shutterstock_490960141-1

Industry News: ESG5

      Know Your Breach: Trezor

      The Target: Popular hardware cryptocurrency wallet vendor Trezor

      The Take: A subset of 66,000 users who have interacted with Trezor Support since December 2021 may have had their names or usernames, and email addresses exposed to an unauthorized party.

      The Vector: Trezor has already confirmed 41 cases where exposed data has been exploited, with the attackers approaching users to trick them into giving away their recovery seeds - a string of words that contain all the information required for gaining access to a wallet.

      As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

      Read more...

      Cybersecurity And The AI Arms Race In A Landscape Of Emerging Threats

      2024-01-25

      Forbes: Of all the headlines in 2023, perhaps none captured our collective imagination last year like the high-profile AI breakthroughs typified by ChatGPT. 

      Read more...

      M|C Partners Makes Strategic Investment in Consortium Networks to Fuel Cybersecurity Growth

      2024-01-24

      PR Newswire: M|C Partners, a digital infrastructure and tech services private equity firm, has made a strategic growth investment in Consortium Networks, a national cybersecurity organization. 

      Read more...

      AI Will Make Scam Emails Look Genuine, UK Cybersecurity Agency Warns

      2024-01-24

      The Guardian: Artificial intelligence will make it difficult to spot whether emails are genuine or sent by scammers and malicious actors, including messages that ask computer users to reset their passwords, the UK’s cybersecurity agency has warned.

      Read more...

      AI Program Poised to Advance Cybersecurity in Abu Dhabi

      2024-01-23

      Dark Reading: Experts have welcomed the creation of a new artificial intelligence (AI) council in Abu Dhabi as a key move toward strengthening national cybersecurity.

      Read more...

      Cybersecurity Automation Firm Torq Lands $42 Million In Expanded Series B

      2024-01-23

      TechCrunch: Torq, a self-described “hyperautomation” cybersecurity startup, today announced that it raised $42 million in an extension to its Series B funding round from investors, including Bessemer Venture Partners, GGV Capital, Insight Partners, Greenfield Partners and Evolution Equity Partners.

      Read more...

      SEC Confirms X Account Was Hacked In SIM Swapping Attack

      2024-01-22

      Bleeping Computer: The U.S. Securities and Exchange Commission confirmed that its X account was hacked through a SIM-swapping attack on the cell phone number associated with the account.

      Read more...

      Microsoft To Overhaul Internal Security Practices After Midnight Blizzard Attack

      2024-01-22

      Cybersecurity Dive: Security researchers and other analysts say the attack raises serious questions about the security of Microsoft products and whether the company is employing the same practices internally that it demands of customers. 

      Read more...

      Know Your Breach: Liquipedia

      The Target: Liquipedia is an encyclopedia on various video games, covering everything from history to tactics. The platform was founded and is run by Team Liquid, a Netherlands-based professional e-sports organization owned by aXiomatic Gaming, an e-sports and gaming enabler.

      The Take: A part of the exposed information was contained in a user collection weighing 77MB, containing data on nearly 119,000 users. The exposed Liquipedia user details include: User IDs, User emails, email verification status, two-factor authentication status and account creation dates.

      The Vector: Researchers surmised that secrets and private RSA keys were used to authenticate admin access to Liquipedia’s Reddit, Discord, Twitch, and X accounts.

      This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

      Read more...

      Expect M&A Uptick In Cybersecurity Market, Says Arctic Wolf Boss

      2024-01-18

      City A.M: The boss of one of the world’s biggest cybersecurity companies has said he expects a surge in M&A activity in the sector in 2024. Nick Schneider, the chief executive of Arctic Wolf, which is valued at $4.3bn, told City A.M. that many potential buyers are “opportunistically” scouring the market.

      Read more...

      Navigating The 'Fog Of A Cyberattack': Critical Lessons In Governance From The SEC Cybersecurity Rule

      2024-01-17

      Forbes: The short breach notification timeline attached to the SEC’s new cybersecurity disclosure rule is loud and clear: C-Suite leaders and boards have important work to do in ensuring their organizations can quickly identify, understand and publicly disclose material cybersecurity events and impacts.

      Read more...

      Cybersecurity Startup Funding Hits 5-Year Low, Drops 50% From 2022

      2024-01-17

      Crunchbase: Just two years ago venture funding to cybersecurity was on fire, with more than $23 billion flooding the sector. In 2023, cyber startups saw only about a third of that, as venture funding dipped to its lowest total since 2018. 

      Read more...

      Quantum Computing to Spark ‘Cybersecurity Armageddon,’ IBM Says

      2024-01-17

      BNN Bloomberg: Governments and businesses are not prepared for the havoc quantum computers will sow in cybersecurity by the end of the decade, according to an International Business Machines Corp. executive.  

      Read more...

      How Blockchain Revolutionizes Data Integrity And Cybersecurity

      2024-01-17

      Forbes: In the current digital landscape, data integrity and security have taken center stage, especially as businesses and institutions continue to depend on digital data. 

      Read more...

      Allianz Risk Barometer: A Cyber Event Is the Top Global Business Risk for 2024

      2024-01-16

      Business Wire: Cyber incidents such as ransomware attacks, data breaches, and IT disruptions are the biggest worry for companies globally in 2024, according to the Allianz Risk Barometer. 

      Read more...

      Thomvest Ventures Closes $250 Million Fund To Invest Across Fintech, Cybersecurity, AI

      2024-01-16

      TechCrunch: Thomvest Ventures is popping into 2024 with a new $250 million fund and the promotion of Umesh Padval and Nima Wedlake to the role of managing directors.

      Read more...

      Know Your Breach: HMG Healthcare

      The Target: HMG Healthcare is headquartered in The Woodlands, Texas, and provides a range of services, including memory care, rehabilitation and assisted living. HMG’s website says it employs more than 4,100 people and serves approximately 3,500 patients, generating more than $150 million in annual revenues.

      The Take: HMG said the stolen information “likely contained” personal information, including names, dates of birth, contact information, Social Security numbers and records related to employment; as well as medical records, general health information and information regarding medical treatment, according to the notice.

      The Vector: In a notice published on its website, HMG chief executive Derek Prince confirmed that hackers in August accessed a server storing “unencrypted files” containing sensitive information belonging to patients, employees, and their dependents. HMG said it learned of the breach months later in November.

      As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

      Read more...

      Canada Will Use Letter Grades To Assess Companies' Cyber Resilience

      2024-01-11

      BNN Bloomberg: The Canadian government is joining forces with the cybersecurity ratings firm SecurityScorecard Inc. to bolster defenses for the country’s critical infrastructure.

      Read more...

      Cybersecurity Funding Dropped 40% in 2023: Analysis

      2024-01-09

      SecurityWeek: Pinpoint’s 2023 annual cybersecurity funding report shows that there were a total of 437 funding and M&A transactions last year, including 346 funding rounds and 91 M&A deals. 

      Read more...

      SEC Account Hack Renews Spotlight on X's Security Concerns

      2024-01-09

      US News: The hack of the U.S. Securities and Exchange Commission's official account on X renewed concerns about the social media platform's security since its takeover by billionaire Elon Musk in 2022.

      Read more...

      AI Advances Risk Facilitating Cyber Crime, Top US Officials Say

      2024-01-09

      Yahoo News: Advances in artificial intelligence may facilitate hacking, scamming and money laundering by reducing the technical know-how required to carry out such crimes, top U.S. law enforcement and intelligence officials said 

      Read more...

      AI Set To Drive VCs To Cybersecurity Investments

      2024-01-08

      Mint: Venture capital investors are scaling their cyber security investments on the back of advancements in artificial intelligence (AI) and rising instances of data security breaches.  

      Read more...

      SentinelOne Acquires Peak XV-Backed PingSafe For Over $100 Million

      2024-01-08

      TechCrunch: SentinelOne’s deal to acquire PingSafe values the Peak XV-backed young startup at over $100 million, two sources familiar with the matter told TechCrunch, in one of the strongest and fastest exits emerging from India.

      Read more...

      How SEC Action Could Shake Up Cybersecurity

      2024-01-08

      Forbes: Remember when the cyberattack on SolarWinds broke through the coverage of Covid-19 and dominated headlines? That was around three years ago, and the story lingered for a while as a kind of cautionary tale.

      Read more...

      Know Your Breach: Orrick, Herrington & Sutcliffe

      The Target: Orrick, Herrington & Sutcliffe, a popular San Francisco-based international law firm.

      The Take: The stolen data encompassed a vast array of information, including names, dates of birth, addresses, email addresses, and government-issued identification numbers like Social Security, passport, driver’s license, and tax identification numbers.

      The Vector: The intrusion into Orrick’s network compromised a file share, revealing personal information and sensitive health data of victims.

      This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

      Read more...

      NZ Firm Pushes for ‘Complete Ban’ on Paying Cyber Ransoms

      2024-01-04

      The Post: A New Zealand cyber-security firm that has the ear of many media organisations around the world has called for a complete ban on paying off ransomware attackers, arguing it is the only way to get on top of the crime.

      Read more...

      Atos Shares Drop After Airbus Deal Talks Disappoint Investors

      2024-01-03

      Yahoo Finance: Atos SE shares fell after the company’s announcement that it was in early talks to sell its big data and cybersecurity business to Airbus SE for as much as €1.8 billion ($2 billion) disappointed investors.

      Read more...

      OpenAI Moves to Shrink Regulatory Risk in EU Around Data Privacy

      2024-01-02

      TechCrunch: While most of Europe was still knuckle deep in the holiday chocolate selection box late last month, ChatGPT maker OpenAI was busy firing out an email with details of an incoming update to its terms that looks intended to shrink its regulatory risk in the European Union.

      Read more...

      Google Cloud Report Spotlights 2024 Cybersecurity Challenges

      2024-01-02

      Security Boulevard: As the New Year dawns, a cybersecurity report from Google Cloud suggests that while there are many challenges ahead, it will also become simpler for cybersecurity teams to leverage artificial intelligence (AI) to better defend IT environments.

      Read more...

      Early-Stage Hard Tech Firm Countdown Capital Shutting Down

      2024-01-02

      TechCrunch: Countdown Capital, an early-stage venture capital firm focused on hard tech industrial startups, will shut down by the end of March and return uninvested capital, firm founder and solo general partner Jai Malik said in an annual letter.

      Read more...

      Four Ways Companies Can Respond And More Effectively Comply With The SEC’s New Cybersecurity Rules

      2024-01-02

      SC Media: With two major actions in the last six months of 2023, the Securities and Exchange Commission (SEC) has made it clear that it plans to get tough on cybersecurity.

      Read more...

      The Law Enforcement Operations Targeting Cybercrime In 2023

      2024-01-01

      Bleeping Computer: In 2023, we saw numerous law enforcement operations targeting cybercrime operations, including cryptocurrency scams, phishing attacks, credential theft, malware development, and ransomware attacks.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates