TrendAI™ Deploys Claude Opus 4.8 to Advance Vulnerability Detection and Risk Mitigation
Threat Research

TrendAI™ Deploys Claude Opus 4.8 to Advance Vulnerability Detection and Risk Mitigation

Vulnerability management is a long-standing pain point for NZ businesses — scanners produce thousands of findings, but security teams lack the time and context to know which ones actually matter. A new collaboration between TrendAI™ and Anthropic, using Claude Opus 4.8 to power smarter detection and

3 min 30 Jun 2026 xteam
TrendAI™ Zero Day Initiative™ Leads Industry Remediation at Pwn2Own Berlin
Threat Research

TrendAI™ Zero Day Initiative™ Leads Industry Remediation at Pwn2Own Berlin

Pwn2Own Berlin 2026 surfaced 47 fresh zero-day vulnerabilities across the technology stack NZ businesses rely on daily — Microsoft Exchange, SharePoint, Edge, VMware ESXi, browsers, AI infrastructure, and more. With Trend research showing vendors are increasingly slow to patch disclosed flaws, the w

3 min 30 Jun 2026 xteam
ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability
Threat Research

ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability

A newly disclosed vulnerability in the X.Org Server (CVE-2026-50263) affects Linux and Unix-like systems running graphical desktop environments — a common configuration in developer workstations, research labs, and engineering teams across New Zealand. While the bug requires local access, it can be

3 min 30 Jun 2026 xteam
ZDI-26-396: X.Org Server ChangeDrawableAttributes Out-Of-Bounds Read Information Disclosure Vulnerability
Threat Research

ZDI-26-396: X.Org Server ChangeDrawableAttributes Out-Of-Bounds Read Information Disclosure Vulnerability

Linux desktops and workstations remain common in NZ engineering, research, and developer environments, and X.Org Server is still the default display server on many distributions. A newly disclosed local information disclosure flaw (CVE-2026-50262) gives attackers another stepping stone toward root —

3 min 30 Jun 2026 xteam
More PayPal emails hijacked to deliver tech support scams
Threat Research

More PayPal emails hijacked to deliver tech support scams

Tech support scammers are once again abusing PayPal's legitimate email infrastructure to deliver convincing scam messages that bypass standard email authentication checks. For NZ businesses — particularly those with finance staff handling payment notifications — these emails will pass DKIM, SPF and

3 min 30 Apr 2026 xteam
Fast16 Malware
Threat Research

Fast16 Malware

Researchers have reverse-engineered Fast16, a state-sponsored malware (likely US in origin) deployed against Iran years before Stuxnet. While the targets were industrial and research systems abroad, the techniques pioneered by Fast16 represent a class of subtle sabotage that any organisation relying

3 min 30 Apr 2026 xteam
AI threats in the wild: The current state of prompt injections on the web
Threat Research

AI threats in the wild: The current state of prompt injections on the web

As New Zealand businesses rapidly adopt AI assistants, copilots, and agentic workflows, prompt injection has emerged as one of the most significant new attack surfaces. Google's latest research into real-world prompt injection activity confirms what defenders have suspected: attackers are now active

3 min 30 Apr 2026 xteam
ZDI-26-299: Docker Desktop Enhanced Container Isolation Exposed Dangerous Function Local Privilege Escalation Vulnerability
Threat Research

ZDI-26-299: Docker Desktop Enhanced Container Isolation Exposed Dangerous Function Local Privilege Escalation Vulnerability

Docker Desktop is widely used across NZ development teams for local container work, CI pipelines, and dev/test environments. A newly disclosed privilege escalation flaw (CVE-2026-6406, CVSS 8.8) breaks the Enhanced Container Isolation boundary that many teams rely on as a safety net — meaning a comp

3 min 24 Apr 2026 xteam