Skip to main content

TrendAI™ Ranks #1 on CyberGym with a 97% Exploit-Remediation Score

TrendAI™ Deep Research

spark

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

Read article
AI
The Mirage of AI Programming: Hallucinations and Code Integrity

The adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.

Read Article
Emerging technologies
Post-Quantum Cryptography: Migrating to Quantum Resistant Cryptography

In the previous parts of this series, we have learned about cryptography, what makes quantum computers unique, and how quantum computers break this cryptography. In the fourth and final part of our study on post-quantum cryptography, we will look at quantum-resistant algorithms that could replace our existing cryptography.  

Read Article
Cloud security
Kong API Gateway Misconfigurations: An API Gateway Security Case Study

Tools that aggregate access into multiple different environments, such as API gateways, pose a security risk for all these environments upon breach. In this article, we continue our journey through the security issues of the API Gateway landscape. Our new research focuses on another popular API gateway — Kong.

Read Article
AICyber crime
Back to the Hype: An Update on How Cybercriminals Are Using GenAI

Generative AI continues to be misused and abused by malicious individuals. In this article, we dive into new criminal LLMs, criminal services with ChatGPT-like capabilities, and deepfakes being offered on criminal sites.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: LockBit

The LockBit intrusion set, tracked by Trend Micro as Water Selkie, has one of the most active ransomware operations today. With LockBit’s strong malware capabilities and affiliate program, organizations should keep abreast of its machinations to effectively spot risks and defend against attacks.

Read Article
Cloud security
Observability Exposed: Exploring Risks in Cloud-Native Metrics

Container Advisor (cAdvisor) is an open-source monitoring tool for containers that is widely used in cloud services. It logs and monitors metrics like network input/output (I/O), disk I/O, and CPU usage. However, misconfigured deployments might inadvertently expose sensitive information, including environment variables such as Prometheus metrics. In this article, we share our findings of the risks we have uncovered and the vulnerable configurations users need to be aware of.

Read Article
Ransomware & extortionPhishing & BEC
Ransomware Spotlight: 8Base

Despite positioning themselves as penetration testers, 8Base ransomware threat actors profit off their victims that are significantly comprised of small businesses. In this feature, we investigate how the gang operates to gain insights on how organizations can protect systems better from compromises that could result in financial loss.  

Read Article
Exploits & Zero-Days
Open RAN: Attack of the xApps

This article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handling

Read Article
Exploits & Zero-Days
Apache APISIX In-the-wild Exploitations: An API Gateway Security Study

This article focuses on the Apache APISIX API gateway and its security implications.

Read Article
Ransomware & extortionPhishing & BEC
Ransomware Spotlight: Rhysida

The threat actors behind the Rhysida ransomware targeted multiple industries by posing as a cybersecurity team that offered to help its victims identify security weaknesses in their networks and systems. Although the group’s activity was first observed back in May 2023, its leak site was established as early as March 2023. Like other ransomware groups, it employs double extortion tactics to pressure its victims into paying a ransom demand in Bitcoin.

Read Article