| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
The Zero Day Initiative (ZDI), which organizes Pwn2Own, published six advisories on Wednesday for each of the security holes fixed by Microsoft.
The malware, called Persirai, has been found infecting Chinese-made wireless cameras since last month, security firm Trend Micro said on Tuesday. The malware does so by exploiting flaws in the cameras that a security researcher reported back in March.

"The industrial robot – it's not ready for the world it's living in," said Mark Nunnikhoven, vice president of cloud research at Trend Micro. "The reality is these things are being connected in more and more places. There are a lot of attacks that could happen in that environment."

The software that runs internet-connected industrial robots is outdated and vulnerable to hacking, according to a new report from cybersecurity firm Trend Micro and the Politecnico de Milano. The researchers found tens of thousands of industrial devices were susceptible to hackers, which included industrial robots.
Trend Micro's Mark Nunnikhoven said the attack was "extremely clever" because it's difficult to filter email with a legitimate Google URL. The URL can't be blocked because it's a legitimate domain, owned and controlled by Google. Defending against this attack relies entirely on the user," he noted.
"As far as the robot thinks, it's still drawing a straight line," Mark Nunnikhoven, vice president of cloud research at Trend Micro, told Forbes. "It's a remote code exploit to change the configuration file, we're not changing the instructions, we’re changing what the robot believes to be true about its environment.
First emerging on the Russian underground marketplace in March 2016, Cerber has been issued in a number of versions with each iteration evolving its structure, techniques and functions. It is now being cited by Trend Micro as the "most prolific family of ransomware in the threat landscape."
Discovered by Trend Micro, FalseGuide's main focus is on infecting and adding as many devices to a centrally-managed botnet. The purpose of this botnet is to show unrequested ads to victims, via popups or other means.

"Despite the best efforts of law enforcement to stem the exponential growth of cybercrime, the truth is that it's an uphill struggle," writes Ed Cabrera, Trend Micro's chief cybersecurity officer. "Transnational cybercriminals these days are well resourced, determined and agile."

A hacking group linked by cybersecurity experts to Russia's military intelligence apparatus has begun taking aim at France's centrist presidential candidate, Emmanuel Macron, the cybersecurity firm Trend Micro said in a report published on Tuesday.

The group, dubbed "Pawn Storm" by security firm Trend Micro, used email phishing tricks and attempted to install malware at think tanks tied to Chancellor Angela Merkel's Christian Democratic Union (CDU) party and coalition partner, the Social Democratic Party (SPD), Feike Hacquebord said.

“There are several things which suggest that the group behind the Macron hacking was also responsible for the DNC breach, for example. We found similarities in the IP addresses and malware used in the attacks,” said Rik Ferguson, vice president of Trend Micro’s security research program.

Machine learning serves as a heavy lifter in security software protecting businesses’ data from cyber criminals’ exfiltration efforts. Since the first deluge of spam created the demand for email security, Trend Micro has been researching and implementing strategies for combining computer intelligence with the wisdom of human experience. Its XGen™ Smart Protection Suite focuses on endpoint, email, and web security, all of which are regularly exploited by criminals.

The security community has gained itself the title of being the team of "no": No clicking on links, no browsing particular websites, no installing certain software. Trend Micro Global VP of cloud security Mark Nunnikhoven told ZDNet this needs to change, because if security is everybody's responsibility, organisations need to act that way.
Looking specifically at the Adobe Flash advisory, Brian Gorenc, senior manager of vulnerability research at Trend Micro, noted that five of the seven fixed issues came through Trend Micro's Zero Day Initiative (ZDI) program and two of the bugs (CVE-2017-3062 and CVE-2017-3063) were disclosed through Pwn2Own, which is operated by Trend Micro's ZDI.

Cybersecurity solutions company Trend Micro Incorporated has announced it is enhancing protection of small business endpoints by adding its newest capabilities of XGen security to Trend Micro Worry-Free Services.

An anonymous hacker working with Trend Micro's Zero Day Initiative (ZDI) disclosed the bugs, which affects Apple TV and watchOS too.
“A remote attacker could exploit this vulnerability in the IIS WebDAV Component with a crafted request using PROPFIND method. Successful exploitation could result in denial of service condition or arbitrary code execution in the context of the user running the application,” said Virendra Bisht, a vulnerability researcher at Trend Micro.

“Other threat actors are now in the stages of creating malicious code based on the original proof-of-concept (PoC) code,” researchers from Trend Micro said in a blog post Wednesday.

I learned this past Saturday that my good friend and Trend Micro CTO, Raimund Genes, passed away suddenly last week. Raimund was only 54.
However, it is unlikely that the group's efforts to stir public pressure against Apple will be effective, noted Mark Nunnikhoven, vice president for cloud research at Trend Micro, in an online post.

Last week, the 10th annual Pwn2own hacking challenge was hosted by Trend Micro's Zero Day Initiative (ZDI), with multiple groups of researchers taking aim at web browsers, operating systems and virtualization technology.
One of the premier hacking contests is Pwn2Own, where security teams get together and see if they can break into the leading operating systems and web browsers.
At this year's installment of Pwn2Own, a hacking competition that's been taking place since 2007, the duo of Samuel Groß and Niklas Baumstark did exactly that.

The Pwn2Own contest runs every year during the CanSecWest security conference in Vancouver, British Columbia. It's organized and sponsored by the Zero Day Initiative (ZDI), an exploit acquisition program operated by Trend Micro after its acquisition of TippingPoint.
Named after its command and control (C&C) panel, the malware “needs only another component from the server to conduct its RAM scraping routine,” Trend Micro says.
Cybercriminals out of West Africa pilfered an average of $2.7 million from businesses and $422,000 on average from individuals during 2013-2015, according to new INTERPOL and Trend Micro data, a rate that is on the rise.
Trend Micro is reporting a new threat to Linux-based Internet of Things (IoT) devices that is specifically able to exploit a specific vulnerability in surveillance cameras made by AVTech.
Cybercrime-related complaints in West Africa soared from 940 in 2013 to 2,182 in 2015, says “Cybercrime in West Africa,” a report jointly done by the global police network known as Interpol and Trend Micro, a security software company with headquarters in Tokyo. Only 30 percent of the cybercrimes reported to police in the region lead to arrests, it said.
West Africa is poised to become a cyber crime hot spot, according to new research out this morning from security firm Trend Micro and Interpol, the international police organization.
This year, TrendMicro sees a 25-percent growth in the number of new ransomware families available for use in breaches.
This year, TrendMicro sees a 25-percent growth in the number of new ransomware families available for use in breaches. Reports of the encroachment of ransomware on government, law enforcement, critical infrastructure, and health and safety are already climbing.

In 2016, security firm Trend Micro counted 247 new ransomware families, compared to just 29 in 2015.
In February 2017, Trend Micro revealed that the Crysis ransomware was being distributed via RDP attacks too.

More than 36,000 healthcare-related devices in the US alone are easily discoverable on Shodan, a sort of search engine for connected devices, according to a recent Trend Micro survey.
2016 was truly the year of online extortion. Cyber threats reached an all-time high, with ransomware and Business Email Compromise (BEC) scams gaining increased popularity among cybercriminals looking to extort enterprises. A 752 percent increase in new ransomware families ultimately resulted in $1 billion in losses for enterprises worldwide, according to Trend Micro.
Trend Micro blocked nearly 82 billion threats in 2016, with ransomware and Business Emil Compromise (BEC) in particular causing havoc for organizations worldwide, according to a new report.
Speaking at RSA Conference 2017 Wendy Moore, director of user protection at Trend Micro, presented a session on going beyond next gen to deliver security with maximum impact.
On Wednesday, researchers Numaan Huq and Stephen Hilt from Trend Micro revealed at the RSA conference in San Francisco, California, that many IoT devices are lacking basic security and are visible using services such as the Shodan search engine, which is used to discover devices which are accessible from the Internet.
(#7) Trend Micro was pleased with its recommended rating by NSS Labs, saying Trend Micro OfficeScan Agent v12.0.1851 received “one of the highest malware protection scores with no false positives.” The vendor noted that scored as “100% effective against exploits and evasion,” but doesn’t mention the exact score handed out by NSS Labs. The graph notes that Trend Micro had “no observed evasions.”
One such ransomware gang is the group behind the Crysis ransomware, who's been recently using RDP brute-force attacks to infect large organizations. In the past six months, this group's activity has more than doubled, according to security firm Trend Micro.

Evil hackers with monomaniacal intentions of a globe-disrupting nature have long dominated pop culture sensibilities. But when it comes to for-profit hacking, it's important to remember that cybercrime has been, and remains, predominantly a business-driven concern, says Eduardo Cabrera, chief cybersecurity officer of endpoint security vendor Trend Micro.
According to Trend Micro, most of the attacks are targeting the healthcare sector in the United States, though other industries were hit hard as well.

A recent Trend Micro report revealed that attacks on business emails and business processes will continue to grow in 2017 because they’re cheap and simple forms of corporate extortion.

“Apps may request administrative privileges to your data, and those privileges could be used by the app later on, or by some malware, to steal your personal information,” says Ed Cabrera, chief cybersecurity officer at TrendMicro, a digital security company.
For example, the price of a customizable Crypto Locker executable file is around $50 according to research done by Trend Micro, on top of that, ransomware operators tend to take a 10% cut of the profits made from targets.
Jon Clay, director of Global Threat Communications at Trend Micro, says corporate IT "needs to have visibility into what is occurring within the office—and that can be challenging in the main network, let alone a remote location."
Cabrera, who served 20 years in the United States Secret Service, with a stint as its CISO, and racked up experience leading information security, cyber investigative, and protective programs in support of the Secret Service integrated missions before moving to the private sector, says local skimming operations that physically compromise credit card and financial accounts have been overtaken and outdone by international cybercrimes where attacks on endpoints, networks and cloud
Trend Micro said it validated Shames' identity thanks to his inadvertently using his real name in a series of Hack Forums posts in January 2012 while logged into the Mephobia account.
Trend Micro noted a sharp increase in the number of unique Android malware samples targeted at mobile users—from 10.7 million samples in 2015 to more than 19.2 million in December 2016.