AV-Comparatives recognizes ESET consumer products with gold medals in cybersecurity awards

BRATISLAVA, February 6, 2020 – ESET, a global leader in cybersecurity, has been recognized with gold and bronze awards in the AV-Comparatives Summary Report 2019. AV-Comparatives, a leading independent testing organization, uses one of the largest sample collections worldwide to create a real-world environment for highly accurate testing. Their Summary Report 2019 provides commentary on the consumer antivirus products tested over the course of the year, and highlights the high-scoring products from the different tests that took place over the 12 months.

The report looked at consumer Windows products from 16 different vendors, with excellent results for ESET, taking awards in three categories: Overall Performance (Low System Impact), Enhanced Real-World Test (Advanced Threat Protection), and the False Positive Test.

Overall Performance (Low System Impact)

ESET was awarded a gold medal in the Low System Impact category, which assesses each product’s impact on system speed and performance. ESET has consistently achieved great results in this category, improving on its silver award in the same category in 2018.

Enhanced Real-World Test (Advanced Threat Protection)

ESET took a gold medal in the Advanced Threat Protection category, which is a new category for 2019 and 2020. This test addresses a program’s ability to protect against advanced targeted and fileless attacks. ESET was also one of only two vendors to block all 15 targeted attacks in the testing process.

False Positive Test

ESET was awarded a bronze medal in the False Positive Test. As the report notes, false positives can cause as much trouble as a real infection, and avoiding them is a crucial element of any antivirus product. AV-Comparatives carried out extensive false-positive testing as part of the Malware protection tests and the Real-World Protection Test.

Commenting on the results, Jiří Kropáč, head of threat detection labs at ESET, said: “ESET’s recognition from AV-Comparatives is testament to our dedication to our customers and our promise to always deliver the best in IT security solutions. Ensuring consumers are equipped with cutting-edge protection against the latest threats is extremely important to us. We are honored to receive these awards and to be recognized as a key player in making technology safer for everyone.”

Read AV-Comparative’s Summary Report 2019 for more information.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET launches Version 3.0 of Secure Authentication

Bratislava – ESET, a global leader in cybersecurity, has launched Version 3.0 of ESET Secure Authentication (ESA), a multifactor authentication solution that allows businesses of all sizes to secure mobile devices, prevent data breaches, and meet compliance requirements. This new version of the solution brings a range of updates, including the introduction of the Identity Connector and support for biometric authentication.

The Identity Connector gives customers the option to employ ESA to protect any service or application that uses a third-party identity provider, via the SAML authentication protocol integration. This significantly extends integration capabilities, now allowing customers to use ESA to protect access to a wide range of services and environments, such as email, VPN, Office 365 or Dropbox.

Version 3.0 also introduces support for native biometric authentication in ESA mobile apps, meaning users can now use integrated fingerprint scanners and facial recognition when approving authentication requests.

The new Notification Center gives users the option to configure their own notifications, so they can be proactively informed without the need to be logged in. The update also provides major performance improvements, bringing customers a robust solution to cover larger deployments.

Vladimír Maťovčík, senior product manager at ESET, states: “Business security solutions need to be reliable, be easy to use and cause minimal impact to a company’s processes. With an increasing need for organizations to protect a range of devices and environments, ESET Secure Authentication provides a simple, effective mobile-based solution that secures data and cloud access without affecting employee productivity.”

“The introduction of the Identity Connector increases the solution’s level of security, whilst the improved performance and addition of support of iOS and Android biometrics makes the experience even smoother for users.” 

For further information on ESET Secure Authentication, click here.  

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET to Lead Linux Malware Workshop and Showcase Groundbreaking Amazon Echo KRACK Research at RSA 2020

Bratislava, Slovakia – January 23, 2020 ESET, a global leader in IT security, today announced a number of activities at next month’s RSA Conference 2020 (February 24-28 in San Francisco). 

ESET Malware Researcher Marc-Etienne M. Léveillé will lead a main stage workshop titled “Hunting Linux Malware for Fun and Flags.” The 50-minute workshop will take place on February 27 at 1:30 PM at Moscone West 3002. Attendees will learn to fight real-world Linux malware targeting server environments and to search for malicious processes and concealed backdoors in a compromised web server. Several examples of malware will be demonstrated with increasing layers of complexity, from scripts to ELF binaries with varying degrees of obfuscation.

ESET Senior Malware Researcher Robert Lipovský and Senior Detection Engineer, Štefan Svorenčík will present a 30-minute session on “Kr00k: How KRACKing Amazon Echo Exposed a Billion+ Vulnerable Wi-Fi Devices” on Wednesday, February 26 at 3:00pm PT at Moscone South. 

On the RSA trade show floor, ESET will be located at booth #753 in the South Hall. Senior Malware Researcher Robert Lipovský will discuss ESET’s latest cutting-edge threat research, including Operation Ghost and KRACKing the Amazon Echo. Malware Removal Support Supervisor James Rodewald will be leading demonstrations of ESET’s award-winning enterprise, SMB and consumer products. Malware Researcher Marc-Etienne M. Léveillé will also review his conference presentation and answer questions from attendees. 

Directly outside the conference, ESET will be running a four-day contest. Attend any of ESET’s inspiring presentations or live demos and get a chance to win the newest MacBook Pro 13, an iPhone 11, iPad, or Apple Watch in a prize raffle. Please see here for more details and contest rules. 

“RSA is a fantastic opportunity for our customers – both current and prospective – to see our multilayered suite of security solutions in action,” said Tony Anscombe, chief security evangelist at ESET. “The cybersecurity landscape has evolved drastically over the past decade, and we expect this to continue in the years to come. ESET is proud to be at the forefront of the field, and we are looking forward to showcasing our groundbreaking research, both on stage and at our trade show booth. We’re excited to meet and talk to attendees next month at RSA.”

Want to meet on-site with ESET at RSA? Please visit https://www.eset.com/us/rsac/.

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries.

NEW GREYCORTEX AREA MANAGER – ALENA ŘEZNÍČKOVÁ

GREYCORTEX is happy to announce that beginning January 1st, Alena Řezníčková will be the new Area Manager for the Czech Republic and Slovakia. Řezníčková has been working in the IT security field since 1992. She has held business and managerial positions in several well-known Czech and international companies, including AEC, ASSECO, PCS, ANECT, McAfee, and Intel Czech Tradings. Prior to assuming the Area Manager role, she worked with GREYCORTEX for several months as an external consultant.
“During the time I have worked with the GREYCORTEX team, I’ve seen for myself that MENDEL, the GREYCORTEX solution for network security monitoring, is a unique product with great potential. The GREYCORTEX team is made up of committed and determined professionals with great personal qualities. It is fascinating to continually experience the “wow effect” when presenting MENDEL to customers and visualizing their networks; since, with MENDEL, they can see what is happening inside their infrastructure. Our clients and customers appreciate that they are part of the team in terms of discussions about our road map and the development of the solution. I can see my main mission in these two areas: strengthening the partner channel and expanding the partner network, including the full lifecycle of cybersecurity management, further leveraging experience and customer needs to develop our solutions,” said Řezníčková.
GREYCORTEX CEO, Petr Chaloupka added: “Alena has many years of experience working in companies offering cyber security solutions and in managing business teams. In previous positions, especially as Country Manager of McAfee (later Intel), she managed to build mutually beneficial partnerships with technology companies in the Czech Republic and Slovakia. I appreciate her involvement in the activities of the Czech branch of AFCEA and long-term relationships with key personalities of IT security.”

Mozilla緊急發布Firefox零時差漏洞更新

Mozilla於1月上旬發佈Firefox 72.0.1及Firefox ESR 68.4.1更新,以修補已被駭客開採的CVE-2019-17026安全漏洞,該漏洞藏匿在Firefox的IonMonkey JIT編譯器中,在設定陣列元素時,若採用錯誤的別人資訊,即會造成類型混淆(Type Confusion)。類型混淆可能導致記憶體越界存取,而讓程式當掉或允許駭客執行任意程式。據了解已有駭客利用該漏洞展開目標式攻擊,但攻擊手法的細節所知不多,此一漏洞同時影響Windows、macOS及Linux平台的Firefox與Firefox ESR,ESET資安專家建議用戶應儘快部署取用新的版本。

*****若有任何資安需求,歡迎洽詢ESET資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://www.eset.tw/

原文出處:https://www.welivesecurity.com/2020/01/09/mozilla-rushes-patch-firefox-zero-day/

 

Amid student protests, Winnti Group targets Hong Kong universities, ESET discovers

BRATISLAVA, MONTREAL – ESET researchers have recently discovered a new campaign by the Winnti group. This time, Hong Kong universities were the desired target. ESET’s machine-learning engine detected a unique, malicious sample on multiple computers belonging to two Hong Kong universities. In addition to the two confirmed compromised universities, ESET has indications that at least three additional universities may have been affected. The attackers were interested in stealing information from the victims’ machines. This campaign of the Winnti Group was taking place as widespread civic protests swept Hong Kong, including the territory’s universities.

The latest research into Winnti Group, previously responsible for high-profile supply-chain attacks against the video game and software development industry as well as attacks against healthcare and education sectors, confirms that the group is still using its flagship ShadowPad backdoors. However, in the campaign against Hong Kong universities, ShadowPad’s launcher was replaced with a new and simpler version detected by ESET products as Win32/Shadowpad.C.

“Both ShadowPad and Winnti, found at these universities in November 2019, contain campaign identifiers and command & control URLs matching the name of the universities, which indicates a targeted attack,” says Mathieu Tartare, leading ESET researcher into the Winnti Group.

“ShadowPad is a multi-modular backdoor and, by default, every keystroke is recorded using the Keylogger module. The use of this module by default indicates that the attackers are interested in stealing information from the victims’ machines. In contrast, the variants we described in our earlier whitepaper didn’t even have that module embedded,” elaborates Tartare on the discovery.

For more technical details about the latest discovery into the Winnti Group, read the blog post Winnti Group targeting universities in Hong Kong on WeLiveSecurity.com. ESET researchers recently published a whitepaper updating our understanding of the arsenal of the Winnti Group as well. Make sure to follow ESET research on Twitter for the latest news from ESET Research. 



About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET

Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. ESET NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100 Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries.

勒索病毒與企業安全:新白皮書

勒索病毒依舊構成嚴重威脅;本白皮書闡述企業為降低風險,需要了解的信息和採取的措施

2018年全年,不法份子繼續運用勒索病毒,針對大型機構發起攻擊。今天,我們發布了一份新的白皮書,闡述為何稱勒索病毒仍對公司企業構成嚴重威脅,含大中小型組織機構在內,以及相關組織機構可採取哪些措施,降低勒索病毒攻擊所造成的風險和損失。

本白皮書重點討論,受勒索病毒攻擊所威脅的三大重災區:遠程訪問、電子郵件和供應鏈,旨在幫助首席執行官、首席信息官、首席信息安全官和企業風險經理了解,勒索病毒威脅現狀及其值得關注的幾大演變領域。有關勒索病毒響應措施的詳細技術探討,請見本文附件。

勒索病毒:企業視角

下載勒索病毒白皮書

目標更廣、胃口更高

倘若貴司近期未曾遭受勒索病毒攻擊,可能會想當然地以為,這一威脅已塵封在網絡犯罪的歷史檔案庫之中。產業期刊專題文章,也將勒索病毒稱為“2017年產物,與採集數字貨幣相比,呈減少趨勢”。但在本質上,這些專題文章所反映的事實是,儘管數字貨幣採集案例的檢測數量一直處於上升勢頭,同時勒索病毒明顯活躍跡象逐漸減少​​,但需要澄清的是,勒索病毒依然構成各類組織機構不得不面臨的一大嚴重威脅。


以美國亞特蘭大市發生的情況為例。五大市政部門遭受勒索病毒攻擊:涵蓋懲教、水利資源管理、人力資源、園林休閒設施建設及城市規劃部門。一系列城市職能受到嚴重影響,含民眾無法網上繳納水費和購買公交車票在內。該市的哈茲菲爾德傑克遜國際機場,也被迫關停公共Wi-Fi服務長達一周時間。雖然亞特蘭大市政府正義凜然地拒絕繳納五萬美元贖金,但事件本身所造成的經濟損失卻高達數百萬美元(最終可能接近1700萬美元)。


截至本白皮書撰文之時,勒索病毒已攻陷各州及地方政府和教育行業內的大量機構,造成重大損失。我們之所以了解這些情況,是因為此類機構通常承擔社會通報義務。醫療保健行業的情況也大致相同,由於患者生命安全受到威脅,政府機關不得不下令強制關停部分醫療機構。


但對於那些無需承擔數據安全洩密事件披露義務的​​機構,情況又如何呢?不妨合理斷言,遭受勒索病毒目標性攻擊的商業企業很可能將竭力掩蓋事實,以免成為新聞輿論的焦點。也就是說,對於勒索病毒所造成的威脅規模,無法單憑公開新聞報導來判斷。通過採訪合作推廣商及安全廠商的客服人員,我們了解到,勒索病毒仍是給各行各業造成巨額損失的一大罪魁禍首,受害者層出不窮。

利用遠程桌面協議推波助瀾

我們還了解到,2018年期間發生、針對醫療保健機構和政府機關的一系列勒索病毒攻擊事件,均有著勒索病毒家族SamSam(ESET產品將其檢測為MSIL/Filecoder.Samas)的身影。 SamSam通過“暴力破解已啟用遠程桌面協議的終端設備”(美國衛生部)發起攻擊,滲透組織機構內網。


啟用遠程桌面協議的終端設備,是諸如數據庫服務器等一類設備,運行有遠程桌面協議(RDP)軟件,可通過互聯網或其他網絡實現遠程訪問。如服務器只採用用戶名和密碼組合的訪問保護機制,攻擊者將在選定服務器作為攻擊目標後,以高速自動化機制反复猜測密碼,即以此命名的所謂暴力破解。由於缺乏輸入失敗次數的上限機制,此類攻擊非常有效,最終可廣泛攻陷各類機構的內部網絡。勒索病毒已在2018年7月成功入侵了大型醫藥檢測機構Lab Corp,在不到一小時的時間內,攻陷7000台計算機及350台運營服務器(CSO)。


據Shodan搜索引擎檢測數據顯示,截至2018年10月28日,互聯網上共有二百五十多萬台計算機明確啟用了遠程桌面協議(需註冊後,方可查看Shodan搜索結果過濾後的條目),其中有一百多萬台位於美國境內。對於攻擊者而言,所有此類設備都是潛在攻擊和被利用對象。一旦被成功入侵,這些計算機可被用作肉雞,或正如白皮書所稱,其登錄口令將在xDedic等黑市上被販賣。

總結

網絡安全威脅具有疊加特性。這種“威脅疊加”現象意味著,廣泛利用外部計算機資源採集數字貨幣,並不會造成不法份子無暇開發和利用遠程桌面協議攻擊技巧,為勒索病毒攻擊營造利潤豐厚的回報空間。同理,組織機構盡量規避遠程桌面協議的應用 – 雖然很多場合,有著充分的應用必要性 – 並不意味著可以因此忽略應給予員工的防釣魚培訓。


正如白皮書中所明確的那樣– 在確保給予員工充分培訓的基礎上,組織機構需具備:良好的安全策略,全面貫徹並紮實執行;正確搭配安全產品和工具,含通過測試的備份還原系統在內;以及時刻更新的事件響應方案。即便所有以上各項全部落到實處,再加上安全防範意識的常態化,也無法保證絕對不會染毒,但卻可以大大提高針對網絡攻擊的防禦能力和/或事後還原能力。


在各國政府實現全球緊張局勢整體緩和之前,針對網絡犯罪行為所做的鬥爭不僅將會繼續下去,鬥爭規模也必將隨新技術應用所帶來的社會效益進一步擴大。衷心希望,通過解釋勒索病毒依然對組織機構構成一大嚴重威脅的原因及其應採取的防範措施,本白皮書能夠在最大程度降低失誤因素所造成損失的同時,有助於保障前句社會效益的實現。

下載白皮書:《勒索病毒:企業視角》。