shutterstock_490960141-1

Industry News: ESG5

    CISA: LockBit Ransomware Extorted $91 Million in 1,700 U.S. Attacks

    2023-06-14

    Bleeping Computer: U.S. and international cybersecurity authorities said in a joint LockBit ransomware advisory that the gang successfully extorted roughly $91 million following approximately 1,700 attacks against U.S. organizations since 2020.

    Read more...

    ‘Aggressive’ China Cyberattacks Are The ‘Defining Threat’ Of Our Time, Top U.S. Cyber Official Says

    2023-06-13

    CNBC: China’s cyber-espionage and sabotage capacities are an “epoch-defining threat,” the top U.S. cybersecurity official said, warning that in the event of open warfare “aggressive cyber operations” would threaten critical U.S. transportation infrastructure “to induce societal panic.”

    Read more...

    Canadian Firms Slow in Responding to Cyber Attacks, Report Suggests

    2023-06-13

    IT World Canada: It can take Canadian organizations up to 48 days to detect and recover from a cyber attack, according to a new survey of infosec professionals.

    Read more...

    Are Cybersecurity Stocks Positioned To Rise? Here’s What One Analyst Says

    2023-06-12

    BNN Bloomberg: Demand for cybersecurity remains front and centre for companies looking to keep up in the tech era, which is why one analyst says she is bullish on stocks within the sector. 

    Read more...

    Know Your Breach: Neho

    The Target: Neho, a Swiss-based online real estate agency.

    The Take: Exposure of sensitive login credentials to Neho’s systems, potentially allowing attackers full access to databases, source-code, configuration profiles and more.

    The Vector: A misconfiguration on Neho’s website exposed login credentials to their systems to the public, allowing anyone with internet access who obtained these credentials to login as an authenticated Neho user.

    This breach is a critical reminder of how important access control is for overall cybersecurity. If an attacker obtains access to vetted credentials, they can pivot their movements into possibly every system belonging to the firm, making the attack an order of magnitude more deadly. Safe and secure storage of login credentials is essential to protecting a firm and their customers.

    Read more...

    The Multidimensional Relationship Between AI And Cybersecurity And Its Impact On Fintech

    2023-06-08

    Forbes: As automation increases, so does the extent of systematic cyber risk. Cybersecurity measures are thus prudent since it is only by looking through the lens of the hacker can one avail a progressive insight as to the best means of securing and protecting data.

    Read more...

    North Korean Hackers Blamed for $35 Million Atomic Wallet Crypto Theft

    2023-06-08

    SecurityWeek: A decentralized cryptocurrency wallet service with roughly five million users, Atomic is available on all major operating systems, including Windows, macOS, Linux, Android, and iOS.

    Read more...

    SEC Cyber Proposals Receive Mixed Feedback From Industry

    2023-06-07

    Plan Adviser: Commenters replying to the Securities and Exchange Commission’s three cybersecurity proposals requested additional flexibility and two years to comply with anything the regulator adopts, based on responses submitted through the deadline.

    Read more...

    Shortfall of Skilled Cybersecurity Workers in the US Reaches an Estimated 466,000, CyberSeek Data Reveals

    2023-06-06

    PR Newswire: Demand for cybersecurity talent continues to outpace supply, according to the latest data from CyberSeek, the joint initiative of the National Institute of Standards and Technology's (NIST) NICE program, Lightcast and CompTIA.

    Read more...

    Federal Cyber Incidents Reveal Challenges of Implementing US National Cybersecurity Strategy

    2023-06-05

    CSO: Microsoft revealed on May 24 that the Chinese threat group Volt Typhoon attempted to gain access to communications systems in the United States, including Navy infrastructure on Guam. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates