Home Blog Page 312

Edgewise Networks secures $11 million

Startup funding

Edgewise Networks, a micro segmentation platform services provider, recently announced that it has raised $11 million in a new funding round led by existing investors 406 Ventures, Accomplice, and Pillar. The new funds will support the company’s R&D and expand market activities to meet the demand for its innovative approach to deploying Edgewise’s Zero Trust Auto-Segmentation.

Founded in 2016, Edgewise helps organizations eliminate the problems of data breach and application compromise against critical business applications. Edgewise claims that its security solutions use machine learning and advanced analytics for discovering potential risks.

Describing the company’s portfolio, Peter Smith, the CEO and founder of Edgewise, said the Micro segmentation can secure applications, hosts, and even individual databases on the network and restrict communication into and out of these “secure zones.” But most means of doing so rely on IP addresses, ports, and VLANs. Today’s networks—especially cloud and containers— are dynamic. Therefore, using only ephemeral, network-based information to make secure access decisions is highly risky and unreliable as instances spin up and down and as new applications are continuously deployed. Plus, traditional methods of micro segmenting a network can take months, even years, cost millions of dollars, and is a policy management nightmare throughout the deployment. We thought there had to be a better way.

“Our innovative, patented approach makes micro segmentation—one of the hardest problems in cybersecurity— incredibly simple to implement. With Edgewise, companies can operate their applications in hybrid cloud and container environments with peace of mind, knowing that they are protected. This strong support from our investors will enable us to expand to meet the demand for automated micro segmentation,” Smith added.

Bithumb cryptocurrency exchange hacked again!

bithumb

Popular cryptocurrency exchange Bithumb once again made it to the headlines after discovering a cyber-attack. This is the third such incident for the South Korean exchange platform in the past three years.

In an official statement, Bithumb stated that on March 29, 2019, at around 10:15 pm the company detected abnormal withdrawals of its cryptocurrencies from its hot wallets. It’s believed that attackers possibly made off around three million EOS (worth $13.4 million) and 20 million Ripple coins (XRP) of worth $6 million.

Bithumb stated that it secured all the cryptocurrency during the detection time and confirmed that the customers’ assets are safe under the protection of a cold wallet.

Describing the incident as an “accident involving insiders”, Bithumb said “we are conducting intensive investigations with KISA, Cyber Police Agency and security companies. At the same time, we are working with major exchanges and foundations and expect to recover the loss of the cryptocurrency equivalent.”

This is a third cyber-attack the company revealed in the past three years. The first hack happened in July 2017, when hackers stole $7 million in Bitcoin and Ethereum, while the second incident took place in June 2018, when hackers stole hackers stole 35 billion won ($31 million). Bithumb released a list of 11 cryptocurrencies lost during the hack as well as the corresponding amounts.

Further, the losses of the hack have been reduced to $17 million, which is around 13 million less than the earlier estimated figure. “The main reason for the reduction of the damage is due to the ongoing participation, support and cooperation of cryptocurrency exchanges and cryptocurrencies foundations across the world. Also, our quick response to the cyber-attack by removing cryptocurrencies from hot wallet to cold wallet effectively contributed to reducing the overall damage,” the exchange stated in a statement about the reduction in the value of the lost coins.

Taiwan bans China-made semiconductors as per new cybersecurity law

Semiconductor

With an aim to build a secure information environment and safeguard national security, the Taiwan government has banned cable television providers from procuring semiconductors and other components made by Chinese companies for use in digital set-top boxes.

The National Communications Commission (NCC), Taiwan’s telecommunications regulator, stated that digital set-top boxes supplied by cable TV broadcasters in Taiwan will no longer use the chips and wafers of hybrid integrated circuits that are made in China, the South China Morning reported.

The ban, which’s intended to safeguard national security, comes after Taiwan’s cabinet introduced new rules on procuring technology in accordance with the Cyber Security Management Act. The prohibition by Taiwan directly impacts the chip-making firm HiSilicon, a unit of Huawei, which is currently facing trade restrictions in the United States.

Recently, Donald Trump, the President of the United States, declared a national emergency over threats against American technology. The president signed an executive order which effectively bars U.S.-based companies from using foreign telecoms, which are believed to pose national security risks, the White House said. The executive order does not name any company, but it’s believed that the move is expected to precede a ban on U.S. firms doing business with the Chinese telecommunications company, Huawei.

Following the executive order, the U.S. Department of Commerce declared the addition of Huawei Technologies and its affiliates to the Bureau of Industry and Security (BIS) entity list. The addition makes the U.S. companies not to sell or transfer technology to Huawei without a license issued by the BIS. The Chinese Telecom giant Huawei hit back after the announcement of the executive order. The company criticized the move as “unreasonable”.

“If the U.S. restricts Huawei, it will not make the U.S. safer, nor will it make the U.S. stronger. It will only force the US to use inferior and expensive alternative equipment, lagging behind other countries and ultimately harming US companies and consumers,” Huawei stated in a statement.

Huawei faced a similar issue last year during Australia’s Shadow Minister for Defence Richard Marles’s apprehension and a possible ruling toward Huawei ban from 5G networks citing cybersecurity concerns. Huawei published a letter to Australian members of Parliament over the comments made. The company vehemently stated that the rumors and comments were ill-informed and have no factual basis.

 

 

 

Automotive cybersecurity solutions startup GuardKnox secures $21 million

Connected Cars

Guardknox, a leading automotive cybersecurity company, recently announced the completion of its $21 million Series A funding round led by Fraser McCombs Capital along with the participation of automotive technology leader Faurecia, SAIC Capital (Shanghai Automotive), Glory Ventures, NextLeap Ventures, VectoIQ, Plug and Play, Allied, Cyphertech, and Kardan LTD. The Israel-based connected car cybersecurity startup stated the new investment will be used to expand its R&D team and support its business reach globally.

Founded in 2016, by Israel Air Force veterans Moshe Shlisel, Dionis Teshler, and Idan Nadav, the company adapts core values and practices from the Air Force to protect the automotive industry from critical cybersecurity threats. Guardknox claims that its cybersecurity technology methods used in jets to analyze every message entering a vehicle’s network with a zero-trust methodology and immediately rejecting, if it’s not designated as acceptable. The company also provides similar cybersecurity solutions to Israel Air Force systems, including Iron Dome, Arrow, and F-35 fighter jets.

“The automotive industry is experiencing massive disruption from emerging technologies,” said Moshe Shlisel, CEO and co-founder of GuardKnox, in a statement. “Paired with increasing customer expectations, companies are under immense pressure to meet client needs and desires for added services, while also providing security solutions that keep pace with passenger safety and data security as well as the ever-changing regulatory environment. We are solving a critical industry pain point and believe our approach to high-performance hardware architecture and secured ECU’s is the best way for companies to ensure the safety of their connected and autonomous vehicles.”

“With connected services available in a majority of new cars and trucks, the ability to secure vehicles and user information will soon redefine automotive brands and insurance,” said Mark Norman, Managing Partner for Fraser McCombs Capital. “FM Capital is proud to partner with the dynamic GuardKnox team delivering transformative cybersecurity solutions for the auto industry.”

 

Indian student finds WhatsApp bug, gets inducted in Facebook Hall of Fame

WhatsApp and Indian governmentWhatsapp Hack

Facebook has honored a 22-year-old civil engineer in India for discovering a WhatsApp bug that violated the privacy regulations. Zonel Sougaijam, who resides in Indian state Manipur, said that he discovered a bug in WhatsApp voice call that allows the caller to switch it to a video call without the authorization of the receiver.

Sougaijam stated that he reported the issue to Facebook in a bug bounty program. He said the Facebook security team acknowledged his report and fixed the bug within 15-20 days

The social media giant awarded Sougaijam with $5000 and included his name in the ‘Facebook Hall of Fame 2019’, for detecting the WhatsApp bug.

“During a voice call through WhatsApp, the bug used to allow the caller to upgrade it to a video call without the authorization and knowledge of the receiver. The caller was then able to see what the other person was doing, violating the privacy of the receiver,” Sougaijam said in a media statement.

Recently, WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. The Facebook-owned social messenger stated the spyware can exploit the mobile device, its calls, texts, and other data. It can also activate the phone’s camera, microphone, and able to perform other malicious activities. According to Facebook, the malicious spyware was developed by Israel-based cyber intelligence company NSO Group.

According to Facebook, the mobile devices with WhatsApp or WhatsApp Business installed in them are affected, including Apple’s iPhone (iOS), Android phones, Windows Phones, and Tizen devices. However, the company clarified that it’s unclear on the number of people spied on by hackers.

Earlier, a survey has discovered that answering a WhatsApp video call can compromise your smartphone. According to Natalie Silvanovich, a digital forensics expert at Google Project Zero, a security bug in the WhatsApp messenger application allows attackers to take control of the smartphone by placing a WhatsApp video call. The security flaw discovered in August 2018 affected the WhatsApp application on Android and iOS devices, but not on WhatsApp Web, the research report stated. The Facebook-owned messaging app fixed the flaw on September 28 for Android platform and October 3 for the iPhone platform after Silvanovich reported the issue to the WhatsApp team.

Also, the Indian Army issued a warning to users of WhatsApp, alleging that Chinese hackers are targeting them to extract personal data. The Army took to the microblogging site, Twitter to urge users to use WhatsApp with caution. Indian Army’s official handle, the Additional Directorate General of Public Interface (ADGPI) also posted a video that said, “Stay cautious, stay alert, stay safe! The Chinese were penetrating the digital world.”

Tech Mahindra and IIT Kanpur join hands to support academic initiatives and research on cybersecurity

Tech Mahindra

Tech Mahindra Ltd., a provider of digital transformation, consulting and business reengineering services and solutions, announced a strategic collaboration with the Indian Institute of Technology Kanpur (IIT Kanpur) to jointly research in the field of cybersecurity. Both the parties have recently signed a Memorandum of Understanding (MOU) towards the knowledge enrichment and to address future cybersecurity challenges.

As per the alliance, Tech Mahindra will be working closely with the students of IIT Kanpur to bring real-world industry exposure and to enhance the digital resilience of critical national infrastructure.

Speaking on the new collaboration Rajiv Singh, Global Head of Cybersecurity at Tech Mahindra, said, “At Tech Mahindra our primary objective is to ensure that the customer’s business is secured against national grade threats and attacks. Through our partnership with IIT Kanpur, we aim to collaborate and co-create superior research-based solutions in cyber security. Our global experience of securing Enterprise and Telecom customers provides a great opportunity to build customized cybersecurity products in the space of Advanced Threat Management, Internet of Things (IoT), 5G, connected devices and securing the Internet of Everything in our digital world.”

Prof. Abhay Karandikar, Director, IIT Kanpur, said, “We are excited to partner with Tech Mahindra for building innovative solutions in the area of Cyber Security. With IIT Kanpur’s strong footing in research capabilities and critical infrastructure, I am confident that our association with Tech Mahindra will lead to novel indigenous technology developments in Cyber Security.”

Recently, Tech Mahindra collaborated with i2Chain Inc., a San Francisco-based startup, leveraging next-gen technologies to secure customer information and data assets. Through this partnership, Tech Mahindra and i2Chain will offer a blockchain-based cybersecurity application to customers that is easy to use and provides information owners with an unprecedented level of control as to how, when and where other users can access their information, with the potential to substantially reduce the frequency and costs of security incidents.

It enables enterprises and users to secure, share and transact with integrity and confidence, and is fully GDPR (General Data Protection Regulation) compliant.  The application also makes “chained” information and identity tamperproof, and records all actions taken against a file in an immutable blockchain, fully accessible to support audits and forensics.

Also, the IIT Kanpur partnered with The National Stock Exchange (NSE), the leading stock exchange of India in January 2019. The partnership aims at developing cybersecurity solutions that can strengthen the security posture of NSE as well as companies in the Indian financial and capital markets ecosystem. To develop cutting-edge solutions, NSE would leverage the capabilities of IIT Kanpur’s C3I center (Cyber Security and Cyber Defense of Critical Infrastructures) that is involved in research on cybersecurity and cyber defense of critical infrastructure.

PDPC Singapore fines service vendor over data leak

Singapore

The Personal Data Protection Commission (PDPC) of Singapore has fined its computer vendor Option Gift $4,000 for disclosing the personal information of 426 NSmen (National Servicemen) last year. The commission recently stated that it discovered in an investigation that Option Gift violated section 24 of the Personal Data Protection Act by exposing the sensitive information.

The compromised data included sensitive information like log-in identifications, e-mail addresses, delivery addresses, and mobile phone numbers of the NSmen from the Singapore Armed Forces (SAF) and Home Team.

The issue occurred due to a technical issue in Uniquerewards, online portal maintained by Option Gift, which allows NSmen to redeem credits for service-linked rewards from the Ministry of Defence (MINDEF) and the Ministry of Home Affairs (MHA).

The personal information of the NSmen was leaked when e-mails that are meant to be sent out individually ended up sending it to all the NSmen due to an error in the program script. The PDPC stated that Option Gift had failed to conduct enough testing before deploying the program script.

“As the administrator of the portal, the organization had full possession and control over the personal data that the portal collects, uses, discloses and processes at all material times,” PDPC said in its report. Accordingly, the organization had full responsibility for the security of the portal, any changes to it, as well as the personal data processed by it.”

Option Gift emailed the affected NSmen to apologize after the incident was discovered and urged them to delete all the emails which are not intended for them.

In order to boost cybersecurity and tackle next-generation cyber threats, the Personal Data Protection Commission of Singapore recently updated the guidelines on data breach notification and accountability. The new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident before 72 hours after discovering a data breach. The PDPC stated the businesses are required to notify authorities if a breach affects more than 500 individuals. The data intermediaries also need to report potential data breaches to their parent organization within 24 hours after identifying a security incident.

In addition, the PDPC also introduced three initiatives to support innovation and strengthen accountability among organizations – Establishing public consultation to seek opinions on proposed data portability and data innovation provisions, Introducing a new guide on Active Enforcement to drive for organizations shift from compliance to accountability, and an updated guide to managing data breaches.

 

Komodo Platform hacks itself to safeguard customers funds

Komodo

In an unusual attempt to protect its customers from getting hacked, Komodo Platform, a cryptocurrency startup hacked itself. When it found out about a vulnerability present in its mobile wallet application named Agama, Komodo hacked it by exploiting the vulnerability to exfiltrate about $13 million of its customers’ funds before an outside group could.

The company stated that it received a notification on June 4, 2019, at 5 pm UTC from the security firm npm about a malware threat targeting the users of its cryptocurrency wallet Agama and helped protect over $13 million USD in cryptocurrency assets. Komodo said the attack was focused on injecting malware to steal the wallet seeds and other login passphrases used within the application.

“It now seems clear that the bug was created intentionally to target Komodo’s version of Agama wallet. A hacker spent several months making useful contributions to the Agama repository on GitHub before inserting the bug. Eventually, the hacker added malicious code to an update of a module that Komodo’s Agama was already using,” Komodo said in a statement. “The update contained malicious code that stored all seed phrases on a public server. The hacker saved the seed phrases on a public server to obscure his/her identity and to create a scenario where anyone could be a suspect when the vulnerability was finally exploited.”

Komodo has notified the affected users about the hack and informed the process of reclaiming the funds.

There have been multiple breaches reported by cryptocurrency exchanges in recent times. In a major security breach, hackers stole over $40 million worth of Bitcoin from the popular cryptocurrency exchange Binance. The Taiwanese company stated it discovered the breach on May 7, 2019, at 17:15:24 (UTC), in which hackers illegally obtained over 7,000 Bitcoins by using a variety of attack methods, including phishing, viruses, and other attacks.

According to Binance, hackers also accessed several user API keys, 2FA codes, and other information. Following the hack, the exchange suspended all the operations temporarily and assured that it will refund the affected customers in full. In February 2019, crypto brokerage platform Coinmama notified users that it suffered a security breach which affected around 450,000 users’ emails and hashed passwords. The company stated that a few unknown intruders compromised customer data and kept for sale on a dark web registry.

Similarly, Cryptopia lost nearly 19,390 ETH tokens in a cyber-attack. According to reports, the hackers have been sending their loot to popular crypto exchanges with Bitbox, Binance, and Huobi seeing the most withdrawal volumes. It is estimated that out of the $16 million stolen by hackers nearly $900,000 have been withdrawn.

 

Rail cybersecurity startup Cylus secures $12 million

Startup funding

Cylus, the rail and metro cybersecurity services provider, recently raised $12 million in a Series A funding round to accelerate its business expansion. The funding round was jointly led by the company’s existing investors, Magma Venture Partners and Vertex Ventures, including several new investors Cyient, Cerca Partners, GlenRock, Leon Recanati’s private investment company, and FollowTheSeed. The round was also joined by former Chancellor of Austria, the Blue Minds Company managing director Christian Kern, and Cylus’ previous backers Zohar Zisapel and SBI.

The Israel-based startup stated the new investment will be used to push its activities in the European Union, the U.S., and in the Asia-Pacific region. Cylus also planning to support its research and development, strengthen its team of cybersecurity, and rail experts.

Cylus helps rail and metro companies avoid safety incidents and service disruptions caused by cyber-attacks. The company claims that its security platform CylusOne is designed to meet the unique cybersecurity needs of the rail industry. It’s said that CylusOne detects cyber threats in the signalling and control networks, trackside and onboard, and assisting rail and metro companies in preventing cyber-attacks.

Commenting on the new investment Amir Levintal, the CEO and co-founder of Cylus, said, “Rail systems have become technologically advanced, and the threat of cyber-attacks is constantly growing.”

“We have already established strong relationships with key players in the rail industry and growing partnerships with leading rail operators. We are moving full steam ahead to scale our team and expand globally,” Levintal added.

“I know firsthand that cybersecurity is among the top priorities for rail executives,” said former Austrian Chancellor and former CEO of ÖBB, the Austrian Federal Railways, Christian Kern. “As cyber-attacks increasingly threaten rail safety and availability, rail stakeholders understand the pressing need for substantial cybersecurity investment. Cylus’ solution is crucial to mitigating the escalating cyber threats railway companies face. Cylus’ laser-sharp focus on this industry provides customers the huge advantage of a dedicated product designed by experts who speak both cyber and rail.”

Security firm Imperva acquires Distil Networks to prevent bot attacks

Acquisitions

Cybersecurity software firm Imperva announced that it has signed an agreement to acquire Distil Networks, a Bot Management startup, to help thwart bot attacks. The California-headquartered firm develops and sells information security software for databases and web applications, on-premises, in the cloud, and across hybrid environments.

The latest acquisition strengthens Imperva’s market leadership in the application security market and further develops the company’s mission to protect business-critical data and applications. As per the agreement, Imperva integrates the Distil Networks’ security solutions into the Imperva security stack to deliver complete protection for APIs.

Founded in 2011, Distil Networks operates in a subdomain of cybersecurity known as bot management. The Virginia-based startup is specialized in blocking bot attacks on websites, mobile apps, and APIs.

“Distil Networks is a globally recognized leader in automated attack mitigation, and this deal perfectly aligns with our vision of delivering best-in-class cybersecurity solutions that protect businesses throughout their cloud journey,” said Chris Hylen, CEO of Imperva. “Distil Networks gives us a comprehensive Bot Management solution that identifies, responds to and manages a full range of automated attacks no matter where these applications or APIs are deployed. We believe Imperva and Distil Networks will create the most comprehensive security platform on the market, and we’re excited to make this available to our customers worldwide.”

“Bots are an evolving attack vector that has become a threat to all organizations, no matter the size or location,” said Tiffany Olson Kleeman, CEO of Distil Networks. “We have been leading the charge to find solutions to better understand, detect and mitigate automated attacks since 2011. Today’s announcement serves as a testament to the ingenuity and dedication of Distil Networks’ team over the past eight years to solve this problem for our customers. We are excited to enter into a new chapter with a company that shares our passion for protecting critical business applications and delivering best-in-class security solutions for all customers.”

Earlier, Imperva acquired network management startup Prevoty for $140 million to provide security solutions for application services residing on-premises and in the cloud. The acquisition allowed both the companies to expand their customers’ security capabilities and their visibility into how applications are accessed, and how applications and users interact with data. This gives deeper insights to the customers to understand the security risks and the ability to protect their business from cybercriminals.