We are pleased to announce that our latest Trellix Endpoint Detection and Response with Forensics (EDRF) Cloud threat detection update for May 2026 is now available.
This cumulative report summarizes the detection content released throughout April 2026, adding 20 new detections to your defense stack.
Key threat coverage
-
Advanced APT and state-sponsored tracking
New detection for Mustang Panda (Perseus Emulation), updated coverage for Iranian actors (UNC1549), and tracking for UNC6755 distributing FUGILUMI malware -
Supply chain and emerging malware
Critical-severity coverage for the Trivy Supply Chain Attack (CVE-2026-33634), enhanced macOS detection for the AXIOS NPM compromise, and new EDR coverage for DCRAT -
Adversary tradecraft and evasion
New logic to identify HTML Smuggling via dynamic browser ZIP creation and added detection against forensic tool abuse (Volt Typhoon using Magnet RAM Capture)
These updates are fully compatible with all EDR and EDRF client versions. There is no action required.
For more details and a complete list of the changes, see the release details in the Knowledge article Trellix EDRF Cloud Threat Detection Updates – May 2026.