<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Cyber Intelligence Review</title>
  <link>https://cir.ai-bpo.net/</link>
  <description>経営課題として注目すべきAIとランサムウェアのインシデントについて図解レポートで解説します。</description>
  <language>ja</language>
  <atom:link href="https://cir.ai-bpo.net/rss.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>EchoLeak：メール1通で Copilot が社内データを漏らした経路——AI 固有の欠陥と、ありふれた実装漏れの合流点</title>
    <link>https://cir.ai-bpo.net/articles/echoleak/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/echoleak/</guid>
    <description>EchoLeak（CVE-2025-32711）は、メール1通で M365 Copilot から社内データを持ち出せたゼロクリック脆弱性。LLM スコープ違反という概念、4段の攻撃チェーン、Microsoft と NVD で割れた深刻度評価まで、一次情報と照合して整理する。</description>
    <category>AI セキュリティ</category>
    <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>LAMEHUG：LLM を積んだ初のマルウェア——ただし、実行時に作られていたのはコマンドであってプロンプトではない</title>
    <link>https://cir.ai-bpo.net/articles/lamehug/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/lamehug/</guid>
    <description>LAMEHUG は LLM を組み込んだ初のマルウェアとされる。だが実行時に生成されているのはコマンドであってプロンプトではない。CERT-UA と Cato CTRL の一次情報を照合し、LLM 統合が実際に何をもたらしたのかを検証する。</description>
    <category>AI セキュリティ</category>
    <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>PromptLock：「初の AI 駆動型ランサムウェア」の正体は、大学の研究プロトタイプだった</title>
    <link>https://cir.ai-bpo.net/articles/promptlock/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/promptlock/</guid>
    <description>ESET が発見した「初のAI駆動型ランサムウェア」PromptLock の正体は、NYU Tandon の研究プロトタイプ Ransomware 3.0 だった。ESET の初報・9月3日の追記・NYU の発表を照合し、何が誤認され何が誤認されなかったのかを整理する。</description>
    <category>ランサムウェア</category>
    <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Claude が暗号アルゴリズムの数学的弱点を発見した——その中身と、しなかったこと</title>
    <link>https://cir.ai-bpo.net/articles/crypto-weaknesses/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/crypto-weaknesses/</guid>
    <description>Claude Mythos Preview による HAWK とラウンド削減版 AES への攻撃発見。一次情報と照合したファクト台帳に基づく図解解説。実務影響、自律性の実態、検証コストの逆転までを整理。</description>
    <category>AI セキュリティ</category>
    <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>評価環境の隔離不備により、AIモデルが実在3組織のシステムへ侵入した事象</title>
    <link>https://cir.ai-bpo.net/articles/cybersecurity-eval-incidents/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/cybersecurity-eval-incidents/</guid>
    <description>Anthropic のサイバーセキュリティ評価で発生した3件の実世界インシデントの図解解説(経営層向け)</description>
    <category>AI セキュリティ</category>
    <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>JADEPUFFER：LLM が駆動したとされるランサムウェア——何が観測され、何が分からなかったか</title>
    <link>https://cir.ai-bpo.net/articles/jadepuffer/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/jadepuffer/</guid>
    <description>Sysdig が報告したエージェント型ランサムウェア JADEPUFFER。一次情報と照合したファクト台帳に基づく図解解説。攻撃の流れ、エージェント性を支える4つの証拠、判別できなかった論点まで整理。</description>
    <category>ランサムウェア</category>
    <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>サイバー能力評価中のAIエージェントが、3者のインフラを横断して Hugging Face 本番環境に到達した事象</title>
    <link>https://cir.ai-bpo.net/articles/openai-hugging-face-eval-intrusion/</link>
    <guid isPermaLink="true">https://cir.ai-bpo.net/articles/openai-hugging-face-eval-intrusion/</guid>
    <description>サイバー能力評価中のAIエージェントが3者のインフラを横断し Hugging Face 本番環境に到達した事象を、OpenAI・Hugging Face・JFrog の公表資料から図解で整理（経営層向け・調査継続中の暫定情報）</description>
    <category>AI セキュリティ</category>
    <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
  </item>
</channel>
</rss>
