Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform 

gem-security-gets-$11-million-seed-investment-for-cloud-incident-response-platform 

Israeli venture group Team8 has bankrolled an $11 million seed-stage investment in Gem Security, a startup with ambitious plans in the cloud threat detection and incident response space.

Gem Security, based in Tel Aviv, emerged from stealth Wednesday with technology that promises to give corporate security teams a practical way to manage threat detection, investigation and response in cloud deployments.

The company said its product supports all major infrastructure platforms — AWS, Azure, Google Cloud and Kubernetes — and integrates with  identity providers, source code repositories and secrets managers, leveraging the additional data for context analysis. 

Gem Security and its investors are betting that there’s a growing market for enabling cloud security operations as attack surfaces expand exponentially with enterprise digital transformation activities. 

“The adoption of cloud infrastructure is increasing and diversifying the attack surface for organizations. 90% of all organizations use more than one cloud provider,” Gem Security said in a note announcing the funding.

“The expansion in attack surface is rarely paralleled with coverage by detection and response initiatives, leaving organizations unaware of a variety of threat vectors. 79% of companies have experienced at least one cloud data breach in the last 18 months, with 43% of companies reporting ten or more,” the company added.

While there is no shortage of products for detection and response, Gem Security is arguing that legacy approaches fall short of providing tooling for the cloud era. Today, the company says companies must work continuously on preparation, detection, investigation and response to cloud data threats. 

Related: Sentra Raises $30 Million for DSPM Technology

Related: What’s Going on With Cybersecurity VC Investments?

Related: Predictions 2023: Big Tech’s Coming Security Shopping Spree

The post Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform  appeared first on SecurityWeek.

Sentra Raises $30 Million for DSPM Technology

sentra-raises-$30-million-for-dspm-technology

Sentra, a cloud data security company with roots in New York and Tel Aviv, has raised a $30 million funding round as investors continue to place big bets on the DSPM (data security posture management) category.

The $30 million Series A comes just 18 months after Sentra’s launch with backing from Bessemer Venture Partners and brings the total raised to $53 million.

Sentra said it attracted several new investors in the latest round, including Standard Investments, Munich Re Ventures, Moore Strategic Ventures, Xerox Ventures and INT3.

Sentra is among a cadre of well-funded startups — Symmetry Systems ($15 million raised), Veza ($110 million raised), Dig Security ($45 million funding) Laminar ($30 million), Securiti.ai ($81 million) and Normalyze ($22 million) — selling machine learning technology and tools to help businesses pinpoint security risks to digital assets in multi-cloud environments. 

The company, which maintains headquarters in Tel Aviv, Israel, is working on technology to allow security teams to gain full visibility and control of cloud data, as well as protect against sensitive data breaches across the entire public cloud stack. 

Sentra said its software can automatically detect if sensitive data is vulnerable due to misconfigurations, over-permissions, unauthorized access, data duplication or other security issues. 

Related: What’s Going on With Cybersecurity VC Investments?

Related: Data Security Company Symmetry Systems Raises $15 Million

Related: Normalyze Announces $22 Million for DSPM Technology

The post Sentra Raises $30 Million for DSPM Technology appeared first on SecurityWeek.

Microsoft’s Verified Publisher Status Abused in Email Theft Campaign

microsoft’s-verified-publisher-status-abused-in-email-theft-campaign

Microsoft and cybersecurity firm Proofpoint on Tuesday warned organizations that use cloud services about a recent campaign that involved malicious OAuth applications and abuse of Microsoft’s ‘verified publisher’ status.

The campaign mainly targeted Microsoft customers in Ireland and the UK. The tech giant has taken steps to disrupt the operation and it has published an article on how users can protect against these threats, which the company calls ‘consent phishing’.

In a consent phishing attack, a threat actor attempts to trick a targeted user into granting permissions to their malicious cloud applications. Once they have obtained the required permissions, the malicious apps can gain access to legitimate cloud services and user data. 

In a campaign uncovered by Proofpoint in December 2022, hackers created malicious OAuth apps and then obtained a ‘verified publisher’ status in an effort to increase their chances of tricking users.

According to Microsoft, the attackers impersonated legitimate companies when enrolling in the Microsoft Cloud Partner Program (MCPP). 

“The actor used fraudulent partner accounts to add a verified publisher to OAuth app registrations they created in Azure AD,” Microsoft explained. 

This made it more likely for targeted users to grant permissions to the malicious applications. These permissions included reading emails, changing email settings, and accessing files and other user data, such as calendar and meeting information.

Microsoft’s investigation showed that the attackers used the malicious OAuth applications to exfiltrate emails. 

According to Proofpoint, the attackers used three malicious apps created by three different publishers. They all used the same malicious infrastructure and targeted the same organizations. 

“The potential impact to organizations includes compromised user accounts, data exfiltration, brand abuse of impersonated organizations, business email compromise (BEC) fraud, and mailbox abuse,” Proofpoint said. “The attack was less likely to be detected than traditional targeted phishing or brute force attacks. Organizations typically have weaker defense-in-depth controls against threat actors using verified OAuth apps.”

According to Proofpoint, the campaign ran until December 27. The security firm observed attacks against financial and marketing staff, as well as executives and managers. 

Microsoft said it became aware of the campaign on December 15. The company has disabled all fraudulent applications and alerted affected customers. 

Microsoft recently also dismantled a campaign that leveraged a network of single-tenant OAuth applications for the distribution of spam

Related: GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

Related: CircleCI Hacked via Malware on Employee Laptop

Related: Okta Source Code Stolen by Hackers

The post Microsoft’s Verified Publisher Status Abused in Email Theft Campaign appeared first on SecurityWeek.