| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
Foreign intelligence services and digital crime rings are probably “digging through” the mammoth database of the more than 36 million people who registered for the extramarital dating site Ashley Madison, said Tom Kellermann, chief cybersecurity officer at security firm Trend Micro.

Tom Kellerman, chief cybersecurity officer at Trend Micro, discusses the hacking of the Ashley Madison website and subsequent release of names and other information related to the site's users. He speaks on "Bloomberg Markets." [Video]
The perils of allowing wearables in the workplace were highlighted again today in new research from Trend Micro which uncovered security and privacy issues with some of the biggest brand smart watches on the market, including the Apple Watch.

The United States makes efforts to ensure that its markets operate fairly, but those values aren't shared by hackers in the former Soviet Union and its satellites, noted Tom Kellermann, chief cybersecurity officer at Trend Micro.

Tom Kellermann, chief cybersecurity officer of threat-intelligence firm Trend Micro, says that while it's not likely the true masterminds behind this hacking and trading scheme will ever be brought to justice, it is refreshing to see law enforcement indict people who are believed to be conducting attacks that compromise market trading.
In February, after an internet-connected gas pump was hacked, Trend Micro security researchers Kyle Wilhoit and Stephen Hilt began conducting an experiment to track hackers targeting gas stations arounnd the world.

Back in April, as similar report which focused on North and South America was released by Trend Micro and the Organization of American States (OAS). That report also showed a dramatic increase in cyberattacks directed against critical infrastructure owners and operators.

A handful of attackers targeted fake fuel-tank monitors during a six-month month experiment, showing that real Internet-connected monitors are at risk, according to Trend Micro researchers.
Petrol station monitoring systems are under attack all over the world, some by possible nation state allied hackers, according to new research from Trend Micro. The cyber security giant explained in new research presented at Black Hat 2015 that attacks against these unsecured SCADA systems are no longer theoretical.
Turns out there were quite a few attacks—at least 23—between February and July, where adversaries modified information associated with gas pumps, Trend Micro's Kyle Wilhoit and Stephen Hilt said at the Black Hat security conference here. The duo observed 12 pump identifications, four pump modifications, and two distributed denial of service or denial of service attacks.

This incident motivated Kyle Wilhoit and Stephen Hilt, two security researchers at Trend Micro, to make an experiment. They set up 10 fake gas station monitoring systems and put them online as honeypots. To hackers, or anyone looking for these systems, they looked exactly like regular gas monitoring devices known as Guardian AST, which are made to check and control fuel levels in gas station tanks, and alert operators whenever they get too low.

Cybercrime has developed substantially due to bulletproof hosting service efficiency. Trend Micro's report explains how and why these services evade law enforcement officials and remain online.
Researchers at Trend Micro have reported finding a second denial-of-service (DoS) vulnerability in Android’s “mediaserver” component.
Kyle Wilhoit, senior threat researcher at Trend Micro, to break down real attacks against gas pump monitoring systems
“The Russian underground has become an economy of scale,” says Tom Kellermann, Trend Micro’s chief cyber security officer.

Trend Micro has found a flaw that uses a malformed Matroska (MKV) video in apps or websites to crash Android's "mediaserver" service, effectively turning the target device into a paperweight.

“The culture of silence regarding cyber-attacks in Asia serves as fuel to the guild of thieves who operate with impunity in the region,” said Tom Kellermann, chief cybersecurity officer at security software developer Trend Micro Inc. “The deep-seated historical mistrust in the region undermines true collaboration.”

Trend Micro was first to publish three of the Hacking Team Flash bugs. The company’s chief cybersecurity officer Tom Kellermann likens the history of laxness of Adobe’s security practices in light of Flash’s popularity to poisoning the water supply for all of a village’s wells.
“The dark web is impressively expansive and organizations of this size, conducting schemes of this magnitude, are hidden throughout it in unprecedented numbers,” said Trend Micro chief cybersecurity officer, Tom Kellermann. “With the amount of exploit kits on the market today, the financial sector must brace itself for an increased level of more intensified attacks.”

Trend Micro threat analyst Jay Yaneza said the combination of more developers using .NET in applications and the ease by which hackers can find vulnerabilities in open source software has led to a boom in point of sale (POS) malware targeting Microsoft's .NET software.

Hacking Team intrusion malware can also target iOS and Android devices. Here are the dirty details about Android attacks, from Trend Micro. Note that it warns that if you've been infected, it will be extremely difficult to clean the infection yourself. You'll have to have root privilege to the device and get help from your phone's manufacturer to flash the firmware.

On the other hand, the European Union, with its Right to Be Forgotten rules, has a "much more stringent framework than we do in the United States because we let companies get away with a lot more" here, says Paul Ferguson, a senior threat research advisor at Trend Micro.

But that may be a race that it cannot win. Paul Ferguson, senior adviser for Trend Micro, a security software provider, said that information on Ashley Madison, deleted in one online forum, is beginning to bubble up in others. Once something is published on the Internet,” he said, “it’s there forever.”

FBN’s Jo Ling Kent, Liz Claman and Trend Micro Chief Cybersecurity Officer Tom Kellerman discuss the Ashley Madison hack. [Video]

These new findings, which come from the security research company Trend Micro, indicate that Hacking Team build a fake Android news app. It was called "BeNews," which happens to also be the name of another, now defunct news site. It appears that Hacking Team was able to build the fake app so that it looked legitimate enough to be accepted into the Google Play app store. Nestled inside the app's code, however, was a backdoor to make it a mobile spy tool.
In life and in fiction, the numbered Swiss bank account stands as an untouchable repository for funds, legally obtained or otherwise. Modern criminals likewise need a secure repository, not necessarily for funds but for online resources. A recent report from Trend Micro delves deeply into the world of Bulletproof Hosting Service (BPHS) providers. We don't yet know precisely how and where Darkode's resources were stored, but a BPHS was almost certainly involved.

Forums like Darkode represent one leg of the stool that is the problem of criminal hacking, says Tom Kellermann, chief cybersecurity officer at Trend Micro, because these shutdowns send a warning to American cybercriminals that they may be arrested.
Chief Cybersecurity Officer Thomas Kellerman weighs in on the suspension of trading at the NYSE and the latest malware release. (VIDEO)
“A separate attack against one of these vulnerabilities shows that not sharing the discovery of vulnerabilities with the vendor or broader security community leaves everyone at risk,” argued Trend Micro global threat communication manager, Christopher Budd.
SkyBridge Capital founder Anthony Scaramucci, Heritage Foundation Fellow Steve Moore, former FBI agent Bill Daly and Chief Cybersecurity Officer Tom Kellermann discuss the suspension of trading at the NYSE and concerns about cybersecurity and potential cyber-attacks. (VIDEO)

Hacking tools work by relying on using so-called "zero day" bugs -- vulnerabilities unknown to software makers. According a blog post from cybersecurity firm TrendMicro, the cache has so far revealed the company's tools relied on least two problems in Adobe's Flash Player and in Windows itself.
Researchers from antivirus firm Trend Micro said in a blog post that the leaked Hacking Team files contain two exploits for Flash Player, one of which is already known and has been patched, and one for the Windows kernel.
On Tuesday, security firm Trend Micro shared that at least three exploits – two targeting Adobe Flash Player and one targeting Windows kernel – were found in the information dump.
“A separate attack against one of these vulnerabilities shows that not sharing the discovery of vulnerabilities with the vendor or broader security community leaves everyone at risk,” wrote Christopher Budd, global threat communications manager at Trend.

A cyber blackmail ring is targeting the UK with bogus, malware-filled emails pretending to come from big name companies and government bodies. Trend Micro fraud analyst Paul Pajares and senior architect Jon Oliver reported uncovering the scam in a threat advisory.
We enlisted a team of moderators to ask a number of prominent IT security professionals about the challenges they faced as a woman entering the field, the prejudices they deal with every day and the skills they use to navigate within their business.

Recently discovered malware which uses digital steganography to hide itself in .PNG files has been overwhelmingly targeted at US healthcare providers, according to Trend Micro.
In the past year, U.S. businesses and consumers have experienced more than $18 million in losses stemming from a single strain of ransomware called CryptoWall, according to the Internet Crime Complaint Center.
It may be known to hackers and coders worldwide but for most internet users, the so-called 'Deep Web' remains shrouded in mystery, a supposed morass of drugs, deviancy and stolen credit card details.
The Sept. 11 attacks spurred changes to airport security to prevent future hijackings. But should airline passengers also worry about virtual hijacking?
'Census report' of the unindexed parts of the Internet unearths everything from Bitcoin-laundering services to assassins for hire.
The dark web operates behind an understanding of anonymity. Users aren’t supposed to be able to access dark web websites unless their traffic is anonymized using services like Tor. The IP addresses of dark web services are also hidden so that their hosts are not able to tracked — or at least that’s how it’s supposed to work.

For the U.S., the extradition of Ercan Findikoglu shows the value of patience when it comes to pursuing suspected hacker kingpins.

The deep Web is the vast section of the Internet that isn’t accessible via search engines like Google. To get to the deep Web, you have to use specific software like TOR—The Onion Router—which works to anonymize traffic between two points on the “unindexed Internet.”
The deep and dark web may have a reputation for the illegal and illicit, but it can be a lifeline to many in oppressive and dangerous regimes.
Working out who is behind a cyber attack is one of the hardest parts of dealing with any security incident - and it's getting a lot harder.

It took less than a week for a functional exploit for a recently patched Adobe Flash Player vulnerability to be added to the Magnitude exploit kit, Trend Micro researchers warn...
Trend Micro researchers have unearthed two separate but closely linked malware campaigns attributed to Arab parties.

Contrary to tradeshow presentations, the industry has not failed cybersecurity professionals as many speakers insinuated
Symantec Describes Dual Attack Now Targeting Consumers