Uber breaches, security awareness saturation, cybercrime P&L, sad acquisitions and AI – ESW #319
- Our teams from Security Weekly and SC Media were onsite at RSA Conference 2023 delivering in-depth reporting, analysis and interviews from the conference. If you were unable to join us in person, or didn't manage to catch our video livestream from Broadcast Alley, you can access all of our RSAC 2023 coverage at https://securityweekly.com/rsac.
Adrian Sanabria
- FUNDING: Kubernetes and sigstore founders raise $17.5M to launch software supply chain startup Stacklok
- FUNDING: Exclusive: Manifest Cyber raises $6M, unveils new government contracts
- FUNDING: SpiderOak Secures Investment from Accenture, Raytheon Technologies & Stellar Ventures
- FUNDING: Visibility-First Zero Trust Networking Platform Lumeus.ai Launches With $6M Seed
Really not seeing how they're working AI/ML into this...
- FUNDING: Entro raises $6M for its end-to-end secrets security solution
- FUNDING: Cork Raises $6M in Seed Funding
- FUNDING: Lakeland cyber startup closes $5.5M in oversubscribed round
An oversubscribed round for security awareness training? Either there's something unique here, or I'm missing something. Kinda late to be bringing security awareness to the market now.
- FUNDING: CISO Global Inc. Announces Pricing of $4.0 Million Registered Direct Offering
- ACQUISITIONS: Data443 Expands Its Global Customer, Technology Base with Transformative Acquisition of Select Israel-based Cyren Ltd. Assets
Threat intel assets only - we talked about Cyren going under earlier this year. Good news is that they were able to sell off some of their assets. Bad news is that the assets were only worth $3.5M.
- ACQUISITIONS: Curity Secures Investment to Scale Growth in API-Driven Identity Management
Article describes it as an "investment" from a PE firm, but Mike Privette describes it as an acquisition.
- ACQUISITIONS: Amsterdam’s EclecticIQ sells its agent software and engineering assets to US-based ReliaQuest
Talent and assets acquisition
- TRENDS: Ransomware resurgence after ‘strange year’ in 2022, insurance data shows
- TRENDS: Concerns around the new .zip gTLD, from @_sn0ww
I’ve seen a lot of concern around the new .zip gTLD.
Let’s look a little deeper into what this means, from my (attacker) perspective.
- AI TRENDS: Drag Your GAN: Interactive Point-based Manipulation on the Generative Image Manifold
- STANDARDS: Equifax Controls Framework
Did we really need another standards framework?
- STANDARDS: OWASP Top 10 for Large Language Model Applications
- ESSAY: Understanding the RSA Conference iceberg: revealing the unknown truths and explaining the well-known concepts
- ESSAY: The AI Attack Surface Map v1.0
- CYBERCRIME: Suspicion stalks Genesis Market’s competitors following FBI takedown
Is VAPEMASTER3000 really a fellow cybercriminal, or is he an FBI mole? #BadGuyProblems
- BREACHES: Former Uber CSO Joe Sullivan and lessons learned from the infamous 2016 Uber breach
- BREACHES: Uber Data Breaches: Full Timeline Through 2023
- SQUIRREL: Montana governor bans TikTok
- SQUIRREL: AN ACT BANNING TIKTOK IN MONTANA
I'm quoting directly from the law here: WHEREAS, TikTok fails to remove, and may even promote, dangerous content that directs minors to engage in dangerous activities, including but not limited to:
- throwing objects at moving automobiles
- taking excessive amounts of medication
- lighting a mirror on fire and then attempting to extinguish it using only one's body parts
- inducing unconsciousness through oxygen deprivation
- cooking chicken in NyQuil
- pouring hot wax on a user's face
- attempting to break an unsuspecting passerby's skull by tripping him or her into landing face first into a hard surface
- placing metal objects in electrical outlets
- swerving cars at high rates of speed
- smearing human feces on toddlers
- licking doorknobs and toilet seats to place oneself at risk of contracting coronavirus
- attempting to climb stacks of milk crates
- shooting passersby with air rifles
- loosening lug nuts on vehicles
- stealing utilities from public places
Prepping for Security Incidents, Automated Validation & No-Code Automation Revolution – Amitai Ratzon, Jon Check, Thomas Kinsella – ESW #319
Jon Check is the Vice President of Cyber Protection Solutions at Nightwing. He
leads the team that delivers proactive cybersecurity and next-generation technology to protect customers from persistent cybersecurity threats. Prior to this role, Jon held executive positions at Raytheon, CSRA Inc, and IBM Global Business Services. Jon is also a board member and former chairman of the National Cybersecurity Alliance, a board member of the U.S. Cyber Games, and an AFCEA DC board member. He holds a Bachelor of Arts in environmental science from the University of Virginia.
Thomas Kinsella is the co-founder and CCO of Tines, a no-code automation platform for security teams. Before Tines, Thomas led security teams in companies like Deloitte, eBay, and DocuSign. As CCO, Thomas is responsible for customer success, professional services, and more. Thomas has a degree in Management Science and Information Systems Studies from Trinity College in Dublin.
Digital Trust as a Strategic Imperative & Insights from RSA Conference 2023 – Deepika Chauhan, Steve Ragan – ESW #319
Before joining the journalism world in 2005, Steve spent 15 years doing consulting and freelance contracting within the IT space, with a focus was on infrastructure management and security.
His award-winning journalism career covering the security industry lasted for more than a decade. After leaving journalism in 2018, he went back into the security field doing threat research and editorial work, where he remains to this day.
He’s a father of two, grandfather of two, and spends his free time gaming.
Deepika Chauhan is the Chief Product Officer at DigiCert. She leads a global team of customer-obsessed product managers and engineers, responsible for continued innovation on DigiCert ONE, the platform for digital trust. Chauhan oversees the overall product strategy to ensure that organizations from the largest enterprises to SMBs can provide comprehensive trust and security across all of their devices, users, servers, software and content.
Chauhan has a wealth of experience in product development, business strategy, marketing, sales and organizational transformation. Prior to DigiCert, Chauhan led Strategy and Business Operations for the Website Security Business Unit at Symantec. Before Symantec, she was at McKinsey & Company, working with a number of different area tech companies on some of their most strategic initiatives. Prior to McKinsey, she led product development as part of the mobile browser team at Nokia for several years.

