| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
Following the tragic death of a woman in Arizona who was struck by a self-driving Uber in autonomous mode, questions have arisen over the other risks of connected cars. In particular, hacking.
Consumers are more worried now about their protected health information (PHI) being compromised, thanks to high-profile breaches like Anthem and Allscripts. The recent RSA Data Privacy Report surveyed 7,500 consumers in Europe and the US. It showed that 59 percent of the respondents were concerned about their medical data being compromised. Thirty-nine percent were worried that a hacker would tamper with their medical information.

A number of recent security industry reports from companies like Trend Micro have found that mobile malware is becoming more widespread and it is increasing in sophistication.

The SecureWorld team just finished reading the latest Trend Micro report, and it's the type of threat landscape information, in plain English, you'll want to share with your leadership team.

Just about all security experts agree that using a VPN, or virtual private network, when accessing the internet via computer or phone is a good idea. In particular, a VPN is one of the easiest ways to avoid getting hacked while you’re taking advantage of the free WiFi at an airport or library.

Criminal “products” from the underworld marketplace are part of a sophisticated and highly profitable global industry.

Time is nearly up. The day of reckoning when it comes to data protection is nearly upon us, with May 25th 2018 marked in bold in every business calendar or diary. The General Data Protection Regulation, or its more popular moniker GDPR, has cast an omnipresent shadow over global business for the last year, with a myriad of surveys and research repeatedly warning against non-compliance – normally with the much used adjective of ‘unprepared’.
The number of unique mobile malware samples increased sharply in 2017 compared to a year ago, according to Trend Micro.

Employing sophisticated scams involving social engineering, email phishing, and the harvesting of employee passwords, attackers have pilfered millions of dollars from some of the world largest corporations—all while bypassing traditional hacking safeguards by simply avoiding the use malware.
An Android trojan that started out as an open-source project has been updated to allow hackers to gain access to virtually all data on infected devices. The new variant of AndroRAT is disguised as an app called 'TrashCleaner' and researchers at Trend Micro say it's distributed via a malicious URL -- indicating that this threat comes from third-party download sites or phishing attacks.

Cyber experts say at least one group of hackers tied to Russia, known as Fancy Bear, has targeted international sporting organizations. According to cyber security firm Trend Micro, the same hacking outfit that penetrated the Democratic National Committee’s computer systems also hacked into the European Ice Hockey Federation, the International Ski Federation, the International Biathlon Union, the International Bobsleigh and Skeleton Federation and the International Luge Federation.

While no cybercriminal worth his salt would turn down a chance to get his hands on your credit card information, there’s an even bigger prize: your Social Security number, which cybersecurity experts say is now the single most valuable piece of information in terms of being able to steal your identity.
IoT stands for the Internet of Things. In the simplest terms possible, it means any device with an on/off switch can be connected to the Internet – from your home heating to vending machines to CCTV cameras. It can also apply in industrial contexts – for instance the drill of an oil rig. Technology research firm Gartner predicts that there will be over 26 billion connected devices by 2020 – “a pervasive digital presence…throughout business process and operations”.
As it has done many times over the past year with unwanted Android applications on its Play store, Google has removed 89 browser extensions from its official Chrome web store after a security vendor identified them as being malicious. Google has also disabled the rogue extensions from running on the devices of over 420,000 Chrome users whose browsers were infected with the malware. In a blog Feb.
The Olympics have always been a geopolitical microcosm: beyond the athletic match-ups, they provide a vehicle for diplomacy and propaganda, and even, occasionally, a proxy for war. It stands to reason, then, that in 2018 they've also become a nexus of hacker skullduggery. The Olympics unfolding next week in Pyeongchang may already be the most thoroughly hacked in the games' history—with potentially more surprises to come.

Vehicle hacking already has a 15-year pedigree. Though there are at least 36 million vehicles on the road today already connected to the internet, manufacturers appear to have learned little from the biggest security crises of the internet era. Cybersecurity is, yet again, a bolted-on afterthought rather than an integral part of the engineering of an interconnected vehicle.

Trend Micro calls the legacy threat 'Throwhack'; after the more benign 'Throwback Thursday' social media trend; but, says principal security strategist Bharat Mistry in a blog published today, "there’s nothing entertaining about this list of legacy security challenges."
The risk and insurance community consistently ranks cyberrisk as its top area of interest and concern, and it’s no wonder—these days, every year is a banner year for cybersecurity. The more that stays the same, the more things change.

North Korea is one of the least wired nations on Earth. It has two internet connections to the outside world, one that crosses the Yalu River into China, and the other plugs into Russia’s Far East.

Google’s DoubleClick ad network has come under attack by cryptocurrency miners who infiltrated Google ads to tap into the CPU power of those who view these ads on YouTube. Operating like a malware attack, the hacked ads were detected when some users got alerts from antivirus software programs and/or experienced slowdowns in their internet activity.

Cybercriminals have learned that many businesses will pay if a ransomware attack cripples their day-to-day operations. Ransomware drove the spike in digital extortion in 2017 and remains cybercriminals' weapon of choice, according to a new Trend Micro study "Digital Extortion: A Forward-Looking View."
Cyber-criminals will find new ways to blackmail and extort organizations and individuals in 2018, supercharging ransomware, launching online smear campaigns and firing out targeted attacks aimed at key facilities, according to Trend Micro.

After the Equifax breach, identity-theft horror stories have been easy to come by. One solution, according to many experts, is freezing your credit — something hardly anyone has done. "The good news is you know all of your own history, and this breach is so well-known and far-reaching that if you are a victim, it should be easier than usual to fight," Mark Nunnikhoven, the head of cloud research for the cybersecurity firm Trend Micro, told CNN.

Alleged Russian hackers claimed to have leaked a series of documents and emails stolen from the International Luge Federation (FIL) just two weeks ahead of the 2018 Winter Olympics. Going by the name "Fancy Bears' Hack Team", the group is believed to be linked to the notorious Fancy Bear hacking group that experts have tied to Russia's military intelligence group GRU.
A new report has warned that traditional lines between hacktivists and cyber-criminals are blurring and could disappear altogether in some cases, fuelling more damaging ransomware and data theft attacks.
The travel and hospitality industry suffers billions of losses each year due to fraud. “With the right combination of other underground services (compromised accounts, credit cards, etc.) it is possible to cover almost every aspect of the holidays, including food and restaurants, shopping, entertainment, guided tours and more – way beyond flights and hotels,” Vladimir Kropotov, Researcher at Trend Micro, told Help Net Security.

A group believed to be linked to Russian hackers on Wednesday claims to have released documents stolen from the International Luge Federation, the latest sign of hacking efforts targeting the 2018 Winter Games.

Cybersecurity should be top of mind for attendees of the World Economic Forum’s annual meeting in Davos, according to the Global Risks Report 2018.

Trend Micro examined website defacement reports from 1998 to 2016 with machine learning technology to identify some long-term trends. Among the most common types of internet attacks is web defacement, where an attacker changes a victim's website to post a message. How are web defacements conducted and are there common trends? Those are some of the questions that a new study released on Jan. 22 by Trend Micro examines.

File inclusion vulnerabilities, SQL injections, and known vulnerabilities are the most common flaws leveraged by hacktivists who launch Web defacement campaigns. Trend Micro researchers dug into 18 years' worth of data to produce "A Deep Dive into Defacement: How Geopolitical Events Trigger Web Attacks." This report is the analysis of more than 13 million Web defacement reports against websites on multiple continents.

Two devastating malware affecting Android devices surfaced this week, raising serious concerns about the security of Google’s mobile operating system. On Tuesday, Kaspersky Labs exposed “Skygofree,” a spyware bundle capable of performing 48 different remote functions and affecting users in Italy.
Business email compromise (BEC) attacks are projected to exceed $9 billion in 2018. To put that number in context, it has been less than a year since the FBI reported BEC attacks had become a $5.3 billion industry. BEC has grown among threat actors due to "its relative simplicity," according to a new Trend Micro report "Tracking Trends in Business Email Compromise (BEC) Schemes."

Network traffic dictates success. No business in the digital era can survive without it—it’s the lifeblood of modern commerce and communication. However, network traffic is also a double-edged sword. Malicious traffic can disrupt or shut down your enterprise’s web activities, interrupt your sales, damage your reputation, and even shutter your business for good through a particularly devastating attack.

The Russian hackers who stole emails from the Democratic National Committee as part of a campaign to interfere in the 2016 election have been trying to steal information from the U.S. Senate, according to a report published Friday by a computer security firm.

Russian state-linked hackers accused of targeting Democratic Party officials ahead of the 2016 US presidential election have turned their focus on the Senate, according to Trend Micro.

The same Russian government-aligned hackers who penetrated the Democratic Party have spent the past few months laying the groundwork for an espionage campaign against the U.S. Senate, a cybersecurity firm said Friday.

A hacking group heavily linked to the Russian government is attempting to steal U.S. Senate email login credentials and also appears to be preparing to disrupt the 2018 Winter Olympics in South Korea, according to new research by cybersecurity firms TrendMicro and ThreatConnect.

The US Senate was targeted last year by the same hacking group that broke into the Democratic National Committee servers during the 2016 presidential election, according to the cybersecurity firm Trend Micro.

Pawn Storm, the hacking group aligned to the Russian government that penetrated the Democratic National Committee, has mounted additional "brazen attacks" over the past eight months, including persistent targeting of the U.S. Senate internal email system, according to a cybersecurity firm that has tracked their progress.

As we enter a world that is increasingly instrumented and connected, we face a unique set of challenges to secure it. Exactly how best to do so is a much-debated subject, but I believe there is a solution to securing the Internet of Things (IoT). More of that in a moment. First, let’s get a sense of where we are today.
Ed Cabrera, chief cybersecurity officer at Trend Micro, says researchers at the company are "seeing a lot of innovation going on" in PoS malware. While the bot delivery method has been around for a while, attackers are evolving their strategies around distributing malware.
Serverless apps are not a new concept, but adoption of the model is growing among enterprises. Among those pushing greater use of serverless apps are major cloud vendors Amazon, Microsoft, and Google. Trend Micro vice president Mark Nunnikhovenexplains what you need to know about the security implications of serverless applications. He reviews the most secure designs, how to implement security, and what IT Ops need to understand about the trend.
Perhaps you've been hearing strange sounds in your home—ghostly creaks and moans, random Rick Astley tunes, Alexa commands issued in someone else's voice. If so, you haven't necessarily lost your mind. Instead, if you own one of a few models of internet-connected speaker and you've been careless with your network settings, you might be one of thousands of people whose Sonos or Bose devices have been left wide open to audio hijacking by hackers around the world.

Researchers at Trend Micro have found that certain models of Sonos and Bose speakers have vulnerabilities that leave them open to hijacking, as reported by Wired. The accessible speakers are being exploited by hackers that are using them to play spooky sounds, Alexa commands, and... Rick Astley tracks.

Researchers at Trend Micro have discovered a potential hack opening key speakers from Sonos and Bose to remote access. As first reported by Wired, the Sonos Play:1, Sonos One, and Bose SoundTouch systems can be located and taken over through an online scan, letting hackers play music through the system.

The social network unveiled on Wednesday a security feature that lets you see a list of recent emails sent by Facebook. Successful phishing campaigns can be costly for consumers and companies. According to security firm Trend Micro, global losses from compromised business email scams, which often originate via phishing, will exceed $9 billion next year.

Researchers at Trend Micro's Zero Day Initiative also suspect one of the updates is aimed at mitigating a nearly undetectable Microsoft Office exploit that takes advantage of a 24-year-old Microsoft protocol called Dynamic Data Exchange (DDE).
“The online tools we’ve seen show how traditional felony and cybercrime can work concertedly—or even strengthen each other—towards bigger payouts for the bad guys,” TrendMicro reports.

According to research from Trend Micro, while 66 percent of companies say they would never pay a ransom as a point of principle, in practice 65 percent actually do pay the ransom when they get hit.

Researchers at Trend Micro have spotted the first known piece of malware to exploit a recently patched vulnerability affecting the Toast feature in Android.