| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Emails purporting to be alerts regarding Google Chrome and Facebook, and pointing to CTB-Locker file-encrypting malware samples, have been found to share compromised websites used for phishing campaigns.
Spammers have worked hard to take advantage of the Valentine’s Day season with socially-engineered spam, and other common online dangers like social networking scams are also trying to take advantage of the season.

A year after the Obama administration released the voluntary framework for improving cybersecurity, questions remain about its current and future success.
Steve Jobs's legendary rant against Adobe Flash turned out to be as personal as it was about technology.
Calling the destructive cyberattack on Sony Pictures "a game changer," a top White House official on Tuesday announced a new intelligence unit to coordinate analysis of cyberthreats, modeled on similar U.S. government efforts to fight terrorism.

Announcements of assessments follows Anthem breach

Everyone worries about stolen credit cards or hacked bank accounts, but just visiting the doctor may put you at greater risk for identity fraud.

In 2004, Insafe, a Brussels-based non-profit funded by the European Union, launched Safer Internet Day. An annual event, it’s now celebrated on the second Tuesday of February in more than a 100 countries.
Security researchers have discovered two new malicious iOS apps which can infect even non-jailbroken devices and are being used to spy on targets as part of an ongoing cyber-espionage campaign.
This week the Anthem breach saw millions exposed from an unencrypted database, Obama created a new White House cyber unit, HipChat got popped, we learned more about the iOS espionage app Pawn Storm. About.com ignored its massive XSS problem, and much more.
A new front has opened up in the Operation Pawn Storm cyber-espionage operation -- an iOS app that spies on users, up to and including secretly turning on the phone's microphone to listen in to meetings and conversations.
Adobe started to push a new release of Flash Player that fixes the zero-day vulnerability currently exploited in the wild and reported by the company on Monday.

Still looking for a reason to upgrade to iOS 8? Security firm Trend Micro released a report on Wednesday revealing that some of the most dangerous spyware it has ever seen is making the rounds on iOS devices, but is far more effective on iOS 7than on Apple’s latest operating system release.

A new brand of malware that could be tied to the Russian government is being used to spy on Western military officials, government workers and members of the media, according to new research from a prominent cybersecurity firm. Known as “Operation Pawn Storm,” the spyware first targeted Microsoft users about the time Russian troops invaded Ukraine, though it has now been discovered on Apple iOS devices.
“Operation Pawn Storm,” an espionage campaign initially profiled in October, has a new tactic for spying on targets' communications - installing spyware on acquaintances' iOS devices.
Attack campaign tied to Russia now zeroing in on mobile user's iPhones, iPads.

Less than five weeks into the new year, 2015 is already shaping up as one of the most perilous years for users of Adobe Flash, with active exploits against three separate zero-day vulnerabilities, one of which still wasn't fully patched as this post went live.

Reports have surfaced today that a new type of spyware is in the wild and targeting iOS devices. The spyware is part of a malware campaign security industry people are calling “Operation Pawn Storm.”

In 2004 a project of the European Commission launched "Safer Internet Day," which became an annual event held on the second Tuesday of February. This year represents the 11th Safer Internet Day, which is now being celebrated in more than 100 countries, including the United States.

Attackers who have slipped malicious advertisements onto major websites over the last month have potentially compromised large numbers of computers.
Breaches of information security and individual privacy hit the headlines regularly in 2014. But how will the arms race between cyber-attackers and defenders develop in the coming year? We analyse the experts' predictions.
The call for papers for Infosecurity Intelligent Defence 2015 is now open.
The latest open-source Linux vulnerability is serious but some security experts say it's not that easy to abuse and use in an attack.

A serious vulnerability in a key Linux library could let attackers take complete control of systems, such as servers, that are based on the open-source operating system. Those running Linux systems are advised to download a patch for their distribution immediately.

Cybercrime has evolved from simply stealing information for financial gain to ruthlessly infiltrating industries with the goals of destroying intellectual property, damaging reputation and crippling critical operating functions.
The Internet of Things (IoT) is often portrayed as some kind of futuristic concept, but the reality is that ‘smart things’ already have an established presence in our homes and workplaces.
ESG research provides another indication that the endpoint security market is in a state of transition

Adobe Systems is once again rolling out an emergency Flash update that patches a critical vulnerability under active attack to compromise the computers of unsuspecting users.
A variant of Curve-Tor-Bitcoin (CTB) Locker ransomware – also known as Critroni – being distributed in a spam campaign now offers victims additional time to pay the ransom, but also requires them to pay a whole lot more than previously, according to the latest research by Trend Micro.

Every antivirus software package promises to protect your computer from danger, but when it comes to detecting malware, there are huge differences among them.

An exploit for a still officially unconfirmed zero-day vulnerability in Adobe Flash Player has been added to the popular Angler exploit kit and is, along with exploits for several other Flash flaws, opening users' Windows machines to the Bedep trojan.
Smart devices largely use the same operating system as their smartphone counterparts. This is the case with Android devices. When we talk about smart devices and Android, we’re talking about a mature platform in terms of malware.

The White House announced plans last week to share more information about cyber threats between the government and the private sector and create a 30-day customer notification requirement after data breaches.
Computer security experts often advise to users to download games, apps, documents, software and software updates directly from the original source (the manufacturer) or from reputable online stores.
Ever wonder how much your personal information is worth when some nasty cyber crook gets their hands on it? You now can get an inkling of that from an interactive infographic that’s been put together by security firm Trend Micro.

U.K. and U.S. security services could hack their countries' own banks, in order to test their defences against cyberattacks.

Expert Ed Tittel examines the top endpoint antimalware products for small, mid-sized, and larger enterprises.

It seems nearly every day we’re reading about Internet attacks aimed at knocking sites offline and breaking into networks, but it’s often difficult to visualize this type of activity.

Trend Micro Chief Cyber Security Officer Tom Kellermann and Mashable Senior Technology Editor Pete Pachal on Twitter’s cyber security systems, Centcom’s account hacking and ways to stay safe.
Trend Micro Vice President of Technology and Solutions JD Sherry and Bloomberg's Phil Mattingly discuss the hack of the United States Central Command's Twitter account.
A malicious email campaign targeting mostly users in Australia with TorrentLocker ransomware has brought its operators a hefty revenue of about $224,000 / €190,000 in one month.

Gartner names Intel Security, Kaspersky Lab, Sophos, Symantec and Trend Micro as leaders in its Magic Quadrant for Endpoint Protection Platforms.
Criminals hijacked ads on AOL's Advertising.com network

The global leader in security software, Trend Micro Inc. has recently announced a $10,000 donation to the Mission College Center for Innovation and Technology (MC²IT) in support to cybersecurity course curriculum.

Researcher spots spike in traditional financial malware hitting ICS/SCADA networks -- posing as popular GE, Siemens, and Advantech HMI products.

Microsoft says German speakers are being targeted by a new variant of a powerful type of malware that steals online banking credentials.

It's been exactly one year since ASUS launched its ZenFone line of relatively affordable Android phones, and having shipped 8 million units so far, the Taiwanese company is keen to keep the momentum going.
So say a dozen security specialists and former law-enforcement officials, who described an intensifying and largely unspoken sense of unease inside many companies after the recent breach of Sony Corp.’s networks.
At least one former employee of Sony Corp. may have helped hackers orchestrate the cyber-attack on the company’s film and TV unit, according to security researcher Norse Corp.
The FBI refused to budge on Tuesday off its finding that North Korea masterminded the massive Sony studio hack — despite a growing number of private cyber-security firms concluding there was no evidence of such a finding.
The studio has canceled the release of the Seth Rogen-James Franco comedy, which was set to open Christmas Day.
Trend Micro Vice President JD Sherry and Invincea CEO Anup Ghosh discuss how to respond to the Sony hacking.
HP has signed a strategic OEM agreement with Trend Micro in an effort to strengthen HP's TippingPoint Advanced Threat Appliance (ATA) family of products.
Trend Micro's Tom Kellermann and Bloomberg's Lucas Shaw discuss the ethical issues raised by the hack attack on Sony Pictures. They speak with Bloomberg's Trish Regan on "Street Smart."
Hacking trends are not like fashion fads. They don't go in and out each year. They withstand defenses by advancing, in terms of stealth and scope.
The latest and greatest hackers drop British clichés in their attack code, deploy Chinese cyberweapons, sprinkle in lines of Hindi and keep an Eastern European workday.
It's been a year since the breach at Target Corp., which exposed 40 million debit and credit cards along with personal information about an additional 70 million customers.
A cyber security startup has raised millions from Kleiner Perkins and others to battle “spear phishing” cyber attacks.
Trend Micro VP of Tech and Solutions JD Sherry gives insight on the Sony hack and cyber security.
Trend Micro Vice President Technology and Solutions JD Sherry and Bloomberg’s Lucas Shaw discuss the Sony hack attack.
Bank fraud is quite the popular area for cybercriminals and while security professionals may think they're making the lives of miscreants more difficult, it's actually the other way around. The cat and mouse game continues in the financial arena and attackers have leveraged popular tactics this year such as “Island Hopping,” targeting the virtual supply chain of an institution in order to compromise those assets and make their way into the primary target's network.
FBI Investigates Threatening Emails Sent to Sony Pictures
The malicious software that crippled Sony Pictures Entertainment and resulted in the release of gigabytes of sensitive information was not something that even state of the art antivirus software would have picked up.
The cyber attack against Sony Pictures continues to be a major problem for the company. For one, it looks like the hackers used malware called Destover (which security firms believe could have been created in Korea) that can completely disable hard drives, rendering computers useless. Worse, the hackers calling themselves the Guardians of Peace recently leaked more info: a whole folder full of company passwords, as well as former and current employees' salaries and social security numbers.
Some cybersecurity experts say they've found striking similarities between the code used in the hack of Sony Pictures Entertainment and attacks blamed on North Korea which targeted South Korean companies and government agencies last year.
Ridge-Schmidt Cyber Partner Howard Schmidt and Trend Micro Inc.’s Tom Kellermann discuss cyber-attacks, Sony’s hacking and biggest threats for the U.S.
The Federal Bureau of Investigation warned U.S. businesses that hackers have used malicious software to launch a destructive cyberattack in the United States, following a devastating breach last week at Sony Pictures Entertainment.
The FBI is warning businesses that hackers have launched a coordinated, destructive cyberattack using malware similar to that seen in last week’s Sony Pictures cyberattack, Reuters reported.
Just as Sony Pictures Entertainment appeared to be recovering from a crippling online attack last month, the studio found itself confronting new perils on Tuesday. The Federal Bureau of Investigation warned United States businesses of a similar threat, and additional Sony secrets were leaked online.
A new report from security vendor FireEye about the emergence of cyber-attacks aimed at the accounts of high-level executives at publicly traded corporations for the purpose of "obtaining an edge" in stock trades has raised some questions among financial fraud experts.
The hacking attack that hobbled Sony Pictures Entertainment in recent days has left other Hollywood studios examining their own security measures.
The presence of debug information in the malware, as well as the lack of any identifiable command-and-control capabilities, has led researchers to believe that TSPY_POSLOGR.K is in a beta testing phase, Christopher Budd, global threat communications manager with Trend Micro, told SCMagazine.com in a Monday email correspondence.
A security researcher came across what appears to be a new family of point-of-sale malware that few antivirus programs were detecting.
Nick Hoffman, a reverse engineer, wrote the Getmypass malware shares traits that are similar to other so-called RAM scrapers, which collect unencrypted payment card data held in a payment system’s memory.
Companies are already seeing wearables around the workplace but it seems many haven't considered the wave of adoption that could be imminent — and the privacy and security issues it will raise.
The use of wearable technology devices at work is set to soar over the coming 12 months, but UK IT leaders appear to be taking a worryingly laid back approach to securing them against data theft, according to Trend Micro.
The October edition of the Harper's Magazine Index included this doozy of a statistic: The average global company in 2013 was subjected to 16,856 cyber-attacks.
‘Tis the seasons for getting monster deals online. But just because Cyber Monday lacks the threat of being trampled to death by a hoard of penny pinchers doesn’t mean you’re safe. Scammers, hackers, and swindlers of all types are lurking in grungy basements around the world, ready to dupe anyone who fails to properly protect their e-commerce transactions. Here’s everything you need to do to make sure your Cyber Monday goes off without a hitch.
An independent test of advanced threat detection products demonstrates how they could be bypassed by attackers.
Brazil has a thriving scene of cybercrime online "schools" offering training programs as well as a vast array of services offering financial data obtained illegally, according to a recent study on the country's digital underworld.
Amazon Web Services partners share how their companies continue to adapt to the growth of AWS.
Earlier this month, researchers at cybersecurity firm FireEye discovered a vulnerability in the iOS operating system which could allow hackers to replace legitimate apps with malicious copies, giving them access to any data the user entered into the hacked app. These “Masque Attacks” were enough of a threat to convince the U.S. government to release a statement warning iPhone users to avoid downloading apps from third-party sources until the issue could be resolved.
Hackers are claiming to have broken into the Sony PlayStation Network (PSN), Microsoft Windows Live and 2K Games to leak over 5,500 usernames and passwords.
The Masque bug that affects iOS apps has the potential to steal data from legitimate sources, due to a lack of encryption in apps across the board.
Over the last few months, I’ve talked to a number of CISOs and security analytics professionals about threat intelligence, as I’m about to dig into this topic with some primary research.
New report shows level of coordination and strategy by three main groups of cyberspies out of Russia.
In today’s “Global Outlook,” Trend Micro's Chief Cybersecurity Officer Tom Kellermann discusses why cybercrime has been thriving in Brazil. He speaks with Bloomberg's Trish Regan on "Street Smart." (Source: Bloomberg)
Despite a massive data breach that compromised 56 million payment cards and 53 million e-mail addresses, Home Depot reported $1.54 billion in net earnings for its third quarter, a 13.8 percent increase from the same period last year.
The U.S. State Department has shut down an unclassified network and email system in response to suspicious activity recently detected by the government.
Though it's unlikely that you'll ever encounter Android malware, it's still possible. It's also pretty dang likely you'll lose your Android device at some point. To combat those and other threats, both exotic and mundane, there are security apps like Trend Micro Mobile Security & Antivirus (free). This app ticks off most of the boxes for a security app, but doesn't distinguish itself in a crowded space.
Hundreds of U.S. financial companies are ramping up spending to combat hackers following attacks this summer on J.P. Morgan Chase & Co. and at least a dozen other firms.
A new version of Bashlite aims to get control of devices running on BusyBox, such as routers.
Cyber attacks and data theft are continuing to infiltrate our daily lives, with some of the largest and most well-known brands falling victim. With the frequency and pervasiveness of these attacks, healthcare organizations must be mindful that they are at a heightened risk of being compromised.
Researchers at Trend Micro have been analyzing two keyloggers, dubbed Predator Pain and Limitless, and they recently released a paper on their findings.
How notorious remote access tools Predator Pain and Limitless have evolved into bargain-basement tools accessible to masses of cybercriminals.
The computer breach of the U.S. Postal Service, revealed Monday, could be part of the undeclared cold war in cyberspace, some experts say.
Security researchers have discovered a new type of phishing attack using proxy programs to make the malicious site harder to detect.
The revelation that Home Depot's breach resulted from the compromise of a third-party vendor is "eerily" similar to the circumstances of the Target data breach, security experts say. The two mega-breaches point to the need for retailers to more closely monitor the security measures of their vendors and ramp up breach detection efforts.
As thousands brave Black Friday lines for door-busting discounts, cyber criminals will be waiting in the shadows to grab the season’s biggest steals.
Tom Kellermann, chief cybersecurity officer at Trend Micro, discusses the Home Depot data breach with Bloomberg's Trish Regan on "Street Smart." (Source: Bloomberg)
Targeted attacks could soar next year as increasing numbers of cyber-criminals in different geographies get their hands on the tools and techniques necessary to do the job, according to Trend Micro.