Deep Patel
8 articles
-
BlogInside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.
August 27th, 2026 30 minAhmed Mohamed Ibrahim, Ashish Verma, Deep Patel
Read article -
BlogTrendAI™ Advances Threat Hunting to Dynamic, Real-World Exploitation of AI Infrastructure
The new threat hunting component of the TrendAI™ agentic exploit-remediation engine, code name AESIR, extends visibility beyond vulnerability disclosure. Its first published investigation links over a year of honeypot data to the LF3 loader framework.
August 26th, 2026 20 minDeep Patel, Ashish Verma
Read article -
BlogYour AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise
TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
ResearchThe Industrialization of Botnets: Automation and Scale as a New Threat Infrastructure
Today’s botnet operations, enabled by automation and shared resources, are outpacing traditional response and patching models. This highlights the growing importance of security capabilities that can match the speed and scale of these attacks.
February 26th, 2026Ashish Verma, Deep Patel, Simon Dulude
Read article -
BlogCVE-2025-55182: Análise React2Shell, Caos de Prova de Conceito e Exploração em Ambiente Real
CVE-2025-55182 é um RCE de pré-autenticação com CVSS 10.0 que afeta os Componentes de Servidor React. Em meio à enxurrada de explorações de prova de conceito falsas, scanners, explorações e equívocos generalizados, esta análise técnica pretende cortar o ruído.
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article -
BlogRondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
October 9th, 2025 9 minDeep Patel, Ashish Verma, Simon Dulude, Peter Girnus
Read article -
ResearchExploiting Trust in Open-Source AI: The Hidden Supply Chain Risk No One Is Watching
As open-source AI models become foundational to digital infrastructure, hidden backdoors and tampered supply chains pose a growing, under-recognized threat that traditional security tools can fail to detect.
July 25th, 2025Ashish Verma, Deep Patel
Read article -
ResearchThe Mirage of AI Programming: Hallucinations and Code Integrity
The adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.
July 25th, 2024 6 minNitesh Surana, Ashish Verma, Deep Patel
Read article