shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: General Electric

    The Target: General Electric (GE) is an American multinational company with divisions in power, renewable energy, and aerospace industries.

    The Take: According to the threat actor, "data includes a lot of DARPA-related military information, files, SQL files, documents etc." As proof of the breach, the threat actor shared screenshots of what they claim is stolen GE data, including a database from GE Aviations that appears to contain information on military projects.

    The Vector: The data was exposed through a server that was misconfigured so that it was accessible online.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Unpacking The New SEC Cybersecurity Rules: What Every CXO Needs To Know

    2023-11-30

    Forbes: The hyper-connected nature of our world, the growing use of cloud applications and the fact that data now resides anywhere are all contributing factors to the ubiquity of cyberattacks. 

    Read more...

    Okta Hackers Stole Data on All Customer Support Users in Major Breach

    2023-11-29

    CNBC: The news sent shares down as much as 7% in pre-market trading, although the stock recovered after Okta posted earnings that beat estimates. The company had originally been expected to report earnings after the bell, but moved its report up to the morning shortly after it disclosed the expanded breach in a blog post filed with the SEC.

    Read more...

    The Role Of Outsourcing In Navigating The Cybersecurity Skills Gap

    2023-11-29

    Forbes: On one hand, 63% of cybersecurity professionals complain that working conditions have become more difficult over the last two years owing to a heavy surge in cyberattacks, mounting data privacy concerns, overwhelming workloads, budget restrictions, staffing shortages and a complex regulatory environment.

    Read more...

    CrowdStrike Forecasts Strong Q4 Revenue on Resilient Cybersecurity Demand

    2023-11-28

    US News: CrowdStrike Holdings on Tuesday forecast fourth-quarter revenue above Wall Street estimates, driven by resilient demand for its cybersecurity offerings in the wake of rising online threats.

    Read more...

    Police Dismantle Ransomware Group Behind Attacks In 71 Countries

    2023-11-28

    Bleeping Computer: In cooperation with Europol and Eurojust, law enforcement agencies from seven nations have arrested in Ukraine the core members of a ransomware group linked to attacks against organizations in 71 countries.

    Read more...

    The Role of Cybersecurity in Attracting Venture Capital for Tech Startups

    2023-11-28

    CXOtoday: Cybersecurity is an integral part of Industry 4.0. In the current era of fast technological advancements and innovations, cybersecurity is the key to continued success and business longevity.

    Read more...

    How AI Is Transforming Cybersecurity Amid Regulatory Overhaul

    2023-11-27

    Yahoo Finance: Artificial intelligence and automation are reshaping the digital defense landscape. Companies are engaged in a relentless race to outpace cyber threats, with the effectiveness of their cybersecurity systems playing a pivotal role in determining market success moving forward.

    Read more...

    Know Your Breach: AutoZone

    The Target: AutoZone is the leading retailer and distributor of automotive spare parts and accessories in the U.S., operating 7,140 shops in the country and also in Brazil, Mexico, and Puerto Rico.

    The Take: The data leaked by the cybercriminals is roughly 1.1GB in size, containing employee names, email addresses, parts supply details, tax information, payroll documents, Oracle database files, data about stores, production and sales information, and more. No customer data appears in the leaked files.

    The Vector: AutoZone became aware that an unauthorized third party exploited a vulnerability associated with MOVEit and exfiltrated certain data from an AutoZone system that supports the MOVEit application. More specifically, on or about August 15, 2023, AutoZone determined that the exploitation of the vulnerability in the MOVEit application had resulted in the exfiltration of certain data.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Fidelity National Financial Shuts Down Network in Wake of Cybersecurity Incident

    2023-11-22

    TechCrunch: Fidelity National Financial, or FNF, a Fortune 500 company that provides title insurance and settlement services for the mortgage and real estate industries, announced that it was the victim of a “cybersecurity incident that impacted certain FNF systems.”

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates