Spec Secures $15M Series A Funding, Accelerating Innovation in Fraud Defense

October 19, 2023 at 05:09PM Leading cybersecurity firm, Spec, has successfully closed a $15M Series A funding round led by SignalFire, with participation from Legion Capital and Rally Ventures. The funding will support Spec’s continued growth and innovation, including advancing their platform, expanding their threat labs, and co-developing specialized products. Spec is dedicated to providing … Read more

SailPoint Unveils Annual ‘Horizons of Identity Security’ Report

October 19, 2023 at 05:09PM SailPoint Technologies, in collaboration with Accenture, released the findings from their annual research report, ‘The Horizons of Identity Security.’ The report revealed that 44% of companies are still in the early stages of their identity security journeys, and only 70% of identities in mature companies are covered by foundational governance … Read more

23AndMe Hacker Leaks New Tranche of Stolen Data

October 19, 2023 at 04:47PM A threat actor known as Golem has released a new dataset containing the records of over 4 million people’s genetic ancestry, including information on wealthy individuals in the US and Western Europe, after compromising the 23AndMe site. 23andMe is still verifying the authenticity of the leaked data. The breach was … Read more

North Korean State Actors Attack Critical Bug in TeamCity Server

October 19, 2023 at 04:33PM North Korean state-backed threat groups, Diamond Sleet and Onyx Sleet, are exploiting a critical vulnerability in JetBrains TeamCity server to carry out cyber espionage, data theft, and other malicious activities. Over 30,000 organizations, including Citibank, Nike, and Ferrari, use TeamCity. The vulnerability allows attackers to gain administrative privileges and execute … Read more

Microsoft extends Purview Audit log retention after July breach

October 19, 2023 at 04:27PM Microsoft is extending Purview Audit log retention following the breach of Exchange and Microsoft 365 accounts by the Chinese hacking group Storm-0558. The affected organizations included government agencies, with the US State and Commerce Departments among them. The changes will roll out to customers with Standard licenses, providing longer retention … Read more

Casio keyed up after data loss hits customers in 149 countries

October 19, 2023 at 03:53PM Japanese electronics company Casio announced that their ClassPad server was breached, resulting in the theft of a database containing personal information of customers from 149 countries. The data includes names, email addresses, purchasing information, and service usage details. Casio has blocked outside access to the affected databases and is working … Read more

Harmonic Lands $7M Funding to Secure Generative AI Deployments

October 19, 2023 at 01:18PM Harmonic Security has raised $7 million in seed funding to develop technology that protects generative AI in businesses. The startup aims to address the lack of regulation in AI apps that collect company data. The financing round was led by Ten Eleven Ventures, with participation from Storm Ventures and other … Read more

Ragnar Locker ransomware’s dark web extortion sites seized by police

October 19, 2023 at 10:50AM Law enforcement agencies from multiple countries have seized the Tor negotiation and data leak sites belonging to the Ragnar Locker ransomware group. The seizure message displayed on the websites indicates that a coordinated international operation involving law enforcement from the US, Europe, Germany, France, Italy, Japan, Spain, Netherlands, and Latvia … Read more

Iran-Linked ‘MuddyWater’ Spies on Mideast Gov’t for 8 Months

October 19, 2023 at 10:35AM An Iranian state-aligned APT known as MuddyWater has conducted a spying campaign on an unnamed Middle Eastern government for eight months. Symantec, which tracks the group, identified daily efforts to steal sensitive government data using custom malware tools. The campaign, which went undetected, involved accessing various computers on the network … Read more

CipherStash Raises $3 Million for Encryption-in-Use Technology

October 19, 2023 at 08:42AM Australian cybersecurity startup, CipherStash, has raised $3 million in a seed funding round led by Skip Capital. The company uses queryable encryption technology to protect data, offering tighter access controls and tracking capabilities. CipherStash’s solution integrates with various programming languages and databases. The funding will support the expansion of their … Read more