Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™ Deep Research

spark

注目のリサーチ記事

2026年上半期のAPT動向を分析: 「信頼」を武器化する攻撃者
APT
2026年上半期のAPT動向を分析: 「信頼」を武器化する攻撃者

国家との関連が疑われる攻撃者は、攻撃チェーンのあらゆる段階にAIを組み込みながら、防御側がすでに信頼しているサービスの内側に自らのインフラを潜ませています。本レポートでは、こうした活動を突き動かす地政学的背景と、防御側が次に優先すべき対策を読み解きます。

TrendAI™ Research
Read article
Expert data center IT technician upgrading hardware equipment
AI governance
ソブリンAIのセキュリティ確保:物理・ソフトウェア・モデルの各サプライチェーンにわたる実践的コントロール

ソブリンAIでは、セキュリティスタックのあらゆるレイヤーの責任が運用者の手に委ねられます。本記事では、この転換に伴う脅威と、国家が保有するAIシステムの信頼性を保つための実践的なコントロールをあわせて解説します。

Numaan Huq, David Girard
Read article
An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers
Cloud security
見えないアタックサーフェス:データセンター周辺で露出する数千台の産業制御システム

TrendAI™ Researchが米国のデータセンター周辺にあるICSプロトコルを調査したところ、冷却、電力、環境設備といった重要インフラを制御する数千台の脆弱なデバイスが見つかりました。運用効率を重視し、セキュリティを前提とせずに設計されたこれらのシステムは、公開インターネットからアクセス可能な状態にありました。

Stephen Hilt, Numaan Huq
Read article
Software supply chain
Unsecured AWS S3 Bucket Found Leaking Data of Over 30K Cannabis Dispensary Customers

An unsecured Amazon S3 bucket was found leaking the data of more than 30,000 individuals. It was discovered to have exposed 85,000 files that included records with sensitive personally identifiable information (PII).

Read Article
サイバー犯罪 エクスプロイトとゼロデイ
Malicious Script Plagues Over 2,000 WordPress Accounts, Redirects Visitors to Scam Sites

Over 2,000 WordPress sites were compromised by a malicious script that redirects visitors to scam sites, gains admin access, and installs fake plugins.

Read Article
フィッシングとBEC
NetWire RAT Hidden in IMG Files Deployed in BEC Campaign

A recent BEC campaign targets organizations by sending them emails with IMG (disk imaging) file attachments hiding a NetWire remote access trojan.

Read Article
サイバー犯罪
Sextortion Scheme Claims Use of Home Cameras, Demands Bitcoin or Gift Card Payment

A new sextortion scheme threatens to expose nude videos supposedly captured via victims' mobile phones and home cameras.

Read Article
OT & critical infrastructure
Fake Company, Real Threats: Logs From a Smart Factory Honeypot

To determine threat actors' degree of knowledge in compromising a smart factory, we deployed our most elaborate honeypot to date. The incidents we observed show the kinds of attacks that can easily affect poorly secured manufacturing environments.

Read Article
マルウェア Botnets 暗号資産
Cryptocurrency Miner Uses Hacking Tool Haiduc and App Hider Xhide to Brute Force Machines and Servers

The cryptocurrency-miner, a multi-component threat comprised of different Perl and Bash scripts, miner binaries, the application hider Xhide, and a scanner tool, propagates by scanning vulnerable machines and brute-forcing (primarily default) credentials.

Read Article
Botnets
Into the Battlefield: A Security Guide to IoT Botnets

We recap the history and recent campaigns of IoT botnets to help users defend against the different malware competing for control and resources of regular smart devices.

Read Article
IoTとスマートデバイス OT & critical infrastructure
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

We break down the digital attacks against the oil and gas industry and its supply chain.

Read Article
サイバー犯罪アンダーグラウンド
Cheats, Hacks, and Cyberattacks: Threats to the Esports Industry in 2019 and Beyond

Esports competitions continue to gain momentum, making the entities involved more attractive targets for cybercrime.

Read Article
ランサムウェアと恐喝 マルウェア
Putting the Eternal in EternalBlue: Mapping the Use of the Infamous Exploit

In 2017, EternalBlue was the driving force behind one of the nastiest ransomware outbreaks on record. And despite available fixes, it is still being used by malware today—from ransomware to widespread cryptocurrency miners.

Read Article