Cylance offers consumer anti-virus product for free until November election

Cybersecurity company Cylance announced on Thursday that it’s making its consumer anti-virus product free until the November election in order to help political organizations protect sensitive data. While the company is primarily positioning the move as a way to protect political campaigns from cyberthreats, the free offer of Cylance Smart Antivirus applies all U.S. residents. The Irvine, California, company joins a number of  others  that have made some programs or services free for the sake of election security. Some offers have focused on state and local election systems, while others are marketed toward candidates and campaigns. People can sign up for Cylance’s offer between now and Nov. 9 — the week of Election Day — and the free service will expire on November 30. The product uses artificial intelligence to monitor a user’s system and detect and block malware. The election security offer covers three devices for free. That’s likely not enough to protect an entire political organization, but […]

The post Cylance offers consumer anti-virus product for free until November election appeared first on Cyberscoop.

Continue reading Cylance offers consumer anti-virus product for free until November election

Twistlock raises $33 million to secure cloud native environments

Twistlock, a startup that provides a security platform for cloud native and containerized applications, announced on Wednesday that it raised $33 million in Series C funding. The company’s container security platform is meant to help customers with things like managing vulnerabilities, setting up firewalls and complying with industry standards and best practices. Twistlock says this is becoming important as enterprises increasingly take up cloud native, containerized and serverless systems. The advantage of such technologies is their portability and the ability to deploy them into different computing environments, but they have also been exploited for recent security lapses. In February, Tesla fell victim to a cryptojacking scheme resulting from an unprotected Kubernetes console. In June, files posted to Docker Hub allowed hackers to conduct cryptojacking on the servers of victims who unknowingly downloaded them. Based in Portland, Oregon, Twistlock presents itself as a catch-all platform to secure cloud native systems. “The […]

The post Twistlock raises $33 million to secure cloud native environments appeared first on Cyberscoop.

Continue reading Twistlock raises $33 million to secure cloud native environments

McAfee offers state election officials a year of free cloud security tools

McAfee is offering free security services to election offices in all 50 states, the company announced on Wednesday, in order to protect voter data stored in the cloud. The offering comes by way of Skyhigh Networks, a cloud security startup that McAfee acquired last year. The product, McAfee Skyhigh Security Cloud, provides monitoring and threat detection tools for cloud software-as-a-service products (such as Microsoft Office 365, Box, Amazon Web Services and others), which are widely used by enterprises including state election offices. McAfee is giving officials a free 12-month license of the product. Since states and localities run federal elections in the U.S., officials are scrambling to make sure that their systems are secure ahead of the November general election. Observers fear that things like voter registration systems, election reporting websites and other sensitive aspects of election infrastructure could be targets. “We believe the McAfee Cloud for Secure Elections Program will […]

The post McAfee offers state election officials a year of free cloud security tools appeared first on Cyberscoop.

Continue reading McAfee offers state election officials a year of free cloud security tools

Exabeam rakes in $50 million investment for SIEM platform

Exabeam, a company that provides a platform for monitoring network data for threats, announced $50 million in a Series D funding round on Tuesday. The round brings its total investment funding to $115 million. The company offers a security information and event management (SIEM) platform. SIEM products essentially aggregate security-related events — such as log-ins and malware activity — from across a network’s infrastructure and analyzes the collected data to inform network administrators and present possible counteraction. Exabeam’s says its product, called the Security Intelligence Platform, uses machine learning for comprehensive threat detection and is scalable to meet a customer’s specific network needs. It says the platform can secure various aspects of an enterprise, including cloud services, machines and internet-of-things devices. As network infrastructures grow more complex, the amount of data that a SIEM can log is skyrocketing, Exabeam says, which is making the use of SIEM products that price […]

The post Exabeam rakes in $50 million investment for SIEM platform appeared first on Cyberscoop.

Continue reading Exabeam rakes in $50 million investment for SIEM platform

Report: ‘Faxploit’ hack can penetrate networks with just a fax number

Fax machines, very much still a thing, can be used as an entry point into an enterprise’s IT network, according to new research from Israeli cybersecurity company Check Point. In a report released Monday, Check Point details an exploit whereby an attacker can infiltrate using only a fax number associated with a machine on a target network. Attacks can then move across a network, even if it’s not connected to the internet, according to the report. As demonstrated by Check Point in the video below, the hacker can execute script that targets the victim’s fax number in order to obtain network access. The attacker can then use EternalBlue, a NSA-developed exploit leaked by the Shadow Brokers hacker group, to further infiltrate the network and execute malware. In Check Point’s video, the hacker uses malware to locate a file on the victim network and send it back to the hacker’s fax […]

The post Report: ‘Faxploit’ hack can penetrate networks with just a fax number appeared first on Cyberscoop.

Continue reading Report: ‘Faxploit’ hack can penetrate networks with just a fax number

Flagship election security bill gets a companion in the House

A bipartisan group of House lawmakers introduced a bill Friday that aims to assist state governments in their election security efforts and boost cooperation between the federal and state officials on the issue. The bill shares the name of a companion bill in the Senate, the Secure Elections Act, which senators from both major parties have been pushing along for months. The House version was introduced by four members of the Intelligence Committee: Trey Gowdy, R-S.C.; Tom Rooney, R-Fla.; Jim Himes , D-Conn. and Terri Sewell, D-Ala. Like its Senate counterpart, the House bill would allow state and local election offices to apply for federal grants to replace paperless, electronic voting machines. Security experts and election integrity advocates say these machines are vulnerable targets to hacking because they don’t leave a paper trail that can be used to verify each vote. The bill also would facilitate the process whereby the […]

The post Flagship election security bill gets a companion in the House appeared first on Cyberscoop.

Continue reading Flagship election security bill gets a companion in the House

Capsule8 raises $15 million for automated threat detection platform

Capsule8, a cybersecurity startup that says it provides a scalable threat detection product for complex cloud environments, announced on Wednesday that it raised $15 million in its Series B funding round. Based in New York, Capsule8 says the platform is “purpose-built for production” — meaning the environment where end users actually interact with a program or software. The company claims the platform can detect zero-day attacks and other threats while scaling and adapting to environments of different sizes. “Capsule8 is driving a new automated approach to attack detection and response that will, over time, help organizations arrive at the SOCless enterprise,” one that doesn’t require human intervention to detect threats, the company said in a press release. The company says it deploys its sensors throughout a customer’s network infrastructure, including cloud instances and data centers, to detect and stop attacks in real-time. “The landscape of enterprise production environments continues to change […]

The post Capsule8 raises $15 million for automated threat detection platform appeared first on Cyberscoop.

Continue reading Capsule8 raises $15 million for automated threat detection platform

Ready-to-use bitcoin ATM malware found for sale online

Hackers are selling malware that can purportedly steal thousands of dollars from bitcoin ATM’s, according to a Japanese cybersecurity company Trend Micro. In a blog post published Tuesday, Trend Micro shows posts by an apparently reputable user in an underground online forum, claiming to have malware that exploits a service vulnerability in a ATM in order to steal up to $6,750 worth of bitcoin from one machine. The main posting is dated June 25, 2018, and Trend Micro shows people on the forum discussing the offering at least a month later. For $25,000, the buyer gets the malware as well as a bank-style card loaded with the malicious code. The card is said to employ two different technologies for potentially communicating with machine: an EMV chip like those in most modern credit cards, and a near-field communication (NFC) capability for wireless access. Trend Micro says that, according to other comments on […]

The post Ready-to-use bitcoin ATM malware found for sale online appeared first on Cyberscoop.

Continue reading Ready-to-use bitcoin ATM malware found for sale online

Singapore health system breach likely conducted by APT group, government says

The government of Singapore says attackers responsible for a recent breach, largely being called the country’s worst in history, are likely inked to a state-backed advanced persistent threat group. S. Iswaran, Singapore’s minister of communications and information, said in a statement to the country’s parliament Monday that a government analysis of the attack shows that it is the work of known state-linked threat actors. Iswaran stopped short of naming the APT group in question, citing “national security reasons.” “The APT group that attacked SingHealth was persistent in its efforts to penetrate and anchor itself in the network, bypass the security measures, and illegally access and exfiltrate data,” Iswaran said in a statement. According to the AFP news agency, third-party security researchers had already indicated that the attack was linked to state-backed hackers. Iswaran’s remarks shed more light on the perceived sophistication behind the attack, albeit without attribution. Singapore initially announced the attack […]

The post Singapore health system breach likely conducted by APT group, government says appeared first on Cyberscoop.

Continue reading Singapore health system breach likely conducted by APT group, government says

Canadian startup HYAS raises $6.2 million for threat attribution platform

HYAS, a Canadian cybersecurity startup that looks to help customers attribute cyberthreats, raised $6.2 million in a Series A funding round announced on Thursday. The company’s flagship product is Comox, a platform that gives customers access to “billions” of threat indicators and proprietary data. The company says customers can leverage this information to gain greater visibility into threats on their networks and enhance their ability to attribute them. Based in Victoria, British Columbia, HYAS is led by CEO and founder Chris Davis. Davis, a Canadian, was recognized by the FBI with an award for his help in taking down the Mariposa botnet in 2009. “Every industry professional today is facing unrelenting adversaries. At HYAS we have dedicated ourselves to helping them finally put their attackers on the back foot,” Davis said in a press release. “Our Comox platform allows enterprises to see the unseeable – it’s like X-ray vision for […]

The post Canadian startup HYAS raises $6.2 million for threat attribution platform appeared first on Cyberscoop.

Continue reading Canadian startup HYAS raises $6.2 million for threat attribution platform