Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      BoE’s Williams: Banks' Third Party Cybersecurity Worries Growing

      2019-09-27

      Bob's Guide: On May 14, BoE’s director of supervisory risk specialists, Nick Strange gave a progress report on operational resilience, and announced that the Financial Policy Committee (FPC) would have an upcoming stress testing pilot on payment systems.

      Read more...

      Know Your Breach: Option Way

      The target: Flight booking site, Option Way.

      The take: Security researchers were able to access Option Way’s Elasticsearch database via browser due to misconfiguration. Exposed (and unencrypted) data personally identifying information is a ripe target for identity thieves.

      The attack vector: Security researchers were able to access Option Way’s Elasticsearch database via browser due to misconfiguration. Exposed (and unencrypted) data includes names, dates of birth, gender, e-mail addresses, phone numbers and addresses - a ripe target for identity thieves. 

      Companies must evaluate their ‘attack surface’ across servers/firewalls and third-party services to ensure that their data is secure and should continuously monitor infrastructure to be assured that changes do not result in exposure of sensitive information.

      Read more...

      State AG Sues Dunkin’ Over Response to App Cyberattacks

      2019-09-26

      New York Post: The New York Attorney General sued the retail chain formerly known as Dunkin Donuts for its handling of a cyber-security lapse that gave hackers access to hundreds of thousands in store credit that could only be used to buy crullers and other Dunkin products.

      Read more...

      Gone Phishing: How Easy is it to Fall for a Fake Email?

      2019-09-26

      CityAM: Phishing emails are a major concern in cyber security. Some, like that message, are intended to trick the recipient into revealing sensitive information, while others are used to install malware onto someone’s device – sometimes without their knowledge – or can even lead to a ransomware attack, where the user is locked out of their system unless they fork over cash to the perpetrator.

      Read more...

      Cybersecurity: Why You Should Hire Staff from Firms That Have Fallen Victim to Hackers

      2019-09-25

      ZDNet: Companies that fall victim to cyberattacks and data breaches often come in for criticism, but one of the best things an organisation can do to ensure it remains protected against the impacts of a hacking incident is to take advantage of the expertise of cybersecurity professionals who've faced a major attack.

      Read more...

      New California Privacy Initiative Proposed for 2020 Ballot

      2019-09-25

      CNet: California is poised to enact the country's most stringent privacy law on Jan. 1, but the driving force behind the California Consumer Privacy Act wants privacy rights in the state to be even stronger. 

      Read more...

      Growth in Fintech Drives Growth in Cyberattacks - Kaspersky

      2019-09-24

      IOL: According to reports, Africa’s Fintech ecosystem has surged 60 percent in the last two years and the continent’s Fintech firms have grown to 491 from 301 in 2017, with $132.8 million raised in 2018, making last year the sector’s best year yet - and proving the sector’s readiness given the high mobile phone penetration levels and the boom in mobile financial services and payment technologies.

      Read more...

      Russian Hacker Pleads Guilty to Huge Data Thefts from JPMorgan, Others

      2019-09-23

      Bloomberg: A Russian hacker admitted Monday that he executed the largest known cyber-attack against a U.S. bank, pleading guilty to charges that he stole data on more than 80 million clients of JPMorgan Chase & Co. and other institutions that netted hundreds of millions of dollars in ill-gotten gains.

      Read more...

      27 Countries Sign Cybersecurity Pledge with Digs at China and Russia

      2019-09-23

      CNN: Twenty-seven countries have signed a joint agreement on what constitutes fair and foul play in cyberspace — with a nod toward condemning China and Russia.

      Read more...

      Know Your Breach: Scotiabank

      The target: Scotiabank, a major Canadian based banking institution

      The take: Login keys to backend systems, internal source code of mobile apps, software blueprints, and credentials for a database of foreign exchange rate data.

      The attack vector: The data in question was left accessible on a non-secured public repository, GitHub. Analysis of the leaked data could provide numerous and deep exploitations and vulnerabilities.

      Source code repositories, like file storage repositories, must be correctly configured to ensure that sensitive data remains internal and accessible only by authorized parties. Default permissions or accessibility settings must always be reviewed before sensitive data is committed to storage.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates