Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    US Senate: Govt’s Ransomware Fight Hindered by Limited Reporting

    2022-05-24

    Bleeping Computer: A report published today by U.S. Senator Gary Peters, Chairman of the Senate Homeland Security and Governmental Affairs Committee, says law enforcement and regulatory agencies lack insight into ransomware attacks to fight against them effectively.

    Read more...

    SolarWinds: Here's How We're Building Everything Around This New Cybersecurity Strategy

    2022-05-24

    ZDNet: It was one of the largest cyber-espionage attacks of recent times: hackers compromised several United States government federal agencies as well as big tech companies, and were inside networks for months before anyone spotted them. 

    Read more...

    Know Your Breach: TDI

    The Target: Texas Department of Insurance. 

    The Take: 2 million records of Personally Identifiable Information affecting 1.8 million individuals were exposed, including: social security numbers, addresses, dates of birth, phone numbers, and worker injury information. 

    The Vector: A configuration error with an online web portal which manages worker’s compensation information was not properly secured, allowing members of the public to freely access pages of the site containing sensitive information.

    This breach is a stark reminder of the importance of access control around public-facing web applications and the configuration of settings that control them. Sensitive information must be protected and ensuring proper authentication and credential management is being used is a key core of maintaining a robust cybersecurity posture.

    Read more...

    U.S. Narrows Scope of Anti-Hacking Law Long Hated by Critics

    2022-05-19

    Insurance Journal: The Department of Justice is changing its policy around a controversial anti-hacking law, addressing longstanding complaints from cybersecurity researchers that the law could criminalize good-faith efforts to improve technology.

    Read more...

    Ransomware Gangs Rely More on Weaponizing Vulnerabilities

    2022-05-19

    Bleeping Computer: Security researchers are warning that external remote access services continue to be the main vector for ransomware gangs to breach company networks but there's a notable uptick in exploiting vulnerabilities.

    Read more...

    India to Press Ahead with Strict Cybersecurity Rules Despite Industry Concerns

    2022-05-18

    Financial Post: India will not change upcoming cybersecurity rules that force social media, technology companies and cloud service providers to report data breaches swiftly, despite growing industry concerns, the government said.

    Read more...

    Ballistic Ventures Launches $300 Million Cybersecurity Venture Fund

    2022-05-17

    SC Media: The firm, which launched last year, is headed by Ted Schlein, formerly of Kleiner-Perkins, who is also on the board of trustees of the non-profit national security venture capital group In-Q-Tel and the board of the CISA Cybersecurity Advisory Committee.

    Read more...

    Cybersecurity Agencies Reveal Top Initial Access Attack Vectors

    2022-05-17

    Bleeping Computer: The advisory, jointly released by agencies from the United States, Canada, New Zealand, the Netherlands, and the United Kingdom, includes guidance to mitigate these routinely exploited weak security controls, poor security configurations, and bad practices.

    Read more...

    Don’t Delegate Away Cyber Security Risk: ASIC

    2022-05-16

    Money Management: Appearing at FINSIA's ‘The Regulators’ event, ASIC commissioner, Cathie Armour, said the case of RI Advice has brought cybersecurity into the public eye as it was the first of its kind in Australia.

    Read more...

    Researchers Warn of APTs, Data Leaks as Serious Threats Against UK Financial Sector

    2022-05-16

    ZDNet: KELA's security team published a report examining the cybersecurity issues and attacks that surfaced in 2021 and early 2022, specifically focused on the United Kingdom's banks and other financial services.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates