Trend Cloud Security Blog – Cloud Computing Experts

The State of Cloud and Virtualization Security

For the last few months, we’ve been conducting a cloud, virtualization, and VDI security survey of 1200 IT professionals from larger companies in 6 countries around the world. Not only did I get to help shape the questions on the survey, I’ve also been on the team interpreting the results. We’ve learned more than a few things we actually were not expecting to learn. Here is a collection of the most interesting top findings about the state of cloud and virtualization security. I’ll be blogging about some of them in more detail over the next few weeks, but in the meantime, here is the big... read more

Ambient Cloud News: Skype protocol has been reverse engineered

This is pretty cool. I gave a talk last week at the Glue Conference in Denver about how ambient clouds ( http://cloud.trendmicro.com/good-clouds-evil-clouds-why-microsoft-has… )work and even used Skype as an example of a massive-scale ambient cloud. This case raises some very important new questions around ambient clouds. For instance, if you create an ambient cloud, one that you control using your own protocol, but where you have no control over when an endpoint may join it, what are the legal implications if someone else uses your protocol? In an open source world, slapping a lawsuit on... read more

Chrome OS: So secure we don’t need security?

With the launch announcements of various Google Chrome netbooks, the focus of the press and security companies alike is beginning to take a closer look at the security promises made and also at some of the more ’media friendly‘ statements such as, “…users don’t have to deal with viruses, malware and security updates”.   Let’s have a look at some of the security features of Chrome OS:   1 – Get out of my playpen. Each process runs in its own sandbox.  Effectively this means that if an application is malicious or compromised, it is unable to interact with or otherwise affect... read more

A Tale: The Snack Supplier, the Vending Machine, and the Cloud

I recently had an interesting chat with the operator of our snack vending machine while making a coffee in the kitchen. She was restocking our machine and had her iPad sitting on the table. In their 2 person company they now have 2 iPads and a PC. They do their inventory control and tracking while onsite at customer premises via the iPad. Then they sync it with their PC and, using an online storage solution they transfer it to the cloud; this then syncs with their online accounting package. Her reason was very, very simple: she wants to reduce the amount of time they spend on bookkeeping and back-office... read more

IPv6 is here. How does this affect email?

Part 1 of 2 parts IPv6 will change how we use the internet, again. To the typical user, there is no difference; web sites work the same. But email is a different story. When using IPv6, addresses are allocated in a different manner. Most end-users today get one IP address, which is shared between multiple machines using a Network Address Translation (NAT) router. In IPv6, each user gets an address block – a /64 – of address space. This is great news, because end-to-end application on the Internet will work much better, and there will be no NAT in the way. A /64 is a huge amount of space –... read more

New type of cloud emerges: Exploits as a Service (EaaS)

For years now, if you knew where to shop on the shady side of the Internet cloud, you could pick up a botnet for cheap. But it was so much work to log in to IRC and pay with egold that a busy cybercriminal just couldn’t be bothered. That’s not a problem anymore, thanks to Robopak. Applying the latest cloud provisioning and marketing analytics technologies, they’ve created an entirely new type of cloud service, Exploits as a Service, or EaaS. Robopak’s EaaS lets you pay as little as $30 per day to access Java, PDF, and IE exploits and roll them out to build your cybercrime... read more

Android – the “Braveheart” of Mobile Devices

Not too long ago, a friend of mine switched from iPhone to Android and he was quite loud about it on his Facebook wall, exclaiming that it was nice to have a phone that let you “make your own decisions.” This is a pretty common theme that I hear again and again from newly converted Android devotees and I think it’s pretty cool because let’s face it, our phones are an extension of our personalities.  Whether it’s the ability to use removable storage or the ability to install any app you want, Android certainly offers the most freedom of any of the popular smartphones... read more

Conflict of Interest Leads to Big Malware Attack

(Ed. note: While the following does not strictly deal with “cloud security,” we thought it was of such a degree of importance to post it here.) Today’s disclosure by Google and Microsoft that they were tricked into serving malware highlights an inherent conflict of interest between advertising-based businesses and the security needs of their customers. Ad networks like Google and MSN get paid when they sell ads, so they naturally focus on being the best at selling ads. Because these ad networks don’t get paid to keep people’s computers secure, they spend just enough on security... read more

New Adobe Flash Critical Vulnerability Exploited in the Wild.

Adobe has issued a security advisory APSA 10-03 describing a new critical vulnerability in its products. This time, the primary target is Flash Player with multiple platforms—Windows, Mac, Linux, Solaris, and Android—all affected and is currently being exploited in the wild. Current versions of Acrobat and Reader—the target of last week’s vulnerability—are also affected by the said exploit although Adobe states that in-the-wild attacks against these have not yet been seen. Trend Micro detects malicious ShockWave Flash (.SWF) files exploiting this vulnerability as TROJ_SWIF.HEL. This functions... read more

Catch the Cloud Before It Chases You

Are you still a skeptic about cloud computing? Do you remember when you refused to bank online because it couldn’t be safe? I do. In fact, I even remember working with one of the leading banks in Canada when the CIO declared that no employees should have access to the Internet—for any business reason, ever. He did not last long in his job. Over the past 15 years our reliance on the Internet has steadily increased, encouraged by advancements in technology (including security), a culture of instant gratification and an obsession with efficiency. After a year of media frenzy, some of us are still... read more

« Previous Entries