Ex-Cylance and Carbon Black execs launch Obsidian Security with $9.5 million investment

Founded by executives from two of the highest-profile endpoint security firms in the U.S., Obsidian Security just announced a $9.5 million Series A round of investment from the Silicon Valley venture capital firm Greylock Partners. Obsidian, headquartered in Newport Beach, Calif., was founded by CEO Glenn Chishold, the former CTO at Cylance; CTO Matt Wolff, former Chief Data Scientist at Cylance and computer scientist at the NSA; and Chief Data Scientist Ben Johnson, former co-founder and CTO at Carbon Black and also a computer scientist at the NSA. The company will focus on cloud and data center security, putting them in competition with companies like Cisco, VMWare and Illumio.  Earlier this week, Illumio announced $125 million in an investment round. Cylance, which has been valued by investors at over $1 billion, was the focus of controversy earlier this year when an Ars Technica investigation suggested the company’s testing demos included false positives. The company denied any wrongdoing. Details […]

The post Ex-Cylance and Carbon Black execs launch Obsidian Security with $9.5 million investment appeared first on Cyberscoop.

Continue reading Ex-Cylance and Carbon Black execs launch Obsidian Security with $9.5 million investment

YubiKey’s maker lands $30 million investment

The cybersecurity hardware company Yubico announced Wednesday a $30 million investment from a mix of European and North American firms including the California-based Valley Fund and the Swedish equity firm Bure. Yubico, which reports over 100,000 customers including Google and Facebook, builds and sells YubiKey, a small, anti-phishing authentication key that tech giants and individual security experts have added to their defenses. The money will be put toward developing new products, the company said in a statement. In an age when phishing is the most-high profile and successful cyberattack vector, physical devices like YubiKey provide the most secure multifactor authentication. “We’ve been traditionally getting individual orders in the hundreds for agencies, divisions, small groups over the past years,” Jerrod Chong, the company’s Vice President of Solutions, told CyberScoop late last year. “This year we are seeing orders in the tens of thousands. It’s a sizable magnitude.” Founded in 2007, Yubico is half-owned by […]

The post YubiKey’s maker lands $30 million investment appeared first on Cyberscoop.

Continue reading YubiKey’s maker lands $30 million investment

Illumio gets $125 million in Series D round, targets federal market

Cybersecurity startup Illumio announced Wednesday a $125 million Series D round investment led by J.P. Morgan Chase, bringing total investment in the Silicon Valley firm to $267 million since 2014. The new round marks the entrance of Wall Street investors after years of investment from some of Silicon Valley’s most prominent venture capitalists. The data center and cloud security company has begun to hire a team dedicated to federal sales including Eric Teasdale, the company’s federal sales director , who joined in April. Teasdale, who is “actively negotiating” on several projects, arrived from federal sales positions at Salesforce and Apptio. The Trump administration’s federal IT budget asks for $95.7 billion in 2018, a billion dollar increase, although most federal agencies would see their budget stay flat or decrease. Illumio intends in particular to target defense and intelligence agencies first, typically early adopters when it comes to major government tech endeavors, Cohen said. The dedicated […]

The post Illumio gets $125 million in Series D round, targets federal market appeared first on Cyberscoop.

Continue reading Illumio gets $125 million in Series D round, targets federal market

Illumio gets $125 million in Series D round, targets federal market

Cybersecurity startup Illumio announced Wednesday a $125 million Series D round investment led by J.P. Morgan Chase, bringing total investment in the Silicon Valley firm to $267 million since 2014. The new round marks the entrance of Wall Street investors after years of investment from some of Silicon Valley’s most prominent venture capitalists. The data center and cloud security company has begun to hire a team dedicated to federal sales including Eric Teasdale, the company’s federal sales director , who joined in April. Teasdale, who is “actively negotiating” on several projects, arrived from federal sales positions at Salesforce and Apptio. The Trump administration’s federal IT budget asks for $95.7 billion in 2018, a billion dollar increase, although most federal agencies would see their budget stay flat or decrease. Illumio intends in particular to target defense and intelligence agencies first, typically early adopters when it comes to major government tech endeavors, Cohen said. The dedicated […]

The post Illumio gets $125 million in Series D round, targets federal market appeared first on Cyberscoop.

Continue reading Illumio gets $125 million in Series D round, targets federal market

Federal report: Hospital cybersecurity is in ‘critical condition’

Many American hospitals and health care practices are critically vulnerable to cyberattack and lack the resources to protect against rising threats, according to a long-awaited report issued by the U.S. Department of Health and Human Service’s Health Care Industry Cybersecurity Task Force. The starkly negative report points to problems beyond hardware and software. The task force, established a year go, is made up of 21 security experts, health care professionals and government officials. “Many organizations cannot afford to retain in-house information security personnel, or designate an information technology (IT) staff member with cybersecurity as a collateral duty,” the task force reported. “These organizations often lack the infrastructure to identify and track threats, the capacity to analyze and translate the threat data they receive into actionable information, and the capability to act on that information.” The talent shortage that hampers cybersecurity in all sectors hits health care especially hard so that the industry leans especially hard on part-time positions or […]

The post Federal report: Hospital cybersecurity is in ‘critical condition’ appeared first on Cyberscoop.

Continue reading Federal report: Hospital cybersecurity is in ‘critical condition’

WikiLeaks releases new round of CIA malware documents, this time with less supporting material

WikiLeaks released a new set of CIA cyberwarfare documents on Thursday, marking the 10th installation in the two-month-old Vault 7 series. This publication focuses on Pandemic, a CIA project that infects networks of Windows machines through the Server Message Block (SMB) file sharing protocol with trojanized versions of software that can mean complete compromise of targeted devices. The documents date from April 2014 to January 2015. The latest release contains less contextual data and documents than most previous Vault 7 publications, prompting questions from experts about the exact operation of the Pandemic malware. For example: How does get into the Windows kernel in order to replace normal files with spyware? And why is this document dump seemingly less complete than others? “Why it’s missing is anyone’s guess,” Williams said. “But you don’t see the operator manual, etc. Everything else, with the exception of MARBLE (which is a library) has a user guide. This does […]

The post WikiLeaks releases new round of CIA malware documents, this time with less supporting material appeared first on Cyberscoop.

Continue reading WikiLeaks releases new round of CIA malware documents, this time with less supporting material

Password manager OneLogin hacked, attackers could ‘decrypt encrypted data’

OneLogin has been hacked, according to the cloud-based password manager and identity management company. The hackers could “decrypt encrypted data,” the company explained on a customer-only support page that was shared publicly. “Today we detected unauthorized access to OneLogin data in our US data region,” the company’s chief security officer Alvaro Hoyos said in a statement on Wednesday night. “We have since blocked this unauthorized access, reported the matter to law enforcement, and are working with an independent security firm to determine how the unauthorized access happened and verify the extent of the impact of this incident.” The San Francisco company posted a short blog post and sent an equally concise email to customers including 2,000 companies in 44 countries. OneLogin serves numerous financial, medical, tech and industrial clients. OneLogin has not yet made clear which of its customers are served by the compromised U.S. data center but is advising all customers to […]

The post Password manager OneLogin hacked, attackers could ‘decrypt encrypted data’ appeared first on Cyberscoop.

Continue reading Password manager OneLogin hacked, attackers could ‘decrypt encrypted data’

Booz Allen Hamilton leaves 60,000 unsecured DOD files on AWS server

Leading U.S. military contractor Booz Allen Hamilton has been found to have left over 60,000 sensitive files on a publicly accessible Amazon Web Services server, according to a leading cybersecurity researcher. The files were discovered by Chris Vickery, an analyst at the cybersecurity firm UpGuard, who told CyberScoop it’s “highly likely” that malicious actors are downloading this publicly exposed data but said it remains unclear if anyone realized and acted on the gravity of the exposed data. On May 26, four days after the discovery was first made, the U.S. government requested UpGuard preserve the data they discovered during their investigation. UpGuard is not naming the specific agency they spoke with in compliance with their request. The data leakage was first reported by Gizmodo on Wednesday. The revelation came just hours after a company spokesperson said the former FBI director Robert Mueller’s review of Booz Allen Hamilton security, personnel and management practices is “substantially complete.” The final report […]

The post Booz Allen Hamilton leaves 60,000 unsecured DOD files on AWS server appeared first on Cyberscoop.

Continue reading Booz Allen Hamilton leaves 60,000 unsecured DOD files on AWS server

PhishLabs investigating claims of a possible customer data dump

Cybersecurity startup PhishLabs has launched an investigation into a possible data breach, the company confirmed to CyberScoop on Wednesday. Earlier this week, a note posted on Pastebin announced the sale of a data dump and email from Joseph Opacki, the vice president of threat intelligence for the Charleston, South Carolina-based PhishLabs. The company, founded in 2008, sells anti-phishing defense and training to clients aimed at protecting employees and customers. The original post was taken down within hours, and the Pastebin user hasn’t responded to CyberScoop’s inquiries. The Pastebin page contained what looked to be a PhishLabs client list, showing 132 customers including tech giants like Apple and dozens of financial institutions. PhishLabs would not confirm or deny the validity of the list. “We’ve gotten quite a few questions about it from clients,” said Stacy Shelley, PhishLabs vice president of marketing. “At this point in the investigation, we haven’t found any evidence that any […]

The post PhishLabs investigating claims of a possible customer data dump appeared first on Cyberscoop.

Continue reading PhishLabs investigating claims of a possible customer data dump

New battle in ‘Crypto Wars’ heating up in wake of Manchester attack

Another round of encryption policy debate, spurred on by the investigation into “a network” of terrorists in Monday night’s bombing in Manchester, is underway with European leaders threatening to pass further laws that would allow governments increased access to data regardless of the security that sits on devices. A Tuesday report from The Sun alleges the U.K. government will push through increased backdoor powers immediately after the upcoming June 8 election. The reported new powers, which will impact companies with over 10,000 customers, have been in the making for over a month. “We will do this as soon as we can after the election, as long as we get back in,” one government minister reportedly told The Sun. “The level of threat clearly proves there is no more time to waste now. The social media companies have been laughing in our faces for too long.” The latest European flare up in the encryption debate […]

The post New battle in ‘Crypto Wars’ heating up in wake of Manchester attack appeared first on Cyberscoop.

Continue reading New battle in ‘Crypto Wars’ heating up in wake of Manchester attack