ESET launches Version 3.0 of Secure Authentication

Bratislava – ESET, a global leader in cybersecurity, has launched Version 3.0 of ESET Secure Authentication (ESA), a multifactor authentication solution that allows businesses of all sizes to secure mobile devices, prevent data breaches, and meet compliance requirements. This new version of the solution brings a range of updates, including the introduction of the Identity Connector and support for biometric authentication.

The Identity Connector gives customers the option to employ ESA to protect any service or application that uses a third-party identity provider, via the SAML authentication protocol integration. This significantly extends integration capabilities, now allowing customers to use ESA to protect access to a wide range of services and environments, such as email, VPN, Office 365 or Dropbox.

Version 3.0 also introduces support for native biometric authentication in ESA mobile apps, meaning users can now use integrated fingerprint scanners and facial recognition when approving authentication requests.

The new Notification Center gives users the option to configure their own notifications, so they can be proactively informed without the need to be logged in. The update also provides major performance improvements, bringing customers a robust solution to cover larger deployments.

Vladimír Maťovčík, senior product manager at ESET, states: “Business security solutions need to be reliable, be easy to use and cause minimal impact to a company’s processes. With an increasing need for organizations to protect a range of devices and environments, ESET Secure Authentication provides a simple, effective mobile-based solution that secures data and cloud access without affecting employee productivity.”

“The introduction of the Identity Connector increases the solution’s level of security, whilst the improved performance and addition of support of iOS and Android biometrics makes the experience even smoother for users.” 

For further information on ESET Secure Authentication, click here.  

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET to Lead Linux Malware Workshop and Showcase Groundbreaking Amazon Echo KRACK Research at RSA 2020

Bratislava, Slovakia – January 23, 2020 ESET, a global leader in IT security, today announced a number of activities at next month’s RSA Conference 2020 (February 24-28 in San Francisco). 

ESET Malware Researcher Marc-Etienne M. Léveillé will lead a main stage workshop titled “Hunting Linux Malware for Fun and Flags.” The 50-minute workshop will take place on February 27 at 1:30 PM at Moscone West 3002. Attendees will learn to fight real-world Linux malware targeting server environments and to search for malicious processes and concealed backdoors in a compromised web server. Several examples of malware will be demonstrated with increasing layers of complexity, from scripts to ELF binaries with varying degrees of obfuscation.

ESET Senior Malware Researcher Robert Lipovský and Senior Detection Engineer, Štefan Svorenčík will present a 30-minute session on “Kr00k: How KRACKing Amazon Echo Exposed a Billion+ Vulnerable Wi-Fi Devices” on Wednesday, February 26 at 3:00pm PT at Moscone South. 

On the RSA trade show floor, ESET will be located at booth #753 in the South Hall. Senior Malware Researcher Robert Lipovský will discuss ESET’s latest cutting-edge threat research, including Operation Ghost and KRACKing the Amazon Echo. Malware Removal Support Supervisor James Rodewald will be leading demonstrations of ESET’s award-winning enterprise, SMB and consumer products. Malware Researcher Marc-Etienne M. Léveillé will also review his conference presentation and answer questions from attendees. 

Directly outside the conference, ESET will be running a four-day contest. Attend any of ESET’s inspiring presentations or live demos and get a chance to win the newest MacBook Pro 13, an iPhone 11, iPad, or Apple Watch in a prize raffle. Please see here for more details and contest rules. 

“RSA is a fantastic opportunity for our customers – both current and prospective – to see our multilayered suite of security solutions in action,” said Tony Anscombe, chief security evangelist at ESET. “The cybersecurity landscape has evolved drastically over the past decade, and we expect this to continue in the years to come. ESET is proud to be at the forefront of the field, and we are looking forward to showcasing our groundbreaking research, both on stage and at our trade show booth. We’re excited to meet and talk to attendees next month at RSA.”

Want to meet on-site with ESET at RSA? Please visit https://www.eset.com/us/rsac/.

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries.

NEW GREYCORTEX AREA MANAGER – ALENA ŘEZNÍČKOVÁ

GREYCORTEX is happy to announce that beginning January 1st, Alena Řezníčková will be the new Area Manager for the Czech Republic and Slovakia. Řezníčková has been working in the IT security field since 1992. She has held business and managerial positions in several well-known Czech and international companies, including AEC, ASSECO, PCS, ANECT, McAfee, and Intel Czech Tradings. Prior to assuming the Area Manager role, she worked with GREYCORTEX for several months as an external consultant.
“During the time I have worked with the GREYCORTEX team, I’ve seen for myself that MENDEL, the GREYCORTEX solution for network security monitoring, is a unique product with great potential. The GREYCORTEX team is made up of committed and determined professionals with great personal qualities. It is fascinating to continually experience the “wow effect” when presenting MENDEL to customers and visualizing their networks; since, with MENDEL, they can see what is happening inside their infrastructure. Our clients and customers appreciate that they are part of the team in terms of discussions about our road map and the development of the solution. I can see my main mission in these two areas: strengthening the partner channel and expanding the partner network, including the full lifecycle of cybersecurity management, further leveraging experience and customer needs to develop our solutions,” said Řezníčková.
GREYCORTEX CEO, Petr Chaloupka added: “Alena has many years of experience working in companies offering cyber security solutions and in managing business teams. In previous positions, especially as Country Manager of McAfee (later Intel), she managed to build mutually beneficial partnerships with technology companies in the Czech Republic and Slovakia. I appreciate her involvement in the activities of the Czech branch of AFCEA and long-term relationships with key personalities of IT security.”

Mozilla緊急發布Firefox零時差漏洞更新

Mozilla於1月上旬發佈Firefox 72.0.1及Firefox ESR 68.4.1更新,以修補已被駭客開採的CVE-2019-17026安全漏洞,該漏洞藏匿在Firefox的IonMonkey JIT編譯器中,在設定陣列元素時,若採用錯誤的別人資訊,即會造成類型混淆(Type Confusion)。類型混淆可能導致記憶體越界存取,而讓程式當掉或允許駭客執行任意程式。據了解已有駭客利用該漏洞展開目標式攻擊,但攻擊手法的細節所知不多,此一漏洞同時影響Windows、macOS及Linux平台的Firefox與Firefox ESR,ESET資安專家建議用戶應儘快部署取用新的版本。

*****若有任何資安需求,歡迎洽詢ESET資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://www.eset.tw/

原文出處:https://www.welivesecurity.com/2020/01/09/mozilla-rushes-patch-firefox-zero-day/

 

GREYCORTEX MENDEL網路流量分析系統收集數百種特徵以檢測網路威脅

【GREYCORTEX MENDEL(人工智慧監控軟體)】針對企業網路流量進行深度剖析,收集流量的數百種特徵,再藉由機器學習,找出潛伏在內部的威脅,達到較為全面保護整體網路環境的目的
 
 
偵測企業內部網路流量,找出可能潛在的威脅,稱做網路流量分析(Network Traffic Analysis,NTA)系統,近年陸續有相關產品引進到臺灣,今年年初,代理ESET防毒軟體的臺灣二版,他們開始提供GreyCortex Mendel解決方案,訴求企業能藉著這套系統,分析流量封包,監控內部網路的行為,進行找出網路環境中,可能存在的弱點或是攻擊事件。
 
這款網路流量分析系統運用了機器學習,並能深度檢測流量內容,找出未知的威脅。原廠也指出,Mendel能處理比NetFlow多出6倍的功能,具備應用程式的感測,以及使用者身分識別的能力,同時能區隔人類與機器人執行的行為。有別於許多同類型產品收取NetFlow流量,這套系統支援進階安全網路評量(Advanced Security Network Metrics,ASNM)協定,會收集網路流量裡的數百種特徵,做為分析資料的來源,以便加以快速檢測。
 
而針對現今網路流量幾乎都受到加密保護的情況,Mendel也能夠拆解,並且支援最新的TLS 1.3。
 
藉著與企業已經部署的防火牆整合,Mendel能進一步封鎖指定的連接埠,阻斷所發現的攻擊事件。
 
原廠也強調Mendel能檢測的裝置類型相當廣泛,能涵蓋員工自行攜帶的設備(BYOD),以及應用相當廣泛的物聯網(IoT)裝置等。由於Mendel也會收集額外的感知資料,原廠宣稱,可更迅速彙整出攻擊事件的樣貌。
 
在建置架構的部分,Mendel由1個收集器(Collector)與多個感測器(Sensor)組合而成,企業可依據網路環境的組態,增加或是減少所需的感測器數量,而這些設備的型態,可以是實體設備或是虛擬機器。
 
產品資訊
●系統組成元件:收集器(Collector)、感測器(Sensor)
●部署型式:純軟體或虛擬機器
●系統需求:8核心處理器、32GB記憶體、500GB儲存空間、2張網路卡
 
*原文出處:<iThome> https://www.ithome.com.tw/review/133852

Amid student protests, Winnti Group targets Hong Kong universities, ESET discovers

BRATISLAVA, MONTREAL – ESET researchers have recently discovered a new campaign by the Winnti group. This time, Hong Kong universities were the desired target. ESET’s machine-learning engine detected a unique, malicious sample on multiple computers belonging to two Hong Kong universities. In addition to the two confirmed compromised universities, ESET has indications that at least three additional universities may have been affected. The attackers were interested in stealing information from the victims’ machines. This campaign of the Winnti Group was taking place as widespread civic protests swept Hong Kong, including the territory’s universities.

The latest research into Winnti Group, previously responsible for high-profile supply-chain attacks against the video game and software development industry as well as attacks against healthcare and education sectors, confirms that the group is still using its flagship ShadowPad backdoors. However, in the campaign against Hong Kong universities, ShadowPad’s launcher was replaced with a new and simpler version detected by ESET products as Win32/Shadowpad.C.

“Both ShadowPad and Winnti, found at these universities in November 2019, contain campaign identifiers and command & control URLs matching the name of the universities, which indicates a targeted attack,” says Mathieu Tartare, leading ESET researcher into the Winnti Group.

“ShadowPad is a multi-modular backdoor and, by default, every keystroke is recorded using the Keylogger module. The use of this module by default indicates that the attackers are interested in stealing information from the victims’ machines. In contrast, the variants we described in our earlier whitepaper didn’t even have that module embedded,” elaborates Tartare on the discovery.

For more technical details about the latest discovery into the Winnti Group, read the blog post Winnti Group targeting universities in Hong Kong on WeLiveSecurity.com. ESET researchers recently published a whitepaper updating our understanding of the arsenal of the Winnti Group as well. Make sure to follow ESET research on Twitter for the latest news from ESET Research. 



About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries.