TrendAI™
資安部落格

熱門文章
The Boardroom Debate: How Cyber Risk Hits Your Bottom Line
You don’t need to be an expert to use cyber risk quantification. TrendAI™ automates data collection to deliver real-time financial risk insights and clear next steps for remediation.
TrendAI™ Brings OpenAI's GPT Cyber Models Into the Race to Shrink Exposure Time to Zero
OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever.
ATF Reports Breach After Qilin Leak Site Appearance: Insights from TrendAI™
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.
搜尋部落格文章
Filter by:
Living Off Trusted Software: ScreenConnect Abuse Across Phishing, Search, and RMM Chains
In this blog entry, researchers at TrendAI Vision One™ Services – Managed Detection and Response (MDR) walk through how attackers deliver, install, and operate a reconfigured ScreenConnect client, and why it slips past defenses built to catch conventional malware.
不肖中間人 (AiTM) 網路釣魚如何避開多重認證 (MFA) 挾持 Microsoft 365 信箱從事變臉詐騙 (BEC)
點一下一個精心設計的誘餌,駭客就能拿到 Microsoft 365 連線階段權杖,這便足以讓駭客假冒廠商的名義變更其收款銀行資料。TrendAI Vision One™ Services – Managed Detection and Response (MDR) 追蹤了這起攻擊並找到了問題的源頭。
AI 的速度正在改變資安漏洞的情勢,但我們對 CISA KEV 的堅持不會改變
TrendAI™ 正進一步深度聚焦 CISA KEV (已知遭到攻擊的漏洞) 目錄,將它視為一種經過證實的活躍風險訊號。在 AI 的協助下,TrendAI™ 將 TrendAI™ ZDI 的研究、漏洞攻擊情資、曝險情況以及業務風險結合在一起,驅動 AI 輔助的持續性優先次序判斷,協助資安團隊做出更好的決策,更快採取行動。
TrendAI™ Research 如何協助解決 Dify 登入後流程中的開放式重導漏洞
TrendAI™ Research 在 Dify 的登入後流程中發現了一個可能讓剛通過認證的連線階段、權杖等等被轉交給駭客的開放式重導漏洞,並且與廠商合作,在漏洞細節公告之前將每一條登入途徑的漏洞都修正完成。
TrendAI™ Intelligence 協助執法機關逮捕 Tycoon 2FA 集團成員
新加坡警察部隊 (SPF) 與巴基斯坦國家網路犯罪調查局 (NCCIA) 以及國際刑警組織 (INTERPOL) 密切合作,逮捕了兩名與 Tycoon 2FA 相關的人士,該網路釣魚集團所服務的對象犯罪足跡遍及四大洲。
Malicious Cyber Activity Targeting US Water Utilities: What Operators Need To Know
Disruption reported across at least seven states, from equipment left accessible online. The issue is largely a matter of configuration and access control, and here's what to fix first.
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.
Agentic AI 資安啟示:OpenAI 模型繞過沙箱、入侵 Hugging Face 系統的完整分析
OpenAI 的模型自己逃出了沙箱模擬測試環境並入侵 Hugging Face 的伺服器,只為了完成一項評估測試。整個過程完全沒有人類介入。這起事件顯示,代理式 AI 的安全,現在不是單靠精進訓練方式就能維護,如何加以隔離也同樣重要。
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw.
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.