REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
25 reports · page 1 of 1
trend_micro · tlp:amber · 6/29/2026, 12:00:00 AM
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry | Trend Micro (US) search close About Mission and Culture Mission and Culture A…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/tonresolver.htmltrend_micro · tlp:amber · 6/23/2026, 12:00:00 AM
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold. From Langflow to Monero: Inside CVE-2026-33017 Cryptominer | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive …
trend_micro · tlp:amber · 6/18/2026, 12:00:00 AM
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker's PSIGW gateway to execute code inside the application server's Java virtual machine (JVM), evading behavioral and network sensors. PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM | Trend Micro (US) search close About …
Read original ↗https://www.trendmicro.com/en_us/research/26/f/PeopleTools.htmltrend_micro · tlp:amber · 6/17/2026, 12:00:00 AM
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware. Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US) search close A…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.htmltrend_micro · tlp:amber · 6/12/2026, 12:00:00 AM
Governing Claude Enterprise in Environments Where Inline Controls Can't Go TrendAI™ integrates the Claude Compliance API into TrendAI Vision One™ through two collectors that bring AI-aware visibility and detection to Claude Enterprise usage: one keeps all data inside the environment, while the other feeds TrendAI Vision One™ for deeper correlation and compliance. Governing Claude Enterprise in Environments Where Inline Controls Can't Go | Trend Micro (US) search close A…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/governing-claude-enterprise.htmltrend_micro · tlp:amber · 6/10/2026, 12:00:00 AM
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 This year’s Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed -- and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath. GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/pwn2own-genai.htmltrend_micro · tlp:amber · 6/8/2026, 12:00:00 AM
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships. Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open | Trend Micro (US) search close About Mission and Culture …
Read original ↗https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.htmltrend_micro · tlp:amber · 6/1/2026, 12:00:00 AM
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet 47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw. Pwn2Own Berlin 2026: On the Ground with ZDI's Biggest AI Showdown Yet | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focus…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/pwn2own-berlin-2026.htmltrend_micro · tlp:amber · 5/26/2026, 12:00:00 AM
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time. Smart Contracts for C&C: How ClearF…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.htmltrend_micro · tlp:amber · 5/22/2026, 12:00:00 AM
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.htmltrend_micro · tlp:amber · 5/19/2026, 12:00:00 AM
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift,…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/banana-rat.htmltrend_micro · tlp:amber · 5/18/2026, 12:00:00 AM
Agentic Governance: Why It Matters Now AI agents now act inside the trust boundary with real credentials, and agentic governance is what keeps them from quietly breaking things at machine speed. Agentic Governance: Why It Matters Now | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of cybersecurity businesses Learn more L…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/agentic-governance-why-it-matters-now.htmltrend_micro · tlp:amber · 5/13/2026, 12:00:00 AM
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale. Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Trend Micro (US) search cl…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/analyzing-teampcp-supply-chain-attacks.htmltrend_micro · tlp:amber · 5/11/2026, 12:00:00 AM
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing attacks from initial access to data exfiltration. Vibe Hacking: Two AI-Augmented Campa…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.htmltrend_micro · tlp:amber · 5/10/2026, 12:00:00 AM
What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do The Instructure Canvas breach affects universities, K–12 school districts, and teaching hospitals globally. This blog entry intends to provide context and practical guidance. What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed …
Read original ↗https://www.trendmicro.com/en_us/research/26/e/What-Is-the-Instructure-Canvas-Breach.htmltrend_micro · tlp:amber · 5/6/2026, 12:00:00 AM
Supporting the National Cyber Strategy: How TrendAI™ Helps A deeper look at the first three pillars and outlining how our capabilities directly support government agencies working to bring this strategy to life. Supporting the National Cyber Strategy: How TrendAI™ Helps | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of …
Read original ↗https://www.trendmicro.com/en_us/research/26/e/national-cyber-strategy.htmltrend_micro · tlp:amber · 5/5/2026, 12:00:00 AM
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads. InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US) search clos…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.htmltrend_micro · tlp:amber · 5/4/2026, 12:00:00 AM
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, an…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.htmltrend_micro · tlp:amber · 4/30/2026, 12:00:00 AM
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond. Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | Trend Micro (US) search close About Mission and Culture Mis…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.htmltrend_micro · tlp:amber · 4/29/2026, 12:00:00 AM
Kuse Web App Abused to Host Phishing Document Bad actors took advantage of the legitimate name and services of Kuse, a popular AI-based app designed for workplaces. The attackers exploited the users’ trust in Kuse to carry out a phishing attack. Kuse Web App Abused to Host Phishing Document | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a …
Read original ↗https://www.trendmicro.com/en_us/research/26/d/kuse-web-app-abused-to-host-phishing-document.htmltrend_micro · tlp:amber · 4/21/2026, 12:00:00 AM
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk. Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories | T…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.htmltrend_micro · tlp:amber · 4/20/2026, 12:00:00 AM
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk. The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.htmltrend_micro · tlp:amber · 4/13/2026, 12:00:00 AM
Identity Protection in the AI Era Enterprises aiming to predict and mitigate human, machine, and AI‑agent risks at scale demand AI‑powered identity‑first security without compromise. Identity Protection in the AI Era | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of cybersecurity businesses Learn more Leadership Team Le…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/ai-era-identity-production.htmltrend_micro · tlp:amber · 4/9/2026, 12:00:00 AM
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 The first quarter of 2026 has reinforced a hard truth: U.S. government agencies and educational institutions are operating in the most hostile cyber threat environment ever recorded. U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate an…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/us-public-sector-under-siege.htmltrend_micro · tlp:amber · 4/7/2026, 12:00:00 AM
Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do Threat actors leveraged Anthropic’s Claude Code npm release packaging error to distribute Vidar, GhostSocks, and PureLog Stealer. This blog details immediate steps organizations can take and best practices to prevent further risk. Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do | Trend Micro (US) search close About Mission and Culture Mission…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/claude-code-remains-a-lure-what-defenders-should-do.html