A U.S. security researcher is warning of a chilling effect after he was detained on arrival at a U.S. airport, his phone was searched, and was ordered to testify to a grand jury, only to have prosecutors reverse course and…
Tag: Security News | TechCrunch
This startup wants to verify your ID without storing your personal data
As government and banking services move away from verifying identities in the real world, moving toward online ID verification, several companies have entered the market to solve this problem. A new startup from France is entering the market with a…
Russian zero-day seller offers $20M for hacking Android and iPhones
A company that acquires and sells zero-day exploits — flaws in software that are unknown to the affected developer — is now offering to pay researchers $20 million for hacking tools that would allow its customers to hack iPhones and…
Gem Security raises $23M for its cloud security platform
Cloud detection and response company Gem Security today announced that it has raised a $23 million Series A round led by GGV Capital, with participation from IBM Ventures, Cisco and Silicon Valley CISO Investments. It was only in February that…
Cybersecurity firm Lumu raises $30M to detect network intrusions
Lumu, a startup that helps enterprises identify and isolate security compromises, today announced that it raised $30 million in a Series B round led by Forgepoint Capital, $6 million of which is debt. Ricardo Villadiego, Lumu’s founder and CEO, says…
Sources: Palo Alto Networks in advanced talks to buy Talon and Dig in a $1B security sweep
Palo Alto Networks’ stock price has been on the rise on the back of strong earnings and growing demand for cybersecurity services, and now the company is using that momentum to do a little shopping. TechCrunch has confirmed with multiple…
Sources: Palo Alto in advanced talks to buy Talon and Dig in a $1B security sweep
Palo Alto Networks’ stock price has been on the rise on the back of strong earnings and growing demand for cybersecurity services, and now the company is using that momentum to do a little shopping. TechCrunch has confirmed with multiple…
Found: Live from TechCrunch Disrupt with cybersecurity trailblazer Window Snyder from Thistle Technologies
Welcome back to Found, the podcast where we get the stories behind the startups. This article has been indexed from Security News | TechCrunch Read the original article: Found: Live from TechCrunch Disrupt with cybersecurity trailblazer Window Snyder from Thistle…
Why the public sector is an easy target for ransomware
We’re on track for 2023 to be a record breaking year for ransomware attacks targeting the U.S. public sector. These attacks, which includes both traditional encrypt-and-extort and newer data theft-only attacks, know the public sector is an easy target: It’s…
New SEC cybersecurity disclosure rules: What you need to know to stay in compliance
The SEC requires companies to report both material cybersecurity incidents and cybersecurity risk management processes in a standardized way. This article has been indexed from Security News | TechCrunch Read the original article: New SEC cybersecurity disclosure rules: What you…
Hackers steal $200M from crypto company Mixin
Hong Kong-based crypto company Mixin announced on Sunday that it was breached and that the hackers stole around $200 million. “In the early morning of September 23, 2023 Hong Kong time, the database of Mixin Network’s cloud service provider was…
Hackers steal $200 million from crypto company Mixin
Hong Kong-based crypto company Mixin announced on Sunday that it was breached and that the hackers stole around $200 million. “In the early morning of September 23, 2023 Hong Kong time, the database of Mixin Network’s cloud service provider was…
Decade of newborn child registry data stolen in MOVEit mass-hack
Ontario’s government-funded birth registry has confirmed a data breach affecting some 3.4 million people who sought pregnancy care, including the personal health data of close to two million newborns and children across the Canadian province. BORN Ontario said in a…
Yes, you have to update your Apple devices again, because spyware is bad
Apple has released urgent security updates for iPhones, iPads, Macs, Apple Watch, and Safari users to block two active spyware campaigns. This article has been indexed from Security News | TechCrunch Read the original article: Yes, you have to update…
Google’s Parisa Tabriz on how the company stays ahead of hackers
Google is constantly under attack. But while hackers have compromised gaming giants, casinos and other technology giants in recent months, Google has so far remained largely unscathed. Parisa Tabriz, who is responsible for Chrome web browser security and Project Zero,…
Kindo aims to take the security stress out of AI workflows
Ron Williams, co-founder and CEO of Kindo, knows a thing or two about cybersecurity, having previously led security teams at League of Legends developer Riot Games, shared scooter startup Bird and Alphabet-backed Clover Health. He is now bringing this expertise…
GitHub launches passkey support into general availability
GitHub is formally launching its passkeys security feature into general availability, two months after first debuting it in beta. Passkeys offer cloud-synced authentication using cryptographic key pairs, allowing users to sign-in to websites and apps with the same screen-lock PIN…
Encrypted email provider Proton has built its own CAPTCHA service
Proton, the Swiss company that develops privacy-focused online services such as email, has developed its very own CAPTCHA service to help discern between genuine login attempts and bots — and it touts the new system as the world’s first CAPTCHA…
Cisco to acquire Splunk in $28B mega deal
Cisco has a reputation of building the company through acquisitions, but it has tended to stay away from the really huge ones. That changed this morning when the company announced it was acquiring Splunk for $28 billion. With Splunk, it…
Meta targeted for fresh UK gov’t warning against E2E encryption for Messenger, Instagram
Buckle up for another encryption fight: Hot on the heels of securing parliament’s approval for its Online Safety Bill yesterday, the UK government is amping up pressure on Meta not to roll out end-to-end-encryption (E2EE) on Facebook Messenger and Instagram…
Donald Trump Jr.’s X account was hacked, spokesperson confirms
Donald Trump Jr.’s account on X (formerly Twitter) was hacked on Wednesday morning. The account published a post that falsely claimed that his father, former president Donald Trump, had passed away. “I’m sad to announce, my father Donald Trump has…
Donald Trump Jr. X account was hacked, spokesperson confirms
Donald Trump Jr.’s account on X (formerly Twitter) was hacked on Wednesday morning. The account published a post that falsely claimed that his father, former president Donald Trump, had passed away. “I’m sad to announce, my father Donald Trump has…
Legit Security lands $40M to lock down apps and dev environments
Legit Security, a cybersecurity company developing a platform to identify app vulnerabilities from code, has raised $40 million in a Series B funding round led by CRV with participation from Cyberstarts, Bessemer Venture Partners and TCV. Co-founder and CEO Roni…
Phalanx protects company data by automatically securing and tracking sensitive documents
Data loss prevention (DLP) has emerged as a foundational strategy for businesses looking to prevent workers from inadvertently (or advertently) sharing sensitive data outside the confines of the company network. At its core, DLP is about solving the “people problem”…
International Criminal Court says hackers accessed its systems
The International Criminal Court (ICC) has said it experienced a cyberattack last week after hackers accessed its internal systems. The ICC, headquartered in The Hague, Netherlands, is the only permanent war crimes tribunal. Established in 2002, the court is currently…
A year into private ownership, SailPoint cracks the $600M ARR threshold
The final earnings report that SailPoint disclosed before it was taken private detailed its Q2 2022 results, including revenue of $134.3M. This article has been indexed from Security News | TechCrunch Read the original article: A year into private ownership,…
HiddenLayer raises $50M for its AI-defending cybersecurity tools
HiddenLayer, a security startup focused on protecting AI systems from adversarial attacks, today announced that it raised $50 million in a funding round co-led by M12 and Moore Strategic Ventures with participation from Booz Allen Hamilton, IBM, Capital One and…
Cato Networks, valued at $3B, lands $238M ahead of its anticipated IPO
Cato Networks, the Tel Aviv-based startup that packages software-defined networking, managed cybersecurity and global backbone services into a single offering, today announced that it raised $238 million in an equity investment that values the company at over $3 billion. LightSpeed…
Sources: CrowdStrike will announce its Bionic.ai acquisition for $350M today
Earlier this year, we broke the news that CrowdStrike was close to acquiring Bionic.ai — a security posture management platform for cloud services — for between $200 million and $300 million. Sources tell us that this deal has now closed…
One of the FBI’s most wanted hackers is trolling the U.S. government
Earlier this year, the U.S. government indicted Russian hacker Mikhail Matveev, also known by his online monikers “Wazawaka” and “Boriselcin,” accusing him of being “a prolific ransomware affiliate” who carried out “significant attacks” against companies and critical infrastructure in the…
UK police officers’ data stolen in cyberattack on ID supplier
The personal details of thousands of U.K. police officers have been stolen after a suspected ransomware attack on a third-party supplier. Greater Manchester Police, one of the largest police departments in the U.K., confirmed last week that the supplier, since…
Microsoft AI researchers accidentally exposed terabytes of internal sensitive data
Microsoft AI researchers accidentally exposed tens of terabytes of sensitive data, including private keys and passwords, while publishing a storage bucket of open-source training data on GitHub. In research shared with TechCrunch, cloud security startup Wiz said it discovered a…
iOS 17 includes these new security and privacy features
Apple’s long-awaited iOS 17 update for iPhones lands today with a number of new and improved security features. Much of the new features are aimed at protecting iPhone owners who are at greater risk of cyberattacks and spyware, like journalists,…
X launches account verification based on government ID
X, formerly Twitter, has launched government ID-based account verification for paid users to prevent impersonation and give them benefits such as “prioritized support.” The social network has partnered with Israel-based Au10tix for identity verification solutions. The pop-up for ID verification…
Caesars Entertainment says customer data stolen in cyberattack
Hotel and casino giant Caesars Entertainment said Thursday that hackers stole a huge trove of customer data in a recent cyberattack, confirming recent media reports. Caesars said in an 8-K notice with federal regulators filed before markets opened on Thursday…
Hackers claim MGM cyberattack as outage drags into fourth day
MGM Resorts continues to battle a widespread outage after a cyberattack forced it to shut down systems across its properties. The hotel and entertainment giant, which operates a number of hotels and casinos on the Las Vegas Strip including the…
Patronus AI conjures up an LLM evaluation tool for regulated industries
It turns out that when you put together two AI experts, both of whom formerly worked at Meta researching responsible AI, magic happens. The founders of Patronus AI came together last March to build a solution to evaluate and test…
Digital forensics firm Binalyze raises $19M to investigate cyber threats
Binalyze, a London-based startup building a toolset for digital forensics and incident response, this week announced that it raised $19 million in a Series A round led by Molten Ventures with participation from Cisco Investments, Citibank Ventures and Deutsche Bank…
Zenity strives to keep no-code/low-code apps secure
So many companies are using low-code and no-code tools these days to create apps and workflows. These tools are by design likely in the hands of non-technical end users, but the problem is that these folks might not know about…
Zenity strives to keep no code/low code apps secure
So many companies are using low code and no code tools these days to create apps and workflows. These tools are by design likely in the hands of non-technical end users, but the problem is that these folks might not…
AuthMind raises seed funding for its identity SecOps platform
AuthMind, a Maryland-based startup that aims to help businesses protect themselves from identity-related cyberattacks, today announced that it has raised an $8.5 million seed round led by Ballistic Ventures, with strategic participation from IBM Ventures. The company was co-founded by…
MGM Resorts blames ‘cybersecurity issue’ for ongoing outage
Hotel and casino giant MGM Resorts has confirmed a “cybersecurity issue” is to blame for an ongoing outage affecting systems at the company’s Las Vegas properties. “MGM Resorts recently identified a cybersecurity issue affecting some of the company’s systems,” the…
Square says daylong outage caused by DNS error
Square said there was “no evidence” a cyberattack caused an outage that left customers and small businesses unable to use the payment giant’s technology on Thursday through early-Friday. The payments technology giant said in a post-mortem of the daylong outage…
0xPass raises $1.8M from Balaji Srinivasan and others to build secure login systems for web3
0xPass is among the many startups trying to make crypto wallets secure and convenient for mass adoption. Specifically, it’s solving the login piece of user experience, which, at the moment, is cumbersome and requires users to have a decent level…
Microsoft reveals how hackers stole its email signing key… kind of
A series of unfortunate and cascading mistakes allowed a China-backed hacking group to steal one of the keys to Microsoft’s email kingdom that granted near unfettered access to U.S. government inboxes. Microsoft explained in a long-awaited blog post this week…
Polish Senate says use of government spyware is illegal in the country
A special commission within Poland’s Senate concluded that the government’s use of spyware, like the one made by NSO Group, is illegal. The commission announced on Thursday the conclusion of its 18-month investigation into allegations that the Polish government used…
Polish senate says use of government spyware is illegal in the country
A special commission within Poland’s Senate concluded that the government’s use of spyware, like the one made by NSO Group, is illegal. The commission announced on Thursday the conclusion of its 18-month-long investigation into allegations that the Polish government used…
Apple fixes zero-day bugs used to plant Pegasus spyware
Apple released security updates on Thursday that patch two zero-day exploits — meaning hacking techniques that were unknown at the time Apple found out about them — used against a member of a civil society organization in Washington D.C., according…
The perils of the platforms of paranoia
Nextdoor has become ground zero for the spread of many rumors, hoaxes and unfounded allegations. This article has been indexed from Security News | TechCrunch Read the original article: The perils of the platforms of paranoia
Traderie, a marketplace for in-game items, alerts users to data breach
In-game trading marketplace Traderie has alerted users to a data breach impacting their personal information, TechCrunch has learned. Tradierie, owned by U.S.-based company Akrew, is a website that allows users to trade and sell in-game items from titles including Roblox,…
US, UK authorities sanction more alleged Trickbot gang members
U.S and U.K. authorities have sanctioned more alleged members of the notorious Russia-based Trickbot cybercrime gang. The U.S. Treasury and U.K.’s Foreign Office announced on Thursday fresh sanctions against 11 individuals “involved in management and procurement for the Trickbot group.”…
ActiveFence snaps up Spectrum Labs, last valued at $137M, to help fight the harmful content creep
Misinformation, harassment, grooming and other illegal activity continue to be major issues in the worlds of content moderation and online safety, balancing big problems and illicit activity against equally important, and sometimes conflicting, needs for privacy, data protection and security…
Ransomware gang claims credit for Sabre data breach
Travel booking giant Sabre said it was investigating claims of a cyberattack after a tranche of files purportedly stolen from the company appeared on an extortion group’s leak site. “Sabre is aware of the claims of a data exfiltration made…
See Tickets says hackers accessed customers’ payment data — again
Global ticketing giant See Tickets has disclosed a data breach affecting customers’ credit card information for the second time in the past 12 months. See Tickets, owned by Vivendi Ticketing, confirmed the latest breach in a filing with Maine’s attorney…
Meet the AI, fintech, SaaS and security industry chairs at TC Disrupt 2023
We’re less than two weeks away from TechCrunch Disrupt 2023, and we still have more amazing people and sessions to share with you. Today, we’re introducing you to our industry chairs. These folks act as expert resources for TechCrunch, and…
API security startup Pynt raises $6M
“We chose ‘Pynt’ because it’s short, memorable, and reflects our love for developers and a good beer,” Pynt co-founder and CEO Tzvika Shneider told me when I asked him about how the company got its name. “As we say: ‘A…
Hacking device Flipper Zero can spam nearby iPhones with Bluetooth pop-ups
Thanks to a popular and relatively cheap hacking tool, hackers can spam your iPhone with annoying pop-ups prompting you to connect to a nearby AirTag, Apple TV, AirPods, and other Apple devices. A security researcher who asked to be referred…
Chipmaker NXP confirms data breach involving customers’ information
Dutch chipmaker NXP Semiconductors has alerted customers to a data breach involving their personal information. The data breach was first flagged by Troy Hunt, the owner of Have I Been Pwned, who tweeted a copy of the email NXP had…
ThetaRay nabs $57M for AI tools to fight money laundering
Money laundering — the process of transferring assets around in order to disguise the illicit origin of the money behind them — has been a huge and growing business for years, used by terrorists to finance their work, criminals to…
India warns of malware attacks targeting its Android users
India has warned its citizens of an advanced malware targeting Android users, capable of accessing sensitive data and allowing hackers control over infected devices. The Controller General of Defence Accounts, a department in India’s Defense Ministry, released the advisory on the…
Maker of ‘smart’ chastity cage left users’ emails, passwords, and locations exposed
A company that makes a chastity device for people with a penis that can be controlled by a partner over the internet exposed users’ email addresses, plaintext passwords, home addresses and IP addresses, and — in some cases — GPS…
Lidl recalls Paw Patrol snacks after website on packaging displayed porn
Supermarket giant Lidl has issued a recall of Paw Patrol snacks after the website listed on the products’ packaging began displaying explicit content unsuitable for children. Lidl, which operates more than 12,000 stores globally, is urging shoppers in the United…
How the FBI took down the notorious Qakbot botnet
A global law enforcement operation this week took down and dismantled the notorious Qakbot botnet, touted as the largest U.S.-led financial and technical disruption of a botnet infrastructure. Qakbot is a banking trojan that became infamous for providing an initial…
Forever 21 data breach affects half a million people
Clothing giant Forever 21 said a data breach earlier in the year affects more than half a million individuals. A data breach notice filed with Maine’s attorney general said the fashion giant was hacked over a three-month period beginning early…
LogicMonitor customers hit by hackers, because of default passwords
Some customers of the network security company LogicMonitor have been hacked due to the use of default passwords, TechCrunch has learned. A LogicMonitor spokesperson confirmed to TechCrunch that there’s “a security incident” affecting some of the company’s customers. “We are…
Malwarebytes lays off 100 employees ahead of business split
Cybersecurity giant Malwarebytes this week laid off 100 employees as it prepares for a major restructuring that will see the business split into two, TechCrunch has learned. The layoffs come almost exactly a year after Malwarebytes eliminated 14% of its global…
With Beijing’s green light, mobility unicorns Zeekr and WeRide inch closer to US IPOs
Six months ago, China’s securities authority announced a set of new rules to facilitate overseas IPOs of Chinese companies, allowing Beijing to tighten its grip on businesses seeking to sell shares abroad. Since then, companies have committed themselves to meeting…
With Beijing’s greenlight, mobility unicorns Zeekr and WeRide inch closer to US IPOs
Six months ago, China’s securities authority announced a set of new rules to facilitate overseas IPOs of Chinese companies, allowing Beijing to tighten its grip on businesses seeking to sell shares abroad. Since then, companies have committed themselves to meeting…
TechCrunch Disrupt 2023 Startup Battlefield 200: AI and Security edition
After months of vetting thousands of applications, the Startup Battlefield 200 (SB 200) cohort for TechCrunch Disrupt 2023 is complete. You do not want to miss this incredible, curated collection of early-stage startups you’ll find exhibiting on the expo floor.…
FBI operation tricked thousands of computers infected by Qakbot into uninstalling the malware
A U.S. government operation has dismantled the infrastructure of the notorious Qakbot malware, which officials say caused “hundreds of millions” of dollars of damage worldwide. In an announcement on Tuesday, the FBI said that it had successfully “disrupted and dismantled” the…
Mom’s Meals says data breach affects 1.2 million customers
Mom’s Meals, a meal delivery service for people with chronic health conditions, has confirmed a data breach affecting more than 1.2 million individuals. In a data breach notice filed this week with Maine’s attorney general, Mom’s Meals parent company PurFoods…
Google is bringing generative AI to its security tooling
Today at Google Cloud Next, the company announced several new generative AI enhancements to its security product line in an effort to make it easier to find information from a massive amount of security data by simply asking questions in…
A Brazilian phone spyware was hacked and victims’ devices ‘deleted’ from server
A Portuguese-language spyware called WebDetetive has been used to compromise more than 76,000 Android phones in recent years across South America, largely in Brazil. WebDetetive is also the latest phone spyware company in recent months to have been hacked. In…
A Brazilian phone spyware was hacked and victims’ stolen data ‘deleted’
A Portuguese-language spyware called WebDetetive has been used to compromise more than 76,000 Android phones in recent years across South America, largely in Brazil. WebDetetive is also the latest phone spyware company in recent months to have been hacked. In…