Fortinet

FortinetSecurity

Deep Analysis of New Poison Ivy Variant

Credit to Author: Xiaopeng Zhang| Date: Wed, 23 Aug 2017 13:05:00 +0000

Recently, the FortiGuard Labs research team observed that a new variant of Poison Ivy was being spread through a compromised PowerPoint file. We captured a PowerPoint file named Payment_Advice.ppsx, which is in OOXML format. Once the victim opens this file using the MS PowerPoint program, the malicious code contained in the file is executed. It downloads the Poison Ivy malware onto the victim’s computer and then launches it. In this blog, I’ll show the details of how this happens, what techniques are used by this malware, as well as…

Read More
FortinetSecurity

We Have Seen the Enemy, and It Is Us

Credit to Author: Derek Manky| Date: Wed, 23 Aug 2017 12:55:00 +0000

Fortinet just released its Global Threat Landscape Report for Q2. Much of the data it provides is just what you’d expect. For example, FortiGuard Labs detected 184 billion total exploit attempts in Q2 from 6,300 unique and active exploits. Not only is this is an increase of 30% over Q1, with the growth of IoT and Shadownet resources we expect these numbers to continue to rise dramatically. In addition, 7 in 10 organizations experienced high or critical exploits during the quarter. By any measure, these are alarming numbers. 

Read More
FortinetSecurity

The GDPR: Adding Teeth to Data Privacy

Credit to Author: Drew Del Matto| Date: Tue, 22 Aug 2017 15:50:00 +0000

The Fortinet Security Fabric allows organizations to harness the collective power and intelligence of Fortinet’s portfolio of security solutions to collect and correlate threat intelligence, actively detect and isolate threats, and automate a coordinated response across the entire network. Such an approach allows organizations to extend visibility deep into their infrastructure, and more importantly, into their data, so they know where it is, who and what have access to it. It also allows them to demonstrate compliance…

Read More
FortinetSecurity

Gartner Peer Insights for Enterprise Firewalls: See What Healthcare Leaders Are Saying About Fortinet

Credit to Author: Trish Borrmann | Date: Fri, 18 Aug 2017 13:00:00 +0000

The healthcare industry requires technology that can keep pace with the speed at which medicine is evolving in order to provide patients with the best possible care. Additionally, this technology must meet HIPAA compliance standards to secure protected health information (PHI) from the growing number cyberattacks targeting the healthcare industry. This comes at a time when more devices than ever are accessing healthcare providers’ networks, including the proliferation of connected medical devices in the Internet of Medical Things (IoMT), and…

Read More
FortinetSecurity

The Role of E-Rate in Protecting the Digital K-12 Learning Environment

Credit to Author: Susan Biddle| Date: Fri, 18 Aug 2017 12:58:00 +0000

The K-12 learning environment has moved beyond the physical walls of the classroom thanks to behavioral shifts and digital connectivity. However, robust and speedy network services that are designed to keep student and faculty data secure come with a price tag. The cost of ongoing connectivity and keeping networks secure is a constant barrier for most school districts, but thankfully, the E-rate program gives them an opportunity to do just that. Take a look at the graphic below to see how the classroom environment has evolved, the threats…

Read More
FortinetSecurity

Locky Launches a More Massive Spam Campaign with New “Lukitus” Variant

Credit to Author: Joie Salvio, Rommel Joven and Floser Bacurio| Date: Thu, 17 Aug 2017 21:37:00 +0000

It has just been a week since the variation of Locky named Diablo6 appeared. Now it has launched another campaign more massive than the previous. This time, it uses “.lukitus”, which means “locking” in Finnish, as the extension for the encrypted files. The FortiGuard Lion Team was the first to discover this variant with the help of Fortinet’s advanced  Kadena Threat Intelligence System [1](KTIS) Fig. 1 Encrypted files with .lukitus extension Fig. 2 Familiar Locky ransom note Same Locky, More Spam This…

Read More
FortinetSecurity

Analyzing Android malware using a FortiSandbox

Credit to Author: Axelle Apvrille| Date: Thu, 17 Aug 2017 13:00:00 +0000

In this blog post we will analyze a couple of Android malware samples in the Android VM of the FortiSandbox. We'll also share a few interesting and useful tricks. Running a sample in the VM To run a given sample in the Android VM, you should log into the FortiSandbox, make sure an Android VM is available, and then "Scan Input" / Submit a New File. Next, if the objective is to run the malware in the sandbox, you must make sure to skip "static scan," "AV scan," and "Cloud Query"…

Read More