Skip to main content

TrendAI™ 深入研究

火花

Featured Articles

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation
AIOT & critical infrastructure

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

Read article
Cloud security
Exposed Container Registries: A Potential Vector for Supply-Chain Attacks

In this entry, we will discuss publicly exposed registries, which are repositories or databases containing information accessible to the public without the need for authentication.

Read Article
By The NumbersRansomware & extortion
LockBit, BlackCat, and Clop Prevail as Top RAAS Groups: Ransomware in 1H 2023

We delve into three of the most active ransomware families that dominated the first half of 2023: LockBit, Clop, and BlackCat. This report features data from ransomware-as-a-service (RaaS) and extortion groups’ leak sites, Trend Micro’s open-source intelligence (OSINT) research, and the Trend Micro™ Smart Protection Network™, collected from Jan. 1 to June 30, 2023.

Read Article
Diving Deep Into Quantum Computing: Modern Cryptography

In our first installment of a four-part series on post-quantum cryptography, we discuss contemporary cryptography and what defenders should know when it comes to developing a quantum-resistant cryptography plan.

Read Article
Machine learning
Uncovering Silent Threats in Azure Machine Learning Service: Part 2

In our previous entry, we examined how credentials were being stored and logged in cleartext on compute instances (CIs) created in Azure Machine Learning (AML) service and the risks posed by the same. This article examines an information disclosure bug we found in one of the cloud agents used in the AML service and sheds light on the importance of threat modeling the agents’ features to uncover silent and hidden attack surfaces.

Read Article
Machine learning
Uncovering Silent Threats in Azure Machine Learning Service: Part I

We probed the Azure Machine Learning (AML) service to identify security flaws and vulnerabilities and shed light on the unseen aspects of silent threats in managed services like AML.

Read Article
AICybercriminal underground
Hype vs. Reality: AI in the Cybercriminal Underground

This report discusses the state of generative artificial intelligence (AI) in the cybercriminal underground: how cybercriminals are using ChatGPT, how they're adding ChatGPT features to their criminal products, and how they’re trying to remove censorship to ask ChatGPT anything.

Read Article
Cybersecurity Under Strain of SecOps Pain Points

In this first installment in our series on the challenges of the cybersecurity industry, we explore the underlying causes of the workforce gaps that have long plagued SOC teams.

Read Article
Cyber crimeExploits & Zero-Days
A Closer Exploration of Residential Proxies and CAPTCHA-Breaking Services

This article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.

Read Article
Ransomware & extortionExploits & Zero-Days
Ransomware Spotlight: Play

Play is shaping up to be a player on the rise within the ransomware landscape, with its operators likely to continue using the ransomware in future. We take a deep dive into its operations and offer ways in which organizations can shore up their defenses against this emerging threat.

Read Article
IoT & smart devices
A Deep Dive into the Packet Reflection Vulnerability Allowing Attackers to Plague Private 5G Networks

The lack of encryption and authentication mechanisms in the GTP-U protocol between base stations and 5GC UPFs could allow cybercriminals to use a packet reflection vulnerability to carry out attacks on 5G devices in internal networks.

Read Article