Peter Girnus
11 articles
-
BlogRanked First on CyberGym: TrendAI™ Agentic Exploit-Remediation Engine Scores 97% on the Top Exploit Benchmark
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.
August 26th, 2026 3 minPeter Girnus
Read article -
BlogThe Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.
April 20th, 2026 29 minPeter Girnus
Read article -
BlogPacote NPM Axios Comprometido: Ataque à Cadeia de Suprimentos Atinge Cliente HTTP JavaScript com Mais de 100 Milhões de Downloads Semanais
Um ataque à cadeia de suprimentos atingiu a Axios quando invasores usaram credenciais npm roubadas para publicar versões maliciosas contendo uma dependência fantasma. Isso acionou um RAT multiplataforma durante a instalação e substituiu seus arquivos por iscas limpas, tornando a detecção desafiadora.
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogYour AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise
TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
BlogIntroducing the TrendAI™ Agentic Exploit-Remediation Engine: Finding Zero-Day Vulnerabilities at the Speed of AI
The TrendAI™ agentic exploit-remediation engine, code name AESIR, combines AI automation with expert oversight to discover zero-day vulnerabilities in AI infrastructure – 21 CVEs across NVIDIA, Tencent, and MLflow since mid-2025.
January 15th, 2026Peter Girnus
Read article -
BlogCVE-2025-55182: Análise React2Shell, Caos de Prova de Conceito e Exploração em Ambiente Real
CVE-2025-55182 é um RCE de pré-autenticação com CVSS 10.0 que afeta os Componentes de Servidor React. Em meio à enxurrada de explorações de prova de conceito falsas, scanners, explorações e equívocos generalizados, esta análise técnica pretende cortar o ruído.
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article -
BlogCritical React Server Components Vulnerability CVE-2025-55182: What Security Teams Need to Know
CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components used in React.js, Next.js, and related frameworks (see the context section for a more exhaustive list of affected frameworks).
December 5th, 2025 3 minPeter Girnus
Read article -
BlogRondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
October 9th, 2025 9 minDeep Patel, Ashish Verma, Simon Dulude, Peter Girnus
Read article -
BlogZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns
Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373 (aka ZDI-25-148), a Windows .lnk file vulnerability that enables hidden command execution.
March 18th, 2025 13 minPeter Girnus, Aliakbar Zahravi
Read article -
BlogBehind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
June 19th, 2024 18 minPeter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim
Read article -
BlogCVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
November 20th, 2023 5 minPeter Girnus
Read article