| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

It's the ultimate challenge for government agencies: How can they be both secure and compliant - especially when operating in a hybrid cloud environment? Trend Micro's Ed Cabrera offers insight into the unique challenges and emerging solutions.
Paul Ferguson, threat research advisor at Trend Micro, told SCMagazine.com that he largely agreedwith the report's premise. “The technology behind a lot of new and emerging services are not built around privacy or security, so it leaves a lot of wiggle room for an adversary to get access to sensitive information, whether that is browsing history, cell phone call detail records, ISP logs, etc.,” said Ferguson. In this instance, the adversary would be a domestic intelligence
But Tom Kellermann, chief cybersecurity officer at Trend Micro, says some data in the study may be a bit skewed since it doesn't appear to include data from hackers in Russia, Brazil, and China, for example.
Uber, PayPal and even Netflix accounts have become much more valuable to criminals, as evidenced by the price these stolen identifiers now fetch on the so-called "Deep Web," according to security company Trend Micro.
Last week, security firm Trend Micro reported finding another piece of ransomware based on Hidden Tear. The threat, detected as Ransom_Cryptear.B, demanded 2,000 Brazilian reals ($500) from victims using a ransom note written in Portuguese.
Last week, security firm Trend Micro reported finding another piece of ransomware based on Hidden Tear. The threat, detected as Ransom_Cryptear.B, demanded 2,000 Brazilian reals ($500) from victims using a ransom note written in Portuguese.

The report, part of a series profiling criminal undergrounds in different countries, placed Brazilian cyber-criminals just behind those in Russia and China in terms of technical expertise. And, because of their focus on financial crimes, Brazilian cyber-criminals are second only to those from Russia in their ability to attack banks and other financial institutions, Tom Kellermann, chief cyber-security officer at Trend Micro, told eWEEK.

Tom Kellermann, chief cybersecurity officer at the security firm Trend Micro, is among the experts who don't anticipate a deterrent effect. "Realistically, this a model that is going to be copied," he says. "There has been an explosion in the last six months of extortion and ransomware. And the more notoriety they get for the takedown, the more copycats there will be."

Eva Chen has served as the CEO of Trend Micro for 11 years. She co-founded the company in 1988, and recently led Trend's $300 million acquisition of IPS vendor TippingPoint from HP. Trend Micro is now doubling down on security products and services for Internet of Things devices, including automobiles, and business and consumer IoT devices and gadgets.

Software will have bugs. And when several researchers start scrutinizing the same code, more bugs will be found. This is exactly what is happening with Mediaserver, as researchers uncover vulnerabilities that are "tangential" to each other, said Christopher Budd, a global threat communications manager at Trend Micro. They all exist in the same component, but are distinct issues.

To help assess whether the Fed system is at risk, I turned to IT security expert Tom Kellermann, chief cybersecurity officer at security provider Trend Micro. He says it's apparently possible that weaknesses in the STAR system could make other Fed systems vulnerable. "Watering hole attacks and integrity attacks are flourishing in the wild, and these pose the most severe threats to STAR," Kellermann says. And he sees as worrisome the IG's call for stronger controls to manage access,
"This is the first time we have proof and can tie malware to a particular outage," said Trend Micro senior researcher Kyle Wilhoit. "It is pretty scary."
A new Ursnif malware variant has been detected in the wild, and the U.S. and U.K. are being particularly targeted, according to Trend Micro researchers.
According to a new report by Trend Micro, the North American cyber criminal underground isn't buried as deep as in other geographies.

“The reality is the sector as a whole is dealing with a cyber crime wave,” said Tom Kellermann, chief cyber security officer at Trend Micro, which sells security software.
The Chinese cybercrime underground has evolved to feature search engines to help darknet users find leaked data, and ATM and POS skimmers to capitalize on the growing consumer trend for non-cash payments, according to Trend Micro.
The Chinese cybercrime underground has evolved to feature search engines to help darknet users find leaked data, and ATM and POS skimmers to capitalize on the growing consumer trend for non-cash payments, according to Trend Micro.

However, this decline is not necessarily a positive indicator, according to Christopher Budd, threat communications manager with Trend Micro, the global cloud security company that issued the report, "Follow the Data: Dissecting Data Breaches and Debunking Myths."

However, this decline is not necessarily a positive indicator, according to Christopher Budd, threat communications manager with Trend Micro, the global cloud security company that issued the report, "Follow the Data: Dissecting Data Breaches and Debunking Myths."

"The security landscape is very fragmented and very discombobulated with regard to encryption," said Paul Ferguson, a threat research advisor at Trend Micro. "There doesn't seem to be a lot of coherency, to the point where end users are confused and don't know how to properly protect themselves."

Data stolen from the targets might also have been shared with others in Russia, if that is where the hacker is working, for his own protection, said Tom Kellermann, chief cybersecurity officer for Trend Micro Inc. "This is not over," Kellermann said. "The real question now is how many backdoors are still in these systems that have yet to be detected."
"This iteration of ransomware targeting Linux servers is an escalation," said Paul Ferguson, a senior threat research advisor at Trend Micro.
The media processing layer is prone to vulnerabilities and attacks, said Trend Micro’s Christopher Budd. The operating system takes the data from Web services and executes it as a lower-level process, and handling the shift correctly can be tricky. It is easy to introduce mistakes in this layer.

But Tom Kellermann, chief cybersecurity officer at the security firm Trend Micro, says the timing of the announcement makes sense, given the Angler and Nuclear zero-day malware exploit kits now in widespread use. "I was at the [Oct. 25-28] FS-ISAC Fall Summit, and I think the presentations woke up regulators," he says.
The security flaw was discovered in mid-October, when it was found being exploited by the Russia-linked Pawn Storm threat group in attacks aimed at Foreign Affairs Ministries. The vulnerability affects all Flash releases up to version 19.0.0.226 for Mac and Windows, and Flash Player 11.2.202.540 for Linux, and was discovered by researchers at Trend Micro.

Law enforcement traditionally has struggled to chase down cybercriminals who use ransomware, said Marco Balduzzi, a senior security engineer and researcher at Trend Micro, who researches the dark Web.

Trend Micro plans to integrate the company to create a network defense unit for enterprise clients.

The enterprise IT industry continues to get its ducks in line. On the heels of Dell buying EMC for $67 billion, Western Digital buying SanDisk for $19 billion and rumblings of more M&A to come, HP is moving out of owning assets in the network security business. Today the company announced that it will sell TippingPoint — a provider of next-generation intrusion systems and network security solutions — to security specialist Trend Micro

The FBI and Secret Service are investigating reports that the personal account of CIA Director John Brennan may have been hacked by a teenager. Tom Kellerman, former Commissioner on President Obama’s Cyber Security Commission and Dave Chronister, Founder of Parameter.

The CVE-2015-7645 vulnerability is actively exploited by the Pawn Storm group in attacks targeting several foreign affairs ministries from around the globe, security researchers from Trend Micro reported Tuesday.
Such hardening could be accomplished by attackers shifting their operations to using "no questions asked" bulletproof hosting services, says Tom Kellermann, chief cybersecurity officer at threat-intelligence firm Trend Micro. "I believe Evil Corp will be back in operation by month's end, [with] ... bulletproof hosting and the protection-racket state of Eastern Europe facilitating this," he says.

The newfound exploit was discovered by the security intelligence lab at Trend Micro. This site offers links to disable Flash in every web browser you have.
The email was descibed by researchers at Trend Micro as being as very well executed, saying it includes the PayPal logo, passable German, some basic clean design and some recipients were likely convinced into installing the app. Trend Micro reports that the malicious app is not currently on the Google Play Store and says that this is where the Android setting that disallows the installation of non-Market applications can really save users.
The Scottrade breach could increase the potential for brokerage fraud, says Tom Kellermann, chief cybersecurity officer at threat-intelligence firm Trend Micro. "Cybercriminals understand the financial sector more than we give them credit for," he says. "As we have realized this year, hackers are pursuing front-running and virtual-insider trading schemes."

According to Christopher Budd, a global threat communications manager at security firm Trend Micro, the inability to protect sensitive data despite encryption efforts suggests the hack could be bigger than initially thought.
The earlier Stagefright flaws prompted researchers to probe Android's multimedia processing libraries for additional vulnerabilities. Researchers from antivirus vendor Trend Micro have since found and reported multiple issues in these components.

Access to these accounts can go for exorbitant fees on the black market, said Tom Kellermann, chief cybersecurity officer at security research firm Trend Micro, which released a report last year on Pawn Storm, a likely Russia-based cyber espionage campaign snooping on government officials.
Trend Micro's Raimund Genes on Building Effective Defense Strategies
Offering integration with security services from companies like Barracuda, Checkpoint, Cisco, Imperva and Trend Micro, the new offering can analyze information gathered from customers' deployments and compare it with global threat intelligence aggregated by Microsoft.
Researchers with Trend Micro have identified two new pieces of point-of-sale malware that are affecting small and medium-sized businesses (SMB) predominately in the U.S.
“One year after, the panic has subsided, but the threat goes on living. Attacks related to Shellshock continue to plague our digital world. Since the second quarter of the year, we have seen about more than 70,000 attacks using Shellshock and about 100,000 attacks using Heartbleed. One of our honeypots, which are vulnerable to Shellshock, has recorded 50 attacks in the past 15 days alone,” wrote Trend Micro.

That’s one of the takeaways from a report this week by security firm Trend Micro, which analyzed a decade’s worth of data breaches. The researchers found that businesses are at greater risk of hackings as they grow their online presence while hackers can more easily profit from stolen data.

However, unlike big companies, SMBs are less likely to use sophisticated security and backup solutions that can prevent ransomware infections and help them recover encrypted files, the Trend Micro researchers said in a blog post.
In Trend Micro's new report, dubbed "Understanding Data Breaches," the security firm explores who is most often targeted in data breaches, how they take place, and what happens to data once it leaves corporate networks.
Over the past 10 years of data breach history, 41 percent of breaches were caused not by hacking, but by device loss. Because of a particularly bad record of holding track of its devices, the healthcare industry has been responsible for more breaches than any other sector this decade, according to Trend Micro's analysis of the past 10 years of data breaches -- as catalogued by the nonprofit Privacy Rights Clearinghouse.
UK organizations were hit with on average 40% more targeted attacks than their European counterparts last year, but ended up paying far less, according to new research from Trend Micro.
A high-level hacking group dubbed Iron Tiger has been observed stealing trillions of bytes of confidential data from the United States government, US defense contractors and related companies in the United States and abroad, security company Trend Micro reports in its research paper posted Tuesday, Operation Iron Tiger: Exploring Chinese Cyber Espionage Attacks on U.S. Defense Contractors.
According to a Trend Micro report, the group – known as “Emissary Panda” or “Threat Group-3390 (TG-3390)” – dates back to 2010 when it was observed focusing on political targets and government agencies in China, the Philippines and Tibet.
According toa report released in June by Trend Micro's Forward-Looking Threat Research Team, a startling 26 percent of the sites on the Darknet are child exploitation sites.
As cybercrime continues to get worse - and more players enter the field - it's notable that at least one of the above rules is no longer unwritten, Max Goncharov, a threat researcher at the security firm Trend Micro, says in a recent update on the Russian cybercrime underground (see Why Russian Cybercrime Markets Are Thriving). "The underground market isn't very articulate about the ends toward which products sold should be used, but sometimes, users find a disclaimer stating that Russia