| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

With high-profile cyberattacks in the news so often, the market for cybersecurity products continues to climb. According to IDC, worldwide spending on security-related hardware, software, and services is forecast to reach $91.4 billion in 2018, an increase of 10.2 percent over the amount spent in 2017.

Trend Micro Research, along with researchers from IssueMakersLab, recently discovered a supply chain attack targeting South Korean organizations, named Operation Red Signature. The attack was targeted to specific IP ranges of certain organizations within South Korea.

Researchers from Trend Micro have exposed two criminal cyber campaigns targeting South Korean organizations – one, a supply chain attack delivering a remote access tool under the guise of a software update, and two, a ransomware attack leveraging malicious .egg files.

Companies look to colleges, high schools and even nascent hackers to create a new pipeline of future security experts.
The message was clear at this year's Black Hat conference: The "culture," for lack of a better term, of security must change, or society faces living in a world of perpetual cyber-risk.

IT leaders could be dangerously underestimating the security risks posed by IoT, according to new research from Trend Micro. The security vendor polled 1150 IT and security decision-makers in the UK, Germany, the US, Japan and France.

Companies are still leaving basic security flaws and points of entry wide open for hackers to exploit.

With more than 3,500 researchers worldwide, 3,500 vulnerabilities discovered and publicly disclosed, and more than $15m paid to researchers to date, Trend Micro’s Zero Day Initiative (ZDI) is one of the world’s largest supplier-agnostic bug bounty programme.

Developers have long been chasing the dream of being able to write an application once and having it run anywhere. Despite valiant attempts over the years, we’ve never quite succeeded.
After a 20-year career in the U.S Secret Service, Ed Cabrera joined Trend Micro in 2015, where he is now the Chief Cybersecurity Officer, working with organizations to help improve cybersecurity. Among the multiple challenges faced by enterprises around the world are ransomware and Business Email Compromise (BEC) attacks, which represent a more immediate form of risk than other forms of attack that are not quickly monetized by attackers.
Trend Micro announced on June 19 a Managed Detection and Response (MDR) service to assist security operations teams. MDR provides managed cyber-security services that benefit from artificial intelligence (AI) capabilities to help detect threats. The new service is not intended to replace an organization's existing security team, but rather is being positioned as a complementary approach.

As the number of organizations that are embracing containers continues to increase, so does the number of incumbent cybersecurity vendors extending the reach of their platforms. Trend Micro, as part of that trend, has begun offering a Deep Security Smart Check module to continuously scan container images, which complements an existing Deep Security module for securing container runtimes.

Confusion persists around DevOps because the term "has been used and abused so much it's lost all meaning," said Mark Nunnikhoven, VP of cloud research for Trend Micro, speaking Tuesday at the Gartner Security and Risk Management Summit in National Harbor, Maryland. DevOps tools have emerged and organizations have marketed "DevOps people." But at its core DevOps is a philosophy designed to balance two formerly disparate parts of an organization: development and operations.
It's been three years since researchers first discovered automated tank gauges (ATGs) at some 5,000 US gas stations exposed on the public Internet without password protection, and a recent scan found 5,635 locations were vulnerable to the same issue.

One of the men behind the Scan4You, a counter-antivirus tool used by cybercriminals to determine whether their malware would be flagged during routine security scans, has been convicted on three counts in federal court.

Everyone has that thing. That trigger that makes a person twitch. Whether that's standing on the left side of an escalator, walking too slow on the sidewalk or coworkers neglecting to take home last Tuesday's Chipotle guacamole (yes, it has indeed gone bad).
Cybercriminals looking to purchase malware are frequent flyers on dark web forums. Often, nefarious actors are in search of the attack that will deliver the greatest gains, which is why it might come as a surprise to learn that many criminals are rolling the dice on crypto-jacking connected devices.
Data breaches stemming from misconfigured cloud-based storage servers are utterly preventable, and it's up to the security community to educate organizations about tools that are readily available to scan for such mistakes, according to Mark Nunnikhoven, Trend Micro's VP of cloud research.
What matters most, right now, to today's information security community, overwhelmed by an increasing number of not only attacks, but also regulations, quantity of solutions and inability to separate snake oil from reality?
An evolved variant of Necurs botnet malware is using .url files -- known as internet shortcuts -- as part of its infection chain in order to bypass conventional detection methods.

As U.S. lawmakers decide how best to respond to Facebook’s personal data scandal, regulators in Canada are being encouraged to do more to protect the privacy of users in this country.
A security researcher discovered the recent Windows Meltdown patches may fix the Intel flaws but also introduced a more severe vulnerability in some versions of Windows.

A hardware wallet for virtual currencies with millions of users has been compromised by a 15-year-old security researcher.

When Facebook co-founder Mark Zuckerberg posted a status update Wednesday on the still-unfolding Cambridge Analytica scandal, he called it an “issue,” a “mistake” and a “breach of trust.” But he didn’t say it was a data breach.
The relative quiet in ransomware attacks so far in 2018 may be a bit misleading, as ransomware developers have been busy and in some cases moving their craft forward with techniques used in enterprise software development.