Cybercriminals no longer need to breach systems when they can buy the trust granted to your employees. TrendAI⢠Research found insider access sold through brokers and escrow on forums such as XSS and Exploit. Read our full research: https://t.co/3MpM0RK5YK
An actor on the Exploit forum advertised full "Master Adminā access to a Tier 1 iGaming conglomerate, proof that trusted credentials, not stolen data, are the underground's top product. TrendAI⢠Research documents the listing. Full breakdown: https://t.co/3MpM0RK5YK
We tracked two years of underground forums, marketplaces, and Telegram channels at TrendAI targeting factories, utilities, and energy networks. Our findings here: https://t.co/6FqWpWeIt4
Criminals are selling remote access into factories, power plants, and utilities on underground forums, from $25 for a Thai manufacturer to 12 BTC for a German energy firm. TrendAI⢠Research mapped the marketplace.
Our findings here: https://t.co/8QfkIo0la1
šØ Stolen health records are one of the hottest commodities in the cybercrime underworld Check out my proposed session, "Bad Operation: The Cyber Underworld of Stolen Health Data," is up for community voting right now
Four suspects tied to Tycoon 2FA, a phishing-as-a-service platform built to steal logins and bypass MFA controls, fled Pakistan before Singapore Police Force and NCCIA's raids. NCCIA is now seeking Interpol Red Notices against them. Read more: https://t.co/DaxTH9fWLE
The team at @trendaisecurity published our 2026 H1 APT Report on how APT groups are weaponizing trust in the age of AI.
AI isn't replacing APT tradecraft. It's helping scale what already works.
Full report:
https://t.co/1R6gwou7fh
Tycoon2FA was one of the most prolific phishing kits targeting Microsoft 365. Our latest publication details how @trendaisecurity intelligence supported law enforcement in identifying leading to the arrest of one of its operators. https://t.co/2TeChqWbei
We looked into two years along of data tracking the underground market for insider access, and it doesn't look like one-off bribery anymore.
Download the full report, "The Market for Trust":What Cybercriminals Look For in Corporate Insiders
https://t.co/kiy5nifgS3
A passport image with hidden text got an AI know your customer (KYC) agent to leak other customers' records onto the uploader's verification page. No exploit code was used, only words an optical character recognition (OCR) engine could read. See how: https://t.co/pFuZCRWKul
Attackers prioritize what works. Nearly oneāthird of exploit requests map to CISAās Known Exploited Vulnerabilities catalog, showing that demand follows proven impact, not disclosure date. Check out our research at
https://t.co/O61tpecmke
ClickFix instructions hosted in the Claude[.]ai shared chat feature sit behind a valid certificate on a trusted domain. No suspicious URL, no low-reputation host, nothing for Safe Browsing to flag. This makes this malvertising campaign more treacherous: https://t.co/AxTKc5BHLd
MCP servers bridge AI agents to your systems. TrendAI⢠Research found that verified MCP servers carry nearly as many security flaws as unverified ones. A verification badge is not a security guarantee. Get the full breakdown: https://t.co/4vY0Vnq2i7
Stolen healthcare data moves through an organized criminal economy with brokers, marketplaces, and pricing tiers. Rhysida and Interlock alone account for 68.5% of leaked records. TrendAI⢠Research mapped the full supply chain:https://t.co/6N6sbLqf63