Linhagem do fabricante
Trend Micro - the vendor that buys the flaws it defends against
Founded on a dongle, run by a co-founder since 2005, owner of the Zero Day Initiative - and the source of a 2005 update that did more damage in ninety minutes than the worm it targeted.
Trend Micro is a Japanese-American security company founded in Los Angeles in 1988 and headquartered in Tokyo, known for endpoint and cloud security, the Zero Day Initiative and the Pwn2Own contests.
Trend Micro began in Los Angeles in October 1988 with the proceeds of a copy-protection dongle, founded by Steve Chang, his wife Jenny Chang and her sister Eva Chen. It moved to Taipei almost at once and, after taking over a Japanese software firm in 1992, to Tokyo, where it has been listed since 1998. The early growth came through other people's channels: Intel sold its LAN antivirus under the Intel name, with royalties flowing one way in America and Europe and the other way in Asia, and from 1993 Novell bundled it with NetWare - the same Novell that appears elsewhere in this catalogue selling hardware at cost to grow an installed base.
Eva Chen became chief executive in January 2005 and still is, which makes her one of the longest-serving leaders in security and one of the few founders of either sex to run a company of this size for two decades. The company's current platform is sold as Vision One, with the AI branding that every security vendor now carries; the record worth keeping is older than the branding and comes in three parts.
The first is the Zero Day Initiative, acquired with TippingPoint from HP in 2015 for 300 million dollars. Started in 2005, it buys vulnerabilities from independent researchers and hands them to the affected vendors to fix before disclosure, and it runs the Pwn2Own contests where the year's browsers, phones and, lately, cars are broken on stage for prize money. A security vendor that buys the flaws it defends against is competing with the grey market on price, and the effect of a lawful buyer is to raise the floor of what a vulnerability is worth. That market is where a great deal of the industry's knowledge of its own weaknesses now comes from.
The second is the morning of 23 April 2005, when a routine pattern update pegged processors to a hundred per cent on Windows XP and Server 2003. The file was pulled after ninety minutes; by then it had been downloaded some three hundred thousand times, support took roughly 370,000 calls, and East Japan Railway and three national newspapers lost their networks for part of a morning. The cause was insufficient testing in the rush to detect a new worm. The lesson is the one the Xerox repairman and the Siemens controllers teach: the channel that keeps a product current is the channel through which it can do the most damage, and a defensive product with automatic updates has a blast radius the threat it targets could only envy.
The third is from 2019 and the company said it plainly: not an external hack. An employee with a premeditated plan reached a consumer support database, took the contact details of about 68,000 customers and sold them to criminals, who then telephoned those customers impersonating Trend Micro support. The Ubiquiti entry records what an insider can do with data; this is the same thing at a company whose product is the defence against it, and the company's own plain disclosure is the source. A security vendor is a company like the others, with employees like the others, and its own controls are the ones it is asked to be judged by.
- Wikipedia: Trend Micro was founded on 24 October 1988 in Los Angeles by Steve Chang, his wife Jenny Chang and her sister Eva Chen, with proceeds from Chang's sale of a copy-protection dongle to Rainbow Technologies; the headquarters moved to Taipei and, after the 1992 takeover of a Japanese software firm, to Tokyo; Intel sold its LAN antivirus as LANDesk Virus Protect under a royalty arrangement, and Novell bundled the product with its network operating system from 1993; listed in Tokyo in 1998 and on Nasdaq in 1999; Eva Chen, chief technology officer from 1996, became chief executive in January 2005 with Chang as chairman; TippingPoint was bought from HP for 300 million dollars in 2015
- Wikipedia, Zero Day Initiative: started in July 2005 by TippingPoint, then a division of 3Com, and acquired by Trend Micro with TippingPoint in 2015; the programme buys software vulnerabilities from independent researchers and discloses them to the vendors for patching before making them public
- Virus Bulletin, 23 April 2005: Official Pattern Release 2.594.00 caused 100 per cent CPU usage, slowdown and in some cases complete failure on Windows XP SP2 and Windows Server 2003; Trend removed it from the update list 90 minutes later, by which time it had been downloaded an estimated 300,000 to 350,000 times, and support staff received in the region of 370,000 calls; the fault was blamed on insufficient testing in the rush to add detection for the Rbot family; the share price fell 4.7 per cent
- Slashdot, citing the Japan Times, April 2005: the faulty update halted computers at East Japan Railway, and Kyodo News, the Asahi Shimbun and the Yomiuri Shimbun lost LAN access for parts of the morning
- Trend Micro's own disclosure, November 2019: an employee accessed a consumer support database with clear criminal intent and sold the data - names, email addresses, support ticket numbers and some phone numbers of about 68,000 customers - to an unknown third party, who then made scam calls impersonating Trend Micro support; the company stated this was not an external hack but the work of a malicious insider who bypassed its controls, dismissed the employee and involved law enforcement