shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Slick

    The Target: Slick, an Indian based social media platform.

    The Take: Exposure of 153,000 records of Personally Identifiable Information including: full names, mobile numbers, dates of birth, and profile pictures, and some belong to minors.  

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection and knowledge of the IP address could have viewed and downloaded the data. The domain name for the database was also at risk by being under an easy to guess subdomain of Slick’s main website.

    Authentication controls are an important piece in an overall robust cybersecurity posture. Companies should be fully aware of how their data is secured and stored. Furthermore, this sensitive user data is perfect for constructing highly effecting spear-phishing campaigns. Regular monitoring of data storage process can help mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    The Cost of Cybersecurity Insurance Is Soaring–And State-Backed Attacks Will Be Harder To Cover

    2023-02-15

    Yahoo Finance: State-backed cyber attacks are on the rise–but they are not raising the level of alarm that they should in the corporate world. When working with companies, my team often encounters executives who say they have insurance, so everything will be alright. 

    Read more...

    New Year, More Cybersecurity Concerns: What To Expect In 2023

    2023-02-14

    Forbes: Despite the pandemic seeming to ease slightly, 2022 was another year plagued with unknowns and disruption. From global conflict and cybercrime to ongoing supply chain challenges, the only certainty appears to be uncertainty.

    Read more...

    ChatGPT And More: What AI Chatbots Mean For The Future Of Cybersecurity

    2023-02-14

    ZDNet: From relatively simple tasks, such as composing emails, to more complex jobs, including writing essays or compiling codeChatGPT -- the AI-driven natural language processing tool from OpenAI -- has been generating huge interest since its launch.

    Read more...

    Airline SAS Network Hit by Hackers, Says App Was Compromised

    2023-02-14

    US News: Scandinavian airline SAS said it was hit by a cyber attack Tuesday evening and urged customers to refrain from using its app but later said it had fixed the problem. News reports said the hack paralysed the carrier's website and leaked customer information from its app.

    Read more...

    Indigo Cyberattack Highlights Mounting Prevalence, Sophistication of Hackers: Experts

    2023-02-13

    BNN Bloomberg: A cybersecurity incident stretched into its fifth day at Indigo Books & Music Inc., on Monday, illuminating the growing risk of cyberattacks on Canadian companies and consumers.

    Read more...

    Spain, U.S. Dismantle Phishing Gang That Stole $5 Million in a Year

    2023-02-13

    Bleeping Computer: Spain's National Police and the U.S. Secret Service have dismantled a Madrid-based international cybercrime ring comprised of nine members who stole over €5,000,000 from individuals and North American companies.

    Read more...

    Cybersecurity, Hardware Cos Join Layoff Race

    2023-02-12

    Bizz Buzz: Technology layoffs continue without any respite in sight as cybersecurity firms and hardware devices companies optimise workforce, joining global technology giants like Google and Amazon among others. Sources in the know said many cybersecurity firms have recently reduced their workforce as hyper-demand arising from the pandemic begins to wane.

    Read more...

    Know Your Breach: 8Twelve Financial Technologies

    The Target: 8Twelve Financial Technologies, a Canadian-based mortgage solution company.

    The Take: Exposure of 717, 814 records of Personally Identifiable Information including: names, phone numbers, email addresses, physical addresses, and more critically, detailed “lead” sales data on what kind of mortgage customers were hoping to secure.

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture. This data is perfect for constructing highly effecting spear-phishing campaigns. Multi-factor authentication and password length and complexity rules on server access are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Law Firm Compliance Challenges Underscore Need for Renewed Cyber Security Focus

    2023-02-09

    PR Web: Messaging Architects, an eMazzanti Technologies Company and legal technology expert, examines law firm compliance challenges in a new article. The informative article first asserts that attorneys must understand how and when numerous regulations apply to law firms.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates