Jeffrey Francis Bonaobra
7 articles
-
BlogWeaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.
April 3rd, 2026 18 minJacob Santos, Sophia Nilette Robles, Jeffrey Francis Bonaobra
Read article -
BlogUnraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp
Through AI-driven code conversion and a layered infection chain involving different file formats and scripting languages, the threat actors behind Water Saci are quickly upgrading their malware delivery and propagation methods across WhatsApp in Brazil.
December 2nd, 2025 16 minJeffrey Francis Bonaobra, Sarah Pearl Camiling, Joe Soares, Byron Gelera…
Read article -
BlogShai-hulud 2.0 蠕蟲攻擊鎖定雲端與開發環境
Shai-hulud 2.0 攻擊行動使用了一個精密的變種來竊取主要雲端平台及開發人員服務的登入憑證和機密,並透過自動化方式在受害者維護的 NPM 套件內植入後門。其進階手法使得它能在軟體供應鏈內部迅速擴散,造成無數的下游使用者陷入風險險。
November 27th, 2025 23 minJeffrey Francis Bonaobra
Read article -
Blog收到熟人傳來的 ZIP 壓縮檔?小心 WhatsApp 新病毒「SORVEPOTEL」正在竊資料!
TrendAI™ Research 發現了一個正在利用 ZIP 附件檔案並經由 WhatsApp 散布的惡意程式攻擊行動。惡意程式一旦執行,就會建立常駐機制,然後經由被駭入的 WhatsApp 帳號將自己複製並傳送給受害者的聯絡人。
October 3rd, 2025 15 minJeffrey Francis Bonaobra, Maristel Policarpio, Sophia Nilette Robles, Cj Arsley Mateo…
Read article -
Blog我們對 NPM 供應鏈攻擊的了解
TrendAI™ Research 分析了持續中的 NPM 供應鏈攻擊背後的關鍵細節,並提供一些防範其潛在入侵的必要步驟。
September 18th, 2025 9 minJeffrey Francis Bonaobra, Joshua Aquino
Read article -
BlogEvilAI 駭客集團利用 AI 生成的程式碼與假應用程式來發動大範圍的攻擊
EvilAI 集團結合了 AI 生成的程式碼與社交工程技巧,正在發動一波迅速擴大的攻擊行動,將其惡意程式偽裝成正常應用程式來躲避資安防護、竊取登入憑證,持續入侵全球企業。
September 11th, 2025 18 minJeffrey Francis Bonaobra, Joshua Aquino, Emmanuel Panopio, Emmanuel Roll…
Read article -
BlogWarlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments.
August 20th, 2025 14 minJeffrey Francis Bonaobra, Joshua Aquino, Mohammed Malubay, John Paul Lim…
Read article