Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™ Deep Research

spark

注目のリサーチ記事

2026年上半期のAPT動向を分析: 「信頼」を武器化する攻撃者
APT
2026年上半期のAPT動向を分析: 「信頼」を武器化する攻撃者

国家との関連が疑われる攻撃者は、攻撃チェーンのあらゆる段階にAIを組み込みながら、防御側がすでに信頼しているサービスの内側に自らのインフラを潜ませています。本レポートでは、こうした活動を突き動かす地政学的背景と、防御側が次に優先すべき対策を読み解きます。

TrendAI™ Research
Read article
Expert data center IT technician upgrading hardware equipment
AI governance
ソブリンAIのセキュリティ確保:物理・ソフトウェア・モデルの各サプライチェーンにわたる実践的コントロール

ソブリンAIでは、セキュリティスタックのあらゆるレイヤーの責任が運用者の手に委ねられます。本記事では、この転換に伴う脅威と、国家が保有するAIシステムの信頼性を保つための実践的なコントロールをあわせて解説します。

Numaan Huq, David Girard
Read article
An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers
Cloud security
見えないアタックサーフェス:データセンター周辺で露出する数千台の産業制御システム

TrendAI™ Researchが米国のデータセンター周辺にあるICSプロトコルを調査したところ、冷却、電力、環境設備といった重要インフラを制御する数千台の脆弱なデバイスが見つかりました。運用効率を重視し、セキュリティを前提とせずに設計されたこれらのシステムは、公開インターネットからアクセス可能な状態にありました。

Stephen Hilt, Numaan Huq
Read article
エクスプロイトとゼロデイ
Exposed Devices and Supply Chain Attacks: Overlooked Risks in Healthcare Networks

This research examines the oft-overlooked infection vectors in today’s healthcare networks: exposed medical devices and supply chain attacks.

Read Article
サイバー犯罪 フィッシングとBEC
InfoSec Guide: Domain Monitoring — Detecting Phishing Attacks (Part 1)

A lot of best practices teach users how to prevent or defend against phishing attacks, but how can organizations actively detect and thwart them before users even see them?

Read Article
サイバー犯罪
Tesla and Jenkins Servers Fall Victim to Cryptominers

Vulnerable enterprise servers are being compromised by individuals or groups looking for resources to mine cryptocurrency. The latest victims are automobile-maker Tesla and users of Jenkins servers.

Read Article
エクスプロイトとゼロデイ 標的型攻撃
North Korean Hackers Allegedly Exploit Adobe Flash Player Vulnerability (CVE-2018-4878) Against South Korean Targets

In a security alert posted on its website on January 31, The South Korean Computer Emergency Response Team (KR-CERT) warned of a zero-day vulnerability in Adobe Flash player that could be maliciously exploited.

Read Article
サイバー犯罪 ハクティビズム
Digital Vandals: Exploring the Methods and Motivations behind Web Defacement and Hacktivism

Activists have traditionally used physical signs and catchy slogans to promote their political agenda, but the internet offers a significantly broader audience, so these activities have since moved online.

Read Article
Delving into the World of Business Email Compromise (BEC)

We looked at BEC-related incidents over a span of nine months to see emerging and present trends from BEC incidents, examine the tools and techniques used by cybercriminals, and analyze the data to give us an overall picture of what BEC looks like today.

Read Article
エクスプロイトとゼロデイ
Meltdown and Spectre Intel Processor Vulnerabilities: What You Need to Know

Microsoft, Linux, Google, and Apple started rolling out patches addressing design flaws in processor chips that security researchers named Meltdown and Spectre. What are they, and how can they affect users?

Read Article
Cloud
Data on 123 Million US Households Exposed Due to Misconfigured AWS S3 Bucket

A year that saw major data breaches, including some notable ones from companies like Uber and Equifax, just saw another breach that will likely rank as among 2017’s most notable incidents.

Read Article
エクスプロイトとゼロデイ
17-Year Old MS Office Flaw (CVE-2017-11882) Actively Exploited in the Wild

Several threat actors are actively exploiting CVE-2017-11882 to deliver a plethora of threats, including the information-stealing Loki, Pony/FAREIT, and a lockscreen with a ransom note that resembles Bad Rabbit's.

Read Article
IoTとスマートデバイス
Cities Exposed in Shodan

Western European, UK, French, German, and US cities exposed. Are your connected devices searchable on the internet? Find out what you are risking.

Read Article