| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

The OCSF represents a great direction for the security industry. We are coming together to fight our shared competitor: cybercriminals. Success for OCSF is threefold: growth for the project, growth for Trend Micro and, most importantly, growth for business users.

At Black Hat USA 2022, Brian Gorenc, Trend Micro senior director of threat research, and Dustin Childs, ZDI senior communications manager, discussed the current state of bug bounty programs.

China-linked cyberespionage group Iron Tiger was observed using the compromised servers of a chat application for the delivery of malware to Windows and macOS systems, Trend Micro reports.

Trend Micro examines nine different categories of threats against the metaverse and inside the metaverse, including cyber-physical crime, financial fraud, legal implications and more.

One thing that makes cybersecurity more difficult is that the array of tools organizations rely on often speak their own language—referring to the same things with unique or proprietary terminology. The Open Cybersecurity Schema Framework (OCSF) project—unveiled today at Black Hat 2022—plans to change that.

Trend Micro’s concern is about increased illegal and criminal activity in Metaverse. Its report points towards the developing security models in the “darkverse.”

Activist investor ValueAct Capital Partners said on Tuesday it has built an 8.7% stake in cybersecurity software provider Trend Micro Inc, driving shares of the Tokyo-listed firm more than 9% higher. The investment comes as Trend Micro, which has a market value of over $8 billion and revenue of $1.9 billion, shifts into a cloud-based cybersecurity platform.

Threat actors have modified SolidBit ransomware to focus their sights on gamers and social media users. Researchers at cybersecurity firm Trend Micro discovered the SolidBit variant disguised as a League of Legends account checker tool.

These 17 dropper apps, collectively dubbed DawDropper by Trend Micro, masqueraded as productivity and utility apps such as document scanners, QR code readers, VPN services, and call recorders, among others. All these apps in question have been removed from the app marketplace.

"There is no question that, whether it is law enforcement pressure or the defenders getting better, that we are seeing that these groups are forced to evolve — they have to get better at what they are doing," says Jon Clay, vice president of threat intelligence for Trend Micro.

Trend Micro has unveiled additions to its Cloud One platform designed to make intrusion prevention and protecting containerized workloads easier and less costly for users of the Amazon Web Services public cloud.

Cybercriminals are targeting victims in a number of different ways with fake cryptocurrency wallet apps, said Trend Micro researchers in January.

In April, the company unveiled Trend Micro One, a new unified cybersecurity platform it says will make it easier and more efficient for channel partners and customers to view and assess their attack surfaces and risk postures.

Dustin Childs of Trend Micro’s Zero Day Initiative said it “allows an attacker to execute code as SYSTEM, provided they can execute other code on the target.”
A leader in cloud and enterprise cybersecurity, Trend Micro has around 7,000 employees across 65 countries, with its cyber security platform protecting 500,000+ organisations and 250+ million individuals across clouds, networks, devices, and endpoints.

The findings come after Trend Micro first reported cryptominer deployment as a result of poor security practices.

Security researchers at Trend Micro have identified a new ransomware family that is being delivered as a fake Google Software Update application.

This means that organizations will buy more products from fewer vendors, and big cybersecurity tech kahunas like Check Point, Cisco, Crowdstrike, Fortinet, Palo Alto Networks, Trellix, and Trend Micro understand this.

In a recent attack, researchers with Trend Micro found evidence that pointed to the ransomware group exploiting the PrintNightmare vulnerability (CVE-2021-34527), a remote code execution flaw in the Windows print spooler service that Microsoft issued patches for in July 2021.

This is not the first time that security researchers have sounded a warning on hackers-for-hire. Trend Micro, for instance, reported on the Void Balaur threat in November 2021.

"The attack surface is larger than it has ever been, so it's a fertile ground for finding and abusing vulnerabilities," says Dustin Childs, communications manager for Trend Micro's Zero Day Initiative, the largest vendor-agnostic bug bounty program.

According(Opens in a new window) to Trend Micro, the gang also previously recruited company insiders to help them hack a target’s network. “LockBit has been detected all over the globe, with the US seeing most of the attack attempts from June 2021 to January 20, 2022, followed by India and Brazil,” the security firm wrote in a February report.

The number of security threats coming through email is growing once again, according to new research from Trend Micro.
According to research by cybersecurity firm Trend Micro, the “rise of deepfakes raises concern: It inevitably moves from creating fake celebrity pornographic videos to manipulating company employees and procedures.”

Trend Micro‘s chief technology strategy officer David Chow expects security vendor collaboration and consolidation to play a significant role in national security, he told SDxCentral in an interview at the RSA Conference.

The cybercriminals behind DeadBolt primarily target NAS devices. QNAP systems are the main targets, though in February the group attacked NAS devices from Asustor, a subsidiary of systems maker Asus, said analysts with cybersecurity firm Trend Micro.

Connected cars provide plenty to entice threat actors, with more than 400 million predicted to be on the roads globally by 2025. Trend Micro announced VicOne, dedicated security for the electric vehicles and connected cars of today and tomorrow.

The FBI in April warned that BlackCat affiliates use previously compromised user credentials to gain initial access to a victim network, but didn't identify Exchange flaws as a point of entry. However, researchers at Trend Micro at the time reported BlackCat affiliates had used the Exchange CVE-2021-31207 flaw initial entry and to install a web shell on the server for remote access.

Survey results from Trend Micro indicate that, when it comes to organizations understanding their attack surfaces, most don't.

More processes could be terminated by the updated Cuba ransomware variant prior to file encryption, such as MySQL, MS Exchange, and Outlook, while additional directories and file types have been added to the ransomware's exclusion list, a Trend Micro report revealed.

These factors make DeadBolt different from other NAS ransomware families and could be more problematic for its victims, according to an analysis from Trend Micro this week.

Surveying more than 6,000 IT and business decision-makers in 29 countries for its latest report, Trend Micro said 73% of respondents are worried about the growing attack surface.
To share these insights and to hear how partner executives are responding, Kevin Rhone, ESG Channel Acceleration Practice Director, spoke with partner executives Craig Halliwell (Red Canary), Jean-David Lehmann (Palo Alto Networks) and Louise McEvoy (Trend Micro).

In January 2020, Trend Micro detailed three malicious apps that were disguised as photography and file manager tools that leveraged a security flaw in Android (CVE-2019-2215) to gain root privileges as well as abuse accessibility service permissions to harvest sensitive information.

Trend Micro researcher Magno Logan looked at how cybercriminals could abuse these clusters and exposed kubelet ports.

Trend Micro, a cybersecurity solutions provider, details Black Basta's modus operandi in a recent report.

Dubbed “Cheers” or “Cheerscrypt”, the ransomware first hijacks an ESXi server, then launches an encryptor that locates virtual machines and then terminates them with an esxcli command, according to the researchers at Trend Micro.

The 37-year-old's detention is part of a year-long, counter-BEC initiative code-named Operation Delilah that involved international law enforcement, and started with intelligence from cybersecurity companies Group-IB, Palo Alto Networks Unit 42, and Trend Micro.

The Japan-headquartered cybersecurity company also shifts one of its vice presidents over to lead the federal business.

According to Trend Micro’s Zero Day Initiative (ZDI), which organizes the event, rewards were paid out for 25 unique zero-day vulnerabilities that were used to target Tesla Model 3, Windows 11, Ubuntu, Microsoft Teams, Safari, Firefox and Oracle VirtualBox.

The hacker in question was the supremely talented Manfred Paul who pulled off the lightning-fast double exploit using two critical vulnerabilities at the PWN2OWN Vancouver, 2022, event that came to an end on Friday, May 20.

Dustin Childs, the communications manager of Trend Micro's Zero Day Initiative, which hosts the contest, told Insider he had expected to see "bug collisions," or two researchers finding the same flaw, but was surprised to find everything "was a unique exploit."

In its 15th anniversary year, the elite hacking event created by the Trend Micro Zero Day Initiative (ZDI) pays big bounties to those who reveal zero-days impacting the most prominent of vendors.

TrendMicro discovered that AvosLocker ransomware actors recently used a PowerShell script to disable antivirus software and evade detection.

Hive ransomware, first observed in June 2021, has already “made its mark as one of the most prolific and aggressive ransomware families today,” according to Trend Micro Inc.

"Similar to Joker, another piece of mobile malware, Facestealer changes its code frequently, thus spawning many variants," Trend Micro analysts Cifer Fang, Ford Quin, and Zhengyu Dong said in a new report. "Since its discovery, the spyware has continuously beleaguered Google Play."

Eva Chen is the Co-founder and CEO of Trend Micro, one of the world’s largest security firms. In 2012, she made Forbe’s list of ‘Asia’s 50 Power Businesswomen’.

ESET data from 2020 suggests WannaCry accounted for as much as 40.5% of all ransomware detections globally and, in 2021, WannaCry was the only ransomware to make Trend Micro’s list of top ten most-used malware strains of the year – coming fourth.

While the software giant classified the attack complexity as "high," it also noted that the vuln is under active attack. So "someone must have figured out how to make that happen," wrote Trend Micro's Dustin Childs on the Zero Day Initiative blog.

"The framework is distributed via a pay-per-install (PPI) service and contains multiple parts, including a loader, a dropper, a protection driver, and a full-featured remote access trojan (RAT) that implements its own network communication protocol," Trend Micro said in a report published Thursday.

AvosLocker ransomware was discovered by Trend Micro researchers to have a new variant that could facilitate antivirus system deactivation and evade detection.

As per Trend Micro’s recent international Cyber Risk Index (CRI) findings for the second quarter of 2021, 76% of those surveyed anticipate a breach within the next 12 months.

Telemetry data gathered by Trend Micro shows that the food and beverage sector was the most hit industry between July 1, 2021 and February 28, 2022, followed by technology, finance, telecom, and media verticals.

Reports from outside Trend Micro have provided valuable insights into the alleged cyberattacks.

Touting its new Trend Micro One as a major step toward consolidating security products on a single platform, the company said it will offer a full suite of its security products to provide, among other things, “continuous lifecycle of risk and threat assessment with attack surface discovery, cyber risk analysis, and threat mitigation and response."

"It is a stressful time for all of the participants, making sure that what they've worked on over the last few months is still working," said Dustin Childs with Trend Micro's Zero Day Initiative, the organization that runs the contest.

“I, the creator of RU_Ransom, created this malware to harm Russia,” the code’s ransom note says, according to an analysis by security firm Trend Micro.

Additional vendors providing AI-based endpoint protection include Broadcom, CrowdStrike, SentinelOne, McAfee, Sophos, Trend Micro, VMWare Carbon Black, Cybereason, etc.

The technology can automatically discover and secure internal and external facing assets with attack surface discovery, cyber risk analysis, threat mitigation and response.

Trend Micro Monday relaunched its flagship software-as-a-service (SaaS) offering as a unified security platform, Trend Micro One, making it the latest vendor to emphasize the complexity of competing consoles in the security operations center.

The contest, organized by Trend Micro’s Zero Day Initiative (ZDI), saw 11 contestants demonstrating their exploits in the OPC UA Server, Control Server, Human Machine Interface, and Data Gateway categories.

At Pwn2Own, the stakes are a little bit lower, but the systems are the same as what you’ll find in the real world. This week in Miami, the targets were all industrial control systems that run critical facilities.

The newly published Cyber Risk Index, a study by Trend Micro and the Ponemon Institute, shows that more than three-quarters of global organizations expect to suffer a cyberattack in the next 12 months — 25% of which say an attack is "very likely."

“We observed active exploitation of Spring4Shell wherein malicious actors were able to weaponize and execute the Mirai botnet malware on vulnerable servers, specifically in the Singapore region,” said Deep Patel, Nitesh Surana and Ashish Verma, security researchers with Trend Micro, in a Friday analysis.

"We observed active exploitation of Spring4Shell wherein malicious actors were able to weaponize and execute the Mirai botnet malware on vulnerable servers, specifically in the Singapore region," said Trend Micro's researchers.

CrowdStrike, Microsoft and Trend Micro sit atop the Forrester Wave report for endpoint detection and response providers as vendors grapple with business data increasingly moving to the cloud.

A report by Trend Micro describing, “A floating battleground navigating the landscape of cloud-based cryptocurrency mining”, claims there’s an “hour-by-hour” battle between multiple groups over which gets to use compromised cloud.

Jon Clay, VP of threat intelligence at the cybersecurity company Trend Micro, recently shared with Enterprise Storage Forum his insights on the storage market and some storage security practices companies can implement.

Security researchers suspect that the Cyclops Blink malware could be used to “build infrastructure to further attacks on high-value targets.”

As autocomplete code writing tools become more and more popular, cybersecurity experts discuss what these tools lack to ensure their security.

Threat experts explain how “cyber patriots” have become involved in the Ukraine/Russia conflict, and how haphazard hacktivism could lead to unintended consequences.

Cybersecurity vendors share their response and ongoing support to citizens and employees of Ukraine as the situation evolves.

This article on TeamTNT’s activity surrounding striking Linux systems and Kubernetes builds on recent cryptojacking campaigns.

This article analyzes LiveAction’s new offering that combines behavior analysis and machine learning to expose malware in encrypted network traffic.

An analysis of SMS phone-verified account (PVA) services has led to the discovery of a rogue platform built atop a botnet involving thousands of infected Android phones.

Some senior execs have their heads in the sand when it comes to cybersecurity - and it might take falling victim to a cyberattack for that issue to be fixed.

Samba has patched a vulnerability that could enable remote, unauthenticated attackers to execute arbitrary code as root on impacted installations.

Researchers are calling a new strain of ransomware that targeted a U.S. bank last week "White Rabbit."

LockBit is a hugely popular form of ransomware for cyber criminals targeting Windows - and now cybersecurity researchers have identified a Linux-ESXi variant of it in the wild.

Security teams trying to defend their organizations need to adapt quickly to new challenges. Yesterday’s buzzwords and best practices have become today’s myths.

Cybersecurity researchers identify White Rabbit, which is a new ransomware that appears to have links to FIN8, a hacking group that previously focused on finances.

A Remote Access Trojan, otherwise known as a RAT, is a type of spyware that allows a cybercriminal to take control of the computer or other device it's installed on.

Praise be & pass the recipe for the software soup: There’s too much scrambling to untangle vulnerabilities and dependencies, say a security experts roundtable.

"Revolutionary" is basically a marketing term these days that's applied to everything from new detergents to cut-rate fashion styles.

Cybercriminals are increasingly using malicious QR codes to trick consumers.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added fifteen common vulnerabilities and exposures (CVEs) to its Known Exploited Vulnerabilities Catalog, a veritable who’s-who of bugs that are being actively exploited.

A security vulnerability in VMware’s Cloud Foundation, ESXi, Fusion and Workstation platforms could pave the way for hypervisor takeover in virtual environments – and a patch is still pending for some users.

Three weeks after the Cybersecurity & Infrastructure Security Agency (CISA) issued an Emergency Directive ordering federal agencies to address their systems that are vulnerable to the Log4j flaw.

Casual computer users have probably never heard of this logging software, but it's used across the entire internet.

The latest Roomba cleans like a champ and is the first robot vacuum I've used that doesn't get tangled up in cables and cords

This week, host Connor Craven interviews Lori Smith, director of product marketing at Trend Micro, on extended detection and response (XDR).

Software in connected devices has little oversight. As more objects come online, that problem will snowball.

Researchers on Monday reported that they found threat actors who attacked Alibaba’s cloud-based Linux servers, disabling features in Alibaba’s Elastic Computing Service (ECS) instances to conduct illicit mining on the Monero cryptocurrency.

The Trend Micro study reveals pressing need for new way to discuss business risk.

Cybersecurity researchers at Trend Micro lift the lid on Void Balaur, a financially motivated cyber-crime group that has targeted politicians, journalists, human rights activists, medical professionals and others since 2015.

Just weeks after hackers managed to breach iOS 15 security measures and hack an Apple iPhone 13 Pro, now it's the turn of Samsung's current flagship smartphone, the Galaxy S21, to feel the hacking heat.

Build applications in the cloud like cattle, not pets, says Aaron Ansari, VP of cloud security at Trend Micro. He also strongly endorses ant relay races, but more on that later.

During the first day of Pwn2Own Austin 2021, contestants won $362,500 after exploiting previously unknown security flaws to hack printers, routers, NAS devices, and speakers from Canon, HP, Western Digital, Cisco, Sonos, TP-Link, and NETGEAR.

Ransomware attacks on the banking industry increased 1,300% during first half of 2021.
Lack of public disclosures for cloud bugs can allow vendors to sit on vulnerability reports and can prevent researchers from getting acknowledgement and payouts.