Deep Patel
8 articles
-
BlogSHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス
TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
August 27th, 2026 30 minAhmed Mohamed Ibrahim, Ashish Verma, Deep Patel
Read article -
BlogTrendAI™、脅威ハンティングを拡張し、AIインフラに対する実環境での悪用を動的に観測
TrendAI™のエージェント型エクスプロイト修復エンジン「AESIR」に、新たな脅威ハンティングコンポーネントが加わりました。脆弱性の開示後も可視性を維持し、1年以上にわたるハニーポットのデータを、ローダフレームワーク「LF3」へと結び付けた初の調査結果を紹介します。
August 26th, 2026 20 minDeep Patel, Ashish Verma
Read article -
BlogAIゲートウェイがバックドアに:LiteLLMサプライチェーン侵害の内幕
サイバー犯罪グループTeamPCPは、これまでに公表された中でも特に高度で、複数のエコシステムにまたがるサプライチェーン攻撃を実行しました。この攻撃は開発者向けツール群に連鎖的に広がり、LiteLLMを侵害しました。その結果、AIプロキシサービスがAPIキーやクラウド認証情報を集約する特性ゆえに、上流の依存関係が侵害された場合、高い価値を持つ標的となることが明らかになりました。
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
ResearchThe Industrialization of Botnets: Automation and Scale as a New Threat Infrastructure
Today’s botnet operations, enabled by automation and shared resources, are outpacing traditional response and patching models. This highlights the growing importance of security capabilities that can match the speed and scale of these attacks.
February 26th, 2026Ashish Verma, Deep Patel, Simon Dulude
Read article -
BlogReact2Shell「CVE-2025-55182」の分析、PoCを巡る混乱と悪用の広がり
脆弱性「CVE-2025-55182」は、React Server Components に影響する、CVSS 10.0の事前認証型リモートコード実行の脆弱性です。多数に及ぶ偽の概念実証(PoC:Proof-of-Concept)、スキャナー、攻撃コード、誤解があふれる状況の中で、本稿ではこれらの実態について解説します。
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article -
BlogRondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
October 9th, 2025 9 minDeep Patel, Ashish Verma, Simon Dulude, Peter Girnus
Read article -
ResearchExploiting Trust in Open-Source AI: The Hidden Supply Chain Risk No One Is Watching
As open-source AI models become foundational to digital infrastructure, hidden backdoors and tampered supply chains pose a growing, under-recognized threat that traditional security tools can fail to detect.
July 25th, 2025Ashish Verma, Deep Patel
Read article -
ResearchThe Mirage of AI Programming: Hallucinations and Code Integrity
The adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.
July 25th, 2024 6 minNitesh Surana, Ashish Verma, Deep Patel
Read article