Netskope raises another $340 million from venture capital crowd

Cloud security provider Netskope has announced a $340 million investment from a handful of venture capital firms that brings the company’s valuation to nearly $3 billion, it says. Netskope CEO Sanjay Beri said in a blog post Thursday the Santa Clara-based company had taken on funding from Sequoia Capital, as well as money from existing investors like Lightspeed Venture Partners, Accel, Sapphire Ventures and others. The company declined to share the exact valuation figure. Founded in 2012, Netskope is a cloud security firm which sells software meant to help businesses enforce data loss prevention policies, increase access controls, respond to possible security incidents and take other steps to defend themselves. The company has experienced 80% year-over-year growth among enterprise customers, Beri said in the blog, and counts 25 companies from the Fortune 100 among its clients. It’s opened 26 data centers in the past nine months to “provide a globally […]

The post Netskope raises another $340 million from venture capital crowd appeared first on CyberScoop.

Continue reading Netskope raises another $340 million from venture capital crowd

Maze ransomware spree continues amid advisories from French, FBI officials

Roughly a month after the FBI advised U.S. companies to protect themselves against a pernicious strain of ransomware, hackers have continued to attack victims and threaten to publicize their private information. A hacking group deploying Maze ransomware has used a network of websites to publicly identify organizations it claimed to hack, and which of them refused to pay a ransom. In one recent note, the group said it would release confidential data if three small law firms based in South Dakota didn’t meet their demands. While it remains unclear if the Maze group has made any information public in this case, this incident only is the latest example of scammers promising to publish data, rather than leaving it encrypted or deleting it outright. A French government cybersecurity agency on Wednesday published a Maze alert suggesting TA-2101, a hacker group which previously targeted German government agencies and U.S. tax professionals, was […]

The post Maze ransomware spree continues amid advisories from French, FBI officials appeared first on CyberScoop.

Continue reading Maze ransomware spree continues amid advisories from French, FBI officials

Joshua Schulte’s attorney suggests Vault 7 leaks were due to the CIA’s poor cybersecurity

So many people had access to the computer network used by CIA software engineers that U.S. officials still don’t know who is actually behind the leak of the agency’s hacking tools, according to the defense attorney for an accused leaker. The lawyer for Joshua Schulte, a former CIA employee on trial for allegedly providing the tools to WikiLeaks, told the jury Tuesday that the government networks their client worked on were so insecure that investigators will never know if Schulte, or some other intruder, carried out the theft. Schulte, 31, faces 11 criminal counts in connection with leaking the so-called Vault 7 files to WikiLeaks. In 2017, the controversial organization spent six months publishing documents detailing the CIA’s ability to hack into mobile operating systems, messaging apps, smart TVs and other consumer technology. Prosecutors have alleged Schulte stole the files in order to cause as much harm as possible to […]

The post Joshua Schulte’s attorney suggests Vault 7 leaks were due to the CIA’s poor cybersecurity appeared first on CyberScoop.

Continue reading Joshua Schulte’s attorney suggests Vault 7 leaks were due to the CIA’s poor cybersecurity

Yubico pushes an enterprise security plan geared toward corporate America

Yubico is trying to go corporate. The authentication company behind the YubiKey, a physical token that users rely on to access devices in a secure way, on Tuesday announced YubiEnterprise Services. It’s a subscription service meant to attract business clients and persuade them to buy batches of YubiKeys, rather than buying one at a time. It’s a big play for the company, which has been widely hailed for giving average people a way to protect their email accounts from phishing, access an array of websites with a strong second factor of authentication, and sign and decrypt protected messages without making their data vulnerable. Yubico is marketing the new service as a way for enterprise security teams to streamline product shipments, inventory management and other key-related tasks by organizing those tasks in a cloud-based Yubico platform. The company has not said whether companies will receive a discount on YubiKeys by buying them in […]

The post Yubico pushes an enterprise security plan geared toward corporate America appeared first on CyberScoop.

Continue reading Yubico pushes an enterprise security plan geared toward corporate America

As Vault 7 trial begins, Joshua Schulte’s attorneys will argue he’s a whistleblower

Nearly three years after WikiLeaks began publishing secret CIA hacking tools, the legal team for the former agency employee who allegedly stole those files will try to convince a jury he did so in order to reveal the secrets behind the tools uses by the government to break into widely used consumer technology. Based on the evidence, it’s shaping up to be a difficult argument. That’s before you consider the current environment: where the U.S. justice system has taken a hard-line approach to those who go public with classified information. While the U.S. has charged former CIA software engineer Joshua Schulte with transmitting files detailing the agency’s arsenal of hacking tools, his lawyers have given no indication that he acted out of conscience. Government prosecutors, meanwhile, will introduce evidence starting Monday that Schulte, now 31, was motivated by nothing more than revenge for what he perceived to be mistreatment by […]

The post As Vault 7 trial begins, Joshua Schulte’s attorneys will argue he’s a whistleblower appeared first on CyberScoop.

Continue reading As Vault 7 trial begins, Joshua Schulte’s attorneys will argue he’s a whistleblower

Dashlane spends big on a Super Bowl ad after $110 million fundraising round

Yes, that commercial about an average guy trying to cross the river Styx during halftime at the Super Bowl was for a cybersecurity company. Sandwiched between the first half of the game and Jennifer Lopez’s halftime performance was a minute-long ad for Dashlane, a password management company that was taking up time usually reserved for multi-billion dollar car companies or giant beer brewers. Founded in 2012, the company last year took on $110 million in a funding round led by the venture capital firm Sequoia, and added a chief marketing officer, Joy Howard, formerly of Lyft. In the spot that ran Sunday night, a Grim Reaper-like character is rowing an unlucky schlub toward heaven. But our hero is apparently doomed to eternal damnation when he can’t remember the answers to a series of security questions, demonstrating how knowledge-based authentication is frustrating and not all that secure. Flush with cash, Dashlane […]

The post Dashlane spends big on a Super Bowl ad after $110 million fundraising round appeared first on CyberScoop.

Continue reading Dashlane spends big on a Super Bowl ad after $110 million fundraising round

AIG must cover client’s $5.9 million in cyber-related losses, judge rules

Insurance giant AIG must cover nearly $6 million in losses for a client that was fleeced by an email scam carried out by suspected Chinese hackers, a federal court has decided. A judge in the Southern District of New York ruled Wednesday that AIG was in breach of contract when it previously denied a claim from SS&C Technologies, a $6 billion financial technology firm. In 2016, hackers defrauded SS&C out of $5.9 million by sending spoofed emails that appeared to be from an SS&C client, Tillage Commodities, asking SS&C employees to transfer money. After SS&C carried out the transactions, Tillage took legal action, resulting in a settlement. While AIG covered SS&C’s court dispute with Tillage, SS&C also sought filed a claim seeking to have AIG cover the stolen $5.9 million. AIG denied the claim. The insurance company had argued its policy included an exclusion stipulating that SS&C was not covered […]

The post AIG must cover client’s $5.9 million in cyber-related losses, judge rules appeared first on CyberScoop.

Continue reading AIG must cover client’s $5.9 million in cyber-related losses, judge rules

Microsoft offers up to $20,000 in Xbox bug bounty program

Microsoft is trying to make life harder for the hackers who ruin Christmas for gamers every year by knocking Xbox services offline. The company on Thursday announced a bug bounty program that offers rewards to security researchers, gamers and technologists who report vulnerabilities in Xbox’s network and services. Submissions that demonstrate a proof-of-concept are eligible for rewards of between $500 and $20,000, depending on the severity of the vulnerability. Unveiling a bug bounty program meant specifically to identify flaws in Xbox’s network and services comes after hackers have spent years working to disrupt the popular gaming system. The hacking group known as Lizard Squad, for instance, made its name in part by launching attacks on the Xbox network on Christmas Day, when gamers receive new systems, while others have made a sport out of stealing prominent user accounts. While there’s no question Xbox deals with security incidents throughout the year, […]

The post Microsoft offers up to $20,000 in Xbox bug bounty program appeared first on CyberScoop.

Continue reading Microsoft offers up to $20,000 in Xbox bug bounty program

Facebook settles facial recognition lawsuit for $550 million

Facebook will pay $550 million to settle a class action lawsuit in which users accused the social media giant of using facial recognition software in a way customers hadn’t authorized, marking a win for U.S. privacy advocates who have used state laws to curb data collection. The settlement ends a suit in which customers alleged Facebook’s “Tag Suggestions” service, which recommends the names of people users can tag on their photos. The case accuses Facebook of breaking privacy law in Illinois by mining information about people in Illinois without their consent, then failing to disclose how long that data would be stored. Facebook has refuted allegations of wrongdoing in this case. The company disclosed the settlement Wednesday during its quarterly financial report, in which executives reported that revenue had risen 25% to $21.1 billion in the fourth quarter of 2019. Of the $550 million, individuals attached to the lawsuit can […]

The post Facebook settles facial recognition lawsuit for $550 million appeared first on CyberScoop.

Continue reading Facebook settles facial recognition lawsuit for $550 million

Zoom squashed a bug that left private meetings unprotected

Corporate conferencing software provider Zoom patched a security flaw that could have enabled hackers to spy on private meetings, the company says. Check Point Software Technologies, the Israel-based security vendor, said Tuesday it uncovered the security vulnerability last year and alerted Zoom, which fixed the issue in an August software update. Attackers could have exploited the bug by creating a list of nine, 10 or 11-digit meeting identification numbers, then enter any meeting in those sessions that wasn’t protected by a password. If a user had failed to require a password to their conference, the meeting ID number would have been the only thing safeguarding the conversation from eavesdroppers, Check Point said. In response, Zoom updated its policies to add password to all scheduled meetings by default, make it more difficult for attackers to view meetings they might try to infiltrate and block devices that repeatedly scan for meeting IDs. […]

The post Zoom squashed a bug that left private meetings unprotected appeared first on CyberScoop.

Continue reading Zoom squashed a bug that left private meetings unprotected