Duncan Riley
Latest from Duncan Riley
A proposal from the U.S. Securities and Exchange Commission to compel companies to disclose cybersecurity incidents has received strong support from cybersecurity professionals. There are two components to the proposal. The first is mandatory cybersecurity incident reporting of “material” incidents. The disclosure …
Leaked correspondence and files expose infamous Conti ransomware gang
An unknown member of the infamous Conti ransomware gang has been leaking internal documentation about the gang after it came out in support of Russia’s invasion of Ukraine. The leaks started in late February in the days following the Russian invasion, with …
Shares in electric car maker Rivian drop on weak earnings and outlook
Shares in Rivian Automotive Inc. dropped in late trading after the electric car maker reported lower-than-expected earnings and outlook in its first earnings report after going public in November. For the quarter ended Dec. 31, Rivian reported a loss before interest, taxes, …
1Password increases top bug bounty to a Bugcrowd record high $1M
Password management software provider 1Password today announced it has increased its top bug bounty reward to $1 million, the highest bounty in the history of the crowdsourced security platform Bugcrowd Inc.’s history. The new reward program is designed to build on a long history …
Enterprise automation platform startup Jiffy.ai raises $53M for sales and marketing
Enterprise automation platform startup Jiffy.ai today said it has raised $53 million in new funding to scale its sales and marketing efforts and to develop its HyperApp platform further. Eight Roads Ventures led the Series B round with Iron Pillar, R-Squared, Nexus Venture Partners, Reaction Capital …
After smashing forecasts and outlook, CrowdStrike sees shares surge in late trading
Shares in CrowdStrike Holdings Inc. surged in late trading after the cybersecurity company smashed both fiscal fourth-quarter expectations and offered an encouraging outlook. For the quarter ended Jan. 31, CrowdStrike reported a profit before costs such as stock compensation net income of …
ServiceNow instances found vulnerable to misconfiguration and leaking data
New research released today by software-as-a-service security management startup AppOmni Inc. details how ServiceNow Inc. instances are vulnerable to misconfiguration. The issue relates to data leaking through improper customer access control list or ACL configurations, with nearly 70% of tested instances having the …
New Palo Alto Networks security offering combats supply chain threats
Network security specialist Palo Alto Networks Inc. today announced a new security offering to combat supply chain threats. The new Prisma Cloud Supply Chain Security provides a complete view of where potential vulnerabilities or misconfigurations exist in an organization’s software supply chain. In doing so, …
Microsoft patches critical Exchange Server vulnerability in Patch Tuesday release
Microsoft Corp. today released a fix for a critical vulnerability in Exchange Server as part of its monthly Patch Tuesday release. The Exchange Server vulnerability addressed was officially named CVE-2022-23277. Microsoft stated in an advisory that by using the critical vulnerability, an attacker …
Tech vendor coalition formed to provide technology and financial support to Ukraine
Domain name system threat protection firm DNSFilter Inc. has formed a new group to provide technology and financial support to Ukraine. The Ukraine Strong Tech Vendor Coalition is inviting technology vendors to provide public support to Ukraine. Those joining the coalition are …