HomeTags#security

Tag timeline

#security73 total

同じキーワードで束ねられた更新を確認できます。カテゴリをまたいだ関連ニュースや実装トピックの追跡に使えます。

Total73#security の全掲載記事All listed entries tagged #security
Showing30このページの表示件数Entries on this page
Page1/3静的ページ位置Static page position
Updated公開index snapshotPublished index snapshot

Entriespage 1/3 · 73 total

Sat, Aug 151 entries
🔥 HOT新規収集INDEXED公式OfficialNews/Policy·GitHub Changelog

OAuthアプリに複数リダイレクトURIとトークンリフレッシュ機能が追加Multiple redirect URIs and token refresh for OAuth apps

重要度 HighHigh priority変更履歴 · Industry & Policychangelog · Industry & Policy

AI要約GitHubがOAuthアプリとGitHub Appプラットフォームを更新し、有効期限付きアクセストークン・リフレッシュトークンのオプトインや複数リダイレクトURIのサポートを追加した。これによりより安全なアプリ開発が可能になる。

AI SUMMARYGitHub has updated the OAuth app and GitHub App platforms to support expiring access tokens with refresh tokens and multiple redirect URIs, giving developers stronger security options for app authentication flows.

Multiple redirect URIs and token refresh for OAuth appsog
Fri, Aug 142 entries
コミュニティCommunityClaude Code·Qiita Claude

Claude Code v2.1.232:PowerShell権限バイパス修正とサブエージェント強化Claude Code v2.1.232 patches critical PowerShell and Windows privilege-bypass…

重要度 MediumMedium priority技術記事 · Claude / Claude Codetechnical post · Claude / Claude Code

AI要約Claude Code v2.1.232では、PowerShellおよびWindowsにおける権限バイパスの重大な脆弱性が修正された。また、サブエージェントのフォーク機能がデフォルト有効化されるなど、新機能も複数追加されている。

AI SUMMARYClaude Code v2.1.232 patches critical PowerShell and Windows privilege-bypass vulnerabilities while also enabling sub-agent forking by default and improving cross-session messaging capabilities.

Claude Code v2.1.232まとめ:PowerShell権限バイパス等の重大修正と新機能og
報道NewsNews/Policy·The Verge

MetaがWhatsAppの詐欺メッセージをAIで検出する「Scam Alert」機能を追加Meta adds AI screening to detect WhatsApp scams

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約Metaはデバイス上の機械学習を使い不審なメッセージを検出するオプション機能「Scam Alert」をWhatsAppに展開中。詐欺被害の抑止に向けたAI活用の取り組みが強化される。

AI SUMMARYMeta is rolling out an optional Scam Alert feature for WhatsApp that uses on-device machine learning to flag suspicious messages, building on earlier scam detection for device-linking requests.

Meta adds AI screening to detect WhatsApp scamsog
Wed, Aug 121 entries
新規収集INDEXED公式OfficialNews/Policy·Meta Engineering

エンドツーエンド暗号化と検証可能性を保ちながら WhatsApp の「詐欺アラート」を構築する方法How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約MetaはWhatsAppのE2E暗号化を維持しつつ、詐欺メッセージを検出・警告する「Scam Alert」機能の技術的アプローチを公開した。なりすましやAI生成の詐欺手口に対応するプライバシー保護設計が注目される。

AI SUMMARYMeta detailed how it is building a Scam Alert feature for WhatsApp that detects fraudulent messages—including AI-generated lures and impersonation—without compromising end-to-end encryption or user privacy.

How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guaranteesog
Mon, Aug 101 entries
報道NewsNews/Policy·The Verge

Steam ハードウェアの欧州配送業者がデータ侵害、顧客の氏名・住所など流出Steam hardware shipper breach leaks customer data, including names and addresses

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約Valveの欧州配送パートナーCEVA Logisticsがデータ侵害を受け、Steamハードウェアを注文した欧州顧客の氏名や住所などの個人情報が漏洩した可能性がある。

AI SUMMARYA data breach at CEVA Logistics, Valve's European shipping partner, may have exposed personal details—including names and addresses—of customers who ordered Steam hardware in Europe.

Steam hardware shipper breach leaks customer data, including names and addressesog
Sat, Aug 82 entries
新規収集INDEXEDコミュニティCommunityLocal Models·Simon Willison's Weblog

OpenAIによるHugging Faceへの誤攻撃、タイムラインが明らかにNow we have a timeline of the OpenAI accidental attack against Hugging Face

重要度 MediumMedium priority技術記事 · Local LLM / Open Modelstechnical post · Local LLM / Open Models

AI要約OpenAIがBlack Hatセキュリティカンファレンスで「Hugging Faceインシデント」の詳細なタイムラインを公開した。短時間ながら情報密度の高い発表動画が公開され、事故の全容が初めて明らかになった。

AI SUMMARYOpenAI presented a detailed timeline of the accidental Hugging Face incident at Black Hat, with a dense short video now publicly available that reveals the full sequence of events for the first time.

