Sean Park
9 articles
-
Researchエージェント型AIを乗っ取る 第3回:AIエージェントを守るには
本記事は、「エージェント型AIを乗っ取る」三部作の最終回として、第2回で実証したリターン・トゥ・ツール(RTT)攻撃(「読み取り専用」Postgresのバイパス、サポートチケットを起点とするランサムウェア、本人確認(KYC)パスポートによる情報流出)に対する防御策を取り上げます。この新しいクラスの攻撃に対して、何が有効で何が有効でないのかを見ていきます。
August 6th, 2026 12 minSean Park
Read article -
Researchエージェント型AIを乗っ取る 第2回:信頼されたエージェントが信頼できない動作をするとき
リターン・トゥ・ツール(RTT)は机上の理論ではありません。TrendAI™ Researchは、侵害されたエージェントが承認済みのツールだけを使いながら、技術スタックで最も危険な構成要素へと変わる実態を、3つの事例を通じて明らかにします。
July 16th, 2026 13 minSean Park
Read article -
Researchエージェント型AIを乗っ取る 第1回:そのAIエージェントはすでに侵害されている
各企業はAIエージェントを自社のデータベース、文書処理パイプライン、社内ツールへと次々と接続しており、その結果、業務の一環として信頼できない入力を読み取る特権的なコンポーネントが生まれています。TrendAI™ Researchは、攻撃者がリターン・トゥ・ツール(RTT)エクスプロイトを通じて、こうしたエージェントをいかにユーザ自身に向ける武器へと転じさせるのか、そしてそれがエージェント型AIセキュリティの将来に何を意味するのかを検証していきます。
May 26th, 2026Sean Park
Read article -
ResearchSlopsquatting: When AI Agents Hallucinate Malicious Packages
Our research examines how AI coding assistants can hallucinate plausible but non-existent package names—therefore enabling slopsquatting attacks—while also providing practical defense strategies that organizations can implement to secure their development pipelines
June 5th, 2025Sean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part V: Securing LLM Services
To conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.
May 28th, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part IV: Database Access Vulnerabilities
How can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.
May 21st, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part III: Data Exfiltration
In the third part of our series we demonstrate how risk intensifies in multi-modal AI agents, where hidden instructions embedded within innocuous-looking images or documents can trigger sensitive data exfiltration without any user interaction.
May 12th, 2025Sean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part II: Code Execution
Our research examines vulnerabilities that affect Large Language Model (LLM) powered agents with code execution, document upload, and internet access capabilities. This is the second part of a series diving into the critical vulnerabilities in AI agents.
May 5th, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part I: Introduction to AI Agent Vulnerabilities
This introductory post kicks off a blog series on AI agent vulnerabilities, outlining key security risks like prompt injection and code execution, and sets the stage for future parts, which will dive deeper into issues such as code execution flaws, data exfiltration, and database access threats.
April 22nd, 2025 6 minSean Park, Principal Threat Researcher
Read article