A Security has emerged from stealth with $37 million in funding led by Lightspeed Venture Partners and Cyberstarts, with angel backing from Wiz chief executive Assaf Rapaport and Cyera chief executive Yotam Segev, to build an autonomous offensive security platform that identifies and remediates exploit paths before attackers can use them. Chief executive and co-founder […]
Cyera's rapid growth underscores the increasing demand for robust AI security solutions, highlighting the critical need for data protection in AI-driven enterprises.
The post Cyera secures $600M to expand AI security trust platform appeared first on Crypto Briefing.
Sandstone has raised $30 million in a Series A funding round led by Lightspeed Venture Partners, to support the development of AI-native legal departments – ...
Data security startup Cyera is finalising a funding round of at least $300 million led by Evolution Equity Partners at a $12 billion valuation, according to sources familiar with the deal — just five months after raising a $400 million Series F at a $9 billion valuation led by Blackstone. The new round would bring Cyera’s total […]
A widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks.
Researchers at Cyera have disclosed six vulnerabilities affecting “protobuf.js,” all stemming from the library’s handling of schema and metadata. Attackers could exploit an input validation oversight to insert malicious data and influence an application’s behavior.
Protocol Buffers is a technology for packaging data in a compact, structured format to streamline the exchange of information between different applications. The protobuf.js library reportedly receives more than 50 million weekly downloads. It is commonly pulled into applications indirectly through dependencies such as gRPC tooling, Google Cloud libraries, and other frameworks, making it difficult for organizations to track.
Researchers disclosed six CVEs covering remote code execution, denial-of-service (DoS) conditions, prototype
Developers who pulled packages from Red Hat’s @redhat-cloud-services npm namespace over the weekend got a secret-stealing worm instead.
Security researchers from several cybersecurity outlets are warning of a new supply chain attack compromising over 30 Red Hat Cloud Services-related npm packages to steal credentials, authentication tokens, and other secrets from developer environments.
The campaign, which Wiz researchers are tracking as Miasma, is thought to be the latest evolution of Shai-Hulud, a self-propagating malware family that has repeatedly surfaced in software supply chain attacks targeting the npm ecosystem.
“Investigation revealed that at least 32 package releases contained unauthorized modifications that do not match the corresponding source repositories,” Wiz researchers said in a blog post. “These packages cumulatively average ~80,000 weekly downloads.“
By compromising packages associated with Red Hat Cloud Services, the attackers are targeting a software ecosystem that
Insider Brief PRESS RELEASE — Reactor, the developer platform for real-time generative video, emerged from stealth with $59 million in funding led by Lightspeed Venture Partners, with participation from WndrCo, Amplify Partners, Sky9 Capital, FPV Ventures, and additional investors. Reactor is building the infrastructure layer that makes real-time world models accessible to developers, enabling a new generation […]