Home Blog Page 330

ShiftLeft secures $20 million to accelerate its automated application security

Funding round

Cloud cybersecurity startup ShiftLeft recently raised $20 million in a Series B funding round led by Thomvest Ventures along with the participation by new investor SineWave Ventures and existing investors Bain Capital Ventures and Mayfield.

The startup stated the new investments will help in expanding its product portfolio, application coverage, and global sales & marketing initiatives. In addition to funding, ShiftLeft also added Jim Sortino, a former executive at Trend Micro and Dome9 Security, as the vice president of global sales.

Founded in 2016 by a group of security professionals like Chetan Conikee, Manish Gupta, and Vlad A Ionescu, ShiftLeft helps businesses identify security issues and remediate them automatically.  The company provides real-time information on early stage cyber threats and delivers a new model for protecting cloud or data center hosted software by understanding the Security DNA of each new version of any application.

ShiftLeft claims that its application security platform combines next-generation static code analysis with application instrumentation in an automated workflow to quickly and accurately identify vulnerabilities.

“Our founding vision is that application security needs to be a seamless part of the development process, not an afterthought,” said Manish Gupta, CEO and co-founder of ShiftLeft. “The problem has long been inaccurate tools and a heavily manual process, leaving security and development teams frustrated and applications vulnerable. ShiftLeft completely upends this paradigm, delivering automated and customized protection for every software release, and the analytics dev teams need to improve on the overall security posture.”

“We are excited to lead ShiftLeft’s Series B financing. The company has an impressive team, led by CEO, Manish Gupta. ShiftLeft provides intelligent automation of code security, which addresses a major pain point for the CISOs of modern enterprises: to protect applications and data,” said Umesh Padval, venture partner at Thomvest Ventures.

California government to support cybersecurity from grassroot

Officials of California’s government have announced that they’re going to support cybersecurity education and committed to providing programs and events that help train the next generation of cybersecurity professionals.

The officials stated that they’ve initiated a program, the California Mayors Cyber Cup (CMCC), that utilizes cyber competitions to spread awareness about cybersecurity and the many career opportunities that exist within that field. CMCC brings students, parents, teachers, government officials, business leaders, and other stakeholders together to create awareness of cybersecurity issues and reinforce the connection between the community and the educational institutions to highlight the many career and business support resources available in each community.

The CMCC will receive critical support from the California Governor’s Office of Business and Economic Development, (GO-Biz), California Governor’s Office of Emergency Services (Cal OES), and the California Department of Technology, the officials stated.

Mario Garcia, the Commander of the California Cybersecurity Integration Center, stated that events like the CMCC are critically important to build the pipeline of cybersecurity workers needed throughout California, across the U.S., and around the world.

“Cybersecurity is the number one threat nationwide: it impacts every government entity, business, educational institution, and each one of us personally. California Cyberhub is helping to unify California’s efforts to fill over 35,000 open cybersecurity jobs by encouraging the development of cyber education and cyber competition opportunities,” Garcia added.

Amid the perennial arguments around the skills gap that has marred the information security space, the topic of cybersecurity education usually makes an appearance. But how big really is the dearth of infosec professionals? At present, there’s a 25 percent gap between the demand for cyber talent and the existing supply.

According to a report by Peninsula Press, more than 209,000 cybersecurity jobs in the U.S. were unfilled, “and postings are up 74 percent over the past five years.” Within months, the demand for cybersecurity professionals will increase to approximately six million globally.

Cisco launches new co-innovation and cybersecurity centers in Singapore

The hardware networking company Cisco has launched an innovation center in South-east Asia. The California-based company stated that the new facility will bring together industry players, government organizations, and startups to work on regional issues in cybersecurity and the Internet of Things (IoT).

Cisco also established a Cybersecurity Center of Excellence (CCX) in partnership with the Economic Development Board (EDB) to boost its Asia-Pacific threat intelligence research, response capabilities, and work towards improving national cybersecurity.

The two centers, which are located at Cisco’s new office in the Mapletree Business City, are designed to catalyze digital innovation with the focus areas of Singapore’s Digital Economy Framework for Action.

Speaking on the latest accomplishments Irving Tan, Cisco’s Senior Vice President and Chief of Operations for Southeast Asia stated, “At Cisco, we build the bridge between hope and possibility. This is only possible when innovative technology and imaginative people come together around a common purpose. Innovation no longer happens behind the closed doors of R&D labs but in open ecosystems. By fostering local and global partnerships, Cisco is leading innovation in cutting edge technology solutions that will create a better future for the region.”

In the past, Cisco had also partnered with the United Kingdom police forces to provide them cybersecurity training through the Cisco Networking Academy. The company stated that it’s going to train more than 120,000 police officers across England, Scotland, Wales, and Northern Ireland to help make the UK the safest cyberspace. The latest training partnership between the National Police Chiefs’ Council and Cisco’s Networking Academy mark the first anniversary of Cisco’s digital skills manifesto in the United Kingdom. The nationwide cybersecurity training will help the police officers develop their knowledge in emerging cybersecurity trends.

Also, Cisco joined hands with Apple, Aon, and Allianz to develop a new cyber risk management solution for businesses. The new solution is designed to help a wider range of organizations better manage and protect themselves from the cyber risk associated with ransomware and other malware-related threats, which are the most common threats faced by organizations today.

Pakistan’s army and foreign ministry websites hacked

Lizard Squad

Over the weekend, Pakistan’s Ministry of Foreign Affairs and the Army websites were attacked by hackers. According to the spokesperson Mohammad Faisal, the ministry received several complaints from various countries reporting that the websites were inaccessible from February 16, 2019. It’s believed that the attack was originated from India, Pakistan’s news site Dawn reported.

The cyber attack was the wake of the terrorist strike in Pulwama, Kashmir on February 14, 2019, that claimed the lives of 40 Indian CRPF personnel. The Pakistan-based terrorist group Jaish-e-Mohammed claimed the responsibility for the attack.

“The IT team is currently occupied in thwarting the hackers’ onslaught. The website is functioning without any issues in Pakistan. However, visitors to the website from Holland, Australia, Britain, and Saudi Arabia are facing difficulty opening it,” Faisal said in a statement.

Pakistan encountered a similar incident in November 2018, when hackers attacked almost all the banking websites in the country. Every person holding a bank account may have become vulnerable to cyber threats, as data from almost all the banks of the nation was stolen in a security breach. The incident was revealed by the Federal Investigation Agency’s (FIA) cybercrime chief, Captain (retd) Mohammad Shoaib.  In an interview with Geo News, he said, “Almost all [Pakistani] banks’ data has been breached. According to the reports that we have, most of the banks have been affected.”

According to him, there are over 100 cases that the agency is currently been investigating. The agency has also arrested several gangs that have been involved in cybercrime and recovered the stolen money. One of the recent apprehended gang used to withdraw money from people’s accounts while masquerading themselves as military officials.

The revelation came while responding to a report from Group-IB, a global cyber security firm, which stated that hackers had released a huge trove of credit and debit cards of Pakistan citizens on the dark web forums.

Aric K. Perminter joins Cybercrime Support Network Board of Directors

design and compliance

PRWeb: Cybersecurity firm Lynx Technology Partners (Lynx), has announced that Founder and Chairman, Aric K. Perminter has joined the board of directors at the Cybercrime Support Network. Cybercrime Support Network (CSN) is a public-private, nonprofit collaboration created to meet the challenges facing millions of individuals and businesses affected each and every day by cybercrime.

“I was immediately drawn to CSN’s mission because every human and business is one click away from becoming a cybercrime victim,” stated Perminter. “Judge has assembled an impressive leadership team with the required experience, passion and commitment to deliver a supportive program designed to eliminate repeat incidents – making our world safer one victim at a time.”

CSN’s mission is to improve the plight of Americans facing the ever-growing impact of cybercrime by bringing together national partners to support cybercrime victims. Before, by pointing consumers and businesses to the best information from experts in cybersecurity education and awareness; During, by enabling a local, one-stop access to get someone on the phone who is empathic and responsive and can direct callers to the appropriate support based on crime type; After, by providing key contacts to guide in recovery and tools to prevent re-victimization.

Perminter guided Lynx Technology Partners through its evolution into a multi-million dollar Information Security and Risk Management company. In his 25-year career, Perminter has held a wide variety of leadership positions across key parts of Information Technology businesses. He founded Lynx in March 2009 and served as the CEO through August 2015. He is also currently serving as the President of the International Consortium of Minority Cybersecurtiy Professionals (ICMCP), a non-profit organization focused on achieving the consistent representation of women and minorities in cybersecurity through programs designed to foster recruitment, inclusion and retention – one person at a time.

Perminter represents a number of external venues. He is the second member and shareholder of THREAT STREAM, serves on the executive board of BCT Partners, is a member of the Employer Advisory Council for Per Scholas, an Advisory Board Member of CloudeAssurance, and investor in SecurityCurrent.

“As CSN takes on the complex mission of serving millions of cybercrime victims in the US, we rely on the passion for service and cybersecurity expertise of our board of directors to guide our team,” said CSN CEO/President Kristin Judge. “Perminter brings the specialized skill set and deep understanding of the issues needed to drive CSN forward. We are truly grateful for his willingness to join our efforts.”

 

 

Dating app hack exposes 6 million users’ personal data

Dating Apps

Coffee Meets Bagel, a dating and social networking app/website has become the latest victim of a data breach after hackers exposed around 6 million users’ personal information. The San Francisco–based company stated that unknown intruders compromised the users’ information and exposed it on the dark web marketplace.

Coffee Meets Bagel notified all the affected users about the incident in an email. The exposed information included users’ names, location, gender, addresses, email addresses, and other personal information, the Independent reported.

“We recently discovered that some data from your Coffee Meets Bagel account may have been acquired by an unauthorized party. Once we became aware, we quickly took steps to determine the nature and scope of the problem. We have engaged forensic security experts to conduct a review of our systems and infrastructure,” the company said in an email statement.

Coffee Meets Bagel also stated that it’s going to enhance the security measures to better detect and prevent unauthorized access to its systems in the future.

Dating apps have been a prime target for hackers. Research by Kaspersky Lab, on analyzing several dating apps, revealed that the dating apps transmit unencrypted user data over insecure HTTP protocol risking user data exposure. According to researchers, the reason for the vulnerability was due to applications using third-party ready-to-go advertising Software Development Kits (SDKs), popular among advertising networks. Researchers while digging deeper found that most of the data were sent out unencrypted and over HTTP, making the data highly vulnerable while travelling through servers. Lack of encryption may mean that the data can be deciphered and intercepted by anyone.

The researchers suggested that these data can be modified and can be infused with malware endangering the user data. They also advised users to follow preventative measures like checking app permissions and using VPNs.

Raytheon receives $406 million contract from U.S. Army

Cisco Routers Vulnerability

The United States-based military contracting giant Raytheon has received $406 million Indefinite Delivery/Indefinite Quantity contract award from the U.S. Army for ARC-231A radio systems. The contract, which will be performed over the next five years, includes upgrades, production, and support for up to 5,000 radios.

ARC-231A is a software-defined and can accommodate rapid upgrades without requiring the radio to be removed from its platform. The radios will be installed on a variety of Army platforms, including the UH-60 Black Hawk, UH-72 Lakota utility helicopter, and the AH-64 Apache attack helicopter. Raytheon stated the latest version of the system gained NSA Type 1 certification and delivers secure, classified communications on the battlefield.

Raytheon is a technology developer specialized in defense, civil government, and cybersecurity solutions. The company provides advanced electronics, mission systems integration, C5I products and services, sensing, effects, and mission support for customers in more than 80 countries.

“These radios are the backbone of rotary-wing communications,” said Barbara Borgonovi, vice president of Raytheon Integrated Communication Systems. “The ARC-231A enables U.S. forces to maintain the edge in secure communications, whether they’re flying in contested or congested environments.”

In December 2018, Raytheon had announced that it was going to form a joint venture with Saudi Arabian Oil Company Saudi Aramco to develop cybersecurity services in the Saudi region. According to the Memorandum of Understanding, the Saudi Aramco and Raytheon Saudi Arabia, a subsidiary of Raytheon Company, developed and provided advanced cybersecurity software and hardware.

They carried out research and development activities in the Saudi Arabia region. Saudi Aramco stated the latest venture would strengthen the cybersecurity capability of the company as well as its suppliers, customers, and affiliates. According to Raytheon, the agreement would continue to fuel its global growth in the areas of defense systems and platforms.

Peltarion raises $20 million to develop its operational AI platform

Software development company Peltarion has raised $20 million in a series A funding round led by Euclidean Capital along with the participation from the existing investors FAM and EQT Ventures. The Swedish startup, founded by former security veterans from companies like Spotify, Skype, King, TrueCaller, and Google, stated the new funds will support its mission to develop and make AI technology affordable to the public and private enterprises.

Founded in 2004, Peltarion claims to provide an operational AI platform to enterprises for fast, efficient, and scalable production of commercially viable AI applications. The company says its mission is to make AI technology useable and affordable for governments, non-profits, and other enterprises. Peltarion also offers collaborative and graphical cloud platform for developing, managing, and deploying deep learning systems at scale.

Peltarion claims that its AI technology platform is already being used by various companies globally, including NASA, Tesla, General Electric, Dell, BMW, Deutsche Bank, Lloyds Banking Group, and the Universities of Harvard, MIT and Oxford.

“The speed at which AI systems can be built and deployed on the operational platform is orders of magnitude faster compared to the industry standard tools such as TensorFlow and require far fewer people and decreases the level of technical expertise needed. All this results in more organizations being able to operationalize AI and focusing on solving problems and creating change,” Luka Crnkovic-Friis, Peltarion’s CEO and co-founder said in a media statement.

“AI is a technology that everyone should benefit from. Our mission is to make AI technology useable and affordable for all and this investment will help us to grow and scale in order to do better in the world,” Crnkovic-Friis added.

Email service provider VFEmail suffers a catastrophic attack

Email service provider VFEmail is the latest victim of a cyber-attack. The United States-based company in a recent statement admitted that unknown intruders wiped out the firm’s primary and backup data from every server in what has been dubbed as a catastrophic attack on the company.

Founded in 2001, VFEmail provides email services to enterprises and end users. Rick Romero, the founder of VFEmail, called the attack a catastrophic one. It’s believed that around 18 years’ worth of customer email data in the United States may be disappeared forever. The issue was discovered on February 11, 2019, after several users reported that they were not receiving messages. VFEmail stated that the mail services are up for the customers presently and they’re making efforts to recover the users’ data.

“We have suffered catastrophic destruction at the hands of a hacker. This person has destroyed all the data in the United States, both primary and backup systems. We are working to recover what data we can,” the company said in a statement.

“At this time, the attacker has formatted all the disks on every server,” VFEmail wrote in a Twitter post. “Every VM [virtual machine] is lost. Every file server is lost, every backup server is lost. Strangely, not all VMs shared the same authentication, but all were destroyed. This was more than a multi-password via ssh exploit, and there was no ransom. Just attack and destroy.”

Recently, a massive data breach left around 773 million email addresses and more than 21 million passwords unprotected online. According to the security researcher Troy Hunt, the person behind the breach notification service website Have I Been Pwned, a huge database that includes records from more than 2,000 hacked databases was exposed online.

The breached data, which Troy Hunt called Collection #1, include around 773 million (772,904,991) unique email addresses and 21 million (21,222,975) unique passwords. Sized around 87 GB, the breached records also included 1,160,253,228 unique combinations of breached email addresses and passwords. Hunt stated the data breach is made up of various individual data breaches from thousands of other sources.

 

Security breach affects 14.8 million 500px users

Data Security, Unprotected Database Exposes 14 Million Key Ring App Users Info

500px, a Toronto-based online photo-sharing platform, recently revealed that it suffered a security breach that compromised around 14.8 million users’ personal information. In an official statement, 500px stated that an unauthorized intruder gained access to its systems on July 5, 2018. The breach was discovered by its security officials on February 8, 2019. 500px is a community for photographers that allows them to share their work globally.

500px concluded that the incident affected certain information provided by the users while filling out their profiles. The data included users’ first and last names, username, email address, password, birth date, addresses, gender details, and other sensitive information.

However, the company clarified that they found no evidence of any misuse of the compromised data. 500px notifying all the affected users via emails to reset their account credentials as a precautionary measure.

“On February 8, 2019, our engineering team became aware of a potential security issue affecting certain user profile data. We immediately launched a comprehensive review of our systems to understand the nature and scope of the issue. We engaged a third-party expert to assist us in our investigation and are coordinating with law enforcement authorities on this matter,” the company said in a statement.

“Regardless of whether or not you were directly affected, given the nature of the personal data involved, we are alerting you to this matter, so you can take steps to help protect yourself against the risk of phishing, spam, and misuse of your information as a result of this issue. We recommend you change your password on any other website or app on which you use a password that is the same as or similar to your password for your 500px account,” the statement added.