Skip to main content

TrendAI™
Security Blog

TrendAI Security Blog

Ausgewählte Blogs

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
Malware
Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read Article
AI
TrendAI™ Advances Threat Hunting to Dynamic, Real-World Exploitation of AI Infrastructure

The new threat hunting component of the TrendAI™ agentic exploit-remediation engine, code name AESIR, extends visibility beyond vulnerability disclosure. Its first published investigation links over a year of honeypot data to the LF3 loader framework.

Read Article
AIExploits & Zero-Days
Ranked First on CyberGym: TrendAI™ Agentic Exploit-Remediation Engine Scores 97% on the Top Exploit Benchmark

The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.

Read Article
Cyber risk
UK Power Facility Cyberattack Shutdown: What Critical-Infrastructure Operators and Defenders Need to Know

A reported cyberattack on a UK power-generation facility in July 2026 shows that even disruptions at a single site can raise broader questions about critical infrastructure resilience.

Read Article
AIEmerging technologies
The Architecture Behind $1B: How Customers Run TrendAI Vision One™ on AWS, and Secure Their AI Workloads
Read Article
Cyber threats
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant

TrendAI™ Research provides a comprehensive analysis of the RedC2 Linux Implant, a sophisticated threat recently discovered in the npm open-source ecosystem. 

Read Article
Malware
Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains

In this blog entry, researchers at TrendAI Vision One™ Services – Managed Detection and Response (MDR) walk through how attackers deliver, install, and operate a reconfigured ScreenConnect client, and why it slips past defenses built to catch conventional malware.

Read Article
Phishing & BEC
How AiTM Phishing Bypassed MFA to Hijack a Microsoft 365 Mailbox in BEC Scheme

One click on a targeted lure handed an attacker live Microsoft 365 session tokens, enough to impersonate a vendor and reroute payments. TrendAI Vision One™ Services – Managed Detection and Response (MDR) tracks the attack to its root cause.

Read Article
AIExploits & Zero-Days
The Speed of AI Is Changing the Vulnerability Landscape. Our Commitment to CISA KEV Isn’t.

TrendAI™ is deepening its focus on the CISA KEV Catalog as a proven signal of active risk. With AI, TrendAI™ combines TrendAI™ ZDI research, exploit intelligence, exposure context, and business risk to drive continuous, AI-assisted prioritization, helping security teams make better decisions and act faster.

Read Article
Exploits & Zero-Days
How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow

TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.

Read Article