The npm blog has been discontinued. Updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. tl;dr - Update to npm v6.13.4 as soon as possible on all your systems to fix a vulnerability allowing arbitrary path access. The Vulnerabilities In versions of npm prior to 6.13.3 (and versions of yarn prior to 1.21.1), a properly constructed entry in the package.json bin fi
éä¿¡å 表è¨ãéä¿¡è IDã®ã±ã¼ã¹ SMSã®ã¡ãã»ã¼ã¸ãåä¿¡ããéã«è¡¨ç¤ºãããéä¿¡å ã«ã¯ãé»è©±çªå·ã®ä»£ããã«ä»»æã®è±æ°åã表è¨ã§ããããã®è±æ°åã®éä¿¡å 表è¨ããéä¿¡è IDï¼Sender IDï¼ãã¨ãããJC3ã®å³ã§ã¯ éä¿¡äºæ¥è A ãéä¿¡è IDã«å½ããã ãªãéä¿¡è IDã®å©ç¨å¯å¦ã¯åä¿¡å´ã®éä¿¡äºæ¥è ã®å¯¾å¿ç¶æ³ã«ãã£ã¦ç°ãªããTwilioã®è²©å£²ãã¼ããã¼ã§ããKWCã®èª¬æã«ããã¨ãæ¥æ¬å½å ã§ã¯NTT DOCOMOã¨SoftBankãéä¿¡è IDã«å¯¾å¿ããKDDIã¯å¯¾å¿ãã¦ããªãã¨ã®ãã¨Â²ãç§ã¯KDDIã®åç·ãææãã¦ããªããããåä¿¡å´ãKDDIã®é»è©±çªå·ã使ç¨ãã¦ããå ´åã®æåã¯æ¤è¨¼ã§ãã¦ããªãã ã¾ãã¯iOSã®å ¬å¼ã¡ãã»ã¼ã¸ã¢ããªã«å±ãã¦ããAmazonããã®ã¡ãã»ã¼ã¸ã®ã¹ã¬ããã§å½è£ ã試ã¿ããéä¿¡è ID㯠Amazon ã¨ãªã£ã¦ãããããTwilioã§SMSãéä¿¡ããéã®Fromã®å¤ã« Ama
7payã®æ°è¦ç»é²åæ¢ãç¥ãããå¼µãç´ãå ¨å½æ´¥ã 浦ã ã®ãã©ã³ãã£ã¤ãºåºèã«ã¾ã§æ²åºãè¡ã渡ãããã®ã¯ç°¡åãªãã¨ã§ã¯ãªãã æ®å½±ï¼7payåæç 7payã®ä¸æ£ä½¿ç¨ãããã£ã¦ããã®èå¼±æ§ãèæ¯ã«ããã¨ã®è¦æ¹ãå¼·ã¾ã£ã¦ãããçªç容çãªã©ã§è¤æ°ã®ä¸å½ç±ã®å®¹çè ããé®æããã¦ããããå®æ ã«ã¯ã¾ã ä¸å¯è§£ãªé¨åãå°ãªããªãã ä¸é£ã®7payå ±éã®ãªãã§ãå¾ã ã«ãããã³ã°ã®ææ³ã«é¢ããæ å ±ãåºã¦ããããå ·ä½çã«ï½¢7payã®èå¼±æ§ã¨ã¯ãä¸ä½ã©ããªãã®ã ã£ãã®ãï½£ã¯ç´æ¥çã«å ±ãããã¦ããªãã Business Insider Japanã®ï½¢7payï½£åæçã§ã¯ãè¤æ°ã®ååè ã®é信解æãéãã¦ã7payã¨ãã®å¨è¾ºã«æ½ãèå¼±æ§ã®ãã¡ãéè¦ãªäºè±¡ã®1ã¤ã§ããå¤é¨IDçµç±ã®ãããã³ã°ï¼ä¸æ£ä¾µå ¥ï¼ã®ã¡ã«ããºã ã«ã¤ãã¦ç¢ºè¨¼ãå¾ãã ä¸æ£ã¢ã¯ã»ã¹ç¯ã¯ã©ããªæå£ã§ä¾µå ¥ããã®ããæ¢ãã
ãã»ãã³ãã¤ãHPããã 7payã§ã®ãã¯ã¬ã¸ããã«ã¼ãããã®ä¸æ£ãã£ã¼ã¸ãäºä»¶ã¯ãå²ä¸ã¾ãã«è¦ããããããªã»ãã¥ãªãã£ããèæ¯ã«ãããã¨ãããã£ã¦ãã¾ããã被害è ã¤ã³ã¿ãã¥ã¼ããèããã¨ãã»ãã³ã¤ã¬ãã³ããã®æ å ±æ¼ããã®å¯è½æ§ãèããªããã°ãªãã¾ããã 決æ¸æ¥çã®ä¸ã®äººã»ãããã°æ°ã被害 7payã®äºä»¶ã§ã¯ãå¤ãã®è¢«å®³è ãçµç·¯ãTwitterã§ãªãã¼ããã¦ãã¾ãããã®ãªãã§ãã£ã¨ãä¿¡é ¼ã§ããæ å ±ãçºä¿¡ããã¦ããã®ãããããã°æ°ã§ãããããã°æ°ã¯ãããä¼æ¥ã§æ±ºæ¸ã®ä»äºãããã¦ãããã¾ãã«ä»åã®äºä»¶ãèµ·ããåãæ¥çã«ããã£ãããæ¹ã§ãããããã°æ°ã«ä¼ºã£ã話ããã被害ã®çµç·¯ãã¾ã¨ãã¾ãã 被害ã«ãã£ããããã°æ°ã®å ±åãã¤ã¼ããä¸é£ã®ãã¤ã¼ãã§è¢«å®³ç¶æ³ã詳ãããªãã¼ããã¦ãã ãããã°æ°ã®è¢«å®³çµç·¯ ã»7æï¼æ¥ï¼7payãµã¼ãã¹éå§ã«ã¨ããªãç»é²ã5,000åãã£ã¼ã¸ãã1åº¦æ±ºæ¸ ã»7æ3æ¥æï¼7
JVN#37288228 ã¹ãã¼ããã©ã³ã¢ããªãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ãã«ããã SSL ãµã¼ã証ææ¸ã®æ¤è¨¼ä¸åã®èå¼±æ§ SoftBank Android ã¢ããªãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ã 10.1.7 ããåã®ãã¼ã¸ã§ã³ iOS ã¢ã㪠ãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ããã¼ã¸ã§ã³ 1.1.23 ããåã®ãã¼ã¸ã§ã³ æ ªå¼ä¼ç¤¾NTTãã³ã¢ Android ã¢ããªãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ã 42.40.2800 ããåã®ãã¼ã¸ã§ã³ iOS ã¢ã㪠ãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ããã¼ã¸ã§ã³ 1.1.23 ããåã®ãã¼ã¸ã§ã³ ï¼«ï¼¤ï¼¤ï¼©æ ªå¼ä¼ç¤¾ Android ã¢ããªãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ã 1.0.6 ããåã®ãã¼ã¸ã§ã³ iOS ã¢ã㪠ãï¼ã¡ãã»ã¼ã¸ï¼ãã©ã¹ã¡ãã»ã¼ã¸ï¼ããã¼ã¸ã§ã³ 1.1.23 ããåã®ãã¼ã¸ã§ã³
Appleã¯ãMacãã¹ãã¼ãããã¤ã¹åãã«ããã¹ãå¦çã«èµ·å ããèå¼±æ§ã解æ¶ããã¢ãããã¼ãããªãªã¼ã¹ããã ãmacOS High Sierra 10.13.3 Supplemental UpdateãããiOS 11.2.6ãã®æä¾ãéå§ãããã®ã ãããã®ã¢ãããã¼ãããããã¹ãå¦çã«èµ·å ããèå¼±æ§ãCVE-2018-4124ããä¿®æ£ããã ç¹å®ã®UNICODEæåãå¦çããã¨ã¡ã¢ãªç ´å£ãçããã¢ããªã±ã¼ã·ã§ã³ãã¯ã©ãã·ã¥ãããåé¡ã®æåã³ã¼ããå«ãã ãã¤ã¼ããªã©æ¡æ£ãããããã¨ãããªã©ãèå¼±æ§ãæªç¨ããåãã確èªããã¦ããã Macã«é¢ãã¦ã¯ããmacOS High Sierra 10.13.3ãåãã®ã¢ãããã¼ãã®ã¿ã¨ãªã£ã¦ãããã¾ãåæ§ã®åé¡ã解æ¶ãããããtvOS 11.2.6ããwatchOS 4.2.3ãããããã¦ãªãªã¼ã¹ããã ï¼Security NEXT - 201
AppleããiOS 11.2.6ããmacOS High Sierra 10.13.3追å ã¢ãããã¼ãããå ¬éãç¹å®ã®æååã使ç¨ããã¨ã¢ããªãã¯ã©ãã·ã¥ããåé¡ãä¿®æ£ããã ç±³Appleã¯2æ19æ¥ãiOSãmacOS High Sierraãªã©ã®ã¢ãããã¼ããå ¬éããã¤ã³ãã§ä½¿ããã¦ãããã«ã°èªã®ç¹å®ã®æåãåä¿¡ããã¨ã¢ããªãã¯ã©ãã·ã¥ããåé¡ã«å¯¾å¦ããã Appleã®ãµãã¼ãæ å ±ã«ããã¨ãiOSã®æ´æ°çã¨ãªããiOS 11.2.6ãã§ã¯ãç¹å®ã®æååã使ç¨ããã¨ã¢ããªãã¯ã©ãã·ã¥ããåé¡ãããã³ä¸é¨ã®ä»ç¤¾è£½ã®ã¢ããªãå¤é¨ã¢ã¯ã»ãµãªã«æ¥ç¶ã§ããªãåé¡ã®2件ãä¿®æ£ããã ã¾ããã»ãã¥ãªãã£é¢é£ã§ã¯CoreTextã®èå¼±æ§ã«å¯¾å¦ããããã®èå¼±æ§ãæªç¨ãããå ´åãç´°å·¥ãæ½ããæååãå¦çãããã¨ã«ãã£ã¦ããã¼ãç ´æãèªçºãããæãããã£ãã iOSã¨åãä¸å ·åãèå¼±æ§ã¯ãåæ¥å ¬éããããm
ç±³Intelã®èå¼±æ§å¯¾çããããã¤ã³ã¹ãã¼ã«ããä¸é¨ã®CPUæè¼ãã·ã³ã§ãªãã¼ããå¢ããä¸å ·åã確èªãããåé¡ã§ãIntelã¯1æ22æ¥ãç¾å¨åºåã£ã¦ãããããã®å°å ¥ãä¸æ¢ãããããã¡ã¼ã«ã¼ãã¨ã³ãã¦ã¼ã¶ã¼ã«å¼ã³æããã Intelã¯ãMeltdownããSpectreãã¨å¼ã°ããCPUã®èå¼±æ§ãçºè¦ãããã¨ãåãã1æä¸æ¬ã¾ã§ã«OEMãªã©ãéãã¦å¯¾çããããé ä¿¡ãããã¨ããããã®ããããåå ã§ãªãã¼ããå¢ããä¸å ·åãå ±åãããIntelã¯BroadwellãHaswellãSkylakeãKaby Lakeã®åCPUãæè¼ãããã·ã³ã§åé¡ã確èªãã¦ããã 1æ22æ¥ã®æç¹ã§ã¯ããã®ãã¡Broadwellã¨Haswellã®åé¡ã«ã¤ãã¦ãæ ¹æ¬ã®åå ãçªãæ¢ããã¢ãããã¼ãã®åæãã¼ã¸ã§ã³ãæ¥çãã¼ããã¼åãã«ãªãªã¼ã¹ãã¦ãã¹ããè¡ã£ã¦ããã¨ããããã¹ããå®äºæ¬¡ç¬¬ãæ£å¼ãªãªã¼ã¹ãäºå®ãã¦ããã
ãã¹ã¯ã¼ããªãã§ãã°ã¤ã³ã§ãã¦ãã¾ããMacãã®ãã°ãã¾ãçºè¦ããããããããååçºè¦ãããåæ§ã®ãã°ã¨ç°ãªããä»åã®ãã°ãæªç¨ããã¦ããã³ã³ãã¥ã¼ã¿ã«å°ããããããããã ãã§æ¸ã¿ããã ã ãã®ãã°ãçºè¦ããããã¨ã§ãAppleã®ã½ããã¦ã§ã¢ã®å ¨ä½çãªå質ã«ã¤ãã¦ãæ¸å¿µã®å£°ãä¸ããã®ã¯é¿ããããªãã ãããããã®èå¼±æ§ãæªç¨ããã¦ããã³ã³ãã¥ã¼ã¿ãå®å ¨ã«ä¹ã£åããããã¨ã¯ãªãã 2ã¤ã®ãã°ãæ¯è¼ãã¦ã¿ããã2017å¹´11æãã¦ã¼ã¶ã¼åã¨ãã¦ãrootãã使ç¨ããã°ã誰ã§ããã¹ã¯ã¼ããªãã§Macã«ãã°ã¤ã³ã§ãããã¨ãæããã«ãªã£ããããã¯ãã³ã³ãã¥ã¼ã¿å ã®ãã¼ã¿ãæ³¥æ£ã詮索好ããªåéã家æãååããå®ãæãåºæ¬çãªé²è¡ç·ãç¡ååããæ·±å»ãªèå¼±æ§ã ãç±³å½æé2018å¹´1æ8æ¥ããã¹ã¯ã¼ããã£ã¼ã«ãã«ã©ã®ãããªæåãå ¥åãã¦ããã·ã¹ãã ç°å¢è¨å®ã®ãApp Storeãè¨å®ã®ããã¯ã解é¤ã§ãããã¨ã
Key Reinstallation Attacks Breaking WPA2 by forcing nonce reuse Discovered by Mathy Vanhoef of imec-DistriNet, KU Leuven, 2017 Introduction We discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. An attacker within range of a victim can exploit these weaknesses using key reinstallation attacks (KRACKs). Concretely, attackers can use this novel attack
Appleã¯ãMacåãOSã®æ°ãã¼ã¸ã§ã³ãmacOS High Sierraãããªãªã¼ã¹ããããããããã®ãããæ°æéåã«ãããã»ãã¥ãªãã£ç 究è ãã¼ããã¤èå¼±æ§ãææãã¦ããã ç±³å½å®¶å®å ¨ä¿éå±ï¼NSAï¼ã®å ã¢ããªã¹ãã§ãç¾å¨ã¯Synackã§ä¸»å¸ã»ãã¥ãªãã£ç 究è ãåããPatrick Wardleæ°ãããããã³ã°ã®æ§åï¼ãã¹ã¯ã¼ããæãåãã¨ã¯ã¹ããã¤ãï¼ã示ããåç»ãæ稿ããã ãã¹ã¯ã¼ãã¯ãMacã®ãã¼ãã§ã¼ã³ã«æ ¼ç´ããã¦ãããé常ã¯ããã¹ã¿ã¼ãã°ã¤ã³ãã¹ã¯ã¼ãããªããã°ãããã«ã¢ã¯ã»ã¹ãããã¨ã¯ã§ããªãã ãããWardleæ°ã¯ãæ»æè ãã¤ã³ã¿ã¼ããããããã¦ã³ãã¼ãããç¡ç½²åã®ã¢ããªã使ç¨ãã¦ããã®ãã¹ã¯ã¼ãããªãã¦ããã¬ã¼ã³ããã¹ãã§è¨ããããã¹ã¦ã®ãã¹ã¯ã¼ããåå¾ãã¦çããã¨ã®ã§ããèå¼±æ§ã示ãã¦ããã åæ°ã¯ããããã³ã°ã®æ§åã示ãçãåç»ã¸ã®ãªã³ã¯ããã¤ã¼ãããã W
