Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Cybersecurity Company Identifies mMonths-long Attack On US federal Commission

    2021-12-20

    ZDNet: The United States Commission on International Religious Freedom (USCIRF) has been hit with a cyberattack, according to cybersecurity firm Avast

    Read more...

    Know Your Breach: Gumtree

    The Target: Gumtree, a U.K based online retailer of used goods.

    The Take: Exposure of potentially 1.7 million records of Personally Identifiable Information including: full name and physical location (postal code or coordinates).

    The Vector: A software vulnerability allowed threat actors to view user’s physical locations by simply pressing F12 to view the Developer Tools and inspect the website’s source code, a feature present in every modern internet browser. In addition, one of its APIs exposed usernames, allowing them to be read without any authentication. 

    This breach highlights the importance of rigorous software testing and the deployment of authentication methods wherever user data is being handled. Ensuring that whenever a firm’s website is transmitting user data it is using protective and confidential methods, such as securing source code and employing proper authentication, will help firms meet cyber industry standards which are critical for a company’s overall posture.

    Read more...

    The Healthcare Cybersecurity Market Was Valued At USD 9.52 Billion In 2020 and Is Expected to Reach USD 24.1 Billion by 2026

    2021-12-16

    Global Newswire: The Healthcare sector is experiencing a paradigm shift due to many factors. New models of care are evolving, the focus is shifting from illness to wellness, and costs continue to climb amid growing demand for personalized, long-term care and the need for patients to participate in care management.

    Read more...

    Trudeau Tasks Cabinet with New Cybersecurity Plan Amid Growing Attacks, Spying

    2021-12-16

    Global News: Prime Minister Justin Trudeau has tasked a committee of senior cabinet ministers to develop a new national cybersecurity plan amid increasingly public warnings from the country’s intelligence community about online threats.

    Read more...

    FINRA, FCA Warn Firms of Cybersecurity Threat

    2021-12-15

    Advisor's Edge: egulators in the U.S. and U.K. are warning the financial industry about a cybersecurity vulnerability that has been uncovered with open-source software widely used in enterprise applications and cloud services.

    Read more...

    After Theft of $77.7 Million, Victim AscendEX to Reimburse Customers

    2021-12-15

    ZDNet: Crypto platform AscendEX has pledged to reimburse their customers, who lost a total of $77.7 million in a hack on December 11.

    Read more...

    Ransomware Hits HR Solutions Provider Kronos, Locking Customers Out of Vital Services

    2021-12-14

    Help Net Security: The end of the year chaos caused by the revelation of the Log4Shell vulnerability has, for some organizations, been augmented by a ransomware attack on Ultimate Kronos Group (UKG), one of the biggest HR and workforce management solutions providers in the US.

    Read more...

    Cybersecurity Startup Guardio, Now with 1M Users of Its Browser Extension, Raises Its First Funding: $47M Led by Tiger Global

    2021-12-14

    Yahoo Finance: Some say that antivirus software that you install on your PC may have run its course when it comes to the next generation of computing in the cloud. Today a startup that has built what it believes comes next is making some news with a large funding round, its first outside money.

    Read more...

    New Cyber Vulnerability Poses 'Severe Risk,' DHS Says

    2021-12-12

    ABC News: The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent statement about a new cyber vulnerability that could touch a wide swath of the internet.

    Read more...

    Know Your Breach: RATP

    The Target: Régie Autonome des Transports Parisiens

    The Take: Exposure of 3 million records of Personally Identifiable Information belonging to 60,000 employees including: full names, email addresses, source code and APIs, logins for their RATP accounts, hashed passwords, and more critically, access to the firm’s Github account where attackers could access ongoing projects.

    The Vector: The data was left open and accessible to public on an unsecured SQL database backup server, allowing anyone with internet access to connect and view the sensitive information.

    It is critical to employ robust practices of credential management, user authentication and validation around all points of access. An unprotected point of entry on a key piece of equipment like a server can lead to a breach with a cascading effect on data exposure. This breach highlights the multiplicative effects of these cascading pivot attacks which is why it’s important to lock down every point of access in an IT system.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates