Duncan Riley
Latest from Duncan Riley
The Synopsys Cybersecurity Research Center has uncovered two critical vulnerabilities in JSON that can expose data in the open-source Node.js headless content management system Strapi. The two vulnerabilities, named CVE-2022-30617 and CVE-2022-30618, are described as sensitive data exposure vulnerabilities that may lead …
Hackers target Discord NFT groups with malicious links
Hackers have targeted Discord Inc. groups that were discussing nonfungible tokens in an attempt to get users to click on malicious links. At a time cryptocurrency has been hit hard, but not even close to NFTs, blockchain security company PeckShield Co. Ltd. …
SpotOn raises $300M to develop its payments platform
Payments startup SpotOn Transact Inc. announced today that it has raised a $300 million late-stage funding round to develop its product offering further. The Series F round was led by Dragoneer Investment Group and included Andreessen Horowitz, DST Global, Franklin Templeton, Mubadala Investment Co. …
Data-centric security startup Seclore raises $27M
Data-centric security startup Seclore Technology Pvt. Ltd. said today it has raised $27 million in new funding to try to become the platform of choice for enterprise data protection initiatives. Origami Capital Partners and Oquirrh Ventures led the Series C round. Including the new …
Hackers actively targeting WordPress sites running unpatched Tatsu plugin
Hackers are reported to be actively targeting WordPress sites with unpatched versions of the Tatsu no-code page builder plugin installed. Detailed Monday by Ram Gall at Wordfence, the large-scale attack is targeting a Remote Code Execution vulnerability in Tatsu that was publicly disclosed …
FBI warns of scraping attacks targeting online checkout pages
The U.S. Federal Bureau of Investigation has issued a flash alert warning businesses that cybersecurity actors are scraping credit card data from online checkout pages. The alert, sent Monday, states that as of January, the unidentified cyber attacker scraped credit card data …
Apple struggled to develop mixed reality headset because of internal politics
A new report today details Apple Inc.’s long struggles with building a mixed reality headset. The Information spoke with 10 people close to Apple’s headset project who detailed issues with the project going back to 2016. Apple was first reported to be …
Keyfactor-Fortanix integration offers improved machine identity management
Machine and “internet of things” identity platform provider Keyfactor Inc. today announced a technology integration with Fortanix Inc. to allow enterprise and managed service providers to simplify and secure machine identity management. The technology integration combines the benefits of certificate lifecycle automation with …
Access orchestration firm Pathlock raises $200M as it combines with four other companies
Unified access orchestration startup Pathlock today announced that it has raised $200 million in new funding and has merged with data security solutions company Appsian and compliance management company Security Weaver. It also announced that it has acquired Belgium-based governance, risk and compliance …
Cybersecurity VC firm Ballistic Ventures announces new fund, first investments
New cybersecurity venture capital firm Ballistic Ventures Alpha LLC today announced its debut fund, expected to close at $300 million, as well as investments in several companies. Ballistic Ventures was established late last year by cybersecurity professionals and is dedicated to investing …