TrendAI™
보안 블로그

추천 블로그
The Boardroom Debate: How Cyber Risk Hits Your Bottom Line
You don’t need to be an expert to use cyber risk quantification. TrendAI™ automates data collection to deliver real-time financial risk insights and clear next steps for remediation.
TrendAI™ Brings OpenAI's GPT Cyber Models Into the Race to Shrink Exposure Time to Zero
OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever.
ATF Reports Breach After Qilin Leak Site Appearance: Insights from TrendAI™
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.
연구 논문 검색
Filter by:
Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains
In this blog entry, researchers at TrendAI Vision One™ Services – Managed Detection and Response (MDR) walk through how attackers deliver, install, and operate a reconfigured ScreenConnect client, and why it slips past defenses built to catch conventional malware.
How AiTM Phishing Bypassed MFA to Hijack a Microsoft 365 Mailbox in BEC Scheme
One click on a targeted lure handed an attacker live Microsoft 365 session tokens, enough to impersonate a vendor and reroute payments. TrendAI Vision One™ Services – Managed Detection and Response (MDR) tracks the attack to its root cause.
The Speed of AI Is Changing the Vulnerability Landscape. Our Commitment to CISA KEV Isn’t.
TrendAI™ is deepening its focus on the CISA KEV Catalog as a proven signal of active risk. With AI, TrendAI™ combines TrendAI™ ZDI research, exploit intelligence, exposure context, and business risk to drive continuous, AI-assisted prioritization, helping security teams make better decisions and act faster.
How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow
TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.
TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators
The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation that served criminal customers across four continents.
Malicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know
Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained.
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw.
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.