<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<oembed>
  <author_name>matsumoto_at</author_name>
  <author_url>https://blog.hatena.ne.jp/matsumoto_at/</author_url>
  <blog_title>アンドエンジニア - エンジニアのこと、エンジニアから。</blog_title>
  <blog_url>https://tenshoku.mynavi.jp/engineer/guide/</blog_url>
  <categories>
    <anon>ニュース</anon>
    <anon>齋藤 公二</anon>
  </categories>
  <description>サイバー攻撃は「産業化」しており、攻撃の手口は高度化、巧妙化している。セキュリティ企業SentinelOneが3月に公開した2025年の「年次脅威レポート」では、近年のサイバー攻撃の手口を8つの攻撃フェーズに分類し、それぞれでどのような攻撃が行われており、どのような対策が有効かを解説している。 1つめの攻撃フェーズは「アクセス(Access)」で、攻撃対象は「アイデンティティ(ID)」だ。攻撃者は、盗んだセッションや悪用された多要素認証(MFA) を用いて、正規の従業員活動を巧妙に模倣する。IDは重大な事案につながる侵入の主要経路であり、これに対抗するには、単なるログイン時の検証だけでなく、認…</description>
  <height>190</height>
  <html>&lt;iframe src=&quot;https://hatenablog-parts.com/embed?url=https%3A%2F%2Ftenshoku.mynavi.jp%2Fengineer%2Fguide%2Farticles%2Fn0127&quot; title=&quot;「MFA回避」「admin寄生」「CI/CDパイプライン攻撃」──サイバー攻撃における代表的な8つの手口を解説、SentinelOne年次脅威レポート - アンドエンジニア - エンジニアのこと、エンジニアから。&quot; class=&quot;embed-card embed-blogcard&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;&quot;&gt;&lt;/iframe&gt;</html>
  <image_url>https://cdn-ak.f.st-hatena.com/images/fotolife/m/matsumoto_at/20260714/20260714110243.jpg</image_url>
  <provider_name>Hatena Blog</provider_name>
  <provider_url>https://hatena.blog</provider_url>
  <published>2026-08-04 11:00:00</published>
  <title>「MFA回避」「admin寄生」「CI/CDパイプライン攻撃」──サイバー攻撃における代表的な8つの手口を解説、SentinelOne年次脅威レポート</title>
  <type>rich</type>
  <url>https://tenshoku.mynavi.jp/engineer/guide/articles/n0127</url>
  <version>1.0</version>
  <width>100%</width>
</oembed>
