
【リンク集:2月10日〜12日のセキュリティ関連ニュース/記事】 <脆弱性> ・Windows 11のメモ帳に脆弱性、Markdownリンク経由でファイルがサイレント実行される(CVE-2026-20841) https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-flaw-let-files-execute-silently-via-markdown-links/ ・マイクロソフトが2026年2月の月例パッチをリリース、ゼロデイ6件含む58件の脆弱性を修正(CVE-2026-21510、CVE-2026-21513他) https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2026-patch-tuesday-fixes-6-zero-days-58-flaws/ ・SAPが重大な脆弱性を複数修正 CRMやS/4HANA、NetWeaverに存在(CVE-2026-0488、CVE-2026-0509他) https://www.securityweek.com/sap-patches-critical-crm-s-4hana-netweaver-vulnerabilities/ ・米CISA、Microsoft OfficeとMicrosoft Windowsの脆弱性をKEVカタログに追加(CVE-2026-21510、CVE-2026-21513他) https://securityaffairs.com/187855/security/u-s-cisa-adds-microsoft-office-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html ・ICS月例パッチ:シーメンス、シュナイダーエレクトリック、アヴィバ、フエニックス・コンタクトが脆弱性を修正 https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-addressed-by-siemens-schneider-aveva-phoenix-contact/ ・GoogleとIntelのセキュリティ監査でTDXに深刻な脆弱性が見つかる 完全な侵害を許す恐れ(CVE-2025-32007、CVE-2025-27940他) https://www.securityweek.com/google-intel-security-audit-reveals-severe-tdx-vulnerability-allowing-full-compromise/ ・Fortinet、深刻度の高い脆弱性を修正(CVE-2025-52436、CVE-2026-22153他) https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/ <マルウェア・その他脅威> ・北朝鮮のハッカーグループ、新たなmacOSマルウェアで暗号資産窃取を目論む https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-macos-malware-in-crypto-theft-attacks/ ・新たなLinuxボットネットのSSHStalker、C2通信に旧式のIRCを使用 https://www.bleepingcomputer.com/news/security/new-linux-botnet-sshstalker-uses-old-school-irc-for-c2-comms/ ・GoogleカレンダーのAIコネクタがマルウェアを起動する恐れ 複数の研究者が指摘 https://www.theregister.com/2026/02/11/claude_desktop_extensions_prompt_injection/ ・モバイル端末へのフルアクセスを可能にするスパイウェア「ZeroDayRAT」 https://securityaffairs.com/187820/malware/zerodayrat-spyware-grants-attackers-total-access-to-mobile-devices.html ・CastleLoaderマルウェアを使ったキャンペーンでLummaStealer感染が急増 https://www.bleepingcomputer.com/news/security/lummastealer-infections-surge-after-castleloader-malware-campaigns/ <ランサムウェア> ・Crazyランサムウェアグループ、従業員監視ツールを攻撃に悪用 https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/ ・「Reynolds」ランサムウェア、ペイロードにBYOVD用ドライバを埋め込む https://www.darkreading.com/threat-intelligence/black-basta-bundles-byovd-ransomware-payload <データ侵害/サイバー犯罪> ・Conduentのデータ侵害でボルボ・グループに被害、約17,000人分の従業員データが流出 https://www.securityweek.com/conduent-breach-hits-volvo-group-nearly-17000-employees-data-exposed/ ・米ジョージア州の医療関連企業でデータ侵害、62万人以上に影響 https://therecord.media/georgia-healthcare-company-data-breach-impacts-620000 <AI関連> ・Amazon、新たなマーケットプレイスの立ち上げを示唆 メディアサイトがAI企業へコンテンツを販売できる場に https://techcrunch.com/2026/02/10/amazon-may-launch-a-marketplace-where-media-sites-can-sell-their-content-to-ai-companies/ ・中国最大のハッキング大会「天府杯」が公安部主導で復活 AI隆盛のさなかに https://www.nattothoughts.com/p/the-tianfu-cup-returns-under-mps ・AI生成の似顔絵をソーシャルメディアに投稿するリスク、情報セキュリティ関係者が警告 https://www.theregister.com/2026/02/11/ai_caricatures_social_media_bad_security/ <サイバー戦/APT/国家型アクター/地政学関連> ・シンガポールの大手通信企業が中国系APTの標的に ルートキットとゼロデイが悪用される https://www.securityweek.com/singapore-rootkits-zero-day-used-in-chinese-attack-on-major-telecom-firms/ ・APT36とSideCopy、インドの複数組織にクロスプラットフォームRATキャンペーンを展開 https://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・監視ツールメーカー元CEOが「数百万台のコンピューターとデバイス」にアクセス可能なエクスプロイトを露ブローカーに売却 米司法省が公訴事実と認める https://techcrunch.com/2026/02/11/doj-says-trenchant-boss-sold-exploits-to-russian-broker-capable-of-accessing-millions-of-computers-and-devices/ ・オランダ警察、MFAパスコード取得ツール「JokerOTP」の販売者を逮捕 https://www.bleepingcomputer.com/news/security/police-arrest-seller-of-jokerotp-mfa-passcode-capturing-tool/ <プライバシー> ・Google、学生ジャーナリストの個人情報と金銭関連情報をICEに提供か https://techcrunch.com/2026/02/10/google-sent-personal-and-financial-information-of-student-journalist-to-ice/ <政府/政策> ・ロシア政府がTelegramの通信速度を制限 独自のメッセージングアプリを推奨する動きに関連か https://therecord.media/russia-throttles-telegram-pushes-its-own-messaging-app
Post summary
The collection highlights newly disclosed vulnerabilities across Microsoft, SAP, and other vendors, notes patch releases and active exploitation via CISA KEV, but provides no PoC or exploit code.

