shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: CalPERS

    The Target: California’s Public Employees' Retirement System, the largest public pension fund in the U.S., managing more than $477 billion in assets for over 1.5 million public employees, retirees, and their families in California.

    The Take: First and last names; dates of birth; and social security numbers. It could have also included the names of former or current employers, spouse or domestic partner, and child or children.

    The Vector: The organization said that it was informed on June 6 by a third-party vendor – PBI Research Services/Berwyn Group – that data was accessed by hackers exploiting the MOVEit file transfer tool.

    This breach serves as a reminder of the risks associated with third-party vendors and highlights the need for stringent security measures and oversight when handling sensitive customer information.

    Read more...

    Uncovering How AI's Dual Relationship With Cybersecurity Operates

    2023-06-28

    Forbes: The rapid growth of artificial intelligence (AI) has invented a new wave of challenges and concerns. Newer technologies such as ChatGPT, robotic surgeries, threat analytics and cybersecurity automation create relationships where protection and harm collectively operate.

    Read more...

    BlackBerry Posts Surprise Profit Thanks to Cybersecurity Strength, Shares Soar

    2023-06-28

    Yahoo Finance: BlackBerry posted a surprise profit for the first quarter as its cybersecurity business benefited from higher client spending, while its enterprise software continued to gain traction in automotive sector.

    Read more...

    Less Than Half of UK Banks Implement Most Secure DMARC Level

    2023-06-27

    CSO: Research suggests UK banks are lagging on email cybersecurity measures exposing customers, staff, and stakeholders to increased risk of email-based impersonation attacks.

    Read more...

    Data Security Startup Cyera Lands a $100M Investment

    2023-06-27

    Yahoo News: A trend accelerated by the mass move to digital during the pandemic, enterprises are having to handle an increasing amount of proprietary data.

    Read more...

    Private Equity and a Historic Approach to Cybersecurity

    2023-06-27

    Middle Market Growth: The exponential increase in both frequency and severity of cybersecurity breaches over the past few years has prompted the U.S. Securities and Exchange Commission (SEC) to propose significant new cybersecurity rules.

    Read more...

    Regulator Sanctions Medibank Following Data Hack Review

    2023-06-26

    Central Western Daily: Medibank says it will have no problems complying with orders to carry an additional $250 million in capital after a catastrophic data breach.

    PetroCanada Issues May Be 'Tip of the Iceberg' After Suncor Cybersecurity Incident

    2023-06-26

    BNN Bloomberg: Suncor Energy Inc. falling victim to a cyberattack may be the most significant cybersecurity breach of an oil and gas company thus far in Canadian history, experts say. 

    Read more...

    Know Your Breach: Intellihartx

    The Target: Intellihartx, a company providing patient balance resolution services to hospitals.

    The Take: Personal information of roughly 490,000 individuals, including names, addresses, insurance data and medical billing, diagnosis and medication information, birth dates, and Social Security numbers.

    The Vector: The cyberattack exploited a zero-day vulnerability in Fortra’s GoAnywhere managed file transfer software. Tracked as CVE-2023-0669 and leading to remote code execution, the flaw had been exploited starting January 28.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Why Your CEO Needs To Be A Cybersecurity Expert

    2023-06-22

    Forbes: The escalating frequency and severity of cyberattacks has made it clear that organizations must fortify their defenses to safeguard sensitive information and maintain the trust of customers and stakeholders.

    Read more...

    Cyber Breach Claims CalPERS Member Data

    2023-06-22

    Financial Standard: The California Public Employees' Retirement System (CalPERS) is alerting its retired members and their relevant family members that some of their personal information was downloaded in an attack on one of its third-party providers' systems.

    Read more...

    Australia's Perpetual Says 'Tech Outage' Affected Some Funds in Cyber Incident

    2023-06-21

    US News: Australian Perpetual confirmed an extended tech outage over an IT security incident, affecting some of its funds, though the fund manager reaffirmed that all its client investments and its own systems were unaffected and secure.

    Read more...

    Cybersecurity ETFs Set to Gain from AI's Usage in Scams

    2023-06-21

    Yahoo Finance: Artificial Intelligence is a doubt-edged sword for cybersecurity. For example, a key talking point at the RSA Conference 2023, as cited on techtarget.com, was the multifaceted impact of OpenAI's GPT-4 on cybersecurity. 

    Read more...

    Placing People & Realism at the Center of Your Cybersecurity Strategy

    2023-06-21

    Dark Reading: The cyber landscape continues to evolve as its economy grows. Ransomware attacks already account for trillions of dollars in damages to enterprises each year and standardized and sophisticated offerings such as ransomware-as-a-service and phishing-as-a service will soon become commonplace.

    Read more...

    UK’s Chief Hacker to Take Over National Crime Agency’s Economic and Organized Crime Directorate

    2023-06-19

    The Record: James Babbage, the head of the United Kingdom’s National Cyber Force (NCF), is to leave his role commanding the nation’s elite hacking capabilities later this month to take the reins at the National Crime Agency’s (NCA) directorate for economic and organized crime threats.

    Read more...

    European Investment Bank Hit by Cyber Attack After Russian Hackers Vow to Bring Down Financial System

    2023-06-19

    MSN: The European Investment Bank (EIB) has been hit by a cyber attack suspected to have been orchestrated by Russian hackers, days after threats to bring down the Western financial system.

    Read more...

    Know Your Breach: Scranton Cardiology

    The Target: Scranton Cardiology

    The Take: Exposure of Personally Identifiable Information including: full names, physical addresses, dates of birth, social security numbers, driver’s license, passport numbers, credit card and bank number details, and some medical information.

    The Vector: The breach occurred through a “brute-force” attack where the threat actor uses a program to sequentially try every combination to a password protected system.

    This breach is a critical reminder of standards and processes around password hygiene. Length and complexity for passwords, no matter where in a firm’s system they are set, is crucial for a robust overall cyber-security posture. When attackers gain access to legitimate employee credentials, they can act with all the permissions and privileges belong to the user.  

    Read more...

    Cybersecurity-as-a-Service Market To Be Worth $46.6 Billion by 2030 - Exclusive Report by Meticulous Research

    2023-06-15

    OpenPR: Cybersecurity-as-a-Service is a cloud-based approach to outsourcing cybersecurity, where security services are provided on a subscription basis and hosted by cloud providers.

    Read more...

    The Pace Of AI Innovation For Cybersecurity Is Fast And Furious

    2023-06-14

    Forbes: Given the speed and scope of digital transformation and related technologies, our vision of what these innovations can achieve encompasses what is possible today and the endless possibilities of tomorrow.

    Read more...

    Crypto Prime Broker FPG Loses Up to $20M in Cyber Attack

    2023-06-14

    CoinDesk: Floating Point Group (FPG), an institutional trading desk specializing in cryptocurrencies, suffered a cyber attack on Sunday, June 11, which resulted in a loss of between $15 million and $20 million in crypto, a spokesman for the firm told CoinDesk.

    Read more...

    CISA: LockBit Ransomware Extorted $91 Million in 1,700 U.S. Attacks

    2023-06-14

    Bleeping Computer: U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly $91 million following approximately 1,700 attacks against U.S. organizations since 2020.

    Read more...

    ‘Aggressive’ China Cyberattacks Are The ‘Defining Threat’ Of Our Time, Top U.S. Cyber Official Says

    2023-06-13

    CNBC: China’s cyber-espionage and sabotage capacities are an “epoch-defining threat,” the top U.S. cybersecurity official said, warning that in the event of open warfare “aggressive cyber operations” would threaten critical U.S. transportation infrastructure “to induce societal panic.”

    Read more...

    Canadian Firms Slow in Responding to Cyber Attacks, Report Suggests

    2023-06-13

    IT World Canada: It can take Canadian organizations up to 48 days to detect and recover from a cyber attack, according to a new survey of infosec professionals.

    Read more...

    Are Cybersecurity Stocks Positioned To Rise? Here’s What One Analyst Says

    2023-06-12

    BNN Bloomberg: Demand for cybersecurity remains front and centre for companies looking to keep up in the tech era, which is why one analyst says she is bullish on stocks within the sector. 

    Read more...

    Know Your Breach: Neho

    The Target: Neho, a Swiss-based online real estate agency.

    The Take: Exposure of sensitive login credentials to Neho’s systems, potentially allowing attackers full access to databases, source-code, configuration profiles and more.

    The Vector: A misconfiguration on Neho’s website exposed login credentials to their systems to the public, allowing anyone with internet access who obtained these credentials to login as an authenticated Neho user.

    This breach is a critical reminder of how important access control is for overall cybersecurity. If an attacker obtains access to vetted credentials, they can pivot their movements into possibly every system belonging to the firm, making the attack an order of magnitude more deadly. Safe and secure storage of login credentials is essential to protecting a firm and their customers.

    Read more...

    The Multidimensional Relationship Between AI And Cybersecurity And Its Impact On Fintech

    2023-06-08

    Forbes: As automation increases, so does the extent of systematic cyber risk. Cybersecurity measures are thus prudent since it is only by looking through the lens of the hacker can one avail a progressive insight as to the best means of securing and protecting data.

    Read more...

    North Korean Hackers Blamed for $35 Million Atomic Wallet Crypto Theft

    2023-06-08

    SecurityWeek: A decentralized cryptocurrency wallet service with roughly five million users, Atomic is available on all major operating systems, including Windows, macOS, Linux, Android, and iOS.

    Read more...

    SEC Cyber Proposals Receive Mixed Feedback From Industry

    2023-06-07

    Plan Adviser: Commenters replying to the Securities and Exchange Commission’s three cybersecurity proposals requested additional flexibility and two years to comply with anything the regulator adopts, based on responses submitted through the deadline.

    Read more...

    Shortfall of Skilled Cybersecurity Workers in the US Reaches an Estimated 466,000, CyberSeek Data Reveals

    2023-06-06

    PR Newswire: Demand for cybersecurity talent continues to outpace supply, according to the latest data from CyberSeek, the joint initiative of the National Institute of Standards and Technology's (NIST) NICE program, Lightcast and CompTIA.

    Read more...

    Federal Cyber Incidents Reveal Challenges of Implementing US National Cybersecurity Strategy

    2023-06-05

    CSO: Microsoft revealed on May 24 that the Chinese threat group Volt Typhoon attempted to gain access to communications systems in the United States, including Navy infrastructure on Guam. 

    Read more...

    After 'Inception' Attack, New Due Diligence Requirements Are Needed

    2023-06-05

    Dark Reading: Researchers investigating a supply chain attack disclosed by 3CX in March found it had an unusual and alarming origin: another company's supply chain attack.

    Read more...

    Microsoft-Backed Rubrik Hires Banks For IPO

    2023-06-05

    Yahoo Finance: Rubrik Inc, a U.S. cybersecurity software startup backed by Microsoft Corp and valued at $4 billion in a fundraising round two years ago, has hired banks for an initial public offering, four people familiar with the matter said.

    Read more...

    Know Your Breach: Toyota

    The Target: Toyota, a Japanese car manufacturer

    The Take: Two cloud databases exposed Personally Identifiable Information including: physical address, name, phone number, email address, customer ID, vehicle registration number, and vehicle identification numbers.

    The Vector: Several misconfigured cloud databases were left open and unsecured with no password, meaning anyone with an internet connection could have downloaded the data.

    Securing access to databases through rigorous password hygiene is an essential component of security, and cloud databases are no exception. Furthermore, the data stolen in this attack can be used for crafting highly effective automotive-based phishing attacks. Regular security compliance reviews can help prevent these breaches.

    Read more...

    Galvanick Announces $10 Million in Seed Funding for Its Industrial Cybersecurity Platform

    2023-06-01

    Business Wire: Galvanick, the cybersecurity solution for protecting industrial infrastructure against cyber attacks, announced its $10 million seed round. 

    Read more...

    Cloud Security is the Greatest Area of Concern for Cybersecurity Leaders According to EC-Council’s Certified CISO Hall of Fame Report 2023

    2023-06-01

    Yahoo Finance: EC-Council, the global leader in cybersecurity education and training, released its Certified Chief Information Security Officer Hall of Fame Report, honouring the top 50 Certified CISOs globally. 

    Read more...

    Investment May Be Down, but Cybersecurity Remains a Hot Sector

    2023-05-31

    Dark Reading: Despite a more cautious approach to financing, investors continue to scour the country for the next generation of cybersecurity startups that can aid enterprises in the never-ending quest to safeguard critical IT systems.  

    Read more...

    Cyberattacks a Matter of When, Not If: Industry Leaders

    2023-05-30

    Investment Executive: The recent data breach that affected customers of Toronto-based InvestorCOM Inc. has reminded large financial services firms of the importance of cybersecurity preparation.

    Read more...

    Governments Require a Comprehensive Workforce Development Strategy to Address Cybersecurity Skills Shortage, Says Info-Tech Research Group

    2023-05-30

    PR Newswire: Governments worldwide are becoming increasingly digital, leading to more prevalent and more diverse cyberattacks.

    Read more...

    The Trend Continues: Increased Regulatory Focus On Privacy & Cybersecurity For Private Funds

    2023-05-30

    Mondaq: Recent enforcement actions highlight the increased regulatory scrutiny that private funds may face with respect to internal cybersecurity protocols and responses to cyber-crimes and cyber incidents under new and updated cybersecurity laws.

    Read more...

    Capita Cyber-Attack: 90 Organizations Report Data Breaches

    2023-05-30

    The Guardian: About 90 organizations have reported breaches of personal information held by Capita after the outsourcing group suffered a cyber-attack, Britain’s data watchdog has said.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates