Skip to main content

TrendAI™ Deep Research

spark

注目のリサーチ記事

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

産業インフラを脅かすもの:フロンティアAIが変えるリスクの構図

失うわけにはいかない重要なシステムが、攻撃者の標的になっています。AIを利用した新世代のサイバー脅威によって、かつては数週間あった対処の猶予が、わずか数時間に縮まる可能性があります。社会を支える産業の脅威は今どのような状況にあり、組織はどうすれば防御を強化できるのでしょうか。本レポートでは、これらの問いを検討します。

Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoTとスマートデバイスASM ASRM
外部アタックサーフェスの再考:公開サイバー・フィジカルデータがもたらす増大するリスクへの対応

中国との関連が疑われるオペレーショナルリレーボックス(ORB)インフラストラクチャが、公開されたセンサーデータを大規模に収集しているものの、多くの組織はその実態を把握できていません。本レポートでは、これらのORBがデータ収集などの目的で公開テレメトリをどのように利用し得るかを掘り下げます。

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
ハクティビズムランサムウェアと恐喝
産業インフラを標的とする犯罪経済の全体像

TrendAI™ Researchは、工場、公益事業、エネルギー企業へのアクセスが売買され、武器化されるフォーラム、マーケットプレイス、Telegramチャネルの内部を調査しました。2年分のデータを精査した結果、金銭目的のアクセスブローカーやランサムウェアグループが、国家との関連が疑われるハクティビストと同じ場で活動し、同じ侵入経路と同じ海賊版トレーニングを共有し、場合によっては人員までも共有しているアンダーグラウンドの実態が明らかになりました。

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Security 101: Virtual Patching
エクスプロイトとゼロデイ
セキュリティ101:仮想パッチ

パッチが適用されていない、または脆弱性を抱えるアプリケーションや組織のITインフラは、どのようなリスクにさらされるのでしょうか。本記事では、企業の脆弱性管理とパッチ管理にまつわる課題を仮想パッチがどのように解決するのかを解説します。

TrendAI™ Research
Read article
サイバー犯罪
Metaverse or Metaworse? How the Apple Vision Pro Stacks Up Against Predictions

In 2022, Trend Micro conducted extensive research to understand potential cyber threats to the metaverse amid significant global changes and a growing focus on AI technologies. The release of Apple's Apple Vision Pro headset a year later provided an opportunity to evaluate these predictions, highlighting both advancements and persistent challenges in areas such as data privacy, biometric security, and multi-vendor interoperability.

Read Article
サイバープロパガンダマルウェア
Understanding Hacktivists: The Overlap of Ideology and Cybercrime

Hacktivist groups are driven by a political or ideological agenda. In the past, their actions were likened to symbolic, digital graffiti. Nowadays, hacktivist groups resemble urban gangs. Previously composed of low-skilled individuals, these groups have evolved into medium- to high-skill teams, often smaller in size but far more capable.

Read Article
サイバー犯罪アンダーグラウンド
Across the Span of the Spanish Cybercriminal Underground: Current Activities and Trends

What does the present state of the Spanish-speaking cybercriminal underground look like? What are the most common scams and other illicit offerings peddled by cybercriminals? Unearth the secrets of the Spanish dark market in our research.

Read Article
ランサムウェアと恐喝RaaS(Ransomware as a Service)サイバー犯罪アンダーグラウンド
Ransomware Spotlight: Ransomhub

RansomHub is a young Ransomware-as-a-Service (RaaS) group tracked by Trend Micro as Water Bakunawa. Despite being a young ransomware group first detected in February 2024, RansomHub moves boldly by targeting larger enterprises more likely to pay ransoms.

Read Article
DevopsCloud security
Unleashing Chaos: Real World Threats Hidden in the DevOps Minefield

Threat actors are actively looking for exposed .env files. These files have become ticking bombs deeply rooted inside DevOps practices. Our research paper uncovers the hidden dangers in DevOps using real-world examples.

Read Article
サイバーリスクASM ASRMランサムウェアと恐喝
From Vulnerable to Resilient: Cutting Ransomware Risk with Proactive Cyber Risk Exposure Management

This article highlights the critical importance of reducing the Cyber Risk Index, presenting findings that establishes a significant correlation between higher Risk Indices and increased susceptibility to ransomware infections.

Read Article
AIデータプライバシーと規制
AI Assistants in the Future: Security Concerns and Risk Management

The article explores the evolving landscape of AI digital assistants, highlighting their transformative potential, associated security risks, and the importance of robust design and collaboration to ensure a secure and user-centric future.

Read Article
AI機械学習
Silent Sabotage: Weaponizing AI Models in Exposed Containers

How can misconfigurations help threat actors abuse AI to launch hard-to-detect attacks with massive impact? We reveal how AI models stored in exposed container registries could be tampered with— and how organizations can protect their systems.

Read Article
AIDeepfakes
AI vs AI: DeepFakes and eKYC

This analysis investigates the security risks of eKYC systems in relation to deepfake attacks, highlighting the diverse strategies employed by cybercriminals in bypassing eKYC security measures.

Read Article
IoTとスマートデバイスネットワーク
Cellular IoT Vulnerabilities: Another Door to Cellular Networks

Cellular IoT vulnerabilities show an increasing trend over the years, indicating that these devices are becoming more and more popular — and that they are being targeted more frequently.

Read Article