Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Ascension

    The Target: Ascension, one of the largest private healthcare systems in the United States.

    The Take: Depending on the impacted patient, the attackers gained access to a combination of personal information, including name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers (SSNs).

    The Vector: The timeline of the breach implies the attack was part of a series of Clop ransomware data theft attacks that exploited a zero-day flaw in Cleo secure file transfer software.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Zero-Day Exploitation Drops Slightly From Last Year, Google Report Finds

    2025-04-29

    Cybersecurity Dive: Zero-day vulnerability exploitation represents one of several important metrics for assessing the software industry’s progress on baking security into its development practices.

    Read more...

    AI Risk Is The New Cybersecurity: How To Start Asking Tough Questions

    2025-04-29

    Forbes: AI has evolved from a futuristic novelty into a workhorse with outsized returns on investment for modern businesses. Companies are already using it to power chatbots, analyze massive datasets and streamline critical operations.

    Read more...

    Cybersecurity Firms Raise Over $1.7 Billion Ahead of RSA Conference 2025

    2025-04-29

    SecurityWeek: According to SecurityWeek’s analysis, more than 30 cybersecurity firms collectively raised more than $1.7 billion in funding in the month of April, underscoring the sector’s robust growth and investor confidence in cyber defense technologies.

    Read more...

    DoJ Data Security Program Highlights Data-Sharing Challenges

    2025-04-28

    Dark Reading: In a sign of how pervasive data sharing has become, businesses may face challenges complying with a new government rule restricting data use outside the US.

    Read more...

    Cybersecurity Vendors Are Themselves Under Attack By Hackers, SentinelOne Says

    2025-04-28

    Cyberscoop: Cybersecurity companies don’t just defend their customers against cyberattacks — they also have to defend themselves, and a SentinelOne report examines some of the biggest threats they’re facing.

    Read more...

    Veza Banks $108 Million Series D at $808 Million Valuation

    2025-04-28

    SecurityWeek: The new financing includes equity stakes for existing backers Accel and GV (Google’s venture fund), True Ventures, Norwest, Ballistic Ventures, J.P. Morgan, and Blackstone Innovations Investments.

    Read more...

    Coinbase Fixes 2FA Log Error Making People Think They Were Hacked

    2025-04-27

    Bleeping Computer: Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates