FORSMILE
JA
ネット安全2026/08/30

Online Safety Recap (Aug 17-29): Support Scams, AI Voice Fraud, Exploited CVEs

Two weeks of scam tactics and security alerts in one place: how to close a fake virus warning, why a familiar voice proves nothing, and three CVEs confirmed as exploited. Four quiz questions at the end.

Back to Blog

Hello! This is Shemihaza, your Sentinel. It has been a little longer than usual since the last recap, so this one covers two weeks, from 17 to 29 August 2026.
One pattern stood out: scams that make you do the work. They do not break your computer. They frighten you into dialling a number, imitate a relative's voice so you transfer money, or dangle easy pay so you collect a package. In every case, the final step is taken by you.
Which also means knowing when not to take that step is enough to stop them. There are four quiz questions at the end. Try them with your family.

Online safety: what we covered

Fake Virus Alert? How to Close a Tech Support Scam Screen

A sudden alarm sound and a full-screen message telling you to call support immediately. That screen is fake, and your computer is not infected. This is stated officially by Japan's IPA (Information-technology Promotion Agency).
Reports of these fake virus warnings to IPA's consultation desk reached 1,428 cases in April-June 2026 alone — the most common category, making up 37.3% of all reports and up roughly 23.7% from the previous quarter. It is currently the scam catching the most people.
The article covers how to close the screen, IPA's safe practice page that reproduces a fake warning, and what to do if you already called the number.

AI Voice Deepfakes: When the Caller Sounds Like Family

What if a call comes in, saying "help me", in your family member's exact voice? AI can now clone a convincing voice from a short sample. "It sounded like them, so it must be them" no longer works as a test.
The article walks through the tactic and the arrangements worth agreeing on with your family in advance.

Spotting the Latest Phishing Emails

Delivery notices, bank warnings, tax office letters — all reproduced convincingly. Do not judge by appearance, and do not follow the link. Open the official app or type the official address yourself. The article lists what to check.

"High-Paying Easy Work": Recognising Criminal Recruitment

"Simple work from your phone." "Same-day high pay." "Just receive a package." In Japan this style of advert is used to recruit people to carry out crimes, a practice known as *yami baito*.
The most dangerous moment is being asked for a photo of your ID while applying. Once you send it, that image becomes leverage to threaten you, and walking away stops being an option. The article covers how to refuse and where to get help.

For engineers: security alerts from these two weeks

All three were added to CISA's KEV catalogue — meaning exploitation was actually observed, not merely predicted. If you run any of these products, do not defer the update.

Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962 (CVSS 3.1: 10.0 CRITICAL)

Exploitable over the network without authentication, and a maximum CVSS 3.1 score of 10.0. Apply the January 2026 Critical Patch Update. CISA's remediation deadline was 27 August.

Gitea CVE-2026-60004 (CVSS 3.1: 9.8 CRITICAL)

In the self-hosted Git service Gitea, the diffpatch API can be used to install a Git hook and execute commands. Versions before 1.27.1 are affected, so upgrade to 1.27.1.

JFrog Artifactory CVE-2026-66384 (CVSS 3.1: 5.3 MEDIUM)

An authenticated user can write outside the intended Docker cache path, so a forged image ends up cached under a trusted image name.
The score is only 5.3, yet it is being exploited in the wild. It is a clear illustration that a high score and a high likelihood of being attacked are two different things. Upgrade to 7.146.35 or 7.161.16.

We also published three AI adoption pieces

Outside security, we looked at how three companies actually put generative AI to work: Panasonic Connect's company-wide rollout (788,000 hours saved in a year), Slack's conversation summarisation and search, and LEGO's customer-service summarisation. Each is based on what the company itself has disclosed, and separates what is confirmed from what is inferred. Links are in the list below.

Quiz time — four questions

If you read these articles, you can spot all four. Try them with your family.

🛡Shemihaza's Quiz — Can you spot it?

A warning screen and an alarm sound suddenly appear on your PC saying you are infected, along with a support phone number. What should you do first?

🛡Shemihaza's Quiz — Can you spot it?

You get a call in a family member's voice saying they had an accident and need money right now. What is the right thing to do?

🛡Shemihaza's Quiz — Can you spot it?

You find a job advert promising easy, same-day, high pay for "just receiving a package". When you apply, they ask you to send a photo of your ID. How should you read this?

🛡Shemihaza's Quiz — Can you spot it?

A vulnerability is disclosed in software you run. Its CVSS score is a modest 5.3, but exploitation has already been confirmed. What should you do?

Everything we published in these two weeks

If something goes wrong

If you think "oh no, I've done it", work through it calmly and in order. There is nothing to be ashamed of. These desks receive hundreds of identical reports every month.
The contacts below are services within Japan:
Police consultation line: #9110 (a nationwide number for non-emergency concerns about everyday safety)
Consumer hotline: 188 (no area code; connects to your nearest consumer affairs centre — this is the number for cancelling a support contract you were talked into)
If a crime is happening right now, call 110 instead.
Outside Japan, contact your national consumer protection body and your local police non-emergency line. The official sources below are the basis for this recap; the IPA and government pages are in Japanese.

Related articles