shutterstock_490960141-1

Industry News: ESG5

      Know Your Breach: Dropbox

      Nov 4, 2022 9:50:19 AM

      The Target: Dropbox, a U.S based file hosting service.

      The Take: Exposure of 130 private GitHub repositories, which contain sensitive files and source code, monitoring tools and configuration files used by the security team.

      The Vector: The attacker created a fake login page for one of Dropbox’s third party integrated platforms, CircleCI, which allowed them to steal the legitimate credentials the employees entered.

      This breach highlights critical need for employee training to protect a firm against phishing attacks. By using the exposed credentials, the attackers were able to act with all the same permissions as the affected employee. The human component of cybersecurity is a very real and important piece of the overall picture of cybersecurity posture.

      Read more...

       

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates