shutterstock_490960141-1

Industry News: ESG5

    Rethinking Cybersecurity's Structure & the Role of the Modern CISO

    2023-04-10

    Dark Reading: Effective cybersecurity operations are as unique as the business models and technology choices of the companies they protect. Their creation and management are constantly complicated by a lack of common terminology and set of expectations, due mainly to the chaotic path our industry has taken since its relatively recent birth.

    Read more...

    Know Your Breach: SafeMoon

    The Target: SafeMoon, a DeFi platform for cryptocurrency trading.

    The Take: Theft of $8.9 million USD. 

    The Vector: A software feature intended for internal use only was set to public, allowing attackers to exploit and artificially inflate the price of the SafeMoon token and then sell them for large amounts of cash.

    This breach is critical reminder that new software features must be thoroughly tested before deployment. In addition, ensuring proper access settings around this kind of software is paramount for an overall robust cybersecurity posture.

    Read more...

    Australia May Inadvertently Fuel Cyber Crime, Says Data Theft Victim Organisation

    2023-04-05

    Economic Times: An Australian government-backed service for victims of identity theft blasted a plan to toughen privacy laws amid an explosion of online data theft, saying it would spur compromised companies to pay ransom and invite more hacking.

    Read more...

    How Strategic Investors Can Help Cybersecurity Startups

    2023-04-04

    Dark Reading: Economic uncertainty puts enormous pressure on cybersecurity startups already struggling to break into a crowded market. It's bad news for both these nascent companies and their potential customers: As cyberattacks grow more prevalent, the need for innovative solutions from startups is greater than ever.

    Read more...

    China Probes Micron for Cybersecurity Risks, Urges Japan to Stay Out of US Chip Export Curbs

    2023-04-04

    Tech Crunch: The U.S. and China chip battle continues to escalate. In China, the country’s cybersecurity watchdog has initiated a probe into U.S. memory chip maker Micron Technology, according to a statement from the Cyberspace Administration of China (CAC) released.

    Read more...

    How Biden's Anti-Hacking 'Dream Team' Was Roiled by Internal Strife

    2023-04-03

    Financial Post: On March 2, US President Joe Biden’s administration proposed some of the most aggressive measures to fight cyberattacks to date. They would require businesses to beef up their defenses and hold software makers more accountable for security breaches.

    Read more...

    Cryptocurrency Companies Backdoored in 3CX Supply Chain Attack

    2023-04-03

    Bleeping Computer: Some of the victims affected by the 3CX supply chain attack have also had their systems backdoored with Gopuram malware, with the threat actors specifically targeting cryptocurrency companies with this additional malicious payload.

    Read more...

    Wages Dominate Cybercrime Groups' Operating Expenses

    2023-04-03

    Cision: Trend Micro Incorporated, a global cybersecurity leader, today published new research detailing how criminal groups start behaving like corporations as they grow bigger, but that this comes with its own attendant costs and challenges.

    Read more...

    Cyber Due Diligence Best Practices for Private Equity Firms

    2023-04-03

    Liberty Mutual: Cyber is a complex and constantly evolving challenge for any company but couple cyber risk with private equity activity and the risks can be compounded exponentially.

    Read more...

    Know Your Breach: Toyota

    The Target: Toyota Italy, one of the world’s largest vehicle manufacturers.

    The Take: Exposure of Personally Identifiable Information belonging to Toyota’s clients including: phone numbers and email addresses.

    The Vector: Unsecured and exposed marketing tools, namely APIs for Salesforce and Mapbox, were able to be accessed publicly on Toyota Italy’s website. This allowed attackers to access employee credentials to the third-party platforms and exfiltrate client data.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. In particular, the information exposed here is perfect for crafting highly believable phishing campaigns as it would allow push notifications. Access monitoring and testing for every public-facing webpage is a key strategy to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates