Trend Micro Research : Articles, News, Reports

TrendAI™ Joins Nvidia’s Open Secure AI Alliance: Closing the Gap Between AI Builders and AI Defenders

TrendAI™ Joins Nvidia’s Open Secure AI Alliance: Closing the Gap Between AI Builders and AI Defenders 2026-07-30 at 19:25 By TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense. This article is an excerpt from Trend Micro Research, News and Perspectives […]

TrendAI™ Joins Nvidia’s Open Secure AI Alliance: Closing the Gap Between AI Builders and AI Defenders Read More »

Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility

Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility 2026-07-30 at 19:25 By TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility Read More »

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave 2026-07-30 at 04:47 By Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan. This

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave Read More »

The Signs Were There: What the First Autonomous Ransomware Case Confirms

The Signs Were There: What the First Autonomous Ransomware Case Confirms 2026-07-24 at 18:02 By An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to

The Signs Were There: What the First Autonomous Ransomware Case Confirms Read More »

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan 2026-07-24 at 03:07 By We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. This article is an excerpt from Trend Micro Research, News and

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan Read More »

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass 2026-07-22 at 22:34 By Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement. This article is

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass Read More »

Volume Is Not Risk: Making Sense of the “Vulnpocalypse”

Volume Is Not Risk: Making Sense of the “Vulnpocalypse” 2026-07-21 at 20:30 By A briefing for security leaders on separating vulnerability disclosure volume from exploitable risk in 2026. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Volume Is Not Risk: Making Sense of the “Vulnpocalypse” Read More »

Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet 2026-07-15 at 05:19 By TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11%

Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet Read More »

TONResolver RAT Abuses TON Blockchain to Target Japan’s Hotel Industry

TONResolver RAT Abuses TON Blockchain to Target Japan’s Hotel Industry 2026-06-30 at 00:33 By In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. This article is an excerpt from

TONResolver RAT Abuses TON Blockchain to Target Japan’s Hotel Industry Read More »

From Langflow to Monero: Inside CVE-2026-33017 Cryptominer

From Langflow to Monero: Inside CVE-2026-33017 Cryptominer 2026-06-23 at 17:26 By We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Read More »

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM 2026-06-19 at 06:49 By A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker’s PSIGW gateway to execute code inside the application server’s Java virtual machine (JVM), evading behavioral and network sensors. This article is an excerpt

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Read More »

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign 2026-06-18 at 05:51 By Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai’s own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware. This article

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Read More »

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go 2026-06-13 at 00:53 By TrendAI™ integrates the Claude Compliance API into TrendAI Vision One™ through two collectors that bring AI-aware visibility and detection to Claude Enterprise usage: one keeps all data inside the environment, while the other feeds TrendAI Vision One™ for deeper correlation and

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go Read More »

GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026

GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 2026-06-11 at 05:32 By This year’s Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed — and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath. This article is an

GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Read More »

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 2026-06-08 at 20:33 By Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships. This

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Read More »

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go 2026-06-08 at 20:33 By TrendAI™ integrates Anthropic’s Claude Compliance API into TrendAI Vision One™ through two collectors that bring AI-aware visibility and detection to Claude Enterprise usage: one keeps all data inside the environment, while the other feeds TrendAI Vision One™ for deeper correlation and

Governing Claude Enterprise in Environments Where Inline Controls Can’t Go Read More »

Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI’s Biggest AI Showdown Yet

Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI’s Biggest AI Showdown Yet 2026-06-01 at 20:16 By 47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here’s what we saw. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI’s Biggest AI Showdown Yet Read More »

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet 2026-05-26 at 17:32 By TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Read More »

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware 2026-05-23 at 06:34 By Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Read More »

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign 2026-05-21 at 13:14 By A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences. This article is an excerpt

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign Read More »

Scroll to Top