オラクル、2022 年 4月 「Critical Patch Update」で 221 件の CVE を修正
Oracle addresses 221 CVEs in its second quarterly update of 2022 with 520 patches, including 27 critical updates....
マイクロソフトの 2022 年 4 月月例セキュリティ更新プログラム、117 件の CVE を修正 (CVE-2022-24521)
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521) Microsoft addresses 117 CVEs in its April 2022 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild and reported to Microsoft by the National Security Agency. 9Criti...
VMware、Workspace ONE、Identity Manager、Lifecycle Manager、および vRealize の複数の脆弱性にパッチを適用 (VMSA-2022-0011)
VMware cautions organizations to patch or mitigate several serious vulnerabilities across multiple products....
Spring Framework におけるリモートコード実行の脆弱性 (Spring4Shell) に関するよくある質問
A list of frequently asked questions related to Spring4Shell (CVE-2022-22965)....
CVE-2022-22948: VMware vCenter Server における機密情報流出の脆弱性
Researchers disclose a moderate severity vulnerability in VMware vCenter Server that can be used in an exploit chain with other vCenter Server flaws to take over servers....
脆弱性「Cr8escape」に対して Tenable がどのように役立つか (CVE-2022-0811)
CrowdStrike discloses container escape vulnerability affecting CRI-O for Kubernetes. Here’s how Tenable.cs can help you detect vulnerable pods. Background On March 15, CrowdStrike published technical details and a proof-of-concept for CVE-2022-0811, a vulnerability they have named cr8escape, i...
ContiLeaks: チャットにより Conti ランサムウェアにより悪用されている 30 件以上の脆弱性が明らかになる
Private messages between Conti members uncover invaluable information about how the infamous ransomware group hijacks victims’ systems. Leaked internal chats between Conti ransomware group members offer a unique glimpse into its inner workings and provide valuable insights, including details on o...
マイクロソフト 2022 年 3 月月例セキュリティ更新プログラム、71 件の CVE を修正 (CVE-2022-23277、CVE-2022-24508)
<p>Microsoft addresses 71 CVEs in its March 2022 Patch Tuesday release, including three vulnerabilities that were publicly disclosed as zero-days.</p>...
米政府、ロシアのウクライナ侵攻に起因する APT 活動について勧告
Government agencies publish warnings and guidance for organizations to defend themselves against advanced persistent threat groups. As governments around the world call for heightened cyber vigilance, the reality of our digital world comes into stark relief: there are no boundaries when it come...
CVE-2022-22536: SAP、Internet Communication Manager Advanced Desync (ICMAD) の脆弱性を修正
SAP and Onapsis Research Labs collaborate to disclose three critical vulnerabilities impacting SAP NetWeaver Application Servers. The most severe of the three could lead to full system takeover. Background On February 8, SAP disclosed several vulnerabilities in the Internet Communication Manag...
マイクロソフト 2022 年 2 月月例セキュリティ更新プログラム、 48 件の CVE を修正 (CVE-2022-2198)
Microsoft addresses 48 CVEs in its February 2022 Patch Tuesday release, including one zero-day vulnerability that was publicly disclosed, but not exploited in the wild....
CVE-2022-20699、CVE-2022-20700、CVE-2022-20708: Cisco Small Business RV シリーズルータにおける「緊急」の脆弱性が発見される
Cisco patches 15 flaws in Cisco Small Business RV Series Routers, including three with critical 10.0 CVSSv3 scores. Update February 4: Cisco has updated their advisory to announce partial patches for the RV160 and RV260 Series Routers. The Solution section has been updated with this informati...