Skip to main content

TrendAI™ Deep Research

spark

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure
Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

TrendAI™ Research
Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoT & smart devicesASM ASRM
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data

China-aligned operational relay box (ORB) infrastructure is harvesting open sensor data at scale, and most defenders can't see it. Our report dives into how these ORBs can use open telemetry for data collection and other purposes.

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
HacktivismRansomware & extortion
Mapping the Criminal Economy Targeting Critical Infrastructure

TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth of data revealed an underground where financially motivated brokers and ransomware crews now operate alongside state-aligned hacktivists, sharing the same entry vectors, the same pirated training, and in some cases, the same personnel.

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Ransomware & extortionPhishing & BEC
Ransomware Spotlight: Rhysida

The threat actors behind the Rhysida ransomware targeted multiple industries by posing as a cybersecurity team that offered to help its victims identify security weaknesses in their networks and systems. Although the group’s activity was first observed back in May 2023, its leak site was established as early as March 2023. Like other ransomware groups, it employs double extortion tactics to pressure its victims into paying a ransom demand in Bitcoin.

Read Article
Cloud security
Enhancing Software Supply-Chain Security: Navigating SLSA Standards and the MITRE ATT&CK Framework

Attackers abuse different supply-chain scenarios to indirectly compromise organizations and applications. We delve into how a software pipeline works, where attacks could come from, and how to improve security.

Read Article
Diving Deep Into Quantum Computing: Computing With Quantum Mechanics

In this entry, the second in our series on post-quantum cryptography, we delve into the history of quantum computing, its foundation in quantum mechanics, and the kind of complex problems quantum computers will be able to solve.

Read Article
Threat Modeling API Gateways: A New Target for Threat Actors?

In this article, we dive into API gateway functions and risks, the advantages of API gateways in hybrid and multi-cloud environments, and common API security risks and best practices.

Read Article
Ransomware & extortion
Ransomware Spotlight: Trigona

After the shutdown of its leak site in October, we look at how ransomware group Trigona operated during its period of activity and discuss how enterprises can fortify their defenses against similar threats.

Read Article
Cloud security
Steering Clear of Security Blind Spots: What SOCs Need to Know

As technologies continue to evolve and expand, organizations experience a technological paradox: Their increasing interconnectivity means that they simultaneously become more distributed. Case in point, robust cloud and networking technologies support today’s widespread adoption of hybrid and remote work arrangements, allowing employees all over the globe to work remotely full time or at least part of the time.

Read Article
Cloud security
Understanding the Kubernetes Security Triad: Image Scanning, Admission Controllers, and Runtime Security

Kubernetes, also known as K8s, is a very complex open-source platform that requires detailed attention to security. Despite previous efforts to increase its security, Kubernetes remains insecure by default and requires different security tools to protect the cluster.

Read Article
IoT & smart devices
Preempting Threats to Connected Cars: The Importance of Cybersecurity in a Data-Driven Automotive Ecosystem

We examine the automotive data ecosystem and take a closer look at privacy and security concerns arising from how data is generated, consumed, and transmitted by connected vehicles.

Read Article
Cyber crime
Your Stolen Data for Sale

In today’s rapidly evolving digital landscape, the risk of personal and professional data being stolen by nefarious actors looms larger than ever. This report lays bare the stark reality of this threat, with a specific focus on the unequal risks associated with data theft and its subsequent misuse.

Read Article
Cloud securitySoftware supply chain
A Deep Dive Into Kubernetes Threat Modeling

This report explores the aspects and considerations required to properly perform threat modeling within a Kubernetes environment, a piece of technology that many organizations worldwide rely on and a leading container orchestration platform.

Read Article