Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Orange Group

    The Target: Orange Group, a leading French telecommunications operator and digital service provider.

    The Take: According to the threat actor, who uses the alias Rey and is a member of the HellCat ransomware group, the stolen data is mostly from the Romanian branch of the company and includes 380,000 unique email addresses, source code, invoices, contracts, customer and employee information.

     The Vector: The threat actor compromised Orange’s systems by exploiting compromised credentials, and vulnerabilities in the company’s Jira software for bug/issue tracking, and internal portals.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    DeepSeek’s AI Shake-Up Could Boost Cybersecurity Risks, Spending: Report

    2025-02-25

    Yahoo Finance: Global cybersecurity spending is projected to surge in coming years as artificial intelligence tools like chatbots and agents proliferate, creating new risks that force enterprises to shore up their information technology defenses, according to Bloomberg Intelligence analysts.

    Read more...

    Geopolitical Tensions Fuel Surge in OT and ICS  Cyberattacks

    2025-02-25

    CSO Online: Attacks against operational technology (OT) networks are on the rise, fueled by geopolitical tensions and conflicts, as OT security fast becomes a mainstream concern.

    Read more...

    NinjaOne Snags $5B Valuation In Massive $500M Round

    2025-02-24

    Crunchbase: NinjaOne, which provides endpoint management, security and monitoring, raised $500 million in Series C extensions at a $5 billion valuation — more than doubling its value from just 12 months ago.

    Read more...

    Cybersecurity Firm Sues Advocis For $560K

    2025-02-24

    Investment Executive: Advocis faces its fourth legal claim in just over a year, this one arising from a cybersecurity contract the association allegedly terminated after naming its new CEO last fall. 

    Read more...

    Cybersecurity As A Brand Differentiator: Building Consumer Trust

    2025-02-24

    Forbes: Amid rising concerns about data breaches, identity theft and privacy violations, cybersecurity has become more than just an IT and business operations necessity—it has become a brand differentiator. 

    Read more...

    Private Equity Surges in Security and Defence Sectors

    2025-02-24

    Funds Europe: Private equity investment in security technology is accelerating, driven by rising geopolitical instability and increased government defence spending, according to research.

    Read more...

    Bybit Hack Exposes Multi-Sig Security Flaws as Industry Reevaluates Protections

    2025-02-24

    Wealth Professional: Bybit, one of the largest cryptocurrency exchanges, suffered a US$1.5bn security breach that has since triggered US$5.5bn in outflows.

    Read more...

    Know Your Breach: Globe Life

    The Target: Globe Life is an American financial services holding company.

    The Take: The information potentially exposed includes names, email addresses, phone numbers, and postal addresses. In some cases, Social Security numbers, health-related data, and other personal details may also have been involved.

     The Vector: The ongoing review indicated that the breach may have involved information linked to its American Life Insurance Co. subsidiary. In a new SEC filing on Jan. 30, Globe Life reported that customer information compromised in the attack was traced to databases maintained by a limited number of independent agency owners.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Tech Investment Firm Insight Partners Discloses Data Breach

    2025-02-19

    Cybersecurity Dive: Insight Partners suffered a data breach in January stemming from what it described as “a sophisticated social engineering attack.” In a statement the private equity and venture capital firm said it initially detected unauthorized access to “certain Insight information systems” on Jan. 16. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates