SCCyberworld

Showing posts with label Trend Micro. Show all posts
Showing posts with label Trend Micro. Show all posts

Wednesday, May 14, 2014

Trend Micro Codinsanity Calls Upon Programming Talents to Solve Big Data Challenges

Adrenaline-pumping Asia Pacific student hackathon now to include software professionals

Kuala Lumpur, 14 May 2014 – Global leader in cloud security, Trend Micro Incorporated (TYO: 4704; TSE:4704), continues to fuel creativity and cultivate young programming talents through its annual programming contest, the Trend Micro Codinsanity 2014 Asia Pacific Programming Contest.  For the first time in 15 years, the contest is now open to both working professionals and students across twelve markets in Asia-Pacific including Malaysia.

Trend Micro Codinsanity 2014 Asia Pacific Programming Contest builds on top of last year’s contest and challenges talent to creatively solve algorithmic challenges in big data. Today’s mobile, social, and collaborative lifestyles have transformed the way people use technology at home, at work, and everywhere in between. With the rise of big data, the challenge to secure devices, personal information, and business data has become even more complex.

Whether it is optimizing existing algorithms or formulating new algorithms, Trend Micro Codinsanity  2014 Asia Pacific Programming Contest provides the ideal test bed for contestants to think big, push boundaries and explore alternative solutions to better link data sets, refine recommendation engines or add intelligence to existing processes. The contest provides a platform to showcase innovative applications with market potential and positive social impact.

“Today, we are living in the cloud era and a data-driven world, which is reshaping the way enterprises, government agencies and individuals operate. As a company, we are approaching security with a data-centric framework. Our annual programming contest brings together like-minded individuals with the same passion to solve real-world problems in big data which will form the basis of innovation, productivity and competition,” said Goh Chee Hoh, Managing Director for Malaysia, Singapore and Indonesia, Trend Micro Inc. “By working with students and working professionals, we gain unique perspectives and new ideas that can help us approach and tackle challenges differently. We are excited about the outcomes of this year’s contest and we welcome students and software programming talents to take part in the contest.”
To help contestants prepare for Trend Micro Codinsanity 2014 Asia Pacific Programming Contest, the company is offering optional coaching services to participating teams from the time of registration to the finals. All coaches are Trend Micro experts based out China, Japan, Taiwan and the Philippines.

The winning team of Trend Micro Codinsanity 2014 Asia Pacific Programming Contest will not only receive a cash prize of USD 20,000, but will also undergo an exclusive two-month student internship program with the company. The first runner-up, second runner-up and finalist teams will receive USD 10,000, USD 6,000 and USD 2,000 respectively.

Sharing his views on the annual programming contest, Goh added: “At Trend Micro, we are committed to fostering and grooming the next generation of software programming talents. These young talents are the linchpins of our industry and will help drive innovation, continue Trend Micro’s legacy as the threat defense and cloud security expert, and achieve our vision of making the world a safe enough place to exchange digital information.”

The format of this year’s contest comprises two stages, beginning with an online test and ending with an onsite final held in Taiwan. The programming languages for the contest are C/C++ and Java. Participating teams will be scored against three key criteria – accuracy, performance and speed – for the online test and the ten highest-scoring teams will embark on an all-expense paid trip to Taiwan where they will pit against one another in the finals. The judging criteria for the onsite final include creativity, completeness of solution, technicality and presentation.

Registration for Trend Micro Codinsanity 2014 Asia Pacific Programming Contest is now open for undergraduates and young professionals in China, Hong Kong, India, Indonesia, Japan, Malaysia, Philippines, Singapore, South Korea, Taiwan, Thailand, and Vietnam. For more information about the contest, visit http://contest.trendmicro.com/2014/

Trend Micro Codinsanity 程式竞赛开跑 
挑战大数据资料解决能力

欢迎学生及各路软件高手前来挑战紧张刺激的亚太区程式设计马拉松赛

吉隆坡,2014年5月14日讯 –全球云端安全领导厂商Trend Micro(TYO: 4704;TSE:4704,对推动软件设计创意工作不遗余力,并将透过其一年一度举行的Trend Micro Codinsanity 2014年亚太区程式竞赛,栽培年轻的软件编程人才。这是该公司15年来,首度将赛事规模扩大至亚太区12个国家,包括马来西亚,今年更开放予在职专业人士及学生参加!

Trend Micro Codinsanity 2014年亚太区程式竞赛,将以去年的竞赛作为基础,挑战参赛者解决巨量资料问题的创意。有鉴于现今的移动装置、社交媒体及结合此两者的生活方式,已彻底改变了人们在居家、工作及生活场所中对于科技的应用方式。再加上巨量资料的兴起,如何确保移动装置、个人资料及商业数据的安全性,已经成为越来越复杂的挑战。

不论是针对现有的演算法加以强化,或是开发新的演算法,Trend Micro Codinsanity  2014年亚太区程式竞赛提供了理想的试验平台,让参赛者大胆地想像、挑战极限,以及探索新的解决方案以提升资料关联性,优化推荐引擎或是智能化现有的流程。这项竞赛也提供一个平台,用于展现具市场潜力和有利于社会的创新应用程式。

“今日,我们正生活在一个云端应用及资料驱动的时代,企业、政府机构的运作与人们的生活方式都已转型。身为全球云端资讯安全领导企业,我们一直以安全的资讯中心为架构。我们每年举办程式竞赛,让各国兴趣相投,技术高超的人才齐聚一堂,一同解决真实世界的巨量资料问题,这也将是科技与软件产业未来创新力、生产力和竞争力的基石,” Trend Micro公司的马来西亚、新加坡及印尼的董事经理吳志豪如此表示。“透过与学生及在职专业人士的合作,我们获得了独特的视角和新的想法,帮助我们接触及应对不同的挑战。我们对今年的竞赛结果充满期待,欢迎学生及软件程式设计人才参加这项竞赛。”

为了帮助参赛者作好参加Trend Micro Codinsanity 2014年亚太区程式竞赛的准备,从报名参加竞赛到决赛阶段,该公司将从为参赛队伍提供选择性的导师服务。所有导师是由中国、日本、台湾及菲律宾的Trend Micro专家担任。

Trend Micro Codinsanity 2014年亚太区程式竞赛的优胜队伍不仅可赢得2万美元的奖金,也将获得提供两个月学生实习计划的独特机会。亚军、季军及进入决赛的队伍也将分別获得1万美元、6千美元和2千美元的奖金。

在分享他对这项年度程式竞赛的看法时,吳志豪 补充说:“在Trend Micro,我们鼓励并栽培更多新一代的软件程式设计人才。这些年轻才俊是我们这个行业的支柱,它将有助推动创造力,延续Trend Micro作为威胁防御和云端资讯安全专家的遗产,以及实现我们致力打造数字信息交换环境安全的愿景。”

今年的比赛形式分成两个阶段,第一阶段将采线上竞赛,第二阶段则是在台湾举办的现场总决赛。竞赛的程式设计语言是 C/C++ 及 Java。线上竞赛将依三项主要条件来评分:正确性、效能及解题速度,分数最高的前10名队伍将获得全程支付费用,前往台湾参加总决赛。总决赛的评判标准包括:创意、解决方案完整性、技术能力及简报表现。

Trend Micro Codinsanity 2014 年亚太区程式竞赛即日起开始接受报名,凡是中国、香港、印度、印尼、日本、马来西亚、菲律宾、新加坡、南朝鲜、台湾、泰国及越南的大专院校学生及年轻专业人士,皆欢迎报名参加。有关比赛详情,请浏览 http://contest.trendmicro.com/2014/

Monday, May 5, 2014

What’s Your Story?

“YOLO” Wins Trend Micro Malaysia’s Internet Safety Video Competition

Kuala Lumpur, 5 May 2014 – The regional “What’s Your Story” competition came to a conclusion with the winners’ announcement today. “What’s Your Story” is a video competition organized by Trend Micro as an alternative platform to highlight Internet safety issues amongst the younger generation, utilizing videos as the main mode of communication.

This year the video competition garnered more than 100 entries from Malaysia, Philippines, Singapore, and Taiwan and received over 36,000 views. The panel of judges included Trend Micro partners, Yahoo!, and Microsoft. The regional winners emerged from Taiwan and Philippines with their winning videos, one provocatively entitled “Take your clothes off!” and “The Story of my (Online) Life” respectively. Trend Micro Malaysia also congratulated the two local winners today whose simple videos summed up the importance of thinking twice before you post up personal data online.

(L to R) Siti Haidah Harun and Junaidy Ismail, parents of Muhammad Afiq B. Junaidy, Grand Prize winner for Malaysia, Marissa Lim, Runner-up for Malaysia, and Jean Lim, Director, Channel Management and Marketing, Trend Micro Malaysia.

The local winning entry entitled “YOLO” emerged as the most well liked video on Trend Micro Malaysia’s Facebook page that encapsulated this year’s competition theme. Muhammad Afiq B. Junaidy, age 21 is the brain behind “YOLO” and currently studies in the U.S as a Chemical Engineer. He took home the Grand Prize of a RM5,000 cash prize. Marissa Lim, age 20, an Advertising and Graphic design student came up with “5 Online Don’ts” that highlighted the dangers of revealing sensitive personal data online and she walked away with a cash prize of RM3,000.

Participants were required to submit their videos that were judged on three main criteria; creativity, relevancy and content that showcases this year’s theme “How to Keep a Good Reputation online and What Are the Consequences of Not Doing So?” in the most interesting way.
(L to R) Siti Haidah Harun and Junaidy Ismail accepting the Grand Prize on behalf of their son, Muhammad Afiq Junaidy from Jean Lim, Director, Channel Management and Marketing, Trend Micro Malaysia.

“Internet security is increasingly important in the digital era that we live in today, particularly for the youth who spends a large portion of their time online. Amongst the long list of Internet security issues are unsuitable content such as pornographic or violent materials being exposed to young children, cyber bullying or harassment, privacy concerns and reputation management that needs to be addressed,” said Jean Lim, Director, Channel Management and Marketing, Trend Micro Malaysia.

 “Trend Micro is always looking for ways to raise awareness about the importance of staying safe in the digital sphere. The mission of Trend Micro Internet Safety for Kids & Families is to enable and empower kids, parents, teachers, and schools around the world to make the Internet a safe and secure place for today's youth. The “What’s Your Story” video competition is a great way to encourage conversations amongst them about the dangers that lurk online, how to safeguard yourself and still be able to get the most out of the Internet,” continued Jean.
(L to R) Marissa Lim, Runner-up for Malaysia, and Jean Lim, Director, Channel Management and Marketing, Trend Micro Malaysia.

“I felt that Trend Micro’s “What’s Your Story” video competition was a cool way to highlight Internet security issues, rather than just reading a boring wordy article. My video submission was inspired by real stories that I hear far too often about the accidental sharing of private photos that causes emotional distress and affects the victim’s reputation as well. I hope that more people will take note and realize the importance of keeping certain information private and protected so these details does not fall in the hands of the wrong people,” said Muhammad Afiq B. Junaidy, the Grand Prize winner.

For more information about Trend Micro’s “What’s Your Story” video competition or to watch the video entries, please go to http://whatsyourstory.trendmicro.com.my/.

Friday, April 18, 2014

Trend Micro Offers Free Heartbleed Scanners for Computer and Mobile Users

Enables Internet users to determine if websites and Android apps are vulnerable to OpenSSL bug

Kuala Lumpur, 18 April 2014 – To help Internet users protect themselves from the Heartbleed bug that is eroding SSL security features on websites worldwide, Trend Micro Inc. (TYO: 4704; TSE: 4704) today announced the release of two free Heartbleed scanners for computers and mobile devices designed to verify whether they are communicating with servers that have been compromised by the Heartbleed bug.

The solutions, Trend Micro™ Heartbleed Detector, a Chrome browser plug-in, and an Android mobile app, are accessible in the Chrome Web Store and Google Play app store, respectively.

Available for Mac and Windows-based computer users, the Trend Micro Heartbleed Detector is a multi-platform plug-in for Chrome that enables users to check for vulnerable URLs and installs with a single click. Trend Micro researchers have also discovered that mobile apps are just as vulnerable to the Heartbleed bug as websites are. To mitigate this threat, Trend Micro has developed the Heartbleed Detector to check apps on a user’s device and the servers they communicate with, to determine if installed apps are vulnerable to the OpenSSL bug. If vulnerable apps are, the detector then prompts the user with the option to uninstall the app.

“Trend Micro has responded to the Heartbleed threat by offering tools to all Internet users as a solution to protect their personal data,” said Goh Chee Hoh, Managing Director for Malaysia, Singapore and Indonesia, Trend Micro Inc. “With in-app purchases and financial transactions on mobile devices becoming the norm, Trend Micro felt it was vital to offer users a solution designed to enable them to continue operating their devices without worry. Heartbleed is a problem that may never entirely go away, but we are committed to providing and updating our solutions to best protect the data of our customers, and provide essential security on each device they use.”

Effective today, users can download Trend Micro’s Heartbleed Scanners for their computers and mobile devices by visiting https://chrome.google.com/webstore/detail/trend-micro-openssl-heart/cmibjcgebllecchcmkiafonmflkeeffo or the mobile link.


Friday, April 11, 2014

Don’t Have Heartburn Over the Heartbleed Vulnerability

The Heartbeat bug has been in the epicentre of the Internet security storm recently and termed the worst security vulnerability to date. Trend Micro Inc. (TYO: 4704;TSE: 4704), the global leading internet security vendor, has moved swiftly to immediately assessed our products and services for the vulnerability and if appropriate, has taken appropriate action to address the issue.  Trend Micro has also provided some answers to a simple FAQ below to address the confusion and concerns of organizations and consumers.

What is the Heartbleed bug?

The Heartbleed bug is a problem that affects SSL, the technology that helps protect your information on the Internet. You’re likely most familiar with SSL when you shop online or enter sensitive information on a site and see the “lock” that tells you your information is protected.

What does this mean?

This means that information that you thought was being protected by SSL may not be as safe as anyone thought. Sensitive information like passwords, credit card information, or other personal information could have been exposed to others without your knowing.

What should ORGANISATIONS do?

Countless organisations have spent the last few days testing and patching their systems in response to the Heartbleed bug. Much like the current issue, it is inevitable that new vulnerabilities will be found in the future and the following are steps that organisations can implement to ensure faster detection and remedial action:

·         Continuous vulnerability scanning: The first step in remediating a bug like Heartbleed is to detect it. Organisations should be continuously testing their deployed web applications for the latest vulnerabilities. Security solutions like Trend Micro for Web Apps provides continuous application scanning along with security expert testing to ensure the time to detect vulnerabilities is minimized.

·         Immediate SSL certificate reissue: In response to Heartbleed, many organisations are now faced with reissuing their SSL certificates with new keys which is a time consuming process. Organizations can explore security solutions such as the Trend Micro Deep Security for Web Apps that will allow organisations to easily rekey their SSL certificates and issue the new key in a matter of minutes. This  helps to minimise the time critical systems are exposed to vulnerability.

·         Instant virtual patching: Upgrading libraries like OpenSSL needs to be done with care to ensure other functionality is not impacted – usually through regression testing. This takes time, which prolongs exposure to vulnerability. Solutions like the Trend Micro Deep Security provides advanced intrusion detection and prevention, which allows virtual patching. This allows attacks exploiting vulnerabilities to be immediately blocked without requiring update to server configuration.

What can CONSUMERS do?

·         How do I fix this?

You don’t. In this case, this isn’t a problem with your computer or devices. It’s a problem that websites have to take care of by fixing SSL on their site.

·         Can I tell if a site has this problem?

Unfortunately, not really. This is something that only the people running the site can know for sure.

·         Is there anything I can do to protect myself?

While you can’t protect yourself from this specific issue, you can take some steps to protect yourself from effects that this issue might have. Specifically, you can do the following:

o    Make sure you’re running up-to-date security software on all your systems.

o    Watch for suspicious activity of any kind. On your online accounts and your financial accounts.

o    Change passwords promptly for sites that recommend you do so.

·         Is there anything else that I should know about this?

This is a new situation and there’s always a lot of confusion and conflicting information in these situations. The important thing is to not panic, follow the steps that we’ve outlined, let the people who can fix this do so, and follow any additional instructions they give.

For the latest updates on the Heartbleed bug and any other security issues, kindly follow the Trend Micro TrendLabs Security Intelligence Blog at http://blog.trendmicro.com/trendlabs-security-intelligence/.

Friday, February 28, 2014

Trend Micro Appoints Dhanya Thakkar as New Managing Director of Southeast Asia and India

Kuala Lumpur, 28 February 2014 – Trend Micro (TYO: 4704; TSE:4704) has announced the appointment of Dhanya Thakkar as Managing Director of Southeast Asia and India. In his newly expanded role, Thakkar will spearhead Trend Micro’s enterprise and consumer product segments in the region, helping deliver on the company’s vision of making the world safe for businesses and consumers to exchange digital information.

Commenting on Thakkar’s appointment, Wael Mohamed, Executive Vice President, Trend Micro, said: “Dhanya’s proven leadership qualities, track record, and extensive experience in Internet security makes him the ideal candidate to spearhead our business in this region. We are confident that our employees, customers and partners will benefit vastly from his leadership.”

“I am delighted and humbled to be offered the opportunity to lead Trend Micro’s business in one of the most diverse and fast-changing regions in the world,” said Dhanya Thakkar, Managing Director, Southeast Asia and India, Trend Micro. “As mobile population and Internet penetration rate continue to grow in Southeast Asia and India, we are committed to safeguarding our stakeholders against evolving cyber threats that may occur on the cloud, the Internet and mobile devices.”

Thakkar was most recently the Managing Director for India and SAARC at Trend Micro, where he joined Trend Micro through the acquisition of IndusGuard, a company he co-founded and served as President.

With a knack for entrepreneurship and a strong blend of business acumen and technology expertise, Thakkar is well-regarded as a thought leader and recognized for having led successful business transformation for public-listed multi-national companies and start-ups. He is also the co-inventor of two patented technologies.

Prior to starting up IndusGuard, Thakkar was the Vice President of the Business Development and Security Center for Third Brigade, where he managed strategy and operations as well as engineered the acquisition of Third Brigade by Trend Micro. Thakkar also held various leadership positions at Entrust from 1995 through 2005.

Thakkar completed the Queen’s Graduate School of Business Executive Program from Queen’s University and holds a Bachelor’s degree in Computer Science from Maharaja Sayajirao University in India.

Friday, December 27, 2013

Trend Micro Discovers Bitcoin-mining Malwares is Rising in APAC Region

Japan and Australia are the most affected and Bitcoin users are advised to be wary of the possibility of personal information leak

Kuala Lumpur, 26 December 2013 - Bitcoin has become a well discussed topic during the past few weeks, especially when people find this virtual currency is tradable and as valuable as real currency. Because of this, Bitcoin has gained much attention and interest of hackers and cybercriminals. Trend Micro Inc. (TYO: 4704;TSE: 4704), the global leading internet security vendor has observed the spreading of Bitcoin-mining malwares recently and most of the affected countries are from the APAC region. Trend Micro reminds Bitcoin owners the importance of keeping their wallets safe from theft by separating their Bitcoin wallets and to manage the Bitcoin account offline which will diminish potential cyber threats.

“Bitcoin users have become the hot target for cybercriminals as Bitcoin transaction is permanent and has no reversal of charges. If you are the victim of credit card fraud, you can appeal to your bank to reverse the transaction and in many cases, they will.  On the other hand, once your Bitcoin wallet is compromised by hackers there is no recourse to undo the transaction. In fact, there is no regulator or authority that Bitcoin users can appeal to if they fall victim to theft or fraud” said Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc.

Trend Micro Smart Protection Network has detected 3 malwares called BKDR_BTMINE, TROJ_COINMINE and HKTL_BITCOINMINE which turns infected systems into Bitcoin miner, making them virtual assets for the criminals. There are more than 12,000 PCs globally affected by Bitcoin-mining malwares which are causing severe slowdown of PC systems.

Trend Micro found that four out of the six countries with the highest number of Bitcoin-mining malwares infected computers are from the APAC region, with Japan being the top followed by Australia, India and Taiwan at the 3rd, 4th and 6th position respectively.

Executing malwares into the victims’ computer to mine Bitcoin is a new type of cybercrime. Bitcoin mining, the process which creates new Bitcoin created, is resource-intensive hence Bitcoin-mining malwares can slow down the infected computer due to the increased CPU load and subsequently raise power consumption.

To protect themselves from cyber threats, Trend Micro advises Bitcoin users to understand the way Bitcoin is being transacted and to manage it with the same caution and prudence that applies to real currency. Besides using security software to filter malwares, Trend Micro also suggests Bitcoin users not to put all Bitcoin in a single wallet. They should divide their Bitcoin into income account for inbound transaction, and expense account for outbound transactions. For additional precaution, they should also consider managing all the wallets offline. Trend Micro also reminds Bitcoin users that although Bitcoin is claimed to be “anonymous”, the transaction records are still in public and it leave traces. Consequently, given enough circumstantial evidence, criminals can identify and obtain the owners’ personal information.

For more information on Bitcoin threats and other security updates, please kindly follow Trend Micro Trendlabs Security Intelligence blog at http://blog.trendmicro.com/trendlabs-security-intelligence/bitcoin-price-hike-spurs-malware-wallet-theft/.

Tuesday, November 12, 2013

Trend Micro: Singapore Prime Minister Office Website Intact and Not Hacked

Recommendations to reduce security risks for organizations

Kuala Lumpur, 12 November 2013 – A global leader in security software, Trend Micro Incorporated (TYO: 4704; TSE:4704), shares that the recently compromised Singapore Prime Minister Office (PMO)’s website remains to be intact, with visits unaffected. Through analysis by its threat experts, Trend Micro found that the attack was not a result of a hacking attack, but an exploitation of vulnerability within the website.

Understanding how the vulnerability came about
Based on Trend Micro’s analysis, the Singapore PMO’s website incident was a result of a typical Cross Site Scripting (XSS) where the cybercriminal exploited the ‘search’ function on the website, and injected content from external sources. In this particular instance, the cybercriminal had redirected the URL to the criminal’s intended image.

Through Trend Micro™ Smart Protection Network™, it was found that the exploited URL was broadcasted across various social networking sites including Twitter, Facebook and more, implying that the Singapore PMO website has been defaced.

With the exploited link referencing to Singapore PMO website’s official URL (www.pmo.gov.sg), when clicked on, unsuspecting visitors and consumers were tricked into thinking that the exploited link was a real defaced Singapore PMO website. With the cybercriminal’s choice of image, visitors and consumers were led to believing the compromise was by global hacker group, Anonymous Collective.

Over the past couple of weeks, online assets of several government organizations in Singapore have been compromised by cyber criminals causing service disruptions and more. Trend Micro advises organizations to conduct regular checks on the robustness of their IT infrastructure against exploitations of possible loopholes.

Recommendations to prevent future loophole exploitations
Trend Micro recommends organizations the following steps to check the health of their online assets, to better protect themselves against exploitations of vulnerabilities:

1. Scan for web application vulnerabilities.
2. Review HTML codes to ensure that search functions are not compromised, including setting up limitations in input content to reject special characters, sanitizing output through HTML-encoding of user input or strings.
3. To ensure complete safety in the short run, disable website search functions.

Monday, October 28, 2013

Trend Micro: Response for Budget 2014

Mr. Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc. 

Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cloud security leader, applauds the government on the announcement of the Budget 2014 themed Strengthening Economic Resilience, Accelerating Transformation & Fulfilling Promises.

Budget 2014 certainly demonstrates a holistic approach in addressing the current challenging economic situation. We are currently living in the Digital era where the Internet is vital in our daily lives. In line with the tabling of Budget 2014, the government has implemented the High-Speed Broadband (HSBB) project under the National Broadband Initiative. With the objective to expand the Internet access in major towns, the government will implement the second phase of HSBB in collaboration with the private sector involving RM1.8bil investment. With this, it is expected to provide more coverage in urban areas, benefiting 2.8 million households with increased Internet speed to 10 Mbps.

In addition, the government will continue to strive for excellence in education via ICT by expanding Internet access in schools especially in rural areas with an allocation of RM168 million.

These announcements will increase the number of Internet users and boost the adoption rate for smart devices such as tablets, smartphones, laptops, phablets as well as Personal Computer (PC) amongst the consumers and businesses especially in the current inevitable movement of the ‘consumerisation of IT or the Bring Your Own Devices (BYOD) trend.

With the increase of Internet users we do foresee the need of Internet security, etiquette and stay vigilant not falling prey to the cyber criminals.  Malaysians are reminded to have appropriate preventive steps and ensure that they have an all-in-one security solution to stay ahead of the potential cyber threats. In addition to that, corporations will also need to include measures to have threat management solutions and Internet security solutions to keep abreast with the increased usage of mobile devices within their organization resulting in elasticity of their business perimeters as well as adhering to the Private Data Protection Act (PDPA).

Thursday, October 24, 2013

Trend Micro Titanium Maximum Security 2014 Demystifies Social Networks Privacy Settings

Socially savvy Malaysians share too much personal information online

Kuala Lumpur, 23 October 2013 – Everything you do online leaves behind a digital footprint that can lead cyber criminals to you. A recent survey1 by Trend Micro, a global leader in security software, revealed that 69% of Malaysians disclose their date of birth on social networks. Further to that, 47% of the respondents have also previously ‘check-in’ their location. With half of the survey respondents posting on their social networks at least once a day, a wealth of information about Malaysians personal lives are being disclosed on the internet every single day.

In the age of online financial frauds, identity thefts and loss of data, where cyber criminals leverage readily available personal information for their own gain, Trend Micro has solved the riddle of social network privacy settings for Facebook, Twitter and Google+ with the launch of the Trend MicroTM TitaniumTM Maximum Security 2014. The latest solution features Trend Micro’s unique social network privacy technology which identifies privacy settings that may leave personal or inappropriate information publicly available or vulnerable to identity theft.

(From L to R) Cedric Lim, Consumer Sales Manager, Trend Micro, Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro, and Lisa Chong, Marketing Manager of Consumer Business, Trend Micro.

“Privacy is a huge concern, and we urge consumers in Malaysia not to be complacent online. Personal information is immensely valuable to cyber criminals, who can leverage such information for their own gain, create false identities for criminal use or even leverage your network to target your friends and family,” said Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Trend Micro.

Privacy Scanner identifies privacy loopholes in social network profiles
The Trend MicroTM Titanium™ Maximum Security 2014 is the latest iteration of the flagship all-in-one security solution, equipped with Web-threat protection that identifies and blocks dangerous links in websites, social networks, emails and instant messaging. It also detects spam emails containing phishing scams that can trick users into revealing private personal information.
(from L to R) Terrence Tang, Senior Director of Consumer Business, APAC Center Sales and Marketing, Trend Micro, Cedric Lim, Consumer Sales Manager, Trend Micro, Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro, and Lisa Chong, Marketing Manager of Consumer Business, Trend Micro.

Trend Micro’s robust Privacy Scanner now dramatically simplifies privacy settings on Twitter and Google+, and Facebook – for both Mac and PC. Facebook settings can also now be managed on-the-go via an Android app. It also gives users control over which apps can access biographical data, and who can tag and see photos.

In this ‘post first, think later’ era on social networks, the Privacy Scanner helps ensure that consumers share information only among those they know.

According to the August 2013 AV Comparatives report, Trend Micro Titanium offers the broadest combination of privacy and Web threat protections for Facebook, Google+, and Twitter across PCs and Macs among 31 security products reviewed (Social Network Protection Review, August 2013, AV Comparatives).
Vulnerability Quotient: How vulnerable are you online?
Trend Micro urges consumers to seek discretion when posting on social networks and diligence in maintaining strong passwords as ways to safeguard their personal lives.

Trend Micro has launched the Trend Micro Vulnerability Quotient, available at http://bit.ly/MYwhoami_qr or via a QR code – an app on Facebook that helps consumers determine how vulnerable they are online. Through a series of questions measuring consumers’ behavior on social networks and password management, amongst other security issues, consumers can find out what their Vulnerability Quotient is and how exposed they are to falling victim to cyber threats. The app also allows them to track how they fare among the rest of the population.
Additional features of Trend MicroTM TitaniumTM Maximum Security 2014
“Trend Micro encourages the building of safer digital social cultures, and aims to enable everyone to protect their digital lives,” said Andrew Tan, Product Marketing Manager (Consumer), Southeast Asia, Trend Micro. “More than just ensuring safe surfing habits, the Trend Micro Titanium Maximum Security 2014 offers consumers all-in-one, all-rounded protection against identity thefts, viruses and other online threats automatically so they can enjoy their online experiences safely and with a peace of mind.”

The Trend Micro Titanium is the flagship all-in-one security solution which utilizes state-of-the-art cloud-based technology to proactively stop threats before they reach users. Trend Micro Titanium features:
First-of-its-kind technology for social networking security – the Privacy Scanner for Windows now NEWLY EXTENDED to include Google+ and Twitter in addition to Facebook. It monitors privacy settings and flags potential privacy concerns.
Trend Micro™ DirectPass™ password management system that help you maintain multiple passwords and securely log on to websites. It also includes a secure browser to conduct safe online commerce that is specifically designed to support secure online banking.
Trend Micro™ Online Guardian™ and parental controls to monitor kids on social networks and online activities.
Tools for protecting data from loss or theft including Secure Erase file shredder, Trend Micro Vault with remote file lock and a 5GB Trend Micro™ SafeSync™ account  to protect, share and access files for Titanium Maximum products
Set-and-forget security – won't hassle users with alerts and pop-ups.  Intuitive interface is easy to install and use with simple screens and reports
Extended protection for up to multiple devices (for Titanium Maximum Security) Available for laptops, smartphones and tablets, running on Android, Mac or Windows including support for Windows 8 operating systems.

Pricing and Availability
Trend Micro TitaniumTM Maximum Security 2014 is available today from all leading IT retailers and Trend Micro Website at the recommended retail price of RM109 for 1 device and RM159 for 3 devices. Trend Micro TitaniumTM Internet Security 2014 is available at a recommended retail price of RM109 for 3 devices. For more information, kindly visit http://www.trendmicro.com.my/my/ or follow https://www.facebook.com/TrendMicroMY.

Friday, October 11, 2013

The Market Dominance of the Android

Keeping with the Times

A perspective by Trend Micro, a global leader in consumer digital information security

Kuala Lumpur, 11 October 2013 – More than 1 billion Android devices have been activated throughout the world1. The Android platform has overtaken the iOS mobile market in many countries including Malaysia, based on a recent survey conducted by Trend Micro Malaysia. It is of no surprise as the open eco system is what smartphone manufacturers, app developers and consumers love but this comes with a price.  The open platform exposes users to become easier target for cybercriminals. 63% of the respondents who took part in the recent survey are Android users but only 19% installed additional mobile security2.

Both the iOS and the Android platforms have in-built capabilities to resist web-based attacks like having traditional access controls, permission-based access control and limiting hardware access, however both platforms also have security weaknesses3.  In Trend Micro’s 2Q Security Roundup for the year, more than 700 thousand malicious and risky apps were already found in the wild.

“Due to the continuous popularity of the Android platform among users, Trend Micro had earlier predicted that 2013 would be the year that mobile threats, specifically malware and high-risk apps to reach the 1 million mark. With three months left to spare before the year ends, our prediction has already came true,” said Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc.

“Our Mobile App Reputation data indicates that there are now 1 million mobile malwares (such as premium service abusers) and high-risk apps (apps that aggressively serve ads that lead to dubious sites). Among the 1 million questionable apps we found, 75% perform outright malicious routines, while 25% exhibits dubious routines, which include adware.4 It is even more pressing today to ensure that you have an additional level of protection in your devices to avoid becoming a victim of such threats,” continued Goh.

Top 3 Mobile Threats5
Although Google is taking steps to keep the Android system secure using known features like the Bouncer service or automated scanning, sandboxing, permissions system, and remote malware removal, Android malwares continue to rise alongside the growing market for Android devices. Here are the top three threats that Android users may face:

Premium Service Abusers
Cybercriminals are using all kinds of tricks to get users to download malicious apps including creating fake versions of Skype, Instagram, Angry Birds Space and other legitimate apps which will then send unauthorized text messages to certain numbers and register users to costly services6. Trojans are deployed to hijack a handset enrolled in premium service contracts, allowing the dispatcher to remotely access the same services that are paid for by the owner of the infected device.

Rootkits or data mining
The master key Android vulnerability allows cybercriminals to replace legitimate apps with malicious copies that release rootkits deep inside a phone's system with one programmed task - to record sensitive data such as key strokes, passwords and locations. Mobile phishing sites are another method of tricking users into divulging personal information.

Fake URLs6
With the prevalence of shortened URLs shared via the various social networks, users are tricked into visiting sites that are compromised, allowing for a virus to be planted on their devices that will steal information and breach user privacy.

Keeping with the Times
With the rising popularity of smart devices, the security of these devices is a growing concern as the threats for mobile devices are catching up with its PC counterparts in terms of severity. With high-profile incidents like the mobile phishing pages with fake WhatsApp notification serving a multiplatform threat, the master key vulnerability, and not to mention the growing number of online banking transactions via mobile devices, here are a few additional security steps that users can take.

Protect your devices by 7:
Using your smartphone’s built-in security features. Keep your smartphone safe from abuse and/or misuse by properly configuring your location and security settings.
Avoiding free but unsecured Wi-Fi access. Accessing the web via an open network may be convenient and free but it also allows anyone to access your phone.
Scrutinizing every app you download regardless of source. Trojanized apps also find their way to official app stores so users would still be encouraged to scrutinize closely the apps you download.
Understanding the permissions you are allowing before accepting them. Be careful about granting access to personal and/or device information or letting apps do other unnecessary actions in order to work.
Investing in an effective mobile security app. Being wary when downloading and installing apps isn’t enough, to stay protected anywhere and anytime, users should consider investing in a mobile security app to effectively defend your device against the latest mobile threats.

Trend Micro Mobile Security Personal Edition This antivirus protects your privacy, finds your phone or tablet if you lose it, backs up your photos and videos, improves your Facebook privacy and even identifies malicious apps that steal your information. Our Mobile Threat Hub also provides helpful information about mobile threats and security tips for your smartphones, tablets and other gadgets. Trend Micro Mobile Security provides 99.9% detection according to Av-test.org and is also certified by PCSL and AV-Comparatives.

Trend Micro Titanium 2013 Maximum Security provides industry-leading, anti-virus and web-threat protection that identifies and blocks dangerous links in websites, social networks, emails and instant messaging. This latest solution features Trend Micro’s unique social network privacy technology, which identifies privacy settings that may leave personal or inappropriate information publicly available or vulnerable to identity theft.

Monday, July 15, 2013

Android ‘Master Key’ Vulnerability Affects 99% of Devices

-Trend Micro protects users against the vulnerability via its Mobile Security Solution-

The new vulnerability in Android phones, codenamed ‘Master Key’, allows installed apps to be modified without its user awareness. Existed since Android 1.6, it has affected 99% of Android devices. Trend Micro, a global leader in mobile, cloud and server security, now protects users against the ‘Master Key’ vulnerability via its Trend Micro Mobile Security. The recent update to the solution allows it to detect any apps attempting to take advantage of the vulnerability including new apps that are yet to be identified by security researchers.

While there have been no recorded malicious apps taking advantage of the ‘Master Key’ vulnerability, it is only a matter of time before cybercriminals develop it and get them into the wild. “Since the announcement of this vulnerability it took less than a week for a security researcher to deliver a proof of concept exploit. We are pretty certain cybercriminals have been doing their own development and testing and we will see malicious apps popping up on 3rd party apps stores and websites in the very near future” said Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc.

Google has since released a patch for the Android operating system and provided it to carriers and device manufacturers. However due to the fragmented nature of the Android ecosystem it is likely to take quite a while for most people to receive the update. “The fragmented nature of Android is a fact of life and fixes for vulnerabilities and security patches will likely never reach a large percentage of users. Unfortunately this is the case where I am afraid a large number of people are going to remain vulnerable” added Goh.

Kindly click on the link below to have an in-depth idea on the ‘Master Key’ vulnerability.

http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-solution-for-vulnerability-affecting-nearly-all-android-devices/

Wednesday, July 3, 2013

Trend Micro Launches Deep Security 9 To Provide The World’s Leading Protection for Virtual and Cloud Data Centres in Asia Pacific

Trend Micro offers the award-winning and most complete server and data security solution designed for enterprises and service providers with virtualization, cloud computing and softwaredefined data centre requirements

Kuala Lumpur, 3 July 2013 – Trend Micro Incorporated (TYO: 4704; TSE:4704), the global leader in cloud security, announced the latest version of its comprehensive server security platform designed to provide server, application and data security across  physical, virtual and cloud environments.

Trend Micro™ Deep Security 9 is specifically designed to maximize the return on investment in
virtualization and cloud technologies for large and small enterprises, as well as managed service providers with an infrastructure-as-a-service (IaaS) practice.

Goh Chee Hoh, Managing Director, SEA Region, Trend Micro.

Well-regarded by industry peers, Trend Micro™ Deep Security is the Preferred Product Award Winner in the Virtualization Review 2013 Reader’s Choice Awards for the cloud security category, and also awarded best secure virtualization solution of the year in 2012 and 2013 by SC Magazine.

Experton Group, a German analyst firm, named Trend Micro the leader in cloud security in its 2013 Cloud Vendor Benchmark report noting the company’s strengths in offering cloud service providers solutions, with one of the highlights being Deep Security.

While previous versions of Deep Security have already delivered on the innovation and market leadership in virtualization security with an agentless security platform designed specifically for VMware® environments, Deep Security 9 offers additional performance and ease-of-use enhancements to the agentless architecture.

At the same time, Deep Security 9 extends the power of the Deep Security server security platform to the public and hybrid cloud, enabling organizations to dynamically instantiate workloads in this environment while still maintaining the highest levels of security and compliance. "More and more data centers are becoming virtualized or moving to a public or hybrid cloud," said Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc. "Deep Security offers VMware customers intrusion prevention, integrity monitoring, and virtual patching on an agentless basis in addition to agentless AV. It allows customers to securely extend their data center and private cloud workloads to public and hybrid clouds, so they can recognize even greater agility and cost savings."

Deep Security leverages both agentless and agent-based protection mechanisms to automatically and efficiently secure virtual servers and desktops, and private and public clouds and accelerate ROI.

Comprised of anti-malware, web reputation, firewall, intrusion prevention, integrity monitoring and log inspection technologies in one integrated solution; the solution protects mission critical enterprise applications and data from data breaches and business disruptions without expensive emergency patching. Deep Security 9 also enables cost-effective compliance to many regulations such as PCI DSS 2.0, HIPAA, NIST and SAS 70.

"We're very happy to see Trend Micro continuing to work closely with VMware to bring customers the benefits of advanced security for virtual and cloud environments," said Parag Patel, vice president, Global Strategic Alliances, VMware. "Trend Micro developed Deep Security 9 with VMware in mind by including integrations with VMware vCenter™, vSphere Endpoint™ and vCloud Director®, and providing improved manageability of security in VMware environments."

What's NEW in Trend Micro Deep Security 9

Integration into vCloud  Director and Amazon Web Services,  as well as a unified management console, enables organizations to extend their data center security to workloads in VMware vCloud® and Amazon-based public cloud workloads enforcing the same corporate policies across both environments and managing the security of both environments through a single pane of glass.

Support for latest VMware releases – vSphere 5.1 and vCloud Networking and Security 5.1 Deep Security 9 will support VMware vSphere® 5.1 and vCloud Networking and Security™ (vCNS).

This release will mark the product's 4th generation of integration with VMware products.

Enhancements to Deep Security Agentless Platform  to include improved performance through VMware ESX® level caching and deduplication, and recommendation scans that take the guesswork out of tuning security policies.

Hypervisor integrity monitoring  in Deep Security 9 extends security and compliance of virtualized systems to the hypervisor. By utilizing Intel TPM/TXT technology, Deep Security 9 is able to monitor for any unauthorized changes to the hypervisor thereby helping organizations meet evolving compliance requirements like PCI DSS Virtualization Guidelines.

Deep Security 9 has an agile multi-tenant architecture for software-defined data centers and providers that  enables logical separation of tenant policies and data, allows delegation and selfservice for tenants, and supports elastic cloud-scaling with automated deployment and provisioning of Deep Security components. RESTful management APIs also facilitates extensibility and integration into modern cloud infrastructure.

Supporting quotes:

Alex Ng, General Manager, Clearmanage, Singapore
“Compliant to stringent IaaS security requirements, Trend Micro’s Deep Security solution provides comprehensive protection with great cost efficiencies. This solution is an attractive and economic option for businesses that wish to embark on the Cloud journey, and hence, we have chosen Trend Micro as our security solution provider and partner.”

Haruki Kobayashi, Research & Business Development Promotion Div., Network-security Consultant Project Promotion Management, Cloud Solution Div., CISSP, TCSE, Softbank Technology Corp, Japan

“Operational management duties could be performed in any situation, and we were able to boost the availability of clients’ services. Moreover, the setup of PCs, and the application of security countermeasures had traditionally been performed independently by each employee. Now, however because central management is possible with Trend Micro’s Deep Security solution, administrative tasks have been reduced by 75 percent and we have been able to spare that time up for more important work.”

Alex Chan, Manager - Data Centre and Operations, National Institute of Education, Singapore
“As Trend Micro’s Deep Security is tightly integrated with VMware solutions, we have a better peace of mind in being armed with complete protection that is seamless and transparent across our servers. The agentless approach has also significantly reduced administration and installation time spent, catering to the vast numbers of VMs and servers within the Institution.”

Pricing & Availability
Deep Security 9 is available in Asia Pacific. Pricing is based on a per server model and also depends on the number of modules licensed.

Friday, June 28, 2013

Trend Micro and INTERPOL to collaborate in Support of Global Law Enforcement Efforts Against Cybercrime

[Kuala Lumpur, June 24, 2013] –Trend Micro Inc. (TYO: 4704; TSE:4704), a global leader in security software and solutions, today announced its collaboration with INTERPOL to support global law enforcement programs against cybercrime.

Today’s  cyber threats are becoming increasingly more targeted and sophisticated with criminal networks operating across the world, coordinating complex attacks against targets in a matter of minutes.

Due to the complexity of the cyber-threat landscape,  cybercrime investigations are profoundly different in nature to traditional crime, requiring high-level technical expertise and large-scale cross-jurisdictional investigations. It is essential that law enforcement prioritize resources, build cross-jurisdictional and crosssectorial collaboration in addition to developing the technical expertise, tools and infrastructure required to effectively combat threats and eventually enhance digital security.

In response, INTERPOL is establishing the INTERPOL Global Complex for Innovation (IGCI) in Singapore in 2014, which will be the centre of excellence for cybercrime toward facilitating international cooperation. The IGCI will seek to implement an alliance with multi-stakeholders, including Internet security specialists from the private sector, to leverage their respective expertise and resources for the benefit of global law enforcement agencies fighting cybercrime.

Trend Micro, will support INTERPOL with its expertise in mitigating cyber threats. On June 21, Eva Chen, CEO of Trend Micro met with Ronald K. Noble, Secretary General of INTERPOL in Lyon, France to discuss the parameters of this important endeavor.

Trend Micro will deliver training programs to INTERPOL, government and/or police organizations in various participating countries, and major companies that manage basic infrastructure, with corresponding expertise and best practices to address emerging digital crime at the national and international level. Training will encompass e-learning modules, classroom-based training sessions, workshops and/or professional certifications, based on overall goals and learning objectives.

The alliance with INTERPOL will enable Trend Micro to fulfill its corporate vision of establishing “A World Safe for Exchanging Digital Information.”

Thursday, June 13, 2013

CLOUDSEC Summit 2013 Addresses New Cybersecurity Threats in Cloud Computing, Consumerisation and targeted Cyber Attacks

- Brings together global thought leaders and showcases what businesses can do to guard against the three Cs of consumerisation, cyber threats and cloud -

Kuala Lumpur, 13 June 2013 – Founded in 2011, CLOUDSEC summits are Asia Pacific's leading cloud security events for CXOs and senior managers. These events are vendor-neutral and features presentations by industry experts who will address a wide spectrum of real-world challenges and strategies in cybersecurity today. The tagline “Have A Safe Journey” seeks to inspire managers and users of cloud computing to adopt the best practices and proven technologies from around the world to secure their journey from physical, to virtual, and finally to the cloud, in an efficient and effective way.

“CLOUDSEC Summits bring together some of the world-renowned cybersecurity experts and industry thought leaders for a valuable time of knowledge sharing, interactive discussions and networking. With eight events across the region, attendees at this premier  event will have the opportunity to learn the latest innovations on data security, understand the impact of standards, and get insights from industry leaders on emerging technology trends. This year, key topics such as Cyber Threats (Targeted Attacks), Consumerisation (BYOD/Mobile Security), Data Privacy & Protection, Security Management, Big Data Security and Cybercrime & Law Enforcement will also be discussed. We welcome all returning delegates, speakers, sponsors and supporters and we hope they will  have another exciting time at CLOUDSEC this year,” said Ken Low, Program Director of CLOUDSEC Summits and Chairman of Asia Pacific Executive Council at Cloud Security Alliance.

(from left to right): 
1. Goh Chee Hoh, Managing Director, SEA Region, Trend Micro. 
2. Anwer Yusoff, Head, Innovation and Commercialisation, CyberSecurity Malaysia.
3. Richard Sheng, Sr. Director, Enterprise Security Trend Micro Incorporated, Asia Pacific.
4. Ken Low – Programme Director, CLOUDSEC Summits, and Chairman, Asia Pacific Executive Council, Cloud Security Alliance.
5. Laurence Si, Country Manager, VMware Malaysia.

Teh Lip Guan - Executive Director, PwC Advisory Services.
The Cloud is Here
CLOUDSEC 2013 highlighted the need to  boost customer confidence and urged industry leaders, end-users and industry bodies to come together as businesses move towards rapid deployments around the three key areas of Consumerisation, Cloud and targeted Cyber Attacks.

Consumerisation
Consumerisation of IT and BYOD trends are fuelling demand for technologies that are more responsive and offer anytime, anywhere and any device access in a reliable, scalable and secure manner. The increasing exposure of information within rapidly-expanding IT infrastructures, application portfolios and cloud environments opens organizations up to new forms of security risk. Organizations will increasingly need to develop systems and solutions that mitigate these risks as well as be able to observe regulatory compliance for data protection.

Developing Cloud Security Guidelines
Highlighting on the need for guidelines, the industry leaders agreed that the  need for guidelines would be the single most important factor responsible for ensuring success in the Cloud. Highlighting its commitment for the region, CSA and Trend Micro shared efforts working with governments, associations and businesses  across the region. The duo have been instrumental in helping influence cloud security initiatives of governments in the US, Europe and Japan and are actively promoting and educating end-users on the best practices in cloud security.

Targeted Cyber Attacks
The sustainability of the Cloud platform will be based on the robustness of the network that supports it.  In  line with its commitment to further support the Cloud platform, Trend Micro’s announced the expansion of the Trend Micro™  Smart Protection Network™, its cloud-based security infrastructure introduced in 2008.

The latest iteration of the Smart Protection Network incorporates advanced big data analytic capabilities that enable Trend Micro to identify new security threats across a broader range of data sources including Mobile app reputation (for mobile threats), vulnerability rules (for vulnerability and exploits), network inspection rules (for network communications), and in-thecloud whitelisting (for minimizing false positives).

These features along with the award winning SecureCloud and Deep Security solution provides businesses with robust data protection across  public and private clouds and VMware vSphere virtual environments. The unique  encryption with policybased key management and unique server validation helps businesses easily secure sensitive data stored with leading cloud service providers keeping data private and helping companies meet regulatory compliance requirements across   physical, virtual, and cloud environments.

“VMware and Trend Micro have partnered to deliver the first agentless security solution designed for VMware® softwaredefined datacenters, desktops  and cloud deployments. Together, VMware and Trend Micro take security to new levels and enable customers to increase consolidation rates, accelerate and complete their virtualization journey, more fully leverage their VMware investments, and maximize their ROI,” said Laurence Si, Country Manager, VMware Malaysia.

“CLOUDSEC Summits are an excellent way to stay informed of latest industry trends including Cyber Threats and what can be done to mitigate them. It's also a great forum to catch up and network with your peers in the industry,” said Suresh Mustapha, MD Asia Pacific, SANS Institute.

Awards and Recognitions
In championing the efforts to provide the best cloud based security solution, Trend Micro recently was recognised as the Market Leader and #1 Cloud Security Vendor by the Experton Group. Trend Micro’s “Deep Security” and “SecureCloud” products set the current benchmark for the competition. It is reputed as an above average diversified and specialized portfolio of technologiesthat is highly rated amongst businesses.

Wednesday, May 8, 2013

Hundreds of Fake Iron Man 3 Streaming Sites Emerge in Recent Internet Scam


Fraudulent Surveys on Facebook Helps Crooks Earn Money

Kuala Lumpur, 8 May, 2013 – With the current hype around the third Iron Man sequel, the leading global security company, Trend Micro Incorporated (TYO:4704), found hundreds of websites emerge on the Internet claiming to stream the box office hit.

Once visited, these sites required users to download a video installer that would not play the aforementioned film, but may instead leave those affected vulnerable to malware. Furthermore, social media platforms like Facebook and many well-known blogs also allowed scammers to further spread “Free Iron Man 3 Streaming Video” websites to draw users into taking surveys that generated financial gain for the said scammers.

TrendLabs noticed the false Iron Man 3 websites even before the film’s official release in the United States. Most of the sites used popular blog providers (half of the fake Iron Man 3 sites found used Tumblr) to lead users to the disguised Iron Man 3 streaming or download pages.

Based on TrendLabs’ analysis, the video player downloaded is said to be “a legitimate video player.” However, this particular video player has been known to display aggressive ads in the past, and these legitimate files could easily be replaced with malware at a later time. Thus, it won’t be a complete surprise to find a malware-hosted Iron Man 3 streaming and download webpage anytime soon.

Unsurprisingly, some scammers also used Facebook to spread supposed free Iron Man 3 movie streaming links. But once users click the link, they are redirected to several web pages with survey scams, and their Facebook contacts spammed with the same post. Similar ruses TrendLabs documented in the past include the “Facebook Profile Viewer” and a survey scam under the veil of the much talked-about Google Glass competition.

None of these sites led to the actual advertised movie. Some of these sites, however, asked users to register and to include their credit card number, which is highly suspicious.

“Summer blockbusters like Iron Man 3 are typical cybercrime baits because they have been effective in tricking users into visiting shady websites,” Paul Oliveria, Security Focus Lead of Trend Labs, Trend Micro Incorporated, mentioned. “Because of the clever use of social engineering tactics, users may end up falling into the bad guys’ traps. Thus, it is important to be aware of how social engineering works and be conscious of what you click and share on your Facebook and other social media accounts” Paul said.

Trend Micro blocks the related sites and domains related to this threat. For further information on this, please check:

http://blog.trendmicro.com/trendlabs-security-intelligence/fake-iron-man-3-streaming-sites-sprout-on-social-media/

Wednesday, April 10, 2013

SURIFNG THE NEWS ONLINE


Online News Exploit or Being Exploited?

A perspective by Trend Micro, a global leader in consumer digital information security

It is learnt that on a daily basis many people spend most of their time doing one of three things on the Internet – reading emails, reading the news online while surfing the Internet and keeping up with friends and family via social networks.

Recently in February, we read the report where the *Los Angeles Times has scrubbed its website of malicious code that served browser exploits and malware to potentially hundreds of thousands of readers over the past six weeks. It’s not clear how many readers may have been impacted by the attack, which appears to have been limited to the Offers and Deals page of the www.latimes.com website.

Site metrics firm www.alexa.com says this portion of the newspaper’s site receives about .12 percent of the site’s overall traffic, which according to the publication are about 18 million unique visitors per month. Assuming the site was compromised from December 23, 2012 through the second week in February 2013, some 324,000 Los Angeles Times readers were likely exposed to the attack.

In fact, the Los Angeles Times incident is unfortunately all-too-common. Most of the time, these websites that were detected malicious content are innocent, legitimate sites that have been hacked. What took place was that once attackers have figured out a way to inject content into a website, the rest of the intrusion follows a familiar script whereby the attackers add malicious. When unsuspecting users visit the legitimate site, their browsers also automatically pull down the exploit kit code from the unauthorized server which is usually termed as Blackhole.

According to **Trend Micro, the new kit, which it dubbed Whitehole Exploit Kit, uses a similar code as Blackhole —but does not bother to hide itself. Other notable features of this new toolkit include the ability to evade antimalware detections, prevent Google Safe Browsing from blocking it and the ability to load a maximum of 20 files at once.

According to Trend Micro an analysis of the sample exploit malware detected as a Trojan, exploits vulnerabilities to download malicious files on a victim's computer. It then downloads a malware, noting the Whitehole that download other malware and push fake applications. This specific Trojan variant connects to certain websites to send and receive information as well as terminates certain processes. It also downloads additional malicious files onto already infected systems, whilst ransomware typically locks systems until users pay money via specific payment modes.

Malaysia’s scenario on online new consumption
In Malaysia, we have seen online news consumption on the rise, with many now getting news on their mobile phones, tablets, laptops or other mobile platforms.

According to a recent study conducted by ***Trend Micro with their Malaysian Facebook fans which polled more than a thousand people, 70% of respondents actually get their news source via online news sites and portals. Apart from news sites over 90% users also received their local news from Facebook, Twitter, Blog sites, Forums and other networking sites.

About 50% of the respondents are also comfortable with sharing their login IDs and passwords with others to access online portals that require membership. 50% of respondents do click on appealing promotions and advertisements pop-ups while surfing the Internet, whilst another 22% will do it for the sake of fun or being inquisitive and the remaining 28% either ignore or disable the pop-ups.

As many as 44% respondents said they have no qualms sharing their information such as emails, contact numbers with these news portals. Interestingly, about 25% of the respondents said they encountered scenarios of security breaches where their personal information ended up in other online portals that they don’t access. In such cases, 65% said they would lodge a report with the administrator, 10% said they would lodge a police report and 25% don’t see a need for any action.

The need to build a smarter and safer digital social culture
From the survey, the findings were not entirely new or surprising. Millions of people are getting their news online or interacting and socializing on websites, creating a large pool of potential victims that attract cybercriminals. Click-jacking, fake applications, malvertising and social engineering are just some of the tactics used in order to deliver malware.

To be secured, one needs more than the standard antivirus and spyware protection. Ensure your solution offers protection on WiFi hotspots, antispam blocking, and search engine result ratings that will help consumer to decide if a website is safe to visit.

Trend Micro’s Maximum Security is built to address these malicious traits. Operating on real time protection, the cloud infrastructure continuously updates new malicious links, apps and software by indicating the possible risks of a particular site or link.

Trend Micro Maximum Security works across multiple operating systems which include Windows, Mac and Android. The alarming findings of an approximately 1mil malwares to be recorded on the Android platform in 2013 underlines the crucial need of a user to be protected at all times.

*Source: http://krebsonsecurity.com/2013/02/exploit-sat-on-la-times-website-for-6-weeks/
**Source: http://www.gmanetwork.com/news/story/294043/scitech/technology/new-whitehole-
malware-exploit-kit-revealed
***Source: Study conducted via www.facebook.com/TrendMicroMY fans

Monday, March 25, 2013

Trend Micro Deep Discovery Protects South Korean Customers From Attack


Crippling attacks on banks and media thwarted by advanced threat protection of Trend Micro Custom Defense

Kuala Lumpur, 25th March 2013 -- Trend Micro Incorporated announced today that customers using its Deep Discovery advanced threat protection product were able to discover and react to the recent cyber-attack before damage could be done. These attacks paralyzed several major banking and media companies, leaving many South Koreans unable to withdraw money from ATMs and news broadcasting crews cut off from their resources.

Deep Discovery network detection and custom sandbox analysis were able to detect the spear phishing email, identify the malware it contained, and discover the external command-and-control sites that the attackers used. With this actionable intelligence in hand, customers were able to immediately stop or remedy any effect and to block all malicious communication sources. This detection and swift response saved Deep Discovery customers from an attack that appears aimed to disrupt normal business processing by disabling critical endpoints and resources.

Cyber-attacks have been a fact of life for some time in South Korea and many enterprise and government agencies have implemented proactive threat detection and response measures. Trend Micro is a leading provider of these security intelligence solutions and services, with three of the six top banks and over 80 government agencies using Deep Discovery to protect themselves from such attacks.

Anatomy of the Attack
According to reports, several computer screens at major South Korean banks and three top TV companies went blank on Wednesday (local time), March 20, 2013. Some screens were even showing an image of a skull and a warning from the “WhoIs” team.

This attack is one of several independent, concurrent attacks plaguing South Korea. Trend Micro research has shown that this is the result of a malware attack that began with the delivery of a spear phishing email spoofed to look like a credit card history for the month of March. The malware attached to these phishing emails that brought these systems down overwrites the Master Boot Record (MBR), and was set to run on March 20 2013. If the malware was installed before March 20, it remains dormant and activates only on this day. Once it runs, it completely cripples the system usually requiring it be rebuilt. Wiping the MBR in this fashion can sometimes be the last step in a targeted attack meant to make investigation and recovery of these systems more difficult. Trend Micro research has shown that attackers targeted for destruction not only systems running Microsoft Windows but also those running Linux, IBM AIX, Oracle Solaris and Hewlett-Packard HP-UX versions of UNIX.

Deep Discovery customers concerned they may also be targets of this attack can examine their Deep
Discovery logs for instances of “HEUR_NAMETRICK.B.”

Deep Discovery and Trend Micro Custom Defense
Trend Micro Deep Discovery provides the custom detection, intelligence and response capabilities to protect customers from targeted attacks and Advanced Persistent Threats (APTs). Its detection engines and custom sandboxing identify and analyze malware, malicious communications and attacker behavior invisible to standard security solutions.

Deep Discovery enables a full Detect – Analyze – Adapt – Respond lifecycle to these attacks, augmenting and integrating with existing security investments to create a full Custom Defense solution tailored to the specific environment of the customer. Deep Discovery integration and security update sharing with network, gateway and endpoint security improve protection and defense against attack at all points.

And Deep Discovery custom threat intelligence and security event analysis enable the rapid containment and remediation of an attack. Only Trend Micro Deep Discovery and Custom Defense solution offer this breadth and depth of protection

More detailed information about this can be found on Trend Micro’s Security Intelligence blog posting: http://blog.trendmicro.com/trendlabs-security-intelligence/how-deep-discovery-protected-against-the-korean-mbr-wiper/.

Friday, March 22, 2013

Cyberattacks in South Korea Heightens Changes in Threat Landscape Trend Micro Urges Enterpises to Redefine their Security Strategy


[Kuala Lumpur, 21 March, 2013] – The leading global security company Trend Micro Incorporated (TYO:4704), detected multiple cyberattacks on South Korean banking corporations and media agencies. The incident began when corporate computer systems were shutdown and could not be rebooted, while others were showing images of a skull and a “warning”. As a result, business operations, ATMs, online banking, and TV broadcasts were disrupted.

Tactics used in these attacks resembles advanced target attacks, where spear-phishing emails were used to penetrate and compromise initial systems within these organizations.

Upon penetration, attackers targeted critical IT infrastructures such as patch management servers, and public facing web sites, in preparation for a “waterhole attack” where these legitimate websites and servers are modified to inject malicious code onto connecting PCs.

Like a lion waiting for speedy gazelles to slow down and have a drink, attackers hacked and loaded viruses onto sites they suspect attractive targets will visit. Compromised websites connected visiting clients to off-shore websites where malicious Trojan program, known as TROJ_KILLMBR.SM, was installed.

This program was responsible for taking down the infected systems by overwriting the Master Boot Record (MBR), thus paralyzing system and business operations. Wiping the MBR, a form of self-destruct, is typically the last step in a targeted attack that makes investigation and recovery of these systems more difficult.

Trend Micro has predicted a significant increase in cyber-attacks, and has been working with our customers and partners in this region to provide custom defense for the last several years. As a result of this investment, Trend Micro customers are protected in this series of attacks.

Customers using Trend Micro Deep Discovery were alerted on March 19th. The Deep Discovery Inspector and Deep Discovery Advisor heuristically detected malicious traffic and email (through the names of HEUR_NAMETRICK.B). As of March 20th, the malicious files and websites involved in these attacks are also detected and blocked by other Trend Micro solutions.

For further information on this threat, please check: http://blog.trendmicro.com/trendlabs-
security-intelligence/mbr-wiping-trojan-other-attacks-hit-south-korea/

To learn about Trend Micro, please check: http://www.trendmicro.com/us/index.html


南韓爆發史上最大駭客攻擊 企業及個人用戶電腦皆停擺

趨勢科技呼籲企業及消費者採取積極行動 以防遭受下一波毒駭

【2013 年 03 月 21 日吉隆坡讯】駭客針對南韓主要銀行、媒體,以及個人電腦發動大規模攻擊,截至目前為止,趨勢科技已經發現多重攻擊。駭客主要針對南韓主要銀行與媒體的補丁更新伺服器(patch management server)佈署惡意程式,造成受攻擊企業內部的電腦全面無法開機,作業被迫停擺;另一攻擊則針對南韓的企業網站,有的網站遭攻擊停擺,有的網站則是使用者造訪該網站都會被導向位於海外的假網站,並被要求提供許多個人資訊;此外,駭客並針對個人用戶發動電子郵件釣魚攻擊,假冒南韓銀行交易記錄名義,誘騙使用者下載內含木馬程式 TROJ_KILLMBR.SM 的執行檔,使用者電腦開機區遭到覆蓋,導致使用者無法開機。

趨勢科技內部偵測到的針對企業內部的目標性攻擊,目前已知受影響的企業主要為銀行以及媒體。這波攻擊以企業補丁更新伺服器(Patch Management Server)為標的,駭客成功入侵受害企業的補丁更新伺服器佈署惡意程式,該惡意程式會隨著企業員工電腦定期下載補丁(Patch) 而散佈至企業內部,造成企業內部電腦全面停擺,無法進行作業。

另一個攻擊則針對企業網站進行攻擊,目前已知南韓知名企業網站遭到入侵,並恐有被植入不明惡意程式之可能。除了企業之外,駭客並針對銀行使用者展開一波社交工程郵件攻擊。駭客透過一封假冒南韓銀行的信件,信件內容表示為使用者的交易記錄,要求使用者打開附件,附件內容其實為一個執行檔,一旦使用者下載執行後,將被下載一個名為 TROJ_KILLMBR.SM 的惡意程式,電腦開機區的所有資訊將被覆蓋,導致電腦無法開機。

趨勢科技表示,此惡意連結已遭趨勢科技封鎖。但值得注意的是,不排除駭客會展開另一波新的攻擊。

根據過往的案例分析,許多網路釣魚電子郵件看起來可能跟原公司的電子郵件一模一樣。使用者應該仔細閱讀電子郵件,而且去驗證電子郵件內容的正確性。除此之外,勿隨意開啟郵件中所附的連結或檔案,更勿輕易提供個人資料。

趨勢科技 Deep Discovery 在第一時間即已偵測到此社交工程郵件攻擊,並偵測其內含HEUR_NAMETRICK. B 惡意檔案。趨勢科技呼籲用戶使用最新病毒碼,以提供相對應的防護。更多Deep Discovery 相關訊息請參考:
http://tw.trendmicro.com/tw/products/enterprise/deep-discovery3/index.html

更多與此攻擊相關訊息請參考:http://blog.trendmicro.com/trendlabs-security-intelligence/mbr-wiping-
trojan-other-attacks-hit-south-korea/

Wednesday, March 20, 2013

Trend Micro warns hidden risks of mobile phishing on multi devices


[Kuala Lumpur – 11 March 2013] –Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global leader in consumer digital information security, releases new findings of TrendLabs on mobile phishing. The research based on the observation of phishing sites during 2012 shows over 4,000 phishing URLs designed for mobile Web. The result highlights that mobile devices, including smartphones and tablets, are valid platforms to launch phishing attacks.

According to a recent research 1, 4 of 5 US users shop online via smartphone, and 52% of users browse websites2 on their gadgets, while 39% visit social networking sites or blogs.

“Users are slowly changing their habits on using mobile devices due to the efficiency and convenience smartphones and tablets provide.” mentioned Paul Oliveria, researcher of Trendlabs. “However, cybercriminals are also taking advantage of this consumer trend by using phishing sites, which are spoofed versions of legitimate sites, to trick users into disclosing sensitive information like usernames, passwords, and even account details.”

Trend Micro also found out in 2012, 75% of mobile phishing URLs were rogue versions of well-known banking or financial sites such as Barclays, while e-commerce and shopping sites, including the top phished entities PayPal and eBay, make up 4%. Once users are tricked into divulging their login credentials to these sites, cybercriminals can use these stolen data to initiate unauthorized transactions and purchases via the victim’s account.

“This trend in launching phishing attacks on mobile devices can be attributed to certain limitations of the platform itself,” Paul said. The small screen size in most mobile devices prevents users from fully inspecting websites for any anti-phishing security element. In addition, the majority of mobile devices use default browsers, so it is easier for cybercriminals to create schemes as they need only focus on one browser instead of many.

Another possible reason of this rising trend of mobile phishing goes back to the awareness of the users. Mobile device users need to understand that smartphones and other mobile devices are as capable as any desktop and need protection as well. These devices should be used more consciously and safely, or the mobile users will be exposed to the same threats that haunt PCs users.

Here are some tips from Trend Micro for users to protect themselves.

1 http://www.comscore.com/Insights/Press_Releases/2012/9/Retailers_Carving_Out_Space_in_the_M-
Commerce_Market
2http://www.comscore.com/Insights/Press_Releases/2013/1/comScore_Reports_November_2012_U.S._Mobile_Subscriber_Market_Share

 Use official apps only. Find the official apps of online banking or shopping website on the official website and download them. This makes it more difficult for cybercriminals to phish for your information.

 Avoid clicking links or opening attachments in emails from suspicious senders. The links and files within them can be malicious.

 Double check the webpage and its URL. There are legitimate emails that ask users to do email verification, but this is how phishing mails usually operate.

 Tap online browser’s address bar to fully display the website address. Scan for typographical errors or additional characters.

 Bookmark the often visited websites. It could lessen the chances of landing on a phishing website due to spelling mistakes.

 Get a mobile security solution. Trend Micro™ Mobile Security keeps the mobile devices and mobile data safe by identifying and blocking not only phishing threats, but also other web threats like malicious or high-risk URL and apps.

More tips on how to Protecting Yourself Against Mobile Phishing:

http://about-threats.trendmicro.com/ebooks/protecting-yourself-against-mobile-phishing/files/assets/downloads/protecting-yourself-against-mobile-phishing.pdf

More information on Trend Micro™ Mobile Security, please visit:
http://www.trendmicro.com/us/home/index.html#mobile-device-solutions

Wednesday, February 6, 2013

趨勢科技指出2013 Android惡意程式將達百萬個 多重社交平台為主要散佈管道 亞太區印度、菲律賓、南韓、香港名列前十大隱私暴露高風險國家


【2013 年02月5日 台北訊】趨勢科技 (東京證券交易所股票代碼:4704) 今天發表「2012年行動裝置資訊與威脅安全總評」,該報告指出在2013年針對Android平台的惡意程式將成長至百萬個,其中惡意程式又以服務濫用程式為大宗。此外,越權廣告程式(aggressive adware)、正常APP可能帶來的隱私外洩問題以及行動裝置平台漏洞,都將會是2013年行動裝置使用者面臨的主要威脅。該報告更指出2013年Android惡意程式將更精密,攻擊手法將運用多重社交平台帳號整合的趨勢快速散佈;網路金融交易付款方式則持續成為駭客攻擊的目標。

行動裝置有多夯?根據尼爾森2012 年上半年度NetWatch 報告顯示,台灣行動裝置的成長爆發力驚人,智慧型手機用戶人數上半年428 萬人,較去年同期成長95%;平板電腦持有人數突破百萬,較去年大幅成長超過一倍 。行動裝置使用者眾,商機龐大,連帶針對行動裝置的資安威脅數量也快速攀升。

2012年高費率濫用程式 越權廣告程式當道   駭客攻擊偏愛社交工程


根據趨勢科技最新發表的「2012年行動裝置資訊與威脅安全總評」,惡意程式仍以針對Android平台為大宗,根據趨勢科技統計顯示,在 2012 年最常見的 Android惡意程式為服務濫用程式。這些程式經常偽裝成熱門的 App 程式,如「Bad Piggies」遊戲、「憤怒鳥上太空(Angry Birds Space)」與「Instagram」等,一旦點選後,駭客將可藉此發送高額簡訊至不明號碼以賺取不法利益。以惡意APP程式比例而言,奈及利亞、秘魯以及印度是惡意APP比例最高的前三名國家。            

惡意 App 程式比例最高的十大國家

奈及利亞是惡意 App 程式比例最高的國家,其次是祕魯和印度。

2012 年 Android 惡意程式倍數成長的另一個主因為越權廣告程式(aggressive adware)爆增。越權廣告程式讓駭客可透過文字訊息詐騙、重複發送廣告訊息,造成使用者困擾。除了可能會蒐集GPS 定位、通話記錄、電話號碼以及裝置資訊等等敏感資訊之外,某些廣告程式庫甚至讓廣告業主直接存取使用者的個人資訊,造成個資與隱私外洩。




隱私暴露風險高的前十大國家
印度名列第一,其次是土耳其和菲律賓。

平台與軟體漏洞更是駭客竊取個資的管道。趨勢科技已經發現駭客利用電話播號程式漏洞、網路釣魚簡訊漏洞,以及Android平台、Samsung裝置驅動程式漏洞進行惡意攻擊。由於行動裝置的漏洞修補取決於廠商發佈更新軟體的速度,但更新軟體發布速度不一,而且某些較老的作業系統版本根本無法進行更新等問題,都讓此類攻擊防不勝防。

除了上述主要威脅外,對智慧型手機使用者而言,耗電量是智慧型手機令人詬病的另一個問題,而根據趨勢科技的統計顯示,耗電量APP比例最高的前10名國家中,包含了7個亞太地區國家,其中泰國和日本更是耗電APP比例最高的前兩名。

趨勢科技更進一步預測Android平台的惡意程式2013將有以下五大趨勢:
新的散佈管道:運用多重社交網路帳號同步功能,以及二維條碼(QR Code)等管道散佈惡意程式。社交網路 App 程式現在已開始提供多重社交網路帳號同步功能。歹徒可以利用這一點來將行動裝置惡意連結同時張貼至多個不同的社交網路。

行動/桌上型裝置雙重威脅:Android 惡意程式也將成為駭客針對桌上型裝置攻擊過程當中的一環,尤其是駭客發動針對網路銀行交易的攻擊時,較常運用這樣的手法。

運用BYOD風潮,透過工作場合的行動裝置散佈惡意程式:BYOD成為風潮。使用者將自行選擇各種不同的裝置、採用各種不同的平台。 網路犯罪者與駭客將透過工作場所當中的各種裝置和平台來散布惡意程式。

惡意程式越來越精密:Android 惡意程式將持續改進其躲避防毒軟體偵測與系統安全機制的能力,並以工具套件的形式出現。資安研究人員已公開一套概念驗證駭客工具套件 (Rootkit),證明惡意程式作者也可利用 Rootkit 神不知鬼不覺的取得行動裝置完全控制權。

新的攻擊目標:更多的惡意程式攻擊將鎖定新的付款方式,如「近距離無線通訊」(Near Field Communication,簡稱 NFC) ,以竊取金融資訊。

針對行動裝置的惡意程式日新月異,散佈管道更趨多元,然現今仍只有約兩成的行動裝置使用者安裝合適的資安軟體,趨勢科技呼籲大眾以及企業都應重視行動裝置安全,選擇合適的資安防護軟體。趨勢科技行動安全防護具有 主動偵測 功能,並且有效阻擋廣告以及惡意行動應用程式 。 趨勢科技行動安全防護免費試用: http://www.pccillin.com.tw/product-tmms.html 。