shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Salesforce

    The Target: Salesforce, Inc., an American cloud-based software company headquartered in San Francisco, California

    The Take: The goal of the phishing kit employed in this campaign was to steal Facebook account credentials, even featuring two-factor authentication bypassing mechanisms.

    The Vector: The attackers chained a flaw dubbed "PhishForce," to bypass Salesforce's sender verification safeguards and quirks in Facebook's web games platform to mass-send phishing emails.

    As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    A Global Law Firm Separates From Its Chinese Partner, Citing Cybersecurity and Data Rules

    2023-08-10

    US News: One of the world’s biggest law firms said it is separating from the Chinese firm that was part of its global network for eight years, citing changes in cybersecurity and other rules that have rattled foreign companies.

    Read more...

    Hackers to Compete For Nearly $20 Million in Prizes by Using A.I. For Cybersecurity, Biden Administration Announces

    2023-08-09

    CNBC: Hackers will have the chance to compete for millions of dollars in prizes by using artificial intelligence to protect critical U.S. infrastructure from cybersecurity risks, the Biden administration announced.

    Read more...

    Cybersecurity Giant Rapid7 Announces Sweeping Layoffs as Losses Mount

    2023-08-09

    TechCrunch: U.S. cybersecurity giant Rapid7 has announced plans to lay off 18% of its workforce, affecting more than 400 global employees.

    Read more...

    PE Cybersecurity Investment Relatively Robust in Europe, Plummets in US

    2023-08-08

    Yahoo Finance: Private equity investors have piled $4.7 billion into European cybersecurity companies so far this year, putting deal value on course to outperform 2022, when the total reached $7.6 billion.

    Read more...

    The Problem With Cybersecurity (and AI Security) Regulation

    2023-08-08

    Dark Reading: With the emergence of generative models, and large language models (LLMs) in particular, and the meteoric rise in the popularity of ChatGPT, there once again are calls for more security regulation. 

    Read more...

    Crypto Heavyweights Back New Cybersecurity Standards After Nearly $4 Billion Was Lost to Hacks in 2022

    2023-08-08

    Yahoo Finance: Amid the crypto industry's myriad obstacles, hacks still rank at the top of the list. Despite the bear market, last year saw a historic spike, with nearly $4 billion stolen by cybercriminals, according to the analytics firm Chainalysis.

    Read more...

    Securing The Future: Embracing Cloud-Centric Cybersecurity Strategies

    2023-08-08

    Forbes: We live in an age in which technology promises to shape the future. The near-constant flow of innovation makes it challenging for many business leaders to keep up.

    Read more...

    Know Your Breach: Hot Topic

    The Target: American retail chain Hot Topic.

    The Take: A threat actor obtained the valid account credentials for Hot Topic Rewards accounts from an unknown third party.

    The Vector: The series of breaches that occurred between Feb. 7 and June 21 was the result of automated credential stuffing attacks against the company’s website and mobile application. 

    This breach is a reminder of how authentication controls are an important part of an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data.

    Read more...

    These Are the Top Five Cloud Security Risks, Qualys Says

    2023-08-03

    Security Week: The five key risk areas are misconfigurations, external-facing vulnerabilities, weaponized vulnerabilities, malware inside a cloud environment, and remediation lag (that is, delays in patching).

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates