Fortinet

FortinetSecurity

The Cybersecurity Threats Presented by Financial Services Remote Employees

Credit to Author: Bill Hogan| Date: Fri, 12 May 2017 11:18:00 -0700

Security and IT professionals at large enterprises across all industries are faced with the daily task of having to secure an expanding attack surface. Vulnerable points of entry used to live within the organization’s walls, where firewalls and inline security tools could protect them. But networks have now evolved into a constantly evolving, borderless environment thanks to cloud usage, the Internet of Things (IoT), and an increasingly mobile workforce. Technological advances, paired with a surge of digitally savvy employees flooding the…

Read More
FortinetSecurity

Internet2: A Collaborative Power That Needs to be Secured

Credit to Author: Susan Biddle| Date: Fri, 19 May 2017 09:23:01 -0700

For what started as a research network that was largely owned and operated by top universities, the Internet as we know it today has become much more. In 1969, ARPANET carried the first data packets between two separate nodes. During its genesis, ARPANET included the University of California, Los Angeles and the Stanford Research Institute before adding the University of Utah and University of California, Santa Barbara. What began as a 4-node network in 1969 had swelled to include 213 hosts by 1981. From there, it took off.  The Internet’s…

Read More
FortinetSecurity

Spring Parade for Refreshed Android Marcher

Credit to Author: Dario Durando, Kenny Yang, David Maciejak| Date: Wed, 17 May 2017 21:14:16 -0700

Android malware continues to grow exponentially now that it has overtaken the top position as the most popular OS (across all platforms), making it the target of choice for malware authors. Android Marcher is an Android banker malware that has been on the FortiGuard Labs radar since late 2013. Since that time it has been seen in a number of campaigns targeting many different banks and countries. And now, Marcher has once again resurfaced with a new campaign. Over the past few months we have observed it masking itself in a variety of ways…

Read More
FortinetSecurity

New Loki Variant Being Spread via PDF File

Credit to Author: Xiaopeng Zhang and Hua Liu| Date: Wed, 17 May 2017 18:24:02 -0700

The Loki Bot has been observed for years. As you may know, it is designed to steal credentials from installed software on a victim’s machine, such as email clients, browsers, FTP clients, file management clients, and so on. FortiGuard Labs recently captured a PDF sample that is used to spread a new Loki variant. In this blog, we will analyze how this new variant works and what it steals. The PDF sample Figure 1. Content of the PDF sample The PDF sample only contains one page, shown above, which includes some…

Read More
FortinetSecurity

WannaCry FAQ – Take-aways and Learnings

Credit to Author: Aamir Lakhani| Date: Wed, 17 May 2017 10:58:45 -0700

WannaCry FAQ: How does WannaCry spread? WannaCry has multiple ways of spreading. Its primary method is to use the Backdoor.Double.Pulsar backdoor exploit tool released last March by the hacker group known as Shadow Brokers, and managed to infect thousands of Microsoft Windows computers in only a few weeks. Because DoublePulsar runs in kernel mode, it grants hackers a high level of control over the compromised computer system.

Read More
FortinetSecurity

Zero Patch IoT Environment

Credit to Author: Axelle Apvrille| Date: Wed, 17 May 2017 09:28:10 -0700

Over the last few months or years I have reported vulnerabilities on several IoT devices. None have been patched so far, and I think it is time to discuss the situation openly. One of the issues I have faced several times is the zero-security-culture phenomenon. Some of those IoT companies were typically very small and young, with sadly neither the skills nor the resources to fix security issues. For example, I remember sending several vulnerabilities to a given company. I got an automated response for the first email (ok),…

Read More
FortinetSecurity

WannaCry: Evolving History from Beta to 2.0

Credit to Author: Kyle Yang| Date: Mon, 15 May 2017 07:12:56 -0700

The WannaCry malware was responsible for a massive infection beginning that affected organizations and systems around the world. FortiGuard Labs has been monitoring this malware carefully. We have provided an analysis of this attack, along with how to protect your organization here.  In this blog post I’ll briefly describe some of the distinct characteristics of each version of this malware, from beta to the latest 2.0 version, and share some interesting findings. Beta Version: We discovered this beta version around Feb 9th,…

Read More