Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Otelier

    The Target: Otelier, previously known as MyDigitalOffice, is a cloud-based hotel management solution used by over 10,000 hotels worldwide to manage reservations, transactions, nightly reports, and invoicing.

    The Take: The small samples seen by BleepingComputer include a broad range of data, including hotel guest reservations, transactions, employee emails, and other internal data. Some of the personal information exposed includes hotel guests' names, addresses, phone numbers, and email addresses.

    The Vector: The threat actors behind the Otelier breach told BleepingComputer that they initially hacked the company's Atlassian server using an employee's login. These credentials were stolen through information-stealing malware, which has become the bane of corporate networks over the past few years.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Automation and AI-Driven Firewall Policy Management Become Essential for Cybersecurity and Compliance

    2025-01-22

    Business Wire: As organizations expand their digital ecosystems, the complexity of managing firewall policies across hybrid and multi-cloud environments continues to rise.

    Read more...

    Security Chiefs Whose Companies Operate in the EU Should be Exploring DORA Now

    2024-01-22

    CSO Online: If your enterprise operates in Europe, you should care about the Digital Operational Resilience Act (DORA), which took effect on January 17. 

    Read more...

    Trump Fires Cyber Safety Board Investigating Salt Typhoon Hackers

    2025-01-21

    Dark Reading: In its first full day, the Trump administration axed all advisory committee members within the Department of Homeland Security, including the people that make up the Cybersecurity and Infrastructure Security Agency's (CISA) Cyber Safety Review Board (CSRB).

    Read more...

    Adoption of AI in Cybersecurity Grows, but Experts Say Risks Remain High

    2025-01-21

    PYMNTS: With scams, fraud and new ways for criminals to commit financial crimes springing up seemingly by the hour, the World Economic Forum 2025 in Davos, Switzerland, has placed cybersecurity front and center.

    Read more...

    A New Line of Defense: Cybersecurity Startup Zynap Raises €5.7 Million for Threat Intelligence

    2025-01-21

    EU Startups: Zynap, a Barcelona-based cybersecurity startup leveraging Gen-AI to fight cybercrime proactively by simulating cyber threat tactics, has announced its launch and close of their €5.7 million funding round to fuel their expansion plans.

    Read more...

    Cognizant and CrowdStrike Partner to Drive Enterprise Cybersecurity Transformation

    2025-01-21

    Yahoo Finance: Cognizant and CrowdStrike announced a strategic partnership to drive enterprise security transformation by delivering cybersecurity services, powered by the AI-native CrowdStrike Falcon® cybersecurity platform.

    Read more...

    President Trump Repeals Biden’s AI Executive Order

    2025-01-20

    TechCrunch: During his first day in office, President Donald Trump revoked a 2023 executive order signed by former President Joe Biden that sought to reduce the potential risks AI poses to consumers, workers, and national security.

    Read more...

    Know Your Breach: Casio

    The Target: Japanese electronics manufacturer Casio.

    The Take: For the nearly 6,500 employees impacted, basic information collected by human resources was accessed, including names, employee numbers, email addresses and departments. Some employees had other information like gender, date of birth and home address leaked while a small number of those affected had taxpayer ID numbers exposed.

    The Vector: An investigation conducted by an outside cybersecurity firm sourced the ransomware attack back to phishing emails that allowed the hackers into Casio’s servers.

    As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    Biden Administration Launches Cybersecurity Executive Order

    2025-01-16

    CNBC: The Biden administration announced an executive order on cybersecurity that imposes new standards for companies selling to the U.S. government and calls for greater disclosure from software providers.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates