Tag: Security | TechCrunch

MOVEit, the biggest hack of the year, by the numbers

The mass-exploitation of MOVEit Transfer software has rapidly cemented itself as the largest hack of the year so far. While the full impact of the attack will likely remain untold for months to come, there are now more than 1,000…

Byju’s exposed sensitive student data, including loan details

Byju’s, the edtech giant and India’s most valuable startup, has fixed a server-side misconfiguration that was exposing the sensitive data of its students. The Indian startup exposed some students’ names, phone numbers, addresses and email IDs. The exposed data also…

Ivanti warns customers another zero-day is under active attack

U.S. software giant Ivanti has scrambled to patch another zero-day vulnerability under active attack. The vulnerability, tracked as CVE-2023-38035 with a vulnerability severity rating of 9.8 out of 10, affects the software company’s Sentry product. Ivanti Sentry (formerly MobileIron Sentry)…

SecureWorks layoffs affect 15% staff

SecureWorks said Monday it will let go of 15% of its workforce, the cybersecurity company’s second round of layoffs this year. In a regulatory filing, SecureWorks said that it would incur about $14.2 million in expenses due to the layoffs,…

Bugs in transportation app Moovit gave hackers free rides

Hackers could have hijacked the user accounts of a popular transportation app and used them to get free rides and access people’s personal information, according to a security researcher. Omer Attias, a security researcher at SafeBreach, said he found three…

How the FBI goes after DDoS cyberattackers

In 2016, hackers using a network of compromised internet-connected devices — vulnerable security cameras and routers — knocked some of the then biggest websites on the internet offline for several hours. Twitter, Reddit, GitHub and Spotify all went down intermittently…

US cyber board to investigate Microsoft hack of government emails

A U.S. review board tasked with investigating major cybersecurity incidents said it will begin looking at the recent intrusion of U.S. government email systems provided by Microsoft, whose handling of the incident drew ire and scrutiny from federal lawmakers and…

UK cybersecurity giant NCC Group is making more layoffs

U.K. cybersecurity giant NCC Group has confirmed it’s making more layoffs, just months after it slashed its workforce by 7%. The Manchester, U.K.-based company is undergoing its second round of layoffs in just six months, a person with knowledge of…

Osano, a data privacy management platform, nabs $25M

Osano, an Austin, Texas-based startup developing a platform to help companies manage their data privacy, today announced that it raised $25 million in a Series B funding round led by Baird Capital with Jump Capital, LiveOak, NextCoast and TDF. In…

Cybersecurity giant Rapid7 announces sweeping layoffs as losses mount

U.S. cybersecurity giant Rapid7 has announced plans to lay off 18% of its workforce, affecting more than 400 global employees. In a regulatory filing, the Boston-based cybersecurity company said its restructuring effort is “designed to improve operational efficiencies, reduce operating…

Parsing the UK voter register cyberattack

A catastrophic breach of the United Kingdom electoral register affects tens of millions of residents following a cyberattack at the U.K. Electoral Commission. With data on more than 40 million voters accessed by unnamed hackers, the cyberattack is already one…

Electoral Commission hack exposed data of 40 million UK voters

The personal information of approximately 40 million U.K. voters was exposed to hackers for more than a year after the Electoral Commission fell victim to a “complex cyberattack”. The Electoral Commission, the watchdog responsible for overseeing elections in the U.K.,…

Horizon3 secures $40M to expand its pen testing platform

Cybersecurity funding is falling after enjoying impressive heights in the last few years. According to Crunchbase, VC financing for security declined to just over $1.6 billion in Q2 2023, marking a 63% drop compared to the same quarter last year…

Colorado warns hackers stole 16 years of public school data

Colorado’s state government has warned students and teachers in the state that hackers may have accessed their personal information — dating back as far as 2004. In a notice on its website, the Colorado Department of Higher Education (CDHE) confirmed…

Health data of 1.7 million Oregon residents accessed by MOVEit hackers

Hackers behind the mass-exploitation of a vulnerability in the popular corporate file transfer tool MOVEit Transfer have accessed the protected health information of 1.7 million Oregon citizens. Performance Health Technology (PH Tech), a company that provides data management services to…

Russia-backed hackers used Microsoft Teams to breach government agencies

Russian state-sponsored hackers posed as technical support staff on Microsoft Teams to compromise dozens of global organizations, including government agencies. Microsoft security researchers said on Wednesday that the “highly targeted” social engineering campaign was carried out by a Russian state-sponsored…

HackerOne lays off 12% workforce as ‘one-time event’

HackerOne, a widely known bug bounty and penetration testing platform, is cutting up to 12% of its workforce as the global economic slowdown continues to impact the tech community. The San Francisco-based startup announced its layoffs on Wednesday, TechCrunch learned…

US, Norway say hackers have been exploiting Ivanti zero-day since April

Hackers exploited a zero-day flaw in Ivanti’s mobile endpoint management software undetected for at least three months, U.S. and Norwegian cybersecurity agencies have warned. It was confirmed last week that hackers had compromised multiple Norwegian government agencies by exploiting a…

There’s no reason to panic over WormGPT

As tools for building AI systems, particularly large language models  (LLMs), get easier and cheaper, some are using them for unsavory purposes, like generating malicious code or phishing campaigns. But the threat of AI-accelerated hackers isn’t quite as dire as…

Threat intelligence startup Cyble lands $24M investment

Cyble, a cybersecurity startup that styles itself as a “threat intelligence provider,” today announced that it raised $24 million in a Series B funding round co-led by Blackbird Ventures and King River Capital with participation from Spider Capital, January Capital,…

Strengthening security in a multi-SaaS cloud environment

When security systems are sourced from different vendors, it becomes even more challenging to detect and prevent attacks in a timely manner. This article has been indexed from Security | TechCrunch Read the original article: Strengthening security in a multi-SaaS…

Protect AI raises $35M to build a suite of AI-defending tools

Protect AI, a startup building tools to harden the security around AI systems, today announced that it raised $35 million in a Series A round led by Evolution Equity Partners with participation from Salesforce Ventures, Acrew Capital, boldstart ventures, Knollwood…

Thales enters app security market with $3.6B Imperva acquisition

French aerospace and defence group Thales is procuring cybersecurity company Imperva from Thoma Bravo in a deal worth $3.6 billion. The news comes four years after private equity giant Thoma Bravo acquired Imperva for $2.1 billion, taking the San Mateo-based…

Spyhide stalkerware is spying on tens of thousands of phones

A phone surveillance app called Spyhide is stealthily collecting private phone data from tens of thousands of Android devices around the world, new data shows. Spyhide is a widely-used stalkerware (or spouseware) app that is planted on a victim’s phone,…

I tried to buy a post on TechCrunch.com

A few times per day, I get a message that asks something along the lines of: “How much do you charge for a guest article on TechCrunch?” People are trying to get inbound links from TechCrunch for SEO reasons. The…

US government adds two more spyware makers to denylist

The U.S. government put Intellexa and Cytrox, two European spyware makers, on an economic denylist on Tuesday. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is…

US government adds two more spyware makers to deny list

The U.S. government put Intellexa and Cytrox, two European spyware makers, on an economic denylist on Tuesday. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is…

Cybersecurity firm Netcraft lands $100M investment

After years of growth, funding for cybersecurity startups is beginning to slow down, a symptom of the broader economic malaise and — perhaps — market oversaturation. According to a recent note from Pinpoint Search Group, cybersecurity funding dipped 55% in…

US government adds two more spyware makers on deny list

The U.S. government put Intellexa and Cytrox, two European spyware makers, on an economic denylist on Tuesday. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is…

ID verification platform Bureau bumps its Series A to $16.5M

Identity verification platform for businesses, Bureau, has added $4.5 million in its Series A, bringing its total to $16.5 million. The funding was raised from GMO Venture Partners and GMO Payment Gateway. Other investors in the round include Quona Capital…

Microsoft lost its keys, and the government got hacked

Microsoft still doesn’t know — or want to share — how China-backed hackers stole a key that allowed them to stealthily break into dozens of email inboxes, including those belonging to several federal government agencies. In a blog post Friday,…

JumpCloud says nation-state hackers breached its systems

Identity and access management firm JumpCloud says it reset customers’ API keys after nation-state hackers breached its systems. JumpCloud, a directory platform that allows enterprises to authenticate, authorize, and manage users and devices, last week told customers that it had…

Cybersecurity professional accused of stealing $9M in crypto

The U.S. government accused a cybersecurity professional of hacking a cryptocurrency exchange and stealing around $9 million in cryptocurrency, in what looks like a case of an ethical hacker turning rogue, then trying to appear ethical again. In a press…

Bangladesh government takes down exposed citizens’ data

The Bangladeshi government on Sunday took down citizens’ sensitive data that it had left exposed online. On Friday, TechCrunch reported that a website belonging to the government of Bangladesh was leaking the personal information of the country’s citizens, including full…