Tomo
banner
tomo.gr
Tomo
@tomo.gr
某大企業のCSIRTやってる人
主にセキュリティ、たまにゲーム(WoW)

I am in charge of leader of a certain global trading company's CSIRT/SOC team. Registered Information Security Specialist in Japan.
Cyber Security and/or World of Warcraft
Reposted by Tomo
MSIgniteがAI一色。

セキュリティで小規模MSSPが生き残れる未来が想像できなくなったのでキャリアチェンジすべきか真剣に悩み中
November 18, 2025 at 7:35 PM
a SQL query なのか an SQL queryなのか。みんなはどっち?
September 28, 2025 at 2:05 PM
Reposted by Tomo
In what is being called the largest supply chain attack in history, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising maintainers' accounts in a phishing attack.
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
In what is being called the largest supply chain attack in history, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising maintainers' accounts in a phishing attack.
www.bleepingcomputer.com
September 8, 2025 at 4:48 PM
Reposted by Tomo
A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys.
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys.
www.bleepingcomputer.com
September 8, 2025 at 7:54 PM
Reposted by Tomo
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
thehackernews.com
July 11, 2025 at 4:01 PM
Reposted by Tomo
Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address
Let's Encrypt Started to Issue SSL/TLS Certificate for IP Address
cybersecuritynews.com
July 3, 2025 at 1:17 PM
Reposted by Tomo
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign
thehackernews.com
June 27, 2025 at 4:31 PM
参加してきました
ウクライナCERT人気だった
June 27, 2025 at 10:48 PM
Reposted by Tomo
Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors
Scattered Spider hackers shift focus to aviation, transportation firms
Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors
www.bleepingcomputer.com
June 27, 2025 at 6:21 PM
今月のアレにコペンハーゲン行く人いるだろうか
June 15, 2025 at 11:56 AM
思いっきり色々使える、おうちサーバーになりそう
(TRとかXeonではないので、小規模だけど)
April 26, 2025 at 9:13 AM
Reposted by Tomo
According to Ransomware.live, qilin ransomware group has added SMC Corporation (🇯🇵) to its victims.
March 17, 2025 at 9:38 AM
Reposted by Tomo
🚨Cyberattack Alert ‼️

🇪🇺🇯🇵 - SMC Corporation

Qilin hacking group claims to have breached the European branch of SMC Corporation.

Allegedly, 1.1 TB (552,000 files) of data were exfiltrated.
March 17, 2025 at 10:06 AM
Reposted by Tomo
CVE-2025–24813: Apache Tomcat Path Equivalence Vulnerability $$ BOUNTY
CVE-2025–24813: Apache Tomcat Path Equivalence Vulnerability $$$$ BOUNTY
Disclaimer: This document is for educational purposes only. Exploiting systems without authorization is illegal and punishable by law.
infosecwriteups.com
March 16, 2025 at 6:07 AM
某大使館でのイベントに参加
日本のはずなのにそこは完全に欧州だった。
March 8, 2025 at 5:13 AM
イギリスのロンドンにある
バターシーパワーステーション…廃火力発電所をショッピングモールにしちゃったもの。外の迫力と中がモダンなモールで驚いた。
March 8, 2025 at 5:10 AM
今回の出張、ほぼ全ての支払いをカードで済ませてポンドに至っては1ポンドも持ってかなかった
February 28, 2025 at 5:15 AM
1週間かけて、オランダ/イギリス出張。帰りはフランス経由だったので空港散策に入出国だけつけた
February 28, 2025 at 4:52 AM
Reposted by Tomo
公開された ASP.NET マシン キーを使用したコード インジェクション攻撃
#CybersecurityNews
www.microsoft.com/en-us/securi...
Code injection attacks using publicly disclosed ASP. NET machine keys
Microsoft Threat Intelligence observed limited activity by an unattributed threat actor using a publicly available, static ASP.NET machine key to inject malicious code and deliver the Godzilla post-ex...
www.microsoft.com
February 6, 2025 at 11:57 PM
Reposted by Tomo
NVIDIA GPU Display Driver Vulnerability Lets Attackers Steal Files Remotely – Update Now
NVIDIA GPU Display Driver Vulnerability Lets Attackers Steal Files Remotely - Update Now
NVIDIA has released a critical software security update to address multiple vulnerabilities affecting its GPU Display Driver and Virtual GPU (vGPU) software.
cybersecuritynews.com
February 3, 2025 at 11:19 AM
Reposted by Tomo
詐欺に注意: YouTube 上の偽の Minecraft、Roblox ハックにマルウェア隠蔽、子供がターゲットに
#CybersecurityNews
www.mcafee.com/blogs/intern...
www.mcafee.com
February 2, 2025 at 3:44 AM