Sign in

piyokango

@piyokango.bsky.social
1.3K followers 2 following 1.7K posts

セキュリティインコです🐣 Blueskyでは海外のセキュリティ関連記事を中心につぶやきます。気の向くままブログ(piyolog)も書いてます📝Podcast #セキュリティのアレ も参加中です🎤よろしくお願いします~🐦 プロフィール画像はアレティさんに描いて頂きました😃

PostsRepliesMedia
piyokango @piyokango.bsky.social · 14/07/2026
13カ国がロシアのサイバー攻撃に警告 #CybersecurityNews cyberscoop.com/russian-fsb-...
cyberscoop.com
Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care.
021
piyokango @piyokango.bsky.social · 14/07/2026
サイバーセキュリティおよびインフラセキュリティ庁(CISA)の最近のデータ漏洩について #CybersecurityNews krebsonsecurity.com/2026/07/less...
krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys --...
010
piyokango @piyokango.bsky.social · 14/07/2026
EU、英国がロシアのサイバー諜報ネットワークに制裁を科す #CybersecurityNews cyberscoop.com/eu-uk-russia...
cyberscoop.com
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’
The EU and UK have imposed coordinated sanctions targeting Russian cyberespionage networks, including the FSB and GRU, following destructive infrastructure attacks.
021
piyokango @piyokango.bsky.social · 14/07/2026
ランサムウェアグループに好まれるVPNサービスが米国に制裁される #CybersecurityNews therecord.media/first-vpn-ad...
therecord.media
VPN service favored by ransomware groups is sanctioned by US
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware...
020
piyokango @piyokango.bsky.social · 14/07/2026
ハッカーがJscrambler npmパッケージに情報窃取マルウェアを仕込む #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times.
010
piyokango @piyokango.bsky.social · 13/07/2026
CISAの資格情報漏洩が厳格なセキュリティ対策を促進 #CybersecurityNews cyberscoop.com/cisa-credent...
cyberscoop.com
CISA looks to remedy ailments from big May credential leak
Following a major AWS GovCloud credential leak on GitHub, CISA released a forensic report detailing updated security plays and improvements to vulnerability reporting.
010
piyokango @piyokango.bsky.social · 13/07/2026
アルメニア国籍者がRyukランサムウェア攻撃に有罪を認める #CybersecurityNews cyberscoop.com/karen-vardan...
cyberscoop.com
Armenian national pleads guilty to Ryuk ransomware attacks
Karen Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution.
010
piyokango @piyokango.bsky.social · 13/07/2026
AIが15年間見逃されていたLinuxの根本的なバグを発見 #CybersecurityNews www.wired.com/story/securi...
wired.com
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
Plus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more.
030
piyokango @piyokango.bsky.social · 13/07/2026
OperaがClickFix攻撃対策のためのPaste Protect機能を導入 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Opera rolls out Paste Protect feature to fight ClickFix attacks
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.
010
piyokango @piyokango.bsky.social · 13/07/2026
ClickFix詐欺がGoogleとCloudflareのチェックを悪用し、7つのマルウェアファミリーを配信 #CybersecurityNews hackread.com/clickfix-sca...
hackread.com
ClickFix Scams Abuse Google, Cloudflare Checks to Deliver 7 Malware Families
Malwarebytes links fake Google and Cloudflare verification pages to shared ClickFix infrastructure delivering StealC, NetSupport and other malware.
010
piyokango @piyokango.bsky.social · 13/07/2026
「初」のAIによるランサムウェア攻撃には人間が必要だった #CybersecurityNews techcrunch.com/2026/07/06/t...
techcrunch.com
The 'first' AI-run ransomware attack still needed a human | TechCrunch
An AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied...
010
piyokango @piyokango.bsky.social · 13/07/2026
UAT-7810が新しいマルウェアを使用してORBネットワークを構築し続ける #CybersecurityNews blog.talosintelligence.com/uat-7810/
blog.talosintelligence.com
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
010
piyokango @piyokango.bsky.social · 13/07/2026
サイバーセキュリティスタートアップの創業者に対する懸念 #CybersecurityNews krebsonsecurity.com/2026/07/felo...
krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most...
010
piyokango @piyokango.bsky.social · 13/07/2026
中国関連APTが新たなマルウェアでプロキシネットワークを拡大 #CybersecurityNews www.infosecurity-magazine.com/news/uat-781...
infosecurity-magazine.com
China-Linked APT Expands Proxy Network With New Malware
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware
010
piyokango @piyokango.bsky.social · 13/07/2026
ハッカーがRoundcubeの脆弱性を悪用し、学術研究者を監視 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware.
010
piyokango @piyokango.bsky.social · 13/07/2026
インターポールのサイバー犯罪取り締まりで97カ国で5,800人逮捕 #CybersecurityNews cyberscoop.com/interpol-cyb...
cyberscoop.com
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams.
010
piyokango @piyokango.bsky.social · 13/07/2026
元ランサムウェア交渉者がBlackCat攻撃で4年の懲役 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Former ransomware negotiator gets 4 years for BlackCat attacks
A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks.
010
piyokango @piyokango.bsky.social · 13/07/2026
ランサムウェアは止まらない:2018年以降9,000件以上の確認された攻撃 #CybersecurityNews securityaffairs.com/195117/cyber...
securityaffairs.com
Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018 - Security Affairs
Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target.
010
piyokango @piyokango.bsky.social · 13/07/2026
中国とインドが同じパキスタン警察に対して別々のスパイ活動を展開 #CybersecurityNews therecord.media/china-india-...
therecord.media
China, India ran separate spying campaigns against same Pakistani police force
The activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the s...
010
piyokango @piyokango.bsky.social · 13/07/2026
新しい‘GigaWiper’マルウェアが諜報活動と破壊機能を統合 #CybersecurityNews www.infosecurity-magazine.com/news/new-gig...
infosecurity-magazine.com
New ‘GigaWiper’ Malware Combines Espionage & Destructive Capabilities
A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations
010
piyokango @piyokango.bsky.social · 13/07/2026
ハッカーがGitea Dockerイメージの重大な認証バイパスを悪用 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers exploit critical auth bypass in Gitea Docker image
Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators.
020
piyokango @piyokango.bsky.social · 30/06/2026
XSSフォーラムの崩壊:DaMaGeLaBから2025年の摘発まで #CybersecurityNews ransomnews.com/xss-forum-da...
ransomnews.com
XSS forum: from DaMaGeLaB to the 2025 takedown
Inside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable countr...
010
piyokango @piyokango.bsky.social · 30/06/2026
DHSが重要インフラサイバーセキュリティのための新しい評議会を発表予定 #CybersecurityNews cyberscoop.com/dhs-anchor-c...
cyberscoop.com
DHS to unveil replacement council for critical infrastructure cybersecurity
DHS is launching ANCHOR-CI, a new CISA-managed program to revive critical infrastructure cybersecurity information sharing after a year-long gap.
010
piyokango @piyokango.bsky.social · 30/06/2026
数十年前のBashトリックがAIコーディングエージェントをサプライチェーン攻撃にさらす #CybersecurityNews www.securityweek.com/decades-old-...
securityweek.com
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, creating a new software supply chain risk.
010
piyokango @piyokango.bsky.social · 30/06/2026
BlueHammer脆弱性がランサムウェア攻撃に悪用される #CybersecurityNews www.securityweek.com/bluehammer-v...
securityweek.com
BlueHammer Vulnerability Exploited in Ransomware Attacks
A Microsoft Defender vulnerability tracked as BlueHammer and CVE-2026-33825 is being exploited in ransomware attacks
010
piyokango @piyokango.bsky.social · 30/06/2026
ClickFixがサイバー犯罪者のお気に入りのマルウェア配信手法に #CybersecurityNews www.infosecurity-magazine.com/news/clickfi...
infosecurity-magazine.com
ClickFix Now Cybercriminals' Favorite Malware Delivery Technique
ReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS users
010
piyokango @piyokango.bsky.social · 30/06/2026
日産の従業員データがOracle PeopleSoftのハッキングで漏洩 #CybersecurityNews www.hendryadrian.com/nissan-emplo...
hendryadrian.com
Nissan Employee Data Breached in Oracle PeopleSoft Hack
Nissan has confirmed a data breach tied to a zero-day campaign against Oracle PeopleSoft customers, with attackers suspected of stealing employee records across the US, Canada, Mexico, and Brazil. The...
020
piyokango @piyokango.bsky.social · 30/06/2026
Blackfield ランサムウェアが日本のニデックに200万ドルの身代金を要求 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Blackfield ransomware asks Nidec Corporation for $2 million ransom
The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications.
010
piyokango @piyokango.bsky.social · 30/06/2026
英国の医療分野、サイバー攻撃が十倍増加 #CybersecurityNews www.infosecurity-magazine.com/news/uk-heal...
infosecurity-magazine.com
UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks
SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege
020
piyokango @piyokango.bsky.social · 30/06/2026
1年間で300以上の英国企業がランサムウェアの被害に遭う #CybersecurityNews www.infosecurity-magazine.com/news/over-30...
infosecurity-magazine.com
Over 300 UK Firms Hit by Ransomware in a Year
Report Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEs
010
piyokango @piyokango.bsky.social · 30/06/2026
TONResolver RATがTONブロックチェーンを悪用し、日本のホテル業界を狙う #CybersecurityNews www.trendmicro.com/en_us/resear...
trendmicro.com
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
010
piyokango @piyokango.bsky.social · 30/06/2026
米国、違法なワールドカップストリーミングサイト約400件を摘発 #CybersecurityNews therecord.media/us-takes-dow...
therecord.media
US racks up about 400 wins over illegal World Cup streaming sites
The World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S., along with the help of U.S. broadcaster NBC Universal and other entities.
021
piyokango @piyokango.bsky.social · 29/06/2026
テキサスGOPサイバー攻撃に関与したアノニマス関連のハッカー、オーブリー・コトルが投獄される #CybersecurityNews hackread.com/anonymous-ha...
hackread.com
Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack
Canadian hacktivist Aubrey Cottle, known as Kirtaner and once linked to Anonymous, gets 18 months for a 2021 Texas GOP website cyberattack.
010
piyokango @piyokango.bsky.social · 29/06/2026
Claude Mythos 5の復活:米国政府がAI禁止令を解除 #CybersecurityNews securityonline.info/claude-mytho...
securityonline.info
031
piyokango @piyokango.bsky.social · 29/06/2026
Linuxに新たなローカル特権昇格脆弱性「pedit COW」が発見される #CybersecurityNews www.ithome.com.tw/news/176912
ithome.com.tw
Linux存在新的本機權限提升漏洞pedit COW,搭配5.18版至 7.1-rc6版核心的系統均可能受影響
Threat Landscape揭露新的Linux本機權限提升漏洞CVE-2026-46331,稱為pedit COW,影響的Linux發行版本涵蓋Red Hat Enterprise Linux的8至10版,以及搭配5.18版至7.1-rc6版Linux核心的Ubuntu與Debian
011
piyokango @piyokango.bsky.social · 27/06/2026
ロシアが人権問題を理由にCellebriteを切り離した後も電話ハッキングツールを使用 #CybersecurityNews therecord.media/russia-used-...
therecord.media
Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country
The continued use of the powerful data extraction product soon after the company in March 2021 said it would stop working with Russia suggests the firm has been unable to pull back its technology from...
010
piyokango @piyokango.bsky.social · 27/06/2026
Windows脅威によるCOM使用の紹介 #CybersecurityNews blog.talosintelligence.com/introduction...
blog.talosintelligence.com
Introduction to COM usage by Windows threats
Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse...
010
piyokango @piyokango.bsky.social · 27/06/2026
イギリス警察が広範な犯罪予測システムを構築、一部の結果は信頼できない可能性がある #CybersecurityNews www.wired.com/story/britis...
wired.com
British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted
As UK police embrace the AI revolution, a WIRED investigation reveals the messy inside story of one region’s experiment with predictive analytics.
011
piyokango @piyokango.bsky.social · 27/06/2026
パッチ指令が限界に達する理由 #CybersecurityNews cyberscoop.com/why-security...
cyberscoop.com
Why patch directives only go so far
CISA's emergency directive for CVE-2026-50751 highlights a critical reality: security patching is not enough to evict ransomware actors already inside your network.
010
piyokango @piyokango.bsky.social · 27/06/2026
パスキーを提供しない企業を名指しする新しいウェブサイト #CybersecurityNews techcrunch.com/2026/06/24/n...
techcrunch.com
New website names and shames companies that still don't offer passkeys to users | TechCrunch
According to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log in to apps and services.
020
piyokango @piyokango.bsky.social · 27/06/2026
悪意のあるEdge拡張機能がネイティブメッセージングを悪用しマルウェアに繋がる #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Malicious Edge extension abuses Native Messaging as bridge to malware
A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor.
021
piyokango @piyokango.bsky.social · 27/06/2026
オペレーション・エンドゲームがStealC、Amadey、SocGholishマルウェアネットワークを撲滅 #CybersecurityNews hackread.com/operation-en...
hackread.com
Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
Operation Endgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
011
piyokango @piyokango.bsky.social · 27/06/2026
Cisco Catalyst SD-WAN Managerにおける脆弱性(CVE-2026-20245)のゼロデイ攻撃 #CybersecurityNews cloud.google.com/blog/topics/...
cloud.google.com
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager | Google Cloud Blog
The threat actor exploited the vulnerability to escalate privileges from a compromised administrative account to root-level access.
011
piyokango @piyokango.bsky.social · 27/06/2026
マディソン・スクエア・ガーデンへのハッカー侵入の経緯 #CybersecurityNews www.404media.co/how-hackers-...
404media.co
How Hackers Broke into Madison Square Garden
Hackers stole more than 45GB of data from Madison Square Garden, including data related to “talent” and the Knicks. Clues in the data point to how the hackers got in.
010
piyokango @piyokango.bsky.social · 27/06/2026
OpenClawのスキルマーケットプレイスと新たなAIサプライチェーンの脅威 #CybersecurityNews unit42.paloaltonetworks.com/openclaw-ai-...
unit42.paloaltonetworks.com
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat
Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.
010
piyokango @piyokango.bsky.social · 27/06/2026
新しいmacOS ClickFix攻撃がDMGを静かにマウントし情報窃盗を推進 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
New macOS ClickFix attack silently mounts DMGs to push infostealer
A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files.
021
piyokango @piyokango.bsky.social · 27/06/2026
LastPassがKlueサプライチェーン攻撃によるデータ侵害を確認 #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.
020
piyokango @piyokango.bsky.social · 27/06/2026
WhatsAppフィッシング攻撃が偽のビジネス文書を使用してPCをハッキング #CybersecurityNews www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
WhatsApp phishing attack uses fake business docs to hack PCs
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access.
010
piyokango @piyokango.bsky.social · 27/06/2026
Klueの侵害によりハッカーがサイバーセキュリティ企業を侵害 #CybersecurityNews www.infosecurity-magazine.com/news/klue-br...
infosecurity-magazine.com
Klue Breach Enables Hackers to Compromise Cybersecurity Firms
At least four cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integration
020
piyokango @piyokango.bsky.social · 27/06/2026
ワールドカップ詐欺が見抜きにくくなっている #CybersecurityNews www.wired.com/story/world-...
wired.com
World Cup Scams Are Getting Harder to Spot
From fake tickets to cloned websites, AI is magnifying World Cup scams. Can fans distinguish between what’s real and what’s not?
010