🕸️ 脅威マップ 🎯 検知アナリティクス ← マトリクスビューアへ

MITRE ATT&CK ATT&CK Enterprise v19.1(2026-05-12 リリース)の知識ベース(脅威グループ 174 / 技法 222)と、CISA KEV(悪用が確認された脆弱性)を組み合わせた脅威動向サマリ。各項目はマトリクスビューアの該当箇所にリンクします。
サイト更新 2026-07-25 / KEV カタログ 2026.07.24 版(1,653件、ランサム332件) / ATT&CK 知識ベースは v19.1 が現行最新

🚨 悪用が確認されている脆弱性(CISA KEV)
カタログ 2026.07.24 / 登録 1,653 件(うちランサムウェア悪用 332 件)/ 各CVEは対応するATT&CK技法にリンク。データ更新日 2026-07-24。

技法別 KEV 悪用状況 CWE/キーワードからのマッピング(参考値)

1T1190公開アプリの悪用11342T1068権限昇格の悪用5233T1203クライアント実行の悪用3974T1059コマンド&スクリプト2445T1078有効なアカウント1896T1505サーバーソフトウェア部品40

狙われているベンダー KEV登録数 TOP15

1Microsoft382
2Cisco94
3Apple93
4Adobe80
5Google72
6Oracle45
7Apache39
8Ivanti35
9Fortinet28
10Linux26
11D-Link26
12VMware26
13Citrix22
14Synacor18
15SonicWall17

最近悪用が確認された脆弱性 最新18件

CISA KEV に最近追加されたエントリ。CVE番号は NVD、関連技法はマトリクスビューアにリンク。🔒 はランサムウェアでの悪用が確認されたもの。

CVE-2026-16232 2026-07-22
Check Point ─ SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
関連技法: T1078 T1190
CVE-2026-50522 2026-07-22
Microsoft ─ SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
関連技法: T1190
CVE-2026-60137 2026-07-21
WordPress ─ Core
WordPress Core SQL Injection Vulnerability
関連技法: T1190
CVE-2026-63030 2026-07-21
WordPress ─ Core
WordPress Core Interpretation Conflict Vulnerability
関連技法: T1190
CVE-2026-0770 2026-07-21
Langflow ─ Langflow
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
関連技法: T1190
CVE-2021-27137 2026-07-21
DD-WRT ─ DD-WRT
DD-WRT Stack-Based Buffer Overflow Vulnerability
関連技法: T1203
CVE-2026-58644 2026-07-16
Microsoft ─ SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
関連技法: T1190
CVE-2026-25089 2026-07-16
Fortinet ─ FortiSandbox
Fortinet FortiSandbox OS Command Injection Vulnerability
関連技法: T1059 T1190
CVE-2026-39808 2026-07-16
Fortinet ─ FortiSandbox
Fortinet FortiSandbox OS Command Injection Vulnerability
関連技法: T1059 T1190
CVE-2026-46817 2026-07-15
Oracle ─ E-Business Suite
Oracle E-Business Suite Improper Privilege Management Vulnerability
関連技法: T1068 T1078 T1190
CVE-2023-4346 2026-07-15
KNX Association ─ KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
関連技法: T1190
CVE-2026-56155 2026-07-14
Microsoft ─ Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
関連技法: T1190
CVE-2026-56164 2026-07-14
Microsoft ─ SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
関連技法: T1078 T1190
CVE-2026-15409 2026-07-14
SonicWall ─ SMA1000 Appliances
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
関連技法: T1190
CVE-2026-15410 2026-07-14
SonicWall ─ SMA1000 Appliances
SonicWall SMA1000 Appliances Code Injection Vulnerability
関連技法: T1059 T1190
CVE-2008-4128 2026-07-13
Cisco ─ IOS
Cisco IOS Cross-Site Request Forgery Vulnerability
関連技法: T1190
CVE-2026-56291 2026-07-10
Balbooa ─ Forms
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
関連技法: T1190 T1505
CVE-2026-48939 2026-07-10
iCagenda ─ iCagenda
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
関連技法: T1190 T1505

ランサムウェアで悪用された脆弱性 最新12件

CISA KEV で「ランサムウェアキャンペーンで使用」と明記された脆弱性のうち最近のもの。基幹システムの優先対処対象。

PTC ─ Windchill and FlexPLM
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
関連技法: T1190
Oracle ─ PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
関連技法: T1078 T1190
Check Point ─ Security Gateway
Check Point Security Gateway Improper Authentication Vulnerability
関連技法: T1078 T1190
Palo Alto Networks ─ PAN-OS
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
関連技法: T1078
Nx ─ Nx Console
Nx Console Embedded Malicious Code Vulnerability
関連技法: T1190
TanStack ─ TanStack
TanStack Unspecified Vulnerability
関連技法: T1190
WebPros ─ cPanel & WHM and WP2 (WordPress Squared)
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
関連技法: T1078 T1190
ConnectWise ─ ScreenConnect
ConnectWise ScreenConnect Path Traversal Vulnerability
関連技法: T1190
SimpleHelp ─ SimpleHelp
SimpleHelp Path Traversal Vulnerability
関連技法: T1190
SimpleHelp ─ SimpleHelp
SimpleHelp Missing Authorization Vulnerability
関連技法: T1078 T1190
Microsoft ─ Defender
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
関連技法: T1190
PaperCut ─ NG/MF
PaperCut NG/MF Improper Authentication Vulnerability
関連技法: T1078 T1190

月別 新規登録数 直近12か月

08
09
10
11
12
01
02
03
04
05
06
07
脅威グループ・技法の統計(ATT&CK知識ベース)

出典: MITRE ATT&CK Enterprise v19.1(リリース 2026-05-12)。脅威グループ174 / 技法222。同リリースで多くのグループのmodified日付が2026-05-12に揃っています。

最も使われている技法 TOP20

この技法を用いたことが報告された脅威グループ/キャンペーンの数。攻撃の「定番手口」を示す。

1 T1105 Ingress Tool Transfer 115
2 T1588.002 Toolsub 107
3 T1059.001 PowerShellsub 102
4 T1204.002 Malicious Filesub 98
5 T1059.003 Windows Command Shellsub 91
6 T1566.001 Spearphishing Attachmentsub 88
7 T1071.001 Web Protocolssub 78
8 T1036.005 Match Legitimate Resource Name or Locationsub 76
9 T1082 System Information Discovery 71
10 T1053.005 Scheduled Tasksub 66
11 T1190 Exploit Public-Facing Application 65
12 T1083 File and Directory Discovery 64
13 T1059.005 Visual Basicsub 62
14 T1070.004 File Deletionsub 60
15 T1005 Data from Local System 60
16 T1547.001 Registry Run Keys / Startup Foldersub 59
17 T1583.001 Domainssub 59
18 T1204.001 Malicious Linksub 58
19 T1016 System Network Configuration Discovery 56
20 T1078 Valid Accounts 56

活発な脅威グループ TOP20

そのグループが使用したことが報告された技法の数。手口の幅広さ=活動の活発さの指標。

1 G0094 Kimsuky 130
2 G0032 Lazarus Group 93
3 G0007 APT28 93
4 G0129 Mustang Panda 85
5 G0096 APT41 82
6 G1017 Volt Typhoon 81
7 G0034 Sandworm Team 79
8 G0059 Magic Hound 78
9 G0050 APT32 78
10 G0049 OilRig 76
11 G0047 Gamaredon Group 70
12 G0010 Turla 68
13 G0069 MuddyWater 68
14 G0046 FIN7 67
15 G0016 APT29 66
16 G0102 Wizard Spider 64
17 G1015 Scattered Spider 64
18 G1055 VOID MANTICORE 63
19 G0114 Chimera 59
20 G1051 Medusa Group 57

国・地域別の脅威グループ

MITRE ATT&CK の各グループ解説に基づく帰属分類。数字は使用技法数。帰属には諸説ある場合があります。

最近更新されたアクター

ATT&CK上で最近情報が更新された脅威グループ(更新日順)。最新の動きがあった示唆。

戦術別の技法数

15の戦術それぞれに分類される技法(トップレベル)の数。攻撃のどの段階に手口が多いか。

偵察 12 リソース開発 9 初期アクセス 11 実行 20 永続化 22 権限昇格 13 ステルス 30 防御妨害 18 認証情報アクセス 17 探索 34 横展開 9 収集 17 C2 18 持ち出し 9 影響 15