Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Iowa’s Largest City Cancels Classes Due to Cyber Attack

    2023-01-09

    The Star: Des Moines Public Schools announced that classes would be cancelled for its 33,000 students after being “alerted to a cyber security incident on its technology network.“

    Read more...

    Know Your Breach: Twitter

    The Target: Twitter, a U.S based social media platform.

    The Take: Exposure of 235 Million records of Personally Identifiable Information including: email addresses, usernames, and phone numbers.

    The Vector: A zero-day exploit was used which allowed the attacker to scrape Twitter user profiles for the stolen information. This vulnerability circumvented Twitter’s privacy option which should prevent searching am account by it’s associated phone number/email.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected.

    Read more...

    Bluebottle Hackers Used Signed Windows Driver in Attacks on Banks

    2023-01-05

    Bleeping Computer: A signed Windows driver has been used in attacks on banks in French-speaking countries, likely from a threat actor that stole more than $11 million from various banks.

    Read more...

    CaixaBank Forms International Consortium for Cybersecurity Research

    2023-01-05

    IBS Intelligence: Working with 11 international entities, CaixaBank has formed a European research consortium to explore ways to improve cybersecurity by leveraging artificial intelligence (AI) and big data. The project, AI4CYBER, is part of the Horizon Europe programme and is funded by the European Union.

    Read more...

    RFA Enhances Hedge and PE Fund Cyber Security Offering

    2023-01-04

    Hedge Week: RFA, a specialist IT provider to the alternative investment sector, has enhanced its cyber security offering for hedge and private equity funds with the addition of external surface attack management and dark web breach and exposure monitoring solutions.

    Read more...

    Twitter Whistleblower ‘Mudge’ Joins Cybersecurity Firm Rapid7

    2023-01-04

    BNN Bloomberg: Peiter Zatko, the prominent computer security expert who blew the whistle last year on alleged security problems at Twitter Inc., is joining the cybersecurity firm Rapid7 Inc., the company said.

    Read more...

    Rackspace Confirms Play Ransomware Was Behind Recent Cyberattack

    2023-01-04

    Bleeping Computer: Texas-based cloud computing provider Rackspace has confirmed that the Play ransomware operation was behind a recent cyberattack that took down the company's hosted Microsoft Exchange environments.

    Read more...

    Preventing Data Breaches: The Role of Threat Intelligence Platforms and Cybersecurity Strategies

    2023-01-03

    Forbes: Threat intelligence platforms are becoming increasingly important for both government agencies and businesses in today's digital landscape. The growing threat of ransomware attacks and other malicious activities from threat actors has highlighted the need for organizations to have a comprehensive and effective way to monitor, analyze and respond to potential threats.

    Read more...

    A Few Cybersecurity Stocks Soared in 2022, But Most Stumbled

    2023-01-03

    Bank Info Security: After two sensational years in the public markets during the height of the COVID-19 pandemic, 2022 was a rude awakening for the cybersecurity industry.

    Read more...

    Cornerstone Payment Systems

    The Target: Cornerstone Payment Systems

    The Take: Exposure of 9 million transaction records which exposed Personally Identifiable Information including: email addresses, names, physical addresses, phone numbers, types of credit cards and donation details including destination and dollar amount. 

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture. This data is perfect for constructing highly effecting spear-phishing campaigns. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates