Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Ernst & Young

    The Target: Sixty-two clients of Big Four accounting firm Ernst & Young

    The Take: 3 terabytes of critical information about Ernst & Young clients including financial reports and accounting documents in client folders, passport scans, Visa scans, risk and asset management documents, contracts and agreements, credit agreements, audit reports and account balances.

    The Vector: The hacking campaign came to light after the Russian-speaking cybercrime group Clop began targeting a previously unknown vulnerability in MOVEit around May 27 and May 28.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Cybersecurity is Top Investor Concern, According to Fund Managers in CAMMI Survey

    2023-07-20

    Funds Tech: The increasing digitisation of the financial services sector has brought many benefits, including enhanced efficiency, improved data management and streamlined processes. 

    Read more...

    Ransomware Attackers Getting More Sophisticated: Canadian Centre for Cyber Security

    2023-07-19

    BNN Bloomberg: The head of the Canadian Centre for Cyber Security says ransomware attacks are getting more common and sophisticated, but there's a lot the country could do to better defend itself.

    Read more...

    TPG Expands Presence in Healthcare IT and Cybersecurity through Major Acquisitions

    2023-07-19

    Best Stocks: TPG, a leading investment firm, has recently made significant strides in the healthcare IT and cybersecurity sectors. On July 19, 2023, TPG successfully acquired Nextech, a renowned provider of clinical and administrative healthcare technology solutions for specialty physician practices.

    Read more...

    Artificial Intelligence Continues To Revolutionize Cybersecurity

    2023-07-19

    Forbes: For many years, artificial intelligence (AI) has been a vital cyber security tool, bolstering defenses and aiding analysts in their battle against ever-evolving threats.

    Read more...

    Darktrace Shares Surge After Probe Into Finances Closes

    2023-07-18

    Yahoo News: Shares in cyber security firm Darktrace have surged after it said a probe into its finances has closed, and as it reported a jump in customers amid the evolving “ChatGPT era”.

    Read more...

    Cybersecurity Firm Netcraft Lands $100M Investment

    2023-07-18

    TechCrunch: After years of growth, funding for cybersecurity startups is beginning to slow down, a symptom of the broader economic malaise and — perhaps — market oversaturation.

    Read more...

    SecurityWeek Analysis: Over 210 Cybersecurity M&A Deals Announced in First Half of 2023

    2023-07-17

    Business Wire: SecurityWeek, a leading provider of cybersecurity news and information to global enterprises, published its analysis of cybersecurity merger and acquisition (M&A) activity for the first half of 2023.

    Read more...

    Know Your Breach: HCA Healthcare

    The Target: U.S. healthcare giant HCA Healthcare, an American for-profit operator of healthcare facilities that was founded in 1968.

    The Take: Patient names; address data, such as city, state and ZIP code; patient email addresses; phone numbers; dates of birth; gender; and patient service dates, such as locations, and details about next appointments.

    The Vector: DataBreaches.net first reported the seller’s forum post on July 5, in which the seller claimed to have 27 million rows of information. Some of the column headers in the stolen file include data that HCA says was stolen, such as names, gender and dates of birth.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. In particular, the information exposed here is perfect for crafting highly believable phishing campaigns as it would allow push notifications. 

    Read more...

    Unveiling The Power Of AI In Cybersecurity: Three Questions CISOs Should Be Asking

    2023-07-13

    Forbes: 2023 may go down in history as the year of artificial intelligence (AI)—or at least the year when business leaders and consumers alike became obsessed with generative AI tools like ChatGPT. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates