| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

According to security researchers at Trend Micro, the sophisticated tool sheds light on the group’s evolving objectives and marks a significant shift in tactics.

Threat actors are leveraging malicious kernel-level drivers in two separate campaigns detailed on Monday by Fortinet and Trend Micro.

Kevin Simzer of Trend Micro shares his top tips on how startups can break into the cybersecurity scene and the importance of security companies working together, rather than competing against one another, in the fight against cybercrime.

Guerilla malware, distributed by cybercrime gang Lemon Group, can load additional payloads, intercept one-time passwords from SMS texts, set up a reverse proxy from the infected device, and infiltrate WhatsApp sessions.

Lemon Group itself has claimed it has a base of nearly 9 million Guerrilla-infected Android devices that its customers can abuse in different ways. But Trend Micro believes the actual number may be even higher.

Miscreants have infected millions of Androids worldwide with malicious firmware before the devices even shipped from their factories, according to Trend Micro researchers at Black Hat Asia.

Bring together a group of hackers to find and exploit vulnerabilities before the bad guys can, and reward the best ones with cash or prizes: that’s the idea behind Pwn2Own.

Trend Micro's Jon Clay Gets Behind the Scenes of Criminal Organizations

Join Kevin Simzer at RSAC 2023 for a panel discussion on the security challenges of mergers and acquisitions.

Bill Malik of Trend Micro had a talk on detecting and reacting to supply chain vulnerabilities from a maritime perspective, describing the issues that pose a significant risk to the port and shipping industry.

Based on what has been publicly disclosed, AI uses techniques similar to rainbow table attacks rather than simply brute forcing a password, observed Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative.

As the metaverse takes shape over the coming years, many of the security issues afflicting cyberspace will begin to spill over into virtual space as well.

The company says it received two reports from cybersecurity expert Trend Micro on January 10th, 2023, informing the company of two high and critical severity flaws impacting PaperCut MF/NG.

Already this year, Trend Micro reports there’ve been Netflix “We’re sorry to see you go” scams, Netflix job scams, Netflix $90 reward scams, Netflix “Having trouble with your account scams,” and Netflix “Your membership has ended, but…” scams.

Women in cybercrime are more common than you think. Mayra Rosario Fuentes, Underground Cybercriminal Expert at Trend Micro, joins Jill Malandrino on Nasdaq TradeTalks to discuss.

To fully comprehend the complexities of the business, Trend Micro's study "Inside the Halls of a Cybercrime Business" sheds light on the importance of defining and understanding the size of these organizations.

Childs says cybersecurity is set to be a defining factor for the auto industry, as manufacturers develop new infotainment and tech features at a rapid pace.

The digital vein of printer vulnerabilities is far from being tapped out, says Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, which runs the Pwn2Own competition.

Fears big and small can hold us back from becoming the best versions of ourselves, personally and professionally.

"Microsoft was reluctant, for a time, to make this patch official," says Jon Clay, vice president of threat intelligence at Trend Micro.

The researchers, who work for security firm Synacktiv, found the vulnerabilities and showcased them at the Pwn2Own conference in Vancouver last week.

Over the course of my career, I’ve seen private equity and M&A be a detriment to the growth of peer companies—motivating me to protect Trend Micro’s growth by deliberately focusing on building internally.

The ChatGPT AI bot has spurred speculation about how hackers might use it and similar tools to attack faster and more effectively, though the more damaging exploits so far have been in laboratories.

Trend Micro has said it stopped 146 billion cyber-threats in 2022, a 55% increase on the previous year and evidence of cyber-criminals widening their efforts to companies of all sizes and sectors.

During its time, DoppelPaymer was “a textbook of the more successful crews that had been doing ransomware attacks,” Ed Cabrera, chief cybersecurity officer at Trend Micro, told me.

As we've noted before, the infosec world moves at a glacial pace toward gender equity. It appears that's not the case in the cyber criminal underground, according to Trend Micro, which recently published a study in which it claims at least 30 percent – if not more – of cyber criminal forum users are women.

Play ransomware, also known as PlayCrypt, first came to light in June 2022. TrendMicro has noted similarities with the Hive and Nokoyawa ransomware groups, suggesting "a high probability of affiliation between these ransomware families."

According to Feike Hacquebord, a senior threat researcher at Trend Micro, some of his peers’ reluctance to discuss attribution comes from the confusion between technical attribution, which consists in identifying sets of threat activity and analyzing patterns, and legal or political attribution, which links these sets to nation-states – and can sometimes lead to the prosecution of individuals.

According to a survey conducted by Trend Micro Incorporated, 86% of global healthcare organizations’ operations have suffered operational outages as a direct ransomware attack on their organization.

Trend Micro is acquiring Anlyz, a provider of security operations center (SOC) technology. This latest Trend Micro acquisition will enable enterprises and MSSPs to improve operational efficiencies, cost effectiveness and security outcomes.

Here is where some of the leading technology CEOs are placing their bets in 2023 and how they are relying on partners to help them tackle emerging opportunities.

"This is not interpreting the Rosetta Stone," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI) told The Register. "It is a first step towards something more."

Trend Micro recently unveiled Trend Micro One, a unified cybersecurity platform aimed at making it easier for partners and customers to view and assess their attack surfaces and risk postures.

Implementing the NIST standard will take time, as many IoT vendors are still catching up to cybersecurity best practices, with devices often lacking strong authentication capabilities, no easy way to distribute and install patches, and poor visibility into activity, including weak or nonexistent logging, Trend Micro's Malik says.

According to Trend Micro, which has been tracking the malicious activity, the threat actors use a set of heavily obfuscated loaders that exploits an old Intel driver flaw to reduce the token integrity of Microsoft Defender and bypass protections.

Many companies have come and gone in the worlds of technology and cybersecurity over the past three and a half decades, but Trend Micro continues to achieve success and stay focused on its mission.

Researchers from Trend Micro who have been tracking the trend reported a 75% increase in ransomware attacks that targeted Linux systems in the first half of 2022 compared with the prior year.

A federal cybersecurity vendor is spinning up a division dedicated to 5G networks, technology that “threat actors are watching and are looking to exploit,” according to Kevin Simzer, Trend Micro’s chief operating officer.

Describing the activity in a Thursday advisory, Trend Micro researchers Mohamed Fahmy, Sherif Magdy and Mahmoud Zohdy have attributed it to the advanced persistent threat (APT) group the company refers to as APT34.

In a Black Hat USA 2022 session, Dustin Childs and Brian Gorenc, both researchers with Trend Micro's Zero Day Initiative (ZDI), pointed to multiple issues like the lack of information around a bug's exploitability, its pervasiveness, and how accessible it might be to attack as reasons why CVSS scores alone are not enough.

Organizations should take note of the risk, especially since the barrier to exploitation for the bugs — aka, the access complexity — is low, says Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI), which reported the vulnerabilities.

Discovered in June 2022 by researchers at cybersecurity company Trend Micro, the malware appears to target mainly English and Russian-speaking users.

In a demonstration, researchers from Trend Micro used a dev container image maintained by Microsoft and wrote a configuration that opened a simple HTTP server using the Python runtime which is included by default and forwarded port 8000 publicly.

Maxwell Leadership Thought Leader Don Yaeger sits down with Trend Micro COO Kevin Simzer to discuss what pro hockey can teach leaders about building pipelines of talent in their organizations.

Two reports from Guardio Labs and Trend Micro explain that these malicious websites are promoted to a broader audience via Google Ad campaigns.

Trend Micro once again takes the top prize with their outstanding report entitled FUTURE / TENSE: TREND MICROSECURITY PREDICTIONS FOR 2023.

According to Trend Micro, Royal is the rebranded version of Zeon ransomware, which emerged earlier this year and which was associated in August with Conti Team One, one of the groups involved in the distribution of the Conti ransomware.

Google has announced Trend Micro will be joining their App Defense Alliance (ADA) to help improve their ability to identify malicious apps before they are published to the Google Play store.

This new tactic was discovered by Trend Micro researchers who observed Raspberry Robin in recent attacks against telecommunication service providers and government systems.

Researchers at Trend Micro have been tracking Raspberry Robin since September and are warning the worm is notable for its 10 layers of obfuscation and its ability to deploy a fake payload to throw off detection efforts.

Lynette Owens, vice president of global consumer education at the cybersecurity firm Trend Micro, said legal action can help bring about change but doesn’t entirely ensure user safety.

In the report, published on 15 December and titled The Near and Far Future of Ransomware Business Models, Trend Micro highlighted 10 potential evolutions of ransomware groups’ TTPs.

"The threat actors not only claimed that they were able to breach the servers of these companies but also threatened to publish their files," wrote Trend Micro researchers, who recently discovered the new malicious campaign.

Cybersecurity services company Trend Micro reiterates the need for organizations to further strengthen their security posture amid rapid digitalization across industries.

Trend Micro security researchers discovered the threat last month. Like earlier, similar versions of the miner that also target Linux operating systems, the code kills competing malware and resources that affect cryptocurrency mining performance.

Researchers at Trend Micro looked at the extent to which robots can be compromised. They found the machines they studied running on outdated software, vulnerable OSes and libraries, weak authentication systems, and default, changeable credentials.

The bi-annual Pwn2Own elite hacking event held in Toronto has come to an end after four days in which 63 zero-day vulnerabilities were successfully exploited. Some 26 hacking teams and individual hackers took part in the event, operated by Trend Micro's Zero-Day Initiative (ZDI).

In addition to joining the Trend Micro Vision One ecosystem partner program, the company has completed the technology integration of its cybersecurity risk validation and exposure management solution with the Trend Micro Vision One XDR platform.

The Pwn2Own hacking event is operated by Trend Micro's Zero-Day Initiative (ZDI), launched in 2005, and sees some of the best hacking teams come together to exploit various devices using previously unknown 'zero-day' vulnerabilities.

AWS Marketplace Partners of the Year recognizes our top partners with significant AWS Marketplace transactions.

Trend Micro has unveiled a new protection deployment model that delivers great value to both security and development teams. Trend Micro identifies threats in minutes and delivers security findings with no performance impact and without removing data from the customer environment.

Trend Micro, a $2 billion security powerhouse that has won AWS Marketplace Global Partner of the Year award, posted 150 percent growth on AWS Marketplace with its partners in 2022 and expects to see another 100 percent-plus growth in 2023, said Trend Micro COO Kevin Simzer.

A wide-ranging international operation by law enforcement agencies in 30 countries aiming to prosecute online fraudsters has resulted in nearly a thousand arrests and a net of $130 million in seized virtual assets.

“In refactoring the Trend Micro Cloud One Workload Security product, the vFunction platform and their expertise enabled us to deliver value to our customers and deploy on AWS four times faster than doing it alone,” says Martin Lavigne, R&D lead, Trend Micro.

Trend Micro’s twice-a-year Cyber Risk Index report shows that respondents in the Asia-Pacific are the most likely to say they think they are somewhat or very likely to be successfully attacked at 89%, followed by respondents in North America (86%), Europe (85%) and Latin/South America (82%).

According to Trend Micro researchers, the threat group targeted mostly organizations in Australia, Japan, Taiwan, Myanmar, and the Philippines.

"The bank customers targeted include account subscribers of seven banks, including some of the most well-known banks located in the country and potentially affecting millions of customers," Trend Micro said in a report published this week.

According to a new Trend Micro report, Earth Longzhi has similar TTP (techniques, tactics, and procedures) as 'Earth Baku,' both considered subgroups of the state-backed hacking group tracked as APT41.

Picus Security has expanded its partnership with Trend Micro to enable Trend Micro Vision One (TMVO) XDR customers to continuously validate their threat detection and response capabilities.
On this week's Industrial Talk we're talking to Jon Clay, VP of Threat Intelligence with Trend Micro about “5 ‘D's' of Cyber Security”. Get the answers to your “Cybersecurity” questions along with Jon's unique insight on the “How” on this Industrial Talk interview!

The cybersecurity space has recently seen rapid growth due to the massive increase in digitalisation, expanding the attack surface. Many organisations have struggled to keep up with the demand for skilled cybersecurity talent.

Using existing codebases also saves time, and making such projects modular allows the tool to be customized for the customer's — read, "attacker's" — needs, says Jon Clay, vice president of threat intelligence at Trend Micro.

The researchers demonstrated that an attacker could cause damage or disruption, they can hijack a machine, or steal valuable intellectual property. Each of these scenarios could have a significant financial impact on an organization.

Greg Young, VP of cybersecurity at Trend Micro, agreed; he added that because IoT and home smart devices are exceptionally vulnerable, “a clear and consumer-focused label is a great idea.”

Trend Micro has formed a committee composed of six executives currently working in the U.S. government as the cybersecurity company targets a 15 percent footprint growth in the federal market.

Trend Micro study last year found storage-related configuration errors to be among the most common cloud security issues that lead to data breaches.

However, according to a global research study conducted by Trend Micro, which included the perspectives of over 5,000 IT professionals in 26 countries, only half of the respondents said they believe C-suite executives fully understand cybersecurity threats and risk management.

Bill Malik, VP of infrastructure strategies at Trend Micro, explained in a video that the metaverse will consist of “many sensors monitoring our every move, gesture and expression. More thoroughly monitored, classified than any human beings ever before.”

In the most recent incident, cybersecurity firm Trend Micro observed QAKBOT-infected systems deploying Brute Ratel, an "adversary emulation" platform used by penetration testers, but also — along with Cobalt Strike — used by cybercriminals for its sophisticated capabilities.

Mayra Rosario Fuentes, a senior threat researcher at Trend Micro, a cybersecurity company, said in an email that the big gaming companies are prime targets because they make billions of dollars and have huge pools of customers.

Trend Micro's attribution of the malware strains to the threat actor is based on the similarities in source code, domains, and naming conventions, with the analysis also uncovering functional overlaps between them.

Bill Malik, VP of infrastructure strategies at Trend Micro, pointed out that other team members will invariably have access to this platform — those who are knowledgeable about data safety and those who are not.

A recent report by Trend Micro warned of the existence of the darkverse, which is the dark web brought to the metaverse. Due to the lack of oversight from regulators and law enforcement, the darkverse is a space for underground marketplaces, criminal communications, and illegal activities.

Trend Micro says the profit made by Water Labbu is estimated to be at least $316,728 based on transaction records from nine identified victims.

Bloomberg Intelligence Senior Analyst Mandeep Singh is hosting Trend Micro's COO and President of North America, Kevin Simzer to talk about the latest trends in cybersecurity and how the company plans to fend-off CrowdStrike.

Cyber criminals are taking advantage of this easy access to resources, and using deepfakes to build on today's crime techniques, such as business email compromise (BEC), to make off with even more money, according to Trend Micro researchers.

"If left unremedied and successfully exploited, this vulnerability could be used for multiple and more malicious attacks, such as a complete domain takeover of the infrastructure and the deployment information stealers, remote access trojans (RATs), and ransomware," Trend Micro threat researcher Sunil Bharti said in a report.

After Uber announced a data breach last week, cybersecurity expert Jon Clay joins Good Day DC to share how you can protect your personal information online.

The Zero Day Initiative, a vendor-agnostic bug-bounty program begun in 2005 and since acquired by Trend Micro, recently addressed concerns of incomplete and ineffective patches by modifying its disclosure deadlines.

Security researchers from Trend Micro recently set up a honeypot with an exposed Docker REST API to try and understand how threat actors in general are exploiting vulnerabilities and misconfigurations in the widely used cloud container platform.

According to cybersecurity company Trend Micro, BlackByte is a ransomware group that has been building a name for itself since 2021. It had already gone after at least three US critical infrastructure sectors (government facilities, financial, and food and agriculture.)

A vulnerable anti-cheat driver for the Genshin Impact video game has been leveraged by a cybercrime actor to disable antivirus programs to facilitate the deployment of ransomware, according to findings from Trend Micro.

Location tracking is important to not just Kochava, but lots of agencies that collect data and then offer it to advertisers and vendors who want to provide a better user experience or feed information that might be of more interest to the user, says Jon Clay, vice president of Threat Intelligence at Trend Micro.

“The deep web is the portion of the Internet that for some reason is not indexed and therefore cannot be searched by search engines like Google,” said Jon Clay, VP of threat intelligence at globally distributed cybersecurity company Trend Micro. “The dark web is a part of the deep web and typically relies on darknets or networks where connections are made between trusted peers.”

Global cybersecurity provider Trend Micro predicts that Linux servers and embedded systems will be an increasing target for ransomware groups in the years to come.
Dustin Childs, senior communications manager for TrendMicro’s Zero Day Initiative, said on a video call that update fatigue compounds this problem. “It seems that they happen so much that it’s difficult for consumers to tell when it’s a regular update and when it’s an increased threat,” Childs said.

Trend Micro’s Zero Day Initiative (ZDI) has announced the targets and prizes for its next Pwn2Own hacking competition, as well as the introduction of a new category that aims to simulate a real world home office environment.

"Agenda can reboot systems in safe mode, attempts to stop many server-specific processes and services, and has multiple modes to run," Trend Micro researchers said in an analysis last week.

David Sancho of Trend Micro Europe discusses the pros and cons of Metaverse investment and which threats pose the biggest challenges.

Clop has been an active ransomware group over the past several years. According to a report earlier this year by Trend Micro, the malware evolved from a variant of the CryptoMix ransomware family and was first tagged with the Cl0p name in 2019.