Google Acquires its First Non-American Cybersecurity Firm

Google Acquires its First Non-American Cybersecurity Firm

American technology company Google has acquired the Israel-based cybersecurity startup Siemplify.

Alphabet Inc-owned Google confirmed the acquisition by its cloud division on Tuesday and said that Siemplify’s security platform would be integrated into its cloud. 

While the deal’s financial details were not made public by the companies involved, Israel-based technology news website CTech reported the acquisition as costing Google an estimated $500m. 

Reuters reported that an unnamed source familiar with the inner workings of the transaction said Google had paid $500m in cash for Siemplify. 

Siemplify is a single-platform solution that offers vendor-agnostic security orchestration, automation, and response (SOAR) services. It was founded in Tel Aviv in 2015 by Alon Cohen, Garry Fatakhov and Amos Stern, who serves as the company’s chief executive officer.

Stern described Google Cloud as a partner with a shared mission, vision, values, and culture.

“We’re excited to join Google Cloud and build on the success we’ve had in the market helping companies address growing security threats,” said Stern.

“Together with Chronicle’s rich security analytics and threat intelligence, we can truly help security professionals transform the security operations center to defend against today’s threats.”

Siemplify employs more than 150 employees around the globe and counts FedEx, BAE Systems, Crowe, Telefonica, and Mondelez International among its clients. 

In a statement published Tuesday, Google Cloud security vice president and general manager Sunil Potti wrote that Siemplify will become part of Google Cloud’s security team “to help companies better manage their threat response.”

Siemplify was advised by Guggenheim Securities on the transaction.

The historic deal marks the first buyout of an Israeli cybersecurity firm by Google and its first acquisition in the cybersecurity industry outside the confines of the United States. 

It comes after Google’s August promise to United States president Joe Biden that it would invest $10bn in cybersecurity over the next five years. 

The acquisition of Siemplify brings the total number of Israeli companies bought by Google to four. Nine years ago, the US tech giant paid $1.1bn for navigation app Waze, founded in 2007 by Israeli trio Ehud Shabtai, Amir Shinar and Uri Levine. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UWO Opens New Cybersecurity Center

UWO Opens New Cybersecurity Center

The University of Wisconsin–Oshkosh (UW Oshkosh) has opened a new cybersecurity center.

The Cybersecurity Center of Excellence was delivered in partnership with the Wisconsin Cyber Threat Response Alliance (WICTRA), a Madison-based nonprofit information technology and services organization.

Sited in the Culver Family Welcome Center on the university’s Oshkosh campus, the Center of Excellence will support research, training and outreach in the field of cybersecurity among both university students and Wisconsinites.

Among the new center’s features are classrooms, a training lab, a small data center and a live-fire cyber range that allows users to take on threats facing the cybersecurity industry today within a controlled learning environment.

Michael Patton, UW Oshkosh information systems lecturer and the director of the new center, said that the new facility’s goal was to demystify cybersecurity for students and the wider Oshkosh community.

“There is no Wisconsinite today who doesn’t have a cyber presence – from a Facebook account to your banking information. And yet, to most people, cybersecurity is this mysterious, specialized body of knowledge that they hope ‘the experts’ are taking care of for them,” said Patton.

“In reality, cybersecurity is more like automotive knowledge: You may not know how all of the systems in your car work, but you have to know about filling it up and when to change the oil. Our goal is to take away the mystery and intimidation so we can elevate everyone’s cybersecurity awareness one notch.”

Students at the university will be offered the chance to expand their cybersecurity awareness and learn marketable skills through free courses, events, lab work, and internship opportunities.

Plans are also under way to create a cybersecurity training program and related practical workshops for local schools and the wider Oshkosh community.

“We really want to be the embodiment of the Wisconsin idea that the universities here in the UW system are not just here to educate students, but to be meaningful in the lives of everyday Wisconsinites,” said Patton.

Services offered to K-12 schools via the new center will include a mobile lab for classroom activities, IT staff training, guest speakers, competitions, and summer camps.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Money Launderers Get 33 Years for £70m Criminal Scheme

Money Launderers Get 33 Years for £70m Criminal Scheme

Two foreign nationals have been handed down what are believed to be among the most severe sentences on record for money laundering.

Artem Terzyan, 38, from Russia, was jailed for 17 years, while 44-year-old Lithuanian national Deivis Grochiatskij received 16 years following a four-year operation by the National Crime Agency (NCA) and Metropolitan Police Service unit.

Reporting restrictions were recently lifted following their December sentencing at Kingston Crown Court.

Officers first caught wind of their illegal activity after tracking a car linked to a money laundering gang back to a luxury East London apartment block the pair lived in.

Large bags of cash were observed being transferred to the building. The duo subsequently opened multiple bank accounts under the names of fake businesses and deposited tens of thousands of pounds at a time.

“The money would be sent from one shell company to another in a complex web of transfers, before it was sent out to international accounts held in countries including Germany, Czech Republic, UAE, Hong Kong, and Singapore,” said the NCA.

Following the 2018 arrest of Terzyan and Grochiatskij, police found hand-written ledgers detailing the laundering activity. They also discovered a computer with evidence of the shell companies the duo set up and even incriminating photos of conspirators handling cash in Grochiatskij’s living room.

A financial investigator estimated that they had laundered £36m in 2017-2018, £16m of which came from cash deposits.

While out on bail, the pair claimed fraudulent government Bounce Back Loans for the shell companies they’d set up, to the tune of over £10m. According to the NCA, they claimed £3.2m from a single bank.

Their ability to operate these schemes at such scale and defraud taxpayers of millions of pounds points to a broken anti-money laundering (AML) regime in the UK.

High street lender NatWest was recently fined a record £264m after admitting it failed to stop a major five-year money laundering operation.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

UK Defence Academy Attack Forced IT Rebuild – Report

UK Defence Academy Attack Forced IT Rebuild – Report

A possible nation-state attack on the UK’s primary defense training facility last year forced the academy to rebuild its IT infrastructure, according to a former senior officer.

Air marshal Edward Stringer served as director-general of joint force development and of the UK Defence Academy before recently retiring.

The academy trains nearly 30,000 UK armed forces personnel annually, alongside civil servants and military staff from other nations.

However, it was caught out by a cyber-attack last March, which had “significant” operational consequences, Stringer told Sky News.

Although no sensitive information is thought to have been stolen, teaching was disrupted as courses moved online due to the pandemic.

“It doesn’t look like a violent attack, but there were costs. There were costs to … operational output. There were opportunity costs in what our staff could have been doing when they were having to repair this damage,” Stringer said.

“What could we be spending the money on that we’ve had to bring forward to rebuild the network? There are not bodies in the streets, but there’s still been some damage done.”

That rebuilding process appears still to be in progress, with a note on the current Defence Academy website stating: “new website coming soon … please bear with us while we continue to update our site … check back soon for updates.”

The IT systems at the academy, including website maintenance, are reportedly managed by outsourcing provider Serco.

While China, Russia and other hostile nations would undoubtedly have had the motivation to launch an attack, Stringer fell short of attributing it to state-backed operatives.

“It could be any of those or it could just be someone trying to find a vulnerability for a ransomware attack that was just, you know, a genuine criminal organization,” he reportedly said.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Microsoft Fixes New Year’s Day Exchange Server Bug

Microsoft Fixes New Year’s Day Exchange Server Bug

Microsoft has released a fix for a problem with Exchange Server that led to corporate emails being left undelivered at the start of the new year.

In an update on January 1 2022, the computing giant revealed that messages were stuck in transport queues of on-premises Exchange Server 2016 and Exchange Server 2019.

Although the problem was traced back to a “date check failure” in Exchange Server’s malware scanning engine, the feature was otherwise unaffected, Microsoft explained.

“The problem relates to a date check failure with the change of the new year and not a failure of the AV engine itself,” it said.

“This is not an issue with malware scanning or the malware engine, and it is not a security-related issue. The version checking performed against the signature file is causing the malware engine to crash, resulting in messages being stuck in transport queues.”

Microsoft announced two ways for admins to fix the problem: an automated and a manual solution. The former requires them to download a script to each Exchange mailbox server that downloads the anti-malware update.

The manual option requires IT teams to verify the impacted Exchange Server version is installed, remove the existing anti-malware engine and metadata, update to the latest version and verify engine update info.

Microsoft warned that even the automated solution “will take some time” to clear message queues, although the script has the advantage of being able to run on multiple servers in parallel.

“Please be patient and monitor those queues are draining (number of messages are decreasing) by using Get-queue command,” it added.

The incident marks an inauspicious start to the year after a festive period during which many IT teams were forced into overtime to detect and patch Log4j instances across their organization.

Since the discovery of the first vulnerability in the popular Java logging utility, rated CVSS 10.0, a further four bugs have been published. The most recent (CVE-2021-44832) was described as a “moderate” severity remote code execution flaw in version 2.17.0

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains