• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Archives for March 2015

The Resurrection of CVE-2011-2461

  • Posted on:March 31, 2015 at 12:42 pm
  • Posted in:Vulnerabilities
  • Author:
    Pawan Kinger (Director, Deep Security Labs)
0

Security researchers Luca Carettoni and Mauro Gentile recently found during their research that even though Adobe has fixed an old vulnerability found in 2011 (CVE-2011-2461), its side effects still linger around the Internet. Your favorite websites might still be affected by this bug. They have shared great details in their blog post. Let’s take a quick look…

Read More
Tags: adobe flashAdobe Flash PlayerCVE-2011-2461

Securing The IT Supply Chain

  • Posted on:March 31, 2015 at 1:01 am
  • Posted in:Targeted Attacks
  • Author:
    Ziv Chang (Director, Cyber Safety Solution)
0

The security of an enterprise is not only dependent on the organization itself, but also on the security of their IT supply chain and contractors. These represent potential weak points into the security of any organization. Third-party contractors and suppliers have been used to compromise larger organizations. Target’s breach began with a breach of a…

Read More
Tags: contractorssupply chainthird party

Fake Judicial Spam Leads to Backdoor with Fake Certificate Authority

  • Posted on:March 30, 2015 at 4:20 pm
  • Posted in:Malware, Spam
  • Author:
    Cedric Pernet (Threat Researcher) and Dark Luo/Kenney Lu (Threats Analysts)
1

Recently, we’ve come across an interesting spam campaign aimed at French users. The campaign itself uses a well-crafted lure that is likely to catch the attention of its would-be victims. In addition, the malware used – the GootKit backdoor – contains several unusual technical characteristics. Both of these highlight how this campaign was quite well thought-out…

Read More
Tags: FranceGootkitjudicial spam

Single-use Yahoo Passwords – Good or Bad?

  • Posted on:March 27, 2015 at 5:58 pm
  • Posted in:Bad Sites
  • Author:
    David Sancho (Senior Threat Researcher)
2

Yahoo recently rolled out a new way for users to access their services without entering a password. Their new system uses a cellphone to authenticate the user. Instead of entering a password, the user receives a verification code via text message on their phone. (The user would have provided their phone number to Yahoo when setting…

Read More
Tags: passwordsYAhoo

URSNIF: The Multifaceted Malware

  • Posted on:March 26, 2015 at 4:43 pm
  • Posted in:Malware
  • Author:
    RonJay Caragay (Threat Response Engineer)
1

The URSNIF malware family is primarily known for being a data-stealing  malware, but it’s also known for acquiring a wide variety of behavior. Known URSNIF variants include backdoors (BKDR_URSNIF.SM), spyware (TSPY_URSNIF.YNJ), and file infectors (PE_URSNIF.A-O). December 2014: Rise in URSNIF infections brought about by file infection routines In December 2014 we discussed a rise in URSNIF infections,…

Read More
Tags: file infectorURSNIF
Page 1 of 612 › »

Security Predictions for 2020

  • Cybersecurity in 2020 will be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to technological developments and global threat intelligence — only so defenders can keep up with the broad range of threats.
    Read our security predictions for 2020.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

Sorry. No data so far.

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.