å ã®é¸æéä¼ã§æ¼èª¬ãããã£ãã©å é¦ç¸ï¼ï¼ï¼æ¥ãã¹ãããã¢ã»ããã©/Martin Divisek/EPA-EFE/Shutterstock ï¼ï¼£ï¼®ï¼®ï¼Â ï¼ï¼æ¥ã«ç·é¸æãæ§ãã¦ããã¹ãããã¢ã§ããã·ã¢å¯ãã®ãã£ãã©å é¦ç¸ãçããéå ãä¸è«èª¿æ»ã§ãªã¼ããã¦ãããæ°é¦ç¸ã決ã¾ãã°ãã®ï¼å¹´ã§ï¼äººç®ã¨ãªããã西å´è«¸å½ã¯è¦ææããã£ã¦é¸æã®è¡æ¹ã注è¦ãã¦ããã æ¨å¹´ï¼æã«ãã·ã¢ãã¦ã¯ã©ã¤ãã«ä¾µæ»ãã¦ä»¥æ¥ãã¹ãããã¢ã¯ã¦ã¯ã©ã¤ãã«ã¨ã£ã¦æãå¼·åºãªåçå½ã®ä¸ã¤ã¨ãªã£ã¦ããã両å½ã¯å½å¢ãæ¥ãã¦ãããã¹ãããã¢ã¯çã£å ã«ã¦ã¯ã©ã¤ãã«é²ç©ºã·ã¹ãã ãéã£ããã¾ããåå½ããä½ä¸äººãã®é¿é£è ãåãå ¥ããã ã ãããã£ãã©æ°ãæ¿æ¨©ã®åº§ã«å°±ãã°ããã¯å¤ãããããããªããåæ°ã¯å ¬ç¶ã¨ãã·ã¢ã«å調ãã¦ãããåå½ã®ãã¼ãã³å¤§çµ±é ãã¦ã¯ã©ã¤ãã§ã®æ®å¿ãªæ¦äºãæ£å½åããã®ã«ä½¿ã£ã¦ããå½ãã®ä¸»å¼µãç¹°ãè¿ãããã¼ãã³æ°ãæçºãã¦ä¾µæ»ãã
æ¡ç¨æ å ±ä¼æ¥æ å ±ä¼æ¥æ¦è¦ãããããã¸ã¡ã³ã伿¥ã¨ãã¦ã®è²¬ä»»ãµã¹ããããªãã£ãµã¹ããããªãã£ã®åãçµã¿å»çåã¢ã¯ã»ã¹ãµã¹ããããªãã£æ å ±éç¤ºä¼æ¥å«ç伿¥å«çéææ§ã®ããæ å ±é示ãã¸ã·ã§ã³ãã¼ãã¼ä¼æ¥ãã£ã©ã³ã½ããã¼æ´»åã³ã¼ãã¬ã¼ãã»ã¬ããã³ã¹ã¬ããã³ã¹æ¦ç¥ã¬ããã³ã¹ä½å¶è¦ç¨ã»å ±åæ¸çãµã¤ã¨ã³ã¹éç¹é åç ç©¶éçºãã¤ãã©ã¤ã³è£½å主è¦è£½å製é ã¨å質ãµãã©ã¤ã¤ã¼è¨åºè©¦é¨ï¼æ²»é¨ï¼ç§ãã¡ã®ã¹ãã¼ãªã¼ç§ãã¡ã®ã¹ãã¼ãªã¼ãã¥ã¼ã¹ãã¬ã¹ãªãªã¼ã¹ã¹ãã¼ãã¡ã³ãã¡ãã£ã¢ãªã½ã¼ã¹IRæ å ±æ¦è¦æ±ºç®æ å ±IRã¤ãã³ã IRã«é¢ãããåãåããæ¡ç¨æ å ±
ãããªèª²é¡ã解決ãã¾ã é販ç¨ã®åºå¹¹ã·ã¹ãã ãæ´ããå¨åº«ã顧客ã®ç®¡çãçµ±åããã é販åºå¹¹ã®æ©è½ããã£ã¦ãã¹ãã¼ãã£ã¼ãªECãã¸ãã¹æ¡å¤§ãå³ããã æ°ããæ©è½è¿½å ããã·ã¹ãã 飿ºã«æéããããç¶æ ãä½ã¨ãããã ãªã ããã£ãã«OMSãµã¼ãã¹æ¦è¦ ããªã ããã£ãã«OMSãã¯ãECåºç¤ã®è¦ç´ãã«éããããã¾ã§ãªã³ãã¬ãã¹ã®è¿½å éçºããåå¥ã®ããã±ã¼ã¸è£½åã§å¯¾å¿ãã¦ããåæ³¨ãå¨åº«ç¢ºèªãåºè·çã®ããã¯ã¨ã³ãæ©è½ãæ ãã¢ã¸ã¥ã¼ã«ã§ãããã£ãã«ã®å¤åã«å¯¾å¿ã§ããã·ã¹ãã ãå®ç¾ãã¾ãã
ã¢ã¯ã»ã¹æç¾¤ã®ç¾ããåºå¤§ãªãå½å¶æåè¨å¿µå ¬åãã ãã®ç´ æ´ãããç°å¢ã®å½å¶å ¬åã§ãä»å¹´æå¾ã®ç· ãããã大ä¼ã¨ãã¦æ¥æ¬é¸é£å ¬èªã³ã¼ã¹ãèµ°ããå ¬èªå¤§ä¼ããéå¬ãããã¾ããç®±æ ¹é§ ä¼äºé¸ä¼ä¼å ´ã«ã使ãããç·ããµããæ¨ã ã®ãªããä¸å¨5kmã®ç¹è¨å ¬èªã³ã¼ã¹ãèªåã®ä½åã¨ã¿ã¤ã ã«ææ¦ãã絶好ã®å¤§ä¼ã§ãã ãé¸é£ç»é²ãã®æ¹ããä¸è¬ãã®æ¹ãã大ä¼ã«åºå ´ãããªãå ¬èªå¯©å¤å¡ã®ããæ£ç¢ºãªè·é¢ãèµ°ãå ¬èªå¤§ä¼ï¼å ¬èªã³ã¼ã¹ï¼ã§ãæ£ç¢ºãªè¨é²ããæ®ãã¾ãããã
A stream of malicious npm and PyPi packages have been found stealing a wide range of sensitive data from software developers on the platforms. The campaign started on September 12, 2023, and was first discovered by Sonatype, whose analysts unearthed 14 malicious packages on npm. Phylum reports that after a brief operational hiatus on September 16 and 17, the attack has resumed and expanded to the
A stream of malicious npm and PyPi packages have been found stealing a wide range of sensitive data from software developers on the platforms. The campaign started on September 12, 2023, and was first discovered by Sonatype, whose analysts unearthed 14 malicious packages on npm. Phylum reports that after a brief operational hiatus on September 16 and 17, the attack has resumed and expanded to the
ã¢ããã«ã¯åç¸å ´ã®æ¥è½ãåãã¦æ¥æ¬ã§ãã¡æ©ãiPhoneã®å¤ä¸ãã«è¸ã¿åã£ãããææ°æ©ç¨®ã«ã¯çµ¶å¯¾ã«ã»ããã¨æããããªæ°æ©è½ãåãã£ã¦ããããé«ä¾¡æ ¼ãç½ããã¦æ¶è²»è ãå¼ãçããããªããªã£ã¦ãã¦ããã éå½ã½ã¦ã«ã«æ ç¹ã®ããã«ã¦ã³ã¿ã¼ãã¤ã³ãã®ã¢ããªã¹ãããã ã»ã«ã³æ°ã¯ã¤ã³ã¿ãã¥ã¼ã§ããæ¥æ¬ã®ã¦ã¼ã¶ã¼ã¯ããç¾å®çã«ãªã£ã¦ãããã¨èªã£ãããã½ãã¼ã°ã«ã¼ãããã®ä»ãã©ã³ããå¤å°ä¼¸ã³ã¦ããããã°ã¼ã°ã«ã®ä¼¸ã³ãæãé©ãã¹ããã®ã ãã¨ããã ãã¯ã»ã«ã®ä¼¸é·ã®èæ¯ã«ã¯æããããªãåå®å¹æããããå端æ«ã¯éãããå½ã§ãã販売ããã¦ããããæµ·å¤å¨ä½è ãæ¥æ¬ã§è³¼å ¥ããå ´åãããã¨ãããæ¥æ¬ä»¥å¤ã®è³¼å ¥è ã«ãã¦ã¿ãã°ã30å¹´è¶ ã¶ãã¨ãªãåå®ã«ãã£ã¦ãæ¥æ¬ã¯ãã¯ã»ã«ãæãå®ãè³¼å ¥ã§ããå½ã¨ãªã£ã¦ããã®ã ã ã«ã³æ°ã¯ããæ¥æ¬ããã¯ã»ã«ã®ç©ã¿æ¿ãããã«ãªãã¤ã¤ãããiPhoneãåå®ã«è¦ããåé¢ãã°ã¼ã°ã«ã¯ãã®æ©æµãåã
2023å¹´9æ7æ¥ã«è¨è ä¼è¦ã§ã³ã¡ã³ãããã¸ã£ãã¼ãºäºåææ°ä»£è¡¨åç· å½¹ç¤¾é·ã®æ±å±±ç´ä¹ã¨ãå社é·ã§ä»£è¡¨åç· å½¹ã®è¤å³¶ã¸ã¥ãªã¼æ¯åãPhotoï¼ Tomohiro Ohsumi / Getty Images æ ã¸ã£ãã¼åå¤å·ã«ããæ§å 害åé¡ãæãã¿ã«åºã¦ã伿¥ã®ãã¸ã£ãã¼ãºé¢ãããé²ãã§ããããã®åé¡ã¯æ 人ã«ãã許ããé£ãè¡çºã¨ãã¦ç³¾å¼¾ãç¶ããããã®ä¸æ¹ã§è¦éãããã¦ãããã¨ãããã¨ãè±ç´ããã£ãã³ã·ã£ã«ã»ã¿ã¤ã ãºãã¯ææããã ãç»åãè¦ããã¸ã£ãã¼ãºäºåæã¯å¤ãããã®ãï¼ è¸è½çãæºããããæ§å 害ã¹ãã£ã³ãã«ãæ¥æ¬ã®è¸è½çãæºãããæ§å 害ã¹ãã£ã³ãã«ãåããè¨è ä¼è¦ã§ã56æ³ã®å ç·æ§ã¢ã¤ãã«ã°ã«ã¼ãã¡ã³ãã¼ã¯ãããå°ããããããèªèº«ããã©ã¹ã¡ã³ããããèªèãã¾ãã¯ãã®ãããªææãåãããã¨ã¯ããããã¨ãå½¼ã¯æ¥æ¬ã§æãå½±é¿åã®å¼·ãã¿ã¬ã³ãäºåæã®è²¬ä»»è ã§ããã ãç´æ¥ææãåãããã¨ã¯ããã¾ã
æå¿å£ä½ã¢ã¼ã±ã¼ãã²ã¼ã åç©é¤¨è¨ç»ã¯ãæããã®ã¢ã¼ã±ã¼ãã²ã¼ã ãç¡æã§éã¹ãã¤ãã³ããã9æ23ï½24æ¥ã«ããã¦å¼çççè°·å¸ã§éå¬ããã ã¢ã¼ã±ã¼ãã²ã¼ã åç©é¤¨è¨ç»ã¯ã代表ã®ä¼è¤ããæ°ãä¸å¿ã¨ãããå人ã§ã¢ã¼ã±ã¼ãã²ã¼ã ãææãã13人ã®ã¡ã³ãã¼ãéã¾ãã2012å¹´ããã¿ã¤ãã¼çè°·ãã«å ã®å庫ã§ãååº«éæ¾ãã¨é¡ããä¸è¨ã¤ãã³ããä¸å®æã«éå¬ãã¦ãããåã¡ã³ãã¼ã¯å¤ããããªã²ã¼ã ã®åºæ¿ã ãã§ãªããå人ã§ç®¡çããã®ã¯æ¥µãã¦é£ããããã¤é常ã«è²´éãªå¤§åã®ä½æçä½ï¼ãããããï¼ãè±å¯ã«ã³ã¬ã¯ã·ã§ã³ãã¦ããã ãååº«éæ¾ãã®ä¼å ´ã«ã¯1æ¥ãããç´200äººãæ¥å ´ããçµæ¥å¤§çæ³ã¨ãªã£ããä»åã¯ãCESAï¼ä¸è¬ç¤¾å£æ³äººã³ã³ãã¥ã¼ã¿ã¨ã³ã¿ã¼ãã¤ã³ã¡ã³ãåä¼ï¼ã主å¬ããã²ã¼ã å±ç¤ºã¤ãã³ããTGSï¼æ±äº¬ã²ã¼ã ã·ã§ã¦ï¼ã®é嬿éã¨éãªã£ããã¨ããããTGSã¨ã®æãæã¡ã§ãã£ã¦æ¥ãå¤å½äººå®¢ãããªãç®ç«ã£ãããã ã ã
IT社ä¼ã¨ITã³ã³ãµã«ã¿ã³ã ãã¤ã¦IT(æ å ±æè¡)ã¯ã人éã®ãããã¨ãæ©æ¢°åãããã¨ã«ããçååãéè¦ãªå½¹å²ã§ãããä¼è¨æ¥åã®å 帳å¦çãæ±ºç®æ¥åã®ã·ã¹ãã åãæ¥åã®å¹çåãæ©æåã«å¤§ããªå¹æãä¸ãã¾ããããã¡ãããä»ã§ãçååã¯ã·ã¹ãã åã®éè¦ãªå½¹å²ã§ãããããã仿¥ã®IT(以ä¸ãéä¿¡ãå«ãICTãITã¨ãã¦è¡¨ç¾ãã)ã¯ã大ããé²åããã¸ãã¹ãæ¯ããã¤ã³ãã©ãæ°ãããã¸ãã¹ã¢ãã«ãä½ãä¸ãããã©ãããã©ã¼ã ã«ãªãã¾ããã ITãæ´»ç¨ããªãã§ãã¸ãã¹ãæåãããã¨ã¯ãä¸å¯è½ã¨ãªããITæ´»ç¨ã®æå¦ããã®ã¾ã¾ãã¸ãã¹ã«ç´çµããæä»£ã§ãã ãã®ãããªä¸ã§ãITã³ã³ãµã«ã¿ã³ãã®ãã¸ã·ã§ã³ã確ç«ããéè¦ãªå½¹å²ãã¯ããè·æ¥ã¨ãªãã¾ããã ITã³ã³ãµã«ã¿ã³ãã¨ã¯ã1)IT(æ å ±æè¡)ãã¹ãã«åºç¤ã«ç½®ãã¦ã2)ã客æ§ã®èª²é¡ãçè§£ãã¦è§£æ±ºæ¡ãæè¨ãã3)解決æ¡ã®å®ç¾ãæ¯æ´ãã人ãã§ãã ã客æ§ã¯ãããããã
2020å¹´2æã«Apple社ãã2020å¹´9æ1æ¥ä»¥éã«çºè¡ãããSSLãµã¼ãè¨¼ææ¸ã§ãæå¹æéã398æ¥ãè¶ ããè¨¼ææ¸ãSafariã§ã¯ç¡å¹ã¨ãããã¨ããçºè¡¨ããã°ãã¼ãã«ãµã¤ã³ããã°ã§ç´¹ä»ãã¾ãããæ¬æ¥ã¯ãã®ç¶å ±ãç´¹ä»ãã¾ãã ãã®å¾ããã©ã¦ã¶ãã³ãã¼ã®ã¢ãã¦ã³ã¹ CA/Browser Forumã§ã¯ãSSLãµã¼ãè¨¼ææ¸ã®æå¹æéã398æ¥æªæºã¨ãããåºæ¬ã«ã¼ã«(Baseline Requirements)ãçãè¾¼ããããæç¥¨ã«åããè°è«ãéãã¦ããæä¸ã§ããã2020å¹´6æ23æ¥ã«ãªã³ã©ã¤ã³ä¼åã®å ´ã§ãGoogleãMozillaãç¸æ¬¡ãã§Appleã®ã¢ãã¦ã³ã¹ã«åæããããã¡ã§ã9æ1æ¥ä»¥éã«çºè¡ãããSSLãµã¼ãè¨¼ææ¸ã§ã398æ¥ãè¶ ããè¨¼ææ¸ã¯ç¡å¹åãããã¨ãã¢ãã¦ã³ã¹ãã¾ããã ããã¯ãCA/Browser Forumã®Baseline Requirementsã®è¦ä»¶ã«ããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}