Apple, Cisco team up with cyber insurers for policy discounts

Apple and Cisco will be partnering with two insurance firms to give organizations discounts on cyber insurance policies when they use equipment from both technology companies. The two tech giants, along with Allianz SE and Aon Plc, will give companies a full suite of options for managing their cyber risk. Participants will receive cheaper insurance policies through Allianz if they use Apple’s iPhone, iPad, and Mac along with Cisco’s ransomware defense products. Enterprises also will able to undergo a “cyber resilience evaluation,” courtesy of Aon, that will assess security postures and recommend ways to improve defenses. In the event of an attack, companies will have access to Cisco and Aon’s Incident Response teams. “Organizations urgently need to be managing these risks from both the technical and the financial perspective,” said Aon Cyber Solutions CEO Jason Hogg in a statement.  “We can provide customers with guidance on what cyber defenses, resources and processes to […]

The post Apple, Cisco team up with cyber insurers for policy discounts appeared first on Cyberscoop.

Continue reading Apple, Cisco team up with cyber insurers for policy discounts

BigID raises $14 million in Series A for data protection compliance product

Whether it’s looming regulations or lapses in operational security, companies face growing pressure to adhere to data privacy rules more stringently than ever before. A startup, flush with new funding, thinks it can help. New York-based BigID announced a $14 million Series A funding round Monday, with investment coming from ClearSky Security, Comcast Ventures and the SAP.iO Fund, among others. BigID launched its product last year to help organizations address various data protection requirements that were set to be enacted, including China’s Cybersecurity Law and the European Union’s General Data Protection Regulation (GDPR). China’s law went into effect in December, while GDPR will go into effect in May. “On the eve of GDPR and in the midst of endless mega breaches, we’re in a new era of personal data rights,” said Jay Leek, ClearSky Security Managing Director and former Blackstone CISO who is now on BigID’s board of directors.  “Individuals now have […]

The post BigID raises $14 million in Series A for data protection compliance product appeared first on Cyberscoop.

Continue reading BigID raises $14 million in Series A for data protection compliance product

Malwarebytes updates lead to a weekend full of crashing computers

It was a rough weekend for California-based Malwarebytes after the anti-virus company had to push several updates to its Endpoint Security products in order to combat an issue that crashed machines due to high RAM usage. Soon after the company pushed an update to its Endpoint Security products, users flooded forums complaining that the product was using as much as 90 percent of their machine’s memory or CPU. The company pushed an update about an hour after the problems first surfaced, but that update caused users’ machines to crash upon a reboot. Please note that we are aware of the current update issues and the complete Malwarebytes team is all hands on deck to fix this ASAP. Thank you for your patience and understanding. https://t.co/TLtSG1TIQv — Malwarebytes (@Malwarebytes) January 27, 2018 A second update, pushed later Saturday, seemed to fix the issue. However, the company has offered help in case […]

The post Malwarebytes updates lead to a weekend full of crashing computers appeared first on Cyberscoop.

Continue reading Malwarebytes updates lead to a weekend full of crashing computers

Congress wants answers on embargo of Spectre and Meltdown information

Lawmakers on the House Committee on Energy and Commerce have sent letters to various CEOs at top tech companies asking why information about massive computer chip vulnerabilities was held under embargo for months. The letters focus on the Spectre and Meltdown bugs, deep-rooted flaws in chips produced by leading computer hardware companies that could allow hackers to access steal sensitive data from machines created as far back as 1995. Co-authored by panel Chairman Greg Walden, R-Ore., and members Marsha Blackburn, R-Tenn., Bob Latta, R-Ohio, and Gregg Harper, R-Miss., the letters request answers about why the bugs weren’t disclosed when the companies learned about them in June 2017. The committee has jurisdiction over technology issues. Information about the flaws was supposed to go public in late January, but security researchers tweeted proof-of-concept code before the companies were ready to make announcements. That tweet lead to wider public scrutiny, forcing the companies involved to […]

The post Congress wants answers on embargo of Spectre and Meltdown information appeared first on Cyberscoop.

Continue reading Congress wants answers on embargo of Spectre and Meltdown information

AWS acquires threat hunting startup Sqrrl

Amazon Web Services announced Tuesday it acquired Cambridge, Massachusetts, threat hunting company Sqrrl. Terms were not disclosed. Sqrrl CEO Mark Terenzoni wrote on the company’s website that he and his co-workers were “thrilled.” “For now, it is business as usual at Sqrrl. We will continue to work with customers to provide advanced threat hunting capabilities,” Terenzoni said. “And, over time, we’ll work with AWS to do even more on your behalf. Thank you for your support. We really appreciate the trust customers have put into Sqrrl over the past five years, and we are excited about the next phase of our journey.” The deal, which has been rumored for weeks, comes as the cloud computing behemoth continues to boost its secure offerings. In November, AWS announced its Secret Region, which can handle data up to the Secret level of security classification — the second-highest level behind only Top Secret. The […]

The post AWS acquires threat hunting startup Sqrrl appeared first on Cyberscoop.

Continue reading AWS acquires threat hunting startup Sqrrl

Data protection startup Baffle raises $6 million in Series A

California-based Baffle, which sells a product that enables secure computing for cloud applications, has raised $6 million in a Series A funding round. The funding was led by Envision Ventures, with participation from ServiceNow Ventures, Thomvest Ventures and Industry Ventures. The company’s BaffleManager service integrates at the SQL layer on servers in order to constrain how applications access sensitive data. Adding this protection to cloud instances helps limit the damage enterprises would face due to a breach. Even if attackers leverage other vulnerabilities elsewhere in the stack, data protected by Baffle would be encrypted and thus useless once extracted. “As enterprises accelerate their migration of critical applications to the cloud, the biggest pain-point identified by Chief Security Officers is protection of their sensitive data. Baffle provides an innovative and comprehensive data security solution to address this enterprise need,” said Umesh Padval, Partner at Thomvest Ventures who focuses on cybersecurity investments. Current Baffle […]

The post Data protection startup Baffle raises $6 million in Series A appeared first on Cyberscoop.

Continue reading Data protection startup Baffle raises $6 million in Series A

Nozomi Networks raises $15 million for expansion of its industrial cybersecurity offerings

Industrial cybersecurity firm Nozomi Networks announced a $15 million Series B funding round Wednesday, positioning itself to be a bigger player in the growing field of companies focused on protecting industrial control systems (ICS). The Invenergy Future Fund led the round, with participation from THI Investments and all existing investors: GGV Capital, Lux Capital and Planven Investments SA. The latest round brings Nozomi Networks’ total funding to date to $23.8 million. Since being founded in 2013, the company has built products focused on machine learning and artificial intelligence that secure companies operating and maintaining critical infrastructure. The San Francisco-based company’s two products, SCADAGuardian and Central Management Console, provide users with a wide array of security options that can be deployed across multiple levels of ICS infrastructure, including supervisory control and data acquisition (SCADA) systems. Nozomi claims it has more than 200 customers across five continents, including companies that deal with energy, […]

The post Nozomi Networks raises $15 million for expansion of its industrial cybersecurity offerings appeared first on Cyberscoop.

Continue reading Nozomi Networks raises $15 million for expansion of its industrial cybersecurity offerings

Alliance aims to thwart nosy Wi-Fi spies with new security standards

A new security protocol for Wi-Fi will be launched before the end of the year, according the industry body responsible for the standard. The protocol, known as WPA3, will deliver a suite of features to simplify Wi-Fi security configuration for users and service providers, according the Wi-Fi alliance. The group, a global network of hundreds of companies within the Wi-Fi ecosystem, has set standards and certified 35,000 devices since being launched in 2000. The standard will include better password protection, simplifying security configurations for devices that have limited or no display interface. Additionally, the standard will strengthen user privacy in open networks through individualized data encryption, which would prevent people from spying on network traffic on open networks. “Wi-Fi security technologies may live for decades, so it’s important they are continually updated to ensure they meet the needs of the Wi-Fi industry,” said Joe Hoffman, SAR Insight & Consulting, in […]

The post Alliance aims to thwart nosy Wi-Fi spies with new security standards appeared first on Cyberscoop.

Continue reading Alliance aims to thwart nosy Wi-Fi spies with new security standards

Verizon acquires startup Niddel and its automated threat hunting platform

Verizon acquired automated threat hunting startup Niddel, according to a company release issued Friday. The price of the acquisition was not disclosed. Founded in 2014, Niddel offers a platform called Magnet that relies on machine learning, removing the need for human analysts to write code or process data in order to stop threats. Founded by three computer scientists with Brazilian backgrounds, the company was awarded a U.S. patent for “Systems and methods for classifying malicious network events” in 2016. “Verizon is the perfect partner to accelerate our long-term vision of delivering automation and intelligence solutions through machine learning to more organizations throughout the world,” said Niddel CEO Felipe Boucas. “Using machine learning to improve information accuracy significantly reduces false positives and significantly improves our detection and response capabilities,” said Alexander Schlager, Verizon’s executive director for security services, in a release. Verizon has long offered a wide array of cybersecurity services, […]

The post Verizon acquires startup Niddel and its automated threat hunting platform appeared first on Cyberscoop.

Continue reading Verizon acquires startup Niddel and its automated threat hunting platform

DHS confirms data breach affecting more than 240,000 current and former employees

The Department of Homeland Security has notified more than 240,000 current and former employees of a data breach that was discovered as part of a criminal investigation into the actions of a former staff member of the Office of the Inspector General. In a letter sent to affected employees on Wednesday, DHS says an unauthorized copy of its investigative case management system was found in the possession of a former DHS OIG employee. The department says the data included information on “approximately 247,167 current and former federal employees that were employed by DHS in 2014.” The agency says the breach, which it categorizes as a “privacy incident,” did not stem from an external cyberattack. The exposed data also included information on “subjects, witnesses, and complainants associated with DHS OIG investigations from 2002 through 2014.” The breached data was not exposed to malicious activity, DHS said. Despite learning about the breach in May, DHS […]

The post DHS confirms data breach affecting more than 240,000 current and former employees appeared first on Cyberscoop.

Continue reading DHS confirms data breach affecting more than 240,000 current and former employees