Skip to main content

TrendAI™ Deep Research

spark

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure
Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

TrendAI™ Research
Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoT & smart devicesASM ASRM
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data

China-aligned operational relay box (ORB) infrastructure is harvesting open sensor data at scale, and most defenders can't see it. Our report dives into how these ORBs can use open telemetry for data collection and other purposes.

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
HacktivismRansomware & extortion
Mapping the Criminal Economy Targeting Critical Infrastructure

TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth of data revealed an underground where financially motivated brokers and ransomware crews now operate alongside state-aligned hacktivists, sharing the same entry vectors, the same pirated training, and in some cases, the same personnel.

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
AIDeepfakesCybercriminal underground
Surging Hype: An Update on the Rising Abuse of GenAI

The cybercriminal abuse of generative AI (GenAI) is developing at a blazing pace. After only a few weeks since we reported on Gen AI and how it is used for cybercrime, new key developments have emerged. Threat actors are proliferating their offerings on criminal large language models (LLMs) and deepfake technologies, ramping up the volume and extending their reach.

Read Article
AI
The Mirage of AI Programming: Hallucinations and Code Integrity

The adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.

Read Article
Emerging technologies
Post-Quantum Cryptography: Migrating to Quantum Resistant Cryptography

In the previous parts of this series, we have learned about cryptography, what makes quantum computers unique, and how quantum computers break this cryptography. In the fourth and final part of our study on post-quantum cryptography, we will look at quantum-resistant algorithms that could replace our existing cryptography.  

Read Article
Cloud security
Kong API Gateway Misconfigurations: An API Gateway Security Case Study

Tools that aggregate access into multiple different environments, such as API gateways, pose a security risk for all these environments upon breach. In this article, we continue our journey through the security issues of the API Gateway landscape. Our new research focuses on another popular API gateway — Kong.

Read Article
AICyber crime
Back to the Hype: An Update on How Cybercriminals Are Using GenAI

Generative AI continues to be misused and abused by malicious individuals. In this article, we dive into new criminal LLMs, criminal services with ChatGPT-like capabilities, and deepfakes being offered on criminal sites.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: LockBit

The LockBit intrusion set, tracked by Trend Micro as Water Selkie, has one of the most active ransomware operations today. With LockBit’s strong malware capabilities and affiliate program, organizations should keep abreast of its machinations to effectively spot risks and defend against attacks.

Read Article
Cloud security
Observability Exposed: Exploring Risks in Cloud-Native Metrics

Container Advisor (cAdvisor) is an open-source monitoring tool for containers that is widely used in cloud services. It logs and monitors metrics like network input/output (I/O), disk I/O, and CPU usage. However, misconfigured deployments might inadvertently expose sensitive information, including environment variables such as Prometheus metrics. In this article, we share our findings of the risks we have uncovered and the vulnerable configurations users need to be aware of.

Read Article
Ransomware & extortionPhishing & BEC
Ransomware Spotlight: 8Base

Despite positioning themselves as penetration testers, 8Base ransomware threat actors profit off their victims that are significantly comprised of small businesses. In this feature, we investigate how the gang operates to gain insights on how organizations can protect systems better from compromises that could result in financial loss.  

Read Article
Exploits & Zero-Days
Open RAN: Attack of the xApps

This article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handling

Read Article
Exploits & Zero-Days
Apache APISIX In-the-wild Exploitations: An API Gateway Security Study

This article focuses on the Apache APISIX API gateway and its security implications.

Read Article