今週の気になるセキュリティニュース - Issue #275

ポッドキャスト収録用のメモですよ。

podcast - #セキュリティのアレ - ゆるーいセキュリティのポッドキャストですよ。



事件、事故


攻撃、脅威

npm の複数のパッケージでサプライチェーン攻撃が発生

(5/11) Postmortem: TanStack npm supply-chain compromise | TanStack Blog

(5/11) TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurity

(5/11) TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud...

(5/12) Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack

(5/12) Mini Shai-Hulud 第二波の概要と対応指針(TanStack Router を含む 200 超の侵害) - GMO Flatt Security Blog

(5/12) Security advisories | Mistral Docs

(5/13) Our response to the TanStack npm supply chain attack | OpenAI


Google が攻撃者による生成 AI の悪用に関する報告

(5/12) Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Google Cloud Blog


脆弱性

Apple が macOS Tahoe 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, iOS 26.5 / iPadOS 26.5, iOS 18.7.9 / iPadOS 18.7.9, iOS 17.7.11, iOS 16.7.16 / iPadOS 16.7.16, iOS 15.8.8 / iPadOS 15.8.8, tvOS 26.5, watchOS 26.5, visionOS 26.5 をリリース

(5/11) Apple security releases - Apple Support

(5/12) Zero Day Initiative — The Apple macOS Security Update Review


Microsoft が 2026年 5月の月例パッチを公開

(5/12) 2026 年 5 月のセキュリティ更新プログラム (月例)

(5/12) A note on patch Tuesday

In this month's release, a greater share of the issues addressed were discovered by Microsoft, compared to prior months. Many of these were surfaced through AI investments and investigations across our engineering and research teams, including the use of Microsoft's new multi-model AI-driven scanning harness. A number were also credited to external researchers working in collaboration with AI. All moved through the same MSRC validation, prioritization, and disclosure workflows we apply to every report.

(5/12) Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark | Microsoft Security Blog

Across the Windows network stack and adjacent services, today’s Patch Tuesday includes 16 CVEs our engineering teams found using codename MDASH.

(5/12) Zero Day Initiative — The May 2026 Security Update Review


GUARDIANWALL MailSuite にバッファオーバーフローの脆弱性。すでに悪用が確認されている

(5/13) 【重要】GUARDIANWALL MailSuite スタックベースのバッファオーバーフロー脆弱性に関するご対応依頼 | サポート情報|GUARDIANWALLシリーズ|キヤノンITソリューションズ

(5/13) JVN#35567473: GUARDIANWALL MailSuiteにおけるスタックベースのバッファオーバーフローの脆弱性

開発者によると、GUARDIANWALL MailSuite(オンプレミス版)において本脆弱性を悪用した攻撃が既に確認されているとのことです。

(5/13) GUARDIANWALL MailSuiteにおけるスタックベースのバッファオーバーフローの脆弱性に関する注意喚起


Linux カーネルにローカル権限昇格の脆弱性 "Fragnesia"

(5/13) pocs/fragnesia at main · v12-security/pocs · GitHub

(5/14) New Fragnesia Linux flaw lets attackers gain root privileges


NGINX にリモートコード実行可能な脆弱性

(5/13) NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945

(5/13) NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability | depthfirst


PAN-OS に認証バイパスの脆弱性

(5/14) CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

(5/15) CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OS


Cisco Catalyst SD-WAN に認証バイパスの脆弱性。すでに悪用が確認されている

(5/14) Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

In May 2026, the Cisco Product Security Incident Response Team (PSIRT) became aware of limited exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

(5/14) Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities


Microsoft Exchange Server に脆弱性。すでに悪用が確認されている

(5/14) Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub

(5/14) CVE-2026-42897 - セキュリティ更新プログラム ガイド - Microsoft - Microsoft Exchange Server のなりすましの脆弱性


CISA が Known Exploited Vulnerabilities (KEV) カタログに 1+1 個の脆弱性を追加

(5/14) CISA Adds One Known Exploited Vulnerability to Catalog | CISA

  • CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

(5/15) CISA Adds One Known Exploited Vulnerability to Catalog | CISA

  • CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability


その他

iOS 26.5 で RCS の E2EE メッセージに対応

(5/11) iOS 26.5 brings E2EE for RCS: A new milestone for secure cross‑platform messaging - Newsroom

(5/11) End-to-end encrypted RCS messaging begins rolling out today in beta - Apple

(5/11) E2EE RCS Messaging Rolls Out for Android and iPhone Users


OpenAI が "Daybreak" を発表

(5/11) Daybreak | OpenAI for cybersecurity | OpenAI


「AI脅威に対する金融分野のサイバーセキュリティ対策強化に関する官民連携会議」の作業部会が開催

(5/14) 「AI脅威に対する金融分野のサイバーセキュリティ対策強化に関する官民連携会議」の作業部会の開催について:金融庁

4月24日(金曜日)に開催した「AI脅威に対する金融分野のサイバーセキュリティ対策強化に関する官民連携会議」における議論を踏まえ、金融業界とIT事業者、政府・日本銀行等がAI技術の進展による脅威について共通の理解を持ち、対応を検討していくため、実務者レベルでの議論を深めることを目的とした作業部会を開催しました。


JPCERT/CC が 2026年 1〜3月のインターネット定点観測レポートを公開

(5/15) インターネット定点観測レポート(2026年 1~3月)