Topic
Threat Intelligence

Hunt or be Hunted: FalconFlank Zero-Day
Within 48 hours of the FalconFlank exploit's release, Tanium HuntIQ built seven behavioral detections and a single Atlas hunt prompt to catch attackers who turn CrowdStrike Falcon's own privileged clean-up against itself. See how Tanium Atlas sweeps an entire Windows fleet for the exposure in about a minute.

Hunt or be Hunted: ShieldBreak Zero-Day
Learn how Tanium HuntIQ turned a Windows Defender zero-day into a tested mitigation before a CVE was assigned.

セキュリティアップデート:Salesforceからのデータ流出を招いたKlue社の情報漏洩に対するTaniumの対応
今週はじめ、弊社が利用しているサードパーティ製プラットフォームである Klue 社において、セキュリティ侵害が発生したことを確認いたしました。Klue 社は、OAuth 連携を通じて Salesforce と競合分析、商談成否データなどを同期するサービスを提供しており、今回その連携サービスが侵害を受けました。攻撃者は、Klue 社のシステムから窃取した認証情報を用いて、弊社の Salesforce CRM 内のデータにアクセスいたしました。弊社は確認後ただちに対応し、問題の是正と防御強化のための措置を講じております。

テレビ東京「ワールドビジネスサテライト(WBS)」にて放送されました
このたび、テレビ東京様の報道番組「ワールドビジネスサテライト(WBS)」に当社が取り上げられました。

タニウムのライセンスを無償提供「フロンティア AI レスキュープログラム」
タニウムを"試せる"を用意しました。初期費用 0円。最大6ヶ月、タニウムを無償提供いたします。 27年間、誰も見つけられなかった脆弱性を、最先端のフロンティアAIはわずか数時間で発見しました。攻撃の「量・速度・担い手」が一変し、日本政府や大手金融機関も備えを始めています。「年に数回パッチを当てる」運用では、もう間に合いません。 いま必要なのは、全端末を継続的に可視化し、是正し続ける運用への転換です。Taniumはその移行を、初期費用0円・最大6ヶ月無償で支援します。

Critical Netlogon RCE on domain controllers (CVE-2026-41089)
A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

Claude Mythos security risks: What the Anthropic System Card tells us
Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.

CVE‑2025‑47813: Wing FTP Server vulnerability flagged by CISA
CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

A Supply Chain Attack in Notepad++
The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.

CTI roundup: SantaStealer, BlackForce, Ink Dragon
SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

CTI roundup: Shanya, GrayBravo, Storm-0249
Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

CTI roundup: Whisper Leak, @acitons/artifact, Quantum Route Redirect
Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing