(2020/5/8 8:30æ´æ°)ã¤ã³ã·ãã³ã Microsoft 365 ã®ã管çã»ã³ã¿ã¼ãã®ããµã¼ãã¹æ£å¸¸æ§ãã®ã¤ã³ã·ãã³ãã確èªããã¨ããã以ä¸ã®ããã«è¡¨ç¤ºããã¦ãã¾ããã Outlookã¯ã©ã¤ã¢ã³ãã§ã®è¤æ°ã®ã¯ã¬ãã³ã·ã£ã«ããã³ãã æçµæ´æ°æ¥æï¼2020å¹´5æ8æ¥ 8:29 AM ã¦ã¼ã¶ã¼ã¸ã®å½±é¿ï¼Outlook ã¯ã©ã¤ã¢ã³ãå ã§ã¯ã¬ãã³ã·ã£ã«ã®ããã³ãããç¹°ãè¿ã表示ããããã¨ãããã¾ãã 詳細ï¼å½ç¤¾ã§ã¯ä¿®å¾©ã«æ³¨åãã¦ãã¾ãããWebãã¢ãã¤ã«ããã¤ã¹ã§Outlookãªã©ã®ä»ã®ãããã³ã«ã«ã¢ã¯ã»ã¹ã§ããã¦ã¼ã¶ã¼ã¯ãåé¡ãªãé»åã¡ã¼ã«ã«ã¢ã¯ã»ã¹ã§ãã¾ãã ãã®åé¡ã¯ãåºæ¬èªè¨¼ããå©ç¨ã®ã客æ§ã«ã®ã¿å½±é¿ãã¾ããå é²èªè¨¼ããå©ç¨ã®ã客æ§ã¯ãå½±é¿ãåããã¦ã¼ã¶ã¼ã¸ã®å½±é¿ã軽æ¸ããããã«å é²èªè¨¼ãæå¹ã«ãããã¨ãã§ãã¾ããããã®ããã»ã¹ãæå¹ã«ãªãã¾ã§ã«æ°æéãããå ´åãããã¾ãã å ¨ã¦
æ¥å¤ããæ å¢ã«ãããã¬ã¯ã¼ã¯ãå®æ½ããä¼æ¥ãå¢å ãã¦ããä»ãç¥ã£ã¦ããã¹ãæ»æããã©ãã©ã«ãã£ãã·ã³ã°ãã§ããã©ãã©ã«ï¼æ¨ªæ¹åï¼ãã£ãã·ã³ã°ã¨ã¯ãä¹ã£åã£ãæ£è¦ã®ã¡ã¼ã«ã¢ã«ã¦ã³ããããã®ã¢ã«ã¦ã³ãã«ãªããã¾ãã¦ãã£ãã·ã³ã°ã¡ã¼ã«ãéãææ³ã®ãã¨ãæãã¾ãã ç¹ã«æ³¨æãããã®ããMicrosoft 365ãï¼æ§ç§°Office 365ï¼ã®ã¢ã«ã¦ã³ãã®ä¹ã£åãã§ããMicrosoft 365ã«ã¯ã¡ã¼ã«ããã¡ã¤ã«å ±æãªã©ãã¾ãã¾ãªãµã¼ãã¹ããããã¯ã©ã¦ãä¸ã®å ±éURLããIDã¨ãã¹ã¯ã¼ãã§ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãã¦å©ç¨ã§ãããããé常ã«ä¾¿å©ãªãã®ã¨ãªã£ã¦ãã¾ãããã¬ã¯ã¼ã¯ã®ããã«Microsoft 365ãå°å ¥ããæ´»ç¨ãã¦ããä¼æ¥ãå¤ãã§ãããããã®åé¢ãã»ãã¥ãªãã£è¨å®ãéç¨æ¹æ³ããã¡ãã¨ã§ãã¦ããªãã¨ã¢ã«ã¦ã³ãæ å ±ãçªåããããã¾ãã¾ãªéè¦ãã¼ã¿ã«ç°¡åã«ã¢ã¯ã»ã¹ã許ãã¦ãã¾ãã¨ãããã¨ãããå¾ã¾
ä¿ææéãåããå ´å éã¢ã¯ãã£ããªã¡ã¼ã«ããã¯ã¹ã確èªããã³ãã³ãã¬ãã éè·è ã®ã¢ã«ã¦ã³ãã«å¯¾ãã¦è¨´è¨ãã¼ã«ããªã©ã®ä¿ææ©è½ãæå¹ã«è¨å®ãã¦ããå ´åãã©ã¤ã»ã³ã¹ãä»ä¸ããã¦ããç¶æ ã§ã¦ã¼ã¶ã¼ãåé¤ãã¾ãã¨ãä»ä¸ããã¦ããã©ã¤ã»ã³ã¹ã¯èªåçã«å¤ãã[éã¢ã¯ãã£ããªã¡ã¼ã«ããã¯ã¹] ã¨ãã¦ã訴è¨ãã¼ã«ããªã©ã®ä¿ææ©è½ã§è¨å®ãã¦ããä¿ææéãµã¼ãã¼ã«ä¿åãããåä½ã«ãªãã¾ãã [éã¢ã¯ãã£ããªã¡ã¼ã«ããã¯ã¹] ã¯è¨´è¨ãã¼ã«ããªã©ã®ä¿ææ©è½ãæå¹ã®ç¶æ ã§ãããã¨ãããã³ãã©ã¤ã»ã³ã¹ãä»ä¸ããã¦ããç¶æ ã§ã¦ã¼ã¶ã¼ãåé¤ãããã¨ãæ¡ä»¶ã¨ãªãã¾ãã ã¦ã¼ã¶ã¼ã®åé¤ãè¡ãããåã«ã©ã¤ã»ã³ã¹ãå¤ãããå ´åã¯ãä¿ææ©è½ãå©ç¨ããããã®å©ç¨è¦ä»¶ãæºããã¦ããªãç¶æ ã«ãªããããä¿æã®ä¿è¨¼ãããã¾ããã ä¿ææ©è½ã«ã¤ãã¦ã¯ã以ä¸ã®è¨äºããåç §ãã ããã it-bibouroku.hateblo.jp ãªããéã¢
ãã®ããã«ã¯ãOffice 365 ã®æ©è½ãæ¥åã®ä¸ã§ã©ã®ããã«ä½¿ããããã使ããããæ¤è¨ãã¦ããå¿ è¦ãããã¾ããããã«ãã£ã¦ãã©ããã£ãæ¥åã«å¹æãä¸ãããããããããã«ãã£ã¦ã©ããã£ãå¹æãå¾ãããããã¨ãã£ããã¨ãå°ããã¤è¦ãã¦ãã¾ãããã®ãããã¯ãå¾è¿°ããã¢ã¼ãªã¼ã¢ããã¿ã¼ããã£ã³ããªã³ã¦ã¼ã¶ã¼ã®æè¦ãåãå ¥ããã¨ããå ·ä½çã«ãªãã¨æãã¾ãã ãã㦠KPI ã®è¨æ¸¬æ¹æ³ã®ã²ã¨ã¤ã¨ãã¦ãOffice 365 ã§ã¯ Office 365 å©ç¨ç¶æ³ã¬ãã¼ããæä¾ããã¦ãããèªç¤¾ã®ããã³ãå ã§ãµã¼ãã¹ãã©ãã ãå©ç¨ããã¦ãããã®å®éçãªãã¼ã¿ãåå¾ãããã¨ãã§ãã¾ããã¾ããPower BI ãç¨ãããã³ãã¬ã¼ããæä¾ããã¦ãã¾ãã Microsoft 365 管çã»ã³ã¿ã¼ã®ã¢ã¯ãã£ããã£ã¬ãã¼ã https://docs.microsoft.com/ja-jp/office365/admi
Most phishing campaigns use social engineering and brand impersonation to attempt to take over accounts and trick the victim into divulging their credentials. PhishLabs has uncovered a previously unseen tactic by attackers that uses a malicious Microsoft Office 365 App to gain access to a victim's account without requiring them to give up their credentials to the attackers. In this technique, the
æ¥æ¬å½å ã§ãå¤ãã®ä¼æ¥ãå©ç¨ãã¦ãããã¤ã¯ãã½ãã社ãæä¾ããOffice365ãå æã¯å¤§è¦æ¨¡ãªãµã¼ãã¹é害ãçºçãããã¬ãã§ãæ¾éãããäºæ ã¨ãªã£ããå 許å¶ã®äºæ¥ã§ããéä¿¡ãã£ãªã¢ã®ãµã¼ãã¹é害ããã¬ãå ±éãããã®ã¯å½ç¶ã ããä¸ä¼æ¥ãæä¾ããã¯ã©ã¦ããµã¼ãã¹ã®ãµã¼ãã¹é害ãNHKçãå ±éããäºæ ã«ãªãã¨ããã®ã¯é常ã«ã¬ã¢ãªã±ã¼ã¹ã§ããããã®ãã¨ãããOffice365ã®é害ãã©ãã ãå½å ä¼æ¥ã¸å½±é¿ãããããããå½±é¿ã®å¤§ãããããããç¥ããã¨ãåºæ¥ãã â Office365çã®ãµã¼ãã¹é害ã®ç¢ºèªæ¹æ³ãOffice365ã®ãµã¼ãã¹é害ãçºçããæã«ã以å¤ã¨ç¥ããã¦ããªãã£ãã®ããOffice365ã®ãµã¼ãã¹é害ã®ã¹ãã¼ã¿ã¹ã確èªããæ¹æ³ã ãé常ã§ããã°ãOffice365ã®ç®¡çã³ã³ã½ã¼ã«ãã確èªå¯è½ã ãããµã¼ãã¹é害æã«Office365èªä½ã«ãã°ã¤ã³åºæ¥ãªããªããã¨ãå¤ã ããããã®ãããã
"Office 365 ãå°å ¥ããåãå°å ¥ããå¾ã«æ å ±å ±æãã¼ã«ã§ã®æè³å¯¾å¹æãã©ã®ããã«èããã°è¯ãã®ãï¼ã¨ãããã¨ãã¾ã¨ããâèªã¿ç©âã¨ãªãã¾ãã (ã¹ã©ã¤ãæ°ãå¤ãã®ã§ãã¦ã³ãã¼ããã¦ãå©ç¨ãã ãããã¾ããåå©ç¨å¯ã®è³æã¨ãªãã¾ãã詳細ã¯è³æå ãã確èªãã ãããã¾ããPowerPoint ãã¡ã¤ã«ã¨ãã¦æµç¨ããããå ´åã¯ããææ°ã§ããä¸è¨ã®ã³ãã¥ããã£ã«ãåå é ããã¦ã³ãã¼ãããé¡ããããã¾ã) ã¾ããä¸è¨ã®è³æã«ã¤ãã¦ã®è³ªåããæè¦ãªã©ã¯ä¸è¨ã³ãã¥ããã£å ã§åãä»ãã¦ããã¾ãï¼å¯è½ãªéãï¼ M365 ã³ãã¥ããã£ã«ãåå ãããå ´åã¯ä»¥ä¸ã® URL ãããåå ãã ããã https://www.yammer.com/japanoffice365users/#/home ""Office 365 ã使ãå§ãã/使ãåãâ ã·ãªã¼ãºãã¾ã¨ããã¯ãªãããã¼ãã¯ä»¥ä¸ã§ãã https://w
United States Computer Emergency Readiness Team (US-CERT)ã¯9æ4æ¥(ç±³å½æé)ããNCSC Releases UK Cyber Incident Trends Reportï½CISAãã«ããã¦ãè±å½ã®ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NCSC: United Kingdom National Cyber Security Centreï¼ãè±å½ã®ãµã¤ãã¼ã¤ã³ã·ãã³ãã«ã¤ãã¦ã¾ã¨ããå ±åæ¸ãå ¬éããã¨ä¼ããã åå ±åæ¸ã¯ã2018å¹´10æãã2019å¹´4æã¾ã§ã«è±å½å ã§è¦³æ¸¬ããããµã¤ãã¼ã¤ã³ã·ãã³ãã®ååãã¾ã¨ãããã®ãè±å½ã®çµç¹ã«å½±é¿ãä¸ãã5ã¤ã®ä¸»ãªå¾åã¨ãã¦ããOffice 365ããã©ã³ãµã ã¦ã§ã¢ãããã£ãã·ã³ã°ããèå¼±æ§ã¹ãã£ã³ãããµãã©ã¤ãã§ã¼ã³æ»æããæãã¦ããããããã®ãªã¹ã¯ã«å¯¾ããã©ã®ããã«é²å¾¡ãå®æ½ããã°ããã®ãã¨ãã£ã
æ¬è£½åä¸ã§ç®¡çããMicrosoft 365 ã¦ã¼ã¶ã¼æ°ã§ãã(管çããã³ãæ°ã¯èª²é対象å¤ã§ãã) â»å ±æã¡ã¼ã«ããã¯ã¹ / ãããªãã¯ãã©ã«ãã¼ / ãã®ä»ã®éã¦ã¼ã¶ã¼ãªã½ã¼ã¹ã¯èª²é対象å¤ã§ãã ä½ããå ±æã¡ã¼ã«ããã¯ã¹ãªã©ã®éã¦ã¼ã¶ã¼ã¡ã¼ã«ããã¯ã¹ã ç£æ» ããå ´åã«éããéã¦ã¼ã¶ã¼ã¡ã¼ã«ããã¯ã¹æ°ã課é対象ã¨ãã¦ã«ã¦ã³ãããã¾ãã
Microsoftã¯ç±³å½æé5æ6æ¥ããWindowsããMacãããã³ã¢ãã¤ã«æ©å¨åãã®ãã¸ãã¹çç£æ§ãµã¼ãã¹ãOffice 365ãã§æä¾ãã¦ããåæãã¼ã«ããMyAnalyticsãã®æ°æ©è½ãçºè¡¨ããããã®ãã¼ã«ã¯ãã¦ã¼ã¶ã¼ãä»äºã®æéãã©ã®ããã«è²»ãããããåæãããã®æ å ±ãããã·ã¥ãã¼ãã«è¡¨ç¤ºãããã®ã æ°æ©è½ã®1ã¤ã¨ãã¦ãéå»1ã«æéã§æ¥åçµäºå¾ã«ãã¡ãã¨ä»äºãé¢ãããã¨ãã§ããæ¥æ°ãç¥ããã¦ãããããã«ãªããããã«ãããæ¥åæéå¤ã«ä¼æ¯ãã¨ããæ¥ãå¢ãããããã«ç®æ¨ãè¨å®ããç¿æ £åããããããã¨ãããã¾ãããã©ã¼ã«ã¹æéãå¹ççã«ç¢ºä¿ããããã®ãã¼ã½ãã«ãã©ã³ãä½æããæ©è½ã追å ããã Microsoftã¯ãããã®æ°æ©è½ããã·ã¢ãã«ã§éå¬ä¸ã®å¹´æ¬¡éçºè ä¼è°ãBuildãã§çºè¡¨ãããITæ¥çã§ã¯ãããã¤ã¹ããµã¼ãã¹ã®å©ç¨ãããå¿«é©ã«ãããã¨ãç®æããåãçµã¿ãå¢ãã¦ããã Ap
æ±äº¬çç§å¤§å¦ã«ããã¦ããã£ãã·ã³ã°ã«ããæå¡ãå¦çãå©ç¨ããã¯ã©ã¦ããµã¼ãã¹ã®ã¢ã«ã¦ã³ããä¹ã£åããããã¨ãããã£ããã¡ã¼ã«ãä¸æ£ã«è»¢éãããã»ããã¡ã¼ã«ããã¯ã¹ãã¯ã©ã¦ãã¹ãã¬ã¼ã¸ãã¢ã¯ã»ã¹ãåããå¯è½æ§ãããã å大ã«ããã°ãæå¡4人ãå¦ç4人ããã£ãã·ã³ã°ãµã¤ãã¸èªå°ããã¦èª¤ã£ã¦ãã¹ã¯ã¼ããå ¥åãã¦ãã¾ããã¯ã©ã¦ããµã¼ãã¹ãOffice 365ãã®ã¢ã«ã¦ã³ããä¹ã£åããã¦ãããã¨ã2018å¹´11æ6æ¥ã«å¤æãããã®ã 10æ30æ¥ãããããå大ã®æè·å¡ãå¦çãåæ¥çã«å¤æ°ã®ãã£ãã·ã³ã°ã¡ã¼ã«ãå±ãã¯ããããã¨ããã調æ»ãé²ãã¦ããã¨ãã被害ãå¤æããã¨ããã ä»åã®ä¹ã£åãã«ããã2018å¹´9æ11æ¥ããåå¹´11æ6æ¥ã«ããã¦æå¡ãå¦çãåä¿¡ãã3727件ã®ã¡ã¼ã«ãå¤é¨ã¸æå³ãã転éããã¦ããã
translation View on GitHub ã¢ããã¤ã¶ãªï¼O365ã¸ã®ä¾µå ¥å¢å ã¨é²å¾¡æ¹æ³ã«ã¤ã㦠注æäºé æ¬è³æã¯ãè±å½ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼(UK National Cyber Security Centre)ã®è³æâAdvisory: The rise of Microsoft Office 365 compromiseâã翻訳ããè³æã§ãã å 容ã«ã¤ãã¦ã¯ãæ大éã®åªåãæã£ã¦æ£ç¢ºã«æãã¦ãã¾ãããæ¬æ¸ã®å 容ã«åºã¥ãéç¨çµæã«ã¤ãã¦ã¯è²¬ä»»ãè² ãããã¾ãã®ã§ããäºæ¿ãã ããã ä»ã®ç¿»è¨³ã¯ããScientia Securtity on GitHubããåç §ãã¦ãã ããã ããã°ã¯ãã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãã®æ¥èªããããåç §ãã¦ãã ããã æ¬ããã¥ã¡ã³ãã«ã¤ã㦠NCSCã¢ããã¤ã¶ãªã¯ãMicrosoft Office 365ã®ä¾µå ¥ã¨ãããããè¦æ¨¡ã®çµç¹ãèæ ®ãã¹ãé²å¾¡
ã³ãã¯ã¿ã¯ãMicrosoft 365 ã¾ã㯠Office 365 organizationã¨ã®éã®ã¡ã¼ã« ããã¼ãã«ã¹ã¿ãã¤ãºããæé ã®ã³ã¬ã¯ã·ã§ã³ã§ãã å®éãã»ã¨ãã©ã® Microsoft 365 ããã³ Office 365 çµç¹ã§ã¯ãé常ã®ã¡ã¼ã« ããã¼ã«ã³ãã¯ã¿ã¯å¿ è¦ããã¾ããã ãã®è¨äºã§ã¯ãã³ãã¯ã¿ãå¿ è¦ã¨ããã¡ã¼ã« ããã¼ã·ããªãªã«ã¤ãã¦èª¬æãã¾ãã ã³ãã¯ã¿ã®ç®çã¯ä½ã§ãã? ã³ãã¯ã¿ã¯ã次ã®ã·ããªãªã§ä½¿ç¨ããã¾ãã ãªã³ãã¬ãã¹ç°å¢ (ãªã³ãã¬ãã¹ã®é»åã¡ã¼ã« ãµã¼ãã¼ã¨ãå¼ã°ãã¾ã) ã«ãã Microsoft 365 ã¾ã㯠Office 365 ã¨é»åã¡ã¼ã« ãµã¼ãã¼éã®ã¡ã¼ã« ããã¼ãæå¹ã«ãã¾ãã Microsoft 365 ã¾ã㯠Office 365 organization ã¨ãã¸ãã¹ ãã¼ããã¼ã¾ãã¯ãµã¼ãã¹ ãããã¤ãã¼ã®éã§éä¿¡ãããé»åã¡ã¼ã«
Office 365ã¯å¤§å¤æ©è½ãå¤ããé²åãéãã§ãã ä¸ã§ãSharePointã¯å·¥å¤«æ¬¡ç¬¬ã§æ§ã ãªäºã«æ´»èºåºæ¥ãåé¢ã ä½ã«ä½¿ã£ã¦è¯ãã®ãè¿·ã£ã¦ãã¾ãã¨ãããããã¾ãã ã¨ãããäºã§ãé·å¹´SharePointãµã¤ãã®æ§ç¯ã«é¢ãã£ã¦ããã¯ã¿ã¯ã·ãçµé¨ããã SharePointã®æ´»ç¨äºä¾ãç´¹ä»ãã¾ãã â» å½è¨äºã§ç´¹ä»ããå 容ã¯ããã¾ã§ç§ã®ä¸»è¦³ã§ãã ã©ã使ãã®ãè¯ãã®ã ç¹ã«å¤ãäºä¾ æ´»ç¨äºä¾ã®ç´¹ä» 社å ãã¼ã¿ã« æ¿èªã»ç³è« ãã®ä» ãªã³ã¯é æ¤ç´¢æ©è½ ä»ã®ãµã¤ãã®æ å ±ãéç´ï¼ãã ãµã¤ãï¼ Excelã§ãªãã¡ãã£ã¦BIï¼ãã¼ã¿ã®è¦ããåï¼ SharePointã«èå³ãåºãã åå¿è åãã®ããã°è¨äº Webãã¼ãä¸è¦§ æ¸ç± ã©ã使ãã®ãè¯ãã®ã ã¢ãã³æ©è½ã®é²åã«åããã¦èãç´ãã¦ã¿ã¾ããã ãã¡ãã®è¨äºãã©ããã www.micknabewata.com ç¹ã«å¤ãäºä¾ ç§ãææ¡ã»æ§ç¯ã«
A screenshot of the fake Office 365 non-delivery notification. (Source: SANS ISC) For the sake of comparison, here's what a legitimate non-delivery notification for Office 365 looks like: A real Office 365 non-delivery notification. As you can see, the real notification provides instructions through which the user can delete out-of-date address information for their contacts before attempting to r
ã365 使ã£ã¦ãããã© ããåããããããããªã®Office 365å°å ¥ãæåã®ã«ã®ã¯âã¢ã³ããµãã¼å¶åº¦âã«ãã£ãï¼å¤æ©è½ããããã¼ã«ã使ãããªãã«ã¯ï¼ï¼1/3 ãã¼ã¸ï¼ æ©è½ãå¤ããã¼ã«ã»ã©ããã®å ¨ã¦ã使ãããªãã®ã¯é£ãããå®¶å ·è²©å£²å¤§æã®ãããªã§ã¯ã2013å¹´ã«Office 365ãå°å ¥ãããã®ã®ãæ©è½ã社å¡ã«ç¥ããã¦ããªããªã©ã®èª²é¡ããã£ããããã§å社ã¯ãã¼ã«ã®æ´»ç¨ãä¿ãã社å ã¢ã³ããµãã¼ããè¨ç½®ã大ããªææãæãã¦ããã¨ããã
ã¯ã©ã¹æé«ã®çç£æ§åä¸ã¢ããªã¨ã¤ã³ããªã¸ã§ã³ããªã¯ã©ã¦ã ãµã¼ãã¹ã®ãææ°ã®æ´æ°æ å ±ãç´¹ä»ãã¾ããMicrosoft 365 ã§çç£æ§ãåèãããã¸ãã¹ ããã»ã¹ãåçåãããã¸ãã¹ãå®ãã¾ãããã
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}