Trend Micro Research : Endpoints

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 2026-04-10 at 12:11 By The first quarter of 2026 has reinforced a hard truth: U.S. government agencies and educational institutions are operating in the most hostile cyber threat environment ever recorded. This article is an excerpt from Trend Micro Research, News and Perspectives View Original […]

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 Read More »

Why East-West Visibility Matters for Grid Security

Why East-West Visibility Matters for Grid Security 2026-03-18 at 12:35 By Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Why East-West Visibility Matters for Grid Security Read More »

From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA

From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA 2026-03-18 at 12:35 By Not every cloud breach starts with malware or a zero-day. In this incident, attackers discovered an exposed Spring Boot Actuator endpoint, harvested credentials from leaked configuration data, then used the OAuth2 Resource Owner Password Credentials (ROPC) flow to

From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA Read More »

IBM Infrastructure: Continuous Risk & Compliance

IBM Infrastructure: Continuous Risk & Compliance 2025-11-12 at 02:00 By Learn all about AI-powered visibility, telemetry, and proactive security across mainframe, cloud, containers, and enterprise workloads. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

IBM Infrastructure: Continuous Risk & Compliance Read More »

AI Security: NVIDIA BlueField Now with Vision One™

AI Security: NVIDIA BlueField Now with Vision One™ 2025-10-29 at 05:48 By Launching at NVIDIA GTC 2025 – Transforming AI Security with Trend Vision One™ on NVIDIA BlueField This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

AI Security: NVIDIA BlueField Now with Vision One™ Read More »

Trend Micro launches new integration with Zscaler to deliver real-time, Risk-Based Zero Trust Access

Trend Micro launches new integration with Zscaler to deliver real-time, Risk-Based Zero Trust Access 2025-10-15 at 02:22 By Discover how Trend Vision One™ integrates with Zscaler to unify detection and access enforcement, accelerate threat containment, reduce dwell time, and deliver seamless Zero Trust protection for modern enterprises. This article is an excerpt from Trend Micro

Trend Micro launches new integration with Zscaler to deliver real-time, Risk-Based Zero Trust Access Read More »

An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps

An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps 2025-09-04 at 22:22 By Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation. This article is an excerpt from Trend Micro

An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps Read More »

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents 2025-08-28 at 14:22 By The TAOTH campaign exploited abandoned software and spear-phishing to deploy multiple malware families, targeting dissidents and other high-value individuals across Eastern Asia. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents Read More »

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware 2025-08-20 at 19:25 By Warlock ransomware exploits unpatched Microsoft SharePoint vulnerabilities to gain access, escalate privileges, steal credentials, move laterally, and deploy ransomware with data exfiltration across enterprise environments. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware Read More »

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises 2025-08-12 at 13:10 By We uncovered Charon, a new ransomware strainfamily that uses advanced APT-style techniques, including DLL sideloading, process injection, and anti-EDR capabilities, to target organizations with customized ransom demands. This article is an excerpt from Trend Micro Research, News and Perspectives View

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises Read More »

New Ransomware Charon Uses Earth Baxia APT Techniques To Target Enterprises

New Ransomware Charon Uses Earth Baxia APT Techniques To Target Enterprises 2025-08-12 at 13:10 By We uncovered Charon, a new ransomware strainfamily that uses advanced APT-style techniques, including DLL sideloading, process injection, and anti-EDR capabilities, to target organizations with customized ransom demands. This article is an excerpt from Trend Micro Research, News and Perspectives View

New Ransomware Charon Uses Earth Baxia APT Techniques To Target Enterprises Read More »

Securing Tomorrow: An Interview with Trend Micro VP of Product Management Michael Habibi

Securing Tomorrow: An Interview with Trend Micro VP of Product Management Michael Habibi 2025-07-18 at 19:13 By Proactive security in a rapidly evolving threat landscape This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Securing Tomorrow: An Interview with Trend Micro VP of Product Management Michael Habibi Read More »

Why Trend Micro Continues to be Named a CNAPP Leader

Why Trend Micro Continues to be Named a CNAPP Leader 2025-06-28 at 01:01 By Trend Micro is recognized for our Cloud CNAPP capabilities and product strategy—affirming our vision to deliver a cloud security solution that predicts, protects, and responds to threats across hybrid and multi-cloud environments. This article is an excerpt from Trend Micro Research,

Why Trend Micro Continues to be Named a CNAPP Leader Read More »

Earth Lamia Develops Custom Arsenal to Target Multiple Industries

Earth Lamia Develops Custom Arsenal to Target Multiple Industries 2025-05-27 at 12:02 By Trend™ Research has been tracking an active APT threat actor named Earth Lamia, targeting multiple industries in Brazil, India and Southeast Asia countries at least since 2023. The threat actor primarily exploits vulnerabilities in web applications to gain access to targeted organizations.

Earth Lamia Develops Custom Arsenal to Target Multiple Industries Read More »

Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain

Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain 2025-05-22 at 12:23 By We have detected a new tactic involving fake CAPTCHA pages that trick users into executing harmful commands in Windows. This scheme uses disguised files sent via phishing and other malicious methods. This article is an excerpt from Trend Micro

Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain Read More »

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal 2025-05-07 at 11:48 By During our monitoring of Agenda ransomware activities, we uncovered campaigns that made use of the SmokeLoader malware and a new loader we’ve named NETXLOADER. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal Read More »

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk 2025-04-28 at 11:46 By Trend Research uncovered misconfigurations in NVIDIA Riva deployments, with two vulnerabilities, CVE-2025-23242 and CVE-2025-23243, contributing to their exposure. These security flaws could lead to unauthorized access, resource abuse, and potential misuse or theft of AI-powered inference services, including speech recognition

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk Read More »

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors 2025-04-25 at 11:22 By An APT group dubbed Earth Kurma is actively targeting government and telecommunications organizations in Southeast Asia using advanced malware, rootkits, and trusted cloud services to conduct cyberespionage. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors Read More »

CrazyHunter Campaign Targets Taiwanese Critical Sectors

CrazyHunter Campaign Targets Taiwanese Critical Sectors 2025-04-16 at 11:55 By This blog entry details research on emerging ransomware group CrazyHunter, which has launched a sophisticated campaign aimed at Taiwan’s essential services. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

CrazyHunter Campaign Targets Taiwanese Critical Sectors Read More »

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets 2025-04-14 at 14:12 By A controller linked to BPF backdoor can open a reverse shell, enabling deeper infiltration into compromised networks. Recent attacks have been observed targeting the telecommunications, finance, and retail sectors across South Korea, Hong Kong, Myanmar, Malaysia, and Egypt. This article is an

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets Read More »

Scroll to Top