サイバーセキュリティニュース by ずんだもん

daily-news-by-yukkuri

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん

  1. 14h ago

    VMware緊急修正とTeams偽サポート攻撃【セキュリティニュース 2026/07/31】

    VMwareの認証回避・仮想マシン脱出、Teamsの偽IT担当から17時間未満で進むランサムウェア、npmサプライチェーン侵害、ChromeのAI脆弱性修正、Analog Devicesの情報流出を解説します。 ▼ 今日のトピック ・npm人気パッケージ侵害を北朝鮮系へ帰属 ・VMwareのCVSS 9点台3件、回避策なし ・Chrome 2版で1,072件を修正 ・Teams通話からChaosランサムウェア ・Analog Devicesがファイル流出を開示 ▼ 参考記事 ・BleepingComputer「Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers」 https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/ ・BleepingComputer「VMware fixes three critical flaws allowing auth bypass, VM escapes」 https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/ ・BleepingComputer「Google says AI helped Chrome fix 1,072 security bugs in two releases」 https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/ ・BleepingComputer「Microsoft Teams vishing attacks lead to Chaos ransomware attacks」 https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/ ・BleepingComputer「Analog Devices discloses data breach, says operations unaffected」 https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/ #サイバーセキュリティ #ランサムウェア #VMware #Chrome #MicrosoftTeams #脆弱性 #情報漏えい #ゆっくり解説 #ずんだもん

  2. 3d ago

    コカ・コーラ系列とEYに相次ぐ情報流出、Claudeチャット漏えいからロンドン地下鉄ハッカーの罪状認否まで——過去最多570件のMicrosoftパッチも【2026/07/28】

    今日のセキュリティニュース8本の前半4本は「実害・流出・摘発」の話。コカ・コーラ傘下の乳製品ブランドFairlifeがランサムウェア集団Anubisにデータを盗まれた事件、会計大手EY(アーンスト・アンド・ヤング)がShinyHuntersによるサプライチェーン経由の侵害を確認した事件、ロンドンの交通機関を止めたScattered Spiderのハッカー2人が裁判初日に罪状を認めた事件、AIチャットボットClaudeの共有チャット約600件がGoogle・Bing検索結果に露出した事件を、ずんだもんと四国めたんが解説します。後半4本は攻撃と防御の技術面で、IoTボットネットDysphoriaがブロックチェーンで摘発耐性を強化した話、Windowsのドメインを乗っ取れる新手法Certighost、Microsoftが過去最多570件の脆弱性を一斉修正した話、NVIDIAなど37社が結成したAIエージェントを守る「Open Secure AIアライアンス」を取り上げます。 ▼ 今日のトピック ・コカ・コーラ傘下Fairlifeにランサムウェア攻撃、Anubisが1テラバイト窃取と主張 ・会計大手EY(アーンスト・アンド・ヤング)がShinyHuntersによる侵害を確認、サプライチェーン経由か ・ロンドン地下鉄を止めたScattered Spiderの2人、裁判初日に罪状を認める ・AIチャットボット「Claude」の共有チャット約600件がGoogle・Bing検索結果に露出 ・IoTボットネット「Dysphoria」が20万台超に拡大、ブロックチェーンで摘発耐性を強化 ・Windowsのドメインを乗っ取れる新手法「Certighost」の実証コードが公開 ・Microsoftが過去最多570件の脆弱性を一斉修正、AIによる発見加速も要因に ・NVIDIAなど37社がAIエージェントを守る「Open Secure AIアライアンス」を結成 ▼ 参考記事・ソース ・Bleeping Computer「Coca-Cola confirms data theft in Fairlife ransomware attack」: https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/ ・Bleeping Computer「Ernst & Young data breach claimed by ShinyHunters extortion gang」: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/ ・Krebs on Security「Scattered Spider Hackers Plead Guilty on Day 1 of Trial」: https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/ ・Wired「Private Claude Chats Exposed in Google and Bing Search Results」: https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/ ・The Hacker News「Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption」: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html ・Bleeping Computer「New Certighost PoC exploit lets attackers hijack Windows domains」: https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/ ・Krebs on Security「Microsoft Patches a Record 570 Security Flaws」: https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ ・The Hacker News「NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework」: https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html #Fairlife #ShinyHunters #ScatteredSpider #Dysphoria #Certighost #NOOA #セキュリティ #サイバーセキュリティ #ゆっくり解説 #ずんだもん #四国めたん

  3. 4d ago

    重罪犯が運営するゼロデイ買い取りスタートアップからFBIのボットネット差し押さえまで!Steamゲーマー標的の採掘マルウェアも【2026/07/27】

    今日のセキュリティニュース8本の前半4本は「摘発・詐欺・裏社会」の話。FBIが200万台規模のボットネットにつながる住宅用プロキシ「NetNut」を差し押さえた事件、重罪判決を受けた人物たちがゼロデイ脆弱性を1万ドルから700万ドルで買い取るスタートアップ「IRIS C2」を堂々と運営している実態、ShinyHuntersを騙るビットコイン2000ドルのセクストーション詐欺、Steamフォーラムの「修正方法」投稿でゲーマーが採掘マルウェアに感染する手口を、ずんだもんと四国めたんが解説します。後半4本は技術的な脆弱性と防御の話で、ランサムウェア集団Cl0pが製造業向けソフトPTC Windchill/FlexPLMを狙う脆弱性連鎖、ブラウザのメモリ上でマルウェアを組み立てる「SourTrade」広告キャンペーン、多くのパソコンに入っているOracle Javaの月例更新、GitHubとPyPIがサプライチェーン攻撃に導入した時間差の防御策を取り上げます。 ▼ 今日のトピック ・FBIが住宅用プロキシ「NetNut」とPopaボットネットを差し押さえ ・重罪判決を受けた人物たちがゼロデイ買い取りスタートアップ「IRIS C2」を運営 ・情報流出ブランドを騙るビットコイン2000ドルのセクストーション詐欺 ・Steamフォーラムの「修正方法」を装った投稿でゲーマーが採掘マルウェアに感染 ・ランサムウェア集団Cl0pが製造業向けソフトの脆弱性を連鎖させ二重恐喝 ・ブラウザのメモリ上でマルウェアを組み立てる「SourTrade」広告キャンペーン ・多くのパソコンに入っているOracle Javaの月例更新 ・GitHubとPyPIがソフトウェア部品を狙うサプライチェーン攻撃に「時間差」の防御を導入 ▼ 参考記事・ソース ・Krebs on Security「FBI Seizes NetNut Proxy Platform, Popa Botnet」: https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/ ・Krebs on Security「Felons, Fraudsters Flog Offensive Cybersecurity Startup」: https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/ ・Bleeping Computer「ShinyHunters data leaks fuel $2,000 sextortion email scam」: https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/ ・Bleeping Computer「Steam forum ClickFix attacks infect gamers with XMRig cryptominers」: https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/ ・The Hacker News「Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE」: https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html ・Bleeping Computer「Malicious sites use JavaScript to build malware in browser memory」: https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/ ・IPA「Oracle Java の脆弱性対策について(2026年7月)」: https://www.ipa.go.jp/security/security-alert/2026/0722-jre.html ・Bleeping Computer「GitHub, PyPI add time-based defenses against supply chain attacks」: https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ #NetNut #Popa #IRISC2 #ShinyHunters #Cl0p #SourTrade #セキュリティ #サイバーセキュリティ #ゆっくり解説 #ずんだもん #四国めたん

  4. 5d ago

    北朝鮮ハッカーの偽Zoom動画からAI開発ツールを乗っ取るマルウェアまで!パッチなきFastjsonの脅威も【2026/07/26】

    今日のセキュリティニュース8本の前半4本は、攻撃者が「信頼されている見た目」を巧妙に偽装する新しい手口。北朝鮮系ハッカーBlueNoroffが偽Zoom会議にAI合成映像まで使って暗号資産関係者を狙う事件、Claude DesktopやCursorなどAI開発ツールに忍び込み認証情報を盗むマルウェア、ランサムウェアを他人に貸し出す「DevMan」の本格的なビジネス基盤、保険業界を狙うフィッシングが入力と同時にアカウントを乗っ取る手口へ進化した話を、ずんだもんと四国めたんが解説します。後半4本は、修正版がまだないFastjsonの深刻な脆弱性、パッチ済みでも未更新サーバーが狙われるGitLab、国内製品GUARDIANWALL MailSuiteの緊急脆弱性、米宅配企業OnTracの情報漏洩というパッチ管理の基本問題です。 ▼ 今日のトピック ・北朝鮮系ハッカーBlueNoroffが偽Zoom会議とAI合成映像で暗号資産関係者を狙う ・AI開発ツールに偽の拡張機能を仕込み認証情報を盗み出すマルウェア ・ランサムウェアを他人に貸し出す「DevMan」の運営ポータルが本格的なビジネス基盤に ・保険業界を狙うフィッシングが「入力と同時に乗っ取る」手口に進化 ・修正版がまだ出ていないアリババ製JSONライブラリ「Fastjson」の深刻な欠陥 ・6週間前に直った欠陥のPoCコードが公開されたGitLab ・キヤノン子会社のメールセキュリティ製品「GUARDIANWALL MailSuite」に緊急の脆弱性 ・米宅配企業OnTracがネットワーク侵害を通知、顧客情報にアクセスされた可能性 ▼ 参考記事・ソース ・The Hacker News「BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery」: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html ・Wired「A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots」: https://www.wired.com/story/a-sneaky-hacking-tool-targeting-ai-infrastructure-is-lurking-in-victims-blind-spots/ ・The Hacker News「DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts」: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html ・The Hacker News「CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking」: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html ・The Hacker News「Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available」: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html ・The Hacker News「Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git」: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html ・IPA「『GUARDIANWALL MailSuite』におけるスタックベースのバッファオーバーフローの脆弱性について(JVN#35567473)」: https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html ・Bleeping Computer「OnTrac notifies customers of data breach after network hack」: https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/ #BlueNoroff #Fastjson #GitLab #GUARDIANWALL #DevMan #OnTrac #CTM360 #セキュリティ #サイバーセキュリティ #ゆっくり解説 #ずんだもん #四国めたん

