🇯🇵Well done, Japan: a lesson in clear and proactive cyber communication
As many of you have noticed, in recent months there has been a worrying increase in cyberattacks targeting Japanese companies, both from organized cybercriminal groups and independent hackers.
However, this unfortunate trend has also shown how remarkably Japan is handling cybersecurity communication. Companies are demonstrating an excellent approach by informing the public quickly, clearly, and transparently about the incidents they face, often sharing technical details on how the attack occurred.
This level of openness not only helps stakeholders stay informed but also contributes to raising cybersecurity awareness across the entire corporate ecosystem, encouraging other organizations to strengthen their defenses.
One notable example is Mino Kogyo Co., Ltd., a manufacturing company that not only disclosed the incident but also provided a detailed timeline and clear explanation of how it unfolded.
Even though no company can be completely immune to cyber threats, this kind of transparency and responsibility can significantly reduce the overall impact of an attack and help the entire community learn and improve.
Well done, Japan.
Hackmanac Team
Active Directoryのドメイン参加用アカウントが、管理者がMicrosoftの指針に従っていても企業環境の侵害経路となっていることが判明した。調査によれば、これらのアカウントは初期設定で過剰な権限を持ち、攻撃者にドメイン支配権を与える恐れがある。
ドメイン参加アカウントはPCをドメインに追加する権限を持つが、OS展開時に平文パスワードがPXEやunattend.xml、MDT構成などに含まれるため、内部ネットワーク上の攻撃者が容易に入手可能である。さらに、このアカウントが作成したコンピュータオブジェクトの所有権を通じ、LAPSパスワード窃取やRBCD悪用、Shadow Credentials攻撃が行える。対策として、①MachineAccountQuotaを0に設定、②LAPS属性へのRead権限を拒否、③RBCD用GUIDへのWrite権限を拒否することが推奨される。Microsoftは2025年8月にようやく正式ガイダンスを公表したが、恒常的な権限管理が依然不可欠である。
https://t.co/k0OPGNfd1n