shutterstock_490960141-1

Industry News: ESG5

    Will Cybersecurity Remain Recession-Proof in 2023?

    2023-01-31

    Dark Reading: We've recently seen substantial layoffs across the tech sector, to the tune of around 140,000 redundancies made by big names such as Amazon, Salesforce, Microsoft, and Tesla. As the recession bites, falling stock prices and further contraction in the market, together with merger and acquisition activity, are expected to force businesses to reduce head count further still. 

    Read more...

    New US Ransomware Strategy Prioritizes Victims But Could Make It Harder To Catch Cybercriminals

    2023-01-31

    CNN: US and European law enforcement’s disruption last week of a $100-million ransomware gang is the clearest public example yet of a new high-stakes strategy from the Biden administration to prioritize protecting victims of cybercrime – even if it means tipping off suspects and potentially make it harder to arrest them.

    Read more...

    Cybercrime Job Ads On The Dark Web Pay Up To $20k Per Month

    2023-01-30

    Bleeping Computer: Cybercrime groups are increasingly running their operations as a business, promoting jobs on the dark web that offer developers and hackers competitive monthly salaries, paid time off, and paid sick leaves. In a new report by Kaspersky, which analyzed 200,000 job ads posted on 155 dark websites between March 2020 and June 2022, hacking groups and APT groups seek to hire mainly software developers (61% of all ads), offering very competitive packages to entice them.

    Read more...

    Why Cybersecurity Regulations And Oversight Are As Important As Safety Standards In The Modern Workplace

    2023-01-30

    Forbes: Now is the time for cybersecurity policies to become as ubiquitous and accepted as workplace safety policies. Cybersecurity today is where physical safety was 40 years ago—there are few regulations or standards, and those that exist often feel arbitrarily imposed. Cybersafety is not an expected or regulated part of corporate culture. 

    Read more...

    Know Your Breach: Zendesk

    The Target: Zendesk, a customer solutions service provider.

    The Take: Access to an internal logging database which may have contained service data belonging to Zendesk and its customers.

    The Vector: An employee’s credentials were compromised though an SMS phishing attack which led to the employees handing over their login credentials to the attackers.

    This breach is a stark reminder of how important authentication controls are in an overall robust cybersecurity posture. Regular social engineering and phishing awareness training are effective strategies to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    UK: Cybersecurity - Private Equity Firms Sharpen Their Focus

    2023-01-25

    Mondaq: Cybersecurity has become an increasingly regulated area of risk for many businesses in the digital world. As technology has advanced and cyber-attacks have become more sophisticated, the measures needed to protect business' data from breaches become more extensive too. This is mirrored by an increased regulatory environment where sanctions are implemented more strictly and conservatively by regulators.

    Read more...

    Zacks Investment Research Data Breach Affects 820,000 Clients

    2023-01-25

    Bleeping Computer: Zacks discovered the at the end of last year that some customer records had been accessed without authorization. An internal investigation into the incident determined that a threat actor gained access to the network somewhere between November 2021 and August 2022.

    Read more...

    German Cybersecurity Officials Looking Into 'Attacks' On Websites

    2023-01-25

    Sky News: The attacks - known as distributed denial-of-service (DDoS) - work by directing high volumes of internet traffic towards targeted servers in a bid by so-called hacktivists to knock them offline.

    Read more...

    North Korea-linked Hackers Behind $100 Million Crypto Heist, FBI Says

    2023-01-24

    CNBC: North Korean-linked actors were behind the theft of $100 million through the hack of a crypto product last year, the Federal Bureau of Investigation said.

    Read more...

    LastPass Owner GoTo Says Hackers Stole Customers’ Backups

    2023-01-24

    TechCrunch: LastPass’ parent company GoTo — formerly LogMeIn — has confirmed that cybercriminals stole customers’ encrypted backups during a recent breach of its systems.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates