| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, says Tom Kellermann, VP of AI Security and Threat Research at Trend AI.

The cumulative milestone reached by TrendAI, whose U.S. headquarters is in Irving, underscores how quickly AI is reshaping cybersecurity spending — and how the AWS Marketplace captures that growth.

Tom Kellermann, VP of Al Security and Threat Research, analyses how Al has altered the cyberattack kill chain, as enterprise Al is being used against them

Security teams often treat frontier and open-weight artificial intelligence models as competing choices. The two are complementary, not substitutes, said Johnny Hand, global CISO at TrendAI.

The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally of vulnerabilities that surfaced in 2025, an explosion driven by increasingly capable artificial intelligence systems.

A jailbroken Google Gemini did 90 percent of the work in a credential- and cryptocurrency-stealing spree, including spinning up a new command-and-control (C2) server in just six minutes, according to a TrendAI report shared exclusively with The Register.

TrendAI has published research on a cybercrime economy built around stolen healthcare data, ransomware, and traded access to health systems.

Economic growth and innovation thrive in the light. But mounting cyber risk threatens to cast a shadow over global organizations at a time of tremendous change. From healthcare to financial services, and energy to education, AI is helping businesses to work faster, smarter and more efficiently. But it also exposes those same organizations to risk.

New research from TrendAI highlights the immense reach of Fancy Bear, also known as APT28 and Forest Blizzard.

TrendAI finds 70% of requested exploits in the last three years were for vulnerabilities that were at least two years old.

“The massive amount of volume coming in terms of software projects is quite overwhelming,” said Peter Girnus, senior threat researcher at Trend Micro’s Zero Day Initiative. “I think the industry really has to figure out how to add that security piece between how these agents work—between the models and the tool chains and the various components of the AI ecosystem.”

Bharat Mistry, field CTO at TrendAI, a business unit of Trend Micro, says healthcare leaders should stop thinking one environment can do it all and instead put each system where it works best.

A record 73 entries were included in this year's competition at Automotive World in Tokyo, and, while not all were successful, Trend Micro's Zero Day Initiative still ended up paying out more than $1 million to successful competitors.

Security researchers exploited dozens of vulnerabilities in vehicle infotainment systems and EV chargers during the latest Pwn2Own contest at Automotive World 2026.

My top priority for 2026 is to scale differentiated, AI-driven cybersecurity platforms, turning unique expertise into durable growth and long-term value for customers worldwide.

A digital double can take twice the trouble. That is - a virtual replica of an organization's IT infrastructure allows for the dynamic deployment of simulations and proactive defenses, said Trend Micro COO Kevin Simzer.

Rachel Jin, chief platform and business officer at Trend Micro, says the speed and overall volatility of AI models is reshaping everything – from IT lifecycles to threat patterns. LLMs update monthly and attackers are increasingly using that pace to generate highly tailored phishing attacks, automate tasks and further scale operations.

Overall, the incidents underscore that Japanese companies are suffering the long tail of recovering from ransomware, especially if the victims refuse to pay the ransom, says Jon Clay, vice president of threat intelligence for cybersecurity firm Trend Micro.

Cybercriminals, including ransomware crews, will lean more heavily on agentic AI next year as attackers automate more of their operations, Trend Micro's researchers believe.

Over the past year, VLMs have become significantly more accurate and practical, agrees Bharat Mistry, field CTO at Trend Micro. That's due to training on huge collections of paired images and texts, along with improved model designs, he says.
Japanese cybersecurity software company Trend Micro Inc. today gave a preview of its soon-to-be-launched Trend Vision One AI Security Package, a solution that delivers proactive, centralized exposure management with analytics for artificial intelligence-driven environments.

At Pwn2Own Ireland 2025, competitors targeted products in eight categories, including printers, network storage systems, messaging apps, smart home devices, surveillance equipment, home networking equipment, flagship smartphones (Apple iPhone 16, Samsung Galaxy S25, and Google Pixel 9), and wearable technology (including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets).

As the final day of the Pwn2Own Ireland 2025 hacking event enters its final phase, the biggest single reward ever offered by the organizers, $1 million, was up for grabs by a hacker known only as ‘Eugene’ from Team Z3. This would be the Messenger holy grail hack, a successful zero-day, zero-click, remote code execution hack targeting WhatsApp.

The second 24 hours of the three-day hacking frenzy that its Pwn2Own Ireland 2025 has come to a conclusion, and Samsung has been the headline victim with its flagship Galaxy S25 smartphone falling victim to a collaboration between Mobile Hacking Lab and Summoning Team hackers.

Pwn2Own Ireland kicked off on Oct. 21. What researchers found continues to highlight how secure development practices are lacking across the industry.

"RondoDox" is characteristically unlike most botnets, researchers from Trend Micro said in a report on Thursday. Where others are specially crafted to pick apart select vulnerabilities like a surgeon, RondoDox blasts onto infected devices like Rambo, trying exploit after exploit to see which one sticks.

The expiration this week of decade-old legal protections for companies sharing cyberattack intelligence with the federal government is sending a chill across the cybersecurity industry, with experts fearing a wave of attacks ahead.

“Ransomware actors and their affiliates are regularly changing their TTPs [tactics, techniques, and procedures] nowadays to stay ahead of defenses as well as law enforcement,” said Jon Clay, Trend Micro’s vice-president of threat intelligence.

The extended MirrorFace campaign, for example, has likely led to critical data loss, says Jon Clay, VP of threat intelligence at cybersecurity firm Trend Micro.

None of the vulnerabilities Apple disclosed this week appear to be under active attack, Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, told CyberScoop.

A threat actor is using legit-looking AI tools and software to sneak malware for future attacks on organizations worldwide. The campaign, which Trend Micro researchers are tracking as "EvilAI," has already racked up hundreds of victims across manufacturing, government, healthcare, and other sectors, and has infected organizations in the US, India, the UK, Germany, France, Brazil, and beyond.

Africa's cybercriminals, like the continent overall, are quickly gaining maturity, says Joshua Paul Ignacio, a senior threat researcher at Trend Micro, which also aided Interpol in the latest operation.

"We're talking artificial intelligence, but chatbots are really stupid," says David Sancho, Senior Threat Researcher at Trend Micro. "They process all text as if they had new information, and if that information is a command, they process the information as a command."

On the latest episode of the TechSpective Podcast, Tony Bradley spoke with Kevin Simzer, COO of Trend Micro, about how generative and agentic AI are reshaping development and defense strategies.

"A leak happened here somewhere," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI), told The Register in July. "And now you've got a zero-day exploit in the wild, and worse than that, you've got a zero-day exploit in the wild that bypasses the patch, which came out the next day."

Dark Reading's Becky Bracken meets with Dustin Childs of Trend ZDI at Black Hat 2025.

While the cybercrime underground has professionalized and become more organized in recent years, threat actors are, to a great extent, still using the same attack methods today as they were in 2020.

How Kim Jong Un's regime leverages AI and vulnerable Americans to earn millions
The new offering allows organizations to model their entire information technology and operational technology environments in real time, including support to simulate threats, validate defenses and adjust policies before attacks can occur.

The expanded alliance brings new capabilities to partners in three critical cybersecurity growth areas.

A program to share information with cybersecurity companies may have exposed unpatched flaws in the company's SharePoint service.

Both Microsoft and Trend Micro later said that hackers had actually begun exploiting the bugs on July 7, a day before the patches. It is unclear how these hackers learned of these flaws, Childs said. Trend Micro said a technology company—which it declined to identify—was compromised in the attack that it observed.

The vulnerability opening the way for the attack was first identified in May at a Berlin hacking competition organised by cybersecurity firm Trend Micro that offered cash bounties for finding computer bugs in popular software.

Both techniques remain popular with state-sponsored and cybercriminal groups, says Peter Girnus, a senior threat researcher with cybersecurity firm Trend Micro's Zero Day Initiative (ZDI).

Louise McEvoy, Trend Micro’s vice president of U.S. channel, told CRN in an email that the vendor is “working to ensure that the changes within Microsoft’s MVI program strengthen our joint business.”

This new feature also has a security hole that "could affect thousands of AI agents," according to Trend Micro principal threat researcher Sean Park, who detailed the flaw and how an attacker could exploit it to hijack a support bot in a Tuesday post.

Operation Secure was also assisted by private cybersecurity partners, including Kaspersky, Group-IB, and Trend Micro.

Hallucination mitigation is also a core part of Trend Micro's responsible AI development strategy, says Shannon Murphy, senior manager of global security and risk strategy at Trend Micro. The company recently open sourced its threat detection AI model and agent, Trend Cybertron.

Irrespective of market conditions, only the top 5% of the Zacks-covered stocks get a 'Strong Buy' rating and the next 15% get a 'Buy' rating.

Kevin Simzer, chief operating officer at Trend Micro, shared a firsthand experience with me that emphasizes this shift. At a CISO roundtable just nine months ago, he polled the room—and every single participant was trying to block AI tools. Now? “We’re about to release some new research... and actually, 97% of them are leveraging AI,” Simzer said.