www.fgks.org   »   [go: up one dir, main page]

AI

Bolster, creator of the CheckPhish phishing tracker, raises $14M led by Microsoft’s M12

Comment

Deepfake or Deep Fake Concept as a symbol for misrepresenting or identity theft or faking identification and misrepresentation in a 3D illustration style.
Image Credits: wildpixel (opens in a new window) / Getty Images

A dodgy email containing a link that looks “legit” but is actually malicious remains one of the most dangerous, yet successful, tricks in a cybercriminal’s handbook. Now, an AI startup called Bolster that has built a novel approach to tackle that trick has raised $14 million in funding to expand its work, both across a popular free phish-checking portal it operates called (appropriately) CheckPhish, as well as with its primary paying customers: brands and other businesses.

Microsoft’s venture fund M12 led the round as a new backer in the company, with participation also from Thomvest Ventures, Crosslink Capital, Liberty Global Ventures, Cheyenne Ventures, Cervin Ventures and Transform Capital. Bolster’s not disclosing its valuation but it has now raised around $40 million. 

Bolster’s business model is based around providing brand and URL checking services to businesses that spend a lot of time emailing their customers, and thus are prime candidates for malicious hackers to imitate in hopes of tricking people, or to simply copy with branding to sell products of their own. (Its client list includes big names like Dropbox, Uber, LinkedIn and Coinbase.) Phishing, according to the Cybersecurity Infrastructure Security Agency, is the start of more than 90% of all “cyberattacks,” which might include data breaches, network infiltrations or device viruses.

The ability to set up suspiciously similar-looking domain pages for these companies, and to start using them to run malicious phishing activities, has become very cheap and easy to do. 

“There are tools that you can purchase for $10 or $20 to launch phishing attacks,” said Bolster CTO Shashi Prakash (who co-founded the company with CEO Abhishek Dubey) in an interview. With malicious hackers now well versed in using AI, they create realistic login pages for banks, for example, and use phishing-as-a-service to launch these attacks “within minutes.” 

These have become more sophisticated, and more targeted, over time, he said. One recent example was the incident involving the CEO of WPP, Mark Read, who was at the center of a scam to try to solicit money. It sounds improbable when you read that out, and indeed it was unsuccessful, but it is just a sign of where these scams are going.

Bolster’s approach uses machine learning algorithms and AI techniques to track the wider internet — URLs, domain registration databases, conversations in open and closed forums and social media platforms, as well as emails (when it works with a client) and more — to detect scam operations, which it does on a continuous basis. When it identifies iffy links, it then shuts them down at their root by way of automated takedowns.

The approach is notable because it complements the myriad email security products that are on the market today that are adopted by organizations to help filter emails as they come into a person’s inbox: That’s still important as one mechanism to halt phishing activity. But in cases where those bad links pass through the gates unencumbered, the idea here is that, if a person does click on a link, now that person might not get anywhere. 

Considering that the wider funnel of email can be so complicated to contain, and hackers themselves makes themselves hard to find, identifying and shutting down the root of their operations becomes very valuable. 

“One of the advantages that Bolster has is its ability to automatically shut down where these attacks are originating from, they can shut down where those are hosted,” said Todd Graham, managing partner at M12, in an interview. “That is really, really important, given the scale at which these criminal enterprises operate.” Microsoft does not yet work directly with Bolster, Prakash said, but the idea is that this investment is a signal of how they will in the future.

Microsoft’s interest would be on a couple of levels: The company is a major international brand in itself, operating a number of services that would trigger emails to users (and I can personally attest to getting way, way too many “account login” emails from suspicious “Microsoft” links). On top of that, it’s a provider of cloud and managed and software services to numerous businesses, and thus an important link through to a large market of would-be customers. Lastly, it’s making a major move into putting more AI into all aspects of its business, and so threat protection inevitably has to be a part of that equation, too.

Graham added that while the company is effectively just a B2B business — with even the CheckPhish tool aimed at scanning websites rather than offering tools to individual users — the fact that it works with big brands by default gives it a consumer angle, in that it’s ultimately aiming at protecting the customers of the business in question. 

“If you are getting an impersonated email that claims to be from Microsoft, but it probably isn’t, it’s in the best interest of Microsoft or Wells Fargo or whoever, to ensure that that email, if it does go out, gets detected.”

More TechCrunch

As browsers continue to add AI features into their products, Mozilla is looking give users some choice in the matter. The company announced on Tuesday that it’s launching an opt-in…

Firefox now lets you choose your preferred AI chatbot in its Nightly builds

Smart ring makers Oura and Circular Tuesday announced a settlement in an ongoing patent suit. The agreed-upon terms find the French company entering into a multi-year agreement with Oura, wherein…

Circular will pay competitor Oura royalties to sell its smart ring in the US

The new addition was inspired by the video-sharing activity that was already taking place on apps like TikTok.

Inspired by Gen Z, Pinterest users can now turn boards into videos for sharing on Instagram and TikTok

Stability AI, the beleaguered generative AI startup behind Stable Diffusion, has raised new cash. But it won’t reveal how much. Greycroft, Coatue Management, Sound Ventures, Lightspeed Venture Partners, O’Shaughnessy Ventures…

Stability AI lands a lifeline from Sean Parker, Greycroft

London-based internet rights monitoring group NetBlocks has reported a major internet disruption in Kenya following a wave of demonstrations across the country, as police violently cracked down on citizens taking…

Internet goes dark in Kenya in the wake of major protests over finance bill

Waymo no longer has a waitlist for its San Francisco robotaxi service, removing the final obstacle for customers keen to use the self-driving technology.  Waymo said Tuesday that anyone can…

Waymo dumps its waitlist and opens up its San Francisco robotaxi service to everyone

Popular productivity tool Notion has long allowed its users to make any of their pages public. Now, the company is expanding on this with the launch of Notion Sites, which…

Notion Sites takes Notion sites up a level

Investors, you know you need to keep your pipelines primed, and one of the best places to find early-stage startups with promising portfolio potential is, you guessed it, TechCrunch Disrupt.…

Maximize your deal flow at TechCrunch Disrupt 2024

Payabli builds the infrastructure that allows companies, specifically software companies, to embed and facilitate payments through APIs.

Payabli is building payment management tools for software startups

Patreon, the paid membership platform for creators, announced Tuesday the release of new features designed to help creators monetize their non-paying followers and tap into new revenue streams. This includes…

Patreon introduces a gifting feature and other creator tools

Google is rolling out a new Gemini AI side panel in Gmail that can help you write emails and summarize email threads. The company is also adding the Gemini side…

Google brings its Gemini AI to Gmail to help you write and summarize emails

iPhone Mirroring, one of the more notable features arriving in Apple’s upcoming operating systems, is now available to developers testing the beta versions of iOS 18 and macOS Sequoia. The…

Apple launches iPhone Mirroring on Mac in latest iOS and Mac betas

Tengo uses AI to find, evaluate and respond to public tenders. It’s a software-as-a-service tool that helps companies handle public tenders at scale — a bit like Govly in the…

Tengo untangles the messy world of public sector procurement with AI

Smashing is an AI and community-powered content recommendation app, now launching into an invite-only beta.

Smashing, from Goodreads’ co-founder, curates the best of the web using AI and human recommendations

Wisk Aero, a subsidiary of Boeing, has acquired Verocel, a software verification and validation company that’s served the aerospace industry for 25 years. 

Boeing’s Wisk Aero buys Verocel to boost software safety for its self-flying eVTOL

In 2024, it seems like no week goes by without a media organization, author group, or artist suing generative AI companies for using their work to train models without permission.…

Backed by David Sacks, Garry Tan and Walter Isaacson, Created by Humans helps people license their creative work to AI models

Coder’s open-source software has around 1.2 million monthly active users, and Dropbox, Discord and Skydio are among the company’s paying customers.

Coder nabs new funds to move dev environments to the cloud

Leveraging large languge models, Jobright created an AI agent that acts as a headhunter tailored to individual job seekers.

How Jobright uses AI to help foreign workers navigate the US job market

k-ID’s platform makes it easy for game devs to comply with child safety and data privacy regulations.

k-ID wins $45M to help game devs speedrun the child safety compliance puzzle

A startup called EvolutionaryScale, founded by ex-Meta researchers, has raised $142 million for its AI-powered protein-generating tech.

EvolutionaryScale, backed by Amazon and Nvidia, raises $142M for protein-generating AI

Don’t call this company a “ghost kitchen.” Since its Series A in 2021, Local Kitchens grew 5x and achieved unit-level profitability.

General Catalyst leads $40M round for Local Kitchens, a different kind of restaurant kitchen startup

Ashley Beckwith spent years of her academic and professional career focused on the intersection of biology, materials and manufacturing to build medical solutions more efficiently. When she realized the tech…

Foray Bioscience is breaking down the barriers of bringing biomanufacturing to plants

Etched, founded by Harvard dropouts, is building an AI chip that can only run one type of model: transformer-based models.

Etched is building an AI chip that only runs one type of model

Less than a year after closing its seed round, software-for-hardware startup Sift announced a $17.5 million Series A led by Google’s venture capital arm GV to scale their platform for…

Sift is building a better platform for analyzing hardware telemetry data

The acquisition allows Swipewipe’s founder to take some money off the table while also continuing to benefit financially from his work via an ongoing revenue-sharing agreement with MWM.

Gen Z photos app Swipewipe sells to French publisher MWM in its largest acquisition to date

As of today, nearly all of the world’s most popular website homepages are not compliant with the Web Content Accessibility Guidelines.

TestParty raises $4M to help automate the coding for accessible websites

Uber Freight and Aurora Innovation have announced a multi-year collaboration that will see Aurora’s autonomous driving technology offered on the Uber Freight network through 2030.  The deal gives Aurora access…

Uber Freight and self driving trucks startup Aurora partner for the long haul

The European Union accused Microsoft of breaching competition rules Tuesday. In a formal statement of objections the bloc said it suspects the software giant of abusing antitrust rules by bundling…

EU accuses Microsoft of competition breach over Teams bundling

Snapchat on Tuesday announced a new suite of safety features, including updates to its account blocking functionality and enhanced friending safeguards, making it difficult for strangers to contact users on…

Snapchat introduces new safety features to limit bad actors from contacting users

Rocketlane initially aimed to support customer onboarding. However, it has broadened its scope and doubled down on addressing the needs of professional services teams.

Rocketlane snags $24M to bring AI-led experiences for professional services teams