Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Know Your Breach: Intellihartx

      The Target: Intellihartx, a company providing patient balance resolution services to hospitals.

      The Take: Personal information of roughly 490,000 individuals, including names, addresses, insurance data and medical billing, diagnosis and medication information, birth dates, and Social Security numbers.

      The Vector: The cyberattack exploited a zero-day vulnerability in Fortra’s GoAnywhere managed file transfer software. Tracked as CVE-2023-0669 and leading to remote code execution, the flaw had been exploited starting January 28.

      This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

      Read more...

      Why Your CEO Needs To Be A Cybersecurity Expert

      2023-06-22

      Forbes: The escalating frequency and severity of cyberattacks has made it clear that organizations must fortify their defenses to safeguard sensitive information and maintain the trust of customers and stakeholders.

      Read more...

      Cyber Breach Claims CalPERS Member Data

      2023-06-22

      Financial Standard: The California Public Employees' Retirement System (CalPERS) is alerting its retired members and their relevant family members that some of their personal information was downloaded in an attack on one of its third-party providers' systems.

      Read more...

      Australia's Perpetual Says 'Tech Outage' Affected Some Funds in Cyber Incident

      2023-06-21

      US News: Australian Perpetual confirmed an extended tech outage over an IT security incident, affecting some of its funds, though the fund manager reaffirmed that all its client investments and its own systems were unaffected and secure.

      Read more...

      Cybersecurity ETFs Set to Gain from AI's Usage in Scams

      2023-06-21

      Yahoo Finance: Artificial Intelligence is a doubt-edged sword for cybersecurity. For example, a key talking point at the RSA Conference 2023, as cited on techtarget.com, was the multifaceted impact of OpenAI's GPT-4 on cybersecurity. 

      Read more...

      Placing People & Realism at the Center of Your Cybersecurity Strategy

      2023-06-21

      Dark Reading: The cyber landscape continues to evolve as its economy grows. Ransomware attacks already account for trillions of dollars in damages to enterprises each year and standardized and sophisticated offerings such as ransomware-as-a-service and phishing-as-a service will soon become commonplace.

      Read more...

      UK’s Chief Hacker to Take Over National Crime Agency’s Economic and Organized Crime Directorate

      2023-06-19

      The Record: James Babbage, the head of the United Kingdom’s National Cyber Force (NCF), is to leave his role commanding the nation’s elite hacking capabilities later this month to take the reins at the National Crime Agency’s (NCA) directorate for economic and organized crime threats.

      Read more...

      European Investment Bank Hit by Cyber Attack After Russian Hackers Vow to Bring Down Financial System

      2023-06-19

      MSN: The European Investment Bank (EIB) has been hit by a cyber attack suspected to have been orchestrated by Russian hackers, days after threats to bring down the Western financial system.

      Read more...

      Know Your Breach: Scranton Cardiology

      The Target: Scranton Cardiology

      The Take: Exposure of Personally Identifiable Information including: full names, physical addresses, dates of birth, social security numbers, driver’s license, passport numbers, credit card and bank number details, and some medical information.

      The Vector: The breach occurred through a “brute-force” attack where the threat actor uses a program to sequentially try every combination to a password protected system.

      This breach is a critical reminder of standards and processes around password hygiene. Length and complexity for passwords, no matter where in a firm’s system they are set, is crucial for a robust overall cyber-security posture. When attackers gain access to legitimate employee credentials, they can act with all the permissions and privileges belong to the user.  

      Read more...

      Cybersecurity-as-a-Service Market To Be Worth $46.6 Billion by 2030 - Exclusive Report by Meticulous Research

      2023-06-15

      OpenPR: Cybersecurity-as-a-Service is a cloud-based approach to outsourcing cybersecurity, where security services are provided on a subscription basis and hosted by cloud providers.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates