Security assessment and information provision

This site provides information on security and offers web audit tools.

  Annoucement          Show List

Update Date":June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date
1 8.8 HIGH
Network
- - Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted mar… New CWE-78
OS Command 
CVE-2026-49492
2026-06-6 03:59 2026-06-6
2 8.8 HIGH
Network
- - Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled c… New CWE-94
Code Injection
CVE-2026-49493
2026-06-6 03:59 2026-06-6
3 8.8 HIGH
Network
- - Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll… New CWE-95
Eval Injection
CVE-2026-50733
2026-06-6 03:59 2026-06-6
4 4.3 MEDIUM
Network
strawberry strawberry_graphql Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the … New CWE-200
CWE-201
Information Exposure
 Insertion of Sensitive Information Into Sent Data
CVE-2026-45739
2026-06-6 03:43 2026-06-5
5 4.3 MEDIUM
Network
synology hyper_backup An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. New CWE-22
Path Traversal
CVE-2024-47273
2026-06-6 03:32 2026-06-3
6 4.1 MEDIUM
Network
synology hyper_backup An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive informati… New CWE-22
Path Traversal
CVE-2024-47263
2026-06-6 03:31 2026-06-3
7 5.9 MEDIUM
Network
synology note_station_client A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. New CWE-319
Cleartext Transmission of Sensitive Information
CVE-2023-52951
2026-06-6 03:20 2026-06-3
8 7.8 HIGH
Local
synology hyper_backup_explorer An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors. New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2022-49042
2026-06-6 03:19 2026-06-3
9 - - - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. New - CVE-2026-6209
2026-06-6 03:17 2026-06-6
10 - - - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. New - CVE-2026-6208
2026-06-6 03:17 2026-06-6

Update Date:June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date
1 - - (複数のベンダ) (複数の製品) Securly Chrome Extensionにおける複数の脆弱性 New - - 2026-06-5 13:34 2026-06-4
2 6.7 警告
Adjacent
TP-Link Systems Inc. Tapo P300
Tapo L535E
Tapo D100C
複数のTP-LINK製品における重要情報の平文送信の脆弱性 New CWE-Other
その他
CVE-2026-34126 2026-06-5 12:08 2026-06-5
3 9.8 緊急
Network
deltasql Project deltasql deltasql Projectのdeltasqlにおける重要な機能に対する認証の欠如に関する脆弱性 New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2018-25412 2026-06-5 10:52 2026-05-30
4 7.5 重要
Network
WinMTR WinMTR WinMTRにおける古典的バッファオーバーフローの脆弱性 New CWE-120
古典的バッファオーバーフロー
CVE-2018-25426 2026-06-5 10:52 2026-05-30
5 7.8 重要
Local
4mhz Base64 Decoder 4mhzのBase64 Decoderにおける境界外書き込みに関する脆弱性 New CWE-787
境界外書き込み
CVE-2019-25634 2026-06-5 10:52 2026-03-24
6 7.8 重要
Local
Google Android XR GoogleのAndroid XRにおける認可に関する脆弱性 New CWE-285
不適切な認可
CVE-2026-0072 2026-06-5 10:52 2026-06-1
7 9.8 緊急
Network
TRENDnet TEW-432BRP Firmware TRENDnetのTEW-432BRP Firmwareにおける複数の脆弱性 New CWE-74
CWE-77
CVE-2026-10060 2026-06-5 10:52 2026-05-29
8 9.8 緊急
Network
TRENDnet TEW-432BRP Firmware TRENDnetのTEW-432BRP Firmwareにおける複数の脆弱性 New CWE-74
CWE-77
CVE-2026-10061 2026-06-5 10:52 2026-05-29
9 9.8 緊急
Network
TRENDnet TEW-432BRP Firmware TRENDnetのTEW-432BRP Firmwareにおける複数の脆弱性 New CWE-119
CWE-121
CVE-2026-10062 2026-06-5 10:52 2026-05-29
10 9.8 緊急
Network
TRENDnet TEW-432BRP Firmware TRENDnetのTEW-432BRP Firmwareにおける複数の脆弱性 New CWE-119
CWE-121
CVE-2026-10063 2026-06-5 10:52 2026-05-29

Target Period : 2026-05-01 〜 2026-09-30

No Name Normal Support Security Support Extended Support
1 Warning Red Hat OpenJDK 8 for Windows 2026-05-31
2 Warning Red Hat OpenJDK 8 2026-05-31
3 Warning Java 8 (LTS) 2026-05-31
4 MariaDB 10.6 2026-06-30
5 SQL Server 2016 Service Pack 2 2021-07-13 2026-07-14
6 Oracle JDK 11 (LTS) 2023-09-30 2026-09-30
2026-6-6 JST
media_news
blog
vulnerability_notification_site
2026-6-5 JST
media_news
No Image Name URL Excerpt Of Changes Tag
1 Bleeping Computer® https://www.bleepingcomputer.com/ Brave Software releases Origin for a paid, bloat-free browsing experience,Hola Browser for Windows compromised to deliver cryptominer,Credit card theft campaign abuses Stripe to host stolen payment in ...
  • English
  • News
  • Foreign Country
  • Information Provision
2 cnet https://www.cnet.com/ Motorola Razr Ultra Review,Best Smart Sprinklers for 2026: Irrigation the Easy Way,The Fastest, Cleanest Way to Make Bacon,48 Hours With the Oura Ring 5: The New Gold Standard,Gmail's Tool for Unsubsc ...
  • English
  • News
  • Foreign Country
  • Blog
3 Cyber Security Intelligence https://www.cybersecurityintelligence.com/ 2026-06-04,Poisonous AI Chatbot Cryptojacking Campaign,Microsoft Alert: A cryptojacking campaign where attackers infect AI chatbot outputs to install RATs & redirect users to malicious download sites ...
  • English
  • News
  • Foreign Country
  • Information Provision
4 Cybersecurity News https://securityonline.info/ June 4, 2026,Apache Fory Vulnerability: High Severity Flaw Bypasses Core Java Serialization Checks,Do Son,June 4, 2026,0,Vulnerability Report,AI Generated Code Vulnerabilities Threaten Emerging Dev Ec ...
  • English
  • News
  • Foreign Country
  • Information Provision
5 Engadget https://www.engadget.com/ Headphones,Marshall Milton ANC review: Making the rare case for premium on-ear headphones,Marshall's latest headphones are like its Major and Monitor models had a baby.,By,James Trew,Read More,Nintend ...
  • English
  • News
  • Foreign Country
  • Blog
6 Gizmodo https://gizmodo.com/ Archaeologists Opened a Queen’s 700-Year-Old Tomb and Found a Medieval Mystery Instead,For the 700th anniversary of a royal monastery, researchers conducted a special excavation that uncovered archaeo ...
  • English
  • News
  • Foreign Country
  • Blog
7 HELPNETSECURITY https://www.helpnetsecurity.com/ OAuth marketplace apps keep access after publishers vanish,June 4, 2026,The modern-day business can learn a lot about risk from this year’s mega events,June 4, 2026,Spotless compliance evidence can st ...
  • English
  • News
  • Foreign Country
  • Information Provision
8 Mashable https://mashable.com/ Mashable Selects,Safety Net,Mashable's Best: E-readers, robovacs, laptops, earbuds, smart home and more,Apple WWDC 2026 is shaping up to be a big event: Here's everything we expect to learn,Substack g ...
  • English
  • News
  • Foreign Country
  • Blog
9 Schneier on Security https://www.schneier.com/ Hacking Meta’s AI Chatbot,Hackers are,convincing,Meta’s AI support chatbot to let them take over other peoples’ accounts:,A,video,posted on X showed the step-by-step process to hack someone’s Instagra ...
  • English
  • News
  • Foreign Country
  • Blog
10 securityweek https://www.securityweek.com/ Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk,As AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomou ...
  • English
  • News
  • Foreign Country
  • Information Provision
11 TechCrunch https://techcrunch.com/ Security,Filtr is a new privacy tool that blocks ads in almost every iPhone and Mac app,Zack Whittaker,1 hour ago,AI,Apple approves Poke as the first AI agent on its Messages for Business platform,Sar ...
  • English
  • News
  • Foreign Country
  • Blog
  • Site Information Gathering
12 TechNadu.com https://www.technadu.com/ Why Trusted Pipeline Identities Matter More Than Ever in Software Supply Chain Security,By,Vishwa Pandagle,|,Published,Attackers Stole Global Stock Exchange Executive's Mailbox for Five Months in Cove ...
  • English
  • News
  • Foreign Country
  • Information Provision
13 TechRadar https://www.techradar.com/ Meta AI's recent hack is a wake-up call for anyone who puts their trust in AI systems,AI is now so human it can fall victim to social engineering — and I wonder if we should ever trust AI enough to ke ...
  • English
  • News
  • Foreign Country
  • Blog
14 The Verge https://www.theverge.com/ Windows is back on the Microsoft menu,At its annual Build developer conference, Microsoft put Windows front and center.,Tom Warren,4:00 PM UTC,Amazon’s new plan for games: James Bond and AI Snoop Dogg ...
  • English
  • News
  • Foreign Country
  • Blog
15 wired https://www.wired.com/ About Face,Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones,Code reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses ...
  • English
  • News
  • Blog
16 ZDNet Japan Security https://japan.zdnet.com/security/ ネットスコープ、「AI Command Center」などを発表--AI資産のリスクを可視化,2026-06-05 07:15,SPF、DKIM、DMARCでビジネスメールがスパム扱いされない方法,2026-06-05 06:00,米Saviyntとアシスト、合弁事業でIDセキュリティを本格展開--日本法人を設立,2026-06-04 17:29,Red Hatの「npm」名前空間、セキュリティ侵 ...
  • Japanese
  • News
  • Information Provision
17 CyberSecurity.com https://cybersecurity-jp.com/ 2026/06/04,アソビュー、予約管理システムへのサイバー攻撃でパートナー情報約1万4千件が流出,2026/06/04,サーバーがランサムウェアに感染し暗号化被害│興亜硝子株式会社,データ消去・バックアップ,OTP(ワンタイムパスワード),特権ID管理
  • Japanese
  • News
  • Company
  • Blog
  • Information Provision
security_company
No Image Name URL Excerpt Of Changes Tag
1 Compass Security https://www.compass-security.com/ Area 41 Security Conference 2026,18.06.2026,In June, the Zurich region will once again become a hotspot for the security community: the Area41 Security Conference opens its doors on 18–19 June…,Read m ...
  • English
  • Web Audit
  • Company
  • CTF
  • Education
  • Incident Response
  • Forensic
  • E-Learning
2 Positive Technologies https://www.ptsecurity.com/ Новый уровень AppSec на Product Backstage*: контроль, масштабируемость, скорость. Новые подходы к SAST, DAST и защите контейнеров в продуктах Positive Technologies,4 июня 2026,Онлайн-запуск: PT NAD 13 ...
  • English
  • News
  • News
  • Web Audit
  • Network Audit
  • Company
  • Smartphone Audit
  • WAF
  • Forensic
  • Pentest
  • SIEM
  • Vulnerability Management
  • Vulnerability Management
  • ERP Security
  • ERP Security
  • Infra Security
3 NTT Advanced Technology Corporation https://www.ntt-at.co.jp/ 06.04,[木],「IT運用管理ソリューション ZOHO ManageEngine」のページを公開しました。,06.04,[木],商品・サービス,「ユーザ体感品質評価・分析サービス」のページを公開しました。,06.04,[木],「AIセキュリティソリューション F5 AI Red Team・F5 AI Guardrails」のページを公開しました。
  • Japanese
  • Web Audit
  • Network Audit
  • Company
  • Consulting
  • Education
  • Endpoint Detection and Response(EDR)
  • Incident Response
  • Forensic
  • Security enhancement support
  • Security enhancement support
  • Automatic Audit tools
  • Targeted Email Attack Training
  • SIEM
  • Cloud
  • IDS/IPS Management
  • DDos protection
  • Endpoint Audit
  • Monitoring
  • CSPM(Cloud Security Posture Management)
  • Internal information leakage countermeasures
4 NTT DATA INTELLILINK Corporation http://www.intellilink.co.jp/ 2026年6月4日 更新,2026年7月8日 開催,当社主催セミナー「顧客の生成AI導入を阻む『3つの壁』を突破するオンプレミス生成AIの提案」を開催,2026年7月8日 開催,2026.06.04 更新,当社主催セミナー「顧客の生成AI導入を阻む『3つの壁』を突破するオンプレミス生成AIの提案」を開催
  • Japanese
  • Web Audit
  • Network Audit
  • Major
  • Company
  • Source Code Audit
  • Smartphone Audit
  • Smartphone Audit
  • Consulting
  • Consulting
  • Education
  • Endpoint Detection and Response(EDR)
  • Pentest
  • Security enhancement support
  • Requirements Consulting
  • SOC
  • Support for PCIDSS
5 GSX http://www.gsx.co.jp/ 2026年5月28日,GSXはクロス・ヘッドの情シス支援サービスと連携し、サイバー攻撃被害対応を支援 GSXのセキュリティ資格講座をクロス・ヘッドが受講することで、サービス品質の向上を支援,2026年5月28日,Press Release,GSXはクロス・ヘッドの情シス支援サービスと連携し、サイバー攻撃被害対応を支援,GSXのセキュリティ資格講座をクロス・ヘッドが受講することで、サービス品質の向上 ...
  • Japanese
  • Web Audit
  • Network Audit
  • Major
  • Company
  • Smartphone Audit
  • IoT Audit
  • Consulting
  • Consulting
  • Qualifications
  • WAF
  • Endpoint Detection and Response(EDR)
  • Incident Response
  • Pentest
  • Targeted Email Attack Training
  • Database Audit
  • Support for PCIDSS
  • Building CSIRTs
  • Vulnerability assessment Design document review
6 Cybereason Inc. https://www.cybereason.co.jp/ 2026/06/04,【セミナーレポート】連鎖する医療機関へのランサムウェア攻撃の実態と防御 〜日本医科大学武蔵小杉病院の事例から学ぶ〜,プレスリリース・お知らせ,2026/06/01,サイバーリーズン、他社EDR・AV利用企業を対象とした「9ヶ月無償ライセンス提供キャンペーン」を開始,ブログ,2026/06/04,SE Insight,【セミナーレポート】連鎖する医療機関へのランサムウェア攻撃の ...
  • Japanese
  • Foreign Country
  • Company
  • Endpoint Detection and Response(EDR)
  • Security enhancement support
  • Requirements Consulting
  • Log Management
  • Japan Corporation
7 Mitsui Bussan Secure Directions, Inc. https://www.mbsd.jp/ 2026.06.04,≪時事通信 / YAHOO!JAPANニュース≫【詳報】ミュトス並みAI普及でサイバー攻撃は「大衆化」=三井物産セキュアディレクションの吉川孝志フェローに聞く,メディア掲載,[コラム]DSPMとは?データセキュリティ体制管理の基本と導入のポイントを解説,2026/06/04,メディア掲載,≪時事通信 / YAHOO!JAPANニュース≫【詳報】ミュトス並みAI普及でサイバー攻 ...
  • Japanese
  • Web Audit
  • Network Audit
  • Major
  • Smartphone Audit
  • IoT Audit
  • Consulting
  • WAF
  • Education
  • Incident Response
  • Forensic
  • Pentest
  • Create Development Guidelines
  • Security enhancement support
  • Security enhancement support
  • SIEM
  • Log Management
  • SOC
  • Information Provision
  • Building CSIRTs
  • Automotive Audit
  • Malware Audit
  • IDS/IPS Management
  • Managed Detection and Response (MDR)
  • Monitoring
  • Threat Intelligence
  • Threat Intelligence
  • Malware and ransomware support
  • Server Robustness Support
  • AI
8 Kobe Digital Labo https://www.kdl.co.jp/ 2026.06.04,お知らせ,神戸商工会議所イベントにKDL永吉が登壇,2026.06.23,OWASPプロジェクトの歩き方
  • Japanese
  • Web Audit
  • Consulting
  • Incident Response
  • Security enhancement support
  • System Development
  • Targeted Email Attack Training
  • Smartphone App Development
9 Asterisk Research, Inc. https://www.asteriskresearch.com/ 詳しく見る,news,東洋経済ONLINE — バックアップしたのに戻せない!,2026.05.12,東洋経済ONLINE — バックアップしたのに戻せない!
  • Japanese
  • Company
  • Consulting
  • Consulting
  • Education
  • Education
  • Support for PCIDSS
10 Ierae Security, Inc. https://ierae.co.jp/
  • Japanese
  • Web Audit
  • Network Audit
  • Company
  • Game Audit
  • Smartphone Audit
  • IoT Audit
  • Consulting
  • CTF
  • Forensic
  • Pentest
  • Cloud Security
  • Automotive Audit
  • Virtual Currency Audit
  • Anti-tampering Audit
11 Sompo Risk Management Inc. https://www.sompocybersecurity.com/index.html 2026/06/04,サイバーリスク管理の要『サプライチェーンセキュリティリスク管理』の今 ~AIが課題克服をサポートする未来のセキュリティ戦略~(6/4),サイバーセキュリティブログ,記事一覧,セキュリティ対策,コラム,詳しく見る,お役立ち資料,脅威インテリジェンス,セキュリティ対策,詳しく見る,2024/11/01,【WP】サイバー脅威インテリジェンスにおける継続的な監視の重要性(11/1), ...
  • Japanese
  • Web Audit
  • Network Audit
  • Major
  • Consulting
  • WAF
  • Pentest
  • Requirements Consulting
  • Automatic Audit tools
  • SOC
  • Malware Audit
  • IDS/IPS Management
  • Privacy Mark
  • Antivirus software
  • Monitoring
  • GDPR compliance
  • Cyber Security for Medical Institutions
  • Cyber Security Exercise
  • Antiphishing
  • ISO27001
  • Threat Intelligence
tool
blog
organization
Security Advisary