Vulnerabilities Can Allow Attackers to Remotely Gain Control of Weintek HMIs

A cybersecurity researcher who specializes in industrial control systems (ICS) has identified three types of critical vulnerabilities in products made by human-machine interface (HMI) manufacturer Weintek.

The Taiwan-based vendor’s products are used worldwide. The company has posted a technical advisory instructing customers to install available patches and take steps to mitigate risks. It noted that the risk of exploitation is more significant if the devices are connected to an open network.

Weintek HMI vulnerabilitiesThe vulnerabilities were discovered by Marcin Dudek, a senior ICS/OT security researcher at Poland’s CERT Polska. The security holes have been found to impact the EasyWeb web-based configuration interface available for Weintek cMT products. Affected products include HMIs (including screenless HMIs), programmable logic controllers (PLCs), and gateways.

The vulnerabilities can be exploited by a remote, unauthenticated attacker for code execution with root privileges (CVE-2021-27446), to remotely access sensitive information and conduct actions on behalf of an admin (CVE-2021-27444), and to execute malicious JavaScript code via a stored XSS flaw (CVE-2021-27442).

Dudek noted on Twitter that there are more than 170 cMT HMIs connected directly to the internet, including systems located in Europe, Asia and North America.

Learn more about vulnerabilities in industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series

The researcher told SecurityWeek that an attacker could exploit the first two vulnerabilities with a single request sent to the targeted device. In the case of CVE-2021-27444, an attacker could leverage it to obtain the administrator password hash.

In the worst case scenario, an attacker can exploit the vulnerabilities to take complete control of the targeted device with root privileges, which in a real world environment could have serious consequences.

“Having such high privileges, an attacker can have unlimited access to all functions of the HMI,” Dudek explained. “It could also be used as a proxy to get access to the internal network of an organization, or to have direct access to other industrial devices in the same network, such as PLCs.

Dudek said he worked well with the vendor during the disclosure process. He said it took roughly two months to release all patches, but most of the fixes were ready one month after he reported his findings.

Remotely accessible HMIs can pose a serious threat to organizations in critical infrastructure sectors. Some of the high-profile incidents that came to light recently involve attacks on the water sector.

According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which issued an advisory for the Weintek cMT vulnerabilities this week, the impacted products are mostly used in the water and commercial facilities sectors.

Related: Iranian Hackers Access Unprotected ICS at Israeli Water Facility

Related: CISA Issues Advisory for High-Severity Vulnerabilities in Fuji Electric HMI Products

Related: Tens of Vulnerabilities Expose WAGO Controllers, HMI Panels to Attacks

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/SGP3FRQS5uY/vulnerabilities-can-allow-attackers-remotely-gain-control-weintek-hmis




Critical Flaw in Jabber for Windows Could Lead to Code Execution

Cisco this week announced the release of software updates that address several vulnerabilities in Jabber for desktop and mobile platforms, the most severe of which could be abused to execute arbitrary code with elevated privileges.

The bugs impact Cisco Jabber for Windows, macOS, and mobile platforms, and are not dependable to one another. To successfully exploit them, an attacker would need to be authenticated to an Extensible Messaging and Presence Protocol (XMPP) server in use by the affected software and to be able to send XMPP messages.

The most important of them is CVE-2021-1411, a critical arbitrary program execution flaw in Jabber for Windows, which exists because of improper validation of message content. Successful exploitation of this vulnerability could result in code execution, Cisco explains.

Next in line is CVE-2021-1469, a high-severity security hole in Jabber for Windows that, similarly to CVE-2021-1411, could lead to code execution. The third issue is CVE-2021-1417, a medium-severity vulnerability leading to information disclosure.

Two other medium-severity flaws affect Jabber for Windows, Jabber for macOS, and Jabber for mobile platforms. The first of them (CVE-2021-1471) could allow an attacker to inspect or tamper with connections between the Jabber client and a server, while the second (CVE-2021-1418) could be exploited for denial of service.

Cisco has released software updates to address these vulnerabilities and notes that there are no workarounds for them. The company also notes that it is not aware of these bugs being exploited in attacks.

This week, the tech giant also released advisories for more than 40 high- and medium-severity vulnerabilities across its product portfolio.

These include patches for a series of vulnerabilities in IOS XE SD-WAN software (DoS, arbitrary command execution, and buffer overflow), flaws in various IOS XE components (leading to OS command injection, DoS, privilege escalation, and arbitrary code execution), and bugs in Access Points Software (code execution, DoS, and information disclosure).

Cisco also announced that it is investigating the impact of the two high-severity vulnerabilities that the OpenSSL Project patched on Thursday, and which could result in attackers signing certificates, or causing a DoS condition.

This week, Cisco also patched medium-severity vulnerabilities in IOS XE SD-WAN software, IOS application environment, Network Convergence System (NCS) 520 routers, Aironet access points, and IOS XE wireless controller software. The flaws could be exploited for command injection, denial of service, privilege escalation, file overwrite, and other types of attacks.

Information on all of these vulnerabilities is available on Cisco’s security portal.

Related: Cisco Patches Severe Flaws in Network Management Products, Switches

Related: Over 70 Vulnerabilities Will Remain Unpatched in EOL Cisco Routers

Related: Cisco Patches Critical Vulnerabilities in Small Business Routers, SD-WAN

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/zDuOamY5HgY/critical-flaw-jabber-windows-could-lead-code-execution




New Code Execution Flaws In Solarwinds Orion Platform

Solarwinds has shipped a major security update to fix at least four documented security vulnerabilities, including a pair of bugs that be exploited for remote code execution attacks.

The patches were pushed out Thursday as part of a minor security makeover of the Orion Platform, the same compromised Solarwinds product that was exploited in recent nation-state software supply chain attacks.

The latest Orion Platform 2020.2.5 addresses at least four security flaws, one rated “critical” because of the risk of remote code execution attacks. The company did not release technical details of the vulnerability, which does not yet have a CVE assigned.

Solarwinds described that flaw simply as “RCE via Actions and JSON Deserialization.” The company warned that the critical bug was found via the test alert actions and noted that an Orion authenticated user is required to successfully launch an exploit.

A second bug, rated “high-risk” also brings remote code execution risk, Solarwinds warned. “The vulnerability can be used to achieve authenticated RCE as Administrator. In order to exploit this, an attacker first needs to know the credentials of an unprivileged local account on the Orion Server.”

The update also includes fixes for a “high-risk” stored-XSS vulnerability and a medium-severity issue that could lead to reverse-tabnabbing and open redirect attacks.

Related: SolarWinds Says 18,000 Customers May Have Used Compromised Orion Product

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/DwJLj6WR9qY/new-code-execution-flaws-solarwinds-orion-platform




Microsoft Offers Up to $30,000 for Vulnerabilities in Teams Desktop Client

Microsoft on Wednesday announced that its bug bounty programs now also cover the desktop client of its Teams business communications platform.

The tech giant is offering rewards for vulnerabilities in the Teams desktop client as part of its Application Bounty Program, which will feature additional app-related bounties in the future.

The Teams desktop client bug bounty program complements the existing awards for vulnerabilities in online Teams services.

Microsoft says researchers can earn between $500 and $15,000 for general vulnerabilities in the Teams desktop client, and between $6,000 and $30,000 if they demonstrate an exploit that fits one of five scenarios.

For example, white hat hackers can earn up to $30,000 for remote code execution with no user interaction, and $15,000 for the ability to obtain authentication credentials for other users without leveraging phishing attacks.

Payouts for vulnerabilities in Microsoft Teams desktop client

Microsoft reported in August 2020 that it had paid out nearly $14 million through its bug bounty programs in the past year. The single biggest reward was $200,000.

Related: Microsoft Launches ElectionGuard Bug Bounty Program

Related: Microsoft Explains How It Processes Vulnerability Reports

Related: Microsoft Offers Up to $30,000 for Flaws in Chromium-Based Edge

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/z-HHDFK2C1Q/microsoft-offers-30000-vulnerabilities-teams-desktop-client




Facebook Disrupts Chinese Spies Using iPhone, Android Malware

Facebook’s threat intelligence team says it has disrupted a sophisticated Chinese spying team that routinely use iPhone and Android malware to hit journalists, dissidents and activists around the world.

The hacking group, known to malware hunters as Evil Eye, has used Facebook to plant links to watering hole websites rigged with exploits for the two major mobile platforms.

Facebook’s Head of Cyber Espionage Investigations Mike Dvilyanski has published an advisory with indicators of compromise (IOCs) and other data to help victims and targets block the attacks.

Dvilyanski said Evil Eye gang has targeted activists, journalists and dissidents predominantly among Uyghurs from Xinjiang and those living abroad in Turkey, Kazakhstan, the United States, Syria, Australia, Canada and other countries. 

“This group used various cyber espionage tactics to identify its targets and infect their devices with malware to enable surveillance,” he said, warning that the Evil Eye gang is “a well-resourced and persistent operation.”

Facebook published details on the TTPs (tactics, techniques and procedures) by the group, including precise, selective targeting of victims. “This group took steps to conceal their activity and protect malicious tools by only infecting people with iOS malware when they passed certain technical checks, including IP address, operating system, browser and country and language settings,” he explained.

The group also actively hacks — or impersonates — websites that resemble domains for popular Uyghur and Turkish news sites. “They also appeared to have compromised legitimate websites frequently visited by their targets as part of watering hole attacks. Some of these web pages contained malicious javascript code that resembled previously reported exploits, which installed iOS malware known as INSOMNIA on people’s devices once they were compromised,” Dvilyanski said.

Facebook also exposed the use of social engineering with fake accounts to create fictitious personas posing as journalists, students, human rights advocates or members of the Uyghur community to build trust with people they targeted and trick them into clicking on malicious links.

The group has also used fake third party app stores and have been observed outsourcing Android malware development to two Chinese companies. “These China-based firms are likely part of a sprawling network of vendors, with varying degrees of operational security,” Dvilyanski explained.

Facebook has published hashes and domains associated with this threat actor.

Related: Poison Carp Threat Actor Targets Tibetan Groups

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/b6aPlTnPQME/facebook-disrupts-chinese-spies-using-iphone-android-malware




Air Charter Firm Solairus Aviation Suffers Data Breach

Private aviation services provider Solairus Aviation on Tuesday announced that some employee and customer data was compromised in a security incident at third-party vendor Avianis.

In a data breach announcement on March 23, Solairus said aviation business management platform provider Avianis provided notification last December about an intrusion into Avianis’ Microsoft Azure cloud platform, which hosts Solairus flight scheduling and tracking system.

An investigation into the incident has revealed that some of Solairus’ data that was hosted on that environment was indeed accessed by an unknown party.

Solairus data stored in that environment possibly includes employee and client names, along with information such as dates of birth, Social Security numbers, driver’s license numbers, passport numbers, and financial account numbers, the company says.

The private aviation services provider says it has already informed some of the affected individuals, but claims that it does not have the “current addresses for all such individuals.”  

The company also notes that both employees and clients should remain vigilant for any sign of unauthorized activity and to review their financial account statements for any unauthorized charges or activity. If any suspicious activity is identified, the affected individuals should immediately contact their financial institution.

“Solairus regrets the inconvenience or concern this incident may cause you. Every member of the Solairus community is important, and Solairus values your security and privacy,” the aviation services provider notes.

Related: Airlines Impacted by Data Breach at Aviation IT Firm SITA

Related: Airbus Stormshield Discloses Data Breach

Related: Web Developer Hub SitePoint Discloses Data Breach

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/dMOfIoPM-nY/air-charter-firm-solairus-aviation-suffers-data-breach




Microsoft: Ongoing, Expanding Campaign Bypassing Phishing Protections

A phishing email campaign detailed earlier this month is expanding with the use of additional email services to hide malicious intent, according to a warning from software giant Microsoft.

Dubbed ‘Compact’ Campaign, the operation has been ongoing since December 2020, targeting thousands of users. In early March, researchers with the WMC Global Threat Intelligence Team estimated that more than 400,000 Outlook Web Access and Office 365 credentials had been compromised in multiple, connected campaigns.

At the time, the researchers revealed that the adversary behind the campaign was leveraging trusted domains to ensure that phishing emails successfully bypass email protections.

Compromised accounts at the SendGrid email delivery service were used to send many of the emails. After the researchers and SendGrid started terminating the sending accounts, the threat actor switched to MailGun to send the phishing messages.

Now, Microsoft says that the phishing messages are relying on compromised accounts on email marketing services and leverage configuration settings to bypass phishing protections that organizations might have in place.

In addition to SendGrid, the tech giant reveals, the campaign’s operators abused Amazon SES last year, and started leveraging Mailgun for the same purposes since January.

“Microsoft Defender for Office 365 data shows that this phishing operation is still active today and continues to expand,” the company said on Twitter.

“The attackers abuse another legitimate service to further mask the malicious intent of their phishing emails. To evade domain reputation-based solutions, they use Appspot to create multiple unique phishing URLs per recipient,” the tech giant added.

