shutterstock_490960141-1

Industry News: ESG5

    Investors Betting Big on Upwind for CNAPP Tech

    2023-09-06

    SecurityWeek: Upwind, which describes itself as a runtime-powered Cloud-Native Application Protection Platform (CNAPP), has raised a total of $80 million in just 10 months as investors continue to pour cash into startups in the cloud and data security categories.

    Read more...

    Electoral Commission Failed Cybersecurity Test in Same Year as Hack

    2023-09-05

    The Guardian: The Electoral Commission has admitted it failed a cybersecurity test in the same year that hackers successfully attacked the organization.

    Read more...

    Verizon Unit to Pay $4 Million US Penalty to Resolve Cybersecurity Claims

    2023-09-05

    Yahoo Finance: Verizon Business Network Services, a unit of the telecom giant , agreed to pay $4.1 million to resolve U.S. allegations that it failed to follow required cybersecurity standards, the U.S. Justice Department said.

    Read more...

    Dataprise Expands Footprint in New York City & Financial Services with the Acquisition of Cohere's Business

    2023-09-05

    PR Newswire: Dataprise, a premier provider of managed IT, cybersecurity and cloud solutions, announced that it has completed an acquisition of clients and employees of Cohere, a security-first managed services provider headquartered in New York City.

    Read more...

    German Financial Agency Site Disrupted By DDoS Attack

    2023-09-04

    Bleeping Computer: The German Federal Financial Supervisory Authority (BaFin) announced that an ongoing distributed denial-of-service (DDoS) attack has been impacting its website.

    Read more...

    Australian Government Mandates Agencies Appoint CISOs

    2023-09-03

    CSO: The Australian federal government has approved amendments to the Protective Security Policy Framework (PSPF) to mandate non-corporate Commonwealth entities to appoint a CISO to be responsible for cyber security leadership in the entity.

    Read more...

    Know Your Breach: TMX Finance Corporate Services

    The Target: TMX Finance Corporate Services, the parent company of lender TitleMax. TMX, which also operates the brands TitleBucks, InstaLoan and EquityAuto Loan, has more than 1,000 locations in 18 U.S. states.

    The Take: A revised data breach notification sent to victims by TMX stated that beyond the raft of personal information that it previously stated had been stolen - including passport and Social Security numbers - attackers may have also stolen their credit/debit card number in combination with security code, access code, password or PIN for the account.

    The Vector: TMX previously reported detecting suspicious activity on their systems on Feb. 13. A third-party incident response firm called in to investigate found the intrusion appeared to have started in early December 2022.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data.

    Read more...

    UK Cybersecurity Agency Warns Of Chatbot ‘Prompt Injection’ Attacks

    2023-08-30

    The Guardian: The UK’s cybersecurity agency has warned that chatbots can be manipulated by hackers to cause scary real-world consequences.

    Read more...

    AI In Cybersecurity: Harmful Or Helpful?

    2023-08-29

    Forbes: By now, it’s common knowledge that the pandemic accelerated the digital transformation of our work world. Remote and hybrid work environments and anytime-anywhere collaboration became the norm, and the adoption of cloud services increased substantially

    Read more...

    Addressing Cybersecurity's Talent Shortage & Its Impact on CISOs

    2023-08-29

    Dark Reading: The cybersecurity sector continues to face a dire talent shortage as the threat landscape evolves, according to recent research from ISC2, and the skill gap is only growing. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates