Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
Cloud security
Azure Cloudの「使い終わった名前」が悪用されるリスク:ダングリング状態のリソースがサプライチェーン攻撃を誘発

Azureリソースを削除しても、DNS名はコードベースに残ることがあります。攻撃者が同じDNS名を再取得すれば、元の信頼性を逆手にサプライチェーン攻撃を仕掛ける恐れがあります。

Read Article
AI大規模言語モデル(LLM)
Guarding LLMs With a Layered Prompt Injection Representation

TrendAI™ Research has developed a model training procedure for learning an essential representation of prompt injection attacks. The resulting prompt representation exhibits approximately linear separability, allowing the specialized, small-scale classifier trained on features derived from the representation to achieve high classification performance.

Read Article
AI governance
無秩序から統治へ:エージェント型AIにおけるガバナンスギャップの解消

エージェント型AIは、エンタープライズシステム全体において自律的な行動と意思決定を可能にするという、根本的な変化をもたらします。一方で、これまでにない複雑なリスクも新たに生じます。TrendAI™のAgentic Governance Gatewayは、この新たな領域においてエージェント型AIの理解・制御・信頼を可能にし、安全かつ確信を持って活用できるよう支援します。

Read Article
サイバー犯罪Deepfakes
Unconventional Attack Surfaces: Identity Replication via Employee Digital Twins

In this second installment of a series exploring emerging AI-driven attack surfaces, TrendAI™ Research focuses on employee digital twins: AI replicas of employees that create new vectors for identity compromise, data exfiltration, and persistent access.

Read Article
AIエクスプロイトとゼロデイ
Old Vulnerabilities, New AI Era, Amplified Risk: How Outdated Flaws Continue to Fuel the N-Day Exploit Market

Even as AI adoption accelerates, old exploits remain overlooked weaknesses. Underground trends show a renewed demand for exploits, with cybercriminals relying on aging but still effective vulnerabilities. We examine this blind spot and why long-standing issues need to be addressed.

Read Article
ランサムウェアと恐喝サイバー犯罪
Ransomware Spotlight: Agenda

Agenda has rapidly grown into one of the most prolific and dangerous ransomware operations, leveraging advanced techniques, cross-platform variants, and alliances with other major threat groups. Its aggressive double-extortion model and expanding victim base across critical industries make it a serious enterprise risk that demands proactive detection and defense.

Read Article
Cloud securityDevops
Cracking the Isolation: Novel Docker Desktop VM Escape Techniques Under WSL2

TrendAI™ Research has discovered several new methods that enable attackers to escape Docker Desktop's WSL2 VM and run arbitrary code on the host. Our analysis highlights how trusted development tooling can create unexpected attack surfaces when internal APIs and configuration mechanisms are left exposed.

Read Article
Cloud security
Azure Control Plane Threat Detection With TrendAI Vision One™

Malicious access to the Azure control plane can lead to a cascade of assaults that can be disastrous and difficult to detect. TrendAI Vision One™ helps protect the Azure control plane through early threat identification and rapid response.

Read Article
サイバーリスクランサムウェアと恐喝
Forecasting Future Outbreaks: A Behavioral and Predictive Approach to Proactive Cyber Risk Management

TrendAI™ Research has found that user behaviors and machine usage patterns are key drivers of malware risk. This study’s analysis of over 10 million endpoints confirms that risk is highly context-dependent and offers insights into how organizations can pivot to improve their security posture.

Read Article
サイバー犯罪Botnets
The Industrialization of Botnets: Automation and Scale as a New Threat Infrastructure

Today’s botnet operations, enabled by automation and shared resources, are outpacing traditional response and patching models. This highlights the growing importance of security capabilities that can match the speed and scale of these attacks.

Read Article