Skip to main content

TrendAI™ Deep Research

spark

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure
Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

TrendAI™ Research
Read article
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data
IoT & smart devicesASM ASRM
Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data

China-aligned operational relay box (ORB) infrastructure is harvesting open sensor data at scale, and most defenders can't see it. Our report dives into how these ORBs can use open telemetry for data collection and other purposes.

Fyodor Yarochkin, Vladimir Kropotov, Robert McArdle
Read article
An industrial worker inspecting a warehouse
HacktivismRansomware & extortion
Mapping the Criminal Economy Targeting Critical Infrastructure

TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth of data revealed an underground where financially motivated brokers and ransomware crews now operate alongside state-aligned hacktivists, sharing the same entry vectors, the same pirated training, and in some cases, the same personnel.

Mayra Rosario Fuentes, Stephen Hilt, Numaan Huq
Read article
Malware
How BPF-Enabled Malware Works: Bracing for Emerging Threats

We discuss proof-of-concept rootkits and malware used by cybercriminals in conjunction with Berkeley Packet Filtering (BPF), a piece of technology that allows programs to execute code in the operating systems of popular cloud-computing platforms. We also show how to detect such threats.

Read Article
Cloud security
Mining Through Mountains of Information and Risk: Containers and Exposed Container Registries

In this entry, we continue delving into an investigation of exposed registries and look at the types of files and information that malicious actors can access and compromise from these.

Read Article
MQTT and M2M: Do You Know Who Owns Your Machine’s Data?

In our research, we demonstrate how easy it is to discover insecure deployments of MQTT, how to identify customers of these insecure deployments, what data is being transmitted, and explore how an attacker can potentially misuse the data or abuse the insecurity of MQTT brokers.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: Akira

This report spotlights Akira, a novel ransomware family with highly experienced and skilled operators at its helm.

Read Article
Cloud security
Exposed Container Registries: A Potential Vector for Supply-Chain Attacks

In this entry, we will discuss publicly exposed registries, which are repositories or databases containing information accessible to the public without the need for authentication.

Read Article
By The NumbersRansomware & extortion
LockBit, BlackCat, and Clop Prevail as Top RAAS Groups: Ransomware in 1H 2023

We delve into three of the most active ransomware families that dominated the first half of 2023: LockBit, Clop, and BlackCat. This report features data from ransomware-as-a-service (RaaS) and extortion groups’ leak sites, Trend Micro’s open-source intelligence (OSINT) research, and the Trend Micro™ Smart Protection Network™, collected from Jan. 1 to June 30, 2023.

Read Article
Diving Deep Into Quantum Computing: Modern Cryptography

In our first installment of a four-part series on post-quantum cryptography, we discuss contemporary cryptography and what defenders should know when it comes to developing a quantum-resistant cryptography plan.

Read Article
Machine learning
Uncovering Silent Threats in Azure Machine Learning Service: Part 2

In our previous entry, we examined how credentials were being stored and logged in cleartext on compute instances (CIs) created in Azure Machine Learning (AML) service and the risks posed by the same. This article examines an information disclosure bug we found in one of the cloud agents used in the AML service and sheds light on the importance of threat modeling the agents’ features to uncover silent and hidden attack surfaces.

Read Article
Machine learning
Uncovering Silent Threats in Azure Machine Learning Service: Part I

We probed the Azure Machine Learning (AML) service to identify security flaws and vulnerabilities and shed light on the unseen aspects of silent threats in managed services like AML.

Read Article
AICybercriminal underground
Hype vs. Reality: AI in the Cybercriminal Underground

This report discusses the state of generative artificial intelligence (AI) in the cybercriminal underground: how cybercriminals are using ChatGPT, how they're adding ChatGPT features to their criminal products, and how they’re trying to remove censorship to ask ChatGPT anything.

Read Article