Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      How to Protect Your Crypto from Cyber Attacks During COVID-19

      2020-05-09

      Coindesk: Unscrupulous hackers are socially engineering their way into financial systems and financial accounts. Well intentioned efforts to promote public safety are fostering prospective abrogation of personal data privacy.  At the same time, there are new areas of business opportunity for distributed ledger companies emerging from the crisis.

      Read more...

      Know Your Breach: SBA

      The target: Small Business Administration (SBA), a US government agency that supports entrepreneurs and small businesses.

      The take: Up to 8,000 applications for Economic Injury Disaster Loans may have been improperly exposed to other applicants, including such sensitive data as social security numbers, addresses, phone numbers, dates of birth, income and financial/insurance information.

      The attack vector: A flaw in the caching configuration of the online loan application portal, implemented to accommodate increased demand, meant that when one applicant pressed the ‘back’ button in their web browser during the application process, they may have been served a page containing the application data belonging to another business.

      Scalability of critical infrastructure is an essential component of web applications and electronic tools – sudden increases in demand for certain services are a reality in the face of the evolving COVID-19 pandemic. It is equally critical, however, that while considering system capacity, security controls are not weakened.

      Read more...

      150 People Lose Up to $10,000 of Super in Fraud

      Federal Police Commissioner Reece Kershaw said a cybercrime team was investigating the fraud, which came to light on April 30.

      Read more...

      91% of People Know Password Reuse is Insecure, Yet 75% do it Anyway

      2020-05-06

      Security Magazine: LastPass by LogMeIn released findings of its third Psychology of Passwords global report, revealing that people aren’t protecting themselves from cybersecurity risks even though they know they should. Year after year there is heightened global awareness of hacking and data breaches, yet consumer password behaviors remain largely unchanged, says the report.

      Read more...

      Research: Women Are Better at Cybersecurity Than Men

      2020-05-06

      Dark Reading: Women are better at cybersecurity and protecting themselves online, new research by NordPass suggests. The survey revealed that women are more concerned about the potential harm of their personal online accounts being hacked. They also tend to use unique passwords more often than men.

      Read more...

      State-Backed Hackers Behind Wave of Cyberattacks Targeting Coronavirus Response, US and UK Warn

      2020-05-05

      CNN: The United States and United Kingdom issued a new advisory Tuesday warning of ongoing cyberattacks against organizations involved in the coronavirus response, including health care bodies, pharmaceutical companies, academics, medical research organizations and local government.

      Read more...

      SteelEye Offers Financial Firms Free Communications Surveillance Software to Monitor Remote Workers

      2020-05-05

      Institutional Asset Manager: As firms reopen their offices, reduced density rules are likely to prevail for some time, meaning a workforce that is spread between the office and home. Monitoring communications by staff working in multiple locations will require changes in compliance processes, which may prove challenging if access to on-premise technology is needed. 

      Read more...

      US Financial Industry Regulator Warns of Widespread Phishing Campaign

      2020-05-04

      ZDNet: The US Financial Industry Regulatory Authority (FINRA) has issued a rare cyber-security alert today warning member organizations of "a widespread, ongoing phishing campaign."

      Read more...

      UK’s Coronavirus Tracing App Strategy Faces Fresh Questions Over Transparency and Interoperability

      2020-05-04

      Tech Crunch: The UK’s data protection watchdog confirmed today the government still hasn’t given it sight of a key legal document attached to the coronavirus contacts tracing app which is being developed by the NHSX, the digital transformation branch of the country’s National Health Service.

      Read more...

      Know Your Breach: Sheffield City Council

      The target: Council of the City of Sheffield in South Yorkshire, England

      The take: 8.6 million records of vehicle movements, labelled with license plate numbers and millions of photographs from the county’s 100 surveillance cameras.

      The attack vector: The city’s Automatic Number Plate Recognition (ANPR) system was left exposed and publicly available to anyone with an internet connection – furthermore, the internal dashboard on this exposed system employed absolutely no password protection or other method of authentication. Anyone with the public IP address of the system could immediately access and search the system by license plate number, potentially allowing bad actors to recreate the travel patterns and movements of individual citizens, minute by minute.

      As we have previously emphasized, security controls must be commensurate with the level of sensitivity of data being stored, and must travel with that data throughout its lifecycle. When personally identifiable information is being collected and processed, best practise would prescribe multiple compensatory layers of protection, as consequences for breaches of such data can include falling afoul of the GDPR and privacy legislation in other jurisdictions.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates