SCCyberworld

Showing posts with label McAfee. Show all posts
Showing posts with label McAfee. Show all posts

Monday, May 26, 2014

Fortinet Appoints Michelle Ong as Country Manager in Malaysia

MALAYSIA - 26 May, 2014 – Fortinet − a world leader in high-performance network security − today announced that it has appointed a new country manager in Malaysia. Industry veteran Michelle Ong will now oversee Fortinet Malaysia's overall operations and take responsibility for developing and growing the vendor's business in the country.

Ong assumes the reins from Dato' Seri George Chang, who will relinquish his acting country manager position to focus on his role as Fortinet's Vice President for Southeast Asia and Hong Kong.

As head of sales for channel and government accounts in Malaysia for the past two years, Ong has steadily developed Fortinet's traction in these sectors while effectively managing clients, partners and the internal team.

"Ong has left no doubt about her ability to lead and grow a highly experienced team," said Dato' Seri George Chang. "I am confident that under her stewardship, Fortinet will continue to thrive and make inroads into the high-end enterprise, government, financial services and service provider sectors, gaining market share and picking up awards along the way."

Just last month, Fortinet won the Frost & Sullivan Malaysian Network Security Vendor of the Year award for its market share leadership, product innovation and consistent efforts in meeting customer needs.

Ong has held senior sales, marketing and account management roles in prominent technology companies including McAfee, ACA Pacific Technology and MGE Asia. She is well-versed in both vendor and channel business dynamics, and has a track record of success in motivating teams and helping customers attain their business objectives.

"The Malaysian market is expanding rapidly and the opportunity to help enterprises meet their security needs with Fortinet's trusted, end-to-end portfolio has never been greater," said Ong. "I am excited to be leading the team at this time and look forward to making a positive impact on our customers' businesses throughout the country."

Thursday, May 22, 2014

McAfee offers FREE instant protection Scan for mobile apps that overshare personal information

New Release of McAfee Mobile Security Enables Android Users to Instantly Check for Apps That Use Extensive Data Collection Techniques

Singapore – May 22, 2014 – Today McAfee, part of Intel Security, announced the latest version of McAfee Mobile Security that now enables consumers to instantly run free privacy and security scans.  These scans allow users to identify apps that are oversharing personal information. It also scans for and removes malware and looks for other security threats. McAfee makes it simple for users to perform these scans as soon as the product is installed. McAfee Mobile Security also allows users to easily remove apps that pose significant risks.

According to McAfee’s Consumer Mobile Security Report, 80% of mobile apps today collect location information about users, 82% know the device ID, and 57% track when people use their phones.  Additionally, the apps that aggressively and often unnecessarily collect data leverage potentially dangerous ad libraries, and 35% of these apps contain malware.

“Smartphone users download apps so regularly that it is easy to forget how these apps collect information – at times even putting its users at risk,” said David Freer, Vice President, Consumer – APAC at McAfee, part of Intel Security. “Keeping this in mind, McAfee Mobile Security helps users better protect their personal information and inform them of the kind of information their apps have access to.”

McAfee Mobile Security’s privacy scan provides key intelligence about the apps users have installed on a smartphone or tablet.  The scan determines how much information each app is able to access and share, then ranks them by level of privacy sensitivity, while also checking for risky URL associations.  When an app behaves significantly different than others in its category, the level of risk is raised and reflected in its privacy sharing score. At the conclusion of the privacy scan the user can uninstall suspicious apps with one-click.

The most worrisome permissions are apps that read users’ subscriber ID from their smartphones and tablets, anything that gets users’ precise location (as opposed to Wi-Fi network or cell tower), and anything that reads or tracks text messages that can contain private messages and information like online banking transaction authorizations.  To provide a deeper level of protection, the new version of McAfee Mobile Security instantly scans Android apps, files, SD cards and Internet downloads for malware using a method optimized for mobile to be light on resources and battery life.

McAfee Mobile Security
McAfee Mobile Security for Android is designed to prevent privacy invasions, data loss, identity theft and lost or stolen devices.  It includes anti-theft, antivirus, app protection, Web and Wi-Fi protection, along with call and SMS filtering. In AV-Test’s most recent effectiveness test for mobile security products, McAfee Mobile Security received a 100% detection score for the second time this year and was given a top ranking among the 30 vendors that participated in the independent test.  McAfee Mobile Security can be downloaded for free from the Google Play Store.

Monday, April 14, 2014

Mcafee releases free tool to check for heartbleed affected websites

Quick Access to Information Empowers Consumers to Resume Safe Online Surfing

Santa Clara, Calif. / SINGAPORE, April 14th 2014 – Today McAfee, part of Intel Security, released a free tool to help consumers easily gauge their susceptibility to the potentially dangerous effects of the Heartbleed Bug, a vulnerability in OpenSSL that has placed millions of Internet users’ personal information at risk. By entering website domain names into the Heartbleed Checker tool, consumers can immediately determine if the websites they frequent have been affected by Heartbleed by checking whether or not the sites have been upgraded to the version of OpenSSL that is unsusceptible to the bug.

“It’s important that users first check to make sure the websites they frequent are updated before changing their passwords,” said Gary Davis, vice president of consumer marketing at McAfee, part of Intel Security.  “In the wake of confusing information floating around, our tool makes it easy for consumers to quickly access the information they need. Armed with this information, consumers can decide when it is time to change their passwords and regain confidence in a safe web surfing experience.”

Estimated to affect up to two-thirds of all websites, the Heartbleed Bug is a vulnerability in the OpenSSL encryption software that protects usernames, passwords, credit and debit card numbers, and other sensitive user information. A flaw in the SSL code could allow an attacker to gain access to system memory, which potentially could contain sensitive information or communications.  To protect themselves, consumers should determine which sites that they use are affected and then change those account passwords when the affected sites are patched.

To access McAfee’s free Heartbleed Checker visit: http://www.mcafee.com/heartbleed

For more information on the Heartbleed Bug and additional online safety tips visit: http://blogs.mcafee.com/consumer/what-is-heartbleed


Thursday, April 10, 2014

MCAFEE DEFINES STRATEGY FOR SECURING THE INTERNET OF THINGS

Delivers Purpose Built Security Solutions for Connected Devices

SANTA CLARA, Calif. / SINGAPORE — April 10th 2014 – McAfee, part of Intel Security, today outlined its strategy for enabling the secure Internet of Things. Utilizing McAfee’s history of securing the most demanding digital environments, McAfee is building and delivering future-focused security solutions that are essential to unleashing the transformative power of a world in which every device is connected.

Companies of all sizes are linking objects as diverse as smartphones, cars and household appliances to industrial sensors. The installed base of the Internet of Things will be approximately 212 billion "things" globally by the end of 2020, according to IDC. This equates to approximately 27 things for every person on Earth that will need to be secured and managed.  McAfee’s objective is to maintain the trust of these devices while allowing them to perform as intended but with a richer experience.

While this connectivity brings convenience and opens a world of opportunities it also creates unprecedented security challenges in data privacy, safety, governance and trust.  McAfee is addressing these challenges by providing long-term assured functionality and other core security capabilities for the vast array of current and future IoT use cases. To effectively secure these IP connected devices requires that security be designed in and not an afterthought.  A comprehensive IoT strategy includes:

-A secure and holistic solution for information rich environments across multiple environments and devices
-Assurance that devices are operating as intended by the manufacturer and have not been corrupted
-Life cycle security across the device, network, and data center 
-Support for industry standards and device interoperability 
-Ability to solve Information Technology/Cloud services challenges in connecting legacy and new systems to new and future services
-Provide technology to assure individual privacy

Drawing from its 20 plus year history in IT security, McAfee is applying this knowledge and expertise to the evolving IoT market.  McAfee is working closely with the broader Intel and Wind River companies to provide security solutions to ensure connected devices, systems, applications, and data are protected, freeing companies to concentrate on their business. Last week, Intel introduced the Intel Gateway Solutions for IoT, a family of platforms based on Intel® Quark™ and Atom™ processors, as well as McAfee and Wind River software that enables companies to seamlessly interconnect industrial devices into an IoT-ready system of systems.  Additionally McAfee has over 400 OEM partners across the Industrial, Retail and Healthcare verticals.

“McAfee has both the breadth and the depth of security offerings needed to support the complexity and massive scale of the Internet of Things,” said Steve Hoffenberg, Director of M2M Embedded Software & Tools at VDC Research.  “With the company’s strong collaborations with Intel and Wind River, as well as its long history of securing information technology, McAfee is well positioned to proactively address the security needs of the IoT.”

McAfee is focused on addressing security challenges specific to the Internet of Things, including expanded requirements for trust, solution integrity, accountability and privacy.  These solutions must deliver interoperable security which establishes appropriate and effective protection as every layer including the device connection and the cloud.

“Security needs to be built in as the foundation of the Internet of Things,” said Michael Fey, worldwide chief technology officer for Intel Security.  “Any disruption to these IP connected devices can cause damage to the business and our daily lives. We need to have foresight into what is coming so we can prevent against threats and securely manage these devices. McAfee is enabling the future and the possibilities that the Internet of Things brings to our daily lives.”

To learn more about what McAfee is doing to enable a secure Internet of Things, visit www.mcafee.com/embedded.

Monday, March 31, 2014

CONTROVERSY SURROUNDING ADVANCED EVASION TECHNIQUES LEADS TO HIGH PRICE TAG FOR BUSINESSES

Research Commissioned by McAfee Examines the Role and Cost of These Techniques in Recent High Profile Data Breaches

MALAYSIA / KUALA LUMPUR — March 31, 2014 – A new report by McAfee, a division of Intel Security, examines the controversy and confusion surrounding Advanced Evasion Techniques (AETs), and the role that they play in Advanced Persistent Threats (APTs). A Vanson Bourne study, commissioned by McAfee, surveyed 800 CIOs and security managers from the United States, United Kingdom, Germany, France, Australia, Brazil, and South Africa, and showed that there are misunderstandings, misinterpretation, and ineffective safeguards in use by the security experts charged with protecting sensitive data.

“Not many organizations in Malaysia fully understand what impact Advanced Evasion Techniques can have for them and therefore only have limited protection and defense capabilities,” said Alagesan Alagappan, Regional Director for McAfee Malaysia and Indonesia. “As traditional firewalls are unable to protect an organization from AETs, there are different requirements to counter the new generation of cyber attacks.”

Recent high profile data breaches have demonstrated that criminal activity can still evade detection for long periods of time. Survey respondents acknowledged this and more than one in five security professionals admit their network was breached (22 percent). Nearly 40 percent of those breached believe that AETs played a key role. On average, those who experienced a breach in the last 12 months reported a cost to their organization of upwards of $1 million.

“We are no longer dealing with the random drive-by scanner that is just looking for obvious entryways into your network. In today's interconnected world, we are dealing with adversaries who spend weeks or months studying your public facing network footprint, looking for that one small sliver of light which will allow them to gain a foothold into your networks,” said John Masserini, vice president and chief security officer, MIAX Options. “Advanced Evasion Techniques are that sliver of light. When deployed, McAfee’s Next Generation Firewall technology adds an extra layer of depth to protect against such threats, making that sliver of light that much harder to find.”
                                   
Why Current Firewall Tests Hide the Existence of AETs
Nearly 40 percent of IT decision-makers do not believe they have methods to detect and track AETs within their organization, and almost two thirds said that the biggest challenge when trying to implement technology against AETs is convincing the board they are a real and serious threat.

“Many organizations are so intent of identifying new malware that they are falling asleep at the wheel toward advanced evasion techniques that can enable malware to circumvent their security defences,” said Jon Oltsik, senior principal analyst, Enterprise Strategy Group. “AETs pose a great threat because most security solutions can’t detect or stop them. Security professionals and executive managers need to wake up as this is a real and growing threat.”

Of the estimated 800 million known AETs, less than one percent is detected by other vendor’s firewalls. The prevalence of these techniques has risen significantly since 2010 with millions of combinations and modifications of network based AETs having been identified to date.

Professor Andrew Blyth of the University of South Wales has studied the prevalence and impact of AETs for many years. “The simple truth is that Advanced Evasion Techniques (AETs) are a fact of life. It’s shocking that the majority of CIOs and security professionals severely underestimated that there are 329,246 AETs, when in fact the total of known AETs is approximately 2,500 times that number or more than 800 million AETs and growing,” said Blyth.

AETs are methods of disguise used to penetrate target networks undetected and deliver malicious payloads. They were first discovered in 2010 by network security specialist Stonesoft, which was acquired by McAfee in May 2013. Using AETs, an attacker can split apart an exploit into pieces, bypass a firewall or IPS appliance, and once inside the network, reassemble the code to unleash malware and continue an APT attack.

The reason these techniques are under-reported and not well understood is that in some paid tests, vendors are given the chance to correct for them. As such, only the specific techniques identified are corrected for, and not the broader techniques that are rapidly updated and adapted by criminal organizations.
“Hackers already know about advanced evasion techniques and are using them on a daily basis,” said Pat Calhoun, general manager of network security at McAfee. “What we’re hoping to do is educate businesses so they can know what to look for, and understand what’s needed to defend against them.”

High Costs to Organizations
Respondents whose organizations had experienced a network breach in the past twelve months estimate the average cost to the business to be $931,006. Australia, which reported a lower number of breaches at 15 percent, indicated a much higher average cost per breach at $1.5 million. The cost to American respondents also exceeded $1 million on average. The hit to the financial services sector was the hardest, with estimated cost to be over $2 million per breach globally.

To download a copy of the full report, executive summary and infographic, please visit www.mcafee.com/AET.

Tuesday, February 18, 2014

MCAFEE STOPS ADVANCED THREATS WITHIN MILLISECONDS

New McAfee Threat Intelligence Exchange adds Real-Time Orchestration to the Security Connected Platform

SINGAPORE — Feb. 18, 2014 – McAfee today announced, McAfee Threat Intelligence Exchange, the first in the industry to orchestrate local and global threat intelligence information and enterprise-wide security products into one cohesive integrated security system. McAfee Threat Intelligence Exchange brings a unique approach and capability in the elimination of the gap between encounter to containment of advanced targeted attacks.

By sharing threat information across controls and directing preventative actions in real-time, McAfee is able to provide immediate protection against the threats posed by advanced targeted attacks across both network and endpoint controls. What has traditionally taken days, weeks or months now only takes milliseconds. McAfee Threat Intelligence is a significant evolution of the industry-first Security Connected Platform that was delivered by McAfee in 2011.

“We are very excited with the launch of McAfee’s Threat Intelligence Exchange, because this new product will ensure that that organizational threat intelligence can be cross-referenced with global and local threat intelligence. This exchange would then ensure such threats are taken care of in a fast and efficient manner,” said Wahab Yusoff, Vice President of South Asia, McAfee.

Recent high profile data breaches highlight the challenge that organizations face in understanding and combating advanced targeted attacks.  In many cases, the breach is not discovered for days or weeks after the initial compromise has occurred, and often far after proprietary and personally identifiable information has been extracted. The ability to quickly spot and pre-empt advanced threats is now a business differentiator as companies seek to protect their intellectual property and assure customers that their data is safe and secure.

Building on McAfee’s leadership experience across network, endpoint and data security, McAfee Threat Intelligence Exchange allows organizations to orchestrate security controls to identify patterns, immunize assets against newly-identified malware, and prevent data exfiltration in real-time - optimizing security for each organization. McAfee Threat Intelligence Exchange leverages a unique capability called SmartListing that allows broad security controls to extract and exchange contextual information from such examples as certificate information, reputation data, file characteristics and application behaviors within the environment. The resulting actionable intelligence allows the organization to accurately and instantly contain or allow any payload across the organization’s security controls.  Thus for the first time, as threats appear, defenses instantly shield assets much more intelligently and without the limitations of signatures or cloud lookups.

 McAfee Threat Intelligence Exchange combines local threat data with global intelligence data sources such as McAfee Global Threat Intelligence, to offer truly comprehensive threat intelligence for businesses. The collective package provides unprecedented identification of targeted attacks and enables customized controls that protect automatically based on each organization’s unique risks and priorities. This degree of precision offers the most complete and immediate protection against determined criminals and actors behind the most damaging attacks.
Delivering on the Security Connected Vision:

With this announcement, the McAfee Security Connected platform now includes a real-time data exchange messaging framework.  The McAfee data exchange layer provides real-time context sharing and orchestration, as well as the collective threat intelligence and adaptive threat prevention in McAfee Threat Intelligence Exchange.  These industry-leading breakthroughs boost the protective performance of existing McAfee solutions from endpoint, network and analytics environments, and also deliver a standardized data framework by which partners, competitors, and other third party products will be able to orchestrate together in halting advanced threats.

“With complex threats attacking businesses every day, our customers need this adaptive threat prevention now,” said Mike Fey, worldwide chief technology officer for McAfee.  “We are making it easier to tie together intelligence and actions so that our customers’ existing products deliver greater protection while simultaneously finding ways to cut operational costs.  We are delivering the technology that others are just starting to think about to harden the platform upon which future security products will depend.”  

Features & Benefits:
The McAfee Threat Intelligence Exchange solution provides new approaches for answering increasingly urgent problems customers face more often as targeted attacks increase.
Replaces costly manual tasks with automated, real-time data exchange that allows security components to operate as one to share security intelligence in real-time across endpoint, network and other security components.
Brings immediate visibility to the presence of advanced targeted attacks in the organization to answer the question “Am I exposed?”
Protects based on the most complete collective threat intelligence built out of global and third party intelligence data sources combined with local threat intelligence and customized organizational knowledge
Enables endpoints to share contextual intelligence with each other to gain greater environmental threat context which improves accuracy and effectiveness.
Integration simplicity, through McAfee’s data exchange layer, reduces implementation and operational costs and enables unmatched operational effectiveness.

Availability:
Product is expected to be available in Q2 2014. For more information on McAfee Threat Intelligence Exchange visit www.mcafee.com/TIE.


Wednesday, February 5, 2014

STUDY REVEALS MAJORITY OF ADULTS SHARE INTIMATE CONTENT VIA UNSECURED DIGITAL DEVICES

Seventy Percent of 18 - 24 Year Olds Receive Sexually Suggestive Content, 
and Nearly Half Share Passwords

SANTA CLARA, Calif / SINGAPORE - 5 February 2014 – Today, McAfee released the findings from their 2014 Love, Relationships & Technology survey. For a second year in a row, the company examined how more than 1,500 consumers are sharing and storing intimate data on their mobile devices, especially with current or former significant others. The study highlights how sharing personal content such as suggestive texts, naked photos, suggestive video and passcodes on these devices can potentially lead to cyber-stalking and the exposure of private content leaking online.

While 98% of respondents use their mobile device to take photos, 54% send or receive intimate content including video, photos, emails and messages. Of those surveyed, 69% are securing their smartphone with a password or passcode, a 30 percentage point increase from last year’s result.  However, 46% of U.S. adults still share their passwords with another individual (down from 54%), while 42% use the same password across multiple devices, increasing the likelihood that these mobile devices will become hacked.

“With all the stories we’ve heard about intimate photos being leaked, it’s hard to believe people are still sharing their passwords,” said Gary Davis, vice president of McAfee consumer business. “Ultimately, they’re increasing the risks of these photos becoming public and possibly jeopardizing their identity and reputation. Consumers must take precautions and use mobile security to ensure that what should be private stays private.”

McAfee advises consumers not to share passwords or codes for mobile devices with others to help keep their content secure. Mobile users should avoid using weak passwords that can be easily determined such as birthdays, numbers in a row or repeat numbers for their devices. Rather, six-digit passcodes and words translated into numbers using your mobile keypad are stronger and should be utilized.
Additional findings from the survey include:

For Your Eyes Only
Seventy percent of 18 - 24 year olds receive sexually suggestive content from someone, the largest percentage of all age groups. More men are likely to use their mobile device to send and receive similar content (61% men vs. 48% women). Forty-five percent of U.S. adults say they stored intimate content that they have received in comparison to 40% who store risqué photos, videos or messages they have sent. Of those who have sent intimate or racy content, 77% have sent this content to their significant other, while 1 in 10 individuals have sent similar content to a total stranger.

Privacy Gender Gap
According to the survey, more men than women protect their mobile devices (74% men vs. 65% women). Given the desire to protect their mobile devices and its content more than two-thirds of men are interested in purchasing biometric security embedded capabilities (e.g. face recognition, voice recognition, fingerprint recognition, etc.)

The Case of the Ex
While 96% of U.S. adults surveyed trust their significant other with intimate content or otherwise private information they have sent, only 32% have asked their partner to delete the information when ending the relationship. In addition to sharing passwords, 50% share mobile phone content and 48% share email accounts. Yet, a quarter of respondents have taken their partner’s mobile device to see other content stored on it, including messages and photos. One in five people are likely to log into their significant other’s Facebook account at least once a month, and only 30% of those surveyed admitted to stalking their significant other’s ex on social media, with 18 to 24 year olds being the top age group.

Public Display of Online Affection
With 91% of respondents on a social media platform (e.g. Facebook, Twitter, Instagram), of those who answered they would be celebrating Valentine’s Day on social media, 76% of respondents plan to post messages to others while 58% will post photos. Of those that responded, more women than men plan to celebrate their love on social media on Valentine’s Day (80% women vs. 72% men).

To learn more, please visit:
Webpage: www.mcafee.com/loveandtech
Robert Siciliano’s blog post: http://blogs.mcafee.com/consumer/love-and-tech
A Mobile Perspective: http://blogs.mcafee.com/consumer/love-relationships-tech-mobile-2014
Follow on Twitter @McAfeeConsumer and use #SextRegret

Thursday, January 9, 2014

MCAFEE LIVESAFE SERVICE TO SHIP ON NEW HP COMPUTERS

New Relationship Offers Unlimited Cross-Device Security to Safeguard Consumers’ Digital Lives

SINGAPORE—08 Jan. 2014 – McAfee today announced it will deliver McAfee LiveSafe™ service worldwide as a preinstall on select new HP consumer and commercial PCs. McAfee LiveSafe is the first cross-device security service that protects consumers’ data, identity and all the PCs, Macs, smartphones and tablets a user owns. The service delivers on Intel’s vision to redefine the consumer security marketplace.

“We’re entering a new age in computing, where people expect to be able to work, play, invent and explore the digital world without fear,” said Mike DeCesare, president of McAfee. “By helping keep all devices safe, we are empowering people to take advantage of all the amazing things this connected world has to offer.”

McAfee LiveSafe service includes the Personal Locker feature that uses face and voice authentication technology to retrieve a user’s most sensitive personal information and sensitive documents, such as copies of passports and IDs, from a secure online location. In addition to protecting consumers from the latest online viruses and threats for each device a user owns, the McAfee LiveSafe service also offers simplified and automated management of usernames and passwords; privacy protection for smartphone and tablets; and several additional security capabilities.

Tuesday, December 31, 2013

MCAFEE LABS FORECASTS GROWTH IN MOBILE RANSOMWARE AND SECURITY-AWARE ATTACKS IN 2014

2014 Predictions Report Examines Key Trends in the Evolution of Ransomware, Advanced Evasion Techniques, and Social Attacks Targeting Personal and Enterprise Users

SINGAPORE, December 30 2013 -- McAfee Labs today released its annual 2014 Predictions Report, analyzing 2013 trends through its proprietary McAfee Global Threat Intelligence (GTI) service to forecast the threat landscape for the coming year. In 2014, McAfee Labs expects to see the rapidly growing mobile platform draw the lion’s share of threat innovation.

Ransomware is expected to proliferate on mobile devices, as virtual currencies such as Bitcoin fuel the growth of ransomware across all platforms. Attacks using advanced evasion techniques will come of age, with enhanced capabilities to identify and bypass some sandboxing and other local security measures. Social platforms will be used more aggressively to target the finances and personal information of consumers, and the intellectual property and trade secrets of business leaders.

“With target audiences so large, financing mechanisms so convenient, and cyber-talent so accessible, robust innovation in criminal technology and tactics will continue its surge forward in 2014,” said Vincent Weafer, senior vice president of McAfee Labs.

“The activity in mobile and social is representative of an increasing ‘black hat’ focus on the fastest growing and most digitally active consumer audiences, in which personal information is almost as attractive as banking passwords. The emergence and evolution of advanced evasion techniques represents a new enterprise security battlefront, where the hacker’s deep knowledge of architectures and common security tactics enable attacks that are very hard to uncover.”

McAfee Labs foresees the following trends in 2014:
1. Mobile malware will be the driver of growth in both technical innovation and the volume of attacks in the overall malware “market” in 2014.  In the last two quarters reported, new PC malware growth was nearly flat, while appearances of new Android samples grew by 33%. With businesses and consumers continuing their shift to mobile, we expect to see ransomware aimed at mobile devices, attacks targeting near-field communications vulnerabilities, and attacks that corrupt valid apps to expropriate data without being detected.

2. Virtual currencies will fuel malicious ransomware attacks around the world. Although largely a positive development, virtual currencies provide cybercriminals the unregulated and anonymous payment infrastructure they need to collect money from their victims. Currencies such as Bitcoin will enable and accelerate new generations of ransomware such as the Cryptolocker threat of 2013.

3. In the spy vs. spy world of cybercrime and cyber warfare, criminal gangs and state actors will deploy new stealth attacks that will be harder than ever to identify and stop. There will be broad adoption of advanced evasion techniques, such as the use of sandbox-aware attacks that do not fully deploy unless they believe they are running directly on an unprotected device. Other attack technologies will include return-oriented programming attacks that cause legitimate applications to behave in malicious ways, self-deleting malware that covers its tracks after subverting a target, and advanced attacks on dedicated industrial control systems targeting public and private infrastructure.

4. “Social attacks” will be ubiquitous by the end of 2014. We expect to see more attacks that leverage social platform features to capture passwords or data about user contacts, location, or business activities. Such information can be used to target advertising or perpetrate virtual or real-world crimes.  Either directly or through third parties, enterprises will increasingly use “reconnaissance attacks” to capture valuable user and organizational information to gain tactical and strategic advantages.

5. New PC and server attacks will target vulnerabilities above and below the operating system. In 2014, new PC attacks will exploit application vulnerabilities in HTML5, which allows websites to come alive with interaction, personalization, and rich capabilities for programmers. On the mobile platform, we expect to see attacks that will breach the browser’s “sandbox” and give attackers direct access to the device and its services. And cybercriminals will increasingly target vulnerabilities below the operating system in the storage stack and even the BIOS.

6. The evolving threat landscape will dictate adoption of big data security analytics to meet detection and performance requirements. In 2014, security vendors will continue to add new threat-reputation services and analytics tools that will enable them and their users to identify stealth and advanced persistent threats faster and more accurately than can be done today with basic “blacklisting” and “whitelisting” technologies.

7. Deployment of cloud-based corporate applications will create new attack surfaces that will be exploited by cybercriminals. Cybercriminals will look for more ways to exploit the ubiquitous hypervisors found in all data centers, the multitenant access and communications infrastructure implicit in cloud services, and management infrastructure used to provision and monitor large-scale cloud services. Because they lack sufficient leverage to demand security measures in line with their organizational needs, small businesses that purchase cloud-based services will continue to grapple with security risks unaddressed by cloud providers’ user agreements and operating procedures.

For a full copy of the 2014 Predictions Report from McAfee Labs, please visit: http://mcaf.ee/utjz4.

Friday, December 27, 2013

ACCOR HOTELS CHOOSES MCAFEE NEXT-GENERATION FIREWALL FOR SECURE CONNECTIONS WORLDWIDE

SINGAPORE, Dec. 24, 2013 – McAfee today announced that Accor, one of the largest hotel groups in the world, has chosen its next-generation firewall (NGFW) for the protection and continuity of their IT systems. McAfee’s NGFW is the market-leading product from Stonesoft, which was recently acquired by McAfee to enhance its network security portfolio. McAfee NGFW provides unified, modular and flexible network security for every enterprise environment from corporate headquarters and branch sites to data centers and the network edge.

Accor, the world's leading hotel operator and market leader in Europe, is present in 92 countries with nearly 3,600 hotels and 460,000 rooms. Accor's broad portfolio of hotel brands includes Sofitel, Pullman, MGallery, Novotel, Suite Novotel, Mercure, Adagio, ibis, ibis Styles, ibis budget and hotelF1. With more than 160,000 employees in Accor brand hotels worldwide, the company’s network is highly distributed, requiring a strong security solution that’s easy to set up and manage.

“I firmly believe that our IT-based business processes are in the best of hands thanks to the comprehensive and cost-effective security technology platform provided by McAfee’s Stonesoft technology,” said Serge Saghroune, CISO of Accor. “Over the years our confidence has grown because of the excellent level of support and resilient cyber security protection they provide. We trust our next-generation firewall solution and its ability to meet our future security needs.”

The major challenge faced by Accor when they decided to launch their global firewall bid was to ensure continuous secure service while keying in the future development of the hospitality business. ‘Everything as a service’ and the integration of greater bandwidth, full Wi-Fi and mobile applications are part of the evolution, and criteria such as firewall robustness, smart management and ease of deployment were identified as imperatives within this context. The worldwide project involved more than 2,000 sites. The deployment of McAfee NGFW, launched in 2013, will be completed in 18 months.

Accor now benefits from the enhanced management capabilities offered by Stonesoft’s unique centralised console. The best-of-breed encryption functionality ensures secure connections, while at the same time QoS features work to maintain the high availability of the Accor information system. In addition, Stonesoft Service Level Agreements (SLA) also provide unmatched solution support.

“In 2010, the first Stonesoft firewalls were deployed by Accor in France and since then, the dynamic nature of our solutions to meet the latest network security requirements has ensured our staying and growing power,” said Léonard Dahan, Country Manager of Stonesoft France, who first worked with Accor on defining their needs. “We are proud to have been selected for this wide-scale implementation of our NGFW technology with one of the premiere hotel groups in the world today.”

Thursday, December 5, 2013

MCAFEE FINDS EIGHTY PERCENT OF EMPLOYEES USE UNAPPROVED APPS AT WORK

Study Reveals Risky Employee Behavior Known as Shadow IT

SANTA CLARA, Calif. / SINGAPORE, — Dec. 5 2013 – McAfee has released the results of a market research survey designed to uncover the extent and risks of unauthorized Software-as-a-Service (SaaS) applications. The study, conducted by Stratecast (a division of Frost & Sullivan), found that more than 80 percent of survey respondents admit to using non-approved SaaS applications in their jobs. Furthermore, IT employees use a higher number of non-approved SaaS applications than other company employees.

These SaaS applications are also referred to as “Shadow IT,” which is broadly defined as the use of technology solutions within an organization that have not been approved by the IT department or obtained according to IT policies. Frost & Sullivan estimates that the overall SaaS market in North America alone will grow at a rate of 16% CAGR, reaching a market value of $23.5B USD by 2017.  The cloud also makes it relatively easy for employees to acquire and deploy SaaS applications without involving the IT department. As a result, many applications are used by corporate employees and others (such as contractors or business partners) without the participation or approval of the corporate IT department.
Research Highlights:

More than 80% of survey respondents admit to using non-approved SaaS applications in their jobs.
Nearly 35% of all SaaS applications used within the enterprise are non-approved, contributing to Shadow IT.
Microsoft Office 365 is the top unapproved SaaS application (9% of respondents), followed closely by Zoho (8%), LinkedIn (7%) and Facebook (7%).
On average, 15% of users have experienced a security, access, or liability event while using SaaS
IT professionals use Shadow IT more than business users (81% of Line of Business users, and 83% of IT users)
39% of IT respondents use unauthorized SaaS because, “it allows me to bypass IT processes”, while 18% agreed that IT restrictions “make it difficult to do my job.”

“There are risks associated with non-sanctioned SaaS subscriptions infiltrating the corporation, particularly related to security, compliance, and availability,” said Lynda Stadtmueller, program director of the Cloud Computing analysis service within Stratecast.  “Without appropriate knowledge, non-technical employees may choose SaaS providers or configurations that do not measure up to corporate standards for data protection and encryption. They may not realize that their use of such applications may violate regulations concerning handling and storage of private customer data, leaving the company liable for breaches.”

So what makes these employees act rogue and deploy non approved applications? In many cases it is not malicious at all - in fact they are trying to do their job better, or make it easier. In a hypercompetitive global business environment, in which companies are looking to increase tight margins, employees are increasingly being measured on results—in some cases, with their jobs at risk. So they will do whatever it takes to meet their job objectives, which presumably contribute to the company’s own business objectives.

“With over 80 percent of employees admitting to using non-approved SaaS in their jobs, businesses clearly need to protect themselves while still enabling access to applications that help employees be more productive,” said Pat Calhoun, general manager of network security at McAfee.  “The best approach is to deploy solutions that transparently monitor SaaS applications (and other forms of web traffic) and uniformly apply enterprise policies, without restricting employees’ ability to do their jobs better. These not only enable secure access to SaaS applications, but can also encrypt sensitive information, prevent data loss, protect against malware, and enable IT to enforce acceptable usage policies.”

With SaaS application adoption continuing to grow, companies need to develop policies that strike the right balance between flexibility and control. IT and business leaders need to work together to create and support policies that enable employees to use the apps they need to be productive, with controls in place to protect data and minimize corporate risk. McAfee offers organizations the solutions that can provide the access, security, and control needed to meet the growth of SaaS applications.

About the Study:
The survey questioned more than 600 IT and line of business decision-makers or influencers in North America, the UK, Australia and New Zealand. Two thirds of the employees surveyed came from companies with 1000-10,000 employees, and one-third from companies with more than 10,000. To view a copy of the full report visit www.mcafee.com/us/resources/reports/rp-six-trends-security.pdf.


Thursday, November 21, 2013

MCAFEE LABS SEES NEW THREATS SUBVERTING DIGITAL SIGNATURE VALIDATION

Third Quarter Threats Report Identifies Android Malware That Bypasses App Validation as Signed PC Malware Continues to Surge; Bitcoin Popular in Illicit Trade and Cybercrime

SANTA CLARA, Calif. / SINGAPORE — Nov. 21, 2013 – McAfee Labs today released the McAfee Labs Threats Report: Third Quarter 2013, which found new efforts to circumvent digital signature app validation on Android-based devices.

The McAfee Labs team identified a new family of mobile malware that allows an attacker to bypass the digital signature validation of apps on Android devices, which contributed to a 30 percent increase in Android-based malware. At the same time, traditional malware signed with digital signatures grew by 50 percent to more than 1.5 million samples. Less surprising but no less daunting was a 125 percent increase in spam.

“The efforts to bypass code validation on mobile devices, and commandeer it altogether on PCs, both represent attempts to circumvent trust mechanisms upon which our digital ecosystems rely,” said Vincent Weafer, senior vice president of McAfee Labs. “The industry must work harder to ensure the integrity of these technologies given they are becoming even more pervasive in every aspect of our daily lives.”

The third quarter also saw notable events in the use of Bitcoin, for illicit activities such as the purchase of drugs, weapons, and other illegal goods on websites such as Silk Road. The growing presence of Bitcoin-mining malware reinforced the increasing popularity of the currency.

Weafer continued: “As these currencies become further integrated into our global financial system, their stability and safety will require both the financial monetary controls and oversight, and the security measures our industry provides.”

Leveraging data from the McAfee Global Threat Intelligence (GTI) network, the McAfee Labs team identified the following trends in Q3 2013:

Digitally signed malware. Digitally signed malware samples increased 50 percent, to more than 1.5 million new samples. McAfee Labs also revealed the top 50 certificates used to sign malicious payloads. This growing threat calls into question the validity of digital certificates as a trust mechanism.

New mobile malware families. McAfee Labs researchers identified one entirely new family of Android malware, Exploit/MasterKey.A, which allows an attacker to bypass the digital signature validation of apps, a key component of the Android security process. McAfee Labs researchers also found a new class of Android malware that once installed downloads a second-stage payload without the user’s knowledge.

Virtual currencies. Use of new digital currencies by cybercriminals to both execute illegal transactions and launder profits is enabling new and previously unseen levels of criminal activity. These transactions can be executed anonymously, drawing the interest of the cybercriminal community and allowing them to offer illicit goods and services for sale in transactions that would normally be transparent to law enforcement. McAfee Labs also saw cybercriminals develop Bitcoin-mining malware to infect systems, mine their processing power, and produce Bitcoins for commercial transactions. For more information, please read the McAfee Labs report “Virtual Laundry: The Use of Digital Currencies in Cybercrime.”

Android malware. Nearly 700,000 new Android malware samples appeared during the third quarter, as attacks on the mobile operating system increased by more than 30 percent. Despite responsible new security measures by Google, McAfee Labs believes the largest mobile platform will continue to draw the most attention from hackers given it possesses the largest base of potential victims.

Spike in spam. Global spam volume increased 125 percent in the third quarter of 2013. McAfee Labs researchers believe much of this spike was driven by legitimate “affiliate” marketing firms purchasing and using mailing lists sourced from less than reputable sources.

Each quarter, the McAfee Labs team of 500 multidisciplinary researchers in 30 countries follows the complete range of threats in real time, identifying application vulnerabilities, analyzing and correlating risks, and enabling instant remediation to protect enterprises and the public. To read the full McAfee Labs Threats Report: Third Quarter 2013, please visit: http://mcaf.ee/s4xfb

Thursday, November 14, 2013

MCAFEE PARTNERS WITH SAMSUNG TO PROTECT CONSUMERS FROM IN-HOME CYBER ATTACKS

McAfee VirusScan Mobile to Ship on Samsung HomeSync Boxes

SANTA CLARA, Calif./SINGAPORE—14 Nov. 2013 – McAfee today announced protection for Samsung HomeSync users against the growing range of Android-based threats reaching consumers’ living rooms through Internet-connected TV and entertainment platforms. McAfee® VirusScan® Mobile software will come pre-installed in all Samsung HomeSync boxes to provide users with a secure in-home digital entertainment experience.

The Android platform has become increasingly attractive to cybercriminals because it continues to grow as the preferred place for consumers to live out their digital lives.

According to the McAfee Threats Report: Second Quarter 2013, there were nearly 18,000 new Android malware samples in the second quarter of 2013 and this rapid growth is not expected to slow down because Android users are failing to protect themselves. McAfee’s Digital Assets Survey found that only one fifth of U.S. smartphone users and 13 percent of tablet users have security software installed on their devices.

“Consumers are eager to invite new digital entertainment technologies into their home, but with these new technologies comes new security and privacy risks that aren’t being acknowledged,” said Gary Davis, vice president worldwide consumer marketing at McAfee. “We’re able to protect HomeSync customers right at the point of purchase and eliminate the opportunity for malware and other security threats to invade the in-home digital entertainment experience.”

McAfee VirusScan Mobile software is an anti-malware system that scans and cleans mobile data, preventing corruption from viruses, worms, dialers, Trojans, and other malicious code. It protects mobile devices at the most critical points of exposure and will allow all Samsung HomeSync users to enjoy their entertainment and TV experience in a safe and secure environment.

Availability
McAfee VirusScan Mobile software will be pre-installed within all Samsung HomeSync boxes globally as an independent security app at no additional cost to end users. HomeSync will also come with the option to upgrade to McAfee Mobile Security, McAfee’s comprehensive mobile security solution offering best-in-class in privacy features at $29.99 US for a 12-month subscription.

Wednesday, November 13, 2013

MCAFEE SPOTLIGHTS THE “12 SCAMS OF CHRISTMAS” TO KEEP CONSUMERS’ DIGITAL LIVES SAFE

Cyber Scrooges Looking to Capitalize on the Year-End Shopping Season by Hijacking Popular Consumer Habits

SANTA CLARA, Calif./SINGAPORE—13 Nov. 2013 – McAfee today released its annual “12 Scams of Christmas” list to educate the public on the most common scams that criminals use during the upcoming year-end festive season and sales campaigns to take advantage of consumers as they shop on their digital devices. Cybercriminals leverage these scams to steal personal information, earn fast cash, and spread malware.

This year, fall holiday shopping sales are expected to soar to an estimated US$602 billion  in the US alone. E-commerce sales are predicted to rise 15% compared to last year’s digital sales to more than US$60 billion, with m-commerce comprising 16% of this number . Consumers should ensure that they are taking all precautions to protect the data saved on their devices. This is especially true for the 51% of US adults that bank online and 32% that use mobile banking .

“The potential for identity theft increases as consumers share personal information across multiple devices that are often under protected,” said Michelle Dennedy, vice president and chief privacy officer at McAfee. “Understanding criminals’ mindsets and being aware of how they try to take advantage of consumers can help ensure that we use our devices the way they were intended – to enhance our lives not jeopardize them.”

To help consumers stay alert for greedy Grinches as they surf the web for holiday travel deals and seek out gifts for their loved ones, McAfee has identified this year’s top “12 Scams of Christmas”:

1) Not-So-Merry Mobile Apps – Official-looking software for holiday shopping, including those that feature celebrity or company endorsements, could be malicious, designed to steal or send out your personal data.
2) Holiday Mobile SMS Scams – FakeInstaller tricks Android users into thinking it is a legitimate installer for an application and then quickly takes advantage of the unrestricted access to smartphones, sending SMS messages to premium rate numbers without the users’ consent.
3) Hot Holiday Gift Scams – Clever crooks will post dangerous links, phony contests on social media sites, and send phishing emails to entice viewers to reveal personal information or download malware onto their devices.
4) Seasonal Travel Scams – Phony travel deal links and notifications are common, as are hackers waiting to steal your identity upon arrival at your destination. A hotel’s Wi-Fi may claim that you need to install software before using it and instead infect your computer with malware if you “agree.”
5) Dangerous E-Seasons Greetings – Legitimate-looking e-cards wishing friends “Season’s Greetings” can cause unsuspecting users to download “Merry Malware” such as a Trojan or other virus after clicking a link or opening an attachment.
6) Deceptive Online Games – Be wary of games’ sources. Many sites offering full-version downloads are often laden with malware, and integrated social media pages can expose gamers, too
7) Shipping Notifications Shams – Phony shipping notifications can appear to be from a mailing service alerting you to an update on your shipment, when in reality, they are scams carrying malware and other harmful software designed to infect your computer or device.
8) Bogus Gift Cards – Deceptive ads especially on social sites usually claim to offer exclusive deals on gift cards or packages of cards and can lead consumers to purchase phony ones online.
9) Holiday SMiShing – During the holidays, SMiShing is commonly seen in gift card messages, where scammers pose as banks or credit card companies asking you to confirm information for “security purposes”.
10) Fake Charities – Cybercriminals capitalize on generosity and set up fake charity sites and pocket the donations.
11) Romance Scams – Many messages sent from an online friend can include phishing scams, where the person accesses your personal information such as usernames, passwords, and credit card details.
12) Phony E-Tailers – With so many people planning to shop online, scammers set up phony e-commerce sites to steal your money and personal data.

“While devices and computers provide convenience, it also opens up plenty of opportunities for cybercriminals to take advantage of consumers’ purchasing activities,” said Stephen Perchard, Vice President, Consumer and Mobile, Asia Pacific at McAfee. “To protect personal data, consumers should secure their devices before buying and installing applications. Users should also be weary of links offering deals that appear too good to be true and instead, order their purchases from retailers directly.”

If you do plan to search for deals online, use apps or open those shopping related emails, make sure your entire household’s devices have protection, such as McAfee LiveSafe™, which protects all your PCs, Macs, tablets and smartphones. It also includes malware detection software, McAfee® Mobile Security, to protect your smartphone or tablet from all types of malware. This app will guard you from the latest mobile threats and risky apps, offers enhanced privacy and backup features, location tracking and SiteAdvisor® technology to help you steer clear of dangers when searching on a mobile device.

Thursday, October 24, 2013

MCAFEE SURVEY REVEALS OLDER DOES NOT MEAN WISER

According to Study, Social Network Drama Doesn’t Stop at 50

SANTA CLARA, Calif./SINGAPORE – Oct. 24, 2013 – McAfee today released findings from the company’s first survey dedicated to uncovering the online habits and behaviors of individuals ages 50-75. The study, “Fifty Plus Booms Online” indicates that the 50+ demographic is spending a great deal of time online these days (an average of five hours a day), instilling confidence in their attitude toward technology. Some 88% of participants say they consider themselves equally or more tech-savvy compared to others their age. Despite this proclaimed comfort level—or maybe because of it— Baby Boomer adults are socially engaging online, exposing themselves to social media reproach and dangerous security risks, including sharing personal information with strangers.

STRANGER DANGER STILL RELEVENT AT 50+
Many Baby Boomers have voluntarily shared personal information with people they have never met in person (this does not include online shopping or business transactions). Overall, 57% have shared information or posted online personal information. This includes 52% who have shared their email address, 27% who have shared their cell phone number and 26% who have shared their home address.

According to Michelle Dennedy, vice president and chief privacy officer at McAfee, the discovery that this confident, self-proclaimed tech-savvy group exhibits high-risk online behavior, is reason to raise awareness.

“The use of social networks among people 50+ is trending now that it’s become more commonplace across all age groups,” said Dennedy. “It seems counterintuitive that sharing personal information with strangers would not concern them, however. This further highlights their need to better understand the difference between the real and perceived dangers online and how to best protect themselves.

SOCIAL NETWORK DRAMA DOESN’T END WITH TEENAGERS
Despite the fact that social networks have a reputation among the younger generation as a hub for drama among friends, the survey found this to be the case even in this age group. Eight in ten use social media networks, 36% of which log in daily, opening the doors to the possibilities of social media drama. Sixteen percent admitted to experiencing negative situations while logged into their social media accounts. These rifts lead to 19% of claims that the incident was severe enough to end a friendship. Other results from those who had negative experiences include inappropriate posts from friends (23%) and having a fight with a friend, spouse, or partner (9%).

UNPROTECTED AND OVERSHARING
Despite their technological confidence, these adults revealed some concerning and surprising realities regarding online security.

Overall, 57% claimed they have shared and/or posted personal information online. Email addresses (52%), cell phone numbers (27%), and even home addresses (26%) have all been shared by these 57% (excluding instances where this information was necessary for online purchases). About 80% of smartphone users and 43% of tablet users post mobile photos online. Surprisingly, another 24% admit to using their devices to send personal or intimate messages in the form of text, email, or photo messages. Yet, more than 1/3 of them (33% of smartphone users and 38% of tablet users) admit to having no password protection on their devices to safeguard these risqué conversations from reaching the public. Worse still, while nearly all (93%) say their laptops and desktops have updated security software, only 56% of smartphone users and 59% of tablet users say their devices are protected from viruses and malware.

To learn more about this study, please visit:
Blog: http://blogs.mcafee.com/consumer/50plus-tech-savvy-but-still-at-risk
Twitter: @McAfeeConsumer – Use #babyboomers to join the conversation

Wednesday, October 2, 2013

McAfee Security Innovation Alliance Welcomes new partners

Integrated Partner Ecosystem Offers Customers Leading Security Technology

FOCUS13, LAS VEGAS / SINGAPORE — Oct. 2, 2013 – McAfee today announced six new partners have joined the McAfee® Security Innovation Alliance (SIA). McAfee SIA is the security industry’s premier technology-partnering program, designed to deliver integrated solutions that maximize the value of existing customer investments.  Integrated solutions are also designed to improve visibility and dramatically reduce the time it takes to resolve problems, all while lowering overall operational costs.

The new partners that have joined the McAfee SIA program are:
Apperian
Cylance
Norse Corp.
nPulse Technologies
RouteWorks Services
Topia Technology

In addition, InfoReliance, Norse Corp., nPulse Technologies, PIOLINK, Trapezoid, White Cyber Knight (WCK), and Lieberman Software now have “McAfee Compatible” solutions and have been promoted to Technology Partner status in the McAfee SIA program. McAfee has worked with these partners to validate their integrations for their adherence to best practices for integrating with McAfee products.

McAfee has also welcomed Apperian, and Norse Corp. to its Sales Teaming Program. Partners in the Sales Teaming Program complement the McAfee product portfolio and enable the McAfee sales force and channel to provide more complete security solution relationships with enterprise customers.

“Organizations not only need visibility into all IT products connected to their infrastructure, but they need to know they’re integrated into the larger security infrastructure,” said Ed Barry, vice president of the McAfee Security Innovation Alliance. “Having a consolidated view can mean the difference between a successful attack and a secure organization.  McAfee, together with our SIA partners, provides protection and visibility to address threats together and bring the most innovative technologies to our joint customer base.”

McAfee FOCUS ‘13, McAfee’s annual security conference, runs from October 1-3 in Las Vegas, and is sponsored by more than 20 McAfee SIA partners that will showcase their solutions in the main exhibition hall. To further articulate the vision and value of SIA, on Wednesday, October 2, from 3:30 - 4:20 p.m. PT, McAfee SIA Partners FireMon, Hitachi ID, Securonix, and TITUS, along with representatives from McAfee Next Generation Firewall powered by Stonesoft will participate in a customer session hosted by SIA entitled, “Fighting Insider Threats with McAfee SIA.” In addition, numerous McAfee SIA Partners will present their integrated solutions with McAfee in other targeted security sessions at FOCUS’13.

To support the McAfee SIA partner ecosystem, McAfee is hosting its sixth annual McAfee SIA Developers Conference (DevCon) on October 1 in conjunction with McAfee FOCUS ‘13. The McAfee SIA Developer Conference is an opportunity for McAfee SIA partners to meet with McAfee technology experts to further align their solution integrations.  At McAfee SIA DevCon McAfee presented the annual McAfee SIA Partner of the Year Awards. The winners are:

Most Valuable Partner of the Year – Forescout
Most Innovative Partner of the Year – Avecto
Rookie of the Year – Core Security

For more information about how partners announced in this release are working with McAfee, please visit: http://www.mcafee.com/apps/partners/partnerlisting.aspx?region=hk.


Thursday, August 29, 2013

MCAFEE DATA CENTER SUITE PROVIDES ELASTIC SECURITY FOR HYBRID DATA CENTERS

McAfee Data Center Server Security Suite Discovers all Workloads, Protects Servers, and Securely Enables the Cloud  

VMworld, SAN FRANCISCO / SINGAPORE, —Aug. 27, 2013 – McAfee today announced a new version of its data center security solution that addresses enterprises’ growing need to leverage the scalability and cost savings of running workloads in public clouds like Amazon Web Services. When enterprises move workloads to a public cloud, they want to know their data is protected.

The McAfee Data Center Server Security Suite for Server provides complete visibility to all workloads in hybrid data centers so enterprises can securely expand into any cloud environment. This added flexibility gives organizations elastic security that is auto-deployed when new virtual devices are provisioned either on-premise or in the public cloud.

The new McAfee Data Center Security Suite for Server allows organizations to:
Discover all workloads including those from VMware’s vCenter and Amazon Web Services to provide the security administrator with complete visibility of the security status.

Protect every physical and virtual machine in the hybrid data center with fine-grained policy management and data center trust attestation with ease-of-use manageability with McAfee ePolicy Orchestrator.
Expand compute capacity securely into the private and public cloud and ensure identical security posture between on-premise and cloud-based machines.
McAfee Data Center security optimizes security, flexibility and manageability of virtual environments with its MOVE AV functionality, finally providing a simplified security solution for companies investing in virtualization for data centers, applications and desktops.

“The McAfee MOVE AntiVirus solution has provided us with an excellent resolution for our complex IT infrastructure which contains dozens of assorted operating systems in use,” said Rick Snyder, Endpoint Security Manager at Boston Scientific. “Our organization handles sensitive data from customers, vendors, business partners and our own internal activities. Maximizing performance, while continuing protection across multiple internal entities, is a high priority for our IT department, as is providing reporting on its effectiveness.

McAfee MOVE has been integral in achieving these simultaneous goals by giving us the ability to offload all scanning of data into a gateway virtual appliance. This streamlined and efficient approach saves resources and maintains our security posture.”

Customers now have complete visibility to all workloads on-premise and in the cloud, which then enables them to secure all important workloads. With the ability to expand their compute resources into the public cloud while also securing these workloads, customers can now maintain their security posture even in the public cloud.

“Enterprises must stay compliant and meet government regulations and that is a typical barrier for organizations who want to move workloads into the cloud,” said Rishi Bhargava, vice president of data center security at McAfee. “With McAfee’s latest Data Center Server Security Suite and its elastic security, enterprises are now empowered to do just that. McAfee provides comprehensive security from servers to networking to storage.”

To see a demo of the new McAfee Data Center Security Suite for Server and other solutions such as McAfee Network Security Platform now integrated with VMware NSX™ network virtualization platform, stop by McAfee #635 at VMworld, August 25-29.

Tuesday, July 30, 2013

MCAFEE ONLINE SAFETY PROGRAM REACHES MORE THAN 100,000 YOUTH, PARENTS AND TEACHERS GLOBALLY

McAfee teaches Online Safety for Kids to over 15,000 children in South East Asia

SINGAPORE – July 26, 2013—McAfee today announced that it has reached more than 100,000 youth, parents and teachers around the globe with its cyber education program. The McAfee Cares - Online Safety for Kids Program is a free school initiative that utilizes McAfee employees, partners and customers who volunteer to train school-age children and parents on ways to stay safe and secure, as well as maintain good ethics in their online behavior.

According to the 2013 McAfee Digital Deception study, “Exploring the Online Disconnect between Parents and Kids,” about 25 percent of youth spend five to six hours a day online. Eighty-six percent of youth believe that social media sites are safe and are aware that sharing personal details online carry risk, yet they continue to post personal information such as their email addresses and social security numbers.

 “We have a responsibility to equip the next generation of computer users with the skills they need to safely experience all the benefits of the Internet,” said Michelle Dennedy, chief privacy officer, McAfee. “And just as important is making sure they understand how to be responsible cyber citizens. We teach skills needed to navigate the digital world, including how to safeguard against cybercriminals, hackers and cyber bullies.”

On May 16, McAfee hosted its second annual McAfee Global Community Service Day to continue the effort of helping hundreds of non-profits around the world. As part of this day of service, McAfee volunteers taught cyber education to approximately 25,000 kids, parents and teachers around the world.  As one example, California Lieutenant Governor Gavin Newsom, and Michael DeCesare, McAfee president, paired up and shared the stage at Monte Vista High School in Danville, Calif. to educate students about responsible online behavior.
     
Children and McAfee staff in Singapore engaged in playful ways of learning about cyber eduction

In South East Asia, the McAfee Online Safety for Kids program has been running for over a year in local schools across Malaysia, Singapore and Malaysia, and has already reached over 15, 000 children to date. The National Infocomm Security Competition (NISEC) in Singapore, surveying both adults and students about cyber security and online habits, conducted a recent study, finding that 37% of the respondents still feel uncomfortable to share files and conduct transactions online, showing that the participants are aware of the dangers on the internet, and that they might be susceptible to attacks. Survey participants also rated scam and fraud, as well as stolen personal information, as the two biggest online threats.

“While we were able to reach out to a wide number of children through McAfee’s Online Safety for Kids program, there is still more to be done to ensure that the next generation is well aware of the dangers that the internet holds. As the global leader in cyber security it is our duty to share our knowledge and expertise with the communities around use,” said Wahab Yusoff, Vice President of South Asia, McAfee.

The McAfee Online Safety for Kids program is recognized by IDG’s Computerworld Honors Program as a 2013 Laureate. The annual award program honors visionary applications of information technology promoting positive social, economic and educational change. Founded by International Data Group (IDG) in 1988, The Computerworld Honors Program is governed by the not-for-profit Computerworld Information Technology Awards Foundation.

To learn more about the McAfee Online Safety for Kids program, or if you are an educator and would like to schedule a school or youth group visit, contact: Cybereducation@McAfee.com.


Thursday, May 30, 2013

MCAFEE TRANSFORMS ENDPOINT SECURITY MARKET WITH INDUSTRY’S FIRST CHIP-TO-APPLICATION COVERAGE

McAfee Complete Endpoint Protection Suites Uniquely Deliver Hardware-Enhanced Security and Real-Time Security Management

SANTA CLARA, Calif. / SINGAPORE — May 30, 2013 – McAfee introduced two new suites:  McAfee Complete Endpoint Protection – Enterprise, and McAfee Complete Endpoint Protection – Business.  These suites are the first to link security from chip to OS to applications, protecting against new threat vectors and bringing critical visibility to risk management. The suites are the first to include McAfee Deep Defender, a rootkit protection based on hardware-enhanced security jointly developed by Intel and McAfee, dynamic whitelisting, risk intelligence, and real-time security management. By including mobile device management and support for Macs and Linux, McAfee suites help businesses of all sizes protect devices, data and applications.

Security staff will benefit by the extended span of coverage managed within a single console. IT administrators can see efficient installation in minutes, not hours, to ease deployment. End users benefit from higher performance scanning that minimizes the potential overhead of effective protection. Competitive pricing meets the needs of budget-minded buyers while delivering significant value for customers with mission-critical security needs. Finally, new incentives and affordable pricing engage the channel to help businesses with different budgets to adopt these unique products for protection and performance.

New Threats Demand a New Standard of Protection
Modern threats start with an ever-increasing stream of phishing, malicious web pages, rootkits, and compromised devices. These initial contacts can turn into persistent, multi-stage, targeted attacks. The explosion of devices multiplies the chance of an attack affecting the mobile workforce, who can unknowingly endanger the business and systems when reconnecting to the corporate network. McAfee tackles these obstacles with its Complete Endpoint Protection suites that target every phase of stealthy malware and persistent attacks.

Tested and Proven
Dynamic and distributed organizations, especially those with stringent requirements to safeguard data as well as verify and report on regulatory compliance, can rest assured since the new McAfee Complete Endpoint Protection suites include some of the most highly-ranked security technology in the industry. In comparative testing done by AV-Test, McAfee software scored 100% in rootkit protection with McAfee Deep Defender. In the 2013 Corporate Endpoint Protection Group Test by NSS Labs, McAfee software received the highest score in defending against exploit and evasion attacks. Also, in a study conducted by West Coast Labs, McAfee software scored 100% in malware protection with the combination of McAfee Application Control, McAfee VirusScan® Enterprise, and McAfee Host Intrusion Prevention, three of the central products in the McAfee Complete Endpoint Protection—Enterprise suites.

Below are just a few of the many capabilities offered by products included in the McAfee Complete Endpoint Protection suites:

Real Time for McAfee ePO—uses a specialized design and best practice questions and actions within the workflow to help every administrator understand their security posture up to 1,000 times faster than any other means, and take action easily and immediately to manage potential risks.
McAfee® Enterprise Mobility Management (McAfee EMM)—mobile device management and mobile data security are fully integrated with the McAfee® ePolicy Orchestrator® (McAfee ePO) platform environment.  With ePO, customers can use a single pane of glass and policy environment to manage all endpoints, including the suites’ multi-platform package of smartphones, tablets, Macs, Windows, and Linux.  To read the full EMM press release, also announced today, click here.
McAfee Deep Defender—endpoints are protected from stealthy attacks through jointly developed Intel and McAfee hardware-enhanced security that goes beyond the operating system, protecting where traditional security tools can’t reach.
McAfee Application Control for PCs—dynamic whitelisting for laptops and desktops reduces the chance of infection or disruption by containing the applications a user can run, including preventing malware from executing. The technology has been shown by West Coast Labs to offer 100% protection rates with very low system overhead.
McAfee Risk Advisor—helps administrators instantly see which assets are at highest risk so they can protect the most essential assets first and accurately.

“A few years ago, McAfee created the first security suites.  We remain a market leader in what is estimated by IDC to be a $2B market in 20131. That’s more than half of all endpoint security sales,” said Candace Worley, senior vice president and general manager of endpoint security at McAfee. “Now, through performance and automation enhancements to our existing market-leading defenses and integration of distinctive and compelling new protections, McAfee suites again define a new level of endpoint protection—one that is firing on all cylinders: speed, security, simplicity, and value.”

McAfee Complete Endpoint Protection suites incorporate ePolicy Orchestrator software, the world’s leading security management system, a central part of McAfee’s Security Connected management platform. This management system has been enhanced with Real Time for McAfee ePO software, which allows administrators to directly and instantly understand and manage endpoint health across all devices to keep critical assets and data secured and available.

“With the McAfee ePO platform we receive heartbeat status in real time, while gaining visibility into important background information so that we can conduct comprehensive statistical analysis and reporting,” said Rick Snyder, Endpoint Security Supervisor at Boston Scientific. “As a medical device company dedicated to less-invasive medicine, we see the McAfee ePO platform as the most effective solution for managing our entire environment from a single point.”

McAfee’s endpoint security provides complete protection technology for all devices, the data that runs through them, and the applications that run on them. Our comprehensive, tailored solutions reduce complexity to achieve multi-layer endpoint defense that won’t impact productivity and blends traditional smart malware scanning, dynamic whitelisting, behavioral day-zero intrusion prevention, unified management and integrated threat intelligence. McAfee uniquely provides a comprehensive approach to devices, protection technology and management.

Availability
For more information on the McAfee Complete Endpoint Protection - Enterprise Suite and the McAfee Complete Endpoint Protection - Business Suite visit: http://www.mcafee.com/endpoint.

1IDC, "Worldwide Endpoint Security 2012–2016 Forecast and 2011 Vendor Shares," doc #235930, July 2012


Friday, April 26, 2013

MCAFEE DELIVERS ENTERPRISE CLASS SECURITY TO THE CLOUD


McAfee Identity and Access Management Solutions Enable IT to Regain Control of Cloud Applications

SINGAPORE — April 26, 2013 – McAfee today announced the addition of identity and access management solutions to its Security Connected portfolio. The new solutions that were previously sold and developed by Intel, include McAfee Cloud Single Sign On and McAfee One Time Password.  McAfee also introduced a new McAfee Identity Center of Expertise, staffed with experts in identity and cloud security to assist users with questions pertaining to identity and access management issues, such as architecture requirements and best practices.

Organizations of all sizes are moving IT operations and functions to the cloud in order to reduce costs.  As businesses embrace cloud-based applications they quickly find their IT department and application administrators are overwhelmed with the problem of managing cloud-based application accounts.  Many organizations are trying to use legacy identity and authentication solutions which can create security gaps and are often complicated to deploy and customize for new applications.

To address this problem, the new McAfee identity and access management solutions enable simple, safe, secure and compliant access to critical business information, including cloud-based applications, while maintaining agile business practices. McAfee Identity and Access Management solutions include:

McAfee One Time Password – scalable multi-factor authentication solution which delivers a one-time password (OTP) to any mobile device or PC.
McAfee Cloud Single Sign On – delivers single sign-on (SSO) for hundreds of cloud-based applications. McAfee Cloud Single Sign On is available in two form factors:
o On-Premise Edition – application platform which can be deployed on any compatible Windows or Linux server platform, or virtual machine.
o SaaS Edition – cloud-based version available as a service hosted and supported by McAfee.
Customers have the flexibility to purchase McAfee Cloud Single Sign On licenses and apply them to either the On-Premise Edition or SaaS Edition, or in a mixed hybrid configuration.

“There is a huge shift underway to extend enterprise-class security to cloud-based applications and services while also consolidating security onto just a few key platforms,” said Pat Calhoun, senior vice president and general manager of Network Security at McAfee.

“McAfee is not trying to ‘boil the ocean,’ instead we are focusing on several identity-related ‘hot spots’ and investing to help our customers and partners solve critical challenges and maintain business continuity and agility.”

McAfee Cloud Single Sign On includes hundreds of pre-configured Cloud Identity connectors, automated account provisioning and de-provisioning, integration with key enterprise identity repositories, built-in multi-factor authentication based on the McAfee One Time Password product, a management console with monitoring, audit and reporting tools, as well as maintenance, upgrades and 24x7 support, all for one cost-effective subscription price.

 “McAfee has been excellent to work with,” said Kamal Elharam, director of Information Systems and Technology at Senior Service America Incorporated.  “The McAfee Cloud Single Sign On product met all of our needs and it helped us, as well as our system integrator, to implement the best solution to support our business goals.  Other vendors weren’t as eager to adjust to our environment and expected us to do business differently to allow us to use their tools.”  

McAfee One Time Password has a flexible architecture which enables customers to achieve the benefits of multi-factor authentication without the overhead expense and management headaches of legacy hardware tokens. Customers can choose to deliver multi-factor authentication via a smart phone, mobile phone (via SMS text message), a PC client application, email, instant message/chat, or a third-party token.

McAfee and its solution providers deliver integrated identity management and Web protection solutions that simplify and secure access to cloud applications while protecting against advanced malware and other hidden threats. From single-sign-on, strong authentication and granular application control to web filtering, deep content inspection and advanced malware protection, McAfee provides the industry’s most comprehensive Web security solution.

Availability
For more information on McAfee Cloud Single Sign on and McAfee One Time Password visit; www.mcafee.com/Identity.