| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

While attacks from the prolific APT group in China and North Korea continue to make up much of the activity in the region, other nations are using cyber operations as part of their approach to regional conflicts, says Feike Hacquebord, principal threat researcher at cybersecurity firm Trend Micro.

In all, no less than 28 zero-day exploits were demonstrated, and Trend Micro ZDI handed over $1,078,750 to the successful hackers in return for the vulnerability details.

What It Does: Trend Micro offers a comprehensive cybersecurity platform spanning endpoint, email, cloud, OT, and more. It’s all anchored by the Trend Micro Vision One platform.

In this video interview with Information Security Media Group at RSAC Conference 2025, Trend COO Kevin Simzer discussed the impact of trade tariffs on cybersecurity, how data sovereignty is driving on-premises deployments, and cybersecurity skill and talent challenges.

Without a doubt, there is much less eye-rolling when AI gets brought up in a conversation at RSAC this year, according to Kevin Simzer, COO at Trend Micro.

“There is a veil on the front side so we can’t see what they’re working on and what they’re working towards. We only see the results of it when it gets into the wild and actually gets demonstrated against a real live party,” Trend Micro's Dustin Childs said.

Cybersecurity company Trend Micro also put out research on this front. It found that there are detailed online forums in Russia where criminals were offering to carry out physical attacks for the highest bidder.

Trend Micro researchers detailed an emerging ransomware campaign by a new group known as "CrazyHunter" that is targeting critical sectors in Taiwan.

"I can say that, having been in this industry for longer than CVEs themselves, it won't be good," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, told The Register.

Security researchers at Trend Micro are flagging problems with Nvidia’s patch for a critical vulnerability in the Nvidia Container Toolkit, warning that the incomplete mitigation leaves enterprises exposed to container escape attacks.

And although regular agentic AI is still at a very early stage—and criminal or malicious use of agentic AI even more so—it’s even more of a Wild West than the LLM field was two years ago, says Vincenzo Ciancaglini, a senior threat researcher at the security company Trend Micro.

Trend Micro has open sourced its cybersecurity large language model (LLM) and artificial intelligence (AI) agent to help organizations automate threat detection.

Trend Micro rolled out autonomous agents and its own AI brain to customers last year.

According to Trend Micro documentation, the data extortion gang was seen launching exploits against the defect in the Microsoft Management Console (MMC) framework to execute malicious code and exfiltrate data from targeted systems.

Cybercriminals working on behalf of at least six nation-states are actively exploiting a zero-day vulnerability in Microsoft Windows to commit espionage, steal data and cryptocurrency, according to Trend Micro researchers.

As security researchers Peter Girnus and Aliakbar Zahravi with Trend Micro's Zero Day Initiative (ZDI) reported today, Microsoft tagged it as "not meeting the bar servicing" in late September and said it wouldn't release security updates to address it.

Researchers from the security firm Trend Micro collaborated with Human on the Badbox 2.0 investigation, particularly focusing on the actors behind the activity.

The company says Trend Cybertron is the first specialised cybersecurity large language model (LLM) of its kind that leverages AI-driven intelligence, historical threat data and predictive analytics to protect organisations from emerging risks.

The world is worried about deepfakes. Research conducted in the U.S. and Australia finds that nearly three-quarters of respondents feel negatively about them, associating the AI-generated phenomenon with fraud and misinformation. But in the workplace, we’re more likely to let our guard down.

The fight against shadow AI mirrors past efforts to control shadow IT and unauthorized cloud applications, Shannon Murphy, senior manager of global security and risk strategy at Trend Micro, told Axios.

Generally, monitoring for cryptojacking attacks can be difficult, said Jon Clay, vice president of threat intelligence at Trend Micro. “One of the things we see a lot of is, they come in, they drop their miners, and then they wipe their tracks of everything they did prior to that. So it’s very difficult,” he said. “They also wipe out and turn off a lot of the security products that are running on these machines.”

A Trend Micro spokesperson shared a comment from the company's research team, which noted that based on currently available details, the issue could be related to a high volume of traffic from either a surge in popularity for DeepSeek's service or a targeted DDoS attack.

The incidents highlight that organizations are aiming to silence researchers, rather than engage publicly with them, says Dustin Childs, the head of threat awareness and the Zero Day Initiative at Trend Micro, which maintains a third-party bug bounty program.

Researchers at the this year's Pwn2Own Automotive hacking contest successfully hacked Tesla's wall connector electric vehicle (EV) charger.

Pwn2Own is a competitive hacking event with a long and noble history stretching back to 2007; that it attracts some of the best ethical hackers and security researchers on the planet is a testament to its reputation.

After the zero-day vulnerabilities are exploited and reported during Pwn2Own, vendors have 90 days to develop and release security patches before Trend Micro's Zero Day Initiative publicly discloses them.

$380,000 paid out on the first day of Pwn2Own Automotive 2025 for exploits targeting car infotainment units, operating systems, and chargers.

The gang's operator was banned from popular hacker forums Exploit and XSS, making it difficult for him to recruit new members, according to a Trend Micro report.

“Why do people drink one soda over another? Because the brand is so strong,” says Robert McArdle, a director on Trend Micro’s cybercrime research team at Trend Micro, which helped in the investigation. “And if you can destroy that you’re left with soda water.”

“The malicious repository containing the PoC appears to be a fork from the original creator,” Trend Micro said in its report. “In this case, the original Python files were replaced with the executable poc[dot]exe that was packed using UPX.”

From Trend Micro's Jon Clay: Proactive defense needs to be prioritized, because offense is going to stay on the back foot.

Researchers at cybersecurity company Trend Micro first spotted Meta’s VR headsets appearing in its threat intelligence residential proxy data earlier this year, before tracking down that teenagers were using Big Mama to play Gorilla Tag.

Artificial intelligence is transforming cybersecurity by improving threat detection, addressing generative AI risks, and offering tailored solutions for multi-cloud and on-premises environments. "We're thinking about this next wave of innovation with AI as being very disruptive," said Kevin Simzer, COO of Trend Micro.

Trend Micro, a major cybersecurity vendor, has been quietly rolling out a new "AI brain" that gives customers the ability to automate their threat defenses.

Despite the large number of arrests, the operation will likely result only in a brief reduction in cybercriminal activity, as disrupted groups will quickly pivot and recreate their infrastructure, says Stephen Hilt, a senior threat researcher with cybersecurity firm Trend Micro, which also collaborated with authorities on the global intelligence support.

The reach of the China-linked Salt Typhoon gang extends beyond telecommunications giants in the United States, and its arsenal includes several backdoors – including a brand-new malware dubbed GhostSpider – according to Trend Micro researchers.

The gang, tracked as "Water Barghest," has already compromised more than 20,000 IoT devices, including small office and home office (SOHO) routers used by businesses, by using automated scripts to identify and compromise vulnerable devices, according to new research from Trend Micro.

Channel Futures features Louise McEvoy, Vice President of US Channel at Trend.

“On the surface, [CISA’s program is] very good,” Dustin Childs, head of threat awareness in the Zero Day Initiative at Trend Micro, tells CSO. “Every enterprise, especially any large enterprise like the US government, should have some vulnerability disclosure platform.”

Recent research through Trend Micro's Zero Day Initiative (ZDI) has surfaced half a dozen vulnerabilities in the Mazda IVI.

“CISA has a good opportunity to build this out and expand who supports it,” said Jon Clay, vice president of threat intelligence at cyber firm Trend Micro, “as the existing pledges are a very small fraction of developers in the world.”

As part of the operation, which ran from April 1 to August 31, law enforcement agencies in 95 Interpol member countries and private-sector partners such as Group-IB, Trend Micro, Kaspersky, and Team Cymru analyzed roughly 30,000 suspicious IP addresses.

It’s been a headline year for democracy, with over two billion voters casting their ballots in dozens of countries worldwide. But democracy has also never been under greater threat—and in many cases, AI-powered trickery is to blame.

While Synology and QNAP hurried out security updates, vendors are given 90 days until Trend Micro's Zero Day Initiative releases details on bugs disclosed during the contest and usually take their time to release patches.

Risk management and security vendor Trend Micro is looking ahead to 2025 as a year to build upon program enhancements and platform updates that were unveiled throughout 2024.

Trend Micro has acquired TippingPoint IPS and sells it both as a standalone product as well as integrated into their central platform called Vision One. It is available as a virtual machine, a variety of hardware appliances or as a cloud subscription for protecting AWS workloads.

Trend Micro revealed today it will extend an alliance with NVIDIA to include a Morpheus platform that harnesses graphical processor units (GPUs) to apply artificial intelligence (AI) to security operations.

Enter a third study by Trend Micro, a security scam detection app builder. It revealed that a whopping 73% of people think scams have gotten worse in the past year, and almost 80% are worried someone in their family might fall victim.

NIST's security flaw database still backlogged with 17K+ unprocessed bugs. Not great

Nearly two-thirds of organizations lack 24/7 cybersecurity coverage throughout the year due to staffing shortages, a Trend Micro report published Thursday revealed.