| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Nearly a year after Russian government hackers meddled in the 2016 U.S. election, researchers at cybersecurity firm Trend Micro zeroed in on a new sign of trouble: a group of suspect websites.
The incidence of cryptocurrency mining malware continues to skyrocket as the bad guys refocus their efforts away from ransomware in favor of the easy money that cryptocurrency offers them. The latest evidence of the trend came by way of a new report, released earlier this week, that examined attack data for the first half of 2018.

Independent cybersecurity researchers found nearly double the number of vulnerabilities in SCADA systems in the first six months of 2018 as they did in H1 of 2017, according to a new report by Japanese multinational Trend Micro, amid rising concerns about infrastructure security.
Cryptojacking attacks, fileless malware, and malware with small file sizes all increased in the first half of 2018 as cyber thugs tried to use more covert tactics.

Malicious crypto-mining attacks jumped 956 percent from the first half of 2017 to the first half of 2018, IT security firm Trend Micro reported Wednesday.

The 2018 Midyear Security Roundup compiles, analyzes, and synthesizes the global enterprise threat data from the first six months of 2018. The goal of the report is to glean as accurate a picture as possible of the current global digital threat landscape. In the expert opinion of Trend Micro, the threat landscape emphasizes stealth and subtlety rather than more blatant ransomware attacks. T

Cybercriminals are moving away from attention-seeking ransomware attacks in favour of more covert methods to steal money and sensitive data according to a new report from Trend Micro.
Trend Micro's 2018 midyear security report finds that ransomware attack volume is growing slowly, while cryptojacking continues to escalate.
THEY CALL IT Herb2. It’s a dapper robot, wearing a bowtie even while it sits at home in its lab at the University of Washington. Its head is a camera, which it cranes up and down, taking in the view of a dimly lit corner where two computer monitors sit.

Business demand dictates a frenetic pace for delivering new and better technology. To perfect the process, more organizations are taking a DevOps approach—melding software development and software operations simultaneously. The result is greater productivity, standardization, innovation and the ability to scale up.
Trend Micro has reconfirmed its commitment to Internet of Things (IoT) security with a new program designed to leverage its Zero Day Initiative (ZDI) to minimize vulnerabilities as smart products are developed.
Intentionally or not, Microsoft has emerged as a kind of internet cop by devoting considerable resources to thwarting Russian hackers.

With high-profile cyberattacks in the news so often, the market for cybersecurity products continues to climb. According to IDC, worldwide spending on security-related hardware, software, and services is forecast to reach $91.4 billion in 2018, an increase of 10.2 percent over the amount spent in 2017.

Trend Micro Research, along with researchers from IssueMakersLab, recently discovered a supply chain attack targeting South Korean organizations, named Operation Red Signature. The attack was targeted to specific IP ranges of certain organizations within South Korea.

Researchers from Trend Micro have exposed two criminal cyber campaigns targeting South Korean organizations – one, a supply chain attack delivering a remote access tool under the guise of a software update, and two, a ransomware attack leveraging malicious .egg files.

Companies look to colleges, high schools and even nascent hackers to create a new pipeline of future security experts.
The message was clear at this year's Black Hat conference: The "culture," for lack of a better term, of security must change, or society faces living in a world of perpetual cyber-risk.

IT leaders could be dangerously underestimating the security risks posed by IoT, according to new research from Trend Micro. The security vendor polled 1150 IT and security decision-makers in the UK, Germany, the US, Japan and France.

Companies are still leaving basic security flaws and points of entry wide open for hackers to exploit.

With more than 3,500 researchers worldwide, 3,500 vulnerabilities discovered and publicly disclosed, and more than $15m paid to researchers to date, Trend Micro’s Zero Day Initiative (ZDI) is one of the world’s largest supplier-agnostic bug bounty programme.

Developers have long been chasing the dream of being able to write an application once and having it run anywhere. Despite valiant attempts over the years, we’ve never quite succeeded.
After a 20-year career in the U.S Secret Service, Ed Cabrera joined Trend Micro in 2015, where he is now the Chief Cybersecurity Officer, working with organizations to help improve cybersecurity. Among the multiple challenges faced by enterprises around the world are ransomware and Business Email Compromise (BEC) attacks, which represent a more immediate form of risk than other forms of attack that are not quickly monetized by attackers.
Trend Micro announced on June 19 a Managed Detection and Response (MDR) service to assist security operations teams. MDR provides managed cyber-security services that benefit from artificial intelligence (AI) capabilities to help detect threats. The new service is not intended to replace an organization's existing security team, but rather is being positioned as a complementary approach.

As the number of organizations that are embracing containers continues to increase, so does the number of incumbent cybersecurity vendors extending the reach of their platforms. Trend Micro, as part of that trend, has begun offering a Deep Security Smart Check module to continuously scan container images, which complements an existing Deep Security module for securing container runtimes.

Confusion persists around DevOps because the term "has been used and abused so much it's lost all meaning," said Mark Nunnikhoven, VP of cloud research for Trend Micro, speaking Tuesday at the Gartner Security and Risk Management Summit in National Harbor, Maryland. DevOps tools have emerged and organizations have marketed "DevOps people." But at its core DevOps is a philosophy designed to balance two formerly disparate parts of an organization: development and operations.
It's been three years since researchers first discovered automated tank gauges (ATGs) at some 5,000 US gas stations exposed on the public Internet without password protection, and a recent scan found 5,635 locations were vulnerable to the same issue.

One of the men behind the Scan4You, a counter-antivirus tool used by cybercriminals to determine whether their malware would be flagged during routine security scans, has been convicted on three counts in federal court.

Everyone has that thing. That trigger that makes a person twitch. Whether that's standing on the left side of an escalator, walking too slow on the sidewalk or coworkers neglecting to take home last Tuesday's Chipotle guacamole (yes, it has indeed gone bad).
Cybercriminals looking to purchase malware are frequent flyers on dark web forums. Often, nefarious actors are in search of the attack that will deliver the greatest gains, which is why it might come as a surprise to learn that many criminals are rolling the dice on crypto-jacking connected devices.
Data breaches stemming from misconfigured cloud-based storage servers are utterly preventable, and it's up to the security community to educate organizations about tools that are readily available to scan for such mistakes, according to Mark Nunnikhoven, Trend Micro's VP of cloud research.
What matters most, right now, to today's information security community, overwhelmed by an increasing number of not only attacks, but also regulations, quantity of solutions and inability to separate snake oil from reality?
An evolved variant of Necurs botnet malware is using .url files -- known as internet shortcuts -- as part of its infection chain in order to bypass conventional detection methods.

As U.S. lawmakers decide how best to respond to Facebook’s personal data scandal, regulators in Canada are being encouraged to do more to protect the privacy of users in this country.
A security researcher discovered the recent Windows Meltdown patches may fix the Intel flaws but also introduced a more severe vulnerability in some versions of Windows.

A hardware wallet for virtual currencies with millions of users has been compromised by a 15-year-old security researcher.

When Facebook co-founder Mark Zuckerberg posted a status update Wednesday on the still-unfolding Cambridge Analytica scandal, he called it an “issue,” a “mistake” and a “breach of trust.” But he didn’t say it was a data breach.
The relative quiet in ransomware attacks so far in 2018 may be a bit misleading, as ransomware developers have been busy and in some cases moving their craft forward with techniques used in enterprise software development.
Following the tragic death of a woman in Arizona who was struck by a self-driving Uber in autonomous mode, questions have arisen over the other risks of connected cars. In particular, hacking.
Consumers are more worried now about their protected health information (PHI) being compromised, thanks to high-profile breaches like Anthem and Allscripts. The recent RSA Data Privacy Report surveyed 7,500 consumers in Europe and the US. It showed that 59 percent of the respondents were concerned about their medical data being compromised. Thirty-nine percent were worried that a hacker would tamper with their medical information.

A number of recent security industry reports from companies like Trend Micro have found that mobile malware is becoming more widespread and it is increasing in sophistication.

The SecureWorld team just finished reading the latest Trend Micro report, and it's the type of threat landscape information, in plain English, you'll want to share with your leadership team.

Just about all security experts agree that using a VPN, or virtual private network, when accessing the internet via computer or phone is a good idea. In particular, a VPN is one of the easiest ways to avoid getting hacked while you’re taking advantage of the free WiFi at an airport or library.

Criminal “products” from the underworld marketplace are part of a sophisticated and highly profitable global industry.

Time is nearly up. The day of reckoning when it comes to data protection is nearly upon us, with May 25th 2018 marked in bold in every business calendar or diary. The General Data Protection Regulation, or its more popular moniker GDPR, has cast an omnipresent shadow over global business for the last year, with a myriad of surveys and research repeatedly warning against non-compliance – normally with the much used adjective of ‘unprepared’.
The number of unique mobile malware samples increased sharply in 2017 compared to a year ago, according to Trend Micro.

Employing sophisticated scams involving social engineering, email phishing, and the harvesting of employee passwords, attackers have pilfered millions of dollars from some of the world largest corporations—all while bypassing traditional hacking safeguards by simply avoiding the use malware.
An Android trojan that started out as an open-source project has been updated to allow hackers to gain access to virtually all data on infected devices. The new variant of AndroRAT is disguised as an app called 'TrashCleaner' and researchers at Trend Micro say it's distributed via a malicious URL -- indicating that this threat comes from third-party download sites or phishing attacks.

Cyber experts say at least one group of hackers tied to Russia, known as Fancy Bear, has targeted international sporting organizations. According to cyber security firm Trend Micro, the same hacking outfit that penetrated the Democratic National Committee’s computer systems also hacked into the European Ice Hockey Federation, the International Ski Federation, the International Biathlon Union, the International Bobsleigh and Skeleton Federation and the International Luge Federation.

While no cybercriminal worth his salt would turn down a chance to get his hands on your credit card information, there’s an even bigger prize: your Social Security number, which cybersecurity experts say is now the single most valuable piece of information in terms of being able to steal your identity.
IoT stands for the Internet of Things. In the simplest terms possible, it means any device with an on/off switch can be connected to the Internet – from your home heating to vending machines to CCTV cameras. It can also apply in industrial contexts – for instance the drill of an oil rig. Technology research firm Gartner predicts that there will be over 26 billion connected devices by 2020 – “a pervasive digital presence…throughout business process and operations”.