The Boardroom Debate: How Cyber Risk Hits Your Bottom Line
You don’t need to be an expert to use cyber risk quantification. TrendAI™ automates data collection to deliver real-time financial risk insights and clear next steps for remediation.

You don’t need to be an expert to use cyber risk quantification. TrendAI™ automates data collection to deliver real-time financial risk insights and clear next steps for remediation.
OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.
TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.
A new cryptocurrency-mining bot is spreading through Facebook Messenger. We named this Digmine based on the moniker (비트코인 채굴기 bot) it was referred to in a report of recent related incidents in South Korea.
On January 24, 2018, we observed that the number of Coinhive web miner detections tripled due to a malvertising campaign. Attackers seem to have abused Google’s DoubleClick, which provides internet ad serving services, for traffic distribution.
A new variant of Android Remote Access Tool can inject root exploits to perform malicious tasks such as silent installation, shell command execution, WiFi password collection, and more. It targets CVE-2015-1805, a vulnerability disclosed in 2016.
As users start to look for apps and other services from their banks, opportunities for scammers also increase. One recent example of this is the app Movil Secure, part of a SMiShing scheme targeting Spanish-speaking users.
We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. Some of these have been downloaded millions of times.
We uncovered an updated Bashlite malware designed to add infected internet-of-things devices to a distributed-denial-of-service (DDoS) botnet. Based on the Metasploit module it exploits, the malware targets devices with the WeMo UPnP API.
Further investigation led us to a developer’s Xcode project that contained XCSSET source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits.
We discovered vulnerabilities in the SHAREit application. These vulnerabilities can be abused to leak a user’s sensitive data, execute arbitrary code, and possibly lead to remote code execution. The app has over 1 billion downloads.
What tactics do Instagram account hackers use? What do these cybercriminals do with stolen accounts? How can users protect their accounts? We look into Instagram account hacking incidents from a security researcher’s perspective and share recommendations for users of Instagram and other social media platforms.