Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
AIエクスプロイトとゼロデイ
Unveiling AI Agent Vulnerabilities Part IV: Database Access Vulnerabilities

How can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.

Read Article
AIエクスプロイトとゼロデイ
Unveiling AI Agent Vulnerabilities Part III: Data Exfiltration

In the third part of our series we demonstrate how risk intensifies in multi-modal AI agents, where hidden instructions embedded within innocuous-looking images or documents can trigger sensitive data exfiltration without any user interaction.

Read Article
AIエクスプロイトとゼロデイ
Unveiling AI Agent Vulnerabilities Part II: Code Execution

Our research examines vulnerabilities that affect Large Language Model (LLM) powered agents with code execution, document upload, and internet access capabilities. This is the second part of a series diving into the critical vulnerabilities in AI agents.

Read Article
AIエクスプロイトとゼロデイ
Unveiling AI Agent Vulnerabilities Part I: Introduction to AI Agent Vulnerabilities

This introductory post kicks off a blog series on AI agent vulnerabilities, outlining key security risks like prompt injection and code execution, and sets the stage for future parts, which will dive deeper into issues such as code execution flaws, data exfiltration, and database access threats.

Read Article
サイバー犯罪アンダーグラウンドフィッシングとBECDeepfakes
The Ever-Evolving Threat of the Russian-Speaking Cybercriminal Underground

We dive into one of the most sophisticated and impactful ecosystems within the global cybercrime landscape. Our research looks at tools and techniques, specialized forums, popular services, plus a deeply ingrained culture of secrecy and collaboration.

Read Article
サイバー犯罪
From Registries to Private Networks: Threat Scenarios Putting Organizations in Jeopardy

Stolen certificates and private keys could be weaponized by cybercriminals to penetrate a company’s system. Our research investigates how these scenarios would play out, how they affect the organizations, and how to prevent such attacks.

Read Article
ソーシャルエンジニアリング
The Future of Social Engineering

Social engineering is a tactic that, at its core, creates a false narrative to exploit a victim’s credulity, greed, curiosity, or any other very human characteristics. Attackers continue to enhance existing social engineering and use new technologies.

Read Article
ランサムウェアと恐喝
Ransomware Spotlight: Water Ouroboros

Water Ouroboros (aka Hunters International) is a Ransomware-as-a-Service (RaaS) group that first emerged in October 2023. It is suspected to be a possible spin-off of Hive ransomware, which had its activities disrupted by the Federal Bureau of Investigation (FBI) in January 2023.

Read Article
AICloud security
AI in the Crosshairs: Understanding and Detecting Attacks on AWS AI Services with Trend Vision One™

This article offers a fresh perspective on AI security, emphasizing that while core AI models are often the focus, the surrounding infrastructure and cloud services are equally critical to securing AI applications, particularly with the rise of AI-as-a-Service.

Read Article
AI
CES 2025: A Comprehensive Look at AI Digital Assistants and Their Security Risks

In this entry, we mapped the capabilities of various AI digital assistants that were showcased at CES 2025 based on an assessment matrix we developed to determine how this emerging technology holds up against potential security threats.

Read Article