Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Fox News

    The Target: Fox News, a U.S based news organization.

    The Take: Exposure of Personally Identifiable Information including: internal employee emails, usernames, employee ID numbers, affiliate information, event logging, host names, IP address, and device data.

    The Vector: A misconfiguration of a storage server left the data exposed online, meaning anyone with an internet connection could have accessed and downloaded the information. 

    This breach highlights the critical importance of employing robust practices of credential management, user authentication and validation. An unprotected point of entry on a key piece of equipment like a storage server can lead to a breach with a cascading effect on data security. The detailed personal information, along with the event logs and sensitive company information, can lead to highly effective phishing attacks.

    Read more...

    Report Finds Only 3% of Venture-Backed Cyber Security Startups Are Led by Women

    2022-04-07

    Globe Newswire: NopSec, a leading Risk-Based Vulnerability Management platform, today released findings from their Venture-Backed Women in Cyber report. This new report analyzed 654 startups that raised more than $1 million in funding from Jan. 1, 2020, to Dec. 31, 2021.

    Read more...

    Half of Security Leaders Consider Quitting Due to Stress

    2022-04-07

    Info Security: Half of UK cybersecurity chiefs feel burnt out and are thinking about resigning due to the immense pressure they’re under, according to a new study from Vectra AI.

    Read more...

    Cryptocurrency Has Overtaken Bank Transfers for Payments into Investment Scams: ACCC

    2022-04-06

    ZDNet: Losses from Australians to investment scams increased by 90% to AU$103 million from the start of the year to March 20, with the Australian Competition and Consumer Commission saying payments made to scammers are most often made in cryptocurrency.

    Read more...

    Cybersecurity Funding Remains High Even As Venture Cools Off

    2022-04-06

    Crunchbase News: Funding to venture-backed cybersecurity startups continues at an impressive clip—although significantly off the record high set last quarter.

    Read more...

    Bank of Ireland Fined €463,000 for Data Breaches

    2022-04-05

    RTE: Bank of Ireland has been fined €463,000 by the Data Protection Commission for data breaches affecting more than 50,000 customers.

    Read more...

    Financial Institutions to Face Higher Penalty for Cyber Attacks, Disruptions Under New Bill

    2022-04-05

    The Straits Times: Financial institutions today rely heavily on technology to deliver financial services, Monetary Authority of Singapore (MAS) board member Alvin Tan told Parliament on Monday (April 4) during the second reading of the Financial Services and Markets Bill.

    Read more...

    Hackers Breach MailChimp's Internal Tools to Target Crypto Customers

    2022-04-04

    Bleeping Computer: Email marketing firm MailChimp disclosed that they had been hit by hackers who gained access to internal customer support and account management tools to steal audience data and conduct phishing attacks.

    Read more...

    Know Your Breach: PAN

    The Target: Palo Alto Networks, a U.S based cybersecurity company. 

    The Take: Exposure of Personally Identifiable Information including: names, business contact information, conversation records, conversation records, email addresses, and support tickets with attachments such as firewall logs, configurations, and other debugging assets.

    The Vector: A misconfiguration of Palo Alto’s support ticketing system allowed anyone with an internet connection to login and view support tickets, gaining access to personal and client company information.

    The breach is critical reminder of the importance of credential management and authentication around points of access which expose customer data. The information gathered in support scenarios is especially sensitive as the exposed details can greatly aid malicious actors in crafting highly targeted and effective spear-phishing campaigns. All points of access should be appropriately locked down and employing another layer of security like Two-Facto Authentication is highly recommended.

    Read more...

    Cybersecurity Managers with a Direct Line to Executive Boards Set the Tone for Investment

    2022-03-30

    ZDNet: A new report examines how an organization's approach to cyberattack incident and response strategies can have implications for investment in the broader cybersecurity market. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates