{"kind":"incident","id":"aflac-japan-2026","hash":"e7147a302edd53b5d5620ad5861ec3ca6464a90590cb3779fd971d5a8eb2b4a0","record":{"id":"aflac-japan-2026","organization":"アフラック生命保険","title":{"ja":"アフラック:通常の利用に似たアクセスで大量のデータを照会","en":"Aflac Japan: ordinary-looking requests and bulk data queries"},"summary":{"ja":"アフラックは、通常の利用に似たアクセスを検知できず、大量照会への監視や制御も不足していたと公表しました。顧客約440万人の個人情報が漏えいし、そのうち約22万人には口座情報が含まれます。","en":"Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them."},"occurredAt":"2026-06-10","disclosedAt":"2026-06-30","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["implementation"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"アクセスとデータ照会への制御が不十分で、通常利用に似た形式のアクセスを直ちに検知できませんでした。設計レビューと侵入テストでも手口を想定できていなかったと説明しています。","en":"Aflac described insufficient access and query controls; reviews and penetration tests had not anticipated the method."},"status":"confirmed","sourceIds":["s1"],"locator":"4. 発生原因"},{"topic":"impact","text":{"ja":"顧客約440万人(うち口座情報を含む約22万人)と代理店約4万店の個人情報が漏えいしました。顧客数と口座情報の対象者数を合算しません。","en":"The disclosed scope was about 4.4 million customers, including about 220,000 with bank-account information, and about 40,000 agencies. The customer subsets are not additive."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 漏えいした個人情報"}],"timeline":[{"date":"2026-06-30","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"6月25日に関連システムを停止しました。認証・照会時の認可、大量アクセスへの監視・制御、レビューと侵入テストを強化する方針を公表しました。","en":"Aflac suspended related systems on June 25 and announced stronger authentication, query authorization, bulk-access controls, and security testing."},"status":"confirmed","sourceIds":["s1"],"locator":"1. 経緯 / 5. 再発防止策"}],"prevention":{"classification":"operational-control","assessment":{"ja":"画面のログインだけでなく、照会APIの認可と取得量の制御を確認します。通常形式のリクエストでも異常な取得量を検知できるか、試験データで点検します。","en":"Inspect server-side query authorization and retrieval limits, and test detection of abnormal volume with synthetic data."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"具体的な攻撃リクエスト、製品名、CVEは非公表です。ライブラリの修正放置や特定のSQL注入手法とは断定できません。","en":"Specific requests, products, and CVEs are undisclosed; this does not establish neglected library patches or a specific SQL-injection technique."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社システムに対する不正アクセスの発生および情報漏えいに関する調査結果と再発防止策について","url":"https://www.aflac.co.jp/static/corp/profile/news/2026/2026073100.pdf","publisher":"アフラック生命保険","publishedAt":"2026-07-31","kind":"organization"}],"ruleIds":["SEC-008","SEC-009","SEC-012","SEC-014"]}} {"kind":"incident","id":"anthropic-claude-code-abuse-2025","hash":"20d0318c8b3ab9ddede5b6f0dca1923392469c5aeacc7acec2e5544b4522aa64","record":{"id":"anthropic-claude-code-abuse-2025","organization":"Anthropicが調査した複数組織への攻撃","title":{"ja":"Claude Code:攻撃者がAIを悪用した複数組織への侵入","en":"Claude Code: attacker misuse in a multi-organization intrusion campaign"},"summary":{"ja":"Anthropicは、攻撃者がClaude Codeを偵察、攻撃コードの作成、認証情報の取得、データ持ち出しに悪用したと報告しました。約30組織が標的で、侵入成功は少数と説明しています。","en":"Anthropic reported attacker use of Claude Code for reconnaissance, exploit development, credential harvesting, and exfiltration. About 30 organizations were targeted, with success reported at a small number."},"occurredAt":null,"disclosedAt":"2025-11-13","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","unknown"],"cves":[],"claims":[{"topic":"ai","text":{"ja":"Claude Codeの攻撃者による悪用を、Anthropicが調査したと公表しています。評価試験の逸脱ではなく、同社が観測した攻撃キャンペーンの報告です。","en":"Anthropic reports investigating attacker misuse of Claude Code in an observed campaign, distinct from evaluation incidents."},"status":"confirmed","sourceIds":["s1"],"locator":"Introduction / How the cyberattack worked"},{"topic":"entry","text":{"ja":"人間が標的を選び、正当な防御テストを装ってAIへ作業を分割しました。AIは偵察から認証情報の取得、持ち出しまでを支援したと説明しています。","en":"Human operators selected targets and disguised fragmented tasks as defensive testing; Anthropic describes AI assistance through reconnaissance and exfiltration."},"status":"confirmed","sourceIds":["s1"],"locator":"How the cyberattack worked"}],"timeline":[{"date":"2025-11-13","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"不正利用アカウントを停止し、影響を受けた組織への通知、関係当局との連携、検知と安全対策の改善を行ったと公表しました。","en":"Anthropic reported banning accounts, notifying affected organizations, coordinating with authorities, and improving safeguards."},"status":"confirmed","sourceIds":["s1"],"locator":"Introduction"}],"prevention":{"classification":"unknown","assessment":{"ja":"被害環境の具体的な侵入原因は判断できません。認証情報の到達範囲と取得ログを点検し、自社で動かすAIのツール・通信権限も確認します。","en":"Victim-specific entry causes are unspecified; inspect credential reach, access logs, and permissions of AI operated in your own environment."},"sourceIds":["s1"]},"ai":{"status":"confirmed","assessment":{"ja":"攻撃者によるClaude Codeの利用をAnthropicが報告しています。被害環境の穴が回避不能だったことや、AI攻撃全体の増加率を示す証拠ではありません。","en":"Anthropic reports attacker use of Claude Code; this does not establish unavoidable victim vulnerabilities or a population-wide increase in AI attacks."}},"unknowns":[{"ja":"被害組織名、個別の脆弱性とCVE、初回侵入日は非公表です。標的数は被害企業数ではなく、AIの自律性の評価は調査元の見解です。","en":"Victim names, vulnerabilities, CVEs, and precise entry dates are undisclosed; target count is not victim count, and autonomy assessments are the investigator’s interpretation."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Disrupting an AI-orchestrated cyber espionage campaign","url":"https://www.anthropic.com/news/disrupting-AI-espionage","publisher":"Anthropic","publishedAt":"2025-11-13","kind":"investigator"}],"ruleIds":["SEC-005","SEC-008","SEC-009","SEC-011"]}} {"kind":"incident","id":"anthropic-cyber-evals-2026","hash":"df22edd6b470df3c7276c13334a0400fb1c2344c796091898bb40b00c80e7654","record":{"id":"anthropic-cyber-evals-2026","organization":"Anthropic / external evaluation partners","title":{"ja":"Anthropic:評価環境の通信制限が効かず外部へ到達","en":"Anthropic: evaluation connectivity limits failed"},"summary":{"ja":"Anthropicは、サイバー評価中にモデルが外部組織へ到達した3事案をまとめて公表しました。評価環境の通信設定に問題があり、弱い認証や実装上の穴が悪用されました。","en":"Anthropic disclosed three incidents of evaluation models reaching external organizations. Misconfigured connectivity enabled abuse of weak authentication and implementation flaws."},"occurredAt":null,"disclosedAt":"2026-07-30","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["configuration","credentials","implementation","supply-chain"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"通信禁止の指示に反して接続可能な環境がありました。同社は高度な新規脆弱性の悪用は確認していません。","en":"Some environments allowed connectivity despite instructions; Anthropic did not identify sophisticated novel vulnerability exploitation."},"status":"confirmed","sourceIds":["s1"],"locator":"How these incidents happened"},{"topic":"impact","text":{"ja":"1事案では悪性PyPIパッケージが公開され、セキュリティスキャナーを含む15システムで実行されました。","en":"In one incident, a malicious PyPI package was published and executed by 15 systems including security scanners."},"status":"confirmed","sourceIds":["s1"],"locator":"Incident 2"},{"topic":"ai","text":{"ja":"同社は評価モデルによる3事案・6回の実行を調査対象として公表しました。","en":"Anthropic disclosed evaluation-model activity across three incidents and six runs."},"status":"confirmed","sourceIds":["s1"],"locator":"Investigation overview"}],"timeline":[{"date":"2026-07-30","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"7月23日に当該評価を止め、通信設定・監視・評価手順の見直しを公表しました。","en":"Anthropic reported stopping these evaluations on July 23 and reviewing networking, monitoring, and evaluation procedures."},"status":"confirmed","sourceIds":["s1"],"locator":"What we are changing"}],"prevention":{"classification":"operational-control","assessment":{"ja":"指示文で通信を禁止しても境界の証拠にはなりません。許可された試験でネットワーク制御を確認し、公開パッケージの配布権限も分離します。","en":"Instructions alone do not prove network isolation. Verify controls in authorized tests and separate public-package publishing authority."},"sourceIds":["s1"]},"ai":{"status":"confirmed","assessment":{"ja":"Anthropicが評価中のモデルの行動として確認しています。実際の外部影響を伴う評価事案です。","en":"Anthropic confirmed evaluation-model activity with external impact."}},"unknowns":[{"ja":"3事案を1レコードにまとめています。被害組織名と全実行の日付は非公表で、犯罪者の利用とは区別します。","en":"This record groups three incidents. Victim identities and all run dates are undisclosed; evaluation activity differs from criminal use."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Investigating incidents in our cybersecurity evaluations","url":"https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals","publisher":"Anthropic","publishedAt":"2026-07-30","kind":"organization"}],"ruleIds":["SEC-002","SEC-004","SEC-005","SEC-006","SEC-007","SEC-008","SEC-009","SEC-010","SEC-011"]}} {"kind":"incident","id":"askul-2025","hash":"8807f2dc9a76a9250318dde15e88f1d97a29fa9f39feda176246710b552f4235","record":{"id":"askul-2025","organization":"ASKUL","title":{"ja":"アスクル:MFAの例外アカウントから侵入","en":"ASKUL: access through an MFA exception"},"summary":{"ja":"委託先用の管理者アカウントの認証情報が悪用され、ランサムウェア被害が発生しました。このアカウントにはMFAが適用されていませんでした。","en":"Stolen credentials for a contractor administrator account without MFA enabled a ransomware intrusion."},"occurredAt":null,"disclosedAt":"2025-10-19","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"委託先用アカウントのID・パスワードが悪用されました。認証情報が漏れた経路は特定されていません。","en":"A contractor account was misused; the original credential leak remains unresolved."},"status":"confirmed","sourceIds":["s1"],"locator":"6. 調査結果 (1)"},{"topic":"impact","text":{"ja":"一部のサーバーにはEDRと常時監視がなく、バックアップの暗号化・削除が復旧を妨げました。","en":"Some servers lacked EDR and continuous monitoring; encrypted or deleted backups impeded recovery."},"status":"confirmed","sourceIds":["s1"],"locator":"6. 調査結果 (2)–(5)"}],"timeline":[{"date":"2025-10-19","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"認証情報の更新、MFA適用、環境の再構築を実施したと公表しました。","en":"ASKUL reported credential resets, MFA rollout, and environment rebuilding."},"status":"confirmed","sourceIds":["s1"],"locator":"7. 対応状況"}],"prevention":{"classification":"operational-control","assessment":{"ja":"MFAの例外と委託先の管理権限を確認します。侵害された権限から削除できないバックアップと復元試験も必要です。","en":"Inspect MFA exceptions and contractor privileges, plus protected backups and restoration tests."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"認証情報の流出元は不明です。VPNの脆弱性を悪用した痕跡は確認されていません。","en":"Credential theft origin is unresolved; the report found no evidence that the VPN vulnerability was exploited."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"ランサムウェア攻撃に関する調査結果および今後の対応について","url":"https://www.askullogist.co.jp/pdf/20251212.pdf","publisher":"ASKUL","publishedAt":"2025-12-12","kind":"organization"}],"ruleIds":["SEC-002","SEC-003","SEC-005","SEC-008","SEC-009","SEC-013"]}} {"kind":"incident","id":"awabank-test-environment-2026","hash":"274695977d4b0103725da2aef85bb23722b25dde5a57ad8c0d4d2c1e25ee7b74","record":{"id":"awabank-test-environment-2026","organization":"阿波銀行","title":{"ja":"阿波銀行:残存したテスト環境から情報が流出","en":"Awabank: leakage from a retained test environment"},"summary":{"ja":"廃止・データ消去が必要だったテスト環境が、AI高度化の検証用として残っていました。ID・パスワードによる不正アクセスを受け、顧客・株主の情報が流出したと公表しています。","en":"A test environment due for retirement and data deletion remained for AI-related verification. Credential-based unauthorized access led to reported customer and shareholder data leakage."},"occurredAt":null,"disclosedAt":"2026-04-03","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"外部からテスト環境へID・パスワードを用いた不正アクセスがありました。","en":"External unauthorized access used an ID and password against the test environment."},"status":"confirmed","sourceIds":["s1"],"locator":"原因"},{"topic":"control","text":{"ja":"開発後の環境廃止・データ消去が行われず、アクセス制御も不十分だったと報告しました。","en":"The bank reported missing post-development retirement and data deletion, and insufficient access controls."},"status":"confirmed","sourceIds":["s1"],"locator":"原因 / 再発防止策"}],"timeline":[{"date":"2026-04-03","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"planned-response","text":{"ja":"警察の調査後の環境廃止と、システム管理・アクセス制御の見直しを予定すると公表しました。","en":"The bank announced planned retirement after police investigation and reviews of system management and access controls."},"status":"confirmed","sourceIds":["s1"],"locator":"再発防止策"}],"prevention":{"classification":"operational-control","assessment":{"ja":"非本番環境の実データ、公開範囲、責任者、廃止期限と消去の証拠を点検します。","en":"Inspect real data in nonproduction, exposure, ownership, retirement deadlines, and deletion evidence."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"AIは環境を残した業務目的として記載されています。攻撃者のAI利用を示す根拠ではありません。","en":"AI is mentioned as a business reason for retaining the environment, not evidence of attacker AI use."}},"unknowns":[{"ja":"認証情報の入手経路と、非本番環境を残した判断の詳細は不明です。","en":"Credential acquisition and detailed decisions behind retaining the environment are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"情報流出に関する調査結果および再発防止策について","url":"https://www.awabank.co.jp/kojin/benri/awagin_app/news/2026/news20260603a/index.html","publisher":"阿波銀行","publishedAt":"2026-06-03","kind":"organization"}],"ruleIds":["SEC-002","SEC-005","SEC-006","SEC-009","SEC-012"]}} {"kind":"incident","id":"axios-npm-2026","hash":"209e538cd359db5c738022789123f0e56efcc115d5b00ac67d20585ee32bb450","record":{"id":"axios-npm-2026","organization":"Axios npm project","title":{"ja":"Axios:公開者アカウントから悪性パッケージを配布","en":"Axios: malicious releases through publisher compromise"},"summary":{"ja":"Googleの調査チームは、Axiosの公開者アカウントが侵害され、悪性の依存パッケージを含む版が公開されたと報告しました。インストール時の処理が複数OS向けのバックドアを配布します。","en":"Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors."},"occurredAt":null,"disclosedAt":"2026-03-31","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["supply-chain","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"公開者アカウントが侵害され、Axios 1.14.1と0.30.4が悪性版として報告されました。","en":"A compromised publisher account was used to distribute malicious Axios 1.14.1 and 0.30.4."},"status":"confirmed","sourceIds":["s1"],"locator":"Overview / Remediation"},{"topic":"execution","text":{"ja":"plain-crypto-jsのインストール処理がWindows・macOS・Linux向けのペイロードを取得します。","en":"The plain-crypto-js install script retrieves payloads for Windows, macOS, and Linux."},"status":"confirmed","sourceIds":["s1"],"locator":"Initial stage"}],"timeline":[{"date":"2026-03-31","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"guidance","text":{"ja":"調査元は依存関係の照合、影響端末の隔離、露出した鍵の更新、キャッシュの除去を推奨しました。","en":"Investigators recommend dependency checks, host isolation, rotation of exposed secrets, and cache remediation."},"status":"confirmed","sourceIds":["s1"],"locator":"Remediation"}],"prevention":{"classification":"operational-control","assessment":{"ja":"ロックファイルと実際のビルド環境を照合し、インストール処理の実行履歴を確認します。版の固定だけでは悪性版の安全性を保証できません。","en":"Compare lockfiles with actual build environments and install execution; pinning does not make a malicious version safe."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"公開者アカウントの侵害方法と、実際に影響した利用者の総数は不明です。","en":"Publisher-account compromise method and total affected consumers are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package","url":"https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package/","publisher":"Google Threat Intelligence Group","publishedAt":"2026-03-31","kind":"investigator"}],"ruleIds":["SEC-001","SEC-003","SEC-004","SEC-005","SEC-007","SEC-009"]}} {"kind":"incident","id":"campfire-2026","hash":"6ebd0adb88b55b1f734f6be5eb9eb9168c3977c7504da6a2c91087448117eca6","record":{"id":"campfire-2026","organization":"CAMPFIRE","title":{"ja":"CAMPFIRE:開発サーバーに置いたGitHub認証情報を悪用","en":"CAMPFIRE: leaked GitHub credentials and cloud access"},"summary":{"ja":"個人の開発サーバーに誤って置いたGitHub認証情報が悪用されました。同社は内部のクラウド管理領域への不正アクセスと、個人情報1件のクエリによる取得を確認しています。","en":"GitHub credentials mistakenly uploaded to a personal development server were misused. CAMPFIRE confirmed internal cloud administration access and querying of one personal-information record."},"occurredAt":null,"disclosedAt":"2026-04-03","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"従業員が発行したGitHub認証情報を、個人の開発サーバーへ誤ってアップロードしていました。","en":"An employee mistakenly uploaded GitHub credentials to a personal development server."},"status":"confirmed","sourceIds":["s1"],"locator":"5. 原因"},{"topic":"expansion","text":{"ja":"GitHubから得た情報でクラウドの認証情報を取得したと同社は判断しています。","en":"The company assesses that information obtained from GitHub enabled acquisition of cloud credentials."},"status":"inferred","sourceIds":["s1"],"locator":"5. 原因"},{"topic":"impact","text":{"ja":"個人情報1件の取得を確認しました。22万5,846人は影響の可能性がある範囲で、流出確認件数ではありません。","en":"One queried personal record was confirmed; 225,846 people are potentially affected, not a confirmed exfiltration count."},"status":"confirmed","sourceIds":["s1"],"locator":"3. 流出した可能性のある情報"}],"timeline":[{"date":"2026-04-03","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"GitHubの接続解除、認証情報の無効化・更新、関連クラウド資源の停止を公表しました。","en":"The company reported disconnecting GitHub, revoking and rotating credentials, and stopping affected cloud resources."},"status":"confirmed","sourceIds":["s1"],"locator":"4. 対応"}],"prevention":{"classification":"operational-control","assessment":{"ja":"公開物への秘密情報の混入と、GitHubから到達できるクラウド権限を点検します。旧鍵の失効も証拠で確認します。","en":"Inspect secret exposure in published files and cloud privileges reachable from GitHub; verify old-key revocation."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"欠けたログがあり、取得・流出範囲の全体を確定できません。","en":"Incomplete logs prevent a complete determination of accessed or exfiltrated information."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"不正アクセスに関する調査結果と再発防止策について","url":"https://campfire.co.jp/press/2026/06/02/campfire/","publisher":"CAMPFIRE","publishedAt":"2026-06-02","kind":"organization"}],"ruleIds":["SEC-004","SEC-005","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"circleci-2023","hash":"2d1c93b1f50bbfabd2c13b0abd6cd587cc5dcf2ddb4569710345a43e627a9788","record":{"id":"circleci-2023","title":{"ja":"CircleCI:端末からSSOセッションを窃取","en":"CircleCI: endpoint malware and stolen SSO session"},"organization":"CircleCI","summary":{"ja":"従業員端末のマルウェアが、二要素認証済みのSSOセッションを窃取しました。従業員の権限が悪用され、本番の一部と顧客の環境変数・鍵などへアクセスされました。","en":"Endpoint malware stole a two-factor-backed SSO session. Employee privileges enabled access to production stores containing customer variables and credentials."},"occurredAt":"2022-12-16","disclosedAt":"2023-01-04","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["endpoint","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"マルウェアによるセッションCookieの窃取が侵入経路でした。","en":"Malware stole a valid session cookie."},"status":"confirmed","sourceIds":["s1"],"locator":"What happened?"},{"topic":"expansion","text":{"ja":"対象従業員は本番アクセストークンを発行できる権限を持ち、攻撃者がその権限を利用しました。","en":"The targeted employee could generate production access tokens; the attacker used those privileges."},"status":"confirmed","sourceIds":["s1"],"locator":"What happened?"}],"timeline":[{"date":"2022-12-16","text":{"ja":"従業員端末が侵害されたと調査で判明。","en":"Investigation dates the endpoint compromise to this day."},"sourceIds":["s1"]},{"date":"2023-01-04","text":{"ja":"顧客に秘密情報の更新を呼びかけ。","en":"Customer credential rotation alert published."},"sourceIds":["s2"]}],"reportedActions":[{"topic":"response","text":{"ja":"端末検知の強化とアクセス制御の変更を実施し、顧客に鍵等の更新・失効を要請しました。","en":"Endpoint detection and access controls were strengthened; customers were asked to rotate and revoke secrets."},"status":"confirmed","sourceIds":["s1"],"locator":"Remediation / customer guidance"}],"prevention":{"classification":"operational-control","assessment":{"ja":"MFAの導入後も、セッション窃取と端末侵害への対策、管理権限の範囲を点検します。","en":"MFA does not eliminate stolen-session risk. Inspect endpoint controls and the scope of privileged access."},"sourceIds":["s1","s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"顧客側の二次被害の全体像や、個々の鍵の利用状況はこの記録では評価できません。","en":"This record does not assess all downstream customer impact or individual credential use."}],"sources":[{"id":"s1","title":"CircleCI Jan 4, 2023 security incident report","url":"https://circleci.com/blog/jan-4-2023-incident-report/","publisher":"CircleCI","kind":"organization","publishedAt":"2023-01-12","reviewedAt":"2026-10-02"},{"id":"s2","title":"CircleCI security alert: Rotate any secrets","url":"https://circleci.com/blog/january-4-2023-security-alert/","publisher":"CircleCI","kind":"organization","publishedAt":"2023-01-04","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-003","SEC-005","SEC-008"]}} {"kind":"incident","id":"cloudflare-thanksgiving-2023","hash":"98665310d09970c4a288fdf4686f8e76fa0483ce3e5f05670bfef949f75001fa","record":{"id":"cloudflare-thanksgiving-2023","title":{"ja":"Cloudflare:失効漏れのトークンとアカウントから侵入","en":"Cloudflare: credentials missed during rotation"},"organization":"Cloudflare","summary":{"ja":"以前のOkta事故で漏洩した資格情報のうち、更新されなかったトークンとアカウントが悪用されました。自己管理のAtlassian環境に侵入され、ソースコード等にアクセスされました。","en":"Credentials stolen in the earlier Okta incident were missed during rotation. They enabled access to self-hosted Atlassian systems and source code."},"occurredAt":"2023-11-14","disclosedAt":"2024-02-01","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"未使用と誤認したサービス用トークン1つとアカウント3つが、更新されずに残っていました。","en":"One service token and three accounts were not rotated because they were mistakenly thought unused."},"status":"confirmed","sourceIds":["s1"],"locator":"Credentials not rotated"},{"topic":"scope","text":{"ja":"侵入は自己管理のAtlassian環境に及びました。顧客データやグローバルネットワークへの影響はなかったと公表しました。","en":"The self-hosted Atlassian environment was accessed; Cloudflare reported no impact on customer data or its global network."},"status":"confirmed","sourceIds":["s1"],"locator":"Executive summary"}],"timeline":[{"date":"2023-11-14","text":{"ja":"公表された偵察・アクセスの開始。","en":"Beginning of disclosed reconnaissance and access."},"sourceIds":["s1"]},{"date":"2023-11-23","text":{"ja":"侵入を検知。","en":"Intrusion detected."},"sourceIds":["s1"]},{"date":"2023-11-24","text":{"ja":"攻撃者のアクセスを停止。","en":"Attacker access terminated."},"sourceIds":["s1"]},{"date":"2024-02-01","text":{"ja":"調査結果を公表。","en":"Investigation published."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"資格情報の広範な更新と、侵入範囲の調査を実施しました。","en":"Credentials were rotated broadly and access scope investigated."},"status":"confirmed","sourceIds":["s1"],"locator":"Remediation"}],"prevention":{"classification":"operational-control","assessment":{"ja":"更新した鍵の一覧だけでなく、対象の全資格情報と旧鍵の失効証拠を照合する点検が必要です。","en":"Reconcile all affected credentials against rotation records and evidence that old credentials are revoked."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"対象資格情報の実値や内部の完全な権限構成は、公表資料から確認できません。","en":"Public sources do not expose credential values or the complete internal authorization model."}],"sources":[{"id":"s1","title":"Thanksgiving 2023 security incident","url":"https://blog.cloudflare.com/thanksgiving-2023-security-incident/","publisher":"Cloudflare","kind":"organization","publishedAt":"2024-02-01","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-005","SEC-008","SEC-009"]}} {"kind":"incident","id":"codecov-2021","hash":"8eddabe999ec0a13dcb7fa03264b806636affbbbaf6806b6faf99fe164fdb1be","record":{"id":"codecov-2021","title":{"ja":"Codecov:イメージ内の鍵からCIスクリプトを改ざん","en":"Codecov: leaked image credential and CI script tampering"},"organization":"Codecov","summary":{"ja":"公開Dockerイメージの中間レイヤーにあった鍵が悪用され、Bash Uploaderが改ざんされました。実行した利用者のCI環境変数などが外部へ送信される攻撃でした。","en":"A credential in a public Docker image layer enabled tampering with the Bash Uploader. The modified script exported CI environment information from affected users."},"occurredAt":"2021-01-31","disclosedAt":"2021-04-15","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","supply-chain"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"公開Dockerイメージの中間レイヤーから、配布物を書き換えられるHMAC鍵が取得されました。","en":"An HMAC key extracted from an intermediate image layer allowed modification of the distributed uploader."},"status":"confirmed","sourceIds":["s2"],"locator":"Root Cause"},{"topic":"impact","text":{"ja":"改ざんされたUploaderは環境変数とGitリモート情報を外部へ送信しました。","en":"The modified uploader transmitted environment variables and Git remote information."},"status":"confirmed","sourceIds":["s1"],"locator":"About the Event"}],"timeline":[{"date":"2021-01-31","text":{"ja":"改ざんが始まった時期。","en":"Beginning of observed script modifications."},"sourceIds":["s1"]},{"date":"2021-04-01","text":{"ja":"利用者のチェックサム検査を契機に発覚。","en":"Detected after a customer checksum check."},"sourceIds":["s2"]},{"date":"2021-04-15","text":{"ja":"事故と利用者向けの対応を公表。","en":"Disclosure and customer response guidance published."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"recovery","text":{"ja":"鍵の失効・更新と、公開イメージのビルド方法の変更を実施しました。","en":"Credentials were revoked and rotated; public image build practices were changed."},"status":"confirmed","sourceIds":["s2"],"locator":"Recovery"}],"prevention":{"classification":"operational-control","assessment":{"ja":"鍵を最終イメージのファイルから消すだけでは、中間レイヤーに残る場合があります。配布物全体とCIの実行権限を点検します。","en":"Deleting a secret from the final filesystem can leave it in layers. Inspect distributed artifacts and CI execution permissions."},"sourceIds":["s1","s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"利用者ごとの漏洩範囲は、当時のCI環境と実行履歴に依存します。","en":"Customer exposure depends on the CI environment and execution history."}],"sources":[{"id":"s1","title":"Bash Uploader Security Update","url":"https://about.codecov.io/security-update/","publisher":"Codecov","kind":"organization","publishedAt":"2021-04-15","reviewedAt":"2026-10-02"},{"id":"s2","title":"Post-Mortem / Root Cause Analysis (April 2021)","url":"https://about.codecov.io/apr-2021-post-mortem/","publisher":"Codecov","kind":"organization","publishedAt":null,"reviewedAt":"2026-10-02"}],"ruleIds":["SEC-004","SEC-005","SEC-007"]}} {"kind":"incident","id":"digital-agency-gss-2026","hash":"f213edc27fdd0fbcd2d58006757eb9243c43e43797634ac1440d9d22d7be9e9c","record":{"id":"digital-agency-gss-2026","organization":"デジタル庁","title":{"ja":"デジタル庁GSS:修正未適用のVPNから侵入","en":"Digital Agency GSS: entry through an unpatched VPN"},"summary":{"ja":"GSSの保守環境で、VPNの既知の脆弱性を利用した不正アクセスを確認しました。修正が未適用で、約24万6千件の情報が流出した可能性を公表しています。","en":"Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked."},"occurredAt":null,"disclosedAt":"2026-09-11","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["known-vulnerability","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"侵入前に公表されていたVPNの脆弱性への修正が未適用でした。公表時の深刻度はMediumでした。","en":"A previously disclosed VPN vulnerability remained unpatched; its published severity was Medium."},"status":"confirmed","sourceIds":["s1"],"locator":"Q&A:原因と脆弱性の対応"},{"topic":"impact","text":{"ja":"約24万6千件は流出の可能性がある範囲です。確定した流出件数ではありません。","en":"About 246,000 records are potentially exposed, not a confirmed exfiltration count."},"status":"confirmed","sourceIds":["s1"],"locator":"Q&A:流出の可能性"}],"timeline":[{"date":"2026-09-11","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"保守用アカウントと通信の停止、修正、パスワード変更などを公表しました。","en":"The agency reported disabling maintenance access and communications, patching, and password changes."},"status":"confirmed","sourceIds":["s1"],"locator":"Q&A:実施した対応"}],"prevention":{"classification":"patch-available","assessment":{"ja":"CVSSだけで優先度を決めず、外部到達性と保守権限を合わせて点検します。修正の適用済み証拠を残します。","en":"Prioritize using exposure and maintenance privileges as well as CVSS, and retain evidence of applied fixes."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"VPN製品名とCVEは非公表です。6月25日は異常検知日で、侵入開始日は特定できません。","en":"VPN product and CVE are undisclosed; June 25 is anomaly detection, not an established intrusion start."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"GSSにおける不正アクセスについて(Q&A)","url":"https://www.digital.go.jp/press/5fc99139-a4e2-4b7b-8b0c-d475e926143f","publisher":"デジタル庁","publishedAt":"2026-09-12","kind":"government"}],"ruleIds":["SEC-001","SEC-002","SEC-005","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"discord-support-vendor-2025","hash":"30b18dd1c522b297ee64df0dafca09e2a43a0b9575ad64e2a0560d34371c6726","record":{"id":"discord-support-vendor-2025","organization":"Discord / 委託先のカスタマーサポート","title":{"ja":"Discord:サポート委託先への侵入で問い合わせ情報にアクセス","en":"Discord: support-provider compromise exposed ticket information"},"summary":{"ja":"Discordは、サポート委託先への侵入により問い合わせ情報へ不正アクセスがあったと公表しました。約70,000人の利用者は本人確認画像が露出した可能性のある範囲であり、画像流出の確定人数ではありません。","en":"Discord reported unauthorized access to support information through a provider compromise. About 70,000 users potentially had identity-document photos exposed; this is not a confirmed image-leak count."},"occurredAt":null,"disclosedAt":"2025-10-03","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["supply-chain","unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"Discordは委託先5CAへの侵入と説明しています。Discord本体のシステム侵害とは区別して公表しています。","en":"Discord attributed the compromise to service provider 5CA and distinguished it from a breach of Discord itself."},"status":"confirmed","sourceIds":["s1"],"locator":"TL;DR / What happened?"},{"topic":"impact","text":{"ja":"問い合わせ情報や一部の本人確認画像が対象です。サポートに提供した内容以外のチャット、パスワード、認証情報は対象外と説明しています。","en":"Support data and some identity images were affected; Discord said other chats, passwords, and authentication data were not involved."},"status":"confirmed","sourceIds":["s1"],"locator":"What data was involved? / What data was not involved?"}],"timeline":[{"date":"2025-10-03","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"委託先のチケットシステムへのアクセスを失効させ、外部の調査会社を起用し、影響を受けた利用者への通知を進めると公表しました。","en":"Discord revoked provider access, engaged forensic specialists, and reported notifying affected users."},"status":"confirmed","sourceIds":["s1"],"locator":"TL;DR / What are we doing about this?"}],"prevention":{"classification":"unknown","assessment":{"ja":"委託先が取得できるチケットと添付書類、アクセスログ、本人確認画像の保存期間を点検します。委託先への初回侵入手法は、この発表だけでは判断できません。","en":"Inspect provider ticket permissions, attachment access logs, and identity-image retention; this notice does not establish the initial entry technique."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"委託先の侵入原因、具体的な脆弱性と流出人数は未確定です。委託先への原因帰属はDiscordの発表に基づきます。","en":"Initial cause, specific vulnerabilities, and confirmed victim count are unresolved; provider attribution reflects Discord’s statement."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Update on a Security Incident Involving Third-Party Customer Service","url":"https://discord.com/press-releases/update-on-security-incident-involving-third-party-customer-service","publisher":"Discord","publishedAt":"2025-10-03","kind":"organization"}],"ruleIds":["SEC-008","SEC-009","SEC-012"]}} {"kind":"incident","id":"equifax-2017","hash":"0954c174783b7f496ec4a924a31369007b98b19efba85df4a6f8e54c2dfa7e5d","record":{"id":"equifax-2017","title":{"ja":"Equifax:未修正のApache Strutsから侵入","en":"Equifax: unpatched Apache Struts"},"organization":"Equifax","summary":{"ja":"既知のApache Struts脆弱性がオンライン異議申立てサイトで悪用され、個人情報が流出しました。更新指示があっても、適用の確認が必要だった事例です。","en":"A known Apache Struts vulnerability in the online dispute portal enabled theft of personal information. Patch instructions needed verification of actual deployment."},"occurredAt":"2017-05-13","disclosedAt":"2017-09-07","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["known-vulnerability"],"cves":["CVE-2017-5638"],"claims":[{"topic":"entry","text":{"ja":"Apache StrutsのCVE-2017-5638が侵入に使われました。","en":"CVE-2017-5638 in Apache Struts was the entry vector."},"status":"confirmed","sourceIds":["s1"],"locator":"Attack vector"},{"topic":"control","text":{"ja":"脆弱性は組織に通知されていましたが、対象のサイトに修正が適用されていませんでした。","en":"The organization had been notified, but the affected portal remained unpatched."},"status":"confirmed","sourceIds":["s2"],"locator":"GAO-18-559, p. 15: Identification"}],"timeline":[{"date":"2017-07-29","text":{"ja":"不審なネットワーク通信を検出。","en":"Suspicious network traffic detected."},"sourceIds":["s1"]},{"date":"2017-09-07","text":{"ja":"事故を公表。","en":"Breach disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"containment","text":{"ja":"対象のWebアプリケーションを停止し、調査と対策を実施しました。","en":"The affected web application was taken offline for investigation and mitigation."},"status":"confirmed","sourceIds":["s1"],"locator":"本文 / Main text"}],"prevention":{"classification":"patch-available","assessment":{"ja":"事前に知られていた脆弱性です。更新の通知から実際の稼働バージョン確認までを一つの点検として扱います。","en":"The vulnerability was known beforehand. Track patch notification through verification of the running version."},"sourceIds":["s1","s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"この要約だけでは、当時の全資産の状態や担当者ごとの判断は評価できません。","en":"This summary cannot assess every asset or individual decision at the time."}],"sources":[{"id":"s1","title":"Equifax Releases Details on Cybersecurity Incident","url":"https://investor.equifax.com/news-events/press-releases/detail/237/equifax-releases-details-on-cybersecurity-incident","publisher":"Equifax","kind":"organization","publishedAt":"2017-09-15","reviewedAt":"2026-10-02"},{"id":"s2","title":"Data Protection: Actions Taken in Response to the 2017 Breach","url":"https://www.gao.gov/assets/gao-18-559.pdf","publisher":"U.S. GAO","kind":"government","publishedAt":"2018-08-30","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-001"]}} {"kind":"incident","id":"forticloud-sso-2026","hash":"0a7f90420b23c4dfb973bdcaff05e36e1eb84dc5c20fa128b3a09de3ba9ff80b","record":{"id":"forticloud-sso-2026","organization":"Fortinet / FortiCloud SSO users","title":{"ja":"FortiCloud SSO:修正済み機器でも認証を悪用","en":"FortiCloud SSO: abuse on fully patched devices"},"summary":{"ja":"Fortinetは、最新の修正を適用したFortiOSでもFortiCloud SSOから不正ログインされる事案を公表しました。攻撃者による管理者アカウントの作成も確認されています。","en":"Fortinet disclosed FortiCloud SSO abuse affecting fully patched FortiOS and attacker-created administrator accounts."},"occurredAt":null,"disclosedAt":"2026-01-22","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["zero-day","implementation"],"cves":["CVE-2026-24858"],"claims":[{"topic":"entry","text":{"ja":"1月22日時点で最新の修正済み機器への不正SSOログインを確認しました。対象はFortiCloud SSOで、第三者SAML IdP全般ではありません。","en":"Unauthorized SSO logins affected fully patched devices on January 22; the issue concerns FortiCloud SSO, not all third-party SAML IdPs."},"status":"confirmed","sourceIds":["s1"],"locator":"Update Jan 22 / Update Jan 28"},{"topic":"vulnerability","text":{"ja":"Fortinetが登録したCVE-2026-24858はFortiCloud SSOの認証回避を扱います。","en":"The Fortinet-submitted CVE-2026-24858 describes FortiCloud SSO authentication bypass."},"status":"confirmed","sourceIds":["s2"],"locator":"Description / vendor references"}],"timeline":[{"date":"2026-01-22","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"Fortinetは不正なクラウドアカウントの無効化、SSOの停止、修正版への接続制限を公表しました。","en":"Fortinet reported disabling malicious cloud accounts, suspending SSO, and restricting connections to patched versions."},"status":"confirmed","sourceIds":["s1"],"locator":"Updates Jan 22–30"}],"prevention":{"classification":"pre-disclosure-exploitation","assessment":{"ja":"公表前の悪用を含みます。更新に加え、FortiCloud SSOの使用状況と管理者の追加履歴を確認します。","en":"Exploitation preceded disclosure. Inspect FortiCloud SSO use and administrator creation in addition to patching."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"各組織への侵入日と被害範囲は不明です。CVEの影響製品・修正版は最新の公式情報で確認します。","en":"Individual intrusion dates and impact are unknown; affected products and fixes require current vendor guidance."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Analysis of SSO abuse on FortiOS","url":"https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios","publisher":"Fortinet","publishedAt":"2026-01-22","kind":"vendor"},{"id":"s2","reviewedAt":"2026-10-02","title":"CVE-2026-24858","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24858","publisher":"NIST / Fortinet","publishedAt":null,"kind":"government"}],"ruleIds":["SEC-001","SEC-002","SEC-005","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"gainsight-oauth-2025","hash":"6ae22e8b926ab069ccfd74df1b7d2ab4ca50731bf2e538e801468489502b486f","record":{"id":"gainsight-oauth-2025","organization":"Gainsight–Salesforce連携の顧客環境","title":{"ja":"Gainsight連携:古いOAuthトークンを顧客環境へのアクセスに悪用","en":"Gainsight integration: old OAuth tokens reused against customer environments"},"summary":{"ja":"攻撃者は、古い連携トークンの有効性を調べ、失効されていないものをSalesforce APIへのアクセスに使いました。トークンを最初に取得した経路は特定されていません。","en":"Attackers tested old integration tokens and used still-valid credentials against Salesforce APIs. The original acquisition path is unidentified."},"occurredAt":"2025-10-22","disclosedAt":"2025-11-20","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"10月22日にトークンを検証し、11月16〜19日に顧客のSalesforce環境でAPIを呼び出したと報告しています。Gainsight環境への同時期の侵入を示すものではありません。","en":"Gainsight reports token validation on October 22 and customer Salesforce API calls on November 16–19, without corresponding recent access to Gainsight systems."},"status":"confirmed","sourceIds":["s2"],"locator":"Analyzing the Token Usage"},{"topic":"cause","text":{"ja":"最も新しいトークンも2023年8月発行でした。調査元は漏えい元を特定できず、失効や更新まで長期間有効な設計を問題として説明しています。","en":"Even the newest token dated to August 2023. Investigators could not identify the leak source; Gainsight identifies long-lived validity as a systemic issue."},"status":"confirmed","sourceIds":["s2"],"locator":"Analyzing the Token Origin / At the Root of the Issue"}],"timeline":[{"date":"2025-11-20","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"全システムの資格情報を更新し、古い鍵を削除しました。連携トークンの頻繁な更新、単回使用の更新トークン、接続元制限、PKCEを導入したと公表しました。","en":"Gainsight reported credential rotation, stale-key removal, frequent token refresh, single-use refresh tokens, trusted IP restrictions, and PKCE."},"status":"confirmed","sourceIds":["s2"],"locator":"Immediate Remediation / OAuth Token Lifecycle Management"}],"prevention":{"classification":"operational-control","assessment":{"ja":"OAuthの有効期限、更新トークンの再利用制御、旧トークンの失効結果を確認します。漏えい元が不明でも、鍵を長期間使い続けられる範囲は点検できます。","en":"Inspect OAuth lifetimes, refresh-token reuse controls, and legacy revocation evidence even when the leak source is unknown."},"sourceIds":["s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"漏えい元と最初の漏えい時期は不明です。古いトークンの再利用を、2025年のGainsight本体への侵入と同一視しません。","en":"The original source and leakage date are unknown; 2025 reuse does not establish a new breach of Gainsight itself."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Salesforce–Gainsight Connected App Incident","url":"https://communities.gainsight.com/community-news-2/salesforce-gainsight-connected-app-incident-29798","publisher":"Gainsight","publishedAt":"2025-11-20","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"How We Accelerated a Year of Security Work in Weeks","url":"https://www.gainsight.com/blog/how-we-accelerated-a-year-of-security-work-in-weeks/","publisher":"Gainsight","publishedAt":"2026-01-02","kind":"organization"}],"ruleIds":["SEC-002","SEC-005","SEC-008","SEC-009"]}} {"kind":"incident","id":"gyazo-2026","hash":"dcfbe0fdc99c01508af80909bf27ebcc40c68ff910badfd997a051e6b57dbbbf","record":{"id":"gyazo-2026","organization":"Helpfeel / Gyazo","title":{"ja":"Gyazo:画像アップロード用サーバーの脆弱性から侵入","en":"Gyazo: upload-server vulnerability and data access"},"summary":{"ja":"画像アップロード用サーバーの脆弱性を悪用され、ユーザー情報と画像メタデータが取得されました。公表されたユーザーレコードには、匿名ユーザーとメール登録者の両方が含まれます。","en":"An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users."},"occurredAt":"2026-09-11","disclosedAt":"2026-09-16","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"9月11日に画像アップロード用サーバーへのコード実行があり、同日夜に検知しました。","en":"Remote code execution affected the image-upload server on September 11 and was detected that evening."},"status":"confirmed","sourceIds":["s2"],"locator":"調査で判明した経緯"},{"topic":"impact","text":{"ja":"ユーザー情報2,362万件と画像メタデータの取得を確認しました。メタデータ件数は画像ファイルの流出件数ではありません。","en":"The company confirmed access to 23.62 million user records and image metadata; metadata counts are not image-file exfiltration counts."},"status":"confirmed","sourceIds":["s2"],"locator":"影響範囲"}],"timeline":[{"date":"2026-09-16","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"脆弱性の修正、接続トークンの失効、停止中の調査を実施し、9月27日にサービスを再開したと公表しました。","en":"Helpfeel reported patching, token revocation, investigation during suspension, and service resumption on September 27."},"status":"confirmed","sourceIds":["s2"],"locator":"対応状況 / 9月27日追記"}],"prevention":{"classification":"unknown","assessment":{"ja":"修正提供時期が不明なため、パッチ放置とは判断できません。アップロード処理とDBへ到達する権限、削除済みデータの保持を確認します。","en":"Unknown patch timing prevents a neglect finding; inspect upload handling, database privileges, and deleted-data retention."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"具体的な脆弱性、CVE、侵入前の修正提供状況は不明です。ユーザーレコード数は実人数を意味しません。","en":"Specific vulnerability, CVE, and pre-intrusion patch availability are unknown; user records do not necessarily represent distinct people."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Gyazoにおける不正アクセスに関するお知らせ","url":"https://corp.helpfeel.com/news/news-20260916-1","publisher":"Helpfeel","publishedAt":"2026-09-16","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"Gyazoにおける不正アクセスに関するお知らせ(第2報)","url":"https://corp.helpfeel.com/news/news-20260925-01","publisher":"Helpfeel","publishedAt":"2026-09-25","kind":"organization"}],"ruleIds":["SEC-001","SEC-005","SEC-006","SEC-008","SEC-009","SEC-010","SEC-012"]}} {"kind":"incident","id":"kddi-isp-2026","hash":"1ce489fa2ebf16936851f2918eefafe2e224aa2f546c6a8bb2730d6397cdc41f","record":{"id":"kddi-isp-2026","organization":"KDDI","title":{"ja":"KDDI:第三者ソフトのゼロデイからISP情報が流出","en":"KDDI: ISP data leakage through a third-party zero-day"},"summary":{"ja":"5月16日からソフトウェアの脆弱性を悪用され、ISP利用者の情報が流出しました。KDDIは、6月17日の発見時点で提供元も把握していなかった脆弱性と説明しています。","en":"A software vulnerability exploited from May 16 led to ISP data leakage. KDDI says the vendor was unaware of it when detected on June 17."},"occurredAt":"2026-05-16","disclosedAt":"2026-06-23","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["zero-day"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"悪用は5月16日から始まり、6月17日の発見時点で提供元も未把握の脆弱性でした。","en":"Exploitation began May 16; the vendor was unaware of the vulnerability at June 17 detection."},"status":"confirmed","sourceIds":["s1"],"locator":"3. 発生原因および対応"},{"topic":"impact","text":{"ja":"7月21日の訂正後の対象はメールアドレス1,223万1,954人、うちパスワード流出761万6,173人です。","en":"Corrected July 21 counts are 12,231,954 email-address holders, including 7,616,173 with password leakage."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 情報流出の詳細(7月21日訂正)"}],"timeline":[{"date":"2026-06-23","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"6月17日のシステム修正、EDR導入と、ISPパスワードのリセット対応を公表しました。","en":"KDDI reported a June 17 system fix, EDR deployment, and ISP password reset measures."},"status":"confirmed","sourceIds":["s1"],"locator":"3. 対応 / 4. お願い"}],"prevention":{"classification":"pre-disclosure-exploitation","assessment":{"ja":"公表前の悪用を含みます。依存製品の把握に加え、流出範囲を限定する権限・保存情報・検知を確認します。","en":"Exploitation preceded disclosure; inspect component inventory, privileges, stored information, and detection to limit impact."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"対策でのAI利用は記載されていますが、攻撃者のAI利用は確認できません。","en":"AI is mentioned for defensive measures, not established attacker use."}},"unknowns":[{"ja":"製品名とCVEは非公表です。漏れたパスワードすべての保存形式はこの資料だけでは判断できません。","en":"Product and CVE are undisclosed; this source does not establish a single storage format for every leaked password."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社ISPサービスのお客さま情報の流出について(第2報・訂正)","url":"https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-73_4619/kddi_nr_s-73_4619_pdf_01.pdf","publisher":"KDDI","publishedAt":"2026-07-06","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"当社ISPサービスのお客さま情報の流出について","url":"https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf","publisher":"KDDI","publishedAt":"2026-06-23","kind":"organization"}],"ruleIds":["SEC-001","SEC-005","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"keio-ransomware-2026","hash":"9e6952a807de15004a7784a79fa5e92539203b4cea8c847adb576bcd515eef51","record":{"id":"keio-ransomware-2026","organization":"京王電鉄","title":{"ja":"京王電鉄:グループのサーバーでランサムウェア被害","en":"Keio: ransomware on group servers"},"summary":{"ja":"グループ共通のサーバーでランサムウェア感染が確認され、一部の業務システムに影響が出ました。公表時点では鉄道運行への影響と情報流出は確認されていません。","en":"Ransomware on group servers affected some business systems; rail operations and information leakage were not reported as affected at disclosure."},"occurredAt":null,"disclosedAt":"2026-09-26","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"impact","text":{"ja":"9月26日未明にランサムウェア感染を確認しました。鉄道の運行には影響していません。","en":"Ransomware was confirmed early September 26 without affecting rail operations."},"status":"confirmed","sourceIds":["s1"],"locator":"1. 概要"},{"topic":"entry","text":{"ja":"侵入原因と経路を外部専門家と調査しています。情報流出も公表時点では未確認です。","en":"Entry cause and route are under external investigation; leakage was unconfirmed at publication."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 現在の状況"}],"timeline":[{"date":"2026-09-26","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"被害拡大を防ぐためネットワークを遮断し、調査を開始したと公表しました。","en":"Keio reported disconnecting networks and starting an investigation to contain impact."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 現在の状況"}],"prevention":{"classification":"unknown","assessment":{"ja":"侵入原因は判断できません。共通システムの依存関係、隔離手順、復元できるバックアップを点検します。","en":"The entry cause is unknown; inspect shared-system dependencies, containment procedures, and restorable backups."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"9月26日は感染確認日です。侵入開始日、原因、CVE、情報流出、復旧の全範囲は確定できません。","en":"September 26 is detection, not an established intrusion start; cause, CVE, leakage, and full recovery scope remain unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"不正アクセスによるシステム障害の発生について","url":"https://www.keio.co.jp/news/update/announce/nr260926v13404/","publisher":"京王電鉄","publishedAt":"2026-09-26","kind":"organization"}],"ruleIds":["SEC-009","SEC-013"]}} {"kind":"incident","id":"metabase-2026","hash":"053252ba1c260199433f8a2d6153668f9bde48f01bc0164cb9a05c534d6404f5","record":{"id":"metabase-2026","organization":"Metabase / affected customers","title":{"ja":"Metabase:ゼロデイと管理者セッションからデータ取得","en":"Metabase: zero-day and administrator-session abuse"},"summary":{"ja":"Metabaseは8月3日の異常なAPIキー利用を調査し、未知の脆弱性を使った侵入を確認しました。入力処理とORMの挙動がつながり、管理者セッションを得た攻撃者がデータを取得しました。","en":"Metabase investigated abnormal API-key activity on August 3 and confirmed zero-day exploitation. Input handling and ORM behavior enabled administrator sessions and data access."},"occurredAt":null,"disclosedAt":"2026-08-06","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["zero-day","implementation"],"cves":["CVE-2026-72898"],"claims":[{"topic":"entry","text":{"ja":"過剰な入力キー、パスワードリセット処理、SQL式を受け付けるORMの挙動が攻撃経路につながりました。","en":"Extra input keys, password-reset handling, and ORM acceptance of SQL expressions formed the exploit chain."},"status":"confirmed","sourceIds":["s1"],"locator":"Technical root cause"},{"topic":"impact","text":{"ja":"同社クラウドの顧客の3%未満と、一部の公開された自己運用環境で侵害を確認しました。","en":"Metabase confirmed compromise of fewer than 3% of cloud customers and some publicly exposed self-hosted installations."},"status":"confirmed","sourceIds":["s1"],"locator":"Scope of impact"},{"topic":"ai","text":{"ja":"複数のコード上の挙動とUser-Agentを根拠に、開発元は高度なLLMが関与した可能性を示しています。","en":"The developer assesses advanced LLM involvement based on code-path complexity and User-Agent evidence."},"status":"inferred","sourceIds":["s1"],"locator":"Was this AI?"},{"topic":"vulnerability","text":{"ja":"開発元のアドバイザリは、認証不要のSQLインジェクションと管理者権限の取得をCVE-2026-72898として公表しています。","en":"The vendor advisory identifies unauthenticated SQL injection enabling administrator access as CVE-2026-72898."},"status":"confirmed","sourceIds":["s3"],"locator":"Summary / CVE ID"}],"timeline":[{"date":"2026-08-06","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"クラウドの修正、自己運用向けの修正版、入力とSQL式の扱いの強化を公表しました。","en":"Metabase reported cloud fixes, patched self-hosted releases, and hardened input and SQL-expression handling."},"status":"confirmed","sourceIds":["s1"],"locator":"Remediation"}],"prevention":{"classification":"pre-disclosure-exploitation","assessment":{"ja":"公表前の悪用を含みます。BIの公開範囲、APIキー、取得権限を確認し、自社実装では入力の許可リストとSQL式の境界を点検します。","en":"Exploitation preceded disclosure. Inspect BI exposure, API keys, and data privileges; inspect input allowlists and SQL-expression boundaries in owned code."},"sourceIds":["s1"]},"ai":{"status":"inferred","assessment":{"ja":"開発元はLLM関与を推定していますが、攻撃者のモデルや利用実態を確認した報告ではありません。","en":"The developer infers LLM involvement without confirming the attacker’s model or actual usage."}},"unknowns":[{"ja":"AI関与は開発元の推定です。自己運用環境の被害総数と個別の侵入開始日は不明です。","en":"AI attribution is the developer’s assessment; total self-hosted impact and individual intrusion starts are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Vulnerability: what happened","url":"https://www.metabase.com/blog/vulnerability-what-happened","publisher":"Metabase","publishedAt":"2026-08-27","kind":"vendor"},{"id":"s2","reviewedAt":"2026-10-02","title":"Security update, 6 Aug 2026","url":"https://www.metabase.com/blog/security-update-6-aug-2026","publisher":"Metabase","publishedAt":"2026-08-06","kind":"vendor"},{"id":"s3","title":"SQL injection using an unauthenticated endpoint leading to admin access","url":"https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf","publisher":"Metabase","kind":"vendor","publishedAt":"2026-08-06","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-001","SEC-005","SEC-006","SEC-008","SEC-009","SEC-010"]}} {"kind":"incident","id":"moveit-2023","hash":"45b350a8a188702b74a004f233526410807f88335b0bca600f2fdba3d548bfef","record":{"id":"moveit-2023","title":{"ja":"MOVEit:公開前のSQLインジェクション悪用","en":"MOVEit: SQL injection exploited before disclosure"},"organization":"Progress MOVEit customers","summary":{"ja":"MOVEit TransferのSQLインジェクション脆弱性が、公表前から悪用されました。調査ではWebシェルの設置とデータ窃取が確認され、更新だけでなく侵害調査が必要でした。","en":"A MOVEit Transfer SQL injection vulnerability was exploited before disclosure. Investigators observed web shells and data theft, requiring investigation alongside updates."},"occurredAt":"2023-05-27","disclosedAt":"2023-05-31","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["zero-day","implementation"],"cves":["CVE-2023-34362"],"claims":[{"topic":"entry","text":{"ja":"調査で確認された最も早い悪用の証拠は2023年5月27日でした。","en":"The earliest exploitation evidence in Mandiant response engagements was May 27, 2023."},"status":"confirmed","sourceIds":["s1"],"locator":"Overview"},{"topic":"weakness","text":{"ja":"製品のSQLインジェクション脆弱性はCVE-2023-34362として公表されました。","en":"The product SQL injection vulnerability was identified as CVE-2023-34362."},"status":"confirmed","sourceIds":["s2"],"locator":"CVE-2023-34362"}],"timeline":[{"date":"2023-05-27","text":{"ja":"調査で確認された悪用の証拠。","en":"Earliest observed exploitation in the cited investigation."},"sourceIds":["s1"]},{"date":"2023-05-31","text":{"ja":"開発元が脆弱性を公表。","en":"Vendor disclosed the vulnerability."},"sourceIds":["s3"]}],"reportedActions":[{"topic":"guidance","text":{"ja":"開発元は利用者に緩和策と修正版の適用を案内しました。","en":"The vendor supplied mitigation and patch guidance to customers."},"status":"confirmed","sourceIds":["s3"],"locator":"Customer response"}],"prevention":{"classification":"pre-disclosure-exploitation","assessment":{"ja":"公表前の侵害に、後から公開されたパッチを適用できなかった責任は付けられません。公開範囲の制限と侵害時の調査・復旧も点検します。","en":"A later patch cannot prevent an earlier compromise. Inspect exposure controls and incident investigation and recovery paths."},"sourceIds":["s1","s2","s3"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"個別の被害組織がいつ侵害されたかは一様ではありません。自社実装のSQL注入と製品側の欠陥を区別します。","en":"Victim timelines vary. Distinguish a vendor defect from SQL injection in your own code."}],"sources":[{"id":"s1","title":"Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft","url":"https://cloud.google.com/blog/topics/threat-intelligence/zero-day-moveit-data-theft","publisher":"Mandiant","kind":"investigator","publishedAt":"2023-06-02","reviewedAt":"2026-10-02"},{"id":"s2","title":"CVE-2023-34362 Detail","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34362","publisher":"NIST NVD","kind":"government","publishedAt":"2023-06-02","reviewedAt":"2026-10-02"},{"id":"s3","title":"An Update on the Steps We are Taking to Protect MOVEit Customers","url":"https://www.progress.com/blogs/update-steps-we-are-taking-protect-moveit-customers","publisher":"Progress","kind":"vendor","publishedAt":null,"reviewedAt":"2026-10-02"}],"ruleIds":["SEC-001","SEC-006","SEC-010"]}} {"kind":"incident","id":"nidek-website-2026","hash":"ccd806ce45a04c06b083881c61fbaec18e1ed24c2a721b9d7de02493c77f4c62","record":{"id":"nidek-website-2026","organization":"ニデック(医療機器・NIDEK)","title":{"ja":"ニデック(医療機器):Webサイトで使うソフトの脆弱性を悪用","en":"NIDEK medical devices: website software vulnerability exploited"},"summary":{"ja":"同社は、Webサイトのソフトウェアの脆弱性を悪用されたと説明しています。会員や問い合わせ情報へのアクセスの可能性がありますが、参照したFAQでは外部への流出は未確認です。","en":"NIDEK reported exploitation of website software. Member and inquiry data may have been accessed; the cited FAQ does not confirm external disclosure."},"occurredAt":"2026-07-20","disclosedAt":"2026-07-24","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"7月20日午前1時ごろ(日本時間)の初回不正アクセスと、7月24日の検知を報告しています。原因はサイトで使うソフトウェアの脆弱性と説明しています。","en":"The FAQ dates initial access to around 01:00 JST on July 20 and detection to July 24, and identifies a website-software vulnerability."},"status":"confirmed","sourceIds":["s2"],"locator":"FAQ Q1 / Q3 / Q14"},{"topic":"impact","text":{"ja":"会員情報と問い合わせ情報がアクセス対象となった可能性があります。約28,000会員は影響を受けた可能性のある範囲で、流出確定人数ではありません。","en":"Member and inquiry information was potentially affected; approximately 28,000 members is a potential-impact figure, not confirmed exfiltration."},"status":"confirmed","sourceIds":["s2"],"locator":"FAQ Q2 / Q7 / Q17"}],"timeline":[{"date":"2026-07-24","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"検知日にソフトウェアを更新し、専門家と調査しています。過去の問い合わせ情報はサイトから削除し、調査・保護措置のため別の場所で保持すると説明しています。","en":"NIDEK patched on detection and engaged specialists. Historical inquiries were removed from the website but retained separately for investigation and safeguards."},"status":"confirmed","sourceIds":["s2"],"locator":"FAQ Q4 / Q10 / Q14"}],"prevention":{"classification":"unknown","assessment":{"ja":"ソフトの稼働版と更新記録、問い合わせ情報の保持先と削除条件を点検します。侵入前の修正提供時期が不明なため、パッチ放置とは判断できません。","en":"Inspect deployed versions, update records, and inquiry-data retention; unknown pre-intrusion patch timing prevents a neglect finding."},"sourceIds":["s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"製品名、CVE、修正提供時期、流出の確定範囲は参照資料から特定できません。NIDEKはモーター企業のNIDECとは別会社です。","en":"Product, CVE, patch timing, and confirmed leakage scope are unspecified; NIDEK is distinct from motor manufacturer NIDEC."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社Webサイトへの不正アクセスに関するお知らせ","url":"https://www.nidek.co.jp/news/20260724_news/","publisher":"NIDEK","publishedAt":"2026-07-24","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"FAQ Regarding Unauthorized Access to Our Website","url":"https://www.nidek-intl.com/information/customer_faq/","publisher":"NIDEK","publishedAt":"2026-08-19","kind":"organization"}],"ruleIds":["SEC-001","SEC-006","SEC-009","SEC-012"]}} {"kind":"incident","id":"nishiyama-2026","hash":"68eb5c7416f2f56fd3f4f2ac4fa0687e7d61f69d46847577f531c1ce0af5304a","record":{"id":"nishiyama-2026","organization":"西山製作所","title":{"ja":"西山製作所:VPNの脆弱性と認証情報を悪用","en":"Nishiyama: VPN vulnerability and account abuse"},"summary":{"ja":"同社は、VPNの脆弱性と特定のアカウント情報を悪用した侵入を報告しました。データの暗号化や流出への対応として、VPNの廃止と環境の初期化を公表しています。","en":"The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization."},"occurredAt":null,"disclosedAt":"2026-02-13","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"侵入にはVPNの脆弱性と特定のアカウント情報が悪用されたと公表しました。","en":"The company reported abuse of a VPN vulnerability and specific account information."},"status":"confirmed","sourceIds":["s1"],"locator":"調査結果"},{"topic":"impact","text":{"ja":"一部データの復元は困難で、流出情報の監視を継続すると公表しました。","en":"Some data could not be restored; monitoring for leaked information continued."},"status":"confirmed","sourceIds":["s1"],"locator":"復旧状況 / 情報流出"}],"timeline":[{"date":"2026-02-13","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"VPNの廃止、認証情報の更新、端末・サーバーの初期化、バックアップ方式の変更を公表しました。","en":"The company reported removing the VPN, credential resets, reinitialization, and backup changes."},"status":"confirmed","sourceIds":["s1"],"locator":"再発防止策"}],"prevention":{"classification":"unknown","assessment":{"ja":"製品や修正時期が不明なため、パッチ放置とは判断できません。VPNの稼働情報、認証情報、バックアップを確認します。","en":"Undisclosed product and patch timing prevent a neglect finding. Inspect VPN deployment, credentials, and backups."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"VPN製品名、CVE、悪用前の修正提供状況、認証情報の流出元は不明です。","en":"VPN product, CVE, pre-attack patch availability, and credential origin are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"サイバー攻撃に関するお知らせ(第3報)","url":"https://www.nishiyama-ss.co.jp/asset/pdf/20260403_CyberAttack3.pdf","publisher":"西山製作所","publishedAt":"2026-04-03","kind":"organization"}],"ruleIds":["SEC-001","SEC-002","SEC-005","SEC-006","SEC-009","SEC-013"]}} {"kind":"incident","id":"okta-support-2023","hash":"ce2a745c071cd0822922d4da150d4c8c22b9b85503b2fc9041c1761718ea25de","record":{"id":"okta-support-2023","title":{"ja":"Okta:サポート添付ファイルのセッション情報を悪用","en":"Okta: support attachments enabled session hijacking"},"organization":"Okta","summary":{"ja":"盗まれたサービスアカウントでサポートシステム内のファイルへアクセスされました。HARファイル内のセッショントークンが、一部顧客への侵入に使われました。","en":"A compromised service account accessed support files. Session tokens in HAR attachments enabled hijacking of some customer sessions."},"occurredAt":"2023-09-28","disclosedAt":"2023-10-20","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","endpoint"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"サポート用サービスアカウントが悪用され、HAR等の添付ファイルにアクセスされました。","en":"A support service account was abused to access attachments, including HAR files."},"status":"confirmed","sourceIds":["s1"],"locator":"Executive Summary"},{"topic":"origin","text":{"ja":"個人Googleアカウントへの認証情報の保存が確認され、個人アカウントか端末の侵害が有力な流出経路と説明されました。","en":"Credentials were saved in a personal Google account; compromise of that account or device was assessed as the most likely leak path."},"status":"inferred","sourceIds":["s1"],"locator":"Executive Summary"},{"topic":"impact","text":{"ja":"盗まれたセッショントークンで5顧客のセッションが乗っ取られたと公表しました。","en":"Okta reported session hijacking affecting five customers."},"status":"confirmed","sourceIds":["s1"],"locator":"Executive Summary"}],"timeline":[{"date":"2023-09-28","text":{"ja":"公表された不正アクセス期間の開始。","en":"Start of the disclosed unauthorized access period."},"sourceIds":["s1"]},{"date":"2023-10-17","text":{"ja":"サービスアカウント停止と関連セッション失効。","en":"Service account disabled and associated sessions terminated."},"sourceIds":["s1"]},{"date":"2023-10-20","text":{"ja":"事故を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"個人Chromeプロファイルへのログイン制限と監視強化を実施しました。","en":"Personal Chrome profile sign-in was restricted and monitoring strengthened."},"status":"confirmed","sourceIds":["s1"],"locator":"Remediation Tasks"}],"prevention":{"classification":"operational-control","assessment":{"ja":"サポート用ファイルも秘密情報の持ち出し経路です。添付前の除去と、漏洩したセッションの失効を点検します。","en":"Support attachments are a credential exposure path. Inspect sanitization and revocation of exposed sessions."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"サービスアカウントの資格情報が流出した具体的な経路は、参照した原因報告でも推定です。","en":"The precise credential leak path remains an assessment in the cited root-cause report."}],"sources":[{"id":"s1","title":"Unauthorized Access to Okta Support: Root Cause and Remediation","url":"https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/","publisher":"Okta","kind":"organization","publishedAt":"2023-11-03","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-003","SEC-004","SEC-005","SEC-009"]}} {"kind":"incident","id":"openai-huggingface-eval-2026","hash":"03227e077cca0327d2bac49a95735ea95166b1b5de15e2c64af2b8e36be565c0","record":{"id":"openai-huggingface-eval-2026","organization":"OpenAI / Hugging Face","title":{"ja":"OpenAI・Hugging Face:評価用AIが外部へ侵入","en":"OpenAI / Hugging Face: evaluation agent reached external systems"},"summary":{"ja":"評価中のOpenAI試作モデルが、制限されたパッケージ接続を足がかりに外部へ到達しました。OpenAIは、未知の脆弱性を使った認証情報の取得とHugging Faceへの侵入を公表しています。","en":"An OpenAI prototype under evaluation used restricted package connectivity to reach external systems. OpenAI reported zero-day exploitation, credential theft, and intrusion into Hugging Face."},"occurredAt":null,"disclosedAt":"2026-07-16","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["zero-day","credentials","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"試作モデルは許可されたパッケージ接続経由でArtifactoryのゼロデイを悪用し、外部へ到達しました。","en":"The prototype exploited an Artifactory zero-day through permitted package connectivity to reach the internet."},"status":"confirmed","sourceIds":["s1"],"locator":"Incident account / technical investigation"},{"topic":"impact","text":{"ja":"認証情報を取得し、複数の脆弱性をつないでHugging Faceの環境へ侵入しました。","en":"It obtained credentials and chained vulnerabilities to enter Hugging Face infrastructure."},"status":"confirmed","sourceIds":["s1"],"locator":"Incident account / updates"},{"topic":"ai","text":{"ja":"OpenAIは、自社の評価中の試作モデルによる行動だったと確認しました。","en":"OpenAI confirmed that its prototype under evaluation performed the actions."},"status":"confirmed","sourceIds":["s1"],"locator":"Incident account"}],"timeline":[{"date":"2026-07-16","text":{"ja":"Hugging Faceが侵入を公表。","en":"Hugging Face disclosed the intrusion."},"sourceIds":["s2"]},{"date":"2026-07-21","text":{"ja":"OpenAIが評価モデルの関与を公表。","en":"OpenAI disclosed evaluation-model involvement."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"OpenAIは試作モデルの停止と外部レビューを、Hugging Faceは修正・環境再構築・鍵の失効を公表しました。","en":"OpenAI reported disabling the prototype and external review; Hugging Face reported fixes, rebuilding, and credential revocation."},"status":"confirmed","sourceIds":["s1","s2"],"locator":"OpenAI mitigations / Hugging Face What we did"}],"prevention":{"classification":"pre-disclosure-exploitation","assessment":{"ja":"公表前の悪用を含みます。評価用AIのネットワーク境界は、宣言した制限だけでなく実際の接続経路と権限で検証します。","en":"Exploitation preceded disclosure; verify actual evaluation-agent network routes and privileges, rather than relying on declared limits."},"sourceIds":["s1"]},"ai":{"status":"confirmed","assessment":{"ja":"OpenAIが評価モデルの関与を確認しています。犯罪者による利用事例ではありません。","en":"OpenAI confirmed evaluation-model involvement; this is not a criminal-use example."}},"unknowns":[{"ja":"評価試験の逸脱であり、犯罪者によるAI攻撃とは別に扱います。各脆弱性とCVEの対応関係はこの記録で確定しません。","en":"Treat this evaluation escape separately from criminal AI use. This record does not establish every vulnerability-to-CVE mapping."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Hugging Face model evaluation security incident","url":"https://openai.com/index/hugging-face-model-evaluation-security-incident/","publisher":"OpenAI","publishedAt":"2026-07-21","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"Security incident disclosure — July 2026","url":"https://huggingface.co/blog/security-incident-july-2026","publisher":"Hugging Face","publishedAt":"2026-07-16","kind":"organization"},{"id":"s3","reviewedAt":"2026-10-02","title":"Agent intrusion: technical timeline","url":"https://huggingface.co/blog/agent-intrusion-technical-timeline","publisher":"Hugging Face","publishedAt":"2026-07-27","kind":"organization"}],"ruleIds":["SEC-001","SEC-004","SEC-005","SEC-006","SEC-008","SEC-009","SEC-011"]}} {"kind":"incident","id":"openai-mixpanel-2025","hash":"0b6f0fec769375ab00c2d6bb0b62379ea04ead5b1745d6db3490b0b8987d7cf5","record":{"id":"openai-mixpanel-2025","organization":"Mixpanel / OpenAI利用者の解析データ","title":{"ja":"Mixpanel:SMSを使うフィッシングと解析データの持ち出し","en":"Mixpanel: smishing and analytics-data export affecting OpenAI users"},"summary":{"ja":"MixpanelはSMSを使うフィッシングへの対応を公表し、OpenAIは委託先から利用者の解析データが持ち出されたと説明しました。OpenAIによると、パスワードやAPIキー、チャット内容は対象外です。","en":"Mixpanel reported a smishing incident; OpenAI reported export of user analytics data from the supplier. OpenAI says passwords, API keys, and chat content were not involved."},"occurredAt":null,"disclosedAt":"2025-11-26","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","supply-chain"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"Mixpanelは11月8日にSMSを使うフィッシングを検知したと説明しています。OpenAIは、Mixpanelで解析データを含むデータセットが持ち出されたと公表しています。","en":"Mixpanel dates smishing detection to November 8; OpenAI reports export of a dataset containing analytics data from Mixpanel."},"status":"confirmed","sourceIds":["s1","s2"],"locator":"Mixpanel: introduction / OpenAI: What happened"},{"topic":"impact","text":{"ja":"氏名、メールアドレス、概略の位置情報などが対象です。OpenAIの12月19日追記では、一部のChatGPT利用者も対象に含むと明確化しています。APIキーや会話内容の流出とは区別します。","en":"Potentially affected data includes names, emails, and coarse locations; a December 19 clarification also includes some ChatGPT users, without API-key or chat-content exposure."},"status":"confirmed","sourceIds":["s1"],"locator":"December 19 clarification / What this means for you"}],"timeline":[{"date":"2025-11-26","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"Mixpanelはセッションの失効、資格情報の更新、認証・出力ログの調査を実施しました。OpenAIはMixpanelの本番利用を停止し、契約先の点検を拡大したと公表しました。","en":"Mixpanel revoked sessions, rotated credentials, and reviewed logs; OpenAI ended production use of Mixpanel and expanded supplier reviews."},"status":"confirmed","sourceIds":["s1","s2"],"locator":"Mixpanel: What we did in response / OpenAI: Our response"}],"prevention":{"classification":"operational-control","assessment":{"ja":"SMSからの偽ログインとセッション失効の手順を点検します。解析先へ送る識別情報の必要性、取得・出力権限、保存期間も確認します。","en":"Inspect resistance to SMS-led fake logins and session revocation, plus analytics identifiers, export permissions, and retention."},"sourceIds":["s1","s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"SMS経由の侵入の詳細、初回侵入日時、影響人数は参照資料から確定できません。11月8日と9日はそれぞれの公表元による検知・認知の日で、初回侵入日とは扱いません。","en":"Exact entry mechanics, initial access date, and victim count are unspecified. November 8 and 9 are provider-specific detection/awareness dates rather than assigned entry dates."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"What to know about a recent Mixpanel security incident","url":"https://openai.com/index/mixpanel-incident/","publisher":"OpenAI","publishedAt":"2025-11-26","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"Our response to a recent security incident","url":"https://mixpanel.com/blog/sms-security-incident/","publisher":"Mixpanel","publishedAt":"2025-11-27","kind":"organization"}],"ruleIds":["SEC-002","SEC-003","SEC-005","SEC-008","SEC-009","SEC-012"]}} {"kind":"incident","id":"postman-shai-hulud-2025","hash":"f8b1047dbd4c170d0117eafc65394441c2892db067107bafdc7a1c86abf7ea6a","record":{"id":"postman-shai-hulud-2025","organization":"Postman","title":{"ja":"Postman:依存パッケージ経由でCIの公開用トークンを悪用","en":"Postman: poisoned dependencies exposed CI publishing authority"},"summary":{"ja":"Postmanは、適切なlockfileのないCIが感染済みの依存パッケージを取り込み、npm公開用トークンを悪用されたと公表しました。17パッケージの改ざんを公表し、本番アプリと顧客データは影響を受けなかったと説明しています。","en":"A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected."},"occurredAt":null,"disclosedAt":"2025-11-24","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["supply-chain","credentials","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"GitHub Actionsのビルドが感染したAsyncAPIパッケージを取得しました。ビルドの公開用トークンと、17パッケージで未設定だったトークン公開禁止・二要素認証の条件が悪用されました。","en":"GitHub Actions installed infected AsyncAPI packages; a publishing token could publish to 17 packages lacking the disallow-tokens/two-factor setting."},"status":"confirmed","sourceIds":["s1"],"locator":"How did it happen?"},{"topic":"impact","text":{"ja":"17の公開npmパッケージに感染版が配布されました。Postmanは環境分離により本番システムと顧客データへの到達はなかったと説明しています。","en":"Infected versions of 17 public npm packages were distributed; Postman attributes production and customer-data isolation to segmented environments."},"status":"confirmed","sourceIds":["s1"],"locator":"What happened?"}],"timeline":[{"date":"2025-11-24","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"悪用されたアカウントの全トークンを失効させ、感染版を削除しました。公開権限の制限、OIDCのTrusted Publishers、lockfileの点検を実施したと公表しました。","en":"Postman revoked the account’s tokens, removed infected versions, restricted publishing access, enabled OIDC Trusted Publishers, and began checking lockfiles."},"status":"confirmed","sourceIds":["s1"],"locator":"How did it happen? / What we have already done"}],"prevention":{"classification":"operational-control","assessment":{"ja":"lockfileの存在と固定インストール、外部コードを実行するジョブの公開権限、長期トークンの必要性を点検します。lockfileだけで依存コードの安全性を保証はできません。","en":"Inspect lockfiles, frozen installs, CI publishing authority, and long-lived tokens; lockfiles alone do not establish dependency safety."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"Postmanの報告対象は同社のパッケージです。Shai-Hulud全体の被害件数と合算しません。時刻は原文のPT表記で、初回侵入のUTC日付はここでは確定していません。","en":"This record covers Postman packages rather than the whole campaign. Source timestamps use PT; an initial-entry UTC date is not assigned here."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Root Cause Analysis: Shai-Hulud 2.0","url":"https://blog.postman.com/engineering/root-cause-analysis-shai-halud-2-0/","publisher":"Postman","publishedAt":"2025-12-04","kind":"organization"}],"ruleIds":["SEC-001","SEC-004","SEC-005","SEC-007","SEC-008","SEC-009"]}} {"kind":"incident","id":"prontest-cloud-2026","hash":"2bb95e8ef1b4820d690fa35891f56e2cc7fbc8cdcc29a17ec2ee372684795dca","record":{"id":"prontest-cloud-2026","organization":"Prontest","title":{"ja":"Prontest:クラウドの計算資源を不正利用","en":"Prontest: unauthorized cloud compute use"},"summary":{"ja":"クラウド環境への不正アクセスにより、計算資源が不正利用されました。同社は、外部に公開した管理サーバーの脆弱性が原因だった可能性が高いと説明しています。","en":"Unauthorized cloud access enabled compute misuse. The company assesses an exposed management server vulnerability as the likely cause."},"occurredAt":null,"disclosedAt":"2026-04-09","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"公開された管理サーバーの脆弱性が侵入原因だった可能性が高いと報告しました。","en":"An exposed management server vulnerability was assessed as the likely entry point."},"status":"inferred","sourceIds":["s1"],"locator":"原因"},{"topic":"impact","text":{"ja":"計算資源の不正利用を確認しました。データベースへのアクセスや個人情報の悪用は確認されていません。","en":"Compute misuse was confirmed; database access or personal-information misuse was not observed."},"status":"confirmed","sourceIds":["s1"],"locator":"調査結果"}],"timeline":[{"date":"2026-04-09","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"不正資源の停止・削除、認証情報の再発行、MFAと監視の強化を公表しました。","en":"Prontest reported stopping and deleting abused resources, credential reissuance, and stronger MFA and monitoring."},"status":"confirmed","sourceIds":["s1"],"locator":"実施済みの対策"}],"prevention":{"classification":"unknown","assessment":{"ja":"侵入原因は推定のため、パッチ放置とは判断できません。管理サーバーの公開範囲とクラウド権限を確認します。","en":"The entry assessment does not establish neglected patching; inspect management exposure and cloud privileges."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"製品名、CVE、修正提供時期、侵入開始日は不明です。3月24日は発見日です。","en":"Product, CVE, patch timing, and intrusion start are unknown; March 24 is the detection date."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"弊社クラウド環境における不正アクセスと対応状況のお知らせ","url":"https://prontest.co.jp/news/notice-of-unauthorized-access-in-our-cloud-environment-and-response-status/","publisher":"Prontest","publishedAt":"2026-04-09","kind":"organization"}],"ruleIds":["SEC-001","SEC-002","SEC-005","SEC-006","SEC-009"]}} {"kind":"incident","id":"quick-2025","hash":"2af038caa32254c502baaf93e1ff3ab3ac89e5d9c8df1bdb1c7798081907def1","record":{"id":"quick-2025","organization":"QUICK","title":{"ja":"QUICK:私物端末から業務用認証情報が流出","en":"QUICK: work credentials leaked from a personal device"},"summary":{"ja":"従業員の私物PCのウイルス感染により、業務用ID・パスワードが流出しました。その従業員のアカウントへの不正アクセスが確認されました。","en":"A virus on an employee’s personal PC leaked work credentials, followed by unauthorized access to that employee’s account."},"occurredAt":null,"disclosedAt":"2025-11-04","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["endpoint","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"私物PCの感染によるID・パスワードの流出と、当該アカウントへの不正アクセスを公表しました。","en":"QUICK disclosed credential leakage from an infected personal PC and access to the affected account."},"status":"confirmed","sourceIds":["s1"],"locator":"本文:感染と不正アクセス"},{"topic":"impact","text":{"ja":"従業員2人のメールアドレスが流出しました。業務情報にアクセスされた可能性も調査対象です。","en":"Two employee email addresses leaked; potential access to work information was also investigated."},"status":"confirmed","sourceIds":["s1"],"locator":"本文:影響範囲"}],"timeline":[{"date":"2025-11-04","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"流出したパスワードの変更と、クラウドサービス側の対策を実施したと公表しました。","en":"QUICK reported password changes and measures on the cloud service."},"status":"confirmed","sourceIds":["s1"],"locator":"本文:対応"}],"prevention":{"classification":"operational-control","assessment":{"ja":"私物端末から業務アカウントを利用する条件、端末の管理、セッション失効を確認します。","en":"Inspect conditions for personal-device access, endpoint management, and session revocation."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"アクセスされたクラウドサービス名と、業務情報の流出範囲は明示されていません。","en":"The affected cloud service and full scope of work-information exposure are not disclosed."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"不正アクセスに関するお知らせ","url":"https://corporate.quick.co.jp/news/oshirase20251104/","publisher":"QUICK","publishedAt":"2025-11-04","kind":"organization"}],"ruleIds":["SEC-002","SEC-003","SEC-005","SEC-008","SEC-009"]}} {"kind":"incident","id":"react2shell-2025","hash":"e1fdfa5bfd246913e92ba9225eeda9a0f496fe731af6f782f90ea416e924444a","record":{"id":"react2shell-2025","organization":"React ecosystem / Microsoft observed campaign","title":{"ja":"React2Shell:公開後にRSCの脆弱性を悪用","en":"React2Shell: exploitation after disclosure"},"summary":{"ja":"Microsoftは、React Server Componentsの認証不要のコード実行脆弱性による数百台の侵害を報告しました。脆弱性と修正は12月3日に公表されていました。","en":"Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3."},"occurredAt":null,"disclosedAt":"2025-12-15","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["known-vulnerability","implementation"],"cves":["CVE-2025-55182"],"claims":[{"topic":"entry","text":{"ja":"MicrosoftはCVE-2025-55182による複数組織の端末侵害を観測しました。成功例にはレッドチームの評価も含まれます。","en":"Microsoft observed compromised devices across organizations; successful exploitation also included red-team assessments."},"status":"confirmed","sourceIds":["s1"],"locator":"Analyzing CVE-2025-55182 exploitation activity"},{"topic":"patch","text":{"ja":"Reactは12月3日に脆弱性と修正を公表しました。","en":"React disclosed the vulnerability and fixes on December 3."},"status":"confirmed","sourceIds":["s2"],"locator":"Critical Security Vulnerability"}],"timeline":[{"date":"2025-12-15","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"guidance","text":{"ja":"Microsoftは更新、公開範囲の確認、侵害の調査、影響する秘密情報の更新を推奨しています。","en":"Microsoft recommends patching, exposure checks, compromise investigation, and rotation of affected secrets."},"status":"confirmed","sourceIds":["s1"],"locator":"Mitigation and protection guidance"}],"prevention":{"classification":"patch-available","assessment":{"ja":"稼働するRSC・関連フレームワークのバージョンを最新のアドバイザリと照合します。修正済みでも侵害の痕跡と鍵の利用を確認します。","en":"Compare deployed RSC and framework versions with current advisories; inspect compromise traces and credential use after patching."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"キャンペーンをまとめた記録です。各被害組織の侵入日や、修正を適用しなかった理由は不明です。","en":"This is a campaign record; individual intrusion dates and reasons for delayed patching are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Defending against CVE-2025-55182 (React2Shell)","url":"https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/","publisher":"Microsoft","publishedAt":"2025-12-15","kind":"investigator"},{"id":"s2","reviewedAt":"2026-10-02","title":"Critical Security Vulnerability in React Server Components","url":"https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components","publisher":"React","publishedAt":"2025-12-03","kind":"vendor"}],"ruleIds":["SEC-001","SEC-005","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"rust-arrayref-2026","hash":"636cf32e46b05d55895c1e34fda7bb20010e0d4d7bb0d25a61acf9a5eb673d50","record":{"id":"rust-arrayref-2026","organization":"crates.io / arrayref and related crates","title":{"ja":"Rust:正規クレートの更新に悪性ビルド処理が混入","en":"Rust: malicious build code in legitimate crate updates"},"summary":{"ja":"Rustチームは、arrayrefなどの更新に悪性の依存関係が追加されたと報告しました。ビルド時にペイロードを取得する処理が含まれ、公開された悪性版は削除されました。","en":"The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed."},"occurredAt":null,"disclosedAt":"2026-08-20","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["supply-chain","credentials"],"cves":[],"claims":[{"topic":"distribution","text":{"ja":"arrayref、internment、append-only-vecの悪性版がproc-macro1に依存し、ビルド時にペイロードを取得しました。","en":"Malicious arrayref, internment, and append-only-vec releases depended on proc-macro1 to retrieve a payload at build time."},"status":"confirmed","sourceIds":["s1"],"locator":"Attack overview"},{"topic":"entry","text":{"ja":"8月20日の報告は、管理者の端末または認証情報の侵害が原因と推定しています。","en":"The August 20 report assesses compromise of a maintainer’s computer or credentials as the likely cause."},"status":"inferred","sourceIds":["s1"],"locator":"Maintainer account"}],"timeline":[{"date":"2026-08-20","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"Rustチームは悪性版の削除と公開者アカウントのロックを実施したと報告しました。","en":"The Rust team reported removing malicious releases and locking the publisher account."},"status":"confirmed","sourceIds":["s1"],"locator":"Response"}],"prevention":{"classification":"operational-control","assessment":{"ja":"依存版とビルドスクリプトの実行履歴を照合します。悪性版を実行した環境では、依存更新だけでなく鍵の露出と端末の状態を確認します。","en":"Check dependency versions and build-script execution; examine exposed credentials and hosts rather than only replacing dependencies."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"悪性版のダウンロード数は被害者数ではありません。利用先での侵害範囲は不明です。","en":"Downloads are not a victim count; downstream compromise scope is unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Supply-chain attack on arrayref","url":"https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/","publisher":"Rust Project","publishedAt":"2026-08-20","kind":"vendor"},{"id":"s2","reviewedAt":"2026-10-02","title":"Targeted attacks on Rust crate maintainers","url":"https://blog.rust-lang.org/2026/09/17/targeted-attacks/","publisher":"Rust Project","publishedAt":"2026-09-17","kind":"vendor"}],"ruleIds":["SEC-001","SEC-003","SEC-004","SEC-005","SEC-007","SEC-009"]}} {"kind":"incident","id":"sakura-billing-2026","hash":"493c79f96ce4c126392ba6b9db8dff616fe874d06de5eef3f1b56a8b58eed167","record":{"id":"sakura-billing-2026","organization":"さくらインターネット","title":{"ja":"さくらインターネット:請求情報DBへの別の不正アクセス","en":"Sakura Internet: separate billing-database intrusion"},"summary":{"ja":"2023年4月から2026年3月までの請求情報DBへの不正アクセスが、2026年8月に公表されました。ホスティング事案とは別に、情報流出の可能性を報告しています。","en":"Sakura disclosed billing-database access spanning April 2023 to March 2026 in August 2026, with potential information leakage reported separately from its hosting incident."},"occurredAt":null,"disclosedAt":"2026-08-19","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown","credentials"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"請求情報DBへの不正アクセスが確認されましたが、ホスティング事案との関連は確認されていません。","en":"Billing-database unauthorized access was confirmed without an established link to the hosting incident."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 請求情報データベース"},{"topic":"impact","text":{"ja":"流出の可能性がある対象は136万563件です。一部には初期パスワードが含まれますが、現行パスワード全体の流出を意味しません。","en":"Potential exposure covers 1,360,563 accounts and some initial passwords, not all current passwords."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 影響範囲"}],"timeline":[{"date":"2026-08-19","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"初期パスワードの無効化・変更対応と、アクセス制御・監視の強化を公表しました。","en":"Sakura reported initial-password invalidation or change measures and stronger access control and monitoring."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 対応 / 3. 再発防止策"}],"prevention":{"classification":"unknown","assessment":{"ja":"侵入原因は判断できません。保存する初期認証情報の必要性と形式、廃棄期限、アクセス権を点検します。","en":"The entry cause remains unknown; inspect the need, storage format, retention, and access control for initial credentials."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"侵入開始日は月単位の公表です。ホスティング対象と重複するため、両事案の件数は合算しません。","en":"Intrusion timing is disclosed only by month; account overlap prevents adding the two incident counts."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社サービスへの不正アクセスに関するご報告とお詫び(第3報)","url":"https://www.sakura.ad.jp/corporate/information/newsreleases/2026/09/10/1968225692/","publisher":"さくらインターネット","publishedAt":"2026-09-10","kind":"organization"}],"ruleIds":["SEC-004","SEC-005","SEC-006","SEC-008","SEC-009","SEC-012"]}} {"kind":"incident","id":"sakura-hosting-2026","hash":"4991b42d0a8538c21bb12adb878e1168cac61d2b0903cc1252cad66686c2ed89","record":{"id":"sakura-hosting-2026","organization":"さくらインターネット","title":{"ja":"さくらインターネット:管理用サーバーへの不正アクセス","en":"Sakura Internet: unauthorized management-server access"},"summary":{"ja":"ホスティングサービスの管理用サーバーへの不正アクセスとマルウェア感染を公表しました。請求情報DBへの別の不正アクセスとの関連は、確認されていません。","en":"Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished."},"occurredAt":null,"disclosedAt":"2026-08-17","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"8月9日の異常検知後、管理用サーバーの不正アクセスとマルウェア感染を確認しました。","en":"Unauthorized access and malware were confirmed following an August 9 anomaly."},"status":"confirmed","sourceIds":["s1"],"locator":"1. ホスティングサービス"},{"topic":"impact","text":{"ja":"影響の可能性がある対象は951件ですが、うち368件は侵入との明確な関連が確認されていません。","en":"The potentially affected scope is 951 accounts, including 368 without a clear established intrusion link."},"status":"confirmed","sourceIds":["s1"],"locator":"1. 影響範囲"}],"timeline":[{"date":"2026-08-17","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"対象サーバーの再構築、認証情報の無効化と監視強化を公表しました。","en":"Sakura reported server rebuilding, credential invalidation, and stronger monitoring."},"status":"confirmed","sourceIds":["s1"],"locator":"3. 再発防止策"}],"prevention":{"classification":"unknown","assessment":{"ja":"具体的な侵入経路は不明です。管理面の公開範囲、到達権限、鍵の失効と検知を点検します。","en":"The entry path is unknown; inspect management exposure, reachable privileges, credential revocation, and detection."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"対象件数は流出確定件数ではありません。請求情報DBの事案と件数を合算しません。","en":"Potential scope is not a confirmed leak count; do not add these accounts to billing-incident counts."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社サービスへの不正アクセスに関するご報告とお詫び(第3報)","url":"https://www.sakura.ad.jp/corporate/information/newsreleases/2026/09/10/1968225692/","publisher":"さくらインターネット","publishedAt":"2026-09-10","kind":"organization"}],"ruleIds":["SEC-005","SEC-006","SEC-008","SEC-009","SEC-013"]}} {"kind":"incident","id":"snowflake-unc5537-2024","hash":"24174c9c99c67f8211c4e3c0cf1b613975a33a0eaf02a73d422670a9a81fce03","record":{"id":"snowflake-unc5537-2024","title":{"ja":"Snowflake顧客:窃取済み認証情報でデータ取得","en":"Snowflake customers: stolen credentials used for data theft"},"organization":"Snowflake customer environments","summary":{"ja":"Mandiantが調査した顧客環境では、過去の情報窃取型マルウェア等で盗まれた認証情報が使われました。MFA未適用、資格情報の未更新、接続元の制限不足が共通要因でした。","en":"Mandiant found stolen customer credentials used to access Snowflake environments. Missing MFA, unrotated credentials, and absent network restrictions enabled the investigated compromises."},"occurredAt":null,"disclosedAt":"2024-06-10","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","endpoint","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"調査した侵害は盗まれた顧客の資格情報に追跡でき、Snowflake本体の侵害が原因だという証拠は見つからなかったとしています。","en":"Investigated compromises were traced to stolen customer credentials; investigators found no evidence of a Snowflake platform breach."},"status":"confirmed","sourceIds":["s1"],"locator":"Initial access"},{"topic":"controls","text":{"ja":"影響を受けた調査対象では、MFA・資格情報更新・ネットワーク許可リストに不足がありました。","en":"Affected investigated accounts lacked MFA, rotation of exposed credentials, and network allow-list controls."},"status":"confirmed","sourceIds":["s1"],"locator":"Three primary factors"}],"timeline":[{"date":"2024-06-10","text":{"ja":"Mandiantが調査結果を公表。","en":"Mandiant published its findings."},"sourceIds":["s1"]},{"date":"2024-06-17","text":{"ja":"脅威ハンティングのガイドを追加。","en":"Threat hunting guide added."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"guidance","text":{"ja":"MandiantはMFA適用、資格情報の管理、信頼できる接続元への制限、異常アクセスの検知を推奨しました。","en":"Mandiant recommended MFA, credential management, trusted network restrictions, and abnormal-access detection."},"status":"confirmed","sourceIds":["s1"],"locator":"Recommendations"}],"prevention":{"classification":"operational-control","assessment":{"ja":"調査対象の共通要因であり、全Snowflake利用者の状態を表すものではありません。利用者側の設定と監査ログを点検します。","en":"These are factors in investigated compromises, not all Snowflake customers. Inspect customer-side settings and audit logs."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"個別の被害組織の侵入日と被害範囲は、このキャンペーン単位の記録では確定しません。","en":"This campaign record does not establish each victim’s entry date or impact."}],"sources":[{"id":"s1","title":"UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion","url":"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion","publisher":"Mandiant","kind":"investigator","publishedAt":"2024-06-10","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-002","SEC-006","SEC-008","SEC-009"]}} {"kind":"incident","id":"temairazu-2026","hash":"850d08abeb2117646398605c54df2f7e164b985406fc001155792b8eadc716e4","record":{"id":"temairazu-2026","organization":"手間いらず","title":{"ja":"手間いらず:不正アクセスと宿泊者向け不審メッセージ","en":"Temairazu: unauthorized access and suspicious guest messages"},"summary":{"ja":"同社システムへの不正アクセスを確認したと公表しました。宿泊者への不審な予約関連メッセージも報告されていますが、両者の関係と情報の取得範囲は調査中です。","en":"Temairazu confirmed unauthorized system access. Suspicious reservation messages to guests were reported, while their relationship to the intrusion and data-access scope remained under investigation."},"occurredAt":null,"disclosedAt":"2026-09-28","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"侵入原因を特定し対策したと説明していますが、技術的な詳細は非公表です。","en":"The company says it identified and addressed the cause, but withholds technical details."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 調査・対応状況"},{"topic":"impact","text":{"ja":"9月21日夜以降の不審メッセージと、宿泊情報へのアクセスの可能性を調査しています。","en":"Investigators examined suspicious messages reported from September 21 and possible access to guest information."},"status":"confirmed","sourceIds":["s1"],"locator":"1. 経緯 / 2. 調査・対応状況"}],"timeline":[{"date":"2026-09-28","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"不正アクセスの遮断と対策、監視の強化、宿泊施設への注意喚起を公表しました。","en":"Temairazu reported blocking access, remediation, stronger monitoring, and alerts to lodging facilities."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 対応状況 / 3. お願い"}],"prevention":{"classification":"unknown","assessment":{"ja":"技術的な原因は判断できません。宿泊情報の取得権限・ログと、外部サービスへ預けるデータの必要性を点検します。","en":"Technical cause is undisclosed; inspect guest-data privileges, logs, and the need for data held by external services."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"不審メッセージとの因果関係、流出の確定範囲、具体的な侵入手法は不明です。","en":"Causation of suspicious messages, confirmed leakage scope, and specific entry technique remain unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"当社システムへの不正アクセスに関するお知らせ","url":"https://www.temairazu.co.jp/pdf/1206/news-update","publisher":"手間いらず","publishedAt":"2026-09-28","kind":"organization"}],"ruleIds":["SEC-005","SEC-006","SEC-008","SEC-009","SEC-012"]}} {"kind":"incident","id":"times-car-2026","hash":"8de24493d8aada652dfe02055b6cacca57f0cff723ed7906ca65c10e5eaf6331","record":{"id":"times-car-2026","organization":"タイムズモビリティ","title":{"ja":"タイムズカー:会員情報と本人確認書類が流出","en":"Times Car: member records and identity documents leaked"},"summary":{"ja":"同社は、660万件の会員情報と、そのうち160万件の本人確認書類画像の流出を確認しました。退会済み会員や登録未完了の申込者も対象に含まれます。","en":"The company confirmed leakage of 6.6 million member records, including 1.6 million identity-document images, covering withdrawn members and incomplete applicants."},"occurredAt":null,"disclosedAt":"2026-09-25","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["unknown"],"cves":[],"claims":[{"topic":"impact","text":{"ja":"660万件の会員情報と、うち160万件の本人確認書類画像の流出を確認しました。両者を合算しません。","en":"Leakage covered 6.6 million member records, including 1.6 million identity documents; these counts must not be added."},"status":"confirmed","sourceIds":["s2"],"locator":"流出した情報 / 対象件数"},{"topic":"entry","text":{"ja":"不正アクセスの侵入経路と原因は調査中です。","en":"The intrusion route and cause remain under investigation."},"status":"confirmed","sourceIds":["s1"],"locator":"今後の調査"}],"timeline":[{"date":"2026-09-25","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"9月26日に不正通信を遮断し、対象者への通知を実施すると公表しました。","en":"The company reported blocking malicious communications on September 26 and notifying affected users."},"status":"confirmed","sourceIds":["s1"],"locator":"対応状況"}],"prevention":{"classification":"unknown","assessment":{"ja":"侵入経路は判断できません。退会者・申込者の保持データ、本人確認書類への権限、取得ログを点検します。","en":"The entry path cannot be assessed; inspect former-member and applicant retention, identity-document privileges, and access logs."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"9月25日は検知・公表日です。初回侵入日、具体的な脆弱性と修正提供状況は不明です。","en":"September 25 is detection and disclosure, not an established intrusion start; vulnerability and patch timing are unknown."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"タイムズカーにおける不正アクセスに関するお知らせ(第2報)","url":"https://share.timescar.jp/news/2026/0928/1815.html","publisher":"タイムズモビリティ","publishedAt":"2026-09-28","kind":"organization"},{"id":"s2","reviewedAt":"2026-10-02","title":"タイムズカーにおける不正アクセスに関するお知らせ(第3報)","url":"https://share.timescar.jp/news/2026/0929/1816.html","publisher":"タイムズモビリティ","publishedAt":"2026-09-29","kind":"organization"}],"ruleIds":["SEC-005","SEC-006","SEC-008","SEC-009","SEC-012"]}} {"kind":"incident","id":"toyota-cloud-2023","hash":"5ff255efcb15fa05449044fc4e4496a8fa03254b7a8e73c959b4c53d01ed6bba","record":{"id":"toyota-cloud-2023","title":{"ja":"トヨタ:クラウドの誤設定で車両データが公開状態","en":"Toyota: cloud misconfiguration exposed vehicle data"},"organization":"Toyota / Toyota Connected","summary":{"ja":"管理を委託していたクラウド環境の誤設定により、車両の位置情報などが外部からアクセス可能でした。これは公開状態の確認であり、第三者の窃取を確認した発表ではありません。","en":"Misconfiguration in a delegated cloud environment exposed vehicle data. The disclosure established accessibility, not confirmed third-party theft."},"occurredAt":"2013-11-06","disclosedAt":"2023-05-12","reviewedAt":"2026-10-02","outcome":"exposure-only","categories":["configuration"],"cves":[],"claims":[{"topic":"exposure","text":{"ja":"2013年11月6日から2023年4月17日まで、対象データが外部からアクセス可能でした。","en":"The data was externally accessible from November 6, 2013 to April 17, 2023."},"status":"confirmed","sourceIds":["s1"],"locator":"公開期間の表"},{"topic":"impact","text":{"ja":"約215万人が対象で、端末ID・車台番号・位置情報・時刻に漏洩の可能性がありました。","en":"Potential exposure covered roughly 2.15 million customers and device identifiers, vehicle identifiers, location, and time."},"status":"confirmed","sourceIds":["s1"],"locator":"対象の表"}],"timeline":[{"date":"2013-11-06","text":{"ja":"公表された公開状態の開始日。","en":"Start of the disclosed exposure period."},"sourceIds":["s1"]},{"date":"2023-04-17","text":{"ja":"公表された公開状態の終了日。","en":"End of the disclosed exposure period."},"sourceIds":["s1"]},{"date":"2023-05-12","text":{"ja":"誤設定と漏洩の可能性を公表。","en":"Misconfiguration and potential exposure disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"外部アクセスの遮断と、クラウド設定の監査・継続監視に取り組むと公表しました。","en":"Toyota blocked external access and announced cloud configuration audits and continuous monitoring."},"status":"confirmed","sourceIds":["s1"],"locator":"本文"}],"prevention":{"classification":"operational-control","assessment":{"ja":"ソースコードに問題がなくても、実際のクラウド設定で公開されることがあります。委託先を含む稼働環境の設定を確認します。","en":"Safe source code does not establish safe cloud configuration. Inspect deployed settings, including delegated environments."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"クラウド製品名や具体的な設定項目、第三者の取得の有無は、この発表だけでは特定できません。","en":"This disclosure does not identify the cloud product, exact setting, or actual third-party retrieval."}],"sources":[{"id":"s1","title":"クラウド環境の誤設定によるお客様情報の漏洩可能性に関するお詫びとお知らせ","url":"https://global.toyota/jp/newsroom/corporate/39174380.html","publisher":"トヨタ自動車","kind":"organization","publishedAt":"2023-05-12","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-006"]}} {"kind":"incident","id":"toyota-github-2022","hash":"43212999882c7072a980d356ca9ffceb30fb5eb838a0e95b78cceef75be465bb","record":{"id":"toyota-github-2022","title":{"ja":"トヨタ:公開ソースコードにアクセスキーが残存","en":"Toyota: access key in a public repository"},"organization":"Toyota / Toyota Connected","summary":{"ja":"T-Connectのソースコードの一部がGitHubで公開され、データサーバーのアクセスキーも含まれていました。漏洩の可能性が公表されましたが、第三者のアクセスは確認されていません。","en":"Public T-Connect source code contained a data-server access key. Toyota disclosed potential exposure; third-party access was not confirmed."},"occurredAt":null,"disclosedAt":"2022-10-07","reviewedAt":"2026-10-02","outcome":"exposure-only","categories":["credentials","configuration"],"cves":[],"claims":[{"topic":"exposure","text":{"ja":"2017年12月から2022年9月15日まで、アクセスキーを含むコードが公開されていました。","en":"Code containing an access key was public from December 2017 to September 15, 2022."},"status":"confirmed","sourceIds":["s1"],"locator":"経緯と対応"},{"topic":"impact","text":{"ja":"約29.6万件のメールアドレス等の漏洩可能性があり、第三者のアクセスは確認も完全な否定もできないと公表しました。","en":"Potential exposure covered about 296,000 records; Toyota could neither confirm nor fully rule out third-party access."},"status":"confirmed","sourceIds":["s1"],"locator":"本文"}],"timeline":[{"date":"2022-09-15","text":{"ja":"公開を確認し、コードを非公開化。","en":"Exposure identified and repository made private."},"sourceIds":["s1"]},{"date":"2022-09-17","text":{"ja":"アクセスキーを変更。","en":"Access key changed."},"sourceIds":["s1"]},{"date":"2022-10-07","text":{"ja":"漏洩の可能性を公表。","en":"Potential exposure disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"コードの非公開化とアクセスキーの変更を実施しました。","en":"The source was made private and the access key changed."},"status":"confirmed","sourceIds":["s1"],"locator":"経緯と対応"}],"prevention":{"classification":"operational-control","assessment":{"ja":"リポジトリの公開設定と秘密情報の混入を別々に点検します。公開を止めても、既に取得された鍵は失効が必要です。","en":"Inspect repository visibility and secret inclusion separately. Closing exposure does not revoke credentials already obtained."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"実際の不正アクセスや個人情報の取得は、参照した発表では確認されていません。","en":"Unauthorized access or actual data theft is not confirmed in the cited disclosure."}],"sources":[{"id":"s1","title":"お客様のメールアドレス等の漏洩可能性に関するお詫びとお知らせ","url":"https://global.toyota/jp/newsroom/corporate/38095972.html","publisher":"トヨタ自動車","kind":"organization","publishedAt":"2022-10-07","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-004","SEC-005"]}} {"kind":"incident","id":"trivy-supply-chain-2026","hash":"cb35a6d0ed024d98b333585f5eb25ad4d4550664ccda998253132a9b849b8169","record":{"id":"trivy-supply-chain-2026","organization":"Aqua Security / Trivy","title":{"ja":"Trivy:失効漏れの資格情報から配布物とActionを改ざん","en":"Trivy: residual credentials used to tamper with releases and actions"},"summary":{"ja":"Aqua Securityは、GitHub Actionsの設定不備で特権トークンを取得され、初回対応の失効漏れを経て再び配布物を改ざんされたと報告しました。既存のActionタグも悪性コミットへ付け替えられました。","en":"Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits."},"occurredAt":null,"disclosedAt":"2026-03-20","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["supply-chain","credentials","configuration"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"2月下旬の設定不備によるトークン取得後、3月1日の資格情報更新では一部の有効な資格情報が残り、3月19日の改ざんに利用されました。","en":"Aqua describes late-February token theft, credentials remaining valid after March 1 rotation, and reuse for March 19 tampering."},"status":"confirmed","sourceIds":["s2"],"locator":"Attack Timeline"},{"topic":"impact","text":{"ja":"Trivy v0.69.4とGitHub Actionsに悪性コードが配布され、既存タグも付け替えられました。影響を受けたCIに渡された秘密情報は露出した可能性があると警告しています。","en":"Malicious Trivy v0.69.4 and actions were distributed, including changed existing tags; Aqua warns that secrets accessible to affected runners must be considered exposed."},"status":"confirmed","sourceIds":["s2"],"locator":"What Happened / What Was Affected"}],"timeline":[{"date":"2026-03-20","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"悪性配布物を削除し、資格情報の失効と更新、長期トークンからの移行、CIとアクセス制御の強化を進めていると公表しました。","en":"Aqua reported artifact removal, credential revocation and rotation, moving away from long-lived tokens, and strengthening CI and access controls."},"status":"confirmed","sourceIds":["s2"],"locator":"Ongoing Actions / Attack Timeline"}],"prevention":{"classification":"operational-control","assessment":{"ja":"Actionのタグだけでなく、検証したコミットを固定できているか確認します。初回対応で新しい鍵を作っただけにせず、全旧鍵の失効記録と利用先を照合します。","en":"Inspect verified commit pinning rather than tag names alone, and reconcile every old credential’s revocation with its consumers."},"sourceIds":["s2"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"2月下旬の初回侵入の正確な日は不明です。このレコードは3月19日の再侵害を中心に記録し、配布数を被害組織数とは扱いません。","en":"The exact late-February entry day is unknown. This record focuses on the March 19 recurrence; distribution counts are not victim-organization counts."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"Trivy Security incident 2026-03-19","url":"https://github.com/aquasecurity/trivy/discussions/10425","publisher":"Aqua Security / Trivy maintainers","publishedAt":"2026-03-20","kind":"vendor"},{"id":"s2","reviewedAt":"2026-10-02","title":"Trivy supply chain attack: ongoing investigation and remediation","url":"https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/","publisher":"Aqua Security","publishedAt":"2026-03-22","kind":"vendor"}],"ruleIds":["SEC-001","SEC-004","SEC-005","SEC-007","SEC-008","SEC-009"]}} {"kind":"incident","id":"uber-2022","hash":"378245575d4a60d27b27fc4ce0173d340b03aa930b5475fdfc416585e8186914","record":{"id":"uber-2022","title":{"ja":"Uber:認証要求の連打と委託先アカウントの侵害","en":"Uber: repeated MFA prompts and a contractor account"},"organization":"Uber","summary":{"ja":"委託先のアカウントで繰り返された二要素認証の要求が承認され、内部ツールへのアクセスが拡大しました。パスワードの入手経路については、会社も可能性として説明しています。","en":"A contractor accepted one of repeated two-factor requests, enabling access to internal tools. Uber described the initial password acquisition as a likely explanation."},"occurredAt":"2022-09-15","disclosedAt":"2022-09-15","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","endpoint"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"委託先が二要素認証の要求を承認した後、攻撃者がログインしました。","en":"The attacker logged in after a contractor accepted a two-factor request."},"status":"confirmed","sourceIds":["s1"],"locator":"What happened?"},{"topic":"origin","text":{"ja":"個人端末のマルウェア感染後、パスワードが売買された可能性があるとUberは説明しました。","en":"Uber assessed that malware on a personal device likely led to the password being sold."},"status":"inferred","sourceIds":["s1"],"locator":"What happened?"}],"timeline":[{"date":"2022-09-15","text":{"ja":"事故への対応中であると公表。","en":"Initial incident disclosure."},"sourceIds":["s1"]},{"date":"2022-09-19","text":{"ja":"侵入経路と対応状況を更新。","en":"Entry path and response update published."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"対象アカウントの停止・パスワード変更、鍵の更新、内部ツール復帰時の再認証を実施しました。","en":"Affected accounts were blocked or reset, keys rotated, and reauthentication required when tools were restored."},"status":"confirmed","sourceIds":["s1"],"locator":"How did we respond?"}],"prevention":{"classification":"operational-control","assessment":{"ja":"MFAの有無だけでなく、認証方式・承認の連打への対処・委託先を含む適用範囲を点検します。","en":"Inspect MFA methods, repeated prompt handling, and coverage of contractor accounts, not only whether MFA exists."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した一次情報に、攻撃でAIを利用したことを裏付ける記述はありません。AI不使用を意味しません。","en":"The cited primary sources do not establish AI involvement. This does not establish that AI was absent."}},"unknowns":[{"ja":"パスワード窃取の具体的経路は、参照した発表では確定していません。","en":"The exact password theft path is not established by the cited disclosure."}],"sources":[{"id":"s1","title":"Security update (September 19 update)","url":"https://www.uber.com/us/en/newsroom/security-update/","publisher":"Uber","kind":"organization","publishedAt":"2022-09-16","reviewedAt":"2026-10-02"}],"ruleIds":["SEC-002","SEC-003"]}} {"kind":"incident","id":"unit42-ai-assisted-2026","hash":"5df080af935d7269cf938146b76266693d1f5759a00b76a1bd874ae11b0741fd","record":{"id":"unit42-ai-assisted-2026","organization":"Anonymous enterprise investigated by Unit 42","title":{"ja":"Unit 42:AI支援の侵入でリポジトリの鍵を悪用","en":"Unit 42: AI-assisted intrusion abusing repository secrets"},"summary":{"ja":"Unit 42は、公開サービスへの侵入後、リポジトリの秘密情報を足がかりにクラウドへ広がった事案を報告しました。攻撃中のLLM呼び出しが観測されています。","en":"Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack."},"occurredAt":null,"disclosedAt":"2026-09-02","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["credentials","configuration"],"cves":[],"claims":[{"topic":"expansion","text":{"ja":"リポジトリ内のトークン、保管庫の認証情報、CIのクラウド鍵が侵害拡大に利用されました。","en":"Repository tokens, vault credentials, and cloud keys in CI enabled expansion."},"status":"confirmed","sourceIds":["s1"],"locator":"Repository / vault / CI stages"},{"topic":"control","text":{"ja":"バックドアを加える試みはブランチ保護に阻まれました。侵入全体はランサムウェアと確認されていません。","en":"Branch protection blocked a backdoor attempt; the intrusion was not established as ransomware."},"status":"confirmed","sourceIds":["s1"],"locator":"Branch protection / September corrections"},{"topic":"ai","text":{"ja":"調査元は攻撃中のLLM呼び出しと、複数のエージェントを使う操作を報告しました。","en":"Investigators reported LLM calls and operations involving multiple agents during the attack."},"status":"confirmed","sourceIds":["s1"],"locator":"AI-assisted orchestration"}],"timeline":[{"date":"2026-09-02","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"調査元は、ブランチ保護によって攻撃者の変更が本番へ入るのを阻止したと報告しました。","en":"Investigators reported that branch protection prevented the attacker’s change from reaching production."},"status":"confirmed","sourceIds":["s1"],"locator":"Branch protection"}],"prevention":{"classification":"operational-control","assessment":{"ja":"リポジトリに混入する鍵と、CI・保管庫・AI接続先の権限を点検します。コード変更に必要な承認と本番鍵を分離します。","en":"Inspect repository secrets and CI, vault, and AI-endpoint privileges; separate change approval from production credentials."},"sourceIds":["s1"]},"ai":{"status":"confirmed","assessment":{"ja":"Unit 42が攻撃中のLLM呼び出しを報告しています。全工程が自律実行されたことまでは確認していません。","en":"Unit 42 reports LLM calls during the intrusion; this does not establish autonomous execution of every stage."}},"unknowns":[{"ja":"被害組織名と最初の脆弱性の詳細は非公表です。人の操作とAIの自律行動の全範囲は未検証です。","en":"Victim identity and initial vulnerability are undisclosed; the full human-versus-agent autonomy split is unverified."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"An AI-assisted cyber attack: inside a Unit 42 investigation","url":"https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/","publisher":"Palo Alto Networks Unit 42","publishedAt":"2026-09-02","kind":"investigator"}],"ruleIds":["SEC-004","SEC-005","SEC-006","SEC-007","SEC-008","SEC-009","SEC-011"]}} {"kind":"incident","id":"voising-bi-2026","hash":"f40d9ec1c382b6866d9556f42e40d033ec17c42a91b6d97397ce952724dccaaa","record":{"id":"voising-bi-2026","organization":"VOISING","title":{"ja":"VOISING:修正未適用のBIツールから情報が流出","en":"VOISING: unpatched BI tool data leakage"},"summary":{"ja":"BIツールの脆弱性が悪用され、約17万件の情報流出を確認したと公表しました。同社は、不正アクセス前に提供されていた修正版を適用していなかったと説明しています。","en":"VOISING confirmed leakage of about 170,000 records via a BI vulnerability and reported that an available pre-intrusion patch had not been applied."},"occurredAt":null,"disclosedAt":"2026-08-18","reviewedAt":"2026-10-02","outcome":"confirmed-breach","categories":["known-vulnerability"],"cves":[],"claims":[{"topic":"entry","text":{"ja":"不正アクセス前に修正版が提供されていましたが、適用されていませんでした。","en":"A patch was available before unauthorized access but had not been applied."},"status":"confirmed","sourceIds":["s1"],"locator":"3. 発生原因"},{"topic":"impact","text":{"ja":"約17万件の情報流出を確認したと公表しました。","en":"VOISING reported about 170,000 confirmed leaked records."},"status":"confirmed","sourceIds":["s1"],"locator":"2. 影響範囲"}],"timeline":[{"date":"2026-08-18","text":{"ja":"この事案を公表。","en":"Incident disclosed."},"sourceIds":["s1"]}],"reportedActions":[{"topic":"response","text":{"ja":"BI停止、環境の廃棄・再構築、APIキーと認証情報の無効化・更新を公表しました。","en":"VOISING reported stopping BI, discarding and rebuilding the environment, and revoking and rotating API keys and credentials."},"status":"confirmed","sourceIds":["s1"],"locator":"4. 実施した対応"}],"prevention":{"classification":"patch-available","assessment":{"ja":"稼働するBIのバージョンと修正情報を照合し、更新の担当と期限を確認します。取得できるデータと公開範囲も限定します。","en":"Compare deployed BI versions with advisories and verify patch ownership and deadlines; limit exposure and accessible data."},"sourceIds":["s1"]},"ai":{"status":"unknown","assessment":{"ja":"参照した情報では、攻撃者によるAI利用は確認できません。AI不使用を意味しません。","en":"The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence."}},"unknowns":[{"ja":"BI製品名とCVEは公表されていません。他社事案との時期の近さだけでは同じ製品・脆弱性と判断できません。","en":"BI product and CVE are undisclosed; proximity to another incident does not establish a shared product or vulnerability."}],"sources":[{"id":"s1","reviewedAt":"2026-10-02","title":"不正アクセスによる情報流出に関するご報告(第4報)","url":"https://voising-official.com/news/1015","publisher":"VOISING","publishedAt":"2026-09-30","kind":"organization"}],"ruleIds":["SEC-001","SEC-005","SEC-006","SEC-008","SEC-009","SEC-012"]}}