Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
AI標的型攻撃
From Holiday Snap to Custom Scam in 30 Minutes: How AI Turns Public Photos Into Targeted Attacks

AI now enables attackers to rapidly convert publicly shared personal images into scalable, highly targeted phishing intelligence, turning everyday online photos into a significant and often overlooked security risk for individuals and enterprises.

Read Article
AIソーシャルエンジニアリング
LinkedInの公開データが30分で標的型攻撃に転用されるリスク:AIが標的分析を高速化

AI駆動の公開情報分析により、SNSなどでの個人投稿が自動で回収、解釈されるようになりました。結果、標的毎に特化した攻撃がさらに大規模化、自動化する恐れがあります。

Read Article
AIサイバー脅威
Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation

TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.

Read Article
AIサイバー脅威
重要分野に広がるAIスキルという新たなアタックサーフェス:拡張される能力と増大するリスク

AIスキルは、AIが持つ潜在的な能力と現実の業務運用との間をつなぐ存在です。しかし、その橋渡しを担うがゆえに、新たなリスクや攻撃の入口も同時に生み出します。本稿では、AIスキルを導入していくうえで直面する課題を丁寧に見つめ直しながら、安全に展開していくための実践的な枠組みについて考えていきます。

Read Article
AIAI governance
How Unmanaged AI Adoption Puts Your Enterprise at Risk

We challenge assumptions about AI models by revealing real-world biases and limitations, and the impact of poorly managed AI adoptions.

Read Article
AIサイバーリスク
Estimating Future Risk Outbreaks at Scale in Real-World Deployments

Trend™ Research introduces a novel system that leverages AI and behavioral analytics to proactively estimate the risk of future malware outbreaks based on users’ behavior to help organizations strategically strengthen their defenses.

Read Article
AIサイバー犯罪サイバー犯罪アンダーグラウンド
The Next Phase of Cybercrime: Agentic AI and the Shift to Autonomous Criminal Operations

We dive into the transformation from “Cybercrime-as-a-Service“ to “Cybercrime-as-a-Sidekick“, which fundamentally alters the operational dynamics of criminal enterprises.

Read Article
ソーシャルエンジニアリングAIサイバー犯罪
Reimagining Fraud Operations: The Rise of AI-Powered Scam Assembly Lines

Trend™ Research replicated an AI-powered scam assembly line to reveal how AI is eradicating the barrier for entry to running scams, making fraud easier to run, harder to detect, and effortless to scale.

Read Article
サイバー犯罪大規模言語モデル(LLM)マルウェア
The Devil Reviews Xanthorox: A Criminal-Focused Analysis of the Latest Malicious LLM Offering

Xanthorox AI: flirty, menacing, and potentially devastating? We explored the inner workings of this LLM to unveil its devious capabilities for generating malicious code, obtaining private information, and roleplaying.

Read Article
AI大規模言語モデル(LLM)ゼロトラスト
AI Security Starts Here: The Essentials for Every Organization

AI’s rapid growth brings new risks as well as opportunities. Strong security foundations are essential to ensure innovation remains safe, compliant, and resilient.

Read Article