Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
AIサイバー犯罪
The Silent Leap: OpenAI’s New ChatGPT Agent Capabilities and Security Risks

OpenAI recently introduced ChatGPT agent. What are its capabilities and the associated cybersecurity risks? We examined these using Trend Micro’s Digital Assistant Framework to help organizations navigate the changes and risks this new digital assistant may bring.

Read Article
AISoftware supply chainゼロトラスト
The Road to Agentic AI: Navigating Architecture, Threats, and Solutions

As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.

Read Article
AI大規模言語モデル(LLM)サイバー犯罪
Exploiting Trust in Open-Source AI: The Hidden Supply Chain Risk No One Is Watching

As open-source AI models become foundational to digital infrastructure, hidden backdoors and tampered supply chains pose a growing, under-recognized threat that traditional security tools can fail to detect.

Read Article
エクスプロイトとゼロデイAIゼロトラスト
MCP Security: Network-Exposed Servers Are Backdoors to Your Private Data

Exposed MCP servers pose a risk for organizations utilizing them. Our research examined the types of concerns that emerge and how to keep systems safe through immediate and extended measures.

Read Article
AIDeepfakesフィッシングとBEC
Deepfake It ‘til You Make It: A Comprehensive View of the New AI Criminal Toolset

This report takes a comprehensive look at how deepfakes are used to support criminal business processes, what are the toolkits criminals are exploiting to power their deepfake creation, and what the deepfake underground looks like.

Read Article
ASM ASRMサイバー犯罪
Proactive Security: The Role of Exposure Management and Detection-Response Capability

Cyberattacks are growing increasingly sophisticated and frequent, which is why security strategies focused solely on detection and response are no longer sufficient. This reality brings renewed attention to the importance of identifying and mitigating cyber risks before incidents occur.

Read Article
AI大規模言語モデル(LLM)
The Road to Agentic AI: Defining a New Paradigm for Technology and Cybersecurity

Our latest research provides a framework for understanding agentic AI systems, outlines their core characteristics, and examines the security implications surrounding their use.

Read Article
AI大規模言語モデル(LLM)Software supply chain
Slopsquatting: When AI Agents Hallucinate Malicious Packages

Our research examines how AI coding assistants can hallucinate plausible but non-existent package names—therefore enabling slopsquatting attacks—while also providing practical defense strategies that organizations can implement to secure their development pipelines

Read Article
AIエクスプロイトとゼロデイ
Unveiling AI Agent Vulnerabilities Part V: Securing LLM Services

To conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.

Read Article
サイバー犯罪エクスプロイトとゼロデイBotnets
The Rise of Residential Proxies as a Cybercrime Enabler

This research discusses how residential proxies help cybercriminals bypass antifraud and IT security systems, and how vulnerabilities in the IoT supply chain are exploited where Android-based devices are shipped pre-infected.

Read Article