Home Blog Page 293

Axonius secures $20 million to bolster cybersecurity tools

NCSC for Startups Initiative

Axonius, a developer of end-to-end device management platform, recently raised $20 million in a Series B funding round led by OpenView along with the participation from Bessemer Venture Partners, YL Ventures, Vertex, WTI, and Emerge. The New York and Tel Aviv-based cybersecurity startup stated the new funding will help the company boost its customer acquisition and expedite product development.

“We’ve found a way to solve this decades-old problem, and this funding will allow us to double down on our mission to enable our customers to take control of their assets and rest assured their environments are secure,” said Sysman, co-founder of Axonius.

Founded in 2017, Axonius provides end-to-end management solutions to cover security gaps by validating and enforcing enhanced security policies. It helps enterprises bolster their cybersecurity capabilities. The company has several services including active directory, endpoint protection tools, cloud tools, NAC solutions, VA scanners, and Mobile Device Management systems.

“There’s a tendency to solve enterprise-level problems with complex, heavy solutions. But Axonius is taking the opposite approach by solving asset management with an elegant solution that customers love. It’s time we turn the tide on a problem that has plagued organizations for decades, and we believe Axonius is well positioned to do just that,” said OpenView partner Mackey Craven.

Axonius has been hogging a lot of limelight recently. In the RSA Conference, earlier this year, the company was awarded the Most Innovative Startup of the Year after it won the RSAC Innovation Sandbox Contest.

“I am blown away that the judges recognized a problem as mundane as asset management to be the winner this year,” said Nathan Burke, chief marketing officer of Axonius after winning the award. “It is amazing that a really big and nagging problem that hasn’t been solved yet is something that the judges decided is worthy of winning.”

Ongoing Attack Campaign Exploits Various WordPress Plugins: Researchers

Cybercriminals Tried to Access Database Logins of 1.3 Mn WordPress Sites

Security researchers found that cybercriminals are using WordPress plugins for an ongoing attack campaign targeting numerous WordPress sites. The researchers are from the security firm WordFence. The attackers are exploiting vulnerabilities in the WordPress plugins to divert traffic from the victim’s site to malicious websites.

“Over the past few weeks, our Threat Intelligence team has been tracking an active attack campaign targeting a selection of new and old WordPress plugin vulnerabilities. These attacks seek to maliciously redirect traffic from victims’ sites to several potentially harmful locations. Each of the vulnerabilities targeted by this campaign has been public for some time, and users are protected either by individual firewall rules or generic protections built into the plugin,” the researchers said in an official statement.

According to the researchers, the flaws in the WordPress plugins allow an attacker to get Admin access by modifying WordPress options and also enables the attacker to inject malicious 301 redirects on the targeted website.

Researchers said that various other WordPress plugins are under exploitation in the ongoing campaign including, Yellow Pencil Visual Theme Customizer, Blog Designer, Woocommerce User Email Verification, Coming Soon, and Maintenance Mode.

CrowdStrike announces $20 million Falcon Fund for cybersecurity startups

Startup Funding

CrowdStrike, a provider of cloud-delivered endpoint protection services, recently launched a $20 million early-stage investment fund with the partnership from Accel. The new investment fund, named as Falcon Fund, is intended on seed and Series A investments in security startups that are building applications on the CrowdStrike Falcon platform.

CrowdStrikeoffers instant visibility and protection across enterprises and prevents attacks on endpoints network. The company claims that CrowdStrike’s Falcon platform delivers real-time protection and actionable intelligence. It protects customers against all types of cyber-attacks by using artificial intelligence and Indicator-of-Attack (IoA) based threat prevention to stop known and unknown threats in real-time.

With the launch of the Falcon Fund, CrowdStrike helps foster innovation for new startups. The Falcon fund will act as a co-investor and strategic partner for innovative startups, reducing the investments in expensive platforms for storage and analytics.

In order to qualify for the Falcon Fund, startups must have a dedicated team to tackle a significant problem that requires performing analytics on endpoint data. Also, the startups must be using the CrowdStrike Falcon cloud platform and endpoint agent. Interested startup companies can directly apply at CrowdStrike website.

“With the launch of Falcon Fund, we are investing in the next generation of innovators who are committed to solving today’s most pressing security and IT challenges by leveraging the unique cloud-native architecture and lightweight agent of the Falcon platform. We plan to invest in companies that share our focus on customer success, simplifying security, IT operations and management with our modern, cloud-native platform,” said George Kurtz chief executive officer and co-founder of CrowdStrike.

CrowdStrike recently announced its partnership with New Zealand-based cybersecurity firm InPhySec Security Ltd to address cybersecurity issues in New Zealand. InPhySec is an information security company, which consists of seasoned security specialists with extensive experience in the New Zealand Security, Defence, and Intelligence Community. The new alliance integrates the cloud-native architecture of the CrowdStrike Falcon platform with InPhySec’s security platform to deliver faster, smarter, and more agile solutions to joint customers.

Malware in CamScanner App affects Millions of Android Phones

Trickbot Malware

Security researchers found a Malware in the CamScanner, a phone-based PDF creator, Android application, which has over 100 million downloads from the Google Play Store.

According to security researchers Igor Golovin and Anton Kivva from Kaspersky, the Malware dubbed Trojan-Dropper Malicious Module was discovered in CamScanner Android apps that could inject Malicious codes into the mobile devices.

The researchers said that they found the malware after reading negative reviews on the CamScanner app posted by users. They also stated, “that the developer added an advertising library to it that contains a malicious dropper component.”

“Kaspersky researchers examined a recent version of the app and found the malicious module there. We reported our findings to Google, and the app was promptly removed from Google Play. It looks like app developers got rid of the malicious code with the latest update of CamScanner. Keep in mind, though, that versions of the app vary for different devices, and some of them may still contain malicious code,” Kaspersky said in a statement.

“Kaspersky products detect this module as Trojan-Dropper.AndroidOS.Necro.n, which we have observed in some apps preinstalled on Chinese smartphones. As the name suggests, the module is a Trojan Dropper. That means the module extracts and runs another malicious module from an encrypted file included in the app’s resources. This “dropped” malware, in turn, is a Trojan Downloader that downloads more malicious modules depending on what its creators are up to at the moment,” the statement added.

However, this is not the first time to discover Malwares on Android smartphones. Recently, security researchers revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to the researchers from Kaspersky, a hacker group has been found targeting Israel’s citizens and other Middle East countries with surveillance malware named Triout.

The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or send messages to specific numbers, according to the researchers. The researchers said that attackers used Smali injection technique, that allows hackers to disassemble the code of an original application and add malicious code.

Cybersecurity firm Imperva hacked

70 Mn Records Exposed After AFL Fan Website Leaks Users’ Data

This one is as close to stealing a cop car from a police station. Cybersecurity firm, Imperva, which has often been on the forefront in the information security space, is the latest victim of a massive data breach. This not only takes a dig at the company’s clientele but even ruins the reputation of the company.

The incident was reported by Kerbs on Security. According to the reports, Imperva recently notified its customers that a data breach in Incapsula, the firm’s cloud Web Application Firewall (WAF) product.

“On August 20, 2019, we learned from a third-party of a data exposure that impacts a subset of customers of our Cloud WAF product who had accounts through September 15, 2017,” wrote Heli Erickson, director of analyst relations at Imperva. “We want to be very clear that this data exposure is limited to our Cloud WAF product.”

“While the situation remains under investigation, what we know today is that elements of our Incapsula customer database from 2017, including email addresses and hashed and salted passwords, and, for a subset of the Incapsula customers from 2017, API keys and customer-provided SSL certificates, were exposed,” he added.

Imperva has been among the three most popular Web-based firewall providers. The attack and the possession of customer’s API keys and SSL certificates pose a much greater risk.

Imperva had recently signed an agreement to acquire Distil Networks, a Bot Management startup, to help thwart bot attacks. The California-headquartered firm developed and sold information security software for databases and web applications, on-premises, in the cloud, and across hybrid environments.

It also signed an agreement to acquire network management startup Prevoty for $140 million to provide security solutions for application services residing on-premises and in the cloud. The agreement allowed both companies to expand their customers’ security capabilities and their visibility into how applications are accessed, and how applications and users interact with data. It gave deeper insights to customers to understand the security risks and the ability to protect their business from cybercriminals.

Facebook’s Libra announces Bug Bounty of $10,000

Facebook Data leak, Facebook bans cyber mercenary

Facebook recently announced that it’s working with bug bounty platform HackerOne to launch a bug bounty program for its Libra Association. The social media giant is rewarding up to $10,000 to security researchers who discover potential flaws in Libra’s testnet.

Facebook announced its cryptocurrency LIBRA and digital wallet Calibra in June 2019.  Libra Association is a pool of large enterprises and non-profits, including Visa, Spotify, Mastercard, Lyft, eBay, and Uber, which are responsible for processing the transactions of the crypto coin and blockchain. Despite the regulatory issues, Facebook is moving ahead with its Libra coin, which is expected to launch in 2020.

“The Libra Association launched its public bug bounty program on August 27, 2019. The Libra Bug Bounty program is intended to strengthen the security of the Blockchain. It enables developers to submit bugs and alert the association to security and privacy issues and vulnerabilities to help ensure a scalable, reliable, and secure launch,” Facebook said in an official statement.

“The program will encourage many more people with diverse skills and backgrounds to inspect and review the Blockchain design and implementation. The Libra Bug Bounty program is part of a larger ongoing effort to build an open and vibrant community of security and privacy developers around the globe,” the statement added.

Facebook is not the first company to offer bug bounties. Recently, search engine giant Google announced the increase in bug bounty rewards, making them more lucrative to security researchers. The search engine giant stated that it has raised the bounties for Chrome and Google Play bugs.

Google launched the vulnerability rewards program in 2010 and provides cash rewards to security researchers who report vulnerabilities in Google code. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over $5 million (£4 million).

Also, technology giant, Microsoft admitted that it paid $4.4 million to hackers as bug bounties in the past 12 months. The technology giant confirmed this at the Black Hat 2019 security event in Las Vegas.

Platform9 secures $25 million to accelerate growth

Aviatrix Funding

Platform9, a provider of SaaS-managed hybrid cloud solutions, recently announced that it has raised $25 million in a Series D funding round led by NGP Capital along with the participation from Mubadala Ventures and existing investors including, Canvas Ventures, Redpoint Ventures, Menlo Ventures, and HPE Pathfinder.

The California-based company stated that the new funds will help in expanding its global salesforce, product, and marketing teams. Platform9 also stated that it will continue delivering new capabilities for cloud-native hybrid cloud infrastructure management. As per the investment deal, Rohini Chakravarthy, Partner at NGP Capital, will join Platform9’s board of directors.

Founded in 2013, Platform9 provides SaaS-managed Hybrid Cloud solutions that offer complete automated operations running on-premises and in public clouds. The company claims that it helps enterprises run cloud-native infrastructure at scale without operational costs.

“Simplifying the operational burden of delivering cloud-native infrastructure at scale across any environment is a key consideration for organizations going through digital transformation. They are looking to leverage open-source modern technologies on top of their existing infrastructure and multi-cloud deployments, without crumbling under the complexity of managing technologies such as Kubernetes, monitoring, service-mesh, and more,” said Sirish Raghuram, CEO and Co-founder of Platform9. “This is exactly where our unique SaaS-managed delivery model comes in. Our Cloud Control Plane manages the infrastructure for you – including built-in monitoring, upgrades, disaster recovery, and more.”

“Platform9 continues to win for enterprises that value ease of use, time to market, interoperability, and greater cost efficiencies. We’re excited to further build upon the momentum we are seeing in the market by investing in our world-class teams and partners around the world,” Raghuram added.

Data Breach affects 14 million Hostinger Customers

Hostinger stated that it has changed the login credentials of 14 million of its customers who were affected in the recent security breach. The popular web hosting provider revealed that an unauthorized third-party accessed one of their client’s servers on August 23, 2019, and obtained customers’ sensitive information.

Hostinger stated that the exposed information included customers’ usernames, first names, hashed passwords, IP addresses, and emails. Along with the customers’ data, the attackers managed to gain access to Hostinger’s internal system API that contained hashed passwords and non-financial data of customers.

“On August 23rd, 2019 we received informational alerts that one of our servers has been accessed by an unauthorized third-party. This server contained an authorization token, which was used to obtain further access and escalate privileges to our system RESTful API Server. This API Server is used to query the details about our clients and their accounts,” Hostinger said in a blogpost.

Hostinger clarified that it has reset all its client passwords as a security measure and started an investigation on the issue.

“Following the incident, we have identified the origin of unauthorized access and have taken necessary measures to protect data about our clients, including mandatory password reset for our clients and systems within all of our infrastructure. Furthermore, we have assembled a team of internal and external forensics experts and data scientists to investigate the origin of the incident and increase security measures of all Hostinger operations. As required by law, we are already in contact with the authorities,” Hostinger stated.

Indian Security Researcher exposes a flaw in Instagram, wins $10,000 bug bounty

Instagram

Laxman Muthiyah, an Indian-based security researcher, recently discovered a bug in Instagram’s Account Recovery Process that could have allowed attackers to break into users’ accounts. The Facebook-owned Instagram rewarded the researcher with a bounty of $10,000 for reporting the vulnerability.

The researcher said that he found the vulnerability while investigating how the account recovery process of the photo-sharing application allows the user to regain access to your account when you’ve forgotten the password.

According to Muthiyah, the Instagram server uses device ID as a unique identifier to validate password reset codes. “When a user requests a passcode using his / her mobile device, a device ID is sent along with the request. The same device ID is used again to verify the passcode,” Muthiyah said in a statement.

The researcher found that the same device ID can be used to request passcodes for multiple Instagram accounts of different users, allowing an attacker to breach multiple accounts with a single device ID.

“There are one million probabilities for a 6-digit passcode (000001 to 999999). When we request passcodes of multiple users, we are increasing the probability of hacking accounts. For example, if you request passcodes of a hundred thousand users using the same device ID, you can have a 10 percent success rate since 100k codes are issued to the same device ID.  If we request passcodes for one million users, we would be able to hack all the one million accounts easily by incrementing the passcodes, one by one. Therefore, an attacker should request codes of one million users to complete the attack with a 100 percent success rate. We should also note the 10 minutes expiry of the code, so the entire attack should happen within 10 minutes,” Muthiyah explained.

Recently, an unprotected server containing personal information of millions of Instagram influencers, celebrities, and brand accounts was found online without password protection. According to security researcher Anurag Sen who discovered the leak, the database had over 49 million records exposed online, allowing anyone to access it. The exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number.

Anurag stated the leaky database belongs to a social media marketing firm Chtrbox, which is based in Indian state Mumbai. The database was taken offline and called for an investigation on the incident, Chtrbox stated.

Artificial Intelligence firm Capacity raises $13.2 million

Startup funding

Capacity, a startup that enables users to search using natural language, recently secured $13.2 million in a Series B funding round led by undisclosed Midwest angel and other private investors. Capacity, formerly known as Jane.ai, stated the proceeds will be used to accelerate the company’s growth and business expansion. The startup develops a platform that indexes information from various applications and enables users to search using natural language and artificial intelligence.

Founded in 2017, Capacity provides services in two formats. The first one is that it mines data from documents, webpages, email, and calendar apps like Gmail, customer relationship management (CRM) software like Salesforce and Oracle’s NetSuite. The second format is a chatbot, that’s integrated with natural language processing capabilities, that integrates with various messaging applications.

“We created Capacity to help everyday workers be more successful by eliminating the wasted time and effort that comes from searching for basic workplace information,” said Capacity cofounder and CEO David Karandish. “We’ve all grown accustomed to the convenience of on-demand, personalized services and voice-controlled speakers at home, but we have yet to benefit from these same conveniences at work. [Capacity] is an intuitive, intelligent AI-powered Teammate who gives employees instant access to the information they need to do their jobs well.”

In a similar funding round, artificial intelligence and automatic machine learning services provider H2O.ai secured $72.5 million in a Series D funding round led by Goldman Sachs along with the participation from Wells Fargo, NVIDIA, and Nexus Venture Partners. H2O.ai stated the new proceeds will accelerate the company’s sales and marketing operations. Along with the investment, Jade Mandel from Goldman Sachs will be joining the H2O.ai Board of Directors.

Founded in 2012, H2O.ai provides AI and automatic machine learning services to enterprises with a mission to introduce AI to every sector including financial services, insurance, healthcare, telco, retail, pharmaceutical, and marketing. H2O.ai claims that it has a strong client base of technology firms including NVIDIA, IBM, AWS, Intel, Microsoft Azure, Google Cloud Platform, Snowflake, and IBM Red Hat.