
【リンク集:2月13日〜16日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、Microsoft SCCMの深刻な脆弱性が攻撃に悪用されたと警告(CVE-2024-43468) https://www.bleepingcomputer.com/news/security/cisa-flags-microsoft-configmgr-rce-flaw-as-exploited-in-attacks/ ・Chrome 145、11件の脆弱性を修正(CVE-2026-2313、CVE-2026-2314他) https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/ ・Ivanti製品の脆弱性を狙ったRCE攻撃、83%は単一の脅威アクターによる犯行か(CVE-2026-1281、CVE-2026-1340) https://www.bleepingcomputer.com/news/security/one-threat-actor-responsible-for-83-percent-of-recent-ivanti-rce-attacks/ ・BeyondTrustの脆弱性、PoC公開直後から悪用が確認される(CVE-2026-1731) https://securityaffairs.com/187962/uncategorized/attackers-exploit-beyondtrust-cve-2026-1731-within-hours-of-poc-release.html <マルウェア・その他脅威> ・UAT-9921がVoidLinkマルウェアを展開、標的はテクノロジーおよび金融部門https://thehackernews.com/2026/02/uat-9921-deploys-voidlink-malware-to.html ・認証情報盗むChrome拡張機能を見つけて削除する方法 https://www.malwarebytes.com/blog/news/2026/02/how-to-find-and-remove-credential-stealing-chrome-extensions ・ユーザーデータをリーク・窃取する有害なChrome拡張機能が300超見つかる https://www.securityweek.com/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/ ・ClickFix攻撃でClaude LLMのアーティファクトが悪用される Macにインフォスティーラーを拡散 https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/ ・TrezorとLedgerのユーザーの暗号資産狙う郵便物 https://www.bleepingcomputer.com/news/security/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/ <データ侵害/サイバー犯罪> ・オランダ大手通信会社Odidoがデータ侵害を受ける 顧客620万人に影響 https://techcrunch.com/2026/02/13/dutch-phone-giant-odido-says-millions-of-customers-affected-by-data-breach/ ・フィンテック企業Figureがデータ侵害を公表 従業員がフィッシング攻撃の被害にhttps://securityaffairs.com/187988/cyber-crime/fintech-firm-figure-disclosed-data-breach-after-employee-phishing-attack.html <AI関連> ・設定ミスのあるAIが国家のインフラ崩壊を引き起こす可能性 https://www.theregister.com/2026/02/13/gartner_ai_infrastructure/ <サイバー戦/APT/国家型アクター/地政学関連> ・ロシア系アクターがウクライナへのCANFAILマルウェア攻撃に関与か Googleが指摘 https://thehackernews.com/2026/02/google-ties-suspected-russian-actor-to.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・韓国、データ侵害許したルイヴィトン・ディオール・ティファニーに罰金2,500万ドルを科すhttps://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/ <プライバシー> ・米国土安全保障省、反ICEアカウントの所有者特定へ圧力強化 多くの行政召喚状を送付かhttps://techcrunch.com/2026/02/14/homeland-security-reportedly-sent-hundreds-of-subpoenas-seeking-to-unmask-anti-ice-accounts/ ・Amazon傘下のRingがFlockとの提携計画を終了 プライバシー侵害懸念されるカメラの宣伝騒動から数日後 https://therecord.media/ring-ends-partnership-with-flock-superbowl-ad <リサーチ/攻撃手法/TTP> ・PastebinのコメントがJavaScript使うClickFix攻撃を促進、暗号資産スワップを乗っ取るhttps://www.bleepingcomputer.com/news/security/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/ ・マイクロソフト、DNSベースのClickFix攻撃の詳細を公開 マルウェアのステージングにNslookupコマンドを使用 https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html ・北朝鮮の偽リクルーター、開発者向けコーディング課題にマルウェアを潜ませる https://www.bleepingcomputer.com/news/security/fake-job-recruiters-hide-malware-in-developer-coding-challenges/ ・CRMのコアアプリケーションを攻撃せずに200万件以上のレコードと文書を侵害する方法 https://www.catchify.sa/post/leaking-2m-records-third-party-misconfiguration <政府/政策> ・欧州社会は「恒久的な」サイバー脅威やハイブリッド脅威に適応する必要がある スウェーデンが警告 https://therecord.media/sweden-cyber-threats-europe-permanent ・米国務省サイバー担当官、攻撃者に「実際の代償」を支払わせるべきと主張 https://therecord.media/usa-cyber-actors-consequences ・エストニア諜報機関長官、攻撃的サイバー能力への投資を欧州各国に呼び掛け https://therecord.media/estonia-spy-chief-calls-on-europe-to-invest-in-own-offense <その他> ・独占:パロアルトがハッキング調査報告書から中国を削除か 同国の報復を憂慮した可能性も https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/ ・エプスタイン文書がEVスタートアップとシリコンバレーについて明らかにするもの https://techcrunch.com/2026/02/15/what-the-epstein-files-reveal-about-ev-startups-and-silicon-valley/
Post summary
The article highlights several CVEs—Microsoft SCCM, Ivanti, Chrome, and BeyondTrust—reporting active exploitation, PoC releases, and vendor patch updates.











