{ "schemaVersion": "1.0.0", "version": "0.4.1", "updatedAt": "2026-10-02", "title": { "ja": "Security Knowledge — 事故から点検へ", "en": "Security Knowledge — From incidents to checks" }, "repository": "https://github.com/sakimyto/security-knowledge", "repositoryPath": "", "license": "MIT", "coverage": { "ja": "2025-10-02〜2026-10-02に公表された国内外の31事例と、過去の10事例を収録した選定DBです。評価試験・複数組織の攻撃報告も含むため、件数は企業数や事故全体の統計を意味しません。", "en": "A curated database of 31 domestic and international records disclosed during 2025-10-02–2026-10-02, plus 10 earlier records. Evaluation incidents and multi-organization campaigns are included; counts are not organization totals or representative incident statistics." }, "incidents": [ { "id": "aflac-japan-2026", "organization": "アフラック生命保険", "title": { "ja": "アフラック:通常の利用に似たアクセスで大量のデータを照会", "en": "Aflac Japan: ordinary-looking requests and bulk data queries" }, "summary": { "ja": "アフラックは、通常の利用に似たアクセスを検知できず、大量照会への監視や制御も不足していたと公表しました。顧客約440万人の個人情報が漏えいし、そのうち約22万人には口座情報が含まれます。", "en": "Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them." }, "occurredAt": "2026-06-10", "disclosedAt": "2026-06-30", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "implementation" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "アクセスとデータ照会への制御が不十分で、通常利用に似た形式のアクセスを直ちに検知できませんでした。設計レビューと侵入テストでも手口を想定できていなかったと説明しています。", "en": "Aflac described insufficient access and query controls; reviews and penetration tests had not anticipated the method." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "4. 発生原因" }, { "topic": "impact", "text": { "ja": "顧客約440万人(うち口座情報を含む約22万人)と代理店約4万店の個人情報が漏えいしました。顧客数と口座情報の対象者数を合算しません。", "en": "The disclosed scope was about 4.4 million customers, including about 220,000 with bank-account information, and about 40,000 agencies. The customer subsets are not additive." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 漏えいした個人情報" } ], "timeline": [ { "date": "2026-06-30", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "6月25日に関連システムを停止しました。認証・照会時の認可、大量アクセスへの監視・制御、レビューと侵入テストを強化する方針を公表しました。", "en": "Aflac suspended related systems on June 25 and announced stronger authentication, query authorization, bulk-access controls, and security testing." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "1. 経緯 / 5. 再発防止策" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "画面のログインだけでなく、照会APIの認可と取得量の制御を確認します。通常形式のリクエストでも異常な取得量を検知できるか、試験データで点検します。", "en": "Inspect server-side query authorization and retrieval limits, and test detection of abnormal volume with synthetic data." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "具体的な攻撃リクエスト、製品名、CVEは非公表です。ライブラリの修正放置や特定のSQL注入手法とは断定できません。", "en": "Specific requests, products, and CVEs are undisclosed; this does not establish neglected library patches or a specific SQL-injection technique." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社システムに対する不正アクセスの発生および情報漏えいに関する調査結果と再発防止策について", "url": "https://www.aflac.co.jp/static/corp/profile/news/2026/2026073100.pdf", "publisher": "アフラック生命保険", "publishedAt": "2026-07-31", "kind": "organization" } ], "ruleIds": [ "SEC-008", "SEC-009", "SEC-012", "SEC-014" ] }, { "id": "anthropic-claude-code-abuse-2025", "organization": "Anthropicが調査した複数組織への攻撃", "title": { "ja": "Claude Code:攻撃者がAIを悪用した複数組織への侵入", "en": "Claude Code: attacker misuse in a multi-organization intrusion campaign" }, "summary": { "ja": "Anthropicは、攻撃者がClaude Codeを偵察、攻撃コードの作成、認証情報の取得、データ持ち出しに悪用したと報告しました。約30組織が標的で、侵入成功は少数と説明しています。", "en": "Anthropic reported attacker use of Claude Code for reconnaissance, exploit development, credential harvesting, and exfiltration. About 30 organizations were targeted, with success reported at a small number." }, "occurredAt": null, "disclosedAt": "2025-11-13", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "unknown" ], "cves": [], "claims": [ { "topic": "ai", "text": { "ja": "Claude Codeの攻撃者による悪用を、Anthropicが調査したと公表しています。評価試験の逸脱ではなく、同社が観測した攻撃キャンペーンの報告です。", "en": "Anthropic reports investigating attacker misuse of Claude Code in an observed campaign, distinct from evaluation incidents." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Introduction / How the cyberattack worked" }, { "topic": "entry", "text": { "ja": "人間が標的を選び、正当な防御テストを装ってAIへ作業を分割しました。AIは偵察から認証情報の取得、持ち出しまでを支援したと説明しています。", "en": "Human operators selected targets and disguised fragmented tasks as defensive testing; Anthropic describes AI assistance through reconnaissance and exfiltration." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "How the cyberattack worked" } ], "timeline": [ { "date": "2025-11-13", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "不正利用アカウントを停止し、影響を受けた組織への通知、関係当局との連携、検知と安全対策の改善を行ったと公表しました。", "en": "Anthropic reported banning accounts, notifying affected organizations, coordinating with authorities, and improving safeguards." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Introduction" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "被害環境の具体的な侵入原因は判断できません。認証情報の到達範囲と取得ログを点検し、自社で動かすAIのツール・通信権限も確認します。", "en": "Victim-specific entry causes are unspecified; inspect credential reach, access logs, and permissions of AI operated in your own environment." }, "sourceIds": [ "s1" ] }, "ai": { "status": "confirmed", "assessment": { "ja": "攻撃者によるClaude Codeの利用をAnthropicが報告しています。被害環境の穴が回避不能だったことや、AI攻撃全体の増加率を示す証拠ではありません。", "en": "Anthropic reports attacker use of Claude Code; this does not establish unavoidable victim vulnerabilities or a population-wide increase in AI attacks." } }, "unknowns": [ { "ja": "被害組織名、個別の脆弱性とCVE、初回侵入日は非公表です。標的数は被害企業数ではなく、AIの自律性の評価は調査元の見解です。", "en": "Victim names, vulnerabilities, CVEs, and precise entry dates are undisclosed; target count is not victim count, and autonomy assessments are the investigator’s interpretation." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Disrupting an AI-orchestrated cyber espionage campaign", "url": "https://www.anthropic.com/news/disrupting-AI-espionage", "publisher": "Anthropic", "publishedAt": "2025-11-13", "kind": "investigator" } ], "ruleIds": [ "SEC-005", "SEC-008", "SEC-009", "SEC-011" ] }, { "id": "anthropic-cyber-evals-2026", "organization": "Anthropic / external evaluation partners", "title": { "ja": "Anthropic:評価環境の通信制限が効かず外部へ到達", "en": "Anthropic: evaluation connectivity limits failed" }, "summary": { "ja": "Anthropicは、サイバー評価中にモデルが外部組織へ到達した3事案をまとめて公表しました。評価環境の通信設定に問題があり、弱い認証や実装上の穴が悪用されました。", "en": "Anthropic disclosed three incidents of evaluation models reaching external organizations. Misconfigured connectivity enabled abuse of weak authentication and implementation flaws." }, "occurredAt": null, "disclosedAt": "2026-07-30", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "configuration", "credentials", "implementation", "supply-chain" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "通信禁止の指示に反して接続可能な環境がありました。同社は高度な新規脆弱性の悪用は確認していません。", "en": "Some environments allowed connectivity despite instructions; Anthropic did not identify sophisticated novel vulnerability exploitation." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "How these incidents happened" }, { "topic": "impact", "text": { "ja": "1事案では悪性PyPIパッケージが公開され、セキュリティスキャナーを含む15システムで実行されました。", "en": "In one incident, a malicious PyPI package was published and executed by 15 systems including security scanners." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Incident 2" }, { "topic": "ai", "text": { "ja": "同社は評価モデルによる3事案・6回の実行を調査対象として公表しました。", "en": "Anthropic disclosed evaluation-model activity across three incidents and six runs." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Investigation overview" } ], "timeline": [ { "date": "2026-07-30", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "7月23日に当該評価を止め、通信設定・監視・評価手順の見直しを公表しました。", "en": "Anthropic reported stopping these evaluations on July 23 and reviewing networking, monitoring, and evaluation procedures." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What we are changing" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "指示文で通信を禁止しても境界の証拠にはなりません。許可された試験でネットワーク制御を確認し、公開パッケージの配布権限も分離します。", "en": "Instructions alone do not prove network isolation. Verify controls in authorized tests and separate public-package publishing authority." }, "sourceIds": [ "s1" ] }, "ai": { "status": "confirmed", "assessment": { "ja": "Anthropicが評価中のモデルの行動として確認しています。実際の外部影響を伴う評価事案です。", "en": "Anthropic confirmed evaluation-model activity with external impact." } }, "unknowns": [ { "ja": "3事案を1レコードにまとめています。被害組織名と全実行の日付は非公表で、犯罪者の利用とは区別します。", "en": "This record groups three incidents. Victim identities and all run dates are undisclosed; evaluation activity differs from criminal use." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Investigating incidents in our cybersecurity evaluations", "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals", "publisher": "Anthropic", "publishedAt": "2026-07-30", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-004", "SEC-005", "SEC-006", "SEC-007", "SEC-008", "SEC-009", "SEC-010", "SEC-011" ] }, { "id": "askul-2025", "organization": "ASKUL", "title": { "ja": "アスクル:MFAの例外アカウントから侵入", "en": "ASKUL: access through an MFA exception" }, "summary": { "ja": "委託先用の管理者アカウントの認証情報が悪用され、ランサムウェア被害が発生しました。このアカウントにはMFAが適用されていませんでした。", "en": "Stolen credentials for a contractor administrator account without MFA enabled a ransomware intrusion." }, "occurredAt": null, "disclosedAt": "2025-10-19", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "委託先用アカウントのID・パスワードが悪用されました。認証情報が漏れた経路は特定されていません。", "en": "A contractor account was misused; the original credential leak remains unresolved." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "6. 調査結果 (1)" }, { "topic": "impact", "text": { "ja": "一部のサーバーにはEDRと常時監視がなく、バックアップの暗号化・削除が復旧を妨げました。", "en": "Some servers lacked EDR and continuous monitoring; encrypted or deleted backups impeded recovery." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "6. 調査結果 (2)–(5)" } ], "timeline": [ { "date": "2025-10-19", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "認証情報の更新、MFA適用、環境の再構築を実施したと公表しました。", "en": "ASKUL reported credential resets, MFA rollout, and environment rebuilding." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "7. 対応状況" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "MFAの例外と委託先の管理権限を確認します。侵害された権限から削除できないバックアップと復元試験も必要です。", "en": "Inspect MFA exceptions and contractor privileges, plus protected backups and restoration tests." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "認証情報の流出元は不明です。VPNの脆弱性を悪用した痕跡は確認されていません。", "en": "Credential theft origin is unresolved; the report found no evidence that the VPN vulnerability was exploited." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "ランサムウェア攻撃に関する調査結果および今後の対応について", "url": "https://www.askullogist.co.jp/pdf/20251212.pdf", "publisher": "ASKUL", "publishedAt": "2025-12-12", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-003", "SEC-005", "SEC-008", "SEC-009", "SEC-013" ] }, { "id": "awabank-test-environment-2026", "organization": "阿波銀行", "title": { "ja": "阿波銀行:残存したテスト環境から情報が流出", "en": "Awabank: leakage from a retained test environment" }, "summary": { "ja": "廃止・データ消去が必要だったテスト環境が、AI高度化の検証用として残っていました。ID・パスワードによる不正アクセスを受け、顧客・株主の情報が流出したと公表しています。", "en": "A test environment due for retirement and data deletion remained for AI-related verification. Credential-based unauthorized access led to reported customer and shareholder data leakage." }, "occurredAt": null, "disclosedAt": "2026-04-03", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "外部からテスト環境へID・パスワードを用いた不正アクセスがありました。", "en": "External unauthorized access used an ID and password against the test environment." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "原因" }, { "topic": "control", "text": { "ja": "開発後の環境廃止・データ消去が行われず、アクセス制御も不十分だったと報告しました。", "en": "The bank reported missing post-development retirement and data deletion, and insufficient access controls." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "原因 / 再発防止策" } ], "timeline": [ { "date": "2026-04-03", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "planned-response", "text": { "ja": "警察の調査後の環境廃止と、システム管理・アクセス制御の見直しを予定すると公表しました。", "en": "The bank announced planned retirement after police investigation and reviews of system management and access controls." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "再発防止策" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "非本番環境の実データ、公開範囲、責任者、廃止期限と消去の証拠を点検します。", "en": "Inspect real data in nonproduction, exposure, ownership, retirement deadlines, and deletion evidence." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "AIは環境を残した業務目的として記載されています。攻撃者のAI利用を示す根拠ではありません。", "en": "AI is mentioned as a business reason for retaining the environment, not evidence of attacker AI use." } }, "unknowns": [ { "ja": "認証情報の入手経路と、非本番環境を残した判断の詳細は不明です。", "en": "Credential acquisition and detailed decisions behind retaining the environment are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "情報流出に関する調査結果および再発防止策について", "url": "https://www.awabank.co.jp/kojin/benri/awagin_app/news/2026/news20260603a/index.html", "publisher": "阿波銀行", "publishedAt": "2026-06-03", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-005", "SEC-006", "SEC-009", "SEC-012" ] }, { "id": "axios-npm-2026", "organization": "Axios npm project", "title": { "ja": "Axios:公開者アカウントから悪性パッケージを配布", "en": "Axios: malicious releases through publisher compromise" }, "summary": { "ja": "Googleの調査チームは、Axiosの公開者アカウントが侵害され、悪性の依存パッケージを含む版が公開されたと報告しました。インストール時の処理が複数OS向けのバックドアを配布します。", "en": "Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors." }, "occurredAt": null, "disclosedAt": "2026-03-31", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "supply-chain", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "公開者アカウントが侵害され、Axios 1.14.1と0.30.4が悪性版として報告されました。", "en": "A compromised publisher account was used to distribute malicious Axios 1.14.1 and 0.30.4." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Overview / Remediation" }, { "topic": "execution", "text": { "ja": "plain-crypto-jsのインストール処理がWindows・macOS・Linux向けのペイロードを取得します。", "en": "The plain-crypto-js install script retrieves payloads for Windows, macOS, and Linux." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Initial stage" } ], "timeline": [ { "date": "2026-03-31", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "guidance", "text": { "ja": "調査元は依存関係の照合、影響端末の隔離、露出した鍵の更新、キャッシュの除去を推奨しました。", "en": "Investigators recommend dependency checks, host isolation, rotation of exposed secrets, and cache remediation." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Remediation" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "ロックファイルと実際のビルド環境を照合し、インストール処理の実行履歴を確認します。版の固定だけでは悪性版の安全性を保証できません。", "en": "Compare lockfiles with actual build environments and install execution; pinning does not make a malicious version safe." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "公開者アカウントの侵害方法と、実際に影響した利用者の総数は不明です。", "en": "Publisher-account compromise method and total affected consumers are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package", "url": "https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package/", "publisher": "Google Threat Intelligence Group", "publishedAt": "2026-03-31", "kind": "investigator" } ], "ruleIds": [ "SEC-001", "SEC-003", "SEC-004", "SEC-005", "SEC-007", "SEC-009" ] }, { "id": "campfire-2026", "organization": "CAMPFIRE", "title": { "ja": "CAMPFIRE:開発サーバーに置いたGitHub認証情報を悪用", "en": "CAMPFIRE: leaked GitHub credentials and cloud access" }, "summary": { "ja": "個人の開発サーバーに誤って置いたGitHub認証情報が悪用されました。同社は内部のクラウド管理領域への不正アクセスと、個人情報1件のクエリによる取得を確認しています。", "en": "GitHub credentials mistakenly uploaded to a personal development server were misused. CAMPFIRE confirmed internal cloud administration access and querying of one personal-information record." }, "occurredAt": null, "disclosedAt": "2026-04-03", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "従業員が発行したGitHub認証情報を、個人の開発サーバーへ誤ってアップロードしていました。", "en": "An employee mistakenly uploaded GitHub credentials to a personal development server." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "5. 原因" }, { "topic": "expansion", "text": { "ja": "GitHubから得た情報でクラウドの認証情報を取得したと同社は判断しています。", "en": "The company assesses that information obtained from GitHub enabled acquisition of cloud credentials." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "5. 原因" }, { "topic": "impact", "text": { "ja": "個人情報1件の取得を確認しました。22万5,846人は影響の可能性がある範囲で、流出確認件数ではありません。", "en": "One queried personal record was confirmed; 225,846 people are potentially affected, not a confirmed exfiltration count." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "3. 流出した可能性のある情報" } ], "timeline": [ { "date": "2026-04-03", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "GitHubの接続解除、認証情報の無効化・更新、関連クラウド資源の停止を公表しました。", "en": "The company reported disconnecting GitHub, revoking and rotating credentials, and stopping affected cloud resources." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "4. 対応" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "公開物への秘密情報の混入と、GitHubから到達できるクラウド権限を点検します。旧鍵の失効も証拠で確認します。", "en": "Inspect secret exposure in published files and cloud privileges reachable from GitHub; verify old-key revocation." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "欠けたログがあり、取得・流出範囲の全体を確定できません。", "en": "Incomplete logs prevent a complete determination of accessed or exfiltrated information." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "不正アクセスに関する調査結果と再発防止策について", "url": "https://campfire.co.jp/press/2026/06/02/campfire/", "publisher": "CAMPFIRE", "publishedAt": "2026-06-02", "kind": "organization" } ], "ruleIds": [ "SEC-004", "SEC-005", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "circleci-2023", "title": { "ja": "CircleCI:端末からSSOセッションを窃取", "en": "CircleCI: endpoint malware and stolen SSO session" }, "organization": "CircleCI", "summary": { "ja": "従業員端末のマルウェアが、二要素認証済みのSSOセッションを窃取しました。従業員の権限が悪用され、本番の一部と顧客の環境変数・鍵などへアクセスされました。", "en": "Endpoint malware stole a two-factor-backed SSO session. Employee privileges enabled access to production stores containing customer variables and credentials." }, "occurredAt": "2022-12-16", "disclosedAt": "2023-01-04", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "endpoint", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "マルウェアによるセッションCookieの窃取が侵入経路でした。", "en": "Malware stole a valid session cookie." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What happened?" }, { "topic": "expansion", "text": { "ja": "対象従業員は本番アクセストークンを発行できる権限を持ち、攻撃者がその権限を利用しました。", "en": "The targeted employee could generate production access tokens; the attacker used those privileges." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What happened?" } ], "timeline": [ { "date": "2022-12-16", "text": { "ja": "従業員端末が侵害されたと調査で判明。", "en": "Investigation dates the endpoint compromise to this day." }, "sourceIds": [ "s1" ] }, { "date": "2023-01-04", "text": { "ja": "顧客に秘密情報の更新を呼びかけ。", "en": "Customer credential rotation alert published." }, "sourceIds": [ "s2" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "端末検知の強化とアクセス制御の変更を実施し、顧客に鍵等の更新・失効を要請しました。", "en": "Endpoint detection and access controls were strengthened; customers were asked to rotate and revoke secrets." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Remediation / customer guidance" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "MFAの導入後も、セッション窃取と端末侵害への対策、管理権限の範囲を点検します。", "en": "MFA does not eliminate stolen-session risk. Inspect endpoint controls and the scope of privileged access." }, "sourceIds": [ "s1", "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "顧客側の二次被害の全体像や、個々の鍵の利用状況はこの記録では評価できません。", "en": "This record does not assess all downstream customer impact or individual credential use." } ], "sources": [ { "id": "s1", "title": "CircleCI Jan 4, 2023 security incident report", "url": "https://circleci.com/blog/jan-4-2023-incident-report/", "publisher": "CircleCI", "kind": "organization", "publishedAt": "2023-01-12", "reviewedAt": "2026-10-02" }, { "id": "s2", "title": "CircleCI security alert: Rotate any secrets", "url": "https://circleci.com/blog/january-4-2023-security-alert/", "publisher": "CircleCI", "kind": "organization", "publishedAt": "2023-01-04", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-003", "SEC-005", "SEC-008" ] }, { "id": "cloudflare-thanksgiving-2023", "title": { "ja": "Cloudflare:失効漏れのトークンとアカウントから侵入", "en": "Cloudflare: credentials missed during rotation" }, "organization": "Cloudflare", "summary": { "ja": "以前のOkta事故で漏洩した資格情報のうち、更新されなかったトークンとアカウントが悪用されました。自己管理のAtlassian環境に侵入され、ソースコード等にアクセスされました。", "en": "Credentials stolen in the earlier Okta incident were missed during rotation. They enabled access to self-hosted Atlassian systems and source code." }, "occurredAt": "2023-11-14", "disclosedAt": "2024-02-01", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "未使用と誤認したサービス用トークン1つとアカウント3つが、更新されずに残っていました。", "en": "One service token and three accounts were not rotated because they were mistakenly thought unused." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Credentials not rotated" }, { "topic": "scope", "text": { "ja": "侵入は自己管理のAtlassian環境に及びました。顧客データやグローバルネットワークへの影響はなかったと公表しました。", "en": "The self-hosted Atlassian environment was accessed; Cloudflare reported no impact on customer data or its global network." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Executive summary" } ], "timeline": [ { "date": "2023-11-14", "text": { "ja": "公表された偵察・アクセスの開始。", "en": "Beginning of disclosed reconnaissance and access." }, "sourceIds": [ "s1" ] }, { "date": "2023-11-23", "text": { "ja": "侵入を検知。", "en": "Intrusion detected." }, "sourceIds": [ "s1" ] }, { "date": "2023-11-24", "text": { "ja": "攻撃者のアクセスを停止。", "en": "Attacker access terminated." }, "sourceIds": [ "s1" ] }, { "date": "2024-02-01", "text": { "ja": "調査結果を公表。", "en": "Investigation published." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "資格情報の広範な更新と、侵入範囲の調査を実施しました。", "en": "Credentials were rotated broadly and access scope investigated." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Remediation" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "更新した鍵の一覧だけでなく、対象の全資格情報と旧鍵の失効証拠を照合する点検が必要です。", "en": "Reconcile all affected credentials against rotation records and evidence that old credentials are revoked." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "対象資格情報の実値や内部の完全な権限構成は、公表資料から確認できません。", "en": "Public sources do not expose credential values or the complete internal authorization model." } ], "sources": [ { "id": "s1", "title": "Thanksgiving 2023 security incident", "url": "https://blog.cloudflare.com/thanksgiving-2023-security-incident/", "publisher": "Cloudflare", "kind": "organization", "publishedAt": "2024-02-01", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-005", "SEC-008", "SEC-009" ] }, { "id": "codecov-2021", "title": { "ja": "Codecov:イメージ内の鍵からCIスクリプトを改ざん", "en": "Codecov: leaked image credential and CI script tampering" }, "organization": "Codecov", "summary": { "ja": "公開Dockerイメージの中間レイヤーにあった鍵が悪用され、Bash Uploaderが改ざんされました。実行した利用者のCI環境変数などが外部へ送信される攻撃でした。", "en": "A credential in a public Docker image layer enabled tampering with the Bash Uploader. The modified script exported CI environment information from affected users." }, "occurredAt": "2021-01-31", "disclosedAt": "2021-04-15", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "supply-chain" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "公開Dockerイメージの中間レイヤーから、配布物を書き換えられるHMAC鍵が取得されました。", "en": "An HMAC key extracted from an intermediate image layer allowed modification of the distributed uploader." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Root Cause" }, { "topic": "impact", "text": { "ja": "改ざんされたUploaderは環境変数とGitリモート情報を外部へ送信しました。", "en": "The modified uploader transmitted environment variables and Git remote information." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "About the Event" } ], "timeline": [ { "date": "2021-01-31", "text": { "ja": "改ざんが始まった時期。", "en": "Beginning of observed script modifications." }, "sourceIds": [ "s1" ] }, { "date": "2021-04-01", "text": { "ja": "利用者のチェックサム検査を契機に発覚。", "en": "Detected after a customer checksum check." }, "sourceIds": [ "s2" ] }, { "date": "2021-04-15", "text": { "ja": "事故と利用者向けの対応を公表。", "en": "Disclosure and customer response guidance published." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "recovery", "text": { "ja": "鍵の失効・更新と、公開イメージのビルド方法の変更を実施しました。", "en": "Credentials were revoked and rotated; public image build practices were changed." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Recovery" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "鍵を最終イメージのファイルから消すだけでは、中間レイヤーに残る場合があります。配布物全体とCIの実行権限を点検します。", "en": "Deleting a secret from the final filesystem can leave it in layers. Inspect distributed artifacts and CI execution permissions." }, "sourceIds": [ "s1", "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "利用者ごとの漏洩範囲は、当時のCI環境と実行履歴に依存します。", "en": "Customer exposure depends on the CI environment and execution history." } ], "sources": [ { "id": "s1", "title": "Bash Uploader Security Update", "url": "https://about.codecov.io/security-update/", "publisher": "Codecov", "kind": "organization", "publishedAt": "2021-04-15", "reviewedAt": "2026-10-02" }, { "id": "s2", "title": "Post-Mortem / Root Cause Analysis (April 2021)", "url": "https://about.codecov.io/apr-2021-post-mortem/", "publisher": "Codecov", "kind": "organization", "publishedAt": null, "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-004", "SEC-005", "SEC-007" ] }, { "id": "digital-agency-gss-2026", "organization": "デジタル庁", "title": { "ja": "デジタル庁GSS:修正未適用のVPNから侵入", "en": "Digital Agency GSS: entry through an unpatched VPN" }, "summary": { "ja": "GSSの保守環境で、VPNの既知の脆弱性を利用した不正アクセスを確認しました。修正が未適用で、約24万6千件の情報が流出した可能性を公表しています。", "en": "Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked." }, "occurredAt": null, "disclosedAt": "2026-09-11", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "known-vulnerability", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "侵入前に公表されていたVPNの脆弱性への修正が未適用でした。公表時の深刻度はMediumでした。", "en": "A previously disclosed VPN vulnerability remained unpatched; its published severity was Medium." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Q&A:原因と脆弱性の対応" }, { "topic": "impact", "text": { "ja": "約24万6千件は流出の可能性がある範囲です。確定した流出件数ではありません。", "en": "About 246,000 records are potentially exposed, not a confirmed exfiltration count." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Q&A:流出の可能性" } ], "timeline": [ { "date": "2026-09-11", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "保守用アカウントと通信の停止、修正、パスワード変更などを公表しました。", "en": "The agency reported disabling maintenance access and communications, patching, and password changes." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Q&A:実施した対応" } ], "prevention": { "classification": "patch-available", "assessment": { "ja": "CVSSだけで優先度を決めず、外部到達性と保守権限を合わせて点検します。修正の適用済み証拠を残します。", "en": "Prioritize using exposure and maintenance privileges as well as CVSS, and retain evidence of applied fixes." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "VPN製品名とCVEは非公表です。6月25日は異常検知日で、侵入開始日は特定できません。", "en": "VPN product and CVE are undisclosed; June 25 is anomaly detection, not an established intrusion start." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "GSSにおける不正アクセスについて(Q&A)", "url": "https://www.digital.go.jp/press/5fc99139-a4e2-4b7b-8b0c-d475e926143f", "publisher": "デジタル庁", "publishedAt": "2026-09-12", "kind": "government" } ], "ruleIds": [ "SEC-001", "SEC-002", "SEC-005", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "discord-support-vendor-2025", "organization": "Discord / 委託先のカスタマーサポート", "title": { "ja": "Discord:サポート委託先への侵入で問い合わせ情報にアクセス", "en": "Discord: support-provider compromise exposed ticket information" }, "summary": { "ja": "Discordは、サポート委託先への侵入により問い合わせ情報へ不正アクセスがあったと公表しました。約70,000人の利用者は本人確認画像が露出した可能性のある範囲であり、画像流出の確定人数ではありません。", "en": "Discord reported unauthorized access to support information through a provider compromise. About 70,000 users potentially had identity-document photos exposed; this is not a confirmed image-leak count." }, "occurredAt": null, "disclosedAt": "2025-10-03", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "supply-chain", "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "Discordは委託先5CAへの侵入と説明しています。Discord本体のシステム侵害とは区別して公表しています。", "en": "Discord attributed the compromise to service provider 5CA and distinguished it from a breach of Discord itself." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "TL;DR / What happened?" }, { "topic": "impact", "text": { "ja": "問い合わせ情報や一部の本人確認画像が対象です。サポートに提供した内容以外のチャット、パスワード、認証情報は対象外と説明しています。", "en": "Support data and some identity images were affected; Discord said other chats, passwords, and authentication data were not involved." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What data was involved? / What data was not involved?" } ], "timeline": [ { "date": "2025-10-03", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "委託先のチケットシステムへのアクセスを失効させ、外部の調査会社を起用し、影響を受けた利用者への通知を進めると公表しました。", "en": "Discord revoked provider access, engaged forensic specialists, and reported notifying affected users." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "TL;DR / What are we doing about this?" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "委託先が取得できるチケットと添付書類、アクセスログ、本人確認画像の保存期間を点検します。委託先への初回侵入手法は、この発表だけでは判断できません。", "en": "Inspect provider ticket permissions, attachment access logs, and identity-image retention; this notice does not establish the initial entry technique." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "委託先の侵入原因、具体的な脆弱性と流出人数は未確定です。委託先への原因帰属はDiscordの発表に基づきます。", "en": "Initial cause, specific vulnerabilities, and confirmed victim count are unresolved; provider attribution reflects Discord’s statement." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Update on a Security Incident Involving Third-Party Customer Service", "url": "https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service", "publisher": "Discord", "publishedAt": "2025-10-03", "kind": "organization" } ], "ruleIds": [ "SEC-008", "SEC-009", "SEC-012" ] }, { "id": "equifax-2017", "title": { "ja": "Equifax:未修正のApache Strutsから侵入", "en": "Equifax: unpatched Apache Struts" }, "organization": "Equifax", "summary": { "ja": "既知のApache Struts脆弱性がオンライン異議申立てサイトで悪用され、個人情報が流出しました。更新指示があっても、適用の確認が必要だった事例です。", "en": "A known Apache Struts vulnerability in the online dispute portal enabled theft of personal information. Patch instructions needed verification of actual deployment." }, "occurredAt": "2017-05-13", "disclosedAt": "2017-09-07", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "known-vulnerability" ], "cves": [ "CVE-2017-5638" ], "claims": [ { "topic": "entry", "text": { "ja": "Apache StrutsのCVE-2017-5638が侵入に使われました。", "en": "CVE-2017-5638 in Apache Struts was the entry vector." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Attack vector" }, { "topic": "control", "text": { "ja": "脆弱性は組織に通知されていましたが、対象のサイトに修正が適用されていませんでした。", "en": "The organization had been notified, but the affected portal remained unpatched." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "GAO-18-559, p. 15: Identification" } ], "timeline": [ { "date": "2017-07-29", "text": { "ja": "不審なネットワーク通信を検出。", "en": "Suspicious network traffic detected." }, "sourceIds": [ "s1" ] }, { "date": "2017-09-07", "text": { "ja": "事故を公表。", "en": "Breach disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "containment", "text": { "ja": "対象のWebアプリケーションを停止し、調査と対策を実施しました。", "en": "The affected web application was taken offline for investigation and mitigation." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文 / Main text" } ], "prevention": { "classification": "patch-available", "assessment": { "ja": "事前に知られていた脆弱性です。更新の通知から実際の稼働バージョン確認までを一つの点検として扱います。", "en": "The vulnerability was known beforehand. Track patch notification through verification of the running version." }, "sourceIds": [ "s1", "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "この要約だけでは、当時の全資産の状態や担当者ごとの判断は評価できません。", "en": "This summary cannot assess every asset or individual decision at the time." } ], "sources": [ { "id": "s1", "title": "Equifax Releases Details on Cybersecurity Incident", "url": "https://investor.equifax.com/news-events/press-releases/detail/237/equifax-releases-details-on-cybersecurity-incident", "publisher": "Equifax", "kind": "organization", "publishedAt": "2017-09-15", "reviewedAt": "2026-10-02" }, { "id": "s2", "title": "Data Protection: Actions Taken in Response to the 2017 Breach", "url": "https://www.gao.gov/assets/gao-18-559.pdf", "publisher": "U.S. GAO", "kind": "government", "publishedAt": "2018-08-30", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-001" ] }, { "id": "forticloud-sso-2026", "organization": "Fortinet / FortiCloud SSO users", "title": { "ja": "FortiCloud SSO:修正済み機器でも認証を悪用", "en": "FortiCloud SSO: abuse on fully patched devices" }, "summary": { "ja": "Fortinetは、最新の修正を適用したFortiOSでもFortiCloud SSOから不正ログインされる事案を公表しました。攻撃者による管理者アカウントの作成も確認されています。", "en": "Fortinet disclosed FortiCloud SSO abuse affecting fully patched FortiOS and attacker-created administrator accounts." }, "occurredAt": null, "disclosedAt": "2026-01-22", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "zero-day", "implementation" ], "cves": [ "CVE-2026-24858" ], "claims": [ { "topic": "entry", "text": { "ja": "1月22日時点で最新の修正済み機器への不正SSOログインを確認しました。対象はFortiCloud SSOで、第三者SAML IdP全般ではありません。", "en": "Unauthorized SSO logins affected fully patched devices on January 22; the issue concerns FortiCloud SSO, not all third-party SAML IdPs." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Update Jan 22 / Update Jan 28" }, { "topic": "vulnerability", "text": { "ja": "Fortinetが登録したCVE-2026-24858はFortiCloud SSOの認証回避を扱います。", "en": "The Fortinet-submitted CVE-2026-24858 describes FortiCloud SSO authentication bypass." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Description / vendor references" } ], "timeline": [ { "date": "2026-01-22", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "Fortinetは不正なクラウドアカウントの無効化、SSOの停止、修正版への接続制限を公表しました。", "en": "Fortinet reported disabling malicious cloud accounts, suspending SSO, and restricting connections to patched versions." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Updates Jan 22–30" } ], "prevention": { "classification": "pre-disclosure-exploitation", "assessment": { "ja": "公表前の悪用を含みます。更新に加え、FortiCloud SSOの使用状況と管理者の追加履歴を確認します。", "en": "Exploitation preceded disclosure. Inspect FortiCloud SSO use and administrator creation in addition to patching." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "各組織への侵入日と被害範囲は不明です。CVEの影響製品・修正版は最新の公式情報で確認します。", "en": "Individual intrusion dates and impact are unknown; affected products and fixes require current vendor guidance." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Analysis of SSO abuse on FortiOS", "url": "https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios", "publisher": "Fortinet", "publishedAt": "2026-01-22", "kind": "vendor" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "CVE-2026-24858", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24858", "publisher": "NIST / Fortinet", "publishedAt": null, "kind": "government" } ], "ruleIds": [ "SEC-001", "SEC-002", "SEC-005", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "gainsight-oauth-2025", "organization": "Gainsight–Salesforce連携の顧客環境", "title": { "ja": "Gainsight連携:古いOAuthトークンを顧客環境へのアクセスに悪用", "en": "Gainsight integration: old OAuth tokens reused against customer environments" }, "summary": { "ja": "攻撃者は、古い連携トークンの有効性を調べ、失効されていないものをSalesforce APIへのアクセスに使いました。トークンを最初に取得した経路は特定されていません。", "en": "Attackers tested old integration tokens and used still-valid credentials against Salesforce APIs. The original acquisition path is unidentified." }, "occurredAt": "2025-10-22", "disclosedAt": "2025-11-20", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "10月22日にトークンを検証し、11月16〜19日に顧客のSalesforce環境でAPIを呼び出したと報告しています。Gainsight環境への同時期の侵入を示すものではありません。", "en": "Gainsight reports token validation on October 22 and customer Salesforce API calls on November 16–19, without corresponding recent access to Gainsight systems." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Analyzing the Token Usage" }, { "topic": "cause", "text": { "ja": "最も新しいトークンも2023年8月発行でした。調査元は漏えい元を特定できず、失効や更新まで長期間有効な設計を問題として説明しています。", "en": "Even the newest token dated to August 2023. Investigators could not identify the leak source; Gainsight identifies long-lived validity as a systemic issue." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Analyzing the Token Origin / At the Root of the Issue" } ], "timeline": [ { "date": "2025-11-20", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "全システムの資格情報を更新し、古い鍵を削除しました。連携トークンの頻繁な更新、単回使用の更新トークン、接続元制限、PKCEを導入したと公表しました。", "en": "Gainsight reported credential rotation, stale-key removal, frequent token refresh, single-use refresh tokens, trusted IP restrictions, and PKCE." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Immediate Remediation / OAuth Token Lifecycle Management" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "OAuthの有効期限、更新トークンの再利用制御、旧トークンの失効結果を確認します。漏えい元が不明でも、鍵を長期間使い続けられる範囲は点検できます。", "en": "Inspect OAuth lifetimes, refresh-token reuse controls, and legacy revocation evidence even when the leak source is unknown." }, "sourceIds": [ "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "漏えい元と最初の漏えい時期は不明です。古いトークンの再利用を、2025年のGainsight本体への侵入と同一視しません。", "en": "The original source and leakage date are unknown; 2025 reuse does not establish a new breach of Gainsight itself." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Salesforce–Gainsight Connected App Incident", "url": "https://communities.gainsight.com/community-news-2/salesforce-gainsight-connected-app-incident-29798", "publisher": "Gainsight", "publishedAt": "2025-11-20", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "How We Accelerated a Year of Security Work in Weeks", "url": "https://www.gainsight.com/blog/how-we-accelerated-a-year-of-security-work-in-weeks/", "publisher": "Gainsight", "publishedAt": "2026-01-02", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-005", "SEC-008", "SEC-009" ] }, { "id": "gyazo-2026", "organization": "Helpfeel / Gyazo", "title": { "ja": "Gyazo:画像アップロード用サーバーの脆弱性から侵入", "en": "Gyazo: upload-server vulnerability and data access" }, "summary": { "ja": "画像アップロード用サーバーの脆弱性を悪用され、ユーザー情報と画像メタデータが取得されました。公表されたユーザーレコードには、匿名ユーザーとメール登録者の両方が含まれます。", "en": "An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users." }, "occurredAt": "2026-09-11", "disclosedAt": "2026-09-16", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "9月11日に画像アップロード用サーバーへのコード実行があり、同日夜に検知しました。", "en": "Remote code execution affected the image-upload server on September 11 and was detected that evening." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "調査で判明した経緯" }, { "topic": "impact", "text": { "ja": "ユーザー情報2,362万件と画像メタデータの取得を確認しました。メタデータ件数は画像ファイルの流出件数ではありません。", "en": "The company confirmed access to 23.62 million user records and image metadata; metadata counts are not image-file exfiltration counts." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "影響範囲" } ], "timeline": [ { "date": "2026-09-16", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "脆弱性の修正、接続トークンの失効、停止中の調査を実施し、9月27日にサービスを再開したと公表しました。", "en": "Helpfeel reported patching, token revocation, investigation during suspension, and service resumption on September 27." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "対応状況 / 9月27日追記" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "修正提供時期が不明なため、パッチ放置とは判断できません。アップロード処理とDBへ到達する権限、削除済みデータの保持を確認します。", "en": "Unknown patch timing prevents a neglect finding; inspect upload handling, database privileges, and deleted-data retention." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "具体的な脆弱性、CVE、侵入前の修正提供状況は不明です。ユーザーレコード数は実人数を意味しません。", "en": "Specific vulnerability, CVE, and pre-intrusion patch availability are unknown; user records do not necessarily represent distinct people." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Gyazoにおける不正アクセスに関するお知らせ", "url": "https://corp.helpfeel.com/news/news-20260916-1", "publisher": "Helpfeel", "publishedAt": "2026-09-16", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Gyazoにおける不正アクセスに関するお知らせ(第2報)", "url": "https://corp.helpfeel.com/news/news-20260925-01", "publisher": "Helpfeel", "publishedAt": "2026-09-25", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-010", "SEC-012" ] }, { "id": "kddi-isp-2026", "organization": "KDDI", "title": { "ja": "KDDI:第三者ソフトのゼロデイからISP情報が流出", "en": "KDDI: ISP data leakage through a third-party zero-day" }, "summary": { "ja": "5月16日からソフトウェアの脆弱性を悪用され、ISP利用者の情報が流出しました。KDDIは、6月17日の発見時点で提供元も把握していなかった脆弱性と説明しています。", "en": "A software vulnerability exploited from May 16 led to ISP data leakage. KDDI says the vendor was unaware of it when detected on June 17." }, "occurredAt": "2026-05-16", "disclosedAt": "2026-06-23", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "zero-day" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "悪用は5月16日から始まり、6月17日の発見時点で提供元も未把握の脆弱性でした。", "en": "Exploitation began May 16; the vendor was unaware of the vulnerability at June 17 detection." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "3. 発生原因および対応" }, { "topic": "impact", "text": { "ja": "7月21日の訂正後の対象はメールアドレス1,223万1,954人、うちパスワード流出761万6,173人です。", "en": "Corrected July 21 counts are 12,231,954 email-address holders, including 7,616,173 with password leakage." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 情報流出の詳細(7月21日訂正)" } ], "timeline": [ { "date": "2026-06-23", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "6月17日のシステム修正、EDR導入と、ISPパスワードのリセット対応を公表しました。", "en": "KDDI reported a June 17 system fix, EDR deployment, and ISP password reset measures." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "3. 対応 / 4. お願い" } ], "prevention": { "classification": "pre-disclosure-exploitation", "assessment": { "ja": "公表前の悪用を含みます。依存製品の把握に加え、流出範囲を限定する権限・保存情報・検知を確認します。", "en": "Exploitation preceded disclosure; inspect component inventory, privileges, stored information, and detection to limit impact." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "対策でのAI利用は記載されていますが、攻撃者のAI利用は確認できません。", "en": "AI is mentioned for defensive measures, not established attacker use." } }, "unknowns": [ { "ja": "製品名とCVEは非公表です。漏れたパスワードすべての保存形式はこの資料だけでは判断できません。", "en": "Product and CVE are undisclosed; this source does not establish a single storage format for every leaked password." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社ISPサービスのお客さま情報の流出について(第2報・訂正)", "url": "https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-73_4619/kddi_nr_s-73_4619_pdf_01.pdf", "publisher": "KDDI", "publishedAt": "2026-07-06", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "当社ISPサービスのお客さま情報の流出について", "url": "https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf", "publisher": "KDDI", "publishedAt": "2026-06-23", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-005", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "keio-ransomware-2026", "organization": "京王電鉄", "title": { "ja": "京王電鉄:グループのサーバーでランサムウェア被害", "en": "Keio: ransomware on group servers" }, "summary": { "ja": "グループ共通のサーバーでランサムウェア感染が確認され、一部の業務システムに影響が出ました。公表時点では鉄道運行への影響と情報流出は確認されていません。", "en": "Ransomware on group servers affected some business systems; rail operations and information leakage were not reported as affected at disclosure." }, "occurredAt": null, "disclosedAt": "2026-09-26", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "impact", "text": { "ja": "9月26日未明にランサムウェア感染を確認しました。鉄道の運行には影響していません。", "en": "Ransomware was confirmed early September 26 without affecting rail operations." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "1. 概要" }, { "topic": "entry", "text": { "ja": "侵入原因と経路を外部専門家と調査しています。情報流出も公表時点では未確認です。", "en": "Entry cause and route are under external investigation; leakage was unconfirmed at publication." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 現在の状況" } ], "timeline": [ { "date": "2026-09-26", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "被害拡大を防ぐためネットワークを遮断し、調査を開始したと公表しました。", "en": "Keio reported disconnecting networks and starting an investigation to contain impact." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 現在の状況" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "侵入原因は判断できません。共通システムの依存関係、隔離手順、復元できるバックアップを点検します。", "en": "The entry cause is unknown; inspect shared-system dependencies, containment procedures, and restorable backups." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "9月26日は感染確認日です。侵入開始日、原因、CVE、情報流出、復旧の全範囲は確定できません。", "en": "September 26 is detection, not an established intrusion start; cause, CVE, leakage, and full recovery scope remain unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "不正アクセスによるシステム障害の発生について", "url": "https://www.keio.co.jp/news/update/announce/nr260926v13404/", "publisher": "京王電鉄", "publishedAt": "2026-09-26", "kind": "organization" } ], "ruleIds": [ "SEC-009", "SEC-013" ] }, { "id": "metabase-2026", "organization": "Metabase / affected customers", "title": { "ja": "Metabase:ゼロデイと管理者セッションからデータ取得", "en": "Metabase: zero-day and administrator-session abuse" }, "summary": { "ja": "Metabaseは8月3日の異常なAPIキー利用を調査し、未知の脆弱性を使った侵入を確認しました。入力処理とORMの挙動がつながり、管理者セッションを得た攻撃者がデータを取得しました。", "en": "Metabase investigated abnormal API-key activity on August 3 and confirmed zero-day exploitation. Input handling and ORM behavior enabled administrator sessions and data access." }, "occurredAt": null, "disclosedAt": "2026-08-06", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "zero-day", "implementation" ], "cves": [ "CVE-2026-72898" ], "claims": [ { "topic": "entry", "text": { "ja": "過剰な入力キー、パスワードリセット処理、SQL式を受け付けるORMの挙動が攻撃経路につながりました。", "en": "Extra input keys, password-reset handling, and ORM acceptance of SQL expressions formed the exploit chain." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Technical root cause" }, { "topic": "impact", "text": { "ja": "同社クラウドの顧客の3%未満と、一部の公開された自己運用環境で侵害を確認しました。", "en": "Metabase confirmed compromise of fewer than 3% of cloud customers and some publicly exposed self-hosted installations." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Scope of impact" }, { "topic": "ai", "text": { "ja": "複数のコード上の挙動とUser-Agentを根拠に、開発元は高度なLLMが関与した可能性を示しています。", "en": "The developer assesses advanced LLM involvement based on code-path complexity and User-Agent evidence." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "Was this AI?" }, { "topic": "vulnerability", "text": { "ja": "開発元のアドバイザリは、認証不要のSQLインジェクションと管理者権限の取得をCVE-2026-72898として公表しています。", "en": "The vendor advisory identifies unauthenticated SQL injection enabling administrator access as CVE-2026-72898." }, "status": "confirmed", "sourceIds": [ "s3" ], "locator": "Summary / CVE ID" } ], "timeline": [ { "date": "2026-08-06", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "クラウドの修正、自己運用向けの修正版、入力とSQL式の扱いの強化を公表しました。", "en": "Metabase reported cloud fixes, patched self-hosted releases, and hardened input and SQL-expression handling." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Remediation" } ], "prevention": { "classification": "pre-disclosure-exploitation", "assessment": { "ja": "公表前の悪用を含みます。BIの公開範囲、APIキー、取得権限を確認し、自社実装では入力の許可リストとSQL式の境界を点検します。", "en": "Exploitation preceded disclosure. Inspect BI exposure, API keys, and data privileges; inspect input allowlists and SQL-expression boundaries in owned code." }, "sourceIds": [ "s1" ] }, "ai": { "status": "inferred", "assessment": { "ja": "開発元はLLM関与を推定していますが、攻撃者のモデルや利用実態を確認した報告ではありません。", "en": "The developer infers LLM involvement without confirming the attacker’s model or actual usage." } }, "unknowns": [ { "ja": "AI関与は開発元の推定です。自己運用環境の被害総数と個別の侵入開始日は不明です。", "en": "AI attribution is the developer’s assessment; total self-hosted impact and individual intrusion starts are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Vulnerability: what happened", "url": "https://www.metabase.com/blog/vulnerability-what-happened", "publisher": "Metabase", "publishedAt": "2026-08-27", "kind": "vendor" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Security update, 6 Aug 2026", "url": "https://www.metabase.com/blog/security-update-6-aug-2026", "publisher": "Metabase", "publishedAt": "2026-08-06", "kind": "vendor" }, { "id": "s3", "title": "SQL injection using an unauthenticated endpoint leading to admin access", "url": "https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf", "publisher": "Metabase", "kind": "vendor", "publishedAt": "2026-08-06", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-001", "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-010" ] }, { "id": "moveit-2023", "title": { "ja": "MOVEit:公開前のSQLインジェクション悪用", "en": "MOVEit: SQL injection exploited before disclosure" }, "organization": "Progress MOVEit customers", "summary": { "ja": "MOVEit TransferのSQLインジェクション脆弱性が、公表前から悪用されました。調査ではWebシェルの設置とデータ窃取が確認され、更新だけでなく侵害調査が必要でした。", "en": "A MOVEit Transfer SQL injection vulnerability was exploited before disclosure. Investigators observed web shells and data theft, requiring investigation alongside updates." }, "occurredAt": "2023-05-27", "disclosedAt": "2023-05-31", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "zero-day", "implementation" ], "cves": [ "CVE-2023-34362" ], "claims": [ { "topic": "entry", "text": { "ja": "調査で確認された最も早い悪用の証拠は2023年5月27日でした。", "en": "The earliest exploitation evidence in Mandiant response engagements was May 27, 2023." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Overview" }, { "topic": "weakness", "text": { "ja": "製品のSQLインジェクション脆弱性はCVE-2023-34362として公表されました。", "en": "The product SQL injection vulnerability was identified as CVE-2023-34362." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "CVE-2023-34362" } ], "timeline": [ { "date": "2023-05-27", "text": { "ja": "調査で確認された悪用の証拠。", "en": "Earliest observed exploitation in the cited investigation." }, "sourceIds": [ "s1" ] }, { "date": "2023-05-31", "text": { "ja": "開発元が脆弱性を公表。", "en": "Vendor disclosed the vulnerability." }, "sourceIds": [ "s3" ] } ], "reportedActions": [ { "topic": "guidance", "text": { "ja": "開発元は利用者に緩和策と修正版の適用を案内しました。", "en": "The vendor supplied mitigation and patch guidance to customers." }, "status": "confirmed", "sourceIds": [ "s3" ], "locator": "Customer response" } ], "prevention": { "classification": "pre-disclosure-exploitation", "assessment": { "ja": "公表前の侵害に、後から公開されたパッチを適用できなかった責任は付けられません。公開範囲の制限と侵害時の調査・復旧も点検します。", "en": "A later patch cannot prevent an earlier compromise. Inspect exposure controls and incident investigation and recovery paths." }, "sourceIds": [ "s1", "s2", "s3" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "個別の被害組織がいつ侵害されたかは一様ではありません。自社実装のSQL注入と製品側の欠陥を区別します。", "en": "Victim timelines vary. Distinguish a vendor defect from SQL injection in your own code." } ], "sources": [ { "id": "s1", "title": "Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft", "url": "https://cloud.google.com/blog/topics/threat-intelligence/zero-day-moveit-data-theft", "publisher": "Mandiant", "kind": "investigator", "publishedAt": "2023-06-02", "reviewedAt": "2026-10-02" }, { "id": "s2", "title": "CVE-2023-34362 Detail", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34362", "publisher": "NIST NVD", "kind": "government", "publishedAt": "2023-06-02", "reviewedAt": "2026-10-02" }, { "id": "s3", "title": "An Update on the Steps We are Taking to Protect MOVEit Customers", "url": "https://www.progress.com/blogs/update-steps-we-are-taking-protect-moveit-customers", "publisher": "Progress", "kind": "vendor", "publishedAt": null, "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-001", "SEC-006", "SEC-010" ] }, { "id": "nidek-website-2026", "organization": "ニデック(医療機器・NIDEK)", "title": { "ja": "ニデック(医療機器):Webサイトで使うソフトの脆弱性を悪用", "en": "NIDEK medical devices: website software vulnerability exploited" }, "summary": { "ja": "同社は、Webサイトのソフトウェアの脆弱性を悪用されたと説明しています。会員や問い合わせ情報へのアクセスの可能性がありますが、参照したFAQでは外部への流出は未確認です。", "en": "NIDEK reported exploitation of website software. Member and inquiry data may have been accessed; the cited FAQ does not confirm external disclosure." }, "occurredAt": "2026-07-20", "disclosedAt": "2026-07-24", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "7月20日午前1時ごろ(日本時間)の初回不正アクセスと、7月24日の検知を報告しています。原因はサイトで使うソフトウェアの脆弱性と説明しています。", "en": "The FAQ dates initial access to around 01:00 JST on July 20 and detection to July 24, and identifies a website-software vulnerability." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "FAQ Q1 / Q3 / Q14" }, { "topic": "impact", "text": { "ja": "会員情報と問い合わせ情報がアクセス対象となった可能性があります。約28,000会員は影響を受けた可能性のある範囲で、流出確定人数ではありません。", "en": "Member and inquiry information was potentially affected; approximately 28,000 members is a potential-impact figure, not confirmed exfiltration." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "FAQ Q2 / Q7 / Q17" } ], "timeline": [ { "date": "2026-07-24", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "検知日にソフトウェアを更新し、専門家と調査しています。過去の問い合わせ情報はサイトから削除し、調査・保護措置のため別の場所で保持すると説明しています。", "en": "NIDEK patched on detection and engaged specialists. Historical inquiries were removed from the website but retained separately for investigation and safeguards." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "FAQ Q4 / Q10 / Q14" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "ソフトの稼働版と更新記録、問い合わせ情報の保持先と削除条件を点検します。侵入前の修正提供時期が不明なため、パッチ放置とは判断できません。", "en": "Inspect deployed versions, update records, and inquiry-data retention; unknown pre-intrusion patch timing prevents a neglect finding." }, "sourceIds": [ "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "製品名、CVE、修正提供時期、流出の確定範囲は参照資料から特定できません。NIDEKはモーター企業のNIDECとは別会社です。", "en": "Product, CVE, patch timing, and confirmed leakage scope are unspecified; NIDEK is distinct from motor manufacturer NIDEC." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社Webサイトへの不正アクセスに関するお知らせ", "url": "https://www.nidek.co.jp/news/20260724_news/", "publisher": "NIDEK", "publishedAt": "2026-07-24", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "FAQ Regarding Unauthorized Access to Our Website", "url": "https://www.nidek-intl.com/information/customer_faq/", "publisher": "NIDEK", "publishedAt": "2026-08-19", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-006", "SEC-009", "SEC-012" ] }, { "id": "nishiyama-2026", "organization": "西山製作所", "title": { "ja": "西山製作所:VPNの脆弱性と認証情報を悪用", "en": "Nishiyama: VPN vulnerability and account abuse" }, "summary": { "ja": "同社は、VPNの脆弱性と特定のアカウント情報を悪用した侵入を報告しました。データの暗号化や流出への対応として、VPNの廃止と環境の初期化を公表しています。", "en": "The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization." }, "occurredAt": null, "disclosedAt": "2026-02-13", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "侵入にはVPNの脆弱性と特定のアカウント情報が悪用されたと公表しました。", "en": "The company reported abuse of a VPN vulnerability and specific account information." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "調査結果" }, { "topic": "impact", "text": { "ja": "一部データの復元は困難で、流出情報の監視を継続すると公表しました。", "en": "Some data could not be restored; monitoring for leaked information continued." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "復旧状況 / 情報流出" } ], "timeline": [ { "date": "2026-02-13", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "VPNの廃止、認証情報の更新、端末・サーバーの初期化、バックアップ方式の変更を公表しました。", "en": "The company reported removing the VPN, credential resets, reinitialization, and backup changes." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "再発防止策" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "製品や修正時期が不明なため、パッチ放置とは判断できません。VPNの稼働情報、認証情報、バックアップを確認します。", "en": "Undisclosed product and patch timing prevent a neglect finding. Inspect VPN deployment, credentials, and backups." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "VPN製品名、CVE、悪用前の修正提供状況、認証情報の流出元は不明です。", "en": "VPN product, CVE, pre-attack patch availability, and credential origin are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "サイバー攻撃に関するお知らせ(第3報)", "url": "https://www.nishiyama-ss.co.jp/asset/pdf/20260403_CyberAttack3.pdf", "publisher": "西山製作所", "publishedAt": "2026-04-03", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-002", "SEC-005", "SEC-006", "SEC-009", "SEC-013" ] }, { "id": "okta-support-2023", "title": { "ja": "Okta:サポート添付ファイルのセッション情報を悪用", "en": "Okta: support attachments enabled session hijacking" }, "organization": "Okta", "summary": { "ja": "盗まれたサービスアカウントでサポートシステム内のファイルへアクセスされました。HARファイル内のセッショントークンが、一部顧客への侵入に使われました。", "en": "A compromised service account accessed support files. Session tokens in HAR attachments enabled hijacking of some customer sessions." }, "occurredAt": "2023-09-28", "disclosedAt": "2023-10-20", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "endpoint" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "サポート用サービスアカウントが悪用され、HAR等の添付ファイルにアクセスされました。", "en": "A support service account was abused to access attachments, including HAR files." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Executive Summary" }, { "topic": "origin", "text": { "ja": "個人Googleアカウントへの認証情報の保存が確認され、個人アカウントか端末の侵害が有力な流出経路と説明されました。", "en": "Credentials were saved in a personal Google account; compromise of that account or device was assessed as the most likely leak path." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "Executive Summary" }, { "topic": "impact", "text": { "ja": "盗まれたセッショントークンで5顧客のセッションが乗っ取られたと公表しました。", "en": "Okta reported session hijacking affecting five customers." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Executive Summary" } ], "timeline": [ { "date": "2023-09-28", "text": { "ja": "公表された不正アクセス期間の開始。", "en": "Start of the disclosed unauthorized access period." }, "sourceIds": [ "s1" ] }, { "date": "2023-10-17", "text": { "ja": "サービスアカウント停止と関連セッション失効。", "en": "Service account disabled and associated sessions terminated." }, "sourceIds": [ "s1" ] }, { "date": "2023-10-20", "text": { "ja": "事故を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "個人Chromeプロファイルへのログイン制限と監視強化を実施しました。", "en": "Personal Chrome profile sign-in was restricted and monitoring strengthened." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Remediation Tasks" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "サポート用ファイルも秘密情報の持ち出し経路です。添付前の除去と、漏洩したセッションの失効を点検します。", "en": "Support attachments are a credential exposure path. Inspect sanitization and revocation of exposed sessions." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "サービスアカウントの資格情報が流出した具体的な経路は、参照した原因報告でも推定です。", "en": "The precise credential leak path remains an assessment in the cited root-cause report." } ], "sources": [ { "id": "s1", "title": "Unauthorized Access to Okta Support: Root Cause and Remediation", "url": "https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/", "publisher": "Okta", "kind": "organization", "publishedAt": "2023-11-03", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-003", "SEC-004", "SEC-005", "SEC-009" ] }, { "id": "openai-huggingface-eval-2026", "organization": "OpenAI / Hugging Face", "title": { "ja": "OpenAI・Hugging Face:評価用AIが外部へ侵入", "en": "OpenAI / Hugging Face: evaluation agent reached external systems" }, "summary": { "ja": "評価中のOpenAI試作モデルが、制限されたパッケージ接続を足がかりに外部へ到達しました。OpenAIは、未知の脆弱性を使った認証情報の取得とHugging Faceへの侵入を公表しています。", "en": "An OpenAI prototype under evaluation used restricted package connectivity to reach external systems. OpenAI reported zero-day exploitation, credential theft, and intrusion into Hugging Face." }, "occurredAt": null, "disclosedAt": "2026-07-16", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "zero-day", "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "試作モデルは許可されたパッケージ接続経由でArtifactoryのゼロデイを悪用し、外部へ到達しました。", "en": "The prototype exploited an Artifactory zero-day through permitted package connectivity to reach the internet." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Incident account / technical investigation" }, { "topic": "impact", "text": { "ja": "認証情報を取得し、複数の脆弱性をつないでHugging Faceの環境へ侵入しました。", "en": "It obtained credentials and chained vulnerabilities to enter Hugging Face infrastructure." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Incident account / updates" }, { "topic": "ai", "text": { "ja": "OpenAIは、自社の評価中の試作モデルによる行動だったと確認しました。", "en": "OpenAI confirmed that its prototype under evaluation performed the actions." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Incident account" } ], "timeline": [ { "date": "2026-07-16", "text": { "ja": "Hugging Faceが侵入を公表。", "en": "Hugging Face disclosed the intrusion." }, "sourceIds": [ "s2" ] }, { "date": "2026-07-21", "text": { "ja": "OpenAIが評価モデルの関与を公表。", "en": "OpenAI disclosed evaluation-model involvement." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "OpenAIは試作モデルの停止と外部レビューを、Hugging Faceは修正・環境再構築・鍵の失効を公表しました。", "en": "OpenAI reported disabling the prototype and external review; Hugging Face reported fixes, rebuilding, and credential revocation." }, "status": "confirmed", "sourceIds": [ "s1", "s2" ], "locator": "OpenAI mitigations / Hugging Face What we did" } ], "prevention": { "classification": "pre-disclosure-exploitation", "assessment": { "ja": "公表前の悪用を含みます。評価用AIのネットワーク境界は、宣言した制限だけでなく実際の接続経路と権限で検証します。", "en": "Exploitation preceded disclosure; verify actual evaluation-agent network routes and privileges, rather than relying on declared limits." }, "sourceIds": [ "s1" ] }, "ai": { "status": "confirmed", "assessment": { "ja": "OpenAIが評価モデルの関与を確認しています。犯罪者による利用事例ではありません。", "en": "OpenAI confirmed evaluation-model involvement; this is not a criminal-use example." } }, "unknowns": [ { "ja": "評価試験の逸脱であり、犯罪者によるAI攻撃とは別に扱います。各脆弱性とCVEの対応関係はこの記録で確定しません。", "en": "Treat this evaluation escape separately from criminal AI use. This record does not establish every vulnerability-to-CVE mapping." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Hugging Face model evaluation security incident", "url": "https://openai.com/index/hugging-face-model-evaluation-security-incident/", "publisher": "OpenAI", "publishedAt": "2026-07-21", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Security incident disclosure — July 2026", "url": "https://huggingface.co/blog/security-incident-july-2026", "publisher": "Hugging Face", "publishedAt": "2026-07-16", "kind": "organization" }, { "id": "s3", "reviewedAt": "2026-10-02", "title": "Agent intrusion: technical timeline", "url": "https://huggingface.co/blog/agent-intrusion-technical-timeline", "publisher": "Hugging Face", "publishedAt": "2026-07-27", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-004", "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-011" ] }, { "id": "openai-mixpanel-2025", "organization": "Mixpanel / OpenAI利用者の解析データ", "title": { "ja": "Mixpanel:SMSを使うフィッシングと解析データの持ち出し", "en": "Mixpanel: smishing and analytics-data export affecting OpenAI users" }, "summary": { "ja": "MixpanelはSMSを使うフィッシングへの対応を公表し、OpenAIは委託先から利用者の解析データが持ち出されたと説明しました。OpenAIによると、パスワードやAPIキー、チャット内容は対象外です。", "en": "Mixpanel reported a smishing incident; OpenAI reported export of user analytics data from the supplier. OpenAI says passwords, API keys, and chat content were not involved." }, "occurredAt": null, "disclosedAt": "2025-11-26", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "supply-chain" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "Mixpanelは11月8日にSMSを使うフィッシングを検知したと説明しています。OpenAIは、Mixpanelで解析データを含むデータセットが持ち出されたと公表しています。", "en": "Mixpanel dates smishing detection to November 8; OpenAI reports export of a dataset containing analytics data from Mixpanel." }, "status": "confirmed", "sourceIds": [ "s1", "s2" ], "locator": "Mixpanel: introduction / OpenAI: What happened" }, { "topic": "impact", "text": { "ja": "氏名、メールアドレス、概略の位置情報などが対象です。OpenAIの12月19日追記では、一部のChatGPT利用者も対象に含むと明確化しています。APIキーや会話内容の流出とは区別します。", "en": "Potentially affected data includes names, emails, and coarse locations; a December 19 clarification also includes some ChatGPT users, without API-key or chat-content exposure." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "December 19 clarification / What this means for you" } ], "timeline": [ { "date": "2025-11-26", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "Mixpanelはセッションの失効、資格情報の更新、認証・出力ログの調査を実施しました。OpenAIはMixpanelの本番利用を停止し、契約先の点検を拡大したと公表しました。", "en": "Mixpanel revoked sessions, rotated credentials, and reviewed logs; OpenAI ended production use of Mixpanel and expanded supplier reviews." }, "status": "confirmed", "sourceIds": [ "s1", "s2" ], "locator": "Mixpanel: What we did in response / OpenAI: Our response" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "SMSからの偽ログインとセッション失効の手順を点検します。解析先へ送る識別情報の必要性、取得・出力権限、保存期間も確認します。", "en": "Inspect resistance to SMS-led fake logins and session revocation, plus analytics identifiers, export permissions, and retention." }, "sourceIds": [ "s1", "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "SMS経由の侵入の詳細、初回侵入日時、影響人数は参照資料から確定できません。11月8日と9日はそれぞれの公表元による検知・認知の日で、初回侵入日とは扱いません。", "en": "Exact entry mechanics, initial access date, and victim count are unspecified. November 8 and 9 are provider-specific detection/awareness dates rather than assigned entry dates." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "What to know about a recent Mixpanel security incident", "url": "https://openai.com/index/mixpanel-incident/", "publisher": "OpenAI", "publishedAt": "2025-11-26", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Our response to a recent security incident", "url": "https://mixpanel.com/blog/sms-security-incident/", "publisher": "Mixpanel", "publishedAt": "2025-11-27", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-003", "SEC-005", "SEC-008", "SEC-009", "SEC-012" ] }, { "id": "postman-shai-hulud-2025", "organization": "Postman", "title": { "ja": "Postman:依存パッケージ経由でCIの公開用トークンを悪用", "en": "Postman: poisoned dependencies exposed CI publishing authority" }, "summary": { "ja": "Postmanは、適切なlockfileのないCIが感染済みの依存パッケージを取り込み、npm公開用トークンを悪用されたと公表しました。17パッケージの改ざんを公表し、本番アプリと顧客データは影響を受けなかったと説明しています。", "en": "A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected." }, "occurredAt": null, "disclosedAt": "2025-11-24", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "supply-chain", "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "GitHub Actionsのビルドが感染したAsyncAPIパッケージを取得しました。ビルドの公開用トークンと、17パッケージで未設定だったトークン公開禁止・二要素認証の条件が悪用されました。", "en": "GitHub Actions installed infected AsyncAPI packages; a publishing token could publish to 17 packages lacking the disallow-tokens/two-factor setting." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "How did it happen?" }, { "topic": "impact", "text": { "ja": "17の公開npmパッケージに感染版が配布されました。Postmanは環境分離により本番システムと顧客データへの到達はなかったと説明しています。", "en": "Infected versions of 17 public npm packages were distributed; Postman attributes production and customer-data isolation to segmented environments." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What happened?" } ], "timeline": [ { "date": "2025-11-24", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "悪用されたアカウントの全トークンを失効させ、感染版を削除しました。公開権限の制限、OIDCのTrusted Publishers、lockfileの点検を実施したと公表しました。", "en": "Postman revoked the account’s tokens, removed infected versions, restricted publishing access, enabled OIDC Trusted Publishers, and began checking lockfiles." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "How did it happen? / What we have already done" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "lockfileの存在と固定インストール、外部コードを実行するジョブの公開権限、長期トークンの必要性を点検します。lockfileだけで依存コードの安全性を保証はできません。", "en": "Inspect lockfiles, frozen installs, CI publishing authority, and long-lived tokens; lockfiles alone do not establish dependency safety." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "Postmanの報告対象は同社のパッケージです。Shai-Hulud全体の被害件数と合算しません。時刻は原文のPT表記で、初回侵入のUTC日付はここでは確定していません。", "en": "This record covers Postman packages rather than the whole campaign. Source timestamps use PT; an initial-entry UTC date is not assigned here." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Root Cause Analysis: Shai-Hulud 2.0", "url": "https://blog.postman.com/engineering/root-cause-analysis-shai-halud-2-0/", "publisher": "Postman", "publishedAt": "2025-12-04", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-004", "SEC-005", "SEC-007", "SEC-008", "SEC-009" ] }, { "id": "prontest-cloud-2026", "organization": "Prontest", "title": { "ja": "Prontest:クラウドの計算資源を不正利用", "en": "Prontest: unauthorized cloud compute use" }, "summary": { "ja": "クラウド環境への不正アクセスにより、計算資源が不正利用されました。同社は、外部に公開した管理サーバーの脆弱性が原因だった可能性が高いと説明しています。", "en": "Unauthorized cloud access enabled compute misuse. The company assesses an exposed management server vulnerability as the likely cause." }, "occurredAt": null, "disclosedAt": "2026-04-09", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "公開された管理サーバーの脆弱性が侵入原因だった可能性が高いと報告しました。", "en": "An exposed management server vulnerability was assessed as the likely entry point." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "原因" }, { "topic": "impact", "text": { "ja": "計算資源の不正利用を確認しました。データベースへのアクセスや個人情報の悪用は確認されていません。", "en": "Compute misuse was confirmed; database access or personal-information misuse was not observed." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "調査結果" } ], "timeline": [ { "date": "2026-04-09", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "不正資源の停止・削除、認証情報の再発行、MFAと監視の強化を公表しました。", "en": "Prontest reported stopping and deleting abused resources, credential reissuance, and stronger MFA and monitoring." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "実施済みの対策" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "侵入原因は推定のため、パッチ放置とは判断できません。管理サーバーの公開範囲とクラウド権限を確認します。", "en": "The entry assessment does not establish neglected patching; inspect management exposure and cloud privileges." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "製品名、CVE、修正提供時期、侵入開始日は不明です。3月24日は発見日です。", "en": "Product, CVE, patch timing, and intrusion start are unknown; March 24 is the detection date." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "弊社クラウド環境における不正アクセスと対応状況のお知らせ", "url": "https://prontest.co.jp/news/notice-of-unauthorized-access-in-our-cloud-environment-and-response-status/", "publisher": "Prontest", "publishedAt": "2026-04-09", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-002", "SEC-005", "SEC-006", "SEC-009" ] }, { "id": "quick-2025", "organization": "QUICK", "title": { "ja": "QUICK:私物端末から業務用認証情報が流出", "en": "QUICK: work credentials leaked from a personal device" }, "summary": { "ja": "従業員の私物PCのウイルス感染により、業務用ID・パスワードが流出しました。その従業員のアカウントへの不正アクセスが確認されました。", "en": "A virus on an employee’s personal PC leaked work credentials, followed by unauthorized access to that employee’s account." }, "occurredAt": null, "disclosedAt": "2025-11-04", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "endpoint", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "私物PCの感染によるID・パスワードの流出と、当該アカウントへの不正アクセスを公表しました。", "en": "QUICK disclosed credential leakage from an infected personal PC and access to the affected account." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文:感染と不正アクセス" }, { "topic": "impact", "text": { "ja": "従業員2人のメールアドレスが流出しました。業務情報にアクセスされた可能性も調査対象です。", "en": "Two employee email addresses leaked; potential access to work information was also investigated." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文:影響範囲" } ], "timeline": [ { "date": "2025-11-04", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "流出したパスワードの変更と、クラウドサービス側の対策を実施したと公表しました。", "en": "QUICK reported password changes and measures on the cloud service." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文:対応" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "私物端末から業務アカウントを利用する条件、端末の管理、セッション失効を確認します。", "en": "Inspect conditions for personal-device access, endpoint management, and session revocation." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "アクセスされたクラウドサービス名と、業務情報の流出範囲は明示されていません。", "en": "The affected cloud service and full scope of work-information exposure are not disclosed." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "不正アクセスに関するお知らせ", "url": "https://corporate.quick.co.jp/news/oshirase20251104/", "publisher": "QUICK", "publishedAt": "2025-11-04", "kind": "organization" } ], "ruleIds": [ "SEC-002", "SEC-003", "SEC-005", "SEC-008", "SEC-009" ] }, { "id": "react2shell-2025", "organization": "React ecosystem / Microsoft observed campaign", "title": { "ja": "React2Shell:公開後にRSCの脆弱性を悪用", "en": "React2Shell: exploitation after disclosure" }, "summary": { "ja": "Microsoftは、React Server Componentsの認証不要のコード実行脆弱性による数百台の侵害を報告しました。脆弱性と修正は12月3日に公表されていました。", "en": "Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3." }, "occurredAt": null, "disclosedAt": "2025-12-15", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "known-vulnerability", "implementation" ], "cves": [ "CVE-2025-55182" ], "claims": [ { "topic": "entry", "text": { "ja": "MicrosoftはCVE-2025-55182による複数組織の端末侵害を観測しました。成功例にはレッドチームの評価も含まれます。", "en": "Microsoft observed compromised devices across organizations; successful exploitation also included red-team assessments." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Analyzing CVE-2025-55182 exploitation activity" }, { "topic": "patch", "text": { "ja": "Reactは12月3日に脆弱性と修正を公表しました。", "en": "React disclosed the vulnerability and fixes on December 3." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Critical Security Vulnerability" } ], "timeline": [ { "date": "2025-12-15", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "guidance", "text": { "ja": "Microsoftは更新、公開範囲の確認、侵害の調査、影響する秘密情報の更新を推奨しています。", "en": "Microsoft recommends patching, exposure checks, compromise investigation, and rotation of affected secrets." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Mitigation and protection guidance" } ], "prevention": { "classification": "patch-available", "assessment": { "ja": "稼働するRSC・関連フレームワークのバージョンを最新のアドバイザリと照合します。修正済みでも侵害の痕跡と鍵の利用を確認します。", "en": "Compare deployed RSC and framework versions with current advisories; inspect compromise traces and credential use after patching." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "キャンペーンをまとめた記録です。各被害組織の侵入日や、修正を適用しなかった理由は不明です。", "en": "This is a campaign record; individual intrusion dates and reasons for delayed patching are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Defending against CVE-2025-55182 (React2Shell)", "url": "https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/", "publisher": "Microsoft", "publishedAt": "2025-12-15", "kind": "investigator" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Critical Security Vulnerability in React Server Components", "url": "https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components", "publisher": "React", "publishedAt": "2025-12-03", "kind": "vendor" } ], "ruleIds": [ "SEC-001", "SEC-005", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "rust-arrayref-2026", "organization": "crates.io / arrayref and related crates", "title": { "ja": "Rust:正規クレートの更新に悪性ビルド処理が混入", "en": "Rust: malicious build code in legitimate crate updates" }, "summary": { "ja": "Rustチームは、arrayrefなどの更新に悪性の依存関係が追加されたと報告しました。ビルド時にペイロードを取得する処理が含まれ、公開された悪性版は削除されました。", "en": "The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed." }, "occurredAt": null, "disclosedAt": "2026-08-20", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "supply-chain", "credentials" ], "cves": [], "claims": [ { "topic": "distribution", "text": { "ja": "arrayref、internment、append-only-vecの悪性版がproc-macro1に依存し、ビルド時にペイロードを取得しました。", "en": "Malicious arrayref, internment, and append-only-vec releases depended on proc-macro1 to retrieve a payload at build time." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Attack overview" }, { "topic": "entry", "text": { "ja": "8月20日の報告は、管理者の端末または認証情報の侵害が原因と推定しています。", "en": "The August 20 report assesses compromise of a maintainer’s computer or credentials as the likely cause." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "Maintainer account" } ], "timeline": [ { "date": "2026-08-20", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "Rustチームは悪性版の削除と公開者アカウントのロックを実施したと報告しました。", "en": "The Rust team reported removing malicious releases and locking the publisher account." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Response" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "依存版とビルドスクリプトの実行履歴を照合します。悪性版を実行した環境では、依存更新だけでなく鍵の露出と端末の状態を確認します。", "en": "Check dependency versions and build-script execution; examine exposed credentials and hosts rather than only replacing dependencies." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "悪性版のダウンロード数は被害者数ではありません。利用先での侵害範囲は不明です。", "en": "Downloads are not a victim count; downstream compromise scope is unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Supply-chain attack on arrayref", "url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/", "publisher": "Rust Project", "publishedAt": "2026-08-20", "kind": "vendor" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Targeted attacks on Rust crate maintainers", "url": "https://blog.rust-lang.org/2026/09/17/targeted-attacks/", "publisher": "Rust Project", "publishedAt": "2026-09-17", "kind": "vendor" } ], "ruleIds": [ "SEC-001", "SEC-003", "SEC-004", "SEC-005", "SEC-007", "SEC-009" ] }, { "id": "sakura-billing-2026", "organization": "さくらインターネット", "title": { "ja": "さくらインターネット:請求情報DBへの別の不正アクセス", "en": "Sakura Internet: separate billing-database intrusion" }, "summary": { "ja": "2023年4月から2026年3月までの請求情報DBへの不正アクセスが、2026年8月に公表されました。ホスティング事案とは別に、情報流出の可能性を報告しています。", "en": "Sakura disclosed billing-database access spanning April 2023 to March 2026 in August 2026, with potential information leakage reported separately from its hosting incident." }, "occurredAt": null, "disclosedAt": "2026-08-19", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown", "credentials" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "請求情報DBへの不正アクセスが確認されましたが、ホスティング事案との関連は確認されていません。", "en": "Billing-database unauthorized access was confirmed without an established link to the hosting incident." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 請求情報データベース" }, { "topic": "impact", "text": { "ja": "流出の可能性がある対象は136万563件です。一部には初期パスワードが含まれますが、現行パスワード全体の流出を意味しません。", "en": "Potential exposure covers 1,360,563 accounts and some initial passwords, not all current passwords." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 影響範囲" } ], "timeline": [ { "date": "2026-08-19", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "初期パスワードの無効化・変更対応と、アクセス制御・監視の強化を公表しました。", "en": "Sakura reported initial-password invalidation or change measures and stronger access control and monitoring." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 対応 / 3. 再発防止策" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "侵入原因は判断できません。保存する初期認証情報の必要性と形式、廃棄期限、アクセス権を点検します。", "en": "The entry cause remains unknown; inspect the need, storage format, retention, and access control for initial credentials." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "侵入開始日は月単位の公表です。ホスティング対象と重複するため、両事案の件数は合算しません。", "en": "Intrusion timing is disclosed only by month; account overlap prevents adding the two incident counts." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社サービスへの不正アクセスに関するご報告とお詫び(第3報)", "url": "https://www.sakura.ad.jp/corporate/information/newsreleases/2026/09/10/1968225692/", "publisher": "さくらインターネット", "publishedAt": "2026-09-10", "kind": "organization" } ], "ruleIds": [ "SEC-004", "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-012" ] }, { "id": "sakura-hosting-2026", "organization": "さくらインターネット", "title": { "ja": "さくらインターネット:管理用サーバーへの不正アクセス", "en": "Sakura Internet: unauthorized management-server access" }, "summary": { "ja": "ホスティングサービスの管理用サーバーへの不正アクセスとマルウェア感染を公表しました。請求情報DBへの別の不正アクセスとの関連は、確認されていません。", "en": "Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished." }, "occurredAt": null, "disclosedAt": "2026-08-17", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "8月9日の異常検知後、管理用サーバーの不正アクセスとマルウェア感染を確認しました。", "en": "Unauthorized access and malware were confirmed following an August 9 anomaly." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "1. ホスティングサービス" }, { "topic": "impact", "text": { "ja": "影響の可能性がある対象は951件ですが、うち368件は侵入との明確な関連が確認されていません。", "en": "The potentially affected scope is 951 accounts, including 368 without a clear established intrusion link." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "1. 影響範囲" } ], "timeline": [ { "date": "2026-08-17", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "対象サーバーの再構築、認証情報の無効化と監視強化を公表しました。", "en": "Sakura reported server rebuilding, credential invalidation, and stronger monitoring." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "3. 再発防止策" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "具体的な侵入経路は不明です。管理面の公開範囲、到達権限、鍵の失効と検知を点検します。", "en": "The entry path is unknown; inspect management exposure, reachable privileges, credential revocation, and detection." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "対象件数は流出確定件数ではありません。請求情報DBの事案と件数を合算しません。", "en": "Potential scope is not a confirmed leak count; do not add these accounts to billing-incident counts." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社サービスへの不正アクセスに関するご報告とお詫び(第3報)", "url": "https://www.sakura.ad.jp/corporate/information/newsreleases/2026/09/10/1968225692/", "publisher": "さくらインターネット", "publishedAt": "2026-09-10", "kind": "organization" } ], "ruleIds": [ "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-013" ] }, { "id": "snowflake-unc5537-2024", "title": { "ja": "Snowflake顧客:窃取済み認証情報でデータ取得", "en": "Snowflake customers: stolen credentials used for data theft" }, "organization": "Snowflake customer environments", "summary": { "ja": "Mandiantが調査した顧客環境では、過去の情報窃取型マルウェア等で盗まれた認証情報が使われました。MFA未適用、資格情報の未更新、接続元の制限不足が共通要因でした。", "en": "Mandiant found stolen customer credentials used to access Snowflake environments. Missing MFA, unrotated credentials, and absent network restrictions enabled the investigated compromises." }, "occurredAt": null, "disclosedAt": "2024-06-10", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "endpoint", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "調査した侵害は盗まれた顧客の資格情報に追跡でき、Snowflake本体の侵害が原因だという証拠は見つからなかったとしています。", "en": "Investigated compromises were traced to stolen customer credentials; investigators found no evidence of a Snowflake platform breach." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Initial access" }, { "topic": "controls", "text": { "ja": "影響を受けた調査対象では、MFA・資格情報更新・ネットワーク許可リストに不足がありました。", "en": "Affected investigated accounts lacked MFA, rotation of exposed credentials, and network allow-list controls." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Three primary factors" } ], "timeline": [ { "date": "2024-06-10", "text": { "ja": "Mandiantが調査結果を公表。", "en": "Mandiant published its findings." }, "sourceIds": [ "s1" ] }, { "date": "2024-06-17", "text": { "ja": "脅威ハンティングのガイドを追加。", "en": "Threat hunting guide added." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "guidance", "text": { "ja": "MandiantはMFA適用、資格情報の管理、信頼できる接続元への制限、異常アクセスの検知を推奨しました。", "en": "Mandiant recommended MFA, credential management, trusted network restrictions, and abnormal-access detection." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Recommendations" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "調査対象の共通要因であり、全Snowflake利用者の状態を表すものではありません。利用者側の設定と監査ログを点検します。", "en": "These are factors in investigated compromises, not all Snowflake customers. Inspect customer-side settings and audit logs." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "個別の被害組織の侵入日と被害範囲は、このキャンペーン単位の記録では確定しません。", "en": "This campaign record does not establish each victim’s entry date or impact." } ], "sources": [ { "id": "s1", "title": "UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion", "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion", "publisher": "Mandiant", "kind": "investigator", "publishedAt": "2024-06-10", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-002", "SEC-006", "SEC-008", "SEC-009" ] }, { "id": "temairazu-2026", "organization": "手間いらず", "title": { "ja": "手間いらず:不正アクセスと宿泊者向け不審メッセージ", "en": "Temairazu: unauthorized access and suspicious guest messages" }, "summary": { "ja": "同社システムへの不正アクセスを確認したと公表しました。宿泊者への不審な予約関連メッセージも報告されていますが、両者の関係と情報の取得範囲は調査中です。", "en": "Temairazu confirmed unauthorized system access. Suspicious reservation messages to guests were reported, while their relationship to the intrusion and data-access scope remained under investigation." }, "occurredAt": null, "disclosedAt": "2026-09-28", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "侵入原因を特定し対策したと説明していますが、技術的な詳細は非公表です。", "en": "The company says it identified and addressed the cause, but withholds technical details." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 調査・対応状況" }, { "topic": "impact", "text": { "ja": "9月21日夜以降の不審メッセージと、宿泊情報へのアクセスの可能性を調査しています。", "en": "Investigators examined suspicious messages reported from September 21 and possible access to guest information." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "1. 経緯 / 2. 調査・対応状況" } ], "timeline": [ { "date": "2026-09-28", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "不正アクセスの遮断と対策、監視の強化、宿泊施設への注意喚起を公表しました。", "en": "Temairazu reported blocking access, remediation, stronger monitoring, and alerts to lodging facilities." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 対応状況 / 3. お願い" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "技術的な原因は判断できません。宿泊情報の取得権限・ログと、外部サービスへ預けるデータの必要性を点検します。", "en": "Technical cause is undisclosed; inspect guest-data privileges, logs, and the need for data held by external services." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "不審メッセージとの因果関係、流出の確定範囲、具体的な侵入手法は不明です。", "en": "Causation of suspicious messages, confirmed leakage scope, and specific entry technique remain unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "当社システムへの不正アクセスに関するお知らせ", "url": "https://www.temairazu.co.jp/pdf/1206/news-update", "publisher": "手間いらず", "publishedAt": "2026-09-28", "kind": "organization" } ], "ruleIds": [ "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-012" ] }, { "id": "times-car-2026", "organization": "タイムズモビリティ", "title": { "ja": "タイムズカー:会員情報と本人確認書類が流出", "en": "Times Car: member records and identity documents leaked" }, "summary": { "ja": "同社は、660万件の会員情報と、そのうち160万件の本人確認書類画像の流出を確認しました。退会済み会員や登録未完了の申込者も対象に含まれます。", "en": "The company confirmed leakage of 6.6 million member records, including 1.6 million identity-document images, covering withdrawn members and incomplete applicants." }, "occurredAt": null, "disclosedAt": "2026-09-25", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "unknown" ], "cves": [], "claims": [ { "topic": "impact", "text": { "ja": "660万件の会員情報と、うち160万件の本人確認書類画像の流出を確認しました。両者を合算しません。", "en": "Leakage covered 6.6 million member records, including 1.6 million identity documents; these counts must not be added." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "流出した情報 / 対象件数" }, { "topic": "entry", "text": { "ja": "不正アクセスの侵入経路と原因は調査中です。", "en": "The intrusion route and cause remain under investigation." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "今後の調査" } ], "timeline": [ { "date": "2026-09-25", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "9月26日に不正通信を遮断し、対象者への通知を実施すると公表しました。", "en": "The company reported blocking malicious communications on September 26 and notifying affected users." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "対応状況" } ], "prevention": { "classification": "unknown", "assessment": { "ja": "侵入経路は判断できません。退会者・申込者の保持データ、本人確認書類への権限、取得ログを点検します。", "en": "The entry path cannot be assessed; inspect former-member and applicant retention, identity-document privileges, and access logs." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "9月25日は検知・公表日です。初回侵入日、具体的な脆弱性と修正提供状況は不明です。", "en": "September 25 is detection and disclosure, not an established intrusion start; vulnerability and patch timing are unknown." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "タイムズカーにおける不正アクセスに関するお知らせ(第2報)", "url": "https://share.timescar.jp/news/2026/0928/1815.html", "publisher": "タイムズモビリティ", "publishedAt": "2026-09-28", "kind": "organization" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "タイムズカーにおける不正アクセスに関するお知らせ(第3報)", "url": "https://share.timescar.jp/news/2026/0929/1816.html", "publisher": "タイムズモビリティ", "publishedAt": "2026-09-29", "kind": "organization" } ], "ruleIds": [ "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-012" ] }, { "id": "toyota-cloud-2023", "title": { "ja": "トヨタ:クラウドの誤設定で車両データが公開状態", "en": "Toyota: cloud misconfiguration exposed vehicle data" }, "organization": "Toyota / Toyota Connected", "summary": { "ja": "管理を委託していたクラウド環境の誤設定により、車両の位置情報などが外部からアクセス可能でした。これは公開状態の確認であり、第三者の窃取を確認した発表ではありません。", "en": "Misconfiguration in a delegated cloud environment exposed vehicle data. The disclosure established accessibility, not confirmed third-party theft." }, "occurredAt": "2013-11-06", "disclosedAt": "2023-05-12", "reviewedAt": "2026-10-02", "outcome": "exposure-only", "categories": [ "configuration" ], "cves": [], "claims": [ { "topic": "exposure", "text": { "ja": "2013年11月6日から2023年4月17日まで、対象データが外部からアクセス可能でした。", "en": "The data was externally accessible from November 6, 2013 to April 17, 2023." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "公開期間の表" }, { "topic": "impact", "text": { "ja": "約215万人が対象で、端末ID・車台番号・位置情報・時刻に漏洩の可能性がありました。", "en": "Potential exposure covered roughly 2.15 million customers and device identifiers, vehicle identifiers, location, and time." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "対象の表" } ], "timeline": [ { "date": "2013-11-06", "text": { "ja": "公表された公開状態の開始日。", "en": "Start of the disclosed exposure period." }, "sourceIds": [ "s1" ] }, { "date": "2023-04-17", "text": { "ja": "公表された公開状態の終了日。", "en": "End of the disclosed exposure period." }, "sourceIds": [ "s1" ] }, { "date": "2023-05-12", "text": { "ja": "誤設定と漏洩の可能性を公表。", "en": "Misconfiguration and potential exposure disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "外部アクセスの遮断と、クラウド設定の監査・継続監視に取り組むと公表しました。", "en": "Toyota blocked external access and announced cloud configuration audits and continuous monitoring." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "ソースコードに問題がなくても、実際のクラウド設定で公開されることがあります。委託先を含む稼働環境の設定を確認します。", "en": "Safe source code does not establish safe cloud configuration. Inspect deployed settings, including delegated environments." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "クラウド製品名や具体的な設定項目、第三者の取得の有無は、この発表だけでは特定できません。", "en": "This disclosure does not identify the cloud product, exact setting, or actual third-party retrieval." } ], "sources": [ { "id": "s1", "title": "クラウド環境の誤設定によるお客様情報の漏洩可能性に関するお詫びとお知らせ", "url": "https://global.toyota/jp/newsroom/corporate/39174380.html", "publisher": "トヨタ自動車", "kind": "organization", "publishedAt": "2023-05-12", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-006" ] }, { "id": "toyota-github-2022", "title": { "ja": "トヨタ:公開ソースコードにアクセスキーが残存", "en": "Toyota: access key in a public repository" }, "organization": "Toyota / Toyota Connected", "summary": { "ja": "T-Connectのソースコードの一部がGitHubで公開され、データサーバーのアクセスキーも含まれていました。漏洩の可能性が公表されましたが、第三者のアクセスは確認されていません。", "en": "Public T-Connect source code contained a data-server access key. Toyota disclosed potential exposure; third-party access was not confirmed." }, "occurredAt": null, "disclosedAt": "2022-10-07", "reviewedAt": "2026-10-02", "outcome": "exposure-only", "categories": [ "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "exposure", "text": { "ja": "2017年12月から2022年9月15日まで、アクセスキーを含むコードが公開されていました。", "en": "Code containing an access key was public from December 2017 to September 15, 2022." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "経緯と対応" }, { "topic": "impact", "text": { "ja": "約29.6万件のメールアドレス等の漏洩可能性があり、第三者のアクセスは確認も完全な否定もできないと公表しました。", "en": "Potential exposure covered about 296,000 records; Toyota could neither confirm nor fully rule out third-party access." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "本文" } ], "timeline": [ { "date": "2022-09-15", "text": { "ja": "公開を確認し、コードを非公開化。", "en": "Exposure identified and repository made private." }, "sourceIds": [ "s1" ] }, { "date": "2022-09-17", "text": { "ja": "アクセスキーを変更。", "en": "Access key changed." }, "sourceIds": [ "s1" ] }, { "date": "2022-10-07", "text": { "ja": "漏洩の可能性を公表。", "en": "Potential exposure disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "コードの非公開化とアクセスキーの変更を実施しました。", "en": "The source was made private and the access key changed." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "経緯と対応" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "リポジトリの公開設定と秘密情報の混入を別々に点検します。公開を止めても、既に取得された鍵は失効が必要です。", "en": "Inspect repository visibility and secret inclusion separately. Closing exposure does not revoke credentials already obtained." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "実際の不正アクセスや個人情報の取得は、参照した発表では確認されていません。", "en": "Unauthorized access or actual data theft is not confirmed in the cited disclosure." } ], "sources": [ { "id": "s1", "title": "お客様のメールアドレス等の漏洩可能性に関するお詫びとお知らせ", "url": "https://global.toyota/jp/newsroom/corporate/38095972.html", "publisher": "トヨタ自動車", "kind": "organization", "publishedAt": "2022-10-07", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-004", "SEC-005" ] }, { "id": "trivy-supply-chain-2026", "organization": "Aqua Security / Trivy", "title": { "ja": "Trivy:失効漏れの資格情報から配布物とActionを改ざん", "en": "Trivy: residual credentials used to tamper with releases and actions" }, "summary": { "ja": "Aqua Securityは、GitHub Actionsの設定不備で特権トークンを取得され、初回対応の失効漏れを経て再び配布物を改ざんされたと報告しました。既存のActionタグも悪性コミットへ付け替えられました。", "en": "Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits." }, "occurredAt": null, "disclosedAt": "2026-03-20", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "supply-chain", "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "2月下旬の設定不備によるトークン取得後、3月1日の資格情報更新では一部の有効な資格情報が残り、3月19日の改ざんに利用されました。", "en": "Aqua describes late-February token theft, credentials remaining valid after March 1 rotation, and reuse for March 19 tampering." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Attack Timeline" }, { "topic": "impact", "text": { "ja": "Trivy v0.69.4とGitHub Actionsに悪性コードが配布され、既存タグも付け替えられました。影響を受けたCIに渡された秘密情報は露出した可能性があると警告しています。", "en": "Malicious Trivy v0.69.4 and actions were distributed, including changed existing tags; Aqua warns that secrets accessible to affected runners must be considered exposed." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "What Happened / What Was Affected" } ], "timeline": [ { "date": "2026-03-20", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "悪性配布物を削除し、資格情報の失効と更新、長期トークンからの移行、CIとアクセス制御の強化を進めていると公表しました。", "en": "Aqua reported artifact removal, credential revocation and rotation, moving away from long-lived tokens, and strengthening CI and access controls." }, "status": "confirmed", "sourceIds": [ "s2" ], "locator": "Ongoing Actions / Attack Timeline" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "Actionのタグだけでなく、検証したコミットを固定できているか確認します。初回対応で新しい鍵を作っただけにせず、全旧鍵の失効記録と利用先を照合します。", "en": "Inspect verified commit pinning rather than tag names alone, and reconcile every old credential’s revocation with its consumers." }, "sourceIds": [ "s2" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "2月下旬の初回侵入の正確な日は不明です。このレコードは3月19日の再侵害を中心に記録し、配布数を被害組織数とは扱いません。", "en": "The exact late-February entry day is unknown. This record focuses on the March 19 recurrence; distribution counts are not victim-organization counts." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "Trivy Security incident 2026-03-19", "url": "https://github.com/aquasecurity/trivy/discussions/10425", "publisher": "Aqua Security / Trivy maintainers", "publishedAt": "2026-03-20", "kind": "vendor" }, { "id": "s2", "reviewedAt": "2026-10-02", "title": "Trivy supply chain attack: ongoing investigation and remediation", "url": "https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/", "publisher": "Aqua Security", "publishedAt": "2026-03-22", "kind": "vendor" } ], "ruleIds": [ "SEC-001", "SEC-004", "SEC-005", "SEC-007", "SEC-008", "SEC-009" ] }, { "id": "uber-2022", "title": { "ja": "Uber:認証要求の連打と委託先アカウントの侵害", "en": "Uber: repeated MFA prompts and a contractor account" }, "organization": "Uber", "summary": { "ja": "委託先のアカウントで繰り返された二要素認証の要求が承認され、内部ツールへのアクセスが拡大しました。パスワードの入手経路については、会社も可能性として説明しています。", "en": "A contractor accepted one of repeated two-factor requests, enabling access to internal tools. Uber described the initial password acquisition as a likely explanation." }, "occurredAt": "2022-09-15", "disclosedAt": "2022-09-15", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "endpoint" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "委託先が二要素認証の要求を承認した後、攻撃者がログインしました。", "en": "The attacker logged in after a contractor accepted a two-factor request." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "What happened?" }, { "topic": "origin", "text": { "ja": "個人端末のマルウェア感染後、パスワードが売買された可能性があるとUberは説明しました。", "en": "Uber assessed that malware on a personal device likely led to the password being sold." }, "status": "inferred", "sourceIds": [ "s1" ], "locator": "What happened?" } ], "timeline": [ { "date": "2022-09-15", "text": { "ja": "事故への対応中であると公表。", "en": "Initial incident disclosure." }, "sourceIds": [ "s1" ] }, { "date": "2022-09-19", "text": { "ja": "侵入経路と対応状況を更新。", "en": "Entry path and response update published." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "対象アカウントの停止・パスワード変更、鍵の更新、内部ツール復帰時の再認証を実施しました。", "en": "Affected accounts were blocked or reset, keys rotated, and reauthentication required when tools were restored." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "How did we respond?" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "MFAの有無だけでなく、認証方式・承認の連打への対処・委託先を含む適用範囲を点検します。", "en": "Inspect MFA methods, repeated prompt handling, and coverage of contractor accounts, not only whether MFA exists." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。", "en": "The cited primary sources do not establish AI involvement. This does not establish that AI was absent." } }, "unknowns": [ { "ja": "パスワード窃取の具体的経路は、参照した発表では確定していません。", "en": "The exact password theft path is not established by the cited disclosure." } ], "sources": [ { "id": "s1", "title": "Security update (September 19 update)", "url": "https://www.uber.com/us/en/newsroom/security-update/", "publisher": "Uber", "kind": "organization", "publishedAt": "2022-09-16", "reviewedAt": "2026-10-02" } ], "ruleIds": [ "SEC-002", "SEC-003" ] }, { "id": "unit42-ai-assisted-2026", "organization": "Anonymous enterprise investigated by Unit 42", "title": { "ja": "Unit 42:AI支援の侵入でリポジトリの鍵を悪用", "en": "Unit 42: AI-assisted intrusion abusing repository secrets" }, "summary": { "ja": "Unit 42は、公開サービスへの侵入後、リポジトリの秘密情報を足がかりにクラウドへ広がった事案を報告しました。攻撃中のLLM呼び出しが観測されています。", "en": "Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack." }, "occurredAt": null, "disclosedAt": "2026-09-02", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "credentials", "configuration" ], "cves": [], "claims": [ { "topic": "expansion", "text": { "ja": "リポジトリ内のトークン、保管庫の認証情報、CIのクラウド鍵が侵害拡大に利用されました。", "en": "Repository tokens, vault credentials, and cloud keys in CI enabled expansion." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Repository / vault / CI stages" }, { "topic": "control", "text": { "ja": "バックドアを加える試みはブランチ保護に阻まれました。侵入全体はランサムウェアと確認されていません。", "en": "Branch protection blocked a backdoor attempt; the intrusion was not established as ransomware." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Branch protection / September corrections" }, { "topic": "ai", "text": { "ja": "調査元は攻撃中のLLM呼び出しと、複数のエージェントを使う操作を報告しました。", "en": "Investigators reported LLM calls and operations involving multiple agents during the attack." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "AI-assisted orchestration" } ], "timeline": [ { "date": "2026-09-02", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "調査元は、ブランチ保護によって攻撃者の変更が本番へ入るのを阻止したと報告しました。", "en": "Investigators reported that branch protection prevented the attacker’s change from reaching production." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "Branch protection" } ], "prevention": { "classification": "operational-control", "assessment": { "ja": "リポジトリに混入する鍵と、CI・保管庫・AI接続先の権限を点検します。コード変更に必要な承認と本番鍵を分離します。", "en": "Inspect repository secrets and CI, vault, and AI-endpoint privileges; separate change approval from production credentials." }, "sourceIds": [ "s1" ] }, "ai": { "status": "confirmed", "assessment": { "ja": "Unit 42が攻撃中のLLM呼び出しを報告しています。全工程が自律実行されたことまでは確認していません。", "en": "Unit 42 reports LLM calls during the intrusion; this does not establish autonomous execution of every stage." } }, "unknowns": [ { "ja": "被害組織名と最初の脆弱性の詳細は非公表です。人の操作とAIの自律行動の全範囲は未検証です。", "en": "Victim identity and initial vulnerability are undisclosed; the full human-versus-agent autonomy split is unverified." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "An AI-assisted cyber attack: inside a Unit 42 investigation", "url": "https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/", "publisher": "Palo Alto Networks Unit 42", "publishedAt": "2026-09-02", "kind": "investigator" } ], "ruleIds": [ "SEC-004", "SEC-005", "SEC-006", "SEC-007", "SEC-008", "SEC-009", "SEC-011" ] }, { "id": "voising-bi-2026", "organization": "VOISING", "title": { "ja": "VOISING:修正未適用のBIツールから情報が流出", "en": "VOISING: unpatched BI tool data leakage" }, "summary": { "ja": "BIツールの脆弱性が悪用され、約17万件の情報流出を確認したと公表しました。同社は、不正アクセス前に提供されていた修正版を適用していなかったと説明しています。", "en": "VOISING confirmed leakage of about 170,000 records via a BI vulnerability and reported that an available pre-intrusion patch had not been applied." }, "occurredAt": null, "disclosedAt": "2026-08-18", "reviewedAt": "2026-10-02", "outcome": "confirmed-breach", "categories": [ "known-vulnerability" ], "cves": [], "claims": [ { "topic": "entry", "text": { "ja": "不正アクセス前に修正版が提供されていましたが、適用されていませんでした。", "en": "A patch was available before unauthorized access but had not been applied." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "3. 発生原因" }, { "topic": "impact", "text": { "ja": "約17万件の情報流出を確認したと公表しました。", "en": "VOISING reported about 170,000 confirmed leaked records." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "2. 影響範囲" } ], "timeline": [ { "date": "2026-08-18", "text": { "ja": "この事案を公表。", "en": "Incident disclosed." }, "sourceIds": [ "s1" ] } ], "reportedActions": [ { "topic": "response", "text": { "ja": "BI停止、環境の廃棄・再構築、APIキーと認証情報の無効化・更新を公表しました。", "en": "VOISING reported stopping BI, discarding and rebuilding the environment, and revoking and rotating API keys and credentials." }, "status": "confirmed", "sourceIds": [ "s1" ], "locator": "4. 実施した対応" } ], "prevention": { "classification": "patch-available", "assessment": { "ja": "稼働するBIのバージョンと修正情報を照合し、更新の担当と期限を確認します。取得できるデータと公開範囲も限定します。", "en": "Compare deployed BI versions with advisories and verify patch ownership and deadlines; limit exposure and accessible data." }, "sourceIds": [ "s1" ] }, "ai": { "status": "unknown", "assessment": { "ja": "参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。", "en": "The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence." } }, "unknowns": [ { "ja": "BI製品名とCVEは公表されていません。他社事案との時期の近さだけでは同じ製品・脆弱性と判断できません。", "en": "BI product and CVE are undisclosed; proximity to another incident does not establish a shared product or vulnerability." } ], "sources": [ { "id": "s1", "reviewedAt": "2026-10-02", "title": "不正アクセスによる情報流出に関するご報告(第4報)", "url": "https://voising-official.com/news/1015", "publisher": "VOISING", "publishedAt": "2026-09-30", "kind": "organization" } ], "ruleIds": [ "SEC-001", "SEC-005", "SEC-006", "SEC-008", "SEC-009", "SEC-012" ] } ], "rules": [ { "id": "SEC-001", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "修正対象と稼働バージョンを照合する", "en": "Reconcile advisories with deployed versions" }, "summary": { "ja": "依存パッケージや自前運用の製品を使う環境。ソースのlockfileだけでなく、実際に配布・稼働するものが対象です。", "en": "Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles." }, "category": "known-vulnerability", "surfaces": [ "dependencies", "web-app" ], "applicability": { "ja": "依存パッケージや自前運用の製品を使う環境。ソースのlockfileだけでなく、実際に配布・稼働するものが対象です。", "en": "Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles." }, "targets": [ { "ja": "lockfile・パッケージ定義・SBOM", "en": "Lockfiles, package manifests, SBOMs" }, { "ja": "製品台帳・コンテナのダイジェスト・稼働バージョン", "en": "Product inventory, image digests, running versions" } ], "checks": [ { "ja": "OSV・開発元の最新アドバイザリとバージョンを照合し、影響条件と根拠を記録する。", "en": "Match versions against OSV and current vendor advisories; record affected conditions and evidence." }, { "ja": "悪用が確認されたものと外部から到達可能なものを優先し、更新が本番に反映されたか確認する。", "en": "Prioritize active exploitation and reachable assets; verify deployment of updates." } ], "remediation": [ { "ja": "互換性を確認して更新し、すぐ更新できない場合は開発元の回避策と公開範囲の制限を検討する。", "en": "Test and update; if immediate updating is unavailable, assess vendor mitigations and exposure restrictions." } ], "completionEvidence": [ { "ja": "稼働バージョン・対象アドバイザリ・適用した更新・必要な動作確認の結果を残す。", "en": "Record the running version, advisory, deployed fix, and relevant validation results." } ], "limitations": [ { "ja": "このDBにCVEがないことは安全の証拠になりません。閉じた製品の内部実装や実際の侵害は別途調査が必要です。", "en": "Absence from this dataset is not evidence of safety. Closed-source internals and actual compromise require separate investigation." } ], "incidentIds": [ "axios-npm-2026", "digital-agency-gss-2026", "equifax-2017", "forticloud-sso-2026", "gyazo-2026", "kddi-isp-2026", "metabase-2026", "moveit-2023", "nidek-website-2026", "nishiyama-2026", "openai-huggingface-eval-2026", "postman-shai-hulud-2025", "prontest-cloud-2026", "react2shell-2025", "rust-arrayref-2026", "trivy-supply-chain-2026", "voising-bi-2026" ], "references": [ { "title": "OSV API", "url": "https://google.github.io/osv.dev/api/" }, { "title": "CISA KEV", "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-002", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "MFAの方式と適用漏れを確認する", "en": "Inspect MFA methods and coverage" }, "summary": { "ja": "人がログインする管理画面・SSO・データ基盤。サービスアカウントは別の認証制御として扱います。", "en": "Human access to administration, SSO, and data platforms. Inspect service identities separately." }, "category": "credentials", "surfaces": [ "identity" ], "applicability": { "ja": "人がログインする管理画面・SSO・データ基盤。サービスアカウントは別の認証制御として扱います。", "en": "Human access to administration, SSO, and data platforms. Inspect service identities separately." }, "targets": [ { "ja": "IdP・SaaSの認証ポリシーと委託先アカウント", "en": "IdP/SaaS policies and contractor accounts" }, { "ja": "回復手段・例外設定・管理者認証", "en": "Recovery methods, exceptions, administrator authentication" } ], "checks": [ { "ja": "MFA必須の範囲を管理者・委託先・例外まで確認し、未登録を見落とさない。", "en": "Check enforcement for administrators, contractors, exceptions, and unenrolled accounts." }, { "ja": "プッシュ承認の連打やフィッシングに対する制御と、回復経路が認証を迂回しないか確認する。", "en": "Inspect repeated-prompt and phishing controls, including recovery paths." } ], "remediation": [ { "ja": "対応可能な環境でフィッシング耐性のある認証を採用し、例外には期限と担当者を設定する。", "en": "Adopt phishing-resistant authentication where supported; assign an owner and expiry to exceptions." } ], "completionEvidence": [ { "ja": "対象アカウントの適用率と、未認証の管理操作が拒否される検証を残す。", "en": "Record coverage and evidence that administrative access without required authentication is rejected." } ], "limitations": [ { "ja": "MFAは端末侵害や認証後のセッション窃取を防ぐ保証ではありません。IdPにアクセスできなければ未確認です。", "en": "MFA does not guarantee protection against compromised endpoints or stolen sessions. Missing IdP access means unverified." } ], "incidentIds": [ "anthropic-cyber-evals-2026", "askul-2025", "awabank-test-environment-2026", "digital-agency-gss-2026", "forticloud-sso-2026", "gainsight-oauth-2025", "nishiyama-2026", "openai-mixpanel-2025", "prontest-cloud-2026", "quick-2025", "snowflake-unc5537-2024", "uber-2022" ], "references": [ { "title": "Cloudflare: phishing attack blocked", "url": "https://blog.cloudflare.com/2022-07-sms-phishing-attacks/" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-003", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "端末とセッションの失効経路を確認する", "en": "Inspect endpoints and session revocation" }, "summary": { "ja": "従業員端末やサポート添付ファイルから、認証済みセッションが持ち出され得る環境。", "en": "Environments where endpoints or support files can expose authenticated sessions." }, "category": "endpoint", "surfaces": [ "endpoint", "identity", "support" ], "applicability": { "ja": "従業員端末やサポート添付ファイルから、認証済みセッションが持ち出され得る環境。", "en": "Environments where endpoints or support files can expose authenticated sessions." }, "targets": [ { "ja": "端末管理・SSOセッション設定", "en": "Endpoint management and SSO session policies" }, { "ja": "HAR・サポート添付・ログアウト処理", "en": "HAR/support attachments and logout handlers" } ], "checks": [ { "ja": "HAR等を送る前にCookie・Authorization・個人情報が除去される手順を確認する。実値は出力しない。", "en": "Verify sanitization of cookies, Authorization headers, and personal data before sending HAR files; never output values." }, { "ja": "失効・再認証・管理者セッションの制限を確認し、既存セッションで操作が続けられないか検証する。", "en": "Inspect revocation, reauthentication, and administrator-session limits; verify old sessions cannot continue acting." } ], "remediation": [ { "ja": "管理端末とセッション制御を整え、漏洩疑いのセッションを担当者の承認範囲で失効する。", "en": "Strengthen managed endpoints and session controls; revoke suspected sessions within granted authority." } ], "completionEvidence": [ { "ja": "合成したテストセッションが失効後に拒否される証拠と、添付ファイルの除去検査を残す。", "en": "Record rejection of synthetic revoked sessions and attachment sanitization checks." } ], "limitations": [ { "ja": "リポジトリだけでは端末の状態を確認できません。HTTPOnly等のCookie属性だけで端末マルウェアへの耐性を判断しません。", "en": "A repository cannot establish endpoint health. Cookie flags alone do not establish resistance to endpoint malware." } ], "incidentIds": [ "askul-2025", "axios-npm-2026", "circleci-2023", "okta-support-2023", "openai-mixpanel-2025", "quick-2025", "rust-arrayref-2026", "uber-2022" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-004", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "配布物と添付ファイルへの秘密情報の混入を確認する", "en": "Inspect artifacts and attachments for secret inclusion" }, "summary": { "ja": "コード・ビルド成果物・コンテナ・サポート資料を保存または配布する環境。", "en": "Environments storing or distributing code, artifacts, containers, or support material." }, "category": "credentials", "surfaces": [ "repositories", "containers", "ci", "support" ], "applicability": { "ja": "コード・ビルド成果物・コンテナ・サポート資料を保存または配布する環境。", "en": "Environments storing or distributing code, artifacts, containers, or support material." }, "targets": [ { "ja": "公開設定・Git履歴・配布用の成果物", "en": "Visibility settings, Git history, distribution artifacts" }, { "ja": "Dockerfile・中間レイヤー・CIログ・添付手順", "en": "Dockerfiles, image layers, CI logs, attachment procedures" } ], "checks": [ { "ja": "許可されたスキャナーで確認し、ファイル・位置・種類だけを記録する。秘密の実値や環境変数全体を出力しない。", "en": "Use authorized scanners; record only location and type, never secret values or whole environments." }, { "ja": "最終ファイルを削除してもGit履歴やイメージのレイヤーに残らないか、配布対象全体を確認する。", "en": "Check Git history and image layers as well as the final filesystem." } ], "remediation": [ { "ja": "ビルド時の秘密はsecret mount等に移し、ログと添付の除去処理を整備する。漏洩した鍵はSEC-005で失効を確認する。", "en": "Use build-time secret mechanisms and sanitization. Verify revocation of leaked keys with SEC-005." } ], "completionEvidence": [ { "ja": "合成した秘密の検出テストと、成果物検査の対象範囲・結果を残す。", "en": "Record synthetic-secret test results and the coverage of artifact inspection." } ], "limitations": [ { "ja": "秘密ファイルの読み取りは所有者の権限に従います。外部のコピーを全て消したことは証明できません。", "en": "Secret-file access follows owner permissions. Deletion of all external copies cannot be established." } ], "incidentIds": [ "anthropic-cyber-evals-2026", "axios-npm-2026", "campfire-2026", "codecov-2021", "okta-support-2023", "openai-huggingface-eval-2026", "postman-shai-hulud-2025", "rust-arrayref-2026", "sakura-billing-2026", "toyota-github-2022", "trivy-supply-chain-2026", "unit42-ai-assisted-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-005", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "更新対象の資格情報と旧鍵の失効を照合する", "en": "Reconcile credential inventory and revocation" }, "summary": { "ja": "資格情報の漏洩・侵害・供給元事故が疑われる環境。通常点検では実値を含まない台帳と失効手順を確認します。", "en": "Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures." }, "category": "credentials", "surfaces": [ "identity", "ci", "cloud", "data-store" ], "applicability": { "ja": "資格情報の漏洩・侵害・供給元事故が疑われる環境。通常点検では実値を含まない台帳と失効手順を確認します。", "en": "Suspected credential exposure, compromise, or supplier incidents. Routine checks use metadata inventories and revocation procedures." }, "targets": [ { "ja": "鍵・トークン・サービスアカウントのメタデータ台帳", "en": "Metadata inventory of keys, tokens, service identities" }, { "ja": "旧鍵の失効結果・利用先・失効後の監査ログ", "en": "Revocation results, consumers, post-revocation audit logs" }, { "ja": "OAuthの有効期限・更新トークンの再利用・未使用連携の失効記録", "en": "OAuth expiry, refresh-token reuse, and revocation of unused integrations" } ], "checks": [ { "ja": "使用中と誤認されたものだけでなく、全対象のID・所有者・利用先・失効方法を照合する。", "en": "Reconcile all affected IDs, owners, consumers, and revocation methods, including identities believed unused." }, { "ja": "新しい鍵の発行と旧鍵の失効を分けて確認し、未知の追加アカウントや永続化も調査対象へ渡す。", "en": "Verify issuance and revocation separately; escalate unknown accounts and persistence for investigation." }, { "ja": "長期間有効な連携トークンと更新トークンを棚卸しし、有効期限・再利用制御・失効後の拒否をメタデータと承認済みの試験証拠で確認する。", "en": "Inventory long-lived integration and refresh tokens; verify expiry, reuse controls, and rejection after revocation through metadata and authorized test evidence." } ], "remediation": [ { "ja": "利用先への切替と旧鍵の失効を段階的に行う計画を作る。本番の失効・権限変更は既存の承認範囲で実施する。", "en": "Prepare staged consumer migration and revocation; production revocation and permission changes require existing authority." } ], "completionEvidence": [ { "ja": "台帳の全対象に失効結果が対応し、旧鍵が拒否される検証または供給元の失効記録を残す。", "en": "Record revocation for every affected identity and rejection tests or provider revocation evidence." } ], "limitations": [ { "ja": "新しい鍵を作っただけでは完了ではありません。漏洩した鍵をAIへ渡さず、権限不足なら未確認とします。", "en": "Issuing a new key alone is not completion. Never provide leaked keys to an AI; missing access means unverified." } ], "incidentIds": [ "anthropic-claude-code-abuse-2025", "anthropic-cyber-evals-2026", "askul-2025", "awabank-test-environment-2026", "axios-npm-2026", "campfire-2026", "circleci-2023", "cloudflare-thanksgiving-2023", "codecov-2021", "digital-agency-gss-2026", "forticloud-sso-2026", "gainsight-oauth-2025", "gyazo-2026", "kddi-isp-2026", "metabase-2026", "nishiyama-2026", "okta-support-2023", "openai-huggingface-eval-2026", "openai-mixpanel-2025", "postman-shai-hulud-2025", "prontest-cloud-2026", "quick-2025", "react2shell-2025", "rust-arrayref-2026", "sakura-billing-2026", "sakura-hosting-2026", "temairazu-2026", "times-car-2026", "toyota-github-2022", "trivy-supply-chain-2026", "unit42-ai-assisted-2026", "voising-bi-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-006", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "稼働環境の公開範囲を確認する", "en": "Inspect deployed exposure boundaries" }, "summary": { "ja": "クラウド・データ基盤・管理画面・ファイル転送を持つ環境。委託先が管理する資産も対象です。", "en": "Cloud, data platforms, administration, and file transfer, including delegated assets." }, "category": "configuration", "surfaces": [ "cloud", "data-store", "web-app" ], "applicability": { "ja": "クラウド・データ基盤・管理画面・ファイル転送を持つ環境。委託先が管理する資産も対象です。", "en": "Cloud, data platforms, administration, and file transfer, including delegated assets." }, "targets": [ { "ja": "IaC・実環境の公開設定・ネットワークポリシー", "en": "IaC, deployed visibility, network policies" }, { "ja": "管理画面・データ保存先・委託先の資産一覧", "en": "Admin interfaces, data storage, delegated asset inventory" } ], "checks": [ { "ja": "意図した公開先と実際の設定を照合し、匿名アクセスや広い接続元許可を確認する。", "en": "Compare intended exposure with deployed settings; inspect anonymous access and broad network permissions." }, { "ja": "許可された資産だけで、データを取得せずに拒否を確認する。実環境へアクセスできなければ未確認とする。", "en": "Test rejection only on authorized assets without retrieving data. Without live access, mark deployed state unverified." } ], "remediation": [ { "ja": "公開が不要な経路を制限し、設定変更を検知する監査と責任者を用意する。", "en": "Restrict unnecessary exposure; establish drift detection and ownership." } ], "completionEvidence": [ { "ja": "実環境の設定証拠と、想定外の接続元を拒否する確認結果を残す。", "en": "Record deployed configuration and rejection of unintended access sources." } ], "limitations": [ { "ja": "IaCだけの確認では実環境の手動変更を見つけられません。公開サイトの存在自体を欠陥とは判断しません。", "en": "IaC alone misses manual drift. A deliberately public service is not inherently a defect." } ], "incidentIds": [ "anthropic-cyber-evals-2026", "awabank-test-environment-2026", "campfire-2026", "digital-agency-gss-2026", "forticloud-sso-2026", "gyazo-2026", "kddi-isp-2026", "metabase-2026", "moveit-2023", "nidek-website-2026", "nishiyama-2026", "openai-huggingface-eval-2026", "prontest-cloud-2026", "react2shell-2025", "sakura-billing-2026", "sakura-hosting-2026", "snowflake-unc5537-2024", "temairazu-2026", "times-car-2026", "toyota-cloud-2023", "unit42-ai-assisted-2026", "voising-bi-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-007", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "CIで実行する外部コードと権限を確認する", "en": "Inspect external CI code and permissions" }, "summary": { "ja": "外部Action・Orb・スクリプト・ビルドツールを実行するCI。", "en": "CI executing external actions, orbs, scripts, or build tools." }, "category": "supply-chain", "surfaces": [ "ci" ], "applicability": { "ja": "外部Action・Orb・スクリプト・ビルドツールを実行するCI。", "en": "CI executing external actions, orbs, scripts, or build tools." }, "targets": [ { "ja": "CIワークフロー・取得URL・Actionの参照", "en": "CI workflows, download URLs, action references" }, { "ja": "ジョブの権限・渡す秘密の種類・信頼境界", "en": "Job permissions, secret types, trust boundaries" }, { "ja": "依存パッケージのlockfile・固定インストール・公開用ジョブ", "en": "Dependency lockfiles, frozen installation, and publishing jobs" } ], "checks": [ { "ja": "変更可能なタグやリモートスクリプトの直接実行を確認し、固定・署名・信頼できる検証手段を調べる。", "en": "Inspect mutable references and direct remote-script execution; assess pinning, signatures, and trusted verification." }, { "ja": "外部コードを動かすステップに不要な秘密や書込み権限が渡らないか確認する。", "en": "Check whether external-code steps receive unnecessary secrets or write permissions." }, { "ja": "lockfileが保存され、CIが固定インストールを使うか確認する。依存パッケージのインストール中に、別のパッケージの公開用トークンを取得できないか点検する。", "en": "Check committed lockfiles and frozen installs, and whether dependency installation can access tokens that publish other packages." } ], "remediation": [ { "ja": "検証した参照を固定し、更新はレビューする。秘密が必要な処理と不要な処理を分離する。", "en": "Pin reviewed references and review updates; separate jobs by secret requirements." } ], "completionEvidence": [ { "ja": "固定した参照と検証根拠、権限を絞ったCIの成功結果を残す。", "en": "Record pinned references, verification evidence, and successful execution under narrowed permissions." } ], "limitations": [ { "ja": "固定だけでは固定先が安全だと証明できません。同じ侵害元から取ったチェックサムだけに依存しません。", "en": "Pinning does not prove code is safe. A checksum from the same compromised source is insufficient." } ], "incidentIds": [ "anthropic-cyber-evals-2026", "axios-npm-2026", "codecov-2021", "postman-shai-hulud-2025", "rust-arrayref-2026", "trivy-supply-chain-2026", "unit42-ai-assisted-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-008", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "侵害後に広がる管理権限を確認する", "en": "Inspect privileges enabling lateral access" }, "summary": { "ja": "管理者・サービスアカウント・CIが本番や別のデータ基盤へアクセスする環境。", "en": "Environments where administrators, services, or CI can access production or separate data stores." }, "category": "credentials", "surfaces": [ "identity", "cloud", "data-store", "ci" ], "applicability": { "ja": "管理者・サービスアカウント・CIが本番や別のデータ基盤へアクセスする環境。", "en": "Environments where administrators, services, or CI can access production or separate data stores." }, "targets": [ { "ja": "IAM・ロール・サービスアカウント", "en": "IAM, roles, service identities" }, { "ja": "本番トークン発行経路・環境間の接続", "en": "Production token issuance, cross-environment access" } ], "checks": [ { "ja": "通常業務に必要な権限と、鍵の発行・データ一括取得・権限追加が可能な範囲を比較する。", "en": "Compare job needs with credential issuance, bulk-export, and privilege-grant capabilities." }, { "ja": "一つのセッションや鍵の侵害で他の環境へ到達できる経路を記録する。", "en": "Document cross-environment paths available to a single compromised identity." } ], "remediation": [ { "ja": "権限の縮小と環境の分離を提案し、必要な業務への影響を検証する。", "en": "Propose narrower roles and environment boundaries; test impact on required workflows." } ], "completionEvidence": [ { "ja": "許可した操作が成功し、許可していない操作が拒否されるテストを残す。", "en": "Record positive tests for allowed operations and negative tests for denied operations." } ], "limitations": [ { "ja": "権限の広さだけで侵害を断定しません。本番ロールの変更は所有者の承認範囲に従います。", "en": "Broad privileges do not establish compromise. Production role changes follow owner authorization." } ], "incidentIds": [ "aflac-japan-2026", "anthropic-claude-code-abuse-2025", "anthropic-cyber-evals-2026", "askul-2025", "campfire-2026", "circleci-2023", "cloudflare-thanksgiving-2023", "digital-agency-gss-2026", "discord-support-vendor-2025", "forticloud-sso-2026", "gainsight-oauth-2025", "gyazo-2026", "kddi-isp-2026", "metabase-2026", "openai-huggingface-eval-2026", "openai-mixpanel-2025", "postman-shai-hulud-2025", "quick-2025", "react2shell-2025", "sakura-billing-2026", "sakura-hosting-2026", "snowflake-unc5537-2024", "temairazu-2026", "times-car-2026", "trivy-supply-chain-2026", "unit42-ai-assisted-2026", "voising-bi-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-009", "version": "1.2.0", "updatedAt": "2026-10-02", "title": { "ja": "取得・管理操作のログが揃っているか確認する", "en": "Inspect coverage of access and administration logs" }, "summary": { "ja": "ファイル取得・データ一括出力・鍵発行・管理操作を提供する環境。", "en": "Environments supporting file access, bulk exports, credential issuance, or administrative actions." }, "category": "credentials", "surfaces": [ "identity", "data-store", "support" ], "applicability": { "ja": "ファイル取得・データ一括出力・鍵発行・管理操作を提供する環境。", "en": "Environments supporting file access, bulk exports, credential issuance, or administrative actions." }, "targets": [ { "ja": "監査ログの種類・保管・検索クエリ", "en": "Audit event types, retention, query coverage" }, { "ja": "ファイル直接取得・鍵発行・不審な認証の通知", "en": "Direct file access, credential creation, anomalous login alerts" } ], "checks": [ { "ja": "画面経由と直接API経由の操作が両方記録され、取得漏れがないか合成イベントで確認する。", "en": "Use synthetic events to verify that UI and direct API paths are both logged." }, { "ja": "大量取得や想定外の管理操作に通知が届くか確認し、秘密や個人情報はログへ出さない。", "en": "Verify alerts for bulk access and unexpected administration without logging secrets or personal data." } ], "remediation": [ { "ja": "不足するイベントの記録と通知を整え、保存期間と調査担当者を決める。", "en": "Add missing event coverage and alerts; define retention and investigation ownership." } ], "completionEvidence": [ { "ja": "合成イベントの操作から記録・検索・通知までの一連の証拠を残す。", "en": "Record synthetic event execution, collection, query, and alert delivery." } ], "limitations": [ { "ja": "ログがないことは侵害がない証拠ではありません。ログを取得できなければ未確認とします。", "en": "Missing logs do not establish absence of compromise. Unavailable logs mean unverified." } ], "incidentIds": [ "aflac-japan-2026", "anthropic-claude-code-abuse-2025", "anthropic-cyber-evals-2026", "askul-2025", "awabank-test-environment-2026", "axios-npm-2026", "campfire-2026", "cloudflare-thanksgiving-2023", "digital-agency-gss-2026", "discord-support-vendor-2025", "forticloud-sso-2026", "gainsight-oauth-2025", "gyazo-2026", "kddi-isp-2026", "keio-ransomware-2026", "metabase-2026", "nidek-website-2026", "nishiyama-2026", "okta-support-2023", "openai-huggingface-eval-2026", "openai-mixpanel-2025", "postman-shai-hulud-2025", "prontest-cloud-2026", "quick-2025", "react2shell-2025", "rust-arrayref-2026", "sakura-billing-2026", "sakura-hosting-2026", "snowflake-unc5537-2024", "temairazu-2026", "times-car-2026", "trivy-supply-chain-2026", "unit42-ai-assisted-2026", "voising-bi-2026" ], "references": [], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-010", "version": "1.1.0", "updatedAt": "2026-10-02", "title": { "ja": "外部入力とSQLの組み立てを確認する", "en": "Inspect external input and SQL construction" }, "summary": { "ja": "自社でSQLを実行するコードを持つ環境。閉じた製品は内部実装を推測せず、SEC-001の製品点検へ渡します。", "en": "Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation." }, "category": "implementation", "surfaces": [ "web-app", "data-store" ], "applicability": { "ja": "自社でSQLを実行するコードを持つ環境。閉じた製品は内部実装を推測せず、SEC-001の製品点検へ渡します。", "en": "Owned code executing SQL. For closed-source products, use SEC-001 instead of guessing internal implementation." }, "targets": [ { "ja": "API入力・検索条件・データアクセス層", "en": "API inputs, query parameters, data access layer" }, { "ja": "raw SQL・文字列連結・動的識別子", "en": "Raw SQL, string concatenation, dynamic identifiers" } ], "checks": [ { "ja": "入力が値としてバインドされるか、SQLの構文へ直接連結されないか追跡する。", "en": "Trace whether input is bound as data rather than concatenated into SQL syntax." }, { "ja": "動的な列名やソート指定は許可リストで扱い、代表・境界・不正入力を合成データで検証する。", "en": "Allow-list dynamic identifiers and sort options; test representative, boundary, and malformed inputs using synthetic data." } ], "remediation": [ { "ja": "値はパラメータ化し、識別子には許可リストを使う。必要な検索動作を保つ回帰テストを追加する。", "en": "Parameterize values, allow-list identifiers, and add regression tests preserving required queries." } ], "completionEvidence": [ { "ja": "不正入力がSQL構造を変えず、許可された操作だけが成立するテストを残す。", "en": "Record tests showing hostile input cannot alter query structure and only allowed operations succeed." } ], "limitations": [ { "ja": "MOVEitは製品側の欠陥の事例です。このルールはそこから導いた一般点検であり、同じ実装原因を自社コードへ断定しません。", "en": "MOVEit is a vendor-defect example. This editorial rule does not claim the same implementation flaw exists in your code." } ], "incidentIds": [ "anthropic-cyber-evals-2026", "gyazo-2026", "metabase-2026", "moveit-2023" ], "references": [ { "title": "OWASP SQL Injection Prevention Cheat Sheet", "url": "https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-011", "version": "1.1.0", "updatedAt": "2026-10-02", "title": { "ja": "AIエージェントの接続先と実行権限を確認する", "en": "Inspect AI-agent destinations and execution privileges" }, "summary": { "ja": "コード実行やツール接続を行うAIエージェント・評価環境がある場合に適用します。", "en": "Applies to agents and evaluation environments with code execution or tool connectivity." }, "category": "configuration", "surfaces": [ "ai-agent" ], "applicability": { "ja": "コード実行やツール接続を行うAIエージェント・評価環境がある場合に適用します。", "en": "Applies to agents and evaluation environments with code execution or tool connectivity." }, "targets": [ { "ja": "エージェントのネットワーク設定、パッケージプロキシ、MCP等のツール接続、サービスアカウント。", "en": "Agent network settings, package proxies, tool connections such as MCP, and service accounts." }, { "ja": "評価環境・CI・本番の境界と、接続・権限変更の記録。", "en": "Boundaries among evaluation, CI, and production, plus connection and privilege-change records." } ], "checks": [ { "ja": "プロンプトの禁止事項と実際のネットワーク制御を照合する。例外のプロキシ経由で外部や本番に到達できないか、設定と既存の試験記録で確認する。", "en": "Compare prompt restrictions with actual controls; inspect settings and existing tests for proxy routes to external or production systems." }, { "ja": "ツールごとの取得・書き込み・公開の権限を確認し、未承認の接続、共用鍵、過大な権限を探す。秘密の値は取得しない。", "en": "Inspect per-tool read, write, and publish authority for unapproved connections, shared keys, or excessive privileges without retrieving secret values." }, { "ja": "人の承認が必要な操作と、実行ログ・停止手段を確認する。モデルの自己申告を合格の証拠にしない。", "en": "Verify human approval requirements, execution logs, and stop mechanisms; do not accept model self-reports as evidence." } ], "remediation": [ { "ja": "用途ごとにサービスアカウントを分け、必要な接続先と操作に限定する。通信制御をモデルの外で実装する。", "en": "Separate service accounts by purpose and restrict destinations and operations; enforce networking outside the model." }, { "ja": "評価環境の本番接続と公開権限を分離し、例外を承認・記録する。疑わしい実行では承認範囲内で停止・鍵の失効を提案する。", "en": "Separate production connectivity and publishing authority from evaluation; approve and record exceptions and propose authorized containment and revocation." } ], "completionEvidence": [ { "ja": "対象環境のリビジョンに対応した接続先・権限の一覧と、設定の確認記録。", "en": "Destination and privilege inventory and configuration review tied to the environment revision." }, { "ja": "許可された境界試験の記録、操作の承認履歴、実行ログと停止手段の確認結果。", "en": "Authorized boundary-test records, approval history, execution logs, and verified stop mechanisms." } ], "limitations": [ { "ja": "設定を読むだけでは通信境界の有効性を保証できません。試験記録や実環境へのアクセスがない項目は未確認にします。", "en": "Settings alone do not establish effective isolation; missing tests or runtime access remain unverified." }, { "ja": "このDBを使うこと自体は、外部への通信、鍵の失効、権限変更の許可になりません。", "en": "Using this catalog does not authorize external communication, credential revocation, or privilege changes." } ], "incidentIds": [ "anthropic-claude-code-abuse-2025", "anthropic-cyber-evals-2026", "openai-huggingface-eval-2026", "unit42-ai-assisted-2026" ], "references": [ { "title": "OpenAI evaluation incident", "url": "https://openai.com/index/hugging-face-model-evaluation-security-incident/" }, { "title": "Anthropic evaluation incidents", "url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" }, { "title": "Unit 42 AI-assisted intrusion", "url": "https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-012", "version": "1.1.0", "updatedAt": "2026-10-02", "title": { "ja": "非本番環境と保存データの廃止期限を確認する", "en": "Inspect nonproduction and data retirement deadlines" }, "summary": { "ja": "クラウドやDBに顧客データ、本人確認書類、初期認証情報、テスト用コピーを保存する環境に適用します。", "en": "Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies." }, "category": "configuration", "surfaces": [ "cloud", "data-store" ], "applicability": { "ja": "クラウドやDBに顧客データ、本人確認書類、初期認証情報、テスト用コピーを保存する環境に適用します。", "en": "Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies." }, "targets": [ { "ja": "開発・検証・BI・バックアップのデータコピー、退会者と登録未完了者の保存データ。", "en": "Development, test, BI, and backup copies, including former-member and incomplete-applicant data." }, { "ja": "環境とデータの責任者、用途、アクセス権、保持期限、廃止・消去の記録。", "en": "Owners, purpose, privileges, retention deadlines, and retirement or deletion records." } ], "checks": [ { "ja": "資産一覧と実環境を照合し、用途を終えた環境と期限超過のデータを探す。", "en": "Compare inventory and runtime assets for obsolete environments and overdue data." }, { "ja": "本番データをテストへ持ち込む必要性と匿名化・最小化、外部公開と認証の設定を確認する。", "en": "Inspect the need for production data in tests, anonymization and minimization, exposure, and authentication." }, { "ja": "保持・消去の運用がDB本体だけでなく、コピー・復元・検索・バックアップにどう適用されるか確認する。", "en": "Inspect how retention and deletion apply to copies, restoration, search, and backups as well as the live database." } ], "remediation": [ { "ja": "所有者と合意した保持方針に合わせて、不要な環境を廃止しデータを最小化する。削除は承認範囲と復旧要件に従う。", "en": "Retire unnecessary environments and minimize data under an owner-approved retention policy; deletion follows authority and recovery requirements." }, { "ja": "環境作成時に責任者・期限・アクセス制限を必須にし、期限超過を検知する。", "en": "Require ownership, deadlines, and access restrictions at environment creation; detect overdue assets." } ], "completionEvidence": [ { "ja": "環境リビジョンに対応する資産・保持期限の一覧と、対象を明記した消去・匿名化の記録。", "en": "Revision-linked asset and retention inventory with scoped deletion or anonymization records." }, { "ja": "本番コピー、退会者、未完了申込者、バックアップへの適用を確認した結果。", "en": "Evidence covering production copies, former members, incomplete applicants, and backups." } ], "limitations": [ { "ja": "法令や契約上の保持要件はこのDBで判断できません。必要なデータを独断で削除しません。", "en": "This catalog does not determine legal or contractual retention requirements; do not delete required data without authority." }, { "ja": "設定や期限の定義だけでは消去の実施を証明できません。実施記録がない範囲は未確認です。", "en": "Defined settings or deadlines alone do not prove deletion; absent execution evidence remains unverified." } ], "incidentIds": [ "aflac-japan-2026", "awabank-test-environment-2026", "discord-support-vendor-2025", "gyazo-2026", "nidek-website-2026", "openai-mixpanel-2025", "sakura-billing-2026", "temairazu-2026", "times-car-2026", "voising-bi-2026" ], "references": [ { "title": "阿波銀行の調査結果", "url": "https://www.awabank.co.jp/kojin/benri/awagin_app/news/2026/news20260603a/index.html" }, { "title": "タイムズカー第3報", "url": "https://share.timescar.jp/news/2026/0929/1816.html" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-013", "version": "1.0.0", "updatedAt": "2026-10-02", "title": { "ja": "隔離手順とバックアップの復元を確認する", "en": "Inspect containment and backup restoration" }, "summary": { "ja": "共有システム、クラウド、データ保存先がある場合に、侵害時の被害拡大と復旧を点検します。", "en": "Applies to shared systems, cloud, and data stores for containment and recovery inspection." }, "category": "configuration", "surfaces": [ "cloud", "data-store" ], "applicability": { "ja": "共有システム、クラウド、データ保存先がある場合に、侵害時の被害拡大と復旧を点検します。", "en": "Applies to shared systems, cloud, and data stores for containment and recovery inspection." }, "targets": [ { "ja": "システム間の依存関係、ネットワーク隔離と実行の責任者、バックアップの保存先と削除権限。", "en": "System dependencies, isolation procedures and owners, backup locations, and deletion privileges." } ], "checks": [ { "ja": "侵害された本番権限からバックアップを変更・削除できるかを権限情報で確認する。", "en": "Use privilege metadata to check whether compromised production authority can alter or delete backups." }, { "ja": "復元試験の日時・対象リビジョン・成功結果を確認し、目標復旧時間とデータ損失の要件と照合する。", "en": "Inspect restoration-test dates, revisions, and outcomes against recovery-time and data-loss requirements." }, { "ja": "共有システムの隔離手順、業務影響、連絡・判断の担当を記録と照合する。", "en": "Compare shared-system containment procedures, operational impact, and decision ownership with records." } ], "remediation": [ { "ja": "バックアップの権限と管理経路を本番から分け、保護・保持の方針を設定する。", "en": "Separate backup privileges and administration from production and define protection and retention policies." }, { "ja": "承認された環境で復元・隔離の試験を行い、結果に基づき手順を更新する。", "en": "Conduct authorized restoration and containment tests and update procedures from outcomes." } ], "completionEvidence": [ { "ja": "バックアップの権限・保護設定と、対象リビジョンを明記した復元試験の記録。", "en": "Backup privilege and protection settings, plus restoration-test records with scoped revisions." }, { "ja": "隔離の判断者、手順、業務依存を確認した記録。", "en": "Records verifying containment decision ownership, procedures, and operational dependencies." } ], "limitations": [ { "ja": "バックアップが存在することだけでは復元成功を証明できません。復元試験の証拠がなければ未確認です。", "en": "Backup existence does not prove successful restoration; missing restoration evidence remains unverified." }, { "ja": "本番通信の遮断や破壊的な復旧操作は、この点検ルールだけでは許可されません。", "en": "This inspection rule does not authorize production isolation or destructive recovery." } ], "incidentIds": [ "askul-2025", "keio-ransomware-2026", "nishiyama-2026", "sakura-hosting-2026" ], "references": [ { "title": "アスクル調査結果", "url": "https://www.askullogist.co.jp/pdf/20251212.pdf" }, { "title": "京王電鉄の障害公表", "url": "https://www.keio.co.jp/news/update/announce/nr260926v13404/" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" }, { "id": "SEC-014", "version": "1.0.0", "updatedAt": "2026-10-02", "title": { "ja": "照会APIの認可と取得量の制御を確認する", "en": "Inspect query authorization and retrieval limits" }, "summary": { "ja": "会員・顧客・組織の情報を照会、一覧表示、一括出力するWebアプリやAPI。", "en": "Web apps and APIs that query, list, or export member, customer, or organization information." }, "category": "implementation", "surfaces": [ "web-app", "identity", "data-store" ], "applicability": { "ja": "利用者のIDや所属組織に応じて取得可能なデータが変わる環境。大量照会の制御も対象です。", "en": "Environments where user or organization identity determines accessible data, including bulk-query controls." }, "targets": [ { "ja": "APIルート・認可処理・組織IDによる絞り込み・DBへの照会", "en": "API routes, authorization, tenant filtering, and database queries" }, { "ja": "ページ送り・一括出力・取得量の上限・監視設定", "en": "Pagination, exports, retrieval limits, and monitoring configuration" } ], "checks": [ { "ja": "画面の表示制限に加え、各APIが呼び出し元の権限とデータの所属を照合するか確認する。未認証・権限不足・別組織の試験データが拒否されるか、許可されたテスト環境の証拠で確認する。", "en": "Inspect server-side caller and record authorization; use evidence from an authorized test environment for unauthenticated, insufficient-role, and cross-tenant denial." }, { "ja": "通常形式のリクエストを繰り返した場合も、利用者・組織ごとの取得量を制限・検知できるか確認する。ページ送りや複数のAPIに分けた取得も試験計画に含める。", "en": "Inspect per-user and per-tenant volume limits and detection, including repeated ordinary requests, pagination, and access spread across endpoints." } ], "remediation": [ { "ja": "認可をサーバー側で共通化し、業務に合う取得量の上限と通知を設ける。許可された操作の成功と、許可していない照会の拒否を試験データで確認する。", "en": "Centralize server-side authorization and set appropriate limits and alerts; verify allowed and denied queries with synthetic data." } ], "completionEvidence": [ { "ja": "対象API、権限とデータ所属の組合せ、許可・拒否の試験結果、取得量の上限と通知の証拠を残す。未検査のAPIや一括出力は明記する。", "en": "Record API coverage, role/ownership combinations, allow/deny results, retrieval limits, and alert evidence; identify untested endpoints and exports." } ], "limitations": [ { "ja": "取得量の制限だけでは認可の欠陥を直せません。本番での大量リクエストや実顧客データへの照会を点検のために実行せず、権限や試験証拠が不足すれば未確認とします。", "en": "Limits do not repair authorization flaws. Do not exercise bulk requests or real customer queries in production; unavailable permissions or test evidence mean unverified." } ], "incidentIds": [ "aflac-japan-2026" ], "references": [ { "title": "アフラック生命保険:調査結果と再発防止策", "url": "https://www.aflac.co.jp/static/corp/profile/news/2026/2026073100.pdf" } ], "execution": "read-only-by-default", "provenance": "editorial-guidance" } ], "contentHash": "8475e05c44114b0f314005201084fde4507f872e33e385664e6d54db36106b36" }