Skip to main content

TrendAI™ Investigación Profunda

chispa

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

Read article
AIExploits & Zero-Days
Unveiling AI Agent Vulnerabilities Part V: Securing LLM Services

To conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.

Read Article
Cyber crimeExploits & Zero-DaysBotnets
The Rise of Residential Proxies as a Cybercrime Enabler

This research discusses how residential proxies help cybercriminals bypass antifraud and IT security systems, and how vulnerabilities in the IoT supply chain are exploited where Android-based devices are shipped pre-infected.

Read Article
AIExploits & Zero-Days
Unveiling AI Agent Vulnerabilities Part IV: Database Access Vulnerabilities

How can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.

Read Article
AIExploits & Zero-Days
Unveiling AI Agent Vulnerabilities Part III: Data Exfiltration

In the third part of our series we demonstrate how risk intensifies in multi-modal AI agents, where hidden instructions embedded within innocuous-looking images or documents can trigger sensitive data exfiltration without any user interaction.

Read Article
AIExploits & Zero-Days
Unveiling AI Agent Vulnerabilities Part II: Code Execution

Our research examines vulnerabilities that affect Large Language Model (LLM) powered agents with code execution, document upload, and internet access capabilities. This is the second part of a series diving into the critical vulnerabilities in AI agents.

Read Article
AIExploits & Zero-Days
Unveiling AI Agent Vulnerabilities Part I: Introduction to AI Agent Vulnerabilities

This introductory post kicks off a blog series on AI agent vulnerabilities, outlining key security risks like prompt injection and code execution, and sets the stage for future parts, which will dive deeper into issues such as code execution flaws, data exfiltration, and database access threats.

Read Article
Cybercriminal undergroundPhishing & BECDeepfakes
The Ever-Evolving Threat of the Russian-Speaking Cybercriminal Underground

We dive into one of the most sophisticated and impactful ecosystems within the global cybercrime landscape. Our research looks at tools and techniques, specialized forums, popular services, plus a deeply ingrained culture of secrecy and collaboration.

Read Article
Cyber crime
From Registries to Private Networks: Threat Scenarios Putting Organizations in Jeopardy

Stolen certificates and private keys could be weaponized by cybercriminals to penetrate a company’s system. Our research investigates how these scenarios would play out, how they affect the organizations, and how to prevent such attacks.

Read Article
Social engineering
The Future of Social Engineering

Social engineering is a tactic that, at its core, creates a false narrative to exploit a victim’s credulity, greed, curiosity, or any other very human characteristics. Attackers continue to enhance existing social engineering and use new technologies.

Read Article
Ransomware & extortion
Ransomware Spotlight: Water Ouroboros

Water Ouroboros (aka Hunters International) is a Ransomware-as-a-Service (RaaS) group that first emerged in October 2023. It is suspected to be a possible spin-off of Hive ransomware, which had its activities disrupted by the Federal Bureau of Investigation (FBI) in January 2023.

Read Article