New Indicators of Compromise for APT Group Nitro Uncovered

In mid-July of this year, we noticed yet another legitimate website had been compromised by APT actors and was serving malware. In this case, it was a group commonly referred to as “Nitro,” which was coined by Symantec in its 2011 whitepaper.

As we dug deeper, we found additional compromised legitimate websites and malware from the same group back through March of this year. In most instances, the malware is one commonly referred to as “Spindest,” though we also found “PCClient” and “Farfli” variants in use by the group. We don’t have enough data to say for certain that all of the malware in this blog was delivered via compromised legitimate websites.

Historically, Nitro is known for targeted spear phishing campaigns and using Poison Ivy malware, which was not seen in these attacks.  Since at least 2013, Nitro appears to have somewhat modified their malware and delivery methods to include Spindest and legitimate compromised websites, as reported by Cyber Squared’s TCIRT.  Our findings indicate they are continuing to evolve with the addition of PCClient and Farfli variants.  The Maltego screenshot below shows the activity we describe in this blog.

These events impacted at least the following industries, across four waves:

  • A US based IT Solutions provider;
  • The European office of a major, US based commercial vendor of space imagery and geospatial content;
  • A European leader in power technologies and automation for utilities and industry;
  • A US based provider of medical and dental imaging systems and IT solutions.

In July, Nitro compromised a South Korean clothing and accessories manufacturer’s website to serve malware commonly referred to as “Spindest.”  Of all the samples we’ve tied to this activity so far noted in this blog, this is the only one configured to connect directly to an IP address for Command and Control (C2).  This IP address has been in use by this group for some time, which is interesting since they have evolved other components of their kill chain over time to ensure malware delivery, but oddly not altered their C2 infrastructure. It is simple for companies to block any outbound traffic to this IP, which would negate the effort Nitro put into successfully delivering the malware.

37 AV vendors within VirusTotal properly identify it, and the PE timestamp shows the day before we saw it. In addition, the following three samples were found roughly a week apart from each other, possibly indicating the timing of the waves of activity.

Table 1

SHA256 0a1103bc90725d4665b932f88e81d39eafa5823b0de3ab146e2d4548b7da79a0
MD5 7915aabb2e66ff14841e4ef0fbff7486
File Name update.exe
File Size 106496
First Seen 2014-07-24 11:54:02
C2 IP 223.25.233.248

The next sample we found is commonly known as PCClient, which is not malware previously tied to this group.  We discovered this, and many of the following samples, through historic IP resolution overlap between the same domains alternately resolving to either the 223.25.233.248 or 196.45.144.12. The second IP has also not been reported as tied to this group before.  However, this shifting of IP resolutions back and forth indicates Nitro is in control of these domains. It also makes is fairly easy for any Infosec team to reach the same conclusion we did, which again negates their use both of a previously unreported domain and IP for C2, as well as a new family of malware. 25 AV vendors within VirusTotal properly classify this sample as malware.  Its PE timestamp was 8 July, almost a week prior when we first saw it.

Table 2

SHA256 8aef92a986568ba31729269efa31a2488f35920d136ab41cb6fce55fd8e0b4b7
MD5 7522baef20df95eeeeafdf4efe3aac3c
File Name lsm.exe
File Size 65536
First Seen 2014-07-15 11:48:33
C2 URL xenserver.ddns[.]net
Resolution 196.45.144.12

The next sample was another Spindest variant and had the same timestamp as the aforementioned PcClient sample.  In addition, Nitro chose to use the same C2 for this sample, making it easy to both find and tie to the group. 41 AV vendors within VirusTotal properly classify this sample as malware.

Table 3

SHA256 995bc16a5c2c212b57ba00c2376ac57c8032c7f2b1d521f995a5e1d49066d64d
MD5 6527ba8baab0f86b0ffb6178247772c4
File Name install_reader11_en_aaa_aih.exe
File Type PE
File Size 81920
First Seen 2014-07-09 16:31:26
C2 URL xenserver.ddns[.]net
Resolution 196.45.144.12

The next wave of activity we found took place in mid-May. Both samples were Spindest variants with the same PE timestamp of 15 May. While neither MD5s for C2 match, the aforementioned link to a post by Cyber Squared’s TCIRT did document Nitro using Spindest variants with the same file name starting late December last year. In that case they used the historic C2 IP we note in Table 1 in this blog. 34 AV vendors within VirusTotal properly classify the first sample as malware, and 40 AV Vendors the second sample.

Table 4

SHA256 e7f2af8c48f837da57000c068368d77bc9b06eba1e077edfab58df6aa2ea40ec
MD5 271e6a4d45c2817f86148ca413f97604
File Name mdm.exe
File Size 118784
First Seen 2014-05-20 08:43:15
C2 URL zipoo.redirectme[.]net
Resolution 196.45.144.12

Table 5

SHA256 e601da16f923b33465dbafbff9d47195e8fc50099fd0581a16a1745bf890afb6
MD5 be765cd5723e4366d35172aaf13fad44
File Name CitrixReceiverWeb.exe
File Size 135168
First Seen 2014-05-15 16:34:10
C2 URL zipoo.redirectme[.]net
Resolution 196.45.144.12

The malware dropped was configured to use good.myftp[.]org as the C2 URL, and the IP resolution was 223.25.233.248.  Both of these are known Nitro Indicators of Compromise (IOCs). In this case, the malware was a Farfli variant, again not a malware previously tied to this group. 39 AV vendors within VirusTotal properly identify the file as malware.  The PE timestamp on the file was 1 April, about two weeks before we saw the file. Continuing the activity, we discovered the actors had compromised a legitimate website belonging to an international technology company that provides Software Configuration and Change Management (SCCM) solutions in mid-May. (It is a well regarded company and partners with large companies such as Microsoft.)

Table 6

SHA256 184c083e839451c2ab0de7a89aa801dc0458e2bd1fe79e60f35c26d92a0dbf6a
MD5 ec519d709c0582346741fe0094208216
File Name update.exe
File Size 159744
First Seen 2014-04-15 01:13:14
C2 URL good.myftp[.]org
Resolution 223.25.233.248

The final sample, from mid-March, was also hosted on a compromised legitimate website, this time a small, US based IT company.  The IP resolved by the C2 URL was changed two days after we saw this file to overlap with good.myftp[.]org for a month before returning the below resolution. The filename matches that of the sample in Table 5, which had a very similar third level C2 domain and the same IP resolution. This is also a Spindest variant with a PE timestamp of the same day we saw it. 39 AV vendors within VirusTotal properly identify the file as malware.

Table 7

SHA256 ffbddfb536e8e604c880ec977d06f804a500fc0396899bd2c195fb1f5b74207a
MD5 a3b2e34973691ad320b70248bd67fbd2
File Name CitrixReceiverWeb.exe
File Size 192512
First Seen 2014-03-12 06:58:22
C2 URL zip.redirectme[.]net
Resolution 196.45.144.12

As this post and previous cited research show, APT groups such as Nitro will continue to evolve their techniques within the kill chain to avoid detection.  However, they also demonstrate the value of tracking these threats over time, as this allowed us to uncover and properly attribute the new IOCs because Nitro was still re-using old C2 infrastructure with their new malware.

For Palo Alto Networks customers, all of these files were properly identified by WildFire as malware and all of the C2 domains are labeled as threats in both Threat Prevention and URL Filtering systems.

[Source: Palo Alto Networks Research Center]

Palo Alto Networks Again Revolutionizes Enterprise Security with the Introduction of Advanced Endpoint Protection Offering

Offers Preventative Approach to Stop Cyber Threats at the Endpoint

Palo Alto Networks Santa Clara, CA , Sep 30, 2014 at 5:00:00 AM
Santa Clara, Calif., September 30, 2014 – Palo Alto Networks® (NYSE: PANW), the leader in enterprise security, today announced the availability of Traps, a revolutionary and unique Advanced Endpoint Protection offering designed to prevent sophisticated cyber attacks on endpoints, sparing IT security teams from cumbersome remediation, patching, and often futile recovery scrambles.

Despite major advances in network security, endpoints remain vulnerable to many advanced attacks, especially as increasingly mobile workforces move outside protected enterprise networks.  Legacy endpoint security products require prior knowledge of a threat in order to prevent it, or worse, use an approach that only identifies a new threat after it has compromised the endpoint.

This reactive model results in a never-ending chase after the thousands of new malware attacks that emerge each day, as well as the expanding number of software vulnerabilities that can be used to exploit an endpoint.  These approaches offer little hope or possibility of recovering data that has already been hijacked by an attacker.  Putting an end to the reactive run around, Traps proactively prevents attacks on the endpoint, including unknown malware and zero-day exploits, before they do any damage.

QUOTES

  • “The key differentiator with Traps is its ability to automate the process of protecting the endpoint. Most of the products in the industry today largely deal with informing us that there’s a problem and little more; that leaves us to manually deal with the effort of remediating the endpoint, takes time and leaves us vulnerable.  With Traps, that is done automatically and it is done nearly instantaneously, which is a major win.”

— Golan Ben-Oni, CSO and SVP Network Architecture, IDT

  • “The proven effectiveness of the Traps endpoint capability over other heuristic and signature-based approaches, together with Palo Alto Networks WildFire and next-generation firewall, makes the secure enablement of our entire business possible.”

— Dr. Andres Rohr of RWE Supply & Trading

  • “With the introduction of Traps, we are redefining the endpoint security market much like we did the network security market with our next-generation firewall.  Traps and our platform as a whole are designed to revolutionize enterprise security by putting prevention front and center, closing the door on cyber threats before they can get in and cause damage.”

— Lee Klarich, senior vice president of Product Management at Palo Alto Networks

Since the acquisition of Cyvera and the technology behind Traps, Palo Alto Networks has expanded global support and services operations to meet enterprise customer needs, and completed several key enhancements, including:

  • Integration with Palo Alto Networks WildFire – Traps blocks malware by leveraging the full knowledge of Palo Alto Networks Threat Intelligence Cloud;
  • Added exploitation and malware prevention modules – extends Traps support to include the latest attack techniques; and
  • Enhanced forensics – provides a rich set of reporting for better visibility and understanding of attacks that were prevented.

Natively Integrated Platform Extends Protection Enterprise-wide

The integration of Traps with the Palo Alto Networks Threat Intelligence Cloud brings security of the network and endpoint together under a single common architecture, known as the Palo Alto Networksenterprise security platform, and delivers unparalleled enterprise-wide security and automated threat prevention capabilities, reducing risk across an organization at every stage in the attack kill chain.  It also eliminates management complexity and myopic point product-related security silos that can leave gaping holes in an organization’s security posture.

Availability 

Traps Advanced Endpoint Protection, offered as a subscription service, is available now from authorized Palo Alto Networks channel partners.  The offering is inclusive of all functionality including exploit prevention, malware prevention through WildFire integration, forensics, and premium support.

To learn more about Traps Advanced Endpoint Protection from Palo Alto Networks, visit:

About Palo Alto Networks

Palo Alto Networks is leading a new era in cybersecurity by protecting thousands of enterprise, government, and service provider networks from cyber threats.  Unlike fragmented legacy products, our security platform safely enables business operations and delivers protection based on what matters most in today’s dynamic computing environments: applications, users, and content.  Find out more atwww.paloaltonetworks.com.

Palo Alto Networks and the Palo Alto Networks Logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.

Media Contacts:
Jennifer Jasper Smith
Head of Corporate Communications
Palo Alto Networks
408-638-3280
jjsmith@paloaltonetworks.com

Bob Nelson
Voce Communications
408-201-2402
bnelson@vocecomm.com

The Time Has Come: Advanced Endpoint Protection is Here!

POSTED BY: on September 30, 2014 5:15 AM

FILED IN: Announcement, Cybersecurity, Endpoint, Mobility
TAGGED: ,

It’s not often a company has an opportunity to disrupt an entire industry…. twice.  When we introduced the first next-generation firewall back in 2007 we set out on a path to redefine the network security market.  Today, over 19,000 organizations rely on Palo Alto Networks to protect their networks against the most sophisticated, targeted attacks.

We take our responsibility to those organizations very seriously, and today we’re announcing an important next step: Advanced Endpoint Protection.  If we’ve learned anything from the recent round of breaches, it’s that endpoints remain highly vulnerable to attacks.  Even the most advanced network security architectures can’t protect against every threat vector.  And legacy endpoint security approaches that rely on prior knowledge of the threat, or active scanning, are simply ill equipped to protect organizations from this new era of attacks.

Today marks the official launch of Traps, an Advanced Endpoint Protection solution that truly tears the covers off traditional approaches and exposes them for what they are: misguided attempts at addressing a very real problem.  This isn’t just a product launch. This is the beginning of a new market: a market defined by its ability to turn the tides and rebuild lost confidence, and a market grounded on the principle that attacks can be prevented.

This new Advanced Endpoint Protection market will be defined by solutions that can deliver on the following:

  • Must be able to prevent all exploits, including those utilizing unknown zero-day vulnerabilities
  • Must be able to prevent all malware, without requiring any prior knowledge
  • Must provide detailed forensics against prevented attacks to strengthen all areas of the organization by pinpointing the target and techniques used
  • Must be highly scalable and lightweight to seamlessly integrate into existing operations with minimal to no disruption
  • Must integrate closely with network and cloud security for quick data exchange and cross-organization protection

Carry this list in your back pocket.  As you consider the different approaches to endpoint security we hope you evaluate the underlying technology against these five criteria.  And of course we hope you take the time to evaluate Traps and see for yourself how we’ve delivered not only one of the most advanced approaches in the market, but also one that integrates natively into our Enterprise Security Platform.

 

[Source: Palo Alto Networks]

A Customer Perspective: VMware NSX, Next-Generation Security and Micro-Segmentation

VMware NSX and Palo Alto Networks are transforming the datacenter by combining the fast provisioning of network and security services with next-generation security protection for East-West traffic. At VMworld, John Spiegel, Global IS Communications Manager for Columbia Sportswear will take the stage to discuss their architecture, their micro-segmentation use case and their experience. This is session SEC1977 taking place on Tuesday, Aug 26, 2:30-3:30 p.m. Micro-segmentation is quickly emerging as one of the primary drivers for the adoption of NSX. Below, John shares Columbia’s security journey ahead of VMworld.

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

When I started at Columbia, we were about a $500 million company, now we’re closing in on $2 billion and hoping to get to $3 billion rather quickly. So as you can imagine our IT infrastructure has to scale with the business. In 2009, we embarked on a huge project to add a redundant data center for disaster recovery.  As part of the project, we partnered with VMware and quickly created a nearly 100% virtualized datacenter.  It was a huge success.  But something was missing.  A security solution that matched our virtualized data center.  There just wasn’t a great way to insert security in order to address east-west traffic between VMs, nor have the security tied to the applications as they moved around dynamically. We set out looking for a solution to bridge that gap.

To address our security needs in the data center, we looked at several different strategies and at that time there really weren’t any good solutions. Many of the solutions were physical in nature.  They required us to do some crazy configurations to apply security. We looked at the Cisco 6500 firewall blades, Juniper’s virtual solution and a few other lightweight security solutions, but they just didn’t have what we needed.  We kept looking.

At VMworld last year we were introduced to VMware’s NSX.  I saw the power of the platform, and it all started to click. And when Palo Alto Networks (our perimeter firewall vendor) announced they were a major partner and that their technology integrated with NSX to give us an additional level of security, things really came together for us. The ability to drive security down into the infrastructure, down to the kernel level, and then take advantage of Palo Alto Networks next generation security was very attractive to us. Doing micro-segmentation with NSX, and then having the option of inserting next generation firewalling services from Palo Alto Networks in those areas of the business that require them, will really help us improve our overall security posture. A solution like this is where we need to be.  These tools give us the ability to manage both physical and virtual security policies centrally with Palo Alto Networks management tool Panorama. I know that when workloads move the security and policies follow the workloads.

To me, that’s what it is about – advanced security inside the data center, plus automation via software that’s completely independent of the underlying physical infrastructure. With solutions such as NSX and the integration with Palo Alto Networks to provide advanced security services, we are going to put security back in the data center, the right way.

John Spiegel
Columbia Sportswear

Click here for full details of Palo Alto Networks at VMworld, including a session with John and several presentations by our product experts.

Palo Alto Networks Reports Fiscal Third Quarter 2014 Financial Results and Announces Settlement of Litigation with Juniper Networks

– Fiscal third quarter total revenue grows 49 percent year-over-year to a record $150.7 million– Billings grow 46 percent year-over-year to a record $193.9 million– Product revenue grows 38 percent year-over-year to a record $84.1 million; recurring subscription revenue grows 71 percent year-over-year to a record $32.0 million– Deferred revenue grows 68 percent year-over-year to a record $367.9 million

SANTA CLARA, Calif., May 28, 2014 /PRNewswire/ — Palo Alto Networks, Inc. (NYSE: PANW) today announced financial results for its fiscal third quarter of 2014 ended April 30, 2014.

Total revenue for the fiscal third quarter grew 49 percent year-over-year to a record $150.7 million, compared with $101.3 million in the fiscal third quarter of 2013. GAAP net loss for the fiscal third quarter was $139.1 million, or $1.86 per diluted share, compared with a net loss of $7.3 million, or $0.10 per diluted share, in the fiscal third quarter of 2013.

Palo Alto Networks recorded fiscal third quarter non-GAAP net income of $8.7 million, or $0.11 per diluted share, compared with non-GAAP net income of $5.3 million, or $0.07 per diluted share, in the fiscal third quarter of 2013. A reconciliation between GAAP and non-GAAP information is contained in the tables below.

“We reported record revenue in our third quarter driven by strong customer demand for our next-generation enterprise security platform. We achieved the highest rate of new customer acquisition in our history and now serve more than 17,000 customers globally to address their security needs and prevent increasingly sophisticated and complex cyber attacks from compromising an organization’s critical assets,” said Mark McLaughlin, president and chief executive officer of Palo Alto Networks. “We also announced this afternoon that we have reached a settlement with Juniper Networks of all litigation matters between us; this allows us to further focus our resources and time on our customers and growing our business.”

“Year-over-year revenue growth of 49 percent was driven by our land, expand and retain model, as product, recurring subscription and support revenue all delivered substantial growth,” said Steffan Tomlinson, chief financial officer of Palo Alto Networks. “Additionally, we continue to demonstrate the power of our hybrid SaaS model as gross margin and operating margin improved sequentially, and we generated $28.4 million of free cash flow in the quarter, bringing our fiscal year to date total to $83.2 million.”

Recent Highlights

  • Reached a settlement with Juniper Networks, the terms of which provide that both parties will dismiss all litigation; both parties will license the patents at issue in all outstanding suits to each other for the life of the patents; both parties will also enter into a covenant not to sue each other for patent infringement for eight years; and Palo Alto Networks will pay Juniper Networks a one-time settlement amount of approximately $175 million, consisting of $75 million in cash, approximately $70 million in shares of common stock and a warrant to purchase approximately $30 million of common stock.
  • Positioned in the “Leaders” quadrant of Gartner, Inc.’s April 2014 Magic Quadrant for Enterprise Network Firewalls; this is the third consecutive year in which Palo Alto Networks has been recognized as a leader in the Magic Quadrant for Enterprise Firewall report.1
  • Completed the acquisition of Cyvera Ltd., a privately held cybersecurity company located in Tel Aviv, Israel; with the addition of Cyvera’s unique endpoint protection capabilities to the company’s security platform, Palo Alto Networks can provide protection across the enterprise, extending prevention technology from the network to the endpoint.
  • Strengthened our strategic partnership with VMware by announcing a new reseller agreement and general availability of an integrated offering for automating and accelerating security deployments in the software-defined data center.
  • Announced a global managed security services agreement with NTT Com Security (formerly Integralis) under which NTT Com Security will provide its extensive implementation, integration, and managed security services around the Palo Alto Networks security platform.

Conference Call Information
Palo Alto Networks will host a conference call for analysts and investors to discuss its fiscal third quarter of 2014 results and outlook for its fiscal fourth quarter of 2014 today at 4:30 PM Eastern time / 1:30 PM Pacific time. Open to the public, investors may access the call by dialing 1-877-280-4959 or 857-244-7316 and entering the passcode 37864312. A live audio webcast of the conference call along with supplemental financial information will also be accessible from the “Investors” section of the company’s website at investors.paloaltonetworks.com. Following the webcast, an archived version will be available on the website for one year. A telephonic replay of the call will be available two hours after the call and will run for five business days and may be accessed by dialing 1-888-286-8010 or 617-801-6888 and entering the passcode 58471222.

Forward-Looking Statements
This press release contains forward-looking statements that involve risks and uncertainties, including statements regarding the settlement of the company’s litigation with Juniper Networks and continued momentum in the company’s business. There are a significant number of factors that could cause actual results to differ materially from statements made in this press release, including: the need to receive formal dismissal of the litigation by the relevant courts in Delaware and California; Palo Alto Networks’limited operating history; risks associated with Palo Alto Networks’ rapid growth, particularly outside of the U.S.; rapidly evolving technological developments in the market for network security products; and general market, political, economic and business conditions.

Additional risks and uncertainties that could affect Palo Alto Networks’ financial results are included under the captions “Risk Factors” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” in the company’s quarterly report on Form 10-Q filed with the SEC on February 24, 2014, which is available on the company’s website at investors.paloaltonetworks.com and on the SEC’s website at www.sec.gov. Additional information will also be set forth in other filings that the company makes with the SEC from time to time. All forward-looking statements in this press release are based on information available to the company as of the date hereof, and Palo Alto Networks does not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

Non-GAAP Financial Measures

Palo Alto Networks has provided in this release financial information that has not been prepared in accordance with generally accepted accounting principles in the United States (GAAP). The company uses these non-GAAP financial measures internally in analyzing its financial results and believes that the use of these non-GAAP financial measures is useful to investors as an additional tool to evaluate ongoing operating results and trends and in comparing the company’s financial results with other companies in its industry, many of which present similar non-GAAP financial measures.

Non-GAAP financial measures are not meant to be considered in isolation or as a substitute for comparable GAAP financial measures, and should be read only in conjunction with the company’s consolidated financial statements prepared in accordance with GAAP. A reconciliation of the company’s non-GAAP financial measures to their most directly comparable GAAP measures has been provided in the financial statement tables included in this press release, and investors are encouraged to review the reconciliation.

Non-GAAP net income and diluted net income per share. Palo Alto Networks defines non-GAAP net income as net income (loss) plus share-based compensation expense, tax adjustments related to the valuation allowance on deferred tax assets, expenses related to IP litigation, legal settlement expenses, and acquisition related costs. Palo Alto Networks believes that excluding these items provides management and investors with greater visibility into the underlying performance of the company’s core business operating results, meaning its operating performance excluding these items and, from time to time, other discrete charges that are infrequent in nature, over multiple periods. The company also excludes from non-GAAP net income and non-GAAP diluted net income per share the tax effects, including income tax and payroll tax, associated with these items in order to provide a complete picture of the company’s recurring core business operating results. Without excluding these tax effects, investors would only see the gross effect that excluding these expenses had on the company’s operating results.

Billings. Palo Alto Networks defines billings as total revenue plus the change in deferred revenue, net of acquired deferred revenue, during the period. The company’s management monitors billings because billings drive deferred revenue, which is an important indicator of the health and visibility of the company’s business. The company considers billings to be a useful metric for management and investors, particularly as sales of subscriptions increase and the company experiences strong renewal rates for subscriptions and support and maintenance.

Free Cash Flow. Palo Alto Networks defines free cash flow as cash provided by operating activities less purchases of property, equipment, and other assets.  The company considers free cash flow to be a liquidity measure that provides useful information to management and investors about the amount of cash generated by the business that, after the purchases of property, equipment, and other assets, can be used for strategic opportunities, including investing in our business, making strategic acquisitions, and strengthening the balance sheet.

Investors are cautioned that there are a number of limitations associated with the use of non-GAAP financial measures as an analytical tool. In particular, many of the adjustments to the company’s GAAP financial measures reflect the exclusion of items that are recurring and will be reflected in the company’s financial results for the foreseeable future, such as share-based compensation.  Share-based compensation is an important part of Palo Alto Networks employees’ compensation and impacts their performance.  In addition, the billings metric reported by the company includes amounts that have not yet been recognized as revenue.  The components that Palo Alto Networks excludes in its calculation of non-GAAP financial measures may differ from the components that its peer companies exclude when they report their non-GAAP results of operations. Palo Alto Networks compensates for these limitations by providing specific information regarding the GAAP amounts excluded from these non-GAAP financial measures. In the future, the company may also exclude non-recurring expenses and other expenses that do not reflect the company’s core business operating results.

ABOUT PALO ALTO NETWORKS
Palo Alto Networks is leading a new era in cybersecurity by protecting thousands of enterprise, government, and service provider networks from cyber threats.  Unlike fragmented legacy products, our security platform safely enables business operations and delivers protection based on what matters most in today’s dynamic computing environments: applications, users, and content.  Find out more at www.paloaltonetworks.com.

Palo Alto Networks and the Palo Alto Networks Logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.

1 Gartner, “Magic Quadrant for Enterprise Network Firewalls”, Greg Young, Adam Hils, Jeremy D’Hoinne; April 15, 2014.

http://investors.paloaltonetworks.com/phoenix.zhtml?c=251350&p=irol-newsArticle&id=1935206

[Source: Palo Alto Networks]

Palo Alto Networks News of the Week – May 23

In a three-part series, CSO Rick Howard highlights the importance of understanding differentcyber adversaries and their motivations. Check out Part 1Part 2 and Part 3.

Healthcare organizations are at risk of being the next “Target” for cyber criminals. We’re encouraging an AVR report with Palo Alto Networks to gain deeper visibility into what’s on your network.

On May 20, Palo Alto Networks Wildfire detected the start of the latest Kuluoz spam campaign.

Customer Spotlight: Animal Logic, one of the world’s most accomplished digital studios, relies on Palo Alto Networks next-generation firewall to more efficiently manage its network security.

Palo Alto Networks responded to the recent Richard Stiennon article in Forbes about Microsoft licensing within embedded systems.

Here are more upcoming events you should know about:

Oppdag hurtig ukjente trusler med utvidet visibilitet og intelligens. [Norwegian]
When: May 27, 2014 from 3:00 PM – 3:30 PM CET
Where: Online

Expose the Underground [Spanish]
When: May 28, 2014 from 8:00 PM – 10:00 PM CST
Where: Ciudad de Mexico, DF

Next Generation Security Technical Workshop
When: May 28, 2014 from 10:00 AM – 1:00 PM GMT
Where: London

Palo Alto Networks: Live Demo
When: May 28, 2014 from 9:00 AM – 10:00 AM PST
Where: Online

Transforming Networks Security with the Software Defined Data Center
When: May 28, 2014 from 1:00 PM – 2:00 PM CET
Where: Online

Ultimate Test Drive Workshop Brisbane
When: May 28, 2014 from 11:00 AM – 3:00 PM GMT+10:00
Where: Brisbane

AFCEA: Spring Intelligence Symposium – Intel
When: May 29, 2014 from 8:00 AM – 6:00 PM EST
Where: Bethesda, MD

Combat APTs with Palo Alto Networks
When: May 29, 2014 from 10:30 AM – 11:30 AM GMT+7:00
Where: Online

Expose the Underground
When: May 29, 2014 from 11:30 AM – 1:30 PM MST
Where: Edmonton, AB

Expose the Underground [Spanish]
When: May 29, 2014 6:30 PM – 9:00 PM CST
Where: Monterrey

Oppdag hurtig ukjente trusler med utvidet visibilitet og intelligens. [Norwegian]
When: May 30, 2014 from 3:00 PM – 3:30 PM CET
Where: Online

Combat APTs with Palo Alto Networks
When: June 3, 2014 10:30 AM – 11:30 AM GMT + 7:00
Where: Online

Discover Unknown Threats with Extended Visibility and Intelligence
When: June 3, 2014 1:00 PM – 2:00 PM CET
Where: Online

Palo Alto Networks: Live Demo
When: June 4, 2014 9:00 AM – 10:00 AM PST
Where: Online

Discover Unknown Threats with Extended Visibility and Intelligence
When: June 5, 2014 1:00 PM – 2:00 PM CET
Where: Online

Palo Alto Networks: Live Demo ANZ
When: June 5 2014, 10:00 AM – 11:00 AM GMT + 10:00
Where: Online

[Source: Palo Alto Networks]

English
Exit mobile version