Peter Girnus
11 articles
-
BlogCyberGymリーダーボードで首位:TrendAI™のエージェント型エクスプロイト修復エンジン、主要な脆弱性再現ベンチマークで97%を記録
TrendAI™による評価では、エージェント型エクスプロイト修復エンジン(コードネーム:AESIR)がCyberGymで97%を記録しました。同社が提出した結果はリーダーボードで首位となり、GPT-5.6 SolとClaude Mythos 5をいずれも12ポイント以上上回っています。モデル単体の性能ではなく、AIシステムのアーキテクチャが結果を左右したとしています。
August 26th, 2026 3 minPeter Girnus
Read article -
BlogVercel侵害:OAuthサプライチェーン攻撃がプラットフォーム環境変数に潜む見えにくいリスクを露呈
Vercelに対するOAuthサプライチェーン侵害により、信頼されたサードパーティ製アプリとプラットフォーム環境変数が、従来の防御をどのように回避し、被害範囲を拡大させ得るかが明らかになりました。本記事では、攻撃の連鎖、根底にある設計上のトレードオフ、そしてこの事案が現代のPaaSとソフトウェアサプライチェーンリスクについて何を示しているのかを考察します。
April 20th, 2026 29 minPeter Girnus
Read article -
BlogAxios NPMパッケージ侵害:週1億以上のダウンロードを誇るJavaScript HTTPクライアントにサプライチェーン攻撃
Axiosに対してサプライチェーン攻撃が発生し、攻撃者は盗まれたnpm認証情報を使用して悪意のあるバージョンを公開しました。このバージョンにはファントム依存関係が含まれており、インストール時にクロスプラットフォームのRATを起動し、その後、検出を困難にするために自身のファイルをクリーンなデコイに置き換えました。
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogAIゲートウェイがバックドアに:LiteLLMサプライチェーン侵害の内幕
サイバー犯罪グループTeamPCPは、これまでに公表された中でも特に高度で、複数のエコシステムにまたがるサプライチェーン攻撃を実行しました。この攻撃は開発者向けツール群に連鎖的に広がり、LiteLLMを侵害しました。その結果、AIプロキシサービスがAPIキーやクラウド認証情報を集約する特性ゆえに、上流の依存関係が侵害された場合、高い価値を持つ標的となることが明らかになりました。
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
BlogTrendAI™エージェント型エクスプロイト修復エンジンの登場:AIのスピードでゼロデイ脆弱性を発見
The TrendAI™ agentic exploit-remediation engine, code name AESIR, combines AI automation with expert oversight to discover zero-day vulnerabilities in AI infrastructure – 21 CVEs across NVIDIA, Tencent, and MLflow since mid-2025.
January 15th, 2026Peter Girnus
Read article -
BlogReact2Shell「CVE-2025-55182」の分析、PoCを巡る混乱と悪用の広がり
脆弱性「CVE-2025-55182」は、React Server Components に影響する、CVSS 10.0の事前認証型リモートコード実行の脆弱性です。多数に及ぶ偽の概念実証(PoC:Proof-of-Concept)、スキャナー、攻撃コード、誤解があふれる状況の中で、本稿ではこれらの実態について解説します。
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article -
BlogReact Server Componentsの重大な脆弱性「CVE-2025-55182」: セキュリティ担当者が押さえるべきポイント
脆弱性「CVE-2025-55182」は、React.js、Next.js、関連フレームワークで利用されるReact Server Components に影響する、認証不要のリモートコード実行脆弱性です。CVSS 10.0という非常に高い深刻度が割り当てられています。
December 5th, 2025 3 minPeter Girnus
Read article -
BlogRondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
October 9th, 2025 9 minDeep Patel, Ashish Verma, Simon Dulude, Peter Girnus
Read article -
BlogZDI-CAN-25373: Windowsショートカットの未修正脆弱性を悪用するゼロデイ攻撃
トレンドマイクロのZero Day Initiative™(ZDI)は、ZDI-CAN-25373と識別されるWindowsの.lnkファイルの未修正の脆弱性が、国家背景の攻撃グループやサイバー犯罪組織によって以前から広範に悪用されていることを明らかにしました。この脆弱性を利用すると、隠れたコマンドの実行が可能になります。
March 18th, 2025 13 minPeter Girnus, Aliakbar Zahravi
Read article -
BlogBehind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
June 19th, 2024 18 minPeter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim
Read article -
BlogCVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
November 20th, 2023 5 minPeter Girnus
Read article