|
3 | 3 | <title>AI Security Daily Digest</title> |
4 | 4 | <subtitle>AIセキュリティに関する日次ニュースダイジェスト - 研究・ニュース・政策動向を自動収集・要約</subtitle> |
5 | 5 | <id>https://futabato.github.io/rss/</id> |
6 | | - <updated>2026-04-14T23:40:07Z</updated> |
| 6 | + <updated>2026-04-15T23:39:57Z</updated> |
7 | 7 | <link rel="self" href="https://futabato.github.io/rss/feed.xml"/> |
8 | 8 | <link rel="alternate" href="https://futabato.github.io/rss/"/> |
9 | 9 | <author> |
10 | 10 | <name>AI Security Digest Bot</name> |
11 | 11 | </author> |
12 | 12 | <entry> |
13 | | - <title>Trusted access for the next era of cyber defense</title> |
14 | | - <link href="https://simonwillison.net/2026/Apr/14/trusted-access-openai/#atom-everything" rel="alternate"/> |
15 | | - <id>urn:ai-security-digest:9492782c6947da25</id> |
16 | | - <published>2026-04-14T21:23:59Z</published> |
17 | | - <updated>2026-04-14T21:23:59Z</updated> |
18 | | - <content type="html"><p>OpenAIがサイバー防衛向けに特化したモデル「GPT-5.4-Cyber」を発表した。防御的なサイバーセキュリティユースケースを支援するためにファインチューニングされており、Trusted Accessプログラムの拡張とともに、AIを活用したサイバー防御の新たな時代を切り開く取り組みとして注目される。</p><p><strong>Source:</strong> Simon Willison&#x27;s Weblog</p><p><span class="tag">tool</span> <span class="tag">model-safety</span> <span class="tag">governance</span> </p></content> |
19 | | - <category term="tool"/> |
20 | | - <category term="model-safety"/> |
21 | | - <category term="governance"/> |
| 13 | + <title>[2604.11790] ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection</title> |
| 14 | + <link href="https://arxiv.org/abs/2604.11790" rel="alternate"/> |
| 15 | + <id>urn:ai-security-digest:c68ef2a9f9c96cba</id> |
| 16 | + <published>2026-04-15T23:39:53Z</published> |
| 17 | + <updated>2026-04-15T23:39:53Z</updated> |
| 18 | + <content type="html"><p>本論文では、ツール拡張型LLMエージェントを間接プロンプトインジェクション攻撃から保護するランタイムセキュリティフレームワーク「ClawGuard」を提案している。間接プロンプトインジェクションは、外部ツールや取得データを通じて悪意ある指示をエージェントに埋め込む攻撃手法であり、ClawGuardはその実行時検出・防御を目的としている。LLMエージェントの実用化が進む中で、ツール連携時のセキュリティリスクに対処する重要な研究である。</p><p><strong>Source:</strong> arXiv</p><p><span class="tag">research</span> <span class="tag">agent-security</span> <span class="tag">adversarial</span> <span class="tag">vulnerability</span> </p></content> |
| 19 | + <category term="research"/> |
| 20 | + <category term="agent-security"/> |
| 21 | + <category term="adversarial"/> |
| 22 | + <category term="vulnerability"/> |
22 | 23 | <source> |
23 | | - <title>Simon Willison's Weblog</title> |
| 24 | + <title>arXiv</title> |
24 | 25 | </source> |
25 | 26 | </entry> |
26 | 27 | <entry> |
27 | | - <title>Cybersecurity Looks Like Proof of Work Now</title> |
28 | | - <link href="https://simonwillison.net/2026/Apr/14/cybersecurity-proof-of-work/#atom-everything" rel="alternate"/> |
29 | | - <id>urn:ai-security-digest:5945e6ebcc914718</id> |
30 | | - <published>2026-04-14T19:41:48Z</published> |
31 | | - <updated>2026-04-14T19:41:48Z</updated> |
32 | | - <content type="html"><p>英国AI安全機関(AISI)がAnthropicのClaude Mythosのサイバー能力を独自評価し、セキュリティ脆弱性の発見において非常に高い有効性を確認した。使用トークン量(コスト)が増えるほど性能が向上するという経済的インセンティブ構造が明らかになり、AIによるサイバーセキュリティの「プルーフ・オブ・ワーク」化が議論されている。</p><p><strong>Source:</strong> Simon Willison&#x27;s Weblog</p><p><span class="tag">evaluation</span> <span class="tag">model-safety</span> <span class="tag">adversarial</span> <span class="tag">research</span> </p></content> |
33 | | - <category term="evaluation"/> |
34 | | - <category term="model-safety"/> |
35 | | - <category term="adversarial"/> |
36 | | - <category term="research"/> |
| 28 | + <title>Incident response for AI: Same fire, different fuel</title> |
| 29 | + <link href="https://www.microsoft.com/en-us/security/blog/2026/04/15/incident-response-for-ai-same-fire-different-fuel/" rel="alternate"/> |
| 30 | + <id>urn:ai-security-digest:e827d6ce5b5419cb</id> |
| 31 | + <published>2026-04-15T16:00:45Z</published> |
| 32 | + <updated>2026-04-15T16:00:45Z</updated> |
| 33 | + <content type="html"><p>AIの普及によりインシデントレスポンス(IR)の様相が変化していることを解説したMicrosoftのブログ記事。従来のIR手法が引き続き有効な部分と、AI固有のテレメトリ・ツール・スキルが新たに必要となる領域を整理し、AIシステムに対応したIRの実践的アプローチを提示している。</p><p><strong>Source:</strong> Microsoft Security Blog</p><p><span class="tag">incident</span> <span class="tag">agent-security</span> <span class="tag">tool</span> </p></content> |
| 34 | + <category term="incident"/> |
| 35 | + <category term="agent-security"/> |
| 36 | + <category term="tool"/> |
37 | 37 | <source> |
38 | | - <title>Simon Willison's Weblog</title> |
| 38 | + <title>Microsoft Security Blog</title> |
39 | 39 | </source> |
40 | 40 | </entry> |
41 | 41 | <entry> |
42 | | - <title>AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud</title> |
43 | | - <link href="https://thehackernews.com/2026/04/ai-driven-pushpaganda-scam-exploits.html" rel="alternate"/> |
44 | | - <id>urn:ai-security-digest:e932151f912bd84b</id> |
45 | | - <published>2026-04-14T14:30:00Z</published> |
46 | | - <updated>2026-04-14T14:30:00Z</updated> |
47 | | - <content type="html"><p>AIが生成したコンテンツを悪用し、GoogleのDiscoverフィードに偽のニュース記事を流入させてスケアウェアや詐欺へ誘導する「Pushpaganda」と呼ばれる新たな広告詐欺キャンペーンが発覚した。SEOポイズニングとAI生成コンテンツを組み合わせた手口は、AIの悪用による新たな脅威ベクターとして警戒が必要だ。</p><p><strong>Source:</strong> The Hacker News</p><p><span class="tag">incident</span> <span class="tag">adversarial</span> <span class="tag">tool</span> </p></content> |
48 | | - <category term="incident"/> |
49 | | - <category term="adversarial"/> |
| 42 | + <title>OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams</title> |
| 43 | + <link href="https://thehackernews.com/2026/04/openai-launches-gpt-54-cyber-with.html" rel="alternate"/> |
| 44 | + <id>urn:ai-security-digest:04ad202cb518d299</id> |
| 45 | + <published>2026-04-15T04:30:00Z</published> |
| 46 | + <updated>2026-04-15T04:30:00Z</updated> |
| 47 | + <content type="html"><p>OpenAIが防御的サイバーセキュリティ用途に特化したモデル「GPT-5.4-Cyber」を発表した。セキュリティチームへの拡張アクセスを提供し、脅威の発見・修正を加速することを目的としており、Anthropicの新モデル「Mythos」公開直後のリリースとなっている。</p><p><strong>Source:</strong> The Hacker News</p><p><span class="tag">tool</span> <span class="tag">model-safety</span> </p></content> |
50 | 48 | <category term="tool"/> |
| 49 | + <category term="model-safety"/> |
51 | 50 | <source> |
52 | 51 | <title>The Hacker News</title> |
53 | 52 | </source> |
54 | 53 | </entry> |
55 | 54 | <entry> |
56 | | - <title>Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)</title> |
57 | | - <link href="https://thehackernews.com/2026/04/analysis-of-216m-security-findings.html" rel="alternate"/> |
58 | | - <id>urn:ai-security-digest:17d1cb8a81ffea4b</id> |
59 | | - <published>2026-04-14T10:00:00Z</published> |
60 | | - <updated>2026-04-14T10:00:00Z</updated> |
61 | | - <content type="html"><p>OX Securityが250組織・2億1600万件のセキュリティ調査結果を分析した結果、クリティカルリスクが前年比約400%増加していることが判明した。AI支援による開発速度の向上が高影響度の脆弱性密度を急増させる「velocity gap」を生み出しており、AIが開発・セキュリティ両面に与える影響が浮き彫りになった。</p><p><strong>Source:</strong> The Hacker News</p><p><span class="tag">research</span> <span class="tag">vulnerability</span> <span class="tag">adversarial</span> </p></content> |
| 55 | + <title>Beyond Static Sandboxing: Learned Capability Governance for Autonomous AI Agents</title> |
| 56 | + <link href="https://arxiv.org/abs/2604.11839" rel="alternate"/> |
| 57 | + <id>urn:ai-security-digest:515832f6113c3982</id> |
| 58 | + <published>2026-04-15T04:00:00Z</published> |
| 59 | + <updated>2026-04-15T04:00:00Z</updated> |
| 60 | + <content type="html"><p>自律型AIエージェントにおける「ケイパビリティ過剰プロビジョニング問題」を指摘した研究論文。タスクの種類に関わらず全ツールへのアクセスが許可されるデフォルト設定(15倍の過剰付与)を問題視し、静的サンドボックスを超えた動的なケイパビリティガバナンスアーキテクチャを提案している。</p><p><strong>Source:</strong> arXiv cs.CR (Cryptography and Security)</p><p><span class="tag">research</span> <span class="tag">agent-security</span> <span class="tag">vulnerability</span> </p></content> |
62 | 61 | <category term="research"/> |
| 62 | + <category term="agent-security"/> |
63 | 63 | <category term="vulnerability"/> |
64 | | - <category term="adversarial"/> |
65 | 64 | <source> |
66 | | - <title>The Hacker News</title> |
| 65 | + <title>arXiv cs.CR (Cryptography and Security)</title> |
67 | 66 | </source> |
68 | 67 | </entry> |
69 | 68 | <entry> |
70 | | - <title>ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying</title> |
71 | | - <link href="https://arxiv.org/abs/2604.09747" rel="alternate"/> |
72 | | - <id>urn:ai-security-digest:b127b3d0274d0d24</id> |
73 | | - <published>2026-04-14T04:00:00Z</published> |
74 | | - <updated>2026-04-14T04:00:00Z</updated> |
75 | | - <content type="html"><p>LLMエージェントのメモリモジュールやRAGメカニズムを標的とした新たなデータ抽出攻撃手法「ADAM」が研究者により発表された。適応的クエリを通じてエージェントの記憶から機密情報を系統的に窃取できることが示され、LLMエージェントのプライバシーおよびセキュリティに対する重大な脆弱性として警鐘を鳴らしている。</p><p><strong>Source:</strong> arXiv cs.CR (Cryptography and Security)</p><p><span class="tag">research</span> <span class="tag">agent-security</span> <span class="tag">vulnerability</span> <span class="tag">adversarial</span> </p></content> |
| 69 | + <title>SIR-Bench: Evaluating Investigation Depth in Security Incident Response Agents</title> |
| 70 | + <link href="https://arxiv.org/abs/2604.12040" rel="alternate"/> |
| 71 | + <id>urn:ai-security-digest:8566ef0045fcf87c</id> |
| 72 | + <published>2026-04-15T04:00:00Z</published> |
| 73 | + <updated>2026-04-15T04:00:00Z</updated> |
| 74 | + <content type="html"><p>自律型セキュリティインシデントレスポンスエージェントを評価するベンチマーク「SIR-Bench」を提案した研究論文。794件のテストケースを用い、単なるアラートの繰り返しではなく実際の法科学的調査能力を測定できる設計となっており、AIエージェントの実用的な評価基盤を提供する。</p><p><strong>Source:</strong> arXiv cs.CR (Cryptography and Security)</p><p><span class="tag">research</span> <span class="tag">evaluation</span> <span class="tag">agent-security</span> </p></content> |
76 | 75 | <category term="research"/> |
| 76 | + <category term="evaluation"/> |
77 | 77 | <category term="agent-security"/> |
78 | | - <category term="vulnerability"/> |
| 78 | + <source> |
| 79 | + <title>arXiv cs.CR (Cryptography and Security)</title> |
| 80 | + </source> |
| 81 | + </entry> |
| 82 | + <entry> |
| 83 | + <title>Can we Watermark Low-Entropy LLM Outputs?</title> |
| 84 | + <link href="https://arxiv.org/abs/2604.12051" rel="alternate"/> |
| 85 | + <id>urn:ai-security-digest:a9218ef389fe95c8</id> |
| 86 | + <published>2026-04-15T04:00:00Z</published> |
| 87 | + <updated>2026-04-15T04:00:00Z</updated> |
| 88 | + <content type="html"><p>低エントロピーなLLM出力に対する証明可能な透かし(ウォーターマーク)技術を研究した論文。出力分布を変えずにウォーターマークを埋め込む「検出不可能な透かし」スキームを検討し、攻撃者による除去に対する耐性を理論的に分析している。</p><p><strong>Source:</strong> arXiv cs.CR (Cryptography and Security)</p><p><span class="tag">research</span> <span class="tag">model-safety</span> <span class="tag">adversarial</span> </p></content> |
| 89 | + <category term="research"/> |
| 90 | + <category term="model-safety"/> |
79 | 91 | <category term="adversarial"/> |
80 | 92 | <source> |
81 | 93 | <title>arXiv cs.CR (Cryptography and Security)</title> |
|
0 commit comments