Peter Girnus
11 articles
-
BlogRanked First on CyberGym: TrendAI™ Agentic Exploit-Remediation Engine Scores 97% on the Top Exploit Benchmark
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.
August 26th, 2026 3 minPeter Girnus
Read article -
BlogThe Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.
April 20th, 2026 29 minPeter Girnus
Read article -
BlogAxios NPM 套件遭駭客入侵:供應鏈攻擊瞄準每週超過 1 億次下載的 JavaScript HTTP 用戶端
駭客對 Axios 發動供應鏈攻擊,利用偷來的 npm 登入憑證發布含有幽靈相依元件的惡意版本,然後在安裝過程中觸發一個跨平台遠端存取木馬程式 (RAT),隨後將其檔案更換成乾淨的誘餌檔案來誤導調查,使它難以被偵測。
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogYour AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise
TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
BlogIntroducing the TrendAI™ Agentic Exploit-Remediation Engine: Finding Zero-Day Vulnerabilities at the Speed of AI
The TrendAI™ agentic exploit-remediation engine, code name AESIR, combines AI automation with expert oversight to discover zero-day vulnerabilities in AI infrastructure – 21 CVEs across NVIDIA, Tencent, and MLflow since mid-2025.
January 15th, 2026Peter Girnus
Read article -
BlogCVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation
CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article -
BlogCritical React Server Components Vulnerability CVE-2025-55182: What Security Teams Need to Know
CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components used in React.js, Next.js, and related frameworks (see the context section for a more exhaustive list of affected frameworks).
December 5th, 2025 3 minPeter Girnus
Read article -
BlogRondoDox:從鎖定 Pwn2Own 漏洞到無差別式攻擊利用
Trend Zero Day Initiative™ (ZDI) 和 Trend™ Research 團隊發現了一起大規模的 RondoDox 殭屍網路攻擊行動,駭客使用了 30 多家廠商的 50 多個漏洞,包括 Pwn2Own 競賽上首次揭露的漏洞。
October 9th, 2025 9 minDeep Patel, Ashish Verma, Simon Dulude, Peter Girnus
Read article -
BlogZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns
Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373 (aka ZDI-25-148), a Windows .lnk file vulnerability that enables hidden command execution.
March 18th, 2025 13 minPeter Girnus, Aliakbar Zahravi
Read article -
BlogBehind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
June 19th, 2024 18 minPeter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim
Read article -
BlogCVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
November 20th, 2023 5 minPeter Girnus
Read article