Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Frederick Health

    The Target: Frederick Health Medical Group, a major healthcare provider in Maryland.

    The Take: Depending on the affected individuals, the attackers stole a combination of sensitive personal information, including patient names, addresses, dates of birth, Social Security numbers, and driver's license numbers. They also exfiltrated personal health information, such as medical record numbers, health insurance information, and/or clinical information related to patients' care.

    The Vector: The investigation determined that an unauthorized person gained access to the network and, on January 27, 2025, copied certain files from a file share server.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    $45 Million Stolen From Coinbase Users in the Last Week — ZachXBT

    2025-05-08

    Cointelegraph: Onchain sleuth and security analyst ZachXBT claims to have identified an additional $45 million in funds stolen from Coinbase users through social engineering scams in the past seven days alone.

    Read more...

    CrowdStrike Says It Will Lay Off 500 Workers

    2025-05-07

    TechCrunch: Cybersecurity giant CrowdStrike said that it would lay off 5% of its global workforce, which amounts to about 500 workers. 

    Read more...

    Spyware Maker NSO Ordered to Pay $167 Million Over WhatsApp Hack

    2025-05-07

    SecurityWeek: The lawsuit against NSO was filed in 2019, after it came to light that a zero-day vulnerability had been exploited to deliver NSO-made spyware to roughly 1,400 WhatsApp users.

    Read more...

    Ransomware Claims Dipped Slightly in 2024, Cyber Insurer Says

    2025-05-07

    Cybersecurity Dive: Coalition is one of the world’s largest cyber insurers, so its data offers a broad survey of the cyber risk landscape, from the behavior of threat actors to the best strategies for avoiding a digital security crisis.

    Read more...

    UK Firms Have ‘Alarming Gaps’ in Cybersecurity Readiness

    2025-05-07

    Yahoo News: The vast majority of UK firms are not at the required level of readiness to be able to withstand modern cyber attacks, a new report has warned.

    Read more...

    Identity Security Funding Soars Amid Rise Of AI Agents

    2025-05-06

    Crunchbase: Identity management is a hot area for investment of late. That was particularly obvious in the past few weeks, as two startups in the space secured over $300 million and a major eyeball-scanning initiative made its U.S. debut. 

    Read more...

    Cybersecurity Investors Bet Big on Early-Stage Startups

    2025-05-06

    Bank Info Security: Cybersecurity attracted $13 billion in investments in 2024, a 40% jump in funding compared to 2023, with nearly half going to early-stage startups.

    Read more...

    Know Your Breach: Ascension

    The Target: Ascension, one of the largest private healthcare systems in the United States.

    The Take: Depending on the impacted patient, the attackers gained access to a combination of personal information, including name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers (SSNs).

    The Vector: The timeline of the breach implies the attack was part of a series of Clop ransomware data theft attacks that exploited a zero-day flaw in Cleo secure file transfer software.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Zero-Day Exploitation Drops Slightly From Last Year, Google Report Finds

    2025-04-29

    Cybersecurity Dive: Zero-day vulnerability exploitation represents one of several important metrics for assessing the software industry’s progress on baking security into its development practices.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates