Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Cooper Health System

    The Target: Camden, New Jersey-based Cooper Health System

    The Take: The potentially affected information included individuals’ names, dates of birth, Social Security numbers, health insurance information, treatment information, medical record numbers and medical history information.

    The Vector: During the investigation, Cooper discovered that certain data stored in its systems was potentially acquired without authorization.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Cybersecurity Provider Netskope Taps Morgan Stanley For US IPO, Sources Say

    2025-05-28

    Yahoo Finance: Cybersecurity firm Netskope has hired Morgan Stanley to lead preparations for a U.S. initial public offering that could raise more than $500 million, according to people familiar with the matter.

    Read more...

    Zscaler Enters Agreement To Buy Red Canary

    2025-05-28

    Cybersecurity Dive: Zscaler said it had agreed to buy Red Canary, a leading provider of managed detection and response technology. Zscaler, a top cloud security vendor, said the agreement will help it disrupt competitors’ legacy security operations. 

    Read more...

    Limerston Capital Acquires CyberCrowd to Create New Cyber Security Platform

    2025-05-27

    Business Wire: UK mid-market private equity investment firm Limerston Capital announces the acquisition of CyberCrowd, a UK-based cyber security services specialist.

    Read more...

    Firms Eye Vendor Vulnerabilities as Enterprise Cybersecurity Risks Surge

    2025-05-27

    PYMNTS: The tech sector thrives on rapid innovation, agile partnerships and application programming interface (API)-driven interconnectivity; an ethos that has evolved across other industries.

    Read more...

    Check Point Acquires Veriti Cybersecurity to Bolster Defense

    2025-05-27

    Investing.com: In a move to enhance its cybersecurity offerings, Check Point Software Technologies Ltd. has announced the acquisition of Veriti Cybersecurity, a company specializing in automated threat exposure and mitigation. 

    Read more...

    Fintech Hiring to Boom After Cyber Attack Carnage

    2025-05-26

    Yahoo Finance: UK fintech is set for another shot of momentum after a series of cyber attacks on top retailers exposed a need for greater security expansion.

    Read more...

    Banking Groups Ask SEC to Drop Cybersecurity Incident Disclosure Rule

    2025-05-26

    Cointelegraph: American banking and financial industry advocacy groups have petitioned the Securities and Exchange Commission to repeal its cybersecurity incident public disclosure requirements. 

    Read more...

    Know Your Breach: UK Legal Aid Agency

    The Target: The Legal Aid Agency, which is part of the UK’s Ministry of Justice, provides criminal and civil legal aid and advice to people in England and Wales.

    The Take: The compromised data includes applicants’ contact details and addresses, dates of birth, national ID numbers, criminal history, and employment status, as well as financial information such as contribution amounts, payments, and debts.

    The Vector: An investigation conducted with the aid of the National Crime Agency and National Cyber Security Centre revealed on May 16 that the intrusion was “more extensive than originally understood and that the group behind it had accessed a large amount of information relating to legal aid applicants”.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    H.I.G. Capital Announces Strategic Growth Investment in AgileBlue to Accelerate AI-Powered Cybersecurity for the Mid-Market

    2025-05-22

    PR Newswire: H.I.G. Growth Partners ("H.I.G. Growth"), the dedicated growth capital investment affiliate of H.I.G. Capital ("H.I.G."), a leading global alternative investment firm with $69 billion of capital under management, is pleased to announce its investment in AgileBlue (or the "Company"), an AI-powered Security Operations platform that detects, investigates, and auto-responds to cyber threats across cloud, network, and endpoint environments.

    Read more...

    Cyber and AI Fuel Surge in UK Tech M&A Deals

    2025-05-21

    Yahoo Finance: The UK’s software M&A market has hit a record high, with £13.2bn deployed across 420 deals over the past year, marking a 27 per cent year on year rise and revealing the nation’s pivotal role in Europe’s tech investment scene.

    Read more...

    Hong Kong Regulator Bans Broker Text Links After Phishing Scams Hit Traders

    2025-05-21

    Finance Magnates: A wave of phishing scams has hit Hong Kong investors, with attackers impersonating licensed brokers in fraudulent text messages that link to fake websites.

    Read more...

    Online Criminals Attacking HSBC ‘All the Time’, says Head of UK Arm

    2025-05-20

    The Guardian: The boss of HSBC’s UK arm has said the bank is “being attacked all the time” by online criminals, with cybersecurity now its biggest expense, costing the lender hundreds of millions of pounds.

    Read more...

    Cybersecurity is in a Pivotal Moment With AI, Says Palo Alto Networks CEO

    2025-05-20

    CNBC: According to Nikesh Arora, even “naysayers” of AI are now trying to move data to the cloud in order to keep up with competitors. New AI models require the cloud, he said, claiming that businesses will be left behind if they don’t move their company to the platform.

    Read more...

    30% of Data Breaches Involve Victims’ Third-Party Suppliers and Vendors

    2025-05-19

    PYMNTS: Thirty percent of data breaches that occurred during the year ended Oct. 31 involved a third party, according to Verizon.

    Read more....

    BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

    2025-05-19

    SecurityWeek: The company, which is working on technology to revamp corporate incident response reporting systems, said the new financing included expanded equity positions for SYN Ventures and Overline.

    Read more...

    Know Your Breach: Coinbase

    The Target: Crypto giant Coinbase

    The Take: The company said the hacker stole customer names, postal and email addresses, phone numbers, and the last four-digits of users’ Social Security numbers. The hacker also took masked bank account numbers and some banking identifiers, as well as customers’ government-issued identity documents, such as driver’s licenses and passports.

    The Vector: Coinbase said the hacker “obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities.”

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Cybersecurity Firm Proofpoint to Buy European Rival for $1 Billion as it Eyes IPO

    2025-05-15

    CNBC: Cybersecurity firm Proofpoint announced it will acquire European rival Hornetsecurity for $1 billion to strengthen its European presence as it explores a return to public markets.

    Read more...

    Generative AI May Shoulder Up To 40% Of Workload, Some Bank Execs Predict

    2025-05-15

    CIO Dive: Almost half of bank executives surveyed recently by KPMG expect that generative AI will be able to handle between 21% and 40% of their teams’ daily tasks by the end of the year.

    Read more...

    Orca Security Gets AI-Powered Remediation From Opus Deal

    2025-05-14

    Dark Reading: Orca Security announced it has acquired Opus, a Tel Aviv, Israel-based security startup which developed autonomous vulnerability management technology using agentic AI to remediate and prevent malicious activity automatically.

    Read more...

    Congress Faces Pressure To Renew Cyber Information-Sharing Law

    2025-05-14

    Cybersecurity Dive: A coalition of 52 U.S. organizations urged lawmakers to reauthorize a law that protects cyber threat information that businesses share with the federal government.

    Read more...

    Despite AI Challenges, CEOs Say They Are Doubling Down On Investments

    2025-05-14

    CIO Dive: CEOs expect the growth rate of artificial intelligence investments to more than double during the next two years, prompting an increase in AI-related hiring and reskilling initiatives, according to a May 6 report from IBM’s Institute for Business Value.

    Read more...

    EU Cybersecurity Agency ENISA Launches European Vulnerability Database

    2025-05-14

    SecurityWeek: The EU cybersecurity agency ENISA announced the official launch of the European Vulnerability Database, or EUVD. Industry professionals the EUVD can be a useful resource, but the agency needs to ensure it stays relevant. 

    Read more...

    US Prosecutors Recommend 2 Years For SEC Hacker

    2025-05-12

    Cointelegraph: The US government has asked a federal judge to impose a two-year sentence for Eric Council Jr., the individual who helped post a fake message announcing the approval of Bitcoin exchange-traded funds through the Securities and Exchange Commission’s (SEC’s) X account.

    Read more...

    Know Your Breach: Frederick Health

    The Target: Frederick Health Medical Group, a major healthcare provider in Maryland.

    The Take: Depending on the affected individuals, the attackers stole a combination of sensitive personal information, including patient names, addresses, dates of birth, Social Security numbers, and driver's license numbers. They also exfiltrated personal health information, such as medical record numbers, health insurance information, and/or clinical information related to patients' care.

    The Vector: The investigation determined that an unauthorized person gained access to the network and, on January 27, 2025, copied certain files from a file share server.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    $45 Million Stolen From Coinbase Users in the Last Week — ZachXBT

    2025-05-08

    Cointelegraph: Onchain sleuth and security analyst ZachXBT claims to have identified an additional $45 million in funds stolen from Coinbase users through social engineering scams in the past seven days alone.

    Read more...

    CrowdStrike Says It Will Lay Off 500 Workers

    2025-05-07

    TechCrunch: Cybersecurity giant CrowdStrike said that it would lay off 5% of its global workforce, which amounts to about 500 workers. 

    Read more...

    Spyware Maker NSO Ordered to Pay $167 Million Over WhatsApp Hack

    2025-05-07

    SecurityWeek: The lawsuit against NSO was filed in 2019, after it came to light that a zero-day vulnerability had been exploited to deliver NSO-made spyware to roughly 1,400 WhatsApp users.

    Read more...

    Ransomware Claims Dipped Slightly in 2024, Cyber Insurer Says

    2025-05-07

    Cybersecurity Dive: Coalition is one of the world’s largest cyber insurers, so its data offers a broad survey of the cyber risk landscape, from the behavior of threat actors to the best strategies for avoiding a digital security crisis.

    Read more...

    UK Firms Have ‘Alarming Gaps’ in Cybersecurity Readiness

    2025-05-07

    Yahoo News: The vast majority of UK firms are not at the required level of readiness to be able to withstand modern cyber attacks, a new report has warned.

    Read more...

    Identity Security Funding Soars Amid Rise Of AI Agents

    2025-05-06

    Crunchbase: Identity management is a hot area for investment of late. That was particularly obvious in the past few weeks, as two startups in the space secured over $300 million and a major eyeball-scanning initiative made its U.S. debut. 

    Read more...

    Cybersecurity Investors Bet Big on Early-Stage Startups

    2025-05-06

    Bank Info Security: Cybersecurity attracted $13 billion in investments in 2024, a 40% jump in funding compared to 2023, with nearly half going to early-stage startups.

    Read more...

    Know Your Breach: Ascension

    The Target: Ascension, one of the largest private healthcare systems in the United States.

    The Take: Depending on the impacted patient, the attackers gained access to a combination of personal information, including name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers (SSNs).

    The Vector: The timeline of the breach implies the attack was part of a series of Clop ransomware data theft attacks that exploited a zero-day flaw in Cleo secure file transfer software.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Zero-Day Exploitation Drops Slightly From Last Year, Google Report Finds

    2025-04-29

    Cybersecurity Dive: Zero-day vulnerability exploitation represents one of several important metrics for assessing the software industry’s progress on baking security into its development practices.

    Read more...

    AI Risk Is The New Cybersecurity: How To Start Asking Tough Questions

    2025-04-29

    Forbes: AI has evolved from a futuristic novelty into a workhorse with outsized returns on investment for modern businesses. Companies are already using it to power chatbots, analyze massive datasets and streamline critical operations.

    Read more...

    Cybersecurity Firms Raise Over $1.7 Billion Ahead of RSA Conference 2025

    2025-04-29

    SecurityWeek: According to SecurityWeek’s analysis, more than 30 cybersecurity firms collectively raised more than $1.7 billion in funding in the month of April, underscoring the sector’s robust growth and investor confidence in cyber defense technologies.

    Read more...

    DoJ Data Security Program Highlights Data-Sharing Challenges

    2025-04-28

    Dark Reading: In a sign of how pervasive data sharing has become, businesses may face challenges complying with a new government rule restricting data use outside the US.

    Read more...

    Cybersecurity Vendors Are Themselves Under Attack By Hackers, SentinelOne Says

    2025-04-28

    Cyberscoop: Cybersecurity companies don’t just defend their customers against cyberattacks — they also have to defend themselves, and a SentinelOne report examines some of the biggest threats they’re facing.

    Read more...

    Veza Banks $108 Million Series D at $808 Million Valuation

    2025-04-28

    SecurityWeek: The new financing includes equity stakes for existing backers Accel and GV (Google’s venture fund), True Ventures, Norwest, Ballistic Ventures, J.P. Morgan, and Blackstone Innovations Investments.

    Read more...

    Coinbase Fixes 2FA Log Error Making People Think They Were Hacked

    2025-04-27

    Bleeping Computer: Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates