Home Blog Page 354

Cybersecurity startup Myki bags $4 million to scale operations

Startup funding

Cybersecurity startup Myki recently raised $4 million in Series A funding round led by a returning investor Dubai-based venture capital firm BECO Capital. The other returning investors in the round include Beirut-based LEAP Ventures and B&Y Venture Partners. Myki stated that the new funds will support to scale its U.S. operations in a move to tackle decentralized Identity Management in the enterprise space.

Founded by Priscilla Elora Sharuk and Antoine Vincent Jebara in 2015, the Lebanon-based startup deals with the security and identity management services. It offers identity solutions to both consumers and enterprises that allow users to store sensitive information offline, away from the cloud.

Speaking on the new investment, the co-founder and CEO of Myki, Antoine Vincent Jebara, said: “Our mission for the next two years is to build the infrastructure required on all levels to keep growing fast, the way we have been for the past 12 months and become a world leader in decentralized identity management.”

Myki operates on three user verticals – for customers, administrators, and service providers. Its mobile application, Myki Password Manager & Authenticator, allows users to store and manage their passwords, credit cards, and ID cards using biometric authentication. Its Myki for Teams platform gives organizations a full visibility and control over their access management. And Myki’s web portal, Managed Service Providers, allows service providers to manage the passwords of their clients in a secure manner.

“We are firm believers that online security and data privacy is not a privilege, it is a right, and that is why at Myki, we empower our users with the tools to securely manage their digital identity,” said the co-founder and COO Priscilla Elora Sharuk.

Temasek and StarHub partner to form a joint venture

U.S. and Australia to Jointly Develop Cyber Training Platform

Singapore-based telco StarHub has announced that it has entered a partnership with Temasek Holdings to form a joint venture which will be christened as Ensign InfoSecurity, touted to be one of the largest cybersecurity organization to emerge out of Asia. Services provided by the new entity will include professional cybersecurity services, designing and building enterprise-wide cyber-security solutions and managed security services.

StarHub in a release stated that its Cyber Security Centre of Excellence and Accel Systems and Technologies (ASTL) with Temasek-owned Quann to form Ensign InfoSecurity. StarHub said Ensign will harness the capabilities of ASTL and Quann to “deliver end-to-end cyber-security solutions to organisations in Singapore and overseas markets, as a Singapore-based pure-play cyber-security company with end-to-end capabilities comprising professional services, systems integration and managed security services”.

Lee Fook Sun, the chairman of Quann will head the new cybersecurity entity. “Ensign will be uniquely positioned to integrate the expertise from our founding partners, as well as develop new capabilities, to ensure our clients have the most robust cyber-defence capabilities. We are also fortunate to have the renewed leadership of a strong team to grow our capabilities further and take on market opportunities,” he said in a release.

The release also stated that Temasek will hold 60 percent of the JV while StarHub will own the remaining 40 percent. Ensign will also buy several cybersecurity assets from StarHub, considered at $120 million.

The company is also mulling on extending its effort toward building R&D labs, enhance cyber analytics, and development of global threat intelligence.

Search Group acquires Henderson Scott

Acquisition

UK-based Search Consultancy recently acquired Henderson Scott, a search and recruitment solutions provider. The current acquisition is its first after Search Group underwent MBO. Henderson Scott’s expands its capabilities across several core markets including enterprise architecture, IT infrastructure and data center, enterprise cloud, digital and business transformation, cyber security and software technology.

“This is the first acquisition we have undertaken since Search’s MBO and refinancing. It significantly enhances our capability in the technology space and gives us real market presence in London, “Search Group CEO Grahame Caswell said in a release. “The converging world of IT continues to present exciting opportunities and with a rapidly expanding cloud market place the acquisition of this highly scalable UK business is a clear strategic fit for the Group.”

“This is an exciting time for both businesses. I am delighted that Henderson Scott has joined a Group with the ambition for growth as well as the infrastructure to continue supporting and developing our service offering and our people,” said Mark Bailey, CEO of Henderson Scott. “Backed by the scale of the Search Group, including geographical reach, complementary technology expertise and experience across its verticals, we are very much looking forward to realising our potential as part of the bigger team.”

Two-thirds of UK organizations do not have cyber insurance

Nearly two-thirds of British organizations are not insured for cyber incidents, according to Risk: Value report from NTT Security. Even with massive uproar around cybersecurity and the Global Data Protection and Regulation coming to effect earlier this year, a vast majority of UK companies do not have a cyber insurance to cover major cyber attacks and breaches.

The report which surveyed 1,800 global senior decision makers from non-IT functions pointed out that UK organizations have spent more than $1 million to recover from cyber attacks. “With estimated annual losses from cyber crime now topping $400bn (£291bn) according to the Center for Strategic and International Studies, you would hope more organisations would be beating a path to insurers’ doors. But while the insurance sector is certainly seeing growth in the number of policies being taken out to cover such losses, it’s an issue that many senior decision makers are not on top of, ” said Kai Grunwitz, Senior VP EMEA, NTT Security.

According to the study, less than a third (29 percent) of firms have dedicated cybersecurity insurance in place. Even here six percent said their insurance covers only for information security breaches, while 11 percent covered data loss alone. This was despite the fact that 81 per cent of the respondents felt that it is important for their organizations to be cyber insured.

He added, “While cyber risk insurance should be put in place to help mitigate the potential fallout of a data security breach, a policy must not be seen as a ‘get out of jail free’ card. Cyber insurance must be complementary to an effective risk-based information security strategy, not a replacement for it. You wouldn’t expect your house insurance provider to pay out if you were burgled when the doors and windows are left unlocked. So don’t expect a payout – or indeed an insurance policy – if you haven’t put in place the right processes and policies.”

Major cryptocurrency exchange Bittrex to delist Bitcoin Gold following $18 mn hack

Bittrex

By mid-September, cryptocurrency exchange Bittrex will delist Bitcoin Gold (BTG) following the $18 million hack of the BTG network that began in May.

Earlier this year, the hard fork cryptocurrency Bitcoin Gold suffered a double-spending hacking attack that managed to amass over $18 million worth of BTG coins taking control of more than 51 percent of the BTG hashrate in the process.

Following the hack, the Bitcoin team in a statement said, “An unknown party with access to very large amounts of hashpower is trying to use “51% attacks” to perform “double spend” attacks to steal money from Exchanges. We have been advising all exchanges to increase confirmations and carefully review large deposits. There is no risk to typical users or to existing funds being held. The only parties at risk are those currently accepting large payments directly from the attacker. Exchanges are the primary targets.” While adding, “The cost of mounting an ongoing attack is high. Because the cost is high, the attacker can only profit if they can quickly get something of high value from a fake deposit. A party like an Exchange may accept large deposits automatically, allow the user to trade into a different coin quickly, and then withdraw automatically. This is why they are targeting Exchanges.”

The attack affected several exchanges including Binance, Bitinka, Bitfinex, Bithumb, Hitbtc, and even Bittrex. Bittrex lost approximately 12,372 BTG and had asked BTG team to compensate for the losses, which the latter did not agree upon. The end result was the delistment of BTG.

“We regret to inform our community that the crypto exchange Bittrex has decided to de-list BTG after we declined to pay them 12,372 BTG to remain listed,” explained the BTG team to Bitcoin News. “Bittrex informed us that they make this decision because the BTG team would not “take responsibility for our chain,” and that taking responsibility meant paying Bittrex 12,372 BTG to cover the loss they incurred.”

HMC says ransomware attack turned into a data breach

Ransomware attacks, ransomware, Sinclair Broadcast group

Health Management Concepts (HMC) recently experienced a ransomware attack that quickly turned into a major data breach that compromised the patient’s personal data like names, social security numbers, and health insurance information.

HMC notified the New Hampshire Attorney General that it has discovered, on July 16, a ransomware attack on its server which is used to share files with the clients. The healthcare management vendor provides chronic condition management to IBU (Inlandboatmen’s United of the Pacific National Benefit Funds).

On July 19, HMC revealed that the forensic firm that was engaged to handle the ransomware incident unintentionally provided a file containing personal information like patients’ names, social security numbers, and health insurance plan data of IBU’s members, including social security numbers of four New Hampshire residents.

“To help prevent this type of incident from occurring again, HMC is adding enhanced security protocols to its current server, including removing access to the server through Remote Desktop Protocol. It also is migrating its server to another cloud computing service, which will provide additional security,” HMC said in its letter to the NH Attorney General.

HMC did not clarify how the personal information was provided to the attackers and also did not announced the number of victims affected by the incident apart from the four New Hampshire residents.

In a similar data breach incident, the Lowa-based health system UnityPoint Health fell victim to a data heist that compromised 1.4 million patient records. According to an official statement from the company, the issue began when UnityPoint Health received a series of phishing emails that trapped some employees to provide their sign-in credentials. This gave the hackers unauthorized access to the company’s business email accounts. The organization discovered the incident on May 31, 2018, and notified the victims about the data theft.

 

STC and Anomali partner for establishing cyber threats information sharing platform

STC Anomali partnership

Saudi Telecom Company (STC) recently joined hands with threat intelligence platform provider Anomali to boost cybersecurity. STC stated that the new collaboration establishes a platform for sharing information on cyber threats and focuses on enhancing the methods of dealing with cyber threats within the STC Group.

“Through bilateral agreements with specialized companies, our aim is to continue enhancing cybersecurity in the STC Group in order to protect customer data. The agreements will help in analyzing cyber data for information of cyber-threats via interactive platforms at the right time,” said Yasser Alswailem, cybersecurity general manager.

Anomali helps organizations find and respond to cyber threats. The US-based cybersecurity company notifies organizations against cyber actors and other distrustful activities on their networks through internal security monitoring programs. The partnership enables the STC group to use the latest technologies in cybersecurity with high-quality information on sources of threats and cyberattacks, providing an early alarm system for any possible cyber incidents.

On March 21, 2018, Anomali partnered with the National Health Information Sharing and Analysis Center to raise the security standards for data sharing processes in the healthcare industry. NH-ISAC is a healthcare global community for collaborating and spreading best practices. The council informs and helps its members in the application of physical and cyber threat intelligence to adopt threat mitigation practices. Members of NH-ISAC include hospitals, healthcare insurance payers, pharmaceutical and biotech manufacturers, medical device manufacturers, laboratories and diagnostic centers, ambulatory providers, and more.

Anomali provides the infrastructure and tools to the NH-ISAC, therefore, their partnership is expected to strengthen cybersecurity measures for the healthcare domain. The CEO of Anomali Hugh Njemanze commented on the partnership, “One organization’s threat detection is the next organization’s prevention. We are pleased to support the NH-ISAC mission to secure the nation’s critical healthcare infrastructure and help members better share intelligence and respond to threats.”

RBI working on enhanced measures to strengthen cybersecurity of Indian banks

Reserve Bank of India

To curb rising cyber incidents on monetary transactions, India’s central bank, Reserve Bank of India, recently announced an enhanced security mechanism as part of its agenda for the fiscal year 2018-19. The newly proposed mechanism is intended to provide high-level protection against cybersecurity threats.

“In an endeavor to strengthen the cybersecurity posture of Indian banks, focused and theme-based IT examinations are planned during 2018-19. Targeted scrutiny, as and when required, would also be conducted for appropriate policy and supervisory intervention,” the RBI said.

With digital transactions witnessing a significant rise, the Indian central bank stated that it’s reinforcing data protection, cybersecurity, and Know Your Customer (KYC) norms to make them more effective.

“With the emerging threat landscape, where organized cybercrime and cyber warfare are gaining prominence, the Department (of Information Technology) is working towards ensuring continuous protection against changing the contours of cybersecurity threat,” RBI stated in its annual report.

The RBI’s report said the new agenda includes taking effective steps to initiate the process of developing a cybersecurity culture, endeavor to make cybersecurity a responsibility, and ensure confidentiality, integrity, and availability of information system and resources. According to the report, the new private sector and foreign banks accounted for 36 percent each of all cyber frauds reported in debit, credit, and ATM cards.

“In order to secure consistency and improve the efficiency of the off-site monitoring mechanism, an Audit Management Application portal to facilitate various supervisory functions of the Cyber Security and Information Technology Examination (CSITE) Cell and to fully automate monitoring of returns has been envisaged, which will be operationalized by March 2019.” the report said.

 

John McAfee’s “unhackable” crypto wallet device hacked

Mcafee

We can come to a conclusion that calling something unhackable and boasting about it may not be the best thing to do. For whatever it was, they should understand that hackers are more evolved than ever. The biggest take away here must be for the cybersecurity pundit John McAfee who recently launched his BitFi, an apparent ‘unhackable’ crypto wallet device. Here is the news, BitFi was hacked. Not once, but twice.

The first thing the company has done post the incident is to remove the unhackable word from its website for, we believe, certain obvious reasons! The company made the announcement after a group of security researchers released an evidence of the wallet being compromised. “As part of our ongoing efforts to protect our customers, we have hired an experienced Security Manager, who is confirming vulnerabilities that have been identified by researchers. Next week, we will make comprehensive public announcement acknowledging and addressing these issues that have been identified. Effective immediately, we are closing the current bounty programs which have caused understandable anger and frustration among researchers. We acknowledge and greatly appreciate the work and effort by researchers. In our public announcement next week, we expect to confirm the final status of each of our current bounties and also provide very specific action items on our future product roadmap. Going forward, the company will launch a conventional bounty program through Hacker One,” the website released a statement.

“Effective immediately, we will be removing the “Unhackable” claim from our branding which has caused a significant amount of controversy. While our intention has always been to unite the community and accelerate the adoption of digital assets worldwide, we realize that some of our actions have been counterproductive to that goal. Please stay tuned next week for our public announcement.”

The group claimed that they had hacked the wallet before but Bitfi and Mr McAfee refused to accept their evidence as the rule of the bug bounty program that required the hacker to empty the contents of a BitFi wallet that we have pre-loaded and have sent to you.

Well, for Sir John McAfee is, who is known for is obvious nature, the hack hasn’t occurred even after he upped the bounty to $250K, going all Samuel Jackson’s ‘I double dare you’ way. He even took to twitter saying, “Its selling like hotcakes. And, still, no one has been able to hack it and get the coins. Since the purpose of the wallet is to store coins, every claimed “hack” has been http://unsuccessful.it  is clearly unhackable.”

NewKnowledge raises $11 million in a funding round

Startup Funding

Cybersecurity startup NewKnowledge recently raised $11 million in a Series A funding led by existing investor GGV Capital, with participation from Lux Capital. The company stated the new funds will support to expand its sales and marketing channel and also to strengthen its position in the disinformation defense industry.

“We are living in an age of information warfare,” said New Knowledge CEO, Jonathon Morgan. “Disinformation campaigns may be highly organized and well-funded state attacks on industry, as well as individual operators trolling the internet to create chaos and division. Attacks against governments and political figures are well documented, and the problem has expanded to include attacks against companies, brands, and public figures. New Knowledge’s mission is to help companies identify these threats early, and to remediate them before they gain momentum and erode a company’s reputation.”

The Austin-based company was founded in 2015 by a group of experts from national security, digital media, and machine learning industry. NewKnowledge is specialized in disinformation defense solution that protects brands and corporations to identify attacks and stop the spread of misinformation. The startup uses machine learning, artificial intelligence (AI) and human analysis that provide end-to-end disinformation defense solution to monitor, detect, and mitigate against malicious digital attacks.

“As disinformation campaigns and automated media manipulation have accelerated, New Knowledge has emerged as critical to helping preserve the digital media platforms that the technology sector has helped build,” said GGV Capital Partner, Glenn Solomon. “While social and digital media platforms have taken important steps to thwart hackers and trolls, they cannot be relied upon solely to correct this growing problem. The team at New Knowledge has devised a solution that goes beyond social listening to combat disinformation at the source and help businesses prevent threats from spinning out of control. At GGV Capital we seek to invest in great entrepreneurs addressing large and growing markets with innovative technologies. New Knowledge is focused on a very exciting and important opportunity and we’re excited to back the company.”