| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Pawn Storm, the hacking group aligned to the Russian government that penetrated the Democratic National Committee, has mounted additional "brazen attacks" over the past eight months, including persistent targeting of the U.S. Senate internal email system, according to a cybersecurity firm that has tracked their progress.

As we enter a world that is increasingly instrumented and connected, we face a unique set of challenges to secure it. Exactly how best to do so is a much-debated subject, but I believe there is a solution to securing the Internet of Things (IoT). More of that in a moment. First, let’s get a sense of where we are today.
Ed Cabrera, chief cybersecurity officer at Trend Micro, says researchers at the company are "seeing a lot of innovation going on" in PoS malware. While the bot delivery method has been around for a while, attackers are evolving their strategies around distributing malware.
Serverless apps are not a new concept, but adoption of the model is growing among enterprises. Among those pushing greater use of serverless apps are major cloud vendors Amazon, Microsoft, and Google. Trend Micro vice president Mark Nunnikhovenexplains what you need to know about the security implications of serverless applications. He reviews the most secure designs, how to implement security, and what IT Ops need to understand about the trend.
Perhaps you've been hearing strange sounds in your home—ghostly creaks and moans, random Rick Astley tunes, Alexa commands issued in someone else's voice. If so, you haven't necessarily lost your mind. Instead, if you own one of a few models of internet-connected speaker and you've been careless with your network settings, you might be one of thousands of people whose Sonos or Bose devices have been left wide open to audio hijacking by hackers around the world.

Researchers at Trend Micro have found that certain models of Sonos and Bose speakers have vulnerabilities that leave them open to hijacking, as reported by Wired. The accessible speakers are being exploited by hackers that are using them to play spooky sounds, Alexa commands, and... Rick Astley tracks.

Researchers at Trend Micro have discovered a potential hack opening key speakers from Sonos and Bose to remote access. As first reported by Wired, the Sonos Play:1, Sonos One, and Bose SoundTouch systems can be located and taken over through an online scan, letting hackers play music through the system.

The social network unveiled on Wednesday a security feature that lets you see a list of recent emails sent by Facebook. Successful phishing campaigns can be costly for consumers and companies. According to security firm Trend Micro, global losses from compromised business email scams, which often originate via phishing, will exceed $9 billion next year.

Researchers at Trend Micro's Zero Day Initiative also suspect one of the updates is aimed at mitigating a nearly undetectable Microsoft Office exploit that takes advantage of a 24-year-old Microsoft protocol called Dynamic Data Exchange (DDE).
“The online tools we’ve seen show how traditional felony and cybercrime can work concertedly—or even strengthen each other—towards bigger payouts for the bad guys,” TrendMicro reports.

According to research from Trend Micro, while 66 percent of companies say they would never pay a ransom as a point of principle, in practice 65 percent actually do pay the ransom when they get hit.

Researchers at Trend Micro have spotted the first known piece of malware to exploit a recently patched vulnerability affecting the Toast feature in Android.
Russian developer, Alexey Khripkov, said he'd shared his mining code with other developers, which could explain the number of apps containing code referencing his oxothuk nickname that have also been called out by anti-virus firms such as Trend Micro in recent weeks.
“There are many hurdles for businesses to overcome in establishing GDPR compliance – trying to demystify what ‘State of the Art’ means is but another challenge on the list,” said Bharat Mistry, principal security strategist for Trend Micro.

Vice President of Cloud Research at Trend Micro, Mark Nunnikhoven, has a simple guide on how to secure an Amazon S3 buckets.
Content promotion services have been in the "gray market" for a while, but fake news didn't start to gain widespread attention until the 2016 US Presidential election, explains Vladimir Kropotov, senior researcher for Trend Micro's Forward-Looking Threat Research (FTR).
The vulnerabilities were reported to the vendor by Steven Seeley of Offensive Security through Trend Micro’s Zero Day Initiative (ZDI).
The AP validated the list by running it against a sample of phishing emails obtained from people targeted and comparing it to similar rosters gathered independently by other cybersecurity companies, such as Tokyo-based Trend Micro and the Slovakian firm ESET.
The longest exploit chain in the history of the Pwn2Own competition was demonstrated at the Mobile Pwn2Own 2017 event in Tokyo, with security researchers using 11 different bugs to get code execution on a Samsung Galaxy S8.
"The phone connects to a Wi-Fi network and a malicious app is installed. Sensitive information can be exfiltrated from the targeted device," said a spokeperson from Trend Micro.
Trend Micro recently detected malicious apps in the Google Play store that use JavaScript loading and native code injection to avoid being detected.

The latest examples came on Monday with the revelation from antivirus provider Trend Micro that at least two Android apps with as many as 50,000 downloads from Google Play were recently caught putting crypto miners inside a hidden browser window.

There’s no doubt that organizations are under greater threat today from cyberspace than they’ve ever been – Trend Micro alone blocked over 38 billion threats in the first half of 2017.

From a security standpoint, smart lock technologies pose more of a physical challenge than a technology challenge, suggested William Malik, vice president for infrastructure strategies at Trend Micro.

“Based on our initial analysis, Bad Rabbit spreads to other computers in the network by dropping copies of itself in the network using its original name and executing the dropped copies using Windows Management Instrumentation (WMI) and Service Control Manager Remote Protocol. When the Service Control Manager Remote Protocol is used, it uses dictionary attacks for the credentials,” Trend Micro researchers shared.