Earlier this month, FortiGuard Labs researchers published findings about a malware campaign exploiting a PowerPoint vulnerability. Cybercriminals, however, are equal opportunity exploiters, so just recently an interesting targeted malware campaign was found to be using another document vulnerability. Only this time, it’s a Hangul Word Processor (HWP) document leveraging the already known CVE-2015-2545 Encapsulated PostScript (EPS) vulnerability.
https://blog.fortinet.com/2017/09/20/evasive-malware-campaign-abuses-free-cloud-service-targets-korean-speakers
To quote Larry Kudlow: Free market capitalism is the best path to prosperity! Freedom of thought and free markets have led to the greatest advances in living standards in human history. Matters of business and free enterprise are discussed on this blog. Included are company press releases, 3rd party news articles and videos, articles and videos pertaining to small business, and white collar crime.
Search This Blog
Showing posts with label fortinet. Show all posts
Showing posts with label fortinet. Show all posts
Thursday, September 21, 2017
For Cybercriminals, IoT Devices are Big Business, Part Two
In part one of this article, Anthony Giandomenico described how cybercrime has become not only a business, but a big business, designed to generate revenue with predesigned attacks focused on attack vectors that are easy to exploit: IoT devices.
Opportunity is also the land of innovation
Because cybercriminals are focusing more on attacks that target critical infrastructure based on new, interconnected technologies, they don’t have to spend enormous resources and development cycles on figuring out how to break into these systems using complex zero-day attacks. Instead, they can spend more of their resources on making their exploits more difficult to detect, more effective by introducing things like worm capabilities to spread infections further and faster, adding multivector capabilities in order to run exploits on a wider range of vulnerable systems, and developing intelligent, multilayered malware that provides a lot of options for stealing data or compromising systems.
https://blog.fortinet.com/2017/09/20/for-cybercriminals-iot-devices-are-big-business-part-two
For Cybercriminals, IoT Devices are Big Business, Part One
When people think of cybercrime, they tend to think of geeks in dark rooms staring into computer monitors trying to figure out some new way to infiltrate a network. And historically, that was a pretty accurate assessment.
https://blog.fortinet.com/2017/09/20/for-cybercriminals-iot-devices-are-big-business-part-one
https://blog.fortinet.com/2017/09/20/for-cybercriminals-iot-devices-are-big-business-part-one
Fortinet Partner Insider
Network security is a complex subject that requires those in charge to stay on the lookout for the latest industry news and events. Here, you, our channel partners, will find all of the information you need to answer your current and prospective customers’ questions moving into the fall. Channel partners can also find several new resources and blog posts to help quickly find the proper product(s) for your customers, as well as answer questions about building a strong cybersecurity strategy for today’s threats.
https://blog.fortinet.com/2017/09/20/fortinet-partner-insider
https://blog.fortinet.com/2017/09/20/fortinet-partner-insider
Five Cyber Threats Every Security Leader Must Know About
Networks are evolving at an unprecedented rate. Physical and virtual environments, private and public clouds, and a growing array of IoT and endpoint devices are all dramatically expanding the potential attack surface. Protecting highly elastic network environments present cybersecurity leaders with a complex array of security challenges. In part, this is because cyberthreats continue to grow in both scope and severity in order to exploit the growing number of new attack vectors. As a result, the number of recurring high profile breaches, including ransomware attacks and other cyber incidents, continue to grow at a mind numbing pace in spite of billions of dollars being spent on cybersecurity resources
https://blog.fortinet.com/2017/09/20/five-cyber-threats-every-security-leader-must-know-about
https://blog.fortinet.com/2017/09/20/five-cyber-threats-every-security-leader-must-know-about
Rewriting IDAPython Script objc2_xrefs_helper.py for Hopper
Security researchers have identified more and more Mac OS malware attacks over the past two years. In June 2017, Rommel Joven and Wayne Chin Yick Low from Fortinet’s Fortiguard Labs found and analyzed a new ransomware targeted at Mac OS. Most malware for Mac OS was developed in the Objective-C programming language. A good introduction to reverse engineering Cocoa applications can be found here. In that blog post, the researcher released an IDAPython script named objc2_xrefs_helper.py that can only be executed in IDA Pro. As you know, IDA Pro is the gold standard for disassemblers. However, IDA Pro Licenses start at $1409 (you can refer to that here). So this can be extremely cost prohibitive for many people. One good alternative is the Hopper Disassembler for Mac OS. A Hopper Disassembler v4 Personal License is only $99.00.
https://blog.fortinet.com/2017/09/19/rewriting-idapython-script-objc2-xrefs-helper-py-for-hopper
https://blog.fortinet.com/2017/09/19/rewriting-idapython-script-objc2-xrefs-helper-py-for-hopper
A Look Into The New Strain Of BankBot
BankBot is a family of Trojan malware targeting Android devices that surfaced in the second half of 2016. The main goal of this malware is to steal banking credentials from the victim’s device. It usually impersonates flash player updaters, android system tools, or other legitimate applications. Once installed, it hides itself and then tricks the user into typing his or her credentials into fake bank web pages that have been injected onto the device’s screen.
https://blog.fortinet.com/2017/09/19/a-look-into-the-new-strain-of-bankbot
https://blog.fortinet.com/2017/09/19/a-look-into-the-new-strain-of-bankbot
A Wrap Up of ToorCon 19 at San Diego
ToorCon 19 San Diego was held Monday August 28th to Sunday September 3rd, 2017 at The Westin San Diego. It included three parts. The first was training workshops focused on various aspects of computer security. These took place on Aug 28-31. The second was a Seminar held on Sep 1. The third part was the formal Conference that ran from Sep 1-3.
https://blog.fortinet.com/2017/09/18/a-wrap-up-of-toorcon-19-at-san-diego
https://blog.fortinet.com/2017/09/18/a-wrap-up-of-toorcon-19-at-san-diego
Sunday, February 26, 2017
How Advanced Threat Protection Can Help Protect Financial Data
Technology integration in the financial services industry has opened opportunities that could only be dreamed of a few decades back. Around the turn of the millennium, we began seeing banks set up websites for internet-based banking, and about a decade later, mobile banking customers began tapping their smartphones to make payments at retail stores.
Fortinet Blog
Fortinet Blog
FortiClient Scores High in the Latest Advanced Endpoint Protection Report from NSS Labs
Fortinet is highly committed to the public testing of our products and solutions. We participate in dozens of tests from variety of labs that use a spectrum of testing and analysis approaches. Not only do test results give customers a snapshot into the efficacy and value of a solution, but it also provides us with an opportunity to evaluate the effectiveness of our solutions in a variety of settings, allowing us to more effectively improve the quality of our technology.
Fortinet Blog
Fortinet Blog
Subscribe to:
Posts (Atom)