Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
AIOT & critical infrastructure
Agentic Edge AI: Development Tools and Workflows

Trend™ Research inspected agentic edge AI systems and the development tools and workflows they leverage and uncovered an intricate labyrinth that demands robust protection from cyberthreats.

Read Article
ランサムウェアと恐喝エクスプロイトとゼロデイ
Ransomware Spotlight: DragonForce

DragonForce, a Ransomware-as-a-Service group first observed in 2023, rose to greater prominence in 2025 after a series of notable attacks linked to the group. Despite its unclear origins, what is evident is its rapid evolution and its aggressive, affiliate-driven model, marking it as a rising threat to watch out for.

Read Article
AI大規模言語モデル(LLM)Cloud security
Stay Ahead of AI Threats: Secure LLM Applications With Trend Vision One

Trend Vision One™ tackles 9 of OWASP’s Top 10 LLM vulnerabilities, offering comprehensive protection against prompt injection, data leakage, AI supply chain risks, and other critical flaws.

Read Article
AIOT & critical infrastructure
Agentic Edge AI: Autonomous Intelligence on the Edge

Agentic edge AI offers enhanced advantages, but with this comes cybersecurity challenges. Learn more about agentic edge AI and its architecture, and equip your organization by examining related threats and mitigation strategies for these risks.

Read Article
Cloud security
Using Containers to Secure Your MCP Infrastructure

Security risks to MCP servers can be mitigated by running them within containers. This report discusses these security risks and how MCP containerization can implement least privilege in practice.

Read Article
サイバー犯罪Cloud
Complexity and Visibility Gaps in Power Automate

Amid the rise of low-code automation, Microsoft Power Automate is becoming an attractive target for cybercriminals exploiting its complexity to evade detection and exfiltrate data – but demand for compromised enterprise assets is outstripping supply in the cybercriminal underground.

Read Article
サイバー犯罪Generative AI
Do Security Blogs Enable Vibe-Coded Cybercrime?

Security companies routinely publish detailed analyses of security incidents, making attacker tactics, techniques, and procedures (TTPs) widely known and visible. These reports often provide comprehensive insights into specific vulnerabilities that are or could be exploited, malware delivery mechanisms, and evasion techniques.

Read Article
サイバー犯罪ソーシャルエンジニアリング
Unmasking Task Scams to Prevent Financial Fallout From Fraud

This report exposes the life cycle and tactics of task scams by presenting real-world cases as well as strategies to help identify and avoid these threats.

Read Article
Cloud securityIDおよびアクセス管理(IAM)
Beware of MCP Hardcoded Credentials: A Perfect Target for Threat Actors

Poor secret management in MCP servers can lead to serious consequences, including data breaches and supply chain attacks. This article examines the reality of these unsecure configurations and offers practical recommendations that minimize the chances of exposure.

Read Article
AI大規模言語モデル(LLM)AI governance
LLM as a Judge: Evaluating Accuracy in LLM Security Scans

As large language models (LLMs) become more capable and widely adopted, the risk of unintended or adversarial outputs grows, especially within a security-sensitive context. To identify and mitigate such risks, Trend Micro researchers ran LLM security scans that simulate adversarial attacks.

Read Article