Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware.
This yearβs Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed -- and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath.
TrendAIβ’ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.
In this blog entry, researchers from the TrendAIβ’ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063βs Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
Enterprises aiming to predict and mitigate human, machine, and AIβagent risks at scale demand AIβpowered identityβfirst security without compromise.
A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.
TrendAI reviews the White House National Cyber Strategy, outlining six pillars to strengthen U.S. cybersecurityβfrom deterrence and regulation to federal modernization, critical infrastructure protection, AI leadership, and workforce development.
TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.
This blog discusses the steganography, cloud abuse, and email-based backdoorsβ―used against theβ―Ukrainianβ―defense supply chainβ―in the latest Pawn Storm campaign that TrendAIβ’ Research observed and analyzed.
Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAIβ’. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) proxying.
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
At [un]prompted 2026, TrendAIβ’ demonstrated how documents can be used to exploit AI-driven KYC pipelines and introduced FENRIR, an automated system for discovering AI vulnerabilities at scale.
CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.
TrendAIβ’βs ΓSIR platform combines AI automation with expert oversight to discover zero-day vulnerabilities in AI infrastructure β 21 CVEs across NVIDIA, Tencent, and MLflow since mid-2025.