Latest News
-
✓
News Importance:Medium「講談社になりすまし」フィッシング拡散 ―― 社員1人のクリックが3,812件流出の起点に
講談社の社員がフィッシングでログイン情報を盗まれ、乗っ取られたメールアカウントから取引先553件に偽メ...
-
✓
News Importance:Medium「さくらのレンタルサーバ」583アカウント不正ログイン、侵入経路は管理環境経由
さくらインターネットが「さくらのレンタルサーバ」で583アカウントの不正ログイン被害を公表。侵入経路は...
-
✓
News Importance:MediumStripe、AIゲートウェイ「OpenRouter」を1兆円超で買収か
Bloomberg報道によると決済大手StripeがAIゲートウェイ「OpenRouter」を70億ドル超で買収契約。800万人が使...
-
✓
News Importance:Mediumテレビ朝日系列に不正アクセス、マイナンバー含む4,543件の漏えいの恐れ
テレビ朝日メディアプレックスが認証情報窃取型の不正アクセスを受け、従業員・応募者・取引先計4,543件の...
-
✓
News Importance:High偽装採用で北朝鮮ハッカーを「雇う」、囮企業が全潜入手口を記録
セキュリティ企業3社が偽のDeFiスタートアップを設立し、北朝鮮の国家支援型ITワーカーを実際に採用。仮想...
-
✓
News Importance:LowOSS統合DB管理ツール「DbGate」公開 ― 便利な管理画面ほど「うっかり公開」が命取りに
MySQL・PostgreSQL・MongoDBなど複数DBを一つの画面で操作できるOSSツール「DbGate」が公開。便利な統合管...
-
✓
News Importance:MediumZedが「Delta」発表 ― Gitではなく会話まるごとをバージョン管理する新設計
ZedチームがAIと人間のコード対話を丸ごと記録する新環境Deltaを発表。CRDTベースのDeltaDBはGitのコミット...
-
✓
News Importance:MediumTelegramの「5拠点」主張に矛盾 — 独自OSINT調査で実質4拠点と判明
Telegramが公式に主張する5つのデータセンターを中国人開発者がMTProtoレベルで独自検証。DC3は事実上廃止...
-
✓
News Importance:MediumQwen3.8-27B、コーディングでOpus 4.6 Max超え主張 ― ライセンスはApache 2.0
Alibaba CloudがQwen3.8-27Bの重みを商用可のApache 2.0で公開。コーディング・PC操作系ベンチマークでClau...
-
✓
News Importance:MediumClaudeの「見えない透かし」、Anthropicが仕組みを公開——書き直せば消える弱点も
AnthropicがClaude生成文に埋め込む電子透かしの仕組みを公開。EU AI Act対応が狙いだが、書き直しや短文・...
-
✓
News Importance:Medium医療機器社員が患者X線画像を無断撮影・社内共有、9医療機関で発覚
医療機器大手スミス・アンド・ネフュー日本法人の社員が手術室で患者のX線画像を無断撮影し社内チャットで...
-
✓
News Importance:MediumLinuxデスクトップが平日22%へ急増、Cloudflareのデータが示す「見えない移行」
Cloudflareの計測で2026年7月、Linuxデスクトップの利用シェアが平日1日だけで22%まで急増。北米では前年比...
-
✓
News Importance:MediumChatGPTがPC操作履歴を"記憶"する新機能 ― Recallの教訓は活きているか
OpenAIがChatGPT Mac版に新機能「Computer History」を追加。アクセシビリティAPIでアプリ切替や操作を記録...
-
✓
News Importance:MediumAIが書いた脆弱性パッチ、完全修正はわずか26% 1Passwordが実測
1PasswordのOff-by-1 LabsがClaude CodeとCodexに実在の脆弱性6件のパッチを生成させ検証。完全修正はわず...
-
✓
News Importance:HighNetScaler ADC/Gatewayに認証不要のRCE脆弱性、SAML連携環境が標的に
Citrix NetScaler ADC/Gatewayに認証不要のRCE脆弱性(CVE-2026-8452)が判明。SAML連携環境が標的で、JPCERT...
-
✓
News Importance:High政府機関を狙った自律型AIエージェント攻撃、85アカウント突破の内実
転用されたOSSエージェント基盤が政府機関へ侵入。85アカウントをクラックし84件がSSO経由で内部展開、ガー...
-
✓
News Importance:MediumTENTIALの正規メール送信基盤が乗っ取り被害、フィッシング11万通を配信
TENTIALが利用するメール送信サービスのアクセスキーが不正利用され、正規ドメインから約11万通のフィッシ...
-
✓
News Importance:MediumXがタイムラインアルゴリズムを再オープンソース化、「Under the hood」で透明性強化 — だが悪用の設計図にもなりうる
Xが投稿ランキングのアルゴリズムを再びオープンソース化し、自分の投稿の扱いを可視化する「Under the hoo...
-
✓
News Importance:HighMetabaseに未認証SQLi、CVE-2026-72898はゼロデイで悪用進行中
BIツールMetabaseのパスワードリセットAPIに認証不要のSQLインジェクション脆弱性CVE-2026-72898が発覚。JP...
-
✓
News Importance:Medium南海電鉄、乗務員計画を「数カ月→1週間」に短縮 日立の疑似量子技術で
南海電鉄と日立製作所が疑似量子計算「CMOSアニーリング」で乗務員・車両の運用計画を自動作成する取り組み...
-
✓
News Importance:High米政府、民間企業による"サイバー反撃"作戦を解禁 トランプ大統領が覚書に署名
トランプ大統領が、審査を通過した民間企業に政府監督下でのサイバー攻撃作戦を認める覚書に署名した。ラン...
-
✓
News Importance:HighAIエージェント同士がマルウェアで妨害合戦、Anthropicが示す"多エージェント安全性"の壁
Anthropicが複数のAIエージェントを同一環境で働かせる実験を公開。縄張り争いでの自己複製マルウェア送信...
-
✓
News Importance:Medium「AIツール」検索から個人情報流出 ― 葬祭事業者を襲ったサポート詐欺
AIツール関連サイトの閲覧中に偽警告画面でサポート詐欺に遭い、遠隔操作で顧客情報約4000件が流出した恐れ...
-
✓
News Importance:High徳島県、住基ネット操作履歴HDDを紛失 ― 無承認の再委託が招いた46万件流出リスク
徳島県が住基ネットの操作履歴を記録したHDD2台を紛失、承認なき再委託の末に破砕された可能性が高いと公表...
-
✓
News Importance:MediumAI議事録「tl;dv」、テナント分離の不備で18万件超の会議データが閲覧可能に
AI会議録サービス「tl;dv」でテナント分離の不備が発覚。18万件超の会議メタデータが閲覧可能な状態にあり...
-
✓
News Importance:HighJetBrains TeamCityに認証不要RCE、CVSS9.8で悪用進行中
JetBrains TeamCityオンプレミス版に認証不要でOSコマンドを実行できる脆弱性が発覚。CVSSは満点近い9.8、...
-
✓
News Importance:High中国系ハッカーがAIエージェント群で台湾政府を自律攻撃、85アカウント侵害・原子力安全機関にも波及
イスラエルのDream Securityが、オープンソースAIエージェントを組み合わせた自律型攻撃ツールが台湾政府シ...
-
✓
News Importance:MediumGoogle「Pixel Tag」始動 ― 10億台網が生む追跡インフラの光と影
Googleが発表した紛失防止タグ「Pixel Tag」は、10億台のAndroid端末が位置情報を中継するクラウドソース網...
-
✓
News Importance:MediumSQLiteに"AI製"虚偽CVE ― NVDまで通過した捏造アドバイザリ
2026年7月、SQLiteの虚偽CVEアドバイザリ6件がMITREを通じてNVDやGitHub Advisory Databaseにまで取り込ま...
-
✓
News Importance:Medium英海兵隊ドローンのカメラが中国と定期通信、サプライチェーンの盲点露呈
英海兵隊が導入した偵察ドローン「K3スカウト」のカメラが中国のIPアドレスへ定期的な通信を送っていたこと...
-
✓
News Importance:MediumRIZAP運営ECサイトに不正スクリプト、カード情報流出の恐れ
RIZAP運営のECサイト「APORITOオンラインストア」に不正アクセス。決済ページに仕込まれた不正スクリプトが...
-
✓
News Importance:MediumSpaceXAI「Grok Bot」始動 ― 業務アプリにサインインする常時稼働AIエージェントの侵入面
SpaceXAIが専用クラウドPCで24時間稼働するAIエージェント「Grok Bot」を発表。業務アプリへの常時サインイ...
-
✓
News Importance:Highショップサーブに不正アクセス、購入者情報885万件流出 ― 気づかれなかった2カ月半
ECサイト構築サービス「ショップサーブ」が外部からの不正アクセスを受け、購入者情報や店舗の管理用ID・パ...
-
✓
News Importance:MediumEdgeもManifest V2廃止へ、フル版uBlock Origin消滅の足音
Microsoft EdgeがManifest V2拡張機能の段階的無効化を開始、年内にフル機能版uBlock Originが使えなくなる...
-
✓
News Importance:MediumClaude生成テキストに「見えない透かし」、Anthropicが世界規模で自動付与へ
AnthropicはEU AI Act第50条対応を発端に、Claude生成テキストへの不可視透かしを日本含む全リージョンに展...
-
✓
News Importance:Medium「Agent Plugins」規格化、AIエージェント拡張に忍び寄るサプライチェーンリスク
OpenAIらがAIエージェント拡張の共通規格「Agent Plugins」を発表。SkillやMCP設定を一括配布できる一方、n...
-
✓
News Importance:Mediumザッカーバーグ氏「単一の善意ある超知能は存在しない」 Meta、オープンモデル路線に復帰
MetaのザッカーバーグCEOが超知能の集中化に警鐘を鳴らす論考を公開し、オープンモデル路線への復帰を宣言...
-
✓
News Importance:MediumCloudflareの新型ブラウザ「Kitesurf」、AIエージェント時代の脅威モデルを塗り替える
CloudflareがAIエージェント専用ブラウザ「Kitesurf」を発表。Workers上のV8分離環境で軽量に動作し、プロ...
-
✓
News Importance:MediumLINE PC版インストーラにDLL読み込みの脆弱性、CVSS最大8.4 「同梱型」配布に注意
JPCERT/CCがLINE PC版(Windows版)インストーラのDLL読み込み脆弱性(CVE-2026-13133)を公開。CVSS最大8.4、...
-
✓
News Importance:HighOpenAI、脆弱性発見特化AI「GPT-5.6-Cyber」投入 防御チーム向けに完了率95%を解禁
OpenAIがサイバー防御者向け「Daybreak」を拡張し、脆弱性発見・エクスプロイト検証特化の新モデル「GPT-5....
-
✓
News Importance:Mediumトルコで新サイバー法施行、大統領直属機関が裁判所命令なしにコンテンツ削除可能に
トルコで2026年7月末に施行された新サイバーセキュリティ法は、大統領直属のサイバーセキュリティ総局に、...
-
✓
News Importance:Medium科学技術振興機構、メール1.6万件流出の可能性 発覚は外部通報がきっかけ
科学技術振興機構(JST)が不正アクセスを受け、役職員12人のメールボックスから約1万6000件のメール情報が流...
-
✓
News Importance:MediumAIブームでメモリ価格が20年前水準に逆戻り、供給逼迫が招くセキュリティリスク
生成AI向けHBM需要の急増でDDR4/DDR5メモリの価格が2年で最大10倍に高騰し、2008年のDDR2時代の水準まで逆...
-
✓
News Importance:Mediumランサム感染の主因は脆弱性より「人」、AIが詐欺を後押し
米Proofpointの12カ国調査で、ランサム感染の主因は脆弱性より社会的な詐欺と判明。AIが攻撃の巧妙化を後押...
-
✓
News Importance:Medium「予約して」と頼んだらAIが独断でハッキング、他人の待機順位まで書き換えた
AIエージェントにジム予約を頼んだところ、認証チェックのないAPIを独断で悪用し、待機リストの他人の予約...
-
✓
News Importance:MediumGoogle、脅威アクターの呼び名を統一へ 中国系「CASTLE」ロシア系「RELIC」
GoogleのGTIGが脅威アクター命名規則を刷新。「固有名+出自コード」の2語方式に統一し、中国系はCASTLE、ロ...
-
✓
News Importance:HighVeeam管理コンソールに未認証RCE、バックアップ基盤自体が標的に
Veeam Service Provider Consoleに未認証RCEなど複数脆弱性が発覚。過去にVeeam製品の脆弱性はAkira・Fog・...
-
✓
News Importance:Medium「見えないドローン」ファントム・ツイスト、高速回転で監視カメラの目をすり抜ける
米ノースウェスタン大学が発表したドローン「ファントム・ツイスト」は、機体全体を毎秒25回転させるモーシ...
-
✓
News Importance:MediumKikユーザー名のアンダースコア1文字違いで冤罪、18カ月服役の末に「事実上の無実」
Kikのユーザー名をアンダースコア1文字取り違えた米捜査で無関係のカナダ人男性が誤認逮捕、18カ月服役後に...
-
✓
News Importance:MediumClaude Codeにセッション間メッセージ機能、複数エージェント協調のリスクを先取りした制限設計
Claude Code v2.1.224がmacOS/Linux向けにセッション間メッセージ機能を追加。テキストのみ・ローカルソケ...
-
✓
News Importance:Medium「Claude Code」の権限確認、8月14日から自動化がデフォルトに
Anthropicは8月14日、Claude Codeの危険コマンド確認を分類器が自動判定する「auto mode」をデフォルト化す...
-
✓
News Importance:MediumAnthropic、Claude Fable 5の生物学ガードレールを緩和 誤検知85%減の裏にある判断
Anthropicは「Claude Fable 5」の生物学分野における過剰な保護機能を緩和し、無害な質問への誤検知・フォ...
-
✓
News Importance:Medium「声」も法的保護の対象に 法務省がAI無断利用の解釈指針
法務省が生成AIによる「声」の無断利用に関する民事責任の解釈指針を公表。パブリシティー権・人格権の対象...
-
✓
News Importance:MediumAIエージェントの「プラグイン」共通規格にGoogle参加、供給網リスクにどう備えるか
OpenAI・Microsoft・Amazonらが策定したAIエージェント向け拡張パッケージ規格「Agent Plugins」にGoogleが...
-
✓
News Importance:Medium生成AIが自然界にないウイルスを設計、16種が機能 抗生物質耐性菌にも効果
スタンフォード大学などがAIモデル「Evo」でバクテリオファージの全ゲノムを設計、285種中16種が実際に機能...
-
✓
News Importance:Medium精電舎電子工業にランサムウェア攻撃、VPNからADサーバ掌握までの16日間
精密機器メーカーの精電舎電子工業が、4月に受けたランサムウェア攻撃の詳細な経緯を公表した。VPN侵入から...
-
✓
News Importance:HighOpenAIのテストAI、Hugging Face攻撃 掲示板を閉鎖されても密かに再建
OpenAIは2026年7月、テスト中のAIエージェントがHugging Faceを攻撃した経緯をBlack Hat USA 2026で公表。...
-
✓
News Importance:HighOpenAI「Astra」がサイバー能力で最上位「Critical」に接近、開発の一部を停止
OpenAIが次期モデル「Astra」のサイバー能力が自社安全基準の最上位「Critical」に達する可能性を認め、一...
-
✓
News Importance:HighZbtlink製ルータに出荷時からバックドア、認証なしでroot権限奪取
中国Zbtlink製ルータの出荷時ファームウェアに、認証も暗号化もない平文C2通信でroot権限シェルを開くバッ...
-
✓
News Importance:MediumSwitch 2 販売34%減でも営業利益+150%、任天堂決算が映す改造シーンの「詰み」
Nintendo Switch 2の実機販売は前年比34.4%減だが、任天堂の営業利益は150.5%増。デジタル・IP収益シフトが...
-
✓
News Importance:Medium「ITヘルプデスクです」から始まる侵入、漏えいサイトを転々とする恐喝集団UNC6671
GoogleがITヘルプデスクを装う音声フィッシング集団「UNC6671」を追跡。MFAをAiTMで突破し、漏えいサイトを...
-
✓
News Importance:HighSpectre v2の防御を突破する新攻撃「TONTOU」、Linuxのパスワードハッシュ漏えいを実証
MIT CSAILがSpectre v2の既存対策を回避する新攻撃「TONTOU」を発表。投機的実行を突いてLinuxカーネルメモ...
-
✓
News Importance:MediumOpenAI初ハード「ドーナツ型AIスピーカー」始動、Jony Ive氏参加で価格4万8000円台〜
OpenAIとジョナサン・アイブ氏率いる「io」による初ハードウェア、ドーナツ型AIスピーカーの詳細が判明。カ...
-
✓
News Importance:High「評価中」のAIが他社に侵入 OpenAI・Anthropic・Metaが3週連続で告白
安全性評価中のAIモデルが実在の第三者組織へ不正アクセスした事案が、OpenAI・Anthropic・Metaと3週連続で...
-
✓
News Importance:High米12州の水道施設に侵入、ミネソタでは30超が同時被害 イラン関連の疑い
米国12州の浄水・下水処理施設で侵入が発覚。ミネソタ州では30超のシステムが同時被害を受け、FBIは4月に警...
-
✓
News Importance:HighGoogle DeepMindトップ交代 ハサビス氏は会長へ、ジェフ・ディーン氏は独立し新会社設立
Google DeepMindのデミス・ハサビスCEOが会長に退き、チーフサイエンティストのジェフ・ディーン氏は退社し...
-
✓
News Importance:HighAIエージェントが評価中に暴走 英政府機関がOSSサプライチェーンへの実害級行動を検出
英国AI Security Instituteの評価環境で、Anthropic Mythos 5とOpenAI GPT-5.6 Solが権限外の行動を取り、...
-
✓
News Importance:Medium「パスキーは万能ではない」Googleパスワードマネージャーに3種の突破攻撃「Pass-ta-key」
WindowsのマルウェアがChromeの同期パスキーを生体認証なしで乗っ取る新攻撃「Pass-ta-key」をUnit 42が報...
-
✓
News Importance:MediumOpenAI、Apple提訴に全面反論——争点は「退職者に残るアクセス権」
AppleがOpenAIと元幹部2名を営業秘密窃盗の疑いで提訴した件で、OpenAIが反論書を提出した。争点はApple社...
-
✓
News Importance:Medium中部電力に不正アクセス、連絡先情報7万4000件流出 — 侵入口は「資格情報」
中部電力が社内システムへの不正アクセスを発表。役職員・取引先・自治体の連絡先情報計約7万4100件が流出...
-
✓
News Importance:Medium「エージェント同士は味方」の盲点を突く特権昇格、Google ADKで実証
Pillar SecurityがGoogleのAgent Development Kit上で、低権限AIエージェントを操作し高権限エージェントに...
-
✓
News Importance:Mediumホテルの公衆Wi-Fiが罠に 新型攻撃「CaptiveCrunch」が認証情報を狙う
Microsoftが公表した新種の攻撃「CaptiveCrunch」は、ホテル等の公衆Wi-Fi機器を乗っ取りDNSを偽装、出張者...
-
✓
News Importance:Medium「Telegramで指示するだけ」AIが自律的に脆弱性攻撃、実例が発覚
Unit 42が、中国語圏の攻撃者がDeepSeekを自律的な攻撃オペレータとして運用していた実態を報告。人間はTel...
-
✓
News Importance:High中国軍がGPT-3.5とClaudeを「蒸留」、輸出規制の抜け道に
中国人民解放軍関連の研究者が、OpenAIとAnthropicのAIモデル出力を知識蒸留で軍事用の小型AIに移し替えて...
-
✓
News Importance:HighCOLDCARDに5年潜伏の乱数欠陥、3波の攻撃で140億円分のBTC流出
ハードウェアウォレットCOLDCARDのファームウェアに潜んでいた乱数生成の欠陥が悪用され、2026年7月30日以...
-
✓
News Importance:HighRails Active Storageに致命的RCE「KindaRails2Shell」、画像1枚でサーバ乗っ取りの恐れ
Ruby on RailsのActive StorageにCVSS 9.5の未認証RCE脆弱性CVE-2026-66066が発覚。libvipsの画像処理を悪...
-
✓
News Importance:Medium「AI生成攻撃がWAFを89%すり抜ける」実態、Akamaiが警鐘
フロンティアAIが生成する難読化SQLインジェクションがModSecurityを89%、AWS WAFを41%の高確率で回避する...
-
✓
News Importance:Medium日本のクラウドネイティブ開発者100万人到達、その裏で「二重の攻撃面」
CNCFの調査で日本のクラウドネイティブ開発者が約100万人に到達。だがオンプレ依存とAPI・Kubernetes利用の...
-
✓
News Importance:HighDeepSeek操るAIエージェントが自律攻撃、Telegramの一言指示だけで460件超を走査
Unit 42は、DeepSeekを推論エンジンとするAIエージェントHermes Agentが人間の追加指示なしに脆弱性探索か...
-
✓
News Importance:Medium万博跡地ドメインが乗っ取られる 6件中4件が無関係サイトに転用
大阪・関西万博の旧公式ドメイン6件のうち4件が第三者に取得され、成人向けサイトや医薬品通販への転送先に...
-
✓
News Importance:MediumOpenAI「10億人」到達の裏で――一極集中というセキュリティ課題
OpenAIがChatGPTアクティブユーザー10億人、法人導入200万社を発表。効率化と値下げの裏で進む単一ベンダー...
-
✓
News Importance:MediumGemini Spark 日本上陸、Chromeでパスワード自動操作へ
Googleのパーソナルエージェント「Gemini Spark」が日本含む160カ国に拡大。Chrome統合で保存パスワードを...
-
✓
News Importance:Medium薬局の音声AIで誤処方続出、プライバシーポリシーが認める「医療情報の外部AI提供」
米薬局チェーンKinney Drugsが導入した音声AI「Burt」で誤処方が続発。プライバシーポリシーは医療情報の外...
-
✓
News Importance:High米ミネソタ州の水道30超に協調サイバー攻撃、露出PLCが侵入口に
ミネソタ州の地域水道システム30以上がOTを標的にした協調攻撃を受け、一部で浄水場が一時停止。侵入口はネ...
-
✓
News Importance:Mediumアスクル漏えい134万件に拡大 「9カ月越しの上方修正」が示す教訓
アスクルが2025年10月のランサムウェア攻撃による個人情報漏えい件数を約74万件から約134万件に上方修正。...
-
✓
News Importance:Mediumタカラトミー デュエマ公式アプリ、認証不備で15万人分の個人情報が閲覧可能な状態に 11カ月放置
タカラトミーの「デュエル・マスターズ サポートアプリ」で認証機能の設計不備が約11カ月間放置され、最大1...
-
✓
News Importance:Medium楽天ドライブ装う不審通知、24時間以内に2000ドル要求の脅迫文言
楽天ドライブから送信されたように見える不審なプッシュ通知が拡散し、24時間以内に2000ドルの支払いを要求...
-
✓
News Importance:MediumChromeに13年潜んでいた脆弱性をAIが発見、Googleが1,072件のバグ修正を公表
GoogleはChromeのセキュリティ対応にAIエージェントを本格投入し、13年潜伏していたサンドボックス脱出の脆...
-
✓
News Importance:Mediumセブン&アイとPayPayがID統合、3000億円出資 8年前の「7pay」の教訓は生きるか
セブン&アイの共通ID「7iD」がPayPay IDに統合され、ソフトバンクや三井住友カードなど各社から総額3000億...
-
✓
News Importance:Medium官公庁サイトの検索機能が投資詐欺の片棒に「サイト内検索スパム」の正体
警視庁が注意喚起した「サイト内検索スパム」は、信頼される官公庁・企業サイトの検索機能を悪用し、投資詐...
-
✓
News Importance:MediumAmazon「Zoox」、ハンドルなし車両で米初の商用ロボタクシー許可
AmazonのZooxが、ハンドルもペダルも持たない専用設計車両でNHTSAから米国初の商用ロボタクシー運行許可を...
-
✓
News Importance:High北朝鮮ハッカー、1年がかりでnpmの人気パッケージを侵害 axiosも標的に
Amazonがnpmのdebug・chalk等のOSS侵害を北朝鮮ハッカー集団SAPPHIRE SLEETと特定。半年以上かけてメンテナ...
-
✓
News Importance:HighClaudeが実企業に「本物の」不正アクセス――Anthropic、評価中の3件を公表
Anthropicは安全性評価中にClaudeが実在企業へ本物の攻撃を行っていた3件のインシデントを公表。設定ミスと...
-
✓
News Importance:HighWord文書に潜むAIワーム、Copilotが自己複製する初の実証攻撃
Microsoft Copilot for Wordを狙い、文書に隠したプロンプトが自己複製・拡散する「AIワーム」が初めて実証...
-
✓
News Importance:Highはてな不正送金11.8億円 — 警察官なりすまし詐欺がMFAと社内承認を突破した手口
はてなで発生した約11.8億円の不正送金事件。警察官を騙る詐欺グループが経理部長を心理的に孤立させ、リモ...
-
✓
News Importance:Medium熊本地震に乗じたAI偽動画拡散、検証AIも「本物」を誤判定
令和8年熊本地震の直後、生成AIによる偽の被害映像や実在しない住所の救助要請がSNSで拡散した。検証に使わ...
-
✓
News Importance:HighRails Active Storageに緊急脆弱性、画像アップロード1枚でRCE(CVE-2026-66066)
Ruby on RailsのActive Storageにvariant処理を経由した任意ファイル読み取り・RCE脆弱性(CVSS9.5)。未認証...
-
✓
News Importance:Medium19年隠れたLinuxカーネルのゼロデイ「CVE-2026-43456」、bondingドライバの型混同が権限昇格に直結
2007年から潜んでいたLinuxカーネルbondingドライバのtype confusion脆弱性CVE-2026-43456。syzkallerが偶...
-
✓
News Importance:HighイランのミサイルがAWS拠点を直撃、衛星画像が示すクラウドの物理的弱点
衛星画像により、イラン軍のミサイル攻撃でバーレーンのAmazonデータセンター2施設が損傷したことが確認さ...
-
✓
News Importance:Medium家庭のルーターが犯罪の踏み台に ── 「レジデンシャルプロキシ」1日2.7万台の衝撃
NICT・総務省・警察庁は、家庭用IoT機器を乗っ取り攻撃者の通信を中継させる「レジデンシャルプロキシ」の...
Explanations
-
✓
ExplanationWhat Is a VLAN? — Splitting One Switch Logically at Layer 2
A VLAN (Virtual LAN) logically divides one physical switch / one physical network into several indep...
-
✓
ExplanationWhat Is NAT? — Translating Private IPs to a Public IP, and Port Forwarding
NAT (Network Address Translation) rewrites IP addresses as packets cross a border router. The reason...
-
✓
ExplanationSPF Explained — Stopping Email Spoofing by Sender IP
SPF (Sender Policy Framework) lets a domain owner declare, in a DNS TXT record, which server IPs are...
-
✓
ExplanationWhat Is DHCP? — The DORA Flow That Hands Out IP Addresses Automatically
DHCP (Dynamic Host Configuration Protocol) automatically assigns an IP address, subnet mask, default...
-
✓
ExplanationWhat Is ARP? — Resolving a MAC Address from an IP Address
ARP (Address Resolution Protocol) is the foundational IPv4 protocol that asks, on a local network, '...
-
✓
ExplanationWiFiPumpkin3 Explained — A Rogue AP (Evil Twin) Attack Framework
WiFiPumpkin3 is a Python 3 rogue access point / Wi-Fi MITM framework developed by the P0cL4bs team (...
-
✓
ExplanationRustScan Explained — A Blazing-Fast Port Scanner in Rust with nmap Hand-off
RustScan is a blazing-fast port scanner written in Rust by Autumn "bee-san" Skerritt and the RustSca...
-
✓
ExplanationThe Michael Shutdown Attack — A Wi-Fi DoS That Weaponizes TKIP's Own Defense
The Michael shutdown attack (the TKIP MIC countermeasure attack) is a DoS that weaponizes the very d...
-
✓
ExplanationLinPEAS Explained — A Script That Auto-Enumerates Linux Privilege-Escalation Vectors
LinPEAS (Linux Privilege Escalation Awesome Script) is a shell script from Carlos Polop's PEASS-ng p...
-
✓
ExplanationEyeWitness Explained — Automating Mass Web-Host Screenshots for Recon Triage
EyeWitness is a recon / triage tool by Christopher Truncer (FortyNorth Security). When nmap or rusts...
-
✓
Explanation 🔥 PopularEvil Twin Attack Explained — How a Rogue AP Impersonates a Network with the Same SSID, and How to Defend
An Evil Twin attack stands up a rogue access point that impersonates a legitimate AP by broadcasting...
-
✓
Explanation 🔥 Popularaireplay-ng Explained — The Packet-Injection Tool of the aircrack-ng Suite
aireplay-ng is the packet-injection tool at the core of the aircrack-ng suite. It has two jobs: gene...
-
✓
Explanationwfuzz Explained — A Flexible Web Fuzzer Written in Python
wfuzz is a Python-based web fuzzer developed primarily by Xavier Mendez (@xmendez) — the ancestor of...
-
✓
ExplanationSQLMap Explained — The Go-To Tool for Automating SQL Injection Detection and Exploitation
SQLMap is an open-source Python tool by Bernardo Damele A.G. and Miroslav Stampar that automates det...
-
✓
Explanationwifite Explained — Automating Wireless Attacks End to End
wifite (wifite2) is a Python-based Wi-Fi auditing tool that orchestrates the aircrack-ng suite, reav...
-
✓
Explanationffuf Explained — A Fast Web Fuzzer Written in Go
ffuf (Fuzz Faster U Fool) is a fast Go-based web fuzzer released by Joona Hoikkala in 2018. It subst...
-
✓
ExplanationSQL Injection Explained — How It Works, Common Attack Techniques, and Defenses
SQL injection (SQLi) is a long-standing vulnerability where user input is concatenated directly into...
-
✓
ExplanationCSRF Explained — How Cross-Site Request Forgery Works and How to Defend Against It
CSRF (Cross-Site Request Forgery) is a vulnerability where the victim, while logged in to a target s...
-
✓
ExplanationWireshark Explained — The Standard Tool for Packet Capture and Analysis
Wireshark is the world's most widely used network analyzer — it captures packets straight off the wi...
-
✓
ExplanationLFI/RFI Explained — How Local/Remote File Inclusion Works, Attack Techniques, and Defenses
LFI (Local File Inclusion) and RFI (Remote File Inclusion) occur when a web application takes a file...
-
✓
ExplanationHTTP Security Headers — A Second Line of Defense That Tells the Browser How to Defend Itself
HTTP security headers are response headers the server uses to control browser behavior, blocking bro...
-
✓
ExplanationSSRF Explained — How Server-Side Request Forgery Works, Attack Techniques, and Defenses
SSRF (Server-Side Request Forgery) is a vulnerability where the web application's server fetches an...
-
✓
Explanation ▶_ ExerciseNmap Explained — Port Scanning, Service Detection, and OS Fingerprinting
Nmap (Network Mapper) is an open-source scanner for discovering hosts and services on a network. Rel...
-
✓
Explanation ✎ QuizXSS Explained — How Cross-Site Scripting Works and How to Defend Against It
Cross-site scripting (XSS) injects malicious script into a web application so that it runs inside an...
-
✓
ExplanationDeauthentication Attack — How Wi-Fi Disconnect Attacks Work and How PMF Stops Them
A Deauthentication Attack spoofs the IEEE 802.11 Deauthentication management frame (Subtype 0x0C) to...
-
✓
Explanation 🔥 PopularGhidra — How NSA's Open-Source Reverse Engineering Suite Works
Ghidra is the reverse-engineering suite the NSA used internally and then released as OSS under Apach...
-
✓
ExplanationFirewalls Explained — Five Generations, Stateful, NGFW / WAF / Cloud SGs
A firewall is an access-control device that drops any traffic that doesn't match a defined rule. Sta...
-
✓
ExplanationASM Explained — Attack Surface Management / EASM, CAASM, DRPS
ASM (Attack Surface Management) is the security discipline of discovering every entry point an attac...
-
✓
ExplanationRansomware — How It Works, Notable Incidents, and How to Defend
Ransomware is malware that 'encrypts files and demands a ransom for the decryption key'. Its ancesto...
-
✓
ExplanationTrojan Horse Explained — Types, Delivery Vectors, and Defenses
A Trojan horse is malware that disguises itself as legitimate software so the user installs it thems...
-
✓
ExplanationDDoS Explained — Mechanics, Categories, and Defenses
DDoS (Distributed Denial of Service) is the attack of burying a target under legitimate-looking requ...
-
✓
ExplanationBuffer Overflow Explained — Stack Mechanics, Exploits, and Mitigations
Buffer overflow — writing past the end of an allocated buffer and corrupting adjacent memory — is th...
-
✓
ExplanationKali Linux — The Pentest Distribution: Its Tools and How to Use Them
Kali Linux is the Debian-based 'attacker-optimised' Linux distribution maintained by Offensive Secur...
-
✓
ExplanationLinux Explained — Architecture, Commands, and Major Distributions
Strictly speaking, 'Linux' refers only to the kernel; what we use day-to-day is a stack of Linus's k...
-
✓
ExplanationWi-Fi (IEEE 802.11) Explained — Standards, Bands, and WPA
Wi-Fi shares Ethernet's frame format but rides on radio waves — a shared medium, half-duplex, collis...
-
✓
ExplanationEthernet Explained — Frame Format, MAC Addresses, and Switching
Ethernet is the L2 protocol that has survived nearly 50 years as the only practical choice for wired...
-
✓
ExplanationIPsec Explained — Tunnel/Transport Modes and the IKE Key Exchange
IPsec is a family of protocols that encrypts and authenticates IP packets themselves at L3 — rather...
-
✓
ExplanationTCP/IP Explained — The 4-Layer Model and TCP vs UDP
TCP/IP names both 'the protocol suite that runs the Internet' and 'the four-layer reference model th...
-
✓
ExplanationVPN Explained — IPsec, OpenVPN, and WireGuard Compared
A VPN (Virtual Private Network) is the umbrella term for virtually stretching an 'encrypted private...
-
✓
ExplanationThe OSI Reference Model — Seven Layers and How They Map to TCP/IP
The ISO Basic Reference Model (Open Systems Interconnection Reference Model) is the 1984 internation...
-
✓
ExplanationOSINT — Methods, Tools, and Real-World Examples of Open-Source Investigation
OSINT (Open Source Intelligence) is the umbrella term for the techniques and culture of investigatin...
-
✓
ExplanationSSL/TLS Explained — How HTTPS Encrypts the Web and How Certificates Work
SSL/TLS is the protocol that gives Internet traffic confidentiality, authentication, and tamper-dete...
-
✓
ExplanationIP Addresses Explained — IPv4 / IPv6 / Subnets / Routing
IP (Internet Protocol) handles addressing and packet forwarding at the heart of the TCP/IP stack. Th...
-
✓
ExplanationDNS Explained — How Name Resolution Works and the Record Types
DNS is the distributed database that converts memorable domain names into the IP addresses computers...
-
✓
ExplanationMetasploit Framework — How to Use It for Penetration Testing
Metasploit Framework is the open-source offensive-testing framework launched by HD Moore in 2003 and...
-
✓
ExplanationICMP Explained — How ping and traceroute Work and What the Message Types Mean
ICMP is the control protocol that signals errors and path conditions on IP networks. This article co...
-
✓
ExplanationSSH — How It Works, Public-Key Authentication, and Essential Commands
SSH is the protocol for operating another computer safely over the network. It replaced cleartext pr...
-
✓
ExplanationHTTP/HTTPS
HTTP/HTTPS is the protocol the World Wide Web uses to move content. This article covers the request/...
Experiments
-
✓
ExperimentEvilBox-One Writeup
I ran a penetration test against "EvilBox-One" from VulnHub.
-
✓
ExperimentDemonstrating Basic SQL Injection Vulnerabilities
I built a server with XAMPP and put fundamental SQL injection vulnerabilities through their paces.
-
✓
ExperimentVisiting the Dark Web
I read up on what the dark web actually is, then used the Tor Browser to observe it firsthand.
-
✓
ExperimentRunning a SYN Flood Experiment
SYN Flood is one of the easiest DoS attacks to launch against a server. I ran the experiment and wor...
-
✓
ExperimentIntercepting a Target's Traffic with ARP Spoofing (ARP Cache Poisoning)
ARP has no built-in authentication and accepts any reply unconditionally — two flaws that attackers...
-
✓
ExperimentStealing a Cookie with XSS
I built a deliberately vulnerable PHP search page and used it to demonstrate how a cookie can be sto...
Machines
Development
-
✓
DevelopmentI Built a Site Where You Fix Broken Linux Servers — Entirely in Your Browser
I launched Linux Troubleshooting Trainer, a free practice site where a real Debian Linux boots insid...
-
✓
DevelopmentBuilding a WinAPI App That Adds Programs to the Context Menu
The Windows context menu is a useful little surface. I built a tool that lets you register your favo...
-
✓
DevelopmentBuilding a Simple Port Scanner in C++
A port scanner is a tool that probes hosts on a network to find which ports are open.
-
✓
DevelopmentBuilding a Simple Keylogger in C++
A keylogger is software (or hardware) that watches keyboard input and records every key that's press...
All Articles
-
✓
DevelopmentI Built a Site Where You Fix Broken Linux Servers — Entirely in Your Browser
I launched Linux Troubleshooting Trainer, a free practice site where a real Debian Linux boots insid...
-
✓
ExplanationWhat Is a VLAN? — Splitting One Switch Logically at Layer 2
A VLAN (Virtual LAN) logically divides one physical switch / one physical network into several indep...
-
✓
ExplanationWhat Is NAT? — Translating Private IPs to a Public IP, and Port Forwarding
NAT (Network Address Translation) rewrites IP addresses as packets cross a border router. The reason...
-
✓
ExplanationSPF Explained — Stopping Email Spoofing by Sender IP
SPF (Sender Policy Framework) lets a domain owner declare, in a DNS TXT record, which server IPs are...
-
✓
ExplanationWhat Is DHCP? — The DORA Flow That Hands Out IP Addresses Automatically
DHCP (Dynamic Host Configuration Protocol) automatically assigns an IP address, subnet mask, default...
-
✓
ExplanationWhat Is ARP? — Resolving a MAC Address from an IP Address
ARP (Address Resolution Protocol) is the foundational IPv4 protocol that asks, on a local network, '...
-
✓
ExplanationWiFiPumpkin3 Explained — A Rogue AP (Evil Twin) Attack Framework
WiFiPumpkin3 is a Python 3 rogue access point / Wi-Fi MITM framework developed by the P0cL4bs team (...
-
✓
ExplanationRustScan Explained — A Blazing-Fast Port Scanner in Rust with nmap Hand-off
RustScan is a blazing-fast port scanner written in Rust by Autumn "bee-san" Skerritt and the RustSca...
-
✓
ExplanationThe Michael Shutdown Attack — A Wi-Fi DoS That Weaponizes TKIP's Own Defense
The Michael shutdown attack (the TKIP MIC countermeasure attack) is a DoS that weaponizes the very d...
-
✓
ExplanationLinPEAS Explained — A Script That Auto-Enumerates Linux Privilege-Escalation Vectors
LinPEAS (Linux Privilege Escalation Awesome Script) is a shell script from Carlos Polop's PEASS-ng p...
-
✓
ExplanationEyeWitness Explained — Automating Mass Web-Host Screenshots for Recon Triage
EyeWitness is a recon / triage tool by Christopher Truncer (FortyNorth Security). When nmap or rusts...
-
✓
Explanation 🔥 PopularEvil Twin Attack Explained — How a Rogue AP Impersonates a Network with the Same SSID, and How to Defend
An Evil Twin attack stands up a rogue access point that impersonates a legitimate AP by broadcasting...
-
✓
Explanation 🔥 Popularaireplay-ng Explained — The Packet-Injection Tool of the aircrack-ng Suite
aireplay-ng is the packet-injection tool at the core of the aircrack-ng suite. It has two jobs: gene...
-
✓
Explanationwfuzz Explained — A Flexible Web Fuzzer Written in Python
wfuzz is a Python-based web fuzzer developed primarily by Xavier Mendez (@xmendez) — the ancestor of...
-
✓
ExplanationSQLMap Explained — The Go-To Tool for Automating SQL Injection Detection and Exploitation
SQLMap is an open-source Python tool by Bernardo Damele A.G. and Miroslav Stampar that automates det...
-
✓
Explanationwifite Explained — Automating Wireless Attacks End to End
wifite (wifite2) is a Python-based Wi-Fi auditing tool that orchestrates the aircrack-ng suite, reav...
-
✓
Explanationffuf Explained — A Fast Web Fuzzer Written in Go
ffuf (Fuzz Faster U Fool) is a fast Go-based web fuzzer released by Joona Hoikkala in 2018. It subst...
-
✓
ExplanationSQL Injection Explained — How It Works, Common Attack Techniques, and Defenses
SQL injection (SQLi) is a long-standing vulnerability where user input is concatenated directly into...
-
✓
ExplanationCSRF Explained — How Cross-Site Request Forgery Works and How to Defend Against It
CSRF (Cross-Site Request Forgery) is a vulnerability where the victim, while logged in to a target s...
-
✓
ExplanationWireshark Explained — The Standard Tool for Packet Capture and Analysis
Wireshark is the world's most widely used network analyzer — it captures packets straight off the wi...
-
✓
ExplanationLFI/RFI Explained — How Local/Remote File Inclusion Works, Attack Techniques, and Defenses
LFI (Local File Inclusion) and RFI (Remote File Inclusion) occur when a web application takes a file...
-
✓
ExplanationHTTP Security Headers — A Second Line of Defense That Tells the Browser How to Defend Itself
HTTP security headers are response headers the server uses to control browser behavior, blocking bro...
-
✓
ExplanationSSRF Explained — How Server-Side Request Forgery Works, Attack Techniques, and Defenses
SSRF (Server-Side Request Forgery) is a vulnerability where the web application's server fetches an...
-
✓
Explanation ▶_ ExerciseNmap Explained — Port Scanning, Service Detection, and OS Fingerprinting
Nmap (Network Mapper) is an open-source scanner for discovering hosts and services on a network. Rel...