shutterstock_490960141-1

Industry News: ESG5

    Cryptocurrency Companies Backdoored in 3CX Supply Chain Attack

    2023-04-03

    Bleeping Computer: Some of the victims affected by the 3CX supply chain attack have also had their systems backdoored with Gopuram malware, with the threat actors specifically targeting cryptocurrency companies with this additional malicious payload.

    Read more...

    Wages Dominate Cybercrime Groups' Operating Expenses

    2023-04-03

    Cision: Trend Micro Incorporated, a global cybersecurity leader, today published new research detailing how criminal groups start behaving like corporations as they grow bigger, but that this comes with its own attendant costs and challenges.

    Read more...

    Cyber Due Diligence Best Practices for Private Equity Firms

    2023-04-03

    Liberty Mutual: Cyber is a complex and constantly evolving challenge for any company but couple cyber risk with private equity activity and the risks can be compounded exponentially.

    Read more...

    Know Your Breach: Toyota

    The Target: Toyota Italy, one of the world’s largest vehicle manufacturers.

    The Take: Exposure of Personally Identifiable Information belonging to Toyota’s clients including: phone numbers and email addresses.

    The Vector: Unsecured and exposed marketing tools, namely APIs for Salesforce and Mapbox, were able to be accessed publicly on Toyota Italy’s website. This allowed attackers to access employee credentials to the third-party platforms and exfiltrate client data.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. In particular, the information exposed here is perfect for crafting highly believable phishing campaigns as it would allow push notifications. Access monitoring and testing for every public-facing webpage is a key strategy to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    Cybersecurity: Bright Spot Amid Tech Layoffs

    2023-03-30

    Fox Business: While tech firms are firing, the cybersecurity segment is hiring. Technology firms have shed more than 300,000 jobs in the past two years with more on the way. Electronic Arts announced a restructuring plan that includes a 6% workforce reduction to prioritize "growth opportunities."

    Read more...

    Cybersecurity Investment Outlook Remains Grim as Funding Activity Sharply Declines

    2023-03-29

    DarkReading: Financial activity in the cybersecurity industry declined sharply in the first quarter of 2023 compared to the same period in 2022, and analysts tracking the sector expect little improvement until at least the second half of the year.

    Read more...

    Private Equity Turns to Resiliency Strategies for Software Investments

    2023-03-29

    McKinsey & Company: Private equity (PE) investments in software—500-plus deals of more than $100 billion in value last year—have outperformed other investments made by the asset class for upward of a decade.

    Read more...

    Europe Cyber Security Market will reach US$ 103.51 Billion in 2028

    2023-03-28

    GlobeNewswire: In 2021, according to Eurostat, the expanding penetration of internet users, 95% of young people (aged 16-29 years) in the European region, and the adoption of cloud-based services and Advanced Persistent Threats (APTs) presented an extensive chance for cyber vendors in the European cyber security market size.

    Read more...

    DigitalOcean Study Finds Growing Cybersecurity Concerns Among SMBs and Startups

    2023-03-28

    Yahoo Finance: DigitalOcean Holdings, Inc., the cloud for startups and small-to-medium-sized businesses (SMBs), today announced the findings of a recent report on how SMBs feel about and are responding to cybersecurity threats.

    Read more...

    Regulator Tells Australian Banks to Boost Cyberattack Defenses

    2023-03-27

    BNN Bloomberg: Australia’s financial institutions must improve their resilience to cyberattacks, the head of the nation’s banking regulator said.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates