Home Blog Page 307

Bleckwen raises $10m in funding, appoints David Christie as CEO

Startup funding

Fraud detection & prevention provider Bleckwen announced it has raised $10 million first funding round. The funding will be used to support the company’s international expansion as well as development of its AI-based fraud detection portfolio. The funding round was led by Ring Capital, a Paris-based venture capital firm and existing investors, including TempoCap, Bpifrance and Ineo, alongside senior management.

Bleckwen has its expertise in the field of anti-money laundering (AML) and counter-terrorism financing (CTF). It recently spun-off from Ercom, a French cybersecurity firm.

The company had also appointed industry veteran David Christie as the CEO. David was the former COO of Euronet’s money transfer business, which included the brands Ria, HiFX and XE. He was also the chairman of VitessePSP and investor in Shieldpay. He brings over two decades of experience to the table.

“Nearly $4 trillion is stolen and laundered through banks annually – circa 3% of global GDP. Existing technologies are just not cutting it in the fight against this scourge of society. Something else needs to be done and at Bleckwen, we have made tremendous progress over the last two years as part of the Ercom Group, developing solutions to bring the fight to these criminals,” David Christie, Bleckwen’s CEO, commented in a release.

“This fundraising is confirmation of our ‘scale-up readiness’ and the support from  Ring Capital and our existing investors is testament to our expertise in productising class-leading AI-based analytics in the fight against financial crime for banks. Using Bleckwen’s software, we are seeing false positive ratios drop by over 95%, the time taken to resolve alerts fall by over 50%, and a reduction in fraud loss ratios by over 60% – as compared with incumbent legacy-based rules systems,” he said, while adding, “Working very closely with our customers, which include a tier-1 global bank, we have developed a market-leading, payment-type agnostic, real-time capability to meet their fraud detection and prevention requirements at industrial scale.”

Avast announces appointment of Michal Pěchouček as CTO

Avast has announced the appointment of Michal Pěchouček as Chief Technology Officer. The appointment will be effective from September 1, 2019.  Currently, Michal Pěchouček is a Faculty of Electrical Engineering leading the Department of Computer Science and the Artificial Intelligence Center at Czech Technical University (CTU) in Prague.

“Michal’s experience in academia and industry, his ability to connect ideas, people, and resources from different fields, and his track record in leading successful teams make him the ideal fit for our CTO role. One of his core responsibilities will be to further our research in AI, machine learning, and cybersecurity. Michal will also be leading our core technology and R&D teams to support the work of our Threat Labs, and our big data and innovation teams. I am excited to have him and his colleagues join us, helping us to forge a stronger collaboration with academia in this fast-moving field of applied research,” Ondrej Vlcek, Avast’s new Chief Executive Officer, said of the appointment in a release.

Michal Pěchouček is a renowned technology expert and has been known for his contributions in the field of computer and AI applications. He is also an author of several highly cited papers. He was also the co-founder of several technology start-ups including cybersecurity firm Cognitive Security, AgentFly, and BlindSpot Solutions. He also directed the R&D Center of AI and Computer Security for CISCO as well as worked as a strategist in the CISCO Security CTO office.

“This paves a new way for industry and academia to work together on some of the biggest and most exciting research-based challenges of our time. Avast’s commitment to funding ongoing and new research in AI and machine learning enables CTU to demonstrate its expertise in these fields, helping attract and retain the best and brightest minds. Avast is recognized as the AI company in the field of cybersecurity, so I’m looking forward to getting started in my new role and together with engineers and scientists from AVAST and their colleagues from CTU to further develop AI to help people to be safe on the internet,” Michal Pěchouček commented about his appointment.

 

Yandex allegedly attacked by Western intelligence as part of cyber espionage

Yandex suffers insider attack

Russian search platform, Yandex, also a competitor of Google was hacked by Western intelligence, according to a report on Reuters.  The alleged hack occurred to search for information on how Yandex authenticates user accounts.

As per the reports, the hack occurred between October and November in 2018. The report also quoted four people under anonymity who had knowledge of the hack. A malware dubbed as Regin was used to penetrate into the systems. Apparently, Regin is a tool that is used by the “Five Eyes,” an intelligence nexus which comprises of United States, Britain, Australia, New Zealand, and Canada.

Ilya Grabovsky, a spokesperson from Yandex acknowledged the hack but did not provide any other details. “the attack was detected early on by Yandex’s security team, which stopped it before any damage was done. No user data was compromised by the attack.” According to reports, when Yandex suspected a malware outbreak, they immediately notified a team of security specialists from Kaspersky who identified the type of malware and indicated that programmers inside Yandex were targeted in the attack.

Further analysis by Kaspersky revealed that the attackers originated from Western intelligence with the sole intention of cyber espionage, “rather than to disrupt or steal intellectual property,” the researchers said. According to several security experts, the tools used in the Yandex hack was never seen or used in any other cyber attack and was one of a kind.

Several key bodies were reached out by Reuters for comment but almost all the western agencies declined. Dmitry Peskov, a spokesman from Kremlin told Reuters that the Government of Russia was not aware of the attack. “Yandex and other Russian companies are attacked every day. Many attacks come from Western countries,” he added.

Meanwhile, cybersecurity firm Symantec stated that even they recently discovered a new version of Regin. “Regin is the crown jewel of attack frameworks used for espionage. Its architecture, complexity and capability sits in a ballpark of its own,” Vikram Thakur, technical director at Symantec Security Response, told Reuters. “We have seen different components of Regin in the past few months. Based on the victimology coupled with the investment required to create, maintain, and operate Regin, we believe there are at best a handful of countries that could be behind its existence. Regin came back on the radar in 2019.”

EU Cybersecurity Act gives more power to ENISA

The European Cybersecurity Act has been put to force. The European Union Agency for Network and Information and Security (ENISA) is the key governing body as per the act and will judge products to be assessed for cybersecurity weaknesses. The Act ends ENISA’s temporary role, which was set to end in 2020 after renewal in 2013.

“This means very concretely – if one Member State is a cyberattack victim, it can very quickly use ENISA’s expertise to identify vulnerabilities and resolve it, which has not been possible so far. even when they are not a victim of the cyberattack, ENISA can help them find out very quickly what’s going to make them more cyber-safe, ” Maria Gabriel, Commissioner for Digital Economy and Society, told the Bulgarian National Radio.

According to her, cybersecurity certifications will also be part of the act. “European citizens will be able to know at what level of security are the product they buy, and for European businesses, for the first time, a certificate valid in one of the Member States will be valid for the whole territory of the Union,” she said.

With the newly assigned duties to the ENISA, the key governing body will be instrumental in setting up and maintaining the European cybersecurity certification framework. ENISA will prepare a technical specification for several certifications for both public and private enterprises.

“In order to achieve equivalent standards throughout the Union, to facilitate mutual recognition and to promote the overall acceptance of European cybersecurity certificates and EU statements of conformity, it is necessary to put in place a system of peer review between national cybersecurity certification authorities. Peer review should cover procedures for supervising the compliance of ICT products, ICT services and ICT processes with European cybersecurity certificates, for monitoring the obligations of manufacturers or providers of ICT products, ICT services or ICT processes who carry out the conformity self-assessment, for monitoring conformity assessment bodies, as well as the appropriateness of the expertise of the staff of bodies issuing certificates for assurance level ‘high’. The Commission should be able, by means of implementing acts, to establish at least a five-year plan for peer reviews, as well as lay down criteria and methodologies for the operation of the peer review system,” states the Act.

ENISA has also been mandated to increase cooperation at with member EU states and provide them support while handling cybersecurity incidents, these even include large-scale state-sponsored cyber attacks. With the act in place, ENISA will serve as a secretariat to the Computer Security Incidents Response Teams (CSIRTs) Network.

Mobile app security startup NowSecure raises $15 million

Mobile application security software company NowSecure recently secured $15 million in a stock financing round led by ForgePoint Capital. The U.S.-based startup stated the investment will be used to fuel further product development and scale its business operations.

The NowSecure security platform delivers automated mobile app security and privacy testing with the speed, accuracy, and efficiency necessary for Agile and DevOps environments, that runs on real Android and iOS devices. The company claims that its security software is powered by the industry’s most advanced static, dynamic, behavioral, interactive mobile app security, and privacy testing solutions.

Speaking on the new investment proceeds Alan Snyder, the CEO of NowSecure said, “Every business is becoming mobile first; yet millions of people are using apps daily that have major security and privacy issues. NowSecure is addressing this fundamental, global-scale problem that puts businesses and consumers at direct risk. We’re thrilled to be working with ForgePoint Capital to grow our business and empower mobile app developers to deliver secure mobile apps faster. ForgePoint has the right mix of veteran leadership, industry relationships and successful track record across their security portfolio to support NowSecure.”

“From digital transformation projects to pure mobile businesses driving multi-billion-dollar global economies, the stakes have never been higher for mobile security and privacy. NowSecure has the right mix of talented team, unmatched technology and proven track record serving world-class customers,” said J. Alberto Yépez, Co-Founder and Managing Director, ForgePoint Capital. “We are excited to partner with NowSecure to help them grow the business, serving a global enterprise market expected to grow to nearly $1 billion by 20232. As the market leader in automated mobile app security testing, NowSecure is well positioned to accelerate their leadership position addressing a critical gap in this massive growth market.”

In a similar investment round, the Mobile cybersecurity company Guardsquare recently raised $29 million investment in its first round of institutional financing round led by Battery Ventures. The Belgium-based company also added Battery Venture’s General Partner Dharmesh Thakker and Principal Paul Morrissey to its leadership team. Guardsquare stated the new funds will be used to leverage its investment in sales, marketing, R&D, and customer-success efforts.

Guardsquare provides premium security solutions for the protection of mobile applications against reverse engineering and cyber hacks. The company claims that its technology is already embedded in more than quarter of Android apps and its software products are used across various industries, like financial services, e-commerce, public sector enterprises, telecommunication, gaming, and media.

 

FDA issues warning over security of Medtronic insulin pumps

Medical Data

Medical IoT device maker Medtronic has initiated for a recall for several units of its insulin pumps after it was discovered that the devices were vulnerable to hacks and there is no way to patch the security holes. The said devices were MiniMed 508 and MiniMed Paradigm series insulin pumps.

“The MiniMed™ 508 insulin pump and the MiniMed™ Paradigm™ series insulin pumps are designed to communicate using a wireless radio frequency (RF) with other devices such as a blood glucose meters, glucose sensor transmitters, and CareLink™ USB devices,” Medtronic alerted users in a statement. “Security researchers have identified potential cybersecurity vulnerabilities related to these insulin pumps. An unauthorized person with special technical skills and equipment could potentially connect wirelessly to a nearby insulin pump to change settings and control insulin delivery. This could lead to hypoglycemia (if additional insulin is delivered) or hyperglycemia and diabetic ketoacidosis (if not enough insulin is delivered).”

It was the FDA that announced the vulnerabilities in the medical IoT devices from Medtronic. “The FDA is warning patients and health care providers that certain Medtronic MiniMed™ insulin pumps have potential cybersecurity risks. Patients with diabetes using these models should switch their insulin pump to models that are better equipped to protect against these potential risks,” FDA stated in a statement. The FDA also listed out the devices that were vulnerable in the statement.

Cybersecurity experts say cybercriminals are increasingly targeting the healthcare industry to steal sensitive medical information and sell it on the black market.

A survey from cybersecurity company Carbon Black stated the rate of cyber-attacks on healthcare industry appear to be increasing exponentially. In its survey report Healthcare Cyber Heists in 2019, Carbon Black has disclosed what is happening to the Personal Health Information (PHI) that was stolen by cybercriminals.

The survey, which involved 20 of the healthcare industry’s Chief Information Security Officers (CISOs), found the healthcare sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that personal health information is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.

Bank of Canada announces partnership to enhance cybersecurity in Financial Sector

Bank of Canada

The Bank of Canada recently announced the launch of its public-private partnership with the Canadian Financial Sector Resiliency Group (CFRG) to strengthen cybersecurity resilience of Canada’s financial sector and mitigate the risks to business operations, including cyber-attacks.

The new collaboration allows CFRG to coordinate a sector-wide response to systemic-level operational incidents and accelerate ongoing resiliency initiatives like regular crisis simulation and benchmarking exercises.

The partnership, which’s expected to start from August 2019, will reduce the cyber risks and help ensure a robust recovery in the event of a security incident.

Led by the Bank of Canada, the partnership initiative combines various organizations in the Finance industry, including Department of Finance Canada, Office of the Superintendent of Financial Institutions (OSFI), Canada’s systemically important banks, Designated Canadian financial market infrastructures (FMIs), which include the payment, clearing, and settlement systems.

Commenting on the new initiative Stephen S. Poloz, the Bank of Canada Governor said, “We need strong controls within each institution. And we need partnerships between public agencies and the private sector to bridge any gaps in coordination, especially when it comes to cyber risks. The CFRG brings together many of our trusted partners to work with us making our financial system safe and resilient.”

“Operational risks—including cyber-attacks—are real, and they pose a threat to the payments system and in fact the entire financial system,” said Brian Porter, Chief Executive Officer of Scotiabank. “We look forward to working with the Bank of Canada and organizations across the sector to build a more resilient, more robust financial system that better protects our customers against new threats.”

With an aim to strengthen the artificial intelligence and machine learning practices, the Royal Bank of Canada (RBC) invested around $2 million in Cybersecurity Research Center at Ben-Gurion University last year. The funding supports the development of existing artificial intelligence, creation of advanced protection methods, machine learning procedures and for mitigation of their vulnerability to data threats.

The research center will be supervised by Prof. Yuval Elovici and Dr. Asaf Shabtai from the Department of Software and Information Systems Engineering at the Ben-Gurion University Cybersecurity Research Center.

A peak into Safe-T’s Zero Trust Access solution

Penetration Testing, continuous testing, security testing

Contributed by Safe-T

Safe-T provides a secure application and file access solution with 1) An architecture that implements Zero Trust Access, 2) A proprietary secure access control channel that enables users granted appropriate permissions access to shared sensitive files and folders, and 3) User behavior analytics.
Why The Traditional Network Security Perimeter Is Obsolete

Most data centers implement a security perimeter model that establishes zones of trust based on ranges of IP addresses. They deploy back-to-back firewalls creating a DMZ that separates their trusted internal network from the external untrusted internet.

For the following reasons the traditional security perimeter topology is a flawed paradigm with vulnerabilities and risks that are increasingly difficult for security teams to manage.

Trusted Zones: A hacker who infiltrates the inner firewall of an organization is inside what is regarded as a trusted area. The hacker can then move about laterally stealing credentials and using them to capture and exfiltrate valuable digital resources.

Cyber Attacks: Hackers can bypass and exploit the architecture of a traditional security perimeter. They can use spear phishing attacks, exploit misconfigured firewalls, distribute malware via websites, and collaborate with malevolent insiders.

Mobile Workers: Company networks are expanding in size and complexity. Employees, contractors, and partners use laptops and other mobile devices offsite in locations external to the trusted perimeter network. They connect to company backend servers via Wi-Fi hotspots while sipping a latte in coffee houses, waiting for a plane in an airport lounge, and connecting from other locations anywhere in the world.

Cloud Applications: Companies are increasingly deploying their web applications and data on public clouds such as Amazon Web Services and Microsoft Azure. These public clouds are typically located in geographically locations remote from an organization’s trusted perimeter network.

VPNs: Using VPNs to access an internal network can create a vulnerability if an administrator grants overly broad permissions to users. VPNs are often configured enabling users to access the inner network as if the user was onsite in a company office.

An additional problem with VPNs is they create a high level of risk that malware in a user’s device can spread to an inner network.

Security professionals have come to the realization the traditional perimeter security model is not able to safeguard access to critical IT resources.

What Is Zero Trust Network Access

These are key principles of a Zero Trust network:

Trust Nothing: Users and network traffic are not trusted until verified. Users whether inside or outside the organization’s network should never be trusted by default.

Visibility: Backend servers are not visible to unauthenticated users.

Authentication: Authentication workflows for a user or group should include context-aware data such as device ID, geographic location, and the time and day the user requests access.

Granularity: Zero trust supports network micro-segmentation isolating IT resources to limit threats. It also implements a policy of least privilege by enforcing controls that enable users to have access only to resources needed to perform their jobs.

Logs: All traffic internally as well as externally is logged to detect malicious or anomalous events.

Safe-T’s Zero+ Architecture

Safe-T provides a secure application and file access solution with 1) An architecture that implements Zero Trust Access, 2) A proprietary secure access control channel that enables users granted appropriate permissions access to shared sensitive files and folders, and 3) User behavior analytics.

Safe-T Software Defined Perimeter

Safe-T Zero+ Capabilities
  • Users who want to access a protected server must successfully authenticate and be authorized at an authentication gateway.
  • Configurable policies define orchestrated authentication steps each user or group member is required to perform.
  • Backend servers are not visible to unauthenticated users. The probability of successful attacks is minimized following Safe-T’s axiom: If you can’t be seen, you can’t be hacked®.
  • Eliminates the possibility of users establishing a direct connection from an untrusted network to specific hosts in the internal Provides URL rewriting to hide backend services.
  • Implements a patented technology to eliminate the need to open incoming ports in the internal firewall. Eliminates the need to store sensitive data in the DMZ.
  • Support a variety of communication protocols: HTTP/S, SMTP, SFTP, APIs, RDP, WebDAV.
  • Extends to on premises, public, and hybrid cloud. Zero+ can be deployed on AWS, Azure, and other cloud infrastructures protecting both cloud and on-prem resources.
  • Provides user behavior analytics capability that monitors the actions of protected web applications. A dashboard displays security related events and aggregated statistics. Administrators work at the dashboard to inspect details about anomalous behavior that can trigger alerts and identify suspicious activities.
  • Provides a unique, native HTTPS-based file access solution for NTFS file system, replacing the vulnerable SMB protocol. Users can create a standard mapped network drive in their Windows explorer providing a secure, encrypted, and access-controlled channel to shared backend resources.
Conclusion

Implementing Safe-T Zero+ in your organization helps protect your data center from cyberattacks that could be successful against a traditional security perimeter. Safe-T Zero+ also helps ensure regulatory bodies that your company is meeting information governance and security regulations.

CISO MAG does not evaluate the advertised product, service, or company, nor any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cloud Email Cybersecurity startup GreatHorn secures $13 million

Funding round

GreatHorn, an email security platform provider, recently announced that it has closed a $13 million funding round jointly led by RRE Ventures and .406 Ventures along with the participation from the existing investors, including Techstars Ventures, V1.VC, and Uncork Capital. The American-based company stated the new investment will support its business expansion operations and help the company to continue its position as the innovation leader in the email security industry.

Founded in 2015, GreatHorn offers a security platform that safeguards cloud email from advanced threats such as individual and brand impersonations, credential theft attempts, malware, ransomware, and advanced social engineering-based phishing attacks. The company claims that its security products connect directly to Office 365 and G Suite without any need for DNS editing or existing email setups.

Speaking on the new investment Kevin O’Brien, the CEO of GreatHorn stated, “With a fast-growing customer base and track record of best-in-class detection and innovation for today’s cloud-based email platforms, GreatHorn has changed the way the industry talks about email security. As we continue to meet customer demand and drive the market, we remain fundamentally interested in redefining email as a secure system for all users, and ensuring that organizations who have adopted cloud email platforms are not relying on outdated perimeter controls or simple user education to protect their most critical assets.”

“RRE Ventures invests in passionate and tenacious teams that are building category-defining businesses,” said Raju Rishi, General Partner at RRE Ventures. “Despite decades of experience and billions of dollars spent, the email security industry is no closer to making email safe for businesses. By rethinking how we approach email security, GreatHorn has delivered a platform that comprehensively protects enterprises against the rising sophistication of today’s threats. We’re excited to support GreatHorn as the company continues to build upon its current innovation and grow in the enterprise space.”

Cybersecurity firm unveils hacking campaign Operation Soft Cell

Ransomware gangs

Security researchers from cybersecurity firm Cybereason recently exposed the findings of their investigation into a massive hacking campaign on several global telecommunication companies.

Cybereason stated the hacking operation, named Operation Soft Cell, compromised companies in more than 30 countries and snooped huge amounts of personal data from individuals and companies. It’s believed that the alleged spying operation is possibly linked to state actors of China.

Cybereason is an Israel-based startup founded by former members of the Unit 8200 military intelligence division. Founded in 2012 by Div, Yossi Naar, and Yonatan Striem-Amit, Cybereason develops “military-grade technology” to counter advanced cyber-attacks. Their strategy is based on the immediate detection of an attack, finding a component that is part of the attack, and using this as the starting point to seek out other pieces of information that are part of the attack.

“In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor using tools and techniques commonly associated with Chinese-affiliated threat actors, such as APT10.  This multi-wave attacks focused on obtaining data of specific, high-value targets and resulted in a complete takeover of the network,” Cybereason said in a statement.

According to the investigation findings, the hacking campaign was spanned for seven years and involved in the theft of call records from cellular network providers. The hacker group conducted surveillance on target individuals working in law enforcement, government, and politics.

“During the persistent attack, the attackers worked in waves – abandoning one thread of attack when it was detected and stopped, only to return months later with new tools and techniques,” Cybereason added.

Describing the hacking espionage was on a massive scale, the Cybereason’s CEO and co-founder Lior Div said, “This advanced attack used a low-n-slow attack paradigm which circumvents almost all detection capabilities in the market today. This isn’t a smash-and-grab campaign to steal money or social security numbers. These hackers have very specific motives and are running a highly targeted, persistent operation to own the networks and track a very targeted list of high-profile individuals on different continents.”