| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

While MFA has its vulnerabilities, especially SMS-based authentication, it's better than leaving your accounts open to devastating attacks, Trend Micro VP of Strategy Eric Skinner tells us at RSA.

Trend Micro has revealed new capabilities to its Trend Vision One, Zero Trust Secure Access (ZTSA) controls for AI service use. The AI gateway is designed to protect the end user journey when accessing public or private generative AI services.

Days leading up to RSAC’s kickoff, dozens of companies were turning up the volume on show news ranging from data-cloud security solutions (Lookout), AI-powered cybersecurity platforms (Trend Micro) and debut fraud-prevention tools (DataDome).

Cybersecurity researchers from Trend Micro published a report that found that one of two things happen: either one group allows the other one to use the compromised infrastructure for a fee, or they each find a different way to break into the device and they use them simultaneously.

“Cybercriminals and Advanced Persistent Threat (APT) actors share a common interest in proxy anonymization layers and Virtual Private Network (VPN) nodes to hide traces of their presence and make detection of malicious activities more difficult,” Trend Micro researchers Feike Hacquebord and Fernando Merces wrote.

According to a recent Trend Micro report, the LockBit group was responsible for at least 25% of all ransomware attacks in 2023 and has hit thousands of victims since 2020.

“It should be harder year over year to exploit whatever software we’re using, whatever devices we’re using,” said Dustin Childs, who is the head of threat awareness at Trend Micro ZDI. Unlike Crowdfense and Zerodium, ZDI pays researchers to acquire zero-days, then reports them to the companies affected with the goal of getting the vulnerabilities fixed.

New research from Trend Micro, which looked at the activities following the LockBit disruption announced over a month ago, found that the law enforcement operation has a “significant impact on the group’s activities.”

Just recently, Trend Micro identified a new Agenda ransomware variant in the wild. This latest Rust-based version comes with a variety of new functionalities and stealth mechanisms, and sets its sights squarely on VMware vCenter and ESXi servers.

The payloads identified by Trend Micro all involve the hijacking of legitimate software tools by cybercriminals, with the likely goal of financial gain. Jasmin, SparkRAT and XMRig are all open-source tools available on GitHub.

"Earth Krahang" doesn't seem to be a high-level military APT. In a new report, researchers from Trend Micro suggested that it may be one wing of iSoon, a private hack-for-hire operation contracted by the Chinese Communist Party (CCP).

There is a skills crisis in today’s executive suites. Boards of the future need to evolve to include cybersecurity expertise.

In addition to LockBit and Play, Black Basta and Conti ransomware are also being used in campaigns targeting the ConnectWise CVEs, Trend Micro reported on Tuesday.

The notorious LockBit gang promised a Georgia court leak “that could affect the upcoming US election.” It didn't materialize—but the story may not be over yet.


"The actor came across as someone who was 'too big to fail' and even showed disdain to the arbitrator who would make the decision on the outcome of the claim," Trend Micro said. "This discourse demonstrated that LockBitSupp is likely using their reputation to carry more weight when negotiating payment for access or the share of ransom payouts with affiliates."

Japanese cybersecurity firm Trend Micro, which also took part in Operation Cronos, released a report on February 22 showing that the LockBit group was already trying to develop a new ransomware version.

In its own research this week, cybersecurity firm Trend Micro wrote that while LockBit has been a dominant ransomware variant, the group behind the malware had been running into a range of “logistical, technical, and reputational problems,” and this was before the law enforcement operation against it.

The ransomware operation was working on the "next-generation" crypto-locking malware, dubbed LockBit-NG-Dev, "which could be an upcoming version the group might consider as a true 4.0 version once complete," Trend Micro said.

As a result of the collaboration with the National Crime Agency in the UK, cybersecurity company Trend Micro analyzed a sample of the latest LockBit development that can work on multiple operating systems.

As part of the daily LockBit leaks this week, Trend Micro's report on the group, published today, analyzed a cross-platform version researchers believe was being designed to succeed the most recent LockBit 3.0 iteration.

The Trend Micro Zero Day Initiative (ZDI) has recently unearthed a critical vulnerability, identified as CVE-2024-21412, which they’ve dubbed ZDI-CAN-23100.

Researchers with Trend Micro’s Zero Day Initiative (ZDI) were among those who discovered the flaw. In a Feb. 13 post, they said it was exploited by the DarkCasino threat group (also known as Water Hydra) in a campaign targeting financial traders.

One of the zero-day vulnerabilities patched by Microsoft with its latest Patch Tuesday updates has been exploited in attacks aimed at financial market traders by a threat group tracked as Water Hydra and DarkCasino, according to Trend Micro.

Trend Micro, which began tracking the campaign in late December 2023, said it entails the exploitation of CVE-2024-21412, a security bypass vulnerability related to Internet Shortcut Files (.URL).