| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Shannon Murphy, global security and risk strategist for Trend Micro, joins the Dark Reading News Desk during Black Hat USA with advice for customers engaged in AI transformation with security.

Trend Micro notes that, while the attackers remain unknown, the operation appears highly targeted, using custom URLs for the targeted entities and freshly registered C2 domains to evade blocklists.

Microsoft called the vulnerability a spoofing flaw, while Trend Micro’s Zero Day Initiative (ZDI) team, which claimed credit for discovering the vulnerability, characterized the weakness as a remote execution flaw that deserved a higher severity score.

The world of cybersecurity is continuously changing and evolving—but one constant has been the leadership of Eva Chen, the co-founder and CEO of Trend Micro.

Other top industry players that announced new partnerships and integrations included Trend Micro, which unveiled an integration with Nvidia AI Enterprise.

Trend Micro's Kevin Simzer shares exclusive insights about securing AI PCs against the unique threats of this new computing era.

Case in point, a new report from Trend Micro has found that bad actors are utilizing a tried and true method of weaponizing Facebook ads to lure AI users into downloading malware disguised as AI photo editing tools.

To combat deepfakes, where digitally manipulated video is used to convincingly replace one person's likeness, Trend Micro — a cybersecurity company that partners with MSSPs and MSPs — is releasing advanced technology designed to protect all environments from the rapidly growing threat of AI-based attacks and fraud.

Jon Clay, VP of threat intelligence at Trend Micro, told IT Brew his company is working alongside Olympics partner Decathlon, a sporting goods distributor, to manage the threat surface facing the Paris games, starting on July 26.

Now the threat level for CVE-2024-38112 has become even more serious, with the publication of a new report from Trend Micro, which reports on active attacks that it says have exploited this trick in waking up Internet Explorer.

"It's going to be a wild ride because there's just so much at stake and there's a lot of animosity going on between the two sides, unfortunately," Jon Clay, vice president of threat intelligence for the cybersecurity company Trend Micro, said during an interview at this year's RSA Conference in San Francisco.

“To evolve security organizations to embrace more closely DevSecOps culture by building satellite security positions in product teams and designate developers with security roles for effective operation, patch management, and incident response,” Jon Clay, vice president for threat intelligence at Trend Micro, told Industrial Cyber.

Even showing such exploits without any accompanying details runs the risk of directing attackers to rediscover vulnerabilities, says Dustin Childs, head of threat awareness for the Zero Day Initiative at Trend Micro, which runs the Pwn2Own competition.

The cybersecurity company is looking to protect against future AI risk.

Trend will bring these advanced capabilities to consumers in late 2024.

With companies pouring billions into AI software and hardware, these installations need to be protected from cybersecurity threats and other security lapses.

The tools, which Trend Micro planned to show at the Computex conference in Taiwan beginning on Sunday, will be capable of running on Nvidia's chips and are designed to detect intruders and make sure that data is only seen by those authorized to use it.
Research from Trend Micro shows tension between CISOs and senior enterprise leadership. Many security leaders say they’re perceived as nags.

And to protect you from the increased risks of AI applications, too.

A number of serious Windows bugs still haven't made their way into criminal circles, but that won't remain the case forever — and time is running short before ZDI releases exploit details.

Rachel Jin, Vice President of Product Management at Trend Micro, highlighted their dual approach to AI: "AI for security" and "security for AI."

Trend Micro VP of Strategy Eric Skinner reviewed a type of attack that can defeat many multi-factor authentication (MFA) techniques.

According to a recent study by the cybersecurity company TrendMicro, only 3% of respondents who were 65 and older had a digital estate plan. What happens to the other 97% of respondents’ digital assets?

At the 2024 RSA Conference, taking place this week in San Francisco, Trend Micro on Wednesday delivered an update on its 2023 investigation into the criminal use of gen-AI. “Spoiler: criminals are [still] lagging behind on AI adoption."

Throughout the lifecycle of the LockBit group, two major updates and releases of its malware happened, with each more capable and easier to use than the last. Analysis from the law enforcement operation by security company Trend Micro shows it was working on a new version too.

While MFA has its vulnerabilities, especially SMS-based authentication, it's better than leaving your accounts open to devastating attacks, Trend Micro VP of Strategy Eric Skinner tells us at RSA.

Trend Micro has revealed new capabilities to its Trend Vision One, Zero Trust Secure Access (ZTSA) controls for AI service use. The AI gateway is designed to protect the end user journey when accessing public or private generative AI services.

Days leading up to RSAC’s kickoff, dozens of companies were turning up the volume on show news ranging from data-cloud security solutions (Lookout), AI-powered cybersecurity platforms (Trend Micro) and debut fraud-prevention tools (DataDome).

Cybersecurity researchers from Trend Micro published a report that found that one of two things happen: either one group allows the other one to use the compromised infrastructure for a fee, or they each find a different way to break into the device and they use them simultaneously.

“Cybercriminals and Advanced Persistent Threat (APT) actors share a common interest in proxy anonymization layers and Virtual Private Network (VPN) nodes to hide traces of their presence and make detection of malicious activities more difficult,” Trend Micro researchers Feike Hacquebord and Fernando Merces wrote.

According to a recent Trend Micro report, the LockBit group was responsible for at least 25% of all ransomware attacks in 2023 and has hit thousands of victims since 2020.

“It should be harder year over year to exploit whatever software we’re using, whatever devices we’re using,” said Dustin Childs, who is the head of threat awareness at Trend Micro ZDI. Unlike Crowdfense and Zerodium, ZDI pays researchers to acquire zero-days, then reports them to the companies affected with the goal of getting the vulnerabilities fixed.

New research from Trend Micro, which looked at the activities following the LockBit disruption announced over a month ago, found that the law enforcement operation has a “significant impact on the group’s activities.”

Just recently, Trend Micro identified a new Agenda ransomware variant in the wild. This latest Rust-based version comes with a variety of new functionalities and stealth mechanisms, and sets its sights squarely on VMware vCenter and ESXi servers.

The payloads identified by Trend Micro all involve the hijacking of legitimate software tools by cybercriminals, with the likely goal of financial gain. Jasmin, SparkRAT and XMRig are all open-source tools available on GitHub.

"Earth Krahang" doesn't seem to be a high-level military APT. In a new report, researchers from Trend Micro suggested that it may be one wing of iSoon, a private hack-for-hire operation contracted by the Chinese Communist Party (CCP).

There is a skills crisis in today’s executive suites. Boards of the future need to evolve to include cybersecurity expertise.

In addition to LockBit and Play, Black Basta and Conti ransomware are also being used in campaigns targeting the ConnectWise CVEs, Trend Micro reported on Tuesday.

The notorious LockBit gang promised a Georgia court leak “that could affect the upcoming US election.” It didn't materialize—but the story may not be over yet.


"The actor came across as someone who was 'too big to fail' and even showed disdain to the arbitrator who would make the decision on the outcome of the claim," Trend Micro said. "This discourse demonstrated that LockBitSupp is likely using their reputation to carry more weight when negotiating payment for access or the share of ransom payouts with affiliates."

Japanese cybersecurity firm Trend Micro, which also took part in Operation Cronos, released a report on February 22 showing that the LockBit group was already trying to develop a new ransomware version.

In its own research this week, cybersecurity firm Trend Micro wrote that while LockBit has been a dominant ransomware variant, the group behind the malware had been running into a range of “logistical, technical, and reputational problems,” and this was before the law enforcement operation against it.

The ransomware operation was working on the "next-generation" crypto-locking malware, dubbed LockBit-NG-Dev, "which could be an upcoming version the group might consider as a true 4.0 version once complete," Trend Micro said.

As a result of the collaboration with the National Crime Agency in the UK, cybersecurity company Trend Micro analyzed a sample of the latest LockBit development that can work on multiple operating systems.

As part of the daily LockBit leaks this week, Trend Micro's report on the group, published today, analyzed a cross-platform version researchers believe was being designed to succeed the most recent LockBit 3.0 iteration.

The Trend Micro Zero Day Initiative (ZDI) has recently unearthed a critical vulnerability, identified as CVE-2024-21412, which they’ve dubbed ZDI-CAN-23100.

Researchers with Trend Micro’s Zero Day Initiative (ZDI) were among those who discovered the flaw. In a Feb. 13 post, they said it was exploited by the DarkCasino threat group (also known as Water Hydra) in a campaign targeting financial traders.

One of the zero-day vulnerabilities patched by Microsoft with its latest Patch Tuesday updates has been exploited in attacks aimed at financial market traders by a threat group tracked as Water Hydra and DarkCasino, according to Trend Micro.

Trend Micro, which began tracking the campaign in late December 2023, said it entails the exploitation of CVE-2024-21412, a security bypass vulnerability related to Internet Shortcut Files (.URL).