European venture capital and private equity firm Smartfin on Tuesday announced a deal to acquire Hex-Rays, the Belgian company behind the widely deployed IDA Pro software disassembler.
Microsoft Warns of New Zero-Day; No Fix Yet For Exploited Exchange Server Flaws
Microsoft on Tuesday released software fixes to address more than 90 security defects affecting products in the Windows ecosystem and warned that one of the vulnerabilities was already being exploited as zero-day in the wild.
Endor Labs Joins Race to Secure Software Supply Chain
It’s officially a venture capital funding frenzy in the software supply chain security space.
Threat Modeling Firm IriusRisk Raises $29 Million
Former Uber CISO Joe Sullivan Found Guilty Over Breach Cover-Up

A San Francisco jury on Wednesday found former Uber security chief Joe Sullivan guilty of covering up a 2016 data breach and concealing information on a felony from law enforcement.
KKR Boosts NetSPI Stake with $410 Million Investment
Private equity giant KKR is expanding its big bet on penetration testing and attack surface management firm NetSPI with a new $410 million investment round.
DHS Tells Federal Agencies to Improve Asset Visibility, Vulnerability Detection
The Cybersecurity and Infrastructure Security Agency (CISA) this week published Binding Operational Directive 23-01 (BOD 23-01), which requires federal agencies to take the necessary steps to improve their asset visibility and vulnerability detection capabilities within the next six months.
Investors Bet on Ox Security to Guard Software Supply Chains
The funding frenzy in the software supply chain space now includes Ox Security, an early-stage Israeli startup that just raised a whopping $34 million in seed-stage financing.
Report Shows How Long It Takes Ethical Hackers to Execute Attacks
A survey of more than 300 ethical hackers conducted by cybersecurity companies Bishop Fox and SANS Institute found that many could execute an end-to-end attack in less than a day.













