shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: SuperVPN

    The Target: SuperVPN, a popular free VPN service provider.

    The Take: Exposed database containing of 360,308,817 million records of wide-ranging sensitive information including: email addresses, original IP addresses, geolocation data, UUID numbers, operating systems, internet connection types, and VPN application versions.

    The Vector: A misconfigured database was left open and unsecured with no password, meaning anyone with an internet connection could have downloaded the data.

    This breach is a perfect example of a preventable cyber incident. Securing access to databases through rigorous password hygiene is an essential component of security. Furthermore, the data stolen in this attack can be used for crafting highly effective phishing attacks. Companies should take every measure necessary to secure customer data.

    Read more...

    Binance Aids US Law Enforcement in Seizing $4.4 Million Linked to North Korean Cybercrimes

    2023-05-25

    Blockchain News: Leading cryptocurrency exchange Binance has assisted US law enforcement in seizing $4.4 million and freezing accounts associated with North Korean organized crime. 

    Read more...

    New Veeam Research Finds 93% of Cyber Attacks Target Backup Storage to Force Ransom Payment

    2023-05-23

    Business Wire: Organizations of all sizes are increasingly falling victim to ransomware attacks and inadequately protecting against this rising cyberthreat.

    Read more...

    What Security Professionals Need to Know About Aggregate Cyber-Risk

    2023-05-23

    Dark Reading: Risk aggregation is not a new phenomenon. The insurance industry, for example, has long examined how shared assets and similarities between organizations in their books bundle potential risk. 

    Read more...

    Palo Alto Lifts Annual Forecasts on Resilient Cybersecurity Spending

    2023-05-23

    Yahoo Finance: Palo Alto Networks Inc. raised its annual forecasts for revenue and adjusted profit as enterprise customers shift to one-stop shops for their cybersecurity needs in a bid to reduce costs.

    Read more...

    16 Tips For Creating Effective Companywide Cybersecurity Initiatives

    2023-05-23

    Forbes: With ever-evolving attack strategies and a growing list of countries and states adding regulations, companies have no choice but to be more proactive about cybersecurity. 

    Read more...

    London AI Firm Bags $250m Injection Led By Qatari Sovereign Wealth Fund

    2023-05-23

    City AM: A London-based artificial intelligence firm has announced a $250m cash injection led by the Qatari sovereign wealth fund as investors rush to capitalise on a boom in AI technology.

    Read more...

    Cybersecurity Firms' Earnings Set to Benefit From Growing Threat of Hacks

    2023-05-22

    US News: Top U.S. cybersecurity companies are expected to report another quarter of strong growth as high-profile hacks and a shift in client preference for bigger players with better integrated offerings help support their businesses in a turbulent economy.

    Read more...

    Know Your Breach: Leverage EDU

    The Target: Leverage EDU, a software University Admission platform.

    The Take: Exposure of over 240,000 records of Personally Identifiable Information including: names, email addresses, passport scans, applications, bank statements and loan information.

    The Vector: A misconfigured database was left open and unsecured with no password, meaning anyone with an internet connection could have viewed and downloaded the trove of data.

    This shows how important authentication controls are and that they are purposefully and smartly deployed with security in mind. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Compliance Managers Struggling to Manage Off-Channel Comms Risk

    2023-05-17

    Funds Tech: Despite the fact that the majority of financial firms have banned the use of social media platforms such as WhatsApp and WeChat, compliance officers are not convinced this will be effective in managing the risk of off-channel communications.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates