Enterprise software vendor Twilio (NYSE: TWLO) has been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.
Ghost Security Snags $15M Investment for API Security Tech
Texas startup Ghost Security has joined the list of early-stage companies in the API and application security space attracting venture capital funding.
The Austin-based company emerged from stealth this week with $15 million in investments from 468 Capital, DNX Ventures, and Munich Re Ventures.
Slack Forces Password Resets After Discovering Software Flaw
Workplace productivity software giant Slack on Friday forced password resets for a tiny fraction of its users after the discovery of a security flaw that exposed Slack credentials.
Slack’s security response team alerted users to the issue via email and followed up with a blog post warning about the risk of passwords leaking to a skilled attacker.
Compliance Automation Startup RegScale Scores $20 Million Investment
RegScale, a Virginia startup building technology to manage continuous compliance automation tasks, has attracted $20 million in early-stage venture capital funding.
The Series A round was led by SYN Ventures with participation from SineWave Ventures, VIPC’s Virginia Venture Partners and SecureOctane.
Robinhood Crypto Penalized $30M for Violating NY Cybersecurity Regulations
Thoma Bravo to Acquire Ping Identity for $2.8 Billion
Enterprise identity and access management firm Ping Identity (NYSE: PING) announced Wednesday that it has agreed to be acquired by private equity (PE) firm Thoma Bravo for roughly $2.8 billion in cash.
VMware Ships Urgent Patch for Authentication Bypass Security Hole
Virtualization technology giant VMware on Tuesday shipped an urgent, high-priority patch to address an authentication bypass vulnerability in its Workspace ONE Access, Identity Manager and vRealize Automation products.
Microsoft Connects USB Worm Attacks to ‘EvilCorp’ Ransomware Gang
Cybersleuths at Microsoft have found a link between the recent ‘Raspberry Robin’ USB-based worm attacks and EvilCorp, a notorious Russian ransomware operation sanctioned by the U.S. government.
GitHub Improves npm Account Security as Incidents Rise
Microsoft-owned GitHub this week announced new npm security improvements, amid an increase in incidents involving malicious npm packages.
Calls Mount for US Gov Clampdown on Mercenary Spyware Merchants
Cybersecurity professionals from Google’s threat hunting unit and the University of Toronto’s Citizen Lab are upping the pressure on mercenary hacking firms selling high-end surveillance spyware with fresh calls for the U.S. government to urgently clamp down on these businesses.



