Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Cla…
公的機関の注意喚起とセキュリティ報道の見出しを集めています。掲載しているのは各配信元が公開した見出し・日付・リンクで、本文は配信元のサイトでご覧ください。見出しは取得したまま掲載し、 当サイトによる評価や補足は加えていません。
読んだ見出しのどれから手を付けるか迷ったら、SSVC 判定ツールを使ってください。悪用の状況・公開範囲・自動化可能性・人への影響を選ぶと、 CERT/CC の決定表から「見送り/定期対応/臨時対応/即時対応」のどれかが決まります。
公的機関・CSIRTの発表(リンク先は各機関のサイト)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE…
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies …
a-blog cmsにパストラバーサルの脆弱性
Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live a…
Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract creden…
Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS me…
Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack …
画像は各配信元のOGP画像を参照しています(複製はしていません)
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Cla…
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credential…
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise …
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in La…
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploi…
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed…
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissident…
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions th…
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large languag…
CVE を1件ずつ取り上げ、該当判定・緩和策・恒久対応・検知までを手順として書いています。 CVSS・影響を受けるバージョン・修正版・KEV 収載は、NVD / CISA KEV / ベンダーアドバイザリと突合できた内容だけを載せています。
JVN / JVN iPedia の新着(脆弱性の詳細は各ページで確認してください)
東北電力株式会社が提供するスマートフォンアプリ「東北電力 よりそうeねっと」には、ハードコードされた暗号鍵使用の脆弱性が存在します。
CERT/CCから本件に関するアドバイザリが公表されました。
CERT/CCから本件に関するアドバイザリが公表されました。
東北電力株式会社が提供するスマートフォンアプリ「東北電力 よりそうeねっと」には、次の脆弱性が存在します。 ハードコードされた暗号鍵の使用(CWE-321)- CVE-2026-75553 この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方がIPAに報告…
米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。 新規:8件 ICSA-26-258-01: Digital Watchdog VMAX DVR and NVR Product Lineups ICSA-26-258…
12件のサーバファームウェアに関するセキュリティ問題が存在しています。
XikeStor製Layer3スイッチは、認証なしにコンフィグレーションデータをダウンロード可能です。
クオリティソフト株式会社が提供するQNDには、複数の脆弱性が存在します。
米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
XikeStor製Layer3スイッチには、次の脆弱性が存在します。 コンフィグレーションデータのダウンロード機能における認証欠如(CWE-306)- CVE-2026-88263
クオリティソフト株式会社が提供するQNDには、次の複数の脆弱性が存在します。 ハードコードされた暗号鍵の使用(CWE-321)- CVE-2026-81326 名前付きパイプに対するアクセス制限不備(CWE-782)- CVE-2026-84408 この脆弱性情報は、情報セキュ…
パナソニック インダストリー株式会社が提供するMINAS A5/A6用Windows USBデバイスドライバには、次の脆弱性が存在します。 古典的バッファーオーバーフロー(CWE-120) - CVE-2026-16726 この脆弱性情報は、Nozomi Networks社のL…
実際にフィードを取得できたものだけを載せています