An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAIβ’ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior.
We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets.
OpenAIβs own models broke out of a test sandbox and into Hugging Faceβs servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how itβs contained, not just on how itβs trained.
TrendAIβ’ Research breaks down what changed in CISAβs updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
TrendAIβ’ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
In this blog entry, TrendAIβ’ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved.