Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Know Your Breach: The German Federal Bar (BRAK) Association

      The Target: The German Federal Bar (BRAK) Association, an umbrella organization overseeing 28 regional bars across Germany and representing about 166,000 lawyers nationally and internationally.

      The Take: The organization is still trying to figure out how much information was taken involving communications from people contacting the Brussels office.

      The Vector: The hackers encrypted BRAK’s mail server and exfiltrated 160 gigabytes of data.

      This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

      Read more...

      Business Lobby Struggles to Thwart SEC Cybersecurity Disclosure Rules

      2023-08-23

      BNN Bloomberg: Business lobbyists are struggling to soften new US Securities and Exchange Commission rules that require publicly traded companies to quickly disclose cybersecurity breaches.

      Read more...

      Cybersecurity Companies Report Surge in Ransomware Attacks

      2023-08-23

      SecurityWeek: Ransomware attacks continue to be highly profitable for cybercrime groups and the recent reports released by various cybersecurity firms show that they are increasing both in terms of volume and sophistication. 

      Read more...

      Balancing Risk and Compliance: Implications Of The SEC’s New Cybersecurity Regulations

      2023-08-22

      CSO: Corporate cybersecurity is becoming a non-negotiable priority. How companies prepare for and defend themselves against cyber intrusions has profound implications for their operations, reputation, and bottom line.

      Read more...

      Commitment To Cybersecurity Must Come From The Top

      2023-08-22

      Forbes: As the complexities of cybersecurity evolve daily, it remains essential to grasp some fundamental principles. It can take time to figure out where to start. 

      Read more...

      Palo Alto Networks CEO Warns Companies Need Modern, Integrated Cybersecurity: ‘The Bad Actors Are Moving Faster’

      2023-08-21

      CNBC: Arora said the problem isn’t that companies lack cybersecurity vendors. Rather, their security infrastructure may consist of a complicated assortment of vendors, some of which are outdated.

      Read more...

      Less Noise, Better Signals: Why XDR and AI Are The Future of Cybersecurity

      2023-08-21

      VentureBeat: Capitalizing on malware-free tradecraft to launch undetectable breaches, attackers rely on legitimate system tools and living-off-the-land (LOTL) techniques to breach endpoints undetected.

      Read more...

      Cybersecurity Firm SentinelOne Explores Sale

      2023-08-21

      Yahoo Finance: SentinelOne Inc, a cybersecurity company with a market value of about $5 billion, has been exploring options that could include a sale, according to people familiar with the matter.

      Read more...

      Know Your Breach: Discord.io

      The Target: Discord.io is not an official Discord site but a third-party service allowing server owners to create custom invites to their channels. Most of the community was built around the service's Discord server, with over 14,000 members.

      The Take: The most sensitive information in the breach is a member's username, email address, billing address (small number of people), salted and hashed password (small number of people), and Discord ID.

      The Vector: A person known as 'Akhirah' began offering the Discord.io database for sale on the new Breached hacking forums. As proof of the theft, the threat actor shared four user records from the database.

      This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. In particular, the information exposed here is perfect for crafting highly believable phishing campaigns as it would allow push notifications. Access monitoring and testing for every public-facing webpage is a key strategy to mitigate these kinds of breaches to protect a firm’s customer base.

      Read more...

      Cyber Defenders Lead the AI Arms Race for Now

      2023-08-17

      Dark Reading: Cyber defenders so far are winning the war over artificial intelligence: AI tools have yet to be meaningfully integrated into cyberattacks, while defenders have been using them to greater effect.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates