Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Chinese Hackers Perform 'Rarely Seen' Windows Mechanism Abuse in Three-year Campaign

    2022-05-03

    ZDNet: According to Cybereason, the Chinese advanced persistent threat (APT) group Winnti is behind the campaign, which has gone undetected for years.

    Read more...

    Pentagon Contractors Go Looking for Software Flaws as Foreign Hacking Threats Loom

    2022-05-02

    CNN: A year-long Pentagon pilot program found an array of software vulnerabilities at dozens of defense contractors as Russian and Chinese hackers continue to try to steal sensitive data from the US defense industrial base.

    Read more...

    Cybersecurity Metrics Corporate Boards Want to See

    2022-05-02

    CSO: Cybersecurity pros interested in metrics and measures frequently ponder and pontificate on what measures would be best to show the board of directors.

    Read more...

    Know Your Breach: Newman Regional Health

    The Target: Newman Regional Health, a U.S based Kansas hospital

    The Take: Exposure of Personally Identifiable Information of 52,000 individuals including: names, medical record numbers, employee information, dates of birth, email addresses, phone numbers, and physical addresses. 

    The Vector: A threat actor gained access to compromised employee email accounts, and acting with all the same permissions as the breached credentials, exfiltrated the above data. 

    This breach is a stark reminder of the importance of not only robust employee credential authentication and password hygiene, but also regular internal system scanning. The threat actor had access to the compromised system for nearly a year. Performing regular monitoring on account behaviour is critical to ensure access is kept within the firm. Additionally, locking down appropriate permissions, admin access, and ensuring users only need the tools they need to do their jobs, and no more, will reduce the risk of these attacks.

    Read more...

    Private Equity Executive Sought to Undermine NSO Critics, Data Suggests

    2022-04-28

    The Guardian: When Downing Street was recently named as the suspected victim of a phone hack by the United Arab Emirates using the Israeli-made spyware, Pegasus, few were surprised at who was behind the discovery.

    Read more...

    Post-pandemic Priorities for Security Leaders

    2022-04-28

    Help Net Security: Info-Tech Research Group has published its annual report on the priorities for security leaders. The report combines insights from the 2022 security priorities survey and other related industry reports that the firm releases throughout the year.

    Read more...

    Cybersecurity Skills Gap Contributed to 80 Percent of Breaches According to New Fortinet Report

    2022-04-27

    Financial Post: According to the Fortinet report released, the skills gap isn’t just a talent shortage challenge, but it’s also severely impacting business, making it a top concern for executive leaders worldwide.

    Read more...

    Cybersecurity Agencies Reveal Top Exploited Vulnerabilities of 2021

    2022-04-27

    Bleeping Computer: In partnership with the NSA and the FBI, cybersecurity authorities worldwide have released today a list of the top 15 vulnerabilities routinely exploited by threat actors during 2021.

    Read more...

    Microsoft’s $15 Billion Cybersecurity Business is Giving Investors New Reason for Optimism

    2022-04-26

    CNBC: In January 2021, Microsoft CEO Satya Nadella revealed the size of the software company’s security business for the first time. The number was big.

    Read more...

    Technology to Survive and Thrive in a World of Growing Threats

    2022-04-25

    Hedge Week: The outbreak of the Covid-19 pandemic has created a breeding ground for an increase in fraudulent activity, as the world shifted to working from home and reliance on digital technology was heightened in all aspects of daily life. This underscored the need for tighter procedures and processes around detection and protection within all sectors, but especially financial services.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates