Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Ethical Hackers Reduce $27 Billion In Risk During COVID-19 Vulnerability Surge

    2021-11-26

    Cision: Bugcrowd, the world's first crowdsourced cybersecurity platform for multiple solutions, released its annual Inside the Mind of a Hacker '21 report, which provides CIOs and CISOs valuable insight on ethical hackers and the economics of security research.

    Read more...

    DHS Announces New Program to Attract and Retain Cybersecurity Talent

    2021-11-15

    The Hill: The Department of Homeland Security (DHS) announced a new program to attract and retain cybersecurity professionals, as major cyber incidents have ticked up over the past year and are drawing more government attention.

    Read more...

    Know Your Breach: Robin Hood

    The target: Robin Hood, a U.S based investment and trading platform.

    The take: Exposure of an estimated 7 million customer accounts with Personally Identifiable Information including: 5 million email addresses and 2 million full names. For a small number of the exposed records, dates-of-birth and zip codes were also vulnerable.

    The attack vector: The attacker used social engineering to target one of Robin Hood’s Customer Support Representatives, tricking them into thinking they had authentication to access the firm’s internal systems and handed over their credentials. Using these legitimate permissions, the threat actors immediately accessed the sensitive data. 

    This breach highlights the great and always on-going risk that social engineering attacks pose to organizations. The strongest security controls are often only as effective as the employees who maintain them. Regular awareness testing and training, along with an emphasis on the importance of critical thinking and caution when receiving access requests from third parties is critical to a robust cybersecurity posture.

    Read more...

    Ethical Hackers In Saudi Arabia Take On Cybercriminals, Fraudsters

    2021-11-12

    Arab News: The growing popularity of e-commerce, online public services and social media in Saudi Arabia has brought many benefits that can improve the quality of day-to-day life.

    Read more...

    Cyber Security Breaches Are Greatest Staff-Related Risk, According to Attendees of Walkers’ Employment Conference on Equipping the Board

    2021-11-11

    Lexology: Cyber security breaches are overwhelmingly the greatest staff-related risk for a financial services business, according to a survey of Channel Island employers at Walkers' three-day virtual employment law conference.

    Read more...

    VP Harris Announces US Support for International Cybersecurity Partnership in Paris

    2021-11-11

    ZDNet: US Vice President Kamala Harris said the US will be joining the Paris Call for Trust and Security in Cyberspace -- a voluntary agreement between more than 80 countries, local governments, and tech companies centered on advancing cybersecurity and "preserving the open, interoperable, secure, and reliable Internet."

    Read more...

    Cyber Budgets of UK Enterprises Shrank During COVID-19 Pandemic: Report

    2021-11-11

    UKTN: The unexpected onset of the COVID-19 pandemic and the shift of workspace have led to a rapid increase in cyber-attacks across the world. According to Check Point research, the number of ransomware assaults worldwide increased by 102% in 2021.

    Read more...

    SolarWinds Vulnerability Exploited In First Stage of Clop Ransomware Attacks

    2021-11-10

    Dark Reading: A recent surge in Clop ransomware attacks led researchers to spot a common thread in the first stage of the attack: the exploitation of a known and patched vulnerability in SolarWinds Serv-U file server software.

    Read more...

    McAfee to Be Taken Private In US$14B Deal Including Debt

    2021-11-08

    BNN Bloomberg: An investor group led by buyout firms Advent International Corp., Permira Advisers and others agreed to take McAfee Corp. private in a deal that values the cybersecurity software maker at more than US$14 billion including debt.

    Read more...

    Know Your Breach: Umass Memorial Health

    The target: UMass Memorial Health, a Massachusetts-based healthcare network.

    The take: 209,000 records of Personally Identifiable Information including: names, dates of birth, medical record numbers, health insurance information, and clinical treatment information with dates of services, diagnoses, procedure information, and prescription details.

    The attack vector: The firm’s IT system was compromised when an employee fell for a phishing email. This granted the attackers access to all the files and programs to which the employee’s account was authorized to view. 

    This breach highlights the ongoing threat that phishing attacks pose for firms and remain one of the greatest security threats to an entire organization. Regular social engineering and awareness testing and training, along with tone-from-the-top messaging to emphasize the importance of critical thinking and caution are crucial to protecting sensitive information assets.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates