Skip to main content

TrendAI™ Named a Major Player in 2026 IDC MarketScape for MDR for Midmarket

TrendAI™
Security Blog

TrendAI Security Blog

Featured Blogs

Cyber threats
Hacking Tools, Survey Scam Target Facebook Users
Read Article
Malware
Fake Banking App Found on Google Play Used in SMiShing

As users start to look for apps and other services from their banks, opportunities for scammers also increase. One recent example of this is the app Movil Secure, part of a SMiShing scheme targeting Spanish-speaking users.

Read Article
Malware
Bashlite Updated with Mining and Backdoor Commands

We uncovered an updated Bashlite malware designed to add infected internet-of-things devices to a distributed-denial-of-service (DDoS) botnet. Based on the Metasploit module it exploits, the malware targets devices with the WeMo UPnP API.

Read Article
Cyber threats
#NoFilter: Exposing the Tactics of Instagram Account Hackers

What tactics do Instagram account hackers use? What do these cybercriminals do with stolen accounts? How can users protect their accounts? We look into Instagram account hacking incidents from a security researcher’s perspective and share recommendations for users of Instagram and other social media platforms.

Read Article
AI
EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks

Combining AI-generated code and social engineering, EvilAI operators are executing a rapidly expanding campaign, disguising their malware as legitimate applications to bypass security, steal credentials, and persistently compromise organizations worldwide.

Read Article
Ransomware & extortion
New LockBit 5.0 Targets Windows, Linux, ESXi

TrendAI™ Research analyzed source binaries from the latest activity from notorious LockBit ransomware with their 5.0 version that exhibits advanced obfuscation, anti-analysis techniques, and seamless cross-platform capabilities for Windows, Linux, and ESXi systems.

Read Article
Malware Phishing & BEC
Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users

TrendAI™ Research has identified an active campaign spreading via WhatsApp through a ZIP file attachment. When executed, the malware establishes persistence and hijacks the compromised WhatsApp account to send copies of itself to the victim’s contacts.

Read Article
LLMs
When Tokenizers Drift: Hidden Costs and Security Risks in LLM Deployments

A tokenizer lies at the core of every large language model. When it drifts, whether from unseen flaws or adversarial interference, costs rise and performance drops. We explore this emerging risk, its implications, and the measures to prevent it.

Read Article
Exploits & Zero-Days
CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation

CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.

Read Article
APTs Targeted attacks
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups

PeckBirdy is a sophisticated JScript-based C&C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities.

Read Article