Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Hackers Are Finding Ways Around Multi-factor Authentication. Here's What to Watch for

    2022-08-16

    ZDNet: It's often said that the most important things you can do protect your accounts and wider network from hackers is to use multi-factor authentication (MFA). 

    Read more...

    Cybersecurity Firm Darktrace Confirms Preliminary Approach from Thoma Bravo

    2022-08-15

    Nasdaq: British cybersecurity firm Darktrace Plc DARK.L said on Monday it was in the early stages of discussions with tech investment firm Thoma Bravo regarding a possible cash offer.

    Read more...

    SEC Charges 18 Defendants in International Scheme to Manipulate Stocks Using Hacked US Brokerage Accounts

    2022-08-15

    SEC: The Securities and Exchange Commission today charged 18 individuals and entities for their roles in a fraudulent scheme in which dozens of online retail brokerage accounts were hacked and improperly used to purchase microcap stocks to manipulate the price and trading volume of those stocks.

    Read more...

    Credential Phishing Attacks Skyrocketing, 265 Brands Impersonated in H1 2022

    2022-08-15

    Help Net Security: Abnormal Security released a report which explores the current email threat landscape and provides insight into the latest advanced email attack trends, including increases in business email compromise, the evolution of financial supply chain compromise, and the rise of brand impersonation in credential phishing attacks.

    Read more...

    Know Your Breach: Klaviyo

    The Target: Klaviyo, an email marketing firm.

    The Take: Exposure of client’s Personally Identifiable Information including: names, addresses, emails, phone numbers, and two internal customer lead lists.

    The Vector: The attacker penetrated Klaviyo’s internal systems by tricking an employee to give up their company credentials through a phishing attack, allowing the threat actor to access systems with all the privileges of the stolen login.

    This breach highlights critical need for employee training to protect a firm against phishing attacks. By using the exposed credentials, the attackers were able to act with all the same permissions as the affected employee. The human component of cybersecurity is a very real and important piece of the overall picture of cybersecurity posture.

    Read more...

    Return-To-The-Office Mandates Will Require Cybersecurity Adjustments For Advisors

    2022-08-11

    Financial Advisor: When Elon Musk announced Tesla employees would be required to spend at least 40 hours per week in the company office, the world’s richest man raised eyebrows for overlooking employee needs and preferences.

    Read more...

    New Cross-Industry Group Launches Open Cybersecurity Framework

    2022-08-11

    Dark Reading: Amazon Web Services (AWS) and Splunk are leading an industry effort of 18 systems and security vendors to standardize how different monitoring systems share security alerts. The goal is to deliver a simplified and vendor-agnostic taxonomy to help security teams ingest and analyze security data faster.

    Read more...

    Cisco Hit by Cyberattack From Hacker Linked to Lapsus$ Gang

    2022-08-10

    BNN Bloomberg: Cisco Systems Inc. said it was the victim of a cyberattack in which a hacker repeatedly attempted to gain access to the Silicon Valley firm’s corporate network. 

    Read more...

    Introducing FINRA's Complex Investigations and Intelligence Team and Cyber and Analytics Unit

    2022-08-09

    FINRA: The new Complex Investigations and Intelligence (CII) team and Cyber and Analytics Unit (CAU) are driving a shift in terms of how Member Supervision’s National Cause and Financial Crimes Detection Program comes at its work and leverages intelligence and analytics to drive decision making and operations.

    Read more...

    How to Build an Organizational Culture That is 'Cybersecurity Ready'

    2022-08-09

    World Economic Forum: Cyber risk is one of the main challenges that organizations face today. The World Economic Forum's Global Risks Report 2022 highlights how cyber threats have intensified through digital transformation and growing digital dependency.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates