threat_intelligence1072 wordsRead on Huntaegis

Warning: Notice regarding unauthorized access to domestic organizations in recent succession (Update)

JPCERT-AT-2026-0030 JPCERT/CC October 8, 2026 (Published) October 9, 2026 (Updated) As damage is occurring across multiple products and services, there is a lack of technical information sharing. Although the information we possess is limited and fragmented, in light of the situation regarding the expansion of attack damage, we hereby issue the following warning. Furthermore, this advisory addresses attack types that are particularly increasing in relation to the leakage of large amounts of personal information, such as ransomware attacks that occur intermittently and sporadically. In addition to applications for general users, there are cases where systems that do not anticipate access from unspecified large numbers of users, such as BI (Business Intelligence) tools or employee management systems, are damaged, leading to the leakage of information stored internally. Such systems also require the following inspections. We will update this page if new information regarding the cause of compromise or attack methods is discovered. *The information in this section is based on information received by JPCERT/CC. It does not indicate that the same attack method is used in all cases. Information may be added based on future developments.* **Case A: Exploration and attempted attacks on known vulnerabilities in various software.** Regarding the series of attacks, it is not exploiting a single common software vulnerability, but possibly scanning for the presence or absence of various known vulnerabilities for each target to explore and attempt to exploit vulnerabilities, or attempting attacks by exploiting mismanagement of equipment (such as stealing environment configuration files or backup files) even if they are not vulnerabilities. **Case B: Unauthorized operations via API.** Unauthorized overwriting of information occurs through unauthorized requests to the application management API. JPCERT/CC has received multiple reports regarding the following attack techniques: (a) Analyzing publicly available smartphone applications to identify API endpoints and keys. (b) Attacks against internal APIs that cannot be executed through screen operations. - Changing user permissions - Creating unauthorized accounts - Checking response differences by switching header presence or assigning invalid format authentication tokens. - Identifying account information through blind exploration via NoSQL injection. (c) Using API keys stolen from the compromise of other systems. To date, the following suspicious access sources have been identified: *The IP addresses below were used around September. They may currently be in regular use.* Suspicious Source IP Addresses - 3.112.252[.]14 - 54.95.112[.]6 - 69.10.51[.]162 - 172.86.91[.]7 - 210.149.87[.]120 User-Agent Examples - curl/7.88.1 - python-requests/2.34.2 - Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36 **Case C: SQL Injection vulnerability in Metabase (CVE-2026-72898).** This vulnerability can also be exploited through unauthorized requests to the API. JPCERT/CC announced an advisory regarding this vulnerability on August 14, 2026. Please check the following advisory for details on affected products and countermeasures. JPCERT/CC Advisory regarding SQL Injection Vulnerability in Metabase (CVE-2026-72898) https://www.jpcert.or.jp/at/2026/at260023.html To date, access from the following suspicious source has been confirmed: *The IP addresses below were used between early August and early September. They may currently be in regular use.* Suspicious Source IP Addresses - 213.163.202[.]171 - 221.216.140[.]49 - 221.216.140[.]129 User-Agent Examples - python-requests/2.33.1 - Metabase-GHSA-vwf4/2.0 **Case D: Installation of Web Shell on Application Server Accessible from Public Web Servers.** Cases where WAR files (.war) are installed on an application server accessible from a public web server have been confirmed. The JSP files (.jsp) contained in the WAR file operate as malicious simple web shells. Web shells have the functionality to obtain specific query parameters and execute them as shell commands. To date, access from the following suspicious source has been confirmed: *The IP addresses below were used for repeated GET and POST requests to the web shell around September. They may currently be in regular use.* Suspicious Source IP Addresses - 124.133.237[.]18 **III. Countermeasures** We recommend the implementation of the following countermeasures based on the attack techniques reported to JPCERT/CC. For details on countermeasures against API access, please refer to OWASP guidelines, etc. Countermeasures against API Access: - Restrict the number of requests per unit of time to prevent repeated access or mass execution in a short time. - Set individual rate limits and usage limits for functions with high risks of load or abuse, such as login, password reset, SMS sending, and search processing. - Implement access control for each API endpoint, including non-public APIs, and only allow access from authorized users and HTTP methods. - Grant only the minimum necessary permissions to API users and API tokens. - Set appropriate expiration dates for API tokens and avoid using tokens that remain valid for long periods. - Ensure that unnecessary or suspected leaked API tokens can be promptly invalidated. In addition to the above, general countermeasures: - If service usage regions are limited, restrict access from the source region. - If operating on versions affected by known vulnerabilities, apply corrected updates. - Review countermeasures against lateral movement after web servers, etc., are compromised. - Review the system for detecting unauthorized access and the initial response upon detection. - Implement appeals to customers to prevent secondary damage (such as multi-factor authentication) from the time of the incident (e.g., leakage). - Stop the public disclosure if services or functions not required for business operations (such as management functions) are exposed to the internet. - Do not retain data that has exceeded the retention periods stipulated by laws or contracts, or data whose purpose of use has ended. As reiterated, there are cases where systems that do not anticipate access from unspecified large numbers of users (such as for employees or BI tools) are damaged. We recommend the above inspections for such systems. **IV. Reference Information** OWASP API Security Project team OWASP Top 10 API Security Risks 2023 https://api-security.owasp.org/editions/2023/en/0x11-t10/ OWASP Cheat Sheets Series REST Security Cheat Sheet https://cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html Macnica Security Research Center Regarding Information Leakage Incidents from Web Systems https://security.macnica.co.jp/blog/2026/10/web-incidents2026.html **V. Requests for Investigation, Information Provision, etc.** If you have any specific information regarding suspicious access or compromise, attack methods, or causes of compromise related to this matter, we would appreciate it if you could provide it to JPCERT/CC. Please also contact JPCERT/CC with any consultation requests regarding incident response. Contact for Advisory: General Association JPCERT Coordination Center (JPCERT/CC) Cybersecurity Coordination Group Email: ew-info@jpcert.or.jp Contact for Incident Response Consultation: https://www.jpcert.or.jp/form/ Consultation Response from Investigation Vendors, etc.: https://www.jpcert.or.jp/ir/consult.html **Revision History** October 8, 2026 Published; October 9, 2026 Information added to "I. Overview" and "II. Confirmed Attack Methods and Traces" General Association JPCERT Coordination Center (JPCERT/CC) Cybersecurity Coordination Group Email: ew-info@jpcert.or.jp

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.