🔖
2025/08/17 週 セキュリティニュースメモ
はじめに
- 自身なりに気になったセキュリティ情報の 私のメモ です
- 毎週日曜日起点で作成し、土曜日まで、その週の記事を更新し続けます
- zennでの公開は、翌週の記事を作成したタイミングで実施します。ただし、GitHub上では常にpublicです。そのため、zenn上で未公開でも、GitHub上では確認 はできます。
- あくまで、発見した週に記入します(タイトルが近い場合は、最初に見つけた週)
- 1週間以上前の出来事は、極力日付を入れる気持ちではいますが、確実性はありません
- 今週にhinoshibaが見つけたニュースである事に留意ください
- 実質的には、セキュリティは楽しいかね? Part 2 のような事ができるようになったらいいなと、個人的に真似をして、個人的に漏れチェック等に使います
事件事故
攻撃、脅威
- パスワードマネージャに対するDOMベースクリッククリックジャッキング
脆弱性
- CVE-2025-52970 FortiWeb 未認証のコード実行の可能性
- CVE-2025-20265 Cisco Firewall Management Platform 未認証のコード実行の脆弱性
- https://www.securityweek.com/cisco-patches-critical-vulnerability-in-firewall-management-platform/
- https://thehackernews.com/2025/08/cisco-warns-of-cvss-100-fmc-radius-flaw.html
- https://securityonline.info/critical-cisco-rce-flaw-cve-2025-20265-cvss-10-unauthenticated-attackers-can-hijack-firewalls/
- CVE-2025-9074 Docker Desktop for Windows API未認証状態での内部公開
- https://cybersecuritynews.com/windows-docker-desktop-vulnerability/
- https://thehackernews.com/2025/08/docker-fixes-cve-2025-9074-critical.html
- https://www.bleepingcomputer.com/news/security/critical-docker-desktop-flaw-lets-attackers-hijack-windows-hosts/
- https://www.securityweek.com/docker-desktop-vulnerability-leads-to-host-compromise/
KEV
- CVE-2025-43300 Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
- https://www.bitdefender.com/en-us/blog/hotforsecurity/patch-your-iphones-and-macs-apple-tackles-critical-security-flaw-with-ios-18-6-2-macos-sequoia-15-6-1
- https://www.theregister.com/2025/08/21/apple_imageio_exploit/
- https://www.securityweek.com/apple-patches-zero-day-exploited-in-targeted-attacks/
- https://thehackernews.com/2025/08/apple-patches-cve-2025-43300-zero-day.html
- https://www.bleepingcomputer.com/news/apple/apple-emergency-updates-fix-new-actively-exploited-zero-day/
- CVE-2025-54948 Trend Micro Apex One OS Command Injection Vulnerability
その他
- Microsoft Windowsリカバリに関する緊急パッチをリリース
Discussion