| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
As it has done many times over the past year with unwanted Android applications on its Play store, Google has removed 89 browser extensions from its official Chrome web store after a security vendor identified them as being malicious. Google has also disabled the rogue extensions from running on the devices of over 420,000 Chrome users whose browsers were infected with the malware. In a blog Feb.
The Olympics have always been a geopolitical microcosm: beyond the athletic match-ups, they provide a vehicle for diplomacy and propaganda, and even, occasionally, a proxy for war. It stands to reason, then, that in 2018 they've also become a nexus of hacker skullduggery. The Olympics unfolding next week in Pyeongchang may already be the most thoroughly hacked in the games' history—with potentially more surprises to come.

Vehicle hacking already has a 15-year pedigree. Though there are at least 36 million vehicles on the road today already connected to the internet, manufacturers appear to have learned little from the biggest security crises of the internet era. Cybersecurity is, yet again, a bolted-on afterthought rather than an integral part of the engineering of an interconnected vehicle.

Trend Micro calls the legacy threat 'Throwhack'; after the more benign 'Throwback Thursday' social media trend; but, says principal security strategist Bharat Mistry in a blog published today, "there’s nothing entertaining about this list of legacy security challenges."
The risk and insurance community consistently ranks cyberrisk as its top area of interest and concern, and it’s no wonder—these days, every year is a banner year for cybersecurity. The more that stays the same, the more things change.

North Korea is one of the least wired nations on Earth. It has two internet connections to the outside world, one that crosses the Yalu River into China, and the other plugs into Russia’s Far East.

Google’s DoubleClick ad network has come under attack by cryptocurrency miners who infiltrated Google ads to tap into the CPU power of those who view these ads on YouTube. Operating like a malware attack, the hacked ads were detected when some users got alerts from antivirus software programs and/or experienced slowdowns in their internet activity.

Cybercriminals have learned that many businesses will pay if a ransomware attack cripples their day-to-day operations. Ransomware drove the spike in digital extortion in 2017 and remains cybercriminals' weapon of choice, according to a new Trend Micro study "Digital Extortion: A Forward-Looking View."
Cyber-criminals will find new ways to blackmail and extort organizations and individuals in 2018, supercharging ransomware, launching online smear campaigns and firing out targeted attacks aimed at key facilities, according to Trend Micro.

After the Equifax breach, identity-theft horror stories have been easy to come by. One solution, according to many experts, is freezing your credit — something hardly anyone has done. "The good news is you know all of your own history, and this breach is so well-known and far-reaching that if you are a victim, it should be easier than usual to fight," Mark Nunnikhoven, the head of cloud research for the cybersecurity firm Trend Micro, told CNN.

Alleged Russian hackers claimed to have leaked a series of documents and emails stolen from the International Luge Federation (FIL) just two weeks ahead of the 2018 Winter Olympics. Going by the name "Fancy Bears' Hack Team", the group is believed to be linked to the notorious Fancy Bear hacking group that experts have tied to Russia's military intelligence group GRU.
A new report has warned that traditional lines between hacktivists and cyber-criminals are blurring and could disappear altogether in some cases, fuelling more damaging ransomware and data theft attacks.
The travel and hospitality industry suffers billions of losses each year due to fraud. “With the right combination of other underground services (compromised accounts, credit cards, etc.) it is possible to cover almost every aspect of the holidays, including food and restaurants, shopping, entertainment, guided tours and more – way beyond flights and hotels,” Vladimir Kropotov, Researcher at Trend Micro, told Help Net Security.

A group believed to be linked to Russian hackers on Wednesday claims to have released documents stolen from the International Luge Federation, the latest sign of hacking efforts targeting the 2018 Winter Games.

Cybersecurity should be top of mind for attendees of the World Economic Forum’s annual meeting in Davos, according to the Global Risks Report 2018.

Trend Micro examined website defacement reports from 1998 to 2016 with machine learning technology to identify some long-term trends. Among the most common types of internet attacks is web defacement, where an attacker changes a victim's website to post a message. How are web defacements conducted and are there common trends? Those are some of the questions that a new study released on Jan. 22 by Trend Micro examines.

File inclusion vulnerabilities, SQL injections, and known vulnerabilities are the most common flaws leveraged by hacktivists who launch Web defacement campaigns. Trend Micro researchers dug into 18 years' worth of data to produce "A Deep Dive into Defacement: How Geopolitical Events Trigger Web Attacks." This report is the analysis of more than 13 million Web defacement reports against websites on multiple continents.

Two devastating malware affecting Android devices surfaced this week, raising serious concerns about the security of Google’s mobile operating system. On Tuesday, Kaspersky Labs exposed “Skygofree,” a spyware bundle capable of performing 48 different remote functions and affecting users in Italy.
Business email compromise (BEC) attacks are projected to exceed $9 billion in 2018. To put that number in context, it has been less than a year since the FBI reported BEC attacks had become a $5.3 billion industry. BEC has grown among threat actors due to "its relative simplicity," according to a new Trend Micro report "Tracking Trends in Business Email Compromise (BEC) Schemes."

Network traffic dictates success. No business in the digital era can survive without it—it’s the lifeblood of modern commerce and communication. However, network traffic is also a double-edged sword. Malicious traffic can disrupt or shut down your enterprise’s web activities, interrupt your sales, damage your reputation, and even shutter your business for good through a particularly devastating attack.

The Russian hackers who stole emails from the Democratic National Committee as part of a campaign to interfere in the 2016 election have been trying to steal information from the U.S. Senate, according to a report published Friday by a computer security firm.

Russian state-linked hackers accused of targeting Democratic Party officials ahead of the 2016 US presidential election have turned their focus on the Senate, according to Trend Micro.

The same Russian government-aligned hackers who penetrated the Democratic Party have spent the past few months laying the groundwork for an espionage campaign against the U.S. Senate, a cybersecurity firm said Friday.

A hacking group heavily linked to the Russian government is attempting to steal U.S. Senate email login credentials and also appears to be preparing to disrupt the 2018 Winter Olympics in South Korea, according to new research by cybersecurity firms TrendMicro and ThreatConnect.

The US Senate was targeted last year by the same hacking group that broke into the Democratic National Committee servers during the 2016 presidential election, according to the cybersecurity firm Trend Micro.

Pawn Storm, the hacking group aligned to the Russian government that penetrated the Democratic National Committee, has mounted additional "brazen attacks" over the past eight months, including persistent targeting of the U.S. Senate internal email system, according to a cybersecurity firm that has tracked their progress.

As we enter a world that is increasingly instrumented and connected, we face a unique set of challenges to secure it. Exactly how best to do so is a much-debated subject, but I believe there is a solution to securing the Internet of Things (IoT). More of that in a moment. First, let’s get a sense of where we are today.
Ed Cabrera, chief cybersecurity officer at Trend Micro, says researchers at the company are "seeing a lot of innovation going on" in PoS malware. While the bot delivery method has been around for a while, attackers are evolving their strategies around distributing malware.
Serverless apps are not a new concept, but adoption of the model is growing among enterprises. Among those pushing greater use of serverless apps are major cloud vendors Amazon, Microsoft, and Google. Trend Micro vice president Mark Nunnikhovenexplains what you need to know about the security implications of serverless applications. He reviews the most secure designs, how to implement security, and what IT Ops need to understand about the trend.
Perhaps you've been hearing strange sounds in your home—ghostly creaks and moans, random Rick Astley tunes, Alexa commands issued in someone else's voice. If so, you haven't necessarily lost your mind. Instead, if you own one of a few models of internet-connected speaker and you've been careless with your network settings, you might be one of thousands of people whose Sonos or Bose devices have been left wide open to audio hijacking by hackers around the world.

Researchers at Trend Micro have found that certain models of Sonos and Bose speakers have vulnerabilities that leave them open to hijacking, as reported by Wired. The accessible speakers are being exploited by hackers that are using them to play spooky sounds, Alexa commands, and... Rick Astley tracks.

Researchers at Trend Micro have discovered a potential hack opening key speakers from Sonos and Bose to remote access. As first reported by Wired, the Sonos Play:1, Sonos One, and Bose SoundTouch systems can be located and taken over through an online scan, letting hackers play music through the system.

The social network unveiled on Wednesday a security feature that lets you see a list of recent emails sent by Facebook. Successful phishing campaigns can be costly for consumers and companies. According to security firm Trend Micro, global losses from compromised business email scams, which often originate via phishing, will exceed $9 billion next year.

Researchers at Trend Micro's Zero Day Initiative also suspect one of the updates is aimed at mitigating a nearly undetectable Microsoft Office exploit that takes advantage of a 24-year-old Microsoft protocol called Dynamic Data Exchange (DDE).
“The online tools we’ve seen show how traditional felony and cybercrime can work concertedly—or even strengthen each other—towards bigger payouts for the bad guys,” TrendMicro reports.

According to research from Trend Micro, while 66 percent of companies say they would never pay a ransom as a point of principle, in practice 65 percent actually do pay the ransom when they get hit.

Researchers at Trend Micro have spotted the first known piece of malware to exploit a recently patched vulnerability affecting the Toast feature in Android.
Russian developer, Alexey Khripkov, said he'd shared his mining code with other developers, which could explain the number of apps containing code referencing his oxothuk nickname that have also been called out by anti-virus firms such as Trend Micro in recent weeks.
“There are many hurdles for businesses to overcome in establishing GDPR compliance – trying to demystify what ‘State of the Art’ means is but another challenge on the list,” said Bharat Mistry, principal security strategist for Trend Micro.

Vice President of Cloud Research at Trend Micro, Mark Nunnikhoven, has a simple guide on how to secure an Amazon S3 buckets.
Content promotion services have been in the "gray market" for a while, but fake news didn't start to gain widespread attention until the 2016 US Presidential election, explains Vladimir Kropotov, senior researcher for Trend Micro's Forward-Looking Threat Research (FTR).
The vulnerabilities were reported to the vendor by Steven Seeley of Offensive Security through Trend Micro’s Zero Day Initiative (ZDI).
The AP validated the list by running it against a sample of phishing emails obtained from people targeted and comparing it to similar rosters gathered independently by other cybersecurity companies, such as Tokyo-based Trend Micro and the Slovakian firm ESET.
The longest exploit chain in the history of the Pwn2Own competition was demonstrated at the Mobile Pwn2Own 2017 event in Tokyo, with security researchers using 11 different bugs to get code execution on a Samsung Galaxy S8.
"The phone connects to a Wi-Fi network and a malicious app is installed. Sensitive information can be exfiltrated from the targeted device," said a spokeperson from Trend Micro.
Trend Micro recently detected malicious apps in the Google Play store that use JavaScript loading and native code injection to avoid being detected.

The latest examples came on Monday with the revelation from antivirus provider Trend Micro that at least two Android apps with as many as 50,000 downloads from Google Play were recently caught putting crypto miners inside a hidden browser window.

There’s no doubt that organizations are under greater threat today from cyberspace than they’ve ever been – Trend Micro alone blocked over 38 billion threats in the first half of 2017.

From a security standpoint, smart lock technologies pose more of a physical challenge than a technology challenge, suggested William Malik, vice president for infrastructure strategies at Trend Micro.

“Based on our initial analysis, Bad Rabbit spreads to other computers in the network by dropping copies of itself in the network using its original name and executing the dropped copies using Windows Management Instrumentation (WMI) and Service Control Manager Remote Protocol. When the Service Control Manager Remote Protocol is used, it uses dictionary attacks for the credentials,” Trend Micro researchers shared.

A September 2017 survey conducted by cyber-security solutions provider Trend Micro, in conjunction with Opinium, found that most executives are not adequately prepared for GDPR, and the fallout could be significant.
“While many ransomware families like Cerber, SLocker and Locky are increasingly pinpointing their targets, they’re still distributed globally,” said Trend Micro researchers.
Trend Micro previously attributed other incidents that attacked this vulnerability, which was patched on October 16, to the BlackOasis APT group.
Research by Trend Micro found that 73% of 1000 IT decision makers were unaware of the extent of fines that could be levied for GDPR non-compliance
“Serverless is that last step on the current line of going ‘I don’t have to run any of this stuff — I can just write code that’s directly tied to my business,'” said Mark Nunnikhoven, vice president of cloud research at Trend Micro.

"How it works is technically complex," said William Malik, vice president for infrastructure strategies at Trend Micro. "The easy answer is the attacker gets the access point to rebroadcast part of the initial handshake, analyzes that information, and then the attacker can intercept the rest of the conversation," he told TechNewsWorld.

Connecting everyday devices to the Internet seems like a great idea, but users need to be mindful of the risks, warned JD Sherry, vice president of technology and solutions at Tokyo-based antivirus-software maker Trend Micro.

Analysts at Trend Micro, a cybersecurity firm, in 2014 discovered that copies of Football Manager Handheld, a smartphone game, and TuneIn Radio, an audio app, contained malicious software that mined cryptocurrencies, the proceeds of which were probably funneled to the developers.
When it comes to the Middle Eastern and North African underground, research from Trend Micro showed that the regional cybercrime marketplace has a few unique hallmarks, including a “spirit of sharing” mindset that hinges on a feeling of brotherhood and religious alliance that transcends the illicit transactions that occur.

TrendMicro researchers said the low price point reflected a unique aspect of brotherhood and comradery unlike what is seen other market places where the players only aim to make money.

Bottom Line: In addition to effective malware protection, Trend Micro Antivirus+ Security offers layered protection against ransomware, spam filtering, and a firewall booster.

The Health Information Trust Alliance (HITRUST) and Trend Micro have created a deception-based threat detection collaboration platform that deploys “honeypots” across the healthcare ecosystem.
In July, Trend Micro and VMware announced a new partnership to tackle enterprise mobile security issues. The companies plan to create new solutions which will automatically detect and tackle mobile threats on corporate networks.
The technical excellence of the Russian hacking groups, whether or not affiliated to the FSB, escapes no-one: as long ago as September 2012, Trend Micro warned in the report Peter the Great vs. Sun Tzu, “East Asian hackers are not at the same skill level of maturity as their East European counterparts.”
A Trend Micro mid-year report recently revealed that the firm blocked 82 million ransomware threats in the first six months of 2017, as well as 3000 Business Email Compromise attempts.
In its latest cyber threat report, Trend Micro’s researchers highlight the growing number of network-based attacks targeting ATMs.

Now, more than 1,200 apps available in third-party marketplaces are exploiting Dirty Cow as part of a scam that uses text-based payment services to make fraudulent charges to the phone owner, researchers from antivirus provider Trend Micro reported on Monday.
“Use of cryptocurrency miners is on the rise in the world of cybercrime,” Trend Micro Vice President of Cloud Security Mark Nunnikhoven told SC Media. “We haven't yet seen them coupled with ransomware, but that combination is one that's likely to surface.”
In most of the newly observed attacks, Locky has been distributed alongside another ransomware family calked FakeGlobe, also known as Globe Imposter, Trend Micro says.
According to Trend Micro Inc., FakeGlobe is a form of ransomware that encrypts different files to that of Locky, meaning that potentially victims could be forced to pay up for both infections.
BEC attacks generated $5.3 billion in global losses between 2013 and 2017, Trend Micro researchers reported earlier this year.
Uncovered by cyber security researchers at Trend Micro, the nature of the campaign means it's possible for victims infected by one form of ransomware to still be vulnerable to a further attack from the next one in the rotation.

These consumers could be at greater risk of identity theft because “the more data an attacker has, the harder it is to stop them,” said Mark Nunnikhoven, a vice president with Internet security company Trend Micro.

“There’s no simple fix,” says Mark Nunnikhoven, vice president of cloud-computing research at Trend Micro. “This kind of internal network was never meant to be connected the way it is now.”
A recently malware attack has been leveraging the Hangul Word Processor (HWP) word processing application and its ability to run PostScript code, Trend Micro reveals.

"Government regulation is the only way this is going to happen," William Malik, vice president of infrastructure strategies at Trend Micro said on the panel. "Automobiles didn't get safer until the government regulated them."
The first half of the year saw a continued surge in ransomware, Business Email Compromise (BEC) and other threats, with Trend Micro blocking over 38 billion during the period, it claimed in a new report.

All that information packaged together sells for upwards of $30 per identity on online black markets, according to Mark Nunnikhoven, head of cloud research for cybersecurity firm Trend Micro.
Trend Micro researchers first spotted the banking malware using network sniffing to steal data back in 2014 and recently spotted an increase in activity in August 2017 coming from new variants that all had the potential to unleash different types of payloads

The mobile edition of the Pwn2Own hacking contest is returning for its sixth year, with a prize pool of $500,000 and new targets for security researchers. Pwn2Own is operated by Trend Micro's Zero Day Initiative (ZDI) and has both desktop and mobile events.
Cloud-based online storage service Autodesk A360 Drive has been recently abused as a malware delivery platform, according to Trend Micro.

A trojan spreading fileless malware, which Trend Micro detects as “TROJ_ANDROM.SVN,” conceals itself within two malicious files on an infected USB.
The trend in medical devices connected to the internet has opened the door to hackers being able to threaten victim's lives, Ed Cabrera, chief cybersecurity officer at the threat research firm Trend Micro, tells Wired.

Despite the move toward EMV chip cards, point-of-sale (POS) malware continues to vex merchants’ payment systems, most recently with the discovery of MajikPOS malware in North America, which TrendMicro reported on in March.
Trend Micro this week said that it will offer over $500,000 in cash prizes at Zero Day Initiative’s Mobile Pwn2Own contest, set to take place Nov. 1-2, during the PacSec 2017 Conference in Tokyo, Japan.

The trojan looks very similar to the GhostClicker malware previously analyzed by Trend Micro before its authors decided to use it to launch DDoS attacks.
According to Trend Micro, the mining malware operation includes a timer that automatically triggers the malicious WMI script every three hours.

“Passenger shipping organizations and cruise lines … can be easily impacted,” said Eduardo E. Cabrera, chief cybersecurity officer at Trend Micro, a Tokyo-based cybersecurity firm.
Trend Micro's Federico Maggi and Politecnico di Milano's Andrea Continella visit the Dark Reading News Desk to discuss ShieldFS – a new tool that protects filesystems by disrupting and actually undoing the ransomware's encryption while it's in action.

Trend Micro’s Zero Day Initiative has released details about two remote code execution zero-day flaws affecting popular freemium PDF tool Foxit Reader.
A new, vendor-neutral connected car hack has been discovered that is "indefensible by modern car security technology" and could put many drivers at risk of a critical cyberattack, according to a Wednesday blog post from security firm Trend Micro. The hack was discovered by Trend Micro's Forward-looking Threat Research (FTR) team, Politecnico di Milano, and Linklayer Labs.
Attackers who successfully exploited the vulnerability could assume control over target systems and create new accounts with full user rights, install programs, and view, edit, or delete data. Researchers at TrendMicro have found malware exploiting the same flaw but using PowerPoint files for distribution, a technique not previously seen in the wild.
Users of online dating apps and the businesses they work for could end up the target of spear phishing and social engineering scams, especially when these services make one's personal information accessible to virtually anyone, Trend Micro researchers warned in a blog post on Thursday.

Researchers at Trend Micro examined three years worth of malware from OnionDog — around 200 total samples — and found evidence that the malware was likely developed and used in joint U.S./South Korean military exercises.

Trend Micro alerts users that an email campaign which appeared a couple of months ago is currently targeting Russian-speaking enterprises and delivering a new Windows-based backdoor.
Microsoft added that an unauthenticated attacker in an enterprise setting could remotely trigger the flaw through an SMB connection, which Trend Micro researchers said is "pretty close to wormable," referring to its spreadability.

The HITRUST Alliance and Trend Micro have announced a partnership to create the HITRUST Cyber Threat Management and Response Center, which will expand HITRUST’s cyber threat information sharing program for health care.

Marcus Hutchins arrest does not appear to be directly related to WannaCry, said Mark Nunnikhoven, vice president of cloud security at Trend Micro.
According to Gilbert Sison and Janus Agcaoili, two security researchers at Trend Micro, the most recent version of the Cerber ransomware can dump browser passwords and can steal files related to Bitcoin wallets.
Trend Micro researchers are keen to explain that there are malware that are fileless only while entering a user’s system (and they eventually reveal themselves when they execute their payload), and there are completely fileless malware attacks, where the entire infection chain is fileless.