Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Maxar

    The Target: Maxar Space Systems is a major player in the American aerospace industry, considered an expert in building communication and Earth observation satellites.

    The Take: Maxar Space Systems says that the attacker likely has access to a system that contained the following employee information: name, home address, social security number, business contact information, gender, employment status, employee number, job title, hire/job termination start dates, supervisor, department.

    The Vector: The information security team discovered that a hacker using a Hong Kong-based IP address targeted and accessed a Maxar system containing certain files with employee personal data.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Study Finds 76% Of Cybersecurity Professionals Believe AI Should Be Heavily Regulated

    2024-11-21

    Dark Reading: As artificial intelligence (AI) continues to revolutionize industries, the cybersecurity field faces a dual-edged sword of opportunities and threats. StrongDM's latest report, "The State of AI in Cybersecurity," highlights the growing concerns and readiness of cybersecurity professionals to tackle AI-driven challenges.

    Read more...

    Wiz Acquires Dazz for $450 Million to Expand its Cybersecurity Platform

    2024-11-21

    TechCrunch: Wiz, one of the most talked-about names in the world of cybersecurity, is making a significant acquisition to expand its product reach in cloud security, particularly with developers.

    Read more...

    11 Biggest Financial Sector Cybersecurity Threats

    2024-11-20

    CSO Online: The financial sector faces a wide array of serious security threats that will only increase as cybercriminals make greater use of AI. Financial sector firms are uniquely exposed to cyber risk due to the large amounts of sensitive data and transactions they process. 

    Read more...

    Fintech Giant Finastra Confirms it’s Investigating a Data Breach

    2024-11-20

    TechCrunch: Finastra, a London-based financial software company that serves most of the world’s top banks, has confirmed it’s investigating a data breach after a hacker claimed a compromise of the company’s internal file-transfer platform. 

    Read more...

    Twine Attracts Top Investors for a $12 Million Seed Round to Create Digital Cybersecurity Employees

    2024-11-20

    Business Wire: Twine, a US and Israeli-based cybersecurity company, announced $12M in seed funding co-led by Ten Eleven Ventures and Dell Technologies Capital, with participation from angel investors including the founders of Wiz.

    Read more...

    CISA Director Jen Easterly to Step Down

    2024-11-19

    SecurityWeek: The US government’s cybersecurity agency CISA on Tuesday confirmed that director Jen Easterly and deputy Nitin Natarajan will depart on January 20, clearing the way for a leadership overhaul by the incoming administration.

    Read more...

    Audit Committees Expand Oversight to ESG, Cybersecurity, AI: EY

    2024-11-18

    CFO Dive: The SEC this year blunted requirements of a rule focused on climate risk disclosure before putting the regulation on hold in the face of legal challenges. Companies would be required to disclose the impact of climate change on their finances, operations and business strategy.

    Read more...

    Know Your Breach: Hot Topic

    The Target: Retail giant Hot Topic, which has more than 640 stores across the U.S.

    The Take: The stolen data includes email addresses, physical addresses, phone numbers, purchases, genders, and dates of birth. Partial credit card data was also included in the breach, including credit card type, expiry dates, and the last four digits of the card number.

    The Vector: The breach occurred on October 19 and was claimed by a threat actor operating under the alias “Satanic” on October 21. In a post on the cybercrime forum BreachForums, Satanic claimed to have stolen 350 million user records from Hot Topic and its affiliated brands, Box Lunch and Torrid.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Bitsight Buys Dark Web Security Specialist Cybersixgill for $115 Million

    2024-11-14

    TechCrunch: More consolidation is afoot in the world of cybersecurity. Bitsight, a cybersecurity startup last valued at $2.4 billion when ratings firm Moody’s took a stake in the business and became its largest shareholder in 2021, is acquiring Cybersixgill for $115 million.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates