Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Britain Investigating Whether Leaked Trade Papers Were Hacked: Sources

      2019-12-08

      Reuters: British cyber security officials are investigating whether classified UK-U.S. trade documents that were shared online ahead of Thursday’s election were acquired by hacking or were leaked, two sources told Reuters.

      Read more...

      Know Your Breach: Sprint

      The target: Sprint, an American telecommunications company.

      The take: 261,300 documents, including phone bills and bank statements containing: names, addresses, phone numbers, and in some cases, screenshots with subscribers’ online usernames and account PINs.

      The attack vector: A misconfigured cloud storage bucket was publicly exposed and not protected by a password, allowing anyone with internet access to download the contents. The misconfiguration was traced a marketing agency contracted by Sprint.

      Any subsidiary or contractor which handles sensitive data is a potential breach source. Internal security controls must be extended to third parties handling a firm’s sensitive data.

      Read more...

      How Hackers Stole $1mn Fund Meant for Israeli Start-up

      2019-12-06

      The Economic Times: Tel Aviv, Researchers from cybersecurity firm Check Point have revealed how hackers stole $1 million seed funding sent by a Chinese venture capital firm to an Israeli start-up.

      Read more...

      U.S. Cracks Down on Russian 'Evil Corp' Hackers After $100 Million Spree

      2019-12-05

      Reuters: U.S. authorities on Thursday took aim at a Russian cybercriminal group known as Evil Corp, indicting its Lamborghini-driving alleged leader and ordering asset freezes against 17 of his associates over a digital crime spree that has netted more than $100 million from companies across the world.

      Read more...

      University of Ottawa Partners with IBM on new Cybersecurity Hub

      2019-12-04

      Ottawa Business Journal: Students and researchers at the University of Ottawa will now have access to tools and expertise on the cybersecurity sector from IBM Canada.

      Read more...

      The U.N. Passed a Russia-backed Cybercrime Resolution. That’s Not Good News for Internet Freedom.

      2019-12-04

      Washington Post: On Nov. 18, a United Nations committee passed a Russia-backed cybercrime resolution by a vote of 88 to 58, with 34 countries abstaining. Russia, Belarus, Cambodia, China, Iran, Myanmar, Nicaragua, Syria and Venezuela sponsored the resolution, titled “Countering the use of information and communications technologies for criminal purposes.” The United States said it is “disappointed with the decision.”

      Read more...

      The West Failed to Prepare for Cyber Attacks, Security Chief Admits

      2019-12-04

      The Telegraph: The West was slow to respond to the threat of cyber attacks, the chief of the NATO Cooperative Cyber Defence Centre (CCDCOE) has admitted.  

      **Article may require a subscription**

      Read more...

      Are We Waiting for Cyber Earthquake Before Getting Our Act Together, says NCSC

      2019-12-02

      Business Standard: Cyber Security Coordinator (NCSC) Lt Gen (retd) Rajesh Pant raised concern over the lack of cyber-infrastructure in the country and said are we waiting for a cyber earthquake before getting our act together.

      Read more...

      Top Israeli VC Talks Cyber-Security, Diversity and ‘No Go’ Investments

      2019-12-02

      Tech Crunch: Israel is a powerhouse in both offensive and defensive cyber operations, with cybersecurity giants CyberArk, Check Point, and Illusive Networks  all founded in the country in recent years.

      Read more...

      Know Your Breach: Adobe

      The target: Adobe, an American computer software company.

      The take: 7.5 million customer accounts which contained email addresses, account creation dates, subscription status, country and payment details.

      The attack vector: A misconfigured Elasticsearch cloud database was left online without any password protection. This information could easily be used to launch sophisticated, targeted phishing attacks to trick users into giving further sensitive details.

      When provisioning new systems or types of systems, care must be taken to ensure that appropriate and proportionate security measures are implemented, either by automated scanning or by manual review. Adopting (and validating) robust controls to technological tools employed is critical to secure operations. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates