Application Security

9/25/2018
02:10 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Snyk raises $22 million Series B led by Accel to automatically fix vulnerable open source packages

Funding to scale Snyk's developer-first offering and build runtime malicious package protection

LONDON, 25th September 2018: Snyk, a company that helps organisations use open source code securely, today announces a $22 million Series B investment led by Accel, with participation from GV and existing investors Boldstart Ventures, Heavybit and others. 

Open source software (OSS) is embraced by over 95% of enterprises, which dramatically accelerates software development but also introduces substantial risk. Developers draw vast quantities of OSS components into their apps, unaware that many carry known vulnerabilities, or are outright malicious. In fact, 77% of applications carry such known vulnerabilities, and only one in four OSS maintainers audit their code regularly. Developers need tools to manage these large volumes of third-party software.

Snyk helps organisations use open source code and stay secure. Developers use Snyk to find and block vulnerable and malicious OSS components, building on a comprehensive database maintained by Snyk’s security research team. Snyk’s solution goes further and automatically fixes the discovered issues, patching over 580,000 vulnerabilities each month, and continuously protecting over 140,000 projects.

Founded by serial entrepreneur Guy Podjarny and security experts Assaf Hefetz and Danny Grander, Snyk was built on the belief that developers will embrace security if given the right tools. With 150,000 users, over 200 paying customers including New Relic, ASOS, Auth0, and Skyscanner, and revenue growing 5x in nine months, this is proving to be the case.

With this funding, Snyk will expand from fixing vulnerable OSS components to protecting them in runtime. Today’s applications run these components blindly, implicitly trusting the thousands of authors maintaining them. While most maintainers mean well, recent news clearly demonstrates that some may be compromised, insecure, or outright malicious. Snyk’s upcoming offerings will help organisations regain control and visibility when running these open source libraries. 

“Our mission is to fix open source security, and that can only be done from within the open source community,” said Guy Podjarny, CEO and co-founder of Snyk. “This investment is a humbling validation of the impact that security-conscious developers have, and lets us expand open source security into runtime while continuing to serve these amazing users.”

Snyk will use today’s investment to further scale its business across ecosystems while keeping users happy; define and grow the new category of runtime open source security; and continue investing in the secure developer community and leading the DevSecOps movement. 

Philippe Botteri, Partner at Accel, will be joining the Board as part of the round. He said: “Some of the largest data breaches in recent years were the result of unfixed vulnerabilities in open source dependencies; as a result, we’ve seen the adoption of tools to monitor and remediate such vulnerabilities grow exponentially. We’ve also seen the ownership of application security shifting towards developers. We feel that Snyk is uniquely positioned in the market given the team’s deep security domain knowledge and developer-centric mindset, and are thrilled to join them on this mission of bringing security tools to developers.” 

About Snyk

Snyk is a developer-first security solution that empowers developers to use open source code and stay secure. Building on its unique vulnerability database, Snyk continuously finds and fixes known vulnerabilities & license violations in open source components. Snyk integrates seamlessly into the developer workflow, tightly integrating with source control (e.g. GitHub), hooking into your CI/CD (e.g. Jenkins) pipelines and continuously monitoring PaaS and Serverless apps in production. Lastly, Snyk proactively fixes vulnerabilities using 1-click pull requests and patches.

 

About Accel

Accel is a leading venture capital firm that invests in people and their companies from the earliest days through all phases of private company growth. Atlassian, Algolia, Avito, Celonis, Cloudera, Crowdstrike, Deliveroo, DJI, Dropbox, Etsy, Facebook, Flipkart, Funding Circle, Kayak, Kry, QlikTech, Rovio, Slack, Spotify, Supercell, UIPath and WorldRemit are among the companies the firm has backed over the past 30 years. The firm seeks to understand entrepreneurs as individuals, appreciate their originality and play to their strengths. Because greatness doesn't have a stereotype. For more, visit www.accel.com,  www.facebook.com/accel orwww.twitter.com/accel

Notes to editors

 

- Two-minute Snyk product overview: https://www.youtube.com/watch?v=4ng5usM6fd8

- Snyk named Gartner Cool Vendor: https://snyk.io/blog/snyk-named-a-2018-gartner-cool-vendor-in-application-and-data-security

- Live exploits of an application through known OSS vulnerabilities (product showcase): https://www.youtube.com/watch?v=0dgmeTy7X3I

- Team pictures: https://snyk.io/about/

- Media pack (logo etc): https://snyk.io/press-kit  

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20050
PUBLISHED: 2018-12-10
Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method.
CVE-2018-20051
PUBLISHED: 2018-12-10
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.
CVE-2018-20029
PUBLISHED: 2018-12-10
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
CVE-2018-1279
PUBLISHED: 2018-12-10
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on ...
CVE-2018-15800
PUBLISHED: 2018-12-10
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.