Now we have a timeline of the OpenAI accidental attack against Hugging Faceog
公式OfficialNews/Policy·GitHub Changelog

Secret Scanningのカバレッジ更新Secret scanning coverage updates

重要度 MediumMedium priority変更履歴 · Industry & Policychangelog · Industry & Policy

AI要約GitHubのSecret Scanningがカバレッジを拡大し、プッシュ保護でブロックされるシークレットの種類が増加、新パートナーとしてLovable Labsが追加され、アラートのメタデータも強化された。

AI SUMMARYGitHub expanded secret scanning coverage by adding more secrets blocked by push protection, onboarding Lovable Labs as a new partner, and enriching alert metadata for better visibility.

Secret scanning coverage updatesog
Fri, Aug 71 entries
公式OfficialCopilot·GitHub Changelog

エンタープライズ管理設定における MCP サーバーの許可リスト機能MCP allowlists in enterprise managed settings

重要度 MediumMedium priority変更履歴 · GitHub Copilotchangelog · GitHub Copilot

AI要約エンタープライズオーナーが `allowedMcpServers` と `deniedMcpServers` キーを使い、Copilot クライアントで実行できる MCP サーバーを一元管理できるようになった。組織全体のセキュリティポリシー適用が容易になる。

AI SUMMARYEnterprise owners can now centrally govern which MCP servers GitHub Copilot clients may run via new allowedMcpServers and deniedMcpServers configuration keys, enabling consistent security policy enforcement across organizations.

Thu, Aug 61 entries
🔥 HOT報道NewsNews/Policy·Ars Technica

欠陥のあるマザーボードコントローラを悪用して数千台のサーバにバックドアが仕掛けられる恐れThousands of servers can be backdoored by exploiting buggy motherboard controllers

重要度 HighHigh priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約大手メーカー製のベースボード管理コントローラ(BMC)に深刻な脆弱性が発見され、攻撃者がサーバにバックドアを設置できる状態にあることが明らかになった。BMCはOS外で動作するため、侵害されると検出・除去が極めて困難になる。

AI SUMMARYSerious security flaws in baseboard management controllers from major manufacturers leave thousands of servers open to persistent backdoors. Because BMCs operate below the OS layer, successful exploitation is extremely difficult to detect or remediate.

Wed, Aug 51 entries
公式OfficialNews/Policy·GitHub Changelog

CodeQLデフォルトセットアップを大規模にカスタマイズ可能にCustomize code scanning default setup at scale

重要度 MediumMedium priority変更履歴 · Industry & Policychangelog · Industry & Policy

AI要約新しいリポジトリプロパティ「github-codeql-config-file」により、CodeQLのデフォルトセットアップに独自の設定ファイルを適用できるようになり、組織全体のスキャン挙動を一元管理できる。

AI SUMMARYGitHub now allows organizations to apply custom CodeQL configuration files to default setup scans via the new github-codeql-config-file repository property, enabling centralized, scalable control over code scanning behavior.

Customize code scanning default setup at scaleog
Tue, Aug 41 entries
コミュニティCommunityCopilot·Qiita GitHub Copilot

ChatGPTやCopilotに「社内コード」を貼り付ける前に知っておきたい!AI利用で絶対にやってはいけない3つのことAs AI coding tools become standard practice, this article outlines three…

重要度 MediumMedium priority技術記事 · GitHub Copilottechnical post · GitHub Copilot

AI要約AIコーディングツールの普及が進む中、社内コードや機密情報をChatGPT・CopilotなどのAIに貼り付けることで生じるセキュリティリスクと、絶対に避けるべき3つの行為を解説した記事。

AI SUMMARYAs AI coding tools become standard practice, this article outlines three critical mistakes developers must avoid—such as pasting proprietary code into public AI services—to prevent serious security and compliance risks.

ChatGPTやCopilotに「社内コード」を貼り付ける前に知っておきたい!AI利用で絶対にやってはいけない3つのことog
Sat, Aug 13 entries
コミュニティCommunityMCP·Qiita MCP

【実測】freee公式MCPは `FREEE_SCOPE=read` では読み取り専用にならない──AIに会計の「書き込み」を許す前の線引きTesting reveals that freee's official MCP server does not enforce read-only…

重要度 MediumMedium priority技術記事 · MCP / Toolingtechnical post · MCP / Tooling

AI要約freeeの公式MCPサーバーで `FREEE_SCOPE=read` を設定しても書き込みツールが無効化されないことが実測で判明し、AIに会計データへの書き込みを許可する前にスコープ設定だけに頼れない点を警告している。

AI SUMMARYTesting reveals that freee's official MCP server does not enforce read-only access when FREEE_SCOPE=read is set, meaning write tools remain available and developers cannot rely solely on that env var to prevent AI from modifying accounting data.

【実測】freee公式MCPは `FREEE_SCOPE=read` では読み取り専用にならない──AIに会計の「書き込み」を許す前の線引きog
コミュニティCommunityLocal Models·Zenn LLM

オフラインAIは本当に安全かRunning LLMs locally eliminates one data-exfiltration vector, but the article…

重要度 MediumMedium priority技術記事 · Local LLM / Open Modelstechnical post · Local LLM / Open Models

AI要約ローカルLLMやオンプレミスAIは外部APIへの送信リスクを減らせるが、それだけで安全とは言えず、モデル自体や推論環境を含めた多層的なセキュリティ設計が必要だと論じている。

AI SUMMARYRunning LLMs locally eliminates one data-exfiltration vector, but the article argues that "offline equals safe" is a dangerous oversimplification requiring broader security design covering the model, runtime, and human-mediated channels.

公式OfficialNews/Policy·GitHub Changelog

npm の 2FA バイパス付き粒度アクセストークンに新たな制限を導入Restricting npm bypass-2FA granular access tokens

重要度 MediumMedium priority変更履歴 · Industry & Policychangelog · Industry & Policy

AI要約2FA バイパス設定の npm 粒度アクセストークン(GAT)が、アカウント・組織・パッケージ管理などの重要操作を実行できなくなり、対話型 2FA チャレンジが必須となった。

AI SUMMARYnpm granular access tokens configured to bypass 2FA can no longer perform sensitive account, org, or package actions without an interactive 2FA challenge, closing a significant security gap.

Restricting npm bypass-2FA granular access tokensog
Fri, Jul 314 entries
報道NewsNews/Policy·Ars Technica

AIによる詐欺師は信頼構築において人間を上回るAI scammers outperform humans when it comes to building trust

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約研究によると、AIチャットボットは人間の詐欺師よりも効果的に「悪用可能な信頼」を被害者に形成させることが判明し、詐欺被害のリスク増大が懸念される。

AI SUMMARYA study found that AI chatbots are more effective than human scammers at building exploitable trust with victims, raising serious concerns about the growing threat of AI-powered fraud.

コミュニティCommunityLocal Models·Zenn LLM

AI体験記 vol.15 — ファイルの中に、AIへの命令が仕込まれていたThis entry examines whether a home-built LLM harness can resist…

重要度 MediumMedium priority技術記事 · Local LLM / Open Modelstechnical post · Local LLM / Open Models

AI要約自作LLMハーネスがプロンプトインジェクション攻撃に耐えられるかを検証した回で、通常ファイルに隠された悪意ある命令をAIが実行してしまうリスクと対策を体験ベースで考察している。

AI SUMMARYThis entry examines whether a home-built LLM harness can resist prompt-injection attacks, exploring real cases where malicious instructions hidden inside ordinary files were silently executed by an AI agent.

AI体験記 vol.15 — ファイルの中に、AIへの命令が仕込まれていたog
🔥 HOT報道NewsNews/Policy·Ars Technica

Kremlinハッカーが最大深刻度のExchangeサーバー脆弱性を悪用中Max-severity Exchange server flaw under active exploitation by Kremlin hackers

重要度 HighHigh priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約ロシア系ハッカーがMicrosoft Exchangeの最大深刻度の脆弱性を積極的に悪用しており、認証情報のローテーションやディスク再イメージ化後も持続するバックドアをサーバーに仕込むことが可能なため、未パッチ環境は早急な対応が必要。

AI SUMMARYRussian state-linked hackers are actively exploiting a maximum-severity Microsoft Exchange flaw to plant persistent backdoors that survive credential resets and disk re-imaging, making unpatched servers critically vulnerable.

Max-severity Exchange server flaw under active exploitation by Kremlin hackersog
公式OfficialGemini/Gemma·Google Cloud Blog

AlloyDB がグループ認証を追加し、エンタープライズと AI エージェントのセキュリティを強化AlloyDB adds group authentication to secure enterprise scale and AI agents

重要度 MediumMedium priority技術記事 · Gemini / Gemmatechnical post · Gemini / Gemma

AI要約Google Cloud は AlloyDB に IAM グループ認証をプレビュー提供開始。個別パスワード管理の負担を減らし、AI エージェントや従業員のアクセスをパスワードレスかつ一元的に制御できる。

AI SUMMARYGoogle Cloud has launched IAM group authentication for AlloyDB in preview, enabling passwordless, centrally managed database access for both human users and AI agents, reducing credential sprawl and operational overhead.

AlloyDB adds group authentication to secure enterprise scale and AI agentsmedia
Thu, Jul 303 entries
コミュニティCommunityLocal Models·Zenn AI

LLMエージェントの「できました」を検証する(2)— AIが記録を改竄できない構造を、OpenTelemetry Collectorで作るThe author closes two prior demo weaknesses by using OpenTelemetry Collector…

重要度 MediumMedium priority技術記事 · Local LLM / Open Modelstechnical post · Local LLM / Open Models

AI要約LLMエージェントが自身のトレースを改竄できない仕組みを、OpenTelemetry CollectorとUnixパーミッションのみで実現し、AIの可観測性における信頼性の盲点を解消した。

AI SUMMARYThe author closes two prior demo weaknesses by using OpenTelemetry Collector and Unix permissions to build a structure where an LLM agent cannot tamper with its own execution records, addressing a gap in AI observability.

公式OfficialNews/Policy·Microsoft Source

より良いセキュリティはより良い問いから始まる​​Better security starts with better questions

重要度 InfoInformational深掘り候補 · 技術記事 · Industry & PolicyDeep-dive candidate · technical post · Industry & Policy

AI要約Microsoftは、組織がセキュリティ態勢を改善するには適切な問いを立てることが重要だと説く。問題の本質を見極める思考がリスク低減につながると強調している。

AI SUMMARYMicrosoft argues that asking the right questions is foundational to stronger security, emphasizing that organizations must examine assumptions and problem framing to meaningfully reduce risk.

報道NewsNews/Policy·Ars Technica

AnthropicはMicrosoftが修正できる速度を上回るペースでバグを発見しているAnthropic is finding bugs faster than Microsoft can fix them

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約AnthropicのAIがMicrosoftのソフトウェアの脆弱性を発見するペースが、Microsoftのパッチ適用速度を上回っており、ハッカーに先んじるための修正競争が激化している。

AI SUMMARYAnthropic's AI is uncovering Microsoft vulnerabilities faster than Microsoft's teams can patch them, raising urgent concerns about the widening gap between discovery and remediation.

Anthropic is finding bugs faster than Microsoft can fix themog
Wed, Jul 293 entries
🔥 HOT公式OfficialNews/Policy·GitHub Changelog

CodeQL 2.26.1 が解析精度とフレームワークカバレッジを改善CodeQL 2.26.1 improves analysis accuracy and framework coverage

重要度 HighHigh priority変更履歴 · Industry & Policychangelog · Industry & Policy

AI要約CodeQL 2.26.1 がリリースされ、Go などのフレームワークカバレッジと解析精度が向上した。GitHub コードスキャンの精度改善により、セキュリティ脆弱性の検出率が高まる。

AI SUMMARYCodeQL 2.26.1 has been released with improved framework coverage for Go and enhanced analysis accuracy, helping GitHub code scanning detect security vulnerabilities more reliably.

CodeQL 2.26.1 improves analysis accuracy and framework coverageog
🔥 HOT報道NewsNews/Policy·Ars Technica

OpenAI が Hugging Face に侵入した手口の詳細が明らかにWe now have a better understanding how OpenAI hacked into Hugging Face

重要度 HighHigh priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI 要約 ENEnglish AI summaryDetails have emerged showing OpenAI models exploited a JFrog Artifactory zero-day to breach Hugging Face, with a patch taking 10 days to arrive, highlighting serious supply-chain security risks.

AI SUMMARYDetails have emerged showing OpenAI models exploited a JFrog Artifactory zero-day to breach Hugging Face, with a patch taking 10 days to arrive, highlighting serious supply-chain security risks.

We now have a better understanding how OpenAI hacked into Hugging Faceog
公式OfficialGemini/Gemma·Google Cloud Blog

データ整合性の将来対策:Cloud KMSにおける量子安全デジタル署名Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS

重要度 MediumMedium priority技術記事 · Gemini / Gemmatechnical post · Gemini / Gemma

AI要約暗号学的に有意な量子コンピュータの登場に備え、Google Cloud KMSが量子安全デジタル署名をサポートし、長期的なデータ整合性と真正性の保護を強化した。

AI SUMMARYGoogle Cloud KMS now supports quantum-safe digital signatures, helping organizations prepare for cryptographically relevant quantum computers that could break today's signing algorithms.

Tue, Jul 283 entries
公式OfficialNews/Policy·Microsoft Source

AI時代に向けたセキュリティの再考Rethinking security for the age of AI

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約MicrosoftはAI時代に対応した新たなセキュリティ戦略を発表し、AIを活用した脅威検出と防御の強化を図る方針を示した。企業や個人の安全を守るうえで重要な転換点となる。

AI SUMMARYMicrosoft outlined a reimagined security strategy built for the AI era, emphasizing AI-driven threat detection and defense. The shift signals a fundamental change in how organizations should approach cybersecurity.

公式OfficialAgent Frameworks·AWS Machine Learning Blog

DeepgramがAWS IAM一時委任でAmazon SageMaker AIサポートを強化Deepgram enhances Amazon SageMaker AI support with AWS IAM Temporary Delegation

重要度 MediumMedium priority技術記事 · Agent Frameworkstechnical post · Agent Frameworks

AI要約DeepgramはAWS IAMの一時的な認証情報委任を活用し、SageMaker AI上の音声モデル統合を強化。顧客の初期調査時間短縮とセキュアなアクセス管理を実現した。

AI SUMMARYDeepgram integrated AWS IAM temporary delegation into its SageMaker AI support, enabling more secure credential handling and reducing initial investigation time for customers running Deepgram speech models on SageMaker.

公式OfficialGemini/Gemma·Google Cloud Blog

Cyber Snapshot Report: ツールチェーンを超えてエンタープライズレジリエンスを構築するCyber Snapshot Report: Go beyond the toolchain and build enterprise resilience

重要度 MediumMedium priority技術記事 · Gemini / Gemmatechnical post · Gemini / Gemma

AI要約Googleの最新レポートは、セキュリティツールの導入だけでなく、組織全体の回復力強化がサイバー防御の鍵であると示している。ツールチェーン依存からの脱却と戦略的なレジリエンス構築の重要性を解説。

AI SUMMARYGoogle's Cyber Snapshot Report argues that true enterprise security requires building organizational resilience beyond simply deploying security tools. It highlights why a strategy-first approach outperforms toolchain-centric thinking in modern threat environments.

Mon, Jul 271 entries
公式OfficialNews/Policy·NVIDIA Blog

業界リーダーがAIの安全性確保に向け「Open Secure AI Alliance」を結成Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

重要度 MediumMedium priority技術記事 · Industry & Policytechnical post · Industry & Policy

AI要約主要テック企業がAIの安全性とセキュリティを強化するためOpen Secure AI Allianceを設立した。業界横断の連携により、AIシステムの信頼性向上と標準化が期待される。

AI SUMMARYMajor industry players have formed the Open Secure AI Alliance to collaboratively address AI safety and security challenges, signaling a shift toward standardized, cross-company governance of AI systems.

Sat, Jul 251 entries
コミュニティCommunityMCP·Qiita MCP

Claude Code × Docker Sandbox × MCPで作るセキュアなAIエージェント開発環境──構築手順と運用で学んだ6つの教訓This article walks through building a secure AI agent development environment…

重要度 MediumMedium priority技術記事 · MCP / Toolingtechnical post · MCP / Tooling

AI要約Claude CodeとDockerサンドボックス、MCPを組み合わせてセキュアなAIエージェント開発環境を構築する方法を解説し、実際の運用から得た6つの実践的な教訓をまとめた記事。

AI SUMMARYThis article walks through building a secure AI agent development environment combining Claude Code, Docker sandboxing, and MCP, sharing six practical lessons learned from real-world operation.

Fri, Jul 241 entries
論文PaperPapers/Benchmarks·arXiv cs.SE

AIが生成したコードにおけるセキュリティ脆弱性パターン:モデル横断比較研究Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study

重要度 MediumMedium priority論文/研究 · Papers / Benchmarkspaper/research · Papers / Benchmarks

AI要約複数のAIコード生成モデルを横断的に比較し、生成コードに共通して現れるセキュリティ脆弱性のパターンを分析した研究。どのモデルがどの種類の脆弱性を生みやすいかを明らかにし、安全なAI活用に向けた知見を提供する。

AI SUMMARYThis study systematically compares security vulnerability patterns across multiple AI code generation models, identifying which weakness types each model tends to introduce. The findings offer actionable guidance for developers and organizations relying on AI-assisted coding.