| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
According to a new report by Trend Micro, the North American cyber criminal underground isn't buried as deep as in other geographies.

“The reality is the sector as a whole is dealing with a cyber crime wave,” said Tom Kellermann, chief cyber security officer at Trend Micro, which sells security software.
The Chinese cybercrime underground has evolved to feature search engines to help darknet users find leaked data, and ATM and POS skimmers to capitalize on the growing consumer trend for non-cash payments, according to Trend Micro.
The Chinese cybercrime underground has evolved to feature search engines to help darknet users find leaked data, and ATM and POS skimmers to capitalize on the growing consumer trend for non-cash payments, according to Trend Micro.

However, this decline is not necessarily a positive indicator, according to Christopher Budd, threat communications manager with Trend Micro, the global cloud security company that issued the report, "Follow the Data: Dissecting Data Breaches and Debunking Myths."

However, this decline is not necessarily a positive indicator, according to Christopher Budd, threat communications manager with Trend Micro, the global cloud security company that issued the report, "Follow the Data: Dissecting Data Breaches and Debunking Myths."

"The security landscape is very fragmented and very discombobulated with regard to encryption," said Paul Ferguson, a threat research advisor at Trend Micro. "There doesn't seem to be a lot of coherency, to the point where end users are confused and don't know how to properly protect themselves."

Data stolen from the targets might also have been shared with others in Russia, if that is where the hacker is working, for his own protection, said Tom Kellermann, chief cybersecurity officer for Trend Micro Inc. "This is not over," Kellermann said. "The real question now is how many backdoors are still in these systems that have yet to be detected."
"This iteration of ransomware targeting Linux servers is an escalation," said Paul Ferguson, a senior threat research advisor at Trend Micro.
The media processing layer is prone to vulnerabilities and attacks, said Trend Micro’s Christopher Budd. The operating system takes the data from Web services and executes it as a lower-level process, and handling the shift correctly can be tricky. It is easy to introduce mistakes in this layer.

But Tom Kellermann, chief cybersecurity officer at the security firm Trend Micro, says the timing of the announcement makes sense, given the Angler and Nuclear zero-day malware exploit kits now in widespread use. "I was at the [Oct. 25-28] FS-ISAC Fall Summit, and I think the presentations woke up regulators," he says.
The security flaw was discovered in mid-October, when it was found being exploited by the Russia-linked Pawn Storm threat group in attacks aimed at Foreign Affairs Ministries. The vulnerability affects all Flash releases up to version 19.0.0.226 for Mac and Windows, and Flash Player 11.2.202.540 for Linux, and was discovered by researchers at Trend Micro.

Law enforcement traditionally has struggled to chase down cybercriminals who use ransomware, said Marco Balduzzi, a senior security engineer and researcher at Trend Micro, who researches the dark Web.

Trend Micro plans to integrate the company to create a network defense unit for enterprise clients.

The enterprise IT industry continues to get its ducks in line. On the heels of Dell buying EMC for $67 billion, Western Digital buying SanDisk for $19 billion and rumblings of more M&A to come, HP is moving out of owning assets in the network security business. Today the company announced that it will sell TippingPoint — a provider of next-generation intrusion systems and network security solutions — to security specialist Trend Micro

The FBI and Secret Service are investigating reports that the personal account of CIA Director John Brennan may have been hacked by a teenager. Tom Kellerman, former Commissioner on President Obama’s Cyber Security Commission and Dave Chronister, Founder of Parameter.

The CVE-2015-7645 vulnerability is actively exploited by the Pawn Storm group in attacks targeting several foreign affairs ministries from around the globe, security researchers from Trend Micro reported Tuesday.
Such hardening could be accomplished by attackers shifting their operations to using "no questions asked" bulletproof hosting services, says Tom Kellermann, chief cybersecurity officer at threat-intelligence firm Trend Micro. "I believe Evil Corp will be back in operation by month's end, [with] ... bulletproof hosting and the protection-racket state of Eastern Europe facilitating this," he says.

The newfound exploit was discovered by the security intelligence lab at Trend Micro. This site offers links to disable Flash in every web browser you have.
The email was descibed by researchers at Trend Micro as being as very well executed, saying it includes the PayPal logo, passable German, some basic clean design and some recipients were likely convinced into installing the app. Trend Micro reports that the malicious app is not currently on the Google Play Store and says that this is where the Android setting that disallows the installation of non-Market applications can really save users.
The Scottrade breach could increase the potential for brokerage fraud, says Tom Kellermann, chief cybersecurity officer at threat-intelligence firm Trend Micro. "Cybercriminals understand the financial sector more than we give them credit for," he says. "As we have realized this year, hackers are pursuing front-running and virtual-insider trading schemes."

According to Christopher Budd, a global threat communications manager at security firm Trend Micro, the inability to protect sensitive data despite encryption efforts suggests the hack could be bigger than initially thought.
The earlier Stagefright flaws prompted researchers to probe Android's multimedia processing libraries for additional vulnerabilities. Researchers from antivirus vendor Trend Micro have since found and reported multiple issues in these components.

Access to these accounts can go for exorbitant fees on the black market, said Tom Kellermann, chief cybersecurity officer at security research firm Trend Micro, which released a report last year on Pawn Storm, a likely Russia-based cyber espionage campaign snooping on government officials.
Trend Micro's Raimund Genes on Building Effective Defense Strategies
Offering integration with security services from companies like Barracuda, Checkpoint, Cisco, Imperva and Trend Micro, the new offering can analyze information gathered from customers' deployments and compare it with global threat intelligence aggregated by Microsoft.
Researchers with Trend Micro have identified two new pieces of point-of-sale malware that are affecting small and medium-sized businesses (SMB) predominately in the U.S.
“One year after, the panic has subsided, but the threat goes on living. Attacks related to Shellshock continue to plague our digital world. Since the second quarter of the year, we have seen about more than 70,000 attacks using Shellshock and about 100,000 attacks using Heartbleed. One of our honeypots, which are vulnerable to Shellshock, has recorded 50 attacks in the past 15 days alone,” wrote Trend Micro.

That’s one of the takeaways from a report this week by security firm Trend Micro, which analyzed a decade’s worth of data breaches. The researchers found that businesses are at greater risk of hackings as they grow their online presence while hackers can more easily profit from stolen data.

However, unlike big companies, SMBs are less likely to use sophisticated security and backup solutions that can prevent ransomware infections and help them recover encrypted files, the Trend Micro researchers said in a blog post.
In Trend Micro's new report, dubbed "Understanding Data Breaches," the security firm explores who is most often targeted in data breaches, how they take place, and what happens to data once it leaves corporate networks.
Over the past 10 years of data breach history, 41 percent of breaches were caused not by hacking, but by device loss. Because of a particularly bad record of holding track of its devices, the healthcare industry has been responsible for more breaches than any other sector this decade, according to Trend Micro's analysis of the past 10 years of data breaches -- as catalogued by the nonprofit Privacy Rights Clearinghouse.
UK organizations were hit with on average 40% more targeted attacks than their European counterparts last year, but ended up paying far less, according to new research from Trend Micro.
A high-level hacking group dubbed Iron Tiger has been observed stealing trillions of bytes of confidential data from the United States government, US defense contractors and related companies in the United States and abroad, security company Trend Micro reports in its research paper posted Tuesday, Operation Iron Tiger: Exploring Chinese Cyber Espionage Attacks on U.S. Defense Contractors.
According to a Trend Micro report, the group – known as “Emissary Panda” or “Threat Group-3390 (TG-3390)” – dates back to 2010 when it was observed focusing on political targets and government agencies in China, the Philippines and Tibet.
According toa report released in June by Trend Micro's Forward-Looking Threat Research Team, a startling 26 percent of the sites on the Darknet are child exploitation sites.
As cybercrime continues to get worse - and more players enter the field - it's notable that at least one of the above rules is no longer unwritten, Max Goncharov, a threat researcher at the security firm Trend Micro, says in a recent update on the Russian cybercrime underground (see Why Russian Cybercrime Markets Are Thriving). "The underground market isn't very articulate about the ends toward which products sold should be used, but sometimes, users find a disclaimer stating that Russia

"Four percent may not sound like much, but it's a lot when you consider there's a new threat being created every two seconds," he told TechNewsWorld. Nevertheless, "I don't think antivirus, if modernized, is dead, because you still need to eliminate 90 percent of the noise out there, and focus your attention on how you construct your defense in depth against targeted attacks," Kellermann explained. "Everyone should use antivirus, as long as it's not solely signature-based."
The exploit consists of a specifically crafted Media Center link (.mcl) file and could be delivered to targeted users in different ways including as a download from a website, by e-mail or via instant messaging applications, the Trend Micro researchers said in a blog post Tuesday.
One of Trend's addresses was used for a profile describing a 33-year-old Los Angeles woman who is "sexy, aggressive" and "knows what she wants," wrote Ryan Flores, a threat research manager with Trend, in a blog post.
Tom Kellermann, chief cybersecurity officer at threat-intelligence firm Trend Micro, says cross-border law enforcement collaboration is at an all-time high. "The Electronic Crimes taskforces, some of which exist in Europe, are the ties that bind," he says. "Extradition is now viable, with the exception of the hacker haven that is Russia. The 78 Russian forums will remain untouchable, as they are viewed as national assets within a culture of Robin Hood."
"Companies should block all Ashley Madison related emails at the email gateway and use URL filtering for all inbound emails for those bulletproof hosts which are disseminating this crimewave," said Tom Kellermann, chief cybersecurity officer at Irving, Tex.-based Trend Micro Inc.
"The researcher had infiltrated … and was able to pose as a person of interest in this group, and they had engaged" with the researcher, says Jon Clay, senior global marketing manager for Trend Micro, which along with ClearSky today published new findings on Rocket Kitten. The spear-phishing email included a malicious link purportedly to a Trend Micro malware scanner.
Nearly six months after exposing the group, Trend Micro and ClearSky published an updated report on Rocket Kitten, a state-sponsored group targeting Israeli and European organizations.
Tom Kellermann, chief cybersecurity officer at security firm Trend Micro, says the growing impact of DD4BC on targeted organizations could be a catalyst for closer international collaboration among law enforcement agencies to catch cybercriminals.
Tom Kellermann, chief cybersecurity officer at the security firm Trend Micro, says businesses have to understand that bypassing banks' procedures for wire-transfer confirmation is exposing them to fraud. "Internal procedures should change to ensure that all requests for the transfer of funds be verified," Kellermann says.
Consumers can now expect the same level of security and privacy in the digital realm as they do in the physical.
Anyone whose name and contact information appears in the 9.7GB stolen names contact information will likely be susceptible to opening emails purportedly from Ashley Madison, divorce lawyers and private investigators, says Tom Kellerman, chief cybersecurity officer for Trend Micro.

Unfortunately, the extortion attempts like the one against Mac are likely to increase in number, sophistication and targeting, says Tom Kellerman, chief cybersecurity officer at Trend Micro.

It's called "sextortion." Criminals contact users involved in illicit online activity and try to get money in exchange for their victim's silence. It's popular in South Korea,according to a report from security firm Trend Micro, where scammers try to initiate online relationships and then blackmail those who take the bait.
Foreign intelligence services and digital crime rings are probably “digging through” the mammoth database of the more than 36 million people who registered for the extramarital dating site Ashley Madison, said Tom Kellermann, chief cybersecurity officer at security firm Trend Micro.

Tom Kellerman, chief cybersecurity officer at Trend Micro, discusses the hacking of the Ashley Madison website and subsequent release of names and other information related to the site's users. He speaks on "Bloomberg Markets." [Video]
The perils of allowing wearables in the workplace were highlighted again today in new research from Trend Micro which uncovered security and privacy issues with some of the biggest brand smart watches on the market, including the Apple Watch.

The United States makes efforts to ensure that its markets operate fairly, but those values aren't shared by hackers in the former Soviet Union and its satellites, noted Tom Kellermann, chief cybersecurity officer at Trend Micro.

Tom Kellermann, chief cybersecurity officer of threat-intelligence firm Trend Micro, says that while it's not likely the true masterminds behind this hacking and trading scheme will ever be brought to justice, it is refreshing to see law enforcement indict people who are believed to be conducting attacks that compromise market trading.
In February, after an internet-connected gas pump was hacked, Trend Micro security researchers Kyle Wilhoit and Stephen Hilt began conducting an experiment to track hackers targeting gas stations arounnd the world.

Back in April, as similar report which focused on North and South America was released by Trend Micro and the Organization of American States (OAS). That report also showed a dramatic increase in cyberattacks directed against critical infrastructure owners and operators.

A handful of attackers targeted fake fuel-tank monitors during a six-month month experiment, showing that real Internet-connected monitors are at risk, according to Trend Micro researchers.
Petrol station monitoring systems are under attack all over the world, some by possible nation state allied hackers, according to new research from Trend Micro. The cyber security giant explained in new research presented at Black Hat 2015 that attacks against these unsecured SCADA systems are no longer theoretical.
Turns out there were quite a few attacks—at least 23—between February and July, where adversaries modified information associated with gas pumps, Trend Micro's Kyle Wilhoit and Stephen Hilt said at the Black Hat security conference here. The duo observed 12 pump identifications, four pump modifications, and two distributed denial of service or denial of service attacks.

This incident motivated Kyle Wilhoit and Stephen Hilt, two security researchers at Trend Micro, to make an experiment. They set up 10 fake gas station monitoring systems and put them online as honeypots. To hackers, or anyone looking for these systems, they looked exactly like regular gas monitoring devices known as Guardian AST, which are made to check and control fuel levels in gas station tanks, and alert operators whenever they get too low.

Cybercrime has developed substantially due to bulletproof hosting service efficiency. Trend Micro's report explains how and why these services evade law enforcement officials and remain online.
Researchers at Trend Micro have reported finding a second denial-of-service (DoS) vulnerability in Android’s “mediaserver” component.
Kyle Wilhoit, senior threat researcher at Trend Micro, to break down real attacks against gas pump monitoring systems
“The Russian underground has become an economy of scale,” says Tom Kellermann, Trend Micro’s chief cyber security officer.

Trend Micro has found a flaw that uses a malformed Matroska (MKV) video in apps or websites to crash Android's "mediaserver" service, effectively turning the target device into a paperweight.

“The culture of silence regarding cyber-attacks in Asia serves as fuel to the guild of thieves who operate with impunity in the region,” said Tom Kellermann, chief cybersecurity officer at security software developer Trend Micro Inc. “The deep-seated historical mistrust in the region undermines true collaboration.”

Trend Micro was first to publish three of the Hacking Team Flash bugs. The company’s chief cybersecurity officer Tom Kellermann likens the history of laxness of Adobe’s security practices in light of Flash’s popularity to poisoning the water supply for all of a village’s wells.
“The dark web is impressively expansive and organizations of this size, conducting schemes of this magnitude, are hidden throughout it in unprecedented numbers,” said Trend Micro chief cybersecurity officer, Tom Kellermann. “With the amount of exploit kits on the market today, the financial sector must brace itself for an increased level of more intensified attacks.”

Trend Micro threat analyst Jay Yaneza said the combination of more developers using .NET in applications and the ease by which hackers can find vulnerabilities in open source software has led to a boom in point of sale (POS) malware targeting Microsoft's .NET software.

Hacking Team intrusion malware can also target iOS and Android devices. Here are the dirty details about Android attacks, from Trend Micro. Note that it warns that if you've been infected, it will be extremely difficult to clean the infection yourself. You'll have to have root privilege to the device and get help from your phone's manufacturer to flash the firmware.

On the other hand, the European Union, with its Right to Be Forgotten rules, has a "much more stringent framework than we do in the United States because we let companies get away with a lot more" here, says Paul Ferguson, a senior threat research advisor at Trend Micro.

But that may be a race that it cannot win. Paul Ferguson, senior adviser for Trend Micro, a security software provider, said that information on Ashley Madison, deleted in one online forum, is beginning to bubble up in others. Once something is published on the Internet,” he said, “it’s there forever.”

FBN’s Jo Ling Kent, Liz Claman and Trend Micro Chief Cybersecurity Officer Tom Kellerman discuss the Ashley Madison hack. [Video]

These new findings, which come from the security research company Trend Micro, indicate that Hacking Team build a fake Android news app. It was called "BeNews," which happens to also be the name of another, now defunct news site. It appears that Hacking Team was able to build the fake app so that it looked legitimate enough to be accepted into the Google Play app store. Nestled inside the app's code, however, was a backdoor to make it a mobile spy tool.
In life and in fiction, the numbered Swiss bank account stands as an untouchable repository for funds, legally obtained or otherwise. Modern criminals likewise need a secure repository, not necessarily for funds but for online resources. A recent report from Trend Micro delves deeply into the world of Bulletproof Hosting Service (BPHS) providers. We don't yet know precisely how and where Darkode's resources were stored, but a BPHS was almost certainly involved.

Forums like Darkode represent one leg of the stool that is the problem of criminal hacking, says Tom Kellermann, chief cybersecurity officer at Trend Micro, because these shutdowns send a warning to American cybercriminals that they may be arrested.
Chief Cybersecurity Officer Thomas Kellerman weighs in on the suspension of trading at the NYSE and the latest malware release. (VIDEO)
“A separate attack against one of these vulnerabilities shows that not sharing the discovery of vulnerabilities with the vendor or broader security community leaves everyone at risk,” argued Trend Micro global threat communication manager, Christopher Budd.
SkyBridge Capital founder Anthony Scaramucci, Heritage Foundation Fellow Steve Moore, former FBI agent Bill Daly and Chief Cybersecurity Officer Tom Kellermann discuss the suspension of trading at the NYSE and concerns about cybersecurity and potential cyber-attacks. (VIDEO)

Hacking tools work by relying on using so-called "zero day" bugs -- vulnerabilities unknown to software makers. According a blog post from cybersecurity firm TrendMicro, the cache has so far revealed the company's tools relied on least two problems in Adobe's Flash Player and in Windows itself.
Researchers from antivirus firm Trend Micro said in a blog post that the leaked Hacking Team files contain two exploits for Flash Player, one of which is already known and has been patched, and one for the Windows kernel.
On Tuesday, security firm Trend Micro shared that at least three exploits – two targeting Adobe Flash Player and one targeting Windows kernel – were found in the information dump.
“A separate attack against one of these vulnerabilities shows that not sharing the discovery of vulnerabilities with the vendor or broader security community leaves everyone at risk,” wrote Christopher Budd, global threat communications manager at Trend.

A cyber blackmail ring is targeting the UK with bogus, malware-filled emails pretending to come from big name companies and government bodies. Trend Micro fraud analyst Paul Pajares and senior architect Jon Oliver reported uncovering the scam in a threat advisory.
We enlisted a team of moderators to ask a number of prominent IT security professionals about the challenges they faced as a woman entering the field, the prejudices they deal with every day and the skills they use to navigate within their business.

Recently discovered malware which uses digital steganography to hide itself in .PNG files has been overwhelmingly targeted at US healthcare providers, according to Trend Micro.
In the past year, U.S. businesses and consumers have experienced more than $18 million in losses stemming from a single strain of ransomware called CryptoWall, according to the Internet Crime Complaint Center.
It may be known to hackers and coders worldwide but for most internet users, the so-called 'Deep Web' remains shrouded in mystery, a supposed morass of drugs, deviancy and stolen credit card details.
The Sept. 11 attacks spurred changes to airport security to prevent future hijackings. But should airline passengers also worry about virtual hijacking?
'Census report' of the unindexed parts of the Internet unearths everything from Bitcoin-laundering services to assassins for hire.
The dark web operates behind an understanding of anonymity. Users aren’t supposed to be able to access dark web websites unless their traffic is anonymized using services like Tor. The IP addresses of dark web services are also hidden so that their hosts are not able to tracked — or at least that’s how it’s supposed to work.

For the U.S., the extradition of Ercan Findikoglu shows the value of patience when it comes to pursuing suspected hacker kingpins.

The deep Web is the vast section of the Internet that isn’t accessible via search engines like Google. To get to the deep Web, you have to use specific software like TOR—The Onion Router—which works to anonymize traffic between two points on the “unindexed Internet.”
The deep and dark web may have a reputation for the illegal and illicit, but it can be a lifeline to many in oppressive and dangerous regimes.
Working out who is behind a cyber attack is one of the hardest parts of dealing with any security incident - and it's getting a lot harder.

It took less than a week for a functional exploit for a recently patched Adobe Flash Player vulnerability to be added to the Magnitude exploit kit, Trend Micro researchers warn...
Trend Micro researchers have unearthed two separate but closely linked malware campaigns attributed to Arab parties.

Contrary to tradeshow presentations, the industry has not failed cybersecurity professionals as many speakers insinuated
Symantec Describes Dual Attack Now Targeting Consumers