CISA Flags Actively Exploited Adobe ColdFusion RCE (CVE-2026-48282, CVSS 10.0)
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
CISA added the actively exploited Adobe ColdFusion RDS path-traversal flaw CVE-2026-48282 (CVSS 10.0) to its KEV catalog, enabling unauthenticated RCE.
Context: Security teams need to be aware Mitsubishi Electric has identified a vulnerability in a bunch of their MELSEC iQ-F Series CPU modules—CVE-2025-7405—and it’s got a base score of about… 続きを読む 三菱電機の脆弱性からネットワークを保護する
Security teams need to know—CISA dropped an advisory with the FBI and some international partners about Salt Typhoon. They’re these Chinese state actors hitting telecom networks globally, even Canadian ones.… 続きを読む 中国国家主体から通信ネットワークを今すぐ保護する
Warning: Schneider Electric has dropped a critical advisory about their Modicon M340 controllers, CVE-2025-6625 targets them with around an 8.7 base score. Attackers can exploit this by sending malformed FTP… 続きを読む Schneider Electric Modicon M340の脆弱性に関するアドバイザリー
Security teams, heads up: CISA has just released new SBOM guidance, and they’re seeking public feedback—comments are due by October 3rd. This isn’t merely a tweak to the 2021 iteration.… 続きを読む CISA SBOMガイダンスの見直し、業界からのフィードバックを求める
Security groups should know that CISA dropped an alert about a critical flaw in Siemens Mendix SAML modules, hitting a base score of about 8.7 on the CVSS scale—this one… 続きを読む Siemens MendixのSAML脆弱性、緊急パッチが必要
Security teams should note CISA has dropped CVE-2025-54948 into their Known Exploited Vulnerabilities catalog, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in… 続きを読む Trend Micro Apex Oneの脆弱性、サーバーを危険にさらす
The recent alert for security teams highlights that CISA has worked with NSA, FBI, EPA, and international partners to provide guidance on OT asset inventories. This isn’t the same old… 続きを読む Optimize OT Asset Management with CISA’s New Guidance
Impact: Security teams should note, CISA’s dropped seven ICS advisories yesterday – it’s a mix from CAD software to railroad protocols. This isn’t just one vendor — there’s Johnson Controls… 続きを読む CISA、7件の緊急ICSセキュリティアドバイザリーを発表
CISA released a detailed malware analysis on SharePoint vulnerabilities being actively exploited. The “ToolShell” exploit chains CVE-2025-49704 with CVE-2025-49706 to compromise SharePoint servers, deploying web shells and .NET DLLs that… 続きを読む SharePointサーバーをToolShellエクスプロイトから今すぐ保護する
The Cybersecurity and Infrastructure Security Agency (CISA) just dropped a pair of industrial control system advisories that ought to jolt American critical infrastructure operators awake. Imagine it’s August 5, 2025—a… 続きを読む CISA、産業システムへの脅威の増加についてオペレーターに警告
CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All… 続きを読む CISA、Tigo Energy Cloud Connect Advancedの重大な脆弱性を警告
CISA published industrial control system advisory ICSA-25-212-01 on July 31, 2025, warning of a critical vulnerability in Güralp Systems FMUS-series seismic monitoring devices. Tracked as CVE-2025-8286 and rated CVSS v3.1… 続きを読む CISA警告:Güralp FMUS地震観測機器に重大な脆弱性(CVE-2025-8286)
On July 30, 2025, CISA released the Eviction Strategies Tool, a free and open-source toolset built to help defenders through the containment and eviction phases of incident response — the… 続きを読む CISA、インシデント対応向けに「Eviction Strategies Tool」を公開
On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services… 続きを読む CISA、Cisco ISEおよびPaperCutの脆弱性をKEVカタログに追加
CISA’s advisory ICSA-25-205-01 (published July 24, 2025) draws attention to CVE-2016-2542, a DLL-hijacking vulnerability affecting a broad set of Mitsubishi Electric CNC software tools. Although the CVE is old, the… 続きを読む CISA、Mitsubishi CNCソフトのDLLハイジャック脆弱性を警告(CVE-2016-2542)
Cybersecurity is growing more heated as the latest alert issued by the Cybersecurity and Infrastructure Security Agency (CISA) washes over Hollywood’s digital defenses. In such an information-heavy industry as sensitive… 続きを読む 天文学者のキスカムスキャンダルにサイバーセキュリティの関連なし
CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America.… 続きを読む CISA、Network Thermostat X-Seriesの重大な認証バイパスを警告
On July 22, 2025, CISA published advisory ICSA-25-203-01 covering three vulnerabilities in the DuraComm SPM-500 DP-10iN-100-MU, a DC power distribution and monitoring panel used in industrial settings. All versions up… 続きを読む CISA、DuraComm DP-10iN-100-MUの高リスク脆弱性を警告
サイバー・エッセンシャルズ・スキームは、英国のサイバーセキュリティ対策の要であり、企業がサイバー脅威から自らを守る力を与えるものである。今年で10年目を迎えるこの制度は、サイバーエージェントによって開発された。 続きを読む サイバーエッセンシャル10周年記念:企業のサイバー防御強化の10年
The Cybersecurity and Infrastructure Security Agency today issued a major alert about a sophisticated spear-phishing campaign hitting organizations across various sectors, especially government and IT. CISA said in an alert… 続きを読む 重要なサイバー警告:外国の脅威者が悪意のあるRDPアタッチメントで組織を標的に
オーストラリア信号局(Australian Signals Directorate)の一部門であるオーストラリア・サイバー・セキュリティ・センター(Australian Cyber Security Centre)は、人々を狙った高度な電子メール詐欺が再び発生しているとして、中レベルの警告を発表した。 続きを読む ASDのオーストラリア・サイバーセキュリティセンターになりすます電子メール詐欺師について