| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

The cybercriminals behind DeadBolt primarily target NAS devices. QNAP systems are the main targets, though in February the group attacked NAS devices from Asustor, a subsidiary of systems maker Asus, said analysts with cybersecurity firm Trend Micro.

Connected cars provide plenty to entice threat actors, with more than 400 million predicted to be on the roads globally by 2025. Trend Micro announced VicOne, dedicated security for the electric vehicles and connected cars of today and tomorrow.

The FBI in April warned that BlackCat affiliates use previously compromised user credentials to gain initial access to a victim network, but didn't identify Exchange flaws as a point of entry. However, researchers at Trend Micro at the time reported BlackCat affiliates had used the Exchange CVE-2021-31207 flaw initial entry and to install a web shell on the server for remote access.

Survey results from Trend Micro indicate that, when it comes to organizations understanding their attack surfaces, most don't.

More processes could be terminated by the updated Cuba ransomware variant prior to file encryption, such as MySQL, MS Exchange, and Outlook, while additional directories and file types have been added to the ransomware's exclusion list, a Trend Micro report revealed.

These factors make DeadBolt different from other NAS ransomware families and could be more problematic for its victims, according to an analysis from Trend Micro this week.

Surveying more than 6,000 IT and business decision-makers in 29 countries for its latest report, Trend Micro said 73% of respondents are worried about the growing attack surface.
To share these insights and to hear how partner executives are responding, Kevin Rhone, ESG Channel Acceleration Practice Director, spoke with partner executives Craig Halliwell (Red Canary), Jean-David Lehmann (Palo Alto Networks) and Louise McEvoy (Trend Micro).

In January 2020, Trend Micro detailed three malicious apps that were disguised as photography and file manager tools that leveraged a security flaw in Android (CVE-2019-2215) to gain root privileges as well as abuse accessibility service permissions to harvest sensitive information.

Trend Micro researcher Magno Logan looked at how cybercriminals could abuse these clusters and exposed kubelet ports.

Trend Micro, a cybersecurity solutions provider, details Black Basta's modus operandi in a recent report.

Dubbed “Cheers” or “Cheerscrypt”, the ransomware first hijacks an ESXi server, then launches an encryptor that locates virtual machines and then terminates them with an esxcli command, according to the researchers at Trend Micro.

The 37-year-old's detention is part of a year-long, counter-BEC initiative code-named Operation Delilah that involved international law enforcement, and started with intelligence from cybersecurity companies Group-IB, Palo Alto Networks Unit 42, and Trend Micro.

The Japan-headquartered cybersecurity company also shifts one of its vice presidents over to lead the federal business.

According to Trend Micro’s Zero Day Initiative (ZDI), which organizes the event, rewards were paid out for 25 unique zero-day vulnerabilities that were used to target Tesla Model 3, Windows 11, Ubuntu, Microsoft Teams, Safari, Firefox and Oracle VirtualBox.

The hacker in question was the supremely talented Manfred Paul who pulled off the lightning-fast double exploit using two critical vulnerabilities at the PWN2OWN Vancouver, 2022, event that came to an end on Friday, May 20.

Dustin Childs, the communications manager of Trend Micro's Zero Day Initiative, which hosts the contest, told Insider he had expected to see "bug collisions," or two researchers finding the same flaw, but was surprised to find everything "was a unique exploit."

In its 15th anniversary year, the elite hacking event created by the Trend Micro Zero Day Initiative (ZDI) pays big bounties to those who reveal zero-days impacting the most prominent of vendors.

TrendMicro discovered that AvosLocker ransomware actors recently used a PowerShell script to disable antivirus software and evade detection.

Hive ransomware, first observed in June 2021, has already “made its mark as one of the most prolific and aggressive ransomware families today,” according to Trend Micro Inc.

"Similar to Joker, another piece of mobile malware, Facestealer changes its code frequently, thus spawning many variants," Trend Micro analysts Cifer Fang, Ford Quin, and Zhengyu Dong said in a new report. "Since its discovery, the spyware has continuously beleaguered Google Play."

Eva Chen is the Co-founder and CEO of Trend Micro, one of the world’s largest security firms. In 2012, she made Forbe’s list of ‘Asia’s 50 Power Businesswomen’.

ESET data from 2020 suggests WannaCry accounted for as much as 40.5% of all ransomware detections globally and, in 2021, WannaCry was the only ransomware to make Trend Micro’s list of top ten most-used malware strains of the year – coming fourth.

While the software giant classified the attack complexity as "high," it also noted that the vuln is under active attack. So "someone must have figured out how to make that happen," wrote Trend Micro's Dustin Childs on the Zero Day Initiative blog.

"The framework is distributed via a pay-per-install (PPI) service and contains multiple parts, including a loader, a dropper, a protection driver, and a full-featured remote access trojan (RAT) that implements its own network communication protocol," Trend Micro said in a report published Thursday.