<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CyberLens ニュース</title><description>サイバーセキュリティの最新ニュース・脆弱性情報を、背景解説と実務上の初動判断まで整理してお届けします。</description><link>https://cyber-security-lens.com/</link><language>ja</language><item><title>クラウドストレージ誤公開の初動対応｜S3・Azure Blob・GCS確認チェックリスト</title><link>https://cyber-security-lens.com/news/cloud-storage-public-exposure-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cloud-storage-public-exposure-first-response/</guid><description>S3、Azure Blob、Google Cloud Storageのバケットやコンテナを誤って公開したときの初動対応を解説。情シス・開発者・クラウド管理者向けに、公開停止、ログ保全、影響範囲、署名付きURL、エスカレーションを確認する実務チェックリストです。</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>クラウドストレージ</category><category>S3</category><category>Azure Blob</category><category>Google Cloud Storage</category><category>誤公開</category><category>情報漏えい</category><category>IAM</category><category>インシデント対応</category></item><item><title>FortiSandbox CVE-2026-25089／CVE-2026-39808がCISA KEV入り：影響と初動対応</title><link>https://cyber-security-lens.com/news/fortisandbox-cve-2026-25089-39808-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/fortisandbox-cve-2026-25089-39808-kev/</guid><description>CISA KEVに追加されたFortiSandboxのCVE-2026-25089とCVE-2026-39808について、製品別の影響バージョン、修正版、GUI・APIの公開範囲、ログ保全、更新後確認を公式情報に基づき整理します。管理基盤の初動チェックリスト付きです。</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><category>FortiSandbox</category><category>CVE-2026-25089</category><category>CVE-2026-39808</category><category>CISA KEV</category><category>Fortinet</category><category>管理プレーン</category></item><item><title>マルウェア感染時の初動対応チェックリスト</title><link>https://cyber-security-lens.com/news/malware-infection-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/malware-infection-first-response/</guid><description>マルウェア感染が疑われるときの初動対応を、端末隔離、証拠保全、影響確認、エスカレーション、復旧判断の順で解説。個人・情シス・開発者・SaaS管理者が最初の10分で確認するチェックリストと、電源を切る条件、避けるべき対応を公式資料に基づき整理します。</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><category>マルウェア</category><category>ウイルス感染</category><category>端末隔離</category><category>EDR</category><category>証拠保全</category><category>インシデント対応</category></item><item><title>セッションハイジャックが疑われるときの初動対応｜Cookie・トークン漏えい確認チェックリスト</title><link>https://cyber-security-lens.com/news/session-hijacking-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/session-hijacking-first-response/</guid><description>セッションハイジャックやCookie・アクセストークン漏えいが疑われるときに、利用者・情シス・開発者・SaaS管理者が確認するログ、セッション失効、端末隔離、証跡保全、エスカレーション条件と対応の優先順位を、実務チェックリストで解説します。</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><category>セッションハイジャック</category><category>Pass-the-Cookie</category><category>Cookie</category><category>アクセストークン</category><category>SaaS</category><category>アカウント乗っ取り</category><category>初動対応</category></item><item><title>SharePoint CVE-2026-58644／CVE-2026-56164がCISA KEV入り：影響と初動対応</title><link>https://cyber-security-lens.com/news/sharepoint-cve-2026-58644-56164-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/sharepoint-cve-2026-58644-56164-kev/</guid><description>CISA KEVに追加されたSharePoint ServerのCVE-2026-58644とCVE-2026-56164について、影響バージョン、更新確認、IIS・ULSログ保全、公開範囲、エスカレーション条件を公式情報に基づき整理します。情シスが初動で使えるチェックリスト付きです。</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><category>SharePoint Server</category><category>CVE-2026-58644</category><category>CVE-2026-56164</category><category>CISA KEV</category><category>Microsoft</category><category>パッチ管理</category></item><item><title>AWSアクセスキー漏えい時の初動対応：無効化・CloudTrail確認・再発防止</title><link>https://cyber-security-lens.com/news/aws-access-key-leak-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/aws-access-key-leak-first-response/</guid><description>AWSアクセスキーが漏えいした疑いがある時の初動対応を解説。無効化と削除の違い、CloudTrail・GuardDuty・IAM権限・全リージョン・課金の確認方法、発行済み一時認証情報の扱いを、情シス・開発者向けチェックリストで整理します。</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>AWS</category><category>アクセスキー</category><category>IAM</category><category>CloudTrail</category><category>GuardDuty</category><category>認証情報漏えい</category><category>インシデント対応</category></item><item><title>メール誤送信の初動対応 ─ 宛先・CC/BCC・添付ファイル間違いの確認チェックリスト</title><link>https://cyber-security-lens.com/news/email-misdelivery-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/email-misdelivery-first-response/</guid><description>メール誤送信に気づいた直後の初動対応を、宛先間違い、CC/BCC、添付ファイル、共有リンク別に解説。送信取消の限界、証拠保全、受信者連絡、個人情報保護委員会への報告要否、エスカレーション基準、記録テンプレートを情シス・SaaS管理者向けに整理します。</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>メール誤送信</category><category>情報漏えい</category><category>初動対応</category><category>CC</category><category>BCC</category><category>添付ファイル</category><category>個人情報</category><category>DLP</category><category>SaaS</category><category>情シス</category></item><item><title>サービスアカウントキー漏えい時の初動対応：無効化・影響確認・再発防止</title><link>https://cyber-security-lens.com/news/service-account-key-leak-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/service-account-key-leak-first-response/</guid><description>Google Cloudなどのサービスアカウントキーが漏えいした疑いがある時の初動対応を解説。無効化と削除の違い、監査ログ、付与権限、利用先、ローテーション、影響範囲の確認方法を、情シス・開発者・SaaS管理者向けチェックリストと判断基準で整理します。</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>サービスアカウント</category><category>Google Cloud</category><category>IAM</category><category>認証情報漏えい</category><category>秘密鍵</category><category>Workload Identity Federation</category><category>インシデント対応</category></item><item><title>File Browserの認証関連脆弱性 ─ CVE-2026-54088／CVE-2026-54089の影響条件と初動対応</title><link>https://cyber-security-lens.com/news/file-browser-cve-2026-54088-54089-authentication-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/file-browser-cve-2026-54088-54089-authentication-response/</guid><description>セルフホスト型File Browserの認証関連脆弱性2件を解説します。Hook認証の修正版、Proxy認証の影響条件、直接公開の確認、リバースプロキシ制限、ログ・アカウント点検、エスカレーション判断を実務向けに、確認手順と記録例まで整理します。</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>File Browser</category><category>CVE-2026-54088</category><category>CVE-2026-54089</category><category>認証</category><category>リバースプロキシ</category><category>セルフホスト</category><category>脆弱性対応</category></item><item><title>GitHubリポジトリを誤って公開した時の初動対応 ─ シークレット・履歴・権限の確認チェックリスト</title><link>https://cyber-security-lens.com/news/github-repository-accidental-public-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/github-repository-accidental-public-first-response/</guid><description>GitHubの非公開リポジトリを誤ってPublicにした、または公開範囲の設定ミスに気づいた時の初動対応を解説。非公開化、シークレット失効、履歴・フォーク・Actions・監査ログの確認、影響評価、社内報告、再発防止を、開発者・情シス・SaaS管理者向けチェックリストで整理します。</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>GitHub</category><category>リポジトリ誤公開</category><category>情報漏えい</category><category>Secret Scanning</category><category>シークレット</category><category>インシデント対応</category><category>開発者</category></item><item><title>Joomla拡張機能2件がCISA KEV入り ─ CVE-2026-56291／CVE-2026-48939の影響と初動対応</title><link>https://cyber-security-lens.com/news/joomla-balbooa-icagenda-cve-2026-56291-48939-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/joomla-balbooa-icagenda-cve-2026-56291-48939-kev/</guid><description>Joomla拡張機能Balbooa FormsとiCagendaの脆弱性がCISA KEVに追加されました。影響バージョン、修正版、対象サイトの確認方法、更新前後のログ確認、証跡保全とエスカレーション条件を実務チェックリスト形式で整理します。</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Joomla</category><category>Balbooa Forms</category><category>iCagenda</category><category>CVE-2026-56291</category><category>CVE-2026-48939</category><category>CISA KEV</category><category>CMS</category><category>脆弱性対応</category></item><item><title>身に覚えのないMFA変更・解除通知の初動対応：認証方法を守る確認チェックリスト</title><link>https://cyber-security-lens.com/news/mfa-method-change-alert-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/mfa-method-change-alert-first-response/</guid><description>身に覚えのないMFA・2段階認証の追加、変更、解除通知が届いたときに、通知の真偽、認証方法、回復先、サインイン履歴、既存セッション、管理者監査ログを安全に確認する手順を解説。個人・情シス・SaaS管理者向けに、優先度判断と記録テンプレートまで整理します。</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>MFA</category><category>2段階認証</category><category>認証方法</category><category>アカウント乗っ取り</category><category>アカウント回復</category><category>SaaS</category><category>初動対応</category><category>初心者</category></item><item><title>身に覚えのないログイン通知の確認方法と初動対応 ─ 乗っ取りを見分けるチェックリスト</title><link>https://cyber-security-lens.com/news/unrecognized-login-alert-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/unrecognized-login-alert-first-response/</guid><description>身に覚えのないログイン通知が届いたとき、メール内リンクを押さずに本物か確認し、ログイン履歴、端末、セッション、MFA、連携アプリを安全に点検する手順を解説。個人・情シス・開発者・SaaS管理者向けに、優先度判断、記録項目、エスカレーション条件まで実務チェックリストで整理します。</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>不審なログイン</category><category>アカウント乗っ取り</category><category>ログイン履歴</category><category>MFA</category><category>SaaS</category><category>初動対応</category><category>初心者</category></item><item><title>DNSレコードが勝手に変わった時の初動対応：ドメイン乗っ取り・メールなりすましを確認する</title><link>https://cyber-security-lens.com/news/dns-record-change-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/dns-record-change-first-response/</guid><description>DNSレコードが意図せず変更された時に、NS/MX/TXT/CNAME、ドメイン管理者、DNSSEC、証明書、メール認証、ログ保全をどう確認するか。ドメイン乗っ取り・なりすまし疑いの初動対応を整理します。</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>DNSレコード</category><category>DNS</category><category>ドメイン管理</category><category>DNSSEC</category><category>メール認証</category><category>初動対応</category><category>証拠保全</category><category>SaaS</category></item><item><title>Adobe ColdFusion CVE-2026-48282がCISA KEVに追加：公開Webアプリサーバーの初動確認</title><link>https://cyber-security-lens.com/news/adobe-coldfusion-cve-2026-48282-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/adobe-coldfusion-cve-2026-48282-kev/</guid><description>Adobe ColdFusion CVE-2026-48282は限定的な実悪用が公表されたKEV対象脆弱性です。影響バージョン、更新、公開範囲、ログ保全、報告判断を整理します。</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>Adobe ColdFusion</category><category>CVE-2026-48282</category><category>KEV</category><category>Path Traversal</category><category>Webアプリサーバー</category><category>パッチ管理</category></item><item><title>Langflow CVE-2026-55255がCISA KEVに追加：AIワークフローの認可境界を確認する</title><link>https://cyber-security-lens.com/news/langflow-cve-2026-55255-kev-authorization-bypass/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/langflow-cve-2026-55255-kev-authorization-bypass/</guid><description>Langflow CVE-2026-55255はAIワークフロー基盤の認可境界に関係するKEV対象脆弱性です。影響確認、更新、ログ保全、APIキー確認を実務手順で整理します。</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>CVE-2026-55255</category><category>KEV</category><category>AIセキュリティ</category><category>認可</category><category>APIキー</category></item><item><title>インシデント時の証拠保全とは ─ ログ・端末・クラウド証跡を失わない初動対応</title><link>https://cyber-security-lens.com/news/incident-evidence-preservation-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/incident-evidence-preservation-first-response/</guid><description>インシデント対応で証拠保全・ログ保全をどう進めるか。端末、SaaS、クラウド、メール、監査ログを失わない初動確認、やってはいけないこと、記録テンプレート、エスカレーション基準を整理します。</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>証拠保全</category><category>ログ保全</category><category>インシデント対応</category><category>フォレンジック</category><category>Chain of Custody</category><category>監査ログ</category><category>CSIRT</category><category>SaaS</category></item><item><title>Cisco Unified CM CVE-2026-20230がCISA KEV入り - WebDialer有効環境でまず確認すること</title><link>https://cyber-security-lens.com/news/cisco-unified-cm-cve-2026-20230-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cisco-unified-cm-cve-2026-20230-kev/</guid><description>Cisco Unified CM / Unified CM SMEのCVE-2026-20230について、WebDialer有効有無、修正版、暫定緩和、ログ保全、初動判断を整理します。</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><category>Cisco Unified CM</category><category>CVE-2026-20230</category><category>CISA KEV</category><category>SSRF</category><category>WebDialer</category><category>VoIP</category><category>脆弱性管理</category></item><item><title>PTC Windchill / FlexPLM CVE-2026-12569がCISA KEV入り - PLM基盤でまず確認すること</title><link>https://cyber-security-lens.com/news/ptc-windchill-flexplm-cve-2026-12569-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ptc-windchill-flexplm-cve-2026-12569-kev/</guid><description>CISA KEVに追加されたPTC Windchill / FlexPLM CVE-2026-12569について、対象製品、公開範囲、PLM権限、ログ保全、更新判断を整理します。</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><category>PTC Windchill</category><category>FlexPLM</category><category>CVE-2026-12569</category><category>CISA KEV</category><category>PLM</category><category>脆弱性管理</category><category>Patch Management</category></item><item><title>DNSログの読み方 ─ 不審なドメイン通信を初動で確認する手順</title><link>https://cyber-security-lens.com/news/dns-log-triage-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/dns-log-triage-guide/</guid><description>DNSログで不審なドメイン通信を見つけた時に、問い合わせ元、時刻、応答、NXDOMAIN、Proxy/EDRログとの突合、報告記録までを整理。情シス・SOC・開発者が初動判断に使える確認方法をチェックリスト形式で解説します。</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate><category>DNSログ</category><category>DNS</category><category>不審通信</category><category>ログ分析</category><category>SIEM</category><category>SOC</category><category>IOC</category><category>初動対応</category></item><item><title>メールヘッダーの見方 ─ Gmail / Outlookで不審メールを確認</title><link>https://cyber-security-lens.com/news/email-header-analysis-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/email-header-analysis-first-response/</guid><description>メールヘッダーとは何か、Gmail・Outlookでの表示方法、From・Reply-To・Received・SPF/DKIM/DMARCの見方を解説。不審メールを受け取った直後の保存・報告・エスカレーション判断をチェックリストで整理します。</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate><category>メールヘッダー</category><category>フィッシング</category><category>SPF</category><category>DKIM</category><category>DMARC</category><category>Authentication-Results</category><category>初動対応</category></item><item><title>SharePoint Server CVE-2026-45659がCISA KEV入り ─ オンプレ環境でまず確認すること</title><link>https://cyber-security-lens.com/news/sharepoint-server-cve-2026-45659-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/sharepoint-server-cve-2026-45659-kev/</guid><description>CISA KEVに追加されたSharePoint Server CVE-2026-45659について、影響バージョン、更新判断、公開範囲、ログ保全、初動対応を整理します。</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>SharePoint Server</category><category>CVE-2026-45659</category><category>CISA KEV</category><category>Microsoft</category><category>パッチ管理</category><category>管理画面</category></item><item><title>SimpleHelp CVE-2026-48558がCISA KEV入り ─ リモートサポート基盤でまず確認すること</title><link>https://cyber-security-lens.com/news/simplehelp-cve-2026-48558-kev-remote-support/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/simplehelp-cve-2026-48558-kev-remote-support/</guid><description>SimpleHelpのOIDC認証回避CVE-2026-48558について、影響条件、更新先、Technicianアカウント確認、ログ保全、初動対応を整理します。</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>SimpleHelp</category><category>CVE-2026-48558</category><category>CISA KEV</category><category>RMM</category><category>リモートサポート</category><category>OIDC</category><category>MFA</category></item><item><title>データ分類の始め方 ─ DLP・AI利用・SaaS共有で迷わない実務チェックリスト</title><link>https://cyber-security-lens.com/news/data-classification-dlp-first-step/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/data-classification-dlp-first-step/</guid><description>データ分類とは何か、DLP・AI利用・SaaS外部共有で迷わない分類軸、確認手順、初動対応、判断基準を情シス・開発者・SaaS管理者向けに整理します。</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>データ分類</category><category>DLP</category><category>Data Classification</category><category>Data Discovery</category><category>SaaS</category><category>AIセキュリティ</category><category>情報漏えい</category><category>機密情報</category><category>情シス</category></item><item><title>ソフトウェア資産台帳の作り方 ─ CVE対応・SBOM・SaaS棚卸しを速くする実務ガイド</title><link>https://cyber-security-lens.com/news/software-inventory-vulnerability-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/software-inventory-vulnerability-response/</guid><description>ソフトウェア資産台帳とは何か、CVE対応・SBOM・SaaS棚卸しで集める情報、優先度判断、初動対応、更新サイクルを整理。情シス・開発者が脆弱性ニュースを見た直後に使えるチェックリスト付き。</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>ソフトウェア資産台帳</category><category>SBOM</category><category>CVE</category><category>KEV</category><category>脆弱性管理</category><category>パッチ管理</category><category>SaaS</category><category>開発者セキュリティ</category><category>情シス</category></item><item><title>pnpmの複数アドバイザリ公開：開発端末とCIでまず確認すること</title><link>https://cyber-security-lens.com/news/pnpm-multiple-advisories-package-manager-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/pnpm-multiple-advisories-package-manager-response/</guid><description>pnpmの複数アドバイザリを受け、開発端末、CI、lockfile、リポジトリ設定、トークンをどう確認するかを解説。公式情報に基づき、対象バージョン確認、更新判断、証跡保全、再ビルド範囲、監査ログ確認まで、情シスと開発者向けに初動対応を整理します。</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>pnpm</category><category>サプライチェーン</category><category>パッケージマネージャー</category><category>CVE-2026-55698</category><category>CVE-2026-55700</category><category>GitHub Advisory</category><category>開発者セキュリティ</category></item><item><title>Snipe-IT 複数脆弱性の初動対応 ─ IT資産管理システムの権限・MFA・更新確認</title><link>https://cyber-security-lens.com/news/snipe-it-asset-management-cve-2026-permission-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/snipe-it-asset-management-cve-2026-permission-review/</guid><description>Snipe-ITの複数CVEについて、影響バージョン、修正版、権限、MFA、資産台帳、公開範囲、ログ確認を情シス向けに整理。自社ホスト型IT資産管理の更新前後の証跡保全、エスカレーション条件、現場での初動判断に使える実務チェックリスト付き。</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>Snipe-IT</category><category>CVE-2026-54329</category><category>CVE-2026-48507</category><category>CVE-2026-48493</category><category>CVE-2026-49870</category><category>IT資産管理</category><category>認可</category><category>MFA</category><category>情シス</category></item><item><title>不審なメール転送ルールを見つけた時の初動対応 ─ Microsoft 365・SaaS管理者向け確認手順</title><link>https://cyber-security-lens.com/news/suspicious-mail-forwarding-rule-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/suspicious-mail-forwarding-rule-first-response/</guid><description>Microsoft 365などで不審なメール転送ルールや受信トレイルールを見つけた時、アカウント侵害・BECの可能性、ログ保全、セッション失効、MFA、OAuth確認、影響範囲、削除前の判断基準、報告までをSaaS管理者向けの実務手順として整理します。</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>メール転送</category><category>Microsoft 365</category><category>Exchange Online</category><category>受信トレイルール</category><category>BEC</category><category>フィッシング</category><category>SaaS</category><category>初動対応</category><category>ログ確認</category></item><item><title>MCPサーバーを社内AIに接続する前に確認すること ─ 権限・トークン・ログの実務チェック</title><link>https://cyber-security-lens.com/news/mcp-server-permission-token-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/mcp-server-permission-token-review/</guid><description>MCPサーバーを社内AIや開発環境へ接続する前に、OAuth、トークン、ツール権限、監査ログ、停止手順、初動対応を実務向けに整理します。</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>MCP</category><category>Model Context Protocol</category><category>AIエージェント</category><category>OAuth</category><category>APIキー</category><category>最小権限</category><category>監査ログ</category><category>AIセキュリティ</category></item><item><title>Webhook署名シークレット漏えい時の初動対応 ─ 確認方法とローテーション手順</title><link>https://cyber-security-lens.com/news/webhook-signature-secret-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/webhook-signature-secret-first-response/</guid><description>Webhook署名シークレットの漏えい疑いがあるとき、受信エンドポイント、署名検証、再送、ログ、ローテーションをどう確認するか。開発者・SaaS管理者向けの初動チェックリスト。</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>Webhook</category><category>Webhook Secret</category><category>署名検証</category><category>シークレット管理</category><category>ローテーション</category><category>APIセキュリティ</category><category>SaaS</category><category>開発者セキュリティ</category></item><item><title>Ubiquiti UniFi OSの3件がCISA KEV追加 ─ 管理画面とネットワーク機器で確認すること</title><link>https://cyber-security-lens.com/news/ubiquiti-unifi-os-cve-2026-34908-34909-34910-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ubiquiti-unifi-os-cve-2026-34908-34909-34910-kev/</guid><description>CISA KEVに追加されたUbiquiti UniFi OSの3件の脆弱性について、影響製品、更新目安、管理画面の到達範囲、初動確認、証跡保全を整理します。</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>Ubiquiti</category><category>UniFi OS</category><category>CVE-2026-34908</category><category>CVE-2026-34909</category><category>CVE-2026-34910</category><category>CISA KEV</category><category>管理プレーン</category><category>ネットワーク機器</category></item><item><title>Chrome V8 CVE-2026-11645がCISA KEV入り ─ ブラウザ更新を全社で確認する手順</title><link>https://cyber-security-lens.com/news/chrome-v8-cve-2026-11645-kev-browser-update/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/chrome-v8-cve-2026-11645-kev-browser-update/</guid><description>CISA KEVに追加されたChrome V8 CVE-2026-11645について、影響バージョン、修正版、端末台帳、再起動待ち、未更新端末、SaaS利用まで確認する手順を整理します。</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>Chrome</category><category>Chromium</category><category>V8</category><category>CVE-2026-11645</category><category>CISA KEV</category><category>ブラウザ更新</category></item><item><title>OIDCクライアントシークレット更新手順 ─ OAuthログイン停止とsecret漏えいを避ける確認方法</title><link>https://cyber-security-lens.com/news/oidc-client-secret-rotation-checklist/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/oidc-client-secret-rotation-checklist/</guid><description>OIDC/OAuthクライアントシークレットの期限切れ・漏えい時に、停止を避けて安全に更新する実務手順。新旧secret併用、設定反映、ログ確認、旧secret無効化、PKCEや証明書・フェデレーション資格情報への移行判断、台帳整備まで整理します。</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>OIDC</category><category>OAuth</category><category>クライアントシークレット</category><category>シークレット管理</category><category>SaaS</category><category>認証</category><category>開発者セキュリティ</category><category>Secret Rotation</category><category>PKCE</category></item><item><title>Splunk Enterprise CVE-2026-20253がCISA KEV入り ─ SIEM管理基盤でまず確認すること</title><link>https://cyber-security-lens.com/news/splunk-enterprise-cve-2026-20253-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/splunk-enterprise-cve-2026-20253-kev/</guid><description>CISA KEVに追加されたSplunk Enterprise CVE-2026-20253について、影響バージョン、修正版、SIEM管理基盤の到達範囲、ログ保全、更新判断を整理します。</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>Splunk</category><category>SIEM</category><category>CVE-2026-20253</category><category>CISA KEV</category><category>パッチ管理</category><category>SOC</category></item><item><title>SAML証明書・SSO証明書の期限切れ対応 ─ ログイン停止を避ける更新手順</title><link>https://cyber-security-lens.com/news/saml-sso-certificate-renewal-checklist/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/saml-sso-certificate-renewal-checklist/</guid><description>SAML証明書やSSO証明書の期限切れでSaaSログイン停止を起こさないための実務手順。IdPとSaaSの証明書更新、事前通知、切替順序、ロールバック、ログ確認、監査証跡、緊急時の代替ログインまで情シス・SaaS管理者向けに整理します。</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>SAML</category><category>SSO</category><category>証明書更新</category><category>IdP</category><category>SaaS</category><category>認証</category><category>ログイン障害</category><category>変更管理</category><category>アクセスレビュー</category></item><item><title>SCIM連携・自動プロビジョニングの確認方法 ─ 退職者アカウントをSaaSに残さない実務手順</title><link>https://cyber-security-lens.com/news/scim-provisioning-drift-checklist/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/scim-provisioning-drift-checklist/</guid><description>SCIM連携や自動プロビジョニングで退職者アカウントがSaaSに残る原因を整理。同期対象、グループ、手動招待、provisioning logs、active=false、証跡確認、エスカレーション条件まで情シス・SaaS管理者向けに解説します。</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><category>SCIM</category><category>プロビジョニング</category><category>デプロビジョニング</category><category>退職者対応</category><category>SaaS</category><category>IdP</category><category>SSO</category><category>IAM</category><category>アクセスレビュー</category><category>GitHub</category></item><item><title>JIT Access / PIM導入時の運用設計 ─ 管理者権限を必要な時だけ渡す方法</title><link>https://cyber-security-lens.com/news/jit-access-pim-operation-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/jit-access-pim-operation-guide/</guid><description>JIT Access / PIM導入時に決めるべき対象ロール、承認者、MFA、理由入力、期限、監査ログ、break glassとの違いを整理。情シス・SaaS管理者が一時権限を安全に運用するための実務チェックリスト。導入前確認、初動設計、エスカレーション判断まで解説。</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>JIT Access</category><category>PIM</category><category>PAM</category><category>管理者権限</category><category>Zero Standing Privilege</category><category>Microsoft Entra</category><category>Google Cloud</category><category>監査ログ</category><category>SaaS</category></item><item><title>管理者権限が急に付与された時の初動対応 ─ SaaS・IdP・GitHubでまず確認すること</title><link>https://cyber-security-lens.com/news/admin-role-assignment-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/admin-role-assignment-first-response/</guid><description>Microsoft Entra、Google Workspace、GitHubで管理者権限が急に付与された時の確認方法を、監査ログ、付与理由、影響範囲、失効、記録テンプレートまで整理する。</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>管理者権限</category><category>PAM</category><category>IAM</category><category>SaaS</category><category>Microsoft Entra</category><category>Google Workspace</category><category>GitHub</category><category>監査ログ</category><category>Access Review</category></item><item><title>GitHub Secret Scanningアラート初動対応 ─ トークン漏えい時にまず確認すること</title><link>https://cyber-security-lens.com/news/github-secret-scanning-alert-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/github-secret-scanning-alert-first-response/</guid><description>GitHub Secret Scanningアラートを受け取った時の初動対応を、secret種別、validity、公開範囲、失効、ログ確認、再発防止まで実務チェックリストで整理する。</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>GitHub</category><category>Secret Scanning</category><category>Push Protection</category><category>トークン漏えい</category><category>PAT</category><category>CI/CD</category><category>シークレット管理</category><category>開発者セキュリティ</category></item><item><title>LiteLLM CVE-2026-42271 ─ MCP接続テスト機能のコマンドインジェクションで確認すること</title><link>https://cyber-security-lens.com/news/litellm-mcp-command-injection-cve-2026-42271/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/litellm-mcp-command-injection-cve-2026-42271/</guid><description>CISA KEVに追加されたLiteLLM CVE-2026-42271について、MCP接続テスト機能、低権限キー、AI Gatewayの公開範囲、APIキー、ログ、更新判断を防御側の初動として整理する。</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>LiteLLM</category><category>CVE-2026-42271</category><category>AI Gateway</category><category>MCP</category><category>Command Injection</category><category>APIキー</category><category>CISA KEV</category><category>脆弱性管理</category></item><item><title>LiteSpeed cPanel Plugin CVE-2026-54420 ─ 共有ホスティングで確認すべき初動</title><link>https://cyber-security-lens.com/news/litespeed-cpanel-plugin-cve-2026-54420-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/litespeed-cpanel-plugin-cve-2026-54420-kev/</guid><description>CISA KEVに追加されたLiteSpeed cPanel Plugin CVE-2026-54420について、共有ホスティング、CloudLinux/CageFS、cPanel利用環境でまず確認すべき更新、ログ、顧客影響、委託先連絡を整理する。</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>LiteSpeed</category><category>cPanel</category><category>CVE-2026-54420</category><category>CISA KEV</category><category>共有ホスティング</category><category>権限昇格</category><category>脆弱性管理</category></item><item><title>公開管理画面を見つけた時の初動対応 ─ 外部露出・認証・ログをどう確認するか</title><link>https://cyber-security-lens.com/news/internet-facing-management-plane-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/internet-facing-management-plane-first-response/</guid><description>公開管理画面や認証ポータルがインターネットから到達できると分かった時に、外部露出、MFA、IP制限、ログ、委託先アクセスをどう確認し、封じ込めと記録へ進めるかを整理する。</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>管理画面</category><category>管理プレーン</category><category>外部露出</category><category>初動対応</category><category>ゼロトラスト</category><category>脆弱性管理</category><category>情シス</category></item><item><title>条件付きアクセス例外の棚卸し ─ MFA除外・場所例外を安全に見直す</title><link>https://cyber-security-lens.com/news/conditional-access-exception-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/conditional-access-exception-review/</guid><description>条件付きアクセスのMFA除外、場所例外、端末条件、break glassを安全に棚卸しする実務手順。例外の理由、期限、ログ、初動対応、判断基準を整理します。</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>条件付きアクセス</category><category>MFA</category><category>例外管理</category><category>SaaS</category><category>IdP</category><category>ゼロトラスト</category><category>情シス</category><category>初動対応</category></item><item><title>緊急用管理者アカウントの棚卸し ─ break glassを安全に運用する初動確認</title><link>https://cyber-security-lens.com/news/emergency-admin-account-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/emergency-admin-account-review/</guid><description>緊急用管理者アカウント（break glass）を、IdP障害やロックアウトに備えて安全に運用する確認手順。保管、監査ログ、権限、訓練、誤用時の初動を整理します。</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>緊急用管理者アカウント</category><category>Break Glass</category><category>IdP</category><category>PAM</category><category>条件付きアクセス</category><category>管理者権限</category><category>情シス</category><category>初動対応</category></item><item><title>ヘルプデスクを狙うMFAリセット依頼の初動対応 ─ 本人確認とアカウント復旧で見ること</title><link>https://cyber-security-lens.com/news/helpdesk-account-recovery-social-engineering/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/helpdesk-account-recovery-social-engineering/</guid><description>ヘルプデスクへのMFAリセット、パスワード再発行、端末登録依頼を受けたときの本人確認、ログ確認、セッション失効、エスカレーション条件を実務向けに整理する。</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>ヘルプデスク</category><category>MFA</category><category>アカウント復旧</category><category>本人確認</category><category>ソーシャルエンジニアリング</category><category>SaaS</category><category>IdP</category><category>初動対応</category></item><item><title>委託先・外部パートナーアカウントの棚卸し ─ SaaS・GitHub・Slackでまず確認すること</title><link>https://cyber-security-lens.com/news/third-party-access-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/third-party-access-review/</guid><description>委託先・取引先・外部パートナーのSaaS、GitHub、Slack、Microsoft 365権限を棚卸しする手順を整理。確認項目、初動対応、エスカレーション条件を実務向けに解説します。</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>SaaS</category><category>委託先管理</category><category>外部ユーザー</category><category>サードパーティリスク</category><category>アクセスレビュー</category><category>GitHub</category><category>Slack</category><category>Microsoft Entra</category></item><item><title>SaaS外部共有リンクの棚卸し ─ Google Drive・OneDrive・Slackでまず確認すること</title><link>https://cyber-security-lens.com/news/saas-external-sharing-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/saas-external-sharing-review/</guid><description>Google Drive、OneDrive、SharePoint、Slack Connectなどの外部共有リンクを棚卸しする手順を整理。確認項目、初動対応、判断基準を情シス・SaaS管理者向けに解説します。</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><category>SaaS</category><category>外部共有</category><category>Google Drive</category><category>OneDrive</category><category>SharePoint</category><category>Slack Connect</category><category>DLP</category><category>SSPM</category><category>情シス</category></item><item><title>ブラウザ拡張機能の権限棚卸し ─ Chrome/Edgeでまず確認すること</title><link>https://cyber-security-lens.com/news/browser-extension-permission-review/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/browser-extension-permission-review/</guid><description>ブラウザ拡張機能は閲覧データやSaaS情報に触れる権限を持つことがあります。Chrome/Edgeの拡張機能を棚卸しし、許可範囲、サイトアクセス、初動対応、記録、エスカレーション条件を整理します。</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>ブラウザ拡張機能</category><category>Chrome</category><category>Edge</category><category>SaaS</category><category>権限棚卸し</category><category>OAuth</category><category>初動対応</category><category>情シス</category></item><item><title>退職者アカウントが残っていた時の初動対応 ─ SaaS・GitHub・メール転送の確認手順</title><link>https://cyber-security-lens.com/news/offboarding-account-leftover-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/offboarding-account-leftover-response/</guid><description>退職者アカウントや委託終了者のSaaS権限が残っていた時に、まず何を止め、どのログを確認し、どこまで記録するかを実務手順で整理します。</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>退職者対応</category><category>アカウント管理</category><category>SaaS</category><category>GitHub</category><category>メール転送</category><category>SCIM</category><category>アクセスレビュー</category></item><item><title>PAN-OS CVE-2026-0257がKEV追加：GlobalProtect VPNの初動確認</title><link>https://cyber-security-lens.com/news/pan-os-cve-2026-0257-globalprotect-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/pan-os-cve-2026-0257-globalprotect-kev/</guid><description>CISA KEVに追加されたPAN-OS CVE-2026-0257について、GlobalProtect VPNの利用有無、対象バージョン、緩和策、ログ確認、エスカレーション判断を実務向けに整理します。</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>PAN-OS</category><category>Palo Alto Networks</category><category>CVE-2026-0257</category><category>CISA KEV</category><category>GlobalProtect</category><category>VPN</category><category>脆弱性管理</category></item><item><title>Microsoft Defenderの2件がKEV追加：端末保護の更新確認と初動対応</title><link>https://cyber-security-lens.com/news/microsoft-defender-kev-cve-2026-41091-45498/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/microsoft-defender-kev-cve-2026-41091-45498/</guid><description>CISA KEVに追加されたMicrosoft Defender関連のCVE-2026-41091とCVE-2026-45498について、影響端末、エンジン更新、ログ確認、例外端末の扱いを実務向けに整理する。</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Microsoft Defender</category><category>CVE-2026-41091</category><category>CVE-2026-45498</category><category>CISA KEV</category><category>エンドポイント</category><category>脆弱性対応</category></item><item><title>Nx ConsoleとTanStackのサプライチェーン侵害：開発端末で確認すること</title><link>https://cyber-security-lens.com/news/nx-console-tanstack-supply-chain-cve-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/nx-console-tanstack-supply-chain-cve-2026/</guid><description>CISA KEVに追加されたNx Console CVE-2026-48027とTanStack CVE-2026-45321をもとに、拡張機能、npmパッケージ、開発端末、トークンの確認手順を整理する。</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>サプライチェーン</category><category>Nx Console</category><category>TanStack</category><category>CVE-2026-48027</category><category>CVE-2026-45321</category><category>開発者セキュリティ</category></item><item><title>MFA疲労攻撃の初動対応：プッシュ通知を承認したかもしれない時に確認すること</title><link>https://cyber-security-lens.com/news/mfa-fatigue-first-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/mfa-fatigue-first-response/</guid><description>MFAプッシュ通知を誤って承認したかもしれない時に、本人確認、サインインログ、セッション失効、MFA再登録、番号一致・パスキー移行までを確認する実務手順を整理する。</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>MFA</category><category>MFA Fatigue</category><category>フィッシング</category><category>認証</category><category>初動対応</category><category>パスキー</category></item><item><title>DMARCレポートの見方と初動対応：なりすまし疑いをどう確認するか</title><link>https://cyber-security-lens.com/news/dmarc-report-triage-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/dmarc-report-triage-guide/</guid><description>DMARCレポートで自社ドメインのなりすまし疑いを見つけたとき、SPF/DKIMのアライメント、正規送信元、DNS設定、エスカレーション条件を確認する手順を整理する。</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>DMARC</category><category>SPF</category><category>DKIM</category><category>メールセキュリティ</category><category>フィッシング</category><category>初動対応</category></item><item><title>Langflow CVE-2025-34291がKEV追加：AI基盤のCORSとセッションを確認する</title><link>https://cyber-security-lens.com/news/langflow-cve-2025-34291-kev-cors-session/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/langflow-cve-2025-34291-kev-cors-session/</guid><description>CISA KEVに追加されたLangflow CVE-2025-34291について、公開範囲、CORS、SameSite Cookie、refresh token、更新、ログ確認を防御側の初動手順として整理する。</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>CVE-2025-34291</category><category>KEV</category><category>CORS</category><category>セッション管理</category><category>AIセキュリティ</category></item><item><title>Drupal Core CVE-2026-9082がKEV追加：Web担当者が確認すること</title><link>https://cyber-security-lens.com/news/drupal-core-cve-2026-9082-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/drupal-core-cve-2026-9082-kev/</guid><description>CISA KEVに追加されたDrupal CoreのSQL Injection脆弱性について、対象バージョン、PostgreSQL利用、公開サイト、更新判断、ログ確認を実務向けに整理する。</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><category>Drupal</category><category>CVE-2026-9082</category><category>KEV</category><category>SQL Injection</category><category>CMS</category><category>脆弱性対応</category></item><item><title>Trend Micro Apex One CVE-2026-34926がKEV追加：EDR/エンドポイント運用で確認すること</title><link>https://cyber-security-lens.com/news/trend-micro-apex-one-cve-2026-34926-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/trend-micro-apex-one-cve-2026-34926-kev/</guid><description>CISA KEVに追加されたTrend Micro Apex Oneの脆弱性について、オンプレ管理サーバー、エージェントbuild、管理者権限、更新、ログ確認を整理する。</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><category>Trend Micro</category><category>Apex One</category><category>CVE-2026-34926</category><category>KEV</category><category>EDR</category><category>エンドポイントセキュリティ</category></item><item><title>バックアップ復旧テストの始め方 ─ ランサムウェアに備える確認手順</title><link>https://cyber-security-lens.com/news/backup-restore-test-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/backup-restore-test-guide/</guid><description>バックアップ復旧テストの進め方を初心者向けに整理。RTO/RPO、復旧手順、記録、エスカレーション条件を確認し、ランサムウェア時に慌てない準備へつなげます。</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>バックアップ</category><category>ランサムウェア</category><category>復旧テスト</category><category>RTO</category><category>RPO</category><category>BCP</category></item><item><title>Cisco Catalyst SD-WAN CVE-2026-20182 ─ KEV追加後に管理プレーンで確認すること</title><link>https://cyber-security-lens.com/news/cisco-catalyst-sdwan-cve-2026-20182-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cisco-catalyst-sdwan-cve-2026-20182-kev/</guid><description>CISA KEVに追加されたCisco Catalyst SD-WAN Controller/Managerの認証回避脆弱性について、対象製品、外部公開、ログ保全、更新、エスカレーションの初動確認を整理する。</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN</category><category>CVE-2026-20182</category><category>KEV</category><category>管理プレーン</category><category>認証回避</category></item><item><title>Microsoft Exchange CVE-2026-42897 ─ KEV追加後にメール基盤で確認すること</title><link>https://cyber-security-lens.com/news/microsoft-exchange-cve-2026-42897-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/microsoft-exchange-cve-2026-42897-kev/</guid><description>CISA KEVに追加されたMicrosoft Exchange ServerのXSS脆弱性について、OWA、EEMS緩和策、対象サーバー、ユーザー報告、ログ確認、初動対応を整理する。</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><category>Microsoft Exchange</category><category>CVE-2026-42897</category><category>KEV</category><category>XSS</category><category>OWA</category><category>メール基盤</category></item><item><title>心当たりのないパスワードリセットメールの確認方法と初動対応</title><link>https://cyber-security-lens.com/news/unexpected-password-reset-email-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/unexpected-password-reset-email-response/</guid><description>心当たりのないパスワードリセットメールが届いたとき、本物か不審かをどう確認し、リンクを押さずにアカウント・SaaS・ログを守るかを実務チェックリストで整理する。</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><category>パスワードリセット</category><category>フィッシング</category><category>アカウント保護</category><category>SaaS</category><category>MFA</category><category>初動対応</category><category>初心者</category></item><item><title>EDRアラートの初動対応 ─ 最初に見るべき確認項目</title><link>https://cyber-security-lens.com/news/edr-alert-first-response-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/edr-alert-first-response-2026/</guid><description>EDRアラートを受けたとき、端末、ユーザー、プロセス、通信、隔離要否、記録の残し方をどう確認するか。初心者でも初動で迷わない判断基準とチェックリストを整理する。</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>EDR</category><category>SOC</category><category>インシデント対応</category><category>ログ分析</category><category>封じ込め</category><category>初動対応</category><category>初心者</category></item><item><title>監査ログの保管期間はどう決める？初動で困らないログ設計</title><link>https://cyber-security-lens.com/news/audit-log-retention-guide-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/audit-log-retention-guide-2026/</guid><description>監査ログの保管期間を、インシデント初動、SaaS棚卸し、内部統制、証拠保全から逆算して決める実務ガイド。残すログ、残しすぎない情報、見直し周期を整理する。</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>監査ログ</category><category>ログ保管</category><category>インシデント対応</category><category>SaaS</category><category>内部統制</category><category>証拠保全</category><category>SIEM</category></item><item><title>セキュリティログの読み方 ─ 初心者が最初に見るべき5種類</title><link>https://cyber-security-lens.com/news/security-log-reading-basics-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/security-log-reading-basics-2026/</guid><description>サインインログ、Webアクセスログ、EDR、SaaS監査ログ、DNS/プロキシログをどう読むか。初心者が初動で見るべき順番と記録の残し方を整理する。</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>ログ分析</category><category>SIEM</category><category>SOC</category><category>インシデント対応</category><category>監査ログ</category><category>SaaS</category><category>EDR</category><category>初心者</category></item><item><title>セキュリティ例外申請の書き方 ─ パッチ延期・認証例外を安全に残す実務テンプレート</title><link>https://cyber-security-lens.com/news/security-exception-request-template/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/security-exception-request-template/</guid><description>パッチ延期、SaaS権限、認証例外を期限付きで扱うためのセキュリティ例外申請テンプレート。理由、暫定策、承認者、再評価条件の残し方を整理する。</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>例外管理</category><category>リスク管理</category><category>変更管理</category><category>脆弱性管理</category><category>パッチ管理</category><category>SaaS</category><category>認証</category><category>情シス</category></item><item><title>LiteLLM CVE-2026-42208 ─ AIプロキシのSQL Injectionで最初に確認すること</title><link>https://cyber-security-lens.com/news/litellm-sql-injection-cve-2026-42208/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/litellm-sql-injection-cve-2026-42208/</guid><description>CISA KEVに追加されたLiteLLMのSQL Injection脆弱性について、対象バージョン、影響範囲、APIキー確認、更新・ローテーションの初動を整理する。</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>LiteLLM</category><category>CVE-2026-42208</category><category>AI Gateway</category><category>APIキー</category><category>KEV</category><category>脆弱性管理</category></item><item><title>Windows Shell CVE-2026-32202 ─ spoofing系脆弱性の初動確認</title><link>https://cyber-security-lens.com/news/windows-shell-spoofing-cve-2026-32202/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/windows-shell-spoofing-cve-2026-32202/</guid><description>CISA KEVに追加されたWindows Shellのspoofing系脆弱性について、更新状況、端末影響、ユーザー周知、ログ確認の初動を整理する。</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>Windows</category><category>CVE-2026-32202</category><category>Microsoft</category><category>KEV</category><category>Patch Tuesday</category><category>spoofing</category></item><item><title>Linux Kernel CVE-2026-31431 ─ Copy Failで最初に確認すること</title><link>https://cyber-security-lens.com/news/linux-copy-fail-cve-2026-31431/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/linux-copy-fail-cve-2026-31431/</guid><description>CISA KEVに追加されたLinux KernelのCVE-2026-31431 Copy Failについて、対象サーバー、Kubernetes、CI/CDランナーで最初に確認すべき影響範囲、パッチ判断、暫定緩和、記録の残し方を整理する。</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>Linux</category><category>CVE-2026-31431</category><category>Copy Fail</category><category>KEV</category><category>権限昇格</category><category>Kubernetes</category><category>パッチ管理</category></item><item><title>cPanel/WHM CVE-2026-41940 ─ ホスティング管理画面の認証回避リスクと初動対応</title><link>https://cyber-security-lens.com/news/cpanel-whm-cve-2026-41940-auth-bypass/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cpanel-whm-cve-2026-41940-auth-bypass/</guid><description>CISA KEVに追加されたcPanel &amp; WHM / WP2のCVE-2026-41940について、公開管理画面、更新状況、ログ確認、顧客影響、初動対応を防御側の観点で整理します。</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>cPanel</category><category>WHM</category><category>WP2</category><category>CVE-2026-41940</category><category>CISA KEV</category><category>認証回避</category><category>ランサムウェア</category></item><item><title>デバイスコードフィッシング ─ Microsoft 365で狙われるOAuth認証の盲点</title><link>https://cyber-security-lens.com/news/device-code-phishing-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/device-code-phishing-2026/</guid><description>デバイスコードフィッシングは、正規のログイン画面を使って攻撃者のセッションを承認させる。Microsoft 365で見るべきログ、初動、条件付きアクセスの考え方を整理する。</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>デバイスコードフィッシング</category><category>OAuth</category><category>Microsoft 365</category><category>MFA</category><category>条件付きアクセス</category><category>フィッシング</category><category>2026</category></item><item><title>PAN-OS CVE-2026-0300 ─ User-ID Authentication Portalを公開している組織の初動確認</title><link>https://cyber-security-lens.com/news/pan-os-cve-2026-0300-user-id-portal/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/pan-os-cve-2026-0300-user-id-portal/</guid><description>CISA KEVに追加されたPAN-OS CVE-2026-0300について、User-ID Authentication Portalの公開状況、信頼ゾーン制限、無効化判断、初動確認を防御側の実務観点で整理します。</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>PAN-OS</category><category>Palo Alto Networks</category><category>CVE-2026-0300</category><category>CISA KEV</category><category>管理プレーン</category><category>脆弱性管理</category></item><item><title>SSVCとは ─ 脆弱性対応をTrack/Attend/Actで決める方法</title><link>https://cyber-security-lens.com/news/ssvc-vulnerability-triage/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ssvc-vulnerability-triage/</guid><description>SSVCは、CVSSやEPSSだけでは決めきれない脆弱性対応を、Track・Attend・Actの判断へ落とす考え方。情シスやSOCが使える優先度付けの手順を解説する。</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><category>SSVC</category><category>CVE</category><category>CVSS</category><category>EPSS</category><category>KEV</category><category>脆弱性管理</category><category>パッチ管理</category><category>情シス</category></item><item><title>AIエージェント利用ルール ─ 社内導入で先に決める権限・ログ・禁止事項</title><link>https://cyber-security-lens.com/news/ai-agent-security-policy-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ai-agent-security-policy-2026/</guid><description>AIエージェントを社内導入する前に、権限、データ持ち出し、ツール実行、ログ、承認、停止手順をどう決めるか。情シス・CSIRT向けに実務ルールを整理する。</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><category>AIエージェント</category><category>生成AI</category><category>権限管理</category><category>データ保護</category><category>ゼロトラスト</category><category>情シス</category><category>2026</category></item><item><title>ランサムウェア初動対応 ─ 最初の1時間でやること・やってはいけないこと</title><link>https://cyber-security-lens.com/news/ransomware-first-hour-response/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ransomware-first-hour-response/</guid><description>ランサムウェア感染が疑われる最初の1時間に、端末隔離、共有領域保護、証跡保全、バックアップ確認、社内報告をどう進めるかを実務目線で整理する。</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>ランサムウェア</category><category>インシデント対応</category><category>初動対応</category><category>バックアップ</category><category>EDR</category><category>CSIRT</category></item><item><title>KEVとは ─ CVSSだけに頼らない脆弱性対応の優先順位</title><link>https://cyber-security-lens.com/news/kev-vulnerability-prioritization-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/kev-vulnerability-prioritization-guide/</guid><description>CISA KEV、CVSS、EPSS、インターネット露出、自社資産の重要度を組み合わせ、CVE対応の優先順位を決める実務手順を解説する。</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>KEV</category><category>CVE</category><category>CVSS</category><category>脆弱性管理</category><category>パッチ管理</category><category>情シス</category></item><item><title>SaaS権限棚卸しの進め方 ─ 退職者・OAuth・外部共有を見落とさない実務手順</title><link>https://cyber-security-lens.com/news/saas-access-review-guide/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/saas-access-review-guide/</guid><description>SaaS権限棚卸しを、管理者ロール、退職者アカウント、OAuth同意、外部共有、APIトークンの観点で整理。初回30日の進め方と優先順位を解説する。</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>SaaS</category><category>権限管理</category><category>OAuth</category><category>退職者対応</category><category>ゼロトラスト</category><category>情シス</category></item><item><title>フィッシングメールの見分け方 2026年版 ─ 迷ったときの確認チェックリスト</title><link>https://cyber-security-lens.com/news/phishing-email-checklist-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/phishing-email-checklist-2026/</guid><description>フィッシングメールを開く前に確認すべき送信元、URL、添付ファイル、ログイン画面、AI生成文面の違和感を整理。個人と企業で使える実践チェックリストを紹介する。</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>フィッシング</category><category>メールセキュリティ</category><category>見分け方</category><category>チェックリスト</category><category>個人セキュリティ</category><category>2026</category></item><item><title>サイバーセキュリティ勉強方法 2026年版 ─ 初心者が迷わない学習ロードマップ</title><link>https://cyber-security-lens.com/news/cybersecurity-learning-roadmap-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cybersecurity-learning-roadmap-2026/</guid><description>サイバーセキュリティを何から勉強すればよいか迷う初心者向けに、基礎、用語、攻撃手法、防御、ハンズオンまでの順番を整理。情シス、開発者、SOC志望など目的別の進め方も紹介する。</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>勉強方法</category><category>初心者</category><category>ロードマップ</category><category>用語学習</category><category>ハンズオン</category><category>2026</category></item><item><title>マネーフォワードGitHub不正アクセス ─ リポジトリコピーから考える開発組織の初動</title><link>https://cyber-security-lens.com/news/money-forward-github-breach-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/money-forward-github-breach-2026/</guid><description>2026年5月に公表されたマネーフォワードのGitHub不正アクセスを、公式発表をもとに整理。認証情報漏えい、リポジトリコピー、鍵ローテーション、銀行口座連携停止から、開発組織が確認すべき実務対応を解説する。</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>マネーフォワード</category><category>GitHub</category><category>認証情報漏洩</category><category>インシデント対応</category><category>サプライチェーン</category><category>開発者セキュリティ</category><category>2026</category></item><item><title>OAuth同意フィッシング ─ MFAをすり抜けるSaaS権限奪取</title><link>https://cyber-security-lens.com/news/oauth-consent-phishing/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/oauth-consent-phishing/</guid><description>OAuth同意フィッシングは、MFAを破らずSaaSアプリ連携の権限を奪う。危険な同意画面、管理者同意、監査ログ、アプリ制御の実務対応を整理する。</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>フィッシング</category><category>MFA</category><category>認証</category><category>ゼロトラスト</category><category>クラウドセキュリティ</category><category>2026</category></item><item><title>パスキー導入の落とし穴 ─ フィッシング耐性MFAを失敗させない移行設計</title><link>https://cyber-security-lens.com/news/passkey-rollout-pitfalls/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/passkey-rollout-pitfalls/</guid><description>パスキーはフィッシングに強い認証だが、復旧導線、共有端末、例外運用を誤ると導入後に形骸化する。FIDO2/WebAuthnを組織へ広げる前に決めるべき設計と、段階導入の実務ポイントを整理する。</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>パスキー</category><category>MFA</category><category>認証</category><category>フィッシング</category><category>ゼロトラスト</category><category>2026</category></item><item><title>Marimo RCE CVE-2026-39987 ─ 公開10時間未満で悪用、AIノートブックを守る実務対応</title><link>https://cyber-security-lens.com/news/marimo-rce-cve-2026-39987-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/marimo-rce-cve-2026-39987-kev/</guid><description>MarimoのCVE-2026-39987は、未認証でターミナルWebSocketからシェルに到達できる重大なRCE脆弱性だ。CISA KEV追加、公開後9時間41分での悪用観測、影響環境、更新・露出遮断・資格情報ローテーションまで実務対応を整理する。</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>AIセキュリティ</category><category>RCE</category><category>脆弱性管理</category><category>ゼロデイ</category><category>CVE</category><category>KEV</category><category>管理プレーン</category></item><item><title>FortiClient EMS ゼロデイ CVE-2026-35616 ─ 管理APIバイパスがKEV入り、露出確認と封じ込めを急ぐべき理由</title><link>https://cyber-security-lens.com/news/forticlient-ems-cve-2026-35616-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/forticlient-ems-cve-2026-35616-kev/</guid><description>Fortinet FortiClient EMS の管理API認証・認可バイパス脆弱性 CVE-2026-35616 がCISA KEVへ追加された。影響バージョン、ホットフィックス、管理プレーン露出の危険性、侵害確認と封じ込めの実務手順を整理する。</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category><category>CVE</category><category>KEV</category><category>ゼロデイ</category><category>管理API</category><category>管理プレーン</category><category>パッチ管理</category></item><item><title>Apache ActiveMQ Classic のRCEが実戦投入 ─ CVE-2026-34197 と管理API露出の危険</title><link>https://cyber-security-lens.com/news/apache-activemq-cve-2026-34197-kev-active-exploitation/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/apache-activemq-cve-2026-34197-kev-active-exploitation/</guid><description>Apache ActiveMQ Classic のコード実行脆弱性 CVE-2026-34197 が2026年4月16日にCISA KEVへ追加され、実際の悪用が確認された。影響バージョン、Jolokia管理APIが危険な理由、6.0.0〜6.1.1でさらに深刻になる背景、管理者が直ちに取るべき対策を整理する。</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>Apache ActiveMQ</category><category>CVE</category><category>RCE</category><category>Jolokia</category><category>Java</category><category>KEV</category><category>パッチ管理</category></item><item><title>「私はロボットではありません」の罠 ─ ClickFix攻撃が2026年に主流化したワケ</title><link>https://cyber-security-lens.com/news/clickfix-fake-captcha-attack-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/clickfix-fake-captcha-attack-2026/</guid><description>「人間か確認します」と表示される偽のCAPTCHA画面に従うと、知らぬ間にPowerShellでマルウェアが実行される──。2024年から急拡大したClickFix（クリックフィックス）攻撃は、2026年にはフィッシングと並ぶ主要な配送経路になりました。仕組みと、個人・組織の両方でできる対策をやさしく解説します。</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>clickfix</category><category>social-engineering</category><category>phishing</category><category>infostealer</category><category>powershell</category><category>browser-attack</category><category>user-awareness</category></item><item><title>Adobe Acrobat Reader ゼロデイ CVE-2026-34621 ─ PDFを開くだけでローカルファイル窃取・任意コード実行</title><link>https://cyber-security-lens.com/news/adobe-acrobat-cve-2026-34621-zero-day/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/adobe-acrobat-cve-2026-34621-zero-day/</guid><description>2026年4月12日、Adobe Acrobat Readerに2025年11月から悪用されていたゼロデイCVE-2026-34621（CVSS 8.6）の緊急パッチが公開された。プロトタイプ汚染を利用した手法で悪意あるPDFを開くだけでローカルファイル窃取や任意コード実行が可能。初期VirusTotal検出率は13/64と極めて低く、パッチ未適用環境への警戒が求められる。</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>Adobe Acrobat</category><category>ゼロデイ</category><category>PDF</category><category>プロトタイプ汚染</category><category>CVE</category><category>JavaScript</category><category>緊急パッチ</category></item><item><title>CPU-Z・HWMonitorに仕込まれたSTX RAT ─ 公式サイト6時間改ざんのウォータリングホール攻撃</title><link>https://cyber-security-lens.com/news/cpuid-hwmonitor-stx-rat-supply-chain-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cpuid-hwmonitor-stx-rat-supply-chain-2026/</guid><description>2026年4月9〜10日、PC診断ツールメーカーCPUIDの公式サイトが約6時間改ざんされ、CPU-Z・HWMonitorのダウンロードリンクがSTX RAT配布ファイルに差し替えられた。DLLサイドローディングと5段階インメモリ感染チェーンを使う高度な攻撃の全容を解説する。</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>ウォータリングホール</category><category>サプライチェーン</category><category>DLLサイドローディング</category><category>RAT</category><category>マルウェア</category><category>CPU-Z</category><category>HWMonitor</category></item><item><title>Ivanti EPMM CVE-2026-1340/1281 ─ CVSS 9.8、4,400超インスタンスが危険、CISAが4/11までのパッチを命令</title><link>https://cyber-security-lens.com/news/ivanti-epmm-cve-2026-1340-cisa-kev/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ivanti-epmm-cve-2026-1340-cisa-kev/</guid><description>IvantiのMDMソリューション「EPMM」に深刻な脆弱性CVE-2026-1340/1281（CVSS 9.8）が見つかり、4,400超のインスタンスが危険にさらされています。CISAはKEVカタログに登録し連邦機関へ4/11までのパッチを命令。実際の攻撃手法と緊急対策を解説します。</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>脆弱性</category><category>Ivanti</category><category>MDM</category><category>RCE</category><category>CISA</category><category>CVE</category><category>エンタープライズ</category></item><item><title>北朝鮮「Contagious Interview」— npm・PyPI・Go・Rust・PHPに1,700本超の偽パッケージを展開</title><link>https://cyber-security-lens.com/news/north-korea-contagious-interview-1700-packages-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/north-korea-contagious-interview-1700-packages-2026/</guid><description>北朝鮮連動のAPTグループ「Contagious Interview（UNC1069）」が5つのパッケージエコシステムに1,700本以上の悪意あるパッケージを展開。開発者のクレデンシャルや暗号資産ウォレットを狙うクロスエコシステム・サプライチェーン攻撃の全貌を解説します。</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>サプライチェーン</category><category>北朝鮮</category><category>npm</category><category>PyPI</category><category>開発者</category><category>マルウェア</category><category>OSS</category></item><item><title>週1億DLのaxiosに北朝鮮バックドア ─ UNC1069による3時間のサプライチェーン汚染</title><link>https://cyber-security-lens.com/news/axios-npm-supply-chain-unc1069-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/axios-npm-supply-chain-unc1069-2026/</guid><description>2026年3月31日、北朝鮮系のUNC1069が人気JavaScriptライブラリaxiosのnpmアカウントを侵害し、WAVESHAPER.V2バックドアを仕込んだ悪意あるバージョンを公開しました。80%のクラウド環境が影響を受け得るこのサプライチェーン攻撃の全貌を解説します。</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>サプライチェーン</category><category>npm</category><category>北朝鮮</category><category>UNC1069</category><category>JavaScript</category><category>バックドア</category><category>OSS</category></item><item><title>2026年4度目のChromeゼロデイ ─ WebGPUのUAFがサンドボックス脱出チェーンに悪用</title><link>https://cyber-security-lens.com/news/chrome-webgpu-cve-2026-5281/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/chrome-webgpu-cve-2026-5281/</guid><description>CVE-2026-5281はChromeのWebGPU実装「Dawn」に存在するuse-after-free脆弱性で、野生での悪用が確認されCISAのKEVカタログに追加されました。2026年に入り4度目のChromeゼロデイが示すWebGPUという新たな攻撃面の拡大を解説します。</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Chrome</category><category>WebGPU</category><category>CVE</category><category>ゼロデイ</category><category>ブラウザ</category><category>UAF</category><category>サンドボックス</category></item><item><title>Cisco FMC CVE-2026-20131 ─ KEV追加済みの管理基盤RCEをどう点検するか</title><link>https://cyber-security-lens.com/news/cisco-fmc-cve-2026-20131-interlock/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cisco-fmc-cve-2026-20131-interlock/</guid><description>Cisco Secure Firewall Management CenterのCVE-2026-20131は、CISA KEVにも追加された重大な管理基盤RCEです。公式情報とAmazonの公開分析をもとに、FMC管理者が確認すべき初動を整理します。</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>FMC</category><category>CVE</category><category>ランサムウェア</category><category>Interlock</category><category>KEV</category><category>Javaデシリアライゼーション</category></item><item><title>セッションIDが筒抜けに ─ Citrix NetScaler SAML IDPの記憶漏洩脆弱性CVE-2026-3055が野生で悪用</title><link>https://cyber-security-lens.com/news/citrix-netscaler-cve-2026-3055/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/citrix-netscaler-cve-2026-3055/</guid><description>CVSS 9.3のCitrix NetScalerメモリ読み取り脆弱性が2026年3月27日から積極的に悪用されています。SAMLログインに細工したリクエストを送るだけで、認証済み管理者のセッションIDがCookieに乗って返ってくる──この攻撃の仕組みと即時対応を解説します。</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>Citrix</category><category>NetScaler</category><category>CVE</category><category>メモリ脆弱性</category><category>SAML</category><category>ネットワーク機器</category></item><item><title>FBI長官のメールを盗んだ集団 ─ イラン系ハクティビストHandalaが仕掛けた報復型サイバー作戦</title><link>https://cyber-security-lens.com/news/handala-fbi-director-email-breach-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/handala-fbi-director-email-breach-2026/</guid><description>2026年3月27日、イラン系ハッカー集団HandalaがFBI長官カッシュ・パテル氏の個人メールを侵害し、300通以上のメールと私的写真を公開しました。FBIが同集団のドメインを押収した翌週という「報復」の構図、そして高位職にある人物のデジタルセキュリティが持つ意味を解説します。</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>イラン</category><category>Handala</category><category>国家ハッカー</category><category>ハクティビズム</category><category>標的型攻撃</category><category>個人セキュリティ</category></item><item><title>「侵入」から「ログイン」へ ─ インフォスティーラーとエージェンティックAIが変えたサイバー犯罪の構造</title><link>https://cyber-security-lens.com/news/infostealer-agentic-ai-credential-crisis-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/infostealer-agentic-ai-credential-crisis-2026/</guid><description>2025年に世界で1,100万台のマシンに感染したインフォスティーラーが33億件の認証情報を生産し、エージェンティックAIがそれを自動的にテスト・悪用する時代が来ています。「脆弱性を突く」から「正規のIDで入る」へという攻撃パラダイムの転換と、組織が取るべき対策を解説します。</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>インフォスティーラー</category><category>エージェンティックAI</category><category>認証情報漏洩</category><category>クレデンシャルスタッフィング</category><category>脅威トレンド</category></item><item><title>公開から20時間で世界規模の攻撃へ ─ LangflowのRCE脆弱性が示す「アドバイザリー駆動型エクスプロイト」の脅威</title><link>https://cyber-security-lens.com/news/langflow-rce-20hours-exploit-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/langflow-rce-20hours-exploit-2026/</guid><description>AIワークフロー構築ツールLangflowの重大なリモートコード実行脆弱性CVE-2026-33017が、公開からわずか20時間で実際の攻撃に悪用された。概念実証コードがない状態でも攻撃が成立した衝撃の事例から、AI時代のセキュリティ対応の新しい常識を解説します。</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>AIセキュリティ</category><category>RCE</category><category>脆弱性管理</category><category>ゼロデイ</category></item><item><title>国家ぐるみの暗号資産強盗 ─ 北朝鮮Lazarusが仕掛けたBitrefill侵害と累計6,750億円盗難の全貌</title><link>https://cyber-security-lens.com/news/lazarus-crypto-theft-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/lazarus-crypto-theft-2026/</guid><description>北朝鮮のハッカー集団Lazarusが2026年3月にBitrefillを侵害し、18,500件の購入記録と暗号資産を奪いました。2025年だけで2,020億円を盗んだ彼らの最新手口と、個人・企業が今すぐできる防衛策を解説します。</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate><category>北朝鮮</category><category>Lazarus</category><category>暗号資産</category><category>国家ハッカー</category><category>インサイダー脅威</category></item><item><title>Oracleクラウドの沈黙 ─ 600万件のSSO認証情報が闇市場に出回った「否定された侵害」</title><link>https://cyber-security-lens.com/news/oracle-cloud-sso-breach-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/oracle-cloud-sso-breach-2026/</guid><description>2026年3月、Oracle Cloudのシングルサインオン基盤から約600万件の認証情報が流出したとされる事件が発覚。Oracleは侵害を否定し続けたが、複数の企業が漏洩データの真正性を確認。クラウドセキュリティの盲点と今すぐできる対策を解説します。</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>クラウドセキュリティ</category><category>認証情報漏洩</category><category>SSO</category><category>CVE</category></item><item><title>AIツールが標的になる時代：LiteLLM汚染事件が示したCI/CDパイプラインの死角</title><link>https://cyber-security-lens.com/news/ai-supply-chain-litellm-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ai-supply-chain-litellm-2026/</guid><description>2026年3月、AI開発で広く使われるPythonライブラリ「LiteLLM」のPyPI配布版に悪意あるコードが混入しました。確認済みの事実、影響確認、CI/CDとAPIキーの守り方を整理します。</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>PyPI</category><category>LiteLLM</category><category>CI/CD</category><category>Kubernetes</category><category>credential-theft</category><category>AI-security</category></item><item><title>クレデンシャルの連鎖が1ペタバイトを失わせた：TELUS Digital侵害の解剖</title><link>https://cyber-security-lens.com/news/telus-digital-shinyhunters-breach/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/telus-digital-shinyhunters-breach/</guid><description>2026年3月、ShinyHuntersがTELUS Digitalから最大1ペタバイトのデータを盗み、6500万ドルで脅迫しました。入口はまったく別の企業の侵害で得た1つの認証情報。「クレデンシャルチェーン」の恐怖を解説します。</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>ShinyHunters</category><category>credential-theft</category><category>cloud-security</category><category>GCP</category><category>third-party-risk</category></item><item><title>多要素認証を破る『工場』が壊滅：Tycoon 2FA摘滅作戦の全貌</title><link>https://cyber-security-lens.com/news/tycoon-2fa-takedown-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/tycoon-2fa-takedown-2026/</guid><description>2026年3月、Microsoft・Europol・Cloudflareらの国際連携が、MFAを突き破るフィッシングサービス「Tycoon 2FA」の基盤を壊滅させました。64,000件以上の攻撃を可能にしたインフラとその崩壊の全貌を解説します。</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>phishing</category><category>MFA-bypass</category><category>Tycoon-2FA</category><category>AiTM</category><category>Microsoft</category><category>Europol</category><category>takedown</category></item><item><title>CVSS 10.0の緊急脆弱性：攻撃者が真っ先に狙う理由と組織の防御戦略</title><link>https://cyber-security-lens.com/news/cvss-critical-vulnerability-management/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/cvss-critical-vulnerability-management/</guid><description>2026年3月、Quest KACE SMAにCVSS満点（10.0）の脆弱性が発見されました。スコア10.0とは何を意味するのか、なぜ即座にパッチ適用が必要なのかを詳しく解説します。</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate><category>vulnerability</category><category>CVSS</category><category>patch-management</category><category>CVE</category><category>zero-day</category><category>Quest-KACE</category></item><item><title>英国小売業を震撼させたランサムウェア連合：DragonForceとScattered Spider</title><link>https://cyber-security-lens.com/news/dragonforce-scattered-spider-retail-attacks/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/dragonforce-scattered-spider-retail-attacks/</guid><description>M&amp;S、Co-op、Harrods を立て続けに攻撃した DragonForce と Scattered Spider。なぜ彼らは成功したのか？「犯罪カルテル化」が意味するものを解説します。</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>DragonForce</category><category>Scattered-Spider</category><category>social-engineering</category><category>UK</category><category>retail</category></item><item><title>AIが変えたフィッシング詐欺の脅威：2026年の実態と持続可能な自衛策</title><link>https://cyber-security-lens.com/news/ai-phishing-2026/</link><guid isPermaLink="true">https://cyber-security-lens.com/news/ai-phishing-2026/</guid><description>AI生成文、AiTM、マルチチャネル化でフィッシング対策は「怪しいメールを見分ける」だけでは足りなくなった。公式情報をもとに、2026年に優先すべき防御策を整理します。</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>phishing</category><category>AI</category><category>social-engineering</category><category>threat-intel</category><category>2026</category></item></channel></rss>