Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Why Do Phishing Attacks Work? Blame the Humans, Not the Technology

      2021-04-08

      ZDNet: Phishing attacks remain a huge problem and crooks are spending a lot of time and effort to ensure that, for the potential victim, clicking on a bad link is the most intuitive and easiest thing to do.

      Read more...

      Key House Leader to Press for Inclusion of Cybersecurity in Infrastructure Bill

      2021-04-07

      The Hill: Rep. Yvette Clarke (D-N.Y.), the chair of a key cyber House panel, said Wednesday that she would push for inclusion of language on securing critical systems as part of negotiations around President’s Biden’s infrastructure proposal.

      Read more...

      Facebook Does Not Plan to Notify Half-billion Users Affected by Data Leak

      2021-04-07

      Reuters: Facebook Inc did not notify the more than 530 million users whose details were obtained through the misuse of a feature before 2019 and recently made public in a database, and does not currently have plans to do so, a company spokesman said.

      Read more...

      Data Breach Disclosures Drop in 2020

      2021-04-07

      Compliance Week: The report, “Trends in Cybersecurity Breach Disclosures,” was released and analyzes public company disclosures of cyber-breaches since 2011. According to the report, the 117 breaches that were disclosed in 2020 represents a 19 percent drop from 2019 (144). Still, it is the third highest figure in a single year, behind 2019 and 2018 (130). The number had gone up each year since a dip to 50 in 2015.

      Read more...

      European Institutions Were Targeted in a Cyber-Attack Last Week

      2021-04-06

      BNN Bloomberg: A spokesperson for the commission said that a number of EU bodies “experienced an IT security incident in their IT infrastructure.” The spokesperson said forensic analysis of the incident is still in its initial phase and that it’s too early to provide any conclusive information about the nature of the attack.

      Read more...

      LinkedIn Phishing Ramps Up With More-Targeted Attacks

      2021-04-05

      Dark Reading: Phishing attacks are targeting out-of-work users on LinkedIn, creating lures using job titles scraped from the targeted workers' profiles in an attempt to convince them to open and execute different malicious files or links, according to a new analysis from cybersecurity firm eSentire.

      Read more...

      Know Your Breach: Ubiquiti

      The target: Ubiquiti, a major vendor of cloud-enabled networking devices. 

      The take: Source code, customer data, and cryptographic secrets which would enable remote access to both professional and consumer-grade customer devices.

      The attack vector: The attackers gained control of administrative credentials stored on an IT employee’s LastPass account. With these in hand, the threat actors gained high-level access to Ubiquiti Amazon Web Services accounts, including database storage servers, application logs, and user credentials. Multiple backdoor accounts were reportedly created. A whistleblower alleged that due to an absence of database access logging, Ubiquiti were unable to confirm which records had been accessed, by whom, and when.

      While use of password vaults and privileged account management tools are absolutely a best practice, these tools can only be as secure as the authentication measures enforced upon them. Complex, unique passwords in addition to two-factor authentication should be in place wherever possible to protect privileged credentials and management consoles.

      Additionally – comprehensive logging practices are critical to the reconstruction of events when investigating a breach, and the absence thereof can severely limit a firm’s the ability to determine the full scope of the attack.

      Read more...

      Vanguard Targeted in Bond Fund Scam

      2021-03-31

      Financial Standard: The asset manager said scammers are buying advertisements on search engines for terms relating to "bond or high yield investments". When a person clicks on the ad link, they are taken to a fake investment comparison website with a name like "Investment Compare".

      Read more...

      Cybercrime in the US Jumped By 55% in the Past Two Years

      2021-03-31

      CNet: Cybercrime is on the rise as hackers continue to steal data, disrupt business and cause harm online. The result is billions of dollars in losses: The total annual loss in the US from cybercrime reached $4.2 billion in 2020, according to data released from StockApp.com

      Read more...

      83% of Businesses Hit With a Firmware Attack in Past Two Years

      2021-03-31

      Dark Reading: Firmware attacks targeting enterprises are up over the past two years. However, most victims are too preoccupied with patches and upgrades to invest resources into preventing them. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates