B
ä»é±äž
Pierluigi Paganiniæ°ã«ããé±åã»ãã¥ãªãã£ãã¥ãŒã¹ã¬ã¿ãŒïŒRound 581ïŒã§ã
ð äžèšã§ãããš
Pierluigi Paganiniæ°ã«ããé±åã»ãã¥ãªãã£ãã¥ãŒã¹ã¬ã¿ãŒïŒRound 581ïŒã§ããOracle PeopleSoftã®RCEè匱æ§ãShinyHuntersãã£ã³ããŒã³ã§ãŒããã€ãšããŠå©çšãããŠããããšããCISAãåè匱æ§ãæ¢ç¥ã®æªçšæžã¿è匱æ§ã«ã¿ãã°ã«è¿œå ããããšãå ±åãããŠããŸãããŸããã€ã©ã³é¢é£ã®Handalaã«ããæ°Žäºæ¥æãžã®äŸµå®³ããFortinetã®FortiSandboxã«ãããæ·±å»ãªè匱æ§ã®ä¿®æ£ãªã©ãå«ãŸããŠããŸãã
ð該åœå€å®
- Oracle PeopleSoftïŒäººäºã»çµŠäžç®¡çãªã©ã®åºå¹¹ã·ã¹ãã ïŒãå©çšããŠãã
- Fortinet瀟ã®FortiSandboxïŒãµã³ãããã¯ã¹è£œåïŒãå°å ¥ããŠãã
- ãã¹ã¯ãŒããèšå®ããŠããªããããã¯ãŒã¯ã«ã¡ã©ã瀟å ã§å©çšããŠãã
- BitLockerïŒWindowsæšæºã®ãã£ã¹ã¯æå·åïŒã§ããŒã¿ãä¿è·ããŠãã
äžèšãããã«ã該åœããªã â é芳ã§OK
â
è©²åœæã®å¯Ÿå¿
Oracle PeopleSoftããã³FortiSandboxã®ææ°ããããé©çšããCISAã®KEVã«ã¿ãã°ã確èªããŠåªå
çã«å¯Ÿå¿ããŠãã ããã
ð§ ã¡ãŒã«æ¡ãèŠã (管çè åã)
â ïž ãã㯠AI ãçæããåèäŸã§ããé
ä¿¡åã«å¿
ãå
容ãã確èªã®ããã貎瀟ã®ç¶æ³ã«åãããŠç·šéããŠãå©çšãã ãããå®éã®è¢«å®³ç¶æ³ãèªç€Ÿã®å©çšç°å¢ãèžãŸãã倿ã¯ã貎瀟ã®ã»ãã¥ãªãã£è²¬ä»»è
ã«ã確èªãã ããã
ä»¶å: ãå
±æãOracle PeopleSoft ããã³ FortiSandbox ã®è匱æ§å¯Ÿå¿ã«ã€ããŠ
ãç²ãããŸã§ããææ°ã®è åšæ å ±ã«é¢ããå ±æã§ãã
â æŠèŠ
Oracle PeopleSoftã®RCEè匱æ§ãShinyHuntersãã£ã³ããŒã³ã«ãããŠãŒããã€ãšããŠæªçšãããŠãããCISAã®æ¢ç¥ã®æªçšæžã¿èåŒ±æ§ (KEV) ã«ã¿ãã°ã«è¿œå ãããŸããããŸããFortinetã®FortiSandboxã«ãããŠãæ·±å»ãªè匱æ§ãä¿®æ£ãããŠããŸãã
â 圱é¿ç¯å²
- Oracle PeopleSoft Enterprise PeopleTools
- Fortinet FortiSandbox
â å¯Ÿå¿æé
1. Oracle PeopleSoftã®ææ°ã»ãã¥ãªãã£ããããé©çšããRCEè匱æ§ãè§£æ¶ããŠãã ããã
2. FortiSandboxã®ææ°ããŒãžã§ã³ãžã®ã¢ããããŒãã確èªããé©çšããŠãã ããã
3. CISA KEVã«ã¿ãã°ã«åºã¥ããèªç€Ÿç°å¢ã§ã®æªçšçè·¡ããªãããã°ã確èªããŠãã ããã
â åèæ å ±
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- ãã³ããŒå ¬åŒã¢ããã€ã¶ãª
察å¿åªå 床: é«
å¯Ÿå¿æé: éããã«
ãç²ãããŸã§ããææ°ã®è åšæ å ±ã«é¢ããå ±æã§ãã
â æŠèŠ
Oracle PeopleSoftã®RCEè匱æ§ãShinyHuntersãã£ã³ããŒã³ã«ãããŠãŒããã€ãšããŠæªçšãããŠãããCISAã®æ¢ç¥ã®æªçšæžã¿èåŒ±æ§ (KEV) ã«ã¿ãã°ã«è¿œå ãããŸããããŸããFortinetã®FortiSandboxã«ãããŠãæ·±å»ãªè匱æ§ãä¿®æ£ãããŠããŸãã
â 圱é¿ç¯å²
- Oracle PeopleSoft Enterprise PeopleTools
- Fortinet FortiSandbox
â å¯Ÿå¿æé
1. Oracle PeopleSoftã®ææ°ã»ãã¥ãªãã£ããããé©çšããRCEè匱æ§ãè§£æ¶ããŠãã ããã
2. FortiSandboxã®ææ°ããŒãžã§ã³ãžã®ã¢ããããŒãã確èªããé©çšããŠãã ããã
3. CISA KEVã«ã¿ãã°ã«åºã¥ããèªç€Ÿç°å¢ã§ã®æªçšçè·¡ããªãããã°ã確èªããŠãã ããã
â åèæ å ±
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- ãã³ããŒå ¬åŒã¢ããã€ã¶ãª
察å¿åªå 床: é«
å¯Ÿå¿æé: éããã«
Subject: [Security Advisory] Oracle PeopleSoft and FortiSandbox Vulnerabilities
Dear Team,
We are sharing critical security updates regarding Oracle PeopleSoft and Fortinet FortiSandbox.
â Overview
An RCE vulnerability in Oracle PeopleSoft Enterprise PeopleTools is being exploited as a zero-day in the ShinyHunters campaign and has been added to CISA's KEV catalog. Additionally, a critical flaw in Fortinet FortiSandbox has been patched.
â Scope
- Oracle PeopleSoft Enterprise PeopleTools
- Fortinet FortiSandbox
â Action Plan
1. Apply the latest security patches for Oracle PeopleSoft to mitigate the RCE risk.
2. Update FortiSandbox to the latest patched version.
3. Review system logs for indicators of compromise based on CISA KEV guidance.
â Reference
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- Vendor Official Advisories
Priority: High
Deadline: Immediate
Dear Team,
We are sharing critical security updates regarding Oracle PeopleSoft and Fortinet FortiSandbox.
â Overview
An RCE vulnerability in Oracle PeopleSoft Enterprise PeopleTools is being exploited as a zero-day in the ShinyHunters campaign and has been added to CISA's KEV catalog. Additionally, a critical flaw in Fortinet FortiSandbox has been patched.
â Scope
- Oracle PeopleSoft Enterprise PeopleTools
- Fortinet FortiSandbox
â Action Plan
1. Apply the latest security patches for Oracle PeopleSoft to mitigate the RCE risk.
2. Update FortiSandbox to the latest patched version.
3. Review system logs for indicators of compromise based on CISA KEV guidance.
â Reference
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- Vendor Official Advisories
Priority: High
Deadline: Immediate