Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Singapore, US Run Cross-Border Cybersecurity Drills To Test Banks' Resilience

      2023-05-02

      ZDNet: Singapore and the U.S. have conducted drills to assess how well banks operating in their respective markets respond to cybersecurity threats. 

      Read more...

      FBI Seizes 9 Crypto Exchanges Used To Launder Ransomware Payments

      2023-05-02

      Bleeping Computer: The FBI and Ukrainian police have seized nine cryptocurrency exchange websites that facilitated money laundering for scammers and cybercriminals, including ransomware actors.

      Read more...

      FBI Focuses on Cybersecurity With $90M Budget Request

      2023-05-01

      Dark Reading: The FBI is requesting more than $63 million in new funding to fight cyber threats in 2024. On April 27, FBI Director Christopher Wray presented before the House Committee on Appropriations Subcommittee on Commerce, Justice, Science. 

      Read more...

      Know Your Breach: Peugeot

      The Target: Peugeot, a France based automobile manufacturer.

      The Take: Exposure of company sensitive data including: credentials to a MYSQL database, secure web tokens along with their passphrases and locations of keys, a link to the git repository for the website, and source code.

      The Vector: Peugeot’s website based in Peru was hosting an unsecured environment file (.env), which contains credentials for other services used by the program, or website in this case, that the developers are working on. The logins stored here exposed credentials to a third-party software Peugeot used named Symphony, which could let attackers download session IDs and impersonate users.

      This breach is a critical reminder to monitor, flag, and properly secure all publicly accessible files on a website, and to furthermore ensure these files are protected by passwords adhering to robust cybersecurity standards of complexity and length. This attack also shows how one exposure of a system can lead to a pivot into other systems. It’s essential to secure all public-facing websites.

      Read more...

      Lookout Sells Its Consumer Cybersecurity Business to F-Secure for $223M and Goes All-In on the Enterprise

      2023-04-26

      TechCrunch: Lookout’s long-running transition to becoming an enterprise security company is all but complete, revealing today that it’s selling its consumer mobile security business to Finland’s F-Secure in a deal valued at around $223 million.

      Read more...

      US Deploying More Cyber Forces Abroad to Help Fight Hackers

      2023-04-25

      The Economic Times: The United States is sending more of its cyber forces abroad to help foreign governments fight hackers, a top US military official said at the RSA cybersecurity conference in San Francisco.

      Read more...

      96% of CISOs Struggle to Get the Support Required to Be Resilient Against Cyber Attacks

      2023-04-25

      Business Wire: Trellix, the cybersecurity company delivering the future of extended detection and response (XDR), will highlight new research and insights on stage at the 2023 RSA Conference. 

      Read more...

      M&A Exits For VC-Backed Cyber Startups Continues To Sputter

      2023-04-25

      Crunchbase: Just as funding has sputtered to cybersecurity startups in recent quarters, the main exit avenue for startups and investors also has been narrowing.

      Read more...

      Securing Digital Finance: What SEC Proposed Cybersecurity Amendments Mean

      2023-04-25

      Spiceworks: Last month, the Securities and Exchange Commission proposed sweeping cybersecurity regulations aimed at the finance sector to minimize cybersecurity risk, define incident response and public disclosure protocols, and more.

      Read more...

      12 Critical Steps To Safeguard Your Company From Cyberattacks

      2023-04-24

      Forbes: As the founder of a nonprofit that focuses on cyber resilience, I often stress how important the dialogue is around assessing and analyzing a company's digital footprint, dark web exposure, leaked data and compromised credentials in real time. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates