コンテンツ管理システム「Ghost」の重大な脆弱性が、ウェブサイトを標的とした攻撃に利用されている。
攻撃者は、Ghost CMSの重大なレベルの脆弱性を悪用している。この脆弱性は、何百ものサイトを標的とする「ClickFix」攻撃を可能にしている。
コンテンツ管理システム「Ghost」の重大な脆弱性が、ウェブサイトを標的とした攻撃に利用されている。
攻撃者は、Ghost CMSの重大なレベルの脆弱性を悪用している。この脆弱性は、何百ものサイトを標的とする「ClickFix」攻撃を可能にしている。
AIによるレポート AIによって生成された画像
A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.
Google published proof-of-concept exploit code on Wednesday for a vulnerability in its Chromium browser that has gone unfixed for 29 months. The flaw affects Chrome, Microsoft Edge, and other Chromium-based browsers used by millions worldwide. It enables attackers to establish persistent connections for monitoring user activity and launching attacks.
AIによるレポート
Four days after the CopyFail (CVE-2026-31431) exploit disclosure disrupted Ubuntu services, the US government warned of its critical risks to Linux systems, urging immediate patching amid public exploit code.
Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.
AIによるレポート
A proof-of-concept exploit shows how websites can bypass safety guardrails in AI browsers by feeding them false information. The technique, called BioShocking, prompts the embedded AI models to accept incorrect facts such as 2 + 2 = 5, creating an alternate reality where restrictions no longer apply.