#security
- SynthID-Text
- CEL (Common Expression Language)
- Rego(ポリシー言語)
- Packslip
- aqua
- trusting trust攻撃
- サプライチェーン攻撃
- stripを運び屋にしたtrusting trust攻撃
- Kubernetesのrootless mode (KubeletInUserNamespace)
- 透明性ログ (transparency log)
- タイルベースの透明性ログ
- AI時代の脆弱性エンバーゴ
- SBOM (Software Bill of Materials)
- Log4Shell (CVE-2021-44228)
- in-toto
- DSSE (Dead Simple Signing Envelope)
- Certificate Transparency (CT)
- VEX (Vulnerability Exploitability eXchange)
- TUF (The Update Framework)
- SLSA (Supply-chain Levels for Software Artifacts)
- Sigstore
- Wolfi
- OWASP(Open Worldwide Application Security Project)
- OpenSSF (Open Source Security Foundation)
- distroless
- Chainguard
- Cilium
- Cedar(ポリシー言語)
- TPM(Trusted Platform Module)
- systemd-creds
- Project Glasswing
- パストラバーサル
- OWASP Top 10
- デコードしてから正規化する
- cohttpのパストラバーサル脆弱性 (2026)
- gVisor
- NHI(Non-Human Identity)
- AIエージェント向けタスクスコープ認証情報
- TLSフィンガープリンティング
- vlt (vōlt)
- 大阪急性期・総合医療センターランサムウェア事案(2022年)
- 小島プレス工業ランサムウェア事案(2022年)
- 国内ランサムウェア被害事例
- arrayref Rustクレート ビルド時マルウェア混入事件(2026年)
- WEP
- aircrack-ng
- RC4
- Dogwood(ポリシー言語)
- AIエージェント時代のAPI認可ガバナンス
- PAM(Privileged Access Management)
- フィッシング耐性MFA(Phishing-Resistant MFA)
- MFA(Multi-Factor Authentication、多要素認証)
- IAM/アクセス管理(Identity and Access Management)
- Let's Encrypt
- Gungnir
- CTログ監視・検索ツール
- crt.sh
- CertStream
- Landlock
- Yama (Yama LSM)
- IDOR(Insecure Direct Object Reference)
- BOLA(Broken Object Level Authorization)
- AIエージェントによるジム予約システム侵害事件(2026年8月)
- scrypt
- PBKDF2
- Password Hashing Competition
- パスワードハッシュアルゴリズム
- bcrypt
- Argon2id
- strace
- ptrace
- ptraceされているプロセスはsetuidの昇格が無効化される
- Linuxの権限分離・権限昇格の仕組み
- UNIXのユーザーID(UID)モデル
- setuid / setgid
- seccomp
- polkit
- LSM (Linux Security Modules) フレームワーク
- Linux capabilities
- 最小権限の原則
- Bubblewrap (bwrap)
- QRコードフィッシング (Quishing)
- メール送信者認証(SPF/DKIM/DMARC/BIMI/ARC)
- DMARC (Domain-based Message Authentication, Reporting & Conformance)
- BIMI (Brand Indicators for Message Identification)
- ARC (Authenticated Received Chain)
- SOC 2
- FedCM (Federated Credential Management API)
- Email Verification Protocol (EVP)
- UPKI電子証明書発行サービス
- ACME (Automatic Certificate Management Environment)
- ファジング (Fuzzing)
- SSRF(Server-Side Request Forgery)
- ペネトレーションテスト
- WSTG(Web Security Testing Guide)
- OWASP Cheat Sheet Series
- OWASP API Security Top 10
- OpenHaystack
- Find My ネットワーク
- ssh-agent
- Vault
- OpenBao
- Service Mesh
- RBAC (Role-Based Access Control)
- 脅威ハンティング (Threat Hunting)
- SOC (Security Operations Center)
- SIEM (Security Information and Event Management)
- セキュリティ運用
- ランサムウェア
- MITRE ATT&CK
- Metasploit
- Kali NetHunter
- Kali Linux
- IOC (侵害指標) と IOA (攻撃指標)
- Hack The Box
- EDR (Endpoint Detection and Response)
- Burp Suite
- 7AI
- DevSecOps
- Istio Ambient Mesh
- LLMテキストの電子透かし
- Claudeのテキスト電子透かし導入 (2026-08)
- Apache Polaris
- シャノンエントロピー
- gitleaks
- betterleaks
- grsecurity
- 名古屋港統一ターミナルシステム(NUTS)ランサムウェア事案(2023年)
- KADOKAWAランサムウェア事案(2024年)
- つるぎ町立半田病院ランサムウェア事案(2021年)
- ufw
- iptables
- BYOD (Bring Your Own Device)
- Secure Enclave
- ReDoS (Regular Expression Denial of Service)