Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Cornerstone Payment Systems

    The Target: Cornerstone Payment Systems

    The Take: Exposure of 9 million transaction records which exposed Personally Identifiable Information including: email addresses, names, physical addresses, phone numbers, types of credit cards and donation details including destination and dollar amount. 

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture. This data is perfect for constructing highly effecting spear-phishing campaigns. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    GodFather Android Malware Targets 400 Banks, Crypto Exchanges

    2022-12-21

    Bleeping Computer: An Android banking malware named 'Godfather' has been targeting users in 16 countries, attempting to steal account credentials for over 400 online banking sites and cryptocurrency exchanges.

    Read more...

    Top White House Cybersecurity Official Plans to Step Down

    2022-12-21

    BNN Bloomberg: The US’s first national cyber director, Chris Inglis, is planning to step down in the coming months, according to a person familiar with the matter.

    Read more...

    Sectigo Hires Kevin Weiss As CEO

    2022-12-20

    Help Net Security: Kevin Weiss brings over 25 years of strategy and leadership experience in the technology space and joins Sectigo from Spireon, where he served as CEO for more than six years.

    Read more...

    Cybersecurity Firms Hunker Down for Hard Times

    2022-12-20

    Axios: Heading into 2023, cybersecurity companies are starting to see the first signs of the economic downturn hitting their businesses. The big picture: More companies are starting to see their customers prioritize services like incident response over more costly, proactive IT investments like transitions to the cloud.

    Read more...

    SickKids Hit by Ransomware Attack Affecting Some Phone Lines, Web Pages

    2022-12-20

    CBC: Toronto's Hospital for Sick Children says it has been hit with a ransomware attack affecting some of its phone lines, web pages and clinical systems.

    Read more...

    CFOs Learn How to Respond and Lead During A Cyberattack

    2022-12-19

    CNBC: Imagine this situation: your CEO just resigned and as CFO, you’re the acting chief. After returning to the office from an exhausting overseas trip, your CIO informs you that malware was deployed within your customer databases.

    Read more...

    DraftKings Warns Data of 67K People Was Exposed In Account Hacks

    2022-12-19

    Bleeping Computer: Sports betting company DraftKings revealed last week that more than 67,000 customers had their personal information exposed following a credential attack in November.

    Read more...

    Know Your Breach: Uber

    The Target: Uber, a U.S based ride-service company.

    The Take: Exposure of sensitive company information including: IT Asset reports, Windows domain login names and email addresses, and Active Directory information. 

    The Vector:  The data was stolen through a breach in a third-party provider, Teqtivity, using compromised employee credentials. These were used to gain access to an AWS backup server.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data. The information stolen in this attack could lead to highly targeted phishing campaigns against Uber. Regular vendor assessments are a key component in cybersecurity.

    Read more...

    US Begins Seizure of 48 DDoS-for-hire Services Following Global Investigation

    2022-12-15

    ITPro: The US' Department of Justice (DoJ) has begun the seizure of 48 DDoS-for-hire services and brought criminal charges against six individuals involved.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates