Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Ransomware Gangs Rely More on Weaponizing Vulnerabilities

      2022-05-19

      Bleeping Computer: Security researchers are warning that external remote access services continue to be the main vector for ransomware gangs to breach company networks but there's a notable uptick in exploiting vulnerabilities.

      Read more...

      India to Press Ahead with Strict Cybersecurity Rules Despite Industry Concerns

      2022-05-18

      Financial Post: India will not change upcoming cybersecurity rules that force social media, technology companies and cloud service providers to report data breaches swiftly, despite growing industry concerns, the government said.

      Read more...

      Ballistic Ventures Launches $300 Million Cybersecurity Venture Fund

      2022-05-17

      SC Media: The firm, which launched last year, is headed by Ted Schlein, formerly of Kleiner-Perkins, who is also on the board of trustees of the non-profit national security venture capital group In-Q-Tel and the board of the CISA Cybersecurity Advisory Committee.

      Read more...

      Cybersecurity Agencies Reveal Top Initial Access Attack Vectors

      2022-05-17

      Bleeping Computer: The advisory, jointly released by agencies from the United States, Canada, New Zealand, the Netherlands, and the United Kingdom, includes guidance to mitigate these routinely exploited weak security controls, poor security configurations, and bad practices.

      Read more...

      Don’t Delegate Away Cyber Security Risk: ASIC

      2022-05-16

      Money Management: Appearing at FINSIA's ‘The Regulators’ event, ASIC commissioner, Cathie Armour, said the case of RI Advice has brought cybersecurity into the public eye as it was the first of its kind in Australia.

      Read more...

      Researchers Warn of APTs, Data Leaks as Serious Threats Against UK Financial Sector

      2022-05-16

      ZDNet: KELA's security team published a report examining the cybersecurity issues and attacks that surfaced in 2021 and early 2022, specifically focused on the United Kingdom's banks and other financial services.

      Read more...

      Know Your Breach: MM.Finance

      The Target: MM.Finance, the largest decentralized finance platform on the Cronos blockchain.

      The Take: $2 Million

      The Vector: A DNS (domain name service, a server that directs users to the appropriate website upon entering the name of a site) vulnerability allowed attackers to inject a malicious website address into the code on the front-facing website as a redirected destination. When users visited the site to make transactions, they were instead sent to a bad website address where the threat actor was able to steal the funds being transacted.

      This breach is an important reminder of the critical nature of user-facing website security. Any method which allows public access must be secured to the highest standard and regularly audited for potential breaches. Furthermore, monitoring and updating, if necessary, configurations of key infrastructure like DNS servers is part of maintaining a robust cybersecurity posture.

      Read more...

      EU's 'Patchy' Cybersecurity Efforts Creating Risk of Criminal Hacks

      2022-05-12

      Irish Examiner: The European Union’s “fragmented” approach to cybersecurity and the “patchy” capabilities of member states is creating several problems in terms of combating State-level attacks and criminal hacks, according to an international expert.

      Read more...

      US Charges Hacker for Breaching Brokerage Accounts, Securities Fraud

      2022-05-11

      Bleeping Computer: The U.S. Department of Justice (DoJ) has charged Idris Dayo Mustapha for a range of cybercrime activities that took place between 2011 and 2018, resulting in financial losses estimated to over $5,000,000.

      Read more...

      NSA Warns Managed Service Providers Are Now Prime Targets for Cyberattacks

      2022-05-11

      Dark Reading: The National Security Administration (NSA), along with a coalition of international cybersecurity authorities, today issued an advisory warning managed service providers (MSPs) of an escalating threat of attack from both everyday cybercriminals and state-sponsored threat actors. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates