| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Many other transportation networks are likely be vulnerable the same sort of attack, since the ransomware used attacks Microsoft Windows-based computers with outdated software, said Ed Cabrera, chief cybersecurity officer at TrendMicro.

“I haven’t seen another ransomware attack against another transportation entity,” said Ed Cabrera, chief cybersecurity officer with antivirus vendor Trend Micro Inc.
Investigators say a small corps of elite hacking groups is carrying out the attacks. “The skill level to create the malware for the actual network intrusions is a step up,” from more common ATM crimes, said Robert McArdle, a security researcher with antivirus vendorTrend Micro Inc.

EDR, meanwhile, is now part of the product lines of traditional AV companies such as McAfee, Symantec, and Trend Micro. "EDR is rapidly becoming a feature" in most new endpoint security products, Gartner's Firstbrook says.
According to Trend Micro researchers, since the Adobe fix and the announcement of the Windows zero-day patch, the Pawn Storm attackers ramped up their spear-phishing campaigns against various governments and embassies around the world, seeking to maximize the utility of the soon-to-be patched Windows zero-day.

The Flash Player security updates fix nine critical vulnerabilities that could be exploited remotely to execute malicious code on computers. All of them were privately reported by researchers through Trend Micro's Zero Day Initiative, an exploit acquisition program.

Jon Clay, director of global threat communications for Trend Micro, an internet security firm, said Apple’s tight control over the iPhone had historically kept malicious apps out of its App Store. Fake apps appeared more often on Google’s Android platform or on third-party app stores, he said.

Detecting Mobile-Targeting Ransomware (Thursday, 10:00): Only 10 ransomware families currently target mobile devices, say researchers Federico Maggi of Trend Micro and Stefano Zanero of Politecnico di Milano. They promise to detail new techniques for how related attack code can be spotted.
Stephen Hilt, Trend Micro's lead researcher on the project, said they don’t have a concrete percentage on the number of encrypted messages. "However, there were very few pages that were actually encrypted," he said.
Security giant Trend Micro has launched XGen, a new approach to endpoint security blending multiple layers of threat protection, in a bid to head off what it claims are the over-hyped claims of rivals with narrower feature sets.

Called XGen endpoint security and available immediately, the new architecture reflects a security landscape in which increasingly sophisticated exploits arrive far too fast and often for any one form of protection to handle, according to Kevin Simzer (pictured), Trend Micro’s executive vice president of sales and marketing.
Ransomware often distributed via spam emails, especially now that the notorious Angler Exploit Kit (EK) is gone, and Locky appears responsible for a surge of certain delivery methods, researchers say. According to Trend Micro, 71% of known ransomware families arrive via email.
If an individual jumps through the various hoops necessary to access this part of the Internet, they can buy anything from weaponry to counterfeit documents and data dumps -- and stealing a person's identity is cheap, with Trend Micro estimating that each data record is worth less than a dollar in underground marketplaces.

The cloud is rapidly opening new IT delivery options for a wide range of organizations. “It’s an amplifier,” says Mark Nunnikhoven, vice president of cloud research for security solutions provider Trend Micro. “This is really exciting, as it lets organizations focus on their core business.”

Analyses, by both Morphus Labs and Trend Micro, show that the ransomware arrives at its destination either as an executable, downloaded from malicious sites, or as a file, dropped by another malware.

Google announced the Project Zero Prize a week after security vendor Trend Micro spelled out Mobile Pwn2Own 2016, a more traditional hacking contest that will run Oct. 26 and Oct. 27 in Tokyo.
"You need the right mediums for the right people. You can't have a one-size-fits-all training programme; if you're training your developers, you're going to need different content to what you're using to train your sales people, finance or HR people," says Rik Ferguson, VP of security research at Trend Micro, who stresses the importance of making cybersecurity training interesting, something many companies aren't doing.
Christopher Budd, a global threat communications manager at Trend Micro notes that the latest research focused on adware, but scam apps downloaded from unaffiliated app stores put users at risk of being exposed to all sorts of malware. “The biggest thing is the importance of going only to the official app stores,” Budd says. “The mobile malware problem that we’ve seen is almost exclusively a problem with third-party locations.”

The Dropbox attack also is reminiscent of the LinkedIn breach of 2012, when an attack that originally was thought to have impacted 6.5 million users eventually was found to have exposed 117 million users, noted Christopher Budd, global threat communications manager at Trend Micro.
The figures on reactions to ransomware from Trend Micro come following a surge in cyberattacks using the file encrypting malicious software over the last year which has resulted in it becoming the largest threat to cybersecurity, as demonstrated by some cases of Locky infections against high-profile targets.
Trend Micro researchers have discovered a stealthy new rootkit family named after Pokemon character Umbreon which could allow hackers to remotely control targeted devices.
"I think we can safely say that it's a unanimous and universal concern that electoral systems are appropriately protected," said Christopher Budd, global threat communication manager at Trend Micro.
The IoT ransomware is possible because many IoT devices are based on the Android operating system. In July 2016, Trend Micro reported that an FLocker variant can now affect smart TVs.
The majority of ransomware discovered by Trend Micro came from spam emails. That accounted for 58 per cent of the ransomware discovered by the company. Another 40 per cent came from URLs hosting ransomware files.
Key features: Trend Micro Deep Security secures physical, virtual, cloud hybrid environments. It protects enterprises from ransomware, breaches and disruptions, simplifies security operations and accelerates regulatory compliance.
Jon Clay, a cybersecurity and threat expert for Trend Micro, says that utilizing multiple exploits in an attack is common for most platforms. But since relatively few vulnerabilities are found in iOS to begin with (compared to platforms like Windows) it would be unique to see an attack sequencing multiple exploits.
In fact, for the past four years—between 2012 and 2015, inclusive—hacking and malware have edged out missing devices as the top threat for financial institutions, according to anti-malware firm Trend Micro and research conducted by eWEEK using Privacy Rights Clearinghouse data.

Trend Micro offered insights on the first half of 2016.

It might seem like an odd question as you can probably point out the physical building or buildings that house your data center(s). But does that physical installation line up with the logic concept of the “data center” held by your business?
Whoever is distributing - or helping to distribute - Locky recently began using Windows Script Files to download the ransomware onto victims' PCs, researchers at security firm Trend Micro say in a blog post. The new variant, first seen in the wild on July 15, is being sold on underground Brazilian cybercrime sites, the researchers say.

“Such a technique allows this threat to bypass security measures, including sandbox analysis, since it has no static file type. In addition, using blended scripting languages could result to the samples being encoded, making these arduous to analyze,” Trend Micro researchers said in a blog post.

A new variant of Locky ransomware using Windows Scripting Files (WSF) as a downloader, Trend Micro researchers observed.

Trend Micro reported in April that ATM malware is on the rise. Recent attacks have shown with a combination of hacking and large teams, ATM operators, banks, and account holders are collectively getting slammed with millions of dollars in losses over the course of just a few hours.

Bank card readers and ATMs are yet another vulnerability, IT security firm Trend Micro has warned.
This is the first time when the use of steganography has been observed in a malvertising attack, according to Proofpoint. The company's researchers worked with researchers from Trend Micro to deconstruct the attackers' technique and analyze it.
Trend Micro researchers spotted a new ransomware as a service (RaaS), dubbed Stampado, which may be indicative of ransomware market trends.

The scale of the ransomware problem is still unclear, although Trend Micro claims to have blocked in excess of 100 million threats for its customers around the world in just the past six months alone.

Dallas-based cybersecurity software developer Trend Micro is taking aim at the ransomware market, saying yesterday that it has launched a new, free hotline to help victims of ransomware, and also rolled out a number of free tools to help remove ransomware from computers.

“But if there’s one lesson from the survey that everyone should take and act on right away, it’s that the ransomware threat should be met with a full reevaluation of your organizations countermeasures to see if they really are matching the latest threats out there,” Trend Micro explained in a blog post.
First, Trend Micro reported last week that the so-called “Godless” mobile malware can target any Android running Android 5.1 (Lollipop) or earlier.

Mergers and acquisitions (M&A) are constantly occurring and are complex transactions, often involving entities from around the globe: from bankers, lawyers and investors facilitating the deal, to the actual business owners and stakeholders who benefit.

A similar revision of the balance between victim and kidnapper took place following the terrorist attacks of September 11, 2001, points out Christopher Budd, global threat communications manager at Trend Micro. The terrorists who hijacked multiple planes broke with the traditional hostage-for-ransom model, to say the least. Their actions inspired a no-tolerance attitude toward hijackings that took negotiation or ransom out of the picture.
The information age and impact of globalization have thrust new demands upon the United States’ national security and public safety leadership. The need for technological superiority combined with strategic planning in a rapidly changing global environment is paramount to protecting US citizens. However, it is apparent that technological advantage is no guarantee for future success on this “new battlefield.”
Security firm Trend Micro said the malware, dubbed Godless (ANDROIDOS_GODLESS.HRX), targets a set of rooting exploits in its pockets and uses multiple exploits that can target virtually any Android device running Android 5.1 (Lollipop) or earlier.
“Even without counting the ransom itself, organizations affected by ransomware are going to have to deal with the costs of containment, downtime, and recovery,” explains Mark Nunnikhoven, vice president of cloud research at Trend Micro Inc., a global IT security provider with U.S. headquarters in Irving, Texas. “Prevention is best in order to avoid getting to that point where the tough discussion around paying needs to occur.”
As ransomware grows in popularity, TrendMicro researchers said aside from the social engineeringtactics and commercial grade encryption deployed on victims, cyber crooks also use less sophisticated malware routines including deleting shadow copies, using startup modification, using propagation tactics anti-detection mechanisms and other methods that wreak greater havoc when combined, according to a June 16 blog post.

Ransomware is type of malware that criminals use to lock users out of their own files. Once the user is locked out, a ransom note is displayed providing instructions on how to pay the criminal in order to – potentially – regain access to your data.

"There are no major differences between a FLocker variant that can infect a mobile device and one that affects smart TVs," Trend Micro researcher Echo Duan wrote in a blog post.
"If the Twitter password is reused elsewhere, Twitter two-factor authentication isn't going to help you on those other accounts," Trend Micro Global Threat Communications Manager Christopher Budd told TechNewsWorld.

"If the Twitter password is reused elsewhere, Twitter two-factor authentication isn't going to help you on those other accounts," Trend Micro Global Threat Communications Manager Christopher Budd told TechNewsWorld.
Somewhat interestingly, the individual conducting the chat conversation did not appear to know the ransom amount that the victim was being asked to pay and appeared reliant on the honesty of the victim to provide that information. “That’s because they haven’t built a channel to upload data from the victim to the ‘call center,’” says Christopher Budd, global threat communications manager at Trend Micro.
“The benefit is the user doesn't get infected, so the likelihood that they won't report the issue to the website owner is higher than if malware was used to infect them,” Trend Micro Senior Global Marketing Manager Jon Clay told SCMagazine.com. “This allows their scam to run longer than normal.”

FastPOS doesn't care about this aspect, and Trend Micro says the malware sends any stolen data to the C&C server as soon as it can get its hands on it.

While analyzing the threat, researchers with security firm Trend Micro observed that it was designed to target Windows XP 64-bit computers and that it can also run on more recent versions of Windows such as Windows 7 and 8.
“Most targeted attacks take minutes or seconds for the initial compromise,” explains Ed Cabrera, VP of Cyber Security Strategy at Trend Micro. “But it takes months or years to detect them.”

Software security vendor Trend Micro is promoting a layered approach to defending against the increasing threat of ransomware and malware.
After TeslaCrypt's authors publicly released the ransomware's master decryption key last week, Trend Micro researchers spotted cyber crooks jumping to CryptXXX.
Trend Micro recommends a layered protection approach involving a combination of web/email gateway, endpoint, server and network security. The firm said it stopped a massive 99 million ransomware threats for its customers between October 2015 and April 2016 – although admitted the actual figure for real infections globally is likely to be many times this number.

"Mac OS X and iOS are platforms that Trend Micro's security researchers look at," Christopher Budd, global threat communications manager at Trend Micro, told eWEEK. "As far as our Zero Day Initiative soliciting vulnerabilities from researchers for Mac OS X and iOS for possible vulnerabilities, Mac OS is one of the platforms of focus for Pwn2Own 2016."

Although cybercriminals have been turning out specialized hacking and attack tools at a rapid pace, terrorists are often using legitimate, consumer-focused technologies, according to a new Trend Micro report.
Trend Micro also supports the new policy, saying: "These changes were made in response to Trend Micro and other VirusTotal contributors seeing more and more companies that do not materially contribute to VirusTotal benefit from the data and analysis of those of us who do contribute on an ongoing basis."
Ed Cabrera, VP of Cyber Security Strategy at Trend Micro, advises a “3, 2, 1” rule for backups: three copies, in two different formats, with one held offsite. He describes it as a more resilient way to store backup files, while having offsite copies protects both the backups and infrastructure.

“It was never meant to enable new companies to use it as a shortcut by silently relying on, and benefitting from, the service without a corresponding investment,” said Trend Micro Chief Technology Officer Raimund Genes, one of many old-line tech executives who pushed for the shift.
A new report from Trend Micro has lifted the lid on the homegrown and commercial tools used by terrorists to communicate and spread propaganda – with many of them also used by cyber-criminals.

The free, mobile chatting service Telegram -- which is anonymous and encrypted -- is used by 34% of jihadists whose communications were the subject of a study by cybersecurity firm Trend Micro.
Of course Cyber Command has the resources to go far beyond what cybercriminal groups are capable of, which means the possibility of more complex, multi-layered attacks, says Ed Cabrera, vice president of cybersecurity strategy for Trend Micro.
The security software company Trend Micro issued a warning this monthdescribing two “critical vulnerabilities” in QuickTime for Windows and advised users to uninstall Apple’s abandoned program immediately. The Homeland Security Department posted a warning based on Trend Micro’s findings and also recommends that PC owners remove QuickTime from their systems.

Trend Micro Vice President of Cloud Research Mark Nunnikhoven told SCMagazine.com via emailed comments that the study “is interesting because of the gap it shows between the perception and reality for most organization's database security.”

“He made it very easy,” Jon Clay, of the security firm Trend Micro, told International Business Times. “It had its own administrative console that would track everything for you; you could pick and choose what components you wanted to install and utilize.”
Last week, researchers discovered two new security holes that could allow bad guys to create malicious files to launch within Apple’s media player. Trend Micro, the security research firm that found the vulnerability, said that it hasn’t yet found any evidence of exploits. But now that the findings are public, without promise of a fix from Apple, the risks are rising.
Security company TrendMicro blogged about the QuickTime vulnerability in a post titled "Urgent call to action." TrendMicro said it is unaware of any attacks that were made as a result of the QuickTime security bug, but it recommended deleting the program anyway.
The U.S. government has recommended that Windows PC users uninstall Apple Inc's QuickTime video player after security software maker Trend Micro Inc said on Thursday it had discovered two new bugs in the software.
"We will see much more successful attacks in other industries," said Ed Cabrera, vice president of cybersecurity strategy at Trend Micro.
Japanese security software maker Trend Micro Inc. said that it had warned Adobe that it had seen attackers exploiting the flaw to infect computers with a type of ransomware known as 'Cerber' as early as March 31.

“The problem is that hospitals aren't very mature when it comes to cybersecurity and dealing with robust, sophisticated online attacks,” Eduardo Cabrera, vice president for cybersecurity strategy at the security company Trend Micro Inc. in Irving, Texas. “A hospital needs health data in order to treat its patients. Hackers know there [are] major consequences if they don't act quickly.”
Kyle Wilhoit, who investigates these types of hacks for Trend Micro, said criminal hackers sometimes gain access to sensitive machinery by mistake.
If you’re curious about the teams and their attacks, security firm Trend Micro has recaps available for both days:
Security researchers from antivirus firm Trend Micro recently detected an attack against companies from 18 countries where key employees were targeted with emails that contained a commercial keylogger program called Olympic Vision.

On Sunday and Monday, the Times, the BBC, AOL and a host of other major news and entertainment websites inadvertently ran malicious ads that attempted to hijack the computers of visitors and demand a ransom, according to security researchers Malwarebytes and Trend Micro.

The malicious advertisements are connected to servers hosting the Angler exploit kit, a software package that probes a computer for software vulnerabilities in order to deliver malware, Trend Micro said.
On Monday, Trend Micro researchers said in a blog post that Pawn Storm, well-known for spying upon political targets across the world, is now targeting several government offices -- including the Prime Minister's office and the Turkish parliament -- as well as one of the largest media publications in the country.
On Tuesday, Trend Micro researchers released a whitepaper documenting the results of an investigation into the Web's underbelly, asking if the underground is connected globally, or whether there are countries which have a certain illegal "specialization" in goods or services.

"Over the years, Windows has become a harder target to attack, and less and less of what's connected to the Internet runs Windows," said Christopher Budd, global threat communications manager at Trend Micro.

Trend Micro has been instrumental in bringing down several hostile cyber operations, including, with U.K. partner The National Crime Agency, Refud.me and Cryptex Reborn. Working with Interpol, Kaspersky Lab, Microsoft and the Cyber Defense Institute, the SIMDA botnet was also eliminated.
Researchers at Trend Micro, one of the world's biggest security software firms, said this week that the software used to infect the Ukrainian utilities has also been found in the networks of a large Ukrainian mining company and a rail company.
Four third-party app stores for Android have apps with a malicious component that seeks root access to devices, according to Trend Micro.

It’s the model that Christopher Budd suggests that companies use when thinking about the threats they face. Budd, a global threat communications manager with Trend Micro, has called this a natural evolution. As there’s more money to be made, criminals will get increasingly sophisticated in how to make it.

It's the ultimate challenge for government agencies: How can they be both secure and compliant - especially when operating in a hybrid cloud environment? Trend Micro's Ed Cabrera offers insight into the unique challenges and emerging solutions.
Paul Ferguson, threat research advisor at Trend Micro, told SCMagazine.com that he largely agreedwith the report's premise. “The technology behind a lot of new and emerging services are not built around privacy or security, so it leaves a lot of wiggle room for an adversary to get access to sensitive information, whether that is browsing history, cell phone call detail records, ISP logs, etc.,” said Ferguson. In this instance, the adversary would be a domestic intelligence
But Tom Kellermann, chief cybersecurity officer at Trend Micro, says some data in the study may be a bit skewed since it doesn't appear to include data from hackers in Russia, Brazil, and China, for example.
Uber, PayPal and even Netflix accounts have become much more valuable to criminals, as evidenced by the price these stolen identifiers now fetch on the so-called "Deep Web," according to security company Trend Micro.
Last week, security firm Trend Micro reported finding another piece of ransomware based on Hidden Tear. The threat, detected as Ransom_Cryptear.B, demanded 2,000 Brazilian reals ($500) from victims using a ransom note written in Portuguese.
Last week, security firm Trend Micro reported finding another piece of ransomware based on Hidden Tear. The threat, detected as Ransom_Cryptear.B, demanded 2,000 Brazilian reals ($500) from victims using a ransom note written in Portuguese.

The report, part of a series profiling criminal undergrounds in different countries, placed Brazilian cyber-criminals just behind those in Russia and China in terms of technical expertise. And, because of their focus on financial crimes, Brazilian cyber-criminals are second only to those from Russia in their ability to attack banks and other financial institutions, Tom Kellermann, chief cyber-security officer at Trend Micro, told eWEEK.

Tom Kellermann, chief cybersecurity officer at the security firm Trend Micro, is among the experts who don't anticipate a deterrent effect. "Realistically, this a model that is going to be copied," he says. "There has been an explosion in the last six months of extortion and ransomware. And the more notoriety they get for the takedown, the more copycats there will be."

Eva Chen has served as the CEO of Trend Micro for 11 years. She co-founded the company in 1988, and recently led Trend's $300 million acquisition of IPS vendor TippingPoint from HP. Trend Micro is now doubling down on security products and services for Internet of Things devices, including automobiles, and business and consumer IoT devices and gadgets.

Software will have bugs. And when several researchers start scrutinizing the same code, more bugs will be found. This is exactly what is happening with Mediaserver, as researchers uncover vulnerabilities that are "tangential" to each other, said Christopher Budd, a global threat communications manager at Trend Micro. They all exist in the same component, but are distinct issues.

To help assess whether the Fed system is at risk, I turned to IT security expert Tom Kellermann, chief cybersecurity officer at security provider Trend Micro. He says it's apparently possible that weaknesses in the STAR system could make other Fed systems vulnerable. "Watering hole attacks and integrity attacks are flourishing in the wild, and these pose the most severe threats to STAR," Kellermann says. And he sees as worrisome the IG's call for stronger controls to manage access,
"This is the first time we have proof and can tie malware to a particular outage," said Trend Micro senior researcher Kyle Wilhoit. "It is pretty scary."
A new Ursnif malware variant has been detected in the wild, and the U.S. and U.K. are being particularly targeted, according to Trend Micro researchers.