Stephen Hilt
11 articles
-
Research見えないアタックサーフェス:データセンター周辺で露出する数千台の産業制御システム
TrendAI™ Researchが米国のデータセンター周辺にあるICSプロトコルを調査したところ、冷却、電力、環境設備といった重要インフラを制御する数千台の脆弱なデバイスが見つかりました。運用効率を重視し、セキュリティを前提とせずに設計されたこれらのシステムは、公開インターネットからアクセス可能な状態にありました。
August 8th, 2026 43 minStephen Hilt, Numaan Huq
Read article -
Researchサイバー犯罪者は企業の内部関係者に何を求めているのか
内部不正の実行者となる内部関係者の需要と供給は、散発的な機会主義的犯行から、ブローカー、リクルーター、紹介報酬、保証人サービス、収益分配の取り決めまで揃った、構造化された活発な犯罪市場へと進化しています。本リサーチでは、この市場をさまざまな業界にわたって検証します。
August 4th, 2026Mayra Rosario Fuentes, Stephen Hilt, David Sancho
Read article -
BlogTrendAI™のインテリジェンスが法執行機関による「Tycoon 2FA」運営者の逮捕に貢献
シンガポール警察(SPF)は、パキスタンの国家サイバー犯罪捜査庁(NCCIA)およびINTERPOL(国際刑事警察機構)と緊密に連携し、4つの大陸にまたがる犯罪者顧客にサービスを提供していたフィッシング事業「Tycoon2FA」に関与した2名を逮捕しました。
August 4th, 2026Christopher Boyton, Stephen Hilt
Read article -
Researchアンダーグラウンドで取引される医療データエコノミー
本ブログ記事では、流出した医療データが取引され、悪用・武器化される産業化された犯罪エコシステムの実態に迫ります。ランサムウェア攻撃によるデータ侵害を起点に、初期アクセスブローカーによるアクセス権の取引や偽造診断書を用いた保険詐欺などへと連鎖して拡大し続ける犯罪サプライチェーンが形成されています。
June 4th, 2026Stephen Hilt, Numaan Huq, Mayra Rosario Fuentes
Read article -
BlogEuropol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations
Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI™. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying.
March 4th, 2026 7 minChristopher Boyton, Mayra Rosario Fuentes, Stephen Hilt
Read article -
ResearchThreat Attribution Framework: How TrendAI™ Applies Structure Over Speculation
TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.
February 12th, 2026 15 minStephen Hilt
Read article -
ResearchThe Next Phase of Cybercrime: Agentic AI and the Shift to Autonomous Criminal Operations
We dive into the transformation from “Cybercrime-as-a-Service“ to “Cybercrime-as-a-Sidekick“, which fundamentally alters the operational dynamics of criminal enterprises.
December 9th, 2025 6 minStephen Hilt, Robert McArdle
Read article -
ResearchComplexity and Visibility Gaps in Power Automate
Amid the rise of low-code automation, Microsoft Power Automate is becoming an attractive target for cybercriminals exploiting its complexity to evade detection and exfiltrate data – but demand for compromised enterprise assets is outstripping supply in the cybercriminal underground.
September 7th, 2025Stephen Hilt, Vladimir Kropotov, Dr. Fyodor Yarochkin, Benjamin Zigh
Read article -
ResearchAI Assistants in the Future: Security Concerns and Risk Management
The article explores the evolving landscape of AI digital assistants, highlighting their transformative potential, associated security risks, and the importance of robust design and collaboration to ensure a secure and user-centric future.
December 6th, 2024 15 minVincenzo Ciancaglini, Salvatore Gariuolo, Stephen Hilt, Robert McArdle…
Read article -
ResearchThe Future of Ransomware
Our research looks at the potential evolutions and revolutions in the current ransomware landscape based on significant triggers and catalysts. We highlight the specific developments (triggers) that could cause gradual changes (evolutions) before sparking more drastic transformations (revolutions).
December 15th, 2022 9 minFeike Hacquebord, Stephen Hilt, David Sancho
Read article -
ResearchUncovering IoT Threats in the Cybercrime Underground
Understanding current and future threats to the internet of things (IoT) can help shape how we secure this technology that is increasingly becoming integral to today's world. What insights can be reaped from the cybercrime underground?
September 10th, 2019 3 minStephen Hilt, Vladimir Kropotov, Fernando Mercês, Mayra Rosario…
Read article