Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Cybersecurity Agencies Reveal Top Exploited Vulnerabilities of 2021

    2022-04-27

    Bleeping Computer: In partnership with the NSA and the FBI, cybersecurity authorities worldwide have released today a list of the top 15 vulnerabilities routinely exploited by threat actors during 2021.

    Read more...

    Microsoft’s $15 Billion Cybersecurity Business is Giving Investors New Reason for Optimism

    2022-04-26

    CNBC: In January 2021, Microsoft CEO Satya Nadella revealed the size of the software company’s security business for the first time. The number was big.

    Read more...

    Technology to Survive and Thrive in a World of Growing Threats

    2022-04-25

    Hedge Week: The outbreak of the Covid-19 pandemic has created a breeding ground for an increase in fraudulent activity, as the world shifted to working from home and reliance on digital technology was heightened in all aspects of daily life. This underscored the need for tighter procedures and processes around detection and protection within all sectors, but especially financial services.

    Read more...

    JPMorgan Sued After Millions Stolen From Ray-Ban Maker’s Account

    2022-04-25

    BNN Bloomberg: J.P. Morgan Chase Bank N.A. was sued by a unit of the French maker of Ray-Ban glasses, which claims the bank ignored red flags as international cybercriminals drained $272 million from its New York bank account.

    Read more...

    Know Your Breach: Army Futures Command

    The Target: Army Futures Command, a division of the United States’ Depart of Defense.

    The Take: Exposure of Personally Identifiable Information of an unknown amount.  

    The Vector: Settings controlling access to Shared files on Microsoft Teams were accidentally set to “public” instead of private, resulting in any shared files being exposed to all users across the firm. The default settings were set to public, and the company did not investigate these settings prior using the messaging platform.

    This breach is a stark reminder of the importance of access control around shared files and the configuration of settings that control them. Sensitive information must be protected and trusting in default settings to be sufficient is not part of maintaining a robust cybersecurity posture. Investigating any avenue through which information is shared, even inside the firm, is critical to get a full and clear picture of how information is handled.  

    Read more...

    City Watchdog Warns of Cyber Crime Risk for New Banks

    2022-04-22

    Evening Standard: Six of the top UK “challenger” banks have weak financial controls that leave them at risk of being victims of money laundering, terrorist financing, fraud and cyber-crime, the top City watchdog warned today.

    Read more...

    Ransomware in Fintech: Cybercriminals Adopt New Means as Theft Gives Way to Sabotage

    2022-04-21

    Help Net Security: VMware released a report which takes the pulse of the financial industry’s top CISOs and security leaders on the changing behavior of cybercriminal cartels and the defensive shift of the financial sector. 

    Read more...

    What Makes a Cybersecurity Risk or Incident Material? A Look at the SEC’s Proposed Rules on Cybersecurity

    2022-04-20

    JDSUPRA: On March 9, 2022, the Securities and Exchange Commission (“SEC”) announced Proposed Rules on cybersecurity risk management, strategy, governance, and incident disclosure (“Proposed Rules”) to address concerns of increasing cybersecurity threats to public companies.

    Read more...

    Private Eye Pleads Guilty in Probe of Vast Hedge Fund Hack

    2022-04-20

    Yahoo Finance: An Israeli private investigator pleaded guilty in a probe of a vast hacking-for-hire ring that allegedly targeted hedge funds, short sellers, journalists and advocacy groups fighting climate change.

    Read more...

    Five Eyes Advisory Warns More Malicious Russian Cyber Activity Incoming

    2022-04-20

    ZDNet: Eight cybersecurity authorities from the Five Eye nations have come together to release a joint cybersecurity advisory that more malicious cyber activity is on the way as Russia's invasion of Ukraine continues to affect geopolitical stability.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates