| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
Automation platforms are increasingly being used to chain multiple IoT devices together to create user-friendly smart applications – but that’s also creating unpredictable attack surfaces that can be hard to manage. A Trend Micro report released at RSA Conference 2019 warns that these types of complex IoT environments, which can involve a mix of local standalone servers, cloud-based servers and virtual assistant-based servers, are opening new risks for smart buildings.
Researchers at Trend Micro say they've found new malware that uses Slack channels, GitHub, and the file.io file-sharing site to steal data from Windows PCs.

It seems that some homes may be too smart for their own good. On Monday, March 5, researchers at the San Francisco RSA conference presented to an assembled crowd of journalists and cybersecurity experts an unexpected approach for hacking into the device-enabled homes of the modern day George and Lydia Hadley.
Orbiting hunks of metal make it possible for billions of earthlings to benefit from marvels of the digital age, from GPS signals and weather monitoring systems to the communication protocols for credit card authorizations and other complex transactions.

Smart home devices aren’t just for the home. Businesses are inviting more and more internet-connected devices into their offices and buildings as well. While the technology may simplify some tasks, security experts warn that the Internet of Things is also opening companies up to more security threats.

Today, endpoint security solution provider Trend Micro released their 2018 Trend Micro Cloud App Security Report. Trend Micro drew from the data collected by their Cloud App Security solution to formulate their findings; among these findings, Trend Micro discovered enterprises faced over 8 million high-risk email threats in 2018 alone—a significant increase over 2017.

A blue verified badge on Instagram is among the most sought after status symbols in the digital world, a must-have for many so-called influencers. But now a group of hackers are taking advantages of our obsession with appraisal online.
A group of Turkish-speaking hackers is hijacking popular Instagram profiles, including those belonging to actors and singers, and, in some cases, promising to turn back control to the victims in exchange for a ransom or nude photos and videos.
Traditional attacks, such as phishing and credential stuffing, continue to dominate the threat landscape for most industries, while well-known malware, such as WannaCry, remain a threat for behind-the-curve companies, according to two annual cyberthreat reports released today.

We hear about them all the time, another company getting its data breached, another credit card scanner hacked, but do you really know what a data breach is exactly and what it means if it happens to you? Here’s a quick rundown of data breaches and what you should know.
As long as there are ATMs, hackers will be there to drain them of money. And while ATM-targeted “jackpotting” malware—which forces machines to spit out cash—has been on the rise for several years, but a recent variant on the scheme takes that concept literally, turning the machine’s interface into something like a slot machine. One that pays out every time.
OT, IoT and systems targeted by cryptominers - those are among the main network security concerns of Greg Young, VP of cybersecurity at Trend Micro. Which technology trends should security leaders follow to improve network security? Young shares his insight.
The Outlaw group is conducting an active campaign which is targeting Linux systems in cryptocurrency mining attacks. On Tuesday, the JASK Special Ops research team disclosed additional details (.PDF) of the attack wave which appears to focus on seizing infrastructure resources to support illicit Monero mining activities.

Researchers at Trend Micro recently published their look inside online underground marketplaces in the Middle East and North Africa, where criminals are buying and selling malware, laundering money and event booking their next discount vacation.
Super Bowl LIII will draw the attention of millions of people around the world – and cybercriminals hoping to exploit attendees and fans before and during the big game.

Google has banned dozens of Android apps downloaded millions of times from the official Play Store after researchers discovered they were being used to display phishing and scam ads or perform other malicious acts.

Experts walk us through all the threats lurking in our high tech homes...and tell us some simple – but not always used – ways we can better protect ourselves.

The biggest technology trends ahead are expected to have an impact on security, including the adoption of cloud computing, plus advances in machine learning and artificial intelligence. Greg Young, from Trend Micro explains more.
Microsoft Exchange 2013 and newer versions are vulnerable to a privilege escalation attack that gives anyone with a mailbox a way to gain domain administrator rights at potentially 90% of organizations running Active Directory and Exchange, according to a security researcher.

It’s time to take stock of your private information. Monday, Jan. 28 is Data Privacy Day, which marks the 1981 signing of Europe’s Convention 108, the first legally binding international treaty involving privacy and data protection. But, more important, it’s a reminder that protecting your personal data is vital.
A global team of researchers recently took industrial system hacking to a whole new — and visual — level by exploiting flaws they discovered in radio frequency (RF) controllers that move cranes and other large machinery at construction sites and in factories.

In the future, industrial robots may create jobs, boost productivity and spur higher wages. But one thing seems more certain for now: They’re vulnerable to hackers.
Hundreds of e-commerce websites have been hit with a card-skimming attack that compromised an advertising plugin, according to research from Trend Micro and RiskIQ.
Federico Maggi will never forget the first time he saw a crane being hacked. Last March, he was on a strange kind of road trip. Travelling the Lombardi region of Italy with his colleague Marco Balduzzi in a red Volkswagen Polo, the pair hoped to convince construction site managers, who they’d never met or spoken with before, to let them have a crack at taking control of cranes with their hacking tools.

Most car manufacturers would dread the idea of someone hacking one of their vehicles, but Tesla has decided to go the other way and open up its software to a hacking contest called Pwn2Own in Vancouver.

Another day, another batch of bad apps in Google Play. Researchers at security firm Trend Micro have discovered dozens of apps, including popular utilities and games, to serve a ton of deceptively displayed ads — including full-screen ads, hidden ads and ads running in the background to squeeze as much money out of unsuspecting Android users.
Google has removed 85 Android apps from the official Play Store that security researchers from Trend Micro deemed to contain a common strain of adware.
Over 45,000 Chinese websites have been under a barrage of attacks from miscreants looking to gain access to web servers, ZDNet has learned.

When it is about memes, people usually download them right away on their devices to share further. Posting memes on Facebook and Twitter has become something of a trend today. But, did you ever wonder you could also download malware with these memes? Researchers have discovered some malicious Twitter memes posted on an account that Twitter has since suspended.

Preying on an individuals’ desire to personalize their mobile phones, scammers infused at least 15 Android wallpaper apps to redirect phony ad click revenue, reported Trend Micro in a blog post.
The Google Play Store removed the mobile phone apps, which were downloaded more than 222,200 times while being available over a period of several months. Victims were spotted in Italy, Taiwan, the United States, Germany and Indonesia appeared to be the most infected, according to Trend
Security researchers said they’ve found a new kind of malware that takes its instructions from code hidden in memes posted to Twitter.
You have probably seen dank memes that really speak to you, but research shows that memes can also be made to speak to malware that has infected a computer. A piece of malware analyzed in a report published Friday by Trend Micro responds to executable commands embedded in images posted on Twitter.
New research has highlighted an old problem: The Internet of Things isn't exactly secure. Hardly news, you might say, but the researchers from Trend Micro discovered that two popular IoT protocols are insecure by design. So insecure, indeed, that they are putting both 'Industry 4.0' smart factory implementations and smart cities at risk. In fact, these are the design flaws that could quite literally turn the lights out.

Cybersecurity firm Trend Micro today published a report on the state of IoT security. The company found that two of the leading machine-to-machine (M2M) protocols have inherent design issues, and are frequently deployed in an insecure manner.

NEWS ANALYSIS: AWS is on a $27 billion run rate growing 46 percent a year, CEO Andy Jassy said. Its customer and partner rolls continue to swell, and it's even taking its first steps into what until now has been a missing link: open source.
Security researchers competing in the Pwn2Own competition in Tokyo this week earned a collective $325,000 for demonstrating new exploits on devices made by Samsung, Xiaomi, and Apple.
Pwn2Own, a series of contests run by the Zero Day Initiative, brings security researchers to compete to expose the most vulnerabilities in popular software and devices. The competition in Tokyo on Tuesday and Wednesday focused on mobile devices.

As the popularity of cryptocurrency rises, so does the amount of cryptominer Tojans that are being created and distributed to unsuspecting victims. One problem for cryptominers, though, is that the offending process is easily detectable due to their heavy CPU utilization.

Trend Micro and NTT DoCoMo collaborated on an IoT network security service. It is built on the Trend Micro virtual network function suite on DoCoMo’s 5G open cloud.
An unknown threat actor has been targeting organizations with botnet malware that communicates with its command-and-control server via the Internet Relay Chat application layer protocol. Nicknamed Outlaw, the hacking group developed the botnet as a Perl language-based variant of Shellbot, according to a Nov. 1 blog post from Trend Micro, whose researchers uncovered the threat.

AI and machine learning won't magically solve all of the IT world's security problems, despite what some of the hype might suggest. Used sparingly, though, these technologies can make a security team's life much easier when operating at scale.
Trend Micro Apex One™ redefines endpoint security with the capabilities delivered as a single agent, with consistency across SaaS and on-premises deployments. This offering enhances automated detection and response and provides actionable insights that maximize security for customers and offers growth opportunities for the channel.
Security researchers warn of both new and re-emerging threats that can cause serious harm.

Last week, Trend Micro came to Boston for its annual Trend Insights industry analyst event. The company provided an overview of its business, products, and strategy.
Trend Micro announced its Apex One™ endpoint security offering on Oct. 15, providing organizations with a new set of capabilities. Apex One is the rebranded name for Trend Micro's endpoint security technology, which integrates malware prevention technology with endpoint detection and response (EDR) capabilities. The endpoint security is enabled via a single end-user agent and can be integrated with Trend Micro's managed detection and response (MDR) service.

Trend Micro rolled out its unified threat management product line in North America. Included are Trend Micro Cloud Edge, Worry-Free Services, Cloud Scanner, and more.

Cybersecurity insurance is getting a lot of attention from investors right now as more and more companies try to manage their increasing risks.
Trend Micro revealed that organizations around the world are exposing themselves to unnecessary cyber risk by failing to give IT security teams a voice when planning IoT project deployments in enterprise environments.
The Scoville Scale is a measurement chart used to rate the heat of peppers or other spicy foods. It can also can have a useful application for measuring cybersecurity threats. Cyber-threats are also red hot as the human attack surface is projected to reach over 6 billion people by 2022.
Talking on the changing role of the CISO and the security department internally at the Cloudsec conference in London, Leah MacMillan, SVP global marketing at Trend Micro, asked the panel if the role of the CISO was changing?

Cybersecurity reports are seldom comforting, and this year's Midyear Security Roundup reportthat Japan-based security company Trend Micro released last week is no exception. Somewhat surprising is that although microprocessor vulnerabilities like Meltdown and Spectre top the news, ransomware and cryptomining malware delivered the old fashioned way, by hacking, phishing, or drive-by attack, are perhaps the most active threats.

Nearly a year after Russian government hackers meddled in the 2016 U.S. election, researchers at cybersecurity firm Trend Micro zeroed in on a new sign of trouble: a group of suspect websites.
The incidence of cryptocurrency mining malware continues to skyrocket as the bad guys refocus their efforts away from ransomware in favor of the easy money that cryptocurrency offers them. The latest evidence of the trend came by way of a new report, released earlier this week, that examined attack data for the first half of 2018.

Independent cybersecurity researchers found nearly double the number of vulnerabilities in SCADA systems in the first six months of 2018 as they did in H1 of 2017, according to a new report by Japanese multinational Trend Micro, amid rising concerns about infrastructure security.
Cryptojacking attacks, fileless malware, and malware with small file sizes all increased in the first half of 2018 as cyber thugs tried to use more covert tactics.

Malicious crypto-mining attacks jumped 956 percent from the first half of 2017 to the first half of 2018, IT security firm Trend Micro reported Wednesday.

The 2018 Midyear Security Roundup compiles, analyzes, and synthesizes the global enterprise threat data from the first six months of 2018. The goal of the report is to glean as accurate a picture as possible of the current global digital threat landscape. In the expert opinion of Trend Micro, the threat landscape emphasizes stealth and subtlety rather than more blatant ransomware attacks. T

Cybercriminals are moving away from attention-seeking ransomware attacks in favour of more covert methods to steal money and sensitive data according to a new report from Trend Micro.
Trend Micro's 2018 midyear security report finds that ransomware attack volume is growing slowly, while cryptojacking continues to escalate.
THEY CALL IT Herb2. It’s a dapper robot, wearing a bowtie even while it sits at home in its lab at the University of Washington. Its head is a camera, which it cranes up and down, taking in the view of a dimly lit corner where two computer monitors sit.

Business demand dictates a frenetic pace for delivering new and better technology. To perfect the process, more organizations are taking a DevOps approach—melding software development and software operations simultaneously. The result is greater productivity, standardization, innovation and the ability to scale up.
Trend Micro has reconfirmed its commitment to Internet of Things (IoT) security with a new program designed to leverage its Zero Day Initiative (ZDI) to minimize vulnerabilities as smart products are developed.
Intentionally or not, Microsoft has emerged as a kind of internet cop by devoting considerable resources to thwarting Russian hackers.

With high-profile cyberattacks in the news so often, the market for cybersecurity products continues to climb. According to IDC, worldwide spending on security-related hardware, software, and services is forecast to reach $91.4 billion in 2018, an increase of 10.2 percent over the amount spent in 2017.

Trend Micro Research, along with researchers from IssueMakersLab, recently discovered a supply chain attack targeting South Korean organizations, named Operation Red Signature. The attack was targeted to specific IP ranges of certain organizations within South Korea.

Researchers from Trend Micro have exposed two criminal cyber campaigns targeting South Korean organizations – one, a supply chain attack delivering a remote access tool under the guise of a software update, and two, a ransomware attack leveraging malicious .egg files.

Companies look to colleges, high schools and even nascent hackers to create a new pipeline of future security experts.
The message was clear at this year's Black Hat conference: The "culture," for lack of a better term, of security must change, or society faces living in a world of perpetual cyber-risk.

IT leaders could be dangerously underestimating the security risks posed by IoT, according to new research from Trend Micro. The security vendor polled 1150 IT and security decision-makers in the UK, Germany, the US, Japan and France.

Companies are still leaving basic security flaws and points of entry wide open for hackers to exploit.

With more than 3,500 researchers worldwide, 3,500 vulnerabilities discovered and publicly disclosed, and more than $15m paid to researchers to date, Trend Micro’s Zero Day Initiative (ZDI) is one of the world’s largest supplier-agnostic bug bounty programme.

Developers have long been chasing the dream of being able to write an application once and having it run anywhere. Despite valiant attempts over the years, we’ve never quite succeeded.
After a 20-year career in the U.S Secret Service, Ed Cabrera joined Trend Micro in 2015, where he is now the Chief Cybersecurity Officer, working with organizations to help improve cybersecurity. Among the multiple challenges faced by enterprises around the world are ransomware and Business Email Compromise (BEC) attacks, which represent a more immediate form of risk than other forms of attack that are not quickly monetized by attackers.
Trend Micro announced on June 19 a Managed Detection and Response (MDR) service to assist security operations teams. MDR provides managed cyber-security services that benefit from artificial intelligence (AI) capabilities to help detect threats. The new service is not intended to replace an organization's existing security team, but rather is being positioned as a complementary approach.

As the number of organizations that are embracing containers continues to increase, so does the number of incumbent cybersecurity vendors extending the reach of their platforms. Trend Micro, as part of that trend, has begun offering a Deep Security Smart Check module to continuously scan container images, which complements an existing Deep Security module for securing container runtimes.

Confusion persists around DevOps because the term "has been used and abused so much it's lost all meaning," said Mark Nunnikhoven, VP of cloud research for Trend Micro, speaking Tuesday at the Gartner Security and Risk Management Summit in National Harbor, Maryland. DevOps tools have emerged and organizations have marketed "DevOps people." But at its core DevOps is a philosophy designed to balance two formerly disparate parts of an organization: development and operations.
It's been three years since researchers first discovered automated tank gauges (ATGs) at some 5,000 US gas stations exposed on the public Internet without password protection, and a recent scan found 5,635 locations were vulnerable to the same issue.

One of the men behind the Scan4You, a counter-antivirus tool used by cybercriminals to determine whether their malware would be flagged during routine security scans, has been convicted on three counts in federal court.

Everyone has that thing. That trigger that makes a person twitch. Whether that's standing on the left side of an escalator, walking too slow on the sidewalk or coworkers neglecting to take home last Tuesday's Chipotle guacamole (yes, it has indeed gone bad).
Cybercriminals looking to purchase malware are frequent flyers on dark web forums. Often, nefarious actors are in search of the attack that will deliver the greatest gains, which is why it might come as a surprise to learn that many criminals are rolling the dice on crypto-jacking connected devices.
Data breaches stemming from misconfigured cloud-based storage servers are utterly preventable, and it's up to the security community to educate organizations about tools that are readily available to scan for such mistakes, according to Mark Nunnikhoven, Trend Micro's VP of cloud research.
What matters most, right now, to today's information security community, overwhelmed by an increasing number of not only attacks, but also regulations, quantity of solutions and inability to separate snake oil from reality?
An evolved variant of Necurs botnet malware is using .url files -- known as internet shortcuts -- as part of its infection chain in order to bypass conventional detection methods.

As U.S. lawmakers decide how best to respond to Facebook’s personal data scandal, regulators in Canada are being encouraged to do more to protect the privacy of users in this country.
A security researcher discovered the recent Windows Meltdown patches may fix the Intel flaws but also introduced a more severe vulnerability in some versions of Windows.

A hardware wallet for virtual currencies with millions of users has been compromised by a 15-year-old security researcher.

When Facebook co-founder Mark Zuckerberg posted a status update Wednesday on the still-unfolding Cambridge Analytica scandal, he called it an “issue,” a “mistake” and a “breach of trust.” But he didn’t say it was a data breach.
The relative quiet in ransomware attacks so far in 2018 may be a bit misleading, as ransomware developers have been busy and in some cases moving their craft forward with techniques used in enterprise software development.
Following the tragic death of a woman in Arizona who was struck by a self-driving Uber in autonomous mode, questions have arisen over the other risks of connected cars. In particular, hacking.
Consumers are more worried now about their protected health information (PHI) being compromised, thanks to high-profile breaches like Anthem and Allscripts. The recent RSA Data Privacy Report surveyed 7,500 consumers in Europe and the US. It showed that 59 percent of the respondents were concerned about their medical data being compromised. Thirty-nine percent were worried that a hacker would tamper with their medical information.

A number of recent security industry reports from companies like Trend Micro have found that mobile malware is becoming more widespread and it is increasing in sophistication.

The SecureWorld team just finished reading the latest Trend Micro report, and it's the type of threat landscape information, in plain English, you'll want to share with your leadership team.

Just about all security experts agree that using a VPN, or virtual private network, when accessing the internet via computer or phone is a good idea. In particular, a VPN is one of the easiest ways to avoid getting hacked while you’re taking advantage of the free WiFi at an airport or library.

Criminal “products” from the underworld marketplace are part of a sophisticated and highly profitable global industry.

Time is nearly up. The day of reckoning when it comes to data protection is nearly upon us, with May 25th 2018 marked in bold in every business calendar or diary. The General Data Protection Regulation, or its more popular moniker GDPR, has cast an omnipresent shadow over global business for the last year, with a myriad of surveys and research repeatedly warning against non-compliance – normally with the much used adjective of ‘unprepared’.
The number of unique mobile malware samples increased sharply in 2017 compared to a year ago, according to Trend Micro.

Employing sophisticated scams involving social engineering, email phishing, and the harvesting of employee passwords, attackers have pilfered millions of dollars from some of the world largest corporations—all while bypassing traditional hacking safeguards by simply avoiding the use malware.
An Android trojan that started out as an open-source project has been updated to allow hackers to gain access to virtually all data on infected devices. The new variant of AndroRAT is disguised as an app called 'TrashCleaner' and researchers at Trend Micro say it's distributed via a malicious URL -- indicating that this threat comes from third-party download sites or phishing attacks.

Cyber experts say at least one group of hackers tied to Russia, known as Fancy Bear, has targeted international sporting organizations. According to cyber security firm Trend Micro, the same hacking outfit that penetrated the Democratic National Committee’s computer systems also hacked into the European Ice Hockey Federation, the International Ski Federation, the International Biathlon Union, the International Bobsleigh and Skeleton Federation and the International Luge Federation.

While no cybercriminal worth his salt would turn down a chance to get his hands on your credit card information, there’s an even bigger prize: your Social Security number, which cybersecurity experts say is now the single most valuable piece of information in terms of being able to steal your identity.
IoT stands for the Internet of Things. In the simplest terms possible, it means any device with an on/off switch can be connected to the Internet – from your home heating to vending machines to CCTV cameras. It can also apply in industrial contexts – for instance the drill of an oil rig. Technology research firm Gartner predicts that there will be over 26 billion connected devices by 2020 – “a pervasive digital presence…throughout business process and operations”.