| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

According to security researchers at Trend Micro, the sophisticated tool sheds light on the group’s evolving objectives and marks a significant shift in tactics.

Threat actors are leveraging malicious kernel-level drivers in two separate campaigns detailed on Monday by Fortinet and Trend Micro.

Kevin Simzer of Trend Micro shares his top tips on how startups can break into the cybersecurity scene and the importance of security companies working together, rather than competing against one another, in the fight against cybercrime.

Guerilla malware, distributed by cybercrime gang Lemon Group, can load additional payloads, intercept one-time passwords from SMS texts, set up a reverse proxy from the infected device, and infiltrate WhatsApp sessions.

Lemon Group itself has claimed it has a base of nearly 9 million Guerrilla-infected Android devices that its customers can abuse in different ways. But Trend Micro believes the actual number may be even higher.

Miscreants have infected millions of Androids worldwide with malicious firmware before the devices even shipped from their factories, according to Trend Micro researchers at Black Hat Asia.

Bring together a group of hackers to find and exploit vulnerabilities before the bad guys can, and reward the best ones with cash or prizes: that’s the idea behind Pwn2Own.

Trend Micro's Jon Clay Gets Behind the Scenes of Criminal Organizations

Join Kevin Simzer at RSAC 2023 for a panel discussion on the security challenges of mergers and acquisitions.

Bill Malik of Trend Micro had a talk on detecting and reacting to supply chain vulnerabilities from a maritime perspective, describing the issues that pose a significant risk to the port and shipping industry.

Based on what has been publicly disclosed, AI uses techniques similar to rainbow table attacks rather than simply brute forcing a password, observed Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative.

As the metaverse takes shape over the coming years, many of the security issues afflicting cyberspace will begin to spill over into virtual space as well.

The company says it received two reports from cybersecurity expert Trend Micro on January 10th, 2023, informing the company of two high and critical severity flaws impacting PaperCut MF/NG.

Already this year, Trend Micro reports there’ve been Netflix “We’re sorry to see you go” scams, Netflix job scams, Netflix $90 reward scams, Netflix “Having trouble with your account scams,” and Netflix “Your membership has ended, but…” scams.

Women in cybercrime are more common than you think. Mayra Rosario Fuentes, Underground Cybercriminal Expert at Trend Micro, joins Jill Malandrino on Nasdaq TradeTalks to discuss.

To fully comprehend the complexities of the business, Trend Micro's study "Inside the Halls of a Cybercrime Business" sheds light on the importance of defining and understanding the size of these organizations.

Childs says cybersecurity is set to be a defining factor for the auto industry, as manufacturers develop new infotainment and tech features at a rapid pace.

The digital vein of printer vulnerabilities is far from being tapped out, says Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, which runs the Pwn2Own competition.

Fears big and small can hold us back from becoming the best versions of ourselves, personally and professionally.

"Microsoft was reluctant, for a time, to make this patch official," says Jon Clay, vice president of threat intelligence at Trend Micro.

The researchers, who work for security firm Synacktiv, found the vulnerabilities and showcased them at the Pwn2Own conference in Vancouver last week.

Over the course of my career, I’ve seen private equity and M&A be a detriment to the growth of peer companies—motivating me to protect Trend Micro’s growth by deliberately focusing on building internally.

The ChatGPT AI bot has spurred speculation about how hackers might use it and similar tools to attack faster and more effectively, though the more damaging exploits so far have been in laboratories.

Trend Micro has said it stopped 146 billion cyber-threats in 2022, a 55% increase on the previous year and evidence of cyber-criminals widening their efforts to companies of all sizes and sectors.

During its time, DoppelPaymer was “a textbook of the more successful crews that had been doing ransomware attacks,” Ed Cabrera, chief cybersecurity officer at Trend Micro, told me.

As we've noted before, the infosec world moves at a glacial pace toward gender equity. It appears that's not the case in the cyber criminal underground, according to Trend Micro, which recently published a study in which it claims at least 30 percent – if not more – of cyber criminal forum users are women.

Play ransomware, also known as PlayCrypt, first came to light in June 2022. TrendMicro has noted similarities with the Hive and Nokoyawa ransomware groups, suggesting "a high probability of affiliation between these ransomware families."

According to Feike Hacquebord, a senior threat researcher at Trend Micro, some of his peers’ reluctance to discuss attribution comes from the confusion between technical attribution, which consists in identifying sets of threat activity and analyzing patterns, and legal or political attribution, which links these sets to nation-states – and can sometimes lead to the prosecution of individuals.

According to a survey conducted by Trend Micro Incorporated, 86% of global healthcare organizations’ operations have suffered operational outages as a direct ransomware attack on their organization.

Trend Micro is acquiring Anlyz, a provider of security operations center (SOC) technology. This latest Trend Micro acquisition will enable enterprises and MSSPs to improve operational efficiencies, cost effectiveness and security outcomes.

Here is where some of the leading technology CEOs are placing their bets in 2023 and how they are relying on partners to help them tackle emerging opportunities.

"This is not interpreting the Rosetta Stone," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI) told The Register. "It is a first step towards something more."

Trend Micro recently unveiled Trend Micro One, a unified cybersecurity platform aimed at making it easier for partners and customers to view and assess their attack surfaces and risk postures.

Implementing the NIST standard will take time, as many IoT vendors are still catching up to cybersecurity best practices, with devices often lacking strong authentication capabilities, no easy way to distribute and install patches, and poor visibility into activity, including weak or nonexistent logging, Trend Micro's Malik says.

According to Trend Micro, which has been tracking the malicious activity, the threat actors use a set of heavily obfuscated loaders that exploits an old Intel driver flaw to reduce the token integrity of Microsoft Defender and bypass protections.

Many companies have come and gone in the worlds of technology and cybersecurity over the past three and a half decades, but Trend Micro continues to achieve success and stay focused on its mission.

Researchers from Trend Micro who have been tracking the trend reported a 75% increase in ransomware attacks that targeted Linux systems in the first half of 2022 compared with the prior year.

A federal cybersecurity vendor is spinning up a division dedicated to 5G networks, technology that “threat actors are watching and are looking to exploit,” according to Kevin Simzer, Trend Micro’s chief operating officer.

Describing the activity in a Thursday advisory, Trend Micro researchers Mohamed Fahmy, Sherif Magdy and Mahmoud Zohdy have attributed it to the advanced persistent threat (APT) group the company refers to as APT34.

In a Black Hat USA 2022 session, Dustin Childs and Brian Gorenc, both researchers with Trend Micro's Zero Day Initiative (ZDI), pointed to multiple issues like the lack of information around a bug's exploitability, its pervasiveness, and how accessible it might be to attack as reasons why CVSS scores alone are not enough.

Organizations should take note of the risk, especially since the barrier to exploitation for the bugs — aka, the access complexity — is low, says Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI), which reported the vulnerabilities.

Discovered in June 2022 by researchers at cybersecurity company Trend Micro, the malware appears to target mainly English and Russian-speaking users.

In a demonstration, researchers from Trend Micro used a dev container image maintained by Microsoft and wrote a configuration that opened a simple HTTP server using the Python runtime which is included by default and forwarded port 8000 publicly.

Maxwell Leadership Thought Leader Don Yaeger sits down with Trend Micro COO Kevin Simzer to discuss what pro hockey can teach leaders about building pipelines of talent in their organizations.

Two reports from Guardio Labs and Trend Micro explain that these malicious websites are promoted to a broader audience via Google Ad campaigns.

Trend Micro once again takes the top prize with their outstanding report entitled FUTURE / TENSE: TREND MICROSECURITY PREDICTIONS FOR 2023.

According to Trend Micro, Royal is the rebranded version of Zeon ransomware, which emerged earlier this year and which was associated in August with Conti Team One, one of the groups involved in the distribution of the Conti ransomware.

Google has announced Trend Micro will be joining their App Defense Alliance (ADA) to help improve their ability to identify malicious apps before they are published to the Google Play store.

This new tactic was discovered by Trend Micro researchers who observed Raspberry Robin in recent attacks against telecommunication service providers and government systems.

Researchers at Trend Micro have been tracking Raspberry Robin since September and are warning the worm is notable for its 10 layers of obfuscation and its ability to deploy a fake payload to throw off detection efforts.