Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    96% Of Security Professionals Preparing for AI-Powered Cyber-Attacks

    2021-04-08

    Cision: Darktrace, a leading autonomous cyber security AI company, today announced that a study conducted by MIT Technology Review finds that 96% of security leaders are now preparing for the emergence of AI-powered cyber-attacks, with many embracing AI defenses.

    Read more...

    Why Do Phishing Attacks Work? Blame the Humans, Not the Technology

    2021-04-08

    ZDNet: Phishing attacks remain a huge problem and crooks are spending a lot of time and effort to ensure that, for the potential victim, clicking on a bad link is the most intuitive and easiest thing to do.

    Read more...

    Key House Leader to Press for Inclusion of Cybersecurity in Infrastructure Bill

    2021-04-07

    The Hill: Rep. Yvette Clarke (D-N.Y.), the chair of a key cyber House panel, said Wednesday that she would push for inclusion of language on securing critical systems as part of negotiations around President’s Biden’s infrastructure proposal.

    Read more...

    Facebook Does Not Plan to Notify Half-billion Users Affected by Data Leak

    2021-04-07

    Reuters: Facebook Inc did not notify the more than 530 million users whose details were obtained through the misuse of a feature before 2019 and recently made public in a database, and does not currently have plans to do so, a company spokesman said.

    Read more...

    Data Breach Disclosures Drop in 2020

    2021-04-07

    Compliance Week: The report, “Trends in Cybersecurity Breach Disclosures,” was released and analyzes public company disclosures of cyber-breaches since 2011. According to the report, the 117 breaches that were disclosed in 2020 represents a 19 percent drop from 2019 (144). Still, it is the third highest figure in a single year, behind 2019 and 2018 (130). The number had gone up each year since a dip to 50 in 2015.

    Read more...

    European Institutions Were Targeted in a Cyber-Attack Last Week

    2021-04-06

    BNN Bloomberg: A spokesperson for the commission said that a number of EU bodies “experienced an IT security incident in their IT infrastructure.” The spokesperson said forensic analysis of the incident is still in its initial phase and that it’s too early to provide any conclusive information about the nature of the attack.

    Read more...

    LinkedIn Phishing Ramps Up With More-Targeted Attacks

    2021-04-05

    Dark Reading: Phishing attacks are targeting out-of-work users on LinkedIn, creating lures using job titles scraped from the targeted workers' profiles in an attempt to convince them to open and execute different malicious files or links, according to a new analysis from cybersecurity firm eSentire.

    Read more...

    Know Your Breach: Ubiquiti

    The target: Ubiquiti, a major vendor of cloud-enabled networking devices. 

    The take: Source code, customer data, and cryptographic secrets which would enable remote access to both professional and consumer-grade customer devices.

    The attack vector: The attackers gained control of administrative credentials stored on an IT employee’s LastPass account. With these in hand, the threat actors gained high-level access to Ubiquiti Amazon Web Services accounts, including database storage servers, application logs, and user credentials. Multiple backdoor accounts were reportedly created. A whistleblower alleged that due to an absence of database access logging, Ubiquiti were unable to confirm which records had been accessed, by whom, and when.

    While use of password vaults and privileged account management tools are absolutely a best practice, these tools can only be as secure as the authentication measures enforced upon them. Complex, unique passwords in addition to two-factor authentication should be in place wherever possible to protect privileged credentials and management consoles.

    Additionally – comprehensive logging practices are critical to the reconstruction of events when investigating a breach, and the absence thereof can severely limit a firm’s the ability to determine the full scope of the attack.

    Read more...

    Vanguard Targeted in Bond Fund Scam

    2021-03-31

    Financial Standard: The asset manager said scammers are buying advertisements on search engines for terms relating to "bond or high yield investments". When a person clicks on the ad link, they are taken to a fake investment comparison website with a name like "Investment Compare".

    Read more...

    Cybercrime in the US Jumped By 55% in the Past Two Years

    2021-03-31

    CNet: Cybercrime is on the rise as hackers continue to steal data, disrupt business and cause harm online. The result is billions of dollars in losses: The total annual loss in the US from cybercrime reached $4.2 billion in 2020, according to data released from StockApp.com

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates