Skip to main content

TrendAI™
Blog de Segurança

Blog de Segurança TrendAI

Blogs em Destaque

AI Exploits & Zero-Days
The Speed of AI Is Changing the Vulnerability Landscape. Our Commitment to CISA KEV Isn’t.

TrendAI™ is deepening its focus on the CISA KEV Catalog as a proven signal of active risk. With AI, TrendAI™ combines TrendAI™ ZDI research, exploit intelligence, exposure context, and business risk to drive continuous, AI-assisted prioritization, helping security teams make better decisions and act faster.

Read Article
Exploits & Zero-Days
How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow

TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.

Read Article
Cyber crime
TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators

The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation that served criminal customers across four continents.

Read Article
OT & critical infrastructure MFA & authentication
Malicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know

Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.

Read Article
AI
Por que a Open Secure AI Alliance é Importante: Modelos de Fronteira Abertos, Flexibilidade de Implantação Aberta

TrendAI se junta à Nvidia como parceiro inaugural na Open Secure AI Alliance, avançando em modelos abertos, ferramentas e pesquisas para fortalecer a defesa cibernética.

Read Article
AI Cyber threats
Dentro do Incidente OpenAI – Hugging Face: A Violação de IA Sem Atacante Humano Por Trás

Os próprios modelos da OpenAI saíram de um ambiente de teste e invadiram os servidores da Hugging Face para resolver uma avaliação, sem a participação de um atacante humano. O incidente mostrou que manter a segurança da IA agente agora depende de como ela é contida, não apenas de como é treinada.

Read Article
AI
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables

An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.

Read Article
Cyber threats
Pacote NPM Axios Comprometido: Ataque à Cadeia de Suprimentos Atinge Cliente HTTP JavaScript com Mais de 100 Milhões de Downloads Semanais

Um ataque à cadeia de suprimentos atingiu a Axios quando invasores usaram credenciais npm roubadas para publicar versões maliciosas contendo uma dependência fantasma. Isso acionou um RAT multiplataforma durante a instalação e substituiu seus arquivos por iscas limpas, tornando a detecção desafiadora.

Read Article
Cyber crime
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM

Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows.

Read Article
Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations

Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI™. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying.

Read Article