記事本文へスキップ

運用・セキュリティの記事

運用・セキュリティ / 最新表示設定
運用・安全性hackernews

AIは事件を処理し、エンジニアはシステムとの接触を失う

スコア=368 コメント=327

導入事例microsoft

How to secure edge AI in customer-owned environments

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge A…

運用・安全性thehackernews.com

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them t…

運用・安全性thehackernews.com

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2…

運用・安全性thehackernews.com

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selecte…

運用・安全性Openai

OpenAI Starts Rolling Out Astra, a Flagship AI Model Highly Skilled at Exploiting Security Flaws

Access is currently restricted to trusted partners and members of OpenAI's own Daybreak cybersecurity coalition.

運用・安全性csoonline.com

FBI investigates breach of 153 million driving license records at IDscan.net

Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth…

運用・安全性csoonline.com

Bidding war for defunct Spirit Airlines’ employee data will not die

The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chat…

運用・安全性cisa.gov

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vu…

運用・安全性Openai

OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold

OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers ad…

運用・安全性j-net21.smrj.go.jp

【横須賀市】補助金・助成金:「障害者総合支援事業費補助金(障害福祉分野の介護テクノロジー導入支援事業)〜令和9年度予算にかかる事前調査」

【横須賀市】(神奈川県)本事業は、国の「障害福祉分野におけるロボット等導入支援事業」に採択されたものに対して、障害福祉の現場におけるロボット技術の活用により、介護負担軽減、労働環境の改善、生産性の向上等を通じて安全・安心な障害福祉サービスの提供を推進するため、障害者支援施設等がロボット等の導入をするための費用の一部について、市の予算の範囲内で補助を行うものです。 <令和9年度予算にかかる事前調査> 令和9年度に介護ロボット等の導入を予…

運用・安全性csoonline.com

The democratization of cyber warfare — and what it means for CISOs

For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In th…

運用・安全性AWS

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) -…

運用・安全性AWS

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0.…

運用・安全性Google

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8),…

運用・安全性Openai

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had re…

論文・研究Openai

OpenAI ボットがサイバーセキュリティのテストから逃れた時、本当に何が起こったのか?

何百人ものOpenAIエージェントがテスト環境から抜け出し、AIプラットフォーム「Hugging Face」に侵入したとき、ヘッジ・クラフ氏はこれが間違った話であり、失敗だと警告した。

運用・安全性Openai

Nobody Is Saying Why OpenAI and Anthropic Had Outages Today

ChatGPT, Claude, and Grok all suffered outages at nearly the exact same time for reasons that remain murky.

運用・安全性Openai

OpenAI targets small utilities with $1 billion cyber defense initiative

In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders,…

運用・安全性cloudflare

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediatio…

運用・安全性thehackernews.com

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attac…

運用・安全性microsoft

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to ph…

運用・安全性thehackernews.com

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardeni…

運用・安全性securityweek.com

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Lea…

次の記事を読む