Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Ethical Hackers and the Economics of Security Research

      2021-11-22

      Help New Security: Bugcrowd released a report which provides CIOs and CISOs valuable insight on ethical hackers and the economics of security research. New findings indicate a startling shift in the threat landscape with 8 out of 10 ethical hackers recently having identified a vulnerability they had never seen before.

      Read more...

      4 Key Cybersecurity Threats to New Central Bank Digital Currencies

      2021-11-20

      World Economic Forum: With G7 officials recently endorsing principles for central bank digital currencies (CBDC), and over 80 countries launching some form of initiative related to CBDC, it seems their widespread deployment is a matter of time.

      Read more...

      Know Your Breach: RedDoorz

      The target: RedDoorz, a Singapore based hotel booking site.

      The take: Exposure of 5.9 million records of Personally Identifiable Information including: names, contact numbers, email addresses, dates of birth, encrypted passwords and booking information.

      The attack vector: The attacker gained access to an Amazon Web Services key which was embedded in an APK (Android Application Package), a piece of software used in their systems. Had the firm examined the APK, they could have prevented the exploit by removing the AWS key from the APK.

      This breach highlights the critical importance of IT asset management, specifically just how necessary it is that firms are aware of what software they are using and how it is being deployed. Regular auditing of all software configurations, especially where customer data is stored, across the firm is essential for maintaining a robust cybersecurity posture.

      Read more...

      Senators Look to Defense Bill to Move Cybersecurity Measures

      2021-11-18

      The Hill: The Senate is eyeing the annual defense bill as a vehicle to attach critical provisions to improve the nation’s cybersecurity following a devastating year in which major attacks left the government flat-footed.  

      Read more...

      Cloud Security Firm Lacework Secures $1.3 Billion In New Funding Round

      2021-11-18

      ZDNet: The Series D funding round was led by existing investors Sutter Hill Ventures, Altimeter Capital, D1 Capital Partners, and Tiger Global Management. 

      Read more...

      US, UK Warn of Iranian Hackers Exploiting Microsoft Exchange, Fortinet

      2021-11-17

      Bleeping Computer: The warning was issued as a joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Australian Cyber Security Centre (ACSC), and the United Kingdom's National Cyber Security Centre (NCSC).

      Read more...

      Vaccine Research Among Cyber Attack Targets

      2021-11-17

      BBC: The National Cyber Security Centre says it handled a record 777 incidents between August 2020 and September 2021. Its annual review said protecting the health sector became an urgent priority over the period.

      Read more...

      FBI Left Out of the Loop In Cyberattack Reporting Bill

      2021-11-16

      Politico: The FBI could be sidelined in new cybersecurity legislation, a top Bureau official told lawmakers. And, in the view of America’s most powerful law enforcement agency, that would be a big problem.

      Read more...

      Ethical Hackers Reduce $27 Billion In Risk During COVID-19 Vulnerability Surge

      2021-11-26

      Cision: Bugcrowd, the world's first crowdsourced cybersecurity platform for multiple solutions, released its annual Inside the Mind of a Hacker '21 report, which provides CIOs and CISOs valuable insight on ethical hackers and the economics of security research.

      Read more...

      DHS Announces New Program to Attract and Retain Cybersecurity Talent

      2021-11-15

      The Hill: The Department of Homeland Security (DHS) announced a new program to attract and retain cybersecurity professionals, as major cyber incidents have ticked up over the past year and are drawing more government attention.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates