Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: UScelluar

    The target: UScelluar, the fourth largest mobile network operator in the United States.

    The take: Customer records of personally identifiable information including: names, addresses, account names and PIN codes, telephone numbers, information on their phone service plans, and the ability to alter the phone number on accounts which receive two-factor authentication texts.

    The attack vector: The attackers tricked retail employees into downloading malicious software which contained a RAT (remote access tool), allowing the threat actors to access the computer systems remotely. As the employees were already logged into the CRM (customer retail management) software, the hackers were able to move freely within the systems using an employee’s credentials. 

    Social engineering is a widely used tactic by attackers to exploit our innate desire to be helpful in a quick manner without thinking through the consequences. The employee’s mistake, innocent or not, of clicking on an unverified link granted the attacker the ability to install a Remote Access Tool and navigate through the company’s systems under legitimate credentials. Continuous employee education around suspicious links, and the social engineering tactics they’re paired with, are critical components of a firm’s robust cybersecurity posture.

    Read more...

    New York Regulator Issues Guidance for Insurers Writing Cyber Policies In the State

    2021-02-04

    Insurance Journal: The New York State Department of Financial Services (DFS) has issued new guidance spelling out best practices for New York-regulated property/casualty insurers that write cyber insurance. This serves as the first guidance the regulator has issued on cyber insurance in particular.

    Read more...

    Hackers Steal StormShield Firewall Source Code In Data Breach

    2021-02-04

    Bleeping Computer: Leading French cybersecurity company StormShield disclosed that their systems were hacked, allowing a threat actor to access the company's support ticket system and steal source code for Stormshield Network Security firewall software.

    Read more...

    It’s Time to Rethink Cybersecurity Training… Again

    2021-02-04

    Security Magazine: Cybersecurity training today is much different than it was 10 years ago. In most organizations, we have developed training that is engaging, interactive, even enjoyable at times. Security leaders of yesterday realized that having a once a year, boring, PowerPoint like training that employees had to undergo to check a box was not working. Everyone dreaded that training and that led to skimming the material and clicking through slides, then brute-forcing their way through the answers on the final exam.

    Read more...

    IT Directors Flag Risk of Employees Building Their Own Software

    2021-02-03

    Funds Europe: According to a survey of IT directors and chief technology officers by consulting firm Sionic, 93% of asset management firms have employees creating and designing their own applications.

    Read more...

    Suspected Chinese Hackers Used SolarWinds Bug to Spy On U.S. Payroll Agency

    2021-02-02

    Reuters: Suspected Chinese hackers exploited a flaw in software made by SolarWinds Corp to help break into U.S. government computers last year, five people familiar with the matter told Reuters, marking a new twist in a sprawling cybersecurity breach that U.S. lawmakers have labeled a national security emergency.

    Read more...

    Board Members Aren’t Taking Cybersecurity As Seriously As They Should

    2021-02-01

    Help Net Security: Trend Micro shared results from a study that reveals systemic challenges with security integration into business processes. The report includes the top ways to drive engagement and agreement around cybersecurity strategies within an organization.

    Read more...

    The Necessity for Better Data Security in 2021

    2021-02-01

    IT Pro Portal: Cybersecurity plays an essential role in protecting us and the digital systems we use on a daily basis. Although technology is rapidly evolving, we are witnessing a vast number of data breaches due to organizations facing minimal charges for poor protection of data and storage.

    Know Your Breach: Bonobos

    The target: Bonobos, a men’s clothing store. 

    The take: 70GB database containing personally identifiable information such as: 7 million order records, account information of 1.8 million customers with phone numbers, shipping and email addresses, 3.5 million partial credit card records, and hashed passwords.

    The attack vector: While Bonobos’ own internal systems show no signs of breach, an externally hosted backup of the database was accessed in a provider’s cloud storage environment.

    Security controls must always be commensurate with the sensitivity of data being stored, and must travel with that data, both within internal systems, and when transferring sensitive data to backup media or external vendor or partner’s systems. This attack highlights the importance of auditing and validating security controls at every stage of the data lifecycle.

    Read more...

    WisdomTree Deepens Thematic Offering with Cybersecurity Launch

    2021-01-28

    Investment Week: WisdomTree Cybersecurity UCITS ETF (WCBR) has been developed alongside venture capital firm Team8 and will track the bespoke WisdomTree Team8 Cybersecurity index. It will be available to investors on the London Stock Exchange, Borsa Italiana and Börse Xetra for a total expense ratio of 0.45%.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates