shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Orange Group

    The Target: Orange Group, a leading French telecommunications operator and digital service provider.

    The Take: According to the threat actor, who uses the alias Rey and is a member of the HellCat ransomware group, the stolen data is mostly from the Romanian branch of the company and includes 380,000 unique email addresses, source code, invoices, contracts, customer and employee information.

     The Vector: The threat actor compromised Orange’s systems by exploiting compromised credentials, and vulnerabilities in the company’s Jira software for bug/issue tracking, and internal portals.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    DeepSeek’s AI Shake-Up Could Boost Cybersecurity Risks, Spending: Report

    2025-02-25

    Yahoo Finance: Global cybersecurity spending is projected to surge in coming years as artificial intelligence tools like chatbots and agents proliferate, creating new risks that force enterprises to shore up their information technology defenses, according to Bloomberg Intelligence analysts.

    Read more...

    Geopolitical Tensions Fuel Surge in OT and ICS  Cyberattacks

    2025-02-25

    CSO Online: Attacks against operational technology (OT) networks are on the rise, fueled by geopolitical tensions and conflicts, as OT security fast becomes a mainstream concern.

    Read more...

    NinjaOne Snags $5B Valuation In Massive $500M Round

    2025-02-24

    Crunchbase: NinjaOne, which provides endpoint management, security and monitoring, raised $500 million in Series C extensions at a $5 billion valuation — more than doubling its value from just 12 months ago.

    Read more...

    Cybersecurity Firm Sues Advocis For $560K

    2025-02-24

    Investment Executive: Advocis faces its fourth legal claim in just over a year, this one arising from a cybersecurity contract the association allegedly terminated after naming its new CEO last fall. 

    Read more...

    Cybersecurity As A Brand Differentiator: Building Consumer Trust

    2025-02-24

    Forbes: Amid rising concerns about data breaches, identity theft and privacy violations, cybersecurity has become more than just an IT and business operations necessity—it has become a brand differentiator. 

    Read more...

    Private Equity Surges in Security and Defence Sectors

    2025-02-24

    Funds Europe: Private equity investment in security technology is accelerating, driven by rising geopolitical instability and increased government defence spending, according to research.

    Read more...

    Bybit Hack Exposes Multi-Sig Security Flaws as Industry Reevaluates Protections

    2025-02-24

    Wealth Professional: Bybit, one of the largest cryptocurrency exchanges, suffered a US$1.5bn security breach that has since triggered US$5.5bn in outflows.

    Read more...

    Know Your Breach: Globe Life

    The Target: Globe Life is an American financial services holding company.

    The Take: The information potentially exposed includes names, email addresses, phone numbers, and postal addresses. In some cases, Social Security numbers, health-related data, and other personal details may also have been involved.

     The Vector: The ongoing review indicated that the breach may have involved information linked to its American Life Insurance Co. subsidiary. In a new SEC filing on Jan. 30, Globe Life reported that customer information compromised in the attack was traced to databases maintained by a limited number of independent agency owners.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Tech Investment Firm Insight Partners Discloses Data Breach

    2025-02-19

    Cybersecurity Dive: Insight Partners suffered a data breach in January stemming from what it described as “a sophisticated social engineering attack.” In a statement the private equity and venture capital firm said it initially detected unauthorized access to “certain Insight information systems” on Jan. 16. 

    Read more...

    What A New Presidency Means For Global Cybersecurity—And For SMEs

    2025-02-19

    Forbes: As a cybersecurity leader dedicated to safeguarding small- and medium-sized enterprises (SMEs) from cyber threats, the shifting sands of the cybersecurity landscape are always top-of-mind.

    Read more...

    Bain Capital Backs Israeli AI Cybersecurity Startup Dream at $1.1 Billion Valuation

    2025-02-19

    Insurance Journal: Dream, an artificial intelligence company that provides cybersecurity services to governments and critical infrastructure operators such as hospitals and utilities, has raised $100 million at a $1.1 billion valuation.

    Read more...

    Cybersecurity Gaps Exposed as 96% of S&P 500 Firms Hit by Data Breaches

    2025-02-18

    Tech Monitor: Cybersecurity vulnerabilities continue to pose significant risks to major corporations, with 96% of S&P 500 companies experiencing data breaches, according to the latest findings from the Cybernews Business Digital Index

    Read more...

    Palo Alto Networks Warns Firewall Vulnerability Is Under Active Exploitation

    2025-02-18

    Cybersecurity Dive: Palo Alto Networks confirmed that a high severity vulnerability, listed as CVE-2025-0108, in its PAN-OS management web interface was being exploited by attackers in the wild.

    Read more...

    Cybersecurity Takes Centre Stage In Investor Due Diligence

    2025-02-17

    Funds Europe: Cybersecurity has emerged as a top priority for investors during fundraising due diligence, with 27% of investors now focusing on digital security risks, according to the Core Alternative Managers’ Mood Index (Cammi) report by Gen II Fund Services.

    Read more...

    Fintech Giant Finastra Notifies Victims of October Data Breach

    2025-02-17

    Bleeping Computer: Financial technology giant Finastra is notifying victims of a data breach after their personal information was stolen by unknown attackers who first breached its systems in October 2024.

    Read more...

    Know Your Breach: HPE

    The Target: Hewlett Packard Enterprise, an American multinational information technology company.

     The Take: A breach notification filing with the state of Massachusetts indicated that Social Security numbers, driver’s license numbers and credit/debit card numbers were compromised in the attack.

     The Vector: HPE was notified on Dec. 12, 2023, that a suspected nation-state threat group had breached its Office 365 email environment. An investigation revealed that starting in May 2023, Midnight Blizzard actors accessed emails and pilfered data from mailboxes “belonging to individuals in our cybersecurity, go-to-market, business segments, and other functions.”

     As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    Thoma Bravo-Backed SailPoint Set for US Market  Comeback After Over Two Years

    2025-02-13

    Yahoo Finance/Reuters: Thoma Bravo-backed cybersecurity firm SailPoint will start trading on the Nasdaq, returning to the U.S. stock market more than two years after it went private.

    Read more...

    Ransomware Gangs Shifting Tactics to Evade Enterprise Defenses

    2025-02-12

    Cybersecurity Dive: Huntress found that ransomware gangs are broadly using the kinds of advanced tactics and techniques that were first tested on large organizations, such as tampering or disabling cybersecurity products.

    Read more...

    Buyout Firms Vie For Cybersecurity Firm Trend Micro, Sources Say

    2025-02-12

    Yahoo Finance/Reuters: Bain Capital, Advent International and EQT AB are among the private equity firms competing to acquire Japanese cybersecurity firm Trend Micro, which has a market value of 1.32 trillion yen ($8.54 billion), according to people familiar with the matter.

    Read more...

    71% of Audit Committees Are Now Discussing Cybersecurity Quarterly

    2025-02-12

    CFO: In an time where deepfakes, synthetic identity fraud and fake documents pose an increasing threat to businesses, audit committees are ramping up cybersecurity oversight — yet financial and nonfinancial firms are taking vastly different approaches. 

    Read more...

    Trump to Nominate Sean Cairncross as National Cyber Director

    2025-02-12

    Cybersecurity Dive: President Donald Trump plans to nominate Sean Cairncross, a former official at the Republican National Committee, as the next national cyber director, according to a list of planned nominees obtained by Cybersecurity Dive. 

    Read more...

    India’s Central Bank Launches Exclusive Internet Domains to Combat Cyber Threats

    2025-02-10

    MSN: The Reserve Bank of India (RBI) is set to introduce exclusive internet domains for financial sector participants, including banks and non-banking entities, to enhance cybersecurity.  

    Read more...

    SolarWinds Taken Private in $4.4 Billion Turn/River Capital Acquisition

    2025-02-10

    SecurityWeek: Turn/River Capital is prepared to pay roughly $4.4 billion in cash for SolarWinds — $18.50 per share, which represents a 35% premium to the stock’s closing price over a period of 90 days prior to the deal being announced. 

    Read more...

    Know Your Breach: GrubHub

    The Target: ​Food delivery company GrubHub.

    The Take: GrubHub said that, depending on the affected individual, the attackers gained access to names, email addresses, and phone numbers, as well as partial payment card information (including card type and last four digits of the card number) for some campus diners.

    The Vector: The investigation found that the intrusion originated with an account belonging to a third-party service provider that provided support services to Grubhub.

     This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    21% of CISOs Pressured to Not Report Compliance Issues

    2025-02-06

    CSO Online: CISOs are increasingly getting caught between business pressures and regulatory obligations, leaving them struggling to balance corporate loyalty and legal accountability.

    Read more...

    DeepSeek Surge Hits Companies, Posing Security Risks

    2025-02-05

    Cybersecurity Dive: Employees attempting to use a company device to access Chinese tech startup DeepSeek’s wildly popular artificial intelligence app could inadvertently be exposing their organization to threats such as cyberespionage, experts warned.

    Read more...

    Why Cybersecurity Needs Probability — Not Predictions

    2025-02-05

    Dark Reading: Many cybersecurity leaders kick off each new year with predictions for the year to come. You may have seen a deluge of them over the last month or so: "Cyberattacks will continue to be a problem." "This certain country will ban ransom payments." 

    Read more...

    Cybersecurity is Top Priority for Investors as Digital Threats Escalate, Says Gen II

    2025-02-05

    Private Equity Wire: The report indicates that 27% of investors now prioritise cybersecurity in operational due diligence conversations, reflecting heightened awareness of digital threats in the private capital industry.

    Read more...

    Ransomware Payments Fell 35% in 2024

    2025-02-05

    Cybersecurity Dive: Cryptocurrency ransomware payments fell from a record $1.25 billion in 2023 to nearly $814 million in 2024, a report released by Chainalysis showed.

    Read more...

    Thoma Bravo's SailPoint Eyes up to $11.5 Billion Valuation in US IPO

    2025-02-05

    MSN/Reuters: SailPoint said it was targeting a valuation of up to $11.5 billion in its New York flotation, as the cybersecurity firm looks to go public again in the United States after more than two years.

    Read more...

    How To Address The Complexity Of Network Security

    2025-02-04

    Forbes: It stands to reason that as organizations grow, their footprint becomes more distributed. While this enables them to remain closer to their customers and other stakeholders, it also means their network environments become more complex.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates