Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
ランサムウェアと恐喝
Reveton Ransomware Descendant, CryptXXX Discovered

A new ransomware strain, CryptXXX, was recently discovered making its rounds since the tail-end of March.

Read Article
Locky Ransomware Strain Led Kentucky Hospital to an “Internal State of Emergency”

Kentucky-based Methodist Hospital announced a ransomware attack that led to an “internal state of emergency.”

Read Article
The Angler Connection: Massive Malvertising Campaign Linked to Angler Exploit Kit and BEDEP

Top news sites, entertainment portals, and political commentary sites were affected by a massive malvertising campaign related to the Angler Exploit Kit.

Read Article
IoTとスマートデバイス
Internet of Things: Connected Life Security

The world is now more connected than ever. Gartner predicts 25 billion connected devices will be in use by 2020. How is this increased convenience affecting our privacy and security across the globe?

Read Article
ランサムウェアと恐喝
New Crypto-Ransomware Locky Uses Malicious Word Macros

A new crypto-ransomware type called Locky has been discovered riding on document-based macros and using infection techniques borrowed from the notorious banking malware DRIDEX.

Read Article
サイバー犯罪
Frequently Asked Questions: BlackEnergy

What we know about BlackEnergy, a Trojan known to have been used in attacks on Ukraine power providers that caused a massive outage in late 2015.

Read Article
サイバー犯罪標的型攻撃
Operation Pawn Storm: Fast Facts and the Latest Developments

Operation Pawn Storm is an active economic and political cyber-espionage operation that has targeted high-profile entities from government institutions to media personalities. Here are its latest developments.

Read Article
サイバー犯罪アンダーグラウンド
Ascending the Ranks: The Brazilian Cybercriminal Underground in 2015

Trend Micro's latest visit to the Brazilian cybercriminal underground reveals its latest trends and available services, from online banking malware to tutorial classes for new cybercriminals.

Read Article
フィッシングとBEC
Security 101: Business Email Compromise (BEC) Schemes

The Federal Bureau of Investigation (FBI) released a public service announcement earlier this year warning about Business Email Compromise (BEC) schemes. Here’s what you need to know, and what you can do to prevent attacks.

Read Article
OT & critical infrastructure
First Malware-Driven Power Outage Reported in Ukraine

Malware found in power suppliers' systems may be responsible for causing a massive power outage in Ukraine.

Read Article