• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Author / Yuki Chen (Threat Solution Engineer)

Yuki Chen

Threat Solution Engineer

A Look At A Silverlight Exploit

  • Posted on:November 25, 2013
  • Posted in:Exploits, Malware, Vulnerabilities
  • Posted by:
    Yuki Chen (Threat Solution Engineer)
0

Recently, independent security researchers found that the Angler Exploit Kit had added Silverlight to their list of targeted software, using CVE-2013-0074. When we analyzed the available exploit, we found that in addition to CVE-2013-0074, a second vulnerability, CVE-2013-3896, in order to bypass ASLR. These vulnerabilities are discussed in two separate Microsoft security bulletins, namely MS13-022 and MS13-087, respectively….

Read More
Tags: Exploitexploit kitMalwareMicrosoftSilverlightvulnerability

Trend Micro Finds Vulnerabilities in Java, Patched in Latest Oracle Update

  • Posted on:October 17, 2013
  • Posted in:Vulnerabilities
  • Posted by:
    Yuki Chen (Threat Solution Engineer)
0

Yesterday, Oracle recently released a new round of updates for Java. Two of these vulnerabilities (CVE-2013-5809 and CVE-20135778) and one in-depth defense issue were discovered by Trend Micro researchers and were privately reported to Oracle. All of these are now patched, and we do not believe they are in use or were earlier discovered by threat…

Read More
Tags: ExploitsJavaOraclesecurity updateVulnerabilities

Spam Asks Recipients to Join Jasmine Revolution

  • Posted on:April 8, 2011
  • Posted in:Exploits, Malware, Targeted Attacks, Vulnerabilities
  • Posted by:
    Yuki Chen (Threat Solution Engineer)
6

After the Tunisian Revolution, also called the Jasmine Revolution by many media organizations, in late 2010 or in early 2011, “Jasmine” became a hot word in China. Last week, a friend of mine in China received an email message with an .RTF attachment entitled, “My thoughts on the jasmine flower (the language of the document…

Read More

Using Information Leakage to Avoid ASLR+DEP

  • Posted on:January 20, 2011
  • Posted in:Vulnerabilities
  • Posted by:
    Yuki Chen (Threat Solution Engineer)
15

Today, more and more exploit developers are using Return-Oriented-Programming (ROP) techniques to bypass the Data Execution Prevention (DEP) feature in recent versions of Windows. In order to successfully launch an attack using ROP, one must know the fixed base address of the targeted module. However, Address Space Layout Randomization (ASLR), another security feature, makes it…

Read More

Technical Analysis of Adobe Acrobat and Reader Zero-Day Exploit

  • Posted on:September 23, 2010
  • Posted in:Vulnerabilities
  • Posted by:
    Yuki Chen (Threat Solution Engineer)
12

Several weeks ago, a new Adobe Acrobat/Reader zero-day vulnerability was found and soon exploited in the wild. What’s most interesting about this particular exploit is how it used return-oriented exploitation (ROP) techniques to bypass some of Windows’ security features such as Data Execution Prevention (DEP). In addition, it uses a two-staged shellcode to perform its…

Read More
Page 1 of 212

Security Predictions for 2019

  • Our security predictions for 2019 are based on our experts’ analysis of the progress of current and emerging technologies, user behavior, and market trends, and their impact on the threat landscape. We have categorized them according to the main areas that are likely to be affected, given the sprawling nature of the technological and sociopolitical changes under consideration.
    Read our security predictions for 2019.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

  • August Patch Tuesday: Update Fixes ‘Wormable’ Flaws in Remote Desktop Services, VBScript Gets Disabled by Default
  • TA505 At It Again: Variety is the Spice of ServHelper and FlawedAmmyy
  • Jenkins Admins: Relying on Default Settings Could Put Master at Risk of Remote Code Execution Attacks
  • Adware Posing as 85 Photography and Gaming Apps on Google Play Installed Over 8 Million Times
  • Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.