Home Blog Page 325

Around 2 million diners in U.S. hit by a malware attack

Secret Terrorist Watchlist Leak, Aruba

Italian restaurant company Earl Enterprises recently revealed that it suffered a data security incident that affected payment card information of the customers that dined at its restaurants including Buca di Beppo, Planet Hollywood, Earl of Sandwich, Planet Hollywood, Chicken Guy, Mixology, and Tequila Taqueria. It’s believed that cybercriminals have hacked the restaurant’s point-of-sale systems and compromised credit card information of around 2 million customers who dined at its food outlets across the United States.

In an official statement, Earl Enterprises said that unknown individuals installed malicious software on some of its point-of-sale systems at a number of its restaurants. The malware captured the payment card data for up to 10 months (between May 23, 2018 and March 18, 2019) that included credit and debit card numbers, cardholder names, and expiration dates.

The restaurant chain confirmed the incident after security researcher Brian Krebs alerted the company about the discovery he made on an underground hacking forum a month ago. On February 21, 2019, Krebs contacted the Buca di Beppo after discovering that two million credit and debit card numbers belonging to the company’s customers were kept for sale in the dark web forums, according to krebsonsecurity.

“Once we learned of a potential incident, we promptly launched an internal investigation and engaged two leading cybersecurity firms. As part of the investigation, we have been in contact with federal law enforcement officials and are cooperating with them. Based on the investigation, it appears that unauthorized individuals installed malicious software on some point-of-sale systems at a certain number of Earl Enterprises’ restaurants,” the company said in a statement.

Earl Enterprises stated that it’s working on additional security measures to help prevent a similar incident from happening in the future and suggested the customers check their payment details for any unauthorized transactions.

Zacco acquires Indian startup Lakhshya Cybersecurity Labs

Hellman & Friedman to Acquire Cybersecurity Firm Checkmarx

Europe’s intellectual property firm Zacco has acquired Lakhshya Cybersecurity Labs, India-based cybersecurity research and consulting services company for an undisclosed amount. The acquisition is part of Zacco’s plan of expanding its presence in the South Asian market.

“India is today a global hub for advanced digital technology. Lakhshya is adding unique expertise to our current R&D centre in Bengaluru,” said Mats Boström, CEO, Zacco Group. “In the digitalised world, cybercrime and digital threats are unfortunately an increasing challenge for many organisations and individuals. Data, algorithms and all types of digital technology are today significant intellectual property and strategic assets,” said Bostrom.

Lakhshya Cybersecurity Labs has witnessed unprecedented growth in the last two years, thanks to its prowess in areas like malware analysis, cyber breach investigation, red teaming, and several other vectors of cyber threat analysis. “This combination will be able to add significant expertise and value to Zacco and enable the combined entity to address clients’ digital asset protection in a holistic manner,” said Premchand Kurup, co-founder at Lakshya Labs, who is also the CEO of Paramount Computer Systems.

Lakshya would be integrated into Zacco’s cybersecurity division to enhance its current services. “Lakhshya Labs will add a team of more than 40 professionals with expertise across banking, financial services and insurance, aviation, government, automotive, manufacturing, and trading verticals, with real-time 24/7 monitoring services through its SOC facility. This combination will be able to add significant value to Zacco, and enable the combined entity to address the clients’ Digital Asset Protection in a holistic manner. We plan to grow this team significantly over time, and will continue to build on our existing offerings, both organically and inorganically,” Ravi Sunderrajan, Managing Director, Zacco India R&D said.

Cybersecurity startup Sqreen raises $14 million

Horangi Raises US$20 Million in Funding to Strengthen Cybersecurity in Southeast Asia

Cybersecurity startup Sqreen recently raised $14 million in a series A round of funding led by Greylock Partners along with the participation from existing investors Y Combinator, Alven Capital, and Point Nine. The San Francisco, California-based company helps developers monitor and protect their web applications from vulnerabilities and cyber-attacks.

Sqreen was founded in 2015 by Apple’s former security veterans Jean-Baptiste Aviat and Pierre Betouin. The startup offers an Application Security Management (ASM) platform with a technology known as Runtime Application Self-Protection Security (RASP), which is used to embed microagents into applications to identify threats. Sqreen claims that it offers real-time insights on suspicious activities to companies like ZipRecruiter, Le Monde, and BlaBlaCar.

Pierre Betouin, the CEO and co-founder of Sqreen also the  former leader of Apple’s security Red Team, stated that Sqreen’s security platform protects from all the common attacks, including SQL injections, broken authentication, and cross-site scripting (XSS).

“Security is a must-have for SaaS and internet companies and organizations of any size that ship software for their business. Security needs to enable developers and the rest of the company. It can’t be a silo that blocks or slows down releases anymore. We bring true collaboration between the developers and security teams,” Betouin said in a media statement.

“The state of the art for application security is outdated and complex with approaches that don’t work in production, slow down app development, and are expensive to use and maintain. Today every company is a software company, and Sqreen supports that by putting a scalable security solution in the hands of developers, operations and security teams,” said Sarah Guo, Greylock partner.

 

Unprotected server exposes details of 12.5 million women

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

A misconfigured MongoDB database, managed by the Indian government healthcare agency, was left online without a password exposing more than 12.5 million medical records of pregnant women. The incident came into light after the security researcher Bob Diachenko identified and reported the data breach to the Indian Computer Emergency Response Team (CERT), which immediately took the server down. The Ministry of Electronics and Information Technology clarified that they secured the leaky server on March 29, 2019.

Diachenko stated that he first identified the leaky database on March 7, 2019, which belong to the Department of Medical, Health, and Family Welfare of a state in India, that contained sensitive medical information, including the test reports of the women who were pregnant women who underwent an ultrasound scan, amniocentesis, and other genetic testing of their unborn child in 2014.

The unprotected database contained 7,449,714 forms F and other forms detailing all the aspects of a medical inspection, including anonymous complaints, court cases details, doctors’ details, children details (sex, age, status) were left open for almost a month, according to Diachenko.

“Medical data is among the most sensitive information that organizations can collect, store, or share. It is never a good idea to store medical data in plain text or leave it publicly accessible. The nightmare of any patient to give your most intimate medical details to your Doctor or medical professional and then hope it is never leaked online. Although this massive data breach affects millions of pregnant women in India, it could happen anywhere and reminds us once again how important data privacy is,” Diachenko said in a blog post.

In a similar incident, an unsecured Elasticsearch database exposed the real-time location data for over 11,000 Indian buses online over three weeks. ElasticSearch, an enterprise search engine, provides technology solutions for powering search functions. According to Justin Paine, the security researcher who discovered the breach, the unprotected server was left visible online without a password exposing real-time GPS and bus route information from 27 Indian transportation agencies via an ElasticSearch server.

The server exposed the data of 26 road transport agencies, including Kochi Metro Rail Limited. The exposed information included the details like bus license plates, start-stop stations, route names, GPS coordinates, and details of commuters like usernames and emails.

French group Thales acquires security firm Gemalto to boost its digital identity platform

Google’s Project Nightingale

Thales, the aerospace and defense electronics group, recently announced the takeover of cybersecurity firm Gemalto in a cash deal of 4.8 billion euros ($5.4 billion) to boost its presence in the security services market.

Headquartered in France, Thales designs and builds electrical systems and provides services for the aerospace, defense, transportation, and security markets. The company stated the acquisition of Gemalto will increase its revenues and help to expand its reach in Latin America, North America, and Asia. Gemalto is a digital security company providing software applications, secure personal devices like smart cards, tokens, and managed services.

Thales stated that it will develop secure solutions to address the major challenges in data and network cybersecurity, unmanned air traffic management, airport security, and financial transaction security by incorporating the talent and technologies of Gemalto. The latest acquisition will help to build a strong portfolio of digital identity and security solutions based on technologies such as cybersecurity, biometry, and data protection.

“With Gemalto, a global leader in digital identification and data protection, Thales has acquired a set of highly complementary technologies and competencies with applications in all of our five vertical markets, which are now redefined as aerospace; space; ground transportation; digital identity and security; and defence and security. These are the smart technologies that help people make the best choices at every decisive moment. The acquisition is a turning point for the Group’s 80,000 employees. Together, we are creating a giant in digital identity and security with the capabilities to compete in the big leagues worldwide,” said Patrice Caine, Chairman and CEO, Thales.

Gustuff-A new malware targeting android devices

cybersecurity

According to the latest report from cybersecurity firm Group-IB, a new type of android trojan developed by Russian-based cybercriminals is spreading across global banking apps, cryptocurrency, and marketplace applications. The new malware, dubbed Gustuff, is a different kind of malware designed to steal both authorization and cryptocurrency from the user accounts, the report stated.

According to the report, Gustuff could potentially target users of more than 100 banking apps, including 27 in the United States, 16 in Poland, 10 in Australia, 9 in Germany, and 8 in India and also the users of 32 cryptocurrency apps.

Group-IB stated that its security team analyzed a sample of the malware and found that it uses several different methods to infect victims’ Android devices and gain access to bank accounts and digital wallets.  It tricks users into downloading fake applications that look like real apps from popular digital currency service providers and financial institutions like J.P.Morgan, Wells Fargo, Capital One, Bitpay, Bitcoin Wallet, and Coinbase.

Gustuff exploits the mobile’s Android Accessibility tool, which is intended to help people with disabilities, to turn off Google Protect, bypass bank security systems, and automatically interact with the banking and crypto exchange apps.

“All new Android Trojans offered on underground forums, including Gustuff, are designed to be used mainly outside Russia, and target customers of international companies. In Russia, after the owners of the largest Android botnets were arrested, the number of daily thefts decreased threefold, Trojans’ activity became significantly less widespread, and their developers focused to other markets. However, some hackers patch modifies the Trojan samples and reuse it in their attacks on users in Russia,” said Rustam Mirkasymov, Group-IB Head of Dynamic Analysis of malware department and threat intelligence expert.

Axway acquires French startup Streamdata.io to advance event-driven APIs

Google’s Project Nightingale

France-based technology company Axway recently acquired software publisher Streamdata.io to reinforce its API (application programming interface) management and technological capabilities of its hybrid integration platform.

Axway is a provider of multi-enterprise cloud integration, API, and identity management software services to enterprises. The acquisition of Streamdata.io’s will help Axway strengthen its hybrid integration platform AMPLIFY.

Founded in 2008 by Eric Horesnyi, Streamdata.io is specialized in real-time data distribution. Headquartered in France and the United States, the startup helps developers turn content into streams of data through event-driven APIs.

Streamdata.io claims that the latest acquisition brings multiple additions to Axway’s AMPLIFY platform like event-driven API management, supporting real-time use cases, and providing a methodology for the digital transformation journey designed around full lifecycle API adoption.

Speaking on the new alliance Vince Padua, Chief Technology and Innovation Officer at Axway, said, “To advance our strategy in enabling businesses to accelerate their IT and digital transformation, we need to enable our customers and partners with a prescriptive journey toward digital transformation and hybrid integration. Along the digital transformation journey, hybrid integration with event-driven technologies and API Management enable the real-time response and decision-making customers need.”

Eric Horesnyi, Founder and Chief Executive Officer of Streamdata.io, said, “Axway and Streamdata.io share a passion for data. In joining Axway, we can help our customers stay ahead of the digital transformation curve by securely enabling real-time data. We look forward to jointly paving the way for one of the most innovative hybrid integration platforms on the market.”

Israel-based cybersecurity startup Perimeter 81 raises $5 million to accelerate growth

Startup funding

Network security provider Perimeter 81 recently secured $5 million funding to develop new cloud firewall capabilities and accelerate growth. The funding round was led by Spring Ventures and private US-based investors along with the participation of existing shareholders. The Tel Aviv-based based company stated the investment will be used to expand the company’s sales, marketing and R&D teams in its Tel Aviv and New York offices.

Founded by Amit Bareket and Sagi Gidali in 2018, Perimeter 81 is a Zero-Trust Software Defined company focussed on transforming the secure network access to the modern and distributed workforce. Perimeter 81 offers automatic gateway deployment, easy multi-tenant management, and full network visibility to enterprises. The company claims that its Software-Defined Perimeter solution securely connects employees to cloud-based and internal network resources.

“The rise of Cloud and Mobility has disrupted network, cloud and application security as we know it. With employees working on the go and from different locations around the world, and companies increasingly moving towards the cloud, the traditional hardware-based legacy appliances of the past are no longer suitable for today’s modern and distributed workforce,” said CEO and Co-Founder Amit Bareket. “Perimeter 81’s user-centric Secure Network as a Service, which utilizes the Zero-Trust and Software-Defined Perimeter models, enables businesses to more easily secure access to local network resources, cloud environments, and business applications, with a seamless and highly intuitive SaaS solution.”

“With Perimeter 81, we took our knowledge of what worked for the consumer market, and ultimately, the end-user, and transformed the complex and outdated technology that so many businesses rely upon, into a seamless and user-friendly SaaS service,” said Sagi Gidali, Co-Founder and CPO. With this new funding round, we look forward to expanding our reach and further enabling companies of all industries and sizes to become fully, securely mobile and confidently cloud-based.”

Carbonite acquires cybersecurity startup Webroot

Thoma Bravo Acquires Sophos for US$3.9 Billion

Carbonite, a cloud-based data protection provider, recently announced the acquisition of cybersecurity solutions provider Webroot in a cash deal of $618.5 million.

Carbonite provides Data Protection Platform to enterprises, including backup, disaster recovery, high availability, and workload migration technology. The company claims that its Data Protection Platform supports businesses on a global scale with secure cloud infrastructure.

Webroot offers advanced security solutions and services to small businesses. Headquartered in Colorado, Webroot is focused on endpoint protection, network protection, and security awareness training. It uses the combination of the cloud and artificial intelligence to leverage the power of machine learning to protect critical information of businesses and individuals. The security firm claims that its BrightCloud Threat Intelligence Services are used by leading companies like Cisco, F5 Networks, Citrix, Aruba, and A10 Networks.

The new alliance combines the cloud-based backup and recovery with cloud-based cybersecurity to bring a new approach to data protection for the endpoint.

Commenting on the latest acquisition deal Mohamad Ali, Carbonite’s CEO, said, “The combination of these two companies creates a unique and powerful data protection and cybersecurity solution for our customers and partners. We are thrilled to officially welcome Webroot to the Carbonite family and look forward to delivering positive results together.”

“Webroot and Carbonite share a common vision to empower small and mid-sized businesses with next generation solutions purpose-built for their unique needs,” said John Post, SVP and GM of Webroot. “I’m confident we will build on the momentum of Carbonite and Webroot’s cloud-based approach to protecting endpoint data as we aim to deliver strong results for customers and partners.”

Security firm AppDetex raises $10 million to expand its online presence

Startup funding

The digital risk protection service provider AppDetex recently raised $10 million in a series B equity financing round led by venture capital firm First Analysis along with the participation of the existing investors EPIC Ventures and Origin Ventures.  The Boise-based company stated the new investment will be used to accelerate its sales and marketing efforts and invest in product development.

Founded in 2012 by security professionals Faisal Shah and Chris Bura, AppDetex provides technology solutions to global enterprises that are experiencing revenue loss from brand infringements outside the firewall via mobile or online activity.

AppDetex claims that it specializes in the areas outside of the company’s firewall to prevent brand infringement, fraud, combating the misuse of intellectual property, brand infringement, fraud, and piracy across multiple channels like mobile apps, marketplaces, social media, websites, and domains. The company stated that it’s planning to expand its online presence across multiple platforms to help enterprises protect against counterfeiting, piracy, phishing, cybersquatting, and unauthorized use of trademarks.

“Digital brand infringement is at an all-time high, and current market solutions are insufficient in fighting bad actors across a brand’s entire digital footprint. The market is poised for the differentiated digital risk protection product that AppDetex offers,” said Howard Smith, Managing Director, First Analysis, and new AppDetex Board Member. “We’re thrilled to partner with a management team known for its history of innovation in this industry and look forward to their continued leadership and growth.”

“Our goal is to be the all-in-one solution protecting all brands, anywhere that they live online – both through constant monitoring and discovery, and swift and effective enforcement,” said Faisal Shah, CEO of AppDetex. “This new investment enables AppDetex to continue to develop its team and industry-leading products necessary to defend brands across the globe against dilution of their intellectual property through nefarious means.”