エピソード

  • Cyber Security News for September 2 2026 - Daily DefSec Brief
    2026/09/02
    1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ 2. JFrog Artifactory authentication bypass exploited four days after the patch — CVE-2026-82329 — SC World — https://www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release 3. Langflow remote code execution used to harvest OpenAI and AWS keys — CVE-2026-0768 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/ 4. Twenty-two thousand Exchange servers still unpatched against a mailbox takeover flaw — CVE-2026-62911 — BleepingComputer — https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 5. AI agents ran a full ransomware intrusion in under ten hours — Unit 42 — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ 6. FBI warns of consent phishing that takes an account without a password — CyberScoop — https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/ 7. Sangoma Switchvox SQL injection is being exploited seven weeks after the fix — CVE-2026-9586 — The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html 8. GeoNetwork chain gives unauthenticated code execution on government geoportals — CVE-2026-63219 — The Hacker News — https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html 9. Counterfeit software download sites are installing malware that turns Defender off — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ 10. Phishing crew abuses a real endpoint-management platform to install ScreenConnect — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/ 11. Airport breach traced to admin keys sitting in the websites' own JavaScript — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/ 12. Stolen API key burned 600,000 dollars of model credits before anyone noticed — The Register — https://www.theregister.com/security/2026/09/01/attacker_stole_a_metr_api_key_used_600k_worth_of_credits_and_no_one_noticed_for_weeks/5293730 13. Hugging Face Transformers writes remote code to disk before asking permission — CVE-2026-80047 — CERT/CC — https://kb.cert.org/vuls/id/456290 14. SageMaker SDK leaves its signing key in cleartext where any account role can read it — CVE-2026-83551 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/ 15. Thirteen poisoned Composer packages on Packagist attack visitors of the sites that install them — CVE-2025-31277, CVE-2025-43398, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529 — The Hacker News — https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html 16. Attackers are installing Apache modules that quietly proxy visitors to phishing pages — Check Point Research — https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/
    続きを読む 一部表示
    5 分
  • Cyber Security News for September 1 2026 - Daily DefSec Brief
    2026/09/01
    1. OpenSearch SQL plugin deserialization flaw gives a read-only user code execution — CVE-2026-83497 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/ 2. BGP hijack pushed a malicious Virtualizor update onto hypervisor management servers — Virtualizor — https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ 3. McKesson breach ran from vishing calls through Okta into Salesforce and Snowflake — SC World — https://www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records 4. Password-spraying campaign hit AWS root accounts at more than 150 organizations — Datadog Security Labs — https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/ 5. Scanners are forging AI-crawler user agents to hunt for exposed credentials — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/ 6. A honeypot posing as a free LLM endpoint caught a real coding agent handing over its tools — SANS ISC — https://isc.sans.edu/diary/rss/33298 7. Mirage Kitten hides two new cross-platform RATs in trojanized coding-challenge archives — Securelist — https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/ 8. Researcher drops a working privilege-escalation exploit for Kaspersky Endpoint Security — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/ 9. Residential proxy networks rent out home connections with clean IP reputations — Ars Technica — https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/ 10. BREEZE COMET manipulates Brazilian banking software to move fraudulent transfers — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/ 11. Guildma delivery is geofenced to Brazil and hides its payload in an alternate data stream — SANS ISC — https://isc.sans.edu/diary/rss/33300 12. Boston Scientific outage leaves newly implanted heart devices without remote monitoring — The Register — https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537 13. OpenClaw 2.0 makes the agent harness easier to install and leaves security to the user — The Register — https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492 14. CrowdSec 1.8.0 ships two denial-of-service fixes alongside new bot detection — Help Net Security — https://www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/
    続きを読む 一部表示
    5 分
  • Cyber Security News for August 31 2026 - Daily DefSec Brief
    2026/08/31
    1. PaperCut ships a second emergency patch after attackers chain two zero-days — CVE-2026-82078, CVE-2026-81578 — SecurityWeek — https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/ 2. Ruby on Rails file-read flaw is being exploited for remote code execution — CVE-2026-66066 — SecurityWeek — https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/ 3. Self-spreading worm planted in an npm package with 150,000 weekly downloads — Cyber Security News — https://cybersecuritynews.com/popular-npm-package/ 4. China-linked Fire Ant moves into Cisco routers and TACACS servers to blind logging — The Hacker News — https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html 5. AWS Systems Manager agent path traversal lets a limited user write files as root — CVE-2026-81849 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-091-aws/ 6. TerminalFix pastes a fake CAPTCHA command into Windows Terminal and opens a reverse tunnel — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ 7. Fake IT help desk calls over external Teams accounts end in NTLM relay to the domain controller — Unit 42 — https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ 8. Infostealers are lifting live Claude sessions and walking past two-factor — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/ 9. Nineteen Chrome and Edge extensions were backdoored through automatic updates — The Hacker News — https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html 10. Russian operators embed a nuclear-weapons prompt in malware to make AI analysis tools refuse — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/ 11. A file that passes as an MP4 carries 6.5 MB of encrypted NetSupport RAT — Censys — https://censys.com/blog/fake-mp4-file-carries-malicious-payload/ 12. Voicemail-themed SVG attachments smuggled JavaScript past email filters at 5,527 organizations — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/ 13. ValleyRAT ships as signed adware so users add it to their own exclusion lists — Securelist — https://securelist.com/valleyrat-backdoor-adware/121175/ 14. Metasploit ships modules for Forgejo file read and a batch of other recent flaws — CVE-2026-59774, CVE-2026-3576 — Rapid7 — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners 15. Composer flaw lets a malicious package change permissions on files it does not own — CVE-2026-59944 — Cyber Security News — https://cybersecuritynews.com/composer-flaw-expose-ssh-keys/ 16. UK NCSC warns of rising OT targeting through internet-exposed systems and edge devices — Industrial Cyber — https://industrialcyber.co/control-device-security/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices/ 17. CISA red team walked one network to domain admin and struggled badly in the other — Cybersecurity Dive — https://www.cybersecuritydive.com/news/cisa-red-team-exercises-lessons-cloud-soc/828733/ 18. Microsoft tells everyone to ignore Defender alerts saying antivirus is off — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/
    続きを読む 一部表示
    6 分
  • Cyber Security News for August 28 2026 - Daily DefSec Brief
    2026/08/28
    1. ownCloud unauthenticated file access flaw added to CISA KEV — CVE-2023-49105 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. ServiceNow patches three CVSS 10.0 flaws in its AI Platform — CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 — The Hacker News — https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html 3. cPanel flaw lets a hosting customer take root on the whole server — CVE-2026-65643 — The Hacker News — https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html 4. Next.js patches two critical unauthenticated remote code execution flaws — CVE-2026-75604 — The Hacker News — https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html 5. Linux kernel IPv6 privilege escalation added to CISA KEV — CVE-2026-53362 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 6. JFrog Artifactory path-traversal flaw added to CISA KEV — CVE-2026-66384 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 7. APT28-linked HOOKEDGE backdoor hits European government and diplomatic targets — The Hacker News — https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html 8. Ghost SPN technique makes Kerberoasting far harder to spot — Cyber Security News — https://cybersecuritynews.com/active-directory-spn-misconfigurations/ 9. ASE2000 utility test set has XXE and certificate-validation flaws — CVE-2018-1285, CVE-2026-18717 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04 10. All-Line Fuel-Boss systems carry two remote code execution flaws — CVE-2018-19518, CVE-2019-11043 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02 11. Ebyte NA111-M gateway ships with 13 flaws and no authentication — CVE-2026-69658, CVE-2026-71187, CVE-2026-73125 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05 12. Rockwell OTTO Fleet Manager stores passwords with a weak bcrypt work factor — CVE-2026-75112 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03 13. Exposed open directory reveals Moobot still running after 2024 takedown — Censys — https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/ 14. Executive Social Security numbers sell on dark web markets — Rapid7 — https://www.rapid7.com/blog/post/tr-identity-as-a-service-dark-web-marketplaces-executive-ssn
    続きを読む 一部表示
    5 分
  • Cyber Security News for August 27 2026 - Daily DefSec Brief
    2026/08/27
    1. PaperCut NG/MF under active exploitation, no patch yet — Help Net Security — https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/ 2. GPUThor Rowhammer defeats ECC on NVIDIA workstation GPUs for root — The Hacker News — https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html 3. Veeam ONE coerces SMB auth from service account — CVE-2026-65641 — Cyber Security News — https://cybersecuritynews.com/veeam-backup-replication-flaw-exposes/ 4. Three 10.0 flaws patched across Ubiquiti UniFi — CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 — CyberScoop — https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/ 5. Attackers targeting exposed AI gateways to steal keys and mine crypto — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/ 6. Spark RAT campaign abuses OPSWAT driver to kill security tools — CVE-2026-36425 — The Hacker News — https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html 7. AI-agent llms.txt files push unowned code into corporate networks — Ars Technica — https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/ 8. Claude Code Opus 5 Auto Mode falls to website-summary prompt injection — Embrace The Red — https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/ 9. Chinese-speaking operator loots Philippine nuclear and naval data via old flaws — Cyber Security News — https://cybersecuritynews.com/hackers-exploit-owncloud/ 10. Aurora ransomware affiliate used an AI coding assistant across 20+ intrusions — Cyber Security News — https://cybersecuritynews.com/ransomware-hacker-uses-ai/ 11. GoCaracal malware fetches C2 from an Ethereum smart contract — The Hacker News — https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html 12. AWS details how stolen cloud credentials escalate into full breaches — Cyber Security News — https://cybersecuritynews.com/aws-shows-how-hackers/ 13. Nimbus Manticore adds TWOSTROKE-like backdoor and SSH tunneler — SC World — https://www.scworld.com/brief/nimbus-manticore-expands-infrastructure-and-malware-arsenal 14. Ajax.NET Professional deserialization flaw added to CISA KEV — CVE-2021-23758 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 15. Microsoft SQL Server RCE added to CISA KEV — CVE-2019-1068 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
    続きを読む 一部表示
    5 分
  • Cyber Security News for August 26 2026 - Daily DefSec Brief
    2026/08/26
    1. CISA adds actively exploited Gitea code-injection flaw to KEV — CVE-2026-60004 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. SonicWall NetExtender Linux client path traversal allows root file write — CVE-2026-66152 — Cyber Security News — https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/ 3. Chrome 152 patches over 300 flaws, most found internally by AI — CVE-2026-79282 (+300 more) — SecurityWeek — https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/ 4. NVIDIA NemoClaw flaw lets a malicious webpage poison a local AI model — CVE-2026-65105 — Cyber Security News — https://cybersecuritynews.com/nvidia-nemoclaw-flaw/ 5. Siemens SIMATIC IoT2050 Advanced unauthenticated RCE via Node-RED — CVE-2026-58115 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03 6. Mirage2FA phishing kit bypasses MFA to hijack Microsoft 365 sessions — The Hacker News — https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html 7. Malicious npm packages abuse trusted mirrors to host ClickFix phishing — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/ 8. Iran-linked actors hide Dindoor backdoor behind the Deno runtime — Cyber Security News — https://cybersecuritynews.com/iran-linked-hackers-abuse-developer-tool/ 9. SLEEPWALKER backdoor waits for a magic packet, then runs its own bytecode — The Hacker News — https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html 10. 28,000 exposed .git repositories leak credentials and financial records — Cyber Security News — https://cybersecuritynews.com/28000-exposed-git-repositories/ 11. RMM tools abused in 46-country phishing campaign for remote access — Cyber Security News — https://cybersecuritynews.com/hackers-abuse-legitimate-rmm-tools-3/ 12. Marimo notebook flaw runs MCP commands before cells execute — CVE-2026-75149, CVE-2026-39987, CVE-2026-67618 — The Hacker News — https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html 13. AWS Strands Agents python_repl consent bypass allows RCE — CVE-2026-78379 — AWS — https://aws.amazon.com/security/security-bulletins/rss/2026-089-aws/ 14. Fake Indeed interview apps push Android spyware to job seekers — Malwarebytes Labs — https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware
    続きを読む 一部表示
    4 分
  • Cyber Security News for August 25 2026 - Daily DefSec Brief
    2026/08/25
    1. CISA adds actively exploited Oracle HTTP Server / WebLogic proxy plug-in flaw to KEV — CVE-2026-21962 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Critical Keycloak password-reset flaw allows unauthenticated account takeover — CVE-2026-18963 — The Hacker News — https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html 3. Five high-risk vulnerabilities disclosed in Palo Alto GlobalProtect VPN — Cyber Security News — https://cybersecuritynews.com/5-vulnerabilities-palo-alto-globalprotect/ 4. TP-Link Archer routers hit by three root command-injection flaws — Cyber Security News — https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/ 5. WordlistLoader hides malware inside ordinary English words to drop Amatera stealer — Dark Reading — https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text 6. Doubloon Dredger abuses Notion and device-code phishing to steal auth tokens — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/ 7. Malicious Firefox add-ons steal crypto seed phrases and browser credentials — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/malicious-firefox-add-ons-stealing-cryptowallet-seed-phrases-browser-credentials 8. Fake "SysScan" sites trick users into uninstalling their antivirus — Malwarebytes Labs — https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus 9. TikTok credential-phishing pages target account and MFA codes — Malwarebytes Labs — https://www.malwarebytes.com/blog/threat-intel/2026/08/tiktok-phishing-how-to-spot-fake-login-and-verification-pages 10. OWASP Agentic Skills Top 10 flags SKILL.md files as prose that executes — https://adversa.ai/blog/owasp-agentic-skills-top-10-explained/
    続きを読む 一部表示
    3 分
  • Cyber Security News for August 24 2026 - Daily DefSec Brief
    2026/08/24
    1. Passkey phishing kit keeps mailbox access after a password reset — SecurityWeek — https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/ 2. Encrypted-prompt technique bypasses AI guardrails in Grok and Gemini — SecurityWeek — https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ 3. Hundreds of leaked AWS keys still live, many with admin — BleepingComputer — https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ 4. Trojanized npm packages drop an AI-assisted Linux backdoor on import — The Hacker News — https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html 5. North Korea-linked actors poison popular Rust crates — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/ 6. SynkLoader malware spread via Teams help-desk impersonation — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ 7. Chameleon SEO poisoning cloaks fake bank sites from scanners — Help Net Security — https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/ 8. Malware-as-a-service uses Adobe-themed domain to hit Windows via .bat — Cyber Security News — https://cybersecuritynews.com/malware-as-a-service-adobe-themed-domain/ 9. Agent Tesla v4 uses emoji obfuscation to dodge signature detection — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/ 10. Iran-linked hackers shut down a UK power plant for four days — SecurityWeek — https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/ 11. Vendor essay questions Salesforce free scanner on portal file uploads — Cyber Security Dive (sponsored) — https://www.cybersecuritydive.com/spons/salesforce-gave-every-org-the-same-free-scanner-attackers-already-know-wha/828063/ 12. ThreatLocker walkthrough on abusing Windows named pipes for local privilege escalation — BleepingComputer (ThreatLocker) — https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ 13. Sophos: attackers impersonate Claude, ChatGPT, Copilot and Perplexity — Help Net Security — https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/
    続きを読む 一部表示
    5 分