<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TrendAI™ Deep Research</title><description>In-depth cybersecurity research and reports from the TrendAI team</description><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/</link><language>ja</language><atom:link href="https://www.trendaisecurity.com/ja/resources-insights/deep-research/rss.xml" rel="self" type="application/rss+xml"/><item><title>各国のAIエコシステムから世界のAPTサイバー脅威へ</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/from-state-ai-ecosystems-to-global-apt-cyberthreats</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/from-state-ai-ecosystems-to-global-apt-cyberthreats</guid><description>TrendAI™ Researchは、国家との関連が疑われるAPTによるAI導入を左右する、各国固有の力学と要因を分析しました。中国、ロシア、北朝鮮、イランの4か国を取り上げ、それぞれの国と関連が疑われる攻撃者が、なぜ現在のような形でAIを導入しているのかを明らかにします。</description><pubDate>Tue, 06 Oct 2026 13:00:00 GMT</pubDate><dc:creator>Asako Koizumi</dc:creator><category>AI</category><category>サイバー犯罪</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/ddee3304016ea8ca4c579b3cf01accc1ef0c1032-1920x800.jpg" length="352235" type="image/jpeg"/></item><item><title>Scarecrow：攻撃者のAIに「ノー」と言わせる</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/scarecrow-making-the-attackers-ai-say-no</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/scarecrow-making-the-attackers-ai-say-no</guid><description>文書を取り込むAIエージェントに処理を中止させる拒否命令を隠すツール「Scarecrow」を開発しました。検証の結果、同じ手法が、AIを利用して機密文書へアクセスする攻撃を妨害する防御策として有効であることが分かりました。</description><pubDate>Wed, 30 Sep 2026 19:48:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/febb914ec96d985b4ad768392dfb16bff37c8d8e-1920x800.jpg" length="197649" type="image/jpeg"/></item><item><title>リスクへの処方箋：医療分野における生成AIのサイバーセキュリティリスク</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/prescription-for-risk-the-cybersecurity-hazards-of-genai-in-healthcare</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/prescription-for-risk-the-cybersecurity-hazards-of-genai-in-healthcare</guid><description>生成AIは今や、診療メモを作成し、患者への返信文を起草し、保険請求の可否まで判断しています。その進歩は、医療機関の監督体制が追いつけないほどの速さです。TrendAI™ Researchは、生成AIが作り出した情報が患者記録に入り込む過程で生じる「責任の空白（custody gap）」と、それが診察室からバックオフィスまでにもたらすリスクを明らかにします。</description><pubDate>Wed, 30 Sep 2026 11:35:00 GMT</pubDate><dc:creator>Numaan Huq</dc:creator><category>AI</category><category>ヘルスケア・ライフサイエンス</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/8e83a1079c20edf78de758fd6a5bbdf058f9d798-1920x1280.jpg" length="325106" type="image/jpeg"/></item><item><title>自律するAIの時代：AIエージェントのサイバーリスクと実践的ガバナンス</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-enterprise-guide-to-governing-autonomous-ai-agents</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-enterprise-guide-to-governing-autonomous-ai-agents</guid><description>本レポートでは、企業がAIエージェントを導入・活用する際に検討すべきセキュリティとガバナンスの課題を取り上げます。AIエージェントに特有のリスク構造を整理し、AI導入を支えるセキュリティの枠組みと、技術的・組織的な統制の方法を示します。</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Sean Park</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/993d0ce79e65d721bf35a77452873e7e677bd711-1920x1280.jpg" length="215752" type="image/jpeg"/></item><item><title>AIxploit：偶然うまくいく言い回しからアタックサーフェスの地図へ</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/aixploit-from-lucky-phrasing-to-a-map-of-the-attack-surface</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/aixploit-from-lucky-phrasing-to-a-map-of-the-attack-surface</guid><description>TrendAI™ Researchチームは、攻撃テストを通じてエージェントのAIネイティブなアタックサーフェスを体系的に可視化するフレームワーク「AIxploit」を開発しました。</description><pubDate>Thu, 24 Sep 2026 15:40:00 GMT</pubDate><dc:creator>Sean Park</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/46549ca9fc4b58bf1a86ed3bd2fc50bf32871884-1920x800.jpg" length="202502" type="image/jpeg"/></item><item><title>2026年上半期AIセキュリティレポート ～ 高速化と大規模化に潜む代償 ～</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/1h-2026-state-of-ai-security</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/1h-2026-state-of-ai-security</guid><description>AIが従来型セキュリティの失敗を加速させ、見慣れた脅威の検知と封じ込めが難しくなっている理由</description><pubDate>Thu, 24 Sep 2026 03:36:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/05903cb403ec49b11df0ab13c14c2ba46ed6ef4c-1920x800.jpg" length="296602" type="image/jpeg"/></item><item><title>OpenClawのセキュリティ分析：大規模なエージェント型AIに潜むリスク</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/openclaw-security-analysis-the-hidden-risks-of-agentic-ai-at-scale</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/openclaw-security-analysis-the-hidden-risks-of-agentic-ai-at-scale</guid><description>本記事では、インターネットに公開されたOpenClawの環境、平文で保存される認証情報、プロンプトインジェクション、制御のないMCP連携、悪意あるサードパーティ製スキルが、企業規模で運用するエージェント型AIのセキュリティリスクをどう高めるかを検証します。</description><pubDate>Mon, 21 Sep 2026 01:00:00 GMT</pubDate><dc:creator>David Fiser</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/8265dbabe7def3b2ba5aa3f5fe0da5636d1e25dd-1920x800.jpg" length="264047" type="image/jpeg"/></item><item><title>産業インフラを脅かすもの：フロンティアAIが変えるリスクの構図</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/critical-infrastructure-under-threat-how-frontier-ai-changes-the-risk-equation</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/critical-infrastructure-under-threat-how-frontier-ai-changes-the-risk-equation</guid><description>失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。</description><pubDate>Wed, 16 Sep 2026 08:16:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>AI</category><category>OT &amp; critical infrastructure</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/fc29926ae4c787b1efa52693f709be417ad796f4-1920x800.jpg" length="214152" type="image/jpeg"/></item><item><title>外部アタックサーフェスの再考：公開サイバー・フィジカルデータがもたらす増大するリスクへの対応</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/rethinking-the-external-attack-surface-managing-the-growing-risk-of-open-cyber-physical-data</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/rethinking-the-external-attack-surface-managing-the-growing-risk-of-open-cyber-physical-data</guid><description>中国との関連が疑われるオペレーショナルリレーボックス（ORB）インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。</description><pubDate>Thu, 10 Sep 2026 00:15:00 GMT</pubDate><dc:creator>Fyodor Yarochkin</dc:creator><category>IoTとスマートデバイス</category><category>ASM ASRM</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/23b3982d991418792a601ecfe6105098521beaf8-1920x800.jpg" length="220682" type="image/jpeg"/></item><item><title>産業インフラを標的とする犯罪経済の全体像</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/mapping-the-criminal-economy-targeting-critical-infrastructure</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/mapping-the-criminal-economy-targeting-critical-infrastructure</guid><description>TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。</description><pubDate>Wed, 02 Sep 2026 13:00:00 GMT</pubDate><dc:creator>Mayra Rosario Fuentes</dc:creator><category>ハクティビズム</category><category>ランサムウェアと恐喝</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/fa2f4cd31511e2449f7793d76360d933a9ef6859-1920x1280.jpg" length="552184" type="image/jpeg"/></item><item><title>セキュリティ101：仮想パッチ</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/security-101-virtual-patching</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/security-101-virtual-patching</guid><description>パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。</description><pubDate>Tue, 25 Aug 2026 09:39:05 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>エクスプロイトとゼロデイ</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/6867acdc85792be02ebf7b5e9ef2ac02d644c96c-1920x800.jpg" length="172866" type="image/jpeg"/></item><item><title>2026年上半期のAPT動向を分析: 「信頼」を武器化する攻撃者</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/2026-h1-apt-report-how-apts-are-weaponizing-trust-in-the-age-of-ai</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/2026-h1-apt-report-how-apts-are-weaponizing-trust-in-the-age-of-ai</guid><description>国家との関連が疑われる攻撃者は、攻撃チェーンのあらゆる段階にAIを組み込みながら、防御側がすでに信頼しているサービスの内側に自らのインフラを潜ませています。本レポートでは、こうした活動を突き動かす地政学的背景と、防御側が次に優先すべき対策を読み解きます。</description><pubDate>Thu, 20 Aug 2026 02:31:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>APT</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/6b4e50016f4009568373919df9ac08a0a5ce004e-1920x800.jpg" length="453548" type="image/jpeg"/></item><item><title>ソブリンAIのセキュリティ確保：物理・ソフトウェア・モデルの各サプライチェーンにわたる実践的コントロール</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/securing-sovereign-ai-practical-controls-across-physical-software-and-model-supply-chains</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/securing-sovereign-ai-practical-controls-across-physical-software-and-model-supply-chains</guid><description>ソブリンAIでは、セキュリティスタックのあらゆるレイヤーの責任が運用者の手に委ねられます。本記事では、この転換に伴う脅威と、国家が保有するAIシステムの信頼性を保つための実践的なコントロールをあわせて解説します。</description><pubDate>Tue, 11 Aug 2026 05:31:00 GMT</pubDate><dc:creator>Numaan Huq</dc:creator><category>AI governance</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/1169e8258d69bf1db580fb410be683bc8b812745-1920x1280.jpg" length="423547" type="image/jpeg"/></item><item><title>見えないアタックサーフェス：データセンター周辺で露出する数千台の産業制御システム</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/an-invisible-attack-surface-thousands-of-industrial-control-systems-exposed-near-data-centers</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/an-invisible-attack-surface-thousands-of-industrial-control-systems-exposed-near-data-centers</guid><description>TrendAI™ Researchが米国のデータセンター周辺にあるICSプロトコルを調査したところ、冷却、電力、環境設備といった重要インフラを制御する数千台の脆弱なデバイスが見つかりました。運用効率を重視し、セキュリティを前提とせずに設計されたこれらのシステムは、公開インターネットからアクセス可能な状態にありました。</description><pubDate>Sat, 08 Aug 2026 00:30:00 GMT</pubDate><dc:creator>Stephen Hilt</dc:creator><category>Cloud security</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/19e50d26996bbdec22090fdaf38189c025a34ec5-1920x1280.jpg" length="317012" type="image/jpeg"/></item><item><title>エージェント型AIを乗っ取る 第3回：AIエージェントを守るには</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/pwning-agentic-ai-part-iii-securing-your-ai-agent</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/pwning-agentic-ai-part-iii-securing-your-ai-agent</guid><description>本記事は、「エージェント型AIを乗っ取る」三部作の最終回として、第2回で実証したリターン・トゥ・ツール（RTT）攻撃（「読み取り専用」Postgresのバイパス、サポートチケットを起点とするランサムウェア、本人確認（KYC）パスポートによる情報流出）に対する防御策を取り上げます。この新しいクラスの攻撃に対して、何が有効で何が有効でないのかを見ていきます。</description><pubDate>Thu, 06 Aug 2026 09:00:00 GMT</pubDate><dc:creator>Sean Park</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/f54778e83f1a747e004fdb44164ac9121b75d780-1920x1280.jpg" length="372299" type="image/jpeg"/></item><item><title>サイバー犯罪者は企業の内部関係者に何を求めているのか</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/what-cybercriminals-look-for-in-corporate-insiders</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/what-cybercriminals-look-for-in-corporate-insiders</guid><description>内部不正の実行者となる内部関係者の需要と供給は、散発的な機会主義的犯行から、ブローカー、リクルーター、紹介報酬、保証人サービス、収益分配の取り決めまで揃った、構造化された活発な犯罪市場へと進化しています。本リサーチでは、この市場をさまざまな業界にわたって検証します。</description><pubDate>Tue, 04 Aug 2026 15:52:00 GMT</pubDate><dc:creator>Mayra Rosario Fuentes</dc:creator><category>サイバー犯罪</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/404d97b61f10e85fd7ff69744da7ec76462ef747-1920x800.jpg" length="217185" type="image/jpeg"/></item><item><title>脆弱性対応の猶予は急速に狭まっている：CISAとファイブアイズが公共部門セキュリティについて今伝えていること</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-vulnerability-window-is-closing-quickly-what-cisa-and-five-eyes-now-say-about-public-sector-security</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-vulnerability-window-is-closing-quickly-what-cisa-and-five-eyes-now-say-about-public-sector-security</guid><description>CISAのBOD 26-04と新たなファイブアイズ共同声明は、脆弱性管理における同じ喫緊の課題を浮き彫りにしています。これらの動きが自組織のセキュリティプログラムに何を意味するのかを解説します。</description><pubDate>Thu, 23 Jul 2026 07:52:00 GMT</pubDate><dc:creator>Jon Clay</dc:creator><category>AI</category><category>サイバー脅威</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/3cfada1f8474478f92627a63f17529b44ea6d697-1920x1280.jpg" length="300271" type="image/jpeg"/></item><item><title>Modern Bank Heists 2026：金融の主導権をめぐるマシンスピードの攻防</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/modern-bank-heists-2026-the-machine-speed-war-for-financial-control</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/modern-bank-heists-2026-the-machine-speed-war-for-financial-control</guid><description>エージェント型AI、国家支援型の攻撃者、サービスとしてのサイバー犯罪（Cybercrime-as-a-Service）はいかにして金融セクターの防御を追い越しつつあるのか。そして、防御側はいかにしてマシンスピードで対抗できるのか。</description><pubDate>Wed, 22 Jul 2026 12:45:39 GMT</pubDate><dc:creator>Tom Kellermann</dc:creator><category>AI</category><category>サイバー犯罪</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/a01b3dbad132df08777dba7ab306477fb097161b-1500x962.webp" length="101684" type="image/webp"/></item><item><title>AIエージェントの共和国を統治する：AIエージェントがすでに必要としているフレームワーク</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/governing-the-republic-of-ai-agents</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/governing-the-republic-of-ai-agents</guid><description>AIエージェントは、ツールから組織における自律的な参加者へと進化しました。しかし、ガバナンスはその進化に追いついていません。TrendAI™は、このギャップを埋める6つの柱からなるフレームワークを提案します。</description><pubDate>Tue, 21 Jul 2026 06:33:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>AI</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/dfc3dc21d4e10c646c54b076381c0b3b24394e98-1920x1280.jpg" length="341200" type="image/jpeg"/></item><item><title>ソブリンAIの構築：基盤とアーキテクチャに関する技術的考察</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/building-sovereign-ai-technical-considerations-for-foundation-and-architecture</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/building-sovereign-ai-technical-considerations-for-foundation-and-architecture</guid><description>世界各国の政府が国内AIの開発に巨額の資金を投じています。しかし、ソブリンAI戦略づくりの競争は、主権の実現に本当は何が必要なのかという明確な理解を置き去りにして進んでいます。本リサーチは、政府や企業のリーダーに向けて、どの程度の主権が必要で、それがどこで最も重要になるのかを見極めるための、レイヤーごとの実践的なフレームワークを提示します。</description><pubDate>Mon, 20 Jul 2026 10:06:00 GMT</pubDate><dc:creator>Numaan Huq</dc:creator><category>AI governance</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/bc2ed7ab51a9effe85b6a213cdf871cc3159a93f-1920x800.jpg" length="145715" type="image/jpeg"/></item><item><title>エージェント型AIのシャドーパイプライン：信頼されたワークフローの背後に潜むアタックサーフェスをマッピングする</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/agentic-ais-shadow-pipeline-mapping-the-attack-surface-behind-trusted-workflows</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/agentic-ais-shadow-pipeline-mapping-the-attack-surface-behind-trusted-workflows</guid><description>企業がAIエージェントをクラウドインフラや本番ワークフローに接続するにつれ、クラウドからエージェントに至るパイプラインが主要なアタックサーフェスになりつつあります。本記事では、テクノロジー・メディア・通信業界の組織が直面するリスクを整理し、検知とセキュリティのベストプラクティスを解説します。</description><pubDate>Fri, 17 Jul 2026 08:12:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>AI</category><category>Cloud</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/ccbc856ce1a96bd640f2664304189c4e9c8d28d8-1200x800.webp" length="119030" type="image/webp"/></item><item><title>エージェント型AIを乗っ取る 第2回：信頼されたエージェントが信頼できない動作をするとき</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/pwning-agentic-ai-part-ii-when-trusted-agents-do-untrusted-things</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/pwning-agentic-ai-part-ii-when-trusted-agents-do-untrusted-things</guid><description>リターン・トゥ・ツール（RTT）は机上の理論ではありません。TrendAI™ Researchは、侵害されたエージェントが承認済みのツールだけを使いながら、技術スタックで最も危険な構成要素へと変わる実態を、3つの事例を通じて明らかにします。</description><pubDate>Thu, 16 Jul 2026 01:28:00 GMT</pubDate><dc:creator>Sean Park</dc:creator><category>AI</category><category>エクスプロイトとゼロデイ</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/78ade4d34146959b40b98a9bb86ab48ce04e897d-1920x1280.jpg" length="402865" type="image/jpeg"/></item><item><title>TrendAI™ 2026 サイバーリスクレポート</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/trendai-2026-cyber-risk-report</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/trendai-2026-cyber-risk-report</guid><description>2026年版サイバーリスクレポートは、前年の調査結果を拡充したテレメトリに基づいてまとめられており、攻撃者が到達する前に対処すべき重要なエクスポージャー（リスクにさらされている領域）の優先順位付けに役立つ、方向性を示す知見とデータを組織に提供します。</description><pubDate>Wed, 08 Jul 2026 08:53:00 GMT</pubDate><dc:creator>TrendAI™ Research</dc:creator><category>脅威レポート</category><category>サイバーリスク</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/c80f3d2a2c225839c3874768b7e467ee2c3a37c0-1920x800.jpg" length="189128" type="image/jpeg"/></item><item><title>スターの数では守れない：MCPエコシステムにおいて人気は安全性の証にはならない</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/stars-dont-save-you-popularity-is-not-security-in-the-mcp-ecosystem</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/stars-dont-save-you-popularity-is-not-security-in-the-mcp-ecosystem</guid><description>本リサーチでは、これまでの研究を踏まえ、公開されているMCPサーバで確認されたセキュリティ問題を、主要なディレクトリからクロールしたメタデータと突き合わせて分析しました。そのうえで、人気度・活動状況・審査の有無といった指標が、MCPサーバを採用する際のリスクを推し量る信頼できる尺度となり得るかを検証しました。</description><pubDate>Wed, 24 Jun 2026 03:02:00 GMT</pubDate><dc:creator>Vincenzo Ciancaglini</dc:creator><category>AI</category><category>エクスプロイトとゼロデイ</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/68d79e96092603bd2cca512ecefef81563a06415-1200x800.webp" length="63062" type="image/webp"/></item><item><title>攻撃者は既に内部にいる：NERC CIP-015が電力網の防御策を変える</title><link>https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-attackers-are-already-inside-nerc-cip-015-is-how-the-grid-fights-back</link><guid isPermaLink="true">https://www.trendaisecurity.com/ja/resources-insights/deep-research/the-attackers-are-already-inside-nerc-cip-015-is-how-the-grid-fights-back</guid><description>NERCのCIP-015は、バルク電力システムにおける内部ネットワークのセキュリティ監視を義務付けた初の基準です。本記事では、CIP-015で求められる要件、運用技術環境で対応が難しい理由、TrendAI™が各要件にどのように対応できるかを解説します。</description><pubDate>Mon, 22 Jun 2026 05:41:00 GMT</pubDate><dc:creator>Amruta Namjoshi</dc:creator><category>サイバー脅威</category><category>OT &amp; critical infrastructure</category><enclosure url="https://cdn.sanity.io/images/ch6z6vqj/production/77e0aeca62b9e51e0ec9f055b87a262751a37bdb-1200x801.webp" length="176804" type="image/webp"/></item></channel></rss>