shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: DISA Global Solutions

    The Target: DISA Global Solutions, Inc., a third-party employment screening services provider.

    The Take: The personal information accessed could have included people’s names, Social Security numbers, driver’s license numbers, other government ID numbers, financial account information and other data elements.

    The Vector: The company, which provides drug and alcohol testing and background checks, said it discovered on April 22, 2024, that it was the victim of cyber-attack that gave “an unauthorized third party” access to individuals’ personal information from Feb. 9, 2024, to April 22, 2024, the company said in a notice on its website.

     This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Evolution Equity Partners Adds Cyber Investor Veteran John Cordo

    2025-03-06

    PR Newswire: Evolution Equity Partners, a leading venture capital investor, is thrilled to announce that John Cordo has joined the firm. John joins a team of thirty investment professionals and eight general partners focused on investing in best-of-breed cybersecurity and AI companies. 

    Read more...

    Mass Federal Layoffs Will Hurt Cybersecurity, Former Top US Security Official Says

    2025-03-05

    Yahoo News: The mass culling of workers from federal payrolls will have a "devastating" impact on cybersecurity and national security, a top former National Security Agency official said.

    Read more...

    Cybersecurity In Asset Management: A Growing Battlefield

    2025-03-05

    Private Banker International: In an era where cyber threats loom large over every industry, asset managers find themselves in an increasingly precarious position. With substantial assets under management (AUM) and access to sensitive client data, these firms are prime targets for cybercriminals.

    Read more...

    Americans Are on High Alert as Data Breach Fears Reach a Breaking Point

    2025-03-05

    PR Newswire: A new survey by HostingAdvice reveals 95% of Americans worry about their personal data being exposed in a corporate data breach. The survey also found that more than 61% have received at least one data breach notification in the past two years.

    Read more...

    Cybersecurity Companies' Results Better Than Expected So Far, Modestly Pressured Guidance - Jefferies

    2025-03-04

    MSN: Jefferies said results of cybersecurity stocks have been better than expected so far, with modestly pressured first quarter and full year 2025 guidance.

    Read more...

    Cybersecurity for the Quantum Era: QI Raises €9.5 Million for Secure Communications

    2025-03-03

    EU Startups: Vienna-based Quantum Industries Gmbh (QI), a startup focused on quantum secure communications for critical infrastructure, announced today the successful completion of its Seed financing round, raising a total of €9.5 million in fresh capital.

    Read more...

    US Seizes $31 Million Worth of Crypto Stolen in Uranium Finance Hack

    2025-03-03

    SecurityWeek: Uranium Finance was hacked twice in April 2021, with the total losses amounting to over $53 million, making it one of the largest hacks in decentralized finance (DeFi) at the time.

    Read more...

    Know Your Breach: Orange Group

    The Target: Orange Group, a leading French telecommunications operator and digital service provider.

    The Take: According to the threat actor, who uses the alias Rey and is a member of the HellCat ransomware group, the stolen data is mostly from the Romanian branch of the company and includes 380,000 unique email addresses, source code, invoices, contracts, customer and employee information.

     The Vector: The threat actor compromised Orange’s systems by exploiting compromised credentials, and vulnerabilities in the company’s Jira software for bug/issue tracking, and internal portals.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    DeepSeek’s AI Shake-Up Could Boost Cybersecurity Risks, Spending: Report

    2025-02-25

    Yahoo Finance: Global cybersecurity spending is projected to surge in coming years as artificial intelligence tools like chatbots and agents proliferate, creating new risks that force enterprises to shore up their information technology defenses, according to Bloomberg Intelligence analysts.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates