shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: PayPal

    The Target: Digital payments giant PayPal

    The Take: Hackers had access to names, addresses, Social Security numbers, individual tax identification numbers and dates of birth.

    The Vector: The threat actors behind the PayPal breach used a tactic called credential stuffing, where attackers use stolen username/password combinations from one data breach to attempt to log into other websites and services.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Finra Reports Rising Risks From AI, Cybersecurity, Investment Fraud

    2025-01-30

    Investment News: The constantly evolving landscape of third-party risks that are seen by Finra staff have been highlighted in its 2025 Regulatory Oversight Report.

    Read more...

    88% of High-Uncertainty Firms Report Significant Cybersecurity Risks

    2025-01-30

    PYMNTS: Cybersecurity is a major concern for CFOs of middle-market firms, especially those facing high uncertainty due to fluctuating demand, supply chain disruptions, or macroeconomic volatility. These challenges create financial strain and long-term strategic setbacks.

    Read more...

    The Growing Complexity of Global Cybersecurity: Moving From Challenges to Action

    2025-01-29

    World Economic Forum: While the complexity of today's cyber environment is daunting, our focus at the World Economic Forum's Centre for Cybersecurity must be on translating this complexity into concrete actions that organizations can implement to enhance their resilience.

    Read more...

    Cyber Security Market Size to Reach $578.2 Billion, Globally, by 2033 at 10.4% CAGR: Allied Market Research

    2025-01-28

    GlobeNewswire: Rise in cyber threats and surge in remote work trends are the factors expected to propel the growth of the global cybersecurity market. However, factors such as high implementation costs and a shortage of skilled professionals are anticipated to hamper the growth of the global market. 

    Read more...

    5 Ways Boards Can Improve Their Cybersecurity Governance

    2025-01-28

    CSO Online: As chairman of the board for Cinturion Group, Richard Marshall is intimately involved in ensuring the security of the fiber optic network his company is constructing from India through the Middle East and on to Europe.

    Read more...

    DeepSeek Hit With Large-Scale Cyberattack, Says it’s Limiting Registrations

    2025-01-27

    CNBC: DeepSeek said it would temporarily limit user registrations “due to large-scale malicious attacks” on its services, though existing users will be able to log in as usual.

    Read more...

    India's central bank asks lenders to tighten cybersecurity oversight

    2025-01-27

    MarketScreener: India's central bank said its chief has urged banks to tighten their oversight on cybersecurity issues and to have systems in place that can prevent digital fraud.

    Read more...

    Know Your Breach: Otelier

    The Target: Otelier, previously known as MyDigitalOffice, is a cloud-based hotel management solution used by over 10,000 hotels worldwide to manage reservations, transactions, nightly reports, and invoicing.

    The Take: The small samples seen by BleepingComputer include a broad range of data, including hotel guest reservations, transactions, employee emails, and other internal data. Some of the personal information exposed includes hotel guests' names, addresses, phone numbers, and email addresses.

    The Vector: The threat actors behind the Otelier breach told BleepingComputer that they initially hacked the company's Atlassian server using an employee's login. These credentials were stolen through information-stealing malware, which has become the bane of corporate networks over the past few years.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    Automation and AI-Driven Firewall Policy Management Become Essential for Cybersecurity and Compliance

    2025-01-22

    Business Wire: As organizations expand their digital ecosystems, the complexity of managing firewall policies across hybrid and multi-cloud environments continues to rise.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates