Aquileo | Trend Micro Research, News and Perspectiveshttp://feed.informer.com/digests/G5HRN3DTV4/feeder
Respective post owners and feed distributorsTue, 09 Nov 2021 16:45:03 +0000Feed Informer http://feed.informer.com/Aquileo | TrendAI™ Joins Nvidia’s Open Secure AI Alliance: Closing the Gap Between AI Builders and AI Defendershttps://www.trendmicro.com/en_us/research/26/g/open-secure-ai-alliance.html
Research, News, and Perspectiveurn:uuid:328d08ce-dd6f-48d3-2335-bf240a046270Thu, 30 Jul 2026 00:00:00 +0000TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.Trend Micro Research : Articles, News, ReportsTrend Micro Research : EnvironmentsTrend Micro Research : Artificial Intelligence (AI)Rachel JinAquileo | Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibilityhttps://www.trendmicro.com/en_us/research/26/g/open-secure-ai-alliance.html
Research, News, and Perspectiveurn:uuid:b3b02fd5-5b76-0f66-f93c-679be1fac8d2Thu, 30 Jul 2026 00:00:00 +0000TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.Trend Micro Research : Articles, News, ReportsTrend Micro Research : EnvironmentsTrend Micro Research : Artificial Intelligence (AI)Rachel JinAquileo | Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wavehttps://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html
Research, News, and Perspectiveurn:uuid:83f92258-9179-59f3-01e9-52e650b40c77Wed, 29 Jul 2026 00:00:00 +0000Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan.Trend Micro Research : ResearchTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsKenichiro MotonoAquileo | The Signs Were There: What the First Autonomous Ransomware Case Confirmshttps://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html
Research, News, and Perspectiveurn:uuid:53e961be-93e3-2a06-360e-150e9b4aadabFri, 24 Jul 2026 00:00:00 +0000An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior.Trend Micro Research : Articles, News, ReportsTrend Micro Research : RansomwareTrend Micro Research : Artificial Intelligence (AI)Jacob SantosAquileo | 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japanhttps://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
Research, News, and Perspectiveurn:uuid:94257a93-cfd9-c492-1e0f-2e6244f0ad32Thu, 23 Jul 2026 00:00:00 +0000We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. Trend Micro Research : Cyber CrimeTrend Micro Research : ResearchTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsTakehiro IwaiAquileo | Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind Ithttps://www.trendmicro.com/en_us/research/26/g/inside-the-openai-hugging-face-incident.html
Research, News, and Perspectiveurn:uuid:dcb0a03d-e8b8-6d5b-0bd5-69f17423180fThu, 23 Jul 2026 00:00:00 +0000OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained.Trend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsBestin KoruthuAquileo | Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructurehttps://www.trendmicro.com/en_us/research/26/g/plc-exploitation.html
Research, News, and Perspectiveurn:uuid:31aae313-6e70-d2f7-ea7f-65b85760b5c3Thu, 23 Jul 2026 00:00:00 +0000TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsJamal BetheaAquileo | Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
Research, News, and Perspectiveurn:uuid:2f720658-2833-41b7-b018-dabfcfb70815Wed, 22 Jul 2026 00:00:00 +0000Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.Trend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsTrend Micro Research : ResearchAhmed ElsayedAquileo | Volume Is Not Risk: Making Sense of the 'Vulnpocalypse'https://www.trendmicro.com/en_us/research/26/g/making-sense-of-the-vulnpocalypse.html
Research, News, and Perspectiveurn:uuid:0c59da50-8adb-7bcc-04df-3592d23ac099Tue, 21 Jul 2026 00:00:00 +0000A briefing for security leaders on separating vulnerability disclosure volume from exploitable risk in 2026.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Exploits & VulnerabilitiesJohnny HandAquileo | Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnethttps://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
Research, News, and Perspectiveurn:uuid:3e04a69e-aad5-3031-3cf9-bb64c801c989Tue, 14 Jul 2026 00:00:00 +0000TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.Trend Micro Research : Latest NewsTrend Micro Research : MalwareTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsJoseph C ChenAquileo | TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industryhttps://www.trendmicro.com/en_us/research/26/f/tonresolver.html
Research, News, and Perspectiveurn:uuid:398c67bf-bbdc-a461-0e2f-02d799503be3Mon, 29 Jun 2026 00:00:00 +0000In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved.Trend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsTrend Micro Research : ResearchYuya SatoAquileo | From Langflow to Monero: Inside CVE-2026-33017 Cryptominerhttps://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html
Research, News, and Perspectiveurn:uuid:1b2b90e7-9d7e-9a9f-ba80-cbbc428f525cTue, 23 Jun 2026 00:00:00 +0000We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold.Trend Micro Research : CloudTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : ResearchTrend Micro Research : Cyber RiskTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsSimon DuludeAquileo | PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVMhttps://www.trendmicro.com/en_us/research/26/f/PeopleTools.html
Research, News, and Perspectiveurn:uuid:9cb6f965-8ff1-54fc-d66c-657321fd1436Thu, 18 Jun 2026 00:00:00 +0000A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker's PSIGW gateway to execute code inside the application server's Java virtual machine (JVM), evading behavioral and network sensors.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsJacob SantosAquileo | Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaignhttps://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html
Research, News, and Perspectiveurn:uuid:88d648a8-abc9-3b48-3c19-c1a216010c24Wed, 17 Jun 2026 00:00:00 +0000Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware.Trend Micro Research : Latest NewsTrend Micro Research : MalwareTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsFyodor YarochkinAquileo | Governing Claude Enterprise in Environments Where Inline Controls Can't Gohttps://www.trendmicro.com/en_us/research/26/f/governing-claude-enterprise.html
Research, News, and Perspectiveurn:uuid:32d4fa17-3d94-91b1-6f46-79994a521d2aFri, 12 Jun 2026 00:00:00 +0000TrendAI™ integrates the Claude Compliance API into TrendAI Vision One™ through two collectors that bring AI-aware visibility and detection to Claude Enterprise usage: one keeps all data inside the environment, while the other feeds TrendAI Vision One™ for deeper correlation and compliance.Trend Micro Research : Articles, News, ReportsTrend Micro Research : TM Vision One PlatformTrend Micro Research : Artificial Intelligence (AI)Tawnya LancasterAquileo | GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026https://www.trendmicro.com/en_us/research/26/f/pwn2own-genai.html
Research, News, and Perspectiveurn:uuid:33cf8e57-a765-835b-8499-6cee5890779aWed, 10 Jun 2026 00:00:00 +0000This year’s Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed -- and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Artificial Intelligence (AI)Morton SwimmerAquileo | Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Openhttps://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html
Research, News, and Perspectiveurn:uuid:655fdcea-cfd6-6a9e-fe45-9d552a77be50Mon, 08 Jun 2026 00:00:00 +0000Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships.Trend Micro Research : APT & Targeted AttacksTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsHiroyuki KakaraAquileo | Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yethttps://www.trendmicro.com/en_us/research/26/f/pwn2own-berlin-2026.html
Research, News, and Perspectiveurn:uuid:b63c7e4e-2223-cd3c-f39d-3eb913bd3479Mon, 01 Jun 2026 00:00:00 +000047 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw.
Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Exploits & VulnerabilitiesScott GrahamAquileo | Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html
Research, News, and Perspectiveurn:uuid:2cf18da1-c97c-2ae2-a15c-1009608b3273Tue, 26 May 2026 00:00:00 +0000TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.Trend Micro Research : Latest NewsTrend Micro Research : Cyber CrimeTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsRyan SolivenAquileo | Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malwarehttps://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html
Research, News, and Perspectiveurn:uuid:92be6dd5-8291-f4f6-cfc1-21f6866944c1Fri, 22 May 2026 00:00:00 +0000Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections.Trend Micro Research : MalwareTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsKazuki FujisawaAquileo | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaignhttps://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html
Research, News, and Perspectiveurn:uuid:5066bdec-3759-edaa-598f-16d5ec76d7f5Thu, 21 May 2026 00:00:00 +0000A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.Trend Micro Research : Cyber CrimeTrend Micro Research : ResearchTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsPhilippe LinAquileo | Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraudhttps://www.trendmicro.com/en_us/research/26/e/banana-rat.html
Research, News, and Perspectiveurn:uuid:03376eda-fe79-751e-33ea-49df0d764c98Tue, 19 May 2026 00:00:00 +0000In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. Trend Micro Research : Latest NewsTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsAldrin CeriolaAquileo | Agentic Governance: Why It Matters Nowhttps://www.trendmicro.com/en_us/research/26/e/agentic-governance-why-it-matters-now.html
Research, News, and Perspectiveurn:uuid:3908075b-6fa1-3010-9a7b-39a2dabf1838Mon, 18 May 2026 00:00:00 +0000AI agents now act inside the trust boundary with real credentials, and agentic governance is what keeps them from quietly breaking things at machine speed.Trend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsTrend Micro Research : Artificial Intelligence (AI)Fernando TucciAquileo | Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Thefthttps://www.trendmicro.com/en_us/research/26/e/analyzing-teampcp-supply-chain-attacks.html
Research, News, and Perspectiveurn:uuid:1ef250fb-a3c4-d527-626f-e0aff5104592Wed, 13 May 2026 00:00:00 +0000Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale.Trend Micro Research : MalwareTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsJacob SantosAquileo | Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html
Research, News, and Perspectiveurn:uuid:0d8770e3-8448-9d2a-efb4-8cf19c7e0360Mon, 11 May 2026 00:00:00 +0000TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing attacks from initial access to data exfiltration.Trend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsJoseph C ChenAquileo | What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do https://www.trendmicro.com/en_us/research/26/e/What-Is-the-Instructure-Canvas-Breach.html
Research, News, and Perspectiveurn:uuid:08d2fb38-f9e5-03b6-d11e-d0b04931f5faSun, 10 May 2026 00:00:00 +0000The Instructure Canvas breach affects universities, K–12 school districts, and teaching hospitals globally. This blog entry intends to provide context and practical guidance.Trend Micro Research : Articles, News, ReportsJohnny HandAquileo | Supporting the National Cyber Strategy: How TrendAI™ Helpshttps://www.trendmicro.com/en_us/research/26/e/national-cyber-strategy.html
Research, News, and Perspectiveurn:uuid:e5878722-2749-02aa-c703-c7f66e217bafWed, 06 May 2026 00:00:00 +0000A deeper look at the first three pillars and outlining how our capabilities directly support government agencies working to bring this strategy to life.Trend Micro Research : CloudTrend Micro Research : Expert PerspectiveTrend Micro Research : Data centerTrend Micro Research : APT & Targeted AttacksTrend Micro Research : Compliance & RisksTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : NetworkTrend Micro Research : Articles, News, ReportsJon ClayAquileo | InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromisehttps://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.html
Research, News, and Perspectiveurn:uuid:a676d6e1-a56a-85e6-8e92-b869cdbf9118Tue, 05 May 2026 00:00:00 +0000Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads.Trend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsTrend Micro Research : ResearchAllixon Kristoffer FranciscoAquileo | Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilitieshttps://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html
Research, News, and Perspectiveurn:uuid:719cf5a4-8f2a-e6d6-7b35-644c3e84f841Mon, 04 May 2026 00:00:00 +0000TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.Trend Micro Research : CloudTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Data centerAliakbar ZahraviAquileo | Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asiahttps://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html
Research, News, and Perspectiveurn:uuid:7d202be3-a35b-5b0d-d853-63fba7a1967aThu, 30 Apr 2026 00:00:00 +0000A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.Trend Micro Research : MalwareTrend Micro Research : APT & Targeted AttacksTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsDaniel LunghiAquileo | Kuse Web App Abused to Host Phishing Documenthttps://www.trendmicro.com/en_us/research/26/d/kuse-web-app-abused-to-host-phishing-document.html
Research, News, and Perspectiveurn:uuid:a65a6ea8-7e34-dafe-a93a-d8d2c3b9831cWed, 29 Apr 2026 00:00:00 +0000Bad actors took advantage of the legitimate name and services of Kuse, a popular AI-based app designed for workplaces. The attackers exploited the users’ trust in Kuse to carry out a phishing attack.Trend Micro Research : WebTrend Micro Research : ResearchTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsJed ValderamaAquileo | Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositorieshttps://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html
Research, News, and Perspectiveurn:uuid:8f974fda-7558-7a9b-31fb-0440c1b55662Tue, 21 Apr 2026 00:00:00 +0000Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk.Trend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsTrend Micro Research : ResearchFeike HacquebordAquileo | The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variableshttps://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html
Research, News, and Perspectiveurn:uuid:85236523-680a-55e5-f282-808519c76542Mon, 20 Apr 2026 00:00:00 +0000An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.Trend Micro Research : Articles, News, ReportsTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchPeter GirnusAquileo | Identity Protection in the AI Erahttps://www.trendmicro.com/en_us/research/26/d/ai-era-identity-production.html
Research, News, and Perspectiveurn:uuid:f27cadb5-8b6a-9475-fc04-3ca62eafa0e7Mon, 13 Apr 2026 00:00:00 +0000Enterprises aiming to predict and mitigate human, machine, and AI‑agent risks at scale demand AI‑powered identity‑first security without compromise.Trend Micro Research : CloudTrend Micro Research : Latest NewsTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : WebTrend Micro Research : PhishingTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : NetworkTrend Micro Research : Articles, News, ReportsSara AtieAquileo | U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026https://www.trendmicro.com/en_us/research/26/d/us-public-sector-under-siege.html
Research, News, and Perspectiveurn:uuid:74201df5-6fa6-543d-15fd-03350fdd676eThu, 09 Apr 2026 00:00:00 +0000The first quarter of 2026 has reinforced a hard truth: U.S. government agencies and educational institutions are operating in the most hostile cyber threat environment ever recorded.Trend Micro Research : CloudTrend Micro Research : Expert PerspectiveTrend Micro Research : APT & Targeted AttacksTrend Micro Research : EndpointsTrend Micro Research : RansomwareTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : NetworkTrend Micro Research : Articles, News, ReportsJon ClayAquileo | Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do https://www.trendmicro.com/en_us/research/26/d/claude-code-remains-a-lure-what-defenders-should-do.html
Research, News, and Perspectiveurn:uuid:788d6ca5-c382-1f99-8405-0bbffcfab2afTue, 07 Apr 2026 00:00:00 +0000Threat actors leveraged Anthropic’s Claude Code npm release packaging error to distribute Vidar, GhostSocks, and PureLog Stealer. This blog details immediate steps organizations can take and best practices to prevent further risk.Trend Micro Research : MalwareTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsJacob SantosAquileo | Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloadshttps://www.trendmicro.com/en_us/research/26/d/weaponizing-trust-claude-code-lures-and-github-release-payloads.html
Research, News, and Perspectiveurn:uuid:5e6f918c-4be7-d420-20bd-f009c4439d1aFri, 03 Apr 2026 00:00:00 +0000A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.Trend Micro Research : MalwareTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsJacob SantosAquileo | TrendAI Insight: New U.S. National Cyber Strategyhttps://www.trendmicro.com/en_us/research/26/c/trendai-insight-new-us-national-cyber-strategy.html
Research, News, and Perspectiveurn:uuid:a570caae-8840-6c08-74ca-5044b2f244dbWed, 01 Apr 2026 00:00:00 +0000TrendAI reviews the White House National Cyber Strategy, outlining six pillars to strengthen U.S. cybersecurity—from deterrence and regulation to federal modernization, critical infrastructure protection, AI leadership, and workforce development.Trend Micro Research : Latest NewsTrend Micro Research : Compliance & RisksTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : NetworkTrend Micro Research : Articles, News, ReportsJon ClayAquileo | TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threatshttps://www.trendmicro.com/en_us/research/26/c/trendai-research-at-rsac-2026.html
Research, News, and Perspectiveurn:uuid:ea299908-8a8c-9124-e9d2-c198c16eefdeTue, 31 Mar 2026 00:00:00 +0000TrendAI™ Research explored agentic AI cybercrime and EV infrastructure security through two research sessions at RSAC 2026.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrendAI™ ResearchAquileo | The Real Risk of Vibecodinghttps://www.trendmicro.com/en_us/research/26/c/the-real-risk-of-vibecoding.html
Research, News, and Perspectiveurn:uuid:fdcd43f4-10d1-03c3-99d1-5ad3e1e45c7dTue, 31 Mar 2026 00:00:00 +0000This blog looks at how AI‑driven vibecoding speeds up software development while increasing security risk by outpacing traditional review and ownership. It explains why security needs to move earlier and be built into modern development workflows.Trend Micro Research : CloudTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : Expert PerspectiveTrend Micro Research : Cyber ThreatsTrend Micro Research : Data centerTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : Articles, News, ReportsBestin KoruthuAquileo | Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloadshttps://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html
Research, News, and Perspectiveurn:uuid:9e4c9e6d-1b3d-d870-3e8a-f44de9d04c29Tue, 31 Mar 2026 00:00:00 +0000A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsPeter GirnusAquileo | TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLMhttps://www.trendmicro.com/en_us/research/26/c/teampcp-telnyx-attack-marks-a-shift-in-tactics.html
Research, News, and Perspectiveurn:uuid:7d1fa150-1d19-6f02-4740-6ec0059d1fa1Mon, 30 Mar 2026 00:00:00 +0000Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows.Trend Micro Research : MalwareTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsJohn Rainier NavatoAquileo | Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities https://www.trendmicro.com/en_us/research/26/c/pawn-storm-targets-govt-infra.html
Research, News, and Perspectiveurn:uuid:37b12a6b-9e12-4a63-a80b-f1c8c060ee76Thu, 26 Mar 2026 00:00:00 +0000This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed. Trend Micro Research : Latest NewsTrend Micro Research : APT & Targeted AttacksTrend Micro Research : ResearchTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsFeike HacquebordAquileo | Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise https://www.trendmicro.com/en_us/research/26/c/inside-litellm-supply-chain-compromise.html
Research, News, and Perspectiveurn:uuid:f6b39715-a45b-518b-f5cc-78f6f1d15e41Thu, 26 Mar 2026 00:00:00 +0000TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date that cascaded through developer tooling and compromised LiteLLM, exposing how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.Trend Micro Research : Latest NewsTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : ResearchTrend Micro Research : Cyber ThreatsTrend Micro Research : ThreatsTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : Articles, News, ReportsPeter GirnusAquileo | Your AI Stack Just Handed Over Your Root Keys: Inside the litellm PyPI Breachhttps://www.trendmicro.com/en_us/research/26/c/your-ai-stack-just-handed-over-your-root-keys-inside-the-litellm-pypi-breach.html
Research, News, and Perspectiveurn:uuid:42881fbb-d5c1-e682-2d28-5fc652b4bbdbWed, 25 Mar 2026 00:00:00 +0000Litellm PyPI breach explained: malicious versions steal cloud credentials, SSH keys, and Kubernetes secrets. Learn impact and urgent mitigation steps.Trend Micro Research : CloudTrend Micro Research : Cyber CrimeTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : Expert PerspectiveTrend Micro Research : Data centerTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : Articles, News, ReportsFernando TucciAquileo | Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industrieshttps://www.trendmicro.com/en_us/research/26/c/copyright-lures-mask-a-multistage-purelog-stealer-attack.html
Research, News, and Perspectiveurn:uuid:ba06859f-924f-ba8b-a65d-a5b130191c13Thu, 19 Mar 2026 00:00:00 +0000We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques.Trend Micro Research : MalwareTrend Micro Research : ResearchTrend Micro Research : PhishingTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsMohamed FahmyAquileo | Why East-West Visibility Matters for Grid Securityhttps://www.trendmicro.com/en_us/research/26/c/why-east-west-visibility-matters-for-grid-security.html
Research, News, and Perspectiveurn:uuid:1b280c61-1f39-eba4-19d3-64aa292453d6Wed, 18 Mar 2026 00:00:00 +0000Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks.Trend Micro Research : CloudTrend Micro Research : Compliance & RisksTrend Micro Research : EndpointsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Consumer FocusTrend Micro Research : Exploits & VulnerabilitiesTrend Micro Research : Privacy & RisksTrend Micro Research : Cyber ThreatsTrend Micro Research : ICS OTTrend Micro Research : APT & Targeted AttacksTrend Micro Research : IoTTrend Micro Research : Artificial Intelligence (AI)Trend Micro Research : NetworkVitaliy ShtymAquileo | From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFAhttps://www.trendmicro.com/en_us/research/26/c/from-misconfigured-spring-boot-actuator-to-sharepoint-exfiltrati.html
Research, News, and Perspectiveurn:uuid:e42d74b4-632a-aaa4-c844-c7e41f9ede22Wed, 18 Mar 2026 00:00:00 +0000Not every cloud breach starts with malware or a zero-day. In this incident, attackers discovered an exposed Spring Boot Actuator endpoint, harvested credentials from leaked configuration data, then used the OAuth2 Resource Owner Password Credentials (ROPC) flow to authenticate without MFA.Trend Micro Research : EndpointsTrend Micro Research : Cyber CrimeTrend Micro Research : InvestigationsTrend Micro Research : ResearchTrend Micro Research : Expert PerspectiveTrend Micro Research : Articles, News, ReportsRyan SolivenAquileo | Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attackhttps://www.trendmicro.com/en_us/research/26/c/dissecting-a-warlock-attack.html
Research, News, and Perspectiveurn:uuid:993ee1ab-f64f-4d2d-1ead-a7e3a1ecdadfMon, 16 Mar 2026 00:00:00 +0000Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.Trend Micro Research : Latest NewsTrend Micro Research : ResearchTrend Micro Research : RansomwareTrend Micro Research : Articles, News, ReportsTrend Micro Research : Cyber ThreatsMaristel PolicarpioAquileo | Securing Autonomous AI Agents with TrendAI & NVIDIA OpenShellhttps://www.trendmicro.com/en_us/research/26/c/securing-autonomous-ai-agents-with-trendai-and-nvidia-openshell.html
Research, News, and Perspectiveurn:uuid:d2ec24f2-7d4f-f8a5-35b9-7c43275dc265Mon, 16 Mar 2026 00:00:00 +0000Learn how TrendAI and NVIDIA OpenShell help secure autonomous AI agents and build trusted enterprise AI systems with stronger visibility and control.Trend Micro Research : Latest NewsTrend Micro Research : Articles, News, ReportsTrend Micro Research : Artificial Intelligence (AI)Fernando Cardoso