TrendAI vulnerabilities
3 CVEs tracked
TrendAI features in our current reports primarily as both a research entity and a defense platform. On the research side, the team disclosed critical vulnerabilities including a Windows HTTP.sys RCE (CVE-2026-47291) and an Arista NG Firewall command injection (CVE-2025-6978); on the defense side, it is countering AI-driven threats (like the 'Patriot Bait' AI-built botnet and ClearFake's smart contract campaigns) by integrating controls such as the Claude Compliance API into its Vision One platform. Defenders must urgently patch CVE-2025-6978 on Arista NG Firewall appliances, and simultaneously strengthen adaptive detection mechanisms against AI-assisted social engineering (Booking.com phishing targeting Japan) and unconventional C&C channels like the TON blockchain and BSC testnet.
Azərbaycanca: TrendAI son hesabatlarımızda əsasən tədqiqat qolu və müdafiə platforması kimi önə çıxır. Tədqiqat tərəfində komanda Windows HTTP.sys (CVE-2026-47291) və Arista NG Firewall-da kritik əmr inyeksiyası (CVE-2025-6978) zəifliklərini aşkar edərək dərc edib; müdafiə tərəfində isə AI əsaslı təhlükəyə (AI ilə botnet qurulması, ClearFake kimi ağıllı müqavilə kampaniyaları) qarşı öz Vision One platformasına Claude Compliance API inteqrasiyası kimi tədbirlər görür. Müdafiəçilər Arista NG Firewall istifadə edən şəbəkələrdə CVE-2025-6978 (eyni zamanda CVE-2025-6798) üçün təcili yamaqlanmanı təmin etməli, eləcə də AI dəstəkli sosial mühəndislik (Yaponiyada Booking.com fişinqi) və qeyri-ənənəvi C&C kanallarına (TON blokçeyn, BSC testnet) qarşı adaptiv aşkarlama mexanizmlərini gücləndirməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on TrendAI: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.