Microsoft also notes that Appspot has been notified on the abuse, and that the company has already confirmed that the reported URLs are malicious. Appspot already took action against the offending projects and is working with Microsoft on tracking this operation.

Some of the phishing emails used in these attacks masquerade as notifications from video conferencing services, while recent attacks spoof security solutions and productivity tools, Microsoft reveals.

“Because this campaign uses compromised email marketing accounts, we strongly recommend orgs to review mail flow rules for broad exceptions that may be letting phishing emails through,” the company concludes.

Related: Phishers Target C-Suite with Fake Office 365 Password Expiration Reports

Related: Majority of Phishing and Malware Campaigns Are Small-Scale, Short-Lived

Related: FBI Warns of Employee Credential Phishing via Phone, Chat

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/QUshzdyYGdY/microsoft-ongoing-expanding-campaign-bypassing-phishing-protections




Vulnerabilities in TBox RTUs Can Expose Industrial Organizations to Remote Attacks

UK-based industrial automation company Ovarro recently patched a series of vulnerabilities in its TBox remote terminal units (RTUs). Cybersecurity experts say these flaws could pose a serious risk to organizations.

Ovarro’s TBox RTUs are described by the vendor as a remote telemetry solution for remote automation and monitoring of critical assets. These devices are used worldwide, including in the water, oil and gas, power, transportation and process industries.

Tbox RTU vulnerabilitiesResearchers at industrial cybersecurity firm Claroty discovered last year that the TBox RTUs, as well as the associated TWinSoft engineering software, are affected by five types of vulnerabilities.

Information about the vulnerabilities — all of which have been rated “high severity” — is available in a blog post published by Claroty and advisories released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Ovarro.

Learn More About Vulnerabilities in Industrial Products at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits Virtual Event Series

The vulnerabilities can allow an attacker to bypass protection features, cause a denial-of-service (DoS) condition, and execute arbitrary code on a targeted device.

“The risks associated with these flaws threaten not only the integrity of automation processes, but also, in some cases public safety,” Claroty said in its blog post. “Using these security shortcomings, we were able to find web-based interfaces, similar to HMIs, that monitor process levels and other industrial activity. We’ve seen in the past what could go wrong when such an interface is exposed to the internet without security; the fact such interfaces are exposed online removes many barriers to entry for adversaries of all types.”

The company has conducted a search for TBox RTUs and discovered that more than 62% of the systems exposed to the internet did not require authentication.

Claroty reported last month that the number of vulnerabilities discovered in industrial control system (ICS) products in 2020 increased significantly compared to previous years. The company said nearly 900 flaws were disclosed last year.

Related: Hackers Can Target Rockwell Industrial Software With Malicious EDS Files

Related: Industrial Firms Informed About Serious Vulnerabilities in Matrikon OPC Product

Related: Industrial Systems Can Be Hacked Remotely via VPN Vulnerabilities

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/md1mnuTbuKQ/vulnerabilities-tbox-rtus-can-expose-industrial-organizations-remote-attacks




Ransomware operators are piling on already hacked Exchange servers

A stylized ransom note asks for bitcoin in exchange for stolen data.

Microsoft Exchange servers compromised in a first round of attacks are getting infected for a second time by a ransomware gang that is trying to profit from a rash of exploits that caught organizations around the world flat-footed.

The ransomware—known as Black Kingdom, DEMON, and DemonWare—is demanding $10,000 for the recovery of encrypted data, security researchers said. The malware is getting installed on Exchange servers that were previously infected by attackers exploiting a critical vulnerability in the Microsoft email program. Attacks started while the vulnerability was still a zero-day. Even after Microsoft issued an emergency patch, as many as 100,000 servers that didn’t install it in time were infected.

Opportunity knocks

The hackers behind those attacks installed a web shell that allowed anyone who knew the URL to completely control the compromised servers. Black Kingdom was spotted last week by Security firm SpearTip. Marcus Hutchins, a security researcher at security firm Kryptos Logic, reported on Sunday that the malware didn’t actually encrypt files.

On Tuesday morning, Microsoft Threat Intelligence Analyst Kevin Beaumont reported that a Black Kingdom attack “does indeed encrypt files.

Security firm Arete on Monday also disclosed Black Kingdom attacks.

Black Kingdom was spotted last June by security firm RedTeam. The ransomware was taking hold of servers that failed to patch a critical vulnerability in the Pulse VPN software. Black Kingdom also made an appearance at the beginning of last year.

Brett Callow, a security analyst at Emsisoft, said it wasn’t clear why one of the recent Black Kingdom attacks failed to encrypt data.

“The initial version encrypted files, while a subsequent version simply renamed them,” he wrote in an email. “Whether both versions are being simultaneously operated is not clear. Nor is it clear why they altered their code—perhaps because the renaming (fake encryption) process would not be detected or blocked by security products?”

He added that one version of the ransomware is using an encryption method that in many cases allows the data to be restored without paying a ransom. He asked that the method not be detailed to prevent the operators of the ransomware from fixing the flaw.

Patching isn’t enough

Neither Arete nor Beaumont said if Black Kingdom attacks were hitting servers that had yet to install Microsoft’s emergency patch or if the attackers were simply taking over poorly secured web shells installed earlier by a different group.

Two weeks ago, Microsoft reported that a separate strain of ransomware named DearCry was taking hold of servers that had been infected by Hafnium. Hafnium is the name the company gave to state-sponsored hackers in China that were the first to use ProxyLogon, the name given to a chain of exploits that gains complete control over vulnerable Exchange servers.

Security firm SpearTip, however, said that the ransomware was targeting servers “after initial exploitation of the available Microsoft exchange vulnerabilities.” The group installing the competing DearCry ransomware also piggybacked.

Black Kingdom comes as the number of vulnerable servers in the US dropped to less than 10,000, according to Politico, which cited a National Security Council spokesperson. There were about 120,000 vulnerable systems earlier this month.

As the follow-on ransomware attacks underscore, patching servers isn’t anywhere near a full solution to the ongoing Exchange server crisis. Even when severs receive the security updates, they can still be infected with ransomware if any web shells remain.

Microsoft is urging affected organizations that don’t have experienced security staff to run this one-click mitigation script.

https://arstechnica.com/?p=1751780




Purple Fox Malware Squirms Like a Worm on Windows

Malware hunters at Guardicore are warning that an aggressive botnet operator has turned to SMB password brute-forcing to infect and spread like a worm across the Microsoft Windows ecosystem.

The malware campaign, dubbed Purple Fox, has been active since at least 2018 and the discovery of the new worm-like infection vector is yet another sign that consumer-grade malware continues to reap profits for cybercriminals.

According to Guardicore researcher Amit Serper, the Purple Fox operators primarily used exploit kits and phishing emails to build botnets for crypto-mining and other nefarious uses.  

Now, the new SMB brute-force method is being combined with rootkit capabilities to hide and spread widely across internet-facing Windows computers with weak passwords.

“Throughout the end of 2020 and the beginning of 2021, Guardicore Global Sensors Network (GGSN) detected Purple Fox’s novel spreading technique via indiscriminate port scanning and exploitation of exposed SMB services with weak passwords and hashes,” Serper explained.

Serper said May 2020 saw a “significant amount of malicious activity” where the number of infections climbed by roughly 600% and amounted to a total of 90,000 attacks.

Serper’s blog, which contains IOCs to help defenders hunt for signs of infection, explains the aggressiveness of the malware operator:

“While it appears that the functionality of Purple Fox hasn’t changed much post exploitation, its spreading and distribution methods – and its worm-like behavior – are much different than described in previously published articles. Throughout our research, we have observed an infrastructure that appears to be made out of a hodge-podge of vulnerable and exploited servers hosting the initial payload of the malware, infected machines which are serving as nodes of those constantly worming campaigns, and server infrastructure that appears to be related to other malware campaigns.

Serper’s team at Guardicore warned that the attackers are hosting various MSI packages on nearly 2,000 servers, most of which are compromised machines which were repurposed to host malicious payloads. 

“We have established that the vast majority of the servers, which are serving the initial payload, are running on relatively old versions of Windows Server running IIS version 7.5 and Microsoft FTP, which are known to have multiple vulnerabilities with varying severity levels,” Guardicore said in a technical blog post.

The company found the campaign spreading via two distinct mechanisms — a worm payload after a victim machine is compromised through a vulnerable exposed service (such as SMB); or the worm payload is being sent via email through a phishing campaign.

The company is encouraging malware hunters to use public indicators of compromise to find signs of malicious activity related to this threat.

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/w-pskMTDmDI/purple-fox-malware-squirms-worm-windows