Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Australian Industry Panel Calls for ‘Clear Consequences’ of Cyber Attacks

      2020-07-21

      Computer weekly: An industry panel appointed by the Australian government to provide inputs on the country’s 2020 cyber security strategy has called for clear consequences for cyber attacks targeted at Australia, among other recommendations.

      Read more...

      U.S. Says China Backed Hackers Who Targeted COVID-19 Vaccine Research

      2020-07-21

      NBC News: In the latest attempt to "name and shame" China’s government-sponsored cyber theft, the Justice Department announced an indictment Tuesday charging two Chinese nationals — both in China — with hacking governments, dissidents, human rights activists and private companies, including those engaged in COVID-19 vaccine research.

      Read more...

      Know Your Breach: Cashaa

      The target: Cashaa, a British-based cryptocurrency exchange.

      The take: $3 million USD in Bitcoin

      The attack vector: The attackers compromised Cashaa’s systems by installing malware onto a company computer used to make their transactions. Once this malicious software was active, the attackers received a notification which informed them when one of Cashaa’s employees logged into the computer to make transfers from another crypto exchange site’s wallet. The hackers used their backdoor to access this wallet to drain the funds, receiving all 336 Bitcoin instead of the intended party.

      The point of entry for an attack can have cascading consequences and this incident shows why securing company computers with proper malware detection is absolutely critical to strong cybersecurity. The breach which led to the malicious software being installed and the further monitoring failure which allowed the malware to send out notifications to the attackers, facilitated the theft.

      Read more...

      Russian Group Targeted COVID-19 Vaccine Research in Canada, U.S. and U.K., Say Intelligence Agencies

      2020-07-16

      CBC: The Communications Security Establishment (CSE), responsible for Canada's foreign signals intelligence, said APT29 — also known as Cozy Bear and the Dukes — is behind the malicious activity.

      Read more...

      Twitter Blames 'Coordinated' Attack on Its Systems for Hack of Joe Biden, Barack Obama, Bill Gates and Others

      2020-07-16

      CNN Business: Twitter accounts belonging to Joe Biden, Bill Gates, Elon Musk and Apple, among other prominent handles, were compromised on Wednesday in what Twitter said it believes to be an attack on some of its employees with access to the company's internal tools.

      Read more...

      2020: The Year of Increased Attack Sophistication

      2020-07-15

      Help Net Security: There was an increase in both cyberattack volume and breaches during the past 12 months in the U.S. This has prompted increased investment in cyber defense, with U.S. businesses already using an average of more than nine different cybersecurity tools, a VMware survey found.

      Read more...

      Advent Acquisition Of Forescout Back On, Price Cut By $4 Per Share

      2020-07-15

      CRN: Advent International and Forescout have called off their dueling lawsuits and agreed to move forward with an acquisition for $4 per share less than the deal initially proposed in February.

      Read more...

      Microsoft Shuts Down CEO Fraud Scheme

      2020-07-14

      ACS: Microsoft has taken legal action to bring down a sophisticated cyber fraud scheme that targeted CEOs in more than 60 countries around the world.

      Read more...

      Hacker Breaches Security Firm in Act of Revenge

      2020-07-13

      ZDNet: A hacker claims to have breached the backend servers belonging to a US cyber-security firm and stolen information from the company's "data leak detection" service.

      Read more...

      Know Your Breach: Clubillion

      The target: Clubillion, an online gambling and casino app.

      The take: Over 200 million user records containing the following personally identifiable information: emails, private messages, winnings, IP addresses, and movements in the app itself.

      The attack vector: An unsecured Elasticsearch database hosted on Amazon Web Services was left unsecured and publicly accessible. Unlike other recent cases, this database was not a single static backup/archive of information, but was a live, ‘production’ database, constantly updated with up to 200M new records per day.

      In addition to the usual phishing attacks that could be launched with access to personal information, the inclusion of app movement and the fact the exposed data was continuously updated makes highly targeted spear-phishing campaigns extremely likely to succeed. While it is always disappointing to see lapses in security around database backups, it is absolutely crucial that production systems housing sensitive data are adequately protected.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates