🛡️ Weekly Security Threat Report
çŸåšæ¥ä»: 2026/05/03
èŠæã¬ãã«: High
Section 1: è åšã»è匱æ§äžèЧ & ãã¬ã³ã
1. ãã¥ãŒã¹ããŒãã«
ææ°ã®è åšã€ã³ããªãžã§ã³ã¹ããã³åã»ãã¥ãªãã£æ©é¢ããã®å ±åã«åºã¥ããçŸåšæãèŠæãã¹ãè匱æ§ãšãµã€ããŒã€ã³ã·ãã³ãã®ç¶æ³ã¯ä»¥äžã®éãã§ããã
| Category | Topic (è匱æ§/äºä»¶å) | Severity | Status | URL |
| OS / Kernel | Linux: CVE-2026-31431 (Copy Fail æš©éææ Œ) | Critical (CVSS 7.8) | æªçšç¢ºèªæž / ããããã | (https://www.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds) |
| Web Infrastructure | cPanel & WHM: CVE-2026-41940 (èªèšŒãã€ãã¹) | Critical (CVSS 9.8) | æªçšç¢ºèªæž / ããããã | (https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/) |
| Network / Firewall | Cisco: FIRESTARTER ãã«ãŠã§ã¢ (APTã«ãã䟵害) | Critical | æªçšç¢ºèªæž / åé¿çã»ããããã | (https://www.cisa.gov/news-events/analysis-reports/ar26-113a) |
| OS / Client | Windows: CVE-2026-32202 (Windows Shell ã¹ããŒãã£ã³ã°) | High (CVSS 4.3) | æªçšç¢ºèªæž(ãŒããã€) / ããããã | (https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html) |
| AI Infrastructure | LiteLLM: CVE-2026-42208 (äºåèªèšŒã®SQLã€ã³ãžã§ã¯ã·ã§ã³) | Critical | æªçšç¢ºèªæž / ããããã | (https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-a-critical-litellm-pre-auth-sqli-flaw/) |
| OS / Updates | Windows 11: KB5083769 (ãµãŒãããŒãã£è£œããã¯ã¢ããé害) | Low | æªçšãªã / åé¿çãã | (https://www.bleepingcomputer.com/news/microsoft/april-kb5083769-windows-11-update-causes-backup-software-failures/) |
| Phishing / AI | Bluekit (AIãçµ±åããæ°åãã£ãã·ã³ã°ããã) | Medium | æªçšç¢ºèªæž / 察çå®è£ äž | (https://www.bleepingcomputer.com/news/security/new-bluekit-phishing-service-includes-an-ai-assistant-40-templates/) |
2. 詳现èŠçŽ
2026幎4ææ«ãã5æç¬¬1é±ã«ãããŠã®ãµã€ããŒã»ãã¥ãªãã£æ å¢ã¯ããã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãããæªç¥ã®è«ççæ¬ é¥ã®é²åããšãæ»æãµã€ã¯ã«ã®AIã«ããåçãªççž®ããšããäºã€ã®é倧ãªãã¬ã³ãã«ãã£ãŠç¹åŸŽã¥ãããããä»é±ã®æå€§ã®ãã€ã©ã€ãã¯ã2017幎ããLinuxã«ãŒãã«ã«ååšããŠããèŽåœçãªæš©éææ Œè匱æ§ïŒCVE-2026-31431 “Copy Fail”ïŒããAIé§åã®ãããã¬ãŒã·ã§ã³ãã¹ãåºç€ã«ãã£ãŠããã1æéã®ã¹ãã£ã³ã§çºèŠã»å µåšåãããäºè±¡ã§ãããããã«å ããäžçäžã§150äžå°ä»¥äžã皌åããWebãã¹ãã£ã³ã°ç®¡çã·ã¹ãã ãcPanel & WHMãã®èªèšŒãã€ãã¹ïŒCVE-2026-41940ïŒããŒããã€ãšããŠæªçšãããCisco補ãã¡ã€ã¢ãŠã©ãŒã«ãæšçãšãããFIRESTARTERããã«ãŠã§ã¢ãé«åºŠãªã€ã³ã¡ã¢ãªã»ãããã³ã°ãšåèµ·åãè·šãæ°žç¶åã¡ã«ããºã ãåããŠããããšã倿ããããããã®äºè±¡ã¯ããããå ¬éããæªçšãŸã§ã®ã¿ã€ã ã©ã°ãäºå®äžæ¶æ» ããŠããããšã瀺ããŠãããé²åŸ¡åŽã«ã¯ããŒããã©ã¹ãã®å³æ Œåããšãã¡ã¢ãªã¬ãã«ã®æ·±ããã©ã¬ã³ãžãã¯èœåãããããŸã§ä»¥äžã«åŒ·ãèŠæ±ãããŠããã
Section 2: Deep Dive into Critical Threats (éèŠè åšã®æ·±æã)
ãµã€ããŒé²åŸ¡ã®æåç·ã«ãããŠãä»é±ç¹ã«å®åãžã®åœ±é¿ã倧ããã峿ãã€ç¢ºå®ãªå¯Ÿå¿ãæ±ãããã3ã€ã®ã¯ãªãã£ã«ã«ãªè åšã«ã€ããŠæè¡çæ·±æããè¡ããã·ã¹ãã ã€ã³ãã©ã®æ ¹å¹¹ãæºããããããã®è匱æ§ã¯ã衚é¢çãªãããé©çšã®ã¿ã§ã¯å®å šã«ãªã¹ã¯ãæé€ã§ããªãã±ãŒã¹ãå«ãŸããŠããããã®æ ¹æ¬çãªã¡ã«ããºã ã®çè§£ãäžå¯æ¬ ã§ããã
🚨 Alert 1: (Linuxã«ãŒãã«ã«å åšãã9幎è¶ãã®è«ççæ¬ é¥ / CVE-2026-31431)
- æŠèŠ (3è¡ãŸãšã):2017幎ã®Linuxã«ãŒãã«ãžã®ã³ãããã§æ··å
¥ããæå·åãµãã·ã¹ãã ã®è«ççæ¬ é¥ãçªããããŒã«ã«æš©éææ ŒïŒLPEïŒè匱æ§ã§ãããæš©éã®ãªãããŒã«ã«ãŠãŒã¶ãŒãç«¶åç¶æ
ãå¿
èŠãšããã«ãå®å
šã«ç¢ºå®ãªææ³ã§
setuidãã€ããªã®ããŒãžãã£ãã·ã¥ãæ±æããç¬æã«ã«ãŒãæš©éã奪åããããšãå¯èœãšãªã£ãŠãããAIã·ã¹ãã ã«ãã£ãŠçºèŠããããã®è匱æ§ã¯ãäž»èŠãªLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã»ãŒãã¹ãŠã«åœ±é¿ãåãŒãã - æè¡ç詳现:ãã®è匱æ§ã¯éç§°ãCopy FailããšåŒã°ããCVSSã¹ã³ã¢7.8ïŒHighïŒãšè©äŸ¡ãããŠãããã®ã®ããã®å®è³ªçãªåœ±é¿åºŠã¯æ¥µããŠç Žå£çã§ãã ã圱é¿ãåããã®ã¯ã2017幎ã®ããŒãžã§ã³4.14以éãããä¿®æ£çïŒ7.0, 6.19.12, 6.18.22ãªã©ïŒãé©çšãããåãŸã§ã®äºå®äžãã¹ãŠã®äž»èŠãªLinuxã«ãŒãã«ã§ãããUbuntu 24.04 LTSãAmazon Linux 2023ãRHEL 10.1ãSUSE 16ãªã©ãã¯ã©ãŠãç°å¢ã§åºãå©çšãããŠãããã£ã¹ããªãã¥ãŒã·ã§ã³ã該åœãã ãæ»æã®æ ¹æ¬åå ïŒRoot CauseïŒã¯ããŠãŒã¶ãŒç©ºéã«å
¬éãããŠããæå·åã€ã³ã¿ãŒãã§ãŒã¹ã§ãã
algif_aeadã¢ãžã¥ãŒã«ã«ãããã2017幎ã®ãã€ã³ãã¬ãŒã¹åŠçïŒin-place processingïŒãæé©åã«äŒŽãè«çãšã©ãŒã«èµ·å ãã ãã«ãŒãã«éçºè ã¯ããã©ãŒãã³ã¹åäžã®ãããAEADïŒAuthenticated Encryption with Associated DataïŒæäœãã€ã³ãã¬ãŒã¹ã§åŠçãããã倿Žãããªã¯ãšã¹ãã®éä¿¡å ãšå®å ãåäžã®ã¡ã¢ãªã¢ãã¬ã¹ã«èšå®ïŒreq->src = req->dstïŒããæé©åïŒcommit 72548b093ee3ïŒãå°å ¥ãã ããã®ããã»ã¹ã«ãããŠãã«ãŒãã«ã¯sg_chain()颿°ãçšããŠãœãŒã¹ã®ã¹ãã£ãã¿ãŒãªã¹ãïŒäžé£ç¶ãªã¡ã¢ãªé åãæãç€ºãæ§é äœïŒããåºåã¹ãã£ãã¿ãŒãªã¹ããžã¿ã°ããŒãžããã§ãŒã³ããåŠçãè¡ã ãè匱æ§ã®çºç«ã¡ã«ããºã ã¯ããŠãŒã¶ãŒç©ºéã®ããã»ã¹ãsplice()ã·ã¹ãã ã³ãŒã«ãå©çšããŠããŒã¿ãæå·åãœã±ããã«éã蟌ãéã«çºçãã ãæ»æè ãã¿ãŒã²ãããšãªãç¹æš©ãã€ããªïŒäŸ:/usr/bin/suïŒã®ããŒãžãã£ãã·ã¥ïŒãã£ã¹ã¯äžã®ãã¡ã€ã«ããŒã¿ãã¡ã¢ãªäžã«ãã£ãã·ã¥ããé åïŒããã®ãã€ãã©ã€ã³ã«éã蟌ãã å Žåãåè¿°ã®ã¹ãã£ãã¿ãŒãªã¹ãã®ãã§ãŒã³åŠçã«æ¬ é¥ããããããåºååŽã®ã¹ãã£ãã¿ãŒãªã¹ããæå³ããããŒãžãã£ãã·ã¥ã®é åãŸã§æ¡åŒµãããŠããŸã ãããã§authencesn(hmac(sha256),cbc(aes))ã¢ã«ãŽãªãºã ãå®è¡ããããšãExtended Sequence NumberïŒESNïŒã®åé 眮ãè¡ãããã®ã¹ã¯ã©ããé åïŒäžæçãªæžã蟌ã¿ã¹ããŒã¹ïŒãšããŠ4ãã€ãã®ããŒã¿ãæžã蟌ãŸãã ãããããåºåã¹ãã£ãã¿ãŒãªã¹ããã¿ãŒã²ãããã¡ã€ã«ã®ããŒãžãã£ãã·ã¥ã«èª€ã£ãŠãããã³ã°ãããŠããããããã®4ãã€ãã®ããŒã¿ã¯ãã¡ã€ã«ã·ã¹ãã ã®å³æ Œãªã¢ã¯ã»ã¹æš©éãã§ãã¯ãå®å šã«ãã€ãã¹ããã¡ã¢ãªäžã®/usr/bin/suã®ãã£ãã·ã¥ããŒã¿å ã«çŽæ¥äžæžããããŠããŸã ããã®äžé£ã®ããã»ã¹ã«ãããæ»æè ã¯ä»¥äžã®3ã€ã®ããªããã£ãïŒåºæ¬æäœïŒãçµã¿åãããããšã§æš©éææ Œãéæãã ã
| Exploitation Primitive | ã¡ã«ããºã ã®è§£èª¬ |
| 1. Binding (ãã€ã³ãã£ã³ã°) | AF_ALGãœã±ãããäœæããauthencesn(hmac(sha256),cbc(aes))æå·åã¢ã«ãŽãªãºã ã«ãã€ã³ãããã |
| 2. Splicing (ã¹ãã©ã€ã·ã³ã°) | splice()ãåŒã³åºããã¿ãŒã²ãããšãªãç¹æš©ãã€ããªã®ããŒãžãã£ãã·ã¥ãæå·åãã€ãã©ã€ã³ã«æµã蟌ãã |
| 3. Corruption (ã¡ã¢ãªæ±æ) | recvmsg()ãçºè¡ããAdditional Authenticated Data (AAD)ã®ç¹å®ã®ãã€ããªãã»ããã«æ»æè
ãå¶åŸ¡ãã4ãã€ãã®ãã€ããŒããé
眮ãããã«ãŒãã«ã®ã¹ã¯ã©ããæžãèŸŒã¿æ©èœãããããã£ãã·ã¥å
ã®ã¿ãŒã²ããããŒãžã«è»¢åããã |
ãã®ææ³ã®æãæãããç¹ã¯ãéå»ã®é¡äŒŒè匱æ§ïŒDirty PipeçïŒã«èŠããããããªã¿ã€ãã³ã°ã«äŸåããç«¶åç¶æ ïŒRace ConditionïŒãäžåå¿ èŠãšããªãããšã§ãã ãæ»æè ã¯ãã®æäœãé£ç¶ããŠå®è¡ããããšã§ãã¡ã¢ãªäžã®ç¹æš©ãã€ããªå ã«ä»»æã®ã·ã§ã«ã³ãŒããæ¥µããŠé«ãä¿¡é Œæ§ã§é 眮ããããšãã§ãããã®åŸæ¹ããããããã€ããªãå®è¡ããã ãã§å³åº§ã«ã«ãŒãæš©éã®ã·ã§ã«ãç²åŸã§ãã ãäºå®ãTheoriç€Ÿã®æ»æåºç€ã«ãã£ãŠçæãããããã732ãã€ãã®Pythonã¹ã¯ãªããã¯ãããããã¡ãžã£ãŒãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ãããŠ100%ã®æåçã§ã«ãŒãæš©éã奪åããããšã蚌æãããŠãã ã
- æšå¥šããã察ç (Mitigation):æ¬è匱æ§ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœã«ç倧ãªåœ±é¿ãåãŒãããã以äžã®æ®µéçãªç·©åçãšæä¹
察å¿ãçŽã¡ã«å®æœããå¿
èŠãããã1. ã«ãŒãã«ã®å³æã¢ããããŒãïŒæåªå
äºé
ïŒ ãã³ããŒããæäŸãããŠããä¿®æ£æžã¿ã«ãŒãã«ïŒããŒãžã§ã³ 7.0, 6.19.12, 6.18.22ããŸãã¯åãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ããã¯ããŒãçïŒãžå³åº§ã«ã¢ããããŒãããã·ã¹ãã ãåèµ·åãã ãAlmaLinuxãªã©ã®ç°å¢ã§ã¯æ¢ã«ãããã¯ã·ã§ã³ãªããžããªãžã®å±éãå®äºããŠãã ã2. AF_ALGãœã±ããäœæã®å¶éïŒåèµ·åãå°é£ãªå Žåã®åé¿çïŒ çšŒåäžã®KubernetesããŒããCI/CDã©ã³ããŒãªã©ã峿ã®ããŒãåèµ·åã«ããæ¥å圱é¿ã蚱容ã§ããªãç°å¢ã«ãããŠã¯ãã³ã³ããã©ã³ã¿ã€ã ã®ããã©ã«ãèšå®ãSeccompãããã¡ã€ã«ãå©çšããŠããŠãŒã¶ãŒç©ºéããã®
AF_ALGãœã±ããã®äœæã峿 Œã«ãããã¯ããæªçœ®ãè¬ãã ãäžè¬çãªWebã¢ããªã±ãŒã·ã§ã³ãããŒã¿ããŒã¹ã®ã¯ãŒã¯ããŒããã«ãŒãã«ç©ºéã®æå·åAPIãçŽæ¥åŒã³åºãããšã¯çšã§ããããããã®åé¿çã«ããå¯äœçšã¯æå°éã«æããããã3. ã©ã³ã¿ã€ã æ€ç¥ã«ãŒã«ã®ããã〠Falcoãªã©ã®ã¯ã©ãŠããã€ãã£ããªã©ã³ã¿ã€ã ã»ãã¥ãªãã£ããŒã«ã掻çšããæ£èŠã®ãã£ã¹ã¯æå·åããŒã«ãã§ãŒã³ïŒcryptsetupãveritysetupçïŒä»¥å€ã®æªç¥ã®ããã»ã¹ããAF_ALG SEQPACKETãœã±ãããäœæãããæ¯ãèããæ€ç¥ã»ãããã¯ããã«ãŒã«ãæ©æ¥ã«ãããã€ãã ãè¥ææè¡è ãééãããããã€ã³ã: ã³ã³ããç°å¢å ã§æš©éææ Œã䟵害ã®ã¢ã©ãŒããæ€ç¥ããå Žåãã³ã³ããã®åèµ·åããããã®åã¹ã±ãžã¥ãŒã«ã ãã§å¯Ÿå¿ãå®äºããŠã¯ãªããªããæ¬è匱æ§ã¯ãã¹ãããŒãåŽã®ã«ãŒãã«ã®ããŒãžãã£ãã·ã¥èªäœãçŽæ¥æ±æããŠãããããåœè©²ãã¹ãäžã§æ°ãã«èµ·åããã³ã³ãããæ±æããããã€ããªãèªã¿èŸŒãå±éºæ§ãé«ã ã䟵害ãçããããã¹ãããŒãã¯å³åº§ã«ã¯ã©ã¹ã¿ããåãé¢ãïŒCordon/DrainïŒãåºç€ã¬ãã«ã§ã®å®å šãªåäœæïŒããŒãã®ãªãµã€ã¯ã«ïŒã宿œããããšã絶察æ¡ä»¶ãšãªã ã - æ å ±æº:(https://www.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds)
🚨 Alert 2: (cPanel & WHM ã«ãããèŽåœçãªèªèšŒãã€ãã¹ / CVE-2026-41940)
- æŠèŠ (3è¡ãŸãšã):äžçäžã§å©çšãããŠããWebãã¹ãã£ã³ã°ã³ã³ãããŒã«ããã«ãcPanel & WHMãã«ãããŠãHTTPãããã®CRLFã€ã³ãžã§ã¯ã·ã§ã³ãéããŠèªèšŒããã»ã¹ãå®å šã«ãã€ãã¹ããã·ã¹ãã ã®ã«ãŒãæš©éã奪åã§ããæ¥µããŠæ·±å»ãªè匱æ§ïŒCVSS 9.8ïŒã§ããããã®æ¬ é¥ã¯2026幎2æé ããæ¢ã«ãŒããã€ãšããŠå®ç°å¢ã§æªçšãããŠãã圢跡ããããã€ã³ã¿ãŒãããäžã«é²åºããŠãã150äžå°ä»¥äžã®ã€ã³ã¹ã¿ã³ã¹ãæœåšçãªè åšã«æãããŠããã
- æè¡ç詳现:æ¬è匱æ§ïŒCVE-2026-41940ïŒã¯ãWebã€ã³ãã©ã¹ãã©ã¯ãã£ã«ããã管çã€ã³ã¿ãŒãã§ãŒã¹ã®å®å
šæ§ãæ ¹æ¬ãã厩å£ããããã®ã§ããã圱é¿ãåããã®ã¯ãcPanel & WHM ã®ããŒãžã§ã³ 11.40 以éã®ãã¹ãŠã®ãµããŒã察象ããŒãžã§ã³ãããã³é¢é£è£œåã§ãã WP Squared ã§ãã ãæ»æã®ã¡ã«ããºã ã¯ãcPanelã®ã³ã¢ãµãŒãã¹ããŒã¢ã³ã§ãã
cpsrvdããŠãŒã¶ãŒã®ãã°ã€ã³èŠæ±ãšã»ãã·ã§ã³ç¶æ ãåŠçã»ä¿åãããããŒã«ãããé倧ãªèšèšäžã®æ¬ é¥ã«åºã¥ããŠãã ãéåžžããŠãŒã¶ãŒããã°ã€ã³ã詊ã¿ããšãã·ã¹ãã ã¯èªèšŒããã»ã¹ãå®äºããåæ®µéãšããŠãäžæçãªæ°ããã»ãã·ã§ã³æ å ±ããã£ã¹ã¯äžã®ãã¡ã€ã«ã«æžãåºãæåã瀺ã ããã®éãã·ã¹ãã ã¯ã»ãã·ã§ã³ãèå¥ã»ä¿è·ããããã«whostmgrsessionãšåŒã°ããCookieå€ãçæã»æ€èšŒããããæ»æè ã¯æå³çã«ãã®Cookieå€ã®ç¹å®ã®ã»ã°ã¡ã³ããçç¥ããäžæ£ãªãªã¯ãšã¹ããéä¿¡ãã ãããã«ãããã·ã¹ãã ãæ³å®ããŠããæå·åã»é£èªåããã»ã¹ããã€ãã¹ãããæ»æè ãæäŸããå€ããã®ãŸãŸå¹³æãšããŠåŠçãããç¶æ ãäœãåºããã ãæå·åããã»ã¹ãç¡å¹åããæ»æè ã¯ã次ã«Base64ãšã³ã³ãŒããããããŒã¿ãæ ŒçŽãããAuthorizationããããïŒBasicèªèšŒãããïŒãã·ã¹ãã ã«éä¿¡ãã ããã®Base64ããŒã¿ããã³ãŒãããããšããã®äžã«ã¯çã®ãã£ãªããžãªã¿ãŒã³ãšã©ã€ã³ãã£ãŒãïŒ\r\nïŒã®æååãå«ãŸããŠãã ãcPanelã®ã»ãã·ã§ã³åŠçæ©æ§ã¯ãã®ãã³ãŒããããããŒã¿ããã£ã¹ã¯äžã®ã»ãã·ã§ã³ãã¡ã€ã«ã«æžã蟌ãéãé©åãªå ¥åãµãã¿ã€ãºïŒç¡å®³åïŒãæ¹è¡ã³ãŒãã®ãšã¹ã±ãŒãåŠçãå®è¡ããªã ãçµæãšããŠãå žåçãªCRLFã€ã³ãžã§ã¯ã·ã§ã³æ»æãæç«ããæ»æè ã¯ã»ãã·ã§ã³ãã¡ã€ã«å ã®ä»»æã®æ°ããè¡ã«ã管çè æš©éã瀺ãããããã£ïŒäŸ:user=rootïŒã匷å¶çã«æ³šå ¥ããããšãå¯èœã«ãªã ããã®äžæ£ãªå±æ§ãæžã蟌ãŸããåŸãæ»æè ãåœè©²ã»ãã·ã§ã³ããªããŒããããåŸç¶ã®ãªã¯ãšã¹ããéä¿¡ãããšãã·ã¹ãã ã¯æ¹ãããããã»ãã·ã§ã³ãã¡ã€ã«ãæ£èŠã®ãã®ãšããŠèªã¿èŸŒã ãããã«ãããæ»æè ã¯æå¹ãªã¯ã¬ãã³ã·ã£ã«ïŒãã¹ã¯ãŒããå€èŠçŽ èªèšŒããŒã¯ã³ïŒãäžåæç€ºããããšãªãããµãŒããŒå šäœã®æ§æãããŒã¿ããŒã¹ãããã³ãã¹ããããŠãããã¹ãŠã®é¡§å®¢ã®Webãµã€ãã«å¯Ÿããå®å šãªç®¡çè ã¬ãã«ã®ã¢ã¯ã»ã¹æš©ã確ç«ãã ã - æšå¥šããã察ç (Mitigation):æ¬è匱æ§ã¯æ¢ã«åºç¯ãªæªçšã確èªãããŠãããã€ã³ã¿ãŒãããã«çŽæ¥å ¬éãããŠããã€ã³ã¹ã¿ã³ã¹ãéçšããŠããçµç¹ã¯ã峿ã®ç·æ¥å¯Ÿå¿ãããã³ã«ãçºåããå¿ èŠããã ã1. å ¬åŒãããã®é©çšïŒæåªå äºé ïŒ ãã³ããŒã§ããWebProsããæäŸãããŠããä¿®æ£ããŒãžã§ã³ïŒcPanel & WHM 11.136.0.5, 11.134.0.20, 11.132.0.29, 11.130.0.19, 11.126.0.54, 11.118.0.63, 11.110.0.97, 11.86.0.41 ãªã©ïŒãžã®å³æã¢ããã°ã¬ãŒãã宿œãã ãã¢ããããŒãå®äºåŸã¯ãå¿ ãcPanelãµãŒãã¹ãåèµ·åãããã«ãçªå·ãæ£ããåæ ãããŠããããšã確èªãã ã2. ç·æ¥ãããã¯ãŒã¯éé¢ïŒãããé©çšãŸã§ã®æ«å®æªçœ®ïŒ ãããã®é©çšã«æéãèŠããå Žåããããã¯æ€èšŒããã»ã¹ãå¿ èŠãªç°å¢ã«ãããŠã¯ããã¡ã€ã¢ãŠã©ãŒã«ïŒWAFãå«ãïŒããã³ãããã¯ãŒã¯ACLã¬ãã«ã§ãã³ã³ãããŒã«ããã«ãžã®ã€ã³ããŠã³ããã©ãã£ãã¯ãå³åº§ã«é®æãã ãå ·äœçã«ã¯ãTCPããŒã 2083ïŒcPanelã»ãã¥ã¢ã¢ã¯ã»ã¹ïŒã2087ïŒWHMã»ãã¥ã¢ã¢ã¯ã»ã¹ïŒã2095ã2096ã«å¯Ÿããã€ã³ã¿ãŒãããããã®ã¢ã¯ã»ã¹ããã¹ãŠããããããä¿¡é Œã§ãã管ççšIPã¢ãã¬ã¹ããã®æ¥ç¶ã®ã¿ãèš±å¯ãããã¯ã€ããªã¹ãæ¹åŒãžç§»è¡ãã ã3. 䟵害ã®çè·¡ïŒIoCïŒã®èª¿æ» 2026幎2æä»¥éã®ã¢ã¯ã»ã¹ãã°ã粟æ»ããAuthorizationãããå ã«ç°åžžãªBase64ãšã³ã³ãŒãæååãå«ãŸãããªã¯ãšã¹ããããã°ã€ã³æåã®èšé²ããªãã«ãããããã管çè æš©éã§ã®èšå®å€æŽãè¡ããã圢跡ããªããããã©ã¬ã³ãžãã¯èª¿æ»ãã ãè¥ææè¡è ãééãããããã€ã³ã: ãéçšãæ¢ããããªããããäžæçã«WAFã®ã·ã°ããã£ã«é Œãããšããã¢ãããŒãã¯æ¥µããŠå±éºã§ãã ãCRLFã€ã³ãžã§ã¯ã·ã§ã³ã¯ãšã³ã³ãŒãææ³ã®ããªãšãŒã·ã§ã³ã«ããWAFã®æ€ç¥ãããæããå¯èœæ§ãé«ãããããã¯ãŒã¯ã¬ãã«ã§ã®ç©ççãªããŒã鮿ïŒTCP 2083/2087ã®ãããã¯ïŒã«åãé²åŸ¡çã¯ãªã ããŸãã管çç³»ã€ã³ã¿ãŒãã§ãŒã¹ã宿ã«ã€ã³ã¿ãŒãããå šäœã«é²åºãããã¢ãŒããã¯ãã£ãã®ãã®ãæ ¹æ¬çãªã»ãã¥ãªãã£ã¢ã³ããã¿ãŒã³ã§ããããšã匷ãèªèããåžžã«VPNãZTNAïŒZero Trust Network AccessïŒã®èåŸã«é èœãããããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ã®ååãéµå®ããªããã°ãªããªã ã
- æ å ±æº:(https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/)
🚨 Alert 3: (ããããç¡å¹åããã€ã³ã¡ã¢ãªæ°žç¶åãã«ãŠã§ã¢ / CISA Emergency Directive 25-03 FIRESTARTER)
- æŠèŠ (3è¡ãŸãšã):ç±³åœCISAãšè±åœNCSCãå ±åã§åæçµæãå ¬éãããCisco補ãã¡ã€ã¢ãŠã©ãŒã«è£œåãæšçãšããåœå®¶æ¯æŽåïŒAPTïŒãã«ãŠã§ã¢ãFIRESTARTERãã®è åšã§ããããã¡ã€ã¢ãŠã©ãŒã«ã®ã³ã¢ã»ãã¥ãªãã£ãšã³ãžã³ã§ãããLINAãã®ã¡ã¢ãªé åãããã¯ããŠããã¯ãã¢ãæ§ç¯ããããã«ããã€ã¹ã®åèµ·åã·ã°ãã«ãæ€ç¥ããŠèªèº«ããã°ãã£ã¬ã¯ããªã«éé¿ãããããšã§ãéåžžã®ãã¡ãŒã ãŠã§ã¢ã¢ããããŒãåŸãæ°žç¶çã«åç¶ããé«åºŠãªã¹ãã«ã¹æ©èœãåããŠããã
- æè¡ç詳现:FIRESTARTERã¯ããããã¯ãŒã¯ã®é²åŸ¡å¢çãå®ãã¹ãã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹èªäœãææªã®ããã¯ãã¢ãžãšå€è²ããããæ¥µããŠæŽç·ŽãããLinux ELFïŒExecutable and Linkable FormatïŒãã€ããªã§ãã ã圱é¿ãåãããã©ãããã©ãŒã ã¯ãAdaptive Security Appliance (ASA) ãŸã㯠Firepower Threat Defense (FTD) ãœãããŠã§ã¢ãå®è¡ããŠãã Cisco FirepowerïŒ1000/2100/4100/9300ã·ãªãŒãºïŒããã³Secure FirewallïŒ200/1200/3100/4200/6100ã·ãªãŒãºïŒã®åºç¯ãªããã€ã¹çŸ€ã§ãã ãæ»æè
ã¯åæäŸµå
¥ãã§ãŒãºã«ãããŠãCisco ASAãã¡ãŒã ãŠã§ã¢ã«ååšããæ¢åã®è匱æ§ïŒCVE-2025-20333 ããã³ CVE-2025-20362çïŒããšã¯ã¹ããã€ãããããã€ã¹å
éšã«FIRESTARTERãå±éãã ãå®è¡ãéå§ããããšããã«ãŠã§ã¢ã¯çŽã¡ã«èªèº«ã®ã³ãŒããã·ã¹ãã ã®æ®çºæ§ã¡ã¢ãªäžã«ã³ããŒãããã©ã¬ã³ãžãã¯èª¿æ»ããéããããã«ãã£ã¹ã¯äžã®å
ã®å®è¡å¯èœãã¡ã€ã«ïŒäŸ:
/usr/bin/lina_csïŒãäžæãã¡ã€ã«ãå®å šã«æ¶å»ãã ããã®ãã«ãŠã§ã¢ã®çã®è åšã¯ãCiscoããã€ã¹ã®ã³ã¢ã»ãã¥ãªãã£åŠçãšã³ãžã³ã§ãããLINAãã«å¯Ÿããé«åºŠãªã€ã³ã¡ã¢ãªã»ãããã³ã°æè¡ã«ãã ãFIRESTARTERã¯LINAã®ä»®æ³ã¡ã¢ãªç©ºéãåçã«ã¹ãã£ã³ãããXML Handlerãã®èŠçŽ ããŒãã«ãç¹å®ããŠç¬èªã®ããã¯ïŒå²ã蟌ã¿åŠçïŒãã€ã³ã¹ããŒã«ãã ããã®ããã¯ã«ããããã«ãŠã§ã¢ã¯ããã€ã¹ãééããæ£åžžãªãã©ãã£ãã¯ãååããç¹å®ã®æ¡ä»¶ãæºããWebVPNãªã¯ãšã¹ããåŸ ã¡åãã ãæ»æè ããéä¿¡ãããWebVPNãªã¯ãšã¹ãå ã«ããŒãã³ãŒãããã8ãã€ãã®ASCIIæååãšç¹å®ã®è¢«å®³è IDïŒVictim IDïŒã確èªããããšããã«ãŠã§ã¢ã¯ãªã¯ãšã¹ãã«å å ãããä»»æã®ã·ã§ã«ã³ãŒããã¡ã¢ãªäžã§çŽæ¥å®è¡ãã ããã®ã¡ã«ããºã ã«ãããæ»æè ã¯ãLINE VIPERããªã©ã®åŸç¶ã®ã€ã³ãã©ã³ããèªç±ã«å±éãããããã¯ãŒã¯å éšãžã®ã©ãã©ã«ã ãŒãã¡ã³ãïŒæšªå±éïŒã®è¶³å Žã確ç«ãã ãããã«é²è¡åŽãå°é£ã«ãããŠããã®ããFIRESTARTERãåããç°åžžãªã»ã©ã®æ°žç¶åïŒPersistenceïŒèœåã§ãã ãéåžžã®ã¡ã¢ãªåžžé§åãã«ãŠã§ã¢ã¯ããã€ã¹ã®åèµ·åã«ãã£ãŠæ¶æ» ããããFIRESTARTERã¯OSã®å²ã蟌ã¿ãã³ãã©ãç£èŠããã·ã¹ãã ã·ã£ããããŠã³ãåèµ·åã®å åãšãªãçµäºã·ã°ãã«ïŒSIGTERM, SIGINT, SIGHUPçïŒãæ€ç¥ããã³ãŒã«ããã¯é¢æ°ãç»é²ããŠãã ãåèµ·åã®ã³ãã³ããçºè¡ãããç¬éããã«ãŠã§ã¢ã¯èªèº«ã®ã³ããŒãåèµ·ååŸãããŒã¿ãä¿æãããç¹å®ã®ãã°ãã£ã¬ã¯ããªïŒ/opt/cisco/platform/logs/var/log/svc_samcore.logïŒã«æžãåºããŠéé¿ããã ãåæã«ãããã€ã¹ã®èµ·åã·ãŒã±ã³ã¹ãå¶åŸ¡ããCSP_MOUNT_LISTãã¡ã€ã«ãæ¹ããããæ¬¡åã®ã·ã¹ãã èµ·åæã«éé¿ããããã«ãŠã§ã¢ãåã³/usr/bin/lina_csã«åŸ©å ãããããã¯ã°ã©ãŠã³ãããã»ã¹ãšããŠå¯ãã«åå®è¡ãããã¹ã¯ãªãããä»èŸŒãã®ã§ãã ã - æšå¥šããã察ç (Mitigation):æ¬ãã«ãŠã§ã¢ã®æåãå®å šã«çè§£ããªããŸãŸæšæºçãªã€ã³ã·ãã³ã察å¿ãè¡ããšãè åšãæž©åããçµæãšãªããCISAãçºä»€ããç·æ¥æä»€ïŒED 25-03ïŒã«åºã¥ãã以äžã®å³æ Œãªå¯Ÿå¿æé ã宿œããå¿ èŠããã ã1. ç©ççãªããŒããªã»ããã®å®è¡ïŒèŽåœçã«éèŠïŒ ãœãããŠã§ã¢ããŒã¹ã®åèµ·åã³ãã³ãïŒãªããŒãïŒã¯ããã«ãŠã§ã¢ã®ãéé¿ããã»ã¹ããèµ·åããSIGTERMã·ã°ãã«ãçºè¡ããŠããŸãããã絶察ã«äœ¿çšããŠã¯ãªããªã ãææã®çããããããã€ã¹ãåæåããããã¯ããããé©çšããéã¯ãããã€ã¹ã®é»æºã±ãŒãã«ãç©ççã«åŒãæããããŒããªã»ãããã宿œããªããã°ãªããªã ãããã«ããããã«ãŠã§ã¢ã«éé¿ã¹ã¯ãªãããå®è¡ããCPUãµã€ã¯ã«ãäžãããæ®çºæ§ã¡ã¢ãªäžã®ããã¯ãšãã«ãŠã§ã¢æ¬äœãå®å šã«æ¶æ» ãããããšãã§ãã ã2. ã¡ã¢ãªãã©ã¬ã³ãžãã¯çšã³ã¢ãã³ãã®ååŸãšä¿å š ããŒããªã»ããã宿œããåã«ãæ®çºæ§ã¡ã¢ãªäžã®èšŒæ ãä¿å šãããããCISAã®ãCore Dump and Hunt Instructionsãã«åŸããããã€ã¹ããå®å šãªã³ã¢ãã³ããååŸãã ãååŸããã³ã¢ãã³ãã¯CISAã®æäŸããYARAã«ãŒã«ãçšããŠèµ°æ»ããããç±³åœé£éŠæ©é¢ã®å Žåã¯ãMalware Next Generation (MNG)ããã©ãããã©ãŒã ãžæåºããŠè§£æãäŸé Œãã ã3. ã¯ãªãŒã³ãªç¶æ ããã®ãã¡ãŒã ãŠã§ã¢é©çš ããŒããªã»ããã«ããã¡ã¢ãªç©ºéãå®å šã«æµåãããããšã確èªããåŸãCiscoããæäŸãããŠããææ°ã®ã»ãã¥ãªãã£ããããé©çšãã ããããé©çšæžã¿ã®ç°å¢ã§ãã£ãŠããéå»ã«äžåºŠã§ã䟵害ãåããŠããã°ãã«ãŠã§ã¢ã¯åç¶ããŠããå¯èœæ§ããããããå¿ ãç©ççãªé»æºæã䌎ããªã»ãããæé ã«çµã¿èŸŒãå¿ èŠããã ãè¥ææè¡è ãééãããããã€ã³ã: ã€ã³ãã©éçšã«ãããæå€§ã®èª€è¬¬ã¯ããã³ããŒãå ¬éããææ°ã®ãã¡ãŒã ãŠã§ã¢ããããé©çšããã°ããã¹ãŠã®è åšã¯æé€ãããããšããæã蟌ã¿ã§ãã ãFIRESTARTERã®ãããªAPTã¯ã©ã¹ã®ãã«ãŠã§ã¢ã¯ãããããé©çšããããåèµ·åã®ééããçž«ã£ãŠãã¡ã€ã«ã·ã¹ãã ã«å¯çãããããé©çšåŸã®ã¯ãªãŒã³ãªã·ã¹ãã ã«åã³ææãåºããèšèšãšãªã£ãŠãã ãæ®çºæ§ã¡ã¢ãªã®ç¹æ§ïŒé»æºåªå€±ã§ããŒã¿ãæ¶ããïŒãæŠç¥çã«æŽ»çšãããœãããŠã§ã¢ã«ããå¶åŸ¡ããã€ãã¹ããç©ççãªå¯Ÿå¿ïŒããŒããªã»ããïŒããããé«åºŠãªæç¶çè åšãæã¡åãå¯äžã®ææ®µã§ããããšãæ·±ãçè§£ããªããã°ãªããªãã
- æ å ±æº:(https://www.cisa.gov/news-events/analysis-reports/ar26-113a),(https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices)
Section 3: CISO/Manager Summary
ä»é±ã®ããŒã¯ãŒã: ãAI-Accelerated Exploitation & Edge Persistenceã (AIã«ããæ»æã®å éãšå¢çããã€ã¹ã§ã®æ°žç¶å)
ä»é±ã®ã»ãã¥ãªãã£æ å¢ã®ä¿¯ç°ããæµ®ãã³äžããæ¬è³ªçãªçµå¶èª²é¡ã¯ãæ»æã€ã³ãã©ã¹ãã©ã¯ãã£ã«ããããAI掻çšã«ããå µåšåãµã€ã¯ã«ã®å§åçãªé«éåããšããããã¯ãŒã¯ã®å¢çãå®ãã¹ããšããžããã€ã¹ã«ãããŠããããé©çšãç¡å¹åããé«åºŠãªæ°žç¶åïŒPersistenceïŒææ³ããå®çãã€ã€ãããšãããé²è¡åŽã«ãšã£ãŠæ¥µããŠäžå©ãªãã©ãã€ã ã·ããã§ãããçµç¹ã®ã»ãã¥ãªãã£è²¬ä»»è ã¯ãåŸæ¥ã®ãå¢çé²åŸ¡ãšå®æçãªãããé©çšããåæãšããã³ã³ãã©ã€ã¢ã³ã¹äž»å°ã®ã»ãã¥ãªãã£ã¢ãã«ããæ¢ã«éçãè¿ããŠããäºå®ãçŽèŠããªããã°ãªããªãã
管çè ãžã®æèš
çµç¹ã®ã»ãã¥ãªãã£ã€ã³ãã©ã¹ãã©ã¯ãã£ãçµ±æ¬ãã責任è ïŒCISOïŒããã³ITãããŒãžã£ãŒã¯ãçŽã¡ã«èªçµç¹ã®ãªã¹ã¯ãããžã¡ã³ãæŠç¥ãåè©äŸ¡ãã以äžã®3ã€ã®æ žå¿çãªé åã«ãããŠã¢ãŒããã¯ãã£ã®ææ¬çãªåæ§ç¯ãšããªã·ãŒã®ç£æ»ãå®è¡ãããã匷ãæèšããã
1. AIäž»å°ã®è匱æ§çºèŠã«ããããŒããã€åžžæ åããšããããŠã£ã³ããŠã®æ¶æ» ãžã®é©å¿ ãµã€ããŒæ»æã®åæãã§ãŒãºã«ãããŠãAIã¯ãã¯ãæŠå¿µå®èšŒã®åãè±ããå®çšçãªå µåšãšããŠçåšãæ¯ãã£ãŠãããä»é±äžçãéæŒãããLinuxã«ãŒãã«ã®è匱æ§ïŒCVE-2026-31431 “Copy Fail”ïŒã¯ãTheori瀟ã®AIãããã¬ãŒã·ã§ã³ããŒã«ãXint Codeãã«ãã£ãŠãããã1æéã®èªåŸçãªã¹ãã£ã³ã«ããçºèŠãããçŽã¡ã«100%ã®æåçãèªããšã¯ã¹ããã€ãã³ãŒããçæããã ããŸããAIã¢ãã«ã®çµ±åç°å¢ãæäŸããLiteLLMã®SQLã€ã³ãžã§ã¯ã·ã§ã³è匱æ§ïŒCVE-2026-42208ïŒã¯ãèåŒ±æ§æ å ±ãå ¬éãããŠããããã36æéåŸã«ã¯å®ç°å¢ã§ã®æªçšãéå§ãããããšã確èªãããŠãã ãããã«ãLlamaãGPT-4ãªã©ã®åŒ·åãªLLMãçµ±åããæ¥µããŠèªç¶ã§æèã«æ²¿ã£ãæšçåãã£ãã·ã³ã°ã¡ãŒã«ãèªåçæãããã©ãããã©ãŒã ãBluekitãã®å°é ããæ»æã³ã¹ãã®å€§å¹ ãªäœäžã瀺ããŠãã ã
ãããã®äºè±¡ã瀺ãå·åŸ¹ãªäºå®ã¯ãããã³ããŒããããããæäŸãããŠãããã·ã¹ãã ã«é©çšãããŸã§ã®ç¶äºæéïŒããããŠã£ã³ããŠïŒããšããé²åŸ¡åŽã®åæãå®å šã«åŽ©å£ãããšããããšã§ãããè匱æ§ãçºèŠãããç¬éããããã¯ãã以åã«ãAIã«ãã£ãŠèªååãããæ»æã€ã³ãã©ãäžçäžã®ã€ã³ã¿ãŒãããå¢çãã¹ãã£ã³ãããšã¯ã¹ããã€ããæäžããæä»£ã«çªå ¥ããŠãããCISOã¯ãææ¬¡ã鱿¬¡ãšãã£ãå®äŸçãªãããé©çšãµã€ã¯ã«ã«äŸåããã¬ã¬ã·ãŒãªéçšã¢ãã«ãæšãŠãªããã°ãªããªãããã®ä»£æ¿ãšããŠãWebã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒWAFïŒãã©ã³ã¿ã€ã ã¢ããªã±ãŒã·ã§ã³èªå·±ä¿è·ïŒRASPïŒãã³ã³ããã¬ãã«ã§ã®ã·ã¹ãã ã³ãŒã«å¶éïŒSeccompçïŒãçµã¿åãããåçãªé²åŸ¡å±€ã®æ§ç¯ãæ¥åã§ãã ãåæã«ãMicrosoftãæ°ãã«æäŸãéå§ãããAgent 365ãã®ãããªãAIãšãŒãžã§ã³ãã®èªåŸçãªæ¯ãèããç£èŠããç°åžžãªã¢ã¯ã»ã¹ããã¢ãªã¢ã«ã¿ã€ã ã§ãããã¯ãããAIã«ã¯AIã§å¯Ÿæããããœãªã¥ãŒã·ã§ã³ã®å°å ¥æ€èšãéå§ãã¹ãã§ãã ã
2. ãšããžããã€ã¹ãšç®¡çåºç€ãžã®ãé²åŸ¡å¢çãã®åå®çŸ©ãšãŒããã©ã¹ãã®åŸ¹åº ãå éšãããã¯ãŒã¯ã¯å®å šã§ãããå€éšããã®æ»æã¯ãã¡ã€ã¢ãŠã©ãŒã«ãé²ãããšããå¢çé²åŸ¡ã¢ãã«ã¯ãä»é±æããã«ãªã£ãcPanel & WHMã®èªèšŒãã€ãã¹ïŒCVE-2026-41940ïŒããCisco ASA/FTDããã€ã¹ãä¹ã£åããã«ãŠã§ã¢ïŒFIRESTARTERïŒã®äºäŸã«ããããã®è匱æ§ãå®å šã«é²åãã ãæ»æè ã¯çŸåšã匷åºã«å®ãããå éšã·ã¹ãã ã«æ£é¢ããæãã®ã§ã¯ãªããããããã¯ãŒã¯ã®å¢çãå®ãã»ãã¥ãªãã£æ©åšãããã·ã¹ãã ã管çããããã®ã³ã³ãããŒã«ããã«ããã®ãã®ãæåªå ã®æšçãšããŠããããããã¯ç¹æš©çãªã¢ã¯ã»ã¹æš©ãæã¡ãªãããã€ã³ã¿ãŒãããã«åºãå ¬éãããŠããã±ãŒã¹ãå€ãããã§ãã ã
CISOã¯ãèªçµç¹ã®ãããã¯ãŒã¯ã¢ãŒããã¯ãã£ãå æ¬çã«ç£æ»ããã³ã³ãããŒã«ããã«ãVPNã²ãŒããŠã§ã€ããã¡ã€ã¢ãŠã©ãŒã«ã®ç®¡çããŒããªã©ããããã管çç³»ã€ã³ã¿ãŒãã§ãŒã¹ãã€ã³ã¿ãŒããã空éïŒ0.0.0.0/0ïŒã«çŽæ¥é²åºããŠããªããã培åºçã«ç¢ºèªããå¿ èŠããã ããã¹ãŠã®ç®¡çã¢ã¯ã»ã¹ã¯ãå ç¢ãªã¢ã€ãã³ãã£ãã£ãããã€ãïŒIdPïŒãšé£æºãããã£ãã·ã³ã°èæ§ã®ããå€èŠçŽ èªèšŒïŒMFAïŒãããã³ããã€ã¹ã®ãã¹ãã£ïŒå¥å šæ§ïŒè©äŸ¡ãäŒŽãæ¡ä»¶ä»ãã¢ã¯ã»ã¹å¶åŸ¡ã®èåŸã«å®å šã«é èœãããªããã°ãªããªãããããã¯ãŒã¯ã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãæšé²ããäžãäžãšããžããã€ã¹ã䟵害ãããå Žåã§ããå éšãããã¯ãŒã¯ãžã®ã©ãã©ã«ã ãŒãã¡ã³ãïŒæšªå±éïŒãç©ççã»è«ççã«å°ã蟌ãããŒããã©ã¹ãã¢ãŒããã¯ãã£ã®ååããã€ã³ãã©ã®æ·±éšã«ãŸã§æµžéãããããšãæ±ãããã ã
3. ã衚é¢çãªãããé©çšãããã®è±åŽãšãã¡ã¢ãªãã©ã¬ã³ãžãã¯èœåã®ç¢ºç« ã€ã³ã·ãã³ãã¬ã¹ãã³ã¹ïŒIRïŒã«ãããæå€§ã®ãã©ãã€ã ã·ããã¯ããããããåœãŠãŠã·ã¹ãã ãåèµ·åããã°å¯Ÿå¿å®äºããšããç§æçãªéçšããé«åºŠãªè åšã°ã«ãŒãã«ã¯ãã¯ãéçšããªãç¹ã«ãããCISAãçºä»€ããç·æ¥æä»€ïŒED 25-03ïŒã瀺ãéããCisco補ããã€ã¹ã«ææãããFIRESTARTERããã«ãŠã§ã¢ã¯ããœãããŠã§ã¢çãªåèµ·åã·ã°ãã«ïŒSIGTERMçïŒãããã¯ããã·ã¹ãã ã忢ããçŽåã«èªèº«ã®ã³ããŒãäžæ®çºæ§ã¹ãã¬ãŒãžã®ãã°ãã£ã¬ã¯ããªã«éé¿ãããããšã§ããããé©çšãããšãç°¡åã«çãå»¶ã³ã ã
ãã®äºå®ããå°ãåºãããæèšã¯ãã€ã³ãã©éçšæ åœè ã«å¯Ÿãããã€ã³ã·ãã³ã察å¿ããã»ã¹ã®åæè²ãã®çµ¶å¯Ÿçãªå¿ èŠæ§ã§ãããã»ãã¥ãªãã£ç®¡çè ã¯ãèªçµç¹ã®IRãã©ã³ã«ãããŠãã€ã³ã·ãã³ãçºçæã®èšŒæ ä¿å šããã»ã¹ãæ£ããå®çŸ©ãããŠããããå確èªããªããã°ãªããªããå ·äœçã«ã¯ãæ®çºæ§ã¡ã¢ãªäžã®ããã¯ããã«ãŠã§ã¢æ¬äœãæ¶æ» ãããããã®ãç©ççããŒããªã»ããïŒé»æºã±ãŒãã«ã®æç·ïŒãã®æé ããããã宿œããåã«ã¡ã¢ãªç©ºéã®å®å šãªã¹ãããã·ã§ããïŒã³ã¢ãã³ãïŒãååŸãè§£æãããã¡ã¢ãªãã©ã¬ã³ãžãã¯ãã®ããã»ã¹ãäžå¯æ¬ ã§ãã ãããã«ãã©ã³ãµã ãŠã§ã¢è¢«å®³ã®èª¿æ»ã«ãããŠJPCERT/CCãææããŠããããã«ãWindowsã€ãã³ããã°ïŒã€ãã³ãID: 10000, 10001çïŒã®ç°åžžãªæ¥å¢ãContiãAkiraãšãã£ããã«ãŠã§ã¢ã«ããæå·åçŽåã®ã¢ããªã±ãŒã·ã§ã³åŒ·å¶çµäºã®çè·¡ãšããŠæŽ»çšã§ãããªã©ããã£ã¹ã¯ãšã¡ã¢ãªã®äž¡é¢ããè åšã®çè·¡ïŒIoCïŒãããã¢ã¯ãã£ãã«ãã³ãã£ã³ã°ããäœå¶ã®æ§ç¯ãæ¥åã§ãã ãé²åŸ¡åŽã¯ãäŸµå®³ãæ¢ã«çºçããŠãããšãããAssume Breachãã®åæã«ç«ã¡ãã·ã¹ãã æ·±å±€ã®æ¯ãèãããæªæãèŠã€ãåºãé«åºŠãªç£èŠèœåãçŽã¡ã«çµç¹åããªããã°ãªããªãã


ã³ã¡ã³ã