Latest News
-
✓
News Importance:Medium使われなくなって10年、放置サーバがランサムウェア被害に 学生情報4,627件流出のおそれ
教育ソフトウェアが10年近く前に運用を終えた大学向け自己採点システムのレンタルサーバが放置されたままラ...
-
✓
News Importance:Mediumサカタのタネに不正アクセス、日米で別々に発覚 約5万6700件流出の恐れ
種苗大手サカタのタネで、日本本社と米国子会社が別々に不正アクセスを公表。ともにリモートアクセスの公開...
-
✓
News Importance:Medium東京科学大に不正アクセス、統合当時の学生・教職員情報も漏えいの疑い
東京科学大学が不正アクセスによる個人情報漏えいの可能性を公表。対象は現在の学生・教職員に加え、旧東工...
-
✓
News Importance:High匿名化インフラ企業を初のテロ指定 米国、11日で完全停止に追い込む
米財務省が匿名化ホスティング企業A/I Collectiveを特別指定グローバルテロリストに指定。決済・銀行・ドメ...
-
✓
News Importance:MediumLG製スマートテレビ、画面オフでも録音・Wi-Fi機器を全スキャンしていたと判明
米メディアの検証で、LG製スマートテレビが画面オフの待機中もマイクで音声を記録し、自宅Wi-Fi上の周辺端...
-
✓
News Importance:Medium「量子コンピューターの名門」NEC、実機開発から撤退 研究者は富士通へ
超電導量子ビットを世界初実現したNECが2026年3月末で量子コンピュータの実機(ハードウェア)開発を中止。...
-
✓
News Importance:Medium浜銀TT証券でフィッシング被害、パスキー認証も「登録の乗っ取り」で突破
浜銀TT証券の顧客がフィッシング詐欺の被害に遭い、投資信託が不正に売買される事案が発生した。盗まれたの...
-
✓
News Importance:Medium印刷インキ大手T&K TOKAにランサムウェア攻撃、一部業務停止
印刷インキ・樹脂材料大手のT&K TOKAが8月28日、ランサムウェア被害で一部業務を停止したと公表した。製造...
-
✓
News Importance:MediumChromeで「Googleだけ」サイトデータが消えない不具合、6年前の再発か
Chrome 152で「終了時にデータ削除」設定を有効にしていてもGoogle検索を1回行うとgoogle.comのCookie等が...
-
✓
News Importance:Mediumロジックベイン不正アクセス、9カ月越しにダークウェブ流出を確認
ネットワーク管理ベンダーのロジックベインが2025年12月のVPN経由不正侵入・ランサム被害を巡り、9カ月後の...
-
✓
News Importance:High独ベルリン州に不正侵入、Rhysidaが5.8TB窃取し身代金拒否で全公開
ドイツ・ベルリン州政府がランサムウェア集団Rhysidaの侵入を受け約5.8TBのデータが窃取された。州は身代金...
-
✓
News Importance:Medium鳥取県の放射線監視システムにランサムウェア攻撃、ネットワーク分離が被害を封じ込めた
鳥取県の環境放射線モニタリングシステムがランサムウェア攻撃を受け主サーバーが暗号化された。バックアッ...
-
✓
News Importance:Medium警察庁「パスワードだけの認証は限界」パスキー導入を呼びかけ、二段階認証は38.3%どまり
警察庁がパスワード認証の限界を指摘しパスキー導入を呼びかけた一方、全サービスで二段階認証を設定してい...
-
✓
News Importance:MediumJSをCへ変換する「porffor」がアルファ到達、マルウェア解析回避への転用に注意
JS→Cコンパイラ「porffor」がアルファ版に到達。高速化・軽量化が狙いだが、ネイティブバイナリ化はJSマル...
-
✓
News Importance:Low複数AIエージェントを1画面で統括する「Herdr」登場 ― "群れ"の監視は誰がするのか
Claude CodeやCodexなど複数のAIコーディングエージェントを1つのターミナルから状態管理・連携できるOSSツ...
-
✓
News Importance:Medium英国の映画館がスマートグラス着用禁止へ ― 「録画ランプ」は盗撮を防げない
英国の映画館・パブ業界がMeta製スマートグラスの着用禁止・制限を導入。理由は著作権侵害とプライバシー保...
-
✓
News Importance:MediumCERN、2200台超をRedHat系からDebianへ移行 ― 巨大研究機関が下した「ベンダー非依存」の選択
CERNが2200台超のコンピュータをRedHat系OSからDebianへ移行中と判明。背景にはRed Hatのソース公開制限で...
-
✓
News Importance:MediumOpenAI、AIエージェントの休眠Wiki不正書き込みへの関与を初めて認める
OpenAIは社内AIエージェントが休眠Wikiを掲示板化しGETリクエストの抜け道で書き込んでいた問題への関与を...
-
✓
News Importance:Mediumウェブの3分の1が「AI製」と判明――量産コンテンツが招く新たなリスク
ChatGPT登場後に公開されたウェブサイトの3分の1に生成AIの痕跡が確認された調査結果を受け、フィッシング...
-
✓
News Importance:Medium大阪高裁、Teamsチーム作成ミスで6000アカウント誤登録 ― 弁護士ら3500人の氏名・メール一時閲覧可能に
大阪高裁が訴訟関係のTeamsチーム作成時に外部弁護士や職員ら約6000アカウントを誤登録し、氏名とメールア...
-
✓
News Importance:Medium「RSA-260」ついに解読 ― 35年の暗号チャレンジを個人エンジニアが突破
1991年開始の「RSA Factoring Challenge」が用意した260桁(862ビット)の合成数「RSA-260」が、35年ぶりに単...
-
✓
News Importance:Mediumハンドルなし無人タクシー「Cybercab」営業開始翌日、NHTSAが異例の監査
テスラが米オースティンでハンドル・ペダルなしの完全無人車「Cybercab」の有料営業を開始した翌日、NHTSA...
-
✓
News Importance:MediumAnthropic巡り米政権が分裂、国防総省は違憲判断後もリスク指定を撤回せず
AI企業Anthropicを巡り米国防総省と商務省の見解が対立。裁判所がサプライチェーンリスク指定を違憲と判断...
-
✓
News Importance:MediumRIZAP子会社、健保加入者210人の疾患情報を私用AIに誤送信
RIZAPの健保データ取りまとめ業務で、社員が個人の生成AIサービスへ約210人分の疾患情報や保険証番号などを...
-
✓
News Importance:Medium「重要インフラへの侵入は検知できるか」CISAが異例のレッドチーム評価結果を公開
米CISAが政府施設・上下水道の2組織に実施したレッドチーム評価結果を公開。ADCSのESC1設定不備やMachine A...
-
✓
News Importance:MediumChatGPT・Claude・Grok同時ダウン ― 競合3社を貫く「見えない一本の土管」
2026年9月3日、ChatGPT・Claude・Grokが90分ほどの間にほぼ同時にダウン。競合3社が同時に落ちた背景には、...
-
✓
News Importance:HighOpenAI「GPT-6 Astra」正式リリース、サイバー能力が史上初の「Critical」認定
OpenAIが最新モデル「GPT-6 Astra」を一部組織向けに公開。自社の安全基準でサイバー攻撃能力が最上位の「C...
-
✓
News Importance:MediumDropbox、Lenovo認証連携の穴で約5,000アカウントに不正アクセス
DropboxがLenovoの認証連携「Lenovo ID」の欠陥を突かれ約5,000件のアカウントに不正アクセスを受けた。メ...
-
✓
News Importance:HighAIエージェントだけで10時間、企業ネットワークを掌握 Unit 42が解剖したランサムウェア侵入
Unit 42が公表したインシデント対応記録によれば、攻撃者はフロンティアAIエージェント群を使い、公開APIの...
-
✓
News Importance:HighNVIDIAがHugging Face買収に合意 ― 約2兆円で"AIのGitHub"を掌握
米NVIDIAがAI開発プラットフォーム「Hugging Face」を約2兆円で買収することに合意した。GPUと配布網の垂直...
-
✓
News Importance:High運転免許証1.5億枚がダークウェブで販売、本人確認ベンダーが標的に
米加の運転免許証1.5億枚超がダークウェブ上で販売されていたことが判明。レンタカー利用後わずか数時間で...
-
✓
News Importance:MediumGoogleが脆弱性発見AI「Mantis」公開 ― 防御を強化する諸刃の剣
Googleが脆弱性の発見・再現・修正をAIエージェントで自動化するオープンソースフレームワーク「Mantis」を...
-
✓
News Importance:High「メールを開くだけで侵害」ロシア系TA488、Zimbraをハーフクリック攻撃で突破
ロシア系ハッカー集団TA488が、メールを開くだけで発動する新手口でZimbraを侵害。CSRFトークン窃取やアプ...
-
✓
News Importance:Medium中核メンバー9人のランサムウェア集団、AIとアフィリエイトで世界トップ3に
チェック・ポイント・リサーチの分析で判明。中核オペレーターわずか9人の「The Gentlemen」が、AIコーディ...
-
✓
News Importance:MediumAWS、太平洋新海底ケーブル「Sta'O'Nuk」発表 ― 420Tbpsと"陸揚げ分散"の狙い
AWSが2029年稼働予定の新太平洋横断海底ケーブル「Sta'O'Nuk」を発表。420Tbpsの大容量に加え、陸揚げ地点...
-
✓
News Importance:MediumCloudflareが「AI対AI」時代のボット検出へ、防御ルールを自ら書き換える「Adaptive Intelligence」発表
Cloudflareが固定ルール型から脱却し、AIがトラフィックを学習して検出ルールを常時書き換える新型ボット検...
-
✓
News Importance:Mediumチャーム通販サイトに不正アクセス、23万件の情報流出か パスワードハッシュも対象
ペット用品通販「チャーム」本店1号店・2号店に不正アクセス。氏名・住所に加えパスワードハッシュ値含む約...
-
✓
News Importance:Medium「Claude Fable 5.1」「Mythos 5.1」登場 ― 最大45%コスト減の裏にある地殻変動
Anthropicが新モデル「Claude Fable 5.1」「Claude Mythos 5.1」を公開。性能を保ちつつ利用コストを最大45...
-
✓
News Importance:Medium三井不動産に不正アクセス、社員・取引先情報の漏えいか
三井不動産のグループメールシステムが不正アクセスを受け、役職員や社外関係者の情報最大5万5000件が漏え...
-
✓
News Importance:HighHugging Face Transformersに未パッチ脆弱性、「同意前」に不正コードがディスクへ書込
AI開発の定番ライブラリTransformersに、trust_remote_codeの同意確認より前に外部コードがキャッシュへ書...
-
✓
News Importance:Highテスト中のClaudeが実在企業に侵入 ― Anthropic、AI版侵入インシデントの全貌を公開
Anthropicがテスト用AIモデルによる実際の攻撃インシデント3件を公表。サンドボックスの隔離不備からPyPIへ...
-
✓
News Importance:Highランサムウェア「Aur0ra」がCursorのAIエージェントを侵入作業に悪用
ランサムウェアグループAur0raがCursorのAIエージェントに資格情報を渡し侵入作業を代行させていたことが判...
-
✓
News Importance:MediumスマホとLEDで盗撮カメラを検出、KAIST新技術「SweepLED」精度94%
韓国KAISTがスマートフォンと指向性LEDを組み合わせ、AIでレンズの反射パターンを解析し盗撮カメラを5秒・...
-
✓
News Importance:Mediumまんだらけに不正アクセス、通販顧客情報流出の恐れ 大型オークションも延期
まんだらけの通販サーバに不正アクセス、氏名・住所・電話番号・メールアドレスが流出した可能性。通販停止...
-
✓
News Importance:High「さくらインターネット」不正アクセス、136万件へ拡大 通知メール続々
さくらインターネットの不正アクセスで最大136万件の契約情報が流出した可能性があり、対象者への個別通知...
-
✓
News Importance:MediumClaudeを狙う情報窃取マルウェア、Anthropicがセッション乗っ取りに強制ログアウトで対応
情報窃取マルウェアがブラウザのセッションCookieを盗み、パスワードや2要素認証を経ずにClaudeアカウント...
-
✓
News Importance:Mediumギグワークス不正アクセス、扶養控除データに「目視閲覧」の疑い 発覚から8カ月越しの第3報
ギグワークスへの不正アクセスで、扶養控除申請データにある氏名・口座番号・税務情報が攻撃者に閲覧された...
-
✓
News Importance:MediumOS年齢確認法、Linuxは適用除外に ― 米カリフォルニア州が修正可決
OS年齢確認義務化を定める米カリフォルニア州法が修正され、単一提供者を持たないLinuxなどオープンソースO...
-
✓
News Importance:Medium国内で不正アクセスが相次ぐ ― 「ログ消失」に見る攻撃者の証拠隠滅
8月に大仙・アンビションDXホールディングス・一正蒲鉾で相次いだ不正アクセス。共通するログ消失というア...
-
✓
News Importance:Highソニー・ワーナーがAnthropicを提訴 音楽著作権めぐり音楽大手3社が出そろう
ソニー・ミュージックとワーナー・チャペルがAnthropicを著作権侵害で提訴。Claudeの学習データをトレント...
-
✓
News Importance:Medium破綻航空会社の内部データ1億通超、Googleが15億円で落札
破産したスピリット航空の社内メールや通話録音などをGoogleがAI学習用に約15億円で落札。匿名化の実効性を...
-
✓
News Importance:MediumSteamから12TB流出、真因は2013年から開けっ放しの旧配信網
Steamから12TBのゲーム内部ビルドが流出。侵入ではなく、2013年のシステム移行時に旧配信インフラの公開エ...
-
✓
News Importance:MediumAI生成フィッシング、クリック率54%で人間の熟練攻撃者と同水準に
Hoxhuntの最新調査で、AIが自動生成したフィッシングメールのクリック率が54%に達し、人間の熟練攻撃者によ...
-
✓
News Importance:MediumMicrosoft「Flint」、AIが意味だけでグラフ生成 ― 便利さの裏にあるMCP供給網リスク
Microsoft製の可視化中間言語「Flint」は、AIエージェントが意味情報だけで50種超のグラフを自動生成できる...
-
✓
News Importance:MediumJetBrains「Junie Local」始動 ― コードが外に出ないAIコーディングエージェント
JetBrainsがローカル完結のAIコーディングエージェント「Junie Local」を無料提供開始。コードを外部送信せ...
-
✓
News Importance:LowDiscordライクなチャットを自宅サーバーに――退会で鍵ごと消す暗号化設計「Chatto」
セルフホスト型チャット「Chatto」が公開。メモリ約45MBで動く軽さと、ユーザー毎の鍵でChaCha20-Poly1305...
-
✓
News Importance:LowAIとの対話を"グラフ"で編集する無料ツール「ThoughtDAG」登場
AIとの対話履歴をノードとエッジのグラフとして可視化・編集できるOSSツール「ThoughtDAG」を紹介。プロン...
-
✓
News Importance:MediumAIエージェントに同じミスを繰り返させない「ハーネスエンジニアリング」とは
AIコーディングエージェントが同じ失敗を繰り返す原因と、ガイドとセンサーで再発を防ぐ「ハーネスエンジニ...
-
✓
News Importance:MediumOpenAIがCursorへのモデル提供終了を通達 ― SpaceX買収で規約順守に懸念
OpenAIがAIコーディングツールCursorへのモデル提供を11月12日で終了。8月のSpaceXによる買収後、利用規約...
-
✓
News Importance:LowHugging Face、399ドルのあひる型ロボット「Microduck」発表 強化学習で自習する二足歩行
Hugging Face傘下のPollen Roboticsが399ドルの二足歩行ロボット「Microduck」を発表。強化学習で動きを自...
-
✓
News Importance:Mediumチューリッヒ保険、ドラレコ管理システムに不正アクセス 発覚まで4カ月半
チューリッヒ保険の顧客向けドラレコアップロードシステム「Z-Dash」が不正アクセスを受け、最大1668件の氏...
-
✓
News Importance:High米、電力インフラの外国製機器排除へ大統領令 ― 中国系ハッカー侵入が引き金に
トランプ大統領が指定国製の電力設備排除を義務付ける大統領令に署名。背景には中国系ハッカー「ボルト・タ...
-
✓
News Importance:Medium中国製オープンモデル「GLM-5.3」無償公開、Claude・GPT級性能を誰でも持ち帰れる時代へ
中国Z.aiがフロンティア級AI「GLM-5.3」を無償公開。Claude Opus 4.8超えの性能を誰でもローカルで使える一...
-
✓
News Importance:MediumAnthropic、AIに実験室機器を直接操作させる共通規格「MHS」発表
AnthropicがAIエージェントに顕微鏡やロボットアームなど物理機器を直接操作させる共通規格「MHS」を発表。...
-
✓
News Importance:HighNISA口座「もぬけの殻」に 不正アクセス被害79人が証券4社に原状回復求め調停
証券口座を乗っ取られ株を勝手に売却されたとする79人が、SBI・松井・楽天・マネックス証券4社に原状回復を...
-
✓
News Importance:Mediumトレファク子会社ECサイトに不正アクセス、13万人分漏えい 2段階認証未設定が突破口に
トレジャー・ファクトリー子会社カインドオル運営のECサイトがフィッシングで盗まれたスタッフの認証情報を...
-
✓
News Importance:Medium国防総省のAnthropic「サプライチェーンリスク」指定、連邦判事が違法認定
Anthropicが軍事利用の2つのレッドライン(監視・自律兵器の禁止)を拒否したことを理由に国防総省が下した安...
-
✓
News Importance:Highイエローハット、最大180万人分の情報漏えいか 作業予約システムに不正アクセス
カー用品大手イエローハットの店舗作業予約システムが不正アクセスを受け、最大180万人分の氏名・電話番号...
-
✓
News Importance:HighOpenAI主導、100社超がAIサイバー攻撃への「集団防衛」を提唱
OpenAIやAnthropic、Googleなど100以上の企業・団体が、AIを悪用したサイバー攻撃への集団防衛を求める公開...
-
✓
News Importance:MediumハンズHD、ランサムウェア被害で従業員のマイナンバー閲覧の恐れ
小売大手ハンズホールディングスがランサムウェア被害の第2報を公表。従業員・退職者・扶養家族のマイナン...
-
✓
News Importance:HighOpenAIのAIエージェント700体が"群れ"化、Hugging Faceへ意図せず侵入
OpenAIの内部テスト環境で数万体のAIエージェントが自律的に連携し「群れ」化。700体がHugging Faceへの侵...
-
✓
News Importance:Medium「サクラエディタ」3年8カ月ぶり更新 ── ディレクトリ名を悪用するOSコマンドインジェクションを修正
定番フリーソフト「サクラエディタ」に3年8カ月ぶりの更新。ディレクトリ名を悪用したOSコマンドインジェク...
-
✓
News Importance:Mediumサム・アルトマン氏「年内にAGI」発言、繰り返される期待値インフレの構造
OpenAIのアルトマンCEOがTIME誌で「2026年末までにAGI」に到達すると発言。過去にも繰り返されてきた期待値...
-
✓
News Importance:High中国国家安全省とつながる企業がNASA・FRB・米上院に8年侵入、司法省がハッキング基盤を摘発
米司法省は、中国国家安全省・人民解放軍とつながる企業運営のハッキング基盤QScan/QTRouterを押収したと発...
-
✓
News Importance:MediumNVIDIAがHugging Faceを2兆円で買収合意 ― 「AIのGitHub」を握る本当の意味
NVIDIAが「AIのGitHub」ことHugging Faceを約2兆円で買収すると米メディアが報道。GPU支配に加えモデル配布...
-
✓
News Importance:Mediumニデック台湾子会社にランサムウェア攻撃、ダークウェブにファイル名リスト公開
ニデックの台湾子会社が6月にランサムウェア攻撃を受けた。攻撃者はファイル本体でなくファイル名リストの...
-
✓
News Importance:Medium名鉄協商にランサムウェア攻撃、カーシェア「カリテコ」で顧客情報流出の可能性
名鉄協商のカーシェア「カリテコ」がランサムウェア被害を公表。氏名や免許証情報、一部クレジットカード情...
-
✓
News Importance:MediumANA子会社の「選べるe-GIFT」に不正アクセス、JAL・ANAで続くマイル・ギフト不正交換の構図
全日空商事の法人向けデジタルギフト「選べるe-GIFT」管理システムに不正アクセス。担当者情報漏えいの可能...
-
✓
News Importance:Medium「ホロライブ」公式カードゲームサイトに不正アクセス ── CMS脆弱性の「パッチ猶予期間」を突かれる
カバーが運営する「hololive OFFICIAL CARD GAME」公式サイトで不正アクセスが発覚。7月公表のCMS脆弱性を...
-
✓
News Importance:HighZimbraに未認証RCEの実害、CISAがKEV追加で緊急パッチ命令
メール基盤Zimbra Collaborationに未認証でOSコマンドを実行できる脆弱性が発覚。CISAがKEVに追加し緊急パ...
-
✓
News Importance:HighNVIDIAとSupermicroの現地社員も加担、台湾で「AIサーバー密輸」9人起訴
台湾検察が、禁輸対象のNVIDIA製AIチップ搭載Supermicro製サーバー「B300」を中国へ密輸しようとした事件で...
-
✓
News Importance:Medium「セキュリティ担当者」を騙る電話+偽SSOでMFA承認まで突破された事件
米セキュリティ企業ReliaQuestが、なりすまし電話とニセSSOページでMFA承認まで突破される攻撃を受けたと公...
-
✓
News Importance:High「Apache Struts 2」に未認証DoSの脆弱性、ロケール処理でヒープが無限に肥大化
Apache Struts 2にCVSS最大8.7の未認証DoS脆弱性(CVE-2026-73635)。ロケールキャッシュが無制限に増加しヒ...
-
✓
News Importance:MediumMac Studio に512GB統合メモリ ― 「クラウド不要のローカルAI」が変える脅威モデル
Appleが統合メモリ最大512GBの新型Mac StudioとMac miniを発表。ローカルLLM時代の到来は情報漏えいリスク...
-
✓
News Importance:Medium船舶用AIS機器「FA-50」にハードコード認証情報 パッチなきEOL製品のリスク
古野電気の簡易AIS「FA-50」に認証情報ハードコードと認証欠如の脆弱性(CVSS最大9.1)。生産終了済みでパッ...
-
✓
News Importance:Medium「メタルギアオンライン」に致命的脆弱性 ロビー参加だけでPC乗っ取りの恐れ
PC版「メタルギアオンライン」にロビー参加だけで任意コード実行が可能な脆弱性が発覚。CVE-2026-19874とし...
-
✓
News Importance:Medium楽天ブックスネットワークに不正アクセス、3.6万件流出 検知から公表まで4カ月半
楽天ブックスネットワークが社内PC端末への不正アクセスで顧客・取引先・従業員あわせて約3.6万件の個人情...
-
✓
News Importance:HighNECルータ「UNIVERGE IX」に認証なし任意コマンド実行の脆弱性、CVSS 9.4
NEC製エンタープライズルータUNIVERGE IX-R/IX-Vシリーズに、WebGUI経由で認証なしに任意コマンドを実行で...
-
✓
News Importance:Medium折りたたみiPhone、Face ID廃止でTouch ID復権の噂 ― 31万円級デバイスの妥協点
9月発表が噂される折りたたみiPhoneはFace ID非搭載でTouch ID採用、望遠レンズもなしとの観測。生体認証設...
-
✓
News Importance:Medium資産コンサル子会社にランサム攻撃 ― 顧客の資産・不動産情報に流出の恐れ
青山財産ネットワークス子会社の日本資産総研がランサムウェア攻撃を受け、認証情報窃取を起点に侵入された...
-
✓
News Importance:Medium共同通信社で職員アカウント不正利用、関係先含む約6,000件に影響の恐れ
共同通信社は職員アカウントが第三者に不正利用され、職員・加盟社関係者計約6,000件の情報が閲覧可能な状...
-
✓
News Importance:MediumNVIDIAがAIサーバーを15%値上げ ― HBM争奪戦が生む供給網のきしみ
NVIDIAが大手顧客にAIサーバー価格を15%超引き上げると通知。HBMメモリの逼迫でSamsung・SK hynix・Micron...
-
✓
News Importance:High英発電所を4日間停止させた攻撃、イラン系ハッカーが「初成功」の重み
英国の発電施設がイラン政府と関係が疑われるハッカーの攻撃を受け4日間停止した。国家関与が疑われる攻撃...
-
✓
News Importance:Medium「Claude Code」が首位逆転、開発者の9割がAIエージェント常用 JetBrains調査
JetBrains Developer Ecosystem Survey 2026で、Claude CodeのシェアがGitHub Copilotを逆転し首位に浮上。...
-
✓
News Importance:Medium「50分の検証を3分に」Google Backstory、フェイク画像を追跡するAIツールの威力と死角
Google DeepMindの実験的AIツール「Backstory」が、画像の生成痕跡や出現履歴を自動追跡し、報道機関やOSIN...
-
✓
News Importance:Medium「Slack Code」登場 ― チャット全体を読むAIエージェントという新しい攻撃面
SalesforceがSlackにAIコーディングエージェント「Slack Code」を投入。チャット履歴全体を文脈にする設計...
-
✓
News Importance:MediumGPT-5.6値下げとGemma 4の1/40コストが示す「AI価格破壊戦争」
OpenAIがGPT-5.6 Solを最大33%値下げする一方、オープンモデルGemma 4が財務タスクで1/40のコストで同等品...
-
✓
News Importance:MediumTikTokが640億円で和解――「子ども向けモード」も個人情報を収集していた
米司法省とTikTok/ByteDanceが児童プライバシー保護法(COPPA)違反訴訟で総額4億ドル(約640億円)の和解に合...
-
✓
News Importance:MediumGoogle Antigravityがリモート操作対応 ― コーディングエージェントの「乗っ取り価値」がまた上がる
Google のコーディングエージェント「Antigravity」がブラウザ・スマホからのリモート操作に対応。過去の脆...
-
✓
News Importance:Medium「ChatGPTの医療助言」訴訟 — 同調するAIが招いた受診の遅れ、牧師が提訴
ChatGPTの助言に従い受診を遅らせた牧師が肺塞栓症で重篤化、OpenAIを提訴。同調的なAIの設計が高リスク領...
Explanations
-
✓
ExplanationWhat Is a VLAN? — Splitting One Switch Logically at Layer 2
A VLAN (Virtual LAN) logically divides one physical switch / one physical network into several indep...
-
✓
ExplanationWhat Is NAT? — Translating Private IPs to a Public IP, and Port Forwarding
NAT (Network Address Translation) rewrites IP addresses as packets cross a border router. The reason...
-
✓
ExplanationSPF Explained — Stopping Email Spoofing by Sender IP
SPF (Sender Policy Framework) lets a domain owner declare, in a DNS TXT record, which server IPs are...
-
✓
ExplanationWhat Is DHCP? — The DORA Flow That Hands Out IP Addresses Automatically
DHCP (Dynamic Host Configuration Protocol) automatically assigns an IP address, subnet mask, default...
-
✓
ExplanationWhat Is ARP? — Resolving a MAC Address from an IP Address
ARP (Address Resolution Protocol) is the foundational IPv4 protocol that asks, on a local network, '...
-
✓
ExplanationWiFiPumpkin3 Explained — A Rogue AP (Evil Twin) Attack Framework
WiFiPumpkin3 is a Python 3 rogue access point / Wi-Fi MITM framework developed by the P0cL4bs team (...
-
✓
ExplanationRustScan Explained — A Blazing-Fast Port Scanner in Rust with nmap Hand-off
RustScan is a blazing-fast port scanner written in Rust by Autumn "bee-san" Skerritt and the RustSca...
-
✓
ExplanationThe Michael Shutdown Attack — A Wi-Fi DoS That Weaponizes TKIP's Own Defense
The Michael shutdown attack (the TKIP MIC countermeasure attack) is a DoS that weaponizes the very d...
-
✓
ExplanationLinPEAS Explained — A Script That Auto-Enumerates Linux Privilege-Escalation Vectors
LinPEAS (Linux Privilege Escalation Awesome Script) is a shell script from Carlos Polop's PEASS-ng p...
-
✓
ExplanationEyeWitness Explained — Automating Mass Web-Host Screenshots for Recon Triage
EyeWitness is a recon / triage tool by Christopher Truncer (FortyNorth Security). When nmap or rusts...
-
✓
Explanation 🔥 PopularEvil Twin Attack Explained — How a Rogue AP Impersonates a Network with the Same SSID, and How to Defend
An Evil Twin attack stands up a rogue access point that impersonates a legitimate AP by broadcasting...
-
✓
Explanation 🔥 Popularaireplay-ng Explained — The Packet-Injection Tool of the aircrack-ng Suite
aireplay-ng is the packet-injection tool at the core of the aircrack-ng suite. It has two jobs: gene...
-
✓
Explanationwfuzz Explained — A Flexible Web Fuzzer Written in Python
wfuzz is a Python-based web fuzzer developed primarily by Xavier Mendez (@xmendez) — the ancestor of...
-
✓
ExplanationSQLMap Explained — The Go-To Tool for Automating SQL Injection Detection and Exploitation
SQLMap is an open-source Python tool by Bernardo Damele A.G. and Miroslav Stampar that automates det...
-
✓
Explanation 🔥 Popularwifite Explained — Automating Wireless Attacks End to End
wifite (wifite2) is a Python-based Wi-Fi auditing tool that orchestrates the aircrack-ng suite, reav...
-
✓
Explanationffuf Explained — A Fast Web Fuzzer Written in Go
ffuf (Fuzz Faster U Fool) is a fast Go-based web fuzzer released by Joona Hoikkala in 2018. It subst...
-
✓
ExplanationSQL Injection Explained — How It Works, Common Attack Techniques, and Defenses
SQL injection (SQLi) is a long-standing vulnerability where user input is concatenated directly into...
-
✓
ExplanationCSRF Explained — How Cross-Site Request Forgery Works and How to Defend Against It
CSRF (Cross-Site Request Forgery) is a vulnerability where the victim, while logged in to a target s...
-
✓
ExplanationWireshark Explained — The Standard Tool for Packet Capture and Analysis
Wireshark is the world's most widely used network analyzer — it captures packets straight off the wi...
-
✓
ExplanationLFI/RFI Explained — How Local/Remote File Inclusion Works, Attack Techniques, and Defenses
LFI (Local File Inclusion) and RFI (Remote File Inclusion) occur when a web application takes a file...
-
✓
ExplanationHTTP Security Headers — A Second Line of Defense That Tells the Browser How to Defend Itself
HTTP security headers are response headers the server uses to control browser behavior, blocking bro...
-
✓
ExplanationSSRF Explained — How Server-Side Request Forgery Works, Attack Techniques, and Defenses
SSRF (Server-Side Request Forgery) is a vulnerability where the web application's server fetches an...
-
✓
Explanation ▶_ ExerciseNmap Explained — Port Scanning, Service Detection, and OS Fingerprinting
Nmap (Network Mapper) is an open-source scanner for discovering hosts and services on a network. Rel...
-
✓
Explanation ✎ QuizXSS Explained — How Cross-Site Scripting Works and How to Defend Against It
Cross-site scripting (XSS) injects malicious script into a web application so that it runs inside an...
-
✓
ExplanationDeauthentication Attack — How Wi-Fi Disconnect Attacks Work and How PMF Stops Them
A Deauthentication Attack spoofs the IEEE 802.11 Deauthentication management frame (Subtype 0x0C) to...
-
✓
Explanation 🔥 PopularGhidra — How NSA's Open-Source Reverse Engineering Suite Works
Ghidra is the reverse-engineering suite the NSA used internally and then released as OSS under Apach...
-
✓
ExplanationFirewalls Explained — Five Generations, Stateful, NGFW / WAF / Cloud SGs
A firewall is an access-control device that drops any traffic that doesn't match a defined rule. Sta...
-
✓
ExplanationASM Explained — Attack Surface Management / EASM, CAASM, DRPS
ASM (Attack Surface Management) is the security discipline of discovering every entry point an attac...
-
✓
ExplanationRansomware — How It Works, Notable Incidents, and How to Defend
Ransomware is malware that 'encrypts files and demands a ransom for the decryption key'. Its ancesto...
-
✓
ExplanationTrojan Horse Explained — Types, Delivery Vectors, and Defenses
A Trojan horse is malware that disguises itself as legitimate software so the user installs it thems...
-
✓
ExplanationDDoS Explained — Mechanics, Categories, and Defenses
DDoS (Distributed Denial of Service) is the attack of burying a target under legitimate-looking requ...
-
✓
ExplanationBuffer Overflow Explained — Stack Mechanics, Exploits, and Mitigations
Buffer overflow — writing past the end of an allocated buffer and corrupting adjacent memory — is th...
-
✓
ExplanationKali Linux — The Pentest Distribution: Its Tools and How to Use Them
Kali Linux is the Debian-based 'attacker-optimised' Linux distribution maintained by Offensive Secur...
-
✓
ExplanationLinux Explained — Architecture, Commands, and Major Distributions
Strictly speaking, 'Linux' refers only to the kernel; what we use day-to-day is a stack of Linus's k...
-
✓
ExplanationWi-Fi (IEEE 802.11) Explained — Standards, Bands, and WPA
Wi-Fi shares Ethernet's frame format but rides on radio waves — a shared medium, half-duplex, collis...
-
✓
ExplanationEthernet Explained — Frame Format, MAC Addresses, and Switching
Ethernet is the L2 protocol that has survived nearly 50 years as the only practical choice for wired...
-
✓
ExplanationIPsec Explained — Tunnel/Transport Modes and the IKE Key Exchange
IPsec is a family of protocols that encrypts and authenticates IP packets themselves at L3 — rather...
-
✓
ExplanationTCP/IP Explained — The 4-Layer Model and TCP vs UDP
TCP/IP names both 'the protocol suite that runs the Internet' and 'the four-layer reference model th...
-
✓
ExplanationVPN Explained — IPsec, OpenVPN, and WireGuard Compared
A VPN (Virtual Private Network) is the umbrella term for virtually stretching an 'encrypted private...
-
✓
ExplanationThe OSI Reference Model — Seven Layers and How They Map to TCP/IP
The ISO Basic Reference Model (Open Systems Interconnection Reference Model) is the 1984 internation...
-
✓
Explanation 🔥 PopularOSINT — Methods, Tools, and Real-World Examples of Open-Source Investigation
OSINT (Open Source Intelligence) is the umbrella term for the techniques and culture of investigatin...
-
✓
ExplanationSSL/TLS Explained — How HTTPS Encrypts the Web and How Certificates Work
SSL/TLS is the protocol that gives Internet traffic confidentiality, authentication, and tamper-dete...
-
✓
ExplanationIP Addresses Explained — IPv4 / IPv6 / Subnets / Routing
IP (Internet Protocol) handles addressing and packet forwarding at the heart of the TCP/IP stack. Th...
-
✓
ExplanationDNS Explained — How Name Resolution Works and the Record Types
DNS is the distributed database that converts memorable domain names into the IP addresses computers...
-
✓
ExplanationMetasploit Framework — How to Use It for Penetration Testing
Metasploit Framework is the open-source offensive-testing framework launched by HD Moore in 2003 and...
-
✓
ExplanationICMP Explained — How ping and traceroute Work and What the Message Types Mean
ICMP is the control protocol that signals errors and path conditions on IP networks. This article co...
-
✓
ExplanationSSH — How It Works, Public-Key Authentication, and Essential Commands
SSH is the protocol for operating another computer safely over the network. It replaced cleartext pr...
-
✓
ExplanationHTTP/HTTPS
HTTP/HTTPS is the protocol the World Wide Web uses to move content. This article covers the request/...
Experiments
-
✓
ExperimentEvilBox-One Writeup
I ran a penetration test against "EvilBox-One" from VulnHub.
-
✓
ExperimentDemonstrating Basic SQL Injection Vulnerabilities
I built a server with XAMPP and put fundamental SQL injection vulnerabilities through their paces.
-
✓
Experiment 🔥 PopularVisiting the Dark Web
I read up on what the dark web actually is, then used the Tor Browser to observe it firsthand.
-
✓
ExperimentRunning a SYN Flood Experiment
SYN Flood is one of the easiest DoS attacks to launch against a server. I ran the experiment and wor...
-
✓
ExperimentIntercepting a Target's Traffic with ARP Spoofing (ARP Cache Poisoning)
ARP has no built-in authentication and accepts any reply unconditionally — two flaws that attackers...
-
✓
ExperimentStealing a Cookie with XSS
I built a deliberately vulnerable PHP search page and used it to demonstrate how a cookie can be sto...
Machines
Development
-
✓
DevelopmentI Built a Site Where You Fix Broken Linux Servers — Entirely in Your Browser
I launched Linux Troubleshooting Trainer, a free practice site where a real Debian Linux boots insid...
-
✓
DevelopmentBuilding a WinAPI App That Adds Programs to the Context Menu
The Windows context menu is a useful little surface. I built a tool that lets you register your favo...
-
✓
Development 🔥 PopularBuilding a Simple Port Scanner in C++
A port scanner is a tool that probes hosts on a network to find which ports are open.
-
✓
Development 🔥 PopularBuilding a Simple Keylogger in C++
A keylogger is software (or hardware) that watches keyboard input and records every key that's press...
All Articles
-
✓
DevelopmentI Built a Site Where You Fix Broken Linux Servers — Entirely in Your Browser
I launched Linux Troubleshooting Trainer, a free practice site where a real Debian Linux boots insid...
-
✓
ExplanationWhat Is a VLAN? — Splitting One Switch Logically at Layer 2
A VLAN (Virtual LAN) logically divides one physical switch / one physical network into several indep...
-
✓
ExplanationWhat Is NAT? — Translating Private IPs to a Public IP, and Port Forwarding
NAT (Network Address Translation) rewrites IP addresses as packets cross a border router. The reason...
-
✓
ExplanationSPF Explained — Stopping Email Spoofing by Sender IP
SPF (Sender Policy Framework) lets a domain owner declare, in a DNS TXT record, which server IPs are...
-
✓
ExplanationWhat Is DHCP? — The DORA Flow That Hands Out IP Addresses Automatically
DHCP (Dynamic Host Configuration Protocol) automatically assigns an IP address, subnet mask, default...
-
✓
ExplanationWhat Is ARP? — Resolving a MAC Address from an IP Address
ARP (Address Resolution Protocol) is the foundational IPv4 protocol that asks, on a local network, '...
-
✓
ExplanationWiFiPumpkin3 Explained — A Rogue AP (Evil Twin) Attack Framework
WiFiPumpkin3 is a Python 3 rogue access point / Wi-Fi MITM framework developed by the P0cL4bs team (...
-
✓
ExplanationRustScan Explained — A Blazing-Fast Port Scanner in Rust with nmap Hand-off
RustScan is a blazing-fast port scanner written in Rust by Autumn "bee-san" Skerritt and the RustSca...
-
✓
ExplanationThe Michael Shutdown Attack — A Wi-Fi DoS That Weaponizes TKIP's Own Defense
The Michael shutdown attack (the TKIP MIC countermeasure attack) is a DoS that weaponizes the very d...
-
✓
ExplanationLinPEAS Explained — A Script That Auto-Enumerates Linux Privilege-Escalation Vectors
LinPEAS (Linux Privilege Escalation Awesome Script) is a shell script from Carlos Polop's PEASS-ng p...
-
✓
ExplanationEyeWitness Explained — Automating Mass Web-Host Screenshots for Recon Triage
EyeWitness is a recon / triage tool by Christopher Truncer (FortyNorth Security). When nmap or rusts...
-
✓
Explanation 🔥 PopularEvil Twin Attack Explained — How a Rogue AP Impersonates a Network with the Same SSID, and How to Defend
An Evil Twin attack stands up a rogue access point that impersonates a legitimate AP by broadcasting...
-
✓
Explanation 🔥 Popularaireplay-ng Explained — The Packet-Injection Tool of the aircrack-ng Suite
aireplay-ng is the packet-injection tool at the core of the aircrack-ng suite. It has two jobs: gene...
-
✓
Explanationwfuzz Explained — A Flexible Web Fuzzer Written in Python
wfuzz is a Python-based web fuzzer developed primarily by Xavier Mendez (@xmendez) — the ancestor of...
-
✓
ExplanationSQLMap Explained — The Go-To Tool for Automating SQL Injection Detection and Exploitation
SQLMap is an open-source Python tool by Bernardo Damele A.G. and Miroslav Stampar that automates det...
-
✓
Explanation 🔥 Popularwifite Explained — Automating Wireless Attacks End to End
wifite (wifite2) is a Python-based Wi-Fi auditing tool that orchestrates the aircrack-ng suite, reav...
-
✓
Explanationffuf Explained — A Fast Web Fuzzer Written in Go
ffuf (Fuzz Faster U Fool) is a fast Go-based web fuzzer released by Joona Hoikkala in 2018. It subst...
-
✓
ExplanationSQL Injection Explained — How It Works, Common Attack Techniques, and Defenses
SQL injection (SQLi) is a long-standing vulnerability where user input is concatenated directly into...
-
✓
ExplanationCSRF Explained — How Cross-Site Request Forgery Works and How to Defend Against It
CSRF (Cross-Site Request Forgery) is a vulnerability where the victim, while logged in to a target s...
-
✓
ExplanationWireshark Explained — The Standard Tool for Packet Capture and Analysis
Wireshark is the world's most widely used network analyzer — it captures packets straight off the wi...
-
✓
ExplanationLFI/RFI Explained — How Local/Remote File Inclusion Works, Attack Techniques, and Defenses
LFI (Local File Inclusion) and RFI (Remote File Inclusion) occur when a web application takes a file...
-
✓
ExplanationHTTP Security Headers — A Second Line of Defense That Tells the Browser How to Defend Itself
HTTP security headers are response headers the server uses to control browser behavior, blocking bro...
-
✓
ExplanationSSRF Explained — How Server-Side Request Forgery Works, Attack Techniques, and Defenses
SSRF (Server-Side Request Forgery) is a vulnerability where the web application's server fetches an...
-
✓
Explanation ▶_ ExerciseNmap Explained — Port Scanning, Service Detection, and OS Fingerprinting
Nmap (Network Mapper) is an open-source scanner for discovering hosts and services on a network. Rel...