐れ ・供給網攻撃シャイフルードの容疑者2人を逮捕 ・シスコ・ネクサス9000とIOS XRの重大欠陥 ・クラウド開発環境コーダーのレジストリ乗っ取り ・セルビア学生運動メンバーへのペガサス感染 ・HPEアルーバOSの重大バッファオーバーフロー ・46カ国601件へ広がった遠隔管理ソフト誘導型フィッシング ▼ 参考記事・ソース ・The Hacker News「裁判所ソフト侵害」 https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html ・Krebs on Security「TeamPCP容疑者を逮捕」 https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/ ・The Hacker News「Cisco Nexus 9000の重大欠陥」 https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html ・BleepingComputer「Coderレジストリ侵害」 https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/ ・The Hacker News「Pegasusゼロクリック感染」 https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html ・BleepingComputer「HPE ArubaOS-CXの欠陥」 https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/ ・The Hacker News「46カ国に広がるRMMフィッシング」 https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html #サイバーセキュリティ #情報漏洩 #脆弱性 #フィッシング #ゆっくり解説 #ずんだもん

  2. 3日前

    免許証1億5300万件とAI開発端末を狙う新攻撃【2026/09/03】

    正規に見える本人確認、ソフト配布、広告、VPN、電話、バックアップが攻撃の入口に。個人と管理者が今すぐ取れる対策まで整理します。 ▼ 今日のトピック ・運転免許証1億5300万件超を売るサービスをFBIが捜査 ・悪性Git設定がAIコーディングエージェントに命令 ・偽インストーラーがWindowsの更新と防御を弱体化 ・Meta広告からAndroidへ入るStreamRat ・SonicWall、Switchvox、WordPressの脆弱性 ▼ 参考記事・ソース ・Krebs on Security「FBI Probes Service Selling 153M+ Drivers Licenses」 https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ ・The Hacker News「Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code」 https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html ・The Hacker News「Fake Software Installers Disable Windows Update and Weaken Microsoft Defender」 https://thehackernews.com/2026/09/fake-software-installers-disable.html ・The Hacker News「Meta Ads Push StreamRat Android Trojan」 https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html ・The Hacker News「Attackers Exploit Two SonicWall SMA 1000 Zero-Days」 https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html ・BleepingComputer「Hackers exploit Sangoma Switchvox flaw」 https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/ ・BleepingComputer「WordPress backup plugin flaw exposes millions of sites」 https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/ #サイバーセキュリティ #情報漏洩 #脆弱性 #ゆっくり解説 #ずんだもん #四国めたん

  3. 6日前

    Claude乗っ取り・870万人流出・ゾンビカード【セキュリティ 2026/08/31】

    ログイン済みセッションの窃取、空港予約情報の流出、WordPress脆弱性、期限切れVisaカードの悪用など7件を、仕組みと対策まで解説します。 ▼ 今日のトピック ・Claudeのログインセッション窃取 ・マンチェスター空港グループ870万人分の流出 ・WordPress人気プラグイン3種の脆弱性 ・TerminalFixと偽CAPTCHA ・スマートテレビの住宅用プロキシ化 ・期限切れVisaのゾンビカード攻撃 ・Braveの無料メールエイリアス ▼ 参考記事・ソース ・BleepingComputer「Claude sessions hijacked」 https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/ ・BleepingComputer「Manchester Airports hack」 https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/ ・The Hacker News「Critical WordPress flaws」 https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html ・The Hacker News「TerminalFix」 https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html ・Krebs on Security「LG to Ban Residential Proxies」 https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/ ・The Hacker News「Zombie Card Attack」 https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html ・BleepingComputer「Brave email aliases」 https://www.bleepingcomputer.com/news/security/brave-browser-adds-email-aliases-to-help-users-evade-tracking/ #セキュリティ #サイバー攻撃 #情報漏洩 #WordPress #Claude #ゆっくり解説 #ずんだもん

番組について

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん