Showing posts with label bug. Show all posts
Showing posts with label bug. Show all posts

4 December 2014

Q314 saw cyberattacks grow in volume and sophistication: Trend Micro

Source: Trend Micro website.
The third quarter saw a new critical vulnerability, Shellshock threaten more than half a billion servers and devices worldwide. This major development, as well as an uptick in volume and sophistication of cyberattacks, are detailed in Trend Micro's latest quarterly security roundup report, Vulnerabilities Under Attack: Shedding Light on the Growing Attack Surface. 

The report also reveals web platform and mobile app vulnerabilities that have broadened significantly, resulting in high-impact attacks on businesses and consumers alike.

“Our findings confirm that we are battling rapidly moving cybercriminals and evolving vulnerabilities simultaneously,” said Raimund Genes, CTO, Trend Micro. “With this fluidity, it’s time to embrace the fact that compromises will continue, and we shouldn’t be alarmed or surprised when they occur. Preparation is key and as an industry we must better educate organisations and consumers about heightened risks as attacks grow in volume and in sophistication. 


"Understanding that cybercriminals are finding vulnerabilities and potential loopholes in every device and platform possible will help us confront these challenges so technology can be used in a positive way.”

The report dissects vulnerabilities such as Shellshock, which affects popular operating systems, including Linux,UNIX and Mac OS X. The surprising discovery of the Shellshock vulnerability emerged after going unnoticed for more than 20 years, suggesting the likelihood of more long, undiscovered vulnerabilities lurking within with operating systems or applications.

Vulnerabilities in mobile platforms and apps are also proving to be a greater challenge. As in previous quarters, the report cites that significant and critical vulnerabilities were found in mobile platforms, such as Android. Exploit kits were highly utilised in Web platforms and provided cybercriminals with another resource to compromise victim’s systems.

In an effort to steal credit card information and money, the report also reveals that threat actors are targeting large retailers’ Point-of-Sale (PoS) systems to execute massive data breaches. This ongoing practice further indicates that PoS networks are highly accessible and vulnerable. Cyber thieves also utilised updated versions of older versions of popular malware and online banking malware to successfully target victims.


Click here for the complete report, and read the associated blog post here.

15 November 2014

Trend Micro urges Windows users to update Windows to protect against the Winshock bug

A flaw recently discovered in Microsoft Windows has Trend Micro emphasising that Windows users should update their systems immediately. The problem lies in Microsoft’s delivery platform, which is meant to transfer data securely. Trend Micro says that users who ignore the problem are in a “wormable” situation that could enable attackers to commandeer their system without user interaction.

Christened “Winshock,” the bug received a score of 9.3 out of 10 by the Common Vulnerability Scoring System. Higher scores mean that the bug can cause more harm. Based on this classification, and the propensity for attacks following potential exploit announcements, Trend Micro’s Deep Security solution already provides protection against this vulnerability. Microsoft has also released a patch, or a solution against this problem, through Windows updates.

Said JD Sherry, VP, technology and solutions, Trend Micro: “When news like this breaks, cyber criminals go into hyperdrive developing attacks to take advantage of the flaw. As such, it’s important to quickly respond to avoid system disruption and compromise. We are urging our customers to make addressing this bug a top priority and we have provided resources accordingly to complement the latest Microsoft patches.”

Trend Micro experts recommend the following action:

§ Install Microsoft patches immediately
§ Use a browser other than Internet Explorer to reduce risks. Alternative browsers include Google's Chrome, Mozilla's Firefox, and Apple's Safari.
§ Employ newer versions of Windows platforms, supported by Microsoft

More  information can be found in the associated blog post here.

5 October 2014

Fishbat comments on iOS8 developments, Apple Pay

Apple recently released the first beta of iOS 8.1, an upgrade to iOS 8 that followed just a few days after the release of iOS 8.0.2, which itself fixed a bug in the recently-introduced iOS 8.0.1. 

The new beta version includes these features:
  • A newly designed iBooks icon.
  • A new Enable Dictation toggle in the keyboard settings.
  • New permission settings of applications.
  • Larger application icons for new widgets in the notification center.
  • Solutions to issues relating to mail, notifications, & photos.
With all the releases and changes, it's getting pretty hard to keep up, notes Internet marketing firm fishbat.

Apple is expected to be launching Apple Pay on or around October 20. Many believe that will be the launch date of iOS 8.1, the company points out. Apple Pay is expected to change the way users pay for items by using payment technology built into the device, so they no longer need to carry around credit cards. The current 8.0 version has a credit card icon in the Passbook, but lacks functionality, fishbat observed. Rather than abolishing credit card companies completely, Apple Pay will simply store the credit card information in Passbook, in a secure enclave.

Scott Darrohn, COO, fishbat, said: "
Apple's beta process typically takes months, not weeks, therefore it will be interesting to see if the rumours hold value." 

29 September 2014

Trend Micro rolls out free tools to protect users against Shellshock (the Bash bug)

Trend Micro, a security software and solutions provider, has released license-free tools to help protect web users against the Shellshock or Bash bug across the Mac OSX and Linux platforms. 

Source: Trend Micro infographic.

Broadly publicised the week of 22 September, Shellshock is a vulnerability that can exploit command access to Linux-based systems and adversely impact a majority of the web servers around the world, as well as Internet-connected devices on the Mac OSX platform. The vulnerability has potential to adversely impact a half billion web servers and other Internet-connected devices including mobile phones, routers and medical devices.

"Since this situation has potential to escalate quickly, we are taking immediate preventative steps to help keep the public safe from this unprecedented vulnerability," said Eva Chen, CEO, Trend Micro. "We believe the most responsible course of action is for technology users to remain calm and apply the resources made available from Trend Micro, and others, to create a strong defensive front. By making our tools accessible free of charge to our customers, and beyond, we are trying to address this 'outbreak' to stop a possible epidemic before it can start."
One of the free tools featured, the on-demand BashLite Malware Scanner, will determine if the BashLite malware is resident on Linux systems.

"Shellshock could be notably more widespread than the infamous Heartbleed from earlier this year," said Raimund Genes, CTO, Trend Micro. "Heartbleed was very different in nature and behaviour. With Shellshock the threats are much more severe."

For those unable to implement the Trend Micro wall of protection against the Shellshock threat, Trend Micro's threat defense experts recommend the following steps to help businesses and end-users mitigate the vulnerability:

  • End-users should watch for patches for Mac OSX and implement them immediately.
  • Linux system operators should consider virtually patching until a patch is available from their vendor.
  • Linux/Apache web server operators using BASH scripts should consider retooling those scripts to use something other than BASH until a patch is available.
  • Hosted service customers should contact their service provider to determine if they are vulnerable and find out their remediation plans if they are exposed.
Trend Micro researchers are currently monitoring this vulnerability in the wild to anticipate additional escalations. The company has released a detailed blog post explaining the vulnerability with additional recommendations to stay protected, and created an infographic detailing what the vulnerability is and how it works.