| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

Marco Balduzzi, senior research scientist with Trend Micro, next month at the Black Hat USA virtual event will disclose details of multiple vulnerabilities he and his team discovered in a sampling study of five popular ICS gateway products. Their findings focused not on the gateways' software nor the industrial protocols as in previous research, but rather on a lesser-studied function: the protocol translation process the devices conduct.

A new Trend Micro study reveals how remote workers address cybersecurity -- 72% say they are more conscious of their organization’s cybersecurity policies since lockdown began, but many are breaking the rules anyway due to limited understanding or resource constraints.

A new wave of data breaches in eight U.S. city governments is the work of online scammers using malicious code against the troubled online payments platform Click2Gov, according to research published by TrendMicro.

Trend Micro is adding functionality to its Cloud One platform that will boost managed security service providers’ practices. The vendor made the announcements on Thursday during its first-ever live virtual event. Like other companies, Trend Micro has opted to host customer and partner gatherings over the web until the COVID-19 pandemic passes. As such, Trend Micro shared news that its MSSPs are sure to embrace.

Data breaches, cybercrime and targeted attacks in the cloud have driven demand for cloud security products and services in recent years. From misconfigured storage buckets and excess privileges to Infrastructure as Code templates and automated attacks, this article looks at 12 of the biggest cloud threats that experts are worried about this year.
The Internet Security group Shadowserver has a vital behind-the-scenes role; it identifies online attacks and wrests control of the infrastructure behind them. In March, it learned that longtime corporate sponsor Cisco was ending its support. With just weeks to raise hundreds of thousands of dollars to move its data center out of Cisco's facility—not to mention an additional $1.7 million to make it through the year—the organization was at real risk of extinction. Ten weeks later, Shadowserver has come a long way toward securing its financial future.

Trend Micro has created a guide to Kubernetes threats that categorizes the threats into three broad categories: external attacks, misconfiguration issues and vulnerable applications.

Patch management has historically been a challenge for IT and security teams, which are under pressure to create strong programs and deploy fixes as they're released. Now their challenges are intensified as a global shift to remote work forces companies to rethink patching strategies. Security pros share insights and best practices.

Millions of people have signed up for Netflix during the coronavirus crisis. But cyber criminals have created their own video services on the small screen. It’s like ‘Netflix’ for crooks — and the stars of these shows are you and your money. [VIDEO]

We’re four weeks into the massive time-out forced on us by coronavirus. Many of us have spent much of that time trying to get used to the radical lifestyle change the virus has brought. But we’re also beginning to think about the end of the crisis, and what the world will look like afterward.
Fast Compnay asked some executives, venture capitalists, and analysts for thoughts on the specific changes they expected to see in their worlds. Our CEO Eva Chen weighs in.

Human error and complex cloud deployments open the door to a wide range of cyber threats, according to Trend Micro.
This report reaffirms that misconfigurations are the primary cause of cloud security issues. In fact, 230 million misconfigurations are identified on average each day, proving this risk is prevalent and widespread.

For the past year, one of Russia's top state-sponsored hacking units has spent its time scanning and probing the internet for vulnerable email servers, according to a report published yesterday by cyber-security firm Trend Micro.
The report deals with the activities of APT28, also known as Fancy Bear, Sednit, and Pawn Storm.

Trend Micro blocked over 52 billion unique cyber-threats in 2019, 61 million of which were ransomware, according to its annual roundup report.
The security firm revealed that email remained by far the most popular threat vector, accounting for 91% of all threats. It detected 15% more email threats than in 2018, including a 5% increase in BEC detections.

Researchers at cybersecurity company Trend Micro ran a simulated factory network for seven months that invited all sorts of digital miscreants into the fray. Different attackers used the mock network, or honeypot, to mine cryptocurrency and infected it with two strains of a ransomware known as CrySIS.

Trend Micro's Zero Day Initiative (ZDI) has now officially announced the first Pwn2Own for 2020, to take part in Vancouver at CanSecWest, March 18-20. This time the stakes have been upped in the automotive category: the hacker who can evade the multiple layers of security found in a Tesla Model 3 to pull off a complete vehicle compromise will win a $500,000 (£380,000) prize. Oh yes, and a brand spanking new Tesla Model 3 for good measure.

Trend Micro aims to maintain its leadership position in cloud security over Palo Alto Networks through the $70 million purchase of cybersecurity startup Cloud Conformity.
The Tokyo-based platform security giant said its acquisition of the 50-person cloud security posture management company will help Trend Micro address misconfigurations and unprotected user accounts in the public cloud space, according to Chief Operating Officer Kevin Simzer.

Trend Micro today announced an alliance with Snyk through which alerts about vulnerabilities in open source code will be passed on to the tools Trend Micro makes available to apply virtual patches to both monolithic and microservices-based applications.

Trend Micro, a cybersecurity and defense company, recently announced a strategic partnership with the developer-first security company Snyk to help businesses cope with potential vulnerabilities without interrupting the software delivery process.
The new alliance integrates open source vulnerability intelligence from Snyk with Trend Micro’s comprehensive ability to detect vulnerabilities for teams operating in a DevOps environment.

Hackers will soon be able to stress-test the Facebook Portal at the annual Pwn2Own hacking contest, following the introduction of the social media giant’s debut hardware device last year.

Trend Micro is among the top five endpoint security vendors who’ve been in the battle since the earliest iterations of antivirus software, more than three decades ago. The company has evolved far beyond those days. They came to Las Vegas prepared to push detection and response beyond the endpoint.

A report from Trend Micro detailed some of the latest ways cybercriminals are using the social media platform to defraud users of their cash. Trend Micro analyzed Twitter data over a three-day period in February and found criminals are gaming search engine results to lure more victims.

Data from Black Hat’s fifth attendee survey of more than 300 information security professionals uncovered massive concern over the security of the 2020 U.S. presidential election – and most think the picture is bleak. “In any jurisdiction where digital election technology is not treated like critical infrastructure it is akin to having unregulated ATM machines,” said Greg Young, vice president of cybersecurity at Trend Micro.

Enterprise search engine Elasticsearch is under threat of being turned into a sophisticated cryptocurrency mining botnet to be used in distributed denial of service (DDoS) attacks. Trend Micro describes a new malware strain that launches multi-stage attacks on publicly accessible databases and servers that run old versions of Elasticsearch software.

Trend Micro said it has made its Deep Security as a Service product available on the Microsoft Azure Marketplace. Launching at Microsoft’s Inspire 2019 event, the Trend Micro offering lets organizations combine the benefits of security software-as-a-service (SaaS) with consolidated cloud billing and usage-based, metered pricing.

Trend Micro announced the extension of its industry leading network protection to the cloud, now available on Amazon Web Services (AWS) Marketplace. This was delivered in response to the operational challenges enterprises often experience with available network security solutions. It will first be available for AWS Transit Gateway, with multiple deployment models planned to follow.

According to a recent report issued by security researchers at Trend Micro, ATM malware has become a commodity and any criminal with $1,000 to invest can start attacking ATMs in no time.

A vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without a user's permission. According to Trend Micro's Greg Young, having your camera and audio enabled on your Mac without your knowledge can create a number of scenarios with bad outcomes, including the use of the captured video or screenshots for blackmail.

The attacker behind the development of Anubis has been active for at least 12 years, and in order to stay current, has retooled the malware for use in fresh attack waves, according to Trend Micro researchers.

DevOps initiatives have become important for 74% of organizations over the past year, but communication must improve for DevOps to be successful, according to Trend Micro.

Cybersecurity experts from Trend Micro blocked five million attempted hacks of IoT cameras. Trend Micro teamed up with IP security solution provider VIVOTEK in a bid to secure IoT cameras. Data from 7,000 IP cameras were analysed by Trend Micro to find the scale of the threat against them, and how few protections they have.

The first day of the re:Inforce conference showed how AWS views security—as a fundamental part of building technology. Trend Micro's Mark Nunnikhoven took away three repeated themes: Security is a key business concern, automation is key part of modern security, and security must be built into the fabric of everything.

Trend Micro researchers discovered a cryptocurrency mining botnet that uses the Android Debug Bridge (ADB) Wi-Fi interface and SSH connections to hosts stored in the known_hosts list to spread to other devices.
Trend Micro announced it has blocked 5 million attempted cyberattacks against IP cameras in just five months. Through its strategic partnership with VIVOTEK, a global leading IP security solution provider, Trend Micro’s IoT security solutions are embedded in globally deployed IP cameras to provide superior protection.
According to researchers at Trend Micro, criminals have been using hacking tools that were reportedly stolen from the National Security Agency in targeting companies around the world as part of a cryptomining campaign since March.
SmarTone Japanese operator NTT Docomo will launch a service designed to protect IoT devices running on its mobile network using Trend Micro’s security platform. Protection will be enabled by the Docomo Cloud Platform Network Security Service. The security shield will mainly target Docomo’s customers who are building infrastructure-as-a-service environments.

Trend Micro has confirmed that attackers have been exploiting a vulnerability in the Oracle WebLogic server to install monero (XMR) mining malware, while using certificate files as an obfuscation trick.
Trend Micro published its findings on a new malware, dubbed BlackSquid, which has proven itself to be especially dangerous. The malware has emerged from the depths to attack web servers with a barrage of exploits designed to land illicit cryptocurrency miners.

Trend Micro's Bill Malik tells TechRadar about some of the most pressing IoT threats, including phishing and business email compromise attacks as well as ransomware.
Real estate insurance company First American Financial Corp exposed nearly 885 million sensitive customer documents dating back up to 16 years on a publicly available web page. Trend Micro's Mark Nunnikhoven comments that BEC is a rising issue in the real estate market and is starting to target realtors. An attacker can apply a sense of urgency when posing as a realtor and try to fool a buyer into sending money to a fake account, or vice versa.

Trend Micro is extending the reach of its container security offerings to now address the full range of the DevSecOps life cycle. The latest updates to Trend Micro Deep Security add the ability to inspect all lateral and horizontal traffic movement between containers and platform layers such as Kubernetes and Docker.

Security researchers from Trend Micro said they had recently discovered a new variant of Trickbot arriving via redirection URL in a spam mail message. The URL appears to point toward a Google domain but instead redirects users who click on it to a site that downloads Trickbot on the user's system.

Microsoft released a patch for an elevation-of-privileges vulnerability being exploited in the wild. It’s tied to the Windows Error Reporting feature and is being abused by attackers who have gained local access to affected PCs. According to Trend Micro's Zero Day Initiative, they would need to first gain access to run code on a target system, but malware often uses elevations like this one to go from ‘user’ to ‘admin’ code execution.

Trend Micro's Greg Young shares how complex IoT environments (CIEs) offer new opportunities for hackers to launch physical and digital attacks. That’s bad news for IT professionals as it means a further expansion of the corporate attack surface.
Cybersecurity researchers at Trend Microhave detailed a new means of the Dharma family of ransomware being deployed: by bundling it inside a fake anti-virus software installation.

Trend Micro says that a key vulnerability in smart homes is the control systems and automation platforms used to coordinate all our smart devices. The increasing complexity with each additional device and automation rule also means an expanding attack surface.

Trend Micro found that the radio signals crane controllers use are not encrypted over the air in any way, and can be easily intercepted and spoofed using off-the-shelf equipment and a basic knowledge of electronics and radio engineering.

Trend Micro discovered that a hacking group, nicknamed Mirrorthief, relied on the scripting technique to steal card data from 201 online campus stores across the US and Canada on April 14th. The team slipped its scripts into the checkout pages of the sites (all created by a common developer, PrismRBS) to harvest full card details, names, addresses and phone numbers.
Trend Micro comments that the delineation between pure web defacement and cybercriminal or cyberespionage activity is disappearing. If this continues and escalates, then the line between defacers, hacktivists and cybercriminals will become even more blurred.
Trend Micro is now making it possible to employ Kubernetes to orchestrate security scans of container images conducted by Trend Micro Deep Security, its suite of of tools that rely on deep packet inspection to protect applications using a combination of firewalls, intrusion protection systems and monitoring of logs and files.
Manufacturing networks still running outdated technology could risk their intellectual property and production processes. The Trend Micro report, Securing Smart Factories: Threats to Manufacturing Environments in the Era of Industry 4.0, outlines the security dimension of a new era for manufacturing driven by IoT and connectivity everywhere.