security

The software supply chain faces threats from all sides. A 2024 report by the Ponemon Institute found that over half of organizations have experienced a software supply chain attack, with…

Lineaje raises $20M to help organizations combat software supply chain threats

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The Mumbai-based firm said one of its multisig wallets had suffered a security breach, and it was temporarily pausing all withdrawals from the platform.

WazirX halts withdrawals after losing $230 million, nearly half its reserves

Pindrop builds deepfake-combatting and multi-factor authentication products targeting businesses in banking, finance and related industries.

Deepfake-detecting firm Pindrop lands $100M loan to grow its offerings

This is a guide on how to check whether someone compromised your online accounts.

How to tell if your online accounts have been hacked

Apple has issued a new round of threat notifications to iPhone users across 98 countries, warning them of potential mercenary spyware attacks. It’s the second such alert campaign from the…

Apple warns iPhone users in 98 countries of spyware attacks

Airtel, India’s second-largest telecom operator, on Friday denied any breach of its systems following reports of an alleged security lapse that has caused concern among its customers. The telecom group,…

India’s Airtel dismisses data breach reports amid customer concerns

Cover says what sets it apart is the underlying technology it employs, which has been exclusively licensed from NASA’s Jet Propulsion Laboratory.

A new startup from Figure’s founder is licensing NASA tech in a bid to curb school shootings

Late Friday afternoon, a time window companies usually reserve for unflattering disclosures, AI startup Hugging Face said that its security team earlier this week detected “unauthorized access” to Spaces, Hugging…

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

Generative AI makes stuff up. It can be biased. Sometimes it spits out toxic text. So can it be “safe”? Rick Caccia, the CEO of WitnessAI, believes it can. “Securing…

WitnessAI is building guardrails for generative AI models

The company said it is increasing the on-device capability of its Google Play Protect system to detect fraudulent apps trying to breach sensitive permissions.

Google adds live threat detection and screen-sharing protection to Android

Ahead of the U.S. presidential election, Google is bringing passkey support to its Advanced Protection Program (APP), which is used by people who are at high risk of targeted attacks,…

Google expands passkey support to its Advanced Protection Program ahead of the US presidential election

In 2019, Jyoti Bansal co-founded San Francisco-based security company Traceable alongside Sanjay Nagaraj. With Traceable, Bansal — who previously co-launched app performance management startup AppDynamics, acquired by Cisco in 2017…

Citigroup’s VC arm invests in API security startup Traceable

When a company raises $175M at a $3B valuation, it gets your attention. When that startup is a browser company, all the more.

With $175M in new funding, Island is putting the browser at the center of enterprise security

Security review automation platform SafeBase has raised new cash from investors including Zoom’s corporate VC arm.

SafeBase taps AI to automate software security reviews

Apple’s App Store isn’t always as trustworthy as the company claims. The latest example comes from RockAuto, an auto parts dealer popular with home mechanics and other DIYers, which is…

Despite complaints, Apple hasn’t yet removed an obviously fake app pretending to be RockAuto

Simbian is a cybersecurity platform that effectively controls other cybersecurity platforms as well as security apps and tooling.

Simbian brings AI to existing security tools

Apple sent threat notifications to iPhone users in 92 countries on Wednesday, warning them that they may have been targeted by mercenary spyware attacks. The company said it sent the…

Apple alerts users in 92 nations to mercenary spyware attacks

At Cloud Next, many of the announcements had to do with Gemini, Google’s flagship family of generative AI models.

Google injects generative AI into its cloud security tools

Zscaler, a cloud security company with headquarters in San Jose, California, has acquired cybersecurity startup Avalor 26 months after its founding, reportedly for $310 million in cash and equity. In a…

Zscaler buys Avalor to bring more AI into its security tools

Thanks to an uncertain economy, cybersecurity budgets are in a tight spot. According to a 2023 survey from IANS and recruiting firm Artico Search, more than a third of chief…

Reach Security taps a company’s existing tools to fight cyber threats

Cycode is a well-funded startup that offers an end-to-end application security posture management platform — that is, a tool that continuously scans code (and the libraries it relies on) for…

Cycode acquires Bearer to accelerate its move into AI-enhanced security remediation

Security researchers say a pair of easy-to-exploit flaws in a popular remote-access tool used by more than a million companies around the world are now being mass exploited, with hackers…

Researchers say easy-to-exploit security bugs in ConnectWise remote-access software now under mass attack

Apple announced today it is upgrading iMessage’s security layer to post-quantum cryptography, starting in iOS and iPadOS 17.4, macOS 14.4 and watchOS 10.4. The technology giant said that in the…

Apple readies iMessage for when quantum computers could break encryption

1Password, the AgileBits-owned password management software developer, today announced that it has acquired Kolide, an endpoint security platform, for an undisclosed amount. According to 1Password CEO Jeff Shiner, Kolide founder…

1Password expands its endpoint security offerings with Kolide acquisition

A misconfigured cloud storage server belonging to automotive giant BMW exposed sensitive company information, including private keys and internal data, TechCrunch has learned. Can Yoleri, a security researcher at threat…

BMW security lapse exposed sensitive company information, researcher finds

KTrust, a Tel Aviv–based security startup, is taking a different approach to Kubernetes security from many of its competitors in the space. Instead of only scanning Kubernetes clusters and their…

KTrust launches an automated red team for Kubernetes security

A user on the Twitter/X alternative Spoutible claims the company deleted their posts after they pushed Spoutible CEO Christopher Bouzy to be more honest about the nature of its recent…

Twitter rival Spoutible alleges smear campaign amid security breach controversy

Apple has removed a fake app that was masquerading as password manager LastPass on the App Store. The illegitimate app was listed under an individual developer’s name (Parvati Patel) and…

Apple pulled a fake app masquerading as password manager LastPass from the App Store

Don’t type anything into Gemini, Google’s family of GenAI apps, that’s incriminating — or that you wouldn’t want someone else to see. That’s the PSA (of sorts) today from Google,…

Google saves your conversations with Gemini for years by default