Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: SK Telecom

    The Target: SK Telecom is the largest mobile network operator in South Korea, holding approximately 48.4% of the mobile phone service market in the country, corresponding to 34 million subscribers.

    The Take: USIM data is information stored on a Universal Subscriber Identity Module (USIM), which typically includes International Mobile Subscriber Identity (IMSI), Mobile Station ISDN Number (MSISDN), authentication keys, network usage data, and SMS or contacts if stored on the SIM. This data could be used for targeted surveillance, tracking, and SIM-swap attacks.

    The Vector: A malware infection allowed threat actors to access sensitive USIM-related information for customers.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Cybersecurity Startup Chainguard Almost Triples Valuation To $3.5 Billion After Fundraise

    2025-04-24

    MSN/Reuters: Computer and cloud security startup Chainguard said its latest funding round valued it at $3.5 billion, almost tripling in less than a year, underscoring sustained investor appetite for robust digital infrastructure.

    Read more...

    FBI: Cybercrime Losses Surpassed $16.6 Billion in 2024

    2025-04-24

    SecurityWeek: The reported losses increased 33% compared to 2023, but the number of complaints received by the IC3 was slightly lower in 2024, at nearly 860,000 (compared to over 880,000 the year before). 

    Read more...

    AI Impact on Data Breach Outcomes Remains ‘Limited’: Verizon

    2025-04-23

    Cybersecurity Dive: Cybersecurity risks are a top concern for business leaders globally, especially as ongoing AI additions expand the attack surface and make techniques like phishing more accessible for novice bad actors. 

    Read more...

    Cynomi Cinches $37 Million for its AI-Based 'Virtual CISO' for SMB Cybersecurity

    2025-04-23

    Yahoo Finance: Small and medium businesses are the latest targets for cybersecurity attacks, with one in three small businesses experiencing a data breach last year.

    Read more...

    Banks Rethink Cybersecurity Amid Rise of Credential-Based Compromise

    2025-04-22

    PYMNTS: The image of a hacker furiously typing strings of code to brute-force their way into a corporate server is becoming outdated. Today, the most dangerous cyber intrusions can come not from forced entries, but from front doors to organizational perimeters being quietly opened with valid credentials.

    Read more...

    Tariff Turmoil May Have Killed The Tech M&A Market’s Comeback

    2025-04-21

    TechCrunch: The tech market doesn’t need to be soaring up and to the right to foster healthy M&A activity. Deals can get done even in down markets. But can M&A thrive in an uncertain market? That’s a harder question.

    Read more...

    Can Cybersecurity Weather the Current Economic Chaos?

    2025-04-21

    Dark Reading: As the Trump administration continues to pursue a chaotic tariff policy — announcing steep tariffs on the United States' major trading partners, only to pause most of the import taxes for 90 days — economists are increasingly predicting a recession in the next 12 months.

    Read more...

    Know Your Breach: Hertz

    The Target: ​Car rental giant Hertz

    The Take: The stolen data varies by region, but largely includes Hertz customer names, dates of birth, contact information, driver’s licenses, payment card information, and workers’ compensation claims. Hertz said a smaller number of customers had their Social Security numbers taken in the breach, along with other government-issued identification numbers.

    The Vector: The company attributed the breach to a vendor, software maker Cleo, which last year was at the center of a mass-hacking campaign by a prolific Russia-linked ransomware gang. Hertz is one of dozens of companies that used Cleo’s software at the time of their data thefts. The Clop ransomware gang claimed last year to have exploited a zero-day vulnerability in Cleo’s widely used enterprise file transfer products, which allow companies to share large sets of sensitive data over the internet. By breaching these systems, the hackers stole reams of data from Cleo’s corporate customers.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    CISOs No Closer To Containing Shadow AI’s Skyrocketing Data Risks

    2025-04-17

    CSO Online: Generative AI’s many benefits come with the drawback of data security risks, primarily through shadow AI use and the leakage of sensitive information.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates