Home Blog Page 399

Israel startups raised $2.3 billion in first half of 2017

Israel

Israeli startups are currently on track to break the previously held fundraising record of $4.8 billion. The total value of funding received by the Israeli startups has already touched $2.3 billion during the first six months of 2017. This is the second year in a row that the Israeli startups are able to attract large investments, as the previous record was set in the last year itself. The raised $400 million only in the month of June.

Some startups cracked lucrative deals, with web and app traffic monitoring digital company SimilarWeb leading the way with a funding worth $47 million. The other companies that followed include Iguazio, a big data and IoT company, with $33 million; cybersecurity companies PerimeterX and Nyotron at $23 million and $21 million; Prospera, a digital farming company, at $15 million; and digital health big data company Somatix at $6 million. The total value of investment summed up to $145 million in a single week despite the financial investments starting slow at the beginning of the month.

Among other investments in the month, cybersecurity company Deep Instinct notched up around $32 million, cloud cost management company Spotinst raised $15 million, and robotics company Intuition Robotics secured $14 million.  Gong.io and smartphone repair company CellSavers were also able to impress the investors as they received a funding of around $20 million each.

HBO targeted in major security breach

In a major cyber breach, hackers have reportedly broken into the American television network HBO and subsequently leaked the forthcoming episodes and scripts of popular TV show “Game of Thrones.” New episodes from other shows including “Ballers” and “Room 104” were also stolen by the hackers who have already released some of the data online. The total volume of data stolen, according to several news agencies, is believed to be around 1.5 terabytes, though the official figure is yet to be revealed.

An anonymous email to the reporters said, “greatest leak of cyber space era is happening. What’s its name? Oh I forget to tell. Its HBO and Game of Thrones……!!!!!! You are lucky to be the first pioneers to witness and download the leak. Enjoy it & spread the words. Whoever spreads well, we will have an interview with him. HBO is falling.”

There has been a surge in cases of security infringement against major Hollywood companies, including Disney and Netflix that were threatened with early release of certain movies and TV shows earlier this year.

The latest incident puts HBO in a fix over maintaining the secrecy of the plot of its most valuable property  ”Game of Thrones.” The TV channel had already faced a similar issue back in 2016, when the first four episodes of the fifth season of the series were leaked, which led to the company’s decision of not sending any advance screeners before the original broadcast.

The recent hack was termed as “disruptive, unsettling, and disturbing” by HBO Chairman Richard Piepler. The channel issued a statement saying, “HBO recently experienced a cyber-incident, which resulted in the compromise of proprietary information. We immediately began investigating the incident and are working with law enforcement and outside cybersecurity firms. Data protection is a top priority at HBO, and we take seriously our responsibility to protect the data we hold.”

OpenText to acquire Guidance Software

OpenText

In a recent announcement, Ontario-based content management company OpenText said it is all set to acquire Guidance Software as a fully owned subsidiary for an overall price of $240 million in a deal that is expected to close by the third quarter of this year. The shareholders of Guidance will be paid $7.10 a share which would translate to a total value of $18 million, making the final price just around $222 million.

Guidance Software is a forensic security and eDiscovery vendor that has a customer base consisting 78 of the Fortune 100 companies. The acquisition will give OpenText a complete access to the forensic and eDiscovery tools along with the rich customer base of Guidance Software, though some overlapping functionality would also be included in the package. OpenText had already closed another high-profile deal with overlapping functionality last year when it acquired enterprise content management firm Documentum from EMC for $1.62 billion.

Cheryl McKinnon, analyst from a content management industry research firm, Forrester Researcher, said, “It certainly adds, with some overlap, to their eDiscovery and file analytics portfolio (i.e., those tools to clean up network drives, detect sensitive text inside documents, etc.). But OpenText has never had anything focused more on the forensic side of the discovery business. — that is, more security, deeper inspection of how information [has been] accessed, copied, etc. So that forensics side is net new for them,”

Several other analysts from the content management industry research firms expects OpenText to come up with more such acquisitions in coming months. The founder of one such firm Alan Pelz-Sharpe said, “I doubt it will be the last such acquisition by OpenText this year, indeed I expect to see more similar sized deals before year end.” On the deal with Guidance, he commented, “it’s about twice revenue, which is what you would expect on a deal like this one.”

Belfast-based tech firm bags £3.5m investment for heartbeat ID system

Belfast firm raises funding

Belfast-based cybersecurity firm B-Secur, the creator of a software that can turn human heartbeat pattern into an ID, was able to secure £3.5 million in investments from multiple investors in the United Kingdom and Ireland, including Accelerated Digital Ventures (ADV) and Kennel Capital.

Founded in 2002 by Colin Anderson OBE, the company provides biometric security solutions to customers in automotive industry, financial services, buildings and healthcare.

Commenting on the deal, The CEO of B-Secur, Alan Foreman, said, “This announcement underscores the growing demand from organizations to provide better security to their customers in this digital world, amid an escalation in high-profile cyberattacks. I believe that our ECG authentication technology is crucial to supporting this global challenge. We are thrilled to gain the backing of ADV, Kernel and others. This will help us to grow significantly in the next 12 months and continue to invest in world-class science and engineering in the UK and beyond, and we are proud to have the opportunity to build a truly global business solving a serious problem that each of us faces every day.”

The biometric technology developed by B-Secur uses the electrocardiogram of an individual to authenticate their identity. It is seen as a step ahead than the already existing biometric technologies like fingerprint or iris scanners, which are dubbed as more vulnerable due to their common availability. On the other hand, B-Secur’s solution is based on “internal biometric” used in the ECG technology, reducing any chances of potential cybersecurity threats.

Michael Dimelow, head of investment for ADV, emphasized on the importance of the deal as he said, “In a world where security and personal identity are central to accessing a range of online digital services, B-Secur’s technology harnesses the unique power of the human heartbeat to unlock everything from finance to healthcare, from cars to buildings. ADV is excited to be supporting B-Secur as they deploy their market-leading patented software across all forms of devices including mobile and wearables.”

 

Facebook CSO urges security industry to be more people centric

Facebook office

In the recently held 2017 Black Hat conference, the Chief Security Officer (CSO) of Facebook Alex Stamos reprimanded the security industry for being more concerned about the technological aspect of a cyber attack rather than being focused on finding methods that would ensure protection for the common people on the Internet. He provided examples of technically sound presentations at the conference which failed to address the “real” issues faced by people who have less clarity while working around a technology. Stamos said, “We have perfected the art of finding problems without fixing real world issues. We focus too much on complexity, not harm.”

Addressing the audience, Stamos asked the security industry to show more empathy towards people or “the situation will only worsen.” According to Stamos, the security industry is only concerned about the “small number of complex hacks” that affects large corporations, and said “most Facebook users who lost data were not being targeted by spies or nation-states.” He added that, “things that we see, that we come across every day, that cause people to lose control of their information are not that advanced. Adversaries will do the simplest thing they need to do to make an attack work.”

Addressing the issue about the security breaches due to human negligence, Stamos urged the security experts to provide “tools and services that were more straightforward to use.” He also cited examples of rolling out end-to-end encryption for Facebook-owned WhatsApp which was not appreciated by some experts, and said that the WhatsApp security team had to make “difficult choices” to make the app easier to use.

Stamos also asked the cybersecurity industry to be more tolerant towards accepting human failures and to find a workforce balance to take care of the “blind spots” faced by the industry. He said, “Things are not getting better, they are getting worse. That’s because we do not have enough people and not the right people to make the difference. The growing importance and influence of cyber-security meant the industry had a real chance to improve peoples’ lives. We have the world’s attention, now we have to ask what we are going to do with it.”

More than 2.5 million people encountered ransomware in last 12 months: Europol

Ransomware attack on Nunavut, Emotet Cobalt Strike

The European police and Kaspersky Lab conducted a study that reported, “Ransomware has soared since 2012, with criminals lured by the promise of profit and ease of implementation.” According to Kaspersky Lab, “total number of users who encountered ransomware between April 2016 and March 2017 rose by 11.4 percent compared to the previous 12 months, from 2,315,931 to 2,581,026 users around the world.” The statement comes in the wake of Wannacry and Petya attacks in the last couple of months which had crippled thousands of businesses across the globe.

To counter the menace of ransomware attacks, Europol had launched the “No More Ransom” initiative in association with Kaspersky Labs, Dutch Police, and other cybersecurity agencies last year. The inititative in now backed by more than 100 companies, including top names such as Barclays Bank and Cyber Security Agency of Singapore, among others.

The “No More Ransom” website features 54 specialized decryption tools from nine partners that was used to “decrypt more than 28,000 devices, depriving cybercriminals of an estimated eight million euros in ransoms.” The website is accessible in 26 different languages including Chinese, Malay, Tamil, and Thai.

The Europol stressed on regular updation of security protocols in all computer systems. It also urged cyberattack victims to reach out to the authorities in case of any security breach. “If you do become a victim, it is important not to pay the ransom,” Europol warned.

Victims lost more than $25 million to ransomware in last two years: Google

Goolge

A recent study by researchers at Google, Chainalysis, UC San Diego, and the NYU Tandom School of Engineering has revealed that the victims of ransomware attacks have collectively paid more than $25 million as ransom in the past couple of years. The researchers investigated 34 families of malwares and tracked the total amount of ransom paid to the attackers by the victims, mainly through blockchains or bitcoins.

According to the study, the most lucrative ransomware is “Locky” strain, which was first detected in 2016. The strain has accounted for $7 million from the time it was detected. “Locky” is followed by Cerber and CryptXXX which made the victims pay up around $6.9 million and $1.9 million, respectively.

Damon McCoy, the New York University professor, who worked on the “Locky” project, said that the ransomware’s big advantage was “the decoupling of the people who maintain the ransomware from the people who are infecting machines. Locky just focused on building the malware and support infrastructure. Then they had other botnets spread and distribute the malware, which were much better at that end of the business.”

The study also suggested that the attackers are improving the programing of the modern malware so that they can even infiltrate a system protected by antivirus software by changing their binaries automatically upon detection. The current development in the field of malware makes it very difficult to trace, and the impact generated has been costly as well as widespread, the study explained.

Indian government strengthens efforts to promote cybersecurity startups

India

To accelerate the commercialization of cybersecurity products in India, the country’s government organizations Technology Development Board (TDB) and Data Security Council of India (DSCI) have entered a partnership. The two organizations would be working to come up with a plan to provide funding support and create a favorable environment to promote the cybersecurity startups and product entrepreneurship in an ecosystem that includes about 100 companies involved in areas like threat Intelligence, identity and access management (IAM), and cloud access security solutions.

According to reports, the two organizations discussed the current cybersecurity ecosystem with stakeholders and identified a roadmap for cybersecurity product development and commercialization. Avenues through which TDB can be leveraged as a funding platform were also discussed. TDB has been already in the process of funding upscaling, manufacturing, and commercialization of domestic and imported technologies for over two decades, and has signed almost 400 agreements with companies in multiple sectors.

The Secretary of TDB, Dr. Bindu Dey, said, “Cybersecurity is IP-rich & Technology-driven domain that needs minimum investment but serious attention from key stakeholders. While we have been funding companies in various verticals, we are now committing to strengthen this ecosystem along with other players to accelerate the growth of cybersecurity start-ups in the country,”

Rama Vedashree, CEO of the DSCI, said, “Promoting Indian cybersecurity innovation & entrepreneurship is one of the imperatives to build robust capabilities for strengthening cybersecurity posture of the country. Though Indian cybersecurity industry is at a nascent stage, we have seen some success stories of our entrepreneurs winning in global markets. As cybersecurity startups continue to face challenges in marketing and market access, it is important that government and investors come forward to support them at different stages of their lifecycles. In the line with our Honourable Prime Minister’s vision to make India a hub of cybersecurity products and services, last year NASSCOM-DSCI Cybersecurity Task Force (CSTF) had launched the roadmap for building the cybersecurity products and services industry to USD35 billion by 2025. We are currently working with the industry and government to meet this ambitious target.”

Simplilearn and EC-Council Partner to Train Tomorrow’s Cyber Security Experts

EC-Council

Digital economy training company Simplilearn and cyber security leader EC-Council announced their partnership to bridge the growing skill gap in cyber security, one of the fastest-growing careers in the U.S. and globally. Simplilearn now offers the same EC-Council ‘Certified Ethical Hacking’ course used by many of the U.S. Government’s military and security agencies.

A report by Frost & Sullivan predicts that there will be a global shortage of 1.5 million cyber security professionals by 2020. In the U.S. alone, over 40,000 information security analyst jobs go unfilled every year and employers are challenged to fill 200,000 other cyber security related roles, according to cybersecurity data tool Cyber Seek . To bridge this shortage in skills, employers must not only increase their hiring of certified and skilled professionals for these lucrative and high-demand security jobs but also train existing employees from within to meet these strategic goals.

“EC-Council has always been a thought leader in equipping Government and Corporate organizations globally with real, tactical hands-on vendor agnostic offensive and defensive cyber security skills to really secure their cybersecurity posture. Having programs like Certified Ethical Hacker (CEH), Certified Hacking and Forensics Investigator (CHFI) and many others, in the portfolio, that are mapped to NIST framework and endorsed by Department of Defense USA (DOD 8570), CNSS and other key organisations, EC-Council certified professionals have become one of the most sought after by employers worldwide. A partnership with Simplilearn would allow these programs to be accessible to the masses who are currently pursuing a lucrative career in Cybersecurity and looking to attain the highest quality skills and accreditation,” said EC-Council Executive Director Danish Arshad.

Speaking on the partnership, Anand Narayanan, Chief Product Officer at Simplilearn said, “Every day, organizations of all sizes are victims of data breaches. The increasing number of cyber threats across industries has led to companies losing out on revenues and reputations. This is largely because the demand for skilled cyber security experts currently surpasses the supply. By partnering with an industry leader like EC-Council, our aim is to provide our learners with access to the highest quality cyber security training and help them become employable in one of the hottest and most lucrative fields, while helping organizations reduce their security risks.”

The course is available through online self learning as well as live virtual classrooms where individuals can learn from global instructors. This partnership further provides flexible training access to attend multiple live classes for all learners who enrol by August 31st. EC-Council’s in-depth training in cyber security is augmented by Simplilearn’s high touch learning model which allows learners to access community forums, projects, teaching assistance, study plans, and reminders. Upon completing the courses, learners will be certified by EC-Council that will help them prepare for IT security job roles across industries.

Botched data backup in Sweden

Sweden, security data leak

In a massive botched data transfer, Sweden’s Transport Agency sent information about every vehicle in the country to marketers. The agency believed it was moving the data to cloud storage via an outsourcing agreement with IBM, but apparently, the information was forwarded to third parties and the agency then tried to cover up the cyber security breach.

According to Pirate Party Founder Rik Falkvinge, who is also a key player at the Virtual Private Network (VPN) company Private Internet Access, a whole host of sensitive information was compromised. Several databases that may have had top-secret designation may have been included in the information security violation, including data on members of the military holding high-security positions, criminal suspects, and citizens in witness protection programs. The information breached included names, photos, and addresses.

Falkvinge also criticized the lack of punishment in the case. The department director found guilty in criminal court for being responsible for the incident was sentenced only to the loss of half of her monthly salary.

It also became clear that the response to the leak was lackadaisical, with the marketers who incorrectly received the information simply receiving a follow-up email requesting that they delete it with no follow-up. It has also been reported that IBM employees without security clearance outside of Sweden also had access to the information.

Itsik Mantin, the director of the cyber security firm Imperva, noted that, as with many network security breaches, this one was the result of lax internal protocols, not the efforts of hackers breaking into a database. Sensitive information was simply sent to a significant number of third parties who had no business having access to it.