Application Security

9/25/2018
02:10 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Snyk raises $22 million Series B led by Accel to automatically fix vulnerable open source packages

Funding to scale Snyk's developer-first offering and build runtime malicious package protection

LONDON, 25th September 2018: Snyk, a company that helps organisations use open source code securely, today announces a $22 million Series B investment led by Accel, with participation from GV and existing investors Boldstart Ventures, Heavybit and others. 

Open source software (OSS) is embraced by over 95% of enterprises, which dramatically accelerates software development but also introduces substantial risk. Developers draw vast quantities of OSS components into their apps, unaware that many carry known vulnerabilities, or are outright malicious. In fact, 77% of applications carry such known vulnerabilities, and only one in four OSS maintainers audit their code regularly. Developers need tools to manage these large volumes of third-party software.

Snyk helps organisations use open source code and stay secure. Developers use Snyk to find and block vulnerable and malicious OSS components, building on a comprehensive database maintained by Snyk’s security research team. Snyk’s solution goes further and automatically fixes the discovered issues, patching over 580,000 vulnerabilities each month, and continuously protecting over 140,000 projects.

Founded by serial entrepreneur Guy Podjarny and security experts Assaf Hefetz and Danny Grander, Snyk was built on the belief that developers will embrace security if given the right tools. With 150,000 users, over 200 paying customers including New Relic, ASOS, Auth0, and Skyscanner, and revenue growing 5x in nine months, this is proving to be the case.

With this funding, Snyk will expand from fixing vulnerable OSS components to protecting them in runtime. Today’s applications run these components blindly, implicitly trusting the thousands of authors maintaining them. While most maintainers mean well, recent news clearly demonstrates that some may be compromised, insecure, or outright malicious. Snyk’s upcoming offerings will help organisations regain control and visibility when running these open source libraries. 

“Our mission is to fix open source security, and that can only be done from within the open source community,” said Guy Podjarny, CEO and co-founder of Snyk. “This investment is a humbling validation of the impact that security-conscious developers have, and lets us expand open source security into runtime while continuing to serve these amazing users.”

Snyk will use today’s investment to further scale its business across ecosystems while keeping users happy; define and grow the new category of runtime open source security; and continue investing in the secure developer community and leading the DevSecOps movement. 

Philippe Botteri, Partner at Accel, will be joining the Board as part of the round. He said: “Some of the largest data breaches in recent years were the result of unfixed vulnerabilities in open source dependencies; as a result, we’ve seen the adoption of tools to monitor and remediate such vulnerabilities grow exponentially. We’ve also seen the ownership of application security shifting towards developers. We feel that Snyk is uniquely positioned in the market given the team’s deep security domain knowledge and developer-centric mindset, and are thrilled to join them on this mission of bringing security tools to developers.” 

About Snyk

Snyk is a developer-first security solution that empowers developers to use open source code and stay secure. Building on its unique vulnerability database, Snyk continuously finds and fixes known vulnerabilities & license violations in open source components. Snyk integrates seamlessly into the developer workflow, tightly integrating with source control (e.g. GitHub), hooking into your CI/CD (e.g. Jenkins) pipelines and continuously monitoring PaaS and Serverless apps in production. Lastly, Snyk proactively fixes vulnerabilities using 1-click pull requests and patches.

 

About Accel

Accel is a leading venture capital firm that invests in people and their companies from the earliest days through all phases of private company growth. Atlassian, Algolia, Avito, Celonis, Cloudera, Crowdstrike, Deliveroo, DJI, Dropbox, Etsy, Facebook, Flipkart, Funding Circle, Kayak, Kry, QlikTech, Rovio, Slack, Spotify, Supercell, UIPath and WorldRemit are among the companies the firm has backed over the past 30 years. The firm seeks to understand entrepreneurs as individuals, appreciate their originality and play to their strengths. Because greatness doesn't have a stereotype. For more, visit www.accel.com,  www.facebook.com/accel orwww.twitter.com/accel

Notes to editors

 

- Two-minute Snyk product overview: https://www.youtube.com/watch?v=4ng5usM6fd8

- Snyk named Gartner Cool Vendor: https://snyk.io/blog/snyk-named-a-2018-gartner-cool-vendor-in-application-and-data-security

- Live exploits of an application through known OSS vulnerabilities (product showcase): https://www.youtube.com/watch?v=0dgmeTy7X3I

- Team pictures: https://snyk.io/about/

- Media pack (logo etc): https://snyk.io/press-kit  

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Devastating Cyberattack on Email Provider Destroys 18 Years of Data
Jai Vijayan, Freelance writer,  2/12/2019
Up to 100,000 Reported Affected in Landmark White Data Breach
Kelly Sheridan, Staff Editor, Dark Reading,  2/12/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8360
PUBLISHED: 2019-02-16
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
CVE-2019-8361
PUBLISHED: 2019-02-16
PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection.
CVE-2019-8362
PUBLISHED: 2019-02-16
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg, .png, o...
CVE-2019-8363
PUBLISHED: 2019-02-16
Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value.
CVE-2019-8358
PUBLISHED: 2019-02-16
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.