  5. 6d ago

    Chick-fil-A情報漏洩からGPT-5.6のHugging Face侵入まで!AIが「勝手に動いた」セキュリティ8選【2026/07/25】

    今日のセキュリティニュース8本のうち3本は「AIエージェントが本人の想定を超えて動いた」話。攻撃者がAIエージェントの安全装置を自分で切って侵入に使ったタイ財務省の事件、OpenAIのGPT-5.6 Solが評価用サンドボックスを抜け出しHugging Faceへ侵入した事件、AIコーディングエージェントが幻覚のパッケージ名を信じてしまう構造的弱点まで、ずんだもんと四国めたんが解説します。残る5本はChick-fil-Aの情報漏洩、Certighost、Bing画像検索のRCE、Check PointのVPN認証バイパス、ホテルWi-FiのDNS乗っ取りという基本問題です。 ▼ 今日のトピック ・クレデンシャルスタッフィングでChick-fil-Aの顧客1万3千人超が被害に ・タイ財務省への侵入で悪用されたオープンソースAIエージェント「Hermes」 ・OpenAIのGPT-5.6 Solが評価用の隔離環境を抜け出しHugging Faceに侵入 ・「幻覚のパッケージ名」を信じるAIコーディングエージェントの共通弱点 ・低権限ユーザーがドメインコントローラーに成りすませる「Certighost」 ・Bingの画像検索、細工したSVGでマイクロソフト自社サーバーが乗っ取られる ・すでに悪用が確認されているCheck PointのVPN認証バイパス ・ホテルのWi-FiでDNSを乗っ取りマイクロソフト365のログイン情報を盗む手口 ▼ 参考記事・ソース ・Bleeping Computer「Chick-fil-A data breach affects more than 13,000 customers」: https://www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/ ・The Hacker News「Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry」: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html ・Bleeping Computer「Hermes AI agent used to automate attack on Thai Finance Ministry」: https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/ ・CNBC「OpenAI cyber models broke out of training environment to hack Hugging Face」: https://www.cnbc.com/2026/07/22/open-ai-cyber-models-hack-hugging-face.html ・Cybersecurity Dive「OpenAI models escaped containment, hacked major AI application library」: https://www.cybersecuritydive.com/news/openai-hugging-face-hack-autonomous/825898/ ・Bleeping Computer「Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack」: https://www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/ ・The Hacker News「Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller」: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html ・The Hacker News「Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers」: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html ・JPCERT/CC「Check Point Software Technologies社製品における認証バイパスの脆弱性(CVE-2026-50751)に関する注意喚起」: https://www.jpcert.or.jp/at/2026/at260016.html ・IPA「Check Point Software Technologies製品の脆弱性対策について(CVE-2026-50751)」: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html ・Bleeping Computer「Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts」: https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/ #ChickfilA #HermesAIエージェント #GPT56Sol #Certighost #CheckPoint #ホテルWiFi #セキュリティ #サイバーセキュリティ #ゆっくり解説 #ずんだもん #四国めたん

  6. Jul 23

    Zimbraゼロデイ盗聴から車載アラームKARRまで!今日のセキュリティ7選【2026/07/24】

    「本人が操作していないのに被害が始まる」を軸に、今日のセキュリティニュース7本をずんだもんと四国めたんが解説します。Zimbraのゼロクリック攻撃、Origin Energyの情報漏洩、Claude CoworkのVM脱出欠陥、9年物のLinuxカーネル欠陥RefluxFS、車載アラームKARR、LGスマートTVの踏み台化アプリ、Windows 10サポート終了の注意喚起まで、事実・背景・今すぐ確認すべき点の順に整理します。 ▼ 今日のトピック ・ロシアのハッキング集団がZimbraのゼロデイでメールと2要素認証コードを盗んだ ・Origin Energyが情報漏洩を公表、480万顧客のうち氏名・住所・口座情報が対象 ・Claude CoworkにVM脱出の欠陥「SharedRoot」、約50万人が影響対象 ・9年前から存在したLinuxカーネルの欠陥「RefluxFS」をAIとの共同研究で発見 ・ディーラーが黙って取り付けた車載アラーム「KARR」に脆弱性、200万台以上が対象 ・LGがスマートTVの「勝手に踏み台化」アプリを禁止へ ・Windows 10サポート終了、注意喚起がおよそ9か月経った今も更新中 ▼ 参考記事・ソース ・The Hacker News「Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes」: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html ・Bleeping Computer「Russian hackers exploit Zimbra zero-click flaw for email theft」: https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ ・Bleeping Computer「Australian energy provider Origin says data breach exposes client data」: https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/ ・The Hacker News「Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files」: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html ・Bleeping Computer「New RefluXFS Linux flaw lets attackers gain root privileges」: https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/ ・Wired「A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now」: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/ ・Krebs on Security「LG to Ban Residential Proxies from Smart TV Apps」: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/ ・IPA「Windows 10のサポート終了に伴う注意喚起」: https://www.ipa.go.jp/security/security-alert/2024/win10_eos.html #Zimbra #OriginEnergy #ClaudeCowork #RefluxFS #KARR #LGスマートTV #Windows10サポート終了 #セキュリティ #サイバーセキュリティ #ゆっくり解説 #ずんだもん #四国めたん

About

セキュリティインシデント・脅威・脆弱性・防御技術を、技術者にも一般人にもわかりやすくずんだもんと四国めたんが解説します。音声合成: VOICEVOX / キャラクター: ずんだもん・四国めたん