| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

"Every place we move to in technology creates a seam for bad actors," said Trend Micro's chief security officer, Ed Cabrera, whose company sells IT security services and issues reports on global cyber trends.
A trio of researchers, representing a team from Politecnico di Milano and Trend Micro, presented their findings on the security of robots.

The arrest of Vinnik adds a new twist to the case against Karpeles, the former head of Mt. Gox, said Mark Nunnikhoven, vice president of cloud research at Trend Micro.

"If you look at the demands they are relatively low — they are in the ballpark of what people can afford to pay," says Bharat Mistry, a Trend Micro cybersecurity consultant. In fact, 65 percent of companies pay a ransom when they are hit by ransomware, according to Trend Micro's research.
A piece of malware spotted by Trend Micro in early July leverages the SambaCry vulnerability to target NAS devices, particularly ones used by small and medium-size businesses.
The tools tactics and procedures used by hacking group CopyKittens are explained in a new in-depth report produced in collaboration by cyber-security firms Trend Micro and ClearSky.

“The data GhostCtrl steals is extensive, compared to other Android info-stealers,” explained Trend Micro cyber security researchers.
A Samba remote code execution flaw patched in May is being exploited to compromise IoT devices running on different architectures, Trend Micro researchers warn.
The GhostCtrl RAT was discovered by Trend Micro researchers part of a wave of attacks against Israeli healthcare organizations.
Simon Edwards, European cyber security architect at Trend Micro, told us that, as defined in GDPR, organisations should be deploying ‘state of the art' security controls to protect user data. "Insurers will probably require much the same if they are to cover the risk as required," Edwards said.

Trend Micro reports that HoloLens use is not very widespread compared to PCs and other more popular devices, but this particular patch is notable for being the first reminder that such systems can represent yet another vector of attack.
Trend Micro and VMware have announced a new partnership to improve the enterprise mobile security space. Trend Micro Mobile Security for Enterprise will now be integrated into VMware's Workspace ONE and VMware AirWatch.
According to Trend Micro, the original ransomware sample found earlier this month was named King of Glory Auxiliary and was posing as a cheating tool for the game King of Glory. Once installed, however, the ransomware featured a similar appearance to WannaCry.

Trend Micro, an information security company, has reported that the health care sector is now the preferred target for cybercriminals.

Want to influence an election? All you need is about $400,000, according to cyber security consultant Trend Micro Inc.

Security firm Trend Micro is the latest corporate to jump into the startup investment world after it unveiled a $100 million corporate fund today.

“The first thing you should not do after a breach is create your response on the fly,” said Mark Nunnikhoven, Vice President of Cloud Research at cyber security solution provider Trend Micro.

Trend Micro recently unearthed Xavier, an ad library that was discovered by the company’s Reputation Service.

The AdGholas malvertising threat group conducted a new campaign in May and June 2017 using the Astrum exploit kit to infect victims with Mole ransomware – an unusual change-up for these adversaries, who historically have favored banking trojans, according to researchers from Trend Micro and Proofpoint.

To defend against ransomware, Trend Micro’s threat defense experts recommend backing up your files regularly and staying on top of your security updates.
A newly discovered ransomware family incorporates a combination of fileless attack and code-injection, Trend Micro security researchers warn.
According to Trend Micro, a Trojan dubbed Xavier, which is embedded in more than 800 applications on Android’s app store, clandestinely steals and leaks personal data.

A new report from the cybersecurity firm Trend Micro takes a closer look at the cost of running misinformation campaigns hosted by various "content marketers" that offer services in Russian, Chinese, Middle Eastern, and English.
A 77-page report released today by cyber-security firm Trend Micro explores the underground landscape of fake news, where anyone can buy influence and create artificial trends to serve personal interests.
In a blog post, ZDI noted that the CVE-2017-8464 vulnerability is similar to the approach used by the Stuxnet malware. ZDI noted that while the new Microsoft patch touches different parts of code, the exploit vector remains the same, with remote code execution occurring if a specially crafted shortcut is displayed.
Security vendor Trend Micro recently discovered a new method of delivering malware that doesn't require a mouse click to trigger.
"While features like macros, [object linking and embedding], and mouse hovers do have their good and legitimate uses, this technique is potent in the wrong hands," researchers from antivirus provider Trend Micro wrote in a blog post published Friday morning.
Researchers from Trend Micro recently discovered Persirai targeting over 1,000 IP camera models based on multiple original equipment (OEM) products.
Popular chat platforms such as Slack, Discord and Telegram can be abused by malicious actors and turned into command and control (C&C) infrastructure, according to Trend Micro.
Hackers are abusing Slack, Discord, Telegram and other third-party chat platforms by incorporating them into their malicious command-and-control infrastructure and then using their functionality to communicate data and even download malware, according to a new Trend Micro report.
A study of the Dark Web by Trend Micro shows that cybercriminals attack each other with almost the same ferocity as they reserve for their victims outside of it.

Trend Micro states that more than 90 percent of successful hacks and data breaches stem from phishing, emails crafted to lure their recipients to click a link, open a document or forward information to someone they shouldn’t. Training users how to detect and react to these threats are a critical ransomware deterrent.
“Behind most modern conveniences, there exists a SCADA system somewhere that controls them,” Trend Micro researchers pointed out in a new report that delves in the heart of vulnerabilities affecting SCADA systems’ Human Machine Interfaces (HMIs).
Trend Micro researchers are taking a stand against the published reports stating UIWIX ransomware is the new WannaCry when, in fact, the only thing it has in common with Wanacrypt0r is its threat vector.
Meanwhile, iOS 10.3.2 fixes 41 vulnerabilities including multiple fixes for WebKit, the most severe of which “could allow the processing of maliciously crafted web content to allow arbitrary code execution”, ZDI said.
Researchers at IT security company Trend Micro say warnings that the Uiwix ransomware could be a more dangerous version of WannaCry might be inaccurate, according to a new report.

Cybersecurity experts say this piece of malware had an especially malicious quality. Mark Nunnikhoven is vice president of cloud research at the security software company Trend Micro.
The Zero Day Initiative (ZDI), which organizes Pwn2Own, published six advisories on Wednesday for each of the security holes fixed by Microsoft.
The malware, called Persirai, has been found infecting Chinese-made wireless cameras since last month, security firm Trend Micro said on Tuesday. The malware does so by exploiting flaws in the cameras that a security researcher reported back in March.

"The industrial robot – it's not ready for the world it's living in," said Mark Nunnikhoven, vice president of cloud research at Trend Micro. "The reality is these things are being connected in more and more places. There are a lot of attacks that could happen in that environment."

The software that runs internet-connected industrial robots is outdated and vulnerable to hacking, according to a new report from cybersecurity firm Trend Micro and the Politecnico de Milano. The researchers found tens of thousands of industrial devices were susceptible to hackers, which included industrial robots.
Trend Micro's Mark Nunnikhoven said the attack was "extremely clever" because it's difficult to filter email with a legitimate Google URL. The URL can't be blocked because it's a legitimate domain, owned and controlled by Google. Defending against this attack relies entirely on the user," he noted.
"As far as the robot thinks, it's still drawing a straight line," Mark Nunnikhoven, vice president of cloud research at Trend Micro, told Forbes. "It's a remote code exploit to change the configuration file, we're not changing the instructions, we’re changing what the robot believes to be true about its environment.
First emerging on the Russian underground marketplace in March 2016, Cerber has been issued in a number of versions with each iteration evolving its structure, techniques and functions. It is now being cited by Trend Micro as the "most prolific family of ransomware in the threat landscape."
Discovered by Trend Micro, FalseGuide's main focus is on infecting and adding as many devices to a centrally-managed botnet. The purpose of this botnet is to show unrequested ads to victims, via popups or other means.

"Despite the best efforts of law enforcement to stem the exponential growth of cybercrime, the truth is that it's an uphill struggle," writes Ed Cabrera, Trend Micro's chief cybersecurity officer. "Transnational cybercriminals these days are well resourced, determined and agile."

A hacking group linked by cybersecurity experts to Russia's military intelligence apparatus has begun taking aim at France's centrist presidential candidate, Emmanuel Macron, the cybersecurity firm Trend Micro said in a report published on Tuesday.

The group, dubbed "Pawn Storm" by security firm Trend Micro, used email phishing tricks and attempted to install malware at think tanks tied to Chancellor Angela Merkel's Christian Democratic Union (CDU) party and coalition partner, the Social Democratic Party (SPD), Feike Hacquebord said.

“There are several things which suggest that the group behind the Macron hacking was also responsible for the DNC breach, for example. We found similarities in the IP addresses and malware used in the attacks,” said Rik Ferguson, vice president of Trend Micro’s security research program.

Machine learning serves as a heavy lifter in security software protecting businesses’ data from cyber criminals’ exfiltration efforts. Since the first deluge of spam created the demand for email security, Trend Micro has been researching and implementing strategies for combining computer intelligence with the wisdom of human experience. Its XGen™ Smart Protection Suite focuses on endpoint, email, and web security, all of which are regularly exploited by criminals.

The security community has gained itself the title of being the team of "no": No clicking on links, no browsing particular websites, no installing certain software. Trend Micro Global VP of cloud security Mark Nunnikhoven told ZDNet this needs to change, because if security is everybody's responsibility, organisations need to act that way.
Looking specifically at the Adobe Flash advisory, Brian Gorenc, senior manager of vulnerability research at Trend Micro, noted that five of the seven fixed issues came through Trend Micro's Zero Day Initiative (ZDI) program and two of the bugs (CVE-2017-3062 and CVE-2017-3063) were disclosed through Pwn2Own, which is operated by Trend Micro's ZDI.

Cybersecurity solutions company Trend Micro Incorporated has announced it is enhancing protection of small business endpoints by adding its newest capabilities of XGen security to Trend Micro Worry-Free Services.

An anonymous hacker working with Trend Micro's Zero Day Initiative (ZDI) disclosed the bugs, which affects Apple TV and watchOS too.
“A remote attacker could exploit this vulnerability in the IIS WebDAV Component with a crafted request using PROPFIND method. Successful exploitation could result in denial of service condition or arbitrary code execution in the context of the user running the application,” said Virendra Bisht, a vulnerability researcher at Trend Micro.

“Other threat actors are now in the stages of creating malicious code based on the original proof-of-concept (PoC) code,” researchers from Trend Micro said in a blog post Wednesday.

I learned this past Saturday that my good friend and Trend Micro CTO, Raimund Genes, passed away suddenly last week. Raimund was only 54.
However, it is unlikely that the group's efforts to stir public pressure against Apple will be effective, noted Mark Nunnikhoven, vice president for cloud research at Trend Micro, in an online post.

Last week, the 10th annual Pwn2own hacking challenge was hosted by Trend Micro's Zero Day Initiative (ZDI), with multiple groups of researchers taking aim at web browsers, operating systems and virtualization technology.
One of the premier hacking contests is Pwn2Own, where security teams get together and see if they can break into the leading operating systems and web browsers.
At this year's installment of Pwn2Own, a hacking competition that's been taking place since 2007, the duo of Samuel Groß and Niklas Baumstark did exactly that.

The Pwn2Own contest runs every year during the CanSecWest security conference in Vancouver, British Columbia. It's organized and sponsored by the Zero Day Initiative (ZDI), an exploit acquisition program operated by Trend Micro after its acquisition of TippingPoint.
Named after its command and control (C&C) panel, the malware “needs only another component from the server to conduct its RAM scraping routine,” Trend Micro says.
Cybercriminals out of West Africa pilfered an average of $2.7 million from businesses and $422,000 on average from individuals during 2013-2015, according to new INTERPOL and Trend Micro data, a rate that is on the rise.
Trend Micro is reporting a new threat to Linux-based Internet of Things (IoT) devices that is specifically able to exploit a specific vulnerability in surveillance cameras made by AVTech.
Cybercrime-related complaints in West Africa soared from 940 in 2013 to 2,182 in 2015, says “Cybercrime in West Africa,” a report jointly done by the global police network known as Interpol and Trend Micro, a security software company with headquarters in Tokyo. Only 30 percent of the cybercrimes reported to police in the region lead to arrests, it said.
West Africa is poised to become a cyber crime hot spot, according to new research out this morning from security firm Trend Micro and Interpol, the international police organization.
This year, TrendMicro sees a 25-percent growth in the number of new ransomware families available for use in breaches.
This year, TrendMicro sees a 25-percent growth in the number of new ransomware families available for use in breaches. Reports of the encroachment of ransomware on government, law enforcement, critical infrastructure, and health and safety are already climbing.

In 2016, security firm Trend Micro counted 247 new ransomware families, compared to just 29 in 2015.
In February 2017, Trend Micro revealed that the Crysis ransomware was being distributed via RDP attacks too.

More than 36,000 healthcare-related devices in the US alone are easily discoverable on Shodan, a sort of search engine for connected devices, according to a recent Trend Micro survey.
2016 was truly the year of online extortion. Cyber threats reached an all-time high, with ransomware and Business Email Compromise (BEC) scams gaining increased popularity among cybercriminals looking to extort enterprises. A 752 percent increase in new ransomware families ultimately resulted in $1 billion in losses for enterprises worldwide, according to Trend Micro.
Trend Micro blocked nearly 82 billion threats in 2016, with ransomware and Business Emil Compromise (BEC) in particular causing havoc for organizations worldwide, according to a new report.
Speaking at RSA Conference 2017 Wendy Moore, director of user protection at Trend Micro, presented a session on going beyond next gen to deliver security with maximum impact.
On Wednesday, researchers Numaan Huq and Stephen Hilt from Trend Micro revealed at the RSA conference in San Francisco, California, that many IoT devices are lacking basic security and are visible using services such as the Shodan search engine, which is used to discover devices which are accessible from the Internet.
(#7) Trend Micro was pleased with its recommended rating by NSS Labs, saying Trend Micro OfficeScan Agent v12.0.1851 received “one of the highest malware protection scores with no false positives.” The vendor noted that scored as “100% effective against exploits and evasion,” but doesn’t mention the exact score handed out by NSS Labs. The graph notes that Trend Micro had “no observed evasions.”
One such ransomware gang is the group behind the Crysis ransomware, who's been recently using RDP brute-force attacks to infect large organizations. In the past six months, this group's activity has more than doubled, according to security firm Trend Micro.

Evil hackers with monomaniacal intentions of a globe-disrupting nature have long dominated pop culture sensibilities. But when it comes to for-profit hacking, it's important to remember that cybercrime has been, and remains, predominantly a business-driven concern, says Eduardo Cabrera, chief cybersecurity officer of endpoint security vendor Trend Micro.
According to Trend Micro, most of the attacks are targeting the healthcare sector in the United States, though other industries were hit hard as well.

A recent Trend Micro report revealed that attacks on business emails and business processes will continue to grow in 2017 because they’re cheap and simple forms of corporate extortion.

“Apps may request administrative privileges to your data, and those privileges could be used by the app later on, or by some malware, to steal your personal information,” says Ed Cabrera, chief cybersecurity officer at TrendMicro, a digital security company.
For example, the price of a customizable Crypto Locker executable file is around $50 according to research done by Trend Micro, on top of that, ransomware operators tend to take a 10% cut of the profits made from targets.
Jon Clay, director of Global Threat Communications at Trend Micro, says corporate IT "needs to have visibility into what is occurring within the office—and that can be challenging in the main network, let alone a remote location."
Cabrera, who served 20 years in the United States Secret Service, with a stint as its CISO, and racked up experience leading information security, cyber investigative, and protective programs in support of the Secret Service integrated missions before moving to the private sector, says local skimming operations that physically compromise credit card and financial accounts have been overtaken and outdone by international cybercrimes where attacks on endpoints, networks and cloud
Trend Micro said it validated Shames' identity thanks to his inadvertently using his real name in a series of Hack Forums posts in January 2012 while logged into the Mephobia account.
Trend Micro noted a sharp increase in the number of unique Android malware samples targeted at mobile users—from 10.7 million samples in 2015 to more than 19.2 million in December 2016.
Over the last decade, the Zero Day Initiative's (ZDI) annual Pwn2Own competition has emerged to become one of the premiere events on the information security calendar and the 2017 edition does not look to be any different.

Trend Micro last week announced the availability of the latest Trend Micro TippingPoint NX Series Next-Generation Intrusion Prevention Systems (NGIPS).
Trend Micro has also analyzed the attacks and determined that the threat actor sent out the spear-phishing emails from compromised accounts, particularly ones belonging to attorneys and associates at various law firms.
"The $1 billion number isn't at all unreasonable and might even be low," confirmed Mark Nunnikhoven, vice president of cloud research at Trend Micro.
Ransomware is set to have another bumper year in 2017, although growth is likely to level out, according to Trend Micro.
The HiveSpot goes one step further than both the Orbi and the Velop however, by offering Ai Protection at no extra cost. This is a built-in network security suite powered by Trend Micro that detects and blocks online security threats. Basically the entire home network powered by the HiveSpot system is protected in real-time against online malware and cyber threats.
“Enterprises that have edge-of-network devices could find theirs utilized by hacktivists and other threat actors in launching DDoS attacks,” said Trend Micro Inc. Director of Global Threat Communications Jon Clay. “The Mirai botnet code has been made available publicly so anyone could utilize this to recruit new IoT devices that are not secured properly. Enterprises which have IoT devices should be sure to update any account credentials used by the devices as well as ensuring the devices are
A newly discovered family of malware targeting ATMs (automated teller machines) has been designed with the sole purpose of emptying cash from the safes of the self-serve machines, Trend Micro security researchers warn.

As per Trend Micro’s report, ransomware has almost doubled in the first half of 2016 with a 172% growth in comparison to the past year.

Since their founding in 1988, Trend Micro has innovated software solutions to protect the privacy of consumers and businesses on the web.
On Thursday, Europol announced that security vendors Bitdefender, Check Point, Emsisoft, and Trend Micro have joined the project as associated partners.
Security software company Trend Micro says cyber-attacks on enterprise networks and the internet of things will only grow in volume and sophistication in 2017.
Ed Cabrera, chief cybersecurity officer at Trend Micro, said things have become markedly worse since that report. He said at the end of September, the increase was 400 percent. “In 2015, there had been 29 families observed, and as of September, we have observed and blocked 145 families,” he said.