Skip to main content

TrendAI™
Security Blog

TrendAI Security Blog

Featured Blogs

Exploits & Zero-Days
How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow

TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.

Read Article
Cyber crime
TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators

The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation that served criminal customers across four continents.

Read Article
OT & critical infrastructure MFA & authentication
Malicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know

Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.

Read Article
AI
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility

TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.

Read Article
AI Cyber threats
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It

OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained.

Read Article
Cyber threats
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.

Read Article
APTs Targeted attacks
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups

PeckBirdy is a sophisticated JScript-based C&C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities.

Read Article
Exploits & Zero-Days
CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation

CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.

Read Article
LLMs
When Tokenizers Drift: Hidden Costs and Security Risks in LLM Deployments

A tokenizer lies at the core of every large language model. When it drifts, whether from unseen flaws or adversarial interference, costs rise and performance drops. We explore this emerging risk, its implications, and the measures to prevent it.

Read Article
Malware Phishing & BEC
Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users

TrendAI™ Research has identified an active campaign spreading via WhatsApp through a ZIP file attachment. When executed, the malware establishes persistence and hijacks the compromised WhatsApp account to send copies of itself to the victim’s contacts.

Read Article