DHS confirms data breach affecting more than 240,000 current and former employees

The Department of Homeland Security has notified more than 240,000 current and former employees of a data breach that was discovered as part of a criminal investigation into the actions of a former staff member of the Office of the Inspector General. In a letter sent to affected employees on Wednesday, DHS says an unauthorized copy of its investigative case management system was found in the possession of a former DHS OIG employee. The department says the data included information on “approximately 247,167 current and former federal employees that were employed by DHS in 2014.” The agency says the breach, which it categorizes as a “privacy incident,” did not stem from an external cyberattack. The exposed data also included information on “subjects, witnesses, and complainants associated with DHS OIG investigations from 2002 through 2014.” The breached data was not exposed to malicious activity, DHS said. Despite learning about the breach in May, DHS […]

The post DHS confirms data breach affecting more than 240,000 current and former employees appeared first on Cyberscoop.

Continue reading DHS confirms data breach affecting more than 240,000 current and former employees

Thales acquires chip giant Gemalto in $5.6B all-cash deal

French technology giant Thales SA will acquire digital security company Gemalto after outbidding a rival French company whose bid was rejected. Thales will acquire Gemalto — the world’s largest manufacturer of SIM cards and credit card chips — in an all-cash transaction worth €4.76 billion ($5.6 billion), beating an offer from rival Atos that was valued at €4.3 billion ($5.06 billion). Gemalto said Atos’ bid significantly had undervalued the company. Known more for its work in aerospace, Thales has spent the past three years focusing on cybersecurity and artificial intelligence. As part of that effort, the company has acquired a host of others, including Sysgo, Vormetric and Guavus. “The acquisition of Gemalto marks a key milestone in the implementation of Thales’s strategy,” Patrice Caine, Thales’s chairman and chief executive officer, said in a release. “Together with Gemalto’s management, we have big ambitions based on a shared vision of the digital transformation of our industries […]

The post Thales acquires chip giant Gemalto in $5.6B all-cash deal appeared first on Cyberscoop.

Continue reading Thales acquires chip giant Gemalto in $5.6B all-cash deal

Menlo Security raises $40 million in Series C round

California-based startup Menlo Security announced a $40 million Series C funding round on Monday, with money coming in from American Express Ventures, Ericsson Ventures and HSBC. Menlo’s business has grown on the back of its malware isolation platform, which operates between endpoints and the broader internet, giving enterprises a way to curb malware and phishing attempts without disrupting users’ web, email and document traffic. The new investors join a bevy of existing ones, including JPMorgan Chase, General Catalyst, Sutter Hill Ventures, Osage University Partners and Engineering Capital. “More than a million users at hundreds of companies are protected by Menlo, with zero infections to date,” said Amir Ben Efraim, CEO of Menlo Security. “This funding allows us to respond to this opportunity by continuing to expand our deployments globally to meet this growing demand, while delivering on our vision of eliminating the phishing, ransomware and malware risks from email, web and document downloads.” […]

The post Menlo Security raises $40 million in Series C round appeared first on Cyberscoop.

Continue reading Menlo Security raises $40 million in Series C round

Steven Hernandez named new Department of Education CISO

The Department Education has hired government IT veteran Steven Hernandez as its new chief information security officer. Hernandez comes to the position from the Department of Health of Human Services’ Office of Inspector General, where he served as CISO since 2010. Hernandez will be responsible for maintaining the integrity and privacy of the department, as well as “the coordination and integration of all aspects of the Department’s cyber, telecommunications, and information security programs,” according to a job listing posted in June. Additionally, the CISO will help department CIO Jason Gray with “preparing budget justifications and ensuring compliance to federal statues and directives governing management of enterprise-wide security operations, Risk Management, mitigation of security vulnerabilities and improvement of the Department’s IT security posture.” “I’m excited to have a cybersecurity leader with Steven’s knowledge, skills, abilities, and experiences join our leadership team” Gray told CyberScoop. “I look forward to Steven joining [the […]

The post Steven Hernandez named new Department of Education CISO appeared first on Cyberscoop.

Continue reading Steven Hernandez named new Department of Education CISO

Pepsi denies claim that it hacked Russian government watchdog

PepsiCo has denied a claim from an agricultural watchdog in Russia that the multinational food and beverage giant hacked into its computer networks in order to steal an internal document. The strange claim was made public Monday when Russia’s Rosselkhoznadzor issued a public statement stating the American-based company uses “illegal methods of obtaining information from government agencies.” Specifically, the agency says the company obtained a document that is stamped “for official use.” “PepsiCo refutes the accusations made today by Rosselkhoznadzor,” Sergey Glushkov, VP of corporate affairs for PepsiCo’s Eastern Europe division, told CyberScoop. “We strictly comply with rules in Russia and all the countries in which we operate.” The bizarre claim comes as Rosselkhoznadzor and PepsiCo have butted heads in recent weeks. Late last month, the agency claimed to find an excess level of antibiotics in a brand of cheese produced by a company belonging to Pepsi. The agency then restricted […]

The post Pepsi denies claim that it hacked Russian government watchdog appeared first on Cyberscoop.

Continue reading Pepsi denies claim that it hacked Russian government watchdog

Pepsi denies claim that it hacked Russian government watchdog

PepsiCo has denied a claim from an agricultural watchdog in Russia that the multinational food and beverage giant hacked into its computer networks in order to steal an internal document. The strange claim was made public Monday when Russia’s Rosselkhoznadzor issued a public statement stating the American-based company uses “illegal methods of obtaining information from government agencies.” Specifically, the agency says the company obtained a document that is stamped “for official use.” “PepsiCo refutes the accusations made today by Rosselkhoznadzor,” Sergey Glushkov, VP of corporate affairs for PepsiCo’s Eastern Europe division, told CyberScoop. “We strictly comply with rules in Russia and all the countries in which we operate.” The bizarre claim comes as Rosselkhoznadzor and PepsiCo have butted heads in recent weeks. Late last month, the agency claimed to find an excess level of antibiotics in a brand of cheese produced by a company belonging to Pepsi. The agency then restricted […]

The post Pepsi denies claim that it hacked Russian government watchdog appeared first on Cyberscoop.

Continue reading Pepsi denies claim that it hacked Russian government watchdog

Bitdefender valued at $600M after private equity company buys significant minority stake

A European-based private equity company announced Friday it has taken a significant minority stake in Romanian cybersecurity company Bitdefender, valuing the company at more than $600 million. Vitruvian Partners, a London-based private equity firm, acquired approximately 30 percent of Bitdefender from existing shareholder Axxess Capital. Vitruvian becomes the second-largest shareholder with co-founders Mariuca and Florin Talpes continuing to hold the majority stake. The investment comes as the company has been growing, particularly in the United States. Bitdefender says more than 40 percent of sales are currently generated in the U.S., primarily from corporate customers. Bitdefender claims it has over 500 million users worldwide, putting in the ranks with other large anti-virus companies like Kaspersky Lab, McAfee and Symantec. “Vitruvian’s extensive experience investing in high growth technology companies endorses our strategy for international growth and in particular the significant investment we are making in building our Enterprise Solutions offering and our […]

The post Bitdefender valued at $600M after private equity company buys significant minority stake appeared first on Cyberscoop.

Continue reading Bitdefender valued at $600M after private equity company buys significant minority stake

Serious flaw in Apple’s MacOS allows any user to gain full root access

A new flaw discovered in Apple’s MacOS gives users a remarkably easy way to gain root access on machines. The bug, discovered Tuesday, allows people to bypass administrative accounts when trying to access various system preferences, such as network or privacy settings. When prompted to enter administrator credentials, a user can enter the username “root,” leave the password blank, and be granted access to the locked menus. The bug only activates after users attempt to sign in via the “root” name multiple times. Lemi Orhan Emrin, a Turkish software engineer, first announced the bug in a tweet on Tuesday. You can access it via System Preferences>Users & Groups>Click the lock to make changes. Then use “root” with no password. And try it for several times. Result is unbelievable! pic.twitter.com/m11qrEvECs — Lemi Orhan Ergin (@lemiorhan) November 28, 2017 CyberScoop editors reproduced the bug multiple times on their machines. Multiple security researchers […]

The post Serious flaw in Apple’s MacOS allows any user to gain full root access appeared first on Cyberscoop.

Continue reading Serious flaw in Apple’s MacOS allows any user to gain full root access

Barracuda taken private as part of $1.6B acquisition

Cloud-based network security company Barracuda Networks will return to being a private company, announcing a buyout by private equity investment firm Thoma Bravo, LLC in an all-cash transaction valued at $1.6 billion. Founded in 2003, Barracuda Networks offers cloud-based network security, email security, web application firewalls and more. The company went public in 2013 with a stock price of $18 per share, hitting a high of $45.12 per share in 2015. After dipping to $10 per share in 2016, the price has floated between $21 and $24 since the start of the year. “We believe the proposed transaction offers an opportunity for us to accelerate our growth with our industry-leading security platform that’s purpose-built for highly distributed, diverse cloud and hybrid environments,” said B.J. Jenkins, chief executive officer of Barracuda, in a release. “We will continue Barracuda’s tradition of delivering easy-to-use, full-featured solutions that can be deployed in the way […]

The post Barracuda taken private as part of $1.6B acquisition appeared first on Cyberscoop.

Continue reading Barracuda taken private as part of $1.6B acquisition

FBI charges man in massive data theft from HBO

The FBI charged a man with allegedly stealing a trove of data from HBO earlier this year containing personal financial information and passwords belonging to company employees, as well as unreleased television scripts and episodes. In a complaint released Tuesday, the Department of Justice contends that Behzad Mesri, an Iranian national, compromised accounts tied to HBO employees in order to steal confidential and proprietary data belonging to the premium cable network. The document says Mesri was part of a hacking group called Turk Black Hat Security. According to the complaint, among the confidential files taken were “unaired episodes of original HBO television programs, including episodes of ‘Ballers,’ ‘Barry,’ ‘Room 104,’ ‘Curb Your Enthusiasm,’ and ‘The Deuce;’ scripts and plot summaries for unaired programming, including but not limited to episodes of ‘Game of Thrones;’ confidential cast and crew contact lists; e-mails belonging to at least one HBO employee; financial documents; and […]

The post FBI charges man in massive data theft from HBO appeared first on Cyberscoop.

Continue reading FBI charges man in massive data theft from HBO