Tomo
banner
tomo.gr
Tomo
@tomo.gr
某大企業のCSIRTやってる人
主にセキュリティ、たまにゲーム(WoW)

I am in charge of leader of a certain global trading company's CSIRT/SOC team. Registered Information Security Specialist in Japan.
Cyber Security and/or World of Warcraft
Reposted by Tomo
中国の新サイバーセキュリティ法が施行、企業にとってすべてが変わる
#CybersecurityNews
thecyberexpress.com/china-cybers...
China’s New Cybersecurity Law Is Here — And It Changes Everything for Businesses
China has officially entered a new era of cyber regulation. As of January 1, 2026, the amended China cybersecurity law
thecyberexpress.com
January 4, 2026 at 5:55 AM
Reposted by Tomo
How to Integrate AI into Modern SOC Workflows
How to Integrate AI into Modern SOC Workflows
thehackernews.com
December 30, 2025 at 11:29 AM
Reposted by Tomo
Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code
Critical Vulnerability in SmarterMail Let Attackers Execute Remote Code
cybersecuritynews.com
December 30, 2025 at 12:19 PM
RSAC2026行きたいけど今期の予算がなーってなってるのに、帰国を来期にして来期の予算につけるという暴挙をする話が流れてきて、ええええってなってる。
December 20, 2025 at 2:06 PM
Reposted by Tomo
MSIgniteがAI一色。

セキュリティで小規模MSSPが生き残れる未来が想像できなくなったのでキャリアチェンジすべきか真剣に悩み中
November 18, 2025 at 7:35 PM
a SQL query なのか an SQL queryなのか。みんなはどっち?
September 28, 2025 at 2:05 PM
Reposted by Tomo
In what is being called the largest supply chain attack in history, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising maintainers' accounts in a phishing attack.
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
In what is being called the largest supply chain attack in history, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising maintainers' accounts in a phishing attack.
www.bleepingcomputer.com
September 8, 2025 at 4:48 PM
Reposted by Tomo
A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys.
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys.
www.bleepingcomputer.com
September 8, 2025 at 7:54 PM
Reposted by Tomo
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
thehackernews.com
July 11, 2025 at 4:01 PM
Reposted by Tomo
Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address
Let's Encrypt Started to Issue SSL/TLS Certificate for IP Address
cybersecuritynews.com
July 3, 2025 at 1:17 PM
Reposted by Tomo
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign
thehackernews.com
June 27, 2025 at 4:31 PM
参加してきました
ウクライナCERT人気だった
June 27, 2025 at 10:48 PM
Reposted by Tomo
Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors
Scattered Spider hackers shift focus to aviation, transportation firms
Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors
www.bleepingcomputer.com
June 27, 2025 at 6:21 PM
今月のアレにコペンハーゲン行く人いるだろうか
June 15, 2025 at 11:56 AM
思いっきり色々使える、おうちサーバーになりそう
(TRとかXeonではないので、小規模だけど)
April 26, 2025 at 9:13 AM
Reposted by Tomo
According to Ransomware.live, qilin ransomware group has added SMC Corporation (🇯🇵) to its victims.
March 17, 2025 at 9:38 AM
Reposted by Tomo
🚨Cyberattack Alert ‼️

🇪🇺🇯🇵 - SMC Corporation

Qilin hacking group claims to have breached the European branch of SMC Corporation.

Allegedly, 1.1 TB (552,000 files) of data were exfiltrated.
March 17, 2025 at 10:06 AM
Reposted by Tomo
CVE-2025–24813: Apache Tomcat Path Equivalence Vulnerability $$ BOUNTY
CVE-2025–24813: Apache Tomcat Path Equivalence Vulnerability $$$$ BOUNTY
Disclaimer: This document is for educational purposes only. Exploiting systems without authorization is illegal and punishable by law.
infosecwriteups.com
March 16, 2025 at 6:07 AM
某大使館でのイベントに参加
日本のはずなのにそこは完全に欧州だった。
March 8, 2025 at 5:13 AM
イギリスのロンドンにある
バターシーパワーステーション…廃火力発電所をショッピングモールにしちゃったもの。外の迫力と中がモダンなモールで驚いた。
March 8, 2025 at 5:10 AM
今回の出張、ほぼ全ての支払いをカードで済ませてポンドに至っては1ポンドも持ってかなかった
February 28, 2025 at 5:15 AM