In Case You Missed It: FireEye Top Stories 9/11

1. SUCEFUL Targets ATMs Differently: FireEye Labs discovered a new type of ATM malware called SUCEFUL that can retain debit cards on infected ATMs, and can disable alarms and read the debit card tracks. It can run without detection on multiple hardware vendors and can create an interface with the ATM. It is the first ATM malware able to steal the debit card tracks and to allow the hackers to steal the actual physical ATM cards.
2. The Security Operations Hierarchy of Needs: Security Week posted an article Josh Goldfarb, FireEye VP and CTO Americas, on the challenges facing some security operations centers that aren’t as mature as others. The article points out that foundational needs must be addressed first, including awareness, vision, process, instrumentation, content, unified work queue, staffing, training, operations, intelligence, and information sharing.
3. New Zero-day Vulnerabilities: FireEye recently uncovered an attack that exploits two previously unknown vulnerabilities: one in Microsoft Office and another in Windows. The exploit was hidden inside a Microsoft Word document that appeared to be a resume, and the two exploits worked in tandem for fully privileged remote code execution.

4. New CFO for FireEye: FireEye named industry veteran Michael Berry as the company’s new VP and CFO. Berry most recently held the executive vice president and CFO position at Informatica, which reported revenues of $105 billion last year.

5. Winner, Winner, Chicken Dinner: FireEye announced its winners in the 2015 FLARE-ON Challenge Solutions. More than 1,400 people participated in the reverse engineering challenge, and 162 winners were named. The solutions are posted here.

