FORSMILE
JA
FORSMILE Tech Blog

CODE & CREATE

Tech articles on Web development, AI, and frontend engineering.

SECURITY ALERT
セキュリティ2026/08/26

[URGENT] Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962: Apply the January 2026 CPU Now — Unauthenticated Data Tampering

CISA added this flaw to the KEV catalog on August 24, 2026 with a remediation deadline of August 27. Exploitable over the network without authentication and scored 10.0 under CVSS 3.1, here are the affected versions, the patch to apply, and Oracle's own stance on workarounds.

Read More →
CategoriesAIネット安全セキュリティすべて見る →
This week in AIIssue #5 / 15 items

This Week in AI, 15 Items — OpenAI and Anthropic Both Moved to Make Their Own Failures Externally Checkable

Read the latest issue →

Latest Posts

Latest articles
ネット安全2026/09/24

Deepfake fraud is not just voices any more: Japan's police report an AI-generated face used on a video call to impersonate an officer

A report published by Japan's National Police Agency in September 2026 describes arrests in a fraud case where the caller generated a face with AI for a video call while posing as a police officer. Special fraud losses in the first half of 2026 reached about 181.62 billion yen, up 51.7% year on year.

Read More →
セキュリティ2026/09/24

F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE, but only on OAuth Authorization Server setups — CISA deadline 25 September

F5 BIG-IP APM has a heap-based buffer overflow that reaches unauthenticated remote code execution. CISA added it to the KEV catalog on 22 September 2026 with a 25 September deadline. It only affects deployments configured as an OAuth Authorization Server.

Read More →
ネット安全2026/09/23

Two-Step Verification Is Not Enough: 19,207 Brokerage Account Break-Ins

Japan's FSA updated its figures on 9 September 2026: 19,207 unauthorised logins and 10,639 unauthorised trades in online brokerage services. Here is how real-time phishing defeats one-time codes, and what to do today.

Read More →
セキュリティ2026/09/23

Zyxel GS1900 CVE-2026-7273: Patch Now — 996 Switches Already Breached

Zyxel shipped the fix on 16 June 2026, but CISA added CVE-2026-7273 to the KEV catalog on 21 September. 996 switches across 48 countries were compromised, 564 of them still on factory default credentials. Here are the ten affected models and their fixed firmware.

Read More →
ネット安全2026/09/21

"My Parents Don't Use the Internet" Is the Wrong Assumption

Japan's National Consumer Affairs Center reported on 16 September 2026 that consultations involving someone aged 65 or over reached 330,497 in FY2025 — 37.7% of all consultations. The age group with the highest share of mail-order complaints is 65 to 69, and that share falls as age rises. Here is what not to do when a bill arrives for something nobody bought.

Read More →
セキュリティ2026/09/21

Linux Kernel CVE-2025-39682: Patch Now If You Use kTLS

CISA added three Linux kernel flaws to KEV on 18 September, not two — our 18 September article covered only two of them. The third, CVE-2025-39682, is in the kernel TLS receive path and its deadline is today, 21 September. Three assessors disagree: kernel.org 9.8, NIST 7.1, Red Hat 7.0.

Read More →
View All Posts