èå¼±æ§
ç 究éçºé¨ ç 究éçºæ å½ã®ä¿è¦ (@takahoyo) ã§ãã ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºã§ã¯ã2023年度ã«å¼ãç¶ããç¾å ´åãå ¥ãåã¤ã³ã¿ã¼ã³ã·ããããå®æ½ãã¾ããã 2023年度ã®æ¨¡æ§ blog.nflabs.jp blog.nflabs.jp 2024年度ã®ä»ãã¼ã ã§ã®ã¤ã³ã¿ã¼ã³ã·ããã®æ¨¡æ§â¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®é½è¤ã§ãããã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ 14 æ¥ç®ã®è¨äºã§ãã æ®æ®µã¯ Blue Team ã®ä¸ã§å©ç¨ããã·ã¹ãã ã®éçºããã¦ãã¾ãã ç§ã¯ä»ã®ãã¼ã 㧠DevSecOps ã®ä»çµã¿ããã¼ã«ãè²ã ã¨è©¦ãã¦å°å ¥ãé²ãã¦ããæä¸â¦
ããã«ã¡ã¯ãNFLabs. Offensive Teamã®é¿é¨ã§ãã 10/5 (ç«) ã«ãç¹å®ã®è¨å®ããªããã¦ããApache HTTP Server (以å¾Apache) 2.4.49ã®ç°å¢ã«ããã¦ãªã¢ã¼ãããã³ã¼ãå®è¡ (RCE) ãå¯è½ãªèå¼±æ§ï¼CVE-2021-41773ï¼ãçºè¦ããã¾ããã ããã«ããã®èå¼±æ§ãå¡â¦