NIBS (credit image/Pixabay/ Ryan McGuire)It was a busier week than the week before and one dominated by a single story — CrowdStrike. The company pushed an automatic update to more than 24,000 companies that hosed their Windows servers and desktops, causing global chaos as systems failed.

In other news, Bluevoyant unveiled a new security operations platform called the Cyber Defence Platform. It brings all its offerings under a single banner, combining internal, supply chain, and external defence solutions and giving IT security teams a single cloud-native platform to manage their cyber defence posture.

WaveBL has adopted the GLEIF Legal Entity Identifier (LEI) to help it identify shippers. It will use them to confirm the digital identity data of the shippers, consignees, and other legal entities engaged in the movement of goods worldwide.

Cloud-based threat detection company Tracebit has secured US$5 million in seed funding. Accel led the round, which included a raft of other investors. The funds will be used for product and sales development.

Apricorn has discovered that 17 councils in the UK had over 5,000 data breaches in 2023. Almost 60% of the breaches were recorded at five councils. Those breaches involved lost devices, laptops, and tablets.

PureCyber has secured a £5 million investment from growth capital investor BGF. The investment will help it grow its market share and work on product development.

Threathunter.AI will be at Defcon 32 and Vetcon. At the latter, it is bringing back its whiskey-tasting event run by James McMurry, CEO. Vetcon is a major event for all veterans operating in cybersecurity.

CultureAI has closed a US$10 million Series A funding round led by Mercia Ventures and Smedvig Ventures. Over the next 12 months, the company plans to invest in product development and double its headcount. Additionally, it plans to increase its market profile and presence in the US.

ORO Labs has become the first organisation in the world to be awarded ISO 42001 certification for AI Systems Management.

Jumpcloud has released its Q3 2024 SME IT Trends Report, “Detours Ahead: How IT Navigates an Evolving World.” It highlights concerns over Shadow IT, cyberattacks, AI, device sprawl, funding, a lack of resources and staffing.

FBI

New EAD for Criminal, Cyber Response and Services

Michael D Nordwall has been appointed the new executive assistant director of the Criminal, Cyber, Response, and Services Branch at FBI Headquarters in Washington, DC. Mr. Nordwall will oversee all criminal and cyber investigations worldwide, as well as international operations, critical incident responses, and assistance to victims.

Nordwell joined the FBI in 2002 and has worked in various offices, including those dealing with drug gangs and counterterrorism.

Chicago man jailed for cyber fraud

Charles Boyd, of Chicago, IL, has been sentenced to 33 months in prison. He was convicted of involvement in a business email compromise (BEC) case. Along with several unknown co-conspirators, they gained access to a mortgage company’s email server in 2019.

Once inside the server, they monitored for emails showing completion dates and money transfers. Boyd set up bank accounts using forged documents and sent spoofed emails to customers to redirect the money. Over $400,000 was stolen, and no repayment option was included in the sentence.

Boyd is serving an 18-month sentence for a separate financial fraud scheme in Wisconsin. Once that sentence is complete, Boyd will begin serving his 33-month sentence in this case.

Nigerian, extradited from UK, pleads guilty to real estate phishing scam

Kolade Akinwale Ojelade, a 34-year-old Nigerian national living abroad in Leicester,  pleaded guilty on Wednesday to wire fraud affecting a financial institution and aggravated identity theft. He now faces a 32-year sentence and will be deported upon completion.

According to court documents, Mr. Ojelade sent phishing emails to real estate businesses and gained unauthorized access to many accounts. He used this to monitor accounts for large transactions about to take place. He then intercepted wire payment instructions, changed the information, and resent the emails via spoofed emails that mimicked the original senders’ addresses.

Forescout

Forescout Technologies, Inc. has achieved two new milestones in its strategic partnership with Microsoft. Its Risk and Exposure Management (REM) solution is available on Microsoft Azure, and two new integrations with Microsoft Copilot for Security have been launched.

Barry Mainz, CEO, Forescout, said, “As enterprises increasingly converge IT and OT resources — including cloud endpoints and unmanaged, unagentable assets — they require enterprise-ready solutions that enforce consistent governance and control. Together, we empower security leaders to integrate and enhance their security programs seamlessly.”

National Cyber Security Centre

The National Cyber Security Centre (NCSC) has issued a warning over last week’s CrowdStrike-inspired global IT meltdown. It says that organisations should follow the instructions from CrowdStrike and apply patches. It also warns of phishing campaigns that seek to reference the outage.

noyb

noyb has released a video and presentation looking at amendments to the Commission’s draft GDPR procedural regulation. National DPAs are supposed to cooperate when dealing with complaints and enforcement against organisations. That is not currently the case, due to the mismatch between national laws.

To address this, the European Parliament and the Council of the EU have each issued a proposal to improve this. The release links back to all the supporting documents, a video, and a PDF from noyb. It believes that the version from the Parliament is easier to understand. It also says there is another set of proposals for Article 65/66, at which point it will publish a full written comparison.

Security news from the week beginning 8 July 2024

LEAVE A REPLY

Please enter your comment!
Please enter your name here