Skip to main content

Perspectives sur les recherches

Gardez une longueur d'avance sur les menaces grâce à des recherches menées par des experts, à la veille sur les menaces et à des perspectives décisionnelles sur la cybersécurité.

image principale

Featured Articles

Cyber Crime Cloud Deep Dives Phishing and BEC Zero trust Misconfigurations General Markets
Complexity and Visibility Gaps in Power Automate

Amid the rise of low-code automation, Microsoft Power Automate is becoming an attractive target for cybercriminals exploiting its complexity to evade detection and exfiltrate data – but demand for compromised enterprise assets is outstripping supply in the cybercriminal underground.

Read Article
Cyber Crime Generative AI
Do Security Blogs Enable Vibe-Coded Cybercrime?

Security companies routinely publish detailed analyses of security incidents, making attacker tactics, techniques, and procedures (TTPs) widely known and visible. These reports often provide comprehensive insights into specific vulnerabilities that are or could be exploited, malware delivery mechanisms, and evasion techniques.

Read Article
Cyber Crime Social Engineering General Markets Cryptocurrency Research Features
Unmasking Task Scams to Prevent Financial Fallout From Fraud

This report exposes the life cycle and tactics of task scams by presenting real-world cases as well as strategies to help identify and avoid these threats.

Read Article
The Silent Leap: OpenAI’s New ChatGPT Agent Capabilities and Security Risks

OpenAI recently introduced ChatGPT agent. What are its capabilities and the associated cybersecurity risks? We examined these using Trend Micro’s Digital Assistant Framework to help organizations navigate the changes and risks this new digital assistant may bring.

Read Article
AI Cloud Network Deep Dives Software supply chain Misconfigurations Zero trust Information technology
The Road to Agentic AI: Navigating Architecture, Threats, and Solutions

As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.

Read Article
AI Cyber Crime Deep Dives Information technology Software supply chain Zero trust LLMS
Exploiting Trust in Open-Source AI: The Hidden Supply Chain Risk No One Is Watching

As open-source AI models become foundational to digital infrastructure, hidden backdoors and tampered supply chains pose a growing, under-recognized threat that traditional security tools can fail to detect.

Read Article
Exploits and Zero-Days AI Research Features Cloud Security Misconfigurations Information technology Zero trust
MCP Security: Network-Exposed Servers Are Backdoors to Your Private Data

Exposed MCP servers pose a risk for organizations utilizing them. Our research examined the types of concerns that emerge and how to keep systems safe through immediate and extended measures.

Read Article
AI Deep Dives Deepfakes Financial services Social Engineering Phishing and BEC
Deepfake It ‘til You Make It: A Comprehensive View of the New AI Criminal Toolset

This report takes a comprehensive look at how deepfakes are used to support criminal business processes, what are the toolkits criminals are exploiting to power their deepfake creation, and what the deepfake underground looks like.

Read Article
AI Deep Dives Emerging Technologies LLMS General Markets
The Road to Agentic AI: Defining a New Paradigm for Technology and Cybersecurity

Our latest research provides a framework for understanding agentic AI systems, outlines their core characteristics, and examines the security implications surrounding their use.

Read Article
AI Deep Dives Software supply chain LLMS Information technology
Slopsquatting: When AI Agents Hallucinate Malicious Packages

Our research examines how AI coding assistants can hallucinate plausible but non-existent package names—therefore enabling slopsquatting attacks—while also providing practical defense strategies that organizations can implement to secure their development pipelines

Read Article