サイバーセキュリティニュース by ずんだもん

daily-news-by-yukkuri

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん

  1. Sep 7

    Magentoゼロデイに緊急パッチ、MFA突破258組織【セキュリティ 2026/09/08】

    Magento StyleSmugglerの緊急パッチ、フィッシング代行BigBear2.0のMFA突破、Metabase経由のMathspace108万人流出、航空旅客2億2000万件露出、FreeIPAの認証なし管理者権限、GoogleのAI攻撃フレームワーク報告など8件を対策まで解説します。 ▼ 今日のトピック ・Magento・Adobe Commerceゼロデイ「StyleSmuggler」に9月8日パッチ(CVE-2026-75650、CVSS10.0) ・フィッシング代行「BigBear 2.0」が多要素認証を突破、258組織で5137件の認証情報 ・学習アプリMathspace、Metabaseの欠陥で108万人分流出(ShinyHunters疑い) ・航空旅客2億2000万件超、ベトナム関連の事前旅客情報データベースが露出 ・FreeIPAに認証不要で管理者権限を奪う脆弱性連鎖(CVE-2026-76578、CVSS9.8) ・Google、生成AIを組み込んだ攻撃自動化フレームワーク「Recon」を報告 ・Bing検索汚染「BengalSEO」がMayaBotとサポート詐欺へ誘導 ・Grindr、HIV状態の広告目的共有をめぐり英国で2600万ポンドの和解 ▼ 参考記事・ソース ・The Hacker News「Adobe Patches Magento Zero-Day」 https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html ・Bleeping Computer「BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations」 https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ ・Bleeping Computer「Mathspace discloses data breach affecting over 1 million people」 https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/ ・Bleeping Computer「220 million traveler records exposed in Vietnam-linked APIS leak」 https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/ ・The Hacker News「FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials」 https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html ・Bleeping Computer「Hackers build AI frameworks for widescale credential theft」 https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/ ・The Hacker News「BengalSEO Poisons Bing Search Results」 https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html ・The Hacker News「Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing」 https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html #セキュリティ #脆弱性 #フィッシング #多要素認証 #ずんだもん

  2. Sep 3

    裁判所の封印記録も流出?供給網攻撃と重大脆弱性7選【2026/09/04】

    裁判所バックアップ侵害、供給網攻撃の容疑者逮捕、シスコとHPEの重大脆弱性、開発環境乗っ取りなど7件を対策まで解説します。 ▼ 今日のトピック ・米裁判所システム侵害と社会保障番号流出の恐れ ・供給網攻撃シャイフルードの容疑者2人を逮捕 ・シスコ・ネクサス9000とIOS XRの重大欠陥 ・クラウド開発環境コーダーのレジストリ乗っ取り ・セルビア学生運動メンバーへのペガサス感染 ・HPEアルーバOSの重大バッファオーバーフロー ・46カ国601件へ広がった遠隔管理ソフト誘導型フィッシング ▼ 参考記事・ソース ・The Hacker News「裁判所ソフト侵害」 https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html ・Krebs on Security「TeamPCP容疑者を逮捕」 https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/ ・The Hacker News「Cisco Nexus 9000の重大欠陥」 https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html ・BleepingComputer「Coderレジストリ侵害」 https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/ ・The Hacker News「Pegasusゼロクリック感染」 https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html ・BleepingComputer「HPE ArubaOS-CXの欠陥」 https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/ ・The Hacker News「46カ国に広がるRMMフィッシング」 https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html #サイバーセキュリティ #情報漏洩 #脆弱性 #フィッシング #ゆっくり解説 #ずんだもん

  3. Sep 2

    免許証1億5300万件とAI開発端末を狙う新攻撃【2026/09/03】

    正規に見える本人確認、ソフト配布、広告、VPN、電話、バックアップが攻撃の入口に。個人と管理者が今すぐ取れる対策まで整理します。 ▼ 今日のトピック ・運転免許証1億5300万件超を売るサービスをFBIが捜査 ・悪性Git設定がAIコーディングエージェントに命令 ・偽インストーラーがWindowsの更新と防御を弱体化 ・Meta広告からAndroidへ入るStreamRat ・SonicWall、Switchvox、WordPressの脆弱性 ▼ 参考記事・ソース ・Krebs on Security「FBI Probes Service Selling 153M+ Drivers Licenses」 https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ ・The Hacker News「Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code」 https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html ・The Hacker News「Fake Software Installers Disable Windows Update and Weaken Microsoft Defender」 https://thehackernews.com/2026/09/fake-software-installers-disable.html ・The Hacker News「Meta Ads Push StreamRat Android Trojan」 https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html ・The Hacker News「Attackers Exploit Two SonicWall SMA 1000 Zero-Days」 https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html ・BleepingComputer「Hackers exploit Sangoma Switchvox flaw」 https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/ ・BleepingComputer「WordPress backup plugin flaw exposes millions of sites」 https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/ #サイバーセキュリティ #情報漏洩 #脆弱性 #ゆっくり解説 #ずんだもん #四国めたん

About

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん