Skip to main content

TrendAI™
Blog de Seguridad

Blog de Seguridad de TrendAI

Blogs destacados

Malware
Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains

In this blog entry, researchers at TrendAI Vision One™ Services – Managed Detection and Response (MDR) walk through how attackers deliver, install, and operate a reconfigured ScreenConnect client, and why it slips past defenses built to catch conventional malware.

Read Article
Phishing & BEC
How AiTM Phishing Bypassed MFA to Hijack a Microsoft 365 Mailbox in BEC Scheme

One click on a targeted lure handed an attacker live Microsoft 365 session tokens, enough to impersonate a vendor and reroute payments. TrendAI Vision One™ Services – Managed Detection and Response (MDR) tracks the attack to its root cause.

Read Article
AIExploits & Zero-Days
La velocidad de la IA está cambiando el panorama de vulnerabilidades. Nuestro compromiso con CISA KEV no lo está.

TrendAI™ está profundizando su enfoque en el Catálogo CISA KEV como una señal comprobada de riesgo activo. Con IA, TrendAI™ combina la investigación de TrendAI™ ZDI, inteligencia de explotación, contexto de exposición y riesgo empresarial para impulsar la priorización continua asistida por IA, ayudando a los equipos de seguridad a tomar mejores decisiones y actuar más rápido.

Read Article
Exploits & Zero-Days
How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow

TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.

Read Article
Cyber crime
TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators

The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation that served criminal customers across four continents.

Read Article
OT & critical infrastructureMFA & authentication
Malicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know

Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.

Read Article
AI
Por qué importa la Alianza Abierta de IA Segura: Modelos de Frontera Abiertos, Flexibilidad de Despliegue Abierto

TrendAI se une a Nvidia como socio inaugural en la Open Secure AI Alliance, avanzando en modelos abiertos, arneses e investigación para fortalecer la defensa cibernética.

Read Article
AICyber threats
Dentro del incidente de OpenAI – Hugging Face: La brecha de IA sin atacante humano detrás de ella

Los propios modelos de OpenAI salieron de un entorno de prueba y entraron en los servidores de Hugging Face para resolver una evaluación, sin la intervención de un atacante humano. El incidente demostró que mantener la seguridad de la IA agente ahora depende de cómo se contiene, no solo de cómo se entrena.

Read Article
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet

47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw.

Read Article
AI
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables

An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.

Read Article