Fernando Tucci
6 articles
-
BlogAIゲートウェイがバックドアに:LiteLLMサプライチェーン侵害の内幕
サイバー犯罪グループTeamPCPは、これまでに公表された中でも特に高度で、複数のエコシステムにまたがるサプライチェーン攻撃を実行しました。この攻撃は開発者向けツール群に連鎖的に広がり、LiteLLMを侵害しました。その結果、AIプロキシサービスがAPIキーやクラウド認証情報を集約する特性ゆえに、上流の依存関係が侵害された場合、高い価値を持つ標的となることが明らかになりました。
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
BlogAIスタックのルートキー漏洩の可能性:litellmのPyPI侵害の実態
litellmのPyPI侵害を解説します。侵害されたバージョンがクラウド認証情報、SSHキー、Kubernetesシークレットを窃取します。影響と緊急の対処方法を確認してください。
March 25th, 2026 6 minFernando Tucci
Read article -
BlogCISOs in a Pinch: A Security Analysis of OpenClaw
Learn about OpenClaw (a sovereign agent) and how this can be viable for enterprises.
March 10th, 2026 5 minFernando Tucci
Read article -
Blog拡散するAIと不可視のリスク:OpenClawが描き出すエージェント型アシスタントの現在
OpenClaw(別名:Clawdbot、Moltbot)は、エージェント型AIの新たな局面を象徴する存在です。高い自律性と強力な機能を備えながら、驚くほど簡単に使えてしまう。今回の調査では、OpenClawの能力が従来のツールと比べてどのように進化しているのかを確認しつつ、エージェント型AIという枠組みそのものに内在するセキュリティリスクを明らかにします。
February 6th, 2026 14 minSalvatore Gariuolo, Vincenzo Ciancaglini, Fernando Tucci
Read article -
ResearchStay Ahead of AI Threats: Secure LLM Applications With Trend Vision One
Trend Vision One™ tackles 9 of OWASP’s Top 10 LLM vulnerabilities, offering comprehensive protection against prompt injection, data leakage, AI supply chain risks, and other critical flaws.
October 14th, 2025 4 minFernando Cardoso, Dave McDuff, Fernando Tucci, Kim Kinahan…
Read article -
ResearchThe Road to Agentic AI: Navigating Architecture, Threats, and Solutions
As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.
July 28th, 2025Fernando Tucci, Vincenzo Ciancaglini, Marco Balduzzi, Salvatore Gariuolo…
Read article