Incapsulaã®ã»ãã¥ãªãã£ç 究è ã§ããDaniel Svartmanæ°ã¯8æ30æ¥(ç±³å½æé)ããDiscovering a Session Hijacking Vulnerability in GitLabï½Incapsulaãã«ããã¦ãGitLabã«ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯å¯è½ãªèå¼±æ§ãåå¨ãã¦ããã¨ä¼ãããåæ°ã¯5æ18æ¥ã®æç¹ã§GitLabã«åé¡ãå ±åãã¦ããã対å¦ãè¡ãããã¾ã§æ å ±å ¬éãæ§ãã¦ããã¨ãã¦ãããè¨äºã§ã¯ãGitLabã«åå¨ãã¦ããã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã®èå¼±æ§ãã©ã®ãããªãã®ã§ãã£ãããGitLabãã©ã®ãããªå¯¾å¦ãããããä¼ãã¦ããã GitLabã¨ã¯ãGitãã¼ã¹ã®ãªãã¸ããªç®¡çãåé¡è¿½è·¡ãã³ã¼ãã¬ãã¥ã¼ãªã©ãè¡ããOSSã ä»åçºè¦ãããã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã¯å¤ãããåå¨ãã¦ããèå¼±æ§ã®1ã¤ãã»ãã·ã§ã³ãã¼ã¯ã³ãçªåãããã¨ãã¦ã¼ã¶ã¼ã«ãªããã¾ãã¦ãã¾ã
ã¨ã°ã¼ã¯ãã£ããµã㪠WordPress 4.7ã¨4.7.1ã®REST APIã«ãèªè¨¼ãåé¿ãã¦ã³ã³ãã³ããæ¸ãæããããèå¼±æ§ãåå¨ãããæ»æã¯æ¥µãã¦å®¹æã§ããã®å½±é¿ã¯ä»»æã³ã³ãã³ãã®æ¸ãæãã§ãããããé大ãªçµæãåã¼ãã対çã¯WordPressã®ææ°çã«ãã¼ã¸ã§ã³ã¢ãããããã¨ã§ããã æ¬ç¨¿ã§ã¯ãèå¼±æ§æ··å ¥ã®åå ã«ã¤ãã¦å ±åããã ã¯ããã« WordPressæ¬ä½ã«ä¹ ãã¶ãã«é大ãªèå¼±æ§ãè¦ã¤ãã£ãã¨çºè¡¨ããã¾ããã ãããªé¢¨ã«æ¸ãã¨ãWordPressã®èå¼±æ§ãªãã¦ããã£ã¡ã ãè¦ã¤ãã£ã¦ããã¨ããæè¦ãããããã§ãããè½åçãã¤èªè¨¼ãªãã«ãä¾µå ¥ã§ããèå¼±æ§ã¯ããæ°å¹´åºã¦ããªãããã«æãã¾ããããããã¯ã©ã¹ã®ãã®ãä¹ ãã¶ãã«è¦ã¤ãã£ãã¨ãããã¨ã§ããã WordPressãæ´æ°çã§æ·±å»ãªèå¼±æ§ãä¿®æ£ãå®å ¨ç¢ºä¿ã®ããæ å ±å ¬éãå éã Make WordPress Core Conten
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}