FORSMILE
JA
FORSMILE Tech Blog

CODE & CREATE

Tech articles on Web development, AI, and frontend engineering.

SECURITY ALERT
セキュリティ2026/08/26

[URGENT] Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962: Apply the January 2026 CPU Now — Unauthenticated Data Tampering

CISA added this flaw to the KEV catalog on August 24, 2026 with a remediation deadline of August 27. Exploitable over the network without authentication and scored 10.0 under CVSS 3.1, here are the affected versions, the patch to apply, and Oracle's own stance on workarounds.

Read More →
CategoriesAIネット安全セキュリティすべて見る →
This week in AIIssue #2 / 8 items

This Week in AI, 8 Stories — OpenAI Cuts Off Cursor, and Discloses an Eval That Escaped

Read the latest issue →

Latest Posts

Latest articles
ネット安全2026/09/04

The Celebrity "Easy Money" Pitch on Social Media: If the Account Is in a Personal Name, It Is a Scam

Japan's National Consumer Affairs Center published new case reports on September 1, 2026, with losses around 10 million yen. There is one reliable test: whose name is on the bank account. Here is the full flow and how to check a firm's registration.

Read More →
セキュリティ2026/09/04

MapLibre GL JS CVE-2026-85061: Update to 6.4.1 — Zero-Click XSS via Map Attribution

MapLibre GL JS 6.4.0 and earlier carry a CVSS 10.0 XSS. The sanitizer skips one dangerous attribute out of every adjacent pair, and the surviving handler fires the moment the map renders its attribution. Update the maplibre-gl npm package to 6.4.1 or later.

Read More →
セキュリティ2026/09/03

LiteLLM CVE-2026-59822: Update to 1.84.0 — Exploited MCP Auth Bypass

CISA added LiteLLM's MCP auth bypass and Starlette's missing Host header validation to its KEV catalog of actively exploited flaws on September 2, 2026. Update LiteLLM to 1.84.0, Starlette to 1.0.1.

Read More →
AI2026/09/02

LY Corporation's AI Agent Platform: Agent Builder, Agent Runtime, and Going From 7 to 22 Domains

LY Corporation has published the design behind its Agent i service. It shelved its original multi-agent plan after finding that building a single agent was the real bottleneck, then built the platform in-house: Agent Builder, an intermediate representation, LangGraph, and per-environment Kubernetes namespace isolation.

Read More →
セキュリティ2026/09/02

Amelia for WordPress CVE-2026-9055: Update to 9.6.3 or Later — Unauthenticated Admin Takeover

Amelia Premium 8.0 through 9.6.2 lets an unauthenticated attacker overwrite an administrator's password and take over the account (CVE-2026-9055, CVSS v3.1 9.8 CRITICAL). The fix is 9.6.3; the current release is 9.8.1. Check your version number first — the free edition uses a different version series.

Read More →
セキュリティ2026/09/01

PaperCut NG/MF CVE-2026-81578: Patch Now, Exploited in Wild

PaperCut NG/MF, CVE-2026-81578 and CVE-2026-82078: restrict internet access to the admin interface now, then apply Emergency Patch Release 3. The two are being chained in real attacks and CISA added both to its Known Exploited Vulnerabilities catalog on 2026-08-31. Version numbers will not tell you whether you are safe.

Read More →
View All Posts