| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Internet security company Kaspersky says software was used to infiltrate venues for international negotiations on Tehran’s nuclear programme
The targeted cyber-attack on French TV company TV5Monde in April may have been the work of state-backed Russian hackers and not a pro-ISIS group, as originally thought. The hack forced several channels off the air.

Things could get worse before they get better as the FBI, US-CERT and Office of Personnel Management investigate a data breach that may have compromised the personal information of some 4 million current and past federal employees...
Recent point-of-sale malware attacks, and reports about emerging malware strains, highlight why more attention needs to be paid to POS system security.
A new malware program designed to steal payment card details from point-of-sale (PoS) systems is targeting businesses using Oracle Micros products.

The United States is engaged in a proxy war with its enemies, a war where cyberspace is the battlefield, cyber experts say.
There’s a new, easier and free way to store and organize your photos, but beware of the fine print.
There's a new twist in the way feds are seeking to penalize bad actors for making and distributing software used in crimes, suggest recent arrests by Justice Department and FBI officials.

Most virtualization security tools still follow dedicated agent models, but some technologies are starting to offload resources to a dedicated VM and leverage hypervisor APIs.
The hackers who got access to over 100,000 personal records through the Internal Revenue Service's Get Transcript site didn't need all that much information to break in, say experts.
Trend Micro provides peek at methods of amateur, lone-wolf carder.
Everywhere you look, it seems to be that everything is becoming “smart”. On my wrist, I frequently wear a smart watch that monitors how many steps I take, what my heart rate is, and so on...

The IP address for a command and control (C&C) server employed by Carbanak, an advanced piece of malware used in attacks targeting financial institutions directly, now resolves to a domain that appears to be owned by the Russian Security Service (FSB), researchers found.

Add CareFirst - the Maryland and Washington, D.C. BlueCross BlueShield - to the expanding list of insurers that have suffered data breaches. Over 1.1 million customer records have been acknowledged to have been stolen in a breach announced this week.

An IDC report indicates the market for the Internet of Things will only become more robust over the next few years. An increased use in retail digital signage will help the IoT market grow 19 percent in 2015.

On Thursday, Taryn Naidu, the CEO of domain registrar eNom, sent a letter to customers disclosing a "very sophisticated attack" that targeted the DNS settings on four domains.
The United States remained the largest host and target for cyber-attacks in the first three months of the year, a quarter which saw hackers take up new tools, tactics and procedures – and return to some old ways – in order to improve success rates...

Trend Micro is a company with a simple, yet ambitious goal, to protect their users from cybercriminal activity...
Trend Micro TrendLabs released a new report today that summed up the first three months worth of malicious activity as a function of utility rather than ingenuity...
In April, the New York State Department of Financial Services issued a report about significant third-party and vendor management risks that numerous banks throughout the state were failing to address.
While some security experts warn that the VENOM vulnerability disclosed yesterday is potentially worse than Heartbleed, others dismiss those comparisons and say the media coverage is overblown.
CrowdStrike CSO Shawn Henry and Trend Micro Chief Cyber Security Officer Tom Kellermann discuss the deadline for the NSA Dragnet deal wtih Emily Change on "Bloomberg West."
Amid the turmoil in Ukraine, Romania has emerged as an unlikely cybersecurity ally for the international community.

In an era when businesses are scrambling to defend against sophisticated advanced persistent threats, old school anti-virus may seem like a relic. But traditional anti-virus companies are changing with the times, delivering defense-in-depth for a BYOD world.

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.
A rise in cyber attacks against doctors and hospitals is costing the U.S. health-care system $6 billion a year as organized criminals who once targeted retailers and financial firms increasingly go after medical records, security researchers say.

Spear phishing and its evolutions like the watering hole attack represent one of the most insidious attack techniques adopted by the majority of threat actors in cyberspace.
Security researchers have shed new light on seven-year-old point-of-sale (POS) malware still being used today, most recently to attack casinos and resort hotels...
Security firms report a sharp rise in the quantity of attacks that use macro code - designed to automate tasks - to trigger malware downloads, often for the purpose of stealing people's online banking credentials.

Last year's breach of unclassified White House computer systems was far more intrusive than initially thought and included the theft of some presidential correspondence, The New York Times reported Friday.
Macro malware isn't dead yet, if a new campaign targeting banks and financial institution is any indication.

Four days after Defense Secretary Ash Carter launched the Pentagon’snew cyber strategy, experts and officials offered a grim picture of the global threat. The threat is metastasizing in ways that will require new kinds of defenses — even while many US companies and government agencies lag on basic cybersecurity measures.
Trend Micro’s Dave Abramowitz discusses the White House hack attack with Bloomberg’s Alix Steel on “Street Smart.”
Sextortion—enticing victims to send naked or sexually suggestive pictures of themselves, which are then used to blackmail them for money or sexual favors—is not a new digital phenomenon. But the methods of accomplishing it are evolving. A new Android app has been developed expressly for use by sextortionist-minded hackers.

Times are a changing. Once a upon a time your security was all about a decent Firewall and some Anti-Virus and you were good to go. Yeah, not so much any more. Signature based Anti-Virus, as a tool to protect you from infection, is pretty much useless in this day and age. Why, because hackers and the techniques they use to infect you have evolved.

Failing to properly secure your website can seriously damage your brand. Don't let your site visitors get cyber-mugged.
The threat landscape is constantly changing, and so is the information deemed valuable to hackers. While 2014 was the so-called year of the breach, when consumer card data was the hottest commodity, 2015 has been marked by more attacks aimed at compromising personally identifiable information and corporate intellectual property.

Threat Intelligence, Crypto Among Topics at Must-See Sessions
Our handpicked list of compelling RSA 2015 sessions will help you find the cybersecurity signal above the conference noise.
A widely reported Russian cyber-spying campaign against diplomatic targets in the United States and elsewhere has been using two previously unknown flaws in software to penetrate target machines, a security company investigating the matter said on Saturday.
Threat actors have set up several new C&C servers and dozens of new malicious URLs -- and now targeting White House staffers, Trend Micro says.
Even though its activities were exposed last year, a cyberespionage group dubbed Pawn Storm has ramped up its efforts over the past few months, targeting NATO members and potentially the White House.

Many ordinary people imagine hackers as Guy Fawkes-mask-wearing rebels living on the margins of society, suspicious of government, and courageous or crazy enough to follow wherever their computer wizardry takes them. In reality, said experts, many just want a steady job.

More small businesses are falling victim to “ransomware,” in which malicious code locks up computer files and cybercriminals demand a ransom to free them.
Online dating hackers are becoming much more sophisticated in the way they target and steal money victims' cash. Cybercriminals are now asking their "dates" to install a custom-made smartphone app that installs malware and allows them to extract details for blackmail purposes, Global Dating Insights reports.
Fourteen C&Cs dismantled to take out nerve center of a botnet that spanned 190 countries.

Analysts believe that recent point-of-sale (POS) malware attacks targeting more than 100 terminals in Brazil were the handiwork of a single person – who managed to steal more than 22,000 unique credit cards numbers in a little over a month.

Survey results indicate a lack of information about the security safeguards in place is fueling respondents’ worries about Internet of Things (IoT).

A new report released this week by Trend Micro and the Organization of American States (OAS) shows a dramatic increase in cyberattacks directed against critical infrastructure owners and operators.

Tokenization, where credit card numbers and other sensitive data is replaced by random characters, can be a secure alternative to encryption in many cases -- but would not have helped in the majority of retail breaches over the past two years.
Trend Micro’s Tom Kellerman and David Hoovler, former trial attorney at the U.S. Justice Department, discuss the report that criminal hackers doing the bidding of the Russian government hacked into a non-classified White House computer network last year.
A new ransomware variant detected by Trend Micro as BAT_CRYPVAULT.A, or CRYPVAULT, is being distributed as an attachment in spam emails and is targeting mostly Russian speakers

Trend Micro just released a new report that shows how many businesses are vulnerable to Sony-like attacks. Trend Micro Chief Cybersecurity Officer Tom Kellermann breaks down the report.
Hacking attacks that destroy rather than steal data or that manipulate equipment are far more prevalent than widely believed, according to a survey of critical infrastructure organizations throughout North and South America.
Hackers are trying to tamper with critical infrastructure with cyberattacks designed to delete files, manipulate equipment and shut down networks, according to a new international survey.
You don't have to be a celebrity to get nailed by a nude photo. According to a report by Trend Micro, sextortion—the use of compromising photos or videos to extract money from victims—is on the rise.

Recent research from IBM Security and the Ponemon Institute disclosed a major lack of mobile security – according to the results, almost 40% of large companies aren’t taking the necessary measures to protect their mobile apps.
The Health Information Trust (HITRUST) Alliance will sponsor a study to analyze the effects of cyber attacks on healthcare organizations.
While observing the evolution of point-of-sale malware, called NewPosThings, Trend Micro traced suspicious traffic back to two U.S. airports.
The majority of consumers aren't willing to alter their behavior to preserve privacy in the era of the Internet of things, even though it remains a huge issue for people, a Trend Micro survey of 1,903 individuals from 18 countries found.

Repackaged applications can present multiple enterprise security risks. Expert Nick Lewis explains what these fake apps are and how to defend against them.

A big part of what makes technology exciting is the promise it holds for the future.
Quickly patching vulnerable software is key to keeping computer systems secure. Yet, consumers are increasingly leaving their systems open to attack by failing to patch two ubiquitous third-party programs: Oracle's Java and Adobe's Flash.
Experts Weight Reasons for New Regulatory Warnings
In recent years we've seen increasing numbers of companies fall victim to ransomware that encrypts a compromised computer's files, threatening to delete them all if a Bitcoin ransom isn't paid to the attacker…

Although compliance rules are supposed to set minimum standards for protecting data, many companies treat them as maximum benchmarks.
Trend Micro Chief Cybersecurity Officer Tom Kellermann examine GitHub under cyber-attacks for the fourth day. He speaks with Bloomberg's Alix Steel on "Street Smart."

Organizations are collecting, processing, and analyzing more and more network traffic.
Software and tech predictions have been the talk of IT town for a good bit of time, particularly when 2014 came to a close. Despite the fact that predictions are just that – predictions – and may either come to fruition or not, they point businesses in the right direction in terms of the trends to watch out for in their respective fields.

The final piece of the info sharing legislative puzzle was laid down on Tuesday as lawmakers push toward an April session that could see cyber bills hit the floors of both chambers.

For years, criminals have been tricking people into performing embarrassing sexual acts on the Internet, and then blackmailing them with recordings of that behavior.
Sextortion rings that dupe victims into recording themselves performing sexual acts and afterward demanding ransom or they will publicly distribute the recordings are on the rise according to a report by Trend Micro.
Researchers have picked up on a new spam campaign that sends victims phishing messages from a .gov account that thwarts email validation systems.
Next-generation endpoint security suite could be a billion dollar play
Security researchers have uncovered a new targeted attack campaign against Israeli and European organizations launched by the state-sponsored threat group known as ‘Rocket Kitten’.

The Apple Watch hasn't even been released yet—but one company is betting it's going to be a big hit with business users, and has made an app to turn the smartwatch into an office.
Trend Micro's Tom Kellermann and Cylance CEO Stuart McClue discuss why hackers are targeting health insurance companies.
Experts analyze bank breach investigation developments
Since 2006, when the earliest exploit kit (WebAttacker) was made available in the crimeware market, these hack toolkits have become one of the preferred ways for cybercrooks to deliver malware to unsuspecting users.
Why experts say employee education is critical
Lenovo may have publicly buried bloatware, but it’s anything but dead. After the company’s Superfish scandal, we shopped Best Buy and found it alive and well on major vendors’ PC offerings. A little research should save you from the worst of it, though. Here’s what we learned.
The tools and tactics being used to go after victims reveal growing sophistication, and gamers need to look out, security researchers say.

Additional login step brings extra layer of protection against hackers for Apple’s messaging and video chat, but more can be can be done say experts

Kathleen Pender has answers to reader questions about online tax filing, credit scores and how long to keep tax records.
Dell is getting deeper into the business of securing corporate networks, releasing a new integrated security suite based on encryption technology it acquired when it purchased Credent in 2012.
Security researchers have discovered two point-of-sale (POS) malware families: “PwnPOS,” which showcases attackers' “simple but thoughtful construction” for skirting detection, and the “LogPOS” family that uses Microsoft Windows' mailslots to deliver stolen credit card data to attackers.

Most people have something in common with Hillary Clinton, and it has nothing to do with politics: they struggle to keep their email accounts safe. This could be particularly dangerous as far as their finances are concerned.
OCC, NY DFS Call for Better Standards, Info Sharing
Israel is rapidly building an elite team of cyber warriors to prevent Iran from obtaining nuclear weapons, analysts say.
Just before Hillary Rodham Clinton was sworn in as secretary of state in January 2009, she and her closest aides decided that she should have her own private email address as Mrs. Clinton moved away from the Blackberry address that she had used during her 2008 presidential campaign.
By leveraging email authentication methods to ensure that malicious messages evade spam filters and end up directly in inboxes, attackers are improving the chances of infecting users with TorrentLocker ransomware, according to researchers with Trend Micro.

In its 2014 Annual Security Roundup, security firm Trend Micro reported that the digital attacks on Sony Pictures last year may have cost the company $100 million USD.

The cloud security software market will balloon by nearly 50 percent annually as more end users move to sidestep the high total cost of ownership (TOC) associated with traditional on-site security software.

Intuit’s brief shutdown of state tax filing this month exposed a dirty little secret: U.S. companies, even those dealing with the most sensitive information, don’t always use the highest level of security available.

Groups in the Middle East and North Africa are becoming increasingly skilled at mounting cyber-attacks that apply cyber-crime tactics to steal sensitive data.

Israeli institutions have been targeted by an Arab-speaking hacker group that sought to extract sensitive documents, according to Trend Micro.

The dedicated researchers at AV-Test Institute run constant tests on several dozen popular antivirus products under several different versions of Windows.
Security researchers have uncovered two interconnected Middle East attack campaigns of very different skill levels aimed at stealing sensitive information from Israeli and Egyptian targets.
Israel may be known as a technology and cyber security powerhouse, but a sophisticated Arab-led hacking campaign has been relatively successful in penetrating several important Israeli sites and possibly extracting data from them.